TL;DR
India's banking system lost Rs 36,014 crore to fraud in FY 2024-25. While Loan scams caused the heaviest rupee losses; digital payment fraud dominated by volume. Current Rule-based systems are not able to stop either problem at scale
Fraud is the function where AI has the highest structural advantage: fraud patterns mutate continuously, attackers learn from detection, and the attack surface expands with every new product and channel. A static rule cannot keep pace with an adversary that iterates faster than your compliance cycle
The three fraud vectors at origination are application fraud, identity fraud, and synthetic identity fraud. Each requires a different architecture: document forensics, biometric liveness detection, and network graph analysis respectively
“Mulehunter.ai” developed by the Reserve Bank Innovation Hub is now used by 26+ banks, and it detects approximately 20,000 mule accounts per month. The MHA integration mandate by December 2026 makes this shared fraud infrastructure a regulatory requirement, not just an optional upgrade
AI-first compliance is not periodic sampling. It is real-time surveillance architecture. Automated SMA classification, CRILC reporting, and AML transaction monitoring at the speed RBI's norms now require cannot be delivered by a manual process
RBI's FREE-AI framework creates a specific governance tension for fraud models: a fraud flag that blocks a loan application produces the same outcome as a credit decline, the borrower does not get the loan. This raises questions about whether the same explainability and contestability obligations apply
The best fraud system is the one that catches bad applications before money leaves the door. Every fraud caught post-disbursement is a recovery problem. Every fraud caught at origination is a cost permanently avoided.
01/WHY TRAD. MODELS ARE OUTPACED?

Figure 1 : The Scale of the Problem — and Why Traditional Models Are Structurally Outpaced
India's banking system lost Rs 36,014 crore to fraud in FY 2024-25. That is a 194% increase over the prior year, even as the number of reported fraud cases fell to approximately 24,000 from over 32,000 in FY24. The RBI's annual report attributed the spike primarily to the reclassification of 122 legacy high-value loan scams (Rs 18,674 crore) after a Supreme Court directive.
Public sector banks absorbed 71% of total losses, largely from large-ticket loan frauds. Private banks logged the most incidents 14,000+ driven by card and internet banking breaches. Digital payment fraud formed 56% of cases by volume but a small share of total value. Loan scams caused the heaviest rupee losses.
The outstanding wilful default stock tells the longer story. As of March 2024, TransUnion CIBIL reported Rs 3.6 lakh crore in outstanding wilful defaults across Indian banks and NBFCs. These are not defaults but deliberate non-repayments by borrowers with the capacity to repay. A significant portion of this stock was originated by lenders who relied on documents, collateral assessments, and periodic reviews rather than real-time behavioural signals. The fraud was not invisible. It was below the detection threshold of the tools deployed.
This is why fraud is the function in the lending lifecycle where AI has the highest structural advantage and where the case for AI-first architecture is strongest.
Traditional rule-based fraud detection works by encoding known fraud patterns into fixed decision rules: if transaction amount exceeds threshold X and account age is less than Y days, flag. The problem is not that these rules are wrong. The problem is that they are fixed. Fraud is not. As digital lending volumes have scaled and new channels have opened Video KYC, UPI-linked origination, AA-enabled instant disbursals the attack surface has expanded faster than any rule set can track. A static rule encodes yesterday's fraud pattern. A new attack vector that does not match any existing rule produces no flag at all.
AI fraud models address this structurally differently. An ML model trained on behavioural patterns device fingerprinting, transaction velocity, network connections between applications, document forensic anomalies learns from new fraud patterns as they emerge in the portfolio data. When a new attack vector appears, the model's anomaly detection has a basis for identifying deviation from expected behaviour. The rule-based system requires a human analyst to first identify the new pattern, then write a new rule. The time between discovery and deployment is the window during which the fraud operates undetected.
This adaptability is AI's primary advantage in fraud over every other lending function. In credit underwriting, the model's objective is relatively stable — predict repayment. In servicing, the model optimises for borrower retention. In collections, it optimises propensity to pay. In fraud, the objective is a moving target: detect behaviour that evolves continuously, across a digital infrastructure that itself keeps expanding.
AI's structural advantage in fraud detection is not accuracy at a fixed point in time. It is the ability to keep learning as the threat landscape
02/FRAUD VECTORS AT ORIGINATION

Figure 2: Three Fraud Vectors at Origination
Fraud in Indian lending concentrates at three points in the origination stack. Each requires a different architecture.
Application fraud is the oldest vector and still the most prevalent by volume. The borrower submits fabricated income documents ITR printouts with altered income figures, salary slips from shell companies, bank statements with modified credit entries. The AI architecture for application fraud is document forensics: OCR extraction combined with computer vision to detect metadata inconsistencies, pixel-level anomalies, font irregularities, and timestamp mismatches between document content and the claimed issuance date. Cross-validation against GST filing data, ITR API verification, and salary account transaction patterns adds a second layer.
Tata Capital's 97.8% digital onboarding rate achieved through AI-powered OCR, NLP, and video KYC illustrates what this stack looks like in production. The residual 2.2% that requires manual intervention is not a failure of the AI; it is the governance design working correctly, routing genuine edge cases to human review.
Identity fraud has expanded significantly with the growth of digital lending channels. SIM swap attacks intercept OTP verification. Deepfake video technology now achieves sufficient quality to pass basic liveness detection. The industry expects deepfakes to make biometric authentication unreliable in isolation for roughly 30% of enterprise deployments by 2026. Video KYC, which RBI enabled as a remote onboarding mechanism, is the target because it is the highest-trust verification step in a fully digital origination flow.
The response is multi-modal verification: facial recognition combined with behavioural biometrics (typing cadence, device orientation, scroll patterns), device fingerprinting against known fraud device registries, and cross-session behavioural consistency checks. ICICI Bank's ML deployment for transaction anomaly detection across its private banking services uses the same underlying principle not a single signal, but the convergence of multiple signals that together produce a confidence score. No individual signal is sufficient; the model weights the combination.
Synthetic identity fraud is the most difficult to detect. A synthetic identity combines real data elements a genuine Aadhaar number, a real address with fabricated ones, creating a borrower identity that does not correspond to a real person but passes point-in-time verification checks. Bureau queries return thin files rather than fraud flags because the identity has no prior fraud history. Document checks pass because the real elements are genuine.
The architecture most suited to synthetic identity detection is network analysis: graph models that map connections between applications across shared attributes same device, same IP address, same employer listed, same guarantor contact, same nominated bank account. A single synthetic identity application appears clean in isolation. Applications from the same coordinated operation, submitted across different lenders over time, create a network signature that a graph model is designed to identify. This is an established fraud detection architecture globally; its deployment at scale in Indian lending is still at an early stage. The key constraint is not the model: it is the cross-lender data sharing infrastructure, which MuleHunter.AI is beginning to provide.
Fraud detection at origination requires three distinct architectures running in parallel. A lender that deploys only one of them is defending against the attack it can see, not the ones it cannot.
03/RBIH's MULEHUNTER

The most significant fraud prevention development in Indian banking in 2025–26 did not come from a private sector lender. It came from the regulator.
MuleHunter.AI was developed by the Reserve Bank Innovation Hub (RBIH), a wholly-owned subsidiary of RBI, using machine learning algorithms to analyse transaction and account data and detect mule bank accounts. Mule accounts are the plumbing of financial fraud: they receive proceeds from fraud, hold them briefly, and transfer them onward through layered transactions designed to break the audit trail. Without a mule account network, large-scale digital fraud cannot convert to accessible cash.
The system was built by analysing patterns from 19 different fraud cases across multiple institutions. The RBIH's CEO described it as having "tripled accuracy and significantly reduced detection time" compared to the previous manual system. The initial pilot ran in two public sector banks; the system now covers 26+ banks. It detects approximately 20,000 mule accounts per month.
The scale of the problem it addresses is visible in concentrated geography. Haryana's Nuh district recorded over 1,000 mule accounts identified in 2025. Jharkhand's Jamtara district — long documented as a cyber fraud hub saw over 350 identified in the same period. These are not distributed fraud incidents. They are organised operations with established account sourcing networks. A model trained on transaction patterns from a single bank cannot see the full network. A model trained on transaction patterns from 26 banks, with data shared under a regulated infrastructure, can.
On May 12, 2026, the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs signed an MoU with RBIH to integrate the I4C's Suspect Registry with MuleHunter.AI. The Suspect Registry contains intelligence on suspicious accounts and cyber fraud networks compiled by law enforcement. The integration connects criminal investigation intelligence directly into the banking fraud detection model a significant step in coordinating law enforcement and financial sector fraud response at the national level.
The Ministry of Home Affairs has directed all financial institutions to integrate with the MuleHunter platform by December 2026. This is not a recommendation. It is a compliance deadline.
The implication for lenders is architectural. Before shared fraud infrastructure existed, the build-vs-buy calculation for mule account detection was clear: the data requirements were high enough that only the largest private sector banks could train a proprietary model with sufficient coverage. With MuleHunter.AI as a shared platform, smaller NBFCs and regional banks access detection capability calibrated on the cross-industry fraud network at the marginal cost of integration, not model development.
The broader principle is that some fraud problems are industry-wide and cannot be solved at the individual institution level. Synthetic identity networks span lenders. Mule account chains cross banks. The shared infrastructure model MuleHunter.AI being the clearest Indian example is the architecture that matches the actual attack surface.
Individual fraud models catch the fraud that appears in one institution's portfolio. Shared fraud infrastructure catches the fraud that appears across the industry simultaneously. Both are necessary.
04/COMPLIANCE

Figure 4: Compliance
The traditional compliance function in an Indian lender runs on a periodic sampling model. A team reviews a random sample of loan files each quarter for KYC completeness. AML transaction monitoring runs batch jobs overnight and generates exceptions for review the following morning. SMA classification happens at month-end when the portfolio data is refreshed. The CRILC submission goes out weekly after a manual compilation process that takes two to three days.
This model has two problems at the current scale of Indian lending. First, the reporting cadence does not match the risk reality. A borrower's account can deteriorate from SMA-0 to SMA-1 in the gap between one week's CRILC run and the next. A suspicious transaction pattern in a large NBFC's portfolio may generate an AML exception alert three hours after the funds have moved. Second, the volume of decisions required across millions of loan accounts, hundreds of thousands of KYC refresh cycles, and real-time transaction monitoring exceeds what any manual sampling process can cover representatively.
AI-first compliance treats these functions as real-time infrastructure problems, not periodic audit problems.
Transaction monitoring and AML: HDFC Bank deploys real-time deep learning models that score every transaction as it passes through the system. ICICI Bank uses ML for transaction anomaly detection across its private banking services the model identifies deviations from each account's established behavioural baseline rather than flagging against static thresholds. The performance improvement over rule-based systems is consistent across deployments: ML-based behavioural monitoring reduces false positives by up to 50% compared to rule-based systems, according to compliance technology implementation data from 2025-26. False positive reduction is not just an efficiency metric it is a customer experience metric. A legitimate large transaction flagged by a rule-based system and held for manual review costs the lender trust and the customer time.
KYC and re-KYC: RBI's KYC Master Direction requires re-KYC at 2-year, 8-year, and 10-year intervals depending on customer risk classification. At the scale of a large bank or NBFC, the volume of scheduled re-KYC actions in any given month creates pressure on manual processes that grows with the portfolio. AI-powered KYC — OCR extraction, document cross-validation, risk score update — automates the standard case and routes only genuine complexity to human officers. Clari5 and Gieom, two India-focused compliance technology vendors active in Indian banking, are building KYC automation specifically calibrated to RBI's KYC Master Direction requirements. The infrastructure layer for AI-first KYC compliance is being built with domain specificity to India's regulatory context.
SMA classification and CRILC reporting: The RBI's IRACP norms require weekly CRILC reporting. An AI-first compliance architecture classifies SMA-0, SMA-1, and SMA-2 accounts in real time as the trigger conditions are met, rather than at week-end batch. The CRILC submission becomes an automated extract from a live classification. The practical consequence is that the lender's portfolio management team sees deterioration as it happens rather than up to a week later. For collections teams, an earlier SMA-0 flag creates the opportunity for a proactive contact before the account ages further.
Regulatory reporting automation: India's large private banks HDFC Bank, ICICI Bank, Axis Bank have invested heavily in data warehousing over the past five years, in part to support regulatory reporting automation. SBI's NextGen Data Warehouse and Data Lake initiative was motivated partly by the reporting obligation volume that manual processes could not scale to meet. The AI compliance layer sits on top of the data layer: it does not create the reporting obligation, but it automates the execution of it. The lender that has not built the data layer cannot automate the reporting, even if the AI model exists.
AI-first compliance is not about reducing the compliance burden. The regulations have not changed. It is about matching the delivery architecture to the regulatory cadence that already exists.
05/FREE AI ARCHITECTURE

Figure 4: FREE_AI REQUIREMENTS
RBI's FREE-AI framework creates a specific governance tension for fraud and compliance models that deserves careful attention.
A credit decline is explicit: the borrower applied for a loan and was declined. The reason code requirement under the Fair Practices Code is clear the lender must communicate the primary factors. A fraud flag that blocks a loan application produces the same outcome for the borrower the loan is not sanctioned but the mechanism is different. The lender is not saying "you are not creditworthy." It is saying "we have identified signals that indicate a potential fraud risk." That is a more sensitive determination, and it raises a question that lenders building AI fraud models need to answer before deployment: what does explainability look like for a fraud block, and what is the borrower's right to contest it?
The FREE-AI framework does not yet answer this question explicitly for fraud models. The framework's explainability and contestability principles apply to AI decisions broadly. How those principles translate to a fraud flag where full disclosure of the triggering signals would itself compromise the fraud model's security is a design challenge that requires lenders to make documented governance choices, not simply apply the credit model governance template.
Explainability: Every AI-driven fraud decision must be interpretable and available to the regulator on request. The audit trail for every fraud flag must be queryable. This does not require disclosing the specific signals to the applicant but it does require that the regulator can review the basis for the decision and that the lender has documented why those signals are valid fraud indicators.
Fairness: Geographic fraud signals carry the same bias risk described in Part 3 for credit models. A fraud model trained on historical fraud data from regions with high past fraud incidence may learn to flag applications from those regions at higher rates, not because the current applicants are fraudulent, but because the historical training data is geographically concentrated. Regular bias audits, with documented remediation, are a governance requirement under the FREE-AI framework. The cadence for those audits should be defined before the model goes live.
Human oversight: RBI expects that high-risk fraud flags those that block or substantially delay a loan application route to human review. Full automation of fraud blocking decisions, with no human review path, is not consistent with the FREE-AI framework's human agency principle. The design choice is where to set the threshold: which fraud model scores trigger automatic rejection, and which trigger human review.
Vendor liability: Many Indian lenders use third-party fraud detection tools e.g. bureau fraud modules, device intelligence APIs, document verification platforms. The FREE-AI framework is explicit that the lender carries regulatory liability for the governance of those third-party AI systems. A vendor's tool without documented bias testing, explainability architecture, and a monitoring schedule creates a gap in the lender's own FREE-AI compliance posture. The vendor governance requirement needs to be a contractual condition, not an assumption.
Data retention and DPDP: Fraud data presents a specific challenge under the DPDP Act's storage limitation principle. Transaction patterns, device fingerprints, and network analysis data collected for fraud detection have a legitimate purpose but that purpose has a time boundary. The consent architecture for fraud data collection, and the retention schedule for fraud model training data, need to be defined before the model is deployed, not at the first audit.
The FREE-AI governance requirements for fraud models are not a compliance exercise. They are the documentation that proves the fraud model is doing what it claims to do — and that the lender can defend that claim to RBI.
06/FRAUD & COMPLIANCE STACK

Figure 6: Four Layer Fraud & Compliance Stack
L&T Finance and Poonawalla Fincorp have built parallel fraud layers. Poonawalla's 57-project AI programme covers fraud detection across multiple workflows. L&T Finance's data architecture flags inconsistencies in trust signals at application stage rather than at portfolio review.
The regulatory framing matters here. RBI's FREE-AI principles require explainability in fraud decisions. A borrower whose application is rejected on a fraud flag must, in principle, be informed in plain language why. That is harder than it sounds. A black-box neural network that flags fraud but cannot say why is not deployable under FREE-AI. The fraud models being built into Indian origination stacks today are, by design, interpretable. The model says fraud and points to the specific signal. Signature anomaly score X. Geolocation mismatch Y. Document tampering confidence Z.
Inline fraud detection is the only origination AI use case where the bar is set by the regulator, not the lender. FREE-AI makes interpretability a deployment condition.
07/FOUR LAYER CREDIT ARCHITECTURE

Figure 6: Multi Layered Credit Architecture
In Part 3 of this series, the credit underwriting architecture of an AI-first lender was described as four layers: data ingestion with consent mapping, a champion model with documented explainability, a live challenger infrastructure, and a collections feedback loop. The fraud and compliance stack maps onto the same four-layer logic with different components at each layer and a specific addition: the shared infrastructure layer that no individual lender can build alone.
Layer 1: Real-time data ingestion at the point of application. Device fingerprinting, behavioural biometrics, document metadata, network graph signals all captured at the moment of application, before any credit assessment begins. The consent architecture here is governed by DPDP and the KYC Master Direction simultaneously: what data can be collected, for what stated purpose, with what retention schedule. The lender that has not defined this consent layer before deploying AI fraud detection is collecting data without a defensible legal basis.
Layer 2: Inline fraud detection — at origination, before disbursement. Document forensics, identity verification, and network analysis running as part of the origination flow, not as a post-processing check. The three vector architectures described in Section 2: document forensics, multi-modal identity verification, network graph analysis operate here. The decision architecture determines which combination of signal outputs produces an automatic decline, which produces a human review flag, and which produces a clean proceed. That decision architecture needs to be documented, bias-tested, and auditable.
Layer 3: Post-disbursement transaction monitoring. AML behavioural monitoring, SMA classification in real time, CRILC reporting automation, and early warning signal generation for the servicing team. This layer connects to the broader portfolio management infrastructure described in Part 5 (Servicing) the same data pipeline that feeds the SMA classification model also feeds the early warning system that triggers a proactive servicing contact. The technical architecture is shared; the business processes it serves are separate.
Layer 4: Shared infrastructure. MuleHunter.AI integration, I4C Suspect Registry connectivity (mandatory by December 2026), bureau fraud module feeds, and the lender's own fraud data contribution to shared platforms. This layer cannot be built by any single lender. It requires regulatory infrastructure that RBI and RBIH have now provided and integration capability. The lenders that delay MuleHunter.AI integration past the December 2026 deadline are not just non-compliant. They are operating without the mule account detection layer that 26+ banks already have.
The connection back to the credit underwriting stack from Part 3 is not incidental. The same data layer that feeds the credit model also feeds the fraud model. The consent records that govern AA data use for credit assessment also govern what fraud signals can be drawn from those same data flows. The champion-challenger governance framework that manages credit model deployment applies equally to fraud model deployment. An AI-first lender does not build separate data layers and separate governance frameworks for credit and fraud. It builds one data layer, one governance architecture, and deploys separate models against both.
Bajaj Finance's inline fraud detection Vision AI, Voice AI, and network anomaly detection running at origination as part of the FINAI stack illustrates that this integration is live in practice. The FINAI architecture positions fraud detection as part of the origination flow itself, not as a separate retrospective check. The governance framework, completed in Q4 FY26 and aligned to RBI's FREE-AI principles, covers both credit and fraud models within a single policy structure.
The fraud and compliance stack of an AI-first lender is not separate from the credit underwriting stack described in Part 3. It is the same architecture, deployed against a different objective — and the lender that builds one without building the other has protected the model without protecting the portfolio.
08/CONCLUSION
India's Rs 36,014 crore fraud loss in FY 2024-25 is not primarily a technology failure. It is a detection architecture failure. The large-ticket loan scams that account for Rs 18,674 crore of that total were originated over years of relationship banking, periodic review processes, and document-based underwriting exactly the processes that AI-first fraud detection replaces.
The digital fraud volume 24 lakh incidents, Rs 4,245 crore, 67% year-on-year increase reflects a different problem: a digital lending infrastructure that expanded faster than the fraud detection architecture deployed to protect it. The two problems have the same solution: real-time, behavioural, learning-based fraud detection built into the origination and monitoring stack rather than layered on top of it after the fact.
Mulehunter, the I4C integration, the FREE-AI governance framework, and the December 2026 mandate together constitute the most coherent regulatory fraud architecture India has assembled. The lenders that integrate early will have a compliance head start and a detection advantage.
Up next — Part 5: Servicing and Loan Management. What AI-first servicing looks like
Sources:
RBI Annual Report FY 2024-25 (fraud losses data);
TransUnion CIBIL Wilful Default Report March 2024;
RBI Innovation Hub Mulehunter documentation;
I4C-RBIH MoU, May 12, 2026 (BusinessToday);
RBI FREE-AI Committee Report (August 2025);
PwC/Dvara Research/FACE — Principles of RTAI in Digital Lending (March 2026);
Cedar-IBSi FinTech Lab — AI-Powered Compliance Real Use Cases (January 2026);
Decentro — AI Fraud Detection in Banking (November 2025);
Frontiers — AI in Indian Banking Sector (January 2026);
Tata Capital digital onboarding data (Appwrk, March 2026)
