5 min read
The widespread availability of open-source AI is making fraud harder to catch—and easier to commit. It helps fraudsters generate polished emails and impersonate familiar contacts at scale. Across the J.P. Morgan Commercial & Investment Bank, attempted fraud volume rose more than 20% every year for the last 5 years.1
But AI is also helping detect and prevent fraudulent payments.
“It’s continuous adaptation,” said Joel Kalamba, business analysis director at J.P. Morgan. “Fraudsters evolve, but so do we—using AI to help detect subtle anomalies and sophisticated attacks.”
Kalamba and Nick Smallwood, data scientist at J.P. Morgan, explain how AI for fraud detection supports payment security—and why time-tested fraud prevention strategies remain critical to protecting your business.
Detecting fraudulent payments starts with identifying activity that deviates from expected behavior. This may include unusual transaction characteristics, payment patterns or behaviors that warrant additional scrutiny.
AI models are trained on millions of transactions and generate risk scores, which help teams decide when to flag a payment for client review before it's released.
However, AI is just one piece of a multifaceted fraud detection strategy—and it isn’t new. The machine learning models in use today represent an evolution from traditional fraud detection tools in banking, such as linear regression and decision trees.
AI is expanding what those tools can identify, using methods including:
Graph analysis, which maps every party and payment in a dataset into a single connected picture, helping illuminate possible suspicious links. For example, a first-time payment that looks fine on its own can prove risky once you see that the sender is potentially linked to fraud flagged at another company. This is particularly useful with virtual cards, which are designed for single use.
Transformer models—the same technology behind large language models—help surface subtle relationships in a dataset that no rule was written to catch. Using attention mechanisms to focus on the most relevant signals, they can help detect nuanced patterns that point to potential fraud.
Incorporating AI and machine learning into fraud prevention offers three main benefits:
1. New types of data: AI can help fraud prevention systems use data that couldn’t previously be analyzed at scale. For example, language models can interpret non-standard, free-text records linked to ACH payments—pulling more information out of each transaction.
2. Large-scale data processing: AI and machine learning systems can analyze billions of data points, surfacing subtle patterns that signal fraud. “With more traditional approaches, the more features you add to the analysis, the more complex and difficult it can become,” Smallwood said.
3. Targeted detection: Traditional fraud detection models require heavily structured data. Newer machine learning models need less structure to identify important signals. “The fraud we see is truly a needle in a haystack, if you look at how many transactions we process. Newer models’ ability to focus helps with that problem,” Smallwood said.
The goal: more precise detection that helps stop fraud attempts while reducing the friction and alert fatigue caused by false positives. AI and machine learning techniques are particularly powerful when combined with data on the $12 trillion in payments J.P. Morgan processes each day.
“We’re able to analyze and learn from large, diverse transaction flows, and leverage that data in a way we couldn’t before,” Kalamba said.
AI fraud detection solutions can help protect payments. But even with new technology, the fundamentals haven’t changed.
“Technology combined with strong internal controls is what keeps clients safeguarded,” Kalamba said. “A lot of times, when someone realizes they’ve been duped, it’s because those controls got lost or something slipped through the cracks.”
Stick to your processes: “People have a tendency to think they couldn’t get scammed. It’s this bias we all have, that we believe in our own faculties and abilities,” Smallwood said. Following strict standard operating procedures—for example, verifying any change in payment instructions using a phone number from a reliable system of record—can help your team interrupt that bias and spot red flags.
Strengthen validation practices: The rise of affordable, convincing deepfakes makes it even more important to authenticate requests for payments, credentials or other sensitive information. “We’re seeing more emphasis on validation of knowledge,” Smallwood said. “If someone who sounds like your CFO asks you to make an urgent payment, do you have pieces of information you can use to validate their identity?”
Communicate with your banker: The more you tell your bank about your company’s payments, the more precise its fraud detection can be. Wires and ACH payments have built-in mechanisms for sharing transaction information that can help your bank spot potential fraud or avoid false positives. And if your company expects unusual payment activity—for example, a spike in volume or transactions in a country where you don’t typically do business—tell your banker in advance. “It takes strong collaboration,” Kalamba said. “The more accurate data we have, the better we’re going to be—and the better the client experience will be.”
We’re continually investing in AI and enhancing our fraud prevention solutions to help you protect your business as threats evolve. Whether you’re looking to strengthen authentication technology, safeguard payments or train your team on prevention strategies, J.P. Morgan bankers and industry specialists can help you get there.
JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non deposit products are not FDIC insured. Visit jpmorgan.com/cb-disclaimer for disclosures and disclaimers related to this content.