Use multi-layer detection that evaluates face, device, camera, and behavior signals together, rather than relying on a single liveness check. That approach helps catch injected video, virtual cameras, emulated devices, and synthetic identity attacks before approval. Teams should also watch for low-friction controls that preserve user experience while tightening fraud screening across high-risk verification steps.
Why This Matters for Security Teams
Remote onboarding and step-up verification are no longer simple trust checks. They are adversarial intake points where fraudsters test whether a team can distinguish a real person from injected video, replayed media, emulated devices, or synthetic identity artifacts. Current guidance suggests that single-signal liveness is not enough on its own because attackers can defeat isolated checks while still passing the overall flow.
Identity teams should treat these journeys as risk-based decision points, not one-time gates. That means combining document, face, device, network, and behavior signals, then evaluating them against a policy that can adjust challenge strength in real time. The operational goal is to reduce false approvals without making legitimate users abandon the flow.
This is where broader identity risk patterns matter. NHIMG research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents resulting in tangible damage, which is a reminder that weak identity assurance often becomes a downstream compromise vector in other systems as well, as reflected in the Ultimate Guide to NHIs. For the security posture itself, the baseline should align with NIST Cybersecurity Framework 2.0 so verification controls are managed as an ongoing risk function. In practice, many teams discover deepfake abuse only after a fraudulent account is already funded or a step-up challenge has already been bypassed.
How It Works in Practice
The strongest approach is layered verification that scores the session, not just the selfie. A modern flow typically starts with document capture and face match, then adds camera integrity, device posture, browser or app telemetry, and behavioral patterns such as interaction timing, retry cadence, and navigation consistency. The point is not to create perfect certainty. It is to make spoofing expensive enough that the attacker’s path becomes noisy and detectable.
Step-up verification should be triggered by context, not only by failure. High-risk indicators can include velocity anomalies, IP or device reuse, mismatched geolocation signals, unusual enrollment timing, and repeated identity changes across the same trust boundary. Where the environment supports it, policy should raise friction progressively: a stronger biometric challenge, additional document checks, or a human review queue.
For this to work, teams need explicit controls for injection risk:
- Reject virtual camera sources and known emulation artifacts before liveness scoring.
- Correlate face and document signals with device binding and session continuity.
- Use short-lived step-up tokens so a successful check does not become a reusable bypass.
- Log challenge outcomes, device fingerprints, and reason codes for investigation and tuning.
This pattern aligns with risk-based identity assurance in FATF Recommendations for KYC-driven workflows and with NHIMG guidance in the 52 NHI Breaches Analysis, which is useful when identity assurance failures cascade into credential abuse or account takeover. These controls tend to break down in high-latency mobile environments because network instability can look similar to adversarial tampering and drive false rejections.
Common Variations and Edge Cases
Tighter fraud controls often increase user friction and manual review volume, so organisations must balance detection strength against conversion loss and support cost. That tradeoff becomes sharper in markets with low-bandwidth devices, shared phones, accessibility needs, or cross-border onboarding where document quality and camera performance vary widely.
Best practice is evolving for these edge cases. There is no universal standard for how much weight to give liveness versus device integrity versus behavioral scoring, so teams should calibrate based on fraud loss, customer impact, and local regulatory expectations. In some environments, especially where remote onboarding feeds financial access or regulated services, a conservative policy is justified even if it adds one more step.
Two practical exceptions deserve attention. First, legitimate users on privacy-focused browsers or enterprise-managed devices may suppress telemetry that fraud models expect, which can raise risk scores without indicating abuse. Second, sophisticated attackers may pass one channel consistently, so overreliance on any single vendor score can create a false sense of safety. The better control is continuous tuning: compare false positives, false negatives, and review outcomes, then update thresholds as attack patterns shift. NHIMG’s Top 10 NHI Issues is a useful reminder that identity risk usually appears first as weak visibility, then as active compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | Covers prompt and tool injection patterns that mirror verification-flow abuse. | |
| CSA MAESTRO | Addresses security controls for autonomous and decisioning-heavy workflows. | |
| NIST AI RMF | GOVERN | Supports accountability and oversight for AI-assisted fraud and verification decisions. |
| NIST CSF 2.0 | PR.AA-01 | Identity proofing and access control map directly to verification assurance. |
| NIST SP 800-63 | IAL2 | Identity proofing assurance levels are relevant to remote onboarding rigor. |
Apply layered verification, telemetry correlation, and runtime policy to risk-based onboarding.
Related resources from NHI Mgmt Group
- How should security teams refine identity verification flows for carsharing platforms to reduce fraud and account takeover risk?
- How should healthcare teams reduce ransomware risk in identity flows?
- How should security teams reduce remote-work identity risk for employees using home offices?
- How should security teams reduce identity risk in remote workforce environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org