Lend to borrowers, not fraud rings.
Some bad loans were fraud from day one. Sieve spots reused IDs at application and holds the cash-out.
For mobile lenders, BNPL providers and SME credit platforms in Kenya and Nigeria.
Four ways the money goes missing.
Each looks like ordinary activity. Sieve scores every event in context, before the money moves.
- 01
Recycled identities
One national ID, NIN, BVN or phone behind several “different” borrowers.
Caught by Identity shared across customers, known fraud link
- 02
Loan stacking
Many applicants on one phone, all borrowing before any repayment is due.
Caught by Device shared by several customers, scripted activity
- 03
Disburse-and-vanish
The loan lands and leaves within minutes, to an account added that morning.
Caught by Rapid cash-out after a deposit, payout to a new account
- 04
First-loan fraud
A new account changes its details, takes a first loan and disappears.
Caught by New-account cash-out pattern
Minutes of activity. One decision.
A story from the Digital lending demo, run through the same engine as your events. Each reason is written for the analyst who acts on it.
- Day 1Five borrowers sign up on one phone with one national IDIdentity shared by 5 customers
- +20 minEach receives a KES 15,000 loanDisbursement
- +26 minEach adds a new M-Pesa number
- +30 minEach asks to withdraw KES 14,900 to the new number
- DecisionBlocked
- National ID used by 5 customers
- Device shared by 5 customers
- Leaving 6 minutes after a KES 15,000 deposit
All five payouts blocked: KES 74,500 kept from write-off. Once an analyst confirms it, threat memory catches the next borrower using that ID or phone.
Choose “Digital lending” and these start enforcing.
Plain-English rules you can adjust, joined into fraud patterns. Everything else runs in Watch, scoring without acting, until you trust it.
- Identity shared across customers
- Device shared by several customers
- New account moving money out
- Rapid cash-out after a deposit
- Details changed right after signup
- New-account cash-out
- Scripted activity
Send these events. One endpoint.
customer.createdNational ID or BVN, phone and device, so reuse shows at application.transactionDisbursements (direction in) and repayments (direction out).payout.requestedWithdrawals after disbursement, with the destination.
// The loan lands… await sieve.events.create({ type: 'transaction', customer_id: 'bor_2231', direction: 'in', amount: 15000, method: 'mpesa', status: 'success', counterparty: { id: 'loan_disbursement' }, }) // …and Sieve decides before it can leave. const d = await sieve.events.create({ type: 'payout.requested', customer_id: 'bor_2231', amount: 14900, destination: { type: 'mpesa', account: '254733000111' }, })
What your regulator will ask, answered.
Sieve supports your obligations. It doesn’t replace your compliance team.
- CBK Digital Credit Providers Regulations (Kenya)
- Every flag has plain-English reasons you can show a borrower or the regulator.
- Kenya Data Protection Act (ODPC) and Nigeria Data Protection Act 2023 (NDPC)
- Spot a reused national ID, NIN or BVN without ever exposing it.