Glossary

Anti-Money Laundering, Know Your Customer, fraud and risk terms defined, as the industry uses them. Each entry describes the concept, not the DetectX® implementation of it.

Regulatory foundations

Anti-Money Laundering
The controls a regulated firm operates to stop criminal proceeds moving through it, and to report them when they are found. Obligations are set nationally but follow the recommendations of the Financial Action Task Force, and generally cover customer identification, ongoing monitoring, record keeping and reporting. Usually abbreviated to AML.
Customer Due Diligence
The checks a firm makes to identify a customer, verify that identity against reliable sources, understand the purpose of the relationship and establish who ultimately owns or controls it. Applied before the relationship starts, and repeated when the relationship changes or its risk rating moves. Abbreviated to CDD.
Enhanced Due Diligence
The deeper set of checks applied where a relationship presents higher risk, such as a politically exposed person, a higher-risk jurisdiction or an opaque ownership structure. It typically adds source of funds and source of wealth enquiries, senior management approval and more frequent review. Abbreviated to EDD.
Know Your Customer
Establishing and maintaining a verified picture of who a customer is, before and throughout a business relationship. It covers identification, verification, beneficial ownership and the risk assessment that decides how closely the relationship is watched. KYC is the entry point to due diligence rather than a synonym for it.
Suspicious Activity Report
A report filed with a national financial intelligence unit when a firm knows or suspects that funds or a transaction relate to criminal conduct. The report is confidential, and in most regimes the firm is forbidden to tell the customer it has been made. Some jurisdictions call it a Suspicious Transaction Report.

Screening, lists and entities

Adverse Media Search
Searching news, open web sources and public registers for negative information about a person or an organisation. It looks for risk no list has captured yet, such as an investigation or a regulatory action reported before any designation follows. Also called negative news screening.
Asset Screening
Screening assets rather than people against sanctions and watch lists. The subjects are typically vessels, aircraft, cargo and property, each identified by a registration, an IMO number or a similar identifier rather than by a name, which changes how a match is made and scored.
Data Enrichment
Adding to a customer or transaction record from sources outside it: sanctions and watch list entries, media coverage, company registry data or behavioural signals. Screening and scoring are only ever as good as the record they run against, which is what enrichment exists to improve.
Entity Resolution
Identifying and linking records that refer to the same person or organisation across different sources, spellings and identifiers. Without it one customer is several records, and both screening and link analysis run against a fragment rather than the whole.
List Consolidation
Merging several external and internal watch lists into a single screening framework, so a name is checked once against everything rather than once per list. It is what keeps screening consistent as the number of lists a firm subscribes to grows.
Name Screening
Comparing a name, whether a customer, a counterparty, an entity or a vessel, against sanctions lists, PEP registers and other watch lists. Because names vary in spelling, transliteration and order, screening uses fuzzy matching and returns a similarity score rather than a yes or no.
Politically Exposed Person
A person entrusted with a prominent public function, together with close family members and known associates. PEP status is not an allegation. It marks a raised risk of bribery and corruption, which is why most regimes require enhanced due diligence on the relationship. Abbreviated to PEP.
Sanctions List
A published list of people, organisations, vessels or jurisdictions subject to restrictive measures imposed by a government or an international body. Lists are maintained by bodies such as the United Nations, the European Union, the United States Office of Foreign Assets Control and the United Kingdom Office of Financial Sanctions Implementation, and they change without notice.
Sanctions Screening
Checking individuals, companies and transactions against official sanctions lists to establish that no restriction applies. It differs from most screening in what it is: a legal prohibition rather than a risk judgement. A subject either is the designated party or is not, and the consequence of being wrong is not a missed risk but a breach.
Screening List Management
Organising and maintaining the external and internal lists a firm screens against: sanctions, PEP registers, adverse media sources and private databases. Lists change without notice, so keeping them current, versioned and attributable is part of the control rather than administration around it.
Transaction Filtering
Screening a payment message against sanctions and watch lists while the payment is in flight. Filtering reads the parties, the narrative fields and any entity referenced in the message. It differs from name screening in its subject: a single message passing through, rather than a customer record on file.
Ultimate Beneficial Owner
The natural person who ultimately owns or controls a legal entity, whether directly or through a chain of holdings. Most regimes set a shareholding threshold above which a person must be identified, commonly 25 per cent, and apply a control test where no shareholder reaches it. Abbreviated to UBO.

Monitoring and analysis

Backtesting
Running a detection rule or a risk model against historical data to measure how it would have performed, and tuning it before it goes live. It is how a change is validated without waiting for real alerts to prove it wrong, and it is the evidence behind a decision to move a threshold.
Behavioural Analysis
Assessing how a customer, account or user behaves rather than judging a single transaction on its own. It flags activity that departs from an established pattern, such as an unfamiliar device, an unusual time of day, or a change in how payments are made.
Digital Identity
The set of attributes and signals used to establish that a person online is who they claim to be. It typically combines document and biometric verification at onboarding with device, network and behavioural signals gathered during a session.
Early Warning Indicators
Signals that risk is rising before any threshold is breached: a change in behaviour, a new media mention, a shift in transaction patterns. An indicator is a reason to look sooner rather than a finding, and acting on one is a judgement rather than an obligation. Abbreviated to EWI.
Fraud Detection
Identifying transactions or sessions intended to obtain money or information dishonestly, usually in or close to real time. It shares techniques with AML monitoring but answers a different question: fraud asks whether the customer is being defrauded or is the one defrauding, AML asks where the money came from.
Link Analysis
Examining the relationships between entities, accounts and transactions rather than each record on its own. It surfaces structures no single record shows, such as a shared address or directorship, or funds routed through intermediaries to put distance between an origin and a destination.
Ongoing Monitoring
Continuous review of customer activity, data changes and risk indicators after the relationship has started. Due diligence at onboarding is a snapshot; ongoing monitoring is the obligation to keep that picture current for as long as the relationship lasts, and to notice when it stops matching the customer.
Pattern Recognition
Detecting recurring structures in data that match a known typology, such as deposits kept below a reporting threshold or funds passed straight through an account. Patterns may be written as rules or learned from historical data, and a pattern is a reason to look rather than a finding.
Transaction Monitoring
Ongoing review of transactions across an account or a portfolio to find activity inconsistent with what the firm knows about the customer. It runs against rules, thresholds and models, and produces alerts for an analyst to assess. Distinct from filtering, which acts on one message in flight.

Risk, scoring and alerts

Alert Management
The workflow that takes an alert from creation to a recorded decision: assignment, investigation, escalation where it is needed, and disposition with a stated reason. Supervisors examine this record, so who decided what, and on what evidence, carries as much weight as the detection that raised the alert.
Audit Trail
A time-stamped, tamper-evident record of system activity and of the decisions taken on it. In a compliance setting it is what accountability rests on: it supports backtesting, and it is what a supervisor reads when a decision has to be reconstructed years after the people involved have moved on.
Case Management
Consolidating several alerts and the data around them into one investigative case, so that a pattern spread across separate alerts is worked as one thing rather than as four unrelated ones. It is where the decisions are documented and where a regulatory report is assembled from.
Client Risk Scoring
Assigning each customer a risk score that moves as the relationship does, built from onboarding data, transaction history, adverse media and behaviour. The score is what decides which controls the relationship attracts, which is why how it is calculated has to be explainable.
Customer Risk Assessment
Evaluating a client's risk profile from what is known about them: geography, business type, product, behaviour and external data. The result sets how closely the relationship is monitored and how much due diligence it attracts, and it is revisited rather than fixed at onboarding.
False Positive
An alert that turns out not to carry the risk it was raised for, most often a name matched to the wrong person. False positives dominate screening and monitoring workloads. Reducing them without losing true hits is the central tuning problem in both, because a threshold moved to cut noise also cuts detection.
Geographic Risk
How much a customer's or a transaction's location raises the likelihood of financial crime. Jurisdictions are treated as higher risk on the basis of Financial Action Task Force listings, national law and regional instability, and an assessment moves when any of those does.
Model Governance
Keeping the machine learning and rule-based models used in compliance transparent, tested and monitored across their working life. Supervisors expect a model to be explainable, controlled and owned by someone, rather than accurate alone, and expect the same of every change made to it.
Profiling and Scoring
Building a profile of a customer, account or counterparty from its attributes and its behaviour, then expressing the resulting risk as a score. The score drives how the relationship is handled: how often it is reviewed, which thresholds apply to it, and what due diligence it attracts.
Risk Based Profiling
Directing control effort in proportion to assessed risk rather than applying the same checks to every customer. It is the approach the Financial Action Task Force recommends and most regimes require, so a higher-risk relationship receives more due diligence and more frequent review than a lower-risk one. The principle is also called the risk-based approach, abbreviated to RBA.

Terms are grouped by the job they do rather than alphabetically. Where a term is also the name of a DetectX® module, the page for that module under Solutions or Platform is where the implementation is described. Definitions here state common regulatory practice and are not legal advice.