It’s no secret that fraud prevention is shifting from a back-office tick-box to a board-level and even government-level priority. In this episode of Follow the Money, Dr Nicola Harding speaks with Pallavi Kapale, Senior Financial Crime Officer (2LOD) at Bank of China, and Salv CEO and Co-founder Taavi Tamkivi, about what is actually changing on the front line — from SARs reform and money mules to real-time fraud detection, voice-cloning scams and the cross-border gaps criminals exploit. Listen to the converseration as three practitioners share how fraud prevention is changing, based on what they are seeing day-to-day. The full conversation is transcribed underneath.
Introduction
Nicola: Welcome to Follow the Money, brought to you by Salv. I’m Dr Nicola Harding, and today I’m hosting a conversation I’m really excited about, between Pallavi Kapale and Salv’s CEO, Taavi Tamkivi. It comes about because every year Salv publishes the FinCrime Time Machine, which reflects on what’s been happening and brings us forward with predictions of what we’re likely to see. Pallavi has been a repeat contributor, and she gave us one of the boldest predictions in the whole paper: that beating fraud isn’t a technology problem first, it’s an organisational chart problem, and that the endgame is a collective, encrypted network of institutions sharing what they see in real time through machine learning. Today we find out what’s actually happened since, and we hear from Taavi on how Salv has been building the very thing Pallavi described, and how it’s launching across Europe. So we’ve got the prediction and the build, side by side. Welcome, both, and thank you for being here.
Taavi: Thank you.
Pallavi: Thank you, Nicola.
Nicola: Let’s start with the predictions themselves. Pallavi, how much of what you described has actually happened? Were you too optimistic, or not optimistic enough? What’s been happening in the world of financial crime as you see it?
Pallavi: Thank you again for having me — I always enjoy our conversations. You could call them bold predictions, but I’ve seen a lot of proof of them in the industry now, and I’m quite optimistic about the change. Take fraud becoming a strategic priority. That has been visible at conference after conference: the topic now is how fraud is dealt with at management level. When I started working in fraud, it was a tick-box, prevention-first approach — you saved the customer from falling victim, and the job was done. But fraud now sits at around 45% of all financial crime in the UK. Rather than saying the banks are going wrong, I’d say the criminals have got faster, and as banks it’s our job to protect those customers and keep the bad actors out. Look at the fraud strategy released this year. Yesterday I attended the FATF 2026–2028 Fraud Strategy session, which talks much more about cross-border collaboration. When I started, fraud came after KYC — a small department within financial crime. On the AML side we always looked at the transaction, the proceeds of crime, and worked back from there. Now the industry is working backwards into fraud, and there’s a lot of positive publication coming out on it. At the FCA conference I attended last month, there were clear calls to bring the social media companies into scope, because it’s the banks bearing the brunt of the losses. So I’m optimistic. I can’t say it will all happen in the next six months, but the direction is positive. It’s slow, but we’re getting somewhere.
What SARs reform changed inside the bank
Nicola: In terms of the regulatory reshaping you flagged — SARs reform, digital ID, Companies House, the Economic Crime Plan 2 — and your position at Bank of China, how have you seen that play out operationally inside the bank over the last twelve months?
Pallavi: SARs is a good one, because I write a lot of suspicious activity reports and I love writing them — the typologies, the linking, the controls. The threshold is now around £3,000, which lets the NCA focus on much higher-quality reports. Instead of volume, they’re getting quality. I’m not saying anything below £3,000 isn’t suspicious, but the bank now has the authority to exit those customers below the threshold. The other improvement is with law enforcement. It used to be routed from the NCA onwards; now the NCA can send SARs directly to law enforcement, and they’re using a lot of AI to make that connection. So after the £3,000 revision, a lot of noise has been reduced and more quality SARs are going into the system. When I started, the threshold was only £250 — imagine how many SARs the NCA must have received every day. Now they can focus on predicate crimes and the more interesting reports. The next development is on victim SARs. It used to be that both the beneficiary bank and the victim’s bank logged the same SAR on the same customer. That noise has been cut: the victim’s SAR is now reported by the bank where the funds went through — the beneficiary bank. Because all of this has been reduced, operationally the investigators get more time for complex cases and can use that time wisely. On information sharing and the Economic Crime Plan 2, the call for evidence raised a lot of objections, because you can’t just email another bank directly. There needs to be a proper process, a proper contact person: if I send this to a third-party bank, will it be protected? Is it fine under GDPR? Is my legal team happy for me to send this information to another third party? I’m very optimistic here, because information sharing is something I care about and would love to do, and the banks are taking steps. It’s a bit slow, but we’re getting somewhere. On Companies House — it’s a big playground for fraudsters, and criminals find cracks all the time. You get cases where a customer opens an account at an address that already has 50 other customers registered to it; we’ll leave it to the KYC team to figure out how to pull those together at onboarding. Even with the new ID verification at Companies House, I’ve come across cases where customers use a specific bank branch address and still manage to set up companies against it. So those examples still exist, and the gaps are still there.
Building the rails for real-time information sharing
Nicola: What’s so interesting is that one of the main problems is a lot of talk and slow movement. You go to conferences, events, round tables, and you see movement, but it’s creeping forward slowly. For me, the only way we really embed information sharing and the changes that are needed is through infrastructure. Taavi, can you give us an update on where you’re building that infrastructure with Bridge? Because it’s no longer just about banks talking to banks — it’s these public-private partnerships that have thought it through legally, worked out what they can and can’t do, and created the infrastructure to let it happen in real time.
Taavi: The infrastructure, or rails, for information exchange has existed in some countries for many years, so it isn’t new in itself. We’ve been serving multiple countries in a fully compliant, encrypted way. As Pallavi mentioned, old-school emails — or in some countries encrypted emails — sort of work too, but they’re not convenient, not scalable, not operational, and the auditability is poor. Some of this has run over Swift messaging for a long time as well, so proper technology is available: properly embedded into banks’ daily procedures, integratable with internal tools to cut the manual jumping between systems, and able to automate some messages. On the infrastructure side, that’s already business as usual in many countries. What’s more interesting with the recent changes is what type of information is being exchanged and the additional value it brings. On one side, more countries — especially under EU regulation, usually via national banking associations — are taking the initiative to find proper infrastructure for their banks and to accelerate data exchange. We had one really exciting story with a medium-sized EU country that launched its tender in February and took just three months to run the whole selection and decide, at the end of May, that we’d won. That three-month cycle is a huge record. Other countries are moving more slowly, but the requirements are pretty similar. On the other side, regulators are trying to support their banks. There’s a lot of talk about the PSR — the Payment Services Regulation — and Article 83, and a cross-European solution. But before that, individual countries are already changing their laws to make things clearer, especially around fraud. We saw good changes earlier this year in Norway, then France, and now, from 1 July, in Estonia, where a new law states clearly that banks should exchange data and mutual RFIs about fraud cases, and that instant payments can be suspended or slowed in cases of fraud. Before that law, some banks were doing it and some weren’t; it was uncertain whether they could. Now it’s written down, so fraud teams know that if they share intelligence through the infrastructure, one concrete action available to them is slowing a payment to win more time. That makes them more confident to do automated, real-time data sharing. In the old days it was manual: one agent triggered an RFI over the Bridge system, and the other bank’s operations team responded. Now, thanks to the legal changes, they can use the same infrastructure for automated messages, which increases volume and processing power — and they catch more fraud. Speed is improving massively, the countermeasures are getting better, and countries’ ability to adopt new technology has improved enormously over the last six months.
Handing money to another bank with no way to warn them
Nicola: The speed is crucial, isn’t it — and the scalability. The will is there, the legal precedent is there, and it’s happening across multiple countries. Pallavi, you’re at Bank of China, serving multiple jurisdictions. You’re based in the UK, but you have the cross-border challenge, and some of the regions Taavi is describing will include your customers. How important is it that we get to a more global way of doing this information sharing, and what could it mean for a bank like yours?
Pallavi: I’ve worked in this industry a long time, and I have handed terrorist-financing funds to another bank without any information, and I feel really sad about that. We knew the funds were from terrorist financing, we’d received consent, but we had to move them on to another third-party bank with no information attached. I’d love to see that gap close. In my experience with the high-street banks, a lot is still siloed: you work in fraud investigations, so you only handle investigations; you don’t see what’s happening on the fraud first line, or on the beneficiary side. Your job is just this much, and no more. Those silos need to break down. We used to worry about organised crime groups; now we’re giving organised-crime capabilities to ordinary criminals too. The barrier to entry for fraudsters is so low. It used to be people specialising in phone fraud or romance scams; now, with fraud as a service and phishing as a service, they can buy everything at the click of a button. Take contact centres — I started my career in a contact-centre role. It was a big achievement to catch one fraudster in a nine-to-five day, to stop one person accessing an account, and it made me so happy. But now you’ve got voice cloning calling in and actually pulling funds out. So the change needs to come to contact centres first, because that’s where they’re attacking. Criminals are innovative and agile, and they know how every high-street bank works. As banks, we need to break those silos too and say: we had a fraud loss here, an AML loss there, and this is how we join them up. A lot of high-street banks are moving towards that approach, but again, everything is very slow.
Nicola: The contact-centre point is crucial, because it’s a place where you can gather so much intelligence if you have the structures to do something with it. A lot of my recent work is with contact centres and financial institutions on the role they play in gathering intelligence — with the victim. How do they intervene? There’s real skill in that, and the data gathered there will be important for whatever investigation comes next. But that information has to go somewhere. We can’t just rely on payment risk scores on the payment rail; we have to bring all of that intelligence together — the investigators, the emotional first responders in the contact centres dealing with victims, or people who may be victims and don’t realise it yet — in a way that’s useful and gets to the right people at the right time. Taavi, in terms of where Bridge is being used across Europe, and Pallavi’s point about deepfakes, synthetic voices and fraud as a service — how are we seeing Bridge and the movement in Europe disrupt some of these networks? Is it posing a particular challenge for you, or is it something you can actively tackle?
Why fraudsters don’t need deepfakes
Taavi: For me these are two parallel discussions that are only semi-correlated. On one side, the fraud business model — how fraudsters operate in decentralised organisations, using more modern technology — is definitely happening, and we need to be very aware of it. I’m glad to see new startups tackling these specific problems: companies building AI agents that play the victim in front of fraudsters to waste their time, or gather evidence and data points about fraudulent IBANs and entities to hand to the banks. So there are initiatives tackling the newer trends. At the same time, from my own perspective, the average level of crime-fighting capability is so low that fraudsters don’t need any modern technology. They just need to be half a step, or one step, ahead. There doesn’t need to be any deepfake involved. Of course they’re innovators and they can use it, but it’s cheaper and more efficient to use old-school methods, because crime fighters aren’t doing the basic hygiene. One of the core parts of fraud fighting is getting more data in real time — and if you do, you can build all the wonderful engines to make fair decisions and investigate. But the repetitive problem is that institutions can’t even use the raw data they gather internally. They first need to resolve how to give crime fighters access, in real time, to the data they already control. It gets even worse when you talk about real-time data from other institutions around them. As long as we haven’t solved that, fraudsters can use very basic technology and still make money. And some of what we’re doing as a broader community actually makes it worse. In the EU there’s the eIDAS 2.0 programme — an e-identity or virtual identity for people — and crime fighters in many countries expect it to reduce fraud, because in theory it should be more certain to verify who’s behind the screen. In real life it will increase fraud. In countries where e-identity has been used for a long time, fraudsters find it very easy to take over someone’s whole virtual identity, log into banks, take loans in their name and do everything else. E-identity is very good and useful for end users and consumers, but the quiet assumption that it will make crime fighters’ lives easier is wrong — it will make their lives much harder, and make things easier for criminals.
Nicola: Such a good point — both points, but the e-identity one especially. It’s not just Europe; I work a lot in the UAE, where different jurisdictions have similar e-identities, and it creates a culture of “nobody can pretend to be us, because we all have our unique ID.” It’s very government-backed, and it creates a false sense of security — it must be true. But as you say, when a criminal gets hold of that, there are no checks later on, because you’re not going to ask them to validate their identity a different way. You’ve already done it. So when it’s compromised, it becomes an even bigger problem.
Privacy is becoming the new excuse
Nicola: I’m going to ask a bit of a wild-card question. About five years ago we talked a lot about friction versus fraud. The customer-experience people wanted everything frictionless — fast onboarding, fast payments, slick and quick — and that created a big problem for fraud and financial crime. We’ve since come round to the idea that some healthy friction, in the right place, makes people stop and think. So that argument has more or less gone away. What I see emerging now is privacy versus fraud. Privacy is used as a reason not to share data — GDPR, and so on — and we’ve unpicked that on other episodes to show it’s simply not true. Another example: this week WhatsApp announced it will move from phone numbers to usernames, which is privacy by design — you don’t necessarily want to give out your phone number. But in prioritising privacy, what do you think the knock-on effect for financial crime is?
Pallavi: It’s going to create a bit of chaos. Whatever we do, we seem to be giving rise to more financial crime and more potential fraud victims. Friction versus fraud was still manageable — you knew it was the customer, they’d logged into their account, and you could ask, “Are you sure you want to make this payment?” With privacy, the controls have to change. They need to be designed around what information the customer is actually going to disclose. Again, the industry needs a proper process, and the regulator needs to step in and say, “This is what we’re seeing, so let’s start doing something about it.” But it will all be slow. Mules are across every bank in the UK. If I close a mule down in my own bank, that person can open an account in another bank ten or twenty minutes down the road. So cross-bank and cross-border detection needs to step in, and something concrete needs to come in, because we’re giving rise to more and more victims. It’s not good when victims lose so much money and the industry can’t do anything. There are cases where victims have lost huge sums, but the thing that stays with them for so long is the guilt they carry, even if the bank has reimbursed them. That needs looking into. It makes me really sad that we reimburse them, but at the end of the day it stays in their mind for a long time.
Nicola: Absolutely — the harm is always more than financial. Especially when we’re dealing with numbers: going back to your point about SARs, under £3,000 you now don’t need to produce one. Thirty thousand pounds to a large business may not feel like a lot, and may not carry the emotional harm, whereas £300 to someone who hasn’t got that to lose can be life-changing and devastating, with much longer ramifications — particularly if it was done in a controlling, coercive way. So you’re absolutely right, Pallavi. Coming back to privacy versus fraud, Taavi — this is something you’ve had to really understand the legalities of, particularly around data sharing. Do you think there’s a pushback on privacy in the current environment, and that it’s affecting financial crime?
Taavi: When you brought up WhatsApp, it reminded me of my work 20 years ago at Skype, where I was head of the data science and fraud team. At Skype we had usernames, and everyone could choose — whether it was Taavi.Tamkivi or some random combination of letters. People were free to choose, and Skype covered the whole world, but I never thought I needed to know exactly who was behind an anonymous account. So I still wonder why WhatsApp needs phone numbers at all. On our current topic — privacy and GDPR are still used by many people as an excuse not to take serious action. It’s more convenient not to dig into the detail of the GDPR requirements. I’ve seen so many misinterpretations of what you can and can’t do, what is and isn’t personal data. Take an IBAN — can we treat it as an anonymous username, and is it okay to share, with the banks around you, how old the IBAN is, or the average incoming and outgoing volume on it? Some European-wide data providers share this kind of information quite freely, which means that for them an IBAN isn’t super-delicate PII. Yet some banks still treat it as something they can’t share with anyone — because it’s easier not to act if you use that excuse. Some companies say GDPR requires PII to be treated with the highest security standards available on the market. That’s not true: if you read the regulation, it has to be secure, you shouldn’t over-engineer it or make it overly complex, but of course it must meet your legal obligations. There’s also ongoing learning about how wide the set of data points needs to be to hand over a really crucial signal. Some people think they’d have to transfer the whole KYC profile to another bank, which sounds crazy — and it would be. But to give the signal that a single transaction is most likely fraudulent, you don’t even need the customer’s name. You just need to refer to a transaction ID, or the IBAN, maybe the amount — which is completely different from the whole KYC profile. If people won’t get into that level of analysis — comparing AML regulations, fraud regulations and GDPR, and their own internal risk assessments — it’s easy to say privacy matters more than fraud fighting, or vice versa, and that’s not a constructive discussion at all. But I’m happy to see that, bank by bank and country by country, people are willing to dig in. The RFPs we see from banking associations are very mature about what they’re asking technology providers for. They understand their members’ data-processing rights and duties, and what’s expected from providers. That maturity is spreading, and it makes it far easier to come up with constructive solutions.
Pallavi: I agree with a lot of Taavi’s points on data sharing — it’s been made into a major thing. Before the pandemic, before GDPR really kicked in, I was in a role where I could call up a third-party bank and say, “We have concerns about our customer — it’s a mutual customer.” Just simple questions, two minutes: is the customer funding the account with wages, or with benefits? The other person would say, “It’s only benefits.” Fine — that starts building a picture, rather than making it a big deal. We just wanted to know what had actually happened with a particular transaction. I’ve been in those roles: the funds have gone to that bank, so let’s see — has the customer withdrawn them, or paid them to someone else? — and you could build a picture of the customer on your side. I’m really sad that it’s all gone away, because we used to get the chance to speak to other banks. Keep it short and sweet — some small, minor piece of information can add a lot to your investigation.
Taavi: That’s a really important point people should grasp. Compare the pre-pandemic data-protection layers: it was legal back then, and it’s legal now. It’s just that we now have clearer rules of the game, and people need to know how to use them. It’s not about a lack of legislation, or overly controlling legislation. What’s needed is more maturity in the responsible people’s heads — to say, “Yes, I’m following it, I’ve been following it all along, but there are restrictions: audit logging, four-eye principles.” There are extra steps, of course, but they don’t mean you can’t do what you were already doing years ago.
What the next twelve months hold
Nicola: It calls for strong leadership and transparency about what this actually looks like. That’s one reason I like talking to you, Taavi, about what you’ve done in other jurisdictions — it offers a roadmap, and it reassures people. In a world with so much at risk in our roles, so much uncertainty around AI and regulation, so many changes at once, having strong leaders who know what they’re talking about and give practical guidance is really helpful. So if you were writing your predictions on paper again today, what would you change, sharpen or add? Where do you think we’re going over the next twelve months?
Pallavi: I’d love the social media companies to come under one umbrella. Almost every fraud and scam originates on social media, and that’s why we struggle. As a bank, all I can see is that the customer has lost money — that’s the whole story I get. I don’t get to see whether the ad or post the customer responded to has been taken down. So it’s high time the social media companies came under one banner and got this sorted. My other prediction is about AI — and this is the first podcast where I haven’t mentioned it. AI is available to everyone, but the real differentiator won’t be who has the best AI. It will be who has the best data, the best governance, the strongest collaboration, and the courage to redesign their financial-crime programmes around how criminals actually operate. Banks have gone digital — everything is digital — but financial crime is becoming more industrialised, and our response needs to evolve much more quickly.
Nicola: Absolutely. What about you, Taavi — what do you see over the next twelve months?
Taavi: It depends heavily on the region. Comparing the UK and the rest of Europe: in the UK, thanks to initiatives like Stop Scams and the Global Anti-Scam Alliance, and to FATF leadership, I think we’ll see more collaboration between sectors — social media, as Pallavi said, but also telcos — and some success coming out of pilots and real-life work. Banks themselves moving fast into efficient crime fighting and cutting fraud losses significantly — that might take a bit longer. In the European Union, thanks to the Payment Services Regulation that’s coming, more banks and associations are realising it’s actually coming, with mandatory requirements, and the liability is being put on the banks — not on telcos yet, not on social media yet. So banks will find themselves under huge pressure to resolve it, which means they’ll move faster on different initiatives — data sharing being part of it, but also the speed of actions. That’s where I agree AI agents can help make faster decisions, but not only them: direct API integrations between systems will help too, because quite often these decisions are simple and programmable. They don’t need broad context or dynamic decisioning, where agents are good — it’s straightforward: if this happens, send a message there and suspend the payment. So there will be more technology providers helping to automate things, agentically or non-agentically, to increase the speed of these transactions and the controls over them.
Pallavi: I’d add one more point. After the PSR came into the UK, it only covers the UK jurisdiction. I can go and talk to another third-party bank about funds that are proceeds of crime — but fraudsters have found a gap by moving them into cross-border payments. So cross-border payment flows need to be streamlined. Look at which countries your customers are sending funds to, put those countries on your watch list or transaction-monitoring system, and start intervening in those payments and asking the customer questions. They’ve found a good crack: if it’s a UK account it goes on the scanner, but if the funds travel internationally, they don’t.
Nicola: Whenever we tighten a rule or regulation so we can’t do something, we just get displacement — it sends the problem over there. The only way to truly tackle this is for the threshold to rise everywhere, with all the layers covered or overlapping. That’s the constant problem. Predictions are easy to make and much harder to hold yourself to later, but you’ve both just done that — reflecting on where we’ve been and where we’re going. If there’s one thing to take from this conversation, it’s that the collective network isn’t a someday idea anymore. It’s under construction. We’re all part of it, piece by piece, and I’m sure we’ll be back to check on it again. Thank you both so much for joining me on Follow the Money — we look forward to seeing you again soon.
Pallavi: Thank you, Nicola. Thank you, Taavi.
Nicola: Thank you.
Taavi: Thanks, both.