Platform
Solutions
Resources
Company
Resources
Solutions

Credit and financing: identity and fraud risk at the time of application

There are two distinct questions in a credit application: is the applicant really who they say they are, and will they pay it back. TruvaLI answers the first with identity verification and fraud signals, and provides data for the second.

Risk in credit and financing institutions is two-layered. Credit risk is whether the borrower will repay. Fraud risk is whether the application itself is genuine, and these are measured using different methods. An application can have a perfect credit score and still be made with a stolen identity.

What does application fraud look like?

PatternWhat it indicates
Identity theftAn application made using a real person's information without their knowledge
Synthetic identityAn identity created by combining real and fabricated information
Income declaration manipulationAltering the amount or employer information on a document
Application clusterMultiple applications coming from the same device, IP, or email pattern
Re-applicationA rejected application resubmitted with minor changes

Synthetic identity is particularly challenging because the individual builds a credit history and pays regularly for a period. Therefore, device, network, and email signals at the time of application create a control layer independent of credit history.

How is identity verified?

Remote identity verification in remote credit applications starts with document reading but does not end there: chip reading via NFC on chipped documents, liveness testing, and face matching validate each other. Someone who can copy a document cannot bypass both the chip and liveness checks. Details are on the customer onboarding page.

The text of uploaded income documents is read, and the amount, date, and party information within are converted into structured data, making it comparable with the declaration.

What does the application network reveal?

A single application may look clean. Thirty applications coming from the same device, the same IP, or highly similar email addresses do not. The relationship network unpacks these clusters: if one application is suspicious, others linked to it are also put under review. Details are on the fraud detection page.

On the email side, the address provider generates a reputation score: whether the address contains the person's first name, last name, or date of birth, and its proximity to similar addresses in the system via fuzzy search, serve as separate signals.

There are also money laundering obligations

Credit and financing institutions are MASAK obliged parties: identity verification during customer onboarding, identifying the ultimate beneficial owner (UBO), sanctions and PEP screening, and suspicious transaction reports are mandatory. The source of credit payments and early closures is also subject to monitoring: an unexpected bulk closure raises questions about the source of funds.

The framework is detailed on the MASAK obligations page, and the review process is on the source of funds review page. The regulator of the institution is BDDK.

Who determines the threshold?

The threshold debate is particularly sensitive in credit institutions because the rejection rate directly impacts revenue. How many applications a new rule will reject and how many of those are actually fraud is measured against historical application traffic before the rule goes live. This is explained on the rule simulation and backtesting page.

A past fraud case is a source for rules: generating rules from past cases.

Common questions

Is credit risk the same as fraud risk?
No. Credit risk asks whether the borrower will repay, while fraud risk asks whether the application is genuine. An application with a perfect credit score can be made with a stolen identity.
Why is synthetic identity hard to detect?
An identity created by combining real and fabricated information builds a credit history and pays regularly for a period. Therefore, device, network, and email signals create a layer independent of credit history.
How is remote identity verification performed?
It starts with document reading: chip reading via NFC on chipped documents, liveness testing, and face matching validate each other. Someone who copies a document cannot bypass both the chip and liveness checks.
Are income documents checked?
The text of the uploaded document is read, and the amount, date, and party information within are converted into structured data, making it comparable with the declaration.
Are bulk application clusters detected?
Yes. Applications coming from the same device, IP, or similar email addresses are unpacked using a relationship network: if one application is suspicious, others linked to it are also put under review.
Are credit institutions MASAK obliged parties?
Yes. Identity verification, identifying the ultimate beneficial owner (UBO), sanctions and PEP screening, and suspicious transaction reports are mandatory. The regulator of the institution is BDDK.
Why are early closures reviewed?
An unexpected bulk closure raises questions about the source of funds and is subject to monitoring.
Can the impact of the rejection rate be measured?
Yes. How many applications a new rule will reject and how many of those are actually fraud is measured against historical application traffic before going live.

Related