Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Operational Risk

The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.

The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.

By Rebecca Leung · October 1, 2026 ·
Table of Contents

TL;DR

  • The Federal Reserve Financial Services 2026 Risk Officer Survey of 400+ institutions found no major fraud category declining — debit card fraud affects nearly all institutions; ACH account takeover is rising sharply; money mule accounts are persistent for 47% of respondents; synthetic identity fraud is a problem for 39%
  • The survey’s most important finding isn’t the fraud rates themselves — it’s when institutions discover it: mule accounts are routinely found only after funds are depleted, not before
  • Standard TPRM and AML monitoring is oriented around transaction-time detection; the fraud patterns the Fed flagged require earlier-stage behavioral analytics that most programs haven’t built
  • The Fed survey is the benchmark examiners are using to evaluate whether your fraud risk program is keeping pace with actual threat patterns

It used to be that “fraud is getting worse” was background noise — something compliance officers acknowledged and moved past. The Federal Reserve’s 2026 Risk Officer Survey makes that kind of dismissal harder to sustain.

Published April 22, 2026, the Federal Reserve Financial Services 2026 Risk Officer Survey represents responses from more than 400 financial institutions across all asset sizes. The headline finding is blunt: no major fraud category is improving. Debit card fraud is near-universal. ACH fraud is shifting toward account takeover and business email compromise. Money mule accounts are a persistent or growing problem for nearly half of respondents — and most institutions are finding them after the money is gone. Synthetic identity fraud is defeating onboarding controls at a rate that hasn’t reversed.

What makes this survey different from the usual fraud-trend summaries is the specificity of the failure modes it documents. This isn’t a report that fraud is happening. It’s a report about where controls are arriving too late.

What the Survey Actually Measured

The survey was conducted in Q4 2025, covering fraud experience, control effectiveness, and emerging risk patterns across debit, ACH, wire, and check payment channels. Respondents range from community banks to large regional institutions.

The methodology matters for how you use the findings. This isn’t regulatory guidance and it doesn’t create new compliance obligations. But when your next examiner sits down across from your chief risk officer and asks how your fraud risk program addresses the specific patterns regulators are tracking, the survey’s framework is the reference point they’re working from.

A program that can demonstrate it has assessed and responded to these specific categories — CNP debit fraud, ACH account takeover, pre-depletion mule detection, synthetic identity onboarding gaps — is a program that speaks the examiner’s language. A program that produces aggregate fraud loss numbers without this breakdown is not.

Debit Card Fraud: Near-Universal Exposure

Debit card fraud is the most pervasive fraud category in the survey, with 75% of respondents reporting fraud attempts and the figure approaching universal for institutions of any meaningful size.

The survey distinguishes three debit card fraud types that have different control implications:

Card not present (CNP). Card credentials used in online or phone transactions without the physical card present. The attack surface is card data obtained through breaches, skimmers, or phishing campaigns. Controls: velocity monitoring on digital channels, device fingerprinting, 3-D Secure (3DS) authentication for online merchants, real-time velocity limits.

Did not authorize or recognize (DNAR). The account holder has the card but doesn’t recognize the transaction. This category increasingly overlaps with account takeover — the account holder’s credentials were compromised, the transaction was authorized using the correct PIN or 3DS credentials, and the account holder was unaware. Controls: behavioral analytics post-authorization, rapid customer notification, anomalous transaction pattern rules (new merchant categories, cross-border patterns, high-velocity small transactions before a large one).

Never received (NFR). Cards intercepted in the mail before reaching the account holder. This is the one category showing improvement, likely because most institutions have moved to branch pickup or real-time digital card provisioning for new account openings.

The practical implication: CNP and DNAR fraud require different control investments. Many institutions have built robust CNP controls — velocity monitoring, digital channel rules, 3DS implementation — while underinvesting in DNAR controls, which require behavioral analytics that don’t depend on the transaction being out of policy at the moment of authorization.

ACH Fraud Is Shifting to Higher-Value Attack Patterns

ACH fraud in the survey is shifting away from simple unauthorized debit patterns toward account holder scams, business email compromise (BEC), and account takeover. All three are rising.

Account holder scams involve manipulating the account holder into authorizing the transfer themselves — impersonation calls from “the bank,” fake investment platforms, romance scams, tech support fraud. The transaction is authorized by the account holder, which is why Regulation E’s “did not authorize” dispute rights don’t apply and why detection at the transaction level is difficult. These show up in fraud losses but not in dispute volumes, which means programs that measure fraud exposure through dispute rates are undercounting this category.

BEC in ACH has grown substantially. The pattern: fraudsters compromise a business email account and redirect ACH payroll or vendor payment files to attacker-controlled accounts. The transaction looks legitimate at the file level — it comes from the right originator, in the normal transaction range, to a new account. The controls that stop this are originator behavior monitoring (new payee not seen in prior ACH batches, file origination at an unusual time or from an unusual IP) and out-of-band callback verification for large payment files.

Account takeover in ACH combines credential theft with real-time payment manipulation. Once the fraudster has access to the account, they change the ACH origination account number — a step that passes standard controls if the account change isn’t subject to holding periods and callback verification.

Our earlier analysis of BEC wire fraud liability under UCC 4A explored how courts are interpreting bank liability when a customer’s ACH or wire instructions are compromised. The short version: security procedure adequacy and customer agreement terms are the key liability factors. The survey’s ACH findings reinforce why “adequate security procedures” needs to include callback verification for changed payment instructions, not just transmission security.

Money Mule Accounts: You’re Finding Them After the Money Is Gone

The survey’s most operationally specific finding is on money mule accounts: 18% of respondents say the problem is increasing, 29% say it’s persistent, and the majority of institutions report that mule accounts are identified only after funds have already been depleted.

That last point is the critical failure mode. A mule account that’s been identified and closed after the money is gone is an accounting entry, not a fraud prevention result. The question the survey raises is whether your detection model is designed to find mule accounts before the final transfer event.

The detection challenge: mule accounts often look legitimate at onboarding and behave normally through an accumulation phase. The account may receive multiple small transfers — appearing to be routine direct deposit or P2P activity — before a single large outgoing transfer depletes the balance. The individual incoming transfers may not be suspicious on their own. The outgoing transfer may not exceed reporting thresholds if the mule network is using multiple accounts to aggregate.

The behavioral signals that precede the depletion event — and that most current monitoring programs don’t explicitly test for — include:

  • Rapid accumulation of incoming transfers from multiple sources within a 3-7 day window
  • Account receiving transfers from accounts that themselves show similar accumulation patterns (network-level signal)
  • Geographic displacement between the account’s registration address and the origination location of incoming transfers
  • Dormant accounts that suddenly become active with high-volume incoming transfers
  • Account balance approaching zero after accumulation — not through normal spending but through one or two large transfers

The mule detection problem increasingly requires graph analytics — looking at relationships between accounts, not just the behavior of individual accounts. That’s a capabilities investment many community and mid-size institutions haven’t made.

Synthetic Identity Fraud: The KYC Blind Spot

Synthetic identity fraud affects 39% of respondents as either a persistent (25%) or increasing (14%) problem. The surge in synthetic identity schemes at financial institutions that began accelerating in 2024 has not reversed.

The core problem: a synthetic identity combines a real Social Security Number (often belonging to a minor, elderly person, or someone with limited credit history) with fabricated supporting information. SSN-based identity verification — the backbone of most KYC programs — passes because the SSN is real. New-account negative file screening passes because the synthetic identity has no derogatory history. The account then “ages” through legitimate-looking small transactions before a bust-out event.

Generative AI has made synthetic identity creation faster and the supporting documentation more convincing. AI-generated pay stubs, utility bills, and identification documents are now good enough to defeat document review systems that weren’t trained on this generation of fakes.

The survey finds that institutions are often first learning about synthetic identity accounts when they surface in collections — meaning the fraud cycle completed before detection. The fix requires moving detection earlier in the account lifecycle: during onboarding, through credit file velocity analysis during the aging phase, and through behavioral monitoring that flags the accumulation patterns that precede bust-out.

Our coverage of FedNow and RTP fraud control requirements noted that synthetic identities are a particular risk in instant payment environments where settlement finality prevents post-authorization reversal. The survey’s synthetic identity findings strengthen the case that onboarding is the point where the fraud has to be caught.

The Diagnostic: Where Your Controls Are Arriving Late

Fraud TypeWhat Most Programs MonitorSurvey-Identified Gap
Debit CNPTransaction velocity, amountPost-authorization behavioral patterns for DNAR
ACH Account TakeoverOriginator authenticationChanged payee/account number verification
ACH BECFile-level originator authenticationNew payee in ACH batch, unusual origination time
Money MuleSAR filing after depletionPre-depletion accumulation signals, network analysis
Synthetic IdentitySSN validation, negative file screeningCredit aging velocity, onboarding document AI detection
Account Holder ScamsNone at transaction levelReal-time scam pattern detection, warm transfer to fraud team

The common thread: the gap between when fraud is detectable and when most programs detect it is measured in days or weeks. In ACH and wire fraud, that gap is often the entire window between the fraudster’s access to an account and the completion of the fraudulent transfer.

So What?

Three priority gaps based on the survey findings:

Build a pre-depletion mule detection layer. Add explicit behavioral rules targeting the accumulation pattern that precedes mule account depletion — incoming transfer velocity over 3-7 days, geographic displacement, sender network analysis. This is not covered by standard transaction monitoring rules calibrated to individual transaction characteristics.

Add payee velocity analysis to ACH BEC detection. For commercial ACH originators, flag new payee accounts that appear in ACH batch files but have no prior history in the originator’s payments. Require out-of-band callback verification for batch files that contain new payees above a defined threshold.

Expand synthetic identity detection to the credit aging phase. Don’t wait for bust-out to identify synthetic identities. Implement credit velocity analysis that flags accounts showing unusually rapid credit limit increases relative to their account age and credit file history. Coordinate with the credit team — this signal often sits in credit files before it surfaces in fraud analytics.

The Federal Reserve’s full Risk Officer Survey is worth reading in full. The data gives fraud program owners a defensible basis for prioritizing control investments over the next budget cycle — and a set of reference points for examiner conversations about whether your fraud program reflects current threat patterns.

A well-designed RCSA (Risk & Control Self-Assessment) should explicitly map fraud categories to controls and test whether detection is occurring at the right point in the fraud lifecycle. If your current RCSA doesn’t distinguish between pre-depletion and post-depletion mule detection, or doesn’t separately assess CNP versus DNAR debit fraud controls, the survey findings give you the case for why it should.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Who does the Federal Reserve's 2026 Risk Officer Survey cover?
The Federal Reserve Financial Services 2026 Risk Officer Survey collected responses from more than 400 financial institutions of varying sizes across the United States. The survey was conducted in the fourth quarter of 2025 and published April 22, 2026. It covers fraud trends across all major payment channels including debit cards, ACH, wire transfers, and checks, as well as cross-cutting patterns like account takeover, money mule activity, and synthetic identity fraud.
Why do institutions keep finding money mule accounts after funds are already gone?
The survey identifies two structural gaps. First, mule accounts often appear legitimate at onboarding — they may use real customer credentials acquired through credential stuffing or social engineering, or synthetic identities that pass initial KYC. Second, the typical transaction monitoring framework is optimized for detecting high-value suspicious transactions at the time of occurrence, not for identifying accounts that are accumulating funds before a single large exit transfer. By the time the pattern triggers a SAR, the account has already been depleted. The fix is earlier-stage behavioral monitoring: velocity checks on incoming transfers, dormancy followed by sudden activity, and device/location anomalies before the withdrawal event.
What types of debit card fraud are rising fastest and why does the distinction matter for controls?
The survey identifies 'card not present' and 'did not authorize or recognize' fraud as the most prevalent categories, with 'never received' fraud showing some improvement. The CNP/DNAR distinction matters because they require different controls: CNP fraud targets the card number used without the physical card, calling for velocity monitoring on online channels, device fingerprinting, and 3DS controls. DNAR fraud often involves account takeover — the account holder's credentials were compromised and someone else made the transaction. DNAR is harder to detect pre-authorization because the transaction uses valid credentials, requiring post-authorization behavioral analysis and customer notification speed as secondary controls.
How does synthetic identity fraud defeat standard KYC controls?
A synthetic identity combines a real Social Security Number — often belonging to a child, elderly person, or someone with limited credit history — with a fabricated name, date of birth, and contact information. Because the SSN is real, SSN-based identity verification passes. Because the identity has no prior credit file, it passes new-account fraud checks that look for negative file hits. The account then 'ages' — making small, legitimate transactions over months to build apparent credit history — before a 'bust-out' event where the account holder maxes out credit lines and disappears. Generative AI has accelerated this by making the supporting documents (pay stubs, utility bills, addresses) more convincing than human-crafted synthetics.
What specific changes should an operational risk team make based on the survey findings?
Three priority actions: First, add a pre-depletion mule detection layer — flag accounts showing rapid incoming transfer accumulation followed by large outgoing transfers, even when individual transactions are under monitoring thresholds. Second, expand synthetic identity detection to include velocity of credit aging: accounts that open with thin files and show unusually rapid credit limit increases deserve additional review. Third, build a fraud categorization mapping between your SAR filing categories and the survey's fraud taxonomy (CNP, DNAR, account holder scam, BEC, ATO) — many programs cannot answer which of these categories is driving their fraud losses because the internal categorization doesn't match.
Does the Fed Risk Officer Survey create any supervisory obligations?
The survey itself is not a regulatory requirement — it is a data collection and reporting tool published by Federal Reserve Financial Services. However, the findings inform examination priorities. When examiners visit and ask about your fraud risk program's effectiveness, the survey's benchmarks are the context they're using. A risk program that cannot show it has assessed and responded to the specific fraud patterns the survey identifies — debit CNP, ACH account takeover, mule detection timing, synthetic identity — will be at a disadvantage in that conversation.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.

◆ Keep reading

Related posts.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.