What fraud detection is for
Fraud detection aims to spot and stop fraudulent activity, such as unauthorised payments, account takeover or fake applications, ideally before money is lost.
It is related to anti-money laundering monitoring, but different in important ways:
- Who is harmed: fraud usually harms the institution or its customer directly; money laundering disguises the origin of money gained from crime, including fraud, so that it can be used.
- Timing: fraud detection often has to decide in real time, in the seconds before a payment completes. Anti-money laundering work includes some real-time checks, such as sanctions screening, but much of its transaction monitoring looks for patterns built up over days, weeks or months.
- Action: fraud controls can block, hold or challenge a transaction; anti-money laundering monitoring leads to investigation and, where suspicion remains, a report to the authorities.
The two share data, signals and often teams, and many cases are both: the money stolen by fraud is then laundered through mule accounts. Many organisations now bring fraud and anti-money laundering (AML) work closer together by sharing data, investigators and case information. The industry sometimes calls this "FRAML" (fraud and AML). The aim is that a pattern seen by one team is not missed by the other.
Some of the hardest fraud to stop is authorised: the genuine customer, deceived by a scammer, makes the payment themselves. Checking who is paying is therefore not enough. Detection must also ask whether the payment makes sense.
Detection is always a balance. Stop too little and fraud losses grow. Stop too much and genuine customers are blocked, annoyed and lost. Good fraud detection is judged on both.
Rules and risk scores
Most fraud detection combines two approaches.
Rules are explicit conditions written by experts, for example:
- a transfer to a new recipient above a set amount, within an hour of a PIN reset;
- more than a set number of failed PIN attempts;
- a login from a new device followed immediately by adding a payee;
- payments to recipients already linked to confirmed fraud;
- a withdrawal or transfer of most of the balance shortly after a SIM replacement.
Rules are easy to understand, explain and change quickly when a new scam appears. But they are rigid: fraudsters learn the limits and stay just under them, and a large rule set becomes hard to manage.
Machine learning models and other statistical models weigh many signals at once and produce a risk score, often expressed as an estimated probability that an event is fraudulent. Models learn from past cases labelled as fraud or genuine. They can spot subtle combinations no one would write as a rule, and adapt as they are retrained. Their weaknesses are the opposite of rules: they are harder to explain, and they depend on good, correctly labelled data.
Practical systems use both: models to score, rules to act on the score and to handle known patterns, and people to review the uncertain middle. Three problems are common:
- Delayed labels: a fraud may only be confirmed weeks later, when the customer complains. Models therefore learn from yesterday's fraud while fraudsters are already doing something new.
- Class imbalance: fraud is usually a tiny fraction of all activity, so models see few examples of it.
- Concept drift: fraud patterns keep changing, so a model's accuracy fades over time unless it is monitored and retrained.
Because fraud is rare, simple accuracy misleads. If 1 payment in 1,000 is fraud, a model that calls everything genuine is 99.9% "accurate" and catches nothing. Fraud teams use measures such as detection rate, false-positive ratio and value saved instead.
The signals that matter
Effective detection looks beyond the transaction itself.
- Transaction signals: amount, time, recipient, channel, and how these compare with the customer's usual pattern.
- Velocity: how many actions happen in a short time: payments, logins, failed attempts, new payees.
- Device and network signals: whether the device is new, whether it has been seen with other accounts, whether the connection looks unusual. One device linked to many accounts is a classic sign of organised fraud.
- Behaviour: how the person uses the app or website, such as typing rhythm, navigation and hesitation, compared with how that customer normally behaves. Differences can suggest a fraudster using the account, or a genuine customer being coached by a scammer on the phone.
- Account events: recent changes of PIN, phone number, email, SIM or address, which often come just before a takeover.
- Network links: connections between accounts through shared phone numbers, devices, addresses or payments. Graph analysis can reveal whole rings of mule accounts that look innocent one at a time.
Many of these signals involve personal data. In Kenya, the Data Protection Act, 2019 applies. Processing must be lawful, fair and transparent (section 25). Fraud prevention usually relies on a lawful basis such as legitimate interests or a legal obligation (section 30). Customers must be told what is collected and why (section 29). High-risk processing, such as large-scale profiling, calls for a data protection impact assessment (section 31). Data may be kept only as long as reasonably necessary for its purpose, unless a law requires or allows longer, as anti-money laundering record-keeping rules do (section 39). Collect only what is necessary and proportionate, and secure it.
Handling alerts without losing good customers
Detection only helps if the response is right. Common responses, from least to most disruptive:
- Allow and monitor, for low risk.
- Step-up authentication: ask for an extra check, such as a one-time code, a biometric check or confirmation in the customer's registered app, before continuing. One-time codes sent by SMS can be intercepted after a SIM swap, so a recent SIM change should raise the risk score.
- Warn: show a clear, specific warning about a likely scam, especially for authorised payments the customer is being tricked into making.
- Hold and contact: pause the payment and contact the customer through a channel you already trust, not one given in the suspicious session.
- Block and, where needed, freeze the account.
Good practice for teams reviewing alerts:
- Prioritise by risk and value, so the most dangerous cases are handled first, within minutes where money can still be stopped.
- Give reviewers the full picture: the signals behind the alert, the customer's history and linked accounts.
- Record the outcome of every alert as confirmed fraud or genuine. These outcomes become the labels that improve rules and models.
- Respect the customer: most alerts are genuine customers. Clear explanations, quick resolution and an easy way to confirm "it was me" keep their trust.
- Escalate confirmed fraud to recovery, law enforcement and, where laundering is suspected, the anti-money laundering team.
Measuring whether it works
Fraud detection needs honest measurement on both sides of the balance.
- Fraud caught: the share of fraud, by number and by value, that was detected or prevented.
- Fraud missed: fraud found later through complaints, disputes or chargebacks (card payments reversed after the cardholder disputes them). It is easy to overlook, but without it detection rates are meaningless.
- False positives: genuine activity flagged as fraud, often expressed as a ratio of false alerts to real fraud found (not the same as the statistical false positive rate, which divides false alerts by all genuine activity).
- Customer friction: payments delayed or declined, extra checks triggered, complaints and customers lost.
- Speed: time from alert to decision, which determines whether money can still be stopped.
- Losses and recoveries: the money actually lost and recovered.
Measure by segment and channel, not only overall, because fraud concentrates where controls are weakest. Test changes before making them: estimate how many more frauds a new rule would catch and how many more genuine customers it would stop.
Models need governance like any other decision system: documentation of what they do and why, testing before release, monitoring for drift and for unfair effects on groups of customers, and human review of decisions that significantly affect people. In Kenya, section 35 of the Data Protection Act, 2019 gives people the right not to be subject to such decisions made solely by automated processing, with limited exceptions. Fraudsters adapt constantly, so fraud detection is never finished; it is a cycle of detecting, learning and adjusting.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- Data Protection Act, 2019 (No. 24 of 2019) · Kenya Law
- The FATF Recommendations (for the anti-money laundering comparison) · Financial Action Task Force
- Credit Card Fraud Detection: A Realistic Modeling and a Novel Learning Strategy (Dal Pozzolo et al., 2018) · IEEE Transactions on Neural Networks and Learning Systems
- Machine learning in UK financial services (2019) · Bank of England and Financial Conduct Authority
- FSI Insights No 63: Regulating AI in the financial sector · Bank for International Settlements
- Joint report on payment fraud · European Banking Authority and European Central Bank
- Fraud safety · Central Bank of Kenya
- NIST SP 800-63B: Digital Identity Guidelines, Authentication · US National Institute of Standards and Technology