Anti-Fraud Architecture: Why Two Banks Facing the Same Fraud Need Different Solutions (Part 2)
Fraud isn’t uniform: every institution has its own blind spots, and treating them all with the same protocol is exactly why generic detection keeps falling short. This second article translates a framework that already solved the same problem in another field, precision medicine, axis by axis, into contextualized defense, and closes with four questions any risk team can apply this week.
In the first part of this series, I explained why spending more on cybersecurity isn’t bringing fraud down. I noted that each signal (the document, the biometrics, user behavior) works well on its own, but almost never gets read alongside the others. We call the layer that connects them contextualized defense.
What I didn’t cover there is where the framework for building that layer comes from. And before getting to that, it’s worth being clear about the underlying shift: moving away from classifying risk by attack type and toward classifying it by the full profile of whoever is affected. Fraud isn’t uniform, and every institution has its own blind spots.
This way of thinking already exists in another field. A century ago, German physician Ludolf von Krehl said something similar about his own field: “there are no diseases, only sick people.” Medicine took decades to put that into practice (it needed the Human Genome Project to get the technology to diagnose the whole patient, not just the disease label), but once it did, precision medicine was born: a framework with six very specific axes that today translates, almost frictionlessly, into contextualized defense.
Six Pillars of Precision Medicine Applied to Fraud Prevention
The table below translates each of these six pillars into their exact equivalent in contextualized defense—not as a loose metaphor, but as six concrete capabilities that your current stack probably doesn’t have and that, if it did, would stop fraud that is currently slipping through.
| AXIS | PRECISION MEDICINE | CONTEXTUALIZED DEFENSE |
|---|---|---|
| Taxonomy | Abandons classification by symptom and adopts molecular classification: there are no diseases, only sick people with different profiles. | Abandons classification by attack type and adopts classification by profile: there is no such thing as “fraud,” only institutions with different blind spots. |
| Prior diagnosis | The companion diagnostic anticipates whether a patient will respond to a therapy before it’s administered, avoiding ineffective treatments and adverse effects. | Architecture diagnosis anticipates which controls will work for a specific institution before they’re deployed, avoiding investment in detection that doesn’t stop real fraud. |
| Stratification | Classifies patients into subpopulations based on their susceptibility, biology, and expected response to treatment. | Classifies operations and users into risk profiles based on channel, geography, history, and current attack vector. |
| Integrated data | Integrates genomic, clinical, environmental, and lifestyle information into a single patient profile. | Integrates document, biometric, transactional, and behavioral signals into a single, continuous identity history. |
| Collaboration | Impossible without public-private collaboration: the clinical problem is addressed in one place, validation and industrialization in another. | Impossible without shared intelligence: no single bank sees the whole system, but the attacker does. Consortia between institutions and federated training of AI models reverse that asymmetry without centralizing sensitive data. |
| Sustainability | Supports the sustainability of the healthcare system by avoiding costly, unnecessary treatments for patients who won’t respond. | Supports the sustainability of security spending by concentrating investment where it stops real fraud, not where it improves a module-level metric. |
Of these six pillars, two were already introduced in Part 1 under different names (the continuous identity story was, at its core, about integrated data, while protecting the entire system rather than the individual account follows the same logic I now call collaboration).
The new pillar that interests me most is pre-deployment diagnosis, or what oncology calls a companion diagnostic: a test that anticipates whether a patient will respond to a therapy before administering it, rather than treating blindly and correcting course afterwards.
The fraud prevention industry still does the opposite: it deploys detection and measures the outcome once the fraud has already entered. It’s the difference between deploying a mule-account detection engine and waiting months to see how many it caught, versus diagnosing beforehand what type of mule network operates in that specific market (individual accounts purchased one by one, synchronized networks, fronts recruited through social media) and calibrating the engine to that pattern from day one, rather than six months after seeing it fail.
Architecture diagnosis, which means assessing in advance which controls a specific institution will actually need, is what reverses that order.
Who Is the Patient in This Comparison?
Here, the parallel has an important twist worth highlighting. In precision medicine, the patient is the individual. In fraud defense, the patient is the financial institution, with its technological legacy built up over decades, its specific regulatory framework, the actual composition of its user base, and the effective capabilities of the data infrastructure in the country where it operates.
Two banks with the same clinical symptom may need radically different response architectures, just as two patients with the same diagnosis may require completely different protocols depending on their molecular profile.
Contextualized defense needs to know the patient in order to treat it; there is no one-size-fits-all protocol here.
As in medicine, adopting this model is not simply about incorporating new detection technologies. Precision medicine would not be possible without public-private collaboration: the clinical problem is addressed in the hospital, while validation and industrialization take place in the R&D sector.
Contextualized defense requires the same kind of collaboration between banks, regulators, and technology providers—for example, through consortia between private institutions and federated AI model training that complies with the GDPR. Healthcare has already solved this challenge with equally sensitive data, addressing three fronts at once: privacy, specialization, and improved security.
The fundamental mistake I described in the first article in this series is acting as if each institution sees the whole problem, when in reality it only sees its own slice: its customers, its channel, and its failed fraud attempts. The attacker, by contrast, does see the whole system and tests the same pattern across multiple banks until it finds the one with the blind spot that the others have already closed.
A bank that diagnoses only its own architecture, without cross-referencing signals with the rest of the sector, can improve internally and still remain the weakest link, because its diagnosis is still limited to one fragment of the board.
Four Questions to Assess Your Own Stack
The precision medicine framework translates into four concrete questions that any risk team can ask about its own stack:
In most of the teams we’ve spoken to, at least one of these four questions has an uncomfortable answer. That answer is, in itself, a diagnosis of where the real gap lies in the architecture—and it is the same starting point we use with any bank before proposing a change: first identify which pillar is missing, then decide what to build.
The Next Step
If the diagnosis resonates, if you recognize that same pattern in your own stack—layers that don’t talk to each other and generic controls deployed in an environment that looks like no other—the next step isn’t to start looking for new tools. It’s to first map out exactly where the gap is and how much contextual orchestration you already have in place.
Precision medicine replaces label-based diagnosis—treating the disease—with a diagnosis of the whole patient, integrating medical history, biology, and lifestyle into a single profile. The fraud prevention industry faces the same problem that medicine solved two decades ago: security layers that work well independently but never share context with one another.
A companion diagnostic is a test that anticipates whether a patient will respond to a therapy before it is administered, avoiding ineffective treatments. Its equivalent in contextualized defense is architecture diagnosis: assessing in advance which fraud controls an institution actually needs, rather than deploying generic detection and measuring the outcome once the fraud has already entered.
Because each institution has a different technological legacy, regulatory framework, and user base, just as two patients with the same clinical diagnosis may require completely different protocols depending on their molecular profile. Contextualized defense diagnoses the specific institution before prescribing an architecture; there is no standard configuration that works for everyone.
Because no bank can see the entire fraud system on its own—it only sees its own slice of it. The attacker, however, sees the ecosystem and tests the same pattern across multiple banks until it finds the blind spot that the others have already closed. Sharing contextual intelligence reverses that asymmetry, just as precision medicine depends on public-private collaboration.
Four, drawn from the precision medicine framework: whether it classifies risk by attack type or by complete profile, whether it anticipates which controls will work before deploying them, whether its signals live in a single profile or each module keeps its own…
No, as of August 2026. Instead, the legal framework consists of the U.S. Supreme Court’s June 2025 ruling in Free Speech Coalition v. Paxton, which upheld states’ authority to require age verification for adult content, along with roughly 25 states that have enacted or introduced their own age verification laws. The SCREEN Act, which would establish a federal requirement, remains in committee.
They are beginning to be. Canada explicitly includes AI chatbots in its proposed Safe Social Media Act, placing them in the same regulatory category as social media platforms. The United Kingdom has pledged to ban AI companion chatbots for users under 18, while both Australia and the UK have already extended existing legislation to cover chatbots.