The rise of AI-driven fraud: Why financial crime is becoming a boardroom risk

As businesses reopen physical locations, fraudsters reduce online schemes against organizations: Study

In January 2024, an employee at a Hong Kong-based company was reportedly tricked into transferring US$25 million after joining a video conference with what appeared to be the company’s chief financial officer and other colleagues. They were not real. Fraudsters had created deepfake versions of the executives and used them to authorise the transfers.

For years, financial fraud was largely a game of deception at the edges of a business. A fraudulent email, a stolen password, a forged document, or a suspicious transaction would trigger controls designed to identify and stop the activity before money changed hands.

Artificial intelligence is changing that equation.

As generative AI becomes cheaper and more accessible, this kind of social engineering is becoming easier to execute at scale. Voice cloning, deepfake video, synthetic identities, fake documents and highly personalised phishing messages can now be produced with a speed and sophistication that would have required considerably more resources in the past.

That changes the risk equation for businesses. AI-driven fraud is increasingly a financial, operational and governance risk that belongs on the boardroom agenda.

The fraudster now has AI too

Financial institutions have spent years using artificial intelligence to detect unusual transactions, identify suspicious behaviour and strengthen anti-money laundering controls. The same technology is now being used on the other side of the equation.

AI can help fraudsters personalise scams, imitate executives, manufacture identities and automate attacks against multiple targets simultaneously. The result is a fundamental asymmetry: the cost of producing a convincing fraudulent interaction is falling while the potential financial impact remains large.

The Financial Stability Board and other financial authorities have highlighted deepfakes, synthetic identities and AI-enabled fraud as emerging vulnerabilities for the financial system. Regulators are also increasingly focused on the possibility that AI could make scams more industrialised and harder to detect.

This is particularly relevant for financial services, where trust and identity are at the centre of almost every transaction. A convincing synthetic identity can potentially be used to open an account or obtain credit. A cloned voice can be used to impersonate a customer or senior executive. A fabricated document can undermine traditional know-your-customer processes. A personalised phishing message can be tailored to an employee’s role, relationships and responsibilities.

The challenge is therefore not simply that fraud is becoming more sophisticated. It is becoming more convincing.

The weakest link may be outside the organisation

There is another complication. Modern businesses rarely operate entirely within their own technology environment.

They depend on cloud providers, payment processors, software vendors, outsourced customer-service platforms and other technology partners. An incident affecting one of these providers can have consequences for several businesses simultaneously.

This makes third-party and contingent exposures increasingly important. A company may not be directly attacked, but a technology provider could suffer an incident that prevents the company from accessing systems, processing transactions or serving customers.

The boardroom question then becomes broader: where does the organisation’s financial exposure actually sit?

A business that is heavily dependent on digital operations may be particularly vulnerable to revenue losses during system downtime. Another may have a larger exposure because it holds vast amounts of sensitive customer information. A financial institution may face a different risk again, where fraudulent transactions, account takeovers and regulatory obligations can compound one another.

There is no single model for an adequate fraud or cyber risk programme. It has to reflect the way the business actually operates.

Cyber insurance can provide an important layer of financial resilience when an incident disrupts systems or compromises data. Depending on the policy, it can respond to costs such as incident response, forensic investigation, business interruption, data restoration, regulatory proceedings and third-party liabilities.

Crime insurance addresses a different part of the exposure: the direct financial loss caused by fraudulent acts. Depending on the coverage, this can include employee dishonesty, theft and certain forms of impersonation or funds-transfer fraud – areas becoming increasingly relevant as AI makes fraudulent instructions more convincing.

AI changes the boardroom conversation

There is also a governance question emerging from all of this.

Boards have traditionally been asked to oversee financial risk, operational risk, cyber risk and regulatory risk as distinct categories. AI is increasingly blurring those boundaries.

A single deepfake-enabled fraud could involve technology-enabled deception, employee manipulation, financial loss, data compromise, regulatory exposure and reputational damage at the same time.

The Financial Stability Board has also pointed to another emerging concern: concentration. Financial institutions and businesses are increasingly dependent on a relatively small number of technology, cloud and AI providers. If many organisations rely on similar models, infrastructure or vendors, an incident affecting one part of that ecosystem could potentially create correlated risks across multiple companies.

From prevention to preparedness

The old approach to fraud was built around the idea that better controls would keep bad actors out.

That remains important. But AI makes it increasingly difficult to assume that every fraudulent interaction will look fraudulent.

The more useful approach is to prepare for the possibility that something will get through.

That means testing incident response plans, defining who has authority to stop or approve high-value transactions, creating alternative communication channels for sensitive instructions and regularly testing business continuity arrangements. It also means understanding the financial consequences of downtime and fraud before an incident occurs rather than trying to calculate them in the middle of a crisis.

AI may be making financial crime more sophisticated, but the underlying lesson for businesses is straightforward. Security can reduce the likelihood of a loss. Preparedness can reduce its severity. Business continuity can reduce the time it takes to recover. And financial protection can help prevent an unexpected incident from becoming a balance-sheet crisis.

The organisations that are best prepared for the next generation of financial crime will not necessarily be those that believe they can prevent every attack. They will be those that have already planned for what happens when prevention fails.

Authored by Evaa Saiwal, Head of Cyber & Liability Insurance at Policybazaar for Business

Share on