You check the number. It is active. It is reachable. The OTP lands, the customer types it in, and the onboarding flow moves on. For most businesses in India, that is the whole phone check. It answers one question well: can we reach this person? It says nothing about a harder question: should we trust them?
A mobile number is one of the most reused identifiers in Indian finance. It is the login, the OTP channel, the UPI handle, the recovery key and the field every KYC form asks for first.
That makes it valuable to fraudsters for exactly the same reason it is useful to you. A number that was issued three weeks ago, that has changed hands twice, that mostly talks to known spam numbers, or that the telecom department has flagged for revocation, can still receive an OTP today. Active is not the same as clean.
This blog explains what Phone Risk Intelligence is, which signals exist in India, from government registries to the life of the number itself, and how to use them without adding friction for the customers you want. It also shows how phone risk can complement digital identity verification rather than replace it.
What is Phone Risk Intelligence?
Phone Risk Intelligence means reading the risk signals behind a mobile number, not just checking whether it is active. Basic verification tells you the number exists and can receive an OTP. Risk intelligence adds two layers of context: what the ecosystem has already recorded about the number (revocation, fraud risk rating, cybercrime complaints), and what the number’s own life reveals (how old it is, whether it has been recycled, how it behaves, who it is connected to, and whether it really belongs to the name on the form).
The output is not a pass or fail. It is a set of decision inputs your risk rules can act on.
That matters because fraud increasingly involves real identities. A mule account can belong to a real person, use real documents and have a real phone number. Everything passes. The risk is in the intent, and intent leaves traces that basic checks do not see.
Layer one: what the ecosystem has recorded
India now has three official signal sources that describe the risk behind a phone number. They answer different questions, and the useful picture comes from reading them together.
MNRL: has the number been revoked?
The Mobile Number Revocation List (MNRL), published by the Department of Telecommunications through its Digital Intelligence Platform, lists numbers disconnected due to cybercrime, failed re-verification, or usage limits. RBI’s January 2025 circular directs regulated entities to use it to clean their records and define procedures for accounts linked to revoked numbers.
What it tells you: The number on file has been revoked and should not be trusted as a contact or OTP channel without further verification.
FRI: how risky does the government consider this number?
The Financial Fraud Risk Indicator (FRI), introduced by the Department of Telecommunications in May 2025, classifies mobile numbers as Medium, High, or Very High risk of financial fraud. It uses inputs from I4C, the National Cybercrime Reporting Portal, DoT’s Chakshu platform, and banks and financial institutions. Banks and UPI apps can use these alerts to warn users, step up checks or decline transactions linked to Very High risk numbers.
What it tells you: A graded risk level, maintained by the government, that already reflects what banks and payment apps have seen.
I4C: has the number been reported in a cybercrime complaint?
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, runs the National Cybercrime Reporting Portal and the 1930 helpline. Complaints may include identifiers used in the fraud, such as phone numbers and bank accounts. These reports help authorities and participating institutions identify potentially repeated fraud activity.
What it tells you: Whether the number has appeared in a cybercrime complaint.
Layer two: what the number’s own life tells you
Registries record what has already gone wrong. The second layer reads the number itself, so you can see risk before it becomes a complaint. These are the signals Phone Risk Intelligence returns for a number.
Age and tenure
When the number was first and last seen, and how long it has been active, from under a week to over a year. Years of steady history tell a very different story from a number that appeared last month.
Recycling and identity changes
How often the number has been reassigned or changed identities, and how long the current identity has held it. Recently recycled numbers deserve a closer look.
Activity pattern
Incoming and outgoing call scores and activity spread across 7, 14, 30 and 60-day windows. A phone that is used like a phone shows a steady, two-way pattern. A SIM used as a tool shows bursts, silence, or traffic that flows only one way.
Network quality
The number’s network score, spam-linked connections, and balance of strong and weak ties. Who a number connects with can reveal what it is being used for.
Spam standing
A graded score from no activity to very high, reflecting how the wider ecosystem has experienced the number.
Name to number match
Whether the collected name matches the identity associated with the number, with match confidence and a signal for potential family-member usage. This can flag a borrowed SIM during onboarding. A separate Name Match API can help compare names across identity and account records when the journey needs another layer of validation.
Context fields
The original carrier and telecom circle, whether DND is active, and, where a custom model is deployed, a risk probability between 0 and 1.
Privacy by design
The check can run on a hashed number. Send a SHA-256 hash with the country code instead of the raw number and receive the same signals back.
How Phone Risk Signals Change a Real Decision
A customer can pass every standard check. The number is active, the OTP goes through, the identity matches, and the required verification checks are clear. On paper, everything looks right.
Now add the signals. The number was first seen three weeks ago, has been recycled, is connected to known spam numbers, the name does not match the identity behind it, and FRI rates it High. None of this would surface in a standard verification flow because it was never looking for it.
The response does not have to be a rejection. It could mean an additional verification step, a deeper review, a payment hold, or tighter limits. Risk intelligence is most useful when it changes the path, not when it simply closes the door.
The same principle applies wherever identity and money intersect. A recently created account, a revoked number, or a sudden change in payment details may not be fraud on its own. But together, these signals can show when something deserves a closer look. This layered approach also supports broader payment fraud detection without treating every unusual signal as a confirmed threat.
Also Read: How RiskShield’s fraud-prevention technology connects risk signals
Introducing Mobile360 Phone Risk Intelligence
Mobile360 brings phone risk intelligence into a single API call. It combines MNRL, FRI and I4C checks with signals such as number age, recycling, activity patterns, network quality, spam standing and name-to-number match, giving your rules engine the context to make a more informed decision. It works alongside Secure ID, so you can move from phone risk to bank account verification, face match and liveness or Mule Sentinel when needed.
Where phone risk fits in a wider identity risk stack
The phone number is often the first identifier you collect and one of the identifiers you keep using longest. Checking it well can provide an efficient early signal in the stack. But no single signal is a verdict. The strongest fraud programmes layer it: phone risk at the front, document and face checks in the middle, account ownership before money moves, and a mule score that reads behaviour across all of them. Teams can bring these checks together within a digital onboarding flow and test relevant verification APIs in Cashfree Dev Studio.
The question for your team is simple. Right now, when a number passes OTP, what else do you know about it? If the answer is nothing, that is the gap.
Also Read: How identity infrastructure supports explainable onboarding decisions
The number is active. What else do you know about it?
Phone Risk Intelligence reads registry checks and the life of the number in one call, so you can decide with the full picture, not just an OTP.
✓ MNRL, FRI and I4C in one response
✓ Age, activity, recycling and network signals
✓ Name-to-number match at onboarding
FAQs
What is Phone Risk Intelligence?
Phone Risk Intelligence looks beyond whether a mobile number is active. It combines registry checks such as MNRL, FRI and I4C with signals including number age, recycling, activity patterns, network quality, spam standing and name-to-number match.
What is a phone number risk check?
A phone number risk check assesses a mobile number against fraud, revocation and cybercrime data, along with its behavioural history, to understand its risk beyond simply confirming that it can receive an OTP.
What is MNRL?
MNRL stands for Mobile Number Revocation List. Published by the Department of Telecommunications through its Digital Intelligence Platform, it lists disconnected mobile numbers, including those linked to cybercrime, failed re-verification or usage violations.
What is the Financial Fraud Risk Indicator (FRI)?
FRI is a risk classification for mobile numbers introduced by the Department of Telecommunications in May 2025. It rates numbers as Medium, High or Very High risk of financial fraud, using inputs from I4C, the National Cybercrime Reporting Portal, Chakshu and financial institutions.
What is I4C?
I4C, or the Indian Cyber Crime Coordination Centre, is a Ministry of Home Affairs body that operates the National Cybercrime Reporting Portal and the 1930 helpline. Phone numbers reported through cybercrime complaints can become signals for fraud detection.
What is number recycling and why does it matter?
Telecom operators can reassign disconnected numbers to new subscribers. A recycled number may still carry links and reputation from its previous use. Knowing how often a number has changed hands and how long the current identity has held it adds important context.
Does the RBI require banks to check the MNRL?
Yes. The RBI’s January 2025 circular asked regulated entities to use the MNRL to monitor and clean their databases and apply enhanced monitoring to accounts linked to revoked numbers.
Can an active mobile number still be fraudulent?
Yes. An active number can be recently created, recycled, connected to spam numbers, reported in cybercrime complaints or pending revocation. OTP delivery confirms control of the SIM, not the history or risk behind the number.
Can I run a phone risk check without sharing the raw number?
Yes. The check can run using a SHA-256 hash of the number and the country code, so the raw number does not need to leave your system.
How is Phone Risk Intelligence different from mobile number verification?
Mobile number verification confirms that a number exists and that the user can access it, usually through an OTP. Phone Risk Intelligence adds risk, history and ecosystem context, helping you decide whether to proceed, step up verification or review.