The New Fraud Risk Many Businesses Are Not Prepared For

Fraud has always been a risk for financial services businesses, but the nature of that risk is changing rapidly. While organisations continue to focus on traditional cyber threats such as phishing emails, data breaches and account compromises, criminals are increasingly adopting artificial intelligence to create more sophisticated and convincing attacks. Deepfake technology, AI-generated communications, and voice cloning are becoming more accessible, more convincing, and harder to detect. Financial institutions and advice businesses are increasingly attractive targets.

Recent reports highlighted by Cyber Daily noted that deepfake scams have increased significantly over recent years, with financial institutions identified as a key target for AI-enabled fraud. The growing availability of AI tools allows criminals to generate realistic voices, videos, documents, and communications that can be used to impersonate clients, advisers, executives, and service providers. What previously required significant resources can now be achieved by bad actors with relatively limited technical expertise.

For AFSL and ACL holders, this creates a challenge that extends far beyond information security. Many compliance frameworks were developed when identity verification relied heavily on documentation, known client information, and direct communication. Those controls are increasingly being tested. A phone call that appears to come from a client, a request that sounds genuine, or a video conference that appears legitimate may no longer provide the level of assurance organisations have historically relied upon.

The risk is particularly relevant given the increasing use of digital communication methods across financial services. Clients expect speed, convenience and flexibility when engaging with businesses, but these same efficiencies can create opportunities for fraudsters. Instructions relating to withdrawals, account changes, investment transactions, or sensitive personal information may now require greater scrutiny than many businesses currently apply.

These threats are particularly concerning because they often target the human element of a control framework rather than the technology itself. Criminals know procedures can be bypassed when staff are under pressure, presented with convincing information, or encouraged to prioritise client service over verification requirements. In many instances, the failure is not a technology failure but a governance and process failure.

This challenge aligns closely with broader regulatory expectations around operational resilience, governance and risk management. Regulators increasingly expect organisations to understand emerging risks and demonstrate that controls remain fit for purpose. As AI-generated fraud becomes more prevalent, businesses may need to reassess existing procedures surrounding identity verification, authorisations, client instructions and transaction approvals.

A practical starting point is understanding where critical decisions rely on trust rather than verification. Businesses should consider whether sufficient safeguards exist when handling client instructions, changing personal information, processing payments or communicating sensitive information. Processes that previously worked may now need additional controls to address the changing threat landscape.

AI-enabled fraud is unlikely to slow. As the technology continues to improve, businesses that proactively assess their governance arrangements, operational controls and fraud prevention processes will be better positioned to protect both their clients and their organisations. The challenge is no longer preparing for a future risk. The risk is already here.

Call to Action

A common misconception is that fraud prevention is primarily an IT responsibility.

In reality, many fraud events occur because operational controls, approval processes, supervision arrangements or staff verification procedures fail. As AI-generated communications and deepfake technology become more sophisticated, businesses should be asking a simple question:

Would your current processes detect a convincing fraudulent instruction from a client, adviser or authorised representative?

AICS conducts independent AFSL and ACL License Reviews, Governance Reviews and Compliance Health Checks that assess whether your operational controls remain fit for purpose against emerging risks such as AI-enabled fraud, deepfake attacks and identity manipulation. Our reviews identify weaknesses in governance, monitoring, delegation and verification processes before they become incidents, complaints or regulatory concerns.

If you would like an independent assessment of your compliance framework, governance arrangements or operational controls, contact Cheyenne and the team to discuss your business at [email protected] or call 07 3251 2481.

References