Elder Abuse Typology Referral

Elder financial exploitation is difficult for a bank because the same transaction can tell very different stories. A large transfer may be a legitimate gift to an adult child, a payment made under manipulation by a stranger, a withdrawal controlled by a caregiver, or a customer’s deliberate decision that other people simply dislike. The bank therefore cannot treat age, an unusual payment or family involvement as proof of abuse. It has to understand change, control, consent, benefit and context.

The World Health Organization describes abuse of older people broadly as a single or repeated act, or a failure to act, within a relationship where there is an expectation of trust and where the conduct causes harm or distress. Financial and material abuse is one part of that wider problem. Financial institutions usually see only a slice of the underlying relationship, but that slice can be important because banks hold transaction histories, account-access records, beneficiary data, device information and customer-contact evidence that other organisations may not have.

For financial-crime work, a useful mental model is to separate two broad patterns. The first is elder scams, where a stranger or imposter manipulates the customer into sending money, disclosing credentials or surrendering remote access. The second is elder theft or trusted-person exploitation, where a family member, caregiver, attorney, fiduciary, friend or other trusted person misuses access, authority or influence. FinCEN used this broad distinction in its U.S. analysis of elder financial exploitation. It is analytically useful, but it is not a universal legal definition. Local law determines who is covered, what conduct is reportable, which authorities receive a referral and whether a bank may delay, refuse or disclose a transaction.

Two principles should guide the whole chapter. First, older age does not equal incapacity. Customers remain entitled to make unusual, generous, risky or even unwise decisions when they have authority and the transaction is genuinely theirs. Second, customer autonomy does not require a bank to ignore manipulation or theft. When evidence points to coercion, deception, unauthorised access or misuse of a fiduciary role, the institution needs a controlled way to pause where lawful, investigate, protect and report.

Elder financial exploitation risk model showing baseline behaviour, change signals, influence or access concerns, corroboration and bank response.

Why this belongs in financial crime, not only customer service

Elder financial exploitation crosses several bank disciplines. It may begin as fraud because a scammer deceives a customer into making a payment. It may become an AML concern when stolen money is moved through mule accounts, crypto assets, remittance networks or layered beneficiaries. It may be a safeguarding concern because the customer depends on the suspected perpetrator for care, transport, housing, communication or access to banking. It may raise conduct and vulnerability issues if the bank’s own processes make it difficult for the customer to obtain help. In some jurisdictions it may also trigger reporting outside the ordinary suspicious-transaction process.

The U.S. interagency statement on elder financial exploitation, issued in December 2024 and revised by the Federal Reserve in June 2026, is a useful example of a joined-up operating model. It discusses governance, employee training, transaction holds or disbursement delays where lawful, trusted contacts, suspicious activity reporting, referrals to protective or law-enforcement authorities, permitted information sharing and participation in prevention networks. The statement does not create a universal rule or a new global compliance standard. A multinational bank should take the control ideas and map each action to the law applying to its entity, customer, product and location.

The UK framing is different. The Financial Conduct Authority’s vulnerability guidance and Consumer Duty focus on firms understanding and responding to customer needs, designing services that do not create avoidable harm and delivering good outcomes to customers in vulnerable circumstances. The FCA’s work on bereavement and powers of attorney is operationally relevant because it shows how authority, access and support arrangements can themselves become sources of customer harm when systems or staff handle them poorly. That is conduct and customer-outcome context; it is not a substitute for AML law or a universal elder-abuse reporting rule.

A mature bank therefore avoids assigning the subject to one team. Fraud, AML, branch operations, payments, customer support, legal, privacy, vulnerable-customer specialists and complaints teams may all hold part of the evidence or control response.

Age is context, not a transaction rule

Definitions of an “older adult” vary. FinCEN’s 2022 advisory uses age 60 or older for that U.S. advisory context. Other jurisdictions, laws and programmes use different thresholds or do not define the issue by a single age. A bank should not silently turn one jurisdiction’s age threshold into a global monitoring rule.

Age can be relevant because certain forms of exploitation disproportionately affect older customers and because losing retirement savings or essential income can have severe consequences. But age alone is a poor predictor of whether an individual transaction is abusive. A 78-year-old customer may be digitally confident and financially sophisticated. A much younger customer may be highly vulnerable because of disability, bereavement, coercive control or financial distress.

The better approach is to use age as one contextual variable within a broader model. The model asks whether behaviour changed, whether a new person obtained influence or access, whether the customer appears to understand the transaction, whether the beneficiary is new or inconsistent with the relationship history, whether there are signs of deception or urgency, and whether the customer still controls their own channels and credentials.

This matters for fairness. Monitoring should not punish customers for being older by placing excessive friction on ordinary payments. Controls should be proportionate to evidence, payment risk and the legal powers available to the institution.

Elder scams and trusted-person exploitation are operationally different

A scam usually involves deception by someone the customer did not previously know, or an imposter pretending to be someone trusted. The perpetrator may claim to be a bank employee, police officer, government official, investment adviser, technical-support worker, romantic partner, relative in distress or recovery specialist. The customer may authenticate the payment themselves and insist it is urgent. From the payment system’s point of view the instruction can be technically valid even while the customer’s decision is being manipulated.

Trusted-person exploitation looks different. The suspected perpetrator may already have legitimate access as a joint account holder, attorney under a power of attorney, caregiver, relative or helper. The abuse can involve unauthorised withdrawals, excessive gifts, misuse of cards, changing beneficiaries, moving investments, redirecting pensions, obtaining loans, or using authority for the representative’s own benefit. A transaction can therefore pass ordinary authentication controls because the person initiating it is genuinely authorised to operate the account, yet the use of that authority may still be improper.

These patterns require different detection questions. In a scam case, investigators often focus on social-engineering indicators, destination risk, device compromise, payment urgency and beneficiary intelligence. In trusted-person exploitation, they focus more on the customer’s historical pattern, the representative’s authority, benefit flow, conflicts of interest, account-control changes and whether funds are being used for the customer or diverted elsewhere.

A third pattern sits between them: a previously unknown person develops a relationship with the customer and gradually becomes trusted. Romance and investment scams can move from stranger deception to sustained influence over time. That is why time-series analysis matters.

What a bank can actually observe

Banks do not normally see the whole household, care relationship or medical picture. They should therefore build cases from evidence they legitimately hold rather than attempt to diagnose abuse from stereotypes.

Transaction evidence can show unusual withdrawals, new high-value transfers, rapid movement of savings, liquidation of investments, early breakage of deposits, repeated cash withdrawals, new remittance corridors, transfers to crypto platforms, cash-like spending, loans taken against assets, or payments inconsistent with the customer’s established pattern. None of those is automatically abusive.

Access evidence can show new devices, password resets, changed telephone numbers, changed email addresses, authentication failures, remote-access indicators where available, a sudden shift from branch to digital activity, new third-party authority, or several customers being operated from a common device. Access evidence becomes especially important when the customer says they did not authorise activity.

Relationship and authority evidence can show a new joint holder, power of attorney, trusted contact, beneficiary, caregiver payee or family member receiving value. The evidence should distinguish legal authority from actual economic benefit. An adult child holding power of attorney may legitimately pay care bills. Concern rises when funds move to the representative’s personal account without an explanation connected to the customer’s needs, particularly when the pattern is new or accelerating.

Interaction evidence can come from branches, contact centres, complaints and fraud calls. Staff might observe that another person answers every question, the customer appears afraid to speak freely, a companion insists on a large withdrawal, or the customer repeats a scripted explanation inconsistent with earlier statements. Staff should record observable facts, not make unsupported diagnoses such as “customer has dementia” or categorical accusations such as “son is abusive.”

External intelligence can include confirmed fraud-beneficiary data, law-enforcement requests, known scam infrastructure, mule-account intelligence, device-risk information and public warnings. External data needs provenance and confidence labels so investigators understand what is verified, inferred or merely indicative.

Behavioural change is usually more useful than a static threshold

A rule such as “alert every transfer above 10,000 for customers over 70” creates large volumes of poor alerts and risks unfair treatment. A more useful control compares the customer with themselves and then adds contextual risk.

Consider a customer who has used the same branch, paid ordinary household bills and transferred modest amounts to two family members for eight years. In one month the customer registers a new mobile device, increases daily limits, liquidates a term deposit, sends three international payments to a new beneficiary and then asks to transfer another large amount after receiving repeated calls from an unknown number. No single event proves exploitation. Together they form a coherent change pattern that deserves intervention.

Behavioural models can consider transaction size relative to history, beneficiary novelty, channel change, velocity, time of day, device trust, new contact details, cash intensity, loan or investment liquidation, responses to scam warnings and prior customer-contact notes. A strong model sends explainable evidence to a trained reviewer rather than producing an opaque “elder abuse score” with no rationale.

Peer groups can help, but they should not replace individual history. Older customers are not one behavioural segment. Retirement income, health spending, family support, travel, property sales and estate planning can all create legitimate outliers.

Trusted-person and fiduciary abuse

One of the hardest cases is misuse of legitimate authority. A power of attorney or similar mandate may allow another person to transact, but its scope, activation conditions and legal effect vary by jurisdiction. Bank systems need to store authority accurately: who may act, on which accounts, for what period, whether multiple representatives must act jointly, whether limits apply and whether the authority has been revoked or superseded.

Investigators should not assume that a representative benefiting from a transaction is automatically acting improperly. Some arrangements permit reimbursement, household cost sharing or authorised gifts. The bank should compare the activity with the legal mandate, customer instructions, normal spending and any available explanation. Where interpretation of the mandate or fiduciary duty is material, the decision belongs with the appropriate legal or specialist function rather than an investigator inventing a rule.

Warning patterns can include rapid depletion after a new authority is registered, payments to the representative’s debts or lifestyle, transfers inconsistent with the customer’s care needs, unexplained sale of investments, frequent cash withdrawals by the representative, repeated changes to contact details that isolate the customer, or refusal to allow the bank to speak with the account holder when policy expects direct confirmation.

The central analytical question is who benefits, under what authority, and does the activity fit the customer’s known instructions and interests? That is a financial-evidence question first. The bank should avoid leaping from suspicion to a legal finding of abuse.

Trusted-person exploitation flow showing legitimate authority, misuse indicators, benefit tracing and controlled escalation.

Scam typologies affecting older customers

Older customers can be targeted by the same scams that affect everyone, but some campaigns deliberately use life stage, savings profile or social isolation to increase effectiveness. Common patterns include government or law-enforcement impersonation, bank impersonation, technology-support scams, romance scams, investment scams, family-emergency scams, prize or lottery scams and recovery scams that target people who already lost money.

The bank should focus on the financial mechanics rather than the story label. A government-impersonation scam and a technical-support scam may both result in the customer moving funds to a new “safe account.” A romance scam and an investment scam may both evolve into repeated transfers to overseas beneficiaries or crypto platforms. A recovery scam may appear shortly after a previous fraud complaint and ask the customer to pay fees to recover earlier losses.

FinCEN’s 2024 analysis of U.S. Bank Secrecy Act reporting found that scam-related reports formed a much larger share of the elder-financial-exploitation filings studied than trusted-person theft. That is useful U.S. typology intelligence, not a global prevalence estimate. Reporting rules, banking behaviour, population structure and scam ecosystems differ by jurisdiction.

A useful fraud platform therefore stores scam narrative, payment destination, customer belief, contact method, device events and outcome separately. That lets AML teams identify mule and laundering networks while vulnerable-customer teams focus on the victim’s support needs.

The authorised-payment problem

Many scams succeed because the customer authorises the payment. Strong authentication proves that the genuine customer approved an instruction; it does not prove that the customer understood the beneficiary’s true identity or purpose. This is especially important for instant payments and crypto transfers where recovery may become difficult once value leaves.

The control objective is to create useful friction before irreversible value movement. Depending on law, product and scheme rules, that can include payee-name checks, high-risk beneficiary scoring, tailored warnings, cooling-off periods, transaction holds, call-backs through known channels, additional questions or specialist review.

The 2024 U.S. interagency statement notes that transaction holds and disbursement delays can be useful where lawful. That qualification matters. A bank must not invent a generic right to hold funds merely because an older customer wants to make an unusual payment. Product terms, payment law, local elder-protection law, scheme time limits and emergency exceptions need explicit mapping.

Warnings should also be tested. A generic screen saying “scams are common” is easy to click through. A more useful intervention reflects the risk actually observed: for example, a safe-account warning where the customer says a caller told them to move money to protect it. The exact wording and intervention still require jurisdiction and product review.

Scam payment intervention showing manipulation, payment intent, bank friction, independent verification and safe or unsafe outcomes.

Customer conversations: verify without taking control away

When a payment looks risky, staff need to understand whether the instruction is genuinely the customer’s and whether someone is influencing the decision. The conversation should be respectful and private where feasible. Questions should be open enough to reveal the customer’s understanding without turning staff into interrogators.

Useful questions can explore the relationship with the beneficiary, how contact began, why the payment is needed, whether anyone asked the customer to keep the transaction secret, whether the customer was told to ignore bank warnings, whether remote-access software was installed, and whether someone is coaching the customer during the call. The objective is to identify manipulation indicators, not to perform a clinical capacity assessment.

If another person is present, staff should follow local procedure on when a private conversation is safe and appropriate. Confronting a suspected caregiver in front of the customer can increase risk after the customer leaves the branch. Sending a fraud alert to a telephone controlled by the suspected perpetrator can also disclose the bank’s concern.

Banks therefore need a concept of safe contact. Case records may need to identify channels that should not be used until reviewed, while preserving privacy and ensuring restrictions are lawful. Such flags need strict access control because they contain sensitive information about vulnerability and suspected exploitation.

Capacity, impairment and consent

Financial institutions should be extremely careful about cognitive assumptions. Forgetfulness, difficulty with technology, hearing impairment, speech differences or a need for assistance do not by themselves establish lack of decision-making capacity. Capacity is a legal concept with jurisdiction-specific rules, and bank staff are rarely the authority making a medical diagnosis.

The practical banking task is narrower. Staff need to determine whether the customer can engage with the transaction process under applicable policy, whether an authorised representative is acting within authority, whether there are signs of undue influence or deception, and whether specialist escalation is required. Where the bank has a formal vulnerable-customer or capacity procedure, it should be applied consistently.

Accessible service matters. A customer who struggles with an app may appear confused because the process is badly designed, not because they cannot make decisions. The FCA’s vulnerability guidance is useful here: firms should design communications and services so customers with different needs can understand and use them. That can mean alternative channels, clearer language, additional time or properly managed third-party support.

The control should protect the customer’s agency rather than replace it automatically.

Trusted contact is not the same as account authority

Some jurisdictions or product frameworks support a trusted-contact model. A trusted contact is typically someone the institution may contact in defined circumstances, subject to consent and applicable rules. That does not automatically give the person transaction authority or ownership rights.

Systems should keep concepts separate. trustedContact, powerOfAttorney, jointOwner, beneficiary, guardian and authorisedRepresentative are not interchangeable roles. Each can carry different rights and obligations. Collapsing them into one generic “related person” record creates access and investigation failures.

A trusted contact can itself become a risk if the suspected exploiter is the nominated person. Staff therefore need a route to bypass that contact and escalate safely. The U.S. interagency statement identifies trusted contacts as one potentially useful practice; other jurisdictions and products need their own legal basis and operating model.

From alert to case: run two tracks at once

A strong elder-exploitation case runs two tracks in parallel.

The first asks: What happened financially? Investigators reconstruct transactions, access events, beneficiaries, customer-profile changes, account authorities, device history, communications and prior alerts. They trace where value went and whether linked accounts or known fraud infrastructure are involved.

The second asks: What does the customer need now? That can include stopping further loss, securing online banking, replacing cards, changing compromised contact details, obtaining an accessible support channel, contacting a trusted person where lawful and safe, or escalating to a specialist team. The bank should not wait until an AML case is complete before taking proportionate fraud-prevention steps when loss is still occurring.

The tracks then converge into separate decisions: fraud disposition and reimbursement, AML/SAR or STR decisioning, safeguarding or external referral, and account action. Those decisions should share evidence but should not be collapsed into one outcome. Filing a suspicious activity report does not itself decide whether a customer should be reimbursed. Closing or restricting an account does not itself satisfy a safeguarding obligation. Reporting a suspected perpetrator does not prove that every connected transaction was unauthorised.

Case decision lanes showing financial investigation, customer protection, AML reporting and account-action decisions with separate owners.

Evidence quality: facts before labels

Case notes should distinguish what the bank observed from what it inferred. Strong notes might record that a customer historically withdrew less than a certain amount each month, a new attorney was registered on a specific date, several cash withdrawals followed, two transfers went to the attorney’s personal account, and the customer later said they did not know about those transfers. That chronology is much stronger than writing “daughter is stealing from elderly mother.”

Evidence should include timestamps, transaction identifiers, channel, device, beneficiary information, authority records, contact notes, prior fraud reports and relevant supporting documents. If a call recording or branch observation is material, the case should reference it according to retention rules rather than rely on an analyst’s summary alone.

This factual discipline improves both customer fairness and external reporting. Protective services, law enforcement, FIUs and regulators can act more effectively when the bank provides chronology and evidence instead of conclusions without support.

Reporting and referral are jurisdiction-specific

There is no single global “elder abuse report.” In the United States, FinCEN has specific guidance for suspicious activity reporting on elder financial exploitation, and state law can also create reporting obligations to Adult Protective Services, law enforcement or other bodies. The U.S. interagency statement reminds institutions that state requirements vary.

In the United Kingdom, suspicious activity reporting follows the UK money-laundering framework where the legal threshold is met, while customer-vulnerability and conduct obligations sit in a different regulatory framework. A vulnerability concern is not automatically a SAR, and a SAR decision does not replace fair-treatment responsibilities.

Other jurisdictions use their own FIUs, adult-safeguarding structures, privacy laws and payment rules. A global bank should therefore maintain a jurisdiction matrix covering the relevant definition or scope, reporting thresholds, mandatory reporters, emergency contacts, confidentiality rules, permitted information sharing, transaction-delay powers, record-retention expectations and customer-notification restrictions.

The case workflow should call the correct jurisdictional policy based on customer location, booking entity, product and event rather than asking investigators to remember every local rule.

Fraud-to-AML handoff

An elder scam often exposes criminal infrastructure beyond the victim’s account. The beneficiary may be a mule, shell company, crypto off-ramp, money-service business or account controlled by a wider network. Fraud teams tend to focus on stopping the victim’s loss and attempting recovery. AML teams need the beneficiary and network evidence for suspicious-activity analysis.

A good handoff contains more than a fraud code. It should include the customer’s explanation, scam type, contact method, payment references, destination accounts, device or session indicators, recovery attempts, linked victims where known, and whether the customer may have been used to receive or forward funds.

Repeated victimisation matters. FinCEN’s advisory notes that older adults can be targeted again after an initial loss, including through recovery scams. A prior confirmed scam should become a protective signal, not a reason to blame the customer. Future high-risk payments may warrant tailored intervention consistent with law and customer consent.

Recovery and customer remediation

Speed matters after a scam or unauthorised transfer. Payment operations may attempt recall, beneficiary-bank contact, card dispute, account freeze at the receiving institution, or other rail-specific recovery measures. The exact tools depend on payment rail, scheme and jurisdiction. AML investigation should not delay urgent recovery action.

Customer remediation also involves restoring control. That can mean revoking compromised credentials, re-registering secure devices, replacing cards, resetting contact details, adding appropriate alerts, reviewing linked products and checking whether the perpetrator changed standing instructions or beneficiaries.

Where the suspected exploiter holds legal authority, account changes can be more complicated. Revoking an attorney, guardian or other representative may require formal documentation or legal action. Front-line staff should not improvise. The case should be routed to the function responsible for mandate and legal-authority governance.

The customer’s remaining funds may be essential for housing, care, medicine and daily living. Restrictions that protect against further theft can also create harm if they block legitimate essential spending. Controls need proportionate emergency access and escalation paths.

Data and system touchpoints

Elder-exploitation controls are strongest when data can be joined across customer, payment and interaction systems. Useful touchpoints include the core customer profile, KYC record, account mandates, power-of-attorney register, joint ownership, trusted contacts, payment hub, card platform, digital identity service, device-risk engine, beneficiary intelligence, fraud decisioning, CRM, call recordings, complaints, case management and AML monitoring.

The architecture should maintain effective dates. If a new attorney was registered yesterday, an investigator reviewing a payment from six months ago should not see that authority as if it existed at the time. Contact details and devices also need history because a change immediately before a large transfer may be relevant.

Relationship data should identify the basis of each link. A relationship declared by the customer is different from a shared address inferred by analytics. A bank employee should be able to tell whether a link is verified, declared, observed or model-derived.

Sensitive vulnerability information needs access controls, purpose limitation and retention rules. The FCA and UK Information Commissioner’s Office have clarified that firms can process vulnerability-related data where appropriate while remaining responsible for data-protection compliance. Other jurisdictions require their own privacy analysis.

Detection scenarios that are actually useful

A practical scenario usually combines several conditions rather than relying on one red flag. Examples include a new high-risk beneficiary plus sudden liquidation of savings plus a recent device or contact-detail change; repeated transfers to an attorney or connected person after a new authority is registered; a previously low-cash customer beginning frequent large ATM withdrawals after a caregiver starts accompanying them; a customer with a recent scam loss sending money to a new “recovery” service; or several customers paying the same beneficiary after similar social-engineering stories.

These are scenario ideas, not proof rules. A property purchase, family gift, care-home move or estate-planning decision can produce large, unusual transactions without abuse. Detection should therefore produce explainable features so the reviewer knows why the case was raised. A model that only outputs risk=0.87 is less useful than one that shows new beneficiary, savings liquidation, remote-access session, repeated failed warning and prior scam case.

Failure modes banks should expect

A bank can fail by doing too little or by doing too much. Doing too little includes treating successful authentication as proof that a scam payment is safe, ignoring branch observations because they are not transaction data, failing to connect repeated beneficiaries across victims, or allowing fraud and AML cases to remain separate with no intelligence handoff.

Doing too much includes automatically blocking every unusual payment by an older customer, assuming family assistance is abuse, treating disability as incapacity, disclosing suspicions to a suspected perpetrator, or closing accounts in a way that leaves the customer unable to pay for essentials.

Another failure is poor authority data. If the bank cannot tell whether a representative is an attorney, joint holder, trusted contact or merely an emergency contact, staff can grant inappropriate access or refuse legitimate support.

A final failure is policy without operational ownership. A procedure may say “escalate elder exploitation concerns,” but if nobody owns the queue during the period when a payment is pending, value can settle before anyone reviews it.

Roles and governance

Front-line staff observe and escalate; they should not investigate family dynamics. Fraud teams assess deception, authorisation, payment risk and recovery. AML investigators assess suspicious activity and criminal-network implications. Vulnerable-customer or safeguarding specialists coordinate customer support and external referrals where relevant. Operations manages transaction status and account controls. Legal interprets authority, privacy, disclosure and hold powers. Compliance maps regulatory obligations. Data and technology teams ensure signals are captured and traceable. Product owners make sure controls work inside real payment journeys.

Governance should review more than the number of alerts. Useful management information includes prevented loss, actual loss, recovery rates, repeat victimisation, time to intervention, time to secure compromised access, false-positive friction, outcomes for customers with vulnerability characteristics, referral quality and cases where a hold or restriction caused avoidable customer harm.

Quality assurance should test whether investigators considered innocent explanations, verified authority, separated facts from assumptions, followed jurisdiction rules, documented safe-contact decisions and connected fraud evidence to AML where appropriate.

BA, architecture and testing considerations

A business analyst should translate policy into explicit decision points and data requirements. What triggers specialist review? Which payment states can be paused? Which roles may see vulnerability flags? How is a power of attorney represented? Which system owns trusted-contact consent? What happens if the fraud engine is unavailable? How is a customer safely contacted if their phone is suspected to be compromised? What evidence is mandatory before a case can be closed?

Architecture needs event history, not only current state. It should preserve when contact details changed, when authority was granted, which device initiated a transaction, what warning was shown, how the customer responded and what downstream decision was taken. Case systems need separate fields for suspected victim, suspected perpetrator, customer relationship, authority type, scam type, account action, external referral and AML reporting.

Testing must include legitimate unusual behaviour. A test pack that only contains fraud will prove the system can block; it will not prove the system can avoid age-based overreach. Negative cases should include large family gifts, property purchases, care costs, attorney-managed bills and digitally confident older customers making genuine investments.

Failure-mode tests should cover service outage, delayed case queues, inaccessible customer channels, conflicting instructions between customer and representative, cross-border accounts and attempts to bypass warnings. Audit evidence should show both the rule result and the human decision.

Composite mini case: the investment that changed everything

A fictional 81-year-old customer has held deposits with the bank for 18 years. Her activity is stable: pension credits, household bills, occasional travel and quarterly transfers to two children. Over six weeks she installs a remote-access application, changes her mobile number, breaks a term deposit and sends two transfers to a newly added company described as an investment platform. The fraud engine generates warnings, but she confirms the payments after a caller tells her the bank is trying to stop her from earning a guaranteed return.

The third payment is larger. A specialist calls using a previously verified channel and learns that the “adviser” contacted the customer through social media, asked her to keep the opportunity confidential and is currently connected to her computer. The bank follows its local procedure to stop or delay the pending payment where lawful, secures digital access and attempts recovery of the earlier transfers. Fraud opens a scam case. AML reviews the beneficiary and finds other victim reports to the same destination. The customer-support team arranges a safe channel because the new mobile number was set up during the scam.

The important point is not the customer’s age. The case becomes compelling because of the sequence: behavioural change, remote access, savings liquidation, new beneficiary, secrecy instruction, prior warnings and linked victim intelligence. The bank’s actions are also separated correctly: prevent further loss, restore account control, investigate the beneficiary network, consider required reporting and support the customer without treating her as incapable of making future decisions.

Composite elder exploitation case timeline showing behavioural change, high-risk payment, intervention, recovery and follow-up.

Practical takeaways

Elder financial exploitation is best understood as a change-and-control problem, not an age threshold. The bank looks for evidence that a customer’s normal financial behaviour, access or relationships changed in a way consistent with deception, theft, coercion or misuse of authority.

Scams and trusted-person exploitation need different investigation lenses, but both require factual evidence, careful customer contact and joined-up work across fraud, AML, operations and customer support. Age does not remove autonomy, and protection should not become paternalism.

The strongest control environment combines behavioural monitoring, beneficiary intelligence, authority data, device and access history, trained staff, safe escalation, lawful transaction intervention, clear jurisdictional reporting matrices and customer-centred remediation. When those pieces work together, the bank can protect funds and generate useful financial intelligence without pretending that a monitoring system can make the final legal determination of abuse.

Operational deep dive: authority, safe contact and evidence reconstruction

The base chapter established the core distinction between elder scams and trusted-person exploitation. In practice, the hardest cases are those in which access is technically valid but the purpose or use of that access is questionable. A bank can see an attorney, joint holder, caregiver or family member making transactions through an authorised channel and still need to ask whether the activity is consistent with the customer’s instructions, the representative’s authority and the customer’s welfare. That analysis has to remain evidence-led because the bank is neither a court nor a clinical capacity assessor.

Start with the authority record, not the family story

Before an investigator interprets a payment, the system should answer a basic set of questions. What role does the other person hold? When did that role begin? Which products and accounts does it cover? Can the person transact independently or only jointly? Are there monetary or purpose limits? Is the authority still effective? Which document or legal process supports it? These fields are not administrative detail; they are part of financial-crime evidence.

A common control weakness is to store only the current representative. If a power of attorney was registered in September, the bank must still be able to reconstruct who could operate the account in March. Effective-dated authority records let investigators compare legal access with the transaction timeline. They also prevent a current mandate from being applied retrospectively to activity that occurred before it existed.

The next question is benefit. A representative may legitimately pay the customer’s rent, care fees, medical costs or household bills. A payment to the representative personally may also be legitimate if the legal arrangement permits reimbursement or gifts. The bank should therefore trace destination and purpose before drawing conclusions. Concern becomes stronger when a newly appointed representative receives repeated personal transfers, the customer’s normal living expenditure falls, explanations are inconsistent, or the representative appears to control all communication.

The bank should preserve the difference between authority to operate and authority to benefit. Those concepts can have different legal treatment. Product and legal teams should define how each supported authority type is represented and which questions require specialist interpretation.

Safe contact is a control, not a courtesy

Many investigations fail because the bank contacts the customer through a channel controlled by the suspected exploiter. A changed mobile number, newly registered email address or companion-managed device may be the very mechanism through which the customer has been isolated. Case systems should therefore support a safe-contact assessment rather than assuming the newest contact detail is automatically the safest.

A safe-contact record can identify the last independently verified channel, whether a third party normally answers, whether branch contact is feasible, whether a trusted contact is available and whether the trusted contact is themselves part of the concern. Access to this information should be tightly controlled because it can reveal vulnerability and suspected abuse.

Staff should avoid confrontation. If a suspected caregiver is present, openly accusing that person may expose the customer to retaliation once they leave the branch. Where the bank’s local procedure permits a private conversation, staff can ask factual questions in a calm manner and escalate observations. They should not attempt a forensic interview, demand that the customer denounce a family member, or promise outcomes they cannot guarantee.

Capacity is not a monitoring output

Financial-crime systems can identify signs that further support may be needed; they cannot diagnose cognitive impairment. A customer who repeats a question, needs extra time, misunderstands an app or relies on a relative may still be capable of making the relevant decision. Capacity tests and legal consequences differ by jurisdiction.

A bank’s operational response should therefore focus on supported decision-making where appropriate. Clearer explanations, alternative channels, additional time and permitted assistance can help the customer understand the transaction without transferring control to another person. Specialist escalation is appropriate when staff observe serious concern about the customer’s ability to understand the decision, but the case record should describe the observation rather than state a medical conclusion.

Where an authorised representative is already acting because of a formal capacity arrangement, the system should store that status accurately and enforce the required controls. The existence of the arrangement does not itself indicate abuse. The financial-crime question remains whether the activity fits the authority, customer interests and observed pattern.

Build a time-ordered evidence chain

A strong investigation reconstructs the sequence rather than reviewing isolated debits. Useful timestamps include changes to contact details, new device registration, password reset, creation of a payee, increase of payment limit, registration of a representative, investment liquidation, branch visits, fraud warnings and the questioned transactions themselves.

Sequence often reveals causality that a transaction list hides. A new phone number followed by a password reset, a new beneficiary and a large transfer within the same day is different from a beneficiary the customer has paid regularly for five years. Likewise, a caregiver becoming an authorised representative and then gradually receiving more value over six months requires a different review from a single reimbursed expense supported by evidence.

Investigators should connect transaction data with interaction evidence. Call recordings, branch notes and fraud conversations can show whether the customer was being coached, whether secrecy was requested, or whether the explanation changed. This evidence must be handled under applicable privacy and retention rules.

Separate four decisions at closure

Elder-exploitation cases become confused when one disposition is expected to answer every question. The case should instead record four separate outcomes where relevant.

The fraud outcome addresses authorisation, deception, reimbursement and recovery. The AML outcome addresses suspicion concerning the beneficiary, representative or wider network and determines whether internal escalation or a jurisdiction-specific SAR or STR decision is required. The customer-protection outcome addresses safe contact, credential security, product restrictions and specialist support. The external-referral outcome records whether another authority or safeguarding body must or may be contacted under local law.

These decisions can differ. A customer may have authorised a scam payment, making the fraud analysis complex, while the receiving account still presents clear money-laundering suspicion. A trusted-person transfer may not meet an AML reporting threshold but may still require customer-protection escalation. Conversely, a suspicious beneficiary network may be reportable even when the customer no longer needs immediate safeguarding support.

This separation improves auditability. Reviewers can see which facts supported which decision instead of trying to infer a universal conclusion from a single case status such as confirmed elder abuse.

What good evidence looks like

The strongest case language is neutral and reconstructable. It records what changed, who initiated the activity, what authority existed, where value moved, what the customer said, which channel was used and what independent corroboration was available. It distinguishes verified facts from analyst inference and from third-party allegations.

That discipline protects both sides. It makes it easier to escalate a genuine exploitation case because downstream teams receive usable evidence, and it reduces the risk of unfairly accusing relatives or representatives when the activity has a legitimate explanation. The purpose of the control is not to prove abuse from the first alert. It is to recognise a credible risk, preserve evidence, protect the customer where necessary and route the matter to the functions that can make the appropriate legal, fraud, AML or safeguarding decision.

Advanced practice: detection design, intervention and jurisdiction control

The most useful elder-exploitation controls do not search for “old customer plus big payment.” They search for combinations of behavioural change, destination risk, access change, influence and loss of customer control. Advanced practice therefore begins with scenario design and ends with a legally scoped response matrix.

Design scenarios around combinations, not labels

A scenario should represent a hypothesis that investigators can test. One hypothesis might be: a customer who has historically retained long-term savings is being manipulated into sending value to a new beneficiary. Useful features could include liquidation of a deposit or investment, beneficiary novelty, unusual payment size relative to the customer’s history, recent device registration, contact-detail change, remote-access signals, repeated fraud-warning overrides and destination intelligence.

A different hypothesis might concern misuse of representative authority. Features could include a newly registered attorney or other account operator, payments to that person or a connected beneficiary, declining expenditure on the customer’s normal needs, repeated cash withdrawals, and a sharp change in how the customer contacts the bank. The model should not assume these features prove wrongdoing. They identify cases where human review can determine whether the pattern is consistent with legitimate support.

Scenario design should avoid protected-characteristic shortcuts. Age may be relevant to a specific vulnerability or legal framework, but the control should not make age alone determinative. Analysts need the reason the alert fired: for example, “new payee + term-deposit break + remote-access event + prior scam warning,” not merely a score.

Use beneficiary intelligence before the payment leaves

For scam risk, beneficiary information is often more valuable than another customer-authentication challenge. The customer may be genuine and fully authenticated while being deceived about who receives the funds. Banks can use permitted internal or industry intelligence to identify beneficiaries previously associated with fraud, rapid account turnover, multiple victim reports or suspicious onward movement.

This intelligence needs careful governance. A receiving account linked to a prior fraud report is a risk signal, not an automatic statement that the account holder is a criminal. Data sources should have provenance, confidence and retention rules. When intelligence is shared between institutions or through a consortium, the legal basis and permitted use need to be explicit.

For instant payments, timing matters. A risk service that responds after settlement may still support investigation but cannot prevent the initial loss. Product and fraud teams should identify which checks must happen before authorisation, before release, immediately after settlement and during recovery. Timeouts and degraded-service behaviour should be tested rather than left to operational improvisation.

Intervention should be specific to the observed risk

A good intervention interrupts the scam narrative. If a caller has told a customer to move money to a “safe account,” the warning should address that claim. If the customer is paying an “investment adviser” contacted through social media, staff can explore how the relationship began, whether guaranteed returns were promised and whether the customer was instructed to keep the investment secret.

The bank should not assume it can always hold the transaction. Legal powers, payment-service obligations, scheme deadlines and product terms differ. The operating model should contain a jurisdiction and product matrix showing which actions are permitted: warning only, step-up review, temporary delay, refusal, post-event recovery or specialist escalation. Any delay mechanism should have ownership, maximum duration, exception handling and auditable release criteria.

The customer’s response to a warning is evidence. Repeating a script, refusing independent verification because the caller forbids it, or insisting that bank staff are part of a conspiracy can strengthen the concern. But a customer who calmly explains an unusual family gift and provides coherent supporting context may simply be making a legitimate decision.

Build a jurisdiction-aware reporting matrix

Global programmes fail when they use one country’s elder-protection process everywhere. The United States provides a clear example of why mapping is necessary: FinCEN guidance addresses U.S. suspicious activity reporting, while state law may create separate obligations or permissions involving Adult Protective Services, law enforcement or other agencies. The December 2024 interagency statement explicitly recognises variation in state requirements.

The UK uses a different structure. AML suspicious activity reporting applies under UK law when the relevant suspicion and legal conditions are met. FCA vulnerability expectations concern fair treatment and customer outcomes. Adult safeguarding arrangements sit within a separate legal and local-authority framework. A vulnerability flag is therefore not automatically a SAR trigger, and a SAR filing does not by itself complete the bank’s customer-protection responsibilities.

Other markets need their own mapping. At minimum, the policy service should record the applicable booking entity, customer location, product, FIU reporting route, protective-services route where relevant, permitted information-sharing basis, transaction-delay power, confidentiality constraints and any rules about notifying the customer or representative.

Measure customer harm in both directions

Control performance cannot be judged only by loss prevented. Over-intervention can also harm customers. An older customer may need to pay a legitimate care provider, purchase property, assist family or move investments. A poorly designed control can delay essential care, create embarrassment, remove access to funds or cause the customer to avoid the bank entirely.

Management information should therefore include false-positive friction and service outcomes alongside prevented fraud. Useful measures include time to specialist review, percentage of interventions resulting in confirmed scam indicators, recovery rate, repeat victimisation, number of legitimate payments materially delayed, complaints caused by the control, and whether customers could still access essential funds during restrictions.

Fairness review should compare outcomes across customer groups and channels. A branch-based intervention model may miss digitally active customers. A digital-only model may miss customers whose account is being controlled by a companion in person. The control framework needs both behavioural analytics and human observation.

Connect fraud intelligence to AML network analysis

The victim-side case and the beneficiary-side case are different views of the same event. Fraud teams may conclude that a customer was deceived and focus on reimbursement and recovery. AML teams may identify that the destination account receives funds from several unrelated victims and rapidly disperses them. The second pattern can reveal mule activity or a larger criminal network.

Handoffs should preserve the payment identifiers, beneficiary details, customer narrative, contact method, device evidence, prior warnings and recovery attempts. Where several victim cases point to one destination, link analysis can prioritise the receiving relationship for review without forcing every victim case into the same disposition.

This is where elder-exploitation typology work becomes genuine financial intelligence. The bank is not merely protecting one customer; it is using a well-evidenced victim event to identify infrastructure that may be harming many customers.

Advanced control principle

A mature control answers three questions quickly and separately: Is the customer being manipulated or deprived of control? Is the destination or representative suspicious? What actions are legally available right now? Keeping those questions distinct prevents two common errors: treating successful authentication as proof of safety, and treating suspicion as permission to take any protective action the bank would prefer.

Practice close: delivery checks, acceptance criteria and testing

A policy can say “protect vulnerable customers” and still fail in production because the payment cannot be paused, representative authority is stored incorrectly, investigators cannot see old contact details, or the case workflow has no safe way to reach the customer. The following practice converts the chapter into testable delivery requirements.

BA checklist before accepting the design

The business analyst should be able to trace the control from risk event to customer outcome. The requirements should identify which systems provide age or vulnerability context, transaction history, beneficiary data, device events, contact-detail changes, representative authority, branch observations and prior fraud cases. Each field needs a source, owner, timestamp and quality rule.

Authority data deserves its own acceptance criteria. The solution should distinguish at least the supported legal or operational roles used by the bank, such as joint holder, attorney, guardian, trusted contact and other authorised representative. The model should record effective and end dates, relevant limits and the evidence supporting the role. A trusted contact must not accidentally receive transaction permissions merely because both concepts are stored in a relationship table.

The case workflow should define the decisions it supports. At minimum, teams should be able to record fraud outcome, customer-protection actions, AML escalation or reporting decision, external referral where relevant, payment-recovery activity and final account action. A single generic disposition such as elder abuse confirmed is too coarse for audit and can encourage unsupported legal conclusions.

Safe contact also needs explicit fields. A case should show whether the normal phone or email may be compromised, which channel was last independently verified, whether a third party controls communications, and whether the nominated trusted person is themselves connected to the concern. Access to those fields should be restricted to roles that need them.

Acceptance criteria for detection

A useful control should meet several practical conditions. It should explain why an alert was generated rather than expose only a model score. It should support behavioural comparison with the customer’s own history. It should allow new beneficiary, savings liquidation, device change, contact change, payment velocity, representative activity and prior scam history to be combined where data is available. It should not treat age alone as proof of exploitation.

Alert evidence should be point-in-time accurate. If a representative was added after the transaction, the case must not show that person as authorised at the transaction time. If a phone number changed, investigators should be able to see both the old and new values with timestamps.

Where beneficiary intelligence is used, the reviewer should know the source and confidence of the information. A prior fraud report, confirmed account closure, model-derived network link and shared address are not equivalent pieces of evidence.

Acceptance criteria for intervention

The payment journey should identify which interventions are legally and operationally available for each relevant rail and product. If a payment may be delayed, requirements must define who can invoke the delay, its maximum duration, what happens when the review timer expires, how the customer is informed and which emergency exceptions exist. If the bank has no lawful power to delay a particular payment, the system should not imply that it does.

Warnings should be risk-specific where possible and their presentation should be testable for accessibility. The solution should record which warning was displayed, whether the customer acknowledged it and whether staff performed a call-back or additional review. This creates an evidence trail for later investigation and control tuning.

Recovery action should not depend on AML case completion. Where the rail supports recall, dispute or beneficiary-bank contact, the fraud or payment process should be able to begin immediately while AML investigation continues in parallel.

Positive, negative and boundary tests

Positive testing should include a stranger scam with a new beneficiary, a trusted-person case with value flowing to the representative, a recovery scam following a previous loss, and a case where the customer’s contact details were changed shortly before a payment. Each test should prove that the right evidence reaches the reviewer and that the correct escalation options are available.

Negative testing is equally important. Test a legitimate large gift to an adult child, a property purchase, payment of genuine care-home fees, an attorney paying the customer’s household costs, a digitally confident older customer opening a new investment relationship and a customer who chooses to proceed after receiving a warning but provides a coherent independent explanation. The objective is to prove that the control can distinguish risk from ordinary autonomy.

Boundary testing should cover conflicting evidence. A representative may have valid authority but the customer disputes a transfer. A customer may insist a scammer is genuine. A trusted contact may be the suspected exploiter. A customer may be unable to use digital banking but fully understand the financial decision. The case process should route uncertainty to the right specialist rather than forcing the reviewer to choose an unsupported binary answer.

Failure-mode tests

Run the journey with the fraud-scoring service unavailable, beneficiary intelligence delayed, case queues overloaded and the customer’s normal contact channel marked unsafe. Verify that fallback behaviour is documented and does not silently release or block payments outside approved rules.

Test time zones and out-of-hours ownership for urgent payments. If a branch raises a concern late on Friday but the specialist queue is unstaffed, the system needs a defined path. A control that works only during office hours is not complete for products that move money around the clock.

Test privacy boundaries as well. Staff without a need to know should not be able to browse sensitive vulnerability notes. Exports, analytics and management-information feeds should avoid spreading unnecessary personal detail.

What QA should look for in a completed case

A high-quality file tells a coherent story. It shows the behavioural change or access concern, identifies the relevant authority and beneficiary, records what the customer said, separates facts from assumptions, documents immediate protection and recovery steps, explains whether AML or external reporting was considered, and records why the final decision was proportionate.

QA should challenge both under-response and over-response. It should ask whether a credible scam signal was dismissed because the customer authenticated successfully, and whether a legitimate transaction was restricted merely because the customer was older or accompanied by family. Good quality is the ability to protect without replacing the customer’s agency unnecessarily.

Masterclass: the helper who became the gatekeeper

This fictional composite case is designed to show how trusted-person exploitation develops gradually and why a bank should not jump from one unusual payment to an accusation. The figures, names and events are invented for learning. The mechanics reflect recurring control problems described in public elder-exploitation guidance.

The relationship begins normally

A 79-year-old customer has banked with the institution for more than twenty years. She receives pension income, pays household bills, uses a debit card for ordinary spending and occasionally transfers modest amounts to family. After a period of ill health, her nephew begins helping with shopping and transport. The customer tells the branch that he may accompany her because she finds long journeys difficult.

Nothing about that arrangement is suspicious. Family support is common, and the customer continues to make her own decisions. Several months later she grants the nephew a formal authority supported by documentation accepted under the bank’s local process. The authority allows him to make specified transactions on her behalf. The account system records the role, effective date and document reference.

The pattern changes

During the next four months, the customer stops using her debit card in places she previously visited. Cash withdrawals increase. Two transfers go to the nephew’s personal account, initially described as reimbursement for home repairs. A third transfer is larger. Contact-centre notes show that the nephew answers questions for the customer and becomes impatient when the agent asks to speak with her directly.

A monitoring alert is generated not because the customer is 79 or because the nephew has authority, but because several conditions now combine: payments to the representative, material change from the customer’s historical pattern, reduced ordinary spending, repeated cash withdrawals and a change in interaction behaviour.

The first-level reviewer does not label the activity abuse. They verify the authority, map the transactions and note that the first reimbursement has an invoice attached while the later transfers do not. The reviewer also sees that the customer’s mobile number was changed shortly after the authority became active.

Safe contact changes the investigation

The case is escalated to the bank’s specialist customer-protection team. Rather than calling the newest mobile number, the team checks the safe-contact record and arranges a conversation through the branch under the institution’s approved procedure. The customer attends without the nephew after being offered an appointment at a convenient time.

In the conversation she explains that she expected the nephew to pay household and care expenses, but she is surprised by two of the transfers to his personal account. She does remember approving the home repair. She also says the nephew encouraged her to change the mobile number because he would “handle the bank calls.” Staff record those statements factually and avoid asking her to make a legal accusation.

The bank now has stronger evidence: not merely a transaction anomaly, but a difference between the customer’s understanding and the observed use of the account. The authority document is sent to the relevant specialist function for interpretation. The bank does not assume that every payment by the nephew is unauthorised; ordinary household payments continue to be reviewed separately.

Four outcomes, not one

The fraud team reviews the questioned transfers and determines the relevant fraud and reimbursement treatment under the product terms and local law. Payment operations examine whether any recovery action remains possible. The customer-protection team secures contact details and arranges the permitted account controls without unnecessarily blocking essential expenses.

AML separately reviews the nephew’s receiving account and connected payments. If the evidence meets the applicable suspicion threshold, the appropriate reporting process is followed. That decision is documented separately from any safeguarding or customer-support referral. Legal and compliance teams determine whether another authority must or may be notified under the jurisdiction’s rules.

The case does not need a dramatic ending to be valuable. The bank’s job is not to prove a criminal offence or manage the family relationship. Its job is to recognise the risk, protect the customer using lawful controls, preserve a reliable evidence trail, recover funds where possible and route suspicion to the bodies authorised to act.

What would have gone wrong in a weak bank

A weak control environment could have failed in several ways. Authentication might have been treated as sufficient because the nephew had valid access. The branch could have called the new phone number, allowing him to control the conversation. A generic representative record might have prevented staff from understanding what the authority actually permitted. Fraud could have closed the case after deciding one transfer was technically authorised, with no AML review of the receiving account. Or the bank could have overreacted by freezing every transaction, leaving the customer unable to pay for care and household needs.

The better model is proportionate and evidence-led. It respects the original legitimacy of the family-help arrangement while recognising that legitimate access can later be misused. It protects the customer without assuming that older age removes decision-making rights.

Lessons for delivery teams

For business analysts, the case demonstrates why effective dates, authority type, safe contact, transaction purpose and beneficiary relationship need structured fields. For architects, it demonstrates why contact history and representative history must be reconstructable. For investigators, it demonstrates the value of chronology and neutral language. For product owners, it demonstrates that protective controls need emergency access for legitimate spending. For testers, it demonstrates why both genuine exploitation and legitimate family support must be included in acceptance testing.

The central lesson is simple: trusted access is not the same as trusted use. The bank needs enough evidence to distinguish ordinary support from a pattern in which control and economic benefit move away from the customer.

Knowledge check and glossary

The questions below test whether the chapter’s evidence and customer-protection principles are understood rather than whether individual red flags have been memorised.

Does a large transfer by an older customer prove financial exploitation? No. Amount and age are context only. The bank needs evidence such as behavioural change, destination risk, manipulation, unauthorised access, misuse of authority or another coherent risk pattern. Legitimate gifts, care payments, property purchases and investments can all be unusual without being abusive.

Why can strong authentication fail to prevent an elder scam? Authentication can prove that the genuine customer approved the instruction, but it does not prove that the customer knows the beneficiary’s true identity or has not been deceived about the purpose. Scam controls therefore also need beneficiary intelligence, contextual warnings and intervention where permitted.

What is the difference between a trusted contact and a power of attorney? The terms depend on jurisdiction and product, but they are not interchangeable. A trusted contact may be someone the bank is permitted to contact in defined circumstances, while a power of attorney or other representative may hold legal authority to act. Systems should store roles and rights separately.

Why are effective dates important for representative authority? Because investigators need to know whether the person could act at the time of the transaction. Showing today’s authority against an older payment can create a false impression that access was valid when the payment occurred.

Can a representative benefit from a payment without abusing the customer? Potentially yes. Reimbursement, authorised gifts or shared household costs may be legitimate depending on the arrangement and law. The investigator should trace benefit, authority, customer instructions and supporting context before escalating a conclusion.

Should front-line staff decide whether a customer lacks mental capacity? Generally no. Capacity is legally and factually complex and varies by jurisdiction. Staff should record observable difficulties, provide accessible support, follow the bank’s specialist procedure and avoid making medical or legal diagnoses outside their role.

What is safe contact? It is the process of choosing a communication channel that is not controlled or compromised by the suspected exploiter. The newest phone number or email address may not be safe if it was changed during the period of concern.

Why should fraud and AML outcomes be recorded separately? Fraud focuses on deception, authorisation, customer loss, reimbursement and recovery. AML focuses on suspicious activity, destination accounts and possible criminal networks. One event can produce different conclusions in the two disciplines.

Does filing a SAR or STR complete the bank’s response? No. Where a report is required, it is one outcome. Customer protection, recovery, credential security, account access and any separate safeguarding or external referral still need their own decisions under applicable law.

Why is a behavioural baseline useful? It gives context to change. A customer who regularly sends large family transfers is different from a customer who has never done so and suddenly liquidates savings, changes devices and pays a new beneficiary after receiving a suspicious call.

Glossary

Elder financial exploitation: A broad term for financial abuse involving an older person. Exact legal definitions and age thresholds vary by jurisdiction.

Elder scam: Deception in which a perpetrator manipulates an older customer into sending value, revealing credentials or surrendering access. The term is descriptive, not a universal legal category.

Trusted-person exploitation: Suspected misuse of access, authority or influence by a family member, caregiver, friend, attorney, fiduciary or other person the customer trusts.

Behavioural baseline: The customer’s historical pattern of payments, channels, beneficiaries, devices and interactions used to interpret later changes.

Authority record: Structured evidence of a representative’s role, scope, effective dates and supporting documentation.

Benefit tracing: Following where value ultimately goes and who economically benefits, while distinguishing that evidence from legal conclusions.

Safe contact: A verified communication route that reduces the risk of disclosing the bank’s concern to a suspected exploiter or using a compromised channel.

Supported decision-making: Assistance that helps a customer understand and make a decision without unnecessarily transferring control to another person. The legal form and availability vary by jurisdiction.

Transaction intervention: A warning, review, delay, refusal or other payment action applied under the bank’s lawful powers, product terms and scheme obligations.

Recovery scam: A scam that targets a previous victim with a false promise to recover lost money, commonly in exchange for further fees or transfers.

Fraud-to-AML handoff: Transfer of victim, payment, beneficiary, device and narrative evidence from fraud operations to AML teams so receiving-account or network suspicion can be assessed.

External referral: Notification to a protective, regulatory or law-enforcement body where local law requires or permits it. The destination and threshold are jurisdiction-specific.

Customer autonomy: The principle that customers retain the right to make their own financial decisions unless a lawful authority or valid restriction applies. Protection controls should not treat age alone as loss of autonomy.

References and further reading

The sources below are public, first-party or official materials used to frame the chapter. Jurisdiction-specific guidance should be read only within the legal system and supervisory context in which it was issued.

Global and public-health context

United States: elder financial exploitation and bank response

United Kingdom: vulnerability, customer support and data

Using these materials responsibly

The U.S. sources explain U.S. Bank Secrecy Act reporting, state-law interfaces and U.S. supervisory practices; they do not create obligations for banks in other countries. The FCA materials address UK conduct, vulnerability and customer-outcome expectations and should not be read as a substitute for another jurisdiction’s AML or adult-safeguarding law. The WHO and UN materials provide broad context rather than bank-specific legal rules. Institutions should map their actual reporting, transaction-intervention, privacy and safeguarding duties to the booking entity, customer, product and location involved.