How AI-enabled attacks, expanding liability, and weak governance are turning fraud prevention into a leadership responsibility
For years, many organizations treated fraud as an unavoidable operating expense. Losses were investigated, written off, and handed to legal, compliance, security, or insurance teams to resolve.
That mindset is becoming increasingly dangerous.
Fraud can consume executive attention, damage customer relationships, disrupt acquisitions, jeopardize government contracts, trigger regulatory investigations, and create criminal or civil exposure. In serious cases, the consequences can threaten the continued viability of the business.
During a recent episode of Bawn’s Crushing It podcast, Jonathan Trimble spoke with Michael Ruck, a London-based partner and financial crime attorney, about the changing fraud landscape. Their discussion covered AI-assisted impersonation, corporate liability, sanctions compliance, insider risk, and the organizational weaknesses that allow fraud to spread.
The central lesson was clear:
Fraud prevention is no longer simply a legal or accounting function. It is an enterprise risk management responsibility.
The direct financial loss from a fraud may be the most visible consequence, but it is often only the beginning.
A significant incident can require simultaneous involvement from executives, attorneys, investigators, cybersecurity professionals, insurers, communications teams, regulators, customers, and employees. It can also interfere with mergers and acquisitions, financing, government contracting, and other strategic business activities.
As Ruck explained, fraud committed against a company—or on its behalf—can create substantial demands on time, resources, and executive attention while also producing reputational and regulatory consequences.
This resembles what organizations experience after a major cyber incident. The initial intrusion may happen quickly, but the response can continue for months or years. Leadership must determine what happened, preserve evidence, communicate with customers, manage regulatory inquiries, work with insurers, and restore confidence.
The operational disruption can easily exceed the original monetary loss.
Businesses therefore need to stop asking only:
How much money could we lose?
They should also ask:
What would this incident prevent us from doing?
A fraud event can delay growth, distract leadership, damage client confidence, and expose weaknesses that regulators or business partners may not have previously noticed.
Traditional fraud-awareness training frequently teaches employees to identify obvious warning signs:
AI is rapidly reducing the usefulness of many of those indicators.
Criminals can now produce polished emails, realistic text messages, convincing voice recordings, and increasingly sophisticated video impersonations. They can also use publicly available information to research executives, identify reporting relationships, imitate communication styles, and create highly personalized requests.
During the interview, Ruck described how AI can eliminate the language and formatting mistakes that once helped employees recognize phishing attempts. He also discussed fraud scenarios involving deepfake video calls in which employees believed they were communicating with senior executives and other members of their leadership team.
These attacks are not simply the result of someone pressing a button and asking an AI system to commit fraud.
The most successful attacks resemble carefully planned heists. Criminal groups may study:
AI makes the impersonation easier, but human reconnaissance and social engineering make it believable.
That distinction is important. Businesses do not need to prepare only for autonomous AI systems. They need to prepare for organized criminals using AI to increase the speed, scale, and credibility of familiar fraud techniques.
Many fraud attempts are designed to create urgency.
An employee may receive what appears to be a message from the CEO, CFO, attorney, customer, or vendor instructing them to:
The employee may recognize that the request is unusual but still comply because the instruction appears to come from someone with authority.
This is why awareness training alone is not enough.
Organizations need payment procedures that remain in effect even when a senior executive appears to demand an exception.
Practical controls may include:
The purpose of these controls is not to slow the business unnecessarily. It is to ensure that no single email, voice call, video conference, or executive request can override the safeguards protecting the company’s funds.
Many regulated organizations are required to maintain written security, compliance, or risk-management plans. Smaller companies may respond by downloading a template, changing the company name, and storing the document until a customer, auditor, insurer, or regulator requests it.
That approach may satisfy a documentation request temporarily, but it does not create a functioning program.
The same problem can occur with anti-fraud policies.
A generic policy will not identify:
Ruck noted that organizations increasingly need to assess fraud risks specific to their operations instead of assuming that a standard technology product or policy template will resolve the problem. He also described expanding attention to fraud committed on behalf of a company—not only fraud in which the company is the victim.
A defensible anti-fraud program should connect policy to actual business processes.
That means documenting not only what the organization intends to do, but also:
One of the most common governance failures is assigning a risk to an executive who does not understand it.
An organization may technically designate someone as responsible for cybersecurity, fraud, AI, sanctions, privacy, or regulatory compliance. But assigning a name does not create effective oversight.
Ruck identified several recurring weaknesses:
In some regulated environments, senior managers are increasingly expected to understand the risks within their areas of responsibility, challenge the information they receive, and demonstrate how they supervise those activities.
Boards and executive teams should therefore ask:
Responsibility without knowledge is not governance. It is simply a name on an organizational chart.
Most organizations conduct some form of screening before hiring an employee. Once the person begins working, however, monitoring often ends.
Yet circumstances change.
Employees may experience financial distress, personal pressure, coercion, conflicts of interest, addiction, resentment, or other situations that increase risk. This does not mean organizations should treat employees as suspects. It does mean that companies should identify positions where one person can cause significant financial or operational harm.
Ruck discussed the growing interest in continuous monitoring, financial-risk indicators, and controls such as four-eye reviews for sensitive activities.
Some organizations also require employees in sensitive roles to take an uninterrupted block of leave while access to systems and communications is suspended. This can expose fraudulent activity that depends on one person continually manipulating transactions, messages, or records.
Other practical insider-risk controls include:
The objective is not surveillance for its own sake. It is reducing the ability of one individual to conceal misconduct indefinitely.
Organizations may assume sanctions compliance applies only to banks, multinational corporations, defense contractors, or companies directly conducting business in sanctioned countries.
The reality is increasingly complicated.
A company may sell a product to an apparently legitimate distributor, only to discover that it was transferred through several intermediaries and ultimately reached a restricted entity, individual, or jurisdiction.
Businesses must therefore understand not only their immediate customer, but also:
This places a growing compliance burden on organizations that may have limited legal, compliance, or investigative resources.
Ignoring the issue because enforcement appears unlikely is still a gamble. A company may avoid scrutiny for years, but a single enforcement action can create financial penalties, reputational harm, operational restrictions, and extensive legal expense.
No organization can eliminate every possible fraud, cyber, sanctions, or insider risk.
Attempting to address everything at once can result in excessive spending, unfocused policies, and controls that employees eventually ignore.
Ruck suggested that leaders begin with a more practical question:
What are the key risks to our business in this space?
Organizations should identify the scenarios most likely to cause serious harm and determine whether they have the people, technology, processes, and outside support needed to manage them.
A focused assessment might begin with questions such as:
The answers will usually reveal whether the organization has a working fraud-prevention program or merely a collection of informal practices.
Fraud, cybersecurity, sanctions, compliance, and insider risk are often managed as separate disciplines. In reality, they frequently intersect.
A compromised email account can enable payment fraud. A fraudulent vendor may create sanctions exposure. An insider can misuse legitimate access. A weak reporting structure can prevent executives from recognizing a pattern until the damage becomes severe.
That is why fraud prevention should be viewed as part of the organization’s broader resilience strategy.
Strong programs combine:
The organizations best positioned to withstand fraud are not necessarily those with the largest budgets. They are the ones that understand their most consequential risks, assign responsibility clearly, and consistently perform a small number of effective controls.
Fraud is not simply a cost of doing business.
It is a business risk that leaders must actively manage.
Bawn helps organizations evaluate cyber, fraud, payment, and operational risks; identify control gaps; and develop practical programs that can be implemented, tested, and defended.
Start by identifying the scenarios that could cause the most damage—and determine whether your current controls would actually stop them.