(a)
In general— The Federal banking agencies, in consultation with the Secretary of the Treasury, the Financial Crimes Enforcement Network, the Federal Trade Commission, the Bureau of Consumer Financial Protection, the Federal Communications Commission, and other appropriate Federal and State government agencies, including appropriate law enforcement agencies, shall jointly conduct a comprehensive study on the use of advanced fraud detection technology by insured depository institutions and credit unions.
(b)
Required elements— The study required under subsection (a) shall evaluate the following:
(1)
Current use and effectiveness— The current use and effectiveness of advanced fraud detection technologies, including–
(A)
the extent to which insured depository institutions and credit unions of varying asset sizes deploy advanced fraud detection technology;
(B)
measurable outcomes relating to fraud detection, prevention, loss reduction, loss mitigation, privacy, and consumer protection;
(C)
barriers to adoption and considerations of interoperability, data access, liability, error rates, and regulation; and
(D)
how various fraud detection technologies differ in use, effectiveness, costs, benefits, and considerations under subparagraphs (A) through (C).
(2)
Community financial institution access— Community financial institution (that is either an insured depository institution or credit union) access to advanced fraud detection technology, including—
(A)
challenges faced by community financial institutions in accessing or deploying advanced fraud detection tools, including unique challenges faced by various types of community financial institutions;
(B)
whether economies of scale disadvantage smaller community financial institutions in general, or certain types of smaller financial institutions;
(C)
options to facilitate shared services, utility models, managed-service providers, or consortium-based fraud detection platforms; and
(D)
recommendations to ensure regulatory guidance is appropriately tailored to avoid discouraging adoption by smaller community financial institutions.
(3)
Artificial intelligence and machine learning— Artificial intelligence and machine learning, including—
(A)
the use by insured depository institutions and credit unions of artificial intelligence and machine learning models, applications, and tools in detecting fraud patterns, anomalies, synthetic identity fraud, and real-time payment fraud;
(B)
governance frameworks used by insured depository institutions and credit unions to manage fraud model risk, explainability, and validation; and
(C)
steps Federal banking agencies can take in coordination with other relevant government agencies and the private sector to ensure access by insured depository institutions and credit unions, including community financial institutions and their third-party vendors, to such models, applications, and tools.
(4)
Information sharing and public-private partnerships— Information sharing and public-private partnerships, including—
(A)
the effectiveness of existing information-sharing frameworks;
(B)
whether expanded public-private partnerships or centralized fraud utilities would enhance detection capabilities;
(C)
the feasibility of a voluntary fraud analytics consortium accessible to community financial institutions; and
(D)
privacy, data protection, and cybersecurity considerations associated with expanded data sharing.
(5)
Payments system risks— Payments system risk, including—
(A)
fraud risks associated with electronic funds transfers and checks; and
(B)
whether advanced analytics can reduce fraud while preserving settlement finality and payment system stability.
(6)
Regulatory and supervisory considerations— Regulatory and supervisory considerations, including—
(A)
what benefits and risks arise from existing supervisory expectations with respect to innovations in fraud detection and prevention, including whether existing supervisory expectations create barriers to innovation while maintaining relevant safeguards;
(B)
the need for interagency guidance, regulatory clarity, or safe harbors to support technology adoption in a manner that promotes fraud detection and prevention consistent with consumer protection, privacy, safety and soundness, and national security;
(C)
opportunities to harmonize expectations across Federal banking agencies; and
(D)
whether additional training for Federal banking agencies staff is necessary to promote effective regulation and supervision of financial institutions’ use of advanced fraud detection technology, especially for community financial institutions.
(c)
Report and recommendations—
(1)
Report— Not later than 18 months after the date of enactment of this Act, the Federal banking agencies shall issue a report to the Committee on Financial Services of the House of Representatives and the Committee on Banking, Housing, and Urban Affairs of the Senate containing all findings and determinations made in carrying out the study required under this section, and make such report publicly available.
(2)
Classified annex— A report under paragraph (1) may include a classified annex, if applicable, provided to the committees.
(3)
Recommendations— The report required under paragraph (1) shall include legislative, regulatory, or supervisory recommendations that promote fraud detection and prevention consistent with consumer protection, safety and soundness, and national security, which may include—
(A)
proposals to support shared fraud detection utilities or consortium-based analytics platforms;
(B)
guidance or safe harbors to encourage artificial intelligence use in fraud prevention;
(C)
pilot programs tailored to community financial institutions; and
(D)
recommendations to strengthen public-private information sharing consistent with privacy and civil liberties protections.