TOS005
Use multi-stage detection with feedback-driven threshold refinement so sensitivity increases without creating unmanageable false-positive volumes.
CyberTRIZ analysis · Audit contradiction TOS005 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Automated Detection vs False Positives
Business ContextAutomated detection can identify unusual transactions and patterns across populations too large for manual review. Increasing sensitivity improves the probability of identifying genuine problems but can also produce large numbers of false positives that consume audit resources.
Audit TRIZ ResolutionUse multiple detection stages rather than one threshold. Broad screening identifies potential anomalies, while contextual rules, risk scoring, pattern analysis, and secondary validation progressively distinguish meaningful exceptions from normal variation.
Applicable TRIZ Principles
Principle 1 – Segmentation separates broad detection from exception validation.
Principle 23 – Feedback uses investigation results to refine detection logic.
Principle 35 – Parameter Changes adjusts sensitivity according to risk and observed performance.
Expected Outcome
Higher detection effectiveness
Fewer false positives
Lower investigation workload
Better analytical precision
Decision Indicators
Most automated alerts are ultimately determined to be normal activity.
Auditors begin ignoring alerts because volumes are excessive.
Detection thresholds are weakened primarily to reduce workload.
High-risk exceptions remain hidden within large alert populations.
Detection models are not refined using investigation outcomes.