Customer vulnerability as fraud intelligence: rethinking customer risk to combat money muling

In July 2026, the Home Office published new research into money muling, revealing both the scale of recruitment and the growing sophistication of criminal exploitation.  

The research found that:

  • 20% of respondents encountered a money mule recruitment opportunity in the last 12 months, through online/social media platforms, emails or direct messaging apps.

  • Only 18% of people correctly identified all three money muling scenarios as illegal, highlighting a significant awareness gap. 

  • Previous victims of fraud or cybercrime were more than twice as likely to be targeted for money mule recruitment than non-victims through online and social media platforms.

This survey highlights not just the scale of recruitment, but also who is being targeted and why. Criminals deliberately exploit vulnerability. Financial hardship, unemployment, loneliness, previous victimisation, coercive relationships and misplaced trust all increase susceptibility to recruitment. Importantly, many participants weren't motivated solely by financial gain; they genuinely believed they were engaging in legitimate activity because recruiters created convincing and credible narratives.

Financial crime, customer vulnerability and financial inclusion are therefore becoming increasingly interconnected. 

This presents a significant challenge for firms - if vulnerable customers are viewed primarily as presenting higher fraud risk, there is a danger that firms respond by withdrawing services or applying increasingly restrictive controls. Such de-risking would undermine financial inclusion while not necessarily addressing the underlying criminal exploitation. The FCA, in their FG21/1 policy statement, makes it clear that ‘firms should consider consumers’ vulnerability and capacity to make decisions when deciding how to treat consumers who have been victims of scams or fraud’, and that if the firm assesses that ‘they are acting as a result of fraud or coercion, it should assess whether it should allow the consumer to proceed’. In other words, declining to act on a customer’s instructions can be in the customer’s best interests.

Firms need to strike a careful balance between preventing financial crime and ensuring vulnerable customers continue to receive fair access to financial services.

Rethinking customer risk 

Customer risk assessments (CRAs), undertaken in line with Regulation 18 of the Money Laundering Regulations, have traditionally focused on assessing the risk that the customer poses. Those factors have included static risk attributes such as customer type, occupation, geographical location, expected account behaviour, politically exposed persons (PEP) status, and products/services used. These remain essential to a CRA methodology. 

Firms have historically reviewed customer risk as ‘how much risk does this customer pose to our business?’. A vulnerability-focused approach requires a fundamentally different question:  ‘how much risk does the environment present to this customer?’ This shifts the focus from protecting the firm to understanding the customer's exposure to harm, recognising that involvement in money muling exists on a spectrum, ranging from deliberate participation by known associates of criminal networks, to customers who have been manipulated or exploited as unwitting accomplices.

Rather than viewing vulnerability solely through the lens of Consumer Duty, firms should therefore begin incorporating indicators of customer susceptibility into their financial crime frameworks. This is not a new concept - the FCA’s policy statement (PS24/17) on changes to the Financial Crime Guide (FCG) pinpoints the relationship between consumer duty, vulnerability and financial crime prevention. Specifically, the FCG now states that ‘firms should consider whether their financial crime systems and controls are consistent, where applicable, with their Consumer Duty obligations’. 

A multi-dimensional customer risk assessment

Traditional CRAs should be complemented by a vulnerability assessment ‘overlay’ which considers vulnerable indicators and dynamic fraud intelligence; this enables firms to design tailored support paths for customers more susceptible to fraud.

Examples may include: 

Dynamic fraud intelligence may further include:

  • Periods of dormancy followed by sudden increases in payment frequency or value

  • First-time payments to new beneficiaries

  • Payments from numerous unrelated third parties

  • Customers repeatedly overriding scam warnings

  • Requests to increase payment limits shortly before making transfers

  • Incoming funds that are rapidly dispersed to multiple recipients

Unlike static customer information (e.g. occupation, location, or PEP status which offers only a point-in-time snapshot), these dynamic indicators capture customer activities in real-time. 

Shifts in behaviour can also be vulnerability indicators. By tracking subtle behavioral shifts, such as sudden changes in transaction velocity or interactions with high-risk counterparties, firms can move away from reactive, historical and static profiling, and focus on threat detection, empowering teams to intercept suspicious activity, and safeguard customers before financial losses crystallise.

Designing tailored support paths:

Overlaying CRAs with vulnerability assessments can lead to more proportionate interventions which reflect the customer’s individual circumstances and the nature of the risk, such as:

Education awareness and campaigns

  • Tailored scam and fraud awareness education

  • Enhanced payment warnings

  • Referral to specialist customer support teams

  • Delayed payment review where appropriate

Transaction monitoring

  • ‘Hard blocks’ on transactions following periods of dormancy, or payments which exceed defined thresholds

  • Step-up verification for specific risks (e.g. unusually large payments to a new beneficiary)

  • Customer prompts to interact with an educational warning, or staff member (i.e. to confirm they are not being coerced)

  • Restrictive transaction caps (e.g. daily/monthly) which adapt to changing behavioural risk

Intelligent customer journeys

  • Simpler, easy-to-understand and digestible language

  • Proactive communications outside the payment journey 

  • Different communication channels, and access to specialist support

  • Proactive check-ins following fraud attempts 

  • Exemptions from immediate account suspensions, pending further review of the customer’s vulnerability and suspected mule activity 

The Consumer Duty places emphasis on deploying positive friction throughout the customer journey, enabling customers to think before they act. These interventions should be applied proportionately, reflecting the level of identified risk and the type of protection most likely to support good customer outcomes.

Importantly, firms should establish clear criteria for determining when customers have regained sufficient ‘resilience’ to justify lifting friction and removing heightened monitoring activities. This assessment should be appropriately reflected in the customer’s risk profile and internal system notes. 

Avoiding a new wave of de-risking:

A vulnerability informed framework should not mean that vulnerable customers are automatically treated as inherently higher financial crime risks. Instead, firms should recognise that they may face greater exposure to exploitation, and customers should therefore benefit from different forms of support and protection. Fraud risk should be a component of the overall CRA, and weighted accordingly as per the guidance set out in JMLSG (section 4.49 and 4.50). 

This distinction is important - equating vulnerability with financial crime risk could drive harmful de-risking practices. The FCA has warned against wholesale de-risking, requiring firms to manage the financial crime risks within their organisations. 

Instead, firms should use fraud insights and vulnerability markers to inform a more nuanced understanding of customer risk. This enables firms to tailor inventions which simultaneously strengthen fraud prevention and foster better customer outcomes.

This shifts the question from ‘should we trust this customer’ to ‘how can we best protect the customer in the context of the risks they face?’ 

Creating joined-up governance

Delivering this approach requires collaboration across organisational boundaries; this can be challenging, depending on the size, scale and operations of the firm. However, many firms still manage fraud, financial crime, customer vulnerability, product design and customer service as separate functions, each with their own objectives, goals and data sets. 

As mentioned in this paper, the FCA has repeatedly highlighted that Consumer Duty should be embedded across the organisation, so this isn’t a new concept. 

But the Home Office research suggests a broader need for an enterprise-wide response to fraud prevention and detection. This should be a single shared customer protection outcome rather than separate objectives. Firms should therefore be asking themselves:

  1. What fraud intelligence does the firm have to inform vulnerability assessments?

  2. What vulnerability insight does the firm have to enhance fraud decision-making?

  3. What processes are in place to support customer service agents to identify emerging fraud risks, and how is this information disseminated and escalated across the firm?

  4. How does the firm align objectives across product design, fraud and consumer duty teams to avoid retrofitting fraud controls later?

  5. Does the firm have any operational or organisational barriers to prevent sharing of customer data across different business units? 

Fraud intelligence informs vulnerability assessments ↔ vulnerability insights inform fraud decisioning

Measuring outcomes differently 

Many firms simply track fraud through fraud losses, false positives, payment declines and recovery rates. To track success, firms should expand these traditional fraud loss metrics towards customer protection outcomes, which measure the firm's effectiveness in safeguarding the individual and strengthening their resilience against exploitation.

This may include: 

Conclusion

The latest insights from the Home Office prompt whether our approach to financial crime should evolve further, towards identifying customers who are more susceptible to exploitation, and tailoring anti-financial crime framework to protect customers and deliver good outcomes. 

By weaving together vulnerability indicators alongside dynamic fraud intelligence, firms can develop a richer, more nuanced understanding of customer risk to intervene earlier and provide more proportionate protections. 

Customer vulnerability should not be a trigger to de-risk - it should be recognised as a valuable source of intelligence to help distinguish criminal intent (i.e. mule herders and recruiters) from criminal exploitation (victims). 

Firms embracing a more consumer-centric approach will not only strengthen their controls, but support better customer outcomes - effective fraud prevention and good customer protection are not (and should not be) competing objectives, but complementary ones. 

How FINTRAIL and Cosegic can help

Building a vulnerability-informed financial crime framework isn't a policy tweak; it means rethinking how fraud, financial crime and customer vulnerability teams work together.

FINTRAIL's regulatory compliance and financial crime services support firms through every stage of this shift from reviewing existing CRA methodologies against JMLSG and FCA guidance, to designing tailored intervention frameworks and enhancing anti-financial crime controls, risk assessments and operating models.

We also support firms through the practical challenges of joined-up governance: breaking down silos between fraud, financial crime and Consumer Duty teams.

Explore our free resources, including checklists, guides, and practical tools, to help strengthen your anti-financial crime controls, or visit the FFE to connect with the wider fincrime community tackling these challenges together.

Get in touch with FINTRAIL or Cosegic to discuss how we can help you build a more resilient, customer-centric approach to financial crime prevention.