For decades, financial crime compliance has operated on the simple principle of trace the money after it moves. However, a wave of federal actions in 2026 signals a fundamental shift in which banks may be expected to stop illicit transactions before they ever happen.
Listen to this article
Key insights:
- Federal policy is pivoting from recovery to prevention — Federal agencies like CMS and Treasury are prioritizing stopping fraudulent payments before disbursement, rather than tracing stolen funds afterward.
- Banks face a new, higher stakes role — Government anti-fraud specialists are moving from being retrospective investigators to real-time gatekeepers capable of interrupting suspicious transactions using AI and behavioral analytics.
- Technology outpaces governance — As detection speeds up, however, the harder challenge becomes deciding when evidence justifies intervention and who holds that authority.
For more than half a century, the adage Follow the money! has helped define the architecture of financial crime compliance. This past summer, however, Washington sent financial institutions a different message: Following the money may no longer be enough. Increasingly, success may depend on stopping fraud before the check clears.
That shift took tangible form in July, when the Centers for Medicare & Medicaid Services (CMS), part of the U.S. Department of Health and Human Services (HHS), deferred more than $1 billion in Medicaid payments to California and Minnesota pending review of high-risk claims, describing a new approach aimed at stopping fraud “before the check clears” rather than chasing stolen funds after they had left the building.
Weeks later, the White House pointed to $56 billion in fraudulent payments stopped, while Treasury officials intensified their scrutiny of financial flows linked to public-benefit fraud in public-benefit fraud in Minnesota, requiring enhanced reporting on certain international transfers from two counties in the state.
Shifting the focus of fraud prevention
Taken together, these measures suggest something broader than another enforcement campaign. They point toward an emerging federal policy direction in which anti-fraud controls are measured not only by how successfully illicit funds can be identified, traced, and recovered, but by whether they are prevented from leaving the system in the first place.
Yet the government cannot make this shift alone. Federal program payments ultimately move through the financial system, placing banks at a critical intersection between the disbursement of public funds, the execution of fraudulent schemes, and the subsequent movement and potential laundering of illicit proceeds. Banks have traditionally occupied a critical but largely retrospective position in the anti-fraud architecture, with their roles usual defined as identifying suspicious activity, reconstructing financial flows, reporting concerns, and helping investigators follow the money after the transaction has occurred.
However, a system focused on preventing losses before funds are disbursed raises a different question: What role should banks play before the money moves?
What should banks be doing?
Indeed, that question is becoming harder to avoid. Banks occupy one of the few points in the fraud lifecycle in which a transaction can still be interrupted. They see the accounts, counterparties, and payment patterns through which funds move. They also have access to real-time analytics, behavioral indicators, and AI capable of identifying anomalies before completion. If the traditional value of financial intelligence was its ability to reconstruct what happened, its emerging value may lie in helping prevent it altogether.
Federal program payments ultimately move through the financial system, placing banks at a critical intersection between the disbursement of public funds, the execution of fraudulent schemes, and the subsequent movement and potential laundering of illicit proceeds.
Moving from detection to intervention, however, is considerably more complicated than following the money. Suspicion is not proof, and a financial institution deciding whether to delay or interrupt a transaction operates under very different constraints from an investigator reconstructing it afterward. For example, false positives can delay legitimate payments, disrupt businesses, and damage customer relationships. Intervention also raises questions of legal authority, operational responsibility, and where the line should be drawn between identifying financial crime risk and acting on it.
Part of the answer may lie in seeing more of the picture before making that decision. On June 12, the Financial Crimes Enforcement Network (FinCEN), part of the Treasury Department, issued updated guidance clarifying how financial institutions can share information about suspected fraud under Section 314(b) of the USA PATRIOT Act. A transaction that appears unusual to one institution may look very different when viewed alongside activity observed by another. By reducing informational boundaries between institutions, the guidance strengthens all institutions’ ability to identify fraud earlier while funds may still be within reach.
This development reflects a broader shift in Washington in which large-scale fraud is being treated not simply as a source of financial loss, but as a threat that intersects with organized crime, transnational risks, and national security.
In March, President Trump established a White House Task Force to Eliminate Fraud, chaired by the Vice President and directed to develop a government-wide strategy built around pre-payment controls, information sharing, and disruption of fraud networks. The order also requires coordination with the Homeland Security Council on matters involving transnational crime, organized criminal activity, and national security.
By August, the administration had gone further, declaring transnational criminal organizations engaged in cyber-enabled fraud a growing threat to national security and calling for the use of “all instruments of national power,” including private-sector capabilities, to identify and disrupt criminal networks.
The role of technology
The timing of this policy shift is particularly important. A decade ago, expecting financial institutions to identify complex fraud patterns and intervene before settlement would have been operationally unrealistic. Today, that equation is changing. Real-time payment monitoring, network analytics, behavioral data, and AI-assisted detection are rapidly narrowing the distance between identifying suspicious activity and acting upon it. Patterns that once became visible only after transactions were completed can be detected while funds are still in motion, giving financial institutions an opportunity to intervene before suspicious activity becomes a financial loss for the government or the bank’s customers.
There's been a broader shift in Washington in which large-scale fraud is being treated not simply as a source of financial loss, but as a threat that intersects with organized crime, transnational risks, and national security.
Technological capability, however, does not resolve the more difficult question of decision-making. The earlier institutions seek to intervene, the less complete the information they have available to them to make that decision. AI can identify anomalies, network analytics can reveal connections, and behavioral models may flag deviations from established patterns, but none of these signals alone determines whether there is sufficient evidence to delay or stop a legitimate transaction.
The challenge, therefore, is no longer simply whether suspicious activity can be detected early enough. It is whether financial intelligence is sufficiently reliable to justify intervention and, ultimately, who should make that decision. As technology moves detection closer to real time, human judgment may become not only more important, but also more consequential.
For financial institutions, that means that governance, rather than technology alone, is the next critical layer of the preventive model. Institutions will need to determine how quickly risk can be identified, when intelligence becomes sufficient for action, who has the authority to intervene, and under what controls.
Follow the money, of course, will remain indispensable. However, the next evolution of financial crime compliance may begin one step earlier. And the primary question will be whether financial institutions can recognize the risk early enough and with sufficient confidence to stop it beforehand, not just whether institutions can determine where the suspicious money went once it’s gone.

