Banks should move identity proofing toward layered assurance: document authenticity checks, liveness detection, fraud analytics and escalation paths for anomalies that simple selfie matching cannot resolve. The aim is to detect manipulation at capture time, before an account is created and before downstream AML controls have to clean up the failure.
Why synthetic media changes applicant verification
Synthetic faces, voices, and documents weaken the old assumption that a good image is evidence of a real person. In banking, that matters because onboarding is a trust gate: if the applicant is fabricated, the institution can create an account, extend fraud exposure, and trigger remediation work across fraud, compliance, and operations. The practical response is to verify the applicant through multiple independent signals, not one polished capture.
A resilient onboarding design treats the selfie or video as one input, not the proof itself. Banks should compare document features, capture integrity, device and network signals, and behavioural consistency so that spoofing has to defeat several controls at once. That shifts the problem from “is this media convincing?” to “does the full application package remain internally consistent?”
For a broader view of impersonation and deepfake-enabled fraud, see Deepfakes, Social Engineering and AI Impersonation Guide, which covers callback verification and identity-based checks.
Where layered assurance belongs in the onboarding flow
Layered assurance should be applied before account creation, not as a cleanup step after the customer is already live. That means document authenticity checks, liveness detection, metadata and device-risk analysis, and human review for edge cases must be part of the initial decision path. Once synthetic media passes into the customer record, downstream controls are already working with a false premise.
The strongest programs separate routine approvals from exceptional cases. Straight-through processing can continue for low-risk, high-confidence applicants, but any anomaly in document quality, capture behaviour, identity history, geolocation, or contactability should trigger escalation rather than automatic rejection or automatic approval. That escalation path is essential because synthetic media often looks normal until several weak signals are considered together.
Governance also matters. Banks need clear ownership for model tuning, review thresholds, false-positive handling, and exception approval, because weak escalation design creates bottlenecks on one side and blind spots on the other. The right question is not whether to use automation, but where the institution wants human judgement to override machine confidence.
For identity proofing standards and assurance concepts, NIST SP 800-63 Digital Identity Guidelines remain a useful reference point for authentication strength and assurance thinking.
What banks should monitor beyond the selfie
The best detections are usually the ones that synthetic media alone cannot manipulate easily. Banks should look for inconsistencies across document font and template behaviour, image compression artifacts, replay signs, session anomalies, device reputation, velocity patterns, and repeated enrolment attempts from the same infrastructure. Those signals help distinguish a legitimate applicant from an industrialised fraud workflow.
Fraud analytics should also correlate identity proofing events with later account behaviour. If an applicant clears onboarding too cleanly but immediately shows mule-like transaction patterns, contact changes, password resets, or login geography shifts, the original proofing decision deserves review. That feedback loop is what turns onboarding controls into an adaptive fraud signal, rather than a one-time gate.
Technical controls should be paired with a manual path that can request alternate evidence, such as a live callback, additional verification document, or in-branch or assisted completion. Where the bank serves high-risk products or high-value customers, a stricter step-up path is justified because the cost of a false acceptance is usually much higher than the cost of one more verification step.
Risk and Threat Considerations
Synthetic media creates a direct onboarding fraud risk because the attacker’s objective is not merely to look convincing, but to pass identity proofing with a fabricated or stolen persona. Once that happens, the false customer can be used for mule activity, account abuse, or later laundering and fraud operations.
Failure mechanism: The control fails when the bank treats a single visual check as strong evidence of personhood, while the attacker uses generated imagery, voice, or document composites to satisfy the narrow test and evade weak liveness or review steps.
Impact: The institution can open accounts for non-existent or impersonated applicants, absorb remediation costs, and allow downstream AML and fraud controls to operate after the damage has already started.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, CIS Controls v8, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Applicant proofing and authentication assurance are central to this onboarding problem. |
| Recommendation — Apply assurance levels and phishing-resistant verification to strengthen applicant identity proofing. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Banks need layered identity proofing and escalation before account creation. |
| Recommendation — Enforce strong identity proofing and step-up controls for suspicious applicant onboarding. | ||
| CIS Controls v8 | 5 — Account Management | The issue is preventing fraudulent customer account creation and limiting weak onboarding paths. |
| Recommendation — Restrict and review account-creation paths that accept weak or anomalous identity evidence. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Applicants are external users whose identity proofing must resist synthetic media. |
| Recommendation — Use external-user identity proofing controls that combine multiple verification signals. | ||
| OWASP ASVS | V10 — OAuth and OIDC | Federated login and identity assurance patterns are relevant when onboarding ties into digital identity flows. |
| Recommendation — Validate identity assurance steps wherever onboarding relies on federation or external identity claims. | ||
Practitioner Guidance
What to prioritise: Put the highest scrutiny on high-value accounts, remote onboarding, and any application that combines synthetic-looking media with weak device or contact signals. Those are the cases where layered assurance returns the most value.
What to verify: Confirm that liveness detection is paired with document authenticity checks and a documented escalation path. If review staff can override the control without leaving a clear audit trail, the design is not ready.
Common mistake: Do not measure success only by approval speed. The better metric is whether the bank can explain, after the fact, why a suspicious applicant was stopped, stepped up, or escalated.
Practitioner takeaway: Synthetic media means banks must evaluate applicant authenticity as a multi-signal decision, because any control that depends on one convincing image is now too easy to game.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org