Skip to content
From the team · Page 7

Inside Toden.

Page 7

  • Product Updates

    Account takeover: step up the challenge instead of blocking the customer

    When a login looks like account takeover, do not guess. Let the session continue with limited rights, and ask for proof that only the verified person can give, such as a fresh selfie matched to their enrolment, before any payout, beneficiary change or password reset goes through.

  • Risk & Compliance

    Finding the same person behind many accounts

    Rank shared artefacts by what they prove. A repeated verified ID number means the same person. A repeated face is strong evidence for review. A shared device, phone or address is common in families, so treat it as corroboration and count distinct people before acting.

  • Risk & Compliance

    Preparing customer due diligence for the EU AML Regulation

    The EU AML Regulation applies directly from 10 July 2027 and replaces national CDD rules with one text. Build to the Regulation now: its data list, verification routes, 25% ownership test and refresh ceilings are fixed, while AMLA's detailed CDD standards were still in draft as of September 2026.

  • Risk & Compliance

    CBN's 2026 BVN framework changes: what onboarding teams should note

    From 1 May 2026, under a CBN circular dated 12 March 2026, only adults can enrol for a BVN, the linked phone number can change only once, banks must hold BVNs tied to suspicious transactions on a 24-hour watchlist, and database access is limited to licensed institutions.

  • Risk & Compliance

    CBN's baseline standards for automated AML: preparing your stack

    The CBN's baseline standards, issued on 10 March 2026, set mandatory minimum requirements for automated systems that detect, analyse and report suspicious activity in real time. The CBN has said compliance is assessed at the level of the institution, so buying a tool is a start, not an answer.

  • Risk & Compliance

    goAML explained: how reports reach financial intelligence units

    goAML is software built by the UN Office on Drugs and Crime for financial intelligence units. Reporting entities register on their FIU's goAML portal and submit reports by web form or as XML files that follow the goAML schema, using the FIU's own codes.

  • Risk & Compliance

    Writing a suspicious activity report an FIU can act on

    A useful SAR or STR narrative answers who, what, when, where, why and how in one chronological account, explains why the activity is unusual for this customer, and gives facts an analyst can follow without opening your systems.

  • Risk & Compliance

    Backtest before you switch on: testing monitoring rule changes safely

    Replay recent scored events through the proposed configuration, then read each decision that would change as well as the count. A backtest shows what a change would have done to the past; your written expectation is what tells you whether that is the right result.

  • Risk & Compliance

    Transaction monitoring rules that find risk instead of noise

    A monitoring rule earns its place when it maps to a risk you actually carry, fires on data you actually send, and produces alerts an analyst can close with a reason. Tune rules against labelled outcomes, never against alert counts alone.