Machine Learning (ML)

Machine learning is a set of methods for building systems that derive their behavior from data rather than from explicit instructions. Instead of a person writing the rule, the system infers the relationship from examples — which makes it suited to problems where the pattern is real but nobody can articulate it.

Fraud detection and identity verification are both such problems, and machine learning underpins most of what is deployed in each. It is also a field where the limits are less discussed than the capabilities, and in fraud the limits are mostly about the data rather than the algorithms.

Supervised learning Learns from labeled examples — most fraud scoring
Unsupervised learning Finds structure without labels — anomaly detection, clustering
In identity verification Document classification, data extraction, face matching, liveness
In fraud detection Risk scoring, behavioral modeling, network and link analysis
Evaluated with AUC, precision and recall — not accuracy
Main constraint in fraud Label quality, not model architecture

What machine learning does better than rules

A rule encodes a relationship somebody already knows. That is a strength when the relationship is stable and needs to be explainable, and a hard ceiling when the useful pattern involves many weak signals interacting.

Fraud signals are mostly weak individually. A new device is unremarkable. A slightly unusual hour is unremarkable. A shipping address two hundred miles from the billing address is unremarkable. The combination, at a particular value, from a particular network, may be strongly predictive — and nobody would have written that rule, because the interaction is not visible to inspection.

Models also adapt as the population shifts, where a rule set accumulates. Most mature rule engines contain hundreds of rules, some contradicting each other, many written for conditions that no longer exist, and no one is willing to remove them because nobody knows what depends on what.

In identity verification the case is stronger still. Reading a document under varied lighting from hundreds of design variants, or determining whether a face is physically present, are perception tasks that cannot be specified as rules at all.

Why labels are the real constraint

This is the part that determines whether a fraud model is any good, and it is a data problem rather than a modeling one.

  • Declined cases have no outcome. An application that was rejected never revealed whether it was fraudulent. The model never learns whether those declines were right, and retraining on its own decisions reinforces them. Over time it gets better at reproducing past decisions, which is not the same as getting better at detecting fraud.
  • Undetected fraud is labeled legitimate. Fraud that was never caught sits in the training data as a good outcome, actively teaching the model that the pattern is fine.
  • Labels arrive late. A chargeback can take months; a sleeper account can take years. The model is always learning from a world that has moved on.
  • Fraud is rare. With positives well under 1%, the model sees very few examples of the thing it exists to find, and accuracy becomes a meaningless measure — approving everything scores over 99%.

The consequence: in fraud, the gap between a good model and a mediocre one is usually smaller than the gap between good features and poor ones. Effort spent on data quality generally returns more than effort spent on architecture.

Why it matters for identity verification

Machine learning appears twice in identity work, doing different jobs.

Inside verification it does the perception: classifying which document is being presented from hundreds of types, locating and reading the fields, assessing whether security features are present and consistent, matching a face to a portrait, and determining liveness. These are the tasks where models replaced approaches that never worked well.

Downstream, verification supplies the model with a qualitatively different class of feature. A fraud model reading self-asserted application data is reasoning about claims the applicant chose to make. The same model given a verified name, date of birth and document number is reasoning about facts. It also becomes able to resolve records to the same real person, which is what velocity and network features require — and which self-asserted data cannot support, since a fabricated identity is designed not to resolve.

The honest summary: better models help at the margin, better inputs move the whole curve.

What machine learning cannot do in fraud

It cannot detect what it has never seen. Supervised models find patterns resembling known fraud. A truly novel technique is invisible until enough of it is labeled, which is why rules and analyst judgment remain necessary alongside models rather than as a legacy.

It cannot explain itself without deliberate effort. Several regimes require adverse decisions to be explained to the person affected. A score does not satisfy that, and explainability has to be built rather than assumed.

It cannot be made fair by removing protected attributes. Models learn proxies — geography, device cost, name patterns — and dropping the explicit field leaves the correlation intact. Fairness requires measuring outcomes across groups, not omitting columns.

It does not stay good on its own. Fraud adapts, populations shift, and models drift. A model that is not monitored against fresh outcome data degrades quietly while continuing to emit confident numbers.

It cannot establish identity. A model can conclude that a case resembles fraud. It cannot determine who someone is — that requires evidence, and evidence is a different kind of thing from inference.

Frequently asked questions

How is machine learning used in fraud detection?

Mainly for risk scoring, where a model weighs many weak signals to rank cases; for behavioral modeling, comparing activity against learned patterns; and for network analysis, finding connections between accounts that no rule expresses. In identity verification it also does document reading, face matching and liveness.

Is machine learning better than rules for fraud?

For different things. Models handle many interacting weak signals and adapt as populations shift. Rules are explicit, explainable, and immediate to deploy — which matters for regulatory constraints and for responding to a new attack the same day. Production systems almost always run both.

Why is accuracy a bad metric for fraud models?

Because fraud is rare. At a 0.1% fraud rate, a model that approves everything is 99.9% accurate and catches nothing. Precision, recall and the area under the precision-recall curve reflect what the model does on the cases that matter.

What limits machine learning in fraud detection?

Label quality, more than anything else. Declined applications have no outcome, undetected fraud is recorded as legitimate, and labels arrive months late. A model trained this way learns to reproduce past decisions, so improving the underlying data usually returns more than improving the model.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data