Skip to content

4.11 Fraud databases and device intelligence

Detect identity fraud, application fraud, and recurring-actor patterns that single-data-source underwriting misses.

  • Borrowers, PANs, mobiles, bank accounts, devices, emails, addresses that have defaulted, been involved in fraud, or hit confirmed flags.
  • Built over time; first-party data.
  • Critical that internal blacklist is segregated from analyst’s view (no informal sharing) and used in decisioning explicitly.
  • Bureau enquiries reveal whether the same PAN has been applied at multiple lenders recently; velocity signal.
  • Browser / mobile fingerprint identifies same device across applications.
  • Flags: same device → multiple PANs; same device → multiple submissions; emulator detected; rooted device.
  • Bureau (bureau.id), Lokyata (lokyata.com), TruValidate (TransUnion).
  • Phone number age, history of association, SIM-recency, mobile network.
  • Email age, history, domain reputation.
  • TruValidate, Bureau, Whitepages, IPQS, Karza.
  • Court-case checks via vendor scraping or paid databases.
  • Probe42, Karza, Tofler.
  • Periodic monitoring via GSP.
  • Via MCA APIs (Karza / Probe42 / Tofler).
  • RBI maintains a list of wilful defaulters; CICs publish.
  • CIC suit-filed / wilful-defaulter list — pull periodically.
  • Some industry bodies and vendors operate consortium fraud feeds where member lenders share known fraud actors.
  • Hunter (RSA / Experian) used in some markets.
  • Adoption in India growing but uneven.
  • Internal blacklist: free; storage cost only.
  • Device fingerprint: per check ₹1 – ₹5.
  • Phone / email intel: per check ₹1 – ₹10.
  • Litigation: per check ₹50 – ₹200.
  • Consortium feeds: subscription / volume.
  • Internal blacklist: Build (small).
  • Device fingerprint: Buy vendor SDK.
  • Phone / email: Buy vendor API.
  • Litigation: Buy at need; expensive per-check, so use selectively.
  • Consortium: Buy subscription.
  • DPDP — fraud data is personal data; basis: legitimate interest / consent.
  • Bureau — wilful-defaulter pulls per CICRA.
  • Outsourcing MD — vendors governed.
  • Internal blacklist: Build (it’s your first-party data).
  • Device fingerprint: Buy.
  • Phone / email intel: Buy.
  • Litigation: Buy at need.
  • Consortium: Buy / join.
  • Fraud-decision rules: Build (your scorecard).