Sumsub vs Veriff vs deepidv: Mitigating the New FATF Greylist Risk Matrix
A compliance comparison evaluating deepidv, Sumsub, and Veriff against the updated June 2026 FATF surveillance watchlists.
Deepfake-powered KYC fraud is surging. Compliance teams need new frameworks, updated controls, and modern verification technology to stay ahead. This guide covers the regulatory landscape and practical defenses.
In late 2025, the Financial Crimes Enforcement Network (FinCEN) issued an advisory specifically warning financial institutions about the use of deepfake technology in identity fraud. Months on, that advisory reads less like a warning and more like a baseline expectation. It was never speculative: it responded to a measurable increase in AI-generated identity documents and biometric spoofing attempts detected across the banking sector, and the trend has only accelerated through 2026.
For compliance teams, this is no longer a theoretical risk. It is an operational reality that demands updated controls, revised risk assessments, and modern verification technology. The center of gravity has shifted, too. Injection attacks that feed synthetic video directly into the verification pipeline now outpace physical presentation attacks held up to a camera.
Industry data from 2025 paints a stark picture:
These numbers will get worse before they get better. The tools for creating deepfakes are becoming more accessible, while the tools for detecting them are not yet universally deployed.
Most compliance frameworks were built for a world where identity fraud meant stolen credentials and forged documents. Deepfakes introduce a category of fraud that many existing frameworks do not adequately address:
Standard Customer Due Diligence (CDD) procedures verify that a customer's identity documents are authentic and that the person presenting them matches the documents. Enhanced Due Diligence (EDD) adds additional scrutiny for higher-risk customers.
Both assume that biometric verification, matching a face to a document photo, is a reliable control. With deepfakes, this assumption no longer holds. A deepfake face that matches a forged document photo will pass CDD and EDD checks designed around these assumptions.
Many compliance risk assessments categorize identity fraud risk based on geography, transaction patterns, and customer type. Deepfake risk does not correlate neatly with these traditional risk factors. A deepfake attack is equally likely to target a domestic retail banking customer as an international correspondent banking relationship.
When a deepfake bypasses verification, the audit trail shows a clean pass. The document checked out. The biometric matched. The liveness check passed. If the institution later discovers the fraud, the audit trail provides no indication that the verification was compromised, because the verification system believed it was legitimate.
Regulators are catching up, but the landscape is evolving rapidly:
United States: FinCEN's 2025 advisory directs institutions to evaluate their identity verification controls against AI-generated threats. The advisory is not a regulation, but it signals regulatory expectations and will likely inform future enforcement actions.
European Union: The EU AI Act includes provisions for AI systems used in identity verification, requiring transparency about detection capabilities and limitations. eIDAS 2.0 mandates specific security standards for digital identity wallets that include deepfake resistance requirements.
United Kingdom: The FCA has issued guidance on operational resilience that specifically mentions AI-generated fraud as a threat that firms must assess and mitigate.
Global: FATF guidance on digital identity emphasizes that verification technology must be "fit for purpose" against current threats. Deepfakes are explicitly mentioned as a threat that verification providers must address.
Compliance teams should update their frameworks across four dimensions:
Evaluate your current verification provider against specific deepfake attack types:
Request specific detection rates for each attack category, not just overall accuracy statistics.
Add deepfake-specific factors to your risk assessment framework:
Implement post-verification monitoring for synthetic identity indicators:
Develop specific response procedures for suspected deepfake fraud:
deepidv's platform provides the technology foundation for a deepfake-aware compliance framework:
The regulatory direction is clear: institutions are expected to maintain verification controls that are effective against current threats. Deepfakes are a current threat. Verification stacks that were adequate two years ago may no longer satisfy regulatory expectations.
The time to assess your controls is now, before the next FinCEN advisory becomes an enforcement action.
Go live in minutes. No sandbox required, no hidden fees.
A compliance comparison evaluating deepidv, Sumsub, and Veriff against the updated June 2026 FATF surveillance watchlists.
Sumsub vs Veriff compared for European businesses: pricing, automation, AMLA readiness, the Vespia acquisition, and where both platforms fall short.
Explore why digital financial platforms are replacing point-in-time identity refreshes with continuous, agentic asset profiling to satisfy federal mandates.