Visual review breaks because deepfakes can now look convincing enough to pass a fast human check, while the real decision is whether a live person is present on a trustworthy device. For high-assurance workflows, manual inspection is only advisory. Identity proofing needs liveness, device context, and replay resistance to make the trust decision defensible.
Why visual review fails as assurance
Visual review is attractive because it feels fast and intuitive, but it treats identity proofing as a picture-matching problem rather than an assurance problem. A convincing face is not the same thing as a trustworthy enrollment. Once deepfakes, replayed video, virtual cameras, and other presentation attacks enter the workflow, the reviewer is judging appearance, not presence, continuity, or device trust.
The core failure is that a human reviewer can confirm “someone is on screen” without confirming whether the person is live, whether the content is synthetic, or whether the device and session are part of a trusted proofing path. That gap matters most in remote onboarding, where the control needs to resist replay and impersonation rather than merely look plausible to a fast operator.
For that reason, visual review should be treated as a weak signal, not a decisive control. It can help with exception handling or escalation, but it does not by itself establish the level of assurance needed for high-risk identity proofing decisions.
What trustworthy remote proofing has to verify
remote identity proofing becomes defensible only when it combines multiple signals that are harder to forge together than apart. Liveness checks test that a real person is interacting in the moment. Device context helps determine whether the session originates from a controlled, expected environment. Replay resistance reduces the chance that a previously captured image, stream, or recording can be reused to pass the process.
That is why the trust decision shifts away from “does this look right?” toward “is this live, bound to the current device and session, and resistant to reuse?” When those elements are missing, the proofing step is vulnerable to low-friction fraud because an attacker only needs to satisfy the reviewer, not the underlying assurance model.
Systems that support stronger proofing usually make the reviewer one input among several, not the final arbiter. In practice, the workflow should be designed so the machine-enforced checks carry the assurance burden and the human step handles ambiguity, exception triage, or fraud review.
Where organisations usually overestimate control strength
The common mistake is assuming that “manual review” becomes stronger because it is human-led. In reality, it often creates a false sense of confidence, especially when reviewers are under time pressure, using inconsistent criteria, or asked to approve borderline cases without strong supporting signals. A polished deepfake can look more credible than a poor-quality live capture.
Another weak point is that organisations sometimes measure reviewer consistency rather than fraud resistance. A process can be highly repeatable and still be easy to deceive. If the proofing workflow does not bind the person, the device, and the current session together, the attacker can exploit the gap between appearance and assurance.
For identity teams, this is the point at which policy, user experience, and fraud tolerance need to align. High-assurance workflows should not ask staff to solve by eye what the control design itself has failed to verify.
Risk and Threat Considerations
Remote visual review is exposed to synthetic media and replay abuse because attackers only need to pass a short human judgement window. Once a deepfake or injected stream is convincing enough, the reviewer may approve a fraudulent enrollment that later becomes the attacker’s durable foothold.
Failure mechanism: The control fails when the decision depends on visual plausibility instead of liveness, device trust, and anti-replay signals, allowing an attacker to substitute synthetic presence for real presence.
Impact: The organisation may onboard the wrong person, weaken downstream account recovery, and create an identity record that is difficult to unwind after fraud or takeover.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, OWASP ASVS and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Defines remote identity proofing, liveness, and assurance levels for trustworthy enrollment. |
| Recommendation — Apply identity assurance and proofing requirements before accepting remote enrollment evidence. | ||
| OWASP ASVS | V6 — Authentication | Remote proofing depends on strong identity verification and anti-replay signals before access is issued. |
| Recommendation — Require stronger verification than visual approval before granting authenticated access. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Remote proofing failures directly affect how reliably users are identified and authenticated. |
| IA-5 — Authenticator Management | Proofing workflows often rely on controlled issuance and lifecycle of authenticators after enrollment. | |
| IA-8 — Identification and Authentication (Non-Organizational Users) | Remote onboarding and customer proofing require assurance for external identity claims. | |
| Recommendation — Verify identity evidence and authentication strength before establishing user accounts. Bind authenticator issuance to validated proofing evidence and rotate suspect credentials promptly. Use stronger proofing and verification for external users before account activation. | ||
Practitioner Guidance
What to prioritise: Treat the proofing step as an assurance workflow, not a reviewer workflow. If the process can grant access, approve onboarding, or establish a durable identity record, the machine-verified signals need to be stronger than the human impression.
What to verify: Confirm that the workflow actually checks liveness, ties the session to a trustworthy device, and resists replay or virtual camera injection. If any one of those checks is missing, visual review should be treated as advisory only.
What good looks like: A reviewer can still escalate edge cases, but the system itself decides whether the proofing evidence is live, current, and bound to the expected context before trust is granted.
Practitioner takeaway: If a remote proofing process can be fooled by looking convincing, it is not proving identity at the assurance level the business usually thinks it is.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on basic identity checks instead of full due diligence for remote customers?
- What breaks when organisations rely on manual review for every identity alert?
- What breaks when organisations rely on helpdesk verification without stronger identity proofing?
- What breaks when organisations rely on device-centric identity controls in remote work environments?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org