Organisations should add liveness and deepfake detection when remote onboarding, higher-value accounts, or cross-border activity increases impersonation risk. These controls matter most when identity evidence can be spoofed or reused. They work best alongside screening and verification checks, not as stand-alone safeguards, because fraud prevention depends on layered assurance across the onboarding journey.
Why This Matters for Security Teams
Liveness and deepfake detection belong in onboarding when the organisation can no longer trust a document upload, a selfie, or a video call as durable proof of presence. That shift usually happens when onboarding is remote, high-value, cross-border, or exposed to organised fraud. The risk is not just fake people entering the system. It is also the creation of accounts that later become trusted anchors for access, payments, approvals, or privileged workflows.
This is why identity assurance should be treated as a layered control, not a single checkpoint. NHI Management Group’s Ultimate Guide to NHIs — Key Challenges and Risks notes that 79% of organisations have experienced secrets leaks, which is a reminder that weak identity proofing and weak credential governance often reinforce each other. For onboarding decisions, the relevant question is whether the organisation can detect spoofed presence before trust is granted. That aligns with the NIST Cybersecurity Framework 2.0 focus on risk-based protective controls. In practice, many security teams encounter impersonation only after a fraudulent account has already been used to move money, request access, or pass downstream verification.
How It Works in Practice
Effective onboarding uses liveness and deepfake detection as one signal within a broader verification flow. The control is most useful when the account being created will later influence financial, legal, administrative, or privileged actions. Current guidance suggests the strongest design is risk-based: apply stronger checks when the onboarding context indicates elevated impersonation likelihood, such as remote-only entry, unusual device geolocation, mismatched document provenance, repeated retries, or high-risk jurisdictions.
Common implementation patterns include passive and active liveness checks, challenge-response prompts, image forensics, video integrity analysis, and step-up review when confidence drops. Deepfake detection should be tuned to the channel being used, because a tool that works on a short selfie clip may not be reliable in a live video interview or document capture flow. Organisations should also preserve evidence for audit and fraud analysis, and define what happens when the system cannot reach a clear decision.
- Use liveness as an assurance boost, not as a substitute for document, sanctions, or background screening.
- Escalate to manual review when signals conflict, rather than auto-approving on partial confidence.
- Set thresholds by risk tier so routine accounts do not carry the same friction as privileged ones.
- Document false-positive handling so legitimate users are not locked out unnecessarily.
This approach fits the broader onboarding lifecycle described in the NHI Lifecycle Management Guide, where assurance should connect to subsequent access decisions, not end at the first approval. For identity proofing principles, the FATF Recommendations are relevant where fraud, AML, or KYC obligations shape onboarding controls. These controls tend to break down when organisations try to use a single vendor score as final truth in high-friction or high-volume onboarding pipelines because attackers adapt faster than static thresholds.
Common Variations and Edge Cases
Tighter onboarding controls often increase friction, review volume, and abandonment, requiring organisations to balance fraud reduction against conversion and user experience. That tradeoff is especially visible in consumer onboarding, contractor intake, and partner enrollment, where too much challenge can create business loss even when the security logic is sound.
There is no universal standard for when liveness must be mandatory. Best practice is evolving toward tiered assurance: low-risk accounts may only need lightweight checks, while accounts with payment authority, administrative privileges, or cross-border operating scope should face stronger evidence. High-trust environments may also combine liveness with device binding, out-of-band verification, or human review when the consequences of impersonation are severe.
Organisations should be careful not to overstate what deepfake detection can do. It is an indicator of possible deception, not proof of fraud. It also degrades when attackers use short clips, low-light captures, replay attacks, or synthetic media that does not match the detector’s training assumptions. NHI Management Group’s Top 10 NHI Issues is a useful reminder that identity controls fail most often when they are implemented in isolation rather than as part of a governed lifecycle.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity proofing failures often lead to compromised non-human accounts. |
| CSA MAESTRO | T01 | Agent and workload onboarding needs strong identity assurance before tool access. |
| NIST AI RMF | MAP | Risk mapping supports deciding when stronger onboarding controls are justified. |
| NIST CSF 2.0 | PR.AA-1 | Identity management controls support stronger proofing and access assurance. |
| NIST SP 800-63 | IAL2 | Identity proofing assurance levels directly inform when liveness checks are needed. |
Use higher identity assurance levels for high-value onboarding and verify evidence before account issuance.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org