Skip to content

Lloyds banking data shows patterns linked to financial abuse

A Lloyds-led study of anonymised banking records links missed payments, falling credit scores and account changes to women who disclosed abuse, but researchers warn against reading single events as individual warning signs.

By

Published
An open ledger book on a table, its written entries trailing off into blank pages with a single key resting in the fold.

A peer-reviewed study using anonymised Lloyds Banking Group banking records has found that women who later disclosed domestic or financial abuse to their bank showed markedly different financial behaviour, in the years beforehand, from women with no known disclosure. The study (opens in a new tab), published in Nature on 23 September 2026, compared 5,428 women who disclosed abuse with 15,602 matched women, drawing on up to seven years of account history each.

The finding matters to any UK current-account holder, but particularly to women, since 87% of customers who disclosed financial abuse to the bank in the study identified as female. It also matters to every FCA-regulated retail bank now working out how to meet the Consumer Duty, which since 31 July 2023 for open products and 31 July 2024 for closed products has required firms to pay "appropriate regard" to customers' characteristics of vulnerability. The researchers and universities involved stress, however, that this is a retrospective, group-level analysis. It was not designed to identify individual customers or to trigger automated interventions, and it does not, on its own, tell a bank who is being abused.

What the banking records show

The research drew on the bank's record of 9,728 women who disclosed abuse between 2020 and 2024. After filters for age (18 or over), holding a current account, an account-structure restriction and averaging at least six transactions a month in each year across current-account and credit-card records, 5,444 candidates remained and 5,428 entered the final sample. Each was matched, without replacement, to up to three women with no known disclosure, using nearest-neighbour propensity-score matching on age, income, transaction frequency, deprivation, credit score and borrowing products. The final matched sample totalled 21,030 people.

Researchers examined 373 outcomes: 353 transactional categories and 20 non-transactional variables such as credit score and benefit receipt, drawn from 162 million card transactions. Comparisons against the bank's wider customer base, in the year before disclosure, produced some of the study's starkest figures.

Measure (year before disclosure)Victim-survivorsWider bank-population benchmark
At least one unpaid Direct Debit63%17%
Average credit score767960
Average savings balance£3,088£14,215
Universal Credit receipt51%10%

The paper describes the unpaid-Direct-Debit gap as 279% higher and the Universal Credit gap as 421% higher; the credit score was about 20% lower and average savings 78% lower. In the more tightly controlled matched comparison — victim-survivors against women matched on income, deprivation and existing credit standing — the gaps narrowed but remained large and statistically robust: credit scores were 109 points lower (95% CI, 101 to 116; adjusted P<0.001) and the proportion with an unpaid Direct Debit was 31.9 percentage points higher (95% CI, 30.4 to 33.4; adjusted P<0.001). The credit score ran on a scale of 0 to 1,344 and drew on information from products beyond the bank, so a falling score reflects wider credit standing, not one account.

Signals, not diagnoses

Of the 373 outcomes examined, only 116 showed a statistically significant temporal cluster ahead of disclosure. A Nature Portfolio press release describes "373 indicators of financial abuse", which overstates what the analysis supports; this article uses "373 outcomes analysed" and reserves "signal" for findings the statistics actually back.

Among the account-management variables, victim-survivors changed passwords, changed addresses, reordered PINs and reported lost or stolen cards more often than matched controls. But the published main text gives no standalone accuracy figure — no sensitivity, specificity or predictive value — for any one event, and some variables were only recorded from June 2022, shortening that comparison. A password reset alone cannot distinguish safety-seeking from routine security hygiene, a fraud response or a forgotten login.

Timing adds a further caveat. Differences in balances and financial distress were already present at the start of the seven-year study window; differences in debt costs emerged around five years before disclosure, account-access differences around four years before, and some interaction, income-source and transport differences around six years before. These mark when a statistical difference between the two groups first became detectable relative to the date of disclosure — they do not date when abuse began, and disclosure itself may come long after abuse starts.

How banks might use the evidence

The FCA's guidance on vulnerable customers (FG21/1, 23 February 2021) defines a vulnerable customer as someone "especially susceptible to harm", particularly where a firm fails to act with appropriate care. Its Consumer Duty implementation review, published 20 February 2024, cites using customer data to identify potential vulnerability and referring the case to trained staff for appropriate communication as good practice — human-led escalation, not automatic diagnosis. UK Finance's voluntary Financial Abuse Code aims to support safe disclosure; membership creates no statutory duty to detect abuse.

The study's authors frame their findings the same way, calling for research to establish which indicators have genuine predictive validity before any could inform live support prompts. Nothing in the paper tests whether contacting a customer changes their safety or financial position.

The false-positive problem

A missed Direct Debit or a falling credit score is not specific to abuse. Redundancy, illness, fraud, separation or ordinary financial strain can produce the same pattern — using either as an individual label would carry a material false-positive risk. The study's "control" group is defined only by the absence of a known disclosure, not confirmed absence of abuse; the authors note that undisclosed victim-survivors may sit inside it, which, if anything, would understate rather than overstate the true differences. That does not make individual-level flagging safe: the population-level gap could be larger than measured, while the accuracy of any single flag for any single customer remains untested.

The sample also narrows what can be concluded. It draws on one bank's disclosure population, filtered to women with active current accounts and regular transactions, and does not establish that the findings extend to men, non-binary customers, women who never disclose, customers of other banks, or people with limited or joint-only banking access. The design cannot show causation: the relationship could run in either direction, or reflect other unobserved factors common to both.

Privacy and automated decisions

Any bank moving from research to a live, individual-level abuse-risk system would face distinct data-protection questions. The ICO's summary (opens in a new tab) of the Data (Use and Access) Act 2025, published 19 June 2025, says significant solely automated decisions now require safeguards: information about the decision, an opportunity to make representations, meaningful human intervention, and a route to contest it. Restrictions on using special-category information in automated decision-making remain in place, which matters here because inferring abuse status touches on sensitive personal circumstances. Separately, ICO guidance on data protection impact assessments (opens in a new tab) lists systematic profiling with significant effects, large-scale use of sensitive data, monitoring and processing data about vulnerable people as high-risk factors that can require one. Whether these provisions were fully in force in every respect as at 28 September 2026 was not conclusively established for this article, so firms considering this route would need their own current legal assessment.

The Lloyds research went through the bank's internal privacy governance: a Privacy Risk and Impact Assessment was submitted in March 2024 and approved in August 2024, following review that included its Group Data Protection Officer, using anonymised data with only aggregate findings reported. That approval covered a retrospective research project, not a live detection tool, and does not validate any future system built on these findings.

Safeguarding before contact

UK Finance's Financial Abuse Code is built around supporting safe disclosure, and Lloyds Bank's own financial abuse support page (opens in a new tab) describes specialist support and an in-app messaging route as a more discreet way to make contact than a letter or phone call. The underlying safeguarding concern is straightforward: an abuser may monitor a partner's post, email, texts, banking app, device or a joint account, so contact that reveals a bank's suspicion could increase risk. The material reviewed does not set out a single, universal protocol for safe contact — the right channel likely depends on the customer's circumstances, and that judgement sits with trained staff rather than an automated system.

Funding and disclosure

Lloyds Banking Group funded the study and supplied the underlying data, and three of the paper's authors were Lloyds employees. The paper states that the bank otherwise had no role in study design, analysis, the decision to publish or manuscript preparation, and the work underwent peer review before publication in Nature.

What to watch next

The authors call for further research to test predictive validity before these patterns could inform individual support decisions; a prospective, independently validated and survivor-led trial would be a meaningful next step. Further FCA guidance on vulnerable customers, and any updated ICO guidance on automated decision-making following the Data (Use and Access) Act 2025, would bear directly on whether and how a bank could lawfully build on this research. Readers wanting official detail can consult the Nature paper (opens in a new tab) directly, the FCA's guidance for firms on the fair treatment of vulnerable customers (opens in a new tab), and UK Finance's Financial Abuse Code (opens in a new tab). Anyone currently experiencing financial or domestic abuse should use their bank's own support channels, such as Lloyds' financial abuse support page linked above, rather than rely on this article for individual guidance.

Sources

  1. Social science: Identifying the signs of financial abuse (opens in a new tab)

    Nature Portfolio · · Accessed

  2. FG21/1: Guidance for firms on the fair treatment of vulnerable customers (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. Consumer Duty implementation: good practice and areas for improvement (opens in a new tab)

    Financial Conduct Authority · · Accessed

  4. Domestic Abuse Act 2021 (opens in a new tab)

    UK Parliament · · Accessed

  5. Financial Abuse Code (opens in a new tab)

    UK Finance · · Accessed

  6. Data protection: Data (Use and Access) Act 2025 summary of the changes (opens in a new tab)

    Information Commissioner's Office · · Accessed

  7. When do we need to do a DPIA? (opens in a new tab)

    Information Commissioner's Office · Accessed

  8. Financial abuse support (opens in a new tab)

    Lloyds Bank · Accessed

All Fraud & Security coverage