Intelligent Warning System

A computer-based system addresses the challenge of detecting money laundering by analyzing transaction data and calculating conditional probability values, enhancing detection efficiency and reducing human error.

JP7697095B2Active Publication Date: 2025-06-23SONG YU-SHENG +3
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024062329
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-01-14
Filing Date
2024-04-08
Publication Date
2025-06-23
Estimated Expiration
2040-02-10

AI Technical Summary

Technical Problem

Conventional systems struggle to effectively detect and report suspicious financial activities, particularly money laundering, due to reliance on human operators and ineffective fraud detection methods that fail to identify changes in behavior.

Method used

A computer-implemented method that uses a system of computer systems to detect money laundering activities by analyzing transaction data, calculating conditional probability values, and comparing these values to thresholds to identify potential cases for investigation and reporting.

Benefits of technology

The system improves the detection of suspicious financial activities by reducing human error and increasing efficiency, allowing for the identification of money laundering cases that may not involve changes in behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007697095000001
    Figure 0007697095000001
  • Figure 0007697095000002
    Figure 0007697095000002
  • Figure 0007697095000003
    Figure 0007697095000003
Patent Text Reader

Abstract

To provide an intelligent warning system capable of gradually learning from an investigator, automatically determining some future potential cases with little human involvement, and improving warning management.SOLUTION: An intelligent warning system triggers a potential case based on a set of scenarios, sends the potential case and a report having a default narrative to an investigator, learns a writing style of the investigator through changes made by the investigator to a default narrative, automatically submits a report having the narrative matching the writing style of the investigator, and after investigation, records, in a database, investigation results about each potential case, an associated set of scenarios with the triggered potential case, and a date and time of such investigation.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Cross - Reference to Related Applications

[0001]

[0001] This application claims the benefit of U.S. Patent Application No. 16 / 742,766, filed on January 14, 2020, entitled "INTELLIGENT ALERT SYSTEM" and U.S. Patent Application No. 16 / 742,780, filed on January 14, 2020, entitled "INTELLIGENT REPORT WRITER", both of which claim priority to U.S. Provisional Patent Application No. 62 / 805,085, filed on February 13, 2019, entitled "INTELLIGENT ALERT SYSTEM", and the disclosures of which are hereby incorporated by reference in their entirety.

Technical Field

[0002]

[0002] This disclosure generally relates to intelligent alert systems. More specifically, this disclosure relates to systems and methods for improving alert management.

Background Art

[0003]

[0003] The amount of data available for public consumption is increasing at an exponential rate. Data can be used to discover hidden opportunities or reveal bad events. In conventional information management systems, manual searches, report - based search systems, and / or alert - based search systems can be used. These conventional search systems can be used to detect and report suspicious activities.

[0004]

[0004] The U.S. Bank Secrecy Act was first established in 1970. Based on the Bank Secrecy Act, financial institutions must report suspicious activities to the government. Heretofore, financial institutions have trained front - line staff (e.g., bank tellers) to observe and identify suspicious activities. However, most financial institutions have been unable to effectively comply with the Bank Secrecy Act. After the tragedy of 9 / 11, U.S. lawmakers thought that financial institutions could have prevented the 9 / 11 tragedy by effectively complying with the Bank Secrecy Act.

[0005]

[0005] To further strengthen the Bank Secrecy Act, the U.S. Congress passed the U.S. Patriot Act and enacted severe civil and / or criminal penalties for violations of the Bank Secrecy Act. Further, U.S. government agencies such as the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), state banking departments, and financial institutions bureaus strictly oblige financial institutions to comply with the Bank Secrecy Act, particularly the obligation to submit Suspicious Activity Reports (SARs) to FinCEN.

[0006]

[0006] Suspicious activities cover a very wide range. For example, money laundering, terrorist financing, fraud, embezzlement, identity theft, computer intrusion, private financial transactions, acceptance and giving of bribes, false statements, forged securities, mysterious disappearances, etc. are all classified as suspicious activities.

[0007]

[0007] Nevertheless, many financial institutions are unable to detect and report suspicious activities. In fact, many financial institutions use products that are effective in preventing fraud but ineffective in preventing money laundering or other financial crimes. Generally, since a wrongdoer who steals the personal information (or financial products) of a victim behaves differently from the victim, fraud can be detected based on changes in behavior. A computer system can detect fraud cases when the activities of an account differ from the expected activities derived from past activities.

[0008]

[0008] For example, in a U.S. application (Publication No. 2003 / 0177087), it is specified that high-risk variables can include, for example, changes in the normal behavior of an account indicated when a transaction deviates from its profile. According to this publication, Beta models, Delta models, and Theta models are used to detect transactions that deviate from a customer's profile.

[0009]

[0009] However, money laundering and some other financial crimes can be committed without a change in behavior. As a result, with traditional approaches to detecting fraud based on changes in behavior, some basic money laundering activities and other financial crimes cannot be detected. In the area of money laundering, higher-risk customers may not be suspicious. For example, money service businesses (MSBs), pawnbrokers, ATM vendors, flight attendants, etc. are typically classified as higher-risk customers by banks in the bank's money laundering prevention programs. However, this does not mean that these higher-risk customers are engaging in money laundering activities. These customers are associated with a higher risk, but there may be nothing wrong with these customers.

[0010]

[0010] Some businesses are very difficult to monitor. For example, MSBs handle a large number of transactions every day, and with traditional approaches, it may not be possible to detect a single money laundering transaction mixed in with these large numbers of transactions.

[0011]

[0011] The issues to be noted in complying with the USA Patriot Act and the Bank Secrecy Act (BSA) are just some examples to illustrate the importance of identifying suspicious activities. Identifying suspicious activities can also be used to comply with other laws such as the Fair and Accurate Credit Transactions Act (FACT Act), the Unlawful Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA) regarding the reporting of financial abuse against the elderly, the Sarbanes-Oxley Act (SOX), regulations set by the Office of Foreign Assets Control (OFAC), and other laws and regulations.

[0012]

[0012] Compliance with regulations has conventionally been implemented by means of guidelines and procedures that require human operators to take certain specific actions in response to certain conditions. For example, in order to comply with the banking secrecy law, a bank trains its tellers at the branch to observe and report anything suspicious.

[0013]

[0013] This conventional approach is no longer effective in modern times because customers no longer need to visit a bank branch. For example, customers can conduct remote electronic transactions (e.g., via the Internet), and there are numerous financial products available to customers (e.g., checks, credit cards, debit cards, etc.). Furthermore, criminals are sophisticated and know how to avoid attracting the attention of tellers. As a result, it is insufficient to rely on tellers to detect suspicious activities in order to comply with the banking secrecy law.

[0014]

[0014] Furthermore, the cost of this human-based approach is very high. In order to ensure that human operators accurately know how to comply with different laws and regulations and how to handle each different situation, intensive training must be conducted regularly. However, human operators are prone to making mistakes. In fact, many financial institutions have received severe penalties from government agencies for their failure to comply with different laws and regulations due to human oversight.

[0015]

[0015] In order to improve the detection of different types of suspicious activities and to assist companies in complying with different types of laws and regulations, it is desirable to improve the search system. The methods, functions, embodiments, computer systems, networks, software, hardware, mechanisms, and other components used to detect suspicious activities can also be used for other applications or other organizations for purposes other than detecting suspicious activities.

Summary of the Invention

[0016]

[0016] This disclosure includes several embodiments that can be combined together to form various methods. The method detects money laundering activities. The method includes detecting, by a first computer system, a first potential case when a flagged scenario within a cause vector of a first potential case related to money laundering meets a detection criterion. The method also includes comparing, by the first computer system, a first ratio of a first value of the cause vector to a second value of the cause vector with a threshold. The method also includes transmitting, when the first ratio is less than the threshold, the first potential case from the first computer system to a second computer system for investigation. The method further includes adjusting, by the first computer system, the first value when the result of the investigation indicates that the first potential case is a true positive. The method also includes adjusting, by the first computer system, the second value based on a cause vector that meets the detection criterion. The method further includes transmitting, when the first potential case is a true positive, a first report related to the first potential case from the first computer system to a third computer system.

[0017]

[0017] Another method detects money laundering activities. The method includes detecting, by a first computer system, a potential case when a flagged scenario within a cause vector of the potential case related to money laundering meets a detection criterion. The method also includes calculating, by the first computer system, a conditional probability value for the potential case based on the cause vector. The method further includes comparing, by the first computer system, the conditional probability value with a threshold. The method also includes transmitting, when the conditional probability value is greater than the threshold, a report related to the potential case from the first computer system to a second computer system.

[0018]

[0018] Yet another method detects money laundering activities. This method includes detecting, by a first computer system, a potential case when a flagged scenario within a first cause vector for a potential case related to money laundering meets a detection criterion. The method also includes generating, by the first computer system, a composite cause vector by combining the first cause vector with a second cause vector of a previous potential case. The method further includes calculating, by the first computer system, a conditional probability value for a case triggered by the composite cause vector. The method also includes comparing, by the first computer system, the conditional probability value with a threshold. The method also includes transmitting, when the conditional probability value is greater than the threshold, a report related to the potential case and the previous potential case from the first computer system to a second computer system.

[0019]

[0019] Yet another method detects money laundering activities. The method includes detecting, by a first computer system, a potential case when a flagged scenario within a cause vector for a potential case related to money laundering meets a detection criterion. The method also includes calculating, by the first computer system, a conditional probability value for a case triggered by a child vector of the cause vector. The method further includes comparing, by the first computer system, the conditional probability value with a threshold. The method also includes transmitting, when the conditional probability value is greater than the threshold, a report related to the potential case from the first computer system to a second computer system.

[0020] Another method detects money laundering activities. The method includes detecting, by a first computer system, a potential case when a flagged scenario within a first cause vector for money laundering meets a detection criterion. The method also includes generating, by the first computer system, a composite cause vector by combining the first cause vector with a second cause vector of a previous potential case. The method also includes calculating, by the first computer system, conditional probability values for child vectors of the composite cause vector. The method further includes comparing, by the first computer system, the conditional probability values to a threshold. The method also includes transmitting, when the conditional probability values are greater than the threshold, reports related to the potential case and the previous potential case from the first computer system to a second computer system.

[0021]

[0021] The computer-implemented method generates a report. The method includes storing, in a database of a first computer system, a first fact related to a first subject, a second fact related to a second subject, and a third fact related to a third subject. The first fact, the second fact, and the third fact have the same field name in the database. The method also includes receiving, in the first computer system, from a second computer system, a first report of the first subject. The first report includes the first fact and a first set of link words generated by a human writer. The method further includes sending the first report of the first subject from the first computer system to a third computer system. The method includes sending the second fact and the first set of link words from the first computer system to the second computer system. The method further includes receiving, in the first computer system, from the second computer system, a second report of the second subject. The second report includes the second fact and a second set of link words generated by a human writer. The method includes sending the second report of the second subject from the first computer system to the third computer system. The method also includes sending, from the first computer system to the third computer system, a third report of the third subject when the first set of link words corresponds to the second set of link words. The third report includes the third fact and the second set of link words.

[0022]

[0022] The above methods are just a few examples. Many other methods can be formed by combining and rearranging the embodiments of the present disclosure.

[0023]

[0023] This fairly broadly outlines the features and technical advantages of the present disclosure so that the following detailed description can be better understood. Additional features and advantages of the present disclosure are described below. It should be understood by those skilled in the art that the present disclosure can be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes as those of the present disclosure. It should also be recognized by those skilled in the art that such equivalent configurations do not depart from the teachings of the present disclosure as set forth in the appended claims. The novel features believed to be characteristic of the present disclosure will be better understood from the following description when considered in connection with the accompanying drawings, together with further objectives and advantages. However, it should be clearly understood that each of the drawings is provided for purposes of illustration and description only and is not intended as a definition of the limits of the present disclosure.

[0024]

[0024] The features, nature, and advantages of the present disclosure will become more apparent from the detailed description set forth below when considered in conjunction with the drawings.

Brief Description of the Drawings

[0025]

Figure 1

[0025] Illustrates a system and network diagram of an intelligent warning system according to an aspect of the present disclosure.

Figure 2

[0026] It is a flowchart for an intelligent warning system according to an aspect of the present disclosure.

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0026]

[0027] The detailed description set forth below is intended as a description of various configurations in connection with the accompanying drawings and is not intended to represent the only configuration in which the concepts described herein may be implemented. The detailed description includes specific details for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form in order not to obscure such concepts. As used herein, the use of the term "or" may mean either an "inclusive OR" or an "exclusive OR" depending upon the context of its conventional application.

[0027]

[0028] Aspects of the present disclosure are directed to an intelligent warning system. In one configuration, a computer system monitors transactions and / or activities to generate warnings. The computer system can learn from humans and become smarter by automatically accepting potential cases as true positives and / or rejecting potential cases as false positives. As a result, this computer system can help financial institutions reduce human resources while still complying with laws and regulations such as the Bank Secrecy Act.

[0028]

[0029] Depending on the details of the law or regulation, the computer system may use different functions or methods to monitor different types of activities. The present disclosure provides various details for monitoring transactions and activities in order to reduce human resources while still complying with different requirements, laws, and regulations. The computer system of the present disclosure may also be used for other applications or other purposes. The computer system of the present disclosure can reduce or eliminate human labor and / or human error, reduce resources, save money, and improve results.

[0029]

[0030] In a conventional information management system, an individual manually searches the Internet and / or databases for data. Manual searches are time-consuming. To improve manual searches, decision-makers often hire additional searchers to assist in performing manual searches.

[0030]

[0031] Additionally, in some conventional information management systems, various reports with graphics are generated to summarize or compare data. By reading the reports, manual searches can be improved. Still, when a large amount of data is involved, it can be time-consuming to read the reports. Additionally, it is unrealistic for the human eye to identify events from the various numerical values presented in the reports. When humans are tasked with reading multiple reports, they may not be able to identify different problems.

[0031]

[0032] To improve searches, in some conventional systems, warnings are generated when conditions are met. Warning systems can reduce the need for humans to read reports. That is, the warning can notify the user of a particular matter and provide data regarding that matter. Compared to a report-based approach, warning systems reduce the amount of time and manpower.

[0032]

[0033] To increase efficiency and reduce the need for human monitoring, it is desirable to improve warning systems. Aspects of the present disclosure are directed to an information management system that processes warnings via a computer system. The information management system may be referred to as an intelligent warning system.

[0033]

[0034] Warning systems can be used by various types of organizations. For example, financial institutions are legally obligated to report suspicious activities to the government. Therefore, financial institutions can use warning systems to determine when suspicious activities are detected. As another example, a loan company can use a warning system to generate a warning when a borrower may be delinquent in loan payments. In yet another example, a social media company can use a warning system to generate a warning when a target of clickbait sales is identified. As another example, a defense-related company can use a warning system to identify security policy violations. In another example, the police can use a warning system to generate a warning before a crime is committed. Warning systems are not limited to organizations and can also be used by families or individuals. For example, an individual can receive a warning when an investment opportunity is realized and / or before the stock market crashes.

[0034]

[0035] As described above, warning systems have various uses. Aspects of the present disclosure are not limited to the uses described above. The methods, functions, embodiments, computer systems, networks, software, hardware, firmware, mechanisms, and other components of the present disclosure can be used by other types of individuals and organizations for other purposes. For the sake of clarity, the present disclosure describes an example of the use of a warning system in a financial institution for detecting suspicious activities.

[0035]

[0036] The U.S. government strictly enforces that companies comply with the U.S. Patriot Act, the Bank Secrecy Act (BSA), the Fair and Accurate Credit Transactions Act (FACT Act), the Unlawful Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), the rules set by the Office of Foreign Assets Control (OFAC), and other related laws and regulations. Companies can include, for example, financial institutions such as banks, credit unions, mortgage companies, money service businesses, stockbrokers, insurance companies, etc. For violations of these laws and regulations, financial institutions have had billions of dollars in civil money penalties (CMP) imposed by the U.S. government. Criminal penalties are also imposed on some individuals working for financial institutions.

[0036]

[0037] Financial institutions are just one type of business. Organizations that need to comply with these laws and regulations are not just financial institutions. Many other types of businesses need to comply with these laws and regulations. This disclosure applies to all companies, such as those with an obligation to comply with laws and regulations.

[0037]

[0038] The Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) are U.S. organizations. In this disclosure, U.S. laws and regulations are used as examples. Many other countries also have similar organizations performing similar tasks. Therefore, many other countries also have similar laws and regulations. This disclosure is also applicable in those countries and helps companies comply with their respective laws and regulations. Aspects of this disclosure can also be used by companies, individuals, or organizations that do not need to comply with laws or regulations.

[0038]

[0039] Often, it can be difficult to determine whether one or more individuals or groups have engaged in illegal activities. Under the U.S. Bank Secrecy Act, when a company submits a Suspicious Activity Report (SAR) to FinCEN, the company has no obligation to prove that the reported instance is an illegal act. In fact, the “safe harbor” rule encourages companies to report more suspicious activities without fear of being blamed for misreporting legitimate activities as illicit. Under this “safe harbor” rule, a person (or organization) cannot sue an entity on the grounds that the entity submitted a Suspicious Activity Report (SAR) to FinCEN regarding that person (or organization). SARs are used by the government to gather information, and companies are required only to provide information and opinions in the SAR. Government agencies conduct their own investigations to determine whether the activities reported in the SAR are actually illegal.

[0039]

[0040] Generally, the decision-making process regarding whether to report suspicious activities other than fraud is different from the decision-making process regarding whether to report fraud cases. In the case of fraud cases, entities such as companies or consumers may lose money. Therefore, fraud is easier to detect compared to other crimes. Thus, it is easier to decide whether to report a fraud case. Preventing fraud is also easier compared to preventing other crimes. For example, when a computer system detects a high risk of fraud related to a transaction, the computer system can block the transaction and have an investigator examine the transaction to determine whether it is actually a fraud case.

[0040]

[0041] In one aspect of the present disclosure, for fraud detection, a computer system calculates a risk score related to a transaction based on different factors related to the transaction. These factors may include the past activities of the account, the deviation from the expected activities, the location, time, amount, frequency, and nature of the transaction, the relationships between multiple accounts, the type, nature, and structure of the account holder, etc.

[0041]

[0042] In one aspect of the present disclosure, for fraud detection, a computer system blocks a transaction if the fraud risk score of the transaction exceeds a threshold. The threshold is predefined based on the company's policy.

[0042]

[0043] In one aspect of the present disclosure, for fraud detection, a computer system creates a case based on a detected transaction with a high fraud risk. The case and related information are presented to an investigator for further investigation.

[0043]

[0044] Compared with fraud, there may be no clear evidence for suspicious activities. For example, a certain customer may frequently deposit a large amount of cash. There is a possibility that this customer is involved in money laundering by selling illegal goods and receiving cash as payment. It is also possible that this customer sells homemade products at a farmers' market and only accepts cash as payment. In many cases, due diligence is required to determine whether there are suspicious points.

[0044]

[0045] A customer sells homemade products at a farmers' market, but there is also a possibility that the customer sells illegal goods at other locations. Unless the bank is informed that the customer is selling illegal goods, there is no evidence for the bank to prove that the customer is selling illegal goods. If the customer is actually selling illegal goods and the bank does not report such suspicious activities to FinCEN, and the government arrests the customer for selling illegal goods, the bank may be severely punished later for not reporting the case to FinCEN.

[0045]

[0046] On the other hand, if the bank reports all cases with even a slight possibility of suspicion, the bank may unnecessarily draw the attention of government agencies. Government agencies may spend months in the bank to investigate the bank's business, which may have a serious impact on the bank's business.

[0046]

[0047] The decision to report an incident can be a subjective judgment by those considering the incident. In addition, the decision-making process can be highly subjective. Furthermore, a company cannot block a transaction simply because it appears to be a suspicious money laundering activity. Consumers can sue a company that blocks their transaction when the company cannot clearly prove that money laundering has occurred. In fact, many government agencies often advise companies that have reported suspicious activities such as money laundering or terrorist financing to do nothing to prevent the suspects from being warned and fleeing, and to process the suspicious transactions as normal transactions. This approach gives government agencies more time and opportunity to identify all relevant offenders.

[0047]

[0048] Under the US Bank Secrecy Act, a company that files a SAR is obliged to keep the SAR confidential, and suspects (e.g., persons involved in this case) must not know anything about the SAR, including its existence. The SAR can only be reviewed by authorized government agencies.

[0048]

[0049] As described above, since the handling of suspicious activity cases is very different from the handling of fraud cases, many traditional approaches and concepts applicable to fraud detection and prevention are no longer useful for detecting and managing suspicious activities such as money laundering, terrorist financing, elder abuse, and online gambling. In one aspect of the present disclosure, a computer system records the opinions of those who have decided not to report a detected suspicious activity case. In such situations, the decision maker records the reasons justifying their decision.

[0049]

[0050] Unlike an instance of improper conduct, an instance of suspicious activity may not be apparent to those considering the instance until additional evidence becomes available. Thus, a person may initially reject a detected instance of suspicious activity but later change their mind when additional evidence becomes available. In one aspect of the present disclosure, a person considering a detected instance of suspicious activity may also need to consider all past detected instances regarding the same suspect to determine whether any new evidence, possibly combined with old evidence from any rejected instances, makes the newly detected instance more suspicious. As a result, even if an instance was previously rejected as a false detection, it may later be reconsidered.

[0050]

[0051] The conduct of this examination of instances of suspicious activity and the conduct of an examination of instances of improper conduct may differ because instances of improper conduct typically have a clear conclusion. If a customer is an improper actor, the customer's account is closed and the customer is unable to conduct future transactions / activities. If a customer is a victim of improper conduct, the detected instance of improper conduct is unrelated to the customer and the evidence will not be used against the customer in the future. Thus, an investigator of improper conduct typically focuses only on newly detected instances. In contrast, an investigator of suspicious activity may need to consider the history of detected instances and make a decision after intensive investigation and analysis. In one aspect of the present disclosure, the justification for a decision not to report a suspicious activity is stored in a database and made available for future reference.

[0051]

[0052] In another aspect of the present disclosure, the computer system also records personal information of a person who decides not to report a detected instance. The computer system may compare decisions made by multiple people not to report suspicious activities of the same suspect(s) to determine whether an investigator is trying to conceal a detected suspect or instance.

[0052]

[0053] In the case of large enterprises, thousands of suspicious activities can be detected every month. To determine whether the enterprise needs to file a SAR for these cases, the task of examining the detected cases can be assigned to a group of multiple people. In one aspect of the present disclosure, a computer system automatically assigns the detected cases to different people based on the policies set by the enterprise. The computer system can monitor and record the status of each detected case. If the examination of a case is delayed by a particular person, the computer system warns the enterprise of such a delay.

[0053]

[0054] In yet another aspect of the present disclosure, the computer system monitors the workload of each person examining the detected cases. If the number of cases examined by a person is abnormally high compared to other people who also examined the cases detected during the same period, this person himself or herself may be suspected or regarded as a problem.

[0054]

[0055] On the other hand, if the number of cases examined by a person is low compared to other people who also examined the cases during the same period, this person may also be suspected or regarded as a problem. In either of the above two situations, the enterprise manager may wish to investigate the situation and draw his or her own conclusions and solutions.

[0055]

[0056] Generally, since suspicious activities can occur in many different types of activities, different detection functions are used to detect suspicious activities. Since the detection of suspicious activities is not clear, some of the detected cases may turn out not to be truly suspicious as a result of the investigation. In such a situation, such detected cases are rejected as false detections or false positives. False detections or false positives are generally regarded as the conclusion of the investigation of the case, but do not justify the reason why the case was rejected.

[0056]

[0057] For example, when a financial institution detects a case where several customers live at the same address and deposit a large amount of cash in the financial institution, this case may be related to a drug-dealing family that deposits the proceeds obtained from selling drugs by many of its family members. However, as a result of the investigation, this case may actually be that a group of cohabiting students are depositing the tips they received from working at a restaurant. The reason to justify the decision not to report this case should be that "cohabiting students deposit the tips received from part-time work." Therefore, for a given reason, the conclusion of the detected case is a false detection or false positive.

[0057]

[0058] Generally, after considering a detected case, the case can be classified as a false detection (or false positive) by the person who considered this case. In one aspect of the present disclosure, the computer system provides information and / or statistics for the user to analyze all detected cases classified as false detections. From these false detections, the user can identify a detection function that generated a number of false detections greater than a threshold. The user can further improve the identified detection function to improve the detection of future suspicious activities.

[0058]

[0059] The USA PATRIOT Act, the Bank Secrecy Act (BSA), anti-money laundering (AML), and anti-terrorist financing (ATF) have been important compliance matters in the financial industry since 9 / 11. Many financial institutions have invested a large amount of capital in these compliance matters, but still miss genuine money laundering and terrorist financing cases.

[0059]

[0060] The main causes of these compliance problems are that many financial institutions have not even detected basic money laundering cases, and senior managers of financial institutions struggle to understand these problems. Many financial institutions use fraud detection principles to detect money laundering activities, and in some cases, they mix fraud cases and money laundering cases.

[0060]

[0061] However, in reality, money laundering is very different from fraud. Fraud detection products can easily compare the current activities of an account holder with the account holder's past activities and detect possible fraud when the current activities deviate from the expected activities derived from the past activities. For example, if a fraudster steals a credit card from a victim, the fraudster will conduct purchasing activities different from the victim's past activities. It is only a matter of time before the credit card company detects the fraud and makes the credit card unusable. If the account is new and the past records are not yet sufficient, the fraud detection product compares the current activities of the account holder with what the account holder said during the account opening process.

[0061]

[0062] Since the goal of fraud detection products is to prevent losses as soon as possible, financial institutions usually perform fraud detection or risk scoring in real time or at least once a day. In contrast, many basic money laundering activities cannot be detected by methods such as real-time risk scoring, real-time detection, daily risk scoring, and daily detection that are effective for fraud detection. In fact, as explained earlier, higher-risk customers may not be money launderers. Assuming that higher-risk customers are engaged in suspicious money laundering activities is a waste of time.

[0062]

[0063] Financial institutions typically have a Bank Secrecy Act (BSA) officer who is responsible for reporting suspicious money laundering or terrorist financing activities to FinCEN. The following example is one where the BSA officer within a financial institution wastes a significant amount of time reviewing the results of real-time risk scoring or daily risk scoring, yet still misses a true money laundering case. This example consists of the following facts: (a) Client A sends less than $3,000 to XYZ around the 5th of each month, (b) Client B sends less than $3,000 to XYZ around the 8th of each month, (c) Client C sends less than $3,000 to XYZ around the 12th of each month, (d) Client D sends less than $3,000 to XYZ around the 17th of each month, (e) Client E sends less than $3,000 to XYZ around the 24th of each month, (f) Client F sends less than $3,000 to XYZ around the 29th of each month, (g) A, B, C, D, E, and F are unrelated individuals, and (h) XYZ is a Los Angeles-based drug dealer with no criminal history.

[0063]

[0064] In the above example, when the BSA officer compares the current activities of the clients with their past activities to detect changes in behavior, since the clients consistently conduct similar transactions each month, the BSA officer does not detect any anomalies. Even if the bank teller asks the clients about the purpose of the funds transfer, the clients can easily lie. Since these clients conduct transactions on different days throughout the month, the BSA officer will not be able to detect any risk on any day of that month.

[0064]

[0065] Furthermore, since these clients are not related, the BSA officer will not see their combined activities. Additionally, in each transaction, only a small amount of money occurs once a month, and since the recipients of the funds live in large, commercially active U.S. cities, none of these clients are considered high-risk or suspicious based on these transactions. As a result, despite the BSA officer's diligent daily use of anti-fraud products, the anti-fraud products will miss these basic money laundering cases.

[0065]

[0066] To detect these money laundering cases, in one configuration, a computer system collects transaction data from a financial institution and performs data mining based on anti-money laundering and anti-terrorist financing scenario over all transactions of all clients for a specified period such as 30 days or more. The computer system can collect details of all fund transfer transactions from different data sources within the financial institution, such as telecommunications, ACH, card payments, mobile payments, etc. The computer system can then identify common recipients of these fund transfer transactions.

[0066]

[0067] Once a common recipient is identified, the computer system can display all transactions sent to the common recipient to the BSA officer. The BSA officer reviews the identified transactions through the computer system. The BSA officer also reviews all past cases related to the suspect of the newly detected case. If the BSA officer (e.g., the responsible officer) agrees that such transactions are suspicious activities due to the common recipient receiving too much money, the computer system assists the BSA officer in submitting a SAR to FinCEN. If the BSA officer decides not to submit a SAR, the BSA officer enters into the computer system the reasons justifying the decision not to report such detected activities.

[0067]

[0068] There are several ways to report SAR cases to FinCEN. One approach is to send the SAR report directly in electronic format to a server at FinCEN. In such a situation, the BSA officer can instruct the computer system where the suspicious activity was detected to submit the SAR report. The computer system prepares the SAR report based on the suspect and transactions identified by the BSA officer and then transmits the SAR report to a computer system at FinCEN.

[0068]

[0069] As can be understood, data mining the vast amount of transaction data of all clients of a financial institution accumulated over a long period of time requires a certain amount of time even for a very small financial institution. Since financial institutions do not directly lose money in money laundering cases, according to regulatory guidelines, the BSA officer has a maximum of 30 days' grace before submitting an SAR. This example shows that performing real-time risk scoring or daily risk scoring that actually misses true money laundering activities is a waste of time and resources.

[0069]

[0070] BSA officers often voice a common complaint that they are wasting time on false positives every day at the expense of detecting actual money laundering cases. This complaint is the result of a pervasive misunderstanding that money laundering and fraud are often committed by the same criminals and should be detected together based on changes in detected behavior. After purchasing fraud detection products, some financial institutions try to detect both money laundering cases and fraud cases together. As a result, a vast amount of time, money, and resources have been wasted. This misunderstanding can be corrected by properly understanding the sophisticated aspect of transaction risk.

[0070]

[0071] Transaction risk is defined as the risk directly related to a transaction. For example, money laundering risk and fraud risk are directly associated with a transaction. Nevertheless, these risks have very different characteristics. Customers who conduct money laundering through a financial institution attempt to use the financial institution as a means to achieve their goals. These money launderers usually act as good customers because they need the support of the financial institution to achieve their plans. Since money launderers do not care about paying additional fees or losing interest on their money, from the perspective of the financial institution, these money launderers are desirable customers. This is one of the main reasons why financial institutions need to perform data mining on all transactions to detect the underlying money laundering activities.

[0071]

[0072] In contrast, fraud risk appears in different forms. Fraud committed by customers is generally classified into two categories: (1) third-party fraud and (2) counterparty fraud. Third-party fraud is defined as fraud committed by a third party who is neither a financial institution nor a customer. For example, if a fraudster (e.g., a third party) steals a checkbook from a customer, both the financial institution (e.g., the first party) and the customer (e.g., the counterparty) can become victims. In such a situation, the transactions conducted by the third-party fraudster are independent of the customer. Therefore, it is a waste of time, money, and resources for the BSA officer to be misled by an ineffective fraud detection product and assume that the customer is laundering money just because the customer is a victim of fraud committed by a third party (e.g., when there is a change in behavior).

[0072]

[0073] Counterparty misconduct is defined as misconduct committed by a customer (e.g., the counterparty) who defrauds a financial institution (e.g., the first party). When a customer successfully defrauds a financial institution, the customer immediately disappears and does not conduct money laundering through the financial institution. The wrongdoer may launder money stolen from financial institution B using financial institution A. For financial institution B, this is a case of misconduct. For financial institution A, this is a case of money laundering. However, neither financial institution A nor financial institution B will notice that both a misconduct case and a money laundering case are occurring with the same customer. A system that attempts to detect misconduct cases daily will systematically create many false positives for money laundering and will actually miss real money laundering cases. Using such an approach increases the workload of BSA officers and exposes financial institutions to unnecessary regulatory risks.

[0073]

[0074] There are other risks in the category of third-party misconduct. For example, forged checks, credit card fraud, debit card fraud, ATM fraud, internet fraud, etc. are typical risks that fall into the category of third-party misconduct. Similarly, there are many different risks in the category of counterparty misconduct, such as check kiting, deposit fraud, loan fraud, etc. Therefore, an excellent transaction risk management system uses multiple detection algorithms that intelligently consider the unique characteristics of each type of misconduct to successfully detect fraud.

[0074]

[0075] Furthermore, as previously explained, multiple customers may engage in money laundering or terrorist financing by each conducting one small transaction on different days, and daily monitoring may miss such cases. This leads to the logical conclusion that a system using a single method to detect behavioral changes wastes resources and misses true money laundering and terrorist financing cases. In one aspect of the present disclosure, money laundering and terrorist financing activities are detected by different detection methods that perform data mining on all transactions across financial institutions accumulated over a period of time based on user-defined scenarios.

[0075]

[0076] In one aspect of the present disclosure, a computer system uses multiple detection methods for monitoring transactions and integrates the detection results into a centralized case management platform. This approach integrates and rationalizes anti-money laundering, fraud prevention, and financial crime prevention measures to improve detection while always maintaining a holistic and accurate overall picture. As a result, financial institutions can improve compliance with regulatory requirements, eliminate risks, avoid losses, improve productivity, reduce the resources used to manage transaction risks, reduce costs associated with hardware, databases, and software, reduce the IT maintenance workload, and increase overall profitability.

[0076]

[0077] In one aspect of the present disclosure, a computer system compares the transaction patterns of a customer (or group of customers) with known money laundering transaction patterns to detect suspicious money laundering activities. If there is a match, there may be a detected activity that has the potential for money laundering.

[0077]

[0078] For example, many criminals know that if more than $10,000 in cash is deposited into a bank account on the same day, the bank must file a Currency Transaction Report (CTR) with the U.S. government. To avoid filing a CTR, criminals often split a single large cash deposit into multiple smaller cash deposits, make each cash deposit on a different day, and keep each cash deposit below $10,000. This transaction pattern is called "structuring" and is a known money laundering transaction pattern, and a computer system can detect this type of transaction pattern. There are many other types of transaction patterns known as money laundering transaction patterns. A computer system can be designed to detect each of these known money laundering transaction patterns. As a result, even without a change in behavior, money laundering activities can be detected based on the transaction patterns of one or more suspects.

[0078]

[0079] In one aspect of the present disclosure, the BSA officer (or responsible person) investigates the detected case to determine whether it is a genuine money laundering case. In one aspect of the present disclosure, the BSA officer also reviews all past cases related to the suspect(s) of the currently detected case. In one aspect of the present disclosure, if the BSA officer agrees that such a transaction is suspicious activity, the computer system assists the BSA officer in filing a SAR with FinCEN. In another aspect of the present disclosure, if the BSA officer decides not to file a SAR, the BSA officer inputs into the computer system the reason justifying the decision not to report such detected activity.

[0079]

[0080] In another aspect of the present disclosure, to detect suspicious money laundering activities, groups of customers having one or more common risk factors (or characteristics) such as type of business, business model, organizational structure, scale, location, products, services, career type, position, etc. are compared together. If a customer's transaction activities (e.g., transaction patterns, transaction volume, transaction frequency, transaction trends, number of transactions, transaction amount, derivatives of transactions, etc.) differ from those of other customers, this customer may have engaged in suspicious money laundering activities. In one aspect of the present disclosure, to facilitate such comparisons, statistical values such as the mean, variance, standard deviation, etc. of the group of customers are used. Similarly, if a customer behaves differently from other customers having the same set of risk factors (or characteristics), this customer may have engaged in suspicious money laundering activities. As a result, even if there is no change in behavior in any account, suspicious money laundering activities can be detected.

[0080]

[0081] Sometimes, it may not be easy to compare groups of customers together. For example, an MSB with 100 branches will likely have much more cash activity than another MSB with only 2 branches. In one aspect of the present disclosure, to achieve a more effective comparison, it is useful to compare some derivatives (e.g., ratios of some numerical values) instead of the original raw data. For example, the ratio can be "the total amount of cash withdrawn from the bank divided by the total number of checks deposited in the bank". In this example, the number of checks deposited can be used to measure the scale of the check cashing business of the MSB. Thus, the ratio of "the total amount of cash withdrawn divided by the total number of checks deposited" basically scales the check cashing business of the 100 - branch MSB and the 2 - branch MSB to approximately the same level based on the check cashing activity, enabling them to be compared on a more equitable basis.

[0081]

[0082] To achieve a better comparison, many other derivatives can be used. Generally, derivatives for a more effective comparison can include "the first variable of interest divided by a second variable that measures the size of the enterprise (or business)". For example, "the total amount of ACH outgoing transactions divided by the total number of deposited checks", "the total wire outgoing transactional amount divided by the total number of deposited checks", "the total number of issued prepaid cards divided by the total number of deposited checks", "the total amount of ACH outgoing transactions divided by the total number of branches", "the total wire outgoing transactional amount divided by the total number of branches", "the total number of issued prepaid cards divided by the total number of branches", "the total amount of ACH outgoing transactions divided by the total number of issued prepaid cards", "the total wire outgoing transactional amount divided by the total number of issued prepaid cards", etc. are just some examples of the possible derivatives that can be used. In one aspect of the present disclosure, in addition to the above ratios, other forms of mathematical transformation create derivatives.

[0082]

[0083] In one aspect of the present disclosure, a computer system compares the derivative of a particular customer with the derivatives of a group of customers (e.g., the same type of business or occupation) that have one or more common risk factors (or characteristics) with the particular customer. If the derivative of the particular customer significantly deviates from the derivatives of the customer group, the particular customer may have engaged in suspicious money laundering activities. In one aspect of the present disclosure, statistical analyses such as the mean, variance, standard deviation, etc. of the customer group facilitate such comparisons.

[0083]

[0084] In one aspect of the present disclosure, a computer system uses many different risk factors to determine the money laundering risk of each customer of a financial institution. For example, these risk factors include the customer's industry, business type, geographical area, country where the customer resides, nature of the customer's business, product type of the business, service type of the business, business structure, customer's occupation, nationality, past records (including compliance records such as the number of currency transaction reports, the number of suspicious activity reports, matches with the OFAC list, matches with the 314(a) list, matches with the list of persons with significant public positions, special designations by the compliance program, etc.), type of transactions conducted, account balance, inflow of funds, outflow of funds, transaction patterns, number of transactions, transaction amounts, transaction volumes, transaction frequencies, derivatives of transactions, location of transactions, time of transactions, country of transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, recipient of remittance transactions, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, etc. In fact, thousands of risk factors can be considered to determine a customer's money laundering risk. For the purposes of the present disclosure, a "risk factor" is also referred to as a "representative element of a risk dimension" or simply a "risk dimension".

[0084]

[0085] According to an aspect of the present disclosure, each attribute of a customer that can affect the customer's risk is a risk factor. Additionally, each characteristic of a customer that can affect the customer's risk can be a risk factor. Further, each type of activity of a customer that can affect the customer's risk is a risk factor. Risk factors can also be affected by other risks such as a piece of information related to the customer, each type of customer transaction, and / or each customer transaction pattern. A risk value is assigned to each risk factor.

[0085]

[0086] In one configuration, each degree of the same type of risk is a risk factor and a risk score is given. For example, to measure the degree of risk associated with money laundering, the total cash transaction amount over 30 days can be used. For example, a total cash transaction amount of $0 to $5,000 over 30 days has a risk score of 10, $5,001 to $50,000 has a risk score of 50, $50,001 to $250,000 has a risk score of 100, $250,001 to $1,000,000 has a risk score of 200, $1,000,001 to $10,000,000 has a risk score of 500, and a total cash transaction amount level (or degree of total cash transaction amount) of $10,000,000 or more has a risk score of 1,000 can be defined. In this example, a person with a total cash transaction amount of $60,000 over 30 days is classified into the total amount level of "$50,001 to $250,000" and has a risk score of 100.

[0086]

[0087] "Cash transaction amount" is only used as an example. Other considerations such as the number of cash transactions, the rate of increase in cash transactions, etc. can also be used to measure the degree of risk associated with money laundering. In addition to cash, other financial transactions such as checks, telecommunications, ATMs, ACHs, virtual currencies, virtual securities, virtual instruments, credit cards, debit cards, prepaid cards, currency substitutes, transfers, etc. can also be used to measure the degree of risk associated with money laundering. A person skilled in the art can easily grasp a number of risk factors based on the above examples.

[0087]

[0088] In one aspect of the present disclosure, a risk score-based scenario is based on customer data. Each piece of information about a customer is a risk factor and a risk score is assigned. Additionally or alternatively, a risk score-based scenario is based on transaction data. Each amount level (or degree of amount) of one type of transaction is a risk factor and a risk score is assigned.

[0088]

[0089] In one aspect of the present disclosure, customer data is related to the customer's industry, business type, geographical area, country where the customer is located, nature of the customer's business, business product type, business service type, business structure, customer's occupation, customer's nationality, past records, type of transactions conducted, account balance, inflow of funds, outflow of funds, transaction patterns, number of transactions, transaction amount, quantity of transactions, transaction frequency, derivatives of transactions, location of transactions, time of transactions, country of transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, recipient of remittance transactions, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, number of suspicious activity reports (SARs) provided regarding money laundering and terrorist financing cases, category of the first financial institution, business type of the first financial institution, geographical area of the first financial institution, country where the headquarters of the first financial institution is located, nature of the business of the first financial institution, age of a person, gender of a person, income level of a person, appearance of a person, judgment regarding a person, personal status of a person, family status of a person, members of a person's family, status of members of a person's family, friends of a person, status of friends of a person, past records of a person, industry of a person, geographical area of a person, country where the person is located, occupation of a person, job type of an employee, educational background of an employee, income level of an employee, employment period in the current job, record of work evaluations, work history, period of each employment in the work history, reason for leaving each employment in the work history, age of an employee, gender of an employee, personal status of an employee, family status of an employee, members of an employee's family, status of members of an employee's family, status of friends of an employee, past records of an employee, type of work performed, number of transactions executed, amount of transactions executed, maximum transaction amount, number of transactions with a specific counterparty, amount of transactions with a specific counterparty, number of changes to important records, number of changes to important records related to a specific counterparty, geographical area of an employee's home, geographical area of an employee's office, country where the employee is located, customer due diligence results, length of account history, number of names matching a gambling organization in a transaction, or one or more of their combinations.

[0089]

[0090] In one aspect of the present disclosure, transaction data is associated with one or more of cash, checks, wire transfers, ATMs (Automated Teller Machines), ACHs (Automated Clearing Houses), virtual currencies, virtual securities, virtual certificates, credit cards, debit cards, prepaid cards, electronic funds transfers, telecommunications, currency substitutes, letters of credit, notes, securities, commercial paper, commodities, precious metals, account opening, account closing, account applications, deposits, withdrawals, cancellations, balance confirmations, inquiries, credits, debits, or combinations thereof.

[0090]

[0091] In one aspect of the present disclosure, each risk factor is assigned a risk score, and a customer is assigned a total risk score that is the sum of all the risk scores of the risk factors associated with the customer. This process of generating a total risk score for each customer may be referred to as risk scoring. This total risk score is used to determine the level of risk associated with the customer. In the present disclosure, the sum is used as an example. In fact, many different types of mathematical transformations may also be used to achieve a similar effect.

[0091]

[0092] In one aspect of the present disclosure, each risk factor is assigned a risk score, and a customer is assigned a total risk score that is a value derived from a mathematical transformation of all the risk scores of the risk factors associated with the customer.

[0092]

[0093] As previously explained, unlike the situation of illegal acts, a higher-risk client may not be a suspect of money laundering or terrorist financing. The high risk may simply be the nature of that client. For example, MSBs, pawnbrokers, car dealers, pilots, flight attendants, etc. are often classified as higher-risk customers for the purposes of anti-money laundering and counter-terrorist financing measures, but this does not mean that these customers are engaged in money laundering activities or terrorist financing.

[0093]

[0094] Nevertheless, because the customer has a high risk score, this customer can be closely monitored and different monitoring methods can be applied. Thus, in one aspect of the present disclosure, the total risk score of the customer is used to determine the monitoring method applied to monitor the customer. If the total risk score of the customer is higher, a more stringent monitoring method is applied to monitor the customer. If the total risk score of the customer is low, a more relaxed monitoring method is applied to monitor the customer.

[0094]

[0095] In other words, in one aspect of the present disclosure, the total risk score of the customer is not used to determine whether the customer is suspicious. Instead, the total risk score of the customer is used to select an algorithm or set of algorithms for monitoring the customer.

[0095]

[0096] Sometimes, customers with very high risk scores may be suspicious. Thus, in one aspect of the present disclosure, if the total risk score of the customer is higher than a predetermined value, a warning about this customer is triggered so that an investigator can investigate potential cases. The predetermined value can be set by a software module, a person designing the system, a person adjusting the system, a person using the system, or a combination thereof.

[0096]

[0097] In one aspect of the present disclosure, groups of customers having the same risk factors are compared together. For example, all customers who are flight attendants can be compared together. In one aspect of the present disclosure, if the total risk score of a particular flight attendant is much higher than a reference value derived from the total risk scores of all flight attendants, this particular flight attendant may have engaged in some suspicious money laundering activities. The reference value includes an average value, a median value, a mean value, a mode value, a weighted average, and / or other statistical values.

[0097]

[0098] Statistical approaches can also be applied to facilitate the detection of suspicious activities. For example, the mean, variance, and standard deviation can be derived from the total risk scores of all customers who are flight attendants. In one aspect of the present disclosure, if the total risk score of a particular flight attendant is more than 4 times the standard deviation higher than the mean of the total risk scores of all flight attendants, this particular flight attendant may have engaged in suspicious activities.

[0098]

[0099] The above “4 times” is just an example. The number “4” can be any number such as 3.75, 4.21, 10, etc. In one aspect of the present disclosure, if the total risk score of a particular flight attendant is more than x times the standard deviation higher than the mean of the total risk scores of all flight attendants, this particular flight attendant may have engaged in suspicious money laundering activities, where x is a number assigned by the BSA officer (or responsible person). This statistical approach is applicable whenever group comparisons are used.

[0099]

[0100] Flight attendants are just one example for illustrating this method of detecting suspicious money laundering activities within a group of entities. In reality, many other risk factors can be used for the same purpose. Since there are hundreds of thousands of risk factors, in one aspect of the present disclosure, a computer system enables a user to select any risk factor to identify all customers having the same risk factor. In one aspect of the present disclosure, if a particular customer has a total risk score that is much higher than a reference value derived from the total risk scores of other customers having the same risk factor, this particular customer may have engaged in suspicious money laundering activities. The reference value includes the mean value, median, average, mode, weighted average, and / or other statistical values.

[0100]

[0101] Instead of a single risk factor, a group of risk factors can also be used. In fact, a group of risk factors can enhance the accuracy of the detection results. For example, in addition to the risk factor of occupation (e.g., flight attendant), the country where the flight on which the flight attendant works is destined can be another useful risk factor for detecting money laundering risks. For example, a flight attendant working on a flight between New York and Chicago may have activities different from those of another flight attendant working on a flight between Miami and Mexico City. It may be more accurate to compare subgroups of flight attendants working on flights between Miami and Mexico City. In this example, two risk factors, namely occupation and the city where the flight is destined, are considered to enhance the accuracy of detection.

[0101]

[0102] In one aspect of the present disclosure, a set of risk factors is used to identify a group of entities. If a particular entity has a total risk score that is much higher than a reference value derived from the total risk scores of all entities having the same set of risk factors, this particular entity may have engaged in suspicious money laundering activities. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. To simplify the calculation, standard group statistics such as an average, a variance, and a standard deviation that can be easily calculated based on existing software development tools can be derived to facilitate such comparisons within a group of entities. As a result, even if there is no behavioral change in the account, the computer system can still detect suspicious money laundering activities based on the above approach.

[0102]

[0103] Sometimes, since some entities are very different from others, it may be useful to exclude such entities from the group comparison process. In one aspect of the present disclosure, the computer system enables a user to select some entities that are not included in the group comparison process.

[0103]

[0104] Detecting a flight attendant as having suspicious money laundering activities is just one example. Similar methods are applicable to many other different situations. For example, money service businesses (MSBs) conduct many transactions every day, and since one money laundering transaction can be hidden among many other normal transactions, it is usually very difficult for a bank or credit union to detect an MSB customer as having suspicious money laundering or terrorist financing activities.

[0104]

[0105] In one aspect of the present disclosure, additional risk factors (e.g., near the Mexican border) are used to identify a group of MSBs having this same set of risk factors (e.g., in addition to the first risk factor, i.e., the type of business). If a particular MSB has a total risk score higher than a threshold value derived from the total risk scores of all MSBs having the same set of risk factors, this particular MSB may likely have engaged in suspicious money laundering activities. The threshold value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. Similarly, standard group statistics such as an average, a variance, a standard deviation, etc. can be derived to facilitate such comparisons among a group of MSBs.

[0105]

[0106] Sometimes, it may not be easy to compare groups of MSBs because they can have different types of operations and different scales. In one aspect of the present disclosure, part-time MSBs and full-time MSBs are given two different risk factors because their nature of business can be different. In another aspect of the present disclosure, risk factors are given to each of different types of MSB products and / or services. For example, although all can be provided by the same MSB, risk factors are given to each of remittance, check cashing, currency trading, prepaid card management, etc. In one aspect of the present disclosure, a set of risk factors that precisely defines the type of product and / or service is used to identify risks.

[0106]

[0107] In one aspect of the present disclosure, some risk factors are adjusted based on the scale of the business so that group comparisons are more effective. For example, an MSB with 50 branches will necessarily have a total cash transaction amount that can be five times that of another MSB with 10 branches. Sometimes, to perform a group comparison, risk factors that are affected by the scale of the business can be adjusted to account for the scale of the business. For example, in the case of an MSB with 50 branches, the total cash transaction amount over 30 days can be divided by 50 to establish an adjusted risk factor and a risk score for group comparison. Here, the number of branches is used as an example to measure the scale of the business. Other information such as the number of customers, the number of transactions, the number of employees, and the asset size can also be used to measure the scale of the business.

[0107]

[0108] In one aspect of the present disclosure, a set of risk factors adjusted based on the scale of the business (e.g., adjusted risk factors) is used to identify a group of entities having this set of adjusted risk factors. The risk score of the adjusted risk factors is called an adjusted risk score. If a particular entity has an adjusted total risk score that is much higher than a reference value derived from the adjusted total risk scores of all entities having the same set of adjusted risk factors, this particular entity may have engaged in suspicious money laundering activities. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. Generally, in one aspect of the present disclosure, a detection algorithm that incorporates risk factors into the detection algorithm can also be modified to incorporate adjusted risk factors into the detection algorithm. A detection algorithm that incorporates a risk score into the detection algorithm can also be modified to incorporate an adjusted risk score into the detection algorithm.

[0108]

[0109] To simplify the calculations, standard group statistics such as mean, variance, and standard deviation based on the adjusted risk factors and adjusted risk scores can be derived to facilitate such comparisons among groups of entities. As a result, even if there is no behavioral change in the account, the computer system can still detect suspicious money laundering activities based on the above approach.

[0109]

[0110] MSBs may have transaction activities different from other types of businesses, so it is more effective to monitor MSBs based on their specific transaction activities. Thus, in one aspect of the present disclosure, different sets of detection algorithms can be used to monitor entities having different sets of risk factors. In one aspect of the present disclosure, a set of risk factors is used to identify a group of entities having this set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activities in this group of entities. In other words, the set of detection algorithms is selected based on the set of risk factors associated with the group of entities to monitor the group of entities.

[0110]

[0111] In another aspect of the present disclosure, a set of risk factors is adjusted based on the scale of the business and used to identify a group of entities having this set of adjusted risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activities in this group of entities. In other words, the set of detection algorithms is selected based on the set of adjusted risk factors associated with the group of entities to monitor the group of entities.

[0111]

[0112] Sometimes, it is meaningful to monitor entities with higher risks more closely than those with lower risks. Therefore, different sets of detection algorithms are used to monitor different entities with different levels of risk. In one aspect of the present disclosure, a set of detection algorithms is selected based on the total risk score of an entity to monitor the entity. In another aspect of the present disclosure, a set of detection algorithms is selected based on the adjusted total risk score of an entity to monitor the entity, where the adjusted total risk score is obtained from the risk scores of adjusted risk factors.

[0112]

[0113] In one aspect of the present disclosure, when an MSB is detected as having activities that may involve money laundering, the computer system can identify the transaction (or group of transactions) that caused the detected MSB to have a total risk score higher than a reference value derived from the total risk scores of all MSBs. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values.

[0113]

[0114] Similarly, when an MSB is detected as having activities that may involve money laundering, the computer system identifies the transaction (or group of transactions) that caused the detected MSB to have an adjusted total risk score higher than a reference value derived from the adjusted total risk scores of all MSBs. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. As a result, money laundering transactions (or groups of money laundering transactions) can be identified by this approach. This approach of identifying specific transactions (or groups of transactions) with higher risk scores (or higher adjusted risk scores) can be used not only for MSBs but also for other types of customers.

[0114]

[0115] Conventionally, a higher risk score means a higher risk. However, there is no rule that prohibits a person or a company from defining a lower risk score for a higher risk. To avoid confusion, the descriptions in this disclosure are based on the convention that a higher risk score means a higher risk. Further, the risk score can be a negative value. A negative risk score means a reduced risk based on this convention.

[0115]

[0116] As described above, the MSB is just an example. Other types of businesses, such as pawnshops, car dealers, etc., can also be monitored in a similar way. As a result, risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, and adjusted total risk scores can be used in various ways to detect suspicious money laundering activities even when there is no behavioral change in the account.

[0116]

[0117] In fact, government agencies or non-government agencies such as the OCC, FDIC, FRB, NCUA, FinCEN, SEC, FINRA, etc. can monitor financial institutions such as banks, credit unions, insurance companies, stock brokers, etc. based on an approach similar to the above-described approach for monitoring MSBs. Different risk factors, risk scores, adjusted risk factors, and adjusted risk scores can be defined for this monitoring purpose.

[0117]

[0118] In one aspect of the present disclosure, a computer system uses many different risk factors to determine whether a financial institution is in compliance with regulatory requirements regarding the submission of SARs for reporting money laundering and terrorist financing cases. For example, these risk factors may include the number of SARs provided for money laundering and terrorist financing cases, the category of the financial institution, the business type of the financial institution, the geographical area of the financial institution, the country where the head office of the financial institution is located, the nature of the business of the financial institution, the product type of the business, the service type of the business, the structure of the business, the customer profile of the financial institution, past records, the type of transactions conducted, the inflow of funds, the outflow of funds, transaction patterns, the number of transactions, the amount of transactions, the volume of transactions, the frequency of transactions, the derivatives of transactions, the location of transactions, the time of transactions, the country of transactions, the sender of remittance transactions, the location of the sender, the country of the sender, the nature of the sender, the recipient of remittance transactions, the location of the recipient, the country of the recipient, the nature of the recipient, relationships, the social status of customers, the political exposure of customers, the political exposure of the sender, the political exposure of the recipient, past transactions, etc. In fact, thousands of risk factors can be considered to determine the compliance risk of a financial institution.

[0118]

[0119] In one aspect of the present disclosure, the number of branches is used to adjust risk factors and risk scores. In another aspect of the present disclosure, the asset size is used to adjust risk factors and risk scores. Many other factors can also be used to adjust risk factors and risk scores. In this current example, the risk factor of "the number of SARs submitted" may have a negative value because the more SARs are submitted by a financial institution, the lower the likelihood that the financial institution will fail to submit SARs.

[0119]

[0120] In one aspect of the present disclosure, a set of risk factors is adjusted based on the scale of the business and is used to identify a group of banks having this adjusted set of risk factors. If a particular bank has an adjusted total risk score that is much higher than the benchmark value of the adjusted total risk scores of all banks having the same set of adjusted risk factors, this particular bank may have failed to meet its compliance obligation to detect and report suspicious money laundering and / or terrorist financing activities. The benchmark value includes an average value, a median value, a mean, a mode, a weighted average, and / or other statistical values. To simplify the calculation, standard group statistics such as an average, a variance, and a standard deviation can be derived to facilitate such comparisons among a group of entities.

[0120]

[0121] Furthermore, different detection algorithms can be used to monitor different banks having different sets of risk factors. In one aspect of the present disclosure, a set of risk factors is used to identify a group of banks having this set of risk factors, and a particular set of detection algorithms is used to detect possible oversights of compliance matters in this group of banks. Thus, in one aspect of the present disclosure, a set of detection algorithms is selected based on a set of risk factors related to a group of banks to monitor the group of banks.

[0121]

[0122] In another aspect of the present disclosure, a set of risk factors is adjusted based on the business scale and is used to identify a group of banks having this adjusted set of risk factors, and a particular set of detection algorithms is used to detect possible oversights of compliance matters in this group of banks. In other words, a set of detection algorithms is selected based on a set of adjusted risk factors related to a group of banks to monitor the group of banks.

[0122]

[0123] In the above example, a bank is used, but the same set of methods can be used to monitor credit unions, stockbrokers, insurance companies, other financial institutions, and other types of businesses. Further, the scope of monitoring is not limited to compliance with anti-money laundering and counter-terrorist financing issues. In fact, all types of problems in all types of businesses can be monitored by the methods described in this disclosure by appropriately defining risk factors, risk scores, adjusted risk factors, adjusted risk scores, and detection algorithms related to such problems.

[0123]

[0124] MSBs are also under pressure to comply with many laws and regulations. However, unlike banks or credit unions, MSBs do not actually know who their customers are. A typical MSB provides money services to consumers who walk into its office. Even if an MSB collects identification information from all of its clients, the MSB may not be able to correctly identify money laundering activities. For example, a consumer may use a Mexican passport to conduct a $7,000 remittance transaction by paying cash to an MSB in the morning and a California driver's license to conduct another $8,000 remittance transaction by paying cash to the same MSB in the afternoon. Because two forms of identification are used, this same consumer may be considered two different people. Although the law requires a currency transaction report to be filed because more than $10,000 in cash has been provided by the same consumer, the MSB may not do so. This situation is further complicated if the MSB has multiple branches, as the same consumer can walk into different branches and conduct transactions based on different forms of identification.

[0124]

[0125] In one aspect of the present disclosure, the computer system compares the names, phone numbers, addresses, dates of birth, etc. of all consumers who conducted transactions at the MSB to identify all transactions that could have been made by the same consumer. After all transactions related to the consumer are identified, the computer system can detect suspicious money laundering activities related to the consumer based on the transactions related to the consumer.

[0125]

[0126] In one aspect of the present disclosure, the BSA officer (e.g., the person tasked with the investigation) investigates the detected case to determine whether it is a genuine money laundering case. The BSA officer also reviews all past cases related to the consumer of the newly detected case. If the BSA officer agrees that the detected case is a suspicious money laundering case, the computer system assists the BSA officer in submitting a SAR to FinCEN. If the BSA officer decides not to submit a SAR, the BSA officer inputs into the computer system the reasons justifying the decision not to report the detected case.

[0126]

[0127] Sometimes, since CorresBank A and CorresBank B do not have a direct banking transaction relationship, a bank receives a wire transfer from a client of CorresBank A and then sends the wire transfer again to another client of CorresBank B. This situation occurs frequently during international wire transfers because there is a possibility that banks in two different countries do not have a direct banking transaction relationship. This type of wire transfer is often called an intermediary wire transfer.

[0127]

[0128] Banks that provide intermediated telecommunications money transfer services are exposed to very high money laundering risks because the senders and recipients of intermediated telecommunications money transfers are not customers of the bank. In addition, the bank may not know the true background of the senders and recipients of the telecommunications money transfers. The sender may be a terrorist financier and the recipient may be a terrorist. Banks handling intermediated telecommunications services may unwittingly become a means for money laundering and terrorist financing.

[0128]

[0129] In one configuration of the present disclosure, a computer system compares the names, addresses, countries, phone numbers, email addresses, etc. of all senders and recipients of intermediated telecommunications money transfers and identifies transactions associated with each sender and each recipient. In one aspect of the present disclosure, if the computer system detects an unusually large number of telecommunications money transfers from the same sender, this sender and recipient may be involved in money laundering or terrorist financing activities. If the computer system detects an unusually large total amount of telecommunications money transfers from the same sender, this sender and recipient may be involved in money laundering activities.

[0129]

[0130] Similarly, if the computer system detects an unusually large number of telecommunications money transfers to the same recipient, this sender and recipient may be involved in money laundering or terrorist financing activities. If the computer system detects an unusually large total amount of telecommunications money transfers to the same recipient, this sender and recipient may be involved in money laundering activities.

[0130]

[0131] If a computer system detects that an abnormal number of wire transfers have been sent from the same sender to the same recipient, there is a possibility that this sender and recipient may be involved in money laundering or terrorist financing activities. If a computer system detects that an abnormally large total amount of wire transfers have been sent from the same sender to the same recipient, there is a possibility that this sender and recipient may be involved in money laundering or terrorist financing activities.

[0131]

[0132] In one aspect of the present disclosure, the BSA officer investigates such detected cases to determine whether it is a genuine money laundering case. The BSA officer also examines all past cases related to the suspects of the newly detected cases. If the BSA officer agrees that there is suspicious money laundering activity, the computer system assists the BSA officer in submitting a SAR to FinCEN. If the BSA officer decides not to submit a SAR, the BSA officer inputs into the computer system the reasons justifying the decision not to report such detected activities.

[0132]

[0133] Due to the rapid aging of a large portion of the population, in some states, the Elder Abuse Reporting Act (EARA) regarding the reporting of financial abuse of the elderly has recently been enacted to protect the elderly who are unable to protect themselves. It is frequent that the elderly are deceived by criminals and give money to the criminals. Therefore, financial institutions are training front-line staff to observe and report cases that seem to have the potential for elder abuse. Since transactions can be conducted remotely and criminals can skillfully hide their activities, this human-based approach is not effective. Furthermore, human operators are prone to making mistakes and errors. Relying on human operators to detect and report cases of elder abuse is not effective.

[0133]

[0134] In many companies, customer date of birth information is stored in a database. In one aspect of the present disclosure, a computer system collects date of birth information and identifies elderly persons who are older than a predetermined age. The computer system monitors all transactions of the elderly persons and detects changes in their activities.

[0134]

[0135] For example, if an unusually large amount of funds is transferred from an elderly person's account, the financial institution may wish to investigate the purpose of the funds transfer. In one aspect of the present disclosure, if an unusually large number of counterfeit checks are deposited into an elderly person's account, the financial institution may wish to investigate whether the elderly person has been given counterfeit checks in exchange for their real money or assets. If there is an abnormal transaction pattern (e.g., abnormal frequency or amount) in an elderly person's account, the financial institution may wish to investigate the transaction(s). If the balance of an elderly person's account is rapidly decreasing, the financial institution may wish to investigate the transactions related to this account.

[0135]

[0136] In one aspect of the present disclosure, a method of selecting risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, adjusted total risk scores, statistical approaches, and the detection algorithms described above is applicable for detecting cases where elder abuse may be present. Since elder abuse is different from money laundering, different sets of risk factors and risk scores may be used to detect elder abuse. For example, these risk factors may include the age of the person, the gender of the person, the income level of the person, the appearance of the person, the judgment regarding the person, the personal status of the person, the family status of the person, the family members of the person, the status of the family members of the person, the friends of the person, the status of the friends of the person, the past record of the person, the industry of the person, the geographical area of the person, the country where the person resides, the occupation of the person, nationality, the type of transaction conducted, the account balance, the inflow of funds, the outflow of funds, the transaction pattern, the number of transactions, the amount of transactions, the volume of transactions, the frequency of transactions, the derivative of the transaction, the location of the transaction, the time of the transaction, the country of the transaction, the sender of the remittance transaction, the location of the sender, the country of the sender, the nature of the sender, the recipient of the remittance transaction, the location of the recipient, the country of the recipient, the nature of the recipient, the relationship, the social status, the political exposure, past transactions, and the like. In fact, many different risk factors may be considered to determine an individual's risk of elder abuse.

[0136]

[0137] For example, in one aspect of the present disclosure, risk factors are used to identify a group of elderly persons having the same risk factors. If a particular elderly person has a total risk score higher than a reference value derived from the total risk scores of all elderly persons having the same risk factors, this particular elderly person may be a victim of a potential elder abuse case. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. In another aspect of the present disclosure, a set of risk factors is used to identify a group of elderly persons having this set of risk factors. If a particular elderly person has a total risk score higher than a reference value derived from the total risk scores of all elderly persons having the same set of risk factors, this particular elderly person may be a victim of a potential elder abuse case. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values.

[0137]

[0138] To simplify calculations, standard group statistics such as the mean, variance, and standard deviation can be derived to facilitate such comparisons within a group of entities. As a result, even when there is no behavioral change in an account, the computer system can still detect cases that may involve elder abuse based on the above approach.

[0138]

[0139] Very often, companies will have a compliance officer who is responsible for all regulatory compliance matters. In one aspect of the present disclosure, an investigator (e.g., a compliance officer) investigates the detected case to determine whether a true case of elder abuse has occurred. The compliance officer also reviews all past cases related to the elder in the newly detected case. If the compliance officer agrees that the case is a case of potential elder abuse, the computer system assists the compliance officer in reporting the detected case. If the compliance officer decides not to report the detected case, the compliance officer inputs into the computer system the reason justifying the decision not to report the detected case.

[0139]

[0140] According to the Sarbanes - Oxley Act (SOX), certain companies (e.g., publicly traded companies) must conduct internal control monitoring to prevent fraud committed by employees. Conventionally, such internal control monitoring has been performed by human workers (e.g., auditors) who spend several months each year auditing a company's financial records. Since human workers are prone to errors and mistakes, such a human - based approach is not effective. Furthermore, since it takes a significant amount of time to audit financial records, it may be too late to prevent crime.

[0140]

[0141] In one aspect of the present disclosure, a computer system monitors general ledger accounts and detects abnormal patterns (e.g., abnormal frequency, amount, rate of increase, etc.) related to the general ledger accounts to identify suspicious internal fraud activities. For example, if the general ledger account of travel and transportation expenses suddenly increases by 500% this month compared to the history of the past 12 months, there may be a possibility that some employees are abusing their rights and generating abnormal expenses.

[0141]

[0142] In one aspect of the present disclosure, a computer system compares the current value of a general ledger account with a reference value derived from the historical values of the same general ledger account over the past x months, where the value x is predefined. If the current value is significantly greater than the reference value by a margin, there may be a possibility that some employees have committed fraud. The reference includes the average value, median value, mean, mode, weighted average, and / or other statistical values. Further investigations can be conducted to determine the reason for the deviation of the general ledger account value from its historical value.

[0142]

[0143] In another aspect of the present disclosure, a computer system compares the current activities of an employee with the past activities of the employee to detect any changes. For example, if a financing officer issues an abnormally large number of financings in one month compared to the number per month in the past, the activities of this financing officer may be suspicious. If a financing officer issues a financing with an abnormally large amount compared to the past amount, the activities of this financing officer may be suspicious. If a financing officer issues a financing with an abnormally large total amount in one month compared to the total amount per month in the past, the activities of this financing officer may be suspicious.

[0143]

[0144] In many cases, activities can be measured by a value called the activity value. For example, the activities of a financing staff member can be measured by the number of financings, the maximum financing amount, the total financing amount, the average amount per financing, the number of financings to the same customer, the number of changes to the financing record, the number of changes to the financing record with the same customer, the frequency of changes to the financing record, the frequency of changes to the financing record with the same customer, the type of financing, etc. The activities of a bank teller can be measured by the total number of transactions, the total transaction amount, the maximum transaction amount, the average amount per transaction, the transaction type, the number of customers who conduct transactions with the teller, the average number of transactions per customer, the number of transactions with the same customer, the number of changes to the customer record, the number of changes to the customer record with the same customer, the frequency of changes to the customer record, the frequency of changes to the customer record with the same customer, etc. In one aspect of the present disclosure, a computer system compares the current value of an activity with a reference value derived from the historical values of the same activity. If the current value is greater than the reference value by a significant margin, the person who performed the activity may have engaged in fraud. Further investigation can be conducted to determine whether this person actually committed fraud. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values.

[0144]

[0145] In one aspect of the present disclosure, a computer system compares an employee's activities with the activities of other employees having the same role in the company. For example, if a certain teller (or financing staff member, etc.) behaves very differently from other tellers (or financing staff members, etc.) in the same branch, this teller (or financing staff member, etc.) may have engaged in some suspicious activities.

[0145]

[0146] In one aspect of the present disclosure, a computer system compares the activity value of a specific employee with a reference value derived from all activity values for the same activity of all employees having the same responsibility as this specific employee. If the activity value of the specific employee deviates significantly from the reference value, this specific employee may have engaged in fraud. Further investigation can be conducted to determine whether this employee actually committed fraud. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values.

[0146]

[0147] When one employee is compared to a group of employees, the statistical approach used in the example of the flight attendants described above is applicable. For example, a comprehensive set of risk factors related to the employee can be identified and a risk score assigned to each risk factor. As a result, each employee has an overall risk score obtained from a mathematical transformation (e.g., sum) of all the risk scores related to the employee.

[0147]

[0148] The set of risk factors for detecting fraud related to an employee can be different from the set of risk factors for detecting other types of suspicious activities such as money laundering. For example, risk factors for detecting employee fraud can include the employee's job type, educational background, income level, length of employment in the current job, record of performance evaluations, work history, length of each employment in the work history, reason for leaving each employment in the work history, employee's age, employee's gender, employee's personal status, family status of the employee, family members of the employee, status of family members of the employee, status of the employee's friends, past record of the employee, type of work performed, number of transactions executed, amount of transactions executed, maximum transaction amount, number of transactions with a specific counterparty, amount of transactions with a specific counterparty, number of changes to important records, number of changes to important records related to a specific counterparty, geographical area of the employee's home, geographical area of the employee's office, country where the employee resides, nationality, type of transactions performed, account balance, inflow of funds, outflow of funds, transaction pattern, number of transactions, amount of transactions, volume of transactions, frequency of transactions, derivatives of transactions, location of transactions, time of transactions, country of transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, recipient of remittance transactions, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, etc. In fact, a number of risk factors can be considered to determine the risk of employee misconduct. In one aspect of the present disclosure, different sets of risk factors can be used to detect different types of suspicious activities.

[0148]

[0149] In one aspect of the present disclosure, if the total risk score of a particular employee is significantly higher by a margin than the average of the total risk scores of all employees having the same risk factors as this particular employee, this particular employee may have engaged in suspicious activities. The significant margin can be set from the perspective of the number of standard deviations or other reference values.

[0149]

[0150] To increase the accuracy of the detection results, multiple risk factors rather than just one risk factor can be used. In one aspect of the present disclosure, if the total risk score of a particular employee is significantly higher by a margin than the average of the total risk scores of all employees having the same set of risk factors as this particular employee, this particular employee may have engaged in some suspicious activities. In one example, the significant margin is set from the perspective of the number of standard deviations or other reference values.

[0150]

[0151] In fact, by identifying the risk factors associated with a group of entities and appropriately assigning risk scores to each risk factor, a statistical approach based on the total risk score of each entity to identify suspicious activities of a particular entity is applicable to many other situations in addition to money laundering, terrorist financing, and employee fraud.

[0151]

[0152] In one aspect of the present disclosure, many risk factors are associated with a group of entities. A risk score can be assigned to each of the risk factors. Each entity can be given a total risk score based on a mathematical transformation such as summation. For example, other possible mathematical transformations include, but are not limited to, multiplication, division, and subtraction, sum of squares, square of the sum, the above mixtures, and other similar ways of combining risk scores.

[0152]

[0153] In one aspect of the present disclosure, if the total risk score of a particular entity is higher by a predetermined margin than the average of the total risk scores of all entities having the same risk factors as this particular entity, then this particular entity may have engaged in some suspicious activity. The predetermined margin can be set in terms of the number of standard deviations or other reference values.

[0153]

[0154] In another aspect of the present disclosure, if the total risk score of a particular entity is higher by a predetermined margin than the average of the total risk scores of all entities having the same set of risk factors as this particular entity, then this particular entity may have engaged in some suspicious activity.

[0154]

[0155] In one aspect of the present disclosure, a computer system identifies one transaction (or group of transactions) that caused a particular entity to have a total risk score higher than the average of the total risk scores of all entities. Such a transaction (or group of transactions) may be a suspicious activity.

[0155]

[0156] The statistical approach described above is just one way to manage risk. Many other group comparison methods may also be used. Furthermore, suspicious activities may not be limited to illegal or prohibited activities. An activity may be suspicious because it is different from normal activities. It may be harmless or even an activity with good intentions. Therefore, an investigation is often required to make the final decision on whether to report a detected case.

[0156]

[0157] In one aspect of the present disclosure, the responsible person investigates the newly detected case to determine whether it is illegal. The responsible person also examines all past cases related to the suspect(s) of the newly detected case. If the responsible person agrees that the detected case is illegal, the computer system assists the responsible person in reporting the detected case. If the responsible person decides not to report the detected case, the responsible person inputs into the computer system the reasons justifying the decision not to report the detected case.

[0157]

[0158] After the 9 / 11 tragedy, the US Congress passed the Unlawful Internet Gambling Enforcement Act (UIGEA) because online gambling could be a means for money laundering and terrorist financing activities. In response to this UIGEA, Regulation GG was established. According to Regulation GG, financial institutions are required to ask new customers during the account opening process whether they engage in any online gambling activities. Since the offender knows that online gambling is illegal, they will lie during the account opening process. As a result, the "question and response" approach defined in Regulation GG is only formal. However, it is specified in Regulation GG that the obligation of financial institutions to file a SAR based on the Bank Secrecy Act is not changed by Regulation GG.

[0158]

[0159] In other words, if a criminal lies during the account opening process and actually conducts an illegal online gambling business, the financial institution is obliged to report such cases to FinCEN via SAR. In one aspect of the present disclosure, the computer system compares the senders and recipients of all fund transfer transactions during a certain period. If a customer sends a large amount of money to a recipient and receives a large amount of money from the same recipient during a certain period, such transactions may be deposits of bets and payments of money earned from gambling activities between an online gambler and an online gambling organization. The computer system detects such cases as cases that may involve illegal online gambling. When a case is detected, further investigation is required.

[0159]

[0160] In one aspect of the present disclosure, since an online gambling organization usually conducts transactions with a large amount of money and a large number of clients, when the computer system detects a large number of transactions involving a large amount of money related to a customer, the computer system detects the customer as a potential online gambling organization. The computer system detects such cases as cases that may involve illegal online gambling. When a case is detected, further investigation is required.

[0160]

[0161] In one aspect of the present disclosure, the computer system compares a list of known names of online gambling organizations with the senders and recipients of fund transfer transactions related to a customer. If there is a match, the customer may be involved in online gambling activities. The computer system detects this case as a case that may involve illegal online gambling. When a case is detected, further investigation is required.

[0161]

[0162] In addition to the aforementioned transaction pattern monitoring, the group comparison method described above is also applicable for detecting activities that may be illegal online gambling. In one aspect of the present disclosure, all risk factors related to online gambling are identified. For example, these risk factors may include customer due diligence results, length of account history, customer industry, customer business type, number of names that match a gambling organization in a transaction, customer geographical area, country where the customer's headquarters is located, nature of the customer's business, business product type, business service type, business structure, customer occupation, nationality, past records, type of transactions conducted, account balance, funds inflow, funds outflow, transaction pattern, number of transactions, transaction amount, transaction volume, transaction frequency, derivatives of transactions, number of chargebacks, location of transactions, time of transactions, country of transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, recipient of remittance transactions, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, etc. In fact, many different risk factors can be considered to determine online gambling risks. As previously explained in the present disclosure, adjusted risk factors may also be used so that the adjusted risk score can be applicable based on the scale of the business.

[0162]

[0163] In one aspect of the present disclosure, risk factors are used to identify groups of customers having the same risk factors. If a particular customer has a total risk score higher than a reference value derived from the total risk scores of all customers having the same risk factors, this particular customer may be involved in illegal online gambling. In another aspect of the present disclosure, a set of risk factors is used to identify groups of customers having this set of risk factors. If a particular customer has a total risk score higher than a reference value derived from the total risk scores of all customers having the same set of risk factors, this particular customer may be involved in illegal online gambling. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. To simplify the calculation, standard group statistics such as an average, a variance, a standard deviation, etc. can be derived to facilitate such comparisons among groups of customers.

[0163]

[0164] In one aspect of the present disclosure, a responsible person (or BSA officer) investigates the detected case to determine whether it is a genuine online gambling case. The BSA officer also reviews all past cases related to the suspect of the newly detected case. If the BSA officer agrees that the detected case is a potential illegal online gambling case, the computer system assists the BSA officer in submitting a SAR to FinCEN. If the BSA officer decides not to submit a SAR, the BSA officer inputs into the computer system the reasons justifying the decision not to report the detected case.

[0164]

[0165] The United States Congress passed the Fair and Accurate Credit Transactions Act (FACT Act) to protect consumers. In particular, companies are required to identify and report cases of personal information theft. Financial institutions are also required to submit a SAR when a case of personal information theft is detected.

[0165]

[0166] In one aspect of the present disclosure, a computer system monitors consumer reports and other available information to detect fraud warnings or alerts contained in credit freeze notifications, address mismatch notifications, and / or consumer reports. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0166]

[0167] In one aspect of the present disclosure, a computer system monitors consumer reports and available information to detect consumer reports that indicate activity patterns inconsistent with the applicant's or customer's past and normal activity patterns. For example, a recent significant increase in the volume of inquiries, an abnormal number of recently established credit relationships, particularly a material change in the use of credit in recently established credit relationships, or an account that has been closed for legitimate reasons or has been identified as misusing account privileges by a financial institution or creditor may represent an abnormal pattern. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0167]

[0168] In one aspect of the present disclosure, a computer system detects whether the documents provided for identity verification appear to have been altered or forged. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0168]

[0169] In one aspect of the present disclosure, a computer system detects whether the photograph or physical characteristics on an identity document do not match the appearance of the applicant or customer presenting the identity document. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0169]

[0170] In one aspect of the present disclosure, a computer system detects whether other information on an identity certificate conflicts with information provided by the person opening a new account or presenting the identity certificate. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0170]

[0171] In one aspect of the present disclosure, a computer system detects whether other information on an identity certificate conflicts with readily available information recorded on the financial institution or creditor side, such as a signature card or a recent check. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0171]

[0172] In one aspect of the present disclosure, a computer system detects whether an application form appears to be altered or forged, or appears to be torn and reassembled. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0172]

[0173] In one aspect of the present disclosure, a computer system determines whether provided personal identification information does not match when compared against external information sources used by a financial institution or creditor. For example, when the address does not match any address in the consumer report, or when the Social Security number (SSN) has not been issued or is listed in the Social Security Administration's Death Master File. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0173]

[0174] In one aspect of the present disclosure, a computer system determines whether some of the personal identification information provided by a customer conflicts with other personal identification information provided by the customer. For example, there may be no correlation between the SSN range and the date of birth. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0174]

[0175] In one aspect of the present disclosure, a computer system determines whether the provided personal identification information is associated with known fraudulent activities indicated by internal or third - party sources used by a financial institution or creditor. For example, the address on the application may be the same as the address provided on a fraudulent application, or the phone number on the application may be the same as the number provided on a fraudulent application. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0175]

[0176] In one aspect of the present disclosure, a computer system determines whether the provided personal identification information is of a type generally associated with fraudulent activities indicated by internal or third - party sources used by a financial institution or creditor. For example, the address on the application is a fictitious one, a post office box, or a prison, or the phone number is invalid or associated with a pager or an answering service. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0176]

[0177] In one aspect of the present disclosure, a computer system determines whether the provided social security number is the same as that provided by another person or customer opening an account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0177]

[0178] In one aspect of the present disclosure, a computer system determines whether a provided address or phone number is the same as or similar to an account number or phone number submitted by an unusually large number of other people or other customers opening accounts. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0178]

[0179] In one aspect of the present disclosure, a computer system determines whether a person opening an account is unable to provide all the personal identification information required at the time of application or in response to a notice that the application is incomplete. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0179]

[0180] In one aspect of the present disclosure, a computer system determines whether the provided personal identification information is inconsistent with the personal identification information recorded by a financial institution or creditor. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0180]

[0181] In one aspect of the present disclosure, a computer system determines whether a person opening an account is unable to provide authentication information, such as answers to identity challenge questions, that exceeds what is generally available from a wallet or consumer report. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0181]

[0182] In one aspect of the present disclosure, a computer system determines whether there is unusual use of an account or suspicious activity related to the account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0182]

[0183] In one aspect of the present disclosure, a computer system determines whether, soon after notification of an address change for an account, an institution or creditor has received a request for a new, additional, or replacement card or mobile phone, or a request to add an authorized user to the account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0183]

[0184] In one aspect of the present disclosure, a computer system determines whether a new revolving credit account is being used in a manner commonly associated with known fraud patterns. For example, when a large portion of the available credit is used for cashing services or items easily convertible to cash (such as electronic devices or jewelry), or when a customer fails to make an initial payment or makes an initial payment but then fails to make subsequent payments. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0184]

[0185] In one aspect of the present disclosure, a computer system determines whether an account is being used in a manner inconsistent with the established activity pattern on that account. For example, non-payment when there is no history of late or missed payments, a significant increase in the use of available credit, a significant change in purchase or consumption patterns, a significant change in the electronic funds transfer pattern associated with a deposit account, or a significant change in the phone call pattern associated with a mobile phone account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0185]

[0186] In one aspect of the present disclosure, a computer system determines whether an account that has been inactive for a fairly long period (taking into account the type of account, expected usage pattern, and other relevant factors) is being used. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0186]

[0187] In one aspect of the present disclosure, a computer system determines whether mail sent to a customer repeatedly returns as undeliverable even though transactions are continuing to be conducted in relation to the customer's account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0187]

[0188] In one aspect of the present disclosure, when a financial institution or creditor notifies that a customer has not received a paper account statement, the computer system carefully examines all transactions. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0188]

[0189] In one aspect of the present disclosure, when a financial institution or creditor is notified of an unauthorized claim or transaction related to a customer's account, the computer system carefully examines all transactions. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0189]

[0190] In one aspect of the present disclosure, when a financial institution or creditor is notified by a customer, a victim of identity theft, a law enforcement agency, or any other person that an unauthorized account has been opened on behalf of a person involved in identity theft, the computer system carefully examines all transactions. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.

[0190]

[0191] In addition to monitoring the transaction patterns as described above, the group comparison method described above is also applicable for detecting cases where there is a possibility of personal information theft. Personal information theft cases can be classified into two main categories. The first category includes cases where a perpetrator steals the victim's account, financial product, or identification document in order to conduct activities. In such a situation, as described above, the computer system can detect activities that deviate from the victim's expected activities, which can be established from the victim's past activities.

[0191]

[0192] The second category includes cases where the victim's personal information is stolen in order to open a new account and / or start some new activity. In such a situation, the victim is initially irrelevant. Since there is no true past activity of the victim, it is not possible to accurately establish the victim's expected activities for the purpose of preventing fraud. It is possible to ask the perpetrator some questions and collect answers during the account opening process with the intention of establishing the perpetrator's expected activities, but this questioning approach may not work because the perpetrator knows how to answer the questions for establishing the expected activities without triggering a warning.

[0192]

[0193] To detect identity theft when true past activities are not available, in one aspect of the present disclosure, all risk factors for a new account or a new customer are identified. For example, these risk factors include customer due diligence results, previous records of the customer with other businesses, the customer's credit report records, the customer's industry, the customer's business type, the customer's geographic area, the country where the customer's address is located, the nature of the customer's business, the business's product type, the business's service type, the business's structure, the customer's occupation, nationality, past records, the type of transactions conducted, account balance, funds inflow, funds outflow, transaction patterns, number of transactions, transaction amounts, transaction volumes, transaction frequencies, derivatives of transactions, number of chargebacks, location of transactions, time of transactions, country of transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, recipient of remittance transactions, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, and the like. In fact, a number of risk factors can be considered to determine the identity theft risk.

[0193]

[0194] In one aspect of the present disclosure, risk factors are used to identify groups of multiple people having the same risk factors. If a particular person has a total risk score that is much higher than a reference value derived from the total risk scores of all people having the same risk factors, this particular person may be involved in an identity theft case. A set of risk factors can be used to identify groups of multiple people having this set of risk factors. If a particular person has a total risk score that is higher than a reference value derived from the total risk scores of all people having the same set of risk factors, this particular person may be involved in an identity theft case. The reference value includes an average value, a median value, an average, a mode, a weighted average, and / or other statistical values. To simplify the calculation, group statistics such as an average, a variance, a standard deviation, etc. can be derived to facilitate such comparisons among groups of multiple people.

[0194]

[0195] In one aspect of the present disclosure, a responsible person (or compliance officer) investigates the detected case to determine whether it is a genuine personal information theft case. The compliance officer also reviews all past cases related to the newly detected case. If the compliance officer agrees that this case has the potential for personal information theft, the computer system assists the compliance officer in submitting a SAR to FinCEN. If the compliance officer decides not to submit a SAR, the compliance officer inputs into the computer system the reasons justifying the decision not to report the detected activity.

[0195]

[0196] The Office of Foreign Assets Control (OFAC) has a very simple rule that any commercial transaction with an entity listed on a list issued by OFAC is illegal. This list is generally referred to as the "OFAC list". This rule applies to all U.S. persons and entities, including financial institutions. For example, Walmart was fined by OFAC for violating this rule. U.S. financial institutions under the strictest regulatory supervision, of course, must strictly comply with this rule.

[0196]

[0197] Originally, this was a very simple rule. However, what this rule means has become much more complex over the past 20 years. A common problem occurs when people misspell their names (including mistyping, mispronouncing, etc.). Even if the name of an entity is misspelled, if it is on the OFAC list, the financial institution still has an obligation to identify this entity as the entity on the OFAC list (generally referred to as OFAC match).

[0197]

[0198] The most obvious question is how much deviation from the original name on the OFAC list would classify it as a "typo". OFAC and government regulators have not provided detailed guidance on answering this question. A very common exercise that examiners or auditors can perform is to use infamous names such as "Osama bin Laden" as samples to test companies. Generally, companies are supposed to identify any business transactions related to "Osama bin Laden", "Osama Laden", "Osama Laten", "Laten Osama", "Latin Obama", etc. as potential OFAC matches. Here, it is doubtful whether a financial institution would identify the single word "Obama", which is the name of a former US president, as a potential OFAC match if the scope of deviation from the OFAC name is further widened. It is easy to see that such simple OFAC rules have caused a lot of confusion in recent years.

[0198]

[0199] In one aspect of the present disclosure, an "OFAC match scale" is used to measure the degree of deviation. A value called "relative correlation" ("RC value") is generated by the OFAC match scale to measure the similarity between two names. For example, if a name has an RC value of 100%, it exactly matches the OFAC name on the OFAC list. If a name has an RC value of 97%, it may differ from the OFAC name on the OFAC list by only one or two characters. If a name has an RC value of 0%, it is completely different from all OFAC names on the OFAC list.

[0199]

[0200] In one aspect of the present disclosure, the length of the name also affects the RC value. For example, if a 25-character name differs from an OFAC name by only one character, the RC value can be 96%, but another 10-character name, although it also differs from another OFAC name by only one character, can have an RC value of 90%.

[0200]

[0201] Some long words such as "international", "international", "limited", "company", "organization", etc. are commonly used in company names, and such words also exist in the OFAC name list. As a result, these long words generate a higher RC value for companies using these long words in their names. To avoid unnecessary false positives, in one aspect of the present disclosure, commonly used long words can be replaced with short words to mitigate their impact on the RC value. For example, the word "international" can be replaced with "intl".

[0201]

[0202] In addition, some countries do not use the descriptions "first name" and "last name". As a result, when a person is asked to provide a first name and a last name, that person may use names in a different order. "Osama Laden" can become "Laden Osama". In one aspect of the present disclosure, the OFAC match scale identifies possible "off-sequence" OFAC matches.

[0202]

[0203] Furthermore, some words are generally used in a particular culture without contributing to a clear distinction. For example, in Islamic culture, "bin" means "son of" and "binti" means "daughter of". A formal name in Islamic culture has either "bin" or "binti" in the name. For example, if an Islamic father's name is "John", his daughter "Mary" has a formal name of "Mary binti John", and his son "David" has a formal name of "David bin John". In such situations, the words "bin" and "binti" commonly used in Islamic names create a "false similarity" between two Islamic names. To provide more scientifically correct results, in one aspect of the present disclosure, the OFAC match scale may exclude these types of "trivial words" before calculating the RC value. Sometimes, names may be translated into English based on sound. Therefore, in one aspect of the present disclosure, the OFAC match scale must measure sound matches to determine the RC value.

[0203]

[0204] In one aspect of the present disclosure, a financial institution determines which threshold to use when performing an OFAC check. For example, if a financial institution uses a 75% threshold, a potential OFAC match is detected when the name has an RC value of 75% or more. Since each financial institution may have a different risk exposure, it is very likely that for financial institution A, X is the best threshold, while for financial institution B, Y is the best threshold. As a general guideline, the X value or Y value is selected according to risk-based principles.

[0204]

[0205] Generally, the higher the threshold used by a financial institution, the fewer OFAC matches the financial institution is likely to detect. As a result, more false positives are avoided, saving time during the review process. However, if the threshold is too high, the financial institution may miss legitimate deviations from OFAC names, such as "Osama bin Laden". If the threshold is too low, the financial institution may incorrectly detect many of its clients as potential OFAC matches. Best practice is to find a trade-off between "too many potential OFAC matches to review" and "missing legitimate deviations from OFAC names caused by spelling mistakes".

[0205]

[0206] In one aspect of the present disclosure, a user can randomly select several OFAC names from the OFAC list and find out how the OFAC match scale responds to deviations from these selected OFAC names. Then, based on this test, the user can determine when to call it a "potential OFAC match". It is desirable to keep the test results for future auditors and reviewers to consider.

[0206]

[0207] Certain names may be very close to OFAC names. For example, American Express is a very well-known credit card company, but is often incorrectly detected as an OFAC match because of the word "express". Therefore, to avoid this type of frequent false positive, in one aspect of the present disclosure, an exemption list is generated by the user, and these well-known and reputable companies are included in the exemption list. Companies on the exemption list are classified as false positives automatically by the computer or manually by the user when detected as potential OFAC matches.

[0207]

[0208] In many cases, a company will likely have an OFAC officer who handles all OFAC-related matters. In one aspect of the present disclosure, when an OFAC officer (e.g., a responsible person) of a financial institution detects an OFAC match that may have an RC value exceeding a predetermined threshold, the OFAC officer investigates whether this is a true OFAC match. If the OFAC officer is convinced that it is a true match, the OFAC officer must handle the case in accordance with the guidelines issued by the Office of Foreign Assets Control. According to the OFAC rules, in some cases, the OFAC officer may need to block a transaction so that a person on the OFAC list does not benefit from the transaction. As a result of the investigation, if the OFAC officer determines that the OFAC match is a false positive, the OFAC officer must enter into the computer system the reasons justifying the decision not to report such an OFAC match case to the Office of Foreign Assets Control and / or not to block the transaction.

[0208]

[0209] Section 314(a) of the USA PATRIOT Act obliges financial institutions to detect matches of names on the 314(a) list regularly published by FinCEN. As described above, the computer system can handle 314(a) compliance matters using a similar approach to that for handling OFAC compliance matters.

[0209]

[0210] Sometimes, the 314(a) list also includes additional personal identification information such as a personal identification document number, date of birth, address, etc. In one aspect of the present disclosure, in addition to the above-described method for detecting a potential OFAC match, personal identification information such as a personal identification document number, address, and / or date of birth is used by the computer system to determine whether the detected 314(a) match is a true match. This approach can reduce false positives in the 314(a) match process.

[0210]

[0211] In one aspect of the present disclosure, when a compliance officer (e.g., a responsible person) of a financial institution detects a 314(a) match having an RC value that may exceed a predetermined threshold, the compliance officer investigates whether this is a true 314(a) match. In one aspect of the present disclosure, if the compliance officer is convinced that it is a true match, the compliance officer reports the 314(a) match case to FinCEN. As a result of the investigation, if the compliance officer determines that the 314(a) match is a false positive, the compliance officer inputs into the computer system the reason for justifying the reason for not reporting the 314(a) match to FinCEN.

[0211]

[0212] In one aspect of the present disclosure, the computer system receives customer information and transaction data from the core data processing system of a financial institution or other data processing systems that may be internal or external to the financial institution. The customer information may include background information.

[0212]

[0213] In one aspect of the present disclosure, the computer system receives information regarding suspicious activities observed by front-line staff. For example, the computer system may receive information input by front-line staff. The computer system may also receive information provided by other internal or external sources.

[0213]

[0214] Although "financial institution" is used as an example for ease of explanation, the present disclosure is also applicable to other types of businesses. Generally, any enterprise that needs to comply with laws and regulations may adopt the intelligent warning system described in the present disclosure.

[0214]

[0215] In one aspect of the present disclosure, the risk score of a risk factor or the degree of a risk factor may be assigned by a computer software module, a person who designs or adjusts the system, or a user who uses the system. In most cases, the absolute value of the risk score may not be important, and the relative relationship between all risk scores may be more important.

[0215]

[0216] Furthermore, the total risk score of the subject should only vary within a reasonable range. In one aspect of the present disclosure, if the total risk score of the subject suddenly increases and exceeds the threshold value, this subject may have engaged in suspicious or abnormal activities. That is, when the difference between the first total risk score and the second total risk score of the subject increases and is greater than the increase threshold, and the first total risk score is less than the second total risk score, this subject may have engaged in suspicious or abnormal activities. In another aspect of the present disclosure, if the total risk score of the subject suddenly decreases significantly, this subject may also have engaged in suspicious or abnormal activities. That is, when the difference between the second total risk score and the first total risk score of the subject decreases and is greater than the decrease threshold, and the first total risk score is greater than the second total risk score, this subject may have engaged in suspicious or abnormal activities. Therefore, a warning is sent to the investigator, BSA officer, compliance officer, or another type of responsible person who will investigate the subject when the total risk score suddenly increases or decreases significantly.

[0216]

[0217] The observed data of the subject can sometimes vary. Therefore, the intelligent warning system can allow a specific range of variation from the total risk score of the subject in order to avoid false warnings. In one aspect of the present disclosure, the intelligent warning system increases the allowable total risk score variation range of the subject when the total risk score of the subject is lower than the threshold value. In another aspect of the present disclosure, the intelligent warning system decreases the allowable total risk score variation range of the subject when the total risk score of the subject is higher than the threshold value. The allowable variation range can be determined (e.g., set) by a software module, a person designing the system, a person adjusting the system, or a person using the system.

[0217]

[0218] For example, if the total risk score of a subject is higher than the average of the total risk scores of all subjects plus a certain number of standard deviations of all risk scores, such as four standard deviations, the intelligent warning system may modify the allowable total risk score variation range of the subject to be within half of the standard deviation without triggering a warning. In another example, if the total risk score of a subject is within the range of the average of the total risk scores of all subjects plus a certain number of standard deviations, such as three standard deviations, the intelligent warning system may allow the total risk score of the subject to vary within one standard deviation without triggering a warning.

[0218]

[0219] In yet another example, if the total risk score of a subject is within the range of the average of the total risk scores of all subjects plus a certain number of standard deviations, such as two standard deviations, the intelligent warning system may allow the total risk score of the subject to vary within 1.5 standard deviations without triggering a warning. In yet another example, if the total risk score of a subject is within the range of the average of the total risk scores of all subjects plus a certain number of standard deviations, such as one standard deviation, the intelligent warning system may allow the total risk score of the subject to vary within two standard deviations without triggering a warning.

[0219]

[0220] In the field of machine learning, negative refers to a set of data that has not triggered a warning. A true negative is a set of data that has not triggered a warning and does not contain a true instance for triggering a warning. A false negative is a set of data that has not triggered a warning but contains a true instance for triggering a warning that the system has missed. As an example, in the case of false negative money laundering, if this false negative case is discovered by the US government, a fine may be imposed on the financial institution by the US government. Therefore, it is desirable to prevent false negatives in a warning system designated to prevent money laundering (for example, an anti-money laundering warning system).

[0220]

[0221] In the money laundering countermeasure warning system in U.S. financial institutions, true money laundering cases are reported to FinCEN, which is a U.S. government agency. FinCEN has a set of communication protocols. U.S. financial institutions can report cases to FinCEN by sending files from the money laundering countermeasure warning system to a computer system at FinCEN based on FinCEN's communication protocols.

[0221]

[0222] Conventionally, rule-based systems are used to detect suspicious activities, and each rule can trigger a warning. Many financial institutions have used a rule-based approach that can trigger a large number of warnings. For example, there are more than 200 countries in the world. If a financial institution uses a rule-based approach to monitor wire transfers to or from each country, the financial institution may have more than 200 branches at the country decision node of a decision tree. As another example, there are thousands of different industries. If a financial institution uses a rule-based approach to monitor wire transfers to or from each industry, the financial institution may have thousands of branches at the industry decision node of a decision tree. Country and industry are two of many risk categories with money laundering risks. Similarly, wire transfer is one of many transaction types with money laundering risks. For example, cash, checks, ACH, ATM, credit cards, debit cards, letters of credit, etc. are other possible transaction types.

[0222]

[0223] There are numerous risk factors for money laundering. There are a large number (e.g., millions) of possible combinations of branches to form a path from the root of a decision tree to a leaf node of the decision tree. In other words, a rule-based system can use millions of rules to cover the entire range of money laundering risks and detect suspicious money laundering activities. In a rule-based system with a limited number of rules, the number of false negatives (e.g., the system misses a true money laundering case) can increase, and the number of false positives (e.g., the number of impurities at the leaf node of the decision tree increases and the goal of classification cannot be achieved) can increase. Due to the number of false negatives and false positives when a rule-based approach is used, financial institutions hire investigators to consider a large number of warnings. It is difficult for financial institutions to reduce all false negatives in a rule-based system.

[0223]

[0224] In the field of machine learning, conventional systems consider 70% accuracy to be satisfactory. Training a machine learning model to have a high accuracy such as 100% is difficult if not impossible. Unfortunately, while 70% accuracy can be effective for some purposes, this 70% target cannot meet regulatory standards such as those set by the US government. As described above, financial institutions may face severe regulatory penalties if they fail to detect specific activities such as money laundering. Therefore, financial institutions will not use a warning system with 70% accuracy. Thus, conventional machine learning models are not satisfactory for an intelligent anti-money laundering warning system.

[0224]

[0225] According to aspects of the present disclosure, an intelligent money laundering countermeasure warning system uses a risk scoring approach. Each risk factor or degree of a risk factor may be similar to a branch in a rule-based system. Thus, as described in the present disclosure, a risk scoring process for generating a total risk score from many risk factors may integrate information from many rules into the total risk score. For example, if the total risk score is generated from 10,000 risk factors, the user only needs to pay attention to warnings with a total risk score exceeding a threshold without having to evaluate each of the 10,000 risk factors. When a rule-based approach is used, each risk factor may have two possible outcomes: match or mismatch. The total number of possible combinations of outcomes for 10,000 risk factors is two to the power of 10,000 (e.g., 2 10,000 ). Therefore, an evaluation based on the total risk score effectively replaces the need to evaluate each of two to the power of 10,000 (e.g., 2 10,000 ) possible outcomes. Since these 2 10,000 outcomes may potentially generate 2 10,000 different types of warnings, the intelligent money laundering countermeasure warning system can avoid at least 2 10,000 warnings. Therefore, the intelligent money laundering countermeasure warning system is an improvement over conventional rule-based systems.

[0225]

[0226] One total risk score can replace many rules, but not all rules. For example, if a person frequently deposits a certain amount of cash (e.g., $9,900) slightly below the CTR reporting threshold of $10,000, the financial institution is required to report this person to the Financial Crimes Enforcement Network (FinCEN) as a structuring case. It is difficult to accurately detect structuring cases based on the total risk score. Thus, a warning system based on risk score-based technology may include some rules in addition to risk score-based criteria.

[0226]

[0227] In one aspect of the present disclosure, an intelligent money laundering countermeasure warning system uses scenarios based on risk scores instead of rules. In one example, the intelligent money laundering countermeasure warning system may use about 20 to 30 scenarios. The scenarios may include both risk score-based scenarios and non-risk score-based scenarios.

[0227]

[0228] In addition to or instead of scenarios, other conditions may be used to generate warnings. For example, a computer system such as a machine learning network may be trained to generate a model. After training, the discriminant used by the model may be converted into an if-then conditional format to trigger a warning.

[0228]

[0229] For the purposes of the present disclosure, a scenario may be defined as a condition or set of conditions that can trigger a warning or can be used to classify a subject into a category for a particular purpose. For example, a customer with a total risk score within a certain range will likely not trigger a warning. Further, in this example, the total risk score can classify the customer into a particular risk category such as high risk, medium risk, or low risk. As another example, a customer who was previously a suspect in a Suspicious Activity Report (SAR) will likely not trigger a warning. In this example, the customer can be classified into a particular category such as a prior SAR suspect or another similar category. As another example, a customer who matches an OFAC list, a 314(a) list, a list of persons with significant public positions, and / or other lists can be classified into one or more categories.

[0229]

[0230] A scenario can be composed of rules, sets of rules, criteria, or sets of criteria, based on rules, facts, behavior patterns, risk scores, risk dimensions, total risk scores, special categories, mathematical models, and / or machine learning models. A scenario can trigger a warning by using a rule-based method, a behavior-based method, a risk-based method, a model-based method, and / or a machine learning-based method (e.g., an artificial intelligence-based method). An intelligent warning system can include one or more scenarios.

[0230]

[0231] As described above, a warning can be triggered by a scenario. In a scenario, a flag can be set when one or more conditions are met. A potential case that triggers a warning can be called a positive. A potential case can include one or more warnings. Thus, the cause of a potential case can be one or more scenarios. A potential case, or positive, can be investigated. A true positive can refer to a potential case (e.g., a positive) that is a true case. If an investigation shows that a potential case is not a true case, the potential case can be called a false positive. As a result, a false positive can be rejected, and the associated warning can be rejected as a false warning. A true positive can be reported to an authority such as FinCEN or a law enforcement agency.

[0231]

[0232] In one configuration, the posterior probability can be estimated via Bayes' principle. The product of the posterior probability and the evidence is the product of the prior probability and the class likelihood. Using as an example an application that reports suspicious money laundering activities to FinCEN, the Bayes' equation is p(S / c)p(c)=p(c / S)p(S). The evidence p(c) is the probability of the potential cases triggered by the cause c among all potential cases. The class likelihood p(S) is the probability of true positives S (e.g., true SAR cases) among all potential cases. The prior probability p(c / S) is the probability of true positives triggered by the cause c among all true positives. As a result, the posterior probability p(S / c) can be determined as follows: p(S / c)=p(c / S)p(S) / p(c). The posterior probability P(S / c) is also the conditional probability that the potential cases triggered by the cause c are true positives. That is, the conditional probability P(S / c) is derived from historical data but is the best estimate of the future probability that the potential cases triggered by the cause c will be true positives. Therefore, the posterior probability can also be called the conditional probability for the future or the future conditional probability.

[0232]

[0233] Many risk factors (e.g., thousands of risk factors) can affect the risk of money laundering. In one configuration, when a risk-score-based scenario is used as part of the scenario, the number of scenarios used by an intelligent money laundering warning system is not large. As an example, an intelligent money laundering warning system can use 30 scenarios. A potential case can be triggered by one or more of the scenarios. In this example, a vector with 30 elements can represent the possible causes of a potential case. As a result, in this example, there are 2 30 different possible combinations of causes. Each triggered scenario is identified by a flag. For example, the cause vector can be initialized to have a value of "0" for each element. When a scenario is triggered, the value of the element corresponding to this scenario can change from "0" to another value such as "1".

[0233]

[0234] For example, if a potential case is triggered by the first scenario and the third scenario, the vector x may include "1" at the first and third positions and "0" at all other positions. That is, the vector can be represented as x = (1, 0, 1, 0, 0, 0, …, 0). As another example, if a potential case is triggered by the third scenario and the fourth scenario, the third and fourth positions of the vector may include the value "1", and all other positions may include the value "0". In this example, the vector x can be represented as x = (0, 0, 1, 1, 0, 0, …, 0). In the present disclosure, a vector including scenarios (e.g., causes) for triggering a warning about a potential case may be called a cause vector.

[0234]

[0235] A scenario may include one or more conditions for classifying a subject into one or more categories, but the scenario itself will not trigger a potential case. A potential case may be triggered by multiple scenarios within a related cause vector. For example, if a scenario attempts to classify a subject into the former SAR suspect category, such a scenario will not, by itself, trigger a money laundering warning. However, if a customer is a former SAR suspect and another scenario (e.g., a transfer of more than $10 million to a high-risk country) is triggered, a potential case may be triggered. Further, the cause vector may have two scenarios, one for a money transfer transaction and another for a former SAR suspect. Including various special categories (e.g., former SAR suspects) in the cause vector is a good idea because these special categories may increase the accuracy of detecting suspicious activities.

[0235]

[0236] Potential cases with multiple triggered scenarios within the cause vector may be more likely to be true positives. For example, if a customer receives $250,000 via a wire transfer, one scenario within the cause vector may be flagged (e.g., triggered). This cause vector with one flagged scenario may be registered as a potential case, and it is not known whether this is a true money laundering case. Similarly, if a customer withdraws $250,000, another scenario within the cause vector may be flagged. Still, it is not known whether this potential case is a true money laundering case.

[0236]

[0237] However, if a customer receives $250,000 via a wire transfer and then withdraws $250,000 in cash from the account, two different scenarios within the cause vector may be flagged. A cause vector with two flagged scenarios may be registered as a potential case, and since the combined activities described by these two different scenarios match a common money laundering behavior pattern, this is likely to be a true money laundering case. Therefore, it is desirable to calculate the conditional probability of a potential case based on a cause vector with multiple flagged scenarios rather than calculating the conditional probability based on a single flagged scenario.

[0237]

[0238] If the cause vector has 30 scenarios, since each scenario has two possibilities (e.g., triggered or not triggered), the possible combinations of the 30 scenarios can be at most 2 30 to the power of 30. However, if none of the scenarios are triggered, the case is not triggered, so the total number of possible combinations to trigger a case is (2 30 to the power of 30 - 1). Each combination may have a unique conditional probability to trigger a potential case. 2 30Since [the number] is extremely large, calculating these conditional probability values can be impractical. In practice, potential cases average the scenarios triggered simultaneously by five or fewer. Thus, the actual total number of significant combinations of scenarios that can trigger potential cases is a much smaller number and can be managed via the computing device associated with the intelligent warning system. For example, if the maximum number of possible scenarios in one potential case is 5, the total number of possible potential cases that can be triggered by these 30 scenarios is C(30,1) + C(30,2) + C(30,3) + C(30,4) + C(30,5), where C(m,n) is the possible number of different choices for selecting n objects from m objects. For example, since there are 30 possible choices for selecting 1 from 30 objects, C(30,1) is 30. C(30,2) is 435. C(30,3) is 4,060. C(30,4) is 27,405. C(30,5) is 142,506. The total number of possible cause vectors is 174,436. These cause vectors and their associated conditional probability values can be managed via the computing device and the database associated with the intelligent warning system.

[0238]

[0239] An investigator may use the intelligent warning system to investigate potential cases triggered by a cause vector. The cause vector may include multiple flagged scenarios. A potential case can be a false positive or a true positive. A true positive refers to a potential case that is a true case. A false positive refers to a potential case that is not a true case. If it is a false positive, all warnings for the potential case are rejected as false warnings. If it is a true positive, the potential case becomes a true case that can be reported to an authority such as FinCEN.

[0239]

[0240] Generally, it takes time to investigate a single potential case. In the United States, it is common for large financial institutions to hire hundreds of investigators. Each investigator is tasked with investigating whether a potential case triggered by various money laundering countermeasure systems is a genuine money laundering case. If there is a genuine money laundering case, the financial institution is required by U.S. law to report the money laundering case to FinCEN within 30 days. However, as described above, whether a potential case is a genuine money laundering case is a subjective opinion of the investigator.

[0240]

[0241] Even if an investigator reports a false positive as a genuine money laundering case, the financial institution is protected by the safe harbor rule and there is no penalty. Generally, there are huge regulatory penalties for not reporting a genuine money laundering case to FinCEN. Therefore, it is desirable to report potential cases to FinCEN without rejecting them. Thus, as long as there is reasonable doubt, it is a common practice for investigators to treat potential cases as true positives. Current U.S. law does not oblige investigators to prove that a potential case is a genuine case. That is, investigators tend to report potential cases when there is a high probability that they are genuine cases. This also means that probability plays a role in this decision-making process.

[0241]

[0242] The user's decision-making can be improved based on knowledge of the conditional probability p(S / x) that a potential case becomes a true SAR case based on the cause vector x. For example, if the conditional probability is greater than a threshold value, the user may wish to report the case to FinCEN without spending time on an investigation. In one configuration, the intelligent warning system automatically reports the case to an appropriate entity (e.g., FinCEN) when the conditional probability for the case is greater than the threshold value. The threshold value can be set by a software module, a person designing or tuning the system, and / or the user of the system. Alternatively, the threshold value can be set by an intelligent warning system that learns the user's preferences by evaluating the user's past behavior. For example, if the user often submits an SAR when the conditional probability of the cause vector is greater than a value Z, the system can use the value Z as the threshold value to automatically submit an SAR for the user in the future. In one configuration, the system stores potential cases in a database to determine the conditional probability. For each potential case, the system also stores the associated cause vector. The system can also store investigation results such as whether a potential case triggered by a cause vector was accepted as a true positive by an investigator or rejected as a false positive by the investigator.

[0242]

[0243] If the user continues to use the intelligent warning system, the system accumulates historical data in a database. In one aspect of the present disclosure, over any given period, the system can determine from the database how many potential cases were triggered by the cause vector x and how many of the potential cases triggered by the cause vector x were true positives (e.g., SAR cases reported to FinCEN). The ratio of the number of true positives triggered by the cause vector to the number of potential cases triggered by the cause vector is the conditional probability p(S / x). The conditional probability can also be referred to as the posterior probability. The posterior probability indicates the probability that a future potential case triggered by the cause vector will be a true case reported to FinCEN. Generally, the conditional probability of a potential case is equivalent to the conditional probability of the cause vector that triggered the potential case.

[0243]

[0244] In one aspect of the present disclosure, the intelligent warning system calculates and displays the conditional probability of each potential case based on its cause vector. The conditional probability indicates the probability that a potential case triggered by the cause vector will be a true positive reported to FinCEN. In another aspect of the present disclosure, the intelligent warning system accepts a potential case as a true positive and reports it to FinCEN in response to the conditional probability of the cause vector being higher than a predetermined value. This predetermined value is also referred to as the true positive acceptance threshold.

[0244]

[0245] The intelligent warning system may also reject potential cases as false positives in response to the conditional probability of the cause vector being less than the false positive rejection threshold. The false positive rejection threshold and the true positive acceptance threshold may be set by a software module, a person designing or tuning the system, and / or a user of the system. Alternatively, these thresholds may be set by an intelligent warning system that learns the user's preferences by evaluating the user's past behavior. In the case of potential cases that have not been accepted as true positives or rejected as false positives, an investigator may manually consider the potential cases and determine whether each potential case is a false positive or a true positive.

[0245]

[0246] Data for determining the conditional probability may be obtained over a period of time. For example, the period may be the past 12 months, the past 3 years, or any period. In one configuration, the conditional probability is determined from a rolling period that continues to advance. For example, if the environment (e.g., corporate policies, customer demographics, products, services, etc.) changes, the old probability values may no longer be accurate after the change. Additionally, if a financial institution modifies a scenario, the old probability values may be affected. Thus, a rolling period (e.g., the past 3 years) provides the intelligent warning system with the ability to continuously self-adjust to generate the most current and accurate probability values.

[0246]

[0247] Many computer systems perform data processing on a batch-by-batch basis (e.g., one batch per month). Instead of a period, several batches may be used to define the amount of historical data used in the probability calculation. For example, if a computer system executes one batch per month, the computer system can use a rolling period of the past 36 batches instead of a rolling period of the past 3 years.

[0247]

[0248] In one configuration, the intelligent warning system intentionally leaves some potential cases for the investigator to process. The intelligent warning system can use the results of these cases to train the system, i.e., adjust the probability values to better fit the current environment. Thus, the intelligent warning system is a learning system that improves predictions when more potential cases are evaluated by human investigators.

[0248]

[0249] The intelligent warning system may generate a flag for, or display a message about, a potential case triggered by a cause vector when the cause vector did not generate a potential case during a specified period. Under such circumstances, the user may manually investigate the potential case to determine whether it is a false positive or a true positive. The results of the manual investigation can be used to calculate the conditional probability value for the cause vector. The calculated conditional probability value can be used to evaluate future potential cases. This manual investigation process has an effect equivalent to supervised training and enhances the accuracy and reliability of the intelligent warning system.

[0249]

[0250] The intelligent warning system may also display or link to past potential cases and / or true positives triggered by a cause vector. In addition, the user can view additional details (e.g., drill-down) for each case. Thus, the investigator can use the historical data as a reference when deciding whether to pursue a potential case.

[0250]

[0251] The system may also display or link to past potential cases triggered by the same suspects as the suspects in the current potential case and the decisions regarding those potential cases. The investigator can drill down to detailed background information and transaction information about the suspects. As a result, the investigator can determine whether the current potential case is a false positive or a true positive.

[0251]

[0252] In some cases, the cause for reporting the current potential case to the authorities may not be sufficient. However, when the current potential case is combined with past potential cases, the cause for reporting may become sufficient. In such a situation, the true cause for reporting the case is composed of the cause vector of the current potential case in addition to the cause vector of the past potential cases. Past potential cases may be referred to as previous potential cases. For this true cause, a composite cause vector may be used. The composite cause vector may be a combination of the cause vectors of multiple potential cases.

[0252]

[0253] As an example, the cause vector x1 of the current case may have "1" at the 1st and 5th positions of the vector and "0" at all other positions (e.g., x1=(1,0,0,0,1,0,0,···0)). In this example, the cause vector x2 of the past potential case has "1" at the 3rd and 5th positions and "0" at all other positions (e.g., x2=(0,0,1,0,1,0,0,···0)). The composite cause vector x3 (e.g., a combination of x1 and x2) has "1" at the 1st position, the 3rd position, and the 5th position and "0" at all other positions (e.g., x3=(1,0,1,0,1,0,0,···0)). In the above example, only one cause vector of one past potential case is used, but the composite cause vector may be composed of multiple cause vectors of multiple past potential cases.

[0253]

[0254] In one configuration, the investigator manually examines multiple past potential cases and the current potential case to determine whether the combined case is a false positive (e.g., should not be reported) or a true positive (e.g., should be reported). The result of the manual investigation can be used to calculate the conditional probability value p(S / cbv) (e.g., the posterior probability value) for the composite cause vector cbv. The composite cause vector cbv is a combination of the cause vector of the current potential case and one or more cause vectors of the past potential cases.

[0254]

[0255] In some cases, it is difficult for an intelligent warning system to know which past potential cases have been investigated by an investigator. Therefore, the intelligent warning system can prompt the investigator to select past potential cases that will be combined with the current cases to be reported to the authorities.

[0255]

[0256] Additionally, in some cases, it is difficult for an intelligent warning system to know which scenario of the composite cause vector or cause vector has caused the investigator to report a potential case. Therefore, the intelligent warning system can prompt the investigator to select the scenario that caused the investigator to report a potential case.

[0256]

[0257] Many reports of suspicious activities require the investigator to provide comments or a narrative of the potential case. To improve processing time, it is desirable for the intelligent warning system to automatically populate the comments or narrative of the reported case. Generally, the information for writing the comments or narrative is composed of the background information and transaction information of the suspect. Since this information is stored in a database, the intelligent warning system can learn from the user how to write the comments or narrative as described later in this disclosure.

[0257]

[0258] In one aspect of the present disclosure, the intelligent warning system prompts the investigator to select past potential cases to be combined with the current potential cases for reporting. Based on the cause vector of the selected past potential case and the cause vector of the current potential case, the intelligent warning system prepares a comment or narrative. The prepared comment or narrative is provided in the report about the combined cases.

[0258]

[0259] When the intelligent warning system fills in comments or a narrative, the intelligent warning system can also identify the composite cause vector of the reported case. Thus, the conditional probability value p(S / cbv) may be associated with the identified composite cause vector cbv based on the results of a human investigation.

[0259]

[0260] The intelligent warning system can prompt the investigator to select a scenario of the cause vector or composite cause vector that caused the potential case to be reported. Based on the selected scenario, the intelligent warning system prepares comments or a narrative for filling in the report on that case. These selected scenarios form the true cause vector of the reported case. The scenario of the true cause vector of the reported case is identified. The conditional probability value of the true cause vector can be calculated based on the results of a human investigation.

[0260]

[0261] Since each person may have their own writing style (or preference), the investigator may initially not like the comments or narrative generated by the intelligent warning system. If the investigator does not like the comments or narrative generated based on the selected scenario and there is no way to modify it, the investigator will not deliberately select a scenario to enable the intelligent warning system to generate comments or a narrative. In such a situation, the intelligent warning system cannot learn the true reason why the investigator decided to report the case to the authorities. As a result, the intelligent warning system may not be able to calculate the future conditional probability value of the true cause vector based on the results of a human investigation.

[0261]

[0262] Therefore, it is desirable for the intelligent warning system to learn and conform to the investigator's writing style (or preference). In one configuration, the intelligent warning system learns the investigator's writing style (or preference) and generates future comments or narratives based on this investigator's writing style (or preference).

[0262]

[0263] In one configuration, to learn a person's writing style (or preference), the intelligent warning system first displays a comment or narrative about the initially selected scenario based on a pre-stored default comment or narrative about the initially selected scenario. The pre-stored default comment or narrative consists of two main parts. The first main part consists of facts such as the suspect name, identification information, the suspect's background, the suspect's relationships, the location of the event, the description of the event, the date and time of the event, information related to the event, details of the transaction, etc. The second main part may include words, phrases, sentences, symbols, etc. used to link the facts to each other. These words, phrases, sentences, symbols, etc. are collectively referred to as "link words".

[0263]

[0264] Facts can be obtained from stored data or information related to the intelligent warning system. It is rare for an investigator to modify the stored facts. The investigator can modify the link words based on the investigator's writing style (or preference). Therefore, the intelligent warning system tracks the facts and link words for comments and narratives. The intelligent warning system can also track where the facts are stored in memory (e.g., a database) and the relationships between those facts.

[0264]

[0265] Generally, a person's writing style (or preference) is determined by link words and the order of presenting facts (e.g., format). Since the examiner should avoid changing facts, including the relevant facts, the writing style (or preference) will not be determined based only on the selection of facts. In some cases, when the same scenario detects two different cases, the facts may be different. Nevertheless, since the writing style (or preference) is the same for the same examiner, the order of presenting link words and facts (e.g., format) in the comments or narrative will not change.

[0265]

[0266] In one configuration, the intelligent warning system provides an editing function for the examiner to add, delete, or modify link words that link facts to each other. The intelligent warning system may provide an editing function for the examiner to add, delete, or modify facts in the narrative. The intelligent warning system may provide an editing function and a database search function for the examiner to extract additional facts from the database and insert them into the narrative.

[0266]

[0267] After the examiner revises the comments or narrative for the scenario initially selected, the examiner may store this revised comments or narrative as the next default comments or narrative. In the future, when the examiner selects the scenario initially selected again in other cases, a revised comments or narrative (e.g., the next default comments or narrative) based on a different set of facts may be displayed for the examiner to edit. After several revisions, the examiner may be satisfied with the then-current revised version and may not wish to edit again. Through this evolutionary revision process, the intelligent warning system learns from the examiner and generates comments or narratives that match the examiner's writing style (or preference).

[0267]

[0268] The intelligent warning system can process the next selected scenario based on the same approach as described above for the initially selected scenario. The intelligent warning system can process other selected scenarios in the same way. Over time, the intelligent warning system gradually learns how to write comments or narratives for each scenario based on the investigator's preferences.

[0268]

[0269] As described, based on learning, the intelligent warning system can automatically generate comments or narratives on behalf of the investigator. Based on the aspects of the present disclosure, it is no longer necessary for the investigator to write comments or narratives. The investigator can select a scenario, and in response, the intelligent warning system automatically fills in the SAR form and the comments or narrative. Then, the intelligent warning system can report the case to the appropriate authorities. Currently, investigators may spend several hours writing comments or narratives for SAR cases. The intelligent warning system can reduce the significant effort of the investigator.

[0269]

[0270] In some cases, a person's writing style can be influenced by that person's mood. For example, a person in a good mood may write a narrative in detail. As another example, a person in a bad mood may write a poor or incomplete narrative. The aspects of the present disclosure eliminate the influence of the human writer's mood on the narrative so that the narrative maintains a consistent level.

[0270]

[0271] In an exemplary situation, when the intelligent warning system detects that customer John Doe deposited $9,990 on June 1 and $9,995 on June 2 into an account at ABC Bank, a warning can be generated as follows using the default narrative: " John Doe was, June 1st to $9,990 at June 2nd on $9,995 and ABC Bank“deposited into.” In the short narrative of this example, the underlined words are facts and the remaining words are link words.

[0271]

[0272] In one example, the investigator may change the narrative as follows: “ John Doe is June 1st to $9,990 and June 2nd to $9,995 and ABC Bank deposited into. Since this is a typical cash structuring pattern, in accordance with the Bank Secrecy Act, this case is reported as suspicious activity.” In the above narrative, the underlined words are facts and the remaining words are link words. When the investigator saves the SAR form for John Doe, the Intelligent Warning System stores the revised narrative as the default narrative.

[0272]

[0273] At a later point, the Intelligent Warning System may detect customer Jack Daniel who deposits $9,999 on July 1 and $9,999 on July 2 into an account at ABC Bank. In response, the Intelligent Warning System may generate an SAR case as follows using the default narrative: “ Jack Daniel is July 1st to $9,999 and July 2nd to $9,999 and ABC Bank deposited into. Since this is a typical cash structuring pattern, in accordance with the Bank Secrecy Act, this case is reported as suspicious activity.”

[0273]

[0274] In one example, the investigator may change this narrative to the following narrative: “In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activities through Suspicious Activity Reports (SARs). Jack Daniel However, July 1st to $9,999 and July 2nd to $9,999 and ABC BankIt has been confirmed that [the money] was deposited. This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, this case is reported through a SAR as a suspicious structuring activity case.」When the investigator saves the SAR form for Jack Daniel, the Intelligent Warning System stores the revised narrative as the default narrative.

[0274]

[0275] In a subsequent period, the Intelligent Warning System detects customer Jim Beam who deposits $9,980 on August 3 and $9,985 on August 4 into an account at ABC Bank. In response, the Intelligent Warning System can generate a SAR case as follows using the default narrative: "In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activities through Suspicious Activity Reports (SARs). Jim Beam However, August 3rd to $9,980 [the money] August 4th was $9,985 deposited ABC Bank It has been confirmed that [the money] was deposited. This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, this case is reported through a SAR as a suspicious structuring activity case.」

[0275]

[0276] Looking at the above narrative, the investigator may wish to add some words as follows: "In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activities through Suspicious Activity Reports (SARs). Jim Beam However, August 3rd to $9,980 [the money] August 4th was $9,985 deposited ABC Bank It has been confirmed that [the money] was deposited. This is a typical cash structuring activity to avoid filing a Currency Transaction Report (CTR). Therefore, this case is reported through a SAR as a suspicious structuring activity case. Jim Beam is March 1st, 2019has an open bank account, and the average account balance over the past three months is $123,197 .」 In this case review process, the investigator included additional facts extracted from the Intelligent Warning System's database. These additional facts are underlined in the following text: 「 Jim Beam has an open bank account, and the average account balance over the past three months is March 1st, 2019 .」 When the investigator saves the SAR form for Jim Beam, the Intelligent Warning System stores the revised narrative as the default narrative. $123,197

[0276]

[0277] At yet another later period, the Intelligent Warning System detects customer Remy Martin who deposits $9,998 on September 5 and $9,998 on September 6 into an account at ABC Bank. In response, the Intelligent Warning System can generate a SAR case using the default narrative as follows: 「In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activities through Suspicious Activity Reports (SARs). Remy Martin has September 5th deposited $9,998 into September 6th on $9,998 and ABC Bank into Remy Martin on February 15th, 2019 . This is a typical cash structuring activity to avoid filing Currency Transaction Reports (CTRs). Therefore, this case is reported through a SAR as a suspicious structuring activity case. $83,225 .」

[0277]

[0278] Looking at the above narrative, the investigator may decide that no further changes are necessary. Until the investigator makes future changes, cases detected by the same scenario will use the following comment or narrative: 「In accordance with the Bank Secrecy Act, financial institutions are required to report cash structuring activities through Suspicious Activity Reports (SARs).​(Suspicious Person's Name) was (First Deposit Date) deposited (First Cash Transaction Amount) into (Second Deposit Date) and (Second Cash Transaction Amount) then (Bank Name) deposited (Suspicious Person's Name) It (Account Opening Date) was confirmed that an account was opened with (Average Account Balance) and the average account balance over the past three months was

[0278]

[0279] In the example above, the set of facts consists of the suspect's name, the first cash transaction amount, the first deposit date, the second cash transaction amount, the second deposit date, the bank name, the account opening date, and the average account balance. These different pieces of facts can be extracted from a storage location such as a database.

[0279]

[0280] Furthermore, John Doe, Jack Daniel, Jim Beam, and Remy Martin are the same type of facts that are subordinate to the field name "suspect's name". Each suspect's name can be defined as a corresponding fact to other suspect's names. For example, Remy Martin can be a corresponding piece of Jim Beam's fact. Similarly, a set of corresponding pieces of facts can be defined based on the following fields: the first cash transaction amount, the first deposit date, the second cash transaction amount, the second deposit date, the bank name, the account opening date, and the average account balance.

[0280]

[0281] When the intelligent warning system presents a default narrative based on a new set of facts for a new suspect, the intelligent warning system replaces each old fact of the old suspect with the new corresponding fact of the new suspect. In the above example, the old suspect name Jim Beam is replaced with the new suspect name Remy Martin, $9,980 is replaced with $9,998, August 3rd is replaced with September 5th, $9,985 is replaced with $9,998, August 4th is replaced with September 6th, ABC Bank is replaced with ABC Bank, March 1, 2019 is replaced with February 15, 2019, and $123,197 is replaced with $83,225. The link words are not changed.

[0281]

[0282] If an investigator uses the same default narrative a certain number of times without revision, this default narrative is consistent with the investigator's writing style (or preference). Under such circumstances, the intelligent warning system may skip the narrative review process or recommend to the investigator to skip it.

[0282]

[0283] In one configuration, in addition to providing one comment or narrative for each scenario, the intelligent warning system provides an introduction section for each case. Additionally or alternatively, the intelligent warning system may provide a conclusion section for each case. The introduction section is placed at the beginning of the overall narrative, and the conclusion section is placed at the end of the overall narrative. For example, if a case has three scenarios selected by an investigator, the overall comment or narrative has one introduction section, three comment or narrative sections corresponding to the three selected scenarios, and one conclusion section.

[0283]

[0284] In one application of the present disclosure, the introduction section and the conclusion section can also be modified and saved by the examiner. Similarly, the intelligent warning system will learn to construct the examiner's preferred introduction section and conclusion section. This general format, including the introduction section and the conclusion section, provides the examiner with more flexibility to write a more comprehensive and universal narrative.

[0284]

[0285] In one configuration, when a case involves multiple suspects, each suspect is detected by a set of scenarios. The overall comment or narrative about the case can include an introduction section, a relationship section that explains the relationships of these suspects, a single set of comment (or narrative) sections for each scenario, and a conclusion section.

[0285]

[0286] By updating the link words and the relative positions of the facts in the default narrative based on different sets of facts, the SAR case review and filing process can be simplified. For example, when the intelligent warning system detects a warning regarding a suspect, the intelligent warning system sends to the examiner's computer system the current matching scenario and all scenarios that match the past warnings regarding this suspect. The examiner selects the scenarios that constitute the reasons for submitting the SAR and sends the selected scenarios back to the intelligent warning system. The intelligent warning system searches the database to identify the default narrative for the selected scenarios and sends back to the examiner's computer system the default narrative based on the facts of the suspect. The examiner can review the narrative and make changes as needed.

[0286]

[0287] When the investigator saves the revised narrative, the investigator's computer system sends the revised narrative back to the intelligent warning system. The intelligent warning system stores the revised narrative and sends the SAR form with the revised narrative to the BSA officer's computer system. When the BSA officer approves the SAR form, the intelligent warning system sends the SAR form to the FinCEN computer system. If the investigator determines that no changes need to be made to the default narrative, the intelligent warning system can send the SAR with the default narrative directly to the BSA officer's computer system for approval.

[0287]

[0288] In some cases, the investigator also serves as the BSA officer, or the BSA officer allows the investigator to submit the SAR directly without the need for approval. In these cases, the investigator can accept the default narrative based on the most current facts at that time. In response, the intelligent warning system can send the SAR with the default narrative based on the current facts directly to the FinCEN computer system.

[0288]

[0289] After the investigator continuously accepts the default narrative for scenarios based on different sets of facts without any changes for a predetermined number of times, the intelligent warning system can assume that the default narrative matches the investigator's writing style (or preference) for that scenario. Therefore, when a future true positive case is detected again for the most current suspect with the same scenario, the intelligent warning system can send the SAR with the default narrative based on the most current facts of the most current suspect directly to the FinCEN computer system. This situation saves effort related to the investigator and the BSA officer.

[0289]

[0290] The above description for one selected scenario can also apply to multiple selected scenarios. For example, if an investigator continuously accepts the default narratives for all selected scenarios of detected cases based on different sets of facts over a predetermined number of times, the intelligent warning system can send an SAR with the default narratives of multiple selected scenarios based on the most current facts of the most current suspect to the FinCEN computer system.

[0290]

[0291] In addition to the SAR submission application, aspects of the present disclosure can be used by a computer system to automatically generate different types of reports based on the preferences of human writers. For example, a hospital may need to create a report for each patient. A police department may need to create a report for each incident. A school may need to create a report for each student. There are many other instances where reports need to be generated. Conventional reports are created using a vast amount of human resources. Aspects of the present disclosure can reduce the human resources used in generating reports.

[0291]

[0292] Reports can be classified into different types of reports based on different factors such as reasons, purposes, criteria, scenarios, etc. For example, in the case of a hospital, different types of reports can be used based on the reason a patient checks into the hospital. By way of example, the reason can be a heart surgery, childbirth, etc. A patient can have multiple reasons for checking into the hospital. Additionally, for each main reason, there can be multiple sub-reasons. For example, if there is a need for a heart surgery and the patient checks into the hospital, there are many reasons for that need. Since each different reason may require a different type of writing style (or preference) for generating a report, it is desirable to classify these reasons in detail. As another example, there are many different reasons, purposes, criteria, scenarios, etc. for a police department to create a report for an incident. In yet another example, there are many different reasons, purposes, criteria, scenarios, etc. for a school to generate a report for each student.

[0292]

[0293] A report can be written based on one or more facts. These facts can be stored in a database and can consist of data entered by a human, data detected by a sensor, data collected from different sources, and / or data derived from other data. Further, a human uses words, phrases, sentences, symbols, etc. to link the facts together to form a report. For ease of reference, words, phrases, sentences, symbols, etc. used to link the facts together are collectively referred to as "link words".

[0293]

[0294] In one configuration, a computer system stores facts in a database. The computer system provides an editing ability for a human writer to create a set of factors that may include reasons, purposes, criteria, scenarios, etc. The computer system may provide an editing function for a human writer to use a set of facts to create a default narrative for each factor. Additionally, the computer system provides an editing function for a human writer to write link words for the default narrative of each factor. The computer system may also store the default narrative for each factor. The default narrative includes facts and link words.

[0294]

[0295] In one configuration, the computer system stores default narratives for each factor in a database. In this configuration, the default narrative includes link words, the positions of each fact in the narrative, and the storage locations in the database for storing each fact. For example, the default narrative can be "(Object 1) caused a car accident to (Object 2)". In this example, Object 1 and Object 2 are two facts. The computer system stores the entire sentence including the link words "caused a car accident to" and the positions of Object 1 and Object 2 in this sentence in the database. In addition, the computer system stores the table names and field names of Object 1 and Object 2 respectively in the database.

[0295]

[0296] Data fields having the same definition can be stored in the same database table. For example, all patient names are stored in the same database table that contains all patient names. Thus, when two different sets of facts are used to write two narratives for two cases, the corresponding pairs of facts at the same positions within each respective narrative are in the same database table. When multiple database tables are used to generate facts, database keys for linking these multiple database tables can also be stored in the database. As a result, when a default comment or narrative based on an old set of facts is used to generate a new narrative for a new set of facts, the computer system identifies each corresponding pair of facts and replaces the old facts with the corresponding new facts.

[0296]

[0297] For example, object 1 is the "patient name field" stored in the patient table, and object 2 is the "date field" of the event table. In the above example, "Jack Daniel had a car accident on January 20, 2018." and "Jim Beams had a car accident on February 3, 2018." are based on the same narrative format but contain two different fragments of facts (e.g., patient name and event date). The link words for these two scenarios are the same, which is "had a car accident on."

[0297]

[0298] In one configuration, the computer system lists a set of factors that may include reasons, purposes, criteria, scenarios, etc. The computer system may enable a human writer to select factors for displaying a default narrative based on a new set of facts. The human writer may add, delete, or modify the link words of the narrative displayed by the computer system.

[0298]

[0299] In one configuration, the computer system provides database search and editing functions so that a human writer can add, delete, or modify facts and change the position of the facts in the narrative displayed by the computer system. The human writer can store the revised narrative as a new default narrative, which includes the facts, the position of each fragment of the facts, and the link words. The computer system stores the database table, key, and field information for obtaining each fact of the new default narrative.

[0299]

[0300] In one aspect of the present disclosure, a human writer selects factors for displaying a new default narrative based on a new set of facts and the same set of link words stored in a database. The computer system extracts each new fragment of the new facts based on where the old corresponding fragments of the old facts are stored in the database. The computer system may display each new fact between the link words in the narrative based on the position of each old corresponding fact in the narrative.

[0300]

[0301] In one configuration, the computer system provides functionality for a human writer to add, delete, or modify the link words of the new default narrative displayed by the computer system. The human writer may also add, delete, or modify facts and change the position of the facts in the new default narrative displayed by the computer system. The human writer may store the revised new default narrative as the next new default narrative again.

[0301]

[0302] The above process can be repeated to enable a human writer to continue to revise the default narrative based on a new set of facts and store the revised default narrative as the next new default narrative. As a result of this evolutionary process, future default narratives may match the preferences of the human writer.

[0302]

[0303] In one aspect of the present disclosure, if a human writer has not changed the narrative for different cases using different sets of facts over a predetermined number of instances based on the same factors selected by the human writer, this narrative is considered to be mature for the selected factors. The predetermined number may be defined by a person and / or a computer system.

[0303]

[0304] In one configuration, if a human writer has not changed the link words presented by the computer system for different cases using different sets of facts over a predetermined number of instances based on the same factors selected by the human writer, this link word is considered mature for the selected factors. The predetermined number of instances can be defined by a person and / or the computer system.

[0304]

[0305] In one configuration, if the narrative has matured for a factor selected by a human writer, the computer system automatically skips the narrative review process or recommends to the human writer to skip it, and uses the current default narrative as the standard narrative format to generate a report for the selected factor. The standard narrative format includes different facts for each report and the same set of link words that match the writing style (or preference) of the human writer.

[0305]

[0306] In one configuration, if the link word has matured for a factor selected by a human writer, the computer system automatically skips the narrative review process or recommends to the human writer to skip it, and uses the current default link word as the standard link word to generate a report for the selected factor.

[0306]

[0307] In one configuration, if a human writer selects multiple factors to write a report, the computer system uses the selected factors to generate one narrative section for each factor, and combines the multiple narrative sections together based on the multiple selected factors to generate a report.

[0307]

[0308] An introduction section can be inserted at the beginning of the report. The introduction section includes facts and / or link words. The facts and / or link words can be revised by a human writer through multiple reports so as to ultimately match the writing skills (or preferences) of the human writer based on the evolutionary process described in the present disclosure.

[0308]

[0309] A link section can be inserted in the middle of the report. The link section includes facts and / or link words, which can be revised by a human writer through multiple reports so as to ultimately match the writing skills (or preferences) of the human writer based on the evolutionary process described in the present disclosure.

[0309]

[0310] A conclusion section can be inserted at the end of the report. The conclusion section includes facts and / or link words, which can be revised by a human writer through multiple reports so as to ultimately match the writing skills (or preferences) of the human writer based on the evolutionary process described in the present disclosure.

[0310]

[0311] As a result of the present disclosure, a computer system can learn the writing style (or preference) of each human writer and automatically generate various reports for each human writer based on the writing style (or preference) of the human writer.

[0311]

[0312] One or more of the above examples are based on money laundering countermeasure applications in financial institutions. Nevertheless, the present disclosure is also applicable to many other different types of applications for different organizations and different purposes. For example, an intelligent warning system can be used by a government agency to identify employees who may steal confidential information from the government. An intelligent warning system can be used by a school to identify students who may drop out of school. An intelligent warning system can be used by a social network company to identify members who may commit illegal acts on the social network. An intelligent warning system can be used by an employer to identify employees who may quit their jobs. An intelligent warning system can be used by a marketing company to identify potential targets for business transactions. An intelligent warning system can also be a mobile application used by an individual to identify potential stocks or commodities for investment purposes. As a public health application, an intelligent warning system can be a mobile app that monitors a person's health status and sends messages when there are potential health concerns. There are countless uses for an intelligent warning system. The following procedure is an example of how to design and develop an intelligent warning system for monitoring a group of subjects for any specific goal.

[0312]

[0313] In one configuration, the intelligent warning system assigns scores to various factors. Additionally or alternatively, the intelligent warning system assigns scores to each degree of each factor. The degree of a factor is used to distinguish different levels of the factor's impact. For example, sending a telecommunications transfer is a risk factor to be considered for the purpose of anti-money laundering measures. However, the amount of the telecommunications transfer can have different impacts. For example, a telecommunications transfer amount from $0 to $10,000 may have a low level of money laundering risk, while a telecommunications transfer amount from $250,000 to $1,000,000 may have a high level of money laundering risk. The factors can be based on data related to a subject that has a positive or negative impact on the achievement of the goal. The intelligent warning system assigns scores to each factor. The intelligent warning system can identify the possible degrees of the factors within the data related to the subject that has a positive or negative impact on the achievement of the goal. The intelligent warning system assigns scores to each degree of each factor. In one configuration, the intelligent warning system generates an overall score for each subject under surveillance by summing all the scores of the factors or degrees of factors related to the subject.

[0313]

[0314] The intelligent warning system uses a set of scenarios based on different criteria. The criteria can include factors from data related to the subject, the degree of factors from data related to the subject, and / or scores derived from data related to the subject. Additionally or alternatively, the criteria can be based on rules derived from decision trees, special categories related to the subject, if-then conditional formats derived from models trained by a machine learning network, if-then conditional formats derived from behavioral patterns, if-then conditional formats derived from transaction patterns, factors established by a software module, and / or factors established by a user or designer of the system.

[0314]

[0315] Through the above method, scenarios of the intelligent warning system are established in various ways. These scenarios can trigger warnings to generate potential cases, and each potential case can have one or more scenarios within its cause vector. The intelligent warning system can list a set of potential cases triggered by one or more scenarios. An investigator can examine the potential cases to determine which cases are true positives and which are false positives. Additionally, the investigator can examine the current potential cases together with past potential cases to determine which combinations of cases are true positives or false positives.

[0315]

[0316] In one configuration, the intelligent warning system enables an investigator to examine the scenarios of potential cases to determine which combinations of scenarios generate true positives and which combinations of scenarios generate false positives. The intelligent warning system also provides the investigator with the ability to examine the scenarios of current potential cases together with the scenarios of past potential cases to determine which combinations of scenarios are true positives and which combinations of scenarios are false positives.

[0316]

[0317] The composite cause vector is obtained from a combination of a number of cause vectors, but the composite cause vector has the same form as the cause vector. By definition, the composite cause vector is the cause vector of the combined cases. Therefore, the conditional probability P(S / cbv) of the composite cause vector and the conditional probability P(S / x) of the cause vector can be calculated via similar methods.

[0317]

[0318] Furthermore, a cause vector (or composite cause vector) can trigger potential cases for investigation, but the reason for reporting a case can be based on a subset of the scenarios of the cause vector. To maintain the accuracy of the posterior probability calculation, it is desirable to identify the subset of scenarios that form the true cause vector for true positives.

[0318]

[0319] The intelligent warning system provides the investigator with the ability to examine the scenario of a potential case to identify the true cause vector if the potential case is a true positive. The investigator may examine the scenario of the combined potential cases to identify the true cause vector if the combined potential cases are true positives. The intelligent warning system may store the investigation results of each potential case and the associated cause vector (or true cause vector). As explained above, once the true cause vector is identified, a set of narratives can be generated using the set of scenarios that make up the true cause vector, and the SAR form can be automatically filled out and sent to FinCEN.

[0319]

[0320] In one configuration, the intelligent warning system stores the investigation results of the combined cases and the associated composite cause vector (or true composite cause vector) of the combined cases. Each composite cause vector (or true composite cause vector) may be composed of one or more scenarios. The results and other information may be stored in a database or other data structure.

[0320]

[0321] After the investigator uses the intelligent warning system for a period of time, the intelligent warning system accumulates a large amount of data related to the subject. The data may include past potential cases, past investigation results (e.g., true positives or false positives), and associated cause vectors (or true cause vectors). As a result, the accuracy of the system may increase as the use of the system increases. That is, the accuracy of the system may increase through data accumulation.

[0321]

[0322] For clarity, the cause vector or true cause vector is generally referred to hereinafter as the cause vector. Further, the cause vector generally includes hereinafter both the cause vector and the composite cause vector. Thus, the cause vector generally refers to the cause vector, the composite cause vector, the true cause vector, and / or the true composite cause vector.

[0322]

[0323] In one configuration, the system calculates the conditional probability for each cause vector after the amount of historical data exceeds a threshold. The threshold can be based on the number of true cases, potential cases, data size, and / or other factors. The conditional probability of a cause vector based on a given period is the number of true positives triggered by the cause vector divided by the total number of potential cases triggered by the cause vector.

[0323]

[0324] In one aspect of the present disclosure, the intelligent warning system rejects potential cases triggered by a cause vector as false positives when the conditional probability of the cause vector is lower than the false positive rejection threshold. The false positive rejection threshold can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.

[0324]

[0325] In some cases, if potential cases triggered by a cause vector always have a low conditional probability, it is possible that the scenario of the cause vector is not properly defined. In such a situation, the user adjusts these scenarios so that the scenario of the cause vector improves the probability prediction. The intelligent warning system can prompt the user to make such changes.

[0325]

[0326] The intelligent warning system can accept potential cases triggered by a cause vector as true positives in response to the conditional probability of the cause vector being higher than the true positive acceptance threshold. The true positive acceptance threshold can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.

[0326]

[0327] The vector of a plurality of elements can be converted into a combination of a plurality of vectors. For example, vector A has three elements v1, v2, and v3. In this example, vector A can be a combination of three vectors (for example, vector B having element v1, vector C having element v2, and vector D having element v3). For clarity, vector A is called the parent vector. Vector B, vector C, and vector D can be called child vectors. In the following disclosure, the cause vector is regarded as the parent vector.

[0327]

[0328] The above example assumes that the child vector has only one element. Generally, a child vector can have a plurality of elements. For example, vector A in the above example can have a child vector having elements v1 and v2. Since each element can be included in or excluded from the parent vector to form a child vector, a parent vector having N elements can have a total of 2 combinations including itself having all N elements and a null vector having no elements. N Thus, a parent vector having N elements can have 2 N - 2 possible significant child vectors. Each element of the cause vector corresponds to a scenario. If the element is 1, the corresponding scenario is included. If the element is 0, the corresponding scenario is excluded. A subset of the scenarios of the parent cause vector can form the scenarios of the child cause vector.

[0328]

[0329] Generally, as the number of scenarios of the cause vector increases, the conditional probability value of the cause vector can increase. For example, if the first cause vector has only scenario A as its vector element and the second cause vector has both scenario A and scenario B as its vector elements, the conditional probability value of the second cause vector should be the same as or higher than the conditional probability value of the first cause vector.

[0329]

[0330] Therefore, the parent cause vector has the same conditional probability value as any of its child vectors or a higher conditional probability value. That is, if a child vector has a conditional probability value greater than the true positive acceptance threshold, the conditional probability value of the parent cause vector is also greater than the true positive acceptance threshold.

[0330]

[0331] In one configuration, the intelligent warning system accepts a potential case triggered by a cause vector as a true positive when the conditional probability value of one of its child vectors is greater than or equal to a threshold. The threshold can be set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system.

[0331]

[0332] The current potential case can be combined with a group of past potential cases to form a composite cause vector. The intelligent warning system can accept the composite cause vector of the potential case as a true positive when the conditional probability value of one of the child vectors of the composite cause vector is greater than or equal to a threshold. The threshold can be set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system.

[0332]

[0333] Trying all possible combinations of past potential cases to determine whether a particular combination of the current potential case and past potential cases meets the automatic true positive acceptance criterion can be difficult for the intelligent warning system. Therefore, in one configuration, the intelligent warning system accepts a composite cause vector as a true positive when the conditional probability value of one of the child vectors of the composite cause vector is greater than or equal to a threshold. The threshold can be set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system.

[0333]

[0334] Generally, all potential cases related to one subject can be related to each other. Additionally, all potential cases related to a group of related subjects can be related to each other. For example, if five students live in the same dormitory, all potential cases related to any of these five students are related cases. The scope of the relationship for defining related potential cases can be set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system.

[0334]

[0335] When an intelligent warning system is used over a long period of time, it may not be practical or efficient to use all related potential cases. That is, the number of related potential cases may be too large, which may cause performance degradation. Therefore, it may be desirable to limit the scope of related cases within a certain period. In one configuration, a composite cause vector can be generated from a current potential case and a group of related past potential cases that occurred within a predetermined period. The intelligent warning system can accept the composite cause vector as a true positive when the conditional probability value of a child vector of the composite cause vector is greater than or equal to a threshold value. The threshold value can be set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system. The predetermined period is set by a software module, a person designing the system, a person adjusting the system, and / or a user of the system.

[0335]

[0336] The intelligent warning system provides an opportunity for an investigator to investigate cases that are neither automatically rejected as false positives nor automatically accepted as true positives. The intelligent warning system records the investigation result of each potential case and the related cause vector for the potential case. This information can be used to calculate the future conditional probability value of the cause vector.

[0336]

[0337] The intelligent warning system can adjust itself to future environmental changes because it continues to use the survey results to further adjust future conditional probability values. The more potential cases the intelligent warning system can handle without human interaction, the fewer potential cases remain for the investigator to handle.

[0337]

[0338] The intelligent warning system can exclude cases that are automatically accepted as true positives or rejected as false positives from the calculation of posterior probability values. This approach avoids problems caused by positive feedback. For example, if a potential case triggered by the cause vector x is automatically accepted as a true positive, the value of the conditional probability p(S / x) may increase if the result of this case is included in the calculation of the posterior probability value of the cause vector x. As a result, the next potential case triggered by the cause vector x may be automatically accepted as a true positive. Since the posterior probability value continues to increase, the automatic acceptance of future potential cases triggered by the cause vector x continues. In other words, if a potential case triggered by a cause vector is automatically accepted as a true positive and the accepted case is included in the calculation of the posterior probability value of the cause vector, all future potential cases triggered by the same cause vector will be automatically accepted as true positives. This is undesirable because when the future environment changes, this "no-return" process takes away the intelligent warning system's ability to readjust itself backward.

[0338]

[0339] In one configuration, the intelligent warning system does not automatically reject a potential case when the conditional probability value of the potential case is lower than the false positive rejection threshold. As a result, the investigator can finely adjust the conditional probability value through this potential case. For reference, this case is called a false positive verification case. The number, ratio, and / or frequency of the occurrence of false positive verification cases are determined by the software module, the person designing or adjusting the system, and / or the user of the system.

[0339]

[0340] Additionally, in some cases, the intelligent warning system may not automatically accept a potential case as a true positive when the conditional probability value of the potential case is higher than the true positive acceptance threshold. As a result, the investigator can fine-tune the conditional probability value through this potential case. For clarity, this case is called a true positive verification case. The number, ratio, and / or frequency of the occurrence of true positive verification cases are determined by the software module, the person designing or adjusting the system, and / or the user of the system.

[0340]

[0341] In some cases, specific subjects are treated differently for different reasons. For example, some subjects are on a "Do Not Compare List" or "White List". Potential cases related to subjects on such lists can be treated as false positives without the need for investigation. For example, it may be a politically correct decision to place politicians on the "Do Not Compare List" of an anti-money laundering system regardless of what is detected. Similarly, for other purposes, potential cases related to subjects on another list can be treated as true positives without the need for investigation.

[0341]

[0342] Since these cases are treated differently, they are considered outliers. It is desirable to exclude these outliers from the calculation of the posterior probability value. The intelligent warning system can skip potential cases associated with subjects on the "Do Not Compare List" or "White List". The skipped cases will not be used when calculating the posterior probability value of the cause vector.

[0342]

[0343] In some cases, warnings triggered by scenarios for a subject may turn out to be false alarms because the scenario is not suitable for monitoring the subject. For example, a cash-intensive business may naturally have more cash than other types of businesses, and a scenario that compares the amount of cash between this business and others may not be meaningful or appropriate. In such situations, the investigator can mark this scenario as verified for this subject. This means that the scenario has already been verified by the investigator for this subject, and no action needs to be taken if another warning is triggered by this scenario for this subject. Therefore, potential cases triggered by scenarios with a verified status are also considered outliers.

[0343]

[0344] In one configuration, the intelligent warning system skips potential cases related to a subject that have a verified status on the scenario that triggered the potential case. The intelligent warning system does not include the skipped cases in the calculation of the posterior probability values of the cause vectors.

[0344]

[0345] When the investigator rejects a potential case as a false positive, the intelligent warning system prompts the investigator to determine whether the scenario that triggered the potential case should be marked as verified. If this scenario is not marked as verified, it may trigger another false positive in the future. Therefore, it is desirable to mark this scenario as verified when it is determined that the potential case triggered by the scenario is a false positive.

[0345]

[0346] The number of potential cases used to calculate the conditional probability value can also affect the reliability of the conditional probability value. For example, if only one potential case is triggered by the cause vector x and this potential case is accepted as a true positive by the investigator, the conditional probability p(S / x) may not be reliable even if it has a value of 100%. However, if five potential cases are triggered by the cause vector x and the conditional probability p(S / x) is 100%, this conditional probability may be more reliable compared to the previous example.

[0346]

[0347] The intelligent warning system can automatically reject the potential cases triggered by the cause vector as false positives when the conditional probability of the cause vector is less than the threshold value A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than the threshold value B. Each of the threshold values A and B can be set by a software module, a person designing or adjusting the system, and / or a user of the system.

[0347]

[0348] The intelligent warning system accepts the potential cases triggered by the cause vector as true positives when the conditional probability of the cause vector is higher than the threshold value A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than the threshold value B. Each of the threshold values A and B can be set by a software module, a person designing or adjusting the system, and / or a user of the system.

[0348]

[0349] When an intelligent warning system automatically accepts potential cases as true positives or rejects potential cases as false positives based on conditional probability thresholds, it may be desirable to use different conditional probability thresholds for subjects in different categories. For example, a financial institution may file an SAR for potential cases related to a subject who was a suspect in a past SAR case, even if the conditional probability of the current potential case is lower than the true positive acceptance threshold.

[0349]

[0350] In one configuration, the intelligent warning system uses different true positive acceptance thresholds and false positive rejection thresholds for subjects in different categories. The different categories can be defined by software modules, those who design or tune the system, and / or the users of the system. In an example of a money laundering countermeasure application, these categories can include customers who were suspects in previous SARs, customers who matched the OFAC list, customers who matched the 314(a) list, customers who matched a list of persons with important public positions, customers who matched other watchlists, high-risk customers, medium-risk customers, low-risk customers, high-risk counterparties, medium-risk counterparties, low-risk counterparties, high-risk countries, medium-risk countries, low-risk countries, high-risk regions, medium-risk regions, low-risk regions, high transaction amounts, medium transaction amounts, low transaction amounts, etc.

[0350]

[0351] Since these categories can also be factors (e.g., risk factors) used for score (e.g., risk score) assignment and calculation purposes, it is desirable to use different true positive acceptance thresholds and false positive rejection thresholds for different factors. In one aspect of the present disclosure, the intelligent warning system enables the user to assign true positive acceptance thresholds and false positive rejection thresholds to each factor.

[0351]

[0352] In one configuration, the intelligent warning system accepts a potential case as a true positive if the conditional probability of the cause vector is higher than one of the true positive acceptance thresholds of the factors related to the potential case. The intelligent warning system may reject a potential case as a false positive if the conditional probability of the cause vector is lower than one of the false positive rejection thresholds of the factors related to the potential case.

[0352]

[0353] Such an approach can become complex when many factors are involved. Therefore, it is desirable to select only some of the important factors to assign different true positive acceptance thresholds and false positive rejection thresholds. In one configuration, the intelligent warning system enables the user to select a set of factors and assign a true positive acceptance threshold to each selected factor. The user may also select a set of factors and assign a false positive rejection threshold to each selected factor.

[0353]

[0354] Thus, the intelligent warning system may accept a potential case triggered by a cause vector as a true positive if the conditional probability of the cause vector is higher than one of the true positive acceptance thresholds of the selected factors related to the potential case. Additionally, the intelligent warning system may reject a potential case triggered by a cause vector as a false positive if the conditional probability of the cause vector is lower than one of the false positive rejection thresholds of the selected factors related to the potential case.

[0354]

[0355] To improve accuracy, it is desirable that the total number of potential cases is greater than a threshold when calculating the conditional probability. The threshold can be the number of cases or a period. The threshold can be arbitrarily set by the user.

[0355]

[0356] In one configuration, the intelligent warning system records potential cases, investigation results, associated cause vectors, and the date and time when the records were established. The intelligent warning system can calculate the conditional probability of cause vector x, which is the number of true positives triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.

[0356]

[0357] After calculating the conditional probability value, the intelligent warning system also records the following additional values in the database: (1) the number of true positives triggered by cause vector x up to that time, (2) the total number of potential cases triggered by cause vector x up to that time, and (3) the date and time of the calculation, which can be called the last calculation time for cause vector x. As a result of storing these additional values, the intelligent warning system does not need to repeat the same calculation to obtain the same values for cause vector x again.

[0357]

[0358] The intelligent warning system can update the conditional probability of cause vector x, which is based on the sum of the number of true positives triggered by cause vector x (before the last calculation time) and the number of true positives triggered by cause vector x (after the last calculation time), divided by the sum of the total number of potential cases triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (after the last calculation time).

[0358]

[0359] In the above calculation, the number of true positives triggered by the cause vector x (before the last calculation time), plus the number of true positives triggered by the cause vector x (after the last calculation time), is the same as the number of true positives triggered by the cause vector x at the current calculation. Similarly, the total number of potential cases triggered by the cause vector x (before the last calculation time), plus the total number of potential cases triggered by the cause vector x (after the last calculation time), is the same as the total number of potential cases triggered by the cause vector x at the current calculation. Therefore, the above calculation will reach the same conditional probability p(S / x), which is the number of true positives triggered by the cause vector x divided by the total number of potential cases triggered by the cause vector x.

[0359]

[0360] Both the number of true positives triggered by the cause vector x (before the last calculation time) and the total number of potential cases triggered by the cause vector x (before the last calculation time) can be stored in the database after the last calculation of the conditional probability. Therefore, the intelligent warning system can search the database to find these two values. Therefore, the intelligent warning system calculates two new values based on the potential cases detected after the last calculation time. This approach reduces many calculations, thus reducing the amount of data stored in memory.

[0360]

[0361] In one aspect of the present disclosure, when the calculation of the conditional probability value is completed, the intelligent warning system stores the following additional values in addition to the potential cases, investigation results, and cause vector x: (1) the number of true positives triggered by the cause vector x up to that time, (2) the total number of potential cases triggered by the cause vector x up to that time, and (3) the date and time of the calculation, which can be called the new last calculation time for the cause vector x. As a result, these values simplify the next round of calculation of the conditional probability for potential cases triggered by the cause vector x.

[0361]

[0362] The above method can be further modified during the software coding process. In one aspect of the present disclosure, the intelligent warning system holds two counters for the cause vector x, one counter for the number of true positives (NTPX), and the other counter for the number of potential cases (NPCX).

[0362]

[0363] In one aspect of the present disclosure, the intelligent warning system resets both counters NTPX and NPCX to 0 to start counting. As an example, a potential case triggered by the cause vector x can be manually examined by an investigator and determined to be a true positive. In this example, since the number of true positives manually examined triggered by the cause vector x has increased by one, the intelligent warning system adds 1 to the NTPX counter. In the current example, since the number of potential cases triggered by the cause vector x has increased by one, the system also adds 1 to the NPCX counter.

[0363]

[0364] As another example, a potential case triggered by the cause vector x is manually examined by an investigator and determined to be a false positive. In this example, since the number of true positives manually examined triggered by the cause vector x has not increased, the intelligent warning system adds 0 to the NTPX counter, and since the number of potential cases y triggered by the cause vector x has increased by one, the system adds 1 to the NPCX counter.

[0364]

[0365] In one configuration, the conditional probability p(S / x) for a new potential case triggered by the cause vector x is NTPX divided by NPCX. This method can reduce the complexity of calculating the conditional probability p(S / x) and simplify the software coding effort.

[0365]

[0366] In the example, the cause vector x is used, but the above method can be used for any cause vector. The intelligent warning system can have many pairs of counters, one pair for each cause vector. As explained above, since only a very small number of scenarios can coexist in the same cause vector to trigger potential cases, the total number of pairs is limited.

[0366]

[0367] By using the above method, the intelligent warning system can reduce the amount of time for calculation. Furthermore, the conditional probability value increases in accuracy when more potential cases are used in the calculation for deriving the conditional probability value.

[0367]

[0368] Since the intelligent warning system continues to learn from human operators, it is only a matter of time before the intelligent warning system automatically detects warnings, makes a decision to submit an SAR, fills out the SAR form, writes the narrative, and sends the SAR form to FinCEN. The intelligent warning system reduces human resources and processes SAR compliance matters in the same way as how humans handle SAR compliance matters.

[0368]

[0369] Although the detection of suspicious activities, the investigation of SAR cases, and the submission of suspicious activity reports are used as examples, the same set of methods in the present disclosure can be used to handle the detection of currency transactions, the investigation of CTR cases, and the submission of currency transaction reports (CTRs) to FinCEN.

[0369]

[0370] Similarly, to process the detection of potential OFAC matches, the investigation of potential matches, and the reporting of true matches to the Office of Foreign Assets Control (OFAC), the same set of methods as in the set of methods in this disclosure can be used. In such situations, the relative correlation (RC) value used to measure the degree of a match is equivalent to the risk score used to measure the degree of risk. Thus, instead of using a risk score-based scenario, an intelligent warning system can use an RC-based scenario.

[0370]

[0371] The OFAC list is just one example of many regulatory lists. For the detection, investigation, and reporting of matches for all types of regulatory lists, such as the 314(a) list, the list of denied persons, the list of persons with significant public positions, and any other list published by a government agency and / or non-government agency, the same set of methods as in the set of methods in this disclosure can be used. Persons familiar with regulatory compliance requirements can understand that the set of methods in this disclosure can be used to detect, investigate, and report any subject to comply with any type of regulatory reporting requirement.

[0371]

[0372] As described, this disclosure describes a set of methods that can be used by an intelligent warning system for any application and purpose. Whenever an application involves warning generation, human consideration of warnings, and human follow-up actions in response to the results of warning consideration, the intelligent warning system gradually learns from humans, makes decisions on behalf of humans, and executes follow-up actions on behalf of humans. As a result, the intelligent warning system can reduce human labor and time and can replace some or all humans in such applications.

[0372]

[0373] As contemplated in the described embodiment, one of many possible combinations is described below by way of example. Computer networks 600, such as intelligent warning system 500 and local area network, enable BSA officer 100, compliance officer 200, investigator 300, and other responsible persons 400 to comply with different types of laws and regulations and send SAR cases directly to another computer system 700 at FinCEN, as shown in FIG. 1.

[0373]

[0374] The compliance officer 200 configures and / or adjusts the parameters of the computer system 500 through the computer network 600. The computer system 500 uses an internal workflow function to send potential cases to the investigator 300 through the computer network 600. After the investigation, the investigator 300 sends the potential case and its investigation results to the computer system 500 through the computer network 600. The computer system 500 uses an internal workflow function to send the potential case and the investigation results to the BSA officer 100 through the computer network 600 for approval. After the BSA officer 100 approves the investigation results, if the potential case is a true positive, the computer system 500 receives approval from the BSA officer 100 through the computer network 600. Then, the computer system 500 sends the true positive to the computer system 700 at FinCEN.

[0374]

[0375] In some small financial institutions, the same person may have multiple positions. For example, one person can be a BSA officer, a compliance officer, and an investigator. In such a situation, the intelligent warning system uses its internal workflow function to assign different tasks to this person based on their different roles at different stages of the workflow.

[0375]

[0376] After the computer system 500 gradually learns the investigator 300's experience, the computer system 500 becomes smarter and automatically accepts potential cases as true positives when the conditional probability of the potential cases is higher than a predetermined value. Under such circumstances, the computer system 500 directly sends true positives to the computer system 700 at FinCEN without human intervention. The more the investigator 300 uses the computer system 500, the smarter the computer system 500 becomes. The computer system 500 is ultimately expected to process almost all potential cases by itself with minimal human intervention.

[0376]

[0377] As shown in the flowchart of FIG. 2 in combination with the system diagram of FIG. 1, computer system 500 is used for money laundering countermeasure applications. First (block 2001), computer system 500 receives customer background data and transaction data from a financial institution. Next (block 2002), computer system 500 assigns a risk score to each risk factor of the data. Compliance officer 200 has the option to adjust the risk score through network 600. Additionally (block 2003), computer system 500 assigns the risk score to each degree of the risk factors of the data. Similarly, compliance officer 200 also has the option to adjust the risk score through network 600 in this case. After the risk scores are assigned and adjusted, computer system 500 calculates the total risk score for each customer (block 2004). Further (block 2005), computer system 500 establishes a set of risk score-based detection scenarios. Compliance officer 200 has the option to adjust the scenarios through network 600. Further (2006), computer system 500 establishes a set of non-risk score-based detection scenarios. Similarly, compliance officer 200 also has the option to adjust the scenarios through network 600 in this case. After the scenarios are established and adjusted, computer system 500 uses the scenarios to detect potential cases (block 2007). Computer system 500 uses its workflow function to communicate with investigator 300 and BSA officer 100 through network 600 based on the following mechanisms (block 2008). Computer system 500 sends potential cases to investigator 300 through network 600. Investigator 300 investigates the potential cases and sends the investigation results to computer system 500 through network 600. Computer system 500 sends the investigation results to BSA officer 100. BSA officer 100 approves the investigation results and sends the approval to computer system 500 through network 600.After the approval of the investigation results by the BSA officer 100, the computer system 500 stores the potential cases, investigation results, and related cause vectors in a database with timestamps (block 2009). Through the network 600, the BSA officer 100 instructs the computer system 500 to report true positives to FinCEN. The computer system 500 sends the true positives to a computer system 700 at FinCEN based on the FinCEN communication protocol.

[0377]

[0378] Figure 3 illustrates a flowchart for reporting potential cases related to money laundering according to an aspect of the present disclosure. According to an aspect of the present disclosure, the computer system 500 enhances its ability to detect true positive cases after accumulating potential cases, investigation results, and cause vectors over a period of time (as described above). The computer system 500 uses a set of true positive acceptance thresholds. The compliance officer 200 approves the true positive acceptance thresholds through the network 600.

[0378]

[0379] As shown in FIG. 3, in block 3001, computer system 500 detects potential cases triggered by cause vector x. Next (block 3002), computer system 500 calculates the conditional probability p(S / x) for cause vector x. Computer system 500 compares the conditional probability value of cause vector x with a set of true positive acceptance thresholds (decision block 3003). If the conditional probability value of cause vector x exceeds any of the thresholds (YES branch 3005), computer system 500 sends the potential case as a true positive to computer system 700 at FinCEN (block 3011). If the conditional probability value does not exceed any of the thresholds (NO branch 3004), computer system 500 sends the potential case through network 600 to investigator 300 for manual investigation (block 3006). Investigator 300 sends the investigation results to computer system 500 through network 600. Computer system 500 sends the investigation results to BSA officer 100 through network 600. Computer system 500 receives approval of the investigation results from BSA officer 100 through network 600. After approval, computer system 500 stores the potential case, the investigation results, the timestamp, and the associated cause vector in a database, and the stored information will be used for future calculations of the conditional probability value of cause vector x (block 3007). Further, computer system 500 determines whether the investigation results indicate that the potential case is a true positive (decision block 3008). If the potential case is a true positive (YES branch 3010), computer system 500 sends the true positive to computer system 700 at FinCEN (block 3011). If the potential case is not a true positive (NO branch 3009), computer system 500 rejects the potential case as a false positive.

[0379]

[0380] In block 3003, the computer system 500 compares the conditional probability value of the cause vector x with a set of true positive acceptance thresholds to determine whether the computer 500 can automatically accept a potential case as a true positive. However, if the total number of potential cases previously triggered by the cause vector x is a very small number, the conditional probability value of the cause vector x may not be reliable. Under such circumstances, the computer system 500 can still send the potential case to the investigator 300 through the network 600 for manual investigation (block 3006).

[0380]

[0381] However, as described above, if the conditional probability value of one of the child vectors of the cause vector x is reliable and higher than any of the true positive acceptance thresholds, the computer system 500 can still send the potential case as a true positive to the computer system 700 at FinCEN (block 3011).

[0381]

[0382] As shown in the flowchart of FIG. 4 in combination with the system diagram of FIG. 1, computer system 500 uses a method to calculate the conditional probability p(S / x) of cause vector x based on the investigation results of investigator 300. Computer system 500 uses counter NTPX to count the number of true positives triggered by cause vector x. Additionally, computer system 500 uses counter NPCX to count the total number of potential cases triggered by cause vector x. In the initial stage, computer system 500 sets the values of both counters to 0. When a potential case is detected, computer system 500 determines whether the potential case was triggered by cause vector x (decision block 4002). If the potential case was not triggered by cause vector x (NO branch 4004), this process ends (block 4005) and computer system 500 moves on to the next potential case. If the potential case was triggered by cause vector x (YES branch 4003), computer system 500 determines whether the potential case needs to be processed manually (decision block 4006). As previously explained, sometimes a potential case may exceed the true positive acceptance threshold and no manual processing of the potential case is required. Sometimes, even if a potential case exceeds the true positive acceptance threshold, the potential case may still require a manual process so that investigator 300 can further improve the accuracy of the conditional probability value. If the potential case should not be processed manually (NO branch 4008), computer system 500 processes the potential case in another way (e.g., automatically sending the true positive to computer system 700 at FinCEN). As a result, since there is no manual investigation and the conditional probability is not affected by the potential case, this process ends (block 4005) and computer system 500 moves on to the next potential case.

[0382]

[0383] If a potential case is to be processed manually (YES branch 4007), the computer system 500 determines whether the potential case requires consideration, e.g., investigation (decision block 4009). For example, as previously explained, if a customer is on the comparison-excluded list, the computer system 500 should skip the potential case, and the conditional probability should not be affected by the skipped cases that are outliers. Thus, if there is no need to consider the potential case (NO branch 4011), this process ends (block 4005), and the computer system 500 moves on to the next potential case.

[0383]

[0384] If the potential case requires consideration (YES branch 4010), as previously explained, many events can occur. For example, the computer system 500 sends the potential case to the investigator 300 through the network 600. The investigator 300 sends the investigation results to the computer system 500 through the network 600. The computer system 500 sends the investigation results to the BSA officer 100 through the network 600. The computer system 500 receives approval of the investigation results from the BSA officer 100 through the network 600. Based on the investigation results, the computer system 500 determines whether the potential case is a true positive (decision block 4012).

[0384]

[0385] If the potential case is not a true positive (NO branch 4014), the computer system 500 adds 0 to the NTPX counter and 1 to the NPCX counter (block 4016), and then stores the investigation results and the date and time of the investigation decision in the database together with the potential case and the cause vector x (block 4017).

[0385]

[0386] If the potential case is a true positive (YES branch 4013), the computer system 500 adds 1 to the NTPX counter and 1 to the NPCX counter (block 4015), and then stores the investigation result and the date and time of the investigation decision in the database together with the potential case and the cause vector x (block 4017). Then this process ends (block 4005), and the computer system 500 moves on to the next potential case.

[0386]

[0387] The cause vector of a potential case defines the possible causes for reporting the potential case. Thus, two potential cases of two different customers may have the same cause vector. Although the cause vector x is used in the above description, there may be multiple cause vectors. Each cause vector may have a flowchart similar to that in FIG. 4. For example, a potential case triggered by the cause vector y can also be processed in the same way as shown in the flowchart of FIG. 4, except that the counters NTPY and NPCY are used instead of the counters NTPX and NPCX.

[0387]

[0388] In the above method, since the total number of potential cases triggered by the cause vector x and manually investigated by the investigator 300 is also identified via the NPCX counter, the computer system 500 can also determine whether the conditional probability value is reliable. For example, when NPCX has a value of 1 or 2, the conditional probability value of the cause vector x, such as NTPX / NPCX, may not be reliable. However, when the NPCX value is greater than a threshold, the conditional probability value of the cause vector x becomes very reliable. Thus, the computer system 500 can set a true positive acceptance threshold for the cause vector x under the condition that the value of NPCX is greater than a predetermined value. The predetermined value can be set by a software module, the person designing the system, the person adjusting the system, and / or the user of the system.

[0388]

[0389] As shown in the flowchart of FIG. 5 in combination with the system diagram of FIG. 1, the computer system 500 gradually learns the writing style of the investigator 300 so that the computer system 500 can automatically generate a report of the investigator 300. As described above, each subject (e.g., customer) can have its corresponding set of facts. The position of the fact relative to the link word is generally called a format. The relative positions (e.g., formats) of each fragment of the link word and the fact generally define the writing style of a human writer. A human writer can complete the report by modifying the link word, the position of the fact, or adding or deleting fragments of the fact.

[0389]

[0390] First, the computer system 500 generates a report based on the default format and the default set of link words together with the set of facts of the current subject (block 5002). Next (decision block 5003), the computer system 500 determines whether the investigator 300 has modified the previous report generated by the computer system 500. If the investigator 300 has not modified the previous report (NO branch 5004), the investigator 300 does not need to make additional modifications to the current report, and the current report can be sent to the BSA officer 100 for approval (or alternatively, if the investigator 300 has the authority to send the report directly to FinCEN, to the computer system 700 at FinCEN).

[0390]

[0391] If the investigator 300 has modified the previous report generated by the computer system 500 (YES branch 5005), the computer system 500 sends the current report to the investigator 300 for review and modification (block 5006). Then, after the investigator 300 has completed the review, the report is sent back to the computer system 500 (block 5007).

[0391]

[0392] Next, the computer system 500 determines whether the investigator 300 has made any modifications to the current report (decision block 5008). If the investigator 300 has not made any modifications to the current report (NO branch 5009), the existing default format and the existing default set of link words match well with the writing style of the investigator 300 and can be used for future reports. If the investigator 300 has modified the current report (YES branch 5010), the computer system 500 uses the set of link words modified by the investigator 300 as the format (e.g., the position of the facts) and the default set of link words for the next subject (block 5011).

[0392]

[0393] The above process is repeated for subsequent subjects. The computer system 500 enables the investigator 300 to continue to modify the format and link words for subsequent subjects until the report generated by the computer system 500 matches well with the writing style of the investigator 300 without any need for modification by the investigator 300.

[0393]

[0394] Even after the computer system 500 successfully generates a report that matches the writing style of the investigator 300, the computer system 500 can still send the report to the investigator 300 regularly so that the computer system 500 can adapt if the investigator 300 changes his or her writing style. This continuous learning process is desirable to enable the computer system 500 to adapt to changing needs. The frequency of sending the report to the investigator 300 for the purpose of adapting the computer system 500 to changes in the writing style can be determined by a computer algorithm that self-adjusts based on the system designer, system user, engineer, or the past behavior of the investigator 300.

[0394]

[0395] In the present disclosure, thresholds, predetermined values, or parameters that can be set by a person such as a designer or a user can also be set by an intelligent system that learns the person's preferences by evaluating the person's past behavior.

[0395]

[0396] In the present disclosure, the term "network" generally refers to one or more communication networks that can be wireless or wired, private or public, real-time or non-real-time, or a combination thereof, including the well-known Internet.

[0396]

[0397] In the present disclosure, the term "computer" or "computer system" generally refers to either a single computer or a group of computers that can function alone or together to achieve the purpose of the system.

[0397]

[0398] In the present disclosure, the term "processor" generally refers to either a single processor or a group of processors that can function alone or together to achieve the purpose of the processor.

[0398]

[0399] In the present disclosure, the term "module" can be hardware, software, firmware, or a combination thereof, and refers to a single component or a plurality of components that can function alone or together to achieve the purpose of the module.

[0399]

[0400] In the present disclosure, "bank" or "financial institution" generally refers to any financial service provider, either a bank or a non-bank, where financial services and money services are provided. Some examples of financial institutions include banks, credit unions, insurance companies, insurance agencies, stock brokers, stock agencies, bond brokers, bond agencies, commodity brokers, commodity agencies, securities companies, housing finance companies, mortgage institutions, securities companies, money service providers, agencies for money service providers, agencies for organizations providing financial services or money services, financial holding companies, trading companies, trading agencies, other financial service providers, other financial institutions, stock exchanges, commodity exchanges, securities exchanges, currency exchanges, virtual currency companies, virtual currency issuers, virtual currency service providers, virtual currency network providers, virtual currency computer providers, virtual currency dealers, virtual currency exchanges, virtual securities exchanges, bond exchanges, other exchanges, fund managers, investment companies, private equity investment companies, venture capital, franchise acquirers, payment processors, payment card issuers, payment card program managers, Internet merchants, transaction processors, securities processors, and other organizations related to financial services, etc.

[0400]

[0401] In the present disclosure, "bank account" or "financial account" generally refers to an account related to any financial institution, either a bank or a non-bank, through which financial transactions can be conducted using financial products such as cash, virtual currency, virtual certificates, virtual securities, checks, credit cards, debit cards, ATM cards, stored value cards, gift cards, prepaid cards, telecommunications, currency substitutes, letters of credit, notes, securities, commercial paper, commodities, securities, precious metals, electronic funds transfers, automated clearinghouses, etc.

[0401]

[0402] In the present disclosure, "financial transaction" generally refers to transactions related to financial activities including, but not limited to, payments, fund settlements, money services, securities issuances, securities transactions, currency transactions, commodity transactions, salary payments, invoice issuances, trading, escrows, insurance, underwriting, mergers, acquisitions, account openings, account closures, account status checks, etc.

[0402]

[0403] In the present disclosure, "trading" generally refers to both private and public trading activities, including but not limited to trading of stocks, currencies, virtual currencies, virtual certificates, virtual securities, commodities, rights, values, securities, derivatives, articles, services, goods, etc.

[0403]

[0404] In this disclosure, "securities" are generally considered to be as defined in the Securities Act of 1933 and other laws and regulations related to the Securities Act of 1933. For example, securities generally include notes, stocks, secured bonds, unsecured debentures, checks, exchange notes, warrants, traveler's checks, letters of credit, warehouse receipts, negotiable bills of lading, evidence of indebtedness, certificates of interest or participation in any profit-sharing agreement, collateral-trust certificates, preorganization certificates or subscriptions, transferable shares, investment contracts, voting-trust certificates; certificates of title to vehicles, whether valid or blank; certificates of interest in property, tangible or intangible; certificates or instruments or writings that evidence or transfer rights, title, or interest in goods, products, and merchandise; or generally, any instrument commonly known as a ''security'', or any certificate of interest or participation in, temporary or interim certificate for, receipt for, warrant, or right to subscribe to or purchase any of the foregoing may be included.

[0404]

[0405] In the present disclosure, "consumer" generally refers to an individual, organization, merchant, and / or customer, person, subject, payer, payee, beneficiary, user, or client who attempts to execute a transaction with a financial institution, etc.

[0405]

[0406] In this specification, the term "identity document" generally refers to a passport, driver's license, voter card, benefit card, student ID, social security card, national identification card, identity certificate, legal status certificate, and other official documents and information transmission certificates that identify an individual specified by certain verifiable features and are issued or recognized by a consulate, embassy, government agency, public or private organization, or other government authority and are protected from unauthorized copying or forgery by one or more responsible parties. In particular, such "identity documents" are made of various materials including paper, plastic, polycarbonate, PVC, ABS, PET, Teslin, composite materials, etc., and can embed identification information in various formats, for example, be printed or embossed on a document (or card), written on a magnetic medium, programmed into an electronic device, stored in memory, and combinations thereof. "Identification information" includes, but is not necessarily limited to, name, identification number, date of birth, signature, address, password, phone number, email address, personal identification number, taxpayer identification number, national identification number, country that issued the ID, state that issued the ID, ID expiration date, photo, fingerprint, iris scan, physical characteristics, and other biometric information. The embedded information can be read via optical media, acoustic media, electronic media, magnetic media, electromagnetic media, and other media.

[0406]

[0407] In the present disclosure, "personal identification information" generally refers to name, address, date of birth, personal identification number, user ID, password, taxpayer identification number, type of personal identification document used, identification number related to the personal identification document, country, state, government agency and / or private organization that issued the personal identification document, expiration date of the personal identification document, telephone number, screen name, email address, photo, fingerprint, iris scan, physical characteristics, biometric information, and other information that can be used to identify a person.

[0407]

[0408] In the present disclosure, "personal information" includes personal identification information, personal relationships, personal status, personal background, personal hobbies, and personal financial information including information related to financial products, financial accounts, and financial activities, as well as other information related to a person.

[0408]

[0409] In the present disclosure, "financial product" generally refers to a document used for conducting financial transactions. Examples of financial products include cash, virtual currency, virtual securities, virtual certificates, credit cards, debit cards, ATM cards, prepaid cards, stored value cards, gift cards, checks, currency substitutes, wire transfers, ACH transfers, letters of credit, notes, securities, commercial paper, commodities, precious metals, gold, silver, etc.

[0409]

[0410] In the present disclosure, "personal communication device" generally refers to a device interface used for personal communication purposes.

[0410]

[0411] In the present disclosure, "device interface" generally refers to a keyboard, keypad, monitor, display, terminal, computer, control panel, vehicle dashboard, network interface, machine interface, video interface, audio interface, electrical interface, electronic interface, magnetic interface, electromagnetic interface including electromagnetic wave interface, optical interface, light interface, acoustic interface, video interface, audio interface, contactless interface, mobile phone interface, smartphone interface, smartbook interface, tablet interface, other communication device interface, personal digital assistant (PDA) interface, handheld device interface, portable device interface, wireless interface, wired interface, and other interfaces.

[0411]

[0412] In this specification, the terms "terminal" or "kiosk" generally refer to devices including a computer and / or its peripheral devices, a microprocessor and / or its peripheral devices, an ATM terminal, a check cashing kiosk, a money service kiosk, a merchant checkout stand, a cash register, a currency exchange machine, a parking payment machine, other payment machines, contactless devices, a landline phone, a mobile phone, a smartphone, a smartbook, a tablet, a personal communication device, a tablet device, a digital assistant, an entertainment device, a network interface device, a router, and / or a personal digital assistant (PDA), etc., which interface the user with a computer network so that the user can interact with a computer system and other devices connected to the computer network.

[0412]

[0413] The methods described in this specification can be implemented by various means according to the application. For example, these methods can be implemented in hardware, firmware, software, or any combination thereof. In the case of a hardware implementation, the processing can be implemented within one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described in this specification, or any combination thereof.

[0413]

[0414] In the case of a firmware and / or software implementation, the method can be implemented using modules (e.g., procedures, functions, etc.) that perform the functions described in this specification. When implementing the methods described in this specification, any machine-readable medium that tangibly embodies instructions can be used. For example, software code can be stored in a memory and executed by a processor. The memory can be implemented within the processor or external to the processor. As used in this specification, the term "memory" refers to any type of long-term, short-term, volatile, non-volatile, or other memory, and should not be limited to any particular type of memory or number of memories, or the type of medium on which the memory is stored.

[0414]

[0415] When implemented in firmware and / or software, the functions may be stored as one or more instructions or codes on a computer-readable medium. Examples include computer-readable media encoded with a data structure and computer-readable media encoded with a computer program. The computer-readable medium includes physical computer storage media. The storage media can be any available media accessible by a computer. By way of example and not limitation, such computer-readable media can be RAM, ROM, EEPROM (registered trademark), CD-ROM, DVD, or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and disc include compact disc (CD), laser disc (registered trademark), optical disc, digital versatile disc (DVD), floppy disk (registered trademark), and Blu-ray disc, where disk typically magnetically reproduces data and disc optically reproduces data using a laser. Combinations of the above should also be included within the scope of computer-readable media.

[0415]

[0416] In addition to storage on computer-readable media, instructions and / or data may be provided as signals on a transmission medium included in a communication device. For example, the communication device may include a transceiver having signals indicative of instructions and data. The instructions and data are configured to cause one or more processors to implement the functions recited in the claims. The communication device will not necessarily store all of the instructions and / or data on a computer-readable medium.

[0416]

[0417] The aspects described in this disclosure can be assembled to form various applications as needed. Those skilled in the art related to the technology of this disclosure can understand that modifications and changes to the described structure can be implemented without significantly departing from the principles, spirit, and scope of this disclosure. Such modifications and changes should not be construed as a departure from this disclosure. The following is appended as it is the matter described in the original claims of the application. [C1] A method for detecting money laundering activities, when a flagged scenario within a cause vector of a first potential case related to money laundering meets a detection criterion, detecting, by a first computer system, the first potential case; comparing, by the first computer system, a first ratio of a first value of the cause vector to a second value of the cause vector with a threshold; when the first ratio is less than the threshold, transmitting, for investigation, the first potential case from the first computer system to a second computer system; when the result of the investigation indicates that the first potential case is a true positive, adjusting, by the first computer system, the first value; adjusting, by the first computer system, the second value based on the cause vector that meets the detection criterion; when the first potential case is the true positive, transmitting, from the first computer system to a third computer system, a first report related to the first potential case; A method including the above. [C2] Detecting, by the first computer system, a second potential case related to money laundering triggered by the cause vector; Comparing, by the first computer system, a second ratio of the adjusted first value to the adjusted second value to the threshold value; When the second ratio is not less than the threshold value, sending, from the first computer system to the third computer system, a second report related to the second potential case; The method according to C1, further comprising. [C3] The method according to C2, further comprising bypassing an investigation of the second potential case when the second ratio is not less than the threshold value. [C4] The first value is based on the number of true positives triggered by the flagged scenario in the cause vector during a period; The second value is based on the number of potential cases triggered by the flagged scenario in the cause vector during the period; The method according to C1. [C5] The method according to C1, further comprising flagging one scenario of the plurality of scenarios of the cause vector based on at least one of customer data, transaction data, or a combination thereof that meets the conditions. [C6] The customer data includes the customer's industry, business type, geographical area, country where the customer is located, nature of the customer's business, product type of the business, service type of the business, business structure, customer's occupation, customer's nationality, past records, type of the transactions conducted, account balance, funds inflow, funds outflow, transaction patterns, number of transactions, transaction amount, transaction quantity, transaction frequency, derivatives of the transactions, location of the transactions, time of the transactions, country of the transactions, sender of the remittance transaction, location of the sender, country of the sender, nature of the sender, recipient of the remittance transaction, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political exposure, past transactions, number of suspicious activity reports (SARs) provided regarding money laundering and terrorist financing cases, category of the first financial institution, business type of the first financial institution, geographical area of the first financial institution, country where the headquarters of the first financial institution is located, nature of the business of the first financial institution, age of the person, gender of the person, income level of the person, appearance of the person, judgment regarding the person, personal status of the person, family status of the person, members of the person's family, status of the members of the person's family, friends of the person, status of the friends of the person, past records of the person, industry of the person, geographical area of the person, country where the person is located, occupation of the person, job type of the employee, educational background of the employee, income level of the employee, employment period in the current job, record of the performance evaluation, work history, period of each employment in the work history, reason for leaving each employment in the work history, age of the employee, gender of the employee, personal status of the employee, family status of the employee, members of the employee's family, status of the members of the employee's family, status of the friends of the employee, past records of the employee, type of the work done, number of transactions executed, transaction amount executed, maximum transaction amount, number of transactions with a specific counterparty, transaction amount with a specific counterparty, number of changes to important records, number of changes to important records related to a specific counterparty, geographical area of the employee's home, geographical area of the employee's office, country where the employee is located, customer due diligence results, length of the account history, number of names that match a gambling organization in the transactions,The computer-implemented method according to C5, associated with at least one of them or a combination thereof. [C7] The method according to C5, wherein the transaction data is associated with at least one of cash, check, wire transfer, ATM (Automated Teller Machine), ACH (Automated Clearing House), virtual currency, virtual security, virtual certificate, credit card, debit card, prepaid card, electronic funds transfer, telecommunications, currency substitute, letter of credit, note, security, commercial paper, commodity, precious metal, account opening, account closing, account application, deposit, withdrawal, cancellation, balance confirmation, inquiry, credit, debit, or a combination thereof. [C8] The method according to C1, wherein the report includes a Suspicious Activity Report (SAR). [C9] The method according to C1, wherein the second computer system comprises a device interface resident in a financial institution. [C10] The financial institution includes at least one of a bank, a credit union, a money service provider, a financial holding company, an insurance company, an insurance agent, a housing finance specialized company, a mortgage institution, a stock broker, a stock agent, a bond broker, a bond agent, a commodity broker, a commodity agent, a trading company, a trading agent, other financial service providers, other financial institutions, a stock exchange, a commodity exchange, a currency exchange, a virtual currency company, a virtual currency issuer, a virtual currency service provider, a virtual currency network provider, a virtual currency computer provider, a virtual currency dealer, a virtual currency exchange, a virtual securities exchange, a bond exchange, other exchanges, a fund manager, an investment company, a private equity investment company, a venture capital, a virtual currency company, a franchise acquirer, a payment processor, a payment card issuer, a payment card program manager, an Internet merchant, other organizations related to financial services, or a combination thereof, and the method according to C9. [C11] The third computer system includes a device interface resident in a government agency, and the method according to C1. [C12] The government agency includes a Financial Crimes Enforcement Network (FinCEN), and the method according to C11. [C13] The flagged scenario includes at least one scenario, and the method according to C1. [C14] The detection criteria includes at least one criterion, and the method according to C1. [C15] A method for detecting money laundering activities, when a flagged scenario in a cause vector of a potential case related to money laundering meets the detection criteria, detecting the potential case by a first computer system; calculating a conditional probability value for the potential case based on the cause vector by the first computer system; comparing the conditional probability value with a threshold value by the first computer system; when the conditional probability value is greater than the threshold value, transmitting a report related to the potential case from the first computer system to a second computer system and the method includes. [C16] A method for detecting money laundering activities, when a flagged scenario in a first cause vector of a potential case related to money laundering meets the detection criteria, detecting the potential case by a first computer system; generating a composite cause vector by combining, by the first computer system, the first cause vector with second cause vectors of previous potential cases; calculating, by the first computer system, a conditional probability value for a case triggered by the composite cause vector; comparing, by the first computer system, the conditional probability value with a threshold value; when the conditional probability value is greater than the threshold value, transmitting, from the first computer system to a second computer system, a report related to the potential case and the previous potential cases A method comprising. [C17] A method for detecting money laundering activities, detecting, by a first computer system, a potential case when a flagged scenario in a cause vector of a potential case related to money laundering meets a detection criterion; calculating, by the first computer system, a conditional probability value for a case triggered by a child vector of the cause vector; comparing, by the first computer system, the conditional probability value with a threshold value; when the conditional probability value is greater than the threshold value, transmitting, from the first computer system to a second computer system, a report related to the potential case A method comprising. [C18] A method for detecting money laundering activities, detecting, by a first computer system, a potential case when a flagged scenario in a first cause vector of a potential case related to money laundering meets a detection criterion; generating, by the first computer system, a composite cause vector by combining the first cause vector with second cause vectors of previous potential cases; calculating, by the first computer system, a conditional probability value for a child vector of the composite cause vector; comparing, by the first computer system, the conditional probability value with a threshold value; when the conditional probability value is greater than the threshold value, transmitting, from the first computer system to a second computer system, a report related to the potential case and the previous potential cases A method comprising. [C19] A computer-implemented method for generating a report, comprising: Storing a first fact related to a first subject, a second fact related to a second subject, and a third fact related to a third subject in a database of a first computer system, wherein the first fact, the second fact, and the third fact have the same field name in the database; Receiving, in the first computer system, a first report of the first subject from a second computer system, wherein the first report includes the first fact and a first set of link words generated by a human writer; Transmitting the first report of the first subject from the first computer system to a third computer system; Transmitting the second fact and the first set of link words from the first computer system to the second computer system; Receiving, in the first computer system, a second report of the second subject from the second computer system, wherein the second report includes the second fact and a second set of link words generated by the human writer; Transmitting the second report of the second subject from the first computer system to the third computer system; When the first set of link words corresponds to the second set of link words, transmitting a third report of the third subject from the first computer system to the third computer system, wherein the third report includes the third fact and the second set of link words; A computer-implemented method comprising the above steps. [C20] The computer-implemented method according to C19, wherein the third fact is based at least on customer data. [C21] The computer-implemented method according to C20, wherein the customer data is associated with at least one of an individual, an organization, or a combination thereof. [C22] The customer data is associated with at least one of the customer's industry, the customer's business type, the customer's geographic area, the country where the customer is located, the nature of the customer's business, the product type of the business, the service type of the business, the structure of the business, the customer's occupation, the customer's nationality, past records, the type of transactions conducted, account balance, funds inflow, funds outflow, transaction patterns, number of transactions, transaction amount, transaction volume, transaction frequency, derivatives of the transaction, the location of the transaction, the time of the transaction, the country of the transaction, the sender of a remittance transaction, the location of the sender, the country of the sender, the nature of the sender, the recipient of a remittance transaction, the location of the recipient, the country of the recipient, the nature of the recipient, relationships, social status, political exposure, past transactions, the number of suspicious activity reports (SARs) provided regarding money laundering and terrorist financing cases, the category of the first financial institution, the business type of the first financial institution, the geographic area of the first financial institution, the country where the headquarters of the first financial institution is located, the nature of the business of the first financial institution, the age of a person, the gender of the person, the income level of the person, the appearance of the person, the judgment regarding the person, the personal status of the person, the family status of the person, the members of the person's family, the status of the members of the person's family, the friends of the person, the status of the friends of the person, the past records of the person, the industry of the person, the geographic area of the person, the country where the person is located, the occupation of the person, the job type of an employee, the educational background of the employee, the income level of the employee, the employment period in the current job, the record of work evaluations, work history, the period of each employment in the work history, the reason for leaving each employment in the work history, the age of the employee, the gender of the employee, the personal status of the employee, the family status of the employee, the members of the employee's family, the status of the members of the employee's family, the status of the friends of the employee, the past records of the employee, the type of work performed, the number of transactions executed, the transaction amount executed, the maximum transaction amount, the number of transactions with a specific counterparty, the transaction amount with a specific counterparty, the number of changes to important records, the number of changes to important records related to a specific counterparty, the geographic area of the employee's home, the geographic area of the employee's office, the country where the employee is located, the customer due diligence results, the length of the account history, the number of names that match a gambling organization in a transaction, or a combination thereof.The computer-implemented method according to C20. [C23] The computer-implemented method according to C19, wherein the third fact is based at least on transaction data. [C24] The computer-implemented method according to C23, wherein the transaction data is associated with at least one of a person, an organization, or a combination thereof. [C25] The transaction data is associated with at least one of cash, check, wire transfer, ATM (Automated Teller Machine), ACH (Automated Clearing House), virtual currency, virtual security, virtual certificate, credit card, debit card, prepaid card, electronic funds transfer, telecommunications, currency substitute, letter of credit, note, security, commercial paper, commodity, precious metal, account opening, account closing, account application, deposit, withdrawal, cancellation, balance confirmation, inquiry, credit, debit, or a combination thereof, and is a computer-implemented method described in C23. [C26] The third report is a computer-implemented method described in C19, including a Suspicious Activity Report (SAR). [C27] The second computer system includes a device interface resident in a financial institution, and is a computer-implemented method described in C19. [C28] The financial institution includes at least one of a bank, credit union, money services business, financial holding company, insurance company, insurance agency, housing finance company, mortgage institution, stock broker, stock agency, bond broker, bond agency, commodity broker, commodity agency, trading company, trading agency, other financial service provider, other financial institution, stock exchange, commodity exchange, currency exchange, virtual currency company, virtual currency issuer, virtual currency service provider, virtual currency network provider, virtual currency computer provider, virtual currency dealer, virtual currency exchange, virtual security exchange, bond exchange, other exchange, fund manager, investment company, private equity investment company, venture capital, virtual currency company, franchise acquirer, payment processor, payment card issuer, payment card program manager, internet merchant, other organization related to financial services, or a combination thereof, and is a computer-implemented method described in C27. [C29] The third computer system includes a device interface resident in a government agency, and is a computer-implemented method described in C19. [C30] The government agency includes the Financial Crimes Enforcement Network (FinCEN), and is a computer-implemented method described in C29.

Claims

1. 1. A computer-implemented method for generating a report, comprising: storing a first fact related to a first subject, a second fact related to a second subject, and a third fact related to a third subject in a database of a first computer system, wherein the first fact, the second fact, and the third fact have the same field names in the database; receiving, at the first computer system, a first report of the first subject from a second computer system, wherein the first report includes the first facts and a first set of linking words generated by a human writer; transmitting the first report of the first subject from the first computer system to a third computer system; transmitting the first set of second facts and link words from the first computer system to the second computer system; receiving, at the first computer system, a second report of the second subject from the second computer system, wherein the second report includes the second facts and a second set of linking words generated by the human writer; transmitting the second report of the second subject from the first computer system to the third computer system; sending a third report of the third subject from the first computer system to the third computer system when the first set of link words matches the second set of link words, wherein the third report includes the third fact and the second set of link words; The method includes:

2. The method of claim 1 , wherein the third fact is based on at least customer data.

3. The method of claim 2 , wherein the customer data is associated with at least one of an individual, an organization, or a combination thereof.

4. The customer data may include, for example, the type of business of the customer, the geographic area of ​​the customer, the country in which the customer is located, the nature of the business of the customer, the product type of the business, the service type of the business, the structure of the business, the occupation of the customer, the nationality of the customer, past records, types of transactions made, account balances, inflows of funds, outflows of funds, transaction patterns, number of transactions, transaction amounts, transaction volumes, transaction frequency, derivatives of transactions, location of the transactions, time of the transactions, country of the transactions, sender of remittance transactions, location of the sender, country of the sender, nature of the sender, remittance transactions the recipient, the location of the recipient, the country of the recipient, the nature, relationships, social status, political exposure, past transactions, number of suspicious activity reports (SARs) provided for money laundering and terrorist financing cases, a category of a first financial institution, a business type of the first financial institution, a geographic area of ​​the first financial institution, a country in which the first financial institution is headquartered, the nature of the business of the first financial institution, an age of a person, a sex of the person, an income level of the person, an appearance of the person, a judgment regarding the person, a personal status of the person, a family status of the person, the person's family members, the status of the person's family members, the person's friends, the status of the person's friends, the person's past records, the person's industry, the person's geographic area, the person's country of residence, the person's occupation, the employee's job type, the employee's educational background, the employee's income level, the length of employment in the current job, performance evaluation records, employment history, the length of each employment in the employment history, the reason for leaving each employment in the employment history, the employee's age, the employee's gender, the employee's personal status, the status of the employee's family members, the employee's family members, the employee's friends associated with at least one of the following: a person's status, the employee's past records, the type of work performed, the number of transactions performed, the value of transactions performed, the maximum transaction value, the number of transactions with a particular counterparty, the value of transactions with a particular counterparty, the number of changes to key records, the number of changes to key records related to a particular counterparty, the geographic area of ​​the employee's home, the geographic area of ​​the employee's office, the country in which the employee resides, the results of due diligence of the customer, the length of the account history, the number of names matched to gambling organizations in transactions, or any combination thereof;The method according to claim 2.

5. The method of claim 1 , wherein the third fact is based on at least transaction data.

6. The method of claim 5 , wherein the transaction data is associated with at least one of a person, an organization, or a combination thereof.

7. 6. The method of claim 5, wherein the transaction data is associated with at least one of cash, check, wire transfer, ATM (Automated Teller Machine), ACH (Automated Clearing House), virtual currency, virtual securities, virtual certificates, credit cards, debit cards, prepaid cards, electronic funds transfer, wires, monetary instruments, letters of credit, notes, securities, commercial paper, commodities, precious metals, account opening, account closing, account application, deposits, withdrawals, cancellations, balance confirmations, inquiries, credits, debits, or combinations thereof.

8. The method of claim 1 , wherein the third report comprises a suspicious activity report (SAR).

9. The method of claim 1 , wherein the second computer system comprises a device interface resident at a financial institution.

10. 10. The method of claim 9, wherein the financial institution includes at least one of a bank, a credit union, a money services provider, a financial holding company, an insurance company, an insurance agency, a mortgage lender, a mortgage institution, a stockbroker, an equity agency, a bond broker, a bond agency, a commodity broker, a commodity agency, a trading company, a trading agency, other financial service providers, other financial institutions, a stock exchange, a commodity exchange, a currency exchange, a virtual currency company, a virtual currency issuer, a virtual currency service provider, a virtual currency network provider, a virtual currency computer provider, a virtual currency dealer, a virtual currency exchange, a virtual securities exchange, a bond exchange, other exchanges, a fund manager, an investment company, a private equity firm, a venture capital firm, a virtual currency company, a merchant acquirer, a payment processor, a payment card issuer, a payment card program administrator, an Internet merchant, other financial services organizations, or combinations thereof.

11. The method of claim 1 , wherein the third computer system comprises a device interface resident at a government agency.

12. The method of claim 11 , wherein the government agency includes the Financial Crimes Enforcement Network (FinCEN).

Citation Information

Patent Citations

  • Money laundering detecting device, money laundering detecting method and money laundering detecting program

    JP2005228077A

  • Money laundering determination assistance system, method, and program

    JP2010225040A

  • System, method and program for evaluating account

    JP2016075989A

  • Transactional monitoring system

    US20140058914A1

  • Fraud detection systems and methods

    US20160132886A1