Use cases · Bank
Banking fraud — across account opening, deposits, cards, and payments.
Banking fraud isn't one problem — it's a portfolio of them, each with its own data shape and decisioning latency. Merchant fraud reads nothing like deposit fraud. Synthetic identity reads nothing like first-party bust-out. We've built ML and rule-based detection across all of them — inside the infrastructure of a leading US bank.
Why banking is different
Money out, money in — two flows, two fraud taxonomies.
Banks give money out (loans, lines, deposits-paid-out) and take money in (deposits, payments, repayment). Each flow attracts different fraud. The defense has to be designed for the flow — generic fraud platforms get it wrong in both directions.
Money out
Where the bank pays first and recovers later.
Identity theft, ATO, synthetic identity, application fraud, mule-account opening, first-party bust-out, push-payment scams. The defense is identity coherence at opening and behavior-aware decisioning at every outbound movement.
Money in
Where the customer pays and the asset is at risk.
Deposit fraud, fake-check schemes, kiting, RDC duplicate deposit, merchant-side fraud, dispute and chargeback abuse, AML / consortium signal. The defense is real-time scoring at deposit and at acquirer authorization — not next-day case review.
By customer journey
Five lifecycle stages. Every banking decision lives in one of them.
From prospect to AML referral — Centurion plugs in at every stage where a banking risk decision gets made. Find your stage. Find your use case.
01
Attract
Prospecting & prescreen
- Lead-scoring & prescreen (prime / sub-prime)
- Marketing-channel risk weighting
- Pre-application identity-coherence checks
02
Acquire
Account opening & application
- Deposit-account opening fraud
- Credit / loan application fraud
- Synthetic-identity detection
- Mule-account onboarding signal
- KYC / CIP, document & ID-document fraud
- First-party fraud / bust-out propensity
03
Engage
Login & money movement
- Login & session-trust (ATO, bots, credential stuffing)
- Card-not-present & e-commerce authorization
- PIN POS / ATM transaction fraud
- Wire / ACH / P2P (Zelle) fraud scoring
- Deposit (RDC / mobile check) fraud — kiting, fake-check, duplicate deposit
- Merchant authorization & acquirer-side fraud
04
Grow
Account management
- Account-change risk (address, phone, beneficiary, signers)
- Behavioral / account-management scoring
- Credit-line management (CLI / CLD)
- Cross-sell eligibility & risk-aware pricing
- Merchant-portfolio monitoring
- Consortium / AML signal feed
05
Resolve
Disputes & AML
- Dispute / chargeback classification (genuine / friendly / abuse)
- Recovery & charge-off routing
- AML alert triage & SAR-referral prioritization
- Fraud-loss attribution & restitution tracking
The fraud surfaces
Eight surfaces every bank has to defend.
Each surface has its own signal, latency, and decisioning bar. Centurion treats them as first-class — one fabric, distinct strategies, common audit log.
Synthetic identity at account opening
Fabricated identities assembled from real and stolen attributes. Graph + behavioral signal at signup catches the constructed identity before the account funds, the line opens, or the application bonus pays out.
Mule onboarding & money laundering
Money-mule accounts opened for layering and integration. Identifier-overlap density, device-network coherence, and post-funding transaction-pattern signal surface mule rings — at signup and at the first outbound wire.
Deposit fraud — fake check, kiting, RDC
Mobile / remote-deposit-capture fraud, fake-check schemes, deposit kiting, duplicate deposit. Real-time scoring at deposit, with holds calibrated to fraud risk and not blanket policy.
Card-not-present & PIN POS / ATM
CNP fraud at e-commerce checkout, BIN-attack patterns, PIN POS skimming, ATM cash-out networks. Network-level signal aggregates merchant and acquirer pattern across millions of transactions.
Account takeover (ATO)
Credential stuffing, session hijack, SIM-swap-driven takeover, voice-channel ATO. Session-trust scoring at login + account-change risk + transaction-anomaly composition.
Wire / ACH / P2P fraud
Push-payment fraud (Zelle, RTP), authorized-push-payment scams, business-email-compromise wires, ACH return-abuse rings. Beneficiary-graph scoring + behavioral-context at initiation.
First-party fraud & bust-out
Customers with intent to default — accumulating credit across products, then walking away. Behavioral pattern at lifecycle markers (paydown velocity, utilization climb, mule-money inflow) surfaces the intent.
Merchant & application fraud
Acquirer-side merchant fraud — laundering through legitimate merchants, bust-out merchants, MOTO collusion. Application fraud across credit-card, loan, deposit products with rule + model composition.
What plugs in
Three components, tuned to the banking data shape.
Deployment boundaries are agreed before implementation. HD Trust is Hudson-managed SaaS today; customer data flows, residency, access controls, and any Centurion workloads in bank-controlled infrastructure are documented in the engagement architecture.
ML Graph
Real-time graph across customer, device, merchant, beneficiary, address, phone, and prior fraud. Survival-model tracking of tainted assets through the network — the signal that catches PIN POS cash-out rings before the next ATM hit.
Learn more →Model Foundry
Custom models for synthetic-identity scoring, mule detection, deposit-fraud classification, ATO defense, and dispute classification. Tuned to your channel mix, your product line, and your loss-attribution definitions.
Learn more →FlowX
The decisioning fabric for account opening, transaction authorization, deposit holds, wire screening, and dispute routing. Versioned, A/B-testable, and audit-logged within the agreed deployment boundary.
Learn more →What changes
$12M in annual loss reduction at a leading US bank — driven by survival-model tracking of tainted assets through the PIN POS network, in real time. The same playbook extends to deposit fraud, ATO, wire fraud, and merchant-side schemes.
For bank fraud, risk, and AML leaders
See it on your book.
We'll run an approved benchmark on a scoped slice of historical transactions and openings — with the data boundary and measurement method agreed before work begins.

