Platform
Solutions
Resources
Company
Resources
Help Center

Frequently asked questions

Answers to common questions about the TruvaLI platform.

KYC and customer onboarding
What is the difference between active and passive liveness?

Active liveness requires a random action from the user, such as smiling, turning their head, or blinking. Passive liveness, on the other hand, performs micro-expression, depth, and reflection analysis on a single selfie, delivering the same decision without requiring any action from the user. The passive method increases completion rates, while the active method provides extra assurance for high-risk applications.

Why is NFC chip reading important?

Photos and identity details read from the chip are digitally signed by the government, making them much harder to forge than a photo of the front of the document. When the selfie comparison is performed against this official photo, the matching score becomes far more reliable.

Do we need to purchase separate third-party software for identity verification?

No. Document reading, chip verification, liveness, face matching, and compliant video calls are built into the platform. You do not need to allocate additional budget for separate licenses.

Where is biometric data processed?

All verification runs on the institution's own infrastructure. Selfies, document images, and chip data are not sent to external cloud environments, making it easier to meet special categories of personal data obligations under KVKK.

KYB and ultimate beneficial owner (UBO) detection
Who is an ultimate beneficial owner (UBO)?

An ultimate beneficial owner is the natural person who ultimately controls or benefits from a legal entity. In practice, a shareholding of 25% or more is typically used as a threshold, but individuals who exercise control through signature authority or management control are also evaluated, even if their shareholding percentage is lower.

What is the difference between KYC and KYB?

KYC verifies individual customers through identity documents, biometrics, and screening. KYB, on the other hand, verifies legal entities and additionally requires resolving the ownership structure to identify the natural persons behind them. The KYB process also includes KYC checks for every natural person in the chain.

What happens if the ownership structure changes later?

When a change is detected, the company's risk score is recalculated. If a new shareholder appears on a sanctions list or has a PEP record, an alert is generated immediately, without waiting for the next periodic review.

How many layers deep does the system go?

The chain is traced until natural persons are reached; there is no fixed limit on the number of layers. Structures that cannot be resolved or that contain loops are flagged for investigation rather than being silently bypassed.

Video customer calls
Is a video call mandatory for every customer?

No. The institution defines the handover conditions based on its own risk appetite. It is typically triggered by low face matching scores, document suspicion, or screening hits. Other applications are completed via the biometric flow.

Why is random routing so important?

In a setup where the customer can select the agent or vice versa, the call cannot provide the assurance required for remote identity verification. Random routing from a pool eliminates this possibility, and the assignment log can be presented as evidence during audits.

Where are call recordings stored?

Screenshots and audio recordings are stored within the institution's own infrastructure, linked to the relevant customer record. They are never transferred to an external provider and remain accessible throughout the legal retention period.

Sanctions, PEP and adverse media screening
What is the difference between PEP and sanctions screening?

Being on a sanctions list is a legal restriction, making it illegal to transact with that person. A PEP status is not a prohibition but a risk indicator. You are free to work with a politically exposed person, but it requires enhanced due diligence.

Why is adverse media screening also necessary?

Serious allegations against a person can appear in the press long before they are reflected on official lists. Adverse media screening closes this gap and enables the early detection expected by a risk-based approach.

How do you reduce false positives?

The match threshold can be adjusted by segment, records previously closed as false positives are remembered, and matches are presented to the compliance officer along with a pre-analysis. The goal is not to reduce the number of matches, but to highlight those that require investigation.

How often are the lists updated?

Global sanctions lists are retrieved daily. The entire customer database is rescreened every night, so any new match appears as an alert the very next day.

Open source intelligence
Is OSINT different from adverse media screening?

They are closely related. Adverse media screening typically runs on content compiled by a pre-packaged data source. In OSINT, the institution defines the sources itself: publications not included in pre-packaged sets, such as local press and industry newsletters, can also be monitored.

Is there a risk of confusion with another person of the same name?

Matching is not based solely on name: it is evaluated alongside other identity data in your possession, and results are presented with a score. Furthermore, because every finding is linked to the source news article, the compliance officer can verify the decision.

Does a news finding automatically block transactions?

The institution can block them if desired, but the default behavior is to flag the profile as high risk and generate an alert for review. The final decision depends on the scenario written by the institution.

Creating your own screening lists
How deep does the crawl go when we provide a website address?

The link pattern to follow, depth, and maximum page count are defined separately. The crawl targets only the section specified by the pattern rather than the entire site, and it is not unlimited.

Can we see what was extracted from an uploaded document?

Yes. You can view the status and completion time of the process, and the raw response is stored so you can audit exactly what the extraction process read.

Can we define our own extraction templates?

Yes. Analysis prompt presets are structures with a name and a template, which are linked to sources, feeds, and documents. This distinction is necessary because extracting names from an official gazette decision is different from extracting them from a squad list.

Does the record only store names?

No. It stores the first name, last name, corporate title, aliases, gender, date of birth, birth year, and city. The birth year is a separate field because official sources often only provide the year.

Do internal blacklists and sanction records get mixed up?

No. A record can be flagged as either, and both enter the same screening flow, but the source of the record and its associated authority remain clearly distinguishable.

Real-time transaction monitoring
What is the difference between real-time monitoring and threshold-based monitoring?

Threshold-based monitoring only looks at the amount, and fraudsters easily learn these limits. In real-time and risk-based monitoring, the amount is evaluated alongside the context of the behavior: the customer's history, transaction time, sector, device, and counterparty relationships are also taken into account.

What is a non-financial event and why is it monitored?

These are events that do not involve fund movements but alter the risk profile, such as logins from a new device, email changes, or updates to the ownership structure. A significant portion of account takeover cases begin with this type of event before any funds are transferred.

Will the transaction monitoring system affect our current speed?

TruvaLI is designed to operate in environments with millions of daily transactions and returns decisions in milliseconds. Heavy reporting tasks are executed in the background to avoid keeping users waiting.

When exactly is an alert generated?

An alert is generated when an event meets the conditions of a scenario defined by the institution. The alert then becomes a structured case for investigation, showing which rule was triggered by which data within the case.

Real-time risk scoring
How often is the risk score updated?

It is updated on an event basis, not periodically. When a new transaction, device change, profile update, or screening match occurs, the score is recalculated instantly.

Can we show auditors how the score is calculated?

Yes. The signals contributing to the score and their weights are recorded: the reason behind a decision can be traced directly within the case. This is crucial for documenting your risk-based approach.

Can we customize the scoring model ourselves?

Yes. Signal weights and decision thresholds are adjusted according to the institution's risk policy, and changes can be tested on historical data before going live.

Fraud detection
What is the difference between rule-based and AI-based detection?

Rule-based detection looks at predefined conditions and makes decisions explainable. AI-based detection can capture undefined patterns but is difficult to justify. TruvaLI combines both: patterns discovered by AI are converted into rules that undergo human approval.

How is account takeover detected?

Usually through signals that precede fund withdrawals: login from an unrecognized device or IP, followed immediately by an email or phone number change, and transaction attempts at unusual hours. Because TruvaLI also monitors these non-financial events, it can catch the chain before any money moves.

Are fraud rules written separately from AML rules?

They are written in the same rule engine, but they can be separated into distinct rule sets and authorization groups. This allows the fraud team and the compliance team to use the same infrastructure without modifying each other's rules.

Rule and scenario engine
Do I need to know SQL or coding to write rules?

No. Scenarios are created by building logic blocks in the interface or by describing them in daily operational language. The expression editor is only there for advanced cases requiring custom calculations.

How flexible is the aggregation window?

It is not limited to pre-set periods like days and months. Free-form time windows like 'the last 73 hours' or volume-based windows like 'the last 15 transactions' can be defined.

Can a rule stop a transaction directly?

Yes. By triggering a callback to your core system from within the rule, a transaction can be suspended, additional verification can be requested, or the account can be restricted. Depending on the institution's maker/checker settings, putting the decision into production may be subject to approval.

Do we have to deploy a new rule directly to production?

No. A rule can be run against your historical data to preview the alert volume and false positive rate it will generate. For details, see the rule sandbox and simulation page.

Rule sandbox & simulation
How much historical data is required for simulation?

Historical data can be transferred into the system during implementation, allowing meaningful testing from the beginning. The institution can choose the test period, and longer periods may be preferred when seasonal effects need to be evaluated.

How is the false positive rate calculated?

The alerts the rule would have generated historically are compared with how similar cases were resolved during the same period. The result is an estimate, but it provides a more reliable basis than publishing a rule without measuring its likely impact.

Can we test the same rule with different thresholds?

Yes. Running the same rule with multiple thresholds and comparing the results is one of the main uses of simulation. This allows the threshold to be determined through measurement rather than guesswork.

Is the performance of rules already in production also monitored?

Yes. Rules with consistently high false positive rates can be flagged and threshold improvement recommendations can be provided, helping the rule set remain effective over time.

Plain language rule writing
What happens if the system misunderstands my sentence?

The generated rule does not go straight to production. It appears on the screen with its parameters, allowing you to edit it and simulate it on historical data. Additionally, going live is subject to an approval workflow.

Which terms does it understand?

Compliance and risk terminology: expressions such as age limits, ID number formats, activity codes, time windows, and amount thresholds are resolved from context. The term 'minor' converts into an age condition, and 'foreign national' converts into ID number and nationality conditions.

Do we still need to write code for complex scenarios?

Most scenarios do not require code. For advanced cases requiring custom calculations, there is an expression editor in the rule engine, but this is an additional capability rather than a necessity.

Alerts & case management
What is the difference between an alert and a case?

An alert is a technical output showing that a rule has been triggered. A case is a work record created to investigate that alert, with an assigned owner, timeline, and decision rationale. From an audit perspective, the key question is not only how many alerts were generated, but how cases were reviewed and resolved.

How does the Maker-Checker workflow work?

When an analyst (maker) closes a case or publishes a rule, the action is submitted to a predefined approval pool for review by a checker. The decision does not become effective until approval is received. Once approved, a callback can be sent to the institution's main system.

How are cases approaching their deadlines tracked?

The age of each case is monitored, cases approaching their deadlines are flagged, and they can be escalated to management when required. Since the queue can be prioritized by risk score, limited investigation capacity can be focused on the highest-risk cases.

Do multiple alerts caused by the same reason need to be closed individually?

No. Alerts arising from the same reason can be closed in bulk, and a common rationale can be applied to all of them. This helps prevent repetitive situations from consuming unnecessary investigation capacity.

AI-powered case investigation
Does the AI close cases on its own?

No. Pre-analysis is a recommendation. The compliance officer makes the decision and adds their own comments. For low-risk cases, one-click closure may be suggested, but this is still subject to the approval workflow.

Can we see the reasoning behind the pre-analysis?

Yes. The signals on which the assessment is based are clearly documented: the triggered rule, customer history, and IP and device patterns. This makes it possible to demonstrate how the decision was reached during audits.

Is case data sent to an external AI service?

No. The analysis runs on the institution's own infrastructure. Customer data, transaction details, and case content are never sent to external cloud environments.

Rules from past fraud
Can generated rules be used directly?

They should be used as drafts. They may be too narrow or too broad, so thresholds should be adjusted according to the institution’s risk appetite and tested through simulation before being put into use.

How many historical cases are required?

Patterns can be identified from a single case, but when similar cases are analyzed together, common elements can be separated more reliably and the resulting rule can be more accurate.

How is this different from a ready-made rule library?

A ready-made library covers general industry typologies. Rules generated from historical cases are based on attacks that have actually occurred within your own product and customer base. The two approaches are complementary rather than alternatives.

Automated reporting
Is the suspicious transaction report draft submitted automatically?

No. The draft is prepared for review, and the compliance officer reads, edits, and approves it. The institution remains responsible for the content and submission of the report; the system does not assume this responsibility.

Is SQL knowledge required to create reports?

No. Reports can be created by selecting fields and filters through the interface or by describing the required report in natural language, after which the system generates the query.

Can reports be distributed on a recurring schedule?

Yes. Reports can be scheduled to run daily, weekly, or monthly and can be delivered to relevant users in PDF or Excel format.

Maker/checker, authorization and audit trail
Is maker/checker mandatory for every action?

The institution determines which actions are subject to approval. Rule publishing and case closure are the two most commonly used steps: authorization groups and approval pools are defined according to the institution's own hierarchy.

Can audit records be modified retroactively?

No. Records are kept in an immutable format, and archive integrity is verified with hash values. A legally valid timestamp is added to approvals.

How granular can authorization be configured?

Down to the screen, button, and data level. A user may view a screen but not perform a specific action within it: sensitive fields can be displayed with masking.

We have multiple subsidiaries, can we segregate the data?

Yes. Data sources are managed independently, and each department only sees its own source, rule set, and alerts.

On-premise deployment
Do AI features also run on-premise?

Yes. The analysis layer, including case pre-analysis, open-source screening, and report generation, runs on your own servers: customer data is never sent to external services.

Does on-premise deployment require significant hardware?

The platform is designed to process high volumes with limited resources: scoring across millions of records is completed in milliseconds with a modest server configuration. Exact requirements are determined together based on your transaction volume.

What happens to our historical data?

It is migrated into the system before going live. This ensures that your scenarios using lookback windows, such as 'the last 6 months', run with your real data from day one.

How are updates performed?

Releases are applied to your own environment during scheduled maintenance windows. Running the deployment offline does not hinder the update process.

About Bitrelic
Which certificates do you hold?

An ISO/IEC 27001 information security management certificate and a SOC 2 Type II independent attestation report, alongside ISO 22301 (business continuity), ISO/IEC 20000-1 (IT service management), ISO 9001 (quality), ISO 37001 (anti-bribery), ISO 10002 (customer satisfaction) and ISO 45001 (occupational health and safety). Scope and validity details are shared on request.

Are there compliance specialists on the team, or only engineers?

Both. The founding team includes compliance officers who have carried personal responsibility in supervisory audits, and they usually run the product demonstrations.

Which sectors use TruvaLI?

Today's focus is payment systems and institutions, electronic money institutions, closed-loop wallets, loyalty systems and SPK-regulated crypto-asset service providers. Before those, the decision engine was hardened in high-volume regulated gaming infrastructure, where real-time decisions are mandatory.

MASAK compliance and transaction monitoring in banking
Can TruvaLI integrate with the core banking system?

Yes. Field mapping is dynamic, connecting without changing the bank's own data model. Card, loan, and branch records can also be linked to the same customer view; a portion of the types in the guide already require reading these systems together.

Do we have to write all 173 types in the guide as rules?

The guide states the opposite: obliged parties should not limit themselves to the listed types and must report any transaction that raises suspicion, even if it does not match any of them. The types are a minimum common ground, not a ceiling.

Does customer data leave the bank?

Not with an on-premise deployment. The software runs on the bank's own infrastructure, data remains in the bank's information systems, and keys and the audit trail are under the bank's control. Cloud and private cloud are also options; the decision belongs to the bank.

Can a new rule be tested before going live?

Yes. The rule is run on historical traffic in rule simulation to see the alert volume it will generate. You can also specify any date you want and see the result on that day's traffic.

Who is the regulator of banks?

The regulator of banking activities is BDDK. The counterparty for money laundering and terrorist financing obligations is MASAK.

Why are indicators not visible from a single system?

Most indicators require reading customer, account, transaction, and channel data together; in banks, this data usually resides in separate systems.

How are linked accounts detected?

The relationship network between accounts is mapped via shared IPs, devices, phone numbers, addresses, and counterparties; this reveals clusters that are not visible when looking at individual accounts.

How does integration with the core banking system work?

The application sends events, and the system returns the score and decision. Non-financial events also go through the same path and are used in rules.

Fintech: managing rapid growth and compliance burden simultaneously
Which regulator am I subject to as a fintech?

It depends on the license you hold: TCMB for e-money and payment services, BDDK for lending and finance, and SPK for crypto assets and capital markets brokerage. Regarding money laundering obligations, the authority is always MASAK.

How do you keep up with a small compliance team?

By ensuring that rule changes do not require development tickets. Controls are written in your own words, drafts are tested in simulation, and deployed to production upon approval.

How does alert volume affect growth?

As the customer base grows, the number of alerts increases, and at a certain point, the team can no longer realistically investigate them. Alerts are closed, but they are closed without justification, which surfaces during audits.

Does the onboarding flow reduce conversion?

Not if the level of control adapts to risk. Simplified due diligence is applied to low-risk applications, while enhanced due diligence is applied to high-risk ones, with the difference defined as a rule.

What signals can be used at the moment of onboarding?

The provider and structure of the email address, whether the IP address is a proxy or VPN, and whether there are other applications connecting from the same device or address.

Does AI make the decision?

No. It generates a preliminary assessment during case investigation, while the final decision remains with the human and is recorded with its justification.

What are the benefits of a single platform over separate products?

Having the onboarding file, transaction history, and case reside on the same record eliminates integration costs and the data collection burden during audits.

Can the impact of a new rule be measured in advance?

Yes. The new threshold is run against historical traffic to see how many alerts it will produce before going live.

Payment account and balance risk in electronic money institutions
How are top-ups to accounts of different individuals from the same IP detected?

IP data must be collected at onboarding, stored in the customer record, and compared across accounts. TruvaLI extracts the connection network between accounts via shared IP, device, phone, and email. This corresponds to type T-006-2.62 in the guide.

Can a change in balance compared to the long-term average be written as a rule?

Yes. The rule engine supports flexible aggregation windows, meaning rules that compare against the account's historical average are set up within a single rule. The threshold is determined by the institution's own risk policy.

How is the use of a prepaid card for purchasing precious goods detected?

Merchant category data must be analyzed alongside the transaction record. Once the category data is linked, type T-006-2.27 in the guide can be turned into a rule.

Does customer data leave the institution?

Not with an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Who is the regulator of electronic money institutions?

The operational regulator is TCMB. For money laundering obligations, the authority is MASAK.

Why does risk accumulate in the account rather than the transaction?

Individual top-ups and withdrawals may appear normal; the pattern emerges in the balance accumulating in the account and the relationship between top-ups and withdrawals.

How is structuring detected?

The accumulation of sub-threshold amounts across the same account or related accounts is calculated via aggregation windows, and attempted transactions also remain in the records.

Can data collected during onboarding be generated later?

No. Email and IP scores serve as inputs for subsequent rules and cannot be obtained retroactively if they are not collected at onboarding.

Merchant risk and KYB in payment institutions
Is KYB in a payment institution a check that ends at onboarding?

No. Most merchant types in the guide are read from data generated after the merchant is onboarded: chargeback rates, round amount density, volume relative to sector averages, and transferring balances to third parties. KYB begins with onboarding and continues with monitoring.

Can a merchant's website be analyzed automatically?

Yes. When a website address is provided, the site can be scanned end-to-end, its content extracted, and adverse media and open-source records about the merchant classified by risk type. Types T-006-2.28, T-006-2.35, and T-006-2.40 in the guide require this.

Does merchant data leave the institution?

Not with an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Are we required to write all types in the guide as rules?

The guide states the opposite: obliged parties should not limit themselves to the listed types and must report any transaction that raises suspicion, even if it does not match any of them. The types are a minimum common ground, not a ceiling.

Who is the regulator for payment institutions?

The operational regulator is TCMB. For money laundering obligations, the authority is MASAK.

Why is the merchant considered the primary customer?

The institution is responsible for the merchant's activity and the legitimacy of that activity; risk is largely concentrated in what the merchant sells.

What happens if the declared activity and the sold product diverge?

This is a well-known issue in the sector and one of the first things monitoring looks at: deviations in volume, product category, and chargeback rates change the risk classification.

What is monitored after merchant onboarding?

Deviations in transaction volume from declarations, rising chargeback rates, changes in product categories, and changes in ownership structure.

MASAK compliance and customer risk in the gaming and betting sector
Are betting and gaming operators MASAK obliged parties?

Yes. MASAK publishes a dedicated suspicious transaction report guide for this sector and expects reports to be submitted electronically via MASAK.Online.

Do we have to write rules for all 68 types in the guide?

The guide states the opposite: obliged parties must not limit themselves to the listed types and must submit a report even if a suspicious transaction does not match any of them. The types are a minimum common ground, not a ceiling.

If email and IP data are not collected at onboarding, can they be generated later?

No. If the server where the account was opened and the IP of the first login are not recorded at that moment, they cannot be retrieved retroactively. A portion of the types in the guide rely directly on this first-contact data.

Where do the athlete, referee, and club manager lists come from?

T-010-2.36 considers a customer holding a role or position that could influence the outcome of the game they play to be an indicator of suspicion. TruvaLI supports creating internal lists for these individuals and integrating them into the screening workflow.

Is the gaming sector a MASAK obliged party?

Yes. Operators in the field of gaming and betting are obliged parties under Law No. 5549 and are subject to MASAK's sector-specific guide.

Why is first-contact data so important?

In a remotely opened player account, email, phone, and IP are often the only verifiable information available: if this data is not collected at onboarding, it cannot be generated retroactively.

Why is occupational information requested?

The guide lists occupational declaration as an indicator: a disproportion between the declared occupation and gaming volume raises suspicion. Occupation is not a field left in the onboarding form: it is a rule input.

How is multi-accounting detected?

Clusters of accounts connecting via the same device, IP, payment instrument, and similar email addresses are uncovered through relationship networks.

MASAK compliance and wallet risk for crypto asset service providers
Can sanctions screening be performed via a wallet address?

Yes. The screening workflow accepts the wallet address alongside the individual's name, and the institution can create its own address lists. Type T-010-2.8 of the guide covers attempts to transfer to individuals or addresses on lists of banned or wanted persons.

How are fragmented transfers from different customers to the same address detected?

A relationship network among customers must be extracted via the destination address. It cannot be detected by looking at a single account. This is Type T-010-2.27 of the guide.

How are anonymous wallet and decentralized exchange indicators turned into rules?

The address and the counterparty platform must be classified. This data comes from the institution's own systems or integrated data sources; the rule engine combines this with time-dependent conditions.

Does customer data leave the institution?

Not in an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Who is the regulator for crypto asset service providers?

In Türkiye, the operational regulator is SPK. In terms of money laundering obligations, the authority is MASAK.

Is a separate system required for crypto?

No. The wallet address is accepted as an entity alongside the individual's name in the screening workflow; on-chain and off-chain data converge in the same customer view.

What is looked at during address screening?

Direct sanctions matches, distance to a listed address, mixer exposure, cluster relationships, and the path of funds.

Is crypto covered on the EU side?

Yes. The direct supervision definition in Regulation (EU) 2024/1620 specifically lists crypto asset service providers.

MASAK compliance in e-commerce, merchant and buyer risk
Does this guide also cover businesses selling from their own websites?

The guide defines its scope around intermediary service providers, meaning platforms where third parties make sales. A business selling its own products on its own website is not the direct target, but most of the indicators listed have equivalents in any e-commerce structure that accepts payments.

Why is the chargeback rate considered a money laundering indicator?

The guide lists an unusually high number of return transactions under T-020-2.21, and the use of fake cards along with the detection of fake product purchases under T-020-2.31. Fraud control and money laundering control look at the same data.

Are product and price data also subject to monitoring?

Four types in the guide are directly related to products and prices: the sale of prohibited products, off-market pricing, frequent and sudden price changes, and sending different or fake products instead of the ordered item. A system that only looks at the payment flow will not detect any of them.

Does customer data leave the institution?

Not in an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Are e-commerce intermediary service providers obliged parties?

Yes. They are obliged parties under Law No. 5549 and are subject to MASAK's relevant sectoral guide.

How does money laundering manifest in e-commerce?

Not in the transaction itself, but in the authenticity of the product, price, and parties. Payment for a product that is never actually delivered is recorded as a regular sale.

Can product and price data be included in rules?

Yes. Product category, price, and cart contents are rule inputs; a price that significantly deviates from market value is an indicator.

Can the link between buyer and merchant be detected?

Yes. The relationship network between the parties is mapped through shared device, IP, payment instrument, and address.

Credit and financing: identity and fraud risk at the time of application
Is credit risk the same as fraud risk?

No. Credit risk asks whether the borrower will repay, while fraud risk asks whether the application is genuine. An application with a perfect credit score can be made with a stolen identity.

Why is synthetic identity hard to detect?

An identity created by combining real and fabricated information builds a credit history and pays regularly for a period. Therefore, device, network, and email signals create a layer independent of credit history.

How is remote identity verification performed?

It starts with document reading: chip reading via NFC on chipped documents, liveness testing, and face matching validate each other. Someone who copies a document cannot bypass both the chip and liveness checks.

Are income documents checked?

The text of the uploaded document is read, and the amount, date, and party information within are converted into structured data, making it comparable with the declaration.

Are bulk application clusters detected?

Yes. Applications coming from the same device, IP, or similar email addresses are unpacked using a relationship network: if one application is suspicious, others linked to it are also put under review.

Are credit institutions MASAK obliged parties?

Yes. Identity verification, identifying the ultimate beneficial owner (UBO), sanctions and PEP screening, and suspicious transaction reports are mandatory. The regulator of the institution is BDDK.

Why are early closures reviewed?

An unexpected bulk closure raises questions about the source of funds and is subject to monitoring.

Can the impact of the rejection rate be measured?

Yes. How many applications a new rule will reject and how many of those are actually fraud is measured against historical application traffic before going live.

Client, debtor and receivable risk in factoring
Is the debtor screened as well as the client?

Yes. The client assigns the receivable, but the debtor is the party that pays it, so both are screened against sanctions and PEP lists and both carry a risk score. On a cheque or a bill the drawer and the endorsers are screened too.

Why is screening repeated after onboarding?

The client is onboarded once, but its debtor portfolio changes with every assignment. A list checked at onboarding is out of date by the second transaction, so screening runs continuously and re-runs when a name enters a list later.

How is a fictitious invoice detected?

The text of the invoice is read and the amount, date and party information in it become structured data, which is compared with the client's declared sector and turnover and with the rest of its portfolio. The same amount circulating between related companies is what a circular invoicing rule looks for.

Are factoring companies MASAK obliged parties?

Yes. Identity verification, identifying the real beneficiary, sanctions and PEP screening, continuous monitoring and suspicious transaction reports are obligations, and each has to be evidenced with a record of when it was done and by whom.

Why is an early settlement reviewed?

A debt settled long before its due date, or settled by someone who is not the debtor, raises a question about where the money came from. Both cases are written as rules, so they are raised as alerts rather than noticed by hand.

Can one platform cover KYB and transaction monitoring?

Yes. Screening, KYB, monitoring and case management share one rule engine and one audit trail, so a decision about a client and a decision about its debtor are not taken in two systems that cannot see each other.

MASAK compliance in insurance, beneficiary and source of funds risk
Does this guideline cover insurance companies?

The guideline defines its own scope as insurance and reinsurance brokers. Most of the indicators it lists stem from the nature of the brokerage relationship and apply across the entire insurance chain, but the guideline specifically addresses brokers.

What happens when the beneficiary changes?

A change in beneficiary, representative, or payment source triggers a new screening and a new risk assessment. The decision made on day one does not remain static.

Are the policyholder, the insured, and the beneficiary screened separately?

Yes. All four, including the representative, are recorded as separate parties and screened against sanctions, PEP, and internal lists. For corporate parties, the ownership structure is resolved to identify the ultimate beneficial owner (UBO).

How is the concealment of the source of funds detected?

The payment source is recorded and compared alongside the party structure. Types T-012-2.15 and T-012-2.16 of the guideline cover the purpose of concealing the source of funds and payments through entities in countries known as tax havens.

Does customer data leave the institution?

Not with an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Who does the guideline address?

The relevant MASAK guideline specifically addresses insurance and reinsurance brokers in terms of its scope.

Where is the money laundering risk concentrated in insurance?

Not in the payment of the premium, but in whose name, with whose funds, and for what reason the policy is established. Early cancellation and transfer are also indicators.

How is the party structure resolved?

The policyholder, the insured, and the beneficiary are recorded as separate parties, and each is screened against sanctions, PEP, and internal lists.

Is the relationship limited to day one?

No. Beneficiary changes, early cancellations, additional premiums, and transfers occur later and are subject to monitoring.

MASAK compliance and merchant risk in marketplaces
Where is the primary risk surface of a marketplace?

The majority of the guide's sector-specific types focus on the merchant. Volume spikes, incomplete or incorrect registration details, manipulated reviews, failure to act on complaints, and sudden activity after prolonged inactivity are listed individually.

Why is review manipulation considered a laundering indicator?

Under T-020-2.26, the guide considers the detection of unrealistic positive reviews or manipulated feedback about a merchant to be an indicator of suspicion. This means that the platform's own reputation system is also a data source that must be monitored.

Is merchant onboarding a KYB task?

Yes. Concealing the ultimate beneficial owner (UBO), the third party directing the transaction not being a party to documents, and complex multi-jurisdictional structures are separate types in the guide. They cannot be addressed without resolving the ownership structure of the company behind the store.

Does platform data leave the organization?

Not with an on-premise deployment. The software runs on the platform's own infrastructure, data remains within the platform's information systems, and keys and the audit trail are controlled by the platform.

Why is the intermediary service provider an obliged party?

Because it facilitates transactions for goods it does not sell itself, it is responsible for verifying the authenticity of both the merchant and the buyer; it is an obliged party under Law No. 5549.

What is reviewed during merchant onboarding?

Identity and ownership structure, activity category, consistency between declared information and public footprint, and links to previously closed merchant accounts.

Can it be detected if the buyer and the merchant are the same person?

Yes. A network of relationships established through shared devices, IPs, payment methods, and addresses reveals these connections.

Can platform data be integrated into rules?

Yes. Platform-specific fields such as product category, price, shipping, and return behavior are used as rule inputs.

Money transfers: analyzing sender, receiver, and their relationship
How is the risk of a transfer determined?

Not by its amount, but by the relationship between the parties. The sender, receiver, frequency, country, transaction history, and time window are analyzed together.

Which guideline applies to us?

Organizations providing money transfer services generally operate under a payment institution license and are subject to MASAK's guideline for payment and electronic money institutions.

Are incomplete transfers stored?

Yes. The guideline also covers attempts in structuring; rejected and incomplete transfers remain in the records. Since events are ingested using upsert logic, updates do not generate new records but re-evaluate the existing record.

Are the sender and receiver screened separately?

Yes. Both are recorded as separate parties and screened against sanctions, PEP, and internal lists.

Can transfers coming from different senders to the same receiver be detected?

Yes, but not by looking at a single sender account. The relationship network around the target must be extracted using shared IPs, devices, phone numbers, emails, and counterparties.

Why are cash transactions handled separately?

Transferring funds deposited from ATMs in different provinces into a single account, and withdrawing loads made to an inactive account from ATMs at the maximum amount, are distinct types in the guideline; they cannot be analyzed without channel information.

Which data should be collected at onboarding?

Email and IP scores. The guideline considers loading funds into accounts belonging to different unrelated individuals from the same IPs as an indicator, and this data cannot be generated later.

Where is the report draft prepared from?

From the same case data. The decision is linked to the case with its justification and evidence, and the signature remains with the institution.

MASAK compliance and ultimate beneficial owners in capital markets
How are complex and multi-jurisdictional ownership structures handled?

In the KYB flow, the structure is unraveled to identify the ultimate beneficial owner (UBO), and each layer is recorded individually. Types T-011-2.11 and T-011-2.13 of the guide require this.

Can indicators based on customer attitude be converted into rules?

No, they are not generated by an automated rule. The customer representative's observation is added to the case as a note, stored alongside the evidence, and included in the justification of the report.

Does the guide cover the entire capital market?

No, it covers investment trusts. However, the weight of the indicators it lists points to a common challenge for capital market institutions: identifying the actual person behind the transaction.

Does customer data leave the institution?

Not in an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.

Who is the regulator for capital market institutions?

The operational regulator is SPK. In terms of anti-money laundering obligations, the authority is MASAK.

Where is the risk visible?

Not in the profit of the transaction, but in whose name the account is opened and the economic logic of the transaction. Transactions performed at a loss or without economic justification are indicators.

How is the ownership structure unraveled?

It is unraveled layer by layer down to the ultimate beneficial owner (UBO); each natural person in the chain undergoes sanctions and PEP screening.

Can regulatory bulletins be ingested into the system?

Yes. A bulletin, decision text, or PDF list is uploaded; the text is read, and the individuals and entities within it are converted into structured records.

The Balkans: Compliance infrastructure in Montenegro and Serbia
Which evaluation are Montenegro and Serbia subject to?

The Council of Europe's MONEYVAL committee evaluation on anti-money laundering and combating the financing of terrorism.

Is it necessary to deploy two separate systems for the two countries?

No. Each country is defined as a separate data source: the same deployment hosts different rule sets, and one country's threshold does not affect another.

What is common and what is different between the two countries?

The risk-based approach, customer identification, ultimate beneficial owner (UBO) identification, and suspicious transaction reports share a common framework. Reporting thresholds, reporting formats, retention periods, and authority expectations vary.

Does the EU's new AML package affect these countries?

Yes. Since both are in the process of aligning with the EU acquis, the framework established by (EU) 2024/1620, (EU) 2024/1624, and (EU) 2024/1640 sets their compliance target.

When did AMLA start to apply?

From 1 July 2025. It directly supervises selected obliged parties in the financial sector, including crypto-asset service providers.

What do we do when a country-specific obligation is introduced?

It is written into the rule engine: nested logic, named aggregation definitions, and callbacks from rules are supported. The rule can be described in your own language and tested on historical traffic before going live.

Is there a local team in the region?

Bitrelic has a team in Podgorica: we track regulatory changes and authority expectations by having a physical presence in the region.

Where does the data reside?

In an on-premise deployment, within the institution's own information systems: keys and the audit trail are under the institution's control. Since data residency rules vary from country to country, this is a decisive factor in regional deployments.

Middle East and North Africa: multi-country compliance deployment
Is a separate system required for each country in the region?

No. Each country is defined as a separate data source; the same deployment carries different rule sets, and one country's threshold does not affect another.

What is the main challenge in the region?

It is diversity, not complying with a single regulation. Reporting thresholds, identity verification requirements, retention periods, and authority expectations vary from country to country.

Does a single set of thresholds fit the entire region?

No. The ratio of foreign national customers, the weight of worker remittances, and cash habits vary even within the region; a volume that is normal in one country can be an indicator of suspicion in another.

How are cross-border transfers evaluated?

Transfers to or from high-risk countries that reach significant amounts within a certain time frame without a reasonable explanation are a common indicator; the sender and receiver context, time window, and repetition are analyzed together.

Can a single transaction be subject to two regimes simultaneously?

Yes. When remittance and transfer flows cross multiple jurisdictions, the transaction may need to be evaluated against two different regimes simultaneously.

What do we do when a country-specific obligation arises?

It is written into the rule engine: nested logic, named aggregation definitions, and callbacks from rules are supported. The rule is tested on historical traffic before going live.

Where do the shared components remain?

Customer records, screening infrastructure, case management, audit trail, and report drafting remain in a single place; a separate system is not deployed for each country.

Where does the data reside?

In an on-premise deployment, within the institution's own information systems; keys and the audit trail are under the institution's control.

KVKK: personal data protection in financial crime analysis
How does KVKK affect financial crime analysis?

Law No. 6698 regulates the protection of personal data used in analysis. The classification of biometric data as special category and the restriction of international transfers to an adequacy decision are two decisive points.

Is the software vendor also liable?

Yes. The second paragraph of Article 12 of the Law provides for joint liability in taking measures if data is processed by another party on behalf of the data controller.

Do face matching and liveness checks constitute biometric data processing?

Yes. Article 6 of the Law classifies biometric data as special category and, as a rule, prohibits its processing: processing is only possible under one of the specified conditions.

Can we transfer data abroad?

Pursuant to Article 9, data can be transferred if one of the conditions in Articles 5 and 6 is met and an adequacy decision exists regarding the country, sector, or international organization to which the transfer will be made.

Who issues the adequacy decision?

It is issued by the Board, published in the Official Gazette, and re-evaluated at least once every four years.

What needs to be done in the event of a data breach?

The fifth paragraph of Article 12 of the Law requires that if data is obtained through unlawful means, the situation must be reported to the data subject and the Board as soon as possible.

Can we see who has accessed personal data?

Yes. Access is recorded in the audit trail: role and authorization definitions, approval policies, and delegation of authority are logged separately, and the log can be exported to a separate destination.

How is the data collected during identity verification managed?

The document image, data read from the chip, selfie, liveness video, and call recording are recorded separately: the collection time, the check in which it is used, and the retention period of each can be managed individually.

GDPR: technical and organizational measures in risk analysis
Which articles of GDPR apply to risk analysis?

Article 25, which regulates data protection by design; Article 32, which lists security of processing; and Article 9, which classifies biometric data as a special category.

Which measures does Article 32 explicitly list?

The use of aliases and encryption; the ability to ensure the confidentiality, integrity, availability, and resilience of systems and services; the ability to restore access in a timely manner in the event of an event; and a process for regularly testing, assessing, and evaluating the effectiveness of the measures.

Is taking the measure sufficient?

It is not sufficient. Article 32(d) requires regular testing, assessing, and evaluating the effectiveness of the measures.

Is face matching a special category under GDPR?

Yes. Article 9 prohibits, as a rule, the processing of biometric data for the purpose of uniquely identifying a natural person, and only permits it under specific conditions.

Is the deployment model considered a measure?

Article 25 requires measures to be taken at the time of determining the means of processing; the choice of deployment model falls under this scope. In an on-premise deployment, data remains within the organization's information systems and keys are under the organization's control.

How do we evaluate the effectiveness of the measures?

Through access, decision, and approval logs. Since the audit log can be exported to a separate destination, it can also be evaluated within the organization's own logging infrastructure.

How is identity verification data stored?

The document image, data read from the chip, selfie, liveness video, and call recording are recorded separately; the collection time, the check it is used in, and the retention period of each are managed individually.

How is data minimisation applied in rules?

The rule engine shows which field is used in which rule; when it is traceable which decision a field enters, it can be seen whether an unnecessary field is being processed.

Compliance teams: bearing the responsibility of the compliance officer
Why is the compliance officer's liability treated separately?

Liability is personal as much as it is corporate. When auditors ask questions, they address that individual, and if the answer is not in the records, there is no defense.

What questions are asked most during audits?

Why a rule was written with that specific threshold, why a case was closed, why a report was not filed, who approved the decision, which rule set was running in the past, and who accessed the data.

Is a technical team required to write rules?

No. Controls can be written in your own words, and the corresponding draft rule is generated automatically. The draft does not go live without approval and is first tested in simulation.

Why is generating too many alerts more dangerous than missing them?

When the team is overwhelmed, alerts are not actually reviewed, yet the records show an investigation was conducted. This is the hardest scenario to defend during an audit.

Does artificial intelligence make the decision?

No. It generates a preliminary assessment from the case data, but the decision remains with the human and is logged with its justification.

Is the approval workflow limited to a single second signature?

No. Approval policies, multi-signature decisions, and delegation of authority can be defined, and the delegation itself is recorded alongside its documentation.

Where is the draft report generated from?

Directly from the case itself. The date range, total amount, channel breakdown, and suspicion category already reside within the case. The signature and filing decision rest with the compliance officer.

What if we encounter a situation with no direct equivalent in the regulations?

Our team of compliance and fraud practitioners have done this work inside banks for over fifteen years. You can reach someone who has answered that exact question from their own desk.

Fraud and risk teams: changing rules with your own hands
What is the biggest bottleneck for fraud teams?

It is not identifying the threat, but translating that insight into the system. When the rule writer and the risk expert are different people, every change enters a request queue.

Is technical knowledge required to write rules?

No. You write the control in your own words to generate a draft rule, which never goes live without approval.

Does a rule always have to block a transaction?

No. Contributing to a score, adding an alert reason, or simply flagging the transaction are also valid outcomes. This allows you to monitor aggressive rules before deploying them to production.

Can non-financial events be included in rules?

Yes. Events without monetary values, such as logins, device changes, document uploads, and setting modifications, are also used in rules.

How is the impact of a new rule measured?

The rule is run against historical transaction traffic, showing how many transactions it would block, how many alerts it would generate, and how many of those actually turn out to be fraud, all before going live.

Can tests be run against a specific day?

Yes. The rule can be replayed against that day's traffic to see exactly what the outcome would have been.

Can rules be generated from past cases?

Yes. The signal pattern within the case can be extracted and converted into a rule, keeping institutional knowledge within the organization rather than with individuals.

Can the execution order of rules be controlled?

Yes. The sequence in which rules are evaluated can be defined, and the rule's owner and sharing permissions are also recorded.

Engineering: integration, event model, and deployment
How does the core integration work?

Your application sends an event, and the system returns the score, triggered rules, and the decision. The decision is returned fast enough to be used inline within the flow.

Are only financial transactions sent?

No. Logins, device changes, document uploads, setting changes, and account openings are also events, and they are used in rules in the exact same way.

Will data from different products get mixed up?

No. Data sources are kept separate, and rules can be scoped by source.

How are aggregations defined?

A customer's transaction count, sum, and average within a period are pre-defined and referenced by name in rules.

Do rule changes require deployment?

No. Rules exist as data, not code; compliance and fraud teams can modify rules without entering the engineering queue.

How do you find the source of a change in behavior?

The specific rule set and version executed are stored alongside the result of each event, making it possible to trace which rule caused the change.

Where is the deployment hosted?

It can be hosted on the organization's own infrastructure. Data never leaves the organization, logs remain on your own systems, and the audit trail can be sent to a separate destination.

Where is the best place to start?

With a single flow that causes the most losses or generates the most alerts. Events for that flow are sent, rules are run in simulation, and the results are compared with your existing system.

Internal audit: tracing decisions back to their source
Why can't internal audit look at today's screen?

Control systems are living systems; rules and thresholds change. Explaining a decision from six months ago using today's rule set yields incorrect results.

Why is the rule version so important?

If the specific rule and the version that triggered it are not stored alongside the event, the justification for a past decision cannot be reconstructed.

How is audit sampling conducted?

A subset is selected from the cases of a specific period using filters. Report definitions are created without code, results are saved, and the same definition can be run again in the subsequent period.

Does data need to be exported for auditing?

No. In an on-premise deployment, all logs remain within the institution's own infrastructure, so the audit itself does not create a data risk.

How is it verified that segregation of duties actually works?

Decisions prepared and approved by the same person can be queried. Approval policies, multi-signature decisions, and delegation of authority remain in the logs.

How is the effectiveness of a rule measured?

How many times it was triggered, how many cases it turned into, how many went to reporting, and how many were closed without justification are measured. A rule that never triggers and a rule that triggers everything are both audit findings.

Can the impact of a rule change be seen in advance?

Yes. The rule is run on historical traffic, and the before and after of the change can be compared.

Can the audit trail be altered later?

It cannot be altered. Logs can also be sent to a separate destination, so a change within the platform does not affect the audit trail.

MASAK compliance: obligations, reporting, and suspicion categories
Are we required to write all the types in the guide as rules?

The guides state the opposite: obliged parties must not limit themselves to the listed types, and must file a report even if a suspicious transaction does not match any of them. The types represent a minimum common ground, not a ceiling.

Can an event without a monetary value be subject to a report?

Yes. Matters such as suspicious account openings and closures, safe deposit box visits, or power of attorney and guarantee transactions are written in the description section of the form. The case must be capable of carrying these types of events.

Why is the suspicion category important?

When filing a report, the suspicion is mapped to one of the 38 categories in MASAK's reference table, and each category is matched with a legal regulation. Case management must operate with this taxonomy rather than arbitrary custom tags.

What is required for a report with a suspension request?

The guides set a clear threshold: there must be documents or serious indications supporting the suspicion, going beyond mere suspicion, and the report must be submitted with its justifications. This requires evidence to be attached to the case and the identity of the decision-maker to be recorded.

Who is a MASAK obliged party?

Law No. 5549 designates a wide range of institutions as obliged parties: banks, payment and electronic money institutions, capital markets institutions, insurance companies, crypto asset service providers, and operators in the field of games of chance are among them.

Are sectoral guides binding?

The guides list sector-specific indicators and establish a floor. If a pattern not listed in the guide raises suspicion, the obligation to report still applies.

How are reports submitted?

Application procedures and all submissions for suspicious transaction reports are carried out electronically through the MASAK.Online system.

Can we write rules specific to our own sector?

Yes, you can. A rule can be described in your own words to generate a draft, tested on historical traffic before going live, and put into effect upon approval.

AMLA and EU regulations: the direct supervision framework
What is AMLA?

It is the European Union's authority for anti-money laundering and countering the financing of terrorism, established by Regulation (EU) 2024/1620.

When did AMLA start to apply?

The Regulation was adopted on 31 May 2024 and has been applicable since 1 July 2025. Certain articles have been in force since 26 June 2024, and one article will apply from 31 December 2025.

Who does AMLA supervise directly?

Selected obliged parties in the financial sector, including crypto-asset service providers. It also coordinates and oversees financial and non-financial sector supervisory authorities.

Which texts form the framework?

Regulation (EU) 2024/1620, Regulation (EU) 2024/1624, Directive (EU) 2024/1640, and Regulation (EU) 2023/1113, which regulates information accompanying transfers of funds and certain crypto-assets.

What does direct supervision change?

Supervision is no longer a relationship maintained solely with national authorities; selected obliged parties are directly supervised by AMLA.

Can we establish different rule sets for different countries?

Yes. Countries and business units are defined as separate data sources; rule and data isolation is managed through this separation, allowing a single deployment to support the rule sets of different jurisdictions.

Is a separate system required for crypto?

No. In the screening workflow, a wallet address is treated as an entity alongside the individual's name; on-chain and off-chain data merge into a single customer view.

What is expected from the audit trail?

The reasoning behind every decision must be auditable. Details on who made the decision, under what authority, using which data, and when, are written to an immutable audit trail; which rule was triggered by which event is also recorded.

Customer onboarding: identity verification, KYB and onboarding risk score
Which methods are used for remote identity verification?

OCR and MRZ reading from document images, chip reading via NFC for chipped documents, liveness testing, face matching, and video calls where required by regulations. The layers verify one another; a single check is never the sole basis for onboarding.

Why is NFC reading particularly important?

Data read from the chip comes directly from the document itself. While checks based on image processing can be fooled by a high-quality copy, chip reading cannot be spoofed.

How is the ultimate beneficial owner (UBO) identified for corporate customers?

The ownership structure is resolved layer by layer down to the natural person. Every natural person identified in the chain also undergoes sanctions and PEP screening, with every step of the path recorded.

How is the email address scored?

The provider is matched against lists of trusted, disposable, and privacy-focused providers. The address is checked to see if it contains the person's first name, last name, date of birth, or initials, and a fuzzy search is run against similar or sequentially numbered addresses in the system.

What is extracted from the IP address?

By analyzing geolocation, ownership information, and rDNS records, the system determines whether the address is a proxy, VPN, or residential service provider. Finding other accounts using the same IP is a separate risk signal.

Can simplified due diligence be applied?

Yes. Where risk is low and regulations permit, fewer documents are requested; high risk triggers enhanced due diligence. Which threshold leads to which outcome is defined by the institution's own rules.

Who makes the onboarding decision?

Applications that exceed the score threshold are routed to human review. Decisions are recorded with their justification, subject to segregation of duties, and written to the audit trail.

Where are the documents collected during onboarding stored?

On the institution's own infrastructure in an on-premise deployment. Document images, call recordings, and screening results remain linked to the decision and can be presented as evidence later.

Sanctions compliance: screening, match verification, and decision logging
When does sanctions screening run?

During customer onboarding, at the moment of transaction, across the entire existing customer base when lists change, and during periodic reviews based on risk classification.

How is a match verified?

Aliases and transliterations, date of birth, ID and passport numbers, nationality, and city information are evaluated together. The photo is retrieved from the source and displayed with a confidence score, and the validity date of the record is also checked.

Do lifted sanctions generate alerts?

No. The validity dates of the record are read, and a lifted decision does not generate an alert.

Can you see which authority a match originates from?

Yes. Every record is stored with the issuing authority and its country, and the source link is also preserved.

Can an institution add its own sanctions list?

Yes. Through official source definitions, feed polling, or document uploads, the institution's own lists enter the same screening workflow.

How is the burden of false matches reduced?

Since verification signals are stored in the record, name similarity alone does not generate alerts. Where the threshold is set is written as a rule, and how many alerts a new threshold will generate on historical traffic is previewed via simulation.

How does the process proceed after a match?

A match opens a case. The review, decision, and approval chain is logged with its justification and written to an immutable audit trail. If a notification is required, the case is converted into a report.

Does screening data leave the institution?

Not in an on-premise deployment. Lists, screening, and decisions all remain entirely within the institution's own infrastructure.

Payment screening: real-time sanctions checks
Who is screened in payment screening?

Senders, beneficiaries, the beneficiary's bank, and any intermediary institutions. Name and address information in free-text fields is also covered, as a sanctioned party often appears in the description line.

Does screening slow down the payment flow?

Screening is embedded directly into the transaction pipeline and operates within a latency budget. The result must return fast enough to be part of the decision; otherwise, screening is effectively disabled.

Is the payment rejected when a match occurs?

It is not rejected; it is suspended. The suspended transaction is linked to a case, and a human makes the decision.

How are false stops reduced?

Confirmation signals such as aliases, date of birth, ID and passport numbers, nationality, and city are stored in the record, so a common name alone does not stop a payment. The effective date of the record is also checked.

Are country and currency covered by screening?

Yes. Sanctions regimes target countries and sectors as much as individuals; the route of the transfer may require verification even if all parties are clear.

Can the impact of a new rule be seen in advance?

Yes. How many transactions the new threshold would stop in historical payment traffic is measured via simulation before the rule goes live.

Is the release decision logged?

Yes. Both releasing and stopping are decisions; both are written to the immutable audit trail with their justification and are subject to segregation of duties.

Can an institution add its own restricted party list?

Yes. The institution's own lists enter the same screening flow via official source definition, feed, or document upload.

Continuous monitoring: tracking post-onboarding behavior
What does continuous monitoring compare?

It evaluates transactions against the customer's own history, declared activity, peer groups, below-threshold structuring patterns, and network relationships established through shared devices, IPs, or accounts.

Does the customer risk class change?

Yes. A new sanctions record, adverse media finding, a series of transactions inconsistent with declarations, or a change in ownership structure elevates the risk class: monitoring frequency and the review schedule change accordingly.

Are existing customers re-screened?

Yes. As lists change, the existing customer base is re-screened, because a record that is clean today might match later.

How is the risk of generating too many alerts managed?

Before a rule goes live, it is run against historical traffic to measure how many alerts it will generate. A threshold that drowns the team is just as problematic as one that misses risks.

Is technical knowledge required to write rules?

No. The required control can be written in plain language, and its equivalent is generated as a draft rule: the draft does not go live without approval.

Can you see later which rule was used to make a decision?

Yes. Which version of which rule triggered the alert is recorded with the event, allowing a past decision to be explained using the rule set active on that day.

How does the process proceed after an alert?

An alert becomes a case. Following the investigation, the case is closed, snoozed, or escalated to a report: the justification and decision are written to the audit trail.

Is monitoring independent of the onboarding process?

No. The declaration and profile collected at onboarding serve as the baseline for monitoring: without a declaration, deviations cannot be measured.

Account takeover: detection through session, device, and behavioral signals
Why is account takeover not caught during authentication?

Because the login is successful. The password is correct, and in most cases, multi-factor authentication has also been bypassed; the takeover becomes visible in post-login behavior.

Which signals are evaluated together?

New device ID, the proxy or VPN status of the IP, impossible travel between two sessions, shared devices, funds leaving the account following a settings change, and unusual transaction speed.

Does a single signal trigger a decision?

No. What makes a takeover visible is the combination of signals; a new device, a VPN, and funds leaving after an IBAN change together form a single strong pattern.

Are accounts opened from the same device detected?

Yes. Account clusters connected via the same device, IP, or email pattern are revealed through link analysis; a suspicious account opens up others sharing the same device for investigation.

How does an email address generate a signal?

Whether the provider is reputable, disposable, or privacy-focused generates a risk score. The similarity of the address to other addresses in the system via fuzzy matching, and clusters of addresses with sequential endings, serve as additional indicators.

Does the check slow down the payment flow?

The evaluation runs inline within the transaction flow and is fast enough to make a decision. A slow check provides the correct answer only after the money has left, which has no practical value.

How is the risk of blocking legitimate users measured?

The new threshold is run against historical session and transaction traffic, showing how many legitimate users would be blocked before the rule goes live.

Can a rule be generated from a past case?

Yes. The signal pattern within the case can be extracted and converted into a rule, ensuring the same path cannot be exploited twice.

Bonus abuse and multi-accounting: seeing the connection
Why is bonus abuse invisible on a single account?

Because a single account behaves in compliance with the rules: the user registers, claims the bonus, and meets the requirements. The violation lies in the relationship between the accounts.

What information is used to link accounts together?

Device ID, IP and network, payment method, email patterns, identity detail combinations, and behavioral synchronicity.

How are similar email addresses detected?

Addresses are scanned against each other using fuzzy matching; this reveals highly similar or sequentially numbered email clusters. The use of disposable email providers serves as an additional signal.

Is VPN usage considered a violation on its own?

No, it is not. The characteristics of the IP address are just one of many signals; the final decision depends on the combination of signals and the rules defined by the institution.

Can two people playing from the same household be mistakenly flagged as a cluster?

This risk is real, which is why the number of accounts a new threshold would catch in historical traffic is measured before the rule goes live.

Is technical knowledge required to write this type of rule?

No, it is not. You can describe what the check should be in your own words, and the corresponding draft rule is generated; the draft does not go live without approval.

What happens when a cluster is detected?

The cluster triggers a case where the accounts, the links between them, the triggered rule, and the investigator's justification are kept together. Revoking the bonus or clearing the cluster is recorded as a decision.

Can decisions be audited later?

Yes. Which rule and version was triggered, and who made the decision with what justification, is recorded in an immutable audit trail.

Chargebacks and payment fraud: catching them before the dispute
Why is the cost of a chargeback more than just the refunded amount?

A dispute fee is added to the refunded amount for each transaction, and the payment processor imposes sanctions if the chargeback rate exceeds a certain threshold. The third is the most expensive because it impacts the merchant's license to operate.

Which signals are analyzed at the moment of transaction?

Device ID, proxy or VPN status of the IP, match between billing/shipping addresses and IP location, card velocity, email attributes, and cart behavior.

Does a single signal reject a transaction?

No. The decision depends on the aggregation of signals and the threshold set by the institution.

Can you detect if the same card is used across different accounts?

Yes. Clusters of accounts and transactions linked by the same card, device, or email pattern are uncovered using link analysis.

Is raising the threshold always beneficial?

No. Raising the threshold reduces chargebacks but also lowers legitimate sales. The optimal threshold is found by balancing these two costs.

Can the impact of a new rule on sales be measured?

Yes. The rule is run against historical transaction traffic, allowing you to see how many transactions it would reject and how many of those would actually turn into disputes before going live.

What evidence is used when responding to a dispute?

Device and IP information at the moment of transaction, address matching, session history, and delivery records. Having this data stored alongside the transaction determines your leverage during the dispute process.

Can a rule be created from a past case?

Yes. The pattern of the case can be extracted and converted into a rule, ensuring the same path cannot be exploited again.

Source of funds investigation: documenting where the money comes from
Are source of funds and source of wealth the same thing?

No. Source of funds asks about the origin of the money in a specific transaction, while source of wealth asks where a person's total assets come from. A customer may be able to explain their wealth but fail to explain the funds in a single transaction.

What triggers an investigation?

An amount disproportionate to the declared profile, a sudden change in behavior, a high-risk counterparty or country, a PEP relationship, and adverse media findings.

Which documents are accepted?

Evidence supporting the declaration: such as a sales contract, payslip, inheritance certificate, dividend resolution, or loan agreement. The text of the document is read, converting the parties, amounts, and dates within it into structured data.

Is a document sufficient on its own?

No. The declaration, document, and transaction behavior are evaluated together; the document supports the declaration, while the transaction behavior tests it.

Is the path of the funds investigated?

Yes. Sending parties, intermediary accounts, and associated individuals are examined; connections established through a shared device, IP, or address can reveal structures that are invisible when viewed individually.

How is the source of funds queried in crypto assets?

The inquiry shifts to the wallet: the history of the address where the funds originate, its contact with mixing services, and its proximity to sanctioned addresses are analyzed.

How does an investigation conclude?

The explanation is deemed sufficient and the case is closed, additional documentation is requested and the case is deferred, or the explanation remains insufficient and proceeds to a report.

How is a closure decision defended during an audit?

The declaration, documents, screening results, transaction history, and the investigator's justification all reside within the same case. The question asked during an audit is usually why it was closed, and the answer is right inside the case.

Regulatory reporting: suspicious transaction reports and case data
How is the report draft prepared?

It is not filled out from scratch on a separate reporting screen: it is generated directly from the case itself. The date range, total amount, channel and type distinction, party information, and suspicion category already reside in the case.

Are all transactions that are not deemed suspicious included in the report?

No. The guideline does not require writing all financial transactions of the customer with the obliged party that are not deemed suspicious into the form: the report carries a selection, not a full dump, and the justification for that selection resides within the case.

Are events with no monetary value reported?

Yes. Suspicious account openings and closures, safe deposit box visits, and guarantee or power of attorney transactions are written in the description section of the form, leaving the suspicious transaction section blank.

Can a single report cover multiple transactions?

Yes. If the suspicion is based on multiple transactions within a certain date range, the total amount and the date range are reported together as a multiple transaction.

How is the suspicion category determined?

It is placed into one of the 38 categories in the MASAK reference table, and each category maps to the relevant legal regulation: for example, usury and POS usury are linked to Article 241 of Law No. 5237.

What threshold applies to reports with a suspension request?

Under the regulation based on Article 19/A of Law No. 5549, there must be documents or serious indications supporting the suspicion, rather than mere suspicion, that the asset is related to the crime of money laundering or financing of terrorism.

How is the report submitted?

Application procedures and all submissions regarding suspicious transaction reports are carried out electronically through the MASAK.Online system.

Can the institution's own internal reports be generated from the same data?

Yes. Report definitions are made without code, and the results are saved and repeatable: where each figure originated from in terms of cases and events remains traceable.

Can you find which rule generated a report from a year ago?

Yes. Which version of which rule triggered the event is recorded alongside the event.

Crypto wallet screening: querying address history
What is screened in crypto wallet screening?

Not a person, but a blockchain address. The address's direct match with sanctions records, its distance to a listed address, mixer exposure, cluster relationship, and the path of the funds are evaluated.

What does distance mean?

It is how many steps away the address is from a listed address. Funds coming directly and funds coming through three intermediaries are not the same, but the latter is not considered clean either.

Who decides which distance is acceptable?

The institution. Risk appetite is written as a rule, and what the threshold will generate is measured against historical transfer traffic before going live.

Does a risky address automatically make the customer risky?

It does not. The address evaluation enters the customer risk score; the customer's own profile also affects the threshold with which the address is evaluated.

How is the source of funds documented in a crypto transfer?

Address history is part of the answer, not the whole. Declarations and supporting documentation are still required; all three are evaluated together.

Is mixer usage a violation on its own?

It is not a ground for a decision on its own, but having passed through a service designed to obscure the origin of funds is a strong signal and can suspend the transaction depending on the institution's threshold.

How is the result recorded?

A match opens a case; the address, matching record, distance, fund path, and the reviewer's justification reside together, and the decision is written to an immutable audit trail.

Does screening data leave the institution?

It does not in an on-premise deployment; evaluations and records remain within the institution's own infrastructure.

Merchant onboarding: knowing the business and the person behind it
How does merchant onboarding differ from individual customer onboarding?

The risk is concentrated not in the business itself, but in the activities it performs and the real person behind it. The ownership structure is mapped, and the line of business is evaluated separately.

How is the ultimate beneficial owner (UBO) determined?

The ownership structure is mapped layer by layer down to the natural person. Every natural person in the chain undergoes sanctions and PEP screening.

What happens if the ownership structure changes later?

Changes can invalidate the onboarding decision. This is why the structure is not mapped just once, but is continuously monitored.

Why is the line of business so important?

The declared line of business and the products actually sold can diverge. Registering under an approved category and selling in another is a well-known industry challenge.

Why does the pre-order model carry a distinct risk?

When the time between collection and delivery is long, if the business goes bankrupt, the chargebacks for undelivered orders fall on the payment institution.

Is the return of a rejected application detected?

Yes. Applications connecting with the same device, IP, email pattern, or identity credentials become visible through relationship networks.

What is monitored post-onboarding?

Deviations in transaction volume from what was declared, rising chargeback rates, and changes in product categories. These deviations alter the risk classification.

How is the onboarding decision documented?

Obtained documents, the mapped ownership chain, performed screenings, the resulting score, and the approver are recorded. Due to segregation of duties, the reviewer and the approver may not be the same person.

Employee screening: internal controls and periodic renewal
Is employee screening a separate product?

No. It is the application of the same customer screening infrastructure to a different subject. Sanctions records, internal lists, and adverse media entities reside in the same place.

Which lists are screened against?

Sanctions lists, PEP and associate records, adverse media, and the organization's own watchlists. Organizations can add their own lists via official source definitions, feed streams, or document uploads.

How is the risk of false positives reduced?

Name similarity alone is not a sufficient basis for a decision. Aliases and transliterations, date of birth, ID and passport numbers, nationality and city details, and photo confirmation are evaluated together; the record's effective date is also checked.

Is there a difference between candidate screening and employee screening?

The screening is the same, but the legal basis and retention periods differ. Candidate data is processed for the duration of the recruitment process, while employee data is processed for the duration of the employment relationship and as prescribed by legislation.

Is screening repeated?

Yes. Re-screening is performed as lists change, and any new match generates a new alert. A person who clears screening today might match a decision published later.

How up to date are the lists?

Three methods work in tandem: official source pages are read at defined intervals, adverse media feeds are regularly polled, and regulatory bulletins are uploaded and converted into structured records. Every record is stored with its source link.

Is access to employee data logged?

Yes. Access is restricted by authorization, and who accessed employee data and when is written to the immutable audit trail.

Does data leave the organization?

Not with an on-premise deployment. All screening and records remain entirely within the organization's own infrastructure.