Consumer rights in scam targeting detection for at-risk demographics in UK

 

Consumer Rights in Scam-Targeting Detection for At-Risk Demographics in the UK

Consumer rights in scam-targeting detection for at-risk demographics in the UK concerns the legal and regulatory issues arising when banks, payment providers, insurers, online platforms, telecommunications companies or other organisations use AI, behavioural analytics, transaction monitoring or demographic indicators to identify people who may be particularly vulnerable to scams.

The central legal tension is:

How can organisations detect and prevent scams affecting vulnerable consumers without unfairly profiling, discriminating against, surveilling or restricting those consumers?

This is particularly significant in financial services because the FCA's Consumer Duty requires firms to act to deliver good outcomes for retail customers and to avoid foreseeable harm.

1. What is scam-targeting detection?

A financial institution might analyse:

  • unusual transaction patterns;
  • rapid changes in payment behaviour;
  • new beneficiaries;
  • unusual geographical activity;
  • repeated failed transactions;
  • suspicious telephone activity;
  • device characteristics;
  • previous fraud indicators;
  • customer-reported vulnerability;
  • sudden large transfers.

An AI system might then produce:

Scam-risk score: High

The institution could respond by:

  • issuing a warning;
  • delaying a payment;
  • requiring additional verification;
  • contacting the customer;
  • requiring confirmation from a trusted person where appropriately authorised;
  • escalating the transaction for human review.

The objective should be protection rather than exclusion.

2. Who may be considered "at risk"?

UK financial-regulatory guidance recognises that vulnerability can arise from different circumstances, including:

  • health conditions;
  • cognitive difficulties;
  • bereavement;
  • relationship breakdown;
  • low financial knowledge;
  • low income;
  • caring responsibilities;
  • other major life events.

The FCA states that vulnerable consumers may have different needs and should receive outcomes as good as those experienced by other consumers.

Importantly, vulnerability is not synonymous with age or disability.

A consumer who is not normally vulnerable can become vulnerable because of a temporary life event.

3. The Consumer Duty

The Consumer Duty is central to this area.

The FCA's consumer principle requires:

firms to act to deliver good outcomes for retail customers.

The Duty includes requirements relating to:

  • acting in good faith;
  • avoiding foreseeable harm;
  • enabling consumers to pursue their financial objectives.

 

Therefore, a bank deploying scam-detection technology should consider not merely:

"Can our algorithm identify fraud?"

but also:

"Does the system produce good outcomes for customers, including customers in vulnerable circumstances?"

4. Duty to identify foreseeable scam harm

A financial institution may be expected to identify foreseeable scam risks and take reasonable steps to mitigate them.

For example:

A customer who normally makes small payments suddenly attempts a £30,000 transfer to a newly created account.

An effective system might:

  1. identify the unusual transaction;
  2. generate a warning;
  3. pause or review the transaction where legally permitted;
  4. contact the customer through a trusted channel;
  5. provide clear information;
  6. allow the customer to make an informed decision.

The FCA expects firms to understand the needs of vulnerable customers and incorporate those needs into product and service design.

5. Consumer rights when an AI system flags them

A consumer should not automatically be treated as a fraudster simply because an algorithm identifies them as high risk.

Potential consumer interests include:

  • fair treatment;
  • understandable communications;
  • appropriate support;
  • access to complaint procedures;
  • correction of inaccurate information;
  • appropriate human involvement;
  • protection against unreasonable restrictions;
  • protection of personal information.

The FCA specifically expects firms to ensure that communications enable customers to make informed decisions and that communications are tailored to characteristics of vulnerability.

6. False positives

A major problem is the false positive.

Example:

An elderly customer legitimately transfers £20,000 to a family member.

The AI identifies the payment as a likely romance or impersonation scam.

The bank blocks the transaction.

The customer complains:

"The system wrongly treated me as incapable of making my own financial decision."

This raises questions about:

  • accuracy;
  • proportionality;
  • human review;
  • communication;
  • delay;
  • inconvenience;
  • potential financial loss.

A good system should therefore distinguish:

risk detection

from

automatic refusal of service.

7. False negatives

The opposite problem is a false negative.

A vulnerable consumer is targeted by a sophisticated scam.

The bank's system fails to detect the unusual transaction.

The consumer loses £50,000.

The consumer may argue that:

  • the transaction was clearly unusual;
  • the institution possessed relevant warning indicators;
  • the bank's fraud controls were inadequate;
  • the institution failed to provide appropriate protection.

Whether the bank is legally liable will depend on the applicable payment rules, contract, regulatory obligations and facts.

8. APP fraud protection

This is particularly important.

Authorised Push Payment (APP) fraud occurs when a customer is deceived into authorising a bank transfer to a fraudster.

For qualifying UK Faster Payments and CHAPS transactions made from 7 October 2024, mandatory reimbursement protections apply, subject to the applicable rules and exceptions. The maximum mandatory reimbursement amount is generally £85,000.

The PSR states that the gross-negligence exception does not apply to vulnerable consumers under its APP reimbursement framework.

This is particularly significant for scam-targeting systems.

9. Consumer caution and vulnerability

The APP reimbursement framework does not mean every scam loss is automatically reimbursed.

However, the PSR describes the gross-negligence standard as a high bar and expressly states that the exception does not apply to vulnerable consumers.

The latest PSR data reported that between 7 October 2024 and 31 March 2026, 88% (£316 million) of money lost to APP scams was reimbursed, with 98% of claims closed within 35 business days.

Thus, an arbitration or complaint may require examination of:

  • whether the consumer was vulnerable;
  • what warnings were given;
  • whether the bank detected risk;
  • whether the customer understood the warning;
  • whether the payment was genuinely authorised;
  • whether the reimbursement rules apply.

10. Demographic profiling

A difficult issue arises when an AI system uses demographic characteristics.

Suppose the system gives higher scam-risk scores to:

  • older customers;
  • people with certain disabilities;
  • people with limited financial experience.

The institution may argue:

"These groups statistically experience greater scam exposure."

The consumer may respond:

"You are treating me differently because of my demographic characteristics."

The legally safer approach is generally to focus on individualised indicators of actual risk and support needs, rather than using demographic characteristics as crude proxies for susceptibility.

11. Age-based protection

Age can be relevant to vulnerability analysis, but it should not automatically determine competence or financial autonomy.

This is important because FCA data shows that older consumers can be disproportionately targeted by certain scams. For example, the FCA reported that almost two-thirds of reports concerning fake-FCA scams during the first half of 2025 came from people aged 56 or above.

That evidence can justify stronger preventative measures, but not necessarily blanket restrictions on older consumers.

A better approach is:

age as a contextual signal

rather than:

age = presumed inability to decide.

12. Disability and cognitive vulnerability

AI systems may attempt to identify customers who need additional assistance.

Potential safeguards include:

  • accessible warnings;
  • slower confirmation procedures;
  • alternative communication channels;
  • telephone support;
  • simplified explanations;
  • human review.

The FCA's vulnerable-customer guidance emphasises understanding customers' needs and treating vulnerable consumers fairly.

13. Privacy and data protection

Scam detection can involve significant personal information.

Potential data includes:

  • transaction history;
  • device information;
  • location;
  • communication patterns;
  • vulnerability information;
  • behavioural characteristics.

This raises questions concerning:

  • lawful processing;
  • data minimisation;
  • purpose limitation;
  • accuracy;
  • retention;
  • security;
  • automated decision-making;
  • data sharing.

The more sensitive the data, the stronger the governance framework should be.

14. Automated decision-making

A particularly sensitive scenario is:

AI score → automatic account restriction

rather than:

AI score → human review → proportionate intervention

The latter generally provides stronger procedural safeguards.

A financial institution should be able to explain:

  • why a transaction was flagged;
  • what factors were relevant;
  • what action was taken;
  • how the customer can challenge an incorrect assessment.

This is especially important where an automated decision materially affects the customer's ability to access money.

15. Explainability

Suppose a consumer asks:

"Why was my £15,000 payment blocked?"

A response such as:

"Our AI system determined that you are high risk."

may be inadequate from a consumer-support perspective.

A better explanation might identify understandable factors:

  • new recipient;
  • unusually large payment;
  • unusual payment pattern;
  • known scam characteristics.

The objective is to give the customer enough information to understand and safely challenge the decision without revealing security-sensitive fraud-detection mechanisms.

16. Human oversight

Human review can be particularly important for vulnerable consumers.

For example:

AI detection

Risk classification

Human assessment

Customer contact

Appropriate intervention

The FCA has highlighted good practice where firms integrate vulnerability considerations into their systems and processes.

17. Scam warnings must be understandable

A warning such as:

"Your transaction exhibits anomalous behavioural characteristics consistent with APP fraud."

may be technically accurate but difficult for many customers to understand.

Instead:

"This payment is unusual for your account. Someone may be trying to trick you into sending money. Please stop and check who you are paying before continuing."

The FCA expects firms to provide information in a form customers can understand and to consider the communication needs of vulnerable customers.

18. Consumer autonomy

Protection should not become paternalism.

A financially capable consumer may legitimately want to:

  • purchase an expensive item;
  • send money overseas;
  • invest;
  • transfer money to a new recipient.

A bank should therefore distinguish between:

risk-based intervention

and

unjustified restriction of consumer choice.

The Consumer Duty aims at good outcomes rather than simply maximising transaction prevention.

19. Complaint and redress rights

If a consumer believes a firm mishandled a scam, the consumer can complain to the relevant financial firm.

Where the complaint concerns an APP reimbursement decision, the Financial Ombudsman Service may be available where the relevant requirements are met. The FCA specifically directs consumers to the Ombudsman where they are unhappy with how a bank or payment provider handled a scam.

The consumer should preserve:

  • bank messages;
  • transaction records;
  • telephone records;
  • scam communications;
  • screenshots;
  • warnings received;
  • correspondence with the bank.

20. Arbitration disputes

Where the bank, technology vendor and consumer-protection service provider have commercial contracts, arbitration may arise between the businesses.

For example:

Bank → AI fraud-detection provider

The bank alleges:

"Your system failed to identify a predictable scam."

The AI provider responds:

"The bank supplied incomplete data and failed to implement the recommended configuration."

The arbitration could involve:

  • software performance;
  • model accuracy;
  • data quality;
  • cybersecurity;
  • contractual warranties;
  • service levels;
  • regulatory compliance;
  • liability allocation.

Consumer rights remain relevant even though the arbitration is between commercial parties.

21. Example

A UK bank deploys an AI scam-detection system.

A customer who has recently experienced a major life event attempts a large transfer to a new recipient.

The system identifies:

  • unusual payment amount;
  • new beneficiary;
  • unusual device;
  • high-risk transaction pattern.

It gives the customer a warning but permits the transaction.

The customer later discovers that the recipient was a fraudster.

The customer seeks reimbursement.

The bank argues:

"The customer authorised the payment."

The customer argues:

"The bank's own system identified the transaction as high risk and failed to provide adequate protection."

The dispute could require examination of:

  1. the customer's vulnerability;
  2. the warning supplied;
  3. the bank's fraud controls;
  4. the payment method;
  5. whether APP rules apply;
  6. whether the bank complied with its regulatory obligations;
  7. whether the customer understood the warning.

22. Key legal and regulatory issues

IssueCentral question
VulnerabilityWas the customer in vulnerable circumstances?
ProfilingWas demographic information used fairly?
AI accuracyDid the system correctly identify risk?
False positivesWere legitimate transactions unnecessarily blocked?
False negativesDid the system miss a foreseeable scam?
TransparencyWas the customer given understandable information?
Human reviewWas automated intervention appropriately supervised?
APP fraudDo mandatory reimbursement rules apply?
PrivacyWas personal information processed lawfully?
Consumer DutyWere foreseeable harms identified and mitigated?
RedressIs reimbursement or other compensation available?
EqualityDid the system create unjustified discriminatory effects?

23. Best-practice framework

A strong scam-detection system should operate approximately as follows:

Risk indicators

AI assessment

Vulnerability-sensitive analysis

Proportionate warning

Human review where appropriate

Customer confirmation

Payment / temporary intervention

Post-transaction monitoring

Redress and learning

The system should continuously test:

  • false positives;
  • false negatives;
  • demographic disparities;
  • accessibility;
  • customer comprehension;
  • reimbursement outcomes.

Conclusion

Consumer rights in scam-targeting detection for at-risk demographics in the UK centre on a balance between fraud prevention, consumer autonomy, privacy, equality, transparency and effective redress.

The UK's regulatory framework is increasingly protective. The FCA's Consumer Duty requires firms to pursue good outcomes and avoid foreseeable harm, while its vulnerable-customer guidance expects firms to understand and respond appropriately to customers' differing needs.

For payment scams, the position is even stronger: qualifying APP fraud payments made through UK Faster Payments or CHAPS since 7 October 2024 are subject to mandatory reimbursement rules, generally up to £85,000, subject to the applicable conditions. The PSR expressly states that the gross-negligence exception does not apply to vulnerable consumers.

The central principle should therefore be:

Use AI to identify and reduce scam risk, not to presume that a particular demographic is incapable of making its own financial decisions.

A legally robust system should combine individualised risk signals, accessible warnings, human oversight, proportionate intervention, strong data governance and effective complaint/reimbursement mechanisms.

LEAVE A COMMENT