- Landlord News
- AI tenant fraud is exposing weak ID checks — three controls landlords and agents should add in the next 30 days
AI tenant fraud is exposing weak ID checks — three controls landlords and agents should add in the next 30 days
AI-enabled tenant fraud is increasing the pressure on older verification processes. For London landlords and letting agents, the risk is not only rent loss but also failures in AML controls, Right to Rent checks, record-keeping and data protection. The most practical response is to strengthen applicant verification, escalate higher-risk cases and keep a clear audit trail of decisions.
Legacy ID checks are becoming a weak point. The immediate change is not a new law, but a sharper risk: fraud specialists cited by Landlord Today say criminals are using AI to get past older document-only verification systems, while many firms still rely on emailed scans, inconsistent manual checks or one-off onboarding reviews. For London landlords and agents, that raises exposure to tenancy fraud, rent default, unlawful subletting and, for regulated firms, anti-money laundering failures.
Existing legal duties still apply
What is confirmed is that current obligations have not fallen away just because the fraud method has changed. If your business is within scope of the UK anti-money laundering regime, customer due diligence requirements still apply. Right to Rent checks also still apply in England where required, and suspicious activity should be reported to the National Crime Agency by submitting a Suspicious Activity Report if the legal threshold is met. The warning here is operational: if your verification process has not kept pace with AI-enabled fraud, you may be relying on a control that no longer works as intended.
Why one-stage ID checks are no longer enough
The biggest mistake is treating ID as a one-off admin task. A passport image and a bank statement sent by email may not be enough if the applicant is using a synthetic identity, a manipulated selfie or a deepfake-style video interaction. Where risk indicators are present — such as large upfront rent, unexplained third-party payments, cross-border funds, inconsistent documents or an applicant who repeatedly avoids meeting in person — enhanced due diligence is the safer response.
That means slowing the file down, asking more questions and recording why the case was escalated.
The financial exposure can be significant
For London operators, the downside can be steep even before any regulatory issue arises. A fraudulent tenant in a £2,200 to £3,000 per month let can create five-figure losses once arrears, legal costs, void time and repair bills are added together. In higher-rent boroughs such as Westminster, Kensington and Chelsea, Camden and Islington, the exposure can rise quickly if several months' occupation is obtained through false credentials. In HMOs and rent-to-rent arrangements, one bad applicant can also trigger wider licensing, overcrowding or anti-social behaviour problems.
Add multi-factor verification for new applicants
The most useful process change is multi-factor verification. For new applicants, property teams should move to at least document checks plus biometric matching plus a live interaction step, whether that is a live video check or an in-person meeting for higher-risk cases. Self-submitted scans on their own are no longer a strong control.
If you use a third-party provider, look for features such as liveness testing, biometric matching and watchlist screening rather than basic document capture alone. The source reporting does not name specific suppliers, so firms should assess products against their own risk profile rather than buying on price alone.
Tighten controls around payments
Payments need attention as well. One clear red flag is money coming from someone who is not the named applicant, especially where the explanation is vague or changes during the process. Another is a request for rent or deposits to be paid into a personal account rather than a named business client account or secure payment platform.
Property teams should require funds to come from a verified account in the tenant's name unless there is a documented and approved reason otherwise. If third-party payments are accepted, record the rationale and apply enhanced checks to the payer.
Monitor for problems after move-in
Fraud does not always stop at move-in. A point-in-time check on day one will not help if the occupier changes, the payment pattern shifts or the named tenant disappears after the tenancy starts.
Set clear triggers for escalation, including:
- repeated failed payments from different accounts
- sudden requests to change contact details
- inconsistent signatures
- unusual urgency
- new occupants not disclosed at application stage
For portfolio operators, these triggers should be built into arrears and renewals workflows rather than left to individual negotiators.
Check the data protection position before adding new ID tech
There is also a data protection issue if you expand digital verification. If you use biometric or digital ID tools, you still need a lawful basis for processing personal data and, where the risk justifies it, a data protection impact assessment. The Information Commissioner's Office expects firms to understand what personal data their suppliers collect, where it is stored and how long it is retained.
Do not add a new ID app without checking contracts, privacy notices and deletion processes.
Staff training is part of the control framework
Training is now a control, not a nice-to-have. Staff should be briefed on AI-enabled impersonation, voice cloning, fake urgency and social engineering, with a clear escalation route for suspicious cases. A junior lettings negotiator under pressure to push a deal through is often the point a fraudster targets first.
Give teams a script for pausing an application, requesting further evidence and referring the case to a manager or compliance lead. That helps reduce inconsistent decisions across branches and portfolios.
Three actions to complete in the next 30 days
- Update your AML risk assessment and written policies to refer explicitly to AI-generated and synthetic identity risks, then review due diligence on any digital ID supplier already in use.
- Audit 10 recent applicant files from the last 90 days and test whether each one would stand up if challenged: proof of identity, proof of funds, payment source, Right to Rent evidence where applicable, and a clear approval record.
- Put three controls in place for all new applicants: mandatory multi-factor ID checks, enhanced due diligence for large upfront payments or third-party funders, and a rule that rent and deposits must go only to verified business accounts.
If fraud is suspected, preserve the file, take legal or compliance advice, submit a SAR to the NCA where required and report the matter to Action Fraud.
This article is general information, not legal advice.
This article is general information, not legal or financial advice. Rules can change and may apply differently to each property. Check the dated source and seek appropriate professional advice before acting.
Need help reviewing your property?
Arrange a conversation with our team about your property, tenancy and the local requirements that may apply.
Request a compliance conversationStay informed
Get compliance alerts delivered weekly
Receive selected landlord updates and links to source material.
