On this page
First-party fraud losses recovered per year (modelled).
Denials carrying replayable evidence.
Provisional credit forced by missed deadlines, approaching zero.
First-party fraud evidenced and correctly denied (modelled).
Challenge
When a customer disputes a charge they actually made, the bank does not get to simply disbelieve them. It has to prove it, from transaction history, device signals, location, behavioural patterns, and prior claim history, inside ten business days. The bank needs speed and evidence on every case, and a manual function cannot deliver both at 2026 dispute volumes.
- No longer a marginal category. First-party fraud became the leading fraud type globally in 2024 at 36% of all reported fraud, up from 15% the year before (LexisNexis Risk Solutions, Cybercrime Report, 2025, drawn from 104 billion transactions). A substantial share of chargebacks now trace back to it, and the direction of travel is still upward.
- Under-deny and the bank eats losses it never owed. An investigator with a queue and a ten-day clock takes the path of least resistance on ambiguous cases. Reimburse, close, move on. Each one is a loss the bank funded because assembling the evidence cost more time than it had.
- Over-deny and the bank creates a different liability. A denial on thin evidence produces a complaint, an overturn, a regulatory record, and a customer who was telling the truth and just got called a liar by their own bank.
- Run past the clock and the decision is taken away. Provisional credit is issued automatically, so the bank has paid out on a case it had not finished investigating. Clawing that back is a second process with its own failure rate.
Two ways to be wrong, one of them funded today
Deny too little
- ~$23.5M absorbedFirst-party fraud paid out for want of evidence in time.
- ~$15.75M forcedProvisional credit issued automatically on a missed clock.
Deny too much
- Complaints and overturnsA denial on thin evidence comes back, with a record attached.
- A customer who was telling the truthWrongly accused, and unlikely to stay.
Solution
CreateOS deploys an investigation and decision crew inside the bank's environment, built around one principle: no denial leaves the system without the evidence that defends it.
- The case assembles itself before a human opens it. Transaction history, device and counterparty signals, geolocation, merchant relationship, and prior claim patterns are chased in parallel. What took days of tab-switching arrives as an evidence pack in minutes.
- The bank keeps the loss policy. We do not set the threshold at which a claim is denied. The bank does, explicitly and auditably, and the agent applies it consistently, which is itself an improvement over hundreds of investigators applying it from memory under time pressure.
- Built not to falsely accuse. Low-confidence first-party-fraud findings route to a human by policy. The agent assembles the case and surfaces the open questions rather than making the accusation cheap.
- Every denial is replayable years later. The full decision chain is logged step by step for an examiner, a complaint review, or a court, with the supporting evidence attached and the deadline tracked.
- Credit and chargebacks are bounded in the kernel. Egress is allowlisted to sanctioned payment-system paths, so an agent that is wrong or manipulated cannot move money to an unapproved destination. VM suspension is the kill switch.
- Payment data never leaves the bank. Control plane and storage sit inside the bank's own region and boundary. CreateOS is SOC 2 Type II and ISO 27001 certified.
Outcome Derived
The committed numbers here are about process and defensibility, because those travel between banks. The loss-recovery figure is a model, presented as one, with every assumption exposed so a bank can replace it with its own actuals.
- First-party fraud evidenced and correctly denied rises from 35% to 60%. Modelled at roughly $9.1M a year in losses the bank no longer absorbs.
- 100% of denials carry replayable, examiner-ready evidence. The defensibility is the deliverable. A denial the bank cannot evidence is a denial it will hand back.
- Provisional credit forced by missed deadlines approaches zero. From roughly $15.75M, because the clock stops being the thing that decides.
Modelled on a Representative Mid-Size Bank
| Assumption | Figure |
|---|---|
| Fraud and dispute cases per year | 1,500,000 |
| Average disputed value | ~$105 (derived from 146M US cases at $15.3B) |
| Total disputed value in play | $157.5M per year |
| First-party fraud share of disputes | 23% (assumption, measured in Phase 0) |
| Cases where the customer made the transaction | ~345,000, worth ~$36.2M |
| Denials successfully evidenced today, under manual investigation | 35% (assumption, measured in Phase 0) |
| Cases missing the ten-day clock today | 10% (assumption, measured in Phase 0) |
Narrowing to the exposure in question
1,500,000
Disputes a year
~$105
Average disputed value
23%
First-party fraud share
~$36.2M
In play on cases the customer made themselves
What the bank loses today
| Loss channel | Annual exposure |
|---|---|
| First-party fraud absorbed for want of evidence in time | ~$23.5M |
| Provisional credit issued automatically on missed deadlines | ~$15.75M forced payout, recovery uncertain |
| Wrongful denials on thin evidence | Complaints, overturns, regulatory record, churn |
What the agent changes
| Metric | Before | After |
|---|---|---|
| Evidence pack assembled | Days of investigator time | Minutes |
| Denials carrying replayable evidence | Partial | 100% |
| Regulation E resolution inside the clock | ~90% (assumed) | 100% |
| Provisional credit forced by missed deadlines | ~$15.75M | Approaching zero |
| First-party fraud evidenced and correctly denied | 35% | 60% (modelled) |
| First-party fraud losses recovered | , | ~$9.1M per year (modelled) |
| Audit coverage of every decision | Partial | 100% |
| Unauthorized money movement | Risk | Zero, enforced in-kernel |
Headline: roughly $9M per year in first-party fraud losses no longer absorbed, plus the collapse of forced provisional credit, on a $36M exposure the bank is largely funding today.
Read the model, do not just read the number. It rests on two assumptions we cannot know before we measure your operation: your current evidenced-denial rate and your current miss rate against the ten-day clock. Both are Phase 0 deliverables. If your evidenced-denial rate is already 55%, the recovery is smaller and we will say so. We would rather hand a CFO a number they can audit than one they have to trust.
Why this exposure is growing, and why waiting costs more. First-party fraud went from 15% to 36% of all reported fraud in a single year (LexisNexis Risk Solutions, Cybercrime Report, 2025). The evidence gap is not a stable problem the bank can defer. It is a widening one, and every year it stays open the bank funds more of it.
The counterweight, stated plainly. Every percentage point of improvement in denial rate has to come from better evidence, not from a lower bar. A bank that denies more claims without proving more of them has not solved first-party fraud. It has manufactured a complaints problem and a regulatory one. We prove that distinction in shadow mode: the agents run against live cases without binding authority, and we compare decision by decision against the human team, confirming that the additional denials are the evidenced ones. That is the whole game, and it is the number a risk committee will actually ask about.
What We Would Prove, and How
| We commit to | We validate on your data |
|---|---|
| 100% of denials carry replayable, examiner-ready evidence | Current evidenced-denial rate and first-party fraud share |
| 100% Regulation E resolution within the ten-day clock | Current miss rate and provisional-credit absorption |
| 100% audit coverage of every decision and action | Complaint and overturn rate on existing denials |
| No increase in wrongful denials, proven in shadow mode | Actual recoverable value of the exposure |
| Zero unauthorized money movement | Case mix between clear-cut and genuinely ambiguous |
The first deliverable of the engagement is not the agent. It is the bank's own baseline: how many first-party fraud claims it is funding today, how many denials it cannot defend, and how often the clock beats it. That baseline becomes the yardstick in the contract, and it protects both sides.
Highlights
- Roughly $9M per year in first-party fraud losses no longer absorbed (~$9.1M modelled).
- 100% of denials carry replayable, examiner-ready evidence.
- 100% Regulation E resolution inside the clock; provisional credit forced by missed deadlines approaching zero.
- 35% to 60% first-party fraud evidenced and correctly denied (modelled).



