
Embedded Finance and BNPL: Fraud Controls for Non-Bank Issuers in Regulated Markets


Embedded finance has fundamentally redrawn the map of consumer credit issuance. Non-bank providers, buy now pay later platforms, and platform fintechs now originate meaningful volumes of unsecured lending outside the traditional perimeter of prudentially regulated institutions.
Regulators have caught up. Jurisdictions across the UK, EU, Australia, and the United States have now formalised obligations for BNPL and embedded credit, and fraud controls will be directly within the supervisory spotlight.
Why BNPL Is a Distinct Fraud Problem
BNPL originations typically occur at the checkout moment with limited customer friction and decision windows measured in milliseconds. Traditional credit bureau checks were not designed for this decisioning tempo, and many early BNPL platforms under-invested in identity and fraud controls.
First payment default rates in some BNPL portfolios have been materially higher than equivalent credit card cohorts, indicating both credit deterioration and fraud exposure. Synthetic identities, account takeover, and repeat-offender behaviours are all more prevalent than in branch-originated lending.
The Regulatory Shift
The UK's Consumer Credit Act reforms bring BNPL into the scope of mainstream consumer credit regulation, with affordability assessment and treatment of customer vulnerability now formal obligations. Australia's regulatory regime follows similar contours.
EU Consumer Credit Directive updates extend information, disclosure, and creditworthiness requirements to embedded finance providers. US state-level enforcement and CFPB attention provide the most active compliance frontier for BNPL firms operating there.
Controls That Meet the New Bar
Identity verification must extend beyond name and email checks. Device intelligence, behavioural signals, and linked-identity graph analytics are essential to counter synthetic identity and account takeover patterns characteristic of high-volume digital originators.
Affordability must be demonstrable, not merely asserted. Access to transaction data through open banking, combined with consistent methodology, provides the documentation standard regulators will expect in any post-event review of BNPL lending practices.
Platform Risk and Accountability
Where BNPL is embedded in third-party merchant checkouts, clear contractual delineation of responsibility for fraud, returns, and dispute handling is essential. Regulatory focus on platform accountability means providers cannot distance themselves from merchant conduct at scale.
Merchant onboarding, ongoing monitoring, and performance scoring must reflect fraud and financial crime risk, not just commercial performance. Poor-quality merchants drive disproportionate losses and disproportionate complaints, both of which attract regulatory attention.
What Banks Providing Embedded Credit Should Prioritise
Banks that partner with embedded finance platforms should demand control parity, including KYC, fraud monitoring, and suspicious activity reporting aligned with the bank's own standards. Regulatory fines for control failures have been levied at the bank level in several recent enforcement actions.
Data sharing agreements, periodic on-site review, and technology-level assurance of fraud and AML control execution should be contractual requirements, not matters of inter-party trust. Programmes that delegate control execution wholly to platforms are at material regulatory risk.
Embedded finance and BNPL are now mainstream regulated activities. Providers, sponsoring banks, and platform partners that build mature fraud and conduct controls aligned to traditional banking standards will earn licence durability and regulatory goodwill, while those that maintain shortcuts inherited from earlier growth phases will find themselves rapidly constrained by enforcement and reputational damage.
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments