Use identity verification before the call, and repeat checks during the call when the risk is higher, such as shift changes, sensitive approvals, or spot checks. For finance, HR, legal, and board conversations, pair verification with an audit trail so teams can prove who attended and when. The goal is to reduce trust based only on video or voice.
Why This Matters for Security Teams
High-risk video calls are now a realistic fraud channel because attackers can combine stolen credentials, cloned voices, and live deepfake video to bypass normal “seen on screen” trust. The problem is not only impersonation at join time. It is also the risk of false authority during approvals, finance requests, HR actions, and board-level decisions. Current guidance suggests that video presence should be treated as a weak signal, not proof of identity.
This is where identity assurance, call-time verification, and auditability need to work together. The NIST Cybersecurity Framework 2.0 treats identity and access as an operational control area, while NIST Cybersecurity Framework 2.0 and NIST SP 800-207 Zero Trust Architecture both reinforce continuous verification rather than one-time trust. For NHI governance context, NHI Mgmt Group’s Ultimate Guide to NHIs — Why NHI Security Matters Now is useful because the same failure pattern appears here: overreliance on credentials or surface signals without proving who is actually behind the interaction. In practice, many security teams discover impersonation only after an approved payment, record change, or confidential disclosure has already occurred, rather than through intentional verification design.
How It Works in Practice
Effective verification for high-risk calls should be layered, not theatrical. Start with identity proofing before the meeting, then add a second check during the call when the interaction becomes sensitive. That may include a pre-shared code delivered out-of-band, a callback to a known number, confirmation through a managed identity portal, or a policy-driven step-up check before any approval is accepted. For regulated or high-value workflows, teams should also log who verified whom, when, and by what method.
That approach aligns with zero trust thinking: trust is granted per event, not because a face appears on camera. It also matches the operational lesson in Top 10 NHI Issues, where weak governance often comes from assuming a visible session means a legitimate actor. The same control logic applies to video fraud. Teams should define risk triggers such as change of bank details, termination discussions, privileged access requests, emergency payments, or board actions. At those points, verification should escalate from “attendance confirmed” to “identity re-confirmed.”
- Use a known, trusted directory or IAM workflow for attendee validation before joining.
- Require step-up verification for approvals, account changes, and confidential decisions.
- Record the verification method, time, and participant identity in an auditable trail.
- Train staff to treat voice and video as useful cues, not authoritative proof.
The control set is strengthened by policy discipline and by correlating call records with access logs, but it breaks down in fast-moving incident response bridges and executive war rooms because participants often join from unplanned devices, shared links, or cross-border numbers.
Common Variations and Edge Cases
Tighter call verification often increases friction, so organisations must balance fraud resistance against meeting urgency and executive convenience. That tradeoff is real: the more sensitive the decision, the less acceptable it is to rely on informal recognition alone. Best practice is evolving, but there is no universal standard yet for how much identity assurance every video call should require.
In lower-risk meetings, a lightweight check may be enough. In high-risk scenarios, the bar should be higher and the process should be repeatable across finance, HR, legal, and board operations. Deepfake fraud also changes the playbook for multilingual meetings, outsourced teams, and geographically distributed leadership, where voice recognition is weaker and cultural expectations around identity checks may differ. The safest approach is to standardise verification triggers by risk, not by role seniority.
For teams that want a formalised control model, NIST CSF 2.0 supports governance and response planning, while the NHI security guidance in Ultimate Guide to NHIs — Key Challenges and Risks helps teams think in terms of proof, traceability, and revocation rather than trust by appearance alone. The practical rule is simple: if a bad actor could cause financial, legal, or personnel harm by sounding convincing on video, then the organisation should verify identity out of band before it approves anything.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity assurance is central to preventing impersonation in video-based approvals. |
| NIST Zero Trust (SP 800-207) | 4.2 | Zero trust supports continuous verification instead of trusting a visible participant. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Weak identity proofing and trust assumptions mirror common NHI verification failures. |
| CSA MAESTRO | IAM-1 | Agent and workload identity patterns inform stronger verification and audit trails. |
| NIST AI RMF | AI risk management covers deepfake-driven impersonation and trust degradation. |
Assess deepfake fraud as an AI trust risk and define controls for detection, verification, and response.
Related resources from NHI Mgmt Group
- How should organisations reduce CEO fraud risk when attackers use executive impersonation and urgent payment requests?
- How should security teams handle identity verification in high-risk video calls?
- What breaks when organisations rely on video alone to verify participants?
- How should organisations reduce the risk of borrowed identities in high-value environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org