How it works
A velocity spike is a sharp change in how often, or how much, an account transacts compared with its normal behavior. It is less a scheme in itself than the visible footprint of one: a taken-over account being emptied, a mule account entering service, a compromised card being used before it is blocked, or a business account suddenly used for pass-through payments.
Fixed velocity rules, such as a cap on transfers per day, are blunt. They fire constantly on high-volume customers whose activity is normal for them, and they miss a low-activity account whose volume has jumped but still sits under the cap. Measuring velocity against each entity's own baseline, and against peers with a similar profile, separates genuine change from routine busy days.
Legitimate events also produce spikes, including salary days, school fees, harvest payments and festive periods. Detection has to account for these, or analysts are flooded with alerts every month end.
Red flags
- Transaction count or value in a short window far above the account's own history
- A burst of new payees or first-time counterparties added and paid in the same session
- Activity at hours the customer does not normally transact, or from a new device or location
- Many small outbound transfers in quick succession, or one large transfer after a series of small test payments
- A dormant or low-activity account that suddenly transacts every day
Signals the engine evaluates
- Transaction count and value per entity across short and long rolling windows, against the entity's own baseline
- Deviation from the peer group of customers with a similar product, segment and tenure
- Rate of new payee creation and first-time counterparties per session
- Device, location and channel changes that coincide with the change in velocity
- Calendar effects such as salary dates and month end, so expected peaks are not scored as anomalies
Investigation and response
- 01Establish what changed first: a login from a new device, a contact-detail update, a new payee or an unusual inbound credit.
- 02Contact the customer through a verified channel to confirm whether they made the transactions before releasing any held payments.
- 03If the account was taken over, secure it, reset credentials and pursue recalls; if the customer is moving funds for others, treat it as a possible mule account.
- 04Close the case with the confirmed outcome, and file a suspicious transaction report where the activity points to fraud or laundering.