Risk scoring and step-up authorisation for the moments fraudsters target: SIM swaps, device changes, account changes on self-care channels and mobile-wallet transactions. Signals from CDRs and subscriber data are combined into one score, and policy decides whether to allow, challenge, hold or block.
The pressureSIM-swap, scam and bypass fraud now land on the operator’s brand — and its regulatory exposure.
Why it matters to an operator executiveThe phone number is the key to banking, wallets and identity. Scoring every risky event at the moment it happens protects customers and interconnect revenue without adding friction for everyone else.
Highlighted: the stages this use case changes. See how our services map to it →
The fraud and revenue-assurance use cases come together in the SENTINEL command centre →
We start from the KPI an executive owns, not from the technology — then work back to the decisions, data and agents that move it.
Fraud typology and loss value case
Scoring features, policy matrix, case SLAs
Real-time scoring and SENTINEL case pipeline on live feeds
Fraud ops trained; step-up journeys in retail and care
New typologies, model retraining, round-the-clock monitoring
Same five phases on every engagement; the pilot (phase 3) runs on your data with your team. How the methodology works →
One-time passcodes, wallet logins and account recovery all rely on the mobile number. Take over the SIM and you take over the customer: a fraudulent SIM swap can be followed within minutes by password resets and wallet cash-outs. Meanwhile SIM boxes, Wangiri call-backs and cloned devices drain interconnect and premium-rate revenue.
Most operators still detect these patterns after the fact, in batch reports. Real-time scoring moves the decision to the moment of risk — and a supervised case pipeline makes sure the exceptions reach an analyst with the evidence already assembled.
Scoring runs on the governed Data Fabric; decisions and cases flow into the SENTINEL fraud command centre.
SIM swap, device change, login, account change or wallet transaction, as it happens.
Recent CDR behaviour, device history, channel, verification method and complaints.
Rules and ML models produce one explainable risk score with the signals behind it.
Allow, step up verification, hold high-value transactions or block — per your risk appetite.
Exceptions open a case for an analyst; outcomes feed back into thresholds and models.
Each panel below is drawn from the platform APIs on this site, over the synthetic operator dataset. CDR pattern analysis can take a second or two to load.
| Subscriber | Fraud type | Pattern | Risk score | Severity | Exposure | Recommended control |
|---|---|---|---|---|---|---|
The same observe, orient, decide, act loop that runs the SENTINEL fraud command centre. Blocks and wallet holds above policy limits wait for an analyst.
Watches SIM swaps, device changes, CDR patterns and complaints, and opens a case when a signal crosses threshold.
Enriches the case with subscriber, device and usage context, scores it and classifies the fraud type.
Picks the playbook action within policy; anything outside it goes to a named analyst with the rationale.
Human approval above policy limitsBlocks, holds, requests step-up verification or escalates, and tracks each action against its SLA.
Confirmed and false-positive outcomes tune thresholds and retrain the scoring models.
Every signal, score, decision and action is logged for investigators, auditors and regulators.
A short reading of the panels above, written the way we would brief an operator executive after a first look at their data.
SIM-swap requests arrive through the self-care app, the hotline and retail stores in similar volumes. High-risk swaps cluster in lost- and stolen-phone claims. Account takeover after a SIM swap dominates the case list, followed by IMEI sharing, SIM-box and Wangiri patterns.
A policy matrix your risk team owns, measured on losses avoided, false positives and customer friction, with every exception worked as a case in the SENTINEL command centre.
Risky swaps and account changes are challenged or held before money moves, instead of being found in next week's report.
One explainable score lets you step up verification only where the risk is, rather than adding friction for everyone.
Analysts receive the signals, score and recommended control together, and every decision is on the record.
Want a number for your own network? Our value calculator estimates fraud losses avoided from your own assumptions.
Most operators start with SIM-swap scoring on one channel, then add patterns and channels.
Map fraud types, channels, current rules and the decisions you want to automate; agree risk appetite.
1-2 weeksConnect SIM-swap, CDR and subscriber feeds; tune scoring on your history; run in shadow mode, then live.
30-45 daysAdd SIM box, Wangiri and device patterns; connect wallet and self-care channels for step-up authorisation.
SprintsModel monitoring, retraining and AgentOps under agreed SLAs through Managed Services.
Managed serviceTell us which fraud pattern costs you most. We'll propose a 30-45 day pilot on your data.