Fraud, Consumer Duty and the Test for UK Banks

1-888-216-3544

             
Contact Us
Fraud & Consumer Duty

Fraud, Consumer Duty and the Test for UK Banks

How does Consumer Duty change fraud prevention for UK banks by focusing on customer outcomes, intent, vulnerability and scam prevention?

Fraud, Consumer Duty and the Test for UK Banks

Are we protecting customers before the harm happens?

Fraud & Consumer Duty
Mary believes she is moving her money to safety. Her bank’s security protocols recognise the device she’s using, validate her login details and accept her payment authentication code.

From a pure authorisation standpoint, the bank can say it has fulfilled its duty to the customer to ensure the transaction is normal and safe.

Yet Mary may still be about to hand over her entire savings pot to a criminal. Consumer Duty asks banks to look beyond simple authorisation and consider whether there were warning signs before Mary pressed “send”.

Mary’s story: when authorisation is not the same as control

Mary receives a call from a friendly, articulate gentleman claiming to be from her bank’s fraud team. The caller knows enough of her personal information and transaction history to sound credible. She is told that her account is under attack and that she must move her savings to a ‘safe account’. She is understandably alarmed and acts with urgency as she’s coached through every step.

The bank’s standard fraud checks will find nothing amiss. The payment appears valid. Mary uses her usual phone, enters the correct credentials, passes authentication and confirms the transfer. But what the fraud checks don’t account for, is intent. She is not acting freely. She is being manipulated.

This distinction sits at the heart of the relationship between fraud prevention and Consumer Duty. The question is no longer only whether a transaction was authorised or whether the bank followed its due process. It is whether the bank did everything it could to prevent harm. Was the customer properly protected from foreseeable risk?

Consumer Duty makes fraud a customer-outcomes issue

The Financial Conduct Authority’s (FCA) Consumer Duty sets a higher standard of protection for retail customers and requires firms to act to deliver good outcomes. Its three cross-cutting rules require firms to act in good faith, avoid causing foreseeable harm and enable and support customers to pursue their financial objectives.

Fraud belongs directly within that framework. It affects whether a customer can use an account safely, understand a warning, make an informed decision and access effective support. For banks, preventing fraud is not only about reducing their financial losses. It is also about showing that reasonable, proportionate steps were taken to protect customers from risks that the bank could reasonably anticipate.

The FCA also expects firms to consider customers’ needs, characteristics and objectives – including characteristics of vulnerability across the customer journey – and to understand, and importantly evidence, whether good outcomes are being achieved.

What the regulation requires in practice

Consumer Duty is deliberately outcomes based rather than a checklist of prescribed controls. The Consumer Principle stating ‘a firm must act to deliver good outcomes for retail customers’ is supported by the three cross-cutting rules and four outcomes covering products and services, price and value, consumer understanding and consumer support. In a fraud context, these elements combine to ask: was the journey designed around customer needs? Did it communicate risk clearly? Did it provide effective support? And did it deliver an outcome that the bank can evidence?

The obligation to avoid causing foreseeable harm is particularly important. It does not guarantee that no customer will ever suffer fraud; Consumer Duty is after all underpinned by reasonableness. But where harm is known, such as in scams or account takeover fraud, the firm should consider how its products, communications and support can help prevent or reduce it. For Mary, the regulatory question is wider than whether the payment journey worked as designed. It is whether the design took proper account of the foreseeable risk that a genuine customer could be manipulated into using it against her own interests.

The four outcomes provide a practical framework. Products and services should meet the needs, characteristics and objectives of the target market, pointing towards journeys designed with scam risk and customer vulnerability in mind. Price and value are less directly about transaction monitoring, but fraud losses, service limitations or poor support can affect the benefits customers reasonably expect. Consumer understanding requires communications that support effective, timely and properly informed decisions. Consumer support means meeting customers’ needs throughout their relationship with the firm.

Vulnerability also matters because Consumer Duty requires good outcomes for all customers, including those with vulnerable characteristics. Vulnerability may be enduring, temporary or situational. A customer under acute pressure from a criminal may not present as vulnerable in the usual way, yet their ability to make an informed decision could be impaired at the point of payment. A proportionate fraud strategy should therefore test how interventions, contact routes and escalation processes work for various groups of customer – not simply the ‘average’ customer.

Finally, Consumer Duty creates an ongoing monitoring and governance expectation. Firms must regularly assess, test, understand and evidence customer outcomes, identify shortfalls, and act. The governing body must receive an annual report on monitoring and required action. For fraud, this supports a virtuous feedback loop: detect an issue, understand who was affected, identify the root cause, change the journey or control and test whether the change improved outcomes. That demonstrates a materially higher standard of care than showing that a warning was displayed or a policy was followed.

The uncomfortable problem with authorised fraud

APP fraud exposes the pitfalls of treating a completed authentication step as proof of genuine intent. A customer may press the button while feeling under pressure on a live call, following instructions from someone impersonating a bank, the police or another trusted organisation.

Reimbursement matters, but it is not the same as prevention. Even when money is returned, the customer may still experience anxiety, embarrassment, disruption and a loss of trust. For Mary, the better outcome is not simply a faster refund. It is an intervention that helps her recognise the scam before the money leaves.

This is where Consumer Duty changes the framing. A technically valid journey may still result in a poor customer outcome.

Fraud has moved into the customer journey

Fraud risk rarely appears at one isolated moment. Signals can surface at onboarding, login, device registration, setting up a new beneficiary, card-not-present activity, inbound payments, outbound payments and account servicing.

In Mary’s case, the payment alone may not tell the full story. Yet, the wider context might: a new payee, unusual transaction speed, a remote-access tool, an active phone call, a sudden unexpected change in behaviour or a payment inconsistent with her normal activity.

That is why banks need a connected view across all customer journey touchpoints. The objective is not to treat every customer as suspicious. It is to distinguish genuine behaviour from manipulation with enough confidence to intervene when it matters and allow legitimate customers to continue with minimal friction where certainty exists.

Good fraud prevention should create better friction

Poor controls create indiscriminate friction; repeated step-ups, generic warnings, unnecessary declines and avoidable calls. Better fraud intelligence helps create purposeful friction only when the context justifies it.

A generic ‘are you sure?’ pop-up message is easy to ignore, especially when a criminal knows to expect it and can coach the customer to hit ‘yes’. A specific warning is more useful, such as: ‘We are seeing signs that someone may be remotely connected to your device. If anyone is telling you what to do, stop and contact us using the number on the back of your card.’

This aligns closely with the FCA’s consumer understanding outcome. The FCA says firms should help customers make effective, timely and properly informed decisions, with information that is fair, clear, not misleading and provided at the right time. In a fraud journey, the quality and timing of the intervention can determine whether the customer pauses or proceeds.

The evidence test: prove protection, not just process

Consumer Duty raises the evidence bar. It is not enough to show that a control exists; firms need to assess, test, understand and evidence the outcomes customers receive.

For fraud leaders and boards, that means looking beyond losses, alert volumes, reimbursement and case-closure times. Those measures remain important, but they should sit alongside evidence of scams prevented before payment, customers protected through targeted interventions, vulnerable customers supported, high-risk journeys escalated and lessons fed back into product and journey design.

The FCA’s review makes clear that strong Consumer Duty reporting is not simply about producing more data. It is about using reliable evidence to understand customer outcomes and act when those outcomes fall short of acceptable. For banks, the practical test is whether they can evidence why they intervened based on the warning signs that were present, whether the intervention helped the customer understand the risk and what happened next.

The strongest response is not, ‘we reimbursed Mary after the fraud.’ It is ‘we recognised the risk, intervened at the right moment, explained the concern clearly and can evidence the positive effect it had on the outcome.’

The strategic implication for UK banking

Digital banking gives customers speed, convenience and control. It also gives criminals new ways to exploit trust. If a bank makes it easy to move money instantly, it must be equally serious about recognising when that speed is being abused. If it relies on digital authentication, it must also consider when authentication has been completed under pressure.

No bank can stop every scam. Consumer Duty does not change that reality. But it does strengthen the expectation on firms to understand foreseeable harm, act proportionately and learn from customer outcomes.

For fraud leaders, that is an opportunity. It moves fraud prevention from a narrow loss-and-operations conversation into customer strategy, journey design and trust. The next phase of fraud prevention is not only about confirming identity. It is about understanding intent, control and context.

Why? Because the best customer outcome for Mary is not a faster refund after the harm has occurred. It is stopping the harm before Mary ever has to suffer the loss.

Have Sales Contact Me

Related Resources

Loading...

Products You May Be Interested In