Blogs

Fraud As A Service – How Industrialised Fraud Is Targeting Business Onboarding

20 September, 2026

blog_image blog_image

A company can appear on an official register and still be part of a fraud attempt. In a UK investigation, Companies House identified 786 companies suspected of cloning established restaurant businesses between December 2023 and February 2024. 

Their names often differed from familiar brands by only a character or punctuation mark. Companies House said such clones could be used to deceive suppliers and financial institutions or open business bank accounts under false pretences.

The investigation was not identified as a Fraud as a Service operation. It does, however, expose a problem for business onboarding: fraudulent applications can carry details that look credible at first glance. 

As criminal tools and expertise become easier to buy, onboarding teams need to examine how the details fit together before they approve a business.

What Is Fraud as a Service?

Fraud as a Service (FaaS) is a criminal business model that involves the sale of tools, stolen information or know-how that allows others to commit fraud. Offerings may include phishing kits, stolen personal information, and services that aid attackers in gaining access to accounts. 

Buyers do not have to build all of the capabilities; they can purchase parts of a scheme from others.

That division of labour matters. One group may obtain data, another may prepare fraudulent materials, and another may use them to apply for accounts or services. However, it all may vary.

For an onboarding team, the concern is that an application may be supported by more resources than its ordinary appearance suggests.

FaaS does not mean every suspicious business application or request comes from a criminal marketplace. It provides a useful way to understand why fraud attempts may become easier to prepare and repeat.

How Can FaaS Affect Business Onboarding?

Business onboarding asks the organisation to make a decision whether to form a business relationship with an applicant. This usually requires gathering company information, verifying company legal identity, checking related individuals and evaluating related risks.

A fraudulent applicant might be able to go through those steps with false information. They may provide information that looks like a real business, submit paperwork that isn’t consistent with the business, or provide names of individuals that are not associated with the business. 

Buying data or criminal services may make part of an application more convincing.

Consider a hypothetical application from a company whose name closely resembles a well-known business. Its registration number leads to an active entity. Yet the registered address, directors, and submitted documents point to a different organisation. 

A check that stops at “company found” may miss the mismatch. A connected review gives the onboarding team a reason to investigate before granting access.

The purpose of that review is not to treat every discrepancy as proof of fraud. Businesses make errors, records can lag, and corporate structures can be complicated. The purpose is to identify questions that need an answer before approval.

What the UK Company Cloning Case Reveals

The Companies House investigation offers a concrete example of business identity being used to create an appearance of legitimacy. Organised crime groups registered companies with names closely resembling established restaurant brands. 

Companies House said the intended uses could include deceiving suppliers and financial institutions, obtaining business bank accounts under false pretences and placing fraudulent orders. Following its investigation, it removed 965 companies and 2,895 fraudulent appointments from the register.

The lesson for KYB teams is precise: finding a company on a register is only one part of verifying the applicant. A registered entity may not be the established business its name evokes. The team also needs to establish which legal entity is applying, who represents it and whether the information supplied belongs to that entity.

This case supports the business onboarding angle. It should not be presented as evidence that the cloned companies used FaaS providers; Companies House did not make that connection.

Five Checks That Strengthen Onboarding Fraud Prevention

No single check can rule out a well-prepared fraud attempt. These five steps help teams build a clearer picture of the applicant and make inconsistencies easier to spot.

  • Confirm the Exact Legal Entity

Check the company’s registered name, number, jurisdiction and current status against an appropriate source. Compare them with the name used in the application, website, contract and payment details. A near match deserves attention, particularly when an applicant appears to be trading on another company’s identity.

  • Review the People Behind the Application

Identify directors, legal representatives and beneficial owners where relevant. Then establish how the person submitting the application is connected to the entity. A genuine registration record does not, on its own, verify that the applicant is authorised to act for that company.

Ownership can also be held by more than one entity or jurisdiction. In cases where the structure is not clear, you as the reviewer must have sufficient information to determine who the true owners or controlling persons of the business are.

  • Compare Documents With Company Records

Documents should reflect the same name used for the business as on the application and in the official information. Match names, addresses, dates and named representatives between the materials given. When the details differ, seek more information or clarification when you ask a question rather than assume one document resolves an issue.

  • Screen Related Business Entities and People

Sanctions, PEP and adverse media screening can reveal exposure that requires further assessment. A match is a lead for review, not an automatic finding about the applicant. The team should resolve potential matches and record how it reached its decision.

  • Escalate inconsistencies before approval

Provide reviewers with a clear pathway on how to resolve differences that have not been resolved. This could involve requesting more additional documents, verifying with the authoritative source or referring for further review. The key to effective onboarding fraud prevention isn’t how many checks you do; it’s what you do when information conflicts.

These steps form a practical fraud-prevention solution that can be built from various sources. They also note the reasons for approving, questioning, or rejecting a business.

Why the Review Cannot End at Approval

An accurate onboarding decision reflects the information available at that time. Directors can change. Ownership can change. A business may begin operating in a different sector or jurisdiction.

A follow-up process helps teams respond when relevant details change or new risk information emerges. The level and frequency of review should follow the organisation’s risk approach. The central point is simple: yesterday’s evidence should not be assumed to describe the business indefinitely.

How The KYB Supports a Connected Review

The KYB can help this process by incorporating business information collection, company checks, document based KYB and AML screening into the review of an applicant. 

The Cross team can take those steps to explore information about legal entities, review ownership and UBO, compare submissions, and review relevant risk exposure.

The role has a very clear boundary. The KYB helps to set the stage for who and which business is applying. Additional controls can be implemented after onboarding to monitor account activity, payment activity or indicators of an attack.

This can be a complex area with potentially confusing terminology. Fraud as a Service refers to criminal services used to enable criminal activities. Fraud detection as a service and fraud prevention as a service typically refer to real services companies rely on to detect or deter fraud. Although sounding similar, they’re two different ideas.

Make the Approval Decision Count

Industrialised fraud can make an application look polished. A company name, registration record and complete form may each appear reassuring while failing to tell the whole story.

The UK cloning case shows why onboarding teams must verify the exact entity and connect it to the people, documents and risks in the application. A strong fraud-as-a-service defense starts with questions that a convincing form alone cannot answer.

Want a clearer view of the businesses you onboard? Book a demo with The KYB.

very any business

Verify Any Business,
Anywhere In The World

Live registry documents & UBOs across
250+ countries

Stay Updated!

Join Our Newsletter

Loading

Latest Posts

30 September, 2026

.

Simplified Due Diligence: How to Reduce Compliance Work Without Increasing Risk

30 September, 2026

.

Switzerland to Launch Beneficial Ownership Register on 1 October 2026

29 September, 2026

.

Ecommerce Fraud Prevention: Strategies, Systems and Best Practices

Stay Updated!

Join Our Newsletter

Loading

Recent Blogs

Simplified Due Diligence: How to Reduce Compliance Work Without Increasing Risk
Ecommerce Fraud Prevention: Strategies, Systems and Best Practices
What Is Operational Due Diligence? 10 Essential Checks for M&A Deals