risk
External fraud — third-party theft, forgery, payment and account fraud
Third parties defraud the entity: cheque/payment-card forgery, counterfeit currency, identity theft, account takeover with stolen credentials, fraudulent loan applications, and first-party (bust-out) fraud by customers.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- operational
- domain
- Access Control & Identity Management
- Risk Assessment & Management
- taxonomy
- basel-operational-risk
- coso-erm-risk
- inherent_rating
- high
Details
- risk_id
- fraud-external
- category
- operational
- likelihood
- high
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- basel-operational-risk
- coso-erm-risk
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- Risk-based anomaly signals and lockout directly detect and block credential-stuffing account takeover.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- related
- rationale
- Strong, rotated authenticators revoked on compromise reduce stolen-credential account takeover.
- UC-RISK-17 — Operate threat intelligence and threat hunting mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- related
- rationale
- Threat intel on fraud campaigns and hunting for indicators of account compromise help surface credential-theft account takeover, alongside auth/monitoring defenses.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- Member logical-access security over protected assets (SOC2 CC6.1) directly defends against credential-based account takeover.
- UC-ACCESS-13 — Notify users of system terms and previous logon activity mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- related
- rationale
- Last-logon notification helps users spot stolen-credential account takeover early.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- MFA directly defeats account takeover using stolen credentials.
- UC-ACCESS-07 — Proof identities before binding credentials mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- Evidence-based identity proofing before credential issuance, with re-proofing on recovery, directly defeats identity theft, impersonation, and fraudulent-application account fraud.