Financial Services & Insurance6 months

Scenario: AI Triage for Fraud Alerts in a Credit Union

agents/workflow-automationanalytics/predictive

This is a typical scenario. It shows how Remolda would approach AI triage of fraud alerts in a Canadian credit union, what we would build and what we would measure.

The situation

Picture a regional credit union in Ontario with a small fraud and compliance team. A rules-based system flags unusual transactions: a large transfer, an out-of-province purchase, activity at an odd hour. Every flag goes to an investigator.

Most flags turn out to be ordinary member activity. Each one still needs a person to pull the transaction history, sometimes call the member, record the outcome and close the case. The queue grows faster than the team can clear it. Genuine fraud cases wait behind routine ones.

The rules were written to miss nothing. That choice is sound. The cost is a queue full of legitimate transactions.

The approach

Audit (3 weeks). We review the detection rules, the transaction data, the case management workflow and the reporting duties, and interview the investigators, the compliance manager and the chief risk officer. The goal is to measure, on the credit union's own history, how often each rule leads to confirmed fraud and how long each type of case takes to clear. Those two numbers become the baseline.

Strategy (4 weeks). The design keeps the rules-based system and adds a triage layer after it. For each flagged transaction the layer assesses member history, transaction context and known fraud patterns, then routes the case one of three ways:

  1. Clear with a documented reason. Only below a conservative threshold, set from historical cases with known outcomes.
  2. Priority review. Routed to an investigator with an AI-written case summary and the evidence behind it.
  3. Standard review. Queued with a context summary so the investigator starts from the facts.

The risk committee and the chief compliance officer approve the design, the threshold and the oversight plan before any build starts.

Implement (3 months). Month one builds and tests the scoring model on the credit union's own transaction data. Months two and three connect the triage layer to the existing case management system, so investigators keep the screens they know. The investigator makes the final decision on every case that reaches them.

For the first 60 days a senior investigator reviews a random sample of auto-cleared cases every week. Sampling moves to monthly only after the weekly results hold.

Empower (parallel). Training covers three things: reading AI case summaries critically, flagging assessments that look wrong through a feedback button, and producing the documentation that shows examiners how the framework works.

What we would measure

Each item below is a target we would set with the credit union and measure against the baseline from the audit. The size of each target is set only after the baseline is measured.

  • Share of flags that turn out legitimate. Tracked weekly, split into auto-cleared and reviewed cases.
  • Time to close a case. From flag to decision, by case type.
  • Missed fraud. Confirmed fraud found among auto-cleared cases in the sampling program. The acceptable level is agreed with the risk committee before go-live, and the threshold is tightened if it is exceeded.
  • Investigator time on genuine cases. Hours per week spent on cases that lead to action.
  • Documentation completeness. Every auto-clear has a recorded reason, every sample has a recorded result.

Rules that frame this scenario

Credit unions in Ontario are regulated provincially, and all credit unions are reporting entities under FINTRAC rules. A triage layer supports the compliance officer; reporting decisions stay with people. Federally regulated institutions would also design to OSFI Guideline E-23 on model risk, which takes effect on May 1, 2027. Where a decision about a member in Quebec is made exclusively by automated processing, Quebec's Law 25 requires notice to the person. The finance sector page lists the sources.

Key lessons

1. Precision and recall both matter. Catching every fraud case is the right instinct. A triage layer is worth building only if it improves precision without lowering recall, and the sampling program is how you check.

2. Documentation is part of the product. Examiners look for a systematic, documented and proportionate framework. The triage layer records its reason for every decision, which gives the compliance team evidence it can show.

3. People keep the decision. A fully automated fraud decision adds regulatory and liability risk. AI triage with a human decision combines the speed of the model with the accountability of the investigator.

For related work, see AI for banks and credit unions and AI workflow automation.

Frequently asked questions

Key questions about this scenario: the situation, the approach and what we would measure.

What situation does this scenario describe?
A regional credit union whose rules-based fraud system flags many transactions that turn out to be ordinary member activity. Each flag needs an investigator, so genuine fraud cases wait behind routine ones.
What would Remolda build?
A triage layer after the existing rules: each flagged transaction is cleared with a documented reason below a conservative threshold, or sent to an investigator with an AI-written case summary. Investigators decide every case that reaches them, and auto-cleared cases are sampled weekly for the first 60 days.
How would results be measured?
We would set targets with the credit union for legitimate-flag share, time to close a case, missed fraud in sampling and investigator time on genuine cases, and measure them against the baseline from the audit.

Talk to an AI transformation consultant

A 30-minute call: you describe the situation, we tell you what to do first and what it would cost.

Book a 30-min call

30 minutes. English or French.