Computer-implemented method and computer system for protecting against financial crimes
Patent Information
- Application Number
- TW113126081
- Authority / Receiving Office
- TW · TW
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-03-17
- Filing Date
- 2020-03-25
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2040-03-24
AI Technical Summary
Existing methods for detecting financial crimes, particularly money laundering and terrorism financing, are inadequate as they rely on behavioral changes that may not be present, leading to missed detections and compliance failures with laws like the Bank Secrecy Act, resulting in significant financial losses and regulatory penalties.
A computer system that converts identification information into encrypted codes, shares them across networks to verify transactions, and uses data mining and risk scoring based on multiple factors to identify suspicious activities without disclosing customer information, enabling real-time monitoring and reporting of potential financial crimes.
Enhances the detection of financial crimes by reducing human error, minimizing resource waste, and improving compliance with regulatory requirements, thereby increasing profitability and reducing regulatory risks for financial institutions.
Smart Images

Figure TWG2TB001910181_001 
Figure TWG2TB001910181_002 
Figure TWG2TB001910181_003
Abstract
Description
Technical Field
[0001] The present invention generally relates to a consumer protection system and, more particularly, to enabling individuals, organizations, and financial institutions to protect themselves from various types of financial crime. Prior Art
[0002] Criminals and fraudsters have used numerous schemes to steal funds, financial instruments, and other valuables from individuals and organizations. Numerous methods have been proposed throughout history to prevent financial crime. However, criminals and fraudsters continue to thrive, and billions of dollars are lost annually to financial crime. A more effective solution is needed to prevent financial crime.
[0003] The United States Bank Secrecy Act (BSA), first enacted in 1970, requires financial institutions to report suspicious activity to the government. Historically, financial institutions have trained frontline personnel (e.g., bank tellers) to observe and identify suspicious activity. However, most financial institutions fail to effectively comply with the BSA. Following the tragedy of 9 / 11, U.S. lawmakers believed that effective compliance with the BSA could have prevented the tragedies of 9 / 11.
[0004] To further enforce the BSA, the US Congress passed the USA PATRIOT Act, which imposes severe civil and / or criminal penalties for BSA violations. Furthermore, US government agencies (such as the Financial Crimes Enforcement Network (FinCEN), the Office of the Commissioner of Financial Conduct (OCC), the Federal Reserve Bank (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), state banking departments, and financial institution departments) strictly require financial institutions to comply with the BSA, particularly regarding their obligation to submit suspicious activity reports (SARs) to FinCEN.
[0005] Suspicious activities cover a very broad range. For example, money laundering, terrorist financing, fraud, embezzlement, identity theft, computer intrusion, self-dealing, bribery, misrepresentation, counterfeiting, and unexplained disappearances are all classified as suspicious activities.
[0006] Yet, many financial institutions fail to detect and report suspicious activity. In fact, many financial institutions use products that are effective at preventing fraud but ineffective at preventing money laundering or other financial crimes. Fraud can often be detected based on behavioral changes, as a fraudster who has stolen a victim's identity (or financial instruments) behaves differently from the victim. A computer system can detect a fraud case if the activity on an account differs from what would be expected based on historical activity.
[0007] For example, U.S. Patent Application Publication No. 2003 / 0177087 states that a high-risk variable may include a change in an account's typical behavior, such as when a transaction exceeds its profile. According to this publication, Beta, Delta, and Theta models are used to detect transactions that exceed a client's profile.
[0008] However, money laundering and some other financial crimes can occur without any behavioral changes. Therefore, traditional fraud detection methods based on behavioral changes are unable to detect some basic money laundering activities or other financial crimes. In the context of money laundering, a high-risk customer may not appear suspicious. For example, money service businesses (MSBs), pawnshops, ATM vendors, and flight attendants are often classified as high-risk customers by banks in their money laundering prevention programs. However, this does not mean that these high-risk customers engage in money laundering activities. Although a high risk is associated with these customers, they may not have committed any crime.
[0009] Some businesses are extremely difficult to monitor. For example, an MSB processes a large number of transactions daily and may not be able to detect a single money laundering transaction intermingled with the bulk of the transactions using traditional methods.
[0010] The challenges of complying with the USA PATRIOT Act and the Bank Secrecy Act (BSA) are just a few examples of the importance of identifying suspicious activity. Identifying suspicious activity can also be used to comply with other laws, such as the Fair and Accurate Credit Transactions Act (FACT Act), the Unlawful Internet Gambling Enforcement Act (UIGEA), the Reporting of Elder Abuse Act (EARA), the Sarbanes-Oxley Act (SOX), regulations issued by the Office of Foreign Assets Control (OFAC), and other laws and regulations.
[0011] Traditionally, compliance has been implemented through policies and procedures that require human workers to take specific actions in response to specific conditions. For example, a bank trains its tellers in a branch to observe and report anything they consider suspicious regarding compliance with the Bank Secrecy Act.
[0012] This traditional approach is no longer effective in modern times because customers no longer need to be physically present at a bank branch. For example, customers can conduct transactions electronically remotely (e.g., via the internet), and a wide variety of financial instruments are available to customers (e.g., checks, credit cards, debit cards, etc.). Furthermore, criminals are highly skilled and know how to avoid attracting the attention of tellers. Therefore, relying on tellers to detect suspicious activity is insufficient for compliance with the Bank Secrecy Act.
[0013] Furthermore, this human-based approach is extremely expensive. Periodic and intensive training is required to ensure that human workers understand how to respond to various legal and regulatory situations. However, human workers are prone to error. In fact, due to human oversight, many financial institutions have been severely penalized by government agencies for failing to comply with various laws and regulations.
[0014] It is desirable to improve surveillance systems to improve detection of various types of suspicious activity and to help businesses comply with various laws and regulations. The methods, functions, embodiments, computer systems, networks, software, hardware, mechanisms, and other components for detecting suspicious activity may also be used in other applications or by other organizations for purposes other than detecting suspicious activity.
[0015] U.S. Patents 9,866,386, 9,288,197, 8,870,068, 8,500,011, 8,191,774, and 7,533,808 disclose computerized methods and apparatus for identifying a common subject of interest among multiple parties without disclosing the subject's true identity. However, products based on these patents have failed to attract user interest. This is primarily because compliance officers are very busy and lack the time to log onto a website to discover more information about a person with suspicious activity. This application discloses a computerized system and network that enables financial institutions to perform multi-year tasks with virtually no effort and without disclosing any confidential information about their customers. While an illegal proceeds tracking system is used as an example in this invention, the computerized system and network can be used in many other applications. Summary of the Invention
[0016] The present invention includes several embodiments that can be combined to form various computer systems and methods.
[0017] First, a computer system and method enable individuals and organizations to prevent financial crime by: receiving identification information of a first object from a first computer system; transforming the identification information of the first object into a first identity code that conceals the identification information of the first object; transmitting the first identity code to a second computer system; when the second computer system determines that the first identity code matches a second identity code transformed from a second object and stored in the second computer system, receiving a message from the second computer system, the second identity code concealing the identification information of the second object; transmitting a question associated with the message to the first computer system; receiving an answer to the question from the first computer system; and approving a request from the first computer system when the answer is correct. For example, when a computer system on a central computer system's network conducts a transaction with an object using a consumer's identity code, the central computer system communicates with the consumer's computer system so that the consumer can stop the transaction if it is unauthorized.
[0018] The computer system and method transform identification information into an identity code by at least one of: selecting characters, encoding characters, arranging characters, reassembling characters, encrypting characters, converting characters, decomposing characters into bytes, selecting bytes, converting bytes, rearranging a sequence of bytes, reassembling bytes into characters, encrypting bytes, or a combination thereof.
[0019] The computer system and method further enable individuals and organizations to prevent financial crime by: receiving a first account and contact information of the first computer system from the first computer system; receiving a second account and a request from a fourth computer system; transmitting the request to the first computer system based at least in part on the contact information of the first computer system when the first account matches the second account; receiving a response to the request from the first computer system; and transmitting a message corresponding to the response to the request to the fourth computer system.
[0020] In addition, the computer system and method enable individuals and organizations to prevent financial crime by: transmitting the first account number to a plurality of computer systems when the response indicates that the request has been denied.
[0021] In addition to the above computer systems and methods, a computer system enables individuals and organizations to prevent financial crime by performing the following steps: transmitting a second password to a second computer system; receiving a first password from a first computer system in response to transmitting the second password; receiving a first financial instrument number from the first computer system; receiving a second financial instrument number and a description of a transaction from a fourth computer system; transmitting the description of the transaction to the first computer system when the first password corresponds to the second password and the first financial instrument number matches the second financial instrument number; receiving a message from the first computer system in response to transmitting the description of the transaction; and transmitting an instruction corresponding to the message to the fourth computer system.
[0022] The computer system and method further enable individuals and organizations to protect against financial crime by transmitting the first financial instrument number to a plurality of computer systems when the message indicates that the transaction has been declined.
[0023] Additionally, a computer system and method enable a network of computer systems to privately and confidentially share information by: receiving from a first computer system a first identity code transformed from identification information of a first object, the first identity code concealing the identification information of the first object; transmitting the first identity code to a second computer system; receiving a message from the second computer system when the first identity code matches a second identity code transformed from identification information of a second object stored in the second computer system, the second identity code concealing the identification information of the second object; and performing an action in response to the message.
[0024] In addition, the computer system and method enable individuals and organizations to prevent financial crime by following the steps of: receiving identification information of a first object from a first computer system; converting the identification information of the first object into a first identity code; receiving a second identity code and a piece of information from a second computer system; when the first identity code corresponds to the second identity code, transmitting a question related to the piece of information to the first computer system; receiving an answer in response to the question from the first computer system; and transmitting a message corresponding to the answer to the second computer system.
[0025] The above computer systems and methods are merely examples. Many other computer systems and methods can be formed by combining and rearranging the embodiments of the present invention.
[0026] This has been a rather broad overview of the features and technical advantages of the present invention so that the detailed description that follows may be better understood. Additional features and advantages of the present invention will be described below. Those skilled in the art will appreciate that the present invention may readily serve as a basis for modifying or designing other structures for carrying out the same purposes of the present invention. Those skilled in the art will also recognize that such equivalent constructions do not depart from the teachings of the present invention as set forth in the accompanying claims. The novel features believed to be characteristic of the present invention (both in terms of its organization and method of operation), together with further objects and advantages, will be better understood from the following description when considered in conjunction with the accompanying drawings. It should be expressly understood, however, that each of the figures is provided for purposes of illustration and description only and is not intended as a definition of limitations of the present invention. Simple diagram description
[0027] The features, nature and advantages of the present invention will become more apparent from the following detailed description when read in conjunction with the accompanying drawings.
[0028] FIG. 1A illustrates a system and network diagram of a smart alarm system according to an aspect of the present invention.
[0029] FIG. 1B illustrates a system and network diagram of a consumer protection system according to aspects of the present invention.
[0030] FIG. 1C illustrates a system and network diagram of an illegal proceeds tracking system according to an aspect of the present invention.
[0031] 2 , 3 and 4 are flow charts of a consumer protection system according to an aspect of the present invention.
[0032] FIG5, FIG6 and FIG7 are flow charts of an illegal income tracking system according to an aspect of the present invention.
[0033] FIG8 is a flow chart of a consumer protection system according to an aspect of the present invention.
[0034] The detailed description set forth below, in conjunction with the accompanying drawings, is intended as a description of one of various configurations and is not intended to represent the only configuration in which the concepts described herein may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring the concepts. As described herein, the use of the term "or" may mean either an "inclusive OR" or an "exclusive OR," depending on the context of application based on common convention. Implementation Method
[0035] Cross-reference to related applications
[0036] This application claims the benefit of U.S. Patent Application No. 16 / 821,471, filed on March 17, 2021, and entitled “IDENTITY PROTECTION SYSTEM,” U.S. Patent Application No. 16 / 791,972, filed on February 14, 2020, and entitled “CONSUMER PROTECTION SYSTEM,” and U.S. Patent Application No. 16 / 791,993, filed on February 14, 2020, and entitled “ILLICIT PROCEEDS TRACKING SYSTEM,” which patent applications claim the benefit of U.S. Provisional Patent Application No. 62 / 823,305, filed on March 25, 2019, and entitled “CONSUMER PROTECTION SYSTEM,” the disclosures of which are expressly incorporated herein by reference in their entireties.
[0037] Some aspects of the present invention relate to a consumer protection system that enables financial institutions, merchants, individuals, and organizations to work together to prevent financial crime. Consumers are thus protected by this system. Other aspects of the present invention relate to an illicit proceeds tracking system that enables financial institutions to work together to prevent financial crime and recover funds stolen from the financial institutions.
[0038] Additionally, the consumer protection system works in conjunction with multiple Intelligent Alert Systems (IAS) that monitor transactions and activities of various businesses' customers to generate alerts. These IAS can be installed at financial institutions, merchants, or any other organization focused on preventing financial crime. More importantly, IAS learn from humans and can become more intelligent, automatically accepting potential cases as true positives and / or rejecting them as false positives, just like humans. Therefore, IAS can help financial institutions comply with various requirements, including laws, regulations, and rules, with minimal human resources.
[0039] In addition to the Bank Secrecy Act, smart alarm systems can also help organizations comply with numerous other laws and regulations with minimal human resources by monitoring transactions and activity. Depending on the specific requirements of these laws and regulations, smart alarm systems can monitor different types of activity using different methods. This invention provides details on how to monitor transactions and activity and help organizations comply with different types of requirements, laws, and regulations with minimal human resources. Furthermore, smart alarm systems can be used in other applications or by other organizations for other purposes, as explained above in the [Prior Art] section. Smart alarm systems reduce or eliminate human workload and errors, saving resources and money, and effectively achieving improved results.
[0040] Once the Smart Alert System detects a potential financial crime against an individual (or organization), it sends a description of the financial crime and the individual's (or organization's) contact information to a consumer protection system. The consumer protection system then contacts the individual (or organization) and asks them to verify whether the individual (or organization) is indeed a financial crime. The consumer protection system then sends feedback from the individual (or organization) to the Smart Alert System. If the case is a genuine financial crime, the Smart Alert System uses the feedback to prevent the financial crime; if not, the Smart Alert System dismisses the potential case as a false positive.
[0041] Furthermore, because the consumer protection system communicates with numerous intelligent alert systems residing at various financial institutions, it will receive feedback from numerous individuals and organizations that are customers of these financial institutions. This feedback information is also valuable to third parties (such as merchants) who wish to prevent future losses from similar financial crimes. These third parties would like to subscribe to the services provided by the consumer protection system, which is capable of providing feedback information.
[0042] The consumer protection system incorporates an alert system, and the subscriber is a third party, such as a merchant. Based on feedback from an individual (or organization), the consumer protection system can send an alert to the subscriber if a real crime has occurred. The third party will use this information to deter future crimes, preventing criminals or fraudsters from committing similar crimes against the individual or organization.
[0043] Many anti-money laundering professionals have realized that transaction monitoring cannot identify all money launderers. After obtaining illegal proceeds, criminals often move to another financial institution to re-establish discretionary control. These criminals pretend to be good citizens, and even after their illegal proceeds are deposited into a financial institution, the institution fails to detect any of their transactions as suspicious. A money launderer without a transaction monitoring system can be detected without suspicious transactions.
[0044] For example, John Doe, a customer of Financial Institution A in Los Angeles, disappears after defaulting on a $250,000 unsecured loan obtained through fraudulent misrepresentation. Subsequently, Financial Institution A, completely unaware of the $250,000, deposits the funds into an account John Doe opened several years earlier at Financial Institution B in San Francisco. If Financial Institution A knows that John Doe's ill-gotten gains are held at Financial Institution B, it can seize the proceeds from John Doe's account at Financial Institution B by issuing a prejudgment garnishment order.
[0045] However, the Gramm-Leach-Bliley Act in the United States and similar laws in other countries prohibit financial institutions from disclosing non-public personal information about their customers or members. Therefore, Financial Institution A cannot publicly disclose John Doe's name, and Financial Institution B cannot know that John Doe has stolen funds from Financial Institution B.
[0046] This application also discloses a system for tracking illegal proceeds that tracks John Doe without disclosing any personally identifiable information about John Doe. In the above scenario, when Financial Institution A tracks John Doe's illegal proceeds, Financial Institution B will receive an alert. Under Section 314(b) of the USA PATRIOT Act, Financial Institution A and Financial Institution B are fully protected by the safe harbor when discussing John Doe. Financial Institution A can obtain a prejudgment garnishment order from the court to seize John Doe's funds held at Financial Institution B.
[0047] According to the latest statistics released by the US government, the ratio of net loan losses to average total loans for all US banks was 0.47% in the third quarter of 2019. This figure is close to its historical low of 0.35%. The historical high was 3.12%. This means that even in the current favorable economic conditions, a "normal" financial institution that accepts deposits and makes loans could still incur loan losses of approximately 0.47% of total loan assets. For example, a financial institution with $1 billion in loan assets could incur loan losses of approximately $4.7 million. Because this figure is an average, some financial institutions may fare better while others may fare worse.
[0048] Typical annual profits for banks and credit unions range from 1% to 2.0% of total assets. Typical assets for banks and credit unions consist primarily of loans. Using an average of 1.5% as an example, even in a good economy, average loan losses (0.47%) are still about one-third of average profits (1.5%). This is why loan losses can keep senior managers and directors awake at night.
[0049] If a financial institution's credit department has done its job correctly, the most common cause of loan losses is misrepresentation by the borrower. Funds stolen from a borrower due to misrepresentation are legally classified as ill-gotten gains. If the BSA team can track the ill-gotten gains stolen from the financial institution, they can help the financial institution recover the stolen funds and significantly increase its overall profitability.
[0050] Therefore, in addition to identifying money launderers missed by AML transaction monitoring systems, illicit proceeds tracking can also substantially increase a financial institution's overall profitability.
[0051] Furthermore, if every financial institution tracks illegal proceeds after a criminal has committed a financial crime (such as money laundering, terrorism financing, Ponzi schemes, human trafficking, embezzlement, bank fraud, securities fraud, insurance fraud, and tax fraud), then criminals will be unable to launder the proceeds through any financial institution, as the Money Laundering Control Act, which covers hundreds of designated illegal activities, is required. This is the ultimate goal of anti-money laundering laws, regulations, and rules. The Illegal Proceeds Tracking System will achieve this goal.
[0052] The U.S. government strictly enforces compliance with the USA PATRIOT Act, the Bank Secrecy Act (BSA), the Fair and Accurate Credit Transactions Act (FACT Act), the Unlawful Internet Gambling Enforcement Act (UIGEA), the Elder Abuse Reporting Act (EARA), the Sarbanes-Oxley Act (SOX), regulations issued by the Office of Foreign Assets Control (OFAC), and other relevant laws and regulations. These companies include, for example, financial institutions such as banks, credit unions, mortgage companies, money service businesses, securities brokers, and insurance companies. The U.S. government has levied billions of dollars in civil penalties (CMPs) against financial institutions for violations of these laws and regulations. It has also imposed criminal penalties on some individuals working within financial institutions.
[0053] A financial institution is just one type of business. Financial institutions are not the only organizations required to comply with these laws and regulations. Many other types of businesses also need to comply with these laws and regulations. The present invention is applicable to all businesses, including those that are obligated to comply with laws and regulations.
[0054] The Financial Crimes Enforcement Network (FinCEN) and the Office of Foreign Assets Control (OFAC) are US organizations. US laws and regulations are used as examples in this disclosure. Many other countries have similar organizations that perform similar tasks. Consequently, many other countries have similar laws and regulations. This disclosure is also applicable to those countries to help businesses comply with their respective laws and regulations. Aspects of this disclosure can also be used by businesses, individuals, or organizations that do not need to comply with specific laws or regulations.
[0055] It can often be difficult to determine whether a person or group of people has engaged in illegal activity. Under the U.S. Bank Secrecy Act, when a business submits a Suspicious Activity Report (SAR) to FinCEN, it is not obligated to prove whether the reported activity is illegal. In fact, a "safe harbor" rule encourages businesses to report more suspicious activity without fear of being accused of falsely reporting legitimate activity as illegal. Under this "safe harbor" rule, a person (or organization) cannot bring a lawsuit against an entity simply because that entity filed a Suspicious Activity Report (SAR) with FinCEN regarding that person (or organization). The government uses a SAR to gather information and only expects a business to provide information and opinions in a SAR. Government agencies conduct their own investigations to determine whether the activity reported in a SAR is indeed illegal.
[0056] Typically, the decision-making process for reporting suspicious activity that isn't fraud differs from the decision-making process for reporting a fraud case. In a fraud case, an entity (such as a business or a consumer) may lose money. Therefore, fraud is easier to detect than other crimes. Consequently, deciding whether to report a fraud case is easier. Preventing fraud is also easier than preventing other crimes. For example, if a computer system detects a high risk of fraud associated with a transaction, the system may block the transaction and allow an investigator to investigate the transaction to determine whether it is indeed a fraud case.
[0057] In one aspect of the present invention, for fraud detection, a computer system calculates a risk score associated with a transaction based on various factors associated with the transaction. These factors may include historical account activity, deviations from expected activity, the location, time, amount, frequency, and nature of transactions, relationships between multiple accounts, and the type, nature, and structure of account holders.
[0058] In one aspect of the present invention, for fraud detection, a computer system blocks a transaction if the fraud risk score of the transaction exceeds a threshold value. The threshold value can be predetermined based on corporate policy.
[0059] In one aspect of the present invention, for fraud detection, a computer system generates a case based on detected high-risk fraud transactions. The case and related information are presented to an investigator for further investigation.
[0060] In contrast to fraud, suspicious activity may not present obvious evidence. For example, a customer may frequently deposit large amounts of cash. This customer may be engaging in money laundering by selling illegal items and accepting cash as payment. Alternatively, this customer may sell homemade products at a farmers' market and only accept cash as payment. Due diligence is generally required to determine if anything suspicious is occurring.
[0061] It's also possible that while a customer sells homemade products at a farmers' market, they also sell illegal items at other locations. Unless the bank is informed of the customer's sale of illegal items, there's no evidence to prove to the bank that the customer is selling illegal items. If the customer does sell illegal items and the bank fails to report this suspicious activity to FinCEN, if the customer is caught by the government selling illegal items, the bank could later face severe penalties for failing to report the case to FinCEN.
[0062] On the other hand, if a bank reports every case that might be suspicious, it may attract unnecessary attention from government agencies, which could spend months inside the bank investigating its operations and potentially severely impact its operations.
[0063] The decision to report a case can be a matter of instinctive judgment by the person reviewing the case. Furthermore, the decision-making process can be highly subjective. Furthermore, a business cannot block a transaction simply because it appears to be a suspicious money laundering activity. When a business cannot definitively prove that money laundering has occurred, a consumer can sue the business that blocked the consumer's transaction. In fact, many government agencies often advise businesses that have reported suspicious activity (such as money laundering or terrorist financing) to remain silent and treat the suspicious transactions as normal transactions, thereby ignoring the suspects and allowing them to abscond. This approach gives government agencies more time and opportunity to identify all relevant criminals.
[0064] Under the U.S. Bank Secrecy Act, a company that files a SAR is obligated to keep it confidential and not disclose any information about the SAR, including its existence, to the suspect (e.g., a person involved in the case). SARs can only be reviewed by authorized government agencies.
[0065] As described above, because handling a suspicious activity case is fundamentally different from handling a fraud case, many conventional methods and concepts applicable to fraud detection and prevention are no longer effective for detecting and managing suspicious activities (such as money laundering, terrorist financing, elder abuse, and online gambling). In one aspect of the present invention, a computer system records the opinions of individuals who decide not to report a detected suspicious activity case. In such cases, the decision maker records a reason for their decision.
[0066] Unlike a fraud case, a suspicious activity case may not be clear to the person reviewing the case until additional evidence becomes available. Therefore, a person may initially dismiss a detected suspicious activity case, but later change their mind when additional evidence becomes available. In one aspect of the present invention, a person reviewing a detected suspicious activity case may also need to review all historical detections related to the same suspect to determine whether any new evidence, when combined with any previous evidence that may have come from any dismissed cases, makes the new detection more suspicious. Therefore, even if a case was previously dismissed as a false positive, the dismissed case can still be reviewed later.
[0067] The review process for suspicious activity cases may differ from that for fraud cases because fraud cases typically have a definitive conclusion. If a customer is a fraudster, their account will be closed and they will be blocked from future transactions / activity. If a customer is a victim of fraud, the detected fraud case is not associated with the customer, and the evidence will not be used against them in the future. Therefore, a fraud investigator typically focuses only on newly detected cases. In contrast, a suspicious activity investigator may need to review a history of detected cases and make a decision after in-depth research and analysis. In one aspect of the present invention, the justification for a decision not to report suspicious activity is stored in a database and available for future reference.
[0068] In another aspect of the present invention, a computer system also records the identities of individuals who decide not to report a detected case. The computer system can compare decisions made by multiple individuals not to report suspicious activity by the same suspect(s) to determine whether an investigator is attempting to conceal a detected suspect or case.
[0069] For a large enterprise, thousands of suspicious activities may be detected each month. A group of individuals may be tasked with reviewing detected cases to determine whether the enterprise needs to file a SAR for them. In one aspect of the present invention, a computer system automatically assigns detected cases to different individuals based on enterprise-defined policies. The computer system monitors and records the status of each detected case. If a specific individual delays reviewing a case, the computer system alerts the enterprise to the delay.
[0070] In yet another aspect of the present invention, a computer system monitors the workload of individuals reviewing detected cases. If an individual has reviewed an unusually large number of cases compared to other individuals who also reviewed detected cases during the same time period, the individual themselves may become suspicious or problematic.
[0071] On the other hand, if an individual has reviewed a small number of cases compared to others who also reviewed cases during the same time period, that individual may also become suspicious or problematic. In either case, a manager at the company may want to investigate the situation and reach their own conclusions and resolutions.
[0072] Typically, different detection functions are used to detect suspicious activity because suspicious activity can occur in many different types of activity. Because the detection of suspicious activity is unclear, some detected cases may not be truly suspicious after investigation. In these cases, the detected cases are dismissed as false detections or false positives. A false detection or false positive is typically referred to as a conclusion of an investigation into a case, rather than as a reason to dismiss the case.
[0073] For example, if a financial institution detects a case in which several customers living at the same address deposited large amounts of cash into the institution, this case could be linked to a family of suspected drug traffickers, with multiple family members depositing their drug proceeds. However, upon investigation, this case could actually be a group of students living together and depositing tips from their jobs at a restaurant. The reasoning for not reporting this case could be that "the students living together were depositing tips from their part-time jobs." Thus, due to the given reason, the conclusion of the detected case becomes a false detection or false positive.
[0074] Typically, after reviewing a detected case, the case may be classified as a false positive (or a false positive) by the person reviewing the case. In one aspect of the present invention, a computer system provides a user with information and / or statistics to analyze all detected cases that have been classified as false positives. From these false positives, the user can identify detection functions that have generated a number of false positives greater than a threshold. The user can further refine the identified detection functions to improve future detection of suspicious activity.
[0075] Since 9 / 11, the USA PATRIOT Act, the Bank Secrecy Act (BSA), Anti-Money Laundering (AML), and the Anti-Terrorism Financing (ATF) have been crucial compliance requirements for the financial industry. Despite significant investments in these areas, many financial institutions continue to miss real money laundering and terrorist financing cases.
[0076] The primary reason for these compliance issues is that many financial institutions fail to detect even basic money laundering cases, and senior managers struggle to understand these issues. Many financial institutions use fraud detection principles to detect money laundering, and some even confuse fraud cases with money laundering cases.
[0077] However, in reality, money laundering and fraud are completely different. A fraud detection product can easily compare an account holder's current activity with the account holder's historical activity and detect possible fraud if the current activity deviates from the expected activity derived from historical activity. For example, if a fraudster steals a credit card from a victim, the fraudster will make purchases that differ from the victim's historical activity. The credit card company will detect the fraudulent activity, and it will only be a matter of time before the card is disabled. If a new account does not yet have sufficient history, a fraud detection product can compare the account holder's current activity with what the account holder said during the account opening process.
[0078] Because the goal of a fraud detection product is to prevent losses as quickly as possible, financial institutions typically run fraud detection or risk scoring on a real-time or at least daily basis. In contrast, real-time risk scoring, real-time detection, daily risk scoring, and daily detection methods, which are effective for fraud detection, fail to detect many basic money laundering activities. In fact, as explained above, a high-risk customer may not actually be a money launderer. Assuming a high-risk customer is engaging in suspected money laundering activities is a waste of time.
[0079] Financial institutions typically have a Bank Secrecy Act Officer (BSA Officer) responsible for reporting suspected money laundering or terrorist financing activity to FinCEN. The following example illustrates how a BSA Officer within a financial institution can waste significant time reviewing their real-time or daily risk scores and still miss a true case of money laundering. This example consists of the following facts: (a) Customer A wires less than $3,000 to XYZ on or about the 5th day of each month; (b) Customer B wires less than $3,000 to XYZ on or about the 8th day of each month; (c) Customer C wires less than $3,000 to XYZ on or about the 12th day of each month; (d) Customer D wires less than $3,000 to XYZ on or about the 17th day of each month; (e) Customer E wires less than $3,000 to XYZ on or about the 24th day of each month; (f) Customer F wires less than $3,000 to XYZ on or about the 29th day of each month; (g) A, B, C, D, E, and F are unrelated individuals; and (h) XYZ is a drug dealer in Los Angeles with no prior criminal record.
[0080] In the above example, if a BSA supervisor compares a customer's current activity with their historical activity to detect any behavioral changes, they won't detect any anomalies because the customer consistently performs similar transactions each month. If a bank teller asks the customer about the purpose of the funds transfer, the customer might easily lie. Because these customers perform their transactions on different days of the month, a BSA supervisor won't be able to detect any risk on any given day of the month.
[0081] Furthermore, these customers are unrelated, and therefore BSA officers will not be able to see their aggregate activity. Furthermore, because each transaction involves only a small dollar amount that occurs once a month, and the recipient of the funds resides in a US city with a large population and high commercial activity, these customers will not be considered high-risk or suspicious based on these transactions. Therefore, despite the BSA officers diligently working with a fraud detection product every day, the fraud detection product will miss these basic money laundering cases.
[0082] To detect these money laundering cases, in one configuration, a computer system collects transaction data from financial institutions and performs data mining based on money laundering and terrorism financing prevention scenarios across all transactions of all customers within a specified time period (e.g., 30 days or longer). A computer system can collect all funds transfer transaction details from various data sources within a financial institution (e.g., remittance, ACH, card payments, mobile payments, etc.). The computer system can then identify a common payee for these funds transfer transactions.
[0083] When a common payee is identified, the computer system displays all transactions sent to the common payee to the BSA Supervisor. The BSA Supervisor reviews the identified transactions through the computer system. The BSA Supervisor also reviews all historical cases related to the suspect in the newly detected case. If the BSA Supervisor (e.g., a principal) agrees that the transactions are suspicious because the common payee received excessive amounts of funds, the computer system assists the BSA Supervisor in filing a SAR with FinCEN. If the BSA Supervisor decides not to file a SAR, the BSA Supervisor enters a reason into the computer system to justify the decision not to report the detected activity.
[0084] There are several ways to report SAR cases to FinCEN. One method involves electronically sending the SAR report directly to a server located at FinCEN. In this case, a BSA supervisor can instruct a computer system that has detected suspicious activity to file a SAR report. The computer system will prepare a SAR report based on the suspect and transaction identified by the BSA supervisor and then transmit the SAR report to FinCEN's computer system.
[0085] As we can understand, even for a very small financial institution, data mining the vast amount of transaction data accumulated over a long period of time for all of its customers takes considerable time. Because a financial institution does not directly lose any funds in a money laundering case, regulatory guidelines allow a BSA supervisor a maximum of 30 days to submit a SAR. This example illustrates the waste of time and resources associated with performing real-time or daily risk scoring, which can miss actual money laundering activity.
[0086] BSA executives are generally frustrated by the time they waste each day making false positives at the expense of detecting actual money laundering cases. This frustration stems from a widespread misconception that money laundering and fraud are often committed by the same criminals and should be detected together based on detected behavioral changes. After purchasing fraud detection products, some financial institutions attempt to detect both money laundering and fraud cases simultaneously. This results in a significant waste of time, money, and resources. This misconception can be corrected through a proper understanding of the complex aspects of transaction risk.
[0087] Transaction risk is defined as the risk directly associated with a transaction. For example, money laundering risk and fraud risk are directly associated with transactions. However, these risks have distinct characteristics. Clients who launder money through financial institutions intend to use the financial institutions as a tool to achieve their goals. These money launderers often masquerade as high-quality clients because they require the financial institutions' assistance to complete their schemes. Money launderers do not mind paying additional fees or losing interest on their own funds, and therefore, from the perspective of financial institutions, they are desirable clients. This is a key reason why financial institutions need to conduct data mining on all transactions to detect hidden money laundering activities.
[0088] In contrast, fraud risk manifests itself in different ways. Fraud committed by customers is generally categorized into two categories: (1) third-party fraud; and (2) counterparty fraud. Third-party fraud is defined as fraud committed by a third party that is not the financial institution and is not the customer. For example, when a fraudster (e.g., a third party) steals a checkbook from a customer, both the financial institution (e.g., the first party) and the customer (e.g., the counterparty) may become victims. In such cases, the transactions conducted by the third-party fraudster have nothing to do with the customer. Therefore, when BSA executives are misled by an ineffective fraud detection product into assuming that a customer has engaged in money laundering simply because the customer was a victim of fraud committed by a third party (e.g., when there is a change in behavior), it is a waste of time, money, and resources.
[0089] Counterparty fraud is defined as fraud committed by a customer (e.g., the counterparty) who defrauds a financial institution (e.g., the first party). Once a customer successfully defrauds a financial institution, they quickly disappear without laundering funds through the institution. A fraudster might use Financial Institution A to launder funds stolen from Financial Institution B. For Financial Institution B, this is a fraud case. For Financial Institution A, this is a money laundering case. However, neither Financial Institution A nor Financial Institution B is aware of both the fraud and money laundering cases occurring with the same customer. Clearly, a system intended to systematically detect fraud cases daily generates numerous false positives for money laundering and misses actual money laundering cases. Using this approach increases the workload of BSA supervisors and exposes financial institutions to unnecessary regulatory risk.
[0090] Other risks exist within the third-party fraud category. For example, check forgery, credit card fraud, debit card fraud, ATM fraud, and online fraud are typical risks within the third-party fraud category. Similarly, counterparty fraud presents a wide variety of risks, such as bounced checks, deposit fraud, and loan fraud. Therefore, a well-established transaction risk management system utilizes multiple detection algorithms that intelligently consider the unique characteristics of various fraud types to successfully detect fraud.
[0091] Furthermore, as explained above, multiple customers can collectively launder money or finance terrorists by performing small transactions on different dates, and daily monitoring can miss these cases. This leads to the logical conclusion that a system that uses a single method to detect behavioral changes wastes resources and misses true money laundering and terrorist financing cases. In one aspect of the present invention, money laundering and terrorist financing activities are detected using a different detection method that mines data based on a user-defined scenario across all transactions accumulated over a period of time across the entire financial institution.
[0092] In one aspect of the present invention, a computer system uses multiple detection methods to monitor transactions and integrates the detection results into a centralized case management platform. This approach unifies and streamlines money laundering prevention, fraud prevention, and financial crime prevention to improve detection while maintaining a holistic, accurate picture. As a result, a financial institution can improve compliance with regulatory requirements, mitigate risk, avoid losses, improve productivity, reduce resources used to manage transaction risk, lower costs associated with hardware, databases, and software, reduce IT maintenance workload, and increase overall profitability.
[0093] In one aspect of the present invention, a computer system compares a transaction pattern of a customer (or a group of customers) with known money laundering transaction patterns to detect suspicious money laundering activity. If there is a match, a possible money laundering activity may have been detected.
[0094] For example, many criminals know that if more than $10,000 in cash is deposited into a bank account on the same day, the bank must file a Currency Transaction Report (CTR) with the US government. To avoid filing a CTR, criminals often split a large cash deposit into multiple smaller deposits, each made on a different date and less than $10,000. This transaction pattern is called "structuring" (a known money laundering transaction pattern), and a computer system can detect this type of transaction pattern. There are many other types of transaction patterns known as money laundering transaction patterns. A computer system can be designed to detect each of these known money laundering transaction patterns. Therefore, even if there is no behavioral change, a money laundering operation can still be detected based on the transaction pattern of a suspect or several suspects.
[0095] In one aspect of the present invention, the BSA Director (or Head) investigates the detected case to determine whether it is a true case of money laundering. In one aspect of the present invention, the BSA Director also reviews all historical cases related to the suspect(s) in the current detected case. In one aspect of the present invention, if the BSA Director agrees that the transactions are suspicious activity, the computer system assists the BSA Director in filing a SAR with FinCEN. In another aspect of the present invention, if the BSA Director decides not to file a SAR, the BSA Director enters a reason into the computer system to justify the decision not to report the detected activity.
[0096] In another aspect of the present invention, a group of customers sharing one or more common risk factors (or characteristics) (such as a business type, business model, organizational structure, size, location, products, services, occupational type, position, etc.) are compared to detect suspicious money laundering activity. If a customer's transaction activity (e.g., transaction pattern, transaction volume, transaction frequency, transaction trend, number of transactions, transaction amount, transaction derivatives, etc.) differs from that of other customers, then that customer may have engaged in suspicious money laundering activity. In one aspect of the present invention, statistics (such as mean, variance, standard deviation, etc.) of the group of customers are used to facilitate this comparison. Similarly, if a customer's behavior differs from other customers sharing the same set of risk factors (or characteristics), then that customer may have engaged in suspicious money laundering activity. Thus, even if no behavioral changes occur in any account, suspicious money laundering activity can still be detected.
[0097] Sometimes, it's not easy to compare a group of customers together. For example, an MSB with 100 branches may have significantly more cash activity than another MSB with only two branches. In one aspect of the present invention, to achieve a more effective comparison, it's useful to compare derivatives (e.g., ratios of numbers) instead of raw data. For example, a ratio might be "total cash withdrawals from a bank divided by the total number of checks deposited into the bank." In this example, the number of checks deposited can be used to measure the scale of an MSB's check cashing operations. Therefore, based on check cashing activity, the ratio "total cash withdrawals divided by the total number of checks deposited" essentially scales the check cashing operations of a 100-branch MSB and a 2-branch MSB to roughly the same level, allowing them to be compared on a more even footing.
[0098] Many other derivatives can be used to achieve a better comparison. Typically, a derivative for a more effective comparison might include "a first interest variable divided by a second variable measuring the size of the business (or operation). For example, "total ACH disbursement transaction amount divided by the total number of checks deposited," "total remittance disbursement transaction amount divided by the total number of checks deposited," "total number of prepaid cards issued divided by the total number of checks deposited," "total ACH disbursement transaction amount divided by the total number of branches," "total remittance disbursement transaction amount divided by the total number of branches," "total number of prepaid cards issued divided by the total number of branches," "total ACH disbursement transaction amount divided by the total number of prepaid cards issued," "total remittance disbursement transaction amount divided by the total number of prepaid cards issued," etc. are just a few examples of possible derivatives that can be used. In one aspect of the present invention, in addition to the above ratios, other forms of mathematical transformations can produce a derivative.
[0099] In one aspect of the present invention, a computer system compares a derivative of a specific customer with derivatives of a group of customers who share one or more common risk factors (or characteristics) with the specific customer (e.g., the same type of business or occupation). If the derivative of the specific customer deviates significantly from the derivatives of the group of customers, the specific customer may have engaged in suspected money laundering activity. In one aspect of the present invention, statistical analysis (such as mean, variance, standard deviation, etc.) of the group of customers facilitates this comparison.
[0100] In one aspect of the present invention, a computer system uses a number of different risk factors to determine the money laundering risk of each customer of a financial institution. For example, such risk factors may include an industry, category of customer, type of customer business, geographic region of customer, country of customer location, nature of customer business, product type of business, service type of business, structure of business, customer occupation, nationality, historical record (including compliance records, such as the number of currency transaction reports, the number of suspicious activity reports, matches with the OFAC list, matches with the OFAC list, matches with the 314(a) list, matches with the Politically Exposed Persons List, special designations under compliance programs, etc.), type of transactions conducted, account balances, fund inflows, fund outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, transaction frequency, transaction derivatives, location of transactions, time of transactions, country of transactions, remittance originator of a transfer transaction, location of remittance originator, country of remittance originator, nature of remittance originator, recipient of a transfer transaction, location of recipient, country of recipient, nature of recipient, relationships, social status, political visibility, historical transactions, etc. In fact, thousands of risk factors can be considered to determine a client's money laundering risk. For the purposes of this invention, a "risk factor" is also referred to as a "representative element of a risk dimension" or simply a "risk dimension."
[0101] According to aspects of the present invention, each attribute of a customer that may affect customer risk is a risk factor. Furthermore, each characteristic of a customer that may affect customer risk is a risk factor. Furthermore, each type of customer activity that may affect customer risk is a risk factor. Risk factors may also be influenced by other risks, such as information related to a customer, various types of transactions by a customer, and / or various transaction patterns of a customer. Each risk factor is assigned a risk value.
[0102] In one configuration, each level of the same type of risk is a risk factor and assigned a risk score. For example, the total cash transaction amount within a 30-day period can be used to measure the level of risk associated with money laundering. For example, we can define a total cash transaction amount level (or total cash transaction amount) from $0 to $5,000 during a 30-day period as having a risk score of 10; from $5,001 to $50,000 as having a risk score of 50; from $50,001 to $250,000 as having a risk score of 100; from $250,001 to $1,000,000 as having a risk score of 200; from $1,000,001 to $10,000,000 as having a risk score of 500; and $10,000,000 and above as having a risk score of 1,000. In this example, a person with a total cash transaction amount of $60,000 during a 30-day period is categorized as "between $50,001 and $250,000" and has a risk score of 100.
[0103] The "cash transaction amount" is used as an example only. Other considerations (such as the number of cash transactions and the speed of cash transactions) can also be used to measure the risk associated with money laundering. In addition to cash, other financial transactions (such as checks, remittances, ATMs, ACH, virtual currencies, virtual securities, virtual instruments, credit cards, debit cards, prepaid cards, monetary instruments, and transfers) can also be used to measure the risk associated with money laundering. Based on the above examples, those familiar with the technology can easily understand the numerous risk factors.
[0104] In one aspect of the present invention, a risk score-based scenario is based on customer data. Each piece of information about the customer is a risk factor and is assigned a risk score. Additionally or alternatively, a risk score-based scenario is based on transaction data. Each amount level (or amount amount) of a transaction type is a risk factor and is assigned a risk score.
[0105] In one aspect of the present invention, the customer information is associated with one or more of the following: an industry category of the customer, a business type of the customer, a geographic region of the customer, a country of address of the customer, a nature of a business of the customer, a product type of the business, a service type of the business, a structure of the business, an occupation of the customer, a nationality of the customer, a history record, a type of transaction performed, a balance of an account, funds inflow, funds outflow, a transaction pattern, a number of transactions, a transaction amount, a transaction frequency, a transaction derivative, a location of the transaction, a time of the transaction, a country of the transaction, a transfer transaction, remitter, location of the remitter, country of the remitter, nature of the remitter, recipient of a transfer transaction, location of the recipient, country of the recipient, nature of the recipient, a relationship, social status, political reputation, historical transactions, number of suspicious activity reports (SARs) filed for money laundering and terrorism financing cases, type of a first financial institution, type of business of the first financial institution, geographical region of the first financial institution, country of headquarters of the first financial institution, nature of the business of the first financial institution, age of a person, gender of the person, income level of the person, appearance of the person, judgment of the person, a person of the person status, the person's family status, a family member of the person, the status of a family member of the person, a friend of the person, the status of a friend of the person, a historical record of the person, an industry category of the person, a geographical area of the person, a country of address of the person, an occupation of the person, an employee's job type, an employee's education level, an employee's income level, years of employment in a current job, a performance evaluation record, employment history, the duration of each employment in the employment history, a reason for termination of each employment in the employment history, the employee's age, the employee's gender, an employee's personal status, the employee's family status, the employee's a family member, the status of a family member of the employee, the status of a friend of the employee, a history record of the employee, a type of work performed, a number of transactions performed, an amount of transactions performed, a maximum amount of transactions, a number of transactions with a specific counterparty, an amount of transactions with a specific counterparty, a number of changes to a key record, a number of changes to a key record associated with a specific counterparty, a geographic area of an employee's residence, a geographic area of an employee's office, a country of address of the employee, a due diligence result of the customer, a length of an account history, a number of matches to the name of a gambling organization in a transaction, or a combination thereof.
[0106] In one aspect of the invention, the transaction data is associated with one or more of: cash, check, wire transfer, ATM (automated teller machine), ACH (automated clearing house), virtual currency, virtual security, virtual instrument, credit card, debit card, prepaid card, electronic funds transfer, remittance, monetary instrument, letter of credit, bill, security, commercial bill, commodity, precious metal, account opening, account closing, account application, deposit, withdrawal, cancellation, balance check, inquiry, credit, debit, or a combination thereof.
[0107] In one aspect of the present invention, each risk factor is assigned a risk score, and a customer is assigned a total risk score. This total risk score is the sum of all risk scores for the risk factors associated with the customer. This process of generating a total risk score for each customer can be referred to as risk scoring. This total risk score is used to determine the risk level associated with the customer. A sum is used as an example in the present invention. In fact, many different types of mathematical transformations can also be used to achieve a similar effect.
[0108] In one aspect of the invention, each risk factor is assigned a risk score and a customer is assigned an overall risk score, the overall risk score being a value derived from a mathematical transformation of all risk scores of the risk factors associated with the customer.
[0109] As explained above, unlike in fraud cases, a higher-risk customer may not be a suspect in money laundering or terrorist financing. High risk may simply be a characteristic of the customer. For example, for money laundering and terrorist financing prevention purposes, MSBs, pawnshops, car dealerships, pilots, and flight attendants are often categorized as higher-risk customers. However, this does not necessarily mean that these customers are engaging in money laundering or terrorist financing activities.
[0110] However, because a customer has a high risk score, the customer may be monitored more closely and a different monitoring approach may be applied. Therefore, in one aspect of the present invention, the customer's overall risk score is used to determine the monitoring approach to be applied to the customer. If a customer's overall risk score is high, a more stringent monitoring approach may be applied to the customer. If a customer's overall risk score is low, a more relaxed monitoring approach may be applied to the customer.
[0111] In other words, in one aspect of the present invention, a customer's overall risk score is not used to determine whether the customer is suspicious. Instead, a customer's overall risk score is used to select an algorithm or a set of algorithms to monitor the customer.
[0112] Sometimes, a customer with a very high risk score may be suspicious. Therefore, in one aspect of the present invention, if a customer's overall risk score is above a predefined value, an alert is triggered regarding the customer, allowing investigators to investigate the potential case. The predefined value can be set by a software module, a person designing the system, a person tuning the system, a person using the system, or a combination thereof.
[0113] In one aspect of the present invention, a group of customers with the same risk factors are compared. For example, we can compare all customers who are flight attendants. In one aspect of the present invention, if the total risk score of a particular flight attendant is significantly higher than a reference value derived from the total risk scores of all flight attendants, then this particular flight attendant may have engaged in some suspicious money laundering activities. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0114] Statistical methods can also be applied to facilitate the detection of suspicious activity. For example, the mean, variance, and standard deviation can be derived from the overall risk score of all customers who are flight attendants. In one aspect of the present invention, if the overall risk score of a particular flight attendant is at least four times the standard deviation higher than the mean of the overall risk scores of all flight attendants, then that particular flight attendant may have engaged in suspicious activity.
[0115] The number "4 times" cited above is merely an example. The number "4" can be any number, such as 3.75, 4.21, or 10. In one aspect of the present invention, if a particular flight attendant's total risk score is more than x times the standard deviation of the mean total risk score for all flight attendants, then that particular flight attendant may have engaged in suspected money laundering activity, where x is a number assigned by the BSA Director (or a responsible person). This statistical method can be applied whenever a group comparison is used.
[0116] The use of a flight attendant is merely one example of a method for detecting suspected money laundering activity within a group of entities. In practice, numerous other risk factors can be used for similar purposes. Because there are tens of thousands of risk factors, in one aspect of the present invention, a computer system allows a user to select any risk factor to identify all customers with the same risk factor. In one aspect of the present invention, if a particular customer has a total risk score significantly higher than a reference value derived from the total risk scores of other customers with the same risk factor, the particular customer may have engaged in suspected money laundering activity. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0117] Instead of a single risk factor, a group of risk factors can be used. In fact, a group of risk factors can improve the accuracy of detection results. For example, in addition to the risk factor of occupation (e.g., flight attendant), the destination country of the flights on which the flight attendant works can be another useful risk factor for detecting money laundering risk. For example, a flight attendant working on a flight between New York and Chicago may have different activities than another flight attendant working on a flight between Miami and Mexico City. Comparing a subgroup of flight attendants working on flights between Miami and Mexico City may be more accurate. In this example, considering two risk factors (occupation and flight destination city) improves detection accuracy.
[0118] In one aspect of the present invention, a set of risk factors is used to identify a group of entities. If a particular entity has an overall risk score significantly higher than a reference value derived from the overall risk scores of all entities sharing the same set of risk factors, the particular entity may have engaged in suspected money laundering activity. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) that can be easily calculated using existing software development tools can be derived to facilitate comparisons within a group of entities. Thus, even if no behavioral changes occur in any account, a computer system can still detect suspected money laundering activity based on the above method.
[0119] Sometimes, it may be helpful to eliminate some entities from the group comparison because these entities are very different from other entities. In one aspect of the present invention, a computer system allows a user to select some entities that will not be included in a group comparison process.
[0120] Detecting suspected money laundering activity by a flight attendant is just one example. Similar methods can be applied to many other situations. For example, it is often very difficult for a bank or credit union to detect suspected money laundering or terrorist financing activity by a money services business (MSB) customer. This is because an MSB conducts numerous transactions daily, and a single money laundering transaction can be hidden among many other normal transactions.
[0121] In one aspect of the present invention, an additional risk factor (e.g., near the Mexican border) is used to identify a group of MSBs sharing the same set of risk factors (e.g., in addition to the first risk factor (business type)). If a particular MSB has a total risk score that is higher than a reference value derived from the total risk scores of all MSBs sharing the same set of risk factors, the MSB may have engaged in suspected money laundering activities. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Similarly, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate this comparison among a group of MSBs.
[0122] Comparing a group of MSBs is sometimes challenging because they may have different types of operations and sizes. In one aspect of the present invention, a part-time MSB and a full-time MSB are assigned two different risk factors because they may have different business natures. In another aspect of the present invention, different types of MSB products and / or services are each assigned a risk factor. For example, money transfers, check cashing, currency exchange, prepaid card management, etc., are each assigned a risk factor, even though they may all be provided by the same MSB. In one aspect of the present invention, a set of risk factors that precisely define the type of product and / or service is used to identify risk.
[0123] In one aspect of the present invention, adjusting some risk factors based on the scale of operations makes group comparisons more effective. For example, a MSB with 50 branches may naturally have five times the total cash transaction amount of another MSB with 10 branches. Sometimes, to make group comparisons, risk factors affected by operational scale can be adjusted to account for operational scale. For example, for an MSB with 50 branches, its total cash transaction amount over a 30-day period can be divided by 50 to establish an adjusted risk factor and a risk score for group comparisons. Branches are used here as an example to measure operational scale. Other information (such as the number of customers, number of transactions, number of employees, asset size, etc.) can also be used to measure operational scale.
[0124] In one aspect of the present invention, a set of risk factors (e.g., adjusted risk factors) adjusted based on operational scale is used to identify a group of entities with this set of adjusted risk factors. The risk score for an adjusted risk factor is referred to as the adjusted risk score. If a particular entity has a total adjusted risk score significantly higher than a reference value derived from the total adjusted risk scores of all entities with the same set of adjusted risk factors, the particular entity may have engaged in suspected money laundering activities. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Generally, in one aspect of the present invention, a detection algorithm that incorporates a risk factor can be modified to incorporate an adjusted risk factor. A detection algorithm that incorporates a risk score can also be modified to incorporate an adjusted risk score.
[0125] To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) based on the adjusted risk factor and the adjusted risk score can be derived to facilitate such comparisons among entities in a group. Thus, even if there are behavioral changes in any account, a computer system can still detect suspicious money laundering activity based on the above methods.
[0126] Because MSBs may have transactional activities that differ from other types of businesses, monitoring them based on their unique transactional activities is more effective. Therefore, in one aspect of the present invention, different sets of detection algorithms can be used to monitor entities with different sets of risk factors. In one aspect of the present invention, a set of risk factors is used to identify a group of entities with this set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activity among entities in this group. In other words, a set of detection algorithms is selected to monitor a group of entities based on the set of risk factors associated with that group of entities.
[0127] In another aspect of the present invention, a set of risk factors is adjusted based on the scale of operations and used to identify a group of entities with the adjusted set of risk factors, and a specific set of detection algorithms is used to detect suspicious money laundering activity among the entities in the group. In other words, a set of detection algorithms is selected to monitor a group of entities based on the set of adjusted risk factors associated with the entities.
[0128] Sometimes, it makes sense to monitor entities with higher risk more closely than entities with lower risk. Therefore, different sets of detection algorithms are used to monitor different entities with different risk levels. In one aspect of the present invention, a set of detection algorithms is selected to monitor an entity based on an overall risk score for the entity. In another aspect of the present invention, a set of detection algorithms is selected to monitor the entity based on an overall adjusted risk score for the entity, where the overall adjusted risk score is derived from risk scores adjusted for risk factors.
[0129] In one aspect of the present invention, upon detecting a possible money laundering activity by an MSB, a computer system may identify transactions (or a group of transactions) that result in the detected MSB having an aggregate risk score that is higher than a reference value derived from the aggregate risk scores of all MSBs. The reference value may include an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0130] Similarly, once an MSB is detected as potentially engaging in money laundering activities, a computer system identifies transactions (or a group of transactions) that result in the detected MSB having an aggregate adjusted risk score that is higher than a reference value derived from the aggregate adjusted risk scores of all MSBs. The reference value may include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Thus, a money laundering transaction (or a group of money laundering transactions) can be identified through this method. This method of identifying a specific transaction (or a group of transactions) with a higher risk score (or higher adjusted risk score) can be applied to other types of customers, not just MSBs.
[0131] Conventionally, a higher risk score implies a higher risk. However, there is no rule prohibiting a person or enterprise from defining a lower risk score for a higher risk. To avoid confusion, the description herein is based on the following convention: a higher risk score means a higher risk. Furthermore, a risk score can be a negative value. A negative risk score implies a reduced risk based on this convention.
[0132] As described above, an MSB is just one example. Other types of businesses (such as pawn shops, car dealerships, etc.) can be monitored in a similar manner. Therefore, even if there are no behavioral changes in any account, risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, and total adjusted risk scores can still be used in various ways to detect suspected money laundering activity.
[0133] In fact, a government or non-governmental agency (such as the OCC, FDIC, FRB, NCUA, FinCEN, SEC, FINRA, etc.) can monitor financial institutions (such as banks, credit unions, insurance companies, securities brokers, etc.) based on similar methods as described above for monitoring MSBs. Different risk factors, risk scores, adjusted risk factors, and adjusted risk scores can be defined for such monitoring purposes.
[0134] In one aspect of the present invention, a computer system uses a number of different risk factors to determine whether a financial institution complies with regulatory requirements for filing SARs to report money laundering and terrorist financing cases. For example, these risk factors may include the number of SARs filed for: money laundering and terrorist financing cases, type of financial institution, type of business of the financial institution, geographic region of the financial institution, country of headquarters of the financial institution, nature of the financial institution's business, product types of the business, service types of the business, structure of the business, customer profiles of the financial institution, historical records, types of transactions conducted, inflows, outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, frequency of transactions, derivatives of transactions, location of transactions, time of transactions, country of transactions, remittance of transfer transactions, location of remittance, country of remittance, nature of remittance, recipient of transfer transactions, location of recipient, country of recipient, nature of recipient, relationships, social status of the client, political profile of the client, political profile of the remittance, political profile of the recipient, historical transactions, etc. In fact, thousands of risk factors can be considered to determine a financial institution's compliance risk.
[0135] In one aspect of the present invention, the number of branches is used to adjust the risk factor and risk score. In another aspect of the present invention, asset size is used to adjust the risk factor and risk score. Many other factors may also be used to adjust the risk factor and risk score. In this current example, the "number of SARs filed" risk factor may have a negative value because the more SARs a financial institution files, the less likely it is that the financial institution will fail to file a SAR.
[0136] In one aspect of the present invention, a set of risk factors is adjusted based on the scale of operations and used to identify a group of banks with this set of adjusted risk factors. If a particular bank has a total adjusted risk score that is significantly higher than a reference value for the total adjusted risk scores of all banks with the same set of adjusted risk factors, the particular bank may not be meeting its compliance obligations to detect and report suspected money laundering and / or terrorist financing activities. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons among entities in a group.
[0137] Furthermore, different detection algorithms can be used to monitor different banks with different sets of risk factors. In one aspect of the present invention, a set of risk factors is used to identify a group of banks with the set of risk factors, and a specific set of detection algorithms is used to detect potential compliance oversight of banks in this group. Therefore, in one aspect of the present invention, a set of detection algorithms is selected to monitor a group of banks based on the set of risk factors associated with the group of banks.
[0138] In another aspect of the present invention, a set of risk factors is adjusted based on the scale of operations and used to identify a group of banks with these adjusted risk factors. A specific set of detection algorithms is then used to detect potential compliance oversight of banks in this group. In other words, a set of detection algorithms is selected to monitor a group of banks based on the set of adjusted risk factors associated with the banks.
[0139] While banks are used in the above examples, the same set of methods can be used to monitor credit unions, securities brokers, insurance companies, other financial institutions, and other types of businesses. Furthermore, the scope of monitoring is not limited to compliance with anti-money laundering and anti-terrorist financing regulations. In fact, all types of issues at all types of businesses can be monitored using the methods described in this invention by appropriately defining risk factors, risk scores, adjusted risk factors, adjusted risk scores, and detection algorithms associated with these issues.
[0140] MSBs also face the pressure of complying with numerous laws and regulations. However, unlike banks or credit unions, MSBs don't truly know who their customers are. A typical MSB provides money services to any consumer who walks into its offices. Even if an MSB collects identifying information from all of its customers, it may still be unable to accurately identify money laundering activity. For example, a consumer might use their Mexican passport to make a $7,000 transfer in the morning by paying an MSB cash, and then use their California driver's license to make another $8,000 transfer in the afternoon by paying the same MSB cash. Because two identifying documents are used, the same consumer could be considered two different individuals. An MSB could fail to file a currency transaction report as required by law because the same consumer has provided more than $10,000 in cash. This situation becomes even more complicated if the MSB has multiple branches, as the same consumer could visit different branches and conduct transactions based on different identifying documents.
[0141] In one aspect of the present invention, a computer system compares the names, phone numbers, addresses, dates of birth, etc. of all consumers who transact with an MSB to identify all transactions that may have been conducted by the same consumer. After identifying all transactions associated with a consumer, the computer system can detect suspicious money laundering activities associated with the consumer based on the transactions associated with the consumer.
[0142] In one aspect of the present invention, a BSA supervisor (e.g., someone tasked with investigation) investigates a detected case to determine whether it is a true money laundering case. The BSA supervisor also reviews all historical cases associated with the consumer in the newly detected case. If the BSA supervisor agrees that the detected case is a suspected money laundering case, the computer system assists the BSA supervisor in filing a SAR with FinCEN. If the BSA supervisor decides not to file a SAR, the BSA supervisor enters a reason into the computer system to justify their decision not to report the detected case.
[0143] Sometimes, a bank receives a wire transfer from a customer of Corresponding Bank A and retransmits it to another customer of Corresponding Bank B, because Corresponding Bank A and Corresponding Bank B do not have a direct banking relationship. This situation often occurs during international wire transfers, as banks in two different countries may not have a direct banking relationship. This type of wire transfer is often called an intermediary wire transfer.
[0144] A bank that provides intermediary wire transfer services is exposed to a significantly higher risk of money laundering because the sender and recipient of the intermediary wire transfer are not the bank's customers. Furthermore, the bank may not know the true backgrounds of the sender and recipient. A sender could be a terrorist financier, and a recipient could be a terrorist. A bank handling intermediary wire transfer services could unwittingly become a conduit for money laundering and terrorist financing.
[0145] In one configuration of the present invention, a computer system compares the names, addresses, countries, phone numbers, email addresses, etc. of all senders and recipients of intermediary wire transfers and identifies transactions associated with each sender and recipient. In one aspect of the present invention, if the computer system detects an unusually large number of wire transfers from the same sender, the sender and recipient may be involved in money laundering or terrorist financing activities. If the computer system detects an unusually large total amount of wire transfers from the same sender, the sender and recipient may be involved in money laundering.
[0146] Similarly, if the computer system detects an unusually large number of wire transfers to the same beneficiary, both the remitter and the beneficiary may be involved in money laundering or terrorist financing activities.
[0147] If the computer system detects an unusual number of wire transfers from the same remitter to the same beneficiary, the remitter and beneficiary may be involved in money laundering or terrorist financing activities. If the computer system detects an unusual total amount of wire transfers from the same remitter to the same beneficiary, the remitter and beneficiary may be involved in money laundering or terrorist financing activities.
[0148] In one aspect of the present invention, a BSA officer investigates the detected case to determine whether it is a true case of money laundering. The BSA officer also reviews all historical cases related to the suspect in the newly detected case. If the BSA officer agrees that suspected money laundering activity has occurred, the computer system assists the BSA officer in filing a SAR with FinCEN. If the BSA officer decides not to file a SAR, the BSA officer enters a reason into the computer system to justify the decision not to report the detected activity.
[0149] With a large proportion of the population rapidly aging, several states have recently enacted Elder Abuse Reporting Acts (EARA) to protect vulnerable elders. A senior citizen may often give money to a criminal because they were defrauded. Consequently, financial institutions are training their frontline staff to observe and report suspected cases of elder abuse. However, human-based methods are ineffective because transactions can be executed remotely and criminals can cleverly conceal their activities. Furthermore, human workers are prone to errors and mistakes. Relying on human workers to detect and report elder abuse cases is ineffective.
[0150] Many businesses store their customers' birthdates in a database. In one aspect of the present invention, a computer system collects birthdate information and identifies seniors over a predefined age. The system monitors all transactions of seniors and detects any changes in their activity.
[0151] For example, if an unusually large amount of money is transferred from an elderly person's account, a financial institution may want to investigate the purpose of the funds transfer. In one aspect of the present invention, if a check with an unusually large amount is deposited into an elderly person's account, a financial institution may want to investigate whether the elderly person was given a counterfeit check in exchange for their actual cash or assets. If an elderly person's account exhibits an unusual transaction pattern (e.g., unusual frequency or volume), a financial institution may want to investigate certain transactions. If an elderly person's account balance decreases rapidly, a financial institution may want to investigate transactions associated with that account.
[0152] In one aspect of the present invention, the risk factors, risk scores, adjusted risk factors, adjusted risk scores, total risk scores, total adjusted risk scores, statistical methods, and selected detection algorithms described above can be applied to detect possible cases of elder abuse. Because elder abuse differs from money laundering, a different set of risk factors and risk scores can be used for elder abuse detection. For example, these risk factors may include a person's age, gender, income level, appearance, judgment about the person, personal status, family status, family members, status of family members, friends, status of friends, history, industry, geographic region, country of residence, occupation, nationality, types of transactions performed, account balance, inflows, outflows, transaction patterns, number of transactions, transaction amounts, volume, frequency of transactions, derivatives of transactions, location of transactions, time of transactions, country of transactions, remittance of a transfer, location of the remittance, country of the remittance, nature of the remittance, recipient of a transfer, location of the recipient, country of the recipient, nature of the recipient, relationships, social status, political prominence, and historical transactions. In fact, many different risk factors can be considered to determine a person's risk of elder abuse.
[0153] For example, in one aspect of the present invention, a risk factor is used to identify a group of elderly individuals sharing the same risk factor. If a particular elderly individual has a total risk score that is higher than a reference value derived from the total risk scores of all elderly individuals sharing the same risk factor, the particular elderly individual may be a potential victim of elder abuse. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. In another aspect of the present invention, a set of risk factors is used to identify a group of elderly individuals sharing the set of risk factors. If a particular elderly individual has a total risk score that is higher than a reference value derived from the total risk scores of all elderly individuals sharing the same set of risk factors, the particular elderly individual may be a potential victim of elder abuse. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0154] To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate this comparison among entities in a group. Thus, even if there is no behavioral change in an account, a computer system can still detect a possible case of elder abuse based on the above method.
[0155] Typically, a company may have a compliance officer who is responsible for all compliance matters. In one aspect of the present invention, an investigator (e.g., a compliance officer) investigates a detected case to determine whether an actual elder abuse case has occurred. The compliance officer also reviews all historical cases associated with the elderly individual in the newly detected case. If the compliance officer agrees that the case is a possible elder abuse case, the computer system assists the compliance officer in reporting the detected case. If the compliance officer decides not to report the detected case, the compliance officer enters a reason into the computer system to justify their decision not to report the detected case.
[0156] Under the Sarbanes-Oxley (SOX) Act, certain companies (e.g., publicly traded companies) are required to implement internal control monitoring to prevent employee fraud. Traditionally, this internal control monitoring is performed by human workers (e.g., auditors) who spend several months each year auditing a company's financial records. This human-based approach is ineffective because human workers are prone to mistakes and errors. Furthermore, because auditing financial records takes so much time, it may be too late to prevent a crime.
[0157] In one aspect of the present invention, a computer system monitors accounting general ledger entries and detects any unusual patterns associated with the general ledger entries (e.g., unusual frequency, transaction volume, acceleration, etc.) to identify suspected internal fraudulent activity. For example, if the travel expense general ledger entry suddenly increases by 500% this month compared to the past 12 months, it is possible that some employees have abused their privileges and incurred unusual expenses.
[0158] In one aspect of the present invention, a computer system compares the current value of an accounting general ledger item with a reference value derived from historical values of the same accounting general ledger item over the past x months, where x is a predefined value. If the current value exceeds the reference value by a significant margin, it is possible that some employees have committed fraud. The reference value may include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. Further investigation may be conducted to determine why the general ledger item value deviates from its historical value.
[0159] In another aspect of the present invention, a computer system compares an employee's current activity with their historical activity to detect any changes. For example, if a loan officer has been issuing loans of unusually large amounts each month compared to historical monthly amounts, the loan officer's activity may be suspicious. If a loan officer has been issuing loans with loan amounts that are unusually large compared to historical amounts, the loan officer's activity may be suspicious. If a loan officer has been issuing loans of unusually large total amounts each month compared to historical monthly totals, the loan officer's activity may be suspicious.
[0160] Typically, an activity can be measured using a value called an activity value. For example, a loan officer's activity can be measured using the following: number of loans, maximum loan amount, total loan amount, average amount per loan, number of loans to the same customer, number of changes to loan records, number of changes to loan records for the same customer, frequency of changes to loan records, frequency of changes to loan records for the same customer, type of loan, etc. A bank teller's activity can be measured using the following: total number of transactions, total transaction amount, maximum transaction amount, average amount per transaction, type of transaction, number of customers transacting with the teller, average number of transactions per customer, number of transactions with the same customer, number of changes to customer records, number of changes to customer records for the same customer, frequency of changes to customer records, frequency of changes to customer records for the same customer, etc. In one aspect of the present invention, a computer system compares a current value for an activity with a reference value derived from historical values for the same activity. If the current value exceeds the reference value by a significant margin, the person performing the activity may have committed fraud. Further investigation may be conducted to determine whether the person has actually committed fraud. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0161] In one aspect of the present invention, a computer system compares an employee's activities with those of other employees with the same role in the business. For example, if a teller (or loan officer, etc.) behaves differently from other tellers (or loan officers, etc.) in the same branch, the teller (or loan officer, etc.) may be engaging in suspicious activity.
[0162] In one aspect of the present invention, a computer system compares an activity value of a specific employee with a reference value derived from all activity values of the same activity for all employees with the same responsibilities as the specific employee. When the specific employee's activity value deviates significantly from the reference value, the specific employee may have committed fraud. Further investigation may be conducted to determine whether the employee has indeed committed fraud. The reference value includes an average, a median, a mean, a mode, a weighted average, and / or other statistical values.
[0163] When comparing an employee to a group of employees, the statistical methods used in the flight attendant example described above can be applied. For example, a comprehensive set of risk factors associated with the employee can be identified and a risk score assigned to each risk factor. Thus, each employee has an overall risk score derived from a mathematical transformation (e.g., summation) of all risk scores associated with the employee.
[0164] The set of risk factors used to detect employee-related fraud may be different from the set of risk factors used to detect other types of suspicious activity, such as money laundering. For example, the risk factors used to detect employee fraud may include the employee's job type, the employee's education level, the employee's income level, years of employment in the current job, performance evaluation records, employment history, the duration of each employment in the employment history, the reason for termination of each employment in the employment history, the employee's age, the employee's gender, the employee's personal status, the employee's family status, the employee's family members, the status of the employee's family members, the status of the employee's friends, the employee's historical record, the type of work performed, the number of transactions performed, the amount of transactions performed, the maximum amount of a transaction, the number of transactions with a specific counterparty, the amount of transactions with a specific counterparty, The number of key record changes, the number of key record changes associated with a specific counterparty, the employee's geographic location of residence, the employee's geographic location of office, the employee's country of address, nationality, types of transactions performed, account balances, funds inflow, funds outflow, transaction type, number of transactions, transaction amount, transaction volume, transaction frequency, transaction derivatives, transaction location, transaction time, transaction country, remittance of a transfer transaction, remittance location, remittance country, remittance nature, remittance recipient of a transfer transaction, remittance location, remittance country, remittance nature, relationships, social status, political prominence, historical transactions, etc. In fact, numerous risk factors can be considered to determine employee fraud risk. In one aspect of the present invention, different sets of risk factors can be used to detect different types of suspicious activity.
[0165] In one aspect of the present invention, when a specific employee's total risk score exceeds the mean total risk score of all employees with the same risk factor as the specific employee by a significant margin, the specific employee may have engaged in suspicious activity. The significance margin can be set based on a number of standard deviations or other reference values.
[0166] Instead of using a single risk factor, multiple risk factors can be used to improve the accuracy of detection results. In one aspect of the present invention, if a particular employee's total risk score exceeds the mean total risk score of all employees with the same set of risk factors by a significant margin, the particular employee may be engaging in suspicious activity. In one example, the significance margin is set relative to a number of standard deviations or other reference values.
[0167] In fact, by identifying risk factors associated with a group of entities and appropriately assigning a risk score to each risk factor, a statistical method for identifying suspicious activity of a specific entity based on the overall risk score of each entity can be applied to many other situations besides money laundering, terrorist financing and employee fraud.
[0168] In one aspect of the present invention, multiple risk factors are associated with a group of entities. Each risk factor can be assigned a risk score. Each entity can be assigned an overall risk score based on a mathematical transformation, such as a summation. For example, other possible mathematical transformations include, but are not limited to, multiplication, division, and subtraction, sum of squares, sum of squares, combinations of these mathematical transformations, and other similar methods of combining risk scores.
[0169] In one aspect of the present invention, when the total risk score of a particular entity exceeds the average total risk score of all entities with the same risk factor as the particular entity by a predefined margin, the particular entity may have engaged in some suspicious activity. The predefined margin can be set based on a number of standard deviations or other reference values.
[0170] In another aspect of the present invention, if the total risk score of a specific entity is higher than the average of the total risk scores of all entities with the same set of risk factors as the specific entity by a predefined margin, the specific entity may have performed some suspicious activities.
[0171] In one aspect of the present invention, a computer system identifies a transaction (or a group of transactions) that has caused a particular entity to have an overall risk score that is higher than the average overall risk score of all entities. This transaction (or group of transactions) may be a suspicious activity.
[0172] The statistical methods mentioned are just one way to manage risk. Many other group comparison methods can also be used. Furthermore, suspicious activity may not be limited to illegal or prohibited activities. An activity becomes suspicious because it differs from normal activity. It may be harmless or even well-intentioned. Therefore, an investigation is often required to make the final decision on whether to report a detected case.
[0173] In one aspect of the present invention, a supervisor investigates a newly detected case to determine whether it is illegal. The supervisor also reviews all historical cases associated with the suspect(s) in the newly detected case. If the supervisor agrees that the detected case is illegal, a computer system assists the supervisor in reporting the detected case. If the supervisor decides not to report the detected case, the supervisor enters a reason into the computer system to justify their decision not to report the detected case.
[0174] Following the 9 / 11 tragedy, the U.S. Congress passed the Unlawful Internet Gambling Enforcement Act (UIGEA) because online gambling can be a tool for money laundering and terrorist financing. Regulation GG was enacted in response to UIGEA. Under Regulation GG, a financial institution is required to ask a new customer during the account opening process whether they will engage in any online gambling activities. Because criminals know that online gambling is illegal, they may lie during the account opening process. Therefore, the "inquiry" method defined in Regulation GG is merely a formality. However, Regulation GG explicitly states that it does not modify a financial institution's obligation to file a SAR under the Bank Secrecy Act.
[0175] In other words, if a criminal lies during the account opening process and actually operates an illegal online gambling operation, the financial institution is obligated to report the case to FinCEN via a SAR. In one aspect of the present invention, a computer system compares the sender and recipient of all funds transfer transactions during a period of time. If a customer has sent and received a large amount of funds from a single recipient during the same period, these transactions may represent deposits of wagering funds and payments earned from gambling activities between an online gambler and an online gambling organization. The computer system detects these cases as possible instances of illegal online gambling. Once a case is detected, further investigation is required.
[0176] In one aspect of the present invention, when a computer system detects a large number of transactions involving large dollar amounts associated with a customer, the computer system identifies the customer as a possible online gambling organization. This is because online gambling organizations typically handle large amounts of funds and a large number of customers. The computer system then identifies this case as a possible illegal online gambling case. Once a case is detected, further investigation is warranted.
[0177] In one aspect of the present invention, a computer system compares a list of known names of online gambling organizations with the sender and recipient of a customer's money transfer transaction. If a match is found, the customer may be involved in online gambling activities. The computer system detects this as a possible case of illegal online gambling. Once a case is detected, further investigation is required.
[0178] In addition to the aforementioned transaction pattern monitoring, the group comparison method described above can also be applied to detect possible illegal online gambling activities. In one aspect of the present invention, all risk factors associated with online gambling are identified. For example, these risk factors may include the customer's due diligence results, the length of their account history, the customer's industry category, the customer's business type, the number of matches with gambling organization names in transactions, the customer's geographic region, the customer's country of headquarters, the nature of their business, the product types of their business, the service types of their business, the structure of their business, their occupation, nationality, historical record, types of transactions conducted, account balances, fund inflows, fund outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, transaction frequency, transaction derivatives, number of chargebacks, transaction location, transaction time, transaction country, remittance of a transfer transaction, remittance location, remittance country, nature of the remittance, recipient of a transfer transaction, recipient location, recipient country, nature of the recipient, relationships, social status, political prominence, historical transactions, etc. In fact, many different risk factors can be considered to determine online gambling risk. As previously explained in this disclosure, adjusted risk factors can also be used, allowing for the application of an adjusted risk score based on the scale of the operation.
[0179] In one aspect of the present invention, a risk factor is used to identify a group of customers sharing the same risk factor. When a specific customer has a total risk score that is higher than a reference value derived from the total risk scores of all customers sharing the same risk factor, the specific customer is likely to engage in illegal online gambling. In another aspect of the present invention, a set of risk factors is used to identify a group of customers sharing the set of risk factors. If a specific customer has a total risk score that is higher than a reference value derived from the total risk scores of all customers sharing the same set of risk factors, the specific customer is likely to engage in illegal online gambling. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. To simplify calculations, standard group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons among a group of customers.
[0180] In one aspect of the present invention, a responsible person (or BSA Director) investigates a detected case to determine whether it is a genuine case of online gambling. The BSA Director also reviews all historical cases related to the suspect in the newly detected case. If the BSA Director agrees that the detected case is a possible case of illegal online gambling, the computer system assists the BSA Director in filing a SAR with FinCEN. If the BSA Director decides not to file a SAR, the BSA Director enters a reason into the computer system to justify their decision not to report the detected case.
[0181] The U.S. Congress passed the Fair and Accurate Credit Transactions Act (FACT Act) to protect consumers. Specifically, businesses are expected to identify and report instances of identity theft. Financial institutions are also expected to file a SAR when they detect an instance of identity theft.
[0182] In one aspect of the present invention, a computer system monitors consumer reports and other available information to detect a fraud or active alert, a credit freeze notification, and / or an address discrepancy notification included in a consumer report. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0183] In one aspect of the present invention, a computer system monitors consumer reports and available information to detect a consumer report that indicates a pattern of activity that is inconsistent with the historical and typical patterns of activity of an applicant or customer. For example, a recent and significant increase in inquiry volume, an unusual number of recently established credit relationships, significant changes in credit usage (particularly with respect to recently established credit relationships), or an account closed for a specific reason or identified as abusive by a financial institution or creditor may indicate an unusual pattern. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0184] In one aspect of the present invention, a computer system detects whether a document provided for identification appears to have been altered or forged. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0185] In one aspect of the present invention, a computer system detects whether a photograph or description of an entity being identified is inconsistent with the appearance of the applicant or client being identified. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0186] In one aspect of the present invention, a computer system detects whether other information about an identification is inconsistent with information provided by a person opening a new account or presenting an identification. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0187] In one aspect of the present invention, a computer system detects whether other identifying information is inconsistent with readily accessible information on file with a financial institution or creditor (such as a signature card or a recent check). If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0188] In one aspect of the present invention, a computer system detects whether an application appears to have been altered or forged, or to have been given the appearance of being destroyed and reassembled. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0189] In one aspect of the present invention, a computer system determines whether the provided personally identifiable information is inconsistent when compared with external information used by financial institutions or creditors. For example, the address may not match any address on a consumer report, or the Social Security number (SSN) may not have been issued or is listed on the Social Security Administration's Death Master File. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0190] In one aspect of the present invention, a computer system determines whether certain personally identifiable information provided by a customer is inconsistent with other personally identifiable information provided by the customer. For example, there may be a lack of correlation between a social security number (SSN) and a date of birth. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0191] In one aspect of the present invention, a computer system determines whether provided personal identification information is associated with known fraudulent activity, as indicated by internal or third-party sources used by financial institutions or creditors. For example, an address on an app may be identical to an address provided on a fraudulent app; or a phone number on an app may be identical to a phone number provided on a fraudulent app. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0192] In one aspect of the present invention, a computer system determines whether the provided personally identifiable information is of a type typically associated with fraudulent activity, as indicated by internal or third-party sources used by financial institutions or creditors. For example, an address on an application might be fictitious, a mailing address, or a prison; or a phone number might be invalid or associated with a pager or answering service. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0193] In one aspect of the present invention, a computer system determines whether the provided social security number is the same as the social security number submitted by another person opening an account or other customer. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0194] In one aspect of the present invention, a computer system determines whether a provided address or phone number is the same as or similar to account numbers or phone numbers submitted by an unusually large number of other individuals or other customers opening accounts. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0195] In one aspect of the present invention, a computer system determines whether an account holder fails to provide all required personal identification information for an application or responds to a notification that an application is incomplete. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0196] In one aspect of the present invention, a computer system determines whether the provided personal identification information is inconsistent with the personal identification information on file with the financial institution or creditor. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0197] In one aspect of the present invention, a computer system determines if an account holder is unable to provide identification information, such as answers to challenge questions, beyond what would typically be obtained from a wallet or consumer report. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0198] In one aspect of the present invention, a computer system determines whether there is unusual use of an account or suspicious activity associated with the account. If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0199] In one aspect of the present invention, a computer system determines whether an institution or creditor receives a request for a new, additional, or replacement card or a mobile phone, or a request to add an authorized user to an account, shortly after notification of a change of address for an account. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0200] In one aspect of the present invention, a computer system determines whether a new revolving credit account is being used in a manner commonly associated with known fraud patterns. For example, a large portion of available credit is used for cash advances or goods easily convertible to cash (e.g., electronic devices or jewelry); or the customer fails to make the initial payment or makes the initial payment but no subsequent payments. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0201] In one aspect of the present invention, a computer system determines whether an account is being used in a manner inconsistent with established activity patterns on the account. For example, a payment is not made when: there is no history of late or missed payments; there is a significant increase in the use of available credit; there is a significant change in purchasing or spending patterns; there is a significant change in electronic funds transfer patterns associated with a deposit account; or there is a significant change in telephone call patterns associated with a cellular phone account. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0202] In one aspect of the present invention, a computer system determines whether an account has been inactive for a significant period of time (taking into account the type of account, expected usage patterns, and other relevant factors). If a suspicious activity case is detected, the computer system makes the detected case available for review by a responsible person.
[0203] In one aspect of the present invention, a computer system determines whether emails sent to a customer are repeatedly returned as undeliverable while transactions continue to be conducted in connection with the customer's account. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0204] In one aspect of the present invention, when a financial institution or creditor is notified that a customer has not received a paper statement, a computer system closely reviews all transactions. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0205] In one aspect of the present invention, when a financial institution or creditor is notified of unauthorized charges or transactions related to a customer's account, a computer system closely reviews all transactions. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0206] In one aspect of the present invention, when a customer, a victim of identity theft, a law enforcement authority, or any other person notifies a financial institution or creditor that a fraudulent account belonging to a person involved in identity theft has been opened, a computer system closely reviews all transactions. If a case of suspicious activity is detected, the computer system makes the detected case available for review by a responsible person.
[0207] In addition to monitoring transaction patterns as described above, the group comparison method described above can also be applied to detect possible identity theft cases. Identity theft cases can be categorized into two main categories. The first category includes cases where a fraudster steals a victim's account, financial instruments, or identification documents to conduct activities. In these cases, as described above, a computer system can detect activities that deviate from the victim's expected activities, which can be established based on the victim's historical activities.
[0208] The second category includes cases where a victim's identity is stolen to open a new account and / or initiate some new activity. In these cases, the victim is irrelevant from day one. Because there is no real historical activity of the victim, it is impossible to accurately establish the victim's expected activity for fraud prevention purposes. While someone could ask the criminal questions during the account opening process and collect the answers in an attempt to establish the criminal's expected activity, this question-and-answer method may not be effective because the criminal knows how to answer the questions establishing their expected activity without triggering any alarms.
[0209] In order to detect identity theft when no real historical activity is available, in one aspect of the present invention, all risk factors for a new account or new customer are identified. For example, these risk factors may include the customer's due diligence results, the customer's previous record with other businesses, the customer's credit report history, the customer's industry category, the customer's business type, the customer's geographic region, the customer's country of residence, the nature of the customer's business, the product types of the business, the service types of the business, the structure of the business, the customer's occupation, nationality, historical records, types of transactions conducted, account balances, funds inflows, funds outflows, transaction patterns, number of transactions, transaction amounts, transaction volume, transaction frequency, transaction derivatives, number of chargebacks, transaction locations, transaction times, transaction countries, remittance of a transfer transaction, remittance location, remittance country, nature of the remittance, recipient of a transfer transaction, recipient location, recipient country, nature of the recipient, relationships, social status, political reputation, historical transactions, etc. In fact, there are many risk factors that can be considered to determine the risk of identity theft.
[0210] In one aspect of the present invention, a risk factor is used to identify a group of people sharing the same risk factor. If a particular person has a total risk score significantly higher than a reference value derived from the total risk scores of all people sharing the same risk factor, the particular person is likely involved in an identity theft case. A set of risk factors can be used to identify a group of people sharing this set of risk factors. If a particular person has a total risk score higher than a reference value derived from the total risk scores of all people sharing the same set of risk factors, the particular person is likely involved in an identity theft case. Reference values include an average, a median, a mean, a mode, a weighted average, and / or other statistical values. To simplify calculations, group statistics (such as mean, variance, standard deviation, etc.) can be derived to facilitate comparisons among a group of people.
[0211] In one aspect of the present invention, a responsible person (or compliance officer) investigates a detected case to determine whether it is a true case of identity theft. The compliance officer also reviews all historical cases associated with the newly detected case. If the compliance officer agrees that the case is a possible case of identity theft, the computer system assists the compliance officer in filing a SAR with FinCEN. If the compliance officer decides not to file a SAR, the compliance officer enters a reason into the computer system to justify their decision not to report the detected activity.
[0212] The Office of Foreign Assets Control (OFAC) has a very simple rule that states that any business transaction with any entity on the list published by OFAC is illegal. This list is commonly referred to as the "OFAC List." This rule applies to all U.S. persons and entities, including financial institutions. For example, Walmart was penalized by OFAC for violating this rule. Naturally, U.S. financial institutions, which are subject to the most stringent regulatory oversight, must strictly adhere to this rule.
[0213] Initially, this was a very simple rule. However, over the past 20 years, its implications have become much more complex. A common problem arises when people misspell their names (including misspellings, mispronunciations, etc.). Even if an entity's name is misspelled but is on the OFAC list, a financial institution is still obligated to identify the entity as one on the OFAC list (commonly known as an OFAC match).
[0214] The natural question is how much deviation from the original name on the OFAC list is considered a "misspelling." OFAC and government regulators have never provided any precise guidance on answering this question. A very common practice that an examiner or auditor may implement is to use a notorious name like "Osama bin Laden" as a sample to test a company. Generally, a company should identify all business transactions associated with "Osama bin Laden," "Osama Laden," "Osama Laten," "Laten Osama," "Latin Obama," and so on as possible OFAC matches. Now, if the scope of deviation from OFAC names is further expanded, whether a financial institution should identify the single word "Obama," the name of a former US president, as a possible OFAC match becomes questionable. We can easily see that this simple OFAC rule has caused a lot of confusion in recent years.
[0215] In one aspect of the present invention, an "OFAC Match Ratio" is used to measure the degree of deviation. The OFAC Match Ratio can be used to generate a value called a "relative correlation" ("RC value") to measure the similarity between two names. For example, if a name has an RC value of 100%, it completely matches an OFAC name on the OFAC list. If a name has an RC value of 97%, it may differ from an OFAC name on the OFAC list by as little as one or two letters. If a name has an RC value of 0%, it completely differs from all OFAC names on the OFAC list.
[0216] In one aspect of the present invention, the length of the name also affects the RC value. For example, if a name differs by one letter from a 25-letter OFAC name, the RC value may be 96%, while another name may have an RC value of 90%, even though it also differs by only one letter from a 10-letter OFAC name.
[0217] Certain long words (such as "international," "incorporation," "limited," "company," and "organization") are commonly used in business names and are also on the OFAC list of names. Therefore, these long words generate higher RC values for businesses that use them in their names. To avoid unnecessary false positives, one aspect of the present invention replaces a commonly used long word with a shorter word to reduce its impact on the RC value. For example, the word "international" can be replaced with "intl."
[0218] Additionally, some countries do not use the descriptors "first name" and "last name." Therefore, when a person is asked to provide a first name and a last name, they may use a different name sequence. "Osama Laden" may become "Laden Osama." In one aspect of the present invention, an OFAC match ratio identifies a possible "out-of-sequence" OFAC match.
[0219] Furthermore, some words are commonly used within a particular culture without creating a noticeable distinction. For example, in Muslim cultures, "bin" means "son" and "binti" means "daughter." Formal names in Muslim cultures often contain "bin" or "binti." For example, if a Muslim father's name is "John," his daughter "Mary"'s formal name would be "Mary binti John," and his son "David"'s formal name would be "David bin John." In these cases, the common use of the words "bin" and "binti" in Muslim names creates a "false similarity" between the two Muslim names. To provide a more scientifically accurate result, in one aspect of the present invention, the OFAC match ratio may exclude these "insignificant words" before calculating the RC value. Sometimes, a name can be translated into English based on sound. Therefore, in one aspect of the present invention, the OFAC match ratio should measure sound matching to determine the RC value.
[0220] In one aspect of the present invention, a financial institution determines the threshold value to use when conducting an OFAC check. For example, if a financial institution uses a 75% threshold, a possible OFAC match is detected when a name has an RC value of 75% or higher. Because each financial institution may have different risk exposures than another, it is likely that X is the optimal threshold value for Financial Institution A, while Y is the optimal threshold value for Financial Institution B. As a general guideline, the X or Y value is selected based on a risk-based approach.
[0221] Generally, the higher the threshold a financial institution uses, the fewer possible OFAC matches it detects. This saves time during the review process by avoiding more false positives. However, if the threshold is too high, the financial institution may miss a legitimate deviation from an OFAC name (such as "Osama bin Laden"). If the threshold is too low, the financial institution may mistakenly detect many of its customers as possible OFAC matches. Best practice is to find a balance between having too many possible OFAC matches to review and missing deviations from a genuine OFAC name due to misspellings.
[0222] In one aspect of the present invention, a user can randomly select several OFAC names from the OFAC list and find out how the OFAC match ratio responds to deviations from these selected OFAC names. A user can then determine when to call a "possible OFAC match" based on this test. It is advisable to retain this test for future auditors and reviewers to review.
[0223] A specific name can be very close to an OFAC name. For example, American Express, a reputable credit card company, is often mistakenly detected as an OFAC match simply because of the word "Express." Therefore, to avoid this type of frequent false positives, in one aspect of the present invention, users create an exemption list to include businesses they know to be reputable. Businesses on the exemption list are automatically classified as false positives by a computer or manually by the user when they are detected as possible OFAC matches.
[0224] Typically, a company may have an OFAC officer who handles all OFAC-related matters. In one aspect of the present invention, if an OFAC officer (e.g., a principal) at a financial institution detects a possible OFAC match with an RC value exceeding a predefined threshold, the OFAC officer investigates whether it is a genuine OFAC match. If the OFAC officer believes it is a genuine match, the OFAC officer should handle the case in accordance with guidance issued by the Office of Foreign Assets Control. Under OFAC regulations, in some circumstances, the OFAC officer may need to block a transaction to prevent a person on the OFAC list from benefiting from the transaction. If, after their investigation, the OFAC officer determines that the OFAC match is a false positive, the OFAC officer should enter a reason into the computer system to justify not reporting the OFAC match to the Office of Foreign Assets Control and / or not blocking the transaction.
[0225] Section 314(a) of the USA PATRIOT Act requires financial institutions to detect matches to names on a 314(a) list, which is published periodically by FinCEN. Computer systems can handle 314(a) compliance matters using a method similar to that used for OFAC compliance matters, as described above.
[0226] Sometimes, a 314(a) list also includes additional personal identification information, such as identification document numbers, dates of birth, addresses, etc. In one aspect of the present invention, in addition to the methods described above for detecting possible OFAC matches, a computer system uses personal identification information (such as identification document numbers, addresses, and / or dates of birth) to determine whether a detected 314(a) match is a true match. This method can reduce false positives in the 314(a) matching process.
[0227] In one aspect of the present invention, if a compliance officer (e.g., a principal) at a financial institution detects a possible 314(a) match with an RC value exceeding a predefined threshold, the compliance officer investigates whether the match is a true 314(a) match. In one aspect of the present invention, if the compliance officer believes the match is a true match, the compliance officer reports the 314(a) match to FinCEN. If the compliance officer determines, after their investigation, that the 314(a) match is a false positive, the compliance officer enters a reason into the computer system justifying their decision not to report the 314(a) match to FinCEN.
[0228] In one aspect of the present invention, a computer system receives customer information and transaction data from a financial institution's core data processing system or other data processing systems that may be internal or external to the financial institution. The customer information may include background information.
[0229] In one aspect of the present invention, a computer system receives information regarding suspicious activity observed by frontline personnel. For example, the computer system may receive information input from frontline personnel. The computer system may also receive information provided by other internal or external sources.
[0230] Although "financial institutions" are used as an example for ease of explanation, the present invention is also applicable to other types of businesses. Generally, any business that needs to comply with laws and regulations can adopt a smart alarm system as described in the present invention.
[0231] In one aspect of the present invention, a risk score or a level of a risk factor can be assigned by a computer software module, a person designing or tuning the system, or a user of the system. In most cases, the absolute value of the risk score is not important and the relative relationship among all risk scores may be more important.
[0232] Furthermore, a subject's total risk score should fluctuate only within a reasonable range. In one aspect of the present invention, if a subject's total risk score suddenly increases and exceeds a threshold, the subject may have engaged in suspicious or unusual activity. Specifically, if the difference between a subject's first and second total risk scores exceeds an increase threshold (where the first total risk score is less than the second total risk score), the subject may have engaged in suspicious or unusual activity. In another aspect of the present invention, if a subject's total risk score suddenly and sharply decreases, the subject may also have engaged in suspicious or unusual activity. Specifically, if the difference between a subject's second and first total risk scores exceeds a decrease threshold (where the first total risk score is greater than the second total risk score), the subject may have engaged in suspicious or unusual activity. Therefore, an alert is sent to an investigator, a BSA supervisor, a compliance officer, or another person responsible for investigating a subject when a subject's total risk score suddenly and sharply increases or decreases.
[0233] A subject's observed data may fluctuate from time to time. Therefore, the intelligent alarm system may allow a subject's total risk score to fluctuate within a specific range to avoid false alarms. In one aspect of the present invention, when a subject's total risk score falls below a threshold, the intelligent alarm system increases the subject's allowable total risk score fluctuation range. In another aspect of the present invention, when a subject's total risk score rises above a threshold, the intelligent alarm system decreases the subject's allowable total risk score fluctuation range. The allowable fluctuation range can be determined (e.g., set) by a software module, a person designing the system, a person tuning the system, or a person using the system.
[0234] For example, if a subject's total risk score is higher than the mean of all subjects' total risk scores plus a specific number of standard deviations (e.g., four standard deviations), the intelligent alarm system may modify the subject's allowable total risk score fluctuation range to within one-half of one standard deviation without triggering an alarm. In another example, if a subject's total risk score is within the mean of all subjects' total risk scores plus a specific number of standard deviations (e.g., three standard deviations), the intelligent alarm system may allow the subject's total risk score to fluctuate within one standard deviation without triggering an alarm.
[0235] In yet another example, if a subject's total risk score is within a certain number of standard deviations (e.g., two standard deviations) of the mean of all subjects' total risk scores, the smart alarm system may allow the subject's total risk score to fluctuate within a range of 1.5 standard deviations without triggering an alarm. In yet another example, if a subject's total risk score is within a certain number of standard deviations (e.g., one standard deviation) of the mean of all subjects' total risk scores, the smart alarm system may allow the subject's total risk score to fluctuate within a range of two standard deviations without triggering an alarm.
[0236] In the field of machine learning, a negative is a dataset that has not triggered an alert. A true negative is a dataset that has not triggered an alert and does not include a true case that triggered an alert. A false negative is a dataset that has not triggered an alert but includes a true case that triggered an alert that the system missed. As an example, if the US government discovers a false negative of money laundering, the false negative could result in a financial institution being penalized by the US government. Therefore, it is desirable to prevent false negatives in alert systems designed to prevent money laundering (e.g., money laundering prevention alert systems).
[0237] Reporting a real money laundering case to FinCEN, a U.S. government organization, using a money laundering alert system at a U.S. financial institution. FinCEN has a communication protocol. U.S. financial institutions can report cases to FinCEN by sending a file from their money laundering alert system to FinCEN's computer system based on FinCEN's communication protocol.
[0238] Conventionally, rule-based systems are used to detect suspicious activity, and each rule can trigger an alert. Many financial institutions already use rule-based approaches, which can trigger numerous alerts. For example, there are over 200 countries in the world. If a financial institution uses a rule-based approach to monitor wire transfers to and from each country, the financial institution may have over 200 branches at the country decision node in the decision tree. As another example, there are thousands of different industries. If a financial institution uses a rule-based approach to monitor wire transfers to and from various industries, the financial institution may have thousands of branches at the industry decision node in the decision tree. Country and industry are two of the many risk categories that pose money laundering risks. Similarly, a wire transfer is one of the many transaction types that pose money laundering risks. For example, cash, checks, ACH, ATM, credit cards, debit cards, letters of credit, etc. are other possible transaction types.
[0239] There are numerous money laundering risk factors. There are countless (e.g., millions) possible combinations of branches that form a path from the root of a decision tree to its leaf nodes. In other words, a rule-based system can use millions of rules to cover the entire spectrum of money laundering risk and detect suspected money laundering activity. A rule-based system with a limited number of rules can have an increased number of false negatives (e.g., the system misses actual money laundering cases) and many false positives (e.g., the leaf nodes of the decision tree have an increased number of impurities and fail to achieve classification goals). Due to the number of false negatives and false positives when using a rule-based approach, financial institutions employ investigators to review the large number of alerts. It is difficult for financial institutions to mitigate all false negatives using a rule-based system.
[0240] In the field of machine learning, conventional systems consider 70% accuracy to be satisfactory. It is difficult, if not impossible, to train a machine learning model to achieve high accuracy (such as 100%). Unfortunately, while 70% accuracy may be good for some purposes, this 70% target fails to meet regulatory standards, such as those set by the US government. As discussed, if a financial institution fails to detect certain activities (such as money laundering), it may face severe regulatory penalties. Consequently, a financial institution will not use an alert system with 70% accuracy. Therefore, conventional machine learning models are not satisfactory for an intelligent money laundering prevention alert system.
[0241] According to an aspect of the present invention, the intelligent money laundering prevention alarm system uses a risk scoring method. Each risk factor or a degree of a risk factor can be similar to a branch in a rule-based system. Therefore, as described in the present invention, the risk scoring process for generating a total risk score from multiple risk factors can combine information from multiple rules into the total risk score. For example, if a total risk score is generated from 10,000 risk factors, a user only needs to pay attention to those alarms with a total risk score exceeding a threshold value without having to evaluate each of the 10,000 risk factors. If a rule-based method is used, each risk factor can have two possible results: match or no match. The total number of possible result combinations of 10,000 risk factors is two (2) to the power of 10,000 (e.g., 2 10,000). Therefore, an evaluation based on the total risk score has effectively replaced the need to evaluate each of two (2) to the power of 10,000 (e.g., 2 10,000) possible results. Because these 210,000 results could potentially generate 210,000 different types of alarms, the intelligent money laundering prevention alarm system can avoid at least 210,000 alarms. Therefore, the intelligent money laundering prevention alarm system is an improvement over one of the conventional rule-based systems.
[0242] While an overall risk score can replace many rules, it cannot replace all of them. For example, if an individual frequently deposits a specific cash amount (e.g., $9,900) (which is slightly below the CTR reporting threshold of $10,000), financial institutions are expected to report this individual to the Financial Crimes Enforcement Network (FinCEN) as a case of mass transfers. Accurately detecting a mass transfer based on an overall risk score is difficult. Therefore, an alert system based on risk score-based technology may include rules beyond risk score-based criteria.
[0243] In one aspect of the present invention, the intelligent money laundering prevention alarm system uses risk-based scenarios to replace rules. In one example, the intelligent money laundering prevention alarm system can use approximately 20 to 30 scenarios. These scenarios can include both risk-based scenarios and non-risk-based scenarios.
[0244] In addition to or in lieu of these scenarios, other conditions can be used to generate an alert. For example, a computer system (such as a machine learning network) can be trained to generate a model. After training, the discriminant used by the model can be converted into an if-then conditional format to trigger an alert.
[0245] For the purposes of this disclosure, a scenario can be defined as a condition or set of conditions that can trigger an alert or be used to categorize an object into a category for a specific purpose. For example, a customer with an overall risk score within a specific range may not trigger an alert. However, in this instance, the overall risk score may categorize the customer into a specific risk category, such as high risk, medium risk, or low risk. As another example, a customer previously listed as a suspect in a suspicious activity report (SAR) may not trigger an alert. In this instance, the customer may be categorized into a specific category, such as a previous SAR suspect or another similar category. As another example, a customer matching the OFAC list, the 314(a) list, the Highly Prominent Politically Exposed Persons list, and / or other lists may be categorized into one or more categories.
[0246] A scenario can consist of a rule, a set of rules, a criterion, or a set of criteria based on rules, facts, behavioral patterns, risk scores, risk dimensions, total risk scores, special categories, mathematical models, and / or machine learning models. The scenario can trigger an alert using a rule-based approach, a behavior-based approach, a risk-based approach, a model-based approach, and / or a machine learning-based approach (e.g., an artificial intelligence-based approach). A smart alert system can include one or more scenarios.
[0247] As discussed, an alert can be triggered by a scenario. When one or more conditions are met, the scenario can be flagged. A potential case that has triggered an alert can be called a positive. A potential case can contain one or more alerts. Therefore, the cause of a potential case can be one or more scenarios. Potential cases or positives can be investigated. A true positive can refer to a potential case (e.g., a positive) that is a real case. If the investigation indicates that the potential case is not a real case, the potential case can be called a false positive. Therefore, the false positive can be dismissed and the associated alert can be dismissed as a false alarm. True positives can be reported to an authority (such as FinCEN or law enforcement).
[0248] In one configuration, a posterior probability can be estimated using a Bayesian principle. The product of the posterior probability and the evidence is the prior probability multiplied by the class likelihood. Using the application of reporting suspected money laundering activity to FinCEN as an example, the Bayesian equation is p(S / c)p(c) = p(c / S)p(S). The evidence p(c) is the probability of a potential case being triggered by cause c among all potential cases. The class likelihood p(S) is the probability of a correct positive S (e.g., a true SAR case) among all potential cases. The prior probability p(c / S) is the probability of a correct positive being triggered by cause c among all correct positives. Therefore, the posterior probability p(S / c) can be determined as follows: p(S / c) = p(c / S)p(S) / p(c). The posterior probability P(S / c) is also the conditional probability that a potential case triggered by cause c is a correct positive. That is, although the conditional probability P(S / c) is derived from historical data, it is the best estimate of the future probability that a potential case triggered by cause c will become a correct affirmation. Therefore, the posterior probability can also be called the conditional probability for the future or the future conditional probability.
[0249] Numerous risk factors (e.g., thousands of them) can influence money laundering risk. In one configuration, when risk score-based scenarios are used as part of the scenarios, the number of scenarios used by the intelligent money laundering alert system is not large. As an example, the intelligent money laundering alert system can use thirty scenarios. A potential case can be triggered by one or more of these scenarios. In this example, a vector with thirty elements can represent the possible causes of the potential case. Therefore, in this example, there are 230 possible cause combinations. Each triggered scenario is identified by a flag. For example, a cause vector can be initialized with a value of "0" for each element. If a scenario is triggered, the value of an element corresponding to that scenario can be changed from "0" to another value, such as "1."
[0250] For example, if a potential case is triggered by a first scenario and a third scenario, the vector x may contain "1"s at the first and third positions and "0"s at all other positions. That is, the vector can be represented as x = (1, 0, 1, 0, 0, 0, ..., 0). As another example, if a potential case is triggered by a third scenario and a fourth scenario, the third and fourth positions of the vector may contain "1" values, and all other positions may contain "0" values. In this example, the vector x can be represented as x = (0, 0, 1, 1, 0, 0, ..., 0). In the present invention, a vector containing the scenarios (e.g., causes) that triggered an alarm for a potential case may be referred to as a cause vector.
[0251] A scenario may contain one or more conditions for classifying a subject into one or more categories; however, a scenario alone cannot trigger a potential case. A potential case can be triggered by multiple scenarios within a related cause vector. For example, if a scenario is intended to classify a subject as a prior SAR suspect, this scenario alone cannot trigger a money laundering alert. However, if a customer is a prior SAR suspect and another scenario has been triggered (e.g., wired over $10 million to a high-risk country), a potential case may be triggered. However, a cause vector may have two scenarios: one for money transfer transactions and another for prior SAR suspects. Including various special categories (e.g., prior SAR suspects) in a cause vector is a good idea because these special categories can improve the accuracy of suspicious activity detection.
[0252] A potential case with multiple triggered scenarios in a cause vector is more likely to become a true positive. For example, if a customer receives $250,000 via wire transfer, one scenario in the cause vector may be flagged (e.g., triggered). This cause vector with one flagged scenario may register as a potential case, which may or may not be a true money laundering case. Similarly, if a customer withdraws $250,000, another scenario in the cause vector may be flagged. However, this potential case may or may not be a true money laundering case.
[0253] However, if a customer receives $250,000 via wire transfer and then withdraws $250,000 in cash from their account, two different scenarios may be flagged in the cause vector. A cause vector with two flagged scenarios may be registered as a potential case, which is more likely to be a true money laundering case because the combined activities described by these two different scenarios match a common money laundering behavior pattern. Therefore, it is desirable to calculate the conditional probability of a potential case based on a cause vector with multiple flagged scenarios, rather than calculating the conditional probability based on a single flagged scenario.
[0254] If a cause vector has thirty scenarios (because each scenario has two possibilities (e.g., triggered and not triggered)), then the thirty scenarios can have up to 2 30 possible combinations. However, since the case will not be triggered if no scenario is triggered, the total possible combinations that trigger a case is (2 30 - 1). Each combination can have a unique conditional probability of triggering a potential case. Calculating these conditional probability values may be impractical because 2 30 is a very large number. In practice, a potential case averages five or fewer simultaneous triggering scenarios. Therefore, the actual total number of meaningful combinations of scenarios that can trigger a potential case is much smaller and can be managed by a computing device associated with the smart alarm system. For example, if the maximum number of possible cases in a potential scenario is 5, the total number of possible potential cases that can be triggered by these 30 scenarios is C(30,1)+C(30,2)+C(30,3)+C(30,4)+C(30,5), where C(m,n) is the number of different possible choices of selecting n objects from m objects. For example, C(30,1) is 30 because there are 30 possible choices of selecting 1 object from 30 objects. C(30,2) is 435. C(30,3) is 4,060. C(30,4) is 27,405. C(30,5) is 142,506. The total number of possible cause vectors is 174,436. These cause vectors and their associated conditional probability values can be managed by a computing device and a database associated with the intelligent alarm system.
[0255] An investigator can use the smart alert system to investigate a potential case triggered by a cause vector. The cause vector can contain multiple flagged scenarios. A potential case can be a false positive or a true positive. A true positive refers to a potential case that is a real case. A false positive refers to a potential case that is not a real case. If it is a false positive, all alerts for the potential case are dismissed as false alarms. If it is a true positive, the potential case becomes a real case that can be reported to an authority such as FinCEN.
[0256] Typically, investigating a potential case is time-consuming. In the United States, it's common for a large financial institution to employ hundreds of investigators. Each investigator's task is to determine whether a potential case triggered by various money laundering prevention systems is actually a case of money laundering. If a case of money laundering is actually a case, US law requires the financial institution to report it to FinCEN within 30 days. However, as discussed above, whether a potential case is a true case of money laundering is a subjective opinion of the investigator.
[0257] If an investigator reports a false positive as a true money laundering case, there is no penalty because financial institutions are protected by the safe harbor rules. Generally, because of the significant regulatory penalties for failing to report a true money laundering case to FinCEN, there is an expectation that potential cases will be reported to FinCEN rather than dismissed. Therefore, it is common practice for investigators to treat a potential case as a true positive whenever reasonable doubt exists. Current US law does not require investigators to prove that a potential case is a true case. In other words, if a potential case is highly likely to be a true case, an investigator is more inclined to report it. This also means that probability plays a role in this decision-making process.
[0258] Understanding the conditional probability p(S / x) of a potential case becoming a true SAR case based on the cause vector x can improve a user's decision-making. For example, if the conditional probability is greater than a threshold, the user may want to report the case to FinCEN without the time-consuming investigation. In one configuration, when the conditional probability of a case is greater than a threshold, the intelligent alert system automatically reports the case to an appropriate entity (e.g., FinCEN). The threshold can be set by a software module, a person designing or tuning the system, and / or a user of the system. Alternatively, the threshold can be set by the intelligent alert system, which learns the user's preferences by evaluating their past behavior. For example, if a user typically files a SAR when the conditional probability of the cause vector is greater than a value Z, the system can use the value Z as a threshold to automatically file a SAR for the user in the future. In one configuration, the system stores potential cases in a database to determine the conditional probability. For each potential case, the system also stores the associated cause vector. The system may also store investigation results, such as whether a potential case triggered by a cause vector has been accepted by the investigator as a true positive or rejected by the investigator as a false positive.
[0259] As users continue to use the smart alert system, the system accumulates historical data in a database. In one aspect of the present invention, for any given time period, the system can determine from the database how many potential cases were triggered by a cause vector x and how many potential cases triggered by cause vector x have become true positives (e.g., SAR cases reported to FinCEN). The ratio of the number of true positives triggered by a cause vector to the number of potential cases triggered by the cause vector is the conditional probability p(S / x). The conditional probability can also be referred to as the posterior probability. The posterior probability indicates the probability that a future potential case triggered by a cause vector will become a true case reported to FinCEN. Typically, the conditional probability of a potential case is equal to the conditional probability of the cause vector that triggered the potential case.
[0260] In one aspect of the present invention, the intelligent alert system calculates and displays a conditional probability for each potential case based on its cause vector. The conditional probability indicates the probability that a potential case triggered by the cause vector will become a true positive reported to FinCEN. In another aspect of the present invention, the intelligent alert system accepts a potential case as a true positive and reports it to FinCEN in response to the conditional probability of the cause vector being above a predefined value. This predefined value is also referred to as the true positive acceptance threshold.
[0261] The intelligent alert system can also reject a potential case as a false positive in response to the conditional probability of the cause vector being less than a false positive rejection threshold. The false positive rejection threshold and true positive acceptance threshold can be set by a software module, a person designing or tuning the system, and / or the system's user. Alternatively, these thresholds can be set by the intelligent alert system, which learns the user's preferences by evaluating the user's past behavior. For potential cases that have not yet been accepted as true positives and rejected as false positives, an investigator can manually review the potential cases and determine whether each potential case is a false positive or a true positive.
[0262] The data used to determine the conditional probability can be obtained over a time period. For example, the time period can be the past 12 months, the past three years, or any other period. In one configuration, the conditional probability is determined over a rolling time period that continues to move forward. For example, if circumstances (e.g., corporate policies, customer demographics, products, services, etc.) have changed, the old probability value may no longer be accurate after the change. Furthermore, if a financial institution modifies a scenario, the old probability value may be affected. Therefore, a rolling time period (e.g., the past three years) provides the intelligent alert system with the ability to continuously self-adjust to generate the most current and accurate probability values.
[0263] Many computer systems process data in batches (e.g., monthly batches). Instead of a time period, batches can be used to define the amount of historical data used in probability calculations. For example, instead of a rolling time period of the past three years, if a computer system runs monthly batches, the computer system could use a rolling time period of the past 36 batches.
[0264] In one configuration, the smart alert system purposefully leaves some potential cases to the investigators. The smart alert system can use the results of these cases to train the system, adjusting the probability values to better suit the current circumstances. Thus, the smart alert system is a learning system that improves its predictions as more potential cases are evaluated by human investigators.
[0265] When a cause vector does not generate a potential case triggered by the cause vector within a specified time period, the intelligent alarm system can generate a flag or display a message for the potential case. In these cases, a user can manually investigate the potential case to determine whether it is a false positive or a true positive. The results of this manual investigation can be used to calculate the conditional probability value of the cause vector. The calculated conditional probability value can be used to evaluate future potential cases. This manual investigation process has the equivalent effect of supervised training and improves the accuracy and reliability of the intelligent alarm system.
[0266] The intelligent alert system can also display or link to historical potential cases and / or corrective affirmations triggered by the cause vector. Furthermore, users can view additional details (e.g., drill-downs) for each case. Investigators can therefore use historical data as a reference when deciding whether to pursue a potential case.
[0267] The system can also display or link to historical potential cases triggered by the same suspect in the current potential case and the decisions made regarding those potential cases. Investigators can delve into the suspect's detailed background information and transaction information. Thus, an investigator can determine whether the current potential case is a false positive or a true positive.
[0268] In some cases, there may not be sufficient reason to report a current potential case to an authority. However, a current potential case combined with a historical potential case may have sufficient reason to be reported. In these cases, the actual reason for reporting the case is comprised of the current potential case's reason vector in addition to the historical potential case's reason vector. The historical potential case may be referred to as a previous potential case. A combined reason vector may be used for this actual reason. The combined reason vector may be a combination of multiple reason vectors from multiple potential cases.
[0269] As an example, a cause vector x1 for a current case may have "1"s at the first and fifth positions of the vector and "0"s at all other positions (e.g., x1=(1,0,0,0,1,0,0,...0)). In this example, a cause vector x2 for a historical potential case may have "1"s at the third and fifth positions and "0"s at all other positions (e.g., x2=(0,0,1,0,1,0,0,...0)). A combined cause vector x3 (e.g., a combination of x1 and x2) may have "1"s at the first, third, and fifth positions and "0"s at all other positions (e.g., x3=(1,0,1,0,1,0,0,...0)). Although only one cause vector for one historical potential case is used in the above example, a combined cause vector may be composed of multiple cause vectors for multiple historical potential cases.
[0270] In one configuration, an investigator manually reviews multiple historical potential cases and the current potential case to determine whether the combined case is a false positive (e.g., not reported) or a true positive (e.g., pending report). The results of the manual investigation can be used to calculate a conditional probability value p(S / cbv) (e.g., a posterior probability value) for the combined cause vector cbv. The combined cause vector cbv is a combination of the cause vector of the current potential case and one or more cause vectors of the historical potential cases.
[0271] In some cases, it is difficult for the smart alert system to know which historical potential cases the investigator has investigated. Therefore, the smart alert system can prompt the investigator to select historical potential cases, which will be combined with the current case to report to the authorities.
[0272] In addition, in some cases, it is difficult for the smart alert system to know which of the combined cause vectors or circumstances of a cause vector caused the investigator to report a potential case. Therefore, the smart alert system can prompt the investigator to select the circumstances that caused the investigator to report the potential case.
[0273] Many suspicious activity reports (SARs) require investigators to provide a comment or narrative about the underlying case. To improve processing time, it is desirable for a smart alert system to automatically complete the comment or narrative for reported cases. Typically, the information used to write a comment or narrative consists of background information and transaction information about the suspect. Because this information is stored in a database, the smart alert system can learn from the user how to write the comment or narrative, as explained later in this invention.
[0274] In one aspect of the present invention, an intelligent alert system prompts an investigator to select a historical potential case to be combined with a current potential case for reporting. Based on the causal vector of the selected historical potential case and the causal vector of the current potential case, the intelligent alert system prepares a commentary or narrative. The prepared commentary or narrative is provided in the report of the combined case.
[0275] When the smart alert system fills in the comments or narrative, it can also identify the combined cause vector of the reported case. Therefore, a conditional probability value p(S / cbv) can be associated with the identified combined cause vector cbv based on the results of the human investigation.
[0276] The intelligent alert system can prompt the investigator to select a causal vector or a combined causal vector scenario that led to the reporting of a potential case. Based on the selected scenario, the intelligent alert system prepares a commentary or narrative to complete a report for the case. These selected scenarios form a true causal vector for the reported case. The scenario of the true causal vector of the reported case is identified. A conditional probability value for the true causal vector can be calculated based on the results of the human investigation.
[0277] Individuals may have unique writing styles (or preferences), so an investigator may initially dislike the commentary or narrative generated by a smart alert system. If the investigator dislikes the commentary or narrative generated based on the selected scenario and cannot modify it, the investigator may not bother selecting the scenario that the smart alert system generates. In such cases, the smart alert system may not understand the true reason why the investigator decided to report the case to the authorities. Consequently, the smart alert system may not be able to calculate the future conditional probability value of the true cause vector based on the human investigation results.
[0278] Therefore, it is desirable for the smart alert system to learn and adapt to the investigator's writing style (or preference). In one configuration, the smart alert system learns the investigator's writing style (or preference) and generates future comments or narratives based on the investigator's writing style (or preference).
[0279] In one configuration, to learn a person's writing style (or preferences), the intelligent alert system displays a commentary or narrative for a first-selected scenario based on a pre-stored, preset commentary or narrative for the first-selected scenario. The pre-stored, preset commentary or narrative includes two main components. The first component consists of facts such as the suspect's name, identifying information, the suspect's background, the suspect's relationships, the location of the incident, a description of the incident, the date and time of the incident, information related to the incident, transaction details, etc. The second component may contain words, phrases, sentences, symbols, etc., used to link the facts together. These words, phrases, sentences, symbols, etc. are collectively referred to as "linking words."
[0280] Facts can be obtained from stored data or information associated with the intelligent alert system. An investigator may rarely modify stored facts. An investigator may modify linking words based on the investigator's writing style (or preferences). Therefore, the intelligent alert system tracks facts and linking words in comments and narratives. The intelligent alert system also tracks the location of facts in memory (e.g., a database) and the relationships between facts.
[0281] Typically, a person's writing style (or preferences) is determined by the linking words and presentation sequence (e.g., format) of facts. Writing style (or preferences) cannot be determined solely based on the selection of facts themselves, as investigators should include relevant facts and avoid altering them. In some cases, when two different cases are detected in the same scenario, the facts may differ. However, the linking words and presentation sequence (e.g., format) of facts can remain the same across commentaries or narratives, as the same investigator has the same writing style (or preferences).
[0282] In one configuration, the intelligent alert system provides the investigator with an edit function to add, delete, or modify the linking words that link facts together. The intelligent alert system may provide the investigator with an edit function to add, delete, or modify facts within a narrative. The intelligent alert system may provide the investigator with an edit function and a database search function to retrieve additional facts from a database and insert them into the narrative.
[0283] After the investigator has revised the comment or narrative for the first selected scenario, they can save the revised comment or narrative as the next default comment or narrative. In the future, when the investigator selects the first selected scenario again for another case, a revised comment or narrative based on a different set of facts (e.g., the next default comment or narrative) can be displayed for the investigator to edit. After several revisions, the investigator may be satisfied with the revised version and may not want to edit it again. Through this evolutionary revision process, the intelligent alert system learns from the investigator and will generate a comment or narrative that matches the investigator's writing style (or preferences).
[0284] The smart alert system can handle a second selected scenario using the same method described above for the first selected scenario. The smart alert system can handle other selected scenarios in the same manner. Over time, the smart alert system will gradually learn how to write a comment or narrative for each scenario based on the investigator's preferences.
[0285] As discussed, based on learning, the intelligent alert system can automatically generate an investigator's commentary or narrative. Based on aspects of the present invention, the investigator no longer needs to write a commentary or narrative. The investigator selects the scenario, and in response, the intelligent alert system automatically completes the SAR form and the commentary or narrative. The intelligent alert system then reports the case to the appropriate authorities. Currently, an investigator may spend hours writing a commentary or narrative for a SAR case. The intelligent alert system can eliminate a significant amount of investigator labor.
[0286] In some cases, a person's writing may depend on their mood. For example, a person in a good mood may write a detailed narrative. As another example, a person in a bad mood may write a poor or incomplete narrative. Aspects of the present invention eliminate the influence of the human author's mood on the narrative, allowing the narrative to maintain a consistent standard.
[0287] In an exemplary scenario, when the smart alarm system detects that a customer, John Doe, deposited $9,990 on June 1 and $9,995 on June 2 into an account at ABC Bank, an alarm with a preset description may be generated as follows: [John Doe] [Mr.] [6] [moon] [1] [Daily] Deposit [9,990] [US dollar] and in [6] [moon] [2] [Daily] Deposit [9,995] [USD] to [ABC] [Bank] in". In this short description of the example, the underlined words are facts and the remaining words are links.
[0288] In one example, an investigator might modify the statement as follows: [John Doe] [Mr.] [6] [moon] [1] [Daily] Deposit [9,990] [US dollar] and in [6] [moon] [2] [Daily] Deposit [9,995] [USD] to [ABC] [Bank]. Pursuant to the Bank Secrecy Act, we are reporting this case as suspicious activity because it is a typical cash batch transfer. In the above description, the underlined words are facts and the remaining words are links. When the investigator saved the SAR form regarding John Doe, the intelligent alert system saved the revised description as the default.
[0289] At a later time, the smart alert system may detect that a customer, Jack Daniel's, deposited $9,999 on July 1 and $9,999 on July 2 into an account at ABC Bank. In response, the smart alert system may generate a SAR case with a pre-set description as follows: [Jack Daniel] [Mr.] [7] [moon] [1] [Daily] Deposit [9,999] [US dollar] and in [7] [moon] [2] [Daily] Deposit [9,999] [USD] to [ABC] [Bank] In accordance with the Bank Secrecy Act, we are reporting this case as suspicious activity because it is a typical cash batch transfer type."
[0290] In one example, the investigator could change the narrative to read as follows: “Under the Bank Secrecy Act, a financial institution is required to report a batch of cash transfers through a Suspicious Activity Report (SAR). We have identified [Jack Daniel] [Mr.] [7] [moon] [1] [Daily] Deposit [9,999] [US dollar] and in [7] [moon] [2] [Daily] Deposit [9,999] [USD] to [ABC] [Bank]. This is a typical cash batch transfer activity that avoids filing a Currency Transaction Report (CTR). Therefore, we reported this case as a suspicious batch transfer activity through a SAR. When the investigator saved the SAR form regarding Jack Daniel's, the intelligent alert system saved the revised description as the default description.
[0291] At a later time, the smart alert system detects that a customer, Jim Beam, deposited $9,980 on August 3 and $9,985 on August 4 into an account at ABC Bank. In response, the smart alert system may generate a SAR case with a pre-set description as follows: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer activity through a Suspicious Activity Report (SAR). We have identified [Jim Beam] [Mr.] [8] [moon] [3] [Daily] Deposit [9,980] [US dollar] and in [8] [moon] [4] [Daily] Deposit [9,985] [USD] to [ABC] [Bank] This is a typical cash batch transfer activity that avoids filing a Currency Transaction Report (CTR). Therefore, we reported this case as a suspicious batch transfer activity through a SAR.
[0292] An investigator could see the above statement and might want to add a few words like this: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer through a Suspicious Activity Report (SAR). We have identified [Jim Beam] [Mr.] [8] [moon] [3] [Daily] Deposit [9,980] [US dollar] and in [8] [moon] [4] [Daily] Deposit [9,985] [USD] to [ABC] [Bank]. This is a typical cash batch transfer activity that avoids filing a Currency Transaction Report (CTR). Therefore, we reported this case as a suspicious batch transfer activity through a SAR. [Jim Beam] [Mr.]
[2019] [Year] [3] [moon] [1] [Day] to open a bank account with an average account balance of [123,197] [USD]". In this case review process, the investigator has included additional facts extracted from the intelligent alarm system's database. These additional facts are underlined in the following sentence: " [Jim Beam] [Mr.]
[2019] [Year] [3] [moon] [1] [Day] to open a bank account with an average account balance of [123,197] [USD]". When the investigator saved the SAR form regarding Jim Beam, the intelligent alert system saved the revised statement as the default statement.
[0293] At yet another later time period, the smart alarm system detects a customer, Remy Martin, who is [9] [moon] [5] [Daily] Deposit [9,998] [US dollar] and in [9] [moon] [6] [Daily] Deposit [9,998] [USD] to [ABC] In response, the intelligent alert system may generate a SAR case with a pre-set description as follows: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer activity through a Suspicious Activity Report (SAR). We have identified [Remy Martin] [Mr.] [9] [moon] [5] [Daily] Deposit [9,998] [US dollar] and in [9] [moon] [6] [Daily] Deposit [9,998] [USD] to [ABC] [Bank]. This is a typical cash batch transfer activity that avoids filing a Currency Transaction Report (CTR). Therefore, we reported this case as a suspicious batch transfer activity through a SAR. [Remy Martin] [Mr.]
[2019] [Year] [2] [moon]
[15] [Day] to open a bank account with an average account balance of [83,225] [Dollar]".
[0294] The investigator may see the above description and decide that no changes are needed. Until the investigator makes changes in the future, cases detected by the same scenario will use the following comment or description: "Under the Bank Secrecy Act, a financial institution is required to report a cash batch transfer through a Suspicious Activity Report (SAR). We have identified ( [Name of suspect]) at ( [First Deposit Date]) Deposit ( [First cash transaction amount]), and in ( [Second Deposit Date]) Deposit ( [Second Cash Transaction Amount]) to ( [Bank Name]). This is a typical cash batch transfer activity that avoids filing a Currency Transaction Report (CTR). Therefore, we report this case as a suspicious batch transfer activity through a SAR. [Name of suspect]) at ( [Account Opening Date]) and the average account balance during the past three (3) months is ( [Average Account Balance]). The underlined words are extracted from the Smart Alert System's database. The remaining words in the description are the preferred linking words used by the investigator and learned by the Smart Alert System based on the investigator's descriptions of previous cases detected by the same scenario.
[0295] In the above example, the set of facts consists of the following: suspect's name, first cash transaction amount, first deposit date, second cash transaction amount, second deposit date, bank name, account opening date, and average account balance. These different fact segments can be retrieved from a storage location (such as a database).
[0296] Furthermore, John Doe, Jack Daniel, Jim Beam, and Remy Martin are all facts of the same type under the field named "Suspect Name." Each suspect name can be defined as a fact corresponding to the other suspect names. For example, Remy Martin might be a corresponding fact segment for Jim Beam. Similarly, a set of corresponding fact segments can be defined under the following fields: First Cash Transaction Amount, First Deposit Date, Second Cash Transaction Amount, Second Deposit Date, Bank Name, Account Opening Date, and Average Account Balance.
[0297] When the smart alert system displays a pre-set narrative based on a new set of facts about a new suspect, it replaces each old fact about the old suspect with the new facts about the new suspect. In the above example, the old suspect's name, Jim Beam, is replaced with the new suspect's name, Remy Martin; $9,980 is replaced with $9,998; August 3rd is replaced with September 5th; $9,985 is replaced with $9,998; August 4th is replaced with September 6th; ABC Bank is replaced with ABC Bank; March 1, 2019, is replaced with February 15, 2019; and $123,197 is replaced with $83,225. The linking characters remain unchanged.
[0298] If an investigator has used the same default narrative a predefined number of times without revising it, the default narrative may already match the investigator's writing style (or preferences). In such cases, the intelligent alert system can skip or suggest the investigator skip the narrative review process.
[0299] In one configuration, in addition to providing a commentary or narrative for each scenario, the intelligent alert system also provides an introduction section for each case. Additionally or alternatively, the intelligent alert system can provide a conclusion section for each case. The introduction section is placed at the beginning of the overall narrative, and the conclusion section is placed at the end of the overall narrative. For example, if a case has three scenarios selected by the investigator, the overall commentary or narrative will have an introduction section, three commentary or narrative sections matching the three selected cases, and a conclusion section.
[0300] In one aspect of the present invention, the introduction and conclusion sections can also be modified and saved by the investigator. Similarly, the intelligent alert system will learn to construct the investigator's preferred introduction and conclusion sections. This general format, including an introduction section and a conclusion section, provides the investigator with additional flexibility to write a more comprehensive and versatile narrative.
[0301] In one configuration, if a case involves multiple suspects, each suspect is detected by a set of scenarios. The overall review or narrative of the case may include an introduction section, a relationship section describing the relationships between the suspects, a separate review (or narrative) section for each case, and a conclusion section.
[0302] Updating the linking and relative placement of facts in the default narrative based on different sets of facts can streamline the SAR case review and submission process. For example, when the intelligent alert system detects an alert regarding a suspect, it sends the current matching scenario and all scenarios matching historical alerts related to the suspect to the investigator's computer system. The investigator selects a scenario that constitutes reason for filing a SAR and sends the selected scenario back to the intelligent alert system. The intelligent alert system searches the database to identify a default narrative for the selected scenario and sends the default narrative based on the suspect's facts back to the investigator's computer system. The investigator reviews the narrative and can make changes if necessary.
[0303] When the investigator saves the revised narrative, the investigator's computer system sends the revised narrative back to the Smart Alert System. The Smart Alert System stores the revised narrative and sends the SAR form with the revised narrative to the BSA Administrator's computer system. If the BSA Administrator approves the SAR form, the Smart Alert System sends the SAR form to FinCEN's computer system. If the investigator does not determine that any changes to the default narrative are necessary, the Smart Alert System may send the SAR form with the default narrative directly to the BSA Administrator's computer system for approval.
[0304] In some cases, the investigator is also the BSA Director, or the BSA Director authorizes the investigator to file a SAR directly without any approval. In these cases, the investigator may accept a pre-determined narrative based on the facts at the time. In response, the Smart Alert system can directly send a SAR with a pre-determined narrative based on the current facts to FinCEN's computer system.
[0305] After an investigator has received a predefined narrative for a scenario based on different sets of facts without any changes for a predefined number of times, the intelligent alert system can assume that the predefined narrative matches the investigator's writing style (or preferences) for that scenario. Therefore, when a future positive case with the same scenario is detected again for a current suspect, the intelligent alert system can directly send a SAR with the predefined narrative based on the current suspect's facts to FinCEN's computer system. This eliminates the labor associated with investigators and BSA supervisors.
[0306] The above description of a single selected scenario can also apply to multiple selected scenarios. For example, if an investigator has received a predefined number of predefined narratives for all selected scenarios of a detected case based on different sets of facts, the intelligent alert system can send a SAR with predefined narratives for multiple selected scenarios based on the suspect's current facts to FinCEN's computer system.
[0307] In addition to SAR filings, aspects of the present invention can be used by a computer system to automatically generate different types of reports based on the preferences of human authors. For example, a hospital may need to generate a report for each patient. A police department may need to generate a report for each incident. A school may need to generate a report for each student. There are many other needs for generating reports. Conventional reports require extensive human resources to generate. Aspects of the present invention can reduce the human resources used in generating reports.
[0308] Reports can be categorized into different types based on various factors, such as reason, purpose, criteria, and circumstances. For example, a hospital might use different types of reports based on the reason for a patient's hospitalization. For example, a reason might be heart surgery, childbirth, or the like. A patient may have multiple reasons for hospitalization. Furthermore, for each primary reason, there may be multiple sub-reasons. For example, if a patient is hospitalized due to needing heart surgery, there may be multiple reasons for this need. Detailed categorization of reasons is desirable because each different reason may require a different type of writing style (or preference) for generating a report. As another example, a police department might generate a report for an incident using a variety of reasons, purposes, criteria, and circumstances. In yet another example, a school might generate a report for each student using a variety of reasons, purposes, criteria, and circumstances.
[0309] A report may be written based on one or more facts. These facts may be stored in a database and comprised of data entered by humans, detected by sensors, collected from various sources, and / or derived from other data. Furthermore, a human may use words, phrases, sentences, symbols, etc. to link facts together to form a report. For ease of reference, the words, phrases, sentences, symbols, etc. that link facts together are collectively referred to as "link words."
[0310] In one configuration, a computer system stores facts in a database. The computer system provides an editing function for a human author to generate a set of factors, which may include reasons, objectives, criteria, plot points, etc. The computer system may also provide an editing function for the human author to use the set of facts to generate a default narrative for each factor. Furthermore, the computer system may also provide an editing function for the human author to write linking words for the default narrative for each factor. The computer system may also store the default narrative for each factor. The default narrative includes facts and linking words.
[0311] In one configuration, a computer system stores a default statement for each factor in a database. In this configuration, the default statement includes a linking word, the location of each fact in the statement, and a storage location in the database where each fact is stored. For example, a default statement might be "(Object 1) was involved in a car accident at (Object 2)." In this example, Object 1 and Object 2 are two facts. The computer system stores the entire sentence in the database, including the linking word "was involved in a car accident" and the locations of Object 1 and Object 2 in the sentence. Furthermore, the computer system stores the table name and field name of Object 1 and Object 2, respectively, in the database.
[0312] Data fields with the same definition can be stored in the same database table. For example, all patient names are stored in the same database table that lists all patient names. Therefore, when two narratives of two cases are written using two different sets of facts, a pair of corresponding facts located at the same position in each narrative is stored in the same database table. When multiple database tables are used to generate a fact, database keys used to link these multiple database tables can also be stored in the database. Therefore, when a new narrative of a new set of facts is generated using a pre-set comment or narrative based on an old set of facts, the computer system identifies each corresponding pair of facts and replaces the old facts with the corresponding new facts.
[0313] For example, Object 1 is stored in the "Patient Name" field of a Patient table, and Object 2 is the "Date" field of an Event table. In the above example, "Jack Daniel was in a car accident on January 20, 2018" and "Jim Beams was in a car accident on February 3, 2018" are based on the same narrative format but contain two different factual segments (e.g., patient name and event date). The linking word for these two scenarios is the same: "car accident occurred."
[0314] In one configuration, a computer system lists a set of factors, which may include reasons, objectives, criteria, plot points, etc. The computer system may allow a human author to select a factor based on a new set of facts to display a pre-set narrative. The human author may add, delete, or modify the link words in the narrative displayed by the computer system.
[0315] In one configuration, a computer system provides database search and editing capabilities, allowing a human author to add, delete, or modify facts and change the location of facts in a narrative displayed by the computer system. The human author can save the revised narrative as a new default narrative, which includes the facts, the location of each fact segment, and a linking keyword. The computer system stores database table, keyword, and field information for each fact in the new default narrative.
[0316] In one aspect of the present invention, a human author selects a factor to display a new predefined narrative based on a set of new facts and the same set of linking words stored in a database. A computer system extracts each new segment of the new fact based on the location of the old corresponding segment of the old fact stored in the database. The computer system can then display each new fact within the linking words in the narrative based on the location of each old corresponding fact in the narrative.
[0317] In one configuration, the computer system provides a human author with the ability to add, delete, or modify link words in a new default narrative displayed by the computer system. The human author can also add, delete, or modify facts and change the position of facts in the new default narrative displayed by the computer system. The human author can then save the revised new default narrative as the next new default narrative.
[0318] The above process can be repeated so that a human author can continue to revise the default narrative based on a new set of facts and store the modified default narrative as the next new default narrative. Due to this evolutionary process, future default narratives can match the preferences of the human author.
[0319] In one aspect of the present invention, a narrative is considered mature for a selected factor if the human author has not modified the narrative for a different case using a different set of facts for a predefined number of instances based on the same factor selected by the human author. The predefined number may be defined by a person and / or a computer system.
[0320] In one configuration, a link word is considered mature for a selected factor if the human author has not changed the link word displayed by the computer system for a predefined number of instances based on the same factor selected by the human author using different sets of facts for different cases. The predefined number of instances can be defined by a human and / or a computer system.
[0321] In one configuration, if a narrative is mature for a factor selected by a human author, the computer system automatically skips or suggests to the human author that the narrative review process be skipped and generates a report for the selected factor using the current default narrative as a standard narrative format. The standard narrative format contains facts that may vary from report to report and the same set of linking words that matches the writing style (or preference) of the human author.
[0322] In one configuration, if the link word is mature for a factor selected by a human author, the computer system automatically skips or suggests to the human author to skip the narrative review process and generates a report for the selected factor using the current default link word as the standard link word.
[0323] In one configuration, if a human author has selected multiple factors to write a report, the computer system uses the selected factors to generate a narrative section for each factor and combines the multiple narrative sections based on the multiple selected factors to generate the report.
[0324] An introduction section may be inserted at the beginning of the report. The introduction section may contain facts and / or linking words. The facts and / or linking words may be revised by the human author over multiple reports to ultimately match the human author's writing skills (or preferences) based on the evolutionary process explained in this invention.
[0325] A link section can be inserted in the middle of the report. The link section contains facts and / or link words that can be revised by the human author through multiple reports to eventually match the human author's writing skills (or preferences) based on the evolutionary process explained in this invention.
[0326] A conclusion section may be inserted at the end of the report. The conclusion section includes facts and / or linking words that may be revised by the human author over multiple reports to ultimately match the human author's writing skills (or preferences) based on the evolutionary process explained in this invention.
[0327] Due to the present invention, the computer system learns the writing style (or preference) of each human author and can automatically generate various reports based on the writing style (or preference) of each human author.
[0328] One or more of the above examples are based on anti-money laundering applications in financial institutions. However, the present invention can also be applied to many other different types of applications for different organizations and different purposes. For example, a government organization could use a smart alert system to identify any employees who might potentially steal confidential information from the government. A school could use a smart alert system to identify any students who might potentially drop out. A social networking company could use a smart alert system to identify any members who might potentially engage in illegal activity on the social network. An employer could use a smart alert system to identify any employees who might potentially resign. A marketing company could use a smart alert system to identify a target for a potential business transaction. A smart alert system could also be a mobile application used by a person to identify potential stocks or commodities for investment purposes. As a public health application, a smart alert system could be a mobile application that monitors a person's health and sends a notification if a potential health issue exists. There are countless applications for smart alert systems. The following process is an example of how to design and develop a smart alarm system to monitor a group of objects for any specific purpose.
[0329] In one configuration, an intelligent alert system assigns scores to various factors. Additionally or alternatively, the intelligent alert system assigns scores to the extent of each factor. The extent of a factor is used to distinguish different levels of impact of the factor. For example, sending a wire transfer is a risk factor considered for money laundering prevention purposes. However, the dollar amount of the wire transfer may have different impacts. For example, a wire transfer amount from $0 to $10,000 may have a low money laundering risk level, while a wire transfer amount from $250,000 to $1,000,000 may have a high money laundering risk level. Factors may be based on data associated with subjects that have a positive or negative impact on achieving a goal. The intelligent alert system assigns a score to each factor. The intelligent alert system can identify the likely extent of a factor in data associated with subjects that have a positive or negative impact on achieving a goal. The intelligent alert system assigns a score to the extent of each factor. In one configuration, the intelligent alarm system generates an overall score for each monitored object by summing all scores for factors or factor levels associated with the object.
[0330] The intelligent alert system utilizes a set of scenarios based on various criteria. The criteria may include factors derived from data associated with the subject, degrees of factors derived from data associated with the subject, and / or scores derived from data associated with the subject. Additionally or alternatively, the criteria may be based on rules derived from a decision tree, specific categories associated with the subject, an if-then conditional structure derived from a model trained using a machine learning network, an if-then conditional structure derived from a behavioral pattern, an if-then conditional structure derived from a transaction pattern, factors established by a software module, and / or factors established by a user or designer of the system.
[0331] Through the above methods, scenarios for the intelligent alarm system can be established in a variety of ways. These scenarios may trigger an alarm, generating potential cases, and each potential case may have one or more scenarios in its cause vector. The intelligent alarm system can list a set of potential cases triggered by one or more scenarios. Investigators can review the potential cases to determine which are true positives and which are false positives. In addition, investigators can review current potential cases along with historical potential cases to determine which combinations of cases are true positives or false positives.
[0332] In one configuration, the intelligent alert system enables investigators to review the circumstances of a potential case to determine which combinations of circumstances result in true positives and which combinations of circumstances result in false positives. The intelligent alert system also enables investigators to review the circumstances of the current potential case and the circumstances of historical potential cases to determine which combinations of circumstances result in true positives and which combinations of circumstances result in false positives.
[0333] Although a combined cause vector is obtained by combining several cause vectors, it has the same form as a cause vector. By definition, a combined cause vector is the cause vector of the combined case. Therefore, the conditional probability P(S / cbv) of a combined cause vector and the conditional probability P(S / x) of a cause vector can be calculated using a similar method.
[0334] Furthermore, while a cause vector (or a combined cause vector) may trigger a potential case for investigation, the reason for reporting the case may be based on a subset of the episodes in the cause vector. To maintain the accuracy of the posterior probability calculation, it is desirable to identify the subset of episodes that form the true cause vector that is the correct positive.
[0335] The Smart Alert System enables investigators to review the circumstances of a potential case to identify the true causal vector if the potential case is a true positive. If a combined potential case is a true positive, investigators can review the circumstances of the combined potential case to identify the true causal vector. The Smart Alert System stores the investigation results and associated causal vector (or true causal vector) for each potential case. As explained above, once the true causal vector has been determined, the set of circumstances comprising the true causal vector can be used to generate a narrative that can automatically complete and submit a SAR form to FinCEN.
[0336] In one configuration, the intelligent alarm system stores the investigation results of a combined case and the combined case's associated combined cause vector (or true combined cause vector). Each combined cause vector (or true combined cause vector) can consist of one or more scenarios. The results and other information can be stored in a database or other data structure.
[0337] After investigators have used the smart alarm system for a period of time, it accumulates a large amount of data related to the subject. This data may include historical potential cases, historical investigation results (e.g., true positives or false positives), and associated cause vectors (or true cause vectors). Therefore, as the system's usage increases, its accuracy may improve. In other words, the system's accuracy can be improved through the accumulation of data.
[0338] For the sake of clarity, a cause vector or a true cause vector is generally referred to below as a cause vector. Furthermore, a cause vector is generally referred to below as including both a cause vector and a combined cause vector. Thus, a cause vector generally refers to a cause vector, a combined cause vector, a true cause vector, and / or a true combined cause vector.
[0339] In one configuration, the system calculates the conditional probability for each cause vector after the amount of historical data exceeds a threshold. The threshold can be based on the number of actual cases, the number of potential cases, the size of the data, and / or other factors. The conditional probability for a cause vector over a given time period is the number of true positives triggered by the cause vector divided by the total number of potential cases triggered by the cause vector.
[0340] In one aspect of the present invention, when the conditional probability of a cause vector falls below a false positive rejection threshold, the intelligent alarm system rejects a potential case triggered by a cause vector as a false positive. The false positive rejection threshold can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0341] In some cases, if potential cases triggered by a cause vector consistently have a low conditional probability, the cause vector's scenarios may not be appropriately defined. In these cases, the user can adjust the cause vector's scenarios to increase the predicted probability. A smart alert system can prompt the user to make these changes.
[0342] The intelligent alarm system can accept a potential case triggered by a cause vector as a true positive in response to the conditional probability of the cause vector exceeding a true positive acceptance threshold. The true positive acceptance threshold can be set by a software module, a person who designs the system, a person who tunes the system, and / or a user of the system.
[0343] A vector of multiple elements can be converted into a combination of multiple vectors. For example, vector A has three elements v1, v2, and v3. In this example, vector A can be a combination of three vectors (e.g., vector B with element v1, vector C with element v2, and vector D with element v3). For clarity, vector A is referred to as the parent vector. Vectors B, C, and D can be referred to as child vectors. In the following disclosure, the parent vector will be considered the parent vector.
[0344] The above example assumes a subvector has only one element. In general, a subvector can have multiple elements. For example, vector A in the above example can have a subvector with elements v1 and v2. Because each element can be included in or excluded from the parent vector to form a subvector, a parent vector with N elements can have a total of 2N possible combinations, including the parent vector itself with all N elements and an empty vector with no elements. Therefore, a parent vector with N elements can have 2N-2 possible meaningful subvectors. Each element of a cause vector corresponds to an episode. When the element is 1, the corresponding episode is included. When the element is 0, the corresponding episode is excluded. A subset of the episodes of the parent cause vector can form the episode of a child cause vector.
[0345] Generally, an increase in the number of episodes in a cause vector can increase the conditional probability value of the cause vector. For example, if a first cause vector has only episode A as its vector element and a second cause vector has both episode A and episode B as its vector elements, the conditional probability value of the second cause vector should be the same as or higher than the conditional probability value of the first cause vector.
[0346] Therefore, a parent cause vector has the same conditional probability value as any of its child vectors or a conditional probability value higher than any of its child vectors. That is, if a child vector already has a conditional probability value greater than the true positive acceptance threshold, then the conditional probability value of the parent cause vector is also greater than the true positive acceptance threshold.
[0347] In one configuration, the intelligent alarm system accepts a potential case triggered by a cause vector as a true positive when the conditional probability value of one of the subvectors of the cause vector is equal to or greater than a threshold value. The threshold value can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0348] A current potential case can be combined with a group of historical potential cases to form a combined cause vector. When the conditional probability value of one of the subvectors of the combined cause vector is equal to or greater than a threshold value, the intelligent alarm system can accept the combined cause vector of the potential case as a true positive. The threshold value can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0349] It may be difficult for an intelligent alarm system to try all possible combinations of historical potential cases to determine whether a particular combination of historical potential cases and current potential cases satisfies the automatic true positive acceptance criteria. Therefore, in one configuration, the intelligent alarm system accepts a combined cause vector as a true positive when the conditional probability value of one of the subvectors of the combined cause vector is equal to or greater than a threshold value. The threshold value can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0350] Generally, all potential cases associated with an object can be related to each other. Furthermore, all potential cases associated with a group of related objects can be related to each other. For example, if five students live in the same dormitory, all potential cases associated with any of these five students are related cases. The scope defining the relationships between related potential cases can be set by a software module, a person designing the system, a person tuning the system, and / or a user of the system.
[0351] If the smart alarm system has been in use for an extended period of time, using all relevant potential cases may not be practical or effective. That is, the number of relevant potential cases may be excessive, thereby reducing efficiency. Therefore, it may be desirable to limit the scope of relevant cases to a time period. In one configuration, a combined cause vector can be generated from a current potential case and a group of related historical potential cases that occurred within a predefined time period. When the conditional probability value of a subvector of the combined cause vector is equal to or greater than a threshold value, the smart alarm system can accept the combined cause vector as a true positive. The threshold value can be set by a software module, a person who designs the system, a person who tunes the system, and / or a user of the system. The predefined time period can be set by a software module, a person who designs the system, a person who tunes the system, and / or a user of the system.
[0352] The intelligent alert system provides investigators with an opportunity to investigate cases that were not automatically rejected as false positives and not automatically accepted as true positives. The intelligent alert system records the investigation results for each potential case and its associated cause vector. This information is used to calculate future conditional probability values for the cause vector.
[0353] Because the smart alert system continues to use the survey results to further adjust future conditional probabilities, it can adapt to future environmental changes. The more potential cases the smart alert system can handle without human interaction, the fewer potential cases are left for investigators to handle.
[0354] The intelligent alarm system can exclude cases that are automatically accepted as true positives or rejected as false positives from the calculation of posterior probability values. This approach avoids problems caused by positive feedback. For example, if a potential case triggered by a cause vector x has been automatically accepted as a true positive, then if the results of this case are included in the calculation of the posterior probability value for cause vector x, the value of the conditional probability p(S / x) may increase. Therefore, the next potential case triggered by cause vector x can be automatically accepted as a true positive. The automatic acceptance of future potential cases triggered by cause vector x will continue because the posterior probability value continues to increase. In other words, once a potential case triggered by a cause vector has been automatically accepted as a true positive, if the accepted case is included in the calculation of the posterior probability value for the cause vector, all future potential cases triggered by the same cause vector will be automatically accepted as true positives. This is undesirable because this "no return" process deprives the intelligent alarm system of the ability to recalibrate itself in the event of future environmental changes.
[0355] In one configuration, the intelligent alert system does not automatically reject a potential case if its conditional probability value falls below the false positive rejection threshold. Therefore, an investigator can fine-tune the conditional probability value based on this potential case. For reference, this case is referred to as a false positive validation case. The number, percentage, and / or frequency of false positive validation cases is determined by a software module, a person designing or tuning the system, and / or a user of the system.
[0356] Additionally, in some cases, when a potential case's conditional probability value exceeds the true positive acceptance threshold, the intelligent alert system may not automatically accept the potential case as a true positive. Therefore, an investigator can fine-tune the conditional probability value based on this potential case. For clarity, this case is referred to as a true positive verification case. The number, percentage, and / or frequency of true positive verification cases is determined by a software module, the person designing or tuning the system, and / or a user of the system.
[0357] In some cases, specific subjects are treated differently for different reasons. For example, some subjects may be placed on a "do not compare list" or a "white list." A potential case associated with a subject on one of these lists may be considered a false positive, without requiring any investigation. For example, placing a politician on a money laundering prevention system's "do not compare list" may be a politically correct decision, regardless of any other detections. Similarly, for other purposes, a potential case associated with a subject on another list may be considered a true positive, without requiring any investigation.
[0358] Because these cases are treated differently, they are considered outliers. It is desirable to exclude these outliers from the calculation of the posterior probability value. The intelligent alert system can skip a potential case associated with an object on a "do not compare list" or "white list." Skipped cases are not used when calculating the posterior probability value for the cause vector.
[0359] In some cases, an alarm triggered by a scenario related to an object may become a false alarm because the scenario is inappropriate for monitoring the object. For example, a cash-intensive business may naturally have more cash than other types of businesses, and a scenario comparing the cash amounts of this business with those of other businesses may be meaningless and inappropriate. In such cases, an investigator can mark the scenario as verified for the object. This means that the scenario has been verified by an investigator for the object, and if another alarm is triggered by the scenario for the object, no action is required. Therefore, a potential case triggered by a scenario with a verified status is also considered an outlier.
[0360] In one configuration, the intelligent alarm system skips a potential case associated with an object having a verified state related to a scenario that triggers the potential case. The intelligent alarm system does not include the skipped case in the calculation of the posterior probability value of the cause vector.
[0361] When an investigator dismisses a potential case as a false positive, the intelligent alert system prompts the investigator to determine whether the scenario that triggered the potential case should be marked as verified. If this scenario is not marked as verified, it may trigger another false positive in the future. Therefore, it is desirable to mark a scenario as verified when a potential case triggered by a scenario is determined to be a false positive.
[0362] The number of potential cases used to calculate a conditional probability value can also affect the reliability of the conditional probability value. For example, if only one potential case was triggered by a cause vector x and an investigator accepted that potential case as a true positive, the conditional probability p(S / x) may be unreliable, even if it has a value of 100%. However, if five potential cases were triggered by a cause vector x and the conditional probability p(S / x) is 100%, then this conditional probability may be more reliable than the previous example.
[0363] When the conditional probability of a cause vector is less than a threshold value A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability is greater than a threshold value B, the intelligent alarm system can automatically reject a potential case triggered by the cause vector as a false positive. Each of the threshold values A and B can be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0364] When the conditional probability of a cause vector exceeds threshold A and the number of potential cases triggered by the cause vector and used to calculate the conditional probability exceeds threshold B, the intelligent alarm system accepts a potential case triggered by the cause vector as a true positive. Thresholds A and B can be set by a software module, a person designing or tuning the system, and / or a user of the system.
[0365] It may be desirable to use different conditional probability thresholds for subjects in different categories when the intelligent alert system automatically accepts a potential case as a true positive or rejects a potential case as a false positive based on the conditional probability threshold. For example, a financial institution may still file a SAR for a current potential case even if the conditional probability of a potential case associated with a subject who was a suspect in a previous SAR case is lower than the true positive acceptance threshold.
[0366] In one configuration, the intelligent alert system uses different true positive acceptance thresholds and false positive rejection thresholds for different categories of objects. The different categories can be defined by a software module, a person designing or tuning the system, and / or a user of the system. In a money laundering prevention application, these categories may include a customer who is a suspect in a previous SAR, a customer matched on the OFAC list, a customer matched on the 314(a) list, a customer matched on the Highly Visible Political Figures list, a customer matched on other watch lists, a high-risk customer, a medium-risk customer, a low-risk customer, a high-risk counterparty, a medium-risk counterparty, a low-risk counterparty, a high-risk country, a medium-risk country, a low-risk country, a high-risk region, a medium-risk region, a low-risk region, a high transaction amount, a medium transaction amount, a low transaction amount, etc.
[0367] Because these categories can also be factors (e.g., risk factors) used for score assignment and calculation purposes (e.g., risk scores), it is desirable to use different true positive acceptance thresholds and false positive rejection thresholds for different factors. In one aspect of the present invention, the intelligent alert system allows a user to assign a true positive acceptance threshold and a false positive rejection threshold to each factor.
[0368] In one configuration, if the conditional probability of the cause vector is higher than one of the true positive acceptance thresholds of the factors associated with a potential case, the intelligent alarm system accepts the potential case as a true positive. If the conditional probability of the cause vector is lower than one of the false positive rejection thresholds of the factors associated with a potential case, the intelligent alarm system may reject the potential case as a false positive.
[0369] This approach can be complex when many factors are involved. Therefore, it is desirable to select only a few important factors and assign different true positive acceptance thresholds and false positive rejection thresholds. In one configuration, the intelligent alarm system allows a user to select a set of factors and assign a true positive acceptance threshold to each selected factor. A user can also select a set of factors and assign a false positive rejection threshold to each selected factor.
[0370] Thus, if the conditional probability of a cause vector is higher than one of the true positive acceptance thresholds of the selected factor associated with a potential case triggered by the cause vector, the intelligent alarm system may accept the potential case as a true positive. Alternatively, if the conditional probability of a cause vector is lower than one of the false positive rejection thresholds of the selected factor associated with a potential case triggered by the cause vector, the intelligent alarm system may reject the potential case as a false positive.
[0371] To increase accuracy, it is desirable to ensure that the total number of potential cases is greater than a threshold when calculating the conditional probability. The threshold can be a number of cases or a time period. The user can set the threshold as needed.
[0372] In one configuration, the intelligent alarm system records potential cases, investigation results, associated cause vectors, and the date and time the record was created. The intelligent alarm system can calculate the conditional probability of a cause vector x, which is the number of true positives triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.
[0373] After calculating the conditional probability value, the intelligent alarm system also records additional values in a database, such as: (1) the number of true positives triggered by cause vector x at that time, (2) the total number of potential cases triggered by cause vector x at that time, and (3) the date and time of the calculation, which can be referred to as the last calculation time for cause vector x. By storing these additional values, the intelligent alarm system does not need to repeat the same calculation to obtain the same value for cause vector x again.
[0374] The intelligent alarm system can update the conditional probability of cause vector x, which is based on the sum of the number of correct positives triggered by cause vector x (before the last calculation time) and the number of correct positives triggered by cause vector x (after and including the last calculation time) divided by the sum of the total number of potential cases triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (after and including the last calculation time).
[0375] In the above calculation, the number of true positives triggered by cause vector x (before the last calculation time) plus the number of true positives triggered by cause vector x (after and including the last calculation time) is equal to the number of true positives triggered by cause vector x at the current calculation time. Similarly, the total number of potential cases triggered by cause vector x (before the last calculation time) plus the total number of potential cases triggered by cause vector x (after and including the last calculation time) is equal to the total number of potential cases triggered by cause vector x at the current calculation time. Therefore, the above calculation will reach the same conditional probability p(S / x), which is the number of true positives triggered by cause vector x divided by the total number of potential cases triggered by cause vector x.
[0376] After the last calculation of the conditional probability, both the number of true positives triggered by cause vector x (before the last calculation time) and the total number of potential cases triggered by cause vector x (before the last calculation time) can be stored in the database. The intelligent alarm system can then search the database to find these two values. The intelligent alarm system then calculates two new values based on potential cases detected after and including the last calculation time. This approach reduces many calculations, which in turn reduces the amount of data stored in memory.
[0377] In one aspect of the present invention, once the calculation of the conditional probability value is completed, in addition to the potential case, the investigation result, and the cause vector x, the intelligent alarm system also stores additional values, such as: (1) the number of true positives triggered by the cause vector x at that time, (2) the total number of potential cases triggered by the cause vector x at that time, and (3) the date and time of the calculation, which can be referred to as the new last calculation time of the cause vector x. Therefore, these values will simplify the next round of calculation of the conditional probability of the potential case triggered by the cause vector x.
[0378] The above method can be further modified during the software coding process. In one aspect of the present invention, the intelligent alarm system maintains two counters for a cause vector x, one counter for the number of true positives (NTPX) and the other counter for the number of potential cases (NPCX).
[0379] In one aspect of the present invention, the intelligent alarm system resets two counters, NTPX and NPCX, to zero to begin counting. As an example, a potential case triggered by cause vector x may be manually reviewed by an investigator and determined to be a true positive. In this example, the intelligent alarm system increments the NTPX counter by 1 because the number of true positives from manual review triggered by cause vector x has increased to 1. For the current example, the system also increments the NPCX counter by 1 because the number of potential cases triggered by cause vector x has increased to 1.
[0380] As another example, a potential case triggered by cause vector x is manually reviewed by an investigator and determined to be a false positive. In this example, the intelligent alarm system increments the NTPX counter by 0 because the number of true positives triggered by cause vector x has not yet increased, and increments the NPCX counter by 1 because the number of potential cases triggered by cause vector x has increased to 1.
[0381] In a configuration, the conditional probability p(S / x) of a new potential case triggered by cause vector x is NTPX divided by NPCX. This method reduces the computational complexity of the conditional probability p(S / x) and simplifies software coding.
[0382] Although a cause vector x is used in this example, the above method can be applied to any cause vector. The intelligent alarm system can have many pairs of counters, one for each cause vector. As explained above, the total number of pairs is finite because only a very small number of scenarios can coexist in the same cause vector to trigger a potential case.
[0383] By using the above method, the intelligent alarm system can reduce the amount of time used for calculation. In addition, when more potential cases are used in the calculation to derive the conditional probability value, the accuracy of the conditional probability value increases.
[0384] Because the smart alert system continues to learn from human workers, it is only a matter of time before the smart alert system automatically detects an alert and makes the decision to file a SAR, completes the SAR form, writes a narrative, and sends the SAR form to FinCEN. The smart alert system will reduce human resources and will handle SAR compliance matters in a manner similar to how a human would handle SAR compliance matters.
[0385] Although the detection of suspicious activity, investigation of SAR cases, and filing of suspicious activity reports are used as an example, the same set of methods in the present invention can be used to handle the detection of currency transactions, investigation of CTR cases, and filing of currency transaction reports (CTRs) to FinCEN.
[0386] Similarly, the same set of methods in this invention can be used to handle the detection of potential OFAC matches, the investigation of potential matches, and the reporting of actual matches to the Office of Foreign Assets Control (OFAC). In these cases, the relative correlation (RC) value used to measure the degree of match is equivalent to the risk score used to measure the degree of risk. Therefore, instead of using scenarios based on risk scores, the intelligent alert system can use scenarios based on RCs.
[0387] The OFAC list is just one example of many regulatory lists. The same set of methods in this invention can be used to detect, investigate, and report matches against all types of regulatory lists, such as the 314(a) list, the Denied Persons List, the Highly Visible Politically Exposed Persons List, and any other lists published by governmental and / or non-governmental organizations. Those familiar with regulatory compliance requirements will appreciate that the same set of methods in this invention can be used to detect, investigate, and report matches against any subject subject to any type of regulatory reporting requirement.
[0388] As discussed, the present invention describes the functionality that can be implemented by a smart alarm system for various applications that can generate an alarm. A human can review the alarm and perform subsequent actions based on the alarm review. In one configuration, the smart alarm system learns from the human's actions, makes decisions on their behalf, and performs subsequent actions for them. Thus, the smart alarm system reduces human workload and time and can replace some or all humans in such applications.
[0389] Typically, because a financial institution could suffer significant losses in a fraud case, they set low thresholds for generating fraud alerts in their smart alert systems. These low thresholds result in an increased number of false positives. Investigating fraud alerts to distinguish actual fraud from a false positive is laborious and time-consuming.
[0390] Aspects of the present invention relate to a computer system and network for rejecting false positives and confirming true positives. In one configuration, the rejection of false positives and the confirmation of true positives can be automated (e.g., without requiring any human intervention). The rejection of false positives and the confirmation of true positives can improve fraud detection and reduce the damage (e.g., financial loss) caused by fraud.
[0391] In one aspect of the present invention, in response to detecting an alert, a smart alert system sends at least a portion of transaction details to a consumer protection system. The alert may be generated in response to a transaction between a payer and a payee. The payer may be a client of a financial institution. The consumer protection system may be a computer system or a device interface. The transaction details may be transmitted via a communication channel. In this invention, a communication channel refers to a wired network (e.g., the Internet), a wireless network (e.g., a mobile phone network), and / or another type of communication channel. Unless otherwise indicated, transmissions between devices, individuals, systems, organizations, and / or other entities in this application may be performed via a communication channel.
[0392] Transaction details may include one or more of the following: a transaction date, a transaction time, a transaction amount, a payer's account number, a payer's routing number, a payer's card number, a payer's wallet number, a payer's phone number, a payer's email address, a payer's other contact information, a payer's personal identification information, a SWIFT number of the payer's bank, a payee's account number, a payee's routing number, a payee's card number, a payee's wallet number, a payee's phone number, a payee's email address, a payee's other contact information, a payee's personal identification information, a SWIFT number of the payee's bank, and other information that may be used to define the transaction. A payer may be a person or an organization. A payee may be a person or an organization.
[0393] In one aspect of the present invention, a consumer protection system sends a portion of the transaction details to a payer (e.g., a customer of a financial institution). The portion of the transaction details may be transmitted to a payer's device. The payer's device (e.g., a device interface) may include, for example, a mobile phone, a tablet, a laptop, a computer system, etc. The transmission may be facilitated based on the payer's phone number, the payer's email address, the payer's device interface address, and / or other contact information of the payer.
[0394] The payer can review some of the transaction details to determine whether the transaction is legitimate. If the transaction is legitimate, the payer accepts the transaction. Alternatively, if the transaction is not legitimate, the payer rejects the transaction. The payer's input (e.g., confirmation or rejection) is transmitted from the payer's device to the consumer protection system via a communication channel.
[0395] In one aspect of the present invention, the consumer protection system sends the payee's response to a smart alert system, which generates an alert regarding a potential fraud case. If the payee accepts the transaction, the smart alert system dismisses the alert as a false positive. If the payee declines the transaction, the smart alert system notifies the financial institution's transaction system to block the transaction. The transaction blocking process does not involve human interaction; that is, it is automated. The smart alert system can work together with the consumer protection system to block fraud or dismiss a false positive alert without any human intervention.
[0396] Furthermore, a payee's rejection of a transaction may indicate that a criminal may have stolen financial instruments, financial account information, identity, etc. from the payee. In such cases, the consumer protection system sends an alert to one or more devices associated with financial institutions, merchants, and any other organizations that have subscribed to the services provided by the consumer protection system. Thus, once a payee has declined a transaction, the payee is protected because the criminal cannot use the same method to commit another crime against the payee through the financial institutions, merchants, and organizations that have received the alert.
[0397] At any given time, all financial institutions, merchants, and any other organization that needs to prevent financial crime can subscribe to the alert service provided by the consumer protection system. This approach can reduce or even eliminate many types of financial crime, such as check fraud, credit card fraud, debit card fraud, ATM fraud, online banking fraud, ACH fraud, remittance fraud, virtual currency fraud, and identity theft. Consequently, the volume of financial crime can be reduced.
[0398] Furthermore, in one aspect of the present invention, consumers and organizations can be encouraged to open accounts in the consumer protection system to become members of the consumer protection system. In one configuration, during the account opening process, the consumer protection system collects a portion of the new member's identifying information, such as name, date of birth, address, zip code, city, country of residence, etc.
[0399] In another aspect of the present invention, the consumer protection system collects financial instrument numbers and financial account numbers from new members through a device interface, such as checking account numbers, savings account numbers, routing numbers, credit card numbers, debit card numbers, ATM card numbers, virtual currency wallet numbers, insurance account numbers, transaction account numbers, cryptocurrency wallet address numbers, and any other information that can identify a financial account, a financial instrument, or any financing tool that can be used to conduct a transaction. For increased security, the consumer protection system can collect all of a member's financial instrument numbers and financial account numbers.
[0400] Additionally, a new member may be prompted through a device interface to provide expiration dates and descriptions of financial instruments, financial accounts, and financing instruments. Furthermore, the consumer protection system may prompt the member to provide identification information for the member's device, such as a phone number, email address, device interface address, IP address, etc. The member may be an individual or an organization. This process for collecting information from the member is referred to as a "registration process" or "ownership registration process." The registration process may collect one or more of the identification information, financial instrument number and financial account number, expiration date and description, and device identification information.
[0401] After a member has opened an account in the consumer protection system and completed the registration process, they will be protected against many types of financial crime. For example, a party (e.g., an individual or an organization) may use a credit card to conduct a transaction with an online merchant. The merchant receives from the party a portion of the credit card information (e.g., the last four digits of the credit card number), along with the cardholder's name, the account address associated with the credit card, the cardholder's phone number, and the cardholder's email address. The merchant converts this information into an identification code. The meaning of an identification code is explained in more detail below.
[0402] The merchant transmits the identification code and a portion of the transaction details to the consumer protection system. The consumer protection system sends the portion of the transaction details to a device (e.g., a mobile phone) of a member whose identification code matches the received identification code based on the information provided by the subject. The portion of the transaction details may be transmitted based on the member's device identification information provided by the member.
[0403] The member can accept or decline the transaction through the device. If the member accepts the transaction, the consumer protection system notifies the merchant system that the transaction has been accepted by the registered owner of the credit card. The merchant system can then proceed with the transaction without worrying about fraud. Because the merchant only sends the identity code to the consumer protection system, the member's original identification information is protected during this process.
[0404] Smart alert systems may not be used by all financial institutions, as some may have their own systems. In the following example, the financial institution system does not use a smart alert system. Furthermore, in this example, after the merchant system submits the transaction to the financial institution system for approval, the financial institution system detects the transaction as a fraud alert. In response to detecting the fraud alert, the financial institution system may send a portion of the transaction details and the credit card number to the consumer protection system. Because the member has already accepted the transaction, there is no need to contact the member again. The consumer protection system can notify the financial institution system that the member has accepted the transaction. If there are no other issues, such as insufficient credit, the financial institution system can proceed with approving the transaction. This process can be completed without any human intervention.
[0405] In one aspect of the present invention, if the member declines the transaction through their device interface, the consumer protection system notifies the merchant system that the transaction has been declined by the registered owner of the credit card. Consequently, the merchant system declines the transaction. In this process, there is no third-party human involvement in fraud prevention. The merchant system and the consumer protection system can work together to prevent fraud without any human intervention.
[0406] In some cases, a member's transaction rejection may indicate that a fraudster has stolen financial instruments, financial account information, financing tools, or identity from the member. In these cases, the consumer protection system sends an alert to one or more devices of financial institutions, merchants, and / or organizations that have subscribed to the alert service provided by the consumer protection system. The devices of the financial institutions, merchants, organizations, etc. communicate with associated computer systems to prevent future financial crimes based on the alert. Therefore, once a member rejects a transaction, the member is protected because the criminal cannot use the same method to commit another crime against the member at the financial institution, merchant, organization, etc. that has received the alert.
[0407] While an online merchant is used in the above example, the same approach can be applied to all types of merchants. Furthermore, while a credit card is used in the above example, other types of financial instruments, financial accounts, financing tools, etc. can be used. For reference purposes, a definition of a device interface is provided in the [Summary of the Invention] section of this disclosure.
[0408] Check deposit fraud occurs when an individual deposits a check and then quickly withdraws a large amount of cash based on the deposited check before the financial institution can verify that the deposited check is invalid. Check deposit fraud is particularly common in financial institutions that do not withhold deposited checks before clearing them.
[0409] As an example application of a consumer protection system, when a subject cashes (or deposits) a check at a financial institution (e.g., a bank, credit union, money service business, etc.), the financial institution may transmit the checking account number, routing number, payee name, check serial number, and the dollar amount shown on the check to the consumer protection system. The consumer protection system transmits the payee name, check serial number, and dollar amount to a device (e.g., a mobile phone) of a member whose checking account number and routing number match the checking account number and routing number shown on the check provided by the subject. The payee name, check serial number, and dollar amount may be transmitted based on device identification information provided by the member to the computer protection system.
[0410] The member can accept or decline the transaction through the device. If the member accepts the transaction, the consumer protection system notifies the financial institution that the transaction has been accepted by the registered owner of the checking account. The financial institution can proceed to cash (or deposit) the check without worrying about forged check fraud, altered check fraud, or check deposit fraud.
[0411] In one aspect of the present invention, if the member declines the transaction through the device interface, the consumer protection system notifies the financial institution that the transaction has been declined by the registered owner of the checking account. Accordingly, the financial institution declines the check presented by the subject.
[0412] Additionally, the consumer protection system sends an alert to one or more devices of financial institutions, merchants, and / or organizations that have subscribed to the alert service provided by the consumer protection system. The devices of the financial institutions, merchants, organizations, etc. communicate with associated computer systems to prevent future financial crimes based on the alert.
[0413] For example, in one aspect of the present invention, when a person enters a password to conduct a virtual currency transaction based on a payer's wallet address, the virtual currency transaction system sends the payer's wallet address and a portion of the transaction details to the consumer protection system. The consumer protection system then sends a portion of the transaction details to the mobile phone of a member who has registered the wallet address in their account. The member can accept or decline the virtual currency transaction through a mobile app. The member's action on their mobile phone (e.g., their response) can be sent back to the consumer protection system. The consumer protection system can then send the member's response to the virtual currency transaction system. Therefore, even if the person enters a correct password, if the member declines the transaction, the virtual currency transaction system can still block the transaction. On the other hand, if the member accepts the transaction and the person enters the correct password, the virtual currency transaction system can complete the transaction. In one configuration, if the member denies a criminal's account access, the consumer protection system sends an alert to the device interfaces of all alert subscribers to protect the member.
[0414] The examples provided above are not limited to mobile devices. Other types of device interfaces are contemplated. Furthermore, users can accept or decline a transaction through an application within the device interface. Transactions based on a virtual currency account can be used with any type of account (e.g., online banking, insurance, or trading accounts), as long as the member has registered the account with the consumer protection system.
[0415] Financial institutions can also become members of a consumer protection system. In one configuration, a financial institution's computer system sends all addresses (e.g., phone numbers, email addresses, etc.), account names, and account numbers of its customers' device interfaces to the consumer protection system. The consumer protection system can contact the customer via the device interface and prompt the customer to download an application on the device interface (e.g., mobile phone, computer, etc.). Furthermore, the consumer protection system can prompt the customer to register their account numbers, financial instrument numbers, and other financial information with the consumer protection system through the application. In one aspect of the present invention, the consumer protection system verifies the information provided by the customer. Thus, all such customers can become members of the consumer protection system.
[0416] Furthermore, if a customer discovers that their financial instrument (e.g., checkbook, credit card, debit card, ATM card, etc.) is lost or stolen, they can immediately notify the consumer protection system. In response, the consumer protection system notifies the financial institution's computer system to block all transactions associated with the lost or stolen financial instrument. As a result of this proactive action taken by the consumer, the financial institution and merchant are protected by the consumer protection system without any human intervention.
[0417] In one possible scenario, all financial institutions, businesses, and organizations subscribe to the alert service provided by the consumer protection system. Thus, the consumer protection system can automatically stop criminals from committing crimes against financial institutions, consumers, businesses, and any organizations without any human intervention.
[0418] Fraudsters may attempt to open a member account in the consumer protection system and register the victim's financial instrument number, financial account number, and other financial information based on the fraudster's contact information (e.g., phone number, email address, etc.). Therefore, internal fraud prevention within the consumer protection system is important.
[0419] In one aspect of the present invention, when a person attempts to open a membership account in the consumer protection system, their identification information is scanned against blacklists provided by various sources (such as an internal blacklist, etc.) If there is a match, the consumer protection system will not open the account.
[0420] In one aspect of the present invention, a consumer protection system can periodically scan members against watchlists (such as the OFAC list, the Denied Persons List, etc.). This functionality can be achieved using the popular PATRIOT OFFICER system available from GlobalVision Systems, Inc. of Chatsworth, California. A consumer protection system is not a financial institution and does not have the regulatory obligations that financial institutions have. However, it is desirable to identify members of watchlists and notify financial institutions when a customer is an identified member of a watchlist.
[0421] This could be an additional service provided by the consumer protection system. In theory, if a financial institution ensures that all of its customers become members of the consumer protection system, it might not need to worry about complying with regulatory requirements to screen customers against a regulatory checklist. This service would incentivize financial institutions to cooperate with the consumer protection system. Smaller financial institutions could save on compliance costs by working with the consumer protection system.
[0422] In one aspect of the present invention, when a person attempts to open a membership account in a consumer protection system, the consumer protection system requires the person to provide their device interface number (e.g., mobile phone number). In one aspect of the present invention, the consumer protection system sends a password to the device interface (e.g., mobile phone) number via a message and requests the person to enter the password into an interface provided by the consumer protection system to open the account. If the person enters the correct password into the screen before the password expires, then the person does possess the device interface (e.g., mobile phone). If the person is unable to enter the correct password, then something is wrong and the consumer protection system denies the person's application to open an account. This provision ensures that one person cannot open an account for another person and cannot frame the other person as a fraudster.
[0423] In one aspect of the present invention, the consumer protection system purposefully sends a password to a different interface than the member uses to open a membership account. For example, if the member communicates with the consumer protection system via the internet, the consumer protection system sends the password to the member's mobile phone. If the member communicates with the consumer protection system via a mobile application, the consumer protection system sends the password to the member's email address.
[0424] In one aspect of the present invention, a consumer protection system compares a mobile phone number and a person's name with the customer records of the mobile phone network operator providing mobile phone service to the mobile phone owner. An anomaly may be detected when the name of a person applying for a membership account in the consumer protection system differs from the name of the customer who subscribed to the mobile phone service. The name of the mobile phone service subscriber can be obtained from the mobile phone network operator's records. Based on the anomaly, the consumer protection system may deny the person's application to open an account.
[0425] Checking a mobile phone operator's customer records can be time-consuming. In one aspect of the present invention, the consumer protection system first opens a member account and then checks the mobile phone operator's customer records. If an existing member's name and mobile phone number do not match the mobile phone operator's customer records, the consumer protection system can perform a background check on the member.
[0426] Typically, if suspicious activity is detected before a member account is opened, the consumer protection system may deny the member's application. If suspicious activity is detected after a member account is opened, the consumer protection system may conduct a background check on the member. In one aspect of the present invention, the consumer protection system does not provide any services to the member (e.g., freezes the account) until the background check is successfully completed and the member is proven innocent.
[0427] In one aspect of the present invention, the consumer protection system performs an account ownership check based on the method explained below. For example, if a member has registered four financial accounts, A, B, C, and D, with the consumer protection system, the system may transfer a first amount from account A and a second amount from account B, then transfer a third amount to account C and a fourth amount to account D. The consumer protection system then requires the member to provide the correct values for A, B, C, and D, which are randomly assigned by the consumer protection system. If the member is unable to provide the correct answers, the system performs a background check on the member.
[0428] Account ownership checks can be performed on any number of accounts and are not limited to four. Using both "Transfer Out" and "Transfer In" actions prevents members from feeling like the consumer protection system has taken money from them. However, either "Transfer Out" or "Transfer In" is sufficient to verify an account. For example, if a member needs to pay a membership fee, only "Transfer Out" is sufficient to verify the account.
[0429] Account ownership verification can be performed through other procedures. For example, if the member has only one registered financial account, the consumer protection system can transfer two amounts (e.g., X and Y) and require the member to provide the correct values for both amounts. After the member provides the correct answer, the consumer protection system can transfer the combined value (e.g., X + Y) back to the financial account, ensuring that the member does not lose any funds.
[0430] In one configuration, the consumer protection system randomly generates a code that is equivalent to a dollar amount that may contain a dollar value and a cent value. The consumer protection system sends the code to a transaction system that conducts a transaction with the member's registered financial account based on the value of the code.
[0431] In one aspect of the present invention, the consumer protection system prompts the member to enter a password through a member's device interface. If the password received from the member is the same as the password sent from the consumer protection system to the transaction system, the member can control the registered financial account. This process achieves the goal of account verification.
[0432] For verification purposes, the password can be any number. However, if the consumer protection system transfers a large amount of money from the member's registered financial account, the member may feel uncomfortable. Therefore, it may be a good idea to use a small number so that the member will not feel uncomfortable.
[0433] In one aspect of the present invention, the consumer protection system requires a new member to enter their current residence zip code. If the geographic location of the member's device interface (e.g., cell phone) is far from the member's current residence zip code, the consumer protection system may perform a background check on the member.
[0434] In one aspect of the present invention, the consumer protection system may continue to monitor the geographic location of the new member's device interface. The monitoring determines the amount of time the member's device interface has been away from the zip code. If the amount of time exceeds a threshold, the consumer protection system may perform a background check on the member.
[0435] In one aspect of the present invention, when a member conducts a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's name or a portion of the member's name based on an official identification card provided by the member. If the name or portion of the member's name is different from or does not correspond to the member's name or a portion of the member's name in the consumer protection system's records, the consumer protection system performs a background check on the member.
[0436] In one aspect of the present invention, when a member conducts a face-to-face transaction with a merchant, the consumer protection system prompts the merchant to enter the member's date of birth, or a portion of the member's date of birth, based on an official identification card provided by the member. If the date of birth, or a portion of the date of birth, differs from or does not correspond to the member's date of birth, or a portion of the date of birth, in the consumer protection system's records, the consumer protection system performs a background check on the member.
[0437] In one aspect of the present invention, if a member fails a background check, the consumer protection system can close the member's account. In one aspect of the present invention, if the background check reveals that the member is lying, the consumer protection system can close the member's account. In one aspect of the present invention, once the consumer protection system closes a member's account due to fraud (e.g., a failed background check), the consumer protection system adds the member to its internal blacklist.
[0438] In one aspect of the present invention, the consumer protection system records the timestamp of each financial instrument, financial account, financing tool, financial information, etc. registered by the member. In another aspect of the present invention, the consumer protection system verifies the accuracy and ownership of each financial instrument, financial account, financing tool, financial information, etc. registered by the member and only begins providing services for a specific financial instrument, financial account, financing tool, financial information, etc. after the verification is successful. Therefore, in the database of the consumer protection system, each financial instrument, financial account, financial information, etc. may have a "service start timestamp" that is different from or later than the "registration timestamp."
[0439] In one aspect of the present invention, if any of the registered financial instruments, financial accounts, financing instruments, financial information, or identity is incorrect, the consumer protection system may notify the member to make a correction. The consumer protection system monitors and records the number of corrections made by each member. In one aspect of the present invention, if the number of corrections exceeds a threshold, the consumer protection system may consider conducting a background check on the member.
[0440] In one aspect of the present invention, whenever a member registers a new financial instrument number, the consumer protection system scans the new financial instrument number against all financial instrument numbers of all members in the database. If a match is found, additional actions, such as a background check, may be performed. A financial instrument number may also refer to a financial account number, financing instrument, or other type of financial information. In one aspect of the present invention, the consumer protection system performs background checks on both the member registering the new financial instrument number and the member with a matching financial instrument number.
[0441] In one configuration, a financial institution sends a financial instrument number, a portion of transaction details, and a device interface address (e.g., a mobile phone number) to a consumer protection system for verification purposes. In response, the consumer protection system compares the device interface address provided by the financial institution with the device interface address provided by a member. The member is identified based on the financial instrument number. If the member has a different device interface address, additional actions may be taken. In one aspect of the present invention, if the member's device interface address differs from the device interface address provided by the financial institution, the consumer protection system performs a background check on the member.
[0442] In one aspect of the present invention, the above method of detecting inconsistent device interface addresses can also be used to detect inconsistencies in other types of information, such as name, birthday, etc. If an inconsistency is detected, the consumer protection system performs a background check on the member of the inconsistent information.
[0443] When the consumer protection system receives a "verification inquiry" from a financial institution, a merchant, or another organization regarding a transaction involving a particular financial instrument of a member, the inquiry result may indicate the accuracy of the financial instrument (or financial account, financing instrument, financial information, etc.). For example, if a member has frequently accepted transactions involving a financial instrument and no financial institution, merchant, or other organization has complained about the member's responses, this further confirms that the member is the true owner of the financial instrument.
[0444] In one aspect of the present invention, a consumer protection system records each member's query regarding a financial instrument, along with the query timestamp and query results. Each query result consists of two parts: a "yes" or "no" answer from the member, and a second part indicating whether the inquirer subsequently filed a complaint with the member.
[0445] In one aspect of the present invention, a consumer protection system records refunds and refund timestamps for each member's financial instruments, financial accounts, financing instruments, financial information, etc. Merchants provide refund information via a device interface provided by the consumer protection system. If a member's refund count exceeds a threshold, the consumer protection system may conduct a background check on the member.
[0446] In one aspect of the present invention, a consumer protection system determines whether a member is trustworthy based on historical inquiries, inquiry timestamps, inquiry results, refunds, and refund timestamps for all financial instruments belonging to the member. In another aspect of the present invention, the consumer protection system establishes a reputation score for each member. In another aspect of the present invention, the consumer protection system provides members' reputation scores as a service to financial institutions, merchants, or other organizations.
[0447] A fraudster may attempt to take over a member's account by changing a member's contact information, device interface address, etc. Therefore, security should be used to enable the member to prevent any changes to a member's contact information, device interface address, etc.
[0448] In one aspect of the present invention, the consumer protection system asks a challenge question when the member attempts to change their contact information. In another aspect of the present invention, a member designs a set of challenge questions when the member attempts to open a membership account. A challenge question should not have a "yes" or "no" answer. Therefore, it is a good idea to design a challenge question based on "who, where, what, when, how, etc."
[0449] In one aspect of the present invention, the consumer protection system uses a previous query history or a previous user action as a challenge question. For example, the question might be, "Which store required you to confirm a transaction through the consumer protection system around September 22nd?" Another example might be, "Which financial instrument did you register with the consumer protection system around January 16th?" If these types of challenge questions are used, the application running on the member's device interface (e.g., a mobile application) should only display a limited length of history (e.g., 7 days), making it impossible for a fraudster to find the answer to the challenge question from the application running on the device interface.
[0450] In one aspect of the present invention, the consumer protection system stores all historical records for a period of time, such as five years. For example, when a member replaces an old credit card number with a new one, the old credit card number and all related records (including the replacement date) are stored in a database. This record keeping can also be handled by the PATRIOT OFFICER system popular in the financial industry.
[0451] Although the consumer protection system does not process any financial transactions, its operations can be similar to those of a financial institution. Each member can be considered a customer. Each registered financial instrument, financial account, financing instrument, financial information, identification information, etc. can be considered an account under the customer's name. Each inquiry from a third party can be considered a type of transaction. Each inquiry result can be considered a type of transaction. Each refund can be considered a type of transaction. Each complaint from a third party regarding a member can be considered a type of transaction. Therefore, the smart alert system can also be used to generate alerts based on data in the consumer protection system's database. Thus, the smart alert system enables the consumer protection system to prevent fraud committed by members or potential members.
[0452] A person is typically identified by their name, date of birth, place of residence, and a unique government-issued identification number (such as a Social Security number, driver's license number, passport number, financial instrument number, telephone number, email address, etc.). However, partial identification information, such as a person's initials, is rarely sufficient for identification purposes. Similarly, other partial information (such as a Social Security number, the last four digits of a credit card number or driver's license number, street number, the last four digits of a postal code, the last digits of a birth month, etc.) is also insufficient for identification purposes.
[0453] However, in one aspect of the present invention, if several pieces of this partial identification information from the same object are combined together through a pre-agreed data manipulation procedure, they form a coded data set or an identity code that can be used for identification purposes even if no one understands the meaning of the identity code.
[0454] Similarly, in one aspect of the present invention, to provide greater security and privacy, an advanced encryption technology encrypts the identification information to form an identity code. If someone intentionally hides or destroys the decryption key, there may be no chance of recovering the identification information behind the identity code.
[0455] In yet another application of the present invention, we can combine the above encryption with the encoding of partial identification information to form an identity code. The chance of recovering the original identification information from this identity code is virtually zero. Although it is impossible to decode and / or decrypt an identity code to obtain the original identification information, two matching identity codes indicate that the original identification information of the two objects corresponding to these matching identity codes can match each other with a very high probability.
[0456] For example, the probability that two people have the same last five digits of their Social Security number and driver's license number is 1 in 10 to the 10th power, or 1 in 10 billion. The probability that these two people have the same last two digits of their birth year is 1 in 10 to the 12th power, or 1 in 1 trillion. Furthermore, if these two people also have the same ZIP code, the probability becomes 1 in 10 to the 17th power, which is likely to never happen in reality. By combining these pieces of information through a pre-defined data manipulation process, we can construct a coded data set that becomes an identity code.
[0457] For a person with an English name, we can, for example, include the first two letters of the first name and the first two letters of the last name as part of the ID code. Although these four letters do not provide enough information about the person's name, adding these four letters to the ID code can substantially reduce the chance of two people having the same ID code.
[0458] Often, a financial instrument is used to identify an individual. For example, when a financial institution requires a consumer to present two forms of ID, a credit card or debit card is often accepted as one form of ID. Therefore, a portion of a financial instrument's account number (such as the last four digits of a credit card number) can also be included in the ID code to reduce the chance of two people having the same ID code. For example, the last four digits of a credit card number, the postal code of the card's account address, and the cardholder's name can form an ID code that uniquely identifies the cardholder, even though multiple people may have the same name.
[0459] Conventionally, a single byte is used in the computer industry to represent an English letter or number. In one aspect of the present invention, an English letter or number is transformed into another byte with a different meaning. For example, the letter A can be transformed into the letter W. This transformation has the effect of hiding the original meaning. For example, the name "John" can be transformed into "Oh!a." Someone unaware of the transformation rules would have no idea what "Oh!a" means. The bytes generated by the transformation can be used to form an identity code that is unrelated to its original meaning before the transformation.
[0460] Some countries do not use English as their official language and may use multi-byte units to encode their languages (e.g., UTF-8, UTF-16, UTF-32, GB 18030, etc.). Modern POSIX documents define a "character" as a sequence of one or more bytes representing a single graphic symbol or control code. Therefore, regardless of the character encoding method used, languages used by different countries or cultures can be composed of both single-byte and multi-byte units. To avoid confusion, in this disclosure, a single-byte unit or a multi-byte unit is generally referred to as a character.
[0461] In one aspect of the present invention, a transformation converts each original multibyte unit into a new multibyte unit to conceal the original meaning. The new multibyte unit generated by the transformation can be used to form an identity code that conceals the original meaning.
[0462] In another application of the present invention, a transformation converts each byte in an original multi-byte unit into a new byte to conceal the original meaning. The new multi-byte unit generated by the transformation can be used to form an identity code that conceals the original meaning.
[0463] In yet another application of the present invention, an algorithm decomposes an original multibyte unit into a group of bytes, selects some bytes from the group, transforms them into a different group of bytes, rearranges their sequence, and then reassembles them to form a new multibyte unit. This new multibyte unit can be used to form an identity code that conceals the original meaning. Those who do not know the transformation rules have no idea what the original multibyte unit is.
[0464] The above methods for forming an identity code are merely examples. There are numerous ways to convert a set of bytes or multi-byte units (regardless of the language used) into an identity code. While it is theoretically possible to convert back to the identity code to recover some of the original bytes or multi-byte units, if only a small portion of the original bytes or multi-byte units is used for the conversion, the original information cannot be recovered.
[0465] Similarly, if we encrypt a sufficient amount of identification information to form an ID code, the chances of two people having the same ID code can be reduced to almost zero. For example, hashing (a type of encryption method) can be used to encrypt the identification data of two objects. If the identification information of two objects stored in two databases has the same hash result (e.g., hash), then they are likely the same object.
[0466] The above methods of using different types of transformation rules to form an identity code are just some examples. There are many possible transformation rules.
[0467] Generally, transformations can be categorized into three types: many-to-one, one-to-many, or one-to-one. The input to a transformation is a source. The output of a transformation is an image. A many-to-one transformation can transform multiple different sources into the same image. A one-to-many transformation can transform a single source into multiple different images. Many-to-one and one-to-many transformations can be confusing. Therefore, it is desirable to use a one-to-one transformation, which transforms a single source into a single image.
[0468] If we use a one-to-one transformation method to convert a sufficient amount of identification information for each object into a corresponding image dataset, then that image dataset can be used to identify the object, even if it does not contain any original identification information. Therefore, when two image datasets are identical, their corresponding source datasets are also identical. This means that the two matched image datasets are likely to belong to the same object.
[0469] In one aspect of the present invention, we use image data of an object to identify the object. The image data is generated by performing a one-to-one transformation on the identification data. The image data of the object is also called a token of the object's identification information, a token of the object, or an identity code.
[0470] When two parties discuss matters using the same ID code, they know they are discussing the same subject. No third party can understand the true identity behind the ID code, thus protecting the subject's privacy. An ID code can be used to identify any object, such as a person, an object, an organization, a legal entity, tangible property, intangible property, a document, a concept, a plan, a design, revenue, an asset, a liability, a trade secret, equity, funds, confidential information, a financial instrument, or a non-financial instrument, while maintaining privacy.
[0471] To achieve the goal of both parties using the same one-to-one conversion method, in one aspect of the present invention, a pre-agreed rule or set of pre-agreed rules is used to select, encode, configure, encrypt, convert and / or transform segments of identification data from an object to form an identity code that is inherently unique to that object and conceptually serves as a public proxy for that object's private identification data, a token of that object's private identification data, or a token of that object.
[0472] In one aspect of the present invention, an identity code is created based on a pre-agreed relatively simple transformation of the identification information, such as a direct concatenation of only a few specified individual numbers and letters selected from the original identification information.
[0473] In another aspect of the present invention, the identity code is created by performing a pre-defined, relatively complex transformation of one of the specified numbers, letters, and bytes of the original identification information. The transformation may include known methods of data conversion, transformation, encryption, and / or encoding of selected pieces of identification data, thereby further protecting the privacy of the original identification information from unauthorized access.
[0474] Furthermore, because only a small and relatively meaningless portion of the private information is used to generate the identity code, even if that portion is recovered by a malicious third party, the privacy of the remaining identification information will be protected and it will be impossible to steal the identity of the subject.
[0475] In one aspect of the present invention, multiple computer systems are connected via a network (e.g., the Internet). Each of these computer systems may reside at a single organization. In one aspect of the present invention, a central computer system is connected to the network to control the functions, mechanisms, and communications of the computer systems connected to the network.
[0476] In one aspect of the present invention, within each organization, a one-to-one conversion converts each customer's identification information into a unique ID code, which is a collection of image data. All customer ID codes are stored in a database within each organization. Relational information linking each ID code to its customer (e.g., account number, customer number, etc.) is also stored in the database.
[0477] In one aspect of the present invention, a computer interface is provided on each of the computer systems so that a person in an organization can select any client and send the client's identity code to the central computer system of the network. The organization that sends the identity code is called the initiator organization or the sender of the identity code.
[0478] In one aspect of the present invention, when a central computer system receives an identity code from a sponsoring organization, it sends the identity code to all other computer systems on the network. Each of the other computer systems on the network scans the received identity code generated by the sponsoring organization against all the identity codes stored in its database. These identity codes stored in the database are images or tokens of the identification information of the organization's customers.
[0479] In one aspect of the present invention, if there is a match between the received identity code and one of the identity codes stored in the database, the computer system of the organization with the match sends a message to the central computer system indicating that a match has been found among the organizations. The organization with the matched identity code is referred to as a matched organization or a payee with a matched identity code.
[0480] In one aspect of the present invention, a computer system having a matched identity code uses relationship information (eg, account number, etc.) to identify a corresponding customer whose identification information has been converted into a matched identity code.
[0481] In one aspect of the present invention, the computer system of the matched organization sends additional information associated with the customer with the matched identity code to the central computer system. The additional information may include background information and transaction information of the customer with the matched identity code.
[0482] In one aspect of the present invention, the central computer system sends the additional information received from the computer system of the matched organization to the computer system of the originator organization that sent the identity code.
[0483] In one aspect of the present invention, the sponsor organization's computer system uses relationship information (e.g., customer number, etc.) to identify the customer whose identification information has been converted into an identity code. This customer is referred to as the sponsor customer.
[0484] In one aspect of the present invention, the sponsor organization's computer system sends additional information associated with the sponsor's clients to the central computer system. The additional information may include background information and transaction information of the sponsor's clients.
[0485] In one aspect of the present invention, the central computer system sends additional information associated with the originator client to the computer system of the matched organization. In another aspect of the present invention, the central computer system sends contact information of a contact in the originator organization to a contact in the matched organization. In another aspect of the present invention, the central computer system sends contact information of a contact in the matched organization to a contact in the originator organization. Thus, users of computer systems on the network can communicate with each other and coordinate their workload on a common object represented by an identity code without disclosing any identifying information about the user's own object to other users.
[0486] In one aspect of the present invention, a sponsoring organization's computer system uses additional information about matched clients received from matched organizations, as well as the sponsoring organization's own information, to perform an analysis to generate new information about the sponsoring client. For example, the new information may relate to potential fraudulent activity, money laundering, or crime related to the sponsoring client. The new information may also relate to a positive activity, such as anonymous donations. As more information becomes available from more data sources, a better analysis can be performed to generate a better prediction, estimate, conclusion, etc.
[0487] Similarly, in one aspect of the present invention, the computer system of the matched organization uses the additional information about the sponsor client received from the sponsor organization and the matched organization's own information to perform an analysis to generate new information about the matched client. For example, the new information may be related to potential fraud, money laundering, crime, etc., related to the matched client.
[0488] In one aspect of the present invention, a computer system of an initiator organization sends an identity code and related information to be verified to a central computer system. In another aspect of the present invention, the central computer system sends the identity code and related information received from the initiator organization to all other computer systems on the network. In another aspect of the present invention, a computer system of a matched organization uses the matched identity code to identify the matched customer and then verifies the accuracy of the received related information. In another aspect of the present invention, the computer system of the matched organization sends a message indicating whether the information related to the identity code is accurate to the central computer system. In another aspect of the present invention, the central computer system sends a message indicating whether the information related to the identity code received from the matched initiator is accurate to the computer system of the initiator organization.
[0489] The above method has a broadcast effect. It can be used when the initiating organization does not know which other organizations may be able to verify the relevant information. Therefore, the central computer system sends the identity code to all other computer systems on the network.
[0490] Sometimes, the sponsoring organization knows which other organizations can check the relevant information. In such cases, in one aspect of the present invention, a sponsoring organization's computer system sends an identity code, a piece of relevant information to be checked, and identification information of a specific computer system on the network to the central computer system.
[0491] In one aspect of the present invention, a central computer system sends the identity code and the associated information received from the initiator organization to a specific computer system. In one aspect of the present invention, the specific computer system uses the matched identity code to identify the matched customer and then verifies the accuracy of the received associated information. In one aspect of the present invention, the specific computer system sends a message to the central computer system indicating whether the information associated with the identity code is accurate. In one aspect of the present invention, the central computer system sends a message received from the specific computer system indicating whether the information associated with the identity code is accurate to the computer system of the initiator organization. In one aspect of the present invention, instead of verifying whether the information associated with the identity code is correct, the initiator organization can request the matched organization to send specific information about the matched customer based on the identity code.
[0492] This application is extremely useful. For example, if a consumer applies for a new account with Organization ABC and claims to have an account with Bank XYZ, if both Organization ABC and Bank XYZ are on the network of the present invention, Organization ABC can quickly verify the accuracy of the information provided by the consumer, even though no identifying information is ever transmitted over the network. Only an identification code, which is indecipherable to any third party, is transmitted over the network. Consumer privacy is fully protected.
[0493] In one aspect of the present invention, to verify whether a consumer actually has an account with Bank XYZ, organization ABC may request the consumer to provide an account number, recent transaction amounts, recent transaction dates, other recent activity, background information, or any other information that may be stored by Bank XYZ. Alternatively, in one aspect of the present invention, to verify whether a consumer actually has an account with Bank XYZ, organization ABC may collect information from Bank XYZ using the consumer's ID code and then ask the consumer to answer questions based on this information. For example, the questions might be, "What was the last transaction amount in that account? What was the date of the last transaction?" If the consumer can answer all of these questions correctly, then the consumer likely has an account with Bank XYZ.
[0494] Because some consumers may not have good memories, in one aspect of the present invention, questions can be designed with multiple choices. For example, a question might ask a consumer to select one of five digits for the final transaction amount. In one aspect of the present invention, after a consumer has correctly answered a series of questions, organization ABC can feel confident opening an account or conducting a transaction for the consumer, or fulfilling a request from the consumer without worrying about identity theft.
[0495] In one aspect of the present invention, a computer system of a sponsoring organization sends an identity code and a set of requests to a central computer system. The set of requests may include a request for information, an action, or other types of requests. In one aspect of the present invention, the central computer system sends the identity code and the set of requests received from the sponsoring organization to all other computer systems on the network.
[0496] In one aspect of the present invention, a computer system of a matched organization uses a matched identity code to identify a customer whose identification information corresponds to the identity code. In response to information requests, the computer system of the matched organization collects the customer's information based on the set of requests. In response to action requests, the computer system of the matched organization instructs the device interface of the matched organization to take the requested action.
[0497] In one aspect of the present invention, the computer system of the matched organization sends the collected information to the central computer system based on the matched identity code. In one aspect of the present invention, the central computer system sends the collected information to the computing system of the initiator organization based on the matched identity code.
[0498] The above application can be used, for example, by law enforcement organizations. For example, if a law enforcement agency (e.g., the FBI) requests information about a criminal named John Doe, the agency can send John Doe's identification code to all organizations connected to the network to collect information about John Doe. These requests may include information such as address, phone number, email address, account balance, maximum remittance transaction amount, transaction date, remittance recipient, and remittance sender. The government agency can immediately collect all the information it needs about John Doe from all organizations connected to the network, even though John Doe's identifying information is never transmitted over the network. Only the identification code, which is unintelligible to any third party, is transmitted over the network. The information collected by the government agency about John Doe is confidential.
[0499] For example, if a law enforcement agency wishes to locate or arrest the criminal John Doe, the law enforcement agency may send John Doe's identification code to all organizations connected to the network and request them to freeze all of John Doe's accounts and stop all transactions with John Doe. All device interfaces instructed by the computer systems of the matched organizations to be controlled by such organizations freeze John Doe's account and stop John Doe's transactions, making it impossible for John Doe to survive in the modern computer-controlled world. It was only a matter of time before John Doe surrendered to law enforcement agencies. Because only any identification code incomprehensible to third parties has been transmitted over the Internet, the government agency's plan to find or arrest John Doe is confidential.
[0500] Notwithstanding the customer's use as an instance in the above interpretation, the application of the present invention may be applied to any tangible or intangible object, including a customer, employee, contractor, supplier, collectibles, intellectual property, trade secrets, and the like. Despite the use of background information and / or transactional information in the above explanations, any type of information may be used in the application of the present invention.
[0501] Application of the present invention A new private and confidential communication network for use in a computer system has been established. An ID code is used as a symbol to identify all objects that may reside in the database of a computer system connected to the network. The central computer system is the control and communication center for that network. When multiple computer systems have the same identity code, the communication can consist of a group of communications. When a pair of specific computer systems communicate with each other, that communication can also consist of one-point-to-point communication. Communication between a central computer system and a computer system on that network may be accomplished by electronic mail, a one-telephone call, file delivery protocol (FTP), network services, mobile applications, or any method of communication that can be used for computer communication purposes.
[0502] 1A illustrates an instance of an intelligent alarm system 500 (e.g., a device interface) and a computer network 600 (such as an LAN) according to the present invention. In one configuration, the intelligent alarm system 500 enables a BSA supervisor 100 , a law compliance supervisor 200 , an investigator 300 and other responsible persons 400 to follow different types of laws and regulations and send SAR cases directly to another computer system 700 at FinCEN.
[0503] Compliance Director 200 configures and / or adjusts parameters of computer system 500 via computer network 600. Computer system 500 uses an internal workflow function to send a potential case to investigator 300 via computer network 600. After investigation, investigator 300 sends the potential case and its investigation results to computer system 500 via computer network 600. Computer system 500 uses an internal workflow function to send the potential case and its investigation results to BSA Director 100 via computer network 600 for approval. After BSA Director 100 has approved the investigation results, if the potential case is a positive positive, computer system 500 receives the approval from BSA Director 100 via computer network 600. Computer system 500 then sends the positive positive positive to FinCEN's computer system 700.
[0504] In some financial institutions, the same person may have multiple job roles. For example, a single person could be a BSA supervisor, a compliance officer, and an investigator. In these cases, the Smart Alert system uses its internal workflow functionality to assign different tasks to the individual based on their role at different stages of the workflow.
[0505] As computer system 500 learns from investigator 300's experience, it becomes smarter and automatically accepts a potential case as a true positive if the conditional probability of the potential case becoming a true positive is higher than a predefined value. In these cases, computer system 500 sends the true positive directly to FinCEN's computer system 700 without any third-party human involvement. The more computer system 500 is used by investigator 300, the smarter it becomes. Over time, computer system 500 will handle most or all potential cases autonomously with minimal human involvement.
[0506] FIG1B illustrates an example of a computer system 1000 (e.g., a device interface) for consumer protection according to aspects of the present invention. In one configuration, computer system 1000 is connected to three smart alarm systems 1501...
Claims
1. A computer-based method for preventing financial crimes, comprising: The system transmits a second password from a third computer system to a second computer system; in response to the transmission of the second password, the third computer system receives a first password from a first computer system; the third computer system receives a first financial instrument number from the first computer system; the third computer system receives a second financial instrument number and a description of a transaction from a fourth computer system, wherein the fourth computer system includes a smart alarm system that generates a potential fraud alarm upon detecting the transaction; when the first password corresponds to the second password and the first financial instrument number matches the second financial instrument number, the description of the transaction is transmitted from the third computer system to the first computer system; in response to the transmission of the description of the transaction, the third computer system receives a message from the first computer system; When the message indicates acceptance of the transaction, an instruction is transmitted from the third computer system to the fourth computer system to reject the potential fraud alert as a false positive; and when the message indicates rejection of the transaction, an alert is transmitted from the third computer system to multiple subscriber computer systems associated with financial institutions, merchants and organizations, the alert indicating potential fraud associated with the first financial instrument number.
2. A computer system for preventing financial crimes, comprising: A memory device; The device includes at least one processor coupled to the memory device, the at least one processor configured to: transmit a second password to a second computer system; receive a first password from a first computer system in response to transmitting the second password; receive a first financial instrument number from the first computer system; receive a second financial instrument number and a description of a transaction from a fourth computer system, wherein the fourth computer system includes a smart alarm system that generates a potential fraud alarm in response to detecting the transaction; transmit the description of the transaction to the first computer system when the first password matches the second password and the first financial instrument number matches the second financial instrument number; receive a message from the first computer system in response to transmitting the description of the transaction; transmit an instruction to the fourth computer system to reject the potential fraud alarm as a false positive when the message indicates acceptance of the transaction; and transmit an alarm to a plurality of subscriber computer systems associated with financial institutions, merchants, and organizations when the message indicates rejection of the transaction, the alarm indicating potential fraud associated with the first financial instrument number.
Citation Information
Patent Citations
Electronic certificate receiving method and device
CN106355408A
An account registration and transaction security method and system
CN108985762A
A system and method for account transaction security
CN109087091A
Identity authentication method, device and system
TW201118641A
Anti-fraud POS transaction system
US20040138955A1