Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should fraud teams update KYC controls when…
Governance, Ownership & Risk

How should fraud teams update KYC controls when synthetic identities are being used to create fake accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

Fraud teams should treat KYC as an ongoing control, not a one-time onboarding checkpoint. The strongest approach combines better identity verification, phone-centric identity signals, and persistent monitoring across the full customer lifecycle. That reduces the chance that synthetic identities slip through initial checks and later support fraud types such as account takeover, payment fraud, and dispute abuse.

How synthetic identities change the KYC problem

Synthetic identity fraud works because the account looks plausible enough to pass an isolated onboarding screen, even though the underlying person does not exist. That means KYC has to shift from a single identity-proof event to a risk control that accumulates evidence over time. The practical goal is to make weak, stitched-together identities harder to create, easier to challenge, and more expensive to sustain.

For fraud teams, the key change is not just stricter document checks. It is using multiple signals that are harder to synthesise at scale, then comparing those signals against lifecycle behaviour. That includes evidence of phone ownership, device continuity, contact reuse, account velocity, and whether the profile behaves like a real consumer after first login.

That lifecycle view matters because synthetic identities often only fail after they start transacting, linking funding sources, or interacting with support. A KYC control that does not continue after onboarding will miss the patterns that distinguish a fabricated identity from a low-risk customer.

What stronger KYC controls look like in practice

The most effective update is to combine identity verification with step-up signals that are more resistant to fabrication. Phone-centric evidence is often useful because it can help anchor the customer to a persistent contact point, but it should be treated as one signal, not a standalone proof. The same is true for device intelligence, address consistency, and velocity checks across applications, logins, funding events, and recovery actions.

Teams should also tighten controls around joins and changes that synthetic identities tend to exploit. Reused phone numbers, shared devices, rapid profile edits, weak recovery paths, and repeated failed verification attempts are all signs that the original KYC decision may need to be revisited. If those conditions are present, the account should move into a higher-friction review path rather than remain on default trust.

Monitoring needs to be proportional to customer risk. Low-risk customers may only need periodic review and automated anomaly detection, while higher-risk segments may need additional identity proofing, transaction review, and support-event scrutiny. The important point is that KYC outcomes should be revisable when downstream behaviour contradicts the original onboarding picture.

How to align fraud controls with the full customer lifecycle

Fraud teams get better results when KYC, transaction monitoring, and servicing controls share the same case view. Synthetic identity programs often succeed by staying calm at onboarding and becoming active later, so no single team can own the problem in isolation. Onboarding should flag uncertainty, analytics should watch for drift, and servicing should treat recovery requests, credential resets, and contact changes as high-value verification points.

This is also where control design should avoid false confidence. A strong document check does not compensate for weak post-onboarding monitoring, and a good risk model does not rescue a process that allows easy reuse of contact details or fast account re-creation. Teams need a control stack that makes it difficult for the same synthetic pattern to survive multiple checkpoints.

Where the business depends on fast onboarding, the right trade-off is usually targeted friction rather than blanket rejection. Put the most friction on combinations of signals that correlate with fabrication, and keep lower-friction paths for customers who present consistent, durable evidence across channels.

Risk and Threat Considerations

Synthetic identities are attractive because they convert weak onboarding controls into durable downstream fraud capacity. Once an account survives initial checks, it can be used for account takeover, payment abuse, credit or dispute fraud, mule activity, and recycling of trust across related accounts.

Failure mechanism: The control fails when KYC is treated as a point-in-time proofing event instead of an ongoing assessment, allowing reused contact data, device reuse, and behavioural drift to go unchallenged.

Impact: Fraud losses increase, manual review queues expand, and the organisation may keep trusting accounts that were never authentic in the first place, which weakens both detection and recovery.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementSynthetic identity controls depend on managing proofing and recovery factors over time.
IA-8 — Identification and Authentication (Non-Organizational Users)KYC is about proving external customer identities before account use.
AU-6 — Audit Review, Analysis, and ReportingOngoing monitoring is needed to catch synthetic identities after onboarding.
Recommendation — Rotate and govern customer authenticators and recovery factors when identity signals become inconsistent. Apply stronger identity proofing and authentication checks for external customer accounts. Review account and transaction telemetry for post-onboarding identity drift and fraud indicators.
CIS Controls v8CIS-5 — Account ManagementSynthetic identities exploit weak account lifecycle controls and reuse paths.
Recommendation — Tighten account lifecycle governance and remove accounts that fail continued verification.
ISO/IEC 27001:2022A.5.16 — Identity managementKYC updates require identity lifecycle governance, not one-time proofing.
Recommendation — Govern customer identity records across onboarding, change, and recovery events.

Practitioner Guidance

What to prioritise: Focus first on the signals synthetic identities struggle to keep consistent over time, especially phone ownership, device continuity, recovery behaviour, and account-change patterns. Those are usually more operationally useful than adding another one-off onboarding check.

What to verify: Make sure your review process can distinguish a genuinely new customer from an identity that is only newly assembled. If the same contact point, device fingerprint, or recovery path keeps reappearing across cases, treat that as a control weakness rather than an isolated exception.

Practitioner takeaway: The best KYC update is not simply stricter onboarding, it is a lifecycle control that can revise trust when later behaviour no longer matches the original identity story.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org