01 Overview
Payment investigations at a global payments and custody bank
Half the queue closed in a minute. Some of it ran for weeks.
A high-volume investigations operation resolving payment exceptions raised from SWIFT, Fed and internal messages. In aggregate it looked like one process. It was really two, and the reporting could not tell them apart.
02 The problem
An average that described almost nobody
The bank resolved nearly every investigation it opened, and did so inside the month. Nothing in the standard reporting suggested a problem, because the reporting described a queue that did not exist in the form it was being measured.
An eighteen-hour mean sat between an automatic majority and a slow manual minority. Meanwhile SLA performance was only visible after the fact, never at the point where it was being lost. Four things stayed invisible.
Two processes, one queue
More than half the volume closed on receipt while a persistent tail ran past four working days.
SLA visible only in hindsight
Breaches were counted after the event rather than surfaced while a case could still be recovered.
Repeated correspondence
Many investigations required three or more outbound messages before they could be closed.
Uneven message linkage
Messages and investigations were connected instantly in one direction and slowly in the other.
03 How it worked
One month of records, reconstructed as a process
The bank provided read-only extracts of case, message and correspondence records together with a short period of subject-matter support. RE-ViVE handled the data modeling, execution reconstruction and analysis from evidence the bank was already storing for compliance.
Read the source evidence as it existed
Investigation cases, inbound messages, outbound correspondence, SLA definitions and audit trail entries — around 9.7 million rows already written and retained, but never read as a process. The evidence was not delivered as ready-made flows organised by case type.
Create a common execution foundation
RE-ViVE mapped those records into a common Execution Data Model, linking each message to its investigation, correspondence and resolution, and applying the bank's working-hour calendar so elapsed time reflected available capacity.
Reconstruct and analyse execution
RE-ViVE reconstructed the observed paths and measured resolution time, SLA attainment, channel mix and correspondence loops across every case type, each drillable to the evidence behind a single investigation.
| 06 Nov 09:02 | Message received | |
| 06 Nov 09:02 | Investigation created | instant |
| 06 Nov 14:41 | Adjustment — manual | |
| 07 Nov 10:15 | Correspondence sent | outbound 1 |
| 07 Nov 15:38 | Verification approved | |
| 08 Nov 09:20 | Correspondence sent | outbound 2 |
| 08 Nov 16:24 | Investigation resolved |
Every manual correspondence case in the period sent at least one outbound message, and more than half sent three or more. Each one is recorded faithfully in the audit trail and counted nowhere as effort.
04 What we found
What the evidence showed
The average sat between two populations
144,654 investigations — 54.68% of the total — closed within one minute of arriving. At the other end, 9,594 were still open after four working days.
An eighteen-hour average describes almost no individual case. It sits in the empty space between an automatic majority and a slow manual minority, and any target built on it will miss both.
The operational challenge is the 9,594 cases at the far right, which the average completely conceals.
Most cases cleared, but few cleared inside SLA
34,743 investigations — 13.13% — were resolved without exceeding their deadline SLA. Measured against the goal SLA, 17.16%.
Resolution channel explains much of the difference. Straight-through adjustment handled 37.96% of cases; another 29.07% needed a combination of automated and manual work, and 9.23% were worked by hand end to end.
13.13%of investigations were resolved without exceeding their deadline SLA
Case type, not volume, determined the wait
The busiest case type in the period — correspondent bank charges, at 154,495 investigations — cleared in under seven working hours. Case types with a few hundred cases ran for days.
Sanctions-related investigations dominated the slow end, which points at a specific workflow rather than a general capacity problem.
2,000xbetween the fastest case type at 0.06 working hours and the slowest at 123.28 — inside the same operation, on the same clock.
Linkage was instant one way and slow the other
Where a message created an investigation, 90.71% of the links were made within a minute — automation doing exactly what it should.
In the reverse direction, attaching a message to an investigation already in flight, 62.63% took more than four working days. Same two records, opposite experience.
05 What we recommended
Where the time comes back
Five plays, in the order we would take them. Every figure is drawn from the bank's own records and describes opportunity identified during the engagement.
Work the four-day tail as a named population
The 9,594 investigations running beyond 96 hours are individually traceable, so they can be managed as a list rather than a statistic.
Design SLAs around two distinct populations
A single target across an automatic majority and a slow manual minority cannot be met meaningfully by either.
Address the slowest case types directly
Separating external wait from internal handling shows how much of the sanctions-related duration is actually addressable.
Review correspondence verification on a risk basis
Manual correspondence is verified six times more often than straight-through, and roughly 95% is approved unchanged.
Close the reverse linkage gap
Attaching a message to an investigation already in flight is the one direction automation has not covered.
06 Next steps
The opportunity was already in the data
Every number on this page came from audit records the bank was already retaining for compliance. RE-ViVE made them measurable, and then made them actionable.
This is Execution Intelligence: reconstructing how work actually executed from the evidence already produced by the enterprise, then exposing where time, effort and complexity accumulate.
Where should we send it?
Tell us who you are and the PDF will download straight away.
We use these details to send you related material and to follow up about Execution Intelligence. We do not share them. See our privacy notice for how we handle your data.
