VaultAP Docs

How Risk Scoring Works

VaultAP uses a deterministic, rules-first approach to fraud detection. Every invoice is evaluated against a defined set of rules, each carrying a numeric weight. There is no black-box AI making decisions — the score is fully transparent and auditable.

AI is used only to generate plain-language explanations of flagged invoices. It never influences the score or makes approval decisions.

How the Score Is Calculated

When an invoice enters the system, VaultAP evaluates it against every enabled rule. Each rule that fires contributes its configured weight to the total score.

Rules are evaluated

Every enabled rule is checked against the invoice data. Rules examine attributes such as vendor history, amount patterns, bank details, and OCR confidence.

Weights are summed

The weights of all triggered rules are added together. For example, if BANK_CHANGE (30) and ODD_TIMING (5) both fire, the raw sum is 35.

Score is capped at 100

The final score is capped at a maximum of 100, regardless of how many rules fire. A score of 0 means no rules triggered.

Routing Based on Score

Once a score is calculated, VaultAP routes the invoice into one of three buckets:

OutcomeConditionWhat happens
Auto-clearedScore is at or below the auto-clear thresholdInvoice proceeds without manual review.
Standard reviewScore is above auto-clear but below high-alertInvoice is queued for reviewer attention.
High-alertScore meets or exceeds the high-alert thresholdInvoice is escalated and flagged prominently in the dashboard.

The default auto-clear threshold is 25 and the default high-alert threshold is 70. Anything scoring 25 or below clears automatically, 26 to 69 is queued for review, and 70 or above is treated as a high alert. Both thresholds are configurable and work in tandem with dynamic calibration.

Dynamic Thresholds

After your organization has processed 100 or more invoices, VaultAP can automatically calibrate thresholds using your historical data. The system targets the top 5-8% of invoices as high-alert, adjusting weekly to reflect your actual risk distribution.

You can switch between automatic and manual threshold modes at any time. See Dynamic Thresholds for a full breakdown.

Mandatory Review Rules

Certain rules bypass threshold logic entirely. When a mandatory review rule fires, the invoice always requires human review regardless of the total score.

Two rules are mandatory by default: BANK_CHANGE and BLOCKED_VENDOR_MATCH. An invoice triggering either one is routed to manual review even when its overall score falls below the auto-clear threshold, and it cannot be cleared automatically at any score.

Mandatory review ensures that high-risk scenarios — such as bank detail changes, which are a leading vector in invoice fraud — are never silently approved.

Summary

  • Scores are the sum of triggered rule weights, capped at 100.
  • Routing uses two thresholds: auto-clear (default 25) and high-alert.
  • Dynamic calibration adjusts thresholds automatically after 100 invoices.
  • Mandatory review rules always force human review, regardless of score.
  • AI generates explanations only — it never makes decisions.