Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

AI-Enhanced Fraud Is Now the OCC's Top Operational Risk Concern. Here's What That Means for Your Fraud Risk Program.

The OCC's Spring 2026 Risk Perspective named fraud the primary driver of operational losses. But having a fraud operations team isn't a fraud risk program — examiners want second-line oversight, documented loss events, and KRIs that signal emerging exposure.

By Rebecca Leung · July 15, 2026 ·
Table of Contents

The OCC examiner’s question during the on-site visit was direct: “Who in your second line owns fraud risk oversight?” The community bank’s compliance officer paused. The fraud team was excellent — they caught things early, had good case management, and had kept loss rates below peer. But a second-line fraud risk program? That was the fraud team’s job.

It wasn’t the answer the examiner was looking for.

That dynamic is playing out across the federal banking system in 2026. The OCC’s Spring 2026 Semiannual Risk Perspective, released in May, named fraud the primary driver of operational losses — and the exam community is taking it seriously. But the gap most institutions are discovering isn’t their fraud operations capability. It’s their fraud risk governance.

TL;DR

  • The OCC’s Spring 2026 Semiannual Risk Perspective named fraud the primary driver of operational losses across the federal banking system
  • AI is reshaping the fraud threat landscape: impersonation scams via text and social media are more sophisticated and cheaper to scale than ever
  • Most banks and fintechs have a fraud operations team (first line) — far fewer have a fraud risk program (second line oversight, loss event tracking, KRI monitoring, risk governance reporting)
  • The OCC’s 2026 community bank exam rightsizing makes second-line documentation MORE important, not less — examiners rely on your risk functions to draw risk conclusions
  • Fraud loss event classification is where most programs have silent gaps: events coded only as External Fraud when they had internal control dimensions

What the OCC’s Spring 2026 Report Actually Said

The OCC releases a Semiannual Risk Perspective twice a year as a public signal of examiner priorities. The Spring 2026 edition, released in May, covered the full range of risk themes — credit, market, operational, and compliance — but the operational risk section contained language that hasn’t appeared in prior editions.

Fraud was named “a primary driver of operational losses.” The specific emphasis was on the sophistication trajectory: impersonation scams facilitated by social media and text messages are rising in sophistication at the same time that AI is “lowering the barrier to entry for threat actors” by enabling automated reconnaissance, targeted social engineering, and adaptive attacks that evade traditional controls.

The report also flagged foreign state-sponsored actors as an elevated and persistent threat — not specific to fraud, but part of the same operational risk landscape.

What makes this notable isn’t any single data point. It’s the convergence: fraud is already the top operational loss driver, AI is making fraud attacks cheaper and more scalable to execute, and the OCC’s 2026 exam focus is explicitly on operational risk. That combination creates a specific examiner expectation: your fraud risk program needs to be ready to answer for all three dimensions.


Why Fraud Operations Isn’t a Fraud Risk Program

The distinction matters enormously in an examination context, and it’s where most banks and fintechs have a gap.

Fraud operations (first line): The team that detects fraud events, investigates cases, manages fraud disputes, recovers losses, and optimizes fraud models. They operate prevention and detection controls. They handle regulatory notifications when an event requires it. They report fraud metrics — case volumes, loss amounts, recovery rates — to management.

Fraud risk program (second line): An independent function that assesses whether the first line’s controls are adequate relative to the institution’s fraud risk exposure, monitors KRIs to identify emerging risk, reviews loss event data for control gaps, tests the effectiveness of key controls, and reports to risk governance on whether fraud risk is within appetite.

These are different functions. Fraud operations can produce excellent metrics and still have no one independently evaluating whether those metrics indicate the risk is being managed adequately. An institution running its fraud team well but with no second-line oversight is, from an examiner’s perspective, missing a governance layer.

The OCC’s examiner handbook and the broader interagency guidance on operational risk governance are consistent on this point: the risk function should provide independent challenge to the business line’s risk management. For fraud, that means an independent assessment of fraud risk exposure, not just a report on the fraud team’s performance metrics.


How AI Is Changing the Fraud Threat Landscape

The Spring 2026 Risk Perspective’s identification of AI as a threat enabler is grounded in specific changes to the fraud attack surface.

Impersonation at scale. AI voice synthesis and text generation make it possible to impersonate an institution’s employees, government officials, or trusted counterparties with a degree of fidelity that previously required significant effort. A social engineering call that once required a skilled actor can now be partially automated, customized by target, and deployed at volume.

Synthetic identity fraud. AI-generated synthetic identities — combinations of real and fabricated information — have become harder to detect at account opening. Traditional CIP controls were designed for conventional document fraud; synthetic identity requires behavioral and analytical signals that many institutions aren’t monitoring.

Business email compromise (BEC) evolution. AI tools that can analyze email threads and generate plausible follow-on communications have moved BEC from a manual craft to a semi-automated attack. Wire transfer fraud executed through BEC has historically been the largest single category of cybercrime losses, and the attack methodology is getting more scalable.

Adaptive attacks. AI-assisted malware and fraud tooling can be modified to evade detection patterns. Fraud models trained on historical fraud patterns can be gamed by attackers who test and iterate their approach against the institution’s visible defenses.

This doesn’t mean a bank’s fraud controls are ineffective. Banks are also deploying AI for fraud detection and behavioral monitoring. The OCC report specifically noted that banks are taking a “measured approach” to generative and agentic AI, with limited use cases and human-in-the-loop accountability as the current standard. But the threat landscape has shifted, and a fraud risk program built around pre-AI threat models needs to be assessed against the current attack surface.


What a Second-Line Fraud Risk Program Actually Requires

Building a fraud risk program that satisfies examiner expectations doesn’t require reinventing the institution’s entire operational risk framework. It requires applying your existing operational risk governance structure specifically to fraud — and producing the documentation that lets an examiner follow the logic.

Fraud Risk Assessment. Conducted at least annually (more frequently if the fraud threat environment or the institution’s product mix changes significantly). The assessment identifies fraud risk categories relevant to the institution — card fraud, wire fraud, ACH fraud, check fraud, application fraud, account takeover, insider fraud — evaluates the adequacy of controls for each, assigns an inherent and residual risk rating, and identifies gaps for remediation. This is a second-line document, not a fraud team operations report.

Loss Event Database. Every fraud-related operational loss should be captured in the institution’s loss event database. This is not the fraud case management system — it’s the operational risk database that tracks losses by event type, root cause, business line, and control failure dimension. Basel event type ET3 (External Fraud) is the primary category, but losses that also involved an internal control failure need to be coded with the relevant control dimension. Many institutions run their fraud team’s case management system separately from the operational risk loss database, resulting in loss data that’s never analyzed for control patterns.

Fraud KRI Monitoring. Core fraud KRIs monitored against defined thresholds and reported to risk governance. The standard set includes:

KRIThreshold SignalEscalation Trigger
Fraud loss rate (losses / total transactions)Rising quarter-over-quarterExceeds peer benchmark or defined amber threshold
Fraud attempt volume trendSustained increase20%+ increase over 90 days
Account takeover event volumeAny sustained increase>50% increase over 90 days
Social engineering claim rateEmergingAny increase in phishing/vishing/smishing claims
Time-to-detect (confirmed fraud events)Trending upExceeds defined SLA
False positive rate (transaction monitoring)Trending upSignificant increase affecting customer experience

Independent Control Testing. The second line should independently test at least the highest-risk fraud controls — transaction monitoring calibration, authentication controls on high-value transaction paths, and wire transfer verification procedures — on a defined schedule. This is distinct from the fraud team’s own review of its operations.

Risk Governance Reporting. The risk committee or board-level risk reporting should include a fraud risk section at least quarterly. The section should cover KRI status, significant loss events, emerging threats, and program adequacy assessment. If your board report includes fraud case counts from the fraud team but no second-line assessment of whether the program is adequate, the governance piece is missing.


Loss Event Classification: The Silent Gap

One of the most consistent operational risk program failures — discovered in examinations and internal audits — is incomplete loss event classification. Fraud events are recorded, but they’re classified only at the top level (External Fraud), without the control dimension that makes the data useful.

Consider a synthetic identity fraud event that succeeded because the institution’s CIP controls didn’t include document verification tools adequate for synthetic identity detection. That event is External Fraud in the Basel typology. But it’s also a risk management failure — a control that wasn’t calibrated to the current threat. Recording it only as External Fraud means the operational risk program never captures that the CIP control needs improvement. The fraud team may address it internally; the risk program doesn’t.

The same pattern applies to account takeover events that succeed because MFA wasn’t enforced on a customer authentication path, wire fraud losses where the verbal callback procedure wasn’t followed, and push payment fraud losses where customer education on authorized push payment scams was insufficient.

Every fraud event should generate three questions in the loss event database: What happened? Why did the control fail? What control improvement does this indicate? The first question gets answered. The second and third often don’t.


Preparing for the Back Half of 2026

The OCC’s May 2026 Operational Risk Workshop in St. Louis, attended by community bank directors and senior management, focused explicitly on navigating “rapid, wide-ranging changes” in operational risk. Fraud and AI were prominent themes. For institutions subject to OCC oversight, the back half of 2026 is when those examination priorities translate into on-site examiner questions.

Three things to complete before those conversations:

Conduct a fraud risk assessment. If your last independent fraud risk assessment was more than 12 months ago, or if it was produced by the fraud team rather than the risk function, commission a new one. The assessment should specifically address AI-enhanced fraud threats and evaluate whether your current controls are calibrated for the current attack surface.

Close the loss event database gap. Pull your fraud-related loss events from the last 12 months. Verify each is recorded in the operational risk loss database (not just the fraud case management system), classified with the appropriate Basel event type, and analyzed for the control failure dimension. If events aren’t in the operational risk database, the program isn’t capturing the risk data it needs.

Build a fraud KRI dashboard. Even a basic set of five to six fraud KRIs, monitored monthly and reported to the risk committee quarterly, demonstrates second-line oversight. The KRIs don’t need to be sophisticated on day one — they need to exist, have defined thresholds, and be reviewed by someone other than the fraud team.


So What?

The Spring 2026 Risk Perspective isn’t telling banks anything they don’t already know about fraud risk — it’s telling them the OCC considers fraud risk a primary operational risk concern and expects examination findings to reflect a coherent second-line program.

For community banks that benefit from the OCC’s 2026 exam rightsizing: the paradox is that relying on your own risk function requires that function to actually work. Examiners leveraging your reports and documentation to draw risk conclusions means those reports and documentation need to convey second-line rigor, not just first-line metrics.

For fintechs operating under OCC-chartered sponsor banks: the sponsor bank’s OCC examination increasingly covers the fintech’s operational risk posture, including fraud. Documentation gaps in the fintech’s fraud risk program become exam findings in the sponsor bank’s exam.

Fraud operations capability is necessary but not sufficient. The second-line program — independent assessment, loss event tracking, KRI monitoring, governance reporting — is what the OCC is looking for when it shows up.


Further Reading


The Operational Risk Program bundle includes the ERMF, RCSA, KRI Library, and loss event tracking tools — the full second-line stack for banks and fintechs building or upgrading their operational risk governance.

Related: Fraud KRI Examples for Fintechs: Threshold Setting and Drift | RCSA Methodology: Workshop Facilitation, Scoring, and Common Pitfalls | The Three Lines of Defense Model

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the OCC's Spring 2026 Semiannual Risk Perspective say about fraud?
The OCC's Spring 2026 Semiannual Risk Perspective, released in May 2026, named fraud the primary driver of operational losses across the federal banking system. Specifically, examiners flagged rising sophistication in impersonation scams — attacks using AI-generated voice and text communications to impersonate bank employees, government officials, or trusted counterparties — delivered via text message and social media. The report also highlighted AI as a dual-edged tool: attackers use it to scale and speed attacks, while banks deploy it defensively for threat monitoring and anomaly detection.
What's the difference between a fraud operations team and a fraud risk program?
A fraud operations team (first line) detects, investigates, and prevents fraud events. A fraud risk program (second line) provides independent oversight of the first line's controls, assesses whether fraud risk is within appetite, tracks and analyzes loss events, monitors KRIs, and reports to risk governance. Most fintechs and many community banks have the first without the second. OCC examiners increasingly expect to see a second-line function that can produce a fraud risk assessment, loss event data, and KRI reporting — not just reference the fraud team's case management metrics.
How should AI-enhanced fraud attacks be classified in our operational risk loss event database?
AI-enhanced fraud events typically fall under the External Fraud Basel event type (ET3) — specifically, fraud involving technology-enabled deception of customers or employees. However, if the AI-enhanced attack exploited an internal control failure (inadequate authentication, poor employee training, insufficient system monitoring), the event may also have an Internal Fraud or Execution/Delivery/Process Management dimension. Classification drives both regulatory reporting and risk program improvements — events classified only as External Fraud that involved internal control gaps are missing a control improvement opportunity.
What KRIs should a bank or fintech track for fraud risk?
Core fraud KRIs include: fraud loss rate (total fraud losses as a percentage of total transactions or revenue), fraud attempt volume trend, social engineering complaint rate, account takeover event volume, push payment fraud claim rate, fraud false positive rate in transaction monitoring, and time-to-detect metric for confirmed fraud events. For AI-enhanced fraud specifically, tracking the volume of impersonation-related fraud claims and the source channels (SMS, social media, phone) helps calibrate where enhanced controls are needed.
What does second-line fraud risk oversight look like in practice?
Second-line fraud risk oversight involves: (1) an independent fraud risk assessment conducted at least annually, identifying the highest inherent risks and evaluating whether first-line controls are adequate; (2) review of loss event data to identify patterns and control gaps; (3) monitoring KRIs against defined thresholds; (4) independent testing of key fraud controls; and (5) reporting to risk governance — the risk committee or board — on fraud risk exposure, emerging threats, and program adequacy. The key word is 'independent': examiners expect the second line to evaluate first-line performance, not just relay first-line metrics.
How do OCC community bank exam changes in 2026 affect fraud risk program expectations?
The OCC's 2026 exam rightsizing for community banks removed mandatory examination activities not required by statute or regulation. But this creates a paradox: examiners rely more heavily on a bank's own risk functions, reports, and documentation to draw conclusions about risk posture. A bank whose fraud risk program produces robust documentation — loss event data, KRI reports, risk assessments, control testing results — gives examiners the information they need to conclude the risk is being managed. A bank with no documented second-line oversight of fraud relies on the examiner to do that work — and that's not a position any bank wants to be in.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Operational Risk Program

Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.