Digital payment fraud has grown alongside real-time and account-to-account payment rails, where fraud types pose distinct detection problems. This narrative review examined peer-reviewed studies on machine learning for digital payment fraud detection in financial institutions, drawing on government and regulator publications only to establish fraud scale and policy context. It assessed detection methods, fraud typologies, reported performance, class-imbalance handling, explainability, and regulatory relevance across 47 sources. Most measurable performance evidence came from credit card studies, where supervised and ensemble models reported strong results that proved sensitive to the dataset, the metric emphasized, and the way validation was performed. For authorized push payment fraud, a high-loss authorized-transfer category that now carries direct reimbursement liability for payment service providers, no peer-reviewed detection-performance study was found; its only quantified figure came from a non-peer-reviewed industry pilot. Account takeover and synthetic identity fraud were similarly underserved. Recurring weaknesses ran deeper than any single method: class imbalance, data-leakage risk, absent temporal validation, concept drift, and accuracy-heavy metrics that need not reflect deployment cost. Explainability was weaker still. Many studies treated predictive accuracy as proof that an explanation was sound, while the resampling used to manage rare fraud can itself distort post hoc tools such as Local Interpretable Model-agnostic Explanations and SHapley Additive exPlanations. Machine learning fraud detection is mature for credit card fraud but not yet validated for authorized-transfer and scam-based fraud. Detection research must be built on institution-held authorized-transfer data, leakage-free protocols, cost-sensitive metrics, and direct tests of explanation fidelity.
Sorinola et al. (Fri,) studied this question.