HOST

Alexandre Berkovic

CEO at Sphinx

GUESTS

Cihat Fitzgerald

Chief Risk Officer at Ballerine

TL;DR: Cihat Fitzgerald spent 10.5 years at Visa as VP of Global Ecosystem Security, where he authored the risk standards that banks and regulators still reference today. Now Chief Risk Officer at Ballerine, he explains how agentic AI reduces merchant underwriting from 30-40 minutes to 8 minutes — and why fintechs entering payments consistently underestimate their regulatory obligations until the consequences arrive.

What This Episode Covers

Cihat Fitzgerald has worked every level of the payments stack. He started on the acquiring side at an ISO, managed merchant portfolios and fintech oversight at West America Bank, then spent a decade at Visa overseeing compliance and risk across the entire payment network. That career arc — from the trenches to the network level — gives him a perspective most compliance leaders do not have. In this conversation, he maps that experience onto the questions that matter now: where fintechs go wrong when they enter payments, how AI-first platforms eliminate the false positives that plague legacy monitoring, and what happens when AI agents start transacting autonomously.

Cihat also talks candidly about leaving a Dow 30 company for a 15-person startup, what he gained from a mentor at Visa who was comfortable putting him in rooms he did not expect, and why his personal philosophy — memento vivere, remember to live — shapes how he handles high-stakes work. He DJs on weekends.

Who Is Cihat Fitzgerald

Cihat Fitzgerald is the Chief Risk Officer at Ballerine, an AI-first platform that provides risk intelligence, merchant monitoring, and underwriting automation for financial institutions and fintechs. Born in Holland and raised in Cape Town, Cihat entered the payments industry when a recruiter pitched him with five words: "Yes, but we do it on the internet." He spent the next three decades building risk controls across every layer of the ecosystem — from ISO-level merchant acquiring to bank-level fintech oversight at West America Bank to a 10.5-year tenure at Visa, where he served as VP of Global Ecosystem Security and Integrity. At Visa, Cihat authored the Global Acquirer Risk Standards and the Payment Facilitator and Marketplace Risk Guide, frameworks that banks, fintechs, and government regulators worldwide still use today.

Why Fintechs Keep Failing at Payments Compliance

Fintechs entering payments see themselves as technology companies. They build a product, connect to the networks, and start processing transactions — often without understanding that they have entered one of the most regulated industries in existence. Cihat has watched this pattern end in what he calls a "smoldering impact crater" more times than he can count. The three most common failures: not maintaining a proper control environment, not documenting policies and procedures, and onboarding merchants without adequate underwriting. When Cihat managed compliance at Visa, the first question was always the same — show me your policies. Some fintechs handed them over. Others did not know what he was asking for. That gap is where most fintechs break. Jennifer Lee from Savvy Labs covers the same tension in her episode, and Sphinx has written about building a compliance program from the ground up.

How Agentic AI Cuts Underwriting from 40 Minutes to 8

Traditional merchant underwriting is analyst work disguised as a decision. The underwriter spends 30 to 40 minutes searching websites, checking complaint boards, pulling regulatory filings, and scanning for negative media — then makes a credit decision in the final few minutes. Ballerine's agentic AI automates that research layer. Feed it a merchant URL and the system reviews the site, identifies what is being sold, cross-references complaint boards and regulatory databases, and delivers an aggregated risk profile in roughly 8 minutes. The critical advantage is contextual awareness. Rule-based legacy systems flag any keyword match — a t-shirt with a marijuana leaf printed on it triggers the same alert as an actual marijuana seller. AI trained on payments risk understands the difference. The underwriter's role does not disappear. It shifts from data gathering to reviewing a complete evidence package and making the credit decision.

The Risk Vector Nobody Is Watching

The old saying in risk still holds: build a 10-foot wall, and the bad guys bring a 12-foot ladder. What has changed is the ladder. AI-powered fraud now operates at scale and with a precision that brute-force attacks never achieved. But Cihat points to a less obvious threat — agentic AI commerce. Autonomous agents browse websites, make purchases, and interact with payment systems, but there is no standardized way for a website to verify who or what an agent represents. That trust handshake between an AI agent and a URL does not exist yet. Regulators, as Cihat notes, usually show up after the first major incident. The risk officer of 2030 will need deep domain expertise, real-time visibility into key risk indicators, and the ability to manage AI systems that produce auditable decisions at every step. Nick Passarelli from Melio covers the operational side of running AI in compliance workflows.

Who This Episode Is For

  • Fintech founders and product leaders entering payments who need to understand the regulatory and risk obligations that come with processing transactions
  • Risk managers and compliance officers evaluating AI-powered underwriting, monitoring, and KYC solutions for their organizations
  • Payment facilitators, ISOs, and acquiring banks replacing legacy rule-based compliance systems with contextually aware AI
  • Corporate compliance professionals considering a move from large financial institutions to AI-driven startups and wondering what actually changes

Frequently Asked Questions

What are the biggest compliance risks for fintechs entering payments?

The three most common failures are operating without a proper control environment, lacking documented policies and procedures, and onboarding merchants without adequate underwriting or KYC. Cihat Fitzgerald, who managed compliance for Visa's global payment ecosystem, describes a recurring pattern: fintechs treat payments as a technology problem and neglect regulatory infrastructure until enforcement action or a fraud attack forces the issue.

How does AI reduce false positives in merchant monitoring?

AI-first compliance platforms use contextual awareness to distinguish between genuine risks and noise. Legacy rule-based systems flag any keyword match — a marijuana leaf printed on a t-shirt triggers the same alert as an actual marijuana seller. Contextually aware AI evaluates the full merchant profile, understands what is actually being sold, and eliminates alerts that do not represent real risk.

What is the difference between rule-based and AI-first compliance?

Rule-based compliance systems operate on if-then keyword logic: if a flagged term appears on a merchant website, the system generates an alert regardless of context. AI-first platforms analyze the complete merchant environment — website content, product catalog, complaint patterns, regulatory filings — and assess risk based on contextual understanding rather than isolated keyword matches. The result is significantly fewer false positives and more comprehensive risk coverage.

How long does AI-powered merchant underwriting take?

Ballerine's agentic AI reduces merchant underwriting from 30-40 minutes of manual analyst research to approximately 8 minutes. The time savings come from automating the investigation work — website review, regulatory checks, complaint board scanning, negative media searches — so the human underwriter receives a complete risk profile and focuses on the credit decision.

What is agentic AI in payments compliance?

Agentic AI refers to autonomous AI systems that browse websites, gather information, cross-reference data sources, and execute multi-step workflows without continuous human direction. In payments compliance, agentic AI automates merchant underwriting research, transaction monitoring, and risk assessment. Cihat Fitzgerald identifies agentic AI commerce — where autonomous agents make purchases and interact with payment systems — as an emerging threat vector that currently lacks standardized trust verification protocols.

Episode Transcript

Alex: Cihat, thank you so much for coming on the podcast. It's great to have you here.

Cihat Fitzgerald: Thank you.

Alex: You've lived across continents. You were born in Holland. You were raised in Cape Town. Now you're based in San Francisco. You move a lot. And you started out in aerospace before jumping into fintech. From defense tech to the dawn of e-commerce, from writing Visa's global risk standards to leading AI-driven compliance at Ballerine. You've seen every stage of fintech evolution. Today we'll dig into what those decades taught you about building trust at scale, pairing AI with governance, and keeping human judgment in an increasingly automated world. You once got a career changing call with the pitch, yes, but we do it on the internet. What made that moment click for you? And does this current AI wave feel the same point of inflection that you saw back then?

Cihat Fitzgerald: Good point. Okay. I worked for a software company primarily providing systems to defense and aerospace and what have you and I was there in a marketing function and I got a call one day and somebody asked, "Hey, we're looking for a marketing person." I'm like, "Okay." They're like, "Yeah, what do you do?" "Well, we process payments for Visa, Mastercard, other networks." And I'm like, "Okay, so who doesn't? What's the big deal?" And then indeed, the response was, "Yes, but we do it over the internet." And this was just when the internet was taking off and e-commerce was brand new. And I was like, this could be interesting. I decided to join them and I think it was a good decision because I just talked to somebody today too who jumped into payments. It says once you're in the payments business, I think you'll never leave, and it's pretty much like that. I think a lot of people can agree with me on that. I ended up in payments and I started on the marketing side, but then just evolved on the operations and the risk component and things evolved to that extent.

Alex: I love it. And do you think the internet moment and the AI moment are similar, different? What do you feel there being in payments from the dawn of internet to the dawn of AI?

Cihat Fitzgerald: I think it has a similar feeling for me, meaning when e-commerce came around and we developed a gateway that actually did the online transactions and what have you and it was very exciting and things were evolving and you have to keep up to date with what's next. Once that subsided, you're in the groove and you're doing things and e-commerce now is a pretty well standard thing. Once AI came around, it was interesting and I didn't know much about it. The only thing you hear about is GPT and things like that, but that's very rudimentary AI. But when I started working with Ballerine, I was really introduced into the depths of AI and how it can really revolutionize commerce or any aspect of business. And it has that same element to it where I feel excited about it and feel blessed to be basically on that side, pioneering that industry. Yes.

Alex: I love it. And you began in aerospace and defense on the software side.

Cihat Fitzgerald: On the software side. Yeah.

Alex: I imagine it's a very structured and risk averse space. Is there anything that carried over to your fintech compliance and risk?

Cihat Fitzgerald: I would say it was a completely different world. Obviously if anything, we did some business with large corporations or the government, and in that sense I got used to doing that and being -- I spoke at Boeing for a press conference and that was pretty awesome. Obviously in payments, that evolved, and in the end I was working with multinationals and large financial institutions, but I think that component carried over. My role was a little different. Previous company I was in marketing, started in marketing, but quickly evolved into operations of risk. That was a whole new world for me. Yeah.

Alex: Love it. Love it. Would love to dive into a little bit more of your career evolution. You've managed risk in the financial industry in a lot of places. You were at FinTech as VP of acquiring operations at West America Bank and as head of global ecosystem security at Visa. How did each environment change how you think about control, accountability, speed?

Cihat Fitzgerald: Sure. Okay. Just for those who maybe don't know -- I was on the acquiring side of payments and generally what that means is everybody's pretty familiar with the issuing side. The banks that issue you your card, that's all one side of the whole industry, and then the other side is actually the acceptance side. The acquiring side sets up merchants for card acceptance and essentially acquires the transactions, the sales, and then clears it into interchange. That's the side I was on, the acceptance side. A lot of people when I talked to them and they knew I worked for Visa, they're like, "Can you do something about my bill?" And I'm like, first of all we don't issue cards and second of all no. On the acquiring side, yes, I entered in through the fintech side, commonly known in the industry as an ISO or independent sales organization. Payment facilitators were involved and stuff like that. I came in through that side and what happened is those businesses are really in the trenches. They're on the forefront. They work directly with the merchants. They have to connect to the networks and the processors. They have to work with the banks. But you're really in the trenches and specifically on the risk side because you're responsible for a portfolio of merchants. You have to do the underwriting, the monitoring, the risk monitoring and everything, and I can tell you that in my career, there have been times when things didn't go perfect and things blow up or there's a fraud attack or whatever. To that extent, I learned a lot from being actually in the trenches doing it hands-on. Once I ended up at the bank and actually now managed a portfolio of merchants, but also fintechs -- now we have the oversight responsibility for the fintechs because the bank is held accountable by the networks. That added that extra dynamic. Now I had to have oversight over these fintechs but I knew the fintechs because I worked in that environment. It wasn't brand new to me. I knew how they thought. I knew how they conduct business and that really helped me. And then obviously graduating to the network itself, now you oversee a portfolio of financial institutions and fintechs too. But because I've been in that world and I worked myself up through that entire stack, it essentially gave me really good capabilities and visibility and understanding. When I had to talk to big banks or big fintechs, they essentially knew what I was talking about because I lived in their shoes. That was really helpful.

Alex: Yeah, I can imagine. And also talking about big banks and big fintechs, you helped author the global acquirer risk standards and the payment facilitator and marketplace risk guides. What do you think aged best in that framework and which piece do you think you'd need to rewrite today in the age of AI?

Cihat Fitzgerald: Good question. When I authored the global acquirer risk standards, there was a fragmented earlier iteration of it, but it was not truly global and it was not fully one cohesive framework for acquiring risk. I authored that and it was very well used not just by network participants like the banks and fintechs and what have you but actually also by the federal government and other non-US governments, because it provided a framework that protected the banks, the acquirers, but also other participants, the ecosystem in itself. That went a long way. When I left Visa, I know they rewrote it, so it graduated. But funny enough, I have people still asking me, "Do you have an original copy?" I have it. It was a public document, so obviously I have it. Yeah. And literally one of the biggest banks in the US not too long ago was asking me, "Do you have a copy of that version?" And I'm like, "Yeah, I do." But things always evolve and the new version that Visa has is more applicable to what the new risks are, the new fraud schemes and attack vectors. But yeah, I also wrote the PF and marketplace -- pay facilitating marketplace risk guide -- that's still on Visa's website and it's still used. I think that is really applicable today still. I think it really provides new fintechs with, hey, these are the risks. This is what you need to know. This is how you need to mitigate them. Because a lot of these fintechs consider themselves to be technology companies. They create a tech product or some service or platform and then they enter the payments industry and they have no idea that they're just entering a highly regulated industry that's very open to different risks they're used to. And I've seen the wheels come off many times where a FinTech's like, "Yay, we're doing payments now." And then, smoldering impact crater. I was like, I'm going to write this guide. And it really just provides the fundamentals and teaches FinTechs, hey, this is a new environment you're in. You're no longer just a tech company. You have responsibilities. You're accountable. You could be exposed to risks that you've never thought about.

Alex: And for all the fintechs watching us at home today, what do you say is the top three risks? What you've seen a lot of FinTechs fail really hard on?

Cihat Fitzgerald: I think one thing is indeed not maintaining a proper control environment. Meaning that they're all gung-ho -- let's do business, let's go to market, let's process lots of payments, let everybody into the payment system, all these merchants -- but not really understanding who they're letting in to the payment system and then exposing themselves to fraud attacks and other issues, regulatory complaints and what have you. It's good to enter the market and be gung-ho about it, but you need to pair it up with a proper control environment to really do it right because the bad guys go after those that have the weakest link. And that's what I've seen. That's number one. Number two is just not possessing really good policy and procedures on how to carry out their risk control environment and just winging it. That was one of the biggest things when I managed compliance for Visa and I saw a fintech or a bank faltering. The first thing I asked was, "Show me your policies." And some of them may go, "Hey, here they are." And I'm like, "Hey, great. Okay, you got something." And some of them were like, "Wait, what?" And I'm like, "Okay, there's your problem right there." Yeah.

Alex: Great. And after 10 years at Visa, you joined Ballerine. You went from leaving a Dow 30 company to joining a 15 person AI startup. What tipped the balance? Was it the product, the people, the timing? Why did you join?

Cihat Fitzgerald: It's a -- well, first of all, it's a big difference going from a corporate multinational to a startup. To me, I've never really worked for a startup. I've always been on the corporate hamster wheel, and that was my thing. And then when I left Visa, I actually took some time off, went back to Holland, spent some time just because my job there was extremely stressful. No pressure being the head of global security and integrity for the entire payment system. I took some time off and then I was contacted by Ballerine and at first I was like, okay, this sounds pretty interesting, but I wasn't quite sure what I was getting myself into. But we started talking and it really intrigued me and I was like, okay, yeah, AI, this is really the next future. But I didn't know really what they did, but I understood obviously my environment, my field. When I actually saw the technology that was being developed, to me I was very much like, oh wow, I wish I had this when I was at the bank or earlier. And it clicked and I was very impressed with it. And it is a different world. On the corporate side you have a specific function and you have your group that does your function. It seems in the startup world everybody does everything. You have a quote-unquote function, but in the end everybody does everything. That was pretty interesting and I'm sure there was a little bit to get used to.

Alex: Yeah. How did you adapt? Because you did go from Visa to that. And I imagine in terms of day-to-day responsibilities, adapting to fast-moving changes and sometimes being in a really ambiguous environment of high growth issues and back to high growth, etc. How does that really differ? How do you adapt?

Cihat Fitzgerald: Well, I think one thing -- I've had a lot of help from the Ballerine leadership. They really helped me understand where we're going, what we're doing, more as to how I can help. I think one thing that's been really interesting to me is training our AI models because I do have that knowledge and honing in those models so they really perform really well, but it's a constant thing. I think the funniest thing is -- if I can mention this -- my girlfriend came from the startup world. She's very startup startup startup and now she's in the corporate world. She works for a big multinational headquartered in San Jose.

Alex: And I'm the other way around. I came from the corporate world now.

Cihat Fitzgerald: You don't look really corporate. You feel very startupy.

Alex: Yeah. Hey, I've evolved.

Cihat Fitzgerald: Well, I guess I was the same on the corporate side. But it's funny, when she gets home or I get home, she's like, "Ah, this is what happened." I'm helping like, "Okay, this is how that works in the corporate world." But I'm like, "Wait, but I got this and this." And she's like, "Oh, this is how that works in the startup world." We really augmented each other. She's been also a really good mentor for me. But the Ballerine folks, really helpful, and I could see how they think now. And it is a different world, but it's very ambitious. It's good stuff.

Alex: And I think it's interesting because you said merchant underwriting used to take hours. What's actually happening now when Ballerine's AI can do it in minutes? Where's the time saved? What tasks disappear and what do teams do instead?

Cihat Fitzgerald: Okay. Well, I used to underwrite old school. Does it take an hour? It could take 30 minutes. Could take 40 minutes. Very easy merchants could be quick. If it's a restaurant, it's been around forever -- hey, approved. No big deal, no disputes, doing great. But sometimes you have to do large e-commerce companies with future delivery and maybe very little processing background. In that sense, you really need to understand who you're dealing with, what the risks are. And what's still being done today very often is an underwriter is actually doing a lot of analyst work going online, looking for the merchant, what's their website sell, how are they selling it, do they have any issues with regulators, with the FTC, you name it, or is there any negative media, do they have bankruptcies -- there's all these facets that you need to find out. And in the old school, you just go online and you sit there and pull it all up. You get the paperwork. You have to nonstop go to the scam boards, hope to find something, whatever. Whereas with AI, specifically agentic AI, that is all very automated now. To the point where you can just put a URL in and the AI can go and say, "Okay, here's the merchant. Go to the site." And then it's contextually aware, meaning, "Oh, well, they're selling crypto." We're going to go to the SEC or we're going to go to complaint boards, and we're not just looking at, okay, do they have a five-star, four-star rating? No, we go look at the one-star ratings and what are people saying? Why are they having -- "My card got charged without my authorization." That's what we want to know. And it really does essentially what an underwriter would take in half an hour, 40 minutes, in about 8 minutes if that, and much more comprehensively. The underwriter can just basically be there to make the credit decision, look at it once all the information is aggregated and then decide, okay, what are we going to do? Are we going to use mitigating controls to approve it? How can we underwrite this account, as opposed to just doing all the leg work. Yeah.

Alex: Yeah. And what do you see teams will do then? Is there going to be more expansion, more growth? Is there going to be consolidation? How do we deal with going from hours to minutes and make teams still productive?

Cihat Fitzgerald: Well, I think the biggest thing is that it's scalable now. Fintechs that have to take a lot of time to onboard these merchants can do it faster now. And they can pay better attention to the details. It's not like now they're going to sit there and do nothing. It's just that their job is more optimized to really look, okay, this is all the information we have, and they can scale. Now, for instance, if they start taking in more merchants, it's not like they're going to have to start hiring and doing a whole lot more stuff or train people because underwriters are hard to find and experienced ones for sure. Now you have basically AI augmenting the process by providing the information. Importantly, not making the actual credit decisions. That's still what the underwriter does. There are certainly some fintechs that say, hey, we can score based on all this information, anything with a very low risk score just auto-approve. But that's on them still.

Alex: Yeah, 100%. Legacy vendors decided to bolt AI on top of their systems but Ballerine was built AI first. What would you say is a measurable difference? What measurable difference does that make?

Cihat Fitzgerald: Yeah, there's legacy providers that have been around for a while. And when I talk providers, I'm talking primarily about the function of merchant monitoring. There's a mandate from the networks that e-commerce merchants have to be periodically monitored to make sure, hey, what's being sold online? Are there any issues? Did they add any products that maybe shouldn't be there? And there are legacy companies that have been around and developed the technology to do that. Back then it was very relevant, but it was very rule-based. If-then. Very rigid. And in that sense there are drawbacks. Back then it was a solution and it made sense. These days it delivers a lot of false positives. I'll give you an idea, strictly rule-based. If you're looking for a merchant -- it's a keyword search. If marijuana is on the website, then flag it as a risk. But what if a merchant's got a -- selling iPhone covers and there's a marijuana leaf on the iPhone cover and it says marijuana leaf t-shirt, it would be flagged by rule-based logic. Whereas AI is contextually aware. It looks at everything and it goes, well, okay, they're selling iPhone covers, so marijuana is not going to be a thing here because there's nothing else about marijuana. That reduces the false positives and it makes the workload so much easier for risk managers. They don't have to start going to all these websites and say, oh, there's a problem here. And the AI can also flag something and then explain itself -- hey, we got a problem here because on the website it says that, and here's the link to exactly where it is. Saving a lot of time.

Alex: And we see the same exact thing in compliance at Sphinx. The auditability is probably one of the most important things that people want to see in those models. And especially one thing is fraudsters -- they evolve really fast as well. I've seen sometimes the evolution of the financial crime companies that fight financial crime goes just as fast as fraudsters because they compete with one another. And how do you make sure that models don't just automate old biases or miss new tricks? Because I would imagine if you at Ballerine or us make a wrong decision -- a credit score you have to approve, or us a compliance decision you have to make -- the trust is really broken with the company you work with. What is a feedback loop? What do you have in place to mitigate that?

Cihat Fitzgerald: Number one, yeah, you're right. On the fraudster side, there's this old school saying in risk: when you build a 10-foot wall, they'll bring a 12-foot ladder. There's always something. I guess it's job security. And yes, now that we use AI, rest assured the bad guys use AI quite a bit, and soon really leveraging agentic AI. Doing attacks at scale and very precise and more subdued than just brute force type stuff. And in that sense, at Ballerine we maintain models that are specifically trained on the field of payments and fraud control and risk management as opposed to just a straight-up GPT that will -- who knows, it will come back with something but not always that reliable and hallucinate -- where our models are very trained. And we keep an eye on what the latest rules are, where the latest trends are, what the latest attack vectors are and things that we need to know about. And then we train our models. That's what people pay for -- those very trained models. And how do we mitigate the model going sideways? There is human intervention. It's not just, here's the model, good luck, here's the keys and enjoy. We train our models and we closely monitor output. And then we have a human element in it so that we can look at it, qualify it. The main issues that we run into is that our models actually do too good of a job and bring back a lot of information. We may want to just tighten it down a little bit. But then also we retrain our models based on the output and evaluate it and say, okay, hey, that's great, but this is what we need. And that's really a lot of value that we provide.

Alex: Yeah, that makes a lot of sense. We have exactly the same thing for us as well. And I think there's a balance to strike between the amount and level of information you bring, the quantity of it, not to overload people, and sometimes it's even harder to make it more concise and readable to someone rather than give them a huge dictionary of facts. Move fast and break things is one of the startup mottos. Every startup lives by it. We try to move as fast as possible, break things, repair it and then move again and whatnot. Doesn't really always apply to payments and compliance and risk. How do you keep Ballerine fast but also risk-free or compliant? What's the internal mechanism that prevents speed from turning into sloppiness?

Cihat Fitzgerald: Yeah, you're right. It is more fast-paced, but I think it's done in a controlled fashion. We don't just say, oh yeah, this is a great idea, roll out to production and enjoy it. There's a testing environment and it goes through many iterations of testing. And we do roll out new capabilities. One big thing I've noticed is on the corporate side, it's like an aircraft carrier. If clients say we need this, we're like, "Yeah, we'll get to it." And one year later, "Hey, is this what you want?" Where in the startup world, it is completely different. We have PCs with clients and they're like, "Yeah, but we really want this." And then within very short order, we have something that's already been tested. And in that sense, it takes a lot of work. I can see there's a lot of around-the-clock work that goes into this. It's not like the corporate side. This is, we're working on it all night. We have a deadline. And it is like that. To that extent, I don't see us breaking things and, as you said, it's probably not a good approach in the payments or financial sectors. Yeah.

Alex: Yeah. And it's interesting because as you said you've been both in the traditional corporate side of things, now in the startup side of things, and this space -- compliance, risk -- is well, obviously very risk-averse. Sales cycles can be long, there's a lot of skepticism. And you're often selling to traditional banks, acquirers I imagine with Ballerine. What is a way to convince a skeptical compliance head to trust your AI platform? Is it demos? Is it relationships? What really goes at play there?

Cihat Fitzgerald: I think one big factor is actually demonstrating the capabilities. I'm often at trade shows or engaged with prospects and they're like, "Well, tell me what you do." And I tell them but it's very abstract -- yeah, we help with risk intelligence, merchant monitoring, all that stuff. And they're like, "Yeah, okay, that's great, but so do many other companies." The rubber hits the road when they actually see it in action and see the product itself. And I've been literally in many meetings with risk leadership where they're sitting around a table and we show the capabilities and they're literally looking at each other like, "Are you seeing this? What is this?" It's like, "I didn't know this was possible." I'm like, yeah, it's so hard to explain. The demos are super helpful because AI is new to everybody. Yeah, okay, use GPT at home or whatever. But not agentic AI with that power. And when you show it to them then the wheels start turning. "Oh, I get it."

Alex: But always in startup demos, and even for us, it often looks amazing, and then when you have to actually go to production there's different data sources that are fragmented and are unformatted and you have to orchestrate everything in order to actually make your decisions correctly and whatnot. How does that work for you guys? How long is an implementation time and where do you see the real stickiness of the product?

Cihat Fitzgerald: I'd say the implementation depends. Larger clients -- we need to work with the tech group, get API set up and all that integration done and sometimes customized things. But in reality, for a fintech, if they want to start using it overnight, it's, here's the platform, here's your password, here's your environment, good luck. For the larger players it is a little bit more work on the integration side. Also some of them are still very heavily dependent on legacy providers and very fragmented. They use one solution for this, another for that, another for that. And they have all these different platforms that don't talk to each other where we have a unified platform that looks at all the data elements, all the risk intelligence and then cross-pollinates it to say, hey, this makes sense, but that doesn't make sense. That is generally not the use case right now in most of the industry from what I see. Yeah.

Alex: Yeah. Ballerine really has to orchestrate for those legacy players that have six different systems, all of those sources together.

Cihat Fitzgerald: Yeah. And obviously they're already integrated and they've been used to it in some sense. Some of them even have contracts that can't just cancel overnight. I think the biggest good thing is that we show our capabilities. They see what they're actually now missing out on and then start working an actual step-by-step program to adopt our technology. It's not like, oh, hey, this is great, yeah, where do I sign? It's a little bit more work than that. Yeah.

Alex: And you said that compliance with network rules is non-negotiable. How do you prove that AI decisions are really compliant? Even for us, we see sometimes when we show them the results with the audit trails, they're like, "I'd still rather have a human review it or do that." How do you go past that mental barrier?

Cihat Fitzgerald: Yeah, it depends on what component of the network rules. There are obviously certain components that are fairly straightforward when it comes to merchant underwriting and monitoring. If you get into more complex things, it is a little bit of a different world. But I think on our side, our models are trained on the rules and constantly retrained on the rules. I've seen our models do a really solid job, but yeah, you're right. We still have that human component to look at the output. It's in the background so the client is not really in the loop, but it is something that's super important. Also, rules change, regulations change, and you have to stay up to speed and you have to see how the model handles that. Yeah.

Alex: And there's been so many companies -- as you said, the systems are the environments in which analysts work in are extremely fragmented. They use a tool for this, a tool for that and so on. There's never really been a runaway winner in compliance or reg. There are really big companies of course -- you have the LexisNexis and the NICE Actimize and the ComplyAdvantage etc. But there's never been a runaway winner. Why do you think that is? And do you think that AI might actually change that?

Cihat Fitzgerald: Yeah, I think each solution provider or platform has their own niche of what they do, like LexisNexis, and then there's, for instance, OFAC compliance and sanction screening and all that, which is another solution. Everybody has their wheelhouse that they really do well. Where AI and good platforms come in is that in our sense we have the risk intelligence, we have the monitoring, we have the underwriting, but then we're not here to reinvent LexisNexis or other solutions. We could easily API into that, which is what we do, and make it part of the entire workflow. It's not just a lone-standing platform but now we have also the power of LexisNexis. We could even plug in the FIS transactions of their merchants into it and start cross-pollinating that as well. Yeah.

Alex: And do you think the industry is ready for AI-specific compliance standards or will existing frameworks like card network programs or OCC guidance simply expand to cover it?

Cihat Fitzgerald: No. I think at some point there will be some compliance standards put in specifically with agentic AI. Now you have everybody can build their own agent. They go to websites and do who knows what -- agentic commerce. Now you can buy your shoes with an agent. But how do you know where the agent's going? How does the website trust who the agent is? When there's a handshake between a URL and an agent, maybe there has to be some standardized solution along that line. And I think at some point the regulators will probably catch up, but the regulators usually show up after there's already been a problem.

Alex: They always do.

Cihat Fitzgerald: There has to be a problem for them to come in. Sorry, I didn't say that.

Alex: I just want to get back to what you said right before. Having AI being able to cross-pollinate different systems and being able to, for instance, use the power of LexisNexis and the power of Actimize together for a broader system. But you said those companies still cobble together tools for KYC, onboarding, monitoring and whatnot. I agree that today there's this cross-pollination, connecting systems together, allowing them to create a layer on top of it. But in 5 years, do you see there being one unified platform emerging, a modular ecosystem that actually plays nicely together, and what we're doing right now is actually going to be the standard and just be done in a better way? How do you see it in five years?

Cihat Fitzgerald: I think if there was such a thing, to a large extent it would have already existed today. I don't think there's going to be one solution for everything. There may be some really top competitors, but it's just the way of commerce. I don't think there will be one overarching solution. Obviously you have different networks. It is a complex ecosystem and no, I don't see that really happening. I do see some players that will stand out above the rest, but there will always be competition. Yeah.

Alex: Thank God. What's the next blind spot risk leaders aren't watching yet? There's AI-generated fraud and synthetic IDs and deep fake onboardings. What do you think is one of these big issues that might really cause problems to some risk leaders?

Cihat Fitzgerald: Yeah, if I had to bring up something, it is the agentic component of AI -- to automate agents with really good context capabilities and to do it very fast over broad scale. I think as opposed to old school when we had bots -- this is next-level bots. I think that's really where something that we haven't fully comprehended yet as to what risk that could pose. Yeah.

Alex: And as automation is going to scale, what does the risk or compliance officer of 2030 look like? Is it a data literate operator managing AI pipelines? Or a strategist focusing on edge cases and escalation, or on growth and expansion? What does that risk officer look like?

Cihat Fitzgerald: I think personally the role of a risk officer is to have either a deep expertise of risk in its field. And maybe you can't know everything, but to create a group or a team that has all the expertise needed to properly manage risk in that field. Expertise is really big, either if it's a chief risk officer or the group he's put together. And then to constantly look at key risk indicators, to potentially look at the needles, and to have a control environment so if something goes sideways you immediately know about it and you can immediately mitigate or contain or whatever it is. To put that visibility in place so you have really good oversight over things. And I think to obviously stay up to date on the latest fraud trends, threats and what have you. Sure.

Alex: Yeah, for sure. All right, let's go a bit more personal here. Personal insights, philosophical takes. I always like to go into it. You live by the motto memento mori, remember to live. How has that mindset shaped your career choices and leadership style?

Cihat Fitzgerald: Well, yeah, the whole one is here. Memento mori. Remember to live because remember you die. It's a Latin saying, obviously. Pretty to the point. And that philosophy of mine is you have to live life. Even when I work and work and work, you have to offset that. You can't just -- you have to live life. To that extent, I do things to offset the intensity of the work and what have you, specifically in my role at Visa. There was a lot of responsibility. And in that sense, you need to have a little bit of a steam valve. Yeah, I like to live life. I have a lot of hobbies that I do and things that make me happy. On the other hand, I'll tell you this. My girlfriend likes to have another tattoo over on this arm that says what Dirty Harry used to say. He says, "A man's got to know his limitations." And I was like, "Hey, I know you like to live life, but timeouts."

Alex: You're a bit like David Solomon from Goldman. You're really intense, but you also DJ ever so often. You're DJing this weekend. That's amazing.

Cihat Fitzgerald: Yeah. No, it's a good creative outlet. And I've been doing it for a long time, but it is definitely -- when you're DJing or working on music and sets or whatever, that's all you think about. You don't think about all the other stuff.

Alex: I'm curious. I've always been curious. I feel like if you're in a startup and you tell, "Hey, I'm a DJ as well." No one's going to be shocked. And then for being at Visa in the more corporate world, what is the reaction of people? Did they ever come to your sets?

Cihat Fitzgerald: Yeah, I have friends at Visa. They definitely like my music. Some -- we've DJed together. Some friends. Actually at Ballerine, a good colleague of mine is also a really good DJ.

Alex: No way.

Cihat Fitzgerald: And we're definitely set to play together at an industry event or when we're together sometime. But yeah, it is a little bit cooler on the startup side. You're like, hey, DJ, hey, great. Of course. Whereas the corporate side, you're like, "You do what? What? How did that happen?" But then again, I worked with a lot of people -- "Send me your sets." You'd be surprised how many people like good music.

Alex: I can imagine. And you've also mentioned exploring Rupert Spira's work on consciousness. How does that influence how you handle uncertainty or lead?

Cihat Fitzgerald: Yeah, I think it changes your perspective a little bit. You're in the world, you're doing your stuff, everything seems so -- reality is so finite and solid and you're doing everything, but do you ever really think about who you really are and what you do here? And it gets deep. But you learn that, in my sense, you're technically not just the meat popsicle. There's more to it. There's also a bigger spiritual side to things. And when you start thinking about life that way, it shifts just your focus. And I think you become more capable at handling things and not overwhelmed easily. And it adds a sense of zen or peace. Yeah.

Alex: Yeah. And you've also mentioned you had a mentor at Visa who helped you navigate a really complex system there. What's the most valuable thing you learned from him and how do you mentor others now that you're on the other side?

Cihat Fitzgerald: Yeah, I think -- funny enough, I just had lunch with him. Really good guy. Yeah. Jumping in from a bank into a Dow 30 component and working in a very intense group -- I knew risk, I've worked with merchants, I know the banking side, I know the fintech side, but I didn't really fully -- my expectations were like, oh my god, the whole how a corporation's politics and interactions and everything works within that machine, and how to navigate that. It's different and it is more intense. And it's something also along the line where everybody makes mistakes but at that level it was almost like, no, we don't make mistakes here. And it adds a new level of intensity. And also you have to learn all the different functions within the organization. And he was very helpful in helping me navigate that whole how everything worked -- the politics, the interactions, how to deal with certain leadership components, other functions. He introduced me, actually made me visible. And he wasn't a leader who's like, hey, you tell me what to do and I'm going to be the guy. He's like, here, you do it. And not many people do that. Not many people have the wherewithal and the confidence to just say, hey, as my subordinate, go ahead and present to this committee or whatever. And he was very comfortable with that, but he also gave me a lot of guidance -- hey, great, well done, or, what the hell is that? You can do better than that. He was a really good mentor and helped me tremendously for sure. And how that works today, I'd say mentors are hard to find like that. If you find somebody like that in your organization, you're very lucky. It's a cutthroat business often, specifically the corporate side. And not everybody's willing to help you. If you do find a soul like that, appreciate it and also make them better. Do what you can to lift them up. That's very important. Yeah.

Alex: How heavy were the politics at Visa?

Cihat Fitzgerald: No, it wasn't like politics. It was just how to navigate certain things. I would say a big component was the fact that if you're in meetings, it's just that you cannot just go sideways. It is a very high level of expectancy. It's high stakes. And if you do go sideways, you will know. People will be glad to point it out. In that respect, also with certain components -- how do you approach certain people? Certain leaders in certain functions, they respond differently to how you approach them, so you need to know that. You can't go to one person like, "Hey, this is this," and they're like, "Great." You do the same to another person, and it's, "Who are you? What do you want? Get out of here." I wouldn't say politics in a bad sense, but more in navigating how to interact with people and their specific roles, leadership and responsibilities.

Alex: And how does that differ from being at a startup? I imagine it's much more flat, especially with the size.

Cihat Fitzgerald: Easy peasy. Yeah, totally different. I think my colleagues -- we're all in the trenches together. Nobody's sitting on a pedestal. Our CEO, he's just your buddy, and that's different. In that sense, that is not an overtone. It's more about getting things done and getting deliverables. Going to market is a really big thing. In that sense, it does alleviate a lot of that pressure but then again it's offset by, we need everything now, we need to close, we need this and that. We have investors, we have this and that. In that sense, it's a balance, but yeah, much better in a startup from my experience.

Alex: Different levels of stress. Yeah. Cool. Well I'd love to close with a few lightning questions. What's the most overhyped buzzword in fintech right now?

Cihat Fitzgerald: AI.

Alex: I couldn't agree more. It's crazy how much people put that word everywhere and it is part of a process now. You can't use it to your advantage. It's not an advantage anymore. If you don't have it, you're just done. You're cooked.

Cihat Fitzgerald: A good way to see what the buzzwords are -- when you drive on I-80 to get on the Bay Bridge and back and you see all these billboards. It used to be back in the day, it says FPGA -- field programmable gate array -- to ASIC, application specific integrated circuit. That was everywhere, that was the big thing. And then later it was e-commerce, "We do this and e-commerce." And now it's all AI agents, agents, AI agent. You just drive down there and you know what the latest buzzword is.

Alex: Most underrated control that actually works?

Cihat Fitzgerald: In my world, you'd be surprised -- this sounds basic but I've seen it overlooked so many times, I'll reiterate -- it is just to have proper policy in place. First of all, okay, what are your intentions, what do you want to do? And then attached to that policy you need to have your procedures and business processes. And then you do have a control environment to make sure -- and this is probably the most important, to answer your question -- the controls in place to make sure that your procedures are effective and your policy is effective and being followed. And that's how that works. Yeah.

Alex: One Visa habit you kept and one you dropped.

Cihat Fitzgerald: Oh wow. Interesting question. Let's see. One I dropped was not worrying about everything on planet earth. On the Visa side, there was always something. There was always crisis here, explosion there, whatever. But I think one thing I kept is just that perspective from looking at the entire ecosystem. Having that visibility -- that's very rare. Not everybody has that, especially on the risk side. You have folks that manage risk on the bank level or fintech level and that's the ecosystem. And I had the privilege of looking at it holistically, from the bottom up and even higher with the regulators and the government and what have you. To have had that visibility really helped me understand how the ecosystem works, and also when I approach a bank or whatever, to me it's easy peasy. That's probably one I kept. Yeah.

Alex: And what's the hardest thing you've had to learn in a startup?

Cihat Fitzgerald: Sales, sales, sales, sell, sell, sell. We go to market, more selling. And I'm not a sales professional. But I think, as I said, everybody's in the trenches together doing their thing.

Alex: What's one risk, rule, or regulation that you'd delete tomorrow if you could?

Cihat Fitzgerald: One rule, regulation. Honestly, I have to think about it.

Alex: All of them.

Cihat Fitzgerald: No, no, you need regulations. You need regulations. Yeah. Off hand, I don't know. Nothing comes to mind. If anything, in some sense, there are certain things that could probably be regulated better in my view. Yeah.

Alex: And last question. If you weren't in risk, what would you be doing? I feel like I know the answer, but go for it.

Cihat Fitzgerald: Yeah. I'd own a club on an island in the tropics. Making food, drinks, and playing music and just have a lot of fun. I like scuba diving, so that helps out a lot. There's my answer.

Alex: Love it. And is there anyone we should bring on the podcast next?

Cihat Fitzgerald: Yeah, I have some friends. One person comes to mind -- a former Secret Service guy, a really great friend of mine, come in with a cap and sunglasses and stuff and a trench coat. Yeah. With a big rifle. He's got some stories to tell, but I don't know if he can tell them all. But the thing is we worked very closely together and it was never a dull moment.

Alex: Yeah, I can imagine. Well, I'd love to have him there. Cihat, it was a pleasure having you on the podcast. Thank you so much for the time and yeah, we'll take the conversation offline.

Cihat Fitzgerald: Okay. Appreciate it. Thank you so much. All right. Take care.

View full transcript

Subscribe to the Podcast

Get new episodes in your inbox

Thanks for subscribing! New episodes are on the way.
Oops! Something went wrong while submitting the form.