It's a great question. You're talking about using the four fraud controls.
It's mandatory that they consume it, but once they consume it, their internal risk policies are what guide their individual thresholds on what to pass and what to fail. All of them have supplementary tools. For example, they might be absorbing four different scores, including the one we're providing, which has some network-level efficacy to add to what they're using today. For that part of it, they'll choose which score and threshold to use, from amongst the number of tools, to decide to let the payments through or to stop them, and that's because they bear the liability as the sender. They do the checks before and, generally, they have to deal with the fraud that arises between their own fraud losses and customer fraud losses, so that's where it leads to.
The parts of the solution that are mandatory, via our rules, are the contribution to the risk list and the contribution to the standard reporting nationally.
