Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should payment companies strengthen onboarding when deepfakes…
Identity Beyond IAM

How should payment companies strengthen onboarding when deepfakes and synthetic identities are being used to bypass verification?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Identity Beyond IAM

Payment companies should combine strong document and biometric checks with liveness detection, risk-based step-up review, and continuous monitoring after onboarding. Deepfakes can defeat a one-time control, so verification must extend across the full customer journey. Teams should also tune review thresholds for local fraud patterns and escalate accounts that show mismatched identity signals or unusual transaction behaviour.

Why This Matters for Security Teams

Deepfakes and synthetic identities turn onboarding into a control-testing exercise: attackers are no longer trying to defeat a single document check, but to assemble a believable identity narrative across documents, faces, device signals, and account behavior. For payment companies, that creates direct exposure to fraud losses, mule activity, chargebacks, and regulatory scrutiny under KYC and AML expectations. Current guidance from the FATF Recommendations emphasizes risk-based customer due diligence, which matters because synthetic identities often look clean at the point of entry.

The practical mistake is treating onboarding as a one-time pass or fail event. That approach leaves a gap between initial verification and later misuse, especially when the same identity is reused across multiple accounts or paired with a different device, funding source, or behavioral profile. NHIMG research on the Ultimate Guide to Non-Human Identities shows how often organisations underestimate identity risk when controls are static and visibility is limited, and the same pattern shows up in payment onboarding when review thresholds are too rigid. In practice, many security teams encounter synthetic identity abuse only after the first fraudulent transactions have already cleared, rather than through intentional pre-onboarding detection.

How It Works in Practice

Strong onboarding for payment companies should layer independent signals so that one manipulated signal does not dominate the decision. Document verification still matters, but it should be paired with liveness detection, face-to-document comparison, device fingerprinting, velocity checks, and risk-based step-up review. For higher-risk cohorts, best practice is evolving toward continuous verification across the customer lifecycle, not just at account creation.

A workable pattern is to score the applicant in real time and route only the riskiest cases to manual review. That means combining identity proofing with operational context: IP reputation, geolocation anomalies, payment instrument quality, prior application history, and whether the same attributes appear across multiple identities. This is consistent with FATF’s risk-based approach and with the broader fraud-control principle that onboarding signals should be revisited when behavior changes.

  • Use liveness and presentation-attack resistance to reduce photo, replay, and deepfake spoofing.
  • Require stronger step-up checks when device, network, or document signals conflict.
  • Compare onboarding data against internal watchlists and repeat-application patterns.
  • Trigger post-onboarding monitoring when transaction velocity, funding source, or beneficiary behavior diverges.

NHIMG research on JetBrains GitHub plugin token exposure and Hard-Coded Secrets in VSCode Extensions reinforces a broader lesson: trust breaks down when organisations assume a single control is enough and fail to monitor what happens after the first trust decision. These controls tend to break down when onboarding is fully automated, review queues are under-resourced, and synthetic identities are being created at scale because false positives and false negatives both rise sharply.

Common Variations and Edge Cases

Tighter onboarding often increases customer friction, so payment companies have to balance fraud reduction against abandonment, especially for legitimate users in thin-file or newly relocated populations. There is no universal standard for this yet, and current guidance suggests using graduated controls rather than forcing every applicant through the same high-friction path.

Edge cases matter. High-risk corridors, prepaid funding, marketplace sellers, and cross-border remitters often need stricter step-up rules than low-value consumer wallets. Conversely, trusted returning customers may warrant lighter checks if their device, funding source, and transaction pattern remain stable. Manual review teams should also be trained to spot synthetic identity tells such as inconsistent age progression, reused images, subtle facial artifacts, or rapid account creation bursts that align with local fraud campaigns.

Payment firms should also avoid over-relying on biometric scores alone. Deepfakes continue to improve, and a biometric match without corroborating device or behavioral evidence is not enough. The strongest programs combine onboarding controls with post-onboarding monitoring, case management, and rapid account restriction when the risk picture changes. The challenge is hardest where customer acquisition is outsourced or multi-step onboarding is fragmented across vendors, because inconsistent evidence handling weakens the entire decision chain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10A01Covers identity abuse and trust failures in automated verification flows.
CSA MAESTROTRUST-02Addresses runtime trust decisions and continuous evaluation for digital identities.
NIST AI RMFSupports risk-based governance for AI-influenced identity verification decisions.
NIST CSF 2.0PR.AA-01Identity proofing and access assurance align to strong authentication outcomes.
NIST SP 800-63IAL2Identity proofing level is central to resisting synthetic identity enrollment.

Treat onboarding automation as a high-risk trust boundary and add layered challenge-response checks.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org