in ,

PCI Federal’s Nick Dunn Calls for AI-Driven Program Testing for Fraud Control

PCI Federal’s Nick Dunn Calls for AI-Driven Program Testing for Fraud Control
Photo: PCI Federal
  • Nick Dunn has recommended testing government programs for fraud risks before launch
  • The PCI Federal executive has urged agencies to use AI to simulate fabricated identities and altered documents
  • Dunn has proposed measuring the time between fraud detection and deployment of a validated control

Nick Dunn, CEO of PCI Federal‘s Technology & Mission Solutions Sector, has proposed a “Time-to-Control” measure to help federal agencies assess how quickly they can respond to newly identified fraud schemes, not just how much fraud they uncover.

In a commentary published on Federal News Network Wednesday, Dunn noted that annual estimates of improper payments do not show how quickly agencies can address emerging fraud. He recommended combining response-time measurements with pre-launch testing and controls tied to key program decisions.

How Can Agencies Measure Fraud Response?

Dunn’s Time-to-Control metric would measure the period between identifying a credible fraud pattern and deploying a validated control to address similar attempts. Agencies could use the measure to identify delays caused by factors such as data access, technology release cycles, legal review, training or unclear responsibility.

Dunn cautioned that the metric should be balanced against the time needed to clear flagged transactions and the strain placed on legitimate recipients. A faster response could still create problems if controls generate excessive false positives or delay legitimate payments.

The emphasis on balancing speed with oversight echoes Dunn’s earlier discussion of AI governance, in which he argued that agencies need controls that can operate at machine speed while preserving accountability and an evidence trail for automated decisions.

How Can AI Help Test Government Programs?

Dunn recommended using AI in controlled environments before a program launches to examine how its rules and workflows could be manipulated. Agencies could simulate fabricated identities, altered documents, coordinated applications and repeated activity designed to avoid normal review thresholds.

The testing would focus on the program’s operating design rather than solely on cybersecurity or AI model vulnerabilities. It could also reveal whether a program accepts reused supporting documents, lets bank account changes go through without new verification or prevents reviewers from seeing links between related cases.

Dunn’s recommendations build on PCI Government Services’ previous work in AI-enabled fraud detection. In December 2025, PCI Government Services partnered with Seekr to provide federal agencies with AI capabilities for fraud detection and investigations, along with data readiness and intelligence analytics.

Where Should Agencies Apply Controls?

According to Dunn, agencies should start with decisions, including eligibility approvals, payment releases, award authorizations, bank account changes and exception overrides. Controls should provide reviewers with the evidence behind an alert, the applicable rule and permitted next steps.

He also called for agencies to assign a specific person to resolve each exception and document overrides, including who approved them and why. Contractors can support the process, Dunn said, but the government remains responsible for the decision.

ExecutiveBiz Logo

Sign Up Now! ExecutiveBiz provides you with Daily Updates and News Briefings about Artificial Intelligence

mm

Written by Miles Jamison

Carahsoft to Make Oxide Cloud Computer Available to Government Customers
Carahsoft to Make Oxide Cloud Computer Available to Government Customers
Mark Mager Joins GreyNoise as Head of Adversary Engagement
Mark Mager Joins GreyNoise as Head of Adversary Engagement