Case studies
Banking

The Bank Cannot Simply Disbelieve the Customer

Each denial carries the evidence behind it, assembled while the case is open.

CreateOS for Defensible Fraud Denials
On this page
~$9.1M

First-party fraud losses recovered per year (modelled).

100%

Denials carrying replayable evidence.

~$15.75M → ~0

Provisional credit forced by missed deadlines, approaching zero.

35% → 60%

First-party fraud evidenced and correctly denied (modelled).

Challenge

When a customer disputes a charge they actually made, the bank does not get to simply disbelieve them. It has to prove it, from transaction history, device signals, location, behavioural patterns, and prior claim history, inside ten business days. The bank needs speed and evidence on every case, and a manual function cannot deliver both at 2026 dispute volumes.

  • No longer a marginal category. First-party fraud became the leading fraud type globally in 2024 at 36% of all reported fraud, up from 15% the year before (LexisNexis Risk Solutions, Cybercrime Report, 2025, drawn from 104 billion transactions). A substantial share of chargebacks now trace back to it, and the direction of travel is still upward.
  • Under-deny and the bank eats losses it never owed. An investigator with a queue and a ten-day clock takes the path of least resistance on ambiguous cases. Reimburse, close, move on. Each one is a loss the bank funded because assembling the evidence cost more time than it had.
  • Over-deny and the bank creates a different liability. A denial on thin evidence produces a complaint, an overturn, a regulatory record, and a customer who was telling the truth and just got called a liar by their own bank.
  • Run past the clock and the decision is taken away. Provisional credit is issued automatically, so the bank has paid out on a case it had not finished investigating. Clawing that back is a second process with its own failure rate.

Two ways to be wrong, one of them funded today

Deny too little

  • ~$23.5M absorbedFirst-party fraud paid out for want of evidence in time.
  • ~$15.75M forcedProvisional credit issued automatically on a missed clock.

Deny too much

  • Complaints and overturnsA denial on thin evidence comes back, with a record attached.
  • A customer who was telling the truthWrongly accused, and unlikely to stay.
An investigator with a queue and a ten-day clock takes the path of least resistance on an ambiguous case, which is why the left pan is the one carrying weight today. Neither side is fixed by moving the bar. Both are fixed by having the evidence before the clock runs out.

Solution

CreateOS deploys an investigation and decision crew inside the bank's environment, built around one principle: no denial leaves the system without the evidence that defends it.

  • The case assembles itself before a human opens it. Transaction history, device and counterparty signals, geolocation, merchant relationship, and prior claim patterns are chased in parallel. What took days of tab-switching arrives as an evidence pack in minutes.
  • The bank keeps the loss policy. We do not set the threshold at which a claim is denied. The bank does, explicitly and auditably, and the agent applies it consistently, which is itself an improvement over hundreds of investigators applying it from memory under time pressure.
  • Built not to falsely accuse. Low-confidence first-party-fraud findings route to a human by policy. The agent assembles the case and surfaces the open questions rather than making the accusation cheap.
  • Every denial is replayable years later. The full decision chain is logged step by step for an examiner, a complaint review, or a court, with the supporting evidence attached and the deadline tracked.
  • Credit and chargebacks are bounded in the kernel. Egress is allowlisted to sanctioned payment-system paths, so an agent that is wrong or manipulated cannot move money to an unapproved destination. VM suspension is the kill switch.
  • Payment data never leaves the bank. Control plane and storage sit inside the bank's own region and boundary. CreateOS is SOC 2 Type II and ISO 27001 certified.

Outcome Derived

The committed numbers here are about process and defensibility, because those travel between banks. The loss-recovery figure is a model, presented as one, with every assumption exposed so a bank can replace it with its own actuals.

  • First-party fraud evidenced and correctly denied rises from 35% to 60%. Modelled at roughly $9.1M a year in losses the bank no longer absorbs.
  • 100% of denials carry replayable, examiner-ready evidence. The defensibility is the deliverable. A denial the bank cannot evidence is a denial it will hand back.
  • Provisional credit forced by missed deadlines approaches zero. From roughly $15.75M, because the clock stops being the thing that decides.

Modelled on a Representative Mid-Size Bank

AssumptionFigure
Fraud and dispute cases per year1,500,000
Average disputed value~$105 (derived from 146M US cases at $15.3B)
Total disputed value in play$157.5M per year
First-party fraud share of disputes23% (assumption, measured in Phase 0)
Cases where the customer made the transaction~345,000, worth ~$36.2M
Denials successfully evidenced today, under manual investigation35% (assumption, measured in Phase 0)
Cases missing the ten-day clock today10% (assumption, measured in Phase 0)
Projected. Modeled on stated assumptions and published sources, not measured from a delivered deployment.

Narrowing to the exposure in question

1,500,000

Disputes a year

~$105

Average disputed value

23%

First-party fraud share

~$36.2M

In play on cases the customer made themselves

The 23% is an assumption, not a measurement, and it is the one that moves the answer most. It is measured against the bank's own book in Phase 0 before any of the figures below are claimed.

What the bank loses today

Loss channelAnnual exposure
First-party fraud absorbed for want of evidence in time~$23.5M
Provisional credit issued automatically on missed deadlines~$15.75M forced payout, recovery uncertain
Wrongful denials on thin evidenceComplaints, overturns, regulatory record, churn

What the agent changes

MetricBeforeAfter
Evidence pack assembledDays of investigator timeMinutes
Denials carrying replayable evidencePartial100%
Regulation E resolution inside the clock~90% (assumed)100%
Provisional credit forced by missed deadlines~$15.75MApproaching zero
First-party fraud evidenced and correctly denied35%60% (modelled)
First-party fraud losses recovered, ~$9.1M per year (modelled)
Audit coverage of every decisionPartial100%
Unauthorized money movementRiskZero, enforced in-kernel

Headline: roughly $9M per year in first-party fraud losses no longer absorbed, plus the collapse of forced provisional credit, on a $36M exposure the bank is largely funding today.

Read the model, do not just read the number. It rests on two assumptions we cannot know before we measure your operation: your current evidenced-denial rate and your current miss rate against the ten-day clock. Both are Phase 0 deliverables. If your evidenced-denial rate is already 55%, the recovery is smaller and we will say so. We would rather hand a CFO a number they can audit than one they have to trust.

Why this exposure is growing, and why waiting costs more. First-party fraud went from 15% to 36% of all reported fraud in a single year (LexisNexis Risk Solutions, Cybercrime Report, 2025). The evidence gap is not a stable problem the bank can defer. It is a widening one, and every year it stays open the bank funds more of it.

The counterweight, stated plainly. Every percentage point of improvement in denial rate has to come from better evidence, not from a lower bar. A bank that denies more claims without proving more of them has not solved first-party fraud. It has manufactured a complaints problem and a regulatory one. We prove that distinction in shadow mode: the agents run against live cases without binding authority, and we compare decision by decision against the human team, confirming that the additional denials are the evidenced ones. That is the whole game, and it is the number a risk committee will actually ask about.

What We Would Prove, and How

We commit toWe validate on your data
100% of denials carry replayable, examiner-ready evidenceCurrent evidenced-denial rate and first-party fraud share
100% Regulation E resolution within the ten-day clockCurrent miss rate and provisional-credit absorption
100% audit coverage of every decision and actionComplaint and overturn rate on existing denials
No increase in wrongful denials, proven in shadow modeActual recoverable value of the exposure
Zero unauthorized money movementCase mix between clear-cut and genuinely ambiguous

The first deliverable of the engagement is not the agent. It is the bank's own baseline: how many first-party fraud claims it is funding today, how many denials it cannot defend, and how often the clock beats it. That baseline becomes the yardstick in the contract, and it protects both sides.

Highlights

  • Roughly $9M per year in first-party fraud losses no longer absorbed (~$9.1M modelled).
  • 100% of denials carry replayable, examiner-ready evidence.
  • 100% Regulation E resolution inside the clock; provisional credit forced by missed deadlines approaching zero.
  • 35% to 60% first-party fraud evidenced and correctly denied (modelled).

Give Us One Stuck Pilot.

We'll have it in governed production before your next board meeting.