Open source intelligence
Open source intelligence (OSINT) systematically screens public publications to turn them into risk indicators. TruvaLI continuously monitors your defined news sources, flagging individuals and entities mentioned in adverse contexts without waiting for official lists.
The cost of waiting for official lists
When an investigation begins into an individual, this information usually hits the press long before they appear on official sanctions lists. An institution that only monitors lists learns of the risk months after the event occurs. In that window, accounts are opened, transactions are processed, and the institution carries risk without realizing it.
OSINT closes this gap. The goal is not to replace lists, but to bridge the time lag until they are updated.
Sources are defined by the institution
You define which sources TruvaLI monitors:
- Local and national media.
- Industry newsletters and regulatory announcements.
- RSS feeds and blogs.
- Custom sources tracked by the institution.
These sources are screened 24/7. The source list can be expanded based on the institution's risk profile: for example, it is possible to monitor only the local press of the provinces where you operate.
Resolving context
A name appearing in the news is not a risk on its own. The deciding factor is the context in which it appears. TruvaLI analyzes sentence meaning to distinguish contexts such as:
- Illegal betting operations, gambling, and casino connections.
- Qualified fraud and organized crime allegations.
- Suspected felony offenses.
- Regulatory sanctions and administrative fine news.
To prevent confusing your customer with news about someone else with the same name, matching is evaluated alongside other identity data in your possession.
How findings are utilized
A profile mentioned in an adverse context is flagged as high risk or PEP in your database. This flag is not a passive note:
- If they are an existing customer, their risk score is recalculated and an alert is generated.
- If it is a new application, additional verification or a video call can be triggered in the onboarding flow.
- Different thresholds can be applied to this profile in Transaction Monitoring scenarios.
Every finding is stored with the source and date of the underlying news article: the compliance officer sees the decision with its justification and can present this during audits.
Regulatory updates are also monitored
The same capability works on the regulatory side. SPK, MASAK, and BDDK announcements, as well as the Official Gazette, are tracked: when a new regulation is published, the system flags it and generates recommendations for rules and policies that might be affected.
What it delivers to the institution
- The ability to see risks before they hit official lists.
- Source selection remains entirely under the institution's control.
- Every finding is recorded with its source, ready to be shown during audits.
- Screening runs on-premise: customer names are never sent to an external service.
Common questions
- Is OSINT different from adverse media screening?
- They are closely related. Adverse media screening typically runs on content compiled by a pre-packaged data source. In OSINT, the institution defines the sources itself: publications not included in pre-packaged sets, such as local press and industry newsletters, can also be monitored.
- Is there a risk of confusion with another person of the same name?
- Matching is not based solely on name: it is evaluated alongside other identity data in your possession, and results are presented with a score. Furthermore, because every finding is linked to the source news article, the compliance officer can verify the decision.
- Does a news finding automatically block transactions?
- The institution can block them if desired, but the default behavior is to flag the profile as high risk and generate an alert for review. The final decision depends on the scenario written by the institution.