Document-only workflows fail because they verify artefacts, not the conditions of capture or the authenticity of the person presenting them. Attackers can pair stolen data with AI-generated faces, voices, and video to pass weak checks. Security teams need controls that test for real human presence, manipulation, and abnormal device behaviour, not just document quality.
Why This Matters for Security Teams
Document-only verification fails because synthetic identity fraud now scales faster than manual review, and the check itself is often too shallow to distinguish a real applicant from a generated one. Once an attacker can combine stolen personal data, AI-generated face swaps, and replayed video, the document becomes just one artifact in a broader deception chain. That creates downstream risk for onboarding, fraud screening, and account recovery.
Security teams should treat this as a control design problem, not just a fraud problem. The NIST Cybersecurity Framework 2.0 emphasises outcomes such as identity assurance, detection, and response, which is where document-only workflows are weakest. NHIMG research on the DeepSeek breach shows how quickly exposed data and secrets can expand an attack surface once an adversary has usable inputs. In practice, many security teams discover synthetic identity abuse only after an account is already approved and being used for fraud, mule activity, or escalation.
How It Works in Practice
Effective workflows move beyond document image checks and test whether the person, device, and session are credible at the same time. That means combining liveness detection, capture integrity checks, document authenticity analysis, and behavioural signals such as device reputation, geolocation consistency, and velocity across attempts. Best practice is evolving toward layered verification rather than a single pass-fail document step.
For higher-risk journeys, teams should add step-up verification and compare the claimed identity against independent signals instead of trusting a submitted document alone. This is especially important where synthetic identities are cheap to produce because attackers can iterate rapidly until one combination gets through. Practical controls often include:
- Challenge-response liveness checks that detect replay, injection, and deepfake-style manipulation
- Document validation against issuer formats, tamper indicators, and cross-field consistency
- Risk scoring based on device fingerprint, IP reputation, and session anomalies
- Manual review for exceptions, with clear escalation thresholds
- Post-verification monitoring for account takeover indicators and abnormal transaction patterns
Teams should also tie verification outcomes to fraud rules and identity lifecycle governance. That means a low-risk document may still fail if the device is new, the capture is synthetic, or the session behaviour indicates automation. NHIMG’s reporting on JetBrains GitHub plugin token exposure is a reminder that attackers value any reusable trust signal they can steal or repurpose. These controls tend to break down in high-volume onboarding environments because review queues, inconsistent vendor tuning, and weak exception handling let attackers probe the process faster than analysts can respond.
Common Variations and Edge Cases
Tighter verification often increases friction, requiring organisations to balance fraud reduction against conversion loss and customer support burden. That tradeoff matters most when the business wants low-friction onboarding, but the threat model includes synthetic identities, mule accounts, or refund abuse. There is no universal standard for this yet, so organisations should align controls to risk rather than assume one verification flow fits every journey.
Some environments need stronger human presence checks, while others need stronger device and network assurance. For example, a consumer signup flow may prioritise liveness and document integrity, while a financial workflow may require step-up proofing, sanctions screening, and transaction monitoring. Current guidance suggests treating document-only verification as one input, not an acceptance decision.
Two common failure modes are worth calling out. First, overreliance on static rule thresholds creates blind spots because synthetic identities can be tuned to sit just below alert levels. Second, outsourced verification can hide model drift if vendors are not re-tested against current attack techniques. If the workflow must support remote users, accessibility constraints and privacy rules may also limit the depth of biometric or liveness checks, so compensating controls become essential. NHIMG’s Code Formatting Tools Credential Leaks research reinforces a broader lesson: once trust is misplaced in a single control, attackers tend to exploit the shortest path around it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Synthetic identity fraud often starts with weak identity proofing and trust assumptions. |
| OWASP Agentic AI Top 10 | A-03 | Automated fraud workflows and synthetic generation create agent-like abuse patterns. |
| CSA MAESTRO | GOV-02 | Identity proofing needs governance, assurance, and monitoring across the full workflow. |
| NIST AI RMF | AI-assisted fraud requires risk management for model outputs and decision reliability. | |
| NIST CSF 2.0 | PR.AC-1 | Identity proofing and access control depend on reliable verification outcomes. |
Verify identity inputs with layered checks, not document appearance alone, before granting trust.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org