Fraud Analysis in TalentWall
How Crosschq ApplicantX checks candidates for integrity risks, and how to read the results in TalentWall and your ATS.
Note: This article covers Fraud Analysis for TalentWall — which evaluates candidates from your ATS. If you're looking for fraud detection in reference checks, see Understanding Fraud Risk in Crosschq 360. For fraud detection in AI interviews, see Fraud Analysis in Crosschq Interview.
- Overview
- How to access Fraud Analysis
- Reading the risk score
- Signal groups
- Viewing results in your ATS
- How to act on results
- How this differs from other Crosschq fraud detection
Overview
When a candidate applies through your ATS, Crosschq ApplicantX automatically analyzes their application within 5 minutes of submission—or immediately via webhook where supported—every 5 minutes for signals that may indicate identity fraud, fabricated credentials, or suspicious application behavior. The analysis runs in the background once the connector is active — no action is required from your team to trigger it.
If fraudulent indicators are found, the application is flagged with a detailed breakdown of the identified risks, ranked from most to least critical. If no fraud is detected, a transparent summary of the checks performed is provided.
Results appear in the Fraud Analysis tab of the candidate card in TalentWall, and are also written back to the candidate's profile in your ATS.
Fraud Analysis is designed to give your team an early signal to investigate further — it does not make a hiring decision automatically.
To enable Fraud Analysis, the ATS connector must be active and fraud analysis must be configured in Account Settings. See Greenhouse Connector for ApplicantX or Workday Connector for ApplicantX for setup instructions.
How to access Fraud Analysis
- Navigate to the Wall in TalentWall and open the candidate card for the candidate you want to review.
- Select the Fraud Analysis tab.
[Screenshot to be added]
The Fraud Analysis tab only appears when fraud analysis has been enabled for the job the candidate applied to. If the tab is missing, confirm that fraud analysis is configured for that job in Account Settings > Customize > Fraud Analysis.
The overall Fraud Score is also visible in the right-hand panel of the candidate card, with a color-coded risk level indicator.
[Screenshot to be added]
Reading the risk score
The Fraud Score is a numeric value displayed alongside a color-coded gradient bar ranging from Low risk on the left to High risk on the right.
| Risk level | What it means |
|---|---|
| Low | Few or no signals detected. The application does not present notable integrity concerns. |
| Medium | One or more signals detected that warrant a closer look, but are not conclusive on their own. |
| High | Multiple or significant signals detected. Review the signal groups and consider following up with the candidate before advancing them. |
Important: A high risk score does not confirm that fraud occurred. It means the analysis produced patterns worth reviewing. Always look at the full picture — application, resume, and other information — before making a decision.
Signal groups
Below the risk score, the Fraud Analysis tab shows signal groups — the categories of signals Crosschq evaluates for each candidate. Each group is evaluated independently and ranked by severity. A group with insufficient data is reported as Could not be processed and does not count toward the overall risk level.
| Signal group | What it evaluates |
|---|---|
| Resume | Inconsistencies across work history, education, and career progression; claims that do not appear on LinkedIn; and whether the resume text reads as AI-generated. Needs the candidate's resume. |
| Email Address | Whether the email address looks disposable, spoofable, or otherwise irregular — a throwaway domain, a suspicious username, missing mail records, or an address only recently seen. Needs the candidate's email address. |
| Phone Number | The kind of line behind the number — non-fixed VoIP, voicemail-only, toll-free, or an invalid format. Needs the candidate's phone number. |
| Device Fingerprint |
Whether the application arrived over Tor, a VPN, a web proxy, a data-center network, or in private browsing. Needs the candidate's IP address or device fingerprint data from the ATS. |
| Digital Presence | The candidate's LinkedIn profile — follower counts, and whether a profile could be found at all. Needs a LinkedIn profile Crosschq can identify from the resume or the candidate's identity information. |
| Identity Consistency | Whether names, email addresses, phone numbers, and locations agree across the sources Crosschq gathered, and whether the location falls in a sanctioned country. Needs identity details from more than one source to compare. |
| Application Behavior |
Signs of automated or high-volume applying — application velocity, suspiciously fast submissions, data-center networks. Needs application data from your ATS. |
Viewing results in your ATS
Fraud analysis results are also written back to the candidate's profile in your ATS automatically.
Greenhouse
Results appear in two places on the candidate's application profile:
- Documents — a PDF fraud report (
crosschq_fraud_report.pdf) is automatically attached to the candidate's profile. If configuring in Account Settings. - Application Custom Fields — individual fraud signals and the overall score are written to custom fields, including Crosschq Fraud Score, Crosschq Fraud Risk Level, Crosschq Fraud Report URL, Crosschq Fraud Feedback URL, and individual signal fields (Crosschq Fraud Signal 01, 02…).
Workday
Results appear in the Fraud Signals custom object on the Job Application, under the Additional Data tab. The following fields are populated:
| Field | Description |
|---|---|
| Report URL | A direct link to the full fraud report. |
| Risk Level | Low, Medium, or High. |
| Score | The numeric overall fraud score. |
| Signal 01 – Signal 10 | Individual signal findings, ranked from most to least critical. When no fraud is detected, these fields summarize the modules analyzed and confirm no fraud was found. |
| Fraud Feedback URL | A link to submit feedback if you believe a finding is inaccurate. |
How to act on results
- Low risk: No action required. Continue your normal review.
- Medium risk, single group flagged: Review the signal group description and the finding shown. Many medium signals have benign explanations — a VoIP number, a recently created email address, or a resume written with AI assistance. Use your judgment alongside the rest of the application.
- High risk or multiple groups flagged: Consider reaching out to the candidate to verify their identity through another channel before advancing them in the process.
- A group shows "Could not be processed": The data required to evaluate that group was not available — typically because the ATS did not provide the relevant field. This does not affect the overall score.
- A finding looks wrong: Use the Fraud Feedback URL available in your ATS to submit feedback. Feedback does not change the candidate's current result — contact support@crosschq.com if the finding needs to be reviewed directly.
How this differs from other Crosschq fraud detection
| TalentWall (ApplicantX) | Crosschq Interview | Crosschq 360 | |
|---|---|---|---|
| What it analyzes | The candidate's ATS application — resume, contact details, device, and behavior | The AI Agent interview session — image and answer text | Reference check responses — identity, contact details, shared devices |
| Who it flags | The candidate (are their credentials and identity authentic?) | The candidate (was the image synthetic, and did the answers read as AI-written?) | References and candidates (are the references real?) |
| Where it appears | Fraud Analysis tab in the TalentWall candidate card, and in the candidate's ATS profile | Fraud Analysis tab in the Interview Report | Response Analysis section of the Crosschq 360 report |