Curriculum / Module 02
core2 hours5 lessonsTimed assessment

The Threat Landscape

How AI is turned against financial institutions

The evidence module. It walks you through how generative and agentic AI have rewritten the economics of financial crime: deepfake voice and video fraud, AI-synthesised identity documents, fraud-as-a-service, and multi-step, agent-driven schemes — anchored in the numbers and the named cases, including the South African picture. You leave able to describe the principal attack types, cite the leading evidence to make the internal case for AI-risk competency, and map your own institution's exposure surface.

Create an accountBack to curriculum

By the end of this module, you can
  • Describe the principal AI-enabled attack types now facing financial institutions and the direction of the trend lines.
  • Cite the leading evidence, including the South African fraud data, to make the internal case for AI-risk competency.
  • Recognise the institution's own exposure surface across onboarding, payments, advice and lending.
Skills taught
  • Threat-model literacy
  • Reading fraud and identity-verification reports critically
  • Translating threat intelligence into desk-level vigilance
  • Making the evidence-based internal case

Lessons in this module

L1
The new economics of financial crime
Explain how generative AI collapsed the cost, skill and scale barriers of financial crime, and what fraud-as-a-service means for an institution's threat model.
20 min
L2
Deepfake voice and video fraud: the attack on human trust
Describe how deepfake audio and video are used against financial institutions and their clients, cite the canonical cases and regulator alerts, and identify the process weaknesses these attacks exploit.
25 min
L3
Synthetic identities and fabricated documents: the attack on automated trust
Describe how AI-synthesised identities and documents target automated onboarding, verification and credit pipelines, and cite the supply-chain evidence.
25 min
L4
The South African picture, and the regulators' answer
Assemble the South African evidence base — losses, trends, regulator findings — into a defensible internal briefing, and state what the sector's regulators have said about the skills gap.
20 min
L5
Mapping your exposure surface: the four-desk threat map
Construct a desk-level map of how each attack type in this module reaches your institution through onboarding, payments, advice and lending.
20 min
Case 02.1
Case file: The Friday afternoon instruction
An applied fact pattern worked against a model resolution, followed by the timed assessment (30 minutes, pass mark 70 percent).
20 min

How it lands across the four desks

Fraud & AML

Your desk sits at the sharp end of every attack type in this module: synthetic documents at onboarding, deepfake-authorised payments, and AI-automated schemes designed to move faster than a rules engine. You leave with the full attack taxonomy and the trend data behind it.

Compliance & Risk

You own the exposure map. This module gives you the evidence base — regulator alerts, threat-intelligence data, the named cases — to brief a board, justify control spend, and document that the institution understood its threat environment.

Wealth & Advisory

Your clients and your own likeness are the raw material: deepfake investment scams using synthetic video of trusted figures, impersonation of advisers, and social-engineering built from scraped client data. You learn the patterns your clients will be hit with.

Credit & Underwriting

Manipulated and fabricated application inputs are your front line: AI-polished payslips, synthetic income narratives, and identities assembled specifically to pass onboarding and default later. This module shows you the industrialised supply chain behind them.

Key literature · 6 sources

Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.

  • Europol (2024) 'Internet Organised Crime Threat Assessment (IOCTA) 2024' — the fraud-as-a-service supply chain, including AI-generated identity documents sold to defeat onboarding.
  • FinCEN (2024) 'Alert FIN-2024-Alert004: Fraud Schemes Involving Deepfake Media Targeting Financial Institutions' — the operational alert and red-flag indicators.
  • FATF (2025) 'Horizon Scan: AI and Deepfakes — Impacts on ML/TF/PF' — the detection-lags-generation finding that frames the defensive posture.
  • SABRIC (2024) 'Annual Crime Statistics 2023' — the South African loss and trend anchor, with generative AI named among drivers.
  • SARB Prudential Authority & FSCA (2025) 'Artificial Intelligence in the South African Financial Sector' — adoption, risk rankings, the skills-shortage finding, and the announced discussion paper.
  • U.S. Federal Reserve (2019) 'Synthetic Identity Fraud' payments-fraud insights — the definitional treatment of synthetic identities and bust-out patterns.
Create an account