CyberTRIZPEDIA

ETQ013

Implement layered detection with contextual risk scoring to preserve sensitivity while feeding investigation results back to refine alert thresholds.

CyberTRIZ analysis · Audit contradiction ETQ013 · one of 8,235 worked contradictions published by CyberTRIZ.AI

Regulations

Exception Detection vs False Positives

Business ContextAnalytics and automated testing can identify large numbers of unusual transactions, control deviations, or risk indicators. Increasing detection sensitivity can reveal more genuine problems, but it can also generate excessive false positives that consume investigation capacity and reduce confidence in the testing process.

Audit TRIZ ResolutionUse layered detection rather than one universal threshold. Broad screening identifies potential exceptions, while contextual rules, risk scoring, historical patterns, and secondary validation progressively distinguish significant conditions from normal variation.

Applicable TRIZ Principles

Principle 1 – Segmentation separates initial detection from subsequent validation and prioritization.

Principle 23 – Feedback uses investigation results to refine detection rules and thresholds.

Principle 35 – Parameter Changes adjusts analytical sensitivity according to risk, transaction type, and observed performance.

Expected Outcome

Higher-quality exception detection

Fewer false positives

Better investigation productivity

Preserved detection sensitivity

Decision Indicators

Most analytical alerts are closed without identifying meaningful issues.

Auditors spend substantial time investigating routine transactions.

Users begin ignoring automated alerts because volumes are excessive.

Detection thresholds are reduced simply to control workload.

Significant exceptions remain hidden within large alert populations.

TRIZ principles applied

P1 SegmentationP23 FeedbackP35 Parameter changes