Fraud Analysis in Crosschq Interview
How Crosschq Interview detects integrity risks during AI-conducted interview sessions, and how to read the results in the Interview Report.
Note: This article covers Fraud Analysis for Crosschq Interview — which evaluates AI Agent interview sessions. If you're looking for fraud detection in reference checks, see Understanding Fraud Risk in Crosschq 360.
- Overview
- How to access Fraud Analysis
- Reading the risk score
- Signal groups
- How to act on results
- How this differs from Crosschq 360 fraud detection
Overview
When a candidate completes an AI Agent interview, Crosschq automatically analyzes the session for signals that may indicate the person who took the interview was not the actual candidate, or that outside assistance was used. The analysis happens after the interview finishes, and the risk level it produces also reflects other information about the candidate. The results appear on the Fraud Analysis tab of the Interview Report.
Fraud Analysis is designed to give your team an early signal to investigate further — it does not make a hiring decision automatically.

How to access Fraud Analysis
Open any completed AI Agent interview from Interview Management and select the Fraud Analysis tab. Results appear once the interview has finished processing. The tab only appears when your organization has fraud detection enabled in your organization settings.

Reading the risk score
At the top of the Fraud Analysis tab, a gradient bar shows the overall risk level for the candidate, ranging from low risk on the left to high risk on the right.
| Risk level | What it means |
|---|---|
| Low | Few or no signals detected. The session proceeded without notable integrity concerns. |
| Medium | One or more signals detected that warrant a closer look, but are not conclusive on their own. |
| High | Multiple or significant signals detected. Review the signal groups and consider following up with the candidate before advancing them. |
Important: A high risk score does not confirm that fraud occurred. It means the analysis produced patterns worth reviewing. Always look at the full picture — responses, scorecard, and other information — before making a decision.
Signal groups
Below the risk bar, the tab shows signal groups — the categories of signals Crosschq evaluates, named the same way in the report. The first covers the interview itself; the rest cover the candidate's application, and all of them feed the same risk level. Each group needs its own data — a group with nothing to work with is reported as unevaluated and does not count toward the level.
| Signal group | What it evaluates |
|---|---|
| Interview Integrity & Deepfake | Two things, each reported at high, medium, or low confidence: whether the interview shows signs of being synthetic or manipulated (Deepfake Detected), and whether the candidate's answers read as AI-written rather than spoken naturally (AI-Generated Answers Detected). Both feed one combined rating for this group. |
| Email Address | Whether the email address looks disposable, spoofable, or otherwise irregular — a throwaway domain, a suspicious username, missing mail records, an address only recently seen. Needs the candidate's email address. |
| Phone Number | The kind of line behind the number — non-fixed VoIP, voicemail-only, toll-free, or an invalid format. Needs the candidate's phone number. |
| Resume | Inconsistencies across work history, education, and career progression; claims that do not appear on LinkedIn; and whether the resume text reads as AI-generated. Needs the candidate's resume. |
| Device Fingerprint | Whether the application arrived over Tor, a VPN, a web proxy, a data-center network, or in private browsing. Needs the candidate's IP address or device fingerprint data. |
| Digital Presence | The candidate's LinkedIn profile — follower counts, and whether a profile could be found at all. Needs a LinkedIn profile Crosschq can identify from the resume or the candidate's identity information. |
| Identity Consistency | Whether names, email addresses, phone numbers, and locations agree across the sources Crosschq gathered, and whether the location falls in a sanctioned country. Needs identity details from more than one source to compare. |
| Application Behavior | Signs of automated or high-volume applying — application velocity, suspiciously fast submissions, data-center networks. Needs application data from your ATS. |
How to act on results
- Low risk: No action required. Continue your normal review — but confirm the interview section actually reports a result.
- Medium risk, single group flagged: Review the signal group description. Many medium signals have benign explanations — poor image quality or unusual lighting for the image, and rehearsed or formal phrasing for the answers. Use your judgment alongside the rest of the report.
- High risk or multiple groups flagged: Consider reaching out to the candidate to verify their identity through another channel before advancing them in the process.
How this differs from Crosschq 360 fraud detection
| Crosschq Interview | Crosschq 360 | |
|---|---|---|
| What it analyzes | One still image from the interview, plus the text of the candidate's answers | Reference check responses — identity, contact details, shared devices |
| Who it flags | The candidate (was the image synthetic, and did the answers read as AI-written?) | References and candidates (are the references real?) |
| Where it appears | Fraud Analysis tab in the Interview Report | Response Analysis section of the Crosschq 360 report |