01
FINMA and digital fraud risks: key points
- A FINMA survey of 19 banks shows that 8 of 19 institutions, or 42%, have no dedicated digital fraud policy, and only 12 have any structured governance in this area.
- Twenty-six per cent of the surveyed institutions do not conduct horizon scanning to identify new fraud patterns early.
- Deepfakes, forged identity documents and AI-supported attacks make digital account opening more difficult; MROS reports involving digitally opened accounts are increasing.
- Most institutions make little use of collected KYC data for transaction monitoring; TmeR thresholds are often set at CHF 100,000 to CHF 200,000.
- Banks should review their governance, detection processes and role-based training now, before FINMA asks targeted questions.
02
Why is FINMA focusing on digital fraud risks now?
Since the end of 2022, FINMA has recorded a continuous increase in digital fraud cases at banks and persons under Article 1b of the Banking Act. Artificial intelligence and increasing automation, including online access and instant payments, are reinforcing the trend. At the end of 2025, FINMA therefore surveyed 19 banks from different supervisory categories about digital banking. The result was a clear need for action in governance, detection, controls and anti-money laundering prevention.
03
What does FINMA’s survey show about digital fraud governance?
Only 12 of 19 institutions reported having sustainable governance structures for digital fraud, and even these usually rely on staff holding several functions without clear allocation of tasks or documented authority. Three institutions have no governing body for digital fraud risks. Institutions with interdisciplinary fraud desks stood out positively because they combine requirements, controls and processes under clear reporting lines. In addition, 8 of 19 institutions, or 42%, have no dedicated digital fraud policy. Matters such as employee transactions, money laundering and information security are instead addressed without coordination in other directives.
04
How effectively do banks identify new fraud patterns at an early stage?
Twenty-six per cent of the surveyed institutions conduct no horizon scanning at all and therefore do not proactively identify relevant fraud trends. Although 12 of 19 institutions use real-time detection technologies, seven do not evaluate ongoing fraud campaigns or do so only manually. Seven institutions also lack a standard process or response plan for digital fraud cases, and only seven update their response plans at least annually; the remainder react only after a specific incident. Few institutions offer round-the-clock availability for fraud reports, which are usually handled through the general telephone hotline.
05
Are the existing fraud prevention controls sufficient?
Three institutions use no technical controls such as geoblocking, IP risk ratings or device fingerprinting. Around 20% lack key controls as a central management instrument or do not regularly test their effectiveness. Staff training presents a similar picture: where training takes place at all, it is often generic rather than tailored by role, activity and risk exposure, for example for client advisers. Not all institutions identify particularly exposed client segments either.
06
What risks arise in digital account opening?
The survey data does not show a clear increase in fraudulent digital account openings themselves, but it does show more MROS reports involving client relationships opened digitally. A typical pattern involves people being deceived into opening an account using their own valid identity documents and subsequently handing control to criminals; the opening process itself is formally correct. Deepfake and video-manipulation technology also makes it more difficult to identify forged documents during identification.
07
What does FINMA expect from anti-money laundering controls?
The relative number of money laundering suspicion reports connected with fraud varies by a factor of ten among the surveyed institutions, a clear indication of controls with differing effectiveness. Collected KYC information is usually limited and is rarely used for transaction monitoring. Alert thresholds at most institutions are CHF 100,000 or CHF 200,000, suggesting rigid limits rather than specific fraud scenarios. FINMA expects transaction-monitoring systems to identify potential fraud and money-muling cases considerably faster.
08
Frequently asked questions
Does this FINMA Guidance apply only to large banks? No. It is addressed to all banks and persons under Article 1b of the Banking Act, regardless of supervisory category. Smaller institutions should also review their governance and controls.
Is a general information security directive sufficient instead of a digital fraud policy? No. FINMA criticises precisely this uncoordinated approach. A dedicated digital fraud policy coordinated with other directives is expected.
What is a "TmeR" threshold and why is it relevant? TmeR refers to transactions involving increased risks. Excessively high, rigid thresholds, such as CHF 100,000, make it more difficult for monitoring systems to identify smaller transactions that are typical of fraud.
Do we need to provide specialist training for staff? Yes, and it should be role-based. FINMA considers generic training for everyone insufficient. Client advisers, for example, require different content from IT or back-office staff.
What should we review first? Whether a documented governance structure with clear responsibility for digital fraud exists, whether horizon scanning is conducted and whether KYC data is actually used in transaction monitoring.
Primary sources