Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Lesson 7 of 7 · 15 min

Building the Function

Where fraud reports determines what it optimises for. The four-function routing problem, building the signal layer before the rules, and reporting both sides of your own effect.

In this lesson

  • Choose a reporting line deliberately and apply the correction its bias requires
  • Design routing between fraud, financial crime, responsible gambling and payments
  • Sequence the build: identity resolution first, then signals, then rules, then models
  • Report the loss side and the cost side together, and run the annual blunt-control exercise

Where fraud sits, and why it matters

Fraud is one of four functions looking at the same customer data with different objectives, and where it reports determines what it optimises for.

Under finance or payments, it optimises for loss reduction and chargeback ratio. Fast to justify, and it will tighten indefinitely because loss is the only number it owns.

Under risk or compliance, it optimises for control and evidence. Better routing into financial crime, and it can become slow and conservative in a way that costs revenue nobody attributes to it.

Under operations or commercial, it optimises for customer experience and conversion. Better at the friction side, and structurally reluctant to restrict valuable customers, which is exactly where the largest cases are.

None of these is right and the choice is less important than the correction applied to it. A fraud function reporting into finance needs a customer-experience measure it is accountable for. One reporting into compliance needs a conversion measure. One reporting into commercial needs an independent escalation route that does not pass through the person whose revenue a restriction affects.

The structural minimum, wherever it sits: the decision to restrict a high-value customer must not require the approval of the person whose target it damages.

The four-function problem

Fraud, financial crime, responsible gambling and payments all read the same signals and have different obligations. Deposit velocity, failed deposits, reverse withdrawals, multiple instruments and unusual withdrawal patterns appear in all four playbooks.

Three arrangements exist and they are not equally good.

Separate teams, separate systems, no routing. The common default, and it produces systematic under-referral in every direction. Each team resolves ambiguous cases within its own frame because that is the only frame it can see.

Separate teams, shared triage. A first-line step with visibility of all four domains routes the case, and specialists handle it. This works and is the arrangement most mature operators converge on.

Single combined team. Efficient at small scale and it degrades: financial crime and responsible gambling carry obligations with personal and regulatory exposure that a generalist queue handles badly.

Whatever the arrangement, three things need to be explicit. A case can belong to more than one domain simultaneously and the handling must not collapse it to one. Tipping-off constraints bind the whole chain, so a responsible gambling interaction with a customer under financial crime suspicion needs a protocol. And the responsible gambling route must never be subordinated to commercial recovery: a self-excluded customer who multi-accounted is a compliance failure first and a terms breach second.

Building the signal layer before the rules

The common sequencing error is buying a decision engine before having signals worth deciding on.

The order that works: identity resolution first, then device and network signals, then the behavioural layer, then rules, then models.

Identity resolution comes first because every other control is computed per account, and if one person holds several accounts each control sees a fragment. This is a data engineering problem entirely within the operator's own estate, it improves fraud, financial crime, responsible gambling and marketing suppression simultaneously, and it is unresolved at more operators than anyone would like to admit.

An operator with excellent identity resolution and simple rules will outperform one with a sophisticated model on fragmented data, and it will do so at a fraction of the cost.

Vendors, and what to ask them

Most operators buy rather than build, and the buying decisions are made on demonstrations rather than on the questions that matter.

What was the model trained on, and what bias does that import? If the answer is unclear, the vendor either does not know or does not want to say.

Can decisions be explained to a customer and to a regulator? Unexplainable decisions in a regulated context are a liability whatever their accuracy.

What is the measured precision on a book like ours? Aggregate accuracy across all clients is not an answer.

Does the data leave our control, and where does it go? A data protection question before it is a fraud one.

Can we tune it ourselves, or is every threshold change a support ticket? This determines whether the system adapts at your speed or the vendor's.

What happens at contract end? Models, rules and case history built inside a vendor platform frequently cannot be exported, which turns a tooling decision into a long-term dependency.

Consortium data deserves its own assessment. Shared industry data on known fraud is genuinely valuable, particularly for organised activity spanning operators. It also raises real data protection questions about the lawful basis for sharing, the accuracy of shared markers, and the customer's ability to challenge an entry made by someone else. An operator relying on a consortium marker to restrict a customer should be able to say where the marker came from and how the customer could contest it.

Staffing and the human layer

Sizing follows from alert volume and the review depth intended. Deciding the depth first and staffing to it is the honest sequence; the common alternative is staffing to budget and then quietly reducing depth until the queue clears, which produces exactly the superficial closures that are worse than no system.

Skills are investigative rather than procedural. The core competence is testing a hypothesis, and it is trainable.

Shift coverage matters because fraud is not confined to business hours, and payout review queues that only move during the day produce the withdrawal delays that generate most complaints.

Attrition is a real operational risk. Fraud analysts accumulate pattern knowledge that is not written down, and losing an experienced reviewer removes detection capability that no document captures. Documenting typologies as they are found is the mitigation, and it is always the thing that gets deferred.

Reporting that supports a decision

Most fraud reporting describes activity. Useful reporting shows the two-sided trade.

On the loss side: realised loss by type, prevented loss with the estimation method stated, chargeback ratio against scheme thresholds with friendly fraud broken out, and recovery achieved.

On the cost side: false positive rate and reversal rate, declined legitimate deposits and their estimated value, complaint volume arising from fraud actions, and customers lost following a restriction.

On the system side: precision by alert source, alert volume against review capacity, closure quality from independent sampling, and below-the-line testing results.

On the routing side: referrals made to financial crime and to responsible gambling, because a fraud function that never refers is resolving everything within its own frame.

A board seeing only the loss side will ask for tighter controls every quarter and will get them. A board seeing both sides can make the trade deliberately, which is the entire purpose of producing the second half.

The exercise worth doing once a year

Take the three bluntest controls in the stack, the ones applied uniformly rather than by segment. For each, compute the fraud prevented and estimate the legitimate customers stopped and their value.

The estimate is achievable: sample the declines, manually review a subset to establish what proportion were legitimate, apply the average customer value, and extrapolate. It is not precise and it does not need to be. The question is whether the number is larger or smaller than the prevented loss, and that is usually clear well inside the error bars.

Operators that run this exercise frequently find at least one control costing more than it saves, and almost always find that segmentation delivers equivalent protection at a fraction of the cost to legitimate customers.

The reason this is worth restating at the end of the course is that it is the finding the reporting is structured to hide. Prevented fraud is counted, attributed and celebrated. Declined customers are a number nobody owns. A function that closes that gap is doing something almost none of its peers are, and it is doing it with data it already holds.

Key terms

Shared triage
A first-line step with visibility of fraud, financial crime, responsible gambling and payments, routing cases to specialists. The arrangement most mature operators converge on.
Signal layer
Identity resolution, device and network data and behavioural signals, beneath rules and models. Buying a decision engine before building it is the common sequencing error.
Consortium data
Shared industry fraud markers. Genuinely valuable against organised activity, and raising real questions about lawful basis, marker accuracy and the customer’s ability to contest an entry.
Closure quality
The proportion of closed alerts an independent reviewer would have escalated. Measures whether reviews were real, which closure rate cannot.
Blunt control
A control applied uniformly rather than by segment. The category where the annual cost exercise most often finds a control costing more than it saves.

Key takeaways

  • Wherever fraud sits, the structural minimum is that restricting a high-value customer must not require approval from the person whose target it damages.
  • Identity resolution comes first because every other control is computed per account, and fragments defeat all of them at once.
  • An operator with excellent identity resolution and simple rules will outperform one with a sophisticated model on fragmented data, at a fraction of the cost.
  • Ask a vendor what the model was trained on, whether decisions are explainable, and what happens to your rules and case history at contract end.
  • A fraud function that never refers to financial crime or responsible gambling is resolving everything within its own frame.

Check your understanding

3 questions · answer them all, then check.

  1. 1. A fraud function reports into finance. What correction does that bias require?

  2. 2. What should be built first when standing up a fraud capability?

  3. 3. What does the annual blunt-control exercise typically reveal?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Building the Function - Learning hub | iGaming Times