Skip to main content
FinCrimes

Real-time detection with typologies that explain themselves

The FinCrimes detection engine scores a single transaction or claim in milliseconds and a historical backfile overnight, using the same 28 typologies on both paths. Each score carries the matched typologies, the signals behind them and a recommendation. Thresholds, windows and severities are parameters your team tunes, tests against its own history and promotes under version control.

See how it works
TransactionClaimPolicy & partyDetection engineReal-time API · streaming · batchTypology rules28 named typologiesversioned rulesetsEntity baselinesAdaptive thresholdsrelative to historyScreeningSanctions & watchlistsat ingest and decisionRing analysisEntity resolutionshared devices & IDsRisk score 0–100Contributing signals, matched typologies and an explainable evidence trailApproveProceeds as normalReviewRouted to an SLA queueBlockBefore the money movesDECISION RETURNED IN MILLISECONDS
Capabilities

What real-time detection gives your team

Scoring API

A machine-to-machine endpoint per workspace scores a transaction or claim before it is booked or paid. The response carries a 0 to 100 risk score, weighted signals, matched typologies and an approve, review or block recommendation.

  • Per-workspace API keys, each with its own rate limit
  • State carries across calls, so three sub-threshold deposits sent in three requests still read as structuring
  • A block-grade score or an inline sanctions hit returns a hold that a second person must release
  • Every scored event lands on the event stream, so batch analytics see real-time traffic too

Streaming and batch on one engine

Events arrive through an authenticated webhook, a message bus, SFTP file drops or uploads, and pass through one ordered, idempotent ingest path into the same detectors the API uses.

  • Native parsers for ISO 20022 (pacs.008, pacs.002, camt.053), SWIFT MT103, MT202 and MT940, ISO 8583, NACHA and ACORD
  • Schema inference, column-mapping templates and a data-quality report for every batch
  • Drift detection, and quarantine with a stated reason for records that fail validation
  • Batch lineage with rollback, and exactly-once handling of dropped files

28 explainable typologies

Each typology is a transparent, parameterized detector. An alert states every criterion with its threshold, the observed value and whether it was met, in plain language, with references to the records involved.

  • Banking: AML, cards, mobile money and remittances
  • Insurance: motor, life, medical and property claims
  • Further detectors for account takeover, authorized push payment scams, first-party bust-out and application fraud from shared devices
  • A seven-stage trace on every alert, from ingest to disposition

Per-entity baselines and analyst feedback

Activity is scored against each account’s own history as well as fixed parameters. Rolling state and precomputed features per entity let a velocity spike or dormant reactivation fire on the call that causes it.

  • Analyst dispositions become labels that measure precision for each rule
  • Whitelists and suppressions for confirmed false positives, applied on the real-time and batch paths
  • A proposed higher bar when a rule’s precision drops, active only after approval
  • An optional calibrated model, trained on your labels, that adds a capped, reason-coded signal

Rules studio

Every typology is a configurable rule for each organization and workspace. Rulesets are versioned, so you can show which version produced any alert.

  • Backtest a candidate parameter set over your own history before it goes live
  • Label agreement: how many confirmed alerts a change keeps and how many dismissed ones it drops
  • Shadow scoring of a challenger ruleset against the live champion
  • Counterfactual replay that turns a rule change into alert volume, rings caught and analyst workload

Detection assurance

A recall run plants labeled fraud rings in a shadow dataset and measures how many your current parameters catch. An adversarial run builds evasion variants that sit just under your thresholds and reports the tune that would close each gap.

  • Recall per typology, with the missed rings listed
  • Evasion margins per typology and the threshold change that would close each one
  • Recommendations only: no live rule changes without approval
How it works

From data to decision

  1. 01Connect sourcesWire up the scoring API, webhook, message bus or file drop, and map fields once with a reusable template.
  2. 02ScoreEach event is scored against the typologies for its product line, its entity’s rolling state and any promoted model.
  3. 03DecideThe response returns approve, review, block or hold. Your core system acts on it.
  4. 04RouteAlerts land in severity queues with SLA clocks and the evidence that raised them.
  5. 05LearnDispositions become labels that measure precision and drive suppressions and proposed tuning.
  6. 06Tune and testCandidate parameters are backtested, shadow-scored and replayed before a second person promotes them.
In the field

Where it is used

FAQ

Questions buyers ask

Get started

Take the next step

See real-time detection working on your own data, deployed on infrastructure you control.

Explore FinCrimes