The Challenge of Cross-Border Fraud
Imagine you're in a compliance team meeting. Someone brings up a fraud case that started overseas, moved through multiple payment systems, and involved social media before reaching your institution. The room goes silent. Everyone knows the current information-sharing setup can't handle this, but no one's sure what to do.
These are the questions compliance teams are quietly asking. The FFIS research program's recent survey of collaborative analytics platforms highlights a glaring issue: 91% of platforms see cross-border fraud-risk information sharing as crucial, yet most report no significant international cooperation. The gap between needs and capabilities isn't closing on its own.
Here's what practitioners are actually asking.
Q1: Why Can't We Share Fraud Data Across Borders Now?
You're facing three main barriers.
Legal uncertainty is the first. There's no clear guidance on how to lawfully share personal data across borders for fraud prevention. Your legal team defaults to "no" because the risk of a data protection violation is too high. This isn't paranoia; it's rational risk management without clear rules.
Operational friction is the second. Even with a willing partner overseas, you're speaking different languages. Your fraud taxonomy doesn't match theirs, and your data formats are incompatible. Building translation layers for every relationship doesn't scale.
Political vacuum is the third. There's no international body overseeing global anti-fraud efforts or setting standards for cooperation. Unlike anti-money laundering, where FATF provides a framework, fraud intelligence sharing lacks a coordinating authority. You're left navigating a patchwork of national approaches.
Q2: How Do We Get Social Media and Telcos to Share Intelligence?
Currently, you can't. The incentive structure is broken.
Financial institutions face regulatory liability when fraud occurs. You file Suspicious Activity Reports, reimburse victims, and answer to regulators. Social media platforms and telcos, where scammers recruit victims, face little equivalent pressure. The legal liability is uneven across the fraud attack chain.
The FFIS survey found that AI model development firms aren't members of any fraud-risk information sharing platforms. The technology enabling both sophisticated fraud attacks and potential detection solutions isn't at the table.
Policy intervention is needed to level the playing field. If a sector is used to facilitate fraud, it should share responsibility for detecting and mitigating threats. Regulators must extend information-sharing obligations to technology, social media, and AI sectors. Until these sectors face consequences for non-participation, they won't join platforms that create compliance work for them.
Q3: Should We Wait for FATF or Start Bilateral Arrangements Now?
Do both, but don't wait for permission to start bilateral work.
FATF can adjust its toolkit to address fraud-specific challenges and drive a coordinated global response. The cyber-security community offers a useful model: they developed a common taxonomy for threats and a clear basis in international law for sharing risk information. Fraud intelligence sharing needs the same foundation.
But waiting for a global framework before acting is a mistake. Start building bilateral "innovation corridors" with institutions in jurisdictions where you see frequent fraud flows. Work with your legal team to document the legal basis for each data exchange. Use these corridors to prove the operational model, then expand and replicate what works.
The survey suggests supplementing multilateral efforts with bilateral engagement. You're not choosing one or the other; you're building bottom-up proof points that inform the top-down framework.
Q4: What's the Risk of Sharing Fraud Data Without Legal Clarity?
You're weighing a data protection enforcement action against ongoing fraud losses and potential regulatory criticism for inadequate controls. Neither is hypothetical.
Data protection authorities can impose significant fines for unlawful cross-border data transfers. Your institution's risk appetite determines how much legal ambiguity you can tolerate. Most general counsels won't approve cross-border fraud data sharing without explicit legal gateways, and they're not wrong to be cautious.
But there's a second risk: the cost of inaction. Fraud is moving faster than your defenses. Cross-border, cross-sector scams succeed because intelligence stays siloed. When regulators examine your AML/CFT Framework and fraud controls, they're starting to ask why you're not participating in available information-sharing platforms. "We were waiting for legal clarity" won't satisfy if that clarity never arrives and fraud losses keep climbing.
Document your risk assessment. Show your legal and compliance leadership the trade-offs explicitly. Push for policy reform that creates the legal gateways you need, rather than accepting the status quo as permanent.
Q5: How Do We Prepare for a More Connected Fraud Defense Ecosystem?
Start with data standardization and internal cross-functional coordination.
Adopt a common fraud taxonomy now, even if your jurisdiction hasn't mandated one. Map your current fraud categories to emerging international classifications. When cross-border sharing platforms mature, you won't need to rebuild your entire data architecture to participate.
Build cross-functional fraud response teams that include payments operations, customer service, legal, and compliance. Fraud spans the attack chain; your response can't stay in silos either. These teams should meet regularly to review cases that touched multiple channels or crossed borders.
Evaluate your technology stack for interoperability. Can your transaction monitoring system export fraud signals in standardized formats? Can it ingest intelligence from external platforms? If you're locked into proprietary formats, you'll struggle to connect with collaborative analytics platforms when they become available.
Engage with industry working groups focused on cross-border and cross-sector information sharing. The FFIS research program is one. Your payments network likely has others. Show up, contribute your operational perspective, and shape the frameworks being developed.
Q6: What If AI-Driven Fraud Scales Faster Than Our Intelligence Sharing?
You'll face an asymmetric threat where attackers coordinate globally and defenders remain fragmented.
The FFIS survey warns that AI can enhance the velocity, volume, and effectiveness of fraud attacks. Scammers are already using generative AI for social engineering, deepfakes for identity fraud, and machine learning to identify vulnerable targets. These tools don't respect borders or sectors.
AI can also support fraud detection and response, but only if the AI models have access to intelligence from across the fraud attack chain and jurisdictions. That's why the absence of AI model development firms from fraud-risk information sharing platforms is concerning.
You can't solve this alone. Advocate within your institution for participation in collaborative analytics platforms. Push your industry associations to engage AI and technology sectors. Support policy reforms that create obligations for upstream participants in the fraud attack chain.
The alternative is watching fraud losses surge while your defenses remain disconnected from the intelligence you need.
Next Steps
Review the FFIS comparative study at www.future-fis.com for detailed analysis of current practices across platforms. Check FATF's evolving guidance on fraud and scams; it's developing but not comprehensive. Consider how the cyber-security community built cross-border threat intelligence sharing frameworks; the legal and operational precedents are instructive.
Talk to your peers at other institutions. The questions in this FAQ aren't unique to your team. The more compliance professionals articulate these gaps publicly, the harder it becomes for policymakers to ignore them.



