Reference / Glossary

Glossary

The language of payments and fintech risk, explained in plain terms.

129 terms

5

50 Percent Rule
OFAC’s rule concerning entities owned 50 percent or more in aggregate, directly or indirectly, by one or more blocked persons.
Ownership graphs and the 50 Percent Rule

A

Acceptance evidence
Observable results that show a stated requirement or readiness condition has been met.
A complete risk system: the Lantern case
Account takeover
Unauthorized control of an existing account or its capabilities.
Account takeover and account recovery
ACH
Automated Clearing House; a U.S. network for eligible bank credits and debits.
ACH, bank debits, and returns
Acquirer
The financial institution on the merchant side of a card-acceptance arrangement.
Money movement and the risk map
Adverse action
A defined unfavorable credit action under the applicable framework; scope and notice treatment depend on the facts.
Fair lending, explainability, and adverse action
Alert
A signal selected for review; it does not itself establish wrongdoing.
Transaction monitoring and alert quality
AML
Anti-money laundering; the applicable controls and processes addressing illicit proceeds and related obligations.
AML programs and the risk-based approach
Atomic operation
An operation that completes as one indivisible state change within its defined system boundary.
Decision engines, rules, and reliable execution
Authentication
Establishing confidence that an actor controls an authenticator or credential.
Account takeover and account recovery
Authorization
An approval step in a payment workflow; it does not by itself prove settlement or delivery.
Cards, authorization, and disputes
Authorization control
A check of whether an actor is permitted to perform a particular action; distinct from card authorization.
Account takeover and account recovery

B

Backpressure
A mechanism that limits incoming or upstream work when downstream capacity is constrained.
Operational resilience and failure design
Beneficial owner
A natural person identified through applicable ownership or control rules; the precise test depends on the framework.
Customer due diligence and beneficial ownership
Blocked property
Property immobilized under applicable sanctions requirements; blocking is distinct from seizure or ordinary refunding.
Sanctions scope, prohibitions, and licenses
Business email compromise
Fraud involving a compromised or impersonated business communication, often to redirect payments.
Scams, money mules, and social engineering

C

Calibration
Agreement between predicted probabilities and observed event frequencies under a defined evaluation.
Risk models, calibration, and delayed outcomes
Capture
The step that submits an authorized card payment toward collection.
Cards, authorization, and disputes
Cash conversion cycle
A simplified measure of time cash is tied up: inventory days plus receivable days minus payable days.
Cash-flow analysis and financial evidence
Cash ladder
A time- and currency-specific schedule of available funds, inflows, outflows, and buffers.
Treasury, liquidity, and settlement operations
CDD
Customer due diligence; understanding and maintaining relevant customer and relationship information under the applicable framework.
Customer due diligence and beneficial ownership
Chargeback
A card-payment dispute mechanism through which value may be reversed under network rules.
Cards, authorization, and disputes
Clearing account
An accounting account used to track amounts between stages of a financial process.
Ledgers, reconciliation, and settlement risk
Concentration risk
Risk from exposures that share a significant counterparty, dependency, or loss driver.
Portfolio monitoring and credit deterioration
Containment
An action that stops or limits the active harmful path during an incident.
Risk incidents, containment, and learning
Control invariant
A property that must remain true across the relevant workflow, such as one financial effect per logical operation.
A complete risk system: the Lantern case
Control relationship
A relationship involving management or authority; it is not automatically the same as ownership.
Ownership graphs and the 50 Percent Rule
Corridor
A defined payment route, usually described by origin, destination, currency, and partners.
Instant payments and cross-border transfers
Counterfactual
The outcome that would occur under an alternative action or condition.
Experiments, causal effects, and risk tradeoffs
Custody
Control or safeguarding of assets or keys under a defined service arrangement.
Digital assets, stablecoins, and wallet risk

D

Data leakage
Use of information in model development or evaluation that would not be available or appropriate in the intended prediction setting.
Risk data contracts and event time
Data lineage
The trace from source records through transformations to downstream uses.
Risk data contracts and event time
Debt-service capacity
Funds available to meet debt payments under a defined cash-flow analysis.
Cash-flow analysis and financial evidence
Decision replay
Reconstruction of an evaluation from its historical inputs and versions without repeating external side effects.
Decision engines, rules, and reliable execution
Delivery exposure
Open risk arising while the promised goods or services remain undelivered.
Underwrite the merchant business
Disposition
A documented conclusion and associated action for a case or decision.
Investigations, reporting, and confidentiality
Double-entry accounting
A recording method in which each journal event has equal total debits and credits.
Ledgers, reconciliation, and settlement risk

E

Effective challenge
Critical review that tests assumptions, evidence, implementation, and suitability for the intended use.
Model governance and AI-assisted risk work
Eligible cover
Funds both available and permitted to cover the specific exposure being measured.
Reserves, limits, and payout policy
End user
The person or entity that ultimately uses the goods or service in the relevant transaction.
Trade, corridors, and restricted activity
Enhanced due diligence
Additional investigation and evidence appropriate to the specific risk and applicable requirements.
Customer due diligence and beneficial ownership
Entity resolution
Determining whether different records refer to the same real-world entity.
Entity resolution and financial networks
Error resolution
The applicable investigation, communication, and corrective process for a reported transaction error.
Consumer protection, errors, and complaints
Estimand
The precisely defined effect an analysis aims to estimate for a population and intervention.
Experiments, causal effects, and risk tradeoffs
Evidence provenance
The source, history, and handling information that explains where evidence came from.
Identity, credentials, and synthetic profiles
Exit plan
A prepared process for ending or replacing a dependency while managing data, funds, customers, and remaining obligations.
Sponsor banks, vendors, and third-party risk
Expected loss
An estimate of average loss under stated probability, exposure, severity, and other assumptions.
Transaction risk and decision economics
Export controls
A separate legal framework regulating covered items and activity based on factors such as destination, end user, and end use.
Trade, corridors, and restricted activity
Exposure at default
Estimated amount at risk when default occurs, commonly abbreviated EAD.
Credit risk and repayment capacity
Exposure limit
A boundary on a defined amount of risk, such as unresolved obligations or available credit.
Reserves, limits, and payout policy

F

False match
A screening candidate resolved as not referring to the relevant listed or restricted subject on the supported evidence.
Screening engines and match resolution
False merge
An entity-resolution error that combines records of different entities.
Entity resolution and financial networks
False-positive rate
False positives divided by all actual negatives, not by all flagged records.
Risk models, calibration, and delayed outcomes
Feature attribution
A method’s estimate of how input features contribute to a model output; not automatic proof of causation.
Fair lending, explainability, and adverse action
Finality
The point at which settlement is final under a system’s rules; later legal claims can still exist.
Instant payments and cross-border transfers
First-party misuse
Deceptive use or a deceptive claim by a party about its own transaction or obligation.
First-party misuse, merchant abuse, and feedback
Foreign-exchange risk
Exposure to changes in relative currency values or conversion terms.
Instant payments and cross-border transfers

G

General license
An authorization for defined activity under stated conditions, issued without an individual application for each qualifying transaction.
Sanctions scope, prohibitions, and licenses
Ground truth
The best supported outcome evidence available for a defined analytical task, with its limitations.
First-party misuse, merchant abuse, and feedback
Guardrail
A defined limit or stop condition used to constrain a rollout or experiment.
A complete risk system: the Lantern case

I

Idempotency
A defined repeated operation produces one intended business effect rather than duplicate effects.
Ledgers, reconciliation, and settlement risk
Identity proofing
Establishing confidence in a claimed real-world identity through suitable evidence.
Identity, credentials, and synthetic profiles
Incident command
The assigned leadership and decision structure used to coordinate an incident response.
Risk incidents, containment, and learning
Inherent risk
Exposure considered before the effect of the relevant controls.
AML programs and the risk-based approach
Issuer
The institution that provides the card account to the cardholder.
Money movement and the risk map

L

Label maturity
The extent to which enough time has passed for an outcome label to develop.
First-party misuse, merchant abuse, and feedback
Least privilege
Access limited to the functions and information required for an authorized task.
Privacy, payment data, and secure evidence
Liability shift
A rule-dependent change in which party bears specified payment liability.
Cards, authorization, and disputes
Liquidity
Ability to meet obligations with usable funds when they are due.
Treasury, liquidity, and settlement operations
List version
The identifiable sanctions dataset used by a screening system at a point in time.
Screening engines and match resolution
Little’s Law
The relation L equals lambda times W between long-run average work in progress, arrival rate, and time in a stable system.
Case operations and human decisions
Loss given default
Estimated loss fraction conditional on default, commonly abbreviated LGD.
Credit risk and repayment capacity

M

Merchant of record
The entity responsible as merchant in the relevant payment arrangement, determined by the actual structure and agreements.
Underwrite the merchant business
Merchant underwriting
Assessment of a merchant’s identity, business model, capacity, obligations, and processing exposure.
Underwrite the merchant business
Model inventory
A maintained record of models, their uses, owners, versions, dependencies, limitations, and review status.
Model governance and AI-assisted risk work
Money mule
A person or account used to receive or move funds for another actor, with knowledge and involvement varying by case.
Scams, money mules, and social engineering
Monitoring scenario
A defined hypothesis, population, data logic, and alert process used to identify activity for review.
Transaction monitoring and alert quality

O

Obligation register
A traceable map from a requirement to scope, trigger, owner, implementation, and evidence.
Compliance architecture and policy as code
ODFI
Originating Depository Financial Institution; the institution that introduces an ACH entry to the network.
ACH, bank debits, and returns
OFAC
The U.S. Treasury’s Office of Foreign Assets Control, which administers and enforces U.S. sanctions programs.
Sanctions scope, prohibitions, and licenses
Ownership graph
A set of entities and dated ownership relationships used to analyze direct and indirect interests.
Ownership graphs and the 50 Percent Rule

P

Payment rail
The rules, participants, and infrastructure used to move a payment.
Money movement and the risk map
Payment recall
A request to recover a sent payment; success is not guaranteed merely because a request was made.
Instant payments and cross-border transfers
PCI DSS
Payment Card Industry Data Security Standard; security requirements for in-scope payment-data environments.
Privacy, payment data, and secure evidence
Peer group
A defined set of comparable entities used to interpret activity or outcomes.
Transaction monitoring and alert quality
Point-in-time correctness
Use of only the information that was available at the relevant historical decision cutoff.
Risk data contracts and event time
Policy as code
Machine-executable policy logic maintained with defined scope, versions, review, and tests.
Compliance architecture and policy as code
Precision
True positives divided by all positive predictions for a defined population and label.
Risk models, calibration, and delayed outcomes
Probability of default
Estimated probability of a defined default event over a stated horizon, commonly abbreviated PD.
Credit risk and repayment capacity
Prompt injection
Untrusted content that attempts to redirect an AI system’s instructions or actions.
Model governance and AI-assisted risk work
Provisional credit
Temporary credit under defined conditions during a relevant resolution process; distinct from final resolution.
Consumer protection, errors, and complaints

Q

Queue aging
Measurement of how long work has remained unresolved, preserving its original relevant start time.
Case operations and human decisions

R

RDFI
Receiving Depository Financial Institution; the institution that receives an ACH entry for the receiver.
ACH, bank debits, and returns
Recall
True positives divided by all actual positives for a defined population and label.
Risk models, calibration, and delayed outcomes
Reconciliation
Comparison of independent records to identify and explain differences in obligations or value.
Ledgers, reconciliation, and settlement risk
Recovery point objective
The target tolerance for lost data history after recovery from a failure.
Operational resilience and failure design
Recovery time objective
The target time to restore the required service after a failure.
Operational resilience and failure design
Regulation B
A U.S. regulation implementing the Equal Credit Opportunity Act, including applicable evaluation and notice requirements.
Fair lending, explainability, and adverse action
Regulation E
A U.S. regulation governing specified electronic fund transfers and related consumer rights and duties.
Consumer protection, errors, and complaints
Remediation
Actions that address the consequences of an identified defect or harm.
Compliance architecture and policy as code
Residual risk
The risk remaining after considering control effectiveness and limitations.
AML programs and the risk-based approach
Return
A rail-specific event that sends a payment entry back under an applicable reason and process.
ACH, bank debits, and returns
Risk signal
An observation used to assess uncertainty; it is evidence rather than a verdict.
Transaction risk and decision economics
Roll rate
The rate of movement from one defined delinquency state to another during a stated period.
Portfolio monitoring and credit deterioration
Rolling reserve
A reserve structure that retains eligible funds and releases them according to a defined schedule and conditions.
Reserves, limits, and payout policy
Root cause analysis
Investigation of the trigger and contributing system conditions that allowed an event and its impact.
Risk incidents, containment, and learning

S

Sanctions screening
Comparison of relevant party and activity data against applicable sanctions information and controls.
Screening engines and match resolution
SAR
Suspicious Activity Report; a report under applicable rules, with protected confidentiality and institution-specific requirements.
Investigations, reporting, and confidentiality
Selection bias
Distortion arising when the observed or analyzed population is selected in a way relevant to the conclusion.
Experiments, causal effects, and risk tradeoffs
Service time
Time actively spent handling a case or request, excluding its waiting time.
Case operations and human decisions
Settlement
The discharge of payment obligations through the relevant payment system and accounts.
Money movement and the risk map
Shadow evaluation
Running a candidate policy or model without applying its action to the customer.
Decision engines, rules, and reliable execution
Social engineering
Manipulation of a person to obtain access, information, or an action.
Scams, money mules, and social engineering
Solvency
The relationship between assets and obligations under the relevant financial assessment; distinct from immediate cash availability.
Treasury, liquidity, and settlement operations
Source of funds
The origin of money in a particular transaction or flow.
Investigations, reporting, and confidentiality
Source of wealth
How a person’s or entity’s broader wealth was accumulated over time.
Investigations, reporting, and confidentiality
Specific license
An authorization issued for a particular person or transaction within its stated terms.
Sanctions scope, prohibitions, and licenses
Sponsor bank
A bank supporting a fintech arrangement under defined roles and agreements; exact responsibilities depend on the structure.
Sponsor banks, vendors, and third-party risk
Stablecoin
A digital asset designed to track a reference value; stability and redemption depend on its structure and conditions.
Digital assets, stablecoins, and wallet risk
Step-up authentication
A request for stronger authentication for a particular action or context.
Transaction risk and decision economics
Synthetic identity
A constructed persona that combines identity elements, some of which may be genuine.
Identity, credentials, and synthetic profiles

T

Third-party risk
Exposure created by relying on another organization or its subcontractors to perform a service.
Sponsor banks, vendors, and third-party risk
Tokenization
Replacement of sensitive values with references under a defined system; it does not automatically make all linked data anonymous.
Privacy, payment data, and secure evidence
Trade-based money laundering
Use of trade transactions to disguise illicit proceeds or move value with an illicit purpose.
Trade, corridors, and restricted activity
Transactional outbox
A pattern that records business state and a pending event in one database transaction for later delivery.
Operational resilience and failure design
Typed edge
A graph relationship with an explicit meaning, such as ownership, payment, or shared address.
Entity resolution and financial networks

V

Vintage
A cohort grouped by origination period for comparison at similar age.
Portfolio monitoring and credit deterioration

W

Wallet attribution
Evidence linking a blockchain address to a real-world entity, with a stated source and confidence.
Digital assets, stablecoins, and wallet risk
Working capital
Resources and obligations associated with the operating cycle; the precise accounting measure must be specified.
Cash-flow analysis and financial evidence