AI Against Fraud, AI as Fraud Risk: Two Control Loops, One Accountability
Why FINMA’s latest Guidance 02/2026 raises a governance question for every financial intermediary that cannot be delegated to IT.
Wealth managers and family offices are now facing a new generation of attacks. Deepfake voice instructions, forged source-of-wealth documents, and targeted phishing against relationship managers and executives hit them directly, often before a bank transaction even looks suspicious. FINMA has documented the same pattern at banks and, at the same time, set strict expectations for the use of artificial intelligence. That puts boards in front of two control loops that cannot be delegated to IT.
Guidance 02/2026 on digital fraud risks paints a sobering picture:
- Of 19 banks surveyed, eight lack a standalone digital fraud policy.
- Three institutions have no governance body for the topic at all.
- One in four surveyed banks has no process for anticipating fraud trends.
- Only around half regularly provide the executive team with digital fraud metrics.
- Twelve institutions claim to have sustainable governance structures, but FINMA notes that these mostly consist of dual-hatted roles across security, payments, risk, and IT, without clear task allocation, accountability, or documented competencies.
That is not a resilient governance structure. It is a structure without documented accountability. Which means it cannot be steered.
Formally, the Guidance addresses banks and persons under the Banking Act. Its findings are nonetheless relevant to every financial intermediary. The due diligence duties under Art. 3 to 6 AMLA and Art. 14 et seq. AMLO-FINMA also apply to FinIA-regulated wealth managers, fund management companies, and collective investment schemes. The board of an independent wealth manager or a family office cannot opt out of the discussion by arguing that the Guidance is primarily aimed at banks.
For wealth managers, the relevance is shaped differently than for banks. The focus is less on the bank-typical payment engine than on governing service providers, instruction and communication processes, and AMLA-relevant clarifications. The governance question, however, stays the same: who recognises patterns, who decides the rules, who escalates, who documents?
What FINMA writes in Guidance 02/2026 about the mechanics of today’s transaction monitoring systems is particularly telling. Many institutions do not use their KYC information for ongoing monitoring at all. They only apply it retrospectively for plausibility checks. The thresholds at which pass-through transactions for retail clients with low or normal risk are flagged as elevated-risk transactions sit, for most respondents, at CHF 100,000 or CHF 200,000. FINMA reads this as a sign of unsophisticated systems that work with rigid limits rather than specific scenarios.
Two control loops
This is exactly where Guidance 08/2024 on governance and risk management in the use of artificial intelligence comes in. It names insufficient robustness, correctness, bias, stability, and explainability as the central model risks, and requires a centrally maintained inventory, risk classification, testing, ongoing monitoring, documentation, and an independent review of the entire model development process.
FINMA writes in its 2023 Risk Monitor: ‘Clear roles and responsibilities, as well as risk management processes, must be defined and implemented. Responsibility for decisions cannot be delegated to AI or third parties. Everyone involved must have sufficient AI expertise.’
This puts boards in front of a duality I have already outlined in earlier LinkedIn articles: AI is both a tool that supports the board and a subject of board oversight in its own right. The same pattern appears at operational level, but it is worth separating the two levels cleanly.
-
The first control loop concerns the effectiveness of fraud defence: are suspected cases detected in time, are response plans effective, do reporting channels work around the clock, are key controls tested regularly?
-
The second control loop concerns the robustness of the AI system itself: are model risks identified, is model drift monitored, is there an independent model review, is dependency on third parties under control? Both loops need different questions, different metrics, and different escalation paths. The board must be able to act in both loops at the same time.
The reverse question: is there a duty to use AI?
German-language legal literature discusses whether the requirement for an adequate information basis could, conversely, establish a duty to use available AI tools (see Langenbucher, ZHR 2023, 723 et seq.; Möslein, Robots in the Boardroom, 2017). For the board of a typical Swiss company, this is not currently a factor relevant to liability. Not using AI does not, on its own, constitute a breach of the duty of care, because how much information is adequate ahead of a decision remains itself a business judgement, one that courts review only with restraint.
Möslein already sketched the trajectory in 2017: as adoption spreads, using AI becomes an industry standard, and not using it starts to require an explanation. It is precisely in these exceptional cases that FINMA’s criticism of rigid limits becomes relevant. Where full machine-based evaluation is available, relying on fixed thresholds requires justification. The argument is familiar from auditing: the sampling approach historically rested on efficiency grounds under limited data-processing capacity. As technical alternatives become more available, the burden of justification grows. Should an incident occur, the question will come: why, despite available methods, the institution stuck with rigid thresholds.
Role clarity between the board and the executive team
The division of roles can be stated clearly:
-
The board sets the risk appetite, approves the digital fraud policy, requires meaningful metrics, reviews the effectiveness of controls, and ensures independent review of AI applications.
-
The executive team runs the fraud desk, implements the controls, organises round-the-clock response capability, manages vendor oversight, and maintains the AI inventory with testing, monitoring, drift detection, and documentation.
The board carries accountability; the executive team carries implementation responsibility.
For the second control loop, Guidance 08/2024 spells out the expectations in more detail. Four questions are central.
- Do we have an inventory of all AI applications with risk classification, including purchased solutions and third-party providers?
- Are testing, performance indicators, drift monitoring, and the handling of exceptions properly governed?
- Is the explainability of those decisions ensured that we must justify to clients, auditors, or regulators?
- Is there an independent review by qualified staff who are not part of the development team?
If these questions cannot be answered at board level, that is not a sign of insufficient technology competence. It is a sign of insufficient oversight within the meaning of Art. 716a para. 1 no. 5 OR.
Why delegation deserves attention
FINMA requires supervised entities to identify, assess, manage, and monitor all material risks. By definition, that is a governance task. If this is poorly designed, client losses and reputational damage are at stake. In addition, the board risks personal liability under Art. 754 OR. If a board outsources AI-supported fraud defence to service providers without effective governance structures in place, it effectively weakens its own ability to exercise oversight. FINMA addresses this unambiguously in Guidance 02/2026: heavy dependency on service providers means that some institutions cannot adjust detection rules promptly. Whoever cannot steer cannot oversee.
Conclusion
Across Guidance 08/2024 and 02/2026, FINMA paints a clear picture. AI becomes an important tool for fraud defence and remains, at the same time, one of the central operational risks. This dual mandate cannot be handed off. It requires two separate control loops, a clear split between accountability and implementation, and a board capable of asking the right questions.
Sources
- FINMA, Guidance 02/2026 – Digital Fraud Risks for Banks and Persons under Art. 1b of the Banking Act, 9 April 2026.
- FINMA, Guidance 08/2024 – Governance and Risk Management in the Use of Artificial Intelligence, 18 December 2024.
- FINMA, Risk Monitor 2023, 10 November 2023.
- Langenbucher, K., Künstliche Intelligenz in der Leitungsentscheidung des Vorstands, ZHR 187 (2023), 723 et seq.
- Möslein, F., Robots in the Boardroom: Artificial Intelligence and Corporate Law, 2017.