Rules from past fraud
Generating rules from past cases means analyzing fraud incidents previously experienced by the institution and turning them into scenarios designed to detect similar patterns. TruvaLI identifies common patterns across historical cases and presents them as editable rule drafts.
Your Best Source: Your Own History
Ready-made scenario libraries are a good starting point, but they may not fully cover risks specific to your industry, product, and customer profile. Cases your institution has actually experienced contain exactly this type of information: attackers have already shown what works against your product and within your customer base.
The problem is that this knowledge often remains scattered across closed case records.
How Does It Work?
You provide your historical cases to the system. TruvaLI looks for recurring elements across those cases:
- Common time windows and transaction frequencies.
- Amount distributions and behavior designed to remain below thresholds.
- Device, IP, and channel overlaps.
- Counterparty relationships and direction of money flow.
- Non-financial events that occurred before the case.
The identified pattern is converted directly into a rule draft: which fields, which thresholds, and which time window should be used.
Work on the Draft
The generated rule is a recommendation and is not expected to be used in its raw form. It may be too narrow or too broad.
You can edit the draft, adjust thresholds according to your institution’s risk appetite, and test it against historical data using simulation.
The simulation shows not only whether the rule would have detected the original cases, but also which legitimate transactions it would have captured.
This step helps prevent recommendations from being applied blindly.
Prevent Your Rule Set from Becoming Outdated
Attack methods change. A rule written two years ago may either generate unnecessary alerts today or fail to trigger at all.
As the institution feeds new cases into the system, the rule set can remain more up to date.
Similarly, false positive rates generated by active rules can be monitored and threshold improvement recommendations can be provided.
Keep Institutional Knowledge Within the Organization
The value of an experienced compliance analyst often lies in knowing which patterns indicate which risks.
When that knowledge remains only with an individual, it may leave the institution when that person does.
Rules generated from historical cases help turn this experience into documented and operational knowledge within the system.
What It Provides to the Institution
- Concrete scenarios designed to help prevent the repetition of previously experienced fraud patterns.
- Coverage of sector-specific risks without relying solely on ready-made libraries.
- A rule set that can evolve over time.
- Transfer of institutional knowledge from individuals into the system.
Common questions
- Can generated rules be used directly?
- They should be used as drafts. They may be too narrow or too broad, so thresholds should be adjusted according to the institution’s risk appetite and tested through simulation before being put into use.
- How many historical cases are required?
- Patterns can be identified from a single case, but when similar cases are analyzed together, common elements can be separated more reliably and the resulting rule can be more accurate.
- How is this different from a ready-made rule library?
- A ready-made library covers general industry typologies. Rules generated from historical cases are based on attacks that have actually occurred within your own product and customer base. The two approaches are complementary rather than alternatives.