Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
AI, Automation & Digital Finance
1AI Foundations
Artificial Intelligence in FinanceAlgorithmNeural Networks and Deep LearningMachine LearningArtificial Intelligence vs Machine…Computer Vision in FinanceTraining Data and LabelsNatural Language Processing in Finance
2Generative AI
Generative AIGenerative AI vs Predictive AILarge Language ModelsEmbeddingsHallucinationFine TuningPrompting vs Fine TuningThe PromptThe Context WindowTool CallingGroundingVector DatabasesRetrieval Augmented GenerationRAG vs Fine Tuning
3Automation and Workflow
Workflow AutomationAutomation vs AugmentationHow to Map a…Straight-Through Processing and Exception…Robotic Process AutomationRule EnginesMachine Learning vs Rule-Based…
4Document and Operations AI
Intelligent Document ProcessingBatch vs Real-Time vs…Document Classification vs Entity…Service Level AgreementsCase ManagementHow to Document Data…Reconciliation AutomationOptical Character Recognition and Data ExtractionConfidence Scores
5Customer Systems, Identity and Digital Assets
Digital IdentityConsent ManagementBlockchain and Distributed LedgerChatbots and Conversational AIFrom Use Case to ProductionDigital Assets and TokenisationDigital SignaturesData Sharing in FinanceElectronic KYC and Digital Onboarding
6Credit and Fraud Systems
The Fraud AlertCredit Decisioning SystemsHuman in the Loop…Adverse ActionAnomaly DetectionThe Decision ThresholdCredit Score vs Credit DecisionAlert Triage and EscalationFraud Detection and Transaction MonitoringFraud Model vs Credit ModelHow to Build Human…
7Governance, Data and Vendors
AI Governance and the AI PolicyHow to Create an…Explainability and Interpretability ComparedThe AI VendorBias and Fairness in Financial AIShadow AIAccess Control and Data MinimisationCloud Computing in FinanceData Lineage and Master DataData ResidencyThe AI Use Case Register and Model InventoryThe Model Owner
8Model Performance, Monitoring and Resilience
Model DriftFalse Positives and False NegativesClassification MetricsAdversarial AttacksModel TestingBias, Fairness and Explainability…Stopping an Automated SystemModel ValidationAI Governance vs Model Risk ManagementPrompt InjectionHow to Create an…

Fraud Detection and Transaction Monitoring: Rules and Models

Transaction monitoring watches every transaction on a book against written lines and raises an alert when one matches. Fraud detection is the whole arrangement that turns those alerts into confirmed cases. At Sumeru Bank Limited, invented, the arrangement is right 0.15 per cent of the times it speaks, and that is the design working rather than failing, because the two errors do not cost the same thing.

The whole arrangement rests on one asymmetry, and the asymmetry is worth stating before any number arrives. A case that gets missed costs this bank an amount of money it can name and put in a budget. An alert on a lawful payment costs the desk ninety seconds, and it costs somebody outside the bank an afternoon of not being able to pay for something. Because those two errors are different sizes, an arrangement that is wrong almost every single time it opens its mouth can still be the right arrangement, and the moment that is said without the second half it becomes a sentence that defends anything. So the second half has to travel with the first, in the same breath, every time the claim is made.

What is Transaction Monitoring, and what does it actually produce?

Start at the gate of a residential society. The guard has a printed sheet on a clipboard, and the sheet says things like: stop anybody carrying a television out after eight in the evening, and stop any vehicle whose number is not on the resident list. The guard is not deciding who is a thief. The guard is comparing what walks past against a sheet somebody wrote, and when something matches, a name goes in a register and a supervisor gets a call. The sheet does not know what theft is. The sheet knows what a previous theft looked like.

Transaction monitoringWatching every transaction on a book against a set of written lines, and raising an alert whenever one of them matches. is that clipboard, running over money instead of televisions. At Sumeru Bank Limited the servicing book carried 2,000,000 transactions in one month. Component 7 of the intake chain sat across all of them. Component 7 is not fitted to anything: it is 61 written linesA rule somebody stated in advance. A written line fires only on the thing it names, and the person who wrote it can read it out loud., each one a comparison somebody stated in advance. The 61 lines raised 18,000 alerts in the month, being 0.9 per cent of the transactions.

The entire output of transaction monitoring is a list, and the list is not a finding, an accusation or a decision. Nothing on it has been read. Nothing on it has been stopped. Nobody outside the bank knows any of it exists. An alert says only that a transaction matched a comparison, a much smaller claim than the word fraud makes it sound. Almost every argument about whether a monitoring arrangement is any good turns out to be an argument about what happens after the list, not about the list itself.

WHAT THE MONITORING STEP TAKES IN, AND THE ONE THING IT PUTS OUT THE SERVICING BOOK 2,000,000 transactions in one month COMPONENT 7, 61 WRITTEN LINES not one of them is fitted to data 44 written after a loss, 17 from an expectation THE ALERT LIST 18,000 alerts, 0.9 per cent of the book WHAT THAT LIST IS NOT, ON THE DAY IT IS PRODUCED Not read by anybody. Not stopped. Not confirmed. Not known to a single person outside the bank.
Monitoring takes in a whole month of transactions and puts out exactly one artefact, a list of 18,000 rows that nobody has read yet, which is why an alert is a match against a written comparison and not yet a finding about anybody.
Breaking Into Quants Bootcamp — Fin Maverick

Fraud Detection vs Transaction Monitoring: where exactly do the two come apart?

The society gate makes the same point. The clipboard is the monitoring. But nobody in that society would say the building is protected by a clipboard. Protection is the clipboard plus the guard who reads it, plus the supervisor who is called, plus the register the entry goes into, plus the decision somebody makes about whether to stop the person at the gate or wave them through and ring the resident instead. Strip all of that away and what remains is a clipboard, and a clipboard is not protection.

Fraud detectionThe whole arrangement that turns raised alerts into confirmed cases, including every person, stage and record between the two. is the whole arrangement, and monitoring is one component inside it. At Sumeru Bank Limited the arrangement runs from those 18,000 alerts through four stages, set out under alert triage and escalation, down to 27 confirmed casesAn alert that an investigation established was fraud. Nothing else the arrangement produces would be called a finding.. Monitoring produces alerts. Detection produces confirmed cases. Alerts and confirmed cases are two different things, and no amount of good monitoring turns one into the other on its own.

The split matters commercially, and it is where a firm most often buys half an arrangement and thinks it has bought the whole one. The monitoring half can be bought. Monitoring arrives as a running service, it can be switched on in a quarter, and its cost sits in one line of a budget. The detection half arrives as salaries: at this bank it is 5 posts on a fraud desk, and those posts appear in a headcount request that a completely different person has to approve, in a completely different meeting, often in a different year. So the two halves are approved separately, and it is entirely possible to end up with excellent monitoring, 18,000 alerts a month, and nobody with time to read them. The gap is not a hypothetical failure mode. The arithmetic below makes it almost inevitable whenever the second approval does not happen.

ONE OF THESE TWO CONTAINS THE OTHER, AND ONLY ONE OF THEM CAN BE BOUGHT TRANSACTION MONITORING 61 WRITTEN LINES 2,000,000 TRANSACTIONS A LIST OF 18,000 ALERTS Produces: a list, and nothing else. Every step of it can be bought as a running service. The whole difference between these two bands is four stages of people, and nobody sells those with the monitoring. FRAUD DETECTION EVERYTHING IN the band above AUTOMATICSUPPRESSIONA FIRST READof 90 secondsA FULLERREVIEWANINVESTIGATIONHOLD ORRELEASE Produces: 27 confirmed cases in the month, and a decision about somebody's payment on 218 of them. The five boxes to the right of the green one are 5 posts on a desk. They arrive as salaries, not as a service.
Monitoring produces alerts and detection produces confirmed cases, and the distance between those two words is four stages of people that arrive on a payroll rather than in a contract.
Try it out

What does transaction monitoring produce, and what does fraud detection produce?

What does a written line give the person who has to answer for it?

Component 7 is a rule set, and that was a choice. The bank could have fitted something to its own past fraud cases and let it rank every transaction by how unusual it looked. The bank did not, and the reason has nothing to do with which approach finds more fraud. The reason is what happens on a Tuesday afternoon when an account holder rings up and asks why their payment was stopped.

Two security guards stand at the same gate. The first can state the rule: nobody carries a television out after eight without a gate pass, here is the sheet, that is why the person was stopped. The rule may well be a stupid one, and it can be argued with, and if enough people argue the society can change the sheet at the next meeting. The second guard says the person looked wrong to him. He may well be a better guard, with sharper instincts and a better record. But there is nothing there to argue with, and nothing the society can change on Friday.

Agrawal, Gans and Goldfarb, in Prediction Machines, published in 2018, draw the line between the prediction a component produces and the deciding that a person still has to do afterwards. The 61 written lines buy this bank something other than accuracy: a sentence that can be read out to the person the alert was about, and the ability to change the rule inside a week when the pattern moves. A fitted component would very likely rank better. A fitted component would also leave the person on the phone with nothing to say.

FOUR QUESTIONS, ASKED OF A WRITTEN LINE AND OF A FITTED COMPONENT THE QUESTION SOMEBODY ACTUALLY ASKS A WRITTEN LINE A FITTED COMPONENT Can the person accountable for itread it out loud, today?Yes. It is one sentence,and it names what it compared.No. It returns a ranking,and a ranking is not a sentence.Can it be changed by Fridaywhen the pattern moves?Yes. Somebody edits a lineand the change is dated.No. It has to be refittedand looked at again first.What can be said to the account holderwhose payment was stopped?The comparison that fired,in the words it was written in.Nothing anybody can quoteback to a person on a call.What does it do about a patternnobody has ever written down?Nothing at all. It hasno line for what it never saw.It can still rank it as farfrom that account's own habit.
Three of these four questions go the way of the written line and the fourth goes the other way, which is the whole trade: readability on the questions a person has to answer, reach on the pattern nobody thought of.
Try it out

An account holder rings and asks why their payment was held. Which arrangement leaves somebody able to answer?

AI For Finance Bootcamp — Fin Maverick

How does a line get written, and what does that say about what it cannot see?

Of component 7's 61 lines, 44 were written after a loss the bank had already taken and 17 were written from an expectation of one. The split between the 44 and the 17 explains almost everything about how a rule set behaves. A line exists because somebody lost money, somebody looked at how it was done, and somebody wrote down the comparison that would have caught it. A rule set is therefore a written record of what has already happened to the bank. A record of the past is accurate about the past and blind in a shape that cannot be seen from inside it.

The productive lines confirm this. Alert sources 3, 4 and 5 together carry 22 of the month's 27 confirmations, being 81.5 per cent, and all three sit among the 44 that were written after a loss. The bank knows those patterns because it paid for them once each. Nothing in the rule set knows about the pattern that has not yet cost anybody anything.

HOW A LINE COMES TO EXIST, AND WHERE THE PRODUCTIVE ONES SIT A LOSS HAPPENSon one account, onceSOMEBODY LOOKSat how it was doneA LINE IS WRITTENnaming that comparisonTHE LINE FIRESon the next one like it 44 LINES written after a loss already taken 17 LINES from an expectation Alert sources 3, 4 and 5 carry 22 of the month's 27 confirmations, being 81.5 per cent, and all three sit in here. Which means the most productive lines this bank has are the ones it paid for the hard way, once each.
A rule set is a written record of what has already happened to the bank, so 44 of the 61 lines exist because a loss came first, and the three sources carrying 22 of the 27 confirmations all sit inside that block.

There is a second consequence, and it is a comfort rather than a warning. A fraud case is confirmed or not within days, so somebody can look at last month's lines against last month's outcomes and argue about them at a meeting this month. The scoring model on the credit side cannot be looked at that way at all: under this bank's own definition an outcome is not known until twelve months of observation have run, so the earliest a month of credit decisions can be scored is fifteen months after them. The fraud lines can be argued with monthly. The speed at which an outcome arrives, more than anything about the technology, is why one part of this chain is 61 sentences and the other is a fitted component.

Why are so many alerts not fraud, and is that a fault in the lines?

One number decides everything downstream, and it is not a number about the lines at all. In the month, 2,000,000 transactions produced 27 confirmed cases. The rate is about one in every 74,074. Whatever is being looked for is that rare, and the base rateHow rare the thing being looked for actually is. The base rate sets how many alerts will not be that thing, whatever the lines say. of a thing sets how often anything looking for it will speak about something else.

A wedding at scale, the kind with 2,000 guests over three days, has one person present who is there to steal from the gift table. Instructions for the staff good enough to catch that one person now have to be written. Every instruction available, stop anybody who walks towards the gift table alone, ask about anybody nobody at the top table recognises, will stop dozens of perfectly ordinary guests for every single time it is right. Not because the instruction is badly written. Because there is one of them and 2,000 of everybody else.

WHAT ONE CONFIRMED CASE COSTS IN VOLUME, PER CASE The scale is logarithmic. Each equal step along it is a ten times change, not an equal one. Transactions the arrangement movedabout 74,074Alerts the 61 lines raisedabout 667Alerts a person actually readabout 227Cases kept for a fuller reviewexactly 20Cases confirmed as fraud1 The bottom bar is drawn at a minimum width. At true scale beside the top bar it would be one seventy-four-thousandth as long.
Per single confirmed case the arrangement moves about 74,074 transactions and speaks about 667 times, so the count of alerts that are not fraud is set by how rare the event is rather than by any fault in the lines.

So the 17,973 alerts a month that were not fraud are arithmetic before they are anything else, and rewriting the lines to speak less often moves the confirmations before it moves much else. This is the part that gets argued about wrongly in almost every review. Somebody looks at 18,000 alerts and 27 cases and concludes the lines are badly written. Sometimes they are. But a line sensitive enough to catch a one in 74,074 event will speak far more often than that event happens. The only way to make it speak much less is to make it less sensitive, and a less sensitive line takes cases off the bottom of the list first.

Try it out

27 confirmed cases in 2,000,000 transactions. Why does that produce 18,000 alerts rather than a few hundred?

What does a missed case cost this bank, in rupees?

Now price the first of the two errors. Sumeru Bank Limited's own amount at riskWhat a confirmed case would have cost the bank if it had not been stopped, on the bank's own average across its own cases. on a confirmed case is Rs 84,000/-, an average across its own cases rather than any published figure. So the 27 cases in the month carry Rs 22,68,000/- between them, and on the same steady volumes 324 cases a year carry Rs 2,72,16,000/-.

The first error, pricedWorkingAmount
Average amount at risk on one confirmed casethe bank's own averageRs 84,000/-
Confirmed cases in the monthfrom 18,000 alerts27
Carried by the month's cases27 times Rs 84,000/-Rs 22,68,000/-
Confirmed cases in a year27 times 12324
Carried by the year's cases324 times Rs 84,000/-Rs 2,72,16,000/-

Every rupee in that column is the bank's own money, and somebody in the building is accountable for it. Every bank has already written this column for exactly that reason. Notice what it assumes: that every confirmed case would have completed if nobody had stopped it, and that a stopped case saves the whole amount. A real month delivers neither cleanly. So the total prices the shape of the exposure rather than money anybody got back.

Financial Analyst Program Bootcamp — Fin Maverick

What does an alert cost the desk, and what does a hold cost somebody else?

Now price the second error. The second error lands in two different places on two different people, so pricing it takes two units rather than one.

Inside the bank it is minutes. Of the month's 18,000 alerts, 11,880 were closed by automatic suppression and nobody read them, so they cost almost nothing. The remaining 6,120 were read. Take out the 27 that turned out to be fraud and the arithmetic on this bank's own locked handling times runs like this: 5,580 first reads at 90 seconds is 8,370 minutes, the 513 kept cases that were investigated and found nothing carry another 769.5 minutes of first reading and 20,520 minutes of fuller review, and the three together are 29,659.5 minutes a month. At the assumed working month of 8,400 minutes that is 3.53 posts. So of the 4.24 posts of work the desk actually does, 3.53 of them go on alerts that were not fraud, being 83.2 per cent of every minute the desk spends. That is not a scandal. The arithmetic of the base rate makes it unavoidable.

Outside the bank it is not minutes at all. Of the 540 cases kept, Sumeru Bank Limited stopped the payment while the case was reviewed on 218 of them. Twenty seven were confirmed. HoldingStopping a payment from completing while the alert on it is being reviewed. The money does not move until somebody releases it. a payment is the only step in this whole arrangement that anybody outside the bank can feel, and it happened to 218 people in the month.

THE TWO COLUMNS OF ONE MONTH, WRITTEN OUT SIDE BY SIDE THE SIDE THAT IS IN RUPEESRs 84,000/-average amount at risk on one confirmed case27confirmed cases in the month324confirmed cases in a year on the same volumesRs 2,72,16,000/-carried by the year's casesRs 45,00,000/-the fraud desk, 5 posts a yearAbout 6 times overwhich is how this column gets read out loud THE SIDE THAT IS NOT17,973alerts in the month that were not fraud29,659.5 minutesdesk time spent on them, being 3.53 posts513kept, investigated, and nothing was found191of those 513 also had a lawful payment stoppedNo rupee figurerecorded anywhere at this bank, or at most banksNothingwhich is how a column with no total gets read out loud The artefact is not either column. It is the fact that most firms have only ever written the left one.
Put the month on one sheet and the two columns are not the same kind of thing: one totals in rupees and has an accountable owner inside the bank, the other has 191 people in it and no total at all.

191 of those payments were released after review. 191 people were stopped from paying for something and had done nothing whatever wrong. They are not a rounding error and they are not a cost the design absorbs on their behalf. Somebody's rent went late. Somebody's supplier was not paid on the day. Nothing in the right-hand column above is denominated in a unit that can be compared with the left-hand one, and the comparison everybody makes therefore uses only the left.

Try it out

218 payments were held and 191 of them were released after review. Who paid for those 191?

Investment Banking Analyst Bootcamp — Fin Maverick

Where is the break-even, and what makes the trade arguable at all?

Put the two priced sides together and the argument becomes arithmetic. The year's 324 confirmed cases carry Rs 2,72,16,000/-. The desk that produces them costs Rs 45,00,000/-. The ratio is 6.05 times, and it is where the sentence about paying for itself six times over comes from.

But the far more useful number is the one underneath it. The desk divided by the year's cases gives the break-evenThe average case value at which the desk costs exactly what it prevents. Above it the arrangement pays; below it, it does not.: Rs 45,00,000/- over 324 cases is Rs 13,889/- an average case. Stating the break-even converts a question nobody can settle, is this arrangement worth it, into a question anybody can settle, is the average case bigger than Rs 13,889/-. At this bank it is six times bigger, and that is the whole defence, resting on one figure that most firms have never written down.

WHERE THE ARGUMENT TURNS OVER, AND THE ONE NUMBER THAT DECIDES IT The grey bar and the vertical line are the same thing: Rs 45,00,000/- a year, which does not move. AT Rs 84,000/- A CASEthe bank's own average6.05 timeswhat the year's cases carry, Rs 2,72,16,000/-the desk, Rs 45,00,000/- a yearAT Rs 13,889/- A CASEthe break-even1.00 timeswhat the year's cases carry, Rs 45,00,036/-the desk, Rs 45,00,000/- a yearAT Rs 10,000/- A CASEbelow the break-even0.72 timeswhat the year's cases carry, Rs 32,40,000/-the desk, Rs 45,00,000/- a year THE DASHED LINE IS THE BREAK-EVEN: Rs 13,889/- AN AVERAGE CASE Any bar ending left of it is a year in which the desk costs more than it prevents.
Stating the break-even at Rs 13,889/- an average case turns an argument about whether the arrangement is worth it into a question somebody can actually answer with one number.
Try it out

Suppose this bank's average amount at risk on a confirmed case fell to Rs 10,000/-. What has changed about the design?

Try it out

Before the control below is touched: at roughly what average case value does this desk stop paying for itself?

Play with it

Move the one number the whole defence rests on

Everything else is held where the month put it and does not move: 27 confirmed cases a month, being 324 a year, and a fraud desk of 5 posts at an assumed fully loaded Rs 9,00,000/- each, being Rs 45,00,000/- a year. Only the average amount at risk on a confirmed case moves.

The bank's own reading, which the control opens on: Rs 84,000/- an average case, so the year's 324 cases carry Rs 2,72,16,000/- against a desk costing Rs 45,00,000/-, being 6.05 times over. The break-even is Rs 13,889/- an average case. Standing beside both, and unchanged by anything the control does: 17,973 of the month's alerts were not fraud, and 191 people had a lawful payment stopped and released.
Rs 5,000/-Rs 84,000/- an average caseRs 2,00,000/-
ONE YEAR OF CONFIRMED CASES AGAINST ONE YEAR OF DESK Carried a year The desk BREAK-EVEN, Rs 13,889/- A CASE Rs 2,72,16,000/- Rs 45,00,000/- PAYS FOR ITSELF 6.05 TIMES OVER 191 LAWFUL PAYMENTS HELD no rupee figure, so neither bar moves These 191 squares are drawn once and never change, whatever the control is set to. That is the point of them.
Average case value
Rs 84,000/-
Carried in a year
Rs 2,72,16,000/-
Times the desk
6.05

At Rs 84,000/- an average case, the year's 324 confirmed cases carry Rs 2,72,16,000/- against a desk costing Rs 45,00,000/-, being 6.05 times over.

Educational illustration. One invented bank, one month annualised: 27 confirmed cases a month, 324 a year, a desk of 5 posts at an assumed fully loaded Rs 9,00,000/-. Every confirmed case is assumed to be stopped in time, which no real month delivers. The half this control cannot show: the cost borne by the 191 people whose lawful payment was held has no rupee figure at this bank, so it appears as a count and never inside the bars.
Bond Pricing and Yield Mechanics — free micro-course from Fin Maverick

Why do both halves of that sentence have to be said together?

One sentence carries the whole case, and it only works whole. The arrangement at Sumeru Bank Limited is right 0.15 per cent of the times it speaks, and that is the design working rather than failing, because the two errors do not cost the same thing. Said with only the first half, it condemns a design that pays for itself six times over on the strength of a rate that was never the right measure. Said with only the second half, the only party left in the comparison is the bank, and the sentence will defend absolutely any amount of wrongness.

ONE MONTH, TWO READINGS, AND THE ARITHMETIC IS THE SAME BOTH TIMES THE SAME 27 CASES one month, one arrangement READ AS A RATE 0.15 PER CENT right 0.15 per cent of the times it speaks, which sounds indefensible READ AS A COMPARISON 6.05 TIMES Rs 2,72,16,000/- a year against a desk of Rs 45,00,000/- BOTH OF THESE ARE CORRECT readings of the same 27 cases NEITHER READING IS ALLOWED OUT OF THE BUILDING ON ITS OWN The rate alone condemns a design that works. The comparison alone will defend any amount of wrongness at all.
The same 27 cases give a rate that reads as failure and a comparison that reads as success, and because both readings are arithmetically correct the honest statement is the one that carries them together.

Watch how the second failure works. The second failure is the more comfortable one and therefore the more common. The claim is that the desk carries six times its own cost. Now imagine the alerts double to 36,000 while the confirmations stay at 27. Every rupee in the comparison is unchanged, so the sentence still reads six times over. Twice as many people have been looked at, and plausibly twice as many lawful payments have been held. An argument that does not get worse as the wrongness rises is not an argument about wrongness at all, and that is the precise defect in offering the six times figure alone.

Try it out

Somebody defends this monitoring arrangement by saying it pays for itself six times over. What is missing from that defence?

The failure that hides behind a correct slide, and what it costs

A monitoring arrangement is reviewed. Somebody produces one slide: Rs 2,72,16,000/- carried a year against a desk costing Rs 45,00,000/-, six times over, approved. Every figure on the slide is correct and the slide is not wrong about anything it says. The slide is wrong about what it leaves out. The same month held 17,973 alerts that were not fraud and 191 people who were stopped from paying for something and had done nothing.

The cost is not that the arrangement gets approved. On these numbers it should be. The cost is that the slide sets the standard of proof for every future review, so when the alerts double and the confirmations do not, the same slide will be produced, it will still read six times over, and nothing in the room will have got worse. A measure that cannot deteriorate cannot govern anything.

Half the sentence condemns a desk that is working. See what monitoring costs. Hypothesis Testing — free micro-course from Fin Maverick

What does this arrangement cost the people it is wrong about?

The 17,973 alerts that were not fraud are usually written as one number. Three completely different experiences are stacked inside that one number, so writing them as one is itself part of the problem.

THE 17,973 THAT WERE NOT FRAUD, BY WHAT EACH ONE ACTUALLY COST 11,880 plus 5,580 plus 513 is 17,973, being 99.85 per cent of the month's 18,000 alerts. 11,880 SUPPRESSED closed with a record, nobody read them, nobody felt them 5,580 READ AND CLOSED 90 seconds each 513 KEPT, INVESTIGATED, AND NOTHING WAS FOUND 191 also had a lawful payment stopped 322 looked at, and no payment was stopped Three segments, three completely different costs: nothing, 90 seconds, and 40 minutes plus somebody's afternoon. Only the red block on the lower bar is felt by anybody outside the bank, and only it has no unit of account.
Splitting the 17,973 by what each one cost shows they are not one number: 11,880 cost nothing at all, 5,580 cost 90 seconds each, and 513 cost a full review of which 191 also cost somebody the use of their own money.

Follow the third block down. 513 alerts were kept, investigated by a person for about 40 minutes each, and nothing was found. The 513 are people about whom a bank formed a question and answered it in their favour, and almost all of them will never know it happened. But 191 of those 513 also had a lawful payment stopped while the question was being answered. The 191 did nothing wrong at all, and they are not a cost the design quietly absorbs on their behalf: the cost was moved onto them, and it was moved without being counted anywhere.

O'Neil, in Weapons of Math Destruction, published in 2016, makes the general point that a system's errors rarely fall evenly across the people they land on. Sumeru Bank Limited has not measured who its 191 are, and that absence is worth stating plainly rather than filling with a guess. A payment held for two days is a small inconvenience to somebody with a balance and a serious event for somebody paying a hospital. Sumeru Bank Limited does not know which of those it did 191 times last month, and no arrangement that has not asked the question can claim to know the answer.

Hypothesis Testing teaches you to run a test, say what it can and cannot support, and recognise a manufactured result.

Where does the judgement in all of this actually sit?

Looking at 61 lines running over 2,000,000 transactions, somebody could easily conclude that the arrangement makes the decisions. The arrangement makes none of them. Every judgement was made in advance by a person, and it is worth being able to point at all three.

THE THREE PLACES THE JUDGEMENT ACTUALLY SITS 1SOMEBODY CHOSE THE LINESWhich 61 comparisons were worthwriting down at all, and 44 ofthem only after a loss.2SOMEBODY CHOSE THE ATTENTION90 seconds at one stage, 40minutes at the next, about 3hours at the last.3SOMEBODY CHOSE TO STOP MONEYA payment held on 218 accounts,decided before anybody knewwhich 27 would matter. NOT ONE OF THE THREE IS INSIDE THE MONITORING All three were settled by people before a single alert existed. The lines only compare what they were told to compare.
Every judgement in this arrangement was made by a person in advance, in three specific places, and the monitoring itself makes none of them: it compares what somebody already decided was worth comparing.

The monitoring compares; the people chose what was worth comparing, how much attention each stage was worth, and whether to stop somebody's money while the question was open. That is why the interesting review questions are never about the lines. Ask who set the 90 seconds and what evidence they had. Ask who decided that 218 payments a month is an acceptable number to stop. Both are answerable questions with names attached, and neither is a technical question.

Try it out

Name one of the three places the judgement in this arrangement sits.

How would somebody reviewing this arrangement test it in one hour?

A risk reviewer, an internal auditor or a board member can run this test without any access to the monitoring itself. Neelima Rao, in the risk function at Sumeru Bank Limited, built no part of the chain, and building no part of it is exactly why she can ask these four things. Every one of them is answerable from records the bank already keeps.

What to ask forWhat a usable answer looks like
The break-even, written downThe desk's annual cost divided by the year's confirmed cases. At this bank, Rs 45,00,000/- over 324, being Rs 13,889/-. If nobody has ever computed it, the arrangement has never been argued about, only asserted.
The second column of the ledgerA count of alerts that were not fraud, split by how much attention each one consumed, and a count of payments held and released. At this bank: 11,880, 5,580, 513, and 191.
Which lines earn their volumeAlerts and confirmations by source, side by side, so a line that speaks constantly and is almost never right is visible as such rather than hidden inside a total.
Who chose the holdsA name and a date against the decision to stop a payment pending review, and the standing arrangement for releasing one quickly. This is a conduct question long before it is a fraud question.

Notice what is not on that list. Nothing about how the monitoring works internally, nothing about statistics, and nothing that requires the reviewer to have built anything. Every one of those four questions is answerable from records the bank already keeps, and the ones a firm cannot answer are the finding.

India

Who states what applies here

The international standard on transaction monitoring originates with the Financial Action Task Force at fatf-gafi.org. The expectation that a regulated institution watches transactions comes from there in the first place. The Reserve Bank of India at rbi.org.in states what actually applies to a bank in India, and where the deployer is a market intermediary rather than a bank the Securities and Exchange Board of India at sebi.gov.in states it.

The 61 lines, the 90 seconds, the two suppression and review windows and the Rs 84,000/- are Sumeru Bank Limited's own choices, not a standard, a norm or a requirement of any authority. Anything resting on them should be checked against the position at source.

What raises an alert is set out under the fraud alert, how one is triaged and escalated under alert triage and escalation, and how a transaction is scored by its distance from a pattern under anomaly detection. How the two kinds of error are counted and reported as measures is covered separately.

Sources

SourceDocumentSite
Financial Action Task ForceThe origin of the international standard under which a regulated institution monitors transactions. Named here as the origin only. What applies to a bank in India is stated by the Reserve Bank of India rather than herefatf-gafi.org
Reserve Bank of IndiaPublished expectations on a regulated lender covering fraud monitoring, outsourcing, digital lending, data and consent, and the treatment of a customer whose transaction is stopped. What applies to a bank in India is stated here and must be read at sourcerbi.org.in
Securities and Exchange Board of IndiaEquivalent expectations where the deployer of a monitoring arrangement is a market intermediary rather than a banksebi.gov.in
Agrawal, Gans and GoldfarbPrediction Machines, 2018, for the split between the prediction a component produces and the deciding a person still has to do afterwardsHarvard Business Review Press
O'NeilWeapons of Math Destruction, 2016, for a system's errors falling unevenly across the people they land onCrown

Sumeru Bank Limited and Neelima Rao are invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Transaction MonitoringFraud Detection vs Transaction Monitoring
← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.