Tenant Admins
Fraud and AML Monitoring
Review fraud alerts and anti-money-laundering cases, record outcomes, and understand how an open case affects seller payouts.
Babylon watches activity on your marketplace and raises two kinds of review item for your team. Fraud Alerts flag accounts behaving in ways that usually mean trouble. AML Cases (anti-money laundering) are opened automatically for high-value sales that need an identity-based check before money moves. Both live in the Post-Sale group. Neither needs switching on, and you never create an alert or case by hand.
This guide explains what you will see, how to work through each queue, and what each outcome does. It deliberately does not describe how detection works in detail: publishing that would make it easier to evade.
Before you start
- Fraud Alerts can be opened by staff whose role includes reviewing reports or moderating content. The Admin and Moderator roles can both open it.
- Recording an outcome on a fraud alert (Confirm Fraud or Dismiss Alert) currently needs the Admin role, or a custom role with report or ban permissions. A Moderator can open alerts and use Mark Under Investigation, but should ask an Admin to record the final decision.
- AML Cases needs the compliance permission, which the Admin role has. Anyone else sees a short explanation instead of the list.
- Both screens are included for every account. If you think you should see one and cannot, check your role in Team members and roles.
Fraud Alerts
Open Post-Sale → Fraud Alerts. The red badge in the sidebar is the total number of alerts on record, not just the ones waiting for review.
What gets flagged
Each alert has a type:
- Suspicious Bidding: bidding activity that may be an attempt to manipulate a sale, such as shill bidding.
- Payment Fraud: payment activity that may be fraudulent.
- Account Takeover: signs that an account may be in the wrong hands.
- Multiple Accounts: one person appearing to operate several accounts.
- Other: anything else worth a human look.
Each alert also carries a severity (Low, Medium, High or Critical), a description and some detection details. Treat severity as a guide to what to look at first, not as a verdict.
Finding alerts
The tabs across the top are All Alerts, Pending Review, Under Investigation, Confirmed Fraud, Dismissed, User Blocked and High Risk (high and critical severity). You can also filter by status, type, severity, user and Detected Date.
Click an alert to see its details, the review so far, and the flagged user's email, KYC Status, whether they are banned, and how old the account is. View User Profile in the row menu opens the user in a new tab.
Reviewing an alert
- Open the row menu and choose Mark Under Investigation when you start looking into a Pending Review alert. You can also select several alerts and use the bulk Mark Under Investigation action.
- Look at the user's profile, their bids, orders and identity check. See Identity verification.
- Record the outcome from the row menu, using one of the two actions below.
- Confirm Fraud: choose an Action to Take. No Further Action records the alert as Confirmed Fraud. Block User bans the account and records the alert as User Blocked. Add Notes to explain your reasoning.
- Dismiss Alert: enter Notes (required) explaining why it is not fraud. The alert moves to Dismissed.
Confirm and dismiss are only available while an alert is Pending Review or Under Investigation. Your name and the time are recorded against the decision.
Statuses
- Pending Review: new, nobody has looked yet.
- Under Investigation: someone is working on it.
- Confirmed Fraud: fraud confirmed, no further action taken on the account.
- User Blocked: fraud confirmed and the account banned.
- Dismissed: reviewed and found not to be fraud.
A confirmed fraud alert also stops the user from receiving the verified seller badge. To lift a ban later, use Unban User from the user's row menu in Audience → Users.
About the Edit button
Alerts also have an Edit button, which lets you change the status and review notes directly. Prefer the actions above: they record who reviewed the alert and when, and Block User actually bans the account, whereas changing the status by hand does neither.
AML Cases
Open Post-Sale → AML Cases. The badge counts cases waiting for your decision.
When a case is opened
When a sale completes and meets Babylon's high-value review rules, a case is opened automatically for the parties involved (the seller, the buyer, or both). The rules are set by Hammerd and are not configurable in the admin panel. If you have questions about when cases open for your account, contact Hammerd support.
Each case shows the Subject (the person being reviewed), the Trigger (which rule opened it), the linked Order, its status, and when it was Opened.
How a case affects payouts
While a sale has any AML case that is not Cleared, the seller's payout for that sale is held when it is scheduled. Escalated and Blocked cases keep it in place. Clearing the case stops it blocking the payout, but a payout that was already held is not released automatically: once the case is Cleared, someone with permission to execute payouts releases it with Mark Releasable on the payout in Post-Sale → Payouts. For more on payouts, see Orders, settlements and payouts.
Statuses
- Open: just opened, not yet screened.
- Screening: a screening run is in progress.
- Awaiting evidence: the subject has not verified their identity yet, so there is nothing to screen against. Ask them to complete identity verification.
- Under review: screening has finished and the case is waiting for your decision.
- Cleared: you are satisfied the sale can proceed.
- Escalated: you have passed the case on for further review, for example to your compliance officer.
- Blocked: you have decided the proceeds should not move.
Cleared, Escalated and Blocked are final. Once a case reaches one of them, the decision buttons are disabled.
Working a case
- Start with the Under review tab. Other tabs are Awaiting evidence, Open / screening, Escalated, Blocked, Cleared and All.
- For a case that is Open or Awaiting evidence, click Run screening. If the subject is now verified, the case moves to Under review. If not, it stays at Awaiting evidence.
- Open the case to read the Trigger reason, the order details, and the Identity evidence section, which shows the same identity information a KYC reviewer sees.
- Record your decision with one of the three row buttons below. Each shows the case briefing before you confirm.
- Clear: optionally add Notes (optional), then click Clear case. The case no longer blocks the payout. If the payout is already held, release it as described above.
- Escalate: explain in Why is this being escalated? (at least 10 characters), then click Escalate case.
- Block: explain in Why is this being blocked? (at least 10 characters), then click Block case. This holds the seller's remittance.
The Case history tab on each case records every status change, when it happened and who or what caused it.
What screening does today
Run screening checks that the subject is verified and then puts the case in front of a human reviewer. Babylon does not currently give an automated sanctions verdict: the decision to clear, escalate or block is always yours. Keep your own records of any external checks you carry out, and note them when you decide.
Common questions
A case has been at Awaiting evidence for days
The subject has not completed identity verification. Contact them and ask them to verify, then use Run screening. See Identity verification.
I confirmed fraud by mistake
Outcomes are final through the review actions. Contact Hammerd support if an alert was recorded incorrectly. If you blocked the user, you can unban them from Audience → Users.
Can I change what counts as suspicious or high value?
No. Detection and case rules are managed by Babylon for all accounts and are not published. Contact Hammerd support if you think something is being missed or flagged too often.