Curriculum / Module 02
core2 hours5 lessonsTimed assessment

The Threat Landscape

How AI is turned against financial institutions

This module sets out the evidence. It describes how generative and agentic AI have changed the economics of financial crime: deepfake voice and video fraud, AI-synthesised identity documents, fraud-as-a-service marketplaces, and multi-step schemes run by AI systems that plan and act with limited human input. Each attack type is anchored in published figures and named cases, including the South African evidence. By the end you can describe the principal attack types, cite the leading sources when you make the internal case for AI-risk competency, and map where your own institution is exposed.

Create an accountBack to curriculum

By the end of this module, you can
  • Describe the principal AI-enabled attack types now facing financial institutions, and the direction in which the published trends are moving.
  • Cite the leading evidence, including the South African fraud data, to make the internal case for AI-risk competency.
  • Recognise where the institution is exposed to these attacks across onboarding, payments, advice and lending.
Skills taught
  • Threat-model literacy
  • Reading fraud and identity-verification reports critically
  • Translating threat intelligence into desk-level vigilance
  • Making the evidence-based internal case

Lessons in this module

L1
The new economics of financial crime
Explain how generative AI lowered the cost, skill and scale barriers to financial crime, and what fraud-as-a-service means for an institution's threat model.
20 min
L2
Deepfake voice and video fraud: the attack on human trust
Describe how deepfake audio and video are used against financial institutions and their clients, cite the best-documented cases and the regulator alerts, and identify the process weaknesses these attacks exploit.
25 min
L3
Synthetic identities and fabricated documents: the attack on automated trust
Describe how AI-synthesised identities and documents target automated onboarding, verification and credit pipelines, and cite the supply-chain evidence.
25 min
L4
The South African picture, and the regulators' answer
Assemble the South African evidence base, covering losses, trends and regulator findings, into a defensible internal briefing, and state what the sector's regulators have said about the skills gap.
20 min
L5
Mapping your exposure surface: the four-desk threat map
Construct a desk-level map of how each attack type in this module reaches your institution through onboarding, payments, advice and lending.
20 min
Case 02.1
Case file: The Friday afternoon instruction
An applied fact pattern worked against a model resolution, followed by the timed assessment (30 minutes, pass mark 70 percent).
20 min

How it lands across the four desks

Fraud & AML

Every attack type in this module arrives at your desk: synthetic documents at onboarding, deepfake-authorised payments, and AI-automated schemes designed to move faster than a rules engine can respond. You leave with the full attack taxonomy and the trend data behind it.

Compliance & Risk

You are usually the person who maintains the exposure map. This module gives you the evidence base, meaning regulator alerts, threat-intelligence data and the named cases, to brief a board, support a case for control spending, and record that the institution understood its threat environment.

Wealth & Advisory

Your clients and your own recorded likeness are both targets: deepfake investment scams using synthetic video of trusted figures, impersonation of advisers, and social engineering built from scraped client data. You learn the patterns your clients are most likely to meet.

Credit & Underwriting

Manipulated and fabricated application inputs are the main risk on your desk: AI-polished payslips, invented income histories, and identities assembled specifically to pass onboarding and default later. This module shows you the industrialised supply chain behind them.

Key literature · 6 sources

Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.

  • Europol (2024) 'Internet Organised Crime Threat Assessment (IOCTA) 2024': the fraud-as-a-service supply chain, including AI-generated identity documents sold to defeat onboarding.
  • FinCEN (2024) 'Alert FIN-2024-Alert004: Fraud Schemes Involving Deepfake Media Targeting Financial Institutions': the operational alert and red-flag indicators.
  • FATF (2025) 'Horizon Scan: AI and Deepfakes — Impacts on ML/TF/PF': the detection-lags-generation finding that frames the defensive posture.
  • SABRIC (2024) 'Annual Crime Statistics 2023': the South African loss and trend anchor, with generative AI named among drivers.
  • SARB Prudential Authority & FSCA (2025) 'Artificial Intelligence in the South African Financial Sector': adoption, risk rankings, the skills-shortage finding, and the announced discussion paper.
  • U.S. Federal Reserve (2019) 'Synthetic Identity Fraud' payments-fraud insights: the definitional treatment of synthetic identities and bust-out patterns.
Create an account