Feature Operational Risk
AI-Enhanced Fraud Is Now the OCC's Top Operational Risk Concern. Here's What That Means for Your Fraud Risk Program.
The OCC's Spring 2026 Risk Perspective named fraud the primary driver of operational losses. But having a fraud operations team isn't a fraud risk program — examiners want second-line oversight, documented loss events, and KRIs that signal emerging exposure.
Table of Contents
The OCC examiner’s question during the on-site visit was direct: “Who in your second line owns fraud risk oversight?” The community bank’s compliance officer paused. The fraud team was excellent — they caught things early, had good case management, and had kept loss rates below peer. But a second-line fraud risk program? That was the fraud team’s job.
It wasn’t the answer the examiner was looking for.
That dynamic is playing out across the federal banking system in 2026. The OCC’s Spring 2026 Semiannual Risk Perspective, released in May, named fraud the primary driver of operational losses — and the exam community is taking it seriously. But the gap most institutions are discovering isn’t their fraud operations capability. It’s their fraud risk governance.
TL;DR
- The OCC’s Spring 2026 Semiannual Risk Perspective named fraud the primary driver of operational losses across the federal banking system
- AI is reshaping the fraud threat landscape: impersonation scams via text and social media are more sophisticated and cheaper to scale than ever
- Most banks and fintechs have a fraud operations team (first line) — far fewer have a fraud risk program (second line oversight, loss event tracking, KRI monitoring, risk governance reporting)
- The OCC’s 2026 community bank exam rightsizing makes second-line documentation MORE important, not less — examiners rely on your risk functions to draw risk conclusions
- Fraud loss event classification is where most programs have silent gaps: events coded only as External Fraud when they had internal control dimensions
What the OCC’s Spring 2026 Report Actually Said
The OCC releases a Semiannual Risk Perspective twice a year as a public signal of examiner priorities. The Spring 2026 edition, released in May, covered the full range of risk themes — credit, market, operational, and compliance — but the operational risk section contained language that hasn’t appeared in prior editions.
Fraud was named “a primary driver of operational losses.” The specific emphasis was on the sophistication trajectory: impersonation scams facilitated by social media and text messages are rising in sophistication at the same time that AI is “lowering the barrier to entry for threat actors” by enabling automated reconnaissance, targeted social engineering, and adaptive attacks that evade traditional controls.
The report also flagged foreign state-sponsored actors as an elevated and persistent threat — not specific to fraud, but part of the same operational risk landscape.
What makes this notable isn’t any single data point. It’s the convergence: fraud is already the top operational loss driver, AI is making fraud attacks cheaper and more scalable to execute, and the OCC’s 2026 exam focus is explicitly on operational risk. That combination creates a specific examiner expectation: your fraud risk program needs to be ready to answer for all three dimensions.
Why Fraud Operations Isn’t a Fraud Risk Program
The distinction matters enormously in an examination context, and it’s where most banks and fintechs have a gap.
Fraud operations (first line): The team that detects fraud events, investigates cases, manages fraud disputes, recovers losses, and optimizes fraud models. They operate prevention and detection controls. They handle regulatory notifications when an event requires it. They report fraud metrics — case volumes, loss amounts, recovery rates — to management.
Fraud risk program (second line): An independent function that assesses whether the first line’s controls are adequate relative to the institution’s fraud risk exposure, monitors KRIs to identify emerging risk, reviews loss event data for control gaps, tests the effectiveness of key controls, and reports to risk governance on whether fraud risk is within appetite.
These are different functions. Fraud operations can produce excellent metrics and still have no one independently evaluating whether those metrics indicate the risk is being managed adequately. An institution running its fraud team well but with no second-line oversight is, from an examiner’s perspective, missing a governance layer.
The OCC’s examiner handbook and the broader interagency guidance on operational risk governance are consistent on this point: the risk function should provide independent challenge to the business line’s risk management. For fraud, that means an independent assessment of fraud risk exposure, not just a report on the fraud team’s performance metrics.
How AI Is Changing the Fraud Threat Landscape
The Spring 2026 Risk Perspective’s identification of AI as a threat enabler is grounded in specific changes to the fraud attack surface.
Impersonation at scale. AI voice synthesis and text generation make it possible to impersonate an institution’s employees, government officials, or trusted counterparties with a degree of fidelity that previously required significant effort. A social engineering call that once required a skilled actor can now be partially automated, customized by target, and deployed at volume.
Synthetic identity fraud. AI-generated synthetic identities — combinations of real and fabricated information — have become harder to detect at account opening. Traditional CIP controls were designed for conventional document fraud; synthetic identity requires behavioral and analytical signals that many institutions aren’t monitoring.
Business email compromise (BEC) evolution. AI tools that can analyze email threads and generate plausible follow-on communications have moved BEC from a manual craft to a semi-automated attack. Wire transfer fraud executed through BEC has historically been the largest single category of cybercrime losses, and the attack methodology is getting more scalable.
Adaptive attacks. AI-assisted malware and fraud tooling can be modified to evade detection patterns. Fraud models trained on historical fraud patterns can be gamed by attackers who test and iterate their approach against the institution’s visible defenses.
This doesn’t mean a bank’s fraud controls are ineffective. Banks are also deploying AI for fraud detection and behavioral monitoring. The OCC report specifically noted that banks are taking a “measured approach” to generative and agentic AI, with limited use cases and human-in-the-loop accountability as the current standard. But the threat landscape has shifted, and a fraud risk program built around pre-AI threat models needs to be assessed against the current attack surface.
What a Second-Line Fraud Risk Program Actually Requires
Building a fraud risk program that satisfies examiner expectations doesn’t require reinventing the institution’s entire operational risk framework. It requires applying your existing operational risk governance structure specifically to fraud — and producing the documentation that lets an examiner follow the logic.
Fraud Risk Assessment. Conducted at least annually (more frequently if the fraud threat environment or the institution’s product mix changes significantly). The assessment identifies fraud risk categories relevant to the institution — card fraud, wire fraud, ACH fraud, check fraud, application fraud, account takeover, insider fraud — evaluates the adequacy of controls for each, assigns an inherent and residual risk rating, and identifies gaps for remediation. This is a second-line document, not a fraud team operations report.
Loss Event Database. Every fraud-related operational loss should be captured in the institution’s loss event database. This is not the fraud case management system — it’s the operational risk database that tracks losses by event type, root cause, business line, and control failure dimension. Basel event type ET3 (External Fraud) is the primary category, but losses that also involved an internal control failure need to be coded with the relevant control dimension. Many institutions run their fraud team’s case management system separately from the operational risk loss database, resulting in loss data that’s never analyzed for control patterns.
Fraud KRI Monitoring. Core fraud KRIs monitored against defined thresholds and reported to risk governance. The standard set includes:
| KRI | Threshold Signal | Escalation Trigger |
|---|---|---|
| Fraud loss rate (losses / total transactions) | Rising quarter-over-quarter | Exceeds peer benchmark or defined amber threshold |
| Fraud attempt volume trend | Sustained increase | 20%+ increase over 90 days |
| Account takeover event volume | Any sustained increase | >50% increase over 90 days |
| Social engineering claim rate | Emerging | Any increase in phishing/vishing/smishing claims |
| Time-to-detect (confirmed fraud events) | Trending up | Exceeds defined SLA |
| False positive rate (transaction monitoring) | Trending up | Significant increase affecting customer experience |
Independent Control Testing. The second line should independently test at least the highest-risk fraud controls — transaction monitoring calibration, authentication controls on high-value transaction paths, and wire transfer verification procedures — on a defined schedule. This is distinct from the fraud team’s own review of its operations.
Risk Governance Reporting. The risk committee or board-level risk reporting should include a fraud risk section at least quarterly. The section should cover KRI status, significant loss events, emerging threats, and program adequacy assessment. If your board report includes fraud case counts from the fraud team but no second-line assessment of whether the program is adequate, the governance piece is missing.
Loss Event Classification: The Silent Gap
One of the most consistent operational risk program failures — discovered in examinations and internal audits — is incomplete loss event classification. Fraud events are recorded, but they’re classified only at the top level (External Fraud), without the control dimension that makes the data useful.
Consider a synthetic identity fraud event that succeeded because the institution’s CIP controls didn’t include document verification tools adequate for synthetic identity detection. That event is External Fraud in the Basel typology. But it’s also a risk management failure — a control that wasn’t calibrated to the current threat. Recording it only as External Fraud means the operational risk program never captures that the CIP control needs improvement. The fraud team may address it internally; the risk program doesn’t.
The same pattern applies to account takeover events that succeed because MFA wasn’t enforced on a customer authentication path, wire fraud losses where the verbal callback procedure wasn’t followed, and push payment fraud losses where customer education on authorized push payment scams was insufficient.
Every fraud event should generate three questions in the loss event database: What happened? Why did the control fail? What control improvement does this indicate? The first question gets answered. The second and third often don’t.
Preparing for the Back Half of 2026
The OCC’s May 2026 Operational Risk Workshop in St. Louis, attended by community bank directors and senior management, focused explicitly on navigating “rapid, wide-ranging changes” in operational risk. Fraud and AI were prominent themes. For institutions subject to OCC oversight, the back half of 2026 is when those examination priorities translate into on-site examiner questions.
Three things to complete before those conversations:
Conduct a fraud risk assessment. If your last independent fraud risk assessment was more than 12 months ago, or if it was produced by the fraud team rather than the risk function, commission a new one. The assessment should specifically address AI-enhanced fraud threats and evaluate whether your current controls are calibrated for the current attack surface.
Close the loss event database gap. Pull your fraud-related loss events from the last 12 months. Verify each is recorded in the operational risk loss database (not just the fraud case management system), classified with the appropriate Basel event type, and analyzed for the control failure dimension. If events aren’t in the operational risk database, the program isn’t capturing the risk data it needs.
Build a fraud KRI dashboard. Even a basic set of five to six fraud KRIs, monitored monthly and reported to the risk committee quarterly, demonstrates second-line oversight. The KRIs don’t need to be sophisticated on day one — they need to exist, have defined thresholds, and be reviewed by someone other than the fraud team.
So What?
The Spring 2026 Risk Perspective isn’t telling banks anything they don’t already know about fraud risk — it’s telling them the OCC considers fraud risk a primary operational risk concern and expects examination findings to reflect a coherent second-line program.
For community banks that benefit from the OCC’s 2026 exam rightsizing: the paradox is that relying on your own risk function requires that function to actually work. Examiners leveraging your reports and documentation to draw risk conclusions means those reports and documentation need to convey second-line rigor, not just first-line metrics.
For fintechs operating under OCC-chartered sponsor banks: the sponsor bank’s OCC examination increasingly covers the fintech’s operational risk posture, including fraud. Documentation gaps in the fintech’s fraud risk program become exam findings in the sponsor bank’s exam.
Fraud operations capability is necessary but not sufficient. The second-line program — independent assessment, loss event tracking, KRI monitoring, governance reporting — is what the OCC is looking for when it shows up.
Further Reading
- OCC Spring 2026 Semiannual Risk Perspective — primary source
- OCC Highlights AI as Both Cyber Threat and Defensive Tool — Orrick analysis
- OCC Spring 2026 Risk Perspective Analysis for Community Bankers
- OCC Operational Risk Workshop
- Beyond Bank Runs: OCC Warns of More Complex Financial Threat — Forbes analysis
The Operational Risk Program bundle includes the ERMF, RCSA, KRI Library, and loss event tracking tools — the full second-line stack for banks and fintechs building or upgrading their operational risk governance.
Related: Fraud KRI Examples for Fintechs: Threshold Setting and Drift | RCSA Methodology: Workshop Facilitation, Scoring, and Common Pitfalls | The Three Lines of Defense Model
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Operational Risk Program
Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the OCC's Spring 2026 Semiannual Risk Perspective say about fraud?
What's the difference between a fraud operations team and a fraud risk program?
How should AI-enhanced fraud attacks be classified in our operational risk loss event database?
What KRIs should a bank or fintech track for fraud risk?
What does second-line fraud risk oversight look like in practice?
How do OCC community bank exam changes in 2026 affect fraud risk program expectations?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Operational Risk Program
Build a complete ORM program: ERM framework, RCSA, loss monitoring, financial risk, KRIs, and the Contingency Funding Plan for chartered banks.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026