News

Vivox AI at the 6th Financial Innovation Forum: Tim Khamzin to moderate the panel on AI agents in FinCrime

Learn more
All

Before the payment: where AI can make the difference in stopping scams

A payment can look legitimate even when the customer authorising it is being manipulated. At QUBE Events’ Financial Innovation Forum in London, financial crime leaders explored how AI, behavioural intelligence and human judgement can help stop scams before the money moves.

A payment may look legitimate even when the person authorising it is being manipulated. The account name matches. The customer insists they know the recipient. The bank’s warning is dismissed.

The transaction itself may be valid. The story behind it is not.

This gap between an apparently legitimate payment and a customer acting under a scammer’s influence shaped the discussion at QUBE Events’ sixth Financial Innovation Forum, Payments & RegTech, held in London on 17 September 2026.

Tim Khamzin, founder and CEO of Vivox AI, moderated the panel “AI Agents in FinCrime: Real-Time Scams Defence, Investigations and Governance.”

He was joined by:

  • Natalia Gburzyńska, Deputy MLRO and Senior Financial Crime Compliance Manager at Revolut;
  • Pallavi Kapale, Senior Financial Crime Officer, FIU, at Bank of China (UK);
  • John Sudbury, Threat Intelligence Lead at Wise; and
  • Anne Markey, Managing Director at Alvarez & Marsal.

The panellists spoke in a personal capacity. Their central challenge went beyond identifying suspicious transactions: how can financial institutions recognise the manipulation behind a payment and intervene while there is still time?

Break the scammer’s momentum

Scam victims are not simply naïve. Fraudsters exploit trust, fear, distraction and other human responses, creating emotional pressure that can override otherwise sound judgement.

Natalia Gburzyńska described scammers as “emotional illusionists” and highlighted urgency as one of their most effective tools.

“Urgency is the absolute enemy of due diligence.”

That observation has practical implications for fraud controls. A warning delivered after a customer has become emotionally invested in a transaction may have little effect. In some cases, introducing a delay of a few hours could interrupt the scammer’s momentum and give the customer space to reconsider.

Interventions must also account for coaching. Fraudsters often prepare victims to answer banks’ standard questions, making predictable controls easier to bypass. An unexpected question, including whether anyone has instructed the customer to conceal information or mislead the bank, can disrupt that script.

For complex investment or romance scams, an automated notification may not be enough. An empathetic conversation with a trained member of staff may be necessary to help the customer recognise what is happening.

A matching account name does not explain the payment

Confirmation of Payee and similar beneficiary checks are important, but a name match cannot establish that an investment is genuine, a relationship is real or the stated purpose of a payment is truthful.

Pallavi Kapale illustrated this distinction with a case from her previous work. A woman travelling in Spain wanted to transfer money to someone she believed was her boyfriend, a member of the military who said he needed funds for flights. By the time the receiving account was examined, the customer had already lost £65,000 over six months.

The intervention required difficult conversations and temporary restrictions on the customer’s access to her account while she was abroad. The case showed why scam prevention depends not only on detecting anomalies, but also on having trained frontline teams who can explain an intervention and support someone confronting a painful reality.

Move detection earlier in the sequence

The transaction is often the last opportunity to prevent harm.

John Sudbury discussed kill-chain mapping: tracing the sequence of events leading to an attack and identifying where it can be interrupted. Applied to scams, this means looking beyond the payment itself to changes in customer behaviour before the transaction is initiated.

Potential signals could include unusual interactions with a banking app or changes in the cadence of a customer’s voice during a telephone payment request. Analysing behavioural signals alongside transaction data could help institutions recognise when an apparently authorised payment is being made under manipulation.

Kapale offered another example of why a longer observation window matters. Money mules may send £1 test payments to several accounts and then leave them dormant for months. A later £2 transaction can be used to confirm that an account remains active before a much larger transfer follows.

Individually, those payments appear insignificant. Viewed as a sequence, they tell a different story. Effective detection therefore depends on connecting events over time, not assessing each transaction in isolation.

Combine controls instead of relying on a single check

No single signal can reliably determine whether an interaction is genuine.

Anne Markey argued for combining authentication, behavioural intelligence and transaction analysis. Establishing that a person resembles the expected customer is only one part of the task. Institutions must also determine whether the interaction is live and genuine, and whether the verification process itself has been compromised.

Biometrics, liveness tests, IP data and controls against injection attacks all contribute different pieces of evidence. Assessed together, they can help determine whether a payment should proceed, be stopped or trigger additional authentication.

Markey also recalled introducing machine learning for payment anomaly detection at UBS in 2012. Transaction analytics are not new to banking. The next step is to incorporate broader behavioural evidence and coordinate the response across multiple controls.

Automate the work, but retain responsibility for decisions

AI agents can support transaction monitoring, screening, rule tuning and the preparation of suspicious activity report narratives. The panel nevertheless drew a clear distinction between producing analysis and taking responsibility for a consequential decision.

“AI supports judgement, but it doesn’t replace the judgement.”

The operating model proposed by Gburzyńska was straightforward: AI detects and explains; a human reviews; action follows. An institution cannot adequately justify a decision by saying only that an AI system recommended it.

Kapale described a spectrum of human involvement, from using AI as a tool through collaboration, consultation and approval, to observing autonomous activity within defined limits. Moving directly to an observer role would be premature for sensitive decisions involving suspicious activity reports, sanctions or customer exits.

Markey added that segregation of duties must also apply to AI agents. When software performs operational work, initiation and approval should remain separate. The same discipline is needed when sensitive information is released.

Look beyond defence to the criminal operation

Sudbury broadened the discussion beyond internal bank controls. Capabilities that once required specialist technical knowledge can now be bought as services on platforms such as Telegram. Financial institutions must operate within governance and regulatory constraints, while criminals can adopt new technology without those safeguards.

AI therefore has a role not only in detecting individual attacks, but also in supporting intelligence gathering, identifying those coordinating them and enabling closer cooperation with law enforcement and industry partners. Detecting an attack more efficiently does not, by itself, dismantle the operation behind it.

The real test: can we intervene sooner?

In the case described by Kapale, the customer had already lost £65,000 before the receiving account was examined. Many of the measures discussed by the panel: behavioural signals before the payment, questions a fraudster has not rehearsed, a short delay and an empathetic human intervention are designed to recover some of that lost time.

That creates a useful test for every fraud-prevention system: does it shorten the gap between the first warning sign and an effective intervention, or does it merely document that gap more thoroughly?

At Vivox AI, we believe automation in financial crime compliance must be explainable, auditable and governed by clear human accountability. AI agents should connect evidence, accelerate investigations and make their reasoning reconstructable while leaving consequential decisions with the people responsible for them.

The objective is not automation for its own sake. It is earlier insight, better-informed action and stronger protection for customers before the money moves.

Conclusion

Stopping scams earlier requires AI to connect behavioural, identity and transaction signals, supported by governance that keeps every decision explainable, auditable and under meaningful human oversight. The goal is not automation for its own sake, but faster, accountable action before the money moves.

In 2026 it won't be the most impressive models that win, but the outputs that hold up in front of an auditor. On scams that bar is higher still. The explanation has to work for the customer too, in the moment, while they still believe the scammer.

From the blog

The latest industry news, interviews, technologies, and resources.

Vivox AI at the 6th Financial Innovation Forum: Tim Khamzin to moderate the panel on AI agents in FinCrime

Vivox AI is sponsoring the 6th Financial Innovation Forum – Payments & RegTech on 17 September 2026 at the Montcalm Hotel Mayfair, London, where our Founder and CEO Tim Khamzin will moderate a panel on AI agents in financial crime prevention.

all

How TELF AG Accelerated Global Due Diligence with AI-Powered Adverse Media Screening

TELF AG, a global commodities trading business operating across multiple jurisdictions, partnered with Vivox AI to automate adverse media screening and due diligence investigations. The result: case review times cut from 60 minutes to as little as 10–15 minutes, with broader global coverage and risks uncovered that traditional providers had missed.

all

How Vivox AI is putting AI agents to work in compliance

Vivox AI Founder & CEO Tim Khamzin joined RegTech Analyst to discuss how agentic AI is reshaping financial crime compliance, and why the future of compliance operations lies in trusted, explainable AI agents rather than fragmented tooling. The conversation explores AI governance, auditability, operational scalability and the growing compliance gap facing regulated financial institutions today.

all