Skip to main content

As Australia's response to financial crime continues to take shape, the industry conversation has largely focused on liability and reimbursement. The more pressing challenge is prevention: establishing the controls that stop scams from succeeding in the first place. As Fred Slikker, Managing Director of Digidentity, has stated, banks can only do so much if the trust layer underneath the financial system remains fragmented.¹

The limitations of single-point verification

Traditional identity verification confirms that an identity exists, not that the person presenting it is its legitimate owner.

AFCA regularly publishes determinations involving stolen identity documents, and AUSTRAC has warned that students are being recruited as mule account holders.2 Synthetic identities constructed from genuine details belonging to different individuals further demonstrate that documentation alone is no longer a reliable signal of legitimacy.


"By combining data checks, document authentication, and biometric matching, we greatly reduce the chances of stolen identities slipping through the system."
- Dr Memoona Anwar, Chief Compliance and Innovation Officer, Data Zoo3

 

A single point of verification cannot address the full range of identity-based threats. A layered approach is the path forward.

Now more than ever, the responsibility sits with the institution, not the member

The obligation to prevent scams rests with the institution. The Scam-Safe Accord places it across three pillars: disrupt scams before they happen, detect them as they occur, and respond decisively when they do.

Security across the member journey

Ultradata's layered approach maps directly to the three pillars of the Scam-Safe Accord:4 Disrupt, Detect, and Respond.

Disrupt: stopping scams before they succeed

At the point of onboarding, Digital Onboarding with Biometric ID Verification establishes identity through real-time document verification, facial matching, and liveness detection. This confirms the person opening the account is who they claim to be, not a photograph, a fabricated profile, or an identity built from stolen details.

Device and PC fingerprinting builds a profile of the devices a member typically uses. When an unfamiliar device is detected, a flag is raised before the session begins. New device registration notifications trigger immediate alerts to the member, adding a further layer of visibility at the point of access.

Payment controls operate across multiple touchpoints. Confirmation of Payee verifies that the account name matches the intended recipient before funds move.4 For high-value payments, responsive SMS confirmation requires the member to authorise the transaction before it proceeds. For international transfers to new payees, targeted new payee rules apply a further checkpoint at the point of highest risk. Where Multi-Factor Authentication is applied, the member receives an in-app prompt or one-time password as a final confirmation step before the transaction is processed.

Detect: identifying threats as they occur

Within every session, BioCatch behavioural intelligence builds a continuous picture of the member through physical and cognitive signals. Physical indicators include swiping patterns, press size, device movement, and typing cadence. Cognitive indicators include aimless mouse movement, hesitation, data familiarity, and copy-and-paste behaviour. Together these signals form a behavioural profile that identifies anomalies consistent with social engineering, remote access, or unauthorised account use.

That profile is passed directly to Fraud Interceptor, which applies it in real time across every transaction. Fraud Interceptor assesses incoming and outgoing payments against institution-defined rules, incorporating BioCatch risk scores alongside device, network, and transaction data to build a unified picture of each session. Where anomalies are identified, the system escalates for review or automated action.

Respond: acting before harm is done

When a threat is identified, sessions can be challenged or blocked, high-risk channels restricted, and future logons controlled. All actions are logged with a full audit trail, including the BioCatch data that informed each decision, supporting operational response and regulatory reporting obligations.  

The evidence that layers work

Confirmation of Payee, now live across more than 100 Australian financial institutions, was used over 150 million times in its first year.4 One participating institution reported more than 570,000 payments abandoned after a no-match result, including over 10,000 attempted payments to accounts flagged on the Australian Financial Crimes Exchange.

Building beyond compliance

Australia's scam prevention landscape is evolving, and the frameworks now in place reflect a sector-wide commitment to raising standards. For financial institutions, the question is no longer whether to act, but how comprehensively.

Scams do not happen at a single point in the member journey, and neither should the controls designed to stop them. Each layer in a well-designed stack compensates for the limitations of the one before it. The result, when it works as it should, is protection that members never notice when everything is right, and cannot miss when something is not.

For customer-owned institutions, that question carries particular weight. The trust members place in their institution is built over generations, and meeting regulatory expectations is the floor, not the ceiling. The institutions that serve their members best treat scam prevention as an ongoing practice, not a compliance exercise completed at a point in time.

Ultradata's capabilities are built with that standard in mind. To discuss what the right approach looks like for your institution, contact the Ultradata team. 

ged-headshot-01.png

Ged Smith
Chief Innovation & Design Officer

 

References

1 Banking Day. "The stolen identity problem lurking in the Scams Prevention Framework." Jennifer Harrison, 3 July 2026. www.bankingday.com.
2 Australian Financial Complaints Authority (AFCA) and Australian Transaction Reports and Analysis Centre (AUSTRAC). www.afca.org.au; www.austrac.gov.au.
3 Data Zoo. "Transforming Fraud Prevention: Shifting from Legacy Methods to Layered Solutions." July 2025. www.datazoo.com — and Banking Day, 3 July 2026 (ibid).
4 Banking Day. "Confirmation of Payee enters second year with 150 million clicks on the dashboard." Ian Rogers, 8 July 2026. www.bankingday.com.