This podcast episode details how a major payments processor successfully repurposed its internal fraud and anti-money laundering (AML) infrastructure, named "Framble," from a defensive cost center into a profitable product. Facing immense scale with 60 million monthly transactions, the company's legacy systems were slow, siloed, and unable to keep pace with modern threats or regulatory demands. The transformation centered on building a unified, real-time platform that consolidated fraud and AML operations. This platform incorporated no-code/low-code tools for rapid rule updates by analysts and ensemble machine learning for superior detection accuracy. The critical strategic element was designing the system with multi-tenancy architecture from the start. This allowed the company to securely host dozens of external clients on the same core infrastructure, turning its risk management expertise into a white-labeled, scalable service. The outcomes were significant: a 35% drop in fraud losses, a 98% acceleration in deploying new countermeasures, a quadrupling of operational capacity, and the ability to onboard new revenue-generating clients in less than 24 hours. The case study illustrates how necessary internal compliance and security investments can be engineered into a core, differentiated business advantage and a new revenue stream.
[MUSIC PLAYING] Welcome to What the F Happened, Fraud and Financial Crime Deconstructed, a defend podcast where we break down what's actually happening across Fraud, Scams, AML, and Financial Crime. Each episode cuts through the noise to explain the tactics, trends, and real world impact behind the headlines. So you're better prepared for what comes next. Let's get into it. So if you've ever had to manage a budget, you know this pain point we're diving into today. The whole risk management department, security, fraud, compliance is usually just seen as this massive, necessary cost center. You're spending millions just to stop bad things from happening. Right. It's purely defensive. Exactly. But our sources today, they tell this fascinating story about a leading payments processor that just completely flipped that script. Oh, completely. They took their internal risk infrastructure, specifically for Fraud and AML, they call it Framble, and they transformed it from this operational drain into a strategic incremental revenue generator. Which is, I mean, that's the Holy Grail, right? It really is. So we're going to be unpacking the technical foundations that made this possible. We're talking unified systems, ensemble machine learning, and this really critical architecture decision called multi-tenancy. That's the key. It is. Our mission for you, the listener, is to walk away understanding not just how to tighten security, but how that security can be engineered to become a high-value product you can actually sell. And you have to establish the scale here right away, because the complexity of the challenge, I mean, it's what dictated this whole radical transformation. We're talking huge volumes. Huge. We're talking about a leading merchant, a choir, a payment processor handling, just immense volume. Our sources say, oh, with 60 million transactions every single month. Wow. Yeah. And that's for an ecosystem of more than 2,500 clients, think major retailers, downstream fintechs, financial institutions. So in that world, the margins are tiny. Razor thin. You're operating in this low-margin environment where protecting your existing revenue from fraud, while simultaneously controlling your operating costs, that's the central tension of the business. You can't afford delays. You simply can't. The pressure to get the risk decision right in milliseconds every single time, it's just immense. That environment, it just sets the stage perfectly. But what was the tipping point? What forced them away from the comfort of their established homegrown system? Well, the starting problem was classic. They were relying on these legacy in-house fraud systems. Kind of everyone builds it first. Exactly. And as their customer base and their transaction volume just exploded, the old system, it just couldn't evolve fast enough to keep pace with modern sophisticated attacks. It was an operational bottleneck, and it was threatening their growth. So when a new fraud pattern emerged, their response was delayed, and their customers, the merchants, they were the ones feeling the heat. It led to complaints to operational pressure for faster solutions. This wasn't just about losing money. No, it's about losing trust. Exactly. Losing customer trust and hindering future acquisitions. And the company's leadership, they summarizes so perfectly in the source material. They said, and I'm quoting here, we needed a single platform that could handle fraud and Ambell decisions in real time at massive scale. Real time. That's the key phrase. It is. And they add, we started to see the decrease in fraud exposure from month one. So that quote, it just perfectly frames the goal, unified control, high speed, immediate impact. Right. But what I find most insightful is that they didn't just see a problem to fix. They saw an asset to sell. Yes. That's the strategic leap. Well, they recognize the defensive necessity, you know, stop the bleeding. But they also saw the commercial opportunity. If we're going to build this amazing thing, let's package it up. Risk would stop being purely a cost center and start becoming a profitable service they could offer their vast client base. OK, so let's unpack the specific issues. The things that made their old system just unsustainable and kept that revenue opportunity locked away. Because it wasn't just one thing. No, there were four core roadblocks threatening their entire roadmap. And we can kind of group them. We can. You can group them into two internal operational issues and two external sort of commercial and technical demands. On the internal side, the first big one was just their limited agility. Meaning what, exactly? Well, their existing fraud and AML stacks were siloed. They were often separate systems running different databases. And that made it exceptionally difficult for their risk teams to keep pace with new threats. So think about what that means in practice. Yeah, think about the practical impact. A fraudster finds a new weakness, say, exploiting gift card reloads or something with cross-border transactions. It required heavy time-consuming engineering work just to update the rules. You're talking weeks, not hours. Exactly. The time from identifying the threat to deploying the countermeasure was measure in weeks. That's just far too slow. And then compounding that problem was the second internal issue, which was this rising compliance and audit pressure. Yes. As they grew, the regulatory scrutiny grew exponentially. It always does. The pressure for fully-auditable transparent processes to reduce regulatory exposure was constant. And their legacy homegrown system it just didn't provide that granular level of transparency and reporting that regulators demand. So it created a huge amount of work for the compliance team. An enormous operational overhead. And that's a great distinction to make. Compliance is about meeting the rules. Audit pressure is about proving you met the rules. Reliably transparently over time. Their system made that second part extremely difficult. And the other two points, they really hammer home the technical and the commercial pain. They do. So on the technical front, they had the serious real-time high throughput requirements. It's 60 million transactions a month and growing. You need a decisioning engine that can scale with ultra low latency. And if you can't make a complex fraud decision in the blink of an eye, we're talking under 100 milliseconds, you either halt the transaction, which creates friction for the customer. Or you let the fraud pass through. And neither of those is sustainable at that scale. Right. And that technical demand was directly linked to the commercial failure. The fourth roadblock was this massive missed opportunity, no merchant-facing framel offering. They had all this knowledge. Deep proprietary knowledge about risk. But because their internal system was messy and just wasn't built for external use, they had no way to package it and sell it to their clients. It just constrained their ability to launch a whole new high-version revenue stream. That final point is so key for you, the listener, I think, no matter your industry. If you have to invest heavily in security or compliance just to run your business, you have to ask yourself, are we sitting on a strategic asset? We aren't selling. That's the question. This payments process or recognize that risk management itself could be repurposed and sold as a product. And what's so fascinating is that the solution they chose is this unified platform. It was designed to address all four challenges at once by fundamentally transforming the system's architecture. So where did they start? The first essential step was consolidating fraud and AML into a single unified end-to-end real-time platform. Which historically were two different worlds. Totally different silos. Fraud looks backward at a transaction. AML looks forward at suspicious activity. Bringing them together instantly centralized workflows reduced operational complexity and just eliminated all that data fragmentation. And that unification. That's what set the stage for solving that limited agility problem you mentioned. It did. They got immediate operational speed by adopting a no-code or low-code strategy development approach within this new platform. Think about the internal power shift there. It's huge. The risk teams, the fraud analysts, who live and breathe this stuff, they could suddenly deploy and update rules, logic, and models rapidly. Right, often with just a simple drag and drop interface, and this is the key, without heavy dependence on core engineering teams to write and deploy a production code. It fundamentally changed the speed of response. From weeks to hours, it directly addressed that slowness roadblock. And to handle the sheer sophistication of modern threats, they also integrated advanced detection methods. They moved way beyond simple rules. This is where the machine learning comes in. Exactly. They adopted what's called ensemble machine learning. OK, so in simple terms, what does that mean? It's about running specialized models that all kind of debate the risk at the same time. They combined supervised learning, which finds patterns based on historical fraud data, with unsupervised learning, which is designed to spot anomalies and brand new zero-day attacks the system has never seen. Like a committee of detectives. A committee of specialized detectives, yes. And by running them all at once, they achieved significantly higher accuracy and far fewer false positives. It dramatically improved their proactive detection. OK, so they built a faster, smarter, more unified, internal defense system. That covers three of the roadblocks. But here's where it gets really strategic. The revenue engine? The revenue engine. The technical architecture that turned this internal solution into a product they could sell. And that was the built-in multi-tenancy. This is the game changer. Explain what that means. Multi-tenancy just means the platform was designed from day one to securely and independently host dozens or hundreds of different clients or tenants, all sharing the core computing infrastructure, but with their data and configurations strictly isolated. So it's like a secure high-rise apartment building. That's a perfect analogy. Every merchant gets their own completely locked down unit. They have customized policies, rules, data storage. But they all share the foundation, the elevators,
the maintenance crew, in this case the core processing engine, the ML models, the infrastructure. Why is that so critical? Because maintaining one massive shared system is vastly cheaper and easier than deploying say 40 separate custom single tenant installations. This built-in efficiency is what allowed them to easily package and resell these framel services to their clients. As a white labeled value added offering. Exactly. They solved the commercial roadblock by making the underlying technology inherently monetize a ball. So, essentially they took their decade of experience fighting fraud, wrapped it in this secure scalable tech shell, and then started selling access to it at a profit because their cost to deploy for each new customer was so low. That's the business model. Let's look at the numbers now because the sources show the impact was immediate and tangible. This shift from a slow reactive posture to one built for speed, it generated results that just validated the entire investment. Well the first and most crucial result for any payments business was risk reduction. They achieved a massive 35% reduction in fraud losses. 35%. In a low margin environment, that's millions of dollars. It translates directly into millions saved on their own book of business instantly. And at the same time, their internal agility that roadblock we talked about, it just skyrocketed. Bummage faster. Strategy updates and deploying new fraud countermeasures became 98% faster. 98%. So when a new threat emerges, they're deploying a fix instantly, not weeks later, they're dramatically cutting the window for exposure. And the operational efficiency gains are just as staggering. They achieved a four times operational capacity expansion. Which means the same risk team, the same headcount, was able to support this massive increase in volume and the sheer number of new customers buying the service. The Titan protection and controlled operating costs. At the same time. Simultaneously. Were the sources clear on how the engineering team handled that? I mean, supporting four times the capacity without hiring more people sounds like a huge lift. They attribute it directly to the unification by having a single centralized platform for both fraud and AML, all the administrative overhead, the maintenance, the data wrangling, it just dropped precipitously. So engineers weren't scrambling to patch separate systems? No, they were simply updating the core engine. It allowed the team to focus on strategic enhancements, not reactive maintenance. And that focus on efficiency, it translated directly into their scaling revenue. The real business story here is just how rapidly they monetized this internal capability using that multi-tenancy framework. The platform delivered an incredibly fast time to revenue. The sources confirmed that the new system enabled them to onboard new subtenants. That is, new paying clients in less than one day. Think about that. Less than a day. That implementation speed is just. It's the secret sauce for monetization. Low friction means fast adoption. If setting up a security service takes months, a client might bulk. If it takes less than a day, it's an easy upsell. And this capability allowed them to scale incredibly quickly. To over 40 subtenants in a short period, it just confirmed that the incremental revenue stream they envisioned wasn't just realized it was accelerating rapidly and sustainably. So if we synthesize the core lesson here. This case study really illustrates that centralizing risk intelligence, the unified framil system, the real time decision, the ensemble ML. That's the necessary technical foundation. But it's only half the battle. It's only half the battle. The strategic use of multi-tenancy is what truly unlocked the commercial potential. It allowed them to take an internal capability when they needed for compliance and safety and reposition it as a valuable, scalable, and profitable service. This is the achieved that dual goal. Exactly. Tightening internal protection while simultaneously creating this dynamic new stream of income by improving the customer experience. This platform, it fundamentally transformed risk management from being purely defensive, which is a constant cost strain, into a core, differentiated business advantage in a super competitive space. It really did. So here's our final provocative thought for you to mull over. Considering this payments platform successfully monetize an internal operational capability, where else in your own industry could a necessary internal cost center be repurposed. Right, think about it. Whether it's supply chain logistics optimization or advanced internal training programs, or maybe even your internal cybersecurity auditing capabilities. Could those be packaged, white labeled, and sold as a differentiated high margin service to generate revenue? Look at the internal investments you already make. And ask yourself how you might start selling the output of those investments. You've been listening to what the F happened, fraud and financial crime deconstructed, a defend podcast by DataVisor. If you want to keep learning between episodes, check out Defend Training. It's a set of self-paced online courses for fraud and financial crime professionals, practical and built around real world scenarios. And you can earn CPE credits through the ACFE San Francisco Bay Area chapter. You can find it at DataVisor Defend Training, the links in the description. This episode's audio was generated using Google's Notebook LM based on expert analysis and trusted sources. Thanks for listening. We'll see you next time.
Podcast Summary
Key Points:
A leading payments processor transformed its internal fraud and AML risk management system from a cost center into a strategic, revenue-generating product.
The transformation addressed four core challenges
The solution involved building a unified, real-time platform with no-code/low-code tools and ensemble machine learning for faster, more accurate detection.
A key architectural decision was multi-tenancy, allowing the secure, efficient hosting of multiple clients on shared infrastructure, enabling rapid, low-cost deployment as a sellable service.
Results included a 35% reduction in fraud losses, 98% faster deployment of countermeasures, 4x operational capacity expansion, and the ability to onboard new paying clients in under a day.
Summary:
This podcast episode details how a major payments processor successfully repurposed its internal fraud and anti-money laundering (AML) infrastructure, named "Framble," from a defensive cost center into a profitable product. Facing immense scale with 60 million monthly transactions, the company's legacy systems were slow, siloed, and unable to keep pace with modern threats or regulatory demands. The transformation centered on building a unified, real-time platform that consolidated fraud and AML operations.
This platform incorporated no-code/low-code tools for rapid rule updates by analysts and ensemble machine learning for superior detection accuracy. The critical strategic element was designing the system with multi-tenancy architecture from the start. This allowed the company to securely host dozens of external clients on the same core infrastructure, turning its risk management expertise into a white-labeled, scalable service.
The outcomes were significant: a 35% drop in fraud losses, a 98% acceleration in deploying new countermeasures, a quadrupling of operational capacity, and the ability to onboard new revenue-generating clients in less than 24 hours. The case study illustrates how necessary internal compliance and security investments can be engineered into a core, differentiated business advantage and a new revenue stream.
FAQs
Risk management is often viewed as a massive cost center focused purely on defensive measures, spending millions to prevent fraud and financial crime without generating revenue.
They repackaged their internal fraud and AML system, called Framble, into a scalable product using multi-tenancy architecture, allowing them to sell it as a white-labeled service to clients.
The legacy system had siloed fraud and AML stacks, slow response times to new threats, and couldn't handle real-time decisions at scale, leading to operational bottlenecks and missed opportunities.
Multi-tenancy is an architecture that securely hosts multiple clients on shared infrastructure while isolating their data. It enabled low-cost, rapid deployment of the risk service as a profitable offering.
They saw a 35% reduction in fraud losses, 98% faster deployment of countermeasures, and scaled to over 40 paying clients with onboarding in less than a day, boosting operational efficiency and revenue.
By adopting a no-code/low-code approach and unified systems, risk teams could update rules and models in hours instead of weeks, drastically cutting response time to emerging threats.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.