VIRTICUSDiscuss your situation

Fraud & AML Rules · Flagship

Fraud and AML rules that catch more fraud and stop fewer good customers

Since the PSR’s mandatory APP-fraud reimbursement came into force, UK firms bear the cost of the fraud they fail to stop, and every genuine customer a rule turns away is a cost as well. We work both ends: designing and tuning the rules so they catch more and block less, then reviewing them rule by rule, with a regulator-ready record of exactly where the estate stands across all four financial-crime domains. When the FCA asks whether the rules are adequate and defensible, the answer is already written down.

Twenty years across banks, financial services, government and international advisory.

Rule Scorecard

Scoring

Documented rationale

Why the rule exists

Pending

Backtested

Validated pre-deploy

Pending

Performance monitored

FPR / hit-rate tracked

Pending

Named owner

Accountable individual

Pending

Mapped to obligation

PSR / SYSC / MLR 2017

Pending

A rule passes only when every dimension is evidenced. Missing evidence is reported as “cannot attest” — never as a pass.

The shift

Fraud is now a P&L line

Mandatory APP reimbursement turned fraud losses into a direct cost the business carries — and a question the board, the FCA, and the Financial Ombudsman now ask about the controls.

The gap

Nobody owns the full picture

Compliance sees the law, the fraud team sees the rules, data sees the gaps — and no single artefact connects the three. When a rule is challenged, there is no single place to show why it exists and that it works.

The standard

Same rule, same verdict

Score the same rule twice and the second verdict matches the first, with the same reasoning written down both times. A regulator, the Financial Ombudsman or a court is not looking for a good answer. It is looking for the same answer, and the working behind it.

How a rule is judged

Six dimensions decide whether a rule is defensible

We score every rule the way a reviewer would. A rule passes only when each dimension is positively evidenced. Where evidence is missing, we report it as “cannot attest” — never as a pass. Missing evidence is not the same as a safe rule.

01

Documented rationale

Is there a written, approved reason this rule exists: the typology it targets, and the basis for its thresholds?

02

Tested

Was the rule back-tested against confirmed fraud before deployment, and is that evidence retained?

03

Monitored

Is performance tracked closely enough to show the rule still works? Hit rate, false-positive rate, alert volume.

04

Owned

Is there a named, accountable individual responsible for the rule and its outcomes?

05

Change-controlled

Are changes to the rule reviewed, impact-assessed, and recorded?

06

Mapped to obligation

Does the rule trace to the regulation it implements: PSR reimbursement, the MLRs, SYSC financial-crime expectations?

Coverage across the whole estate

All four financial-crime domains, one connected picture

A detection estate spans every domain at once. We check the rules against recognised UK typologies across every domain, so the verdict covers the whole detection estate — not just one corner of it.

APP scams

Authorised push payment fraud: purchase, investment, romance, impersonation, CEO and invoice, advance-fee, and mule-receiving patterns.

AML transaction monitoring

Placement, layering, structuring, rapid movement, and the typologies behind suspicious-activity detection.

Card fraud

CNP, account takeover, testing, and the card-present and card-not-present vectors firms must cover.

Application & mule fraud

Synthetic and stolen-identity applications, first-party fraud, and money-mule account behaviour.

What the engagement delivers

A diagnosis to act on, and a record that stands up

We diagnose and document. The diagnosis names every gap and the direction of the fix; the rule logic and thresholds that close those gaps are a separate build step. We show exactly where the estate stands, and hand over a regulator-ready artefact to prove it.

Regulator-ready means the pack is built to be clear, dated, and traceable, so it can be put in front of a reviewer without further work. Whether any finding is accepted remains a matter for the FCA, the Financial Ombudsman, or a court.

Rule scorecard

Every rule scored on six evidence dimensions, with one clear verdict per rule, from fully evidenced to cannot attest, and the gaps in between named.

Coverage map

Every rule checked against 43 recognised UK fraud typologies across all four domains, so what is not being caught is named, one by one.

Estimated false-positive reduction

Where aggregate alert figures are shared (not transaction data), an estimate of the false positives and analyst hours a tuning pass could remove.

Regulator-ready documentation pack

A frozen, dated, traceable record mapping each rule to the obligation it implements. The artefact to reach for the moment someone says prove it.

How engagements are priced

Start small, on a fixed price, with nothing to procure

Most firms start with the snapshot. It is deliberately scoped to be approvable by the person who feels the problem — no data, no system access, and a fixed fee that does not need a procurement cycle to sign off.

Start here

Rule Review Snapshot

£2,500+ VAT, fixed

  • Five rules, scored across the six dimensions
  • One week, from brief to written verdict
  • Named gaps and the exposure they create
  • No production data, no system access

Then

Full estate diagnosis

Scoped on the rule count

  • Every rule scored, rule by rule
  • Coverage mapped across recognised UK typologies
  • Estimated false-positive reduction
  • The full documentation pack

Ongoing

Retained assurance

Monthly or quarterly

  • Rule review on a set cycle
  • Typology and obligation updates
  • Evidence and change-control refresh
  • Support when a rule is challenged

The returns that report it

The same alerts are counted twice, and the two counts should agree

The annual financial crime return under SUP 16.23 and the APP scams performance data the PSR publishes are built from the numbers your detection rules produce. We build those returns reconciled to the monitoring and case systems, reproducible months later, and with “not recorded” kept apart from “recorded as none”. How the returns are built.

No production data

A review that runs in an afternoon, not a six-month security project

The diagnosis works from structured descriptions of the rules and, optionally, aggregate performance counts — alerts, hits, false positives. No transaction data, no customer data, no live system access. That stays below the procurement and DPIA wall, so value lands fast. Any estimate is computed on the figures provided and labelled as such — it is an advisory diagnostic, not an independent audit of a live system.

Start with the free check

See where one rule stands in 60 seconds — no data, no sign-up

The free check returns a headline verdict on rule-writing practice. When the full rule-by-rule diagnosis and documentation pack are needed, we run them together. Every enquiry is treated in confidence.