Topics
Fraud · AML

Fraud & AML/CFT

Fraud and AML/CFT live in the same decision surface. These essays cover layered controls, sanctions screening, chargebacks and the feedback loop that keeps them honest.

◆ Essays

Field notes for this hub.

35 essays
Aug 12, 20267 min read

FedNow Intermediary Banks Turn Cross-Border Into A Rulebook Problem

The Federal Reserve's Regulation J proposal for FedNow intermediaries is not just a cross-border growth story. It turns real-time domestic settlement, correspondent banking, sanctions screening, message design, and exception ownership into one operating model.

Aug 11, 20267 min read

PSR APP Fraud Data Turns Reimbursement Into A Payments Control Loop

The PSR's latest APP fraud evidence moves beyond consumer-protection coverage. It turns Faster Payments reimbursement into a measurable operating loop across sending PSPs, receiving PSPs, Pay.UK, Confirmation of Payee, claim handling, scam-source data, and board-level fraud controls.

Aug 10, 20267 min read

Marqeta and Riskified Move False Declines Into Issuer Controls

Marqeta and Riskified's issuer-risk integration is a card-programme signal: false declines are partly an issuer authorization problem. Issuers need merchant intelligence, rule feedback, override paths, and evidence that protects approvals without weakening fraud controls.

Aug 9, 20267 min read

The Bank of England Just Turned Payment Vendor Risk Into a Programme Gate

The Bank of England's updated third-party and incident reporting framework turns payment-system vendor risk into a programme-delivery gate, not a procurement appendix.

Aug 5, 20267 min read

DeepMind's AI Control Roadmap Is a Programme Gate

DeepMind's AI Control Roadmap is a delivery-governance signal: AI-agent programmes need gates for monitored coverage, recall, response time, authority boundaries, drills, and escalation ownership.

Aug 1, 20267 min read

Mastercard's Scam Rules Move Fraud Into Acquirer Operations

Mastercard's scam-merchant monitoring shift is not just a fraud-rule update. It moves scam detection into acquirer and payment facilitator operations, where merchant onboarding, monitoring, dispute evidence, and shutdown authority have to work as one control loop.

Jul 28, 20267 min read

Microsoft Project Perception Makes Security Agents an Operating Model

Agentic security is not a model launch. It is an operating model where signals, context, model routing, agent identity, permissions, actuators, and human control have to be designed as one system.

Jul 27, 20267 min read

iDenfy Shows Card Verification Needs Its Own Risk Gate

Standalone card verification is not just a compliance widget. It is a risk gate that decides whether card ownership, identity evidence, account control, and onboarding policy are strong enough before money movement begins.

Jul 22, 20267 min read

Agent Payment Guard Shows x402 Needs Pre-Payment Risk Gates

Agentic payments do not become safe because the payment rail works. They become safe when every agent payment has an approved mandate, bounded amount, trusted counterparty, and a pre-signing risk gate that can stop the transaction.

Jul 17, 20267 min read

A SWIFT Compliance Checklist for Banks and Fintechs

A working checklist of the SWIFT compliance items that audits, sponsors, and regulators actually ask about.

Jul 4, 20267 min read

Adyen's 3% Refund Signal: Fraud Controls Need a Lifecycle

Refund and policy abuse can come from verified customers. Payment teams need controls across account, order, fulfilment, refund, and dispute events.

Jul 2, 20267 min read

GitHub Models Is Shutting Down. Your AI Stack Needs an Exit Plan

GitHub Models' shutdown is a useful warning: an AI prototype becomes an operational dependency faster than most teams build an exit path.

Jun 26, 20268 min read

Forter Agents Show AI Risk Work Is Becoming Operational

Forter's agent launch and today's repo radar point to the same pattern: AI is moving from generic assistants into bounded workflows with data access, controls, and operating accountability.

Jun 19, 20269 min read

Correspondent Banking and the Reality of Emerging-Market Corridors

De-risking did not reduce risk. It moved the risk to the corridors that need access most.

Jun 12, 20269 min read

SWIFT, AML/CFT, and Sanctions Screening in Practice

Sanctions screening is where compliance theory meets throughput reality. The product decisions live in the list overlay, the matcher, and the review queue.

Jun 1, 20268 min read

Sanctions Screening Without Killing Throughput

Sanctions screening is a latency problem and a false-positive problem dressed up as a compliance problem.

May 31, 20269 min read

AML/CFT: Rules vs Models, and Why You Need Both

Rules are explainable and weak. Models are powerful and unexplainable. Production AML needs both, layered.

May 30, 202610 min read

PCI DSS and ISO 27001 as Product Programs

PCI DSS and ISO 27001 are not paperwork projects. Run as product programs, they make the platform measurably stronger.

May 29, 20268 min read

Chargebacks Are a Product Problem

A rising chargeback line is product debt that finance is paying. The fix is upstream.

May 28, 20269 min read

Layered Fraud Controls in the Payments Stack

No single fraud control survives a determined attacker. Layered controls do, and they do it without crushing conversion.

May 28, 20269 min read

The Risk-Adjusted Backlog: Prioritising Payment Products When Failure Costs Real Money

A payment roadmap cannot be ranked by revenue alone. The backlog has to price the cost of failure, the cost of delay and the cost of operating complexity.

May 26, 20268 min read

Onboarding Conversion vs. Default Rate: The Real Tradeoff

Conversion and default rate are not enemies. They are two sides of the same product surface.

May 25, 20268 min read

Risk Tiering Merchants Is a Product Decision

Tiering is the single most leveraged product decision in a payments platform. Most teams hand it to risk and never recover.

May 24, 20269 min read

Agentic Payments Operations: What Works, What Is Theatre

Agentic AI can help payments operations when the task is bounded, observable and reversible. It becomes theatre when teams let agents improvise inside money movement.

May 23, 20269 min read

Regulatory UX: Why the Name on a Payment Screen Can Block a Launch

Regulators do not read your roadmap. They read your screen.

May 22, 202610 min read

Merchant Onboarding: Where Growth, Risk and Compliance Collide

Three teams own onboarding. The merchant only sees one experience. That gap is the product.

May 20, 202611 min read

Compelling Evidence 3.0 (Visa): What Changed, and How To Actually Win Disputes Now

Compelling Evidence 3.0 is the most consequential dispute-rule change Visa has shipped in a decade. The mechanics look like a documentation update; the operating implication is a complete rework of how acquirers capture, store and present transaction evidence.

May 20, 202612 min read

CSPO + RICE in Practice: A Real Payments Roadmap Walkthrough

RICE is a clean ranking framework that does not know payments exists. CSPO is a clean product mindset that does not know prioritisation maths. Put together, with a risk-adjusted overlay, they become a working operating system for a payments backlog. Here is the walkthrough.

May 20, 202612 min read

How Credit Scoring Systems Actually Work: From Feature Pipeline to Bureau Reporting

Reaching for an off-the-shelf credit-scoring vendor is easy; the trap is stopping there. The vendor's output is a number. The substance an operator has to own is the pipeline that produces it, the governance that protects it, and the bureau reporting cycle that keeps it current.

May 20, 202612 min read

Why AI / ML Solutions Fail In Production Payments: Seven Patterns I See Every Year

Most AI/ML projects in payments fail in production for reasons that have nothing to do with model accuracy. They fail because the team optimised for a leaderboard metric, the operating environment moved, the labels were wrong, or the audit cycle the model now lives inside was not part of the design. Seven patterns I see every year.

May 19, 202610 min read

Where ML Beats AI: Six Payment Problems an LLM Cannot Touch

There is a quiet AI-in-fintech mistake teams keep making: reaching for an LLM the moment the word 'AI' shows up on the roadmap. Sometimes the right answer is a gradient-boosted tree and a clean feature pipeline. This is the operator's argument for the boring choice.

May 16, 202611 min read

Product Management for Payments Platforms: What's Different, and What's Not

A payments PM is a SaaS PM with three extra constituencies and one extra reflex. Get the reflex wrong and the other constituencies stop trusting you.

May 15, 202610 min read

GenAI in Fintech: 3 Production Systems and 1 Banking Pilot

Most fintech AI work in 2026 is still demos. Three of these use cases run in production; the fourth is a regulated banking pilot.

May 14, 202611 min read

Project Management for Fintech Regulatory Programmes: PCI DSS, ISO 27001, SOC 2, AML/CFT

Six weeks before the audit, every troubled regulatory programme looks identical: forgotten Confluence pages, evidence requests rotting in inboxes, a year of work crammed into six weeks of theatre. Run it as delivery with an immovable deadline and an external grader, or pay remediation many times over.

May 7, 202610 min read

AI Fraud Detection vs Rule Engines: A Field Comparison

ML catches novel attacks; rule engines win on explainability, ops cost, and the regulator conversation. In regulated payments the answer is a hybrid, and designing where each one fires is the whole job.

Discussing senior payments product roles? Get in touch.