Industry Intel - Conference Recaps and Thought Leadership Article

One Criminal Two Teams

The organized groups behind 2026’s fastest-growing financial crime run one continuous operation. Most institutions still fight it with two: fraud on one side, AML on the other. That seam is the opening.

The organized groups behind 2026’s fastest-growing financial crime run one continuous operation. Most institutions still fight it with two: fraud on one side, AML on the other. That seam is the opening.

Criminals run one operation while you run two

A scam, a mule network, a laundering chain: to the organized group behind it, that is one continuous operation. To most institutions, it is two. Fraud sits in one function, with its own team, its own technology stack, and its own view of the customer. AML sits in another, with a separate team, stack, and view. The criminal moves smoothly across a seam your own org chart created.

That seam is exactly where 2026’s fastest-growing financial crime lives. Authorized push payment scams now rival or exceed card fraud by value. Pig butchering, romance baiting, and money-mule recruitment blend social engineering (a fraud problem) with laundering (an AML problem) in a single unbroken flow. Regulators have noticed: the growing expectation from FinCEN to FATF is that institutions demonstrate enterprise-wide financial crime visibility, not departmental snapshots.

Organized crime does not respect your org chart. The seam between fraud and AML is not a boundary. It is an opening.

Three forces are collapsing the wall

FRAML, the convergence of fraud and AML into one operating model, has been discussed for years. Three forces turned it from an aspiration into something close to a necessity in 2026. Instant payments compressed the detection window from days to seconds, leaving no time to hand a case from one team to the next. AI-driven scams, from deepfakes to synthetic identities, industrialized the attack and outran any single siloed control. And regulators moved from tolerating the silo to expecting a unified view of financial crime risk.

Put together, those forces do not just make convergence attractive. They make the old two-team model a liability you have to actively defend.

Converging is not collapsing

Here is where FRAML goes wrong when it is done carelessly, and it is worth saying plainly. Fraud and AML are not the same obligation. A fraud loss is a number on a balance sheet; a suspicious activity report is a legal filing to the government. They answer to different regulatory drivers, different metrics, and different data-handling rules. Merging the teams and the dashboards while blurring those duties does not reduce risk. It creates a new kind.

The silo was always a data problem

Strip away the org-chart debate and the reason the seam exists is simpler than it looks. Fraud and AML have historically run on different data about the same customer: two systems, two risk scores, two partial pictures of one person. You cannot see a layered scam-to-laundering flow when the fraud team can see the scam and the AML team can see the laundering, but neither can see both.

So the real act of convergence is not merging two teams. It is giving both of them the same authoritative, shared view of the entity, so a single alert can carry both fraud and AML context, and an investigator can follow the money and the behavior without switching systems or losing the thread.

The real test of a FRAML program: not whether fraud and AML sit in the same department, but whether they reason over the same data. If they do not, you have merged the org chart and kept the silo.

Converge the evidence

Five moves build a program that unifies without blurring:

  1. Start with shared data, not a shared org chart. Give fraud and AML one authoritative view of the customer, and of the entities behind them, before you reorganize a single team. The data is the hard part; the reporting lines are the easy part.
  2. Let one alert carry both lenses. Build detection so a single event can trigger fraud and AML scrutiny together, with the specific context each function needs attached to it.
  3. Keep the obligations distinct. Preserve separate suspicious-activity-report and fraud-loss processes, metrics, and data-handling rules even as the underlying view is shared. Converge the evidence, not the filings.
  4. Screen the whole picture, continuously. Sanctions, PEP, and adverse media signals belong in the fraud view too. A mule account tied to a sanctioned network is both problems at once, and only visible if both functions see the same screening.
  5. Preserve one audit trail. Capture the rationale for every disposition in a single, defensible record that an examiner, and both functions, can follow without reconciliation.

Convergence runs on shared trustworthy data

The through-line is unavoidable. FRAML is sold as an operating model, but it stands or falls on a shared data foundation. Both functions need the same authoritative picture of who they are dealing with, delivered in real time, or the seam simply reopens somewhere else.

VITAL4

See How Vital4 Gives Fraud and AML One Shared View

REQUEST A DEMO