Shifting Left: The New Era in Fraud Prevention
Matthew Hedges (Cleafy), Lasse Riihimäki (Nordea) & Antti Alestalo (OP)
Shifting left in fraud prevention emphasizes early detection and intervention before funds leave accounts, leveraging adaptive AI and behavioral analytics to swiftly identify abnormalities and verify genuine users. Collaboration between fraud, cybersecurity, and authorities, especially in the Nordics, enhances threat intelligence and rapid response against phishing and evolving tactics. AI reduces false positives, supports investigators, and could integrate diverse data for better intuition-based risk assessment. Social manipulation, notably in romance and investment scams, remains a major challenge due to victims’ own devices and behavior, demanding advanced notification and behavioral assessment tools.
"Fraudsters constantly evolve their tactics, so banks must adapt by combining large data sets and using adaptive AI to detect fraud earlier, reduce false alarms, and enable more proactive prevention."
Summary
- Shifting left means detecting and preventing fraud earlier, ideally before payment initiation, to reduce losses and improve customer protection. - Adaptive AI models, combining transactional and behavioral data, enhance fraud detection by quickly identifying abnormalities and stolen credentials use. - Close collaboration between fraud and cybersecurity teams, plus external authorities, is vital for effective threat detection and rapid response. - AI helps reduce false positives and streamline investigator efforts but cannot fully replace human intuition, especially for complex social engineering scams. - Romance and investment scams are challenging because victims initiate payments willingly, requiring AI-driven behavioral analytics and push notifications for better risk assessment.
Article
Banking's new frontline: How 'shifting left' is transforming fraud prevention
Nordic financial leaders champion early detection and AI in fighting digital fraud
At the Nordic Fintech Summit held in May 2025, industry experts unveiled how banks are fundamentally rethinking their approach to fraud prevention, moving toward what they call "shifting left" – detecting and stopping fraud much earlier in the transaction process, ideally before payments are even initiated.
"We're all living digital lives with devices in our pockets, but 81% of fraud is cyber-enabled, so shifting left means tackling fraud earlier to better protect customers," explained Matthew Hedges from Cleafy, who moderated a panel featuring fraud prevention leaders from major Nordic financial institutions including Lasse Riihimäki from Nordea and Antti Alestalo from OP.
The evolution of fraud prevention: from reactive to proactive
The concept of "shifting left" borrows from cybersecurity practices, emphasizing prevention over recovery. Riihimäki explained how fraud prevention has evolved dramatically in recent years.
"In the early days, we got some batches and it was three days late before we started to investigate. By that time, the money was already gone," Riihimäki said. "Nowadays, we're aiming to start the investigation before the money leaves the account—ideally blocking it before the customer even makes the payment."
This approach represents a significant departure from traditional fraud management, where banks typically detected fraud after transactions had been completed, then attempted to recover funds – often unsuccessfully.
"Fraudsters very rarely cooperate," Riihimäki noted when asked about recovering stolen funds. "They're not interested."
AI and behavioral analytics: the new detection arsenal
A key enabler of the shift-left approach is the integration of artificial intelligence and advanced behavioral analytics. Alestalo emphasized that as fraudsters continuously adapt their tactics, banks' prevention methods must become equally adaptive.
"Banks need to use larger sets of data—transactional, device, behavioral data, etc.—and combine them," Alestalo explained. "To do this effectively, generative or adaptive AI systems are needed to analyze efficiently and reduce false alarms while preventing more fraud."
The panelists highlighted how behavioral biometrics – analyzing how users interact with devices through mouse movements or keyboard typing patterns – can detect when stolen credentials are being misused.
"Behavioral based analytics can detect when stolen credentials are being misused by analyzing user behavior like mouse movements or keyboard typing," Alestalo said. This technology helps identify cases where the person using the account isn't its legitimate owner, even if they have valid login information.
Breaking down silos: the collaboration imperative
The panel emphasized that effective fraud prevention increasingly depends on cross-functional collaboration, both within financial institutions and across the broader ecosystem.
"Close cooperation between fraud and cybersecurity teams is key to understanding threats quickly and setting up proactive prevention before fraud hits," Riihimäki stated. He explained how Nordic financial institutions have established strong connections with authorities, technology companies, and telecommunications providers to quickly respond to emerging threats.
In one example, Riihimäki described how coordination between these entities allows them to take down phishing sites within half an hour of detection.
The panelists praised the effectiveness of information sharing across the Nordic region, noting that frameworks like the Nordic Financial Cert facilitate crucial exchange of expertise and threat intelligence.
The persistent challenge of social engineering
Despite technological advances, the panel identified social manipulation as perhaps the most difficult fraud vector to combat. Romance and investment scams were highlighted as particularly challenging because victims themselves initiate payments willingly, often using their own devices.
"The biggest challenge is that the victim often makes payments themselves with their own device, and the behavior appears normal," Alestalo explained. "We have to identify fraud from the transactional data alone."
The speakers suggested that emerging solutions might include AI-triggered notifications during suspicious transactions, asking customers specific questions and analyzing their response patterns for signs of manipulation.
"AI helps reduce false positives, allowing experienced investigators to focus on higher-risk cases, making fraud detection more efficient and effective today," Alestalo noted, though he cautioned that AI cannot yet fully replace human judgment in complex cases.
The future of fraud prevention
As the session concluded, the panelists expressed confidence in the Nordic region's position to lead in fraud prevention innovation, citing high digital maturity across the region's financial systems. However, they emphasized that the battle against fraud remains fundamentally human.
"While AI and machine learning are helpful, they can't fully replace human intuition and judgment, especially since we're ultimately dealing with human beings," Hedges noted in his closing remarks at the Nordic Fintech Summit.
The shift-left approach represents not just a technological evolution but a philosophical one – moving from recovering lost funds to preventing losses altogether, and placing customer protection at the center of fraud prevention strategy.
As Riihimäki summarized: "Fraud prevention must start before the customer even makes the payment, ideally blocking fraudulent transactions before they enter the banking system."
Part of Nordic Fintech Summit