Get alerted of anomolies in T24 financial transactions and User-behaviour.
RJB's Financial Integrity & Compliance (FIC) applications for T24
T24 Transaction & User oversight - microfinance affordability, with banking power.
Jump to our products...
Fraud, Anti-money Laundering and T24 User behaviour alerting.

STM - Suspicious Transaction Monitor
Catch Fraud & AML risks before they escalate - get alerted about transaction and user anomalies.
STM has a proven record - detecting high-volume money laundering.
Alerts your team - via ticket emails from it’s integrated opensource Redmine helpdesk system. Risk staff can document all analysis in the tickets created.
Lightweight, robust & reliable - Quick to install and configure. Centralised updates, for enhancements and patches.
Integrates with UAL - so that it can also send alerts for T24 User behaviour.
Safeguards your operational sovereignty - STM is deployed on your local infrastructure, giving your IT team full visibility, and a perpetual licence giving operational security - backed by our expert support.
STM is available in two service modes:
Managed - take a load off your Risk team, RJB proactively assists with ongoing configuration, monitoring, analyses & tuning. We recommend a regular team call to discuss findings, recommendations and further needs.
Self-managed - with RJB on hand to help as needed.
Clients are using STM to monitor the following specific types of behaviour - using our "Rule Types" -
-
Changes in key field values - Any change to registered mobile numbers
-
Privileged User activity - Super-users doing financial transactions
-
Transaction summing (over time, to handle smurfing) -
-
Till account credits per day being more than a set regulatory amount
-
Dormant savings accounts seeing any net-debit transaction sums within the last working day
-
-
Transaction volumes -
-
High volumes of debits or credits (or both) on drawdown and savings accounts, over any period of time.
-
Fixed deposit maturities (more for liquidity management)
-
Multiple loan disbursements within a short period of time.
-
-
Individual large transactions - Teller transactions greater than a defined regulatory amount, in the last working day.
-
Transactions between specific accounts - Teller transactions being done into forbidden account categories.
...and there are more Rule Types, and new ones can be added easily.


Examples of the daily Redmine "heartbeat" ticket, and a 'breach' ticket.
Example of a specific Transaction Volume monitoring "Rule" configuration:


STM has significantly strengthened our financial crime risk management, enabling us to detect money laundering and report it to the authorities. UAL further supports user audit activities, improving transparency, internal control and regulatory compliance. We are very satisfied. – Jastini Majaliwa, Risk & Compliance, VisionFund Tanzania
STM is really adding value to Risk management because the branch staff are checked on any change [to key client data fields]. - Senior Risk Officer, VisionFund Malawi

UAL - User Activity Logger
Capture everything Users do & touch, over any time frame - Supporting governance & accountability.
Capture the following:
-
User Sign-ons
-
Report requests
-
Record events - Capture when Users see, commit to NAU, reverse, copy, delete and authorise any record.
Clearly see records being self- or separately authorised.
Capture multiple stages within a single User action - for example, if a User commits a record to "INAU" status, UAL can can capture the initial See when the user opens the record; Then the 'commit request'; and finally a 'Successful commit to INAU' - three 'events' for one user 'action'.
Historical record event capture - UAL includes a tool to capture Input and Authorisation events from tables of your choice, that happened before UAL was installed.
UAL integrates with STM - allowing alerts to be generated based on T24 User behaviours.
UAL is also a powerful workflow analysis tool - For example to track all the events that any loan record experienced over time - which users, using which screens, changing what values, etc.

Powerful reporting from inside T24 - UAL's single enquiry shows you the following for each event captured:
-
The T24 User ID involved, the System Date, as well as the real local Date & Time at the time of the event, as per the T24 server.
-
Which T24 Application and Version or Enquiry name was involved
-
The type of event it was - "Logon Success", "Report Requested", "Successful commit to INAU", "Historical Authorisation", etc
-
Before-and-after field values, if they were edited -

[T24 field name] = [Before-edit value] / [After-edit value]
-
Events done by Super Users
Also - what IP address did they connect from? What audit trail version of the record got edited (CURR.NO) ... and more!

Backend Logging
Capture what Linux Operating System users are doing on your production T24 servers.
Capture the following:
-
All TAFC Jbase commands executed - from Jshell and other shells.
-
TAFJ DBTools & tRun commands - other options possible also.
-
Linux 'edit-type' commands - a parameterisable set, to balance logging volumes vs worthwhile data.
-
Changes to Backend Loggings own configurations
-
Additional contextural data - to help any forensic analysis
-
User Log-ons/offs
Backend logging provides passive logging - to support your forensic analysis, should it be needed.
Events are written into Linux standard syslog and auditd logs - So can be queried as text files or using Linux 'ausearch' commands.
Events can be stored in up to two places:
-
Locally - On the production server, say, with configurable log rotation settings
-
Remote - Duplicate entries can be written online, to any remote location, with it's own log rotation settings.



