Nationwide consumer-reported fraud losses well exceed $10B annually, with regulatory alerts directly to consumers and companies being issued nearly every week. This, coupled with a new Administration focus on fraud, waste and abuse (particularly in/related to government spend), will help drive the focus in regulatory supervision of fraud model management, customer and party authentication, and investigation processes. Anticipate expanding attention in monitoring and reporting practices as well as regulatory policy and alerts in areas of both fraud management and consumer data, particularly in areas such as online privacy, cybersecurity, identify theft, and AI-generated deepfakes. Likewise, state requirements will continue to increase in such areas of AI, privacy and access, causing potentially divergent requirements.
As advancements in technology continue to rapidly evolve so too do the risks of fraud and scams along with increasing and significant impacts to consumers, companies, and national security. The magnitude of these risks - and the ties with other risk areas such as cybersecurity, AI, and data privacy - will focus regulators on areas of expanding threat and vulnerabilities.
Key considerations in assessing sizing exposures involve:
Across industries, regulatory agencies’ supervisory and enforcement activities are focused on mitigating expanding risks of fraud, waste, identity theft, and imposter and other scams, including those related to “predatory” pricing and payments. Regulatory expectations will include standardized processes and controls around access, authorization, data use, privacy, security, and sharing. Companies must continue to ensure the use of accurate data and controls to measure and manage risk exposure and reporting.
Given expansions to supply chains and arrangements with third parties and providers, regulators will have concerns for fraud risk as customer data potentially becomes more accessible across diverse platforms. To mitigate fraud and scams, risk management strategies must address vital areas such as large data models, third-party and affiliate data sharing, consent-based customer data sharing, payment verification procedures, and model development and validation.
The increasing volume and related costs of fraud and scams against individuals and businesses has led regulators to intensify their efforts to assess the breadth of fraud (e.g., numbers of individuals and/or products impacted) and impact severity through enhanced risk and fraud model management including considerations across:
Acting quickly and decisively to prevent, detect, and respond to fraud and misconduct concerns is essential to minimize disruption and loss. Anticipate increased regulatory attention to fraud identification, oversight, investigations, and mitigation.
For example, regulators will evaluate companies’ activities related to:
Identification and escalation of potential cases of fraud, through active monitoring of:
Ongoing and thorough reviews of customer complaints management with a focus on issues identification including trends/fact patterns, escalation, investigation, and resolution. Within the fraud and investigations management processes, regulators will evaluate the timeliness, substance, and completeness of responses/remediation to customer complaints, claims, and disputes as a measure of “fair treatment”. They will also consider the clarity of consumer communications, including what is reimbursable as well as the consistency of responses and/or remediation between consumer groups. Key areas will include:
The effectiveness of risk and compliance oversight of fraud and coordination across the AML/CFT, cybersecurity, and fraud functions. Regulatory attention will also focus on demonstratable, effective Board oversight and the implementation of threat detection/ monitoring processes that include:
To safeguard against fraud and other scams, as well as ensure consumer/investor protections, companies must establish effective internal controls for monitoring, detecting, and mitigating the attempts of threat actors.
Expect heightened attention to processes and controls relating to:
Consent management and customer authentication requirements, such as multifactor authentication, password protection, one-time passwords, biometrics, third-party access, tokens, and peer-to-peer platforms. Implementing safeguards and controls in these areas, aids in the prevention of unauthorized use of sensitive information as it creates barriers for illicit activities.
Updates to fraud risk management programs to keep pace with evolving threats (in addition to effective internal controls, fraud model development and use, and assessments of consumer impacts). Regulators are currently focused on enhancements related to:
Processes and controls to effectively track and trace customer and transaction data. Examinations and reviews of risk management programs will assess a company’s:
Regulators will continue to strongly encourage companies to bolster their risk mitigation and remediation efforts through self-identification, self-reporting, and accountability, as measures of responsiveness to:
KPMG Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments.
Points of View
Insights and analyses of emerging regulatory issues and their impact.
Regulatory Alerts
Quick hitting summaries of specific regulatory developments and their impact.
Regulatory Insights View
Series covering regulatory trends and emerging topics