home / case studies / Indian private-sector bank, retail segment (composite)
Banking

Real-Time Fraud Detection for Cards, UPI and Digital Banking

We built a real-time fraud decisioning engine that scores transactions and login events in milliseconds. Fraud losses and false declines both moved in the right direction, and analysts gained a modern case management tool.

Indian private-sector bank, retail segment (composite) · Banking

Real-Time Fraud Detection for Cards, UPI and Digital Banking

Challenge

Very tight latency budgets and highly imbalanced data. We precomputed features in a low-latency store, used champion/challenger deployments and tuned thresholds jointly with fraud operations.

Approach

Transaction and session events stream through Kafka into a decision service combining rules, velocity features (Flink) and gradient-boosted models trained on labelled fraud history. Device fingerprinting and behavioural signals add context for digital banking. Decisions (allow, step-up authentication, hold, decline) are returned within the authorisation window. A case management UI lets analysts investigate linked accounts through a graph view, and feedback labels flow back into model retraining.

Outcome

Fraud stopped at authorisation rather than discovered afterwards Illustratively ~20–40% fewer false declines on genuine transactions Step-up authentication used selectively instead of blanket blocks Faster investigations with linked-entity graph views Continuous improvement through analyst feedback loops

✓Fraud stopped at authorisation rather than discovered afterwards
~20–40%Illustratively fewer false declines on genuine transactions
✓Step-up authentication used selectively instead of blanket blocks

Problem solved

A batch, rules-only system detected fraud after the money had left, and blunt rules caused high false declines that frustrated genuine customers.

What we built

Transaction and session events stream through Kafka into a decision service combining rules, velocity features (Flink) and gradient-boosted models trained on labelled fraud history. Device fingerprinting and behavioural signals add context for digital banking. Decisions (allow, step-up authentication, hold, decline) are returned within the authorisation window. A case management UI lets analysts investigate linked accounts through a graph view, and feedback labels flow back into model retraining.

Benefits

Fraud stopped at authorisation rather than discovered afterwards Illustratively ~20–40% fewer false declines on genuine transactions Step-up authentication used selectively instead of blanket blocks Faster investigations with linked-entity graph views Continuous improvement through analyst feedback loops

KafkaApache FlinkGradient boostingDevice fingerprintingGraph viewChampion/challenger

Talk to us