Come build the future with Rain.
View open roles
Rain is now a Mastercard Principal Member.
Read more
Perspectives
|
6 min read

How Rain approaches transaction monitoring

Kevin Carr
Chief Compliance Officer

At Rain, we monitor every single transaction that runs on our infrastructure. We screen in real-time at the authorization level, and continue reviewing payment activity as it accumulates. That coverage is the foundation of our broader fraud prevention and detection program built to protect the people and businesses who rely on our products. 

Transaction monitoring systems are both the least visible and most important parts of a payments company. In the sections that follow  we share information about the shape of our transaction monitoring program and the thinking behind it. We do this because openness and transparency are core to our overall approach to compliance, though of course we can’t share all the details because doing so might provide too clear a roadmap to those who might try to circumvent them.

Layered by design 

Our approach to fraud prevention and detection is layered by design, because no single control catches everything. Consider how office buildings are protected. The badge reader at the entrance turns away anyone without credentials. The security officer that knows the staff catches the person who has a badge but does not belong. One is a fixed rule and the other is an awareness of what normal looks like, and removing either weakens the whole. Payments security is no different. 

Transaction monitoring really starts before a Rain-powered program is even up and running. Our extensive Know Your Business (KYB) screening process helps us establish a baseline for normal program activity, including where transactions will be taking place and what payment volume will look like. Through Know Your Customer (KYC) screening, we collect cardholder details like occupation and address, information that enables us to paint an even more detailed picture of what we should expect from individuals in a program. 

Activity that is normal for one program could be suspicious for another, so a single rulebook is ineffective. Picture a corporate travel program next to a payroll card program. In the first, purchases across three countries in a single week look routine. In the second, that same pattern raises red flags. Understanding each program is what allows us to spot genuinely unusual activity without turning away legitimate spending. 

The next layer is at the authorization level, in the seconds between a card being presented and a purchase being approved. We monitor card activity in real-time, often catching suspicious activity as soon as a bad actor initiates it. This allows us to reject a fraudulent purchase before it even clears. 

When it comes to authorization level declines, some rules are constant and apply to every program that runs on Rain. Transactions tied to sanctioned or restricted jurisdictions will always be declined, as will purchase attempts from blocked merchant categories. When spending breaks the velocity limits for a given card, merchant, or merchant category, we decline transactions. This is one of the most effective defenses against card testing and rapid-fire attacks where a bad actor will run many small charges in quick succession to find out which stolen numbers still work. Catching that burst early makes a real difference. Enhanced, custom controls can be added on top of the ones Rain requires to fit an individual program’s specific risk profile. 

The next layer looks beyond any single payment. Once a transaction clears, we keep analyzing activity across the program to catch systemic risks. A group of transactions that each seemed ordinary at authorization can reveal a coordinated scheme when viewed together, and we cannot see that pattern unless we continue to monitor after settlement. Post-transaction monitoring also includes tracking disputes, refunds, and chargebacks to identify fraudulent activity. This layer is important when it comes to tracking fraud rates and the effectiveness of the entire transaction monitoring system. 

These layers each work alongside network-level controls and transaction monitoring. The card networks decline transactions their models flag as unauthorized, and they intervene against patterns like BIN attacks, where fraudsters generate and test card numbers at scale.

The controls described in this section are only part of a broader program. We layer in additional rules and dynamic risk signals that adjust as behavior and threats change, and we work to anticipate new attacks rather than react to them.

Where people come in 

Not everything resolves in an automated rule, and it shouldn't. When activity trips our monitoring, it goes to human review. Analysts investigate the context around it, and cases that warrant it are escalated to our Compliance team, where we make the final decisions and fulfill our reporting obligations. Automation gives the program its reach, but our skilled people give it judgment.

The honest reality of this work is that it’s never finished. Threats constantly evolve, and a program that is effective today will be tested by something new tomorrow. Our rules and risk signals adjust as behavior changes, and we devote time to studying attack patterns that have not reached us yet. Some of the controls I am proudest of were built for attacks we anticipated before they were attempted.

Transaction monitoring is just one part of a larger system. The KYB and KYC programs I mentioned above and our intensive wallet screening program are described in more detail in our guide on how Rain reduces risk. Together, each part of our risk mitigation program reflects a belief we hold across Rain. In payments, trust is the product and it has to be engineered and defended every day.

Launch your stablecoin payments platform with Rain

Let's talk
See what your favorite AI has to say about Rain's solution