Use identity verification before the call, and repeat checks during the call when the risk is higher, such as shift changes, sensitive approvals, or spot checks. For finance, HR, legal, and board conversations, pair verification with an audit trail so teams can prove who attended and when. The goal is to reduce trust based only on video or voice.
Why High-Risk Video Calls Need More Than Visual Trust
Video calls now sit inside approval, hiring, treasury, legal, and incident-response workflows, which means a successful impersonation can create direct business impact rather than a simple social-engineering nuisance. High-quality deepfakes, replayed audio, and account takeovers all exploit the same weak point: organisations often treat a live face or familiar voice as proof of identity. NIST Cybersecurity Framework 2.0 is relevant here because the problem is not just authentication, but governance of who is trusted to act in a sensitive business process.
Verification has to reflect the risk of the decision being made, not the convenience of the meeting format. A low-risk team stand-up may only need ordinary meeting access controls, but a payment approval, contract signature, or executive instruction needs stronger identity assurance and a recorded decision trail. In practice, many organisations discover the gap only after a fraud attempt succeeds because the call felt “normal” enough to lower scrutiny.
Where the stakes are higher, organisations should treat the call as one step in a broader identity workflow, not the moment at which identity is established for the first time.
How Verification Should Work During the Call
Effective verification combines pre-call checks, in-call challenge steps, and post-call evidence. The best approach depends on the business action being authorised, but the control objective is consistent: make impersonation harder, make replay or coercion less useful, and make it possible to prove what happened later. NIST SP 800-207 Zero Trust Architecture is relevant because the caller’s identity should not be trusted simply because the session is live; trust must be continuously evaluated against context and assurance.
A practical pattern is to verify the participant before the sensitive agenda starts, then repeat a second check when the decision point arrives. That second check matters because deepfake fraud often succeeds by staying benign until a moment of approval or transfer. Organisations can use a combination of out-of-band confirmation, known-contact validation, signed calendar invitations, one-time verification codes, or internal directory-backed checks. The right method depends on the sensitivity of the interaction and the consequences of a mistake.
- For finance or treasury calls, verify the request through a second channel before funds move.
- For HR or legal calls, confirm the participant against an authorised roster and meeting purpose.
- For board or executive calls, require stronger attendee validation and a preserved audit trail.
- For any call involving urgent change, treat pressure to skip verification as a warning signal.
Video and voice can support identity, but they should not be the deciding evidence when the call authorises a high-impact action. If the call cannot support a reliable second-factor or process control, the organisation should move the decision to a more controlled workflow.
Where Video-Call Verification Breaks Down
Tighter verification often adds friction, so organisations have to balance speed against assurance. That trade-off becomes visible in time-sensitive work, where teams may be tempted to waive checks for senior people, urgent requests, or familiar external contacts. The danger is that familiarity is exactly what impersonation and deepfake fraud are designed to exploit.
One common edge case is a legitimate participant using a new device, a new phone number, or an assistant-managed calendar invitation. Another is a sensitive call that includes several people, where one verified participant is assumed to vouch for everyone else. Neither assumption is safe by default. The question is not whether the person can join the call, but whether the organisation can defend the decision that follows from the call.
NIST SP 800-53 Rev. 5 Security and Privacy Controls is relevant where organisations need stronger process evidence, logging, and access governance around sensitive approvals. Where a call is advisory only, lighter verification may be enough; where it authorises action, the verification standard should rise with the impact. The guidance breaks down when teams rely on the meeting platform itself as proof of identity rather than treating it as only one weak signal among several.
Risk and Threat Considerations
High-risk video calls create exposure when organisations assume that real-time audio or video proves that the participant is genuine. That assumption fails against impersonation, stolen meeting links, account compromise, synthetic media, and coerced or delegated attendance.
Failure mechanism: An attacker or fraudster uses a convincing face, voice, or familiar contact pattern to satisfy casual trust, then pushes the conversation toward an approval, payment, disclosure, or policy exception before stronger verification occurs.
Impact: The organisation may authorise a fraudulent transfer, release confidential information, approve a harmful change, or lose evidentiary confidence about who actually attended and agreed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63, NIST IR 8596 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Oversight of Security and Privacy Risk | High-risk call verification is a governance decision about trust and fraud exposure. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | The question centers on verifying who may participate in a high-risk interaction. | |
| DE.CM-08 — Monitoring for Anomalous Activity | Impersonation and deepfake fraud benefit from weak detection of abnormal participation patterns. | |
| Recommendation — Set verification thresholds for sensitive calls and require oversight when trust decisions change. Apply stronger identity assurance before allowing sensitive call participation. Monitor for unusual participant changes, urgent requests, and verification bypass attempts. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | High-risk calls need stronger identity proofing than casual visual recognition. |
| AAL2 — Authenticator Assurance Level 2 | Repeat checks and step-up verification reduce reliance on a single meeting presence signal. | |
| FAL2 — Federation Assurance Level 2 | Federated or external participant verification needs stronger assertion confidence. | |
| Recommendation — Use higher identity assurance before relying on a participant for sensitive approvals. Require step-up authentication when the call reaches a high-risk decision point. Validate federated identity assertions before accepting external participants in sensitive calls. | ||
| NIST IR 8596 | IR-4 — Incident Handling | Impersonation or deepfake fraud during calls should be handled as a live security event. |
| IR-6 — Incident Reporting | High-risk call fraud needs rapid reporting so affected decisions can be contained. | |
| Recommendation — Treat suspected impersonation as an incident and preserve evidence from the session. Report suspected call fraud quickly so downstream approvals can be stopped. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | Trusted participants must map to known, managed identities rather than ad hoc call presence. |
| 6.3 — Promptly Remove Access for Offboarding | Former staff or stale access can be abused in impersonation and call-based fraud. | |
| Recommendation — Keep participant identities tied to managed accounts and approved business roles. Remove stale identities so former access cannot be reused in sensitive calls. | ||
Practitioner Guidance
What to prioritise: Separate “joining the call” from “authorising the action.” The verification bar should rise only when the meeting moves into a decision, approval, or disclosure that would be costly to reverse.
What to verify: Confirm that the participant check is independent of the call medium. A valid video feed, familiar voice, or reused meeting link is not enough on its own for sensitive business actions.
Decision rule: If the call can trigger a payment, contract, policy exception, or privileged disclosure, require a second assurance step and an auditable record before the action proceeds. If it is purely informational, a lighter check may be acceptable.
Practitioner takeaway: The most reliable control is not “better video detection,” but a process that refuses to let live audiovisual trust stand in for identity assurance when the business consequence is high.
Related resources from NHI Mgmt Group
- How should organisations reduce CEO fraud risk when attackers use executive impersonation and urgent payment requests?
- How should security teams handle identity verification in high-risk video calls?
- What breaks when organisations rely on video alone to verify participants?
- How should organisations reduce the risk of borrowed identities in high-value environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org