Sources & editorial notes
Edition 02 · September 18, 2026. Primary sources, original explanations, and a clear boundary between rules and examples.
Scope and audience
This book covers payments and fintech risk engineering with a U.S. focus and global context. It connects payment mechanics, fraud, underwriting, credit, AML, sanctions, compliance, data, models, and operations. Read it in order for the full system, or use the chapter list and search for a specific subject.
The examples explain engineering choices. They are not production policies, legal advice, or an institution-specific compliance program. Legal duties depend on the entity, product, activity, jurisdiction, and facts. Network rules and provider behavior can also differ. Chapters identify those boundaries where they affect the design.
How sources are used
Chapter sources link to regulators, standards bodies, official technical documentation, and provider documentation. Provider examples explain a particular implementation; they are not universal rail rules. Older examination material is read with current rules and agency updates. The original source library was checked on September 17, 2026. The September 18 expansion rechecked key technical and consumer-rule references and added the SciPy reference for binomial intervals.
The edition includes FinCEN’s 2026 beneficial-owner relief, the September 2, 2026 statement on SAR confidentiality and customer communication, Nacha’s 2026 Phase 2 monitoring changes, and the revised federal model-risk guidance in SR 26-2. These dates describe the source edition, not a guarantee that future requirements will remain unchanged.
Original cases and illustrations
Lantern, its customers, and all case records are fictional. Amounts, rates, thresholds, service targets, and stress assumptions are teaching examples unless a passage explicitly identifies an authoritative rule. The 8,000 illustrations include flows, records, ownership graphs, loss curves, confusion matrices, cash ladders, and control failure modes. The 600 worked cases each contain 12 figures and accessible data tables. Analytical forms and some reference data repeat where the same principle applies. They are original vector images, with readable text versions on small screens.
Explanations and diagrams were authored with AI assistance. Automated checks verify structure, links within the book, image coverage, and selected calculations. They do not establish legal accuracy or constitute independent human subject-matter review. No independent human review is claimed.
Corrections and maintenance
Review a correction together with its chapter text, diagrams, glossary terms, source references, and relevant calculations. Record the changed source and effective date. A rule update can affect customer messages, data requirements, and operations as well as the rule itself.
Privacy
The textbook has no accounts, assessments, tracking profile, or analytics integration. Search runs in your browser. The color preference is stored locally. A hosting provider may process ordinary request data when the site is hosted.
Design attribution
The reading interface follows the existing ca-re book and its adaptation of Rubix Documents. The original MIT license is preserved. The interface uses Next.js, shadcn/ui, and Radix. No affiliation with a regulator, payment network, or source publisher is implied.
Book coverage
| Unit | Chapters | Illustrations |
|---|---|---|
| Payments & money movement | 5 | 1000 |
| Fraud & transaction risk | 5 | 1000 |
| Underwriting & credit risk | 5 | 1000 |
| AML & financial crime | 5 | 1000 |
| Sanctions & global risk | 5 | 1000 |
| Compliance by design | 5 | 1000 |
| Risk systems & models | 5 | 1000 |
| Risk operations & resilience | 5 | 1000 |
Topic map
Payments & money movement5 topics
| Textbook topic | Chapters |
|---|---|
| Money movement and the risk map | Money movement and the risk map |
| Cards, authorization, and disputes | Cards, authorization, and disputes |
| ACH, bank debits, and returns | ACH, bank debits, and returns |
| Instant payments and cross-border transfers | Instant payments and cross-border transfers |
| Ledgers, reconciliation, and settlement risk | Ledgers, reconciliation, and settlement risk |
Fraud & transaction risk5 topics
| Textbook topic | Chapters |
|---|---|
| Identity, credentials, and synthetic profiles | Identity, credentials, and synthetic profiles |
| Account takeover and account recovery | Account takeover and account recovery |
| Transaction risk and decision economics | Transaction risk and decision economics |
| Scams, money mules, and social engineering | Scams, money mules, and social engineering |
| First-party misuse, merchant abuse, and feedback | First-party misuse, merchant abuse, and feedback |
Underwriting & credit risk5 topics
| Textbook topic | Chapters |
|---|---|
| Underwrite the merchant business | Underwrite the merchant business |
| Credit risk and repayment capacity | Credit risk and repayment capacity |
| Cash-flow analysis and financial evidence | Cash-flow analysis and financial evidence |
| Reserves, limits, and payout policy | Reserves, limits, and payout policy |
| Portfolio monitoring and credit deterioration | Portfolio monitoring and credit deterioration |
AML & financial crime5 topics
| Textbook topic | Chapters |
|---|---|
| AML programs and the risk-based approach | AML programs and the risk-based approach |
| Customer due diligence and beneficial ownership | Customer due diligence and beneficial ownership |
| Entity resolution and financial networks | Entity resolution and financial networks |
| Transaction monitoring and alert quality | Transaction monitoring and alert quality |
| Investigations, reporting, and confidentiality | Investigations, reporting, and confidentiality |
Sanctions & global risk5 topics
| Textbook topic | Chapters |
|---|---|
| Sanctions scope, prohibitions, and licenses | Sanctions scope, prohibitions, and licenses |
| Screening engines and match resolution | Screening engines and match resolution |
| Ownership graphs and the 50 Percent Rule | Ownership graphs and the 50 Percent Rule |
| Trade, corridors, and restricted activity | Trade, corridors, and restricted activity |
| Digital assets, stablecoins, and wallet risk | Digital assets, stablecoins, and wallet risk |
Compliance by design5 topics
| Textbook topic | Chapters |
|---|---|
| Compliance architecture and policy as code | Compliance architecture and policy as code |
| Consumer protection, errors, and complaints | Consumer protection, errors, and complaints |
| Fair lending, explainability, and adverse action | Fair lending, explainability, and adverse action |
| Privacy, payment data, and secure evidence | Privacy, payment data, and secure evidence |
| Sponsor banks, vendors, and third-party risk | Sponsor banks, vendors, and third-party risk |
Risk systems & models5 topics
| Textbook topic | Chapters |
|---|---|
| Risk data contracts and event time | Risk data contracts and event time |
| Decision engines, rules, and reliable execution | Decision engines, rules, and reliable execution |
| Risk models, calibration, and delayed outcomes | Risk models, calibration, and delayed outcomes |
| Experiments, causal effects, and risk tradeoffs | Experiments, causal effects, and risk tradeoffs |
| Model governance and AI-assisted risk work | Model governance and AI-assisted risk work |
Risk operations & resilience5 topics
| Textbook topic | Chapters |
|---|---|
| Case operations and human decisions | Case operations and human decisions |
| Treasury, liquidity, and settlement operations | Treasury, liquidity, and settlement operations |
| Operational resilience and failure design | Operational resilience and failure design |
| Risk incidents, containment, and learning | Risk incidents, containment, and learning |
| A complete risk system: the Lantern case | A complete risk system: the Lantern case |