Platform
Solutions
Resources
Company
Resources
Platform

Fraud detection

Fraud detection is the process of identifying indicators that a transaction or account belongs to an attacker rather than the legitimate user before the transaction is completed. TruvaLI achieves this by evaluating device, behavior, network relationships, and transaction history within the same scenario.

How does it differ from compliance?

AML processes protect the institution from regulatory sanctions and inherently involve a retrospective reporting obligation. Fraud prevention, on the other hand, prevents immediate loss: it requires intervention before funds leave, before an account is compromised, or before a bonus is exploited. Both run on the same engine, but their time pressures differ.

TruvaLI handles both sides using the same scenario infrastructure; the compliance team and the fraud team do not have to learn separate systems.

What is analyzed?

Device and connection. Device fingerprinting, IP, geolocation consistency, browser characteristics, and their alignment with the user's history.

Behavior. Transaction times, amount distribution, recipient diversity, and sudden deviations in these patterns. A typical deviation is when an account that has operated with small amounts for a long time suddenly attempts a high-value transfer.

Network relationships. Accounts sharing the same IP, device, or phone number. Accounts that appear normal when viewed individually may indicate an organized scheme when analyzed together. For details, see network and relationship analysis.

Counterparty. Recipient history, blacklist status, and prior relationship established with the sender.

Common scenarios

  • Account takeover: Login from a new device, followed immediately by contact information changes and attempted fund withdrawals.
  • Bonus abuse and multi-accounting: Shared device, shared payment instrument, or groups of accounts feeding each other.
  • Payment fraud and chargebacks: Inconsistency between card usage patterns and customer history.
  • Money mule accounts: Numerous small incoming transactions in a short period, followed by a single large outgoing transfer.

Rules and AI together

Rule logic provides explainability: you can show the regulator why a decision was made. AI, on the other hand, surfaces new patterns that fall outside existing rules.

TruvaLI uses both together. When AI suggests a pattern, it is not deployed directly to production; instead, it is presented for human approval as a parameterized draft rule. This ensures that new threats are captured while keeping the rationale for every decision documented.

Action is taken instantly

Detection alone is not enough. TruvaLI can suspend transactions, request additional verification, or temporarily restrict accounts by triggering a callback to your core system from within a rule. Decisions are returned in milliseconds, ensuring the user experience remains seamless.

What it delivers to your institution

  • Intervention before losses occur.
  • Compliance and fraud scenarios on a single platform.
  • The rationale for every decision is explainable and auditable.
  • New scenarios can be tested against historical data before going live.

Common questions

What is the difference between rule-based and AI-based detection?
Rule-based detection looks at predefined conditions and makes decisions explainable. AI-based detection can capture undefined patterns but is difficult to justify. TruvaLI combines both: patterns discovered by AI are converted into rules that undergo human approval.
How is account takeover detected?
Usually through signals that precede fund withdrawals: login from an unrecognized device or IP, followed immediately by an email or phone number change, and transaction attempts at unusual hours. Because TruvaLI also monitors these non-financial events, it can catch the chain before any money moves.
Are fraud rules written separately from AML rules?
They are written in the same rule engine, but they can be separated into distinct rule sets and authorization groups. This allows the fraud team and the compliance team to use the same infrastructure without modifying each other's rules.

Related