TechForge

August 26, 2026

  • AI-enabled fraud is outpacing traditional controls.
  • AI governance starts with trusted data and clear business goals.

 

Organisations need to look beyond regulatory compliance when managing risk as AI-enabled fraud, cyber threats, and other risks develop faster than traditional controls, Stu Bradley, Senior Vice President of Risk, Fraud and Compliance at SAS, told Tech Wire Asia.

Risk teams are dealing with greater complexity across areas including market, liquidity, interest rate, environmental, financial crime, and cyber risk. Managing those risks through separate systems and processes can make it harder for institutions to understand how one area affects another.

“Risk leaders need to start thinking differently around how they can manage that overall complexity,” Bradley said. “First and foremost, they need to be thinking differently about data. Too many times, data is sitting in silos and it’s not being used across the entirety of a programme.”

Regulatory reporting programmes can also be used to support operational and financial decisions rather than being treated solely as compliance requirements.

When different risk functions remain separated, institutions can miss connections between risks and make decisions based on an incomplete view of their exposure. Analytics and AI can also support more granular stress testing across different types of risk.

“Risk leaders have the ability to get the granularity of different scenarios and use those scenarios to make better decisions, strategic decisions, things like how they manage their capital on behalf of the institution,” Bradley said.

AI fraud is outpacing traditional controls

Financial crime presents another challenge because criminals are not subject to the same regulatory and governance requirements as the organisations trying to stop them.

Stu Bradley, Senior Vice President of Risk, Fraud and Compliance at SAS

“The problem is the fact that the financial criminals are leveraging technology much faster than the institutions that are protecting us,” Bradley said. “They’re not encumbered by regulations. They’re not encumbered by initiatives around responsible innovation, and they’re not encumbered by internal audit.”

Organisations should not approach financial crime solely as a regulatory obligation. Breaking down data silos and making greater use of existing technology are also necessary as fraud methods change.

A SAS study conducted with the Association of Certified Fraud Examiners found that 75% of fraud professionals surveyed had seen an increase in AI-enabled fraud. Another 55% expected AI-enabled fraud to continue accelerating in the near term.

Fraud techniques can change before regulations or internal policies are updated, making it difficult for organisations to rely on formal guidance alone when responding to new threats.

The focus, Bradley argued, should be on improving the organisation’s ability to respond rather than trying to predict each emerging threat.

“There’s a more important question that needs to be asked, and it’s not about what’s coming next, because if you’re only focused on what’s coming next, you’re always going to be chasing,” Bradley said.

“The question needs to be: What do I need to do as an enterprise to become more agile for whatever comes next? Whether that’s a technology innovation I need to adopt or a financial crimes threat that I need to be able to respond to,” Bradley said.

AI governance starts with data

One common mistake is focusing too narrowly on model governance while overlooking the wider data and AI lifecycle.

“Organisations need to take a step back and think more holistically about the entire data and AI lifecycle,” Bradley said. “So it starts with data.”

That includes controls around data quality, completeness, availability, and lineage. Organisations need to know whether the data used by a model is appropriate for a particular decision and whether its origin can be traced when outputs are reviewed.

“Do I have the right data? Is it coming to me at the right time to make the decisions I need to make? Is it of the right completeness and quality that are required?” Bradley said. “Do I have the data lineage? Do I know where it came from?”

Once those controls are established, organisations can move to model governance, including building, testing, challenging, and assessing models before deployment. The process also needs to account for intended and unintended consequences.

Governance continues after a model enters production. Organisations need to monitor whether model outputs remain aligned with their intended outcomes and use those findings to update data, models, and controls.

“It’s a cycle. It’s not linear,” Bradley said. “Then you continue to improve that process, going back to the data as you want to address data, bring in new data, build new models, and then monitor those from a production outcomes perspective.”

An IDC report cited during the interview found that only 11% of organisations surveyed had both a high degree of trust in AI and AI systems considered highly trustworthy.

The report also found that 60% of respondents with what it described as trustworthy innovation initiatives reported returns on investment of at least twice their spending.

Governance therefore needs to be built into AI development rather than treated as a separate process after deployment.

“Executives now are looking to more rapidly and aggressively adopt innovation governance, AI governance, data governance capabilities because it’s not an impediment to innovation,” Bradley said. “If you lay that down and get the foundational capability correct, it’s actually going to help you accelerate your innovation.”

Simplifying risk and fraud infrastructure

Many organisations have accumulated separate applications to address individual problems in fraud, risk, and compliance, creating environments that require continued integration, security updates, and patching.

“The next problem arises, a new technology to solve it. The next problem arises, a new technology to solve it,” Bradley said. “They’ve created a very cumbersome integration of all of that technology.”

That complexity can reduce the ability of fraud, risk, and compliance teams to respond quickly when requirements or threats change. IT rationalisation is one way organisations are looking to simplify those environments.

Risk, fraud, compliance, sanctions, and identity processes often rely on the same or similar data despite being handled by separate applications.

“If you think about risk decisions, fraud decisions, compliance decisions, it’s all the same or very similar data that’s required, and yet this sits in a multitude of different applications,” Bradley said.

Integrating decisioning systems can allow institutions to use common data across fraud, risk, compliance, sanctions, and identity processes. In financial services, that includes decisions such as identity verification, sanctions screening, fraud checks, credit origination, and credit pricing during customer onboarding.

Fragmented systems can also affect fraud detection after a customer relationship has been established. A bank may view the same customer differently across credit cards, payment accounts, and digital services, limiting the information available to individual fraud systems.

“What the criminals are doing is they’re preying on the fact that banks and other organisations operate in these silos, and they hide within these silos,” Bradley said.

Bringing fraud, anti-money laundering, sanctions, and identity-validation decisions together can give institutions access to more data points when assessing suspicious activity.

The discussion around infrastructure also extends to how organisations select and deploy AI. Some companies approached generative AI by starting with the technology rather than the business problem they needed to solve.

“No matter what the problem was, they tried to take generative AI and apply it to that problem,” Bradley said.

“Twelve to 18 months later, the CFO is looking at them, saying, ‘Well, we spent all of this money on this new technology. Where’s my return on that investment?’” Bradley said. “They didn’t start with the outcome. They didn’t start with the business problem they were looking to address.”

Technology decisions should instead begin with the business problem and intended outcome before organisations decide which tools to use.

AI adoption also differs according to an organisation’s existing capabilities. Large global financial institutions and smaller community banks operate with different budgets, technical resources, and levels of expertise.

“The conversation with our customers quickly turns to maturity,” Bradley said. “We work with our customers to understand where they’re at on the maturity curve, such that we can build them to using the more sophisticated technologies, so they can build their skill sets, their human capital, to be able to leverage those technologies over time.”

Moving directly to more advanced systems can result in technology being underused if an organisation has not developed the skills and processes needed to support it.

In banking, some institutions are starting broader decisioning infrastructure projects with credit risk and credit origination before extending those systems to fraud and identity decisions.

Outside banking, insurers are also examining more dynamic actuarial modelling processes. SAS is also working with government agencies on tax compliance and tax fraud, including cases in which stolen identities are used to file fictitious tax returns before the legitimate individual or business submits its own return.

The same identity-based controls used in bank fraud prevention can also be applied to insurance claims and tax filings.

 

 

 

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events, click here for more information.

Tech Wire Asia is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

September 14, 2026

September 11, 2026

September 10, 2026

September 10, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

35545 view(s)
17827 view(s)
17802 view(s)
17438 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.