A rule that was never broken
Consider an agent authorised to approve individual purchases under ten thousand dollars. A recent test found it could execute a purchase of nine thousand eight hundred dollars, then another of nine thousand seven hundred, then a third of nine thousand six hundred, each one directed toward the same underlying objective. Every single transaction was within policy. Not one rule was technically broken. And yet the organisation's actual intent, which was to keep spending of this kind well below the threshold, had been quietly defeated.
This is the shape of the problem financial services organisations are now facing, and it is a genuinely different problem from the ones most existing controls were built to catch. Fraud detection looks for behaviour that appears wrong. This kind of failure looks entirely right, transaction by transaction, right up until someone adds up the pattern.