A loyalty program run as a financial instrument — six layers, one wallet, and a governed control room.
Every reward value is an IFRS 15 contract liability, revalued nightly and tied to the general ledger daily.
No reward change is self-service. Draft, submit, second signature, applied on the next nightly run.
No preferential credit pricing off the score until risk-model cohort validation clears. A launch gate, not a formality.
| Layer | What it is | Funded by | Fails when |
|---|---|---|---|
| Onramp | One-time bonus for clearing Level 0 to Level 1 | Growth budget | Bonus paid, customer never returns |
| Foundation | Instant cashback — cash, not points | Bank's own margin | Rate creeps above the point value |
| Daily Habits | Check-ins, streaks, fraud quizzes | Marketplace partners | Engagement rises, Trust Score does not |
| Moments | Capped chance reward on a qualifying transaction | Marketing budget | Velocity farming on small tickets |
| Trust Score | Behavioural score that unlocks credit terms | Reduced cost of risk | Used for pricing before validation |
| Marketplace | Where points are spent; literacy and grants | Partners, bank, donors | A redemption fails and nobody notices |
Points are earned by doing. The Trust Score is earned by banking well.
Habits, quizzes and campaign awards never touch the score. That separation is what makes the score usable for credit — and why the console refuses to add a points input to it, for anyone, at any level.
Ledger · not an opinion
Produced by the earn engine and tied to the GL account by account, every day.
Finance + Internal Audit
The highest-impact number in the console — it reprices the entire liability at once.
Finance signs · Audit traces
Re-signed quarterly. A change appears in the audit log as a re-signature, never a silent edit.
Lower breakage means a larger liability — and a better program. A program with 40% breakage is cheap because it is not working. Read the liability with redemption rate beside it.
Edited values highlight; the banner counts unpublished changes.
Backtest against real history; simulate the forward liability curve.
A line-by-line diff enters Approvals and the audit log, under a name.
A different person, with the right role. Rejection carries a reason.
It applies tomorrow, not now. The batch is the bank's own batch.
A customer with two years of punctual bill payments through the wallet and no bureau history is invisible to a traditional score and legible to this one. The return is a lower cost of risk on customers the bank currently cannot price.
Five behavioural inputs — repayment punctuality, transaction regularity, savings behaviour, tenure, dispute history — each with a weight and a lookback. Weights must total 100%. Recalculated weekly.
Preferential pricing off the score stays gated on risk-model cohort validation. Pressure to move early is refused and routed to Credit Risk — the console will not carry the decision.
Eligible customers deliberately not given the bonus. The gap between them and the treated group is the effect.
Divided by the customers the campaign caused — never by everyone it reached.
Habit retained after the campaign ended. A spike that vanishes bought transactions, not customers.
Spend that cannot be read — campaigns with no adequate control — is excluded from the blended cost figure rather than assumed to work.
Backtest prices a change on activity that really happened. It answers cost, never behaviour.
Simulation projects the liability curve 6–24 months. Quote the peak and the band, never the closing figure alone.
Only a holdout can tell you whether behaviour moved.
Nothing reverses points on its own. A claw-back is the mirror of a goodwill credit and carries the same dual authorisation; agent and ring cases are referred to the Financial Crime Unit in parallel.
Opening, issued, redeemed, expired, closing, GL, variance — account by account. A variance becomes a break with an owner and a target date. The ledger is never adjusted to force a tie.
A streak payout job once timed out with no retry. Three days later it was a customer complaint; three days after that, a goodwill adjustment with two signatures. Batch reliability is a customer-trust metric, not an IT metric.
The console runs on the bank's own infrastructure. Points, scores, traces and audit entries are computed and stored in-house — there is no external analytics dependency to explain to Compliance.
The north star: it moves two to three months before churn shows up in revenue.
Engagement and Trust Score read on the same cohort. Engagement rising with the score flat means we are buying attention, not habit.
Spend with no detectable lift, spend that cannot be judged, SLA breaches, open reconciliation breaks.
A board pack containing only good news is a pack nobody can act on — and the first time bad news arrives from outside the program office, the argument for the program is already lost.