A merchant applies with a PAN card, a GST certificate, a business registration.
Every document clears. The photo matches the ID. The address resolves.
None of it belongs to a real business.
Synthetic identity does not steal a face. It builds one.
A real PAN number. A fabricated business name. An address rented for a month, just long enough to receive verification mail. Each piece checks out on its own. That is the design, not an accident.
It asks: is this ID authentic. Is this certificate genuine. Does this address exist.
A synthetic identity is engineered to answer yes to all three.
The lie is not in any single document. It is in the relationship between documents that were never meant to describe the same entity. No document check can see a relationship. That is not what it is built to see.
Building a synthetic identity from scratch takes more effort than stealing one. It also survives longer. A stolen identity gets flagged the moment the real owner notices something is wrong. A synthetic identity has no real owner. Nobody is coming to notice anything.
Most onboarding stacks were designed to catch impersonation - someone using a stolen or fake identity to pose as themselves. The checks that resulted, document authenticity verification, sanctions screening, address resolution, are well suited to that problem.
They are the wrong tool for this one. A synthetic identity has no history to contradict. No compromised credential to detect. It looks exactly like a new business that has never done anything wrong. That part is technically true. It has never done anything. It does not exist as a business at all.
The tell is never inside one file. It is what connects across files. Multiple onboarding attempts sharing a device fingerprint, claiming no relationship to each other. Registrations filed days apart, using addresses that were never operational. Payouts from several unrelated merchant identities converging on one beneficiary account.
None of that is visible inside a single application. It is only visible when applications get compared against each other - which a document-checking workflow was never built to do. RBI's Master Direction on Regulation of Payment Aggregators requires ongoing merchant due diligence, not a one-time check at the door. A synthetic identity is specifically engineered to pass the door and fail everything that comes after it - which is exactly the window a one-time check cannot cover.
It accumulates transaction history. It builds payout trust. Often, it recruits more synthetic identities into the same network before anything looks anomalous enough to check.
By the time it does, the fraud is not one bad application. It is a cluster of entities that all cleared the same checks, for the same reason. None of those checks were looking for a relationship between them.
Reconstructing that cluster after the fact means manually rebuilding, by hand, the connections that should have been visible on day one. Which accounts share a device. Which registrations share an address. Which payouts converge on an account with no reason to be receiving money from five unrelated merchants.
That is not a documents problem. It was never a documents problem. It is a relationship problem wearing paperwork as a disguise.
Verafye's graph-native network risk intelligence is built specifically for the relationship problem. When a new merchant application arrives, Verafye maps its identity attributes - PAN, GST number, device fingerprint, contact details, beneficiary account - against the existing network across the portfolio.
A device fingerprint shared with three other applications filed in the same week surfaces immediately. An address that appeared in two prior onboarding records - neither of which became an active, operational business - surfaces as a pattern before any transaction clears. A beneficiary account already linked to a merchant under investigation appears at the point of onboarding, not after the synthetic identity has accumulated transaction history.
When a synthetic identity cluster forms, Verafye maps it as a network: which entities share infrastructure, which onboarding records connect through common attributes, which payouts converge on accounts with no legitimate reason to be receiving funds from multiple unrelated merchants. The structure of the fraud becomes visible as a shape - not a list of separately triggered rules. This is the same investigation intelligence that assembles the case for the analyst, rather than leaving the connection-tracing to manual reconstruction after the fraud has completed.
For payment aggregators managing ongoing merchant due diligence under RBI's PA Master Direction, this is the layer that makes continuous monitoring operationally possible - catching the relationships that form in the months after a document check cleared, not waiting for a scheduled review to notice them. To see where synthetic identity relationships currently exist undetected in your merchant book, the Verafye Risk Shadowing Review provides a scoped assessment with no commitment required.
If onboarding cannot tell a new business from a new business that does not exist, the documents were never where it broke.
It broke earlier. It broke the moment paperwork got asked a question only relationships can answer.
What is synthetic identity fraud in merchant onboarding?
Synthetic identity fraud involves creating fake merchant identities using a mix of genuine and fabricated information - a real PAN number, a fabricated business name, a rented address - to pass document verification and gain access to a payment aggregator's platform.
Why isn't document verification enough to catch synthetic identities?
Document verification confirms whether each document appears authentic. A synthetic identity is engineered so that each document does. The fraud is in the relationship between documents that were never meant to describe the same entity - and that relationship is not visible inside any single document check.
How can payment aggregators detect synthetic identity fraud?
Detection requires combining document verification with device intelligence, identity resolution across the full merchant portfolio, graph intelligence that maps relationships between entities, and continuous monitoring that compares new applications against existing records.
What signals indicate synthetic identity fraud?
Common signals include shared device fingerprints across applications claiming no relationship, addresses used in multiple onboarding records that never became operational businesses, beneficiary accounts receiving funds from multiple unrelated merchants, and registration filing patterns suggesting batch creation.
How does graph intelligence help prevent synthetic identity fraud?
Graph intelligence maps the relationships between merchants, devices, bank accounts, and contact details across the full portfolio. When a synthetic identity shares attributes with prior records - even subtly - the connection surfaces at onboarding rather than after fraud has completed.
Vasuki
Co-Founder & CPO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.