Joining me now is Arina Rumiantseva, Senior Legal Counsel at Sumsub. Arina, welcome to Wall Street to Mena.
Hello. Thank you so much for having me today.
Deepfakes, fake documents, synthetic identities — fraud is getting a serious tech upgrade. What is the wildest fraud attempt that has caught your attention?
It is quite hard to explain the wildest case because to be honest, we are facing around 23,000 fraudulent attempts per day. The trend is usually around the combination of real ID documents plus a fully falsified document photo and a deepfake for the biometric check. But the most important thing is how to cope with them. We truly believe that the combination of biometric checks, extensive document analysis, and device and behavioural analysis is the only way to cope with any kind of fraud.
You work across the EU, UK, Middle East, and CIS. Which region keeps you on your toes when it comes to regulation?
I work for Sumsub — an AI-driven global verification platform — and I am personally responsible for compliance in the UAE and MENA. I actually love the approach currently used by Middle East countries. It is very effective and ambitious — the digital industry sandboxes and digital identity projects are just enormous. For Europe, it is a unified approach across multiple countries and it is quite heavy in regulation — businesses, even startups, are expected to have mature practices, systems, and controls from the very start.
Verification used to be one step. Now it is multiple steps and it never seems to stop. Why does the industry need this many layers of verification?
The regulatory approach is moving from onboarding towards ongoing Know Your Customer practices. The lack of ongoing control was previously due to a lack of regulation — everything in our AML legal framework comes from regulations. Recently, the instruction has been to monitor transactions and report suspicious ones. But to find and report a suspicious transaction, you first have to define what suspicious looks like. Regulators across the globe are now moving further — describing in detail what should be found and requiring that monitoring be based on normal behaviour that must first be defined before the ongoing monitoring phase can begin.
You are using AI to fight AI. Does that ever feel like a race without a finish line?
Of course. Generative AI is lowering the price of fraudulent activities — making them more accessible and higher volume. But it is more about quantity than quality. We have invested ten years into building effective systems. We have large R&D offices primarily focused on coping with fraud. The fraudsters we are fighting are professionals — and we are ready to put our resources and investments into being more efficient than anything they can imagine.
Crypto platforms are major clients. Is verifying someone buying crypto a completely different game from verifying someone opening a bank account?
Yes and no. From one perspective it is a very different game — the crypto industry has more fraudulent attempts at the onboarding stage, which is quite normal. But crypto users are now more accustomed to passing controls than they used to be. At the same time, banks are learning a lot from crypto's development because they also need to optimise their processes and implement modern techniques to stay in line with where the industry is heading.
You are a lawyer sitting inside a tech company. What is one grey area in AI verification that even you do not have a clean answer on yet?
From a legal perspective, we are all focused on explainability — the transparency of decisions made by AI, for AI, or through AI. The general development of AI has made us work very closely with the product side to ensure that the services we provide are effective, compliant, transparent, and reliable. That balance is still being worked through.
What is the one thing that still catches even smart, well-prepared businesses off guard?
The most dangerous fraud — and historically this has always been the case — is social engineering and account takeovers. Something bad is usually happening after accounts are opened, not before. This is the part where all of us need to be very cautious. Implementing effective controls and procedures that protect businesses throughout the entire user lifecycle — not just at onboarding — is what is worth focusing on.
Thank you so much for joining us today, Arina.
Thank you for having me. And I also want to say thank you to the MENA Fintech Association for this amazing opportunity.