AI Adoption GuideGovernmentFund
Drawdown anomaly monitor
Real-time ML flags suspicious disbursement patterns, such as recurring reimbursements just below audit thresholds, before payment clears.
Government processPlanFundAuthorizeDeliverInspectEnforceReportClose
By Don, DoneThat’s AI coach · updated
What the hold must cite
A drawdown anomaly monitor belongs in the payment queue only when it can pause a disbursement with a cite the officer can check, or stay silent. The quality outcome is a hold that names the award ID, the specific draw, and the pattern: a reimbursement that repeats just under a documented review threshold, a cadence that does not match the award's spend plan, or a request coded to a budget line the NOFO never funded. If the draw is ordinary, the output is empty. The payment officer still releases or stops the payment.
A flag is a pause with a reason. It is not an allegation, a questioned cost, a notice of investigation, or a substitute for release authority.
Run the sequence at draw time: load the award and the history, require cites, leave ordinary rows blank, and keep the decision with the officer. The failure modes that stall a cycle are a red tile with no pattern, treating the hold as a finding, and inventing a threshold the NOFO never set.
Load the award and the draw history
Do not score a voucher in isolation. Load the live award record and every prior draw against it before the model runs.
You need the Assistance Listing, the award ID, the approved budget by object class or activity, amendments, the period of performance, and the payment method: advance, reimbursement, or working capital. You need the draw history: dates, amounts, object class, voucher or invoice IDs, and whether each prior item cleared, was held, or was returned.
Grants.gov-class portals typically hold the application, the NOFO excerpt, and the award package. The disbursement queue itself usually sits in a Tyler-class ERP or a state equivalent. Entity graphs and related-award context may live on Palantir-class platforms or Microsoft-class data estates. Use those systems as sources. Do not import a dollar floor from a neighboring program, a training slide, or a model default if the NOFO and the payment SOP do not state it.
If the award file is incomplete, stop and complete it. Scoring a partial history produces noise: a first draw that looks large only because there is no prior draw, a quarterly reimbursement that looks clustered only because monthly history was never loaded, an object-class mismatch that is actually an unposted amendment.
Eligibility and pattern are different questions. Pair this load with the compliance pre-check generator when the issue is whether the cost is allowable under the award terms at all. A draw can be allowable and still present as a near-threshold repeat. Run eligibility first or in parallel. Do not let a pattern flag stand in for a missing budget narrative.
Patterns that justify a pause
Emit a hold only when three cites are on the screen.
- Award ID, and the recipient UEI if the queue is shared across awards.
- Draw identifier: voucher, invoice, or SF-270 or SF-271 equivalent, plus amount and requested payment date.
- A pattern label a reviewer can re-check without the model: near-threshold repeat, unusual cadence, or mismatched budget line.
Near-threshold repeat is the same recipient, same award or closely related budget category, submitting reimbursements that sit just under a documented review trigger. The trigger has to exist in writing: the agency's sampling floor, a single-transaction second-reviewer amount in the payment SOP, or a NOFO-stated prior-approval line. Cite that document and the prior draws in the same band. If neither the NOFO nor the SOP names a number, you cannot call the amount "just below threshold." You can still describe recurring structure (same line, same timing, same round amounts) if that is what you observed. Do not invent the missing number.
Unusual cadence is timing that does not match the period of performance or the spend plan on file. Examples include a cluster of reimbursements in the last days of a quarter after months of inactivity, or a sudden acceleration with no corresponding amendment. Cite the spend plan dates and the draw dates. Cadence is unusual only against the plan you loaded.
Mismatched budget line is a draw coded to an object class, activity, or cost category the award budget does not contain, or that an amendment moved elsewhere. Cite the budget line on the award and the code on the voucher. A pending amendment is an amendment hold, not an anomaly pattern, unless the pattern is also present.
If the model cannot produce those three cites, it must not produce a red tile. A red tile with no pattern is a failure mode. Route it to insufficient cite rather than to the payment officer's exception queue.
When the same recipient appears across awards or programs, pass the cite to the cross-program fraud pattern detector. Stretching this monitor into a network investigation without a second control produces flags nobody can close.
Supporting documents (receipts, timesheets, contractor invoices) are document review. If the real issue is that the PDF does not match the line, or that pages look reused, use the document forensics engine. Do not collapse authenticity and disbursement pattern into one flag. The officer needs to know which control fired.
Ordinary draws stay empty
Most draws are ordinary: a monthly personnel reimbursement inside the approved salary line, a quarterly draw that follows the Federal Financial Report already on file, an advance within the authorized working-capital ceiling. The correct output is empty. Do not force a residual score, a traffic light, or a low-risk badge onto those rows. Empty means the officer can clear the queue with the controls they already apply.
Filling every row with a score trains people to ignore cites. That is how a real hold becomes wallpaper.
Do not keep this monitor attached to a closed award because a score is still available. After closeout, leftover obligation and deobligation questions belong to the post-closure obligation monitor. A drawdown control on a closed award is the wrong queue.
Illustrative example: reimbursement under the review floor
This is an illustration of the control, not a measured result and not an agency case.
A payment officer opens the morning queue. Award 24-XYZ-4811. Reimbursement of $24,850, object class contractual, same-day ACH. The agency payment SOP, not the NOFO, requires a second reviewer on any single reimbursement at or above $25,000. The last four contractual reimbursements on this award were $24,900, $24,875, $24,910, and $24,840, each submitted within two business days of month-end. No amendment increased the contractual ceiling.
The monitor holds voucher V-10922 and cites: award 24-XYZ-4811; draw V-10922, $24,850, contractual; pattern near-threshold repeat against the SOP second-reviewer floor, four prior draws in the same band, same object class, same month-end cadence. It does not say fraud. It does not estimate how often this happens. It does not pretend the NOFO set $25,000.
The officer opens the four prior vouchers, confirms the SOP floor exists, and then either stops the payment and asks for the underlying contracts, or releases after documenting that the contractual line still has budget and the invoices are distinct jobs. The monitor's job was the pause with a cite.
If the same $24,850 were the first contractual draw on a new award, with no prior band, the monitor stays empty. A single amount near a floor, without a repeat, is not this pattern. Inventing history to force a hold is the same class of error as inventing a threshold.
The officer still releases or stops
After the cites are on the screen, the payment officer decides. Release if the budget line, the invoices, and the cadence check out. Stop if they do not. Record the decision against the award ID and the draw. The monitor does not clear the payment.
Revisit the three failure modes before you sign. A red tile with no pattern is not a hold; send it back for the three cites or drop the flag. A hold is not a finding: do not write fraud into the file because a model paused a payment. If the NOFO and the SOP never set a dollar floor, do not cite a threshold you invented; cite recurring structure only if that is what you saw.
Grants.gov-class portals, Palantir-class and Microsoft-class platforms, and Tyler-class payment systems are sources and queues, not a ranked stack. None of them decide the payment.
Is this worth automating for you?
Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other. This one is rated high effort to implement, so the baseline matters more than usual.
DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.
Measure the baseline first