The Intelligence Layer

Beyond rules:
risk that thinks

Machine learning that learns your business, and an AI investigator that explains the risk in plain English — with a person always making the final call.

Risk Console Portfolio View
42
Live

Events today

128,402

Flagged

312

False positives

4.1%

Auto-cleared

96.8%

Risk score by channel — last 24h

Field Digital Partner

Flagged events by pre-built model

Banking
Finance
Inst.
Micro-
finance
Insurance
FMCG

Anomaly density — last 24h

1am

AI Investigator assembling evidence for Agent #4021…

Agent #4021 — disbursement gap

Flagged 2 min ago · Micro-finance

High

Vendor "Alta Supplies" — split PO pattern

Flagged 11 min ago · FMCG

Medium

Claim #88213 — provider billing outlier

Cleared by AI · Insurance

Cleared

Illustrative console — not live customer data.

Scroll

What True North Offers

It combines real-time fraud detection, fraud analytics, machine learning, data enrichment, orchestration and decisioning, model management and governance, alert triage and case management, dashboards and reporting, and prebuilt fraud models — on one cloud-native platform for enterprise fraud management.

Real-Time Detection Fraud Analytics Machine Learning Data Enrichment Orchestration & Decisioning Model Governance Case Management Dashboards & Reporting Prebuilt Fraud Models

3 layers

Rules, machine learning and an AI investigator, working on every single event.

4 industries

Pre-built Knowledge Packs — micro-finance, procurement, insurance, banking.

100% reviewed

Every recommendation goes to a person. It cannot act on its own.

Key Features

Everything the engine ships with

Enterprise-ready from day one — no assembly required.

Pre-built Fraud Models

Production-ready models trained for your industry, cutting implementation time from months to weeks — no data science team required.

Military-Grade Security

Encryption at rest and in transit on hardened infrastructure, tested continuously against real attack patterns.

Role-Based Access Control

Investigators, approvers and auditors each see exactly what their role allows — nothing more.

Advanced AI Threat Detection

A multi-layer AI agent reasons about intent instead of just matching static rules — surfacing emerging fraud threats and hidden patterns with 24/7 automated coverage.

Analytics Engine

Live dashboards and a plain-English query interface turn every event into an answerable question.

Single Sign-On

Sign in once through your existing identity provider — SAML and OAuth supported out of the box.

Real-Time Decisioning

Score, triage and recommend a decision in milliseconds on a cloud-native platform built to scale with your transaction volume — every event, as it happens, not on a batch cycle.

Flexible Data Orchestration

Bring in transaction, customer, account and third-party data regardless of source or format — the context every model needs, unified before it reaches a decision.

Strategy Testing & Optimization

Compare rules, models and thresholds against history before you deploy — know exactly what a change would have caught, and what it would have missed.

Pre-Built Risk Models

Pre-built for your industry

Five Knowledge Packs, already trained — deploy the one that matches your business today.

Ready to deploy

Banking

Account takeover, mule networks and card-not-present fraud, checked in real time.

Ready to deploy

Financial Institutes

Cross-product exposure and portfolio-level risk across NBFCs and leasing books.

Ready to deploy

Micro Finance

Loan stacking, agent auditing and group-network analysis, built for the field.

Ready to deploy

Insurance

Staged claims, provider billing outliers and application risk, caught before payout.

Ready to deploy

FMCG

Distributor fraud, trade-promotion abuse and leakage across the supply chain.

Use Cases

Where True North catches what rules miss

Real scenarios across the Knowledge Packs — the same engine, applied to your business.

Detect payment fraud from social engineering scams

Monitor payments and disbursements in real time to catch scam-driven transfers before funds leave the account.

Uncover mule networks and shared-identity fraud

Surface shared phones, devices and guarantors linking accounts that look unrelated on paper.

Catch loan stacking before it compounds

Flag borrowers drawing from several lenders at once, before any single lender can see the full picture.

Prevent agent and disbursement fraud in the field

Close the gap between the amount approved and the amount that actually reaches the customer.

Stop application fraud at onboarding

Flag synthetic identities and inconsistent history before a policy or account is opened.

Catch staged claims and provider billing fraud

Identify claim patterns and provider billing outliers consistent with a staged loss — before payout.

Detect distributor and trade-promotion fraud

Catch leakage across the FMCG supply chain — distributor fraud, rebate abuse and invoice manipulation.

Surface emerging fraud schemes earlier

Machine learning flags what doesn't fit your baseline — including patterns nobody has written a rule for yet.

The Limits of Rules

Rules only catch what you already knew to look for

Every rule-based control shares the same three limits.

Always one step behind

A new scheme is invisible until somebody writes a rule for it — and that usually happens after the first loss.

No sense of context

Rules check a number against a threshold. They cannot ask whether this vendor, this month, from this account, makes sense.

Catch more, drown more

Lowering thresholds to catch more fraud buries the team in false alarms — false positives that cost real analyst hours.

"Organizations with strong controls still lose money — because the controls were written for last year's fraud."

The Triple-Layer Solution

Three layers, working on every event

Each layer asks a different question.

1

Rules

Did this break a policy?

2

Machine Learning

Is this unusual?

3

AI Investigator

What is actually going on?

Layer 01 — Rules Sub-millisecond

"Checks known patterns instantly, on every single event."

Fast, cheap and completely predictable. Rules test every transaction against your lending, payment and procurement policy the instant it happens — a deterministic, versioned ruleset written in C++ for heavy load, sub-millisecond processing.

Continuously re-modeled from human decisions — not hand-edited by an engineer months after the fact.

Layer 02 — Machine Learning 60–70% fewer false positives

"Learns what normal looks like for your business — not an industry average."

Learns your baseline from 12–24 months of history — seasonality, growth and quiet periods, with no threshold set by hand.

Compares like with like — a rural field agent judged against rural peers, not a national average.

Notices behaviour changing — a shifting repayment rhythm, surfaced before the loss lands.

Sees hidden connections — shared phones, guarantors and accounts linking people who look unrelated.

Layer 03 — AI Investigator 80% faster investigation

"Gathers evidence and explains the risk, before a person opens the case."

Gathers the history — the customer, the counterparty, and how similar cases resolved before.

Checks the playbook — policies, procedures and known fraud patterns, on demand.

Assembles the case — a one-page explanation where every statement links to its record.

Recommends, never acts — allow, step up authentication, or block. A person decides.

Layer 1 of 3
See it on your own data →

Rules and ML run on everything. The AI investigates only the small flagged share — which is what keeps it affordable to run.

Inside the Risk Engine

The orchestrator at the heart of every decision

A deterministic core, a machine learning plug-in, and an agentic AI investigator — working together, with a human always closing the loop.

The Heart / Orchestrator Written in C++

Rule Engine

Deterministic, versioned rulesets that make the pass/fail call on every event — continuously re-modeled from human decisions, not hand-edited by an engineer months after the fact.

Why C++

Sub-millisecond

Heavy load, processed in real time.

Stable under load

Resilient through sustained peak traffic.

Hardened posture

Immune to common OS-level vulnerabilities.

Close to hardware

Runs natively, not layered on top.

Machine Learning · Plug-in

Bidirectional signal exchange

  • Pattern recognition across every event

  • Cluster identification across accounts and agents

  • Layered risk & behavioral scoring

Agentic AI · Investigator

Acts autonomously, decides nothing

Designed to reason toward a goal — requesting tools, reflecting on outcomes, and adapting — then requests new connectors and re-models the Rule Engine based on what it learns.

For every high-risk block, it produces a plain-English rationale — the reasoning an analyst would otherwise reconstruct by hand.

Human-in-the-loop

1

Activate Workflow

Triggered the moment the agent flags a high-risk block, with its rationale attached.

2

Human Interface

A dashboard presents the rationale for the block, spelled out in plain English.

3

Release or Confirm

The reviewer releases the transaction or confirms the block — a reason recorded either way.

The Feedback Loop

Release and Confirm decisions both flow back into the Rule Engine — closing the loop. Every human decision re-models it over time, so the system gets sharper with every case an analyst resolves, without ever letting the model decide unsupervised.

The Revolutionary Capability

Ask the system, in plain English

Analysts explore risk by asking — no query language, no report requests required.

Your analyst asks

Which field agents disbursed less than the approved amount last quarter?
Show me borrowers with active loans at more than one lender.
Why was this case flagged, and what evidence supports it?
How often does this rule turn out to be a false alarm?
1

Shows its working

Every answer arrives with the query it ran, and links through to the underlying records.

2

States what it assumed

Date ranges, filters and exclusions are declared openly — never chosen silently behind the answer.

3

Turns a question into a control

Found a pattern worth watching? Turn it into a standing rule, tested against history, with one click.

The same interface answers questions about a single case, about the whole portfolio, and about how well the system itself is performing.

The Core Architecture

One engine. Every industry.

The core shared engine stays identical for every customer. The territory is mapped by an Industry Pack — pure knowledge, not software.

Risk in the field looks nothing like risk in a branch: cash changes hands away from any office control, borrowers are often invisible to credit bureaus, and the same agent originates, disburses and collects.

Loan stacking

Borrowing from several lenders at once, before any of them can see the others.

Agent auditing

Gaps between the amount approved and the amount that reaches the borrower.

Behaviour analysis

Repayment rhythm shifting well before an account is formally in arrears.

Group & network

Shared phones, guarantors and collateral linking borrowers who appear unrelated.

Procurement risk hides in the gap between what a policy allows and what a purchase order actually does.

Vendor risk

Shell suppliers, shared bank details and duplicate registrations across your vendor master.

Split purchasing

Orders broken into smaller amounts to stay under an approval threshold.

Bid rigging

Patterns across tenders that suggest bidders are not competing independently.

Invoice anomalies

Pricing, quantities or terms that drift from the matching purchase order.

Claims fraud rarely announces itself in a single field — it shows up in how a claim relates to everything around it.

Staged incidents

Claim patterns and participant networks consistent with a staged loss.

Provider billing

Repair shops and clinics whose billing sits outside the norm for the same procedure.

Application risk

Undisclosed history or inconsistencies surfaced before a policy is bound.

Claimant networks

Repeat claimants, witnesses and providers appearing together across unrelated claims.

Banking risk moves at the speed of a real-time payment rail — detection has to keep pace.

Account takeover

Login and device behaviour that breaks from a customer's established pattern.

Mule networks

Accounts that receive and rapidly move funds on behalf of someone else.

Card-not-present

Transaction context checked, not just card number and amount.

Transaction laundering

Merchant activity inconsistent with the business it claims to be.

The shared engine — identical for every customer

Rules
Machine learning
Triage
AI investigator
Evidence & audit
Review workflow
Controls & approvals
Testing

A pack is knowledge, not software: what an event looks like in that industry, what counts as risky, the investigation playbook and the vocabulary. Adding an industry means writing a new pack — not building a new product.

Every improvement to the engine reaches every customer, in every industry, at the same time.

Micro-finance, Step by Step

From a field agent's disbursement to a decision

1

Capture

Reads the event from your systems as it happens.

2

Score

Rules and machine learning run on every event.

3

Triage

Routine activity clears; the rest is escalated.

4

Investigate

The AI gathers evidence and drafts the case.

5

Decide

A person chooses: Allow, Step-up MFA, or Block.

Allow — cleared and logged

Nothing is interrupted. The reasoning stays on record if anyone asks later.

Step-up MFA

One more factor requested, rather than turning a genuine customer away.

Block — stopped and escalated

Held, with the evidence pack already assembled for whoever handles it next.

Elapsed: minutes. Human effort: one decision, already evidenced. The system recommends — it cannot move money or change its own rules.

Security & Governance

Built to close the gap agentic AI opens

Agentic AI introduces new attack surface. True North is built to close it from day one — not bolted on after a breach.

Audit Trail

Immutable by design

Every decision, override and model version is logged to write-once storage for regulatory review.

Access Control

Least-privilege by default

Role-based access scoped per function — no standing admin credentials on production data.

LLM Guardrails

PII masked before reasoning

Sensitive fields are masked before they ever reach the model's context window.

Adversarial Testing

Injection-hardened

The agent is evaluated against adversarial and prompt-injection cases before every release.

Four-Eyes Review

No single point of failure

High-risk blocks and overrides require a second reviewer before they take effect.

SLA Escalation

Nothing sits unattended

Unactioned high-risk cases automatically escalate within a defined time window.

Security and governance aren't a checklist bolted on at the end — they're load-bearing in how the agent is designed to act.

Compliance-Ready

Built to a recognized standard

True North's detection and response engine maps directly to NIST CSF 2.0 — with the deepest investment in Detect and Respond, where automated risk decisions actually happen.

Govern · GV

Risk appetite, policy and oversight set the operating envelope.

Identify · ID

Baselines assets, vendors and behaviour across every connected system.

Protect · PR

Access control, encryption and safeguards on every data path.

Detect · DE

Ensemble ML and agentic AI score and investigate every event in real time.

Respond · RS

Human-in-the-loop workflow releases, blocks and retrains the engine.

Recover · RC

Structured incident reporting and clean-state validation.

True North invests deepest where automated decisions actually happen — Detect and Respond — while still covering the full NIST CSF 2.0 lifecycle, end to end.

The Competitive Moat

Five things almost nobody else does

Where we are genuinely different, not merely current.

It improves its own detection

It reviews what your team overrode and proposes better rules, showing what each change would have caught. You approve — it never changes itself.

It is built for adversaries

Fraudsters write the text our AI reads. We treat every invoice note and payment reference as hostile, and test that defence continuously.

Every decision is reproducible

Years later we can show which rules, which model and which settings produced a decision. Most AI systems cannot answer that.

It earns its autonomy

As it proves it agrees with your analysts, it proposes handling more cases alone. Trust is measured and granted, never assumed.

It's engineered for speed, not just accuracy

The deterministic core is written in C++ — sub-millisecond processing under sustained load, immune to common OS-level vulnerabilities. Most AI risk tools bolt detection onto a general-purpose stack; ours is built close to the hardware from day one.

30 days

To go live, vs. 12–18 months for legacy enterprise tools.

80%

Of maximum detection accuracy from day one, on pre-trained models.

60–70%

Fewer false positives than static, rule-only systems.

Company

Unified risk intelligence across industries

True North builds one shared risk engine and adapts it to your industry with a pre-built Knowledge Pack — not a separate product for every vertical. That means every customer, in every industry, benefits from the same engine improvements at the same time.

Capability of this kind has, until now, been available only in enterprise-scale platforms carrying enterprise-scale cost. We built True North to change that.

1

Shared engine, identical for every customer

4

Industry Knowledge Packs, live today

3

Layers working on every single event

0

Decisions made without a person reviewing

Proudly Australian

Built and based in Sydney

True North is an Australian company, headquartered in Sydney — engineering, product and customer teams working from home turf.

True North Headquarters

359 Prince Street, Sydney, Australia

Map of Australia marking True North's headquarters in Sydney Sydney (HQ)

Rules tell you what you already knew. This tells you what you did not.

Fewer false alarms

Analysts spend the day on real risk, not noise.

Catches new schemes

Not only the frauds someone already wrote a rule for.

New packs in weeks

A new industry is a pack, not a product build.

Audit-ready by design

Evidence and reproducibility, built in from day one.

Request a demo

Tell us about your risk surface — we'll show you the engine against your own industry.

True North

Headquarters

True North Headquarters
359 Prince Street
Sydney, Australia

General & Careers

info@truennorth.com careers@truennorth.com

Sales

+61 449 787 478

© 2026 True North. Unified risk intelligence across industries.