
The Fraud Review Program Most Banks Don’t Have
Most treasury management teams at community and regional banks know that fraud reviews with business clients are valuable. They protect clients from losses, which builds relationship trust and can lead to new upsell opportunities. But very few banks have turned fraud reviews into a structured program that happens consistently without requiring someone to remember to do it every quarter.
Instead, fraud reviews happen reactively. They’re done only after an incident or when an RM happens to think of it. The result is a portfolio where no one has visibility into which relationships are under protected or overdue for a conversation.
Below you’ll find a step-by-step guide to building a fraud review program that operates on a predictable quarterly cadence and produces measurable results in both client protection and treasury management fee income growth.
Why Fraud Reviews Fail to Become Programs
Before building the program, it helps to understand why fraud reviews typically stay ad hoc:
Reason #1: No One Owns It
Fraud reviews often pass back and forth between the RM and the TM officer. The RM assumes the TM officer will bring it up during the annual review. The TM officer assumes the RM owns the relationship conversation. Neither party schedules it proactively, so it does not happen unless a client calls with a concern or a fraud incident forces the conversation.
This can be avoided through explicitly assigned ownership. Someone, either the TM officer or TM leader, needs to own the fraud review process from calendar invites to completion rates.
Reason #2: No Portfolio Segmentation
Banks that try to review every client with the same frequency and depth quickly discover they don’t have capacity to do that. Reviewing a $50,000 relationship with the same rigor as a $5 million relationship is not a good use of time, and attempting to do so means neither gets reviewed well.
Tier your portfolio by fraud risk and relationship value, and assign different review frequencies to each tier. Not every client needs a quarterly review, but for your highest-risk, highest-value clients, it’s a necessity.
Reason #3: No Structured Process
Undocumented or unstructured fraud reviews produce fragmented results. One RM asks about ACH filters while another focuses on dual control, and yet a third spends the entire meeting talking about general fraud trends without ever assessing the client's actual controls. The inconsistency means clients get uneven coverage, and the bank has no way to measure what is working.
Build a standard fraud review agenda and documentation process that every RM and TM officer uses. Consistency allows you to scale the program and measure results accurately.
Reason #4: No Tracking or Accountability
If you can’t see individual review results, you can’t manage the program. Most banks don’t track fraud reviews in their CRM, which means there is no visibility into completion rates or outcomes.
Build fraud review tracking into your CRM or portfolio management system. You should have be able to document every gap and track every recommended control through to implementation or rejection.
The Three-Tier Portfolio Segmentation Model
The foundation of a scalable fraud review program is portfolio segmentation. Not all clients require the same level of attention, and trying to treat them all equally guarantees the program will collapse under its own weight.
Tier 1: High-Risk, High-Value Clients (Quarterly Reviews)
Who belongs in Tier 1:
· Top 10–15% of treasury management relationships by total relationship profitability (deposits + loans + TM fee income)
· Businesses with high transaction volumes and complex treasury management setups, or industries known to be targeted by fraud (property management, healthcare, professional services, real estate, construction)
· Any client that has experienced a fraud attempt or incident in the past 24 months
Review frequency: Every 90 days
Review depth: Full fraud controls assessment covering user access, approval workflows, payment controls, monitoring and alerts, and fraud training. Includes gap identification and specific product recommendations.
Ownership: TM officer conducts review with RM participation recommended.
Tier 2: Moderate-Risk, Solid Relationships (Semi-Annual Reviews)
Who belongs in Tier 2:
· Middle 50–60% of treasury management relationships. These are your solid clients with stable balances and moderate transaction activity
· Businesses with established treasury management product usage but not complex setups
· Clients in lower-risk industries or with relatively simple payment workflows
Review frequency: Every 180 days (twice per year)
Review depth: Streamlined controls assessment focusing on high-impact controls (e.g, ACH filters, positive pay, dual approval, and user access reviews). Less time spent on general fraud landscape education, and more time on specific gaps.
Ownership: TM officer or senior RM conducts review.
Tier 3: Lower-Risk, Smaller Relationships (Annual Reviews or Touchpoint Only)
Who belongs in Tier 3:
· Bottom 25–35% of treasury management relationships by profitability or transaction activity
· Businesses with minimal treasury management product usage (often just basic online banking and RDC)
· Very low transaction volumes or very low balances
Review frequency: Annual review or proactive outreach touchpoint (email or brief call) without a full meeting
Review depth: High-level check-in on whether fraud controls are still in place and whether any changes in business activity warrant a deeper review.
Ownership: RM or TM support staff handles via email or brief phone check-in.
The Standard Fraud Review Agenda (45 Minutes)
Every Tier 1 and Tier 2 fraud review should follow the same basic structure. This ensures consistency, makes reviews easier to conduct, and improves the quality of documentation.
Minutes 0–10: Landscape and Context
Establish why you are having the conversation and provide brief industry-specific fraud context.
Script:
"Thank you for making time for this fraud review. We conduct these [quarterly / semi-annually] with our key clients to make sure the controls you have in place match your current risk exposure. Our goal today is to walk through your setup in order to identify any gaps, and recommend one or two specific enhancements."
Provide 2–3 current fraud trends relevant to the client's industry. Keep it brief and specific. Fear-mongering isn’t necessary.
Minutes 10–25: Controls Assessment
Walk through the client's current controls using a structured question framework.
Five control categories to assess:
1. User access and entitlements — Who has access to initiate payments? When was access last reviewed? Do any team members share credentials?
2. Approval controls — What are their dual control thresholds? Who are secondary approvers? Are approvals consistent across payment types?
3. Payment controls — Are ACH filters, positive pay, wire callback verification, or other controls in place? Have they noticed any gaps?
4. Monitoring and alerts — Does the client receive daily alerts? Who reviews them? What is the escalation process?
5. Training and awareness — When was the last fraud awareness training? Do employees know how to spot phishing or social engineering?
Document answers in your CRM or review template as you go.
Minutes 25–35: Gap Identification and Recommendations
Synthesize what you learned into 2–3 specific, named gaps. Present 1–2 protection bundles matched to those gaps.
Example gap statement:
"You mentioned your user access list has not been reviewed in over a year. We typically see 10–15% of entitlements become stale in that time. I would recommend adding a quarterly user access review to your setup; we can facilitate that for you so it happens automatically."
Use your protection bundles to match gaps to product packages.
Minutes 35–45: Pricing, Next Steps, and Close
Present pricing clearly, position as investment not cost, and lock in next steps.
Script:
"The protection bundle we are recommending runs $[X] per month. Think of this as business continuity insurance for your operating cash flow. I will send you a summary of what we discussed, and let's reconnect next week to answer any questions and move forward."
Document the conversation in your CRM and schedule the follow-up call before leaving the meeting.
The Quarterly Calendar and Tracking System
A fraud review program will only work if there is you have visible, managed calendar in place that tracks both the status and results of each client review.
The Quarterly Review Calendar
Step #1: Build your tiered client list
Segment your entire treasury management portfolio into Tier 1, Tier 2, and Tier 3 based on the criteria above. You really should only need to revisit segmentation annually or when significant relationship changes occur.
Step #2: Assign review months
Spread Tier 1 reviews across the year so you are conducting approximately the same number of reviews each quarter. Don’t schedule all Tier 1 reviews in Q1; distribute them evenly.
Example for a portfolio with 40 Tier 1 clients:
· Q1: 10 Tier 1 reviews
· Q2: 10 Tier 1 reviews
· Q3: 10 Tier 1 reviews
· Q4: 10 Tier 1 reviews
Do the same for Tier 2 clients, recognizing they are reviewed every six months.
Step #3: Load the calendar into your CRM or task management system
Every fraud review should appear as a scheduled task assigned to the TM officer or RM responsible for that relationship. The task should include the client name, review tier, last review date, and any prior gaps or recommendations.
The Tracking Dashboard
Build a simple tracking dashboard (Excel, Google Sheets, or CRM report) that shows:
· Reviews scheduled this quarter (by tier)
· Reviews completed this quarter (by tier)
· Completion rate (completed / scheduled)
· Gap identification rate (reviews that identified at least one actionable gap)
· Conversion rate (reviews that resulted in a protection bundle sale)
· Average bundle value sold
· Total fee income generated from fraud reviews this quarter
Review this dashboard monthly with your TM team. If completion rates are lagging, address capacity or scheduling issues immediately. If conversion rates are low, review the quality of gap identification and recommendations.
Building It Into Annual Relationship Planning
Fraud reviews should be integrated into your annual relationship planning process so they happen automatically as part of managing the relationship.
Step #1: Include Fraud Review Cadence in Account Plans
Every Tier 1 and Tier 2 client should have a documented account plan that includes scheduled fraud reviews as a relationship touchpoint. This ensures fraud reviews are not seen as optional or ad hoc — they are part of how you manage the relationship.
Example account plan entry:
"Q2 fraud review: assess current ACH and positive pay controls, review user access list, and identify upsell opportunities related to dual control or enhanced monitoring."
Step #2: Coordinate with Annual TM Reviews
If you conduct annual treasury management product reviews with clients, the fraud review should happen at a different point in the year . Don’t stack reviews on top of each other. Spreading touchpoints across the year increases client engagement and gives you more natural upsell opportunities.
Example cadence for a Tier 1 client:
· Q1: Fraud review
· Q2: Product usage check-in (brief)
· Q3: Fraud review
· Q4: Annual TM product and relationship review
Step #3: Use Fraud Reviews to Surface Broader Relationship Opportunities
Fraud reviews are not just about selling fraud controls — they are relationship deepening conversations that often surface other needs. Use the review as an opportunity to ask broader questions:
"How has your business changed in the past six months? Have you experienced any new challenges on the payment or cash management side? Is there anything you wish your treasury management setup could do that it does not do today?"
These questions often lead to conversations about working capital, deposit management, or other banking services beyond treasury management.
Measuring Success and Adjusting the Program
A fraud review program is only as good as the results it produces. Measure these metrics quarterly and adjust the program based on what you learn:
Metric #1: Completion Rate
What to measure: Percentage of scheduled fraud reviews actually completed each quarter.
Target: 90%+ completion rate for Tier 1 clients, 80%+ for Tier 2.
If you are missing the target: Look into capacity constraints or make improvements to your scheduling discipline. If you have too many Tier 1 clients for available capacity, adjust your tier segmentation accordingly.
Metric #2: Gap Identification Rate
What to measure: Percentage of fraud reviews that identify at least one actionable gap in the client's current controls.
Target: 70%+ of Tier 1 reviews should identify at least one gap.
If you are missing the target: Your assessment questions may not be deep enough, or your TM officers may not be confident in identifying gaps. Revisit training on the question framework and gap identification.
Metric #3: Conversion Rate
What to measure: Percentage of fraud reviews that result in a protection bundle sale.
Target: 40–50% conversion rate for Tier 1 clients.
If you are missing the target: Review the quality of recommendations and how you position pricing, and ensure your follow-up system is actually effective. Low conversion often means weak pain point to product matching or lack of follow-through after the review.
Metric #4: Fee Income Generated
What to measure: Total treasury management fee income generated from protection bundles sold through fraud reviews.
Target: Set based on portfolio size. A portfolio of 100 Tier 1 clients should generate $50,000–$100,000 annually in fraud-related fee income if the program is working.
If you are missing the target: Focus on improving conversion rate and ensuring you are recommending appropriately sized bundles.
Programs Beat Intentions
Every bank has good intentions around fraud reviews. The banks that actually protect clients and grow treasury management fee income through fraud conversations are the ones able to turn those intentions into a documented, trackable program that runs on a calendar and produces measurable results.
Building that program doesn’t require a technology or process overhaul. It requires portfolio segmentation, a standard review agenda, a quarterly calendar, and the discipline to track completion and results.
If your bank does not have a fraud review program today, you can build one in the next 90 days and have your first quarter of reviews complete by year-end.
Related Reads for You
Discover more articles that align with your interests and keep exploring.


