Customer 360 & Real-Time Risk Intelligence Platform  ·  View 11 of 20

Real-Time Risk Enrichment

How a trigger event is joined with profile and feature context, scored against declarative rules, published for the risk domain, and fed back as labelled outcomes.

Editable source SVG draw.io All views
Trigger
Trigger
Card Authorisation
ISO 8583 event
Card Authorisation...
Digital Login
Device, IP, geo
Digital Login...
Payment Initiation
Payment Initiation
Context lookup
Context lookup
Customer Profile
Gold, cached
Customer Profile...
Online Features
Velocity, ratios
Online Features...
Watchlist & Sanctions
Refreshed daily
Watchlist & Sanctions...
Stream enrichment
Stream enrichment
Stateful Join
Flink keyed state
Stateful Join...
Derive Signals
Deviation, novelty
Derive Signals...
Risk Rules
Declarative, versioned
Risk Rules...
Publish
Publish
Enriched Event Topic
Contract v2
Enriched Event Topic...
Decision Audit Log
Immutable, bronze
Decision Audit Log...
Decisioning
Decisioning
Fraud Model Service
Owned by risk
Fraud Model Service...
AML Scenario Engine
AML Scenario Engine
Case Management
Case Management
Outcome
Outcome
Block or Challenge
Step-up auth
Block or Challenge...
Analyst Alert
Analyst Alert
Outcome Feedback
Back to features
Outcome Feedback...
scored
scored
consume
consume
label loop
label loop
every decision
every decision
Real-Time Risk Enrichment and Decision Path
Real-Time Risk Enrichment and Decision Path
External / third party
External / third party
Data store
Data store
Application we own
Application we own
Decision point
Decision point
Queue / topic
Queue / topic
event / async
event / async
synchronous
synchronous
The platform enriches and publishes; scoring and case handling stay owned by the risk domain.
The platform enriches and publishes; scoring and case handling stay owned by the risk domain.
v 1.0 · owner Risk Data Engineering · date 2026-08
v 1.0 · owner Risk Data Engineering · date 2026-08
Text is not SVG - cannot display

Responsibility split

  • The platform enriches and publishes; it does not decide
  • Fraud models, AML scenarios and case handling remain owned by risk
  • This keeps model governance where the regulator expects to find it

Latency budget

  • Event to enriched topic: 2 seconds at p99, measured end to end
  • Profile and feature lookups served from a low-latency store, not the lake
  • Stateful joins use Flink keyed state to avoid a remote call per event

Auditability

  • Every enrichment decision writes an immutable audit record to bronze
  • Rule versions are recorded with each decision, so past outcomes are explainable
  • Outcome feedback closes the loop into features without leaking model logic upstream