Fraud, cyber threats, AI model risk, third-party concentration, geopolitical volatility and liquidity pressure are converging. Banks need controls that connect transaction evidence with enterprise-wide intelligence.
Sibos 2026 | Miami | 28 September - 1 October 2026
The defining risk-management challenge for 2026 and 2027 is not the arrival of one new threat. It is the speed at which previously separate risks now amplify one another across data, technology, counterparties, supply chains and markets.
A deepfake can enable payment fraud. A compromised third-party interface can become an operational outage. A sanctions change can alter the risk of a trade corridor overnight. Poor document data can obscure both financial crime and credit exposure. Generative AI can strengthen detection while making impersonation, phishing and malware cheaper to scale.
The numbers explain why incremental controls are no longer enough. A 2025 BIS speech cited estimates of more than US$3 trillion in illicit funds moving through the financial system each year, with less than 1% intercepted and recovered. IBM's 2026 breach study found that one in four malicious breaches was AI-enabled - 56% more than the previous year - and that AI-enabled breaches cost an average of US$6 million. Financial-services breaches averaged US$6.3 million.
THE 2026 RISK SIGNAL 94% of respondents to the World Economic Forum's Global Cybersecurity Outlook 2026 expected AI to be the most significant driver of change in cybersecurity. 65% of large organisations identified third-party and supply-chain vulnerabilities as their greatest cyber-resilience challenge.
The response should not be five new silos. It should be a connected risk architecture that can see more of the transaction, explain what it sees and adapt as the environment changes. The following five strategies provide a practical agenda for banks entering 2027.
1. Replace isolated alerts with layered transaction intelligence
Rules remain essential, but rules operating on one data source at one point in time are no longer sufficient. Financial crime often becomes visible only when apparently ordinary facts are connected: an unusual price, a changed route, a vessel event, inconsistent goods descriptions, linked counterparties, duplicate documents or a pattern across multiple institutions.
Banks should combine deterministic controls with network analytics, anomaly detection, external intelligence and case feedback. The BIS Innovation Hub's Project Hertha illustrates the potential. In experiments using a synthetic dataset of 1.8 million accounts and 308 million transactions, payment-system analytics helped banks and payment providers identify 12% more illicit accounts. For previously unseen behaviours, the improvement was 26%. The BIS also stressed the need for labelled data, robust feedback loops and explainable algorithms.
In trade finance, TraydGuard applies this layered approach inside document scrutiny, connecting sanctions and watchlists with vessel information, pricing anomalies, goods, counterparties, document discrepancies and TBML indicators. The aim is not to create more alerts. It is to present better-contextualised findings, score severity and direct specialist attention to the transactions that warrant it.
What to implement
Create a shared transaction-risk layer with common identifiers, linked internal and external data, scenario-specific rules, anomaly models and investigator feedback. Measure true-positive yield, false-positive reduction, time to disposition and the proportion of material risks detected before release or payment.
2. Make AI governance an operating control, not a policy document
AI model risk is now inseparable from operational and third-party risk. In the Bank of England/FCA survey, one third of AI use cases were third-party implementations, 46% of firms reported only a partial understanding of the AI they used, and the top three providers accounted for 73% of named cloud providers and 44% of named model providers. Concentration can turn a local dependency into a system-wide concern.
A bank therefore needs more than responsible-AI principles. It needs an inventory of models and embedded AI, a named owner, risk tiering by use and materiality, documented data provenance, pre-deployment validation, performance thresholds, drift monitoring, access controls, change approval, incident reporting and a tested route back to a safe manual process. Vendor models should be governed to the same outcome standard as internal models.
Human oversight must also be designed, not merely promised. Reviewers need enough context to challenge a finding; escalation thresholds must be clear; and the audit trail should show the data, logic, model or rule version, output and final action. This is especially important when AI touches sanctions, AML, credit, pricing, client treatment or regulatory reporting.
What to implement
Link the AI inventory to enterprise risk, model risk, data governance, outsourcing and operational-resilience registers. Test high-materiality use cases through adverse data, ambiguous cases, bias scenarios and dependency failures before increasing autonomy.
3. Engineer cyber and operational resilience across the ecosystem
The perimeter is no longer the bank. It includes cloud platforms, model providers, data sources, APIs, software dependencies, corporate channels and critical market infrastructure. The World Economic Forum found that 87% of respondents saw AI-related vulnerabilities as the fastest-growing cyber risk during 2025, while 91% of the largest organisations had changed their cybersecurity strategies in response to geopolitical volatility.
IBM's 2026 findings show both sides of the equation. AI is making attacks faster and cheaper, but organisations using AI and automation in security operations reduced breach costs by almost US$2 million on average. For banks, the priority is secure adoption: strong identity for people and non-human agents, least-privilege access, protected APIs, encryption, data-loss controls, continuous monitoring and rapid remediation.
Operational resilience requires an equally practical lens. Map important business services to the technology and third parties that support them. Define impact tolerances. Exercise cloud, model, data-feed and connectivity failures. Maintain tested recovery and exit options for concentrated providers. An AI control is not effective if it becomes unavailable precisely when transaction volumes or threat levels rise.
What to implement
Run joint exercises involving risk, security, operations, compliance and material vendors. Include deepfake-enabled social engineering, compromised APIs, model manipulation, data poisoning, sanctions-feed failure and prolonged cloud disruption. Track time to detect, contain, recover and return to a controlled operating state.
4. Treat trusted trade data and digital documents as control infrastructure
A bank cannot automate risk decisions reliably if the underlying data is repeatedly rekeyed, trapped in images or exchanged through uncontrolled versions. ICC Academy estimates that global trade still relies on four billion documents every day. At the same time, the ICC Digital Standards Initiative reports that electronic bill of lading adoption has risen to 12.8%, from 5% in 2024. Legal reform and digital-document standards are creating momentum, but adoption remains uneven across corridors and platforms.
The strategic response is to build provenance, standardisation and validation into the data flow. Banks should know who issued a document, whether it has changed, which transaction and parties it belongs to, whether the same invoice or transport record has appeared elsewhere, and how key data maps to internal systems. Digital identity, common data definitions, version control and interoperable records reduce both operational friction and fraud opportunity.
TraydCheck and TraydConnect support this transition by extracting and validating document information, applying trade and institution-specific checks, and enabling more structured collaboration between banks and corporates. The longer-term benefit is not paper removal for its own sake. It is a trusted information layer that supports compliance, credit, operations, analytics and financing from the same evidence.
"The challenge now is not whether paperless trade is possible, but how quickly the industry can align around trusted, interoperable infrastructure."Sameer Sehgal, Chief Executive Officer, Traydstream
What to implement
Prioritise high-volume document sets and corridors. Establish canonical data fields, provenance requirements, duplicate-detection controls and exception ownership. Align digital-document programmes with compliance and risk outcomes, not only processing-cost targets
5. Manage risk dynamically at portfolio, corridor and relationship level
Transaction controls are necessary, but they do not show whether risk is accumulating across a client group, commodity, country, tenor, insurer, funder or supply chain. The Asian Development Bank estimates that the trade-finance gap remained at US$2.5 trillion in 2025, around 10% of global trade. Banks are being asked to support more legitimate activity while navigating sanctions, geopolitical fragmentation, credit pressure and capital constraints.
Dynamic risk management connects the individual case to portfolio exposure and forward scenarios. Real-time analytics should show limits, concentrations, maturities, exceptions, turnaround, collateral, funding and distribution options. Scenario analysis should test events such as a corridor restriction, commodity-price shock, counterparty downgrade, shipping disruption, cyber outage or sudden loss of a funding channel.
TraydAnalytics provides consolidated operational and portfolio views, while TraydAccess connects origination and distribution to liquidity and balance-sheet capacity. Used together with strong governance, these capabilities can help a bank distinguish between risk that should be declined, risk that requires mitigation and risk that can be distributed. That supports growth without weakening control.
What to implement
Create dashboards and trigger thresholds that join transaction findings to relationship and portfolio exposure. Review scenarios at a cadence that reflects market speed, and connect risk appetite directly to pricing, limits, collateral, insurance, funding and distribution decisions.
What good looks like by 2027
A mature risk function will not be the one with the greatest number of alerts or the longest policy. It will identify material risk earlier, explain decisions more clearly, recover from disruption faster and release legitimate transactions with less friction. It will also be able to show which controls are working through measurable outcomes.
Banks can begin now by selecting two or three high-friction workflows, establishing a baseline, mapping their data and third-party dependencies, testing the worst credible failure modes and scaling only when the evidence supports it. The institutions that connect data, technology and human judgement will be best placed to manage the risk environment of 2026-2027 - and to convert resilience into a competitive advantage.
Editorial source notes
For fact-checking and internal approval. These notes can be removed before web publication. Statistics were checked against sources available on 27 August 2026.
Bank for International Settlements, Working together to ensure financial integrity (2025). Estimates for illicit funds, recovery rates and the case for technology-enabled collaboration. View source
BIS Innovation Hub, Project Hertha (2025). 12% more illicit accounts identified; 26% improvement for previously unseen behaviours; synthetic dataset scale and implementation caveats. View source
IBM, Cost of a Data Breach Report 2026. AI-enabled breach frequency, average costs, financial-services costs and security-automation savings. View source
World Economic Forum, Global Cybersecurity Outlook 2026. AI, geopolitical, fraud and third-party/supply-chain risk statistics. View source
Bank of England and Financial Conduct Authority, Artificial intelligence in UK financial services (2024). Third-party AI, model understanding, provider concentration and governance data. View source
ICC Digital Standards Initiative. Electronic bill of lading adoption and digital-trade indicators. View source
ICC Academy, Digital Trade 101 (2024). Scale of document use in global trade. View source
Asian Development Bank, Global Trade Finance Gap Survey (2025) and 2026 update. US$2.5 trillion trade-finance gap and share of global trade. View source
Traydstream, MLETR Informed Reformation of Global Trade Law (2026). Published Sameer Sehgal quotation on trusted, interoperable infrastructure. View source
Traydstream solution pages. Product descriptions for TraydGuard, TraydCheck, TraydConnect, TraydAnalytics and TraydAccess. View source





