Designing an AI Model to Triage National Cybercrime Reports

The Canadian Anti-Fraud Centre receives 200+ fraud and cybercrime reports every single day. Staff were manually reviewing them from a database of 350,000+ records. The backlog kept growing. People reporting fraud were waiting weeks for a response. Something had to change.

Category
Justice & Public Safety
Client
RCMP National Cybercrime Coordination Centre
Timeline
May 2024 – Sep 2024
My Role
Design Lead

The Problem

I started by talking to the people actually doing the work. The RCMP staff reviewing cybercrime reports weren't complaining about too little information. They were drowning in it. Every report came in as a text statement from a victim. The staff had to manually read each one, figure out what kind of crime it was (fraud, identity theft, phishing, online sextortion), and categorize it so it could be sent to the right investigative team.

The real issue was scale, not technology. 200+ reports a day meant hours of reading and re-reading similar stories. Staff told me they'd see patterns instantly (a romance scam, a credit card fraud, a spoofed email) but still had to document it formally for the system. Meanwhile, fraud victims were waiting two, three, sometimes four weeks for confirmation that their report was even received.

That's where the idea came from: what if an AI model could do the pattern matching that humans were already doing instinctively? Not to replace the staff, but to let them work faster on the thinking that only they could do.

Research and Discovery

I conducted 25 interviews with RCMP staff across multiple teams. Analysts. Investigators. Supervisors. I wanted to understand not just what they did, but why. What decision points existed? Where did they get stuck? What did confidence look like?

I also facilitated 8 workshops with the team to map out the actual workflow. We created detailed experience maps showing where AI intervention would create the most value. It became clear pretty quickly that the highest-impact moment was right at the beginning, when a report first arrived. That's where the categorization bottleneck happened.

Data Flow: From Reports to Categorization

The AI model ingests historical fraud data and real-time reports to suggest incident categories

350k+Historical Records200+Daily ReportsAI ModelPattern Matching &Confidence ScoringSuggestionswith Confidence

Designing the Solution

I didn't want a black box that spits out answers. I wanted a tool that showed staff why the model made its suggestion, so they could verify it or override it with confidence.

I designed a prototype that worked like this: a fraud report arrives. The AI model reads the statement and automatically suggests an incident category based on patterns in the 350,000+ historical records. It shows the top three categories ranked by confidence. It highlights the language in the report that triggered each suggestion. The staff member reviews the recommendation in seconds and either accepts it or selects a different category.

I tested this with actual RCMP staff using real (anonymized) fraud reports. The feedback was immediate. People said they could verify AI suggestions instantly because they could see the reasoning. A few tweaks to how confidence scores were displayed, and the prototype was ready to move forward.

Beyond the interface itself, I led design and accessibility work across the entire National Cybercrime System platform. This meant WCAG 2.1 AA compliance testing, usability testing with staff who had varying levels of technical comfort, and building accessibility in from the start, not as an afterthought.

The Solution: Human-Centered AI

AI that shows its reasoning, so staff can verify and override with confidence

User NeedsSee cases ranked by priorityGet suggestions, not replacementsUnderstand WHY the model chose itDesign ApproachAI analyzes 350k+ historical casesShows top 3 ranked suggestionsHighlights reasoning in textBenefits~70% faster review timeBetter prioritizationMore time for investigation

Delivering a Framework

The prototype mattered less than the process behind it. I documented that process so the RCMP could do this again on future projects without needing external help.

I created a repeatable methodology for designing user-centered AI/ML models. This was a first for the organization. It included templates for stakeholder interviews, experience mapping, prototype testing with real users, and accessibility validation. The process was handed off to the RCMP internal data and delivery team so they could continue the work independently.

Impact

The AI model reduced the time spent per report review by approximately 70 percent. What used to take 5-10 minutes of manual reading now takes under 2 minutes. The model processes 200+ daily reports and can work through the entire 350,000+ record database.

But the real impact was on the people. Fraud victims get faster confirmation. RCMP staff spend less time on repetitive pattern matching and more time on investigation and strategy. The organization proved it could build AI tools that work for the people using them, not against them.

Key Learnings

• AI works best when embedded in existing workflows, not when it tries to replace human judgment.

• Showing your reasoning matters more than being right. Staff trusted the model when they could see why it made a suggestion.

• Accessibility and usability aren't add-ons. They're foundational to whether people will actually use the tool.

• The most valuable deliverable might not be the product. It might be the process or framework that lets people continue the work after you're gone.

Let’s build together