
Risk and Reason · 2026-03-26 · 37 min
Key moments - from our scoring
Substance score
59 / 100
Five dimensions, 20 points each
Zach Trotsky, BizOps Hire at Comun (formerly at Mercury and Capital One), explains why complete fraud elimination is unrealistic and fundamentally incompatible with revenue generation. Drawing from his experience at Capital One's fraud prevention team, he outlines the cat-and-mouse dynamic between fraudsters operating as full-time organized operations with access to dark web data breaches, and companies trying to defend against evolving attack vectors. Major financial institutions like Capital One provision hundreds of millions annually for fraud losses on their balance sheets - a cost they accept as part of scaling. Trotsky advocates for balancing proactive defense (machine learning models, behavioral analytics, geolocation data) with reactive monitoring, since fraudsters continuously adapt their methods. He highlights AI applications beyond just prevention: automating manual document review by fraud agents, improving data labeling for model training, and leveraging behavioral intelligence to detect suspicious user activity patterns. The episode explores the tension between growth teams pushing to minimize friction and fraud teams adding security checks, arguing this healthy debate drives better outcomes than aiming for the impossible goal of zero fraud.
No. Zero fraud losses is not realistic and would require zero revenue. Major companies like Capital One provision hundreds of millions of dollars annually for fraud losses on their balance sheets, treating it as an unavoidable cost of scaling.
Fraudsters use ML-powered automation to rapidly guess credit card number, expiration date, and security code permutations - sometimes thousands per second - testing them against merchant systems to find valid combinations.
AI can automate manual review of documents and customer activity that fraud agents currently do manually, improve data labeling for machine learning model training, and analyze behavioral patterns and user interactions to flag suspicious activity proactively.
There's an ongoing healthy debate between the two teams with different incentives but the same ultimate goal - the key is maintaining regular communication rather than letting one side dominate, since neither pure growth nor pure security is viable.
Yes. Fraudsters have active access to dark web markets where data breaches from major companies are continuously flowing and being bought and sold, giving organized fraud groups comprehensive victim information to exploit.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a solid grounding in fraud operations and AI applications with concrete examples (geolocation data, card-guessing bots, deepfakes), but substantial portions are taken up by biographical context and conversational meandering that don't advance the core ideas. The insights about BPO switching costs, manual review copilots, and regulatory friction are valuable but not densely packed - there's notable filler between them.
fraud is a data problem
fraudsters are consistently evolving their approach
Most frameworks here are industry standard (fraud as cat-and-mouse, proactive vs. reactive defense, AI as manual review augmentation). The BPO criticism and copilot approach are sensible but not contrarian. The observation that synth AI identities represent a near-future threat is somewhat novel but underdeveloped. The episode largely recycles existing fraud-fighting playbooks without strong first-principles pushback.
zero fraud losses means zero revenue
maybe that's beyond 2026, like a little bit further, but I think we'll start to see that soon
Zach has solid practitioner credibility - Capital One internship, Mercury role, current Comun BizOps position - with hands-on experience across large and early-stage fintech. However, he's relatively early-career (internship starting in 2018 means ~6 years experience max) and is a BizOps/fraud ops hire rather than a founder or P&L owner who built fraud systems from zero. The guest has real scars but isn't yet operating at the scale or seniority of someone who'd be considered a top-tier authority.
I was a VP in fraud, first party fraud specifically
at a previous job at Mercury, when you're at a company that all of a sudden grows from maybe like 150, 200 people to like much bigger
The episode includes some concrete specifics: card-guessing bot attacks, geolocation datasets from Capital One, BPO cost structures, and Capital One's balance-sheet provisioning (hundreds of billions). However, many claims lack hard numbers - no specific fraud rates, no ROI on AI implementations, no concrete timelines for new systems. The Capital One anecdotes are real but sanitized; the fraud examples are illustrative rather than detailed.
literally just guessing credit card numbers in rapid, like sequential order
Capital One, for example, on the balance sheet are provisioning like hundreds of billion dollars away
The host asks decent setup questions but rarely pushes back on vague claims or forces specificity. When Zach hedges ("I don't even know if we have a good answer yet" on LLM hallucinations), the host lets it slide. No sharp follow-ups on the BPO confidence rating comparison (3-4 vs. 7-8) or on how partner banks actually validate AI. The interview feels friendly but lacks the friction needed to extract deeper insights or surface disagreements.
This is the hard part, obviously. I think one of the really difficult things. And like to be honest, like I don't even know if we have a good answer yet
How do you think about building in protections there
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Risk and Reason, Eli Wachs sits down with Zach Trunsky, Founding Business Operations at Comun, to explore how early-stage fintechs build fraud and risk programs from the ground up. Drawing on his experience at Capital One, Mercury, and now Comun, Zach shares why zero fraud losses is an unrealistic goal, how fraudsters operate as sophisticated full-time professionals, and why the era of massive BPO review teams may be coming to an end. Chapters (0:00) Can You Actually Eliminate All Fraud? (1:25) From Capital One Intern to Founding Risk Hire (5:42) The Cat-and-Mouse Game With Fraudsters (11:15) Why Zero Fraud Means Zero Revenue (18:25) AI as a Weapon on Both Sides (24:06) Why BPOs Are Holding Fintechs Back (27:38) Rating BPOs vs. AI Copilots (33:11) Advice for New Risk Leaders and 2026 Predictions Follow Zach Trunksy LinkedIn: Follow Eli Wachs LinkedIn: Check out Footprint Footprint is an AI-native platform powering identity verification, fraud prevention, and AI fincrimes agents for banks and fintechs.
Transcribed and scored by The B2B Podcast Index.
These things actually can't fully stop. The reality is like you're never gonna fully stop that. Like zero product losses is like not realistic. These like very large companies like Capitoline, for example, on the balance sheet are provisioning like hundreds of billion dollars away.
They know it's gonna happen. It's just exciting to think about like a time where we can be a little bit more than putting with these. Don't think that because a major attack isn't happening to you. I don't want to like it probably will eventually, if the major attention deck, everybody, welcome back to the risk and reason podcast.
Uh I'm Eli, your host from Footprint. This episode is brought to you by our friends at Loan Pro. And we have an awesome guest today, Zach Trotsky, founding BizOps Hire at Kamun by way of Mercury, by way of Capital One. Uh you've worked at some of the most fascinating companies in Risk, some of the largest and now some of the fastest growing.
Thanks for joining us on the show. Yeah, of course. Thank you for having me on and excited to have a good discussion. Zach, we were talking about before, uh, how does one end up in this world?
Uh this doesn't seem like, you know, childhood, you're looking at NASA, uh, you're looking at NBA players. Uh how did were you looking that you've posters of compliance professionals? You know, what what drew you in? Yeah, like the Michael Jordan of compliance.
The Michael Jordan of compliance, exactly. No, it's uh I feel like a lot of people might say this, but I think for me it was probably a little bit of an accident the way I fell into this career path. Um actually it went back to when I first interned in Capital One after my junior year of college. Um, it was a rotational corporate strategy program.
And they kind of for the internship place you embed you within a specific team. Um, I obviously, you know, only started to know about fintech. I was not really knowledgeable about the space, definitely not knowledgeable about um risk compliance and fraud. And my interviewer when I was interviewing for the internship at Capital One, someone running my case interview, actually, was a VP in fraud, first party fraud specifically.
And I remember her telling me about some of her stories, like stopping fraud at scale for this like obviously very large Fortune 100 company, and how kind of they were on the forefront of machine learning, artificial intelligence. And this is back in 2018. And I obviously didn't have a background in this. I didn't, you know, know a lot about it.
And it sounded fascinating. I'm like, this sounds like kind of like working for the FBI. Yeah. And and like I was just kind of enamored by the opportunity.
So after that, I'm like, okay, I love this. Like, and then when I got the offer, I was like, okay, my interviewer worked in fraud. This fraud sounds super cool, you know, busting the bad guys. And I like requested to be a part of that team, and and sure enough, they placed me on that team.
And that's kind of where I got my first exposure to it. Um, and obviously it was really cool. You were working on the forefront of data and on the forefront of machine learning and and all these advanced kind of quantitative techniques, and I loved it. And then um fast forward, you know, obviously working for Mercury and then my current job.
Um, it's, you know, I've gotten the opportunity to kind of play a more active role in building those programs from the ground up. But yeah, I think just it kind of happened by accident, but I just really fell in love with just kind of the prospective, you know, the the advanced nature of fighting fraud and just kind of how kind of sometimes fun it is to just like the bad guys, you know. What did Day One look like at Cap One? Uh iconic, very innovative company.
Uh QD Letter of Series A, they're the founders of Capital One. We've very much heard the the origin stories. Yeah. Do they give you did were you given a a textbook of this is how you should go and learn about first party fraud with sister osmosis?
How did you think about that? And how do you think someone should think about that? Yeah, yeah. I mean, basically the team, there are so many resources.
Like you think about it, Capital One has like many, many, many millions of customers, like moving billions of dollars um every single day. The sheer amount of data they have is unlike anything I've ever seen. And like I think fraud largely is a data problem. And, you know, so the team had just like developed such in expertise on the various MOs, the data, the, you know, various techniques.
There are all these like PowerPoint decks. And I think like one of the things that they're really good at is transferring knowledge to people like within teams, like within the company. I think part of why Capital One is so good is like they have it's very talent-dense, but also like they're very good at passing information between the company and to people who are growing within the company. So just literally by finding mentors like on my team who are a little bit senior and um who had developed all these resources, and also quite frankly, by just like playing in with the data, I was able to kind of start to learn about the MO, start to learn about what the data looks like.
My first project as an intern actually was to work with this novel geolocation data set that they just had. They had just purchased it from some vendor, and it was literally a data set that had, you know, the time zone of a of a user, you know, the operating system time zone, like all this like geolocation-based data. And like my job was essentially to just like play with it and understand it and try to come to a reasonable conclusion by the end of the project on how this can add business value.
And that was just kind of, you know, dipping my toes in that world of data and exploration hypothesis testing was kind of really how I learned about it. Like you can learn about it by talking with people, you can learn about it by by reading resources, but I think just like getting in it and understanding it and eventually like seeing fraud happen and starting to pattern match, like using the data, I think was kind of, you know, my how I learned about the space in the most effective way.
So it's very interesting. You bring up this FBI analogy, Joe, like of you you're a detective in a way. What does it actually look like? So you you bring up this scenario, you buy a geolocation data set.
I I know this is first proud of the internet, so you maybe weren't given the budget to buy that data set to give them to. How do you think about this kind of mouse game where it's do you think that about buying tools proactively? Do you do you think we just got hit by this fraud at all was from the state of Georgia? We need to be better at geofencing.
How do you think about putting those pieces together? Also knowing that once you've caught someone, they're probably gonna come back a different way. Yeah, it's it's really difficult, obviously. And I think like it's still the companies still aren't very good at it.
And I think this is actually more relevant to some of my experience at smaller companies. Um, you know, when you don't have the level of sophistication, the level of scale that uh, you know, obviously a company like Capital One does. Um I think like there, when you're kind of on the ground level, I think you start to actually look at individual cases, you know, see people starting to commit fraud. And that really is where you start to like, you know, understand the user behavior.
And I think when you don't have these sophisticated techniques yet and you know are relying on kind of a patchwork of vendors and other like defenses, like static rules, you almost the way you learn is almost by getting hit the first time, you know, and just kind of mitigating, make sure the blast radius of that initial fraud attack is mitigated. Learn from that and respond to that. Obviously, you know, that's very reactive, but the reality is fraudsters are consistently evolving their approach, like you said.
Um, they are consistently trying new strategies, like using new technologies. And it's a balance. You have to balance, you know, trying your best to anticipate and put yourself in the psychology of the fraudster. Like I think that was one of the parts that I underestimated was just like how psychologically driven, you know, fraud is.
You have to under put yourself in their shoes, understand like where might they attack, how might they find vulnerabilities, what type of resources do they have at their disposal. And you can start to like, you know, procure different defenses, you know, build a team that can, you know, proactively prevent against that type of attack. But the reality is that will have to be balanced by just proactive monitoring, you know, or reactive monitoring, like making sure that you are watching the right things, making sure that literally, you know, if you're launching a new product and you might suspect you have some vulnerabilities, literally watching, you know, transactions come in by one case, cases come in one by one and review those and try to be as reactive as possible.
So I think like it's you don't want to be fully reactive, but it's almost like impossible to be 100% fully proactive because fraudsters change all the times. They understand your vulnerabilities, they shift their approach. You have to kind of balance the two. And it's an ongoing balance between the two.
And it's very difficult. When you get into psychology of a fraudster, are you joining Telegram chats? Are you, you know, watching, you know, you're reading news articles on who you won in Cambodia. How how do you think about that?
Because I think this is such a misunderstood point, maybe of we spend so much time talking about defenses that we don't spend enough time talking about, like it or not, these are real people and this is a full-time job. Yeah, yeah. And we probably all disagree with the ethics of the full-time job, but yeah, they're they're also multinational companies at this point with thousands of employees. We're probably we're very far gone from the days of someone in their mom's basement.
But how do you think about getting in at psychology and trying to almost predict what they would want to do next? Yeah, you you make a good point. Like at the first, like a lot of people who aren't familiar with the space won't believe that, you know, there are people who are literally here, their job is to have many different devices, you know, many different like access to the dark web, access to all the data breaches. That if you're not familiar with the space, you don't know that there's this like insane flow of information on the dark web from various data breaches from some of the largest company in the world.
And it's flowing around. Like there's an active market of people buying this information, using it to commit fraud. And it's it's very real. Um, and that I think is is obviously important for people to recognize.
And yeah, I think just the the key is to like work with people if you who have access to this type of information, like at various jobs I've I've had in the past. Like we've worked with advisors, you know, who are very deep in the space and they'll be like, oh yeah, we heard about chatter about your company on the dark web. And like the reality is, is like when you recognize that this is a full-time job for for some people, you also have to recognize that they are constant, they're very opportunistic.
They're going to look for every opportunity to, you know, attack you if you're if you're a fintech company, if you have vulnerabilities and you have to be extremely careful. Like obviously, you know, if you're about to launch a new product or if you're about to like start something new, you have to realize that someone whose full-time job it is to commit financial fraud will be, you know, on the prowl for these types of opportunities. And just I think understanding that is incredibly important for, you know, making sure that you have the right level of safety for whatever product you're launching.
Cause I think it's one thing to know that that's happening. And then it's another thing to, you know, see that hop in and have that start, you know, cannibalizing your PL. So um it's very you have to it, you have to think about what they are watching out for from a psychological perspective and then like, you know, make sure that your defenses are to the point that can actually stop them. Froster's full-time job to make your life unfortunate.
Um, from trying to take money. Uh, growth team's full-time job is to also probably bug you by saying, Are you adding all of these defenses? Which puts someone in your shoes in a pretty unique and difficult position that there are two people whose goals are somewhat at ends. Yeah.
This leads to, I guess, a two more question. One, do you think it's actually possible to get rid of all fraud? And two, what do you think how do you think about the balance of checks that you're adding versus friction? This is this is the age-old question.
I feel like I I've I've been j I was joking with my girlfriend the other day. She's like, I feel like this answering this question, the balance between fraud and growth has been your full-time job at three different companies now. So it's very like it's very, it's very personal. But I think, yeah, the reality is there's it's a healthy debate.
It's a very healthy dynamic to think, have, think about how can you grow versus, you know, how can you defend yourself from fraud and from, you know, penal cannibalization. Um, and I think there's not really a right answer, more so than just making sure that it's a healthy ongoing debate between those two teams with like two different, you know, underlying incentives, but ultimately like the same goal to put the company in the best success position to succeed. And I don't know.
I think it's very like it's very interesting. And the reality is that we try to remind ourselves every day is you wanna put yourself in the best position to fight against fraud, especially you want to put yourself in the best position to see it, like know that it's happening, like have the right data, have the right visibility. But I think the reality is like you're never gonna fully stop fraud. Like zero fraud losses is like not realistic.
And I think to be honest, like zero fraud losses means zero revenue. Like you're you're not gonna be able to grow. Um, there's a reason that these like very large companies, like Capital One, for example, on their balance sheet are provided provisioning like hundreds of billion dollars away, like each earnings call for like, you know, fraud losses, credit losses, et cetera. Credit's a little adjacent, but they know it's gonna happen.
They know that there are going to be losses incurred. It's just a part of growing. And it's less about like making sure you have zero fraud, but more so making sure fraud is like within budget and that you have the data and you can learn from it and consistently adapt to make it like less and less of a problem. So, like the reality is you're never gonna get rid of it.
Like the goal is to grow, obviously. Um it's an ongoing crazy statement of capital on this is public, you know, hundreds of millions of dollars on their annual earnings calls are set aside for fraud. Do you think that should be a paradigm? You know, like that it when you hear something like that, does that make you think these systems are fundamentally flawed?
The the other things I could think about is legal expenses where public companies will just set aside an amount, we're gonna get sued, and this is what we have to spend on it. Like, does that not almost make you drive your head into a wall, which is you know, what we've just accepted that this this has to be the case? Yeah. I mean it it does.
Like when you think about it, it's why are you kind of settling for defeat, I guess. I mean, when you're when you're Capital One and you're also, you know, making it won a lot. They say yeah, yeah. They won a lot.
And they also have like other processes in place that they're amazing at, you know, like recovering fraud, you know, and obviously they're an extremely profitable, extremely successful company. So they can they can get away with it. But I think the reality is is that, you know, I think that the current state of fraud, the current way fraud is committed is very much a reminder of kind of the, I don't want to say legacy, but just, you know, financial infrastructure, payment stack, the way that all these products have been built have been, you know, underlying like relatively similar for the past maybe like 30, 40 years, and we're starting to see more evolution in the fintech space around the underlying infrastructure, you know, around like crypto, around tokenization.
And part of me wonders if like this concept of like, oh, fraud is gonna happen and we just have to like make the right budget for it and let it happen and learn from it, if that's like reminiscent of kind of, you know, the old guard of fintech infrastructure. Um, but it's a really compelling question. And I think, you know, like as there's both sides of the coin could potentially be true. Like you have to, you you know, you have to learn from fraud and it's gonna happen.
But at the same time, like you shouldn't settle for it because when you do see it, like I I know when I see this happening at certain jobs, I'm like, you know, this can this could have been prevented. If we had the right systems in place, we could have identified this pocket of users, you know, allowed the good users to grow. And like, there's no reason we should just like settle for this coming in. So it's interesting.
But I I think that again, there it I'm not so sure there's the right answer just yet. What's the most unique thing you've seen a fraudster or a group do to try to compromise the system? Yeah. I mean, this this was at a at a previous job, but um I've seen a lot.
Like you'd you'd like, I mean, you wouldn't be surprised. Other people would be surprised that but how sophisticated these people can get. But like literally, we had something happen in a previous job a while ago where someone just had some sort of, you know, machine learning, rapid automation system where they just spammed bin numbers, like bank identification numbers, like into cards, and literally was just guessing credit card numbers in rapid, like sequential order to try to like guess what what card like expiration date combo was correct.
Obviously, you know, when you think about the different permutations of a credit card number, an expiration date, like a security code, there's infinite number of permutations. Like we had a fraudster once who was literally just like had an automated system that was just guessing these, like like many thousands per second in random sequential, just trying to get authorizations to get transactions to go to through a frauddy merchant. So I think just that story was So they're successful?
Partially for the most part, not like a lot of them were declined, a lot of them didn't work, but like they they still were able to, like, you know, um it probably goes to the PL of that fraudster where they're willing to spend a certain amount on on compute to get a certain amount of transactions. Yeah, exactly. And like they definitely weren't just doing this to us, you know, they were doing this probably to like a lot of other comp like companies. And I think it just goes that was my first reminder of like, you know, even fraudsters targeting smaller fintechs have these crazy capabilities, are very sophisticated, are leveraging like machine learning.
And um, I think that, you know, was just a reminder for me of like how creative they can get and like how, you know, when it's a full fraudsters full-time job and they want to be, you know, state of the art, then they have a lot of capabilities. Machine learning there makes a lot of sense. Uh using it to guess these permutations. Very hot topic these days, artificial intelligence.
Yeah. Another tool that's very good for fraudsters, and that now for the first time ever, you can fairly cheaply and quickly generate hundreds or thousands of compelling fake documents, whether they're driver's licenses, bank statements, utility bills, or nurture synthetic identities. What are you seeing on the other side of ways that you can leverage artificial intelligence in your seat to try to defeat fraud? Yeah, there's there's a lot of different ways.
I think like they I will say, first of all, like a lot of it, some right now is, you know, it's very, I don't want to say hit or miss, but I think like there's a lot of like really interesting conceptual ways in which like we can prevent fraud. There's like a few that we're seeing that like prev that show some immediate viability. I think one of them is actually, you know, as as we were talking about before the episode, you know, fraud traditionally has involved like some, you know, element of manual review, um, having like, you know, agents, fraud agents specifically, you know, actually going through and reviewing customers, reviewing documents, like looking into our systems, like to try to like look, oh, is this customer, is this activity they've done on our platform, is it fraud?
Is it not fraud? Um, you know, they submitted this document for us as as proof that they're not doing fraud. Is this document legit? Um, and uh companies all over the world are still using like manual agents to to go and you know, review back office documents and and conduct investigations and and leave an audit trail on on you know various customer activity.
And, you know, we think that AI can, you know, do a lot of these reviews, you know, for us, like help us, you know, create a feedback loop between what our systems are seeing and what defenses we're building, make that feed book feedback loop a lot more efficient, a lot cheaper, obviously a lot faster. And so that's one immediate area where we are kind of using it and we, you know, see this as being like incredibly valuable. Um, there's a lot of other really interesting potential use cases here too.
I think going back to first party fraud, um, obviously I learned about it a lot from my time at Capital One working on the specific team. And it was kind of crazy that they hold had a whole business team specifically dedicated to that one type of fraud. Um, but like behavioral intelligence, like behavioral analytics, like literally think and looking at the you know, cookies and the way that you click on the application and on like the web portal, and and use so there's a lot of artificial intelligence capabilities around understanding just user behavior and you know, peract putting in proactive defenses against that.
So those are two ways in which we're seeing it, but I think there's a ton. Like obviously, as I mentioned before, fraud is a is a big data problem. I think another thing that comes to mind is data labeling. You need to like be able to actually label the fraud after it's happened in your systems to learn from it and take that data and have it feed machine learning models to, you know, get more proactive and get more sophisticated.
So I think like, you know, using artificial intelligence to like help label data and like help, you know, make sure that our feedback loops like going into our machine learning models are accurate. So I think there's a ton of interesting potential in here. And we're really just at the frontier. I think like, you know, it's it's just a lot of the capabilities here are very nascent and very promising.
And there's so much, I think, to be discovered in the space, and it's very exciting. We're very bullish on on this first bug you mentioned about manual review. At the same time, the biggest question we hear is hallucinations. Yeah.
Uh these are big decisions. And if you make it to the wrong person, it could be a pretty catastrophic impact. Yeah. How do you think about building in protections there to or just more broadly, how do you think about getting to a level of confidence whether you, any partner banks you work with, do given that even if you ask the LLMs what part they're wrong about, they will know.
Yeah, yeah. This is This is the hard part, obviously. I think one of the really difficult things. And like to be honest, like I don't even know if we have a good answer yet, but like we don't yet either.
Yeah, yeah, yeah, yeah, yeah. But like one of the things is just, you know, obviously how regulated fintech is. Like everything must be documented. Every decision you make must be, you know, auditable, traceable.
And that, you know, obviously is a little bit difficult sometimes, especially in the nascent era of artificial intelligence. And I think the thing that I found, um, I've in in two different jobs now I've worked, you know, on problems where, you know, we needed to do something for a partner bank, or there was like an audit from like a regulator or a partner bank or whatever, and we needed to like provide some documentation. And obviously, you know, like I think partner banks, United States regulators, they don't have necessarily always the reputation of being so like technologically advanced.
I think like the concept of artificial intelligence is sometimes like a little bit scary. And so I think like, you know, we the there's always been like a really delicate balance between like, you know, thinking about trying to be forward thinking and trying to be, you know, as efficient and as accurate and you know, as, you know, technologically advanced using artificial intelligence as much as possible. But at the same time, like, you know, we can't do anything that necessarily puts us at risk with like regulators, partner banks, et cetera.
And I think I think we're really trying to find that balance. I recently was speaking, meeting with regulators about this. And yeah, one thing that came up is the idea of we can definitely put AI in a spotlight to say, well, what what about this issue? On the flip side, as I'm sure you can speak about from different companies.
Yeah. The flip side is I'm guessing Cap One, Mercury, hundreds, thousands of different humans who do interview. You don't have consistency there either, right? Yeah.
How could you maybe log through like what does the paradigm look like today? And maybe why though you do see, you know, we can talk for many hours about what could go wrong, but what's going wrong today that actually could go right if we use these tools correctly? Yeah, I I think just like the consistency is one of them. And obviously, you know, that but I think just the the other thing is just, you know, the sheer kind of like from thinking from a business perspective, like the sheer cost and like the sheer like lack of mobility you have sometimes when there's so like there's so many manual reviews, like I think that is like you know, a little bit like it holds you back a little bit as a basic.
Because manual reviews translating to the bottom line in that you're not onboarding as many people or businesses. Yeah. Or or like if you're in the case where you like a lot of you know, partner banks, a lot of regulators, they see the manual review as like a vote of confidence. Like you have a sign of confidence in this customer, we want to see like all these customers manual reviewed because we trust the eye of the human.
However, like I think, you know, manual reviews are not always perfect. Like, so I don't know if that's true, number one. But number two, like if you're doing if you're in a place where, you know, you have to, you know, you could prove some, you use your manual reviews to like prove something to the regulator, prove something to the partner bank, like that holds you back. It's not very fast.
You have to like complete those before you can go, you know, launch new products, launch new business units, gain the trust of regulators, you know, like grow as a business, like do the things that you want to do. But like when you have to like, you know, use like these BPOs, like business process outsourcing companies to go and review your customers, review your products, it feels like you're living like 20 years in the past and odyssey it's expensive and it's slow. And I think there's there's probably a future where like you don't have to use those companies at all.
Do you think about kind of a copilot approach where you can have AI maybe have a 14-step review process? AI is doing 12 and you get to look at what it puts out and do the final tune. Is there a world where then you can actually give to banks this notion of everybody who's manually reviewed? Yeah, yeah, yeah.
I think I think it's sad too. And I think like that the copilot, you know, is very promising and it's very, and then obviously like the copilot is efficiency gain. And like um, we've been thinking about using some some manual review copilots as well, um, just to like, you know, augment the review, like help with accuracy, help with efficiency, drive down cost, et cetera. And I think like the way this goes is like I don't want to say that this will go to a completely autonomous human out-of-the-loop system.
I think the heat feedback loop is very important, but I think like what I've seen at like fintech companies so far is uses utilizing these like generalized outsourcing companies. And and these are huge companies. This was a world I had no idea about before I entered, you know, fintech. And then I realized, you know, there's all these massive companies with like armies of of people offshore, and their their whole job is to just like plow through documents, plow through reviews, plow through a checklist.
I think like what this enables is you can move from that generalized model to a more, you know, focused subject matter expertise specific model of have like, oh, instead of having an army of 50 people who are all generalists, you can have, you know, four or five people who are specialists, who are trained in financial crimes, who are trained in like finance, like fluent in regulation, understand what to do, add like real business value in addition to just completing the investigation and equip them with like, you know, a co-pilot to be able to like be much faster and be much more effective.
And I think so. We'll probably, when it comes to manual reviews, move towards that model, and that'll probably help the business, you know, reduce costs and just make the general system a lot more effective. A scale of one to ten, how confident would you be in an arbitrary decision made by the BPO army versus scale of one to ten uh an AI co-pilot? Wow.
It's a very close that's a that's a very good question. Um might get in trouble for saying this, but I but I but I think I don't know, the B the BPO I think would I it's probably a three or four, and I think AI co-pilot, I would I would generally trust. I wouldn't fully trust, but I'd probably put that around like a seven or eight. And the cost of the BPO is real.
Yeah. And it's probably not the most enjoyable work. Yeah, no, definitely not. It's not the most enjoyable work.
And like you obviously, you know, if you, you know, you have to, and I think from the business side, you have to, and you think about it, it's expensive. And then there's also overhead in addition to, you know, just paying for the agents, paying for the BPO, you have to like, you have to hire a team to manage the BPO, you have to like train the BPO every time you do something new. There's switching costs from having them switch from one thing to another thing. Um, and then you have to like, if you want to launch a new product, you have to like retrain them on the new product.
Um, so I think just from like a cost optimization perspective, and then just, you know, a broader question of like, you know, efficiency more generally, like it's not so ideal. Because like obviously, you know, like even at when in at my past job at Mercury, when you're at a company that all of a sudden grows from maybe like 150, 200 people to like much bigger, the BPO kind of scales with it. Yeah. And then all of a sudden you have this like huge army of agents.
Like can you talk about the switching costs there? Yeah, yeah. It's it's fairly sticky. And it gets like stickier the bigger that it gets.
Um I guess you've trained them on your processes. Yeah, you you've trained them on your processes, you've trained them to think of do things a certain way, think a certain way. And the reality of working in early stage or mid-stage tech and fintech is things move very fast. The the market moves very fast.
You know, you have to consistently launch new products, um, especially like when the bigger you get, you launch more products, you start to kind of like create a bundle around your core target customer. People forget that you you have to, if you're a fintech company, you have to also train your agents like in all these products because they all come. The reality is like every new fintech product that's launched, or a lot of new fintech product that's launched, comes with its own set of like back office processes that have to be done.
That so, like if you're launching a new product, for example, and it has like a different level of KYC, like you still have to do KYC. It's a regulatory obligation. And you are likely going to have like some element of manual review required for that, you know, a new onboarding that you have. And new agents have to be trained in a different way.
They have to undo their mental model that they were thinking, get trained in something new. Yep. And, you know, that takes time. It slows down your ability to roll out the product, you know, it might lead to inaccuracies, it might lead to a poor customer experience.
And obviously, if you grow, sometimes like the easy answer if you're growing, instead of like figuring out, oh, how can we, you know, use AI to like not grow back office operational headcount, like that takes time, that takes scoping, that takes resources. Sometimes the easiest answer is like, oh, let's just hire more agents, we'll deal with it, and then we'll cut back down later. Well, like the cut back down like doesn't always happen. So I think like in theory, like it's nice to think about a world where you don't have these switching costs, you don't have this like major item on your PL and see it grow over time.
And like it's just exciting to think about like a time where like we can be a little bit more autonomous, autonomous, and quicker moving um with using artificial intelligence. We try to be balanced, the risk and reason podcasts. How do you weigh the following two concerns? For BPOs, no secret, they're pretty international overseas.
So from a privacy perspective, you're sending data outside the US and then you're bringing it back to a bank. Flip side, for models, you're sending sensitive information to large language models who aren't supposed to train on it, uh, but the auditability there is a bit loose. Yeah, you think about both of those from a privacy security perspective. Yeah, it's tough.
I think I'm not like a huge expert in privacy and security pertaining to data. But like what I do know is that the BD, the BPO model is like it's very proven. Like they have their, these are very, very large companies and like they have ways to deal with data security. Um I think like, as from my understanding, like the data security element of of LLMs as it comes to audibility, you know, it's an on, it's an ongoing thing.
It's an ongoing discovery, like how to make that most effective. And I think the thing that we just consistently put in front of mind in all our jobs, it's just like, you know, making sure we have very clear decision making, very clear audit trails. And like I think the reality is, is like right now for us, if we're trying to use like artificial intelligence to do something to like, you know, automate some process, to, you know, make some area of our business a little bit more efficient, it's we're not at a place where like we can have an LLM be fully autonomous.
Like someone needs to kind of, you know, it operates within this kind of broader box of like some person managing this process and an LM and the LLM is just one part of that because of partially because of the auditability piece. So I think like I'm sure that problem will be figured out. I'm sure that problem will be solved. Yeah, but it it's hard for me to say that that's at a point where you know it can be fully solved right now, if that makes sense.
As we get to the end here, what would your advice be to someone taking your seat at a different role? And by that I mean if I'm the founding uh BizOps kind of fraud person at a fast growing startup, yeah, what would you do on day one? And if I'm joining a large public FI to establish risk systems, but still a couple hundred million on the balance sheet data fraud, yeah. What would I do?
Yeah, it's a great question. For the for the first part, just talk to people. Like it could be a lonely job if you try to, if you try to solve it alone, if you try to like fight fraud alone, you're probably gonna fail. Um like definitely like leverage your network.
Fraud stores often, you know, coordinate across multiple companies. Everyone, like obviously, you know, there's there's competition, businesses are competing against each other, but at the same time, like I think businesses can probably, you know, unite around the shared common goal of, you know, wanting to fight fraud, make sure that that is not, you know, cannibalizing anyone's ability to operate. So I think definitely talk to people, share knowledge, um, understand latest trends in the industry, understand what other people are seeing when it comes to fraudsters.
Because if a fraudster has hit another company, but it hasn't hit you yet, it's probably gonna come soon. So I think just if you're standing something up, that that's my advice. And also just don't think that because it hasn't a major attack hasn't happened to you that it won't. Like it probably will eventually.
It's a nature of being in fintech. Every in my career, I think m almost all like exciting product launches have come with, you know, fraud, particularly like credit products, pray myth products. It all it all happens, so it will come. And yeah, if you're joining a bigger company, I think obviously, you know, you're afforded kind of the you know, safety net of having, you know, a company that's doing really well, probably, you know, making makes a lot of money, kind of, you know, every, you know, incremental, you know, $10,000, $20,000 in fraud loss is an existential.
But take advantage of that, you know, cushion to really understand how to build a state of the art system. Like where can you invest your money into like building like the best, most frontier forward-facing systems and understand what it looks like to be like really sophisticated at scale at scale. But again, the same principle applies. Like it will happen, like it will continue to scale.
So, like if you're working at a really large company, then just you know, take that opportunity that you have there to like think about how can I build something like really truly sophisticated and state of the art. Because then, like, if you want to like to take go from there and then become like the head of fraud, head of risk at a smaller company, you can take the principles there and like start to build your own system from the ground up. Final question any predictions for 2026 when it comes to fraud?
It's a good question. Um just as we're talking about AI, you know, using being helped being used to help fight fraud, we'll see AI, you know, potentially starting to commit fraud. We'll see, you know, you know, we've already seen like talked with some vendors about like, you know, the issue of you know, people using deepfakes to get access to the bank accounts, like gener AI generated people to try to get access to bank accounts. We haven't seen too much of that yet, but if I had to guess in some way or some form, like we'll probably have these fully AI created synthetic identities that are just, you know, completely autonomously signing up for bank accounts, you know, committing fraud, not tied to a person because it's all AI.
Yeah. Maybe that's beyond 2026, like a little bit further, but I think we'll start to see that soon. And I don't know how we're gonna stop that, but we'll find a way. There's work to do.
Fighting AI with AI. So it becomes a little meta, but very interesting. There's work to do. We appreciate your role in stopping it.
And thanks so much for coming on the podcast. For trying, yeah. Thank you for having me.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.