Thought Leadership
Interview with Hamza Zarrouk, Head of Investigations and Fraud Control, AXA XL

To kick us off, can you tell us a bit about your role at AXA XL and your focus within investigations and fraud control?
My name is Hamza Zarrouk, and I am the Head of Investigations at AXA XL. I have dedicated my career to uncovering and mitigating various forms of financial and organizational misconduct as well as improving fraud prevention and detection capabilities within AXA.
In my role, I lead a global team responsible for investigating high-risk issues including asset misappropriation, and impersonation attacks. These threats are increasingly sophisticated and can undermine trust and integrity within organizations. My team works in conjunction with Information security to develop strategies to detect and prevent such frauds, implement standardized processes, and promote a security culture labelled “Care, Protect, Alert”
At the event, I will be discussing impersonation attacks — an insidious form of fraud that often involves impersonating trusted individuals or entities. I look forward to sharing insights on how organizations can better recognize, prevent, and respond to these cyber-enabled threats to safeguard their assets and reputation.
Compromised advisor emails and fraudulent instructions from legitimate accounts are increasingly common – what patterns are you seeing in how these attacks unfold?
In today’s landscape of cyber threats, our focus must go beyond the traditional phishing scenarios of generic email scams or CEO impersonations that most organizations have learned to defend against. These are well-understood, and while evolving with deepfake technology, they are not the core of the current wave of sophisticated attacks we’re witnessing.
What’s more insidious is how fraudsters have shifted their attention. They’ve discovered that it’s far easier and more lucrative to target the very arteries of our business ecosystem—our clients, beneficiaries, claimants, intermediaries, brokers, and legal professionals. These actors often serve as the bridge between the insurance company and the ultimate recipient of funds, making them an attractive target for impersonation and manipulation.
The simplest scenario involves impersonating the insurance company itself. Fraudsters craft convincing communications instructing clients to transfer funds to bank accounts controlled by the criminals. To the client, it seems legitimate—an official request from their insurer, leading to financial losses that are often difficult to recover.
A more complex scenario emerges when we consider the recent surge in data breaches. The leakage of passwords and sensitive information has made access to emails and resources of individuals and small-to-medium enterprises (SMEs) readily available. AI tools enable these criminals to sift through vast volumes of stolen data, quickly identifying upcoming transactions or vulnerable accounts. They don’t even need to contact the insurance company directly; instead, they hijack the communication channels of trusted intermediaries.
Once they gain control of a beneficiary’s account, the fraudsters impersonate the individual’s identity and instruct the solicitor, broker, or accountant to redirect payments—often to offshore accounts. Here, the insurance company’s controls might still validate the solicitor’s identity, making the deception even more convincing, because the communication appears legitimate and compliant with existing protocols.
The third scenario involves a strategic wait. After the funds are transferred to the intermediary—be it a solicitor, broker, or accountant—the fraudsters impersonate the beneficiary again, instructing the intermediary to deposit the funds into offshore or shell accounts. This layered approach complicates detection and increases the potential for significant financial loss.
Despite our extensive efforts—hundreds of training sessions, awareness campaigns, and technological controls—our weakest link remains the individual beneficiary or SME. Human nature and organizational complacency often open the door for these intrusions. That’s why our defense must be multi-layered, combining technological safeguards, ongoing education, and rigorous verification processes—not only within our organization but across the entire broader ecosystem in which we operate.
In essence, today’s fraud landscape isn’t just about technical vulnerabilities; it’s about understanding the behavioral and systemic weaknesses that fraudsters exploit. As experts, our role is to stay one step ahead – anticipating these evolving tactics and reinforcing our defenses at every level, including the wider ecosystem, to effectively mitigate these risks.
How has the rise of AI-generated content and deepfakes changed the landscape for impersonation fraud?
Traditionally, impersonation fraud required significant time and effort for fraudsters to prepare and execute, involving manual reconnaissance, impersonation, and communication. However, with the advent of AI-generated content, these campaigns can now be launched rapidly and at scale. Attackers can produce highly tailored messages by leveraging data from breached accounts, social media profiles, or other sources to craft convincing narratives that resonate with targeted individuals. This level of personalization dramatically increases the likelihood of success, as recipients perceive these communications as authentic.
The integration of AI and deepfake technology further complicates detection efforts. Conventional controls—such as verifying email addresses, cross-checking phone numbers, or employing basic identity checks—are often insufficient against AI-crafted content, which can be seamlessly embedded into legitimate communication channels, making fraudulent messages appear highly credible.
Personally, I have not yet encountered a case involving high-quality deepfakes, but I am aware that criminals have found ways to circumvent traditional verification methods. For instance, some have used free to bypass selfie verification when opening bank accounts in victims’ names. There is even a publicly available video tutorial detailing how to carry out such attacks, which adds to the challenge of detection.
In the past, we recommended verbal verification for large transactions as an additional safeguard. However, with AI-generated voice synthesis and deepfake audio, this approach can also be circumvented. Similarly, SMS-based verification codes—once considered a robust control—are increasingly vulnerable to techniques like SIM swapping or well-executed social engineering attacks.
Overall, these technological advancements mean that our defenses must evolve. Relying solely on traditional controls is no longer sufficient; we need to implement multi-layered, behavior-based detection methods and continuously educate all stakeholders about these emerging threats.
Looking forward, what kinds of controls or collaboration are needed to stay ahead of increasingly sophisticated impersonation attacks?
Real-Time Alerts:
Given that a primary goal of many impersonation scams is to divert funds, the banking sector has a crucial role to play by implementing smarter, more reactive controls to detect and prevent these fraudulent transactions.
I dream of a real-time alerting system (embedded within the bank offer) that flag suspicious transactions based on fraud/impersonation red flags. For example, banks could introduce alerts when the actual beneficiary of a transfer does not match the name recorded by the payer. Some solutions in the market already provide such services, but it would be highly beneficial to everyone to embed this functionality into the standard banking offerings.
Layered Authentication and Customer Education:
Another key control is educating all participants within the ecosystem on layered authentication, especially for high-risk transactions. This could include requiring multi-channel confirmation—such as secondary verification through a different communication channel—before executing large or unusual transfers. This approach helps ensure that requests are genuine at every stage of the process. (sharing a concrete example of failure because one participant missed to get a verbal confirmation).
Leveraging Advanced Identity Verification:
At an early stage, we should also promote the widespread use of advanced identity verification tools that cross-reference customer information against multiple trusted data sources. This can help detect anomalies or inconsistencies early on. Incorporating AI-driven analytics further enhances this process by identifying irregular transaction patterns, such as recently created email accounts, phone numbers, or bank accounts linked to profile changes, which may indicate fraudulent activity.
Industry Collaboration for Enhanced Security:
Finally, collaboration across the industry is essential. Sharing threat intelligence with other institutions helps create a unified front against emerging impersonation tactics. Industry-wide initiatives for data sharing and best practice exchange enable us to stay ahead of evolving threats and strengthen our collective defenses.
Article: External Fraud in Banking

External Fraud in Banking: The Systemic Threat that Demands a Coordinated National Response
External fraud has become one of the greatest threats to the stability of the financial sector, customer trust, and the integrity of the economic system. In recent years, banks have witnessed a continuous, sophisticated, and diversified growth in fraud attempts, in a context where organised crime, technology, and the digitalisation of financial services have created new vulnerabilities.
Public reports show continued increases in fraud rates in 2025, with many financial institutions recording rising losses resulting from customer reimbursements linked to fraud-related incidents.
Scams, phishing, and psychological manipulation have become the most impactful typologies. Other threats such as account takeover, CEO Fraud, and Investment Fraud also remain prevalent. At a global level, authorised fraud is already viewed by some countries as a national security threat due to the financial harm it causes to individuals and businesses, and the sense of alarm and insecurity it generates.
Digital onboarding—which has emerged as a key initiative to improve customer experience and accelerate access to financial services—has also contributed to the rise of mule accounts, as remote onboarding allows for reduced scrutiny of the true intentions behind account openings. Instant Payments, designed to accelerate fund transfers within the European Union, have also become one of the main instruments used to disperse the proceeds of fraud. Fraudsters exploit the speed of fund movement to accelerate circulation and reduce the window for timely detection, thereby decreasing the likelihood of freezing or recovering funds. Even judicial authorities, despite international cooperation mechanisms, face significant limitations due to the speed at which funds are dispersed.
Europe faces more than EUR 190 billion in illicit flows associated with cross‑border networks and mule accounts. Criminal networks use digital platforms to recruit mules, open accounts remotely, and move funds quickly. Mule accounts are also available on the Dark Web, where they are sold to criminal organisations to receive the proceeds of illicit activities. It is increasingly common for a single mule account to receive funds originating from multiple types of crime.
Regulatory developments have been moving towards greater victim protection, which has translated into reimbursement obligations for consumers in cases of fraud. The UK’s Financial Services Markets Act and the European PSD3 directive (currently under development) increase the responsibilities of financial institutions, with the expectation that this will lead to more effective fraud prevention and response.
Why the Response Must Go Beyond the Banking Sector
Most of the fraud cycle occurs outside the banking system: social networks, marketplaces, messaging platforms, and telecommunications providers are now the main channels through which victims are targeted. The lack of cross border coordination creates significant vulnerabilities, allowing criminal networks to exploit different jurisdictions to hinder the rapid exchange of information that is essential for fund recovery and disruption of criminal activity.
An effective response to fraud requires:
- Coordinated blocking of suspicious phone numbers
- Sharing of fraud indicators between banks and telecoms
- Rapid removal of fraudulent profiles and advertisements on digital platforms
- Legal mechanisms enabling real‑time information sharing
- Joint public awareness campaigns
To effectively combat mule accounts, it would be crucial to establish a transnational database that enables:
- Immediate identification of accounts and account holders flagged as mules
- Preventive blocking of new banking relationships
- Detection of interbank behavioural patterns
- Faster cooperation with authorities
- Prevention of the issuance of new mobile phone numbers to individuals identified as mule recruiters or participants
The global trend is clear: only through integrated compliance ecosystems — where fraud, AML, KYC, and sanctions functions operate in a unified manner, providing a complete risk view — can financial institutions effectively combat the rise and impact of fraud. Effective fraud risk mitigation requires coordinated action across all economic sectors through joint initiatives and information sharing. Law enforcement agencies must also strengthen their capacity to act quickly, ensuring international judicial cooperation can occur within operationally relevant timeframes.
Failure to act on rising fraud levels will result in a pervasive sense of distrust among consumers, particularly towards financial institutions, with wider repercussions across the digital ecosystem.
By João Caeiro, March 2026
Interview with Pallavi Kapale, Senior Financial Crime Officer, Financial Crime Intelligence Unit, Bank of China

To start us off, can you tell us a bit about your role at the Bank of China and your focus within the Financial Crime Intelligence Unit?
I detect, analyse, prevent and disrupt fraud and money laundering networks. The objective is not only restricted to resolving complex cases but also to anticipate future threats. Within the Financial Crime Intelligence Unit, my focus is on strategic intelligence – overseeing and managing complex, high-priority investigations ensuring timely resolution. I also track and update emerging financial crime typologies and develop threat intelligence. I also train the wider bank on detecting suspicious activity, spotting red flags and navigating transaction-monitoring alerts. A significant part of my remit currently is working on the transaction monitoring risk assessment, collaborating with data analytics and product teams to refine detection rules.
Can you outline some of the tactics used when targeting victims via pig butchering to maximise impact?
Pig butchering fraudsters are very meticulous in building long-term trust before exploiting it for maximum gain. The common tactics include;
- Extended grooming period: They spend weeks or months engaging in daily, highly personalised conversation to lower suspicion.
- Emotional manipulation: They create a false sense of intimacy or partnership, sometimes even staging small ‘acts of care’ like remembering anniversaries or other personal milestones.
- Gradual investment escalation: They start with small ‘wins’ on a fake trading platform to build the illusion of legitimacy, followed by a larger deposit.
- Psychological anchoring: They use fabricated screenshots, fake portfolio dashboards, or staged ‘withdrawals’ to convince victims that their funds are safe and growing.
- Pressure points: They apply urgency via time-limited ‘opportunities’ or invoke shared life goals to trigger fear of missing out.
How are fraud farms, particularly those involving trafficked individuals, being used to scale romance-investment scams on a global level?
According to the Council of Foreign Relations, numerous criminal organisations, primarily originating from China, have established sophisticated cyber centers in Southeast Asia that are specifically dedicated to conduct fraudulent activities. These call centers carry out a form of fraud known as ‘pig butchering’, combination of romance and investment scam. They target victims across social media, dating platforms and messaging apps. A study from the University of Texas shows that an astonishing $75 billion has been lost to pig butchering scams in the last four years.
Organised criminal groups now run ‘fraud farms’ where trafficked or coerced individuals are forced to operate multiple scam personas across social media, dating platforms, and messaging apps. These farms operate on an industrial scale, with hundreds of operators working through scripted conversations and playbooks. They use multilingual teams to target victims in different regions simultaneously.
These operations are based in Southeast Asia, particularly Cambodia, Myanmar, and Laos. Victims are tricked into fake jobs and forced to scam others under threats of violence, facing severe punishments for noncompliance. The link between financial fraud and human trafficking adds a disturbing layer of exploitation to pig butchering scams. Criminal groups use trafficked victims because they need skilled workers for large scams, it costs less than hiring real employees, Not only do these scams devastate victims financially, but they also fuel a criminal industry that profits from human suffering.
In what ways are fake websites and AI-driven impersonation being used to create false legitimacy?
- Cloned investment platforms: Fraudsters are cloning investment platforms; they are replicating legitimate brokerage or crypto exchange interfaces, coupled with fabricated live market data and account dashboards.
- AI-generated identities: Fraudsters are using Deepfake video calls, synthetic profile pictures, and voice cloning to pose as investment advisers, romantic partners, or customer service representatives is increasing at an alarming rate.
- Domain spoofing: Fraudsters are registering lookalike URLs to mimic real financial institutions.
- Search engine manipulation: Fraudsters are using paid ads and Search Engine Optimisation (SEO) to push fake sites above legitimate results.
What are the biggest challenges in tackling these cases when they involve multiple jurisdictions and regulatory environments, and how can international collaboration be improved?
Due to the global nature of these scams and fragmented legal frameworks, asset freezing powers vary drastically between countries. The exchange of this information is very slow while the funds move out in minutes/seconds. Cross-border data sharing can be hindered by various interpretations of GDPR.
Criminal networks exploit countries with limited enforcement capacity of high corruption, ensure these countries are listed and the payments are screened. For example; if a company in the UK is sending funds referenced as salary payments to countries in South-East Asia, flag those payments for further review.
Intelligence sharing is needed between banks, regulators and law enforcement. Increase in public-private partnerships can help the banks to share red-flag indicators in real-time. A combination of cybercrime, financial intelligence and human trafficking units would be beneficial.
Disclaimer – The views expressed in the content are my own and do not necessarily reflect the views of my employer or other associated parties.
Interview with Giana Quandt-Martiena, Chief Compliance Officer, KBC Bank NV, Rotterdam

To start us off, can you tell us about yourself and your role at KBC Bank NV, Rotterdam?
A little about myself, born in the Caribbean, with a legal and business background, international experience and for the last four (4) years working as Chief Compliance Officer in the Netherlands, the city of Rotterdam for a Belgian Bank insurer which is registered at the Euronext.
If I contemplate my role today, I note a paradigm shift towards advice, support, and guidance. Naturally, the classic requirements of the role are still part of the day today. These being monitoring, translation of policy and the provision of training and awareness. Next to this I am a board member and the officer that communicates with the regulator.
As noted, the branch is part of KBC Bank NV and also from that angle I have a reporting and participation obligations
Can you outline some of the challenges of embedding friction intelligently into the customer journey so that fraud is detected without driving legitimate customers away?
In the last two (2) years I observe that there is a high degree of public awareness in the Netherlands. Especially where it concerns outside fraud. There are a number of public awareness campaigns mostly related to the natural person in the public domain. I work in a corporate environment and for the corporate entity the controls and the requirements sometimes are considered cumbersome. For this environment being a victim of a fraud scheme can bring a feeling of awkwardness. The biggest challenge I consider is connecting to the right person without delay so that the (possible) damage can be minimized.
When delays occur due to fraud checks, what strategies have been found to be effective in maintaining customer trust?
Open and honest communication, taking the customer with you in the investigative journey. No chatbots, but a warm body to answer concerns
What approaches can help financial institutions design onboarding journeys that feel smooth for customers while still meeting strong KYC requirements?
- Education, education, the why you need data
- Ask for the minimum requirements, remember that when data is outdated it should be disposed of correctly
- Do not use software if you are not aware of the risks
- Be open for criticism from the client. There is always a lesson learned there
- Do not forward a genuine concern to a chatbot
What are the benefits of calibrating controls to specific customer types, behaviours, and risk profiles, and can you provide a brief insight as to how do financial institutions put this into practice?
In terms of high level, I would say:
- Know what type of customers you are willing to service
- What their business purpose is, can you comply with their need?
- Is your customer aware of its risks and what has it done to keep them under control?
- When looking at the customer’s value chain, are you comfortable with the chain, the countries, the volumes?
- How are you communicating with the customer as to its risks and controls?
- Are you open to discuss risk triggers with the customer and if yes what will you do with the data?
Article: The EU’s AML Reset: From Compliance Activity to Operational Effectiveness and Credible Outcomes

The EU’s new AML framework – anchored in AMLR and AMLA – is not simply regulatory evolution. It is a structural reset of how financial crime risk is judged, supervised, and operationalised across the financial system.
For years, institutions have invested heavily in controls, systems, and resourcing. Yet the uncomfortable truth remains – despite this effort, the measurable impact on financial crime risk has been limited.
The new regime crystallises that gap – and raises the bar decisively. This shift, however, is unfolding within a broader macro-financial and geopolitical context that is materially shaping implementation conditions. Increasing global fragmentation, evolving security priorities, and renewed focus on economic resilience are placing competing demands on both institutional capacity and supervisory attention. In this environment, the effectiveness of the new framework will depend not only on its design, but on the system’s ability to sustain focus and execution alongside these broader pressures.
What is fundamentally changing?
From rules to outcomes
Compliance is no longer assessed by the existence of controls, but by their effectiveness in reducing risk. Supervisory focus shifts to outcomes: alert quality, escalation logic, and decision consistency.
From fragmented interpretation to EU-wide comparability
With AMLR introducing a single rulebook, national discretion narrows. Practices that once reflected “local interpretation” will now be tested against a common European benchmark – making inconsistencies across jurisdictions far more visible and difficult to defend.
From process-driven to judgement-driven supervision
AMLA introduces a comparative, peer-based supervisory model. Institutions will increasingly be assessed not only on their own frameworks, but on how their decisions and outcomes compare with peers facing similar risks.
From control intensity to risk prioritisation
The risk-based approach is being re-anchored. Uniform application of controls across risk tiers will no longer be seen as conservative – it may be interpreted as a failure to differentiate risk.
From governance structure to governance accountability
Boards and senior management move to the centre of supervisory scrutiny. Risk appetite, resource allocation, and trade-offs must be explicit, evidenced, and defensible.
Operational effectiveness: the new battleground
A critical, and often underestimated, shift is the elevation of operational effectiveness as a core supervisory expectation.
This goes beyond policy design. It is about how the entire AML framework performs in practice:
- Are alerts calibrated to identify real risk, not just generate volume?
- Do investigations lead to consistent and explainable outcomes?
- Is management information decision-useful – or retrospective justification?
- Can the institution clearly demonstrate how resources translate into risk mitigation?
Inefficiency is no longer neutral – it is a supervisory weakness. High false positives, fragmented systems, and manual workarounds are not just operational challenges; they are signals of poor risk prioritisation and weak governance.
This expectation is further reinforced by a changing external environment. As financial systems become more closely linked to geopolitical risk, sanctions regimes, and economic security considerations, supervisory expectations around effectiveness are increasingly shaped by the need for timely, credible, and decision-useful outcomes.
What this means in practice across the industry
For large banks
The challenge is complexity and consistency.
- Cross-border institutions must align previously fragmented frameworks into a coherent, group-wide model
- Divergent practices across jurisdictions will be increasingly visible under comparative supervision
- Legacy systems and siloed data architectures will struggle to support the required level of traceability and explainability
The strategic imperative: move from federated compliance to integrated, data-driven risk management.
This imperative is also influenced by broader systemic dynamics. Institutions are operating in an environment where financial crime risk increasingly intersects with geopolitical developments, cross-border tensions, and evolving economic priorities. As a result, AML capability must be resilient not only to regulatory scrutiny, but to a more complex and rapidly changing external risk landscape.
For neo banks
The challenge is scaling with credibility.
- Rapid growth models (including AI) must now demonstrate mature governance and defensible risk decisions
- Simplified or overly standardised controls will be challenged under an effectiveness lens
- Heavy reliance on automation increases expectations around explainability and model governance
The strategic imperative: ensure that speed and innovation are matched by decision transparency and control discipline.
For fintechs
The challenge is institutionalisation of AML capability.
- AML can no longer be treated as an adjunct function or outsourced responsibility
- Participation in ecosystems (including partnerships and embedded finance) increases exposure to shared risk
- Article 75-style information sharing introduces both opportunity and governance complexity
The strategic imperative: build robust, scalable AML frameworks that can withstand direct supervisory scrutiny.
The strategic reality
This is not a compliance readiness exercise, but rather an operating model transformation. It is also a transformation taking place under conditions of heightened economic and geopolitical uncertainty, where institutions must balance regulatory expectations with broader strategic and operational pressures.
Institutions that continue to optimise for activity – more alerts, more reviews, more documentation – will struggle in a regime that rewards:
- clarity of judgement
- coherence of governance
- and demonstrable operational impact
Those that succeed will take harder, more deliberate decisions:
- prioritising high-impact risks over blanket coverage
- reallocating resources toward analytical capability and data quality
- embedding explainability into both human and automated decision-making
- and aligning governance with real, not theoretical, risk appetite
Final thought
The EU’s new AML regime redefines credibility. It is no longer built on the volume of controls or the completeness of documentation – but on the quality of decisions and the effectiveness of outcomes.
The trajectory of this transformation will be shaped by the broader environment in which it is implemented. Sustaining consistency, comparability, and supervisory focus in a context defined by economic pressure and geopolitical complexity will be a key determinant of whether the framework achieves its intended impact.
Interview with Aisling Twomey, Head of FinCrime, Business Banking, EU, Sanctions, Monzo Bank

To start us off, can you tell us a bit about your role at Monzo Bank and your focus as Head of FinCrime for Business Banking, EU and Sanctions?
I have been at Monzo Bank almost 4 years now. When I first joined, I worked on building financial crime controls for the Retail Bank, before moving across to the Business Bank at the start of 2023. My background is in corporate and business banking so I was really pleased to return to it. I’ve always working on sanctions policy at Monzo and it’s been fun to watch it grow and change as the world changes around us. Finally, when Monzo decided to go international, I signed up to be part of that journey and it’s been exciting to watch everyone come together to make new banks in new locations!
Can you provide some insight into what effective sharing of AML-detected activity with fraud and cyber teams involves within a unified operating model?
For me, this is about playing football instead of running a relay race. So often I see firms ‘pass the baton’ between teams but it would be more efficient to have everyone working together with the same goal in mind. I want a shared data layer, joint investigation units, feedback loops and machine learning to enrich customer profiles, spot trends and learn on a loop. It’s no longer about sending an email and saying the job is done, we have to integrate information across the areas that need it because all support each other‚ like the players on a football team.
How can financial institutions effectively move from traditional alert clearing toward more intelligence-led, cross-typology investigations and risk anticipation?
We need to continue progress away from tick the box compliance toward outcome based effectiveness with metrics to match. We need to break the typology silo by building data interoperability and move from manual alert clearing to agentic AI approaches. Machine Learning models can help us learn at scale and we need to be looking to the horizon always. It’s no longer a ‘nice to have’ for us to think about the future and the world around us.
What does strong cross-team coordination look like when dealing with money mule and IVTS typologies?
It’s a smooth, efficient system where people work in parallel. The fraud team identifies the theft, the AML team finds the muling and the security team identifies the infrastructure, all at the same time. Getting on top of money muling means near real-time signalling shared across spaces in the same moments with a joined up view and a data stack that includes all possible information at once. For IVTS, AML teams should be focusing on the signals and seeking cyber support to understand the IVTS customer profile. A joint investigation across AML, fraud and security could help us identify parts of the pattern.
Can you outline some of the challenges involved in upskilling financial crime analysts to work effectively across fraud, AML and sanctions?
It’s busy! People who have traditionally worked in Fraud or Financial Crime may need to cross-skill and it’s tricky to achieve this when time is tight. Organisations need to provide opportunities, training and development. Sanctions is its own huge item too; the pace of change is incredibly fast and it’s impossible to stay on top of it all, but teams need different levels of training to ensure the risks are spotted in the right places.
Interview with Laura Lehane, Head of Financial Crime & MLRO, AJ Bell

To start us off, can you tell us about yourself and your role at AJ Bell?
I’m Laura Lehane, Head of Financial Crime and MLRO at AJ Bell. I joined the business in June 2024, moving into the Investment industry after 20 years in Retail Banking. I lead everything financial crime, including the design and delivery of our financial crime strategy, covering everything from fraud and AML to market abuse and sanctions. My role is about making sure we’re not just compliant, but proactive—using data, technology, and collaboration to stay ahead of emerging threats. I work closely with teams across the business to embed a strong control environment that protects our customers and supports safe growth.
One area I’m particularly passionate about is data sharing. I’ve seen first-hand how effective it can be in disrupting fraud and protecting customers, and I’m committed to driving change across the industry to make it the norm, not the exception. Whether it’s working with other platforms, regulators, or the markets themselves, I believe collaboration is the key to really disrupting the criminals.
Can you provide a brief outline of how online engagement tactics, such as fraudulent ads and impersonation, exploit user behaviour on digital platforms?
Absolutely. Fraudsters are getting smarter about how they use digital platforms to manipulate behaviour, especially in scams like pump and dump. It usually starts with a convincing ad or social media post that looks legitimate. Once someone clicks through, they’re quickly moved onto WhatsApp or Telegram, where the real manipulation kicks in.
They’ll start by promoting genuine stocks that deliver small, steady returns, just enough to build trust. Then they pivot to the stock they’ve lined up for the pump. The group gets flooded with charts, graphs, and technical jargon, often designed to confuse rather than inform. They’ll falsify data, reference fake news articles, and impersonate analysts or firms to create urgency and credibility.
It’s a calculated strategy: build trust, create hype, and then exit once the price peaks—leaving retail investors exposed. Because it all happens in closed groups, it’s harder to detect until the damage is done. That’s why early intervention and platform collaboration are so important.
How can industry collaboration effectively prevent scams originating on platforms like social media and other digital platforms?
We’ve seen real disruption when firms come together and share intelligence across platforms. Through collaboration with other investment platforms, we’ve been able to spot patterns early and intervene before scams escalate. That kind of joined-up approach has led to measurable reductions in customer losses, particularly around scams and investment fraud.
We’re also looking at how we can extend this collaboration to the stock markets themselves, especially in cases where trading activity is being manipulated as part of wider scam operations. There’s a huge opportunity here to build a more connected response—one that spans platforms, markets, and regulators.
And now, with the new data sharing powers under ECCTA, we’ve got the legal framework to really harness that potential. It gives us the ability to move faster, share more meaningfully, and act with confidence. Fraud doesn’t operate in silos, and neither should our defences. The more we collaborate, the more we raise the bar for prevention across the industry.
What are some of the key hurdles in co-ordinating cross-sector responses to reduce scam exposure?
One of the biggest challenges is fragmentation. Different sectors have different priorities, systems, and regulatory frameworks, which makes coordination complex. There’s also the issue of data sharing—we need to be able to exchange information quickly and securely, but that’s not always straightforward.
There are some strong initiatives out there, like FIRE and Data Fusion, which have made real progress in the retail banking space. But outside of that, it’s been harder to get traction. As an investment platform, we’ve had to be quite assertive to be heard, especially when engaging with larger players like the banks, or bodies like UK Finance and the NCA. Sometimes it feels like we’re just asking for a seat at the table—or even just an invite to the party. And if we get it, we promise to bring the good snacks.
That said, we’re making progress. There’s growing recognition that the data we hold is incredibly valuable, and we’re starting to see real interest in bringing us into the fold. If we could combine that full suite of intelligence—across banks, platforms, telcos, and markets—the ability to properly identify and disrupt fraud would be exponential. It’s not just about plugging gaps; it’s about building a truly integrated defence. And we’re pushing hard to make that happen.
Please can you provide a couple of recent examples of collaboration success stories?
I’ll be sharing more details in my session at the summit, but for a bit of a teaser – The first is a multi-platform SIPP fraud that had been running for over three years. Within just a few months of sharing intelligence across platforms, we were able to piece together the full picture and effectively all but shut it down. That kind of result shows what’s possible when we break out of silos and start connecting the dots.
The second is the recent Ostin Technology pump and dump case, where coordinated data sharing across platforms allowed us to identify and disrupt a scam that was gaining traction fast. The global impact of losses from this scam is estimated to be around $500mn, yes half a BILLION dollars. By working with other platforms and surfacing intelligence early, along with proactive intervention and customer education, we were able to intervene and significantly reduce customer harm—something that wouldn’t have been possible without that collaborative effort.
These cases prove that when we collaborate—especially with the right data and the right partners—we can move from reactive to proactive. The intelligence is there. The challenge is making sure it’s shared, understood, and acted on. And when it is, the impact is huge.
Interview with Katharine Strain, Head of Financial Crime Prevention, Danske Bank

To start us off, can you tell us a bit about your role at Danske Bank and your focus within Financial Crime Prevention?
I lead the Financial Crime Prevention team with responsibility for protecting both our customers and the Bank from financial crime. Our work spans customer due diligence, transaction monitoring, fraud detection and prevention, and importantly supporting and educating customers who may be at risk or who have already been impacted by fraud.
As financial crime becomes increasingly digital and fast moving, we need to harness available technology along with close collaboration across the industry, including working with technology partners, law enforcement, and other financial institutions to ensure we are identifying emerging threats early and responding in a way that is both effective and customer centric.
Without giving too much away ahead of April, how are you seeing identity and financial crime attacks become more sophisticated through criminal use of AI?
Across the industry we have seen an increase in the use of AI including for the generation of identity and documents used to support account opening and digital onboarding. We have also seen AI used to create convincing scam journeys through eg fake investment advertisements and personalised communication that appear legitimate. AI also gives criminals the ability to scale operations enabling them to run high volume campaigns with relatively low cost, increasing the number of potential victims and overall impact of fraud.
How do you see AI acting as both an opportunity and an evolving threat within the financial crime landscape?
AI enables industry to move away from eg static rules based fraud controls to more dynamic, intelligence-led detection. AI can analyse large volumes of data, identify complex patterns and identify suspicious activity that would be hard to detect manually improving detection and operational efficiency.. However, the same technology can be exploited by criminals. It is a cost effective way for criminals to scale their attacks and add legitimacy to their scam journeys. Financial Services need to keep pace with increasing sophisitication and criminal’s adaptability.
Can you share your perspective on how AI-enabled identity theft, impersonation, document forgery, and deepfakes are challenging current verification processes?
The industry needs to stay ahead of the fraudsters in the identification of AI generated content or identity theft. Addressing this requires a joined up approach across financial services, tech and telecom to detect and prevent the use of AI generated material to perpetrate a crime. No single organisation can tackle this risk in isolation.
Can you please outline some examples that you are seeing of criminals using AI to outpace existing financial crime controls?
Criminals are becoming increasingly sophisticated in developing AI synthetic ID’s and deepfakes enabling entirely fictitious customers to open accounts and carry out financial crimes. We are also seeing increased use of AI driven impersonation with voice cloning and deepfake video. Individuals are being deceived into authorising payments based on a sense of urgency and trust in the fake. They demonstrate how human judgement can be manipulated with convincing AI.
Interview with Joe Goddard, Membership & Account Director, Stop Scams UK

To start us off, can you tell us a bit about yourself, as well as your role at Stop Scams UK and what your work focuses on day-to-day?
I’m the Membership & Account Director at Stop Scams UK. I joined Stop Scams in November 2024, having previously led multi-discipline, global collaboration campaigns in online advertising. My focus is on delivering value for our members and helping them to engage and participate in our cross-sector collaborations be it data-sharing to deliver scam intelligence across the sectors, working with other organisations to identify opportunities to shape policy, or collaborating on comms to reach mutual customers with crucial advice to protect themselves from scams.
I love seeing our members from large traditional banks and telcos, to fast growing fintechs and global tech platforms working together to identify ways to disrupt scammers. There are so many opportunities to collaborate and it’s great to see our members come together to deliver innovative, high impact intelligence sharing work.
What are the main blind spots in tracking scams that cross between telcos, online platforms, and banks?
Scams cross the finance, tech and telco sectors; but no one sector has end-to-end visibility over a typical scam journey. The Financial Services firms and their customers feel the financial pain; but they cannot stop the problem without working with telcos and online tech firms. When an individual organisation, no matter how big they are, looks only at the fraud signals they can detect on their own platform, it may not be obvious what is happening. However, if we can layer up the signals across 3 x sectors our members can quickly build a more accurate picture, build legal certainty that there is a fraud attempt and start to trigger appropriate action.
What are the key barriers to achieving real-time intelligence sharing between firms, and how are organisations starting to overcome them?
Privacy, data protection and consumer protection are some of the key obstacles to navigate in working toward real-time intelligence sharing between firms, and it’s absolutely right that this be the case. Industry has an obligation to protect the data and privacy of their customers, but also to help protect them from scams and prevent crime. We have worked very closely with our members over the last 5 years to build the case for data sharing, through robust Data Sharing Agreements and Data Protection Impact Assessments, but also by identifying incredibly strong use cases and pilots. Being able to quickly prove the impact of a data sharing initiative and demonstrate impact and ROI to a business is the most effective way to build momentum for further collaboration and change.
We have also found that having a neutral 3rd party to own and drive the collaboration, with a sole focus on making this happen, has been really useful. We focus on delivering the initiatives that our members have tasked us with, and we do the heavy legwork to make it happen, ensuring we stay focused on our goals and objectives.
Once intelligence is gathered, how do you ensure it’s actionable and reaches the right teams or institutions quickly enough to make an impact?
Across our membership we have access to a vast amount of potential data and signals, however ensuring that what we deliver to each member is actionable intelligence is crucial. We do this by working very closely with our members, facilitating cross-sector discussion and testing our pilots and initiatives very carefully. Sometimes enrichment of data is required before it can become useful and actionable to another sector/organisation, and sometimes a signal can be shared directly. In either case speed and legal certainty are vital, and we have built a platform that allows data to be shared via API.
What is equally as important as sharing intelligence, is sharing back the results and impact of that intelligence. Our members are committing significant resources to cross-sector data sharing and it’s important to be able to demonstrate the impact of this to their own organisations. It creates an ever expanding view of fraud networks and their movements across different sectors and that helps everyone to continuously improve their detection and takedown models. Ultimately we want to get ahead of the fraudsters so sharing intelligence and receiving feedback, and then optimising based on this, is all really important.
Looking ahead, what does ‘good’ look like when it comes to upstream scam prevention — and how close are we as an industry to achieving that vision?
Looking ahead we believe it’s important to measure the impact of scam prevention in terms of its ‘ecosystem’ impact. How much of the UK population are we able to protect, and how can we continue to drive these figures forward be that through covering X% of the UK banking sector, X million UK online users or telephone customers.
So a future where all UK consumers are protected because the companies that provide their bank, phone and online platforms etc. are all actively working with each other and sharing intelligence in real time is what we are striving towards. We are well on our way to achieving that vision with Stop Scams UK now including 100% of the UK’s Mobile Network Operators and 99.7% of the UK’s retail banking providers as members, alongside some of the largest technical platforms in the world. Acceleration of the work that is already happening, and engagement from the businesses that are still fighting this alone, is what is needed next.