Join our Newsletter — 33% off our NHI Course

How should organisations verify payment instructions when a video meeting or voice call could be synthetic?

Organisations should treat any request for secrecy, urgency, or unusual payment routing as a verification trigger, not proof of legitimacy. Use out-of-band confirmation through known contact details, require dual approval for high-value transfers, and train staff to challenge even familiar faces and voices. Deepfake scams succeed when routine trust replaces independent validation, so payment controls must assume that audio and video can be fabricated.

Why synthetic calls change the payment control you need

The core issue is not whether the caller sounds convincing, it is whether the payment request can survive independent validation. Synthetic audio and video remove the old shortcut of “I saw or heard the person, so the request is real.” That means the control objective shifts from recognition to verification, especially when the request is urgent, secret, or outside normal routing.

Payment teams should treat human likeness as an input to assess, not evidence to rely on. A familiar face on screen, a known voice, or a plausible backstory can all be forged well enough to bypass routine trust, so the process must assume the meeting channel itself is untrusted until corroborated elsewhere.

For high-value or unusual transfers, the practical question is whether the instruction can be confirmed through a separate channel that the requester cannot easily influence. If the answer depends only on the meeting, the control is too weak for modern fraud conditions.

How to verify payment instructions without trusting the call

The most reliable pattern is to verify payment details through known contact routes that were established before the request arose. That means calling a pre-registered number, using a separately known email address or portal, or confirming through an internal approval path that does not depend on the same meeting or device used to make the request.

Dual approval is especially important where the amount, beneficiary, jurisdiction, or timing is outside routine behaviour. It creates a second judgment point that can catch instructions that sound plausible but do not fit the business context, and it reduces the chance that one persuasive call can trigger an irreversible transfer.

Where payment controls already exist, the key test is whether they force a break in the chain of influence. If the same person, same channel, and same urgency can move the payment from request to release, then the organisation has a social engineering problem disguised as a process problem.

What staff need to look for in a synthetic-payment attempt

Deepfake-enabled fraud usually relies on pressure, not technical sophistication alone. Requests that demand secrecy, bypass the usual approver, or alter beneficiary details at short notice deserve immediate scrutiny, because they are designed to stop normal challenge behaviour before anyone checks independently.

Training should focus on pattern recognition and refusal skill, not on spotting fake pixels or odd speech alone. Staff need to be comfortable pausing the transaction, escalating it, and using the callback or approval process even when the requester sounds senior, familiar, or impatient.

A useful practical indicator is mismatch: the more the request deviates from normal payment history, the more the organisation should prefer formal validation over conversational confidence. Familiarity is not a control; it is simply one more feature that attackers can imitate.

Risk and Threat Considerations

Synthetic audio and video raise the risk of business email compromise style payment fraud by making impersonation more believable and faster to execute. The failure mode is a process that treats a live conversation as sufficient evidence, which allows urgency, authority, and familiarity to override independent confirmation.

Failure mechanism: Attackers exploit trust in real-time communication, then pair it with secrecy or time pressure so staff skip out-of-band confirmation and release funds on a fabricated instruction.

Impact: The result can be an unrecoverable transfer, weak non-repudiation, and a wider breakdown in payment governance because the organisation can no longer distinguish genuine approval from synthetic impersonation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Synthetic calls exploit weak human verification before payment approval.
AC-6 — Least Privilege Limits who can approve or route high-risk payment instructions.
Recommendation — Require independent authentication and approval steps before releasing payments. Restrict payment release authority to the minimum necessary roles.
CIS Controls v8 CIS-5 — Account Management Payment workflows need controlled approval paths and verified access roles.
Recommendation — Review and restrict payment approver accounts and escalation paths.
NIST CSF 2.0 PR.AA-05 — Least privilege Directly supports dual-control and approval separation for payment actions.
Recommendation — Enforce least privilege and separate approval authority for payments.
MITRE ATT&CK T1204 — User Execution Deepfake payment fraud depends on persuading a person to act on false instructions.
Recommendation — Hunt for social-engineering lures that prompt users to authorize transfers.

Practitioner Guidance

What to prioritise: Build payment verification around a channel the requester cannot control during the same interaction. A callback to a known number, a separate approver, and a documented beneficiary check are more valuable than trying to judge whether a face or voice seems authentic.

What to verify: Confirm that high-risk payments require at least one independent check that is not reachable from the original call, and that the approver must reconcile amount, beneficiary, and urgency against the normal payment pattern before release.

Decision rule: If any instruction includes secrecy, urgency, or a change in routing, treat it as a verification event. If the request cannot survive a separate confirmation path, do not pay until it can.

Practitioner takeaway: The right control is not “recognise the executive”, it is “prevent a convincing impersonation from being sufficient to move money.”