Now that AI is being weaponised to create verification-ready fake loan applications, banks are trying to get a handle on the new shape of their fraud risk profile. Boards must ensure the right questions are being asked.
Recent Australian banking industry revelations suggest that AI-powered home loan fraud is a multi-billion-dollar problem, likely tied to organised crime gangs. Generative AI is helping this lending fraud to scale by enabling the creation of fake identity documents, bank statements and payslips, as well as synthetic identities and shell entities that are hard to both detect and trace.
Australian banks have invested heavily in fraud prevention, particularly in scams and cyber security. Yet industry evidence suggests that document-based lending controls cannot prevent sophisticated attackers from embedding criminal funds in property assets.
The perfect storm making home loan fraud a major risk
For decades, Australia's rising property market meant that, when fraud occurred, lenders were often protected by the increasing value of the underlying asset. But as property prices stabilise – and in some markets decline – many lenders will be exposed to genuine credit losses.
Organised crime groups see residential property as an attractive vehicle for laundering illicit funds. Rather than simply disguising the origin of criminal proceeds, they may also benefit from capital growth, making mortgage fraud a more profitable proposition than many traditional money laundering methods.
At the same time, cost-of-living pressures are contributing to a rise in first-party fraud. Advances in generative AI and digital editing tools have made it easier than ever for otherwise legitimate borrowers to alter payslips, bank statements or employment records to qualify for larger loans. These techniques pose a multi-sector threat not limited to banks, most notably with insurance and government challenged by AI generated fraudulent documents.
And the mortgage ecosystem itself creates additional points of vulnerability. Brokers, referral partners and professional advisers play an essential role in Australia's lending market. But investigations have shown that some accountants, lawyers and brokers – and even internal employees – are facilitating fraudulent applications.
A fragmented response to a connected threat
One of the biggest challenges for banks is fragmented ownership: no single team owns the problem, and those involved are often not structured to collaborate effectively.
In some institutions, mortgage fraud is led by fraud teams. In others, it sits with financial crime and anti-money laundering teams, reflecting growing regulatory scrutiny and requests from AUSTRAC. Elsewhere, action is being taken by conduct teams, recognising that the behaviour of brokers and referral partners can create significant exposure, even where they are not direct employees.
Many of these functions operate independently, with different objectives, technologies and reporting lines. As a result, institutions can end up responding to different aspects of the same threat through multiple disconnected programs.
An organised crime network exploiting a mortgage application may involve document fraud, money laundering, insider facilitation, broker misconduct and eventual credit losses – all within the same transaction. Without a joined-up view across these touchpoints, institutions risk detecting only part of the problem, or missing the broader patterns that reveal organised fraud.
Where should boards and senior executives focus?
In the current arms race between banks deploying AI for fraud detection and criminals using AI to commit fraud, criminals arguably have the tactical advantage. But banks can still find a strategic edge by adopting a range of agile mitigation strategies.
For example, documents can be verified through sophisticated methods that detect tampering or forgery. Aggregate data from internal and external data sources to gain a more comprehensive view of an applicant’s risk profile. Rules can be configured with thresholds that accept, reject, or review applications based on the level of risk. New typologies can be identified through simulated fraud attack testing and industry intelligence.