The Intelligence Layer
Beyond rules:
risk that thinks
Machine learning that learns your business, and an AI investigator that explains the risk in plain English — with a person always making the final call.
Events today
128,402
Flagged
312
False positives
4.1%
Auto-cleared
96.8%
Risk score by channel — last 24h
Flagged events by pre-built model
Inst.
finance
Anomaly density — last 24h
1amAI Investigator assembling evidence for Agent #4021…
Agent #4021 — disbursement gap
Flagged 2 min ago · Micro-finance
Vendor "Alta Supplies" — split PO pattern
Flagged 11 min ago · FMCG
Claim #88213 — provider billing outlier
Cleared by AI · Insurance
Illustrative console — not live customer data.
What True North Offers
It combines real-time fraud detection, fraud analytics, machine learning, data enrichment, orchestration and decisioning, model management and governance, alert triage and case management, dashboards and reporting, and prebuilt fraud models — on one cloud-native platform for enterprise fraud management.
3 layers
Rules, machine learning and an AI investigator, working on every single event.
4 industries
Pre-built Knowledge Packs — micro-finance, procurement, insurance, banking.
100% reviewed
Every recommendation goes to a person. It cannot act on its own.
Key Features
Everything the engine ships with
Enterprise-ready from day one — no assembly required.
Pre-built Fraud Models
Production-ready models trained for your industry, cutting implementation time from months to weeks — no data science team required.
Military-Grade Security
Encryption at rest and in transit on hardened infrastructure, tested continuously against real attack patterns.
Role-Based Access Control
Investigators, approvers and auditors each see exactly what their role allows — nothing more.
Advanced AI Threat Detection
A multi-layer AI agent reasons about intent instead of just matching static rules — surfacing emerging fraud threats and hidden patterns with 24/7 automated coverage.
Analytics Engine
Live dashboards and a plain-English query interface turn every event into an answerable question.
Single Sign-On
Sign in once through your existing identity provider — SAML and OAuth supported out of the box.
Real-Time Decisioning
Score, triage and recommend a decision in milliseconds on a cloud-native platform built to scale with your transaction volume — every event, as it happens, not on a batch cycle.
Flexible Data Orchestration
Bring in transaction, customer, account and third-party data regardless of source or format — the context every model needs, unified before it reaches a decision.
Strategy Testing & Optimization
Compare rules, models and thresholds against history before you deploy — know exactly what a change would have caught, and what it would have missed.
Pre-Built Risk Models
Pre-built for your industry
Five Knowledge Packs, already trained — deploy the one that matches your business today.
Banking
Account takeover, mule networks and card-not-present fraud, checked in real time.
Financial Institutes
Cross-product exposure and portfolio-level risk across NBFCs and leasing books.
Micro Finance
Loan stacking, agent auditing and group-network analysis, built for the field.
Insurance
Staged claims, provider billing outliers and application risk, caught before payout.
FMCG
Distributor fraud, trade-promotion abuse and leakage across the supply chain.
Use Cases
Where True North catches what rules miss
Real scenarios across the Knowledge Packs — the same engine, applied to your business.
Detect payment fraud from social engineering scams
Monitor payments and disbursements in real time to catch scam-driven transfers before funds leave the account.
Uncover mule networks and shared-identity fraud
Surface shared phones, devices and guarantors linking accounts that look unrelated on paper.
Catch loan stacking before it compounds
Flag borrowers drawing from several lenders at once, before any single lender can see the full picture.
Prevent agent and disbursement fraud in the field
Close the gap between the amount approved and the amount that actually reaches the customer.
Stop application fraud at onboarding
Flag synthetic identities and inconsistent history before a policy or account is opened.
Catch staged claims and provider billing fraud
Identify claim patterns and provider billing outliers consistent with a staged loss — before payout.
Detect distributor and trade-promotion fraud
Catch leakage across the FMCG supply chain — distributor fraud, rebate abuse and invoice manipulation.
Surface emerging fraud schemes earlier
Machine learning flags what doesn't fit your baseline — including patterns nobody has written a rule for yet.
The Limits of Rules
Rules only catch what you already knew to look for
Every rule-based control shares the same three limits.
Always one step behind
A new scheme is invisible until somebody writes a rule for it — and that usually happens after the first loss.
No sense of context
Rules check a number against a threshold. They cannot ask whether this vendor, this month, from this account, makes sense.
Catch more, drown more
Lowering thresholds to catch more fraud buries the team in false alarms — false positives that cost real analyst hours.
"Organizations with strong controls still lose money — because the controls were written for last year's fraud."
The Triple-Layer Solution
Three layers, working on every event
Each layer asks a different question.
Rules
Did this break a policy?
Machine Learning
Is this unusual?
AI Investigator
What is actually going on?
"Checks known patterns instantly, on every single event."
Fast, cheap and completely predictable. Rules test every transaction against your lending, payment and procurement policy the instant it happens — a deterministic, versioned ruleset written in C++ for heavy load, sub-millisecond processing.
Continuously re-modeled from human decisions — not hand-edited by an engineer months after the fact.
"Learns what normal looks like for your business — not an industry average."
Learns your baseline from 12–24 months of history — seasonality, growth and quiet periods, with no threshold set by hand.
Compares like with like — a rural field agent judged against rural peers, not a national average.
Notices behaviour changing — a shifting repayment rhythm, surfaced before the loss lands.
Sees hidden connections — shared phones, guarantors and accounts linking people who look unrelated.
"Gathers evidence and explains the risk, before a person opens the case."
Gathers the history — the customer, the counterparty, and how similar cases resolved before.
Checks the playbook — policies, procedures and known fraud patterns, on demand.
Assembles the case — a one-page explanation where every statement links to its record.
Recommends, never acts — allow, step up authentication, or block. A person decides.
Rules and ML run on everything. The AI investigates only the small flagged share — which is what keeps it affordable to run.
Inside the Risk Engine
The orchestrator at the heart of every decision
A deterministic core, a machine learning plug-in, and an agentic AI investigator — working together, with a human always closing the loop.
Rule Engine
Deterministic, versioned rulesets that make the pass/fail call on every event — continuously re-modeled from human decisions, not hand-edited by an engineer months after the fact.
Why C++
Sub-millisecond
Heavy load, processed in real time.
Stable under load
Resilient through sustained peak traffic.
Hardened posture
Immune to common OS-level vulnerabilities.
Close to hardware
Runs natively, not layered on top.
Bidirectional signal exchange
Pattern recognition across every event
Cluster identification across accounts and agents
Layered risk & behavioral scoring
Acts autonomously, decides nothing
Designed to reason toward a goal — requesting tools, reflecting on outcomes, and adapting — then requests new connectors and re-models the Rule Engine based on what it learns.
For every high-risk block, it produces a plain-English rationale — the reasoning an analyst would otherwise reconstruct by hand.
Human-in-the-loop
Activate Workflow
Triggered the moment the agent flags a high-risk block, with its rationale attached.
Human Interface
A dashboard presents the rationale for the block, spelled out in plain English.
Release or Confirm
The reviewer releases the transaction or confirms the block — a reason recorded either way.
The Feedback Loop
Release and Confirm decisions both flow back into the Rule Engine — closing the loop. Every human decision re-models it over time, so the system gets sharper with every case an analyst resolves, without ever letting the model decide unsupervised.
The Revolutionary Capability
Ask the system, in plain English
Analysts explore risk by asking — no query language, no report requests required.
Your analyst asks
Shows its working
Every answer arrives with the query it ran, and links through to the underlying records.
States what it assumed
Date ranges, filters and exclusions are declared openly — never chosen silently behind the answer.
Turns a question into a control
Found a pattern worth watching? Turn it into a standing rule, tested against history, with one click.
The same interface answers questions about a single case, about the whole portfolio, and about how well the system itself is performing.
The Core Architecture
One engine. Every industry.
The core shared engine stays identical for every customer. The territory is mapped by an Industry Pack — pure knowledge, not software.
Risk in the field looks nothing like risk in a branch: cash changes hands away from any office control, borrowers are often invisible to credit bureaus, and the same agent originates, disburses and collects.
Loan stacking
Borrowing from several lenders at once, before any of them can see the others.
Agent auditing
Gaps between the amount approved and the amount that reaches the borrower.
Behaviour analysis
Repayment rhythm shifting well before an account is formally in arrears.
Group & network
Shared phones, guarantors and collateral linking borrowers who appear unrelated.
Procurement risk hides in the gap between what a policy allows and what a purchase order actually does.
Vendor risk
Shell suppliers, shared bank details and duplicate registrations across your vendor master.
Split purchasing
Orders broken into smaller amounts to stay under an approval threshold.
Bid rigging
Patterns across tenders that suggest bidders are not competing independently.
Invoice anomalies
Pricing, quantities or terms that drift from the matching purchase order.
Claims fraud rarely announces itself in a single field — it shows up in how a claim relates to everything around it.
Staged incidents
Claim patterns and participant networks consistent with a staged loss.
Provider billing
Repair shops and clinics whose billing sits outside the norm for the same procedure.
Application risk
Undisclosed history or inconsistencies surfaced before a policy is bound.
Claimant networks
Repeat claimants, witnesses and providers appearing together across unrelated claims.
Banking risk moves at the speed of a real-time payment rail — detection has to keep pace.
Account takeover
Login and device behaviour that breaks from a customer's established pattern.
Mule networks
Accounts that receive and rapidly move funds on behalf of someone else.
Card-not-present
Transaction context checked, not just card number and amount.
Transaction laundering
Merchant activity inconsistent with the business it claims to be.
The shared engine — identical for every customer
A pack is knowledge, not software: what an event looks like in that industry, what counts as risky, the investigation playbook and the vocabulary. Adding an industry means writing a new pack — not building a new product.
Every improvement to the engine reaches every customer, in every industry, at the same time.
Micro-finance, Step by Step
From a field agent's disbursement to a decision
Capture
Reads the event from your systems as it happens.
Score
Rules and machine learning run on every event.
Triage
Routine activity clears; the rest is escalated.
Investigate
The AI gathers evidence and drafts the case.
Decide
A person chooses: Allow, Step-up MFA, or Block.
Allow — cleared and logged
Nothing is interrupted. The reasoning stays on record if anyone asks later.
Step-up MFA
One more factor requested, rather than turning a genuine customer away.
Block — stopped and escalated
Held, with the evidence pack already assembled for whoever handles it next.
Elapsed: minutes. Human effort: one decision, already evidenced. The system recommends — it cannot move money or change its own rules.
Security & Governance
Built to close the gap agentic AI opens
Agentic AI introduces new attack surface. True North is built to close it from day one — not bolted on after a breach.
Immutable by design
Every decision, override and model version is logged to write-once storage for regulatory review.
Least-privilege by default
Role-based access scoped per function — no standing admin credentials on production data.
PII masked before reasoning
Sensitive fields are masked before they ever reach the model's context window.
Injection-hardened
The agent is evaluated against adversarial and prompt-injection cases before every release.
No single point of failure
High-risk blocks and overrides require a second reviewer before they take effect.
Nothing sits unattended
Unactioned high-risk cases automatically escalate within a defined time window.
Security and governance aren't a checklist bolted on at the end — they're load-bearing in how the agent is designed to act.
Compliance-Ready
Built to a recognized standard
True North's detection and response engine maps directly to NIST CSF 2.0 — with the deepest investment in Detect and Respond, where automated risk decisions actually happen.
Risk appetite, policy and oversight set the operating envelope.
Baselines assets, vendors and behaviour across every connected system.
Access control, encryption and safeguards on every data path.
Ensemble ML and agentic AI score and investigate every event in real time.
Human-in-the-loop workflow releases, blocks and retrains the engine.
Structured incident reporting and clean-state validation.
True North invests deepest where automated decisions actually happen — Detect and Respond — while still covering the full NIST CSF 2.0 lifecycle, end to end.
The Competitive Moat
Five things almost nobody else does
Where we are genuinely different, not merely current.
It improves its own detection
It reviews what your team overrode and proposes better rules, showing what each change would have caught. You approve — it never changes itself.
It is built for adversaries
Fraudsters write the text our AI reads. We treat every invoice note and payment reference as hostile, and test that defence continuously.
Every decision is reproducible
Years later we can show which rules, which model and which settings produced a decision. Most AI systems cannot answer that.
It earns its autonomy
As it proves it agrees with your analysts, it proposes handling more cases alone. Trust is measured and granted, never assumed.
It's engineered for speed, not just accuracy
The deterministic core is written in C++ — sub-millisecond processing under sustained load, immune to common OS-level vulnerabilities. Most AI risk tools bolt detection onto a general-purpose stack; ours is built close to the hardware from day one.
30 days
To go live, vs. 12–18 months for legacy enterprise tools.
80%
Of maximum detection accuracy from day one, on pre-trained models.
60–70%
Fewer false positives than static, rule-only systems.
Company
Unified risk intelligence across industries
True North builds one shared risk engine and adapts it to your industry with a pre-built Knowledge Pack — not a separate product for every vertical. That means every customer, in every industry, benefits from the same engine improvements at the same time.
Capability of this kind has, until now, been available only in enterprise-scale platforms carrying enterprise-scale cost. We built True North to change that.
1
Shared engine, identical for every customer
4
Industry Knowledge Packs, live today
3
Layers working on every single event
0
Decisions made without a person reviewing
Proudly Australian
Built and based in Sydney
True North is an Australian company, headquartered in Sydney — engineering, product and customer teams working from home turf.
True North Headquarters
359 Prince Street, Sydney, Australia
Rules tell you what you already knew.
This tells you what you did not.
Fewer false alarms
Analysts spend the day on real risk, not noise.
Catches new schemes
Not only the frauds someone already wrote a rule for.
New packs in weeks
A new industry is a pack, not a product build.
Audit-ready by design
Evidence and reproducibility, built in from day one.
Request a demo
Tell us about your risk surface — we'll show you the engine against your own industry.
Headquarters
True North Headquarters359 Prince Street
Sydney, Australia
Sales
+61 449 787 478© 2026 True North. Unified risk intelligence across industries.