CBE Moves Fraud Detection From Investigation to Real-Time AI Intervention
The Commercial Bank of Ethiopia (CBE) is deploying artificial intelligence to detect and assess transaction fraud risks in real time, marking a shift toward automated security controls as digital banking activity expands.
The bank’s AI-powered fraud management system analyses customer behaviour and establishes normal transaction patterns. When a transaction deviates significantly from those patterns, the system assigns a risk score and can hold, block or subject the transaction to additional verification.
The approach allows CBE to intervene while a potentially fraudulent transaction is still being processed rather than relying solely on investigations after funds have moved.

From Unusual Transactions to Fraud Networks
According to a presentation by Seyom Damtew, CBE’s Vice President for Information System Security, the system is designed to identify several increasingly sophisticated forms of financial crime.
These include:
- Account takeovers, where criminals gain control of legitimate customer accounts.
- Mule accounts, which are used to receive and move illicit funds.
- Organised fraud networks, where multiple accounts and transactions may be connected.
- Other abnormal transaction patterns that differ from a customer’s established behaviour.
The bank’s AI models are continuously retrained as fraud techniques evolve, while flagged cases are prioritised for CBE’s fraud investigation teams.
This creates a layered approach: AI identifies potential threats at scale, automated controls can interrupt suspicious transactions, and human investigators handle cases requiring deeper analysis.
Security Extends Beyond the Transaction
CBE is also deploying Runtime Application Self-Protection (RASP) within its mobile banking application to detect threats originating from customers’ devices.
The technology can identify risks associated with malware, rooted or jailbroken devices, screen-overlay attacks and application tampering.
Where a security threat is detected, suspicious transactions can be blocked.
This is significant as mobile banking increasingly shifts the security perimeter away from the bank’s physical infrastructure and toward customers’ phones and other devices.
CBE’s Zero Trust Shift
The fraud systems form part of CBE’s broader move toward a Zero Trust security model.
Under Zero Trust, users, devices, applications and network connections are not automatically trusted simply because they have previously been granted access or operate within the bank’s network. They must instead be continuously verified.
CBE’s framework includes multi-factor authentication for critical systems, centralised identity and access management, and tighter controls over privileged credentials.
The bank also requires servers to pass security checks before entering production, including vulnerability assessments and patch-compliance checks.
Third-Party Systems Also Face Scrutiny
The security framework extends beyond CBE’s own systems.
Technology suppliers and third-party integrations are required to undergo security clearance, risk assessment, architecture reviews and data-flow analysis before being approved.
CBE is also monitoring information entering and leaving its network through approved gateways, with encryption and data-classification controls applied to communications.
The broader shift reflects a changing risk environment for Ethiopian banks as digital transactions become more central to financial activity.
For CBE, the challenge is no longer simply protecting a central banking network. It is securing an ecosystem involving customers, mobile devices, applications, third-party technology providers and increasingly complex transaction patterns.
The deployment of AI therefore represents more than an additional fraud tool. It signals a move toward continuous, behaviour-based security in which the bank attempts to identify and stop threats before they become financial losses.
Source: EBR