1. Purpose
IDYC360 provides real-time entity-centric Fraud & AML Intelligence for financial institutions.
This Policy establishes principles and governance requirements for the responsible design, development, validation, deployment, monitoring and use of artificial intelligence, machine learning and algorithmic risk-intelligence components within IDYC360.
The objective is to ensure that AI-assisted risk decisions are explainable, proportionate, privacy-conscious, secure, auditable and subject to appropriate human and institutional oversight.
2. Scope
This Policy applies to AI/ML models and algorithmic intelligence used by IDYC360, including:
- Transaction-risk models
- Behavioural features
- Proprietary FPSM capabilities
- Graph/network intelligence
- Mule-network scoring
- Geo-behaviour analytics
- Entity-risk scoring
- Alert prioritisation
- Model explanations
- Related decision-support services
It applies across research, development, testing, demonstration, pilot and production environments.
3. Responsible AI Principles
IDYC360 adopts the following principles:
- Fairness – models and algorithms should not intentionally discriminate on protected or irrelevant personal characteristics.
- Explainability – material risk outcomes should be supported by understandable contributing signals or evidence appropriate to the use case.
- Accountability – model ownership, approvals, changes and material decisions should be traceable.
- Human oversight – AI-generated risk signals support authorised FI decisioning; they do not by themselves establish guilt or wrongdoing.
- Privacy and minimisation – use only data necessary and authorised for the intended risk purpose, preferring pseudonymised/tokenised identifiers where feasible.
- Reliability and robustness – models should be validated and monitored for performance, stability and data-quality issues.
- Security – model artefacts, features, credentials and decision services must be protected against unauthorised access or manipulation.
- Transparency – capabilities, limitations and validation status must be represented accurately to customers and stakeholders.
4. Role of AI in IDYC360
IDYC360 combines AI/ML with deterministic and analytical intelligence rather than relying on a single opaque model.
Risk evaluation may incorporate behavioural features, transaction velocity, historical baselines, geo-behaviour, entity relationships, graph/network signals, FPSM outputs and other authorised indicators.
The platform generates risk scores, risk bands, alerts, explanations and evidence to assist Fraud Risk, AML/Compliance and Investigation teams.
A risk score or alert is an indicator requiring treatment according to the financial institution’s approved policies and is not, by itself, proof of fraudulent or criminal conduct.
5. Data Governance for AI
Training, validation and inference data must be appropriate for the authorised use case and handled according to IDYC360’s Data Privacy Policy and customer agreements.
IDYC360 will:
- Minimise use of directly identifying information where pseudonymised identifiers are sufficient;
- Assess relevant data for quality, completeness and consistency;
- Segregate production FI data from development/testing environments unless expressly authorised;
- Use synthetic, anonymised or appropriately de-identified data for demonstrations and performance testing wherever feasible;
- Maintain lineage for material model features, datasets and model versions where practicable;
- Not use one FI’s production data to train a general/shared model for other institutions without explicit written authorisation and a lawful basis.
6. Model Development and Validation
Material AI/ML models should follow a controlled lifecycle covering problem definition, feature selection, training, validation, approval, deployment, monitoring and retirement.
Validation should use metrics appropriate to the financial-crime use case. For imbalanced fraud datasets, evaluation should not rely solely on overall accuracy.
Relevant measures may include:
- Precision
- Recall
- PR-AUC
- ROC-AUC
- False-positive rate
- False-negative considerations
- Threshold performance
- Operational alert volumes
Training/validation design must seek to avoid data leakage and misleading performance results.
Synthetic validation results must be clearly identified as synthetic and must not be presented as live financial-institution performance.
7. Threshold and Decision Governance
Production thresholds and risk bands should be configurable according to the FI’s risk appetite, use case, operational capacity and approved governance.
Thresholds should be evaluated against precision/recall trade-offs, false-positive burden and the cost of missed fraud.
Changes to material thresholds, risk-band definitions or decision logic should be controlled, documented and traceable.
Where models are periodically retrained, the new version should be validated before promotion to production.
8. Explainability and Evidence
IDYC360 is designed to provide decision context rather than only an opaque score.
Depending on the model/use case, explanations may include:
- Material behavioural deviations
- Transaction velocity
- Geo anomalies
- Network relationships
- Graph indicators
- Contributing model features
- Relevant alert/evidence references
Explainability outputs must be treated as decision-support evidence and presented in a manner appropriate to authorised FI users, auditors and investigators without unnecessarily exposing proprietary algorithms, source code or confidential model intellectual property.
9. Graph and Mule-Network Intelligence
Graph/network intelligence evaluates relationships between entities and counterparties to identify multi-hop risk, suspicious network structures, mule-network indicators, circular fund movement, reactivated relationships and coordinated activity.
Graph risk must be interpreted contextually.
Association with a high-risk node does not automatically establish wrongdoing. Network scores should be combined with transaction, behavioural and other relevant evidence, with escalation or customer action governed by the FI’s policies and appropriate review.
10. Fairness and Bias Risk
IDYC360 will seek to prevent inappropriate bias arising from training data, proxy variables, model design or operational use.
Features should have a defensible relationship to the financial-crime risk purpose.
Where relevant, model reviews should consider whether performance differs materially across appropriate segments.
Directly identifying or sensitive personal attributes should not be used merely to increase predictive performance where they are unnecessary, inappropriate or prohibited for the use case.
11. Human Oversight and Customer Impact
IDYC360 is primarily a decision-intelligence platform.
Material actions affecting an FI customer—such as account restriction, transaction blocking, enhanced due diligence, escalation or regulatory reporting—remain subject to the FI’s authorised controls, governance and applicable legal/regulatory requirements.
If an FI configures automated intervention, the scope, thresholds, exception handling, audit trail and human-review mechanism should be explicitly agreed and governed by the FI.
12. Model Monitoring and Drift
Deployed models should be monitored proportionately for:
- Data drift
- Feature drift
- Performance degradation
- Abnormal score distributions
- Changes in alert volumes
- Other indicators relevant to the use case
Where ground-truth outcomes become available, they should be used, where authorised, to assess precision, recall and threshold effectiveness.
Material deterioration should trigger investigation, recalibration, retraining, rollback or other corrective action as appropriate.
13. Model Versioning, Change Control and Auditability
Material model versions, deployment dates, validation results and approved changes should be traceable.
Production promotion should follow authorised change-control procedures.
IDYC360 should preserve sufficient decision lineage to reconstruct, where reasonably possible, the model/rule version and relevant risk evidence associated with a material historical decision, subject to retention and contractual requirements.
14. Security and Adversarial Risk
AI and model assets must be protected against unauthorised modification, extraction, poisoning, credential compromise and inappropriate access.
Access to model artefacts, feature stores, source code and administrative functions should follow least-privilege principles.
Material anomalies suggesting manipulation, model abuse or compromised data integrity must be investigated under applicable security and incident-management procedures.
15. Third-Party Models and Components
Third-party models, libraries or AI services used in material risk workflows should be assessed proportionately for security, licensing, privacy, reliability, explainability and operational dependency.
Use of external AI services must not result in unauthorised disclosure of FI/customer data.
Third-party components do not remove IDYC360’s responsibility for governance of the overall solution delivered to its customers.
16. Generative AI
Generative AI, where used internally or in future product capabilities, must not be treated as an authoritative source for fraud determinations or regulatory conclusions without appropriate verification.
Confidential FI data, credentials, proprietary algorithms or personal data must not be submitted to public or unapproved generative-AI services.
Any customer-facing generative-AI functionality must be separately risk-assessed, appropriately disclosed and subject to security, privacy, hallucination-control and human-oversight measures.
17. Regulatory and Customer Alignment
IDYC360 will seek to align its AI governance with applicable Indian legal and regulatory expectations, customer model-risk requirements, privacy obligations and recognised responsible-AI practices.
Where an FI imposes stricter model governance, validation or audit requirements, those requirements may be incorporated into the applicable deployment agreement and operating controls.
18. Roles and Accountability
Management is accountable for adoption of this Policy.
Technology/model owners are responsible for appropriate development, documentation and monitoring of models under their control.
Authorised reviewers are responsible for validation and challenge proportionate to model materiality.
No employee or contractor may intentionally bypass approved controls, manipulate validation results or conceal a known material limitation of a model.
19. Exceptions, Incidents and Escalation
Material model failures, unexplained performance changes, suspected bias, data-quality failures, security incidents or inappropriate automated outcomes must be escalated to responsible management.
Corrective actions may include:
- Disabling a model
- Reverting a version
- Changing thresholds
- Correcting data
- Retraining
- Requiring additional human review
Exceptions to this Policy must be documented, risk-assessed and approved by authorised management.
20. Review and Continuous Improvement
This Policy will be reviewed at least annually and earlier when material changes occur in IDYC360’s models, FPSM/graph capabilities, data use, deployment architecture, applicable law, regulatory expectations or customer requirements.
IDYC360 will continuously improve its responsible-AI controls as the platform progresses from synthetic validation to FI pilots and production deployments.
21. Contact
Questions concerning this Policy may be directed to:
IDYC360 Private Limited
Email:
[email protected]
Adoption note: This Policy should be formally approved by IDYC360 management/Board-authorised authority, communicated to relevant personnel and reflected in actual model-development and deployment controls before IDYC360 represents it as an implemented Ethical AI Policy.