RDCPASSBusiness
Fraud Reporting · Risk

Report fraud to the national fraud desk and follow the case to its outcome

Fraud Reporting files cases involving Congolese identities with the RDCPASS national fraud desk. Investigators review each one and compare it with reports from the other banks, operators and platforms on the network. Your system is told every time the case moves.

  • Usurpation, SIM swap, robbery and more
  • Case updates sent to your system
  • Free for approved organizations
Sandbox example

Report a fraud case

Type
SIM swap
Victim
Kabeya Mwamba Tshisekedi
Loss
2,450,000 CDF
  1. Signing request · HMAC-SHA256
  2. Encrypting payload · AES-256-GCM
  3. Filing with the national fraud desk
  4. Tracking case status by webhook

Result

case types
12
case types
tracked case statuses
5
tracked case statuses
for approved organizations
Free
for approved organizations
case status updates
Webhook
case status updates

Why businesses choose Fraud Reporting

1

Stop the same fraud elsewhere

When one operator reports a SIM swap, the same citizen’s bank account in another city can be protected that day.

2

Follow each case to its outcome

Every report gets a case number, and your system is notified each time its status changes.

3

Feed the checks you already use

Confirmed cases become fraud signals in other RDCPASS services, AML & CTF Screening among them.

How it works

  1. 01

    Your team spots fraud

    At a branch, online, in your app, over USSD or in your call centre.

  2. 02

    You file a factual report

    Say what type of fraud it is, who is involved and what happened, with where, when and any evidence you hold.

  3. 03

    RDCPASS investigators review it

    They assess the case and compare it with other reports and signals on the network.

  4. 04

    You receive each status update

    Under review, confirmed, dismissed or escalated to the competent authorities. Each update goes straight to your system.

Capabilities

What you receive

For every report, RDCPASS gives you what you need to track the case:

  • A unique case number to use with RDCPASS or the authorities
  • Confirmation that the case was received and is waiting for review
  • A notification each time the case changes status
  • The final outcome: confirmed, dismissed or escalated to the competent authorities
  • Your own case or ticket reference, repeated on every update
01

Twelve fraud types

Identity usurpation, document forgery, account takeover, SIM swap, money laundering, terrorist financing, robbery, payment fraud, phishing, social engineering, insider fraud and other cases.

02

Report with or without an ID

Identify the person by RDCPASS ID or identity document. If all you have is a name, date of birth and phone number, that works too.

03

Supporting evidence

Attach images, documents, transaction logs or audio recordings. Only RDCPASS investigators can open them.

04

Case tracking

Quote the case number in any correspondence and check the status whenever you need to.

05

Historical case import

Bring the cases you have already investigated onto the network from day one, up to 10,000 in one request.

06

Real time or in the background

File a case in real time. Reports with large evidence files can be processed in the background.

Integration

One integration for sandbox and production

Requests are HTTPS calls with JSON bodies, signed and encrypted. The sandbox returns the same formats as production, so the code you test with is the code you ship.

  1. 1

    Create an application

    Sign up, create a sandbox application and select the services and data scopes you need.

  2. 2

    Make your first call

    Start from an official SDK or from the samples on the right. Eight languages are covered.

  3. 3

    Go live

    After due diligence, replace the sandbox keys with production keys and add your mTLS certificate. The request code stays the same.

Request modes

Single · sync

One record, answered immediately.

Single · async

One record, result by webhook.

Batch · sync

Up to 50 records per call.

Batch · async

Up to 10,000 records, result by webhook.

mTLSHMAC-SHA256AES-256-GCMAudit log
report-fraud.sh
# Body shown in plaintext — encrypt it per /docs/authentication before sending.
curl https://api.rdcpass.cd/v1/fraud/reports \
  -X POST \
  -H "X-RDCPASS-Key-Id: key_live_8f2a1c0e9b" \
  -H "X-RDCPASS-Timestamp: 1790418900" \
  -H "X-RDCPASS-Nonce: 3c7e1a9d-2b4f-4d6a-8e15-9f0b7c2d4a61" \
  -H "X-RDCPASS-IV: q2Vh8Zk1pX0rT7mB" \
  -H "X-RDCPASS-Signature: b61d4e...9a07" \
  -H "Idempotency-Key: 5f0c2a8e-7d41-4b39-a6e2-1c9d8b3f7a50" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "sim_swap",
    "subject": {
      "identifier": {
        "type": "rdcpass_id",
        "value": "COD-2103-0214-4937"
      },
      "full_name": "Kabeya Mwamba Tshisekedi",
      "phone_number": "+243812345678"
    },
    "description": "SIM card replaced at an unauthorised agent in Lubumbashi, followed within 40 minutes by three mobile money transfers the customer did not initiate.",
    "occurred_at": "2026-09-24T09:12:00Z",
    "location": {
      "province": "Haut-Katanga",
      "city": "Lubumbashi"
    },
    "amount": {
      "value": 2450000,
      "currency": "CDF"
    },
    "channel": "ussd",
    "evidence": [
      {
        "type": "transaction_log",
        "file": {
          "url": "https://files.example-bank.cd/cases/88213/transfers.csv"
        },
        "description": "Wallet transaction export for 24 September 2026"
      }
    ],
    "reporter_reference": "INC-2026-88213"
  }'
200 OK
{
  "id": "frd_5c8e1a7d42",
  "object": "fraud_report",
  "livemode": true,
  "case_number": "RDC-FRD-2026-004812",
  "status": "received",
  "type": "sim_swap",
  "reporter_reference": "INC-2026-88213",
  "created_at": "2026-09-26T10:15:02Z"
}

Trust & privacy

  • Each report is attributed to your application, audited, and reviewed as part of your production due diligence.
  • Evidence files can only be accessed by RDCPASS investigators, for as long as the case exists.
  • A money laundering report filed here complements your own suspicious transaction reporting to CENAREF. It never replaces it.
  • Requests are signed, encrypted end to end and sent over mutually authenticated connections.

Pricing

Free for every approved organization.

Fraud reports are never billed, whether single or batch, real time or in the background. Each case you file adds to what every connected organization can see.

Frequently asked questions

What if I do not know the person’s RDCPASS ID?+

Report them by passport, CENI voter card, driving licence or national ID. You can also use their name, date of birth and phone number. An RDCPASS ID gives the fastest correlation.

What happens after I file a report?+

An RDCPASS investigator reviews the case and compares it with other reports. It is then confirmed, dismissed, or referred to the competent judicial, police or financial intelligence authorities. You are notified at each step.

Should I tell the person that a report was filed?+

No. Stick to facts rather than opinions, and never inform the subject. This matters most in money laundering and terrorist financing cases.

Can I try it before going live?+

Yes. The sandbox is free and behaves like production, using synthetic test identities.

Start using Fraud Reporting

Building and testing in the sandbox is free. You go live once your business and application have passed due diligence.