Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
AI For Finance · CoreTrack
1AI, Automation & Digital Finance
iAI Foundations
Artificial Intelligence in FinanceAlgorithmNeural Networks and Deep LearningMachine LearningArtificial Intelligence vs Machine…Computer Vision in FinanceTraining Data and LabelsNatural Language Processing in Finance
iiGenerative AI
Generative AIGenerative AI vs Predictive AILarge Language ModelsEmbeddingsHallucinationFine TuningPrompting vs Fine TuningThe PromptThe Context WindowTool CallingGroundingVector DatabasesRetrieval Augmented GenerationRAG vs Fine Tuning
iiiAutomation and Workflow
Workflow AutomationAutomation vs AugmentationHow to Map a…Straight-Through Processing and Exception…Robotic Process AutomationRule EnginesMachine Learning vs Rule-Based…
ivDocument and Operations AI
Intelligent Document ProcessingBatch vs Real-Time vs…Document Classification vs Entity…Service Level AgreementsCase ManagementHow to Document Data…Reconciliation AutomationOptical Character Recognition and Data ExtractionConfidence Scores
vCustomer Systems, Identity and Digital Assets
Digital IdentityConsent ManagementBlockchain and Distributed LedgerChatbots and Conversational AIFrom Use Case to ProductionDigital Assets and TokenisationDigital SignaturesData Sharing in FinanceElectronic KYC and Digital Onboarding
viCredit and Fraud Systems
The Fraud AlertCredit Decisioning SystemsHuman in the Loop…Adverse ActionAnomaly DetectionThe Decision ThresholdCredit Score vs Credit DecisionAlert Triage and EscalationFraud Detection and Transaction MonitoringFraud Model vs Credit ModelHow to Build Human…
viiGovernance, Data and Vendors
AI Governance and the AI PolicyHow to Create an…Explainability and Interpretability ComparedThe AI VendorBias and Fairness in Financial AIShadow AIAccess Control and Data MinimisationCloud Computing in FinanceData Lineage and Master DataData ResidencyThe AI Use Case Register and Model InventoryThe Model Owner
viiiModel Performance, Monitoring and Resilience
Model DriftFalse Positives and False NegativesClassification MetricsAdversarial AttacksModel TestingBias, Fairness and Explainability…Stopping an Automated SystemModel ValidationAI Governance vs Model Risk ManagementPrompt InjectionHow to Create an…

Alert Triage and Escalation: Sorting Signal From Volume

Alert triage is the sorting that stands between a monitoring system and an investigator. At Sumeru Bank Limited, invented, four stages handle one month: 11,880 of 18,000 alerts close automatically as repeats, 6,120 get a 90 second read, 540 get 40 minutes and 27 become investigations. Escalation is the separate question of which of those 540 cannot wait.

A monitoring arrangement that raises eighteen thousand messages a month and puts five people behind them is not solving a detection problem but an attention problem. Detection already happened, in the sense that something matched a written line and a message exists; what remains is the far harder question of how much of a working life each of those messages is worth. Every stage is a bet that a cheaper look can safely close a large share of what arrives, and the whole design stands or falls on whether each of those bets can be checked afterwards rather than asserted.

What is alert triage, and what is it actually sorting?

Think about a small shop that takes orders on a phone. By evening there are two hundred messages. The shopkeeper does not read them in order and does not read them equally. She thumbs down the list in about a second each, and what she is deciding in that second is not whether a message is true. She is deciding whether this one gets answered now, gets answered tonight, or gets nothing at all. She will be wrong sometimes. She will still be right that reading two hundred messages carefully is not available to her, and that pretending otherwise means the urgent ones wait behind the routine ones.

Alert triageSorting alerts by how much attention each one is worth before anybody investigates any of them. is that thumb moving down the list, written down as a procedure so that it happens the same way every day and can be argued with. Triage sorts attention, and never truth. The distinction does real work: deciding what can be said about a closed alert. An alert that closed at the first read has not been declared lawful. Nobody established anything about it. The decision was that the ninety seconds already spent was the right amount, and that a second look was worth less than the same time spent on the next alert in the list.

Get that backwards and two things go wrong at once. The desk starts recording closures as findings. A month's report then says the arrangement examined 18,000 transactions and found 27 problems. No such examination happened. And the people working the list start feeling that closing an alert is a judgement about a customer rather than a judgement about a queue. Carried sixty times a day, that feeling is heavier than the work needs it to be.

Try it out

What is triage sorting?

What are the four stages, and what closes at each one?

Sumeru Bank Limited runs four numbered stages on the month's 18,000 alerts. The figures are that bank's own and describe one month of one deployment. Stage 1 is automatic suppressionClosing an alert automatically, with a record, because it repeats a pattern already cleared on that same account recently.: an alert repeating a pattern the desk already cleared on that same account within the last 30 days closes with a record and nobody reads it, and that is 11,880 alerts, being 66.0 per cent of the month. Stage 2 is a first readA short look at an alert, long enough to close most of them and no longer. of 90 seconds on the 6,120 that survive, of which 5,580 close there. Stage 3 is a fuller review of 40 minutes on the 540 that are kept. Stage 4 is an investigationThe work that establishes whether a case is actually fraud, rather than whether it is worth more looking at. of about 3 hours on each of the 27 that are confirmed.

The two closing identities are what make a stage list a description rather than a story, and they are worth reading slowly. Every alert closes exactly once: 11,880 plus 5,580 plus 540 is 18,000. And the 540 are the survivors of the first read: 6,120 less 5,580 is 540. A stage list that does not close in both directions is a diagram, not a design, and the difference is visible in about a minute.

StageWhat happensWho does itArrivesCloses hereGoes on
1Automatic suppression of a repeat already cleared on that account within 30 daysNobody. A record is written18,00011,8806,120
2A first read of 90 secondsA person on the desk6,1205,580540
3A fuller review of 40 minutes on a kept caseAn alert that survives triage and is given a fuller review rather than being closed.A person on the desk54051327
4An investigation of about 3 hoursAn investigator27270
One month on the servicing book18,00018,0000

Look down the last three columns and notice what is happening to the price. Stage 1 costs nothing per alert and handles the most. Stage 2 costs a minute and a half and handles a third of the month. Stage 3 costs forty minutes and handles three per cent. Stage 4 costs about three hours and handles fifteen alerts in every ten thousand. The cost per alert rises by a factor of roughly a hundred and twenty across the four stages, and the volume falls by a factor of nearly seven hundred, and those two movements are the whole engineering idea. The desk buys the right to spend three hours on twenty seven things by refusing to spend three minutes on eighteen thousand.

FOUR STAGES, FOUR DIFFERENT PRICES ALERTS ARRIVING HERE, SCALE TO 18,000 MINUTES EACH ALERT COSTS, SCALE TO 180 18,000 STAGE 1 SUPPRESSION 0 nothing at all 6,120 STAGE 2 FIRST READ 1.5 thinner than this text 540 STAGE 3 FULLER REVIEW 40 27 STAGE 4 INVESTIGATION 180 27 of 18,000 is 0.15 per cent, drawn as a stub so it can be seen at all THE BARS SWAP SIDES BETWEEN STAGE 2 AND STAGE 3. THAT CROSSING IS THE WHOLE DESIGN. Minutes consumed: 0 plus 9,180 plus 21,600 plus 4,860 equals 35,640 a month.
Volume falls and price rises across the four stages, and the two bars swap sides between the first read and the fuller review: stage 1 takes 18,000 alerts at nothing each, and stage 4 takes 27 at about three hours each. The left scale runs to 18,000 alerts and the right scale to 180 minutes.
AI For Finance Bootcamp — Fin Maverick

What does each stage cost, and how big a desk does that make?

The desk falls straight out of the volumes and the rates, with nothing else added. Multiply each stage by its own price and add. The 6,120 first reads at 1.5 minutes are 9,180 minutes. The 540 fuller reviews at 40 minutes are 21,600. The 27 investigations at 180 minutes are 4,860. The three totals sum to 35,640 minutes a month. At the bank's assumed working month of 8,400 minutes a person, that is 4.24 posts, so the fraud desk at Sumeru Bank Limited is 5 people, and the fifth exists entirely because 4.24 does not round down.

StageItemsMinutes eachMinutes a monthShare of the desk
1 Suppression11,880000.0%
2 First read6,1201.59,18025.8%
3 Fuller review5404021,60060.6%
4 Investigation271804,86013.6%
The month35,640100.0%

There is a second way to cut the same 35,640 minutes and it is more useful than the first. Instead of asking what each stage cost, ask what each alert cost by the time it finally closed. An alert that closes at stage 1 costs nothing. One that closes at the first read costs 1.5 minutes. One kept and then taken no further costs 1.5 plus 40, being 41.5. One that becomes a confirmed case costs 1.5 plus 40 plus 180, being 221.5. Now count the alerts by where they ended: 11,880 at stage 1, 5,580 at the first read, 513 at the fuller review and 27 at investigation. The four counts sum to 18,000. The minutes come out at 0, 8,370, 21,289.5 and 5,980.5, and those sum to exactly 35,640. The second cut is arithmetic on the bank's own locked figures rather than a new measurement, and landing on the same total from a different direction is the check that it is right.

THE SAME MONTH CUT TWO WAYS, BY WHERE EACH ALERT FINALLY CLOSED 18,000 ALERTS 11,880 5,580 513 kept and taken no further 27 investigated, being 0.15 per cent, drawn thinner than this leader line 35,640 DESK MINUTES 8,370 21,289.5 5,980.5 the 11,880 suppressed contribute nothing to this bar at all Closed at suppression 11,880 alerts, 66.0 per cent 0 minutes each, 0.0 per cent of the desk Closed at the first read 5,580 alerts, 31.0 per cent 1.5 minutes each, 23.5 per cent Closed at the fuller review 513 alerts, 2.85 per cent 41.5 minutes each, 59.7 per cent Closed at investigation 27 alerts, 0.15 per cent 221.5 minutes each, 16.8 per cent
Cut the month by where each alert finally closed and the two bars come out near opposites: the 66.0 per cent suppressed take none of the desk, while the 2.85 per cent kept and taken no further take 59.7 per cent of it. The 27 investigated cases cost 5,980.5 minutes, which is about 71 per cent of what all 5,580 first-read closures cost between them.

Two readings fall out of that picture and both are useful. The average alert costs this bank 1.98 minutes from arrival to closure. A figure that small is easy to hold in the head and multiply. And the expensive half of the desk is not where the volume is: the 540 kept cases, three per cent of the month, take about sixty per cent of everything. A cheaper desk comes not from attacking the 18,000, but from attacking the 540, and the only honest way to do that is to make the first read better at deciding which cases deserve forty minutes.

Try it out

The desk needs 35,640 minutes a month. Which stage eats most of them?

What does stage 1 do, given that nobody reads those alerts?

Everybody has a version of stage 1 at home. The smoke alarm outside the kitchen goes off whenever fish is fried. After the fourth time, nobody in the house runs to the kitchen; they hear it, register that it is seven in the evening on a frying day, and carry on. Running to the kitchen four times a week costs something, and finding fish there four times a week teaches nothing. The household has built a suppression rule, and a sensible one. The rule also carries the only risk a suppression rule ever carries: the evening the alarm means something else.

Stage 1 at Sumeru Bank Limited is exactly that written down. If an alert repeats a pattern the desk has already cleared on that same account within the last 30 days, it closes automatically with a record and nobody reads it. The 30 days is that bank's own choice and is not anybody's requirement. The one written line disposes of 11,880 alerts a month, being 66.0 per cent of everything the monitoring raises. The stage that does two thirds of the work is the one nobody would call detection, and it consumes no minutes at all.

Take it away and the arithmetic moves in a way that surprises people. Without stage 1, every alert reaches the first read: 18,000 at 1.5 minutes is 27,000 minutes. Suppression only ever removes repeats of patterns already cleared on that account, so stages 3 and 4 do not move. The desk then needs 27,000 plus 21,600 plus 4,860, being 53,460 minutes, or 6.36 posts and therefore 7 people. Suppression saves 17,820 minutes a month, being 2.12 posts, and in whole heads it is the difference between a desk of 5 and a desk of 7. At the bank's assumed fully loaded Rs 9,00,000/- a post, two posts is Rs 18,00,000/- a year.

THE DESK WITH STAGE 1, AND WITHOUT IT Each grid line is one whole post of 8,400 minutes. A bar rounds up to the next line. 1 2 3 4 5 6 7 WITH STAGE 1 9,180 21,600 4,860 35,640 minutes, being 4.24 posts, rounds up to 5 WITHOUT IT 27,000 21,600 4,860 53,460 minutes, 6.36 posts, rounds up to 7 ONLY THE FIRST SEGMENT MOVES. THE TWO EXPENSIVE STAGES ARE IDENTICAL IN BOTH BARS. 17,820 minutes saved, being 2.12 posts, and in whole heads a desk of 5 rather than 7.
Switching stage 1 off adds 17,820 minutes a month and takes the desk from 5 people to 7, and it does so entirely through the cheapest stage: the 540 fuller reviews and the 27 investigations are identical in both bars. The grid lines are whole posts of 8,400 minutes, and a desk always rounds up to the next one.
Try it out

Before the control below is moved: suppression closes 66.0 per cent of alerts with nobody reading them. With it switched off, how many posts does the desk need?

Play with it

Move the suppression share and watch the desk resize

One control: the share of the month's 18,000 alerts closed automatically by stage 1, from 0 to 80 per cent. One consequence: the alerts reaching a person redraw on the upper bar, the desk minutes restack on the lower one, and the post count is read off the grid line the bar rounds up to. Stages 3 and 4 are held fixed at 26,460 minutes throughout, on the assumption that suppression removes only repeats of patterns already cleared on that account.

The deployed reading, in numbers. At 66.0 per cent suppression: 6,120 alerts read at the first read, 35,640 desk minutes a month, 4.24 posts and therefore 5 people, costing about Rs 45,00,000/- a year at the bank's assumed Rs 9,00,000/- a post. At 0 per cent suppression: 18,000 alerts read, 53,460 minutes, 6.36 posts and therefore 7 people, about Rs 63,00,000/- a year. The 540 kept cases and the 27 confirmed cases do not move at any setting.
0 per cent, nothing suppressedsuppression 66 per cent80 per cent
1. ALERTS REACHING A PERSON AT THE FIRST READ, OF 18,000 6,120 2. DESK MINUTES A MONTH, AND THE WHOLE POSTS IT ROUNDS UP TO 1 2 3 4 5 6 7 9,180 rounds up to 5 the dashed line is the deployed reading, 35,640 minutes first read fuller review investigation Only the first read segment responds to the control.
Suppressed
11,880
Read at stage 2
6,120
Desk minutes
35,640
Posts needed
4.24
People
5
Desk cost a year
Rs 45,00,000/-

At the deployed suppression share of 66 per cent, 11,880 alerts close with nobody reading them and 6,120 reach a person, so the desk needs 35,640 minutes a month, being 4.24 posts, and therefore 5 people at about Rs 45,00,000/- a year.

Educational illustration. Figures are Sumeru Bank Limited's own and describe one deployment: one bank, one month, 18,000 alerts on a servicing book of 2,000,000 transactions. Suppression removes only repeats of patterns already cleared on that account, so stages 3 and 4 are held at 540 fuller reviews and 27 investigations at every setting. The hand check on 400 suppressed alerts tests that assumption on 3.4 per cent of one month. Posts are minutes over the assumed working month of 8,400 and people are that figure rounded up, at the assumed fully loaded Rs 9,00,000/- a post. The honest limit: pushing the share higher removes alerts nobody reads, and the arithmetic cannot establish whether the ones removed mattered.
Breaking Into Quants Bootcamp — Fin Maverick

How would anybody know the suppression is safe?

Here is the uncomfortable property of stage 1. Every other stage leaves behind a person who looked. A closure at the first read has somebody's name on it, and if that person was wrong somebody can go back and ask them what they saw. A suppressed alert has a record that it was suppressed and nothing else, so being wrong at stage 1 leaves exactly the same trace as being right. The only way to learn anything about it is to go back and read some of the suppressed alerts by hand. Reading them is precisely the work the stage exists to avoid.

Sumeru Bank Limited did that once. The bank pulled 400 of the month's 11,880 suppressed alerts and had them read as though they had arrived at the first read. None of them would have been kept by triage. A count of zero is worth something only because there is a number to compare it against. Among the alerts a person actually reads, 540 of 6,120 are kept, a keep rate of 8.8 per cent. Had the 400 behaved like the alerts people read, about 35 of them would have been kept. The check found zero against an expectation of thirty five, and that gap is the whole of the evidence.

The check on stage 1ReadingWhere it comes from
Suppressed alerts in the month11,880Stage 1, being 66.0 per cent of 18,000
Read by hand4003.4 per cent of the suppressed alerts
Keep rate among alerts a person reads8.8%540 kept of 6,120 read at stage 2
Expected keeps in the 400, at that rate35400 times 8.8 per cent
Keeps actually found0The hand check
What the same rate would imply for all 11,8801,048Arithmetic on the locked keep rate, not an observation

The 1,048 in the last row is the reason anybody bothered. If suppressed alerts were just ordinary alerts that nobody happened to read, stage 1 would be discarding roughly 1,048 keepable cases a month, nearly twice the 540 the desk actually keeps. The hand check argues hard against that. Zero out of four hundred is not the result a stage quietly throwing away a fifth of the desk's real work would produce.

Try it out

400 suppressed alerts were read by hand and none would have been kept. What does that establish?

Financial Analyst Program Bootcamp — Fin Maverick

Why is that check smaller than it sounds?

Because 400 is 3.4 per cent of one month of suppressed alerts, and one month is one month. A hand check on a sample can show that a stage is not making a large, evenly spread mistake. A hand check cannot show that the stage is not making a narrow one. If there is one kind of alert that suppression removes systematically, and that kind is rare enough that a sample of four hundred is unlikely to contain any of it, the check comes back clean and the kind stays invisible.

There is also a cost reason nobody escapes. Reading all 400 by hand at the first read rate of 1.5 minutes is 600 minutes, about a working day and a half. Reading every suppressed alert in the month would be 11,880 times 1.5, or 17,820 minutes. The 17,820 minutes are exactly, to the minute, what stage 1 saves, so a complete audit of the suppression costs precisely as much as the suppression is worth. The identity is not a coincidence and it is not a trick; it is the definition of the stage restated. The same identity also means the only checks available are partial ones, and the honest way to describe stage 1 forever is: a stage that saves two posts, checked once on 3.4 per cent of one month, with a result that argues in its favour and cannot settle it.

WHAT THE HAND CHECK ON STAGE 1 FOUND, AND HOW MUCH OF IT IT SAW 1. THE MONTH'S SUPPRESSED ALERTS 11,880 400 read by hand, being 3.4 per cent of them and 1.4 working days of somebody's time 2. KEEPS IN THOSE 400, ON A SCALE TO 40 Expected at 8.8 per cent 35 Actually found nothing was kept 0 3. WHAT THE SAME RATE WOULD IMPLY ACROSS ALL 11,880, ON A SCALE TO 1,200 Implied keepable cases 1,048 Cases the desk keeps in a month 540 The check argues hard against the top bar being real.
The hand check found nothing where about 35 keeps would have been expected, which makes it a real result, and it read 400 alerts, being 3.4 per cent of one month, which makes it a small one. Both halves belong in the same sentence, and the bottom panel shows what was at stake: the same keep rate across all 11,880 suppressed alerts would imply about 1,048 keepable cases a month.

What is case escalation, and how is it a different question from triage?

Everything so far has answered one question: how much attention is this worth. Case escalationSending a case out of the ordinary queue because waiting for its turn would itself cost something. answers a different one: does waiting cost anything. The two questions have different answers often enough that a design carrying only the first will reliably work the wrong cases first.

The household version is a leaking tap against a gas smell. The tap will cost more to fix if it is left, but it will cost the same amount tomorrow as today, so it belongs in the ordinary list. The gas smell may turn out to be nothing. The cost of being wrong about it grows by the hour, so it is still the one dealt with in the next four minutes. Nobody thinks the gas smell is more important than the tap. The gas smell is less patient.

At Sumeru Bank Limited the impatient cases are concrete. Of the 540 kept cases in the month, the bank held the transaction pending on 218 of them and released 191 after review, so 191 people had a lawful payment stopped in one month. Every day a kept case sits in the queueThe cases waiting for a person, worked in the order they arrived. is a day of somebody's held payment or a day in which money that has already left the bank gets further away, and neither of those costs is visible in the attention ranking triage produces. Escalation exists to close that gap.

TWO DIFFERENT QUESTIONS ABOUT THE SAME CASE TRIAGE ESCALATION The question it asks How much looking is this worth Would waiting cost something What it chooses A stage A route, and therefore a day What it is applied to All 18,000 alerts Only the 540 already kept What being wrong costs Minutes spent in the wrong place Money gone, or a hold left standing What it ranks against The other cases The clock THE CASE THAT SEPARATES THEM: A SMALL TRANSFER WHERE THE MONEY HAS ALREADY LEFT THE BANK. Triage ranks it low on attention. Escalation sends it the same working day. Both are right about their own question.
Triage asks how much attention a case is worth and escalation asks whether waiting for the queue would cost something, and the two genuinely disagree: a case can be small in value and still be one where a day of waiting decides the outcome. A design carrying only the attention question will work the wrong cases first.
Try it out

A case is small in value and the money has already left the bank. Triage or escalation?

Investment Banking Analyst Bootcamp — Fin Maverick

Which five criteria send a case the same working day?

Sumeru Bank Limited wrote down five. Any one of them, met by a case kept at stage 3, sends it to an investigator the same working day instead of into the queue. All five are that bank's own choices, and none of them is a standard, a norm or anybody's requirement.

CriterionWhat it saysWhy waiting costs something
1The money has already left the bank and cannot be reversed by an internal entryRecovery gets harder by the hour once funds are outside
2The account holder has already contacted the bank about the same transactionA person is already waiting, and the bank is already late
3The account was opened within the last 30 daysA new account has no ordinary behaviour to compare against
4The same beneficiary appears on alerts across three or more unrelated accounts within one weekA pattern across accounts is still running while the case waits
5The amount is at or above a value the bank set for itselfThe single loss is larger if it completes

One criterion is enough, and that choice is what makes the route usable at all. A rule requiring two or three would be more selective, and it would also take longer to apply than the ninety seconds of the read it sits inside. Taking longer than the read defeats the purpose of having it. The five are written as things somebody can check by looking at the case in front of them, not as things somebody has to work out.

FIVE WRITTEN CRITERIA, AND ANY ONE OF THEM IS ENOUGH 1 The money has already left the bank 2 The account holder has already called 3 The account is under 30 days old 4 One beneficiary across three unrelated accounts 5 The amount is at or above a value the bank set ANY ONE OF THEM SAME WORKING DAY 63 cases THE ORDINARY QUEUE 477 cases 63 PLUS 477 IS 540, WHICH IS EVERY KEPT CASE IN THE MONTH. The test sits inside the 90 second first read, so every criterion has to be checkable by looking rather than by working it out.
Five written criteria feed one junction and any single one of them sends a case out of the queue the same working day, which is what keeps the test cheap enough to apply inside a 90 second read. In the month, 63 of the 540 kept cases met at least one and 477 waited for the next working day.
Try it out

How many of the five criteria have to be met to send a case the same day?

India

Where the expectation behind any of this comes from

The international standard on monitoring transactions originates with the Financial Action Task Force at fatf-gafi.org, and what actually applies to a bank operating in India is stated by the Reserve Bank of India at rbi.org.in, with the Securities and Exchange Board of India at sebi.gov.in where the deployer is a market intermediary. Read the position at those sites and confirm the current version there.

The four stages, the 30 day suppression window, the 90 seconds, the 40 minutes, the five escalation criteria and the money value criterion 5 compares against are all Sumeru Bank Limited's own choices, not requirements, thresholds or effective dates.

What did the same-day route catch that the queue did not?

A route is only worth building if it can be shown to be selecting something, and that demands a count almost nobody produces by default: not how many cases went each way, but how many confirmations came out of each. In the month, 63 of the 540 kept cases went same day, being 11.7 per cent, and 19 of the month's 27 confirmed cases came from those 63. Nineteen of twenty seven is 70.4 per cent of all the confirmations, arriving through 11.7 per cent of the cases. The other 477 produced 8.

Put it as hit rates and the gap sharpens. The same-day routeThe path a case takes out of the ordinary queue when an escalation criterion is met. confirmed 19 of 63, being 30.2 per cent. The queue confirmed 8 of 477, being 1.7 per cent. A case on the same-day route was about eighteen times as likely to end in a confirmation as a case in the queue, and that ratio is the only evidence anybody has that the five criteria are doing more than sorting. Without it there is a route, a policy and no way to tell whether either was worth having.

A SMALL ROUTE CARRYING MOST OF THE FINDINGS 540 KEPT CASES 63 477 into the queue 11.7% 27 CONFIRMED CASES 19 from the same-day route 8 70.4% HOW OFTEN EACH ROUTE ENDED IN A CONFIRMATION, ON A SCALE TO 35 PER CENT Same-day route 30.2% The ordinary queue 1.7% About eighteen times the difference, and it is a count nobody produces by default.
The two bars flip: the same-day route carries 11.7 per cent of the kept cases and 70.4 per cent of the month's confirmations, so a case on it was about eighteen times as likely to be confirmed as one in the queue. That comparison is the only evidence that the criteria select rather than merely sort.

One caution before that is taken as proof the criteria are well chosen. The five are not equal. Criterion 1, whether the money has already gone, accounts on its own for 21 of the 63 cases and 8 of the 19 confirmations. Criterion 5, the money value, is the one written first in most places, and it adds 8 cases and 1 confirmation. The value threshold is the weakest of the five and it is usually the only one anybody writes down.

Try it out

63 of 540 kept cases went same day and carried 19 of the month's 27 confirmations. What does that say about the criteria?

Retrieval and Grounding for Finance — free micro-course from Fin Maverick

What does a case need in front of the person working it?

Ninety seconds is the entire budget for the first read, and 6,120 of them is 9,180 minutes of somebody's working life. Whether ninety seconds is enough is decided by one thing only: whether the case arrives assembled. The contents of an alert record when it is raised are set out under the fraud alert. A case has an age and an alert does not, so a triaged case needs that list plus one more item.

The eight items are the transaction, the account, the line that fired, what that line compared, what this account usually looks like, whether the payment is held, the age of the case, and who holds it. Two of those are the ones that quietly break the budget. If the case does not carry what the line compared, or what this account usually looks like, the person has to go and assemble the comparison instead of reading it. A first read that drifts from 90 seconds to four minutes adds 2.5 minutes across 6,120 alerts, being 15,300 minutes a month, and that takes the desk from 35,640 minutes to 50,940 and from 5 posts to 7. Seven people is the identical answer produced by switching suppression off altogether. A presentation fault and a missing stage cost the same two people.

WHAT A TRIAGED CASE CARRIES, AND WHICH TWO ITEMS DECIDE THE 90 SECONDS ITEM DOES IT ARRIVE WITH THE CASE 1 The transaction Yes, assembled 2 The account Yes, assembled 3 Which line fired Yes, assembled 4 What that line compared Often fetched, and this is where the budget goes 5 What this account usually looks like Often fetched, and this is where the budget goes 6 Whether the payment is held Yes, assembled 7 The age of the case Yes, and only a case has one 8 Who holds it Yes, assembled A 90 SECOND FIRST READ 35,640 desk minutes, 4.24 posts, 5 people A 4 MINUTE FIRST READ 50,940 desk minutes, 6.06 posts, 7 people
Six of the eight items on a triaged case arrive assembled and two are usually fetched, and those two decide whether a first read costs 90 seconds or four minutes. The drift costs 15,300 minutes a month and takes the desk from 5 people to 7, which is the same 7 the bank would need with no suppression stage at all.

Note how this list sits beside the one the exception desk on the lending side uses. The lending case carries seven numbered fields, and Ismail Sheikh's desk works them at 19 minutes each. The fraud case carries eight of its own, and only the last two are shared: the age of the case and who holds it. Everything else differs because the two desks are answering different questions, and a bank that gives both desks the same case layout has decided that consistency matters more than either of them working.

Try it out

A first read is meant to take 90 seconds and takes four minutes. What is most likely missing?

Retrieval and Grounding for Finance teaches you to design a retrieval setup over a document set and to say what grounding does and does not prevent. Backtesting a Strategy — free micro-course from Fin Maverick

How does a triage arrangement fail, and what does the failure look like?

The suppression rule that quietly stopped being right

Suppose one of the patterns stage 1 treats as an already cleared repeat starts being used by somebody who worked out that it is treated that way. Or suppose an ordinary change in how a payment type is recorded makes a new kind of alert look like an old cleared one. Nothing announces either event. The rule keeps matching, the alerts keep closing, and the records keep being written.

Now ask what moves in the numbers the desk reports. The alert count does not move. The alerts are still being raised. The suppression share does not move. The 6,120 read does not move. The keep rate does not move. The cases that would have been kept never reach the read. The confirmation count does not move. The cases that would have been confirmed were never opened. Every count the desk produces looks exactly as it did before. A suppression fault cannot be found by watching the counts, however carefully anybody watches them.

The shape of the failure is worth naming precisely: not one alert missed, but one kind of alert never seen, for as long as the rule that suppresses it stands. A missed instance shows up eventually because the loss arrives. A missed kind never does. There is nothing to compare the month against.

WHAT THE DESK REPORTS WHEN A SUPPRESSION RULE IS QUIETLY WRONG ALERTS RAISED 18,000 READ BY A PERSON 6,120 KEPT 540 CONFIRMED 27 NOT ONE OF THESE FOUR NUMBERS MOVES. THE KINDS OF ALERT ARRIVING UNDERNEATH THEM kind A kind B kind C kind D kind E kind F suppressed as a repeat, so it never reaches any count above THE FAILURE IS A KIND, NOT AN INSTANCE, SO COUNTING MISSED ALERTS WILL NEVER FIND IT. It ends when somebody reads suppressed alerts by hand, or when the loss it hides is large enough to arrive on its own.
A suppression stage fails by kind rather than by instance: one kind of alert stops reaching the counts and every number the desk reports stays exactly where it was. That is why the only defence is a periodic hand check on suppressed alerts rather than closer attention to the monthly totals.
Try it out

A suppression rule is quietly wrong. What does the failure look like in the numbers?

Backtesting a Strategy teaches you to build a backtest, name how it flatters itself, and state what the result establishes.

How does somebody running this desk read the four stages?

A triage arrangement is a capacity arrangement wearing a detection costume. Start with the margin. Five people at the assumed working month of 8,400 minutes is 42,000 minutes of capacity against 35,640 of work, so the margin is 6,360 minutes a month, being 15.1 per cent, or about 318 minutes a working day. In cases that is room for roughly eight extra fuller reviews a day. The margin exists only because 4.24 posts rounded up to 5, and reading it that way makes it obvious how fragile it is: the same desk with 4 people would be 6,240 minutes short every month.

Now put it beside the other desk in the same bank. The exception desk on the lending side runs at a margin of 4.2 cases a day, being 2.7 per cent of its capacity. A week carrying three per cent more volume turns its stable queue into a growing one. The fraud desk sits at 15.1 per cent. Two desks in one bank, one with five times the other's headroom, and neither number appears in any report either desk produces. Working it out takes about four minutes and a locked working month, and it is the first thing anybody reviewing either arrangement should compute.

Then ask for four things, in this order. First, the two closing identities. A stage list that does not close is not a description of anything. Second, the date and result of the last hand check on suppressed alerts, with the expected count beside the found count. A check reported without its expectation is a number with nothing to lean on. Third, the confirmation counts by route, not just the case counts. The 11.7 per cent of cases carrying 70.4 per cent of the findings is the only evidence the criteria work. Fourth, the measured first read time against the 90 seconds the desk was sized on. The measured time moves the desk by two posts before anybody notices it has moved at all.

Covered elsewhere. The six numbered lines that raise the month's 18,000 alerts in the first place are set out under alert sources. How to build the escalation into a workflow step by step, and how the five criteria behave when they are added one at a time, are covered under escalation design. Scoring a transaction by how far it sits from an account's own pattern is covered under anomaly scoring, and how false positives are counted and reported as a measure is covered separately.

Sources

SourceDocumentSite
Financial Action Task ForceOrigin of the international standard on monitoring transactions, named as the origin only. The position for a bank in India is stated by the Reserve Bank of India insteadfatf-gafi.org
Reserve Bank of IndiaPublished expectations on a regulated lender covering monitoring, outsourcing, digital lending, data and consent, and the treatment of a customer where a decision is automated. Must be read at sourcerbi.org.in
Securities and Exchange Board of IndiaEquivalent expectations where the deployer of an automated monitoring arrangement is a market intermediary rather than a banksebi.gov.in
Agrawal, Gans and GoldfarbPrediction Machines, 2018, for the split between a prediction and the deciding that follows itHarvard Business Review Press

Sumeru Bank Limited and Ismail Sheikh are invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Case Escalation
← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.