Generic filters

What is anomaly detection?

Anomaly detection (also: anomaly identification) refers to the systematic identification of data points, patterns, or events that deviate significantly from expected behavior. In controlling and business intelligence, it is a key tool for filtering out precisely those outliers from the mass of business data that are relevant to decision-making. Bissantz software makes it possible to efficiently detect anomalies in business data and investigate their causes.

Feature Description
Category Data analysis / artificial intelligence / controlling
Application Automated monitoring of KPIs, time series, and business data
Typical areas of use Controlling, finance, IT security, quality assurance, fraud detection
Related terms Outlier detection, variance analysis, predictive analytics
Benefits Early detection of risks, reduced manual review effort, improved data quality

At a glance

  • Three types of anomalies: point anomalies, contextual anomalies, and collective anomalies require different detection methods and interpretations.

  • Three detection approaches: Statistical methods, rule-based systems, and machine-learning models can be combined and complement one another.

  • In controlling, an anomaly is often a signal of process problems, posting errors, or unexpected business developments.

  • Anomaly detection is always relative to a frame of reference.

Mehr anzeigen

What is an anomaly?

An anomaly is a data point, sequence, or pattern that cannot be explained by the expected behavior of a system. The term comes from the Greek anomalia (irregularity) and essentially describes what people or machines would consider “strange” or “in need of explanation.”

The key point is that an anomaly is not an absolute quantity; it is always relative to a frame of reference. What is normal in one context may indicate a serious problem in another. A 30% increase in revenue in December is expected during the holiday season; in February of the same year, it would be an anomaly requiring an explanation.

In practice, three types are distinguished:

  • Point anomalies are individual data points that deviate significantly from the expected value. They are the most common type and the easiest to detect—for example, a single posting amount that is several times higher than the usual level.

  • Contextual anomalies are values that appear unremarkable when viewed in isolation but are implausible in the context of their surroundings. A temperature of 25 degrees is normal in summer but an anomaly in January. In controlling, this could be a cost item that appears plausible on its own but cannot be explained in relation to revenue, seasonality, or the prior-year value.

  • Collective anomalies do not arise from individual outliers but from the combination of several values that are unusual when viewed together. No individual value necessarily exceeds a threshold—the pattern as a whole is what makes the deviation visible. In controlling, this could occur when several cost centers simultaneously show slightly elevated values without any one of them being conspicuous on its own.

Mehr anzeigen

This distinction affects which detection method is appropriate and how the results need to be interpreted. A system designed only for point anomalies will miss collective patterns—and potentially overlook precisely those anomalies that indicate systematic problems.

What does anomaly detection mean in controlling?

Controllers work with large volumes of data every day: revenue figures, cost trends, contribution margins, and liquidity KPIs. Most of these values fall within expected ranges. The exceptions are both problematic and informative: a cost item that suddenly rises 40% above the previous month’s level; a decline in revenue in a region that cannot be explained by seasonal patterns; a payment item that falls outside the normal range.

Without systematic anomaly detection, controllers rely on manual visual checks, experience, or chance. This is error-prone and does not scale—especially when companies need to monitor dozens of cost centers, hundreds of products, and multiple entities in parallel.

Anomaly detection automates precisely this step: It makes unusual patterns visible before they disappear into the noise of large volumes of data.

How does automated anomaly detection work?

Technically, three basic approaches can be distinguished:

  • Statistical methods: The classic approach: A measurement is considered an anomaly if it deviates statistically significantly from the expected value—for example, if it is more than two standard deviations away from the moving average. These methods are transparent, easy to explain, and sufficient for many controlling applications. Their disadvantage is that they assume the data follows a particular distribution and are sensitive to structural breaks in time series.

  • Rule-based systems: Here, the user explicitly defines what constitutes an anomaly: “If cost center X exceeds the budget value by more than 15%, trigger an alert.” Rule-based systems are easy to understand and can be readily integrated into existing controlling processes. However, they are blind to unknown types of anomalies—anything not covered by a rule remains invisible.

  • Machine-learning-based methods: Algorithms such as Isolation Forest, autoencoders, or LSTM networks (Long Short-Term Memory) learn the “normal” behavior of a dataset and identify deviations without explicit rules. They are particularly well suited to high-dimensional data and complex patterns that are difficult to capture statistically. The trade-off is that explainability must be strictly ensured, and implementation requires more effort.

Mehr anzeigen

In practice, these approaches are often combined. A rule-based filter triggers alerts for known thresholds; a statistical model monitors time series for unexpected breaks in trends; and a machine-learning model searches for hidden patterns in multidimensional data.

 

Comparison of detection approaches

 

Approach Strengths Weaknesses
Statistical Transparent, explainable, easy to implement Requires distribution assumptions, sensitive to structural breaks
Rule-based Easy to understand, directly controllable Blind to unknown patterns
Machine learning Detects complex and hidden patterns May require more implementation effort; explainability must be ensured

How are anomaly detection and visualization connected?

Anomaly detection only delivers its full value when its results are presented appropriately. Raw alert lists that report dozens of outliers every day create alert fatigue: Controllers start ignoring alerts because the signal-to-noise ratio is too low.

Effective visualizations show anomalies in context: embedded in time series, with reference ranges, and with indications of comparable historical events. Sparklines and color-coded heatmaps help users quickly identify unusual patterns without losing sight of the overall picture.

What are the limitations of anomaly detection?

To reliably detect all anomalies, a system must address several typical limitations:

  • False positives: Correct values are incorrectly flagged as anomalies—for example, because a special effect such as annual bonuses or one-time payments was not accounted for in the model.

  • False negatives: Genuine anomalies are overlooked because they develop gradually and never exceed a threshold on their own.

  • Concept drift: The model was trained on historical data representing a business model that has since changed. What was normal in the past may now be considered an anomaly—and vice versa.

Mehr anzeigen

These limitations are not an argument against automated anomaly detection. They are an argument for using it thoughtfully. Human-in-the-loop approaches and explainable AI help ensure the reliability of AI-powered anomaly detection.

Bissantz and anomaly detection

Bissantz does not treat anomaly detection as an isolated feature but as an integral part of an AI-powered controlling tool. In DeltaMaster, Bissantz’s BI and analytics platform, this concept is embedded in several functions:

  • Automatic outlier highlighting in reports: DeltaMaster analyzes KPIs and time series using artificial intelligence and immediately highlights values that deviate from the expected range.

  • Threshold logic: Configurable thresholds can be used to define business-specific tolerance ranges. Values that exceed these limits are highlighted using color—a simple but effective tool that integrates rule-based anomaly detection directly into the reporting context.

  • Sparklines and visual compression: Bissantz uses condensed time-series charts embedded in table rows. They make it possible to identify patterns at a glance and recognize anomalies in their temporal context without switching between a table and a chart.

  • Automatic report commentary: With its automatic text-generation feature, DeltaMaster describes notable deviations in natural language. The system identifies which values fall outside the expected range and provides explanations and recommendations for action.

Mehr anzeigen

Bissantz takes a clear approach here: Anomaly detection is not an algorithm that makes decisions autonomously. It is an attention system that supports fast and intelligent decision-making.

Investigate anomalies

Time is money. That is why it is crucial for companies to identify anomalies in their KPIs at an early stage. Instead of searching for causes in Excel spreadsheets, Bissantz users know immediately what is going on.

Data analysis tool

FAQ: frequently asked questions

What are anomalies?

Anomalies are conspicuous deviations from expected or typical values in data. In companies, they can indicate unusual revenue developments, significant fluctuations in sales volumes, or unexpected changes in costs and inventory, for example. In data analysis, anomalies help identify relevant developments early and investigate them in a targeted manner.

What is anomaly detection in simple terms?

Anomaly detection refers to the automatic identification of unusual patterns, values, or developments in data that deviate from expected behavior. It helps companies identify errors, risks, or unusual developments at an early stage and take appropriate action in a timely manner.

What is anomaly detection used for in controlling?

In controlling, anomaly detection can help identify posting errors, unexpected cost developments, deviations from budget targets, or unusual revenue patterns at an early stage—making it possible to take corrective action more quickly.

What is the difference between anomaly detection and variance analysis?

Variance analysis compares known reference values—for example, plan and actual figures—and explains why a difference occurred. Anomaly detection automatically identifies that a value is unusual, even without a predefined plan value. Both methods complement each other effectively in controlling.

What does concept drift mean in anomaly detection?

Concept drift describes the problem that a model was trained on historical data representing a business model or market environment that has since changed. What the model learned as “normal” may no longer correspond to current reality. Regular retraining and monitoring are therefore essential.

How does DeltaMaster support anomaly detection in controlling?

DeltaMaster automatically highlights outliers in KPIs and time series, integrates configurable thresholds directly into the reporting context, visualizes patterns over time using embedded sparklines, and describes notable deviations in natural language—as part of a continuous, AI-powered analytics process.

Summary

Anomaly detection is an indispensable tool in modern controlling: It makes unusual patterns visible before they disappear into the noise of large volumes of data—automated, scalable, and context-sensitive. Choosing the right detection approach, using appropriate visualization, and establishing clearly defined human-in-the-loop processes determine whether anomaly detection delivers genuine value or leads to alert fatigue. With DeltaMaster, Bissantz integrates anomaly detection as a permanent part of the controlling workflow—not as an isolated feature, but as an attention system that supports controllers where fast, well-founded decisions matter.

Free of charge for you

How AI takes over the work of interpretation—and helps companies move more quickly from analysis to action

Whitepaper Decision Intelligence

Nicolas Bissantz

Diagramme im Management

Besser entscheiden mit der richtigen Visualisierung von Daten

Erhältlich überall, wo es Bücher gibt, und im Haufe-Onlineshop.