VIRTICUSRequest Assessment
Our own engine for defensible decisions

DefensibleAIandautomationforregulated,high-stakeswork.

A decision you cannot defend is a decision you cannot use. Somebody has to be able to say what it was based on, who owned it, and why it went that way. We build for banking, payments and financial services, on an engine we built ourselves, so the same inputs reach the same answer every time and the working is there to be read.

Twenty years across banks, financial services, government and international advisory.

Traceable by design

Every decision keeps its working: what went in, how it was reached, and who owned it.

Human oversight

Somebody is named on every workflow, with a review step and a route to escalate it.

Audit-ready evidence

Run it again on the same inputs and you get the same answer, with the evidence to show it.

Live Assessment

AI & Automation Defensibility

Independent

Decision rationale

Documented and mapped to obligation

Human oversight

Owner named — escalation path defined

Model & data drift

Gap flagged — monitoring incomplete

Workflow defensibility87%

Every workflow is scored the same way — a documented chain from input to decision to accountable owner, reproducible on demand.

Proof · the hardest version, already built

01·PROOF

All four domains

Rule-writing depth across APP scams, AML transaction monitoring, card fraud, and application/mule fraud — the full financial-crime surface.

02·PROOF

Built inside banks

Detection rules written and tuned at scale in live UK banking and payment environments, under regulatory scrutiny, in production.

03·PROOF

Mapped to UK obligations

Every rule tied to what it implements — PSR APP reimbursement, the MLRs, FCA SYSC financial-crime, and Consumer Duty.

04·PROOF

Reproducible by design

The same inputs produce the same documented, traceable verdict — evidence a regulator, the Financial Ombudsman, or a court will accept.

What we build · legal · health · financial

Defensible AI and automation, built to survive audit.

We build AI, agents, and automation for the sectors where a wrong decision is expensive — banking, payments and financial services — to a standard that holds up under scrutiny. Every build runs on an engine we made ourselves for traceable, reproducible, defensible decisions. The proof it works: a court-defensible fraud and AML engine, already built for FCA-regulated firms. Compliant by design across the UK — clients come from anywhere, the standard doesn’t move.

AI & Automation · Flagship

Live

Defensible AI & Automation

Traceable, human-defensible AI, agent, and automation workflows for regulated and compliance-critical businesses — banking, payments and financial services — with clear ownership, review, escalation, and audit-ready evidence, built to the UK regime: FCA and PRA expectations, UK GDPR, and the record an auditor or a court will accept.

Audit-ready by designOwnership & escalationUnited Kingdom

Financial Crime · Proven flagship

Live

Fraud & AML Rule Defensibility

The proof of the standard: a court-defensible fraud and AML rule engine, built for FCA-regulated firms. Design, tune, and assure detection rules — documented, tested, monitored, owned, and mapped to the regulation each implements, across APP scams, transaction monitoring, card, and application/mule fraud.

Rule-by-rule scorecardTypology coverage gapsRegulator-ready pack

Models & Controls

Live

Models & Controls

Two kinds of work, and they are not the same. A model produces an estimate that did not exist — a score, a forecast, a probability — and is judged on how it was fitted. A control decides or checks something and is judged on whether it is documented, owned, tested and traceable to its obligation. Most control estates need far fewer models than they are sold. For UK banking and financial services firms, handed over with the record a supervisor or an internal auditor can read cold.

Scorecards & affordabilityControl design & testingOwned by the firm

Regulatory Reporting

Live

Regulatory Reporting

IFRS 9 expected credit loss, the annual financial crime return, the APP scams performance data the PSR publishes and ranks, and the periodic returns that go out whether or not anything happened. Built as controls rather than spreadsheets: reconciled to source, reproducible months later, and keeping “not recorded” distinguishable from “recorded as none”.

IFRS 9 ECLLineage to sourceReproducible returns

Governance & Compliance

Live

AI Governance & Compliance

Own every AI and automated decision: clear accountability, active oversight, and a reproducible record — for when a regulator, board, or customer asks who owned a decision and how it was made. The same defensibility standard, applied to the governance layer.

Accountability & ownershipTraceable decisionsReview & oversight

Security & Resilience

Live

Cybersecurity & Operational Resilience

Evidence-forward, repeatable assurance for the controls that move money and protect customers — the same defensibility approach, applied to cyber and operational-resilience controls: documented, owned, tested, and mapped to the regulation each implements.

Control assuranceResilience mappingReproducible by design

Three points where fraud rules are tested

When fraud rules have to defend themselves

Each now carries a direct financial cost — and each turns on whether the rule was documented, tested, and defensible.

Moment 01

Before a reimbursement claim lands

Since mandatory APP-fraud reimbursement, a weak or undocumented detection rule is no longer only a control gap. It is a cost, carried on every claim.

We diagnose the fraud and AML rules against a defensibility scorecard and surface coverage gaps across recognised UK fraud typologies, before they are tested.

Pre-review exposure

Data lineageAt risk
Model oversightAt risk
Control evidencePartial
2 of 3 exposure areas unresolved before review

Moment 02

When the rule is challenged

The FCA, the Financial Ombudsman, or a court can demand proof that a fraud rule was adequate, tested, owned, and mapped to the regulation it implements.

We establish whether each rule has documented rationale, monitoring and change control, and where the evidence is missing.

Evidence chain

System decision log

Available

Override record

Incomplete

Expert witness analysis

Not commissioned

Moment 03

When the board must demonstrate control

Defensibility only holds if the rationale is documented, the rule is owned, and the output is reproducible: same inputs, identical traceable result.

We make that structure visible and challenge-ready, with every assessment documented and repeatable, and hand over a regulator-ready pack.

Accountability trace

Business owner

Decision recorded

Governance owner

Review documented

Decision owner

Sign-off traceable

Business output

Defensible?

What we do

Prove the controls would stand up — traceable by design.

Pipeline Resolution24%

Ingress

Lineage

Model

Decision

Review

Data stream

Source integrity and lineage confirmed

Control lane

Exception rules and overrides inspected

Evidence lane

Decision record prepared for challenge

Decision Gate

Input completePending
Controls verifiedPending
Escalation mappedPending
Release defensiblePending

Review finding

The flow only clears when lineage, control evidence, and accountable release conditions align.

The illustration reads as a resolution sequence: signals enter, controls are tested, evidence accumulates, and the decision gate clears only when the chain is defensible.

Governance

When a decision is challenged, can it be traced?

Customers, regulators, and the Financial Ombudsman can demand an explanation for any decision a fraud or AML rule made. Good governance means each question has a clear answer before it is asked.

Named owners

Every decision point has a documented, accountable person.

Traceable decisions

The path from data input to business outcome is reviewable.

Evidence-ready

Records exist in a form regulators and auditors can use.

Decision challenged

Credit decision #REF-4471 — Declined

Referred by compliance team · Tracing accountability chain

Governance questionAnswer
1

Accountable owner

Pending
2

Approval pathway

Pending
3

Data source

Pending
4

Decision rationale

Pending
5

Override record

Pending
Defensibility score

Tracing 0 of 5 governance controls…

How it works

A three-step operating sequence

Three steps. Each replaces uncertainty with a clear view of where the exposure lies and what to do about it.

01

Situation framing

We identify the system, the decision path, the accountable audience, and the timing pressure.

Scope map

System & decision path
Accountable audience
Timing & pressure
Scope confirmed
02

Independent examination

Evidence, system behaviour, governance controls, and decision logic are reviewed without ownership conflict.

Signal isolation

Data integrityVerified
Control logicFlagged
Decision trailTraced
Ownership conflictClear
03

Actionable reporting

Findings are presented in plain language, with enough technical depth to satisfy regulators, legal advisers, or auditors.

Decision brief

Management
Regulator
Legal
Plain language · Technical depth preserved

Selected cases

Work where the rule had to hold up

A detection rule is only as strong as the evidence behind it. Whether it runs in a vendor engine or in-house logic, the same question applies — could it be shown adequate, owned, and defensible?

How well would today’s fraud rules hold up?

Run the free defensibility check →

What we see in practice

Risk patterns from real situations

See all patterns →

Get in touch

See how defensible today’s fraud rules are

Start with the free defensibility check — an estate scorecard and a single-rule mini-check, no data required. Or book a confidential briefing.