Initial full research published September 27, 2026. Historical events retain their dates; hypothetical examples and analytical recommendations are labeled.
Identity confidence is a separate decision input
SentiLink supplies identity and fraud-risk products intended to help organizations assess applications and related identity information. Its published Synthetic Score white paper describes evaluating the relationship among identifying attributes, including name, date of birth and Social Security number. [1] The product addresses whether an identity appears synthetic or otherwise risky; that is a different question from whether a verified person can afford a loan.
The vendor's workflow discussion places its signals among identity checks and downstream application decisions. [2] That is a suggested implementation pattern, not a legal requirement to use a specific vendor or sequence. An October 14, 2025 announcement also describes a customer-identification offering combining identity matching, configurable controls and related screening capabilities. [3] The announcement establishes a vendor offering, not regulatory endorsement of a bank's eventual program.
Read the score definition before selecting a threshold
The Synthetic Score white paper describes a score on a 0–1000 scale with higher values indicating greater risk. It should not be read as a directly calibrated probability: a score of 800 does not by itself mean an 80% likelihood of fraud. The document also describes model-version information and explanatory feature codes. [1] Buyers should confirm the current contracted product, version and definitions because names and capabilities can change.
Thresholds translate a rank into an operational choice. A bank might approve, request additional evidence, refer for review or decline under its policy. The right threshold depends on fraud prevalence, the cost of missed fraud, review capacity and the harm of rejecting legitimate applicants. A threshold copied from another lender can perform differently in a new population even when the underlying model is unchanged.
The white paper cautions that its feature codes are for internal understanding rather than consumer adverse-action reasons. [1] That boundary is important: an internal signal describing an unusual identity pattern is not automatically an accurate, legally sufficient explanation for a credit denial. The institution needs a process that connects the actual decision to the applicable notice and dispute requirements.
Worked example: high accuracy can still create a review burden
Assume a hypothetical population of 100,000 applications contains 1,000 fraudulent identities, a 1% base rate. A test catches 80% of those cases, producing 800 true positives. If it flags 1% of the 99,000 legitimate applicants, it also produces 990 false positives. The flagged population totals 1,790, of which about 44.7% is actually fraudulent under these assumptions.
The example is not SentiLink performance data. It shows why a low false-positive rate can still affect many legitimate people when fraud is relatively uncommon. Automatically rejecting every flagged applicant would deny 990 legitimate applications in this scenario. Step-up verification could reduce that harm, but adds customer friction, staffing and abandonment risk.
If each flagged case takes ten minutes to review, the initial queue requires about 298 hours. A stronger threshold might shrink the queue while missing more fraud. A lower threshold might catch more fraud while exceeding review capacity. The decision should reflect observed tradeoffs on the institution's own population rather than a single headline accuracy statistic.
| Hypothetical validation population | Count |
|---|---|
| Applications | 100,000 |
| Actual fraudulent identities | 1,000 |
| True positives at 80% detection | 800 |
| False positives at 1% of legitimate applicants | 990 |
| Fraud share among flagged applications | 44.7% |
Labels and population shifts can change the apparent result
Fraud labels are imperfect. A charged-off account is not necessarily identity fraud, and an account without a reported loss is not necessarily legitimate. Synthetic identities may behave normally for a period before exploitation. Validation should explain how outcomes were established, how long they were observed and whether the sample excludes cases that never reached account opening.
Recommended evaluation separates synthetic-identity risk, identity theft and ordinary credit deterioration where reliable labels permit. Examine performance across acquisition channels, identity-data completeness and applicant populations. A material shift in marketing or product eligibility can change the base rate and therefore the meaning of a fixed threshold even if model ranking performance remains stable.
Run a shadow test before imposing broad adverse outcomes. Independently review a sample below as well as above the threshold to estimate missed cases. Preserve the model version and input record used at the time of decision. When a vendor updates a model, compare changed decisions and explanations rather than assuming a newer version must improve every relevant segment.
Identity controls still require a complete bank process
The October 2025 vendor announcement describes a broader customer-identification solution. [3] A bank evaluating it should map each function to its own requirements: information collection, verification, exception resolution, records and ongoing handling of discrepancies. A product can support that process without replacing the bank's responsibility for designing and operating it.
Recommended controls include input validation, secure transmission, access restrictions and a documented correction path when identity information is wrong. A legitimate applicant should have a usable way to provide additional evidence. Record whether the eventual decision was driven by identity concerns, credit criteria, incomplete information or another reason; those categories should not be collapsed merely because one platform supplies several signals.
Costs include vendor charges, integration, data handling, step-up verification and manual review. Public materials reviewed here do not provide a verified price schedule sufficient to calculate deployment economics. Estimate avoided losses conservatively and distinguish realized recoveries from projected prevention. Customer case studies and vendor-authored fraud reports can provide leads, but they do not establish independently controlled performance for another bank.
Evidence that would change the assessment
SentiLink's technical materials provide more specific information about score interpretation than a generic AI marketing claim. They still leave bank-specific performance and current contractual details to be tested. Reliable labels, stable out-of-time results, manageable review queues and effective correction procedures would support use. Excessive legitimate-applicant friction, weak explanations or deterioration after population shifts would weaken the case. The appropriate role is a governed identity-risk input within a broader decision process.