Fraud controls and AML controls are not the same audit
Fraud teams track loss rates, chargebacks, and authentication friction. Financial crime compliance teams track monitoring quality, screening coverage, CDD refresh, and escalation to the MLRO. Both matter in payment services. They are not interchangeable.
When a single slide deck merges “risk controls” without separating purposes, boards hear comfort that neither team can defend under scrutiny. In our audits we keep the two lenses distinct even when the same people wear both hats.
If you are scoping an assurance cycle, say whether the question is “are we losing money to abuse” or “can we evidence financial crime controls to a regulator or sponsor bank.” The fieldwork, samples, and findings language should follow that answer.