AML alert triage
Financial crime
Alert storms on a single corridor, overwhelmingly false, ranked so the investigator's hour goes to the case that deserves it.
- Alerts per SAR
- Investigator hours
- Detection coverage
Reduce fraud. Improve AML yield. Increase credit accuracy. Meet regulatory expectations — with a reason code on every decision and an evidence trail behind every alert.
Every bank already has scorecards, alert engines and thresholds. The difficulty is rarely building another model — it is that the ones in production generate more work than they resolve, and the ones that would resolve more work cannot get through model risk.
An AML engine that raises twelve hundred alerts on one corridor, of which almost all have historically been false, is not a detection problem. It is a triage problem, and triage is a ranking task with an evidence requirement attached. Equally, a fraud model that cuts loss by declining more good customers has not helped anybody; the constraint is the false-decline rate, not the catch rate.
So the useful question for a bank is not can a model do this but can this model be explained to somebody whose job is to doubt it — a validator under SR 11-7, an investigator writing up a case, a customer entitled to know why they were declined.
Deterministic where the decision has to be reproducible under challenge; language models where the problem is genuinely reading a document. Most of these are both.
Financial crime
Alert storms on a single corridor, overwhelmingly false, ranked so the investigator's hour goes to the case that deserves it.
Payments
A new, mule-linked beneficiary and an amount far off the customer's baseline — decided in the payment window, not afterwards.
Credit
Leverage running above covenant for consecutive quarters, buried in a reporting pack nobody reads until the relationship manager is told.
Operations
Merchant evidence contradicts the chargeback claim, across a backlog measured in hundreds of claims per analyst.
Treasury
A nostro buffer projected to breach in the afternoon, forecast in the morning while there is still something to do about it.
Onboarding & CDD
A registry filing changes the ultimate beneficial owner, and the periodic review is eleven months away.
Read at query time through governed connectors, with credentials sealed per tenant. Your data does not move into a vendor database to be modelled.
Where a decision has to be reproducible and defensible, the model is deterministic by design — scorecards, gradient-boosted classifiers, anomaly detectors, survival and time-series models, graph networks and regulatory calculation engines. The same input gives the same output, the attribution is mathematical, and a model-risk team can take it apart without calling us.
The frameworks these were designed against ship mapped with them:
Adverse-action reason codes are native to every scoring model — which is not a feature so much as a legal precondition anywhere a declined applicant has a right to an explanation.
Reference deployments: a problem shape, the design we would propose for it, and what we would expect to be measured afterwards.
Bring us a threshold you cannot move because nobody can defend the model behind it. That is usually the fastest place to start.