Security Services Domain Model / Worked Examples / Payment Services

Worked Example: Payment Services

A bank's payment services sit under some of the heaviest regulatory weight in financial services — PSD2 Strong Customer Authentication, PCI-DSS, anti-money-laundering obligations — while carrying a threat that never stops evolving: payment fraud and authorised-push-payment scams. This example instantiates the Security Services Domain Model for that scenario: the business driver is simply moving money safely; the risk is loss and regulatory breach; and the chain runs through a payment security policy, a fraud screening and SCA service, transaction scoring workflows, and down to the actual fraud detection platform and 3-D Secure step-up that execute it in production. It shows how the same generic model carries the specific regulatory and fraud-control weight a payments domain actually has to bear.

Interactive Payments Example

The same interactive model, instantiated for payment services.

Open full screen

Every element names both its real-world instance and the generic concept it plays. Click any concept to see its definition and relationships.

Same Model, This Scenario

Every concept in the base model has a named, concrete instance here — the traceability chain is identical, only the content has changed.

Generic ConceptInstantiated As
Business DriverMove Money Safely
Business Attribute ProfilePayment Attributes
DomainPayment Services
Sub-DomainCard & A2A Payments
Compliance ObligationPSD2 SCA / PCI-DSS / AML
ThreatPayment Fraud / APP Scams
RiskLoss & Regulatory Breach
Business OutcomeSafe, timely payments
MeasuresFraud bps · false positives
Domain PolicyPayment Security Policy
Control ObjectivePrevent Unauthorised Payments
Security ServiceFraud Screening & SCA Service
Logical MechanismTransaction Scoring Workflow
Logical Sub-MechanismRisk-Rule & Model Evaluation
Physical SystemFraud Detection Platform
Physical MechanismScoring Engine Node
Physical Sub-Mechanism3-D Secure Step-up
ProductFeedzai + 3DS
← Identity & Access Management Next: AI Governance →