Skip to main content
Shared Liability Shifts Fraud Defense StrategyFraud Typologies
4 min readFor Fraud Risk Managers

Shared Liability Shifts Fraud Defense Strategy

What Changed

The financial industry is changing how it assigns responsibility for authorized push payment (APP) fraud. Nacha will require all non-consumer ACH participants to monitor for suspected fraud by mid-2026. This shifts from the old model where victims bore all the loss when they authorized a fraudulent payment.

This change comes as losses from investment scams hit $4.57 billion in 2023, a 38% increase from the previous year, according to the FBI's Internet Crime Complaint Center. LSEG Risk Intelligence projects global APP fraud losses could reach $331 billion by 2027. Business Email Compromise alone accounted for 21,489 complaints and $2.9 billion in reported losses in 2023.

Key Findings

1. Real-time settlement eliminates recovery windows

Most instant payment transactions complete in 10 seconds or less. Once funds leave the account, reversal is typically impossible. Your fraud detection must operate faster than settlement finality.

2. Cross-border complexity creates detection gaps

Each jurisdiction has different regulatory frameworks. When a transaction crosses borders, it involves at least two sets of rules. This slows investigations and delays potential reimbursements. Your monitoring system needs visibility across correspondent banks and payment rails.

3. AI lowers the skill floor for convincing fraud

Generative AI now produces executive-level email prose without errors. Voice cloning requires only a few seconds of audio from social media. In one case, a Hong Kong company lost millions when employees participated in a Zoom call with what they believed was their CFO. All failed to detect the deepfake video in real time.

4. Behavioral signals precede fraudulent authorization

Victims under coercion show measurable anomalies: extended phone call duration during login, typing pattern changes, unusual account access times, hesitation in transaction flow. These signals appear before the authorization, not after.

5. Single-point verification no longer suffices

One authentication factor or identity check at account opening won't catch a compromised supplier account months into a business relationship. Constant validation of beneficiary accounts, ownership, and transaction context is now essential.

What This Means for Your Team

You're moving from detection to prevention. Shared liability means you can't wait for the transaction to clear and then file a SAR. Your controls must intervene during the authorization window.

Your current monitoring likely focuses on transaction patterns after the fact. You'll need to incorporate pre-authorization signals: device fingerprinting, behavioral biometrics, real-time identity verification at the point of payment, and continuous beneficiary account validation.

If you're still treating consumer education as a compliance checkbox, you're leaving exposure on the table. Friction at the authorization point isn't customer-hostile when it prevents a $50,000 loss. The UK model embeds multiple confirmation prompts directly in the payment flow. Frustrating? Yes. Effective? Also yes.

Cross-border payments require coordination you may not have built yet. You need visibility into fraud patterns occurring at other institutions and across other payment networks. No single bank can anticipate APP fraud vectors in isolation.

Action Items by Priority

Immediate (Next 30 Days)

Audit your current fraud monitoring against Nacha's mid-2026 deadline. If you're a non-consumer ACH participant, you have less than two years to implement suspected fraud monitoring. Identify gaps in your current detection coverage.

Map your authorization flow timing. Measure how long each authentication step takes and where your intervention points exist. If your fraud rules run after settlement, you have no prevention capability.

Short-Term (Next 90 Days)

Implement behavioral analytics on high-value transactions. Monitor for phone call duration during sessions, typing cadence changes, and access pattern anomalies. These signals cost little to collect but provide early warning.

Establish secondary verification requirements for large transfers or beneficiary changes. If an employee requests a payment above your threshold or a supplier asks to update banking details, require out-of-band confirmation through a separate channel.

Medium-Term (Next 6 Months)

Deploy continuous beneficiary validation. Don't verify account ownership once at onboarding and never again. Run periodic checks on active supplier and vendor accounts. Domain hijacking and account takeover happen between transactions.

Build cross-institution intelligence sharing. Join fraud consortiums or implement API-based fraud intelligence feeds. Your ability to prevent fraud depends on seeing patterns beyond your own customer base.

Integrate identity verification at payment initiation, not just account opening. Age verification is a starting point, but you need real-time identity and account verification intelligence before high-risk transactions complete.

Long-Term (Next 12 Months)

Automate your layered defense. Spreadsheet-based fraud review won't scale to real-time payment volumes. Move to API-driven services that triangulate multiple signals: biometrics, device intelligence, behavioral analytics, beneficiary validation, and transaction context.

Redesign your customer education from static website content to embedded prompts in the transaction flow. Interrupt the authorization sequence with contextual warnings when risk signals appear. The goal is to disrupt the urgency that scammers create.

PCI DSS requirements

You Might Also Like