Behavioural Analytics
Patterns used for experience, security and financial wellbeing
Interpret actions in context
Behavioural analytics studies sequences or patterns of activity. App navigation can reveal a confusing journey; payment velocity can support a fraud review; spending patterns can inform an optional budgeting tool. The same observation has different meanings in these contexts.
A hesitation, shared device or late-night login does not establish a personality, intent or vulnerability. Use behavioural evidence alongside the relevant business context and its uncertainty. Accessibility tools, intermittent networks, travel and unfamiliarity can produce patterns that resemble anomalies.
Define the use before collecting the stream
Specify which events are needed, why, how long they are retained and who may use them. Distinguish security monitoring, product research, marketing and wellbeing assistance. A security log should not automatically become a commercial targeting feed because it is technically available.
Capture event meaning and version, not just a button identifier. A “payment started” event is not “payment completed”. Avoid unnecessary sensitive content in session recordings, logs and analytics vendors. Masking visible fields should be checked across errors, exports and server-side data, not assumed from one screenshot.
Security actions and false positives
Risk indicators can support an allow, step-up, referral or restriction under the bank's policy. Tune thresholds against confirmed outcomes and legitimate friction. A blocked action is not automatically prevented fraud; a successful authentication does not prove absence of deception.
Provide suitable recovery or review routes and avoid circular checks that use compromised contact information. Analyse new devices and changed behaviour in relation to enrollment, permissions and payment history. Do not let a single anomaly permanently determine a customer's access without the appropriate process.
Experience and wellbeing uses
Repeated retries can identify a failed interface, not a highly engaged user. Join behavioural patterns with error reports and qualitative research to find the cause. A redesign should improve task completion and understanding, with accessibility considered explicitly.
Wellbeing features may offer customer-controlled reminders or budgeting information. Avoid diagnosing distress or medical conditions from spending categories. Sensitive inference and automated significant decisions require assessment under applicable rules. Offering support and selling credit are distinct actions with distinct incentives.
Worked example: slower payment entry
In this fictional app, customers using an accessibility tool take longer to enter payment details and revisit fields. A risk rule flags many of them for extra authentication. Investigation finds that the pattern reflects interface interaction rather than confirmed fraud.
The team reviews the rule, improves accessible entry and monitors both security outcomes and legitimate completion. Simply forcing faster entry would penalise the customers and could increase payment mistakes. A controlled pilot includes affected users and a clear rollback route.
Models and monitoring
Validate behavioural features against the actual intended outcome, including drift as app designs change. A redesigned screen can alter event sequences without changing customer risk. Version features and thresholds and monitor missing events so that broken instrumentation does not masquerade as improved performance.
The US agencies' revised model-risk guidance, SR 26-2, issued in April 2026, replaces SR 11-7 and SR 21-8 and emphasises a tailored risk-based approach. Its applicability is scoped; it is not a universal law for every analytics service.
Takeaway
Behavioural patterns support a question, not a complete judgement about a person. Purpose, context, uncertainty and observed outcomes determine whether the resulting action is useful and defensible.
Continue to Data Monetisation.