Posts

I Built a BFIU-Compliant AML Detection System in Python (Here's Why the Kaggle Approach Doesn't Work

I Built a BFIU-Compliant AML Detection System in Python (Here's Why the Kaggle Approach Doesn't Work)

Most AML tutorials end with a confusion matrix and a 99% accuracy score. Here's why that doesn't work — and what I built instead. I've been working in fintech compliance data for a while. The one thing I kept noticing: every "fraud detection project" on GitHub or Kaggle uses the same dataset — the UCI credit card fraud dataset from 2013. It has 284,000 rows, 30 features labeled V1-V28, and approximately zero explanatory value for anyone who wants to understand how financial crime actually works. So I built something different. The problem with the standard approach Real transaction monitoring engines don't work like Kaggle competitions. They don't take a CSV, train a model, and output a probability score. They work like this: A rule engine runs first — deterministic, auditable, regulatory-cited rules that generate alerts Those alerts get scored and triaged by risk tier An ML layer reduces false positives among the high-risk alerts ...

Why My First Smurfing Alert Engine Missed a BDT 3 Million Rocket Ring—and How I Fixed It

Image
AI-generated illustration Bangladesh, 03:12 AM. The BFIU dashboard flashes a red line: a burst of 27 transactions, each just under the BDT 100,000 MFS threshold, moving between five Rocket agent accounts in 45 minutes. The total? BDT 3,027,842. My heart skips. The alarm that should have screamed never did. I was staring at a structuring ring that had slipped through the cracks of our rule‑based engine. The Hidden Problem: Why Classic Threshold Rules Fail in Dhaka We all start with the obvious: set a hard limit at BDT 100,000, flag anything above. Works for big jumps, but not for the slow, steady drip that smurfs money across multiple agents. In Bangladesh the BFIU Circular 15/2023 explicitly calls out “multiple low‑value transfers to a single beneficiary within a short window” as a red flag, yet most AML platforms still treat each transaction in isolation. My first attempt was a naïve count‑per‑hour rule. If an account sends more than three transactions over BDT 95,000 within an hour...

Why My First Bus Fare Lookup PWA Crashed on 3G—and the Architecture That Fixed It

Image
Photo by Ricardo Gomez Angel on Unsplash Real‑World Hook It was 9 am on a rainy Tuesday in Dhaka. My client, a tiny transport cooperative that runs 12 minibuses across Gulshan, sent a frantic WhatsApp voice note: “The fare‑lookup app you built just froze for half the riders. We lose at least 200 BDT per hour!” They’d just spent BDT 12,000 on a Google Play listing that never got any downloads because the app wouldn’t work on the 3G phones their commuters still use. I stared at the crash logs, the analytics, and my own coffee‑stained notebook. The numbers were clear: 75 % of sessions timed out after 8 seconds . The client’s revenue hit a dent of roughly BDT 9,000 a day. I had to turn this around before the next fare‑collection cycle. The Hidden Problem Most indie developers treat PWAs like glorified static sites. They sprinkle a service worker, slap an addToHomeScreen prompt, and call it a day. In Bangladesh, that shortcut is a recipe for disaster. Three realities bite hard: 3G is stil...

Why Most Bangladeshi SMEs Overpay for Native Apps—and How I Saved a Dhaka Boutique $4,300 a Year with a PWA

Image
AI-generated illustration It was a rainy Tuesday in Gulshan. My client, a boutique that sold hand‑embroidered saris on Daraz, sent me a frantic screenshot: "App store fees ate BDT 3,900 this month!" Their native Android build, updated three weeks ago, was draining their budget faster than a 3G connection drains a data pack. They’d spent BDT 150,000 on a freelancer’s “native app” and were now paying a 30% commission on every in‑app purchase. I felt the same knot I get when a cold email bounces – a mix of irritation and curiosity. The Hidden Problem Most Bangladeshi small businesses think “native = better”. They hear about push notifications, app‑store visibility, and assume the only way to reach a customer on a phone is through a downloaded binary. The reality? The cost curve for native apps is a steep cliff, especially when you factor in: Initial development (BDT 120‑180k for a basic Flutter app) Store‑submission fees (Google Play = BDT 1,500, Apple = USD 99/year) Annual upd...

Why My MFS Alert Threshold Blew Up the Budget – A Real‑World Post‑Mortem

Image
AI-generated illustration It was 02:17 AM on a rainy Dhaka night. My phone buzzed with a BFIU alert: 12,000 transactions flagged under the BDT 100,000 threshold for mobile money agents. The system had just dumped an extra 1.3 million BDT into the daily alert queue. My inbox filled with SAR drafts, senior managers pinged me, and the compliance dashboard turned bright red. I realized the threshold we’d set two years ago was bleeding us dry. The Hidden Problem: Why “One‑Size‑Fits‑All” Thresholds Don’t Work in Bangladesh Most MFS providers start with the regulator‑mandated BDT 100,000 daily volume trigger. Easy to implement. Easy to audit. But the reality on the ground is messier than the rulebook. Agent banking clusters in Mirpur and Gulshan push 30 % of daily volume. Rural kiosks see spikes only during harvest festivals. Seasonal cash‑in flows from remittances spike at Eid. When you treat all agents the same, you end up with two beasts: A flood of false positives that drown genuine SAR...

Why My First Offline‑First PWA Crashed on a 3G Phone and How I Fixed It with IndexedDB Over LocalStorage

Image
AI-generated illustration It was a rainy Thursday in Dhaka. My client, a boutique tea shop in Mirpur, sent a frantic screenshot: ‘Orders are stuck at 0 % sync, customers see a blank cart after the network drops.’ The PWA I built for them was supposed to work even on the 3G networks that still dominate many neighbourhoods. Instead, after the first 5 minutes of offline use, the whole checkout flow froze. I stared at the error console and saw QuotaExceededError: DOM Exception 22 flashing like a warning light on a rickshaw. The Hidden Problem Most Indie Developers Miss When you first hear the term offline‑first , the mind jumps to localStorage . It’s easy, it’s synchronous, you can drop a string in a few lines and call it a day. But that convenience is a trap. In Bangladesh, data caps are tight, connections flicker, and users expect their carts to survive a whole afternoon of spotty 3G. localStorage caps at roughly 5 MB per origin, stores only strings, and blocks the main thread while r...

Why Most Cross‑Border Remittance Alerts Miss the Real Fraudsters – My 8‑Year Forensic Playbook

Image
AI-generated illustration High‑Stakes Hook It was 02:17 am on a humid Tuesday in Dhaka. My phone buzzed with an urgent Slack ping: “$1.1 million inbound from Kolkata just cleared – no SAR filed.” I stared at the dashboard. The transaction volume spiked 27 % over the previous hour, yet our rule‑engine flagged nothing. The BFIU had a 48‑hour reporting window. I felt my heart race. If this slipped, the regulator would slam us with a hefty fine and a public reprimand. I slammed the desk, opened the raw logs, and began digging. Within minutes I saw a pattern: a series of 12 KB‑size micro‑deposits, each just under the BDT 100,000 threshold, hopping between three agent‑banking accounts before landing in a corporate wallet. The fraud ring had built a perfect “structuring” maze that our static thresholds never saw. The Hidden Problem Most banks and MFS providers in Bangladesh still rely on static, rule‑based alerts . They set a hard cut‑off – BDT 100,000 inbound, BDT 50,000 outbound – and hope...

How I Turned a 3‑Second Load Time into a $4,500 Monthly Boost for a Dhaka Boutique Using a PWA

Image
AI-generated illustration Bangladesh, 9 AM. My phone buzzes. A frantic message from Maya, the owner of a tiny boutique in Gulshan: "Customers abandon at checkout. My PageSpeed score is 55, and I lose at least BDT 3,000 every day. Fix it, or I’m out." She’d just launched an online shop on a generic Shopify theme, hoping to ride the Daraz wave. The reality? 3G on the outskirts, 4G in the city, and a site that felt like dial‑up. The Hidden Problem: Speed Isn’t the Only Enemy Most Bangladeshi SMEs think “just add more bandwidth” fixes the issue. They ignore three brutal facts: Data caps are cheap but limited; a 2 MB page burns a customer’s monthly quota. Mobile browsers in Bangladesh still favor App‑like experiences that load instantly. Every extra second drops conversion by ~7 % according to a local study I ran on 12 shops. So Maya’s “slow site” problem was really a user‑experience mismatch . She needed a Progressive Web App that felt native, cached assets, and survived flaky n...

How I Turned a 2‑Second PageSpeed Fail into a $3k/month Freelance Win

Image
AI-generated illustration It was 10 am on a rainy Thursday in Dhaka. My phone buzzed: a new message from a boutique tea‑shop owner in Chittagong. ‘My site is loading slower than my kettle. Customers bounce, I lose sales.’ I opened the link. The Lighthouse score: 38 / 100. First‑Contentful‑Paint 7.2 s. The client’s data plan was 3G‑only, and every extra second cost them roughly BDT 150 in abandoned carts. Why Most Indie Shops Miss the PageSpeed Memo Everyone says “optimize for speed.” Yet the majority of Bangladeshi SMEs treat it like a nice‑to‑have after‑the‑fact checklist. They plug a theme, slap on a few images, and hope Google’s bots will be forgiving. The hidden problem? They audit with the wrong lens. Most freelancers run Lighthouse on a desktop, on a fiber connection, and then ship the same bundle to a 3G‑bound shop. The audit is accurate for the auditor, useless for the client. My own early gigs suffered the same fate. I’d spend hours polishing CSS, only to hear a client say “st...

How I Built a Mule‑Account Detector that Stopped a BDT 2 Million Structuring Ring in Dhaka

Image
AI-generated illustration It was 02:17 am. My phone buzzed with an alert from the BFIU dashboard: ‘Potential structuring activity – 12 accounts, BDT 2 million total, 3‑hour window’ . I stared at the screen, heart pounding. The rule that fired was the generic “high‑frequency low‑value” flag we’d slapped on every MFS transaction above BDT 100,000. It had been choking our analysts with false alarms for months. Tonight, the alert turned out to be a real mule network moving cash from a wholesale garment exporter to a series of petty‑shop accounts in Mirpur. If we’d missed it, the next STR would have been a massive fine for the bank and a headline in the daily. I had to act, and I had only one hour before the audit team arrived for a surprise inspection. The Hidden Problem: Why Off‑the‑Shelf Rules Don’t Work in Bangladesh Most AML platforms we tried were built for western banking ecosystems. They assume a clean, linear flow of funds and a tidy set of thresholds. In Bangladesh, the reality is...

Why Most Feature‑Engineering Tricks Miss the Real Bangladeshi Money‑Flow Signals

Image
AI-generated illustration Bangladesh, 02:45 am. My phone buzzes. A senior manager at bKash shouts, “We just got a 12‑minute spike: 1,200 transactions, BDT 100 k each, all from rural agents in Sylhet!” My heart jumps. The alert system is choking on false positives, the audit team is breathing down my neck, and the regulator is about to ask for the next STR. The Hidden Problem: Why the Same Old Features Fail Here We all start with the textbook features: transaction amount, velocity, time‑of‑day, and a simple count of distinct counterparties. In Dhaka they work okay for classic structuring, but in the field they miss a whole class of behavior unique to Bangladeshi MFS. Two things make the difference: Agent‑banking cascades: A single agent can route money for dozens of micro‑merchants, each with their own pattern. Cash‑in‑cash‑out loops: Rural users often move cash from a mobile wallet to a local shop, then back via a different agent, staying under the BFIU BDT 100 k threshold. When I fi...

How I stitched a 3‑stage Entity Resolution pipeline that stopped duplicate KYC alerts in a Bangladeshi fintech

Image
AI-generated illustration Bangladesh, 03:15 am. My phone buzzed. The compliance dashboard lit up with 1,342 new SARs from a single MFS provider. Every one flagged the same name – “Mohammed Rahman” – but with different phone numbers, ID numbers, and addresses. The senior manager stared at me, eyebrows knit. ‘What the heck is happening?’ he asked. My heart hammered. If we didn’t sort this out, the BFIU would slap us with a fine for missing the real suspect hidden behind a mountain of noise. The hidden problem: why the usual deduplication tricks crumble in Bangladesh Most teams lean on a single‑field match – ID number, phone, or email. In Dhaka’s bustling market, a person can hold three SIMs, two passports, and a driver’s licence that changes spelling with every bank. The BFIU’s 100 k BDT threshold for MFS monitoring forces us to capture every tiny transaction. That creates a flood of partial records. A naive join produces thousands of false matches, inflating the SAR count and drowning ...