What is this course about?
Fraud detection optimizes a cost asymmetry: false negatives lose money and false positives lose customers. This course covers anomaly detection against rules, behavioral and device signals, adversarial adaptation, real-time latency budgets, and the fair lending exposure a detection model can create.
Who is this course for?
- Fraud strategy and analytics teams
- Financial crimes technology staff
- Risk modeling teams
- Compliance staff covering fair lending
What do I need before starting?
- Analytics or modeling background
- Familiarity with your fraud detection systems
What will I be able to do afterwards?
- Model the cost asymmetry between false negatives and false positives
- Combine anomaly detection with rules rather than replacing them
- Handle adversarial adaptation as fraud patterns change
- Meet real-time latency budgets in scoring
- Assess fair lending exposure created by a detection model
What does each module cover?
What does each error type actually cost?
45 minModeling the asymmetry properly, including the customer cost that rarely appears in a business case.
Objectives
- Model the cost of false negatives and false positives
- Include customer lifetime cost of a wrong block
- Set thresholds from the cost model
Topics
Activity. Build the cost model including the customer cost of a wrong block.
Why do you need both anomaly detection and rules?
50 minThe complementary strengths, and why replacing rules with a model loses coverage.
Objectives
- Compare rules and anomaly detection coverage
- Design a layered approach
- Avoid losing known-pattern coverage
Topics
Activity. Measure what rules catch that a model misses, and the reverse.
What signals belong in the feature set?
50 minBehavioral, device, and network signals, with the privacy and fairness constraints on each.
Objectives
- Select signals with predictive value
- Assess privacy constraints on each signal
- Exclude signals that proxy protected characteristics
Topics
Activity. Audit a feature set for proxies of protected characteristics.
How do you handle fraud that adapts weekly?
50 minAdversarial adaptation and retraining cadence when the adversary observes your responses.
Objectives
- Detect pattern shift quickly
- Set a retraining cadence that keeps pace
- Avoid leaking your detection logic
Topics
Activity. Simulate an adaptive fraud pattern and measure detection decay over time.
How do you score in real time?
45 minLatency budgets and the architecture that meets them without sacrificing accuracy.
Objectives
- Meet real-time latency budgets
- Trade off model complexity against latency
- Design graceful degradation
Topics
Activity. Profile scoring latency and optimize to a stated budget.
What is your fair lending exposure?
55 minDisparate impact testing on a fraud model, which is frequently not tested at all.
Objectives
- Test a fraud model for disparate impact
- Distinguish legitimate risk signals from proxies
- Document testing for examination
Topics
Activity. Run disparate impact testing on a detection model and document the findings.
How do you explain a decline?
45 minExplanation to the customer and to a regulator, from a model that may not decompose easily.
Objectives
- Produce customer-facing explanations
- Produce regulator-facing explanations
- Handle models that resist decomposition
Topics
Activity. Produce both explanation types for ten declined transactions.
Building the triage workflow
50 minThe lab module: a triage workflow with false positive cost modeled into the thresholds.
Objectives
- Build triage with cost-derived thresholds
- Include a review path before customer impact
- Measure both error types
Topics
Activity. Build the workflow and measure both error rates against the cost model.
What is the capstone project?
Fraud detection workflow with fair lending testing
Build a fraud detection workflow with a cost model including customer impact, layered rules and anomaly detection, a proxy-audited feature set, adaptation monitoring, latency-compliant scoring, disparate impact testing, and dual-audience explanations.
Deliverable: A working detection workflow with documented fair lending testing and both error rates measured.
How are learners assessed?
- Cost model must include customer lifetime impact of a wrong block
- Feature set audited for proxies with findings documented
- Disparate impact testing completed and documented for examination
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for financial services.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- FinCEN
U.S. Treasury
Fraud and financial crime typologies informing detection design.
- FFIEC
Federal Financial Institutions Examination Council
Examination expectations for fraud models and fair lending.
- Gramm-Leach-Bliley Act guidance
Federal Trade Commission
Privacy constraints on the behavioral signals used in the feature set.
- AI Risk Management Framework
NIST
Bias testing methodology adapted in Module 6.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 6 is the module most fraud teams have never run. Fraud models are frequently exempted from fair lending testing by assumption, and the exposure is real.
- Module 1's customer cost is systematically omitted from fraud business cases. Insist on including it — the threshold that follows is materially different.
- Use synthetic transaction data with injected fraud patterns. Real transaction data cannot be used and injected patterns give you ground truth.
- Module 4's adversarial framing should not become a security-through-obscurity argument. Detection logic will leak; the design should assume it.
- Have a fair lending compliance officer review Module 6. The methodology has regulatory consequences and should not be written by modelers alone.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Fraud Detection with AI: Anomalies, Alerts, and False Positives course cover?
Fraud detection optimizes a cost asymmetry: false negatives lose money and false positives lose customers. This course covers anomaly detection against rules, behavioral and device signals, adversarial adaptation, real-time latency budgets, and the fair lending exposure a detection model can create. It runs 6 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Fraud detection workflow with fair lending testing.
Who should take Fraud Detection with AI: Anomalies, Alerts, and False Positives?
It is written for Fraud strategy and analytics teams, Financial crimes technology staff, Risk modeling teams, Compliance staff covering fair lending. Prerequisites: Analytics or modeling background; Familiarity with your fraud detection systems.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.
How do we get access to Fraud Detection with AI: Anomalies, Alerts, and False Positives?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for financial services cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.