Accelerator · Revenue Assurance & Fraud Management

Real-Time Fraud Scoring

Score every risky event before it becomes a loss

Risk scoring and step-up authorisation for the moments fraudsters target: SIM swaps, device changes, account changes on self-care channels and mobile-wallet transactions. Signals from CDRs and subscriber data are combined into one score, and policy decides whether to allow, challenge, hold or block.

What it scores
SIM swap
And the account-takeover chain that follows
SIM box
Bypass and interconnect fraud patterns
Wangiri
One-ring and premium callback fraud
IMEI
Cloned and shared device identities
On the demo platform now Loading
–
SIM swaps scored
–
High-risk swaps
–
Open fraud cases
–
Exposure in cases
Figures come from the demo database behind this site (synthetic operator data), read live from the platform APIs. Amounts are in demo currency units.
Chapter 4The proof Use case 2 of 6 Value-chain stageFraud management · retail and care SIM operations

Stop fraud in the moment

The pressureSIM-swap, scam and bypass fraud now land on the operator’s brand — and its regulatory exposure.

Why it matters to an operator executiveThe phone number is the key to banking, wallets and identity. Scoring every risky event at the moment it happens protects customers and interconnect revenue without adding friction for everyone else.

Where it sits in the telecom value chain
  1. Network
  2. Product & pricing
  3. Sales & channels
  4. Customer care
  5. Billing, RA & fraud
  6. Wholesale & enterprise
  7. Regulatory

Highlighted: the stages this use case changes. See how our services map to it →

Business lens

From a business outcome to measured value

We start from the KPI an executive owns, not from the technology — then work back to the decisions, data and agents that move it.

Our delivery methodology
  1. 1 · Outcome & KPI Cut fraud and scam losses Fraud loss rate · detection rate · false positives · time to block
  2. 2 · Value-chain domain Fraud & SIM ops Retail and care SIM swaps, wallet, interconnect
  3. 3 · Decisions Allow, step up, hold, block Open a case; tune thresholds to risk appetite
  4. 4 · Data Event in context SIM swap and port events, CDR behaviour, device history, account changes
  5. 5 · AI & agents Explainable scoring Rules plus ML risk score; OODA agents work cases in SENTINEL
  6. 6 · Governance & adoption Policy, not hunches Risk appetite as policy; analysts decide blocks; model monitoring
  7. 7 · Measured value Losses avoided Against a pre-pilot baseline; customers protected

How we’d deliver it

Indicative durations · sized with you in discovery
  1. 1 2–3 wks
    Discover & value case
    Main deliverable

    Fraud typology and loss value case

  2. 2 2–3 wks
    Design
    Main deliverable

    Scoring features, policy matrix, case SLAs

  3. 3 30–45 days
    Build & integrate
    Main deliverable

    Real-time scoring and SENTINEL case pipeline on live feeds

  4. 4 2–4 wks
    Deploy & adopt
    Main deliverable

    Fraud ops trained; step-up journeys in retail and care

  5. 5 Ongoing
    Run & scale
    Main deliverable

    New typologies, model retraining, round-the-clock monitoring

Same five phases on every engagement; the pilot (phase 3) runs on your data with your team. How the methodology works →

The problem

The phone number has become the key to everything

One-time passcodes, wallet logins and account recovery all rely on the mobile number. Take over the SIM and you take over the customer: a fraudulent SIM swap can be followed within minutes by password resets and wallet cash-outs. Meanwhile SIM boxes, Wangiri call-backs and cloned devices drain interconnect and premium-rate revenue.

Most operators still detect these patterns after the fact, in batch reports. Real-time scoring moves the decision to the moment of risk — and a supervised case pipeline makes sure the exceptions reach an analyst with the evidence already assembled.

  • SIM swap & account takeoverSwaps on lost or stolen-phone claims with weak verification, followed by account changes.
  • SIM box & bypassHigh outbound, low inbound, many sites and contacts — terminating traffic off-net.
  • WangiriBursts of short calls to many targets to trigger premium call-backs.
  • IMEI cloning & sharingOne device identity seen across many subscriber numbers.
  • Behavioural anomaliesUnusual night activity and contact patterns against a subscriber's own baseline.
How it works

Score, decide, act — in the moment

Scoring runs on the governed Data Fabric; decisions and cases flow into the SENTINEL fraud command centre.

  1. 01
    Capture the event

    SIM swap, device change, login, account change or wallet transaction, as it happens.

  2. 02
    Add context

    Recent CDR behaviour, device history, channel, verification method and complaints.

  3. 03
    Score the risk

    Rules and ML models produce one explainable risk score with the signals behind it.

  4. 04
    Apply policy

    Allow, step up verification, hold high-value transactions or block — per your risk appetite.

  5. 05
    Case & feedback

    Exceptions open a case for an analyst; outcomes feed back into thresholds and models.

Screens · live demo data

Fraud signals on the demo platform

Each panel below is drawn from the platform APIs on this site, over the synthetic operator dataset. CDR pattern analysis can take a second or two to load.

Some demo data could not be loaded just now. The panels that loaded are shown; refresh to try again.
SIM box suspects
–
From CDR call patterns
Wangiri suspects
–
Short-call bursts
IMEI clone alerts
–
Shared device identities
Night-activity anomalies
–
Against subscriber baseline
SIM swaps by reason · high-risk share
SIM swaps by channel
Fraud cases by type and severity
Risk-score distribution of cases
Highest-risk cases
Open the case manager
SubscriberFraud typePatternRisk scoreSeverityExposureRecommended control
Agent squad · supervised digital workforce

OODA agents work the cases

The same observe, orient, decide, act loop that runs the SENTINEL fraud command centre. Blocks and wallet holds above policy limits wait for an analyst.

Observe Agent
Signal collector

Watches SIM swaps, device changes, CDR patterns and complaints, and opens a case when a signal crosses threshold.

Orient Agent
Context & scoring

Enriches the case with subscriber, device and usage context, scores it and classifies the fraud type.

Decide Agent
Policy & playbook

Picks the playbook action within policy; anything outside it goes to a named analyst with the rationale.

Human approval above policy limits
Act Agent
Execution & SLA

Blocks, holds, requests step-up verification or escalates, and tracks each action against its SLA.

Feedback loop
Learning

Confirmed and false-positive outcomes tune thresholds and retrain the scoring models.

Audit trail
Controls

Every signal, score, decision and action is logged for investigators, auditors and regulators.

Demo brief

What the demo data is telling us

A short reading of the panels above, written the way we would brief an operator executive after a first look at their data.

Illustrative demo briefWritten from this page’s synthetic demo data · not client results
What the demo data shows

SIM-swap requests arrive through the self-care app, the hotline and retail stores in similar volumes. High-risk swaps cluster in lost- and stolen-phone claims. Account takeover after a SIM swap dominates the case list, followed by IMEI sharing, SIM-box and Wangiri patterns.

Where we would act first
  1. Step-up verification for lost- and stolen-phone swaps, whatever the channel.
  2. A short hold on sensitive account changes and wallet cash-outs right after a swap.
  3. SIM-box and Wangiri suspects fed straight into interconnect blocking and partner disputes.
What a pilot would prove

A policy matrix your risk team owns, measured on losses avoided, false positives and customer friction, with every exception worked as a case in the SENTINEL command centre.

Value

What changes for the business

Decisions at the moment of risk

Risky swaps and account changes are challenged or held before money moves, instead of being found in next week's report.

Less friction for good customers

One explainable score lets you step up verification only where the risk is, rather than adding friction for everyone.

Evidence-ready cases

Analysts receive the signals, score and recommended control together, and every decision is on the record.

Want a number for your own network? Our value calculator estimates fraud losses avoided from your own assumptions.

Getting started

From pilot to production

Most operators start with SIM-swap scoring on one channel, then add patterns and channels.

Phase 1
Discovery

Map fraud types, channels, current rules and the decisions you want to automate; agree risk appetite.

1-2 weeks
Phase 2
Pilot

Connect SIM-swap, CDR and subscriber feeds; tune scoring on your history; run in shadow mode, then live.

30-45 days
Phase 3
Scale

Add SIM box, Wangiri and device patterns; connect wallet and self-care channels for step-up authorisation.

Sprints
Phase 4
Run

Model monitoring, retraining and AgentOps under agreed SLAs through Managed Services.

Managed service
Scope a fraud-scoring pilot

Tell us which fraud pattern costs you most. We'll propose a 30-45 day pilot on your data.

Chapter 4 · The proof · 2 of 6

Next: prove every number

Subscriber registration, privacy and new AI rules all ask the same question: where did this number come from?

AI
AI Analyst

I'm the DaasLabs AI Analyst for the telecom demo platform. I can help with:

  • Revenue assurance & CDR reconciliation
  • Fraud: SIM swap, SIM box, IRSF and Wangiri
  • Churn, customer and network analytics
  • Executive briefings across the accelerators

Answers are generated from the demo data.