Fraud Prevention, Detection and Mitigation Controls
Every control stops a fraud, spots it, or limits the loss. Put each one in the right box and half of Unit 6 is done.
Every fraud control does one of three jobs. It stops the fraud happening, it spots the fraud quickly when prevention fails, or it limits the damage and recovers what it can. IIBF's Unit 6 names them prevention, detection and mitigation controls, and the exam expects you to put any given control in the right box.
No bank relies on one type. A card has a chip and PIN (prevention), a real-time alert to the cardholder (detection) and a hotlisting process when the cardholder calls (mitigation). The question is always which layer failed.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Three Control Types
Preventive
Job
Stop the event before it happens
Banking examples
Maker-checker on transfers; segregation of duties; multi-factor authentication; device binding; access rights on least privilege; staff KYC and vetting; firewalls; customer awareness
Detective
Job
Spot it as early as possible
Banking examples
SMS and email alerts on every debit; transaction monitoring for unusual velocity; Early Warning Signals on loan accounts; reconciliation; audit and concurrent audit; log review; whistle blower complaints
Mitigation (corrective)
Job
Limit loss and recover
Banking examples
Card hotlisting; freezing or marking a lien on the beneficiary account; incident response plan; insurance; backup and disaster recovery; staff accountability and root cause analysis
| Type | Job | Banking examples |
|---|---|---|
| Preventive | Stop the event before it happens | Maker-checker on transfers; segregation of duties; multi-factor authentication; device binding; access rights on least privilege; staff KYC and vetting; firewalls; customer awareness |
| Detective | Spot it as early as possible | SMS and email alerts on every debit; transaction monitoring for unusual velocity; Early Warning Signals on loan accounts; reconciliation; audit and concurrent audit; log review; whistle blower complaints |
| Mitigation (corrective) | Limit loss and recover | Card hotlisting; freezing or marking a lien on the beneficiary account; incident response plan; insurance; backup and disaster recovery; staff accountability and root cause analysis |
RBI's Early Warning Framework
RBI's fraud directions require every bank to have a Board-approved fraud risk management policy covering prevention, early detection, investigation, staff accountability, monitoring, recovery and reporting. The detection engine is the Early Warning Signals (EWS) and Red Flagging of Accounts (RFA) framework, integrated with the core banking system.
An EWS alert on a loan account (cheque returns, diversion of funds, a sudden drop in turnover) must be examined to decide whether the account should be red-flagged. The turnaround time for examining alerts is set by the Board's risk committee, preferably not more than 30 days. A red-flagged account with aggregate exposure of ₹3 crore and above must be reported on RBI's CRILC platform within seven days, and the decision to classify it as fraud or remove the red flag should ordinarily be completed within 180 days.
The same framework now reaches beyond loans. Banks must parameterise EWS for non-credit transactions too, especially digital ones, and watch for money mule and non-KYC-compliant accounts. A dedicated Data Analytics and Market Intelligence Unit is required to spot unusual patterns early.
Digital Channel Controls
RBI's digital payment security directions add detection and mitigation controls specific to online banking and cards:
- check_circleAlerts by SMS and email on payment transactions, beneficiary additions, account detail changes and limit revisions, with the merchant's name rather than the payment aggregator's.
- check_circleMonitoring parameters such as transaction velocity, especially in accounts of customers who have never used mobile or internet banking before.
- check_circleAlerts to customers on failed authentication attempts.
- check_circleReconciliation of digital payment transactions with all counterparties in real time or near real time, not later than 24 hours from receipt of settlement files.
Quick practice on banking operations. No signup.
Which Version of the Rules
RBI's Master Directions on Fraud Risk Management of 15 July 2024 were repealed and reissued as entity-wise Directions, 2026 on 31 July 2026. The EWS and red-flagging rules above, including the ₹3 crore, seven-day and 180-day figures, appear in both. Sittings to February 2027 use a 30 June 2026 cut-off, so the 2024 Master Directions are the reference for now.
How the IIBF Exam Tests This
- check_circleClassification questions: 'Which of these is a detective control?' with three preventive options and one alert or audit option.
- check_circleAudit is detective, not preventive. It finds what has already happened. Maker-checker is preventive because it stops one person completing a transaction alone.
- check_circleInsurance and backups are mitigation: they don't stop or spot anything.
- check_circleEWS figures: ₹3 crore threshold, seven days to report on CRILC, 180 days to conclude. Distractors swap these numbers.
FAQs
What is the difference between preventive and detective controls?expand_more
Preventive controls stop a fraud from happening, such as maker-checker or multi-factor authentication. Detective controls find it after it has started, such as transaction alerts, reconciliation and audit.
What are mitigation controls in fraud management?expand_more
Controls that limit the loss and help recovery once a fraud has occurred: hotlisting a card, freezing the beneficiary account, the incident response plan, insurance and disaster recovery.
What is a red flagged account?expand_more
An account where one or more Early Warning Signals suggest possible fraud, triggering a deeper investigation. Banks report red-flagged accounts with exposure of ₹3 crore and above on RBI's CRILC platform within seven days.
Is audit a preventive or detective control?expand_more
Detective. An audit examines transactions that have already happened and finds errors or frauds after the event. Its deterrent effect is a side benefit, not its primary function.
Next steps
- MFAarrow_forward
- RBI Fraud Reportingarrow_forward
- Firewalls & IDSarrow_forward
- Preparationarrow_forward
120 questions, 2 hours, scored instantly.
