This article starts after a bank's monitoring or risk system surfaces a signal. The signal might be an unusual login or a transaction that breaks a customer's normal pattern.
From there, the questions are practical. What may an agent do, and what must a person decide? Can the bank show what happened afterward?
The bank's systems and people own detection and case conclusions. Agents support the approved steps around them. For wider context, see our overview of agentic AI use cases in banking and our agentic banking explainer.
What is the difference between fraud detection, prevention, investigation, and containment?
Banks often blur four separate jobs. Each has its own owner and its own test of success.
- Detection: a monitoring or risk system surfaces a signal. The output is an alert with the reason it was flagged.
- Prevention: a bank-approved action limits a possible loss before it completes. Examples include a step-up verification request or a temporary hold.
- Investigation: a review of records establishes what happened. A person owns the documented case conclusion.
- Containment and recovery: the bank limits further exposure once fraud is confirmed or likely, then works to restore the customer's position. Examples include blocking compromised credentials and reissuing a card.
An agent prepares evidence and carries out steps the bank has authorized.
What does an agentic fraud investigation workflow look like after an alert?
The workflow below is illustrative. Each bank will adapt the steps to its own policies, systems, and regulators.
- Open the case. The agent creates a case from the alert. It records the alert reason and the linked transaction.
- Retrieve permissioned evidence. The agent reads only the sources its permissions allow. Examples include transaction history, device and session records, prior alerts, and contact history.
- Draft a source-linked summary. Each statement points to the original record. The summary is a working aid and carries no evidentiary weight by itself.
- Suggest checks. The agent may propose explanations, such as a new device or a changed payee. It may suggest checks, such as comparing the session with earlier logins. The investigator chooses which to run.
- Route the case. Bank rules send it to the right queue, such as fraud operations or an AML team. Exceptions go to a person with context attached.
- Record the conclusion. The investigator documents the outcome and the rationale. The system keeps a trail of who or what performed each step.
Investigators verify summaries against the original records before relying on them. That check catches retrieval and wording errors. It also keeps the conclusion attributable to a named person.
How do bank-defined authority and human control work in fraud operations?
Human control is risk-based. The bank defines which actions need approval and which bounded tasks an agent may perform. Consequential actions stay attributable and explainable, and people keep control of judgment and exceptions.
Banking OS lets a bank set autonomy by domain, use case, actor, and action. It uses five levels:
- Observe. The AI watches and takes note. Illustrative example: an agent notes that an alert shares a device with two earlier alerts.
- Recommend. The AI suggests the next step, and a person decides. Illustrative example: the agent suggests a step-up verification request.
- Prepare. The AI gets the work ready so a person can finish it quickly. Illustrative example: the agent assembles transaction and session records and drafts the case summary.
- Act with approval. The AI carries out the task only after an employee says yes. Illustrative example: the agent is ready to place a temporary hold and waits for approval.
- Act within limits. The AI handles the task alone, inside boundaries the bank defines. Illustrative example: the agent sends a customer notification on a low-risk alert.
A bank might set Act within limits for low-risk customer notifications and Recommend for account holds. The bank can revoke or tighten a level without changing the underlying model.
Bank control checklist
- Permissioned data: list the sources each agent may read, and block the rest.
- Defined authority: set allowed actions per actor, with limits and required evidence.
- Approval rules: name the actions that need a person and who approves them.
- Source links: require every summary statement to point to a record.
- Audit trail: record who or what took each step, and why.
- Stop controls: keep the ability to suspend or revoke an agent's authority.
- Pre-production testing: run workflows against bank scenarios before customers or employees rely on them.
Which metrics show whether agentic fraud support is working?
Every metric here is a bank-defined option, and every target depends on the bank's own baseline. Measure the starting point before any agent goes live. Report business outcomes such as handling time, evidence completeness, and reversal rates.
Prevention metric options
- Time from alert to a preventive action, as the bank defines it.
- Share of preventive actions later reversed.
- Legitimate customers affected by holds or step-up requests.
- Loss limited, using the bank's own loss definition.
Investigation metric options
- Handling time per case.
- Evidence completeness at handoff to the investigator.
- Share of agent summaries that investigators correct.
- Escalation and rework rates.
- Policy adherence and human exceptions, as control measures.
Where does Backbase fit?
The Banking OS gives intelligence persistent context and bank-defined authority, so it can carry work across systems. In fraud work, that means an agent works from the same case context as the investigator. It acts only inside the authority the bank sets.
Backbase Banking Operations describes risk and fraud operations as AI agents preparing cases for human investigators, who make the judgment calls.
Banks design, test, and simulate workflows and authority contracts in the Banking OS Transformation Engine before they reach production.
120+ banks run on the Backbase platform foundation. That figure describes the Backbase platform foundation. The Banking OS page covers the wider architecture.
FAQs
Can agentic AI detect fraud?
In this article's scope, the bank's monitoring and risk systems detect and surface signals. Agents support the steps after the alert, such as gathering evidence and drafting a summary. People own case conclusions.
What separates a bank-initiated investigation from a customer dispute?
The trigger sets them apart. Because both can involve the same transaction, banks should link the two cases.
Who decides the outcome of a fraud case?
A person. The investigator documents the conclusion and the rationale. The bank defines what agents may do, and it keeps human control for judgment and exceptions.
How should a bank measure agentic fraud support?
Choose metrics for both prevention and investigation, and set a baseline first. Targets are bank-defined. Measure business and control outcomes.
