Fraud rarely happens in isolation
Traditional fraud controls often assess one event at a time:
- Is this transaction unusual?
- Does this device appear suspicious?
- Does the customer’s identity information match?
- Has this beneficiary previously received fraudulent funds?
These questions remain important, but they can miss the wider picture.
Modern fraud is frequently organised across networks of accounts, identities, devices, payment instruments and counterparties. A transaction that appears reasonable on its own may become highly suspicious when connected to other activity.
The challenge for fraud teams is therefore not simply to identify risky transactions. It is to understand the relationships surrounding them.
The limitations of event-by-event detection
Many fraud detection systems were designed around individual rules or alerts. A payment may be stopped because it exceeds a threshold. An account may be reviewed because it was accessed from a new device. An application may be rejected because identity information could not be verified.
This approach can detect obvious anomalies, but sophisticated fraudsters deliberately keep individual events below detection thresholds.
They may:
- Spread activity across multiple accounts
- Reuse devices while changing identity details
- Rotate telephone numbers, email addresses or payment methods
- Move funds through layers of mule accounts
- Create synthetic identities using a mixture of genuine and fabricated information
- Test controls with low-value activity before increasing transaction amounts
Viewed separately, each event may appear low risk. Viewed as part of a connected network, the pattern becomes much clearer.
What is connected risk intelligence?
Connected risk intelligence is the process of combining data from multiple sources to identify relationships between people, accounts, devices, transactions and organisations.
Instead of analysing only the transaction in front of them, investigators can examine the broader risk environment.
Relevant connections may include:
- Multiple accounts accessed from the same device
- Different customers using the same address or telephone number
- Several payment cards linked to one digital wallet
- New accounts transferring funds to the same beneficiary
- Shared IP addresses across apparently unrelated applicants
- Accounts receiving funds shortly after being opened
- Common identity documents or document templates
- Repeated links to previously confirmed fraud cases
Not every shared attribute indicates wrongdoing. Families, businesses and customers using shared networks can create legitimate connections. The purpose of connected analysis is not to treat every relationship as suspicious, but to place each relationship in context.
How fraud networks hide in legitimate activity
Fraud networks often attempt to resemble ordinary customer behaviour.
A mule account may initially receive a salary payment or make normal retail purchases. A synthetic identity may build a credit history over time. A compromised account may continue to show legitimate activity alongside unauthorised transactions.
This mixture of genuine and fraudulent behaviour makes detection difficult.
Fraudsters also exploit organisational silos. Information may be separated across:
- Fraud prevention teams
- Anti-money laundering teams
- Cybersecurity functions
- Customer service operations
- Payments teams
- Credit risk departments
- External data providers
One team may identify a suspicious device while another sees unusual transfers. A third may receive a customer complaint. Unless these signals are connected, the organisation may fail to recognise that they relate to the same underlying threat.
Five capabilities required for a connected approach
1. Entity resolution
The same person or organisation may appear in multiple systems with different names, addresses or identifiers.
Entity resolution brings these records together and determines whether they relate to the same real-world subject. It should account for spelling variations, formatting differences, incomplete data and deliberately manipulated information.
Strong entity resolution helps prevent fraudsters from appearing to be new customers simply by changing minor details.
2. Relationship analysis
Once entities have been identified, organisations need to understand how they are connected.
Relationship analysis can reveal clusters of accounts sharing devices, beneficiaries, contact details or transaction patterns. It can also identify indirect links that may not be visible through conventional alert reviews.
For example, two accounts may not transact with each other, but both may send funds to accounts controlled through the same device.
3. Behavioural context
A connection alone is not enough to determine risk.
Fraud teams should consider:
- When the relationship was established
- How frequently it appears
- Whether the behaviour is consistent with the customer profile
- Whether the linked entities have known risk indicators
- How funds move through the network
- Whether activity changed following a specific event
Behavioural context helps distinguish legitimate shared attributes from coordinated fraud.
4. Real-time decisioning
Connected intelligence delivers the greatest value when it can influence decisions at the point of risk.
Relevant use cases include:
- Customer onboarding
- Account login
- Beneficiary creation
- Payment initiation
- Credit applications
- Password or contact-detail changes
- Account recovery requests
A real-time decision may involve approving the activity, requesting additional verification, delaying the transaction or escalating the case for investigation.
5. Investigator feedback
Fraud detection improves when confirmed case outcomes are fed back into the system.
When an investigator identifies a mule account, compromised device or fraudulent beneficiary, related entities should be reassessed. This can expose additional cases that were previously considered low risk.
Feedback loops also help organisations understand which indicators are genuinely predictive and which create unnecessary alerts.
Connecting fraud and financial crime risk
Fraud and money laundering are often managed by separate teams, but the underlying activity frequently overlaps.
Fraud generates illicit proceeds. Mule networks move and disguise those proceeds. Scam payments may pass through several accounts before being withdrawn or transferred elsewhere. Identity abuse may support both fraud and broader financial crime.
A connected risk model can help organisations identify activity across the full lifecycle:
- An identity is created, stolen or manipulated.
- An account or financial product is obtained.
- Fraudulent funds are generated or received.
- Money is moved through connected accounts.
- Funds are withdrawn, converted or transferred onward.
Sharing relevant intelligence across fraud and financial crime functions can reduce duplicated effort and provide a more complete understanding of the customer and the network.
Managing false positives and customer impact
More data does not automatically produce better decisions.
Poorly designed network rules can generate high numbers of false positives. Common addresses, corporate devices, public networks and shared family information may create legitimate links between customers.
Controls should therefore consider the strength and meaning of each connection.
A shared IP address may be a weak signal. A shared device, identity document and beneficiary may be significantly stronger. Risk should be based on the combination of indicators, their timing and the surrounding behaviour.
Organisations should regularly review:
- Alert conversion rates
- False-positive rates
- Fraud losses prevented
- Customer friction
- Investigation time
- Repeat exposure to known entities
- The performance of individual risk indicators
The objective is not to block every unusual event. It is to intervene when the available evidence indicates a meaningful level of risk.
Practical steps for fraud leaders
Organisations do not need to rebuild their entire fraud environment before adopting a connected approach.
A practical starting point is to identify the data already available and determine where meaningful relationships can be created.
Fraud leaders should consider the following questions:
- Which identifiers are collected across the customer lifecycle?
- Can accounts be linked through devices, contact details and beneficiaries?
- Are confirmed fraud outcomes shared across relevant systems?
- Can investigators easily view related entities and transactions?
- Are fraud, AML and cybersecurity signals brought together?
- How quickly can a newly identified risk indicator be applied?
- Are decisions explainable to investigators, customers and regulators?
The answers will reveal both immediate opportunities and longer-term data gaps.
From isolated alerts to risk understanding
Fraud detection is moving beyond individual rules and transactions.
The most effective controls increasingly depend on understanding how identities, accounts, devices and funds interact over time. This allows organisations to identify coordinated behaviour that would remain hidden when events are reviewed separately.
Connected risk intelligence does not replace experienced investigators or well-designed controls. It gives them a stronger foundation.
When fraud teams can see the network rather than only the alert, they are better equipped to detect emerging threats, reduce losses and intervene with greater precision.
