For years, financial services organizations often treated fraud primarily as an operational issue, with fraud management responsibilities distributed among departments such as deposit operations, card services and Bank Secrecy Act/anti-money laundering, security, and other business units. Audit committees, meanwhile, generally focused their attention on financial reporting, internal controls, compliance, and other traditional areas of oversight.
But the fraud landscape has changed. AI-enabled fraud, sophisticated social engineering, synthetic identities, customer-authorized scams, business email compromise, and faster payments are changing how fraud occurs and which areas of the organization are exposed.
As a result, the questions for audit committees are no longer simply how much fraud the organization is experiencing and how exposure can be minimized. An additional concern is whether the organization’s governance structure has kept pace with the evolution of fraud.
The changing fraud environment is creating new considerations for audit committee and board oversight.
Historically, financial services organizations designed many fraud controls to detect suspicious transactions involving counterfeit checks, stolen cards, compromised credentials, and other recognizable indicators.
Increasingly, fraudsters are targeting people, convincing customers to willingly transfer their own money. They pretend to be financial institution employees using spoofed phone numbers, create synthetic identities and falsified documentation to obtain loans, or use AI-generated voices and other technologies to impersonate trusted individuals.
Audit committees do not need to understand the technical details of every emerging fraud scheme. They should, however, have confidence that management’s fraud risk assessment, control environment, resources, and governance structure are evolving to outpace the threats.
Fraud has always created financial losses, but now the breadth of its potential impact is larger and it is happening at a more rapid pace than in the past. As fraud becomes more complex and cross-functional, some institutions are reconsidering how responsibility is organized.
Responsibility for managing fraud risk often remains distributed across multiple departments. Other organizations have dedicated fraud teams. No matter the model, the crucial governance question is whether the structure reduces gaps among functions, supports meaningful fraud metrics, allows resources to be directed toward changing risks, and helps the organization identify emerging threats early enough to respond.
Audit committees should understand who owns enterprise fraud risk, how decisions and information are coordinated across business units, and whether organizational silos create gaps in prevention, detection, or response.
Fraud might be following a governance trajectory similar to that of cybersecurity, which once was viewed largely as an IT responsibility. Today, boards routinely oversee cyber risk because threats evolve rapidly, responsibilities span multiple functions, and the consequences extend throughout the organization.
Fraud presents a similar governance challenge. A dedicated fraud function can provide important enterprise ownership and coordination, but effective fraud risk management cannot reside within just one department. Responsibilities extend across business units and control functions, requiring clear accountability and coordination as well as appropriate visibility at the executive and board levels.
Audit committees can consider fraud risk through four interconnected areas: governance, controls, technology, and emerging risks.
Looking at fraud through these four lenses can help audit committees stay focused on governance and oversight without becoming immersed in operational details.
Traditional fraud reporting often emphasizes losses, recoveries, transaction volumes, and other historical measures. Those metrics remain valuable, but they primarily explain what has happened already. Effective oversight also should help determine whether the organization is prepared for what might lie ahead.
Instead of focusing on how much fraud the organization has had, audit committees can pose questions, such as:
These questions move the discussion beyond historical loss reporting and metrics toward governance effectiveness, organizational readiness, and the institution’s ability to respond as fraud techniques evolve.
A current fraud risk assessment can provide a solid foundation for a discussion of governance effectiveness. The assessment should help management and the audit committee understand which departments, products, channels, and processes present the greatest fraud exposure; whether fraud trends are migrating; and how effectively the organization coordinates its response across departments.
An assessment also can assist in challenging the organization’s assumptions about where fraud resources should be concentrated. Risks that are highly visible or easy to understand might not be the ones creating the greatest exposure.
For example, an audit committee naturally might focus on branch cash because the risk is tangible and familiar. Yet cash limit controls and other common business safeguards often reduce that exposure. Meanwhile, a fraudulent loan supported by AI-generated financial information or weaknesses in wire and automated clearinghouse processes could create a much larger risk of loss.
The objective is not simply to devote more resources to fraud mitigation. It is to align governance, controls, and resources with the areas of greatest risk.
Recent examination activity suggests regulators are paying attention not only to whether fraud events have occurred but also to how institutions identify emerging fraud risks, evaluate control effectiveness, assign accountability, and govern fraud risk across the organization.
A formal fraud risk assessment, clearly defined governance responsibilities, appropriate reporting, and independent testing of key fraud controls can help organizations demonstrate a thoughtful approach to fraud risk management while improving coordination across business functions.
Information sharing also can play an important role. Financial institutions that develop strong communication channels with other institutions can gain earlier visibility into fraud trends and activity in their markets. Recent Financial Crimes Enforcement Network guidance related to Section 314(b) of the USA PATRIOT Act supports information sharing to identify fraud and related criminal activity.
Audit committees need confidence that the organization’s approach to fraud matches its risk profile and can adapt as fraud risks evolve. A clear view of enterprise fraud exposure gives audit committees a stronger basis for challenging assumptions and identifying gaps. Fraud methods will change, but effective oversight depends on whether the institution can recognize those changes early and respond accordingly.
Our team has deep experience helping financial services organizations assess their fraud oversight. Contact us today to see how we can do the same for your organization.