What problem does it solve?
Lenders and banks decide on applications from documents and data the applicant provides: pay slips, bank statements, tax forms, identity documents and a selfie. Editing tools and now generative AI make convincing forgeries cheap, and synthetic identities built from real and invented data can pass individual checks and build a credit history before they default.
Manual document review is slow and inconsistent, and reviewers cannot see metadata manipulation or the pattern across many applications, such as the same device, the same template or similar email addresses. Blunt rules, on the other hand, turn away genuine applicants and slow down the digital onboarding that customers expect. The same problem exists outside banking wherever documents prove eligibility: insurance, telecom contracts, rentals and public benefits.
- FinCEN reported an increase in suspicious activity reports describing suspected deepfake media, particularly fraudulent identity documents used to get past identity verification, and issued an alert with red flag indicators.FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (2024)
- In a Feedzai survey of 562 fraud and financial crime professionals at financial institutions, 92% of the institutions said fraudsters use generative AI.AI Fraud Trends 2025: Banks Fight Back (2025)
How does it work?
- Read the documents. Document AI extracts the data from pay slips, statements and identity documents and checks each file for tampering: metadata, fonts, layout against known templates, arithmetic that does not add up, and signs of generation.
- Check the identity. Identity data is verified against bureau and official sources, the identity document is checked for authenticity, and a liveness check confirms the applicant is present and matches the document.
- Look across the queue. Anomaly and graph models link applications that share devices, IP addresses, contact details, employers or document templates, exposing rings and synthetic identity farms.
- Score and explain. Signals combine into a fraud risk score with the reasons behind it, separate from the credit decision.
- Route, do not reject. Clean applications flow straight through; flagged ones go to a fraud analyst with the evidence, who decides whether to request more information, verify directly with the employer or bank, or decline.
- Audience
- Back office
- Autonomy
- Supervised agent
- Adoption
- Early adopters
- Channels
- API and system to system, Internal tools
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| Detection improvement | Too few to pool | 2.5x | 1 | 1 organization |
Value drivers: Risk and loss reduction, Speed and cycle time, Customer experience, Lower cost to serve.
Indicative value
A consumer lender processing 100,000 applications a year
USD 120,000 to USD 1.6 million
Application fraud losses avoided per year
How this is calculated
Formula: applications * fraudRate * lossPerFraud * extraCaught. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Applications per year applications, applications per year | 100,000 | 100,000 | The reference lender. |
| Share of applications that are fraudulent and would be approved today fraudRate, fraction of applications | 0.002 | 0.005 | Editorial assumption. Replace with your own confirmed application fraud rate. |
| Average loss per approved fraudulent application lossPerFraud, USD per case | 3,000 | 8,000 | Editorial assumption. Replace with your own charge off data. |
| Additional share of that fraud caught before approval extraCaught, fraction of fraudulent applications | 0.2 | 0.4 | Editorial assumption, far below the vendor reported result on this page (CNG Holdings saw a greater than 80% drop in third party fraud within 90 days). Replace with results from a back test on your own confirmed fraud. |
What it leaves out: Leaves out manual review time saved, faster approval for genuine applicants, lost revenue from wrongly declined applicants, and the cost of data sources and the platform.
Who already uses it?
6 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Department for Work and Pensions
United Kingdom · Government and public sector · 2026
DWP scores requests for Universal Credit advances in real time with a supervised machine learning classifier and refers the highest risk requests to a caseworker before payment. The caseworker is not told the referral came from the model, a random control group is referred alongside, and every decision to decline is made by a person and can be appealed. DWP's published effectiveness assessment for April 2025 to March 2026 finds the model 2.5 times more effective than random selection with a median payment delay of one day for approved referrals. It also finds that non UK nationals and several age bands were referred more often without a matching increase in confirmed fraud, and that referrals of couples were less often confirmed than those of single claimants; a retrained model was being tested.
- Detection improvement: 2.5x, 1 April 2025 to 31 March 2026
"The performance information for 2025 to 2026 demonstrates the model is 2.5 times more effective at identifying fraud risk than a randomised control group sample."
Claimed by: organization
Telstra
Australia · Telecommunications · 2025
Quantium Telstra built two services in collaboration with Commonwealth Bank. Scam Indicator detects and intercepts suspected scam calls to bank customers in real time and was later extended to landlines. Fraud Indicator, live from early 2025, securely shares intelligence about unusual mobile service usage so the bank can spot fraudsters opening accounts with a phone number they control. Telstra describes the Scam and Fraud Indicator as using AI and says it has safeguarded thousands of customers and prevented millions of dollars in fraud since 2023; the expected gain in detection of fraudulent accounts was published as a forecast.
No outcome disclosed.
BCU
United States · Banking · 2025
BCU, a US credit union, uses Inscribe's document fraud detection on loan documents and member account applications to find altered bank statements, pay stubs and other documents. Its investigators used the signals to uncover fraud rings, synthetic identities and reused document templates. The vendor reports USD 5.6 million in losses from altered documents prevented in the first nine months of 2025.
- Fraud losses prevented: USD 5.6 million, first nine months of 2025
"In the first nine months of 2025, BCU prevented $5.6 million in losses from altered documents and has now saved $80 million total!"
Claimed by: vendor
Close Brothers Motor Finance
United Kingdom · Banking · 2024
Close Brothers Motor Finance added Resistant AI's document forensics to its motor finance application process in August 2024, after a trial that surfaced 18 further fraud cases. Underwriters get a document fraud check, for example on company bank statements, in 12 seconds instead of a 15 minute manual assessment. The vendor reports fraud losses prevented, a high return on investment and faster application reviews.
- Fraud losses prevented: GBP 800,000, first 8 months after implementation
"£800,000 in fraud losses prevented in 8 months."
Claimed by: vendor
CNG Holdings
United States · Banking · 2023
CNG Holdings, a US consumer lender with online lending and around 1,000 retail stores, runs SAS fraud decisioning with machine learning on Microsoft Azure to verify applicants' identities in real time and stop third party and synthetic identity fraud at application. SAS reports a steep drop in third party fraud within 90 days, a very low fraud false positive rate and lower fraud programme costs after CNG retired several older tools.
- Cost reduction: at least 30%, fraud programme costs
"By replacing a disjointed patchwork of expensive and ineffective fraud tools with SAS’ integrated defenses, Cooney estimates that CNG cut its fraud program costs more than 30%."
Claimed by: vendor
Payoneer
United States · Payments and cards · 2023
Cross border payments platform Payoneer added Resistant AI's document forensics to its intelligent document processing in onboarding, to detect fake documents and serial fraud attempts while keeping onboarding fast. Resistant AI says it now supports more than 82% of Payoneer's document fraud decision making, with only edge cases escalated for manual review.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Confirmed application fraud and synthetic identity cases linked to the original applications
- Application, device and session data for every application
- Document images or files in their original format, not only extracted fields
- Access to bureau, identity verification and, where available, official data sources
Systems to integrate
- Loan origination or account opening system
- Identity verification and liveness service
- Credit bureau and fraud data sharing schemes
- Device intelligence
- Fraud case management
Complexity: Medium
Document and identity checks are available as services and integrate through APIs. The work is in combining signals across the application queue, feeding back confirmed fraud, and keeping fraud flags separate from credit decisions.
- 1
Collect the evidence you already have
Link past confirmed fraud and early defaults with no payments to their applications, and keep original document files. This is your test set.
- 2
Add document forensics to the existing flow
Run document checks on every uploaded file in shadow mode, measure what they catch against the test set, and tune thresholds before they affect any applicant.
- 3
Look across applications
Link applications by device, contact details, employer and document template to find rings that single application checks miss.
- 4
Route flagged applications to people
Send flags to fraud analysts with the evidence, and give them fast ways to verify, such as open banking data or direct employer confirmation.
- 5
Keep fraud and credit separate
Document that a fraud flag leads to investigation, not an automatic credit decline, and report false positive rates to the risk committee.
Guardrails
- A fraud flag triggers investigation or verification, never an automatic decline on its own
- Reasons for every flag stored and available to the analyst
- False positive rates monitored across customer groups to avoid unfair outcomes
- Liveness and biometric checks used only for one to one verification with consent
- Confirmed outcomes fed back to keep models current as generation tools improve
KPIs to instrument
- Application fraud losses and first payment defaults, normalised for volume
- Share of confirmed fraud flagged before approval
- Share of genuine applicants flagged, and time to clear them
- Straight through approval rate for clean applications
- Rings detected and applications linked per ring
Human in the loop
Fraud analysts decide every flagged application. Credit decisions stay in the credit process. The fraud strategy owner approves thresholds, and the risk committee receives false positive and performance reports.
Common failure modes
- The arms race
- Generation tools improve faster than template checks. Combine document forensics with data verification at the source and network signals.
- Fraud flag as a hidden decline
- Flags quietly turn into declines, creating fair lending and adverse action exposure. Separate the processes and audit outcomes.
- Punishing thin files
- Young people and newcomers look like synthetic identities. Test false positive rates on these groups and provide alternative verification.
What are the risks and rules?
EU AI Act
Depends on design
Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.
Rules that apply
Guidance
- Annex III: High-Risk AI Systems Referred to in Article 6(2) (European Union, Europe). Point 5(b) excludes fraud detection from high risk credit scoring; point 5(a) covers public benefits decisions; point 1(a) covers remote biometric identification, excluding one to one verification.
- Guidelines on the use of remote customer onboarding solutions (European Banking Authority, Europe). Sets expectations for the reliability of remote onboarding solutions, including checks that identity documents are genuine and not tampered with, and strong and reliable algorithms for biometric matching.
- FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (Financial Crimes Enforcement Network (FinCEN), North America). Describes typologies and red flag indicators for deepfake media, particularly fraudulent identity documents used to get past identity verification, and reminds institutions of their reporting duties under the Bank Secrecy Act.
Controls to put in place
- Documented separation between fraud flags and credit decisions
- Stored reasons for every flag and analyst decision
- Fairness monitoring of flag rates across customer groups
- Consent and data protection impact assessment for biometric checks
- Model inventory entry, validation and drift monitoring
When it went wrong elsewhere
- Revealed: bias found in AI system used to detect UK benefits fraud. The Guardian reported in December 2024 that an internal fairness assessment of the UK Department for Work and Pensions' machine learning model for Universal Credit advance claims found it selected people for fraud investigation at different rates by age, disability, marital status and nationality. Staff make the final decision, but the case shows why flag rates need fairness monitoring.
Frequently asked questions
- Can AI detect AI generated pay slips and bank statements?
- Often, by combining signals: file metadata, template and font analysis, arithmetic consistency and, most reliably, checking the data against the source through open banking or the employer. No single check is enough as generation tools improve.
- Should a fraud flag decline the application?
- No. A flag should lead to verification or investigation. Automatic declines based on fraud scores create fair lending and adverse action exposure and turn away genuine applicants.
- Is application fraud detection high risk under the EU AI Act?
- Fraud detection is excluded from the high risk credit scoring category, but the design matters. If the fraud score in effect decides credit, if you use remote biometric identification rather than one to one verification, or if a public authority uses it to decide on benefits, it can become high risk.
How to cite this page
Blits.ai AI Use Case Library, "AI for application and identity fraud detection", last verified 26 September 2026, https://www.blits.ai/ai-use-cases/application-and-identity-fraud-detection. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published