Skip to content

Global payments intelligence

Updated Sep 05, 2026 · 08:46 UTC

Now tracking ECB Confirms Early Pix-TIPS Study; 2028 Pilot Is Not Yet Committed
Payments intelligence
Payment Infrastructure

Visa’s New A2A Fraud Score Leaves the Final Intervention to Banks

Visa’s enhanced A2A Protect can score suspected scam payments before funds leave an account, but banks still control whether and how to intervene.

Visa has expanded its A2A Protect fraud service to give banks a risk score before an account-to-account payment leaves a customer’s account. The product could move fraud detection closer to the point where a bank can still stop or question a transfer, but it does not automate the final decision: the financial institution receiving the alert remains responsible for deciding whether and how to intervene.

The enhanced service is Visa’s first product integration of technology from Featurespace since acquiring the fraud-detection company, according to Visa. It combines transaction-level screening with optional network intelligence intended to identify scam patterns that may be difficult for one institution to see on its own.

That division of responsibility matters. A stronger signal may help a bank recognize a suspicious payment, but customer outcomes will still depend on the bank’s response rules, staffing, escalation process and ability to act before the transfer is released.

How the pre-payment score works

PaymentsJournal reported that a participating bank sends transfer details to Visa through an application programming interface when a customer initiates a payment. A2A Protect returns a score from 1 to 99 within milliseconds, estimating the likelihood that the payment is connected to a scam. The alert also identifies the type of scam the system believes may be present.

Visa says each alert includes a plain-language explanation of why the transaction was flagged. The service is designed to connect to a financial institution’s existing systems through one API. Banks that opt into network-level intelligence sharing can also receive signals about emerging scam hotspots and coordinated activity across the wider payment ecosystem.

The product is aimed at a difficult category of fraud: transactions that may be technically authorized by the account holder but induced through impersonation, manipulation or another scam. A valid login and a customer’s approval do not necessarily mean the payment is safe. That makes the quality and timing of contextual risk signals especially important.

Performance figures need careful interpretation

Visa says A2A Protect has increased fraud detection by up to 75% during the first six months of deployment. It also says one major European bank reduced unnecessary alerts by more than 40% while improving fraud detection. PaymentsJournal separately reported Visa’s claim that a UK pilot prevented up to $460 million in losses.

These are company-reported results, not independently audited findings presented in the public announcement. Visa did not identify the bank behind the European result or publish the underlying sample size, baseline, false-positive definition or measurement methodology in the release. The figures therefore show the performance Visa says has been achieved in particular deployments; they should not be treated as a guaranteed result for every institution.

The distinction is operationally important. A bank can raise detection by flagging more transfers, but that may also delay legitimate payments and create additional work for fraud teams. Conversely, aggressive efforts to reduce false positives can allow more risky payments to proceed. A useful control must improve the balance between those outcomes rather than optimize one headline metric in isolation.

The alert is only the first control

Suzanne Sando, lead analyst in fraud management at Javelin Strategy & Research, told PaymentsJournal that the score could give banks a broader view of suspicious activity. She also cautioned that its effectiveness depends on how institutions handle alerts in real time rather than treating them only as post-transaction investigative signals.

For risk teams, deployment therefore requires more than connecting an API. Banks must decide which score ranges trigger a warning, additional verification, a temporary hold, specialist review or rejection. They also need fallback procedures for an unavailable or slow scoring service, controls for overrides, and records showing why a payment was delayed or allowed to proceed.

Those decisions should be tested against both fraud losses and customer harm. A model that identifies a scam after the payment has been released may help an investigation, but it has missed the product’s central promise of pre-payment prevention. A model that stops too many legitimate transfers can strand customers, generate complaints and weaken confidence in the payment service.

Network intelligence brings governance obligations

Visa presents cross-institution intelligence as an advantage because coordinated scams and mule-account networks can span multiple banks. Broader signals can reveal patterns that are invisible within one institution’s transaction history. The value of that coverage, however, depends on participating banks supplying useful data and acting consistently on the resulting alerts.

Financial institutions should establish what data is shared, how long it is retained, how corrections are handled and how a potentially incorrect network signal can be challenged. They should also monitor whether performance varies by customer group, payment type, transfer value or scam scenario. A plain-language reason code can support a fraud analyst, but it is not a substitute for model validation and accountable decision-making.

Because Visa and Featurespace provide the scoring layer while banks make the customer-facing decision, governance cannot be outsourced entirely to the vendor. Banks remain responsible for setting risk appetite, integrating the score with their other controls, training staff and measuring whether intervention actually prevents loss without imposing disproportionate friction.

What banks should measure

A sound evaluation should track attempted fraud detected before release, confirmed fraud that escaped detection, legitimate payments interrupted, customer abandonment, review times and recovery outcomes. Results should be compared with the institution’s previous controls and segmented by scam type rather than reduced to one aggregate score.

Banks should also test how quickly new fraud patterns enter the system, whether reason codes remain stable enough for frontline teams to use, and what happens when their own customer information conflicts with Visa’s network signal. Periodic threshold reviews are essential because scam tactics, payment behavior and institutional risk tolerance change over time.

A2A Protect may give banks an earlier view of suspicious transfers and a broader view of coordinated fraud. Whether that produces safer payments will be determined at the last mile: the policies, people and systems that translate a score into a timely and defensible action.