test

Future Stores 2026

test

09/17/2026

Last updated

Event: Future Branches

Session: Balancing Fraud

Speakers: Sean Albertson, Founder and CEO, CX4ROCKS; Greg Stevens, Director of Fraud Analytics, First Technology Federal Credit Union; Chelsea Gstohl, Senior Vice President, Pelican State Credit Union; Rebecca Neumeier, Vice President, Hanscom Federal Credit Union; Douglas Bolton, Senior Fraud Prevention Officer, Cape Cod Five Bank

TL;DR

Verifying an identity at account opening is no longer sufficient because AI now lets fraudsters combine real Social Security numbers and dates of birth with fabricated bank statements and utility bills to build convincing synthetic profiles. At Future Branches, panelists described a shift away from static personal data toward device signals, IP addresses, and continuous monitoring, alongside risk-tiered onboarding that lets low-risk members open accounts with zero staff touch. For practitioners, the panel's core argument was that fraud controls built in isolation from the member experience end up punishing good customers without actually stopping the bad ones.

Key Takeaways

1. Synthetic identity fraud is forcing a shift from static data to behavioral signals

Fraudsters now combine legitimate Social Security numbers and dates of birth with fabricated bank statements and utility bills to construct what Bolton called a "syndicated profile" that looks real to reviewers. Institutions need to move away from gathering static non-public personal information, he said. Look at IP addresses instead. Device fingerprints and location mismatches, such as a login originating out of state or out of the country, help flag likely fraud, he said.

The same pressure shows up at the acquisition level, where Stevens said his institution runs fraud rates of 4 to 5%, concentrated online rather than in branches. The tools bad actors use to defeat verification are increasingly the same AI tools institutions deploy to catch them, he said, which pushes fraud teams to cast a wider net without slowing down legitimate applicants.

2. Risk-tiered onboarding lets most members skip document collection entirely

Pelican State Credit Union now opens roughly 70% of new accounts without any staff member touching the application, according to Gstohl. The credit union uses Alloy to scan new member applications, and when an identity scan comes back clean, staff no longer collect a driver's license, Social Security card, or birth certificate the way they used to on nearly every account.

A comment gets logged instead. It notes that identification will be collected only if the member later interacts in person, over the phone, or attempts something flagged as risky. Staff are trained to read the specific warning codes returned by the screening tools and respond accordingly, Gstohl said, which she described as necessary to compete with digital-first challengers like Chime and Cash App.

3. Fraud response requires centralized workflows across departments, not isolated teams

Hanscom Federal Credit Union only centralized its fraud function in early 2024. Before that, a single fraud incident generated dozens of scattered emails across departments handling maintenance and outreach separately, according to Neumeier.

The credit union built a fraud alert workflow into its CRM so that once any business line opens an alert, tasks automatically route to deposit operations to disable remote deposit, to card services to turn off plastic cards, and to digital banking to restrict online access. A separate "fraud flip" workflow handles cases serious enough to require reissuing a membership number. It pulls in consumer and residential lending as needed.

4. Front-line staff need permission and practice to ask uncomfortable questions

Staff often hesitate to ask direct questions about a suspicious IP address or an unfamiliar phone number because it feels intrusive, according to Gstohl. Pelican State addressed this by role-playing specific scenarios with staff, including scripted questions like asking whether a member's cellphone is on their own plan or someone else's account, until staff had the confidence to ask without hesitation.

Front-line staff need to watch for behavioral cues. Urgency, rushed transactions, a third party speaking on the member's behalf, alongside transactional red flags such as large cash deposits or out-of-state checks that don't match a member's residence, Bolton said. What counts as a red flag can be subjective across departments, Neumeier added. That's why interviewing skills and the ability to escalate matter as much as the checklist itself.

5. Fraud teams that operate in isolation end up punishing legitimate customers

Fraud controls built strictly from a fraud perspective will catch some bad actors in the "red" risk tier but will simultaneously make the experience miserable for legitimate members in the "green" tier without solving the harder problem sitting in the "amber" middle, Stevens said. Evaluating fraud in the context of the wider member experience, not as a standalone metric, was his framing for where institutions should focus.

Product and operations teams should involve fraud staff before launching new products or features, rather than after, so risk tradeoffs get made deliberately. That was Stevens's broader point. "We're fun. We are good to hang out with," he said of fraud teams, adding that too often changes go live with no fraud conversation at all.

In Their Words

With AI, fraudsters have the ability to gain legitimate information like Social Security numbers, date of births, on top of also getting fabricated information, creating bank statements, utility bills. So essentially what we have to do now is go away from gathering static information like non-public personal information and kinda lean towards technology. Look at IP addresses, look at the devices that they're using, see if they're in the same state or out of the country because that may help you identify if fraud is occurring.

— Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod Five Bank

Onboarding is no longer about verifying the identity at the point, and that's enough. You have to do ongoing monitoring to establish trust. The ongoing monitoring is really important with fraud prevention.

— Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union

Actionable Insights

  • Tier onboarding by risk level instead of applying uniform document requirements. Pelican State skips ID collection on roughly 70% of new accounts when identity scans come back clean, reserving document requests for flagged or in-person interactions.
  • Replace static identity checks with device and location signals. Bolton recommended tracking IP addresses, device fingerprints, and geographic mismatches to catch synthetic profiles that pass traditional document review.
  • Build a CRM-based fraud alert workflow that automatically routes tasks across departments. Hanscom's system triggers deposit operations, card services, and digital banking simultaneously once a fraud alert opens, replacing dozens of manual emails per incident.
  • Script and rehearse the specific questions staff should ask about suspicious account activity. Pelican State role-played scenarios like verifying whose name is on a member's cellphone plan until staff felt comfortable asking without sounding accusatory.
  • Invite fraud teams into new product and feature discussions before launch, not after.

More sessions like this one are available from Future Branches for institutions working through the same fraud and onboarding tradeoffs.

{"@context": "https://schema.org", "@type": "Article", "speakable": {"@type": "SpeakableSpecification", "cssSelector": [".article-tldr", ".article-key-takeaways"]}, "headline": "Fraud Without the Friction: Five Credit Unions on Onboarding"}
Full Session Transcript

Sean Albertson, Founder and CEO, CX4ROCKS: So I'm gonna go ahead and ask Greg, Chelsea, Rebecca, and Douglas to come up towards the stage. But we're gonna be talking balancing fraud. We one of the closeouts when we were filling time right before everything started working again was fraud. So we're gonna talk and spend a lot of time that fraud and friction and account opening and onboarding. Greg Stevens, Director of Fraud Analytics from First Technology Federal Credit Union DCU division. Chelsea Stoll, Senior Vice President Member Experience, Pelican State Credit Union. Rebecca Newmar BSA and Fraud, Hanscom Federal Credit Union, and Douglas Bolton, AVP Senior Fraud Prevention Officer at Cape Cod Five Bank. So welcome. All right All right. So we talked when we were preparing, I told you guys my story about my wife getting a call from Chase pretty soon after I- we had created an account where they knew our names, they had all this information. The caller ID came up. Man, they're getting good, 'cause it was not Chase. And so they were getting really good. So this is such an important topic. So we'll start with just saying, let let's, tell us about yourself a little bit, your role and and go from there. Maybe if you'll start us off.

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: Sure. Sean, good to be here. Good morning, everybody. Yeah, Greg Stevens. I am the Director of Fraud Analytics at Digital Federal Credit Union, which is now operating as a division of First Tech, merger activity going on there. I've been in the space, I've been in financial services for 30 years focused on fraud and security for the last 20. And to your point, this is a tremendous topic, right? We're trying to balance acquisition with security, fraud risk, et cetera, and it's so challenging right now. So- Absolutely definitely a lot to dig into here.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. Rebecca?

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: Hi. Thank you. I'm Rebecca Neumayer. I'm the Vice President of BSA and Fraud at Hanscom Federal Credit Union. Been there for just over 21 years, or almost 21 years. Started out on the front line, so I love having that experience being in a fraud position. Today I oversee our BSA fraud and internal controls programs.

Sean Albertson, Founder and CEO, CX4ROCKS: Doug?

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Yeah, I'm Doug Bolton. I'm Senior Fraud Prevention Officer at Cape Cod Five. Like Rebecca, I've been with the bank for 21 years 17 of it in the financial investigative fraud prevention area.

Sean Albertson, Founder and CEO, CX4ROCKS: All right. Chelsea?

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: And I'm Chelsea Gstohl. I'm the s- Senior Vice President of Member Experience at Pelican Credit Union. I've been at the credit union all my life, so s- since I got ... Since I was in college. And so I did marketing and business development for 12 years, and then the last four years I've moved into the front line overseeing contact center, retail branches, and digital banking.

Sean Albertson, Founder and CEO, CX4ROCKS: Awesome. Greg, let, let's start with you. So as mentioned, things have gotten a lot more sophisticated, AI, synthetic identities, social engineering. It, just to name a few. W- what changes are having the biggest impact on how institutions think about the onboarding risk today?

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: I think about this, Sean, a- at the acquisition level. Right now we're running 4 to 5% typically, and I wanna define that in a couple different ways. First is the majority of that is online. I've got a number of my branch colleagues here. They do an exceptional job in the branch identifying. They have the benefit of the individual standing in front of them. That helps for sure, but it's not foolproof. There is fraud going on in the branch. From there we think about the point of acquisition, if we can get it there, then we don't onboard a, a bad actor, right? Unfortunately, although that is usually the case, some of them do get through, they get in, and again, the preponderance of that is online. What does that mean? The sophistication, as you mentioned your own experience, right? That sophistication continues to grow incredibly because the bad guys are using the same tools that we're trying to deploy, and AI is prolific in that space as well. What does it... We gotta cast a wider net and that creates friction. And Ally was just talking about friction, right? It's a bad experience for prospective members, and they'll go somewhere else. So we're really trying to figure out how do we cut through- That and really minimize the friction where we're able to so that we can complete a successful onboard, and quickly too. They're not hoping to go through a whole bunch of hoops so you can figure out if they're good or not, so we're trying to make that as seamless as possible as well. So it's really a precarious balance, and it's getting harder.

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely. Rebecca, what would you add?

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: I think I read a an article, knowing that I was gonna be here today and speaking about fraud and onboarding I was reading some articles on LinkedIn, and I came across one that was interesting. It said that onboarding is no longer about verifying the identity at the point, and that's enough, like it's enough to just verify the identity then. You have to do ongoing monitoring to establish trust. So I, the investigator in me, the BSA analyst in me, I started going down a rabbit hole and how is trust... Like, how do you earn trust? And it's through, repeatable actions and consistency and things like that. So the ongoing monitoring is really important with fraud prevention.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. So- Absolutely. Doug, what would you add?

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Yeah, with AI, fraudsters have the ability to gain legitimate information like Social Security numbers, date of births, on top of also getting fabricated information, creating bank statements, utility bills. And what essentially they're doing is creating a syndicate, a syndicated profile that looks legitimate and real to people looking at the profile. So essentially what we have to do now is go away from gathering static information like non-public personal information and kinda lean towards technology. Look at IP addresses, look at the devices that they're using, see if they're in the same state or out of the country because that may help you identify if fraud is occurring.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah, absolutely. Chelsea obviously we've talked even earlier today, friction is bad, effort is bad, but sometimes there's good friction, right? And this is a great example of when good friction when friction is necessary in many cases. When you're thinking about that what changes or how do you determine when friction is necessary and at what level? How do we make those rules? 'Cause you, again, you wanna be easy, but you need enough friction, et cetera. So how do you look at that?

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: The best way we found to look at it is to utilize technology. And so we're using Alloy to scan all of our new member applications coming in. And what we found is that everyone doesn't have to go through the same onboarding or the same account opening experience when you come in. So if someone's scan, their identity scan through all these partnerships and tools, we might not need their ID. I've been, we've been ... We had departments across the credit union freaking out lately when they realized we don't have IDs on file for members. We didn't need it on file then because everything was clear. We have a comment on their account saying, "Get their ID when we..." If they interact with us in person or over the phone or try to do something risky, we'll do some extra checks. But a kid's account that's opening doesn't need the same verification and the same materials that you have to collect as an adult's account that may have some high alert scans on it. And so we've taught all of our staff to identify the different warnings and codes that come back from these programs and how to address them. And so we're opening about 70% of our new accounts without anybody touching them. And a lot of times it's not gathering an ID or Social Security card or birth certificate, and we used to do that on almost every account in the past. And so we've really had to tier it. So you make it more seamless for The right people are the less red flags, and that has been the best way to kinda compete with Chime and Cash App and those things out there where you just click, and it's open, where people used to be like I'd have to bring you all my paperwork."

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. Doug, what about you?

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Yeah going along that same lines, it's just ongoing ric- risk assessment of the client base itself. As she alluded to it's it's a different assessment when somebody's an existing client versus a new one. Also, if somebody's just opening a CD compared to a business open and operating account, you're gonna need more information. So on top of that, you gotta look for red red flags. If somebody's coming from a different location, again, out of state, opening accounts or utilizing, a check from out of state, that doesn't quite align with where they live or reside you may need to dig a little bit further into the information so that you feel more comfortable with the client themselves, and the bank also has a comfor- comfortability with the risk involved, and then kinda weigh from there.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. Doug, what would you say about the balance of good... the right amount of friction?

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: I think these guys have covered it well. I think about a typical risk stratification, right? You kinda get your red, amber, green, and y- you're aiming for your green, and I think Chelsea covered that part really well, right? They are who they are, you trust them. That's pretty immediate, right? You also similarly have the red part of it, which is the bad actors, and they're probably not great. They're not super creative, and maybe they're not using the tech to do it, so you can weed them out fairly quickly as well. What's your tolerance for the middle? And that's both to figure out who's good and who's not good, and so that's kinda where the action is. And I think, it, for... it's on an institution basis as part of a ric a- a risk appetite conversation. So fig- how wide are we gonna let that be? Where are you gonna, sorta stratify on what you wanna do? And that becomes really that risk management piece of it that I think these guys talked about.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah, I think I think back to a little bit of my own experience. My my brother is special needs, and I'm his guardian. And he had... My dad set him up some money at a credit union, and I- we had to move it. We, once my dad passed. He set it up the wrong way, and so we were on... I had to get my brother there, in his wheelchair and everything to do that. And they still, even in person wouldn't talk to me. They had to talk to my brother, so I had to tell him what to tell them 'cause he didn't know really... it is you gotta watch out for the wrong friction though, too. Too much of it is not good. That was a such a hassle. But as we think about, you know- It's not isolated to, single departments anymore, right? It, it might have been more contact center, people trying to do it behind the scenes. We just talked a little bit about my experience at a branch, but the multi-channel a- and multi-location is real from that perspective. The, the fraud is hitting us at all those different levels. So Rebecca, when you think about that how do you really make sure that, member experience groups are able to work with all of the different, departments that now can face fraud that might not have previously?

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: I love this question because Hanscom's fraud department, as we know it today, is still a baby. We really only started centralizing in 2024, early 2024. Before that, it was so decentralized that there were dozens of emails exchanged for one fraud incident, and it's one department's, doing part of the maintenance, and the other department's doing the outreach, and it was just everywhere. So we started two working groups early on, a tactical group and a strategic group. Tactical was more day-to-day operations, and we meet weekly. We discuss cases and process improvement and things like that. Strategic group obviously focuses on strategy. But two of the most important things we did early on was we replicated all of that email traffic in a workflow in our CRM. So we created a fraud alert in our CRM. Once a fraud alert is opened by whatever business line, it could be front line, it could be lending, it could be anybody, it triggers a series of tasks that go to the back office. Deposit operations turn off remote deposit. Plastic cards get turned off by card services. Digital takes care of online access and so on. So everyone's already working on something. We also created a fraud flip workflow, so once fraud is confirmed and it's compromised enough that we have to flip a membership and create a new number, that's another workflow. So now maybe consumer lending gets involved and residential lending to move loans from one place to the other. So it's truly a team effort. Centralization and these workflows were really important. But the other thing too is training, yes, but also fraud awareness in the credit union and engagement. So due diligence at the front line, asking the right questions so important To, to know what questions to ask, how to interview a member about what they're experiencing,

Sean Albertson, Founder and CEO, CX4ROCKS: yeah, you gotta plan across all of it. So Greg, what would you add to that?

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: Yeah, to add what we've done in addition to some of those things at DCU is also set up committees, and the idea is to understand the activity and how is it impacting the credit union, and that's not just to go off and talk about attempts and losses or whatever. It's really also to look at that impact to good as well, and that's through experience, et cetera, whether they're calling in, whether they're coming into a branch or however they may be reporting a problem. The other part of that is investment in terms of how we're gonna address it. So we have what I'll call a working committee structure, which is really doing the more day-to-day, week-to-week work. And then we have an executive committee structure on top of that, which is really the comment was made about, what are your big rocks? That's exactly what we call them from a fraud perspective. We cannot solve this problem all at once today, so we've gotta be really intentional and figure out where we're gonna have the impact. So I think on top of some of the things that Rebecca talked about, really how we're managing the day-to-day impact and aspect of fraud and what's happening with the credit union.

Sean Albertson, Founder and CEO, CX4ROCKS: Chelsea, what would you add?

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: Kinda back to what Rebecca said, I know she talked about it a bit when we met the awareness of the fraud department. I was wondering for a while, "Why is fraud in every branch manager meeting?" But then I started to see that they had something new to talk about every meeting, and we have started workshops for all our frontline staff based on their focuses, and fraud comes in person and presents and shares ideas, and they've been the most popular speaker in the last workshop we had for them. And we've had people move from our different departments into the fraud team, and the fraud team has done a great job of building the relationships with our frontline so that they feel like the door is always open to come to them. And so I'll see them in our internal chat, chatting fraud. Fraud will sometimes say, "I'll jump on the phone with them right now." And it gives the employee so much more peace and just confidence to know that fraud has their back. And so- Those meetings that seemed excessive to me really built a really strong relationship between the front line and our fraud team. They're up to f- three or four people now, and they were down to two for a while, but we still caught all the fraud because our team reached right out to them, and they kept the doors open for us.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah, absolutely. W- Doug, when you think about it, the front line ends up being kinda, in many cases, that last line of defense for this. And Rebecca even talked about the training and so forth. So how do you ... what are the most important skills and behaviors and s- and training required for really that recognition and then the right action that comes out of that or needs to come out of that?

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Yeah so going along with the training we teach front-line staff, what to look for, what are those red flags, first thing is, a client's, mannerisms, are they urgent? Are they being quiet? Are they trying to rush the transaction? Are they, getting aggressive? Certain things here. Is somebody speaking on their behalf? Do, they came in with somebody else? There's certain areas there where that should raise a red flag immediately, why is this so important? Why are you moving so fast, and sometimes you may n- need to speak with the client for a moment, have it kinda slow down the pace a little bit, get some information as to, what's really going on here. It's really good to pay attention to what's going ... Also, again, going back to the transactions itself, what are they coming in with? If it's a lot of cash, you may wanna know the source of funds of that cash. Again, if it's a check from out of state or out of country, does that make sense for the client? Maybe you need to have a conversation, and the front-line staff need to know when to ask these particular questions because it can be helpful in the long run when looking at these particular cases. Those are certain areas where, we need them to, have knowledge of their customer, know their customer. We're trying to, evolve know your customer instead of just, the regular questions. We try to push the envelope a little bit, try to get some more information if necessary by using different tactics.

Sean Albertson, Founder and CEO, CX4ROCKS: And it's got ... And you gotta go deeper, too, 'cause you're not just you're not just looking out for the bad actors that are trying to come to the bank and interview with or work with you. You're also looking at those who are working through, the clients and the, the, the romantic, type of fraud and things of that nature. So Chelsea, what would you add?

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: For account opening specifically, we mentioned that middle area, and we've really had to work with our team to teach them and help them practice what questions to ask. So being able to have the confidence to ask those questions have been key. 'Cause we'll have alerts on there about their phone number or their IP address, and we've had to really role play and practice. 'Cause they feel at first asking is gonna sound offensive or they're prying too much, but we've just really had to overcome that and talk through stuff like, "Are you on your own cellphone plan or is your cellphone on someone else's bill?" Because those are red flag alerts that we see in our system that need to be addressed, and giving them those questions and specific scenarios had, has helped them really address and catch some things, and also just help ease the process and make the process easier for a few people. They've been able to answer and we move forward.

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely. Rebecca, what would you add?

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: Yeah, similar to Doug and Chelsea, actually. W- warning signs and red flags we train on them, of course. We include them in all of our trainings, and there are guidelines out there and everything. But I also feel like warning signs and red flags can be a little subjective. Like our BSA group at one point in time was made up of a lending person, a deposit ops person, a branch person. We all thought different things were suspicious for different reasons. So the skills and behaviors, I think are really important. Being able to, like you said, interview members and ask the right questions to do the due diligence, find out the nature and purpose of the membership, the nature and purpose of the transaction, and so on. Being able to escalate that activity-

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah ...

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: is important.

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely. So I'm gonna ask all four of you to really an- to answer this one, but when we ... Again we see this evolving and the risk even potentially going higher and higher in this context. Greg, let's start with you. When you look ahead, as the next several years and the threats increase how are you looking to see the, the, the customer expectations of you as their banker and you as the bank really evolves with that?

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: A couple things, Sean. First and foremost, to me, this one is about the data. What do we have for data? Can we access that data? Again back to one of the earlier presentations, are you building things? Are you buying things and so forth? Can we harness it all and can we evaluate it in a meaningful way? And there's so many layers to the data, right? So I think about it as signals. You've got sing- signals coming from people's devices. You've got identity-related signals. Now you've got behavioral signals that you can use and the confluence between those things. And we talk about other things underneath that. How is this person transacting? You can get into demographic data, et cetera, et cetera, et cetera. So can you use that and build something meaningful? The other challenge that's here is you can't... A- and I've been guilty of doing this at times over the course of my career, you cannot come at this strictly from the fraud perspective. You can't treat it as that red area, "Okay, we're focused on that," because if you do that You're gonna hammer the green area, and you're still gonna can be anywhere for the kinda amber area, right? So you haven't really solved anything. You might have picked up using those signals and done a little bit better job on the f- core fraud component, but you've made a miserable acquisition experience and made a miserable probably ongoing member experience, and so forth. So you have to evaluate and understand the fraud in the context of the wider good, and that isn't necessarily easy to do. I think that's really where the focus is. And again, whether you're building things internally, we are leveraging some custom-built models from data science inside our shop. We also have key partnerships with critical providers as well. It's kinda that balance and it's just ongoing and it's what makes it really interesting.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. Chelsea how are things evolving? What are you seeing?

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: We're having to pivot and make changes almost monthly, maybe quarterly lately. And so I think as time goes on, it'll, that pace will keep up or even get faster. And so on my end, working with fraud and working with other departments I kinda urge my team and push all of us to go big, to think big and not worry about the risk at first, and then we let fraud come in and kinda rein us back some. But we haven't really had to be reined back because we'll keep ... You have to keep pushing and asking your vendors and the solution providers, "How do you offer something else?" The other day we had some Plaid fraud in our account opening, and we wanted to raise the Plaid limit, and I was like, "Plaid was supposed to be safe. How did $20,000 just get returned?" I did some copilot research, and then we asked our vendor back, "Do you ha- have the safer version of Plaid, this one that will scan the member's information against the information on that bank account, not just verify the bank account and the money's there?" And they're like, "Yeah, you can upgrade for a few dollars a scan." We're like, "Yes, we want that." And so if we didn't ask, nobody was offering it to us. And i- in some, at some institutions or just some people on the team would be like, "Lower the Plaid funding limit." We don't wanna lower the Plaid funding limit. We wanna make the account opening experience seamless. We don't want someone to have to wire the money in if it's in their account and Plaid verifies it. So we added that on just last week, and that was something that came about when that fraud happened. And so we're learning now to be more proactive and ask the vendors, "What else do you offer that you didn't present to us?" Because it's just something you have to do almost monthly now and keep up with the newsletters that come out from each vendor because you have to keep adjusting too, 'cause people find new ways to scam people all the time, and we don't wanna just shut down or lower our limit all the way down when there's other tools and resources out there.

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah. Rebecca?

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: Yeah, I, it's funny having spent 10 years now in risk management, I can't do anything without a risk assessment. I can't do anything without some type of a risk analysis. Anything. It drives my husband crazy. My kids are learning all about it. But I go back to that. It's, it's-

Sean Albertson, Founder and CEO, CX4ROCKS: Your kids wanna go out and you're like, "All right, we need to do a risk assessment."

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: Yeah. Oh yeah. I'm in compliance too, so my daughter read the whole Chromebook agreement with me before she signed it. But yeah, I just go back to it's risk-based. You want it to be more seamless and easier for the legitimate people, members, and more difficult for the fraudsters, but we just have to keep evolving with, AI-driven tools and supports and biometrics and all those things. It's-

Sean Albertson, Founder and CEO, CX4ROCKS: Yeah ...

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: we're getting into all of it.

Sean Albertson, Founder and CEO, CX4ROCKS: Doug, what would you add?

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Yeah it's gonna be a layered, authentication situation. Whether it's, IDs using multiple factor I- authentication as well as data monitoring cross, department monitoring of transactions, especially if they're a newer client. We're starting to do more real-time processing, which I think will be beneficial to us 'cause right now it's mostly ACH wire, but not checks and ca-... it takes a little bit of time. So the quicker we can get the data, the better. I think we can react quicker to certain things. 'Cause there's not one certain control that can just eliminate fraud. You gotta have multilayers there to kinda help, get to it as quickly as possible.

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely. I know I closed yesterday talking, and part of my message was reinforcing journey mapping, something that's been around for 30 years but, not everybody does anymore. And it's so important to really map that out 'cause y- it... Fraud is not a step in a journey, it's its own journey, from the complexity. And to be able to balance that out you've gotta see it from the customer's perspective, but also see the risk in there from that perspective. You almost have two different personas, the fraudster and the, the regular, the real customer and s- and so for really balancing that out.

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: Can I go back to-

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely ...

Gregg Stephens, Director, Fraud Analytics, First Technology Federal Credit Union - DCU Division: just real quickly, Sean, to something that Chelsea had said, which is that... A- and it kinda goes back to the earlier topic on communication and partnership internally on these things, right? She had made the comment a little bit about inviting fraud in at some point. Make that a partnership. This probably pertains more to Rebecca, Doug, and I as the kind of fraud people, but please invite us, and especially when you're talking about new products, new services, or even changes to existing things. Look we're not... We're fun. We are good to hang out with, okay? We don't bite. How many times have the two of you picked something up or heard about something and went, "W- wait, what just went live?" And there was never a conversation about it from a fraud risk perspective. And again, the idea is we'd like to come in, we'd like to understand what the approach is. Yes, we wanna give guidance. At the end of the day we'll make a business decision. Maybe we go far with fraud and risk controls, and maybe we don't, but let's do it eyes wide open and not in a vacuum.

Sean Albertson, Founder and CEO, CX4ROCKS: Absolutely. So I wanna open up for questions for this audi- Again, hot topic, so I'm expecting some questions. So who's got a question for our panelists? Oh, in the middle back here.

Audience Member: Coming to you with a mic. All the way over left.

Audience Member (2): Thinking about the, the theme of balancing fraud and friction and the member experience we're a CDFI, and one of the things that we regularly see is that especially in the new account acquisition period people lie to you. Right? They lie to you for all kinds of reasons. They tell you what they think you want to hear rather than what is really going on with them. And so I'm wondering how you help your staff identify that this is a bad actor and this is just someone who's got something they're hiding, and there's two different people there. One of them is fraud, the other one is just a challenging consumer.

Sean Albertson, Founder and CEO, CX4ROCKS: Who wants to take that one? That's a tough one.

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: I'll go.

Sean Albertson, Founder and CEO, CX4ROCKS: Go. Go ahead, Doug.

Douglas Bolton, AVP, Senior Fraud Prevention Officer, Cape Cod 5 Bank: Oh, okay. I was ... it can be a difficult situation and conversation to have, especially if you have a client that's, complicit with the activity and not really quite understanding that, essentially they're an unwitting mule or a witting mule 'cause they've gotten so far into it, they're really in hopes that this is actually occurring. Maybe they've won the lottery and have to pay funds to get the rest of it back 'cause they have to put taxes on it. But you, y- you try to ask the right questions. Sometimes if you can stall them for a moment, let them think. We have a lot of documentation if it's wire or cash out activity, where we ask specific questions on the form that we have our frontline staff go through with the client. And the hopes of the having those there allows maybe that particular client to think about what they're doing for a moment. "Oh, was I asked to go to a Bitcoin ATM machine after this?" "Was this a shopping scam?" "Am, am I talking to somebody on the phone, that I think that I know, but I haven't really, spoken to in person, it's all been online or via email?" Those certain things you kinda try to put in their head, and hopefully they think about it and decide not to do the transaction. The goal is to maybe have them wait a day and be like, "Hey, why don't you come back after thinking about this," and then kinda go from there. Sometimes you- we do a lot. We contact the client ourselves from our department. We'll have the banking center call the client afterwards just to have a conversation. And sometimes there is points where you've done what you've done, and they ... there's only so much you can do, unfortunately. And those are difficult conversations to have, but, they're You ... There's only so much, as far as I can do it.

Sean Albertson, Founder and CEO, CX4ROCKS: Another question. All right. We have one more here. Oh.

Audience Member (3): First of all, I can confirm that Greg can be fun. But also very similar to the question that just happened just came up recently. So we ... We're seeing a lot of members coming in asking for large amounts of cash, like 40, $50,000 in cash. And we're training our branch teams to ask more questions, and sometimes they get a little bit defensive, and they don't wanna give us the background. But we've run into things where they said, "No I'm buying a car," and then they find out later on that the car doesn't exist. So I'm w- curious if there's any other institutions that are doing s- seeing something similar to that, and how do you combat that when the member is really feeling that it's completely legitimate, and they're getting scammed through the whole thing. But they also will not take a check. They just r- refuse to do that. They want the cash.

Rebecca Neumeier, VP, BSA & Fraud, Hanscom Federal Credit Union: Yeah, we def-- we, we've had a couple of cases like that recently. We ask for additional documentation basically. Like we-- What we hope is that the training and the awareness that we're spreading in the credit union is effective and that the, the representative's gonna stop for a second and say, and start asking questions about the transaction. But like for a wire transfer recently, a member was convinced this wire was legitimate. He's buying a property in another country. We asked for a purchase and sale. He didn't have a purchase and sale. He didn't have a signed agreement, nothing on file. So we got him to think about it a little bit, and ultimately he actually ended up just stop calling us. But that one ended naturally. But yeah, just asking for more documentation requesting supporting documentation of the transaction has been effective.

Chelsea Gstohl, Senior Vice President, Member Experience, Pelican State Credit Union: And our branch managers, most recently we helped somebody realize something was fake 'cause they asked to call the person and get on the phone with them, and as soon as she said who she-- our branch manager said who she was, they hung up, and that kinda opened the member's eyes. We had another one the other day with a vehicle. He refused to believe us, and he ended up losing the money. But we had it all documented, so it was on him, but the branch fought and fought with him, and they tried all their tricks, and it didn't work. And so sometimes we win and sometimes it turns out not fun for anyone. But getting on the phone I think has been a good tip to help. "Hey, can you call them, and let's talk to them together?" And that kinda spooks them a bit.

Audience Member: Good one.

Sean Albertson, Founder and CEO, CX4ROCKS: We are at time. So I wanna thank the panelists. Help me thank them for a great topic. Thank you so much.