Transaction audit server, transaction audit system, transaction audit method, and transaction audit program

The transaction audit system improves fraud detection by using location and communication data to identify and flag suspicious transactions, effectively preventing cash embezzlement by sales representatives.

JP7823146B1Active Publication Date: 2026-03-03HITACHI SOLUTIONS WEST JAPAN LTD
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-10-25
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Conventional systems fail to detect fraudulent cash embezzlement by sales representatives who do not record speech during transactions and pretend no exchange occurred, leaving room for improvement in preventing such acts.

Method used

A transaction audit system that records location information and communication data from mobile devices, uses a processor to determine fraudulent transactions based on predefined conditions, and generates warning transaction information.

Benefits of technology

Enhances the detection of fraudulent activities like cash embezzlement by analyzing location and communication data to identify suspicious transactions, enabling early intervention and resolution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007823146000001_ABST
    Figure 0007823146000001_ABST
Patent Text Reader

Abstract

We will make improvements to prevent fraudulent activities such as embezzlement of cash by sales staff. [Solution] A mobile terminal of a transaction audit system acquires location information of the mobile terminal, creates transaction history log information that records transaction attributes related to transaction attributes entered into the mobile terminal when a transactor conducts a transaction with a trading partner and the location information of the mobile terminal acquired at the time of the transaction, and sends the information to an audit server. The audit server determines whether a transaction corresponds to a warning transaction based on the location information recorded in the received history log information and warning transaction conditions that indicate the possibility that the transaction related to the history log information is a fraudulent warning transaction, and records transactions that correspond to warning transactions in transaction warning information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention provides a transaction audit server ,Transaction audit system, Transaction audit methods, and transaction audits program Regarding. [Background technology]

[0002] In the sales activities of sales representatives of financial institutions, etc., there are many cases where sales representatives embezzle cash that they have handed over to customers. For example, Patent Document 1 discloses a cash handover confirmation system that prevents sales representatives from embezzling cash by recording the utterances of the sales representative when they hand over cash to customers and determining whether the actual amount of money handed over is correct based on the record of the amount of money handed over included in the occurrence. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-39560 Summary of the Invention [Problem to be solved by the invention]

[0004] However, with the above-mentioned conventional technology, there is a risk that embezzlement may go undetected, for example, if a sales representative does not record the speech spoken when handing over cash to a customer, and pretends as if no cash exchange took place between the sales representative and the customer, while actually receiving and embezzling the cash from the customer. As such, the above-mentioned conventional technology leaves room for improvement in terms of preventing fraudulent acts, including the embezzlement of cash, by sales representatives and others in transactions with customers.

[0005] The present invention has been made in view of the above circumstances, and aims to provide an improvement in preventing fraudulent acts, such as embezzlement of cash, by sales representatives and the like in transactions with customers. [Means for solving the problem]

[0006] In order to achieve the above object, the present invention provides, as one aspect, a transaction audit server, The person in charge of trading Using a mobile device Obtained when conducting business with a trading partner The aforementioned The location information of the mobile device was recorded The aforementioned Transaction log information From the mobile device Incoming communications Department and the communication Department the location information recorded in the history log information received by The aforementioned Related to history log information The aforementioned a warning transaction condition indicating that the transaction may be a fraudulent warning transaction; and The aforementioned The transaction The aforementioned Determine whether a transaction is a warning transaction. Processor And, with The warning transaction conditions include a plurality of location information conditions related to the location information and a location information index representing a weight for each of the location information conditions; The aforementioned The processor determines which of the location information conditions the transaction related to the history log information falls under based on the location information recorded in the history log information and the plurality of location information conditions, calculates a location information warning index by summing up the location information indices corresponding to the location information conditions for the transaction determined to fall under the location information condition, and determines whether the transaction related to the history log information falls under the warning transaction based on the location information warning index. It is characterized by: [Effects of the Invention]

[0007] According to the present invention, for example, it is possible to improve the prevention of fraudulent acts, such as embezzlement of cash by sales staff in transactions with customers. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram showing the configuration of a transaction audit system according to an embodiment. [Figure 2] FIG. 2 is a diagram showing the configuration of a transaction history according to the embodiment. [Figure 3] FIG. 3 is a diagram showing the configuration of a transaction audit log according to the embodiment. [Figure 4] FIG. 2 is a diagram showing the configuration of visiting address information according to the embodiment. [Figure 5] FIG. 10 is a diagram showing the configuration of warning transaction information according to the embodiment. [Figure 6] 10 is a flowchart showing a transaction process according to an embodiment. [Figure 7] 10 is a flowchart showing a warning transaction information creation process according to an embodiment. [Figure 8] 10 is a flowchart showing a warning transaction determination process (transaction attributes) according to an embodiment. [Figure 9] 10 is a flowchart showing a warning transaction determination process (location information) according to an embodiment. [Figure 10] FIG. 10 is a diagram showing a warning transaction list screen according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] (Configuration of transaction audit system S according to the embodiment) FIG. 1 is a diagram showing the configuration of a transaction audit system S according to an embodiment. The transaction audit system S includes a mobile terminal 1, an audit server 2, and an audit terminal 3. The mobile terminal 1, the audit server 2, and the audit terminal 3 are connected to a network N1. The mobile terminal 1 is connected to the network N1 via a wireless base station NE, such as for mobile phone communication or short-range wireless communication. The audit server 2 is also connected to an accounting system server 4 via a network N2.

[0010] The mobile terminal 1 is a tablet, a smartphone, or the like carried by a sales representative (transaction manager) of a financial institution, etc. The mobile terminal 1 has a processor 11, a memory unit 12, an input / output unit 13, a communication unit 14, and a location information acquisition unit 15.

[0011] The processor 11 is a processing device such as a microprocessor, and has a transaction history and audit log creation unit 111 (history log creation unit) that is realized by executing a program. The transaction history and audit log creation unit 111 creates a transaction history 121 (described later) and a transaction audit log 122 (described later).

[0012] The memory unit 12 includes a volatile memory area such as a memory and a non-volatile memory area such as a storage. The memory unit 12 stores a transaction history 121, a transaction audit log 122, and a movement route record 123. The transaction audit log 122 will be described later with reference to FIG. 2. The movement route record 123 will be described later with reference to FIG. 3. The movement route record 123 is time-series information of the latitude and longitude of the current location periodically acquired by the position information acquisition unit 15 described later, and the movement route of the mobile terminal 1 can be determined by tracing the time series.

[0013] The storage unit 12 also stores information (latitude and longitude) of the planned transaction location to be visited by the sales representative carrying the mobile terminal 1, based on visit address information 221 (described below) acquired from the accounting system server 4 by advance automatic batch processing or the like. The planned transaction location to be visited can be changed from the visit address information 221 to, for example, the place of work, via the financial institution's public relations support system (not shown).

[0014] The input / output unit 13 includes an input device such as a touch panel and an output device such as a display. The communication unit 14 is a wireless communication device that complies with communication standards such as mobile phone communication and short-range wireless communication, allowing the mobile terminal 1 to communicate with the audit server 2 via the network N1. The location information acquisition unit 15 acquires self-location information based on a beacon signal of GPS (Global Positioning System (registered trademark)) or short-range wireless communication.

[0015] The audit server 2 is a server that audits cash transactions between sales representatives and customers and is configured in an on-premise environment or a cloud environment. The audit server 2 includes a processor 21, a memory unit 22, an input / output unit 23, and a communication unit 24.

[0016] The processor 21 is a processing device such as a microprocessor, and includes a warning transaction determination unit 211 that is realized by executing a program. The warning transaction determination unit 211 creates warning transaction information 222, which will be described later.

[0017] The storage unit 22 includes a volatile storage area such as a memory and a non-volatile storage area such as a storage, etc. The storage unit 22 stores visit address information 221 and warning transaction information 222.

[0018] The input / output unit 23 includes input devices such as a keyboard and a mouse, and output devices such as a display and a printer. The communication unit 24 is a communication device that enables the audit server 2 to communicate with the mobile terminal 1 via the network N1 and with the accounting system server 4 via the network N2.

[0019] The audit terminal 3 is a personal computer of a manager installed in an office of a financial institution, who audits transactions between sales staff and customers (counterparties). The audit terminal 3 has a processor 31, a memory unit 32, an input / output unit 33, and a communication unit 34.

[0020] Processor 31 is a processing device such as a microprocessor, and has a warning transaction information viewing unit 311 that is implemented by executing a program. Based on warning transaction information 222 received from audit server 2, warning transaction information viewing unit 311 displays a warning transaction list screen 33D (FIG. 10), which will be described later, on the display of input / output unit 33.

[0021] The storage unit 32 includes a volatile storage area such as a memory and a non-volatile storage area such as a storage. The input / output unit 33 includes input devices such as a keyboard and a mouse and output devices such as a display and a printer. The communication unit 34 is a communication device that enables the audit terminal 3 to communicate with the audit server 2 via the network N1.

[0022] The inspection terminal 3 may be a mobile terminal that performs wireless communication.

[0023] The accounting server 4 is a host server that processes the core business of a financial institution.

[0024] (Configuration of transaction history 121 according to the embodiment) 2 is a diagram showing the configuration of the transaction history 121 according to the embodiment. A record is created in the transaction history 121 each time a sales representative carrying the mobile terminal 1 executes a transaction with a customer. The transaction history 121 has the following fields: transaction ID, financial institution code, person in charge ID, branch number, customer ID, transaction date and time, signature, signature, transaction category, transaction details, transaction location latitude, transaction location longitude, workplace, etc.

[0025] The transaction ID is identification information for the transaction. The financial institution code is identification information for the financial institution that performed the transaction identified by the transaction ID. The person in charge ID is identification information for the sales representative that performed the transaction identified by the transaction ID. The branch number is identification information for the branch of the financial institution that performed the transaction identified by the transaction ID. The customer ID is identification information for the customer that performed the transaction identified by the transaction ID. The transaction date and time is the date and time when the transaction identified by the transaction ID was performed. Signature presence indicates whether or not the customer's handwritten signature was input via the touch panel of the input / output unit 13 of the mobile terminal 1 for the transaction identified by the transaction ID. The signature is information that indicates an image file of the customer's handwritten signature or the storage location of the image file of the handwritten signature within the mobile terminal 1.

[0026] The transaction category indicates the category of the transaction identified by the transaction ID (for example, deposit / return of cash or supporting documents). The transaction content is the item given or received during the transaction identified by the transaction ID, such as cash or a passbook. The transaction location latitude and transaction location longitude are the latitude and longitude information of the location acquired by the location information acquisition unit 15 at the time of the transaction, for example, when entering a signature. The transaction location latitude and transaction location longitude indicate the transaction location where the sales representative actually conducted the transaction with the customer. The workplace is identification information of the workplace when the transaction identified by the transaction ID is related to workplace sales.

[0027] (Configuration of transaction audit log 122 according to the embodiment) 3 is a diagram showing the configuration of the transaction audit log 122 according to the embodiment. In the transaction audit log 122, a record is created along with the transaction history 121 each time a sales representative of a financial institution carrying a mobile terminal 1 executes a transaction with a customer. The transaction audit log 122 has the following fields: log ID, financial institution code, person in charge ID, branch number, customer ID, customer name, transaction start date and time, transaction completion date and time, log acquisition date and time, log acquisition category, transaction category, transaction details, transaction location latitude, transaction location longitude, transaction status, principal transaction, etc.

[0028] The log ID is identification information for the log. The financial institution code is the same as the financial institution code in the transaction history 121. The person in charge ID is the same as the person in charge ID in the transaction history 121. The branch number is the same as the branch number in the transaction history 121. The customer ID is the same as the customer ID in the transaction history 121. The customer name is the name or title of the customer identified by the customer ID. The transaction start date and time is the date and time when the transaction conducted by the sales representative with the customer using the mobile terminal 1 started. The transaction completion date and time is the date and time when the transaction conducted by the sales representative with the customer using the mobile terminal 1 was completed.

[0029] The log acquisition date and time is the date and time when the record identified by the log ID was acquired (created). The log acquisition category is information indicating the category in which the record identified by the log ID was acquired. The transaction category is the same as the transaction category in the transaction history 121. The transaction details are the same as the transaction details in the transaction history 121.

[0030] The transaction location latitude is the same as the transaction location latitude in transaction history 121. The transaction location longitude is the same as the transaction location longitude in transaction history 121. The transaction status is information indicating whether the transaction related to the record identified by the log ID is in progress / completed. The principal transaction is information indicating whether the transaction counterparty related to the record identified by the log ID is the customer himself / herself or someone other than the customer himself / herself. For a principal transaction, the sales representative operates the mobile terminal 1 to input, for example, "principal" if the transaction is carried out by the customer himself / herself, or "other than principal" if the transaction is carried out by someone other than the customer himself / herself.

[0031] (Configuration of Visiting Address Information 221 According to the Embodiment) FIG. 4 is a diagram showing the configuration of visit address information 221 according to an embodiment. Visit address information 221 is customer address information obtained from accounting system server 4 prior to execution of the warning transaction information creation process (FIG. 7). Visit address information 221 has the following fields: customer ID, customer name, visit address, visit address longitude, visit address longitude, ... The customer ID and customer name are the same as the customer ID and customer name in transaction history 121 and transaction audit log 122. Visit address is address information of a customer identified by a customer ID, and indicates a planned transaction address indicating the location where a transaction with the customer is planned to be conducted. Visit address latitude and visit address longitude are latitude and longitude information of the visit address identified by a customer ID, and indicate the planned transaction location indicating the location where a transaction with the customer is planned to be conducted.

[0032] (Configuration of warning transaction information 222 according to the embodiment) 5 is a diagram showing the configuration of the warning transaction information 222 according to the embodiment. Records of the warning transaction information 222 are created by executing the warning transaction information creation process (FIG. 7) on a daily, weekly, monthly, or other timing basis.

[0033] The warning transaction information 222 has the following items: transaction ID, customer name, transaction details, warning attribute (transaction attribute), warning attribute (location information), confirmation, transaction location latitude, and transaction location longitude. Furthermore, the warning attribute (transaction attribute) has the following items: warning index 1, identity transaction determination, and signature presence / absence determination. Furthermore, the warning attribute (location information) has the following items: warning index 2, distance between two points, building attribute, same location, previous transaction withdrawal location, and long-term transaction. Furthermore, the confirmation has the following items: person in charge, and manager.

[0034] The transaction ID is the same as the transaction ID in transaction history 121. The customer name is the same as the customer name in transaction audit log 122. The transaction details are the same as the transaction details in transaction history 121 or transaction audit log 122. The warning attribute (transaction attribute) indicates a warning issued by the warning transaction determination process (transaction attribute) (Figure 8) described below. The warning attribute (location information) indicates whether a warning is issued by the warning transaction determination process (location information) (Figure 9) described below.

[0035] Warning index 1 is the value of warning index 1 obtained by adding each index in the warning transaction determination process (transaction attributes) (Fig. 8). For the principal transaction determination, if the determination is YES in step S21a (Fig. 8) described below, a warning transaction flag is entered, and if the determination is NO, it is left blank. For the signature presence determination, if the determination is YES in step S21c (Fig. 8) described below, a warning transaction flag is entered, and if the determination is NO, it is left blank.

[0036] The warning index 2 is the value of the warning index 2 obtained by adding each index in the warning transaction determination process (transaction attributes) (Fig. 8). When the two-point distance determination is judged as YES in step S22a (Fig. 9) described below, a warning transaction flag is entered, and when the determination is NO, the field is left blank. When the building attribute determination is judged as YES in step S22d (Fig. 9) described below, a warning transaction flag is entered, and when the determination is NO, the field is left blank. When the same location determination is judged as YES in step S22j (Fig. 9) described below, a warning transaction flag is entered, and when the determination is NO, the field is left blank. When the past transaction location determination is judged as YES in step S22l (Fig. 9) described below, a warning transaction flag is entered, and when the determination is NO, the field is left blank. When the long-term trade determination is judged as YES in step S22n (Fig. 9) described below, a warning transaction flag is entered, and when the determination is NO, the field is left blank.

[0037] For confirmation, the confirmation date and time indicating that the person in charge of auditing the alert transaction and the administrator have confirmed the transaction is entered. The transaction location latitude and longitude are the same as those in the transaction history 121 and transaction audit log 122.

[0038] (Transaction processing according to the embodiment) 6 is a flowchart showing a transaction process according to the embodiment. The mobile terminal 1 is carried by a sales representative and operated at a customer's premises to start a transaction process, and generates and registers transaction history log information (transaction history 121, transaction audit log 122) related to the transaction.

[0039] First, in step S11, the transaction history and audit log creation unit 111 determines whether the transaction processing has been interrupted. If the transaction processing has been interrupted immediately after startup (step S11: YES), the transaction history and audit log creation unit 111 proceeds to step S17. On the other hand, if the transaction processing has not been interrupted immediately after startup (step S11: NO), the transaction history and audit log creation unit 111 proceeds to step S12.

[0040] In step S12, the transaction history and audit log creation unit 111 accepts the registration of a deposit (e.g., a voucher such as a bankbook). Next, in step S13, the transaction history and audit log creation unit 111 determines whether the transaction processing has been interrupted. If the transaction processing has been interrupted (step S13 YES), the transaction history and audit log creation unit 111 proceeds to step S17. On the other hand, if the transaction processing has not been interrupted (step S13 NO), the transaction history and audit log creation unit 111 proceeds to step S14.

[0041] In step S14, the transaction history and audit log creation unit 111 accepts input of the customer's signature via the touch panel of the input / output unit 13. Next, in step S15, the transaction history and audit log creation unit 111 determines whether the transaction processing has been interrupted. If the transaction processing has been interrupted (step S15 YES), the transaction history and audit log creation unit 111 proceeds to step S17. On the other hand, if the transaction processing has not been interrupted (step S15 NO), the transaction history and audit log creation unit 111 proceeds to step S16.

[0042] In step S16, the transaction history and audit log creation unit 111 creates a transaction history 121 and a transaction audit log 122 for transactions whose processing has been completed, and stores them in the memory unit 12. For the transaction audit log 122 for transactions whose processing has been completed, "Transaction Completed" is entered as the transaction status of the corresponding record. Meanwhile, in step S17, the transaction history and audit log creation unit 111 creates a transaction history 121 (interrupted portion) and a transaction audit log 122 (interrupted portion) for transactions whose processing has been interrupted, and stores them in the memory unit 12. For the transaction audit log 122 (interrupted portion) for transactions whose processing has been interrupted, "Transaction in progress" is entered as the transaction status of the corresponding record. Note that even if the transaction status of "Transaction in progress" later becomes "Transaction completed," an interruption and redo record (for example, a note such as "Interrupted") remains, indicating that the transaction was interrupted and redoed in the past.

[0043] In this way, in the mobile terminal 1, when a transaction is interrupted or restarted, the transaction history / audit log creation unit 111 records an interruption / restart record in the history log information related to that transaction (transaction history 121 and / or transaction audit log 122). In the audit server 2, the warning transaction determination unit 211 may determine whether a transaction related to the history log information corresponds to a warning transaction based on the interruption / restart record recorded in the history log information received from the mobile terminal 1. The warning transaction determination unit 211 then records transactions that correspond to warning transactions based on the interruption / restart record in the warning transaction information 222. In the audit terminal 3, the input / output unit 33 may output interruption / restart records for transactions that correspond to warning transactions by including them in a warning transaction list screen 33D described below.

[0044] (Warning transaction information creation process according to the embodiment) 7 is a flowchart showing the warning transaction information creation process according to the embodiment. The warning transaction information creation process is executed for each record of the same transaction in transaction history 121 and transaction audit log 122 each time transaction history 121 and transaction audit log 122 are acquired from mobile terminal 1, and warning transaction information 222 is created based on transaction history 121 and transaction audit log 122. Alternatively, the warning transaction information creation process may be executed when a certain amount of acquired transaction history 121 and transaction audit log 122 has accumulated.

[0045] First, in step S21, the warning transaction determination unit 211 executes a warning transaction determination process (transaction attributes). Details of the warning transaction determination process (transaction attributes) will be described later with reference to Figure 8. Next, in step S22, the warning transaction determination unit 211 executes a warning transaction determination process (location attributes). Details of the warning transaction determination process (location attributes) will be described later with reference to Figure 9.

[0046] Next, in step S23, the warning transaction determination unit 211 determines whether at least one of the warning index 1 calculated in step S21 and the warning index 2 calculated in step S22 is not 0 (greater than 0). If at least one of the warning indexes is not 0 (step S23 YES), the warning transaction determination unit 211 proceeds to step S24. On the other hand, if both warning indexes are 0 (step S23 NO), the warning transaction determination unit 211 ends the warning transaction information creation process.

[0047] In step S24, the warning transaction determination unit 211 creates warning transaction information 222 based on the warning index 1, identity transaction determination, signature presence / absence determination, warning index 2, distance between two locations determination, outdoor transaction determination, building attribute determination, same location determination, previous transaction location determination, and long-term transaction determination, which are described below.

[0048] (Warning Transaction Determination Process (Transaction Attributes) According to the Embodiment) 8 is a flowchart showing the warning transaction determination process (transaction attributes) according to an embodiment. At the start of the warning transaction determination process (transaction attributes), a warning index 1 (transaction attribute warning index), which indicates a warning transaction based on attribute information, is initialized. Each index (transaction attribute index) added to the warning index 1 is a predetermined number equal to or greater than 0.

[0049] First, in step S21a, the warning transaction determination unit 211 determines whether the transaction is authorized (authorized transaction determination). For example, it determines whether the authorized transaction item value in the transaction audit log 122 is "authorized." This is because transactions with persons other than the authorized person carry the risk of fraud involving cash transfers. "Authorized transaction" is one of the transaction attribute conditions.

[0050] If the transaction is a personal transaction (the personal transaction in the transaction audit log 122 is "personal") (YES in step S21a), the warning transaction determination unit 211 proceeds to step S21c. On the other hand, if the transaction is not a personal transaction (the personal transaction in the transaction audit log 122 is "non-personal") (NO in step S21a), the warning transaction determination unit 211 proceeds to step S21b. In step S21b, the warning transaction determination unit 211 adds index a1 related to the personal transaction determination to warning index 1. The warning transaction determination unit 211 also stores the personal transaction determination warning information in a specified memory area.

[0051] Next, in step S21c, the warning transaction determination unit 211 determines whether a signature is present (determining whether a signature is present). For example, it determines whether the signature presence / absence item value in the transaction history 121 is "signed." Transactions without signatures pose a risk of fraud involving cash transfers. "Whether a signature is present" is one of the transaction attribute conditions.

[0052] If a signature is present (the signature presence / absence in the transaction history 121 is "Signature Present") (YES in step S21c), the warning transaction determination unit 211 terminates the warning transaction determination process (transaction attributes). On the other hand, if a signature is not present (the signature presence / absence in the transaction history 121 is "No Signature") (NO in step S21c), the warning transaction determination unit 211 proceeds to step S21d. In step S21d, the warning transaction determination unit 211 adds index a2 related to the signature presence / absence determination to warning index 1. The warning transaction determination unit 211 also stores warning information on the signature presence / absence determination in a specified memory area.

[0053] (Warning transaction determination process (location information) according to the embodiment) 9 is a flowchart showing the warning transaction determination process (location information) according to an embodiment. At the start of the warning transaction determination process (location information), a warning index 2 (location information warning index) indicating a warning transaction based on location information is initialized. Each index (location information index) added to the warning index 2 is a predetermined number equal to or greater than 0.

[0054] First, in step S22a, the warning transaction determination unit 211 determines whether the distance between two points is greater than a threshold (point-to-point distance determination). For example, the point-to-point distance is the distance between the legitimate visiting address latitude and visiting address longitude where the transaction indicated in the visiting address information 221 should be conducted, and the transaction location latitude and transaction location longitude where the transaction indicated in the transaction history 121 and the transaction audit log 122 actually took place. Transactions with a large point-to-point distance are those that were conducted at a location different from the actual transaction location, and pose a risk of fraud involving cash transfers. "Point-to-point distance > threshold" is one of the location information conditions.

[0055] If the distance between the two points is greater than the threshold (YES in step S22a), the warning transaction determination unit 211 proceeds to step S22b, and if the distance between the two points is less than or equal to the threshold (NO in step S22a), the warning transaction determination unit 211 proceeds to step S22c. In step S22b, the warning transaction determination unit 211 adds an index b1 related to the distance between the two points to the warning index 2. The warning transaction determination unit 211 also stores warning information about the distance between the two points in a specified memory area.

[0056] Next, in step S22c, the warning transaction determination unit 211 determines whether the transaction is outdoors (outdoor transaction determination). For example, by comparing the transaction location latitude and longitude in the transaction history 121 and transaction audit log 122 with map data (not shown), it is determined whether the location is outdoors. This is because outdoor transactions are a type of transaction that does not normally occur and there is a risk of fraud involving the transfer of cash. "Is this an outdoor transaction?" is one of the location information conditions.

[0057] If the transaction is outdoors (step S22c YES), the warning transaction determination unit 211 proceeds to step S22d. If the transaction is indoors (step S22c NO), the warning transaction determination unit 211 proceeds to step S22i. In step S22i, the warning transaction determination unit 211 adds index b2 related to the building attribute (outdoors) to the warning index 2. The warning transaction determination unit 211 also stores the building attribute "outdoors" in a specified memory area.

[0058] In step S22d, the warning transaction determination unit 211 determines the building attributes of outdoor transactions (building attribute determination). For example, the building attributes of the relevant location are determined by comparing the transaction location latitude and longitude in the transaction history 121 and transaction audit log 122 with map data (not shown). This is because the risk of a cash transaction-related scandal varies depending on the building attributes. The "building attributes of outdoor transactions" is one of the location information conditions.

[0059] For example, the warning transaction determination unit 211 transfers processing to step S22e if the building attribute is a private residence, to step S22f if it is a public facility, to step S22g if it is a restaurant, and to step S22h if it is other.

[0060] In step S22e, the warning transaction determination unit 211 adds an index b3 related to the building attribute (private residence) to the warning index 2. In this case, the warning transaction determination unit 211 stores the building attribute "private residence" in a predetermined storage area. In step S22f, the warning transaction determination unit 211 adds an index b4 related to the building attribute (public facility) to the warning index 2. In this case, the warning transaction determination unit 211 stores the building attribute "public facility" in a predetermined storage area. In step S22g, the warning transaction determination unit 211 adds an index b5 related to the building attribute (restaurant) to the warning index 2. In this case, the warning transaction determination unit 211 stores the building attribute "restaurant" in a predetermined storage area. In step S22h, the warning transaction determination unit 211 adds an index b6 related to the building attribute (other) to the warning index 2. In this case, the warning transaction determination unit 211 stores the building attribute "other" in a predetermined storage area.

[0061] Next, in step S22j, the warning transaction determination unit 211 determines whether there is a transaction history in which multiple people who do not belong to the same occupational area conducted transactions at the same transaction location (same-location determination). For example, by referring to the transaction history 121, it is determined whether there are multiple transaction histories in which the transaction location latitude and longitude match or are close within a predetermined range, but the transaction locations are different. This is because multiple people with different occupational areas conducting transactions at the same location is an unusual transaction type and poses a risk of fraud involving cash transfers. "Whether there is a transaction history in which multiple people who do not belong to the same occupational area conducted transactions at the same transaction location" is one of the location information conditions.

[0062] If there is a transaction history of multiple people who do not work in the same occupational area conducting transactions at the same transaction location (step S22jYES), the warning transaction determination unit 211 proceeds to step S22k. On the other hand, if there is no transaction history of multiple people who do not work in the same occupational area conducting transactions at the same transaction location (step S22jNO), the warning transaction determination unit 211 proceeds to step S22l. In step S22k, the warning transaction determination unit 211 adds index b7 related to transactions at the same location to warning index 2. The warning transaction determination unit 211 also stores warning information for the same location in a specified memory area.

[0063] In step S22j, the warning transaction determination unit 211 may determine whether there is a transaction history in which multiple people from different occupations conducted transactions at the same outdoor transaction location. This is because multiple people from different occupations conducting transactions at the same outdoor location is considered to pose a high risk of fraudulent cash transactions.

[0064] In step S22l, the warning transaction determination unit 211 determines whether a transaction exists at the same location as a previous transaction (previous transaction location determination). That is, it determines whether the location information indicating the transaction location where a sales representative conducted a transaction with a customer differs from past location information indicating the transaction location where the same sales representative conducted a transaction with the same customer in the past. For example, by referring to the transaction history 121 and the transaction audit log 122, it determines whether a previous transaction exists where the transaction location latitude and transaction location longitude match or are close within a predetermined range. The absence of a transaction at the same location as a previous transaction indicates that the transaction was conducted at a new location, which poses a risk of fraud related to cash transfers. "Whether a transaction exists at the same location as a previous transaction" is one of the location information conditions.

[0065] If a transaction at the same location as a past transaction exists (step S221YES), the warning transaction determination unit 211 proceeds to step S22n. If a transaction at the same location as a past transaction does not exist (step S221NO), the warning transaction determination unit 211 proceeds to step S22m. In step S22m, the warning transaction determination unit 211 adds index b8 related to the transaction at the past transaction location to warning index 2. The warning transaction determination unit 211 also stores warning information for the past transaction location in a specified memory area.

[0066] In step S21n, the warning transaction determination unit 211 determines whether the transaction occurred over a long period of time at the same location (long transaction determination). That is, it determines whether the location information indicating the transaction location where the sales representative conducted the transaction with the customer remained at the same location for a period of time that exceeds a threshold. For example, if the value obtained by subtracting the transaction start date and time from the transaction completion date and time in the transaction audit log 122 exceeds the threshold, the transaction is determined to be a long transaction. A long transaction at the same location may involve transactions other than normal transactions, which poses a risk of fraud related to cash transactions. "Long transaction at the same location" is one of the location information conditions.

[0067] If the warning transaction determination unit 211 determines that the transaction is a long-term transaction (step S21nYES), it proceeds to step S21o, and if it determines that the transaction is not a long-term transaction (step S21nNO), it terminates the warning transaction determination process (location information). In step S22o, the warning transaction determination unit 211 adds the index b9 related to the long-term transaction to the warning index 2. The warning transaction determination unit 211 also stores warning information about the long-term transaction in a specified memory area.

[0068] (Warning transaction list screen 33D according to the embodiment) 10 is a diagram showing a warning transaction list screen 33D according to an embodiment. The warning transaction list screen 33D is displayed on the display of the input / output unit 33 of the audit terminal 3 based on the warning transaction information 222. The warning transaction information viewing unit 311 of the audit terminal 3 acquires the warning transaction information 222 from the audit server 2 in response to a user's operation of the keyboard or mouse of the input / output unit 33. The warning transaction information viewing unit 311 then generates the warning transaction list screen 33D based on the acquired warning transaction information 222 and displays it on the display of the input / output unit 33.

[0069] The warning transaction list screen 33D is Warning Trade It has an information display area D1 and a map display area D2. Warning Trade In the information display area D1, the transaction ID, customer name, transaction content, transaction attribute, and location attribute are displayed based on the warning transaction information 222.

[0070] The warning index 1 is the cumulative result of the warning transaction determination process (transaction attributes) (Figure 8). Warning Trade The warning index 1 = 10 in the information display area D1 is because the warning transaction flag "●" has been entered in the identity transaction judgment, and the judgment was YES in step S21a (Figure 8).

[0071] The warning index 2 is the cumulative result of the warning transaction determination process (location information) (Figure 9). Warning TradeThe warning index 2 in the information display area D1 is 30 because the two-point distance determination (step S22a), same location determination (step S22j), and long-term transaction determination (step S22n) were all judged as YES, as indicated by the warning transaction flag “●”.

[0072] The map display area D2 plots points corresponding to the transaction location latitude and transaction location longitude of each record of the warning transaction information 222, as in plots D21, D22a, and D22b, on map data obtained from an external source.

[0073] Plot D21 is indicated by a circle, for example, because it represents a case where the planned transaction location matches the location information recorded in the history log information indicating the transaction location. The planned transaction location is the location where the trader plans to conduct a transaction with the counterparty, and corresponds to the visiting address latitude and visiting address longitude in the visiting address information 221. The transaction location is the location where the trader actually conducted the transaction with the counterparty, and corresponds to the location information recorded in the history log information (the transaction location latitude and transaction location longitude in the transaction history 121, and the transaction location latitude and transaction location longitude in the transaction audit log 122).

[0074] In addition, plots D22a and D22b are cases where the distance between the planned transaction location and the transaction location exceeds the threshold, so the planned transaction location is shown with a triangle symbol and the transaction location is shown with a square symbol. When cursor D23 is placed over plot D22b, the attribute transaction (warning index 1, identity transaction determination, signature presence / absence determination) and location information (warning index 2, distance between two points, building attributes, same location, previous transaction location, long-term transaction) of the corresponding location are displayed in display D24.

[0075] Furthermore, the movement route r1 is the movement route of the sales representative carrying the mobile terminal 1, which is overlaid on the map display area D2 based on the movement route record 123 acquired by the audit terminal 3 together with the warning transaction information 222 from the mobile terminal 1 via the audit server 2. Because it is believed that sales representatives often take unnatural movement routes when making warning transactions, checking the movement route r1 may make it easier to discover warning transactions.

[0076] It should be noted that the same information may be output in a form other than the warning transaction list screen 33D.

[0077] (Effects of the embodiment) above Description In this embodiment, a determination is made as to whether a transaction corresponds to a warning transaction based on location information recorded in the history log information (transaction history 121, transaction audit log 122) and warning transaction conditions indicating the possibility that the transaction related to the history log information is a fraudulent warning transaction. Warning Trade This allows managers to quickly detect suspicious transactions that could be fraudulent, such as cash embezzlement, and interview sales staff and customers, enabling the prevention, early detection, and early resolution of incidents.

[0078] In the above embodiment, the location information warning index (warning index 2) and the location information conditions (determination conditions of steps S22a, S22c, S22d, S22j, S22l, and S22n) to which the transaction related to the history log information applies are used. Warning Trade This allows the administrator to know the cause of the warning transaction and take specific measures promptly.

[0079] Although several embodiments have been described above, these are merely examples for the purpose of explaining the present invention, and the scope of the present invention is not limited to these embodiments. The present invention can be embodied in various other forms, such as a form in which part of the configuration of each of the above-described embodiments is deleted, a form in which at least part of the configuration is replaced, a form in which additional configuration is added, or a form in which part or all of each of the embodiments are combined. [Explanation of symbols]

[0080] S: Transaction audit system, 1: Mobile terminal, 2: Audit server, 3: Audit terminal, 15: Location information acquisition unit, 33: Input / output unit, 33D: Warning transaction list screen, 111: Audit log creation unit, 121: Transaction history, 122: Transaction audit log, 222: Warning Trade information

Claims

1. A transaction audit server, a communication unit that receives, from a mobile terminal, transaction history log information that records location information of the mobile terminal acquired when a trader conducts a transaction with a trading partner using the mobile terminal; a processor that determines whether the transaction corresponds to the warning transaction based on the location information recorded in the history log information received by the communication unit and a warning transaction condition that indicates the possibility that the transaction related to the history log information is a fraudulent warning transaction; and The warning transaction conditions include a plurality of location information conditions related to the location information and a location information index representing a weight for each of the location information conditions, The processor: determining which of the location information conditions the transaction related to the history log information corresponds to based on the location information recorded in the history log information and the plurality of location information conditions; calculating a location information warning index by summing the location information indices corresponding to the location information conditions for the transactions determined to satisfy the location information conditions; determining whether the transaction related to the history log information corresponds to the warning transaction based on the location information warning index; A transaction audit server comprising:

2. 10. A transaction audit system comprising: a transaction audit server according to claim 1; and a terminal that communicates with said transaction audit server, The transaction audit server further comprises a storage unit; The processor: The transaction corresponding to the warning transaction, the location information warning index of the transaction, and the location information condition to which the transaction corresponds are recorded in the storage unit as warning transaction information; The terminal acquiring the warning transaction information from the transaction audit server, and outputting a warning transaction list that lists the transactions that fall under the warning transaction based on the warning transaction information; A transaction audit system characterized by:

3. 3. A transaction audit system according to claim 2, The terminal The location information condition and the location information index that correspond to the transaction that corresponds to the warning transaction are included in the warning transaction list and are output. A transaction audit system characterized by:

4. 2. A transaction audit server according to claim 1, The location information condition is: The distance between the location information recorded in the history log information indicating the location where the trader actually conducted the trade with the trading partner and the planned transaction location indicating the location where the trader plans to conduct the trade with the trading partner exceeds a threshold value. A transaction audit server comprising:

5. 2. A transaction audit server according to claim 1, The location information condition is: The location information recorded in the history log information indicating the location where the trader conducted the trade with the trading partner corresponds to outdoors. A transaction audit server comprising:

6. 2. A transaction audit server according to claim 1, The location information condition is: The location information recorded in the history log information indicating the location where the trader conducted the trade with the trading partner corresponds to a specific indoor location. A transaction audit server comprising:

7. 2. A transaction audit server according to claim 1, The location information condition is: The location information recorded in the history log information indicating the transaction location where the trader conducted the transaction with the trading partner is the same as the transaction location where the trader conducted the transaction with another trading partner who is not in the same workplace. A transaction audit server comprising:

8. 2. A transaction audit server according to claim 1, The location information condition is: The location information recorded in the history log information indicating the transaction location where the trader conducted the transaction with the counterparty is different from the location information recorded in the past history log information indicating the transaction location where the trader conducted the transaction with the counterparty in the past. A transaction audit server comprising:

9. 2. A transaction audit server according to claim 1, The location information condition is: The location information recorded in the history log information indicating the location where the trader conducted the transaction with the trading partner remains at the same location for a long period of time that exceeds a threshold. A transaction audit server comprising:

10. 2. A transaction audit server according to claim 1, The history log information further includes transaction attributes related to the attributes of the transaction input into the mobile terminal when the trader conducts the transaction with the trading partner, The warning transaction conditions include a plurality of transaction attribute conditions related to the transaction attributes and a transaction attribute index representing a weight for each of the transaction attribute conditions, The processor: determining which of the transaction attribute conditions the transaction related to the history log information corresponds to based on the transaction attributes recorded in the history log information and the plurality of transaction attribute conditions; calculating a transaction attribute warning index by summing the transaction attribute indices for the transactions determined to meet the transaction attribute conditions; determining whether the transaction related to the history log information corresponds to the warning transaction based on the transaction attribute warning index; A transaction audit server comprising:

11. 2. A transaction audit server according to claim 1, The history log information further includes an interruption / restart record indicating whether the transaction was interrupted or restarted; The processor: determining whether the transaction related to the history log information corresponds to the warning transaction based on the interruption and retry record recorded in the history log information; A transaction audit server comprising:

12. A computer-implemented method for auditing transactions, comprising: a communication step of receiving, from the mobile terminal, historical log information relating to the transaction, in which location information of the mobile terminal obtained when the trader conducts a transaction with a trading partner using the mobile terminal is recorded; a determination step of determining whether the transaction corresponds to the warning transaction based on the location information recorded in the history log information received in the communication step and a warning transaction condition indicating the possibility that the transaction related to the history log information is a fraudulent warning transaction; and The warning transaction conditions include a plurality of location information conditions related to the location information and a location information index representing a weight for each of the location information conditions, In the determination step, it is determined which of the location information conditions the transaction related to the history log information corresponds to based on the location information recorded in the history log information and the plurality of location information conditions, and a location information warning index is calculated by summing up the location information indexes corresponding to the location information conditions for the transaction determined to correspond to the location information condition; determining whether the transaction related to the history log information corresponds to the warning transaction based on the location information warning index; A transaction audit method comprising:

13. A computer-implemented transaction audit program, comprising: a communication step of receiving, from the mobile terminal, historical log information relating to the transaction, in which location information of the mobile terminal obtained when the trader conducts a transaction with a trading partner using the mobile terminal is recorded; a determination step of determining whether the transaction corresponds to the warning transaction based on the location information recorded in the history log information received in the communication step and a warning transaction condition indicating the possibility that the transaction related to the history log information is a fraudulent warning transaction; causing the computer to execute The warning transaction conditions include a plurality of location information conditions related to the location information and a location information index representing a weight for each of the location information conditions, In the determining step, it is determined which of the location information conditions the transaction related to the history log information corresponds to based on the location information recorded in the history log information and the plurality of location information conditions; calculating a location information warning index by summing the location information indices corresponding to the location information conditions for the transactions determined to satisfy the location information conditions; determining whether the transaction related to the history log information corresponds to the warning transaction based on the location information warning index; A transaction audit program characterized by:

Citation Information

Patent Citations

  • Transaction monitoring method, program and device

    JP2005285013A

  • Business risk monitoring system and management server

    JP2006251957A

  • Monitoring system

    JP2008203969A

  • Personal information protection business support system

    JP2017068384A

  • User information management device and user information management system

    JP2019164662A