Identity Fraud
What is identity fraud?
What forms can identity fraud take?
- Impersonation: Using another person's personal information or documents to apply for an account, loan, or service
- Synthetic identity fraud: Creating a fictitious identity from a combination of personal information, which may include real and fabricated details
- Document-based deception: Submitting counterfeit or altered identity documents to support a false claim
- Account takeover: Gaining unauthorized control of an existing account and acting as its owner
How can businesses detect identity fraud?
- Document checks examine authenticity and consistency of the submitted identity evidence
- Biometric verification compares the applicant with a trusted reference, with liveness and capture-security controls supporting remote checks
- Source checks corroborate attributes against suitable issuer records or other reliable sources where available
- Account and device analysis looks for suspicious reuse, coordinated applications, and changes in account control
How can Regula help with identity fraud?
FAQ
How should a business distinguish identity fraud from identity theft?
Identity theft concerns unauthorized use of a real person's identity information. Identity fraud also covers fabricated identities and other deceptive identity claims. Case records can use both labels when stolen information is used fraudulently; the categories are not mutually exclusive.
Does reusing an identity document prove fraud?
No. A customer may legitimately apply for several products or retry verification. Review whether the document is associated with conflicting names, different applicants, or suspicious account activity before treating reuse as fraud.
Can identity fraud occur after successful KYC?
Yes. Credentials may be stolen, recovery procedures manipulated, or account access transferred after onboarding. Customer due diligence and fraud monitoring need to consider subsequent activity, including changes in ownership, control, and expected account use.
When should an identity fraud alert receive manual review?
Review is useful when the evidence is conflicting, an automated result is inconclusive, or rejection could affect a legitimate applicant. Reviewers need the specific reason for the alert and a defined way to obtain additional evidence or correct the decision.
How should businesses measure identity fraud controls?
Measure confirmed fraudulent applications accepted, legitimate applications incorrectly flagged, review workload, and resulting losses. Report biometric false matches and false non-matches separately. Approval rates alone cannot distinguish successful verification from undetected fraud.
What should a business do after confirming identity fraud?
Protect affected accounts, preserve relevant evidence, and investigate connected activity. Correct inaccurate customer records and coordinate fraud, security, support, and compliance teams. Notifications, account restrictions, and reporting should follow the facts of the case and applicable requirements.