
Staff fraud is only 8% of total bank fraud cases but likely much higher in value. Banks need automated red-flag rules and behavioural analytics to catch insiders who exploit CBS architecture.
Bank fraud is no longer just an external cyber threat. Insiders with legitimate access can exploit banking systems, trusted credentials and institutional blind spots to quietly siphon money. The fraudster has the key, a designation, and years of institutional trust.
The core banking solution (CBS) has digitised every branch. It has also handed the insider an invisible weapon: the ability to debit accounts, backdate entries, park funds in suspense accounts, activate dormant accounts and move money to relatives or mule accounts. The fraudster takes advantage of late generation of activity reports and the lack of staff strength to scrutinise entries immediately.
Bank staff fraud cases have fallen from 2,624 in FY21 to 1,935 in FY25, and 400 in the first half of FY26. Staff fraud is only 8% of total cases but likely much higher in value. The decline in numbers suggests that existing controls such as maker-checker, job rotation and whistleblower schemes are working. But more needs to be done.
CBS eliminates manual errors and enables real-time, branch-agnostic processing. It has succeeded on both counts. The same architecture that lets a customer transact from any branch also lets a bank employee debit multiple accounts, credit funds to an account in a different bank, and route the proceeds to mule accounts. Once that is done, recovery becomes difficult.
The most technically dangerous method exploits 'value dating', the principle that interest accrues from the date of credit entry and not the actual transaction date. A staff member can post a backdated credit, square off the entry on the date of creation, let the system calculate and credit interest for the intervening period, then reverse the principal while leaving the already-credited interest untouched. Since each debit is matched by a same-day credit reversal, it may escape routine exception reports. Losses accumulate silently over years.
Inter-branch office and suspense accounts can also be abused. Funds can be fraudulently parked in such accounts and squared off before the end-of-day cycle closes. System logs capture every user ID involved in both schemes but exception reports are typically only reviewed during periodic inspections, not continuously. This gives the insider a wide window of opportunity.
Banks need to shift from annual audits to automated red-flag rules on the CBS/anti-money laundering layer that fire instantly instead of waiting for the periodic review. Biometric login into the system should be non-negotiable. Single biometric identity should not be allowed to play the role of maker and checker of the same transaction. No ID should be allowed to remain active for more than 15 minutes if not used. This will minimise the risk of login password-sharing by higher authorities.
All banks must make use of user and entity behaviour analytics (UEBA) to baseline normal activity per employee and flag deviations in near-real time. Structural controls include adoption of the four-eye principle, which requires at least two distinct authorised people to review and approve a critical action before it takes effect. No single employee can open an account, disburse a loan or execute an RTGS transfer alone.
Other controls include mandatory job rotation, surprise audits, daily automated reconciliation of teller cash and suspense accounts, and anonymous whistleblower hotlines. Industry estimates that about 40% of staff frauds come to light through the last route.
Senior citizens typically have a single trusted point of contact at a bank branch. Banks should encourage such customers to interact with multiple staff members. Any loan sanctioned against a term deposit receipt belonging to a senior citizen should automatically alert a higher-level officer for independent cross-verification. Deceased-account handling needs the same systemic rigour. As civil registration and KYC databases become better integrated, banks should move towards systems that promptly freeze accounts after verified notification of death.
NRI accounts warrant an additional safety layer given the physical distance between the customer and the branch. Any loan or lien against an NRI account should require scanned-document verification through large language model-based document authentication tools before approval.
Vigilance departments in Indian banks have limited deployment of AI or machine learning models for preventive vigilance. Most vigilance activity remains reactive, triggered after a complaint or loss rather than by predictive pattern detection. Industry-wide data on staff-perpetrated fraud, if pooled and modelled, could allow AI systems to learn behavioural baselines for different staff roles, detect deviations over time, and alert administrative and vigilance offices before a loss crystallises. This is an open frontier for fintech vendors.
Cybersecurity tooling has overwhelmingly targeted external, customer-facing fraud, leaving staff behaviour monitoring comparatively underbuilt despite its significant share in the value of frauds. High attrition and frequent staff movement in private banks mean institutional memory about individual behaviour patterns resets constantly. Newly hired, tech-savvy employees understand the system architecture and its blind spots well.
The Reserve Bank of India's directives asking banks to minimise system-generated internal accounts, a favoured parking spot for fraudulent loan proceeds and broken term deposits, reflect the same underlying philosophy: shift responsibility from human vigilance to systemic design. When a bank runs millions of daily transactions, a human reviewer will always arrive too late.
Behind the forensics and the policy responses lies a question that India's banking industry is asking itself: Does working daily with other people's money, in an environment of constrained salaries, rising lifestyle aspirations and algorithmically addictive betting platforms gradually erode ethical boundaries for certain bankers?
Tamal Bandyopadhyay is an author and senior advisor to Jana Small Finance Bank Ltd. His latest book is Roller Coaster: An Affair with Banking. These are his personal views.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.