NETZONE Management Services
Insights

Risk

Fraud control in retail portfolios: sampling, seeding, and the questions dashboards hide

Fraud rarely announces itself as a spike. It accumulates in channels, agencies, and product variants that look healthy until a cluster of files is examined together.

NETZONE Research

NETZONE Research

December 9, 2025·16 min read

Analytics dashboard used for portfolio risk monitoring

Retail fraud in Indian credit markets is a systems problem. Identity collusion, income fabrication, dealer-assisted inflation, and mule accounts do not require a criminal mastermind. They require a process with predictable gaps and an incentive to push files through. The institutions that contain loss treat fraud control as ongoing testing of that process, not as an investigations unit that arrives after a tip-off.

RBI’s emphasis on customer protection and on the regulated entity’s responsibility for outsourced activity has a practical implication: if your partners can originate, you must be able to test them. Mystery shopping, seeding, document de-dupe, merchant and establishment checks, and market intelligence are not “nice to have.” They are how you know the control still works after the last SOP rewrite.

Sampling with intent

Random sampling comforts audit committees and misses fraud. Fraud is clustered. Sampling should overweight new sourcing partners, high-growth pin codes, products with rapid TAT, files with perfect documentation, and agencies whose negative rates are implausibly low.

A second sample should be designed around known typologies: same employer address used across unrelated applicants, repeated mobile number patterns, vehicle valuations that sit in a tight band above LTV policy, and photographs that recur with different names.

Seeding and mystery shopping

Seeding, inserting known defective or test cases into the live stream, is one of the few tests that answers “would we have caught this?” Mystery shopping of verification and collection behaviour answers a different question: “what does the customer actually experience, and does our partner follow the script we signed?”

Both are uncomfortable. Both are cheaper than a vintage that should never have been booked. They should be scheduled, not reserved for scandals.

Investigations as a learning system

When a fraud case is confirmed, the value is not only recovery. It is the update to policy, agency scorecards, and the negative database. Institutions that close cases without feeding typologies back into origination will investigate the same pattern next year.

NETZONE’s fraud-control work sits beside field verification and recovery for this reason: the same network that visits can also test, investigate, and report in a form credit risk can act on.

Clustered

Most retail fraud is not random; it sits in partners and pin codes

Seeding

The cleanest test of whether a live process would have caught the case

Negative DB

Only useful if confirmed cases actually flow back into origination

Typologies that keep returning in Indian retail

Identity collusion around a single address or mobile cluster. Income fabrication through salary slips that share a template. Dealer-assisted LTV inflation on used cars. Synthetic employment on small personal loans. Merchant or establishment fronts that exist only on the day of verification.

None of these require a new model. They require sampling that looks where growth is fastest. The pin code that doubled volume last quarter is the pin code to seed this quarter.

Review of files and working papers
Figure 1. Fraud control is process testing. Investigations arrive after the typology has already booked.

A 12-week fraud-testing calendar

Weeks 1 to 2: pull partner, pin-code, and product growth; list agencies with zero negatives. Weeks 3 to 6: seed known defect files and run mystery shops on verification and collection scripts. Weeks 7 to 10: investigate confirmed hits and update the negative database. Weeks 11 to 12: change policy and partner scorecards, then publish the change to credit.

If the calendar ends without a policy change, the institution ran a project. It did not run a control.

This note reflects NETZONE operating experience in risk, audit, and statutory work across India. It is not legal, tax, or regulatory advice. Institutions should take counsel on their specific facts and licences.