Join our Newsletter — 33% off our NHI Course

How should organisations strengthen account opening to reduce synthetic identity fraud in remote channels?

Organisations should move beyond static knowledge checks and require stronger proof at enrolment. A practical approach combines document verification, face matching, liveness detection, and authoritative data checks against trusted sources. Teams should also verify phone and email ownership, because synthetic identities often pass simple checks by reusing stolen or fabricated attributes that look credible on the surface.

Why This Matters for Security Teams

synthetic identity fraud succeeds when onboarding controls are tuned for speed, not assurance. Remote channels are especially exposed because fraudsters can assemble a believable profile from stolen attributes, then reinforce it with low-cost signals that look legitimate on paper. That is why static knowledge-based checks, SMS-only verification, and weak document review no longer provide meaningful resistance.

Current guidance suggests treating account opening as a risk-based identity proofing problem, not a checkbox exercise. NIST SP 800-53 Rev. 5 emphasises stronger identity assurance and verification controls for access-intensive processes, while NHIMG research shows how easily attackers exploit weak identity and credential hygiene across the broader ecosystem in the Ultimate Guide to NHIs and 52 NHI Breaches Analysis. In practice, many security teams encounter synthetic identities only after the account has already been used for mule activity, credit abuse, or downstream account takeover, rather than through intentional prevention.

How It Works in Practice

Effective remote onboarding layers multiple signals so no single control becomes the point of failure. The strongest programs combine document authenticity checks, biometric comparison, liveness detection, device and session intelligence, and authoritative data verification against trusted sources. The point is not to eliminate all fraud, but to make identity fabrication expensive, slow, and easy to challenge.

Operationally, this usually means separating proofing into stages. First, validate the presented identity evidence. Next, test whether the applicant is physically present and matches the document holder. Then, verify ownership of the phone number and email address using stronger methods than a one-time code alone. Finally, score the application against behavioural and network risk so that edge cases can be routed to manual review.

  • Use document verification that checks authenticity, tampering, and issuer consistency.
  • Pair face matching with liveness detection to reduce replay and deepfake-assisted enrolment.
  • Use authoritative source checks where available, especially for high-risk products or regulated flows.
  • Verify email and phone ownership with evidence that survives SIM swap and disposable-account abuse.
  • Preserve a review trail so investigators can see which signals failed and why.

For teams building a broader control set, the NIST SP 800-53 Rev. 5 control catalog is the right place to map identity proofing, validation, and monitoring requirements to internal policy. NHIMG’s Top 10 NHI Issues also highlights a useful operational pattern: weak identity assurance is often paired with weak lifecycle oversight, which compounds downstream fraud and abuse. These controls tend to break down when onboarding is outsourced across multiple vendors because evidence quality, decision thresholds, and exception handling become inconsistent.

Common Variations and Edge Cases

Tighter onboarding often increases friction and review cost, requiring organisations to balance fraud loss reduction against abandonment rates and operational throughput. That tradeoff is real, especially in consumer-first channels where false rejects can be expensive. The best practice is evolving toward step-up proofing, where low-risk applications move quickly and higher-risk applications trigger stronger checks.

There is no universal standard for this yet, but several patterns are broadly useful. High-value financial products may justify authoritative record checks and manual review. Thin-file applicants may need alternative evidence sources so legitimate customers are not unfairly blocked. Cross-border onboarding can be harder because document formats, source availability, and privacy rules vary significantly. In some regions, current guidance suggests using progressive trust building after enrolment rather than demanding maximum evidence at the first interaction.

Teams should also watch for fraud rings that reuse device fingerprints, phone farms, or synthetic supporting data across many applications. The control goal is consistency: the same identity claim should be corroborated by independent, hard-to-fake signals. Where organisations want a deeper control baseline, the Ultimate Guide to NHIs provides a practical reference point for why identity assurance fails when validation, lifecycle oversight, and exception handling are disconnected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA Identity proofing and access assurance are central to remote account opening.
NIST SP 800-63 IAL2 IAL2 maps to stronger identity proofing needed to resist synthetic identities.
NIST SP 800-53 Rev 5 IA-2 Identity verification at enrolment underpins stronger account assurance.
OWASP Non-Human Identity Top 10 NHI-01 Weak identity validation creates exploitable trust chains analogous to NHI abuse.

Treat onboarding as an identity assurance workflow with risk-based verification and documented exception handling.