What is a Fraud Signal?

A fraud signal is one piece of evidence about a transaction. Here is what the common signals measure and how they combine into a decision your team uses.
Kurt Ernst
September 14, 2026
What is a Fraud Signal?

Somebody at your company is looking at a flagged transaction right now, deciding whether to let it through.

They have a name, a document, a face on a screen, and a warning that something looks wrong. They are probably not a fraud analyst. They have a couple of minutes before the next item in the queue, and whatever they decide, they may not find out for months whether they got it right.

What that person needs is the evidence behind the warning, in language they can actually read. That evidence arrives as fraud signals.

A fraud signal is a single piece of evidence about a transaction that changes how likely it is that the person completing it is who they say they are. Most signals are individually unconvincing. That is the approach working as intended, and understanding why is the difference between a fraud system your team trusts and one it learns to click through.

Key takeaways

  • A fraud signal is one observation about a person, device, or session that shifts confidence in a claimed identity.
  • No single fraud signal is a verdict. Fraud detection works by combining many weak signals, because a system built on one strong check gets engineered around.
  • Nearly all fraud signals answer one of four questions: does this identity exist, is this a live face matching the document, what device and location is in use, and how does this behavior compare to normal.
  • A good fraud signal is passive, explainable, and actionable. A signal that changes nothing about what happens next is decoration.

Why is one signal never enough?

Take a single signal: the email address on the transaction was created 11 days ago. By itself that tells you very little. Plenty of legitimate people open a new email account and use it immediately. Block every transaction with a young email address and you will reject a great many real customers while catching a modest number of bad actors.

Now add a second signal. The device has never been seen before. Still weak. New devices are ordinary. Add a third. The stated home address does not resolve to the person's name in any identity database. Add a fourth. The network location is inconsistent with the address on the application. Add a fifth. The face in the selfie matches the face on the document, but the liveness check found artifacts consistent with a replayed recording.

Individually, each of those is a shrug. Together they describe something specific, and what they describe is a customer having an unusual day far less often than it is fraud. 

This is why fraud detection is built on many weak signals. Strong signals get engineered around. A fraudster who knows you check one thing can defeat that one thing. Defeating 40 things at once, consistently, under time pressure, is a different problem.

What do fraud signals actually measure?

Signals get long technical names, but nearly all of them answer one of four questions.

Does this identity exist, and does it belong to this person?

Identity database checks look up the claimed identity against established records. Home address validation asks whether the address ties to the name. Knowledge-based authentication asks questions the real person should be able to answer and a stranger holding their stolen document should not. These signals are strong against a wholly invented identity and weaker against a real identity that has been taken over.

Is this a live face, and does it match the document?

Selfie matching and facial recognition compare the captured face to the identity document. Liveness detection asks whether the thing in front of the camera is a present human, a photo, a mask, or a screen. Deepfake detection looks for the specific artifacts that generated and face-swapped video leave behind. This group has changed the most in the last two years, because it is the group generative tools attack directly.

What device are they using, and where are they?

Device fingerprinting builds a stable picture of the hardware and software combination in use, which is how you notice that one device has completed transactions under nine different identities. Location risk data flags network origins associated with anonymization or with concentrations of prior fraud. SMS multi-factor authentication ties the transaction to control of a specific phone number. This group is excellent at detecting coordination. A single fraudster is hard to see. An operation running many identities through shared infrastructure is much easier.

How does this behavior compare to normal?

Email age is a crude proxy for how long this persona has existed. Behavioral analytics looks at how the person moves through the transaction: typing rhythm, hesitation, whether personal details are typed from memory or pasted from somewhere else.

Behavioral signals are quiet and hard to fake, precisely because the person performing them does not know they are being observed.

Do fraud signals make decisions?

No. A signal is evidence. A decision is policy. The step between them is where a system becomes useful or becomes something your team works around. A poorly designed system takes a bundle of signals, produces a number, and hands your team a red banner. The team cannot see why, cannot argue with it, and within a month has learned the banner is usually wrong about the cases they care about. They start clicking through it.

A well designed system does three things:

  • It routes for review. A suspicious transaction gets held for a person to decide, and the process continues.
  • It explains itself. The reviewer sees which signals fired and why they matter, so they can apply judgment without being a fraud expert. That is the difference between a tool your operations team uses and a tool your operations team escalates.
  • It learns from the reviewer. When someone marks a case as fraud or clears it, that judgment should improve the model.

How does Proof use fraud signals?

Proof Defend runs fraud risk signals in the background of a transaction. The current set includes identity database checks, home address validation, knowledge-based authentication, selfie matching, facial recognition, liveness detection, deepfake detection, device fingerprinting, location risk data, SMS multi-factor authentication, email age, and behavioral analytics. 

Those signals feed Proof's fraud detection model. Because Proof sees transactions across many organizations, network signals can surface coordinated patterns that no single organization would have the vantage point to notice on its own.

What your team receives is a routed transaction with the reasoning attached. Suspicious transactions are held for review, the signals that fired are shown in plain language, and when your reviewers make a call, that judgment trains the model. Deepfake detection analyzes the video feed for face swaps and AI impersonation when a person is on camera.

Fraud signals are small on their own. The value is in having enough of them, weighted well, and explained clearly enough that the person looking at the screen knows what to do next.

See what signals you can monitor in your transactions with Proof >

graphic of envelop on a square

Subscribe to our newsletter

Related Articles