Manish Agrawal on why the future of banking risk will be decided by speed, connected intelligence and human judgement
As banking becomes faster, more digital and increasingly invisible to the customer, the nature of risk is changing with it. The traditional architecture of control designed to detect an anomaly, investigate it and contain the damage is being challenged by an environment in which fraud can develop in minutes, move across institutions and increasingly exploit human behaviour rather than technological vulnerabilities.
For Manish Agrawal, Senior Executive Vice President – Head, Credit Intelligence & Control at HDFC Bank, this represents a fundamental shift: from controlling risk after it appears to building the intelligence to recognise it while it is still forming.
With more than two decades of experience spanning underwriting, product risk and fraud prevention, Agrawal has witnessed banking move from largely physical processes to real-time digital decision-making. In this CXO Thought Leader conversation, he discusses why fraudsters are increasingly “hacking the mind”, why the next breakthrough may come not from acquiring more data but from connecting existing signals, and why artificial intelligence will strengthen both sides of the fraud battle.
His central argument is deceptively simple: the resilient financial institution of the future will not be the one that predicts every threat. It will be the one capable of recognising, learning and responding faster than the threat can evolve.
You have spent more than two decades across underwriting, product risk and fraud prevention, witnessing banking move from largely physical processes to an increasingly real-time digital ecosystem. How has the very idea of credit intelligence and control changed during this period? What does a truly risk-intelligent financial institution need to do today that a well-controlled bank perhaps did not need to do ten years ago?
If I look at the evolution over the last two decades, the biggest change has been the speed and complexity at which risk now develops.
In a digital environment, the window available to detect and prevent misuse has become much shorter. If you keep it open for long, the cost can be humongous, since onboarding and decisioning are digital. That is where the shift from control to intelligence comes into play.
By every definition, traditional control is largely reactive – detecting issues and containing their impact – whereas intelligence aims to anticipate risk and intervene before it becomes a loss.
Today, it is not enough to know whether a customer met our criteria at the point of onboarding. We also need to understand how that customer’s behaviour and risk profile are evolving. Has there been a significant behavioural change? Are we seeing unusual transaction patterns? Are there new device, identity or beneficiary signals? And, importantly, what do these signals tell us when viewed together?
This is where AI and advanced analytics can add significant value. They allow us to process and connect large volumes of information much faster than traditional approaches.
But I would emphasise that technology should strengthen risk judgement, not substitute it. A truly risk-intelligent institution is one that can identify risk earlier, connect signals across the organisation and respond proportionately before that risk translates into a loss.
You have spoken in the past about fraudsters effectively “hacking the mind”, using emotions such as greed, threat and the need for help to manipulate customers. As banks strengthen their technological defences, is the human being increasingly becoming the most attractive vulnerability? How should the next generation of fraud prevention combine technology, behavioural intelligence and customer awareness?
One of the most significant changes in fraud is that the attacker increasingly does not need to defeat the bank’s technology. The attacker tries to persuade the customer to defeat the control on their behalf.
Social engineering exploits very basic human responses fear, urgency, trust, authority, greed or the instinct to help. The transaction may therefore appear technically authenticated, while the customer has actually been manipulated into initiating it.
That requires us to broaden our definition of security. Authentication tells us who is performing an action; behavioural intelligence increasingly needs to help us understand whether that action is consistent with the customer’s normal behaviour and circumstances.
Technology can identify deviations in transaction behaviour, devices, beneficiaries and interaction patterns. But technology must be complemented by contextual customer protection.
Customer awareness should no longer be viewed only as communication. It should increasingly become part of the bank’s preventive control framework timely warnings, contextual interventions and simple mechanisms that encourage customers to stop and verify before acting.
The next generation of fraud prevention will therefore combine secure technology, behavioural intelligence and customer awareness as three interconnected layers of defence.
Traditional fraud management has largely been about identifying suspicious activity and stopping or investigating it. AI, machine learning, behavioural analytics and network intelligence increasingly offer the possibility of identifying patterns much earlier. How close is banking to moving from fraud detection to fraud anticipation and where must human judgement remain indispensable?
We are already moving in that direction, although I would distinguish carefully between anticipating risk and claiming to predict fraud with certainty.
Traditional fraud management largely begins with an event: a suspicious transaction occurs, a rule is triggered and we decide whether to stop or investigate it.
The emerging model starts earlier. Instead of looking at one transaction in isolation, we can examine combinations of signals a new device, an unusual beneficiary, a sudden change in transaction behaviour, velocity patterns or links to accounts exhibiting mule characteristics.
Individually, these signals may not be conclusive. Collectively, they can indicate elevated risk before the eventual loss occurs.
This is where AI, machine learning and network analytics become particularly powerful. They allow institutions to identify patterns across millions of interactions that would be impossible to assess manually.
But human judgement remains indispensable. Models identify correlations; experienced professionals interpret context, understand emerging typologies, assess customer impact and make decisions where the consequences may be significant.
The future is therefore not AI versus human judgement. It is AI-augmented human judgement machines providing speed and scale, with people providing context, challenge and accountability.
Fraud intelligence can potentially sit across credit underwriting, transaction monitoring, AML, mule-account detection, cyber intelligence, customer behaviour and external intelligence. How important is it for banks to create a unified view of risk across these traditionally separate domains? Is the next breakthrough likely to come from acquiring more data or from becoming substantially better at connecting and acting upon the data institutions already possess?
I believe one of the largest opportunities is not necessarily acquiring more data; it is extracting greater intelligence from the data banks already have.
Fraudsters do not operate according to our organisational structures. They do not distinguish between credit risk, cyber risk, AML or payments fraud. They simply look for the weakest point in the ecosystem.
The challenge is that institutions can sometimes see different parts of the same risk in different systems. A cyber platform may identify a suspicious device. Transaction monitoring may identify unusual movement of funds. AML systems may identify an unusual network of beneficiaries. Another function may detect characteristics associated with mule accounts.
Viewed independently, each may represent a moderate concern. Viewed together, the risk can become much clearer.
The next step is therefore connected risk intelligence.
The institutions that can securely connect customer, account, device, transaction and network intelligence and translate those connections into timely action will have a significant advantage.
Customers increasingly expect instant onboarding, frictionless payments and near-instant credit decisions, while financial institutions are simultaneously expected to strengthen authentication, due diligence and fraud controls. How should banks resolve this apparent tension between customer convenience and risk protection? Can stronger intelligence make banking both safer and less intrusive?
Security and customer experience should not be treated as opposing objectives.
The real issue is indiscriminate friction. If every customer and every transaction is subjected to the same level of intervention, we inconvenience genuine customers without necessarily achieving proportionately better security.
The better model is adaptive, risk-based security.
When a customer’s device, behaviour and transaction are consistent with established patterns, the experience should remain seamless. When the risk profile changes, additional controls can be introduced dynamically stronger authentication, contextual warnings, cooling mechanisms or, where necessary, human intervention.
AI and real-time analytics can make that differentiation much more precise.
The principle should be simple: friction should follow risk, not every transaction.
If we achieve that, stronger security can actually improve the customer experience because genuine customers encounter fewer unnecessary interventions while suspicious activity receives greater scrutiny.
Digital fraud increasingly travels across banks, telecom networks, digital platforms, payment systems, mule accounts and jurisdictions. Does this mean that fraud can no longer be effectively addressed institution by institution? What would a genuinely collaborative financial fraud intelligence ecosystem involving banks, regulators, technology companies, law-enforcement agencies and customers need to look like?
Increasingly, fraud cannot be viewed purely as an individual institution’s problem.
A single fraud journey may begin on a digital platform, use a telecom channel to reach the victim, exploit social engineering, move money through several mule accounts across multiple institutions and potentially cross jurisdictions. No single participant has complete visibility of that chain.
That makes collective defence increasingly important.
Banks, payment networks, telecom providers, technology platforms, regulators and law-enforcement agencies each hold different pieces of intelligence. The opportunity is to develop mechanisms through which relevant risk indicators can be shared securely, responsibly and quickly, with appropriate safeguards for customer privacy and data protection.
Speed is particularly important. Intelligence shared several days later is useful for investigation. Intelligence shared quickly enough can become prevention.
The long-term objective should therefore be an ecosystem where suspicious patterns identified by one participant can strengthen the defences of others without compromising legitimate customer activity or privacy.
Fraud prevention ultimately becomes stronger when we move from institutional defence to collective defence.
Looking ahead three to five years, generative AI, deepfakes, synthetic identities and increasingly sophisticated social engineering could dramatically alter the threat landscape while the same technologies will strengthen institutional defences. In this continuing contest between attackers and defenders, what do you believe will differentiate the financial institutions that remain resilient? And what is the one capability banks should begin building today for risks that may not yet be fully visible?
The important reality is that AI will strengthen both attackers and defenders.
Generative AI can allow fraudsters to create convincing impersonations, highly personalised social-engineering approaches, synthetic identities and potentially deepfake-enabled fraud at a scale and quality that were previously difficult to achieve.
At the same time, AI provides financial institutions with powerful capabilities in behavioural analytics, identity verification, anomaly detection, network intelligence and real-time decisioning.
So, the differentiator will not simply be access to AI. Most major institutions will have access to increasingly sophisticated technology.
The differentiator will be how intelligently and responsibly that technology is integrated into the institution’s risk architecture the quality of its data, the connectivity of its signals, the strength of model governance, explainability, continuous monitoring and the ability of its people to challenge and act on what the technology identifies.
If I had to identify one capability to build today, it would be adaptive risk intelligence the ability to continuously learn from emerging signals and evolve controls as quickly as the threat landscape changes.
Because resilience in 2030 will not come from having predicted every possible threat.
It will come from having built an institution capable of recognising, learning and responding faster than the threat can evolve.
