Suspicious Nodes

Ranks fleet metering nodes by the probability of under-metering using six independent forensic signals combined as probabilities, not a sum.

The Suspicious Nodes report performs a fleet-wide analysis of gas metering nodes and ranks the points that require priority verification for possible under-metering, measurement-channel substitution, incorrect settings, abnormally low consumption, or device events related to physical access and parameter changes.

It draws on the normative framework for gas metering — ISO 5167 (orifice plates), ISO 6976 (calorific value), EN 12405-1 (electronic gas-volume conversion), OIML R 137 (gas meters), OIML R 140 (measuring systems for gaseous fuel) and EN 1359 (diaphragm meters).

This is not an operational report about communication, battery or archive quality — those tasks belong to a separate operational report on problem nodes. This report focuses specifically on forensic signals: behavioural, metrological, comparative and event-based indicators that may suggest the need for a metering-service check.

The report’s main task is not to prove a violation, but to set verification priorities correctly:

  • which nodes to check first;
  • where there are several independent signals;
  • where consumption is abnormally low compared with similar nodes;
  • where there is a combination of zero flow, live pressure and an incomplete passport;
  • where the standard and working volume diverge more than physical P/T-correction can explain;
  • where the expected seasonal growth in consumption is absent;
  • where there were device events related to physical access or reading substitution;
  • where it is worth opening the detailed report on a specific node.
Report header

The report header shows the fleet size, how many nodes entered deep analysis, the covered period and the generation time. These three numbers are distinct entities: the total fleet, the analysed candidates, and the TOP-N rows in the table.

Where this report fits

The Suspicious Nodes report sits between fleet-wide operational monitoring and the detailed forensic breakdown of a single node.

ReportMain questionScale
Operational problem nodeswhere there are communication, battery, passport, archive issuesfleet
Suspicious Nodeswhere there are forensic signals of possible under-meteringfleet
Metering Bypass (node)why a specific node looks suspiciousone node
Consumption Analyticswhether a specific node’s data is fit for metering and analysisone node

A node can be operationally bad but not suspicious from the under-metering point of view, and vice versa: a node can be stably online with a good archive yet consume suspiciously little relative to its cohort.

Who the report is for

RoleHow they use the report
Head of metering servicechooses priorities for checks and field visits
Metrologistanalyses the causes of suspicion and the need to verify the passport
Dispatcherdispatches tasks for high-priority nodes
Field teamreceives the node list and a link to the detailed breakdown
Analystchecks cohorts, seasonality, anomalies and events
Billing analystestimates the potential commercial scale of the risk
Control serviceseparates weak signals from cases requiring investigation
Legaluses it as grounds for launching an investigation (not as proof)

What the report does not do

The report must not:

  • prove the fact of metering bypass;
  • automatically accuse a consumer;
  • replace a field check;
  • treat the loss estimate as confirmed damage;
  • interpret low consumption as a violation without comparison with the object’s regime;
  • treat the absence of data as a zero signal;
  • mix operational issues with forensic signals;
  • treat an unavailable indicator as equal to zero;
  • make a legal conclusion based on the AI summary;
  • replace the detailed report for a specific node.

Key terms

TermMeaning
Nodea gas metering point whose telemetry is analysed
Fleetthe set of all nodes of a company
Candidatea node that passed the pre-selection for deep analysis
Cohorta group of similar nodes for consumption comparison
Percentilethe node’s position by flow among similar nodes
Subscorea partial score for one forensic signal from 0 to 100
Composite scorethe final suspicion score
Ceilingthe maximum contribution of a signal to the final probability
Direct signala direct behavioural forensic signal based on Q/P/T
Peer anomalyflow anomaly relative to similar nodes
Passport bypassthe signature “empty passport + near-zero flow + live pressure”
Divergencedivergence between standard and working volume beyond physical explanation
Seasonal anomalyabsence of the expected seasonal growth
Event recencyfreshness of device events related to access or substitution
Cluster flagindicator that one organisation has several suspicious nodes
Estimated lossescommercial priority: score x consumption, not confirmed damage

General report logic

The report is built as a fleet-wide suspicion filter.

text
All fleet nodes
→ pre-selection of live forensic candidates
→ deep analysis of the hourly archive and events
→ calculation of 6 independent subscores
→ comparison of nodes with the cohort
→ composite score calculation
→ cluster correction by organisation
→ TOP-N ranking
→ output of the level distribution
→ list of actions and links to detailed reports

The key principle: the report looks not just for “bad” nodes, but for nodes with signs of possible under-metering in the presence of data. A fully dead node that has not transmitted data for a long time is an operational problem, but not necessarily a good forensic candidate.

Input data

Minimum required data

DataWhat it is needed for
Node listto form the analysis fleet
Device typeto build cohorts
Organisationto compare within similar groups
Consumption over the periodfor ranking and scale estimation
Hourly archive Q/P/T/Vfor behavioural signals
Analysis periodfor seasonality and events

Additional data

DataWhat it is needed for
Communication sessionsfor the “archive gap with successful sessions” indicator
Device passportfor the passport-bypass indicator
Corrector settingsfor P_const, pulse weight, correction parameters
Device event logfor physical access, substitution, reset, parameter change
Previous data on similar nodesfor the peer baseline
Seasonal window datato check the winter/summer profile

Minimum period for reliable scoring

A period shorter than 30 days automatically makes the seasonal signal unavailable. The recommended minimum is 90 days. A full seasonal analysis is only possible on a period of at least 6 months covering both seasons.

Run parameters

ParameterMeaning
Period from / Period tothe evaluation window (defaults to the last 90 days)
How many nodes in topsize of the final TOP-N table
How many nodes to deep-analyzenumber of candidates retained after pre-selection
Resource companyrestrict the analysis to one organisation, or use the whole fleet
Organization clusteringadd +10 to nodes of organisations with two or more suspicious nodes
AI fleet summaryoptional human-language commentary that does not affect scores

Report scope

Level distribution and AI summary

Right under the report header are three distribution cards and an AI-comment block. They are read together: the distribution gives a quick answer to “how many nodes are critical”, and the AI summary explains why exactly these nodes reached the top and what to pay attention to.

The top block shows:

IndicatorValue
Total nodes in the fleetsize of the whole fleet
Analysedhow many nodes entered the deep analysis
TOP-Nhow many nodes are shown in the final table
Periodevaluation window
Data retrieval errorshow many candidates could not be fully processed
Level distributioncritical / warning / normal

It is important to distinguish:

text
Total fleet nodes ≠ number of deeply analysed nodes ≠ number of rows in TOP-N.

For example, the fleet may contain hundreds of nodes, deep analysis may be performed on a set of candidates, and the report shows only the TOP-N.

Level distribution

CompositeLevelCard colour
≥ 60criticalred
30–60warningorange
< 30normalgreen

A high concentration in red is not a reason to panic, but a signal to carefully check the top: possibly the methodology gave a strong response to a specific operating regime rather than to real interference.

Pre-selection of forensic candidates

Before deep analysis the report prioritises nodes for which it is at all possible to look for forensic patterns.

Why live nodes are needed

For the suspicion report, nodes with data are important. If a node is fully dead, it does not give a sufficient picture of Q/P/T, and it should be checked in the operational communication report, not in the forensic ranking.

A typical principle:

text
a bypasser does not necessarily disable telemetry completely;
they may disguise themselves as a "low consumer".

The pre-selection therefore considers the freshness of the last session, the presence of non-zero volume, the device status, and the presence of data in the archive.

Pre-selection scoring

The preliminary score can be described as:

FastScore=AliveScore+VolumeScore+StatusScoreFastScore = AliveScore + VolumeScore + StatusScore

where:

ComponentLogic
AliveScorehigher if the node was recently online
VolumeScorehigher if there is registered volume
StatusScorehigher if the node is in working or sealed state

The preliminary score is not the final suspicion score. It only selects candidates for deeper analysis.

Six suspicion signals

Six-signal methodology

All six detectors are shown with their description, documentation weight and probabilistic-contribution ceiling. The final score is not a sum but a probabilistic composition. One strong signal alone is not yet “critical”; a combination of independent signals is. Unavailable signals are excluded, not counted as zero.

#SignalDocumentation weightMaximum probabilistic contribution
1Direct tampering30%0.85
2Anomaly relative to cohort (peer anomaly)20%0.57
3”Dummy” signature (passport bypass)15%0.43
4Standard vs. working volume divergence10%0.28
5Seasonal anomaly15%0.43
6Device events with recency10%0.28

Percentage weights are used for documentation and explanation. The final formula uses not a linear sum but probabilistic ceilings (see the probabilistic model).

Signal 1 — direct tampering

This signal reuses behavioural forensic patterns from the hourly archive. It shows whether the node has signs of possible measurement-channel substitution or suspicious zero flow with a working pipe.

Typical indicators that may enter the direct signal:

  • zero flow at working or substituted pressure;
  • frozen pressure channel;
  • recovery of flow and pressure after a zero window;
  • archive gap with successful communication sessions;
  • contextual corrections for season, object type and consumption regime.

The detailed methodology of direct patterns is described in the Metering Bypass (node) report, which defines nine formal detectors with thresholds.

The direct subscore has the range:

Sdirect[0,100]S_{direct} \in [0, 100]

where:

  • 0 — direct behavioural signs not found;
  • 30–60 — weak or medium signs present;
  • 60–100 — strong or repeated signs present.

The direct signal is not proof. It means: open the detailed report on the node and inspect the event windows.

Signal 2 — anomaly relative to cohort

Comparison with the cohort answers the question: does the node consume suspiciously little compared with similar nodes? Similar nodes are those with the same device type and the same organisation or another specified grouping.

For comparison the rate is used:

Ratei=ConsumptioniHoursiRate_i = \frac{Consumption_i}{Hours_i}

where Consumption_i is the total consumption of the node over the period and Hours_i is the number of hours of data.

The percentile shows the node’s position in the cohort by flow:

Percentilei=count(RatejRatei)Ncohort×100%Percentile_i = \frac{count(Rate_j \le Rate_i)}{N_{cohort}} \times 100\%

A low percentile means the node consumes less than most similar nodes. For example, Percentile = 5% means the node consumes less than about 95% of similar nodes.

Base score by percentile

PercentileBase score
< 3%100
< 5%85
< 10%60
< 25%30
≥ 25%0

Adjustment for distance from the median

A low percentile alone does not always mean suspicion: in any cohort someone will be last. The score is therefore scaled by the ratio to the cohort median.

Ratiomedian=RateiMedianRatecohortRatio_{median} = \frac{Rate_i}{MedianRate_{cohort}}
Ratio to medianFactor
≤ 0.331.0
0.33–0.500.6
0.50–0.700.3
> 0.700.0

Final peer score:

Speer=BaseScorepercentile×FactormedianS_{peer} = BaseScore_{percentile} \times Factor_{median}

Interpretation

Peer scoreMeaning
0consumption does not look suspiciously low
30a weak anomaly is present
60the node is noticeably below the cohort
85–100the node is sharply below similar nodes

Signal 3 — “dummy” signature (passport bypass)

The signal looks for a combination of three factors:

  1. the device passport is almost empty;
  2. flow is almost zero for most of the period;
  3. pressure at the same time is working and live.

Such a combination may look like a “dummy on an active pipe”: there is gas in the pipe and pressure is present, but flow is barely registered, and passport data is insufficient for verification.

Zero-flow share

Let:

Nzero=count(Qh0.001)N_{zero} = count(Q_h \le 0.001) Nvalid=count(QhNULL)N_{valid} = count(Q_h \neq NULL)

Then:

ZeroShare=NzeroNvalidZeroShare = \frac{N_{zero}}{N_{valid}}

Zero-flow condition:

ZeroShare0.60ZeroShare \ge 0.60

Live working pressure

The median pressure is computed:

Pmedian=median(Ph)P_{median} = median(P_h)

and the standard deviation of pressure:

σP=1n1(PhP)2\sigma_P = \sqrt{\frac{1}{n-1}\sum(P_h-\overline{P})^2}

Pressure is considered working and live if:

Pmedian>103  kPaP_{median} > 103 \; kPa

and:

σP>0.05  kPa\sigma_P > 0.05 \; kPa

That is, the pressure is above atmospheric level and does not look fully frozen.

Empty passport

The passport is considered empty or critically incomplete if a significant part of the mandatory fields is missing:

  • verification date;
  • Qmin/Qmax;
  • meter type;
  • meter serial number;
  • P_const;
  • pulse weight;
  • pressure type;
  • firmware version.

Score formula

Let:

text
A = PassportEmpty
B = ZeroShare ≥ 0.60
C = P_median > 103 and σP > 0.05

The number of satisfied conditions:

Nsignals=A+B+CN_{signals} = A + B + C

Score:

Number of conditionsScore
3100
250
0–10

This signal does not mean proven bypass. It shows that the node requires documentary and field verification.

Signal 4 — standard vs. working volume divergence

Many correctors transmit both a working volume and a converted / standard volume after P/T correction. Normally the ratio of the standard-volume increment to the working-volume increment should roughly correspond to the physical P/T correction coefficient.

Actual volume ratio

Let:

ΔVstd\Delta V_{std}

be the increment of standard or corrected volume, and:

ΔVwork\Delta V_{work}

the increment of working volume.

Then the actual ratio:

Ractual=ΔVstdΔVworkR_{actual} = \frac{\sum \Delta V_{std}}{\sum \Delta V_{work}}

Expected P/T coefficient

The approximation used is:

Rexpected=PP0×T0273.15+TR_{expected} = \frac{\overline{P}}{P_0} \times \frac{T_0}{273.15 + \overline{T}}

where:

  • P0=101.325  kPaP_0 = 101.325 \; kPa;
  • T0=293.15  KT_0 = 293.15 \; K, i.e. 20°C;
  • P\overline{P} — mean pressure;
  • T\overline{T} — mean temperature in °C.

Relative divergence

Divergence=RactualRexpectedRexpectedDivergence = \frac{|R_{actual} - R_{expected}|}{R_{expected}}

Score

Up to 10% divergence is considered an acceptable zone.

Sdivergence=clamp((Divergence0.10)×250,  0,  100)S_{divergence} = clamp((Divergence - 0.10) \times 250,\;0,\;100)
DivergenceScore
≤ 10%0
20%25
30%50
50% and above100

When the signal is unavailable

The signal is considered unavailable if:

  • there is no standard-volume channel;
  • there is no working-volume channel;
  • there are too few valid hours;
  • volumes are not monotonic;
  • the sum of working volume equals zero;
  • there is no P/T data for the expected coefficient.

Signal 5 — seasonal anomaly

For many gas consumers a winter increase in flow is expected. If the period contains both winter and summer months but winter flow does not grow or even falls, this may be a signal of under-metering in the peak consumption season.

Winter months are December, January and February. Summer months are May, June, July, August and September.

Availability condition

The seasonal signal is counted only if there is sufficient data in both seasons:

Hwinter200H_{winter} \ge 200

and:

Hsummer200H_{summer} \ge 200

If there is less data, the signal is considered unavailable.

Average flow by season

Qwinter=QhwinterHwinterQ_{winter} = \frac{\sum Q_h^{winter}}{H_{winter}} Qsummer=QhsummerHsummerQ_{summer} = \frac{\sum Q_h^{summer}}{H_{summer}}

Seasonal ratio

Rseason=QwinterQsummerR_{season} = \frac{Q_{winter}}{Q_{summer}}

Score

ConditionScore
Rseason0.5R_{season} \le 0.5100
Rseason0.8R_{season} \le 0.860
Rseason1.0R_{season} \le 1.030
Rseason>1.0R_{season} > 1.00

For industrial consumers without heating load, seasonal growth may be absent. The seasonal anomaly must therefore be interpreted with the object type in mind.

Signal 6 — device events with recency

Device events can be more significant than statistical anomalies. Especially important are events of physical access, cover opening, parameter changes, reading substitution, reset, time changes, and events affecting the measurement channel.

Event base score

Event classBase score
physical100
substitution70

Event age and decay

Event age:

AgeDays=ReportEndEventTime1  dayAgeDays = \frac{ReportEnd - EventTime}{1 \; day}

Decay coefficient:

Decay=max(0.2,  1AgeDays225)Decay = max(0.2,\;1 - \frac{AgeDays}{225})

A fresh event has full weight; an old event gradually loses significance; the minimum residual weight is 20%.

Event score

EventScorei=BaseScorei×DecayiEventScore_i = BaseScore_i \times Decay_i

Final recency score

If there are several events, the maximum score is taken:

Srecency=max(EventScorei)S_{recency} = max(EventScore_i)

If the log is available but there are no events, Srecency=0S_{recency} = 0. If the log is unavailable, the signal is unavailable and is excluded from the final formula.

Unavailable signal ≠ zero signal

This is one of the key rules of the report. If a signal cannot be calculated due to lack of data, it receives the status (unavailable), not 0.

Reasons for unavailability:

  • no required archive channel;
  • not enough hours;
  • no event log;
  • no seasonal coverage;
  • no cohort data;
  • no working or standard volume;
  • no passport.

In the final formula, unavailable signals are excluded from the product, neither decreasing nor increasing the score.

Probabilistic model of the final score

If all six signals were simply summed with weights, one strong signal could look like full proven risk, and many weak signals could mechanically create false criticality. A multiplicative model of independent probabilistic contributions is used instead.

Ceiling for each signal

Each signal has a maximum contribution:

SignalCeiling
direct0.85
peer0.57
bypass0.43
divergence0.28
seasonal0.43
recency0.28

Probabilistic contribution of a signal

Let S_i be the signal subscore from 0 to 100 and C_i the signal ceiling. Then the contribution:

pi=Ci×Si100p_i = C_i \times \frac{S_i}{100}

Probability of absence of all signals

Pclean=iAvailableSignals(1pi)P_{clean} = \prod_{i \in AvailableSignals}(1 - p_i)

Final score

Composite=100×(1Pclean)Composite = 100 \times (1 - P_{clean})

that is:

Composite=100×(1iAvailableSignals(1Ci×Si100))Composite = 100 \times \left( 1 - \prod_{i \in AvailableSignals} \left( 1 - C_i \times \frac{S_i}{100} \right) \right)

Example

Suppose there are three signals:

SignalSubscoreCeilingpip_i
direct900.850.765
peer500.570.285
seasonal300.430.129

Then:

Pclean=(10.765)×(10.285)×(10.129)P_{clean} = (1 - 0.765) \times (1 - 0.285) \times (1 - 0.129) Pclean=0.235×0.715×0.871P_{clean} = 0.235 \times 0.715 \times 0.871 Pclean0.146P_{clean} \approx 0.146 Composite=100×(10.146)=85.4Composite = 100 \times (1 - 0.146) = 85.4

Model interpretation

  • one strong signal can give a high score, but not a full 100;
  • a combination of independent signals sharply raises the priority;
  • weak signals do not add up linearly;
  • unavailable signals do not penalise the node;
  • the final score is the verification priority, not proof.

Cluster correction by organisation

If one organisation has several suspicious nodes, this raises the verification priority. Such cases may indicate a systemic operating regime, settings, maintenance or potentially coordinated actions.

If one organisation has:

Nsuspicious,customer2N_{suspicious,customer} \ge 2

and each of these nodes has:

Composite60Composite \ge 60

then each node receives a cluster correction:

Compositeclustered=min(100,  Composite+10)Composite_{clustered} = min(100,\;Composite + 10)

The cluster correction is not proof. It only raises the verification priority, because several nodes of one organisation require joint analysis.

Level distribution

The final score is translated into a level.

CompositeLevel
≥ 60critical
30–60warning
< 30normal

A threshold of 60 means that the node has a strong signal or a combination of several independent signals. This does not mean proof — it means the node must enter the priority verification list.

TOP-N table

Main TOP-N table

Nodes are sorted by the final suspicion score. Each row contains six badge indicators for the signals, which lets you see at a glance why the node entered the top. Numbers in badges are 0…100 or ; the sign means “could not be computed”.

Main columns

ColumnMeaning
Rank (#)place in the ranking
IDnode identifier
Node nameobject name
Device typecorrector / telemetry type
Consumption, m³total consumption over the period
Percentileflow rank among similar nodes
Scorecomposite score
Losses, m³commercial priority, not confirmed damage
Signalssubscore values (6 badges)
Actionslinks to the detailed report and analytics

How to read the signals

In the table each signal is shown as a separate indicator:

  • 0 — signal computed and did not fire;
  • — signal unavailable;
  • >0 — signal fired with the indicated strength.

It is very important that is not equal to 0.

LinkWhat it opens
Suspicionthe Metering Bypass (node) report
Analyticsthe Consumption Analytics report

The “Suspicion” link is the main transition point for the field team and the investigator: the full forensic methodology is disclosed in that detailed report.

The “losses, m³” score

The “losses, m³” column is not a confirmed volume of theft. It is a commercial priority that combines the scale of node consumption and the final suspicion score:

EstimatedLossPriority=Consumption×Composite100EstimatedLossPriority = Consumption \times \frac{Composite}{100}

where Consumption is the total node consumption over the period and Composite is the final suspicion score.

For example, if Consumption = 100000 m³ and Composite = 80, then EstimatedLossPriority = 80000 m³. This does not mean that 80,000 m³ have been lost. It means the node has a large commercial verification scale: large consumption x high score.

Analytics and conclusions

Analytics and conclusions

The summary below the table presents key numbers across the fleet: how many nodes have several independent signals (the most worrying combination), how many have a peer anomaly, and how many are in clusters. The last bullet is a mandatory reminder of the report’s legal status.

The analytics block shows how many nodes were analysed, how many reached the critical level, how many are in the warning zone, how many have two or more independent signals, how many consume abnormally little relative to the cohort, how many are in organisation clusters, and a reminder that the final score is not proof.

Nodes with several independent signals

A node is considered especially important for verification if:

Nstrong_signals2N_{strong\_signals} \ge 2

where a strong subscore is:

Si50S_i \ge 50

Such nodes are often more important than nodes with a single isolated signal — the independence of the suspicion sources sharply raises trust in the ranking.

Nodes with peer anomaly

The number of nodes with abnormally low flow is counted by the condition:

Speer60S_{peer} \ge 60

Organisation clusters

The number of cluster nodes is counted as the number of rows with a cluster flag.

Device events timeline

Events timeline

Chip buttons open the timeline by the device types observed in the TOP-N. The goal is to see mass synchronous events: “vertical columns” on the time axis indicate coordinated actions in one district or mass maintenance.

The timeline displays events over time for the device types appearing in the TOP-N. It helps to see mass events on a single day or hour, find vertical columns of events, tell an individual case from a systemic one, and understand whether there was mass maintenance, an update or a failure.

Timeline viewPossible explanation
isolated eventsindividual node problem
several events for one organisationcluster check
many events for one device typesystemic model feature
vertical column in timemass action, update, failure, maintenance
events before a score increasepossible link with settings or interference

The AI summary

The AI summary is generated only as a human-language explanation of already-calculated results. It can briefly explain which nodes to check first, indicate which combinations of signals are most worrying, remind of possible false positives, and formulate a general conclusion for the manager.

The AI summary cannot change the composite score, change the critical/warning/normal level, confirm a violation, replace formulas, replace a field visit, replace the detailed node report, or create evidence.

False positives

Low consumption

Low consumption can be normal if the object was idle, there was a seasonal shutdown, the object did not work according to the contractual schedule, the production profile changed, the node serves a backup line, or the cohort was chosen too broadly.

Absence of winter growth

The absence of winter growth can be normal for technological consumers without heating, summer-only production, objects with constant load, objects using gas not for heating, or premises with a non-standard regime.

Device events

A device event can be routine if maintenance was carried out, there was verification, the battery was changed, the time was adjusted according to the regulations, the archive was read, or planned works were performed.

Peer anomaly

A node may be at the bottom of the cohort simply because the cohort is small, the object differs in capacity, devices of the same type are on different loads, the organisation has different kinds of objects, or the period contains downtime.

Hard gates and limitations

  • No data — no forensic conclusion. If there is no hourly archive, forensic signals must be unavailable. No data does not mean no suspicion; it means it is impossible to evaluate.
  • Unavailable signals are excluded. An unavailable signal does not participate in the product.
  • A fleet report cannot confirm interference. A fleet report does not have sufficient detail for an act. It only opens the path to the detailed node report.
  • “Losses” cannot be used as a damage amount. EstimatedLossPriority is a ranking of the commercial verification scale.
  • Different object types cannot be compared without a cohort. Flow comparison must be performed only within similar groups.

How to read the report

  1. Look at the distribution. If many nodes are in critical, determine whether these are real independent signals or an over-sensitive methodology.
  2. Open the top candidates. The highest-ranked nodes are the priority candidates for verification.
  3. Look at the signals, not only the score. Two nodes with the same score may have different causes — a direct forensic pattern, a peer anomaly, seasonality or device events.
  4. Check the commercial scale. Large consumption x high score is more important than small consumption x high score.
  5. Open the detailed report. The “Suspicion” link leads to the detailed report on the specific node.
  6. Check false causes. Before a field visit, check seasonality, object downtime, maintenance, consumer type, cohort correctness, the passport and device events.

The correct final conclusion

The correct conclusion from the report sounds like this:

text
The report identifies nodes with an elevated probability of under-metering
or metering bypass on the basis of independent mathematical and event signals.
The final score is used for prioritising verifications.
For a legal conclusion a detailed node breakdown, a field visit, seal check,
control measurement and documentary confirmation of device parameters are required.

An incorrect conclusion would be: “Nodes from the top are proven to bypass metering.”

Minimum criteria for a complete report

A report is methodologically complete if it contains the analysis period, fleet coverage, the number of analysed nodes, the level distribution, the TOP-N table, consumption for each node, the cohort percentile, the final composite score, the estimated loss priority, the values of all available subscores, the marking of unavailable signals, the description of the six signals, the weights and ceilings, the composite-score formula, the exclusion rule for unavailable signals, the cluster correction, the AI disclaimer, the “not proof” disclaimer, and links to the detailed report for each node.

Summary formula

The final logic can be written briefly:

Sdirect,Speer,Sbypass,Sdivergence,Sseasonal,Srecency[0,100]{unavailable}S_{direct}, S_{peer}, S_{bypass}, S_{divergence}, S_{seasonal}, S_{recency} \in [0,100] \cup \{unavailable\} pi=Ci×Si100p_i = C_i \times \frac{S_i}{100} Composite=100×(1iAvailableSignals(1pi))Composite = 100 \times \left( 1 - \prod_{i \in AvailableSignals} (1 - p_i) \right) Compositefinal=min(100,  Composite+ClusterBonus)Composite_{final} = min(100,\;Composite + ClusterBonus)

where:

ClusterBonus={10,if the organisation has ≥2 nodes with Composite ≥ 600,otherwiseClusterBonus = \begin{cases} 10, & \text{if the organisation has ≥2 nodes with Composite ≥ 60} \\ 0, & \text{otherwise} \end{cases}

Commercial priority:

EstimatedLossPriority=Consumption×Compositefinal100EstimatedLossPriority = Consumption \times \frac{Composite_{final}}{100}
text
The report is a verification-prioritisation tool. The final suspicion score
is calculated by formal indicators and is not proof of a violation.
For a legally significant conclusion a field check, an act, seal verification,
control measurement, passport data and a detailed analysis of the specific
node are required.

Relation to other reports

DirectionWhere to look
communication, battery, general gaps, passport issuesoperational problem-nodes report
fleet-wide suspicionthis report
detailed breakdown of a specific nodeMetering Bypass (node)
data quality of a single nodeConsumption Analytics

This separation keeps an operational fault distinct from suspicion of under-metering.

Related topics

Last updated on

Was this page helpful?