VIRTICUSDiscuss your situation
Practitioners for regulated firms

Rules, models, and automation that hold up when challenged.

We have built fraud rules, credit models, marketing analytics, and automation inside banks, payment firms, and lenders, and we build them for yours. More fraud caught with fewer good customers blocked; lending that prices risk properly; marketing spend that shows what it returned; routine work taken off your teams.

Fixed fee and timetable agreed before we start, after a twenty-minute call. Practitioners from banks, payment firms, lenders, and government.

Results first

Rules tuned to catch what they should and leave good customers alone; models that price the risk.

Named owners

Somebody is named on every rule and workflow, with a review step and a route to escalate.

The working kept

Run it again on the same inputs and you get the same answer, and the record to show it.

Example record

One decision, reviewed

Illustration

Decision rationale

Documented and mapped to the obligation

Human oversight

Owner named; escalation route defined

Monitoring

Gap flagged; drift check incomplete

Record complete87%

Every decision is scored the same way: a documented chain from input to decision to the person who owns it, reproducible on demand.

Where the standard comes from

01·SOURCE

All four domains

Rule-writing depth across APP scams, AML transaction monitoring, card fraud, and application/mule fraud: the full financial-crime surface.

02·SOURCE

Built inside banks

Detection rules written and tuned inside UK banks and payment firms, by practitioners who owned them and answered for them.

03·SOURCE

Mapped to UK obligations

Every rule tied to what it implements: PSR APP reimbursement, the MLRs, FCA SYSC financial-crime, and Consumer Duty.

04·SOURCE

Reproducible

The same inputs produce the same documented, traceable verdict, so the record can be re-run in front of whoever asks for it.

What we build

Fewer losses, better decisions, less manual work.

We build fraud rules, credit models, marketing analytics, and automation for the sectors where a wrong decision is expensive: banking, payments, lending, and the wider financial services around them. We have done this work inside banks, and we build it the same way for you: every rule and model documented, tested, and reproducible, so the result still holds when a regulator or a board asks how it was reached. Built to the UK regime.

Fraud & AML

Live

Fraud & AML Rules

Catch more fraud, block fewer good customers, and show why each rule is set where it is. We design, tune, and assure detection rules for FCA-regulated firms across APP scams, transaction monitoring, card and application/mule fraud, with coverage gaps flagged against recognised UK fraud typologies. You get rules that work, and the record to show it.

Rule-by-rule scorecardTypology coverage gapsEvidence pack

Workflows & agents

Live

AI & Automation

Automation that takes work off your team and still stands up to an audit. We build AI, agent, and automation workflows for banks, payment firms, and financial services. Each one names an owner, routes escalation to a person, gives the same answer on the same inputs, and keeps a record built to the standard an auditor asks for, under FCA and PRA expectations and UK GDPR.

Audit-ready recordOwnership & escalationUnited Kingdom

Credit Risk

Live

Credit Risk

Lending decisions that price risk properly, from models a supervisor can read. Application and behavioural scorecards, affordability, IFRS 9 expected credit loss, and impairment forecasting for UK banks and lenders. A scorecard answers whether the customer will repay; affordability answers whether they can without harm, and CONC 5.2A asks both. The model is the easy half; what gets examined is the development record behind it, and the firm owns all of it.

Scorecards & affordabilityIFRS 9 ECLOwned by the firm

Marketing Analytics

Live

Marketing Analytics

Marketing spend that can show what it returned. Customer segmentation, value, retention, look-alike, and campaign measurement. In a regulated firm a segment decides who is offered credit, an account, or a price, so it has to be re-derivable, tested for proxies of protected characteristics, and shown to be fair under Consumer Duty. Every campaign is read against a group that did not receive it.

Segmentation & valueConsumer DutyCampaign measurement

Governance & compliance

Live

AI Governance & Compliance

Own every AI and automated decision: clear accountability, active oversight, and a reproducible record, for when a regulator, board, or customer asks who owned a decision and how it was made. The same standard, applied to the governance layer.

Accountability & ownershipTraceable decisionsReview & oversight

Security & resilience

Live

Cybersecurity & Operational Resilience

The controls that move money and keep services running. We show which controls exist, who owns them, that they have been tested, and which obligation each one meets.

Control assuranceResilience mappingReproducible

Three points where fraud rules are tested

When fraud rules have to defend themselves

Each now carries a direct financial cost, and each turns on whether the rule was documented, tested, and defensible.

Moment 01

Before a reimbursement claim lands

Since mandatory APP-fraud reimbursement, a weak or undocumented detection rule is no longer only a control gap. It is a cost, carried on every claim.

We score each fraud and AML rule against a fixed scorecard and find the coverage gaps across recognised UK fraud typologies, before a claim finds them for you.

Pre-review exposure

Data lineageAt risk
Model oversightAt risk
Control evidencePartial
2 of 3 exposure areas unresolved before review

Moment 02

When the rule is challenged

A regulator, the Financial Ombudsman, or a court can demand evidence that a fraud rule was adequate, tested, owned, and mapped to the regulation it implements.

We establish whether each rule has documented rationale, monitoring, and change control, and where the record is missing.

Evidence chain

System decision log

Available

Override record

Incomplete

Independent review

Not commissioned

Moment 03

When the board must demonstrate control

Control can only be shown if the rationale is documented, the rule is owned, and the output is reproducible: same inputs, identical traceable result.

We make that structure visible and ready to be challenged, with every assessment written down and repeatable, and leave your team with a pack a regulator can read.

Accountability trace

Business owner

Decision recorded

Governance owner

Review documented

Decision owner

Sign-off traceable

Business output

Holds up?

Governance

When a decision is challenged, can it be traced?

A customer, a regulator, or the Financial Ombudsman can ask for an explanation of any decision a rule or a model made. Good governance means each question has a clear answer before it is asked.

Named owners

Every decision has a named, accountable person behind it.

Traceable decisions

The path from data input to business outcome is reviewable.

Audit-ready

Records exist in a form regulators and auditors can use.

Illustration · decision challenged

Credit decision — declined (example)

Referred by compliance team · Tracing accountability chain

Governance questionAnswer
1

Accountable owner

Pending
2

Approval pathway

Pending
3

Data source

Pending
4

Decision rationale

Pending
5

Override record

Pending
Traceability score—

Tracing 0 of 5 governance controls…

How it works

How we build, in five steps

The same five steps for a fraud rule, a credit model, or an automation. Each one ends with something you can read and sign off, and the last one leaves your team owning the result.

01

Discovery

We scope the decision rather than the task: where the rule, model, or workflow decides something, the scrutiny it has to survive, and the regime that binds it. A fixed scope is agreed before any build starts.

Scope map

Where it decides something
Scrutiny it must survive
Regime that binds it
Scope agreed
02

Design

We design the decision path before we write it: inputs, the reasoning steps, the human-oversight checkpoint, and the record each run leaves. A reviewer can read it and sign it off.

Decision design

InputsNamed
Reasoning stepsWritten
Oversight checkpointPlaced
Record each runDefined
03

Build

We build in your environment, wired to one integration surface, with reproducible logging from the first line. Working software on your data, not a slide deck.

Build

Your environment
One integration surface
Logging from the first line
Running on your data
04

Deploy & test

We deploy behind a human-oversight checkpoint and test against real cases. The same inputs give the same answer every time, and a person can override.

Deploy & test

Same inputs, same answerTested
Real casesPassed
Human overrideAvailable
MonitoringFlagged
05

Assure & hand over

We leave you the decision and audit log, a plain-language control write-up, and a working session with the people who will run it, so your team owns it and can change it without us.

What you receive

Your team
Auditor
Regulator
Plain language · Your team owns it

Relevant experience

Experience where the decision had to hold up

Illustrative examples of work involving fraud rules, customer calculations, models, and automated decisions under scrutiny.

Where do today’s fraud rules stand?

Run the free fraud-rule check →

What we see in practice

Where automated decisions go wrong

See all patterns →

Get in touch

Find out what today’s fraud rules are missing

Start with the free fraud-rule check: a scorecard across your rules and a check on a single rule, with no data required. Or talk to us first.