Open fraud detection methodology.

Published methods, documented feature construction, and validation protocols for two detection gaps that existing systems do not cover: provider level anomaly detection in federal healthcare claims, and synthetic identity detection in consumer lending, together with fraud prevention curricula for older Americans.

Free. Verifiable. Available to any qualifying institution.

Portrait of Ayomide Ayeni

The problem

Fraud detection in the United States is allocated by budget rather than by exposure.

The largest financial institutions operate sophisticated commercial detection systems. Community banks, credit unions, and regional lenders generally operate with rule based screening or less. Fraud operations test defences and route toward the institutions that do not detect them. Capability concentrated at the top of the market does not eliminate loss. It displaces it downward, onto the institutions least able to absorb it, in the communities least able to replace a failed local lender.

Federal healthcare claims integrity faces a different constraint with the same effect. Review is predominantly rule based and post payment: a claim is paid, then audited against known fraud patterns. A rule detects only what has already been characterised and written down, and it examines one claim at a time. A provider whose individual claims each appear defensible remains invisible even when their aggregate billing behaviour is a clear statistical outlier against peers.

Both gaps share a structural property: they are resistant to rule based detection. Neither is closed by writing better rules.

And detection, wherever it operates, works only after a fraudulent transaction has been attempted. Where a victim is deceived into authorising a transfer herself, through impersonation of a family member, an official, or a bank, the transaction is not anomalous from the institution's side at all. The only intervention that stops that scheme is the intended victim recognising it.

The approach

Learn what normal looks like, then find what deviates from it.

Rather than encoding known fraud patterns as rules, these methods learn ordinary behaviour from the data itself and identify entities whose conduct departs from it in statistically improbable ways. The system does not need to be told what the scheme is, which is what allows it to surface schemes no one has yet characterised.

Learned systems are harder to explain than rules, and an unexplainable flag is useless in an enforcement context where a referral has to be defensible. Every method published here documents its feature construction in full and attributes each score to the specific measured behaviours that produced it.

The work

Provider level claims anomaly detection

Scores the biller, not the bill. Identifies providers whose billing behaviour deviates from peers of the same specialty, region, and patient mix, surfacing schemes that were never enumerated in a rule set.

For state Medicaid program integrity units, HHS OIG contractors, and Medicare Administrative Contractors.

Initiative 1 →

Transaction and synthetic identity detection

Transaction fraud detection validated across multiple payment environments, extended to synthetic identity detection at account origination, where every data element is individually valid and the falsehood lives in the combination.

For community banks, credit unions, regional lenders, and smaller origination platforms.

Initiative 2 →

Fraud prevention curricula for older Americans

Each detection pattern, reversed, becomes a recognition heuristic taught to the population that pattern targets. Structured modules with a facilitator guide, built to be delivered by any trained volunteer.

For AARP's Fraud Fighter Network and community organisations serving older adults.

Initiative 3 →

Objectives

  • Place detection capability where it is currently absent

    With integrity units and lenders that have no equivalent capability and no budget to acquire one.

  • Make adoption verifiable rather than trusted

    Every method ships with a validation protocol allowing an institution to test performance against its own historical data, including known fraud cases, before deploying anything.

  • Build methodology that improves through deployment

    Institutions report what they find: where features fail to compute against real data, where peer groupings misspecify, where flag volumes exceed investigative capacity. Those findings are incorporated and republished as deployment tested methodology.

  • Extend prevention to the point detection cannot reach

    Curricula built to be taught by volunteers, so reach is not bounded by any one person's calendar.

Access

Methodology is published without restriction. Papers, feature dictionaries, specifications, validation protocols, implementation guides, and all curricula are freely available to anyone. No registration. A competent team can implement from these documents alone.

Reference implementations are available to verified institutions at no cost. Verification confirms institutional identity against public regulatory registries, including NCUA charter numbers, FDIC certificate numbers, and state agency identifiers. It is an identity check, not an approval decision: there is no fee, no discretion, and no institution excluded by size, budget, sector, or geography.

The distinction reflects standard practice for security tooling. Detection logic fully readable by the actors it is designed to catch is detection logic they can engineer around.

Integrity

Every artifact is deposited under a permanent identifier, hashed with SHA-256, and timestamped by an independent RFC 3161 authority. Deposits are frozen on publication and cannot be altered, only superseded, with prior versions permanently retrievable.

Hashes and timestamp tokens are published for every artifact, including those requiring verification, so integrity is checkable without access.