The problem
Fraud detection in the United States is allocated by budget rather than by exposure.
The largest financial institutions operate sophisticated commercial detection systems.
Community banks, credit unions, and regional lenders generally operate with rule based
screening or less. Fraud operations test defences and route toward the institutions that
do not detect them. Capability concentrated at the top of the market does not
eliminate loss. It displaces it downward, onto the institutions least able to absorb it,
in the communities least able to replace a failed local lender.
Federal healthcare claims integrity faces a different constraint with the same effect.
Review is predominantly rule based and post payment: a claim is paid, then audited against
known fraud patterns. A rule detects only what has already been characterised and written
down, and it examines one claim at a time. A provider whose individual claims each
appear defensible remains invisible even when their aggregate billing behaviour is a clear
statistical outlier against peers.
Both gaps share a structural property: they are resistant to rule based detection. Neither
is closed by writing better rules.
And detection, wherever it operates, works only after a fraudulent transaction has been
attempted. Where a victim is deceived into authorising a transfer herself, through
impersonation of a family member, an official, or a bank, the transaction is not anomalous
from the institution's side at all. The only intervention that stops that scheme is the
intended victim recognising it.