Fraud and AML glossary

Use these pages when you need a precise definition, then follow the product CTA for the Naiza API that implements the workflow.

What is AML screening?

AML screening checks customers, businesses, and counterparties against sanctions, PEP, and watchlists so teams can review possible matches.

What is sanctions screening?

Sanctions screening checks people and organizations against official restricted-party lists before onboarding or moving funds.

What is PEP screening?

PEP screening identifies politically exposed persons and related parties so teams can apply enhanced due diligence instead of an automatic block.

What is device fingerprinting?

Device fingerprinting builds a stable identifier from browser or app signals so fraud teams can recognize returning devices, multi-accounting, and account takeover.

What is a velocity check?

A velocity check counts how often an identifier acts inside a time window so teams can catch card testing, credential stuffing, and burst fraud.

What is account takeover (ATO)?

Account takeover is when an attacker uses stolen credentials or session tokens to use a legitimate account. Detect it with device, velocity, and login-event signals.

What is KYC (Know Your Customer)?

KYC is the identity collection and verification process. It is not the same as AML screening. Naiza screens names against watchlists during or after KYC.

What is customer due diligence (CDD)?

Customer due diligence is the risk-based process of identifying a customer, screening them, and deciding how much ongoing monitoring they need.

What is enhanced due diligence (EDD)?

Enhanced due diligence is extra scrutiny for higher-risk customers such as PEPs. A match is a trigger to collect more evidence, not an automatic block.

What is adverse media screening?

Adverse media is negative news used as a risk signal in due diligence. Naiza surfaces watchlist entries from documented sources, not a live news crawler.

What is chargeback fraud?

Chargeback fraud is a disputed payment that may be friendly fraud or stolen-card use. Prevent it with event context, device signals, and review trails.

What is card testing?

Card testing is burst authorization of stolen card numbers, usually for small amounts. Catch it with velocity rules on BIN, device, and IP.

What is transaction monitoring?

Transaction monitoring reviews payments and transfers over time for laundering and fraud patterns. It complements real-time event decisions.

What is watchlist screening?

Watchlist screening compares a customer or entity to sanctions, PEP, and other restricted-party lists, then routes possible matches into review.

What is OFAC screening?

OFAC screening checks names against U.S. Office of Foreign Assets Control lists. It is one sanctions list family inside a broader AML screening workflow.

What is KYB (Know Your Business)?

Know Your Business collects and verifies a company’s identity. AML screening then checks that company against watchlists. An AML API is not a company-registry KYB product.

What is fuzzy matching in AML screening?

Fuzzy matching finds watchlist names that are close but not identical—transliteration, missing middle names, or typos—so you catch possible matches without requiring an exact string.

What is ongoing AML monitoring?

Ongoing monitoring re-screens customers when watchlists change, instead of checking a name only at onboarding. It is how programs catch someone listed after they became a customer.

What is multi-accounting fraud?

Multi-accounting is when one person or device opens many product accounts to abuse bonuses, evade limits, or hide mule activity. Device intelligence is the usual detection signal.

What is credential stuffing?

Credential stuffing is automated login with stolen username/password pairs. Detect it with velocity, device novelty, and IP reputation on the login event—not with KYC.

What is promo abuse?

Promo abuse is farming sign-up bonuses, referral credits, or coupons with many accounts or stolen cards. Catch it with signup velocity, device linking, and payment-instrument reuse.

What is first-party fraud?

First-party fraud is when the legitimate account holder disputes a real purchase or misuses a product (friendly fraud, bonus abuse). It is not account takeover.

What is a money mule?

A money mule moves funds for someone else, often through a fintech account. Detection uses payout velocity, device sharing, and counterparty screening—not a KYC selfie alone.

What is IP reputation?

IP reputation scores whether an address is a datacenter, VPN, proxy, or known-abusive host. It is a supporting fraud signal, not a substitute for device intelligence.

What is VPN detection in fraud prevention?

VPN detection flags when an event likely comes through a virtual private network or proxy. Use it as a REVIEW signal with device context, not as a blanket block.

What is risk scoring in fraud detection?

Risk scoring ranks how suspicious an event looks so operations can order the REVIEW queue. The decision contract should still be ALLOW, REVIEW, or BLOCK with an explainable reason.

What is a false positive in fraud and AML?

A false positive is a REVIEW or BLOCK that a later investigation clears. Measure it before you tighten velocity, fuzzy matching, or denylists.

What is email reputation in fraud prevention?

Email reputation scores whether an address is disposable, previously abusive, or newly created. Use it on signup with device and velocity, not as a standalone block.

What is signup fraud?

Signup fraud is fake or farmed registrations used for bonuses, mule accounts, or card testing. Catch it with device linking, email reputation, and registration velocity.

What is payout fraud?

Payout fraud is abuse of withdrawals and disbursements—ATO cash-out, mule pass-through, or bonus extraction. Score the payout event with device, velocity, and counterparty screening.

What is device linking?

Device linking connects one fingerprint to many customer accounts so you can see multi-accounting, mule farms, and shared ATO tooling.

What is name transliteration in AML screening?

Name transliteration maps Arabic and other scripts to Latin (and back) so watchlist matching can still fire when spelling systems differ.

What is batch AML screening?

Batch screening checks many names in one job—migrations, overnight list deltas, or backfills. Pair it with real-time checks at onboarding and payout.

What is list management in fraud prevention?

List management is how you persist allowlists and denylists of customers, devices, emails, and IPs so later events fail closed or skip noisy rules.