Security teams should combine document verification, liveness checks, and real-time anomaly detection so the workflow tests both possession and presence. The control goal is to reduce spoofing while keeping onboarding fast enough for regulated digital journeys. A strong design also includes escalation paths for suspicious cases, audit logs for review, and regulatory alignment so the process remains defensible.
Design the workflow to test both possession and presence
A resilient video KYC flow should not depend on a single signal, because deepfake fraud succeeds when one check is treated as proof of the whole identity event. The stronger pattern is layered: document verification, liveness or presentation-attack detection, and anomaly detection that watches for injection, replay, or scripted behaviour. NHIMG’s Identity Proofing and KYC Guide is a useful reference for the control mix, and the practical challenge is to preserve assurance without turning every case into manual review.
That balance matters because regulated onboarding is a trust decision as much as a usability decision. If the workflow only checks document quality, a convincing synthetic face or voice can still pass. If it only adds aggressive friction, legitimate users abandon the journey or get routed into avoidable exceptions.
Deepfakes, Social Engineering and AI Impersonation Guide shows why the control set should include out-of-band verification for higher-risk journeys, especially where an attacker can combine synthetic media with social engineering to push a weak reviewer past a shallow check.
Where deepfake-resistant KYC breaks in practice
The failure mode is usually not “no controls”, it is control overconfidence. A team may believe a liveness challenge is enough, even though modern deepfake tooling can be paired with camera injection, virtual cameras, or replayed sessions that imitate real-time interaction. The other common gap is process drift: the controls exist, but escalation criteria are vague, so suspicious sessions are either approved too quickly or blocked without a consistent review path.
Deepfake resistance also has a workflow design problem. Controls that are too strict on the front end push genuine users into friction-heavy remediation, while controls that are too loose create a fraud funnel for account opening, credit applications, or regulated customer onboarding. The right design makes step-up checks conditional on observed risk, not universal for every applicant.
For that reason, the strongest programmes treat review logs, exception handling, and analyst notes as part of the control, not as after-the-fact administration. Arup deepfake fraud 2024 is a reminder that once an impersonation passes the live session, downstream payment or account actions can become the real loss event.
The regulatory side matters too. KYC is not only an anti-fraud workflow, it is an evidentiary workflow that must be defensible when challenged. FATF Recommendations, AML and KYC Framework and FinCEN are relevant because escalation, customer due diligence, and suspicious activity handling need to align with the institution’s broader AML obligations.
How to keep friction low without weakening assurance
Good workflow design uses risk-based branching. Low-risk applicants should pass through a short, smooth path when signals are consistent, while higher-risk sessions should get stronger checks such as re-capture, step-up verification, or callback procedures. This keeps legitimate conversion rates higher while reserving the most intrusive controls for cases that justify them.
EBA AML/CFT Guidance is useful here because it reinforces the need for proportionate customer due diligence and escalation logic. For teams operating in or into the EU, eIDAS 2.0, the EU Digital Identity Framework is also a relevant anchor for digital identity assurance, especially where reusable identity wallets or stronger verification methods can reduce repeated friction.
Operationally, the best user experience comes from making additional friction invisible until needed. That means clear prompts, fast retry paths, and minimal repeated data entry, but also a hard stop when the session shows signs of spoofing, injection, or mismatched identity evidence. The process should feel easy for honest users and inconvenient for adversarial ones.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack surface, OWASP ASVS, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP ASVS | V6 — Authentication | Video KYC relies on strong identity verification before access is granted. |
| Recommendation — Require stronger identity checks and step-up verification for suspicious onboarding sessions. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | KYC onboarding needs verifiable identity assurance suitable for regulated digital journeys. |
| Recommendation — Align onboarding steps to the identity assurance level needed for the account type. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Customer onboarding is a non-organizational identity authentication problem. |
| Recommendation — Use stronger proofing and authentication controls for external user onboarding. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Deepfake KYC failures often start when the identity check is too weak to authenticate the user. |
| Recommendation — Harden authentication steps so spoofed sessions cannot pass initial identity checks. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | KYC decisions govern who is allowed into regulated digital services. |
| Recommendation — Tie onboarding approval to explicit access and verification rules. | ||
Practitioner Guidance
What to prioritise: Treat the verification stack as a decision chain, not a single test. The first priority is to make sure document, biometric, and behavioural signals are independent enough that one compromised control does not collapse the whole onboarding decision.
What to verify: Before trusting the result, confirm that the workflow can detect session manipulation, route suspicious cases to trained reviewers, and preserve evidence for later challenge. If the team cannot explain why a borderline applicant was escalated or approved, the control is too opaque to rely on.
Decision rule: If the session shows synthetic-media indicators or inconsistent user behaviour, step up immediately; if the signals are clean and the customer risk is low, keep the path short. The point is to reserve friction for ambiguity, not to apply maximum friction everywhere.
Practitioner takeaway: Deepfake-resistant KYC is strongest when the user journey is risk-based and the evidence trail is reviewable, because that is what lets teams defend the decision without forcing every legitimate customer through a slow, manual process.
Related resources from NHI Mgmt Group
- How should security teams design liveness checks so they resist spoofing and deepfake attempts without adding too much friction for legitimate users?
- How should fraud teams use device and browser signals to reduce account takeover risk without creating too much friction for legitimate users?
- How should security teams tune AI fraud scores without creating too much customer friction?
- How should businesses build transaction monitoring programs that reduce fraud without creating too much friction for legitimate users?