A new study from American Banker, produced with Plaid, surveyed 143 fraud decision-makers at banks, credit unions, and neobanks and found real-time payments have made fraud faster than most institutions' defenses. Eighty-five percent say real-time payments have increased fraud risk at their institution. Only 15% can consistently intervene before funds actually move. Eighty-eight percent report an increase in cross-rail fraud over the past two years, and 84% say fragmented data is a moderate or major reason fraud gets caught late, or missed entirely.
The finding that matters most sits underneath those numbers: institutions with unified data environments are the only ones reporting real-time fraud detection. Siloed institutions mostly find out after the fact. That's a genuinely strong case for network-level intelligence, and it's hard to argue with the logic behind it.
Fraud has stopped being a single-institution problem. Money moves across rails and providers faster than any one institution's own transaction history can explain, and a customer's legitimate financial life increasingly spans several financial service providers a single bank never sees into. Seeing a transaction in the context of everything else happening around it, not just what happened inside one institution's own systems, is a materially better way to catch fraud than pattern-matching against a single, incomplete data set.
The report backs this with real investment data: 45% of institutions are putting their biggest fraud-prevention dollars into advanced analytics and AI models over the next 12 to 24 months, 38% into cross-rail data integration, and a smaller but growing share, 19% and 7% respectively, into consortium data sharing and network-level intelligence specifically. Plaid's Head of Fraud, Pedro Sanzovo, put the operating principle plainly: relying on time lags for fraud prevention won't cut it anymore, as fraud detection has to become more interconnected and continuous to keep pace with real-time rails.
Plaid's Payments Product Lead, Shaffer Bond, frames the opportunity through a comparison to card networks: banks of all sizes now have access to the kind of network-level defense card networks have used for decades to protect their own transactions. It's a fair comparison, and it's worth extending one step further, because card networks never relied on transaction-level fraud scoring alone. They also built a standing layer underneath it: merchant and acquirer accreditation, PCI compliance requirements, and defined liability rules for what happens when a transaction turns out to be fraudulent. The transaction-level defense card networks are known for sits on top of an entity-level trust layer that decides who's allowed onto the network in the first place, and who's on the hook when something goes wrong.
Open finance needs both layers for the same reason card networks do. Real-time, cross-rail transaction intelligence answers one question well: does this specific transaction look right, given everything the network can see about it. It doesn't answer a different, prior question: is this participant, this third-party provider, this aggregator, this AI agent acting on a customer's behalf, actually trustworthy enough to be connected to the network at all, and who is liable if it turns out not to be.
The UK's approach to Transaction Risk Indicators is a good example of structured, transaction-level signal-sharing done well within open banking specifically, giving payment initiation services standardized risk signals to inform individual transaction decisions. It's a genuine complement to what this report is describing, not a substitute for the standing question of counterparty trust that sits above any single transaction.
That entity-level layer, the one deciding who's allowed onto the network in the first place, isn't specific to payments. A payment initiation provider needs exactly the same standing accreditation a data-sharing provider does: it can execute every transaction cleanly and still carry risk through who it subcontracts to, how its access controls are configured, or whether anyone has independently assessed it at all. Card networks didn't build merchant and acquirer accreditation because merchants only mattered for data. They built it because knowing who's on the network is a precondition for any of it working, payments included.
What's specific to payments is the layer that sits on top of that foundation. A payment happens in real time and carries risk a standing credential can't see in the moment, which is why payments also need transaction-level monitoring, the kind this report and the UK's Transaction Risk Indicators regime both describe well.
See how the Invela Network applies standardized accreditation and continuous risk monitoring at the participant level, the layer real-time transaction defense was never built to cover, so institutions know who they're connected to, not just whether a given transaction looks right.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.