Payment fraud prevention innovation is under more pressure than at any point in the modern era of digital payments. As money moves faster and fraudsters grow more sophisticated, financial institutions are rethinking every layer of their defences, from account verification to AI-driven detection, while regulators on both sides of the Atlantic are tightening the rules on who bears responsibility for stopping losses.
Why Real-Time Payments Change the Fraud Equation
The core tension is simple: consumers expect instant settlement, but speed removes the review windows that banks have historically used to catch suspicious activity. ‘Instant payments remove the buffers for review and investigations that FIs have traditionally been able to rely on, making instances of fraud that much harder to track down and resolve,’ said Suzanne Sando, Lead Analyst of Fraud Management at Javelin Strategy & Research. ‘Fraudsters now exploit faster transaction settlement in hopes that it will outpace outdated fraud detection.’
Authorised Push Payment (APP) fraud sits at the sharp end of this problem. In an APP scam, criminals use social engineering or impersonation to convince victims to send money voluntarily to fraudulent accounts. By the time the victim realises, the funds are gone and are often impossible to recover. The window to act is before the customer clicks ‘Send’, not after.
Some institutions have already moved. JPMorgan Chase, for example, restricts certain Zelle payments to recipients customers first met through social media. But individual safeguards, however targeted, are not a complete answer. The broader industry response is converging on a combination of historical transaction data, device intelligence, account activity and behavioural analytics working together in real time.
Stablecoins, AI and the Shifting Fraud Surface
Emerging payment rails are adding new dimensions to the challenge. Stablecoin adoption continues to grow, partly because it addresses longstanding friction in cross-border payments and foreign exchange. Because stablecoins run on transparent blockchain networks, investigators often have greater visibility into suspicious transactions than they do with traditional systems. But that transparency has a flip side.
‘Stablecoins don’t eliminate fraud, but they shift where it happens,’ said Joel Hugentobler, Cryptocurrency Analyst at Javelin Strategy & Research. ‘Blockchains are transparent and transactions are traceable, so fraud has mostly moved towards exploiting on/off-ramps, things like impersonation, fake investment opportunities, phishing, and social engineering. Stablecoins, especially regulated ones, aren’t very vulnerable, but they can lead to typically either custody and infrastructure issues or human targets.’
Generative AI has given criminals a further edge, enabling highly convincing phishing emails and voice messages that are increasingly difficult for consumers to distinguish from legitimate communications. Financial institutions are responding by deploying AI-driven fraud detection systems of their own: the technology’s ability to analyse large volumes of historical and real-time data makes it well suited to identifying emerging patterns before losses accumulate.
Alongside AI investment, many organisations have moved beyond one-time onboarding checks towards continuous monitoring throughout the customer relationship. ‘Continuous verification over the lifecycle of an account and transaction is important because you are able to determine that a device changed, and the behaviors have drastically changed,’ Sando said. ‘You have to continuously verify that not only is this who they say they are, but it’s their device, their card, and that it’s typical of what they would normally be doing.’
Regulators Set New Benchmarks for Payment Fraud Prevention
Payment fraud prevention innovation is also being driven by regulatory change. In October 2025, the Eurozone made Verification of Payee (VoP) mandatory for all payment service providers (PSPs), with the requirement extending to non-euro-area PSPs by July 2027. Under the framework, PSPs must verify that a payee’s name matches the account information before executing both regular and instant SEPA credit transfers. The UK has adopted a parallel approach through Confirmation of Payee (CoP), designed to reduce the growing incidence of APP fraud.
In the United States, Nacha has introduced a phased set of ACH fraud monitoring rules that are already in force. According to Oscilar, Phase 1 became effective on 20 March 2026 and applies to originating depository financial institutions (ODFIs), receiving depository financial institutions (RDFIs), and non-consumer originators with ACH transaction volume of $1 billion or more. Phase 2, effective 19 June 2026, extends those requirements to Third-Party Senders, Third-Party Service Providers, and all originators regardless of volume, while also eliminating the volume threshold for RDFIs on credit monitoring.
The practical implication is substantial. As Unit21 sets out, covered institutions are required to implement risk-based procedures to detect and prevent fraudulently initiated and false-pretence ACH entries, including Same Day ACH payments. That is a meaningful lift for mid-size and smaller institutions that previously fell below the volume threshold.
The direction of travel across all these jurisdictions is consistent: responsibility for fraud prevention is shifting further onto banks, payment providers and other financial institutions. Intelligence sharing is also gaining ground. Rather than relying on isolated controls, institutions are collaborating to share fraud data across the payments ecosystem, using AI’s pattern-recognition capacity to surface threats that no single organisation would spot alone.
Customer feedback is feeding into the process too. ‘Customer feedback gives FIs a view into the areas of the customer journey that legitimate customers are experiencing unnecessary friction or false positives,’ Sando noted. ‘They can highlight inefficiencies or points of failure in fraud controls.’ With Phase 2 of Nacha’s new rules now in effect, institutions that have not yet mapped their ACH volumes against the expanded scope have a more immediate problem to solve.


























