By MFJ Staff | Source: FinTech Futures
Key takeaway: Fraud detection is expanding from the transaction itself to the full customer and payment lifecycle. Merchants and processors should expect more data-sharing obligations, like the EPC’s forthcoming FRIDA mandate. They should also expect continued pressure to map controls across identity, onboarding and authentication, rather than relying on point-in-time transaction checks.
On day one of Sibos 2026 in Miami, a Bottomline survey of 300 payment professionals found that 44% identify mid-transaction fraud detection as their institution’s biggest vulnerability. Another 28% pointed to prepayment validation, and 19% cited end-to-end visibility.
The survey was presented during a panel titled “Securing payments end-to-end: AI, trust and security in a real-time world.” The panel brought together speakers from PwC, the European Payments Council (EPC) and Bottomline. Jessica Cheney, VP of banking solutions and growth at Bottomline, moderated and opened with the survey’s findings.
Genevieve Gimbert, risk and regulatory partner at PwC, described the scope of the problem. Fraud defense now spans identity verification, authentication, scam detection, mule detection and post-transaction intelligence. These controls typically sit with different teams inside a single bank, and connecting those risk signals end to end is itself a major challenge, she said. Gimbert also pointed to a shift from pure transaction monitoring toward identity-based fraud, driven by deepfakes, fake documentation and voice cloning. Institutions need to pull risk signals from account opening and onboarding all the way through to login and transaction monitoring, she argued.
On liability, Gimbert and EPC director general Giorgio Andreoli agreed that accountability for authorized push payment fraud does not rest with one party alone. Andreoli added that in the UK and Europe, liability is increasingly shifting to payment service providers (PSPs) rather than banks. His reasoning: such scams typically involve some leakage of information from banks or operators.
Andreoli also detailed FRIDA (Fraud Information Distribution Arrangement), an EPC initiative still in development. It will eventually require PSPs to share fraud information and confirmations. The EPC is currently defining both the scheme and the technical architecture for a planned European-wide network, which is expected to encompass more than 3,000 PSPs once built out. He separately noted that the EPC’s existing Verification of Payee programme now processes over one billion transactions monthly across more than 27 countries, with an error rate below 1%. The EPC is also developing a digital identity scheme, he said.
Why it matters: Two signals from the same panel point in the same direction. Banks and PSPs increasingly see fraud as a connected, end-to-end problem rather than a transaction-monitoring problem. Meanwhile, regulators are starting to build the data-sharing infrastructure, like FRIDA, to back that up. For merchants and processors, authentication, onboarding and fraud-data-sharing obligations are converging. Liability for authorized fraud is also trending toward PSPs rather than staying fixed with banks.
Source: FinTech Futures












