The Fraud Market Is Funding Its Way Toward Autonomous IRM

CB Insights just mapped more than 200 companies building the next generation of fraud and trust infrastructure. The pattern in the funding is worth sitting with. The platforms pulling in the most capital have stopped selling single tools. They sell one system that handles risk decisioning, case management, and compliance at once. CB Insights calls it the integrated stack. Fraud detection drew three and a half times the equity capital in 2025 that it raised the year before, and the orchestration platforms that fold identity, monitoring, and compliance into one system post the highest average company-health scores anywhere on the map. Sardine, SEON, and Feedzai lead that group, and they are the ones that have absorbed the most functions.

Here is why that reaches past fraud. Fraud detection is not a market of its own. It is one expression of integrated risk management, the work of governing compliance, enterprise, operational, and technology risk as a single system rather than four separate ones. Wheelhouse Advisors puts that market at $61.6 billion today, on its way to $147 billion by 2032. So the CB Insights map is not a separate industry sitting next to IRM. It is the corner of IRM under the most pressure, and pressure is where you see the direction of travel first.

Buyers learned the hard way that risk intelligence trapped in isolated tools cannot keep up with threats that cross channels faster than any single tool can follow. Fragmentation was the constraint. Consolidation is the response.

What the integration already spans

Take apart what these platforms combine. Compliance screening is GRC. Risk decisioning and case management run through enterprise and operational risk. Identity, device intelligence, and transaction monitoring are technology risk. So the integrated stack is not consolidation inside one domain. It reaches across all four, GRC, ERM, ORM, and TRM, and pulls them into one product. The buyers doing this are not working from a framework. They are following the threats, and the threats are dragging them across every domain at once.

This is where the CB Insights data becomes more than fraud commentary. The IRM Navigator™ Curve maps how an organization moves from Risk Dysfunction to Risk Agency through five stages, and each stage is unlocked by investing in a particular domain. GRC investment gets an organization off the foundational floor. ERM carries it further. ORM and TRM take it the rest of the way toward autonomous risk management. The platforms drawing the most capital are buying down that whole sequence at once, integrating GRC, ERM, ORM, and TRM capabilities that most of the market still runs as separate purchases. The integration is the engine. Moving up the curve is what the engine does.

A caveat keeps this honest. These platforms have integrated the capabilities. They have not connected that integrated system to enterprise risk reporting or the board, and the CB Insights data makes no such claim. What is funded and visible today is the capability layer. Wiring it into governance is the part nobody has finished.

The next layer is already forming

The same report flags a new category forming around autonomous AI agents that initiate transactions with no human in the loop, and it admits plainly that the controls to govern them do not yet exist at scale. I read that admission as the tell. This is an early category, not a mature one dressed up as proof, and early is exactly what the curve predicts here, at the top, where TRM investment pushes an organization into autonomous risk management.

The evidence off the map runs the same way. Accenture found that 85 percent of financial institutions do not believe their current systems can handle high-volume, agent-initiated transactions. The IMF has documented Visa scoring transactions in milliseconds with fraud, sanctions, and compliance logic built into the payment flow, compliance enforced at the moment of decision instead of after it. And Feedzai, sitting near the top of the integrated stack, is already pushing a "Know Your Agent" control layer, on the logic that more than half of fraud now involves AI. When the vendors at the leading edge are designing for autonomous agents, the next stage is not a forecast. It is being built.

Against the curve, this is the top stage showing up ahead of schedule. Once agents transact on both sides of a deal, risk intelligence cannot stop at telling an analyst what happened. It has to act, in the moment, across every domain the agent touches in a single decision. That capacity to act, not just observe, is what separates a system of action from a system of record, and it is the threshold of Autonomous IRM.

Where this goes

None of this finishes cleanly, and I would not pretend the timeline is tidy. But the shape is hard to miss. Integration gives an organization one view of its risk. One view is what makes coordinated action possible. The agent layer then forces the action, because no fraud console moving at human speed can govern a machine making thousands of decisions a second. The market is climbing the curve a stage at a time, and the next gap to close is the one between seeing risk whole and acting on it all the way up to the board.

The top of that climb is Risk Agency, where risk systems stop flagging and routing and start deciding and acting inside boundaries someone has actually governed. Fraud got there first for an obvious reason. It is where AI-driven threats landed first and hit hardest. The pressure arrived early, and the money is following it exactly where the curve said it would go.

What settles the argument is not the argument. It is the capital. The fraud market is simply the first place the climb toward Risk Agency turned visible and fundable, with capabilities from all four domains pulled into systems fast enough to match the threats. What is left is the harder stage, turning that integrated view into integrated action that reaches the board, and that is what the next wave of funding will pay for.

Ori Wellington

Orion “Ori” Wellington is the lead editor for The RiskTech Journal and The RTJ Bridge, where he helps shape editorial direction, guide strategic narratives, and support media relations across Wheelhouse Advisors. As a digital editorial advisor, Ori synthesizes trends in risk, technology, and governance, drawing from roles modeled on information security, risk analytics, and IT leadership.

Part of Wheelhouse’s AI-augmented research team, Ori works to distill complex signals into actionable intelligence—bridging expertise across domains and elevating the voice of integrated risk thinking.

https://wheelhouseadvisors.com
Previous
Previous

The Two Executives the Risk Technology Market Serves Least

Next
Next

Cyber Regret at the Gartner Security & Risk Management Summit: From Risk Dysfunction to Risk Agency