Identity Verification, Income Verification & Fraud Prevention
What this artifact is. A demonstration artifact for PMC prospect outreach. It is not a client deliverable, is not tied to any live engagement, and is not a redaction of a real document. Nothing in it is extracted from any client or prospect. It was authored from specification.
What is real and what is composite. The methodology, the section structure, the scoring framework, the confidence rationale format, and the Capabilities Taxonomy service lines are production. The operator is composite. The vendors are anonymized and characterized by capability profile only.
A brief operator profile, provided because a prospect reading this does not know the portfolio the way a real client would. This is context for the three documents that follow, not part of the Stakeholder Document structure.
| Parameter | Value |
|---|---|
| Portfolio | 76 communities · 19,500 units · average 257 units |
| Markets | Texas ~45% (34 communities) · Midwest ~35% (27) · Mountain West ~20% (15) |
| Asset mix | 50 Class B garden value-add · 17 Class A mid-rise · 9 Class C stabilized |
| Operating model | Hybrid - 47 communities owned, 29 fee-managed for four institutional owners |
| Organization | No CIO or CTO. The CFO owns the technology budget by default. The VP of Operations is the de facto systems owner. Two IT staff and one helpdesk contractor report to the CFO and handle infrastructure only. Marketing runs its own stack. Seven regional managers. A five-person centralized leasing pod covers 22 communities; it was piloted in 2025 and never expanded. There is no vendor management function. |
| Incumbent stack | One core property management platform, nine years in place, renewed twice without competitive review, with bundled modules taken by default. 38 point-solution contracts outside it. Five overlapping pairs, inherited from a 19-community acquisition in 2023. Three auto-renewing contracts whose terms no current employee has read. One vendor paid monthly for 14 months with zero active users. |
| Identified annual technology spend | ~$5.5M · $282 per unit per year · $23.50 per unit per month |
Three documents follow, covering the three decisions a property management company actually faces.
| Document | Service line | Action | The decision |
|---|---|---|---|
| 1 | Maintenance Management & Work Orders | Keep | You already have the right answer. Here is the proof, and here is what it was tested against. |
| 2 | Insurance Programs, Risk Transfer & Resident Insurance Structures | Add | You have nothing here at all. Here is what that costs you, and what to put in. |
| 3 | Identity Verification, Income Verification & Fraud Prevention | Move To | You have something and it is the wrong thing. Here is the case for leaving, and what leaving actually costs. |
§1 Executive Summary
MFC recommends moving to a fraud-native verification provider across all 76 communities at approximately $105,300 a year plus $28,000 once. Confidence: 79%. Sixty-one fraudulent applications reached move-in last year, carrying roughly $487,000 in associated loss, and not one was identified before a lease was signed. That is not a performance failure by the current provider. Its identity check matches an applicant against credit bureau records, which is competent at assessing creditworthiness and structurally blind to the two things actually happening: professionally fabricated income documents, and synthetic identities that pass bureau matching precisely because they have been cultivated to have real credit files. The recommended provider examines the underlying file structure of submitted documents rather than their appearance, detects the pattern of a manufactured identity, and draws on cross-operator data covering all three of this portfolio's regions. This is the strongest financial case in the set - even assuming only 45% of known cases are caught before lease signing, the change clears its cost by roughly $110,700, and 61 is a floor rather than a measured total. It is also the most conditional recommendation of the three. The provider flags roughly 4.1% of applications for review, and most of those applicants will be legitimate people with thin credit files or non-traditional income. If the operator will not commit in writing to human review of every flagged application, MFC's recommendation is to keep the incumbent.
§2 Current State
What runs today
Identity and income verification are handled as a pass-through service attached to resident screening. When an applicant applies, three things happen:
- Identity check. Name, date of birth, and Social Security number are matched against credit bureau records. If the identity matches an existing credit file, it passes.
- Income check. The applicant uploads pay stubs or a bank statement. A leasing associate looks at them and decides whether they appear genuine and whether the stated income supports the rent.
- Screening decision. Credit, criminal, and eviction history are returned and scored against the operator's criteria.
Deployment. All 76 communities, all 19,500 units. Every leasing associate uses it. The five-person centralized leasing pod uses the same workflow for its 22 communities.
Volume. Roughly 16,200 applications a year, producing about 9,400 approved leases.
What it costs
This is the part that makes the decision harder than it looks.
| Line | Amount | Basis |
|---|---|---|
| Application fee charged to the applicant | $75 | Confirmed |
| Screening and verification pass-through cost | $32 per application | Confirmed - current provider agreement |
| Applications per year | 16,200 | Confirmed |
| Net operator cost | $0 | Confirmed |
The operator's direct cost for this service line is nothing. Application fees more than cover the pass-through, and the difference contributes a small amount to the marketing budget. Any change here starts from a position of costing more than what it replaces. That is the honest starting point and §7 does not dodge it.
What it costs elsewhere
The cost of this service line does not appear in this service line. It appears in bad debt, in turn costs, and in vacancy.
Trailing twelve months, portfolio-wide:
| Measure | Value | Basis |
|---|---|---|
| Applications later confirmed fraudulent | 61 | Confirmed - identified after move-in |
| Total loss associated with those 61 | ~$487,000 | Estimated - MFC composite of bad debt, legal cost, turn cost, and vacancy days |
| Of which, bad debt written off | ~$298,000 | Confirmed - general ledger |
| Fraud cases detected before lease signing | 0 recorded | Confirmed absence - no field captures a pre-lease fraud decline |
What the operator does not know
Every one of the 61 cases was found after move-in. Some surfaced when the employer on the pay stub could not be reached during collections. Some surfaced when a resident stopped paying in month one. One surfaced when a regional manager recognized the same employer name on applications at three communities in three different states.
There is no record of a single application declined for suspected fraud, because there is no mechanism that would produce one. The workflow has no fraud decline reason and no place to record a suspicion.
This means the operator knows its detection count and does not know its miss rate. Sixty-one is the number found. The number that got through is unknown and unknowable with the current process. That gap is the central fact in this document and it constrains everything in §7.
Contract posture
The verification and screening service runs on a month-to-month pass-through agreement with 30 days' notice and no minimum volume. There is no term, no exit fee, and no minimum commitment. Contractually, this is one of the easiest categories in the portfolio to change.
The friction is operational, not contractual - workflow, staff retraining, and applicant experience. §9 treats those seriously. But nobody should approach this decision believing they are locked in. They are not.
§3 Problem Framing
The verification in place was built to answer a question nobody is asking anymore.
Credit bureau identity matching answers: does this identity exist and does it have a credit history consistent with what was stated? That was the right question when the primary risk was an applicant overstating their finances. It is still a useful question.
It is not the question that produced 61 fraudulent move-ins.
Two things changed and the operator's process did not change with them.
Fabricated documents became a purchased service. Producing a convincing pay stub, bank statement, or employment letter no longer requires skill. It requires a small payment to a service that specializes in it, with the employer, the pay period, the deposit history, and the formatting all internally consistent. A leasing associate reviewing an uploaded PDF cannot reliably tell the difference, and it is not reasonable to expect one to. The operator's income verification currently depends on a twenty-three-year-old leasing associate detecting professional document fraud by eye.
Synthetic identities pass bureau matching by design. A synthetic identity combines a real Social Security number with a fabricated name and history, then is deliberately cultivated until it has a credit file. When that identity is submitted, bureau matching returns a match - because there genuinely is a file. The check performs exactly as designed and returns exactly the wrong answer.
What the decision is actually about
Not whether the current provider is bad at its job. It is competent at credit assessment and the operator has no complaint about that work.
The question is whether a verification layer built to confirm creditworthiness is the right layer to detect deception, and whether the operator is willing to spend money in a service line that currently costs it nothing in order to reduce a loss it cannot precisely measure.
What makes this hard
The miss rate is unknown. Sixty-one confirmed cases is a floor, not an estimate. Any projected benefit depends on assuming a true rate, and that assumption is MFC's, not the operator's data.
The current arrangement is free and slightly profitable. A CFO looking at this service line sees a line that costs nothing and returns a small margin. Changing it means creating an expense to reduce a loss recorded somewhere else under a different name. That is a genuinely harder internal argument than it should be, and §7 and §10 are written with that argument in mind.
Getting this wrong in the other direction is worse than the fraud. A verification tool that wrongly flags legitimate applicants denies people housing. That is a fair-housing exposure and a real harm to real applicants, and it is treated in §9 and §11 as a first-order consideration rather than a footnote.
§4 Market Insight
What the category looks like
Pass-through bundled verification. Identity and income checks attached to a screening product, usually sold per application and paid for through the application fee. Strong at credit assessment. Generally limited to bureau-based identity matching with no document analysis. This is what most operators run and most did not choose it deliberately - it arrived with screening.
Fraud-native specialists. Built specifically to detect deception rather than assess credit. The distinguishing capabilities are document forensics - examining a submitted document's underlying file structure, metadata, and rendering artifacts rather than its visual appearance - synthetic identity detection using signals bureau matching does not consider, and cross-operator consortium data that flags an identity or employer already seen at another property.
Verification-first providers. Focused on replacing document upload with direct payroll or bank connection. If income is confirmed at the source, a fabricated pay stub has nothing to fabricate against. Very strong on income, generally thinner on identity and document fraud.
What the field is moving toward
Three currents, all real.
Source-connected income verification is displacing document upload. Where an applicant's income can be confirmed through a payroll or bank connection, document review becomes unnecessary. Coverage is the limit - payroll connection works well for W-2 employees at larger employers and poorly for hourly, gig, cash, and self-employed income. In a portfolio weighted toward Class B, a meaningful share of applicants fall outside good coverage.
Document forensics is becoming standard. Analyzing the file rather than the image.
Consortium data is the newest and most contested development. Providers pooling fraud signals across operator customers, so an identity flagged at one property is visible at another. Powerful, and it raises questions about accuracy, dispute rights, and what an applicant can do about being flagged that the category has not fully answered.
A caution about the proof - read this before any vendor number
Every published catch rate in this category is unverifiable in the direction that matters.
A provider can report how many fraudulent applications it caught. No provider can report how many it missed, because a missed fraud is by definition not identified as fraud. Every "detection rate" published in this category has an unknown denominator. This is not a criticism of any particular vendor. It is a structural property of the problem.
The same limitation applies to the operator's own 61 cases and to every projection in §7. MFC will not present a catch-rate claim as if it were a miss-rate measurement, and any provider that blurs that distinction in a demonstration should be pressed on it directly.
The regulatory layer
This category sits closer to regulation than most categories in the taxonomy.
Consumer reporting. When a verification result contributes to a decision to deny an applicant, the process is subject to consumer reporting obligations - adverse action notice, disclosure of the source, and the applicant's right to dispute and correct. A fraud signal that influences a decline is not exempt from this because it is labeled fraud rather than credit.
Biometric identifiers. Several providers offer identity verification using a government ID photograph matched against a live selfie. That is biometric processing, and several states regulate collection, consent, retention, and destruction with private rights of action attached. This capability is optional at every provider MFC reviewed, and whether to enable it is a decision the operator should make deliberately rather than inherit from a default configuration.
§5 Recommended Solution
Move to the Fraud-Native Specialist as the verification layer, with source-connected income verification as the primary path and document review as fallback.
Why this candidate
It examines the document, not the picture of the document. File structure, metadata, generation artifacts, and internal consistency are analyzed rather than appearance. This directly replaces the step currently performed by a leasing associate looking at a PDF - a task no leasing associate should be expected to do.
It looks for the identity pattern the bureau check cannot see. Synthetic identities pass bureau matching because they have real credit files. The specialist evaluates how a file was built - velocity of history, thinness relative to claimed age, address and employer inconsistencies - which is where a cultivated identity differs from a real one.
Consortium data covers the operator's actual exposure pattern. The strongest signal in the operator's own experience was a regional manager noticing the same fabricated employer at three communities in three states. That recognition happened by accident, once, because one person had unusually good recall. Consortium data does that systematically. For a portfolio spread across three non-contiguous regions, this is the single most relevant capability in the set.
Income is verified at the source where possible. Payroll or bank connection as the primary path, with document review as fallback for applicants outside coverage - and the fallback runs through forensics rather than through a person's judgment.
It has the strongest verified proof in the set. Two operating references above 15,000 units were contacted directly by MFC. That does not resolve the miss-rate problem, which nothing resolves. It does mean the product works at this scale and this geography, which two of the alternatives could not demonstrate.
What this recommendation does not do
It does not change resident screening. Resident screening - credit, criminal, and eviction history - stays where it is. This is a verification-layer change, and confusing the two would make a bounded change look like a rebuild. The screening decision, the criteria, and the provider all remain unchanged.
It does not enable biometric identity verification. The specialist offers document-plus-selfie matching. MFC recommends against enabling it in the initial deployment. Document forensics and synthetic identity detection address the demonstrated exposure. Biometric matching adds a regulated data category, consent obligations, retention duties, and litigation exposure in exchange for an increment MFC cannot show this operator needs. If a documented gap emerges that only biometric verification closes, revisit it then, with counsel. See §11.
It does not make the decline decision. The specialist returns a risk assessment. A human reviews anything flagged. No applicant is denied by an automated signal without review, and that is a policy the operator sets, not a product setting. §9 and §11 explain why this matters more than any capability in the comparison.
§6 Comparative Analysis
Four candidates were evaluated.
The comparison set
| Candidate | Capability profile |
|---|---|
| Pass-Through Incumbent | Bureau-based identity matching. Applicant-uploaded income documents reviewed by leasing staff. No document forensics, no synthetic identity detection, no consortium data. Bundled with screening. Costs the operator nothing. |
| Fraud-Native Specialist | Document forensics, synthetic identity detection, cross-operator consortium data, source-connected income verification with forensic document fallback. Optional biometric matching. Strongest verified references. |
| Verification-First Entrant | Payroll-connected income verification, best-in-class at confirming income at source. Thin on identity fraud and no document forensics. Contract renews mid-cycle at a current customer, limiting reference access. |
| Bundled Alternative | Broad feature list attached to a leasing suite. Shallow on every dimension. No adverse-action workflow. |
Dimension comparison
| Dimension | Pass-Through Incumbent | Fraud-Native Specialist | Verification-First Entrant | Bundled Alternative |
|---|---|---|---|---|
| Identity - real person | Bureau match only. Confirmed | Bureau match plus synthetic identity analysis. Confirmed methodology reviewed under NDA | Bureau match only. Confirmed | Bureau match only. Confirmed |
| Synthetic identity detection | None. Passes by design. Confirmed | Present. File-construction analysis. Confirmed capability verified; effectiveness not independently measurable | None. Confirmed | Claimed, no methodology supplied. Claimed |
| Document forensics | None. Visual review by leasing staff. Confirmed | File structure, metadata, generation artifacts, internal consistency. Confirmed demonstrated on MFC-supplied test documents | Not offered - bypasses documents entirely where connection succeeds. Confirmed | Image-based checks only. Claimed |
| Source-connected income | None. Confirmed | Payroll and bank connection, forensic document fallback. Coverage ~72% of applicants at this portfolio's income mix. Estimated provider coverage model applied to operator demographics | Best in set. Coverage ~81%. Weaker fallback. Claimed provider figure | Limited. Confirmed |
| Consortium / cross-operator data | None. Confirmed | Present. Multi-market coverage including all three of this operator's regions. Confirmed coverage confirmed by region | None. Confirmed | None. Confirmed |
| Adverse action workflow | Present - inherits the screening provider's process. Confirmed | Present. Dispute and correction path documented. Confirmed reviewed by MFC | Present. Confirmed | Absent. No documented adverse action path. Confirmed disqualifying, see below |
| Biometric capability | None. Confirmed | Optional, off by default. MFC recommends leaving it off. Confirmed | None. Confirmed | Optional, on by default in standard configuration. Confirmed |
| False decline exposure | Low - the check is permissive. The failure mode is missing fraud, not flagging real applicants. Confirmed | Moderate - this is the trade. Provider reports a flag rate requiring human review on ~4.1% of applications. Claimed provider figure, unverified | Low-moderate. Failure mode is connection failure, not false accusation. Confirmed | Unknown. Provider would not supply a flag rate. Confirmed absence |
| Applicant friction | Minimal - upload a document. Confirmed | Moderate - payroll connection asks for credentials, which some applicants decline. Fallback path exists. Confirmed | Highest - connection is the primary and near-only path. Confirmed | Low. Confirmed |
| Connection to core platform | Native - already in the leasing workflow. Confirmed | Standard connector for this platform, verified in two comparable deployments. Confirmed | Standard connector exists; not verified at this platform version. Claimed | Requires leasing-suite adoption - far beyond this service line. Confirmed |
| Security and compliance | SOC 2 Type II current. Confirmed | SOC 2 Type II current. Consumer-reporting obligations documented. Confirmed | SOC 2 Type II current. Confirmed | SOC 2 Type II current. Confirmed |
| Proof at this scale | Nine years of the operator's own use - including 61 known misses. Confirmed | Two references above 15,000 units, multi-market, contacted directly by MFC. Confirmed | One reference above 15,000 units; contract renews mid-cycle and the customer declined an interview. Confirmed limitation | None found above 8,000 units. Confirmed absence |
| Cost per application | $0 net - covered by the $75 application fee. Confirmed | +$6.50 incremental = $105,300/year. Estimated provider quote, not contracted | +$4.20 = $68,040/year. Estimated | +$2.10 = $34,020/year. Estimated |
| One-time cost | None. | ~$28,000 - connector, workflow configuration, staff training. Estimated | ~$19,000. Estimated | Not quoted - requires suite adoption. |
| Exit | 30 days' notice. Confirmed | Annual term, 60 days' notice. Confirmed | Annual term, 90 days' notice. Confirmed | Bound to the leasing suite term. Confirmed |
What the comparison shows
The Bundled Alternative is eliminated, not merely outscored. It has no documented adverse action workflow and enables biometric capture by default in its standard configuration. Either alone would disqualify it. A verification product that influences housing denials without a documented dispute path is not a product this operator can responsibly deploy, regardless of price. It was the cheapest option in the set and price did not save it.
The Verification-First Entrant is genuinely strong at one thing and does not solve this operator's problem. Its income verification is the best in the set - 81% coverage against the Specialist's 72%. But the operator's 61 confirmed cases were not primarily income overstatements. They involved fabricated documents and identities that passed bureau matching, and the Entrant offers no document forensics, no synthetic identity detection, and no consortium data. It would close the smaller half of the gap and leave the larger half open. Its reference position is also weaker: the single at-scale customer declined an interview, so MFC could not verify its claims independently.
The Pass-Through Incumbent is a real option and it has one strong argument. It is free, it is already in the workflow, it creates no applicant friction, and it does not risk denying housing to a legitimate applicant on a false signal. An operator that weighs the false-decline risk heavily and the fraud loss lightly could rationally keep it. That case is not absurd and this document does not pretend otherwise.
It fails on the specific thing that is happening to this operator. Sixty-one confirmed fraudulent move-ins, zero pre-lease detections, ~$487,000 in associated loss, and no mechanism that could produce a different outcome next year. The incumbent is not underperforming its design. Its design does not address the threat.
The Fraud-Native Specialist wins on capability, on verified proof, and on regional fit - and it is the most expensive option in the set. §7 tests whether that trade holds.
§7 Financial Impact
The direction of the delta
This recommendation increases cost. Today this service line nets zero and contributes a small surplus. There is no version of this change that is cheaper.
| Line | Amount | Basis |
|---|---|---|
| Current net operator cost | $0 | Confirmed |
| Specialist, incremental at $6.50 × 16,200 applications | $105,300/year | Estimated - provider quote, not contracted |
| Implementation - connector, configuration, training | ~$28,000 one time | Estimated |
| Projected annual delta, year one | +$105,300 | Delta Data Confidence: Estimated - vendor quote, not contracted |
| Year one total | ~$133,300 |
Two ways to fund it, and MFC's recommendation
Option A - absorb it. $105,300 a year against an operating budget, roughly $5.40 per unit per year. Application fee unchanged at $75.
Option B - pass it to the applicant. Raise the application fee from $75 to $85. Fully funds the change with margin. But a $10 increase is visible at exactly the moment a prospect is deciding whether to apply, and the operator has no measurement of application-fee elasticity. A conversion loss of even 1.5% across 16,200 applications would cost more in lost leases than the $105,300 it saves.
MFC recommends Option A. The fee increase looks free and is not. It moves a measurable cost into an unmeasured one, and the operator has no data on how its applicants respond to fee changes. If the operator wants Option B, test it in one region for two quarters against a control before applying it portfolio-wide - and that test costs more to run properly than the difference is worth.
The return, and the honest limit on it
Confirmed: 61 fraudulent applications identified after move-in, ~$487,000 in associated loss, ~$298,000 of it written off as bad debt.
What cannot be confirmed: how many were missed entirely. Zero pre-lease fraud declines were recorded, so no baseline detection rate exists.
MFC's assumption, stated plainly. MFC models that the Specialist would identify 45-70% of fraudulent applications before lease signing. The range comes from the two contacted references and from the capability gap between bureau matching and document forensics. It has not been measured at this operator and it rests on the 61 confirmed cases as the population - which is a floor, not a total.
| Scenario | Pre-lease detections | Modeled loss avoided | Net of $105,300 |
|---|---|---|---|
| Low - 45% of confirmed cases | 27 | ~$216,000 | +$110,700 |
| Mid - 58% | 35 | ~$279,000 | +$173,700 |
| High - 70% | 43 | ~$343,000 | +$237,700 |
Even the low case clears the cost by roughly $110,700, and every case here uses 61 as the population. If the true rate is higher than 61 - and the absence of any pre-lease detection mechanism makes that likely rather than possible - the return improves in every scenario. This is the strongest financial case of the three documents, and it is strong specifically because the downside case still works.
What is deliberately excluded
- Leasing associate time recovered from document review
- Reduced eviction and collections volume - partly captured in Document 2 and not counted twice here
- Deterrence effects
- Any benefit from the fraud that is currently undetected - the largest likely benefit, excluded because it cannot be sized
Confidence - cost side
§8 Strategic Value
The operator stops depending on individual judgment for a technical task. Today, whether a fabricated pay stub is caught depends on which leasing associate opens it and how carefully they look. That is not a fair thing to ask of the role and it produces inconsistent outcomes across 76 communities. Moving detection into a system that examines file structure replaces personal vigilance with a uniform standard - and it does so in a decision that affects whether someone gets housing, where consistency is a legal as well as an operational virtue.
Regional spread stops being a blind spot. The operator's most instructive fraud discovery came from one regional manager recognizing a repeated employer across three states. Nothing in the operator's systems would have surfaced that, and it will not happen again by luck. Consortium data makes a three-region portfolio an advantage rather than three separate blind spots.
It closes a gap institutional owners will eventually ask about. Application fraud is now a standing topic in owner diligence. An operator with 29 fee-managed communities that can describe a documented, source-connected verification process is answering that question. One that says its leasing associates review uploaded pay stubs is answering it badly.
It reduces pressure on the recommendation in Document 2. Some portion of the losses that the income disruption program is designed to catch after the fact originate in applicants who should never have been approved. Verification works at the front of that funnel and income-disruption protection works at the back. The front is cheaper. This recommendation should be sequenced ahead of the 28A deployment for exactly that reason - see §9.
Tied to stated goals. Consistent cross-region performance requires a uniform standard for a decision currently made by individual judgment. Fee-managed growth requires a defensible answer to a question owners are asking.
§9 Risks & Considerations
The risk that outranks the fraud
False declines deny housing to real people.
The incumbent's failure mode is permissive: it misses fraud. The Specialist's failure mode is restrictive: it can flag a legitimate applicant. Those two failures are not morally equivalent and should not be weighed as though they were. A missed fraud costs the operator money. A false decline costs a real applicant a home they qualified for.
The provider reports a flag rate of about 4.1% - roughly 664 applications a year requiring human review. Most will be legitimate applicants with unusual but genuine circumstances: a recently arrived immigrant with a thin credit file, someone whose income is cash or gig-based, a young applicant with no history, someone recovering from identity theft. These populations correlate with protected characteristics, which means a flag rate that is not carefully managed can produce a disparate impact even with no discriminatory intent anywhere in the process.
What this requires, without exception:
- No automated decline. Every flag is reviewed by a person before any adverse decision. This is a policy the operator sets and enforces, not a product configuration.
- Trained reviewers. A flag is a signal to look harder, not a verdict. Reviewers must understand what the signal means and what it does not.
- Flag and decline rates monitored by protected class from day one, not audited after a complaint. If the rate diverges, the configuration is wrong and the operator needs to know before a regulator tells them.
- A documented, communicated dispute path. See §11.
MFC's position: if the operator will not commit to human review of every flag, do not make this change. The incumbent's permissiveness is preferable to an automated system that declines applicants without review. That is a real recommendation, not a formality.
Other risks
The 4.1% flag rate is the provider's figure and it drives everything. If the real rate is 8%, that is roughly 1,300 reviews a year - a material staff burden not modeled in §7, and a larger fair-housing surface. Confirming it independently is a Critical item.
Applicant friction at the payroll connection step. Some applicants will decline to connect payroll credentials, for entirely reasonable privacy reasons. The document fallback exists, but a clumsy connection request at the top of the funnel can cost applications. Reasonable declining must not itself become a risk signal.
Staff will need to unlearn a habit. Leasing associates have reviewed documents by eye for nine years. Some will keep doing it and override the system; some will stop looking entirely and defer to it. Both are failure modes and both are training problems.
Consortium data creates an accuracy dependency outside the operator's control. An applicant flagged because of a signal contributed by another operator is being affected by data this operator cannot inspect or correct. The dispute path has to reach the consortium record, not just the operator's file. Confirm this contractually.
Biometric capability exists and is off. It should stay off, and the contract should specify that enabling it requires the operator's affirmative action rather than arriving in a product update. See §11.
Cascade - three service lines move
- Resident Screening & Risk Decisioning. Screening does not change, but the sequence does - verification now precedes and can pre-empt screening. Application criteria and the decision workflow both need updating. Scope this before deployment, not during.
- Digital Leasing Execution & Workflow. The application flow changes at the income step. Test the applicant experience end to end before rollout.
- income disruption (Document 2). Better front-end verification reduces the population the 28A program is designed to protect. Sequence 16B first - the 28A baseline should be captured after verification changes, or the twelve-month result will be confounded by two changes at once.
Maintenance management is unaffected.
What MFC could not verify
The 4.1% flag rate. The synthetic identity detection methodology beyond what was disclosed under NDA. Actual detection effectiveness at this operator's applicant mix. The Entrant's claims, because its only at-scale customer declined an interview. And - structurally, for every provider in this category - the miss rate.
§10 Final Recommendation
Move to the Fraud-Native Specialist as the verification layer for all 76 communities, phased by region, with biometric matching disabled and mandatory human review of every flagged application. Confidence: 79%.
Sixty-one fraudulent applications reached move-in last year and not one was caught before a lease was signed, because nothing in the current process could have caught one. The verification in place is competent at assessing credit and structurally blind to fabricated documents and synthetic identities. Those are the two things actually happening.
The change costs $105,300 a year and about $28,000 once, against roughly $487,000 in associated loss from the cases the operator knows about. Even assuming the Specialist catches only 45% of them, the change clears its cost by roughly $110,700 - and 61 is a floor, not a total.
The recommendation is conditional on how it is operated, not on whether it works. A fraud tool deployed without human review, without monitoring, and without a dispute path would do more harm than the fraud it prevents.
Conditions
- Human review of every flagged application, without exception. No automated decline. If the operator will not commit to this in writing, MFC's recommendation is to keep the incumbent.
- Biometric matching stays disabled, with contract language requiring the operator's affirmative action to enable it.
- Flag and decline rates monitored by protected class from the first week, with a defined threshold that triggers reconfiguration.
- The dispute path reaches consortium records, confirmed contractually before signing.
How to act on this
Weeks 1-4 - Test it against reality before buying it. Ask the provider to run its detection against a sample of 500 already-approved applications from the last twelve months, including all 61 known fraud cases. This is the single most valuable thing available: it shows how many of the known cases it would have caught, and - from the flags on the other 439 - an indication of how many were missed. Most providers will do this as part of a sales process. If the provider will not run a retrospective, that is itself informative.
Weeks 2-6 - Policy before procurement. Draft the human-review policy, the reviewer training standard, the monitoring thresholds, and the adverse action language. These are the conditions of the recommendation and they should exist before a contract, not after. Legal review confirms the dispute path reaches consortium records.
Weeks 4-8 - Contract and configuration. Confirm the flag rate against the retrospective rather than accepting the 4.1% figure. Confirm biometric matching is disabled with affirmative-action language. Verify the connector at the platform's current version.
Weeks 6-10 - Scope the cascade. Update resident screening application criteria and decision workflow. Test the digital leasing applicant experience end to end, including the payroll connection step and the document fallback, before any applicant sees it.
Weeks 10-14 - Train, then deploy to one region. Train reviewers on what a flag means and does not mean. Deploy to the Mountain West first - 15 communities, the smallest region, enough volume to be meaningful and small enough to correct. Not the Midwest: it is carrying the Document 2 deployment.
Weeks 14-26 - Measure before expanding. Track the actual flag rate, review time, decline rate by protected class, and applicant drop-off at the connection step. Expand only when the flag rate and the decline distribution are both within expectation. If either is off, reconfigure before adding regions.
Months 7-9 - Complete rollout. Texas, then Midwest. Sequence the Midwest after the Document 2 program has captured its baseline, so the two changes do not confound each other.
Ongoing. Quarterly review of flag and decline rates by protected class. Annual review of consortium accuracy and dispute volume. 60-day exit notice on an annual term - calendar it.
§11 Mandatory Flags
This product influences decisions to deny housing, which places it inside consumer reporting obligations.
When a verification result contributes to a decline, the applicant has rights that do not depend on how the operator labels the signal. Calling it fraud detection rather than credit assessment does not remove it from scope.
- Adverse action notice issued whenever a verification result contributes to a decline, identifying the source and providing the applicant's rights.
- A dispute and correction path the applicant can actually use - including where the flag originated in consortium data contributed by another operator. Confirm contractually that a dispute reaches the consortium record, not only the operator's file.
- No automated decline. Human review of every flag, without exception. This is Condition 1 of the recommendation and it is not negotiable.
- Flag and decline rates monitored by protected class from the first week. The populations most likely to trip a fraud signal - thin credit files, non-traditional income, recent arrivals, identity-theft victims - correlate with protected characteristics. A disparate outcome can arise with no discriminatory intent at any point.
- Documented reviewer training on what a flag means, what it does not mean, and what the reviewer is authorized to do.
- Retention and destruction schedule for verification data and flagged-application records.
MFC is recommending a product that will cause some legitimate applicants to be flagged. At the provider's stated rate, roughly 664 applications a year will require review, and most of those applicants will be legitimate. The operator is accepting responsibility for how those people are treated. That responsibility is the actual cost of this recommendation, and it is larger than the $105,300.
The Specialist offers identity verification by matching a government ID photograph against a live selfie. This is biometric processing.
Several states regulate the collection, consent, retention, and destruction of biometric identifiers, with private rights of action and statutory damages per violation. This operator holds communities in three regions with different state regimes, and requirements differ across them.
MFC's recommendation: leave it disabled. Document forensics, synthetic identity detection, and consortium data address the demonstrated exposure. Biometric matching adds a regulated data category, a consent regime, a destruction obligation, and litigation exposure for an increment MFC cannot demonstrate this operator needs.
- Contract language stating the capability is disabled and requires the operator's affirmative action to enable - it must not arrive in a product update or a default configuration change.
- If it is ever enabled, counsel reviews consent language, retention, and destruction for each state in the portfolio before it is switched on in any of them.
- Confirm the provider does not perform biometric processing anywhere in its default pipeline. Ask directly and get it in writing.
Note: the Bundled Alternative enables this by default in its standard configuration. That was one of two reasons it was eliminated in §6.
Raised separately from the consumer-reporting flag because it survives full compliance with it. An operator can issue every required notice, provide every dispute path, and still produce a discriminatory outcome if the flag rate falls unevenly across protected classes.
monitoring from week one, not an annual audit; a defined divergence threshold that triggers reconfiguration rather than review; and documented evidence that the operator looked, found what it found, and acted. Requirement 4 above is the mechanism; this flag is why it exists.
§12 Action Items & Next Steps
Confidence gaps, tracked
| # | Priority | Action | Data needed | From | Owner | Due |
|---|---|---|---|---|---|---|
| 1 | Critical | Run the retrospective | Provider detection run against 500 already-approved applications including all 61 known fraud cases; report catches, misses, and flags on the remainder | Provider, pre-contract | VP Operations | 2026-09-30 |
| 2 | Critical | Commit human review in writing | Written policy: no automated decline, every flag reviewed by a trained person, reviewer authority defined | Internal legal and operations | VP Operations | 2026-09-30 |
| 3 | Critical | Build the monitoring before deployment | Flag and decline rate reporting by protected class, with a defined divergence threshold and a named response | Internal legal and operations | CFO | 2026-10-31 |
| 4 | Critical | Confirm the dispute path reaches consortium records | Contract language confirming an applicant dispute corrects the consortium record, not only the operator's file | Provider, before signing | CFO | 2026-10-31 |
| 5 | Critical | Lock biometric to off | Contract language: capability disabled, affirmative operator action required to enable, no biometric processing in the default pipeline | Provider, before signing | CFO | 2026-10-31 |
| 6 | High | Verify the flag rate independently | Actual observed flag rate - from the retrospective and from at least one reference operator, not the provider's marketing figure | Provider and references | VP Operations | 2026-10-15 |
| 7 | High | Contract the price | Executed per-application pricing to replace the $6.50 estimate | Provider | CFO | 2026-11-15 |
| 8 | High | Scope the 16A cascade | Updated application criteria and decision workflow reflecting verification preceding screening | Internal | VP Operations | 2026-11-15 |
| 9 | High | Test the applicant experience | End-to-end walkthrough of the 13B application flow including payroll connection and document fallback | Director of IT | Director of IT | 2026-11-30 |
| 10 | Medium | Model the staff-review burden | Measured review time per flagged application from the first-region deployment, replacing the current assumption of zero | Internal, during phase one | VP Operations | 2027-03-31 |
| 11 | Medium | Set the reviewer training standard | Written curriculum on what a flag means and does not mean, with completion tracked | VP Operations | VP Operations | 2026-12-15 |
| 12 | Medium | Verify the connector | Confirmation at the platform's current version, in a test environment before production | Provider and Director of IT | Director of IT | 2026-11-30 |
| 13 | Low | Decide the fee question | If Option B is still wanted, a controlled single-region elasticity test - otherwise close this item | CFO | 2027-01-31 |
Item 1 is the highest-value action in this document. It costs the operator nothing, it happens before any commitment, and it is the only available way to estimate the miss rate - the number that constrains every projection in §7. It also tests the provider: one that will not run a retrospective against real historical applications is telling the operator something worth hearing.
Operational next steps
| # | Action | Owner | Due |
|---|---|---|---|
| 14 | Record the 61 known cases in a form the retrospective can be scored against | VP Operations | 2026-09-15 |
| 15 | Add a fraud-decline reason to the application workflow - needed regardless of this decision | VP Operations | 2026-09-15 |
| 16 | Brief regional managers and the centralized leasing pod on what is changing and why | VP Operations | 2026-12-15 |
| 17 | Deploy to Mountain West only; hold Texas and Midwest | VP Operations | 2027-01-31 |
| 18 | Sequence the Midwest rollout after the Document 2 baseline is captured | VP Operations | 2027-03-31 |
| 19 | Calendar quarterly flag and decline review by protected class | CFO | 2026-12-15 |
| 20 | Calendar the 60-day exit notice deadline against the annual term | CFO | 2027-01-31 |
Item 15 deserves attention on its own. Adding a fraud-decline reason to the application workflow costs nothing, requires no vendor, and can be done next week. Without it the operator will still be unable to measure its own detection a year from now - with or without a new provider.