For years, banks have been building better systems to detect fraud once an account becomes active.
Transaction monitoring has become smarter. Fraud registries have become richer. RBI’s MuleHunter.AI has made it faster to spot mule accounts once they start transacting.
But money mules expose a gap earlier in the journey.
A mule account can look completely genuine during onboarding. Aadhaar checks out. PAN checks out. The face matches. KYC is complete. It’s only after the account is opened and money starts moving that the risk becomes visible.
So, what if banks could spot that risk before the first transaction?
That’s the gap Mule Sentinel is built to address.
That raises a simple question: can banks identify a mule before the account is opened?
At GFF’26, Cashfree Payments is launching Mule Sentinel, an onboarding risk intelligence engine built to answer exactly that question. It helps banks assess risk at the point of onboarding, before the first transaction, when they still have the opportunity to stop a mule account at the gate.
The onboarding problem no one is solving
Every account starts the same way.
A customer submits their Aadhaar and PAN, completes face verification, goes through Video KYC, and waits for the account to be opened. If every check passes, the onboarding journey moves forward.
The problem is that these checks tell a bank who the customer is, but not what they intend to do with the account.
A money mule can have genuine documents, a genuine mobile number, and a successful KYC journey. What looks normal in isolation can still be risky when you look at the complete profile.
Mule Sentinel adds that missing layer. It looks at how identity, telecom, location, occupation, income, and payment signals fit together, helping banks spot inconsistencies before an account is opened.
Inside the Risk Scoring Engine
Every onboarding journey starts with a few basic details. A customer’s name, mobile number, PAN, address, and identity documents.
Mule Sentinel takes these onboarding signals and turns them into a single risk assessment before the account is opened. Instead of returning a simple pass or fail, it gives banks three outputs: a Mule Score between 0 and 100, a Green, Amber, or Red risk band, and a breakdown of the signals that influenced the score.
The score is built by looking at four parts of an applicant’s profile together.
| Dimensions | What Mule Sentinel checks |
| Identity | PAN, name, age, and identity consistency across records. |
| Telecom | SIM age, telecom circle, portability history, and mobile risk signals. |
| Digital Presence | Whether the applicant’s digital footprint is consistent with the identity being used. |
| Payment & Fraud Registries | Model to identify connections to known risky entities developed using Cashfree’s payment network, fraud registries, and screening systems. |
The important part is what happens next.
Mule Sentinel doesn’t flag someone because of one unusual signal. A recently issued SIM, a new city, or an unexpected income declaration can all belong to genuine customers.
It looks for coherence across the entire profile.
Imagine a 25 year old pharmacist in a small town declaring a monthly income of ₹50 lakh. Or an applicant whose telecom connection belongs to one state while every address they provide belongs to another.
Neither one proves fraud on its own. But together, they raise a simple question: does the applicant’s own profile support what they’re claiming?
That’s the kind of check a sharp risk analyst would make manually. Mule Sentinel does it instantly and consistently across every applicant.
That’s how the Risk Scoring Engine separates isolated anomalies from meaningful onboarding risk.
The same approach protects genuine customers. Someone opening their first bank account in a rural town may have very little financial history, but if their identity, address, telecom information, and occupation all fit together, Mule Sentinel treats that as a low risk, coherent profile instead of sending them into unnecessary review.
Every Mule Score is explainable. Risk and compliance teams can see which signals contributed to the score and why an applicant was placed in Green, Amber, or Red, making every decision easier to review and defend.
Green, Amber, or Red: Three onboarding journeys
Every applicant doesn’t need the same onboarding journey. That’s the biggest change Mule Sentinel brings.
Once the Risk Scoring Engine evaluates an applicant, it places them into one of three decision bands based on the overall risk profile.
Green means the profile looks coherent across all onboarding signals. The customer continues through onboarding immediately, with no additional checks or friction.
Amber is where things get interesting. These are customers who don’t look clearly fraudulent, but don’t have enough confidence for an instant approval either. Today, this is the bucket that usually ends up in manual review queues, creating delays for both operations teams and genuine customers.
Red indicates a high to very high risk profile. Mule Sentinel recommends stopping the account at the gate, with the account opened only if the institution’s own rigorous investigation clears it. Instead of discovering the risk after transactions begin, the bank gets the opportunity to investigate before onboarding is complete, and before the account exists.
The goal isn’t to reject more customers. It’s to give banks a smarter way to decide who needs another look.
Plausibility Checks inside V-KYC/ onboarding phone call
Amber cases move into the next layer of Mule Sentinel: Plausibility Checks.
Instead of sending every uncertain application through a long investigation, Mule Sentinel helps the VKYC agent ask the right question at the right time. The questions may also be asked over a simple phone call.
At the heart of this is a decision tree of pre authored questions. Which question gets asked, and what comes next, depends on more than the signal that triggered Amber. The flow takes into account the applicant’s previous answers in the same call, their broader onboarding details, and the specific attributes that were flagged.
At every step, the objective is simple: understand why the anomaly exists and whether the applicant has a plausible explanation for it.
For example, if an applicant’s occupation and declared income don’t seem consistent, the agent can ask them to explain their source of income. If the telecom circle doesn’t match the customer’s address, the conversation can focus on where they currently live or whether they’ve recently relocated. If the intended use of the account appears unusual, the agent can verify the primary purpose for opening it.
These are not AI generated questions. They are pre authored compliance questions that fit naturally into the institution’s existing VKYC process.
What is AI powered here? It is listening, not asking.
As the customer answers in their own words, an AI classifier listens to the response and maps it in real time to one of a small set of predefined categories. The agent sees the AI’s best match and can confirm it or correct it in a single action.
The agent is never handed a black box verdict. They get additional context from the conversation while retaining full control over the final decision.
Nothing changes for the customer. There is no second verification call, no chatbot, and no new onboarding flow. Plausibility Checks simply make the V KYC conversation more informed, more targeted, and much faster to resolve.
Built for the onboarding stack banks already have
Mule Sentinel is designed to fit into the onboarding journey banks already run today.
It works alongside existing KYC systems, Video KYC, fraud registries, telecom intelligence, and onboarding workflows. Nothing in the customer journey needs to change. Banks continue using the tools they already trust, with Mule Sentinel adding an additional layer of risk assessment before an account is opened.
It also complements the fraud systems that work after onboarding. Behavioural monitoring and transaction intelligence continue to detect suspicious activity once an account is live. Mule Sentinel helps strengthen the decision that comes before that stage, so fewer risky accounts enter the system in the first place.
The result is a sharper onboarding process, fewer unnecessary manual reviews, and more confidence in every account that gets opened.
A new layer of onboarding intelligence
The most important fraud decision a bank makes isn’t after the first transaction. It’s before the first transaction.
Mule Sentinel brings risk intelligence to that moment through a real time Risk Scoring Engine and targeted Plausibility Checks inside VKYC. Together, they help banks identify risky identities early, while keeping genuine customers moving through onboarding without added friction.
The final decision always stays with the institution. Mule Sentinel provides the signals, the context, and the explanation. The bank decides what happens next.
And no system will catch every mule. A well established identity with a genuine phone number and a consistent profile may not raise any unusual signals. Mule Sentinel isn’t about claiming to stop every possible case. It’s about closing one of the biggest gaps in onboarding risk: identifying suspicious profiles before the first transaction.
Because the best way to stop a mule account is to stop it before it enters the financial system.
Why Cashfree Payments
Stopping mule accounts takes more than one source of truth. The strongest signal often comes from connecting identity, telecom, payment, and fraud signals that institutions usually see in isolation.
That’s where Cashfree brings a different advantage. Mule Sentinel combines payment graph intelligence developed using Cashfree’s network with telecom, identity, and fraud registry signals to build a single onboarding risk assessment. The focus isn’t on one signal being right. It’s on understanding how multiple signals fit together before an account is opened.