Challenge

How might we help Unicaja protect customers from digital scams and social-engineering fraud by identifying risk at the right moment and triggering clear, proportionate and secure interventions without adding unnecessary friction to legitimate journeys?

Unicaja wants to strengthen customer protection against digital fraud and social-engineering scenarios in which customers are manipulated, impersonated or induced to disclose credentials or authorize transactions.

The challenge aims to test a mature, risk-adaptive solution that can detect or contextualize suspicious situations, provide timely guidance or verification, and support customer and employee response while preserving smooth digital journeys.

Unicaja

Unicaja is one of Spain’s leading banks and a listed company on the IBEX 35. With a strong regional presence and long-standing social heritage, it provides financial products and services to individuals, businesses and institutions across the country.

Read more

Challenge framing

Current Situation

Unicaja already operates secure digital banking channels, strengthened authentication, customer-assistance tools and cybersecurity education initiatives.

However, fraud may begin outside bank-controlled channels through SMS, email, calls, social media, messaging applications or fraudulent websites. Customers may be manipulated into completing technically legitimate authentication or payment actions.

Desired Situation

Unicaja wants a customer-protection capability that uses available context to identify when a digital interaction may be unsafe and respond with the least intrusive effective action.

Low-risk journeys should remain simple, while higher-risk situations may trigger contextual guidance, verification, a pause, strengthened authentication, human assistance, or another action approved by Unicaja.

The solution should help customers understand what is happening and how to proceed safely, while giving fraud and customer-support teams sufficient context to intervene consistently and securely.

Stakeholders

Stakeholders

Internal stakeholders
Fraud prevention and operations, digital banking product and UX, customer experience, customer service, contact centre, branches, cybersecurity, identity, security operations, data, AI, IT architecture, legal, privacy, compliance, operational risk, innovation, procurement and third-party risk.

External stakeholders
Digital banking customers, startups and technology providers, and relevant regulatory or supervisory authorities whose requirements must be considered.

Primary users
Digital banking customers using customer-facing protection mechanisms, fraud prevention and operations teams, and customer service, contact-centre or branch employees supporting fraud response.

Possible solutions

Possible Solutions

  • Fraud and scam detection and contextual risk-classification tools.
  • Secure communication and identity-verification solutions.
  • Contextual warnings and risk-adaptive customer interventions.
  • Device, session and authentication intelligence.
  • Threat-intelligence and malicious-domain or telephone-number detection.
  • Employee decision-support tools for fraud and customer-service teams.
  • Fraud reporting, escalation and case-orchestration workflows.
  • Customer education and guided fraud-prevention experiences.
  • Voice anti-spoofing for approved telephone use cases.
  • Monitoring and observability for alerts, models and integrations.

Technical Requirements

  • Use of approved transaction, authentication, device, session, fraud-case, customer-contact, journey and threat-intelligence data.
  • Integration with mobile and web banking, identity and authentication, fraud monitoring, CRM/contact centre, case management and secure messaging.
  • Low-latency processing where the selected intervention requires real-time action.
  • Explainable alerts and recommendations with clear reasons and contextual evidence.
  • Human oversight, safe fallback and escalation for uncertain or high-impact situations.
  • Spanish-language content aligned with Unicaja accessibility, tone and brand requirements.
  • Role-based access, encryption, audit logging, secure secrets management and segregation of duties.
  • GDPR, Spanish data-protection, DORA and EU AI Act alignment where applicable.
  • Model validation, monitoring, versioning, lineage, rollback and performance observability.
  • Mature, configurable enterprise product with secure APIs and evidence from banking or another regulated environment.
  • Voice, biometric or emotion-related data only with explicit legal, privacy and compliance approval; emotion recognition is not a default requirement.
Apply now