Fraud Moves Downstream: Intake Is the Cheapest Fraud Control in Loan Origination
Fraud prevention in loan origination is cheapest before funding. What published costs, recovery rates and detection lags show, false positives included.
Alfred BEditorial Reviews
Fraud budgets accumulate where fraud gets discovered. That is rarely where it entered. By the time a file reaches post-funding review the money is out, and the question has changed from whether to lend into whether anything can be recovered.
Fraud prevention in loan origination is cheapest at intake because every control applied later operates on money already gone. The United States Government Accountability Office, in its July 2015 fraud risk framework GAO-15-593SP, states that preventive activities generally offer the most cost-efficient use of resources, since they let managers avoid a costly and inefficient pay-and-chase model.
The interesting part is what happens when you try to put a number on that.
Why does fraud prevention in loan origination pay most at intake?
Fraud prevention in loan origination pays most at intake because the cost of acting falls on the decision, not the recovery. A file refused before funding costs a verification step and one lost application. The same fraud found afterward costs principal, production expense already spent, and years of collection.
The multiplier usually attached to this claim deserves care. Versions of "a dollar spent at intake saves ten downstream" circulate with no traceable origin, and we found no primary study behind any of them. The nearest sourced figure is vendor research: the LexisNexis Risk Solutions True Cost of Fraud study of April 2024 put the cost at US$4.41 per dollar of fraud loss across North America and US$4.45 in Canada, on 2023 data. That is cost per dollar lost, not cost by stage.
The case is stronger without one, because the underlying costs are published separately. The Mortgage Bankers Association reported on 15 May 2026 that total loan production expenses for independent mortgage banks and mortgage subsidiaries of chartered banks averaged US$11,898 per loan in the first quarter of 2026, spent whether the applicant was real or not.
Recovery is worse than most budget debates assume. The Small Business Administration Office of Inspector General, in Report 23-09 dated 27 June 2023, estimated more than US$200 billion in COVID-19 EIDL and PPP loans went to potentially fraudulent actors, at least 17 percent of funds disbursed, against nearly US$30 billion seized or returned by May 2023.
Discovery is slow too. The Financial Crimes Enforcement Network, in its Mortgage Loan Fraud Update for calendar year 2012, found 57 percent of mortgage loan fraud suspicious activity reports described activity that began more than five years before filing, and named repurchase demands as the trigger: those demands prompted the origination document reviews in which filers found the fraud. Someone else's audit was the detection layer.
What each stage can still do about a fraudulent file, with the published costs attached.
| Stage | What can still happen | What the evidence shows |
|---|---|---|
| Intake, pre-decision | Refuse, or ask for source-verified data | Verification cost only; the loan is never produced |
| Underwriting, pre-funding | Decline or restructure | Most production expense incurred, principal not yet at risk |
| Post-funding review | Repurchase, write-off, referral | US$11,898 average production expense per loan, Q1 2026, Mortgage Bankers Association |
| Recovery and enforcement | Seize, litigate, refer | Nearly US$30bn recovered against more than US$200bn potentially fraudulent, SBA OIG Report 23-09, June 2023 |
| Detection lag | Learn about it later | 57 percent of 2012 mortgage loan fraud SARs covered activity begun over five years earlier, FinCEN |
What does the intake control set actually contain?
The intake control set is the group of checks that can run before a lending decision, on data the applicant consents to share. The Federal Reserve's July 2020 payments fraud insights paper on mitigating synthetic identity fraud says a multi-layered approach using both manual and technological data analysis gives organizations the best chance of identifying synthetics.
Four things sit in that layer. Verification against an authoritative source, which in the United States includes the Social Security Administration's Electronic Consent Based SSN Verification service, launched in 2020. Attribute tenure, which the same Federal Reserve paper describes as how long an email address has been active or whether phone and address ownership data match. Link analysis across applications. Source-verified financial data in place of applicant-supplied documents.
The last of those carries more weight in Canada, because the first three are thinner here. Equifax Canada reported on 15 April 2026 that in banking and deposits, falsified financial information rose from 1.5 percent of first-party fraud cases in the fourth quarter of 2024 to 21 percent a year later. That is a document problem, and it does not survive a pull from the institution holding the account. Scale is not the reason to leave it downstream: the Federal Trade Commission's Consumer Sentinel Network Data Book for 2024 recorded 176,400 identity theft reports categorised as loan or lease fraud, and every one of them began as an application.
What do false positives actually cost?
False positives are the strongest argument against moving fraud spend to intake, and the case deserves its best version. A control running before the decision acts on incomplete information, against a population that is overwhelmingly legitimate. The people it gets wrong are customers, and the Federal Reserve's July 2020 paper notes that false positives in customer information can be difficult for them to rectify.
The largest published comparison comes from cards. Javelin Strategy and Research, cited in the National Taxpayer Advocate's 2016 Annual Report to Congress study on reducing false positives in fraud detection, found one in six legitimate cardholders experienced a decline on suspicion of fraud during 2014, amounting to US$118 billion in blocked sales against US$9 billion in real card fraud that year. Javelin is vendor research. The ratio is thirteen to one, and it should bother anyone arguing for more screening.
Base rates make the rest arithmetic. Equifax Canada put first-party fraud in Canadian banking and deposits at 0.68 percent in the fourth quarter of 2025, without publishing the denominator behind that rate. Take it as an incidence rate and the illustration is unforgiving: over 10,000 files, catching 95 percent of fraud at a 5 percent false positive rate returns about 65 correct flags and about 497 wrong ones. Nearly eight good files questioned per fraud caught.
Canadian fraud is not uniformly rising, either. The same Equifax Canada release reported auto fraud down 19.4 percent year over year and mortgage fraud down 12.5 percent, against first-party fraud up 31 percent overall. Arguing for more intake control means arguing for a number of declined good applicants. Anyone taking that position, this piece included, owes the number.
How would a reallocation actually work?
A reallocation here is smaller than the argument sounds. It starts with one measurement almost no lender publishes: on every confirmed fraud loss, the days between funding and discovery, and the stage at which it surfaced. The FinCEN filing lag is that metric with nobody owning it.
Two things follow. Review capacity moves toward the point where a file can still be refused, since the same analyst hour buys a decline before funding and a write-off after. And the per-loan production expense becomes the price tag on every fraudulent file that clears.
Here is the view a committee would soften. A fraud budget weighted toward post-funding review is a budget for measuring fraud rather than preventing it, and it will go on producing well-documented losses.
What we couldn't verify
The by-stage cost multiplier. Every version we chased led to a vendor page, a slide, or an unattributed restatement. The argument above is built without one, on purpose.
Canadian data on detection stage. The Canadian Anti-Fraud Centre reported on 25 February 2026 that Canadians filed over 112,000 fraud reports in 2025 with more than $704 million in losses, identity fraud the most frequently reported type at 8,403 reports. Statistics Canada reported on 22 July 2026 that the police-reported rate of total fraud fell 4 percent in 2025 to 492 incidents per 100,000, still 61 percent above 2015. Neither says where a lender caught anything.
We also found no publicly documented Canadian consent-based identity verification service open to lenders comparable to the SSA's eCBSV.
Common questions
Is fraud cheaper to catch at intake or after funding?
At intake. The United States Government Accountability Office's July 2015 fraud risk framework states that preventive activities generally offer the most cost-efficient use of resources because they avoid a pay-and-chase model. A file refused before funding costs a verification step; the same fraud found later costs principal and production expense.
Is there a real multiplier for fraud caught at intake versus downstream?
No traceable one. Versions of "one dollar at intake saves ten later" circulate without a primary source. The nearest sourced figure is vendor research from LexisNexis Risk Solutions, April 2024, putting fraud cost at US$4.41 per dollar of loss across North America and US$4.45 in Canada, on 2023 data.
How long does loan fraud take to surface?
Longer than most models assume. The Financial Crimes Enforcement Network found 57 percent of mortgage loan fraud suspicious activity reports filed in 2012 described activity beginning more than five years earlier, with repurchase demands prompting the reviews that found it.
What controls can run before a lending decision?
The Federal Reserve's July 2020 paper on mitigating synthetic identity fraud describes a layered set: verification against authoritative sources such as the SSA's eCBSV service, checks on how long an email address or phone number has been tied to the applicant, link analysis across applications, and manual review alongside automated scoring.
What do false positives cost a lender?
More than the fraud, in at least one market. Javelin research cited in the National Taxpayer Advocate's 2016 report to Congress found US$118 billion in legitimate 2014 card sales blocked on fraud suspicion against US$9 billion in real card fraud. At a 0.68 percent incidence rate, a 5 percent false positive rate flags about eight good files per fraud caught.
Carousel runs verification inside the intake flow, before a file becomes a funded loan. See how verification fits your flow


