The Control That Never Got Digitised: Cash Withdrawals, Branch Intervention and the Scam Leg Still Decided by a Human


A scam is not finished when the customer is persuaded. It is finished when the money is somewhere the criminal can spend it, and for a stubborn share of United Kingdom scam losses that somewhere is a bundle of notes counted out at a branch counter, or a run of withdrawals drawn from a cash machine across a few days. The persuasion happens on a telephone. The loss happens at a till.
The pattern comes in several shapes. In courier fraud the victim withdraws savings and hands them to a person attending the door, usually presented as a police officer or a bank investigator collecting evidence. In the cash variant of the safe account scam the customer empties the account and redeposits the proceeds elsewhere, sometimes into an account the criminal already controls. In investment and romance cases the conversion to cash is the cheapest way to break the audit trail. In every shape the customer is coached about what to say if asked, which is the detail that matters most.
The analytical point here is uncomfortable. Detection on the digital channel has improved a great deal: firms score the session, the device, the beneficiary and the shape of the payee history, and intervene inside the payment journey with content tailored to the typology they believe they are seeing. The cash leg has had almost none of that. It remains a judgement made by a colleague at a counter, in seconds, with incomplete context, no view of the customer's digital session and a queue behind them.
Regulatory and Market Context
The formal control is the Banking Protocol, under which branch staff who suspect a customer is being defrauded can summon a police response to the branch. It has operated for years, it is coordinated through UK Finance with police forces and Trading Standards, and by every published account it prevents substantial loss and produces arrests that would not otherwise occur. It is also, and firms tend to elide this, a voluntary industry scheme rather than a statutory power. It gives a colleague a number to call. It does not by itself give the firm authority to keep a customer's money.
The reimbursement perimeter compounds the problem, and the shrinking branch network compounds it again. The Payment Systems Regulator's mandatory reimbursement requirement bites on authorised push payments made over Faster Payments and CHAPS. A cash withdrawal is not a push payment: the customer authorised nothing electronically to a third party, they asked for their own money in notes and received it. The loss is real and the criminal conduct identical, but the reimbursement route is largely absent, leaving the customer to rely on complaint handling, Consumer Duty and vulnerability arguments, and the Ombudsman's view of whether the firm should have intervened. One consequence deserves stating plainly: because industry reporting categories were built around payment instructions, cash scam losses are systematically less visible than their share of consumer harm warrants, and a firm reading only its authorised push payment numbers will conclude the problem is smaller than it is. Meanwhile the access to cash regime introduced through the Financial Services and Markets Act 2023 has preserved access through hubs and post office counters, but access to cash and access to a trained colleague who knows the customer are not the same thing. Every closure converts a counter conversation into a machine transaction, and a machine cannot ask anybody why.
What the Data Is Showing
Across the branch and cash casework TrustSphere reviewed for United Kingdom retail banking clients during 2026, the most consistent finding was about structuring rather than sophistication. Where the criminal had time, the withdrawal was almost never taken in one movement. It was split across multiple cash machine visits on consecutive days, or across a counter withdrawal and a run of machine withdrawals, in amounts sitting just beneath the thresholds at which the firms' own procedures required a conversation. In the files we examined the coaching script was explicit: victims were told the limit and told to stay under it.
That says something specific about how thresholds are set. In most of the institutions we worked with, the trigger was a single fixed amount applied to a single transaction, published implicitly through years of consistent application. It was an entirely learnable rule. The firms with materially better outcomes in our sample had moved to an aggregated view across a rolling period and across channels, so that four withdrawals below the limit in three days produced the same conversation as one above it.
The second finding concerns what the colleague at the counter has in front of them. In our reviews the typical branch screen showed balance, recent transactions and any note on the customer record. It did not show that the customer had abandoned a digital payment an hour earlier, that a scam warning had been displayed and dismissed, that a new payee had been created and left unused, or that the contact centre had spoken to them that morning. Those signals existed inside the institution and did not travel to the counter. This is the most addressable failure in the chain, and it is an integration problem rather than an analytics problem.
The third finding is about the conversation. Where firms had scripted the intervention, the scripts were close to useless against a coached customer, because they asked closed questions with obvious right answers. A customer told to say the money is for home improvements will say the money is for home improvements. The interventions that worked changed the shape of the exchange: asking the customer to explain the purpose in their own words without offering options, asking when they first heard from the person involved, asking whether anybody had told them what to say if questioned, and moving to a private room, which removes both the audience and the live telephone call.
The fourth finding is the outcome data. Where firms could measure it at all, the proportion of branch cash interventions that ended with the withdrawal proceeding anyway was high, and the recorded reason was rarely that the colleague had been satisfied. It was that the customer insisted. A control whose most common outcome is that it is overridden without a documented rationale is not a control.
Implications for Financial Institutions
The first implication is that cash has to be brought inside the scam detection estate rather than left as an operational process owned by the branch network. Counter withdrawals, machine withdrawals and over the counter encashments should generate events that reach the same decision layer as a payment, scored against the same customer risk picture. The related point is that the joining problem runs in both directions. A cash withdrawal following a dismissed scam warning should raise an alert, and a scam claim logged a fortnight later should be capable of being matched back to the withdrawal that funded it, which is how a firm learns what its cash losses actually are. Most firms already hold these events in the core banking system and have never routed them anywhere useful.
The second implication is that intervention thresholds must aggregate and must not be learnable. Firms should assess cumulative cash out across a rolling window, across channels and across the customer's own accounts, weight the assessment by deviation from that customer's established cash behaviour rather than by an absolute amount, and vary the trigger enough that it cannot be reverse engineered. A customer who has never withdrawn more than modest sums and who suddenly begins taking the daily maximum is a stronger signal than any fixed number.
The third implication is that the counter colleague's evidence base is the cheapest available fix. A screen surfacing a handful of contextual facts, that a scam warning was shown in the last seventy two hours, that a payee was created and abandoned, that an unusual credit arrived from another institution last week, turns an interrogation into an informed question. It also changes the colleague's confidence, which is the practical constraint on whether the Banking Protocol is invoked at all.
The fourth implication concerns the people at the counter. This control depends on a junior colleague slowing down a transaction that a distressed and frequently angry customer wants completed, in front of other customers, under service time pressure. Firms get the behaviour they incentivise, and branch measures that reward throughput and immediate satisfaction scores punish exactly what the control requires. Recognition for interventions that turned out to be wrong, as well as those that turned out to be right, is the mechanism that sustains it.
The fifth implication is that the shrinking network makes the cash machine the default cash out channel and therefore the default control point, and almost nobody operates it as one. Machine estates are managed for availability and cost, yet they are capable of pattern based interruption, a full screen warning at a repeat withdrawal, a requirement to complete above a behavioural threshold in branch, and referral to the contact centre. Those product decisions have not been made because the estate sits elsewhere on the organisation chart.
Conclusion
The industry has spent a decade building sophisticated detection around the electronic payment instruction, and criminals have responded by removing the electronic payment instruction. Cash is slower and riskier for them, and they use it anyway, because the control at the end of it is one person making a judgement in seconds with less information than any automated system in the bank would have.
Closing that gap requires no new law, no new industry agreement and no new category of vendor. It requires cash events treated as first class detection events, thresholds that aggregate and cannot be learned, a counter screen that tells the colleague what the institution already knows, incentives that do not punish intervention, and a machine estate run as a control rather than a utility. Firms that do this will also have built the evidential record they need when the Ombudsman asks why a vulnerable customer withdrew their savings in instalments over four days without a single question being asked.
Suggested Next Steps
Route counter and cash machine withdrawal events into the same real time decision layer that scores payments, and assess them against the customer's established cash behaviour rather than a fixed amount.
Replace single transaction thresholds with an aggregated, cross channel, rolling window assessment, and stop communicating limits in ways that let a coach teach around them.
Give the branch counter a contextual panel showing recent scam warnings served, abandoned payee setups and unusual inbound credits, then measure whether intervention and Banking Protocol invocation rates change.
Audit twelve months of branch cash interventions that proceeded anyway, record the reason in each case, and report the override rate to the financial crime committee alongside vulnerability indicators.
Sources: UK Finance Banking Protocol scheme material and fraud analysis; Payment Systems Regulator mandatory reimbursement requirement for authorised push payment scams and its scope over Faster Payments and CHAPS; Financial Conduct Authority financial crime guide, Consumer Duty, guidance on the fair treatment of vulnerable customers and access to cash rules made under the Financial Services and Markets Act 2023; Financial Ombudsman Service published approach to scam complaints; Proceeds of Crime Act 2002 reporting and consent provisions; National Crime Agency and Action Fraud reporting on courier fraud and impersonation scams; National Trading Standards scams team material; Home Office fraud strategy publications; Global Anti-Scam Alliance research on victim coaching; TrustSphere Risk Index, April 2026.
Companion vendor assessment: today's TrustSphere Risk Index post assesses Daon against this problem. Read it at www.trustsphere.ai
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments