Risk & Fraud

Signals, relationships and decisions in one loop.

Fraud is rarely a single record. It is a pattern across parties, devices, timing and history, which means the relationship data is the analysis.

A fraud pattern caught as a network, decided under a deadline, kept as evidence.

The story

A fraud pattern caught as a network, decided under a deadline, kept as evidence.

Where it starts

Detection signals

Velocity, device, channel and behavioural measurements. It is the first of 4 workloads running in Risk & Fraud.

The question it raises

Linked-entity review

A case is opened on a network of related entities rather than one account, because the relationships are stored as data.

Why one question is hard

From Ingest to Learn

Risk & Fraud data moves through 5 stages — Ingest → Link → Score → Review → Learn. The shapes in play are Graph, Time series, SQL, JSON / documents, and answering one question means reading across all of them.

What PLOMID contributes

Detection is a relationship problem with a deadline. These are the parts that decide how fast it can be answered.

The environment

Signals, relationships, cases and decisions across an institution’s data.

Detection reads transactions, behavioural measurements and relationship structure, then writes cases and decisions. Those pieces usually live in four systems and are joined by exports. PLOMID holds the signals, the relationships and the case record in one layer, so a decision and its evidence are one artefact.

Where the data goes to work

Questions money asks repeatedly.

Each one reads records, and where it must, the relationships between them — from the same layer, not an extract.

Linked-entity review

A case is opened on a network of related entities rather than one account, because the relationships are stored as data.

  • SQL
  • Time series

Signal and history together

Behavioural measurements are read against the account’s full history in one request.

  • Graph

Evidence attached to the decision

Notes, attachments and the underlying records stay queryable beside the case.

  • Graph
  • Time series

Outcome feedback

Dispositions are records in the same layer that produced the alert, so the loop is closed without an export.

  • JSON / documents
The data journey

How risk & fraud data reaches one layer.

Walk the path the data takes, from the environment that produces it to the questions it answers. Select a station, or a shape, to read each step.

A fraud pattern caught as a network, decided under a deadline, kept as evidence.

Environment

The transaction stream

Payments and postings arriving continuously with their behavioural measurements.

SQL · Time series

Data models in play

The shapes, in one layer.

4 shapes carry this domain. Choose a stage to read the operation, or a shape to see every stage that handles it.

PLOMID · Risk & Fraud ingest · link · score · review · learn Select a stage
Stage

Ingest

Transactional records and behavioural measurements

SQL · Time series

Workload map Risk & Fraud workload map. Every shape on it is a surface of the layer, and each stage names the part of the operation it carries.
  • Graph Relationships and traversal
  • Time series Measurements and events in time order
  • SQL Records, keys and joins
  • JSON / documents Documents and nested objects
One environment · many workloads

What runs against risk & fraud data.

4 workload families over one set of shapes. Choose one to see what it moves and where it lands.

Velocity, device, channel and behavioural measurements.

  • Planned once against the layer, not once per store
  • Read beside the records it shares a key with
  • Persisted under one storage contract
Workload architecture

From posting to traversal.

Records first, relationships where the question needs them — every path a request can take through this data.

Risk & Fraud · workload architecture
Workloads

What runs against this data.

  • Detection signals
  • Entities and relationships
  • Cases and evidence
  • Outcome history
Data models

The shapes those workloads read and write.

  • Graph
  • Time series
  • SQL
  • JSON / documents
The layer

One path from a request to the data it names.

  • Planning Predicates narrow the work before it runs
  • Execution Records, fields and windows answered together
  • Transactions Readers and writers do not block each other
Surfaces

How the work reaches the layer.

  • SQL surface The query language the layer is documented in
  • Applications Services and jobs writing and reading as they run
  • Analytics & AI clients The same layer, the same access path
Deployment & residency

Where this data is allowed to run.

Detection runs where the data is, which makes placement and latency part of the question rather than an afterthought.

Deployment, residency and control
What you build next

Risk & Fraud

Decisions made across transactions, entities and their relationships.

If Linked-entity review is your question, start here.