Synthetic identities are fake identities created by combining real and fabricated information. A fraudster might use a genuine name or National Insurance number alongside a made-up address, phone number or date of birth to create an identity that looks legitimate on paper.
Unlike identity theft, where someone uses another person’s identity, synthetic identity fraud usually involves creating a new identity from scratch. That can make it harder for businesses to spot because there may be no single victim whose details have been completely stolen.
Why do synthetic identities matter for AML compliance?
Synthetic identities can be used to pass customer onboarding checks, open bank accounts, apply for credit or gain access to financial services. Once an account has been established, the fraudster may use it to move money, build a transaction history or carry out other financial crime.
For AML teams, the problem is that standard identity checks can sometimes confirm that individual pieces of information are genuine without showing that the identity itself is fake. A real name, valid address and genuine identity number can look convincing when checked separately.
This creates a gap between verifying information and understanding who is actually behind an account.
How synthetic identities are used in fraud
A synthetic identity can be built gradually. Fraudsters may start with a small number of genuine details and add fabricated information until they have an identity that can pass onboarding checks. Once an account is open, they may behave normally for a period of time, making legitimate payments and building a credible financial profile. Later, the account can be used for fraudulent transactions, credit fraud, money laundering or as part of a wider network of accounts. That behaviour can make synthetic identity fraud particularly difficult to detect with checks that focus only on the initial application.
How can businesses detect synthetic identities?
Fraud prevention teams can look beyond individual identity attributes and assess how those attributes connect. Signals such as unusual address patterns, inconsistent customer information, suspicious device activity, repeated use of contact details and links between seemingly unrelated accounts can help identify synthetic identities.
Ongoing monitoring also has a role. A customer may appear low risk when they first open an account, but changes in their circumstances, behaviour or risk profile can indicate that further investigation is needed.
For AML compliance, this means regularly reassessing customer information and risk indicators rather than treating identity verification as a one-off check at onboarding.
Synthetic identities and AML risk
Synthetic identities can create AML risk because they give criminals another way to access regulated financial services without presenting a genuine identity. They can also make it harder for firms to understand the true customer behind an account and assess the source and movement of funds.
For firms covered by AML regulations, detecting synthetic identities sits alongside customer due diligence, ongoing monitoring and fraud controls. The aim is to build a clearer picture of who the customer is, how their account is being used and whether their activity matches what the business would reasonably expect.