VIRTICUSDiscuss your situation
Independent specialist advisory

High-stakesdecisionsyoucandefend.

Virticus helps banks, payment firms and other regulated businesses design, test and evidence fraud controls, AI systems and automated decisions. Our work gives decision owners a clear record of what happened, why it happened and who was accountable.

Twenty years across banks, financial services, government and international advisory.

Traceable by design

Every decision keeps its working: what went in, how it was reached, and who owned it.

Human oversight

Somebody is named on every workflow, with a review step and a route to escalate it.

Audit-ready evidence

Run it again on the same inputs and you get the same answer, with the evidence to show it.

Live Assessment

AI & Automation Defensibility

Independent

Decision rationale

Documented and mapped to obligation

Human oversight

Owner named — escalation path defined

Model & data drift

Gap flagged — monitoring incomplete

Workflow defensibility87%

Every workflow is scored the same way — a documented chain from input to decision to accountable owner, reproducible on demand.

Proof · the hardest version, already built

01·PROOF

All four domains

Rule-writing depth across APP scams, AML transaction monitoring, card fraud, and application/mule fraud — the full financial-crime surface.

02·PROOF

Built inside banks

Detection rules written and tuned at scale in live UK banking and payment environments, under regulatory scrutiny, in production.

03·PROOF

Mapped to UK obligations

Every rule tied to what it implements — PSR APP reimbursement, the MLRs, FCA SYSC financial-crime, and Consumer Duty.

04·PROOF

Reproducible by design

The same inputs produce the same documented, traceable verdict — evidence a regulator, the Financial Ombudsman, or a court will accept.

What we build · legal · health · financial

Defensible AI and automation, built to survive audit.

We build AI, agents, and automation for the sectors where a wrong decision is expensive — banking, payments and financial services — to a standard that holds up under scrutiny. Every build runs on an engine we made ourselves for traceable, reproducible, defensible decisions. The proof it works: a court-defensible fraud and AML engine, already built for FCA-regulated firms. Compliant by design across the UK — clients come from anywhere, the standard doesn’t move.

AI & Automation · Flagship

Live

Defensible AI & Automation

We build AI, agent and automation workflows for banks, payment firms and financial services. Each one names an owner, routes escalation to a person, and leaves the record an auditor or a court will accept — built to the UK regime: FCA and PRA expectations, and UK GDPR.

Audit-ready by designOwnership & escalationUnited Kingdom

Financial Crime · Proven flagship

Live

Fraud & AML Rule Defensibility

The proof of the standard: a court-defensible fraud and AML rule engine, built for FCA-regulated firms. Design, tune, and assure detection rules — documented, tested, monitored, owned, and mapped to the regulation each implements, across APP scams, transaction monitoring, card, and application/mule fraud.

Rule-by-rule scorecardTypology coverage gapsRegulator-ready pack

Models & Controls

Live

Models & Controls

Two kinds of work, and they are not the same. A model produces an estimate that did not exist — a score, a forecast, a probability — and is judged on how it was fitted. A control decides or checks something and is judged on whether it is documented, owned, tested and traceable to its obligation. Most control estates need far fewer models than they are sold. For UK banking and financial services firms, handed over with the record a supervisor or an internal auditor can read cold.

Scorecards & affordabilityControl design & testingOwned by the firm

Regulatory Reporting

Live

Regulatory Reporting

IFRS 9 expected credit loss, the annual financial crime return, the APP scams performance data the PSR publishes and ranks, and the periodic returns that go out whether or not anything happened. Built as controls rather than spreadsheets: reconciled to source, reproducible months later, and keeping “not recorded” distinguishable from “recorded as none”.

IFRS 9 ECLLineage to sourceReproducible returns

Governance & Compliance

Live

AI Governance & Compliance

Own every AI and automated decision: clear accountability, active oversight, and a reproducible record — for when a regulator, board, or customer asks who owned a decision and how it was made. The same defensibility standard, applied to the governance layer.

Accountability & ownershipTraceable decisionsReview & oversight

Security & Resilience

Live

Cybersecurity & Operational Resilience

The controls that move money and keep services running — each one documented, owned, tested, and mapped to the regulation it implements.

Control assuranceResilience mappingReproducible by design

Three points where fraud rules are tested

When fraud rules have to defend themselves

Each now carries a direct financial cost — and each turns on whether the rule was documented, tested, and defensible.

Moment 01

Before a reimbursement claim lands

Since mandatory APP-fraud reimbursement, a weak or undocumented detection rule is no longer only a control gap. It is a cost, carried on every claim.

We diagnose the fraud and AML rules against a defensibility scorecard and surface coverage gaps across recognised UK fraud typologies, before they are tested.

Pre-review exposure

Data lineageAt risk
Model oversightAt risk
Control evidencePartial
2 of 3 exposure areas unresolved before review

Moment 02

When the rule is challenged

The FCA, the Financial Ombudsman, or a court can demand proof that a fraud rule was adequate, tested, owned, and mapped to the regulation it implements.

We establish whether each rule has documented rationale, monitoring and change control, and where the evidence is missing.

Evidence chain

System decision log

Available

Override record

Incomplete

Expert witness analysis

Not commissioned

Moment 03

When the board must demonstrate control

Defensibility only holds if the rationale is documented, the rule is owned, and the output is reproducible: same inputs, identical traceable result.

We make that structure visible and ready to be challenged, with every assessment written down and repeatable, and hand over a pack a regulator can read.

Accountability trace

Business owner

Decision recorded

Governance owner

Review documented

Decision owner

Sign-off traceable

Business output

Defensible?

What we do

Prove the controls would stand up when they are challenged.

Pipeline Resolution24%

Ingress

Lineage

Model

Decision

Review

Data stream

Source integrity and lineage confirmed

Control lane

Exception rules and overrides inspected

Evidence lane

Decision record prepared for challenge

Decision Gate

Input completePending
Controls verifiedPending
Escalation mappedPending
Release defensiblePending

Review finding

The flow only clears when lineage, control evidence, and accountable release conditions align.

The illustration reads as a resolution sequence: signals enter, controls are tested, evidence accumulates, and the decision gate clears only when the chain is defensible.

Governance

When a decision is challenged, can it be traced?

Customers, regulators, and the Financial Ombudsman can demand an explanation for any decision a fraud or AML rule made. Good governance means each question has a clear answer before it is asked.

Named owners

Every decision point has a documented, accountable person.

Traceable decisions

The path from data input to business outcome is reviewable.

Evidence-ready

Records exist in a form regulators and auditors can use.

Decision challenged

Credit decision #REF-4471 — Declined

Referred by compliance team · Tracing accountability chain

Governance questionAnswer
1

Accountable owner

Pending
2

Approval pathway

Pending
3

Data source

Pending
4

Decision rationale

Pending
5

Override record

Pending
Defensibility score

Tracing 0 of 5 governance controls…

How it works

A three-step operating sequence

Three steps. Each replaces uncertainty with a clear view of where the exposure lies and what to do about it.

01

Situation framing

We identify the system, the decision path, the accountable audience, and the timing pressure.

Scope map

System & decision path
Accountable audience
Timing & pressure
Scope confirmed
02

Independent examination

Evidence, system behaviour, governance controls, and decision logic are reviewed without ownership conflict.

Signal isolation

Data integrityVerified
Control logicFlagged
Decision trailTraced
Ownership conflictClear
03

Actionable reporting

Findings are presented in plain language, with enough technical depth to satisfy regulators, legal advisers, or auditors.

Decision brief

Management
Regulator
Legal
Plain language · Technical depth preserved

Relevant experience

Experience where the decision had to hold up

Selected examples of work involving fraud rules, customer calculations, models and automated decisions under scrutiny.

How well would today’s fraud rules hold up?

Run the free defensibility check →

What we see in practice

Risk patterns from real situations

See all patterns →

Get in touch

See how defensible today’s fraud rules are

Start with the free defensibility check — an estate scorecard and a single-rule mini-check, no data required. Or book a confidential briefing.