Fraud & AML/CFT
Fraud and AML/CFT live in the same decision surface. These essays cover layered controls, sanctions screening, chargebacks and the feedback loop that keeps them honest.
Shipped in this domain.
Merchant Onboarding + KYC/KYB Automation
Automated merchant onboarding pipeline, KYC/KYB, UBO discovery, sanctions and PEP screening, risk-tiered decisioning with full audit trail. Activation cut from weeks to hours; manual review load down 70%.
Fraud, Risk and AML/CFT Controls: Layered Decisioning at $1B+ GTV
Layered fraud, AML/CFT and sanctions decisioning built natively into the payments stack, vendor signals, device intelligence, internal velocity rules, SAR-ready audit trails. Fraud loss held <0.1% of GTV; fraud incidents down ~65%.
Daraz (Alibaba Group) Payment Operations Across Five Markets
Ran payment operations governance across five South Asian markets during a COVID-driven volume surge, coordinating settlement, disputes, fraud rules, reconciliation and COD-to-digital conversion.
Production GenAI at Simpaisa, 3 Systems and 1 Banking Pilot
Identified and value-modeled three production GenAI systems across merchant integration support, incident auto-escalation and partner support automation, plus a fraud/AML AI pilot with a major banking partner.
SWIFT MT/MX Implementation: ISO 20022 Migration + gpi at Simpaisa
Wired SWIFT MT and MX (ISO 20022) messaging into the Simpaisa cross-border stack with gpi tracking, CSP attestation and dual-rail parsing — sustained 99.9%+ message-acceptance rate through the ISO 20022 migration window.
Field notes for this hub.
FedNow Intermediary Banks Turn Cross-Border Into A Rulebook Problem
The Federal Reserve's Regulation J proposal for FedNow intermediaries is not just a cross-border growth story. It turns real-time domestic settlement, correspondent banking, sanctions screening, message design, and exception ownership into one operating model.
PSR APP Fraud Data Turns Reimbursement Into A Payments Control Loop
The PSR's latest APP fraud evidence moves beyond consumer-protection coverage. It turns Faster Payments reimbursement into a measurable operating loop across sending PSPs, receiving PSPs, Pay.UK, Confirmation of Payee, claim handling, scam-source data, and board-level fraud controls.
Marqeta and Riskified Move False Declines Into Issuer Controls
Marqeta and Riskified's issuer-risk integration is a card-programme signal: false declines are partly an issuer authorization problem. Issuers need merchant intelligence, rule feedback, override paths, and evidence that protects approvals without weakening fraud controls.
The Bank of England Just Turned Payment Vendor Risk Into a Programme Gate
The Bank of England's updated third-party and incident reporting framework turns payment-system vendor risk into a programme-delivery gate, not a procurement appendix.
DeepMind's AI Control Roadmap Is a Programme Gate
DeepMind's AI Control Roadmap is a delivery-governance signal: AI-agent programmes need gates for monitored coverage, recall, response time, authority boundaries, drills, and escalation ownership.
Mastercard's Scam Rules Move Fraud Into Acquirer Operations
Mastercard's scam-merchant monitoring shift is not just a fraud-rule update. It moves scam detection into acquirer and payment facilitator operations, where merchant onboarding, monitoring, dispute evidence, and shutdown authority have to work as one control loop.
Microsoft Project Perception Makes Security Agents an Operating Model
Agentic security is not a model launch. It is an operating model where signals, context, model routing, agent identity, permissions, actuators, and human control have to be designed as one system.
iDenfy Shows Card Verification Needs Its Own Risk Gate
Standalone card verification is not just a compliance widget. It is a risk gate that decides whether card ownership, identity evidence, account control, and onboarding policy are strong enough before money movement begins.
Agent Payment Guard Shows x402 Needs Pre-Payment Risk Gates
Agentic payments do not become safe because the payment rail works. They become safe when every agent payment has an approved mandate, bounded amount, trusted counterparty, and a pre-signing risk gate that can stop the transaction.
A SWIFT Compliance Checklist for Banks and Fintechs
A working checklist of the SWIFT compliance items that audits, sponsors, and regulators actually ask about.
Adyen's 3% Refund Signal: Fraud Controls Need a Lifecycle
Refund and policy abuse can come from verified customers. Payment teams need controls across account, order, fulfilment, refund, and dispute events.
GitHub Models Is Shutting Down. Your AI Stack Needs an Exit Plan
GitHub Models' shutdown is a useful warning: an AI prototype becomes an operational dependency faster than most teams build an exit path.
Forter Agents Show AI Risk Work Is Becoming Operational
Forter's agent launch and today's repo radar point to the same pattern: AI is moving from generic assistants into bounded workflows with data access, controls, and operating accountability.
Correspondent Banking and the Reality of Emerging-Market Corridors
De-risking did not reduce risk. It moved the risk to the corridors that need access most.
SWIFT, AML/CFT, and Sanctions Screening in Practice
Sanctions screening is where compliance theory meets throughput reality. The product decisions live in the list overlay, the matcher, and the review queue.
Sanctions Screening Without Killing Throughput
Sanctions screening is a latency problem and a false-positive problem dressed up as a compliance problem.
AML/CFT: Rules vs Models, and Why You Need Both
Rules are explainable and weak. Models are powerful and unexplainable. Production AML needs both, layered.
PCI DSS and ISO 27001 as Product Programs
PCI DSS and ISO 27001 are not paperwork projects. Run as product programs, they make the platform measurably stronger.
Chargebacks Are a Product Problem
A rising chargeback line is product debt that finance is paying. The fix is upstream.
Layered Fraud Controls in the Payments Stack
No single fraud control survives a determined attacker. Layered controls do, and they do it without crushing conversion.
The Risk-Adjusted Backlog: Prioritising Payment Products When Failure Costs Real Money
A payment roadmap cannot be ranked by revenue alone. The backlog has to price the cost of failure, the cost of delay and the cost of operating complexity.
Onboarding Conversion vs. Default Rate: The Real Tradeoff
Conversion and default rate are not enemies. They are two sides of the same product surface.
Risk Tiering Merchants Is a Product Decision
Tiering is the single most leveraged product decision in a payments platform. Most teams hand it to risk and never recover.
Agentic Payments Operations: What Works, What Is Theatre
Agentic AI can help payments operations when the task is bounded, observable and reversible. It becomes theatre when teams let agents improvise inside money movement.
Regulatory UX: Why the Name on a Payment Screen Can Block a Launch
Regulators do not read your roadmap. They read your screen.
Merchant Onboarding: Where Growth, Risk and Compliance Collide
Three teams own onboarding. The merchant only sees one experience. That gap is the product.
Compelling Evidence 3.0 (Visa): What Changed, and How To Actually Win Disputes Now
Compelling Evidence 3.0 is the most consequential dispute-rule change Visa has shipped in a decade. The mechanics look like a documentation update; the operating implication is a complete rework of how acquirers capture, store and present transaction evidence.
CSPO + RICE in Practice: A Real Payments Roadmap Walkthrough
RICE is a clean ranking framework that does not know payments exists. CSPO is a clean product mindset that does not know prioritisation maths. Put together, with a risk-adjusted overlay, they become a working operating system for a payments backlog. Here is the walkthrough.
How Credit Scoring Systems Actually Work: From Feature Pipeline to Bureau Reporting
Reaching for an off-the-shelf credit-scoring vendor is easy; the trap is stopping there. The vendor's output is a number. The substance an operator has to own is the pipeline that produces it, the governance that protects it, and the bureau reporting cycle that keeps it current.
Why AI / ML Solutions Fail In Production Payments: Seven Patterns I See Every Year
Most AI/ML projects in payments fail in production for reasons that have nothing to do with model accuracy. They fail because the team optimised for a leaderboard metric, the operating environment moved, the labels were wrong, or the audit cycle the model now lives inside was not part of the design. Seven patterns I see every year.
Where ML Beats AI: Six Payment Problems an LLM Cannot Touch
There is a quiet AI-in-fintech mistake teams keep making: reaching for an LLM the moment the word 'AI' shows up on the roadmap. Sometimes the right answer is a gradient-boosted tree and a clean feature pipeline. This is the operator's argument for the boring choice.
Product Management for Payments Platforms: What's Different, and What's Not
A payments PM is a SaaS PM with three extra constituencies and one extra reflex. Get the reflex wrong and the other constituencies stop trusting you.
GenAI in Fintech: 3 Production Systems and 1 Banking Pilot
Most fintech AI work in 2026 is still demos. Three of these use cases run in production; the fourth is a regulated banking pilot.
Project Management for Fintech Regulatory Programmes: PCI DSS, ISO 27001, SOC 2, AML/CFT
Six weeks before the audit, every troubled regulatory programme looks identical: forgotten Confluence pages, evidence requests rotting in inboxes, a year of work crammed into six weeks of theatre. Run it as delivery with an immovable deadline and an external grader, or pay remediation many times over.
AI Fraud Detection vs Rule Engines: A Field Comparison
ML catches novel attacks; rule engines win on explainability, ops cost, and the regulator conversation. In regulated payments the answer is a hybrid, and designing where each one fires is the whole job.