51% identify APP fraud as their most significant operational challenge
The findings reveal an important distinction between severity and prevalence. APP fraud is viewed as the most significant operational challenge, while insider fraud is experienced more widely across the sector. The most severe risks are not always the most common, and each demands a different response. High-impact threats justify specialist capabilities and targeted investment, while widespread risks require consistent controls, training and governance across the organisation. Together, these findings point to the same conclusion: organisations are not only deciding which risks matter most, but where they have the greatest operational uncertainty.
APP fraud is recognised as a major challenge even by organisations that have not yet experienced it, reflecting the widespread awareness of its operational impact.
Recognition isn’t translating into action. Although many organisations identify data sharing as a major challenge, relatively few are investing in the infrastructure needed to improve it.
Key statistic
Fraud prevention is the greatest operational uncertainty
Fraud prevention emerges as the greatest source of operational uncertainty. Unlike regulatory questions, which are often addressed through guidance and policy, fraud prevention depends on real-time decisions, evolving attack methods and controls that must adapt continuously. This makes progress harder to measure and operational resilience more difficult to achieve. The following section explores the regulatory uncertainties organisations are managing alongside these operational challenges.
Identify fraud prevention as their greatest operational challenge
Fraud prevention stands well ahead of every other source of uncertainty, suggesting organisations are more concerned with responding effectively than understanding what the rules require.
Fraud prevention is the leading operational uncertainty for both banks and fintechs, suggesting the challenge is shared across the sector rather than confined to one type of organisation.
Industry perspectives
Industry leaders reflect on the report’s key findings

Kamlesh Harry, Principal Strategic Advisor – Fraud Solutions, Nasdaq Verafin
"Today's fraud threats are networked, adaptive and increasingly cross-border. With 90% of financial crime professionals reporting an increase in AI-driven attacks and $482.9 billion in illicit funds moving across international borders in 2025, fraud prevention must evolve beyond static controls. Success will depend on combining AI, network-level analytics and closer, cross-border, cross-sector collaboration between financial institutions, technology providers, telecos, regulators and law enforcement to stop criminal activity before losses occur."

Freddy Ramirez, Head of Global Financial Crime Worldpay, now Global Payments
"AI agents are starting to initiate payments on behalf of consumers, without pausing for the checks built for human behavior. Most fraud and authentication models still assume a person is choosing, confirming and paying. That assumption is breaking down. Good transactions may appear fraudulent and vice versa. Financial crime teams need distinct verification and authorization standards for agent-initiated transactions now, well before adoption reaches scale, not once the losses arrive."

Humzah Amin, Founder, Guardexia
"Many firms think safeguarding failures start with a broken reconciliation. In practice they start earlier, with uncertainty over what should be reconciled in the first place. The firms best prepared for increased regulatory scrutiny are those with clear methodologies, daily visibility and records that can be understood without relying on institutional memory. That's ultimately what safeguarding is designed to achieve: protecting customers if the firm fails."

Dean Smith, MD, Tag Systems
“Financial crime is evolving faster than traditional fraud controls. The industry's focus must continue shifting upstream, preventing fraud before authorisation rather than simply detecting it afterwards. The payment chip is no longer just a secure component; it's an intelligent security layer that verifies card authenticity, applies risk controls and strengthens payment integrity before the transaction takes place. Security by design means building trust into every card, not just every transaction.”
