Payment companies should combine strong document and biometric checks with liveness detection, risk-based step-up review, and continuous monitoring after onboarding. Deepfakes can defeat a one-time control, so verification must extend across the full customer journey. Teams should also tune review thresholds for local fraud patterns and escalate accounts that show mismatched identity signals or unusual transaction behaviour.
Why payment onboarding becomes the first fraud choke point
For payment companies, onboarding is where synthetic identities, stolen attributes, and deepfake-assisted impersonation can pass as legitimate customers before any meaningful transaction monitoring has a chance to help. That makes the quality of the initial identity check a business integrity issue, not just a fraud-screening detail. If verification is weak, downstream controls inherit bad identity data and false trust. In practice, many payment teams discover the gap only after accounts have already been used to move funds or test mule behaviour.
FATF’s guidance on customer due diligence is relevant here because it treats identity assurance as part of the wider AML and KYC obligation rather than a one-time formality; that broader framing fits payment onboarding better than a narrow document-check mindset. For teams dealing with deepfakes, the practical lesson is that visual similarity alone is no longer a safe proxy for personhood, and any control that depends on a single captured image or short interaction window is easier to game than most operators assume.
How onboarding controls need to work together
Stronger onboarding works best when it is layered and state-aware. Document verification can still be useful, but it should not be treated as decisive on its own. Biometric checks need liveness testing that looks for signs of replay, presentation attack, or generated media, and the system should treat failure patterns, retries, and device inconsistencies as signals rather than noise. Risk-based step-up review matters because not every applicant should face the same friction: low-risk applications may proceed with automated verification, while high-risk combinations such as mismatched geolocation, disposable contact details, or repeated identity reuse should trigger manual review.
Payment companies also need to connect onboarding to what happens after activation. A synthetic identity often looks normal at the point of entry and only becomes visible once it starts transacting, adding beneficiaries, or changing account settings. That means onboarding controls should feed continuous monitoring, and the monitoring should feed back into the onboarding model. The most effective operators maintain a single identity risk view that can correlate document confidence, biometric assurance, device reputation, payment behaviour, and account lifecycle signals.
- Use document and biometric checks as separate signals, not as interchangeable proof.
- Apply liveness detection that is tested against replay, injection, and generated-media abuse.
- Escalate mixed-confidence cases to human review instead of forcing an automatic pass or fail.
- Carry onboarding risk scores into post-onboarding monitoring so later behaviour can confirm or weaken the original trust decision.
- Retune thresholds by region, channel, and fraud pattern so controls do not drift away from actual attack conditions.
This approach breaks down when verification is treated as a closed event and the organisation cannot reconcile onboarding signals with live account behaviour.
Where deepfakes and synthetic identities create the hardest edge cases
Tighter identity checks often increase customer friction and operational review load, so payment companies have to balance conversion rates against the cost of letting high-confidence fraud through. That tradeoff becomes sharper when attackers blend real and fake attributes, because the application may look individually plausible even though the identity is composite. Industry guidance is clear on the need for due diligence, but there is less consensus on the exact threshold at which automation should stop and human judgement should begin.
The hardest cases are not always the most obviously fake. A synthetic identity may be built from valid data points, while a deepfake is used only to clear the last mile of verification. That means teams should be cautious about over-trusting any single signal, including document similarity, selfie match score, or voice recognition. A strong control can still fail if the attacker only needs to satisfy it once. Where the business has cross-border onboarding, remote-only enrolment, or heavy dependence on third-party verification providers, those edge cases deserve extra scrutiny because the weakest link may sit outside the payment company’s direct control.
One external reference that helps frame the governance pressure is the FATF customer due diligence model, but the operational decision still belongs to the payment company: if a control can be bypassed by high-quality synthetic media, it should be treated as a screening layer, not as the final trust decision.
Risk and Threat Considerations
Deepfakes and synthetic identities create a material onboarding fraud risk because they exploit the assumption that a captured face, document, or short live interaction proves a real, unique customer. The exposure is highest where onboarding is optimised for speed, remote self-service, and low-friction approval, because those conditions reduce the defender’s ability to spot reused attributes and manipulated media.
Failure mechanism: An attacker combines fabricated or stolen identity attributes with generated images, video, or voice to satisfy a one-time verification flow, then uses the approved account to open payment pathways, launder fraud proceeds, or establish a trusted foothold for later misuse. The control failure usually comes from over-reliance on point-in-time verification and weak correlation between onboarding evidence and later account behaviour.
Impact: The company can onboard accounts that are not tied to a trustworthy real-world identity, increasing fraud loss, chargeback exposure, AML pressure, manual review burden, and remediation cost. Over time, the identity store itself becomes less reliable, which weakens risk scoring for the rest of the customer base.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | Onboarding depends on reliable identity proofing and authentication evidence. |
| DE.CM-08 — Monitoring for Anomalous Activity | Post-onboarding monitoring is needed to detect synthetic identity behaviour after approval. | |
| Recommendation — Strengthen identity assurance before granting account access or payment capability. Correlate onboarding signals with live activity to detect anomalous account behaviour. | ||
| CIS Controls v8 | 6 — Access Control Management | Onboarding should restrict account access until identity confidence is sufficient. |
| 14 — Security Awareness and Skills Training | Review teams need training to spot deepfake and synthetic-identity patterns. | |
| Recommendation — Enforce least-privilege account activation until verification confidence is established. Train reviewers to recognise manipulated media and composite identity indicators. | ||
| NIST SP 800-63 | 63A — Identity Proofing | Identity proofing directly addresses remote onboarding against fabricated identities. |
| 63B — Authentication and Lifecycle Management | Lifecycle controls help prevent a one-time verification from becoming permanent trust. | |
| Recommendation — Increase identity proofing assurance when remote applicants present higher fraud risk. Link authentication strength to lifecycle events so trust can be downgraded later. | ||
| MITRE ATT&CK | T1656 — Impersonation | Deepfakes support impersonation during verification and account creation. |
| Recommendation — Map impersonation attempts to T1656 and tune detection for synthetic media abuse. | ||
Practitioner Guidance
What to prioritise: Treat onboarding assurance as a layered decision, not a single pass/fail event. The first priority is to separate evidence of document authenticity, biometric presence, and behavioural consistency, because deepfakes usually succeed when those signals are collapsed into one score.
Decision rule: If the application combines low-history contact data, repeated retries, device inconsistency, or unusual geography, route it to step-up review even when the biometric match appears strong. High-confidence synthetic activity often looks “good enough” on any single measure.
What to verify: Verify that post-onboarding monitoring can challenge the original trust decision. If later account behaviour never feeds back into onboarding thresholds, the company is learning too late and is effectively running two disconnected control systems.
Practitioner takeaway: The strongest onboarding programs do not try to “detect deepfakes” in isolation; they build a trust decision that can survive adversarial media, composite identities, and delayed fraud signals.
Related resources from NHI Mgmt Group
- Why do deepfakes and synthetic identities break traditional verification models?
- Why do synthetic identities bypass many verification processes?
- Why do synthetic identities and deepfakes force identity verification to become regulated infrastructure?
- How should security teams handle verification in regulated payment onboarding?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org