You don’t have a fraud problem?
Low reported fraud can hide identity risk, customer friction and review costs. Learn how financial-services teams can test their controls for blind spots.

Your competitors do. You hear about their fraudulent applications, stolen identities and losses. But your own numbers look different.
Fraud losses are low. Your onboarding checks work. Your team reviews suspicious applications. There are more urgent things to spend time and budget on.
That may be an accurate assessment.
But before closing the conversation, there is one question worth asking:
What evidence tells you that fraud is low, and what would your current controls struggle to see?
For teams that approve customers, enable spending or move money, the answer matters. Low reported fraud can reflect effective prevention. It can also reflect how losses are classified, how much business is declined or whether an identity has been investigated deeply enough to establish what happened.
The purpose is to understand what is producing a good result, what it costs and whether it will hold as the business grows.
Key takeaways
- Low reported fraud is encouraging. Assess it alongside detection coverage, loss classification, customer friction and review effort.
- Passing KYC answers the questions those checks were designed to assess. Additional identity questions may remain.
- Competitor incidents are useful prompts to test a specific attack method against your own controls.
- A focused retrospective assessment can test whether additional evidence improves decisions before you commit to another tool.
If an applicant passes KYC, what is left to check?
Passing the checks in your onboarding process is meaningful. It tells you the applicant met the requirements those checks were designed to assess.
The next question is what those requirements cover.
A document check, a database match and a phone verification each answer a particular question. Depending on the implementation, they may leave other questions open:
Does the information form a consistent identity across independent sources? Are there unexplained connections to other applications? Does the broader evidence support the identity being presented?
The Federal Reserve defines synthetic identity fraud as using an identity assembled from real and/or fictitious information to commit a dishonest act for gain. Individual details can therefore look plausible while the identity as a whole deserves investigation.
Additional context can help a fraud team assess the relationship between the details, rather than relying solely on whether each detail passes a check.
That context needs careful interpretation. A limited digital footprint is not proof of fraud. A young applicant, an immigrant or someone who values privacy may have little publicly available information.
The goal is to identify meaningful inconsistencies while preserving a fair path for legitimate applicants.
These questions apply across different business models. In leasing and alternative credit, identity confidence is separate from repayment capacity. In bank payments, new evidence needs to add value beyond existing identity and account ownership checks. In business spending, knowing an individual’s identity does not establish their authority to act for a business or authorise a payment.


Are your low losses coming at the expense of good customers?
Even if fraud is well controlled, there may be another opportunity: improving how efficiently you control it.
Ask how much friction sits behind the result.
How many applicants are asked for additional documents? How many cases require an analyst? Which rules generate the most reviews, and what proportion of those reviews find a real issue?
A control can prevent losses and still create avoidable costs.
This matters particularly when customers have limited conventional data. A sparse credit file can make an applicant harder to assess without making their identity fraudulent. Blanket escalation may leave legitimate customers waiting while reviewers search for evidence.
Additional identity evidence may help resolve uncertain cases, support more targeted verification or give reviewers a clearer basis for a decision. Whether it does so should be tested against actual outcomes.
Loss classification also deserves attention. A customer stops paying and cannot be reached. Was this repayment difficulty, or an identity created to obtain goods or credit? The Federal Reserve’s synthetic identity toolkit discusses whether a loss warrants further investigation or should be classified as a credit loss.
That does not make every default suspicious. It makes selected unexplained losses worth examining.
The commercial question becomes: could we make better decisions with the same risk appetite?
Does fraud at a competitor tell you anything about your own exposure?
It gives you a reason to ask questions, not a reason to assume the same outcome.
Your competitor may have different products, acquisition channels, customer segments or controls. Their losses are not a forecast of yours.
But if you serve similar applicants through similar digital journeys, it is worth examining whether the attack method could apply to your business.
Could the same type of identity pass your onboarding checks? What evidence would cause your team to investigate? Would you recognise the issue before a loss occurred?
For a payment platform, the relevant question may arise when a customer links a funding account. For a business spending platform, it may arise before an applicant receives access to a spending facility.
The point is to identify the decision your controls need to support. You may find that an existing check already addresses the method. You may find a gap worth testing.
A competitor’s incident is most useful when it becomes a specific control question.
“Could this happen here?” is a better starting point than either dismissing it or treating it as proof that your own defences are failing.
How can you test for blind spots without buying another platform?
Start with a focused retrospective assessment.
Choose a question that matters commercially: potential identity fraud among selected early defaults, unresolved manual reviews or suspicious applications that passed existing checks.
Then evaluate whether additional signals provide information your current process missed.
Assess the findings against known outcomes and analyst investigation. Keep confirmed fraud separate from cases that are merely unusual or unresolved.
Look for practical value:
- Did the new evidence identify validated risk beyond existing controls?
- Was that evidence available when the original decision was made?
- Would it have changed the action taken?
- How many legitimate applicants would also have been flagged?
- Would it reduce review effort enough to justify its cost?
For historical assessments, timing matters. Information that appeared after a loss cannot be treated as evidence your team could have used at onboarding.


Heka’s identity intelligence brings digital, social and darknet signals into that assessment, adding context for fraud teams to investigate identities and test where broader evidence could improve decisions.
The assessment may uncover a gap. It may also confirm that your current controls are performing well.
Either result is useful.
You don’t have a fraud problem? That may be true.
The strongest next step is to understand why, and have the evidence to back it up.
Explore what additional identity evidence could add to your current controls.


