The four layers Inside a score Assistant Governance Data foundation Who it's for Book a conversation

Risk analytics platform

Intelligence you can
explain, audit, and trust.

Zua.ai layers rules, statistics, machine learning and AI assistance into one governed intelligence layer — so every score, every summary and every recommendation can be traced back to evidence, not just a black box.

  • 0trust layers, kept deliberately separate
  • 0%of scores carry reason codes
  • 0decisions made without a human path

01 — Why we build AI differently

Most institutions have been shown an AI product that overpromised.

That's why we don't lead with "AI" as the headline — we lead with what our risk analytics can actually prove. We separate what we offer into layers, each with a different level of trust and a different job to do.

LAYER 01Most explainable

Rules-based controls

The most explainable layer. Used to enforce known policy in real time — every trigger is a rule you wrote, versioned and logged.

// policy, enforced in real time
IF amount > 3× baseline
AND device = unrecognised
THEN hold_for_review()
// rule R-118 · v187 · logged
LAYER 02Value from day one

Statistical baselines

Trend and threshold analysis that adds value from day one — without needing any historical data specific to you.

LAYER 03Earns its place

Predictive machine learning

Risk scoring that has to earn its place. It requires real training and validation data — and we won't claim it's accurate until it's been proven against your own outcomes.

validated against your outcomes
LAYER 04Human-supervised

AI / LLM assistance

A natural-language layer for summarising, explaining, and investigating. It supports the people making decisions — it never makes decisions on its own.

Why was this transaction flagged?
Amount is 8.2× the account's 90-day baseline, from a new device. Rules R-118 and R-204 triggered…

02 — Predictive risk scoring

Every score arrives with its reasons attached.

As your institution builds up its own data with us, Zua.ai builds predictive models that generate a risk score for accounts, members, transactions, and staff activity. Hover any guarantee to see where it lives in the response.

01A risk level and a recommendation

Not just a number — every score tells the analyst what to do next.

02Reason codes for every score

A score without a reason can't be acted on by an analyst — or defended to an auditor.

03Model version & rules triggered

So every output is traceable to exactly what produced it.

04Timestamp & correlation ID

Any decision can be reconstructed later, end to end.

POST /v1/scores · response
{  "entity": "txn_7f2e91",  "score": 87,  "risk_level": "HIGH",  "recommendation": "HOLD_AND_REVIEW",  "human_review_path": true,  "reason_codes": [    { "code": "RC-011", "reason": "new device" },    { "code": "RC-207", "reason": "amount 8.2x baseline" },    { "code": "RC-030", "reason": "velocity spike" }  ],  "model_version": "v2.4.1",  "rules_triggered": ["R-118", "R-204"],  "processed_at": "2026-08-13T08:42:17.204Z",  "correlation_id": "9f3e04c8-2f1a-4b21"}

Scores are made available through an API, so they plug straight into your own workflows and systems.

03 — AI assistant for investigations

Analysts move faster when the evidence explains itself.

Investigations generate a lot of evidence — transaction histories, case notes, prior alerts. Zua.ai's AI assistant helps analysts move through it faster.

Case #4821 · investigation assistant
Summarise the evidence on this case so far.
Three alerts over 48h on account A-2203: a new-device login, a beneficiary added, then a transfer at 8.2× the 90-day baseline. Two prior cases on this member were closed as false positives — both on travel-related activity. sources: alerts 4811, 4816, 4821 · case notes · 90-day txn history
Why was the transfer itself flagged?
Rules R-118 (amount vs baseline) and R-204 (new beneficiary + new device) triggered, and the model scored it 87/100 — driven by RC-011, RC-207 and RC-030. sources: score 7f2e91 · rule log v187
  • Summarising case evidence — histories, notes and prior alerts condensed into what matters.
  • Answering natural-language questions about an account or event, grounded in your data.
  • Drafting investigation reports that analysts review, edit and own.
  • Explaining why something was flagged, in plain language anyone can defend.

What it will never do

Make a transaction decision on its own, or be the sole basis for an adverse action against a customer. It's built to support a human reviewer, not replace one.

04 — Model governance

How we keep AI accountable.

Every predictive model and every feature we use is:

Versioned

You always know which version of a model produced a given score.

Logged with every decision

The model version and rule version are recorded alongside every score, permanently.

Validated jointly with you

Acceptance thresholds and validation metrics are agreed before a model goes live — not after.

Monitored continuously

For drift, false positives, and real-world outcome performance.

Explainable

Reason codes or equivalent explanations, appropriate to the type of model.

Paired with human review

Consequential or ambiguous cases always have a path to a human, not just a machine.

Before real-time automated decisions are ever switched on

If Zua.ai ever moves toward real-time, automated decisions, additional safeguards apply first:

✓ defined response-time guarantee ✓ explicit fallback on timeout ✓ full audit trails ✓ tested rollback for models & rules ✓ staged rollout — shadow & limited traffic ✓ manual override, always available & logged

05 — The data foundation behind the AI

AI is only as good as the data underneath it.

Zua.ai is built on a layered data model, so every insight can be traced back to where it came from.

The evidence locker raw data

Exactly what was received from each source system — preserved so nothing is ever lost, and everything can be replayed and reconstructed later.

The common language standardised

Raw data normalised into one consistent, cross-system view of accounts, members, and activity.

The answer business-ready

The polished datasets that power dashboards, reports, APIs, and the AI and ML features themselves.

Features model inputs

Reusable, purpose-built signals — behavioural averages, activity velocity and similar — feeding both model training and live scoring.

Traceability is a design choice,
not an afterthought.

Any output — a score, a flagged case, an AI-generated summary — can always be traced back to the exact source data behind it. The pulse you see travelling the pipeline is the same path an auditor can walk, in reverse.

Replay & reconstruct: because raw evidence is preserved, any historical decision can be rebuilt exactly as it happened — inputs, features, model version and all.

06 — A true SaaS platform

Built to integrate anywhere.

  • Genuine multi-tenant SaaS

    Not a customised install per client. The platform is sized automatically to your institution's scale.

  • Certified connector framework

    Every integration is built on a reusable connector framework — connecting a new system is a configuration step, not a bespoke development project.

  • API-first onboarding

    Standard endpoints for scoring, decisions and data delivery — guided by a standard runbook, not a custom project each time.

api.zua.ai · versioned schemas · rate-limited
POST/v1/scoresscore an entity or transaction
POST/v1/decisionsrecord & retrieve decisions
GET/v1/deliveries/:datasetgoverned data delivery
GET/v1/scores/:id/evidencefull trace for any score
🔒 OAuth2 🔒 mTLS 🔒 API keys versioned schemas rate-limited

07 — Built for every risk-bearing institution

One foundation, every institution that carries risk.

Zua.ai's data model and control library are built around the entities every risk-bearing financial institution shares — accounts, transactions, members or customers, staff, channels, and devices.

Banks

Cross-channel transaction monitoring, reconciliation, and audit-ready controls at scale.

First built for

SACCOs

The sector the platform was first built around — from member risk to staff and branch oversight.

Lending & microfinance

Loan, account, and member risk visibility across the whole lending lifecycle.

Insurance

Extending the same correlation and control approach to policy, claims, and underwriting risk as that part of the platform is built out.

The same principle applies everywhere: correlate what your existing systems can't see on their own — and give every score, alert, and decision a traceable, auditable reason.

Closing the loop

Want to see what governed, explainable risk analytics looks like in practice?

Talk to us about how Zua.ai's rules, statistics, and machine learning layers work together — and where AI assistance fits into your own review process.