If you asked most people where a bank’s fraud budget goes, they’d guess software. Machine learning models, monitoring platforms, detection engines humming in the background. That guess would be wrong, and not by a small margin. Industry estimates put average Tier 1 fraud spend at roughly half a billion dollars a year, and by some estimates, up to 95% of that budget goes to people rather than tools. Analysts, reviewers, and escalation teams, working flagged transactions one at a time, all day, every day.
Once you look at where that money actually goes, the ratio stops being surprising and starts looking inevitable.
Detection was never the hard part
Transaction monitoring already works. Ask any fraud and risk team and they’ll tell you the same thing: the alerts come in fine. Modern monitoring systems are good at their one job, flagging the transaction that doesn’t fit the pattern, and that job has largely been solved for years.
The hard part starts after the flag. A payment gets pulled for review, and now the bank has seconds to decide what to do with it, at scale, without wrecking the customer experience and without quietly bleeding headcount into a queue that never stops growing. That’s the part of the fraud stack nobody has actually fixed. It’s also the part that quietly eats the other half of the budget nobody talks about at the board meeting.
Two options, and neither one really works
Right now, once a payment is flagged, a bank has two paths in front of it, and both come with a real cost.
The first is step-up authentication: asking the customer to confirm they are who they say they are. That works well for account takeover, where someone other than the customer is trying to move the money without their knowledge. But it does nothing for a scam, because in a scam the customer is the one sending the payment. They believe it’s legitimate. They authorized it themselves. Asking them to re-verify their own identity doesn’t surface the one fact that actually matters, which is that they’ve been deceived about who’s waiting on the other end.
The second option is escalating to a human reviewer, and this one genuinely works. A trained analyst can catch what step-up authentication never will. The problem is that it doesn’t scale. Flagged volume keeps climbing as real-time payments and faster rails push more transactions into the review queue every quarter, and analyst headcount can’t climb at the same rate. Hiring and training a reviewer takes months. Transaction volume moves in real time. That gap only widens.
So fraud operations end up being a staffing problem wearing a technology budget. The tools were never the constraint. The people are, and the queue behind them keeps getting longer.
The missing piece is resolution, not detection
This is the gap PayVerify was built to close. The moment a payment gets flagged, PayVerify delivers a real, verified answer about the party on the other end of the transaction, before the bank has to choose between adding friction or adding headcount. Confirming who is actually behind the payment lets a flagged transaction resolve itself on the spot, without another prompt landing in the customer’s inbox and without another analyst getting pulled off whatever they were already working on.
That’s a fundamentally different capability than another layer of monitoring. Monitoring already does its job. What’s been missing is a way to close out what monitoring finds, at the speed the volume actually demands, without treating every flagged transaction as either a customer inconvenience or a staffing cost.
What the ratio could look like instead
If flagged payments could resolve themselves in real time, that 95% figure wouldn’t hold up. Not because banks would suddenly need fewer people who care about fraud, but because the people they already have could spend their time on the cases that genuinely need human judgment, instead of working through a queue that grows faster than headcount ever will.
That’s the question worth bringing into the next budget cycle. How much of that half a billion dollars is paying for detection the bank already has, versus resolution it still doesn’t?




