North America Just Rewrote the Rules on Fraud
Federal enforcement pulled back while states, provinces, and payment networks moved the other way. The result is a patchwork of rules that all test the same capability, which is knowing exactly who you are dealing with across every system that holds a piece of it.
Related Content:

Connecting the Context Gap
Read moreNorth America Just Rewrote the Rules on Fraud
Federal enforcement pulled back while states, provinces, and payment networks moved the other way. The result is a patchwork of rules that all test the same capability, which is knowing exactly who you are dealing with across every system that holds a piece of it.
Key takeaways
Federal disbursements moved off paper checks and toward pre-payment screening, with Treasury's Do Not Pay preventing or recovering $11.7 billion in FY2025. Pay-and-chase is being retired as a strategy.
Zelle network rules now require reimbursement for certain imposter scams, and Canada's Bank Act framework covers payments made under deception or coercion from July 1, 2027. The customer deceived into pressing send is increasingly the institution's problem.
The NAIC model bulletin has been adopted by 24 states plus DC, and 12 states are piloting an evaluation tool for market-conduct examiners. A model that cannot be explained, tested, and documented is an examination finding waiting to happen.
Fraud regulation in North America has been rewritten over the past 18 months, and the plot has moved faster than most compliance teams have. A federal watchdog was defanged overnight, state attorneys general stepped into the gap, Canada quietly built the most demanding regime on the continent, and the amount of money at stake keeps climbing.
The U.S. Government Accountability Office (GAO) estimates the federal government alone loses between $233 billion and $521 billion to fraud every year, on top of roughly $186 billion in improper payments reported for fiscal year 2025 (FY2025). Regulators on both sides of the border have reached the same conclusion, which is that fraud has to be stopped before the money moves.
Banking and payments: Washington steps back, everyone else piles in
In March 2025, the U.S. Consumer Financial Protection Bureau (CFPB) dismissed its own scam-losses lawsuit against Zelle's operator and three major banks, then saw its funding roughly halved. The pressure simply moved. New York's Attorney General revived the claims, Zelle's network rules now require reimbursement for certain imposter scams, and state regulators are setting the pace. Banks face a patchwork that changes faster than any federal rulemaking ever did, while Regulation E, the federal rule requiring banks to investigate disputed electronic transfers and reimburse unauthorized ones, still applies.
The Financial Crimes Enforcement Network (FinCEN) has proposed rebuilding anti-money laundering (AML) programs around a risk-based effectiveness standard, even as the beneficial ownership database was scaled back to cover foreign entities only. Seeing through shell companies is your job again. Canada, meanwhile, skipped the drama and passed the continent's most demanding regime, a Bank Act framework covering authorized payments made under deception or coercion, in force July 1, 2027, plus supervision of roughly 1,500 payment providers and penalties from FINTRAC (Canada's financial intelligence unit) reaching $20 million or 3% of global revenue.
Insurance: your fraud models are now the ones under examination
For insurers, fraud-detection technology is now itself a supervised activity. The National Association of Insurance Commissioners (NAIC) model bulletin on insurer AI (artificial intelligence), adopted by 24 states plus the District of Columbia, explicitly covers AI used in fraud detection and claims. 12 states are piloting an AI Systems Evaluation Tool through September 2026 to give market-conduct examiners a standardized playbook. If your claims-fraud model cannot be explained, tested, and documented, it is an examination finding waiting to happen.
Enforcement is setting records too, with the U.S. Department of Justice (DOJ) charging 455 defendants in its 2026 national health care fraud takedown, the most in the program's history. In Canada, Ontario's Financial Services Regulatory Authority (FSRA) will require every auto insurer to report fraud data quarterly, the country's first mandatory insurance fraud reporting regime, expected operational by December 2026.
Government: the end of pay-and-chase
For decades, government fraud strategy ran on pay-and-chase, sending the money out and then spending years clawing it back. Two 2025 executive orders are retiring that model. One ended paper checks for most federal disbursements (checks are 16 times more likely to be lost, stolen, or altered than electronic payments). The other pushed agencies toward pre-payment screening through the U.S. Treasury's Do Not Pay service, which prevented or recovered $11.7 billion in FY2025, up 63% from the prior year.
Congress extended the statute of limitations for pandemic unemployment fraud to ten years, and the House passed 11 anti-fraud bills in June 2026, with the Senate still to act. States face their own countdown, because six-month Medicaid eligibility redeterminations begin in January 2027, and many legacy state systems were simply not built to verify identity and eligibility at that pace.
Supply chain: trade fraud just became a headline risk
If you wanted a quiet career in customs compliance, you picked the wrong decade. The DOJ and the Department of Homeland Security (DHS) launched a cross-agency Trade Fraud Task Force targeting tariff evasion and origin fraud, and whistleblowers can now earn 15% to 30% of recoveries for reporting customs fraud. Every tariff change creates fresh temptation to fudge origin or value, transshipped goods carry a 40% penalty tariff, and the de minimis exemption that once waved 1.36 billion packages a year through duty-free is gone. U.S. Customs and Border Protection (CBP) stopped more than 7,300 shipments under the Uyghur Forced Labor Prevention Act (UFLPA) in FY2025, up 51%, while Canada's forced-labour reporting law, Bill S-211, now expects demonstrable progress rather than boilerplate.
You can't comply with what you can't see
Four threads run through all of it. Prevention is replacing recovery, and liability for authorized fraud is shifting to institutions, so the customer deceived into pressing send is increasingly your problem. AI cuts both ways, with regulators warning about deepfakes while demanding documented governance of your detection models. Every regime tests the same capability, which is knowing exactly who you are dealing with across products, systems, subsidiaries, and data silos. Fraudsters live in the seams between those systems, and regulators now expect the seams closed. Meeting that standard comes down to whether your data foundation can resolve an entity across every system that holds a piece of it.
Related Content:











