Federal Reserve survey data and FCA guidance point to the same operating problem: many mule cases are detected after another institution raises the issue or after money has already moved. The harder question for identity teams is not whether onboarding worked, but whether anyone owns the moment when a verified account changes hands.
On April 22, 2026, the Federal Reserve Financial Services survey of 400-plus financial-institution risk professionals found that 53% learn of mule activity from another financial institution, 49% identify it after a loss, and only 28% reported real-time screening of received transaction activity Federal Reserve. That is the operational problem. The account may have been opened by the right person and still end up controlled by the wrong one.
Providers across device intelligence, behavioral risk, and identity verification — including Incognia, BioCatch, and Featurespace in fraud monitoring, and Jumio, Persona, and Onfido (acquired by Entrust in April 2024) in onboarding identity verification — address different parts of that chain. Buyers should not confuse those layers. A document-and-selfie decision answers one question; mule handover detection answers another.
A verified applicant and a new controller are different risk states
The FCA's review of proceeds of fraud and money mules says multiple customers using one device can indicate that an account holder sold details to a mule herder FCA mule review. The same review points firms toward onboarding controls, inbound and outbound monitoring, prompt reporting, and governance FCA mule review.
That matters because the failure mode is often misclassified. Teams see a mule account and assume the KYC stack failed at onboarding. The supplied sources do not support that as a blanket explanation. A genuine customer can pass KYC, then later share credentials, lose device control, or deliberately transfer access.
FATF's digital identity guidance says authentication events indicating lost, compromised, stolen, or sold credentials can support ongoing due diligence and transaction monitoring. In practice, that means authentication telemetry belongs in AML workflows when account control may have changed FATF.
The seam is between teams, not just tools
FCA financial-crime guidance in FCG 2 says firms' structures should promote coordination and information sharing and that counter-fraud and AML work should complement each other FCA FCG 2. The wording is straightforward. The operating model often is not.
Identity teams usually own proofing and onboarding assurance. Authentication teams own login risk, recovery, and session controls. Fraud teams tune transaction monitoring. AML teams investigate mule typologies and suspicious activity reports. If no team owns the transition from verified applicant to suspected new controller, the signal arrives in pieces. One team sees an account recovery. Another sees a new device pattern. A third sees fast outbound transfers. Everyone has a shard; no one has the vase.
Vendor research in this category points in the same direction, with the right caution. Incognia said its 2026 survey of 500-plus US and European fraud, risk, and AML professionals found 83% detected handovers reactively and 16% caught them before suspicious transactions. That is vendor-originated research rather than independent market proof, but it tracks with the Federal Reserve survey's late-detection pattern Federal Reserve.
What control-change signals are actually useful
The FCA source gives one concrete indicator: multiple customers using one device may point to account-detail sales to a mule herder FCA mule review. FATF broadens the frame by treating compromised or sold credentials as relevant to ongoing due diligence FATF.
For practitioners, that means mule controls should not sit inside transaction analytics alone. Relevant triggers can include device sharing patterns, abrupt changes in login behavior, repeated recovery events, and high-risk payment activity that follows those changes. The supplied sources do not create a universal rule for any single signal in isolation. They do support a case-based workflow where identity, authentication, fraud, and AML signals are reviewed together.
The main weakness exposed by the April 22, 2026 Federal Reserve data is not poor onboarding in isolation. It is stale assurance after onboarding, when the institution has not built shared ownership for control-change detection across identity, authentication, fraud, and AML Federal Reserve FCA mule review FCA FCG 2 FATF.
Counter-read: late detection may still stem mainly from the evidentiary difficulty of proving a real controller change before suspicious transactions occur, even where cross-team ownership is in place.
What would change this conclusion: evidence that institutions with shared case ownership, linked authentication-and-AML workflows, and real-time screening of received transaction activity do not detect mule behavior materially earlier than peers would weaken the case that the operating seam is the main fault line.
The practical test for buyers
The simplest diagnostic is not whether a vendor can score mule risk. Many providers such as Incognia, BioCatch, and Featurespace can surface device or behavioral anomalies, while identity verification providers such as Persona, Jumio, and Onfido (acquired by Entrust in April 2024) handle proofing earlier in the lifecycle. A reasonable inference is that the following implication holds: The harder question is whether those signals change case ownership fast enough to stop loss.
A buyer should be able to answer three operational questions with evidence:
- Which team owns a suspected controller-change case before suspicious transfers occur? - Which authentication events are pushed into fraud and AML review queues in real time? - How often does the institution detect mule behavior from internal signals rather than peer-bank notifications or post-loss review?
If those answers live in four systems and three managers' heads, that is the problem. Process debt has a way of billing itself at the least convenient moment.
What to Do Next
- Map the control-change workflow before the next quarterly fraud review. Document which team owns alerts tied to device sharing, account recovery, credential reset, and new-payee activity, and identify where cases stall. - Ask current vendors for event-level integration detail during the next renewal or roadmap meeting. Specifically ask how authentication recovery events, device intelligence, and transaction risk signals can be joined in one analyst queue. - Measure detection source for the next 90 days. Track whether suspected mule cases came from peer notifications, post-loss review, transaction monitoring, or pre-transaction identity and authentication signals. - Test one high-risk segment first. For example, apply linked monitoring to newly opened accounts or accounts with recent credential recovery, then compare alert quality and time-to-escalation against current controls.