Visa has updated A2A Protect, its tool for catching account-to-account fraud, with a unified fraud score built on technology from Featurespace, the fraud-detection firm it completed acquiring in December 2024, as it looks to help banks flag suspicious transfers before a payment is authorised rather than after money has left an account.
The update, announced on 1 September, is Visa’s first in-market integration of Featurespace’s technology since the deal closed. The unified score combines Visa’s own network transaction data with Featurespace’s transfer-learning models, giving a bank a risk signal without waiting months for its own fraud models to learn from its own transaction history, Visa said.
Featurespace became part of Visa’s Risk and Identity Solutions business unit when the acquisition completed in December 2024, and Visa said the technology is being folded into its existing fraud-prevention and risk-scoring products.
Banks that opt in can also draw on what Visa calls network-level signals: fraud patterns detected across other institutions on Visa’s network, intended to help catch coordinated scam activity that a single bank might not spot from its own data alone. Visa said the tool integrates with a bank’s existing systems through a single API, and each alert carries a plain-language explanation of why a transaction was flagged.
Account-to-account payments move money directly between bank accounts, often through instant-payment or open-banking rails, rather than through a card network, and the fraud risk is different. In an authorised push payment scam, the customer authorises the transfer themselves, often after being manipulated, so a check that only flags suspicious activity after the money has moved is of limited use.
Visa is positioning A2A Protect as a check that runs before a transfer is authorised, working alongside a bank’s own fraud engines and confirmation-of-payee tools rather than replacing them. That risk isn’t confined to the UK: instant-payment rails have spread fast, from the EU’s SEPA Instant scheme to the US’s FedNow and RTP networks and equivalent real-time systems across Asia-Pacific, all moving money the same way A2A Protect is built to police.
Visa’s move comes as account-to-account payments accelerate globally. Citing Juniper Research’s Global Instant Payments Market Report, Visa said A2A transaction volumes are projected to surpass 5.8 trillion by 2028, a 160% increase on 2024.
Visa said A2A Protect “has been shown to reduce over 50% more fraud and help reduce over 40% in unnecessary fraud alerts,” though its release doesn’t say which institutions were involved, over what period, or how the results were measured. Separately, Visa said the tool has been shown to increase fraud detection by 75% in its first six months of deployment, again without disclosing the underlying sample or independent validation.
“Fraudsters move fast across payment types, and financial institutions need risk insights just as quickly, without slowing down legitimate payments,” said James Mirfin, Visa’s head of risk and security solutions. “A2A Protect combines Visa’s network expertise with Featurespace’s technology to deliver a powerful new layer of protection that helps financial institutions detect more fraud, earlier.”
The update lands against a UK regulatory shift that gives payment firms a direct financial reason to catch this kind of fraud earlier. Since 7 October 2024, firms covered by the Payment Systems Regulator’s rules have generally been required to reimburse eligible victims of authorised push payment scams, subject to the scheme’s conditions and exceptions.
The Payment Systems Regulator reported that payment firms had reimbursed £243 million to victims by the end of 2025, and said it had seen a drop in the categories of fraud its reimbursement policy covers. David Geale, the PSR’s managing director, called the past year “a defining year for payments regulation.” The regulator also fined Bank of Ireland UK in February 2026 for missing the deadline to implement Confirmation of Payee, a separate control aimed at reducing payment fraud; the PSR’s announcement didn’t disclose the size of the fine.
The launch also follows Visa’s agreement in August to acquire BioCatch, a behavioural-biometrics fraud-detection firm, for approximately $2.4 billion in cash, a deal Visa expects to close by the end of its 2027 fiscal second quarter, subject to customary conditions and regulatory approvals. The two deals build out Visa’s fraud and security portfolio, though the company hasn’t said whether BioCatch’s technology will be combined with Featurespace’s.
The more open question is adoption. A2A Protect can run on a bank’s own data alone, but the deeper fraud-detection gains Visa is advertising depend on banks opting into network-level intelligence sharing. How many banks choose to share fraud signals across the network, and under what governance and data-protection terms, remains to be seen.