VaultAP Docs

Risk Rules Reference

VaultAP ships with a set of built-in risk rules. Each rule targets a specific fraud signal and carries a default weight that contributes to the invoice's overall risk score. Weights can be adjusted and rules can be enabled or disabled by administrators.

Rule weights are additive. When multiple rules fire on the same invoice, their weights are summed and capped at 100.

All Rules

RuleDescriptionDefault WeightMandatory Review
BLOCKED_VENDOR_MATCHInvoice vendor name closely matches a vendor that has been blocked45Yes
DUPLICATE_EXACTInvoice number and vendor match an existing invoice40No
INVOICE_NUM_REUSEThis invoice number was previously used by a different vendor35No
BANK_CHANGEVendor bank account differs from record on file30Yes
DUPLICATE_NEARInvoice closely resembles a recent invoice from the same vendor25No
NEW_VENDORNo prior invoices from this vendor on record25No
AMOUNT_OUTLIERInvoice amount significantly exceeds vendor average20No
NO_PO_MATCHNo purchase order number found on the invoice15No
ADDRESS_CHANGEVendor remit-to address differs from record on file15No
FREQUENCY_SPIKEInvoice frequency from this vendor is 3x above normal in the last 30 days10No
FLAGGED_VENDORThis vendor is currently flagged for review10No
ODD_TIMINGInvoice submitted outside normal business hours5No

BLOCKED_VENDOR_MATCH and BANK_CHANGE are mandatory review rules. An invoice that triggers either one cannot auto-clear regardless of its total score — these are the two patterns where a missed detection is most expensive.

Mandatory Review

Rules marked as Mandatory Review bypass the normal threshold routing. When a mandatory rule fires, the invoice is always sent to manual review — even if the total score falls below the auto-clear threshold.

BANK_CHANGE is the only rule with mandatory review enabled by default. Administrators can enable mandatory review on additional rules in the rule configuration settings.

Weight Guidelines

When adjusting rule weights, keep the following in mind:

  • 0 effectively disables the rule's contribution to the score (the rule still fires for audit purposes if enabled).
  • 1-10 is appropriate for low-signal indicators such as ODD_TIMING.
  • 11-25 suits moderate-confidence signals like NEW_VENDOR or NO_PO_MATCH.
  • 26-50 should be reserved for strong fraud indicators like BANK_CHANGE or DUPLICATE_EXACT.
  • Weights above 50 are possible but will dominate the score. Use with caution.

See Configuring Rules for instructions on adjusting weights and enabling or disabling rules.