Bank fraud and financial crime investigation management system

The research team receives risk alerts along with the required client and transaction information. It records checks, decisions made and enforcement of the measures imposed.

The investigator does not see the customer and operation data related to the alert and does not receive confirmation of whether the designated measure has been executed. This results in the investigation being repeated or the action required remaining undone.

How the solution works

  1. The warning is followed by the source, version of the rule, and the associated operation. The investigator receives only the customer's data that they are entitled to use.
  2. Related signals are cross-checked, maintaining criteria for different risks and responsible queues.
  3. The investigator or the rule permissible for this purpose adopts a specific follow-up action.
  4. The system in charge of the measure reports whether the action was accepted, rejected, or whether its outcome is as yet unknown.
  5. The conclusion and subsequent revision of the study are returned for monitoring based on their true reliability.

Key challenges

  • Fraud signals are assessed separately

Solution capabilities

Data needed for investigation

The investigator is given related transactions, their participants, and previous alerts based on the purpose of the investigation and the employee's rights.

Individual Rules of Decision

Cases of fraud, money laundering prevention and sanctions have different criteria, terms and powers.

History of the study

Test records distinguish between confirmed data, hypotheses, additional checks and conclusions of the responsible specialist. Time stamps of events and their recording are maintained.

Adoption of a conservation action

The designated restriction or other measure is checked by the responsible enforcement source; the proposal is not marked as having already been executed.

Limited Communication

The allowed state, not the full content of the confidential investigation, is transmitted to the client or other process.

Monitoring the quality of control

The specialist evaluates the conclusion of the study, the confirmed loss and the data subsequently obtained. They are accompanied by the time of receipt and the reliability to evaluate the previous decision on the basis of the information available at the time.

Business context

Fraud signals are assessed separately
The investigator does not see the customer and operation data related to the alert and does not receive confirmation of whether the designated measure has been executed. This results in the investigation being repeated or the action required remaining undone.
Inspection assesses and impacts on the legitimate customer
The risk warning may be justified, but the signal alone does not yet explain the specific situation. The data available to the investigator helps with the necessary review and capture the solution. Both losses and unreasonable restrictions are assessed which prevent the legitimate customer from using the service smoothly.

Core features

  • Data needed for investigation
  • Individual Rules of Decision
  • History of the study
  • Adoption of a conservation action
  • Limited Communication
  • Monitoring the quality of control

Key integrations

Sources of Operations and Channels
The disorder, its state, and the timing of detection and response have been recorded.
Customer knowledge and risk signals
Identity, communications and inspection information is allowed for the investigation.
Processes in place for the measures
Acceptance and actual outcome of an authorized restriction or other action.
Investigation Papers and Decisions
The incident data, the conclusion of the assessment, its application limits and subsequent adjustments have been verified.

Potential impact (%)

The ranges indicate an illustrative relative change in the metric under the stated assumptions. Results depend on the starting position and actual use of the solution. Percentages for different metrics must not be added together.

Data collection time for the survey

16–42%Decreasing

This illustrative scenario assumes that 40-70% of information searches and repeated cross-checks can be addressed. That share is assumed to fall by 40-60%. Company data is needed to verify both the addressable workload and the resulting change.

Active search and reconciliation for the same type and complexity are measured.

Measures pending enforcement

2–12%Decreasing

This illustrative scenario assumes that the controls described can address 10-30% of discrepancies. That share is assumed to fall by 20-40%. Company data is needed to verify both the addressable share and the resulting change.

Counting against the time limit of a specific action unsolved execution uncertainties.

Conditional calculation scenarios. The assumptions have not been validated against client measurements.

When this solution is relevant

  • Investigators do not see if the suspension of payment or another designated measure has actually been carried out.
  • Data from the fraud alert investigation has been disaggregated, making it difficult to substantiate the conclusion and assess the effectiveness of the checks.

Implementation requirements

The sources of the alerts, the time limits for investigation and the powers of the staff are described. The data obtained and the results of the actions assigned must be visible to the investigation. For emergency measures, it is checked that the enforcement system can carry them out within the time limit.

Further development options

  • The course of additional risk types with their individual criteria and approaches
  • Evaluation of rules and models based on the results of verified studies, after assessing subsequent losses

Frequently asked questions

Adapting the solution to your business