Feature Operational Risk
The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.
The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.
Table of Contents
TL;DR
- The Federal Reserve Financial Services 2026 Risk Officer Survey of 400+ institutions found no major fraud category declining — debit card fraud affects nearly all institutions; ACH account takeover is rising sharply; money mule accounts are persistent for 47% of respondents; synthetic identity fraud is a problem for 39%
- The survey’s most important finding isn’t the fraud rates themselves — it’s when institutions discover it: mule accounts are routinely found only after funds are depleted, not before
- Standard TPRM and AML monitoring is oriented around transaction-time detection; the fraud patterns the Fed flagged require earlier-stage behavioral analytics that most programs haven’t built
- The Fed survey is the benchmark examiners are using to evaluate whether your fraud risk program is keeping pace with actual threat patterns
It used to be that “fraud is getting worse” was background noise — something compliance officers acknowledged and moved past. The Federal Reserve’s 2026 Risk Officer Survey makes that kind of dismissal harder to sustain.
Published April 22, 2026, the Federal Reserve Financial Services 2026 Risk Officer Survey represents responses from more than 400 financial institutions across all asset sizes. The headline finding is blunt: no major fraud category is improving. Debit card fraud is near-universal. ACH fraud is shifting toward account takeover and business email compromise. Money mule accounts are a persistent or growing problem for nearly half of respondents — and most institutions are finding them after the money is gone. Synthetic identity fraud is defeating onboarding controls at a rate that hasn’t reversed.
What makes this survey different from the usual fraud-trend summaries is the specificity of the failure modes it documents. This isn’t a report that fraud is happening. It’s a report about where controls are arriving too late.
What the Survey Actually Measured
The survey was conducted in Q4 2025, covering fraud experience, control effectiveness, and emerging risk patterns across debit, ACH, wire, and check payment channels. Respondents range from community banks to large regional institutions.
The methodology matters for how you use the findings. This isn’t regulatory guidance and it doesn’t create new compliance obligations. But when your next examiner sits down across from your chief risk officer and asks how your fraud risk program addresses the specific patterns regulators are tracking, the survey’s framework is the reference point they’re working from.
A program that can demonstrate it has assessed and responded to these specific categories — CNP debit fraud, ACH account takeover, pre-depletion mule detection, synthetic identity onboarding gaps — is a program that speaks the examiner’s language. A program that produces aggregate fraud loss numbers without this breakdown is not.
Debit Card Fraud: Near-Universal Exposure
Debit card fraud is the most pervasive fraud category in the survey, with 75% of respondents reporting fraud attempts and the figure approaching universal for institutions of any meaningful size.
The survey distinguishes three debit card fraud types that have different control implications:
Card not present (CNP). Card credentials used in online or phone transactions without the physical card present. The attack surface is card data obtained through breaches, skimmers, or phishing campaigns. Controls: velocity monitoring on digital channels, device fingerprinting, 3-D Secure (3DS) authentication for online merchants, real-time velocity limits.
Did not authorize or recognize (DNAR). The account holder has the card but doesn’t recognize the transaction. This category increasingly overlaps with account takeover — the account holder’s credentials were compromised, the transaction was authorized using the correct PIN or 3DS credentials, and the account holder was unaware. Controls: behavioral analytics post-authorization, rapid customer notification, anomalous transaction pattern rules (new merchant categories, cross-border patterns, high-velocity small transactions before a large one).
Never received (NFR). Cards intercepted in the mail before reaching the account holder. This is the one category showing improvement, likely because most institutions have moved to branch pickup or real-time digital card provisioning for new account openings.
The practical implication: CNP and DNAR fraud require different control investments. Many institutions have built robust CNP controls — velocity monitoring, digital channel rules, 3DS implementation — while underinvesting in DNAR controls, which require behavioral analytics that don’t depend on the transaction being out of policy at the moment of authorization.
ACH Fraud Is Shifting to Higher-Value Attack Patterns
ACH fraud in the survey is shifting away from simple unauthorized debit patterns toward account holder scams, business email compromise (BEC), and account takeover. All three are rising.
Account holder scams involve manipulating the account holder into authorizing the transfer themselves — impersonation calls from “the bank,” fake investment platforms, romance scams, tech support fraud. The transaction is authorized by the account holder, which is why Regulation E’s “did not authorize” dispute rights don’t apply and why detection at the transaction level is difficult. These show up in fraud losses but not in dispute volumes, which means programs that measure fraud exposure through dispute rates are undercounting this category.
BEC in ACH has grown substantially. The pattern: fraudsters compromise a business email account and redirect ACH payroll or vendor payment files to attacker-controlled accounts. The transaction looks legitimate at the file level — it comes from the right originator, in the normal transaction range, to a new account. The controls that stop this are originator behavior monitoring (new payee not seen in prior ACH batches, file origination at an unusual time or from an unusual IP) and out-of-band callback verification for large payment files.
Account takeover in ACH combines credential theft with real-time payment manipulation. Once the fraudster has access to the account, they change the ACH origination account number — a step that passes standard controls if the account change isn’t subject to holding periods and callback verification.
Our earlier analysis of BEC wire fraud liability under UCC 4A explored how courts are interpreting bank liability when a customer’s ACH or wire instructions are compromised. The short version: security procedure adequacy and customer agreement terms are the key liability factors. The survey’s ACH findings reinforce why “adequate security procedures” needs to include callback verification for changed payment instructions, not just transmission security.
Money Mule Accounts: You’re Finding Them After the Money Is Gone
The survey’s most operationally specific finding is on money mule accounts: 18% of respondents say the problem is increasing, 29% say it’s persistent, and the majority of institutions report that mule accounts are identified only after funds have already been depleted.
That last point is the critical failure mode. A mule account that’s been identified and closed after the money is gone is an accounting entry, not a fraud prevention result. The question the survey raises is whether your detection model is designed to find mule accounts before the final transfer event.
The detection challenge: mule accounts often look legitimate at onboarding and behave normally through an accumulation phase. The account may receive multiple small transfers — appearing to be routine direct deposit or P2P activity — before a single large outgoing transfer depletes the balance. The individual incoming transfers may not be suspicious on their own. The outgoing transfer may not exceed reporting thresholds if the mule network is using multiple accounts to aggregate.
The behavioral signals that precede the depletion event — and that most current monitoring programs don’t explicitly test for — include:
- Rapid accumulation of incoming transfers from multiple sources within a 3-7 day window
- Account receiving transfers from accounts that themselves show similar accumulation patterns (network-level signal)
- Geographic displacement between the account’s registration address and the origination location of incoming transfers
- Dormant accounts that suddenly become active with high-volume incoming transfers
- Account balance approaching zero after accumulation — not through normal spending but through one or two large transfers
The mule detection problem increasingly requires graph analytics — looking at relationships between accounts, not just the behavior of individual accounts. That’s a capabilities investment many community and mid-size institutions haven’t made.
Synthetic Identity Fraud: The KYC Blind Spot
Synthetic identity fraud affects 39% of respondents as either a persistent (25%) or increasing (14%) problem. The surge in synthetic identity schemes at financial institutions that began accelerating in 2024 has not reversed.
The core problem: a synthetic identity combines a real Social Security Number (often belonging to a minor, elderly person, or someone with limited credit history) with fabricated supporting information. SSN-based identity verification — the backbone of most KYC programs — passes because the SSN is real. New-account negative file screening passes because the synthetic identity has no derogatory history. The account then “ages” through legitimate-looking small transactions before a bust-out event.
Generative AI has made synthetic identity creation faster and the supporting documentation more convincing. AI-generated pay stubs, utility bills, and identification documents are now good enough to defeat document review systems that weren’t trained on this generation of fakes.
The survey finds that institutions are often first learning about synthetic identity accounts when they surface in collections — meaning the fraud cycle completed before detection. The fix requires moving detection earlier in the account lifecycle: during onboarding, through credit file velocity analysis during the aging phase, and through behavioral monitoring that flags the accumulation patterns that precede bust-out.
Our coverage of FedNow and RTP fraud control requirements noted that synthetic identities are a particular risk in instant payment environments where settlement finality prevents post-authorization reversal. The survey’s synthetic identity findings strengthen the case that onboarding is the point where the fraud has to be caught.
The Diagnostic: Where Your Controls Are Arriving Late
| Fraud Type | What Most Programs Monitor | Survey-Identified Gap |
|---|---|---|
| Debit CNP | Transaction velocity, amount | Post-authorization behavioral patterns for DNAR |
| ACH Account Takeover | Originator authentication | Changed payee/account number verification |
| ACH BEC | File-level originator authentication | New payee in ACH batch, unusual origination time |
| Money Mule | SAR filing after depletion | Pre-depletion accumulation signals, network analysis |
| Synthetic Identity | SSN validation, negative file screening | Credit aging velocity, onboarding document AI detection |
| Account Holder Scams | None at transaction level | Real-time scam pattern detection, warm transfer to fraud team |
The common thread: the gap between when fraud is detectable and when most programs detect it is measured in days or weeks. In ACH and wire fraud, that gap is often the entire window between the fraudster’s access to an account and the completion of the fraudulent transfer.
So What?
Three priority gaps based on the survey findings:
Build a pre-depletion mule detection layer. Add explicit behavioral rules targeting the accumulation pattern that precedes mule account depletion — incoming transfer velocity over 3-7 days, geographic displacement, sender network analysis. This is not covered by standard transaction monitoring rules calibrated to individual transaction characteristics.
Add payee velocity analysis to ACH BEC detection. For commercial ACH originators, flag new payee accounts that appear in ACH batch files but have no prior history in the originator’s payments. Require out-of-band callback verification for batch files that contain new payees above a defined threshold.
Expand synthetic identity detection to the credit aging phase. Don’t wait for bust-out to identify synthetic identities. Implement credit velocity analysis that flags accounts showing unusually rapid credit limit increases relative to their account age and credit file history. Coordinate with the credit team — this signal often sits in credit files before it surfaces in fraud analytics.
The Federal Reserve’s full Risk Officer Survey is worth reading in full. The data gives fraud program owners a defensible basis for prioritizing control investments over the next budget cycle — and a set of reference points for examiner conversations about whether your fraud program reflects current threat patterns.
A well-designed RCSA (Risk & Control Self-Assessment) should explicitly map fraud categories to controls and test whether detection is occurring at the right point in the fraud lifecycle. If your current RCSA doesn’t distinguish between pre-depletion and post-depletion mule detection, or doesn’t separately assess CNP versus DNAR debit fraud controls, the survey findings give you the case for why it should.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who does the Federal Reserve's 2026 Risk Officer Survey cover?
Why do institutions keep finding money mule accounts after funds are already gone?
What types of debit card fraud are rising fastest and why does the distinction matter for controls?
How does synthetic identity fraud defeat standard KYC controls?
What specific changes should an operational risk team make based on the survey findings?
Does the Fed Risk Officer Survey create any supervisory obligations?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.
◆ Keep reading
Related posts.
Operational Risk
FTC Just Fined a Payment Processor $12 Million for Sham Merchants. Here's What 'Knowingly Facilitating Fraud' Actually Looks Like.
On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services for processing payments for 1,000+ sham merchant accounts running chargebacks at 10x card network thresholds. This is what payment processor liability looks like—and why it matters for every fintech that routes transactions.
Sep 28, 2026
Operational Risk
FTC Made Corpay's CEO Pay Personally. The $100 Million Unauthorized Fee Case Rewrites What 'Authorization' Means for Billing Controls.
On September 17, 2026, the FTC announced a $100 million settlement with Corpay (formerly FleetCor) and personally named CEO Ronald Clarke for charging unauthorized fees on commercial fuel cards. The injunction's 'clear and unavoidable' disclosure standard goes further than any prior FTC action. Here's what every compliance team with a recurring billing product needs to audit.
Sep 26, 2026
Operational Risk
Congress Never Defined 'Unsafe or Unsound.' Regulators Just Did. What the OCC/FDIC Final Rule Means for Your Risk Program.
The OCC and FDIC finalized a rule on September 1, 2026 that — for the first time in US banking history — defines 'unsafe or unsound practice' in regulation. Effective November 2, it reshapes what kinds of operational failures trigger MRAs. Here's what your risk program needs to change.
Sep 25, 2026