FRAUD-INTELLIGENCE BRIEF TEMPLATE Tervaq Security Intelligence Version: 2026-10-06 Blank planning template. Use only with appropriate authorization. Do not enter live credentials or unnecessary personal data. DECISION AND SUMMARY Lead with what the recipient needs to decide and why the available evidence is relevant. Case reference and report date: [Complete within your approved internal environment] Affected organization or workflow: [Complete within your approved internal environment] Decision or action requested: [Complete within your approved internal environment] Summary of concern and the most important uncertainty: [Complete within your approved internal environment] CLAIMS AND CONFIDENCE Use evidence-status labels rather than allowing every statement to sound independently confirmed. Reported by a source: statement, date, and provenance: [Complete within your approved internal environment] Directly observed: observation and supporting record: [Complete within your approved internal environment] Reproduced under authorization: scope and result: [Complete within your approved internal environment] Assessed impact: reasoning, assumptions, and untested links: [Complete within your approved internal environment] CHRONOLOGY AND EVIDENCE INDEX Keep original records separate from working copies. Do not alter an original to make it easier to present. Event timestamps with time zones: [Complete within your approved internal environment] Evidence item identifier and description: [Complete within your approved internal environment] Original record location, custodian, and access restriction: [Complete within your approved internal environment] Redacted copy identifier and explanation of redactions: [Complete within your approved internal environment] HANDLING AND DISCLOSURE The brief should say how evidence can be shared without inviting an uncontrolled transfer of customer data. Permitted recipients and agreed transfer channel: [Complete within your approved internal environment] Personal data minimized or excluded: [Complete within your approved internal environment] Retention and deletion arrangements: [Complete within your approved internal environment] Disclosure contact, acknowledgement, and internal case reference: [Complete within your approved internal environment] NEXT STEPS Close with a limited set of concrete actions and named responsibilities. What the organization can inspect to confirm or reject the concern: [Complete within your approved internal environment] Open questions and evidence gaps: [Complete within your approved internal environment] Owner and proposed review point: [Complete within your approved internal environment] Any commissioned work to be scoped separately: [Complete within your approved internal environment] Source: https://tervaq.com/resources/fraud-intelligence-brief