A session at Counter Fraud 2026 between Rob Malcomson MBE of the Public Sector Fraud Authority and Chris Lewis, Director of Synectics Solutions - the service provider for the National Fraud Initiative - explored the practical, legal and cultural barriers to moving from fraud recovery to fraud prevention, and what it would take to make that shift a reality.
Here is a summary of what they said:
The law is not the problem
Chris Lewis opened with a point that cuts against a common assumption: the existing legislative and regulatory framework already facilitates preventative fraud strategies at scale. The legal basis is there. The Data Protection Act, the Data Use and Access Act 2025, the Digital Economy Act, the Digital Identity and Attributes Trust Framework - all of these, properly understood, support data sharing for fraud prevention purposes. The framework already has fraud prevention embedded within it, through close collaboration between legislators, regulators and industry.
What is missing is not the law. It is a consistent approach to interpreting and applying it. There is no shared, reusable interpretation of legitimate interests for fraud prevention that organisations can point to when making the case internally. Every organisation is having the same conversation from scratch, often with legal and data governance colleagues who have not been part of the thinking from the start, and who are being asked to sign off on something they have not helped to design.
The data fundamentals have to come first
Rob Malcomson added a point about infrastructure. The shift to prevention requires real-time data flows at the point decisions are made - not batch matching after the fact. That plumbing is being built. The PSFA is constructing an API from HMRC that will give 1,100 public bodies participating in the NFI the ability to check a person's earnings and employment in real time, including for the previous tax year. That is a significant step change in what is practically possible for upstream fraud prevention.
Lewis noted that the private sector - banking, telecoms, insurance - did not develop prevention-first operating models overnight. They took decades of pain and loss to build that muscle memory. The public sector cannot simply lift and shift those approaches; the context is different, the risk calculus is different, and the consequences of getting it wrong are very different. But the operating model question - how do you flex your current way of working to reflect a prevention-first strategy, not just talk about it - needs to be answered seriously.

What is actually holding prevention back
The session was candid about the cultural and institutional barriers. Lewis identified a specific fear: even where prevention is technically possible and legally sound, individuals within departments and local authorities are not confident they will be protected if something goes wrong. If a decision made under a prevention-first strategy results in a constituent being incorrectly refused a benefit or service, and that ends up in the press, the organisation needs to be able to point to a clear mandate and a clear methodology. Without that top-down target-setting and ministerial backing, individual actors are understandably cautious.
Malcomson was equally direct about a different problem: over-interpretation. Legal and data governance teams, he said, are sometimes so focused on what might go wrong that they effectively prevent common-sense things from happening. He was not dismissive of the risk - he acknowledged recent cases where data analytics had produced incorrect outcomes and generated political scrutiny. But he argued that the balance is currently tilted too far towards caution, with too much attention on the 1% of false positives and not enough on the 99% of cases where the analytics delivers real value. Processes can be designed to identify, compensate and correct false positives. Paralysis cannot be corrected at all.
Bring legal and data governance in early
Both speakers converged on the same practical recommendation: stop treating legal and data protection colleagues as external gatekeepers brought in at the end of a project to say Yes or No. Bring them in at the start. Make them part of the solution design team. The reason they ask 100 questions is that they need to understand the proposal before they can advise on it - and if they are only handed a fully-formed plan, those questions feel like obstruction. If they have been involved in developing the thinking, the same questions are answered as part of the process.
Lewis described his organisation's monthly data governance meetings as among the most productive parts of his job - a forum for working through how to solve problems within deliberate constraints, rather than around them. When facilitating industry-wide data sharing at scale, that rigour is not a barrier. It is the foundation that makes the work defensible and sustainable.
Master the basics before reaching for AI
On the technology side, Malcomson made a point that cut against some of the day's broader narrative: AI is not the starting point. The £480 million in fraud identified and prevented through the NFI - referenced by the minister earlier in the day - has been delivered predominantly through the basics: data matching, entity resolution, graph and network analytics. Not advanced AI. Not agentic systems. The fundamentals, done well and at scale.
That is not an argument against AI - both speakers acknowledged it is where the sector is heading, and that more advanced work is already under way. But starting with mastering the basics produces an immediate, measurable, defensible return on investment. It gives organisations something to point to when making the case for further investment. And it provides the data quality and governance foundations on which more advanced capability can be built.
Lewis added the private sector perspective on data sharing: if everyone in a network knows who the bad actors are, it has a displacement effect. Fraud syndicates cannot operate as effectively when their identities are shared across a sector. It allows organisations to be more generous to genuine claimants and applicants, prioritise investigations more efficiently, and ultimately push fraud risk outside the UK rather than just between sectors.
Where could organisations be in 12 months?
Lewis closed with a line from a colleague that has stayed with him since he joined the counter fraud sector: no one has ever asked for more fraud - they always ask for fewer referrals. His answer to where organisations could realistically be in 12 months: finding the same amount of fraud with fewer referrals, by investing in the right data governance approach and the right foundational technology. That is not a small ambition. It is, he said, the right foundation on which a genuinely government-wide counter fraud strategy can be built.
Jessica Kimbell, GovNet

.png?width=600&height=250&name=Fraud%20Blog%20CTAs%20(4).png)
