The fraud baseline: what SBP banks actually face
دھوکہ دہی کی بنیاد: SBP کے بینک حقیقت میں کس چیز کا سامنا کرتے ہیں
35 min read
Three ways to see it
Fraud at a Pakistani bank is not one thing. It is a family of distinct attacks, each with its own attacker, its own victim, its own data trail. Treating them as one blurry category is the most common mistake of new compliance officers. Before you can build any AI defence, you must be able to name the species. There are six that account for over 90 percent of SBP-reported fraud loss: social engineering of customers (the OTP scam above), card-not-present fraud on debit cards used at international merchants, account takeover through credential stuffing, internal fraud by branch staff, money laundering layering through Raast and 1Link rails, and trade-based money laundering through over-invoicing of imports.
The cost is not abstract. SBP's 2025 Payment Systems Review noted PKR 4.78 billion in reported digital fraud losses, with the actual figure widely believed to be 3-5x higher because of underreporting. The average customer-facing fraud incident at a top-tier Pakistani bank now costs roughly PKR 180,000 in direct loss, plus an estimated PKR 60,000 in investigation and remediation cost. Multiply by the number of incidents per branch per month and the figure dwarfs the cost of any monitoring system you would ever propose. The economic argument for AI-based monitoring is already won. What remains is the engineering and the governance.
Look at each species through one shared lens: who is the attacker, who is the victim, who has the data, and who carries the regulatory liability. In OTP social engineering, the attacker is external, the victim is the customer, your bank holds the transaction data, and under SBP's Consumer Protection Framework 2024 your bank carries the liability if you cannot demonstrate the customer was warned and the controls were reasonable. In internal fraud, the attacker is your own teller, the victim is your bank, and the data trail is in your own core banking logs which only you can access. The defence stack for each looks completely different. A monitoring system that confuses the two will fail both.
Quick check
Quick check: what makes modern AI different from a rule-based program?
The why-tree
Why-tree level one: why is digital fraud growing faster in Pakistan than the developed-market average? Because Raast onboarded 50 million users in 36 months, while consumer financial literacy, telco SIM verification rigour, and bank fraud-team headcount grew at a fraction of that pace. Volume of new digital users always outruns the institutional muscle to protect them.
Try this with Claude
AI-edge prompt: 'I run AML for a mid-tier Pakistani bank with PKR 600 billion in deposits, 220 branches, 4 million retail accounts, and roughly 15 million transactions per day across Raast, 1Link, card, and internal rails. Estimate my expected annual digital fraud loss using SBP-published 2025 base rates, broken down by the six fraud species. Show your assumptions and tell me where your estimate is most likely to be wrong.' Compare the model's estimate to your actual loss line and note the gap.
Sources
Sources and further reading. SBP Payment Systems Review 2025 (sbp.org.pk/PS/PDF). SBP Framework for Risk Management in Outsourcing Arrangements 2017. SBP Consumer Protection Framework 2024. SBP Branchless Banking Regulations. FATF Mutual Evaluation Report on Pakistan 2019 and follow-up reports. FMU Pakistan Annual Report 2024. State Bank circular FD-02/2023 on digital fraud reporting. ACFE Report to the Nations 2024. World Bank Global Findex 2024 Pakistan section.