Identity has become one of the most important fault lines in modern financial crime. As financial services move further into digital channels, the question is no longer simply whether a customer can provide the right documents, but whether a firm can establish that the person behind the digital identity is real.
Synthetic identity fraud is making that distinction harder. Criminals can combine genuine and fabricated information to create identities that appear legitimate, while increasingly sophisticated digital tools make deception cheaper, faster and harder to detect.
At the same time, traditional KYC processes are being pushed to prove more than identity alone: they must establish trust in an environment where the signals used to do so are becoming easier to manipulate.
In part 2 of The Future of Trust: Rethinking KYC in a Digital Financial System, we delved into why traditional KYC is no longer sufficient for an increasingly dynamic risk landscape, and how continuous KYC is emerging as the next evolution in customer due diligence.
For the third article of this four-part series, we examine the identity problem in KYC, how dangerous is the rise of synthetic identity fraud, whether we are entering a new era of digital ID and has KYC become a digital trust problem.
The rise of synthetic identity fraud
How dangerous is the rise of synthetic identity fraud? In the view of Duco van Lanschot, CEO and co-founder of Duna, it is dangerous because the economics have inverted.
He said, “The old model of identity fraud had a cost structure that protected us. One person, one forged passport, several hours of work for a single fake identity. The effort did not scale, so the fraud did not scale. Defenses built for that world assumed the attacker was a scarce, expensive thing. That assumption no longer holds.”
A key reason for this is that an AI agent has close to zero marginal cost to spin up a new identity, works around the clock, and does not tire on the thousandth attempt any more than the first.
Van Lanschot remarked, “The same tools that generate a convincing selfie generate a convincing passport, a convincing utility bill, and a convincing director for a company that does not exist. The FBI attributed roughly $893 million in reported losses to AI-enabled fraud in its 2025 Internet Crime Report, and that figure only counts the cases explicitly tagged as such.”
As well as this, the Duna CEO detailed that deepfake video is now used in live onboarding and, increasingly, in remote job interviews to place a synthetic person inside a company.
He said, “We are seeing the early shape of synthetic businesses too: plausible filings for entities that were never real, exploiting how cheap and fast company registration has become online.”
Meanwhile, Jesus Sanchez, CPO at Muinmos, believes that synthetic identity fraud is dangerous only when firms approach it with the wrong tools.
He said, “In synthetic identity fraud, the identity is not stolen. It is manufactured, combining genuine information with fabricated details to construct a customer who appears credible.”
For example, a legitimate identification number may be paired with a false name, address or date of birth. Also, GenAI can now supplement that data with convincing photographs, identity, voices, documents and video.
“The main vulnerability is that many KYC processes assess each piece of information separately,” remarked Sanchez. “A document may appear genuine. A face may pass a biometric comparison. An address may exist. Synthetic identities exploit the gaps between those disconnected checks.”
In order to combat this effectively, businesses, he claims, need to correlate documentary, biometric, and authoritative-source signals rather than treat them as separate pass-or-fail stages.
The last to offer their view on this point is Zurab Kotaria, co-founder and CEO at Identomat.
He stated, “”It’s genuinely one of the harder problems we deal with, because there’s no victim to flag it. You’re not stealing someone’s identity, you’re building a new one out of real and fake pieces stitched together. And it’s not just banks that need to worry about this, it’s things like bonus abuse in gaming and fintech too, wherever a fake identity can be created and cashed out.”
For the Identomat CEO, the tricky part is catching it without slowing everyone else down. He claims that you need orchestration that’s smart enough to push harder on the risky cases and stay out of the way for everyone else. This, Kotaria quips, is the problem Identomat was built around.
The new digital identity verification era
A key question being put by many in the industry has been whether we’re entering a new era of digital identity verification.
On this question, Kotaria agrees with the premise, and believes the size of the shift is definitely not small.
He said, “For years, verification meant scan a document, take a selfie, done. That assumption doesn’t hold anymore. A convincing face can be generated in minutes, so identity checks need to get smarter, not just repeated.”
In the opinion of the Identomat head, it’s less so much about one static process, and more about the system that understanding risk in real time, who this person likely is, and how much scrutiny that warrants. “That’s the era we’re actually in,” he said.
Sanchez also agrees we’re in a new era, but the said era will consist simply of better document scanning, a digital identity wallet or stronger facial recognition.
He said, “Digital identity verification is moving from a one-time document check toward an assurance-based model in which different evidence, credentials, and authentication methods are combined according to the risk of the interaction.”
Sanchez proclaims that identity becomes a living part of a constantly updating picture of the customer.
“It establishes who a person is, and that becomes one input into overall customer risk, alongside sanctions exposure, source of funds, investor classification, suitability, and whether the relationship remains appropriate over time,” he said.
The Muinmos CPO sees that the future is therefore not identity verification in isolation, but identity evidence orchestrated with the wider compliance decision.
Duna’s CEO van Lanschot also backs the premise but is clear to state that its not the era most people describe.
He said, “The optimistic story is the digital identity wallet: a government-issued, cryptographically verifiable credential you carry and present on demand. Europe’s eIDAS framework and the coming EU Digital Identity Wallet are real progress. But a credential only proves an attribute. It does not prove that the person presenting it is its owner, on this device, at this moment, and that problem, identity authentication, stays hard even in a world of digital passports.”
The stack, van Lanschot argues, has answered by moving to biometrics: liveness detection and known-face matching, and he stresses that it works.
He gave the example of a large payments company, where one conditional identity verification of that kind cut certain fraud patterns by around 90%.
He explained, “The catch is that every effective defense becomes the next attack surface, and deepfakes are now a large and fast-growing share of biometric fraud attempts.
“So, the new era is real, but defined by a moving adversary rather than a settled solution. The institutions treating verification as a better one-time gate will keep being surprised; the ones getting it right treat it as risk-based and continuous, with every decision recorded as evidence.”
KYC: A digital trust problem?
In an age where KYC is evolving, a question is also arising: has KYC become a digital trust problem?
Sanchez said that KYC has always been one of the foundations on which digital trust is built. As synthetic identities, deepfakes, and other forms of digital fraud become more sophisticated, effective KYC only becomes more important, he stresses.
He continued, “Trust also works in both directions. A strong KYC process gives the institution confidence that the customer is real, that they are who they claim to be, and that the relationship can be established within the institution’s risk appetite and regulatory obligations.”
At the same time, Sanchez argues, the customer must be able to trust the institution with highly sensitive personal and financial information.
“A secure, transparent, and well-designed KYC process signals that the institution takes compliance, data protection, and customer safety seriously. Increasingly, this forms an important part of the customer’s first impression,” he commented.
Therefore, the real challenge, in his view, is not KYC itself but poor KYC: fragmented journeys, repeated requests for the same information, unexplained decisions, and weak safeguards around customer data. “These experiences undermine trust rather than create it,” Sanchez concluded.
Kotaria believes that KYC has become a digital trust problem because businesses can no longer rely on basic identity checks to determine whether an online user is genuine and trustworthy.
He said, “A valid-looking document does not necessarily prove that the person presenting it is its rightful owner, that the account will remain under their control, or that their risk profile will stay unchanged over time.”
Modern KYC therefore, Kotaria believes, needs to help businesses establish and maintain confidence throughout the customer relationship.
He concluded, “By combining identity verification, liveness detection, fraud prevention, AML screening, biometric authentication, transaction monitoring and ongoing monitoring, businesses can move beyond simply knowing who a user claims to be and gain greater confidence in who they are actually dealing with.”
The last viewpoint comes from van Lanschot, who is succinct: KYC was always a trust problem.
He explained, “It exists so an institution can decide whether to trust a counterparty it has never met. For most of banking’s history that decision rested on physical signals: a person in a branch, a wet signature, a passport you could hold to the light. The digital shift removed those signals, and what replaced them, a scan and a selfie, can now be manufactured on demand.”
He stressed the example of a cartoon ran by The New Yorker in 1993 of a dog at a keyboard: “On the Internet, nobody knows you’re a dog.” More than 30 years later, he states, identity is still the internet’s unsolved problem, and it still costs the financial system billions in fraud, friction, and fines.
The Duna CEO added, “The friction side matters as much as the fraud side, and the industry consistently underweights it. The controls meant to keep bad actors out also turn good customers away. Roughly 4% of new checking-account applicants now open an account with their existing bank without shopping around, down from 25% a generation ago, and an application that runs past 10 minutes completes only about 4% of the time.”
Trust at digital scale has to be evidence-based, he said, with the source of truth held in the data and every decision traceable to the signal that drove it. It also, he says, has to be deterministic: the same input producing the same output every time, logged and open to inspection.
Van Lanschot concluded, “And it has to be continuous, rechecked as the world changes rather than frozen on the day the file was built. As I argued on continuous KYC in the previous piece, the point-in-time file is the wrong unit of work; the change is the unit. That is the only way to hold the line against an adversary with near-zero marginal cost while still rolling out the red carpet for the customer you want.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





