Controlling an interaction using online account opening indicators
A system can be used to control an interaction using online indicators. The system can receive an interaction request associated with an electronic account type and that can be initiated via a computing device via a network communication. In response, the system may identify a request restriction of a security profile of the entity by executing an interaction processing service. The system can use the request restriction to identify an authorized online account opening indicator. In response to determining that the electronic account type is not consistent with the authorized online account opening indicator based on the request restriction, the system can challenge the interaction of the interaction request. In response to determining that the electronic account type of the interaction request is consistent with the authorized online account opening indicator based on the request restriction, the system can initiate the interaction of the interaction request.
1 . A system comprising:
a processor; and
a memory including instructions that are executable by the processor for causing the processor to perform operations comprising:
receiving (i) an interaction request involving an electronic account type associated with an entity and (ii) a technique for requesting generation of the electronic account type, the interaction request being initiated over a network using a computing device;
in response to receiving the interaction request, identifying a request restriction associated with a security profile of the entity by executing an interaction processing service, the request restriction usable to identify a plurality of online account opening indicators that comprises a first indicator of a particular electronic account type and a second indicator of a particular technique used to request generation of the electronic account type;
in response to determining that (i) the electronic account type of the interaction request is not consistent with the particular electronic account type or (ii) the technique for requesting generation of the electronic account type is not consistent with the particular technique used to request generation of the electronic account type based on the request restriction, challenging an interaction associated with the interaction request;
outputting a first command executable to provide a multi-factor authentication challenge in response to the interaction request;
in response to determining that (i) the electronic account type of the interaction request is consistent with the particular electronic account type and (ii) the technique for requesting generation of the electronic account type is consistent with the particular technique used to request generation of the electronic account type based on the request restriction, initiating the interaction associated with the interaction request; and
outputting a second command executable to generate an account of the electronic account type associated with interaction request and the entity.
2 . The system of claim 1 , wherein the operations further comprise, in response to challenging the interaction associated with the interaction request:
transmitting a rejection notification to an entity device associated with the entity, wherein the rejection notification is configured to request an authentication from the computing device that is usable to verify an identity of a user of the computing device;
verifying the identity of the user based on the authentication received from the entity; and
in response to verifying the identity of the entity, initiating the interaction associated with the interaction request.
3 . The system of claim 1 , wherein the operations further comprise, subsequent to determining that the electronic account type of the interaction request is not consistent with the plurality of authorized online account opening indicators:
executing an artificial intelligence (AI) module configured to identify fraudulent activity by analyzing activity data from the interaction processing service using one or more machine-learning models; and
in response to identifying the fraudulent activity, transmitting a warning notification to alert the entity regarding the fraudulent activity associated with the interaction request.
4 . The system of claim 1 , wherein the operations further comprise, in response to challenging the interaction associated with the interaction request:
transmitting a warning notification to the entity using a verified contact preference, wherein the warning notification is configured to alert the entity regarding the electronic account type of the interaction request being inconsistent with the plurality of authorized online account opening indicators.
5 . The system of claim 1 , wherein the electronic account type includes a financial loan, an online security account, or a financial institution deposit account.
6 . The system of claim 1 , wherein the request restriction is adjustable by the entity using an entity device associated with the entity prior to and subsequent to initiating the interaction request, and wherein the operations further comprise, subsequent to identifying the request restriction associated with the security profile of the entity:
determining that the electronic account type of the interaction request renders the interaction request unauthorized based on the plurality of authorized online account opening indicators of the request restriction;
detecting an adjustment to the request restriction, wherein the adjustment is indicatable by the entity using a user interface of the entity device to access the security profile of the entity; and
in response to detecting the adjustment, determining that the electronic account type of the interaction request renders the interaction request authorized based on the adjustment to the request restriction.
7 . The system of claim 1 , wherein the operation of executing the interaction processing service comprises:
determining the security profile of the entity using an entity identifier associated with the entity, wherein the security profile includes the request restriction associated with controlling the interaction based on the electronic account type of the interaction; and
identifying the authorized online account opening indicator based on the request restriction; and
determining whether the authorized plurality of online account opening indicators of the request restriction is consistent with the electronic account type of the interaction request.
8 . The system of claim 1 , wherein:
the operation of receiving (i) the interaction request involving an electronic account type associated with an entity and (ii) the technique for requesting generation of the electronic account type comprises:
receiving metadata with the interaction request, identifying the electronic account type associated with the entity using a first subset of the metadata, and identifying the technique for requesting the generation of the electronic account type using a second subset of the metadata that is different from the first subset of the metadata, the second subset of the metadata including a geographic location tag indicating a location from which the interaction request originated; and
the operation of identifying the request restriction associated with the security profile of the entity by executing an interaction processing service comprises:
ascertaining, using at least a portion of the metadata of the interaction request, that the security profile is associated with the entity, generating a query configured to cause the security profile to provide a set of request restrictions based on the entity, receiving the set of request restrictions from the security profile in response to transmitting the query to the security profile, and extracting the request restriction from the set of request restrictions by determining that the request restriction is applicable to the interaction request and that other request restrictions included in the set of request restrictions are not applicable to the interaction request; and
the request restriction is a machine-learning model that is configured to generate a prediction indicating a likelihood of the interaction request being legitimate; and
the request restriction comprises a decision tree model that is configured to generate the prediction.
9 . The system of claim 1 , wherein the request restriction indicates a set of authorized electronic account types and a set of authorized techniques, and wherein the operations further comprise:
determining that the particular technique used to request generation of the electronic account type based on the request restriction is not included in the set of authorized techniques;
in response to determining that the particular technique used to request generation of the electronic account type based on the request restriction is not included in the set of authorized techniques and challenging the interaction associated with the interaction request, generating a warning notification that is configured to indicate that the interaction is challenged because the particular technique is not included in the set of authorized techniques;
transmitting the warning notification to an entity device associated with the entity, the warning notification including data that causes the entity device to display a user interface with a set of interactive fields to receive input from the entity, the set of interactive fields including a first field to request that the interaction be denied and a second field to request an adjustment to the request restriction;
receiving, via the second field of the set of interactive fields, input indicating a request by the entity for the adjustment to the request restriction associated with the security profile, the adjustment including a change to the request restriction that updates the set of authorized techniques to include the particular technique;
transmitting instructions to the entity device that cause the entity device to provide a multi-factor authentication challenge in response to receiving the input indicating the request for the adjustment;
authenticating the adjustment in response to receiving a successful output from the multi-factor authentication challenge from the entity device;
in response to authenticating the adjustment, updating the request restriction to create an updated request restriction that reflects the adjustment by augmenting the set of authorized techniques with the particular technique; and
determining, based on the updated request restriction, to initiate the interaction associated with the interaction request.
10 . A method comprising:
receiving, by a computing device, (i) an interaction request involving an electronic account type associated with an entity and (ii) a technique for requesting generation of the electronic account type, the interaction request being initiated over a network using a computing device;
in response to receiving the interaction request, identifying, by the computing device, a request restriction associated with a security profile of the entity by executing an interaction processing service, the request restriction usable to identify a plurality of online account opening indicators that comprises a first indicator of a particular electronic account type and a second indicator of a particular technique used to request generation of the electronic account type;
in response to determining that (i) the electronic account type of the interaction request is not consistent with the particular electronic account type or (ii) the technique for requesting generation of the electronic account type is not consistent with the particular technique used to request generation of the electronic account type based on the request restriction, challenging, by the computing device, an interaction associated with the interaction request;
outputting, by the computing device, a first command to provide a multi-factor authentication challenge in response to the interaction request;
in response to determining that (i) the electronic account type of the interaction request is consistent with the particular electronic account type and (ii) the technique for requesting generation of the electronic account type is consistent with the particular technique used to request generation of the electronic account type based on the request restriction, initiating, by the computing device, the interaction associated with the interaction request; and
outputting, by the computing device, a second command to generate an account of the electronic account type associated with interaction request and the entity.
11 . The method of claim 10 , further comprising, in response to challenging the interaction associated with the interaction request:
transmitting, by the computing device, a rejection notification to an entity device associated with the entity, wherein the rejection notification is configured to request an authentication from the computing device that is usable to verify an identity of a user of the computing device;
verifying the identity of the user based on the authentication received from the entity; and
in response to verifying the identity of the entity, initiating the interaction associated with the interaction request.
12 . The method of claim 10 , further comprising, subsequent to determining that the electronic account type of the interaction request is not consistent with the plurality of authorized online account opening indicators:
executing, by the computing device, an artificial intelligence (AI) module configured to identify fraudulent activity by analyzing activity data from the interaction processing service using one or more machine-learning models; and
in response to identifying the fraudulent activity, transmitting, by the computing device, a warning notification to alert the entity regarding the fraudulent activity associated with the interaction request.
13 . The method of claim 10 , further comprising, in response to challenging the interaction associated with the interaction request:
transmitting, by the computing device, a warning notification to the entity using a verified contact preference, wherein the warning notification alerts the entity regarding the electronic account type of the interaction request being inconsistent with the plurality of authorized online account opening indicators.
14 . The method of claim 10 , wherein the request restriction is adjusted by the entity using an entity device associated with the entity prior to and subsequent to initiating the interaction request, and wherein the method further comprises, subsequent to identifying the request restriction associated with the security profile of the entity:
determining, by the computing device, that the electronic account type of the interaction request renders the interaction request unauthorized based on the plurality of online account opening indicators;
detecting, by the computing device, an adjustment to the request restriction, wherein the adjustment is indicated by the entity using a user interface of the entity device to access the security profile of the entity; and
in response to detecting the adjustment, determining, by the computing device, that the electronic account type of the interaction request renders the interaction request authorized based on the adjustment to the request restriction.
15 . The method of claim 10 , wherein executing the interaction processing service comprises:
determining the security profile of the entity using an entity identifier associated with the entity, wherein the security profile includes the request restriction associated with controlling the interaction based on the electronic account type of the interaction; and
identifying the authorized online account opening indicator based on the request restriction; and
determining whether the authorized plurality of online account opening indicators of the request restriction is consistent with the electronic account type of the interaction request.
16 . A non-transitory computer-readable medium comprising program code executable by a processing device for causing the processing device to perform operations comprising:
receiving (i) an interaction request involving an electronic account type associated with an entity and (ii) a technique for requesting generation of the electronic account type, the interaction request being initiated over a network using a computing device;
in response to receiving the interaction request, identifying a request restriction associated with a security profile of the entity by executing an interaction processing service, the request restriction usable to identify a plurality of online account opening indicators that comprises a first indicator of a particular electronic account type and a second indicator of a particular technique used to request generation of the electronic account type;
in response to determining that (i) the electronic account type of the interaction request is not consistent with the particular electronic account type or (ii) the technique for requesting generation of the electronic account type is not consistent with the particular technique used to request generation of the electronic account type based on the request restriction, challenging an interaction associated with the interaction request;
outputting a first command executable to provide a multi-factor authentication challenge in response to the interaction request;
in response to determining that (i) the electronic account type of the interaction request is consistent with the particular electronic account type and (ii) the technique for requesting generation of the electronic account type is consistent with the particular technique used to request generation of the electronic account type based on the request restriction, initiating the interaction associated with the interaction request; and
outputting a second command executable to generate an account of the electronic account type associated with interaction request and the entity.
17 . The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise, in response to challenging the interaction associated with the interaction request:
transmitting a rejection notification to an entity device associated with the entity, wherein the rejection notification is configured to request an authentication from the computing device that is usable to verify an identity of a user of the computing device;
verifying the identity of the user based on the authentication received from the entity; and
in response to verifying the identity of the entity, initiating the interaction associated with the interaction request.
18 . The non-transitory computer-readable medium of claim 16 ,
wherein the operations further comprise, subsequent to determining that the electronic account type of the interaction request is not consistent with the plurality of authorized online account opening indicators:
executing an artificial intelligence (AI) module configured to identify fraudulent activity by analyzing activity data from the interaction processing service using one or more machine-learning models; and
in response to identifying the fraudulent activity, transmitting a warning notification to alert the entity regarding the fraudulent activity associated with the interaction request.
19 . The non-transitory computer-readable medium of claim 16 ,
wherein the operations further comprise, in response to challenging the interaction associated with the interaction request:
transmitting a warning notification to the entity using a verified contact preference, wherein the warning notification is configured to alert the entity regarding the electronic account type of the interaction request being inconsistent with the plurality of authorized online account opening indicators.
20 . The non-transitory computer-readable medium of claim 16 ,
wherein the request restriction is adjustable by the entity using an entity device associated with the entity prior to and subsequent to initiating the interaction request, and wherein the operations further comprise, subsequent to identifying the request restriction associated with the security profile of the entity:
determining that the electronic account type of the interaction request renders the interaction request unauthorized based on the plurality of authorized online account opening indicators of the request restriction;
detecting an adjustment to the request restriction, wherein the adjustment is indicatable by the entity using a user interface of the entity device to access the security profile of the entity; and
in response to detecting the adjustment, determining that the electronic account type of the interaction request renders the interaction request authorized based on the adjustment to the request restriction.