When banks rely on those signals alone, deepfakes can be used to impersonate legitimate customers and bypass identity checks. That can lead to fraudulent accounts, unauthorised transfers, and synthetic identities that are harder to detect later. The practical failure is not just deception at the front door, but downstream fraud that looks legitimate.
Why Face, Video, and Voice Evidence Breaks Without Anti-Spoofing
Biometric-looking evidence only works when the bank can trust that the signal came from a live, present customer rather than a replay, mask, screen capture, voice clone, or synthetic media. Without anti-spoofing, the control is really just a presentation check, not a reliable identity check. That matters because fraudsters only need one convincing pass to open the account or approve the transfer.
Good anti-spoofing is not one technique, it is a set of checks that try to separate genuine capture from replayed or generated content. In practice, that means liveness detection, challenge-response, device and session signals, and correlation with other identity evidence. If those layers are missing, the bank is trusting appearance alone.
For banks, the weakness is amplified by scale: once a spoof method works against one onboarding flow or one remote authentication path, it can be reused across many attempts. NIST Cybersecurity Framework 2.0 is useful here because it frames the need to detect and reduce trust failures before they become repeated fraud patterns.
Where the Failure Shows Up in Banking Workflows
The most common failure point is remote onboarding, where a bank accepts selfie, video, or voice evidence as a proxy for presence. A deepfake or replay can satisfy the front-end check while the underlying account is synthetic or stolen. The same weakness appears in step-up authentication and customer support journeys if the bank accepts media evidence without checking whether it is live, recent, and consistent with the rest of the session.
This is why the issue is not limited to one-off impersonation. Once a fraudulent identity has been accepted, it can be used to create accounts, pass manual review, move funds, or seed mule activity. NIST AI Risk Management Framework is relevant as a governance reference for managing synthetic-media risk, while NIST SP 800-63 Digital Identity Guidelines supports the broader principle that identity evidence should be bound to assurance, not treated as a standalone signal.
Fraud teams should also expect the false account to behave normally at first. That makes detection harder, because the abuse may surface only after funds move or the account is used to launder activity. In other words, the loss is often delayed, and the original spoof may never be obvious in the fraud case file.
What Banks Need to Verify Before Trusting Biometrics
Face, video, and voice can still be useful, but only when they are part of a layered decision that includes anti-spoofing, confidence thresholds, and fallback checks for higher-risk transactions. A bank should verify whether the evidence is live, whether it matches prior enrollment or trusted history, and whether the session context is consistent with expected customer behaviour. If the answer depends on a single biometric signal, the control is too brittle.
For implementation, the practical question is not whether the technology can recognise a face or voice, but whether it can resist presentation attacks at the threat level the bank actually faces. CIS Controls v8 is useful for the surrounding operational controls, especially account management, logging, and secure configuration, while NIST SP 800-53 Rev 5 Security and Privacy Controls provides a control lens for authentication, auditability, and system integrity.
When banks operate across mobile, web, call-centre, and assisted channels, consistency matters more than any single vendor feature. A control that works only in one channel but not in assisted recovery is usually a gap, not a solution.
Risk and Threat Considerations
Without anti-spoofing, biometric evidence becomes an attractive entry point for synthetic identities, account takeover, and payment fraud. The threat is not limited to deepfake sophistication; even modest replay or injection attacks can defeat a process that treats media as proof of presence.
Failure mechanism: The attacker presents replayed, generated, or manipulated face, video, or voice input that satisfies a weak verification flow, then uses the accepted identity to open accounts, bypass step-up checks, or approve transfers.
Impact: The bank may record a legitimate-looking identity event that later supports fraud investigations, increases recovery cost, and makes detection harder because the downstream activity appears to originate from an authenticated customer.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-01 — Monitor for Unauthorized Personnel, Connections, Devices, and Software | Spoofed biometric events create unauthorized trust signals that should be monitored. |
| Recommendation — Monitor biometric enrollment and auth anomalies for signs of spoofing or reuse. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | The question is about whether biometric evidence is sufficient for identity assurance. |
| Recommendation — Bind biometric evidence to an appropriate assurance level and require stronger proof for higher-risk actions. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Bank customers are external users whose identity evidence must resist spoofing. |
| Recommendation — Require robust authentication and anti-spoofing checks for customer identity proofing. | ||
| CIS Controls v8 | CIS-5 — Account Management | Spoofed onboarding creates fraudulent accounts that account controls must detect and govern. |
| Recommendation — Harden account onboarding and approval paths against fake or duplicated identities. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity evidence from biometrics must be governed as part of identity lifecycle control. |
| Recommendation — Tie biometric verification to governed identity lifecycle and exception handling. | ||
Practitioner Guidance
What to prioritise: Treat anti-spoofing as a fraud-control requirement, not a cosmetic UX feature. The first priority is to identify every place where biometric evidence alone can create trust, especially onboarding, recovery, and high-value transaction approval.
What to verify: Confirm that the biometric decision is bound to liveness, session integrity, and a fallback path when confidence drops. If a process cannot explain why a capture is live, recent, and contextually consistent, it should not be used as a sole approval signal.
Decision rule: If the biometric event can create new account privileges or authorize movement of funds, require layered verification and manual exception handling for elevated-risk cases. Use the signal as one input, not the final authority.
Practitioner takeaway: The control objective is not to eliminate biometrics, but to stop media from becoming a standalone proof of identity when the attacker can manufacture the media itself.
Related resources from NHI Mgmt Group
- What happens when video KYC is used without strong anti-spoofing controls?
- What happens when organisations rely on biometrics without anti-spoofing and encryption controls?
- What breaks when voice authentication is used without strong anti-spoofing controls?
- What happens when banks deploy AI customer service and facial recognition without strong identity controls?