Join our Newsletter — 33% off our NHI Course

What do security teams get wrong about relying on manual checks to stop fake IT workers?

Many teams assume video interviews, in-person onboarding, or background checks are enough. In practice, those controls can be bypassed by deepfakes, mule-assisted delivery, stolen credentials, and fraudulent documents. Manual checks are point-in-time controls, while impersonation is a lifecycle risk that requires continuous verification and cross-functional monitoring.

Why This Matters for Security Teams

Manual verification creates a false sense of closure. Video interviews, in-person onboarding, and background screening can confirm a person at a moment in time, but impersonation attacks are built to survive that moment and continue through delivery, account setup, and access use. Security teams that treat identity proofing as a one-time gate miss the operational reality that fake workers often arrive with mule-assisted devices, stolen credentials, synthetic documents, or delegated tasks. NIST Cybersecurity Framework 2.0 emphasizes continuous, outcome-driven risk management, not one-time trust decisions.

NHI Management Group research shows that identity problems become more dangerous when they are not continuously governed, and the same pattern applies here: the attack does not end when the interview ends. The broader lesson from the Ultimate Guide to NHIs is that access, ownership, and revocation must be managed across the full lifecycle, not just at onboarding. In practice, many security teams encounter fake workers only after payroll, device enrollment, or privileged access has already been abused, rather than through intentional pre-employment screening.

How It Works in Practice

Stopping fake IT workers requires shifting from manual checkpoints to continuous verification and access governance. The right control mix is usually a combination of identity proofing, device trust, privileged access management, and cross-functional monitoring across HR, procurement, security, and IT. Static checks help reduce obvious fraud, but they do not scale against impersonation campaigns that exploit gaps between hiring, device shipment, account creation, and first login.

Current guidance suggests four practical moves. First, verify the person and the device separately, because a legitimate-looking candidate can still operate through a fraudulent endpoint. Second, issue access only when a verified business need exists and revalidate it at each sensitive step. Third, monitor for anomalies in location, login cadence, support requests, and credential recovery events. Fourth, require strong revocation procedures so access disappears as soon as employment status, contractor status, or vendor status changes. The NIST Cybersecurity Framework 2.0 is useful here because it reinforces governance, protection, detection, and response as continuous functions rather than single approvals.

The State of Non-Human Identity Security also highlights the operational cost of weak visibility and poor rotation discipline, which maps closely to fake-worker scenarios once the impersonator gains a foothold. One useful metric is whether the organization can prove who sponsored the worker, who approved access, and who can revoke it immediately.

  • Use manual checks as a fraud screen, not as the final trust decision.
  • Bind onboarding to device attestation, access policy, and sponsor approval.
  • Require continuous monitoring for unusual access paths and credential resets.
  • Test revocation speed across HR, IAM, PAM, and endpoint tooling.

These controls tend to break down in outsourced support, remote-only hiring, and distributed contractor models because the handoffs between recruiters, vendors, and IT create enough delay for an impersonator to become operational.

Common Variations and Edge Cases

Tighter verification often increases hiring friction and support overhead, requiring organisations to balance fraud prevention against onboarding speed and contractor experience. That tradeoff is real, especially when teams rely on third-party staffing firms, offshore delivery centers, or just-in-time project workers. There is no universal standard for this yet, but best practice is evolving toward layered verification instead of trust-by-document.

Some environments need stronger controls than others. For example, regulated sectors may require extra identity proofing, while software teams may focus more on device assurance, session monitoring, and least privilege. Manual checks also become weaker when deepfake video, synthetic IDs, or mule-operated devices are part of the threat model. In those cases, the useful question is not whether the person looked real during onboarding, but whether the entire access chain stayed credible after onboarding.

NHIMG research shows that organisations still struggle to maintain full visibility into identity risk across the lifecycle, and that is exactly why a one-time interview does not close the problem. The Ultimate Guide to NHIs is helpful for teams building lifecycle controls, while the NIST framework helps translate that governance into repeatable operational practice. The exception is highly trusted, on-site, fully managed workforces, where stronger physical controls can reduce exposure, but even there, identity fraud can still enter through delegated access or compromised accounts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA Identity assurance must be continuous, not a single onboarding event.
OWASP Non-Human Identity Top 10 NHI-01 Lifecycle governance applies when fake workers gain access through credentials or accounts.
CSA MAESTRO GOV-02 Governance is needed to coordinate human, vendor, and system trust decisions.
NIST AI RMF AI-enabled impersonation increases the need for risk-based, ongoing oversight.
OWASP Agentic AI Top 10 A1 Autonomous fraud tooling can amplify impersonation and bypass static checks.

Use AI RMF governance to assess deepfake and synthetic-identity risk in identity workflows.