Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do replayed or synthetic IDs still bypass…
Authentication, Authorisation & Trust

Why do replayed or synthetic IDs still bypass some eKYC controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Authentication, Authorisation & Trust

Because many onboarding flows still rely on static evidence such as readable fields, face comparison and image quality. Those controls can be satisfied by a convincing fake unless the workflow also tests for physical behaviour, such as angle-dependent glare, light response and movement patterns tied to a genuine card.

Why static eKYC checks miss replayed or synthetic IDs

Static checks are easy to satisfy because they validate the document as an image, not the document as a living object presented by a person in real time. If a flow only scores readability, face similarity, and image quality, a high-fidelity replay or synthetic artifact can look legitimate enough to pass. The control gap is between “looks authentic” and “is physically present.”

What the bypass is actually exploiting

The weakness is not just image fraud, it is overreliance on passive evidence. A replayed ID can preserve the expected layout, data fields, and facial match while still being fake. Synthetic IDs go further by copying the visual cues that automated systems are trained to accept. Where the workflow does not require liveness, capture assurance, or tamper-evident physical response, the attacker only has to imitate the output, not the original document.

Stronger eKYC flows therefore shift from single-frame validation to multi-signal validation. Physical behaviours such as tilt-dependent glare, specular reflection, light response, and movement tied to a genuine card are harder to replicate than static pixels. That is why document verification systems often need challenge-response or motion-based checks in addition to OCR and face matching.

Why physical-response testing raises the bar

Physical-response testing helps distinguish a real credential from a screen replay, printout, or generated image because the control is measuring interaction with the real world. A genuine card responds differently under changing angle, illumination, and motion. A spoof can be convincing in a still image yet fail when the system asks for controlled movement or capture conditions that expose flatness, re-photography, or display artifacts.

That does not make the problem trivial. The stronger the challenge, the more the onboarding flow must manage usability, device variability, and false rejects. Good design looks for signals that are hard to fake but still practical for ordinary users, which is why the best controls are usually layered rather than singular.

Where the control boundary usually breaks down

Many implementations treat eKYC as a one-time document gate and assume the vendor’s score is enough. In practice, bypasses happen when teams trust a single static image, accept weak capture conditions, or fail to verify that the presented evidence changes in a way consistent with a real object. Systems also struggle when they are tuned for fraud reduction but not for presentation attacks, replay artifacts, or generated-media quality.

For practitioners, the important distinction is between identity proofing and document appearance. A photograph that satisfies format checks can still fail authenticity under challenge. If the process does not force the applicant to prove the document is physically present, then the control is validating resemblance, not provenance.

Risk and Threat Considerations

Replay and synthetic-ID bypasses create a direct onboarding fraud risk because they can convert a visually plausible artifact into a trusted identity record. The exposure increases when the same weak check is used for account opening, step-up verification, or recovery, since one successful spoof can become an entry point for broader abuse.

Failure mechanism: Static capture, OCR, and face match are satisfied by an attacker-controlled artifact, while the workflow never demands a physical-response signal that would reveal a replay, printout, or generated image.

Impact: False account approval, synthetic identity creation, downstream money movement abuse, and higher manual review load when fraud cases are discovered after onboarding.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, OWASP ASVS, NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)eKYC onboards external users and must resist spoofed identity evidence.
Recommendation — Require stronger proofing and authentication steps for remote identity checks.
OWASP ASVSV6 — AuthenticationThe bypass exploits weak evidence that passes identity verification without proving presence.
Recommendation — Add stronger verification steps that resist replayed or synthetic evidence.
NIST SP 800-63Digital Identity GuidelinesThe question concerns remote identity proofing assurance and replay-resistant verification.
Recommendation — Apply stronger assurance and presentation-resistant proofing methods.
ISO/IEC 27001:2022A.8.5 — Secure authenticationeKYC controls fail when authentication of the presented evidence is too weak.
Recommendation — Strengthen authentication checks for remote identity evidence and onboarding.
CIS Controls v8CIS-5 — Account ManagementIdentity onboarding weaknesses create fraudulent account creation and misuse risk.
Recommendation — Harden onboarding and approval checks before accounts are created.

Practitioner Guidance

What to verify: Treat any eKYC design that depends only on readable fields and facial comparison as incomplete unless it also verifies real-world interaction with the document. The useful question is whether the system can distinguish a live presentation from a captured or fabricated one under normal user conditions.

Decision rule: If a control can be satisfied from a single static frame, add a second challenge that tests physical presence or motion consistency before you treat the result as trustworthy. If the vendor cannot explain which signals are replay-resistant, assume the workflow still has a presentation-attack gap.

Practitioner takeaway: The most reliable eKYC programs do not ask only whether the ID looks real, they ask whether the capture proves a real document was present at the moment of verification.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org