Personal information protection system
A computerized system converts identifying information and monitors transactions to enhance detection and reporting of suspicious financial activities, addressing compliance challenges and improving financial institution efficiency and profitability.
Patent Information
- Application Number
- JP2025153102
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-03-17
- Filing Date
- 2025-09-16
- Publication Date
- 2026-01-21
AI Technical Summary
Existing financial institutions struggle to effectively detect and report suspicious financial activities, particularly money laundering and terrorist financing, due to the limitations of traditional behavior-based fraud detection methods and the reliance on human oversight, which is costly and prone to errors, failing to comply with regulations like the Bank Secrecy Act and USA PATRIOT Act.
A computerized system and method that converts identifying information into coded forms, monitors transactions, and uses intelligent alert systems to detect and report suspicious activities without disclosing personal information, integrating data mining and case management to improve compliance and detection efficiency.
Enhances the ability of financial institutions to identify and track illicit proceeds, reducing errors and resource wastage, improving compliance with regulatory requirements, and increasing profitability by effectively detecting and preventing financial crimes.
Smart Images

Figure 2026009908000001_ABST
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001]
[0001] This application claims the benefit of U.S. patent application Ser. No. 16 / 821,471, filed March 17, 2019, entitled "IDENTITY PROTECTION SYSTEM," U.S. patent application Ser. No. 16 / 791,972, filed February 14, 2020, entitled "CONSUMER PROTECTION SYSTEM," and U.S. patent application Ser. No. 16 / 791,993, filed February 14, 2020, entitled "ILLICIT PROCEEDS TRACKING SYSTEM," which in turn claims the benefit of U.S. provisional patent application Ser. No. 62 / 823,305, filed March 25, 2019, entitled "CONSUMER PROTECTION SYSTEM," the disclosures of which are expressly incorporated herein by reference in their entireties. [Technical Field]
[0002]
[0002] This disclosure relates generally to consumer protection systems and, more particularly, to protecting individuals, organizations, and financial institutions from many types of financial crimes. [Background technology]
[0003]
[0003] Criminals and fraudsters have used many schemes to steal money, financial instruments, and other valuables from individuals and organizations. Many methods have been proposed to prevent financial crime. Nevertheless, the damage caused by criminals and fraudsters continues, with billions of dollars being stolen each year as a result of financial crime. More effective solutions to prevent financial crime are needed.
[0004]
[0004] The U.S. Bank Secrecy Act was first established in 1970. Under the Bank Secrecy Act, financial institutions must report suspicious activity to the government. Until now, financial institutions have trained their front-line personnel (e.g., bank tellers) to observe and identify suspicious activity. However, most financial institutions have not been able to effectively comply with the Bank Secrecy Act. After the 9 / 11 tragedies, U.S. lawmakers believed that the 9 / 11 tragedies could have been prevented if financial institutions had effectively complied with the Bank Secrecy Act.
[0005] To further strengthen the Bank Secrecy Act, the U.S. Congress passed the USA PATRIOT Act, which established severe civil and / or criminal penalties for violations of the Bank Secrecy Act. Additionally, U.S. government agencies, such as the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), the Federal Reserve Banks (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Cooperative Association of Banks (NCUA), State Banking Departments, and the Bureau of Financial Institutions, strictly require financial institutions to comply with the Bank Secrecy Act, particularly their obligation to submit Suspicious Activity Reports (SARs) to FinCEN.
[0006]
[0006] Suspicious activity covers a very wide range: for example, money laundering, terrorist financing, fraud, embezzlement, identity theft, computer intrusion, private financial transactions, bribery, false statements, counterfeit securities, and mysterious disappearances are all classified as suspicious activity.
[0007]
[0007] Despite this, many financial institutions are unable to detect and report suspicious activity. In fact, many financial institutions use products that are effective at preventing fraud but ineffective at preventing money laundering or other financial crimes. Fraud can be detected based on changes in behavior, since fraudsters who have stolen a victim's personal information (or financial instruments) generally behave differently from the victim. Computer systems can detect instances of fraud when account activity differs from expected activity derived from past activity.
[0008] For example, US application (Publication No. 2003 / 0177087) specifies that high risk variables can include, for example, changes in the normal behavior of an account that are indicated when a transaction deviates from its profile. According to this publication, Beta, Delta, and Theta models are used to detect transactions that deviate from a customer's profile.
[0009] However, money laundering and some other financial crimes can be committed without changes in behavior. As a result, traditional approaches to detecting fraud based on changes in behavior fail to detect some basic money laundering activities or other financial crimes. In the field of money laundering, higher-risk customers may not be suspicious. For example, money service businesses (MSBs), pawnbrokers, ATM vendors, flight attendants, etc. are typically classified by banks as higher-risk customers in their anti-money laundering programs. However, this does not mean that these higher-risk customers will engage in money laundering activities. Although a higher risk is associated with these customers, there may be no problems with these customers.
[0010]
[0010] Some businesses are very difficult to monitor. For example, an MSB handles a large number of transactions every day, and traditional approaches may not be able to detect a single money laundering transaction mixed in with these many transactions.
[0011]
[0011] The challenges noted for complying with the USA PATRIOT Act and the Bank Secrecy Act (BSA) are just a few examples to illustrate the importance of identifying suspicious activity. Identifying suspicious activity can also be used to comply with other laws, such as the Fair and Accurate Credit Transactions Act (FACT Act), the Unlawful Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations set forth by the Office of Foreign Assets Control (OFAC), and other laws and regulations.
[0012]
[0012] Regulatory compliance is traditionally implemented through policies and procedures that require human workers to take some specific action in response to certain conditions. For example, to comply with bank secrecy laws, banks train their branch tellers to observe and report anything that they find suspicious.
[0013]
[0013] This traditional approach is ineffective in the modern era because customers no longer need to appear in person at a bank branch. For example, customers can conduct remote electronic transactions (e.g., via the Internet), and there are numerous financial products available to customers (e.g., checks, credit cards, debit cards, etc.). Furthermore, criminals are sophisticated and know how to avoid the attention of tellers. As a result, relying on tellers to detect suspicious activity to comply with bank secrecy laws is insufficient.
[0014]
[0014] Furthermore, the cost of this human-based approach is very high. Human workers must undergo intensive training on a regular basis to ensure they comply with different laws and regulations and know exactly how to handle each different situation. However, human workers are prone to error. In fact, due to human oversight, many financial institutions have received severe penalties from government agencies for failing to comply with different laws and regulations.
[0015]
[0015] It is desirable to improve monitoring systems to improve detection of different types of suspicious activity and to help businesses comply with different types of laws and regulations. The methods, features, embodiments, computer systems, networks, software, hardware, mechanisms, and other components used to detect suspicious activity may also be used in other applications or by other organizations for purposes other than detecting suspicious activity.
[0016]
[0016] U.S. Patent Nos. 9,866,386, 9,288,197, 8,870,068, 8,500,011, 8,191,774, and 7,533,808 disclose computerized methods and apparatus for identifying objects of common interest among multiple parties without disclosing the true personal information of the objects. However, products based on these patents failed to attract user interest. The primary reason for this is that compliance professionals are extremely busy and do not have time to log into websites to discover more information about individuals with suspicious activity. This application discloses computerized systems and networks that empower financial institutions to function more efficiently and without disclosing confidential information about their customers. Although an illicit revenue tracking system is used as an example in this disclosure, the computerized systems and networks can be used for many other applications. Summary of the Invention
[0017]
[0017] The present disclosure includes several embodiments that can be combined together to form various computer systems and methods.
[0018] First, a computer system and method protect individuals and organizations from financial crimes by receiving a first subject's identifying information from a first computer system, converting the first subject's identifying information into a first identifying code that conceals the first subject's identifying information, transmitting the first identifying code to a second computer system, receiving a piece of information from the second computer system when the second computer system determines that the first identifying code matches a second identifying code converted from a second subject stored in the second computer system, where the second identifying code conceals the second subject's identifying information, transmitting a query to the first computer system related to the piece of information, receiving an answer to the query from the first computer system, and approving the request from the first computer system if the answer is correct. For example, when a computer system on a network of a central computer system conducts a transaction with a subject using a consumer's identifying code, the central computer system communicates with the consumer's computer system to allow the consumer to stop the transaction if it is unauthorized.
[0019]
[0019] The computer system and method converts identification information into an identification code through at least one of character selection, character encoding, character arrangement, character recombination, character encryption, character conversion, character decomposition into bytes, byte selection, byte conversion, byte rearrangement, byte recombination into characters, byte encryption, or a combination thereof.
[0020]
[0020] The computer system and method further protect individuals and organizations from financial crimes by receiving a first account number and contact information for the first computer system from a first computer system, receiving a second account number and a request from a fourth computer system, and when the first account number matches the second account number, sending a request to the first computer system based at least in part on the contact information for the first computer system, receiving a response to the request from the first computer system, and sending a message corresponding to the response to the request to the fourth computer system.
[0021] Additionally, the computer system and method protect individuals and organizations from financial crimes by transmitting the first account number to multiple computer systems when the response indicates that the request was denied.
[0022]
[0022] In addition to the computer system and method described above, the computer system protects individuals and organizations from financial crimes by transmitting a second passcode to a second computer system, receiving a first passcode from the first computer system in response to transmitting the second passcode, receiving a first financial instrument number from the first computer system, receiving the second financial instrument number and a transaction description from a fourth computer system, transmitting a transaction description to the first computer system when the first passcode corresponds to the second passcode and the first financial instrument number matches the second financial instrument number, receiving a message from the first computer system in response to transmitting the transaction description, and transmitting instructions corresponding to the message to the fourth computer system.
[0023] The computer system and method further protect individuals and organizations from financial crime by transmitting the first financial instrument number to multiple computer systems when the message indicates that the transaction has been denied.
[0024]
[0024] The computer system and method further enable a network of computer systems to privately and confidentially share information by receiving from a first computer system a first identification code converted from the identification information of a first subject, where the first identification code conceals the identification information of the first subject, transmitting the first identification code to a second computer system, receiving a message from the second computer system when the first identification code matches a second identification code converted from the identification information of a second subject stored in the second computer system, where the second identification code conceals the identification information of the second subject, and performing an action in response to the message.
[0025]
[0025] Additionally, the computer system and method protect individuals and organizations from financial crimes by receiving identification information of a first subject from a first computer system, converting the identification information of the first subject to a first identification code, receiving a second identification code and a piece of information from a second computer system, sending a question related to the piece of information to the first computer system when the first identification code corresponds to the second identification code, receiving an answer to the question from the first computer system, and sending a message corresponding to the answer to the second computer system.
[0026]
[0026] The above computer systems and methods are only a few examples. Many other computer systems and methods can be formed by combining and permuting embodiments of the present disclosure.
[0027]
[0027] This has outlined rather broadly the features and technical advantages of the present disclosure so that the detailed description that follows may be better understood. Additional features and advantages of the present disclosure are described below. It should be appreciated by those skilled in the art that this disclosure may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. It should also be realized by those skilled in the art that such equivalent constructions do not depart from the teachings of the present disclosure as set forth in the appended claims. The novel features believed characteristic of the present disclosure, both as to its organization and method of operation, together with further objects and advantages, will be better understood from the following description when considered in connection with the accompanying drawings. It is to be expressly understood, however, that each of the figures is provided for the purpose of illustration and description only and is not intended as a definition of the limits of the present disclosure.
[0028]
[0028] The features, nature, and advantages of the present disclosure will become more apparent from the detailed description set forth below when considered in conjunction with the drawings. [Brief explanation of the drawings]
[0029] [Figure 1A] FIG. 1A illustrates a system and network diagram of an intelligent alert system according to an aspect of the present disclosure. [Figure 1B]
[0030] FIG. 1B illustrates a system and network diagram of a consumer protection system according to an embodiment of the present disclosure. [Figure 1C]
[0031] FIG. 1C illustrates a system and network diagram of an illicit proceeds tracking system according to an embodiment of the present disclosure. [Figure 2]
[0032] FIG. 2 is a flow chart for a consumer protection system according to an embodiment of the present disclosure. [Figure 3] FIG. 3 is a flow chart for a consumer protection system according to an embodiment of the present disclosure. [Figure 4]FIG. 4 is a flow chart for a consumer protection system according to an embodiment of the present disclosure. [Figure 5]
[0033] FIG. 5 is a flow chart for an illicit proceeds tracking system according to an embodiment of the present disclosure. [Figure 6] FIG. 6 is a flow chart for an illicit proceeds tracking system according to an embodiment of the present disclosure. [Figure 7] FIG. 7 is a flow chart for an illicit proceeds tracking system according to an embodiment of the present disclosure. [Figure 8]
[0034] FIG. 8 is a flow chart for a consumer protection system according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0030]
[0035] The detailed description set forth below, in conjunction with the accompanying drawings, is intended as a description of various configurations and is not intended to represent the only configurations in which the concepts described herein may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring such concepts. As described herein, the use of the term "or" can mean either an "inclusive OR" or an "exclusive OR," depending on the context of the application based on common practice.
[0031]
[0036] Some aspects of the present disclosure are directed to a consumer protection system that empowers financial institutions, merchants, individuals, and organizations to work together to prevent financial crimes, thereby protecting consumers. Some other aspects of the present disclosure are directed to an illicit proceeds tracking system that empowers financial institutions to work together to prevent financial crimes and recover money stolen from financial institutions.
[0032]
[0037] Additionally, the consumer protection system collaborates with multiple intelligent alert systems (IAS) that monitor the transactions and activities of various enterprise customers to generate alerts. The intelligent alert systems may be installed at financial institutions, merchants, or any type of organization that needs to prevent financial crimes. More importantly, the intelligent alert systems may learn from humans and become smarter, so that, like humans, they can automatically accept potential cases as true positives and / or reject potential cases as false positives. As a result, the intelligent alert systems can help financial institutions use minimal human resources to comply with different requirements, including laws, regulations, rules, etc.
[0033]
[0038] In addition to the Bank Secrecy Act, intelligent alert systems can also help various organizations use minimal human resources to comply with many other laws and regulations through the monitoring of transactions and activities. Depending on the specific requirements of these laws and regulations, intelligent alert systems may monitor different types of activity by using different methods. This disclosure provides various details of how to monitor transactions and activities and help various organizations use minimal human resources to comply with different types of requirements, laws, and regulations. Furthermore, intelligent alert systems may be used by other organizations for other applications or for other purposes, as described in the Background Art section above. Intelligent alert systems reduce or eliminate human effort and errors, saving resources and money and effectively achieving improved results.
[0034]
[0039] When the intelligent alert system detects a potential financial crime against an individual (or organization), the intelligent alert system sends a description of the financial crime and the individual's (or organization's) contact information to the consumer protection system. The consumer protection system requests the contacted party to contact the individual (or organization) and verify whether it is indeed a financial crime. The consumer protection system sends feedback from the individual (or organization) to the intelligent alert system. The intelligent alert system uses the feedback to stop the financial crime if it is a true financial crime, or to dismiss the potential case as a false positive if it is not a true financial crime.
[0035]
[0040] Furthermore, because the consumer protection system communicates with many intelligent alert systems present at different financial institutions, the consumer protection system receives feedback from many individuals and organizations that are customers of the financial institutions. This feedback information is also important to some third parties, such as merchants, who wish to prevent future losses caused by similar financial crimes. These third parties may wish to subscribe to the services offered by the consumer protection system, which can provide feedback information.
[0036]
[0041] The consumer protection system has a built-in alert system, and the subscriber is a third party, such as a merchant. Based on feedback from the individual (or organization), the consumer protection system can send an alert to the subscriber if there is a true crime. The third party uses this information to deter future crimes, so that the criminal or fraudster is unable to commit further similar crimes against the individual or organization.
[0037]
[0042] Many anti-money laundering experts have come to realize that transaction monitoring cannot identify all money launderers. After obtaining their illicit proceeds, criminals often move on to another financial institution and start over. Because these criminals masquerade as honest citizens, financial institutions are unable to detect their transactions as suspicious, even if the illicit proceeds are deposited with the financial institution. Transaction monitoring systems cannot detect money launderers without suspicious transactions.
[0038]
[0043] For example, John Doe, a customer of Financial Institution A in Los Angeles, disappears after defaulting on a $250,000 unsecured loan obtained through fraudulent misrepresentation. The $250,000 is then deposited into an account at Financial Institution B in San Francisco that John Doe opened several years earlier, with no trace of it to Financial Institution A. If Financial Institution A learns that John Doe's illicit proceeds are held in Financial Institution B, Financial Institution A can seize the illicit proceeds in John Doe's account at Financial Institution B through a prejudgment garnishment warrant.
[0039]
[0044] However, the Gramm-Leach-Bliley Act in the United States and similar laws in other countries prohibit financial institutions from disclosing nonpublic personal information of their customers or members. As a result, Financial Institution A cannot publicly disclose John Doe's name, and Financial Institution B cannot know that John Doe stole money from Financial Institution B.
[0040]
[0045] This application also discloses an illicit proceeds tracking system that tracks John Doe without disclosing his personally identifiable information. In the above scenario, when Financial Institution A tracks John Doe's illicit proceeds, Financial Institution B receives an alert. Under Section 314(b) of the USA PATRIOT Act, Financial Institution A and Financial Institution B are fully protected by the safe harbor when discussing John Doe. Financial Institution A can obtain a pre-judgment warrant from a court to seize John Doe's funds at Financial Institution B.
[0041]
[0046] According to the latest statistics published by the U.S. government, the average net loan loss ratio to total loans for all U.S. banks was 0.47% in the third quarter of 2019. This figure is close to the historical low of 0.35%. The historical high was 3.12%. This means that even under current favorable economic conditions, an "average" financial institution that accepts deposits and makes loans could incur loan losses equivalent to approximately 0.47% of its total loan assets. For example, a financial institution with $1 billion in loan assets could incur loan losses of approximately $4.7 million. Because this is an average figure, some financial institutions will fare better and some worse.
[0042]
[0047] Typical annual profits for banks and credit unions are 1% to 2.0% of their total asset size. Typical assets for banks and credit unions consist primarily of loans. Using the 1.5% average as an example, even in good economic conditions, the average loan loss (0.47%) is about one-third of the average profit (1.5%). This is why loan losses keep senior managers and directors up at night.
[0043]
[0048] Assuming a financial institution's credit department has done its job correctly, the most common reason for loan losses is misrepresentation by the borrower. Money stolen by the borrower as a result of misrepresentation is legally classified as illicit proceeds. If the BSA team can track illicit proceeds stolen from a financial institution, the BSA team can help the financial institution recover the money stolen from the financial institution, dramatically increasing the financial institution's overall profitability.
[0044]
[0049] Therefore, in addition to identifying money launderers missed by AML transaction monitoring systems, illicit proceeds tracking can significantly increase the overall profitability of financial institutions.
[0045]
[0050] Furthermore, after criminals commit financial crimes such as money laundering, terrorist financing, equity fraud, human trafficking, embezzlement, bank fraud, security fraud, insurance fraud, and tax fraud, if all financial institutions trace the illicit proceeds under the Money Laundering Control Act, which covers hundreds of Specified Unlawful Activities, criminals will not be able to launder the illicit proceeds through any financial institution. This is the crucial goal of anti-money laundering laws, regulations, and rules. The Illicit Proceeds Tracking System achieves this goal.
[0046]
[0051] The U.S. government strictly enforces business compliance with the USA PATRIOT Act, the Bank Secrecy Act (BSA), the Fair and Accurate Credit Transactions Act (FACT Act), the Unauthorized Online Gambling and Equity Act (UIGEA), the Elder Financial Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations set forth by the Office of Foreign Assets Control (OFAC), and other related laws and regulations. Businesses may include financial institutions, such as banks, credit unions, mortgage lenders, money service providers, stockbrokers, and insurance companies. Financial institutions have been subject to billions of dollars in civil penalties (CMPs) assessed by the U.S. government for violating these laws and regulations. Criminal penalties have also been issued against some individuals employed by financial institutions.
[0047]
[0052] Financial institutions are just one type of business. They are not the only organizations that must comply with these laws and regulations. Many other types of businesses must comply with these laws and regulations. This disclosure applies to all businesses, including those that are obligated to comply with laws and regulations.
[0048]
[0053] The Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) are US organizations. This disclosure uses US laws and regulations as examples. Many other countries have similar organizations that perform similar tasks. As such, many other countries also have similar laws and regulations. This disclosure is also applicable in those countries to help companies comply with their respective laws and regulations. Aspects of this disclosure may also be used by companies, individuals, or organizations that are not required to comply with laws or regulations.
[0049]
[0054] In many cases, it can be difficult to determine whether one or a group of individuals have engaged in illegal activity. According to the U.S. Bank Secrecy Act, when a company submits a suspicious activity report (SAR) to FinCEN, the company is not required to prove whether the reported activity is illegal. In fact, the "safe harbor" rule encourages companies to report more suspicious activity without fear of being accused of falsely reporting legitimate activity as fraudulent. Under this "safe harbor" rule, a person (or organization) cannot file a lawsuit against an entity because the entity submitted a suspicious activity report (SAR) to FinCEN about the person (or organization). SARs are used by the government to gather information, and companies are required to provide only information and opinions in the SAR. Government agencies conduct their own investigations to determine whether the activity reported in the SAR is indeed illegal.
[0050]
[0055] Generally, the decision-making process regarding whether to report suspicious activity other than fraud is different from the decision-making process regarding whether to report a fraud case. In a fraud case, an entity, such as a business or a consumer, may lose money. Therefore, fraud is easier to detect compared to other crimes. Therefore, deciding whether to report a fraud case is easier. Preventing fraud is also easier compared to preventing other crimes. As an example, if a computer system detects a high fraud risk associated with a transaction, the computer system can block the transaction and have investigators investigate the transaction to determine whether it is indeed a fraud case.
[0051]
[0056] In one aspect of the present disclosure, for fraud detection purposes, the computer system calculates a risk score associated with a transaction based on different factors related to the transaction, which may include the account's past activity, deviations from expected activity, location, time, amount, frequency, and nature of the transaction, relationships between multiple accounts, type, nature, and structure of the account holder, etc.
[0052]
[0057] In one aspect of the present disclosure, for fraud detection, the computer system blocks a transaction if the fraud risk score of the transaction exceeds a threshold, which is predetermined based on company policy.
[0053]
[0058] In one aspect of the present disclosure, for fraud detection, a computer system creates a case based on detected high fraud risk transactions. The case and related information are presented to an investigator for further investigation.
[0054]
[0059] Unlike fraud, suspicious activity may not have clear evidence. For example, a customer may frequently deposit large amounts of cash. This customer may be involved in money laundering by selling illegal goods and accepting cash as payment. This customer may also sell homemade products at a farmers market and only accept cash as payment. In many cases, due diligence is required to determine whether there is anything suspicious.
[0055]
[0060] A customer may sell homemade products at a farmers' market, but at other locations, the customer may also sell illegal goods. Unless the bank is informed that the customer is selling illegal goods, there is no evidence for the bank to prove that the customer is selling illegal goods. If the customer is in fact selling illegal goods and the bank does not report such suspicious activity to FinCEN, if the government arrests the customer for selling illegal goods, the bank could later face severe penalties for failing to report the case to FinCEN.
[0056]
[0061] On the other hand, if a bank reports every instance that even remotely seems suspicious, it risks unnecessarily drawing the attention of government agencies, which may spend months inside the bank investigating the bank's operations, potentially severely impacting the bank's operations.
[0057]
[0062] The decision to report a case can be a subjective judgment by the person reviewing the case. Additionally, the decision-making process can be highly subjective. Furthermore, a company cannot block a transaction solely because it appears to be suspicious money laundering activity. A consumer can sue a company for blocking a consumer's transaction when the company cannot clearly prove that money laundering occurred. In fact, many government agencies often advise companies that report suspicious activity, such as money laundering or terrorist financing, to take no action and treat the suspicious transaction as a normal transaction, so that suspects do not receive warnings and flee. This approach gives government agencies more time and opportunity to identify all relevant perpetrators.
[0058]
[0063] Under the U.S. Bank Secrecy Act, a company that files a SAR must keep it confidential and must not allow suspects (e.g., people involved in the case) to know anything about it, including its existence. SARs may only be reviewed by authorized government agencies.
[0059]
[0064] As described above, handling suspicious activity cases is very different from handling fraud cases, so many traditional approaches and concepts applicable to fraud detection and prevention are no longer useful for detecting and managing suspicious activities such as money laundering, terrorist financing, elder abuse, online gambling, etc. In one aspect of the present disclosure, the computer system records the opinions of those who decide not to report a detected suspicious activity case. In such circumstances, the decision maker records the reasons justifying their decision.
[0060]
[0065] Unlike fraud cases, suspicious activity cases may not be apparent to the person reviewing the case until additional evidence becomes available. Thus, a person may initially dismiss a detected suspicious activity case but later change their mind when additional evidence becomes available. In one aspect of the present disclosure, a person reviewing a detected suspicious activity case may also need to review all previously detected cases involving the same suspect to determine whether any new evidence, possibly when combined with older evidence from any dismissed cases, makes the newly detected case more suspicious. As a result, even if a case was previously dismissed as a false positive, such a dismissed case may later be reconsidered.
[0061]
[0066] The implementation of this suspicious activity case review may differ from that of fraud case review because fraud cases typically have a clear conclusion. If a customer is the fraudster, the customer's account is closed and the customer is barred from future transactions / activity. If a customer is the victim of fraud, the detected fraud case is irrelevant to the customer and the evidence cannot be used against the customer in the future. Therefore, fraud investigators typically focus only on newly detected cases. Conversely, suspicious activity investigators may need to review the history of detected cases and make a decision after intensive research and analysis. In one aspect of the present disclosure, the justification for the decision not to report suspicious activity is stored in a database and available for future reference.
[0062]
[0067] In another aspect of the present disclosure, the computer system also records personal information of those who decide not to report detected cases. The computer system may compare decisions made by multiple people about not reporting suspicious activity of the same suspect(s) to determine whether investigators are attempting to cover up detected suspects or cases.
[0063]
[0068] For a large enterprise, thousands of suspicious activities may be detected each month. A group of people may be tasked with reviewing the detected cases to determine whether the enterprise needs to file SARs for these cases. In one aspect of the present disclosure, a computer system automatically assigns the detected cases to different people based on enterprise-defined policies. The computer system may monitor and record the status of each detected case. If case review is delayed by a particular person, the computer system alerts the enterprise of such delay.
[0064]
[0069] In yet another aspect of the present disclosure, the computer system monitors the workload of each person reviewing detected cases, and if a person reviews an abnormally high number of cases compared to others who also reviewed detected cases during the same time period, that person may be suspect or called into question.
[0065]
[0070] On the other hand, if a person has reviewed fewer cases compared to others who have also reviewed cases during the same period, this person may also be suspect or questioned. In either of the above two situations, company managers may want to investigate the situation and draw their own conclusions and solutions.
[0066]
[0071] Generally, suspicious activity can occur in many different types of activity, so different detection features are used to detect suspicious activity. Because the detection of suspicious activity is not clear-cut, some detected cases may turn out not to be truly suspicious after investigation. Under such circumstances, such detected cases are dismissed as false positives or false positives. A false positive or false positive is generally considered the conclusion of a case investigation, but it does not justify why the case was dismissed.
[0067]
[0072] For example, if a financial institution detects a case in which several customers living at the same address deposit large amounts of cash with the financial institution, this case may be related to a drug dealer family in which many of the family members deposit the proceeds of selling drugs. However, upon investigation, this case may actually be a group of students living together who are depositing tips from working at a restaurant. The justification for the decision not to report this case would be "students living together deposit tips from their part-time jobs." Therefore, for the given reason, the conclusion of the detected case is a false positive or a false positive.
[0068]
[0073] Generally, after reviewing a detected case, the case may be classified as a false positive (or a false positive) by the person reviewing the case. In one aspect of the present disclosure, the computer system provides information and / or statistics for a user to analyze all detected cases classified as false positives. From these false positives, the user may identify detection features that generated a number of false positives greater than a threshold. The user may further improve the identified detection features to improve detection of future suspicious activity.
[0069]
[0074] The USA PATRIOT Act, Bank Secrecy Act (BSA), Anti-Money Laundering (AML), and Anti-Terrorist Financing (ATF) have been important compliance matters in the financial industry since 9 / 11. Many financial institutions have invested a large amount of capital in these compliance matters, but still miss genuine money laundering and terrorist financing cases.
[0070]
[0075] The main cause of these compliance problems is that many financial institutions do not detect even basic cases of money laundering, and senior managers at financial institutions have difficulty understanding these issues. Many financial institutions use fraud detection principles to detect money laundering activities, and some conflate fraud cases with money laundering cases.
[0071]
[0076] However, in reality, money laundering is very different from fraud. Fraud detection products can easily compare an account holder's current activity with the account holder's past activity and detect possible fraud when the current activity deviates from expected activity derived from past activity. For example, if a fraudster steals a victim's credit card, the fraudster will make purchases that differ from the victim's past activity. It is simply a matter of time before the credit card company detects the fraud and blocks the credit card. If the account is new and the past record is not yet complete, fraud detection products compare the account holder's current activity with what the account holder said during the account opening process.
[0072]
[0077] Because the goal of fraud detection products is to stop losses as quickly as possible, financial institutions typically perform fraud detection or risk scoring in real time, or at least daily. In contrast, the real-time risk scoring, real-time detection, daily risk scoring, and daily detection methods available for fraud detection cannot detect many basic money laundering activities. In fact, as explained earlier, higher-risk customers may not be money launderers. Assuming that higher-risk customers are engaging in suspicious money laundering activities is a waste of time.
[0073]
[0078] Financial institutions typically have a Bank Secrecy Act Officer (BSA Officer) who is responsible for reporting suspected money laundering or terrorist financing activity to FinCEN. The following example shows how a BSA officer within a financial institution may waste a significant amount of time reviewing the results of real-time or daily risk scoring, yet still miss genuine cases of money laundering. This example consists of the following facts: (a) Client A sends less than $3,000 to XYZ around the 5th of each month, (b) Client B sends less than $3,000 to XYZ around the 8th of each month, (c) Client C sends less than $3,000 to XYZ around the 12th of each month, (d) Client D sends less than $3,000 to XYZ around the 17th of each month, (e) Client E sends less than $3,000 to XYZ around the 24th of each month, (f) Client F sends less than $3,000 to XYZ around the 29th of each month, (g) A, B, C, D, E, and F are unrelated individuals, and (h) XYZ is a drug dealer in Los Angeles with no criminal record.
[0074]
[0079] In the example above, if a BSA officer were to compare a client's current activity with the client's past activity to detect changes in behavior, the BSA officer would not detect an anomaly because the client consistently makes similar transactions from month to month. If a bank teller were to ask the client about the purpose of a fund transfer, the client could easily lie. Because these clients make transactions on different days throughout the month, the BSA officer would not be able to detect risk on any day of the month.
[0075]
[0080] "Furthermore, because these clients are unrelated, BSA officers will not see their overall activity. Additionally, because each transaction involves a small amount and occurs once a month, and the recipients of the funds reside in U.S. cities with large populations and thriving commercial activity, none of these clients would be considered high-risk or suspicious based on these transactions. As a result, despite the diligent daily work of BSA officers using fraud detection products, fraud detection products will miss these basic cases of money laundering."
[0076]
[0081] To detect these money laundering cases, in one configuration, a computer system collects transaction data from financial institutions and performs data mining based on anti-money laundering and anti-terrorist financing scenarios across all transactions of all clients over a specified period, such as 30 days or more. The computer system may collect details of all funds transfer transactions from different data sources within the financial institution, such as wire, ACH, card payments, mobile payments, etc. The computer system may then identify common recipients of these funds transfer transactions.
[0077]
[0082] Once a common payee is identified, the computer system can display all transactions sent to the common payee to BSA personnel. BSA personnel review the identified transactions through the computer system. BSA personnel also review all past cases related to the suspect in the newly detected case. If a BSA personnel (e.g., a responsible person) agrees that the common payee is receiving so much money that such transactions constitute suspicious activity, the computer system assists the BSA personnel in filing a SAR with FinCEN. If the BSA personnel decides not to file a SAR, the BSA personnel enters into the computer system a reason justifying the decision not to report such detected activity.
[0078]
[0083] There are several ways to report a SAR case to FinCEN. One approach is to submit the SAR report in electronic format directly to a server at FinCEN. In such circumstances, BSA personnel can instruct the computer system that detected the suspicious activity to submit the SAR report. The computer system prepares the SAR report based on the suspects and transactions identified by the BSA personnel and then transmits the SAR report to the computer system at FinCEN.
[0079]
[0084] As can be understood, mining the vast amount of transaction data of all of a financial institution's clients accumulated over a long period of time takes some time, even for very small financial institutions. Because financial institutions do not directly lose money in money laundering cases, regulatory guidelines state that BSA officers have a maximum of 30 days to file an SAR. This example illustrates the waste of time and resources involved in real-time or daily risk scoring, which may actually miss true money laundering activity.
[0080]
[0085] A common complaint expressed by BSA personnel is that they waste time every day on false positives at the expense of detecting actual cases of money laundering. This frustration is the result of a widespread misconception that money laundering and fraud are often crimes perpetrated by the same criminals and should be detected together based on detected behavioral changes. After purchasing fraud detection products, some financial institutions attempt to detect both money laundering and fraud cases together. This has resulted in enormous wasted time, money, and resources. This misconception can be corrected with a proper understanding of the sophisticated aspects of transaction risk.
[0081]
[0086] Transaction risk is defined as the risk directly associated with a transaction. For example, money laundering risk and fraud risk are directly associated with a transaction. Nevertheless, these risks have very different characteristics. Customers who launder money through financial institutions attempt to use the institution as a means to achieve their goals. These money launderers usually pose as good customers because they need the financial institution's assistance to achieve their plans. From the financial institution's perspective, these money launderers are desirable customers because they do not mind paying additional fees or losing interest on their money. This is one of the main reasons why financial institutions need to conduct data mining on all transactions to detect money laundering activities hiding behind them.
[0082]
[0087] In contrast, fraud risk manifests itself differently. Customer-perpetrated fraud generally falls into two categories: (1) third-party fraud and (2) counterparty fraud. Third-party fraud is defined as fraud committed by a third party that is neither the financial institution nor the customer. For example, if a fraudster (e.g., a third party) steals a customer's checkbook, both the financial institution (e.g., the first party) and the customer (e.g., the counterparty) may be victims. Under such circumstances, the transactions committed by the third-party fraudster are unrelated to the customer. Therefore, it is a waste of time, money, and resources for BSA personnel to be swayed by ineffective fraud detection products and assume that a customer has committed money laundering simply because the customer is the victim of fraud committed by a third party (e.g., when there is a change in behavior).
[0083]
[0088] Counterparty fraud is defined as fraud committed by a customer (e.g., a counterparty) who deceives a financial institution (e.g., a first party). If a customer successfully deceives a financial institution, they quickly disappear and do not launder money through the financial institution. A fraudster may use Financial Institution A to launder money that the fraudster stole from Financial Institution B. To Financial Institution B, this is a case of fraud. To Financial Institution A, this is a case of money laundering. However, neither Financial Institution A nor Financial Institution B realizes that both a case of fraud and a case of money laundering have occurred with this same customer. It is clear that a system that attempts to detect cases of fraud every day will systematically create many false positives for money laundering and, in fact, miss true cases of money laundering. Using such an approach increases the workload of BSA personnel and exposes financial institutions to unnecessary regulatory risk.
[0084]
[0089] There are other risks in the category of third-party fraud. For example, counterfeit checks, credit card fraud, debit card fraud, ATM fraud, and online fraud are typical risks that fall under the category of third-party fraud. Similarly, there are many different risks in the category of counterparty fraud, such as check kiting, deposit fraud, and loan fraud. Therefore, a good transaction risk management system will successfully detect fraud by using multiple detection algorithms that intelligently consider the unique characteristics of each of the various types of fraud.
[0085]
[0090] Furthermore, as explained above, multiple customers may engage in money laundering or terrorist financing together by making one small transaction for each person on different days, and daily monitoring would miss such cases. This leads to the logical conclusion that a system using a single method to detect behavioral changes would waste resources and miss true cases of money laundering and terrorist financing. In one aspect of the present disclosure, money laundering and terrorist financing activities are detected by different detection methods that data mine all transactions across a financial institution accumulated over a period of time based on user-defined scenarios.
[0086]
[0091] In one aspect of the present disclosure, a computer system uses multiple detection methods to monitor transactions and integrates the detection results into a centralized case management platform. This approach integrates and streamlines anti-money laundering, anti-fraud, and anti-financial crimes measures to improve detection while maintaining a holistic and accurate picture at all times. As a result, financial institutions can improve compliance with regulatory requirements, eliminate risk, avoid losses, increase productivity, reduce resources used to manage transaction risk, reduce costs associated with hardware, databases, and software, lower IT maintenance workloads, and increase overall profitability.
[0087]
[0092] In one aspect of the present disclosure, a computer system compares a customer's (or a group of customers') transaction patterns with known money laundering transaction patterns to detect suspected money laundering activity. If there is a match, possible money laundering activity may have been detected.
[0088]
[0093] For example, many criminals know that if more than $10,000 in cash is deposited into a bank account on the same day, the bank must submit a Currency Transaction Report (CTR) to the U.S. government. To avoid submitting a CTR, criminals often split a single large cash deposit into multiple smaller cash deposits, each on a different day, each for less than $10,000. This transaction pattern, known as "structuring," is a known money laundering transaction pattern, and computer systems can detect this type of transaction pattern. There are many other types of transaction patterns known as money laundering transaction patterns. Computer systems can be designed to detect each of these known money laundering transaction patterns. As a result, money laundering activity can be detected based on the transaction patterns of one or more suspects, even without any changes in behavior.
[0089]
[0094] In one aspect of the present disclosure, a BSA officer (or responsible person) investigates a detected case to determine whether it is a true money laundering case. In one aspect of the present disclosure, a BSA officer also reviews all past cases related to the suspect(s) in the currently detected case. In one aspect of the present disclosure, if the BSA officer agrees that such transactions are suspicious activity, the computer system assists the BSA officer in filing a SAR with FinCEN. In another aspect of the present disclosure, if the BSA officer decides not to file a SAR, the BSA officer enters into the computer system a reason justifying the decision not to report such detected activity.
[0090]
[0095] In another aspect of the present disclosure, to detect suspicious money laundering activities, groups of customers with one or more common risk factors (or characteristics), such as business type, business model, organizational structure, size, location, products, services, carrier type, and position, are compared together. If a customer's trading activity (e.g., trading pattern, trading volume, trading frequency, trading tendency, number of trades, trading value, trading derivatives, etc.) differs from that of other customers, the customer may have engaged in suspicious money laundering activities. In one aspect of the present disclosure, statistical values, such as the mean, variance, and standard deviation of a group of customers, are used to facilitate such comparison. Similarly, if a customer behaves differently from other customers with the same set of risk factors (or characteristics), the customer may have engaged in suspicious money laundering activities. As a result, suspicious money laundering activities can be detected even when there is no change in behavior in any of the accounts.
[0091]
[0096] Sometimes, it may not be easy to compare groups of customers together. For example, an MSB with 100 branches will have much more cash activity than another MSB with only two branches. In one aspect of the present disclosure, to achieve a more effective comparison, it is useful to compare some derivatives (e.g., ratios of some numerical values) instead of the original raw data. For example, the ratio may be "total cash withdrawals from the bank divided by total number of checks deposited in the bank." In this example, the number of checks deposited may be used to measure the size of the MSB's check cashing business. Thus, the ratio of "total cash withdrawals divided by total number of checks deposited" essentially scales the check cashing business of a 100-branch MSB to the check cashing business of a 2-branch MSB to approximately the same level based on check cashing activity, allowing them to be compared on a more equitable basis.
[0092]
[0097] Many other derivatives can be used to achieve better comparisons. In general, derivatives for more effective comparisons may include a first variable of interest divided by a second variable measuring the size of the company (or business). For example, "total ACH outgoing transactional amount divided by total number of checks deposited," "total wire outgoing transactional amount divided by total number of checks deposited," "total number of prepaid cards issued divided by total number of checks deposited," "total ACH outgoing transactional amount divided by total number of branches," "total wire transfer transactional amount divided by total number of branches," "total number of prepaid cards issued divided by total number of branches," "total ACH outgoing transactional amount divided by total number of prepaid cards issued," "total wire transfer transactional amount divided by total number of prepaid cards issued," etc. are just a few examples of derivatives that may be used. In addition to the ratios above, in one aspect of the present disclosure, other forms of mathematical transformations create derivatives.
[0093]
[0098] In one aspect of the present disclosure, a computer system compares a particular customer's derivatives with those of a group of customers (e.g., the same type of business or occupation) that share one or more common risk factors (or characteristics) with the particular customer. If the particular customer's derivatives deviate significantly from those of the group of customers, the particular customer may have engaged in suspected money laundering activities. In one aspect of the present disclosure, statistical analysis, such as the mean, variance, and standard deviation of the group of customers, facilitates such comparisons.
[0094]
[0099] In one aspect of the present disclosure, a computer system uses many different risk factors to determine the money laundering risk of each customer of a financial institution. For example, these risk factors may include the customer's industry, the customer's business type, the customer's geographic area, the customer's country of residence, the nature of the customer's business, the business's product type, the business's service type, the business's structure, the customer's occupation, nationality, past records (including compliance records such as the number of currency transaction reports, the number of suspicious activity reports, matches to OFAC lists, matches to 314(a) lists, matches to Politically Exposed Persons lists, and special designations under compliance programs), the type of transaction made, account balance, fund inflows, fund outflows, transaction patterns, number of transactions, transaction amounts, transaction volumes, transaction frequency, derivatives of the transaction, transaction location, transaction time, transaction country, sender of remittance transaction, sender's location, sender's country, sender's characteristics, recipient of remittance transaction, recipient's location, recipient's country, recipient's characteristics, relationships, social status, political exposure, past transactions, etc. Indeed, thousands of risk factors may be considered to determine a customer's money laundering risk. For the purposes of this disclosure, a "risk factor" is also referred to as a "representative element of a risk dimension" or simply as a "risk dimension."
[0095]
[0100] According to aspects of the present disclosure, each attribute of a customer that may affect the customer's risk is a risk factor. Additionally, each characteristic of a customer that may affect the customer's risk may be a risk factor. Furthermore, each type of customer activity that may affect the customer's risk is a risk factor. Risk factors may also be affected by other risks, such as a piece of information related to the customer, the customer's transaction type, and / or the customer's transaction pattern. Each risk factor is assigned a risk value.
[0096]
[0101] In one configuration, each degree of risk of the same type is a risk factor and is assigned a risk score. For example, a 30-day cash transaction amount can be used to measure the degree of risk associated with money laundering. For example, cash transaction amounts (or degrees) can be defined as follows: $0 to $5,000 over a 30-day period has a risk score of 10, $5,001 to $50,000 has a risk score of 50, $50,001 to $250,000 has a risk score of 100, $250,001 to $1,000,000 has a risk score of 200, $1,000,001 to $10,000,000 has a risk score of 500, and $10,000,000 or more has a risk score of 1,000. In this example, someone with a total cash transaction value of $60,000 over a 30-day period would fall into the "$50,001 to $250,000" total transaction value level and have a risk score of 100.
[0097]
[0102] "Cash transaction amount" is used merely as an example. Other considerations, such as the number of cash transactions and the rate of growth of cash transactions, may also be used to measure the degree of risk associated with money laundering. In addition to cash, other financial transactions, such as checks, wires, ATMs, ACH, virtual currencies, virtual securities, virtual instruments, credit cards, debit cards, prepaid cards, monetary instruments, and transfers, may also be used to measure the degree of risk associated with money laundering. Those skilled in the art can easily identify numerous risk factors based on the above examples.
[0098]
[0103] In one aspect of the present disclosure, the risk score-based scenarios are based on customer data. Individual information about a customer is a risk factor and a risk score is assigned. Additionally or alternatively, the risk score-based scenarios are based on transaction data. Each amount level (or degree of amount) of a transaction type is a risk factor and a risk score is assigned.
[0099]
[0104] In one aspect of the disclosure, the customer data may include the customer's industry, the customer's business type, the customer's geographic area, the country where the customer is located, the nature of the customer's business, the product type of the business, the service type of the business, the structure of the business, the customer's occupation, the customer's nationality, past records, the type of transaction made, the account balance, the inflow of funds, the outflow of funds, the transaction pattern, the number of transactions, the amount of transactions, the volume of transactions, the frequency of transactions, the derivative of the transaction, the location of the transaction, the time of the transaction, the country of the transaction, the sender of the remittance transaction, the location of the sender, the country of the sender, the nature of the sender, the recipient of the remittance transaction, the location of the recipient, the country of the recipient, the nature of the recipient, the relationship, social status, political exposure, past transactions, the number of suspicious activity reports (SARs) filed for money laundering and terrorist financing cases, the category of the first financial institution, the business type of the first financial institution, the geographic area of the first financial institution, the country where the first financial institution is headquartered, the nature of the business of the first financial institution, the age of the person, the gender of the person, the income level of the person, the appearance of the person, judgments about the person, the personal status of the person, the family status of the person, the status of a person's family members, the status of a person's family members, the status of a person's friends, the past records of a person, the person's industry, the person's geographic area, the country in which the person resides, the person's occupation, the employee's job type, the employee's education level, the employee's income level, the length of employment at the current job, the performance evaluation records, the employment history, the length of each employment in the employment history, the reason for leaving each employment in the employment history, the employee's age, the employee's gender, the employee's personal status, the employee's family members, the status of the employee's family members, the status of the employee's friends, the employee's past records, the type of work performed, the number of transactions executed, the amount of transactions executed, the highest amount of transactions, the number of transactions with a specific counterparty, the amount of transactions with a specific counterparty, the number of changes to material records, the number of changes to material records related to a specific counterparty, the geographic area of the employee's home, the geographic area of the employee's office, the country in which the employee resides, the customer due diligence results, the length of account history, the number of names matched to gambling organizations in transactions, or any combination thereof.
[0100]
[0105] In one aspect of the present disclosure, the transaction data is associated with one or more of cash, check, wire transfer, ATM (Automated Teller Machine), ACH (Automated Clearing House), virtual currency, virtual securities, virtual certificates, credit cards, debit cards, prepaid cards, electronic funds transfer, wires, monetary instruments, letters of credit, notes, securities, commercial paper, commodities, precious metals, account openings, account closures, account applications, deposits, withdrawals, cancellations, balance checks, inquiries, credits, debits, or combinations thereof.
[0101]
[0106] In one aspect of the present disclosure, each risk factor is assigned a risk score, and the customer is assigned an overall risk score that is the sum of all of the risk scores of the risk factors associated with the customer. This process of generating an overall risk score for each customer may be referred to as risk scoring. This overall risk score is used to determine the level of risk associated with the customer. In this disclosure, summation is used as an example. In fact, many different types of mathematical transformations may also be used to achieve a similar effect.
[0102]
[0107] In one aspect of the present disclosure, each risk factor is assigned a risk score, and the customer is assigned an overall risk score that is a value derived from a mathematical transformation of all of the risk scores of the risk factors associated with the customer.
[0103]
[0108] As explained earlier, unlike in fraud situations, higher risk clients may not be suspected of money laundering or terrorist financing. High risk may simply be a characteristic of the client. For example, MSBS, pawnbrokers, car dealers, pilots, and flight attendants are often classified as higher risk clients for anti-money laundering and anti-terrorist financing purposes, but this does not mean that these clients are engaging in money laundering or terrorist financing activities.
[0104]
[0109] Nevertheless, because a customer has a high risk score, the customer may be monitored more closely and a different monitoring method may be applied. Thus, in one aspect of the present disclosure, a customer's total risk score is used to determine the monitoring method to be applied to monitor the customer. If the customer's total risk score is higher, a more strict monitoring method is applied to monitor the customer. If the customer's total risk score is low, a less strict monitoring method is applied to monitor the customer.
[0105]
[0110] In other words, in one aspect of the present disclosure, a customer's total risk score is not used to determine whether the customer is suspicious. Instead, the customer's total risk score is used to select an algorithm or set of algorithms for monitoring the customer.
[0106]
[0111] At times, customers with very high risk scores may be suspicious. Thus, in one aspect of the present disclosure, if a customer's total risk score is higher than a predetermined value, an alert is triggered for this customer so that investigators can investigate the potential case. The predetermined value may be set by the software module, by someone who designs the system, by someone who tunes the system, by someone who uses the system, or a combination thereof.
[0107]
[0112] In one aspect of the present disclosure, groups of customers with the same risk factors are compared together. For example, all customers who are flight attendants can be compared together. In one aspect of the present disclosure, if a particular flight attendant's total risk score is much higher than a reference value derived from the total risk scores of all flight attendants, this particular flight attendant may have engaged in some suspicious money laundering activity. The reference value may include an average, median, mean, mode, weighted average, and / or other statistical value.
[0108]
[0113] Statistical approaches can also be applied to facilitate the detection of suspicious activity. For example, a mean, variance, and standard deviation can be derived from the total risk scores of all customers who are flight attendants. In one aspect of the present disclosure, if a particular flight attendant's total risk score is more than four standard deviations higher than the average total risk score of all flight attendants, then the particular flight attendant may have engaged in suspicious activity.
[0109]
[0114] The "four times" mentioned above is merely an example. The number "four" can be any number, such as 3.75, 4.21, 10, etc. In one aspect of the present disclosure, if a particular flight attendant's total risk score is more than x standard deviations higher than the average total risk score of all flight attendants, then this particular flight attendant may have engaged in suspected money laundering activity, where x is a number assigned by the BSA officer (or responsible person). This statistical approach is applicable whenever group comparisons are used.
[0110]
[0115] Flight attendants are merely one example used to illustrate this method of detecting suspicious money laundering activity among a group of entities. In fact, many other risk factors may be used for similar purposes. Because tens of thousands of risk factors exist, in one aspect of the present disclosure, the computer system allows a user to select any risk factor to identify all customers with the same risk factor. In one aspect of the present disclosure, if a particular customer has a total risk score that is much higher than a reference value derived from the total risk scores of other customers with the same risk factor, the particular customer may have engaged in suspicious money laundering activity. The reference value may include a mean, median, average, mode, weighted average, and / or other statistical value.
[0111]
[0116] Instead of a single risk factor, a group of risk factors can also be used. In fact, a group of risk factors can improve the accuracy of detection results. For example, in addition to the risk factor of occupation (e.g., flight attendant), the country of destination of the flight where the flight attendant works can be another useful risk factor for detecting money laundering risks. For example, a flight attendant working on a New York-Chicago flight may have different activities from another flight attendant working on a Miami-Mexico City flight. It may be more accurate to compare subgroups of flight attendants working on a Miami-Mexico City flight. In this example, two risk factors, namely occupation and flight destination city, are considered to improve the accuracy of detection.
[0112]
[0117] In one aspect of the present disclosure, a set of risk factors is used to identify a group of entities. If a particular entity has a total risk score that is much higher than a reference value derived from the total risk scores of all entities with the same set of risk factors, the particular entity may have engaged in suspicious money laundering activities. The reference value may include the mean, median, average, mode, weighted average, and / or other statistical values. To simplify calculations, standard group statistics such as the mean, variance, and standard deviation, which can be easily calculated based on existing software development tools, may be derived to facilitate such comparisons among groups of entities. As a result, even if there is no behavioral change in an account, the computer system can still detect suspicious money laundering activities based on the above approach.
[0113]
[0118] At times, some entities are so different from others that it may be useful to exclude such entities from the group comparison process. In one aspect of the present disclosure, the computer system allows the user to select some entities that will not be included in the group comparison process.
[0114]
[0119] Detecting flight attendants as having suspicious money laundering activity is just one example. Similar methods are applicable to many other different situations. For example, it is typically very difficult for a bank or credit union to detect a customer of a money service business (MSB) as having suspicious money laundering or terrorist financing activity because MSBs conduct many transactions every day and one money laundering transaction can be hidden among many other normal transactions.
[0115]
[0120] In one aspect of the present disclosure, an additional risk factor (e.g., proximity to the Mexican border) is used to identify a group of MSBs having this same set of risk factors (e.g., in addition to the first risk factor, i.e., type of business). If a particular MSB has a total risk score higher than a reference value derived from the total risk scores of all MSBs having the same set of risk factors, then the particular MSB has likely engaged in suspected money laundering activity. Reference values include the mean, median, average, mode, weighted average, and / or other statistical values. Similarly, standard group statistics such as the mean, variance, standard deviation, etc. may be derived to facilitate such comparisons among groups of MSBs.
[0116]
[0121] Sometimes, it may not be easy to compare groups of MSBs because they may have different types of operations and different sizes. In one embodiment of the present disclosure, part-time MSBs and full-time MSBs are assigned two different risk factors because the nature of their businesses may differ. In another embodiment of the present disclosure, a risk factor is assigned to each of the different types of MSB products and / or services. For example, money transfers, check cashing, currency transactions, prepaid card management, etc. are each assigned a risk factor, even though they may all be provided by the same MSB. In one embodiment of the present disclosure, a set of risk factors that precisely defines the type of product and / or service is used to identify risk.
[0117]
[0122] In one aspect of the present disclosure, some risk factors are adjusted based on the size of the operation to make group comparisons more effective. For example, an MSB with 50 branches may necessarily have five times the total cash transaction volume of another MSB with 10 branches. Sometimes, to make group comparisons, risk factors affected by the size of the operation can be adjusted to take into account the size of the operation. For example, for an MSB with 50 branches, the total cash transaction volume over a 30-day period can be divided by 50 to establish adjusted risk factors and risk scores for group comparisons. Branches are used here as an example to measure the size of the operation. Other information, such as the number of customers, number of transactions, number of employees, and asset size, can also be used to measure the size of the operation.
[0118]
[0123] In one aspect of the present disclosure, a set of risk factors adjusted based on the size of operations (e.g., adjusted risk factors) is used to identify a group of entities having this adjusted set of risk factors. The risk score of the adjusted risk factors is referred to as the adjusted risk score. If a particular entity has an adjusted total risk score that is much higher than a reference value derived from the adjusted total risk scores of all entities having the same set of adjusted risk factors, the particular entity may have engaged in suspicious money laundering activities. The reference value may include a mean, median, average, mode, weighted average, and / or other statistical value. Generally, in one aspect of the present disclosure, detection algorithms that incorporate risk factors into their detection algorithms may also be modified to incorporate adjusted risk factors into their detection algorithms. Detection algorithms that incorporate risk scores into their detection algorithms may also be modified to incorporate adjusted risk scores into their detection algorithms.
[0119]
[0124] To simplify the calculations, standard group statistics such as means, variances, and standard deviations based on the adjusted risk factors and adjusted risk scores can be derived to facilitate such comparisons among groups of entities. As a result, even if there is no behavioral change in an account, the computer system can still detect suspicious money laundering activity based on the above approach.
[0120]
[0125] Because MSBs may have different transactional activities than other types of businesses, it is more effective to monitor MSBs based on their unique transactional activities. Therefore, in one aspect of the present disclosure, different sets of detection algorithms may be used to monitor entities with different sets of risk factors. In one aspect of the present disclosure, a set of risk factors is used to identify a group of entities with the set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activity in the group of entities. In other words, a set of detection algorithms is selected to monitor a group of entities based on a set of risk factors associated with the group of entities.
[0121]
[0126] In another aspect of the present disclosure, a set of risk factors is adjusted based on the size of operations and used to identify a group of entities having this adjusted set of risk factors, and a particular set of detection algorithms is used to detect suspected money laundering activity in this group of entities. In other words, a set of detection algorithms is selected for monitoring the group of entities based on the set of adjusted risk factors associated with the group of entities.
[0122]
[0127] Sometimes it makes sense to monitor higher risk entities more closely than lower risk entities. Thus, different sets of detection algorithms are used to monitor different entities having different levels of risk. In one aspect of the present disclosure, a set of detection algorithms is selected to monitor an entity based on the entity's total risk score. In another aspect of the present disclosure, a set of detection algorithms is selected to monitor an entity based on the entity's adjusted total risk score, where the adjusted total risk score is obtained from the risk scores of the adjusted risk factors.
[0123]
[0128] In one aspect of the present disclosure, when an MSB is detected as having potential money laundering activity, the computer system may identify a transaction (or group of transactions) that caused the detected MSB to have an aggregate risk score higher than a reference value derived from the aggregate risk scores of all MSBs, including a mean, median, average, mode, weighted average, and / or other statistical value.
[0124]
[0129] Similarly, when an MSB is detected as having possible money laundering activity, the computer system identifies a transaction (or group of transactions) that caused the detected MSB to have an adjusted total risk score higher than a reference value derived from the adjusted total risk scores of all MSBs. The reference value may include a mean, median, average, mode, weighted average, and / or other statistical value. As a result, a money laundering transaction (or group of money laundering transactions) may be identified by this approach. This approach of identifying specific transactions (or groups of transactions) with higher risk scores (or higher adjusted risk scores) can be used not only with MSBs, but also with other types of customers.
[0125]
[0130] Conventionally, a higher risk score means a higher risk. However, there is no rule prohibiting a person or company from defining a lower risk score for a higher risk. To avoid confusion, the explanation in this disclosure is based on the convention that a higher risk score means a higher risk. Furthermore, the risk score may be a negative value. A negative risk score means a reduced risk based on this convention.
[0126]
[0131] As noted above, MSBs are just one example. Other types of businesses, such as pawn shops, car dealerships, etc., can be monitored in a similar manner. As a result, the risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, and adjusted total risk scores can be used in a variety of ways to detect suspicious money laundering activity even in the absence of behavioral changes in accounts.
[0127]
[0132] Indeed, governmental or non-governmental agencies such as the OCC, FDIC, Federal Reserve, NCUA, FinCEN, SEC, and FINRA may monitor financial institutions such as banks, credit unions, insurance companies, and stockbrokers based on approaches similar to those described above for monitoring MSBs. Different risk factors, risk scores, adjusted risk factors, and adjusted risk scores may be defined for this monitoring purpose.
[0128]
[0133] In one aspect of the present disclosure, a computer system uses many different risk factors to determine whether a financial institution is in compliance with regulatory requirements regarding the filing of SARs to report money laundering and terrorist financing cases. For example, these risk factors may include the number of SARs filed for money laundering and terrorist financing cases, the financial institution's category, the financial institution's business type, the financial institution's geographic area, the financial institution's country of headquarters, the financial institution's business nature, the business's product type, the business's service type, the business's structure, the financial institution's customer profile, past records, the type of transaction conducted, fund inflows, fund outflows, transaction patterns, the number of transactions, the transaction amount, the transaction volume, the transaction frequency, the transaction derivative, the transaction location, the transaction time, the transaction country, the sender of the remittance transaction, the sender's location, the sender's country, the sender's nature, the remittance transaction recipient, the recipient's location, the recipient's country, the recipient's nature, relationships, the customer's social status, the customer's political exposure, the sender's political exposure, the recipient's political exposure, past transactions, etc. In fact, thousands of risk factors may be considered to determine a financial institution's compliance risk.
[0129]
[0134] In one aspect of the present disclosure, the number of branches is used to adjust the risk factors and risk scores. In another aspect of the present disclosure, asset size is used to adjust the risk factors and risk scores. Many other factors may also be used to adjust the risk factors and risk scores. In this current example, the risk factor "number of SARs submitted" may have a negative value because the more SARs submitted by a financial institution, the less likely the financial institution will fail to submit a SAR.
[0130]
[0135] In one aspect of the present disclosure, the set of risk factors is adjusted based on the size of operations and used to identify a group of banks having this adjusted set of risk factors. If a particular bank has an adjusted total risk score that is much higher than the baseline adjusted total risk score of all banks having the same set of adjusted risk factors, the particular bank may have failed to meet its compliance obligations to detect and report suspected money laundering and / or terrorist financing activities. The baseline may include the mean, median, average, mode, weighted average, and / or other statistical values. To simplify calculations, standard group statistics such as the mean, variance, and standard deviation may be derived to facilitate such comparisons among groups of entities.
[0131]
[0136] Additionally, different detection algorithms may be used to monitor different banks having different sets of risk factors. In one aspect of the present disclosure, a set of risk factors is used to identify a group of banks having the set of risk factors, and a particular set of detection algorithms is used to detect possible oversight of compliance matters in the group of banks. Thus, in one aspect of the present disclosure, a set of detection algorithms is selected for monitoring a group of banks based on a set of risk factors associated with the group of banks.
[0132]
[0137] In another aspect of the present disclosure, a set of risk factors is adjusted based on business size and used to identify a group of banks having this adjusted set of risk factors, and a specific set of detection algorithms is used to detect possible oversight of compliance matters in this group of banks. In other words, a set of detection algorithms is selected for monitoring the group of banks based on the set of adjusted risk factors associated with the group of banks.
[0133]
[0138] Although banks are used in the above examples, the same set of methods can be used to monitor credit unions, stockbrokers, insurance companies, other financial institutions, and other types of businesses. Furthermore, the scope of monitoring is not limited to compliance with anti-money laundering and counter-terrorist financing issues. Indeed, all types of issues in all types of businesses can be monitored by the methods described in this disclosure by appropriately defining the risk factors, risk scores, adjusted risk factors, adjusted risk scores, and detection algorithms associated with such issues.
[0134]
[0139] MSBs also must comply with numerous laws and regulations. However, unlike a bank or credit union, MSBs do not actually know who their customers are. A typical MSB provides money services to consumers who walk into its offices. Even if an MSB collects identifying information from all of its clients, the MSB may not be able to correctly identify money laundering activity. For example, a consumer may use a Mexican passport to transfer $7,000 in cash to an MSB in the morning, and then use a California driver's license to transfer $8,000 in cash to the same MSB in the afternoon. Because two identification documents are used, this same consumer may be considered two different people. Although required by law to file currency transaction reports because more than $10,000 in cash is provided by the same consumer, an MSB may not do so. This situation is further complicated when an MSB has multiple branches, as the same consumer can walk into different branches and conduct transactions based on different identification documents.
[0135]
[0140] In one aspect of the present disclosure, a computer system compares the names, phone numbers, addresses, dates of birth, etc. of all consumers who have conducted transactions with the MSB to identify all transactions that may have been conducted by the same consumer. After all transactions associated with the consumer have been identified, the computer system can detect suspicious money laundering activity associated with the consumer based on the transactions associated with the consumer.
[0136]
[0141] In one aspect of the present disclosure, a BSA officer (e.g., a person tasked with investigating) investigates the detected case to determine whether it is a true money laundering case. The BSA officer also reviews all past cases related to the consumer of the newly detected case. If the BSA officer agrees that the detected case is a suspected money laundering case, the computer system assists the BSA officer in filing a SAR with FinCEN. If the BSA officer decides not to file a SAR, the BSA officer enters into the computer system a reason justifying the decision not to report the detected case.
[0137]
[0142] Sometimes, Correspondent Bank A and Correspondent Bank B do not have a direct banking relationship, so one bank will receive a wire transfer from a client of Correspondent Bank A and resend the wire transfer to another client of Correspondent Bank B. This situation often occurs during international wire transfers, as banks in two different countries may not have a direct banking relationship. This type of wire transfer is often called an intermediary wire transfer.
[0138]
[0143] Banks that provide intermediary wire transfer services are exposed to a very high money laundering risk because the sender and recipient of the intermediary wire transfer are not the bank's customers. In addition, banks may not know the true background of the sender and recipient of the wire transfer. The sender may be a terrorist financier and the recipient may be a terrorist. Banks that handle intermediary wire services may unknowingly become a channel for money laundering and terrorist financing.
[0139]
[0144] In one configuration of the present disclosure, a computer system compares the names, addresses, countries, phone numbers, email addresses, etc. of all senders and recipients of intermediated wire transfers to identify transactions associated with each sender and each recipient. In one aspect of the present disclosure, if the computer system detects an unusually large number of wire transfers from the same sender, the sender and recipient may be involved in money laundering or terrorist financing activities. If the computer system detects an unusually large total amount of wire transfers from the same sender, the sender and recipient may be involved in money laundering activities.
[0140]
[0145] Similarly, if a computer system detects an unusually large number of wire transfers to the same recipient, the sender and recipient may be involved in money laundering or terrorist financing activities. If a computer system detects an unusually large amount of wire transfers to the same recipient, the sender and recipient may be involved in money laundering activities.
[0141]
[0146] If a computer system detects an unusual number of wire transfers from the same sender to the same recipient, the sender and recipient may be involved in money laundering or terrorist financing activities.If a computer system detects an unusually large amount of wire transfers from the same sender to the same recipient, the sender and recipient may be involved in money laundering or terrorist financing activities.
[0142]
[0147] In one aspect of the present disclosure, BSA personnel investigate such detected cases to determine whether they are true money laundering cases. BSA personnel also review all past cases related to the suspect in the newly detected case. If the BSA personnel agree that there is suspected money laundering activity, the computer system assists the BSA personnel in filing a SAR with FinCEN. If the BSA personnel decides not to file a SAR, the BSA personnel enters into the computer system a reason justifying the decision not to report such detected activity.
[0143]
[0148] With a large portion of the population rapidly aging, several states recently enacted the Elder Financial Abuse Reporting Act (EARA) to protect elderly people who are unable to protect themselves. Elderly people are frequently tricked into giving money to perpetrators. Therefore, financial institutions train their frontline staff to observe and report what appear to be possible cases of elder abuse. This human-based approach is ineffective because transactions can be conducted remotely and perpetrators can effectively hide their activities. Furthermore, human workers are prone to error and mistakes. Relying on human workers to detect and report cases of elder abuse is ineffective.
[0144]
[0149] Many businesses store customer birthdate information in a database. In one aspect of the present disclosure, a computer system collects the birthdate information and identifies seniors who are above a predetermined age. The computer system monitors all seniors' transactions and detects changes in their activities.
[0145]
[0150] For example, if an unusually large amount of funds is withdrawn from an elderly person's account, the financial institution may wish to investigate the purpose of the fund transfer. In one aspect of the present disclosure, if an unusually large check is deposited into an elderly person's account, the financial institution may wish to investigate whether a counterfeit check was given to the elderly person in exchange for the elderly person's real money or assets. If there is an unusual transaction pattern (e.g., unusual frequency or volume) on an elderly person's account, the financial institution may wish to investigate the transaction(s). If an elderly person's account balance is rapidly decreasing, the financial institution may wish to investigate transactions related to this account.
[0146]
[0151] In one aspect of the present disclosure, the methods for selecting risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, adjusted total risk scores, statistical approaches, and detection algorithms described above are applicable to detect possible cases of elder abuse. Because elder abuse is different from money laundering, different sets of risk factors and risk scores may be used to detect elder abuse. For example, these risk factors may include the person's age, the person's gender, the person's income level, the person's appearance, judgments about the person, the person's personal condition, the person's family condition, the person's family members, the status of the person's family members, the person's friends, the status of the person's friends, the person's past record, the person's industry, the person's geographic area, the person's country of residence, the person's occupation, nationality, the type of transaction made, the account balance, the inflow of funds, the outflow of funds, the transaction pattern, the number of transactions, the amount of transactions, the volume of transactions, the frequency of transactions, the derivative of the transaction, the location of the transaction, the time of the transaction, the country of the transaction, the sender of the remittance transaction, the location of the sender, the country of the sender, the nature of the sender, the recipient of the remittance transaction, the location of the recipient, the country of the recipient, the nature of the recipient, the relationship, social status, political exposure, past transactions, etc. Indeed, many different risk factors may be considered to determine an individual's risk of elder abuse.
[0147]
[0152] For example, in one aspect of the present disclosure, risk factors are used to identify a group of elderly people who have the same risk factors. If a particular elderly person has a total risk score higher than a reference value derived from the total risk scores of all elderly people who have the same risk factors, the particular elderly person may be a victim of a potential elder abuse case. The reference value may include a mean, median, average, mode, weighted average, and / or other statistical value. In another aspect of the present disclosure, a set of risk factors is used to identify a group of elderly people who have the set of risk factors. If a particular elderly person has a total risk score higher than a reference value derived from the total risk scores of all elderly people who have the same set of risk factors, the particular elderly person may be a victim of a potential elder abuse case. The reference value may include a mean, median, average, mode, weighted average, and / or other statistical value.
[0148]
[0153] To simplify the calculations, standard group statistics such as mean, variance, standard deviation, etc. can be derived to facilitate such comparisons among groups of entities. As a result, even if there is no behavioral change in an account, a computer system can still detect possible cases of elder abuse based on the above approach.
[0149]
[0154] Very often, a business will have a compliance officer who is responsible for all regulatory compliance matters. In one aspect of the present disclosure, an investigator (e.g., a compliance officer) investigates the detected case to determine whether a true case of elder abuse has occurred. The compliance officer also reviews all past cases related to the elderly person in the newly detected case. If the compliance officer agrees that the case is a possible case of elder abuse, the computer system assists the compliance officer in reporting the detected case. If the compliance officer decides not to report the detected case, the compliance officer enters into the computer system a reason justifying the decision not to report the detected case.
[0150]
[0155] According to the Sarbanes-Oxley Act (SOX), certain companies (e.g., publicly traded companies) must conduct internal control monitoring to prevent fraud committed by their employees. Traditionally, such internal control monitoring is performed by human workers (e.g., auditors) who spend several months each year auditing a company's financial records. This human-based approach is ineffective because human workers are prone to error and mistakes. Furthermore, because it takes a considerable amount of time to audit financial records, it may be too late to prevent crime.
[0151]
[0156] In one aspect of the present disclosure, a computer system monitors accounting general ledger items and detects anomalous patterns (e.g., abnormal frequency, volume, rate of increase, etc.) associated with the general ledger items to identify suspected insider fraud activity. For example, if the general ledger item for travel expenses suddenly increased by 500% this month compared to its history over the past 12 months, this could indicate that some employees are abusing their privileges to incur anomalous expenses.
[0152]
[0157] In one aspect of the present disclosure, a computer system compares the current value of an accounting general ledger item to a reference value derived from historical values of the same accounting general ledger item for the past x months, where the value x is predefined. If the current value is greater than the reference value by a significant margin, some employees may have committed fraud. The reference value may include the mean, median, average, mode, weighted average, and / or other statistical values. Further investigation may be conducted to determine why the general ledger item's value deviated from its historical value.
[0153]
[0158] In another aspect of the present disclosure, the computer system compares an employee's current activity with the employee's past activity to detect any changes. For example, if a loan officer issues an unusually large number of loans in a month compared to the number per previous month, the loan officer's activity may be suspicious. If a loan officer issues a loan with an unusually large loan amount compared to the amount in the past, the loan officer's activity may be suspicious. If a loan officer issues a loan with an unusually large total amount in a month compared to the total amount in the past month, the loan officer's activity may be suspicious.
[0154]
[0159] Very often, activity can be measured by a value called an activity value. For example, a loan officer's activity can be measured by the number of loans, the largest loan amount, the total amount of loans, the average amount per loan, the number of loans to the same customer, the number of loan record changes, the number of loan record changes with the same customer, the frequency of loan record changes, the frequency of loan record changes with the same customer, the type of loan, etc. A bank teller's activity can be measured by the total number of transactions, the total amount of transactions, the largest transaction amount, the average amount per transaction, the type of transaction, the number of customers with whom the teller transacts, the average number of transactions per customer, the number of transactions with the same customer, the number of customer record changes, the number of customer record changes with the same customer, the frequency of customer record changes, the frequency of customer record changes with the same customer, etc. In one aspect of the present disclosure, a computer system compares the current value of an activity to a reference value derived from historical values of the same activity. If the current value is greater than the reference value by a significant margin, the person performing the activity may have committed fraud. Further investigation can be conducted to determine whether the person has indeed committed fraud. The metric may include the mean, median, average, mode, weighted average, and / or other statistical value.
[0155]
[0160] In one aspect of the present disclosure, the computer system compares the employee's activities with the activities of other employees with the same role at the company. For example, if a teller (or loan officer, etc.) behaves very differently from other tellers (or loan officers, etc.) at the same branch, the teller (or loan officer, etc.) may have engaged in some suspicious activity.
[0156]
[0161] In one aspect of the present disclosure, the computer system compares the activity value of a particular employee to a reference value derived from all activity values for the same activity of all employees with the same responsibilities as the particular employee. If the activity value of the particular employee significantly deviates from the reference value, the particular employee may have committed fraud. Further investigation can be conducted to determine whether the employee has indeed committed fraud. The reference value may include the mean, median, average, mode, weighted average, and / or other statistical value.
[0157]
[0162] When comparing a single employee to a group of employees, the statistical approach used in the flight attendant example above can be applied. For example, a comprehensive set of risk factors associated with the employee can be identified, and a risk score assigned to each risk factor. As a result, each employee has an overall risk score obtained from a mathematical transformation (e.g., summation) of all risk scores associated with the employee.
[0158]
[0163] A set of risk factors for detecting employee-related fraud may differ from a set of risk factors for detecting other types of suspicious activity, such as money laundering. For example, risk factors for detecting employee fraud may include the employee's job type, the employee's educational background, the employee's income level, length of employment at current job, performance evaluation records, employment history, length of each employment in the employment history, reason for leaving each employment in the employment history, the employee's age, the employee's gender, the employee's personal status, the employee's family status, the employee's family members, the status of the employee's family members, the status of the employee's friends, the employee's past records, type of work performed, number of transactions performed, amount of transactions performed, maximum transaction amount, number of transactions with a specific counterparty, amount of transactions with a specific counterparty, significant These risk factors may include the number of changes to important records, the number of changes to important records related to a particular counterparty, the geographic area of the employee's home, the geographic area of the employee's office, the country in which the employee resides, nationality, the type of transaction made, the balance of the account, the inflow of funds, the outflow of funds, the transaction pattern, the number of transactions, the amount of transactions, the volume of transactions, the frequency of transactions, the derivative of the transaction, the location of the transaction, the time of the transaction, the country of the transaction, the sender of the remittance transaction, the location of the sender, the country of the sender, the nature of the sender, the recipient of the remittance transaction, the location of the recipient, the country of the recipient, the nature of the recipient, relationships, social status, political exposure, past transactions, etc. Indeed, numerous risk factors may be considered to determine an employee's risk of fraud. In one aspect of the present disclosure, different sets of risk factors may be used to detect different types of suspicious activity.
[0159]
[0164] In one aspect of the present disclosure, if a particular employee's total risk score is higher than the average total risk score of all employees with the same risk factors as the particular employee by a significant margin, the particular employee may have engaged in suspicious activity. The significant margin may be set in terms of a number of standard deviations or other reference value.
[0160]
[0165] To improve the accuracy of the detection results, multiple risk factors may be used instead of one risk factor. In one aspect of the present disclosure, if a particular employee's total risk score is higher by a significant margin than the average of the total risk scores of all employees who have the same set of risk factors as the particular employee, the particular employee may have engaged in some suspicious activity. In one example, the significant margin is set in terms of the number of standard deviations or other reference value.
[0161]
[0166] Indeed, by identifying risk factors associated with a group of entities and appropriately assigning a risk score to each risk factor, a statistical approach based on each entity's total risk score to identify suspicious activity of a particular entity is applicable to many other situations in addition to money laundering, terrorist financing, and employee fraud.
[0162]
[0167] In one aspect of the present disclosure, a number of risk factors are associated with a group of entities. Each of the risk factors may be assigned a risk score. Each entity may be given a total risk score based on a mathematical transformation, such as a summation. For example, other possible mathematical transformations include, but are not limited to, multiplication, division, and subtraction, sums of squares, squares of sums, mixtures of the above, and other similar methods of combining risk scores.
[0163]
[0168] In one aspect of the present disclosure, if a particular entity's total risk score is higher than the average of the total risk scores of all entities that have the same risk factors as the particular entity by a predetermined margin, the particular entity may have engaged in some suspicious activity. The predetermined margin may be set in terms of a number of standard deviations or other reference value.
[0164]
[0169] In another aspect of the present disclosure, if a particular entity's total risk score is higher by a predetermined margin than the average of the total risk scores of all entities that have the same set of risk factors as this particular entity, then this particular entity may have engaged in some suspicious activity.
[0165]
[0170] In one aspect of the present disclosure, the computer system identifies a transaction (or group of transactions) that caused a particular entity to have a total risk score higher than the average of the total risk scores of all entities. Such a transaction (or group of transactions) may be suspicious activity.
[0166]
[0171] The statistical approach described above is only one way to manage risk. Many other group comparison methods can also be used. Furthermore, suspicious activity may not be limited to illegal or prohibited activity. Activity becomes suspicious because it differs from normal activity. It may be harmless or even activity with good intentions. Therefore, investigation is often required to make a final decision on whether to report a detected case.
[0167]
[0172] In one aspect of the present disclosure, a responsible person investigates a newly detected case to determine whether it is illegal. The responsible person also reviews all past cases related to the suspect(s) of the newly detected case. If the responsible person agrees that the detected case is illegal, the computer system assists the responsible person in reporting the detected case. If the responsible person decides not to report the detected case, the responsible person inputs into the computer system a reason justifying the decision not to report the detected case.
[0168]
[0173] Following the 9 / 11 tragedies, the U.S. Congress passed the Unauthorized Online Gambling and Evasion Act (UIGEA) because online gambling could be a means for money laundering and terrorist financing activities. Regulation GG was established in response to this law. Regulation GG requires financial institutions to ask new customers during the account opening process whether they will engage in any online gambling activities. Because perpetrators know that online gambling is illegal, they often lie during the account opening process. As a result, the "question and answer" approach defined in Regulation GG is merely a formality. However, Regulation GG clearly states that it does not alter financial institutions' obligations to file SARs under the Bank Secrecy Act.
[0169]
[0174] In other words, if a perpetrator lies during the account opening process and actually conducts an illegal online gambling business, the financial institution is obligated to report the case to FinCEN through a SAR. In one aspect of the present disclosure, a computer system compares the senders and recipients of all funds transfer transactions during a certain period. If a customer sends a large amount of money to a recipient and receives a large amount of money from the same recipient during a certain period, such transactions may be deposits of wagers and payments of money earned from gambling activities between online gamblers and online gambling organizations. The computer system detects such cases as possible cases of illegal online gambling. Once a case is detected, further investigation is required.
[0170]
[0175] In one aspect of the present disclosure, because online gambling organizations typically transact with large amounts of money and with large numbers of clients, if the computer system detects a large number of transactions of large amounts of money associated with a customer, the computer system detects the customer as a possible online gambling organization. The computer system detects such cases as possible cases of illegal online gambling. When a case is detected, further investigation is required.
[0171]
[0176] In one aspect of the present disclosure, a computer system compares a list of known names of online gambling organizations with the sender and recipient of funds transfer transactions associated with a customer. If there is a match, the customer may be engaged in online gambling activity. The computer system detects this case as a possible case of illegal online gambling. Once a case is detected, further investigation is required.
[0172]
[0177] In addition to the aforementioned transaction pattern monitoring, the aforementioned group comparison method can also be applied to detect possible illegal online gambling activity. In one aspect of the present disclosure, all risk factors related to online gambling are identified. For example, these risk factors may include customer due diligence results, length of account history, customer industry, customer business type, number of names matching gambling organizations in transactions, customer geographic area, customer's country of headquarters, nature of the customer's business, business product type, business service type, business structure, customer occupation, nationality, past records, type of transactions conducted, account balance, fund inflow, fund outflow, transaction pattern, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivative, number of chargebacks, transaction location, transaction time, transaction country, sender of remittance transaction, sender location, sender country, sender characteristics, recipient of remittance transaction, recipient location, recipient country, recipient characteristics, relationship status, social status, political exposure, past transactions, etc. Indeed, many different risk factors may be considered to determine online gambling risk. As previously described in this disclosure, adjusted risk factors may also be used so that adjusted risk scores are applicable based on the size of the business.
[0173]
[0178] In one aspect of the present disclosure, risk factors are used to identify a group of customers having the same risk factors. If a particular customer has a total risk score higher than a reference value derived from the total risk scores of all customers having the same risk factors, the particular customer is likely to be involved in illegal online gambling. In another aspect of the present disclosure, a set of risk factors is used to identify a group of customers having the set of risk factors. If a particular customer has a total risk score higher than a reference value derived from the total risk scores of all customers having the same set of risk factors, the particular customer is likely to be involved in illegal online gambling. Reference values include the mean, median, average, mode, weighted average, and / or other statistical values. To simplify calculations, standard group statistics such as the mean, variance, and standard deviation can be derived to facilitate such comparisons among groups of customers.
[0174]
[0179] In one aspect of the present disclosure, a responsible person (or BSA officer) investigates the detected case to determine whether it is a true case of online gambling. The BSA officer also reviews all past cases related to the suspect in the newly detected case. If the BSA officer agrees that the detected case is a possible case of illegal online gambling, the computer system assists the BSA officer in filing a SAR with FinCEN. If the BSA officer decides not to file a SAR, the BSA officer enters into the computer system a reason justifying the decision not to report the detected case.
[0175]
[0180] The U.S. Congress passed the Fair and Accurate Credit Transactions Act (FACT Act) to protect consumers. Among other things, it requires businesses to identify and report instances of identity theft. Financial institutions are also required to file SARs when instances of identity theft are detected.
[0176]
[0181] In one aspect of the present disclosure, a computer system monitors consumer reports and other available information to detect credit freeze notices, address mismatch notices, and / or fraud or emergency alerts contained in consumer reports. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0177]
[0182] In one aspect of the present disclosure, a computer system monitors consumer reports and available information to detect consumer reports that exhibit activity patterns inconsistent with an applicant's or customer's past and usual activity patterns. For example, a recent significant increase in the volume of inquiries, an unusual number of recently established credit relationships, a material change in the use of credit, particularly with respect to recently established credit relationships, or accounts that have been closed for cause or identified as an abuse of account privileges by a financial institution or creditor may indicate an abnormal pattern. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0178]
[0183] In one aspect of the present disclosure, a computer system detects whether documents provided for identification purposes appear to have been tampered with or forged, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0179]
[0184] In one aspect of the present disclosure, the computer system detects whether the photograph or physical characteristics on the identification document are inconsistent with the appearance of the applicant or customer presenting the identification document, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible person.
[0180]
[0185] In one aspect of the present disclosure, the computer system detects whether other information on the identification document is inconsistent with information provided by the person opening the new account or presenting the identification document. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0181]
[0186] In one aspect of the present disclosure, the computer system detects whether other information on the identification document is inconsistent with readily available information on file with the financial institution or creditor, such as a signature card or recent check, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0182]
[0187] In one aspect of the present disclosure, the computer system detects whether an application appears to have been tampered with or forged, or torn and reassembled, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0183]
[0188] In one aspect of the present disclosure, the computer system determines whether the provided personal identifying information is consistent when compared against external sources used by financial institutions or creditors, such as if an address does not match any addresses in a consumer report, or if a Social Security Number (SSN) has not been issued or is listed in the Social Security Administration Death Master File. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0184]
[0189] In one aspect of the present disclosure, the computer system determines whether some personal identifying information provided by a customer is consistent with other personal identifying information provided by the customer. For example, there may be no correlation between SSN ranges and dates of birth. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0185]
[0190] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information is associated with known fraudulent activity as indicated by internal or third-party sources used by the financial institution or creditor. For example, an address on an application may be the same as an address provided on a fraudulent application, or a phone number on an application may be the same as a number provided on a fraudulent application. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0186]
[0191] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information is of a type commonly associated with fraudulent activity indicated by internal or third-party sources used by financial institutions or creditors, such as if the address on the application is fictitious, a mailbox, or a prison, or if the phone number is invalid or associated with a pager or answering service. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0187]
[0192] In one aspect of the present disclosure, the computer system determines whether the provided social security number is the same as that submitted by another person opening an account or another customer. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0188]
[0193] In one aspect of the present disclosure, the computer system determines whether the provided address or telephone number is the same as or similar to account numbers or telephone numbers submitted by an unusually large number of other people or other customers opening accounts. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0189]
[0194] In one aspect of the present disclosure, the computer system determines whether a person opening an account fails to provide all required personal identifying information at the time of application or in response to a notice that the application is incomplete. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0190]
[0195] In one aspect of the present disclosure, the computer system determines whether the provided personally identifiable information is consistent with personally identifiable information on file with the financial institution or creditor. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0191]
[0196] In one aspect of the present disclosure, the computer system determines whether a person opening an account is unable to provide authentication information, such as answers to challenge questions, beyond what is typically available from a wallet or consumer report. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0192]
[0197] In one aspect of the present disclosure, the computer system determines whether there is unusual use of the account or suspicious activity associated with the account, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0193]
[0198] In one aspect of the present disclosure, the computer system determines whether the institution or creditor receives a request for a new, additional, or replacement card or mobile phone, or a request to add an authorized user to the account, shortly after notification of a change of address for the account. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0194]
[0199] In one aspect of the present disclosure, the computer system determines whether a new revolving credit account is being used in a manner commonly associated with known fraudulent patterns, such as when a large portion of the available credit is used for cash advances or items easily convertible to cash (e.g., electronics or jewelry), or when a customer fails to make an initial payment or makes an initial payment but no subsequent payments. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0195]
[0200] In one aspect of the present disclosure, the computer system determines whether an account is being used in a manner consistent with an established pattern of activity on that account, such as a late or missed payment with no history of missed payments, a significant increase in the use of available credit, a significant change in purchasing or spending patterns, a significant change in electronic fund transfer patterns associated with a deposit account, or a significant change in telephone call patterns associated with a mobile phone account. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0196]
[0201] In one aspect of the present disclosure, the computer system determines whether an account that has been inactive for a significant period of time is being used (taking into account the type of account, expected usage patterns, and other relevant factors). If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0197]
[0202] In one aspect of the present disclosure, the computer system determines whether mail sent to a customer is repeatedly returned as undeliverable despite continued transactions occurring associated with the customer's account. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by a responsible party.
[0198]
[0203] In one aspect of the present disclosure, the computer system closely reviews all transactions when a financial institution or creditor is notified that a customer has not received a paper account statement, and if an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0199]
[0204] In one aspect of the present disclosure, the computer system closely reviews all transactions when a financial institution or creditor is notified of unauthorized charges or transactions related to a customer's account. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0200]
[0205] In one aspect of the present disclosure, the computer system closely reviews all transactions when a financial institution or creditor is notified by a customer, a victim of identity theft, law enforcement, or any other person that a fraudulent account has been opened for a person engaged in identity theft. If an instance of suspicious activity is detected, the computer system makes the detected instance available for review by responsible parties.
[0201]
[0206] In addition to monitoring transaction patterns as described above, the group comparison method described above can also be applied to detect possible cases of identity theft. Identity theft cases can be divided into two main categories. The first category involves cases in which a fraudster steals a victim's accounts, financial instruments, or identification documents to conduct an activity. In such situations, as described above, a computer system can detect activity that deviates from the victim's expected activity, which can be established from the victim's past activity.
[0202]
[0207] The second category involves cases where a victim's personal information is stolen to open a new account and / or initiate some new activity. In such situations, the victim is irrelevant from the start. Without the victim's true past activity, it is impossible to accurately establish the victim's expected activity for fraud prevention purposes. While it is possible to ask the perpetrator several questions and collect their answers during the account opening process with the intention of establishing the perpetrator's expected activity, this question-and-answer approach may not work because the perpetrator knows how to answer the questions to establish the expected activity in a way that does not trigger an alert.
[0203]
[0208] To detect identity theft when true past activity is unavailable, in one aspect of the present disclosure, all risk factors for a new account or new customer are identified. For example, these risk factors may include the customer's due diligence results, the customer's previous record with other businesses, the customer's credit report record, the customer's industry, the customer's business type, the customer's geographic area, the customer's country of address, the customer's business nature, the business's product type, the business's service type, the business's structure, the customer's occupation, nationality, past records, the type of transaction made, the account balance, the inflow of funds, the outflow of funds, the transaction pattern, the number of transactions, the transaction amount, the transaction volume, the transaction frequency, the transaction derivative, the number of chargebacks, the transaction location, the transaction time, the transaction country, the sender of the remittance transaction, the sender's location, the sender's country, the sender's nature, the remittance transaction recipient, the recipient's location, the recipient's country, the recipient's nature, the relationship status, the social status, the political exposure, past transactions, etc. Indeed, numerous risk factors may be considered to determine identity theft risk.
[0204]
[0209] In one aspect of the present disclosure, risk factors are used to identify a group of people with the same risk factors. If a particular person has a total risk score that is much higher than a reference value derived from the total risk scores of all people with the same risk factors, the particular person may be involved in an identity theft case. A set of risk factors can be used to identify a group of people with this set of risk factors. If a particular person has a total risk score that is higher than a reference value derived from the total risk scores of all people with the same set of risk factors, the particular person may be involved in an identity theft case. Reference values include the mean, median, average, mode, weighted average, and / or other statistical values. To simplify calculations, group statistics such as the mean, variance, and standard deviation can be derived to facilitate such comparisons within a group of people.
[0205]
[0210] In one aspect of the present disclosure, a responsible person (or compliance officer) investigates the detected case to determine whether it is a true case of identity theft. The compliance officer also reviews all past cases related to the newly detected case. If the compliance officer agrees that the case is a possible case of identity theft, the computer system assists the compliance officer in filing a SAR with FinCEN. If the compliance officer decides not to file a SAR, the compliance officer enters into the computer system a reason justifying the decision not to report the detected activity.
[0206]
[0211] The Office of Foreign Assets Control (OFAC) has a very simple rule that states that any business transactions with entities on a list issued by the Office of Foreign Assets Control are illegal. This list is commonly referred to as the "OFAC List." This rule applies to all U.S. persons and entities, including financial institutions. For example, Walmart has been fined by OFAC for violating this rule. U.S. financial institutions, which are under the strictest regulatory scrutiny, must naturally adhere to this rule strictly.
[0207]
[0212] Originally, this was a very simple rule. However, the implications of this rule have become much more complex over the past 20 years. A common problem occurs when a person misspells (including mistyping, mispronouncing, etc.) their own name. If an entity's name is misspelled but is on the OFAC list, financial institutions are still obligated to identify this entity as an entity on the OFAC list (commonly referred to as an OFAC match).
[0208]
[0213] A reasonable question is: How far can a name deviate from the original name on the OFAC list before it is classified as a "misspelling"? OFAC and government regulators have never provided detailed guidance on the answer to this question. A very common exercise that examiners or auditors can perform is to use infamous names like "Osama bin Laden" as a sample to test companies. Generally, companies are expected to identify all transactions related to "Osama bin Laden," "Osama Laden," "Osama Latin," "Latin Osama," "Latin Obama," etc. as possible OFAC matches. However, if the scope of deviations from OFAC names were broadened further, it is questionable whether financial institutions would be expected to identify the single word "Obama," the name of a former U.S. president, as a possible OFAC match. It is easy to see how such a simple OFAC rule has caused much confusion in recent years.
[0209]
[0214] In one embodiment of the present disclosure, an "OFAC match scale" is used to measure the degree of deviation. To measure the similarity between two names, the OFAC match scale generates a value called a "relative correlation" ("RC value"). For example, if a name has an RC value of 100%, it is an exact match with an OFAC name on the OFAC list. If a name has an RC value of 97%, it may differ from an OFAC name on the OFAC list by only one or two characters. If a name has an RC value of 0%, it is completely different from all OFAC names on the OFAC list.
[0210]
[0215] In one aspect of the present disclosure, name length also affects the RC value: for example, a 25-character name that differs from an OFAC name by only one character may have an RC value of 96%, while another 10-character name may have an RC value of 90%, even though it also differs from another OFAC name by only one character.
[0211]
[0216] Some long words, such as "international," "international," "limited," "company," and "organization," are commonly used in business names, and such words are also present on the OFAC name list. As a result, these long words generate higher RC values for businesses that use these long words in their names. To avoid unnecessary false positives, in one aspect of the present disclosure, commonly used long words may be replaced with shorter words to reduce their impact on the RC value. For example, the word "international" may be replaced with "intl."
[0212]
[0217] Additionally, some countries do not use the descriptions "first name" and "last name." As a result, when a person is asked to provide their first and last name, they may use names in a different order. "Osama Laden" may become "Laden Osama." In one aspect of the present disclosure, the OFAC match scale identifies possible "off-sequence" OFAC matches.
[0213]
[0218] Furthermore, some words are commonly used in a particular culture without contributing a clear distinction. For example, in Islamic cultures, "bin" means "son of" and "binti" means "daughter of." Legal names in Islamic cultures have either "bin" or "binti" in the name. For example, if a Muslim father is named "John," his daughter "Mary" would be legally named "Mary binti John," and his son "David" would be legally named "David bin John." In such a situation, the commonly used words "bin" and "binti" in Islamic names create a "false similarity" between the two Islamic names. To provide more scientifically accurate results, in one aspect of the present disclosure, the OFAC agreement scale may filter out these types of "trivial words" before calculating the RC value. Sometimes, names are translated into English based on sound. Therefore, in one aspect of the present disclosure, the OFAC agreement scale must measure sound agreement to determine the RC value.
[0214]
[0219] In one aspect of the present disclosure, a financial institution decides which threshold to use when performing an OFAC check. For example, if the financial institution uses a 75% threshold, a potential OFAC match is detected when a name has an RC value of 75% or greater. Because each financial institution may have different risk exposures, it is very likely that X is the best threshold for Financial Institution A, while Y is the best threshold for Financial Institution B. As a general guideline, the X or Y value is selected according to risk-based principles.
[0215]
[0220] Generally, the higher the threshold a financial institution uses, the fewer OFAC matches the institution will likely find. This saves time during the review process by avoiding more false positives. However, if the threshold is too high, the institution may miss plausible deviations from OFAC names, such as "Osama bin Laden." If the threshold is too low, the institution may mistakenly identify many of its clients as possible OFAC matches. Best practice is to find a trade-off between reviewing too many possible OFAC matches and missing true OFAC name deviations caused by spelling errors.
[0216]
[0221] In one aspect of the present disclosure, a user can randomly select several OFAC names from the OFAC list and find how the OFAC match scale responds to deviations from these selected OFAC names. The user can then determine what to call a "possible OFAC match" based on this test. It may be desirable to retain the results of this test for future review by auditors and examiners.
[0217]
[0222] It is possible that certain names are very close to OFAC names. For example, American Express is a highly reputable credit card company, but is often erroneously detected as an OFAC match due to the word "express." Therefore, to avoid this type of frequent false positive, in one aspect of the present disclosure, an exemption list is generated by the user, and these well-known, reputable companies are placed on the exemption list. Companies on the exemption list are classified as false positives, either automatically by the computer or manually by the user, when detected as a possible OFAC match.
[0218]
[0223] Very often, a company will have an OFAC officer who handles all OFAC-related matters. In one aspect of the present disclosure, when a financial institution's OFAC officer (e.g., a responsible person) detects a possible OFAC match with an RC value above a predetermined threshold, the OFAC officer investigates whether this is a true OFAC match. If the OFAC officer is convinced that it is a true match, the OFAC officer must handle the case in accordance with guidelines issued by the Office of Foreign Assets Control. According to OFAC regulations, in some cases, the OFAC officer may be required to block a transaction to prevent a person on the OFAC list from benefiting from the transaction. If, after investigation, the OFAC officer determines that the OFAC match is a false positive, the OFAC officer must enter into a computer system a reason justifying the decision not to report the OFAC match to the Office of Foreign Assets Control and / or not to block the transaction.
[0219]
[0224] Section 314(a) of the USA PATRIOT Act requires financial institutions to match names on the 314(a) list, which is periodically published by FinCEN. Computer systems can process 314(a) compliance matters using an approach similar to the processing of OFAC compliance matters, as described above.
[0220]
[0225] Sometimes, the 314(a) list also includes additional personal identifying information, such as identification document number, date of birth, address, etc. In one aspect of the present disclosure, in addition to the methods described above for detecting potential OFAC matches, personal identifying information, such as identification document number, address, and / or date of birth, is used by a computer system to determine whether a detected 314(a) match is a true match. This approach can reduce false positives in the 314(a) matching process.
[0221]
[0226] In one aspect of the present disclosure, when a compliance officer (e.g., a director) at a financial institution detects a possible 314(a) match with an RC value above a predetermined threshold, the compliance officer investigates whether this is a true 314(a) match. In one aspect of the present disclosure, if the compliance officer believes it is a true match, the compliance officer reports the 314(a) match to FinCEN. If, after investigation, the compliance officer determines the 314(a) match is a false positive, the compliance officer enters a reason into a computer system justifying why the 314(a) match is not reported to FinCEN.
[0222]
[0227] In one aspect of the present disclosure, a computer system receives customer information and transaction data from a core data processing system of a financial institution or from other data processing systems that may be internal or external to the financial institution. The customer information may include background information.
[0223]
[0228] In one aspect of the present disclosure, a computer system receives information regarding suspicious activity observed by frontline personnel. For example, the computer system may receive information entered by the frontline personnel. The computer system may also receive information provided by other internal or external sources.
[0224]
[0229] Although a "financial institution" is used as an example for ease of explanation, the present disclosure applies to other types of businesses as well. In general, any enterprise that must comply with laws and regulations may employ the intelligent alert system described in this disclosure.
[0225]
[0230] In one aspect of the present disclosure, the risk scores or degrees of risk factors may be assigned by a computer software module, a person designing or adjusting the system, or a user using the system. In most cases, the absolute value of the risk score is not important, and the relative relationship between all the risk scores may be more important.
[0226]
[0231] Furthermore, a subject's total risk score should only fluctuate within a reasonable range. In one embodiment of the present disclosure, if a subject's total risk score suddenly increases and exceeds a threshold, the subject may have engaged in suspicious or abnormal activities. That is, if the difference between the subject's first total risk score and the subject's second total risk score is greater than an increase threshold, and the first total risk score is less than the second total risk score, the subject may have engaged in suspicious or abnormal activities. In another embodiment of the present disclosure, if a subject's total risk score suddenly decreases significantly, the subject may also have engaged in suspicious or abnormal activities. That is, if the difference between the subject's second total risk score and the subject's first total risk score is greater than a decrease threshold, and the first total risk score is greater than the second total risk score, the subject may have engaged in suspicious or abnormal activities. Therefore, when a total risk score suddenly increases or decreases significantly, an alert is sent to investigators, BSA officers, compliance officers, or other responsible parties who will be investigating the subject.
[0227]
[0232] A subject's observation data may fluctuate from time to time. Therefore, the intelligent warning system may allow a certain range of variation from the subject's total risk score to avoid false alarms. In one aspect of the present disclosure, the intelligent warning system increases the subject's allowable total risk score variation range when the subject's total risk score is lower than a threshold. In another aspect of the present disclosure, the intelligent warning system decreases the subject's allowable total risk score variation range when the subject's total risk score is higher than a threshold. The allowable variation range may be determined (e.g., set) by a software module, a person who designs the system, a person who adjusts the system, or a person who uses the system.
[0228]
[0233] For example, if a subject's total risk score is higher than the average of all subjects' total risk scores plus a certain number of standard deviations of all risk scores, such as four standard deviations, the intelligent alert system may modify the subject's allowable total risk score variation range to be within half a standard deviation without triggering an alert. In another example, if a subject's total risk score is within the average of all subjects' total risk scores plus a certain number of standard deviations, such as three standard deviations, the intelligent alert system may allow the subject's total risk score to vary within one standard deviation without triggering an alert.
[0229]
[0234] In yet another example, if a subject's total risk score is within a certain number of standard deviations, such as two standard deviations, above the mean of all subjects' total risk scores, the intelligent alert system may allow the subject's total risk score to fluctuate within a range of 1.5 standard deviations without triggering an alert. In yet another example, if a subject's total risk score is within a certain number of standard deviations, such as one standard deviation, above the mean of all subjects' total risk scores, the intelligent alert system may allow the subject's total risk score to fluctuate within a range of two standard deviations without triggering an alert.
[0230]
[0235] In the field of machine learning, a negative is a set of data that does not trigger an alert. A true negative is a set of data that does not trigger an alert and does not contain true cases to trigger an alert. A false negative is a set of data that does not trigger an alert but does contain true cases to trigger an alert that the system missed. As an example, a false negative money laundering case could result in a financial institution being fined by the U.S. government if the false negative case is discovered by the U.S. government. Therefore, it is desirable to prevent false negatives in alert systems designated to prevent money laundering (e.g., anti-money laundering alert systems).
[0231]
[0236] In the US financial institution anti-money laundering alert system, genuine cases of money laundering are reported to FinCEN, a US government agency. FinCEN has a set of communication protocols. Based on FinCEN's communication protocols, US financial institutions can report cases to FinCEN by sending a file from the anti-money laundering alert system to FinCEN's computer system.
[0232]
[0237] Traditionally, rule-based systems are used to detect suspicious activity, with each rule potentially triggering an alert. Many financial institutions have used rule-based approaches that can trigger numerous alerts. For example, there are over 200 countries in the world. If a financial institution uses a rule-based approach to monitor wire transfers to and from each country, the financial institution may have over 200 branches at the country decision node of the decision tree. As another example, there are thousands of different industries. If a financial institution uses a rule-based approach to monitor wire transfers to and from each industry, the financial institution may have thousands of branches at the industry decision node of the decision tree. Countries and industries are two of many risk categories that pose a money laundering risk. Similarly, wire transfers are one of many transaction types that pose a money laundering risk. For example, cash, check, ACH, ATM, credit card, debit card, and letter of credit are other possible transaction types.
[0233]
[0238] There are many risk factors for money laundering. There are many (e.g., millions) possible combinations of branches to form a path from the root of the decision tree to the leaf nodes of the decision tree. In other words, a rule-based system may use millions of rules to cover the entire range of money laundering risks and detect suspicious money laundering activities. A rule-based system with a limited number of rules may have an increased number of false negatives (e.g., the system misses true cases of money laundering) and a high number of false positives (e.g., the number of impurities in the leaf nodes of the decision tree increases, and the classification goal cannot be achieved). Due to the number of false negatives and false positives when a rule-based approach is used, financial institutions hire investigators to review a large number of alerts. It is difficult for financial institutions to mitigate all false negatives with a rule-based system.
[0234]
[0239] In the field of machine learning, traditional systems consider 70% accuracy to be satisfactory. Training a machine learning model to have a high accuracy, such as 100%, is difficult, if not impossible. Unfortunately, while 70% accuracy may be effective for some purposes, this 70% target cannot meet regulatory standards, such as those set by the U.S. government. As mentioned, financial institutions may face severe regulatory penalties if they do not detect certain activities, such as money laundering. Therefore, financial institutions are unlikely to use an alert system with 70% accuracy. Therefore, traditional machine learning models are not satisfactory for intelligent anti-money laundering alert systems.
[0235]
[0240] According to an embodiment of the present disclosure, an intelligent anti-money laundering alert system uses a risk scoring approach. Each risk factor or degree of a risk factor may be similar to a branch in a rule-based system. Thus, as described in this disclosure, a risk scoring process for generating an overall risk score from many risk factors may integrate information from many rules into the overall risk score. For example, if the overall risk score is generated from 10,000 risk factors, a user need only pay attention to alerts with an overall risk score above a threshold, without having to evaluate each of the 10,000 risk factors. When a rule-based approach is used, each risk factor may have two possible outcomes: match or mismatch. The total number of possible combinations of outcomes for 10,000 risk factors is 2 to the power of 10,000 (e.g., 210,000). Thus, an assessment based on the overall risk score effectively replaces the need to evaluate each of the 2 to the power of 10,000 (e.g., 210,000) possible outcomes. These 210,000 results could potentially generate 210,000 different types of alerts, so an intelligent anti-money laundering alert system could avoid at least 210,000 alerts. Thus, an intelligent anti-money laundering alert system is a considered improvement over traditional rule-based systems.
[0236]
[0241] A single total risk score can replace many rules, but not all rules. For example, if a person frequently deposits a certain amount of cash (e.g., $9,900) that is slightly below the CTR reporting threshold of $10,000, a financial institution is required to report this person to the Financial Crimes Enforcement Network (FinCEN) as a case of structuring. It is difficult to accurately detect cases of structuring based on the total risk score. Therefore, a warning system based on risk score-based technology may include several rules in addition to the criteria based on the risk score.
[0237]
[0242] In one aspect of the present disclosure, the intelligent anti-money laundering alert system uses risk score-based scenarios instead of rules. In one example, the intelligent anti-money laundering alert system may use approximately 20 to 30 scenarios. The scenarios may include both risk score-based scenarios and non-risk score-based scenarios.
[0238]
[0243] In addition to or instead of a scenario, other conditions can be used to generate an alert. For example, a computer system such as a machine learning network can be trained to generate a model. After training, the discriminant used by the model can be converted into an if-then conditional format to trigger an alert.
[0239]
[0244] For purposes of this disclosure, a scenario may be defined as a condition or set of conditions that can trigger an alert or can be used to categorize a subject for a particular purpose. For example, a customer with a total risk score within a particular range would not trigger an alert. Further, in this example, the total risk score may categorize the customer into a particular risk category, such as high risk, medium risk, or low risk. As another example, a customer who was previously a suspect in a suspicious activity report (SAR) would not trigger an alert. In this example, the customer may be categorized into a particular category, such as a prior SAR suspect, or another similar category. As another example, a customer who matches an OFAC list, a 314(a) list, a politically exposed person list, and / or other list may be categorized into one or more categories.
[0240]
[0245] A scenario may be composed of a rule, a set of rules, a criterion, or a set of criteria based on rules, facts, behavioral patterns, risk scores, risk dimensions, total risk scores, special categories, mathematical models, and / or machine learning models. A scenario may trigger an alert by using rule-based methods, behavior-based methods, risk-based methods, model-based methods, and / or machine learning-based methods (e.g., artificial intelligence-based methods). An intelligent alert system may include one or more scenarios.
[0241]
[0246] As mentioned, an alert may be triggered by a scenario. A scenario may be flagged when one or more conditions are met. A potential case that triggered an alert may be referred to as a positive. A potential case may include one or more alerts. Thus, the cause of a potential case may be one or more scenarios. A potential case, or positive, may be investigated. A true positive may refer to a potential case (e.g., a positive) that is a true case. If an investigation indicates that the potential case is not a true case, the potential case may be referred to as a false positive. As a result, the false positive may be dismissed, and the associated alert may be dismissed as a false alert. A true positive may be reported to authorities, such as FinCEN or law enforcement.
[0242]
[0247] In one configuration, the posterior probability can be estimated via Bayes' principle. The product of the posterior probability and the evidence is the prior probability multiplied by the class likelihood. Using the application of reporting suspected money laundering activity to FinCEN as an example, Bayes' equation is p(S / c)p(c)=p(c / S)p(S). The evidence p(c) is the probability of a potential case triggered by cause c among all potential cases. The class likelihood p(S) is the probability of a true positive S (e.g., a true SAR case) among all potential cases. The prior probability p(c / S) is the probability of a true positive triggered by cause c among all true positives. As a result, the posterior probability p(S / c) can be determined as follows: p(S / c)=p(c / S)p(S) / p(c). The posterior probability P(S / c) is also the conditional probability that a potential case triggered by cause c is a true positive. That is, the conditional probability P(S / c), derived from historical data, is a best estimate of the future probability that a potential case triggered by cause c will become a true positive. As such, posterior probability can also be called the conditional probability for the future or the future conditional probability.
[0243]
[0248] Many risk factors (e.g., thousands of risk factors) can affect the risk of money laundering. In one configuration, when risk score-based scenarios are used as part of the scenarios, the number of scenarios used by the intelligent money laundering warning system is not large. As an example, the intelligent money laundering warning system may use 30 scenarios. A potential case may be triggered by one or more of the scenarios. In this example, a vector with 30 elements may represent the possible causes of a potential case. As a result, in this example, there are 230 different possible combinations of causes. Each triggered scenario is identified by a flag. For example, the cause vector may be initialized to have a value of “0” for each element. When a scenario is triggered, the value of the element corresponding to this scenario may change from “0” to another value, such as “1.”
[0244]
[0249] For example, if a potential case is triggered by a first scenario and a third scenario, the vector x may contain a "1" in the first and third positions and a "0" in all other positions. That is, the vector may be represented as x = (1, 0, 1, 0, 0, 0, ... , 0). As another example, if a potential case is triggered by a third scenario and a fourth scenario, the third and fourth positions of the vector may contain a "1" value and all other positions may contain a "0" value. In this example, the vector x may be represented as x = (0, 0, 1, 1, 0, 0, ... , 0). In the present disclosure, a vector containing scenarios (e.g., causes) for triggering an alert for a potential case may be referred to as a cause vector.
[0245]
[0250] A scenario may include one or more conditions for classifying a subject into one or more categories, but the scenario itself will not trigger a potential case. A potential case may be triggered by multiple scenarios in the associated cause vector. For example, if a scenario attempts to classify a subject into the ex-SAR suspect category, such a scenario would not trigger a money laundering alert by itself. However, if a customer is an ex-SAR suspect and triggers another scenario (e.g., remittance to a high-risk country of over $10 million), a potential case may be triggered. Furthermore, a cause vector may have two scenarios: one for remittance transactions and another for ex-SAR suspects. It is a good idea to include various special categories (e.g., ex-SAR suspects) in the cause vector because these special categories may increase the accuracy of suspicious activity detection.
[0246]
[0251] A potential case with multiple triggered scenarios in its cause vector may be more likely to be a true positive. For example, if a customer receives $250,000 via wire transfer, one scenario in the cause vector may be flagged (e.g., triggered). This cause vector with one flagged scenario may be registered as a potential case, and it may or may not be a true money laundering case. Similarly, if the customer withdraws $250,000, another scenario in the cause vector may be flagged. Still, this potential case may or may not be a true money laundering case.
[0247]
[0252] However, if a customer receives a wire transfer of $250,000 and then withdraws $250,000 in cash from their account, two different scenarios may be flagged in the cause vector. A cause vector with two flagged scenarios may be registered as a potential case, which is likely to be a true money laundering case because the combined activity described by these two different scenarios matches a common money laundering behavior pattern. Therefore, rather than calculating the conditional probability based on a single flagged scenario, it is desirable to calculate the conditional probability of a potential case based on a cause vector with multiple flagged scenarios.
[0248]
[0253] If a causal vector has 30 scenarios, each scenario has two possibilities (e.g., triggered or not triggered), so the possible combinations of the 30 scenarios can be up to 2. However, because no case is triggered if none of the scenarios are triggered, the total number of possible combinations for triggering a case is (2-1). Each combination may have a unique conditional probability for triggering a potential case. Because 2 is a very large number, calculating these conditional probability values may be impractical. In practice, a potential case averages five or fewer simultaneously triggered scenarios. Therefore, the actual total number of significant combinations of scenarios that can trigger a potential case is a much smaller number and may be managed via a computing device associated with the intelligent alert system. For example, if the maximum number of possible scenarios in a potential case is 5, the total number of possible potential cases that can be triggered by these 30 scenarios is C(30,1) + C(30,2) + C(30,3) + C(30,4) + C(30,5), where C(m,n) is the possible number of different choices for selecting n objects from m targets. For example, since there are 30 possible choices for selecting one object from 30, C(30,1) is 30. C(30,2) is 435. C(30,3) is 4,060. C(30,4) is 27,405. C(30,5) is 142,506. The total number of possible causal vectors is 174,436. These causal vectors and their associated conditional probability values can be managed via a database associated with the computing device and the intelligent alert system.
[0249]
[0254] Investigators may use an intelligent alert system to investigate potential cases triggered by a causal vector. A causal vector may include multiple flagged scenarios. A potential case may be a false positive or a true positive. A true positive refers to a potential case that is a true case. A false positive refers to a potential case that is not a true case. If it is a false positive, all alerts for the potential case are dismissed as false alerts. If it is a true positive, the potential case becomes a true case that may be reported to authorities such as FinCEN.
[0250]
[0255] Investigating a single potential case generally takes time. In the United States, it is common for large financial institutions to employ hundreds of investigators. Each investigator is tasked with investigating whether potential cases triggered by various anti-money laundering systems are true cases of money laundering. If there are true cases of money laundering, U.S. law requires the financial institution to report the money laundering case to FinCEN within 30 days. However, as mentioned above, whether a potential case is true is a subjective opinion of the investigator.
[0251]
[0256] Financial institutions are protected by the safe harbor regulations and are not penalized if investigators report false positives as true money laundering cases. Generally, because there are significant regulatory penalties for failing to report true money laundering cases to FinCEN, it is advisable to report potential cases to FinCEN rather than dismiss them. Therefore, it is common practice for investigators to treat potential cases as true positives as long as there is reasonable doubt. Under current U.S. law, investigators are not required to prove that a potential case is a true case. In other words, investigators tend to report potential cases when they believe it is likely to be a true case. This also means that probability plays a role in this decision-making process.
[0252]
[0257] A user's decision-making can be improved based on knowledge of the conditional probability p(S / x) that a potential case will become a true SAR case based on a causal vector x. For example, if the conditional probability is greater than a threshold, the user may wish to report the case to FinCEN without spending time investigating. In one configuration, the intelligent alert system automatically reports a case to the appropriate entity (e.g., FinCEN) when the conditional probability for the case is greater than a threshold. The threshold may be set by a software module, a person designing or tuning the system, and / or a user of the system. Alternatively, the threshold may be set by the intelligent alert system, which learns the user's preferences by evaluating the user's past behavior. For example, if a user often submits SARs when the conditional probability of a causal vector is greater than a value Z, the system can use the value Z as a threshold to automatically submit SARs for the user in the future. In one configuration, the system stores potential cases in a database to determine the conditional probability. For each potential case, the system also stores the associated causal vector. The system may also store the results of the investigation, such as whether the potential case triggered by the causal vector was accepted by the investigator as a true positive or rejected by the investigator as a false positive.
[0253]
[0258] As a user continues to use the intelligent alert system, the system accumulates historical data in a database. In one aspect of the present disclosure, over any given period of time, the system may determine from the database how many potential cases were triggered by cause vector x and how many of the potential cases triggered by cause vector x became true positives (e.g., SAR cases reported to FinCEN). The ratio of the number of true positives triggered by the cause vector to the number of potential cases triggered by the cause vector is the conditional probability p(S / x). The conditional probability may also be referred to as the posterior probability. The posterior probability indicates the probability that a future potential case triggered by the cause vector will become a true case reported to FinCEN. In general, the conditional probability of a potential case is equivalent to the conditional probability of the cause vector that triggered the potential case.
[0254]
[0259] In one aspect of the present disclosure, the intelligent alert system calculates and displays a conditional probability for each potential case based on its cause vector. The conditional probability indicates the probability that a potential case triggered by the cause vector will be a true positive reported to FinCEN. In another aspect of the present disclosure, the intelligent alert system accepts the potential case as a true positive and reports it to FinCEN in response to the conditional probability of the cause vector being higher than a predetermined value. This predetermined value is also referred to as a true positive acceptance threshold.
[0255]
[0260] The intelligent alert system may also reject a potential case as a false positive in response to the conditional probability of the causal vector being less than a false positive rejection threshold. The false positive rejection threshold and true positive acceptance threshold may be set by a software module, a person designing or tuning the system, and / or a user of the system. Alternatively, these thresholds may be set by the intelligent alert system learning user preferences by evaluating the user's past behavior. For potential cases that are neither accepted as true positives nor rejected as false positives, an investigator may manually review the potential cases and determine whether each of the potential cases is a false positive or a true positive.
[0256]
[0261] The data for determining the conditional probabilities may be obtained over a period of time. For example, the period may be the past 12 months, the past three years, or any period of time. In one configuration, the conditional probabilities are determined from a rolling period that continues forward. For example, if the environment (e.g., company policies, customer demographics, products, services, etc.) changes, older probability values may no longer be accurate after the change. Furthermore, if the financial institution modifies the scenario, the older probability values may be affected. Therefore, a rolling period (e.g., the past three years) provides the intelligent alert system with the ability to continue self-adjusting to generate up-to-date, accurate probability values.
[0257]
[0262] Many computer systems perform data processing in batches (e.g., one batch per month). A number of batches can be used instead of a period to define the amount of historical data used in the probability calculation. For example, a computer system can use a rolling period of the past 36 batches instead of a rolling period of the past three years if the computer system performs one batch per month.
[0258]
[0263] In one configuration, the intelligent warning system intentionally leaves some potential cases for the human investigator to process. The intelligent warning system can use the results of these cases to train the system, i.e., adjust the probability values to better fit the current environment. Thus, the intelligent warning system is a learning system that improves its predictions as more potential cases are evaluated by the human investigator.
[0259]
[0264] The intelligent alert system may generate a flag or display a message about a potential case triggered by a causal vector when the causal vector has not generated a potential case within a specified period of time. In such circumstances, a user may manually investigate the potential case to determine whether it is a false positive or a true positive. The results of the manual investigation may be used to calculate a conditional probability value for the causal vector. The calculated conditional probability value may be used to evaluate future potential cases. This manual investigation process has the same effect as supervised training and increases the accuracy and reliability of the intelligent alert system.
[0260]
[0265] The intelligent alert system may also display or link to past potential cases and / or true positives triggered by the causal vector. In addition, users can view additional details (e.g., drill down) for each case. Thus, investigators can use historical data as a reference when deciding whether to pursue a potential case.
[0261]
[0266] The system may also display or link to past potential cases triggered by the same suspect as the current potential case and the decisions regarding those potential cases. Investigators can drill down to detailed background and transaction information for the suspect. As a result, investigators can determine whether the current potential case is a false positive or a true positive.
[0262]
[0267] In some cases, there may not be enough cause to report a current potential case to authorities. However, when the current potential case is combined with past potential cases, the cause for reporting may be sufficient. Under such circumstances, the true cause for reporting the case is composed of the cause vector of the current potential case plus the cause vectors of past potential cases. The past potential cases may be referred to as previous potential cases. A composite cause vector may be used for this true cause. A composite cause vector may be a combination of multiple cause vectors of multiple potential cases.
[0263]
[0268] As an example, the cause vector x1 of the current case may have a "1" in the first and fifth positions of the vector and a "0" in all other positions (e.g., x1 = (1,0,0,0,1,0,0,0)). In this example, the cause vector x2 of a past potential case may have a "1" in the third and fifth positions and a "0" in all other positions (e.g., x2 = (0,0,1,0,1,0,0,0)). The composite cause vector x3 (e.g., the combination of x1 and x2) may have a "1" in the first, third, and fifth positions and a "0" in all other positions (e.g., x3 = (1,0,1,0,1,0,0,0)). Although the above example uses only one cause vector from one past potential case, a composite cause vector may be composed of multiple cause vectors from multiple past potential cases.
[0264]
[0269] In one configuration, an investigator manually reviews multiple past potential cases and a current potential case to determine whether the combined case is a false positive (e.g., should not be reported) or a true positive (e.g., should be reported). The results of the manual review can be used to calculate a conditional probability value p(S / cbv) (e.g., a posterior probability value) for a composite cause vector cbv. The composite cause vector cbv is a combination of the cause vector of the current potential case with one or more cause vectors of past potential cases.
[0265]
[0270] In some cases, it may be difficult for the intelligent alert system to know which past potential cases have been investigated by investigators, so the intelligent alert system may prompt the investigator to select past potential cases to be combined with the current case to be reported to authorities.
[0266]
[0271] Additionally, in some cases, it may be difficult for the intelligent alert system to know which scenario in the composite causal vector or causal vector caused the investigator to report a potential case, and therefore the intelligent alert system may prompt the investigator to select the scenario that caused the investigator to report a potential case.
[0267]
[0272] Many reports of suspicious activity require investigators to provide a comment or narrative for a potential case. To improve processing time, it is desirable for the intelligent alert system to automatically populate the comment or narrative for a reported case. Generally, the information for writing the comment or narrative consists of background and transaction information for the suspect. Because this information is stored in a database, the intelligent alert system can learn from the user how to write the comment or narrative, as described later in this disclosure.
[0268]
[0273] In one aspect of the present disclosure, the intelligent alert system prompts an investigator to select past potential cases to be combined with a current potential case for reporting. Based on the causal vectors of the selected past potential cases and the causal vector of the current potential case, the intelligent alert system prepares a commentary or narrative. The prepared commentary or narrative is provided in a report about the combined cases.
[0269]
[0274] When the intelligent alert system writes a comment or narrative, it may also identify a composite cause vector for the reported case. Thus, a conditional probability value p(S / cbv) may be associated with the identified composite cause vector cbv based on the results of the human investigation.
[0270]
[0275] The intelligent alert system may prompt the investigator to select a scenario of the cause vector or composite cause vector that caused the investigator to report the potential case. Based on the selected scenario, the intelligent alert system prepares a comment or narrative to be included in the report for the case. These selected scenarios form the true cause vector of the reported case. The scenario of the true cause vector of the reported case is identified. A conditional probability value of the true cause vector may be calculated based on the results of the human investigation.
[0271]
[0276] Because each person may have their own unique writing style (or preferences), an investigator may initially dislike the comments or narrative generated by the intelligent alert system. If the investigator dislikes the comments or narrative generated based on a selected scenario and has no way to modify it, the investigator will not bother selecting the scenario to allow the intelligent alert system to generate the comments or narrative. Under such circumstances, the intelligent alert system cannot learn the true reasons why the investigator decided to report the case to authorities. As a result, the intelligent alert system may not be able to calculate the future conditional probability value of the true causal vector based on the results of human investigations.
[0272]
[0277] It is therefore desirable for the intelligent alert system to learn and adapt to the writing style (or preferences) of the researcher. In one configuration, the intelligent alert system learns the writing style (or preferences) of the researcher and generates future comments or narratives based on the writing style (or preferences) of the researcher.
[0273]
[0278] In one configuration, to learn a person's writing style (or preferences), the intelligent alert system displays a commentary or narrative for the initially selected scenario based on a pre-stored default commentary or narrative for the initially selected scenario. The pre-stored default commentary or narrative consists of two main parts. The first main part consists of facts, such as the suspect's name, identifying information, suspect's background, suspect's relationships, event location, event description, event date and time, information related to the event, and transaction details. The second main part may include words, phrases, sentences, symbols, etc. used to link facts to one another. These words, phrases, sentences, symbols, etc. are collectively referred to as "linking words."
[0274]
[0279] Facts may be obtained from stored data or information associated with the intelligent alert system. Researchers rarely modify stored facts. Researchers may modify linking words based on the researchers' writing style (or preferences). Thus, the intelligent alert system tracks facts and linking words for comments and narratives. The intelligent alert system may also track where facts are stored in memory (e.g., a database) and the relationships between those facts.
[0275]
[0280] Generally, a person's writing style (or preference) is determined by the order (e.g., format) of presentation of link words and facts. Because researchers should avoid changing facts, including related facts, writing style (or preference) will not be determined solely based on fact selection. In some cases, when the same scenario finds two different instances, the facts may be different. Nevertheless, the same researcher will not change the order (e.g., format) of presentation of link words and facts in their comments or narratives because their writing style (or preference) is the same.
[0276]
[0281] In one configuration, the intelligent alerting system provides editing capabilities for the investigator to add, delete, or modify linking words that link facts to one another. The intelligent alerting system may provide editing capabilities for the investigator to add, delete, or modify facts in the narrative. The intelligent alerting system may provide editing and database search capabilities for the investigator to extract and insert additional facts from a database into the narrative.
[0277]
[0282] After the researcher revise the comment or narrative for the originally selected scenario, the researcher may remember this revised comment or narrative as the next default comment or narrative. In the future, when the researcher reselects the originally selected scenario in another instance, a revised comment or narrative (e.g., the next default comment or narrative) based on a different set of facts may be displayed for the researcher to edit. After several revisions, the researcher may become satisfied with the then-current revised version and not want to edit it again. Through this evolutionary revision process, the intelligent alert system learns from the researcher and generates comments or narratives that match the researcher's writing style (or preferences).
[0278]
[0283] The intelligent alerting system can process a next selected scenario based on the same approach as described above for the first selected scenario. The intelligent alerting system can process other selected scenarios in the same manner. Over time, the intelligent alerting system gradually learns how to write comments or narratives for each scenario based on the investigator's preferences.
[0279]
[0284] As mentioned, based on the learning, the intelligent alert system can automatically generate comments or narratives on behalf of the investigator. Based on aspects of the present disclosure, the investigator does not need to write the comments or narratives. The investigator can select a scenario, and in response, the intelligent alert system automatically fills out the SAR form and comments or narratives. The intelligent alert system can then report the case to the appropriate authorities. Currently, investigators may spend several hours writing comments or narratives for SAR cases. The intelligent alert system can reduce the investigator's considerable effort.
[0280]
[0285] In some cases, a person's writing style may be affected by their mood. For example, a person in a good mood may write a detailed narrative. As another example, a person in a bad mood may write a poorly written or incomplete narrative. Aspects of the present disclosure eliminate the influence of a human writer's mood on a narrative so that the narrative maintains a consistent standard.
[0281]
[0286] In an exemplary situation, when an intelligent alert system detects that customer John Doe deposited $9,990 into an account at Bank ABC on June 1st and $9,995 on June 2nd, an alert may be generated using the default narrative as follows: John Doe teeth, June 1st to $9,990 of, June 2 to $9,995 of ABC BankIn this example short narrative, the underlined words are facts and the remaining words are linking words.
[0282]
[0287] In one example, the researcher might change the narrative to: John Doe teeth, June 1st to $9,990 of, June 2 to $9,995 of ABC Bank This is a typical cash structuring pattern, so we will report this case as suspicious activity pursuant to the Bank Secrecy Act. In the above narrative, the underlined words are facts and the remaining words are link words. When the investigator saves the SAR form for John Doe, the intelligent alert system remembers the revised narrative as the default narrative.
[0283]
[0288] At a later point in time, the intelligent alert system may detect customer Jack Daniel depositing $9,999 into an account at Bank ABC on July 1 and $9,999 on July 2. In response, the intelligent alert system may generate a SAR case using the default narrative as follows: Jack Daniel teeth, July 1st to $9,999 of, July 2nd to $9,999 of ABC Bank This is a typical cash structuring pattern, and we will be reporting this as suspicious activity in accordance with the Bank Secrecy Act."
[0284]
[0289] In one example, an investigator might change this narrative to the following narrative: “Pursuant to the Bank Secrecy Act, financial institutions are required to report cash structuring activity through suspicious activity reports (SARs). Jack Daniel but, July 1st to $9,999 of, July 2nd to $9,999 of ABC BankThis is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, we are reporting this case as a suspicious structuring activity through a SAR." When the investigator saves the SAR form about Jack Daniel's, the intelligent alert system remembers the revised narrative as the default narrative.
[0285]
[0290] In a later period, the intelligent alert system detects customer Jim Beam depositing $9,980 into an account at Bank ABC on August 3 and $9,985 on August 4. In response, the intelligent alert system may generate a SAR case using the default narrative as follows: "Pursuant to the Bank Secrecy Act, financial institutions are required to report cash structuring activity through suspicious activity reports (SARs). Jim Beam but, August 3 to $9,980 of, August 4th to $9,985 of ABC Bank This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, we are reporting this case as a suspicious structuring activity through the SAR."
[0286]
[0291] Investigators may want to look at the above narrative and add a few words such as: “Pursuant to the Bank Secrecy Act, financial institutions are required to report cash structuring activities through suspicious activity reports (SARs). Jim Beam but, August 3 to $9,980 of, August 4th to $9,985 of ABC Bank This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, we are reporting this case as a suspicious structuring activity through SAR. Jim Beam teeth, March 1, 2019The average account balance for the past three months is $123,197 During this case review process, the investigator included additional facts extracted from the Intelligent Warning System database. These additional facts are underlined in the following sentence: Jim Beam teeth, March 1, 2019 The average account balance for the past three months is $123,197 When the investigator saves the SAR form about Jim Beam, the intelligent alert system remembers the revised narrative as the default narrative.
[0287]
[0292] In yet another later period, the intelligent alert system detects customer Remy Martin depositing $9,998 into an account at Bank ABC on September 5 and $9,998 on September 6. In response, the intelligent alert system may generate a SAR case using the default narrative as follows: "Pursuant to the Bank Secrecy Act, financial institutions are required to report cash structuring activity through suspicious activity reports (SARs). Remy Martin but, September 5 to $9,998 of, September 6 to $9,998 of ABC Bank This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, we are reporting this case as a suspicious structuring activity through SAR. Remy Martin teeth, February 15, 2019 The average account balance for the past three months is $83,225 is."
[0288]
[0293] An investigator may look at the above narrative and decide that no further changes are necessary. Until the investigator makes changes in the future, any cases detected by the same scenario will use the following comment or narrative: "In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activity through suspicious activity reports (SARs). (Suspect name) but, (First deposit date) to (First cash transaction amount) , (Second deposit date) to (Second cash transaction amount) of (Bank name) This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, we are reporting this case as a suspicious structuring activity through SAR. (Suspect name) teeth, (Account opening date) The average account balance for the past three months is (Average account balance) The underlined words will be extracted from the intelligent alert system's database. The remaining words in the narrative are the preferred link words used by the investigator that the intelligent alert system has learned from the investigator based on the style of their narratives of past cases detected by the same scenario.
[0289]
[0294] In the above example, the set of facts consists of suspect name, first cash transaction amount, first deposit date, second cash transaction amount, second deposit date, bank name, account opening date, and average account balance. These different pieces of facts may be extracted from a storage location such as a database.
[0290]
[0295] Furthermore, John Doe, Jack Daniel, Jim Beam, and Remy Martin are facts of the same type that are subordinate to the field name "suspect name." Each suspect name can be defined as a corresponding fact to the other suspect names. For example, Remy Martin can be a corresponding fragment of a fact for Jim Beam. Similarly, a set of corresponding fragments of facts can be defined based on the following fields: first cash transaction amount, first deposit date, second cash transaction amount, second deposit date, bank name, account opening date, and average account balance.
[0291]
[0296] When the intelligent alert system indicates a default narrative based on a new set of facts for a new suspect, the intelligent alert system replaces each old fact for the old suspect with a new corresponding fact for the new suspect. In the example above, the old suspect name Jim Beam is replaced with the new suspect name Remy Martin, $9,980 is replaced with $9,998, August 3 is replaced with September 5, $9,985 is replaced with $9,998, August 4 is replaced with September 6, ABC Bank is replaced with ABC Bank, March 1, 2019 is replaced with February 15, 2019, and $123,197 is replaced with $83,225. The linking words remain unchanged.
[0292]
[0297] If a researcher uses the same default narrative a predetermined number of times without revising it, and this default narrative is consistent with the researcher's writing style (or preferences), an intelligent warning system may skip or advise the researcher to skip the narrative review process.
[0293]
[0298] In one configuration, in addition to providing one commentary or narrative for each scenario, the intelligent alerting system provides an introductory section for each case. Additionally or alternatively, the intelligent alerting system may provide a conclusion section for each case. The introductory section is placed at the beginning of the overall narrative, and the conclusion section is placed at the end of the overall narrative. For example, if a case has three scenarios selected by the investigator, the overall commentary or narrative will have one introductory section, three commentary or narrative sections that match the three selected scenarios, and one conclusion section.
[0294]
[0299] In one aspect of the present disclosure, the introductory and conclusion sections can also be modified and saved by the researcher. Similarly, the intelligent alert system will learn to construct the researcher's preferred introductory and conclusion sections. This general format, including the introductory and conclusion sections, provides the researcher with additional flexibility to write a more comprehensive and universal narrative.
[0295]
[0300] In one configuration, if a case includes multiple suspects, each suspect is detected by a set of scenarios. The overall commentary or narrative for the case may include an introductory section, a relationship section that explains the relationships between these suspects, a single set of commentary (or narrative) sections for each scenario, and a conclusion section.
[0296]
[0301] Updating the link words and relative positions of facts in the default narrative based on different sets of facts can simplify the SAR case review and filing process. For example, when the intelligent alert system detects an alert about a suspect, the intelligent alert system sends the current matching scenario and all scenarios that match past alerts about the suspect to an investigator's computer system. The investigator selects the scenarios that constitute the reason for filing the SAR and sends the selected scenarios back to the intelligent alert system. The intelligent alert system searches a database to identify a default narrative for the selected scenario and sends the default narrative, based on the suspect's facts, back to the investigator's computer system. The investigator can review the narrative and make changes as needed.
[0297]
[0302] When the investigator saves the revised narrative, the investigator's computer system sends the revised narrative back to the intelligent alert system. The intelligent alert system stores the revised narrative and sends the SAR form with the revised narrative to the BSA officer's computer system. When the BSA officer approves the SAR form, the intelligent alert system sends the SAR form to FinCEN's computer system. If the investigator determines that no changes need to be made to the default narrative, the intelligent alert system can send the SAR with the default narrative directly to the BSA officer's computer system for approval.
[0298]
[0303] In some cases, investigators are also BSA personnel, or BSA personnel allow investigators to submit SARs directly without approval. In these cases, investigators can accept a default narrative based on the then-current facts. In response, the intelligent alert system can send the SAR with a default narrative based on the current facts directly to FinCEN's computer system.
[0299]
[0304] After an investigator has consecutively accepted a default narrative for a scenario based on different sets of facts without any changes for a predetermined number of times, the intelligent alert system can assume that the default narrative is consistent with the investigator's writing style (or preferences) for that scenario. Thus, when a future true positive case is detected again for the same scenario against the then-current suspect, the intelligent alert system can send a SAR with a default narrative based on the then-current facts for the then-current suspect directly to FinCEN's computer system. This situation eliminates the effort associated with investigators and BSA personnel.
[0300]
[0305] The above description of one selected scenario can also be applied to multiple selected scenarios. For example, if an investigator successively accepts default narratives for all selected scenarios of a detected case based on different sets of facts over a predetermined number of times, the intelligent alert system can send SARs to FinCEN's computer system with default narratives for multiple selected scenarios based on the then-current facts of the then-current suspect.
[0301]
[0306] In addition to the application of SAR filing, aspects of the present disclosure may be used by a computer system to automatically generate different types of reports based on the preferences of a human writer. For example, a hospital may need to create a report for each patient. A police department may need to create a report for each incident. A school may need to create a report for each student. There are many other report generation needs. Traditional reports are created using significant human resources. Aspects of the present disclosure may reduce the human resources used in generating reports.
[0302]
[0307] Reports may be categorized into different types of reports based on different factors, such as reasons, purposes, criteria, and scenarios. For example, in a hospital, different types of reports may be used based on the reason a patient checked into the hospital. For example, the reason may be heart surgery, childbirth, etc. A patient may have multiple reasons for checking into a hospital. Additionally, for each main reason, there may be multiple sub-reasons. For example, if a patient checks into a hospital in need of heart surgery, there may be many reasons for that need. Because each different reason may require a different type of writing style (or preference) for generating the report, it is desirable to further categorize these reasons. As another example, there are many different reasons, purposes, criteria, scenarios, etc. for a police department to write an incident report. As yet another example, there are many different reasons, purposes, criteria, scenarios, etc. for a school to generate a report for each student.
[0303]
[0308] A report may be written based on one or more facts. These facts may be stored in a database and may consist of data entered by humans, data detected by sensors, data collected from different sources, and / or data derived from other data. Furthermore, humans use words, phrases, sentences, symbols, etc. to link facts together to form a report. For ease of reference, the words, phrases, sentences, symbols, etc. that link facts together are collectively referred to as "linking words."
[0304]
[0309] In one configuration, the computer system stores the facts in a database. The computer system provides editing capabilities for a human writer to create a set of factors, which may include reasons, objectives, criteria, scenarios, etc. The computer system may provide editing capabilities for the human writer to use the set of facts to create a default narrative for each factor. Additionally, the computer system provides editing capabilities for the human writer to write linking words for the default narrative for each factor. The computer system may also store the default narrative for each factor. The default narrative includes facts and linking words.
[0305]
[0310] In one configuration, the computer system stores a default narrative for each factor in the database. In this configuration, the default narrative includes a link word, the position of each fact in the narrative, and a storage location in the database for storing each fact. For example, the default narrative may be, "(Object 1) caused a car accident on (Object 2)." In this example, Object 1 and Object 2 are two facts. The computer system stores the entire sentence containing the link word "had a car accident on," and the positions of Object 1 and Object 2 in this sentence in the database. In addition, the computer system stores the table names and field names of Object 1 and Object 2, respectively, in the database.
[0306]
[0311] Data fields with the same definitions may be stored in the same database table. For example, all patient names are stored in the same database table. Thus, when two different sets of facts are used to write two narratives for two cases, corresponding pairs of facts in the same position in each respective narrative will be in the same database table. When multiple database tables are used to generate facts, database keys for linking these multiple database tables may also be stored in the database. As a result, when a default commentary or narrative based on an old set of facts is used to generate a new narrative for a new set of facts, the computer system identifies each corresponding pair of facts and replaces the old facts with the corresponding new facts.
[0307]
[0312] For example, Object 1 is the "Patient Name Field" stored in the Patients table, and Object 2 is the "Date Field" in the Events table. In the above example, "Jack Daniel had a car accident on January 20, 2018" and "Jim Beams had a car accident on February 3, 2018" are based on the same narrative format but contain two different pieces of facts (e.g., patient name and event date). The link word for these two scenarios is the same: "had a car accident on."
[0308]
[0313] In one configuration, the computer system lists a set of factors, which may include reasons, objectives, criteria, scenarios, etc. The computer system may allow a human writer to select factors for displaying a default narrative based on a new set of facts. The human writer may add, delete, or modify linking words in the narrative displayed by the computer system.
[0309]
[0314] In one configuration, the computer system provides database search and editing capabilities so that a human writer can add, delete, or modify facts and change their positions in the narrative displayed by the computer system. The human writer can store the revised narrative as a new default narrative, which includes the facts, the positions of each piece of fact, and linking words. The computer system stores database table, key, and field information for each fact in the new default narrative.
[0310]
[0315] In one aspect of the present disclosure, a human writer selects factors for displaying a new default narrative based on a new set of facts and the same set of link words stored in a database. The computer system extracts each new fragment of a new fact based on where the old corresponding fragment of the old fact was stored in the database. The computer system may display each new fact between link words in the narrative based on the location of each old corresponding fact in the narrative.
[0311]
[0316] In one configuration, the computer system provides functionality for a human writer to add, delete, or modify link words in the new default narrative displayed by the computer system. The human writer may also add, delete, or modify facts and change the position of facts in the new default narrative displayed by the computer system. The human writer may re-store the revised new default narrative as the next new default narrative.
[0312]
[0317] The above process can be repeated to allow the human writer to continue revising the default narrative based on new sets of facts and store the revised default narrative as the next new default narrative. As a result of this evolutionary process, future default narratives can conform to the preferences of the human writer.
[0313]
[0318] In one aspect of the present disclosure, a narrative is considered mature for a selected factor if a human writer has not changed the narrative for different cases using different sets of facts across a predetermined number of instances based on the same factor selected by the human writer, where the predetermined number can be defined by a human and / or a computer system.
[0314]
[0319] In one configuration, a link word is considered mature for a selected factor if a human writer has not changed the link word displayed by the computer system for different instances that used different sets of facts based on the same factor selected by the human writer over a predetermined number of instances, where the predetermined number of instances can be defined by a human and / or the computer system.
[0315]
[0320] In one configuration, when the narrative is mature for a factor selected by the human writer, the computer system automatically skips or encourages the human writer to skip the narrative review process and generates a report on the selected factor using the current default narrative as a standard narrative format that includes facts that may vary from report to report and the same set of linking words that match the writing style (or preferences) of the human writer.
[0316]
[0321] In one configuration, if the link words are mature for a factor selected by a human writer, the computer system automatically skips or encourages the human writer to skip the narrative review process and generates a report on the selected factor using the current default link words as standard link words.
[0317]
[0322] In one configuration, if a human writer selects multiple factors for writing the report, the computer system uses the selected factors to generate one narrative section for each factor and combines multiple narrative sections together based on the multiple selected factors to generate the report.
[0318]
[0323] An introductory section may be inserted at the beginning of the report, the introductory section including facts and / or linking words, which may be revised by a human writer over multiple reports to ultimately match the writing skills (or preferences) of the human writer based on an evolutionary process described in this disclosure.
[0319]
[0324] A link section may be inserted in the middle of the report, containing facts and / or link words that may be revised by human writers over multiple reports to ultimately match the writing skills (or preferences) of the human writers based on the evolutionary process described in this disclosure.
[0320]
[0325] A conclusion section may be inserted at the end of the report, containing facts and / or linking words that may be revised by a human writer over multiple reports to ultimately match the writing skills (or preferences) of the human writer based on the evolutionary process described in this disclosure.
[0321]
[0326] As a result of this disclosure, a computer system may learn the writing style (or preferences) of each human writer and automatically generate various reports for each human writer based on the writing style (or preferences) of the human writer.
[0322]
[0327] One or more of the above examples are based on anti-money laundering applications in financial institutions. Nevertheless, the present disclosure is also applicable to many other different types of applications for different organizations and different purposes. For example, an intelligent alert system may be used by a government agency to identify employees who may be stealing confidential information from the government. An intelligent alert system may be used by a school to identify students who may be dropping out of school. An intelligent alert system may be used by a social networking company to identify members who may be engaging in illegal activities on social networks. An intelligent alert system may be used by an employer to identify employees who may be quitting their jobs. An intelligent alert system may be used by a marketing company to identify potential business targets. An intelligent alert system may also be a mobile application used by an individual to identify potential stocks or commodities for investment purposes. In a public health application, an intelligent alert system may be a mobile app that monitors a person's health status and sends a message if there is a potential health concern. Intelligent alert systems have countless uses. The following procedure is an example of how to design and develop an intelligent alert system to monitor a group of subjects for any specific goal.
[0323]
[0328] In one configuration, the intelligent alert system assigns scores to various factors. Additionally or alternatively, the intelligent alert system assigns a score to each degree of each factor. The degree of a factor is used to distinguish between different levels of the factor's impact. For example, sending a wire transfer is a risk factor to be considered for anti-money laundering purposes. However, the amount of the wire transfer may have a different impact. For example, a wire transfer amount of $0 to $10,000 may have a low level of money laundering risk, while a wire transfer amount of $250,000 to $1,000,000 may have a high level of money laundering risk. The factors may be based on data related to an object having a positive or negative impact on the achievement of the goal. The intelligent alert system assigns a score to each factor. The intelligent alert system may identify the possible degree of a factor in the data related to an object having a positive or negative impact on the achievement of the goal. The intelligent alert system assigns a score to each degree of each factor. In one configuration, the intelligent alert system generates a total score for each subject under surveillance by summing all of the scores for factors or magnitudes of factors associated with the subject.
[0324]
[0329] The intelligent alert system uses a set of scenarios based on different criteria. The criteria may include factors from data related to the object, the magnitude of factors from data related to the object, and / or a score derived from data related to the object. Additionally or alternatively, the criteria may be based on rules derived from decision trees, special categories related to the object, if-then conditional formats derived from models trained by machine learning networks, if-then conditional formats derived from behavioral patterns, if-then conditional formats derived from trading patterns, factors established by a software module, and / or factors established by a user or designer of the system.
[0325]
[0330] Through the above methods, scenarios for the intelligent alert system are established in various ways. These scenarios may trigger alerts to generate potential cases, and each potential case may have one or more scenarios in its causal vector. The intelligent alert system may list a set of potential cases triggered by one or more scenarios. An investigator may review the potential cases to determine which cases are true positives and which cases are false positives. Additionally, an investigator may review current potential cases with past potential cases to determine which combinations of cases are true positives or false positives.
[0326]
[0331] In one configuration, the intelligent alert system allows an investigator to review scenarios of a potential case to determine which combinations of scenarios will produce true positives and which combinations of scenarios will produce false positives. The intelligent alert system also provides an investigator with the ability to review scenarios of a current potential case along with scenarios of past potential cases to determine which combinations of scenarios are true positives and which combinations of scenarios are false positives.
[0327]
[0332] Although a composite cause vector is obtained from the combination of multiple cause vectors, the composite cause vector has the same form as a cause vector. By definition, a composite cause vector is the cause vector of combined cases. Therefore, the conditional probability P(S / cbv) of a composite cause vector and the conditional probability P(S / x) of a cause vector can be calculated through a similar method.
[0328]
[0333] Furthermore, a cause vector (or a composite cause vector) may trigger a potential case for investigation, but the reason for reporting the case may be based on a subset of the scenarios in the cause vector. To maintain accuracy in the posterior probability calculation, it is desirable to identify the subset of scenarios that form the true cause vector for a true positive.
[0329]
[0334] The intelligent alert system provides investigators with the ability to review scenarios of potential cases to identify a true causal vector if the potential case is a true positive. Investigators may review scenarios of combined potential cases to identify a true causal vector if the combined potential cases are true positive. The intelligent alert system may store the investigation results and associated causal vector (or true causal vector) for each potential case. As previously described, once a true causal vector is identified, a set of narratives can be generated using the set of scenarios that make up the true causal vector, and a SAR form can be automatically completed and sent to FinCEN.
[0330]
[0335] In one configuration, the intelligent alert system stores the combined case investigation results and the associated composite cause vectors (or true composite cause vectors) for the combined cases. Each composite cause vector (or true composite cause vector) may be composed of one or more scenarios. The results and other information may be stored in a database or other data structure.
[0331]
[0336] After an investigator has used the intelligent alert system for a period of time, the intelligent alert system accumulates a large amount of data related to the subject. The data may include past potential cases, past investigation results (e.g., true positives or false positives), and associated causal vectors (or true causal vectors). As a result, the accuracy of the system may increase as the system is used more and more. That is, the accuracy of the system may increase through the accumulation of data.
[0332]
[0337] For clarity, a cause vector or a real cause vector will generally be referred to hereinafter as a cause vector. Furthermore, a cause vector will generally be referred to hereinafter as both a cause vector and a composite cause vector. Thus, a cause vector will generally refer to a cause vector, a composite cause vector, a real cause vector, and / or a real composite cause vector.
[0333]
[0338] In one configuration, the system calculates a conditional probability for each cause vector after the amount of historical data is greater than a threshold. The threshold may be based on the number of true cases, potential cases, data size, and / or other factors. The conditional probability of a cause vector based on a given time period is the number of true positives triggered by the cause vector divided by the total number of potential cases triggered by the cause vector.
[0334]
[0339] In one aspect of the present disclosure, the intelligent alert system rejects a potential case triggered by a causal vector as a false positive when the conditional probability of the causal vector is lower than a false positive rejection threshold, which may be set by the software module, the person designing the system, the person tuning the system, and / or the user of the system.
[0335]
[0340] In some cases, if the potential cases triggered by the cause vector always have low conditional probabilities, the cause vector's scenarios may not be properly defined. In such a situation, the user can adjust the cause vector's scenarios to increase their probability predictions. The intelligent warning system can prompt the user to make such changes.
[0336]
[0341] The intelligent alert system may accept a potential case triggered by a causal vector as a true positive in response to the conditional probability of the causal vector being higher than a true positive acceptance threshold, which may be set by the software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0337]
[0342] A vector with multiple elements can be transformed into a combination of multiple vectors. For example, vector A has three elements v1, v2, and v3. In this example, vector A can be a combination of three vectors (e.g., vector B with element v1, vector C with element v2, and vector D with element v3). For clarity, vector A will be referred to as the parent vector. Vectors B, C, and D may be referred to as child vectors. In the following disclosure, the causal vector will be considered the parent vector.
[0338]
[0343] The above example assumes that the child vector has only one element. In general, a child vector can have multiple elements. For example, vector A in the above example can have a child vector with elements v1 and v2. Because each element can be included in or excluded from the parent vector to form the child vector, a parent vector with N elements can have a total of 2 elements, including itself, which all has N elements, and a null vector, which has no elements. N Therefore, a parent vector with N elements can have 2 N - There can be two possible significant child vectors. Each element of a cause vector corresponds to a scenario. If an element is 1, the corresponding scenario is included. If an element is 0, the corresponding scenario is excluded. A subset of the scenarios of a parent cause vector can form the scenarios of a child cause vector.
[0339]
[0344] In general, the conditional probability value of a cause vector may increase as the number of scenarios in the cause vector increases. For example, if a first cause vector has only scenario A as its vector element and a second cause vector has both scenario A and scenario B as its vector element, the conditional probability value of the second cause vector should be the same as or higher than the conditional probability value of the first cause vector.
[0340]
[0345] Thus, a parent cause vector has the same or higher conditional probability value as any of its child vectors. That is, if a child vector already has a conditional probability value greater than the true positive acceptance threshold, then the parent cause vector's conditional probability value will also be greater than the true positive acceptance threshold.
[0341]
[0346] In one configuration, the intelligent alert system accepts a potential case triggered by a causal vector as a true positive when the conditional probability value of one of its child vectors is equal to or greater than a threshold value. The threshold value may be set by the software module, the person designing the system, the person tuning the system, and / or the user of the system.
[0342]
[0347] A current potential case may be combined with a group of past potential cases to form a composite cause vector. The intelligent alert system may accept a composite cause vector of a potential case as a true positive when the conditional probability value of one of the composite cause vector's child vectors is equal to or greater than a threshold. The threshold may be set by the software module, the person designing the system, the person tuning the system, and / or the user of the system.
[0343]
[0348] It may be difficult for an intelligent alert system to try all possible combinations of past potential cases to determine whether a particular combination of a current potential case and a past potential case meets the automated true positive acceptance criteria. Thus, in one configuration, the intelligent alert system accepts a composite cause vector as a true positive when the conditional probability value of one of the composite cause vector's child vectors is equal to or greater than a threshold. The threshold may be set by the software module, the person designing the system, the person tuning the system, and / or the user of the system.
[0344]
[0349] In general, all potential cases related to one object may be related to one another. Additionally, all potential cases related to a group of related objects may be related to one another. For example, if five students live in the same dormitory, all potential cases related to any of these five students are related cases. The scope of relationships for defining related potential cases may be set by the software module, the person designing the system, the person adjusting the system, and / or the user of the system.
[0345]
[0350] When an intelligent alert system is used over a long period of time, it may not be practical or efficient to use all relevant potential cases. That is, the number of relevant potential cases may be too large, resulting in poor performance. Therefore, it may be desirable to limit the scope of relevant cases to a certain period of time. In one configuration, a composite cause vector may be generated from a current potential case and a group of relevant past potential cases that occurred within a predetermined period of time. The intelligent alert system may accept a composite cause vector as a true positive when the conditional probability value of the child vectors of the composite cause vector is equal to or greater than a threshold. The threshold may be set by the software module, the person designing the system, the person adjusting the system, and / or the user of the system. The predetermined period of time may be set by the software module, the person designing the system, the person adjusting the system, and / or the user of the system.
[0346]
[0351] The intelligent alert system provides an opportunity for investigators to investigate cases that are neither automatically rejected as false positives nor automatically accepted as true positives. The intelligent alert system records the investigation results for each potential case and the associated cause vector for the potential case. This information can be used to calculate future conditional probability values for the cause vector.
[0347]
[0352] Because the intelligent warning system continues to use the investigation results to further adjust future conditional probability values, the intelligent warning system may adjust itself to future environmental changes. The more potential cases the intelligent warning system can process without human interaction, the fewer potential cases remain for investigators to process.
[0348]
[0353] An intelligent warning system can exclude cases that are automatically accepted as true positives or rejected as false positives from the calculation of the posterior probability value. This approach avoids problems caused by positive feedback. For example, if a potential case triggered by cause vector x is automatically accepted as a true positive, the value of the conditional probability p(S / x) may increase when the result of this case is included in the calculation of the posterior probability value of cause vector x. As a result, the next potential case triggered by cause vector x may be automatically accepted as a true positive. Because the posterior probability value continues to increase, the automatic acceptance of future potential cases triggered by cause vector x continues. In other words, once a potential case triggered by a cause vector is automatically accepted as a true positive, all future potential cases triggered by the same cause vector will be automatically accepted as true positives if the accepted case is included in the calculation of the posterior probability value of the cause vector. This is undesirable because this "no-return" process deprives the intelligent warning system of the ability to readjust itself backwards when the environment changes in the future.
[0349]
[0354] In one configuration, the intelligent alert system does not automatically reject a potential case when its conditional probability value is lower than a false positive rejection threshold. As a result, an investigator may fine-tune the conditional probability value through this potential case. For reference, this case is referred to as a false positive validation case. The number, rate, and / or frequency of occurrence of false positive validation cases is determined by the software module, the person designing or tuning the system, and / or the user of the system.
[0350]
[0355] Additionally, in some cases, the intelligent alert system may not automatically accept a potential case as a true positive when the conditional probability value of the potential case is higher than the true positive acceptance threshold. As a result, an investigator may fine-tune the conditional probability value through this potential case. For clarity, this case is referred to as a true positive validation case. The number, proportion, and / or frequency of occurrence of the true positive validation cases is determined by the software module, the person designing or tuning the system, and / or the user of the system.
[0351]
[0356] In some cases, certain subjects are treated differently for different reasons. For example, some subjects are on a "Do Not Compare List" or a "White List." Potential cases related to subjects on such lists may be treated as false positives without the need for investigation. For example, it may be politically correct to place a politician on an anti-money laundering system's "Do Not Compare List," regardless of what is detected. Similarly, potential cases related to subjects on other lists for other purposes may be treated as true positives without the need for investigation.
[0352]
[0357] Because these cases are treated differently, they are considered outliers. It is desirable to exclude these outliers from the calculation of the posterior probability values. The intelligent warning system may skip potential cases associated with subjects that are on a "no comparison list" or "white list." Skipped cases will not be used when calculating the posterior probability values of the causal vector.
[0353]
[0358] In some cases, an alert triggered by a scenario for a target may prove to be a false alert because the scenario is not suitable for monitoring the target. For example, a cash-intensive business may naturally have more cash than other types of businesses, and a scenario comparing the amount of cash between this business and others may not be meaningful and appropriate. Under such circumstances, an investigator can mark the scenario as verified for this target. This means that the scenario has already been verified by an investigator for this target, and no action needs to be taken if another alert is triggered by this scenario for this target. Therefore, a potential case triggered by a scenario with a verified status is also considered an outlier.
[0354]
[0359] In one configuration, the intelligent alert system skips potential cases associated with subjects that have a verified status on the scenario that triggered the potential case, and the intelligent alert system does not include the skipped cases in the calculation of the posterior probability value of the causal vector.
[0355]
[0360] When an investigator dismisses a potential case as a false positive, the intelligent alert system prompts the investigator to determine whether the scenario that triggered the potential case should be marked as verified. If the scenario is not marked as verified, it may trigger another false positive in the future. Therefore, it is desirable to mark the scenario as verified when the potential case triggered by the scenario is determined to be a false positive.
[0356]
[0361] The number of potential cases used to calculate a conditional probability value can also affect the reliability of the conditional probability value. For example, if only one potential case is triggered by cause vector x and this potential case is accepted by the investigator as a true positive, the conditional probability p(S / x) may not be reliable even if it has a value of 100%. However, if five potential cases are triggered by cause vector x and the conditional probability p(S / x) is 100%, this conditional probability may be more reliable than the previous example.
[0357]
[0362] The intelligent warning system may automatically dismiss a potential case triggered by a causal vector as a false positive when the conditional probability of the causal vector is less than threshold A and the number of potential cases triggered by the causal vector and used to calculate the conditional probability is greater than threshold B. Each of thresholds A and B may be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0358]
[0363] The intelligent alert system accepts a potential case triggered by a cause vector as a true positive when the conditional probability of the cause vector is higher than threshold A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than threshold B. Each of thresholds A and B can be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0359]
[0364] When an intelligent alert system automatically accepts a potential case as a true positive or rejects a potential case as a false positive based on a conditional probability threshold, it may be desirable to use different conditional probability thresholds for subjects in different categories. For example, a financial institution may submit a SAR for a potential case related to a subject who was a suspect in a past SAR case, even if the conditional probability of the current potential case is lower than the true positive acceptance threshold.
[0360]
[0365] In one configuration, the intelligent alert system uses different true-positive acceptance thresholds and false-positive rejection thresholds for subjects in different categories. The different categories may be defined by the software module, the person designing or tuning the system, and / or the user of the system. In an example anti-money laundering application, these categories may include customers who were the subject of previous SARs, customers matched on OFAC lists, customers matched on 314(a) lists, customers matched on Politically Exposed Person lists, customers matched on other watch lists, high-risk customers, medium-risk customers, low-risk customers, high-risk counterparties, medium-risk counterparties, low-risk counterparties, high-risk countries, medium-risk countries, low-risk countries, high-risk regions, medium-risk regions, low-risk regions, high transaction value, medium transaction value, low transaction value, etc.
[0361]
[0366] Because these categories may also be factors (e.g., risk factors) used for purposes of score (e.g., risk score) assignment and calculation, it may be desirable to use different true positive acceptance thresholds and false positive rejection thresholds for different factors. In one aspect of the present disclosure, the intelligent alert system allows a user to assign a true positive acceptance threshold and a false positive rejection threshold to each factor.
[0362]
[0367] In one configuration, the intelligent alert system accepts a potential case as a true positive if the conditional probability of the causal vector is higher than one of the true positive acceptance thresholds for the factors associated with the potential case. The intelligent alert system may reject a potential case as a false positive if the conditional probability of the causal vector is lower than one of the false positive rejection thresholds for the factors associated with the potential case.
[0363]
[0368] Such an approach can become complicated when many factors are involved. Therefore, it is desirable to select only a few important factors to assign different true-positive acceptance thresholds and false-positive rejection thresholds. In one configuration, the intelligent alert system allows a user to select a set of factors and assign a true-positive acceptance threshold to each selected factor. The user may also select a set of factors and assign a false-positive rejection threshold to each selected factor.
[0364]
[0369] As such, the intelligent alert system may accept a potential case triggered by a cause vector as a true positive if the conditional probability of the cause vector is higher than one of the true positive acceptance thresholds for selected factors associated with the potential case. Additionally, the intelligent alert system may reject a potential case triggered by a cause vector as a false positive if the conditional probability of the cause vector is lower than one of the false positive rejection thresholds for selected factors associated with the potential case.
[0365]
[0370] For improved accuracy, it is desirable for the total number of potential cases to be greater than a threshold when calculating the conditional probability. The threshold can be the number of cases or a time period. The threshold can be arbitrarily set by the user.
[0366]
[0371] In one configuration, the intelligent alert system records the potential case, the investigation results, the associated cause vector, and the date and time the record was established. The intelligent alert system may calculate the conditional probability of cause vector x, which is the number of true positives triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.
[0367]
[0372] After calculating the conditional probability values, the intelligent alert system also records additional values in the database, such as: (1) the number of true positives triggered by cause vector x up to that time, (2) the total number of potential cases triggered by cause vector x up to that time, and (3) the date and time of the calculation, which may be referred to as the last calculation time for cause vector x. As a result of storing these additional values, the intelligent alert system does not need to repeat the same calculation to obtain the same value for cause vector x again.
[0368]
[0373] The intelligent alert system may update the conditional probability of cause vector x based on the sum of the number of true positives triggered by cause vector x (before the last computation time) and the number of true positives triggered by cause vector x (since the last computation time), divided by the sum of the total number of potential cases triggered by cause vector x (before the last computation time) and the total number of potential cases triggered by cause vector x (since the last computation time).
[0369]
[0374] In the above calculation, the number of true positives triggered by cause vector x (before the last calculation time) plus the number of true positives triggered by cause vector x (since the last calculation time) is equal to the number of true positives triggered by cause vector x during the current calculation. Similarly, the total number of potential cases triggered by cause vector x (before the last calculation time) plus the total number of potential cases triggered by cause vector x (since the last calculation time) is equal to the total number of potential cases triggered by cause vector x during the current calculation. Therefore, the above calculations arrive at the same conditional probability p(S / x), which is the number of true positives triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.
[0370]
[0375] Both the number of true positives triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (before the last calculation time) can be stored in a database after the last calculation of the conditional probability. The intelligent alert system can then search the database to find these two values. The intelligent alert system then calculates two new values based on the potential cases detected since the last calculation time. This approach eliminates many calculations, thereby reducing the amount of data stored in memory.
[0371]
[0376] In one aspect of the present disclosure, upon completion of the calculation of the conditional probability values, the intelligent alert system stores, in addition to the potential cases, investigation results, and cause vector x, additional values such as: (1) the number of true positives triggered by cause vector x up to that time, (2) the total number of potential cases triggered by cause vector x up to that time, and (3) the date and time of the calculation, which may be referred to as the new last calculation time for cause vector x. As a result, these values simplify the calculation of the next round of conditional probabilities for potential cases triggered by cause vector x.
[0372]
[0377] The above method can be further modified during the software coding process. In one aspect of the present disclosure, the intelligent alert system maintains two counters for a cause vector x, one counter for the number of true positives (NTPX) and the other counter for the number of potential cases (NPCX).
[0373]
[0378] In one aspect of the present disclosure, the intelligent alert system resets both counters NTPX and NPCX to 0 to begin counting. As an example, a potential case triggered by cause vector x may be manually reviewed by an investigator and determined to be a true positive. In this example, the number of manually reviewed true positives triggered by cause vector x has increased by one, so the intelligent alert system increments the NTPX counter by one. In the current example, the number of potential cases triggered by cause vector x has increased by one, so the system also increments the NPCX counter by one.
[0374]
[0379] As another example, a potential case triggered by cause vector x is manually reviewed by an investigator and determined to be a false positive. In this example, the intelligent alert system adds 0 to the NTPX counter because the number of manually reviewed true positives triggered by cause vector x has not increased, and adds 1 to the NPCX counter because the number of potential cases y triggered by cause vector x has increased by one.
[0375]
[0380] In one configuration, the conditional probability p(S / x) for a new potential case triggered by a cause vector x is NTPX divided by NPCX. This method can reduce the computational complexity of the conditional probability p(S / x) and simplify the software coding effort.
[0376]
[0381] Although the example uses cause vector x, the above method can be used for any cause vector. An intelligent warning system can have many pairs of counters, one pair per cause vector. As explained earlier, the total number of pairs is limited because only a very small number of scenarios can coexist in the same cause vector to trigger a potential case.
[0377]
[0382] By using the above methods, the intelligent warning system may reduce the amount of time for calculations. Furthermore, the conditional probability values become more accurate as more potential cases are used in the calculations to derive the conditional probability values.
[0378]
[0383] Because the intelligent alert system continues to learn from human workers, it is simply a matter of time before the intelligent alert system automatically detects the alert, makes the decision to file a SAR, completes the SAR form, writes the narrative, and sends the SAR form to FinCEN. The intelligent alert system reduces human resources and handles SAR compliance matters similar to how humans handle SAR compliance matters.
[0379]
[0384] Although suspicious activity detection, SAR case investigation, and suspicious activity report submission are used as examples, the same set of methods as in this disclosure can be used to process currency transaction detection, CTR case investigation, and currency transaction report (CTR) submission to FinCEN.
[0380]
[0385] Similarly, the same set of methods as those in the present disclosure can be used to detect potential OFAC matches, investigate potential matches, and report true matches to the Office of Foreign Assets Control (OFAC). Under such circumstances, the relative correlation (RC) value used to measure the degree of match is equivalent to the risk score used to measure the degree of risk. Therefore, instead of using risk score-based scenarios, the intelligent warning system can use RC-based scenarios.
[0381]
[0386] The OFAC list is just one example of many regulatory lists. The same set of methods as in this disclosure can be used to detect, investigate, and report matches for all types of regulatory lists, such as 314(a) lists, denied persons lists, politically exposed persons lists, and any other lists published by governmental and / or non-governmental agencies. Those familiar with regulatory compliance requirements will understand that the set of methods in this disclosure can be used to detect, investigate, and report any subject to comply with any type of regulatory reporting requirement.
[0382]
[0387] As mentioned, this disclosure describes functionality that may be implemented by an intelligent alert system for various applications that may generate alerts. A human may review the alert and take follow-up actions based on the alert review. In one configuration, the intelligent alert system learns from human behavior, makes decisions on behalf of the human, and performs follow-up actions for the human. As a result, the intelligent alert system may replace some or all humans in such applications, reducing human effort and time.
[0383]
[0388] Typically, financial institutions set low thresholds in their intelligent alert systems for generating fraud alerts because fraud cases can incur significant losses. These low thresholds increase the number of false positives generated. Investigating fraud alerts to distinguish actual fraud from false positives is labor-intensive and time-consuming.
[0384]
[0389] Aspects of the present disclosure are directed to computer systems and networks that reject false positives and confirm true positives. In one configuration, the rejection of false positives and the confirmation of true positives can be automatic (e.g., no human review is required). The rejection of false positives and the confirmation of true positives can improve fraud detection and reduce damage (e.g., financial loss) caused by fraudulent activity.
[0385]
[0390] In one aspect of the present disclosure, in response to detecting an alert, the intelligent alert system sends at least a portion of the transaction details to a consumer protection system. The alert may be generated in response to a transaction between a payer and a payee. The payer may be a customer of a financial institution. The consumer protection system may be a computer system or a device interface. The transaction details may be transmitted over a communication channel. In this disclosure, a communication channel refers to a wired network (e.g., the Internet, etc.), a wireless network (e.g., a cellular phone network, etc.), and / or another type of communication channel. Unless otherwise indicated, transmissions between devices, individuals, systems, organizations, and / or other entities in the present application may be performed over a communication channel.
[0386]
[0391] The transaction details may include one or more of the following: transaction date, transaction time, transaction amount, payer account number, payer bank routing number, payer card number, payer wallet number, payer telephone number, payer email address, payer's other contact information, payer's personal identification information, payer's bank SWIFT number, payee account number, payee bank routing number, payee card number, payee wallet number, payee telephone number, payee email address, payee's other contact information, payee's personal identification information, payee bank SWIFT number, and other information that can be used to define the transaction. The payer may be an individual or an organization. The payee may be an individual or an organization.
[0387]
[0392] In one aspect of the present disclosure, the consumer protection system sends a portion of the transaction details to a payer (e.g., a customer of a financial institution). The portion of the transaction details may be transmitted to a payer device. The payer device (e.g., device interface) may include, for example, a mobile phone, a tablet, a notebook, a computer system, etc. The transmission may be facilitated based on the payer's phone number, the payer's email address, the payer's device interface address, and / or other contact information for the payer.
[0388]
[0393] The payer may review some of the transaction details to determine whether the transaction is legitimate. The payer accepts the transaction if it is legitimate. Alternatively, the payer rejects the transaction if it is not legitimate. The payer's input (e.g., confirmation or rejection) is transmitted from the payer's device to the consumer protection system via a communication channel.
[0389]
[0394] In one aspect of the present disclosure, the consumer protection system sends the payer's reply to the intelligent alert system that generated the potential fraud instance alert. If the payer accepts the transaction, the intelligent alert system dismisses the alert as a false positive. If the payer declines the transaction, the intelligent alert system notifies the financial institution's transaction system to stop the transaction. The process of stopping the transaction does not involve human interaction; i.e., the process is automated. The intelligent alert system can cooperate with the consumer protection system to prevent fraud or dismiss false alerts without human intervention.
[0390]
[0395] Furthermore, a denial of a transaction by a payer may indicate that a perpetrator may have stolen financial instruments, financial account information, personal information, etc. from the payer. Under such circumstances, the consumer protection system sends an alert to one or more devices associated with financial institutions, merchants, and any organizations that subscribe to services provided by the consumer protection system. As a result, when the payer denies the transaction, the perpetrator is protected because they cannot use the same method to commit further crimes against the payer through the financial institutions, merchants, and organizations that received the alert.
[0391]
[0396] At any given time, any financial institution, merchant, or any type of organization that needs to prevent financial crimes can subscribe to the alert services provided by the consumer protection system. Many types of financial crimes, such as check fraud, credit card fraud, debit card fraud, ATM fraud, internet banking fraud, ACH fraud, wire fraud, virtual currency fraud, identity theft, etc., can be reduced or even eliminated through this method. Thus, the amount of financial crimes can be reduced.
[0392]
[0397] Additionally, in one aspect of the present disclosure, consumers and organizations may be encouraged to open an account with the consumer protection system to become members of the consumer protection system. In one configuration, during the account opening process, the consumer protection system collects some of the new member's identifying information, such as name, date of birth, address, zip code, city, and country of residence.
[0393]
[0398] In another aspect of the present disclosure, the consumer protection system collects, through a device interface, financial instrument and financial account numbers from the new member, such as checking account numbers, savings account numbers, bank routing numbers, credit card numbers, debit card numbers, ATM card numbers, virtual currency wallet numbers, insurance account numbers, transaction account numbers, cryptocurrency wallet address numbers, and any other information that can identify a financial account, financial instrument, or any financial instrument that can be used to conduct a transaction. To increase security, the consumer protection system may collect all of the member's financial instrument and financial account numbers.
[0394]
[0399] Additionally, new members may be prompted to provide expiration dates and descriptions of financial products, financial accounts, and financial instruments through the device interface. Furthermore, the consumer protection system may also prompt members to provide identification information for the member's device, such as a phone number, email address, device interface address, or IP address. A member may be either an individual or an organization. This process of collecting information from a member is referred to as a "registration process" or "ownership registration process." The registration process may collect one or more of the following: identification information, financial product and account numbers, expiration dates and descriptions, and device identification information.
[0395]
[0400] After a member opens an account with the consumer protection system and completes the registration process, the member is protected from many types of financial crimes. For example, a subject (e.g., an individual or organization) may conduct a transaction with an online merchant using a credit card. The merchant receives from the subject some of the credit card information (e.g., the last four digits of the credit card number), the cardholder's name, the billing address associated with the credit card, the cardholder's telephone number, and the cardholder's email address. The merchant converts the received information into an identification code. The meaning of the identification code is explained in more detail below.
[0396]
[0401] The merchant transmits the identification code and a portion of the transaction details to the consumer protection system. Based on information provided by the subject, the consumer protection system sends the portion of the transaction details to the member's device (e.g., a mobile phone) whose identification code matches the received identification code. The portion of the transaction details may be sent based on the member's device identification information provided by the member.
[0397]
[0402] The member can accept or decline the transaction via the device. If the member accepts the transaction, the consumer protection system notifies the merchant system that the transaction was accepted by the registered cardholder. The merchant system then completes the transaction without concern for fraud. This process protects the member's original identity, as the merchant only sends an identification code to the consumer protection system.
[0398]
[0403] The intelligent alert system may not be used by all financial institutions, as some financial institutions may have their own systems. In the following example, the financial institution system does not use the intelligent alert system. Additionally, in this example, after the merchant system submits a transaction to the financial institution system for approval, the financial institution system detects the transaction as a fraud alert. In response to detecting the fraud alert, the financial institution system may send some of the transaction details and the credit card number to the consumer protection system. Because the member has already approved the transaction, the member does not have to go through the process again. The consumer protection system can notify the financial institution system that the member has approved the transaction. The financial institution system can then approve the transaction if there are no other issues, such as insufficient credit. This process can be completed without human intervention.
[0399]
[0404] In one aspect of the present disclosure, when a member declines a transaction through their device interface, the consumer protection system notifies the merchant system that the transaction was declined by the credit card holder. As a result, the merchant system declines the transaction. This process does not involve a third-party human intervention to prevent fraud. The merchant system can cooperate with the consumer protection system to prevent fraud without human intervention.
[0400]
[0405] In some cases, a member's denial of a transaction may indicate that a fraudster has stolen financial products, financial account information, financial instruments, personal information, etc. from the member. In such circumstances, the consumer protection system sends an alert to one or more devices of financial institutions, merchants, and / or organizations that subscribe to the alert service provided by the consumer protection system. Based on the alert, these devices of the financial institutions, merchants, organizations, etc. communicate with associated computer systems to prevent future financial crimes. As a result, when a member denies a transaction, the perpetrator is prevented from using the same method to commit further crimes against members at the financial institutions, merchants, organizations, etc. that received the alert, thereby protecting the member.
[0401]
[0406] While an online merchant is used in the above example, the same methodology may be applied to all types of merchants. Additionally, while a credit card is used in the above example, other types of financial instruments, accounts, vehicles, etc. may be used. For reference purposes, a definition of the device interface is provided in the Summary of the Invention section of this disclosure.
[0402]
[0407] Check deposit fraud refers to fraudulent activity in which a person deposits a check and then quickly withdraws large amounts of cash based on the deposited check before the financial institution discovers that the deposited check is invalid. Check deposit fraud can easily occur at financial institutions that do not hold deposited checks until the check clears.
[0403]
[0408] As an example application of a consumer protection system, when a subject cashes (or deposits) a check at a financial institution (e.g., a bank, credit union, money services provider, etc.), the financial institution can send the checking account number, bank routing code, payee name, check serial number, and amount shown on the check to the consumer protection system. The consumer protection system sends the payee name, check serial number, and amount to a member's device (e.g., a mobile phone) whose checking account number and bank routing code match the checking account number and bank routing code shown on the check provided by the subject. The payee name, check serial number, and amount can be transmitted to the computer protection system based on the member's device identification information provided by the member.
[0404]
[0409] The member can accept or reject the transaction via the device. If the member accepts the transaction, the consumer protection system notifies the financial institution that the transaction was accepted by the registered holder of the checking account. The financial institution then cashes (or deposits) the check without worrying about counterfeit check fraud, altered check fraud, or check deposit fraud.
[0405]
[0410] In one aspect of the present disclosure, if a member denies a transaction through the device interface, the consumer protection system notifies the financial institution that the transaction was denied by the checking account holder of record, which results in the financial institution rejecting the check submitted by the subject.
[0406]
[0411] Additionally, the consumer protection system sends alerts to one or more devices of financial institutions, merchants, and / or organizations that subscribe to the alert service provided by the consumer protection system. Based on the alerts, the devices of the financial institutions, merchants, organizations, etc. communicate with associated computer systems to prevent future financial crimes.
[0407]
[0412] For example, in one aspect of the present disclosure, when a subject enters a password to conduct a virtual currency transaction based on a payer's wallet address, the virtual currency trading system sends the payer's wallet address and some of the transaction details to a consumer protection system. The consumer protection system then sends some of the transaction details to a mobile phone of a member who has the wallet address registered to their account. The member can accept or reject the virtual currency transaction through a mobile app. The member's actions on the member's mobile phone (e.g., the member's reply) can be sent back to the consumer protection system. The consumer protection system can then send the member's reply to the virtual currency trading system. As a result, the virtual currency trading system can stop the transaction if the member rejects the transaction, even if the subject enters the correct password. On the other hand, the virtual currency trading system can complete the transaction if the member accepts the transaction and the subject enters the correct password. In one configuration, if the member rejects the perpetrator's access to their account, the consumer protection system sends an alert to all subscriber device interfaces to protect the member.
[0408]
[0413] The examples provided above are not limited to mobile devices. Other types of device interfaces are also contemplated. Additionally, a user may accept or reject a transaction via an application on the device interface. Transactions based on virtual currency accounts may be used for any type of account (e.g., online banking account, insurance account, trading account, etc.) as long as the member has registered their account number with the consumer protection system.
[0409]
[0414] Financial institutions may also be members of the consumer protection system. In one configuration, the financial institution's computer system sends all addresses (e.g., telephone numbers, email addresses, etc.), account names, and account numbers of its customers' device interfaces to the consumer protection system. The consumer protection system may contact the customers via the device interfaces and prompt the customers to download an application to their device interfaces (e.g., mobile phones, computers, etc.). In addition, the consumer protection system may prompt the customers to register their account numbers, financial product numbers, and other financial data with the consumer protection system through the application. In one aspect of the present disclosure, the consumer protection system performs verification on the information provided by the customers. As a result, all of these customers can become members of the consumer protection system.
[0410]
[0415] Furthermore, if a customer discovers that their financial instrument (e.g., checkbook, credit card, debit card, ATM card, etc.) has been lost or stolen, the customer can immediately notify the consumer protection system. In response, the consumer protection system notifies the financial institution's computer system to block all transactions related to the lost or stolen financial instrument. As a result of this proactive action by the consumer, the financial institution and merchant are protected by the consumer protection system without human intervention.
[0411]
[0416] In one possible scenario, all financial institutions, merchants, and organizations subscribe to the alert service provided by the consumer protection system. As a result, the consumer protection system can automatically, without human intervention, stop criminals from committing crimes against financial institutions, consumers, merchants, and any organization.
[0412]
[0417] Fraudsters may attempt to open membership accounts in consumer protection systems and register victims' financial product numbers, financial account numbers, and other financial information based on the fraudsters' contact information (e.g., phone numbers, email addresses, etc.). Therefore, internal fraud prevention for consumer protection systems is important.
[0413]
[0418] In one aspect of the present disclosure, when a person attempts to open a membership account with the consumer protection system, the person's identifying information is scanned against blacklists provided by various sources, such as internal blacklists. If there is a match, the consumer protection system will not open the account.
[0414]
[0419] In one aspect of the present disclosure, the consumer protection system may periodically check members against restriction lists, such as OFAC lists, denied party lists, etc. This function may be accomplished by the popular PATRIOT OFFICER system available from GlobalVision Systems, Inc. of Chatsworth, California. The consumer protection system is not a financial institution and therefore does not have the regulatory obligations that financial institutions have. Nevertheless, it may be desirable to identify members on restriction lists and notify financial institutions if their customers are identified members of restriction lists.
[0415]
[0420] This could be an additional service offered by the consumer protection system. In theory, if a financial institution makes sure that all of its customers become members of the consumer protection system, the financial institution could check the customers against the regulatory list without having to worry about complying with regulatory requirements. This service provides an incentive for financial institutions to cooperate with the consumer protection system. Smaller financial institutions can save on compliance overhead by working with the consumer protection system.
[0416]
[0421] In one aspect of the present disclosure, when a person attempts to open a membership account with the consumer protection system, the consumer protection system asks the person to provide their device interface number (e.g., a mobile phone number). In one aspect of the present disclosure, the consumer protection system sends a passcode via message to the device interface (e.g., a mobile phone) number and asks the person to enter the passcode into an interface provided by the consumer protection system to open the account. If the person enters the correct passcode into the screen before the passcode expires, the person truly owns the device interface (e.g., a mobile phone). If the person cannot enter the correct passcode, something is wrong, and the consumer protection system rejects the person's account opening request. This provision prevents one person from opening an account for another person and falsely accusing the other person of fraud.
[0417]
[0422] In one aspect of the present disclosure, the consumer protection system intentionally sends a passcode to a different interface not used by the member to open a membership account. For example, if the member communicates with the consumer protection system through the internet, the consumer protection system sends the passcode to the member's mobile phone. If the member communicates with the consumer protection system through a mobile app, the consumer protection system sends the passcode to the member's email address.
[0418]
[0423] In one aspect of the present disclosure, the consumer protection system compares the mobile phone number and the person's name with the customer records of the mobile phone network carrier that provides mobile phone service to the owner of the mobile phone. An anomaly can be detected when the name of the person applying for a membership account with the consumer protection system differs from the name of the customer subscribing to the mobile phone service. The name of the mobile phone service subscriber can be obtained from the records of the mobile phone network carrier. The consumer protection system can reject the person's account opening application in light of the anomaly.
[0419]
[0424] Checking customer records with a mobile phone network carrier can be time-consuming. In one aspect of the present disclosure, the consumer protection system first opens a membership account and then checks customer records with a mobile phone network carrier. If an existing member's name and mobile phone number do not match the customer records with the mobile phone network carrier, the consumer protection system may conduct a background check on the member.
[0420]
[0425] Generally, if something suspicious is detected before a membership account is opened, the consumer protection system can deny the membership application. If something suspicious is detected after a membership account is opened, the consumer protection system can conduct a background check on the member. In one aspect of the present disclosure, the consumer protection system will not provide any services to the member (e.g., freeze the account) until the background check is successfully completed and the member is proven innocent.
[0421]
[0426] In one aspect of the present disclosure, the consumer protection system performs account ownership verification based on the method described below. For example, if a member has registered four financial accounts A, B, C, and D with the consumer protection system, the consumer protection system can transfer out a first amount from account A, transfer in a second amount from account B, then deposit a third amount into account C, and deposit a fourth amount into account D. The consumer protection system asks the member to provide the correct values for A, B, C, and D, which are randomly set by the consumer protection system. If the member cannot provide the correct answers, the consumer protection system will conduct a background check on the member.
[0422]
[0427] Account ownership verification can be performed for any number of accounts and is not limited to four accounts. Both "withdrawal" and "deposit" actions are used so that members will not feel that the consumer protection system has taken money from them. However, either a "withdrawal" or a "deposit" action is sufficient to verify an account. For example, if a member needs to pay a membership fee, a "withdrawal" action alone is sufficient to verify the account.
[0423]
[0428] Account ownership verification may be performed through other processes. For example, if a member has only one registered financial account, the consumer protection system may withdraw two amounts (e.g., X and Y) and prompt the member to provide the correct values for these two amounts. After the member provides the correct answers, the consumer protection system may credit the combined value (e.g., X+Y) to the financial account to ensure the member does not lose money.
[0424]
[0429] In one configuration, the consumer protection system randomly generates a passcode corresponding to an amount that may include dollar and cent values, and sends the passcode to a transaction system that transacts with the member's registered financial account based on the value of the passcode.
[0425]
[0430] In one aspect of the present disclosure, the consumer protection system prompts the member to enter a passcode through the member's device interface. If the passcode received from the member is the same as the passcode sent from the consumer protection system to the transaction system, the member has control of the registered financial account. This process achieves the account verification goal.
[0426]
[0431] For verification purposes, the passcode can be any number. However, if the consumer protection system withdraws a large amount of money from the member's registered financial account, the member may feel uncomfortable. Therefore, it is advisable to use a small amount to avoid member discomfort.
[0427]
[0432] In one aspect of the present disclosure, the consumer protection system prompts a new member to enter the zip code of their current residence. If the geographic location of the member's device interface (e.g., cell phone) is far from the zip code of the member's current residence, the consumer protection system may conduct a background check on the member.
[0428]
[0433] In one aspect of the present disclosure, the consumer protection system can continue to monitor the geographic location of a new member's device interface. The monitoring determines the amount of time the member's device interface's geographic location is far from their zip code. If the amount of time exceeds a threshold, the consumer protection system can conduct a background check on the member.
[0429]
[0434] In one aspect of the present disclosure, when a member conducts a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's name or a portion of the member's name based on an official identification card provided by the member. If the name or portion of the name differs from or does not correspond to the member's name or portion of the name in the consumer protection system's records, the consumer protection system conducts a background check on the member.
[0430]
[0435] In one aspect of the present disclosure, when a member conducts a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's date of birth or a portion of the member's date of birth based on an official identification card provided by the member. If the date of birth or portion of the date of birth differs from or does not correspond to the member's date of birth or portion of the date of birth in the consumer protection system's records, the consumer protection system conducts a background check on the member.
[0431]
[0436] In one aspect of the present disclosure, if a member's background check fails, the consumer protection system may close a member's account. In one aspect of the present disclosure, if a background check indicates that the member lied, the consumer protection system may close a member's account. In one aspect of the present disclosure, when the consumer protection system closes a member's account due to a fraudulent circumstance (e.g., a failed background check), the consumer protection system adds the member to its internal blacklist.
[0432]
[0437] In one aspect of the present disclosure, the consumer protection system records a timestamp when each financial product, financial account, financial instrument, financial information, etc. is registered by a member. In another aspect of the present disclosure, the consumer protection system verifies the accuracy and ownership of each financial product, financial account, financial instrument, financial information, etc. registered by a member, and begins providing services only to the particular financial product, financial account, financial instrument, financial information, etc. after the verification is successful. Thus, in the consumer protection system's database, each financial product, financial account, financial information, etc. may have a "service initiation timestamp," which may be different from or later than the "registration timestamp."
[0433]
[0438] In one aspect of the present disclosure, if any of the registered financial products, financial accounts, financial instruments, financial information, personal information, etc. is inaccurate, the consumer protection system may notify the member to make corrections. The consumer protection system monitors and records the number of corrections made by each member. In one aspect of the present disclosure, if the number of corrections is greater than a threshold, the consumer protection system may consider conducting a background check on the member.
[0434]
[0439] In one aspect of the present disclosure, whenever a member registers a new financial instrument number, the consumer protection system matches the new financial instrument number with all financial instrument numbers of all members in the database. If there is any match, additional actions, such as a background check, may be performed. A financial instrument number may also refer to a financial account number, a financial instrument, or other types of financial information. In one aspect of the present disclosure, the consumer protection system performs background checks on both the member registering the new financial instrument number and the member with the matching financial instrument number.
[0435]
[0440] In one configuration, the financial institution sends the financial instrument number, some transaction details, and a device interface address (e.g., a mobile phone number) to the consumer protection system for verification purposes. In response, the consumer protection system compares the device interface address provided by the financial institution with the device interface address provided by the member. The member is identified based on the financial instrument number. If the member has a different device interface address, additional actions may be performed. In one aspect of the present disclosure, the consumer protection system performs a background check on the member when the member's device interface address differs from the device interface address provided by the financial institution.
[0436]
[0441] In one aspect of the present disclosure, the above method for detecting conflicting device interface addresses can also be used to detect conflicts in other types of information, such as name, date of birth, etc. If a conflict is detected, the consumer protection system will conduct a background check on the member with the conflicting information.
[0437]
[0442] When the consumer protection system receives a "verification inquiry" from a financial institution, merchant, or another organization regarding a member's transactions related to a particular financial product, the inquiry results may indicate the accuracy of the financial product (or financial account, financial instrument, financial information, etc.). For example, if the member frequently accepts transactions related to the financial product and no financial institution, merchant, or other organization has complained about the member's replies, this further confirms that the member is the true owner of the financial product.
[0438]
[0443] In one aspect of the present disclosure, the consumer protection system records, for each financial product of a member, an inquiry, a timestamp of the inquiry, and an inquiry result. Each inquiry result consists of two parts: a "yes" or "no" answer given by the member, and whether the answer provided by the member resulted in a subsequent complaint from the inquirer.
[0439]
[0444] In one aspect of the present disclosure, the consumer protection system records chargebacks and timestamps of the chargebacks for each of a member's financial products, financial accounts, financial instruments, financial information, etc. The chargeback information is provided by the merchant through a device interface provided by the consumer protection system. If the number of chargebacks by a member is greater than a threshold, the consumer protection system may conduct a background check on the member.
[0440]
[0445] In one aspect of the present disclosure, the consumer protection system determines whether a member is creditworthy based on historical inquiries, inquiry timestamps, inquiry results, chargebacks, chargeback timestamps, etc. for all of the member's financial products. In another aspect of the present disclosure, the consumer protection system establishes a creditworthiness score for each member. In another aspect of the present disclosure, the consumer protection system provides the member's creditworthiness score as a service to financial institutions, merchants, or other organizations.
[0441]
[0446] Fraudsters may attempt to take over a member's account by changing the member's contact information, device interface address, etc. Therefore, security should be used to protect members from changes to the member's contact information, device interface address, etc.
[0442]
[0447] In one aspect of the present disclosure, the consumer protection system asks a member a challenge when the member attempts to change their contact information. In another aspect of the present disclosure, the member creates a set of challenge questions when the member attempts to open a membership account. Challenge questions should not have a "yes" or "no" answer. Therefore, it is a good idea to create challenge questions based on "who, where, what, when, how, etc."
[0443]
[0448] In one aspect of the present disclosure, the consumer protection system uses previous inquiry history or previous user behavior as challenge questions. For example, a question could be, "At which store did you receive a request to verify a transaction through the consumer protection system on or around September 22nd?" Another example could be, "Which financial product did you register with the consumer protection system on or around January 16th?" When these types of challenge questions are used, the application running on the member's device interface (e.g., a mobile app) only needs to show a limited length of history, e.g., seven days, so that a fraudster cannot find the answer to the challenge question from the application running on the device interface.
[0444]
[0449] In one aspect of the present disclosure, the consumer protection system retains all historical records for a period of time, e.g., five years. For example, when a member updates an old credit card number with a new one, the old credit card number and all related records, including the update date, are stored in a database. Such record retention may also be handled by PATRIOT OFFICER systems, which are common in the financial industry.
[0445]
[0450] Although the consumer protection system does not process financial transactions, its operation may be similar to that of a financial institution. Each member may be considered a customer. Each registered financial product, financial account, financial instrument, financial information, identification information, etc. may be considered one account of the customer. Each inquiry from a third party may be considered one type of transaction. Each inquiry result may be considered one type of transaction. Each chargeback may be considered one type of transaction. Each complaint from a third party about a member may be considered one type of transaction. Thus, the intelligent alert system may also be used to generate alerts based on data in the consumer protection system's database. As a result, the intelligent alert system empowers the consumer protection system to prevent fraudulent activity by members or potential members.
[0446]
[0451] Individuals are typically identified by a government-issued unique identification number, such as their name, date of birth, place of residence, Social Security number, driver's license number, passport number, financial instrument number, telephone number, email address, etc. However, for identity verification purposes, partial identification information, such as a person's initials, is far from sufficient. Similarly, other partial information, such as a Social Security number, credit card number, or the last four digits of a driver's license number, street number, last four digits of a zip code, or the last digit of a birth month, is also insufficient for identity verification purposes.
[0447]
[0452] Nevertheless, in one aspect of the present disclosure, when several such partial identification information from the same subject are combined together through a pre-agreed data manipulation process, they form a set of coded data, i.e., an identification code, that can be used for identity verification purposes even if no one understands the meaning of the identification code.
[0448]
[0453] Similarly, in one aspect of the present disclosure, to provide greater security and privacy, advanced encryption techniques encrypt the identifying information to form an identifying code, such that if the decryption key is intentionally hidden or destroyed, the identifying information behind the identifying code cannot be recovered.
[0449]
[0454] In yet another application of the present invention, the encryption described above can be combined with encoding of partial identity information to form an identity code, from which the probability of recovering the original identity is virtually zero. While it is impossible to decode and / or decrypt the identity code to obtain the original identity, two matching identity codes mean that the original identities of the two subjects that both correspond to the matching identity codes can match each other with a very high probability.
[0450]
[0455] For example, the probability that the last five digits of both two people's Social Security numbers and driver's license numbers are the same is 1 in 10 to the power of 10, or 1 in 10 billion. The probability that the two people also have the same last two digits of their birth years is 1 in 10 to the power of 12, or 1 in 1 trillion. Furthermore, if the two people have the same zip code, the probability is 1 in 10 to the power of 17, which is virtually never going to happen. By combining these pieces of information together through a pre-agreed data manipulation process, a set of coded data can be constructed that becomes an identification code.
[0451]
[0456] For a person with an English name, for example, the first two letters of the first name and the first two letters of the last name can be included as part of the identification code. Although these four letters do not provide enough information about the person's name, adding these four letters to the identification code can greatly reduce the chances that two people will have the same identification code.
[0452]
[0457] Financial instruments are very often used to identify individuals. For example, when a financial institution requires a consumer to present two forms of identification, a credit or debit card is commonly accepted as one form of identification. Therefore, a portion of a financial instrument's account number, such as the last four digits of a credit card number, may be included in an identification code to reduce the likelihood that two people will have the same identification code. For example, many people may have the same name, but the last four digits of a credit card number, the zip code of the credit card's billing address, and the cardholder's name can form an identification code that uniquely identifies the cardholder.
[0453]
[0458] The computer industry traditionally uses one byte to represent an English letter or a number. In one aspect of the present disclosure, the English letter or number is converted into another byte that has a different meaning. For example, the letter A may be converted into the letter W. Such a conversion has the effect of hiding the original meaning. For example, the name "John" can be converted into "Oh! a." Someone who does not know the conversion rules has no idea what Oh! a means. The bytes produced by the conversion can be used to form an identification code that is unrelated to the original meaning before the conversion.
[0454]
[0459] Some countries do not use English as an official language, and multi-byte units (e.g., UTF-8, UTF-16, UTF-32, GB18030, etc.) may be used to encode those languages. Modern POSIX documentation defines a "character" as a sequence of one or more bytes that represents a single graphic symbol or control code. Therefore, regardless of which character coding method is used, languages used by different countries or cultures may be composed of single-byte and multi-byte units. To avoid confusion, this disclosure will generally refer to single-byte or multi-byte units as characters.
[0455]
[0460] In one aspect of the present disclosure, a transformation converts each original multi-byte unit into a new multi-byte unit to hide the original meaning, and the new multi-byte units produced by the transformation can be used to form an identification code that hides the original meaning.
[0456]
[0461] In another application of the present disclosure, the transformation converts each byte of the original multi-byte unit into a new byte to hide the original meaning. The new multi-byte units produced by the transformation can be used to form an identification code that hides the original meaning.
[0457]
[0462] In yet another application of the present disclosure, an algorithm decomposes an original set of multi-byte units into a set of bytes, selects some bytes from the set of bytes, converts them into a different set of bytes, rearranges their sequence, and then recombines them to form a new set of multi-byte units. The new set of multi-byte units can be used to form an identification code that hides the original meaning. A person who does not know the conversion rules has no idea what the original set of multi-byte units is.
[0458]
[0463] The above methods for forming an identification code are only a few examples. Regardless of the language, there are many ways to convert a multi-byte unit or set of bytes into an identification code. The identification code could theoretically be reversed to recover some of the original bytes or multi-byte units, but if only a small portion of the original bytes or multi-byte units are used in the conversion, the original information will not be recovered.
[0459]
[0464] Similarly, encrypting enough identifying information to form an identifying code can reduce the likelihood of two people having the same identifying code to nearly zero. For example, hashing, one type of encryption method, can encrypt the identifying data of two subjects. If the identifying information of two subjects stored in two databases has the same hashing result (e.g., hash), then there is a high probability that they are the same subject.
[0460]
[0465] The above methods for forming identification codes using different types of transformation rules are just a few examples. There are many possible transformation rules.
[0461]
[0466] In general, transformations can be categorized into three types: many-to-one, one-to-many, or one-to-one. The input to a transformation is a source. The output of a transformation is an image. A many-to-one transformation may transform multiple different sources into the same image. A one-to-many transformation may transform one unique source into multiple different images. Many-to-one and one-to-many transformations can cause confusion. Therefore, it is desirable to use a one-to-one transformation that transforms a unique source into a unique image.
[0462]
[0467] By using a one-to-one transformation method to transform a sufficient amount of identifying information for each object into a corresponding image dataset, the image dataset can be used to identify the object even if it does not contain any of the original identifying information. As a result, if two image datasets are identical, their corresponding source datasets are also identical, which means that these two matched image datasets belong to the same object.
[0463]
[0468] In one aspect of the present disclosure, image data of a target is used to identify the target. The image data is generated from the identification data by a one-to-one translation. The image data of the target is also referred to as a token of the target's identity, a target token, or an identification code.
[0464]
[0469] Two parties know they are discussing the same subject when discussing an issue based on the same identification code. Third parties cannot figure out the true personal information behind this identification code, thus preserving the subject's privacy. Identification codes can be used to identify and simultaneously preserve the privacy of any subject, including people, objects, organizations, legal entities, tangible property, intangible property, documents, concepts, plans, designs, interests, assets, liabilities, trade secrets, stocks, money, confidential information, financial instruments, non-financial instruments, etc.
[0465]
[0470] To achieve the goal of using the same one-to-one conversion method by two parties, in one aspect of the present disclosure, a pre-agreed rule or set of rules is used to select, encode, arrange, encrypt, convert, and / or transform identifying information from a subject to form an identifying code that is inherently unique to that subject and conceptually serves as a public proxy for that subject's personal identifying data, a token of the subject's personal identifying data, or a token of the subject.
[0466]
[0471] In one aspect of the present disclosure, the identification code is established based on a pre-agreed, relatively simple transformation of the identification information, such as a simple concatenation of only a few designated individual numbers and letters selected from the original identification information.
[0467]
[0472] In another aspect of the present disclosure, the identification code is established by a pre-agreed, relatively complex transformation of designated numbers, letters, and bytes of the original identification information, which may include known methods of data conversion, transformation, encryption, and / or encoding of selected identification data, thereby further protecting the privacy of the original identification information from unauthorized access.
[0468]
[0473] Furthermore, because only a small, relatively meaningless portion of personal information is used to generate the identification code, even if that portion is recovered by a malicious third party, the privacy of the remaining identification information is still maintained and the personal information of the relevant subject cannot be stolen.
[0469]
[0474] In one aspect of the present disclosure, multiple computer systems are connected through a network (e.g., the Internet). Each of the computer systems may reside in one organization. In one aspect of the present disclosure, a central computer system is connected to the network to control the functions, features, and communications of the computer systems connected to the network.
[0470]
[0475] In one aspect of the present disclosure, the one-to-one translation converts each customer's identification information into a unique identification code that is an image dataset at each organization. All customer identification codes are stored in a database at each organization. Relationship information (e.g., account number, customer number, etc.) linking each identification code to that customer is also stored in the database.
[0471]
[0476] In one aspect of the present disclosure, a computer interface is provided at each of the computer systems so that a person at the organization can select any customer and send that customer's identification code to a central computer system in the network. The organization sending the identification code is called the sender or originator organization of the identification code.
[0472]
[0477] In one aspect of the present disclosure, when a central computer system receives an identification code from an originator organization, the central computer system sends the identification code to all other computer systems on the network. Each of the other computer systems on the network matches the received identification code generated by the originator organization against all identification codes stored in its database. These identification codes stored in the database are tokens or images of the identities of the organization's customers.
[0473]
[0478] In one aspect of the present disclosure, if there is a match between the received identification code and one of the identification codes stored in the database, the computer system of the organization where the match occurred sends a message to the central computer system indicating that a match has been found at that organization. The organization with the matching identification code is referred to as the recipient with the matching identification code or the matched organization.
[0474]
[0479] In one aspect of the present disclosure, a computer system having a matched identification code uses relevant information (e.g., account number, etc.) to identify the corresponding customer whose identification information was converted into the matched identification code.
[0475]
[0480] In one aspect of the present disclosure, the computer system of the matched organization sends additional information related to the customer having the matched identification code to the central computer system, which may include background information and transaction information for the customer having the matched identification code.
[0476]
[0481] In one aspect of the present disclosure, the central computer system sends the additional information received from the matched organization's computer system to the originator organization's computer system that sends the identification code.
[0477]
[0482] In one aspect of the present disclosure, the originator organization's computer system uses relationship information (e.g., customer number, etc.) to identify the customer whose identity has been converted into an identification code. This customer is referred to as the originator customer.
[0478]
[0483] In one aspect of the present disclosure, the computer system of the originator organization sends additional information related to the originator customer to the central computer system, which may include background information and transaction information for the originator customer.
[0479]
[0484] In one aspect of the present disclosure, the central computer system sends additional information related to the originator customer to the computer system of the matched organization. In one aspect of the present disclosure, the central computer system sends contact information for a contact person at the originator organization to a contact person at the matched organization. In one aspect of the present disclosure, the central computer system sends contact information for a contact person at the matched organization to a contact person at the originator organization. As a result, users of computer systems on a network can interact with each other to coordinate work on common objects represented by identification codes without disclosing identifying information about their own objects not already known to other users.
[0480]
[0485] In one aspect of the present disclosure, the originator organization's computer system performs an analysis using the additional information of the matched customer received from the matched organization and the originator organization's own information to derive a new piece of information about the originator customer. For example, the new piece of information may relate to potential fraudulent activity, money laundering activity, crime, etc., associated with the originator customer. The new piece of information may also relate to virtuous activity, such as anonymous donations. When more information is available from more data sources, better analysis can be performed to generate better predictions, estimates, conclusions, etc.
[0481]
[0486] Similarly, in one aspect of the present disclosure, the matched organization's computer system performs an analysis using the additional information about the originator customer received from the originator organization and the matched organization's own information to derive new information about the matched customer, for example, the new information may relate to potential fraudulent activity, money laundering activity, crime, etc., associated with the matched customer.
[0482]
[0487] In one embodiment of the present disclosure, the computer system of the originator organization sends the identification code and one related information that needs to be verified to a central computer system. In one embodiment of the present disclosure, the central computer system sends the identification code and one related information received from the originator organization to all other computer systems on the network. In one embodiment of the present disclosure, the computer system of the matched organization uses the matched identification code to identify the matched customer and then verifies whether the received one related information is accurate. In one embodiment of the present disclosure, the computer system of the matched organization sends a message to the central computer system indicating whether the one information related to the identification code is accurate. In one embodiment of the present disclosure, the central computer system sends a message to the computer system of the originator organization indicating whether the one information related to the identification code received from the matched originator is accurate.
[0483]
[0488] The above method has a broadcasting effect. This method can be used when the originating organization does not know which other organizations can verify this information. Therefore, a central computer system sends an identification code to all other computer systems on the network.
[0484]
[0489] In some cases, the originating organization knows which other organizations can verify this piece of relevant information. In such situations, in one aspect of the present disclosure, the originating organization's computer system sends to the central computer system an identification code, the piece of relevant information to be verified, and the identity of the particular computer system on the network.
[0485]
[0490] In one embodiment of the present disclosure, the central computer system sends the identification code and one related information received from the originator organization to a specific computer system. In one embodiment of the present disclosure, the specific computer system identifies the matched customer using the matched identification code and then verifies whether the received one related information is accurate. In one embodiment of the present disclosure, the specific computer system sends a message to the central computer system indicating whether the one information related to the identification code is accurate. In one embodiment of the present disclosure, the central computer system sends a message to the originator organization's computer system indicating whether the one information related to the identification code received from the specific computer system is accurate. Instead of verifying whether the one information related to the identification code is accurate, in one embodiment of the present disclosure, the originator organization can request the matched organization to send specific information about the matched customer based on the identification code.
[0486]
[0491] The above application is very useful. For example, if a consumer applies for a new account with Organization ABC and states that they have an account with Bank XYZ, Organization ABC can quickly verify whether the information provided by the consumer is correct if both Organization ABC and Bank XYZ are on the disclosed network, even though the consumer's identifying information has never been transmitted over the network. Only an identifying code that cannot be understood by a third party is transmitted over the network. The consumer's privacy is fully protected.
[0487]
[0492] In one embodiment of the present disclosure, to verify whether a consumer truly has an account with Bank XYZ, Organization ABC may ask the consumer to provide an account number, the amount of a recent transaction, the date of the most recent transaction, other recent activity, background information, or any other information that may be stored at Bank XYZ. Alternatively, in one embodiment of the present disclosure, to verify whether a consumer truly has an account with Bank XYZ, Organization ABC may collect information from Bank XYZ through the consumer's identification code and then ask the consumer to answer several questions based on that information. For example, the questions may be, "What was the amount of the last transaction on that account?" and "What was the date of the last transaction?" If the consumer can answer all of these questions correctly, it is highly likely that the consumer has an account with Bank XYZ.
[0488]
[0493] Because some consumers may have poor memories, in one aspect of the present disclosure, questions may be designed to have multiple options. For example, a question may ask the consumer to choose one of five numbers as the amount of the last transaction. In one aspect of the present disclosure, after the consumer correctly answers a series of questions, organization ABC can confidently open an account or conduct a transaction or fulfill a request made by the consumer without worrying about identity theft.
[0489]
[0494] In one aspect of the present disclosure, a computer system at an originator organization sends an identification code and a set of requests, which may include a request for information, a request for action, or other types of requests, to a central computer system, which in one aspect of the present disclosure sends the identification code and set of requests received from the originator organization to all other computer systems on the network.
[0490]
[0495] In one aspect of the present disclosure, the matched organization's computer system uses the matched identification code to identify the customer whose identification information corresponds to the identification code. In the case of a request for information, the matched organization's computer system collects some information about the customer based on a set of requests. In the case of a request for action, the matched organization's computer system instructs the matched organization's device interface to take the requested action.
[0491]
[0496] In one aspect of the present disclosure, the computer system of the matched organization sends the information collected based on the matched identification code to a central computer system. In one aspect of the present disclosure, the central computer system sends the information collected based on the matched identification code to a computer system of the originator organization.
[0492]
[0497] The above application can be used, for example, by law enforcement authorities. For example, if a law enforcement agency (e.g., the FBI) needs information about a crimin...
Claims
1. 1. A computer-implemented method for protecting against financial crime, comprising: receiving, at a third computer system, an identification of the first subject from the first computer system; converting, by the third computer system, the identification information of the first subject into a first identification code that conceals the identification information of the first subject; receiving, at the third computer system, a second identification code and a piece of information from the second computer system; sending a query related to the piece of information from the third computer system to the first computer system when the first identification code corresponds to the second identification code; receiving, at the third computer system, a response to the question from the first computer system; sending a message corresponding to the response from the third computer system to the second computer system; 10. A computer-implemented method comprising:
2. 2. The computer-implemented method of claim 1, wherein the identification information includes at least one of a name, an address, a date of birth, a personal identification number, a user ID, a password, a taxpayer identification number, a type of identification document used, an identification number associated with the identification document, a country, state, government agency, and / or private organization that issued the identification document, an expiration date of the identification document, a financial instrument number, a type of the financial instrument, an expiration date of the financial instrument, a financial account number, a type of the financial account, a telephone number, a screen name, an email address, a photograph, a fingerprint, an iris scan, a physical characteristic, biometric information, other information that can be used to identify a person, or a combination thereof.
3. 3. The computer-implemented method of claim 2, wherein the financial instruments include at least one of cash, virtual currency, virtual securities, virtual certificates, credit cards, debit cards, ATM cards, prepaid cards, stored value cards, gift cards, checks, monetary instruments, wire transfers, ACH transfers, letters of credit, notes, securities, commercial paper, commodities, precious metals, gold, silver, any instrument that can be used to conduct a financial transaction, or combinations thereof.
4. 2. The computer-implemented method of claim 1, wherein the identification information of the first object is converted into the first identification code through at least one of selecting characters, encoding characters, arranging characters, recombining characters, encrypting characters, transforming characters, breaking characters into bytes, selecting bytes, transforming bytes, rearranging the order of bytes, recombining bytes into characters, encrypting bytes, or a combination thereof.
5. 2. The computer-implemented method of claim 1, wherein the first object comprises at least one of a person, an object, an organization, a legal entity, tangible property, intangible property, a document, a concept, a plan, a design, profits, assets, liabilities, trade secrets, stock, money, confidential information, financial instruments, non-financial instruments, or combinations thereof.
6. 2. The computer-implemented method of claim 1, wherein the one piece of information is associated with at least one of cash, virtual currency, virtual securities, virtual certificates, credit cards, debit cards, ATM cards, prepaid cards, stored value cards, gift cards, checks, monetary instruments, wire transfers, ACH transfers, letters of credit, notes, securities, commercial paper, commodities, precious metals, gold, silver, or combinations thereof.
7. The computer-implemented method of claim 1 , wherein the first computer system comprises a device interface associated with at least one of an individual, an organization, or a combination thereof.
8. 8. The computer-implemented method of claim 7, wherein the device interface comprises at least one of a keyboard, keypad, monitor, display, terminal, computer, control panel, vehicle dashboard, network interface, mechanical interface, electrical interface, electronic interface, magnetic interface, electromagnetic interface including electromagnetic wave interface, optical interface, light interface, acoustic interface, video interface, audio interface, contactless interface, mobile phone interface, smartphone interface, smartbook interface, tablet interface, other communication device interface, personal digital assistant (PDA) interface, handheld device interface, portable device interface, wireless interface, wired interface, or a combination thereof.
9. The computer-implemented method of claim 1 , wherein the second computer system comprises a device interface associated with at least one of a financial institution, a merchant, an organization, or a combination thereof.
10. 10. The computer-implemented method of claim 9, wherein the device interface comprises at least one of a keyboard, keypad, monitor, display, terminal, computer, control panel, vehicle dashboard, network interface, mechanical interface, electrical interface, electronic interface, magnetic interface, electromagnetic interface including electromagnetic wave interface, optical interface, light interface, acoustic interface, video interface, audio interface, contactless interface, mobile phone interface, smartphone interface, smartbook interface, tablet interface, other communication device interface, personal digital assistant (PDA) interface, handheld device interface, portable device interface, wireless interface, wired interface, or combinations thereof.
11. 10. The computer-implemented method of claim 9, wherein the financial institution comprises at least one of a bank, a credit union, a money services provider, a financial holding company, an insurance company, an insurance agency, a mortgage lender, a mortgage institution, a stockbroker, a stock agency, a bond broker, a bond agency, a commodity broker, a commodity agency, a trading company, a trading agency, another financial service provider, another financial institution, a stock exchange, a commodity exchange, a currency exchange, a virtual currency company, a virtual currency issuer, a virtual currency service provider, a virtual currency network provider, a virtual currency computer provider, a virtual currency dealer, a virtual currency exchange, a virtual securities exchange, a bond exchange, another exchange, a fund manager, an investment company, a private equity firm, a venture capital firm, a virtual currency company, a merchant acquirer, a payment processor, a payment card issuer, a payment card program administrator, an internet merchant, another financial services organization, or a combination thereof.
12. The computer-implemented method of claim 1 , wherein the third computer system comprises a device interface connected to a network of computer systems.
13. 13. The computer-implemented method of claim 12, wherein the device interface comprises at least one of a keyboard, keypad, monitor, display, terminal, computer, control panel, vehicle dashboard, network interface, mechanical interface, electrical interface, electronic interface, magnetic interface, electromagnetic interface including electromagnetic wave interface, optical interface, light interface, acoustic interface, video interface, audio interface, contactless interface, mobile phone interface, smartphone interface, smartbook interface, tablet interface, other communication device interface, personal digital assistant (PDA) interface, handheld device interface, portable device interface, wireless interface, wired interface, or combinations thereof.
14. 1. A computer system for protecting against financial crimes, comprising: Memory devices and at least one processor coupled to the memory device; wherein the at least one processor receiving, from a first computer system, an identification of a first subject; converting the identity of the first subject into a first identity code that conceals the identity of the first subject; receiving a second identification code and a piece of information from a second computer system; sending a query related to the piece of information to the first computer system when the first identification code corresponds to the second identification code; receiving an answer to the question from the first computer system; sending a message corresponding to the response to the second computer system; A computer system configured to:
15. 15. The computer-implemented method of claim 14, wherein the identification information of the first object is converted into the first identification code through at least one of selecting characters, encoding characters, arranging characters, recombining characters, encrypting characters, transforming characters, breaking characters into bytes, selecting bytes, transforming bytes, rearranging the order of bytes, recombining bytes into characters, encrypting bytes, or a combination thereof.
16. 1. A non-transitory computer-readable medium having recorded thereon program code for privately and confidentially managing a network of computer systems, said program code comprising: program code for receiving, from a first computer system, an identification of a first subject; program code for converting the identification information of the first object into a first identification code that conceals the identification information of the first object; program code for receiving a second identification code and a piece of information from a second computer system; program code for transmitting a query related to the piece of information to the first computer system when the first identification code corresponds to the second identification code; program code for receiving an answer to the question from the first computer system; program code for sending a message corresponding to the answer to the second computer system; 1. A non-transitory computer-readable medium comprising:
17. 17. The computer-implemented method of claim 16, wherein the identification information of the first object is converted into the first identification code through at least one of selecting characters, encoding characters, arranging characters, recombining characters, encrypting characters, transforming characters, breaking characters into bytes, selecting bytes, transforming bytes, rearranging the order of bytes, recombining bytes into characters, encrypting bytes, or a combination thereof.
18. 1. A computer-implemented method for privately and confidentially sharing information between a network of computer systems, comprising: receiving, at a third computer system, from the first computer system, a first identification code transformed from the identification information of the first subject, wherein the first identification code conceals the identification information of the first subject; transmitting the first identification code from the third computer system to a second computer system; receiving, at the third computer system, a message from the second computer system when the first identification code matches a second identification code converted from an identification of the second subject stored in the second computer system, wherein the second identification code conceals the identification of the second subject; performing, by the third computer system, an action in response to the message; 10. A computer-implemented method comprising:
19. 1. A computer system for privately and confidentially sharing information between a network of computer systems, comprising: a memory device; at least one processor coupled to the memory device; wherein the at least one processor receiving, from a first computer system, a first identification code transformed from an identification of a first subject, wherein the first identification code conceals the identification of the first subject; transmitting the first identification code to a second computer system; receiving a message from the second computer system when the first identification code matches a second identification code converted from an identification of a second subject stored in the second computer system, wherein the second identification code conceals the identification of the second subject; performing an action in response to said message; A computer system configured to:
20. 1. A computer-implemented method for protecting against financial crime, comprising: receiving, at a third computer system, an identification of the first subject from the first computer system; converting, by the third computer system, the identification information of the first subject into a first identification code that conceals the identification information of the first subject; transmitting the first identification code from the third computer system to a second computer system; receiving, at the third computer system, a piece of information from the second computer system when the second computer system determines that the first identification code matches a second identification code converted from a second object stored in the second computer system, wherein the second identification code conceals the identity of the second object; sending a query related to the piece of information from the third computer system to the first computer system; receiving, at the third computer system, a response to the question from the first computer system; if the answer is correct, approving the request from the first computer system by the third computer system; 10. A computer-implemented method comprising:
21. 1. A computer-implemented method for protecting against financial crime, comprising: transmitting a second passcode from the third computer system to the second computer system; receiving, at the third computer system, a first passcode from the first computer system in response to transmitting the second passcode; receiving, at the third computer system, a first financial instrument number from the first computer system; receiving, at the third computer system, a second financial instrument number and a transaction description from a fourth computer system; transmitting the description of the transaction from the third computer system to the first computer system when the first passcode corresponds to the second passcode and the first financial instrument number matches the second financial instrument number; receiving, at the third computer system, a message from the first computer system in response to transmitting the description of the transaction; sending an instruction corresponding to the message from the third computer system to the fourth computer system; 10. A computer-implemented method comprising:
22. 1. A computer system for protecting against financial crimes, comprising: a memory device; at least one processor coupled to the memory device; wherein the at least one processor receiving, from a first computer system, an identification of a first subject; converting the identity of the first subject into a first identity code that conceals the identity of the first subject; transmitting the first identification code to a second computer system; receiving a piece of information from the second computer system when the second computer system determines that the first identification code matches a second identification code converted from a second object stored in the second computer system, wherein the second identification code conceals the identity of the second object; sending a query related to the piece of information to the first computer system; receiving an answer to the question from the first computer system; if the answer is correct, approving the request from the first computer system; A computer system configured to:
23. 1. A computer system for protecting against financial crimes, comprising: a memory device; at least one processor coupled to the memory device; wherein the at least one processor transmitting a second passcode to a second computer system; receiving a first passcode from the first computer system in response to transmitting the second passcode; receiving a first financial instrument number from the first computer system; receiving a second financial instrument number and a transaction description from a fourth computer system; transmitting the description of the transaction to the first computer system when the first passcode matches the second passcode and the first financial instrument number matches the second financial instrument number; receiving a message from the first computer system in response to transmitting the description of the transaction; sending an instruction corresponding to the message to the fourth computer system; A computer system configured to: