Patralekh Satyam
Menu
Topic

Fraud decisioning: catch more, block fewer

In brief

Patralekh Satyam sets out the DECIDE framework for fraud decisioning in digital banking, from his book Moments of Trust (2026): Define the moment, Establish confidence, Contextualize behavior, Integrate signals, Decide explicitly, Evolve. The approach was tested on a consumer account opening platform he delivered for a large North American credit union, which auto-declined fraudulent applications with 98% accuracy while genuine applicants finished in under three minutes and completion stayed above 80%. The page draws on Alloy's 2026 State of Fraud Report and the Cornerstone Advisors 2026 Digital Banking Performance Metrics for industry context.

Opening

Fraud decisioning is the set of choices a bank makes in the seconds between an application arriving and an answer going back. Ninety-one percent of financial institution decision makers say more financial crime is now committed with AI, and 89% rank synthetic identity creation as the most concerning tactic. The instinct is to add checks. The evidence from production is that adding checks for everyone drives away genuine customers and barely slows fraudsters. Moments of Trust sets out a different discipline, DECIDE, and the credit union platform I delivered is where it was tested: 98% of fraudulent applications auto-declined accurately while genuine applicants finished in under three minutes and completion stayed above 80%.

Why adding checks stopped working

For a long time the fraud answer to a new threat was another gate. A new document to upload, a new set of knowledge-based questions, a phone call before approval. Each gate was reasonable on its own, and together they produced flows that genuine applicants abandoned in large numbers. For every account opened online today, 3.36 applications are abandoned.

The gates also stopped working against the fraud they were built for. Knowledge-based verification assumed that only the real person knew their previous addresses or the make of their first car. That assumption has failed, because enough personal data has leaked over the years that a fraudster assembling a digital dossier can often answer those questions more reliably than the real applicant, who has to remember. Synthetic identities, built from fragments of real data and invented details, pass the checks that look for a match because the fragments match. And AI-generated documents mean a document upload proves less than it used to.

The response cannot be more of the same gate. It has to be a different read of the application: many signals, weighed together, producing a decision with a stated confidence, and a step-up reserved for the cases where confidence is low.

The six moments

DECIDE names six moments of trust in onboarding, and each is a decision the institution is making whether it knows it or not.

Define the moment: name each decision point in the journey and what a wrong answer costs in either direction. A false decline loses a genuine customer and everything they would have brought; a false approval books a loss and a compliance exposure. Until both costs are written down, the thresholds that follow are guesses.

Establish confidence: decide what evidence is sufficient for an automatic yes and an automatic no. This is where the institution states, in advance, the standard a case has to meet to be decided without a human. Writing it down is what makes the automation defensible later.

Contextualize behavior: read the application against how genuine applicants behave, not only against blacklists. How long a field took to fill, whether the device has been seen before, whether the email address has a history, whether the pattern of this application resembles the pattern of the last thousand genuine ones. Lists catch the fraud already known; context catches the fraud that is new.

Integrate signals: bring identity, device, credit, consortium and behavioral data into one decision rather than a sequence of gates. A sequence lets a case fail on one weak signal that the others would have outweighed, and it lets a fraudster pass one gate at a time. A single decision weighs all of it at once.

Decide explicitly: every outcome is approve, review or decline, with a recorded reason, never a silent drop. Applications that simply stall, or that are quietly abandoned by the system rather than the applicant, are the ones nobody can explain afterwards.

Evolve: feed reviewer decisions back so thresholds move with the fraud. What the review queue learns this month is what the automatic decision should know next month.

Intentional friction

Friction is a tool, not a failure, when it is applied to the applications that need it. A five-second step-up for an ambiguous application raises completion overall, because the other 98% never see it. The institutions that lose on both ends are the ones that apply the same friction to everyone.

There is a second effect that is easy to miss. A genuine applicant who is asked for one extra step, at the right moment and with a clear reason, often reads it as a sign that the institution takes their security seriously. Friction applied surgically becomes a trust signal. The same step applied to everyone, early, and without explanation reads as an obstacle, and it is the obstacle that drives abandonment. The design question is therefore never whether to have friction but where, for whom, and why.

The modern fraud prevention stack makes that targeting possible. Identity and document verification, liveness, email reputation and device intelligence each answer a different question about the applicant, and each matters at a different moment in the journey. Ranked and layered, they let the platform get the large majority of legitimate applicants through with nothing extra while raising the cost for the fraudster at exactly the point where the fraudster is weakest.

What the credit union platform showed

The consumer account opening platform I delivered for a large North American credit union is where this design was tested in production. Roughly twenty integrations, including identity verification, address validation and credit data, feed a decisioning layer that decides 98% of applications straight through and routes 2% to bankers. On the fraud side the same layer auto-declined fraudulent applications with 98% accuracy. Genuine applicants opened an account in under three minutes, completion stayed above 80%, and the institution went from under two hundred online accounts a month to more than a thousand applicants in its first month live. Every approved applicant was also enrolled in online banking in the same session, which matters here because a fraud-conscious design that still ends in a hand-off has not removed the abandonment point; it has only moved it past the decision.

Those numbers are one design seen from two sides. The confidence that lets the platform approve without a banker is the same confidence that lets it decline without one. Loosening one to help the other is the old trade-off returning by the back door.

Why this is a governance problem

A decision that cannot be explained to an auditor is not a decision a regulated institution can automate. DECIDE's "decide explicitly" and "evolve" steps are what make auto-decisioning defensible: a recorded reason on every outcome, a review queue with human judgment where confidence is low, and a feedback loop that documents why thresholds changed.

This is the same shape as the compliance auditing platform I delivered for American Express in 2020, where every call was scored with reasons and low-confidence cases went to human review. That system scored each recorded telesales call for the mandatory disclosures and the customer's explicit consent, routed failures and low-confidence cases to reviewers with jump-to-timestamp playback, and fed the reviewers' decisions back to improve the models, with PII redaction, encryption, role-based access and a full audit trail. None of it was generative AI. All of it was the governance that fraud decisioning needs today: explicit outcomes, reasons attached, humans where the machine is unsure, and a documented loop that shows how the system learned.

Fraud decisioning done this way is not a compliance burden laid on top of a growth objective. It is what lets a regulated institution grow digitally at all. The page on /ai-governance-in-banking covers the wider operating model; Moments of Trust covers the decisioning design in full.

Questions

What is the DECIDE framework?

Six moments of trust in onboarding: Define, Establish, Contextualize, Integrate, Decide, Evolve, from the book Moments of Trust (2026).

Can fraud decisioning be automated in a regulated bank?

Yes, when every outcome carries a recorded reason and low-confidence cases route to human review; the credit union platform auto-declined fraud with 98% accuracy.

Does more fraud control mean more abandonment?

Not when friction is targeted; on the same platform completion stayed above 80%.