Anomoly alerts for T24 financial transactions and User-behaviour.
RJB's Financial Integrity & Compliance (FIC) applications for T24
T24 Transaction & User oversight - microfinance affordability, proven results.
Our products:
STM - Suspicious Transaction Monitor

Intercept Fraud & AML risk before it escalates - Cost-effective compliance and alerting, designed to let Risk teams work effectively.
A proven record - STM has provided early-warning alerts on suspected money-laundering activity involving transaction values in the hundreds of thousands of dollars.
Batch alerting - Real-time engines create a constant, unpredictable trickle of alerts that disrupt focus, fragment the workday, and can lead to 'alert fatigue' that increases the risk of something being overlooked. RJB's STM takes a smarter approach for smaller institutions and MFIs, reducing operational noise:
-
Alerting based on a fuller picture: STM analyzes 100% of the day’s user behavior and transaction patterns before deciding whether to alert - reducing the volume of alerts through daily consolidation.
-
A more structured Risk team day: Your team starts every morning with a single consolidated view of what STM found, plus any individual alert - allowing them to plan their investigation time without distractions during the day.
-
Zero System Overhead: STM runs out-of-hours without impacting live core banking system performance.
Insider-risk monitoring - Integrates with RJB's UAL (User Activity Logger) to provide alerting based on T24 User behaviour.
Technological sovereignty - STM is deployed on your local infrastructure, giving your IT team full visibility - plus a perpetual IP licence giving operational security - backed by our expert support.
Rules-based - our heavily-parameterizable Rule Types provide a wide range of financial and user behaviour patterns that can be monitored for, some examples being:
Changes in Field-values - i.e. Any change to a registered mobile phone number.
Privileged User activity - i.e. Super-users doing financial transactions.
Sum of Transaction-Values over a period (for anti-structuring), i.e.
-
Sum of all credits on Drawdown Accounts more than a set regulatory amount over 15 days.
-
Any activity resulting in a net-debit position on Dormant savings accounts in the last working day.
Transaction Volumes (velocity monitoring) - i.e.
-
High volumes of debits or credits (or both) on savings accounts, over any period of time.
-
Multiple loan disbursements within a short period of time.
-
Debit transaction bursts.
-
Can even be used for liquidity management, i.e. Detecting fixed-deposit maturities.
Individual Large Transactions - i.e. Any Teller debit or credit greater than a defined regulatory amount, in the last working day.
Transactions Between Specific Accounts - i.e. Teller transactions being done into operationally-sensitive account categories.
...and more - and new Rule Types can be added easily.
Helpdesk included - Allows staff to document their analysis of each alert in one consolidated system - great for auditability and transparency.
Lightweight implementation, robust & reliable -
-
Operating Systems: Linux or Windows
-
Database: MongoDB Community Edition (free)
Alerts/helpdesk system ticket examples

The daily "heartbeat" status ticket

An alert ticket
A Rule example
A Rule is a fully-parameterized instance of one of our Rule Types - The below illustrates a Rule for the Transaction Volume Rule Type - with the parameter values highlighted:

STM is available in two service modes:
Managed - Take a load off your Risk team - RJB proactively assists with ongoing configuration, monitoring, analyses & tuning, engaging in active collaboration with your staff.
Self-managed - The institution handles ongoing configuration, with RJB on hand to help as needed.
Feedback from clients...

STM has significantly strengthened our financial crime risk management, enabling us to detect money laundering and report it to the authorities. UAL further supports user audit activities, improving transparency, internal control and regulatory compliance. We are very satisfied. – Jastini Majaliwa, Risk & Compliance, VisionFund Tanzania
STM is really adding value to Risk management because the branch staff are checked on any change [to key client data fields]. - Senior Risk Officer, VisionFund Malawi
UAL - User Activity Logger for T24

T24 User auditability and compliance - capture everything Users do in the system, all brought together in one place, in one powerful, convenient report.
Capture every type of interaction a User has with records in T24 - For example: Seeing, Inputting, Deleting, Reversing, Authorising, etc.
-
Easily identify self-authorisations and maker-checker authorisations.
-
Capture multiple stages within a single User action - If a User commits a record to "INAU" status, say, UAL can capture various stages of that interaction: The initial See on opening the record; Then the 'commit request'; and finally a 'Successful commit to INAU' - i.e. multiple 'events' for one user 'action'.
-
Also capture User Sign-ons, and Report requests
Historical record event capture - Capture record Input & Authorisation events from T24 Applications (tables) for any date-range prior to the installation of UAL.
Powerful workflow analysis - Apart from user-centric reporting, UAL can be used to show, for example, all the events that any one contract experienced during some time-frame - which users touched it, what screens did they use, what values did they change, etc.
UAL integrates with STM - Allowing alerts to be generated based on T24 User behaviours.
Lightweight implementation, robust & reliable -
-
TAFC T24 later than R06, or any TAFJ environment.
-
Database: Any SQL-type database, or MongoDB.

Powerful reporting inside T24 - For record events, UAL's single flexible enquiry show both the System and server dates of each event, and the server time it happened, which T24 Application and Version or Enquiry was involved, the record ID, type of event ('Commit to INAU', say), the user's apparent IP number, the user's attributes (SUPER.USER, for example), and more - including the before/after values of any fields they changed:

Field value changes are in format: [T24 field name] = [Before-edit value] / [After-edit value]
Linux Backend Logging

T24 server-level auditability & compliance - capture what Linux Operating System users are doing on your production T24 servers.
Capture the following:
-
All TAFC Jbase commands executed - from Jshell and other shells.
-
TAFJ DBTools & tRun commands - Other types of other TAFJ event can be logged also.
-
Linux commands - a parameterized set, rather than 'all', to balance logging volumes vs worthwhile data.
-
Additional contextural data - to help any forensic analysis
-
User Log-ons/offs
Events can be stored in up to two places:
-
Locally - Within the network, with configurable log rotation settings
-
Remote - A duplicate set of entries is written online, for redundancy and additional security, to any remote location, with it's own log rotation settings.
