Skip to main content

Evidence Framework

TL;DR
  • Tier 1 = Conviction (one alone justifies fraud classification): Device linked to 3+ fraud cases, identity confirmed stolen, previous confirmed fraud
  • Tier 2 = Evidence (combine 3+ for fraud): Never-pay, email under 30 days old, device anomalies, phone recently ported
  • Decision: 1+ Tier 1 = Block/Decline. 3+ Tier 2 = High risk, review. 1-2 Tier 2 = Medium risk. 0 = Low risk

A systematic approach to evaluating fraud signals using tiered indicators.

Overview

Not all fraud signals are equal. This framework categorizes indicators by confidence level to support consistent, defensible decisions.

Core Principle

Tier 1 = Conviction (one is enough)
Tier 2 = Evidence (multiple required)

Tier 1 Indicators

High-confidence signals that alone justify fraud classification:

IndicatorHow to Confirm
SSN issued after stated DOB would suggestBureau data, SSA verification
Identity confirmed as fraud victimPolice report, affidavit, bureau alert
SSN belongs to deceased individualBureau data, death records
SSN never issuedSSA verification
Document forensically invalidDocument verification technology
IndicatorHow to Confirm
Device/IP linked to 3+ confirmed fraud casesDevice intelligence, internal data
Address used by known fraud ringConsortium data, internal analysis
Exact application data matches confirmed fraudPattern matching, feature vectors
Account explicitly claimed by identity theft victimAffidavit, manual review

Tier 2 Indicators

Supporting signals that require combination for confidence:

Application Signals

IndicatorWeightNotes
Email created < 30 days ago⚠️ MediumCommon in fraud, but also new customers
Phone recently ported⚠️ MediumSIM swap indicator
Address mismatch (stated vs. bureau)⚠️ LowMay be recent move
Employment unverifiable⚠️ MediumCheck method matters
Income stated >> bureau income indicators⚠️ MediumCould be recent change

Behavior Signals

IndicatorWeightNotes
Never-pay (0 payments from origination)⚠️ HighStrong but not conclusive (see first-party fraud)
Bust-out pattern (utilization spike)⚠️ HighMay be financial hardship
Device seen on prior fraud (1-2 cases)⚠️ MediumCould be shared device
Velocity anomaly⚠️ MediumContext dependent
IndicatorWeightNotes
Same phone on multiple identities⚠️ MediumCould be family
Same device on multiple identities⚠️ MediumCould be shared device
Address velocity (3+ apps, same address, 30 days)⚠️ HighStrong ring indicator

Decision Matrix

Classification Rules

EvidenceClassification
1+ Tier 1 indicatorFraud
3+ Tier 2 indicators (High weight)Fraud
4+ Tier 2 indicators (any weight)Fraud
1-2 Tier 2 indicatorsInvestigation
0 indicatorsCredit loss (if loss exists)

Example Scenarios

Scenario A: Clear Fraud

  • SSN issued after DOB → Tier 1 ✓
  • Classification: FRAUD

Scenario B: Clear Credit Loss

  • Verified employment, verified income
  • No velocity anomalies
  • No device/address flags
  • Customer payment pattern consistent with financial hardship
  • Classification: CREDIT LOSS

Scenario C: Needs Investigation

  • Email created recently (Tier 2)
  • Never-pay pattern (Tier 2)
  • Employment unverifiable (Tier 2)
  • Action: Gather more evidence, time-box decision

Documentation Requirements

For each fraud classification, document:

  1. Indicators present – List all relevant signals
  2. Evidence sources – Where each signal came from
  3. Decision rationale – Why classification was made
  4. Reviewer – Who made the decision
  5. Date – When decision was made

Next Steps

Setting up evidence framework?

  1. Define Tier 1 indicators - High-confidence signals
  2. Define Tier 2 indicators - Supporting signals
  3. Create decision matrix - Classification rules

Investigating a case?

  1. Check for Tier 1 indicators - One is enough for fraud
  2. Count Tier 2 indicators - 3+ for fraud classification
  3. Manual review - Human investigation for complex cases

Documenting decisions?

  1. Review documentation requirements - What to record
  2. Use example scenarios - Apply to your case
  3. Classify per decision matrix - Make the call