TL;DR: Banks are expected to add behavioral intelligence and device-risk signals because APP fraud, voice phishing, and remote-access scams can pass MFA, device fingerprinting, and rules-based transaction monitoring while still appearing legitimate, according to OneSpan. Static fraud controls are no longer enough when real customers and compromised devices are part of the attack path.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Pourquoi l'intelligence comportementale et les renseignements sur les appareils clients sont désormais non négociables pour les banques”.
Key questions
Q: What breaks when banks rely only on MFA and transaction rules against APP fraud?
A: Those controls still validate the login and the payment, but they do not reveal whether the customer was manipulated into authorising it.
Q: Why do device-risk signals reduce fraud losses in digital banking?
A: They expose conditions that ordinary authentication cannot see, including overlays, remote-access tooling, malicious apps, and suspicious screen-sharing activity.
Q: How can banks tell a coached payment from a normal customer transfer?
A: They should look for interaction patterns that diverge from the customer's baseline, such as hesitation, rapid reversals, unusual pauses, abrupt bursts of activity, or a step-by-step navigation path that matches external instructions.
Practitioner guidance
- Expand transaction review beyond amount and beneficiary Add session sequence, navigation pace, and interaction rhythm to fraud decisioning so the bank can distinguish a legitimate payment from a coached or coerced one.
- Correlate device-risk signals with user behavior Inspect for overlays, remote-access sessions, malware indicators, and accessibility abuse before approving a payment that otherwise appears normal.
- Instrument live-session anomaly detection Score rapid context shifts such as pauses, abrupt bursts, and step-by-step instruction patterns because those are often visible before the fraudulent transfer completes.
Bottom line: The article shows that payment fraud now exploits legitimate customers and compromised devices, not just stolen credentials or obvious account takeover.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static fraud controls are now a boundary, not a strategy: MFA and rules-based monitoring still answer who logged in and what amount moved, but they do not answer whether the customer was manipulated during the session. That is why APP fraud, voice phishing, and remote-access scams keep clearing traditional controls. The practitioner lesson is that banking fraud governance now depends on intent visibility, not just authentication strength.
A question worth separating out:
Q: Should fraud teams prioritize behavioral intelligence before tightening transaction thresholds?
A: Yes, when APP fraud and remote-access scams are a material risk. Thresholds help with obvious anomalies, but they often miss legitimate-looking payments driven by manipulation. Behavioral intelligence gives teams an earlier and richer signal, so it should be prioritized where the bank needs to judge intent, not just value or destination.
👉 Read our full editorial: Behavioral intelligence and device risk are now bank controls