
Fraud is scaling faster. Payment fraud screening has to match.

By Kevin Bailey
Chief Information Officer & Chief Information Security OfficerShare
Fraud used to be constrained by cost and labor: skilled operators, targeted research, and convincing impersonation at scale, with each requirement capping how many attacks could run at once. AI is removing those constraints. BCG estimates the cost of running a financial scam will fall by 90% or more within two years, leading to a twofold or greater surge in attack volume.
When fraud becomes cheap to run, volume becomes the weapon, and the defense architecture has to match.
AI-assisted fraud operations are driving the shift. Fraud operations increasingly use AI to draft more convincing lures, generate cloned voices, and compress weeks of reconnaissance into hours, with a human still directing the operation. BCG's projection describes what comes next: agentic systems that set goals, orchestrate multi-step execution, and adapt in real time without a human directing each step.
The current numbers already show a serious control gap. According to AFP's 2026 Payments Fraud and Control Survey, 76% of U.S. organizations experienced attempted or actual payments fraud last year, while just 17% use AI to detect it. Kyriba's global 2026 CFO Survey shows the same pattern from the other side: 77% of CFOs worldwide flag security and privacy as a risk to their company's financial health, but fewer than one in three named security and fraud prevention as a critical operational priority for 2026.
The gap is architectural, not informational. Understanding that gap starts with payment fraud screening and how it holds up against an attack surface that moves at this speed. Closing it requires three capabilities working together: screening every payment, detecting behavioral anomalies in real time, and authorizing payment release based on current risk.
Volume turns treasury controls into an attack surface
Corporate treasury has always been a high-value target. What changes is the cost structure of attacking it. Fraudsters run their schemes with AI assistance today, and BCG's agentic projection points to fraud operations needing even less human involvement, testing controls, learning what triggers review, and adjusting until a path opens, at a volume no human-run team could match.
Treasury's exposure comes from a familiar set of characteristics: high-value payment volumes, multi-counterparty approval chains, and AP processes that depend on human judgment at critical release points. A payment fraud screening environment designed to catch one sophisticated attempt per quarter will not hold against thousands of adaptive attempts per week.
The cost asymmetry compounds the exposure. In my experience, a single undetected fraudulent wire transfer often costs more than the annual investment in the detection controls that would have prevented it. As attack economics improve for adversaries, the asymmetry widens.
Fraud vectors that exploit different workflow weaknesses
Each vector targets a different point in the payment workflow. Together, they define the treasury attack surface.
Business email compromise (BEC). At its simplest, BEC bypasses technical infrastructure entirely: a convincing instruction reaches someone with authority to act on it. BEC is frequently technical too, running through account takeover, domain spoofing, or lookalike domains that get an instruction past the mail server before a human sees it. AI is already sharpening both variants through better lure copy, faster reconnaissance from public and compromised sources, and executive impersonation that references the right vendors and counterparty details. As agentic systems mature along the path BCG describes, the volume of campaigns will increase beyond the capacity of human-run operations.
Payment redirection and invoice fraud. Fraudulent banking details enter AP workflows at the moment of lowest scrutiny. The operation stays inside normal transaction parameters until it succeeds, which makes the payment appear legitimate to controls built around static rules.
Impersonation at scale. Voice cloning and synthetic identity generation are increasingly accessible capabilities. Fraud operators can run simultaneous campaigns, using AI to calibrate each to a target's communication style and authorization workflow. Personalization that once required a large, skilled team is increasingly automated. These campaigns are designed to clear the human review layer that many fraud controls rely on.
Each vector attacks a different layer of the workflow. BEC pressures human judgment, invoice fraud exploits counterparty data, and impersonation tests authorization discipline. All three converge on the same moment: a payment sitting at the release point, waiting on a decision.
Why a single point of authorization is the real exposure
As CISO, the pattern I encounter most consistently is an authorization architecture designed for operational efficiency that was never pressure-tested against an adversary with the patience and tooling to probe it at volume.
Automated fraud campaigns are built to exploit that weakness. Single-approver workflows for high-value transactions are a known attack path. AI-assisted BEC campaigns help operators identify those workflows, time instructions around known payment cycles, and run campaigns at greater scale.
Consider a concrete example. A vendor's email account was compromised three weeks earlier, quietly, with no ransom demand and no visible damage. That single point of access makes everything that follows possible. A fraud operator, using AI tools to mine the compromised inbox for invoice threads, payment terms, and calendar entries, identifies a $2.3 million wire scheduled for Friday. By Wednesday, the operator has generated a spoofed CFO instruction, drafted and refined with AI, referencing the correct vendor, amount, and counterparty, timed to reach the single AP approver when the payment window is open.
The email compromise creates the opportunity. The exposure is what happens next: compromised information reaches a workflow with a single approval point, and that one approver has the power to convert a fraudulent instruction into an authorized payment. No amount of technical sophistication in the spoofed instruction matters if a second, independent check stands between it and the funds leaving the account.
A human fraud operator is still directing every step here. BCG's agentic projection describes this same scenario running without one, adapting in real time with no operator in the loop. Authorization architecture is the control built to hold regardless of who, or what, is directing the attack.
The screen-detect-authorize model: what effective payment fraud screening requires
Closing that exposure takes more than one control. The screen-detect-authorize model layers three capabilities, each covering a failure point the others miss.
Screen every payment. Rule-based controls remain necessary, and no mature program should remove them; they catch known patterns reliably and cheaply. Their limitation is predictability. A rule flags what it was configured to flag, and an automated fraud system that encounters one adapts its approach until it finds a path the rule does not cover, which is exactly what thousands of adaptive test attempts are built to find. Effective payment fraud screening removes that predictability problem by evaluating counterparty data, behavioral signals, and contextual anomalies simultaneously, for every transaction, before the payment releases rather than after.
Detect abnormal behavior. Behavioral anomaly detection catches what screening alone cannot: a payment that looks normal under every individual rule but falls outside the established pattern for the counterparty, account, or payment type. In control environments I have reviewed, the window between a fraudulent instruction entering a workflow and funds leaving the account can be shorter than the review cycle designed to catch it, which makes the first detection decision the highest-stakes one in the workflow. Behavioral detection is not infallible either; attackers who understand they are being profiled can shape behavior gradually to blend into a baseline. That is why it has to work alongside rules and authorization controls rather than replace them.
Authorize release dynamically. Payment authorization controls prevent unilateral release through segregation of duties. Above defined thresholds, no individual should hold unilateral authority, and the workflow should require dual control or four-eyes review. That structure still has to keep moving: authorization chains should adapt to payment size, counterparty history, and real-time risk signals rather than operate as a fixed sequence a sophisticated fraud operation can map.
Each capability addresses a distinct weakness. Screening catches volume, behavioral anomaly detection catches adaptation, and payment authorization controls eliminate the single points of failure that make the other two necessary in the first place. No single layer stops a well-resourced fraud operation; the combination is what closes what rules alone leave open.
Pressure-test the controls before the next payment releases
Five dimensions every finance team should evaluate across the screen-detect-authorize model:
Payment fraud screening coverage: Does screening run on every transaction, or only on sampled and flagged payments? Automated fraud is calibrated to stay below sampling thresholds. Coverage limited to sampled payments creates a known blind spot.
Detection adaptability: Can behavioral anomaly detection update to a new attack pattern without a manual rule change? If it cannot, detection will lag the fraud it is designed to catch. That lag often becomes visible in loss events and exception volume before it shows up anywhere else.
Payment authorization controls architecture: Do approval workflows contain single points of failure a targeted BEC or impersonation campaign could exploit? Identifying those points is where control redesign starts.
Monitoring continuity: Does fraud monitoring operate in real time, or does it introduce review-cycle latency an automated system can route around? Speed of detection is a control requirement.
Auditability: Can the organization produce a complete audit trail on demand for every payment authorization within defined scope, including a timestamp? The trail is both a detection input and the first document an audit committee will request after a loss event.
The bottom line
The payment fraud risk profile for corporate treasury is not going to stabilize. BCG gives finance teams a two-year forecast window before agentic systems materially change the economics of financial scams, and the 17% of organizations already using AI for fraud detection are building experience the rest of the market does not yet have.
Organizations treating payment fraud as a periodic review problem will find it is a real-time balance sheet problem. If I were briefing your board next quarter, here is what I would tell them. Before money moves, three things have to be true: the payment was screened, the action was authorized, and the trail is auditable. Finance teams that build payment fraud screening, behavioral anomaly detection, and payment authorization controls into their control architecture are the ones who can make that case. The screen-detect-authorize model is what I would put in front of any audit committee, and it belongs in front of yours.
That same approach shapes how we handle payment security at Kyriba.
Written By

Kevin Bailey
Chief Information Officer & Chief Information Security Officer
Kevin Bailey is Kyriba's Chief Information & Security Officer, driving enterprise-wide digital transformation while building world-class security capabilities. With more than 15 years of technology leadership experience, Kevin leads initiatives spanning cloud modernization, IT infrastructure optimization, and security program development across complex global environments. He specializes in aligning technology investments to business outcomes, scaling security operations, and delivering measurable results in both innovation and risk management. Kevin's integrated approach ensures that digital transformation and security work in tandem to accelerate business growth and strengthen organizational resilience.
Related resources


AI payment fraud and a shifting threat landscape: why CFOs need proactive payment controls
Learn more