Join our Newsletter — 33% off our NHI Course
Home FAQ AI Security Why do deepfakes and synthetic applicants force organisations…
AI Security

Why do deepfakes and synthetic applicants force organisations to rethink onboarding controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: AI Security

Deepfakes and synthetic applicants weaken assumptions that visual presence or a polished résumé indicates real identity. When candidates can impersonate others at scale, organisations need layered proofing, consent-based checks, and shared ownership across HR, Security, and IT. That reduces reliance on human judgement alone and creates stronger evidence before trust is extended.

Why deepfakes and synthetic applicants change the onboarding problem

Onboarding controls are often built around a simple assumption: a real person is present, their documents are genuine, and the interview or approval process will expose obvious fraud. Deepfakes and synthetic applicants break that assumption by making identity signals easier to counterfeit and harder to validate in real time. For organisations that onboard employees, contractors, or partners, the question is no longer whether a candidate can talk convincingly, but whether the trust decision is backed by evidence that survives impersonation. The FATF Recommendations — AML and KYC Framework is relevant here because it reflects the broader governance problem of proving who someone is before extending trust. In practice, many teams discover the weakness only after they have already normalised manual approval habits for high-volume hiring or outsourced onboarding.

What stronger onboarding controls actually need to verify

When identity can be manufactured, onboarding has to move from appearance-based judgement to evidence-based verification. That means separating what a person claims, what the system can independently confirm, and what the organisation is willing to accept as sufficient proof. A polished video call, a consistent interview answer, or a well-formed application packet may still be useful, but none of those should function as the final trust anchor.

In practice, stronger onboarding usually combines several layers:

  • Document authenticity checks that test whether the identity evidence itself is genuine and internally consistent.
  • Consent-based verification steps that confirm the applicant is participating under legitimate terms, not through borrowed or synthetic credentials.
  • Cross-checks against authoritative records or approved sources, rather than relying on one interviewer's judgement.
  • Role-specific screening that scales with the access being granted, especially where the new starter will touch finance, customer data, or privileged systems.
  • Escalation paths for exceptions, because a rushed hire or contractor onboarding is exactly where weak controls get bypassed.

This is also where organisations need to be careful about false confidence. A deepfake-resistant step does not prove the whole identity; it only raises the cost of impersonation. Good onboarding design treats each check as partial evidence and deliberately avoids making any single channel carry the entire decision. That is why human review still matters, but only as one input in a controlled decision process. The guidance becomes fragile when organisations assume one biometric, one call, or one vendor check can solve identity assurance on its own.

For identity-heavy onboarding, the practical issue is not just applicant fraud. It is the downstream access decision: once a synthetic applicant is accepted, every system that trusts the onboarding result inherits that mistake.

Where deepfake-resistant onboarding becomes harder to apply

Tighter onboarding often increases friction and investigation time, so organisations have to balance faster hiring against the risk of granting trust to the wrong person. That tradeoff becomes more visible in remote hiring, contractor supply chains, and high-volume recruitment, where the pressure to move quickly can override verification discipline.

There is no single consensus method that defeats synthetic applicants in every context. Face checks, document checks, liveness testing, and callback verification each help, but each also has failure modes and can be bypassed if used in isolation. The standard answer breaks down when the onboarding flow is heavily outsourced, when the organisation has poor ownership of identity evidence, or when exception handling becomes routine rather than exceptional.

Another edge case is legitimate privacy and accessibility constraints. Some verification steps may be inappropriate or unnecessary for low-risk roles, while others may create disproportionate burden for applicants without meaningfully improving assurance. The right control set should be proportional to the trust being extended, not copied from a different hiring population or a higher-risk business unit.

For that reason, teams should be cautious about treating deepfake risk as only a technology problem. It is also a policy problem, a workflow problem, and a trust-boundary problem. When those pieces are not aligned, organisations end up with onboarding that looks secure on paper but still accepts a convincing synthetic identity.

Risk and Threat Considerations

Deepfakes and synthetic applicants create identity assurance risk, insider-threat risk, and access-control risk because they allow an unverified person to enter a trusted process under a credible false persona. The main exposure is not the interview itself, but the trust that flows from a successful onboarding decision into accounts, data, systems, and downstream approvals.

Failure mechanism: An attacker or fraudster exploits weak proofing, overreliance on visual or conversational signals, and fragmented ownership between HR, Security, and IT. Once a synthetic applicant passes the front door, the organisation may issue credentials, approve payroll, grant system access, or accept delegated trust without ever validating the underlying identity with enough confidence.

Impact: The organisation can onboard an impostor, expose internal systems or regulated data, and create a durable compromise path that looks like legitimate employment or contracting activity. That can also undermine auditability, because the approval record may appear normal even when the identity basis was weak.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while NIS2 and EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63IAL — Identity Assurance LevelOnboarding requires stronger proofing when applicant identity can be faked.
Recommendation — Set the required assurance level before issuing trust or access.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlThe issue is whether onboarding proves identity before access is extended.
Recommendation — Align onboarding checks to the access decision they are meant to support.
CIS Controls v85 — Account ManagementSynthetic applicants can lead to accounts being created for the wrong person.
Recommendation — Bind account creation to validated onboarding evidence and review exceptions.
NIS2Art. 21 — Cybersecurity Risk-Management MeasuresThe topic concerns governance of trust decisions and operational control strength.
Recommendation — Document onboarding controls as part of your risk-management measures.
EU AI ActArticle 4 — AI LiteracyDeepfake-driven onboarding fraud intersects with organisational handling of AI-enabled deception.
Recommendation — Train relevant staff to recognise AI-enabled impersonation and escalation cues.

Practitioner Guidance

What to prioritise: Treat onboarding assurance as a trust decision, not an interview-quality problem. The highest-value control change is to make identity evidence, approval authority, and downstream access grant separate checkpoints rather than one blended judgment.

Decision rule: If a role can reach customer data, financial systems, privileged tooling, or sensitive internal workflows, require stronger proofing and explicit exception approval. If the role is low-risk, keep the process lighter, but do not remove verification entirely just to preserve speed.

What to verify: Verify that the same person who was proven during onboarding is the one who later receives credentials, payroll access, and any elevated permissions. Teams often underestimate how quickly a weak onboarding decision becomes a broad access problem once downstream systems auto-trust the result.

Practitioner takeaway: Deepfake resistance is most effective when organisations stop asking only whether a candidate looks real and start asking whether the trust decision is defensible after the person has been onboarded.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org