Table of Contents
Introduction: CKYC 2.0, Synthetic Identity Fraud and Why It Matters Now
CKYC 2.0, India’s shift to real-time verification, does not eliminate synthetic identity fraud on its own. Instead, its stronger digital KYC framework can close several identity-verification gaps that synthetic identities exploit, particularly when combined with real-time validation, trusted digital sources, and layered fraud controls.
Synthetic identity fraud in banking is growing rapidly across India, exploiting fragmented KYC processes and gaps in digital identity verification. According to TransUnion’s H1 2026 fraud trends data, 7.1% of consumer-facing transactions in India were suspected fraud in 2025, nearly double the global average, with identity-centric fraud a significant driver.
The core problem is deceptively simple. A synthetic identity often looks legitimate because each attribute in PAN, Aadhaar, mobile number, and address can be individually valid. But the combination does not represent a real person. CKYC 2.0 does not magically eliminate all fraud, but it can significantly enhance security by improving the coherence, consistency, and digital verification of identity data during financial onboarding, provided institutions strike the right balance between stronger controls and customer experience.
This article examines how financial institutions can use CKYC 2.0 and layered fraud controls to strengthen synthetic identity fraud prevention. It covers:
Why legacy KYC systems miss synthetic identities
How CKYC 2.0 identity verification improves data quality
Real-time cross-referencing and anomaly detection
DigiLocker KYC verification and trusted digital sources
Biometrics, facial matching, and liveness detection
Customer risk scoring for AML and fraud
Practical steps for compliance and fraud leaders to build a compliant and efficient onboarding approach
What Is Synthetic Identity Fraud?
Synthetic identity fraud occurs when criminals combine real and fabricated personal information, such as a legitimate PAN paired with a fake name, manufactured address, and newly generated phone number, to create a seemingly valid but entirely non-genuine customer profile built around a false identity claim.
The construction process is methodical. Fraudsters acquire real identifiers from data leaks or dark web purchases, then attach fabricated demographic details: new email addresses, fresh mobile numbers, and deliverable but unverifiable addresses. They open low-limit accounts or small-ticket products like BNPL, micro-credit, and small credit cards and build a transaction history over months, repaying consistently. Once creditworthiness is established, they escalate to larger exposures and default, vanishing with the funds.
This differs fundamentally from traditional identity theft. Identity theft steals and uses one real person’s complete profile. Synthetic identity fraud assembles a new identity from fragments that may never map to a single real individual. Each field passes validation, but the composite is a fabrication.
Consider these scenarios relevant to Indian financial institutions:
A digital lender receives multiple applications sharing the same Aadhaar number but with different names and addresses. Small loans are repaid on time, then larger applications default simultaneously.
A BNPL provider onboards a customer whose PAN is valid, mobile number is active, and address is a co-working space. Each check passes. The identity is synthetic.
A credit card issuer approves a thin-file applicant who builds usage over six months, then requests a high-limit card and maxes it out before disappearing.
Conventional identity verification struggles here because all documents and numbers validate individually. Without deeper data linkage and cross-attribute analysis, front-line KYC teams and automated systems have no reliable way to verify that the identity claim is genuine, even when individual fields validate.
Why Legacy KYC Systems Can Miss Synthetic Identities
Traditional KYC was designed primarily for document-based identity verification, not for detecting carefully constructed synthetic identities. Many onboarding processes in banks, NBFCs, and fintechs validate fields in isolation, use static checks, and focus on document authenticity rather than full identity coherence.
Validating Individual Fields Instead of the Complete Identity
Legacy onboarding typically confirms that a PAN exists in the Income Tax database, an Aadhaar number is active with UIDAI, a mobile number responds to OTP, and an address proof document appears genuine. But these systems rarely test whether these attributes actually belong together as one real person.
A synthetic applicant can use someone else’s PAN, a freshly fabricated name, a warehouse address, and a new mobile number under their control. Each piece is valid. The combination is not. This field-level validation creates blind spots because the organization only sees isolated data points instead of the full profile relationship between attributes, especially in fully digital journeys where automation pressure is high and manual scrutiny is minimal.
Static and Batch-Based Verification
Many institutions still rely on batch uploads to CKYCR or credit bureaus, periodic document updating, and one-time verification at account opening, which makes the verification process less effective during onboarding. These delayed controls mean fraudsters can reuse or mutate identity attributes across multiple applications before any inconsistency surfaces.
Without real-time identity verification, patterns such as the same mobile number linked to many unrelated names emerge only during audits or post-loss investigations, and those delayed reviews also weaken trust in digital onboarding controls – often too late to prevent damage.
Document Authenticity Is Not the Same as Identity Authenticity
Checking that a document is genuine – with correct watermarks, holograms, or formatting – is not the same as confirming that the applicant is the rightful holder of that identity. A fraudster using a genuine but stolen Aadhaar document can pass document authenticity checks while still operating a synthetic identity.
Synthetic identity fraud prevention requires moving beyond “Is this document valid?” to “Do these attributes coherently represent this person, and is the person presenting them genuinely associated with the record?”
How Does CKYC 2.0 Strengthen Identity Verification and Fraud Prevention?
CKYC 2.0 is the upgraded framework of India’s Central KYC Records Registry, maintained by the Central Registry of Securitisation (CERSAI). It introduces structured, digitally shared KYC data across financial institutions under regulatory oversight, enabling more connected verification workflows.
CKYC 2.0 is primarily a KYC data and process framework. It supports synthetic identity fraud prevention by improving the quality, consistency, and accessibility of customer information – not by acting as an automated fraud engine. Implemented within broader onboarding controls, it also helps institutions stay compliant. Its effectiveness relies on the integrity of the initial data supplied by institutions.
Key improvements relevant to fraud prevention:
CKYC 2.0 implements structured data standards, requiring submissions in JSON or XML formats rather than scanned PDFs. This enables machine-readable parsing and automated field-level validation across institutions.
It introduces an application-first verification network for customer identity data, allowing institutions to verify KYC data in real-time against national databases before account activation.
CKYC 2.0 employs AI-driven deduplication to identify duplicate records, flagging instances where the same identifiers appear across different profiles with conflicting attributes.
OTP-based consent tracking is mandated for accessing CKYC records, improving transparency and access control.
CKYC 2.0 enhances digital identity verification processes in financial services and provides verified KYC data to prevent identity fraud.
Fraud prevention measures in CKYC 2.0 focus on mitigating risks at multiple identity layers, actively combating synthetic identity fraud through registry-level checks.
It is important to distinguish between what CKYC 2.0 regulations require (structured data, deduplication, periodic updating), what the broader digital identity ecosystem enables (Aadhaar e-KYC, DigiLocker, PAN validation), and what additional controls institutions implement at their discretion (graph analytics, device intelligence, ML models).
CKYC 2.0 is expected to significantly enhance the detection of synthetic identities and fraud concerns. However, public effectiveness metrics for CKYC 2.0’s impact on synthetic fraud are currently lacking, and the actual benefit depends on how institutions integrate CKYC data with their internal fraud, AML, and identity verification systems, as well as on each institution’s business model and industry.
How Real-Time Cross-Referencing Exposes Synthetic Identity Signals
Real-time identity verification connects multiple data sources – CKYC records, PAN databases, telecom data where permitted, internal systems, credit bureaus – to test whether identity attributes are consistent, current, and plausible. CKYC 2.0 uses real-time APIs for data validation and KYC processes, and real-time validation reduces the risk of fraudulent identities slipping through.
Discrepancies are risk signals, not automatic proof of fraud, and institutions may place them into different risk categories before escalation. They should feed into the institution’s risk assessment and escalation workflows. Real-time API calls in CKYC 2.0 enhance access control and tracking, and the framework flags discrepancies in identity data before account activation.
Typical synthetic identity indicators institutions can look for:
Same mobile number linked to multiple unrelated CKYC records with different names
Date of birth mismatches between CKYC record and PAN or Aadhaar data
Sudden address changes across short time windows for customers sharing contact details
Applications from the same device or IP for identities that share elements but are not obviously linked
Thin-file customers whose declared income or employment is inconsistent with demographic attributes
The CKYC 2.0 Data API retrieves data using PAN numbers, and results are provided within one second, enabling institutions to run checks during the onboarding flow rather than in batch. Institutions should design rules and machine learning models that treat identity mismatches, duplicate attributes, and unusual combinations as inputs into synthetic identity fraud detection rather than isolated anomalies.
How DigiLocker and Trusted Digital Sources Improve KYC Data Integrity
DigiLocker is a Government of India digital document wallet that allows citizens to access digitally issued or verified documents from participating issuers, including driving licences, certain ID proofs, and financial documents.
The critical distinction is between customer-uploaded scans or photos – which can be manipulated, photoshopped, or forged – and documents retrieved directly from trusted digital channels like DigiLocker or issuer APIs, where permitted. Digitally sourced documents carry issuer signatures, metadata, and integrity checks that make tampering substantially harder.
Combining CKYC 2.0 records with DigiLocker KYC verification can reduce the risk of forged documents entering the onboarding process, indirectly strengthening synthetic identity fraud prevention in financial services. Institutions should design user journeys where, subject to regulatory requirements and consent, digital retrieval from government platforms is preferred over manual uploads.
However, DigiLocker itself does not validate whether all identity attributes belong to the same real person. That responsibility remains with the financial institution’s identity verification and fraud controls. Not all documents are available on DigiLocker, and not all digital document issuers enforce strong verification at issuance.
The Role of Biometrics, Facial Matching and Liveness in Digital Identity Verification
Biometrics, facial matching, and liveness detection are complementary tools that help verify presence and reduce impersonation risk during digital onboarding. Facial recognition is integrated at the registry level in CKYC 2.0, and registration requires checking biometric data across a national database.
However, CKYC 2.0 does not universally mandate these technologies for every onboarding journey. Regulated entities may deploy them as part of digital KYC fraud detection strategies where legally permitted and operationally feasible.
The conceptual stack works in layers:
Document verification – is the document genuine?
Identity verification – do attributes match trusted sources?
Facial matching – does the selfie match the document photo or Aadhaar image?
Liveness detection – is this a live person, not a replay or deepfake?
In a fully digital journey, a user scans their ID, takes a selfie, liveness checks confirm presence, document data is parsed and validated via CKYC and other databases, and any inconsistencies or failed matches trigger manual review. This makes it harder for a fraudster to repeatedly reuse the same synthetic identity across multiple institutions.
Best practices include ensuring explicit consent under the DPDP Act 2023, secure biometric data storage with clear purpose limitation, strong exception handling for customers who cannot easily complete biometric checks, and regular model updates to counter adversarial attacks, including deepfakes.
From Identity Verification to Identity Coherence: A New Fraud-Prevention Mindset
Identity coherence means that multiple identity attributes – name, date of birth, identifiers, address, devices, behavioural signals – must form a credible, internally consistent picture of one real person. Where legacy verification asks “Is this document valid?” the coherence mindset asks, “Do all of these attributes belong together?”
A practical progression for institutions:
Verify each data field independently
Cross-check against trusted sources (CKYC, PAN, Aadhaar, bureaus)
Assess cross-attribute coherence – are attributes plausible in combination?
Verify presence through facial matching, liveness, and device intelligence
Assess risk and determine CDD or EDD level
Monitor continuously for ongoing consistency
A coherent profile shows a stable address over years, consistent employment, matching identity data across sources, and gradually growing financial activity. An incoherent profile reveals frequent identity changes, shared devices across unrelated accounts, mismatched demographic details, and sudden spikes in credit usage.
CKYC 2.0 and digital identity verification tools create the data foundation for coherence analysis, but institutions must build rules, analytics, and case management practices to operationalise it. Identity confidence should be reassessed whenever key attributes change, risk signals appear, or transaction behaviour diverges from the initial profile.
How Enriched Identity Data Improves AML and Fraud Risk Scoring
AML risk scoring assesses money laundering risk for customers, and its accuracy depends directly on the quality of underlying identity data. Weak identity assurance leads to unreliable risk ratings and missed synthetic identity fraud.
The recommended workflow: identity data capture → validation via CKYC 2.0 and other sources → enrichment (bureau data, geolocation, device intelligence) → discrepancy and anomaly detection → customer risk scoring → CDD/EDD decision → ongoing monitoring.
Customer risk factors include political exposure and residency status, helping segment high risk customers from low risk customers. Geographical risk factors consider high-risk jurisdictions for transactions. Different industries require tailored AML risk scoring models, with banking, insurance, and other sectors needing different inputs and thresholds, and dynamic risk scoring adapts to changing customer behaviours rather than relying on a single onboarding assessment. Each organization should calibrate its model to its customer base and current growth stage.
Consider these scenarios: a low-income profile requesting a high-limit product with multiple address changes and no credit history should receive an elevated risk rating and enhanced scrutiny. A corporate entity with complex ownership from high-risk jurisdictions and inconsistent documents should trigger enhanced due diligence.
CKYC 2.0 itself does not calculate AML risk scores. Institutions must design their own models, and poor weighting can draw scrutiny from regulators, but better-quality KYC data supports more accurate segmentation and prioritisation. RegTech providers like ZIGRAM can help institutions aggregate identity data, enrich profiles, and integrate risk scoring with screening and transaction monitoring.
Why Robust Identity Verification Is the First Line of Defence Against Financial Crime
Identity verification is the gateway control in financial crime compliance. If a synthetic or high risk identity enters the system undetected, downstream AML and fraud tools face a significantly harder challenge.
The layered defence framework flows as: identity verification → customer risk assessment → sanctions, PEP, and adverse media screening → due diligence → transaction and fraud monitoring → investigations and reporting. Strong onboarding controls reduce the volume of fraudulent identities entering this funnel, improving the signal-to-noise ratio for every downstream system.
Transaction monitoring focuses on behaviour after onboarding. Synthetic identity fraud prevention at onboarding is about achieving high identity confidence before granting access to banking services and financial products.
This is where a connected FRAML approach matters. Rather than operating name screening, transaction monitoring, adverse media, and fraud analytics as siloed systems, institutions benefit from sharing identity intelligence across modules. Solutions such as ZIGRAM’s Complete FRAML System and Fraud Fighter help connect onboarding identity checks with ongoing fraud monitoring to create continuous, organisation-wide protection.
What Financial Institutions Should Do Next to Combat Synthetic Identity Fraud
For compliance heads, MLROs, and fraud leaders looking to modernise onboarding in line with CKYC 2.0, here is a practical six-step framework:
Move beyond isolated field validation to identity coherence checks. Design rules and analytics that test whether identity attributes logically belong together and remain stable over time.
Increase use of trusted digital sources – CKYC 2.0 records, DigiLocker, issuer APIs, telecom verification where allowed – rather than relying solely on customer-submitted document images.
Introduce layered, real-time identity verification workflows combining document checks, database validation, device and network risk, and where permitted, biometric and liveness verification for high risk or fully remote journeys.
Feed identity discrepancies and anomalies explicitly into customer risk scoring models and case-management queues rather than treating them as purely operational issues.
Connect onboarding intelligence with ongoing AML and fraud monitoring so that suspicious behaviour is interpreted in light of initial identity risk and any subsequent KYC updates.
Ensure regulatory compliance and governance readiness – confirm data privacy alignment under the DPDP Act 2023, maintain audit trails of all identity data access, and provide customer transparency portals for viewing and correcting CKYC records.
Synthetic identity fraud is fundamentally an identity-confidence problem before it becomes a transaction-monitoring problem. The future of financial onboarding is not simply collecting more customer data. It is establishing whether identity information is valid, current, consistent, verifiable, and connected to the person presenting it. CKYC 2.0 strengthens this foundation, but financial institutions must connect identity validation with risk scoring, AML screening, due diligence, and continuous monitoring to build a genuinely secure onboarding process.
ZIGRAM helps regulated entities design and implement connected RegTech ecosystems that support CKYC 2.0 adoption, digital identity verification, synthetic identity fraud detection, and holistic financial crime risk management. Book a demo to explore how a connected FRAML architecture can strengthen your organisation’s first line of defence.