Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should financial institutions stop synthetic identity fraud…
Identity Beyond IAM

How should financial institutions stop synthetic identity fraud before an account is opened?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

The best defence is to verify genuine presence at onboarding, not after account creation. Financial institutions should combine biometric face verification with liveness detection so the system checks whether the person is real, live, and present in real time. That approach is stronger than passwords, OTPs, or device checks because synthetic identities often pass those controls while still being fabricated.

Why pre-open verification has to happen before synthetic identities become accounts

synthetic identity fraud succeeds when onboarding accepts a convincing profile as if it were a real person. Once an account exists, the fraud can move into deposits, credit, or mule activity, so the decisive control point is the first proof of presence. Financial institutions should treat onboarding as a real-time verification problem, not a data-quality problem.

The most effective pre-account check is to confirm that the applicant is physically present and responsive during capture. That is why biometric face verification paired with liveness detection matters: it checks for an actual live subject, not just a face image, replay, or synthetic presentation. This is materially stronger than relying on passwords, OTPs, or device reputation alone.

Institutions also need to understand the fraud pattern they are trying to block. Synthetic identities are often assembled from fragments of real and fabricated data, so traditional identity database checks can look clean even when the underlying person is not real. A good onboarding control therefore measures presentation authenticity, not just document consistency.

What strong onboarding controls should verify

A robust flow should create friction only where it is needed, at the point where fraud would otherwise cross the trust boundary. That usually means verifying the applicant, validating the document or credential evidence, and confirming that the person presenting the evidence is live at that moment. The control is strongest when those checks are linked in one session rather than scattered across multiple asynchronous steps.

  • Use face matching as one signal, not the only signal.
  • Require liveness detection that resists replay, photo, video, and mask attacks.
  • Bind the verification result to the specific onboarding session and account request.
  • Escalate cases with weak facial quality, repeated retries, or inconsistent enrollment signals.
  • Keep a review path for edge cases rather than forcing all exceptions through automation.

For financial institutions, this is especially important because the first successful acceptance often creates downstream lending, payments, or transfer exposure. A strong onboarding control should therefore be designed to fail closed when presence cannot be confidently established, even if the applicant profile otherwise appears plausible.

Risk and Threat Considerations

Synthetic identity fraud is dangerous because it exploits the gap between identity data and real-world presence. Attackers or fraud rings can combine legitimate fragments with fabricated attributes, then use a weak onboarding process to obtain an account that later supports credit abuse, mule activity, or account stacking.

Failure mechanism: if onboarding only validates static attributes, device reputation, or one-time codes, the institution may accept an identity that looks consistent on paper but has no verified live human behind it. That allows fabricated identities to clear before any behavioural or transactional pattern can expose the fraud.

Impact: the institution can open accounts for non-genuine customers, absorb fraud losses later in the lifecycle, and create remediation costs that are much higher than rejecting the applicant up front. It also weakens downstream trust in KYC, monitoring, and fraud-scoring signals because the earliest control point was bypassed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-635.2 — Identity Proofing and EnrollmentDirectly governs remote identity proofing and enrollment for account opening.
4.3 — Phishing-Resistant AuthenticatorsSupports stronger verification than passwords or OTPs during financial onboarding.
Recommendation — Apply identity-proofing controls that require strong enrollment evidence before creating the account. Prefer phishing-resistant authenticators where onboarding also establishes account access.
CIS Controls v86 — Access Control ManagementLeast-privilege and access governance help limit post-onboarding abuse if fraud slips through.
5 — Account ManagementAccount lifecycle controls are central when deciding whether to open or reject a synthetic identity.
Recommendation — Restrict account capabilities until identity evidence and risk checks are complete. Enforce approval and exception handling rules before creating customer accounts.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlThe topic depends on verifying identity before granting account access and trust.
GV.RM — Risk Management StrategySynthetic identity fraud requires risk-based onboarding decisions and escalation thresholds.
Recommendation — Use identity and authentication controls to prevent unverified applicants from obtaining access. Set risk thresholds that trigger step-up verification or manual review before account opening.
PCI DSS v4.08.6 — System and Application Accounts and AuthenticationRelevant where financial services onboarding ties identity proofing to controlled access.
Recommendation — Keep account authentication tightly controlled and avoid weak shared onboarding credentials.

Practitioner Guidance

What to prioritise: put the highest confidence check at the earliest irreversible decision point. If the account can be opened, funded, or used before live presence is proven, the control design is too late.

What to verify: the liveness test must be proven against presentation attacks, not just measured for match accuracy. Review how the vendor handles replay resistance, challenge freshness, retry limits, and fallback handling for poor-quality captures.

Decision rule: if the session cannot establish real-time presence with high confidence, route the case to step-up review or manual verification rather than letting downstream monitoring “catch it later.”

Practitioner takeaway: synthetic identity fraud is best stopped by making real presence a precondition for account creation, because every later control is compensating for an acceptance decision that already went wrong.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org