Skip to content
HeuriTel
Sign in
Revenue, Risk and Assurance

Fraud, Identity & Customer Protection

Stop the SIM swap, the takeover and the subscription fraud before the money moves, and let the fraud system make the call.

Bounded rules and models score SIM, subscription, account-takeover, payment, traffic and roaming fraud, and pass the signal to the authorised fraud or transaction-control system with its reasons.

For Fraud, risk, security and digital identity teams protecting customers and revenue.

The decision, annotated from the record

A password reset, a SIM change and a wallet transfer arrive on one account within an hour.

This sequence as a takeover or not, the value of the signal, and the system that acts on it.

  1. Pass a high-risk signal with its reasons to the transaction-control systemConsidered
  2. Refer the account for human follow-upConsidered
  3. Suppress the signal, where the customer verified through a held channelConsidered
  4. No action, where the sequence has a known causeConsidered

Before anything reaches the customer: Signal quality, consent, customer verification and the control system's own policy checks pass.

What would reach them: The control system steps up, pauses or rejects; the customer is told through a channel the attacker does not hold. On SMS, App, Call.

Annotated, not computed. No engine runs on this page. Read the journey in full

No demonstration is configured for this journey yet.

The journey below is written for a generic operator. Tell us your market and it will be presented in it.

Configure a demonstration
The decision

This sequence as a takeover or not, the value of the signal, and the system that acts on it.

A password reset, a SIM change and a wallet transfer arrive on one account within an hour. Each is ordinary on its own.

  • Pass a high-risk signal with its reasons to the transaction-control system
  • Refer the account for human follow-up
  • Suppress the signal, where the customer verified through a held channel
  • No action, where the sequence has a known cause
What it does

Three things it helps you decide or do.

  • Detect and prioritise the risk with the reasons attached

    SIM, subscription, account takeover, payment, recharge, traffic, roaming, API, SIM box and international revenue share fraud are scored from customer, device and transaction signals, with identity theft detection and KYC verification beside them.

    • customer_id
    • account_type
    • tenure_days
    • active_products
    • recharge_30d
    • usage_30d
    • revenue_30d
    • last_contact
    • consent_status
    • outcome_label
  • Pass the signal to the system that acts

    The authorised fraud or transaction-control system steps up, pauses or rejects; the decision here is to suppress, refer for human follow-up or do nothing, never to move the money itself.

    • Offer
    • service message
    • reward
    • channel change
    • human follow-up
    • suppress
    • do nothing
  • Audit every decision and approval

    The decision log, the eligibility snapshot and the approval record are kept for every signal, so a customer who was blocked and a fraud that was missed can both be examined.

    • Decision log
    • eligibility snapshot
    • price/order response
    • delivery receipt
    • control assignment
    • revenue/outcome ledger
The journey

Stop an account takeover before the transfer, and let the fraud system decide

No demonstration is configured for this product yet.

Fraud, Identity & Customer Protection: the situation this product is about

Fraud, risk, security and digital identity teams

StepWhat the customer experiencesWhat the operator does
The momentThe moment that started it.A password reset, a SIM change and a wallet transfer arrive on one account within an hour.Reads the event sequence and its timing, device, sim and identity verification signals, consent and customer verification history, the control system's own policy.
The decisionThe decision to be made.Nothing reaches the customer yet.Scores the sequence as a takeover risk with its reasons, and passes the signal to the fraud or transaction-control system.
The safeguardsThe conditions that stop it.Still nothing. No action is sent until every check has passed.Signal quality, consent, customer verification and the control system's own policy checks pass.
The actionThe action that reaches the customer.The control system steps up, pauses or rejects; the customer is told through a channel the attacker does not hold. Reaches them on SMS, App, Call, in Kiswahili, English.Recommends. The system that holds the right confirms, charges or provisions.
When it goes wrongRefusal, failure and recovery.A customer who replaced a lost phone and moved money the same day is held, and cannot be reached because the notification goes to the new SIM.The notification goes to a channel the customer held before the change, the hold is lifted on verification, and the case is kept so the score learns the pattern.
The resultThe change it made.What changed for them is what is counted; nothing else is claimed.Takeovers stopped before a loss, against legitimate customers wrongly held.
The proofThe proof anyone can check.Can be answered for, later, from the record.Event sequence, score and reasons, signal passed, control system's decision, customer notification and outcome.

Hypothesis

A takeover stopped before the transfer costs a verification; one found afterwards costs the money and the customer.

Desired result: Incremental revenue or retention; lower contact waste; improved conversion with margin guardrails

Modelled not observed

No figure is modelled for this journey. The mechanism that could produce the result is stated instead.

Ingest → qualify → score → apply limits/consent → assign control → execute approved action → capture delivery and business outcome → monitor/retrain

Observed

Nothing yet. Measurement begins in a pilot’s validate stage, on your systems, against a comparison agreed first.

Randomised holdout where feasible; intent-to-treat primary view; pre-declared denominator; guardrails for complaints, margin and opt-out

Measured on: Eligible population; treatment rate; conversion; incremental revenue; ARPU; churn; contact rate; margin; opt-out; decision latency

Assumptions, costs and the record’s five answers
  1. 01
    Desired result

    The result wanted.

    Incremental revenue or retention; lower contact waste; improved conversion with margin guardrails

  2. 02
    Mechanism

    The mechanism that could produce it.

    Ingest → qualify → score → apply limits/consent → assign control → execute approved action → capture delivery and business outcome → monitor/retrain

  3. 03
    Evidence required

    The records kept to show it.

    Decision log; eligibility snapshot; price/order response; delivery receipt; control assignment; revenue/outcome ledger

  4. 04
    Costs and risks

    The cost, and the ways it can go wrong.

    Costs: Setup fee + annual product subscription; optional managed execution fee; optional verified-outcome fee with agreed baseline

    If it fails: Fail closed on eligibility/consent/price; queue retryable events; do not duplicate orders; route exception to campaign operations

  5. 05
    Measurement approach

    The measure that shows it helped.

    Randomised holdout where feasible; intent-to-treat primary view; pre-declared denominator; guardrails for complaints, margin and opt-out

    Measured on: Eligible population; treatment rate; conversion; incremental revenue; ARPU; churn; contact rate; margin; opt-out; decision latency

Nothing has been observed for this product. Every line above is the record's own design intent; measurement begins in a pilot's validate stage, on your systems, with the comparison agreed first.

The business side

The change
Takeovers stopped before a loss, against legitimate customers wrongly held.
Running cost
Setup fee + annual product subscription; optional managed execution fee; optional verified-outcome fee with agreed baseline
What evidence supports it
Event sequence, score and reasons, signal passed, control system's decision, customer notification and outcome.
Technical detail

Inputs, decision logic, systems touched, records kept.

Four questions an evaluation asks in a different order every time. Every field is the workbook’s own, unedited.

What would we need from your systems, and how much history?

Attributes required

  • customer_id
  • account_type
  • tenure_days
  • active_products
  • recharge_30d
  • usage_30d
  • revenue_30d
  • last_contact
  • consent_status
  • outcome_label

Also useful, not required

  • Network experience
  • digital clickstream
  • complaints
  • location cohort
  • household/account links
  • partner purchases

8-12 weeks of customer, usage, revenue, product, contact and outcome history; stable customer key; one executable channel

The 24 definitions underneath

24 in this product

  1. HeuriTel Fraud ManagementDecision definitionHT-0252

    Detect and prioritise fraud management risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0252
  2. HeuriTel SIM FraudDecision definitionHT-0253

    Detect and prioritise sim fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0253
  3. HeuriTel SIM Swap FraudDecision definitionHT-0254

    Return or subscribe to the last SIM-change signal for an authorised number so an enterprise risk policy can step up, pause or reject a sensitive action.

    /d/HT-0254
  4. HeuriTel Subscription FraudDecision definitionHT-0255

    Detect and prioritise subscription fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0255
  5. HeuriTel Account Takeover PreventionDecision definitionHT-0256

    Detect and prioritise account takeover prevention risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0256
  6. HeuriTel Payment FraudDecision definitionHT-0257

    Detect and prioritise payment fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0257
  7. HeuriTel Recharge FraudDecision definitionHT-0258

    Use customer affordability, usage, renewal and margin data to improve recharge fraud while controlling cannibalisation and measuring incremental value.

    /d/HT-0258
  8. HeuriTel Traffic FraudDecision definitionHT-0259

    Detect and prioritise traffic fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0259
  9. HeuriTel Roaming FraudDecision definitionHT-0260

    Detect and prioritise roaming fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0260
  10. HeuriTel API FraudDecision definitionHT-0261

    Detect and prioritise api fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0261
  11. HeuriTel Customer VerificationDecision definitionHT-0262

    Identify eligible records for customer verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0262
  12. HeuriTel Device VerificationDecision definitionHT-0263

    Identify eligible records for device verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0263
  13. HeuriTel KYC VerificationDecision definitionHT-0264

    Identify eligible records for kyc verification, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0264
  14. HeuriTel Consent ManagementDecision definitionHT-0265

    Identify eligible records for consent management, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0265
  15. HeuriTel AI ComplianceDecision definitionHT-0266

    Identify eligible records for ai compliance, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0266
  16. HeuriTel Decision AuditDecision definitionHT-0267

    Identify eligible records for decision audit, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0267
  17. HeuriTel Approval ManagementDecision definitionHT-0268

    Identify eligible records for approval management, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0268
  18. HeuriTel SIM Box FraudDecision definitionHT-0269

    Detect and prioritise sim box fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0269
  19. HeuriTel International Revenue Share FraudDecision definitionHT-0270

    Detect and prioritise international revenue share fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0270
  20. HeuriTel Identity Theft DetectionDecision definitionHT-0271

    Detect and prioritise identity theft detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0271
  21. HeuriTel Mule Account DetectionDecision definitionHT-0272

    Detect and prioritise mule account detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0272
  22. HeuriTel Promo Abuse DetectionDecision definitionHT-0273

    Detect and prioritise promo abuse detection risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0273
  23. HeuriTel Dealer FraudDecision definitionHT-0274

    Detect and prioritise dealer fraud risk using bounded rules and models, then pass the signal to the authorised fraud or transaction-control system.

    /d/HT-0274
  24. HeuriTel Social Engineering RiskDecision definitionHT-0275

    Identify eligible records for social engineering risk, choose from approved actions including no action, execute through the system of record, and measure the agreed business outcome.

    /d/HT-0275

Search definitions across every product

Implementing it

Four stages, and what has to be true before the next one starts.

12-16 weeks to pilot; 2-4 additional weeks per market after reusable interfaces exist. A team of 8 roles, named in the record rather than promised.

  1. 01

    Scope

    One use case, one value unit and a denominator finance has agreed to. Without these there is nothing a later result can be compared against.

    • Confirm value unit
    • select use case
    • baseline denominator
  2. 02

    Connect

    The attributes mapped from your systems, and the decision and outcome interfaces working in both directions.

    • map attributes
    • integrate decision and outcome APIs
  3. 03

    Validate

    Eligibility agreed, a dry run with nothing sent, then a controlled pilot with a holdout that is actually respected.

    • build eligibility
    • dry run
    • controlled pilot
  4. 04

    Operate

    The live loop: decide, check, execute through your systems, capture what came back, and measure against the control.

    • Ingest
    • qualify
    • score
    • apply limits/consent
    • assign control
    • execute approved action
    • capture delivery and business outcome
    • monitor/retrain

Who does it. 1 telecom product lead · 1 CVM specialist · 1 data engineer · 1 ML engineer · 1 integration developer · 0.5 QA · 0.5 DevSecOps · 1 deployment coordinator

Four states are tracked, and each is assessed against your systems.

Readiness is assessed per client: nothing is offered as pilot-ready until your data, your integration and your authority have been checked.

Readiness

Needs client data and integration review

The client’s data and integration position.
Runtime / build state

Target product definition

What exists as running software.
Surface state

Not audited

Whether this product shows the entry anywhere.
Client status

Not assessed

Where a named client has reached.

Next steps from here.

24 definitions sit under Fraud, Identity & Customer Protection. The two links that matter first are the journey this page describes, and the rest of the family it belongs to.

See HeuriTel configured for your organisation

Verify your work email to open a demonstration configured for your organisation.