Your five cleanest merchants might be the same fraud ring.
Not a hypothetical. A pattern that surfaces regularly in payment aggregator portfolios - and almost never gets caught by the systems that are supposed to catch it.
Each merchant passed KYC. Each one processes modest volume. Each one looks exactly like the kind of clean small business you want more of on your platform. Your rule engine agrees. No alert fires.
That is the problem, not the reassurance.
A rule engine is good at one thing: yes or no, one entity at a time. Velocity too high - yes. Geography flagged - yes. Card retried too many times - yes.
What it cannot do - by construction - is ask whether this merchant shares a beneficiary account with four others onboarded the same quarter. That is not a threshold question. It is a topology question. Topology questions require a different kind of system entirely.
Fraudsters figured this out well before most vendors did. Distribute the activity. Rotate the devices. Split volume across enough legally separate entities that no single one ever crosses a line. The fraud does not disappear. It just stops looking like fraud to a system that checks one thing at a time.
This is not a tuning problem. You cannot fix it by adjusting thresholds or writing more rules. The limitation is structural. Rule-based systems evaluate entities and transactions one at a time. Fraud rings operate across entities and transactions simultaneously. That gap is precisely where organised fraud networks live.
The pattern is consistent whether you are operating in India, Southeast Asia, the UK, or the US.
Accommodation merchant networks: merchants onboarded under distinct KYC identities, operating in plausible business categories, processing transactions that look legitimate at the merchant level. The underlying purpose - washing funds from predatory lending, investment fraud, or impersonation scams - is invisible until you map the network.
Mule account clusters: dozens of individually clean accounts used as intermediate settlement nodes to obscure fund origins. Each account passes KYC. The network only becomes visible when relationships are mapped across time and transaction flow. This is exactly the pattern that mule network detection is designed to surface - not by checking individual accounts, but by connecting them.
Device and network clusters: multiple merchant or customer accounts linked not by ownership documents, but by shared device identifiers, IP addresses, or network patterns revealing a common operational origin - despite apparent KYC separation.
In every case, the fraud is invisible at the entity level. It is only visible at the network level.
A graph maps entities as nodes - merchants, customers, accounts, devices, phone numbers, addresses - and relationships between them as edges. Graph-native network risk intelligence builds and continuously updates this map across your entire portfolio. Then it asks a different question.
A rules engine asks: is this entity suspicious?
Graph intelligence asks: is this entity connected to other entities in patterns consistent with known fraud network structures?
These are different analytical operations. Only the second can identify a fraud ring.
The capabilities that create the difference:
Payment aggregators sit on more relationship data than almost anyone else in the ecosystem. More merchant profiles, more account connections, more device fingerprints, more transaction flows than any single merchant or issuer ever sees.
A rules-only system treats all of that data as isolated records. It evaluates each merchant, each transaction, each account in isolation and misses every connection that matters. The same data that creates the blind spot in a rules-only system creates the biggest detection advantage for anyone asking relationship questions across it.
Regulators across markets have started making this expectation explicit. The RBI's Master Direction on Payment Aggregators in India, FCA guidance in the UK, and FinCEN expectations in the US are all moving toward continuous transaction monitoring and ongoing merchant surveillance - not point-in-time checks at onboarding. Most fraud stacks are still built for the old definition.
This is the specific problem Verafye was built to address.
When we were designing the platform, we kept hearing the same thing from payment aggregator risk teams: multiple systems generating signals, no way to connect them into one picture. Fraud worked from one alert queue. AML from another. When a ring operated across five merchants - different KYC, same device fingerprint, same beneficiary account - neither team ever saw the whole picture. Both had accurate information. Neither had complete information.
Verafye's graph-native network risk intelligence layer sits across both signal streams. It resolves entities - merchants, accounts, devices, counterparties - and maps relationships continuously across the portfolio. When the second merchant in a ring is onboarded, the connection to the first surfaces immediately. When an analyst opens a case, the network context is already assembled.
This is not a replacement for your existing fraud stack or AML monitoring. It is the investigation intelligence that connects them. The relationships the graph surfaces become documented case evidence - not visibility that disappears into a Slack message.
For payment aggregators specifically, this matters beyond detection. When an examiner asks for the investigation trail behind a suspicious merchant cluster, the graph evidence is there. The decision is traceable. The audit record exists - in one place, from signal to disposition.
If you want to see where the gaps are in your current signal coverage before the next audit cycle, the Verafye Risk Shadowing Review is a practical starting point. A scoped pilot, no commitment required.
An examiner does not care how many alerts your system generated last quarter. They care whether you can trace one case - start to finish - with a documented rationale connecting the fraud signal to the AML disposition.
If your fraud team and AML team work from systems that never talk to each other, you cannot produce that trail on demand. You will produce two half-stories and hope nobody notices they do not connect.
They will notice. That is the job.
Every quarter you run rules alone is a quarter where the network gets one layer more distributed and one layer harder to see in hindsight. The chargebacks eventually tell the story your monitoring should have told first. By then the money has usually left.
The question worth sitting with is not whether your rule engine is good. It probably is. The question is whether it was ever the right tool for a problem that lives between entities, not inside them.
Graph intelligence analyzes the relationships between entities - merchants, customers, devices, bank accounts, and counterparties - rather than evaluating transactions in isolation. It surfaces hidden connections and identifies organized fraud networks that traditional rule-based systems miss entirely. It is particularly effective against fraud rings, mule account networks, and coordinated merchant collusion schemes.
Rule-based detection applies predefined conditions to individual transactions or entities. It is effective against known, isolated fraud patterns. Graph intelligence asks relationship questions - which merchants share devices, which accounts route through the same beneficiary, which entities cluster near confirmed fraud cases. These are fundamentally different analytical operations, and only one of them can detect organized fraud networks operating across multiple entities simultaneously.
Payment aggregators hold more relationship data across merchants, customers, and payment flows than almost any other participant in the ecosystem. A rules-only system treats that data as isolated records. Graph intelligence turns it into a network map - revealing fraud rings that would be invisible to any entity-level review. The data advantage already exists. Graph intelligence is the mechanism that activates it.
No. It extends them. Graph intelligence adds a relationship layer to the signals your existing systems already generate. The combination - entity-level detection plus network-level visibility - closes the gap that organized fraud exploits. Most payment aggregators integrate graph intelligence as an additional layer, not a rip-and-replace of existing infrastructure.
Strong indicators include: rising fraud losses despite existing controls, recurring mule account activity that appears only after settlements clear, fraud spanning multiple merchants or payment channels simultaneously, high false-positive rates on legitimate merchants, or regulatory pressure to demonstrate continuous monitoring. Any of these signals suggests that fraud has evolved beyond what isolated entity review can catch.
Regulators increasingly expect fraud and AML investigation workflows to be operationally connected, not running in parallel silos. Graph intelligence supports this by making network relationships visible across both fraud and AML signals. When a fund flow pattern matches money laundering typologies and connects to a known fraud network, a connected investigation workflow lets your team trace that relationship and document the decision in one place. That is the audit trail examiners are looking for.
Sudeendra
Co-Founder & COO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.