A synthetic-identity signal supports an evidence decision
Socure’s Sigma Synthetic documentation describes risk scores and reason codes aimed at manipulated or fabricated identities, with stated U.S. onboarding and portfolio uses. These outputs can help determine what additional evidence is useful. A high score is not proof that an applicant committed fraud, nor a substitute for assessing the suitability or affordability of a financial product. [1][2]
For financial-service staff and customers, the relevant outcome is a reliable identity decision that permits legitimate access and detects material concerns. The product’s score definition, response design and correction process matter as much as the model generating the signal.
Read the score correctly
The product documentation describes a score ranging from 0.001 to 0.999 and explains the ranking relative to identities in its network. Its example of 0.800 indicates a higher synthetic-risk ranking than 80% of that population. Do not interpret this automatically as an 80% probability that the applicant is fraudulent. The response also includes model information and reason codes.
Analysis: the meaning of a threshold depends on the population, fraud prevalence and the cost of each possible action. A threshold that works for an existing-account review may be unsuitable for a new-account application. Keep the model version with the result so changes in score distribution are not confused with changes in customer behavior.
A base-rate example
Assume a fictional set of 10,000 applications contains 100 genuinely . A screening policy identifies 80 of those but also flags 198 legitimate applicants, a 2% rate among the 9,900 legitimate applications. Of 278 flagged applications, only about 28.8% are synthetic under these assumptions.
This is a teaching example, not a Socure performance estimate. It demonstrates why a high detection rate can still create substantial customer friction when the underlying event is uncommon. It also shows why “percent detected” is insufficient without false positives, prevalence and the denominator used.
Design the response as carefully as the detection
A high score could route a case to an additional identity check or human review rather than immediately ending the application. Socure’s documentation discusses additional verification options. The appropriate action depends on the product, legal obligations and the evidence available.
Scroll horizontally to see all columns.
| Stage | Proposed measure | Why it matters |
|---|---|---|
| Inputs | Completeness and source quality | Missing or incorrect data can distort the signal |
| Detection | Recall and precision at chosen thresholds | Balances missed fraud against false alarms |
| Intervention | Completion rate and review time | Measures legitimate-customer friction |
| Outcome | Confirmed fraud loss and appeal results | Tests whether the policy improves results |
| Change control | Model version and threshold history | Makes results comparable over time |
A new architecture is a testable claim
Socure announced Sigma V4.5 in July 2026 and described a shift to a transformer-based architecture. The company’s announcement makes claims about improved identity-fraud detection. Those are vendor claims; the architecture’s name alone does not establish better performance for a particular bank.
Analysis: evaluate the proposed version against the existing version on a common population and outcome definition. Separate changes attributable to the model from changes in available data, thresholds or review capacity. If the new score distribution differs, copying the old threshold can silently change the intervention rate. Require a planned transition and a way to investigate unexpected outcomes.
The evidence challenge
Fraud labels are often delayed and imperfect. A rejected application may never produce an observable loss, and a successful verification may change the outcome. Analysis: document how confirmed fraud is defined, how long outcomes are observed, and how sampled investigations reduce uncertainty in unreviewed populations.
Test differences across relevant customer groups and data-availability conditions. A model can appear strong overall while producing excessive friction for a smaller segment. Review appeals and customer complaints as evidence about , while recognizing that neither an appeal nor its absence proves the original decision was correct.
Review the result of the intervention
Analysis: a request for an additional document or permitted database check should resolve a specific concern. Measure successful verification, unresolved cases, customer effort and subsequent confirmed fraud. A higher approval rate after step-up may reflect better evidence or looser standards; later outcomes help distinguish them.
In the retained hypothetical test, 278 flagged applications include 80 and 198 legitimate applicants. At twelve minutes per initial review, that produces 55.6 hours of work. The legitimate cases are not automatically lost customers: some complete verification. Report their final outcomes rather than treating all flags as declines or all closures as successful access.
Compare versions at the same decision setting
Socure’s July 15, 2026 V4.5 article distinguishes Sigma Identity, aimed at third-party identity fraud, from Sigma Synthetic, aimed at fabricated identities, and describes a shared transformer foundation. These are company statements about architecture and product scope. They do not establish equivalent performance or identical outcomes for the two products. [3]
An upgrade comparison should identify the returned model version, affected population and actual action threshold. Hold a meaningful measure of customer friction or detection constant when comparing models, and include later labels and corrections. A new architecture may justify testing, but architecture alone cannot establish financial benefit.
What would justify confidence in the full process
The strongest evidence connects fewer confirmed identity losses or more efficient verification with reliable customer completion and manageable total cost. Include data quality, rework and service availability in the assessment.
Sigma Synthetic should be evaluated as part of an identity-verification service. The commercial result comes from the quality of the final decision and its effect on access, not from interpreting a high normalized score as a probability of guilt.
Sources
- Socure documentation — Sigma Synthetic Fraud scoring and outputsSourceBack to text: ↑
- Socure documentation — Product usage scopeSourceBack to text: ↑
- Socure — Sigma V4.5 announcement, July 2026SourceBack to text: ↑