Zarv
Insights

Why identity verification and fraud prevention belong in a single step

U.S. fraud losses hit $15.9B in 2025 while good applicants quit mid-signup. Why identity verification and fraud prevention belong in a single step.

··7 min read
Why identity verification and fraud prevention belong in a single step

Somewhere in the United States right now, a credit card is being opened in a name that belongs to someone else. The FTC logged 406,110 of those cases in 2024 alone, the single largest type of identity theft Americans reported that year. And the damage keeps compounding: consumers reported $15.9 billion lost to fraud in 2025, up from $12.5 billion the year before.

On the other side of the counter, the legitimate customer gives up. Roughly seven in ten people abandon a financial-services signup before they finish. Suspicion is rarely the reason. The process is slow, asks for too many documents, and bounces them from one screen to the next.

Those two numbers describe the same problem from two angles: the friction that pushes good customers out is the same friction that gives fraudsters time and room to work. The root cause is an onboarding architecture almost everyone inherited, with identity in one step and fraud in another.

The onboarding paradox

New-account identity theft in the U.S. by product, 2024 — FTC Consumer Sentinel Network

New credit cards lead by a wide margin, but the pattern runs through every product that opens an account online: personal and business loans, bank accounts, auto loans and leases, mobile phone lines. Insurance is catching up fast, with identity theft reports tied to insurance up 37% in 2024. Fraudsters pick the easiest door, not the industry.

And the easiest door is often the one designed to be "rigorous." The more steps, redirects, and manual reviews a flow has, the more time a fraudster gets to adjust. And the more reasons an honest applicant finds to close the tab.

Financial-services onboarding abandonment, 2016 to 2026

Signicat's long-running research tracks the curve: 40% abandonment in 2016, 63% in 2020, 68% today. Among those who quit, 21% blame speed and another 21% blame the amount of data requested. Customers have the same patience they always had. Onboarding still treats every applicant as a suspect until proven otherwise.

Why splitting identity and fraud is the structural mistake

In most operations, the flow looks like this. One vendor checks the document and runs biometrics. Another screens PEP and restricted lists. A third scores fraud risk. Hours later, sometimes days, an analyst stitches the pieces together.

Every seam carries a specific cost.

Two points of failure instead of one. Identity can pass while fraud fails, or the other way around. Who decides? Usually no one. The case lands in a review queue, and the queue is where conversion dies.

Every redirect is a drop-off. Each time an applicant leaves your environment for a third-party page, a biometrics app, or an emailed link, part of your funnel doesn't come back. On mobile, redirects are the single biggest cause of abandonment.

Latency is a fraud window. Between document capture and the final decision, the fraudster already knows whether the document passed. If fraud analysis runs afterward, they retry with another synthetic identity before your systems connect the two attempts.

Scattered data is regulatory exposure. Selfie at one vendor, ID at another, SSN at a third. Every copy of personal data is exposure under the GLBA Safeguards Rule and a growing patchwork of state privacy laws such as the CCPA. It is also one more trail to reconstruct when an examiner asks how your Customer Identification Program reached a decision.

The practical result: you approve slowly the people you should approve fast, and you lose the people you should have approved. The bar looks strict, but it's calibrated against the wrong customer.

One step, two answers

The principle is simple. The moment someone shows their ID and their face, the system should already answer both questions before the screen moves on: who is this person? and is this person trying to defraud us?

That's how Zarv SmartFlow works. It is Zarv's free onboarding flow and the entry point to verification with Zarv ID. A single flow, embedded in your site, a link, or a chat conversation, that covers without ever leaving your context:

  • Document reading: driver's license, state ID, or passport, with authenticity checks.
  • Liveness and deepfake detection: the selfie has to come from a real person, in front of the camera, right now.
  • Face match between the selfie and the document photo.
  • PEP and restricted-list screening in the same pass.
  • Fraud risk assessment in the same decision.

The outcome comes back to your system as approved, rejected, or review, with evidence attached. Zero redirects and under three minutes for the applicant to finish.

Verification depth follows the value at risk. A prepaid phone plan doesn't need the same friction as an auto loan.

In practice, by industry

Insurance. At first notice of loss, Zarv confirms that the person filing is the policyholder, with document, liveness, and face match in one step, before the claim moves forward. Claims filed under someone else's identity are stopped at intake, without adding a queue for legitimate policyholders. More in insurance solutions.

Lending and auto finance. Applicants complete verification inside a web chat or over WhatsApp. They share their ID and a selfie in the conversation, and the identity and fraud decision comes back in the same channel within minutes. No app to download, no link to chase, no applicant lost halfway through. More in credit and lending solutions.

Car rental. At key handover, verification happens at the counter or on the renter's own phone. Identity confirmed, deepfakes ruled out, lists checked. The car leaves with certainty about who is driving it. It's the same problem fleet risk management deals with across the whole rental, solved at the first point of contact.

Digital banks, buy now, pay later providers, wireless carriers, and retailers follow the same logic: wherever there's a digital signup, there's the same choice between a fragmented flow and a single one.

Conclusion

The industry spent a decade trying to reduce fraud by adding steps and mostly succeeded at reducing conversion. The latest numbers show both curves rising together: more fraud, more abandonment.

The answer is a single step that answers identity and fraud at the same instant, inside your own environment, with the right depth for the risk in play.

Start free with Zarv SmartFlow and see the flow running in your operation.

Frequently asked questions

What is KYC verification?

KYC (Know Your Customer) is the set of checks that confirms a person is who they claim to be before opening an account, extending credit, or binding a policy. In the U.S. it typically means document verification, a selfie-to-ID face match, and screening against sanctions and PEP lists. On its own, KYC confirms identity but doesn't measure intent to defraud.

What is synthetic identity fraud?

It's fraud committed with an identity that belongs to no single real person: a valid or stolen SSN combined with a fabricated name, date of birth, and address. Because there's no one victim to notice and report it, a synthetic identity can build credit history for months before it busts out.

Why is synthetic identity fraud difficult to detect?

Because each piece checks out on its own. The SSN is valid, the address exists, and the credit file shows on-time payments. The fraud only appears when signals are read together, which a fragmented onboarding stack never does.

How do you detect a deepfake during onboarding?

With liveness detection, which confirms a real person is in front of the camera at that moment. It blocks photos, replayed videos, and AI-generated faces injected into the capture stream. It works best combined with a face match against the ID photo.

Do you need consent to use facial biometrics for identity verification?

It depends on the state. Illinois' Biometric Information Privacy Act (BIPA) requires informed written consent before collecting a face geometry scan, and Texas and Washington have their own biometric statutes. Collecting consent inside the same flow as the capture, with a clear retention policy, is the practical baseline for any national program.


Sources: FTC, Consumer Sentinel Network Data Book 2024; FTC testimony before the Joint Economic Committee, March 2026; Signicat, The Battle to Onboard (2016–2026); Illinois Biometric Information Privacy Act, 740 ILCS 14.

Stay ahead of what matters

Once a month we send a roundup of Zarv's most relevant content — on risk, product and the market. No spam, just what's worth your time.