ETQ013
Implement layered detection with contextual risk scoring to preserve sensitivity while feeding investigation results back to refine alert thresholds.
CyberTRIZ analysis · Audit contradiction ETQ013 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Exception Detection vs False Positives
Business ContextAnalytics and automated testing can identify large numbers of unusual transactions, control deviations, or risk indicators. Increasing detection sensitivity can reveal more genuine problems, but it can also generate excessive false positives that consume investigation capacity and reduce confidence in the testing process.
Audit TRIZ ResolutionUse layered detection rather than one universal threshold. Broad screening identifies potential exceptions, while contextual rules, risk scoring, historical patterns, and secondary validation progressively distinguish significant conditions from normal variation.
Applicable TRIZ Principles
Principle 1 – Segmentation separates initial detection from subsequent validation and prioritization.
Principle 23 – Feedback uses investigation results to refine detection rules and thresholds.
Principle 35 – Parameter Changes adjusts analytical sensitivity according to risk, transaction type, and observed performance.
Expected Outcome
Higher-quality exception detection
Fewer false positives
Better investigation productivity
Preserved detection sensitivity
Decision Indicators
Most analytical alerts are closed without identifying meaningful issues.
Auditors spend substantial time investigating routine transactions.
Users begin ignoring automated alerts because volumes are excessive.
Detection thresholds are reduced simply to control workload.
Significant exceptions remain hidden within large alert populations.