Resources / Blog · Fraud & Risk
Blog · Fraud & Risk

First-Party Fraud Is a New-Account Decision, Not a Transaction Alert

First-party fraud prevention starts at account opening, not transaction monitoring. How CROs set institution-owned rules that cut losses, not applicants.

By Philip Paul, CEO · Updated September 2026

Quick answer

First-party fraud is decided when your institution agrees to open the account and on what terms, not weeks later when a transaction alert fires. The signals exist at origination: application velocity, device and location, funding intent and which products the applicant reaches for first. The rules that read those signals should be deterministic, owned by your risk team, and built to step an applicant up before they decline them.

The number that changed the budget

Cornerstone Advisors' What's Going On in Banking 2026 (Feb 2026) found that about 50% of credit unions and 40% of banks had elevated fraud losses in 2025, and that first-party fraud now accounts for more than 40% of those losses. Three-quarters of institutions will raise fraud budgets in 2026.

That 40% moved the budget conversations we sat in this year. First-party fraud, where the person opening the account is who they say they are and intends to abuse it anyway, is a different problem from the one most fraud programs were built to solve.

Alloy's 2026 State of Fraud (Dec 2025) puts 29% of fraud events in the first-party column. Synthetic identity is the top tracked fraud type, named by 44% of institutions, and 89% call synthetic identity creation the most concerning evolving tactic. Synthetics sit between the third-party and first-party columns: a fabricated person who behaves like an ordinary member or customer until the day they do not.

Alogent's 2026 Check Fraud Benchmark reports check fraud up more than 25% from 2024 to 2025, with new-account fraud a rising vector.

The picture for a CRO: a growing share of losses comes from accounts your institution chose to open, using identities that were real, or real enough, on the day you opened them.

Why identity checks pass and losses still happen

Identity verification answers one question: is this applicant a real person who is who they claim to be? First-party fraud passes that test by definition. Three patterns account for most of it.

Bust-out. An applicant, real or synthetic, opens accounts and behaves normally long enough to earn trust: higher limits, overdraft, a card, a line. Then every available dollar is drawn and the accountholder disappears. The application rarely looks alarming on its own. Context does: the same identity elements or device across several recent applications, a thin file with appetite for every credit product, contact details that changed recently.

Friendly fraud and first-party chargeback abuse. The accountholder is legitimate and the transactions are theirs. The dispute is not. Purchases are made or funds received, then reported as unauthorized, and the institution absorbs the write-off. At origination the signals are indirect: a device or address attached to prior accounts closed for cause, an applicant who wants payment access before the account has any funding plan, a history your core holds but your onboarding flow never asked about.

New-account check schemes. A deposit account opens with a minimal deposit, followed quickly by a check through the mobile channel and a withdrawal against it before the item returns. The identity is real. The check is not. The account is the tool, and the institution issued it.

All three losses were decided at account opening. Transaction monitoring sees the money leave. Only the origination decision can see the account that should not have existed, or that should have opened on tighter terms.

The cost of the other column

The reflex when losses rise is to tighten. The Alkami and Cornerstone Advisors 2026 Digital Banking Performance Metrics (May 2026) report that about 25% of digital applications are denied over fraud concerns. Some of those declines are correct. Many are members and customers your institution wanted, who tripped a threshold set for a different threat.

A false decline wastes the acquisition spend, which The Financial Brand (Aug 2026) puts at about $489 per checking account fully loaded and above $1,000 at some institutions. And the applicant opens across the street. A fraud program that declines a quarter of applicants is not preventing fraud. It is abandonment with a compliance label.

The alternative is not weaker controls. Experian's 2026 Identity and Fraud Report (Aug 2026) found 84% of consumers will accept extra security steps if they prevent fraud. The applicant who is who they say they are will take a document check, a one-time passcode or a short hold on a privilege. Step-up sorts the two columns. A decline treats them the same.

Most applicants never need any of it: Cotribute clients' identity-verification clean rate is 75% at the median and 88% at best (Cotribute 2026 benchmarks). The fraud decision is about the remaining quarter.

Where the decision belongs

Every CRO we work with has been asked to choose between fraud and growth. It gets asked when the fraud decision lives in a vendor's black box or a manual queue, so the only levers are "tighter" and "looser".

The decision belongs in a rule set your institution owns, applied before the account exists, with five properties.

The rules are deterministic. Same inputs, same outcome. A risk committee can read a rule and predict what a change will do.

The thresholds are yours. Cotribute ships 70+ configurable fraud and decisioning rules across device and geolocation, synthetic identity scoring, document verification, OFAC and watchlist screening, and velocity. Your team sets the thresholds and the routing.

Vendor scores are inputs, not verdicts. Where a third-party score feeds a rule, as with synthetic identity or business fraud scoring, the score is the vendor's model. The rule that consumes it, and the threshold at which it acts, belong to your institution.

Every change is logged: what changed, who changed it and when, so the rule set can be reconstructed exactly as it stood on any date.

Outcomes are open, refer or decline. Clean applicants clear instantly, one unresolved signal triggers step-up, ambiguous cases go to a reviewer with the evidence attached, and a decline comes only where the case is made.

This is a decision about whether and on what terms to open an account, not a credit decision. Underwriting, pricing and any adverse action on a card, line or overdraft happen in your LOS or core, on your credit policy. Cotribute hands off eligibility, fraud and product qualification results; that is what our pre-screening is, and it is not a credit prescreen.

Nutmeg State Financial Credit Union reaches an instant decision on 89.5% of applications. None was waved through; each cleared a rule set configured to Nutmeg's own thresholds.

Prove it in two numbers

A fraud program that reports only losses will always be asked to spend more; one that reports only conversion will always be asked to tighten. Report both monthly, on one page.

The first number is fraud contained before funding: of the fraud identified in the period, what share was stopped before the account was funded. Across Cotribute clients the median is 73% and the best is 88% (Cotribute 2026 benchmarks).

The second is manual review effort: hours or cases spent on applications a rule could have resolved. Cotribute clients automate 71% of fraud handling at the median and 76% at the best. The remainder is the exceptions queue, and its size measures how much of the decision your rules are making.

CPM Federal Credit Union ($742M, 66K members) shows the two columns moving together: 32% more new accounts in 90 days with 82% less manual review effort.

Without both numbers, the failure is predictable. Budgets rise, as three-quarters of institutions told Cornerstone they would. Losses hold, because the spend went to monitoring accounts that should not have opened. The growth team stops trusting risk.

Frequently asked questions

Is first-party fraud a credit decision?

No. The first-party fraud decision is whether, and on what terms, your institution opens the account: instantly, with step-up, after review, or not at all. Credit decisions, underwriting, pricing and adverse action for any card, line or loan are made in your LOS or core on your credit policy. Cotribute runs eligibility, fraud and product qualification and hands the result to that system.

How is this different from our transaction monitoring?

Transaction monitoring watches money move on existing accounts and alerts after a pattern forms. Pre-account rules decide before the account exists, using origination signals: velocity, device and location, funding intent, product mix and vendor risk scores. For first-party fraud, origination is the only point where a hold or a decline is cheap.

Can we tune the rules ourselves?

Yes. Thresholds, routing and step-up logic are set by your risk team, not by a vendor release cycle. The rules are deterministic, so the same inputs always produce the same outcome, and every change is logged with what changed, who changed it and when. Where a rule consumes a third-party score, such as synthetic identity or business fraud scoring, the score is the vendor's model; the rule and its threshold are yours.

What about business accounts?

Business first-party fraud arrives as shell companies and recruited "merchant" accounts; the Oklahoma Bankers Association (May 2026) warned of consumers recruited to open accounts with names containing "MARKETING", "DIGITAL" or "ECOM STORE" to move high-risk merchant activity. The same rule model applies with business inputs: KYB, Secretary of State standing, TIN match, FinCEN CDD beneficial-ownership collection, KYC and watchlist screening on owners and signers, and BusinessGuard+ business fraud scoring.

See it working on your core

Bring your decline rate and last quarter's first-party losses. We will show you the 70+ fraud and decisioning rules live, with your thresholds, against your core. No core conversion, no LOS replacement, no digital banking replacement; the core stays the system of record.

Book a live demo   Talk with us

Sources

  1. Cornerstone Advisors, What's Going On in Banking 2026 press release, 20 Feb 2026
  2. Alloy, 2026 State of Fraud report, 9 Dec 2025
  3. Alogent, State of Check Fraud in 2026 benchmark survey
  4. Alkami / Cornerstone Advisors, 2026 Digital Banking Performance Metrics release (retail and business), 7 May 2026
  5. CUInsight, "The digital banking metrics credit union leadership teams should be watching", 14 Aug 2026
  6. The Financial Brand, "Your bank's front door shouldn't keep good customers out", 31 Aug 2026
  7. Experian, 2026 Identity and Fraud Report, 5 Aug 2026
  8. Oklahoma Bankers Association, "Be alert of fake shell companies opening accounts", 27 May 2026