• Sep 25, 2026
  • 26 min read

Building Trust in Africa’s Digital Economy | "What The Fraud?" Podcast

Dive into the world of fraud with the ‘What The Fraud?’ Podcast! 🚀 In this special episode, recorded at Seamless Africa, we sit down with leaders across telecoms and digital banking to unpack how fraud works on the ground in Africa and what it will take for the industry to stay ahead.

CHANTAL LAMPRECHT: We're here at Seamless Africa, surrounded by some of the people who are building and shaping Africa's rapidly changing payments, banking, fintech, and digital commerce ecosystem. Welcome to What The Fraud?, a podcast by Sumsub, where we go behind the headlines to understand how fraud actually works, how it's changing, and who is fighting it.

I am Chantal Lamprecht from Sumsub, and for this Seamless Africa special, we're coming to you from the Sumsub stand here in Johannesburg. Today, I'm speaking with leaders working across telecoms, crypto, enterprise risk, iGaming, and financial crime to understand what the fraud landscape looks like on the ground in Africa and what organizations need to do next to stay ahead.

So let's get into it.

We have telecom operators that are now sitting underneath almost every digital interaction, from connectivity and cloud infrastructure to identity, payments, and enterprise security. As African businesses digitize faster, that makes telecoms an increasingly important part of the trust and fraud prevention ecosystem.

Kgabo Seopa, Vodacom Business

I am joined by Kgabo Seopa, Managing Executive of Product and Solutions of Vodacom Business. Kgabo, welcome. It is so wonderful to have you here with us today. Before we get into the heavy stuff, I just wanted to ask you, how are you doing today? How are you finding the energy at Seamless here today?

KGABO SEOPA: It's a very beautiful day.

The weather's good outside, and I see fantastic people here. I've interacted with a few people already, and the knowledge is vast. I appreciate the moment.

CHANTAL LAMPRECHT: That's amazing. Thank you so much for that. Yes, we just love the energy that we're feeling in the room and great conversations.

Now, I've got a few questions that I want to ask you today, Kgabo, and let's dive into it. So, as telecom operators have become a critical part of the digital economy, how has the role of telecoms evolved from simply providing connectivity to becoming a trusted partner in helping businesses operate securely?

KGABO SEOPA: A very good question, and thank you for that question. So, I'm gonna talk from Vodacom's point of view and also from the industry point of view and what we've been seeing, more especially in South Africa and Africa in general. We are in a process of migrating, or let me say, transformation from being a telco to a techco.

What that entails is that not only do we play as just a mobile and connectivity provider, now we go up the stack where we add value into the customer's digital journey. It entails a lot of things, and then cybersecurity is the fundamental part of that particular journey. So what we have seen from a cybersecurity point of view, and more especially from a fraud point of view in South Africa or globally, is that more than 2 trillion US dollars is spent by organizations and individuals each year on fraud, and that fraud comes in a multitude of ways.

So what are we doing ourselves as telco providers or techco providers to assist organizations in doing that? Gone are the days where we just provide you with the connectivity and leave you alone. We become part of your digital journey. And then the way we're doing it is in such a way that we give you...

We have solutions, cybersecurity solutions. We have a cybersecurity practice whereby we are able to give you advice as to exactly what to do on top of what you wanna do. So what we are doing from a telco point of view and techco point of view to assist our enterprise customers is just to give them advice every single step of the way, and a lot of times we give them that advice for free.

They can come to us any time with their security posture, and we'll do a free assessment and tell them exactly where they're coming from and where they're going.

CHANTAL LAMPRECHT: Wow, Kgabo. That is such a fascinating shift that we're seeing at Vodacom Business, and you're just moving from your enterprises to actually truly protecting them.

That is really remarkable what you guys are doing. And speaking of this rapid evolution, Kgabo, as organizations accelerate the adoption of AI, because we can't speak about this and not bring in AI, cloud as well as digital services, because they come as a package, where do you see the biggest opportunities and also the biggest vulnerabilities for businesses across Africa?

KGABO SEOPA: The biggest opportunity is where organizations and individuals in the organization can be able to utilize AI to get things much quicker. And most importantly, from a cybersecurity and fraud point of view, we have seen the utilization of AI to analyze and get to understand the security vulnerability in the organizations, and they can be able to act fast.

But it's more like a mouse and a cat situation. The mouse is grazing out there, knowing very well that the cat might be looking after me at any point in time. When the cat sees the mouse, it knows that this mouse is agile enough, I might not catch it. I need to act in a different way.

So the organization knows very well that every single day they have been targeted. The people that are targeting them know very well that these guys know that we are targeting them. So what we have seen in a crossfire is that the organizations are utilizing AI to become much faster in eliminating the risks from a cybersecurity point of view, but also the cybersecurity fraudsters.

And they're also watching them utilizing AI to analyze their movements, to analyze exactly what they're doing, and to come with countermeasures.

It's AI against AI at the end of the day, and then it's a war that no one is a winner at the end of the day.

I'll give you a typical example with a South African bank, to say the fraudsters are always looking at the patterns, and then they leech on those patterns to gain an advantage at the end of the day.

There's a bank in South Africa. There's a scam in South Africa called a 99 rands scam. So this particular bank was sending the notification to their customers only once you hit 100 rand on a transaction. So, knowing very well that at the end of the month there's a lot of transactions that go through, these guys would then put in their transaction at the end of the month for 99 rand.

Therefore, they don't get a notification because it's just 99 rand. And then it took a long period of time for the organization to then realize that they've been scammed. And that time, the scammers are gone. So it is that kind of a cat-and-mouse situation where we continuously need to learn and continuously need to be agile in doing things.

What I've seen is that, and from a Vodacom point of view, we are saying that organizations should focus more on what they do best. If you are a retailer, it would be best to partner with a cybersecurity organization that focuses much more on cybersecurity, and then give you proper advice and proper mechanisms for you to be able to block this.

CHANTAL LAMPRECHT: I agree with you totally. It is a lot of shared responsibility when we're talking about this. But because we know fraud today rarely affects just one organization, it often spans across multiple verticals like banks, telecom, merchants, and technology providers like you mentioned now. What does effective collaboration across these sectors need to look like, you think, if we were going to stay ahead of increasingly sophisticated fraud?

KGABO SEOPA: A great question. Let me step a little bit back so that I can unpack this question more nicely. If you look at South African capability, when you report a fraud at the police station, the first thing the police would ask you is to say, "Did they take your wallet? Did somebody physically do something to you?"

Because the capability and the capacity to investigate the fraud is at a different level, which is at the Hawks level. At the basic level where people are just saying, "I've been defrauded 99 rand," or whatever the amount, they don't necessarily have that capability. So it means that a lot of the masses in our country are left stranded because we don't have capacity and capability to then go and investigate.

I'm gonna give you a typical example of what the banking sector have done. The banking sector have got an organization, SABRIC, where they've got a board and all the banks come together. They then organize themselves in such a way that they share knowledge on cybersecurity and risk and fraud and all those kind of things that are encompassing their existence.

And because of that, a whole lot of... We have seen a move where they're moving the needle in the right direction from a fraud point of view, and they share notes. We don't have that with the merchants, with the telecoms, and we don't have that for a multitude of reasons coming from maybe a competition point of view.

But because we don't have that, we don't share notes, and because we are decentralized in a way and we are distributed, it's easier to attack. Because we don't have a single body that gives people information about what's going on at the ground, and people learn from it and prevent themselves against the same thing, and that is a huge vulnerability.

My wish, and from Vodacom's point of view, if we could get to a level where we organize ourselves like SABRIC in the banking sector, where we then say that we have an organization where we can share notes and share exactly how we can be able to prevent against all these ever-evolving vulnerabilities that we see and the attacks that we see in the industry.

CHANTAL LAMPRECHT: I agree with you. We hear a lot about different organizations saying that collaboration needs to happen across sectors more often, and I love that emphasis on working together. We are really stronger when we collaborate together, Kgabo. But of course, implementing that on a day-to-day level isn't always going to be that easy.

So, working with enterprise customers across industries, what are the biggest challenges businesses face when trying to balance seamless digital experiences with security and customer trust?

KGABO SEOPA: I think it's the ever-evolving cost of digital migration, because security sometimes is seen as a nice-to-have until you get hit, simply because we don't have bodies that tell people to be aware and be careful.

In South Africa, everyone is aware that we've got crime. When you're driving a car, anybody, it can get stolen. We know that we've got crime to an extent that in the middle of the night somebody can jump into your house, and therefore we prevent against that. And because of the lack of knowledge on cybersecurity and the lack of awareness on cybersecurity, both at the consumer and the enterprise level, we then tend to see these lots of incidences that are happening, and sometimes, depending on the value, people are not even afraid.

People are afraid to even report them. Big organizations have got responsibility to report them, but small organizations, and depending on the amount, and even individuals, they don't necessarily have to report it. So because of that, we've seen a huge number of incidents that are happening in the market.

And because of that lack of collaboration in the market, there's no way to cap it in a way that we can be able to see effective change at the end of the day.

CHANTAL LAMPRECHT: Finding that sweet spot is definitely the ultimate goal for many of us, but not an easy task at all.

CHANTAL LAMPRECHT: But Kgabo, if we look towards the horizon, let's look a little bit ahead.

What do you think will define the organizations that customers trust the most in an increasingly digital economy? And what should business leaders be investing in today to be able to get there?

KGABO SEOPA: We need to invest more in the tools and sharing of knowledge and customer awareness, because a lot of customers, they don't realize the danger that is sitting outside there until it's too late.

So I'll give you a typical example, more especially, it's gonna also answer your previous question and give more context. When you look into Safaricom in Kenya, they are responsible for more than 80% of the economic transactions in the country, utilizing a digital platform, fintech platform called M-PESA.

So it means that if you don't have M-PESA, it's more like you can't breathe. It's like an oxygen of the country, the entire country. And what we have seen is that a lot of people, consumers, they don't have the knowledge of what exactly could happen to them without cybersecurity and without the knowledge from a fraud point of view.

Let me give you an example. In South Africa, almost every single day I get more than 20 SMSs for fraud. The phishing attack on my emails, sometimes enterprise emails. So as an organization, an attacker would go and hijack your emails and be able to see all the emails that you send out. Reroute these emails to their intermediate mailbox so that they can send them out. You have done the work, now you're sending out an invoice. Through that intermediary, they are now able to go and change the invoice banking details to their own banking details and send it to the customer. Now, when the customer pays, they know that you've done the work.

Everything is legit except the banking details. Now, when they send you the money, then it goes to the wrong account. As you know, with the mule account, there's somebody watching this account at any point. As soon as the money gets in, they send it out maybe to crypto. And once it goes to a crypto account, it's more like into the dark cloud where you don't know what's going on.

In South Africa, we don't have the capability and the capacity to investigate it because that needs a national-level investigation. We as individuals can never be able to investigate it because it's not an account which isn't sitting in South Africa, and it's a multinational account. That is just a typical example of what we are seeing in the industry and in the market right now.

Suggested read: KYC Solutions Across Africa: Local Providers, Global Platforms, and the Cross-Border Gap

Lack of knowledge of the possible attacks and the fraud posture, because they come in many, many, many ways from an enterprise point of view and from a consumer point of view. We certainly need to educate our people on the ground. We as techcos, we have already invested in a lot of tools and security products and solutions that we can be able to offer to our customers.

So the more the customer comes to us for us to then look into the security posture and give them proper advice and also give them the solutions, the better. So at Vodacom Business, we do this for free. Any customer can come to us and say that, "Guys, I'm not sure what is my security posture. Can you please do an assessment for me and give me a report and give me an advice to say where to from here? Like, where am I sitting today? Where do I need to be, and what are the gaps?" And we start on a journey to close those particular gaps. So we've been doing that in the market, and we offer these services for free for our enterprise customers to come in.

And then as soon as we solve for our enterprise customer, we know that our enterprise customer then serves our consumers. Then it means at the end of the day, we are solving for the ecosystem at the end of the day.

CHANTAL LAMPRECHT: Well, fraud is becoming so sophisticated, Kgabo, and it's like you've been saying now and we've been chatting about, how do you know what the risks are or what the fraud is in your business if you've got no visibility into that?

So it is amazing the work that you are doing. Kgabo, thank you so much for joining us on this What The Fraud? Podcast today. It was an honor to have you here. We wish you all the best going forward. It's a pleasure.

KGABO SEOPA: It's a pleasure. All the best, and thank you for having me.

Pulane Motlokoa, MTN

CHANTAL LAMPRECHT: Mobile money and digital services have become critical infrastructure across the continent. At that scale, risk cannot simply be added at the end of a product launch. It has to be built into how services are designed, governed, and operated across very different markets. With me now is Pulane Motlokoa, Group Senior Manager for Enterprise Risk at MTN. Pulane, welcome. It is so lovely to have you with us today.

PULANE MOTLOKOA: Thank you so much, Chantal, and thank you so much for inviting me onto your podcast.

CHANTAL LAMPRECHT: It is amazing to have you here with us. How's your day been so far?

PULANE MOTLOKOA: It's been exciting. I'm loving it. So I've been to a couple of the stalls, and a lot of learnings have been shared so far. It's only 11:00 AM. That's how fast the time is going. You know, when you're having fun, time just flies.

CHANTAL LAMPRECHT: That's true. I don't know. That's lovely, and I'm so excited we're gonna jump in. And now there's so many amazing questions that I want to ask and get from you today.

So you've spoken about embedding risk early in the design of new products rather than treating it as a final checkpoint. What does risk by design actually look like in a fast-moving fintech environment, and where do organizations still get it wrong today?

PULANE MOTLOKOA: Lovely question. So with us at MTN Fintech, we really start involving risk management from the beginning stages of a product.

So when the product is still an idea, we get our risk teams, our compliance teams, our financial crime teams collaborating closely with the technology and product teams, the information security teams, just to ensure that we are building these safe controls or these secure controls into the product.

And it really helps us a lot because by the time we launch the product, we're faster. It gives us that speed to market, and we don't have multiple revisions or multiple iterations of a product because we spent the time, we've collaborated with all these different functions to ensure that the product will not fail when it gets to market.

The thing about fraudsters is that they don't wait for the product to become mature. As soon as the product is launched, that's when they attack.

So, we invest a lot of time, a lot of teamwork into ensuring that the product is secure. Because as you know, with mobile money and fintechs in Africa, trust is a really big thing, and it is a currency for us.

We work with a lot of vulnerable consumers, so we work with the underbanked, informal business sector, rural areas. And so that trust is a really big thing for us, and we invest a lot into that. But I think, like, something that organizations are getting wrong is when they treat risk as sort of a compliance check, and they don't see it as a strategic asset.

They don't see the risk management function as a strategic asset. They see it more as like a gatekeeper, and they don't appreciate the value that it can bring in. So with us it's always, the question isn't can we launch, but rather can we launch safely, responsibly, and sustainably.

We build in those controls from the start, and then we actually see that innovation for us moves a lot faster, and we're not constantly stuck fixing problems after launch.

CHANTAL LAMPRECHT: Thank you so much for that. I absolutely love that philosophy. Treating risk as a foundational building block instead of an afterthought, right?

Especially when we talk about the scale that you operate at. Mobile money has become a critical financial infrastructure across Africa. As these ecosystems grow in scale and complexity, how is fraud and the risk landscape changing with them, and which emerging risks concern you the most?

PULANE MOTLOKOA: The fraud landscape is definitely evolving.

Previously, you know, it used to be very opportunistic, very simplistic scams. But now these days, especially with the advent of AI, fraudsters are now becoming very good at exploiting trust, right? So the social engineering and the impersonation fraud – we've seen a huge spike in that. They don't really attack the technology as much as they used to. They attack people and emotions and the psychological aspects around that more. So we invest a lot in educating our customers as well, protecting them. We found that making that investment in protecting our customers is just as important as protecting our technological assets and our platform itself.

CHANTAL LAMPRECHT: I like that view, like the human behind it, especially with the social engineering. So AI is giving organizations new ways to detect anomalies and respond to threats in real time.

But at the same time, fraudsters have access to that same technology. Do you think AI is currently shifting the advantage towards defenders or attackers?

PULANE MOTLOKOA: You know, I think right now we are in a temporary phase where it's benefiting both. So both are becoming more powerful in a sense.

Attackers are leveraging AI, as we spoke about earlier. Their phishing attacks are becoming more convincing. Their synthetic identities that they're building, the deepfake voices, and more personalized scams that, you know, people unfortunately are falling for. But I think the differentiator isn't necessarily AI itself.

Suggested read: How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026

It's more about how you combine the AI with trusted data, sound governance, and that human expertise. So that's what will set us apart from, you know, the wrong side of AI. But I think one mistake that organizations make is believing that AI can be the silver bullet that just fixes all of their problems.

So our emphasis that we place is really on the sound governance, customer education, implementing those robust controls, and using our professional judgment and that human element, things like empathy that, you know, cannot really be programmed into AI or machine learning. But it really does help us as well in analyzing those huge volumes of transactional data that we have.

We're able to identify suspicious transactions much faster. We're able to detect risks that might have not been visible to the naked eye. And that has been a real game changer for us. And then we couple it with strong governance principles and keeping the human in the loop at all times. That can really give us the edge long-term, we believe.

And also long term with financial institutions, if we collaborate and cross-collaborate, that will give us an advantage over the fraudsters. Because although they innovate quickly, they're not able to... They're not regulated, right? So they're not able to build that collective defense mechanism that we can, and they won't be able to replicate it as fast as they think they can.

CHANTAL LAMPRECHT: That is such a thoughtful way to look at the AI dynamic. And you have to manage that dynamic across a very diverse landscape, Pulane. You oversee risk across multiple African markets with very different levels of fintech maturity and regulatory environments. How do you build a risk framework that is consistent enough to protect that wider ecosystem we're talking about, but also flexible enough to work locally?

PULANE MOTLOKOA: Great questions. Thanks, Chantal. So our approach is really not to standardize the processes behind. So we standardize principles. So we have very high expectations for all our markets around customer protection, fraud prevention, financial crime compliance, business resilience, governance. Those are consistent, and those are non-negotiable.

But then we do allow for flexibility in terms of how those outcomes are achieved because, I mean, as you can imagine, the regulatory environment in Ghana is very different to Côte d'Ivoire or Uganda or Rwanda. So the customer behaviors, the infrastructure capabilities in those various markets and the regulatory expectations vary significantly as well.

What we've seen is that if we try to impose the exact same controls everywhere, then we end up creating inefficiencies and sometimes even introducing new risks.

So what we do is just establish the minimum standards, common risk appetites, which is always low. We have zero tolerance for fraud, financial crime.

We want to protect our customers. Like we said, trust is at the core of what we do. But then we allow the markets to tailor implementation to their specific environment. Our goal is not uniformity, but our goal is to have consistency across outcomes. Our goal is really to balance, because we wanna keep current with the global standards as well, but we need to also ensure that it's nuanced to our local realities.

Because a lot of the times we find that the global standards do not really cater for the realities in Africa. They've been developed in first-world countries, and they don't really take into account some of the infrastructure challenges and the varying levels of digital literacy that we have here in Africa.

So we want to ensure these frameworks are robust enough, but still practical enough for the markets to be able to execute them.

CHANTAL LAMPRECHT: I love that. And then finding that perfect balance between standardizing and respecting those local nuances that you mentioned is truly an art, and it connects directly to the end user at the end.

So there's often a perception that stronger controls mean more friction, though that's, like, a swear word in our industry, and slower innovation. But from your experience, how can organizations protect customers from fraud without creating barriers to financial inclusion and growth?

PULANE MOTLOKOA: I think, that is one of the biggest myths in our industry, right?

Because customers don't really choose between security and convenience. They expect both. With us, you know, the best controls that we have are actually invisible. So we have things like device binding, behavioral analytics, transaction monitoring, adaptive authentication, and AI-driven fraud detection, which improve security without forcing customers through cumbersome processes.

So, we also have moved away from a one-size-fits-all approach. We realize not every transaction carries the same level of risk, so we use risk-based controls to apply stronger interventions where risk is higher, while keeping low-risk journeys as frictionless as possible.

As we said earlier, these are not opposing objectives. Financial inclusion and fraud prevention are not opposite or competing priorities for us, right? In fact, they depend on each other. If the customers lose trust in our platform, then our app adoption will suffer. And then if the controls are too restrictive, bearing in mind the varying levels of digital literacy and so on, then access to this financial inclusion objective that we're striving so hard for, that suffers as well.

So we believe that organizations that build around trust and keep customer-centric practices at the core of everything they do and in the design of their products, those are the companies that are gonna thrive in the future.

CHANTAL LAMPRECHT: Thank you so much, Pulane. Really appreciate you sharing your perspectives with us. It was really an honor to have you here with us today.

PULANE MOTLOKOA: Thank you so much, Chantal. I really appreciate the opportunity to be on this platform. It's been such a fun conversation. You've been such an amazing facilitator, host. Thank you so much. Looking forward to the next one.

CHANTAL LAMPRECHT: Thank you so much, Pulane. Really appreciate you.

Bonolo Sebolai, GoTymeBank

CHANTAL LAMPRECHT: Digital banks are built around speed and simplicity, but that same immediacy creates a fast-moving fraud environment. As AI becomes part of both fraud attacks and fraud prevention, banks have to strengthen detection and decision-making without losing the seamless customer experience that defines digital banking.

I am joined by Bonolo Sebolai from GoTyme Bank, where he leads fraud prevention. Bonolo, welcome. It's truly lovely to have you here with us today.

BONOLO SEBOLAI: Chantal, thank you very much for having me. A pleasure to speak to you, to speak to everyone that's going to be listening to this.

CHANTAL LAMPRECHT: Awesome. Thank you for making the time once again. How's your day been so far?

BONOLO SEBOLAI: Busy day, and that's the world of fraud. There's no time where we are calm. But calm, I think we need to look at it in a positive sense. We're always asking ourselves, "What could the fraudsters be doing? What could they be trying today? Are positive signals really positive signals?"

And I think that's what fraud and the world of fraud makes you want to always question. Are you aware of what's going on in your ecosystem and the environment? But other than that, it's been a good day. My team is doing the work that it needs to do to make sure that our customers are protected holistically.

CHANTAL LAMPRECHT: That's lovely, and I can't wait. We've got some great questions that we want to dive into in the world of fraud at GoTyme Bank. So Bonolo, fraud in digital banking is evolving incredibly quickly. From what you're seeing today, which threats are changing fastest, and what should banks be paying much more attention to?

BONOLO SEBOLAI: If you look at fraud, and I think to probably rephrase it, I don't think that fraud is changing holistically or rapidly just in digital banking. I think it's changing in the ecosystem of banking as a whole, the financial institutions globally. So whether you're a brick-and-mortar business or whether you're a digital bank, we face the same kind of attack vector and the surface base, and we all have something that we wanna keep precious to us, and that's our customer.

We're all facing the same things, but how it's executed probably differs slightly. And one thing that we continuously see, I wanna use a very simple analogy. If you go back and your doctor says, "You need to eat your vegetables, you need to eat, have a balanced diet, have water," that is part of what we call a balanced diet and what we want to do, and that's the same thing with fraud.

Why I'm pointing to that is the thing that is changing and evolving the most is what we say is a balanced diet within the world of fraud. Human psychology is the one thing that when we sell to people, it's also the thing that is being manipulated by fraud. And we're seeing that what AI is doing and what technology's doing is that it's making the manipulation of human psychology far easier.

We're seeing people fall for the very age-old scams, whether it's vishing, it's smishing, it's phishing. Those general attacks look 10 times better. They are so much easier. You don't need someone who's sophisticated, who understands how to do these things and how to build them and piece them together. You just need someone who can write a simple prompt.

And what we're seeing with technology and just the general sale of technology is that you don't need to even know that. What you need is for you to go to a platform that can say, "Put in this prompt, and you'll get this general outcome." So what we need to now start thinking about is how does technology make the very same thing that we're trying to protect far easier to manipulate?

And this is always going to change. Of course, there's gonna be the guys that do a lot more sophisticated things, where we see remote access Trojan attacks and how these are trying to penetrate people's devices without them even knowing. But at the end of the day, the key thing to everything in fraud is actually human psychology.

I would even say that 80% of general attacks are linked to the change and manipulation of someone's psychology or their understanding of something. And that's where we think the big vector is always gonna transition to. If we can solve for that, if we can help people understand and identify things better, it's gonna help them, but it's also our duty on our end to put the tool sets for the customers to be able to use that for them to be able to find it.

CHANTAL LAMPRECHT: That's very interesting. It is the social engineering, that manipulation, emotional manipulation that happens. You know, we need to have a lot more education for our customers out there, and it's scary how fast things are actually moving, which is why tools that we use are also so important.

So you've spoken about the importance of meaningful integration with AI into fraud prevention. Rather than treating it as a standalone solution, what does getting that right actually look like in practice?

BONOLO SEBOLAI: I think AI as a whole, we do know that it's a tool. It, like mathematics that powers AI, like computers that power AI, it's about how you want to use it. A couple of years ago, people said that if you didn't know Excel, you were gonna be out of the industry relatively soon. And what we're seeing now is that even your Excel skills are no longer something that is gonna set you apart. AI can solve for that. So what we need to be thinking about is how can we vertically integrate AI as part of our security stack?

It's not about us being able to just detect where AI is being utilized. It's also for our customers to be able to know that this might be an AI-powered attack. So integrating AI meaningfully means that we must be able to use it in the background where our customers don't need to know that we're using AI.

They just need to know that they are safe from AI attacks. But also, should the customer want to understand something better, are we putting the toolsets in front of the customer so they can pick one out? If I see how AI is going to evolve and how people can utilize AI, can our customer differentiate between when they're speaking to a human versus when they're speaking to an AI bot that is reading a script that has been provided to it?

So vertical integration is not about us just looking at it from top level or below level, it's about saying both sides, how do we make sure that it's embedded in our products so that it's actually helping us identify fraud quicker? It's helping us identify suspicious behavior quicker. Because the sooner you pick up on the attack vector, the better and the quicker you can be able to stop it.

But also now, when once you've solved it, the onus also then shifts to a certain degree to the customer. What will the customer do on their end to be able to say, "I'm not falling for this"? Because we can protect and block everything as much as we possibly can, but then if the customer still believes that they're speaking to someone that they trust because it's been powered by AI, what have we done on our side to make sure that the customer can say, "Hold on. This is actually not the person that I think I'm speaking to"?

So we need to make sure that the toolsets work both in the background and in the foreground, and allow the customer to not care that there could be an AI attack on the bank. They must know that we're solving for it. But then they must also be able to be, with confidence, say that should anyone try something, I can just use those tools that my bank has given me, and that can tell me that I'm dealing with something that could be AI-based. So that's how we should be thinking about AI.

CHANTAL LAMPRECHT: I strongly and completely agree with you there. It really has to be baked into the strategy. Like you mentioned, it's not just a simple add-on or stick-on. But that leads me to something a lot of people worry about. Fraudsters now have access to many of the same AI tools as the banks.

Do you think AI is currently shifting the advantage toward the fraud teams or the fraudsters? And what will determine who stays ahead?

BONOLO SEBOLAI: So what I do think, and if you think about the question, it's actually a really good one. What I do think AI is doing, and the cost of AI, because what we're seeing is that we're now battling for the cost of the token, right?

So the cheaper the cost of the token gets, the easier it is for people to have accessibility to those very sophisticated models. But what we're also seeing is that the very simple models, or what people would deem the low-tier models, are getting even better. So what AI is doing is it's trying its best to give people access to information as quickly as possible, but also access to skill sets that they wouldn't necessarily have.

So what this then says is that AI is leveling the playing field, not intentionally, but that's what is happening. It's a consequence of this technology. But where we think we have the advantage is that we know the customer. Our relationship is a one-to-one relationship with our customer. Irrespective of how many customers there are, we need to say that we understand from a customer-base perspective.

How does she use her account? Fraudsters don't know that, because we've protected you. We've protected the information that we have about you, and that is part of our contractual obligation and relationship that we have with our customer. If we say, and this is what we do say as GoTyme Bank, that we wanna be the most loved bank by 2030, we know very well that it also means that we must be the most trusted bank by that particular point in time.

And in fraudsters getting accessibility to these tools, we need to make sure that whilst they can use them to try and mimic us as much as possible or to try and create a new attack surface that we haven't necessarily thought of, we need to be far ahead of them, 2 steps, 10 steps, 20 steps ahead of them, and that's why I'm saying that it has to be a vertically integrated strategy.

What experimentation are we doing on our side to say, "If I was a bad guy, what could I do?" So I don't think the powerful AI companies in the world, Anthropic, Google, OpenAI, are saying, "How can we power fraudsters?" I think what they're saying is, "How can we make work a whole lot easier for everyone?" But it's the application that becomes dangerous now.

What are people doing? So I don't think that they're giving them the advantage. I think they're giving them information and accessibility to things that they wouldn't necessarily have, but I do think that we still have the secret sauce as financial institutions. We have the relationship with the customer.

We know what the customer does on a day-to-day basis, and we need to use that to our advantage to protect our customers to the best of our ability, even at the expense of a good customer experience, if we believe that this is gonna affect you financially. We have to make sure that what is yours remains yours.

CHANTAL LAMPRECHT: Wow, Bonolo, I love the emotion behind it, that you mentioned that you want to be the most loved bank by 2030, and putting your customers first, even at the expense of losing sleep at night over how you guys are doing it in the background. Digital banks are built around speed and simplicity, but stronger fraud controls can easily introduce friction.

How do you protect customers without undermining that experience that makes digital banking attractive in the first place?

BONOLO SEBOLAI: Of course, we don't want customers to say, "Yes, I'm safe, but for every payment I need to make, I need to put my face there. I need to go scan a fingerprint." And this is where we are being the custodians of trust for the customer. But what we also don't want to be is the bouncer that says, "We will say what you can do and what you can't do." The point is, by understanding the customer better, you should be able to know what friction this customer needs.

So it's not that friction is bad. It's bad friction that is bad. So the wrong friction at the wrong time is gonna create a very bad customer experience. What we want to do, and what we try to do to the best of our capability, and we're continuously gonna get better at this, is know when we should put something in front of Chantal or Bonolo or any other customer that utilizes our services and our bank to say, "We think that this should be some form of friction, and we need to then scale the friction accordingly.

Some things could be very, very quick, but the risk is that the world is moving faster. We want instant payments, and instant payments are becoming the norm. So how do you make sure that you're doing the risk checks in the background to say that we've secured this payment, and we trust that everything about this payment is correct?

And that's where you need to be able to know how to put certain things in front of the customer to continuously test whether this is how the customer is acting and behaving. But if the customer's behavior changes, you must also adapt your models that tell you what kind of friction you need to put in front.

So it's a seesaw at this particular point. If you go too far down one particular point, you're gonna create a very bad customer experience. But sometimes a bad customer experience when we know very well that we have the right information that is telling us that this isn't something that we should let through should be something that we need to do, but it must be an edge case.

It mustn't be the norm. Knowing when to do it and how to do it becomes far more important than just the fact that you have the capability of doing it. So that's how we need to think of friction.

CHANTAL LAMPRECHT: Wow, that becomes a delicate balancing act at the end of the day. But let's look a little bit ahead to the future.

Over the next few years, what do you think needs to change most in the way banks fight fraud? Is it, do you think, technology, data, collaboration, customer education, or something else entirely?

BONOLO SEBOLAI: No, it's all of those things, but the other part, and I think the most important part, is that product development now needs to have security at the core, and product development must not treat security as an afterthought.

So how we get better over time is that if we secure the product naturally in our design and how we've built it, it makes it a whole lot easier for us to have less friction points. Because we know that as part of us building this house that we want to sell you, we've thought about how a good foundation security-wise looks like.

We've thought about where we need to place the door. We've thought about the economics that basically come and make this thing a whole lot better for you. So intentional design is where we see the strategic or leverage points. How do we make someone think of security from the onset? If we want to sell a credit card to the customer, what controls do we have that have protected the customer?

And then on top of that, how do we think of other layered protocols that we can give to the customer? But then the key one that you mentioned is the customer education. We deal with this on a day-to-day perspective. We bank everyone who works everywhere, who's sitting at home today, who gets a salary, who gets their pension, who gets any form of support in South Africa.

Our job is to make sure that they are also aware of how the security landscape is changing. But even if they're not, are we able to make sure that as part of intentional design, we've put security as the core component, as how someone is gonna interact with this? So I think that's where we need to be looking at as a financial industry.

It's about security as a product or embedded into the product as opposed to security after the fact, and that's how things become better. And the more you educate the customer, make things easier for them to understand, the better the customer is also gonna be able to identify where things could go wrong.

We need to think of things from an overlap. It's a combination of not just marketing, but also product and security. It's all of those things working hand-in-hand to make sure that the customer feels protected and knows that they're protected, and also can leverage the tools that we give to them because we've thought about things from a ground-up perspective, and that's where I think the opportunity lies.

CHANTAL LAMPRECHT: Definitely a combination of a lot of things. Bonolo, thank you so much for joining us and sharing your perspective on the future of fraud prevention in digital banking. It was an honor to have you here with us today.

BONOLO SEBOLAI: Thank you very much. Hoping to chat with you guys very soon.

CHANTAL LAMPRECHT: Thank you, Bonolo. Have a lovely one.

That is it from us here at Seamless Africa in Johannesburg. Across these conversations, one theme keeps coming back. Fraud in Africa is increasingly connected. It moves across channels, companies, and borders, and the answer can't sit with one fraud team, one bank, one telecom operator, or one technology provider.

The organizations that stay ahead will be the ones that combine better intelligence and technology with stronger collaboration, practical risk governance, and an understanding of how real people actually use digital services. Thanks for listening to this Seamless Africa Special of What The Fraud? If you enjoyed this episode, follow the podcast and more conversations with people fighting fraud around the world.