Autonomous Risk & Fraud Intelligence Agents
Build autonomous fraud, AML & risk-intelligence agents
This practitioner course equips participants to design, build, and deploy autonomous agents for real-time fraud detection, credit risk assessment, AML surveillance, and regulatory stress testing. Participants work with production-grade tooling including streaming data pipelines, graph neural networks, and explainable AI techniques within a regulatory compliance framework.
Learning objectives
- 01Architect real-time transaction monitoring agents using streaming data platforms
- 02Build and deploy credit risk agents with automated underwriting logic
- 03Design AML surveillance agents for SAR generation and case triage
- 04Implement explainable AI outputs that satisfy regulatory examination requirements
- 05Construct continuous feedback loops for agent performance improvement
15-module program
01FreeNext-Generation Fraud Detection: Agentic vs. Rule-Based Systems
Rule engines are not obsolete technology waiting to be replaced; they are deterministic controls a supervisor can read, and they will outlive several generations of models. This module separates what genuinely fails in rule-based detection from what merely looks dated, places the agent in the investigation layer rather than the authorisation path, and produces a placement map grounded in measured analyst time.
- 1.Why Rule Engines Persist, and the Three Places They Genuinely Fail10m
- 2.Detection, Investigation, Disposition: Placing the Agent Against 2026 Fraud Typologies10m
- 3.Lab: Building a Fraud Control Inventory and Agent Placement Map20m
02FreeReal-Time Transaction Monitoring Agents with Streaming Data
Streaming is a correctness model rather than a throughput problem, and most monitoring failures come from event-time confusion, duplicate events and silent divergence between offline and online features. This module derives the latency budget by subtraction from the scheme's response window, places the agent in the near-line tier where it belongs, and produces a feature and latency contract an engineering team can build from.
- 1.Event Time, Late Data and the Behavioural Profiles That Lie to You10m
- 2.Latency Budgets, Tiering, and Why Fail-Open Is a Board Decision10m
- 3.Lab: Writing the Streaming Monitoring Agent Specification25m
03FreeGraph Neural Networks + Agents for Syndicate Fraud Networks
Choosing what counts as a node and an edge determines what a fraud graph can ever reveal, and the published evidence for graph neural networks over strong tabular baselines is thinner than vendors suggest. This module works through directed multigraph structure, hub effects and camouflage, sets the boundary between model scoring and agent investigation, and produces a defensible case pack for a suspected network.
- 1.Nodes, Edges and Hubs: The Modelling Decisions That Decide What You Can Find10m
- 2.Bounded Traversal, Named Typologies and the Graph You Are Not Allowed to Build10m
- 3.Lab: Assembling a Syndicate Network Case Pack25m
04FreeCredit Risk Agents: Automated Underwriting & Dynamic Scoring
An underwriting agent answers to two control regimes at once: prudential rules that judge whether the loss estimate is right, and conduct rules that judge whether the applicant can find out why. This module keeps decision authority with the policy engine and the scorecard, separates score refresh from retraining, confronts the feedback and proxy problems in dynamic scoring, and produces an auditable decision record.
- 1.What an Underwriting Agent May Lawfully Decide15m
- 2.Dynamic Scoring, IFRS 9 Staging and the Feedback Loops Nobody Modelled10m
- 3.Lab: Producing the Underwriting Decision Record and Adverse Action Pack25m
05FreeAML Surveillance Agents: SAR Generation & Case Triage Automation
A suspicious transaction report is a legally consequential document, and the suspicion behind it is a state of mind the law assigns to a named officer rather than a threshold a system crosses. This module sets out what an agent may prepare, draft and propose under FATF Recommendation 20 and the UAE AML framework, how to triage an alert queue without quietly changing your regulatory position, and how to ground every narrative sentence in a record.
- 1.What an Agent May and May Not Do in Preparing a Suspicious Transaction Report15m
- 2.Alert Consolidation and Triage: Making the Queue Smaller Without Making It Blinder10m
- 3.Lab: Building a SAR Evidence Pack and Narrative Control Sheet25m
06PremiumKYC/KYB Orchestration Agents for Onboarding Automation
Onboarding is four different problems sharing one name: identity proofing, beneficial ownership, purpose and nature, and ongoing monitoring. This module works through what an orchestration agent can genuinely resolve under FATF Recommendations 10 and 24, UAE Cabinet Decision 109 of 2023 and the NIST identity assurance framework, and why screening adjudication should be the last thing you automate rather than the first.
- 1.Identity Proofing, Beneficial Ownership and the Real Onboarding Bottleneck10m
- 2.Screening Adjudication, UBO Unwinding and the Justification Trap15m
- 3.Lab: Building a KYB Onboarding Decision Record for a Layered Corporate Structure25m
07PremiumMarket Manipulation Detection using Multi-Modal Agents
Manipulation offences turn on purpose, and purpose is not a field in any dataset you own. This module works through what order books, communications and news can actually evidence under MAR, the DIFC Markets Law and the technical standards that already specify your surveillance architecture, and argues that agents belong in case assembly and alternative-explanation testing rather than in detection.
- 1.Manipulation Patterns, Intent, and What the Order Book Can Prove10m
- 2.Fusing Order Books, Communications and News Without Losing Defensibility10m
- 3.Lab: Assembling a Layering Investigation Package and STOR Decision Sheet25m
08PremiumStress Testing Agents: Automated Scenario Generation & Analysis
Every stress scenario must be simultaneously severe and plausible, and a language model can generate text that reads as either while verifying neither. This module sets the boundary between calibrated models and agent assistance under the Basel 2018 stress testing principles and the CBUAE capital adequacy guidance, and shows why reverse stress testing is the one place where an agentic search genuinely changes the work.
- 1.What the Basel Principles and CBUAE ICAAP Guidance Constrain15m
- 2.Calibrated Paths, Agentic Search and the Management Narrative10m
- 3.Lab: Building a Reverse Stress Test Scenario Register and Narrative Assurance Sheet25m
09PremiumRegulatory Reporting Agents: FATF, CBUAE & IFRS 9 Automation
Suspicion reporting, prudential returns and IFRS 9 disclosure share a deadline and nothing else. This module separates the three, sets out what CBUAE and FATF-derived obligations actually demand of a filing, shows where IFRS 9 judgement must stay with a named person, and produces a lineage register and tie-out harness that make an automated submission defensible.
- 1.Suspicion, Returns and Disclosure: Three Regimes, Three Failure Modes15m
- 2.IFRS 9 Expected Credit Loss: Staging, Overlays and the Limits of Automation10m
- 3.Lab: Building a Reporting Lineage Register and Tie-Out Harness25m
10PremiumOperational Risk Agents: Incident Detection, RCA & Escalation
Operational risk is a residual category, and most machine learning proposals in it are trained on the wrong timestamp. This module reframes detection around control failure signatures, is explicit that better detection raises capital under the Basel loss multiplier, and builds an incident brief and causal evidence pack that survives second line challenge rather than merely reading well.
- 1.Why Operational Risk Detection Is Not a Prediction Problem15m
- 2.Hypotheses, Not Causes: Designing an RCA and Escalation Agent10m
- 3.Lab: Producing an Incident Brief and Causal Evidence Pack for a Payment Failure20m
11CertificationExplainable AI for Risk Decisions: SHAP, LIME & Counterfactuals
SHAP, LIME and counterfactuals are precise tools that are routinely asked to do work they cannot do. This module is exact about what each computes, where its assumptions break on correlated credit data, and what separates a feature attribution from a legally sufficient reason — then builds a versioned explanation policy and a test pack that compliance can actually approve.
- 1.What SHAP and LIME Actually Compute, and Where the Assumptions Break15m
- 2.Counterfactual Recourse and the Legally Sufficient Reason15m
- 3.Lab: Writing a Decision Explanation Policy and Testing It on Declined Applications25m
12CertificationAgent Feedback Loops: Continuous Learning from Investigator Decisions
Investigator dispositions are decisions, not ground truth, and treating them as labels imports selective labelling, verification latency and self-confirming feedback into the model. This module is explicit about what can and cannot be learned in fraud and AML, and produces a feedback charter and a pre-approved retraining envelope that makes continuous improvement governable.
- 1.Why Investigator Labels Are Not Ground Truth10m
- 2.Designing the Loop: Disposition Capture, Active Learning and Adversarial Drift15m
- 3.Lab: Writing a Feedback Loop Charter and Retraining Envelope20m
13CertificationHuman-in-the-Loop Escalation Workflows for High-Risk Alerts
Escalation is where an autonomous risk agent meets accountability, and most designs treat it as a safety net rather than a designed control. This module separates the three reasons to involve a person, builds triggers that survive challenge, and specifies the handoff packet, reason codes and capacity arithmetic that decide whether human oversight is real or ceremonial.
- 1.Escalation Triggers, Calibration and the Capacity Nobody Models15m
- 2.The Handoff Packet: Designing for Cheap Disagreement10m
- 3.Lab: Building the Escalation Design Pack for a Card Fraud Agent25m
14CertificationPerformance Monitoring & Drift Detection for Risk AI Agents
A drift alarm is a hypothesis, not an incident, and a model can decay without any input distribution moving at all. This module separates statistical drift from performance degradation, works through what KS, PSI, ADWIN and classifier two-sample tests genuinely tell you, and builds a monitoring regime for an agentic fraud pipeline that now sits outside the scope of the supervisory guidance most banks cite.
- 1.Statistical Drift Is Not Performance Degradation15m
- 2.What Supervisors Expect Now That SR 11-7 Has Been Withdrawn15m
- 3.Lab: Writing the Monitoring and Drift Response Plan for a Fraud Agent25m
15CertificationCapstone: Build an End-to-End Fraud Investigation Agent Pipeline
Fourteen modules produced fourteen artefacts; this one turns them into a single document a financial crime committee could approve or refuse on the evidence. It connects detection, triage, investigation, escalation and monitoring into one pipeline, forces the seams between them into the open, and ends with a defence in front of people whose job is to find the gap.
- 1.Connecting the Pipeline: Where the Seams Leak10m
- 2.The Evidence File: Reconstructing One Case Under Challenge10m
- 3.Lab: Assembling the End-to-End Fraud Investigation Pipeline Dossier25m

