A synthetic identity is not a stolen one. That distinction defeats most of the controls built to catch fraud.

The lifecycle that defeats behavioural monitoring. Every stage before the last one is indistinguishable from a good customer, because the behaviour is good.
Identity fraud controls are largely built on a single assumption: that a fraudulent application is an impersonation of a real person, and that the real person will eventually notice and complain. Synthetic identity fraud breaks that assumption, which is why institutions can hold strong verification controls and still carry meaningful exposure.
What a synthetic identity is
A synthetic identity is a constructed persona, typically assembled from a combination of real and fabricated attributes, that does not correspond to a single living individual. Because no real person is being impersonated, there is no victim to report the fraud, and the account does not generate the complaint that usually triggers investigation.
These identities are frequently cultivated rather than used immediately. The persona opens a small facility, behaves impeccably, builds a credit profile over months or years, and is progressively extended more credit on the strength of that record. The loss is realised at the end, when all available facilities are drawn simultaneously and abandoned.
Why standard controls struggle
Document verification checks that a document is genuine and internally consistent, which a well-constructed synthetic identity can satisfy. Database verification checks that attributes appear in reference data, which cultivated identities eventually do, because their own activity creates the record. Behavioural monitoring looks for anomalies against a profile, and a synthetic identity built through good behaviour is anomalous only at the moment of the loss.
The pattern to note is that each control is doing its job correctly. The failure is at the level of the assumption, not the execution. This is the reason that buying a better verification tool, on its own, tends not to move the number.
The reference-data ground is shifting underneath the controls
Two changes in the last eighteen months are worth registering, because both alter what a verification control can lean on.
In the United States, the Corporate Transparency Act reporting regime was cut back sharply. A FinCEN interim final rule published on 26 March 2026 redefined a reporting company to mean only entities formed under foreign law and registered to do business in a US state or tribal jurisdiction, exempting US-formed entities entirely. The Government Accountability Office assessed in May 2026 that the change eliminates more than 99 per cent of entities that previously had to report. For anyone who had assumed a federal beneficial-ownership registry would become a verification source for US entities, that assumption is gone, and ownership data has to be sourced under the customer due diligence rule and from state registers instead.
Separately, and pulling the other way, a June 2025 order by the OCC, FDIC and NCUA, with FinCEN's concurrence and a matching Federal Reserve order in July 2025, permits a bank to obtain a customer's taxpayer identification number from a third-party source rather than directly from the customer. It is permissive, not mandatory. It is also the first real change to customer identification programme data sourcing since 2003, and it moves the control burden onto the quality of the third-party data and the evidence a firm keeps about why that source is reliable.
In the United Kingdom, the direction is the opposite. Companies House identity verification under the Economic Crime and Corporate Transparency Act became mandatory for new directors on 18 November 2025, with existing directors confirming at their next confirmation statement. Companies House has estimated that six to seven million individuals must verify by mid-November 2026. Verification status is visible on the register, which makes it usable as a risk signal in entity onboarding rather than merely a filing formality.
The useful signal is not the presence of a bad history. It is the absence of a coherent one. Real people accumulate a scattered, inconsistent, cross-referenced footprint over decades. A constructed identity has a history that begins abruptly and is unusually tidy.
What tends to work
Detection generally depends on looking for that absence rather than for the presence of something adverse. Cross-institution signal matters here, because the pattern that identifies a synthetic identity, such as one attribute appearing across multiple otherwise unrelated identities, is frequently invisible inside a single institution's data. This is one of the areas where consortium data and shared signals have a rationale that is not simply vendor positioning.
Note also that the regulatory treatment of fraud models is not the same as the treatment of credit models. In the EU AI Act, the high-risk classification for creditworthiness assessment at Annex III point 5(b) carries an express exception for AI systems used for the purpose of detecting financial fraud. That is a narrow carve-out and it does not extend to the credit decision itself, but it means the two model families sit in different compliance positions inside the same institution.
The measurement problem underneath
Losses from synthetic identity are commonly classified as credit losses rather than fraud losses, because the account defaults and there is no victim to reclassify it. That misclassification compounds: the fraud function is not credited with the exposure it would prevent, and therefore struggles to justify investment, while the credit function absorbs a loss it could never have underwritten against.
Institutions that have addressed this seriously usually began by reviewing charged-off accounts for synthetic characteristics. The exercise is unwelcome, because it tends to reveal that a portion of what was booked as credit loss was never credit risk at all.
This is reporting on financial technology and risk. It is not legal, compliance or investment advice.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
FinCEN, Beneficial Ownership Information Reporting Requirement Revision and Deadline Extension, interim final rule, published 26 March 2025. https://www.federalregister.gov/documents/2025/03/26/2025-05199/beneficial-ownership-information-reporting-requirement-revision-and-deadline-extension
US Government Accountability Office, Beneficial ownership reporting, assessment of the revised scope, May 2026. https://www.gao.gov/products/gao-26-107967
OCC, FDIC and NCUA with FinCEN concurrence, Order permitting collection of taxpayer identification numbers from third-party sources, 27 June 2025. https://ncua.gov/files/press-releases-news/fincen-order-customer-identification-program.pdf
Companies House, Identity verification rollout from 18 November 2025, published 5 August 2025. https://www.gov.uk/government/news/companies-house-confirms-identity-verification-rollout-from-18-november-2025
European Union, Regulation (EU) 2024/1689, the AI Act, Annex III point 5(b). https://artificialintelligenceact.eu/annex/3/
How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.
Filed under Fraud, Risk & Financial Crime · Get The Weekly Brief

