Building Financial Crime Capabilities for Today’s Threats A FINTRAIL and SEON Roundtable

This session brought together senior financial crime compliance leaders from firms based in the Middle East or with current/planned Middle East coverage for an interactive, discussion-led roundtable. The session focused on practical benchmarking and sharing peer experiences around how firms are structuring their financial crime functions, using data and signals effectively, and enabling (or struggling with) information-sharing - framed by the question: “Are we set up appropriately for today’s financial crime challenges?”

Key Points Discussed

  • Organising AML vs fraud

    Participants stated that the ideal operating model varies by business model and product, but there was broad agreement that fraud and AML often require different specialists and workflows, with possible shared supporting resources (e.g., data teams). 

    While fraud and AML are related, they are distinct disciplines with different operational needs, workflows, and control objectives. For instance, fraud controls are preventive and measurable through direct losses. Participants’ real-world experience showed that it was more effective to separate out the functions to enable greater expertise and focus.   

    Fraud is increasingly prominent as a regulatory and operational focus in the Middle East, and requires targeted prevention. Participants highlighted specific reasons why the fraud landscape in the Middle East may be distinct, such as the transient nature of parts of the population, trust-based communities and the common use of shared bank accounts and devices among family and friends.

    Participants did not indicate they had seen significant levels of AI-enabled fraud or technologically advanced criminal activities. Romance scams and APP fraud were highlighted as significant threats, which rely more on psychological manipulation rather than technology. As a result, “the number one tool that is the most useful in fraud is awareness, no matter how advanced the tools are.”

  • Data usage: signals that lead to action (not dashboards for dashboards’ sake)

    The group explored which data signals are genuinely useful – highlighting device intelligence, network analytics, and transactional data- and when those signals translate into concrete control changes or investigations.

    Non-static KYD data signals were highlighted as useful in enabling cluster identification and concrete investigations/control updates, for example, using network/graph analysis to identify fraud clusters. One participant described how using device information and network graphs to connect related actors into clusters turned a “needle in a haystack” search into something meaningful, reducing investigation time and enabling understanding of the modus operandi.

    Participants agreed that compliance teams now need stronger data/technology understanding (e.g., analytics, device and network analysis), and firms now recruit more specifically for these skills. 

    Firms balance the use of internal and vendor tools, with a shift toward in-house-built tools specifically designed for the firm.

    Participants also questioned whether too much data could be a problem. The potential issues include the obligation or expectation to act on accessible data, which firms may not be set up to do (for example, the expectation to screen additional payment data fields, or review device IP information). One participant noted that KYC requirements differ across jurisdictions (e.g., what can be collected in certain Middle Eastern markets vs US/Canada), creating compliance complexity and privacy/data-protection risk.

  • Information sharing: appetite exists, mechanisms lag:

    The discussion highlighted trust, legal basis, and “tipping off” concerns as barriers to greater information sharing. There was support for typology-based sharing, but more reservations and concerns about sharing customer-level intelligence between institutions. In practice, given all the competing areas requiring attention from compliance professionals, most firms are not actively engaged with the question of information or intelligence sharing, even though they appreciate that a clear way to participate would be beneficial.  

Key Takeaways

The roundtable concluded with a strong “design principles” mindset: collect only what you will use, avoid drowning in data that you don’t act on and build structures that align with how fraud and AML actually behave in real operating models.

  • Fraud and AML should typically be treated as distinct operational disciplines.

    A la prevention/real-time needs vs suspicious activity/enforcement workflows, even if there is close collaboration and good visibility, and integration in shared support functions.

  • For all the hype, many major threats are nothing new

    Romance scams, APP fraud and other psychology-based scams still seem more common than advanced Gen AI-enabled frauds or deepfakes.

  • Data only helps if it leads to action.

    Device intelligence and network analytics were highlighted as particularly effective for identifying connected behaviour and shaping next steps. However, collecting more data for data’s sake could be operationally and legally problematic.

  • Information sharing needs both legal clarity and trust-building mechanisms

    Typology-based sharing is often more feasible than customer-level AML sharing.


Disclaimer: This article summarises the discussion and views shared by participants during the FINTRAIL and SEON roundtable, "Building Financial Crime Capabilities for Today's Threats." The insights reflect the perspectives and experiences of attendees at the time of the session and do not necessarily represent the views of FINTRAIL or SEON. This article was last updated in Q3 2026. Please feel free to contact us to request an update or correction.