Computer-implemented method, computer system and computer-readable medium for consumer protection
Patent Information
- Authority / Receiving Office
- TW · TW
- Patent Type
- Patents
- Current Assignee / Owner
- 宋煜燊
- Filing Date
- 2020-03-25
- Publication Date
- 2026-07-21
AI Technical Summary
Existing methods for detecting financial crimes, particularly money laundering and other suspicious activities, are inadequate as they rely on human oversight and behavioral changes, which are ineffective for hidden crimes and resource-intensive, leading to non-compliance with regulations and significant financial losses.
A computerized system and network that transforms identification information into identity codes, shares information confidentially, and uses intelligent alert systems to monitor transactions, learn from human feedback, and automatically verify potential financial crimes, reducing human workload and errors.
Enhances the detection of financial crimes by minimizing human intervention, improving compliance with regulations, reducing errors, and increasing profitability by tracing illicit proceeds, thus preventing financial losses and ensuring adherence to laws like the Bank Secrecy Act.
Abstract
Description
Technical Field
[0001] This invention generally relates to a consumer protection system. More specifically, this invention relates to enabling individuals, organizations, and financial institutions to protect themselves from various types of financial crime. Prior Technology
[0002] Criminals and fraudsters have employed numerous methods to steal funds, financial instruments, and other valuables from individuals and organizations. Many methods have been proposed throughout history to prevent financial crime. However, criminals and fraudsters continue to thrive, and billions of dollars are stolen annually due to financial crime. A more effective solution is needed to prevent financial crime.
[0003] The Bank Secrecy Act of the United States was first enacted in 1970. Under the Bank Secrecy Act, financial institutions are required to report suspicious activity to the government. Historically, financial institutions have trained frontline staff (e.g., bank tellers) to observe and identify suspicious activity. However, most financial institutions have failed to effectively comply with the Bank Secrecy Act. Following the 9 / 11 tragedy, U.S. lawmakers believed that effective compliance with the Bank Secrecy Act by financial institutions could have prevented the 9 / 11 attacks.
[0004] To further enforce the Bank Secrecy Act, the U.S. Congress passed the America Patriot Act, which imposes severe civil and / or criminal penalties for violations of the Bank Secrecy Act. Furthermore, U.S. government agencies (such as the Financial Crimes Enforcement Network (FinCEN), the Office of the Financial Conduct Authority (OCC), the Federal Reserve Bank (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), state banking departments, and financial institutions departments) strictly require financial institutions to comply with the Bank Secrecy Act, particularly their obligation to submit Suspicious Activity Reports (SARs) to FinCEN.
[0005] Suspicious activity encompasses a very broad range. For example, money laundering, terrorist financing, fraud, embezzlement, identity theft, computer intrusion, self-dealing, bribery, misrepresentation, forgery of tools, and unexplained disappearances are all classified as suspicious activity.
[0006] However, many financial institutions fail to detect and report suspicious activity. In fact, many financial institutions use products that are effective in preventing fraud but ineffective in preventing money laundering or other financial crimes. Typically, fraud can be detected based on a change in behavior, because the behavior of a fraudster who has stolen a victim's identity (or financial instrument) differs from that of the victim. If an account's activity differs from expected activity derived from historical activity, a computer system can detect a fraud case.
[0007] For example, U.S. Application No. 2003 / 0177087 states that a high-risk variable may include, for example, a change in the habitual behavior of an account indicated when a transaction exceeds its settings. According to this application, Beta, Delta, and Theta models are used to detect transactions that exceed a customer's settings.
[0008] However, money laundering and some other financial crimes can occur without any change in behavior. Therefore, traditional methods of detecting fraud based on behavioral changes cannot detect some basic money laundering activities or other financial crimes. In the money laundering field, a high-risk customer may not be suspicious. For example, money service businesses (MSBs), pawnshops, ATM providers, and flight attendants are often classified as high-risk customers by banks in their anti-money laundering programs. However, this does not mean that such high-risk customers are engaged in money laundering activities. Although high risk is associated with such customers, they may not have committed any crimes.
[0009] Some businesses are very difficult to monitor. For example, an MSB may process a large number of transactions every day and may not be able to detect a single money laundering transaction mixed in with the large number of transactions using traditional methods.
[0010] The challenges of complying with the USA PATRIOT Act and the Bank Secrecy Act (BSA) are just a few examples illustrating the importance of identifying suspicious activity. Identifying suspicious activity can also be used to comply with other laws, such as the Fair and Correct Credit Transactions Act (FACT Act), the Illegal Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sabine Act (SOX), regulations enacted by the Office of Foreign Assets Control (OFAC), and other laws and regulations.
[0011] Traditionally, compliance is implemented through policies and procedures that require human workers to take specific actions in response to specific conditions. For example, banks train their tellers at branches to observe and report any matters they deem questionable in relation to compliance with the Bank Secrecy Act.
[0012] This traditional method is no longer effective in modern times because customers no longer need to be physically present at a bank branch. For example, customers can conduct transactions remotely electronically (e.g., via the internet) and have access to a wide range of financial instruments (e.g., checks, credit cards, debit cards, etc.). Furthermore, criminals are highly skilled and know how to avoid attracting the attention of tellers. Therefore, relying on tellers to detect suspicious activity is insufficient for compliance with the Bank Secrecy Act.
[0013] Furthermore, this human-based approach is extremely costly. Intensive training must be conducted periodically to ensure that human workers truly know how to respond to different situations in compliance with various laws and regulations. However, human workers are prone to error. In fact, due to human oversight, numerous financial institutions have faced severe penalties from government agencies for failing to comply with different laws and regulations.
[0014] The aim is to improve surveillance systems to enhance the detection of different types of suspicious activity and to help businesses comply with various laws and regulations. The methods, functions, implementations, computer systems, networks, software, hardware, mechanisms, and other components used to detect suspicious activity may also be used by other applications or organizations for purposes other than detecting suspicious activity.
[0015] U.S. patents 9,866,386, 9,288,197, 8,870,068, 8,500,011, 8,191,774, and 7,533,808 disclose a computerized method and apparatus for identifying a common object of interest among multiple parties without disclosing the object's true identity. However, products based on those patents have failed to attract user interest. The main reason is that compliance officers are very busy and do not have time to log onto a website to find more information about a person with suspicious activity. This application discloses a computerized system and network that enables financial institutions to double their work almost effortlessly without disclosing any confidential information about their clients. Although an illicit proceeds tracking system is used as an example in this invention, the computerized system and network can be used in many other applications. Summary of the Invention
[0016] The present invention includes several embodiments that can be combined to form various computer systems and methods.
[0017] First, a computer system and method enable individuals and organizations to prevent financial crimes by means of the following steps: receiving identification information of a first object from a first computer system; transforming the identification information of the first object into a first identity code that hides the identification information of the first object; transmitting the first identity code to a second computer system; when the second computer system determines that the first identity code matches a second identity code transformed from a second object stored in the second computer system, receiving a message from the second computer system, the second identity code hiding the identification information of the second object; transmitting a question associated with the message to the first computer system; receiving an answer to the question from the first computer system; and when the answer is correct, approving a request from the first computer system.
[0018] The computer system and method transform identification information into an identity code through at least one of the following: selecting characters, encoding characters, configuring characters, recombining characters, encrypting characters, converting characters, decomposing characters into bytes, selecting bytes, converting bytes, reconfiguring byte sequences, recombining bytes into characters, encrypting bytes, or a combination thereof.
[0019] The computer system and method further enable individuals and organizations to prevent financial crimes by means of the following steps: receiving a first account and contact information of a first computer system; receiving a second account and a request from a fourth computer system; when the first account matches the second account, transmitting the request to the first computer system at least in part based on the contact information of the first computer system; receiving a response to the request from the first computer system; and transmitting a message corresponding to the response to the request to the fourth computer system.
[0020] Furthermore, the computer system and method enable individuals and organizations to prevent financial crimes by means of the following steps: when the response indicates that the request has been rejected, the first account is transmitted to multiple computer systems.
[0021] In addition to the computer systems and methods described above, a computer system enables individuals and organizations to prevent financial crimes by means of the following steps: transmitting a second password to a second computer system; receiving a first password from a first computer system in response to transmitting the second password; receiving a first financial instrument number from the first computer system; receiving a second financial instrument number and a description of a transaction from a fourth computer system; transmitting the description of the transaction to the first computer system when the first password corresponds to the second password and the first financial instrument number matches the second financial instrument number; receiving a message from the first computer system in response to transmitting the description of the transaction; and transmitting an instruction corresponding to the message to the fourth computer system.
[0022] The computer system and method further enable individuals and organizations to prevent financial crimes by means of the following steps: when the message indicates that the transaction has been rejected, the first financial instrument number is transmitted to multiple computer systems.
[0023] Furthermore, a computer system and method enable a network of computer systems to privately and confidentially share information by means of the following steps: receiving from a first computer system a first identity code transformed from identification information of a first object, the first identity code concealing the identification information of the first object; transmitting the first identity code to a second computer system; when the first identity code matches a second identity code transformed from identification information of a second object stored in the second computer system, receiving from the second computer system a message, the second identity code concealing the identification information of the second object; and responding to the message by performing an action.
[0024] The computer systems and methods described above are merely examples. Many other computer systems and methods can be formed by combining and reconfiguring the embodiments of the present invention.
[0025] This has provided a fairly broad overview of the features and technical advantages of the invention in order to better understand the detailed description that follows. Additional features and advantages of the invention will be described below. Those skilled in the art will understand that the invention can be readily used as a basis for modifying or designing other structures for carrying out the same purpose as the invention. Those skilled in the art will also recognize that such equivalent constructions do not depart from the teachings of the invention as set forth in the claims appended to the invention. The novel features believed to be characteristic of the invention (both in terms of their organization and manner of operation), along with further objectives and advantages, will be better understood from the following description when considered in conjunction with the accompanying drawings. However, it should be clearly understood that the figures are provided for illustrative and descriptive purposes only and are not intended to be a definition of limitation of the invention. Simple Explanation of the Diagram
[0026] The features, properties, and advantages of the invention will become more apparent when understood in conjunction with the drawings, from the detailed description set forth below.
[0027] Figure 1A illustrates a system and network diagram of an intelligent alarm system according to the present invention.
[0028] Figure 1B illustrates a system and network diagram of a consumer protection system according to the present invention.
[0029] Figure 1C illustrates a system and network diagram of an illegal proceeds tracking system according to the present invention.
[0030] Figures 2, 3 and 4 are flowcharts of a consumer protection system according to one aspect of the present invention.
[0031] Figures 5, 6 and 7 are flowcharts of an illicit proceeds tracking system according to one embodiment of the present invention.
[0032] The detailed descriptions accompanying the accompanying drawings are intended to describe one of various configurations and are not intended to represent the only configuration in which the concepts described herein can be practiced. The detailed descriptions include specific details for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts can be practiced without such specific details. In some examples, familiar structures and components are shown in block diagram form to avoid obscuring these concepts. As described herein, depending on the application based on convention, the use of the term "or" may mean "inclusive OR" or "exclusive OR". Implementation
[0033] Cross-reference to related applications This application claims the benefit of U.S. Patent Application No. 16 / 791,972, filed February 14, 2020, entitled "CONSUMER PROTECTION SYSTEM," and U.S. Provisional Patent Application No. 62 / 823,305, filed March 25, 2019, entitled "CONSUMER PROTECTION SYSTEM," the disclosures of which are expressly incorporated herein by reference in their entirety.
[0034] Some aspects of this invention relate to a consumer protection system that enables financial institutions, businesses, individuals, and organizations to work together to prevent financial crime. Consumers are thus protected by this system. Other aspects of this invention relate to a illicit proceeds tracking system that enables financial institutions to work together to prevent financial crime and recover funds stolen from financial institutions.
[0035] In addition, the consumer protection system works in conjunction with multiple Intelligent Alert Systems (IAS) that monitor the transactions and activities of customers across various businesses to generate alerts. Intelligent alert systems can be installed at financial institutions, merchants, or any type of organization that needs to prevent financial crime. More importantly, intelligent alert systems learn from humans and can become even more intelligent, automatically accepting potential cases as correct affirmations and / or rejecting them as incorrect affirmations, much like humans do. Therefore, intelligent alert systems can help a financial institution comply with various requirements, including laws, regulations, and rules, using minimal human resources.
[0036] In addition to the Bank Secrecy Act, intelligent alarm systems can also help organizations comply with numerous other laws and regulations with minimal human resources by monitoring transactions and activities. Depending on the specific requirements of these laws and regulations, intelligent alarm systems can monitor different types of activities using different methods. This invention provides how to monitor transactions and activities and help organizations comply with various requirements, laws, and regulations with minimal human resources. Furthermore, intelligent alarm systems can also be used in other applications or by other organizations for other purposes as explained in the [Prior Art] section above. Intelligent alarm systems reduce or eliminate human workload and errors, save resources and money, and effectively achieve improved results.
[0037] Once the smart alarm system detects a potential financial crime against an individual (or organization), it sends a description of the financial crime and the individual's (or organization's) contact information to a consumer protection system. The consumer protection system contacts the individual (or organization) and requests verification that a financial crime has indeed occurred. The consumer protection system then sends feedback from the individual (or organization) back to the smart alarm system. If it is a genuine financial crime, the smart alarm system uses the feedback to stop the crime; otherwise, if it is not a genuine financial crime, the smart alarm system rejects the potential case as a false positive.
[0038] Furthermore, because the consumer protection system communicates with numerous smart alarm systems located at various financial institutions, it receives feedback from a wide range of individuals and organizations that are customers of these financial institutions. This feedback is also important for some third parties (such as businesses) who wish to prevent future losses due to similar financial crimes. These third parties wish to subscribe to services provided by the consumer protection system, which offers this feedback.
[0039] The consumer protection system has been integrated into an alert system with subscribers being third parties, such as businesses. Based on feedback from individuals (or organizations), if a crime is confirmed, the consumer protection system can send an alert to subscribers. The third party will use this information to deter future crimes, preventing criminals or fraudsters from committing similar crimes against individuals or organizations.
[0040] Many anti-money laundering specialists have recognized that transaction monitoring cannot identify all money launderers. After obtaining illicit proceeds, criminals often move to another financial institution to restart their discretionary transactions. These criminals masquerade as law-abiding citizens, and even if their illicit gains are deposited into the financial institution, the institution may not detect any of their transactions as suspicious. No transaction monitoring system can detect a money launderer without any suspicious transactions.
[0041] For example, John Doe, a client of Los Angeles financial institution A, disappeared after defaulting on a $250,000 unsecured loan obtained through fraudulent misrepresentation. Subsequently, the $250,000 was deposited without the trace by financial institution A into an account John Doe had opened several years earlier with financial institution B in San Francisco. If financial institution A knew that John Doe's illicit gains were in financial institution B, it could seize those gains in financial institution B's account through a pre-judgment seizure order.
[0042] However, the Gramm-Leach-Bliley Act in the United States and similar laws in other countries prohibit financial institutions from disclosing non-public personal information of their clients or members. Therefore, Financial Institution A cannot publicly disclose John Doe's name, and Financial Institution B cannot know that John Doe has stolen funds from Financial Institution B.
[0043] This application also discloses an illicit proceeds tracking system that tracks John Doe without disclosing any personally identifiable information about him. In the above scenario, when Financial Institution A tracks John Doe's illicit proceeds, Financial Institution B will receive an alert. Based on Section 314(b) of the United States Patriot Act, Financial Institution A and Financial Institution B are fully protected by a safe harbor when they discuss John Doe. Financial Institution A may obtain a pre-judgment seizure order from the court to seize John Doe's funds held in Financial Institution B.
[0044] According to the latest statistics released by the U.S. government, in the third quarter of 2019, the ratio of net loan losses to average total loans for all U.S. banks was 0.47%. This figure is close to the historical low of 0.35%, while the historical high was 3.12%. This means that even in the current favorable economic conditions, a "typical" financial institution that accepts deposits and makes loans may still suffer loan losses of approximately 0.47% of its total loan assets. For example, a financial institution with $1 billion in loan assets might suffer loan losses of approximately $4.7 million. Because this is an average figure, some financial institutions may fare better while others may fare worse.
[0045] Typical annual profits for banks and credit unions range from 1% to 2.0% of total assets. The typical assets of banks and credit unions consist primarily of loans. If we use an average of 1.5% as an example, even in a favorable economic climate, the average loan loss (0.47%) is still about one-third of the average profit (1.5%). This is why loan losses can keep senior managers and directors up at night.
[0046] If a financial institution's credit department has performed its duties correctly, the most common cause of loan losses is borrower misrepresentation. Funds stolen by a borrower due to misrepresentation are legally classified as illicit proceeds. If a BSA team can trace illicit proceeds stolen from a financial institution, the BSA team can help the institution recover the stolen funds and significantly increase the institution's overall profitability.
[0047] Therefore, in addition to identifying money launderers missed by AML transaction monitoring systems, illicit proceeds tracking can also substantially increase a financial institution’s overall profitability.
[0048] Furthermore, if every financial institution were to trace illicit proceeds after a criminal has committed a financial crime (such as money laundering, terrorist financing, Ponzi schemes, human trafficking, embezzlement, bank fraud, securities fraud, insurance fraud, tax fraud, etc.), then, based on the Money Laundering Control Act, which covers hundreds of specified illicit activities, criminals would be unable to launder illicit proceeds through any financial institution. This is the ultimate goal of anti-money laundering laws, regulations, and rules. The illicit proceeds tracing system will achieve this goal.
[0049] The U.S. government strictly enforces compliance by businesses with the America Patriot Act, the Bank Secrecy Act (BSA), the Fair and Correct Credit Transactions Act (FACT Act), the Illegal Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sabine Act (SOX), regulations enacted by the Office of Foreign Assets Control (OFAC), and other relevant laws and regulations. Businesses may include financial institutions such as banks, credit unions, mortgage companies, money service companies, securities brokers, and insurance companies. The U.S. government imposes billions of dollars in civil penalties (CMPs) on financial institutions that violate these laws and regulations. It also imposes criminal penalties on some individuals working for financial institutions.
[0050] A financial institution is only one type of business. Financial institutions are not the only organizations required to comply with these laws and regulations. Many other types of businesses are also required to comply with these laws and regulations. This invention applies to all businesses, including those obligated to comply with laws and regulations.
[0051] The Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) are U.S. organizations. U.S. laws and regulations are used as examples in this invention. Many other countries have similar organizations performing similar tasks. Therefore, many other countries have similar laws and regulations. This invention is also applicable to those countries to help businesses comply with their respective laws and regulations. This invention can also be used by businesses, individuals, or organizations that are not required to comply with a particular law or regulation.
[0052] It can often be difficult to determine whether an individual or group of people has engaged in illegal activity. Under the U.S. Bank Secrecy Act, when a company submits a Suspicious Activity Report (SAR) to FinCEN, it is not obligated to prove whether the reported activity is illegal. In fact, a "safe harbor" rule encourages companies to report more suspicious activity without fear of being accused of misreporting legitimate activity as illegal. Under this "safe harbor" rule, no person (or organization) can bring a lawsuit against an entity simply because that entity submitted a Suspicious Activity Report (SAR) to FinCEN concerning that person (or organization). Governments use SARs to collect information and expect only one company to provide information and advice in a SAR. Government agencies conduct their own investigations to determine whether an activity reported in a SAR is indeed illegal.
[0053] Typically, the decision-making process for whether to report a suspicious activity that is not fraudulent differs from the decision-making process for whether to report a fraud case. In a fraud case, an entity (such as a business or a consumer) may lose money. Therefore, fraud is easier to detect than other crimes. Consequently, it is easier to decide whether to report a fraud case. Preventing fraud is also easier than preventing other crimes. As an example, if a computer system detects a high risk of fraud associated with a transaction, the system can block the transaction and allow an investigator to investigate whether it is indeed a fraud case.
[0054] In one embodiment of the present invention, for fraud detection, a computer system calculates a risk score associated with a transaction based on different factors associated with that transaction. These factors may include the account's historical activity, deviations from expected activity, the location, time, amount, frequency, and nature of the transaction, the relationship between multiple accounts, and the type, nature, and structure of the account holders, etc.
[0055] In one embodiment of the invention, for fraud detection, if the fraud risk score of a transaction exceeds a threshold, a computer system blocks the transaction. This threshold can be predetermined based on corporate policy.
[0056] In one embodiment of the invention, for fraud detection, a computer system generates a case based on detected high-risk fraud transactions. This case and related information are then presented to investigators for further investigation.
[0057] Compared to fraud, suspicious activity may lack clear evidence. For example, a customer might frequently deposit large sums of cash. This customer might be involved in money laundering by selling illicit goods and accepting cash payments. This customer might also sell homemade products at a farmers' market and only accept cash as payment. Typically, due diligence is required to determine if anything suspicious is at play.
[0058] It is also possible that while a customer may be selling homemade products at a farmers' market, that same customer may also be selling illegal items at other locations. Unless the bank is informed that the customer is selling illegal items, there is no evidence to prove to the bank that the customer is selling illegal items. If the customer is indeed selling illegal items and the bank fails to report this suspicious activity to FinCEN, the bank could later face severe penalties for failing to report the case to FinCEN should the customer be arrested by the government for selling illegal items.
[0059] On the other hand, if a bank reports every case that is extremely unlikely to be suspicious, it may attract unnecessary attention from government agencies. Government agencies could spend months investigating a bank's operations, potentially severely impacting its business.
[0060] The decision to report a case can be based on an instinctive judgment by the person reviewing it. Furthermore, the decision-making process can be highly subjective. Moreover, a business cannot prevent a transaction simply because it appears to be suspicious money laundering. When a business cannot actually prove money laundering has occurred, a consumer can sue the business that prevented the consumer from making a transaction. In fact, many government agencies often advise businesses that have reported suspicious activities (such as money laundering or terrorism financing) to remain silent and treat suspicious transactions as normal transactions, so that suspects do not become alert or abscond. This approach gives government agencies more time and opportunity to identify all relevant criminals.
[0061] Under the Bank Secrecy Act, a company that submits a Special Purpose Notice (SAR) is obligated to keep the SAR confidential and not allow any suspect (e.g., one of the individuals involved in the case) to know anything about the SAR, including its existence. SARs can only be reviewed by authorized government agencies.
[0062] As described above, because handling a case of suspicious activity is fundamentally different from handling a case of fraud, many conventional methods and concepts applicable to fraud detection and prevention are no longer useful for detecting and managing suspicious activities (such as money laundering, terrorist financing, elder abuse, online gambling, etc.). In one embodiment of the invention, a computer system records the opinion of the person who decided not to report a case of suspicious activity that has been detected. In such cases, the decision-maker records the reasons for their decision.
[0063] Unlike a fraud case, a case of suspicious activity may be unclear to the person reviewing it until additional evidence becomes available. Therefore, someone might initially reject a case of detected suspicious activity but later change their mind when additional evidence becomes available. In one embodiment of the invention, a person reviewing a case of detected suspicious activity may also need to review all historical cases of detection against the same suspect to determine whether any new evidence, when combined with old evidence that may come from any rejected cases, makes the new detection more suspicious. Therefore, even if a case was previously rejected as a false detection, it can still be reviewed later.
[0064] The review process for suspicious activity cases may differ from that for fraud cases because fraud cases typically have a clear conclusion. If a customer is a fraudster, their account will be closed and they will be prevented from making future transactions / activities. If a customer is a victim of fraud, the detected fraud case is unrelated to the customer, and the evidence will not be used against them in the future. Therefore, a fraud investigator typically focuses only on newly detected cases. Conversely, a suspicious activity investigator may need to review a history of detected cases and make a decision after in-depth research and analysis. In one embodiment of the invention, the justification for not reporting a suspicious activity is stored in a database for future reference.
[0065] In another embodiment of the invention, a computer system also records the identity of the person who decides not to report a detected case. The computer system can compare decisions made by multiple individuals not to report suspicious activities of (a number of) the same suspect to determine whether an investigator is attempting to conceal a detected suspect or case.
[0066] For a large enterprise, thousands of suspicious activities can be detected each month. A group of people may be tasked with reviewing detected cases to determine whether the enterprise needs to submit SARs (Special Action Reports) for these cases. In one embodiment of the invention, a computer system automatically assigns detected cases to different individuals based on policies established by the enterprise. The computer system can monitor and record the status of each detected case. If a specific individual delays reviewing a case, the computer system will issue an alert to the enterprise regarding this delay.
[0067] In yet another embodiment of the invention, a computer system monitors the workload of each person reviewing detected cases. If a person has reviewed an unusually large number of cases compared to others who are also reviewing detected cases during the same time period, that person may become suspicious or problematic.
[0068] On the other hand, if someone has reviewed fewer cases compared to others who also reviewed cases during the same time period, that person may also become suspicious or problematic. In either of these two situations, a manager within the company may want to investigate the situation and draw their own conclusions and decisions.
[0069] Different detection functions are typically used to detect suspicious activity because suspicious activity can occur in many different types of activities. Because the detection of suspicious activity is not always clear, some detected cases may not actually be suspicious after investigation. In such cases, these detected cases are rejected as false detections or false affirmations. A false detection or false affirmation is usually referred to as the conclusion of one investigation of a case, rather than as an explanation of why the case was rejected.
[0070] For example, if a financial institution detects a case where several customers living at the same address deposit large sums of cash into the institution, this case might be linked to a potentially drug-dealing family, with many family members depositing their drug profits. However, upon investigation, this case could actually be a group of students living together and depositing tips they received while working at a restaurant. The argument for not reporting this case would be that "the students living together are depositing tips they received from part-time jobs." Therefore, based on the given reason, the conclusion drawn from the detected case becomes a false detection or false affirmation.
[0071] Typically, after reviewing a detected case, the reviewer may classify it as a false detection (or false affirmation). In one embodiment of the invention, a computer system provides a user with information and / or statistics to analyze all detected cases that have been classified as false detections. From these false detections, the user can identify detection functions that have generated several false detections exceeding a threshold. The user can further improve the identified detection functions to improve the detection of future suspicious activities.
[0072] Since 9 / 11, the USA PATRIOT Act, the Bank Secrecy Act (BSA), the Anti-Money Laundering Act (AML), and the Anti-Terrorism Financing Act (ATF) have been crucial compliance matters for the financial industry. Many financial institutions have invested heavily in these compliance matters, yet still miss real money laundering and terrorist financing cases.
[0073] The main reason for these compliance issues is that many financial institutions fail to detect even basic money laundering cases, and senior managers within these institutions often lack understanding of these issues. Many financial institutions use fraud detection principles to detect money laundering activities, and some even confuse fraud cases with money laundering cases.
[0074] However, in reality, money laundering and fraud are quite different. A fraud detection product can easily compare an account holder's current activity with their historical activity, and detect potential fraud if the current activity deviates from the expected activity derived from the historical activity. For example, if a fraudster steals a credit card from a victim, the fraudster will make purchases that differ from the victim's historical activity. The credit card company will detect the fraudulent activity, and it's only a matter of time before the card is deactivated. If a new account does not yet have sufficient historical records, a fraud detection product compares the account holder's current activity with what the account holder said during the account opening process.
[0075] Because the goal of a fraud detection product is to stop losses as quickly as possible, financial institutions typically run fraud detection or risk scoring immediately or at least daily. In contrast, immediate risk scoring, immediate detection, daily risk scoring, and daily detection methods, which are effective for fraud detection, cannot detect many basic money laundering activities. In fact, as explained earlier, a high-risk customer may not be a money launderer. Assuming a high-risk customer is engaged in suspicious money laundering activities is a waste of time.
[0076] A financial institution typically has a Bank Secrecy Officer (BSA) responsible for reporting suspected money laundering or terrorist financing activities to FinCEN. The following case illustrates how a financial institution's BSA officer can waste significant time reviewing immediate or daily risk assessment results and still miss genuine money laundering cases. This case comprises the following facts: (a) Customer A wired less than $3,000 to XYZ around the 5th day of each month; (b) Customer B wired less than $3,000 to XYZ around the 8th day of each month; (c) Customer C wired less than $3,000 to XYZ around the 12th day of each month; (d) Customer D wired less than $3,000 to XYZ around the 17th day of each month; (e) Customer E wired less than $3,000 to XYZ around the 24th day of each month; (f) Customer F wired less than $3,000 to XYZ around the 29th day of each month; (g) A, B, C, D, E, and F are unrelated individuals; and (h) XYZ is a drug dealer in Los Angeles with no prior criminal record.
[0077] In the above example, if a BSA supervisor compares a customer's current activity with their historical activity to detect any behavioral changes, the supervisor will not detect any anomalies because the customer consistently makes similar transactions each month. If a bank teller asks a customer about the purpose of their fund transfer, the customer may be prone to lying. Because such customers conduct similar transactions on different days each month, a BSA supervisor will be unable to detect any risk on any given day of the month.
[0078] Furthermore, these customers are irrelevant, and therefore BSA supervisors will not be able to see their overall activity. Additionally, because each transaction involves only a small amount of US dollars occurring once a month, and the recipients of the funds reside in a densely populated and commercially active U.S. city, these customers will not be considered high-risk or suspicious based on these transactions. Therefore, despite the BSA supervisor's diligent daily work using a fraud detection product, that product will miss these basic money laundering cases.
[0079] To detect such money laundering cases, in one configuration, a computer system collects transaction data from financial institutions and performs data mining based on money laundering and counter-terrorism financing scenarios across all transactions of all customers within a specified time period (such as 30 days or longer). The computer system can collect all fund transfer transaction details from various data sources within a financial institution (such as remittances, ACH, card payments, mobile payments, etc.). The computer system can then identify one of the common recipients of these fund transfer transactions.
[0080] When a co-payee is identified, the computer system displays all transactions to that co-payee to the BSA supervisor. The BSA supervisor reviews the identified transactions through the computer system. The BSA supervisor also reviews all historical cases associated with the suspect in the new detection case. If the BSA supervisor (e.g., a responsible person) agrees that such transactions are suspicious activity because the co-payee received excessive funds, the computer system assists the BSA supervisor in submitting a SAR to FinCEN. If the BSA supervisor decides not to submit a SAR, the BSA supervisor enters a reason into the computer system to justify their decision not to report such detected activity.
[0081] Several methods exist for reporting SAR cases to FinCEN. One method involves sending the SAR report electronically directly to a server located at FinCEN. In this case, a BSA supervisor may instruct the computer system that has detected suspicious activity to submit an SAR report. The computer system prepares the SAR report based on the suspect and transaction identified by the BSA supervisor, and then transmits the SAR report to the computer system at FinCEN.
[0082] As we can understand, even for a very small financial institution, data mining of the vast amount of transaction data accumulated over a long period for all of its customers takes time. Because a financial institution does not directly lose any funds in a money laundering case, according to regulatory guidelines, a BSA officer has a maximum of 30 days to submit a SAR. This example illustrates that conducting immediate or daily risk assessments that actually miss genuine money laundering activities is a waste of time and resources.
[0083] BSA executives are generally frustrated by the fact that they waste time each day on incorrect detections, at the cost of failing to detect actual money laundering cases. This frustration stems from a widespread misconception that money laundering and fraud are often committed by the same criminal and should be detected together based on changes in detectable behavior. After purchasing fraud detection products, some financial institutions attempt to detect both money laundering and fraud cases simultaneously. This has resulted in a significant waste of time, money, and resources. This misconception can be corrected through a proper understanding of one of the complexities of transaction risk.
[0084] Transaction risk is defined as risk directly associated with a transaction. For example, money laundering risk and fraud risk are directly related to a transaction. However, these risks have distinctly different characteristics. Clients who launder money through financial institutions intend to use these institutions as tools to achieve their goals. These money launderers often masquerade as high-quality clients because they need the assistance of financial institutions to complete their schemes. Money launderers are willing to pay additional fees or lose interest on their own funds, and therefore, from the perspective of financial institutions, these money launderers are desirable clients. This is a key reason why financial institutions need to conduct data mining on all transactions to detect money laundering activities hidden behind the scenes.
[0085] In contrast, fraud risk manifests itself in a different way. Fraud perpetrated by a customer is generally categorized into two types: (1) third-party fraud; and (2) counterparty fraud. Third-party fraud is defined as fraud perpetrated by a third party who is neither a financial institution nor a customer. For example, when a fraudster (e.g., a third party) steals a checkbook from a customer, both the financial institution (e.g., the first party) and the customer (e.g., the counterparty) may become victims. In such cases, the transactions conducted by the third-party fraudster are unrelated to the customer. Therefore, it is a waste of time, money, and resources for BSA executives to be misled by an ineffective fraud detection product into assuming a customer has engaged in money laundering simply because they are a victim of fraud perpetrated by a third party (e.g., when a change in behavior exists).
[0086] Counterparty fraud is defined as fraud perpetrated by a client (e.g., the counterparty) who deceives a financial institution (e.g., the first party). Once the client has successfully deceived the financial institution, the client quickly disappears without further money laundering through the financial institution. A fraudster can use financial institution A to launder money stolen from financial institution B. For financial institution B, this is a fraud case. For financial institution A, this is a money laundering case. However, neither financial institution A nor financial institution B can see both the fraud case and the money laundering case occurring with the same client. Clearly, attempting to systematically detect fraud cases daily would inevitably result in numerous errors and miss genuine money laundering cases. Using this method increases the workload of BSA administrators and exposes financial institutions to unnecessary regulatory risks.
[0087] Other risks exist within the third-party fraud category. For example, typical risks under this category include forged checks, credit card fraud, debit card fraud, ATM fraud, and online fraud. Similarly, numerous different risks exist under the counterparty fraud category, such as bounced checks, deposit fraud, and loan fraud. Therefore, a robust transaction risk management system utilizes multiple detection algorithms that intelligently consider the unique characteristics of each type of fraud to successfully detect it.
[0088] Furthermore, as explained above, multiple customers can collude to launder money or finance terrorists by making small transactions to each other on different dates, and daily monitoring misses such cases. This leads to the logical conclusion that using a single method to detect behavioral changes is wasteful of resources and misses genuine cases of money laundering and terrorist financing. In one embodiment of the invention, money laundering and terrorist financing activities are detected using a different detection method that mines data from all transactions accumulated across the entire financial institution over a time period based on a user-defined scenario.
[0089] In one embodiment of the invention, a computer system uses multiple detection methods to monitor transactions and integrates the detection results into a centralized case management platform. This method combines and simplifies money laundering prevention, fraud prevention, and financial crime prevention to improve detection while maintaining a holistic and accurate picture. Therefore, a financial institution can improve compliance with regulatory requirements, mitigate risks, avoid losses, improve productivity, reduce resources used for managing transaction risks, lower costs associated with hardware, databases, and software, reduce IT maintenance workload, and increase overall profitability.
[0090] In one embodiment of the invention, a computer system compares a transaction pattern of a customer (or a group of customers) with known money laundering transaction patterns to detect suspicious money laundering activities. If a match is found, a potential money laundering activity may have been detected.
[0091] For example, many criminals know that if more than $10,000 in cash is deposited into a bank account on the same day, the bank must file a Currency Transaction Report (CTR) with the U.S. government. To avoid filing a CTR, criminals often split a large cash deposit into multiple smaller cash deposits, each occurring on a different date and each less than $10,000. This transaction pattern is known as "structuring" (a known money laundering transaction pattern), and a computer system can detect this type of transaction pattern. Many other types of transaction patterns exist that are considered money laundering transaction patterns. A computer system can be designed to detect each of these known money laundering transaction patterns. Therefore, even without changes in behavior, money laundering activity can be detected based on the transaction patterns of a suspect or several suspects.
[0092] In one embodiment of the invention, the BSA supervisor (or responsible person) investigates detected cases to determine whether they constitute a genuine money laundering case. In another embodiment, the BSA supervisor also reviews all historical cases associated with the suspect(s) in the current detected case. In another embodiment, if the BSA supervisor agrees that such transactions are suspicious activities, the computer system assists the BSA supervisor in submitting a SAR to FinCEN. In yet another embodiment, if the BSA supervisor decides not to submit a SAR, the BSA supervisor enters a reason into the computer system to justify their decision not to report such detected activities.
[0093] In another embodiment of the invention, customers sharing one or more common risk factors (or characteristics) (such as a business type, business model, organizational structure, size, location, products, services, occupation type, position, etc.) are compared to detect suspicious money laundering activities. If a customer's transaction activity (e.g., transaction pattern, transaction volume, transaction frequency, transaction trend, number of transactions, transaction amount, transaction derivatives, etc.) differs from that of other customers, this customer may have engaged in suspicious money laundering activities. In another embodiment of the invention, statistical data (such as mean, variance, standard deviation, etc.) of this group of customers are used to facilitate this comparison. Similarly, if a customer behaves differently from other customers sharing the same set of risk factors (or characteristics), this customer may have engaged in suspicious money laundering activities. Therefore, suspicious money laundering activities can be detected even if no account shows any behavioral changes.
[0094] Sometimes, comparing a group of customers together is not easy. For example, one MSB with 100 branches may have significantly more cash activity than another MSB with only two branches. In one aspect of the invention, to achieve a more efficient comparison, it is useful to compare some derivatives (e.g., ratios of several numbers) instead of the original raw data. For example, a ratio could be "total cash withdrawn from a bank divided by the total number of checks deposited into a bank." In this example, the number of checks deposited can be used to measure the scale of the MSB's check cashing operations. Therefore, based on check cashing activity, the ratio "total cash withdrawn divided by the total number of checks deposited" substantially proportionally adjusts the check cashing operations of an MSB with 100 branches to approximately the same level as those of an MSB with only two branches, allowing them to be compared on a more equitable basis.
[0095] Many other derivatives can be used to achieve a better comparison. Typically, a more effective derivative of a comparison may include "a first interest variable divided by a second variable measuring the size of the enterprise (or operations)". For example, "total ACH transaction amount divided by the total number of deposited checks", "total remittance transaction amount divided by the total number of deposited checks", "total number of prepaid cards issued divided by the total number of deposited checks", "total ACH transaction amount divided by the total number of branch offices", "total remittance transaction amount divided by the total number of branch offices", "total number of prepaid cards issued divided by the total number of branch offices", "total ACH transaction amount divided by the total number of prepaid cards issued", "total remittance transaction amount divided by the total number of prepaid cards issued", etc., are merely some examples of possible derivatives. In one embodiment of the invention, mathematical transformations other than the above ratios produce a derivative.
[0096] In one embodiment of the invention, a computer system compares a derivative of a specific customer with derivatives of a group of customers who share one or more common risk factors (or characteristics) with the same specific customer (e.g., those in the same type of business or profession). If the derivative of the specific customer deviates significantly from the derivatives of the group of customers, the specific customer may have engaged in a suspected money laundering activity. In one embodiment of the invention, statistical analysis of the group of customers (such as mean, variance, standard deviation, etc.) facilitates this comparison.
[0097] In one embodiment of the present invention, a computer system uses a number of different risk factors to determine the money laundering risk of each client of a financial institution. For example, such risk factors may include an industry, customer category, customer business type, customer geographic region, customer country of address, nature of customer business, type of business products, type of business services, business structure, customer occupation, nationality, history (including compliance records, such as the number of currency transaction reports, the number of suspicious activity reports, matching with the OFAC list, matching with the 314(a) list, matching with the list of high-profile political figures, special designations of the compliance program, etc.), type of transactions, account balance, cash inflows, cash outflows, transaction type, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivatives, transaction location, transaction time, transaction country, remitter of a transfer transaction, remitter's location, remitter's country, nature of remitter, recipient of a transfer transaction, recipient's location, recipient's country, nature of recipient, relationship, social status, political prominence, historical transactions, etc. In fact, thousands of risk factors can be considered to determine a client's money laundering risk. For the purposes of this invention, a "risk factor" is also referred to as a "representative element of a risk dimension" or simply a "risk dimension".
[0098] According to the present invention, each attribute of a customer that can affect customer risk is a risk factor. Additionally, each characteristic of a customer that can affect customer risk can be a risk factor. Furthermore, each type of activity of a customer that can affect customer risk is a risk factor. Risk factors can also be affected by other risks, such as a piece of information related to a customer, each type of transaction of a customer, and / or each transaction pattern of a customer. Each risk factor is assigned a risk value.
[0099] In a configuration, different levels of the same type of risk are considered risk factors and assigned a risk score. For example, the level of risk associated with money laundering can be measured using the total amount of cash transactions over a 30-day period. For instance, we can define a total cash transaction amount (or total cash transaction amount) of $0 to $5,000 over a 30-day period as having a risk score of 10; $5,001 to $50,000 as having a risk score of 50; $50,001 to $250,000 as having a risk score of 100; $250,001 to $1,000,000 as having a risk score of 200; $1,000,001 to $10,000,000 as having a risk score of 500; and $10,000,000 and above as having a risk score of 1,000. In this example, a person with a total cash transaction amount of $60,000 over a 30-day period is categorized as "the amount level between $50,001 and $250,000" and has a risk score of 100.
[0100] "Cash transaction amount" is used as an example only. Other considerations (such as the frequency of cash transactions, the speed of cash transactions, etc.) can also be used to measure the level of risk associated with money laundering. In addition to cash, other financial transactions (such as checks, remittances, ATMs, ACH, virtual currencies, virtual securities, virtual instruments, credit cards, debit cards, prepaid cards, money instruments, transfers, etc.) can also be used to measure the level of risk associated with money laundering. Based on the above examples, those familiar with this technology can easily understand the many risk factors.
[0101] In one embodiment of the invention, a risk-score-based scenario is based on customer data. Each piece of information about the customer is a risk factor and is assigned a risk score. Alternatively, a risk-score-based scenario is based on transaction data. Each amount level (or amount) of a transaction type is a risk factor and is assigned a risk score.
[0102] In one embodiment of the present invention, customer information is associated with one or more of the following: the customer's industry category, the customer's business type, the customer's geographical region, the country of the customer's address, the nature of the customer's business, the product type of the business, the service type of the business, the business structure, the customer's occupation, the customer's nationality, a history, a type of transaction performed, an account balance, cash inflows, cash outflows, a transaction pattern, a number of transactions, a transaction amount, a transaction volume, a transaction frequency, a transaction derivative, a transaction location, a transaction time, a transaction country, and a transfer transaction. Remitter, location of the remitter, country of the remitter, nature of the remitter, recipient of a transfer transaction, location of the recipient, country of the recipient, nature of the recipient, relationship, social status, political prominence, transaction history, number of Suspicious Activity Reports (SARs) filed in connection with money laundering and terrorist financing cases, type of primary financial institution, business type of primary financial institution, geographic region of primary financial institution, country of headquarters of primary financial institution, nature of the business of primary financial institution, age of a person, gender of a person, income level of a person, appearance of a person, judgments about the person, and a person's identity. Status, Family Status, Family Members, Status of Family Members, Friends, Status of Friends, Historical Record, Industry Category, Geographic Region, Country of Residence, Occupation, Job Type, Education Level, Income Level, Length of Employment in Current Job, Performance Appraisal Record, Employment History, Duration of Each Employment in the Employment History, Reason for Termination of Each Employment in the Employment History, Age, Gender, Personal Status, Family Status, and other relevant information. A family member, the status of one of the employee's family members, the status of one of the employee's friends, the employee's historical record, the type of work performed, the number of transactions performed, the amount of one transaction performed, the maximum amount of one transaction, the number of transactions with a specific counterparty, the amount of one transaction with a specific counterparty, the number of changes to a key record, the number of changes to a key record associated with a specific counterparty, the geographical area of the employee's residence, the geographical area of the employee's office, the country of the employee's address, the results of due diligence on the client, the length of an account history, the number of transactions that match the name of a gambling organization, or a combination thereof.
[0103] In one embodiment of the present invention, transaction data is associated with one or more of the following: cash, checks, wire transfers, ATMs (automatic teller machines), ACH (automatic clearinghouses), virtual currencies, virtual securities, virtual instruments, credit cards, debit cards, prepaid cards, electronic funds transfers, remittances, monetary instruments, letters of credit, bills, securities, commercial drafts, commodities, precious metals, account opening, account closing, account application, deposits, withdrawals, cancellations, balance checks, inquiries, crediting, debiting, or combinations thereof.
[0104] In one embodiment of the invention, each risk factor is assigned a risk score, and a customer is assigned a total risk score, which is the sum of all risk scores of the risk factors associated with that customer. This process of generating a total risk score for each customer can be referred to as risk scoring. This total risk score is used to determine the risk level associated with the customer. A sum is used as one example in this invention. In fact, many different types of mathematical transformations can also be used to achieve a similar effect.
[0105] In one embodiment of the invention, each risk factor is assigned a risk score and a customer is assigned a total risk score, which is a value derived from a mathematical transformation of all the risk scores of the risk factors associated with the customer.
[0106] As explained earlier, unlike a fraud case, a high-risk customer may not be a suspect in money laundering or terrorist financing. High risk may simply be a characteristic of the customer. For example, for money laundering and terrorist financing purposes, MSBs, pawnshops, car dealerships, pilots, and flight attendants are often classified as high-risk customers; however, this does not necessarily mean that these customers are engaged in money laundering or terrorist financing.
[0107] However, because a customer has a high risk score, that customer can be closely monitored and different monitoring methods can be applied. Therefore, in one embodiment of the invention, the customer's total risk score is used to determine the monitoring method to be applied. If a customer's total risk score is high, a more intensive monitoring method is applied. If a customer's total risk score is low, a more lenient monitoring method can be applied.
[0108] In other words, in one embodiment of the invention, a customer's overall risk score is not used to determine whether a customer is suspicious. Instead, a customer's overall risk score is used to select an algorithm or a set of algorithms to monitor the customer.
[0109] Sometimes, a customer with a very high risk score may be suspicious. Therefore, in one embodiment of the invention, if a customer's total risk score exceeds a predefined value, an alert for that customer will be triggered, allowing investigators to investigate potential cases. The predefined value can be set by a software module, a system designer, a system tuner, a system user, or a combination thereof.
[0110] In one embodiment of the invention, customers with the same risk factors are compared together. For example, we can compare all customers who are flight attendants. In one embodiment of the invention, if a particular flight attendant's total risk score is significantly higher than a reference value derived from the total risk scores of all flight attendants, then this particular flight attendant may have engaged in some suspicious money laundering activities. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0111] Statistical methods can also be applied to facilitate the detection of suspicious activity. For example, the mean, variance, and standard deviation can be derived from the total risk score of all customers who are flight attendants. In one embodiment of the invention, if the total risk score of a particular flight attendant is more than four times the standard deviation of the mean of the total risk scores of all flight attendants, then this particular flight attendant may have engaged in suspicious activity.
[0112] The above reference of "4 times" is merely one example. The number "4" can be any number, such as 3.75, 4.21, 10, etc. In one embodiment of the invention, if the total risk score of a particular flight attendant is more than x times the standard deviation of the mean of the total risk scores of all flight attendants, then this particular flight attendant may have engaged in suspicious money laundering activities, where x is a number assigned by the BSA supervisor (or a responsible person). This statistical method can be applied whenever a group comparison is used.
[0113] A flight attendant is merely one example illustrating this method for detecting suspicious money laundering activity within a group of entities. In practice, numerous other risk factors can be used for similar purposes. Because there are thousands of risk factors, in one embodiment of the invention, a computer system allows a user to select any risk factor to identify all customers with the same risk factor. In one embodiment of the invention, if a particular customer has a total risk score significantly higher than a reference value derived from the total risk scores of other customers with the same risk factor, then that particular customer may have engaged in suspicious money laundering activity. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0114] Instead of a single risk factor, a group of risk factors can be used. In fact, a group of risk factors can improve the accuracy of detection results. For example, in addition to the risk factor of occupation (e.g., flight attendant), the destination country of the flights that flight attendants work on can also be a useful risk factor for detecting money laundering risks. For example, a flight attendant working on a flight between New York and Chicago may have activities different from those of another flight attendant working on a flight between Miami and Mexico City. Comparing a subgroup of flight attendants working on flights between Miami and Mexico City may be more accurate. In this example, two risk factors (occupation and destination city of the flights) are considered to improve the accuracy of detection.
[0115] In one embodiment of the invention, a set of risk factors is used to identify a group of entities. If a particular entity has a total risk score significantly higher than a reference value derived from the total risk scores of all entities with the same set of risk factors, then that particular entity may have engaged in suspicious money laundering activities. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) that can be easily calculated using existing software development tools can be derived to facilitate this comparison among a group of entities. Therefore, even if there is no behavioral change in any account, a computer system can still detect suspicious money laundering activities based on the above method.
[0116] Sometimes, it can be helpful to exclude certain entities from a group comparison because these entities are distinct from the others. In one embodiment of the invention, a computer system allows a user to select entities that will not be included in a group comparison process.
[0117] Detecting a flight attendant's suspected money laundering activity is just one example. A similar method can be applied to many other different situations. For instance, banks or credit unions often find it very difficult to detect suspicious money laundering or terrorist financing activities by a money services business (MSB) client because an MSB handles numerous transactions daily, and a single money laundering transaction can be hidden among many other normal transactions.
[0118] In one embodiment of the invention, an additional risk factor (e.g., near the Mexican border) is used to identify MSBs (e.g., other than the first risk factor (business type)) that share this same risk factor. If a particular MSB has a total risk score higher than a reference value derived from the total risk scores of all MSBs sharing the same risk factor, then that MSB may have been involved in suspicious money laundering activities. Reference values include a mean, a median, a mode, a weighted average, and / or other statistical values. Similarly, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate this comparison within a group of MSBs.
[0119] Sometimes, comparing a group of MSBs is not easy because they may have different operating types and sizes. In one embodiment of the invention, a part-time MSB and a full-time MSB are assigned two different risk factors because they may have different business natures. In another embodiment of the invention, each of different types of MSB products and / or services is assigned a risk factor. For example, transfers, check cashing, currency exchange, prepaid card management, etc., are each assigned a risk factor, even though they may all be provided by the same MSB. In one embodiment of the invention, a set of risk factors that precisely define the type of product and / or service is used to identify risk.
[0120] In one embodiment of the invention, adjusting certain risk factors based on the scale of operations makes group comparisons more effective. For example, one MSB with 50 branches can naturally have five times the total cash transaction amount of another MSB with 10 branches. Sometimes, for group comparisons, risk factors affected by the scale of operations can be adjusted to take into account the scale of operations. For example, for one MSB with 50 branches, its total cash transaction amount over 30 days can be divided by 50 to establish an adjusted risk factor and a risk score for group comparisons. Branches are used here as an example to measure the scale of operations. Other information (such as the number of customers, the number of transactions, the number of employees, the size of assets, etc.) can also be used to measure the scale of operations.
[0121] In one embodiment of the invention, a set of risk factors adjusted for operational scale (e.g., adjusted risk factors) is used to identify entities belonging to a group with this set of adjusted risk factors. The risk score of an adjusted risk factor is referred to as the adjusted risk score. If a particular entity has a total adjusted risk score significantly higher than a reference value derived from the total adjusted risk scores of all entities with the same set of adjusted risk factors, then that particular entity may have been engaged in suspicious money laundering activities. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Typically, in one embodiment of the invention, the detection algorithm that incorporates a risk factor into a detection algorithm can also be modified to incorporate an adjusted risk factor into the detection algorithm. Similarly, the detection algorithm that incorporates a risk score into a detection algorithm can also be modified to incorporate an adjusted risk score into the detection algorithm.
[0122] To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) based on adjusted risk factors and adjusted risk scores can be derived to facilitate comparisons within a group of entities. Therefore, even if behavioral changes occur in any account, a computer system can still detect suspicious money laundering activities using the above methods.
[0123] Because MSBs can have transaction activities different from other types of businesses, monitoring MSBs based on their unique transaction activities is more effective. Therefore, in one embodiment of the invention, a different set of detection algorithms can be used to monitor entities with a different set of risk factors. In one embodiment of the invention, a set of risk factors is used to identify a group of entities possessing this set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activities within this group of entities. In other words, a set of detection algorithms is selected to monitor the group of entities based on a set of risk factors associated with it.
[0124] In another embodiment of the invention, a set of risk factors is adjusted based on the scale of operations and used to identify a group of entities sharing this set of adjusted risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activities within this group of entities. In other words, a set of detection algorithms is selected to monitor the group of entities based on a set of adjusted risk factors associated with it.
[0125] Sometimes, it is meaningful to monitor higher-risk entities more closely than those with lower risks. Therefore, different sets of detection algorithms are used to monitor different entities with different risk levels. In one embodiment of the invention, a set of detection algorithms is selected to monitor an entity based on its total risk score. In another embodiment, a set of detection algorithms is selected to monitor an entity based on its total adjusted risk score, wherein the total adjusted risk score is obtained from the risk score of the adjusted risk factor.
[0126] In one embodiment of the invention, once a potential money laundering activity is detected in an MSB (Money Management Business), a computer system can identify transactions (or a group of transactions) that cause the detected MSB to have a total risk score higher than a reference value derived from the total risk score of all MSBs. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0127] Similarly, once potential money laundering activity is detected in an MSB, a computer system identifies transactions (or groups of transactions) that cause the detected MSB to have a total adjusted risk score higher than a reference value derived from the total adjusted risk score of all MSBs. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Therefore, a money laundering transaction (or a group of money laundering transactions) can be identified using this method. This method of identifying a specific transaction (or group of transactions) with a higher risk score (or a higher adjusted risk score) can be applied to other types of clients, not just MSBs.
[0128] It is commonly known that a higher risk score implies a higher risk. However, there is no rule prohibiting an individual or enterprise from defining a lower risk score for a higher risk. To avoid confusion, the description in this invention is based on the convention that a higher risk score means a higher risk. Furthermore, a risk score can be negative. A negative risk score implies a reduced risk based on this convention.
[0129] As described above, an MSB is merely one example. Other types of businesses (such as pawnshops, car dealerships, etc.) can be monitored in a similar manner. Therefore, even if there is no behavioral change in any account, risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, and total adjusted risk scores can still be used in a variety of methods to detect suspicious money laundering activities.
[0130] In fact, a government or non-governmental organization (such as the OCC, FDIC, FRB, NCUA, FinCEN, SEC, FINRA, etc.) can monitor financial institutions (such as banks, credit unions, insurance companies, securities brokers, etc.) using methods similar to those described above for monitoring MSBs. Different risk factors, risk scores, adjusted risk factors, and adjusted risk scores can be defined for this monitoring purpose.
[0131] In one embodiment of the invention, a computer system uses a number of different risk factors to determine whether a financial institution complies with regulatory requirements to submit SARs to report money laundering and terrorist financing cases. For example, these risk factors may include one number of SARs submitted for the following: money laundering and terrorist financing cases, type of financial institution, type of business of financial institution, geographic region of financial institution, country of headquarters of financial institution, nature of business of financial institution, type of products of business, type of services of business, business structure, customer profile of financial institution, historical records, type of transactions conducted, inflows of funds, outflows of funds, transaction patterns, number of transactions, transaction amounts, transaction volumes, transaction frequency, transaction derivatives, location of transactions, time of transactions, country of transactions, remitter of transfer transactions, location of remitter, country of remitter, nature of remitter, recipient of transfer transactions, location of recipient, country of recipient, nature of recipient, relationship, social status of customer, political prominence of customer, political prominence of remitter, political prominence of recipient, historical transactions, etc. In fact, thousands of risk factors can be considered to determine a financial institution's compliance risk.
[0132] In one embodiment of the invention, the number of branch offices is used to adjust the risk factor and risk score. In another embodiment, asset size is used to adjust the risk factor and risk score. Many other factors can also be used to adjust the risk factor and risk score. In this current example, the "number of SARs submitted" risk factor can have a negative value because the more SARs a financial institution submits, the less likely it is to fail to submit SARs.
[0133] In one embodiment of the invention, a set of risk factors is adjusted based on the size of operations and used to identify a group of banks with this set of adjusted risk factors. If a particular bank has a total adjusted risk score significantly higher than a reference value for the total adjusted risk score of all banks with the same set of adjusted risk factors, that particular bank may have failed to fulfill its legal obligation to detect and report suspected money laundering and / or terrorist financing activities. Reference values include a mean, a median, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate this comparison among entities within a group.
[0134] Furthermore, different detection algorithms can be used to monitor different banks with different sets of risk factors. In one embodiment of the invention, a set of risk factors is used to identify a group of banks possessing this set of risk factors, and a specific set of detection algorithms is used to detect potential oversight of this group of banks regarding compliance matters. Therefore, in one embodiment of the invention, a set of detection algorithms is selected to monitor the group of banks based on a set of risk factors associated with it.
[0135] In another embodiment of the invention, a set of risk factors is adjusted based on the scale of operations and used to identify a group of banks with this set of adjusted risk factors, and a specific set of detection algorithms is used to detect potential oversight of this group of banks regarding compliance matters. In other words, a set of detection algorithms is selected to monitor the group of banks based on a set of adjusted risk factors associated with it.
[0136] Although banks are used in the examples above, the same set of methods can be used to monitor credit unions, securities brokers, insurance companies, other financial institutions, and other types of businesses. Furthermore, the scope of monitoring is not limited to compliance with anti-money laundering and anti-terrorism financing measures. In fact, all types of businesses and all types of matters can be monitored by the methods described in this invention by appropriately defining risk factors, risk scores, adjusted risk factors, adjusted risk scores, and detection algorithms associated with such matters.
[0137] Money laundering companies (MSBs) also face pressure to comply with numerous laws and regulations. However, unlike banks or credit unions, MSBs do not truly know who their customers are. A typical MSB provides money services to any customer who walks into its office. Even if an MSB collects identification information from all its customers, it may still fail to correctly identify money laundering activities. For example, a customer might use their Mexican passport in the morning to make a $7,000 transfer by paying cash to an MSB, and then use their California driver's license in the afternoon to make another $8,000 transfer by paying cash to the same MSB. Because two identification documents are used, the same customer can be considered two different people. The MSB may fail to file a money transaction report as required by law because the same customer has provided more than $10,000 in cash. This situation becomes even more complicated if the MSB has multiple branches, as the same customer can walk into different branches to conduct transactions based on different identification documents.
[0138] In one embodiment of the invention, a computer system compares the names, phone numbers, addresses, dates of birth, etc., of all consumers transacting with an MSB to identify all transactions that can be performed by the same consumer. After identifying all transactions associated with a consumer, the computer system can detect suspicious money laundering activities associated with the consumer based on the transactions associated with the consumer.
[0139] In one embodiment of the invention, a BSA supervisor (e.g., one of the investigators) investigates a detected case to determine whether it is a genuine money laundering case. The BSA supervisor also reviews all historical cases associated with the consumer in the newly detected case. If the BSA supervisor agrees that the detected case is a suspected money laundering case, the computer system assists the BSA supervisor in submitting a SAR to FinCEN. If the BSA supervisor decides not to submit a SAR, the BSA supervisor enters a reason into the computer system to justify their decision not to report the detected case.
[0140] Sometimes, a bank receives a wire transfer from one customer of bank A and then re-transfers it to another customer of bank B. This is because bank A and bank B do not have a direct banking relationship. This situation often occurs in international wire transfers, as banks in two different countries may not have a direct banking relationship. This type of wire transfer is usually called an intermediary wire transfer.
[0141] Banks providing intermediary wire transfer services are exposed to a very high money laundering risk because the remitters and recipients of these transfers are not necessarily the bank's clients. Furthermore, the bank may not know the true background of the remitters and recipients. One remitter could be a terrorist financier, and one recipient could be a terrorist. Banks handling intermediary wire transfer services may unknowingly become conduits for money laundering and terrorist financing.
[0142] In one configuration of this invention, a computer system compares the names, addresses, countries, telephone numbers, email addresses, etc., of all remitters and recipients in an intermediary wire transfer and identifies transactions associated with each remitter and recipient. In another embodiment of this invention, if the computer system detects an unusually large amount of wire transfer from the same remitter, the remitter and recipient may be involved in money laundering or terrorist financing activities.
[0143] Similarly, if a computer system detects an unusually large amount of wire transfers to the same recipient, both the sender and recipient may be involved in money laundering or terrorist financing activities.
[0144] If a computer system detects an unusual number of wire transfers from the same remitter to the same recipient, both the remitter and the recipient may be involved in money laundering or terrorist financing activities. If a computer system detects an unusually large total amount of wire transfers from the same remitter to the same recipient, both the remitter and the recipient may be involved in money laundering or terrorist financing activities.
[0145] In one embodiment of the invention, a BSA supervisor investigates a detected case to determine whether it is a genuine money laundering case. The BSA supervisor also reviews all historical cases associated with the suspect in the newly detected case. If the BSA supervisor agrees that there is suspicious money laundering activity, the computer system assists the BSA supervisor in submitting a SAR to FinCEN. If the BSA supervisor decides not to submit a SAR, the BSA supervisor enters a reason into the computer system to justify its decision not to report such detected activity.
[0146] With a large proportion of the population rapidly aging, some states have recently enacted Elder Abuse Reporting Acts (EARAs) to protect seniors who are unable to protect themselves. An elderly person may frequently give money to a criminal because they have been cheated. Therefore, financial institutions are training frontline staff to observe and report what they perceive as potential cases of elder abuse. However, this human-based approach is ineffective because transactions can be executed remotely and criminals can cleverly conceal their activities. Furthermore, human workers are prone to error and mistakes. Relying on human workers to detect and report elder abuse cases is ineffective.
[0147] For many businesses, the birth date information of their customers is stored in a database. In one embodiment of the invention, a computer system collects birth date information and identifies elderly people who are older than a predefined age. The computer system monitors all transactions of these elderly people and detects any changes in their activities.
[0148] For example, if an unusually large amount of money is transferred from an elderly person's account, the financial institution may want to investigate the purpose of the transfer. In one embodiment of the invention, if a check with an unusually large amount is deposited into an elderly person's account, the financial institution may want to investigate whether a counterfeit check was given to the elderly person in exchange for real cash or assets. If an elderly person's account exhibits an unusual transaction pattern (e.g., unusual frequency or volume), the financial institution may want to investigate (several) transactions. If an elderly person's account balance decreases rapidly, the financial institution may want to investigate transactions associated with that account.
[0149] In one embodiment of this invention, risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, total adjusted risk scores, statistical methods, and the detection algorithm described above can be used to detect potential cases of elder abuse. Because elder abuse is different from money laundering, a different set of risk factors and risk scores can be used for elder abuse detection. For example, such risk factors may include a person's age, gender, income level, appearance, judgments about the person, personal circumstances, family situation, family members, family member circumstances, friends, friend circumstances, historical records, industry, geographical region, country of residence, occupation, nationality, type of transactions, account balance, cash inflows, cash outflows, transaction type, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivatives, transaction location, transaction time, transaction country, remitter of a transfer transaction, remitter's location, remitter's country, nature of the remitter, recipient of a transfer transaction, recipient's location, recipient's country, nature of the recipient, relationship, social status, political prominence, and historical transactions. In fact, many different risk factors can be considered to determine a person's risk of elder abuse.
[0150] For example, in one embodiment of the invention, a risk factor is used to identify elderly people in a group sharing the same risk factor. If a particular elderly person has a total risk score higher than a reference value derived from the total risk score of all elderly people sharing the same risk factor, that particular elderly person may be a potential victim of elder abuse. The reference value includes a mean, a median, a mode, a weighted average, and / or other statistical values. In another embodiment of the invention, a set of risk factors is used to identify elderly people in a group sharing this set of risk factors. If a particular elderly person has a total risk score higher than a reference value derived from the total risk score of all elderly people sharing the same set of risk factors, that particular elderly person may be a potential victim of elder abuse. The reference values include a mean, a median, a mode, a weighted average, and / or other statistical values.
[0151] To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons within a group of entities. Therefore, even if no behavioral changes are observed in an account, a computer system can still detect a potential case of elder abuse based on the above methods.
[0152] Typically, a company may have a compliance officer responsible for all legal compliance matters. In one embodiment of the invention, an investigator (e.g., a compliance officer) investigates detected cases to determine whether an actual case of elder abuse has occurred. The compliance officer also reviews all historical cases associated with the elderly person in the newly detected case. If the compliance officer agrees that the case is a possible case of elder abuse, the computer system assists the compliance officer in reporting the detected case. If the compliance officer decides not to report the detected case, the compliance officer enters a reason into the computer system to justify their decision not to report the detected case.
[0153] Under the Sabine Act (SOX), certain companies (e.g., publicly traded companies) are required to implement internal control oversight to prevent fraud committed by employees. Traditionally, this internal control oversight has been performed by human workers (e.g., auditors) who spend several months each year auditing a company's financial records. This human-based approach is ineffective because human workers are prone to error and mistakes. Furthermore, because auditing financial records is time-consuming, preventing a crime may be too late.
[0154] In one embodiment of the invention, a computer system monitors accounting general ledger items and detects any anomalies (e.g., abnormal frequency, transaction volume, acceleration, etc.) related to the general ledger items to identify suspicious insider fraud activities. For example, if the travel expense general ledger item suddenly increases by 500% this month compared to the past 12 months, some employees may have abused their privileges and caused abnormal expenses.
[0155] In one embodiment of the invention, a computer system compares the current value of a general ledger item with a reference value derived from historical values of the same general ledger item over the past x months, where the value x is predefined. If the current value is significantly larger than the reference value, some employees may have committed fraud. The reference includes a mean, a median, a mode, a weighted average, and / or other statistical values. Further investigation can be conducted to determine why the general ledger item value deviates from its historical value.
[0156] In another embodiment of the invention, a computer system compares an employee's current activities with their historical activities to detect any changes. For example, if a loan officer has been issuing loans in unusually large amounts each month compared to historical monthly amounts, the loan officer's activities may be suspicious. If a loan officer has been issuing loans with an unusually large total amount compared to historical monthly amounts, the loan officer's activities may be suspicious.
[0157] Typically, an activity can be measured using a value known as an activity value. For example, a loan officer's activity can be measured by: the number of loans issued, the maximum loan amount, the total loan amount, the average loan amount per transaction, the number of loans to the same customer, the number of changes to loan records, the number of changes to loan records for the same customer, the frequency of loan record changes, the frequency of loan record changes for the same customer, and the type of loan. A bank teller's activity can be measured by: the total number of transactions, the total transaction amount, the maximum transaction amount, the average transaction amount per transaction, the type of transaction, the number of customers transacting with the teller, the average number of transactions per customer, the number of transactions with the same customer, the number of changes to customer records, the number of changes to customer records for the same customer, the frequency of customer record changes, and the frequency of customer record changes for the same customer. In one embodiment of the invention, a computer system compares the current value of an activity with a reference value derived from historical values of the same activity. When the current value is significantly larger than the reference value, the person performing the activity may have committed fraud. Further investigation may be conducted to determine whether the person has indeed committed fraud. Reference values include a mean, a median, a standard mean, a mode, a weighted average, and / or other statistical values.
[0158] In one embodiment of the invention, a computer system compares the activities of an employee with those of other employees who have the same role in the business. For example, if a teller (or loan officer, etc.) behaves very differently from other tellers (or loan officers, etc.) in the same branch, this teller (or loan officer, etc.) may have engaged in some suspicious activities.
[0159] In one embodiment of the invention, a computer system compares an activity value of a specific employee with a reference value derived from the activity values of all employees with the same responsibilities as that specific employee for the same activity. When the activity value of a specific employee deviates significantly from the reference value, the specific employee may have committed fraud. Further investigation can be conducted to determine whether the employee has indeed committed fraud. The reference value includes a mean, a median, a mode, a weighted average, and / or other statistical values.
[0160] When comparing an employee to a group of employees, the statistical methods used in the flight attendant example described above can be applied. For example, a comprehensive group of risk factors associated with an employee can be identified, and a risk score can be assigned to each risk factor. Thus, each employee has a total risk score obtained from a mathematical transformation (e.g., summation) of all the risk scores associated with that employee.
[0161] The set of risk factors used to detect fraud associated with employees may differ from the set of risk factors used to detect other types of suspicious activity (such as money laundering). For example, risk factors used to detect employee fraud may include: the employee's job type, education level, income level, length of employment in the current job, performance evaluation records, employment history, duration of each employment in the employment history, reason for termination of each employment in the employment history, employee's age, employee's gender, employee's personal circumstances, employee's family situation, employee's family members, the situation of employee's family members, the situation of employee's friends, employee's historical records, type of work performed, number of transactions performed, amount of transactions performed, maximum transaction amount, number of transactions with a specific counterparty, and amount of transactions with a specific counterparty. The factors considered include the number of changes to key records, the number of changes to key records associated with a specific counterparty, the geographical area of the employee's residence, the geographical area of the employee's office, the employee's country of residence, nationality, type of transactions, account balance, cash inflows, cash outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, transaction frequency, transaction derivatives, transaction location, transaction time, transaction country, the remitter of a transfer transaction, the remitter's location, the remitter's country, the nature of the remitter, the recipient of a transfer transaction, the recipient's location, the recipient's country, the nature of the recipient, relationship, social status, political prominence, and historical transactions. In fact, numerous risk factors can be considered to determine the risk of employee fraud. In one embodiment of this invention, different sets of risk factors can be used to detect different types of suspicious activity.
[0162] In one embodiment of the invention, when the total risk score of a particular employee is significantly higher than the mean of the total risk scores of all employees with the same risk factors as that employee, this particular employee may have engaged in suspicious activity. The significant margin can be set for several standard deviations or other reference values.
[0163] Instead of a single risk factor, multiple risk factors can be used to improve the accuracy of detection results. In one embodiment of the invention, if the total risk score of a particular employee is significantly higher than the mean of the total risk scores of all employees with the same set of risk factors as that employee, then that particular employee may be engaging in suspicious activities. In one instance, a significant margin is set for several standard deviations or other reference values.
[0164] In fact, by identifying risk factors associated with a group of entities and appropriately assigning a risk score to each risk factor, a statistical method for identifying a suspicious activity of a particular entity based on the total risk score of each entity can be applied to many other situations besides money laundering, terrorist financing, and employee fraud.
[0165] In one embodiment of the invention, a plurality of risk factors are associated with a group of entities. Each risk factor may be assigned a risk score. Each entity may be assigned a total risk score based on a mathematical transformation (such as a summation). For example, other possible mathematical transformations include, but are not limited to, multiplication, division and subtraction, summation of squares, summation of squares, a combination of the above mathematical transformations, and other similar ways of combining risk scores.
[0166] In one embodiment of the invention, when the total risk score of a particular entity is higher than the mean of the total risk scores of all entities with the same risk factor as the particular entity by a predefined margin, this particular entity may have engaged in some suspicious activities. The predefined margin can be set for several standard deviations or other reference values.
[0167] In another embodiment of the invention, if the total risk score of a particular entity is higher than the mean of the total risk scores of all entities having the same set of risk factors as the particular entity by a predefined margin, then the particular entity may have engaged in some suspicious activities.
[0168] In one embodiment of the invention, a computer system identifies a transaction (or a group of transactions) that has resulted in a specific entity having a total risk score higher than the average of the total risk scores of all entities. This transaction (or group of transactions) may be a suspicious activity.
[0169] The statistical methods mentioned are merely one way to manage risk. Many other group comparison methods can also be used. Furthermore, suspicious activity may not be limited to illegal or prohibited activities. An activity becomes suspicious because it differs from normal activity. It may be harmless or even an activity with good intentions. Therefore, an investigation is usually required to make the final decision on whether to report a detected case.
[0170] In one embodiment of the invention, a responsible person investigates a new detected case to determine its illegality. The responsible person also reviews all historical cases associated with the suspect(s) in the new detected case. When the responsible person agrees that the detected case is illegal, the computer system assists the responsible person in reporting the detected case. When the responsible person decides not to report the detected case, the responsible person enters a reason into the computer system to justify their decision not to report the detected case.
[0171] Following the 9 / 11 tragedy, the U.S. Congress passed the Unlawful Internet Gambling Enforcement Act (UIGEA) because online gambling could be used as a tool for money laundering and terrorist financing. Regulation GG was enacted in response to the Unlawful Internet Gambling Enforcement Act. According to Regulation GG, a financial institution is required to inquire with a new customer during the account opening process whether they intend to engage in any online gambling activities. Because criminals know that online gambling is illegal, they will lie during the account opening process. Therefore, the "inquiry" method defined in Regulation GG is merely a formality. However, Regulation GG explicitly states that it does not amend the obligation of a financial institution to submit a Special Statement (SAR) under the Bank Secrecy Act.
[0172] In other words, if a criminal lies during the account opening process and actually engages in an illegal online gambling operation, the financial institution is obligated to report the case to FinCEN via a SAR. In one embodiment of the invention, a computer system compares the remitters and recipients of all fund transfer transactions over a time period. If a customer has remitted a large amount of funds to a recipient and also received a large amount of funds from the same recipient during a time period, these transactions may be deposits of betting funds and payments earned from gambling activities between an online gambler and an online gambling organization. The computer system detects these cases as potential illegal online gambling cases. Once a case is detected, further investigation is required.
[0173] In one embodiment of the invention, when a computer system detects a large volume of transactions involving large sums of US dollars associated with a customer, the computer system identifies the customer as a potential online gambling organization. This is because an online gambling organization typically handles large sums of money and a large number of customers. The computer system identifies this case as a potential case of illegal online gambling. Once a case is detected, further investigation is required.
[0174] In one embodiment of the invention, a computer system compares a list of known names of online gambling organizations with the remitters and recipients of funds transfer transactions associated with a customer. If a match is found, the customer may be involved in online gambling activities. The computer system detects this case as a possible case of illegal online gambling. Once a case is detected, further investigation is required.
[0175] In addition to the transaction pattern monitoring mentioned above, the group comparison method described above can also be applied to detect potential illegal online gambling activities. In one aspect of this invention, all risk factors related to online gambling are identified. For example, such risk factors may include the client's due diligence results, account history length, client's industry category, client's business type, number of transactions matching the gambling organization's name, client's geographic region, client's headquarters country, nature of client's business, business product type, business service type, business structure, client's occupation, nationality, historical records, type of transactions conducted, account balance, fund inflows, fund outflows, transaction patterns, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivatives, number of chargebacks, transaction location, transaction time, transaction country, remitter of a transfer transaction, remitter's location, remitter's country, remitter's nature, recipient of a transfer transaction, recipient's location, recipient's country, recipient's nature, relationship, social status, political prominence, historical transactions, etc. In fact, many different risk factors can be considered to determine online gambling risk. As previously explained in this invention, adjusted risk factors can also be used, allowing adjusted risk scores to be applied based on the scale of the operation.
[0176] In one embodiment of the invention, a risk factor is used to identify customers in a group sharing the same risk factor. A particular customer may be involved in illegal online gambling if they have a total risk score higher than a reference value derived from the total risk scores of all customers sharing the same risk factor. In another embodiment of the invention, a set of risk factors is used to identify customers in a group sharing this set of risk factors. If a particular customer has a total risk score higher than a reference value derived from the total risk scores of all customers sharing the same set of risk factors, that particular customer may be involved in illegal online gambling. Reference values include a mean, a median, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons within a group of customers.
[0177] In one embodiment of the invention, a responsible person (or BSA supervisor) investigates a detected case to determine whether it is a genuine online gambling case. The BSA supervisor also reviews all historical cases associated with the suspect in the newly detected case. When the BSA supervisor agrees that a detected case is a possible illegal online gambling case, the computer system assists the BSA supervisor in submitting a SAR to FinCEN. When the BSA supervisor decides not to submit a SAR, the BSA supervisor enters a reason into the computer system to justify their decision not to report the detected case.
[0178] The U.S. Congress has passed the Fair and Correct Credit Transactions Act (FACT Act) to protect consumers. Specifically, it is expected that businesses will identify and report cases of identity theft. Financial institutions are also expected to file a SAR (Status Reporting Notice) upon detecting a case of identity theft.
[0179] In one embodiment of the invention, a computer system monitors consumer reports and other available information to detect fraud or activity alerts, credit freeze notifications, and / or address discrepancy notifications contained in a consumer report. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0180] In one embodiment of the invention, a computer system monitors consumer reports and available information to detect consumer reports indicating an activity pattern inconsistent with the historical and routine patterns of an applicant or customer's activities. For example, a recent and significant increase in inquiries, an unusual number of recently established credit relationships, significant changes in credit usage (especially regarding recently established credit relationships), or the closure of an account for some reason or identification of abuse of account privileges by a financial institution or creditor can indicate an unusual pattern. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0181] In one embodiment of the invention, a computer system detects whether a document provided for identification appears to have been altered or forged. If a suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0182] In one embodiment of the invention, a computer system detects whether a photograph or description of an entity being identified does not match the appearance of the applicant or customer presented for identification. If a suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0183] In one embodiment of the invention, a computer system detects whether other information regarding the identification is inconsistent with information provided by the person opening a new account or presenting the identification. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0184] In one embodiment of the invention, a computer system detects whether other information regarding identification is inconsistent with easily accessible information (such as a signature card or a recent check) archived by a financial institution or creditor. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0185] In one embodiment of the invention, a computer system detects whether an application appears to have been altered or forged, or whether it has been given a corrupted and reassembled appearance. If a suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0186] In one embodiment of the invention, a computer system determines whether the provided personally identifiable information is inconsistent with external information used by financial institutions or creditors. For example, the address may not match any address in a consumer report, or the Social Security Number (SSN) may not have been issued, or it may be listed in the Social Security Administration's Death Master File. If a suspicious activity case is detected, the computer system makes the detected case available for review by an official.
[0187] In one embodiment of the invention, a computer system determines whether some personally identifiable information provided by a customer is inconsistent with other personally identifiable information provided by the customer. For example, there may be a lack of correlation between SSN range and date of birth. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0188] In one embodiment of the invention, a computer system determines whether the provided personally identifiable information is associated with known fraudulent activity indicated by an internal or third-party source, such as that used by a financial institution or creditor. For example, an address on an application may be identical to an address provided on a fraudulent application; or a telephone number on an application may be identical to a telephone number provided on a fraudulent application. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0189] In one embodiment of the invention, a computer system determines whether the provided personally identifiable information is of a type typically associated with fraudulent activities indicated by internal or third-party sources, such as those used by financial institutions or creditors. For example, an address on an application might be fictitious, a mailing address, or a prison; or a phone number might be invalid or associated with a pager or answering service. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0190] In one embodiment of the invention, a computer system determines whether the provided Social Security number is the same as a Social Security number submitted by another person who opened the account or by another customer. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0191] In one embodiment of the invention, a computer system determines whether the provided address or telephone number is the same as or similar to an account or telephone number submitted by an unusually large number of other people or customers. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0192] In one embodiment of the invention, a computer system determines whether an account holder has failed to provide all the necessary personally identifiable information about an application or whether they have responded to a notification that the application is incomplete. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0193] In one embodiment of the invention, a computer system determines whether the provided personally identifiable information is inconsistent with personally identifiable information archived by a financial institution or creditor. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0194] In one embodiment of the invention, a computer system determines whether the account holder is unable to provide authentication information, such as answers to challenge questions that exceed what would normally be obtained from a wallet or consumer report. If a suspicious activity case is detected, the computer system makes the detected case available for review by an administrator.
[0195] In one embodiment of the present invention, a computer system determines whether there is any abnormal use of an account or suspicious activity related to the account. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0196] In one embodiment of the invention, a computer system determines whether, shortly after notifying an account of an address change, an institution or creditor has received a request for a new, additional, or replacement SIM card or mobile phone, or a request to add an authorized user to the account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0197] In one embodiment of the invention, a computer system determines whether a new revolving credit account is being used in a manner typically associated with known fraud patterns. For example: most of the available credit is used for advance cash payments or goods easily convertible to cash (e.g., electronic devices or jewelry); or the customer fails to make the first payment or makes the initial payment but no subsequent payments. If a suspicious activity case is detected, the computer system makes the detected case available for review by an authorized representative.
[0198] In one embodiment of the invention, a computer system determines whether an account is being used in a manner inconsistent with the activity pattern established on the account. For example, non-payment occurs when: there is no history of overdue or missed payments; there is a significant increase in the use of available credit; there is a significant change in the purchase or spending pattern; there is a significant change in the electronic funds transfer pattern associated with a deposit account; or there is a significant change in the telephone calling pattern associated with a cellular telephone account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0199] In one embodiment of the invention, a computer system determines whether an account has been inactive for a considerable period of time (considering the account type, intended use pattern, and other relevant factors). If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0200] In one embodiment of the invention, while transactions continue to occur with the customer's account, a computer system determines whether emails sent to the customer are repeatedly returned undeliverably. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0201] In one embodiment of the invention, when a financial institution or creditor notifies a customer that a paper bill has not been received, a computer system closely reviews all transactions. If a suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0202] In one embodiment of the invention, when a financial institution or creditor is notified of unauthorized fees or transactions related to a customer's account, a computer system closely reviews all transactions. If a suspicious activity is detected, the computer system makes the detected case available for review by an authorized representative.
[0203] In one embodiment of the invention, when a customer, a victim of identity theft, a law enforcement authority, or any other person notifies a financial institution or creditor that they have opened a fraudulent account with a person involved in identity theft, a computer system closely reviews all transactions. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0204] In addition to the transaction monitoring models described above, the group comparison method described earlier can also be used to detect potential identity theft cases. Identity theft cases can be categorized into two main types. The first type includes cases where a fraudster steals a victim's account, financial instruments, or identification documents to carry out activities. In such cases, as described above, a computer system can detect activities that deviate from the victim's expected activities, which can be established from the victim's historical activity.
[0205] The second category includes cases where a victim's identity is stolen to open a new account and / or initiate new activities. In these cases, the victim is irrelevant from day one. Because there is no real history of the victim's activity, it is impossible to properly establish the victim's intended activity for fraud prevention purposes. Although someone could ask the criminal questions during the account opening process and collect answers in an attempt to establish the criminal's intended activity, this question-and-answer method may not work because the criminal knows how to answer questions that establish their intended activity without triggering any alarms.
[0206] To detect identity theft when no authentic historical activity is available, in one embodiment of the invention, all risk factors for a new account or new customer are identified. These risk factors may include, for example, the customer's due diligence results, prior records with other businesses, the customer's credit report records, the customer's industry category, the customer's business type, the customer's geographic region, the customer's country of address, the nature of the customer's business, the type of products offered, the type of services provided, the business structure, the customer's occupation, nationality, historical records, types of transactions conducted, account balance, cash inflows, cash outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, transaction frequency, transaction derivatives, number of chargebacks, transaction location, transaction time, transaction country, remitter of a transfer transaction, remitter's location, remitter's country, nature of the remitter, recipient of a transfer transaction, recipient's location, recipient's country, nature of the recipient, relationship, social status, political reputation, historical transactions, etc. In fact, numerous risk factors can be considered to determine the risk of identity theft.
[0207] In one embodiment of the invention, a risk factor is used to identify a group of people sharing the same risk factor. If a particular person has a total risk score significantly higher than a reference value derived from the total risk scores of all persons sharing the same risk factor, that person may be involved in an identity theft case. A set of risk factors can be used to identify a group of people sharing this set of risk factors. If a particular person has a total risk score significantly higher than a reference value derived from the total risk scores of all persons sharing the same set of risk factors, that person may be involved in an identity theft case. The reference value includes a mean, a median, a mode, a weighted average, and / or other statistical values. To simplify calculations, group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons within a group of people.
[0208] In one embodiment of this invention, a responsible person (or compliance officer) investigates a detected case to determine whether it is a case of genuine identity theft. The compliance officer also reviews all historical cases associated with the newly detected case. If the compliance officer agrees that the case is a possible case of identity theft, the computer system assists the compliance officer in submitting a SAR to FinCEN. If the compliance officer decides not to submit a SAR, the compliance officer enters a reason into the computer system to justify their decision not to report the detected activity.
[0209] The Office of Foreign Assets Control (OFAC) has a very simple rule that states it is illegal to conduct any business transaction with any entity on an OFAC-published list. This list is commonly referred to as the "OFAC List." This rule applies to all U.S. citizens and entities, including financial institutions. For example, Walmart was penalized by OFAC for violating this rule. U.S. financial institutions, subject to the most stringent regulatory oversight, are naturally required to strictly adhere to this rule.
[0210] Initially, it was a very simple rule. However, over the past 20 years, the implications of this rule have become much more complex. A common problem arises when people misspell (including typos, mispronunciations, etc.) their names. Even if an entity's name is misspelled but it is on the OFAC list, a financial institution is still obligated to identify that entity as an entity on the OFAC list (often referred to as an OFAC match).
[0211] The natural question is how much a deviation from the original name on the OFAC list is categorized as a "misspelling." OFAC and government regulators have never provided any precise guidance on answering this question. One very common practice an auditor or reviewer can take is to use a notorious name like "Osama bin Laden" as a template to test a company. Typically, a company should identify all business transactions associated with "Osama bin Laden," "Osama Laden," "Osama Laten," "Laten Osama," "Latin Obama," etc., as potential OFAC matches. Now, if we broaden the scope of deviations from OFAC names further, it becomes questionable whether a financial institution should identify the single word "Obama," the name of a former U.S. president, as a potential OFAC match. It is easy to see that this simple OFAC rule has caused considerable confusion in recent years.
[0212] In one embodiment of the invention, an "OFAC matching ratio" is used to measure the degree of deviation. The OFAC matching ratio can generate a value called "relative relevance" ("RC value") to measure the similarity between two names. For example, if a name has an RC value of 100%, it perfectly matches an OFAC name on the OFAC list. If a name has an RC value of 97%, it may differ from an OFAC name on the OFAC list by one or two letters. If a name has an RC value of 0%, it is completely different from all OFAC names on the OFAC list.
[0213] In one embodiment of the invention, the length of the name also affects the RC value. For example, if a name differs from an OFAC name with 25 letters by one letter, the RC value may be 96%, while another name may have an RC value of 90%, even though it also differs from another OFAC name with 10 letters by only one letter.
[0214] Some long words (such as International, Incorporation, Limited, Company, Organization, etc.) are commonly used in business names, and these words also exist in the OFAC name list. Therefore, these long words generate higher RC values for companies that use them in their names. To avoid unnecessary misidentification, in one embodiment of the invention, a commonly used long word can be replaced with a short word to reduce its impact on the RC value. For example, "intl" can be used to replace "International".
[0215] Additionally, some countries do not use descriptions of "first name" and "last name". Therefore, when a person is asked to provide a first name and a last name, that person can use a different name sequence. "Osama Laden" can be changed to "Laden Osama". In one embodiment of the invention, an OFAC matching ratio identifies a possible "out-of-order" OFAC match.
[0216] Furthermore, some words are commonly used in specific cultures without causing significant distinction. For example, in Muslim culture, "bin" means "son" and "binti" means "daughter." Formal Muslim names often contain "bin" or "binti." For instance, if a Muslim father's name is "John," then his daughter "Mary's" formal name would be "Mary binti John," and his son "David's" formal name would be "David bin John." In such cases, the commonly used Muslim names "bin" and "binti" create a "false similarity" between the two Muslim names. To provide a more scientifically accurate result, in one embodiment of this invention, the OFAC matching ratio can exclude such "irrelevant words" before calculating the RC value. Sometimes, a name can be translated into English based on its sound. Therefore, in one embodiment of this invention, the OFAC matching ratio should measure the sound matching to determine the RC value.
[0217] In one embodiment of the invention, a financial institution determines which threshold to use when conducting an OFAC check. For example, if a financial institution uses a threshold of 75%, then a possible OFAC match is detected when a name has an RC value of 75% or higher. Because financial institutions may have different risk exposures than other financial institutions, it is highly likely that X is the optimal threshold for financial institution A, and Y is the optimal threshold for financial institution B. As a general guideline, the value of X or Y is selected based on a risk-based principle.
[0218] Generally, the higher the threshold a financial institution uses, the fewer potential OFAC matches it detects. This saves time during the review process by avoiding more false positives. However, if the threshold is too high, the financial institution may miss a reasonable deviation from an OFAC name (such as "Osama bin Laden"). If the threshold is too low, the financial institution may incorrectly detect many of its customers as potential OFAC matches. Best practice is to find a trade-off between "too many potential OFAC matches to review" and "missing genuine OFAC name deviations due to misses."
[0219] In one embodiment of the invention, a user can randomly select several OFAC names from the OFAC list and determine how the OFAC matching ratio responds to deviations from the selected OFAC names. A user can then use this test to determine when to invoke a "potential OFAC match." It is advisable to retain this test for future review by auditors and examiners.
[0220] A particular name may be very close to an OFAC name. For example, a reputable credit card company, American Express, is often mistakenly detected as an OFAC match simply because of the word "Express." Therefore, to avoid this type of frequent false positives, in one embodiment of the invention, the user generates an exemption list to include well-known and reputable businesses. Businesses on the exemption list are automatically or manually categorized as false positives by the computer or by the user when they are detected as potential OFAC matches.
[0221] Typically, an enterprise may have one OFAC officer handling all OFAC-related matters. In one embodiment of the invention, if an OFAC officer (e.g., a responsible person) of a financial institution detects a possible OFAC match with an RC value exceeding a predefined threshold, the OFAC officer investigates whether this is a genuine OFAC match. If the OFAC officer believes it is a genuine match, the OFAC officer should handle the case according to guidelines issued by the Foreign Assets Control Authority (FAA). Under OFAC regulations, in some cases, the OFAC officer may be required to block the transaction so that a person on the OFAC list cannot benefit from it. If, after its investigation, the OFAC officer determines that the OFAC match is a false positive, the OFAC officer should enter a reason into the computer system to justify its decision not to report the OFAC match case to the FAA and / or not to block the transaction.
[0222] Section 314(a) of the USA PATRIOT Act requires financial institutions to detect matches of names on a 314(a) list, which is periodically published by FinCEN. Computer systems can handle 314(a) compliance matters using methods similar to those used for OFAC compliance matters, as described above.
[0223] Sometimes, a 314(a) list also includes additional personally identifiable information, such as identification file number, date of birth, address, etc. In one embodiment of the invention, in addition to the method described above for detecting possible OFAC matches, a computer system uses personally identifiable information (such as identification file number, address, and / or date of birth) to determine whether a detected 314(a) match is a genuine match. This method can reduce false positives in the 314(a) matching process.
[0224] In one embodiment of the invention, if a compliance officer (e.g., a responsible person) of a financial institution detects a possible 314(a) match with an RC value exceeding a predefined threshold, the compliance officer investigates whether this is a genuine 314(a) match. In another embodiment of the invention, if the compliance officer believes it is a genuine match, the compliance officer reports the 314(a) match case to FinCEN. If, after investigation, the compliance officer determines that the 314(a) match is a false positive, the compliance officer enters a reason into the computer system to justify not reporting the 314(a) match to FinCEN.
[0225] In one embodiment of the present invention, the computer system receives customer information and transaction data from the financial institution's core data processing system or from other data processing systems within or outside the financial institution. The customer information may include background information.
[0226] In one embodiment of the invention, the computer system receives information about suspicious activities observed by frontline personnel. For example, the computer system may receive information input from frontline personnel. The computer system may also receive information provided from other internal or external sources.
[0227] Although "financial institutions" are used as an example for ease of explanation, this invention is also applicable to other types of businesses. Generally, any business that needs to comply with laws and regulations can adopt one of the intelligent alarm systems described in this invention.
[0228] In one embodiment of the invention, a risk factor may be assigned a risk score or a degree of risk by a computer software module, a person designing or tuning the system, or a user of the system. In most cases, the absolute value of the risk score is not important, and the relative relationships among all risk scores may be more important.
[0229] Furthermore, an object's total risk score should fluctuate only within a reasonable range. In one embodiment of the invention, if an object's total risk score suddenly increases and exceeds a threshold, the object may have engaged in suspicious or unusual activity. That is, if the difference between an object's first and second total risk scores is greater than an increase threshold (where the first total risk score is less than the second total risk score), the object may have engaged in suspicious or unusual activity. In another embodiment of the invention, if an object's total risk score suddenly and drastically decreases, the object may also have engaged in suspicious or unusual activity. That is, if the difference between an object's second and first total risk scores is greater than a decrease threshold (where the first total risk score is greater than the second total risk score), the object may have engaged in suspicious or unusual activity. Therefore, an alert will be sent to an investigator, a BSA supervisor, a compliance supervisor, or another type of person in charge of investigating the object when its total risk score has suddenly and drastically increased or decreased.
[0230] Observed data on an object may fluctuate from time to time. Therefore, an intelligent alarm system can allow the total risk score of an object to fluctuate within a specific range to avoid false alarms. In one embodiment of the invention, when the total risk score of an object falls below a threshold, the intelligent alarm system increases the allowable fluctuation range of the object's total risk score. In another embodiment of the invention, when the total risk score of an object exceeds a threshold, the intelligent alarm system decreases the allowable fluctuation range of the object's total risk score. The allowable fluctuation range can be determined (e.g., set) by a software module, a system designer, a system tuner, or a system user.
[0231] For example, if an object's total risk score is higher than the mean of all object total risk scores plus a certain number of standard deviations (such as four standard deviations), a smart alarm system can modify the allowable fluctuation range of the object's total risk score to within half a standard deviation without triggering an alarm. In another instance, if an object's total risk score is within the mean of all object total risk scores plus a certain number of standard deviations (such as three standard deviations), a smart alarm system can allow the object's total risk score to fluctuate within one standard deviation without triggering an alarm.
[0232] In yet another instance, if an object's total risk score is within a certain number of standard deviations (such as two standard deviations) of the mean of all objects' total risk scores, then the intelligent alarm system can allow the object's total risk score to fluctuate within one of 1.5 standard deviations without triggering an alarm. In yet another instance, if an object's total risk score is within a certain number of standard deviations (such as one standard deviation) of the mean of all objects' total risk scores, then the intelligent alarm system can allow the object's total risk score to fluctuate within one of two standard deviations without triggering an alarm.
[0233] In the field of machine learning, a negation is a dataset that has not yet triggered an alarm. A correct negation is a dataset that has not yet triggered an alarm and does not include any real-world cases that would have triggered an alarm. An incorrect negation is a dataset that has not yet triggered an alarm but includes any real-world cases that would have triggered an alarm that the system missed. As an example, if the U.S. government discovers an incorrect negation of a money laundering case, that incorrect negation could lead to penalties imposed on a financial institution by the U.S. government. Therefore, it is desirable to prevent incorrect negations in an alarm system specifically designed to prevent money laundering (e.g., a money laundering prevention alarm system).
[0234] A US financial institution reported a money laundering case to FinCEN, a US government organization, through its anti-money laundering alert system. FinCEN has a set of communication protocols. US financial institutions can report cases to FinCEN by sending a file from the anti-money laundering alert system to FinCEN's computer system using FinCEN's communication protocols.
[0235] As is commonly known, rule-based systems are used to detect suspicious activity, and each rule can trigger an alert. Many financial institutions have used rule-based methods that can trigger numerous alerts. For example, there are over 200 countries in the world. If a financial institution uses a rule-based method to monitor wire transfers to and from these countries, it could have over 200 branches at the country decision node in its decision tree. As another example, there are thousands of different industries. If a financial institution uses a rule-based method to monitor wire transfers to and from these industries, it could have thousands of branches at the industry decision node in its decision tree. Both country and industry are two of many risk categories that carry money laundering risk. Similarly, a wire transfer is one of many transaction types that carry money laundering risk. For example, cash, checks, ACH, ATMs, credit cards, debit cards, and letters of credit are other possible types of transactions.
[0236] There are numerous money laundering risk factors. Numerous (e.g., millions) branches can combine to form a path from the root to a leaf node of a decision tree. In other words, a rule-based system can use millions of rules to cover the entire spectrum of money laundering risk to detect suspicious money laundering activities. A rule-based system with a finite number of rules can have an increased number of false negatives (e.g., the system has missed genuine money laundering cases) and numerous false positives (e.g., the leaf nodes of the decision tree have increased numbers of impurities and fail to achieve the classification objective). Due to the number of false negatives and false positives when using a rule-based approach, financial institutions hire investigators to review numerous alerts. It is difficult for financial institutions to use a rule-based system to mitigate all false negatives.
[0237] In the field of machine learning, learned systems consider 70% accuracy to be satisfactory. It is difficult (if not impossible) to train a machine learning model to have high accuracy (such as 100%). Unfortunately, while 70% accuracy may be good for some purposes, this 70% target fails to meet regulatory standards, such as those set by the US government. As discussed, if a financial institution fails to detect specific activities (such as money laundering), it may face severe regulatory penalties. Therefore, a financial institution would not use an alert system with 70% accuracy. Thus, learned machine learning models are not satisfactory for an intelligent money laundering prevention alert system.
[0238] According to the present invention, the intelligent money laundering prevention alarm system uses a risk scoring method. Each risk factor, or the degree of a risk factor, can be analogous to a branch of a rule-based system. Thus, as described in the present invention, the risk scoring procedure for generating a total risk score from a plurality of risk factors can incorporate information from a plurality of rules into the total risk score. For example, if a total risk score is generated from 10,000 risk factors, a user only needs to pay attention to alarms with total risk scores exceeding a threshold value without evaluating each of the 10,000 risk factors individually. If a rule-based method is used, each risk factor can have two possible outcomes: a match or a mismatch. The total number of possible combinations of outcomes for 10,000 risk factors is a power of 10,000 (e.g., 210,000) of the second (2). Therefore, an evaluation based on the total risk score effectively replaces the need to evaluate each of the 10,000 (e.g., 210,000) possible outcomes of the second (2). Because these 210,000 results could potentially generate 210,000 different types of alerts, the intelligent money laundering prevention alert system can avoid at least 210,000 alerts. Therefore, the intelligent money laundering prevention alert system is an improvement upon one of the known rule-based systems.
[0239] While a total risk score can replace many rules, it cannot replace all of them. For example, if an individual frequently deposits a specific amount of cash (e.g., $9,900) (slightly below the CTR reporting threshold of $10,000), financial institutions are expected to report this individual to the Financial Crimes Enforcement Network (FinCEN) as a batch transfer case. It is difficult to accurately detect a batch transfer case based solely on the total risk score. Therefore, an alert system based on risk score-based technology may include rules in addition to those based on risk score criteria.
[0240] In one embodiment of the invention, the intelligent money laundering prevention alert system uses risk-score-based scenarios instead of rules. In one example, the intelligent money laundering prevention alert system may use approximately twenty to thirty scenarios. These scenarios may include both risk-score-based scenarios and non-risk-score-based scenarios.
[0241] In addition to or in lieu of these scenarios, other conditions can be used to generate an alarm. For example, a computer system (such as a machine learning network) can be trained to generate a model. After training, the discriminant used by the model can be converted into an if-then conditional format to trigger the alarm.
[0242] For the purposes of this invention, a circumstance can be defined as a condition or set of conditions that can trigger an alert for a specific purpose or be used to categorize an object into a category. For example, a customer with a total risk score within a specific range cannot trigger an alert. However, in this instance, the total risk score can categorize the customer into a specific risk category, such as high risk, medium risk, or low risk. As another example, a customer who was previously a suspect in a Suspicious Activity Report (SAR) cannot trigger an alert. In this instance, the customer can be categorized into a specific category, such as a previous SAR suspect or another similar category. As yet another example, a customer matching the OFAC List, the 314(a) List, the List of Highly Public Figures, and / or other lists can be categorized into one or more categories.
[0243] Based on rules, facts, behavioral patterns, risk scores, risk dimensions, total risk scores, special categories, mathematical models, and / or machine learning models, an event can consist of a rule, a set of rules, a criterion, or a set of criteria. The event can trigger an alarm using a rule-based approach, a behavior-based approach, a risk-based approach, a model-based approach, and / or a machine learning-based approach (e.g., an AI-based approach). An intelligent alarm system can contain one or more events.
[0244] As discussed, an alarm can be triggered by a scenario. A scenario can be flagged when one or more conditions are met. A potential case that has triggered an alarm can be called a positive. A potential case can contain one or more alarms. Therefore, the cause of a potential case can be one or more scenarios. Potential cases or positives can be investigated. A correct positive can refer to a potential case that is a real case (e.g., a positive). If the investigation indicates that a potential case is not a real case, then the potential case can be called a false positive. Therefore, a false positive can be rejected and the associated alarm can be rejected as a false alarm. A correct positive can be reported to an authority (such as FinCEN or a law enforcement agency).
[0245] In a configuration, a posterior probability can be estimated using Bayes' principle. The product of the posterior probability and the evidence is a prior probability multiplied by the class likelihood. Using the application of reporting suspicious money laundering activities to FinCEN as an example, the Bayes equation is p(S / c)p(c) = p(c / S)p(S). The evidence p(c) is the probability of a potential case triggered by cause c among all potential cases. The class likelihood p(S) is the probability of a correct affirmation S (e.g., a true SAR case) among all potential cases. The prior probability p(c / S) is the probability of a correct affirmation triggered by cause c among all correct affirmations. Therefore, the posterior probability p(S / c) can be determined as follows: p(S / c) = p(c / S)p(S) / p(c). The posterior probability P(S / c) is also the conditional probability that a potential case triggered by cause c is a correct affirmation. That is, although the conditional probability P(S / c) is derived from historical data, it is the best estimate of the probability that one of the potential cases triggered by cause c will become a correct and certain future probability. Therefore, the posterior probability can also be called the conditional probability for the future or the future conditional probability.
[0246] Numerous risk factors (e.g., thousands) can influence money laundering risk. In a configuration, the number of scenarios used by a smart money laundering alert system is not large when risk score-based scenarios are used as part of those scenarios. As an example, a smart money laundering alert system may use thirty scenarios. A potential case can be triggered by one or more of these scenarios. In this example, a vector with thirty elements can represent the possible causes of a potential case. Therefore, in this example, there are 230 possible combinations of causes. Each triggered scenario is identified by a flag. For example, a cause vector can be initialized to have a value of "0" for each element. If a scenario is triggered, the value of one of the elements corresponding to that scenario can be changed from "0" to another value, such as "1".
[0247] For example, if a potential case is triggered by a first event and a third event, then the vector x may contain "1" at the first and third positions, and "0" at all other positions. That is, the vector can be represented as x = (1, 0, 1, 0, 0, 0, ..., 0). As another example, if a potential case is triggered by a third event and a fourth event, then the third and fourth positions of the vector may contain "1" values, and all other positions may contain "0" values. In this example, a vector x can be represented as x = (0, 0, 1, 1, 0, 0, ..., 0). In this invention, a vector containing the events (e.g., causes) used to trigger an alarm for a potential case may be called a cause vector.
[0248] An incident may contain conditions for classifying an object into one or more categories; however, the incident itself cannot trigger a potential case. A potential case can be triggered by multiple incidents in an associated cause vector. For example, if an incident intends to classify an object into a previous SAR suspect category, this incident cannot trigger a money laundering alert on its own. However, if a customer is a previous SAR suspect and another incident has been triggered (e.g., transferring more than $10 million to a higher-risk country), a potential case may be triggered. However, a cause vector may have two incidents, one for the transfer transaction and another for the previous SAR suspect. It is a good idea to include various special categories (e.g., previous SAR suspects) in the cause vector because such special categories can improve the accuracy of suspicious activity detection.
[0249] A potential case with multiple triggered scenarios in the cause vector is more likely to become a correct affirmative. For example, if a customer receives $250,000 via wire transfer, one scenario in the cause vector can be flagged (e.g., triggered). This cause vector with a flagged scenario can be registered as a potential case, which may or may not be a genuine money laundering case. Similarly, if a customer withdraws $250,000, another scenario in the cause vector can be flagged. However, this potential case may or may not be a genuine money laundering case.
[0250] However, if a customer receives $250,000 via wire transfer and then withdraws $250,000 in cash from their account, two distinct scenarios can be labeled in the cause vector. A cause vector with two labeled scenarios can be registered as a potential case, which is more likely to be a genuine money laundering case because the combined activities described by the two distinct scenarios match a common money laundering pattern. Therefore, it is desirable to calculate the conditional probability of a potential case based on a cause vector with one of multiple labeled scenarios, rather than based on a single labeled scenario.
[0251] If a cause vector has thirty events (since each event has two possibilities (e.g., triggered and not triggered)), then thirty events can have up to 230 possible combinations. However, since no case is triggered if no event is triggered, the total number of possible combinations that trigger a case is (2^30 - 1). Each combination can have a unique conditional probability of triggering one of the potential cases. Calculating these conditional probability values may be impractical, as 2^30 is a very large number. In practice, a potential case averages out to five or fewer events that trigger simultaneously. Therefore, the actual total number of meaningful combinations of events that can trigger a potential case is a much smaller number and can be managed via a computing device associated with a smart alarm system. For example, if the maximum number of possible cases in a potential case is 5, then the total number of possible potential cases triggered by these 30 scenarios is C(30,1) + C(30,2) + C(30,3) + C(30,4) + C(30,5), where C(m,n) is the number of different choices of selecting n objects from m objects. For example, C(30,1) is 30, because there are 30 possible choices of selecting 1 object from 30 objects. C(30,2) is 435. C(30,3) is 4,060. C(30,4) is 27,405. C(30,5) is 142,506. The total number of possible cause vectors is 174,436. These cause vectors and their associated conditional probability values can be managed via a computing device and a database associated with an intelligent alarm system.
[0252] An investigator can use a smart alert system to investigate a potential case triggered by a cause vector. The cause vector may contain multiple labeled episodes. A potential case can be a false positive or a true positive. A true positive refers to a potential case that is a real case. A false positive refers to a potential case that is not a real case. If it is a false positive, all alerts for the potential case are rejected as false alarms. If it is a true positive, the potential case becomes a real case that can be reported to an authority (such as FinCEN).
[0253] Typically, investigating a potential money laundering case is time-consuming. In the United States, it is common for a large financial institution to employ hundreds of investigators. Each investigator's task is to investigate whether a potential case triggered by various anti-money laundering systems is a genuine money laundering case. If a genuine money laundering case exists, U.S. law requires the financial institution to report the case to FinCEN within 30 days. However, as discussed above, whether a potential case is a genuine money laundering case is a subjective opinion of one of the investigators.
[0254] If an investigator falsely reports a money laundering case as a genuine case, there is no penalty because financial institutions are protected by safe harbor rules. Typically, due to the substantial regulatory penalties for failing to report a genuine money laundering case to FinCEN, it is desirable to report a potential case to FinCEN rather than reject it. Therefore, it is common practice for investigators to treat a potential case as a correct affirmation as long as there is reasonable doubt. Current U.S. law does not require investigators to prove that a potential case is a genuine case. That is, if a potential case is highly likely to be a genuine case, an investigator is inclined to report it. This also means that probability plays a role in this decision-making process.
[0255] A user's decision-making can be improved based on understanding the conditional probability p(S / x) of a potential case becoming a real SAR case based on the cause vector x. For example, if the conditional probability is greater than a threshold, the user may want to report the case to FinCEN without spending time investigating. In one configuration, when the conditional probability of a case is greater than a threshold, the intelligent alarm system automatically reports the case to an appropriate entity (e.g., FinCEN). The threshold can be set by a software module, a person designing or tuning the system, and / or a user of the system. Alternatively, the threshold can be set by the intelligent alarm system, which learns user preferences by evaluating past user behavior. For example, if a user typically submits an SAR when the conditional probability of the cause vector is greater than the Z value, the system can use the Z value as a threshold to automatically submit an SAR for the user in the future. In one configuration, the system stores potential cases in a database to determine the conditional probability. For each potential case, the system also stores the associated cause vector. The system can also store survey results, such as whether a potential case triggered by a cause vector has been accepted by the investigator as a correct affirmative or rejected by the investigator as an incorrect affirmative.
[0256] As users continue to use the intelligent alarm system, the system accumulates historical data in a database. In one embodiment of the invention, for any given time period, the system can determine from the database how many potential cases are triggered by a cause vector x and how many of those potential cases have become correct affirmations (e.g., SAR cases reported to FinCEN). The ratio of the number of correct affirmations triggered by the cause vector to the number of potential cases triggered by the cause vector is the conditional probability p(S / x). The conditional probability can also be called the posterior probability. The posterior probability indicates the probability that a future potential case triggered by a cause vector will become a real case reported to FinCEN. Typically, the conditional probability of a potential case is equal to the conditional probability of the cause vector that triggered the potential case.
[0257] In one embodiment of the invention, the intelligent alarm system calculates and displays the conditional probability of each potential case based on its cause vector. The conditional probability indicates the probability that a potential case triggered by the cause vector becomes a correct affirmative case reported to FinCEN. In another embodiment of the invention, the intelligent alarm system responds to a conditional probability of the cause vector exceeding a predefined value by accepting a potential case as a correct affirmative case and reporting the case to FinCEN. This predefined value is also referred to as the correct affirmative acceptance threshold.
[0258] Intelligent alarm systems can also respond to a potential case being rejected as a false affirmative if the conditional probability of the cause vector is less than a false affirmative rejection threshold. The false affirmative rejection threshold and the correct affirmative acceptance threshold can be set by a software module, a person designing or tuning the system, and / or the user of the system. Alternatively, these thresholds can be set by the intelligent alarm system, which learns user preferences by evaluating past user behavior. For potential cases that have not yet been accepted as correct affirmatives and rejected as false affirmatives, investigators can manually review the potential cases and determine whether each aspect of the potential case is a false affirmative or a correct affirmative.
[0259] Data used to determine conditional probabilities can be obtained over a specific time period. For example, the time period could be the past 12 months, the past 3 years, or any other period. In a configuration, conditional probabilities are determined from a rolling time period, which is continuously shifted forward. For example, if circumstances (e.g., corporate policies, customer demographics, products, services, etc.) have changed, the old probability values may no longer be accurate. Furthermore, if a financial institution modifies a scenario, the old probability values may be affected. Therefore, a rolling time period (e.g., the past 3 years) provides intelligent alert systems with the ability to continuously self-adjust to generate the latest and most accurate probability values.
[0260] Many computer systems run data processing in batches (e.g., one batch per month). Instead of a single time period, several batches can be used to define the amount of historical data used for probability calculations. For example, instead of a rolling time period of one past three years, if a computer system runs one batch per month, it can use a rolling time period of one past 36 batches.
[0261] In one configuration, an intelligent alarm system intentionally leaves some potential cases for investigators to handle. The system can then use the results of these cases to train itself, adjusting the probability values to better adapt to the current environment. Therefore, an intelligent alarm system is a learning system that improves predictions as more potential cases are evaluated by human investigators.
[0262] When a causal vector has not yet generated a potential case triggered by it within a specified time period, the intelligent alarm system can generate a flag or display a message for that potential case. In such cases, a user can manually investigate the potential case to determine whether it is a false positive or a true positive. The results of the manual investigation can be used to calculate the conditional probability value of the causal vector. The calculated conditional probability value can be used to assess future potential cases. This manual investigation procedure has the equivalent effect of supervised training and improves the accuracy and reliability of the intelligent alarm system.
[0263] Intelligent alarm systems can also display or link to historical potential cases and / or positive positivity triggered by causal vectors. Additionally, users can view further details of each case (e.g., in-depth analysis). Therefore, investigators can use historical data as a reference when determining whether to continue pursuing a potential case.
[0264] The system can also display or link to historical potential cases triggered by the same suspect in the current potential case, as well as decisions made regarding those potential cases. Investigators can delve into detailed background information and transaction details of the suspects. Therefore, an investigator can determine whether the current potential case is a false positive or a valid positive.
[0265] In some cases, there may not be sufficient grounds to report a current potential case to an authority. However, a current potential case, combined with historical potential cases, may have sufficient reasons for reporting. In such cases, the true reason for reporting the case, in addition to the causal vector of the historical potential cases, also consists of the causal vector of the current potential cases. Historical potential cases may be referred to as previous potential cases. A combined causal vector can be used for this true reason. A combined causal vector can be a combination of one of multiple causal vectors from multiple potential cases.
[0266] As an example, a cause vector x1 for a current case may have "1" at the first and fifth positions and "0" at all other positions (e.g., x1 = (1, 0, 0, 0, 1, 0, 0, ... 0)). In this example, a cause vector x2 for a historical latent case has "1" at the third and fifth positions and "0" at all other positions (e.g., x2 = (0, 0, 1, 0, 1, 0, 0, ... 0)). A combined cause vector x3 (e.g., a combination of x1 and x2) has "1" at the first, third, and fifth positions and "0" at all other positions (e.g., x3 = (1, 0, 1, 0, 1, 0, 0, ... 0)). Although only one cause vector for a historical latent case is used in the above example, a combined cause vector can consist of multiple cause vectors for multiple historical latent cases.
[0267] In one configuration, an investigator manually reviews multiple historical latent cases and current latent cases to determine whether the combined case is an incorrect affirmation (e.g., not reported) or a correct affirmation (e.g., pending report). The results of the manual investigation can be used to calculate the conditional probability value p(S / cbv) of one of the combined cause vectors cbv (e.g., posterior probability value). The combined cause vector cbv is a combination of the cause vector of the current latent case and one or more cause vectors of the historical latent cases.
[0268] In some cases, intelligent alarm systems may struggle to identify which historical potential cases investigators have already investigated. Therefore, intelligent alarm systems can prompt investigators to select historical potential cases that will be combined with current cases to report to the authorities.
[0269] Furthermore, in some cases, intelligent alarm systems may struggle to identify which elements of a combined causal vector or a single causal vector led investigators to report a potential case. Therefore, intelligent alarm systems can prompt investigators to select the elements that prompted them to report a potential case.
[0270] Numerous reports of suspicious activity request investigators to provide comments or descriptions of potential cases. To improve processing time, it is desirable for intelligent alarm systems to automatically fill in comments or descriptions of reported cases. Typically, the information used to write comments or descriptions consists of background information on the suspect and transaction details. Because this information is stored in a database, intelligent alarm systems can learn from users how to write comments or descriptions, as explained later in this invention.
[0271] In one embodiment of the invention, the intelligent alarm system prompts the investigator to select historical potential cases to be combined with the current potential case for reporting. Based on the causal vectors of the selected historical potential cases and the causal vectors of the current potential case, the intelligent alarm system prepares a comment or description. The prepared comment or description is provided in the report of the combined cases.
[0272] When a comment or description is entered into the intelligent alarm system, the system can also identify the combined causal vector of the reported case. Therefore, a conditional probability value p(S / cbv) can be associated with the identified combined causal vector cbv based on the results of a human survey.
[0273] The intelligent alert system prompts investigators to select either a causal vector leading to a potential case or a combination of causal vectors. Based on the selected scenarios, the intelligent alert system prepares a commentary or narrative to complete a report on one of the cases. These selected scenarios form the true causal vector of the reported case. The system identifies the scenarios of the true causal vector of the reported case. The conditional probability value of the true causal vector can be calculated based on the results of human investigations.
[0274] Individuals may possess a unique writing style (or preference), therefore, an investigator may initially dislike the comments or narratives generated by the intelligent alert system. If an investigator dislikes the comments or narratives generated based on selected scenarios and cannot modify them, the investigator may not bother to select scenarios that enable the intelligent alert system to generate comments or narratives. In such cases, the intelligent alert system may not be able to ascertain the true reasons why the investigator has decided to report the case to the authorities. Consequently, the intelligent alert system may be unable to calculate the future conditional probability values of the true cause vector based on human investigation results.
[0275] Therefore, it is expected that intelligent alarm systems will learn and adapt to the investigator's writing style (or preferences). In one configuration, the intelligent alarm system learns the investigator's writing style (or preferences) and generates future comments or narratives based on the investigator's writing style (or preferences).
[0276] In one configuration, to learn an individual's writing style (or preferences), the intelligent alarm system displays a commentary or narrative for a first selected scenario based on pre-stored preset comments or narratives. The pre-stored preset comments or narratives consist of two main parts. The first main part comprises facts such as the suspect's name, identification information, background of the suspect, relationship between the suspects, location of the incident, description of the incident, date and time of the incident, related information, and transaction details. The second main part may contain words, phrases, sentences, symbols, etc., used to link the facts together. These words, phrases, sentences, symbols, etc., are collectively referred to as "linking words."
[0277] Facts can be obtained from stored data or information associated with the intelligent alarm system. Investigators may rarely modify stored facts. An investigator may modify links based on their writing style (or preferences). Therefore, the intelligent alarm system tracks facts and links in comments and narratives. The intelligent alarm system can also track the location of facts in memory (e.g., a database) and the relationships among facts.
[0278] Typically, an individual's writing style (or preference) is determined by the linking words and presentation sequence (e.g., format) of the facts. Writing style (or preference) cannot be determined solely based on the selection of facts themselves, because investigators should include relevant facts and avoid altering them. In some cases, when the same incident is detected in two different cases, the facts may differ. However, the linking words and presentation sequence (e.g., format) of the facts can remain consistent in commentary or narration because the same investigator has the same writing style (or preference).
[0279] In one configuration, the intelligent alert system provides investigators with editing capabilities to add, delete, or modify linking words that connect facts. The intelligent alert system also provides investigators with editing capabilities and a database search function to retrieve additional facts from the database and insert them into the narrative.
[0280] After an investigator has revised their commentary or narrative for the first selected scenario, they can save the revised commentary or narrative as the next preset commentary or narrative. In the future, when the investigator selects the first selected scenario again for other cases, a revised commentary or narrative based on a different set of facts (e.g., the next preset commentary or narrative) can be displayed for the investigator to edit. Investigators may become satisfied with the revised version after several revisions and may not want to edit it again. Through this evolving revision process, the intelligent alarm system learns from the investigator and will generate one of the commentaries or narratives that matches the investigator's writing style (or preferences).
[0281] The intelligent alarm system can handle a second selected scenario using the same method described above for the first selected scenario. The intelligent alarm system can handle other selected scenarios in the same way. Over time, the intelligent alarm system will gradually learn how to write comments or narratives for each scenario based on the investigator's preferences.
[0282] As discussed, based on learning, the intelligent alarm system can automatically generate an investigator's commentary or narrative. Based on the nature of this invention, the investigator will no longer need to write a commentary or narrative. The investigator can select a scenario, and in response, the intelligent alarm system automatically fills in the SAR form and the commentary or narrative. The intelligent alarm system can then report the case to the appropriate authorities. Currently, an investigator may spend hours writing a commentary or narrative for one SAR case. The intelligent alarm system eliminates a significant amount of labor for investigators.
[0283] In some cases, a person's writing can depend on their mood. For example, a person in a good mood may write a detailed narrative. As another example, a person in a bad mood may write a poor or incomplete narrative. The present invention aims to eliminate the influence of the human author's mood on the narrative, thereby maintaining a consistent standard of narrative.
[0284] In one instance, when the intelligent alarm system detects that a customer, John Doe, deposited $9,990 on June 1st and $9,995 on June 2nd into an ABC Bank account, it can generate an alarm with a preset description as follows: [John Doe] [Mr.] is in [6] [moon] [1] [Japan] deposit [9,990] [US dollar] and in [6] [moon] [2] [Japan] deposit [9,99] [5] [USD] to [ABC] "[In the bank]" In this brief description, the underlined words are facts and the rest are linking words.
[0285] In one instance, an investigator might modify the narrative as follows: [John Doe] [Mr.] is in [6] [moon] [1] [Japan] deposit [9,990] [US dollar] and in [6] [moon] [2] [Japan] deposit [9,99] [5] [USD] to [ABC] [In the Bank] section. Under the Bank Secrecy Act, we report this case as a suspicious activity because it is a typical example of a cash lot transfer. In the above statement, underlined words are facts and the rest are links. When the investigator saves the SAR form for John Doe, the intelligent alarm system saves the revised statement as the default statement.
[0286] At a later time, the intelligent alarm system can detect that a customer, Jack Daniel, deposited $9,999 on July 1st and another $9,999 on July 2nd into an account at ABC Bank. In response, the intelligent alarm system can generate one of the SAR cases with a preset description as follows: [Jack Daniel] [Mr.] is in [7] [moon] [1] [Japan] deposit [9,999] [US dollar] and in [7] [moon] [2] [Japan] deposit [9,999] [USD] to [ABC] [In the Bank] section. Under the Bank Secrecy Act, we report this case as a suspicious activity because it is a typical example of a cash lot transfer.
[0287] In one instance, the investigator could change the statement to the following: "Under the Bank Secrecy Act, a financial institution is required to report a cash lot transfer activity via a Suspicious Activity Report (SAR). We have identified..." [Jack Daniel] [Mr.] is in [7] [moon] [1] [Japan] deposit [9,999] [US dollar] and in [7] [moon] [2] [Japan] deposit [9,999] [USD] to [ABC] [In the banking sector.] This is a typical cash bulk transfer activity that avoids submitting a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious bulk transfer activity via an SAR.” When the investigator saves the SAR form for Jack Daniel, the smart alert system saves the revised description as the default description.
[0288] At a later time period, the intelligent alarm system detected that a customer, Jim Beam, deposited $9,980 on August 3rd and $9,985 on August 4th into an account at ABC Bank. In response, the intelligent alarm system can generate a SAR case with a preset statement as follows: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer activity via Suspicious Activity Reporting (SAR). We have identified..." [Jim Beam] [Mr.] is in [8] [moon] [3] [Japan] deposit [9,980] [US dollar] and in [8] [moon] [4] [Japan] deposit [9,985] [USD] to [ABC] [In the banking sector.] This is a typical cash batch transfer activity that avoids submitting a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious batch transfer activity via a SAR.”
[0289] An investigator might see the above description and might want to add something like this: "Under the Bank Secrecy Act, a financial institution is required to report a cash lot transfer via a Suspicious Activity Report (SAR). We have identified..." [Jim Beam] [Mr.] is in [8] [moon] [3] [Japan] deposit [9,980] [US dollar] and in [8] [moon] [4] [Japan] deposit [9,985] [USD] to [ABC] [In the banking sector], this is a typical cash batch transfer activity that avoids submitting a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious batch transfer activity using a SAR. [Jim Beam] [Mr.] is in
[2019] [Year] [3] [moon] [1] [Japan] opened a bank account, and the average account balance over the past three (3) months was [123,197] [US Dollar]”. In this case review process, the investigator has included additional facts retrieved from the database of the smart alarm system. Underline these additional facts in the following sentences: [Jim Beam] [Mr.] is in
[2019] [Year] [3] [moon] [1] [Japan] opened a bank account, and the average account balance over the past three (3) months was [123,197] [US Dollar]”. When the investigator saves the SAR form for Jim Beam, the intelligent alarm system saves the revised description as the default description.
[0290] At a later timeframe, the smart alert system detected a customer, Remy Martin, who deposited $9,998 on September 5th and another $9,998 on September 6th into an ABC Bank account. In response, the smart alert system could generate a SAR case with a preset statement as follows: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer activity via Suspicious Activity Reporting (SAR). We have identified..." [Remy Martin] [Mr.] is in [9] [moon] [5] [Japan] deposit [9,998] [US dollar] and in [9] [moon] [6] [Japan] deposit [9,998] [USD] to [ABC] [In the banking sector], this is a typical cash batch transfer activity that avoids submitting a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious batch transfer activity using a SAR. [Remy Martin] [Mr.] is in
[2019] [Year] [2] [moon]
[15] [Japan] opened a bank account, and the average account balance over the past three (3) months was [83,225] [Dollar]".
[0291] The investigator can see the above description and decide that no changes are needed. Until the investigator makes any changes in the future, cases detected by the same scenario will use the following comment or description: "Under the Bank Secrecy Act, a financial institution is required to report a cash lot transfer activity via a Suspicious Activity Report (SAR). We have identified ( [Suspect's name] in ( [First deposit date]) deposited ( [First cash transaction amount]), and in ( [Second deposit date]) deposited ( [Second cash transaction amount] to ( [Bank Name]). This is a typical cash batch transfer activity that avoids submitting a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious batch transfer activity using a SAR. [Suspect's name] in ( [Account opening date]) opened a bank account, and the average account balance over the past three (3) months is ( [Average account balance]”. The underlined words will be retrieved from the database of the intelligent alarm system. The rest of the words in the description are the best link words used by the investigators and written by the intelligent alarm system based on the investigators' descriptions of past cases detected by the same scenario, and learned from the investigators.
[0292] In the above example, the set of facts consists of the following: the suspect's name, the amount of the first cash transaction, the date of the first deposit, the amount of the second cash transaction, the date of the second deposit, the bank name, the account opening date, and the average account balance. These different factual fragments can be retrieved from a storage location (such as a database).
[0293] In addition, John Doe, Jack Daniel, Jim Beam, and Remy Martin are facts of the same type under the field name "Suspect's Name". Each suspect's name can be defined as a fact corresponding to another suspect's name. For example, Remy Martin may be a fact corresponding to Jim Beam. Similarly, a set of corresponding fact fragments can be defined under the following fields: first cash transaction amount, first deposit date, second cash transaction amount, second deposit date, bank name, account opening date, and average account balance.
[0294] When a smart alarm system presents a pre-defined narrative based on a new set of facts about a new suspect, the system replaces the old facts about the previous suspect with the new corresponding facts about the new suspect. In the example above, the old suspect's name Jim Beam is replaced with the new suspect's name Remy Martin; $9,980 is replaced with $9,998; August 3rd is replaced with September 5th; $9,985 is replaced with $9,998; August 4th is replaced with September 6th; ABC Bank is replaced with ABC Bank; March 1st, 2019 is replaced with February 15th, 2019; and $123,197 is replaced with $83,225. The link text remains unchanged.
[0295] If an investigator has used the same preset narrative a predefined number of times without revising it, the preset narrative has been matched to the investigator's writing style (or preference). In such cases, the intelligent alert system can skip or suggest that the investigator skip the narrative review process.
[0296] In a configuration, in addition to providing a commentary or narrative for each episode, the intelligent alert system also provides an introductory section for each case. Alternatively, the intelligent alert system may provide a conclusion section for each case. The introductory section is placed at the beginning of the overall narrative, and the conclusion section is placed at the end of the overall narrative. For example, if a case has three episodes selected by the investigator, the overall commentary or narrative will have an introductory section, matching the three commentary or narrative sections for the three selected cases, and a conclusion section.
[0297] In one embodiment of the invention, the introduction and conclusion sections can also be modified and saved by the investigator. Similarly, the intelligent alarm system will learn to construct a better introduction and conclusion section from the investigator. This general format, including an introduction and a conclusion section, provides investigators with additional flexibility to write a more comprehensive and universal narrative.
[0298] In a configuration, if a case contains multiple suspects, each suspect is detected through a set of scenarios. The overall commentary or narrative of the case may include an introductory section, a section describing the relationship between the suspects, individual commentary (or narrative) sections for each case, and a conclusion section.
[0299] Updating the linking words and relative positions of facts in preset narratives based on different sets of facts simplifies the SAR case review and submission process. For example, when a smart alarm system detects an alarm about a suspect, it sends the currently matching scenario and all scenarios from historical alarms matching the suspect to the investigator's computer system. The investigator selects a scenario that constitutes a reason for submitting an SAR and sends the selected scenario back to the smart alarm system. The smart alarm system searches its database to identify preset narratives for the selected scenario and sends preset narratives based on the facts about the suspect back to the investigator's computer system. The investigator reviews the narrative and can make changes if necessary.
[0300] When an investigator saves the revised description, their computer system sends the revised description back to the intelligent alarm system. The intelligent alarm system stores the revised description and sends the SAR form with the revised description to the BSA supervisor's computer system. If the BSA supervisor approves the SAR form, the intelligent alarm system sends the SAR form to FinCEN's computer system. If the investigator does not believe any changes are needed to the default description, the intelligent alarm system can directly send the SAR with the default description to the BSA supervisor's computer system for approval.
[0301] In some cases, the investigator is also a BSA supervisor, or the BSA supervisor allows the investigator to submit a SAR directly without any approval. In such cases, the investigator can accept a pre-defined narrative based on the facts at the time. In response, the intelligent alarm system can directly send the SAR with the pre-defined narrative to the FinCEN computer system based on the current facts.
[0302] After an investigator has received a pre-defined narrative of a scenario a certain number of times without any changes based on different sets of facts, the intelligent alert system can assume that the pre-defined narrative matches the investigator's writing style (or preference) for that scenario. Therefore, when a future correct affirmative case with the same scenario is detected again regarding a suspect at that time, the intelligent alert system can directly send the SAR with the pre-defined narrative to the FinCEN computer system based on the facts of that time regarding the suspect. This eliminates the workload associated with investigators and BSA supervisors.
[0303] The above description for a single selected scenario can also be applied to multiple selected scenarios. For example, if an investigator has received preset narratives of all selected scenarios in a detected case a predefined number of times based on different sets of facts, the intelligent alarm system can send a SAR with preset narratives of multiple selected scenarios to the FinCEN computer system based on the facts of the suspect at that time.
[0304] In addition to SAR filing, this invention can be used by a computer system to automatically generate different types of reports based on human authors' preferences. For example, a hospital may need to generate a report for each patient. A police department may need to generate a report for each incident. A school may need to generate a report for each student. There are many other needs for generating reports. Conventional reports are generated by using massive amounts of human resources. This invention can reduce the human resources used in generating reports.
[0305] Reports can be categorized into different types based on various factors such as reasons, purposes, criteria, and circumstances. For example, a hospital might use different types of reports based on the reasons for a patient's hospitalization. As an example, reasons might include heart surgery, childbirth, etc. A patient may have multiple reasons for hospitalization. Furthermore, for each primary reason, there may be multiple sub-reasons. For example, if a patient is hospitalized because they need heart surgery, there are multiple reasons for that need. A detailed categorization of reasons is desirable because different reasons may require different writing styles (or preferences) to produce a report. As another example, there are many different reasons, purposes, criteria, and circumstances for a police department to produce a report on an incident. In yet another example, there are many different reasons, purposes, criteria, and circumstances for a school to produce a report on its students.
[0306] A report can be written based on one or more facts. These facts can consist of data stored in a database and entered by humans, data detected by sensors, data collected from various sources, and / or data derived from other sources. Furthermore, a human will use words, phrases, sentences, symbols, etc., to link the facts together to form a report. For ease of reference, the words, phrases, sentences, symbols, etc., that link the facts together are collectively referred to as "linking words."
[0307] In one configuration, a computer system stores facts in a database. The computer system provides an editorial function for a human author to generate a set of factors, which may include reasons, purposes, criteria, plots, etc. The computer system may also provide an editorial function for a human author to use a set of facts to generate a pre-defined narrative for each factor. Additionally, the computer system provides an editorial function for a human author to write links to the pre-defined narratives for each factor. The computer system may also store the pre-defined narratives for each factor. The pre-defined narratives include facts and links.
[0308] In one configuration, the computer system stores a preset description of one of the factors in a database. In this configuration, the preset description includes a link, the position of each fact within the description, and a storage location in the database used to store each fact. For example, a preset description might be "(Object 1) was involved in a car accident on (Object 2)". In this example, Object 1 and Object 2 are two facts. The computer system stores the entire sentence in a database, which includes the link "car accident" and the positions of Object 1 and Object 2 within the sentence. Additionally, the computer system stores the table names and column names for Object 1 and Object 2 in the database respectively.
[0309] Data fields with the same definition can be stored in the same database table. For example, the names of all patients are stored in the same database table listing all patients' names. Therefore, when two narratives of two cases are written using two different sets of facts, corresponding facts located in the same position within each of the respective narratives are in the same database table. When multiple database tables are used to generate a single fact, the database keywords used to link these multiple database tables can also be stored in the database. Therefore, when a new narrative of a new set of facts is generated using a pre-defined comment or narrative based on a set of old facts, the computer system identifies the corresponding facts and replaces the old facts with the corresponding new facts.
[0310] For example, Item 1 is stored in the "Patient Name" field of a Patient table, and Item 2 is the "Date" field of an Event table. In the example above, "Jack Daniel was in a car accident on January 20, 2018" and "Jim Beams was in a car accident on February 3, 2018" are based on the same narrative format but contain two different factual segments (e.g., patient name and event date). The linking word for these two events is the same, namely, "car accident occurred".
[0311] In one configuration, a computer system lists a set of factors, which may include reasons, purposes, criteria, plots, etc. The computer system allows a human author to select a factor based on a new set of facts to display a preset narrative. The human author can add, delete, or modify links to the narrative displayed by the computer system.
[0312] In one configuration, the computer system provides database search and editing functions, allowing a human author to add, delete, or modify facts and change their positions within a narrative displayed by the computer system. The human author can save the revised narrative as a new preset narrative, containing the facts, the positions of each fact segment, and links. The computer system stores database tables, keywords, and field information to retrieve the facts from the new preset narrative.
[0313] In one embodiment of the invention, a human author selects a factor to display a new pre-defined narrative based on a set of new facts and the same set of links stored in a database. A computer system extracts new fragments of the new facts based on their positions in the database, corresponding to previously existing fragments of the old facts. The computer system can then display the new facts within the links in the narrative based on the positions of the previously existing corresponding facts within the narrative.
[0314] In one configuration, the computer system provides a human author with the ability to add, delete, or modify links to new preset narratives displayed by the computer system. The human author can also add, delete, or modify facts and change their positions within the new preset narratives displayed by the computer system. The human author can then save the revised preset narrative as the next new preset narrative.
[0315] The above procedure can be repeated, allowing a human author to continue revising a pre-defined narrative based on a new set of facts and storing the revised pre-defined narrative as the next new pre-defined narrative. Due to this evolutionary process, future pre-defined narratives can be tailored to the preferences of human authors.
[0316] In one embodiment of the invention, a statement is considered mature for the selected factors if a human author has not modified the narrative of different cases using different sets of facts for a predefined number of case items based on the same factors selected by the human author. The predefined number may be defined by a person and / or a computer system.
[0317] In a configuration, a link is considered mature for the selected factor if the human author has not yet modified the link displayed by the computer system for different cases using different sets of facts for a predefined number of cases based on the same factor selected by the human author. The predefined number of cases can be defined by one person and / or one computer system.
[0318] In one configuration, if a narrative is mature for a factor selected by a human author, the computer system automatically skips or suggests that the human author skip the narrative review process and uses the current preset narrative as the standard narrative format to generate a report for the selected factor. The standard narrative format contains facts that may differ in different reports and the same set of linking words that match the writing style (or preference) of the human author.
[0319] In one configuration, if a link word is mature for one of the factors selected by a human author, the computer system automatically skips or suggests that the human author skip the narrative review process and uses the current preset link word as the standard link word to generate a report for one of the selected factors.
[0320] In one configuration, if a human author has selected multiple factors to write a report, the computer system uses the selected factors to generate a narrative segment for each factor and combines the multiple narrative segments based on the selected factors to generate the report.
[0321] An introductory section may be inserted at the beginning of the report. This introductory section contains facts and / or linking words. These facts and / or linking words may be revised by human authors through multiple reports to ultimately match the writing skills (or preferences) of human authors based on the evolutionary process explained in this invention.
[0322] A link section can be inserted in the middle of the report. The link section contains facts and / or links that can be revised by human authors through multiple reports to ultimately match the writing skills (or preferences) of human authors based on the evolutionary process explained in this invention.
[0323] A conclusion section may be inserted at the end of the report. The conclusion section contains facts and / or links that can be revised by human authors through multiple reports to ultimately match the writing skills (or preferences) of human authors based on the evolutionary process explained in this invention.
[0324] As a result of this invention, the computer system learns the writing styles (or preferences) of various human authors and can automatically generate various reports based on the writing styles (or preferences) of various human authors.
[0325] One or more of the above examples are based on anti-money laundering applications in financial institutions. However, the present invention can also be applied to many other different types of applications for different organizations and purposes. For example, a government organization can use a smart alarm system to identify any employee who may potentially steal confidential information from the government. A school can use a smart alarm system to identify any student who may potentially drop out. A social networking company can use a smart alarm system to identify any member who may potentially engage in illegal activities on social networks. An employer can use a smart alarm system to identify any employee who may potentially resign. A marketing company can use a smart alarm system to identify a target of a potential business transaction. A smart alarm system can also be a mobile application used by a person to identify a potential stock or commodity for investment purposes. As a public health application, a smart alarm system can be a mobile application that monitors a person's health status and sends a message if a potential health problem is found. There are countless applications for smart alarm systems. The following procedure describes how to design and develop an intelligent alarm system to monitor one instance of a group of objects for any specific target.
[0326] In one configuration, a smart alert system assigns scores to various factors. Alternatively, the smart alert system assigns scores to different levels of influence for each factor. A level of influence for a factor is used to distinguish different degrees of influence of that factor. For example, sending a wire transfer is a risk factor considered for anti-money laundering purposes. However, the amount of the wire transfer in US dollars can have different influences. For example, a wire transfer amount from $0 to $10,000 may have a low money laundering risk level, while a wire transfer amount from $250,000 to $1,000,000 may have a high money laundering risk level. Factors can be based on data associated with objects that have a positive or negative impact on achieving the objective. The smart alert system assigns a score to each factor. The smart alert system can identify the possible levels of influence of factors in the data associated with objects that have a positive or negative impact on achieving the objective. The smart alert system assigns a score to different levels of influence for each factor. In one configuration, an intelligent alarm system generates a total score for each monitored object by summing all scores of factors or factor degrees associated with the object.
[0327] Intelligent alarm systems use a set of criteria based on different factors. These criteria may include factors derived from data associated with the object, the degree of those factors, and / or scores derived from data associated with the object. Alternatively, the criteria may be based on rules derived from a decision tree, specific categories associated with the object, an if-then conditional statement derived from a model trained on a free machine learning network, an if-then conditional statement derived from a behavioral pattern, an if-then conditional statement derived from a transaction pattern, factors established by a software module, and / or factors established by a user or designer of the system.
[0328] Using the methods described above, scenarios for an intelligent alarm system can be established in various ways. These scenarios may trigger alarms to generate potential cases, and each potential case may have one or more scenarios in its cause vector. The intelligent alarm system can list a group of potential cases triggered by one or more scenarios. Investigators can review potential cases to determine which cases are correctly affirmative and which are incorrectly affirmative. In addition, investigators can review current potential cases along with historical potential cases to determine which case combinations are correctly affirmative or incorrectly affirmative.
[0329] In one configuration, the intelligent alert system enables investigators to review the scenarios of potential cases to determine which scenarios result in a correct affirmative and which result in a false affirmative. The intelligent alert system also enables investigators to review the scenarios of current potential cases as well as those of historical potential cases to determine which scenarios result in a correct affirmative and which result in a false affirmative.
[0330] Although a combined cause vector is obtained from the combination of several cause vectors, the combined cause vector has the same form as a single cause vector. By definition, a combined cause vector is the cause vector of the combined cases. Therefore, the conditional probability P(S / cbv) of a combined cause vector and the conditional probability P(S / x) of a single cause vector can be calculated using a similar method.
[0331] Furthermore, although a causal vector (or a combination of causal vectors) may trigger a potential case for investigation, the reason for reporting that case may be based on a subset of the scenarios of the causal vector. To maintain the accuracy of posterior probability calculations, it is desirable to identify the subset of scenarios that form the true causal vector that is correctly affirmative.
[0332] The intelligent alert system enables investigators to review the details of a potential case to identify the root cause vector if the potential case is confirmed. If a combination of potential cases is confirmed, the investigator can review the details of the combined potential cases to identify the root cause vector. The intelligent alert system can store the investigation results of each potential case and its associated root cause vector (or root cause vector). As explained earlier, once the root cause vector is determined, the set of details constituting the root cause vector can be used to generate a narrative, automatically filling out an SAR form and sending the SAR form to FinCEN.
[0333] In a configuration, an intelligent alarm system stores the investigation results of a combined case and the associated combined cause vectors (or actual combined cause vectors) of the combined case. Each combined cause vector (or actual combined cause vector) may consist of one or more scenarios. Results and other information may be stored in a database or other data structure.
[0334] After investigators have used the smart alarm system for a certain period, the system accumulates a large amount of data related to the subjects. This data may include historical potential cases, historical investigation results (e.g., correct affirmations or incorrect affirmations), and associated cause vectors (or true cause vectors). Therefore, as the system is used more, its accuracy may improve. That is, the accuracy of the system can be improved through the accumulation of data.
[0335] For clarity, a cause vector or a true cause vector will generally be referred to as a cause vector in the following text. Furthermore, a cause vector will generally include both a cause vector and a combined cause vector. Therefore, a cause vector generally refers to a cause vector, a combined cause vector, a true cause vector, and / or a true combined cause vector.
[0336] In one configuration, once the amount of historical data exceeds a threshold, the system calculates the conditional probability of each causal vector. This threshold can be based on the number of actual cases, the number of potential cases, the data size, and / or other factors. The conditional probability of a causal vector over a given time period is calculated by dividing the number of correct affirmations triggered by the causal vector by the total number of potential cases triggered by the causal vector.
[0337] In one embodiment of the invention, when the conditional probability of a cause vector is lower than an erroneous affirmative rejection threshold, the intelligent alarm system will treat a potential case triggered by the cause vector as an erroneous affirmative rejection. The erroneous affirmative rejection threshold can be set by a software module, a system designer, a system tuner, and / or a system user.
[0338] In some cases, if a potential case triggered by a cause vector consistently has a low conditional probability, the scenario of the cause vector may not be properly defined. In such cases, the user adjusts the scenario of the cause vector so that it increases the probability of prediction. Intelligent alarm systems can prompt users to make these changes.
[0339] A smart alarm system can respond to a cause vector whose conditional probability is higher than a correct affirmative acceptance threshold, and treat a potential case triggered by the cause vector as a correct affirmative acceptance. The correct affirmative acceptance threshold can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0340] A vector with one element can be transformed into a combination of vectors. For example, vector A has three elements v1, v2, and v3. In this example, vector A can be a combination of three vectors (e.g., vector B with element v1, vector C with element v2, and vector D with element v3). For clarity, vector A is referred to as the parent vector. Vectors B, C, and D can be referred to as child vectors. In the following disclosure, the parent vector will be considered the parent vector.
[0341] The above examples assume a subvector has only one element. Typically, a subvector can have multiple elements. For example, vector A in the above examples could have a subvector with elements v1 and v2. Because elements can be included in the parent vector or excluded from the parent vector to form a subvector, a parent vector with N elements can have a total of 2N possible combinations, including the parent vector itself with all N elements and an empty vector with no elements. Therefore, a parent vector with N elements can have 2N-2 possible meaningful subvectors. Each element of a cause vector corresponds to a plot. When the element is 1, the corresponding plot is included. When the element is 0, the corresponding plot is excluded. A subset of the plots of the parent cause vector can form the plot of a subcause vector.
[0342] Generally, increasing the number of scenarios in a cause vector increases the conditional probability value of the cause vector. For example, if a first cause vector has only scenario A as its vector element and a second cause vector has both scenario A and scenario B as its vector elements, then the conditional probability value of the second cause vector should be the same as or higher than the conditional probability value of the first cause vector.
[0343] Therefore, a parent cause vector has a conditional probability value that is the same as or higher than any of its child vectors. That is, if a child vector already has a conditional probability value that is greater than the correct affirmative acceptance threshold, then the conditional probability value of the parent cause vector is also greater than the correct affirmative acceptance threshold.
[0344] In a configuration, when the conditional probability value of one of the subvectors of a cause vector is equal to or greater than a threshold value, the intelligent alarm system will accept a potential case triggered by the cause vector as a correct affirmative. The threshold value can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0345] A current potential case can be combined with a group of historical potential cases to form a combined cause vector. When the conditional probability value of one of the subvectors of the combined cause vector is equal to or greater than a threshold value, the intelligent alarm system can accept the combined cause vector of the potential case as a correct affirmative. The threshold value can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0346] Intelligent alarm systems may struggle to explore all possible combinations of historical potential cases to determine whether a specific combination of historical potential cases and one current potential case would satisfy an automatic positive acceptance criterion. Therefore, in a configuration, the intelligent alarm system accepts a combined cause vector as a positive acceptance when the conditional probability of one of the subvectors of the combined cause vector is equal to or greater than a threshold value. This threshold value can be set by a software module, a system designer, a system tuner, and / or a system user.
[0347] Typically, all potential cases related to an object are related to each other. Additionally, all potential cases related to a group of related objects are related to each other. For example, if five students live in the same dormitory, then all potential cases related to any one of these five students are related cases. The scope of relationships between related potential cases can be defined by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0348] If a smart alarm system has been used for an extended period, using all relevant potential cases may be impractical or ineffective. That is, the number of relevant potential cases may be excessive, thus reducing performance. Therefore, it may be desirable to limit the scope of relevant cases to a single time period. In a configuration, a combined cause vector can be generated from a current potential case occurring within a predefined time period and a group of relevant historical potential cases. When the conditional probability value of a subvector of the combined cause vector is equal to or greater than a threshold value, the smart alarm system can accept the combined cause vector as a correct affirmative. The threshold value can be set by a software module, a system designer, a system tuner, and / or a system user. The predefined time period can be set by a software module, a system designer, a system tuner, and / or a system user.
[0349] Intelligent alert systems provide investigators with an opportunity to investigate cases that were not automatically rejected as incorrect affirmations and were not automatically accepted as correct affirmations. The intelligent alert system records the investigation results for each potential case and the associated causal vectors for those cases. This information can be used to calculate the future conditional probability values of the causal vectors.
[0350] Because intelligent alarm systems continue to use survey results to further adjust future conditional probability values, they can self-adjust according to future environmental changes. The more potential cases an intelligent alarm system can handle without human interaction, the fewer potential cases are left for investigators to handle.
[0351] Intelligent alarm systems can exclude cases that are automatically accepted as correct affirmations or rejected as incorrect affirmations from the calculation of posterior probability values. This method avoids problems caused by positive feedback. For example, if a potential case triggered by a cause vector x has been automatically accepted as a correct affirmation, the conditional probability p(S / x) may increase if the outcome of this case is included in the calculation of the posterior probability value of cause vector x. Therefore, the next potential case triggered by cause vector x can be automatically accepted as a correct affirmation. The automatic acceptance of future potential cases triggered by cause vector x will continue because the posterior probability value continues to increase. In other words, once a potential case triggered by a cause vector has been automatically accepted as a correct affirmation, if the accepted case is included in the calculation of the posterior probability value of the cause vector, all future potential cases triggered by the same cause vector will be automatically accepted as correct affirmations. This is undesirable because this "no-return" procedure deprives the intelligent alarm system of the ability to readjust itself in the face of future environmental changes.
[0352] In one configuration, the intelligent alarm system does not automatically reject a potential case when the conditional probability value of the potential case is below the false positive rejection threshold. Therefore, an investigator can fine-tune the conditional probability value using this potential case. For reference, this case is referred to as a false positive validation case. The number, percentage, and / or frequency of false positive validation cases are determined by a person designing or tuning the software module and / or a user of the system.
[0353] Additionally, in some cases, when the conditional probability value of a potential case is higher than the correct affirmative acceptance threshold, the intelligent alarm system may not automatically accept the potential case as a correct affirmative acceptance. Therefore, an investigator can fine-tune the conditional probability value using this potential case. For clarity, this case is referred to as a correct affirmative verification case. The number, percentage, and / or frequency of correct affirmative verification cases are determined by a software module, a person designing or tuning the system, and / or a user of the system.
[0354] In some cases, specific objects are treated differently for different reasons. For example, some objects are placed on a "no-comparison list" or a "white list." A potential case associated with an object on this list can be treated as a false positive without any investigation. For example, placing a politician on a money laundering prevention system's "no-comparison list" may be a politically correct decision, regardless of what has been detected. Similarly, for other purposes, a potential case associated with an object on another list can be treated as a true positive without any investigation.
[0355] Because these cases are treated differently, they are considered outliers. It is expected that these outliers will be excluded from the calculation of the posterior probability value. Intelligent alerting systems can skip potential cases associated with an object on a "non-comparison list" or "white list." Skipped cases cannot be used when calculating the posterior probability value of the cause vector.
[0356] In some cases, an alarm triggered by a scenario concerning an object may become a false alarm because the scenario is unsuitable for monitoring that object. For example, a cash-intensive business may naturally have more cash than other types of businesses, and a scenario comparing the cash amounts of this business with other businesses may be meaningless and inappropriate. In such cases, an investigator can mark the scenario as checked against the object. This means that the scenario has already been checked against the object by an investigator, and if another alarm is triggered against the object by this scenario, no action needs to be taken. Therefore, a potential case triggered by a scenario with a checked status is also considered an outlier.
[0357] In one configuration, the intelligent alarm system skips a potential case associated with an object that has a verified state containing circumstances that could trigger a potential case. The intelligent alarm system does not include the skipped case in the calculation of the probability value after the cause vector.
[0358] When an investigator rejects a potential case as a false positive, the intelligent alert system prompts the investigator to determine whether the event that triggered the potential case should be marked as verified. If this event is not marked as verified, it may trigger another false positive in the future. Therefore, it is desirable to mark the event that should be verified when a potential case triggered by this event is determined to be a false positive.
[0359] The number of potential cases used to calculate a conditional probability value can also affect the reliability of that value. For example, if only one potential case has been triggered by a cause vector x and an investigator has accepted that potential case as a correct affirmative, the conditional probability p(S / x) may be unreliable, even if it has a value of 100%. However, if five potential cases have been triggered by a cause vector x and the conditional probability p(S / x) is 100%, then this conditional probability may be more reliable compared to previous instances.
[0360] When the conditional probability of a cause vector is less than a threshold A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than a threshold B, the intelligent alarm system can automatically reject one of the potential cases triggered by the cause vector as an erroneous affirmative. The thresholds A and B can be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0361] When the conditional probability of a cause vector is higher than threshold A, and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than threshold B, the intelligent alarm system will accept one of the potential cases triggered by the cause vector as a correct affirmative. Thresholds A and B can be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0362] It may be desirable for intelligent alert systems to automatically accept potential cases as correct affirmatives or reject them as incorrect affirmatives based on conditional probability thresholds, using different conditional probability thresholds for different categories of objects. For example, even if the conditional probability of a potential case related to an object suspected in a past SAR case is below the correct affirmative acceptance threshold, a financial institution may still submit an SAR for the current potential case.
[0363] In a configuration, the intelligent alarm system uses different correct affirmative acceptance thresholds and incorrect affirmative rejection thresholds for objects in different categories. These categories can be defined by a software module, a person designing or tuning the system, and / or a user of the system. In anti-money laundering applications, these categories may include a customer who is a suspect in a previous SAR, a customer matching an OFAC list, a customer matching a 314(a) list, a customer matching a list of high-profile political figures, a customer matching other watch lists, a high-risk customer, a medium-risk customer, a low-risk customer, a high-risk counterparty, a medium-risk counterparty, a low-risk counterparty, a high-risk country, a medium-risk country, a low-risk country, a high-risk area, a medium-risk area, a low-risk area, a high transaction amount, a medium transaction amount, a low transaction amount, etc.
[0364] Because these categories can also be factors (e.g., risk factors) used for score (e.g., risk score) assignment and calculation purposes, it is desirable to use different correct affirmative acceptance thresholds and incorrect affirmative rejection thresholds for different factors. In one embodiment of the invention, the intelligent alarm system allows a user to assign a correct affirmative acceptance threshold and an incorrect affirmative rejection threshold to each factor.
[0365] In one configuration, if the conditional probability of the cause vector is higher than one of the correct affirmative acceptance thresholds of the factors associated with a potential case, the intelligent alarm system will treat the potential case as a correct affirmative acceptance. If the conditional probability of the cause vector is lower than one of the incorrect affirmative rejection thresholds of the factors associated with a potential case, the intelligent alarm system may treat the potential case as an incorrect affirmative rejection.
[0366] This approach can be complex when many factors are involved. Therefore, it is desirable to select only a few key factors and assign different correct affirmative acceptance thresholds and false affirmative rejection thresholds. In one configuration, an intelligent alarm system allows a user to select a set of factors and assign a correct affirmative acceptance threshold to each selected factor. A user can also select a set of factors and assign a false affirmative rejection threshold to each selected factor.
[0367] Therefore, if the conditional probability of a causal vector is higher than one of the correct affirmative acceptance thresholds of the selected factors associated with a potential case triggered by the causal vector, the intelligent alarm system can treat the potential case as a correct affirmative acceptance. Conversely, if the conditional probability of a causal vector is lower than one of the incorrect affirmative rejection thresholds of the selected factors associated with a potential case triggered by the causal vector, the intelligent alarm system can treat the potential case as an incorrect affirmative rejection.
[0368] To increase accuracy, it is desirable that the total number of potential cases exceeds a threshold when calculating conditional probabilities. This threshold can be a number of cases or a time period. The user can set this threshold as needed.
[0369] In one configuration, the intelligent alarm system records potential cases, investigation results, associated causal vectors, and the date and time of the record. The intelligent alarm system can calculate the conditional probability of a causal vector x, which is the number of correct affirmatives triggered by causal vector x divided by the total number of potential cases triggered by causal vector x.
[0370] After calculating the conditional probability value, the intelligent alarm system also records additional values in a database, such as: (1) the number of correct affirmatives triggered by cause vector x at that time, (2) the total number of potential cases triggered by cause vector x at that time, and (3) the date and time of the calculation, which can be referred to as the last calculation time of cause vector x. Because these additional values are stored, the intelligent alarm system does not need to repeat the same calculation to obtain the same value again for cause vector x.
[0371] The intelligent alarm system can update the conditional probability of cause vector x, which is based on the sum of the number of correct affirmations triggered by cause vector x (before the last calculation time) and the number of correct affirmations triggered by cause vector x (after and including the last calculation time), divided by the total number of potential cases triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (after and including the last calculation time).
[0372] In the above calculations, the number of correct affirmations triggered by cause vector x (before the last calculation time) plus the number of correct affirmations triggered by cause vector x (after and including the last calculation time) is the same as the number of correct affirmations triggered by cause vector x at the current calculation time. Similarly, the total number of potential cases triggered by cause vector x (before the last calculation time) plus the total number of potential cases triggered by cause vector x (after and including the last calculation time) is the same as the total number of potential cases triggered by cause vector x at the current calculation time. Therefore, the above calculations will achieve the same conditional probability p(S / x), which is the number of correct affirmations triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.
[0373] The number of correct affirmatives triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (before the last calculation time) can be stored in a database after the final calculation of the conditional probability. Therefore, the intelligent alarm system can search the database to find these two values. Thus, the intelligent alarm system calculates two new values based on the potential cases detected after the last calculation time and including those detected at the last calculation time. This method reduces many calculations, thus reducing the amount of data stored in memory.
[0374] In one embodiment of the invention, once the conditional probability value has been calculated, in addition to potential cases, investigation results, and cause vector x, the intelligent alarm system also stores additional values, such as: (1) the number of correct affirmations triggered by cause vector x at that time, (2) the total number of potential cases triggered by cause vector x at that time, and (3) the date and time of the calculation, which can be referred to as the new last calculation time of cause vector x. Therefore, these values will simplify the next round of calculation of the conditional probability of potential cases triggered by cause vector x.
[0375] The above method can be further modified during the software coding process. In one embodiment of the invention, the intelligent alarm system maintains two counters for a cause vector x: one counter for the number of correct affirmations (NTPX) and the other counter for the number of potential cases (NPCX).
[0376] In one embodiment of the invention, the intelligent alarm system resets two counters, NTPX and NPCX, to zero to begin counting. As an example, a potential case triggered by cause vector x can be manually reviewed by an investigator and determined to be a correct affirmation. In this example, the intelligent alarm system increments the NTPX counter by 1 because the number of correct affirmations triggered by cause vector x through manual review has increased to 1. For this particular example, the system also increments the NPCX counter by 1 because the number of potential cases triggered by cause vector x has increased to 1.
[0377] As another example, a potential case triggered by cause vector x is manually reviewed by an investigator and determined to be a false positive. In this example, the intelligent alarm system increments the NTPX counter by 0 because the number of correct positives from manual review triggered by cause vector x has not yet increased, and increments the NPCX counter by 1 because the number of potential cases triggered by cause vector x has increased to 1.
[0378] In a configuration, the conditional probability p(S / x) of a new potential case triggered by the cause vector x is NTPX divided by NPCX. This method reduces the computational complexity of the conditional probability p(S / x) and simplifies the software coding workload.
[0379] Although a cause vector x is used in this example, the above method can be applied to any cause vector. A smart alarm system can have numerous pairs of counters, each pair corresponding to a cause vector. As explained earlier, the total number of pairs is finite because only a very small number of scenarios can coexist in the same cause vector to trigger a potential case.
[0380] By using the methods described above, intelligent alarm systems can reduce the amount of time spent on calculations. Furthermore, the accuracy of conditional probability values increases when more potential cases are used in the calculations to derive the conditional probability values.
[0381] Because intelligent alarm systems continue to learn from human workers, it is only a matter of time before the intelligent alarm system automatically detects an alarm, makes the decision to submit an SAR, fills out an SAR form, writes a description, and sends the SAR form to FinCEN. Intelligent alarm systems will reduce human resources and handle SAR compliance matters in a manner similar to how humans handle SAR compliance matters.
[0382] Although the detection of suspicious activity, the investigation of SAR cases, and the submission of suspicious activity reports are used as examples, the same set of methods in this invention can be used to handle the detection of currency transactions, the investigation of CTR cases, and the submission of currency transaction reports (CTRs) to FinCEN.
[0383] Similarly, the same set of methods in this invention can be used to handle the detection of potential OFAC matches, the investigation of potential matches, and the reporting of actual matches to the Foreign Assets Control Authority (OFAC). In these cases, the relative correlation (RC) value used to measure the degree of matching is equal to the risk score used to measure the degree of risk. Therefore, instead of using risk score-based scenarios, intelligent alarm systems can use RC-based scenarios.
[0384] The OFAC list is just one example among many regulatory lists. The same set of methods in this invention can be used to detect, investigate, and report matches against all types of regulatory lists, such as the 314(a) list, the list of refused visas, the list of high-profile political figures, and any other lists published by government organizations and / or non-governmental organizations. Those familiar with legal compliance requirements will understand that the set of methods in this invention can be used to detect, investigate, and report any entity complying with any type of regulatory reporting requirement.
[0385] As discussed, this invention describes functionality that can be implemented by an intelligent alarm system for various applications that may generate an alarm. A human can review the alarm and perform follow-up actions based on the review. In one configuration, the intelligent alarm system learns from human actions, makes decisions on behalf of the human, and performs follow-up actions on the human. Therefore, the intelligent alarm system reduces human workload and time, and can replace some or all of the humans in this application.
[0386] Typically, because a financial institution could suffer significant losses in a fraud case, it sets low thresholds in its intelligent alert systems to generate fraud alerts. These low thresholds generate an increased number of false positives. Investigating fraud alerts to distinguish between actual fraud and false positives is both laborious and time-consuming.
[0387] This invention relates to a computer system and network that rejects false affirmations and confirms true affirmations. In one configuration, the rejection of false affirmations and the confirmation of true affirmations can be automatic (e.g., without any human intervention). The rejection of false affirmations and the confirmation of true affirmations can improve fraud detection and reduce the harm caused by fraud (e.g., financial losses).
[0388] In one embodiment of the invention, in response to the detection of an alarm, a smart alarm system sends at least a portion of the transaction details to a consumer protection system. The alarm may be generated in response to a transaction between a payer and a payee. The payer may be a customer of a financial institution. The consumer protection system may be a computer system or a device interface. The transaction details may be transmitted via a communication channel. In this invention, a communication channel refers to a wired network (e.g., the Internet), a wireless network (e.g., a mobile phone network), and / or another type of communication channel. Unless otherwise indicated, transmissions between devices, individuals, systems, organizations, and / or other entities of this application may be performed via a communication channel.
[0389] Transaction details may include one or more of the following: a transaction date, a transaction time, a transaction amount, a payer's account number, a payer's routing number, a payer's card number, a payer's wallet number, a payer's phone number, a payer's email address, other contact information of the payer, a payer's personally identifiable information, a SWIFT code of the payer's bank, a payee's account number, a payee's routing number, a payee's card number, a payee's wallet number, a payee's phone number, a payee's email address, other contact information of the payee, a payee's personally identifiable information, a SWIFT code of the payee's bank, and other information that may be used to define the transaction. The payer may be an individual or an organization. The payee may be an individual or an organization.
[0390] In one embodiment of the invention, the consumer protection system sends a portion of the transaction details to the payer (e.g., a customer of a financial institution). This portion of the transaction details can be transmitted to the payer's device. The payer's device (e.g., device interface) may include, for example, a mobile phone, a tablet computer, a laptop computer, a computer system, etc. Transmission can be facilitated based on the payer's telephone number, email address, device interface address, and / or other contact information.
[0391] The payer can review portions of the transaction details to determine its validity. If the transaction is valid, the payer accepts it. Alternatively, if the transaction is invalid, the payer rejects it. The payer's input (e.g., confirmation or rejection) is transmitted from the payer's device to the consumer protection system via a communication channel.
[0392] In one embodiment of the invention, the consumer protection system sends the payer's response to a smart alarm system that generates a potential fraud alert. If the payer accepts the transaction, the smart alarm system rejects the alert as a false positive. If the payer refuses the transaction, the smart alarm system notifies the financial institution's transaction system to stop the transaction. The transaction-stopping procedure does not involve human interaction; that is, the procedure is automated. The smart alarm system can work in conjunction with the consumer protection system to stop fraud or reject a false alarm without any human intervention.
[0393] Furthermore, a payer's refusal of a transaction can indicate that a criminal may have stolen financial instruments, financial account information, identity, etc., from the payer. In such cases, the consumer protection system sends an alert to one or more devices associated with the financial institution, merchant, and any organization that has subscribed to services provided by the consumer protection system. Therefore, once a payer has refused a transaction, the payer is protected because the criminal cannot use the same method to commit another crime against the payer through the financial institution, merchant, or organization that has received the alert.
[0394] At any given time, all financial institutions, merchants, and organizations of any type that need to curb financial crime can subscribe to the alert service provided by the consumer protection system. This method can reduce or even eliminate many types of financial crime, such as cheque fraud, credit card fraud, debit card fraud, ATM fraud, online banking fraud, ACH fraud, remittance fraud, cryptocurrency fraud, and identity theft. Therefore, the overall volume of financial crime can be reduced.
[0395] Furthermore, in one embodiment of the invention, consumers and organizations can be encouraged to open accounts in the consumer protection system to become members of the system. In one configuration, during the account opening process, the consumer protection system collects a portion of the new member's identification information, such as name, date of birth, address, postal code, city, country of residence, etc.
[0396] In another embodiment of the invention, the consumer protection system collects financial instrument numbers and account numbers from a new member through a device interface, such as checking account numbers, savings account numbers, routing numbers, credit card numbers, debit card numbers, ATM card numbers, cryptocurrency wallet numbers, insurance account numbers, transaction account numbers, cryptocurrency wallet address numbers, and any other information that can identify a financial account, a financial instrument, or any financing instrument that can be used to conduct a transaction. To enhance security, the consumer protection system may collect all financial instrument numbers and account numbers of a member.
[0397] Additionally, a device interface can prompt new members to provide the expiration dates and descriptions of financial instruments, financial accounts, and financing instruments. Furthermore, the consumer protection system can also prompt the member to provide identification information about the member's device, such as telephone number, email address, device interface address, and IP address. The member can be an individual or an organization. This process, which uses information collected from the member, is called a "registration process" or "ownership registration process." The registration process may collect one or more of the following: identification information, financial instrument number and account number, expiration date and description, and device identification information.
[0398] Once a member has opened an account and completed the registration process in the Consumer Protection System, that member will be able to protect against many types of financial crimes. For example, an object (e.g., an individual or an organization) may use a credit card to conduct a transaction with an online merchant. The merchant receives the credit card information (e.g., number and expiry date) and transmits the credit card number information and a portion of the transaction details to the Consumer Protection System. The Consumer Protection System sends a portion of the transaction details to a device (e.g., a mobile phone) of a member whose credit card number matches the one provided by the object. The transaction details may be transmitted based on the device identification information of the member provided by that member.
[0399] The member can accept or reject the transaction via this device. If the member accepts the transaction, the consumer protection system notifies the merchant system that the transaction has been accepted by the registered owner of the credit card. The merchant system then proceeds to complete the transaction without fear of fraud.
[0400] Intelligent alert systems may not be used by all financial institutions because some may have their own proprietary systems. In the following example, the financial institution's system does not use an intelligent alert system. Furthermore, in this example, after the merchant's system submits a transaction to the financial institution's system for approval, the financial institution's system detects the transaction as a fraud alert. In response to the fraud alert, the financial institution's system can send a portion of the transaction details and the credit card number to the consumer protection system. Since the member has already accepted the transaction, there is no need to contact them again. The consumer protection system can notify the financial institution's system that the member has accepted the transaction. If there are no other issues, such as insufficient credit, the financial institution's system can proceed with approving the transaction. This process can be completed without any human intervention.
[0401] In one embodiment of this invention, if a member refuses a transaction through their device interface, the consumer protection system notifies the merchant system that the transaction has been refused by the registered owner of the credit card. Therefore, the merchant system refuses the transaction. In this process, no third-party human involvement is required in fraud prevention. The merchant system can work in conjunction with the consumer protection system to stop fraud without any human intervention.
[0402] In some cases, a member's refusal to transact may indicate that a fraudster has stolen financial instruments, financial account information, financing tools, identity, etc., from that member. In such situations, the consumer protection system sends an alert to one or more devices belonging to financial institutions, merchants, and / or organizations that have subscribed to the alert service provided by the consumer protection system. These devices communicate with their associated computer systems to prevent future financial crimes based on the alert. Therefore, once a member refuses a transaction, that member is protected because the perpetrator cannot use the same method to commit another crime against that member at a financial institution, merchant, or organization that has received the alert.
[0403] Although an online merchant is used in the above example, the same method can be applied to all types of merchants. Furthermore, although a credit card is used in the above example, other types of financial instruments, financial accounts, financing instruments, etc., can be used. For reference purposes, a definition of a device interface is provided in the [Summary of the Invention] section of this invention.
[0404] A cheque deposit fraud refers to a fraudulent case in which a person deposits a cheque and then quickly withdraws a large sum of cash based on the deposited cheque before the financial institution can discover that the cheque is invalid. Cheque deposit fraud is more likely to occur in financial institutions that do not retain deposited cheques before settlement.
[0405] As an example application of a consumer protection system, when an individual cashes (or deposits) a cheque at a financial institution (e.g., a bank, credit union, money services company), the financial institution sends the cheque account number, routing number, payee's name, cheque serial number, and the USD amount shown on the cheque to the consumer protection system. The consumer protection system then sends the payee's name, cheque serial number, and USD amount to a device (e.g., a mobile phone) that matches the cheque account number and routing number shown on the cheque provided by the individual. The payee's name, cheque serial number, and USD amount can be transmitted based on device identification information provided by that device to the computer protection system.
[0406] The member can accept or reject the transaction via the device. If the member accepts the transaction, the consumer protection system notifies the financial institution that the transaction has been accepted by the registered owner of the checking account. The financial institution then continues to cash (or deposit) the checks without fear of cheque fraud, cheque alteration fraud, or cheque deposit fraud.
[0407] In one embodiment of the invention, if a member refuses a transaction via the device interface, the consumer protection system notifies the financial institution that the transaction has been refused by the registered owner of the checking account. Therefore, the financial institution refuses the check offered by that member.
[0408] In addition, the consumer protection system will send an alert to one or more devices belonging to financial institutions, merchants, and / or organizations that have subscribed to the alert service provided by the consumer protection system. These devices communicate with their associated computer systems to prevent future financial crimes based on the alert.
[0409] For example, in one embodiment of the invention, when an object enters a password to conduct a cryptocurrency transaction based on a payer's wallet address, the cryptocurrency transaction system sends the payer's wallet address and a portion of the transaction details to a consumer protection system. The consumer protection system then sends a portion of the transaction details to the mobile phone of a member whose wallet address is registered in their account. This member can accept or reject the cryptocurrency transaction via a mobile application. The member's actions on their mobile phone (e.g., the member's response) can be sent back to the consumer protection system. The consumer protection system can then send the member's response to the cryptocurrency transaction system. Therefore, even if the object has entered the correct password, the cryptocurrency transaction system can still prevent the transaction if the member rejects it. On the other hand, if the member accepts the transaction and the object has entered the correct password, the cryptocurrency transaction system can complete the transaction. In one configuration, if the member denies access to a criminal's account, the consumer protection system will send an alert to the device interfaces of all alert subscribers to protect the member.
[0410] The examples provided above are not limited to a single mobile device. Consider other types of device interfaces. Furthermore, users can accept or reject a transaction through an application on the device interface. Transactions based on a virtual currency account can be used with any type of account (e.g., online banking account, insurance account, trading account, etc.), as long as the member has registered the account in a consumer protection system.
[0411] Financial institutions can also be members of a consumer protection system. In one configuration, a financial institution's computer system sends all addresses (e.g., phone numbers, email addresses, etc.), account names, and account numbers of its customers' device interfaces to the consumer protection system. The consumer protection system can then contact the customer via the device interface and prompt the customer to download an application on the device interface (e.g., mobile phone, computer, etc.). Additionally, the consumer protection system can prompt the customer to register their account numbers, financial instrument numbers, and other financial information through the application within the consumer protection system. In one embodiment of the invention, the consumer protection system verifies the information provided by the customer. Therefore, all such customers can become members of the consumer protection system.
[0412] Furthermore, if a customer discovers that their financial instruments (e.g., checkbooks, credit cards, debit cards, ATM cards, etc.) are lost or stolen, the customer can immediately notify the consumer protection system. In response, the consumer protection system instructs the financial institution's computer system to block all transactions associated with the lost or stolen financial instruments. As a result of this proactive action by the consumer, the financial institution and the merchant are protected by the consumer protection system without any human intervention.
[0413] In one possible scenario, all financial institutions, businesses, and organizations subscribe to the alert service provided by the consumer protection system. Therefore, the consumer protection system can automatically prevent criminals from committing crimes against financial institutions, consumers, businesses, and any organization without any human intervention.
[0414] Fraudsters can attempt to open accounts in consumer protection systems and register victims' financial instrument numbers, account numbers, and other financial information based on their contact information (e.g., phone numbers, email addresses). Therefore, internal fraud prevention within consumer protection systems is crucial.
[0415] In one embodiment of the invention, when a person attempts to open a membership account in the consumer protection system, their identification information is scanned against blacklists provided by various sources (such as an internal blacklist). If a match is found, the consumer protection system will not open the account.
[0416] In one embodiment of the invention, the consumer protection system periodically scans members against a regulatory list (such as the OFAC list, a list of rejected individuals, etc.). This functionality can be achieved using the popular PATRIOT OFFICER system, available from GlobalVision Systems in Chatsworth, California. The consumer protection system is not a financial institution and does not have the regulatory obligations of a financial institution. However, it is desirable to identify members on the regulatory list and notify the financial institution when a customer is identified as a member of the regulatory list.
[0417] This could be an additional service offered by the Consumer Protection System. In theory, if a financial institution ensures all its customers are members of the Consumer Protection System, it may not need to worry about compliance with regulatory requirements by scanning customers against regulatory lists. This service will incentivize financial institutions to cooperate with the Consumer Protection System. Smaller financial institutions can save on compliance costs by working with the Consumer Protection System.
[0418] In one embodiment of the invention, when a person attempts to open a membership account in a consumer protection system, the system requires the person to provide their device interface number (e.g., a mobile phone number). In another embodiment, the system sends a password to the device interface (e.g., mobile phone number) via a message and requests the person to enter the password into the interface provided by the system to open the account. If the person enters the correct password before it expires, they indeed possess the device interface (e.g., mobile phone). If the person cannot enter the correct password, something is amiss, and the system rejects the person's application to open an account. This provision ensures that one person cannot open an account for another and cannot frame another person as a fraudster.
[0419] In one embodiment of the invention, the consumer protection system intentionally sends a password to a different interface not used by the member to open a membership account. For example, if the member communicates with the consumer protection system via the Internet, the consumer protection system sends the password to the member's mobile phone. If the member communicates with the consumer protection system via a mobile application, the consumer protection system sends the password to the member's email address.
[0420] In one embodiment of the invention, the consumer protection system compares a mobile phone number and a person's name with the customer records of the mobile phone network operator providing mobile phone services to the mobile phone owner. An anomaly may be detected when the name of a person applying for a membership account in the consumer protection system differs from the name of a customer subscribing to mobile phone services. The name of the mobile phone service subscriber can be obtained from the mobile phone network operator's records. The consumer protection system may reject the person's application to open an account based on the anomaly.
[0421] Checking mobile network operator customer records can be time-consuming. In one embodiment of the invention, the consumer protection system first creates a member account and then checks the mobile network operator's customer records. If an existing member's name and mobile phone number do not match the mobile network operator's customer records, the consumer protection system can perform a background check on that member.
[0422] Typically, if suspicious activity is detected before a membership account is opened, the consumer protection system may reject the membership application. If suspicious activity is detected after a membership account is opened, the consumer protection system may conduct a background check on the member. In one embodiment of the invention, the consumer protection system does not provide any services to the member (e.g., freezes the account) until a background check has been successfully completed and the member has been proven innocent.
[0423] In one embodiment of the invention, the consumer protection system performs account ownership verification based on the method explained below. For example, if a member has registered four financial accounts A, B, C, and D in the consumer protection system, the system can transfer a first sum from account A and a second sum from account B, then transfer a third sum to account C and a fourth sum to account D. The consumer protection system requires the member to provide the correct values for A, B, C, and D, which are values randomly assigned by the system. If the member cannot provide the correct answers, the system performs a background check on that member.
[0424] Account ownership checks can be performed on any number of accounts, not limited to four. Using both "transfer out" and "transfer in" actions ensures that the member will not feel that the consumer protection system has taken money from them. However, either a "transfer out" or "transfer in" action is sufficient to check the account. For example, if a member needs to pay a membership fee, a "transfer out" action alone is sufficient to check the account.
[0425] Account ownership verification can be performed through other procedures. For example, if a member has only registered one financial account, the consumer protection system can transfer two amounts (e.g., X and Y) and require the member to provide the correct values for both amounts. After the member has provided the correct answers, the consumer protection system can transfer the combined value (e.g., X+Y) back to the financial account, ensuring that the member does not lose any funds.
[0426] In one configuration, the consumer protection system randomly generates a password equivalent to a dollar amount containing a dollar and a cent. The consumer protection system then sends this password to a transaction system, which uses the password value to conduct a transaction with the member's registered financial account.
[0427] In one embodiment of the invention, the consumer protection system prompts the member to enter a password through the member's device interface. If the password received from the member is the same password sent from the consumer protection system to the transaction system, the member can control the registered financial account. This procedure achieves the account verification objective.
[0428] For verification purposes, the password can be any number. However, a member may feel uncomfortable if a consumer protection system transfers a large sum of money from their registered financial account. Therefore, using a small number might be a good idea so that the member will not feel uncomfortable.
[0429] In one embodiment of the invention, the consumer protection system requires a new member to enter their current residential postal code. If the geographical location of the member's device interface (e.g., mobile phone) is far from the member's current residential postal code, the consumer protection system may perform a background check on the member.
[0430] In one embodiment of the invention, the consumer protection system can continuously monitor the geographical location of the device interface of a new member. The monitoring determines the amount of time the member's device interface has been geographically distant from a postal code. If this amount of time exceeds a threshold, the consumer protection system can perform a background check on the member.
[0431] In one embodiment of the present invention, when a member engages in a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's name or a portion thereof based on an official identification card provided by the member. If the name or portion thereof differs from or does not correspond to the member's name or portion thereof in the consumer protection system's records, the consumer protection system performs a background check on the member.
[0432] In one embodiment of the invention, when a member engages in a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's date of birth or a portion thereof, based on an official identification card provided by the member. If the date of birth or a portion thereof differs from or does not correspond to the member's date of birth or a portion thereof in the consumer protection system's records, the consumer protection system performs a background check on the member.
[0433] In one embodiment of the invention, if a member's background check fails, the consumer protection system may close that member's account. In one embodiment of the invention, if a background check reveals that a member is lying, the consumer protection system may close that member's account. In one embodiment of the invention, once the consumer protection system closes a member's account due to a fraudulent situation (e.g., a failed background check), the consumer protection system adds that member to its internal blacklist.
[0434] In one embodiment of the invention, the consumer protection system records timestamps of the registration of various financial instruments, financial accounts, financing instruments, financial information, etc., by the member. In another embodiment, the consumer protection system verifies the accuracy and ownership of the financial instruments, financial accounts, financing instruments, financial information, etc., registered by the member, and only begins providing services to a specific financial instrument, financial account, financing instrument, financial information, etc., after successful verification. Therefore, in the database of the consumer protection system, each financial instrument, financial account, financial information, etc., may have a "service commencement timestamp" that is different from or later than the "registration timestamp".
[0435] In one embodiment of the invention, if any of the registered financial instruments, financial accounts, financing instruments, financial information, or identity is incorrect, the consumer protection system may notify the member to make corrections. The consumer protection system monitors and records the number of corrections made by each member. In one embodiment of the invention, if the number of corrections exceeds a threshold, the consumer protection system may consider conducting a background check on the member.
[0436] In one embodiment of the invention, whenever a member registers a new financial instrument number, the consumer protection system scans the new financial instrument number against all financial instrument numbers of all members in a database. If any match is found, additional actions, such as a background check, can be performed. A financial instrument number can also refer to a financial account, a financing instrument, or other types of financial information. In one embodiment of the invention, the consumer protection system performs background checks on both the member registering the new financial instrument number and the member with a matching financial instrument number.
[0437] In one configuration, a financial institution sends a financial instrument number, a portion of the transaction details, and a device interface address (e.g., a mobile phone number) to a consumer protection system for verification purposes. In response, the consumer protection system compares the device interface address provided by the financial institution with that provided by a member. The member is identified based on the financial instrument number. If the member has a different device interface address, additional actions can be performed. In one embodiment of the invention, when the member's device interface address differs from the device interface address provided by the financial institution, the consumer protection system performs a background check on the member.
[0438] In one embodiment of the present invention, the method for detecting inconsistent device interface addresses can also be used to detect inconsistencies in other types of information, such as names and birthdates. If an inconsistency is detected, the consumer protection system performs a background check on the member with the inconsistent information.
[0439] When a consumer protection system receives a "verification inquiry" from a financial institution, a merchant, or another organization regarding a transaction associated with a specific financial instrument of a member, the inquiry results can indicate the accuracy of that financial instrument (or financial account, financing instrument, financial information, etc.). For example, if a member has frequently received transactions related to a financial instrument, and no financial institution, merchant, or other organization has complained about responses from that member, it further confirms that the member is the true owner of the financial instrument.
[0440] In one embodiment of the present invention, the consumer protection system records a member's inquiries into various financial instruments, the timestamps of those inquiries, and the results of those inquiries. Each result consists of two parts: one part is the member's answer of "yes" or "no," and the other part is whether the inquirer later complained about the answer provided by that member.
[0441] In one embodiment of the present invention, the consumer protection system records refunds and refund timestamps for a member's various financial instruments, financial accounts, financing instruments, financial information, etc. Merchants provide refund information through a device interface provided by the consumer protection system. If a member's refund amount exceeds a threshold, the consumer protection system can perform a background check on that member.
[0442] In one embodiment of the invention, the consumer protection system determines a member's trustworthiness based on their historical queries of all financial instruments, query timestamps, query results, refunds, and refund timestamps. In another embodiment, the consumer protection system establishes a credit score for each member. In yet another embodiment, the consumer protection system provides members' credit scores as a service to financial institutions, merchants, or other organizations.
[0443] A fraudster might attempt to take over a member's account by changing their contact information, device interface address, etc. Therefore, security measures should be implemented to protect the member from any changes to a member's contact information, device interface address, etc.
[0444] In one embodiment of the invention, when a member attempts to change their contact information, the consumer protection system asks a challenge question. In another embodiment of the invention, when a member attempts to open a membership account, a member designs a set of challenge questions. A challenge question should not have a "yes" or "no" answer. Therefore, it is a good idea to design a challenge question based on "who, where, what, when, how, etc."
[0445] In one embodiment of the invention, the consumer protection system uses a previous query history or a previous user action as a challenge question. For example, the question could be, "Which store required you to confirm a transaction through the consumer protection system around September 22nd?" Another example could be, "Which financial instrument did you register with the consumer protection system around January 16th?" If such a challenge question is used, the application running on the member's device interface (e.g., a mobile application) should only display a limited historical length (e.g., 7 days), preventing a fraudster from finding the answer to the challenge question from the application running on the device interface.
[0446] In one embodiment of the invention, the consumer protection system retains all historical records for a period of time, such as five years. For example, when a member replaces an old credit card number with a new one, the old credit card number and all related records (including the replacement date) are stored in a database. This record retention can also be handled by the PATRIOT OFFICER system, which is popular in the financial industry.
[0447] Although the consumer protection system does not process any financial transactions, its operation can be similar to that of a financial institution. Each member can be considered a customer. Each registered financial instrument, financial account, financing instrument, financial information, identification information, etc., can be considered an account under that customer's name. Each inquiry from a third party can be considered a type of transaction. Each inquiry result can be considered a type of transaction. Each refund can be considered a type of transaction. Each complaint from a third party about that member can be considered a type of transaction. Therefore, the intelligent alarm system can also be used to generate alerts based on data in the consumer protection system's database. Thus, the intelligent alarm system enables the consumer protection system to prevent fraud committed by members or potential members.
[0448] A person is typically identified by their name, date of birth, place of residence, and a unique government-issued identification number (such as a Social Security number, driver's license number, or passport number). However, some identifying information, such as the person's initials, is far from sufficient for identification purposes. Similarly, other information (such as the last four digits of a Social Security number or driver's license number, street number, the last four digits of a postal code, or the last digit of the month of birth) is also insufficient for identification purposes.
[0449] However, in one embodiment of the present invention, if several pieces of this identification information from the same object are combined together through a pre-agreed data manipulation procedure, they form an coded data set or an identity code, which can be used for identification purposes, even if no one understands the meaning of the identity code.
[0450] Similarly, in one embodiment of the present invention, to provide greater security and privacy, an advanced encryption technique is used to encrypt the identification information to form an identity code. If someone intentionally hides or destroys the key used for decryption, there may be no opportunity to recover the identification information behind the identity code.
[0451] In another application of this invention, we can combine the above-mentioned encryption and partial identification information encoding to form an identity code. The chance of recovering the original identification information from this identity code is practically zero. Although it is impossible to decode and / or decrypt an identity code to obtain the original identification information, two matched identity codes will indicate that the original identification information of the two objects corresponding to these matched identity codes can match each other with a very high probability.
[0452] For example, the probability of two people having the same last five digits in their Social Security number and driver's license number is 1 in 10 to the power of 10, or 1 in 10 billion. The probability of these two people having the same last two digits of their birth year is 1 in 10 to the power of 12, or 1 in 1 trillion. Furthermore, if these two people also have the same postal code, the probability becomes 1 in 10 to the power of 17, which may never actually happen. By combining this information through a pre-agreed data manipulation procedure, we can construct a coded dataset that becomes an identification code.
[0453] For a person with an English name, we can include, for example, the first two letters of the first name and the first two letters of the last name as part of the identification code. Although these four letters do not provide enough information about the person's name, adding these four letters to the identification code can substantially reduce the chance of two people having the same identification code.
[0454] Conventionally, in the computer industry, a single byte is used to represent an English letter. In one aspect of this invention, an English letter is transformed into another byte with a different meaning. For example, the letter A can be transformed into the letter W. This transformation has the effect of hiding the original meaning. For example, the name "John" can be transformed into "Oh!a". A person unfamiliar with the transformation rules would have no idea what "Oh!a" means. The byte generated by the transformation can be used to form an identity code that is unrelated to the original meaning before the transformation.
[0455] Some countries do not use English as their official language and may use one of multiple byte units to encode their languages (e.g., UTF-8, UTF-16, UTF-32, GB 18030, etc.). Modern POSIX documents define a "character" as a sequence of one or more bytes representing a single graphic symbol or control code. Therefore, regardless of the character encoding method used, languages used by different countries or cultures can consist of single tuples and multiple byte units. To avoid confusion, in this invention, a single tuple unit or a multiple byte unit is generally referred to as a character.
[0456] In one embodiment of the invention, a transformation converts each original multi-byte unit into a new multi-byte unit to hide the original meaning. The new multi-byte unit generated by this transformation can be used to form an identity code that hides the original meaning.
[0457] In another application of the invention, a transformation converts each byte in an original multi-byte unit into a new byte to hide the original meaning. The new multi-byte unit generated by this transformation can be used to form an identity code that hides the original meaning.
[0458] In another application of this invention, an algorithm decomposes the multi-byte units of the original group into a set of bytes. From this set of bytes, some bytes are selected and transformed into a different set of bytes. Their sequences are then reconfigured, and finally, they are reassembled to form a new set of multi-byte units. This new set of multi-byte units can be used to form an identity code that hides the original meaning. Those unfamiliar with the transformation rules will not understand what the multi-byte units of the original group are.
[0459] The methods described above for forming an identity code are merely some examples. Numerous methods exist for converting a set of bytes or multiple bytes (regardless of the language used) into an identity code. While it is theoretically possible to convert back to an identity code to recover some of the original bytes or multiple bytes, if only a small portion of the original bytes or multiple bytes are used for the conversion, the original information cannot be recovered.
[0460] Similarly, if we encrypt a sufficient amount of identification information to form an identity code, the chance of two people having the same identity code can be reduced to almost zero. For example, hashing (a type of encryption method) can encrypt the identification information of two objects. If the identification information of two objects stored in two databases has the same hash result (e.g., hash), then they are likely the same object.
[0461] The methods described above for forming an identity code using different types of transformation rules are just a few examples. Many possible transformation rules exist.
[0462] Transformations are generally classified into three types: many-to-one, one-to-many, or one-to-one. The input system of a transform is the source. The output system of a transform is the image. A many-to-one transform converts multiple different sources into the same image. A one-to-many transform converts a single source into multiple different images. Both many-to-one and one-to-many transforms can lead to confusion. Therefore, it is desirable to use a one-to-one transform, which converts a single source into a single image.
[0463] If we use a one-to-one transformation method to convert a sufficient amount of identification information for each object into a corresponding image dataset, then this image dataset can be used to identify the object, even if the image dataset does not contain any original identification information. Therefore, when two image datasets are identical, their corresponding source datasets are also identical. This means that these two matched image datasets may belong to the same object.
[0464] In one embodiment of the present invention, we use image data of an object to identify the object. The image data is generated by a one-to-one transformation of self-identification data. The image data of the object is also referred to as a symbol of object identification information, an object symbol, or an identification code.
[0465] When two parties discuss a matter based on the same identity code, they know they are discussing the same object. No third party can understand the true identity behind this identity code; thus, the privacy of that object is protected. An identity code can be used to identify any object, such as a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, equity, funds, confidential information, a financial instrument, a non-financial instrument, etc., while maintaining privacy.
[0466] In order to achieve the goal of both parties using the same one-to-one transformation method, in one aspect of the present invention, a pre-agreed rule or a set of pre-agreed rules is used to select, encode, configure, encrypt, transform and / or transform identification data fragments from an object to form an identity code, which is essentially unique to the object and conceptually serves as a public agent of the object's private identification data, a symbol of the object's private identification data, or a symbol of the object.
[0467] In one embodiment of the present invention, an identity code is established based on a relatively simple transformation of one of the private identification information (such as a direct sequence of only some specified individual numbers and letters selected from the original identification information).
[0468] In another embodiment of the invention, an identity code is established through a pre-agreed, relatively complex transformation of one of the specified numbers, letters, and bytes. This transformation may include known methods of data conversion, transformation, encryption, and / or encoding of selected identification data segments, thereby further protecting the privacy of the original identification data from unauthorized access.
[0469] Furthermore, because the identity code is generated using only a small and relatively meaningless portion of private information, even if that portion is recovered by a malicious third party, the privacy of the remaining identification information will be protected, and it will be impossible to steal the identity of the person in question.
[0470] In one embodiment of the invention, multiple computer systems are connected via a network (e.g., the Internet). Each of these computer systems may reside at an organization. In another embodiment of the invention, a central computer system is connected to the network to control the functions, mechanisms, and communications of the computer systems connected to the network.
[0471] In one embodiment of the invention, within each organization, a one-to-one transformation converts each customer's identification information into a unique identifier, which is a set of image data. All customer identifiers are stored in a database within each organization. Relationship information linking each identifier to its corresponding customer (e.g., account number, customer number, etc.) is also stored in the database.
[0472] In one embodiment of the invention, a computer interface is provided on various computer systems, allowing an individual within an organization to select any client and send the client's identification code to the central computer system of the network. The organization sending the identification code is referred to as the initiating organization or the sender of the identification code.
[0473] In one embodiment of the invention, when a central computer system receives an identification code from an initiating organization, the central computer system sends the identification code to all other computer systems on the network. Each of the other computer systems on the network scans the received identification code generated by the initiating organization against all identification codes stored in its database. These identification codes stored in the database are images or symbols representing the identification information of customers within the organization.
[0474] In one embodiment of the invention, if a match exists between the received identity code and an identity code stored in a database, the computer system of the organization with the match sends a message to the central computer system indicating that a match has been found within the organization. The organization with the matched identity code is referred to as the matched organization or the payee with a matched identity code.
[0475] In one embodiment of the present invention, a computer system with a matched identity code uses relationship information (e.g., account number, etc.) to identify the corresponding customer whose identification information has been converted into a matched identity code.
[0476] In one embodiment of the invention, the matching organization's computer system sends additional information associated with a customer having a matched identity code to a central computer system. This additional information may include background information and transaction details of the customer having the matched identity code.
[0477] In one embodiment of the invention, the central computer system sends additional information received from the computer system of the matched organization to the computer system of the initiator organization that sent the identity code.
[0478] In one embodiment of the invention, the initiating organization's computer system uses relationship information (e.g., customer number) to identify a customer whose identification information has been converted into an identity code. This customer is referred to as the initiating customer.
[0479] In one embodiment of the invention, the initiator organization's computer system sends additional information associated with the initiator's clients to a central computer system. This additional information may include background information and transaction details of the initiator's clients.
[0480] In one embodiment of the invention, the central computer system sends additional information associated with the initiator customer to the computer system of the matched organization. In another embodiment, the central computer system sends contact information of a contact person within the initiator organization to a contact person within the matched organization. In yet another embodiment, the central computer system sends contact information of a contact person within the matched organization to a contact person within the initiator organization. Therefore, users of the computer systems on this network can communicate with each other and coordinate their workloads regarding a common object represented by an identity code, without disclosing any identifying information about the user's own object that is unknown to other users.
[0481] In one embodiment of the invention, the initiator organization's computer system uses additional information received from matched clients from the matching organization, along with the initiator organization's own information, to perform an analysis that drives new information about the initiator client. For example, this new information may be related to potential fraudulent activities, money laundering, or crime involving the initiator client. It may also be related to a positive activity, such as anonymous donations. When more information is available from more data sources, a better analysis can be performed to produce better predictions, estimates, and conclusions.
[0482] Similarly, in one embodiment of the invention, the matching organization's computer system uses additional information received from the initiating organization's clients, along with the matching organization's own information, to perform an analysis that drives new information about a matched client. For example, this new information could be related to a potential fraudulent activity, money laundering activity, or crime involving a matched client.
[0483] In one embodiment of the invention, the computer system of an initiating organization sends an identity code and related information to a central computer system for verification. In another embodiment, the central computer system sends the identity code and related information received from the initiating organization to all other computer systems on the network. In another embodiment, the computer system of a matched organization uses the matched identity code to identify the matched customer and then verifies the accuracy of the received related information. In another embodiment, the computer system of the matched organization sends a message indicating whether the information related to the identity code is accurate to the central computer system. In yet another embodiment, the central computer system sends a message received from the matched initiator indicating whether the information related to the identity code is accurate to the initiating organization's computer system.
[0484] The above method has a broadcast effect. It can be used when the initiating organization is unaware of which other organizations might be able to verify the relevant information. Therefore, the central computer system sends the identification code to all other computer systems on the network.
[0485] Sometimes, the initiating organization knows which other organization can verify the relevant information. In such cases, in one embodiment of the present invention, the initiating organization's computer system sends an identification code, a piece of information to be verified, and identification information of a specific computer system on the network to a central computer system.
[0486] In one embodiment of the invention, the central computer system sends the identity code and related information received from the initiating organization to a specific computer system. In another embodiment, the specific computer system uses the matched identity code to identify the matched customer and then verifies the accuracy of the received related information. In another embodiment, the specific computer system sends a message indicating whether the information related to the identity code is accurate to the central computer system. In another embodiment, the central computer system sends a message received from the specific computer system indicating whether the information related to the identity code is accurate to the initiating organization's computer system. In yet another embodiment, instead of verifying the accuracy of the information related to the identity code, the initiating organization can request the matching organization to send specific information about the matched customer based on the identity code.
[0487] The above applications are extremely useful. For example, if a consumer applies for a new account with organization ABC and claims to have an account with bank XYZ, then if both organization ABC and bank XYZ are on the network of this invention, organization ABC can quickly verify the accuracy of the information provided by the consumer, even though the consumer's identification information is never transmitted through the network. Only any identification code that cannot be understood by a third party is transmitted through the network. The consumer's privacy is fully protected.
[0488] In one embodiment of the invention, to verify whether a consumer actually has an account with bank XYZ, organization ABC may request the consumer to provide an account number, recent transaction amount, recent transaction date, other recent activities, background information, or any other information that bank XYZ can store. Alternatively, in one embodiment of the invention, to verify whether a consumer actually has an account with bank XYZ, organization ABC may collect information from bank XYZ using the consumer's identification number, and then request the consumer to answer some questions based on that information. For example, the questions might be, "What was the last transaction amount in his / her account? What was the last transaction date?" If the consumer can correctly answer all such questions, then the consumer may have an account with bank XYZ.
[0489] Because some consumers may not have good memories, in one embodiment of the invention, the questions can be designed to have multiple choices. For example, the questions might ask the consumer to choose one digit from a five-digit number as the final transaction amount. In one embodiment of the invention, after the consumer has correctly answered a series of questions, organization ABC can feel confident in opening an account for the consumer, conducting a transaction, or fulfilling one of the consumer's requests without fear of identity theft.
[0490] In one embodiment of the invention, the computer system of an initiating organization sends an identification code and a set of requests to a central computer system, the set of requests potentially including information requests, action requests, or other types of requests. In another embodiment of the invention, the central computer system sends the identification code received from the initiating organization and the set of requests to all other computer systems on the network.
[0491] In one embodiment of the invention, a matched organization's computer system uses a matched identity code to identify a customer whose identification information corresponds to the identity code. In response to an information request, the matched organization's computer system collects the customer's information based on the request. In response to an action request, the matched organization's computer system instructs the matched organization's device interface to take the requested action.
[0492] In one embodiment of the invention, the computer system of the matched organization sends the collected information to the central computer system based on the matched identity code. In another embodiment of the invention, the central computer system sends the collected information to the computing system of the initiating organization based on the matched identity code.
[0493] The above applications can be used, for example, by law enforcement agencies. For instance, if a law enforcement agency (e.g., the FBI) needs information about a criminal named John Doe, it can send John Doe's identification code to all organizations connected to the network to collect information about him. These requests may include information such as address, phone number, email address, account balance, maximum remittance transaction amount, transaction date, recipient of the remittance, and remitter of the remittance. Government agencies can immediately collect all the information they need about John Doe from all organizations connected to the network, although John Doe's identifying information is never transmitted through the network. Only any identification code that cannot be understood by third parties is transmitted through the network. The government agency's collection of information about John Doe is confidential.
[0494] For example, if a law enforcement agency wishes to locate or arrest the criminal John Doe, the law enforcement agency may send John Doe's identification code to all organizations connected to the network and request them to freeze all of John Doe's accounts and stop all transactions with John Doe. All device interfaces instructed by the computer systems of the matched organizations to be controlled by such organizations freeze John Doe's account and stop John Doe's transactions, making it impossible for John Doe to survive in the modern computer-controlled world. It was only a matter of time before John Doe surrendered to law enforcement agencies. Because only any identification code incomprehensible to third parties has been transmitted over the Internet, the government agency's plan to find or arrest John Doe is confidential.
[0495] Notwithstanding the customer's use as an instance in the above interpretation, the application of the present invention may be applied to any tangible or intangible object, including a customer, employee, contractor, supplier, collectibles, intellectual property, trade secrets, and the like. Despite the use of background information and / or transactional information in the above explanations, any type of information may be used in the application of the present invention.
[0496] Application of the present invention A new private and confidential communication network for use in a computer system has been established. An ID code is used as a symbol to identify all objects that may reside in the database of a computer system connected to the network. The central computer system is the control and communication center for that network. When multiple computer systems have the same identity code, the communication can consist of a group of communications. When a pair of specific computer systems communicate with each other, that communication can also consist of one-point-to-point communication. Communication between a central computer system and a computer system on that network may be accomplished by electronic mail, a one-telephone call, file delivery protocol (FTP), network services, mobile applications, or any method of communication that can be used for computer communication purposes.
[0497] 1A illustrates an instance of an intelligent alarm system 500 (e.g., a device interface) and a computer network 600 (such as an LAN) according to the present invention. In one configuration, the intelligent alarm system 500 enables a BSA supervisor 100 , a law compliance supervisor 200 , an investigator 300 and other responsible persons 400 to follow different types of laws and regulations and send SAR cases directly to another computer system 700 at FinCEN.
[0498] The compliance officer 200 configures and / or adjusts the parameters of the intelligent alarm system 500 via computer network 600. The intelligent alarm system 500 uses an internal workflow function to send a potential case to the investigator 300 via computer network 600. After investigation, the investigator 300 sends the potential case and its investigation results to the intelligent alarm system 500 via computer network 600. The intelligent alarm system 500 uses an internal workflow function to send the potential case and investigation results to the BSA supervisor 100 via computer network 600 for approval. After the BSA supervisor 100 approves the investigation results, if the potential case is confirmed, the intelligent alarm system 500 receives approval from the BSA supervisor 100 via computer network 600. Then, the intelligent alarm system 500 sends the confirmed case to the computer system 700 at FinCEN.
[0499] In some financial institutions, the same person may hold multiple job roles. For example, one person may be a BSA manager, compliance manager, and investigator. In such cases, intelligent alert systems use their internal workflow functions to assign different tasks to the person based on their different roles at different stages of the workflow.
[0500] After learning from the experience of investigator 300, the intelligent alarm system 500 will become more intelligent and will automatically accept a potential case as a correct affirmative if the probability of that case becoming a correct affirmative is higher than a predefined value. In such cases, the intelligent alarm system 500 will directly send the correct affirmative to the computer system 700 at FinCEN without any third-party human intervention. The more investigator 300 uses the intelligent alarm system 500, the more intelligent it becomes. Over time, the intelligent alarm system 500 will handle most or all potential cases autonomously with minimal human intervention.
[0501] Figure 1B illustrates an example of a consumer protection computer system 1000 (e.g., a device interface) according to the present invention. In one configuration, the computer system 1000 is connected to three intelligent alarm systems 1501, 1502, and 1503 residing at three financial institutions, three merchant systems 1601, 1602, and 1603 residing at three merchant locations, and two consumers 1100 and 1200. These connections can be established via a network 1600, which can be a wired network and / or a wireless network. As an example, the intelligent alarm system 1503 is also connected to a financial institution system 1403 that processes transactions for the financial institutions. The connection between the intelligent alarm system 1503 and the financial institution system 1403 can be established via an internal network within the financial institution.
[0502] Figure 1C illustrates an example of a central computer system 3000 (e.g., a device interface) connected to a network of computer systems (e.g., device interfaces) according to the present invention. In one configuration, the central computer system 3000 is connected to three illicit proceeds tracking systems 3100, 3200, and 3300 residing at three financial institutions and an enforcement system 3400 residing at a government agency. These connections can be established via a network 3600, which can be a wired network and / or a wireless network (e.g., the Internet). Each of the illicit proceeds tracking system and the enforcement system is also connected to a user via an intranet within the organization. In this example, James 3101, Evelyn 3201, and Michael 3301 work for three different financial institutions. Lisa 3401 works for a government enforcement agency.
[0503] Figure 2 illustrates an example of a flowchart according to the present invention for opening an account for a new consumer 1100 in a consumer protection system. In one configuration, as shown in Figure 2 together with Figure 1B, at block 2001, a computer system (e.g., a device interface) 1000 receives identification information of the consumer (e.g., consumer 1100), such as a name and a mobile phone number, via a mobile application. At block 2002, the computer system 1000 receives the consumer's financial account number provided by consumer 1100. Additionally, at block 2003, the computer system 1000 receives the consumer's financial instrument number provided by consumer 1100. Thus, consumer 1100 has registered their financial account and financial instruments in the consumer protection system.
[0504] Because fraudsters may also attempt to open accounts in the consumer protection system based on false information, the consumer protection system should work with financial institutions that issue financial accounts and financial instruments to verify the accuracy of information provided by an applicant (such as Consumer 1100) (square 2004).
[0505] An alternative method (not shown in the flowchart) for verifying ownership of a financial account (or financial instrument) registered by consumer 1100 involves computer system 1000 sending a randomly generated password to a transaction system. The transaction system then performs a transaction with the registered financial account (or financial instrument) based on the password value. Next, computer system 1000 prompts consumer 1100 to enter the password into a mobile application. If consumer 1100 correctly enters the password, then consumer 1100 has the necessary control over the financial account (or financial instrument) and can be considered the owner of the financial account (or financial instrument).
[0506] A...
Claims
1. A computer implementation method for privately and confidentially sharing information within a network of computer systems through a central computer system, comprising: A second computer system within the network of the computer system electronically encrypts the identification information of each object stored in the second computer system into a unique identifier, each unique identifier protecting the privacy of each object; the second computer system receives a first identifier from the central computer system within the network of the computer system, the first identifier being derived from the encryption of the first identification information of a first object in the first computer system within the network of the computer system, the first identifier protecting the privacy of the first object; in response to receiving the first identifier from the central computer system, the second computer system compares the first identifier with each unique identifier stored in the second computer system; and when the first identifier corresponds to a second identifier among the unique identifiers, the second computer system transmits a first message to the central computer system, the second identifier being associated with a second object stored in the second computer system.
2. The computer implementation method of claim 1, wherein the electronic encryption includes at least one of the following: hashing, selecting characters, encoding characters, configuring characters, recombining characters, encrypting characters, converting characters, decomposing characters into bytes, selecting bytes, converting bytes, reconfiguring byte sequences, recombining bytes into characters, encrypting bytes, or a combination thereof.
3. The computer implementation method of claim 1, wherein the first object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.
4. The computer implementation method of claim 1, wherein the second object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.
5. The computer implementation method of claim 1, wherein the central computer system includes a device interface.
6. The computer implementation method of claim 5, wherein the device interface includes at least one of the following: a keyboard, a keypad, a monitor, a display, a terminal, a computer, a control panel, a vehicle dashboard, a network interface, a mechanical interface, a video interface, an audio interface, an electrical interface, an electronic interface, a magnetic interface, an electromagnetic interface including an electromagnetic wave interface, an optical interface, a light interface, an acoustic interface, a contactless interface, a mobile phone interface, a smartphone interface, a smart laptop interface, a tablet computer interface, other communication device interfaces, a digital assistant (PDA) interface, a handheld device interface, a portable device interface, a wireless interface, a wired interface, or a combination thereof.
7. The computer implementation method of claim 1, wherein the first computer system includes a device interface.
8. The computer implementation method of claim 7, wherein the device interface includes at least one of the following: a keyboard, a keypad, a monitor, a display, a terminal, a computer, a control panel, a vehicle dashboard, a network interface, a mechanical interface, a video interface, an audio interface, an electrical interface, an electronic interface, a magnetic interface, an electromagnetic interface including an electromagnetic wave interface, an optical interface, a light interface, an acoustic interface, a contactless interface, a mobile phone interface, a smartphone interface, a smart laptop interface, a tablet computer interface, other communication device interfaces, a digital assistant (PDA) interface, a handheld device interface, a portable device interface, a wireless interface, a wired interface, or a combination thereof.
9. The computer implementation method of claim 1, wherein the second computer system includes a device interface.
10. The computer implementation method of claim 9, wherein the device interface includes at least one of the following: a keyboard, a keypad, a monitor, a display, a terminal, a computer, a control panel, a vehicle dashboard, a network interface, a mechanical interface, a video interface, an audio interface, an electrical interface, an electronic interface, a magnetic interface, an electromagnetic interface including an electromagnetic wave interface, an optical interface, a light interface, an acoustic interface, a contactless interface, a mobile phone interface, a smartphone interface, a smart laptop interface, a tablet computer interface, other communication device interfaces, a digital assistant (PDA) interface, a handheld device interface, a portable device interface, a wireless interface, a wired interface, or a combination thereof.
11. A financial intelligent computer system for privately and confidentially sharing information, comprising: At least one memory device; and at least one processor coupled to the at least one memory device, the at least one processor being configured to: electronically encrypt identification information of each object stored in the financial intelligent computer system into a unique identity code, each unique identity code protecting the privacy of each object; receive a first identity code from a central computer system, the first identity code being encrypted from first identification information of a first object in a first computer system, the first identity code protecting the privacy of the first object; in response to receiving the first identity code from the central computer system, compare the first identity code with each unique identity code stored in the financial intelligent computer system; and when the first identity code corresponds to a second identity code among the unique identity codes, transmit a first message to the central computer system, the second identity code being associated with a second object stored in the financial intelligent computer system.
12. The financial intelligent computer system of claim 11, wherein the at least one processor is configured to electronically encrypt the identification information by means of at least one of the following transformations: hash, select character, encode character, configure character, reassemble character, encrypt character, transform character, decompose character into byte array, select byte array, transform byte array, reconfigure byte array sequence, reassemble byte array into character, encrypt byte array, or a combination thereof.
13. The financial intelligent computer system of claim 11, wherein the first object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.
14. The financial intelligent computer system of claim 11, wherein the second object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.
15. A non-transitory computer-readable medium having code stored thereon for privately and confidentially managing information sharing, the code comprising: The program code is used to electronically encrypt the identification information of each object stored in a financial intelligent computer system into a unique identity code, each unique identity code protecting the privacy of each object; the program code is used to receive a first identity code from a central computer system, the first identity code being encrypted from the first identification information of a first object in a first computer system, the first identity code protecting the privacy of the first object; the program code is used to respond to the program code receiving the first identity code from the central computer system by comparing the first identity code with each unique identity code stored in the financial intelligent computer system; and the program code is used to transmit a first message to the central computer system when the first identity code corresponds to a second identity code among the unique identity codes, the second identity code being associated with a second object stored in the financial intelligent computer system.
16. The non-transitory computer-readable medium of claim 15, wherein the program code used for electronic encryption further includes program code that is transformed by at least one of the following: hashing, selection character, encoding character, configuration character, reassembly character, encryption character, conversion character, decomposing a character into bytes, selection byte, conversion byte, reconfiguring a sequence of bytes, reassembling bytes into characters, encryption byte, or a combination thereof.
17. The non-transitory computer-readable medium of claim 15, wherein the first object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.
18. The non-transitory computer-readable medium of claim 15, wherein the first object includes at least one of the following: a person, an object, an organization, a legal person, a tangible property, an intangible property, a document, a concept, a plan, a design, a revenue, an asset, a liability, a trade secret, an equity interest, funds, confidential information, a financial instrument, a non-financial instrument, or a combination thereof.