Citi Fraud Operations Specialist
C04 Position - Study Guide
Comprehensive Preparation Notes
Banking Terminology • Fraud Detection • Credit/Debit Cards
This guide is designed for MS Statistics graduates preparing for the Citi Fraud Operations Specialist (C04)
position. While Citi provides comprehensive training, this foundational knowledge will help you stand out in
interviews and accelerate your onboarding. Focus on understanding the concepts rather than memorizing
everything.
Table of Contents
1. Role Overview & What You Actually Do
2. Credit & Debit Card Fundamentals
3. Fraud Types & Detection
4. Banking & Payment Terminology
5. Transaction Lifecycle
6. Risk & Security Concepts
7. Key Metrics & KPIs
8. Interview Preparation Tips
1. Role Overview & What You Actually Do
Day-to-Day Responsibilities
Transaction Monitoring: Review flagged transactions in real-time fraud detection systems
Customer Contact: Call cardholders to verify suspicious charges and recent account activity
Investigation: Analyze patterns, review account history, and assess risk levels
Case Documentation: Record findings, decisions, and actions taken for each case
Decision Making: Approve or decline transactions, block cards, or escalate complex cases
Queue Management: Work through high volumes of alerts within time-sensitive deadlines
What Your Colleague Meant
Yes, your colleague is correct that "learn about credit and debit cards" covers the core of what you need initially.
The fraud detection systems, internal tools, and specific processes are all taught during training. However,
understanding the fundamentals beforehand helps you ask better questions, recognize patterns faster, and
demonstrate knowledge in interviews.
Skills You'll Use from Your Stats Background
Pattern Recognition: Identifying anomalies in transaction patterns
Data Analysis: Interpreting fraud scores, velocity checks, and behavioral analytics
Statistical Thinking: Understanding false positive rates and model confidence scores
Risk Assessment: Weighing probabilities when making fraud decisions
2. Credit & Debit Card Fundamentals
Card Types
<b>Card Type</b> <b>How It Works</b> <b>Risk Profile</b>
<b>Credit Card</b> Borrows from bank's credit line. Pay later withHigher
interest
fraud
if balance
risk - thieves
carriedcan
over.
make large purchases before d
<b>Debit Card</b> Withdraws directly from checking/savings account.
LowerImmediate
fraud amounts
deduction.
typically, but funds harder to recover
<b>Prepaid Card</b> Loaded with specific amount. Use until balance
Often
depleted.
used in fraud schemes, harder to trace
<b>Charge Card</b> Must be paid in full each month. No preset spending
Less common,
limit. similar fraud patterns to credit cards
Card Anatomy - What Each Number Means
Card Number Structure (16 digits):
• First digit = Major Industry Identifier (4=Visa, 5=Mastercard, 3=Amex, 6=Discover)
• First 6 digits = Bank Identification Number (BIN) - identifies issuing bank
• Next 9 digits = Account identifier
• Last digit = Check digit (validates card number using Luhn algorithm)
Expiration Date: Shows MM/YY when card expires. Fraud indicator if purchase attempts continue after
expiration.
CVV/CVC (Card Verification Value): 3-digit security code on back (4 digits for Amex on front). Used for
card-not-present transactions. Not stored in magnetic stripe - reduces fraud risk.
Magnetic Stripe: Contains Track 1 & 2 data - cardholder name, account number, expiration. Being phased out
for chip.
EMV Chip: Generates unique transaction codes - can't be copied like magnetic stripe. Significantly reduces
counterfeit fraud.
3. Common Fraud Types You'll Encounter
Card-Not-Present (CNP) Fraud
Fraudster uses stolen card details for online/phone purchases without physical card. Most common type.
Red flags: shipping to different address than billing, new account with large purchase, multiple failed CVV
attempts.
Account Takeover (ATO)
Fraudster gains access to legitimate account through phishing, data breach, or social engineering.
Changes contact info, adds authorized users, requests new cards. Red flags: sudden contact info changes,
unusual spending patterns, multiple login attempts from new locations.
Counterfeit Card Fraud
Physical card created using stolen card data. Declining with EMV chip adoption but still occurs. Red flags:
transactions in multiple geographic locations rapidly, chip-read failures followed by swipe.
Lost/Stolen Card Fraud
Physical card used by someone who found/stole it. Usually short window before cardholder reports. Red
flags: rapid succession of transactions, purchases inconsistent with profile, gas station + high-value retail
pattern.
Application Fraud/Identity Theft
Fraudster opens new account using stolen identity. You'll see this less in ops role - more in new accounts.
Red flags: address mismatches, synthetic identities (real SSN + fake personal info).
Friendly Fraud/First-Party Fraud
Legitimate cardholder makes purchase then disputes it claiming fraud. Growing problem in e-commerce.
Red flags: high-value electronics disputed, pattern of chargebacks, claims package never arrived.
Skimming
Device attached to ATM/POS terminal captures card data. Creates counterfeit cards. Red flags: multiple
cards compromised from same location, pattern of fraud from specific merchant category.
Phishing/Vishing
Social engineering to obtain card details. Calls/emails pretending to be bank. Not direct transaction fraud
but how credentials are stolen.
4. Essential Banking & Payment Terminology
Transaction Processing Terms
Authorization
When merchant requests approval for transaction. Card issuer checks: sufficient funds/credit, card not
blocked, within limits. Returns approval or decline code. Amount is 'held' but not yet charged.
Settlement
Actual movement of funds. Happens in batch, usually end of business day. Merchant receives money
(minus interchange fees), cardholder account is debited.
Clearing
Exchange of transaction details between banks. Happens between authorization and settlement.
Chargeback
Forced reversal of transaction initiated by cardholder through issuing bank. Reasons: fraud, service not
rendered, product not as described. Merchants can dispute chargebacks. Important metric for fraud teams.
Reversal
Cancellation of transaction, typically at merchant's request. Different from chargeback (which is
cardholder-initiated).
Declined Transaction
Authorization denied. Reasons: insufficient funds, suspected fraud, card blocked, incorrect PIN, expired
card.
Pending Transaction
Authorized but not yet settled. Shows on account but money not actually moved yet.
Card Network & Parties
Card Network/Payment Network
Visa, Mastercard, American Express, Discover. Facilitate communication between issuer and acquirer. Set
interchange fees and network rules.
Issuing Bank/Issuer
Bank that issues card to customer (e.g., Citi). Responsible for: approving/declining transactions, fraud
detection, customer service, billing.
Acquiring Bank/Acquirer
Bank that processes payments for merchants. Routes authorization requests to issuer through card
network.
Merchant
Business accepting card payments. Subject to merchant category codes (MCC).
Payment Processor
Third-party service connecting merchants to payment networks. Examples: Stripe, Square, First Data.
POS (Point of Sale)
Physical location/system where transaction occurs. Can be terminal in store or online checkout.
Account & Card Management Terms
Card-on-File
Merchant stores card details for recurring payments. Common fraud target.
Authorized User
Person given permission to use account but not financially responsible. Can be fraud vector.
Credit Limit
Maximum amount that can be borrowed on credit card. Fraud might cause over-limit.
Available Credit
Credit limit minus current balance and pending charges.
Statement Balance
Amount owed at end of billing cycle.
Minimum Payment
Smallest amount required to keep account in good standing.
APR (Annual Percentage Rate)
Interest rate charged on carried balances.
Cash Advance
Withdrawing cash using credit card. Higher fees, higher fraud risk.
Balance Transfer
Moving debt from one card to another. Can be fraud indicator if unusual.
Fraud-Specific Terminology
Velocity Checks
Monitoring frequency/speed of transactions. Red flag: 10 transactions in 30 minutes.
Geolocation Mismatch
Transaction location inconsistent with known patterns. Example: purchase in New York 1 hour after Tokyo
transaction.
BIN Attack
Fraudster tests multiple card numbers from same BIN to find valid accounts.
Card Testing
Small transactions to verify stolen card works before making large purchases.
True Positive
Correctly identified fraud. Good catch!
False Positive
Legitimate transaction flagged as fraud. Frustrates customers, key metric to minimize.
False Negative
Fraud that wasn't detected. Most dangerous - leads to losses.
Fraud Score
Algorithmic risk rating (0-100 or 0-999). Higher = more suspicious. You'll use this daily.
Rule-Based Detection
If-then logic (e.g., if transaction >$1000 AND international AND new merchant, flag it).
ML-Based Detection
Machine learning models identify patterns. More sophisticated than rules.
Whitelist
Trusted merchants/customers. Lower scrutiny.
Blacklist
Known fraudsters, compromised BINs. Auto-decline.
5. Transaction Lifecycle (Critical to Understand)
Understanding how a transaction flows from swipe to settlement helps you identify where fraud occurs and what
interventions are possible at each stage.
1. Customer Initiates Transaction
Swipes/inserts/taps card, or enters details online. POS terminal or website captures data.
2. Merchant Requests Authorization
Transaction details sent to acquiring bank, including: amount, merchant info, card details, timestamp.
3. Acquiring Bank Routes to Card Network
Visa/Mastercard network identifies issuing bank based on BIN.
4. Issuing Bank (Citi) Evaluates
THIS IS WHERE YOU WORK! Fraud system checks: available funds/credit, account status
(active/blocked?), fraud rules and ML models, velocity patterns, location anomalies. Returns authorization
response in seconds.
5. Authorization Response Sent Back
Approval code OR decline reason. Decline codes tell merchant why (insufficient funds, call issuer,
suspected fraud, etc.).
6. If Fraud Suspected - You Get Involved
Transaction flagged, appears in your queue. You review history, call customer, make decision: approve,
decline, request additional verification.
7. Merchant Completes Sale (if approved)
Customer receives goods/services. Receipt generated.
8. Settlement (End of Day)
Merchant submits batch of transactions to acquirer. Funds transferred from issuing bank to acquiring bank.
Customer account officially charged. This is when money actually moves.
9. Statement Posted
Transaction appears on customer's monthly statement.
10. Potential Dispute Window
Customer has 60-120 days to dispute charge. Chargeback process if they claim fraud.
6. Risk & Security Concepts
Authentication Methods
Chip & PIN (EMV)
Chip generates unique code per transaction. Can't be cloned. PIN adds second factor. Standard in most
countries.
Chip & Signature
Chip authentication but signature instead of PIN. Less secure, being phased out in US.
Contactless/NFC (Tap to Pay)
Uses same EMV chip technology wirelessly. Limited to lower amounts typically. Apple Pay, Google Pay
use this + device authentication.
3D Secure (3DS)
Online authentication. 'Verified by Visa', 'Mastercard SecureCode'. Adds password/SMS code for online
purchases. Reduces CNP fraud but can reduce conversion.
Two-Factor Authentication (2FA)
Something you know (password) + something you have (phone) or something you are (biometrics).
Biometric Authentication
Fingerprint, facial recognition, voice. Increasingly common in mobile banking apps.
Security Standards & Regulations
PCI DSS (Payment Card Industry Data Security Standard)
Required security standard for all entities handling card data. Covers: encryption, access controls, network
security, regular testing. Non-compliance = huge fines.
Encryption
Scrambling card data during transmission/storage. End-to-end encryption means data protected from POS
to bank.
Tokenization
Replacing card number with randomly generated token. Merchant stores token, not actual card number.
Reduces breach risk.
KYC (Know Your Customer)
Verification processes when opening accounts. Prevents identity theft.
AML (Anti-Money Laundering)
Monitoring for suspicious patterns that might indicate money laundering. Different team but related to fraud.
Regulation E
Federal regulation protecting consumers from unauthorized electronic fund transfers. Limits debit card
liability to $50 if reported within 2 days.
Regulation Z (Truth in Lending)
Protects credit card users. Zero liability for unauthorized charges if reported promptly.
7. Key Metrics & KPIs You'll Be Measured On
Fraud operations is data-driven. You'll be evaluated on these performance indicators:
Fraud Detection Rate
Percentage of actual fraud successfully identified and blocked. Target: >95%. Your statistical background
helps here!
False Positive Rate
Percentage of legitimate transactions incorrectly flagged. Target: <5%. Balance is key - can't block
everything.
Case Resolution Time
Average time to investigate and close a case. Speed matters - fraud moves fast. Typical target: <10
minutes per case.
Customer Contact Success Rate
Percentage of customers successfully reached for verification. Affects your ability to make informed
decisions.
Accuracy Rate
Decisions that were correct (approved legit, blocked fraud). Your most important metric.
Queue Clearance Time
How fast you work through assigned cases. Backlog hurts customer experience.
Escalation Rate
How often you need supervisor help. Lower is better as you gain experience.
Chargeback Rate
Percentage of transactions resulting in chargebacks. Indicates fraud that slipped through.
Fraud Loss Rate
Dollar amount of fraud losses as percentage of total transaction volume. Company-wide metric you
contribute to.
Red Flags to Watch For (Pattern Recognition)
• Multiple small transactions followed by large one (testing then exploiting)
• Transactions from multiple countries in impossible timeframes
• Purchase patterns inconsistent with account history
• High-risk merchant categories (electronics, gift cards, jewelry)
• Shipping address different from billing address (especially for new accounts)
• Multiple failed authorization attempts
• Sudden change in spending behavior (dormant account suddenly active)
• Round-dollar amounts (less common in legitimate purchases)
• Transactions at odd hours inconsistent with customer profile
• Gas station + high-value retail (common fraud pattern)
8. Interview Preparation Tips
Leverage Your Statistics Background
When discussing your qualifications, connect your stats knowledge to fraud detection:
• "My coursework in anomaly detection directly applies to identifying unusual transaction patterns."
• "I've worked with classification models which are fundamental to fraud scoring systems."
• "My experience with statistical hypothesis testing helps me assess the probability of fraud vs. legitimate
activity."
• "I understand the tradeoff between Type I errors (false positives) and Type II errors (false negatives), which is
critical in fraud detection."
• "I'm comfortable with concepts like sensitivity, specificity, and ROC curves that underpin fraud detection
models."
Sample Interview Questions
Q: What interests you about fraud detection?
A: Combine analytical skills with real-world impact. Every day presents new patterns to analyze, and
successful fraud detection directly protects customers and the bank's financial integrity. My statistics
background gives me the analytical foundation, and I'm excited to apply it in this dynamic field.
Q: How would you handle a high-stress situation with multiple urgent cases?
A: Prioritize based on risk and dollar amount. Time-sensitive cases with high fraud scores get immediate
attention. I'd maintain detailed documentation while working quickly, and escalate when appropriate rather
than making rushed decisions that could result in errors.
Q: What would you do if you're unsure whether a transaction is fraudulent?
A: Gather more data - review account history, check for similar patterns, attempt customer contact for
verification. If still uncertain, I'd escalate to a senior analyst rather than risk either approving fraud or
declining a legitimate transaction. It's better to ask than to guess.
Q: Tell me about a time you identified a pattern in data.
A: [Use example from coursework/projects]. Describe the dataset, the analytical method you used, the
pattern you identified, and the insight or action that resulted. Connect it to how this skill applies to fraud
detection.
Q: How do you balance speed with accuracy?
A: Focus on working efficiently rather than rushing. Develop systematic approach to case review - check
key indicators in consistent order. Build pattern recognition over time so decisions become faster naturally
while maintaining accuracy. Track my own metrics to identify improvement areas.
Questions to Ask Your Interviewer
• What fraud detection tools and systems does Citi currently use?
• What does a typical training period look like for new fraud analysts?
• How does the team stay current with emerging fraud trends?
• What's the balance between automated detection and manual review in your workflow?
• Can you describe a complex fraud case the team recently solved?
• What opportunities exist for growth within the fraud operations team?
• How does Citi leverage data science and machine learning in fraud detection?
Final Preparation Tips
Before Your Interview:
• Research recent fraud trends in financial services (check industry news)
• Review Citi's recent fraud prevention initiatives or technology announcements
• Practice explaining statistical concepts in non-technical language
• Prepare 2-3 examples from your academic projects involving data analysis
• Be ready to discuss how you handle pressure and high-volume work
Your Advantages as an MS Statistics Graduate:
• Strong analytical foundation - you understand the math behind fraud models
• Experience with data analysis tools and techniques
• Familiarity with statistical concepts like probability, distributions, hypothesis testing
• Research mindset - comfortable digging into complex problems
• Quantitative thinking - natural fit for metrics-driven environment
What to Emphasize:
• Attention to detail (critical for fraud detection)
• Ability to make data-driven decisions under time pressure
• Strong communication skills (you'll need to explain findings to customers and colleagues)
• Eagerness to learn (you don't need to know everything - curiosity matters more)
• Customer service orientation (this role isn't just analytical - it's about protecting people)
Remember:
Your colleague is right that Citi will train you on their specific systems, processes, and tools. However, this
foundational knowledge demonstrates initiative, helps you ask intelligent questions in interviews, and will
accelerate your learning curve once you start. Focus on understanding the concepts rather than memorizing
every term. Good luck with your interview!
Study Strategy:
• Week 1: Focus on Sections 2-4 (cards, fraud types, terminology)
• Week 2: Deep dive into transaction lifecycle and your stats connection
• Week 3: Practice interview questions and research recent fraud trends
• Day before: Review red flags and key metrics
Additional Resources
Websites to Check:
• Federal Trade Commission (FTC) - Consumer fraud alerts
• FICO blog - Fraud insights and industry trends
• Visa and Mastercard security resources
• LinkedIn - Follow fraud prevention professionals and Citi employees
Certifications to Consider (After Getting the Job):
• Certified Fraud Examiner (CFE)
• Certified Financial Crime Specialist (CFCS)