A version of this article first appeared in the June BAI Executive Report: Reimagining talent, training & culture in banking. In the issue, find more on topics that span efficient customer engagement training, leveraging marketing team resources with AI, and more.
Financial services, and especially banking, are highly regulated, risk-sensitive industries facing increased pressures from fraud threats, including internal breaches. Couple this with combined remote, hybrid and in-office workforces, a more complex roster that may not always be under the watchful eyes of leadership.
While every institution wants to believe they’ve onboarded dependable employees with only the bank and its customers’ best interests in mind, and certainly exhibiting above-board behavior throughout their career, more banks are rechecking and re-fingerprinting existing employees as a preemptive measure. Some bank boards are already requiring this practice.
Indeed, internal fraud accounts for an estimated $3.1 billion in total losses at
organizations around the globe — with the financial services industry reporting the most cases, according to a 2024 report by the Association of Certified Fraud Examiners.
Some of the more common internal fraud, according to Abrigio, includes account manipulation, transaction reversals, account takeovers, loan application fraud, general ledger fraud, employees working together to override controls, as well as unauthorized access and misuse of sensitive customer information. There are also unauthorized system modifications that facilitate fraud or grants access to a non-IT employee who can then approve a fraudulent transaction, and employees manipulating credit lines for unauthorized use.
Suspiciously staying put?
Some banks have started rechecking and re-fingerprinting existing employees when prompted by concerns that individuals have passed up clear opportunities for advancement both internally and externally. Instead, select employees may appear to be nefariously leveraging the continued access granted from of a current position or don’t want to make a jump because they know their records aren’t clean, says Sylwia Czajkowska, associate director for Organizational Risk Management/Enterprise Risk Management and Peer Sharing, Events & Risk Products at ProSight.
Czajkowska says that while employees may have a range of legitimate reasons for sticking with the comfort of existing roles, questions emerge: Why are they not leaving the bank and looking for other opportunities? Is it because they know they would not pass a background check elsewhere? Why are they shunning promotion?
What about other behavior? Did the staff member not attest to an incident for the current financial crimes department? In general, would any factors emerge during a fresh look and that’s why they feel more secure staying in place instead of going somewhere else?
Rechecking and re-fingerprinting existing employees have gained ground because of heightened risks of potential fraud and other suspicious criminal activities, particularly since technology and artificial intelligence use have intensified, Czajkowska says.
“The large banks are starting these practices, and I think the rest will follow suit, especially if that topic is being shared as a best practice in peer-sharing events,” she says.
At a recent ProSight Culture and Conduct Risk Roundtable, bank HR and risk managers expressed the growing demand for these practices because the threat is real. However, they are also sensitive to the awkwardness, legal and protection considerations, and the desire to preserve a positive culture in the workplace.
Know an individual’s rights, including authorization
Edge Information Management Inc., an international provider of employment screening services based in Melbourne, Fla., recommends that any post-hire background screening policy should indicate which positions will be screened, what specific searches are required, and why these searches are required.
“Of course, the employment background screening company can facilitate the screening, but you also need to know the rights and legal obligations to protect consumer rights, and consumer privacy, and to remain in compliance,” Edge consultants say. “Consumer rights include providing a disclosure and obtaining authorization before screening. In addition, there are employer obligations to follow pre-adverse and adverse action procedures.”
At the recent ProSight peer-sharing event, participants shared what is happening in the industry, Czajkowska says.
Some banks start with rechecking high-risk-job individuals, she says. Executives are being re-checked every three years, and some international banks are rechecking on an annual basis. Importantly, even if banks conduct background checks today, that doesn’t mean an incident might not happen tomorrow, Czajkowska says.
“Having continuous monitoring of key personnel helps banks be more secure that they engage with good practices, and that from a reputational-risk standpoint, they won’t be surprised with any event coming to the surface or being reported in the news,” she says.
If banks let existing employees know that multiple positions will be rechecked and re-fingerprinted periodically as a standard policy, then employees will be less likely to take offense because they’ll know that they personally were not singled out, Czajkowska says.
Maintaining internal watchlists among existing employees is also a good idea, she says. Sometimes employees apply for a position in another department, but the new hiring manager might not be aware that this person was already with the institution, and that certain behavior was flagged.
“Maybe there was an agreement between the bank and that person to not do further investigation if the person just voluntarily left the bank,” Czajkowska says. “So the bank should have then noted on an internal watchlist that if the person applies for a different role, they should either not be rehired or alternatively, they could be rehired on a probationary basis with restrictions, depending on the rules.”
Since background checks and fingerprinting only detect reported incidents and crimes, banks should also look for signs of potential abuse, according to ACFE’s 2024 report.
“Perpetrators of occupational fraud often display distinct behaviors while carrying out their fraud schemes,” the report’s authors write. “These behaviors can serve as red flags, potentially indicating the existence of fraud when observed.”
Signs that can warrant fresh scrutiny
The most common behavioral red flag cited by ACFE was living a lifestyle beyond known income sources, followed by experiencing financial difficulties, and having an unusually close association with a vendor or customer.
Other behavioral red flags include divorce or family problems; bullying or intimidation; a “wheeler-dealer” attitude; irritability, suspiciousness, or defensiveness; control issues, unwillingness to share duties; and refusal to take vacations, among other behaviors.
“We also asked survey respondents whether perpetrators experienced any job-related circumstances that might influence their decision to commit fraud, which we refer to as human resources–related red flags,” the authors wrote. “These include a fear of job loss, actual job loss; poor performance evaluations; a demotion; being denied a raise or promotion; and cuts in benefits, pay, or hours.”
Safety and security initiatives are built to protect the institution and its customers, to meet regulatory requirements, and create a sound environment for all employees. Effectively communicating these goals, operating within the law and handling these potentially sensitive exchanges with the utmost professionalism will be key to creating and maintaining the positive culture you want your employees to thrive in.
Katie Kuehner-Hebert is a contributor to BAI.