The Deepfake Defense Playbook for Financial Institutions
An executive playbook for institution-wide deepfake defense: video KYC, payments, helpdesk, and hiring protected in five phases with examiner-ready evidence.
Full name + work email required. We'll email you a copy.
Every financial institution now runs four standing invitations to deepfake fraud, and most defend one of them. Remote onboarding invites synthetic customers; payment workflows invite synthetic executives; helpdesks invite synthetic account holders; hiring pipelines invite synthetic employees. The attacks against all four share tooling, economics, and often operators, yet institutional defenses remain scattered across fraud, treasury, IT, and HR budgets that rarely compare notes. That fragmentation, more than any detection gap, is why the losses keep landing.
The forcing conditions arrived together this year. Deepfake documents now account for 80.10 percent of AI-enabled fraud attacks, deepfake identity fraud was projected to grow nearly five-fold in 2026, and supervisors moved from advisories to requirements, with Hong Kong's mandate for AI deepfake detection in video KYC the template other regulators are absorbing. The market matured on cue: strategic capital moved into detection firms, and accredited laboratories now certify injection attack defenses independently, which means claims are testable and untested claims are choices.
This playbook is the institution-wide program: one detection architecture deployed across all four attack surfaces in five phases over roughly eighteen weeks, with the measurement, evidence, and adversarial validation that turn a security project into examination capital. It is written for the fraud lead, the CISO, and the operations executive as a single audience, because the program only works when the four surfaces are defended as one. The deployments described reflect the deepidv platform; the architecture is stated so any vendor can be held to it.
The threat model, surface by surface
Defense follows exposure, so start with how each surface is actually attacked.
Onboarding and video KYC absorb the volume attacks. Synthetic customers arrive three ways: real-time face puppeting on live calls, pre-rendered responses to challenge sequences, and injection of fully synthetic sessions through virtual cameras and tampered capture layers. The economics favor the attacker at scale, thousands of attempts at near-zero marginal cost, and the ring data shows the assets are reused: 65.68 percent of linked fraud attempts run recycled forged documents, meaning the synthetic face at your gate has probably passed someone else's.
Payments and treasury absorb the precision attacks. The pattern is stable since the canonical $25 million video-call loss: impersonate an authority, executive, vendor, counsel, over video or voice, and direct a payment or a banking-detail change. Precision attacks are researched, rehearsed, and timed for pressure windows, quarter-close, deal deadlines, Friday afternoons, and they defeat process controls because the process authenticated the channel, never the face.
Helpdesk and account recovery absorb the persistence attacks. Cloned voices plus breached personal data pass knowledge-based recovery reliably, converting the support queue into a credential-reset service for account takeover. The attack is quiet, cheap, and compounding: every successful reset seeds the next social engineering round.
Hiring and workforce absorb the patient attacks. Synthetic or misrepresented candidates interview over video for remote roles; the payoff is access, exfiltration, or salary fraud that surfaces months later. HR runs the gate but was never staffed as a verification function, which is exactly why the attack works.
Reference architecture: one engine, four gates
The program's core decision is architectural: one detection engine with four deployment gates, not four vendor point solutions. Shared engine, shared evidence, shared adversarial testing; per-surface policy.
The detection engine
Four layers, evaluated together. Structural liveness, deepeye's structural light and subdermal analysis, tests physical presence rather than rendered appearance, the property that holds as generators improve. Capture and injection defense authenticates the channel: driver provenance, capture-API integrity, hardware-signed frames where devices support them, and sensor forensics where they do not. Media and voice forensics score content: generation artifacts on video, spectral and biomarker analysis on audio, each corroborating or contradicting the other on calls. And the provenance index correlates across sessions and surfaces, so the synthetic face rejected at onboarding is recognized when it dials the helpdesk, which is the payoff of running one engine instead of four.
The four gates
Each surface consumes the engine through a gate sized to its risk. Onboarding runs detection through the entire session, not a snapshot, with injection defense failing closed. Payments add verified-human release: instructions above threshold require a liveness-confirmed re-authentication of the instructing party, independent of the channel that carried the request. Helpdesk recovery routes through login-grade verification, the same evidence the account would demand at sign-in, ending pass-the-quiz resets. Hiring borrows the onboarding gate for sensitive roles: document verification, liveness, and provenance checks before access is provisioned.
The evidence and adversarial planes
Luna converts every gate decision into the evidence file supervisors now request, and assembles the examination packs from system output. Arbiter attacks all four gates on a standing cadence with current generator tooling and fraud persona kits, so the institution's detection claims are measured weekly rather than asserted annually.
Phase 0: exposure audit (weeks 1-2)
Two weeks of measurement before any procurement, producing four artifacts.
The surface inventory maps every workflow where a face, voice, or media artifact can move money, data, or access: onboarding flows by channel, payment authorization paths by threshold, recovery procedures by account tier, and hiring pipelines by role sensitivity. Most institutions find surfaces nobody owns, the vendor-update call, the wealth-client video instruction, the contractor onboarding run by a business unit, and unowned surfaces are where precision attacks aim.
The control reality check tests what currently stands between each surface and a synthetic presenter. The honest finding at most institutions: visual review by staff, a control the research says performs near chance against modern synthetic video. Document the gap plainly; it becomes the program's baseline and its budget justification.
The retrospective sweep runs available forensics over recent history: onboarding sessions re-scored for injection and generation artifacts, payment-change requests re-examined for impersonation patterns, recovery logs mined for cloned-voice indicators. The sweep converts "emerging threat" into a list of probable past incidents with amounts attached, which is what moves executive committees.
The exposure pricing assigns each surface a loss scenario: the onboarding ring at your approval rate, the treasury impersonation at your average large-payment size, the takeover wave at your recovery volume, the insider at your access tiers. The program will be measured against these numbers, so agree on them before the work starts.
- All four artifacts accepted by fraud, security, and operations jointly
- One executive sponsor named
- Exposure pricing signed as the program's baseline
Phase 1: the onboarding gate (weeks 3-6)
Onboarding goes first because it carries the volume and because its build produces the engine every other gate reuses.
Integration proceeds in three tracks. Track one deploys structural liveness through the full capture: deepeye's structural light and subdermal analysis running continuously across video KYC sessions, not as a start-of-call snapshot, since puppeting can begin at minute four. Track two deploys the injection defense: driver provenance and capture-API integrity checks, hardware-signed capture where the device population supports it, sensor forensics where it does not, all failing closed, an unverifiable channel routes to a stronger flow, never to a pass. Track three connects the provenance index: every session's artifacts fingerprinted and searched against history, so reused faces, documents, and infrastructure meet their record.
The design decision that shapes the phase: full-call coverage versus checkpoint coverage. Checkpoints are cheaper and catch the lazy attack; full-call coverage catches the patient one and is the direction supervisory language is moving. Institutions under HKMA-style rules have no choice; everyone else should treat full-call as the target and checkpoints as the migration step.
Exit criteria: liveness and injection defense live on all remote onboarding channels, fail-closed behavior verified by test, provenance index ingesting, and the first Arbiter campaign against the gate passed with findings actioned.
Phase 2: the payments gate (weeks 7-9)
The payments gate is the program's highest-yield three weeks: precision attacks concentrate here, and the control is conceptually simple.
Verified-human release: any payment instruction, banking-detail change, or payout modification above a tiered threshold requires liveness-confirmed re-authentication of the instructing party through the detection engine, independent of the channel that delivered the instruction. The video call may be flawless; the release still requires the instructing executive to pass a structural liveness check bound to their enrolled identity. The $25 million call fails at exactly that step.
Deployment is mostly policy work. Define the thresholds per payment type with treasury; enroll the authorized-instructor population through the onboarding gate's flow; wire the release check into payment operations with a clean escalation path; and script the exception handling, because the first week will surface the executive who resents the check until the day it catches an impersonation of them.
Voice joins the gate here: instructions carried by phone route through synthetic voice detection, with video and voice verdicts fused when both are present. A call that passes one and fails the other escalates rather than releases.
Exit criteria: verified-human release live for all above-threshold instructions, instructor population enrolled, exception path documented, and an Arbiter impersonation campaign, cloned voice plus rendered face against a live release flow, defeated in test.
Phase 3: helpdesk and workforce gates (weeks 10-13)
The persistence and patience attacks fall in one phase because both are identity checks relocated to workflows that never had them.
The helpdesk gate replaces knowledge-based recovery with login-grade re-verification: a recovery request routes the caller through the same liveness and identity evidence the account requires at sign-in, delivered by app link or verification session, with voice forensics screening the call itself. Recovery volume makes friction design matter: legitimate distressed customers need a path that works on a borrowed phone at an airport, so the gate ships with a documented step-down ladder at equal evidence standards rather than a single rigid flow.
The workforce gate applies onboarding-grade verification to hiring and access: document verification, structural liveness, and provenance screening for candidates in sensitive roles, and re-verification at access provisioning for contractors and privileged accounts. The provenance index earns double here, screening candidate media against known synthetic assets and linking application clusters that share generation lineage, the hiring version of the fraud ring.
Exit criteria: knowledge-based recovery retired for all account tiers above baseline, recovery step-down ladder tested with real support staff, workforce verification live for defined role tiers, and helpdesk-targeted Arbiter campaigns, cloned-voice recovery attempts, failing at the gate.
Phase 4: evidence operations (weeks 14-16)
Phase 4 converts the running program into examination capital.
Luna assembles the evidence architecture: per-decision files from every gate, method, verdicts by layer, confidence, escalation path, retained to the strictest applicable standard; measured detection rates by attack class on the institution's own traffic; and the examiner pack, the standing document set answering the questions supervisors now ask, produced from system output rather than assembled under notice. Incident response integrates here too: a detection above severity threshold opens a case with the evidence attached, feeds the SAR process where reporting obligations trigger, and updates the provenance index so the attack's assets are recognized on return.
The phase closes with a mock examination: an internal team, armed with the supervisory question set, requests evidence cold. Which workflows carry detection, what are the measured rates, who tested the injection defense, show the file for this session. Passing from system output alone is the exit criterion; anything requiring archaeology is a Phase 4 finding to fix now.
Incident response: when detection fires
A detection program without a rehearsed response converts catches into chaos, so the response runbook ships with the gates rather than after them.
Severity tiers come first. A blocked onboarding attempt with kit-linked assets is routine: index it, decline it, move on. The same assets appearing at the payments gate is an escalation: an active operator is inside the research phase against your institution, and treasury, the named executive's office, and security should know the same day. A detection on a previously approved account is the highest tier: the retrospective question, what else did this identity touch, opens immediately, with the provenance index supplying the cluster.
Communication paths matter more than committees expect. The impersonated executive must be told, carefully, because their calendar, voice, and likeness are now confirmed attacker assets, and their teams need the warning without the panic. Customer-facing detections need scripts that neither accuse nor educate the attacker: a declined session gets a neutral routing message, never a diagnostic. And counterparty notifications, the vendor whose "CFO" requested the banking change, convert your detection into their warning, which is both good citizenship and good evidence.
Reporting closes the loop. Detections meeting suspicious-activity thresholds feed the SAR process with the evidence file attached, kit-linked clusters file as one coherent narrative, and the incident record updates the provenance index so the attack's assets, faces, documents, device fingerprints, channel signatures, are recognized on their next appearance anywhere in the institution. The response's final step is always the same: Arbiter replays the incident's technique against every gate within the week, confirming the hole that let it get as far as it did is now a regression test rather than a standing invitation.
Phase 5: adversarial assurance (ongoing)
The standing phase, and the one that keeps the other four honest. Arbiter's calendar for a deepfake program runs four tracks: weekly generator-current campaigns against the onboarding gate, injection families and rendered faces refreshed as tooling evolves; monthly precision exercises against the payments gate, full impersonation chains from research to release attempt; quarterly persistence sweeps against helpdesk and workforce gates, cloned voices and synthetic candidates; and event-driven campaigns within days of any new generator capability or kit family surfacing.
Every campaign emits findings ranked by exploitability and a regression suite that re-runs weekly. The same discipline applies to vendors, deepidv included: continuous red-team evidence, plus accredited lab results for the injection layer now that certification exists, is the difference between a measured defense and a believed one.
The regulatory map: one program, every expectation
| Obligation or expectation | Requirement shape | Playbook coverage |
|---|---|---|
| HKMA video KYC circular (live) | AI deepfake detection across remote banking video KYC | Phase 1 full-call liveness and injection defense |
| US supervisory examination practice (hardening) | Demonstrated, measured synthetic-media controls with records | Phase 4 evidence architecture and examiner pack |
| BSA/AML reporting | SARs on detected synthetic-identity and impersonation activity | Phase 4 incident-to-SAR integration via Luna |
| Interagency VDC FAQ (Sept 2026) | Credential validation with presenter verification | Onboarding gate: liveness bound to credential exchange |
| Australia documentation-disclosure regime | Produce control records on demand, not attestations | Phase 4 per-decision files, mock examination |
| EU AI Act transparency and eIDAS 2.0 flows | Synthetic-media handling and wallet-era onboarding | Engine layers plus Arc credential path at the onboarding gate |
| Accredited IAD testing (available now) | Third-party evidence for injection defense claims | Phase 5 lab-battery dry-runs and certification scheduling |
The map's executive reading: every regime is converging on the same two demands, detection that is measured rather than asserted, and records that are produced rather than promised. One program built to those two properties absorbs each new circular as scope, not as a project.
Measurement: the program scoreboard
Reviewed monthly by the three sponsors, one page, four sections. Detection metrics: interception rate by attack class against Arbiter campaigns (target: 100 percent of known families at every gate), detections per month by surface with confirmed-fraud conversion, provenance-index hits linking cross-surface attempts, and time from new generator capability in the wild to regression coverage.
Loss metrics: attempted-fraud value stopped at each gate priced against Phase 0's exposure baseline, the retrospective sweep's probable-incident list trending resolved, and the payments gate's above-threshold releases with zero post-release impersonation findings. Operations metrics: gate latency by surface, false-positive rates with customer-impact review, and helpdesk step-down ladder usage showing legitimate users are landing safely. Evidence metrics: per-decision file completeness sampled weekly, examiner-pack refresh currency, and mock-examination pass state, the single line executives should read first, because it is the one a real examination will test.
Failure modes: how deepfake programs actually fail
Five patterns recur, all preventable in the charter. The one-surface program: the institution hardens video KYC and declares victory while the payments, helpdesk, and hiring surfaces stay open, and the attackers simply move; the four-gate charter exists because the threat is portfolio-shaped. The snapshot control: detection runs at the start of the call, and puppeting starts at minute four, so full-session coverage is the control and checkpoints are a migration step that must carry an end date.
The fail-open channel: unverifiable capture paths get waved through to protect completion rates, and injection tooling finds the waiver in weeks; channel anomalies shift evidence requirements, they never waive them. The trusted-executive exception: verified-human release gets an executive bypass for urgency, recreating precisely the attack surface the gate closed, when the correct urgency path is a faster verified check, not an unverified one. And the unmeasured victory: the program deploys, losses drop, attention moves on, and thresholds go stale against next year's generators, which is what Phase 5's standing cadence exists to prevent.
Segment notes
Regional banks and credit unions should sequence for staff impact: the payments gate first if commercial wire volume dominates, the helpdesk gate first if retail account takeover dominates, with onboarding's full build following. The shared engine still matters at smaller scale, because one integration amortizes across every gate the institution eventually adds.
Fintechs and digital banks carry the volume exposure and usually the strongest engineering: onboarding first, with the provenance index prioritized, since ring reuse hits high-growth books hardest, and the workforce gate deserves early attention in remote-first organizations. Wealth and private banking carry the precision exposure: the payments gate is the program, with verified-human release extended down to relationship-manager instruction flows, and the evidence files double as fiduciary protection. Insurers meet the deepfake wave in claims: synthetic media as fabricated evidence and injected sessions at claims intake, where the onboarding gate's architecture transfers directly with media forensics weighted toward manipulated-content detection.
The human layer: process controls that still matter
Detection technology carries the program, but three process controls multiply it, and their absence has featured in every published loss. Out-of-band confirmation as culture: the playbook's verified-human release is the systematized version of a habit every employee should hold, that instructions moving money or changing banking details get confirmed through an independent, known-good channel before action, whatever the video showed. Train it with the research finding attached, that trained reviewers perform near chance against modern synthetic video, because staff who believe they can spot fakes are the staff who approve them.
Request-pattern recognition: precision attacks share a social fingerprint that outlives every generator improvement, urgency plus secrecy plus a payment or credential change, timed to pressure windows, and frontline staff who escalate on the pattern regardless of who appears to be asking defeat attacks whose media passed every visual test. And enrollment hygiene: the verified-human release control is only as good as the enrollment behind it, so authorized instructors are enrolled through the full onboarding gate, re-enrolled on role change, and removed on departure within hours, not quarters, because the revoked-authority gap is the payments-gate version of the stale credential.
The economics: pricing the program
The budget conversation benefits from plain structure, because deepfake defense competes with every other security line and wins on different math. The loss line is the visible argument: Phase 0's exposure pricing, one prevented treasury impersonation at the institution's average large-payment size typically funds the program's first year alone, and the retrospective sweep usually surfaces probable past losses that make the argument historical rather than hypothetical. The ring data strengthens it: with 65.68 percent of linked fraud running reused assets, every detection compounds, because the provenance index converts today's catch into automatic recognition of the ring's next attempt.
The cost-avoidance line is quieter and often larger: supervisory findings carry remediation programs measured in consultant-years, and the Phase 4 evidence architecture is the difference between an examination that ends in an afternoon and one that ends in a finding, while full-call automated detection displaces the reviewer-hours currently spent on a control the research says does not work. The revenue line surprises committees: the same structural liveness that stops synthetic customers approves legitimate ones faster, and onboarding completion improvements from replacing challenge-based flows with passive detection convert directly at the institution's customer lifetime value.
Pull quote“Synthetic media made faces and voices free to fake, so every workflow that trusts them is either defended or donated.”
Choosing the stack: the vendor evaluation grid
Six questions separate deepfake-defense vendors, drawn from the phases above. First, what does the liveness actually measure? Appearance-based passive models decay with each generator release; structural methods that test physical presence, light response and subdermal signals, hold, so ask for the physics, not the accuracy slide. Second, what happens to an unverifiable channel? The only acceptable answer is fail-closed with a documented step-down; any vendor whose default is pass-with-flag is selling the bypass attackers will find. Third, who has attacked it lately? Continuous red-team evidence with current generator tooling, plus accredited lab results for the injection layer now that certification exists, is the minimum falsifiability standard.
Fourth, does detection correlate across sessions and surfaces? The synthetic face rejected at onboarding must be recognized at the helpdesk; per-surface point products rebuild the silo problem the program exists to end. Fifth, what evidence does a decision produce? Request the examiner-facing file for one contested session, produced live during the evaluation, and time it. Sixth, can the same engine gate all four surfaces? One engine with per-surface policy is the architecture; four vendors with four consoles is the fragmentation that Phase 0 priced. A vendor strong on all six is selling the program; a vendor strong on two is selling a component the institution must architect around.
Day-two operations: running the program
Three standing rhythms keep the deployed program alive. The weekly detection review pairs fraud and security over the scoreboard: gate detections, Arbiter findings, provenance-index links, and false-positive impact, one owner and one date per open item. The monthly threat council updates the attack model, new generator capabilities, new kit families, new injection tooling, and lands each as regression coverage with a test date. The quarterly examination rehearsal produces one supervisor-grade evidence pack from live system output, rotating across the regimes in the regulatory map, keeping the Phase 4 pass state current rather than commemorative.
Staffing lands lighter than committees expect: an adversarial liaison converting Arbiter and lab findings into engineering tickets, a detection-operations owner per gate cluster, and the investigator queue sized to confirmed-detection volume. The manual review hours the program retires typically fund all three roles, which is the quiet reason well-built deepfake programs survive budget season while bolt-on detectors get cut.
The ninety-day variant
Institutions facing a forcing event, a supervisory finding, a fresh loss, a board mandate, compress to the spine: Phase 0 in one week (surface inventory and exposure pricing only), the onboarding gate's injection defense and liveness in four, the payments gate's verified-human release in three, and evidence-file generation switched on from day one, with helpdesk, workforce, and the full examiner pack following after the deadline passes. Nothing in the compressed variant is throwaway; every component is the permanent architecture arriving in triage order.
Deepfake Defense Playbook FAQ
- What is a deepfake defense program for a financial institution?
- An institution-wide architecture that detects synthetic media at every surface where a face or voice can move money, data, or access: onboarding and video KYC, payment authorization, helpdesk recovery, and hiring, using one shared detection engine with per-surface gates, evidence files, and continuous adversarial testing.
- How do banks detect deepfakes in video KYC?
- With layered detection through the full call: structural liveness that tests physical presence, capture-path verification that rejects injected streams, and media forensics on content, all failing closed on unverifiable channels. Manual visual review is no longer considered an adequate control by supervisors or by the research.
- How do institutions stop deepfake wire fraud?
- With verified-human release: payment instructions above threshold require a liveness-confirmed re-authentication of the instructing party, independent of the video call or email that carried the request. The control breaks the executive-impersonation attack at the release step, where the loss actually occurs.
- Should helpdesks use deepfake detection?
- Yes, urgently. Cloned voices plus breached data defeat knowledge-based recovery reliably, making support queues the quiet route to account takeover. The fix is login-grade re-verification for recovery requests plus voice forensics on the call, with a step-down ladder for legitimate customers in difficult circumstances.
- How much deepfake detection evidence do examiners expect?
- Measured detection rates by attack class on the institution's own traffic, third-party or red-team results for injection defense, per-decision evidence files reconstructable on demand, and documented escalation and reporting paths. The examiner's test is production of records, not description of programs.
- How long does an institution-wide deepfake program take?
- Roughly eighteen weeks on this playbook's phasing: two of exposure audit, four for the onboarding gate, three for payments, four for helpdesk and workforce, three for evidence operations, then standing adversarial assurance. A ninety-day compressed variant covers the spine when a forcing event demands it.
Relevant Articles
Deepfake Detection for Banks: Video KYC's New Baseline
The supervisory context in depth.
Sep 14, 2026
Injection Attack Detection: Closing the Virtual Camera Gap
The channel layer of the engine.
Sep 14, 2026
How to Detect a Deepfake
The signal stack behind every gate.
Sep 11, 2026
KPMG Buys Into Deepfake Detection
The market maturation driving the timeline.
Sep 14, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More