Platform
Solutions
Resources
Company
Resources
Platform

Alerts & case management

Case Management is the process of turning generated alerts into reviewable, explainable, and auditable records. In TruvaLI, each alert becomes a structured case with an owner, timeline, evidence, and decision rationale.

Difference Between an Alert and a Case

An alert is a technical output indicating that a rule has been triggered. A case, on the other hand, is a work record created to investigate that alert, with an assigned owner and a defined timeline.

This distinction is important: regulators do not only ask how many alerts were generated, but how those alerts were reviewed and what decisions were based on.

In TruvaLI, related alerts can be grouped into a single case. Five separate alerts associated with the same customer do not necessarily create five separate investigation workloads.

What Does a Case Contain?

  • The rule that generated the alert and the data that triggered it.
  • The customer's profile, risk score, and previous cases.
  • Screening matches and relationship network view.
  • AI-powered pre-analysis and suggested action.
  • Analyst comments, supporting evidence, and final decision.

The analyst does not need to move between separate screens to collect information; everything required for the investigation is available within the case.

Investigation Timeline Tracking

Suspicious activity investigations may need to be completed within defined timeframes.

TruvaLI tracks the age of cases, flags those approaching their deadlines, and can escalate them to management when required. The queue can also be prioritized by risk score so that limited investigation capacity is focused on the highest-risk cases.

Evidence and Rationale Requirements

A written rationale can be required before a case is closed.

Supporting documents can also be made mandatory when necessary, such as a board resolution, invoice, or source-of-funds document.

Team members can be mentioned with @ in comments, and files can be attached.

This ensures that the answer to the audit question, "Why was this decision made?" remains recorded within the case itself.

Maker-Checker

When a compliance analyst closes a case, the decision does not immediately become effective. It remains pending until an authorized checker from the predefined approval pool approves it.

Once approval is received, a callback can be sent to the institution's main system.

The same approval flow can also be applied to rule publishing.

Bulk Actions and Exceptions

Multiple alerts caused by the same reason can be closed in a single action.

At the same time, a compliance officer can manually approve a rejected transaction by providing a rationale. This exception is also recorded in the audit trail.

What It Provides to the Institution

  • Early visibility into potential investigation deadline breaches.
  • Every decision stored together with its rationale and supporting evidence.
  • Critical decisions subject to approval before becoming effective.
  • Reduced investigation workload for repetitive alerts.

Common questions

What is the difference between an alert and a case?
An alert is a technical output showing that a rule has been triggered. A case is a work record created to investigate that alert, with an assigned owner, timeline, and decision rationale. From an audit perspective, the key question is not only how many alerts were generated, but how cases were reviewed and resolved.
How does the Maker-Checker workflow work?
When an analyst (maker) closes a case or publishes a rule, the action is submitted to a predefined approval pool for review by a checker. The decision does not become effective until approval is received. Once approved, a callback can be sent to the institution's main system.
How are cases approaching their deadlines tracked?
The age of each case is monitored, cases approaching their deadlines are flagged, and they can be escalated to management when required. Since the queue can be prioritized by risk score, limited investigation capacity can be focused on the highest-risk cases.
Do multiple alerts caused by the same reason need to be closed individually?
No. Alerts arising from the same reason can be closed in bulk, and a common rationale can be applied to all of them. This helps prevent repetitive situations from consuming unnecessary investigation capacity.

Related