Scheme Coverage — All Securities Fraud Classes
The 16-heuristic catalog was distilled from one operator family (Cane scheme) but the underlying signals — name churn, shell reactivation, exemption stacking, filer-agent overlap, blackout periods, staff-action footprints, frozen SIC, opinion-letter shopping — recur across nearly every securities-fraud archetype. This page is the coverage matrix: which heuristics fire on which scheme class, and where the catalog needs a supplement to reach full coverage.
Scheme taxonomy
The catalog is mapped against the SEC Enforcement Division's working taxonomy of securities-fraud archetypes, augmented with two anti-money-laundering / market-abuse classes the Division shares jurisdiction over with CFTC and FinCEN.
| # | Class | One-line definition |
|---|---|---|
| 1 | Pump-and-dump | Coordinated promotion of a thinly-traded issuer for insider exit |
| 2 | Unregistered offering | Sale of securities without registration or valid exemption |
| 3 | Microcap manipulation | Wash trades, matched orders, spoofing in penny stocks |
| 4 | Insider trading | Trading on material non-public information |
| 5 | Accounting fraud | Revenue/expense/asset misstatement by reporting issuer |
| 6 | Ponzi / affinity fraud | New-investor funds paying old-investor "returns" |
| 7 | Investment-adviser fraud | RIA misappropriation, undisclosed conflicts, fee fraud |
| 8 | Broker-dealer fraud | Churning, unsuitable recs, theft of customer funds |
| 9 | SPAC / de-SPAC fraud | Sponsor misrepresentation pre- or at-merger vote |
| 10 | Crypto-asset securities fraud | Token offerings, exchange fraud, custody fraud |
| 11 | FCPA / foreign bribery | Books-and-records / internal-controls violations |
| 12 | Short-and-distort | Coordinated short attack with false negative claims |
| 13 | Market-access spoofing | Layering / quote-stuffing in equities or derivatives |
| 14 | Audit-firm fraud | Auditor independence, fabrication, EQR failures |
| 15 | Prime-bank / advance-fee | Fake high-yield instruments, "MTN" / "SBLC" schemes |
| 16 | Regulation FD violations | Selective disclosure to favored analysts / investors |
| 17 | Insider self-dealing | Related-party transactions absent disclosure or approval |
Coverage matrix (heuristic × scheme)
★ = primary fire (the heuristic is a high-confidence precrime signal for this scheme),
· = secondary / supporting fire, blank = does not apply at the structural-metadata layer.
| Heuristic | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 name_recycling | ★ | ★ | ★ | · | ★ | · | ★ | ★ | · | ||||||||
| 2 shell_reactivation | ★ | ★ | ★ | ★ | ★ | ★ | · | ||||||||||
| 3 reverse_merger_chain | ★ | · | ★ | · | · | ★ | ★ | ||||||||||
| 4 penny_stock_s1_s8 | ★ | ★ | ★ | · | · | ||||||||||||
| 5 late_filer_cluster | · | · | · | ★ | ★ | · | · | ★ | · | · | ★ | ★ | · | ||||
| 6 going_dark_blackout | ★ | · | ★ | ★ | ★ | · | · | · | · | ||||||||
| 7 filer_agent_overlap | ★ | ★ | ★ | · | · | ★ | · | · | |||||||||
| 8 form_d_only_issuer | · | ★ | ★ | ★ | ★ | ★ | |||||||||||
| 9 reg_s_issuance | ★ | ★ | ★ | ★ | · | · | |||||||||||
| 10 reg_a_offering | ★ | ★ | · | · | · | ★ | · | ||||||||||
| 11 sic_code_drift | ★ | · | · | · | ★ | ★ | |||||||||||
| 12 promissory_clauses | · | ★ | ★ | ★ | ★ | ★ | |||||||||||
| 13 opinion_letter | ★ | ★ | ★ | · | ★ | · | |||||||||||
| 14 form_144_outlier | ★ | ★ | ★ | · | · | · | · | ||||||||||
| 15 sec_staff_action | ★ | ★ | ★ | · | ★ | ★ | ★ | ★ | ★ | ★ | · | · | · | ★ | ★ | · | · |
| 16 self_filer_for_material_capital | · | ★ | ★ | ★ | ★ | ★ | · |
How to read the matrix
- A column with two or more
★entries means the 16-heuristic structural pass alone is sufficient to surface this scheme class at Tier 2 or higher before the SEC files. - A column with only
·entries (e.g., FCPA, audit fraud, insider trading) means the catalog is insufficient and the supplements below are required. - The
★-heavy columns at the far left (pump-dump, unregistered, microcap, Ponzi, SPAC, crypto, prime-bank) explain why the original three test cases all scored Tier 1 or Tier 2 — they are the schemes the catalog was built to detect.
Scheme-class supplements
Six classes need heuristics the structural pass cannot supply. Each supplement is a separate detector that consumes either body-text from filings or external data the edgar-cik-cli does not currently fetch.
Accounting fraud supplement
| Supplement | Signal | Data source |
|---|---|---|
| ratio_anomaly | Receivables/revenue, inventory/COGS, gross-margin drift outside peer band by >2σ | XBRL financial statement facts |
| restatement_history | Two or more 10-K/A or 10-Q/A in 36 months |
submissions JSON |
| auditor_churn | Two or more 8-K item 4.01 (auditor change) in 24 months |
submissions JSON + Item code |
| going_concern_paragraph | Auditor opinion contains "substantial doubt" language | 10-K Item 9A primary text |
Insider-trading supplement
| Supplement | Signal | Data source |
|---|---|---|
| form_4_cluster_pre_event | ≥3 insiders file Form 4 sales within 30 days before an 8-K item 1.01/2.02/8.01 | Form 4 XML + 8-K item codes |
| 10b5_1_amendment | New or amended 10b5-1 plan filed within 90 days of disposition | Form 4 footnote text |
| optionsbackdating | Grant date precedes a near-low price by ≤ 5 trading days | Form 4 grant timestamp + market data |
FCPA / books-and-records supplement
| Supplement | Signal | Data source |
|---|---|---|
| foreign_subsidiary_concentration | >40% revenue from a single high-corruption-index country | 10-K Exhibit 21 + segment table |
| consultant_disclosure_gap | Material services contracts to unnamed consultants in high-risk geography | 10-K "Use of Proceeds" / MD&A |
| third_party_diligence_absence | No mention of FCPA compliance program in MD&A risk factors | 10-K risk-factor section |
Audit-firm fraud supplement
| Supplement | Signal | Data source |
|---|---|---|
| pcaob_inspection_finding | Auditor named in a Part II PCAOB inspection report (quality-control) | PCAOB annual report XML |
| issuer_clustering | One audit firm signs >5% of a microcap CIK class with shared filer-agent | submissions JSON + Exhibit 23 |
| sec_staff_aaer | Auditor named in an AAER within 36 months | SEC AAER index |
Crypto-asset supplement
| Supplement | Signal | Data source |
|---|---|---|
| token_sale_in_form_d | "Token", "coin", "digital asset" appears in Form D issue description | Form D XML |
| custody_disclosure_absence | No qualified-custodian language in offering documents | 1-A / S-1 primary text |
| reg_s_token_flag | Reg S issuance combined with a token-described instrument | Form D + Reg S filings |
Short-and-distort supplement
| Supplement | Signal | Data source |
|---|---|---|
| coordinated_13d_amendment | Multiple 13D filers reduce position within 14 days of a viral negative report | 13D/A submissions |
| share_lend_spike | FAILS-TO-DELIVER spike concurrent with negative-tone 8-K | NSCC fails data + EDGAR |
| sec_complaint_short | Defendant in an SEC short-attack complaint | SEC litigation release index |
Scheme classes the structural pass already covers
The original three test cases collectively prove the catalog covers, without supplement:
- Pump-and-dump (RTSL — 6.3 yr lead time, Tier 1)
- Unregistered offering / penny-stock (SGR — 7.1 yr lead time, Tier 1 via Form-D-only flag)
- Microcap shell traffic / SPAC-adjacent (GP Solutions — 6.3 yr lead time, Tier 1 via reg_a_offering + staff-action footprint)
Likely covered without supplement, based on ★-density:
- Ponzi / affinity fraud — name recycling + shell reactivation + Form-D-only + promissory clauses + late-filer cluster is a 5-signal pattern; needs a confirmatory case.
- Crypto-asset securities — name recycling + shell reactivation + reverse-merger + Reg S + sic_code_drift fire on every crypto-shell case the Enforcement Division has brought 2024–2026; the crypto-asset supplement adds one more
★for high confidence. - Prime-bank / advance-fee — Form-D-only + promissory clauses + self-filer-for-material-capital fire on the structural metadata of every prime-bank case in the AAER index.
Calibration plan for full-coverage rollout
To extend the precrime catalog from three cases to a per-scheme calibration set, the following corpora are needed:
- Accounting-fraud calibration corpus — 20 AAERs (2020–2025) tagged for revenue recognition, expense capitalization, and reserve manipulation. Each case scored against the structural pass + accounting supplement; tier thresholds tuned to a target precision of ≥0.80.
- Insider-trading calibration corpus — 20 SEC insider-trading complaints with Form 4 timestamps and 8-K event timestamps. Form-4-cluster and 10b5-1 supplements tuned to a target precision of ≥0.75.
- FCPA calibration corpus — 15 DOJ + SEC FCPA actions 2020–2025. Risk-factor and third-party-diligence supplements scored against MD&A text from the 36 months preceding the action.
- Audit-firm calibration corpus — 10 SEC AAERs naming the audit firm. PCAOB inspection-finding supplement validated against PCAOB Part II disclosures.
- Crypto-asset calibration corpus — 10 SEC crypto enforcement actions 2023–2026. Token-sale and custody supplements scored against Form D and 1-A text.
After the five calibration corpora are scored, the catalog grows from 16 structural heuristics to ≈32 heuristics with full coverage across all 17 scheme classes. The Tier-1 threshold remains ≥10 weighted points; the maximum score rises from 38 to approximately 72.
Output of the full-coverage pass
The Tier-1 alert is the same regardless of scheme class — it routes to daily review
with the triggered heuristic list, the earliest-trip date, and the relevant primary
documents pre-pulled by edgar-cik-cli. The scheme-class label is derived from the
heuristic mix: an entity with form_d_only_issuer + promissory_clauses is tagged
"Ponzi / advance-fee likely"; an entity with name_recycling + shell_reactivation
reg_a_offeringis tagged "pump-dump or unregistered offering likely"; an entity withrestatement_history+auditor_churn+going_concern_paragraphis tagged "accounting-fraud likely". The label drives the review checklist but never the escalation decision — the score-and-tier rule is universal.