Fraud and compliance vs growth in European FinTech

Published
September 18, 2026
Author
Writer
TL;DR
  • EEA payment fraud losses rose to €4.2bn in 2024 from €3.5bn — at a fraud rate of just ~0.002% of value. Volume, not rate, drives the cost.
  • ~85% of credit-transfer losses fall on users who authorised the transfer themselves. Rules miss this; behaviour and context don't.
  • Instant payments, mandatory since 9 October 2025, cut the decision window from days to seconds.
  • AMLA took over AML/CFT supervision in January 2026, with direct oversight from 2028. 70% of authorities see rising ML/TF risk in FinTech.
  • Scaling risk by headcount raises cost linearly. Shared data across growth and risk doesn't.
  • Measure risk-adjusted CAC: CAC + fraud losses + compliance cost + revenue lost to false positives.
Make summary this article with AI:

The growth-risk trade-off

European FinTech is entering a phase in which technology and capital no longer set the main limits on growth. Companies need to grow their customer base while controlling fraud, AML/CFT, and operational risk.

Here is the tension: the faster a FinTech acquires customers and increases transaction volume, the more exposure it carries to fraud and financial crime. Tight controls create a different cost — they add friction, push up acquisition costs, and lower conversion.

European FinTech companies need a growth system that includes compliance and risk from the start.

Risk must become part of the growth infrastructure.

Key market figures

The EBA–ECB report on payment fraud shows that absolute losses are increasing even though fraudulent transactions remain a very small share of total payment volume. The lesson is simple: a low fraud rate still creates a higher cost of risk as transaction volume grows.

Fraud is moving to the customer

The traditional fraud prevention model centred on one question: “Is this transaction suspicious?” The new model must answer a different question: “Who initiated this transaction, and do they understand what they are doing?”

Around 85% of credit-transfer fraud losses were borne by payment service users, mainly because users were deceived into initiating fraudulent transfers themselves. If a scam does not involve a system breach or an authentication bypass, transaction rules alone miss part of the picture. Companies need to analyse:

  • user behaviour;
  • device;
  • geography;
  • transaction history;
  • changes in behaviour over time;
  • recipient;
  • the relationship between payer and payee;
  • previous communications;
  • anomalies in the customer journey.

AI and behavioural analytics can add more value here than a longer list of rule-based controls.

Fraud is moving to the customer

What the business wants
What the risk team wants
More customers
More KYC
Faster onboarding
More checks
Less friction
More transaction monitoring
More transactions
More manual review
More revenue
Fewer false negatives

When a FinTech reduces friction too far, fraud and regulatory exposure increase. When it adds too much friction, conversion, activation, customer satisfaction, transaction frequency, and revenue fall. Risk therefore cannot be managed separately from growth.

Tighter European regulation

On 19 January 2026, the EBA and AMLA announced the completion of the transfer of all AML/CFT mandates and functions from the EBA to AMLA. AMLA's published timeline schedules the selection of 40 obliged entities during 2027 and the start of direct supervision in 2028.This brings a more unified European standard for enforcement. For FinTech companies, weak compliance will carry a higher cost, especially during cross-border expansion.

Regulators see the same conflict

In its 2025 Opinion and report on ML/TF risks, the EBA reported that 70% of competent authorities saw high or rising ML/TF risk in the FinTech sector. It also points to weak AML/CFT controls and governance and notes cases where firms prioritised customer acquisition over compliance.

The message is direct: FinTech growth can outpace the risk infrastructure that supports it.

The cost of traditional risk models

When risk infrastructure scales only by adding more employees, costs rise in a linear way: more customers → more alerts → more manual reviews → more compliance staff. This creates structural pressure on margins.

The EBA's Spring 2026 Risk Assessment Report identifies fraud as the second most relevant contributor to operational risk. Fraud risk stood at 52% agreement in the EBA's risk assessment questionnaire and has risen sharply over the past three years. Banks are using automation and digitalisation to manage costs, creating an opportunity for FinTech and RegTech.

AI connects growth and risk

A useful model connects fraud, compliance, growth, and data in one Risk Intelligence system. It receives signals from growth and risk systems at the same time.

For example, a system may detect that one acquisition channel brings customers with high onboarding conversion but also an unusually high fraud rate. Traditional marketing will see CAC ↓ and Conversion ↑. Risk will see Fraud ↑. An AI-driven system should see that CAC remains effective only until expected loss and compliance costs are included.

Companies should manage “Revenue − CAC − Expected Fraud Loss − Compliance Cost − Operational Risk Cost”, rather than “Revenue − Marketing Cost”.

Risk-adjusted CAC

Traditional CAC leaves out the costs that risk creates. A more informative measure is:

Risk-adjusted CAC = CAC + expected fraud losses + additional compliance costs + the cost of false positives

The last component matters. When a system blocks customers too aggressively, a FinTech loses legitimate revenue. When the system is too permissive, the FinTech carries fraud losses and regulatory risk. The right system minimises total risk cost while balancing fraud losses and false positives.

The cost of false positives

Compliance can also cost a company its good customers. When someone goes through extra checks several times, waits for a transaction, runs into an unexplained block, or cannot finish onboarding quickly, the company loses more than customer experience — it loses LTV.

A modern risk engine must therefore answer more than “Whom should we block?” It must also answer “Whom can we safely allow to do more?” This is a shift from defensive compliance to risk-based growth.

Europe’s new risk infrastructure

  • Instant Payments Regulation accelerates payments and introduces Verification of Payee.
  • AMLA is creating a unified European approach to AML/CFT supervision and enforcement.
  • DORA strengthens requirements for operational resilience, ICT risk, and third-party dependencies. The EBA also points to the financial sector’s growing dependence on major cloud and payment service providers.

The result is faster payments, tighter controls, more data, and greater responsibility for European FinTech companies.

What FinTech needs to change

The next advantage will go to companies that can deliver high conversion, low fraud, low false positives, fast onboarding, and regulatory evidence at the same time. Growth, fraud, compliance, and data/AI need to work together:

  1. Growth
  2. Fraud
  3. Compliance
  4. Data/AI

These functions need to share the same decisions and evidence.

What comes next

Companies now need risk infrastructure that supports growth. Fraud will keep adapting to new technologies and the rise of instant payments. AI will help fraudsters scale social engineering and automate attacks, while giving financial organisations more behavioural signals to analyse in real time. The EBA's recent risk assessment also highlights AI-enabled fraud among the operational risks facing the financial sector.

The next stage of FinTech development turns on a different question: How can a company attract more of the right customers, activate them faster, increase transaction volume safely, and keep fraud and compliance costs under control?

Growth without risk becomes too expensive. Risk without growth becomes too slow. Risk-adjusted growth wins.

European FinTech companies now need to treat fraud and compliance as part of their growth architecture.

Sources

Figures and regulatory dates were checked against official publications available on 15 September 2026. The payment-fraud figures in Key market figures come from source 1; payment-volume figures from source 2; the instant-payments deadline from source 3; and the AML/CFT and operational-risk claims from sources 4–8.

  1. EBA and ECB, Joint EBA–ECB report on payment fraud: strong authentication remains effective but fraudsters are adapting (15 December 2025)
  2. ECB, Payments statistics: first half of 2025 (29 January 2026)
  3. European Commission, New EU rules make instant euro payments faster and safer (10 October 2025)
  4. EBA, A careless use of innovative compliance products can lead to money laundering and terrorism-financing risks (28 July 2025)
  5. EBA, Risk Assessment Report — Spring 2026
  6. AMLA and EBA, EBA and AMLA complete handover of AML/CFT mandates (19 January 2026)
  7. AMLA, About AMLA — timeline for direct supervision
  8. European Union, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
Have a similar project in mind?
Let’s discuss it on a free consultation call
Contact Us
Portraits of three people with light skin tones against a white background: a man with short dark hair and a neutral expression on the left, a woman with long straight dark hair and a slight smile in the center, and a man with short dark hair and a beard smiling on the right.

Progress
50%

Related articles prompted by Goodface