Payment companies should combine strong document and biometric checks with liveness detection, risk-based step-up review, and continuous monitoring after onboarding. Deepfakes can defeat a one-time control, so verification must extend across the full customer journey. Teams should also tune review thresholds for local fraud patterns and escalate accounts that show mismatched identity signals or unusual transaction behaviour.
Why This Matters for Security Teams
Deepfakes and synthetic identities turn onboarding into a control-testing exercise: attackers are no longer trying to defeat a single document check, but to assemble a believable identity narrative across documents, faces, device signals, and account behavior. For payment companies, that creates direct exposure to fraud losses, mule activity, chargebacks, and regulatory scrutiny under KYC and AML expectations. Current guidance from the FATF Recommendations emphasizes risk-based customer due diligence, which matters because synthetic identities often look clean at the point of entry.
The practical mistake is treating onboarding as a one-time pass or fail event. That approach leaves a gap between initial verification and later misuse, especially when the same identity is reused across multiple accounts or paired with a different device, funding source, or behavioral profile. NHIMG research on the Ultimate Guide to Non-Human Identities shows how often organisations underestimate identity risk when controls are static and visibility is limited, and the same pattern shows up in payment onboarding when review thresholds are too rigid. In practice, many security teams encounter synthetic identity abuse only after the first fraudulent transactions have already cleared, rather than through intentional pre-onboarding detection.
How It Works in Practice
Strong onboarding for payment companies should layer independent signals so that one manipulated signal does not dominate the decision. Document verification still matters, but it should be paired with liveness detection, face-to-document comparison, device fingerprinting, velocity checks, and risk-based step-up review. For higher-risk cohorts, best practice is evolving toward continuous verification across the customer lifecycle, not just at account creation.
A workable pattern is to score the applicant in real time and route only the riskiest cases to manual review. That means combining identity proofing with operational context: IP reputation, geolocation anomalies, payment instrument quality, prior application history, and whether the same attributes appear across multiple identities. This is consistent with FATF’s risk-based approach and with the broader fraud-control principle that onboarding signals should be revisited when behavior changes.
- Use liveness and presentation-attack resistance to reduce photo, replay, and deepfake spoofing.
- Require stronger step-up checks when device, network, or document signals conflict.
- Compare onboarding data against internal watchlists and repeat-application patterns.
- Trigger post-onboarding monitoring when transaction velocity, funding source, or beneficiary behavior diverges.
NHIMG research on JetBrains GitHub plugin token exposure and Hard-Coded Secrets in VSCode Extensions reinforces a broader lesson: trust breaks down when organisations assume a single control is enough and fail to monitor what happens after the first trust decision. These controls tend to break down when onboarding is fully automated, review queues are under-resourced, and synthetic identities are being created at scale because false positives and false negatives both rise sharply.
Common Variations and Edge Cases
Tighter onboarding often increases customer friction, so payment companies have to balance fraud reduction against abandonment, especially for legitimate users in thin-file or newly relocated populations. There is no universal standard for this yet, and current guidance suggests using graduated controls rather than forcing every applicant through the same high-friction path.
Edge cases matter. High-risk corridors, prepaid funding, marketplace sellers, and cross-border remitters often need stricter step-up rules than low-value consumer wallets. Conversely, trusted returning customers may warrant lighter checks if their device, funding source, and transaction pattern remain stable. Manual review teams should also be trained to spot synthetic identity tells such as inconsistent age progression, reused images, subtle facial artifacts, or rapid account creation bursts that align with local fraud campaigns.
Payment firms should also avoid over-relying on biometric scores alone. Deepfakes continue to improve, and a biometric match without corroborating device or behavioral evidence is not enough. The strongest programs combine onboarding controls with post-onboarding monitoring, case management, and rapid account restriction when the risk picture changes. The challenge is hardest where customer acquisition is outsourced or multi-step onboarding is fragmented across vendors, because inconsistent evidence handling weakens the entire decision chain.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A01 | Covers identity abuse and trust failures in automated verification flows. |
| CSA MAESTRO | TRUST-02 | Addresses runtime trust decisions and continuous evaluation for digital identities. |
| NIST AI RMF | Supports risk-based governance for AI-influenced identity verification decisions. | |
| NIST CSF 2.0 | PR.AA-01 | Identity proofing and access assurance align to strong authentication outcomes. |
| NIST SP 800-63 | IAL2 | Identity proofing level is central to resisting synthetic identity enrollment. |
Treat onboarding automation as a high-risk trust boundary and add layered challenge-response checks.
Related resources from NHI Mgmt Group
- Why do deepfakes and synthetic identities break traditional verification models?
- Why do synthetic identities bypass many verification processes?
- How should security teams handle verification in regulated payment onboarding?
- How should security teams respond when synthetic identities pass verification checks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org