Machine-learning and deep-learning transaction fraud scoring
That handcrafted rules are the primary way to identify digital payment fraud.
Financial crime · Nordic banking operations
Executive brief
The operating-model shift, in one view.
The transformation metric is investigator yield, not model accuracy in isolation; a lower false-positive queue changes how scarce human judgment is allocated.
AI value · False-positive alerts and true-positive detection
Company-reported
Vendor case study reports 60% fewer false positives and 50% more true positives
Outcome figures originate from Danske executives and Teradata materials; independent Forbes reporting quotes the same executive, not a separate audit.
Before
Apply human-authored fraud rules to transactions. → Review up to 1,200 alerts per day, most of which are false positives.
After
Score millions of transactions in real time using learned patterns and latent features. → Investigate the smaller, higher-yield alert queue and decide customer or enforcement action.
Human boundary
The model prioritizes and scores; investigators determine whether activity is fraudulent and what action to take.
Why it matters
That handcrafted rules are the primary way to identify digital payment fraud.
This case is company-reported. Use it for the operating-model shift; do not treat the numbers as independently measured.
How the work changed
Before
How the work ran before the change.
Step 1 of 2
Rules engine
Apply human-authored fraud rules to transactions.
ControlStatic rule thresholds
Step 2 of 2
Fraud investigator
Review up to 1,200 alerts per day, most of which are false positives.
ControlHuman investigation
What changed
That handcrafted rules are the primary way to identify digital payment fraud.
Decision rightSelection moves from a fixed rule to the model
After
How the same work runs now.
Step 1 of 2
ML and deep-learning engine
Score millions of transactions in real time using learned patterns and latent features.
ControlSub-300ms scoring target
Step 2 of 2
Fraud investigator
Investigate the smaller, higher-yield alert queue and decide customer or enforcement action.
ControlHuman adverse-action authority
Process model built from the published workflow evidence for Danske Bank. Every step, actor, and control appears in full below.Every step, actor, and control
Exception path
Investigators review alerts, use model explanations, and escalate or clear cases; the public sources do not disclose automated blocking rights.
Decision authority
The model prioritizes and scores; investigators determine whether activity is fraudulent and what action to take.
Before
#
Actor
Action
Control
01
Rules engine
Apply human-authored fraud rules to transactions.
Static rule thresholds
02
Fraud investigator
Review up to 1,200 alerts per day, most of which are false positives.
Human investigation
After
#
Actor
Action
Control
01
ML and deep-learning engine
Score millions of transactions in real time using learned patterns and latent features.
Sub-300ms scoring target
02
Fraud investigator
Investigate the smaller, higher-yield alert queue and decide customer or enforcement action.
Human adverse-action authority
Work that left the path
A large share of false-positive alert review
Exclusive dependence on handcrafted fraud rules
Human role before
Investigators spent most capacity clearing rule-generated false positives.
Human role after
Investigators focus on higher-risk alerts, contribute domain knowledge to model development, and retain case decisions.
AI role
Real-time learned transaction-risk scoring that complements the existing rules engine.
Outcomes
False-positive alerts and true-positive detection
Company-reported
Up to 1,200 false positives per day; 99.5% of investigated cases not fraud; about 40% fraud detection→Vendor case study reports 60% fewer false positives and 50% more true positives
Initial 2017 production deployment · Millions of online banking transactions scored in real time
Outcome figures originate from Danske executives and Teradata materials; independent Forbes reporting quotes the same executive, not a separate audit.
What leaders can reuse
Anti-pattern
Automating account action from an opaque score or presenting vendor-reported uplift as independently audited.
Questions
01What is the residual false-negative risk?
02Which actions require human confirmation?
Portability conditions
Large labeled transaction history
Real-time scoring infrastructure
Human review before adverse customer action
Reputation risk
medium
Evidence and authority
What the public record supports.
Watch · updated
Watch status: verify the cited source and deployment condition before reusing this case.
1 independent, 1 vendor; publication outcomes are reported.
Bundle 1.0.0 · reviewed 2026-09-06 · stable ID a3327c8f8ced4e18