top of page

The Price of Deception: What Cheap Fraud Does to Expensive Controls

Writer: Elizabeth Travis
Elizabeth Travis
14 minutes ago
7 min read

Weathered silver padlock secures a black latch on a bright yellow wooden door, with ACE visible.

On 6 July 2026 the Financial Conduct Authority (FCA) published the Mills Review, its assessment of how artificial intelligence will reshape retail financial services by 2030. The commentary that followed went looking for a new crime. The techniques the Review names, deepfakes, synthetic identities and personalised social engineering, are not new offences; they are the methods financial crime teams have countered for years, and what the Review says has changed is that attacks become "faster, cheaper, more scalable and more persuasive". Yet the absence of a new crime is not the reassurance it has been taken for. A control framework facing no novel offence but a collapse in the cost of committing the familiar ones is not intact; it is mispriced.


The typology list is not the risk


Financial crime governance is organised around typologies. Firms maintain an inventory of known methods, map controls to each, and refresh the list when something genuinely new appears. That architecture treats the arrival of a new method as the event which changes the risk profile, and it is not the only one. A typology that stays exactly where it is while becoming an order of magnitude cheaper to execute will produce more attempts, more victims and more loss than a novel method that remains expensive to run.


The evidence already points that way. The Home Office Fraud Strategy 2026-2029, published in March 2026, records at least £629.3 million stolen in the first half of 2025, of which unauthorised fraud accounted for the majority at £371.8 million, and bank and credit account fraud rising 19 per cent to 2.6 million cases in the year to September 2025. None of that growth is attributable to a method nobody had seen before. The Strategy is candid that the drivers of persistently high unauthorised fraud remain unclear, and has committed to a call for evidence in 2026 to establish them. A system that can measure the loss but not explain it is describing a change in economics rather than a change in technique.


Controls are priced, not permanent


Every preventive control is an economic proposition before it is a technical one. It does not make an attack impossible; it makes the attack cost more than it returns. Document checks work because forgery of a convincing quality was slow and skilled. Callback verification works because staffing a persuasive conversation costs someone an hour. Mule networks are constrained because recruitment carries risk and overhead. Each of those controls holds a price in it, and none of them states that price anywhere in the risk assessment.


The Fraud Strategy puts the consequence bluntly: "Every new control sparks innovation". Its own history bears this out. When two-factor authentication became standard, criminals moved to manipulating victims into surrendering one-time passcodes and to hijacking numbers through SIM swaps. When spam filters improved, messages were restructured and alternative text formats adopted to get past them. Each measure worked until the cost of defeating it fell below the return on doing so; each then failed for reasons that had nothing to do with the control being poorly designed.


What generative tools change is the slope of that curve. The Strategy describes marketplaces on the dark and grey web selling phishing kits and fraud-as-a-service subscriptions which lower barriers to entry and make scalable methods available to anyone willing to pay, and it observes that criminals are adopting generative tools to improve the sophistication, credibility and volume of attacks. Volume is the operative word. The industrialisation of an old crime does not register as an emerging threat on any horizon scan, because nothing has emerged.


Onboarding assumed forgery was scarce


Identity verification rests on an assumption about supply. A synthetic identity was historically constrained by the difficulty of producing a document that survived inspection and a face that survived a liveness check. Those constraints have gone, and the official response concedes it. The Home Office is working with the Department for Science, Innovation and Technology and the Alan Turing Institute on a framework for detecting deepfake media, including fraudulent documents and synthetic audio, and hosted a Deepfake Detection Challenge in January 2026 with support from Microsoft.


That is not an incremental improvement to verification. It is an acknowledgement that inspecting the artefact no longer settles the question of whether the artefact is real, and that provenance must be established by some other means. Firms whose onboarding checks were built to catch poor forgeries are now running them against a supply of forgeries that no longer exists.


Enforcement will not absorb the difference. In the year to September 2025 fraud was estimated at more than four million offences in England and Wales, around 45 per cent of all crime measured by the Crime Survey, while 3,631 individuals were sentenced for it. Cases take over 626 days to reach charge, against 80 days for the average criminal case. Whatever deterrent effect the criminal justice system exerts on the cost side of the calculation, it is not moving at the speed of the account opening it is meant to influence.


Authentication has a half-life


The clearest official recognition of the pricing problem sits in a paragraph that reads like plumbing. HM Treasury will repeal the existing Strong Customer Authentication technical standards, allowing the FCA to incorporate key standards into its rules and adopt a more agile, outcomes-focused approach. The stated purpose is to let firms deploy authentication methods that can be improved continuously.


Read as a legislative tidying exercise, it is unremarkable. Read properly, it is a concession that a prescriptive technical standard cannot be amended at the rate its assumptions decay. That has an uncomfortable implication for firms that have evidenced compliance against the standard for the better part of a decade. They have evidenced conformity with a specification; they have not evidenced that the specification still resists the attack it was written to defeat. Those are different propositions, and only one of them is what a supervisor will eventually want to see.


Detection is calibrated on scarcity


Monitoring and screening carry the same inheritance, in a less visible form. Detection models learn the shape of past attacks, and past attacks were shaped by what criminals could afford. A model tuned on a period when persuasion was expensive has learned the signature of expensive persuasion: reused scripts, imperfect language, repeated infrastructure, the tell-tale economies of an operation that could not afford to be original every time. Remove the cost of originality and those signatures thin out, while the underlying typology is logged, mapped and apparently well controlled.


The Mills Review makes the point in the language of model management rather than financial crime. It observes that criminal methods, customer behaviour and market conditions all move faster than scheduled retraining cycles, and warns that a model validated on the day it went live can degrade as the conditions around it change, a pattern it labels model drift. Firms have generally read that as an argument for retraining more often. It is also an argument about what the model was trained to recognise in the first place.


Volume compounds the problem at the point where thresholds are set. Alert thresholds are calibrated to produce an investigable population, which means they encode an assumption about the rate of attempts as well as the nature of them. If attempts rise sharply while the typology holds steady, a threshold that was proportionate becomes a rationing device. The alert still fires, the team still clears the queue, and the share of attacks reaching a customer quietly rises. Nothing in that sequence looks like a control failure on a dashboard.


Risk assessments should price the attacker


Three shifts follow. First, enterprise-wide risk assessments should record what each material control costs an attacker to defeat, and how that figure has moved since the control was built. A control whose cost of defeat has fallen tenfold has changed its risk rating, whether or not the typology it addresses has changed at all. Second, control testing should be adversarial rather than confirmatory: the question is not whether a control operated as documented during the sample period, but whether it still resists a well-resourced attempt. Third, board reporting should separate volume from novelty, because a framework that escalates only new methods will report stability throughout the period in which its assumptions are being dismantled.


There is a governance dimension too. Senior managers certify the adequacy of systems and controls against a risk assessment; if that assessment never states the economic premise on which a control depends, the certification rests on a premise nobody has been asked to review. The Mills Review concludes that the Senior Managers Regime continues to apply as systems become more autonomous. What moves is the evidential burden of showing that the duty has been discharged.


Fraud got cheaper, not cleverer


The comfort in the finding that artificial intelligence has invented nothing is a category error. Controls were never a catalogue of crimes; they were a schedule of prices, set when deception was laborious, each holding only for as long as attacking it stayed expensive. That schedule has been rewritten across onboarding, authentication and detection at once, and rewritten without the courtesy of a new name to put on a horizon scan. If firms keep testing their defences against the list of things criminals do, they will keep passing. If they test them against what those things now cost, they will find out which of their controls were ever really controls.


Do you know which of your controls hold because they are strong, and which hold only because attacking them used to be expensive?


If that line is not drawn and documented, we can help you draw it before your loss data draws it for you; contact us.


At OpusDatum we test whether financial crime controls hold at the volumes and costs criminals now face, not whether they were sound on the day they were designed. Our focus is control effectiveness rather than control existence, and the evidence a supervisor will expect when it asks why an unchanged control is still thought adequate.


bottom of page