VIRTICUSDiscuss your situation

About Virticus

A decision that can’t be defended is a decision that can’t be used.

When an automated decision goes wrong in banking, payments or financial services, the cost lands on customers, the balance sheet, and standing with a regulator. Virticus builds the AI, automation, and detection systems that can be explained and defended when that decision is challenged — on an engine we built ourselves to make each one reproducible.

The standard runs from the fraud and AML rules that stop financial crime to the AI and automated decisions a business makes on its own behalf under regulatory scrutiny. The purpose is simple: every system documented, accountable, and defensible by design — never a black box no one can answer for.

Operating Profile

Independence

No stake in the system under review.

Focused

One narrow remit, handled end to end — nothing outside it.

Evidence-based

Findings anchored to what the system did, not what it claimed.

Confidential

Handled with business and legal sensitivity.

Advisory Positioning

Defensible AI & AutomationAI GovernanceCybersecurityFraud Rule DefensibilityAMLFinancial Crime

The Standard

Every output has to survive challenge

The common thread is not sector branding. It is exposure: systems operating where outputs matter, evidence matters, and explanations matter. It is the discipline the strictest fraud and AML environments demand — and what Virticus now brings to FCA-regulated firms that have no in-house model-risk function to lean on.

Sector 01

Financial Crime (Flagship)

Writing and tuning fraud and AML detection rules at scale across banking and payment environments — APP scams, transaction monitoring, card, and application/mule fraud. Rules had to be written at pace, perform under pressure, and be defended when challenged: documented rationale, tested thresholds, traceability, and decision control, not detection performance alone.

Sector 02

Banking & Financial Services

Interest calculation models, driver-based financial models, and Buy Now Pay Later balance logic where errors created financial and regulatory exposure. The risk was not only model failure, but misplaced confidence in outputs affecting customer balances, management decisions, and regulatory standing.

Sector 03

Government & Public Sector

Data systems supporting urgent central government decisions during the COVID-19 period, where information had to be reliable, explainable, and timely under exceptional pressure. Errors in underlying data directly affected public decisions and formal reporting.

Sector 04

Public Health

Analytical and operational tooling at a national public health body, where outputs supported policy-shaping evidence chains and reporting at population scale. The challenge was maintaining control and accountability while systems were used at pace under scrutiny.

Sector 05

Education

AI tools used to generate student feedback, support marking activity, and personalise learning pathways. The risk was consistency, fairness, and the difficulty of defending outputs that reached students without adequate review.

Sector 06

Accounting & Professional Services

AI automation in bookkeeping and submission preparation, where small classification errors or unsupported assumptions could flow through into financial and tax outputs. Validation controls were needed before outputs reached formal reporting stages.

Sector 07

Transactions

Transaction environments where data quality, consistency, and explainability were under commercial and investor scrutiny. Information supporting value and performance needed to withstand close external challenge during a sale process.

Experience

Where the standard comes from

Twenty years of practice inside the places that set it: the largest banks, financial services firms, government, and the international advisory firms brought in when something has to hold. The same problems seen from three sides — the institution that owns the decision, the function that has to evidence it, and the reviewer sent to take it apart.

What we have done

Experience

Two decades across banking, payments, financial services, government and international advisory. Detection rules, credit and affordability models, forecasting, regulatory reporting, and the control estates around them: built, reviewed, and defended when somebody came looking.

What we know

Expertise

Fraud and AML rule design. Model risk under SS1/23. Creditworthiness and affordability under CONC. Expected credit loss. Automated decisions under UK GDPR as it now stands. Every regime read from the source document, because the summaries are wrong often enough to matter.

What we can do

Capability

A small team, deliberately. Regulatory framing, model development and validation, data and systems architecture, and delivery — enough to carry a problem from diagnosis to something running, without passing it between firms and losing it at each handover.

Method

The same operating sequence, every time

Scope, examine, analyse, report. The brief may change, but the method is stable, and The engine applies the same sequence every time: understand the system, trace the evidence, and make the findings usable — and defensible.

01

Scope

System, context, accountable audience, and decision pressure.

02

Examine

Data, model, controls, outputs, and where the record is weak.

03

Analyse

Independent technical judgement against the evidence.

04

Report

Clear findings for owners, senior managers, legal advisers, or any formal inquiry.

How we work

The standard is set by what we refuse to do

We read the rule, not the summary

Every regime a deliverable rests on is read from the source document and written up with the date it was read. Summaries are wrong often enough to matter, and a design built on one is wrong in a way nobody notices until it is challenged.

We say when a thing cannot be concluded

Not determined is a finding, and it is the one most reports quietly convert into a pass. Where the evidence is missing we say the evidence is missing, name what would settle it, and leave the conclusion open.

Every figure traces back to where it came from

A number nobody can re-derive is a number nobody can defend. Anything we hand over can be followed to its source and reproduced months later by somebody who was not there.

We would rather hand back the smaller answer

The wider claim that cannot be evidenced is worth less than the narrow one that can. Work that overreaches gets found out at the worst moment, in front of the people it was meant to convince.

The firm keeps what we build

Models, code, and the record of how they were made. A client who cannot run and change their own system without us cannot evidence control of it, and we will not be a dependency inside a regulated decision.

Few engagements, long relationships

A small team is a deliberate constraint. It means the people who scoped the work are the people who do it, and it means we take on what we can do properly rather than what we could bill.

Get in touch

When fraud and AML rules have to be defended, start here

Virticus works with FCA-regulated firms that need to understand where their detection rules are exposed, improve coverage and control, or defend their rules when challenged. A short discussion is usually enough to determine what is needed.