Fraud
Pronunciation: FRAWD
Definition
Fraud is intentional deception, concealment, or abuse of trust used to obtain money, assets, access, services, or another improper benefit. Fraud must be assessed using the actor, deception or abuse method, payment stage, affected party, behavioral and transaction signals, and potential loss or dispute outcome. Controls for Fraud combine identity and device evidence, velocity and value rules, behavioral models, step-up review, merchant procedures, and post-payment monitoring.
Overview
Fraud involves deliberate misrepresentation or dishonest conduct that causes or risks loss to another party. It can target payments, accounts, identity, refunds, investments, insurance, credit, employees, merchants, customers, or digital assets.
Methods include social engineering, forged documents, account takeover, collusion, false disputes, manipulated transactions, insider abuse, synthetic identities, and deceptive business claims. Exact legal definitions, required intent, and evidentiary standards vary by jurisdiction and offense.
Organizations should prevent avoidable opportunities, detect anomalous behavior, investigate fairly, preserve evidence, recover losses where possible, and report as required. Controls must distinguish suspicion from proof and provide review paths because aggressive automation can harm legitimate users. Control owners should track both attempted and realized loss.
In practice, Fraud should be evaluated with security and risk so preventive controls, risk decisions, and response evidence remain connected.
Fraud is intentional deception, concealment, or abuse of trust used to obtain money, assets, access, services, or another improper benefit. Fraud management combines prevention, detection, investigation, evidence, recovery, and fair decision-making rather than relying on one score or rule.
Operational review of Fraud should reconstruct the use of of trust used to obtain money, assets, access, services, or another improper benefit using the identities, communications, devices, and transaction records available for the affected case. Investigators should separate confirmed facts from hypotheses about of trust used to obtain money, assets, and access, preserve the original evidence, and document why the event was cleared, escalated, or treated as a loss. Containment, recovery, and customer communication for the fraud pattern should match the harm indicated by of trust used to obtain money, assets, and access.
Key Takeaway
Fraud management combines prevention, detection, investigation, evidence, recovery, and fair decision-making rather than relying on one score or rule.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)