Fraud Watch: the second look

Fraud Watch looks across everything your company has connected and every finding your modules have raised, and points out the patterns that are worth a second look. It never accuses, never blocks and never decides. It names a supplier, an account or a document, never a person, then links what it saw and says why it is worth a look. It comes with every subscription, is never switched on or off, and sees only the modules you have.

What it reads

Every finding from every module you have, and the Data Room with where each document came from. Your Organisational context and its change log. Your dispositions and the reasons you gave. And the activity ledger, the record of who changed what and when.

The patterns it watches for

  • A supplier's bank details changed shortly before a payment went out to them.
  • A first-time supplier with no agreement in the Data Room sends a first invoice above your approval limit.
  • Two or more invoices that repeat or split one purchase, each small enough to pass without a second approval.
  • A change to your context, or a rejection, made a finding with money on it stop being raised.
  • A supplier's price for the same item keeps climbing across invoices, with no amendment that moves it.
  • A Connection was removed, or something was deleted, within days of a finding on the same supplier, account or document.

Each pattern reads particular things, such as invoices, Procure-to-Pay findings or the activity ledger, and it raises nothing until those things are in the Data Room.

When it runs

On every change that lands in the activity ledger or produces a finding, and once a day as a sweep across everything you have. It raises one finding per subject per pattern per thirty days, and new information updates that finding and its date rather than adding another.

Where it shows

Your Dashboard shows the count of fraud-risk findings, and each module's Overview keeps a Fraud Risk box with its count and the latest items. One Fraud Watch page lists every fraud-risk finding grouped by subject, with the linked findings and ledger events beneath, so you can walk from the pattern to the findings behind it.

What a fraud-risk finding says

It has five parts: what was noticed, in one or two sentences with the subject named; what it links, each one a link; why it matters, in one sentence; one concrete next check you can take; and its confidence, with the reason it is not higher. It carries no dollar value of its own, because the money sits on the exceptions it links.

Asking a module to look again

Fraud Watch may ask a module to run one Control again on one subject through a different lens: against the price before a change, treating an amendment as not applicable, including cancelled documents, widening the window to the prior period, or testing the counterparty across all its subjects. The result is an ordinary finding, linked to the fraud-risk finding and labelled as run again at Fraud Watch's request, and the request itself is recorded in the activity ledger.

How you answer it

Any admin can accept a fraud-risk finding in one step. Rejecting one takes two people, and one of them must be the Owner; until the second person approves, the finding shows rejection pending approval and stays open. Fraud Watch reads every decision and the reason you gave, including decisions on its own findings, and it never learns silently. Findings and Dispositions has the steps.

What it will not do

It will not give an opinion on whether fraud has occurred, and it will not block, hold or reverse anything. It never names a person as responsible, never runs on data from a module you have not subscribed to, and never learns silently from your dispositions.

The Fraud Watch page describes its principles in full, and Members and roles explains the Owner.