ML Collusion Detection via SOD Rules and Network Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current fraud detection systems struggle to identify collusion between trusted employees or vendors, as these behaviors often go undetected due to proper segregation of duties and the complexity of multidimensional information patterns, leading to significant financial losses when collusion is discovered.

Innovation Solution

A machine learning model is trained to recognize patterns indicative of collusive behavior between two or more individuals within an organization, collecting and analyzing data from various platforms to detect anomalies and rank potential collusive activities by risk level, presenting these findings to users for further scrutiny.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional separation of duties (SOD) analysis is used to detect fraud, then individual fraudulent activities can be detected, but collusive fraud between multiple individuals remains undetected

Engineering Contradiction:
Improvefraud detection accuracyVSAvoiddetection coverage against collusion
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple data sources and analysis methods including SOD rules, network analysis, natural language processing, and machine learning into a unified fraud detection system. This merging enables the system to detect both individual fraud and collusive fraud by analyzing relationships and patterns across diverse data types that would be invisible to traditional single-method approaches

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds relational and contextual dimensions to traditional transactional analysis by incorporating network graphs that map relationships between individuals, entities, and transactions. This dimensional expansion allows detection of collusive patterns where multiple actors coordinate their actions across different systems, making the fraud detection capable of identifying coordinated behavior that spans traditional analytical boundaries

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If manual investigation of suspicious activities is performed, then detailed analysis can be conducted, but the process is time-consuming and cannot scale to large datasets

Engineering Contradiction:
Improveinvestigation depthVSAvoiddetection throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary automated analysis of all data including transaction monitoring, network relationship mapping, and anomaly detection before human investigation. This preliminary action identifies and prioritizes suspicious patterns, allowing investigators to focus on pre-validated leads rather than manually reviewing all transactions, thus maintaining investigation depth while scaling throughput

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where machine learning models are continuously trained on investigation outcomes and confirmed fraud cases. This feedback mechanism improves the accuracy of automated detection over time, reducing false positives that require manual review and increasing the proportion of cases that can be detected automatically while maintaining high precision

Inventive Principle:
Principle #23Feedback

3Loss of information

If forensic investigation is conducted after fraud occurrence, then evidence can be gathered, but the damage is already done and recovery is difficult

Engineering Contradiction:
Improveevidence availabilityVSAvoidfinancial loss
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The system performs continuous monitoring and anomaly detection before fraud can cause significant damage. By identifying suspicious patterns in real-time and alerting investigators proactively, the system enables intervention at early stages when losses are minimal and evidence is still available in digital form, preventing the need for damaging forensic investigations after facts are obscured

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system acts as an intermediary between automated detection and human investigation by providing structured anomaly reports, network visualizations, and prioritized lead lists. This intermediary function bridges the gap between raw data and investigator action, enabling rapid response to emerging fraud patterns before they mature into significant losses that would require costly forensic recovery

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240095637A1Collusion detection using machine learning and separation of duties (SOD) rules
Publication Date: 2024.03.21 SAILPOINT TECHNOLOGIES INC
  • US20240095637A1 patent drawing
  • US20240095637A1 patent drawing

AI summary

Systems and methods are disclosed relating to mechanisms for performing scoped investigations into potential collusion fraud where different sides of an SoD risk are found in different people, and to identify likely cases of such collusion, or at least potentially suspicious behavior that should be carefully audited. Systems and method can utilize ML/AI engines and scoring of data (activities) across various platforms to review not only a person's actions, but the actions of people with which they have relationships. In some embodiments, systems standardize data across multiple platforms and analyze data in light of other data from other users to find patterns associated two or more individuals involved in different parts of an SOD risk.