How Synthetic Identities Slip Through Lending KYC

Posted by

–

Most lenders build KYC to answer one question: is this document real? A synthetic identity is built to pass exactly that test.

A synthetic identity is a profile stitched together from mixed material. It might pair a genuine ID number belonging to someone else with an invented name, birth date or photo. Or it might be an entirely fabricated person with documents good enough to clear a basic check. There is no victim calling your helpline, which is a big part of why it goes unnoticed.

This piece looks at where lending KYC leaves gaps, what a synthetic identity tends to look like once you know where to look, and which controls help.

Why this is hard to spot

With ordinary identity theft, a real person eventually notices. They see a loan they never took, file a complaint, and you learn about it. A synthetic identity has no one to complain. The loan simply goes bad, and it often gets written off as a credit loss instead of being logged as fraud.

That misclassification matters. If your collections team treats these accounts as ordinary defaults, your fraud numbers look healthier than they are, and nobody asks why the same pattern keeps repeating.

Where lending KYC leaves gaps

The common weakness is that each check is run in isolation, and each one passes.

Existence checks confirm a record exists, not that it belongs to this applicant. A PAN can be valid and operative and still be in the hands of someone who isn’t its owner. A format check or a status check can’t tell the difference.

Lenient name matching. To reduce false rejections, many teams loosen their fuzzy-match thresholds. That is sensible for genuine users with spelling variations, but a loose threshold also lets near-misses through. Teams often tune this in one direction only.

Liveness proves a live person, not the right person. A selfie that passes liveness confirms someone is present at the camera. It says less about whether that face has any real tie to the identity being claimed, especially when the comparison photo is the same document the applicant supplied.

Thin-file applicants get a pass by design. First-time borrowers have little bureau history, so there is little to contradict. Lenders courting this segment have fewer signals to lean on, and fraudsters know it.

Fresh contact details look the same as old ones. A mobile number activated last month and an email created last week can sit comfortably in an approval flow if nobody checks tenure.

The comparison: what each check sees and what it misses

CheckWhat it confirmsHow a synthetic identity can still passWhat closes the gap
PAN verificationPAN exists and its statusID is real but doesn’t belong to the applicantCross-match name and DOB against a second source
Aadhaar / DigiLockerIdentity data from a trusted sourceGenuine data used by someone else, or data from a different personTie the OTP or consent to a mobile with history
Face match + livenessA live person resembles the photoThe photo itself is the fabricated elementCompare against an independent source, add risk-based review
Name matchNames are similar enoughA loose threshold accepts near-missesTune by risk tier, flag borderline for review
Bank account verificationAccount exists, name returnedAccount is rented or opened with the same fabricated identityCheck account age and name consistency across sources
Bureau checkCredit history existsThin or newly built file looks cleanLook at file age, enquiry velocity and tradeline patterns
Mobile and email checkContact is reachableNewly created contact points passCheck tenure and reuse across applications

Signals that tend to show up in synthetic identity cases

No single signal proves anything, and genuine users trigger most of these occasionally. What matters is the combination.

  • Shared attributes across applications. The same device, phone number, address or bank account appearing under different names.
  • Young everything. A new number, a new email, a new bank account and a thin bureau file all arriving together.
  • Perfectly clean but oddly shallow profiles. Consistent data with no depth, like a stable address but no utility or telecom footprint.
  • Application clustering. Bursts of similar applications within a short window, often with small variations in name or date of birth.
  • Behaviour after approval. Small early loans repaid on time, then a rapid limit increase, then a large draw and silence. This is often called a bust-out pattern.

If your data science team can look at those clusters, graph-based link analysis tends to surface rings that application-by-application review never will.

Controls that actually help

Treat verification as layered, not sequential. Instead of checking PAN, then bank, then selfie as separate gates, compare the results against each other. A name that is slightly different across three sources is a stronger signal than a mismatch in any one.

Use the bank account as an identity anchor. The name returned during bank account verification gives you an independent data point. If it disagrees with the PAN or Aadhaar name, that deserves attention before you disburse.

Add friction in proportion to risk. Not every applicant needs extra steps. Raise scrutiny for larger tickets, thin files, fresh contact details and clustered applications, and keep the path light for everyone else.

Fix your loss classification. Review early-default accounts and ask whether identity was ever properly verified. Reclassifying even a sample will tell you how big the problem is.

Give reviewers context. A manual reviewer who sees the linked-application graph and the signal list makes a better call than one who sees a single applicant in isolation.

Stay aligned with your regulator. If you’re an RBI-regulated entity, your KYC and fraud-reporting obligations shape what you must collect and report. Personal data handling also falls under the Digital Personal Data Protection Act, 2023. Check with compliance before changing flows or adding data sources.

What to measure

  • First-payment and early-default rates by acquisition channel
  • Share of defaults later reclassified as identity fraud
  • Number of applications sharing a device, phone or account across different names
  • Approval rate versus review rate for thin-file applicants
  • Manual review overturn rate, which shows whether your thresholds are well placed

The bottom line

A synthetic identity doesn’t beat any single check so much as it exploits the gaps between them. Lenders who treat each verification as a separate yes/no tend to miss it. Those who compare sources against each other, watch behaviour after approval and count early defaults honestly tend to catch it sooner.

You won’t stop every case, and tightening too far will cost you genuine customers. The goal is to make fabricated profiles expensive to maintain while keeping the real borrower’s path short.

Leave a Reply

Your email address will not be published. Required fields are marked *