Listen to the Article: External Fraudsters Emerging as Bigger Threat to Financial Organizations

The risk landscape for financial institutions is getting tougher as they face environmental, geopolitical and market challenges. Fazzaco published an article last week revealing the shocking details of the Milton scam network behind EverFX, according to a BBC investigation.
Against this backdrop, how are financial institutions adapting to the growing trends of online trading, mobile trading and artificial intelligence technology that emerged earlier this year? Are they taking enough precautions to protect themselves and their clients? The World Health Organization declared on May 5th that the COVID-19 pandemic is no longer a public health emergency of international concern, signaling the start of a new era. But in a volatile economic environment, what policies and incentives are financial institutions adopting to stay ahead of the curve? And what kinds of fraud risks will they have to deal with in the coming years?
A report by PwC on risk and economic crime noted that although various risk behaviors have decreased thanks to compliance policies, internal training and other measures, bigger threats are still out there. Organizations are vulnerable to external fraud attacks that can cause serious damage to their reputation.
Cybercrime Tops the List of Threats for All Industries, Customer Fraud Hits Financial Industry Hard
According to PwC, fraud, corruption and other economic crimes have been dropping steadily across all industries from 2018 to 2022. In 2022, only 46% of the surveyed companies reported experiencing some kind of fraud or economic crime in the previous 24 months (2021-2022).
But even as risk indicators keep falling, risk events still inflict huge losses on companies of different sizes. More than half (52%) of those with annual revenue above US$10 B said they encountered risk events in the past 24 months, with more than US$50 M involved. By contrast, only 38% of companies with annual revenue below US$100 M said they encountered risk events, with only 1 million dollars involved.
So what are these risk events? And which one is the most threatening?
The data below shows that the three main types of risk events that all industries face are: Cybercrime, Customer Fraud and Asset Misappropriation. We averaged the data from all industries and compared it with the data from the financial industry (the top three types in the financial industry do not include "asset misappropriation", but "KYC failure" instead):

The graph shows that cybercrime is the biggest risk for all industries, while customer fraud is the most serious risk for financial service institutions. Both of them have one thing in common: they are caused by external factors.
Pandemic's Impact on Organizational Risk Management Over Three Years
Back in 2021, Fazzaco reported on a data report by ASIC, the Australian watchdog, which indicated that financial fraud reports soared up by more than 200% during January to February 2021. The pandemic has posed unprecedented challenges for organizational risk management as well.
The report analyzed five types of risks: Misconduct, Legal, Cybercrime, Insider Trading, and Platform. It surveyed enterprises based on two categories: "New type of fraud experienced" and "Areas of increased risk".

The report also found that the pandemic had a mixed effect on online trading and working. On the one hand, it reduced the internal risk of asset misappropriation, as many employees worked from home and had less access to company assets. On the other hand, it increased the risk of digital security sharply.
Enterprises Still Vulnerable, New Risk Management Landscape Emerges
According to the survey, the risk landscape is shifting as unregulated outsiders grow in strength and influence. PwC's report reveals that nearly 70% of the fraud victims surveyed said they suffered the most from external attacks, or ones that had some external involvement. What's more, these external fraudsters are not bound by the internal risk controls that apply to insiders, such as policies, training and investigations.
The most common external threats to financial institutions are cyber hackers and organized crimes, both of which have surged in the last two years. The report indicates that cyber attacks accounted for about a third of the external risk incidents, while organized crimes made up 28%.
Online platforms are also hotspots for criminal activity. Two out of five respondents said they had faced fraud related to online platform services, such as inadequate know-your-customer (KYC) processes,disinformation and so on.
Conclusion
PwC's report offers a fresh insight, pushing financial institutions to step up their game in the tough post-pandemic world, where they face major threats from external risks like cybercrime and customer fraud.
But will these measures be enough to deal with the potential new types of fraud and economic crimes that may crop up in the future? How can financial institutions protect their own bottom line while also looking out for their customers' rights and interests? These are questions that we need to think and talk about more.
Subscribe Now

