The Three Identity Checks in an Auto Deal, and Why the Last One Breaks

Every auto deal asks one question three separate times: is this person actually who they say they are?
It comes up first at the credit application, again when the contract gets signed, and a third time when the title work needs a notarized power of attorney. Three different systems answer it, run by three groups of people who rarely compare notes, and every one of those answers proves less than it appears to.
The third answer is the expensive one, because it is where a digital deal turns back into paper, where five to ten days get added to funding, and where the document most likely to be forged gets waved through by the weakest check in the process.
Here is what each of the three actually establishes, and what it costs when the last one fails.
Check one: the credit application
A customer submits name, address, date of birth, and an identification number, and those get matched against bureau records.
What comes back is confirmation that the pieces agree with each other: the identity exists, the file is coherent, and nothing in it contradicts the application. That is a useful screen, and it is also precisely the test a well-built synthetic identity is designed to pass, because a synthetic identity is a coherent file with nobody behind it.
The FTC's Consumer Sentinel Network Data Book for 2024, the most recent edition, logged 60,188 auto loan or lease identity theft reports, up 16% year over year.
Check two: contract signing
The customer signs, and how you check them depends on where they are sitting. In a dealership, an F&I manager looks at a driver's license across a desk. In a remote or refinance context, an emailed or texted access code stands in for that.
Both prove less than they look like they prove. A manager glancing at a license catches the obvious fakes and nothing better, because nobody at a desk can match a face against the record the state actually holds. An access code tells you only that somebody could get into an inbox.
And the shape of these losses has changed. TransUnion's July 2026 analysis of its US consumer credit database found that between Q3 2018 and Q3 2025, first-party fraud losses in auto lending climbed from $88 million to $323 million, synthetic identity fraud from $93 million to $208 million, and third-party fraud from $18 million to $47 million.
What this means: fraudsters that get through are getting better and better at it, and catching them takes depth at the point where the money actually moves, rather than another filter at the application.
Check three: title work, where everything goes back to paper
Now the borrower needs a notarized limited power of attorney so you can handle the title transfer and lien release on their behalf, and every refinance deal needs one. This is the point where a perfectly good digital transaction falls apart: the customer prints the forms, tracks down a notary, signs in person, and mails paper back to you.
Everyone complains about the delay, and the bigger problem is what the notary actually checked. They looked at a driver's license, which is the same look your F&I manager already gave it, with exactly the same ceiling. A notary stamp establishes that a human stood there with the document, and says nothing whatsoever about whether that human was the borrower. Since a forged POA can hand a title to someone the borrower never agreed to, this is the document that gets forged.
Odometer disclosures are stuck in the same bottleneck. NHTSA's long-standing estimate, from its incidence study, is that more than 450,000 vehicles are sold each year with rolled-back odometers, costing buyers over $1 billion a year. That study's own figure is about $1.056 billion, and it counts only what buyers overpaid, leaving out financing, insurance, and the repairs that follow, so the real number for consumers runs higher.
Making the last check the strongest one
The fix is to turn the title step into the best identity check in the whole deal instead of the worst. That is easier than it sounds, because it is the one moment where you have the customer's full attention and they want the process to finish.
We verify the signer before any documents are signed, using government-issued ID, facial biometrics, and risk screening. You compose the checks a given workflow needs rather than accepting one fixed sequence. Credential analysis runs more than 25 verification checks on an ID in under five seconds to confirm it is genuine, and a biometric comparison matches that ID against a real-time selfie of the person holding it. Add Defend and you get fraud screening on top of that, across device fingerprinting, location risk, and behavioral signals.
Signers who have trouble with identity validation, or who behave suspiciously, get routed to our trusted referee network for enhanced verification instead of being waved through or abandoned. And the verification is certified to NIST Identity Assurance Level 2 by the Kantara Initiative, which is the same standard that lets you collect odometer disclosures electronically instead of chasing wet ink on one form while everything else in the deal is digital.
What you keep afterward is a tamper-proof audit trail detailing each step of the transaction and the signer's identity information, sealed and time-stamped. That is the file you want in front of you months later when somebody disputes the transfer.
None of it asks the customer to go somewhere else. We integrate with most major LOS, CRM, and workflow tools, and build custom configurations where you need them, so the POA can be initiated from the systems your team already works in.
Morgan Cavallo, Director of Titling Compliance at Vroom, framed the return in terms of both trust and cost: "The Proof platform gives us greater visibility into the customers we are transacting with and increases trust in the documents we rely upon. Consolidating to one identity management platform reduces our fees and complexity, and better positions us to securely serve our customers online."
See how Proof digitizes POAs, title transfers, and odometer disclosures >




















.jpg)
































































.jpg)



















































