Deepfakes and synthetic applicants weaken assumptions that visual presence or a polished résumé indicates real identity. When candidates can impersonate others at scale, organisations need layered proofing, consent-based checks, and shared ownership across HR, Security, and IT. That reduces reliance on human judgement alone and creates stronger evidence before trust is extended.
Why This Matters for Security Teams
Deepfakes and synthetic applicants break a core onboarding assumption: that a person who looks credible, speaks confidently, or presents a polished record is the same person who will receive access. That assumption is no longer reliable. Identity proofing now has to account for impersonation at scale, stolen credentials, and fraud chains that span HR, Security, and IT. Guidance from the FATF Recommendations — AML and KYC Framework reinforces the need for stronger evidence when trust is being established, not after access has already been granted.
For organisations managing broader identity risk, NHI Management Group has documented how weak lifecycle controls create long-term exposure: 97% of NHIs carry excessive privileges, and 79% of organisations have experienced secrets leaks, with 77% causing tangible damage, according to the Ultimate Guide to NHIs — Standards. The same pattern applies here: once onboarding evidence is accepted without challenge, downstream access decisions inherit that weakness.
Security teams often overfocus on interview fraud and underfocus on how a false identity can persist through payroll, device enrollment, directory creation, and application provisioning. In practice, many security teams encounter synthetic applicants only after onboarding abuse has already become a privileged access problem.
How It Works in Practice
Modern onboarding controls need to shift from “does this applicant appear legitimate?” to “can this identity be proven across multiple independent signals?” That means layered proofing, consent-based checks, and shared workflow ownership. HR can collect and validate employment data, Security can define proofing thresholds and fraud triggers, and IT can ensure that account creation only occurs after identity evidence clears policy. Best practice is evolving, but current guidance suggests that no single check, including video interviews or document scans, is sufficient on its own.
In practice, organisations should combine:
- Document verification with tamper detection and source-of-truth comparison.
- Government ID validation where legally permitted, with explicit consent and retention limits.
- Step-up verification for remote or high-risk hires, especially for privileged roles.
- Device and session risk checks before directory access, payroll enrolment, or application provisioning.
- Strict joiner-mover-leaver controls so access is not created until proofing is complete.
On the governance side, the same “prove before you trust” discipline is reflected in NHI practice. The ASP.NET machine keys RCE attack shows how a trusted secret or key can be abused once it enters the wrong hands. For identity proofing, the lesson is similar: evidence quality matters more than confidence in the claimant. Standards such as the FATF Recommendations — AML and KYC Framework also support risk-based verification rather than blanket trust.
Where this guidance breaks down is in high-volume remote hiring pipelines that rely on outsourced recruiters, weak jurisdictional ID checks, or fully automated onboarding, because fraud detection signals become too thin and too late.
Common Variations and Edge Cases
Tighter proofing often increases hiring friction, requiring organisations to balance fraud reduction against candidate experience, privacy constraints, and time-to-fill targets. There is no universal standard for this yet, so the right control set depends on role criticality, geography, and legal constraints.
High-risk roles, such as finance, admin access, or production support, should get stronger checks than low-risk roles. For contractors and gig workers, organisations may need shorter-lived access, more frequent revalidation, and narrower account scopes. For global hiring, identity documents, biometric checks, and data retention rules vary sharply by country, so legal and HR review is essential before standardising a process.
Another common failure mode is treating onboarding as a one-time gate instead of an ongoing assurance process. Synthetic identities can pass an initial check and later become difficult to distinguish from legitimate employees if access, payroll, and directory records are not continuously reconciled. NHI Management Group has also shown that poor control of secrets and privilege creates lasting exposure; the Ultimate Guide to NHIs — Standards is useful for mapping how lifecycle discipline should work across identities.
In practice, the hardest cases are remote hires in regulated industries, where proofing must satisfy both fraud controls and privacy law while still moving fast enough for the business.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity proofing supports trustworthy onboarding and access decisions. |
| NIST AI RMF | Risk-based governance is needed when AI-enabled fraud can distort trust signals. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Onboarding failures often lead to weak identity lifecycle and excessive trust. |
| CSA MAESTRO | Agentic and automated workflows need strong identity and trust boundaries. | |
| NIST Zero Trust (SP 800-207) | PR.AC-1 | Zero trust requires continuous verification instead of initial trust based on appearance. |
Require stronger identity evidence before account creation and provision access only after validation.
Related resources from NHI Mgmt Group
- What should organisations measure to know if onboarding controls are working?
- How can organisations prove their onboarding controls are working across jurisdictions?
- What do organisations get wrong about deepfakes in financial onboarding?
- How should organisations detect synthetic identities after onboarding?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org