Continuous fraud rescoring, shared AI prevention layers, and always-on compliance enforcement

By DripPublished

The gist

RegTech and FraudTech are shifting from point-in-time checks to continuous, shared, and execution-linked control layers that decide where risk data and workflow value accrue.

This week’s developments

Fraud Operations Shift From Detection to Continuous Rescoring

Alloy’s launch of Fraud Attack Radar and Fraud Signal this week extends the control layer we saw forming last week: the tools scan onboarding activity across a portfolio and combine onboarding, transaction, and behavioral data, with continuous monitoring tied into AI agents and workflows. SEON pushed the same direction with pre-onboarding screening using IP, digital-footprint, and device signals before KYC, plus real-time behavioral analysis for account takeover patterns such as suspicious remote access and screen-sharing. Fraud.net expanded to 50-plus payment-agnostic fraud scenarios and added agentic workflow features for investigation and remediation. UK banks closing 238,000 suspected mule accounts underscores why: exposure often appears after account opening, not just at signup.

Stripe warned that a single identity check can miss synthetic identities during the credit-building phase, while Plaid recommended real-time onboarding screening plus ongoing transaction monitoring. Group-IB, FICO, and TransUnion all pointed to lifecycle monitoring rather than approval-only checks. That makes continuous rescoring the product core, not an add-on. Stakk’s acquisition of ParaScript points to consolidation around broader trust platforms, while inDrive’s use of Zeeh for Nigerian driver KYC and Socure’s integration with Arc show embedded, market-specific verification becoming workflow infrastructure. For practitioners, the shift is now from building defensible onboarding gates to maintaining defensible fraud operations that can rescore, route, and remediate inside customer and compliance systems.

Where should fraud vendors invest to own the control layer?

If you operate in this industry

  • Fraud ops is becoming a live control loop, not a signup gate.
  • Build rescoring, routing, and remediation into core workflows or risk losing to platforms that monitor across the full customer lifecycle.

Sources

If you sell into this industry

  • Buyers now want continuous monitoring, not one-off identity checks.
  • Shift roadmap and GTM toward lifecycle scoring, agentic workflows, and embedded integrations; point tools without ops depth will get squeezed.

Sources

If you invest in this industry

  • Value is moving to platforms that own the fraud control layer.
  • Favor vendors with lifecycle data, workflow depth, and vertical embeds; standalone onboarding checks look increasingly commoditized.

Sources

  • What actually is VAMP? — Leading Detection, August 31, 2026

    Shows how remediation improves approval rates and portfolio growth while reducing fraud risk.

MAS Pilot Turns Cross-Bank Fraud Intelligence Into a Shared AI Operating Layer

MAS’s proof-of-value pilot with GovTech, the Singapore Police Force, and five banks pushes the story one step further: AI/ML models are being tested on historical bank transaction data plus public-private data to flag suspicious accounts and transactions in near real time across banks. The key shift is not just broader coverage, but cross-bank intelligence being exercised as a live decision loop, not a post-event reporting layer.

The vendor stack is reorganizing around that model. Feedzai’s Farol inside RiskOps Studio adds an embedded agent that summarizes alerts, analyzes rule performance, retrieves evidence, drafts SARs, and supports multi-step work; Feedzai says it can cut alert handling time by about 20% and make rule analysis 13x faster. Sardine’s unified AI agent hub points the same way: workflow-native orchestration is becoming the battleground, not detection alone. Brookfield’s reported interest in a $2 billion Actimize acquisition underscores that scaled fraud and compliance platforms still command strategic value when they control data access, workflow depth, and enterprise distribution.

Where will value accrue in cross-bank fraud AI operating layers?

If you operate in this industry

  • Cross-bank AI turns fraud defense into a shared operating layer.
  • Expect faster detection and higher scrutiny; build for data-sharing, workflow depth, and auditability or risk being disintermediated by platform players.

Sources

If you sell into this industry

  • Workflow-native AI is now the product, not just better detection.
  • Shift roadmap toward agentic case handling, SAR drafting, and evidence retrieval; buyers will pay for time saved, not model claims.

Sources

If you invest in this industry

  • Data access and workflow control are where fraud-tech value is concentrating.
  • Favor platforms with bank distribution and embedded ops; point tools without workflow ownership face margin and multiple pressure.

Sources

ProcessUnity Turns TPRM Evidence into an Execution Layer

ProcessUnity’s new AI agents for TPRM on September 16, 2026 pushed the story one step further: intake, due diligence, monitoring, remediation, and reporting are now automated, but each run is still wrapped in pre-execution controls, human sign-off for judgment calls, source attribution, confidence scoring, and a full audit log. Its Evidence Evaluator also validates vendor-submitted controls and flags missing evidence in the output, making proof part of the workflow rather than an afterthought.

That same execution-first pattern showed up across the week. Trustero and Onspring pushed autonomous evidence collection and control testing, Locktivity packaged live-system evidence into cryptographically signed archives, Strac captured screenshots and access reviews, Vanta extended continuous monitoring into agentic TPRM, and Itential and Diligent emphasized immutable action records and agentic evidence development. The market is no longer just assembling compliance artifacts; it is generating regulator-ready evidence at the moment of execution.

For practitioners, this extends the prior shift from workflow control to evidentiary control: buyers will increasingly choose platforms on evidentiary depth, and the value pool is moving to the orchestration layer that can make every AI or third-party risk action attributable, reviewable, and exportable as defensible audit output.

Where does defensible evidence create the next moat?

If you operate in this industry

  • Evidentiary control is now the competitive moat, not just workflow speed.
  • Prioritize audit-ready execution, source attribution, and human review or risk losing deals to platforms that prove every action.

Sources

If you sell into this industry

  • Buyers now pay for proof generation, not just compliance automation.
  • Shift roadmap and messaging to native evidence, confidence scoring, and immutable logs; point tools without them will get boxed out.

Sources

If you invest in this industry

  • Value is moving to platforms that turn actions into defensible evidence.
  • Favor orchestration layers with audit-grade AI controls; standalone workflow or evidence tools face margin and multiple pressure.

Sources

Transfer-Time Enforcement Tightens the Operating Layer

Italy has moved sanctions enforcement from customer onboarding to the moment of transfer: Bank of Italy–supervised PSPs and CASPs must screen both originator and beneficiary against EU and national lists before every funds or crypto-asset transfer, with no minimum threshold. The carve-outs are narrow. Instant payments can rely on at least daily screening under EU rules, and lighter treatment for some domestic Italy-to-Italy fund transfers does not extend to crypto.

South Africa, after exiting the FATF grey list, is tightening the practical standard by demanding more explicit, mainstream-style CDD: beneficial-ownership verification, PEP and sanctions screening, ongoing monitoring, and proof that controls work in practice. Brazil added a different layer of friction: a 24-hour precautionary hold for certain crypto transfers above US$10,000, or the daily cumulative equivalent, with customer notification and fraud-risk review, plus separate COAF reporting for self-custody transfers at that threshold. The hold rule takes effect January 1, 2027.

The strategic shift now extends the earlier move toward orchestration into the transfer layer itself. Buyers need systems that combine sanctions, CDD refresh, wallet-risk analytics, case management, and automated reporting in one auditable workflow. Manual exception handling becomes a scaling risk; vendors that own real-time decisioning and jurisdiction-specific automation gain the edge.

How do transfer-time screening rules change product and investment priorities?

If you operate in this industry

  • Transfer-time screening is now the control point, not onboarding.
  • Build or buy real-time sanctions/CDD/wallet-risk orchestration now; manual exception handling will break scale and auditability.

Sources

If you sell into this industry

  • Demand is shifting to live decisioning with jurisdiction-specific controls.
  • Prioritize transfer-layer workflows, daily/instant-payment logic, and automated reporting; point tools without orchestration will lose deals.

Sources

If you invest in this industry

  • Value is moving to platforms that control the transfer decision.
  • Back vendors with real-time orchestration and local rule depth; narrow point solutions face margin and bundling pressure.

Sources

Stay ahead in RegTech & FraudTech

Get the weekly RegTech & FraudTech brief in your inbox — the developments, what they mean by vantage, and what to do next.