Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Lesson 6 of 7 · 15 min

Investigation Practice

An alert is a hypothesis, and the default drift of any queue is toward confirming it. The order of work, what each evidence type proves, and making reversal easy.

In this lesson

  • Run a case as a hypothesis test, including deliberately seeking disconfirming evidence
  • Assess what each internal evidence source proves, and where intent cannot be established
  • Write a case file that explains and justifies the decision to someone who was not there
  • Handle customer contact, outcomes and reversal without creating a larger problem

What an investigation is for

An alert is a hypothesis. An investigation tests it, and the discipline is in treating it as a test rather than as a confirmation exercise.

That framing has practical force, because the default drift of any fraud queue is toward confirmation. A case arrives labelled as fraud, the reviewer looks for evidence of fraud, finds something consistent with fraud, and closes it as fraud. The same evidence would frequently be consistent with a legitimate customer having an ordinary week, and nobody looked.

The counter-discipline is to state, at the start of each case, what would disconfirm the hypothesis. If nothing would, the case is not being investigated.

The order of work

A repeatable sequence produces consistent outcomes and survives review.

Read the alert and state the hypothesis explicitly. Which typology is this, and what would have to be true for it to be that?

Establish the account's own baseline before looking at the triggering event. What is normal for this customer? A deposit that is alarming for one account is Tuesday for another, and reviewers who skip this step judge everything against a population average.

Examine the triggering event in context. What preceded it, what followed it, what else changed.

Look for linkage. Shared device, network, instrument, address, contact details, behavioural pattern. Linkage is where weak individual signals become strong.

Check the other domains. Has this customer triggered responsible gambling markers? Is there a financial crime angle? A case that is only examined as fraud will be resolved as fraud.

Seek disconfirming evidence deliberately. What in this account's history is inconsistent with the hypothesis?

Reach a conclusion, with a confidence level. "Probable stolen instrument use, moderate confidence, based on X and Y" is a usable finding. "Fraud" is not.

Decide the action proportionate to the confidence, using the tiers from the previous lesson.

Record all of it.

Evidence, and its limits

Fraud investigation in an operator works almost entirely from internal data, and being clear about what each source proves prevents overreach.

Transaction records are strong and complete. They show what happened, to the cent, with timestamps.

Device and network data is strong for linkage and weak for identity. A shared device means two accounts used the same device. It does not mean one person operates both: households, shared computers, public machines and refurbished handsets all produce genuine sharing.

Behavioural data is good for pattern and poor for intent. It shows what was done, never why.

Identity verification records show what was checked and when, which is frequently the most important thing in the file.

Customer communications are the most underused source. What the customer said, when, and how they responded to a question carries real information, and it sits in a support system most fraud teams do not read.

External data such as bureau checks and consortium data adds independent corroboration where available.

The limit that matters: none of this establishes intent. An operator can establish that money moved in a pattern consistent with fraud. It cannot usually establish that a person intended to defraud it, and conclusions written as though it can are the ones that fall apart under challenge.

Writing the case

Assume every case file will be read by someone who was not there: a colleague, a complaints handler, an ADR body, a regulator, or a court.

A usable record contains: what triggered the case and when; the hypothesis tested; the evidence examined, including what was looked at and found to be unremarkable; the linkage established and its strength; the conclusion with a confidence level; the action taken and why that action rather than a stronger or weaker one; what the customer was told; and the review or reopening trigger.

Two failure modes recur.

The conclusion without the reasoning. "Account closed for fraud." Nobody can tell what happened, whether it was right, or whether the same decision would be made again.

The evidence without the conclusion. Pages of transaction data and no statement of what it means. Equally unusable, and slightly worse, because it looks thorough.

The test: if this customer complains in six months and the case is read by someone who has never seen the account, does the file explain and justify what was done?

Talking to the customer

Most investigations involve contacting the customer, and how it is done affects both the outcome and the operator's exposure.

Ask, do not accuse. An open question produces information; an accusation produces defence and ends the conversation. The reviewer's job at this stage is to gather evidence, and an accusation forecloses it.

Say what is happening, without saying more than you can support. "Your withdrawal is under review and we need to verify the payment method" is accurate and bounded. "We have identified fraudulent activity" is a conclusion the operator frequently cannot support and will have to retract.

Give a timeframe and keep to it. Most complaints about fraud reviews are about duration and silence rather than about the review itself.

Be able to explain what is needed and why. A verification request with no explanation reads as obstruction, particularly to a customer waiting on their own money.

Know when you cannot explain. Where a case has become a financial crime matter and a report has been made or is contemplated, tipping-off constraints apply and the customer cannot be told the reason. Staff need a prepared, accurate, minimal form of words for that situation, because improvising produces either a disclosure or an obvious evasion.

Outcomes

The full range, and the discipline is in not defaulting to the strongest.

No action. The hypothesis did not survive. This should be a substantial proportion of closures, and a function where it is near zero is not testing hypotheses.

Monitor. Insufficient evidence to act, sufficient to watch. Requires a defined trigger, or it means nothing.

Verify. A step-up check resolving the uncertainty.

Restrict specifically. Block a payout route, remove offer eligibility, cap stakes. Proportionate and reversible.

Restrict broadly. Suspend the account pending resolution.

Close and recover. The strongest commercial response.

Refer. To financial crime for reporting, to responsible gambling for intervention, or to law enforcement where the threshold is met. Referral is an outcome in its own right and is frequently the correct one alongside a commercial action rather than instead of it.

Reversal, and why it must be easy

A proportion of decisions will be wrong. The system's quality is measured partly by how well it handles that.

A defined route to challenge, communicated to the customer at the point of restriction.

Review by someone other than the original decision-maker. Self-review of a decision is not review.

Full restoration when a decision is reversed, including funds, account status and offer eligibility. A customer reinstated but quietly excluded from promotions has not been reinstated.

Feedback into tuning. Every reversal identifies a rule, a threshold or a review practice that produced it. A function that reverses decisions without recording why is repeating the error by design.

An accurate record. Where the original case said fraud and the review said otherwise, the file has to say so plainly, because the earlier characterisation will otherwise follow the customer through every future interaction.

Measuring the function

Case volume and closure rate describe activity. Four measures describe effect.

Precision by alert source, which tells you which rules are worth keeping.

Reversal rate, and the pattern within it.

Prevented loss and realised loss, the pair that shows what the function is delivering.

False positive cost, estimated from reversals, complaints and abandoned customers, because the alternative to estimating it is implicitly valuing it at zero.

The fourth is the one that changes decisions, and it is the one almost nobody produces. An operator that has measured it usually finds at least one blunt control costing more than the fraud it prevents, which is exactly the finding the first lesson of this course said was available to anyone willing to look.

Key terms

Disconfirming evidence
Evidence inconsistent with the hypothesis, sought deliberately. The counter-discipline to a queue that drifts toward confirmation.
Account baseline
What is normal for this specific customer. A deposit alarming for one account is unremarkable for another, and skipping this step judges everything against an average.
Confidence level
A stated strength attached to a finding. "Probable stolen instrument use, moderate confidence, based on X and Y" is usable; "fraud" is not.
Independent review
Reassessment of a restriction by someone other than the original decision-maker. Self-review of a decision is not review.
Full restoration
Reversing a decision completely: funds, account status and offer eligibility. A customer reinstated but quietly excluded from promotions has not been reinstated.

Key takeaways

  • State at the start of each case what would disconfirm the hypothesis. If nothing would, the case is not being investigated.
  • Establish the account’s own baseline before examining the triggering event, or everything is judged against a population average.
  • Device sharing establishes that a device was shared. It does not establish that one person operates both accounts.
  • An operator can show money moved in a pattern consistent with fraud; it usually cannot establish intent, and conclusions written as though it can fall apart under challenge.
  • A "no action" closure should be a substantial proportion of outcomes. A function where it is near zero is not testing hypotheses.

Check your understanding

3 questions · answer them all, then check.

  1. 1. What single discipline most protects an investigation from confirmation drift?

  2. 2. A case is escalated to financial crime and a report is contemplated. What can the customer be told?

  3. 3. A restriction is reversed on review. Beyond restoring the account, what must happen?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Investigation Practice - Learning hub | iGaming Times