👉Our AI agents platform is now PCI DSS L1 certified!

sei
Compliance

Elder Financial Exploitation on the Voice Channel: What the Senior Safe Act, FinCEN FIN-2022-A002, and the State APS Handoff Actually Ask the AI Agent to Do

13 min read
Pranay Shetty
Share

The Fraud Retail Bank Compliance Talks About the Least

The FinCEN 2022 Advisory on Elder Financial Exploitation documented $27 billion in reported and unreported elder financial exploitation losses over a five-year window and made the point that the reported number is a small share of the actual number, because victims underreport for reasons the advisory names: shame, fear of losing independence, cognitive decline, and family dynamics that make disclosure hard. Retail bank fraud teams see the underreporting problem from the other side. The customer whose account is being drained by a "grandchild in trouble" scam, by a romance scam, or by a family member with power of attorney does not call to report the fraud, and the first signal the bank sees is often the pattern of transactions rather than a complaint from the person losing money.

The voice channel is where the earliest signal usually lives. A customer calling to wire $8,000 to a lawyer they cannot name in a city they cannot describe, a customer who is being coached by a voice in the background, a customer whose account activity looks different than it looked six months ago, a customer whose adult child has been added to the phone banking authorization but who does not seem to know what the child is doing on the account. The signal is present in the conversation, and the compliance team that hears about it is usually the compliance team that hears about it after the money has moved.

We build the agent that runs on retail-bank voice and chat channels. The architecture below is what we run to keep the agent's detection, the branch's response, and the bank's reporting posture consistent with the Senior Safe Act's immunity framework, FinCEN's 2022 advisory, and the state Adult Protective Services statutes the bank reports through.

The Senior Safe Act Immunity Framework and Why It Matters

The Senior Safe Act, passed as part of the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018, provides civil and administrative immunity to covered financial institutions and to specific employees who report suspected elder financial exploitation to a covered regulator or law-enforcement agency, if the report is made in good faith and with reasonable care and if the employee has received training under the Act. The immunity is significant because the historical friction on reporting has been the bank's fear of a civil action from the customer or a third party for the disclosure, or of a regulatory enforcement action for a disclosure that turned out to be wrong.

The training requirement is the operational hook. Covered employees must receive training on identifying and reporting suspected elder financial exploitation, and the training has to be recorded so the immunity is documented. The bank whose training is generic compliance-module content that mentions elder financial exploitation for two slides is a bank whose immunity is theoretically available and practically hard to invoke; the bank whose training is specific, scenario-based, refreshed annually, and documented per employee is a bank whose immunity is defensible.

The AI agent's role in the training and immunity structure is that the agent's detection creates the alerts the bank's employees act on, and the employees who receive the alerts have to be trained to act on them under the Act. The bank whose training is aligned with the agent's alert taxonomy and whose alert response process is documented under the Act's requirements is a bank whose reporting is protected. The bank that layers an AI detection system on top of untrained staff is a bank whose immunity does not fully attach and whose reporting decisions look more risky to the compliance team than they need to be.

What FinCEN's 2022 Advisory Actually Requires

The FinCEN Advisory FIN-2022-A002 updated the 2011 advisory (FIN-2011-A003) and expanded the red-flag list, the reporting mechanics, and the expected internal response. The advisory specifies that Suspicious Activity Reports filed for suspected elder financial exploitation should use the keyword "EFE" in the SAR narrative and the appropriate SAR characterization fields. The keyword is the mechanism by which FinCEN aggregates EFE SARs across the industry, and the bank that files an EFE SAR without the keyword is a bank whose report contributes to the underreporting problem the advisory is trying to solve.

The red-flag list in the advisory covers the transactional patterns (unusual withdrawals, wire transfers to unknown parties, changes in account beneficiaries or contact information, sudden add-ons of new joint owners or authorized signers), the behavioral patterns (a customer accompanied by a third party who does the talking, a customer who seems confused about the transaction, a customer who is under apparent duress or urgency), and the demographic and relationship signals (a customer who is elderly, socially isolated, or dependent on the party accompanying them). The AI agent's detection model runs on all three categories, with the transactional signals coming from the account activity that feeds the agent's context and the behavioral signals coming from the conversation itself.

The behavioral signals on the voice channel are the differentiator. A customer whose speech patterns during a call indicate stress, whose responses are being coached (subtle timing gaps followed by responses that are more precise than the customer's own vocabulary would produce, background audio suggesting a second person is present, or the customer asking to place the caller on hold and returning with different information), or whose emotional register does not match the transaction being requested are all signals that the agent can score and that a human agent listening to the same conversation without the score would often miss.

The Detection Model We Score Without Deciding

The agent's EFE detection produces a risk score per interaction with a set of contributing signals, but the agent does not make the decision to hold a transaction or report the customer. The decision is the branch's or the fraud team's, made by a human trained under the Senior Safe Act, and the agent's role is to surface the signal so the human can decide. This split exists for three reasons.

The first is the false-positive cost. A customer who is genuinely calling about a wire to their attorney for a real estate closing and who is being told the transaction cannot proceed because the AI has flagged them as a possible victim of elder financial exploitation is a customer who is being harmed by the bank's system. The immunity the Senior Safe Act provides does not extend to negligent or bad-faith reporting, and the reputational cost of a wrong hold applied to an elderly customer's legitimate transaction is meaningful. The score exists to prioritize human attention, not to substitute for it.

The second is the reporting immunity. The Senior Safe Act's immunity attaches to a report made by a trained employee acting in good faith with reasonable care. The report from an AI system without a trained human's judgment on the reasonable-care element is a report whose immunity posture is less clear. The bank's compliance and legal teams universally advise that the reporting decision has to be a human decision, with the AI's contribution being the detection and the evidence package rather than the report itself.

The third is the customer relationship. An elderly customer whose account is being managed with the assistance of a family member has a legitimate expectation of privacy and dignity in the transaction. A branch employee who has been trained on EFE and who is having a conversation with the customer or the family member has the judgment to distinguish between an accommodating family arrangement and an exploitative one; the AI's score alone does not carry that distinction.

The Temporary Hold and the State Financial Elder Abuse Statutes

Beyond the federal Senior Safe Act, many states have enacted statutes that allow (or require) financial institutions to place a temporary hold on suspicious transactions when EFE is suspected, and to report to state Adult Protective Services and often to state attorneys general or securities regulators. California's Financial Elder Abuse Reporting Act makes covered financial institutions mandatory reporters and requires a report within specified windows. The FINRA-analogous rules for broker-dealers at FINRA 2165 allow a temporary hold on disbursements and a trusted-contact framework, and while FINRA 2165 does not apply to banks, several state banking laws now include analogous provisions.

The state Adult Protective Services agencies vary in what they accept and how they respond. Some states have a centralized intake with a specific form or portal; others require reports to the county APS office where the customer lives; others require reports to the local law-enforcement agency in parallel. The bank's reporting flow has to know the customer's state of residence, has to route the report to the correct APS entry point, and has to preserve the record of what was reported when.

The temporary-hold decision, when the state statute allows it, is made by a trained employee with specific documentation: the reason for the hold, the reasonable-care basis for the suspicion, the notice provided to the customer under the statute, and the duration of the hold. The AI agent's contribution is the detection signal, the evidence package, and the recommended hold parameters based on the state's rules. The agent does not execute the hold; the branch or the fraud team does.

The Trusted-Contact Pattern the Bank Can Adopt Without Rules

FINRA 2165 requires broker-dealers to make reasonable efforts to obtain a "trusted contact" for each customer at account opening and at account updates. The trusted contact is a person the firm can reach out to when EFE is suspected, without disclosing account details, to help resolve the concern. Banks are not required to adopt the trusted-contact model, but several banks have adopted it voluntarily as an EFE response tool, and it is a control that the AI agent can operate on cleanly.

The pattern the banks we work with have adopted is that the agent asks the customer to enroll a trusted contact during high-risk conversations (account opening, adding an authorized signer, wire transfer setup, POA changes), records the contact's name and reachable channels, and provides a clear disclosure to the customer that the contact will be reached out to only in the specific EFE-suspicion scenario. When an EFE score crosses the threshold and the branch team decides a trusted-contact outreach is appropriate, the agent's system produces the contact record and the outreach script. The trusted contact's role is to help the bank distinguish between a legitimate transaction the customer wants and a coerced or confused transaction that the family or trusted circle would recognize as inconsistent with the customer's actual intent.

The privacy posture around the trusted contact is defined narrowly. The bank does not disclose account balances, specific transaction amounts, or any information beyond "we are concerned about a recent activity and would like to reach out to the customer directly; can you help us reach them?" The AI agent's outreach template does not disclose more than that, and the human employee who follows up does not disclose more either. The customer's consent to the outreach at enrollment is documented, and the customer can update or remove the trusted contact at any time.

The GLBA and Reg P Line the Reporting Crosses

The reporting to APS, to law enforcement, and to FinCEN through the SAR channel involves the disclosure of nonpublic personal information about the customer to a third party, which the Gramm-Leach-Bliley Act at 15 USC 6802 and Regulation P at 12 CFR 1016.15 restrict without the customer's consent. The exception at Reg P 1016.15(a)(2)(vi) allows disclosure to comply with federal, state, or local laws and regulations, and Reg P 1016.15(a)(7)(i) allows disclosure to protect against actual or potential fraud, unauthorized transactions, claims, or other liability.

The reporting under the Senior Safe Act and under state APS statutes falls within these exceptions, and the exceptions were re-affirmed by the CFPB in guidance around EFE reporting. The bank does not need the customer's consent to report suspected EFE to APS, to law enforcement, or to FinCEN, and the reporting under a good-faith reasonable-care standard is protected under the Senior Safe Act. What the bank does need is documentation that the exception was correctly applied, that the reporting was to the appropriate authority under the specific statute, and that the information disclosed was limited to what was necessary for the reporting purpose.

The agent's documentation of the disclosure captures the specific exception relied on, the statute or rule the reporting satisfies, the authority the report went to, and the specific information that was disclosed. The bank's compliance team can produce the record on request from the customer, from the customer's attorney, or from a regulator asking about the bank's Reg P posture on the disclosure. We wrote separately on the GLBA Safeguards Rule architecture that runs the broader Reg P and Safeguards posture.

The Coordination With the SAR and BSA/AML Programs

The EFE SAR the bank files through the BSA/AML reporting channel is a distinct filing with the "EFE" keyword and with specific narrative requirements from the FinCEN advisory. The bank's BSA officer's coordination with the retail banking team on EFE cases is the operational bottleneck we see most often. The retail team knows the customer and the interaction; the BSA officer knows the SAR filing mechanics and the FinCEN expectations. The AI agent's role is to translate the retail team's case notes into the SAR narrative the BSA officer can review, sign, and file within the SAR clock.

The SAR narrative the agent drafts includes the specific red flags observed, the transaction data, the customer profile relative to the historical pattern, the family or third-party involvement observed, and the bank's investigative steps and reasoning. The BSA officer reviews the narrative, adjusts as needed, and files. The 30-day SAR clock from the initial detection runs regardless of the bank's internal handoffs, and the agent's coordination role is to make sure the handoff from retail to BSA to filing happens inside the clock.

We wrote separately on the BSA/AML SAR-narrative architecture that the EFE SAR shares infrastructure with. The EFE SAR is a specialized subset with the "EFE" keyword and the FinCEN-specific narrative expectations, and the workflow the agent runs for EFE fits inside the broader SAR workflow with the specific EFE additions.

What "Good Faith and Reasonable Care" Looks Like in the Documentation

The Senior Safe Act's immunity requires good-faith reasonable-care reporting. What "reasonable care" looks like in the documentation is the specific evidence the report relied on, the training the reporting employee had received, the internal review process the report went through, and the specific decision-maker whose signoff moved the report to filing. The bank whose reporting comes from a compliance team member who has the training documentation, whose decision was based on the specific evidence the case file contains, and whose review process included consideration of alternatives is a bank whose reasonable care is documented.

The bank whose reporting comes from an AI system with a human rubber-stamp is a bank whose reasonable care is harder to defend. The immunity attaches to the human's decision, and the human's decision has to have substance. The agent's role is to make the human's decision easier by producing the evidence package and the recommended action, and the human's role is to actually make the decision with knowledge of the case, the customer, and the alternatives.

The documentation we build per case includes the agent's detection score and contributing signals, the account activity and conversation evidence, the customer's demographic and relationship context that fed the model, the human reviewer's assessment of the evidence, the reviewer's decision (report, hold, follow-up, or no-action-with-monitoring), the reviewer's training record at the time of the decision, and the specific reporting or hold action taken. The file supports the immunity claim and supports the customer's or family's understanding of the bank's response if a question later arises.

The Customer Conversation the Branch Has to Have

A customer whose account has been flagged for EFE, and whose transaction has been placed on temporary hold or whose activity has drawn a bank outreach, is a customer the bank has to talk to. The conversation is delicate for the reasons the FinCEN advisory named: the customer may be embarrassed, in denial, coached by the exploiter, or genuinely uncertain about what is happening. A branch employee's approach to the conversation makes the difference between the bank being an ally in resolving the situation and the bank being another source of stress for the customer.

The bank's script for these conversations, developed in coordination with elder-care advocates and drawing on the CFPB's 2016 Advisory and Report on Elder Financial Exploitation, emphasizes the customer's control over the outcome, the bank's role as protective rather than accusatory, and the specific options available (temporary hold with the customer's knowledge, trusted-contact outreach, APS involvement, joint call with a family member the customer chooses). The AI agent's role in the conversation is not to have the conversation autonomously; it is to prep the human employee with the case history, the specific concerns, and the customer's stated preferences from prior interactions.

We work with several banks whose EFE conversation guidance has been reviewed by state APS agencies and by aging-services nonprofits, and the shared learning is that the conversation quality matters more than the reporting rate. A bank whose reporting rate is high but whose customer relationships in the population are damaged by heavy-handed EFE conversations is a bank that will lose the trust that the population needs to have for the protection to work. The reporting is a tool; the customer relationship is the underlying capability.

The Failure Mode We Engineer Against

The pattern we most consistently see is the bank that has a strong EFE detection capability layered on a weak human response capability. The AI detects the signal; the alert goes to a branch employee who has not been meaningfully trained on EFE beyond the compliance-module content; the employee's response is either to escalate awkwardly to the fraud team without direct engagement with the customer, or to attempt a heavy-handed conversation that the customer experiences as accusatory. The customer's relationship with the bank suffers, the actual exploitation continues on a channel the customer no longer wants to talk about with the bank, and the EFE program's outcomes deteriorate while the detection metrics look strong.

What we build against this is a program where the AI detection is one component and the training, the conversation guidance, the reporting workflow, and the customer-facing response process are the other components. The AI is not the program; the AI is the earliest signal in the program. The program's success is measured by the outcomes of the exploited customers, not by the volume of alerts the AI produced, and the program's design has to keep that measurement at the center.

The Honest Read

Elder financial exploitation is the fraud pattern retail banks handle worst on average and one of the most consequential for the customers involved. The Senior Safe Act's immunity framework, FinCEN's 2022 advisory, and the state APS statutes together provide a framework the bank can operate under, but the framework depends on the bank actually operating under it: trained employees, documented reporting, coordinated internal workflow, and customer-facing conversations that treat the customer as the person the protection is for. The AI agent on the voice channel is a meaningful capability upgrade to the detection layer of the program, and the banks whose full program is upgraded to match are the banks whose EFE outcomes improve at the customer level.

The banks whose detection is upgraded without the corresponding upgrade to the human response are the banks whose EFE metrics look better and whose customer outcomes do not. The customers do not benefit from detection they never learn about; the customers benefit from the bank's response after the detection. We build the detection because the human response depends on it, and we work with our customers on the response training and the workflow because the detection without the response is a metric without a mission.

We have written separately on the FinCEN sanctions-screening architecture that runs the OFAC layer alongside the EFE analysis, on the BSA/AML SAR-narrative process that the EFE SAR filings share infrastructure with, and on the voice-cloning verification architecture that is the counter-fraud layer running alongside the EFE-victim protection layer. The retail bank's fraud and protection programs share the voice channel as the point of both threat and detection, and the architecture that runs the channel well handles both simultaneously.

Pranay Shetty

Pranay Shetty

CEO & Co-Founder

Related Articles

Compliance

The CFPB Consumer Response Portal With AI Complaint Handling: The 15-Day and 60-Day Response Windows, the Portal Tag Discipline, and the Public-Database Read the Bank Cannot Ignore

Every complaint routed through the CFPB Consumer Response portal is a supervised, time-boxed compliance event with a 15-day acknowledgment, a 60-day substantive response, a specific issue-and-sub-issue taxonomy that becomes the public database, and a consumer-dispute flag the Bureau tracks. The rule reads simple and the operations misfire often. Where the AI agent tightens the intake, the response drafting, and the root-cause loop, and the audit file the Bureau tests against in an examination.

Jul 31, 202613 min read
Read more
Compliance

FinCEN's Residential Real Estate Reporting Rule Under Section 6403 With AI at the Title and Closing Table: The Nationwide Reporting Person Cascade, the Beneficial-Owner Capture, and What the December 1, 2025 Effective Date Actually Changed

FinCEN's final rule at 31 CFR 1031.320, effective December 1, 2025, replaces the geographic-targeted Real Estate GTO regime with a nationwide reporting obligation on residential-real-estate transfers to legal entities and trusts. The rule uses a reporting-person cascade, requires beneficial-ownership capture on every covered transfer, and imposes a specific 30-day filing window. What the rule actually requires, how the AI agent participates in the closing workflow, and where the compliance risk lands for title, settlement, and mortgage professionals.

Jul 31, 202612 min read
Read more
Compliance

Reg DD Truth in Savings (12 CFR 1030) With AI Deposit-Product Recommendations: The APY Formula the Rule Actually Prescribes, the Change-in-Terms Notice, and Where an AI Cross-Sell Crosses Into Deception

Reg DD is the deposit-side companion to Reg Z: it prescribes a single APY formula, requires specific account-opening and periodic-statement disclosures, and imposes a 30-day advance-notice regime for adverse changes in terms. The AI cross-sell that suggests a higher-yield product, the retention offer that promises a rate, and the chatbot that answers 'what's my rate?' are all Reg DD surfaces. Where the disclosures actually have to appear, and where an AI conversation crosses the line into a UDAAP problem.

Jul 31, 202613 min read
Read more

BOOK A DEMO

Embed Sei AI in your workflows
Tell us about your operations. We'll show you how Sei handles borrower calls, processes loan documents, and monitors compliance for mortgage lenders and banks.
  • Deploy in weeks, not months
  • Trained on FDCPA, TCPA, TILA, UDAAP, and RESPA
  • SOC 2 Type II and PCI DSS L1 certified
  • Integrates with your LOS, CRM, and telephony

Please provide your full name so we know how to address you.

Tell us which company you represent so we can personalise our response.

Use your work email so we can connect you with the right specialist.

Choose the topics you’d like us to cover during the demo.

Complete the verification to submit the form.

sei

AI operations platform for mortgage lenders, servicers, and banks. Handle borrower calls, process loan documents, and monitor compliance.

Partners

Speechmatics

© 2026 Sei Software Technologies Inc. All rights reserved.