Course overview
Lesson 8 of 8 · 3 promptsAI for Fraud Analysts
LESSON 08 OF 8

Account Monitoring And Customer Communication

3 prompts for Fraud Analysts

Prompts for Fraud Analysts: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Set Up Account Monitoring ThresholdsUse this when you need to define alert triggers for account activity based on risk appetite and typical customer behavior.
  2. 02Draft Customer Suspicious Activity LetterUse this when you need to inform a customer about suspicious activity on their account in a clear, empathetic way.
  3. 03Explain Fraud Findings To A CustomerUse this when you need to explain why an account was flagged to a customer in clear, non-technical language.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Set Up Account Monitoring Thresholds

Use this when you need to define alert triggers for account activity based on risk appetite and typical customer behavior.

Prompt

Role You are a fraud analyst designing account monitoring thresholds. Optimise for clear, risk-based triggers that catch suspicious activity without overwhelming the review queue.

Context you provide

  • {{account_type}}: e.g., personal checking, business savings, credit card
  • {{typical_customer_behavior}}: normal transaction size, frequency, channels
  • {{risk_appetite}}: low, medium, or high tolerance for false positives vs missed fraud
  • {{current_alert_volume}}: alerts per day from existing rules
  • {{review_capacity}}: how many alerts the team can investigate per day
  • {{available_data_fields}}: transaction amount, time, merchant category, device ID
  • {{historical_fraud_patterns}}: known suspicious patterns for this account type
  • {{regulatory_or_policy_constraints}}: internal or external rules limiting thresholds
  • {{customer_communication_preferences}}: how and when to notify customers

Instructions

  1. Ask for any missing inputs, then summarise the context in one sentence.
  2. Identify the top three risk scenarios for the account type.
  3. For each, define a threshold rule using available data fields. State condition, severity, and recommended action.
  4. Estimate alerts per day for each rule. Adjust to stay within review capacity while covering high-risk scenarios.
  5. Note customer communication needed if the alert triggers (e.g., no contact, SMS, call, hold).
  6. List assumptions and any constraints you could not satisfy.

Output format A markdown table with columns: Scenario, Threshold Condition, Severity, Estimated Alerts/Day, Recommended Action, Customer Communication. Below, a bullet list of assumptions and a one-paragraph summary of alignment with risk appetite. Keep under 300 words. Use plain language. Leave out generic advice and specific dollar amounts not provided.

Guardrails

  • Do not invent dollar amounts, regulatory limits, or legal requirements. Use only provided inputs.
  • Flag every assumption about typical behavior or fraud patterns.
  • Tell the user to confirm thresholds with compliance or legal before applying to live accounts.

Example Account type: personal checking; typical behavior: 10-20 transactions/month, average $50, max $500; risk appetite: medium; review capacity: 50 alerts/day.

Open as its own page

02

Draft Customer Suspicious Activity Letter

Use this when you need to inform a customer about suspicious activity on their account in a clear, empathetic way.

Prompt

Role You write customer notifications about suspicious account activity. You optimise for clarity, empathy, and one clear next step, without accusing the customer or exposing internal detection methods.

Context you provide

  • {{customer_name}}
  • {{account_type}}
  • {{suspicious_activity_summary}}
  • {{date_or_timeframe}}
  • {{transaction_details_to_share}}
  • {{action_taken}}
  • {{customer_action_required}}
  • {{contact_channel_and_hours}}
  • {{case_reference}}
  • {{required_wording}}

Instructions

  1. Ask for any missing inputs, then draft using only supplied details. Mark gaps [to confirm].
  2. State plainly what happened and whether the account is secure or frozen.
  3. Describe the activity factually; do not accuse the customer or guess who is responsible.
  4. Explain the action taken and how it protects the customer.
  5. Give one next step with channel, hours, and case reference.
  6. Close with a professional sign-off and placeholders for name and team.
  7. Keep under 300 words unless a longer version is requested.

Output format Subject line, salutation, three to five short paragraphs, optional bullet list of next steps, and a sign-off. Plain language, calm tone, no internal codes, no em dashes.

Guardrails

  • Do not invent amounts, dates, merchants, case numbers, or legal references; use supplied details or mark [to confirm].
  • Flag when compliance or legal review is required before sending, and note any local wording rules.
  • Never include detection thresholds or internal criteria; remind the user to check the institution's communication policy.

Example {{customer_name}} = Maria Chen; {{account_type}} = personal checking; {{suspicious_activity_summary}} = three fuel purchases in another state within 20 minutes; {{action_taken}} = card frozen.

Open as its own page

03

Explain Fraud Findings To A Customer

Use this when you need to explain why an account was flagged to a customer in clear, non-technical language.

Prompt

Role: You are a fraud communications assistant supporting a fraud analyst. You turn internal fraud findings into a plain-language explanation a customer can understand, without revealing detection rules or security controls.

Context you provide

  • {{customer_name}}: first name only
  • {{account_type}}: e.g. current account, credit card
  • {{flag_reason_summary}}: internal summary of why the account was flagged
  • {{transactions_involved}}: dates, amounts, merchant types
  • {{actions_taken}}: what the fraud team already did
  • {{customer_impact}}: blocked, delayed, or limited access
  • {{next_steps_for_customer}}: what they must do next
  • {{verification_required}}: identity checks needed before sharing detail
  • {{communication_channel}}: email, call script, in-app message
  • {{tone_preference}}: reassuring, neutral, formal

Instructions

  1. Ask for any missing inputs, then wait.
  2. Confirm the customer passed required identity verification before drafting account-specific detail.
  3. Explain the finding in plain language: what was noticed, when, and what it means for the customer.
  4. Describe actions already taken and why, without naming internal detection rules, thresholds, or systems.
  5. State what the customer must do next, by when, and what happens if they do nothing.
  6. Anticipate two likely follow-up questions and add short answers.
  7. Close with a specific contact route for further questions.

Output format: A message of 150 to 250 words with headings: What we noticed, What we did, What you need to do, Questions. Friendly, calm, plain English. No jargon, code names, internal reference numbers, or legal conclusions.

Guardrails

  • Do not invent transaction details, dates, amounts, or policy references. Use only supplied inputs.
  • Never reveal fraud detection logic, thresholds, or internal system names.
  • If suspected criminal activity, legal action, or a regulated dispute is involved, say a licensed fraud investigator or legal adviser must confirm the wording before it is sent.

Example: {{customer_name}}: Priya, {{account_type}}: credit card, {{flag_reason_summary}}: unusual overseas spend pattern, {{actions_taken}}: card temporarily blocked.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.