The Build

Every Alert Has to Show Its Work

AE Fraud Division screens names against the live U.S. sanctions lists, watches a transaction file for the classic patterns, and turns what it finds into an evidence-cited case packet. Here is what it does — and the part that matters more, what it doesn't.

Two days ago I said a fraud tool for banks was coming and that it had earned its own post. Here it is. AE Fraud Division is open — three rooms, one job.

SCREEN checks names against the U.S. Treasury's OFAC sanctions lists — the Specially Designated Nationals list and the Consolidated list, refreshed daily, aliases included. The matching handles reversed name order, punctuation, and listed aliases, and a lone shared surname does not become an alert. You can run one name or drop in a batch.

WATCH takes a transaction file — a CSV, or a NACHA/ACH file read straight from the entry-detail records — and runs the classic typologies over it: structuring under the ten-thousand-dollar line, velocity spikes, round-dollar repeats, duplicate payments, dormant accounts waking up, sudden new-payee activity.

FILE is the case room. Promote any alert to a case and it carries its evidence chain plus a draft narrative laid out the way a SAR narrative is actually written — who, what, when, how much, and why it is suspicious. You edit it and export the packet.

No citation, no alert. If the tool can't show you the exact rows behind a finding, it doesn't get to raise one.

The rule the whole thing is built on

Every alert cites its evidence. A sanctions hit shows you the exact list entry and links you to Treasury's own search so you can verify it yourself, against the source, without taking my word for anything. A transaction alert shows you the specific rows that triggered it. If it can't cite, it doesn't fire.

That rule exists because of what the alternative does to people. An analyst handed a score with no reasoning has two bad options: trust a black box, or redo the work by hand. Both of those are worse than no tool. The score is not the product. The reasoning is the product.

The file never leaves your machine

WATCH runs in your browser. Your transaction file is not uploaded, not transmitted, not stored — it is read on the computer in front of you and the findings appear on the same screen. Cases live on that screen too, and go away when you leave.

The one exception is stated plainly in the tool: names you explicitly send to the sanctions screen get checked against the live lists, because that is the entire job. Everything else stays where it started.

What it will not do

This is the section most software companies bury, so I'm putting it in the middle of the page instead.

  • A clear is not a background check and it is not a legal determination.
  • A hit is a lead for a human being to look at. It is not an accusation, and it is not a decision.
  • WATCH catches known patterns. It does not learn your customers' individual behavior — not yet — and it cannot find what isn't in the file you gave it.
  • Case narratives are drafts. Your BSA officer reviews, decides, and files. The tool never files anything, and it never will.

Every one of those sentences is also printed inside the product, not just here. A compliance tool that oversells itself doesn't just embarrass the vendor — it puts an institution in front of a regulator holding a claim it can't support. I would rather be the tool that told you where its edges were.

Why a small shop gets to build this at all

Fair question, and the answer isn't clever software. Twenty-one years of my working life have been operations and media — building targeting models, running market studies for national media groups, managing national accounts, running operations in senior living. Regulated work with real files, real audits, and real consequences for getting a record wrong.

Which means for two decades I have been on the buying end of software like this. I have sat through the demos where the detection rate is a number nobody will explain. I have watched a team pay for a platform, spend a year integrating it, and still keep the spreadsheet that actually ran the work. That experience is the specification. Cite everything. Store nothing. Don't make them integrate for a year before they learn whether it helps.

No integration project, no per-seat bill

Same as everything else here: you open it and use it. There is no implementation phase, no discovery call, no procurement cycle that outlives the problem you bought it for. You can point it at a file this afternoon and know by dinner whether it earns a place in your week.

It's the first thing we've built for an industry this heavily regulated, and it is deliberately narrow. More lists and behavioral work are on the roadmap. What's there now, works now, and shows you why.