Episode 28

Is AI fraud detection for lenders working? | Karan Gandhi, Best Egg

In this episode, Best Egg’s Karan Gandhi and Inscribe CEO Ronan Burke discuss why fraudsters are increasingly blending in rather than standing out, why document review has become forensic work, and what it will take to trust an AI agent to act on a customer’s behalf.

Brianna Valleskey
Head of Marketing

Karan Gandhi has spent 15+ years fighting fraud at JPMorgan Chase, Citi, and Discover, and now leads fraud and verification operations across Best Egg's personal loan product suite. 

He recently sat down with Inscribe co-founder and CEO Ronan Burke on our Good Question podcast to talk through how fraud has industrialized, why document review now looks more like forensic work than a quick visual check, and where the real opportunity for lenders sits: proving who's trustworthy, not just flagging who isn't.

AI has industrialized fraud

Karan's first point cuts through a lot of the noise: what AI has actually changed is the skill required to commit fraud. A fake bank statement or pay stub used to take real expertise. Now it takes minutes and none. That drop is also showing up as more first-party fraud: good customers who decide the math has changed in their favor.

"It's easy to now create a fake bank statement or pay stub compared to what it was before. It would require an expertise skill set for that. Because now AI has made that barrier of expertise go away, the fraud has become a little bit more prevalent."
-- Karan Gandhi

The new fraud playbook is blending in, not standing out

Fraudsters used to go after lender controls head-on. Now they just disappear into normal customer behavior. Karan's point: nobody's building the "perfect" application anymore. They're building the most believable one. Patient. Unremarkable. Built specifically to avoid the red flags that used to give them away.

"Fraudsters no longer try to beat the controls. Today, they try to blend in. The goal is not to become invisible, but to be like a legitimate customer that can blend into the surrounding."
- Karan Gandhi, Senior Director of Credit Strategy, Best Egg

That shift changes the whole job. Fraud teams aren't hunting for one bad-looking application anymore. They're checking whether a customer's entire story holds up across every signal available.

Document review has moved from a visual check to forensic work

A few years ago, catching a fake document was mostly a visual game: does the formatting line up, does anything look edited. AI-generated documents can be flawless now, so the real signal lives somewhere else: metadata, numeric consistency, behavioral context.

"You're not looking for formatting errors or obvious edits anymore. You're looking at things within the metadata, consistency across the documentation, the numeric relationships."
- Karan Gandhi, Senior Director of Credit Strategy, Best Egg

Ronan tied this back to how Inscribe's own detection has evolved: forensic detectors first, then semantic and perceptual layers, and now network detectors that measure a document against every similar one that's passed through Inscribe's network, plus that customer's own behavior over time.

Karan's analogy is airport security: the document stops being the thing under review and becomes one input into a bigger identity check. On its own, a document doesn't prove anything anymore. It's just one piece of evidence in a much bigger trust picture.

Documents vs. data connectivity is a customer experience decision first

When Karan weighs document upload against data connectivity, like Plaid or Finicity, he starts with friction, not fraud risk. If a data connection can verify something passively, that's the path most customers will take without complaint. Document upload and account-linking both ask something of the customer, so the real deciding factor is what's available and what a given customer will actually tolerate.

 The real trigger for pulling both signals together is inconsistency. When something in an application doesn't match what a lender's seen before, that's the moment to stop leaning on just one source of truth.

AI's clearest use case right now is investigation prep, not decisioning

Karan's not ready to hand decisions over to agentic AI yet, but he's already using it for the prep work: pulling information together, summarizing findings, flagging inconsistencies, and building the case file before an analyst even opens it.

"I compare it to radiology. AI can look at all the different X-rays and highlight the areas that may require attention, but the diagnosis is still made by the doctor, looking at patient history, symptoms, and prior scans."
- Karan Gandhi, Senior Director of Credit Strategy, Best Egg

The judgment call still belongs to the human. What AI changes is how much legwork happens before that call gets made.

AI Agents now act on customers’ behalf

Karan splits agentic AI into two very different buckets:

  1. Inside fraud and lending teams, agents helping with investigation, triage, and parts of the application flow are already paying off. That part's working today.
  2. Agents acting autonomously on a customer's behalf, the way one might complete a purchase in e-commerce. 

Karan doesn't think that's ready, and the holdup has nothing to do with the technology. It comes down to trust and authorization: who created the agent, what it's actually allowed to do, and whether that permission can be checked or pulled back in the moment.

 "There's no way for the grocery store to validate that information,” Karan said. 

His analogy: if his nephew tries to buy him a beer, the store has no way to confirm the nephew's actually authorized to do that. 

An AI agent acting on a customer's behalf needs the same kind of verifiable credential, tied to who created it and what it's allowed to do, before a lender can trust it with anything.

The underestimated shift: from catching bad actors to proving trustworthy ones

Karan's closing point reframes everything that came before it. The industry has spent years optimizing for catching fraud. The bigger opportunity is building a trust architecture that validates good customers first, and lets fraud fall out by elimination.

"We're moving away from identifying a bad actor or a bad application. We're moving toward how we create a trust architecture, one that helps you trust the data points you've collected about a customer and identify a good one."
- Karan Gandhi, Senior Director of Credit Strategy, Best Eggi

Ronan landed in the same place: fraud detection is becoming less about spotting who looks wrong, and more about proving who's genuinely right.

"It's not necessarily about catching the bad characteristics. It's about verifying the good ones, and by deduction, separating out the fraudsters from there."
- Ronan Burke, co-founder and CEO, Inscribe

Frequently asked questions

Why is fraud harder for lenders to catch than it used to be?
Fraudsters have shifted from trying to beat detection controls to blending into normal customer behavior. Instead of building an application designed to look "perfect," they build one designed to look ordinary and patient enough to avoid obvious red flags. Fraud teams increasingly have to evaluate whether a customer's full story holds together across signals, not whether any single signal looks suspicious.

How has AI changed document review for lenders?
AI has made fraudulent documents visually indistinguishable from genuine ones, pushing review from a visual check into forensic work. Detection now depends on metadata, numeric consistency, and behavioral context rather than formatting errors, and increasingly on comparing a document against a network of other documents rather than reviewing it in isolation.

Should lenders use document verification or data connectivity like Plaid?
The choice is usually driven by customer experience first. A passive data connection typically creates less friction than a document upload when it's available, but inconsistencies in an application are the trigger to require both. Neither signal is treated as sufficient on its own.

What is a fraud trust architecture?
A trust architecture evaluates whether the full set of signals a lender has about a customer, documents, behavior, and independent verification, supports trusting them, rather than scanning for red flags that mark someone as suspicious. It reframes fraud detection as validating good customers instead of only hunting for bad ones.

Related reading

Subscribe to Inside Inscribe for monthly updates on fraud, AI, and what I'm learning from the people fighting it.

About the Guests

Ronan Burke is the co-founder and CEO of Inscribe. He founded Inscribe with his twin after they experienced the challenges of manual review operations and over-burdened risk teams at national banks and fast-growing fintechs. So they set out to alleviate those challenges by deploying safe, scalable, and reliable AI.

Karan Gandhi is Senior Director of Credit Strategy at Best Egg, where he leads fraud and verification operations across the personal loan product suite. He has spent more than 15 years in consumer lending, fraud strategy, and portfolio management, including roles at JPMorgan Chase, Citi, and Discover.

What will our AI Agents find in your documents?

Start your free trial to catch more fraud, faster.

Join our email list for the latest risk trends and product updates.
Inscribe