The U.S. payments industry does not lack fraud data. It lacks agreement about what that data means.
The Accredited Standards Committee X9’s new Payment Fraud Forum, which holds its first meeting Sept. 10, is targeting exactly that problem. The initiative brings together participants including Federal Reserve Financial Services, The Clearing House (TCH) and the U.S. Faster Payments Council to develop common approaches for identifying, categorizing, reporting and sharing fraud across payment types. Its work could eventually contribute to industry standards.
“Payment fraud is an industrywide challenge that requires collaboration across the payments ecosystem. The Clearing House is pleased to participate in the new X9 Payment Fraud Forum and contribute to this important industry dialogue,” Kyle Caldwell, VP, Fraud Product Management, The Clearing House, told PYMNTS.
For banks, payment providers and corporate finance teams, the significance goes beyond another fraud working group. Payments has spent decades making money interoperable. The next challenge is making fraud intelligence interoperable, too.
Read more: Wall Street’s New Cybersecurity Threat Starts With a Phone Call
Fraudsters Already Operate Across Payment Rails
The payment industry’s fraud architecture remains heavily organized around payment types. There is check fraud, ACH fraud, wire fraud, card fraud and instant-payment fraud.
Criminals see a more fungible system. An attack can begin with a compromised corporate email account, produce a fraudulent supplier instruction, trigger an authorized ACH or wire transfer, arrive at an account at another institution and move again before anyone recognizes the complete pattern. Each participant sees the transaction from its own position. No participant necessarily sees the fraud from beginning to end.
The PYMNTS Intelligence report “Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms“ found that hackers increasingly target middle market firms. These companies depend on third-party cloud providers, software-as-a-service platforms and managed service providers, which can leave them exposed.
That fragmentation becomes particularly problematic when institutions describe what happened differently. Was an incident business email compromise, authorized push-payment fraud, account takeover, vendor impersonation or some combination of them? The classification matters because fraud data becomes substantially more useful when institutions can aggregate comparable events.
X9 is effectively targeting that translation layer.
See also: AI Gives Cybersecurity a Backlog CFOs and CISOs Can’t Patch Away
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The Next Payment Rail Will Carry Fraud Risk Data
Sixty-eight percent of financial institutions increased their fraud-detection budgets year over year, according to the 2025 “State of Fraud and Financial Crime in the United States,” a PYMNTS Intelligence report produced in collaboration with Block. That spending comes as 46% of institutions report increasingly sophisticated fraud schemes, up from 35% a year earlier.
The payments industry has invested heavily in making transactions faster and more information-rich. Fraud creates the inverse challenge: Information about risk needs to move at least as effectively as information about money.
The X9 forum plans to develop approaches for identifying, categorizing and reporting fraudulent activity across payment types. Its existing Check Fraud Industry Forum will become a subgroup, extending an effort previously centered on one stubborn fraud problem toward a broader cross-rail model.
The strategic question is therefore shifting from “Can my institution identify fraud?” to “Can the network recognize what my institution has learned?”
See also: Frontier AI Finds Cracks in the Math Behind Bank Security
If the ecosystem can agree on how fraud events, account behaviors and payment risks are described, institutions do not need identical fraud engines to exchange useful intelligence. They need a common enough language for one system’s signal to mean something to another. As accounts payable becomes more automated, corporations are generating more-structured information about invoices, suppliers, approvals and beneficiary changes. That information can serve two purposes: automate the legitimate payment and establish what a legitimate payment is supposed to look like.
For CFOs, that makes payment-data architecture part of the control environment. The quality of supplier identity, beneficiary information and approval data can determine not only whether finance operates efficiently, but whether external payment infrastructure has enough context to recognize an abnormal transaction.
It can also help with AI. Artificial intelligence doesn’t just create compliance work, it creates an entirely new layer of enterprise operating costs centered on governance. In a new PYMNTS eBook, executives from Visa, FIS, Synchrony, WEX, Billtrust, i2c, Thales, Velera, Bottomline and other industry leaders describe what they are learning as AI agents move from demonstrations into real operating environments.
If X9 can help establish that common language, the payoff will not be another layer of fraud prevention. It will be something the U.S. payments system still largely lacks: a fraud defense capable of operating at the scale of the network it is trying to protect.
For all PYMNTS B2B coverage, subscribe to the daily B2B Newsletter.
Facts Only
* The Accredited Standards Committee X9 launched the Payment Fraud Forum, starting its first meeting on September 10.
* The forum brings together participants including the Federal Reserve Financial Services, The Clearing House (TCH), and the U.S. Faster Payments Council.
* The goal of the forum is to develop common approaches for identifying, categorizing, reporting, and sharing fraud across payment types.
* Fraudsters exploit payment rails such as check fraud, ACH fraud, wire fraud, card fraud, and instant-payment fraud.
* Criminals can initiate attacks using compromised accounts to trigger transfers across different institutions.
* The PYMNTS Intelligence report found that 68% of financial institutions increased their fraud-detection budgets year over year.
* 46% of institutions report increasingly sophisticated fraud schemes, an increase from 35% a year prior.
* Institutions describe incidents differently (e.g., business email compromise vs. account takeover), which affects the utility of aggregated data.
* The goal is shifting from identifying fraud internally to recognizing patterns across the network.
Executive Summary
The Payment Fraud Forum, hosted by the Accredited Standards Committee X9, is being established to address a lack of agreement regarding fraud data within the U.S. payments industry. The initiative brings together entities like the Federal Reserve Financial Services, The Clearing House (TCH), and the U.S. Faster Payments Council to develop common methods for identifying, categorizing, reporting, and sharing fraud across different payment types. This effort aims to create interoperable fraud intelligence, moving beyond siloed views of specific fraud types like check or wire fraud.
The fragmentation in the payments ecosystem is highlighted by the fact that criminals operate across various payment rails, using methods like compromised email accounts to initiate transfers that move between institutions without a single participant seeing the entire pattern. This lack of shared understanding makes aggregated fraud data less useful for institutions. The initiative seeks to establish a common language so that information about risk can be effectively exchanged, which is crucial as the industry matures and systems become more automated.
Full Take
The core tension in this development lies between siloed operational realities and the necessity for systemic interoperability. The existing fraud architecture remains segmented by payment types, creating a fragmented view of threats where individuals only see their segment of the transaction chain. The proposed forum targets the "translation layer"—the semantic gap—between disparate institutional perceptions of an event, aiming to create a common language for risk intelligence across the ecosystem. This addresses the challenge that technical security measures alone are insufficient when the threat landscape is fungible and spans multiple systems.
The shift in focus from "Can my institution identify fraud?" to "Can the network recognize what my institution has learned?" reveals a deeper strategic implication: true defense capability must be network-level rather than purely enterprise-level. If institutions adopt a common framework, it affects how data architecture is perceived, especially concerning supplier identity and approval context, which moves payment data into the control environment for CFOs. This suggests that achieving fraud defense at scale depends less on isolated prevention tools and more on establishing shared epistemological ground regarding risk attribution across the entire payments network.
The fragmentation in reporting forces institutions to manage complexity internally, yet the successful outcome hinges on overcoming institutional inertia to agree on definitions. The implication is that standardization in this area is not merely an administrative exercise but a prerequisite for leveraging advanced concepts like AI effectively in security governance, suggesting that systemic cohesion is necessary before advanced technological integration can yield broad defensive payoffs.
Bridge Questions: What specific metrics or taxonomies will define the common language, and how will the forum manage the inherent political tension between participants who operate within distinct regulatory frameworks? If a unified system emerges, what are the potential consequences for regulatory oversight when fraud intelligence is shared across institutional lines? What alternative models exist for achieving cross-organizational trust in shared risk data outside of formalized standardization efforts?
Sentinel — Human
The text appears to be a well-structured piece of industry commentary, using specific organizational references to build an argument about the necessity of standardized fraud intelligence across the payments ecosystem.
