Common warning signs include repeated account creation with different names or ID numbers, unusual success rates at onboarding, frequent failed logins, and suspicious attempts to reuse the same biometric traits. If the same person can pass verification multiple times, or if high-risk users move through the process without escalation, the programme is not deduplicating or monitoring effectively.
Why duplicate and synthetic identity failures show up in onboarding patterns
An anti-fraud programme that is missing duplicates usually leaves a trace in the onboarding funnel. You see the same device, address, phone number, or biometric pattern reappearing under different profiles, while verification outcomes look better than they should for risky applicants. That combination points to weak deduplication logic, poor linkage across records, or an identity proofing step that is too easy to replay.
The operational clue is not just that bad records exist, but that the programme fails to connect them. If your system treats each application as isolated, it can approve repeated submissions that are materially the same person or synthetic variants of the same identity profile. That is where the NHI definition and overview is useful as a reference point for how identity-linked artefacts, trust signals, and governance expectations need to be managed consistently.
Repeated successful onboarding under slight variations is often the earliest measurable sign that the control is failing. If the review process accepts many lookalike identities without escalating them, the programme is optimising for throughput rather than identity integrity.
Where the control gaps usually sit
Failures in this area usually come from a small set of control weaknesses. One is poor matching logic, where the programme relies on exact field matches instead of cross-signal correlation. Another is weak exception handling, where high-risk applicants can bypass extra checks after only a narrow rule trigger. A third is incomplete visibility, which means fraud analysts cannot see whether a profile already exists across channels, products, or geographies.
For synthetic identities, the gap is often that each piece of data looks individually plausible even though the overall pattern is inconsistent. That is why duplicate and synthetic identity detection has to combine document checks, device intelligence, behavioural signals, and case review, rather than depending on a single approval step. The 2024 ESG report on managing non-human identities is relevant here because it highlights how visibility and posture problems emerge when identity data is fragmented.
When the same applicant can pass verification multiple times, it usually means the programme is not applying enough friction at the right point in the journey. The most important failure is not one rejected case, but the absence of a reliable cross-record view.
Risk and Threat Considerations
Duplicate and synthetic identities create a compounding fraud problem. Once a false identity is onboarded cleanly, it can be reused for account abuse, money movement, mule activity, chargeback abuse, or layered fraud attempts that look legitimate at first glance. The risk grows when analysts only investigate obvious anomalies, because synthetic identities are designed to appear normal in isolation.
Failure mechanism: The programme lacks strong deduplication, escalation thresholds, or cross-channel correlation, so repeat applications and blended identity patterns are treated as separate legitimate customers instead of linked fraud signals.
Impact: Fraudsters can establish durable footholds, increase authorised-looking activity, and scale losses across accounts before the pattern becomes visible enough to block.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 — Monitoring for anomalous activity | Duplicate and synthetic identity patterns require continuous detection of abnormal onboarding behaviour. |
| PR.AA-1 — Identity management, authentication, and access control are implemented | Identity proofing and reuse resistance depend on strong identity handling at onboarding. | |
| Recommendation — Monitor onboarding for repeated, suspicious identity patterns and route anomalies to investigation. Strengthen identity proofing and reuse controls before granting account creation. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | Duplicate identities often persist when account inventory and linkage are incomplete. |
| Recommendation — Maintain a complete account inventory and reconcile repeated identities across systems. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets Sprawl | Identity abuse often scales when supporting identity material and trust signals are poorly governed. |
| Recommendation — Reduce uncontrolled identity-related material that lets repeated identities be recreated or reused. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Synthetic identity detection depends on stronger assurance when onboarding is higher risk. |
| Recommendation — Apply higher identity assurance requirements when onboarding risk indicators stack up. | ||
Practitioner Guidance
What to verify: Check whether the programme can link applicants across devices, contact data, document reuse, and biometric reappearance, then confirm that high-risk matches are routed to manual review rather than auto-approval. If the control only flags exact duplicates, it is probably too weak for synthetic identity activity.
What to measure: Track repeat-onboarding rates, exception override rates, and the share of high-risk applications that receive escalation. A rising approval rate with flat or falling review depth is often a sign that false identities are getting through faster than the controls can adapt.
Practitioner takeaway: The key question is not whether the programme blocks obvious fraud, but whether it can reliably connect weak signals across applications and force a higher-friction path before a synthetic identity becomes reusable.
Related resources from NHI Mgmt Group
- What are the signs that insurance identity verification is not catching synthetic identities?
- Why do synthetic identities make traditional fraud controls less effective?
- How should security teams reduce fraud when attackers use deepfakes and synthetic identities?
- How should insurers handle fraud when synthetic identities move through the full policy lifecycle?