Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
FRAUDFORWARD
#119

How to Build a Fraud Program: Fraud at the Foundation

59 min

What’s up fraud fighters, and welcome back to Fraud Forward!

Today I’m sitting in the guest chair.

If you caught the episode of The Saturday Fraud Strategist that dropped alongside this one, you already know Chen Zamir and I decided to swap roles. He came on Fraud Forward to interview me, and I went on his show to interview him. We are heading to Money 20/20 in Vegas together and thought this would be a fun way to kick it off.

I spend a lot of time asking questions. Sitting on the other side of the mic is a different experience, and Chen does not ask easy questions. This conversation went places I did not fully expect. We ended in a discussion about how to build a fraud program that works, and more importantly, what gets in the way.

If you have ever walked into an organization that has been fighting fraud for a year, spent money on vendors and headcount, and still were at the same place you started, this episode is for you. The answer is a lot deeper than adding another tool.

What you will hear in this episode:

  • How to build a fraud program assessment when you walk into an organization that has been struggling and nobody can tell you why
  • Why fraud and risk management starts with people, process, technology, and data in that order, and why most organizations start with technology and create more problems
  • The fraud capacity planning model I built as a practitioner to prove headcount needs to executives, including the three-minute-per-alert calculation and how to build a 40-hour week model that accounts for everything your team actually does
  • Why fraud team structure matters before you can optimize anything, and how to answer the centralized versus decentralized question before you start hiring or buying
  • The fraud risk assessment framework I consider the most important tool in a fraud leader's program, including the difference between inherent risk vs residual risk fraud and why a lack of losses does not mean a lack of risk
  • Why fraud technology layering done wrong looks like stacking medications that interact badly with each other, and what fraud technology gap analysis actually looks like before a vendor demo
  • How authorized push payment fraud breaks the fraud stack that was built around a single question, is this actually our customer, and why scam detection behavioral signals require a completely different approach
  • The scam intervention banking framework I used as a practitioner, including targeted friction, cooling off periods, and the phrase I call my mic drop moment
  • How I approach fraud executive communication and fraud program advocacy when leadership sees losses on a dashboard and misses the fifteen million the team prevented
  • The fraud dashboard reporting model I want to see: attempted fraud, prevented fraud, actual loss, normalized against transaction volume or deposits, not just gross fraud losses
  • Why human in the loop fraud AI is not scalable and what human on the loop means for fraud team skill development right now
  • Where fraud program maturity actually stands based on the benchmarking work I have been doing, and why fraud teams are doing better than we give ourselves credit for

You should listen to this episode if you:

  • Are building or rebuilding a fraud program and want to hear how I actually approach it from the ground up, not a framework from a textbook but the real process I used as a practitioner
  • Have ever had to justify headcount, technology, or budget to a leadership team that does not fully understand what fraud prevention actually involves and want a model that makes the case with data
  • Work at a bank or credit union and are feeling the pressure of the shift from unauthorized fraud to authorized push payment fraud and scams and are not sure how to adapt your fraud stack
  • Want the fraud capacity planning model I built manually as a practitioner, the three-minute-per-alert calculation and the 40-hour week breakdown that finally got leadership to listen
  • Are trying to figure out where AI fits in your fraud program without losing the investigators you have spent years developing
  • Lead a fraud team and want to know where fraud program maturity actually stands based on the benchmarking work I have been doing across financial institutions
  • Have ever walked into a room of blank stares when you asked your team what is actually driving fraud losses and needed a better starting point for that conversation
Episode notes

A fraud program assessment when the team does not know what is wrong

Ask the questions that help understand the fraud mix, not just the fraud losses. Did the fraud mix change? Did losses move from card fraud into scams? Did a new digital product launch without telling the fraud team? Did transaction volume grow? Did alert volume grow faster than actual fraud? Did a control somewhere just shift fraud into another channel?

Most of the time, teams that are struggling cannot answer those questions. And if they could, they would not be in the hole they are in. That is not a criticism. It is a diagnostic. What I am looking for before I recommend anything is whether the fraud strategy actually reflects the fraud the institution is seeing today, not the fraud patterns from three, four, or five years ago when the rules were originally written.

The practitioner’s fraud capacity planning model

This is one of the frameworks I am most proud of, and I built it manually before AI could do it for me. The model starts with the simple question of how much time does your team spend per alert? Not an estimate. An actual measurement.

My team landed on three minutes as a compromise between quick alerts that resolved in under a minute and complex alerts that required five minutes of investigation. From there, I tracked how many alerts were worked, how many produced a case, how much time was spent per case investigation, how many phone calls the team took, how much time was spent on private messages and internal communication, how much time was spent with scam victims, and how much time was spent on process and procedure development.

When you calculate all of that against a 40-hour week and multiply it by the number of people on staff, the gaps appear immediately. I also built in annual professional training requirements, CPEs, and other obligations that most capacity models ignore. The result is a document that proves to executives not just that the team needs more resources, but exactly why, down to the hour. Fraud team leadership advocacy has to be data-driven. Saying we are overwhelmed is not enough. Showing the math is.

The fraud risk assessment framework

My position is that a fraud risk assessment is the most important thing a fraud program needs in order to advocate for what it requires. And most fraud risk assessments are done wrong.

The purpose is not to confirm that wire fraud is high risk. Anyone in the industry already knows that. The purpose is to answer four specific questions. Where are we exposed? How severe could that exposure be? What controls do we have and how effective are they? And what are we going to do about the residual risk?

That last question is where most assessments fall apart. If the assessment gets completed, assigned red, yellow, and green ratings, presented to a committee once a year, and nothing operational changes, the exercise accomplished nothing.

Inherent risk is the risk before you consider any controls. Residual risk is what remains after your controls are applied. The mistake most teams make is rating inherent risk based on historical losses. A lack of loss does not mean a lack of risk. It may mean your controls are working. It may also mean fraudsters have not found that weakness yet. My check fraud example makes this concrete. If every check your institution has ever taken was fraudulent and you had absolutely no controls, how exposed would you be per item? That is your inherent risk. Not your loss history.

Authorized push payment fraud breaks everything the fraud stack is built around

For years, my fraud infrastructure was built around the question is this actually our customer? Device, password, MFA, biometrics, IP address authentication all answer that question. Scams introduce a second question that authentication cannot answer, does our customer understand what they are doing? I can prove with near certainty that the customer initiated the transaction. That proves nothing about whether they initiated it because someone convinced them their money was in danger.

Scam detection behavioral signals work differently. Is this normal behavior for this customer? Is the destination new? Did they change contact information recently? Did they increase transfer limits? Did they add a new device? Did they move money between accounts immediately before the transaction? Are they draining an account they have spent twenty years building? Each signal alone may not mean much. Together they tell a story. And that story requires a completely different approach than the one I built around authentication.

Fraud executive communication and how AI can change fraud fighting

If the board only sees fraud losses, they are only seeing the failures. They need to see what the program is stopping. The fraud dashboard model I want includes attempted fraud, prevented fraud, and actual losses, all normalized against something meaningful like transaction volume, customer growth, or deposits. A two million dollar loss means something very different at a five hundred million dollar credit union than at a fifty billion dollar bank. Losses are easy to measure. Prevention is hard to measure. The dashboard has to show both or leadership is only seeing half the story.

I will be completely transparent. I do not have a definitive answer for how AI changes the fraud investigator role. What I do have is a clear direction. Human in the loop, where investigators review and validate every AI decision, is not scalable. Human on the loop, where my team governs the policy and oversight of AI systems rather than reviewing individual outputs, is where the role is heading. My advice for fraud teams is to start learning now. Identify what technology your program will likely need in two years and begin developing the skills that make investigators valuable in that environment. We cannot get to a preventative, proactive fraud approach as humans alone. We have to start pouring into our teams now so they are ready when that time comes.

Key takeaways
  • How to build a fraud program starts with understanding why losses are happening before assuming the answer is more technology or more headcount. The fraud mix, the alert volume, and the control placement all have to be understood before any solution is proposed.
  • My fraud capacity planning model starts with three minutes per alert and builds out a full 40-hour week picture that proves resource gaps to executives with data rather than frustration.
  • Inherent risk vs residual risk fraud is the most commonly misunderstood part of a fraud risk assessment. A lack of historical losses does not mean a lack of inherent risk. It may mean controls are working or it may mean fraudsters have not found the weakness yet.
  • Fraud technology layering means understanding where each piece fits and how it integrates, not adding another tool every time something is not working. The fraud technology gap analysis that happens before a vendor demo is what separates effective layering from a medication stack with bad interactions.
  • Authorized push payment fraud requires a completely different question than unauthorized fraud. Authentication proves identity. It does not prove intent. Scam detection behavioral signals are what close that gap.
  • My fraud executive communication framework puts prevented fraud alongside actual losses, normalized against something meaningful like transaction volume. Leadership needs to see both numbers to understand what the program is actually doing.
  • Human on the loop is where fraud team skill development needs to point right now. Governing AI systems at the policy level is a different skill than reviewing individual alerts, and the time to develop that capability is now.
Final takeaway

Chen asked me hard questions in this one and I am glad he did. The conversation we ended up having is the one I wish more fraud leaders were having inside their organizations right now. How to build a fraud program is not a one-time exercise. It is a continuous process of assessing where you are, understanding what is driving your results, and making sure your strategy actually reflects the fraud you are seeing today and not the fraud you were seeing five years ago. If this conversation gave you one thing to bring back to your team this week, I hope it is the permission to slow down before you buy the next tool and ask whether you actually know what problem you are trying to solve.

If you want to hear me turn the tables on Chen, head over to The Saturday Fraud Strategist for the other half of this conversation.

Until next time, stay vigilant, stay informed, and keep moving fraud forward.

Connect with Chen Zamir | LinkedIn
Host of The Saturday Fraud Strategist
Helping fintechs build smarter fraud defenses
Co-author of “The Fraud Fighter’s AI Playbook”

Connect with Hailey Windham, CFCS | LinkedIn
Host of the Fraud Forward Podcast
Banking Community Lead at Sardine
Certified Financial Crimes Specialist (CFCS)
2023 Credit Union Rockstar, CU Magazine
Continuous Improvement Award, SAFE Federal Credit Union, 2023
Top 20 Professionals Under 40, The Sumter Item, 2022

Episode transcript
Chen Zamir
Chen Zamir
00:05
What's up, fraud fighters? I'm Hailey. No, you know what? I'm tired of this charade. Uh, the tokens cost me too much. Uh, being like a fake uh fake blonde with a fake southern accent. I cannot afford it any longer. And I want to admit it's been me all this time. Uh, Chen Zamir. No. Uh, just kidding. Hailey, it's so great to be uh on your show as a guest interviewer. How are you?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:34
I am doing so well and I'm I'm so glad that the the truth has finally come out and I mean come on.
Chen Zamir
Chen Zamir
00:40
Yes.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:41
It's really been you this entire time.
Chen Zamir
Chen Zamir
00:44
Yes. You know, well, uh I thought uh tokens would be cheaper than uh wigs, but apparently that's not the case. So, I'm done with that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:53
I'm just so glad you agreed to to come in on my podcast as well. We just uh recorded the reverse interview on yours and now we're kind of uh flipping the script again and letting you take the lead on the podcast on on Fraud Forward.
Chen Zamir
Chen Zamir
01:09
Yes, absolutely. And if you didn't catch uh the episode of the Saturday Fraud Strategist, uh Hailey and I spoke about why we're doing all of that. And that is because I'm actually not exactly sure when this episode is going to drop, but probably a couple of weeks after you're listening to this, we are heading to Vegas uh to participate in Money20/20. Hailey, do you want to uh uh give the juice about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
01:34
Yeah, I am so stoked. Um last year I went to Money20/20 and um I got lost everywhere I went in the Venetian. Um so I'm really excited to do that again. Uh but this year I will have a partner in crime. Chen Zamir and I will be at uh the Sardine booth. We will be recording podcasts throughout uh the the days um of Money 20/20. And we'll also just kind of be floating around having great conversations with people, hosting a happy hour or two. And I'm just I'm really excited and looking forward to to that time where we can meet in person um and then people can experience the magic of us uh live in in Vegas.
Chen Zamir
Chen Zamir
02:12
It's just me. We just said it. It's just me. There's no Yeah. Yeah. There's no Hailey.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
02:17
There is no Hailey.
Chen Zamir
Chen Zamir
02:23
Yeah. You know, it's a funny thing because I I was just trying to think. I was in in Money 20/20 Vegas once and in my mind it was always like around 2018 2019 and I couldn't quite recall. But one thing that I like that really stuck to my memory is that I remember staying uh back then uh at the Trump Tower and I remember that being like just before the elections and I said well that doesn't make sense because in 2018 2019 Trump was already president and I was like going through my through my uh phone pictures uh like the other day and I realized that actually I've been there in 2016. It was two months before the elections. Yeah. And actually that would mean that I'm now returning to Money 20/20 Vegas after a full decade. So that's a bit of a mindblower.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:16
Yeah.
Chen Zamir
Chen Zamir
03:17
Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:17
You're showing your age there.
Chen Zamir
Chen Zamir
03:20
Uh yeah. Yeah. Uh okay. First question. No. Okay. So I'm super stoked about uh by the way we will meet for the first time uh in person in Vegas. So I'm I'm yeah I'm really looking forward to it and and a bunch of other uh Sardine folks. So yeah I hope to see you all there. Um I want to go uh directly into the topics that I wanted to speak about today Hailey and you know uh I speak a lot about fraud strategy and somehow we never got to talk about it. So I like I'm super curious because you know I had a lot of different conversations with a lot of different folks when it comes to you know fraud strategy and especially when you go into like a new organization. And you've said both you know wearing a hat of a practitioner wearing the hat of a consultant wearing the hat of uh of now a vendor um and you you kind of like you know you need to quite quickly understand what's the what's the state. Uh what is going well and maybe where are the gaps and and and try to kind of like you know give advice or you know like give some guidelines or you know like make your plan as to how best to go about it. And when I talk to like fraud strategists I always hear different answers but around the same principle. So you know I I wanted to start with that and kind of like hear where you stand and how you work. So let's say for the manner of the example let's say that you're you know you're going into organization and an executive tells you look we've you know we've invested in fraud a lot. We've hired more folks. We integrated a couple of vendors. We've been fighting it for a year. We're pretty much at the same place. What how would you go about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
05:20
Well, I think it's a matter of obviously understanding where they are. You have to look at, you know, we're going to talk a little bit more about risk assessments, but trying to understand fully holistically, right? What they have, what products and services they have, where their exposure could be. I'd also want to ask like if if nothing has changed or if if losses are increasing, right, and and your teams are overwhelmed and it's like do we throw more resources at it? Do we throw more money at tech? But I don't think that's where we need to do. That's what we need to do. I, you know, I I would never immediately assume that any organization needs another tool or another person. I want to understand what's driving whatever fraud increase that they may have. You know, did the the did the fraud mix change? Did losses move from card fraud into scams? Did a new digital product launch that you didn't tell your fraud team about? Did transaction volume grow? That never happens, right? Um,
Chen Zamir
Chen Zamir
06:17
Never.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
06:18
Did alert volume grow faster than like actual fraud? Did we introduce a control somewhere that just shifted fraud into another channel? Because that happens a lot too. Then I want to, you know, look at the program from different angles that from risk from people, process, technology, and data. A lot of organizations start with technology because that's the easiest thing to point to. We're losing money so we need a better fraud tool maybe. Or maybe the tool is generating perfectly good alerts and you don't have enough people to work them. Maybe you have enough people but they're spending 70% of their time clearing false positives. Maybe your rules were designed around fraud patterns from three, four, five, 10 years ago, right? And and maybe nobody has stepped up and asked whether your fraud strategy actually reflects the fraud that you're seeing today. And that's where I think, you know, good risk assessment becomes incredibly valuable.
Chen Zamir
Chen Zamir
07:15
You know my like I agree 100% with everything that you said. I would say that my general experience is that when you ask these smart questions to a team that is struggling usually the answers would be I don't know. Or the answer the singular answer would be I don't know because if they would be able to answer these questions most likely they wouldn't be in that hole. So, you know, what do you do in, you know, in this instance where, and I'm guessing that, you know, maybe maybe some of our listeners right now, you know, also have exactly the same thing that, you know, they they see the pressure, but they don't necessarily have the ability to really understand exactly what's going on. How like what would be the best piece of advice to such teams
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:05
In regards to like pressure testing?
Chen Zamir
Chen Zamir
08:08
Not necessarily pressure testing, but like you know, let's say, you know, they see that their fraud rates are up, but they don't necessarily know how many false positives they have. They don't necessarily know from which flow it arrives. They don't necessarily know, you know, how much of that was missed by the investigators versus how much of that was missed by rules. So because usually if you know if if they would have the foresight to ask and answer these questions usually they would also be able to kind of like optimize around these things. So what happens in the case where you know you you just get blank stares when you ask these kind of questions which which I'm guessing happens from time to time.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:51
Oh it definitely happens from time to time. That's why I always uh I think culture matters so much in whatever organization you're at. For me, whenever I was a practitioner, it was I didn't understand not only the infrastructure because I was new coming into that role to build a fraud program. So, I didn't understand the infrastructure completely for the organization, but I also didn't know anyone really in the organization. But they knew that I was the girl that was going to stop transactions because I was in fraud. So, I was going to implement rules. I was going to create processes that just made everyone hate their lives. Um, and I was basically going to come in like a bull in a china shop. It was the perceived uh notion of of what I was doing there, what my role was. So instead, I focused on number one making friends in the organization. And I don't mean by offering to take them out to lunch, but I mean by truly sitting down with the the workers. So, I would go to e-services and instead of going directly to the director, I went to the people hitting the button every day, the ones that were working in PIK um which was our um basically a digital channel for like check deposits um and they and ATM deposits. And so I went and sat with them and I said, "Hey, explain this process to me." And when they saw that I was somebody that actually wanted to not only understand the process first, but then help and make sure that we're creating process efficiencies as well. Which is what I think works really well for fraud uh programs. Anyways, if you kind of structure yourself with that operational hat in which the benchmark report that we have coming out um hopefully this week, hopefully it will be live before this uh this recording comes out. But what you'll see in in the benchmarking is that a lot of fraud professionals and financial institutions came from the operations uh department or operations side of the organization which is a great thing because they understand the payment method. They understand where in our infrastructure is the last point of interception before the fraud leaves right where's our last point of contact where we can say okay we don't want this to happen. So anyways, whenever you're you're going in and you're understanding the infrastructure, you're creating process efficiencies before you even look to say, "Hey, what things do we need to implement to prevent fraud?" That's where you're going to see a lot of good things happen for your organization as a whole. When it comes to preventing fraud, it's developing that culture and making sure that you understand the process yourself before trying to implement any kind of changes, even new tech. You know, you don't want to do that until you fully understand the tech that you currently have.
Chen Zamir
Chen Zamir
11:19
Yeah, I love that because it, you know, goes to show that, you know, nothing beats data and if you don't have data, nothing beats leg work, right? So,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:29
Yeah, and I think I hope I answered that question for you.
Chen Zamir
Chen Zamir
11:33
No, no, definitely. Definitely. I think cuz in the end you you need to get this data right uh and going to the source, you know, in these kind of situations there there's nothing that can really replace that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:45
Yeah.
Chen Zamir
Chen Zamir
11:46
And it takes time and effort, but it is what it is. Um I wonder you know we talked a lot about uh data and the product and the operations or processes side. I wonder when it comes to the organization itself what do you think like how do you how do you assess the organization itself? How it's built? How it is you know accounting for ownership? How it is measured? Um how um you know what kind of skill sets or how do you do hiring or train like how do you look at the organizational piece when it comes to fraud strategy is it part of fraud strategy in your mind or is it something completely different
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
12:31
No 100% I think also you have to answer the question are you a centralized fraud program or a decentralized fraud program. Centralized is all the fraud comes to you you handle all the disputes all the chargebacks everything like that that comes directly through you where decentralized is you're kind of sitting as this advisory level of here's how we should here's how I would here's what I'm learning from the industry and where we can improve this particular fraud scenario. Right? Or or however it happens in your organization. Um and once you have that answer then it makes it easier for you to basically figure out where where you are. If you're looking at um your staffing your current staffing you can't just say, "Hey, I need another fraud analyst." That's not going to work. You have to show the the data for why you need another analyst. Do a capacity planning model. What I did, um, and this was a very manual process back in my day before, um, before we had AI that could do these things for us, and which most organizations won't really allow you to, um, implement these things right now. Anyways, um what I would do is I literally pulled all of our alerts and I would say, "Okay, how often or how much time are you spending per alert?" And we came up with an average minute time frame. So, some some alerts you could go through really quickly, but be within a minute. There were others that you had to actually dive in and look at and they'd be five minutes. So, we came to a compromise of three minutes and we would go through and we'd see how many alerts we had, how many that were worked, right? And then we would compare that and put it in a timestamp of okay, we have 40 hours a week. Here's how much time is allocated to these alerts. Here's how many of those alerts actually produced a case. By the way, case investigation, how much time are we spending per case investigation? Then you have to consider how many phone calls are we getting each each month? How or week? Um how many uh times are we getting a private message on whether it's Teams or Slack or whatever your organization is using. How much time is spent answering those? How much time is spent on a phone call with a victim trying to deescalate a situation and talk them down? How much time is spent developing processes and procedures? And whenever you calculate all of those things and you put it in a 40-hour week and you times it by however many people you have on your staff, you quickly find out, hey, we're we we've got some big gaps here. If we don't fill it, this is how we can prove that. We also did it. We also included like our professional training. So if you're required to have a certain number of CPEs a year, we we did it as an annual total, not just a weekly total. But we're able to then prove to executives that even these things that we have to have factor into how much time is needed because we can't just assume, hey, guess what? We can turn on this new alert, but how many alerts is that going to create for your team to work? Run a test first. See how many if you're cutting it on, if it's got a particular parameter that you're wanting to use, go ahead and let that test run and see how many would have alerted. Check to make sure you have the capacity to fill that in before turning it on. Otherwise, you're just creating more um more instances where you are going to be drowning and it's because of your own demise.
Chen Zamir
Chen Zamir
15:46
Yeah, I love it how again it all comes back to you know how you can quantify different facets of your program whether these are the processes, the organization, uh the technology. And what I love about it is that you know it makes our domain right at least when you approach it in the right way. It makes it very unemotional right I mean there are no opinions here it's just you know what the data tells us and what we want to or how do we want to react to that? Uh and and I really like this approach. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
16:24
Yeah, I I will say I love that you mentioned the opinion aspect. Um one of the things that I struggled with when building my fraud risk assessment, I was trying to understand it. I would go back to my risk officer, which she wasn't a lot of help. So I had to go to one of the associations and found me the most amazing mentor um who guided me through what a fraud risk assessment is. And one of my main questions that I brought up to my chief risk officer at the time was, okay, here's a here's a part on our risk assessment that says, um, the board receives fraud training. Well, the answer to that is yes, they do, but is it effective fraud training and how could I quantify what it was or or how effective it was or not? And so, for my opinion, and my opinion was a a selfish one at the time, I'll be honest with you. I was like, well, I'm not giving the fraud training, so clearly it must be subpar, right? No one can teach fraud like I can. Um, I know not in my organization. So, whoever is conducting that fraud training in my organization, they're not the fraud expert. They didn't even ask me to input into the fraud training. So, for me, I said, I haven't seen it. I don't think it's adequate because I haven't seen it and you're not showing me. But that was more of an opinion based on something that I didn't truly know. The question was, does the board receive fraud training? And the answer is yes. There are ways that we could improve, but again, the way that we would say, "Hey, it's not effective at all right now," is if people on the board were falling for fraud scams, they were mixed up in something um that you know, maybe it was some insider issues. Which I just reported on the Monday uh Fraud Fix newsletter where there was an instance where there was a board member who did misappropriate funds. Um, but if that situation wasn't happening in my organization, then I needed to say accurately that yes, there was fraud training and yes, it currently is effective. I couldn't use my opinion. I had to go off of the facts. And that was that was really hard for me because I knew in my heart of hearts I was like, but it could be better. And so I just used that, you know, residual risk response was board currently receives it. However, it's not given by the fraud leader of the organization. Um and there's no um uh there's no insights that are being provided by the fraud leader either. So this is a a situation that it could be improved.
Chen Zamir
Chen Zamir
18:50
You know, I I can relate so much to to what you just said. I think you know what like if you ever worked with me uh you know that you know I'm not uh I don't have the smallest ego in the world. Uh and when when it's like your team, when it's your organization, when you are the one building it, it's like it is very hard to separate your ego from the data that you're there. There are always like, you know, ways to tell stories with data and there are always ways to add these caveats and asterisks and say, "Yeah, the data shows XYZ, but actually ABC." Um, and honestly, this is a bit what I like about coming like into an organization from the outside where where I have no stakes is that it allows me to be like much more um, you know, impartial, but it also, you know, like I can definitely understand why people get defensive uh about these things. So, I I I really related uh uh to this to that story of yours. Tell me a bit. I know maybe that is something that you know would be like learning the ABC for you and your audience but I'm not you know I didn't grow up in uh in banking I grew up in fintech. And it it smells to me like fraud risk assessment is a loaded term that's an actual kind of like you know like a a specific process a specific artifact. What is it and and you know how would you approach a fraud risk assessment today knowing what you know and with your experience that maybe you haven't done the same when you just started.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
20:36
I I love that you asked this question. Um and I actually I have to tell you a funny story and then I'll answer your question. Um I did a presentation on fraud risk assessments um early this year. And um our our really good friend Eduardo I sent him the presentation to just review the slides. And he asked me he goes why would anybody want to do a fraud risk assessment? Now in my mind I was like what do you mean why wouldn't they want to do one? And the fraud risk assessment is the most important thing that you need for your fraud program in order to advocate for things that you need. And I went on this big passionate tangent with him and He goes, "Hailey, I was asking because you didn't answer that in the slides." He was like, "I'm not saying that they're not important. I just needed you to answer it in the slides." And I was like, "Oh, okay. I thought you were saying why would I present on fraud risk assessments when clearly it's the most important thing you could do." So, I I just wanted to share that little caveat. Whenever you asked that just now, it just reminded me of that. Um so for for like the general right a fraud risk assessment should not just tell you know you that you a particular fraud or payment type is is a high-risk fraud. Um you know for example wire fraud is high risk and debit card fraud is high risk. I can uh probably tell you that without spending three months building a a spreadsheet I could tell you that yes debit card fraud is is high risk. Right? I don't have to that's not the purpose of it. The purpose is not to say yes, this is a high-risk item. We know that. But what a fraud risk assessment should answer is where are we exposed? How severe could that exposure be? What controls do we have? How effective are those controls? Where is the residual risk? And and what are we going to do about it? That last question is where I think a lot of fraud risk assessments fall apart. You know, if we complete a fraud risk assessment, assign everything a a red, yellow, or green box, present it to a committee once a year, and nothing operational changes afterwards, then I'm not sure what you accomplish with that. But the assessment should influence where you're spending money, where you're adding controls, where you're monitoring more closely, and where you're accepting risk, and where you're putting people. So, you know, we there's a challenge that I would say, you know, we haven't experienced much fraud in this channel. So, we've rated the inherent risk as low. That's one of the biggest mistakes you can make. Inherent risk is the risk before you consider your controls. So, whenever you think about like check fraud, right? You're going to say, "Well, check fraud, we've done a great job and blah blah blah." No. Look at each check and that you've taken in that's fraudulent or taken in in general. What happens if that check was fraudulent? How exposed would you be if you had absolutely no controls? And you're doing this per scenario, not per uh product. And and that was another thing that I had to learn too because I was looking at like our check fraud losses in general. That doesn't work. You have to look per item, right? A lack of loss doesn't automatically mean that it's a a lack of risk. So maybe you haven't experienced losses uh precisely because your controls are working or maybe fraudsters simply haven't found that weakness yet. Um, but I want to look at things like transaction volume, dollar exposure, customer behavior, uh, product design, speed of funds, movement, authentication methods, external thread intelligence, and what we're seeing across the industry. Historical losses and is an input, but it cannot be the entire risk assessment. Otherwise, we're essentially saying, you know, nothing bad has happened yet, so we're fine. That that's not risk management. We have to look at it holistically. Look to see, okay, here's where we have a gap in our current process. This is something that that would help us going forward if we were to get and that's how you respond back with that residual risk, right? So the inherent risk is how big of a risk it is without any controls. You put your control effectiveness and then that uh residual risk is what you end up with. Um, so it's a really fun exercise for you to do to truly understand where you're where you are exposed, how well a product is performing. And that's the other thing people think that fraud risk and fraud reporting is just telling the bad story. It's like, all right, here's the we know this is where we're going to get our our deep minus, right? This is where we're going to look and see, oh, well, fraud happened. We don't want to ever read this part of the report. No, you've got to show the positive things that happened in it. How well are these controls working? We can see it monthly on our fraud report, but in this annual risk report, we're looking and saying, "Hey, okay, overall, our controls are doing a good job. They could be better, and here's how we how we can make those better, or here's here's where we need additional resource. Here's where we need another tool or something." But you can't automatically say it without providing that backup data.
Chen Zamir
Chen Zamir
25:27
Yeah. So, good. I mean it's uh it's such a great piece of advice and I think uh you know because again that maybe we use different terms but the principles are are the same. Uh many fraud teams that I encounter really fall in this trap of thinking that you know if we're good on this side it will continue to be good forever. Uh and we should not worry about it we should not pay attention. Uh and so on and in reality actually a lot of the times when you have these loss spikes a lot of the times they would come exactly from these points because like the the fronts that you usually pay attention to are also, you know, the fronts where it's harder to surprise you. Uh the fronts where you invested more, uh the fronts where you catch uh loss spikes earlier. And actually, it's the neglected parts of your system, the ones that usually are neglected because you think they are working well that you know many times end up uh biting you on your backside. So yeah, I think that's a great great great piece of advice. I want to circle back to you mentioned a couple of times technology. I kind of like, you know, got the sense in between the lines that you don't see technology as really a solution to fraud strategy gaps. That's that's the the sense that I got. Uh tell me tell me more.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
26:57
Uh yes, I I don't think that a solution is is always the the answer. I don't think that it's always that you have to buy a new technology. And I say that while working for a fraud technology company, uh technology can dramatically improve a strong fraud program. It can also help expose where a program is weak. What it cannot do is magically fix a strategy that doesn't understand the problem that it's trying to solve. You can buy the best fraud platform in the world and still have bad outcomes if your data is poor, your processes are broken, nobody owns the strategy, or your teams don't understand the tool, or you're measuring the wrong items. One of the questions I think every institution should answer before another vendor vendor demo is what problem are we actually trying to solve? Not oh god we need AI. Not hey we need we need real-time fraud detection. What is the problem? Is it account opening fraud? Is it scams? Is it checks, mules, alert volume? You know investigator efficiencies, false positives, data fragmentation. Those are very different problems. But I think like to answer the the other question right of like when does technology actually solve the problem. I think that's when you clearly connect the capability of that technology to the problem. If if analysts spend hours moving between five systems to investigate one case, technology may absolutely solve that. Right. Um I I've seen it myself Money 20/20 last year. I was very excited about Sardine's uh platform where the OSINT was available within the platform. That's the case management. That's something that I didn't have before and something that I struggled with our um chief information officer where or I couldn't go into, you know, the Google searches and and whatnot to use for my case data um and for my investigation. And so having that availability within that, yeah, that's that's a scenario where technology can solve it. If you're missing fraud because your current system can't connect signals across channels, technology could absolutely solve that. If you're generating 50,000 alerts and 49,000 of those are garbage, technology and better modeling may solve that. Yeah, it's so true. Um, if you have no fraud governance, no documented strategy, and nobody can tell me what the institution's highest fraud risk are, buying tool number seven probably isn't going to fix it. I heard um at a fraud conference that we misunderstand what layering is with our technology. Um layering doesn't mean that we simply add another and another and another. It means truly understanding where it fits where your technology piece is. And if a technology isn't working, you don't just buy one to to fix it. I think about um there was a probably I think it's Criminal Minds or NCIS, one of those uh shows where you dive into fraud, right? Or or dive into some kind of criminal case. And they the woman was she started with high blood pressure, took a high blood pressure pill, it caused her to have something else wrong, so she took another pill. Well, that caused another symptom, so she took another pill. And before long, she was taking like 12 pills a day and they were all doing something together that they didn't need to do. And it caused her to have kind of like this mental breakdown, which I feel like that's where we are with our our fraud technology is we just want to keep layering and layering and layering. But that's not what really layering is. Layering doesn't mean we're just adding more. Layering means that we have to understand where it all fits in the overall infrastructure and how well it integrates into those systems and communicates into those systems.
Chen Zamir
Chen Zamir
30:35
Do you can we can we like go one well layer deeper? Uh like I I think this is this is a very very important point. Can you maybe give like a concrete example of how you've seen layering done right in you know in a fraud stack context and you know what were the principles behind that? I think like hearing about that in a bit more detail would be like very enlightening.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
31:05
Yeah, absolutely. So we had a scenario with this was real time uh for us we did for those ATM and mobile banking deposits right we thought okay well we need to add in another product to prevent the fraud right now because what we're using that integrates with our core it's not exactly catching it in real time we're having to do all of this in batch processing. Okay. Well, that wasn't going to work in order to keep us in that proactive preventative fraud strategy, right? So, what we needed to do was first understand where the gaps were potentially within our current integration. Is there something that we're missing? Is there a plug that didn't happen? Is there a scenario where if we just had this one department connect this one piece of the data in, could we then turn this into real time? And by doing so, then do we need another layered partner or could we now allow for additional types of fraud to go through that we could stop? Meaning, could we increase our limit? So instead of saying okay the only capability we have right now is that we can look at one check per account per day and and that's how we can prevent fraud is just by signaling that one. No we can say they could do 10 and we can trust it because we know we're going to use check 21 return data. We're going to use image data analysis and we're going to compare it to all other deposits that have been made into this account. An example of how we would use this. Think about like lawn care companies that are using like they are DBA accounts. So doing business as it's a person's account that's it's tied to their social. They don't necessarily have a business account, but they're doing a side hustle. This is a a DBA lawn care service. When they get paid, they get paid on uh at the end of the week. They get, you know, five checks from different people. We know that any other consumer account we're going to look at and we're going to say I don't know if I trust that. This is this is odd. Why are we depositing so many checks on on this day for odd amounts? Like that doesn't make sense. We want to see how it ties in. And then being able to look at the account overall holistically. We're going to pull data not just from the checks, not just from check 21 return data. We're going to look at the core. We're going to look to see how they're onboarding for their online banking. Is it new? Can we see all of that in one thing? Can we get that holistic picture from one system versus having to go to three different systems in order to get that view? So, that's where for me that I've seen layering work. It's where we are combining it all into one platform versus having layered uh tech stacks that we have to go into the different tech systems in order to to get that full holistic understanding within an investigation. I hope that answered. I know I was kind of long long winded.
Chen Zamir
Chen Zamir
34:00
Yeah. No, no, no. That that was great. I think I mean it exemplifies the fact that actually, you know, going back to like entire theme is technology, you know, part of uh fraud strategy. Is it a tool? Is it a strategy? And I think that it really exemplifies this this example that you gave how much it's not about okay we need capability X. But it is really about doing a gap analysis of your own stack and understand which data points are missing. And are they missing in real time, or are they missing in core, or are they missing wherever. And what vendor can we find that can specifically solve this gap? And how we can weave that into our existing fraud stack? And many times that requires I mean first of of all, it it makes you ask very pointed, very smart questions when you do vendor assessment. And B, it also Go ahead. Go ahead.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
34:56
I was just going to say, yeah, I I think that it's really important too to understand that a good technology partner should be willing to understand your product, your problem before telling you how their product is the answer. They should understand, you know, if if we're talking specifically about bankers, right? They should understand banking operations. They should understand that fraud doesn't live neatly inside one channel. They should understand or they should be able to help you understand your data. Um should be transparent about what their technology can and cannot do. Um and then most importantly, the relationship shouldn't end when that contract is signed. Fraud changes constantly. Your technology partner should be able to help you adapt with it.
Chen Zamir
Chen Zamir
35:40
Yeah, I I absolutely agree. And I think it goes back to like you know the general theme of you cannot really take any shortcuts here. And throwing money at the problem whether this is more technology or whether this is more people in most cases in vast majority of cases would not do much. And you need to do the leg work, you need really to understand what is it that you need. So yeah I agree with this so much I want to ask you all of this sounds pretty straightforward and if you've been in fraud for a few years. Hopefully, you are familiar with these principles. And yeah, you can always learn and get better. But generally speaking, I think it is pretty straightforward. But in the last few years, we are, you know, we are faced with scams. And I think scams more so than the insane spike in losses that we're experiencing since 2022, 2023, it puts a whole different pressure on your fraud stack. It puts a whole different pressure on your fraud strategy. Let's start with why. How come? Like how like why are scams so difficult to deal with?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
36:48
Well, I think it's because um first of all, I'm I'm going to call you out because yeah, I gave you all the hard questions and now you're giving them back to me. So, I appreciate this. Um, I I think that you hit the nail on the head that, you know, this is one of the biggest changes and challenges that fraud programs are are having to make within their um, you know, fraud programs. For years, so much of our fraud infrastructure was built around answering just one question. Is this actually our customer? So, we've got device, password, MFA, biometrics, IP address authentication. Those things still matter tremendously. The problem is that scams introduce another question. Does our customer understand what they're doing? Those are completely different problems. A customer can authenticate perfectly and still be sitting on the phone with someone pretending to be, you know, uh the bank, uh law enforcement, Microsoft, the their grandchild or an investment adviser. The bank can prove with almost complete certainty that you know Haley initiated the transaction, but that doesn't tell you whether Hailey initiated it because somebody convinced her that her money was in danger. So what changes, right? We have to start layering intent and behavior context on top of identity. Is this normal behavior for this customer? Is the destination new? Did they suddenly change contact information? Did they increase limits? Transfer limits. Did they add a new device? Did they move money between accounts immediately before the transaction? Um, you know, are they even draining the account that they've spent 20 years building? Each signal by itself may not mean much, but together they tell a story. And that is where fraud teams have to get much better at looking beyond uh whether an authentication event passed. What? And and then the other thing that we struggle with is what if the customer is insisting this is where it can get really difficult. Uh you cannot completely eliminate scams without creating an incredible amount of friction for legitimate customers. There's always going to be tension between customer autonomy and protecting someone who may be under manipulation. I think the answer is a thoughtful intervention. Someone that or sometimes that means a a target targeted warning. Sometimes it means asking better questions. Sometimes it's a cooling off period. Sometimes it's escalating the transaction to someone trained specifically in scam intervention. And sometimes the customer is still going to say, "It's my money, send it." And then that's where my favorite quote comes in is, "We will not knowingly participate in fraudulent activity." Um, I used that line anytime I couldn't get through to a victim that was very insistent on sending the money. I when I would drop that line, it was it literally was a mic drop moment for me. Um, and and I hated to use it, but when I did, it gave them that cause for a pause that I've talked about before where if if you're trying to conduct a transaction, you've you've talked till you're blue in the face, your bank still won't do it. And then your bank looks at you and says, "We will not knowingly participate in fraudulent activity." you go, am I doing something I'm not supposed to be doing? Um, and when they're like, I'm not fraud. I I'm I know what I'm doing. This transaction follows a pattern of what we know to be fraud in the industry and in other accounts. We know this is fraud. We are not going to allow this to happen. Now, you can't stop them from getting the cash out because it's their money. They can come in and get it, but you can create some of that targeted friction where it's we want you to understand that as your financial institution, we believe this to be fraudulent because we've seen this pattern before. So, we're trying to do our part. Hopefully, whenever you go to leave and you're, you know, the difference between sending a $20,000 wire and walking out of the bank in 20 with $20,000 in cash, that does something to somebody. You know, it makes them pause and think.
Chen Zamir
Chen Zamir
40:49
Yeah, that's a it's a good one. Uh, for sure. I Yeah, I'm just thinking, you know, for us fraud fighters, you know, life would be so much simpler if there would just be no customers. I mean, maybe the business would not like it, but yeah, for us it it would be Yeah. A great a great day uh when businesses can make money without customers. Um,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
41:12
Yeah. Now, I will say though, I I want to make sure that it's clear. I'm I'm not saying that authentication is becoming less valuable. That that's not the case at all. Authentication answers a very important question of who is doing this. It just doesn't always answer why are they doing it. The mistake is treating successful authentication as proof of intent. And that's where we've got to get better.
Chen Zamir
Chen Zamir
41:36
That's exactly the point where I wanted to go next. I think I see it in FinTech. I definitely see it in banks. Uh I always call it this addiction. Addiction to a binary risk assessment. Either this user is authenticated and good or they are not and we cannot trust uh put our trust in them. And I think scams specifically, not only scams, I think like everything that has to do with, you know, digital banking and e-commerce, like it forces us to be much more mindful to how we manage risk. But scams specifically and you know, authentication is is is a big part of that. And you know the one of the main issues here is that up until scams exploded, our fraud stacks were really geared toward um preventing unauthorized use. But now it's no longer unauthorized, right? It's authorized when you know like stripping back everything that you just outlined to cafe core pillars. Now I'm this, you know, I'm this exact that uh that uh asked you that question at the the beginning of our conversation, but instead of thinking about kind of like unauthorized fraud, I'm thinking about scams from a fraud strategy perspective. What are the pillars that I need to be minded to when I'm suddenly like completely shifting my my view on what fraud is?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:08
So the pillars as in what an executive needs to understand or just like the fraud leader?
Chen Zamir
Chen Zamir
43:14
The fraud leader
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:15
I think the fraud leader has to understand uh truly. I've always said I'm going to treat every customer like my grandmother, how would I want them, how do I want them to treat her. But at the same time I have to think about the overall business of the organization as well. So I can't just be, the full heart of hearts, I'm going to give them back all the money they've lost to scams, because that's not a good business idea, right? Because then you're going to have the problem that I think we're going to start seeing if we do see that push for scam repayment um from organizations is that we're going to see a lot of the first party fraud that we see currently but they're just going to get the money back. Um I think that we have to look at holistically um for each pillar we have to think about the customer experience. We have to think about the loss of the organization. We have to think about where we can prevent it and where we can get in front of it. Where the only option is truly to just react. Um, and then how do we react? How do we respond? I think that response is the most important part of the the pillar for fraud fighting. It's not just how do you have a conversation with a victim. That's not that's not the only thing that response means, but it's what do we do when we've exposed a gap? How quickly are we responding to that? Do we wait until there's a really big fraud? I I struggled with that as a fraud practitioner because I wanted to go into an executive's office, grab him by both sides of his head, and just shake until he listened to me, right? But you can't do that. Um I I wanted to say, "Hey, we've got a really big exposure." And I did. I tried. I I would write it in memos, and I'd say, "If we don't put this in place right now, we're really exposed." An example was credit card um payments. If we allowed for a credit card payment to go through ACH, we have 60 days that that payment is a vulnerability for us. 60 days that we could have a response back of saying, "Hey, nope. They now say that those were unauthorized. We got to send them back. We have no recourse on that except to go after the individual person." Well, what if you find out that was a synthetic identity? Okay, great. So right now I or at that time I was like, "Hey, there's 60 days that if we're allowing a card to be maxed out, paid off, maxed out, paid off, maxed out, paid off, and they do this consistently two times a week." That and and it's a $10,000 limit. So that's $20,000 a week that we're exposed with one card. If we don't put this particular fraud thing in place, we're we're going to we're really exposed. And it was you got to take a loss before you can make any changes. And that to me was so crazy. And so we lost a hundred and something thousands with one account because that wasn't put in. Now when I wrote up the memo again to then say I told you so. I unfortunately couldn't say I told you so in the memo. I did I did however say on you know this date I advised that this was a potential vulnerability that we should put something in place at the time leadership decided it was not a a priority. Um since then this has happened. This is how we were exposed. This is the loss we're currently sitting at now. Then they took it seriously. So the response, you can't think of the response as just a how do we talk to people, but it's how are we going to respond when we've noticed a gap, when we've noticed that there's a potential vulnerability, how do we ensure that we get that message over to leadership that they are going to be receptive of it? And then how do we move ahead going forward? Again, it's all about that fraud strategy. I'm going to bring in some of your your strategy uh comments.
Chen Zamir
Chen Zamir
46:57
Um I I wonder you know specifically when it comes to scam I think one of the bigger challenges is exactly what you uh just described. Is that sometimes it's very hard to convince the business to do things that supposedly hurt the business performance specifically in scams. Because many times the uh report uh like reporting rate is lower than an unauthorized fraud, right? There's a much higher chance that I will file a charge like if someone stole my credit card than if someone fooled me to be like a handsome marine officer uh stationed in Iraq. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
47:34
Right
Chen Zamir
Chen Zamir
47:35
And I think one of the I mean I would guess that many of your conversations were actually internally not necessarily with leadership but with product folks. Because you know in the end you're not talking about a fraud account that you just block and no one cares about but this is a real customer. It's uh a a loyal customer and b so far a profitable customer and you know that even if you're right even if you are right and it is a scam there's a very high likelihood that the customer would never complain and there would never be a loss. And so it's very easy to product come to come and say you see nothing happened so you were wrong and we we shouldn't have uh put the friction in and so on. How do you manage these kind of conversations which are, you know, sometimes very very difficult and very nuanced.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
48:26
Yeah, I'd say that it starts there's two different ways that I approach it. One is obviously trying to sell the story of the the member or the customer friction. Like better be overprepared than underprepared. Um here's here's what this would look like if we took that loss. They're going to take the loss and then that's on us as their financial institution that we didn't do our part. Um so trying to tell that story. The other thing you mentioned was talking with the business unit owners. That was always a great way for me to get in in front of the executives um just through a third party. So I would go and I'd talk to the e-services director and I'd say, "Hey, this is where there's a potential gap. Your team doesn't like the current risk um analysis that's being performed. They don't trust it. Um they're doing manual reviews of this one parameter because again they don't understand what it means. Um, and so if we can adjust these parameters, give them those guidance, and then let executives say, "Yes, we will, we agree to take a loss, if it's $150 or less, they can automatically approve it. It'll be on us, and it won't count against them." That was a big win for that department that the next time I needed something or I saw a vulnerability, I could go directly to that business unit owner who had the ear of the COO and from there, we were able to make things happen. And it was it was a phenomenal experience. But it's all in how you have the conversation, how you're able to bring in different partners from the organization and allow them to also advocate for your program.
Chen Zamir
Chen Zamir
49:57
How do you, I mean I think this is honestly one of the aspects where I see a lot of fraud fighters struggle with. Because you know I think fraud fighters similarly to probably legal and probably to security are mostly the only functions in an organization that are you know that are the no sayers the nay sayers, right? The business excels marketing product operations customer service. Everybody's like geared towards growth and you know revenue and that's like in the end this is how you are measured. And fraud fraud fighters you know operate almost um it's not orthogonally it's yes it's it is orthogonally to the organization we care about losses supposedly. Um and and I see that many times there's a lot of frustration and a lot of incomprehension of how to even begin such conversations. How do like what's your best advice for fraud fighters that want to approach leadership teams and want to influence them to make a decision that they think is the right decision? How, what's your advice?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
51:16
First is to make sure that executives understand that fraud operations are not just a cost center. We are protecting customers, deposits, reputation, operational capacity, and sometimes people themselves from catastrophic financial harm. I I also think the leadership needs to understand capacity differently. If a fraud team says we're overwhelmed, the answer can't always be, we'll hire another investigator. Yeah, maybe we need another investigator, but also maybe our technology needs tuning. Maybe our processes are inefficient. Maybe we're generating unnecessary uh work upstream. Um or there's another department that's creating fraud exposure downstream. Capacity is is a symptom. I want to understand the the cause. Right? I think that the other thing um that I've learned from the benchmarking work that we've been doing is that fraud teams are doing a lot better than we sometimes give ourselves credit for. You know, we are doing formal fraud risk uh assessments. Institutions are tracking false positives. They are using riskbased queuing. They're investing in technology. There's a there's a level of maturity there that I don't think always gets recognized. Um at the same time, you have teams saying that they are at or beyond capacity. Scams continue again to be one of the biggest concerns. Many institutions still struggle to quantify scam losses accurately. You have fraud teams trying to tell their story to leadership while some of the most important work they do is incredibly difficult to put on a balance sheet. You know, if I stop a $100,000 fraud attempt, everybody agrees that is valuable. The problem is proving that the $100,000 would have actually left the institution without the intervention. You know, that creates like this weird problem where losses are easy to to measure and prevent um and prevention is is hard to measure.
Chen Zamir
Chen Zamir
53:09
Mhm.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:10
Then leadership looks at the fraud dashboard and sees $2 million in fraud losses. What they may not see is the $15 million the team prevented. Right.
Chen Zamir
Chen Zamir
53:20
So this needs to be exposed. You're saying?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:22
Yes. 100%.
Chen Zamir
Chen Zamir
53:23
In the dashboard. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:24
Yes.
Chen Zamir
Chen Zamir
53:25
Yeah. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:26
I I think in the dashboard, one of the things um like I'd want some version of a fraud exposure prevented alongside fraud losses incurred, right? No. And not just the gross fraud loss. Show me the attempted fraud. Show me the prevented fraud. Show me the actual loss. Then give me enough context to understand what happened. If the board only sees losses, we're only showing them the failures. They need to see what the program is stopping. Yes. I would also want that normalized against something meaningful like transaction volume, uh, customer growth, deposits, or whichever denominator makes sense for that institution. A $2 million loss means something very different at a $500 million credit union than it does at a $50 billion bank.
Chen Zamir
Chen Zamir
54:12
Yeah, 100%. I agree with that. I do want to challenge you on one thing. I think that today if you would come to a leadership team or to the board and it would say my investigators are overwhelmed. Their answer is unlikely to be hire another investigator. Their answer is likely to be fire them all and put a very cheap AI instead. What, like, that it works 24/7. Um, how would you like how would you manage this kind of challenge from the leadership team?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
54:45
That's one that I'm still working on. I'll I'll be just completely transparent with you. You and I were actually working on a really cool project that I'm so excited to dive into, and that's really understanding the AI concept of of what can be done. Where is the investigator and the analyst still very valuable to an organization? Bottom line is we will at some point have to implement some type of AI that can help our organization. Fraud is too fast. It it's constantly changing. It's constantly evolving. We're going to have to put something in place to help us. That that's inevitable. That that's happening. What I would say is, um, and one concept that I'm becoming really familiar with, is, you know, we've talked about, um, human feedback in the loop, where it's, we're looking and making sure that the alerts worked and that it scored it the way we wanted it to. That still is not scalable. Instead, we're going to have to start looking at human on the loop where it's policy and governance of that AI system how it's working. So, I'll say to answer your question right now, I can't give you a definitive of what would work in order to help you keep your entire team. What I will say is that if you can go ahead and start looking now at what tech you think you may need in two years, do it. Do the research now. Start looking to see where your team might be more valuable. Maybe they need to develop a new skill that helps them become that person on the loop. Help them now. Point them in the right direction now to keep them as a valuable member of your organization. If you don't want to see uh their growth, you don't need to be in leadership anyways. Um so maybe maybe maybe this isn't the right place for you. But if if you're going to make sure that number one, your team is scalable, that you're going to be able to keep up with tech, they've got to start learning now. They've got to start looking now. I was one of those. I'll be honest, when I was the credit union practitioner, I said, um, we're always going to need the fraud investigator. Yeah, to an extent, yes, that is true. But we are teaching AI to do things a lot faster. And our whole uh thing with fraud is that we want to get to this preventative, proactive fraud uh strategy. We can't do that alone as humans. We are just humans, right? AI and scams and fraud, they move a lot faster. Payments move faster. You know that whenever I get that card alert on my card, if I tried to spend $500 at Walmart and it says, "Hey, did you do this?" A human is not going to be able to do that at scale for all their customers. We have to have these programs and systems in place. And so I the the answer to it today, I can't give you the definitive answer that I would say, but I would say definitely start pouring into your team to allow them to be useful and valuable whenever uh that time comes.
Chen Zamir
Chen Zamir
57:32
Yeah. Well, I said earlier fraud strategies uh can be quite straightforward. Uh but even if it is straightforward, it's still shifting and changing uh because fraud is changing, because the technology is changing, because the business landscape and the products are changing. And so there are always this kind of like these new fronts uh these new uncharted waters that you need to well to chart basically and that's part of the part of the job to an extent. Uh that's why we're risk managers. Uh I always say Hailey, it's been such an interesting conversation. Uh it feels like on one hand we covered a lot of ground and on the other hand we just skimmed the surface. So I uh I definitely love to do that again sometime. Uh but for today I would say it's it's uh it's been a pleasure and I uh can't thank you enough for uh letting me take over the pod for an hour.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
58:31
Yeah, I I'm so stoked that you were able to to be here uh to take over and to allow me to sit in the uh practitioner chair or or the guest chair today. I have I found myself asking, man, I'm doing a lot of interviews, but I I feel like there's an opportunity here where I can provide a little bit more insight. Um so, this was a a great opportunity, and I I appreciate you more than you know.
Chen Zamir
Chen Zamir
59:00
Uh goes Same goes back to you. So, uh yeah, I uh we should definitely do it again.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:06
Yes, for sure. Okay, so I'll take the I'll take the microphone back as the host and just say fraud fighters, uh you know, if you want to hear me turn the tables on him, um head over to The Saturday Fraud Strategist um for the other part of this conversation where I was able to turn the tables on him. Um until next time, stay vigilant, stay informed, and keep moving Fraud Forward.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:33
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving Fraud Forward in your own organization. Until next time, stay curious, stay resilient, keep moving Fraud Forward