Financial institutions should use a layered identity approach rather than relying on passwords or one-time passcodes alone. Stronger controls include liveness detection, verified credentials, adaptive authentication, and policy-based access controls. These measures help validate that a person is real, that presented data is trustworthy, and that access decisions reflect current context before money moves or sensitive records are exposed.
Why This Matters for Security Teams
Deepfake attacks turn onboarding and payment authorisation into a trust problem, not just an authentication problem. A synthetic face, voice, or document can satisfy weak checks while the underlying identity remains unverified. That is why financial institutions need layered controls that assess personhood, document integrity, device trust, and transaction context together, rather than treating an OTP as a sufficient signal.
This is especially important where fraud teams, compliance teams, and IAM teams still operate in separate lanes. When identity proofing is too loose, attackers can open accounts, add payees, and move quickly into high-value transactions before manual review catches up. Current guidance suggests aligning stronger identity proofing with the risk level of the activity, as described in NIST SP 800-63 Digital Identity Guidelines and the control-oriented approach in NIST Cybersecurity Framework 2.0.
NHIMG’s research on NHI exposure is a useful reminder of the broader pattern: in the 2024 ESG Report, Oasis Security & ESG found that 72% of organisations have experienced or suspect a breach of non-human identities. In practice, many financial institutions first discover deepfake-enabled identity weaknesses after a fraudulent account or transfer has already been approved, rather than through intentional testing.
How It Works in Practice
The strongest defence is a risk-based identity stack that checks more than one signal at once. For onboarding, that usually means liveness detection, document verification, device reputation, behavioural signals, and step-up review when the confidence level drops. For high-value transactions, it means binding the approval to a strong identity event, then re-evaluating risk at the moment of transfer instead of relying on the original login.
Institutions should also tighten the distinction between identity proofing and transaction authorisation. A user may be properly onboarded but still require additional checks before changing beneficiaries, increasing limits, or moving funds to a new destination. The operational goal is to make fraud harder to scale, not merely to collect more data.
- Use verified credentials and document checks to raise the cost of synthetic onboarding.
- Apply adaptive authentication when risk signals change, such as device change, unusual geography, or payee creation.
- Set policy-based approval rules for high-value transfers, with manual review for exceptions.
- Log proofing outcomes, challenge results, and transaction context for fraud analytics and audit.
Where this becomes more effective is in environments that can link identity proofing to transaction policy in real time, supported by auditability and strong governance. That direction is consistent with Ultimate Guide to NHIs for lifecycle control and with Top 10 NHI Issues for the risks that appear when identity trust is overly broad. These controls tend to break down in call-centre-heavy or branch-heavy environments because manual overrides and inconsistent escalation paths create easy openings for social engineering.
Common Variations and Edge Cases
Tighter onboarding and payment controls often increase friction, so institutions have to balance fraud reduction against abandonment, customer support volume, and false declines. That tradeoff is real, especially for retail banking, cross-border customers, and older identity documents that are harder to validate automatically.
There is no universal standard for every edge case yet. Current guidance suggests treating high-risk events differently from routine activity, but the threshold for step-up checks will vary by product, channel, and jurisdiction. For example, a first-time wire transfer to a new beneficiary should not use the same approval path as a recurring bill payment, and a high-net-worth client may require an alternative path that preserves both security and service.
Institutions should also be careful not to overtrust a single strong signal. Deepfake attacks can bypass one layer while failing another, so the resilience comes from correlation across identity proofing, device trust, behaviour, and transaction intent. When a workflow depends on live video alone, or on static knowledge questions, the controls usually fail once attackers adapt their synthetic media and coaching tactics.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Strong identity proofing and least privilege reduce synthetic account abuse. |
| CSA MAESTRO | GOV-02 | Governance is needed when risk-based decisions span onboarding and payments. |
| NIST AI RMF | AI RMF supports managing synthetic media and deepfake risk across workflows. | |
| NIST SP 800-63 | IAL2 | Identity proofing assurance levels map directly to onboarding confidence needs. |
| NIST CSF 2.0 | PR.AA-01 | Adaptive access and authentication fit risk-based transaction controls. |
Tie onboarding identities to verified proofing signals and limit default access at each lifecycle stage.
Related resources from NHI Mgmt Group
- How should financial institutions reduce fraud risk when onboarding users across stablecoin and banking rails?
- How should financial institutions build identity controls that reduce both insider risk and external attack exposure?
- How should financial institutions reduce credential abuse in high-risk workflows?
- How should financial institutions reduce fraud risk when compliance operations are still fragmented across channels and teams?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org