Financial Crime Didn't Get Smarter. Transaction Monitoring Got Slower Relative to It
Key Takeaways
-
Retail real-time payment rails now settle irrevocably in seconds across most of APAC, the Gulf, the UK and Australia. Most transaction monitoring estates were designed for an era when a bank had hours, not seconds, to review a transaction before money actually moved.
-
The fraud pattern driving losses on these rails is overwhelmingly authorised push payment (APP) fraud - the customer authorises the transfer themselves, under manipulation - not stolen credentials. Bank Negara Malaysia found 95% of 2025's online fraud losses involved genuine, self-authorised transactions. A smarter model that still only flags a transaction after settlement cannot stop this pattern.
-
Regulators have stopped treating real-time detection as best practice and started writing it into binding rules with financial consequences: Singapore's Shared Responsibility Framework made real-time fraud surveillance and blocking a legal duty on banks from June 2025; the UK's mandatory APP reimbursement regime has already returned £316 million to victims since October 2024; Australia's Scams Prevention Framework rules commenced on 1 September 2026, two weeks before this article's publication.
-
Closing the gap is primarily an architecture and case-management problem, not a model-accuracy problem. A highly accurate fraud model that reports its verdict after settlement is operationally equivalent to no model at all under these rules.
-
A useful diagnostic - what we call the Interdiction Clock - breaks the problem into three latencies (signal, decision, action) that must together fit inside the rail's settlement window, not the institution's historical batch cycle.

The rails moved. The rulebook is catching up. The monitoring stack is still behind both.
Real-time retail payment rails are no longer the exception in banking - they are close to the default. Singapore's PayNow, Australia's New Payments Platform, Malaysia's DuitNow, India's UPI, the UK's Faster Payments and a growing list of interlinked cross-border fast-payment corridors all share the same defining property: once a payment is confirmed, it is settled, and it is very difficult or impossible to claw back (Bank for International Settlements, Committee on Payments and Market Infrastructures, 2021). The Committee on Payments and Market Infrastructures documented this shift as a structural one: fast payment systems are proliferating globally and increasingly settling obligations "on a payment-by-payment basis in real time," not in end-of-day batches (BIS CPMI, 2021).
That shift changed the economics of financial crime control more than it changed the sophistication of financial criminals. A transaction monitoring stack built around end-of-day or intraday batch review - score the day's transactions overnight, generate alerts in the morning, have an analyst work the queue by afternoon - was a perfectly reasonable design for a payments environment where settlement itself took a day or more. It is not a reasonable design for a rail that settles in single-digit seconds. The problem most BFSI technology leaders are actually facing in 2026 is not that fraud got smarter faster than detection models did. It is that detection infrastructure, case management workflows and intervention mechanisms were never redesigned for a world where the transaction is irreversible before a human - or in many stacks, even the model - has finished looking at it.
This matters more now than it did even two years ago, because the assumption that "we'll professionalise real-time monitoring eventually" no longer survives contact with three separate regulatory regimes that have each, independently, converted that assumption into a dated legal obligation with financial teeth.
Three regulators, three different mechanisms, one converging demand

Singapore moved first and most explicitly. The Shared Responsibility Framework (SRF) took effect on 16 December 2024, and after a six-month transition it became a live legal duty on 16 June 2025: financial institutions must "implement real-time fraud surveillance directed at detecting unauthorised transactions" where an account is being rapidly drained, and must either block the transaction (and subsequent ones) pending verification, or notify the account holder and hold the funds for at least 24 hours (Allen & Overy Shearman Sterling, 2026; Rajah & Tann Asia, 2026). The framework also imposes a mandatory 12-hour cooling-off period after a new device login or security-token activation, during which high-risk activity is blocked outright. Crucially, the SRF is a liability waterfall: the financial institution bears the loss first if it has not met these real-time obligations, before the telecom operator or the consumer are considered - with no cap on that liability (AO Shearman, 2026).
The United Kingdom took a different mechanism - mandatory reimbursement rather than a prescriptive surveillance duty - but arrived at a similarly unforgiving economic reality. Since the regime began in October 2024, UK payment service providers have processed 438,000 authorised push payment fraud claims. In the first quarter of 2026 alone, 89% of claimed value was reimbursed, totalling £72.6 million - the highest single-quarter figure since the policy began - and 82% of claims were resolved within five business days (Payment Systems Regulator, 2026). Put simply: the UK has now generated eighteen months of hard financial evidence, published quarterly by the regulator itself, of exactly how expensive it is to be the party holding an authorised-but-fraudulent transaction after the fact, rather than the party that stopped it before settlement.
Australia is the most recent and, for this article's timing, the most immediate. The Scams Prevention Framework's rules commenced on 1 September 2026 - thirteen days before this piece was published - with full sector codes for banks, telecommunications providers and designated digital platforms due to be fully in force by 31 March 2027 (Gilbert + Tobin, 2026). The Banking Code under the SPF requires regulated banks to maintain "reasonable systems to identify transactions or activities with a high risk of being or facilitating a scam," to issue a "clear, concise and timely warning" before a high-risk transaction proceeds, to take "proportionate action to identify whether it is, or is facilitating, a scam" before that transaction is made, and to be able to limit or hold high-risk transactions accordingly (Gilbert + Tobin, 2026, summarising the exposure draft Banking Code). Every one of those four obligations depends on a monitoring system that can produce a usable risk signal and a decision before the payment settles - not after.
None of these three regimes cite the same statute, use the same enforcement mechanism, or even share a common regional supervisor. Singapore built a real-time surveillance mandate. The UK built an economic reimbursement incentive. Australia built pre-transaction intervention obligations directly into its banking code. What they share is the underlying assumption: an institution's ability to detect and act on fraud risk must now operate inside the settlement window of the payment rail itself, not on the institution's own historical batch cadence. That is a genuinely new compliance baseline, not a restatement of an old one - and it has arrived within an eighteen-month window across three of the region's most significant BFSI markets.
What most institutions get wrong: this reads as a smarter-fraud story, and treating it that way misdirects the fix
It is tempting - and not entirely wrong - to describe 2026's fraud environment as more sophisticated than 2022's. Deepfake-enabled romance and investment scams, AI-generated identity documents, and early reports of autonomous "agentic" scam tooling are real and growing threats (Sumsub, 2026). Selfie-versus-ID document fraud in APAC rose 73% year-on-year in the twelve months to early 2026, and synthetic identity fraud rose 142% over the same period (Sumsub, 2026). Those are genuine escalations in criminal capability, and no transaction monitoring redesign fixes them on its own.

But the data on where the actual losses are concentrated tells a more specific - and more actionable - story. Bank Negara Malaysia's own 2025 fraud data found that 95% of online fraud cases involved genuinely authorised transactions: the account holder transferred the money themselves, having been manipulated by social engineering rather than having their credentials stolen (Bank Negara Malaysia, reported April 2026). This is the defining characteristic of authorised push payment (APP) fraud, and it is precisely the category every one of the three regulatory regimes above is built around. A traditional transaction monitoring model tuned to detect account takeover - unusual device, unusual location, credential-stuffing patterns - is not well suited to catching a transaction where the legitimate accountholder, from their own device, in their own location, willingly authorises a transfer to a scammer. What actually works against this pattern is behavioural and velocity-based signal generation - the speed and pattern of the transfer relative to the account's history, the destination account's own risk profile, the presence of recent security-setting changes - evaluated and acted on before the money leaves, because after settlement there is very often no "wrong device" or "wrong location" signal to retroactively flag at all.
That is the argument for treating this as a latency problem before it is a modelling problem. A more accurate fraud model that still reports its output on a batch cycle, or that generates a correct alert twenty minutes after an irreversible real-time payment has settled, has not moved the needle on the specific loss category driving most of the regulatory activity described above. The institutions that are actually closing the gap are not necessarily running better algorithms than their peers. They have redesigned the pipeline so that a risk score, a decision and an intervention action can all complete inside the rail's own settlement window.
The Interdiction Clock: a way to diagnose where your own gap actually sits
Because "we need real-time monitoring" is too vague to act on, it is worth breaking the problem into three latencies that must, together, fit inside the payment rail's settlement time - typically single-digit to low double-digit seconds on most modern retail fast-payment rails:

Signal latency - the time between a transaction being initiated and a usable risk signal (device, behavioural, velocity, destination-account, network) being available to a decisioning system at all. Many institutions' signal latency is dominated not by the fraud model but by upstream data plumbing: core banking events that only reach the fraud platform in near-real-time batches of their own, or third-party enrichment data (device intelligence, sanctions/watchlist checks) called synchronously against a service with its own latency budget.
Decision latency - the time for the risk signal to be scored and a clear action recommended: allow, step-up authentication, hold, or block. This is where model complexity genuinely trades off against speed, and where institutions often over-invest relative to the other two latencies, because it is the most visible and most easily benchmarked component.
Action latency - the time between a decision being made and it actually being enforced in the payment rail: holding the transaction, triggering a step-up challenge, or notifying the customer per frameworks like Singapore's 24-hour hold provision. This is frequently the longest and least-instrumented of the three latencies, because it depends on case management, orchestration and workflow systems that were built for analysts working an overnight queue, not for a straight-through decision that must reach the payment rail before settlement finalises.
The diagnostic value of separating these three is that most transaction monitoring modernisation budgets are spent almost entirely on decision latency - buying a faster or smarter model - while signal and action latency, which are architecture and integration problems rather than data-science problems, are left untouched. A bank can install the best fraud model available and still fail Singapore's real-time surveillance duty, the UK's reimbursement economics, or Australia's pre-transaction intervention requirement, if the signal never reaches the model quickly enough or the action never reaches the rail quickly enough.
Business and technology implications
For a CTO or CDO, the implication is architectural before it is analytical: streaming event architecture, synchronous low-latency calls to enrichment and watchlist services (or pre-computed risk profiles that avoid synchronous calls altogether), and a case management layer capable of enforcing a hold or step-up inside the settlement window rather than opening a case for a human to review afterward. For Risk and Compliance leaders, the implication is that "our model performs well in back-testing" is no longer a sufficient answer to a regulator asking whether a specific scam pattern would actually have been intercepted in production, inside the applicable time window, under the specific liability regime in force. For a COO, the implication is operational: analyst workflows built around working a morning alert queue do not map onto an obligation to intervene inside seconds, and headcount-based capacity planning for fraud operations needs to be rethought around exception handling and post-hoc investigation rather than primary interdiction.
A fair counterpoint deserves to be stated directly: real-time interdiction is not free, and false positives carry a real cost too - a step-up challenge or a held transaction on a legitimate high-value transfer is a customer experience cost, and Australia's own consultation material shows regulators actively debating where to set thresholds precisely because over-blocking has its own economic and reputational downside (Gilbert + Tobin, 2026). The right target is not zero friction and it is not maximum interdiction; it is a tuned system where the institution can demonstrate, with evidence, that its signal-decision-action latency fits inside its rails' settlement windows for the specific fraud typologies its regulator has prioritised - which for APP fraud specifically means behavioural and velocity signals rather than only credential-based ones.
What leaders should do next
Map your own signal, decision and action latencies against the settlement time of each payment rail you operate on, separately for each rail - a same-bank real-time transfer, an interbank fast-payment transfer and a cross-border fast-payment corridor can have materially different settlement windows and different applicable obligations. Identify where the historical case-management assumption of "an analyst will review this" still sits inside a path that is now supposed to complete inside seconds. And treat the specific regulatory regime your institution operates under - the SRF's real-time surveillance duty, the UK's reimbursement dashboard economics, or Australia's pre-transaction Banking Code obligations - as the concrete design specification for your intervention latency, not as a compliance checkbox layered on top of an unchanged architecture.
The source[code] perspective
From source[code]'s work inside BFSI technology delivery, the pattern above is consistent: the fraud models banks buy or build are rarely the binding constraint. The binding constraint is almost always the surrounding plumbing - whether a risk signal can reach a decisioning engine, and whether a decision can reach the payment rail, inside a window measured in seconds rather than minutes or hours.
That is an engineering and systems-integration problem as much as it is a data-science one, and it is where an experienced delivery partner adds the most practical value: not replacing the fraud model, but closing the signal-to-action latency around it so that the model's output actually arrives in time to matter under the specific regulatory regime an institution operates in.
Conclusion
The uncomfortable framing in this article's title is deliberately provocative, and it is also, on the evidence, largely accurate for the specific loss category regulators are now targeting. Financial crime has become more sophisticated in some real respects - deepfakes and synthetic identity are genuine escalations. But the losses driving Singapore's, the UK's and Australia's new rules are overwhelmingly authorised, behaviourally-manipulated transfers on rails that settle before a batch-era monitoring stack has finished thinking about them.
Three different regulators, using three different legal mechanisms, have converged on the same underlying requirement within an eighteen-month window: detection and intervention capability has to live inside the payment rail's own clock.
Institutions that treat this as a model-upgrade exercise will keep buying more accurate answers that arrive too late to change the outcome. Institutions that treat it as an architecture and latency exercise have a genuine, measurable target to design against. Talk to us!
Frequently Asked Questions
What is real-time transaction monitoring? Real-time transaction monitoring is the capability to generate a fraud or financial-crime risk signal, score it, and act on that score (allow, challenge, hold or block) before a payment settles - as opposed to batch monitoring, which reviews transactions after they have already cleared.
Why does authorised push payment (APP) fraud matter more than account takeover fraud on real-time rails? Because the account holder authorises the transfer themselves under manipulation, the usual account-takeover signals (unfamiliar device, unfamiliar location, credential-stuffing pattern) are frequently absent. Bank Negara Malaysia found 95% of 2025 online fraud losses in Malaysia involved genuinely authorised transactions, which is why behavioural and velocity-based detection, evaluated before settlement, is the more relevant control.
How does this affect banks and insurers evaluating new fraud or payments technology? It changes the evaluation question from "how accurate is the model" to "what is the combined signal, decision and action latency of the full pipeline, measured against the settlement time of each payment rail in scope, and does that fit inside the applicable regulatory obligation."
What should CTOs and CDOs consider first? Map signal, decision and action latency separately, per payment rail, before evaluating any new fraud model. A faster or smarter model does not close the gap if the surrounding data plumbing or case-management workflow cannot deliver or enforce its output inside the settlement window.
What are the risks of getting this wrong? Beyond direct fraud losses, the risk is now explicitly regulatory and financial: Singapore's SRF places uncapped liability on financial institutions that have not implemented real-time surveillance and blocking; the UK's reimbursement regime has already returned £316 million to victims since October 2024, funded by industry; Australia's Scams Prevention Framework, in force from 1 September 2026, creates equivalent obligations under its Banking Code.
How should organisations evaluate their current transaction monitoring architecture? Separately assess signal latency (can a usable risk signal reach a decisioning engine fast enough), decision latency (can that signal be scored and an action recommended fast enough) and action latency (can that decision actually be enforced in the payment rail fast enough) - each measured against the settlement window of every payment rail in scope, not against an internal service-level target set independently of the rail.
Reference List
Bank for International Settlements, Committee on Payments and Market Infrastructures (2021) Developments in retail fast payments and implications for RTGS systems, CPMI Papers No. 201. Available at: https://www.bis.org/cpmi/publ/d201.pdf (Accessed: 14 September 2026).
Bank Negara Malaysia (2026) Most online fraud losses in Malaysia driven by victims' own transactions, as reported in The Vibes, 4 April 2026. Available at: https://www.thevibes.com/articles/news/121500/most-online-fraud-losses-in-malaysia-driven-by-victims-own-transactions-bnm-reveals (Accessed: 14 September 2026).
AO Shearman (2026) Combatting payment account fraud: Singapore's Shared Responsibility Framework. Available at: https://www.aoshearman.com/en/insights/ao-shearman-on-fintech-and-digital-assets/combatting-payment-account-fraud-singapores-shared-responsibility-framework (Accessed: 14 September 2026).
Rajah & Tann Asia (2026) MAS and IMDA set out duties and liability of financial institutions and telcos in mitigating digital scams. Available at: https://www.rajahtannasia.com/viewpoints/mas-and-imda-set-out-duties-and-liability-of-financial-institutions-and-telcos-in-mitigating-digital-scams/ (Accessed: 14 September 2026).
Payment Systems Regulator (2026) APP scams reimbursement dashboard for Q1 2026, updated 30 July 2026. Available at: https://www.psr.org.uk/information-for-consumers/app-scams-reimbursement-dashboard/ (Accessed: 14 September 2026).
Gilbert + Tobin (2026) 'Click here': Australia's Scam Prevention Framework takes shape. Available at: https://www.gtlaw.com.au/insights/click-here-australias-scam-prevention-framework-takes-shape (Accessed: 14 September 2026).
Sumsub (2026) APAC Fraud in 2026, published 10 April 2026. Available at: https://sumsub.com/blog/guides-reports/apac-fraud-in-2026/ (Accessed: 14 September 2026).
ComplyAdvantage (2026) Real-time payments in APAC and what they demand of compliance, published 24 July 2026. Available at: https://complyadvantage.com/insights/what-apacs-payments-shift-demands-of-compliance/ (Accessed: 14 September 2026).