Best practices for fraud prevention
ESTONIAN BANKING ASSOCIATION BEST PRACTICES FOR FRAUD PREVENTION
I. PURPOSE AND SCOPE
The purpose of the Estonian Banking Association Best Practices for Fraud Prevention (hereinafter the “Practice”) to establish the principles that guide Estonian credit institutions and Estonian branches of foreign credit institutions (hereinafter jointly referred to as "banks") in preventing and combating fraud. The Best Practices contribute to fostering cooperation across the banking sector, fair and free competition, the functioning of a trustworthy banking system, and the safeguarding of a good reputation. This document is part of a broader best practices in banking framework.
The growing dependence of the public and private sectors on digital solutions requires a secure and trustworthy environment. The convenience and simplicity of the services, systems and the like of the highly digitized society also make it a convenient environment for fraudsters, who exploit the strengths and weaknesses of the digital-first nature of the Estonian society, reducing trust in online communication channels and systems. For this reason, combating fraud is important both for protecting clients' assets and for ensuring the trustworthiness of Estonia's digital-first society. As a highly technologically minded country, Estonia is exposed to cyber and fraud risks, however the cooperation across the sectors is the basis for a systematic fraud prevention.
The purpose of the Best Practices is to:
- give an overview of the shared values, guidelines and principles that guide banks in combating fraud;
- increase the awareness of banks and society of fraud risks and of protective measures;
- develop effective cooperation in combating fraud both within the banking sector and as well as across various other sectors, including the public sector, whilst keeping in mind each respective banks autonomy in choosing and implementing specific measures.
Banks carry key importance in the fraud prevention environment, where the role includes, among other things, protecting clients' assets and ensuring the security of the banking environment. Banks acknowledge that the systematic, organized and international nature of the crimes committed by fraudsters negates the possibility that any single market participant or institution could independently tackle the entire chain of fraud events and effectively combat it. Comprehensive combating of fraud requires broader cross-sectoral cooperation, a regulatory environment that enables it, and a functioning information exchange between the private and public sector participants, in which banks participate actively and constructively.
II. VALUES AND GENERAL PRINCIPLES
- Protection of trust: banks acknowledge that combating fraud is important not only for protecting clients' assets but also for ensuring the trustworthiness of the digital-first societal services more broadly. For the planned measures and activities, banks consider the consequences of fraud extend beyond the direct material impact and include an erosion of trust towards digital communication channels and systems.
- Protection of clients' assets: the protection of clients' assets is of primary importance to banks, due to which both the physical and information-technology security measures are continuously developed and target combating all types of fraud.
- Risk-based approach: each bank independently evaluates which protective measures and control mechanisms to apply depending on the specific risk factors that have arisen, considering the bank's customer base, products and technological readiness.
- Lawfulness and proportionality: banks apply measures that have a lawful basis or where the application is permitted under contractual terms and regulatory requirements. Measures are applied proportionately to the identified risk. In areas where there is a lack of regulatory clarity, banks rely on the guidance from the regulator or the government and refrain from establishing any joint obligations until the relevant regulation has been established. In parallel, banks are prepared to participate actively in shaping regulation by issuing proposals to the competent authorities through the Estonian Banking Association.
- Transparency and communication: banks keep their day-to-day actions transparent and apply a sense of responsibly on all their undertakings. In the context of combating fraud, this may include, among other things, raising general awareness of common fraud schemes and how to protect oneself measures, whereby each bank decides independently on the format, scope and content of awareness raising activities.
- Cooperation and information exchange: banks cooperate through the Banking Association in combating fraud, sharing expert knowledge, statistics and best practices, while observing the obligation to maintain banking secrecy as stated by the Credit Institutions Act and the requirements of personal data protection and competition law.
- Internal governance: each member of the Banking Association ensures that there is a clear allocation of responsibility within the bank for combating fraud. This includes, among other things, the coordination of anti-fraud measures and the existence of appropriate internal procedures. The specific governance structure depends on the size and scope of the bank.
III. BANKS' DIRECT MEASURES FOR COMBATING FRAUD
Banks apply the following measures within their direct field of activity to protect clients' assets and combat fraud. Measures planned across the banking sector, timeframes and the scope of implementation are agreed in the Banking Association's action plan. Each bank adapts the measures according to the specific nature of its activities.
- Client authentication and device security: banks implement and develop secure customer authentication and device security measures, including the detection of new devices, multi-factor authentication, and informing clients of security risks. When choosing between various authentication solutions, banks consider the best market practices and technological development.
- Cybersecurity measures: banks implement and develop cybersecurity measures aimed at combating fraud within the technological systems applied in each organisation.
- Limit management: banks periodically review clients' transaction limits based on risk analysis and the client profile. Each bank independently establishes the appropriate thresholds, their scope and the frequency of review.
- Development of monitoring systems: banks ensure that the technical solutions of monitoring systems and the information used for combating fraud are up to date, including that fraud detection rules and scenarios consider the known fraud landscape and that algorithmic solutions are adapted to new fraud schemes. The content and scope of monitoring-system developments depend on each bank's existing infrastructure and resources available.
- Payment security: banks apply risk-based measures to ensure payment security, including considering additional controls for high-risk payments when risk factors emerge.
- Client information and education: banks contribute to raising clients' awareness of common fraud schemes and how to keep themselves safe, using measures suitable for the specific bank. As a joint activity, the Banking Association coordinates communication campaigns aimed at raising the general public's awareness in the field of fraud prevention. Banks and the Banking Association support the development of clients' financial literacy.
- Consideration of the variation among customer: banks acknowledge that different customer segments may have varying levels of vulnerability to fraud. Banks take this into account when designing measures for combating fraud. The scope of specific measures remains an independent decision of each bank.
- Technological innovation: banks monitor the development of artificial intelligence and other new technologies and their impact on the fraud landscape. Where possible and necessary, banks consider implementing new and innovative technological solutions for detecting and combating fraud.
- Management of third-party risks: in designing measures for combating fraud, banks consider risks that may arise from third parties in the chain of payment events. Within their risk management framework, banks apply appropriate measures to mitigate fraud risk also keeping in mind the third-party services which are included into the total set of services applied.
- Assistance to fraud victims: banks design processes that provide quick and clear communication for the victims of fraud after the fraud has been detected and are prepared to cooperate with other institutions to support the appropriate assistance of victims. Banks assess the circumstances of each detected fraud individually and consider the due care practices in assisting victims.
- Staff competence and training: banks consider it important to have the necessary resources for combating fraud and the competence of staff involved in combating fraud. Each bank ensures the continuous development of knowledge of the fraud prevention teams and other relevant structures, including the customer-facing. Knowledge and competence development includes, among other things, knowledge of the fraud landscape, consideration of the particularities of more vulnerable customer segments, and the ability to direct clients towards appropriate assistance.
- Information exchange: banks organize their work in a manner that enables them to respond within a reasonable time to fraud-suspicion notifications received from other banks, to analyse the information received, and to apply measures to reduce potential damage.
- Reporting of violations: banks ensure that persons within the bank can familiarize themselves with the principles of the Best Practices and that suspicions of fraud and violations of the Practices can be reported confidentially and without fear of retaliation. Where internal reporting channels have not produced results, a bank employee may turn directly to the Banking Association regarding violations of the Practices. The reporting channels and procedures must comply with applicable legislation.
IV. BANKS' CONTRIBUTION TO CROSS-SECTORAL COMBATING OF FRAUD
Banks acknowledge that comprehensive combating of fraud requires addressing the entire fraud chain of events and cooperation across various sectors. Banks participate actively in the following areas, which lie partially or entirely outside banks' direct field of activity.
- Security of telecommunications: banks support strengthening the capability of telecom service providers to combat fraud. Banks contribute to the development of solutions for caller identity and number spoofing prevention and blocking suspicious calls, giving input on common fraud schemes and typologies observed.
- Social media and digital platforms: banks support actions that combat fraudulent content on social media platforms and public service providers Banks contribute to the development of r identifying advertisers and give input on the characteristics of common fraudulent ads.
- Development of the legal environment: banks support the development of a regulatory environment that provides a clear basis for applying preventive measures, including suspending suspicious transactions and establishing risk-based restrictions. Banks support and actively participate in improving legislation aimed at establishing a stronger review of the balance of the rights, obligations and liability of the parties and at regulating data exchange between the private and public sectors, as well as at reviewing criminal legislative measures and the descriptions of offences, in order to ensure the systematic and organized treatment of fraud.
- Cross-sectoral operational cooperation: banks contribute to strengthening operational cooperation across the various sectors and fostering more effective information exchange between private and public sector actors. Banks support the creation of clearer cooperation routines between representatives of different sectors.
- Data protection and security of public data: banks support measures that limit the unlawful collection and misuse of personal data, including increasing the security of publicly accessible databases. Banks contribute to clearer regulation of the obligations of data collectors and intermediaries.
- International cooperation and the European Union level: banks support the development of a comprehensive anti-fraud action plan at the European Union level and will contribute as much as possible to strengthening cross-border cooperation, including the development of international information exchange and joint investigative methods.
- Support for national coordination: banks support the idea of creating a permanent public-private cooperation platform dealing with the prevention and combating of fraud, where purposeful, continuous joint activity takes place to cover the entire fraud chain of events. Banks support establishing a key owner organisation of the fraud prevention on a national level. The organization’s remit would include managing and coordinating cooperation between the various ministries and the private sector. Banks are prepared to participate actively and constructively in the work of such a cooperation structure.
V. REVIEW AND UPDATING
The Code is supplemented and updated as necessary, including as a result of changes in the banking, economic and regulatory environment.
The action plan of the Practice’s measures is reviewed at least once a year. During the review, it is assessed whether the principles and guidelines of the Practice remain relevant and whether the action plan needs to be adjusted in light of changes in fraud trends, regulatory developments or feedback from banks.
To ensure reporting across the banking sector, members of the Banking Association regularly submit to the Banking Association an anonymized overview of fraud statistics in their field of activity. The Banking Association consolidates the submitted data and publishes an aggregated summary report that supports evidence-based policymaking and the transparency of the sector. The more detailed principles of reporting, including the structure of the data and the timeframe, are established in the action plan.
VI. APPROVAL AND ENTRY INTO FORCE
The Practice is a voluntary agreement of the members of the Banking Association, expressing the banks' shared will and guidelines in the field of combating fraud. The Practice does not constitute a legally binding contract nor does it create independent rights or obligations in respect of third parties. The members of the Banking Association confirm their readiness to follow the principles of the Practice, while retaining full autonomy in the selection and implementation of specific measures.
If a member of the Banking Association deviates significantly from the principles of the Practice, the Banking Association may initiate a discussion with the member with the goal of inquiring the reasons for straying from the best practices and establishing solutions to ensure compliance with the principles of the Practice. The Banking Association treats such situations confidentially and constructively, involving where necessary the Council of the Banking Association or committees designated by the Council, while ensuring the protection of the member's business secrets and competition-sensitive information.
Notwithstanding the updating provided for in Chapter V, the Practice is reviewed in its entirety at least every three years, or more frequently if necessary, taking into account significant changes in the fraud landscape, the regulatory environment or technological development. A comprehensive review is initiated by the Banking Association, and the results of the review are confirmed by the Council of the Banking Association.
The Estonian Banking Association Best Practices for Fraud Prevention was approved by the Council of the Estonian Banking Association on 19.05.2026 and enters into force on the date of approval.
ESTONIAN BANKING ASSOCIATION FRAUD PREVENTION MEASURES PLAN
I. PURPOSE AND SCOPE OF APPLICATION
The purpose of this Estonian Banking Association fraud prevention measures plan (hereinafter the "Measures Plan") is to set out practical and clear measures that the members of the Estonian Banking Association (hereinafter "banks") apply in combating and preventing fraud. The Measures Plan forms part of the Estonian Banking Association Code of Good Practice for Fraud Prevention (hereinafter the "Code") and specifies the practical implementation of the principles set out in the Code.
The timeframes established in the Measures Plan are set on the assumption that the relevant measures are implemented by most of the banks operating in the Estonian market whose activities include offering active current accounts.
The Measures Plan is by its nature a plan for implementing measures, not a set of practices to be adopted immediately. Technological investments require both analysis and the setting of priorities within each bank's internal work plan.
As at the second quarter of 2026, a review of the Measures Plan is planned before the end of 2026 with regard to the subsequent stages and planned activities. At the present moment, the following activities have been agreed across banks, with the aim of implementing them by the end of 2026 or shortly thereafter by most banks.
The updating of the Measures Plan with regard to the subsequent stages will begin no later than the fourth quarter of 2026.
II. FRAUD TYPOLOGIES
The Measures Plan focuses on two main fraud typologies: account takeovers (hereinafter "ATO"), in which the client hands over their authentication means and thereby enables a third party to access the bank account; and authorised push payment scams (hereinafter "APP"), in which the client manages their own account and authorises payments to third parties.
Distinguishing between these typologies makes it possible to assess whether applying a specific measure to a specific risk produces the desired result. It also ensures measurability, since the volumes of fraud prevented and of fraud that has occurred are known, and the results can be measured after implementation.
III. MEASURES PLAN 2026
The activities of the 2026 Measures Plan primarily involve lower-complexity measures whose implementation is faster, comprehensible to the public, and for which a measurable impact is expected. At the same time, the parties are beginning to develop technologically more complex and more impactful solutions that also meet PSD3-PSR expectations and whose estimated implementation timeframe is 9 to 15 months, by mid-2027 at the latest.
|
ATO |
APP |
|
Client-based review and adjustment of cash limits, taking into account the specifics of each bank. |
Client-based review of cash withdrawal and transaction limits, taking into account risk scenarios in which a client is manipulated into carrying out a transaction or withdrawing cash and passing it to fraudsters. |
|
Development and implementation of risk-based technical solutions for detecting a client's use of a new device and for applying the related control mechanisms. |
Development and implementation of risk-based technical solutions for detecting suspicious or unusual payment orders and notifying the client. |
|
Phased deployment of Smart-ID+ functionality. |
|
|
Periodic review of clients' transaction limits based on risk analysis and the client profile, in the course of which each bank independently establishes the appropriate thresholds, scope and frequency of review. |
Periodic review of clients' transaction limits based on risk analysis and the client profile, in the course of which each bank independently establishes the appropriate thresholds, scope and frequency of review. |
|
Systematic awareness activity directed at legal entities through information letters and client contacts, to encourage broader adoption of the four-eyes principle. |
Systematic awareness activity directed at legal entities through information letters and client contacts, to encourage broader adoption of the four-eyes principle. |
|
Keeping up to date and developing the technical solutions of the monitoring systems used for combating fraud, which take into account at a minimum the following factors:
|
Keeping up to date and developing the technical solutions of the monitoring systems used for combating fraud, which take into account at a minimum the following factors:
|