Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What happens when video-based identity verification is used…
Authentication, Authorisation & Trust

What happens when video-based identity verification is used without strong forgery checks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

Without strong forgery checks, video-based verification can be bypassed by pre-recorded footage, spoofing, or manipulated identity documents. That creates a false sense of assurance and allows fraudulent applicants to pass onboarding. The result is higher exposure to account takeover, identity fraud, and audit findings when the process cannot prove that the person is genuine.

How weak forgery checks change the outcome of video verification

Video-based verification only works when the system can distinguish a live person from reused media, injected video, or altered identity evidence. Once strong forgery checks are missing, the control shifts from verifying presence and authenticity to simply accepting a stream that looks plausible. That makes the process easy to satisfy with pre-recorded footage, spoofed camera input, or manipulated documents.

The practical failure is not just that one check is weaker. It is that the whole onboarding decision starts relying on appearance rather than assurance. A well-formed video can satisfy a reviewer or an automated workflow even when the person behind it is not genuine, which is why identity proofing needs to include document authenticity, liveness, and presentation-attack resistance together. NHIMG’s Identity Proofing and KYC Guide and the FATF Recommendations both reinforce that customer due diligence is only as strong as the assurance behind the verification step.

When forgery resistance is absent, the system may still produce a “verified” outcome, but that label no longer means the applicant was genuinely present or genuine in identity terms. In practice, the most dangerous cases are the ones that look routine, because the process appears to work while the attacker silently substitutes a fake identity, a stolen identity, or a synthetic one. That is why a reliable verification flow has to treat video as one signal, not the proof itself.

Where the fraud risk shows up after onboarding

The immediate consequence is false acceptance, but the downstream impact is broader. Fraudulent applicants who pass onboarding can obtain accounts, payment access, or platform privileges under a trusted identity record, which creates a durable trust error that is difficult to unwind later. The result is higher exposure to account takeover, mule activity, synthetic identity abuse, and audit findings when the organisation cannot evidence that the verified subject was real.

That risk is especially sharp in remote onboarding because the verifier often lacks a second independent trust anchor. If the process does not check for injection, replay, or manipulated source media, an attacker can preserve a believable front-end while bypassing the control behind it. NHIMG’s Identity Verification Buyer’s Guide is useful here because it frames vendor choice around document checks, liveness, injection defence, and fraud signals rather than surface-level video quality. The same issue is why NIST SP 800-63 Digital Identity Guidelines remain relevant when the question is assurance, not just usability.

For regulated onboarding, the failure can also become a governance problem. If the control cannot demonstrate why the verifier trusted the applicant, the organisation may be unable to defend its identity-proofing decision during review, remediation, or dispute handling. That is often where the operational cost becomes visible, because teams then need to investigate fraud after the fact instead of preventing it at the point of entry.

What strong forgery checks need to prove

Strong forgery checks are not a single feature. They need to test whether the input is live, whether the video source is trustworthy, and whether supporting identity documents are genuine enough to support the claim being made. In practice, that means checking for replay, virtual-camera injection, deepfake or face-swap manipulation, document tampering, and abnormal capture conditions that break the link between the person and the evidence.

The most useful design principle is to make the verification decision depend on independent signals that are difficult to fake at the same time. Video, document validation, capture integrity, and risk scoring should reinforce each other. NHIMG’s FATF Recommendations support the broader onboarding requirement for customer due diligence, while the OWASP ASVS provides a useful reminder that authentication, session handling, and access control only work when the upstream identity assumption is trustworthy.

Practically, the question to ask is whether a forged or replayed video could still satisfy the workflow without triggering a separate trust failure. If the answer is yes, the control is not doing enough to protect the onboarding decision. That is the point where teams should treat the process as a fraud-enabling path, not just a user-experience issue.

Risk and Threat Considerations

Without forgery resistance, video verification becomes vulnerable to replay, spoofing, synthetic media, and manipulated capture sources. The risk is not only mistaken identity at the point of onboarding, but the creation of trusted accounts that can later be abused for fraud, chargeback activity, laundering, or post-verification account takeover.

Failure mechanism: The control accepts evidence that is visually convincing but not provenance-assured, so an attacker can substitute prerecorded or altered media for a genuine live identity proofing event.

Impact: False approvals propagate into downstream systems as legitimate accounts, increasing fraud loss, operational investigation cost, and the likelihood of adverse audit or compliance findings.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesIdentity proofing assurance and liveness concerns align directly with these guidelines.
Recommendation — Apply identity assurance checks that resist replay and forged evidence.
OWASP ASVSV6 — AuthenticationForgery-resistant verification supports trustworthy authentication decisions.
V8 — AuthorizationBad verification can grant accounts and access on a false identity basis.
V16 — Security Logging and Error HandlingFraudulent verification attempts need evidence and traceability for review.
Recommendation — Verify that upstream identity proofing cannot be bypassed by fake media. Ensure authorization decisions are not built on untrusted onboarding evidence. Log failed and suspicious verification attempts for investigation and audit.

Practitioner Guidance

What to prioritise: Treat forgery resistance as a control requirement, not a nice-to-have feature. If the workflow cannot distinguish live capture from replay or injection, prioritise liveness and document-authenticity checks before expanding volume or automating approvals.

What to verify: Confirm that the verification stack tests for replay, virtual-camera use, manipulated documents, and abnormal session behaviour, and that those detections are tied to a clear reject or step-up decision.

Common mistake: Teams often over-trust a polished video path and under-test the attacker’s ability to feed the system synthetic or reused media. The system may look accurate in demos while remaining fragile in real onboarding conditions.

Practitioner takeaway: If the platform cannot prove the applicant was genuinely present and the evidence was not forged, the verification result should be treated as weak assurance, not successful identity proofing.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org