Deepfake Detection for Banks: Video KYC's New Baseline
Deepfake detection for banks is now a supervisory expectation. How video KYC, payments, and treasury workflows get defended, and what examiners will ask.

Deepfake detection for banks stopped being optional the day a supervisor first wrote it into guidance. Hong Kong's HKMA now requires AI-based deepfake detection across remote banking video KYC, and equivalent expectations are hardening in every major jurisdiction as examiners absorb the same facts the fraud data keeps repeating: deepfake documents account for 80.10 percent of AI-enabled fraud attacks, deepfake identity fraud was projected to grow nearly five-fold this year, and human reviewers, the control most banks still quietly rely on, perform near chance against modern synthetic video.
The consulting world just confirmed the trajectory with capital: KPMG's investment in a deepfake detection firm this month folds the capability into Big Four service lines, and accredited laboratories now test injection attack defenses independently. When supervisors mandate it, consultancies productize it, and labs certify it, a control has become a baseline.
This guide covers where deepfakes actually hit banks, what a defensible detection architecture looks like, and the questions examiners are learning to ask.
The four bank workflows deepfakes target
Video KYC and remote onboarding
The headline target. Remote account opening over video was built to defeat document fraud and absent customers; synthetic video defeats it back. Attacks arrive as real-time face puppeting on live calls, pre-rendered synthetic responses to challenge prompts, and injection of entirely synthetic sessions through virtual cameras. The HKMA circular exists because manual review of these calls fails: the reviewer sees a fluent, responsive customer whose face was rendered milliseconds earlier.
Payment authorization and treasury
The money-moving deepfake. The canonical case remains the Hong Kong engineering firm that wired $25 million after a video call populated by synthetic executives, and the pattern has since industrialized against payroll changes, vendor banking updates, and treasury releases. The control gap is structural: payment workflows authenticate the channel and the credentials, not the human face giving the instruction.
Helpdesk and account recovery
The quiet epidemic. Account recovery resets credentials for callers who can pass identity questions, and cloned voices plus rehearsed data pass them reliably. IT and customer helpdesks have become the soft entry to otherwise hardened accounts, which is why voice deepfake detection and callback-with-verification policies now belong in the same program as video defense.
Employment and insider onboarding
The long game. Synthetic candidates interviewing over video for remote roles, with an accomplice or an operator behind the rendered face, convert hiring pipelines into access pipelines. Banks running remote-first hiring inherited a verification workload HR was never staffed to run.
The defensible architecture
Supervisory language converges on "AI-based detection," but examiners increasingly understand layers, and a bank's architecture should show them. A single-model detector is an answer to last year's question; the architecture below is the answer to the examination that is coming, and each of the four layers exists because a documented, named attack family defeats the layer above it in production conditions.
Layer one: structural liveness on every face
The foundation is verifying a live, physically present human rather than judging rendered pixels. deepidv's deepeye runs structural light analysis and subdermal reflectance through passive capture, testing properties, three-dimensional geometry, subsurface light scattering in living tissue, that no screen, mask, or injected stream reproduces. Because the test is physical presence rather than visual plausibility, it does not decay as generators improve, which is the property that separates a durable control from a model in an arms race. The full stack is documented on the [deepidv technology page](/technology).
Layer two: capture and injection defense
Most banking deepfakes never touch a camera; they enter through virtual camera drivers or stream substitution. Capture-path verification, driver provenance, sensor noise lineage, hardware-signed capture sessions where devices support them, rejects synthetic streams before their content is judged. This is the layer the new accredited testing regimes certify, and the layer to demand third-party results for.
Layer three: media forensics and voice analysis
Content-level detection still earns its place: frequency-domain artifacts and generation fingerprints on video, spectral and biomarker analysis on voice. In call-based workflows, video and voice verdicts corroborate each other, and a session passing one while failing the other routes to escalation rather than approval.
Layer four: continuous adversarial validation
Detection that is not attacked internally is being attacked externally. deepidv runs [Arbiter](/arbiter) against production stacks with current generator tooling and fraud persona kits on a standing cadence, producing the findings register and regression evidence that also happens to be exactly what an examiner means by "how do you know it works."
Deployment: where detection actually sits
The architecture only pays when it sits inside the workflows, not beside them. Video KYC runs detection through the full call, not a start-of-call snapshot, since puppeting can begin mid-session. Payment workflows above a threshold add verified-human confirmation, a liveness-checked re-authentication of the instructing party, breaking the wire-by-video attack at its point of profit. Helpdesk flows route recovery requests through the same verification the account would require at login, ending the pass-the-quiz reset. And hiring pipelines for sensitive roles borrow the onboarding stack: document verification, liveness, and provenance checks against known synthetic assets.
Each deployment produces the same by-product: a per-decision evidence file. That is the artifact that converts a detection program from a security expense into examination capital.
What examiners will ask
The questions are standardizing quickly, and banks can rehearse them. Which workflows carry deepfake exposure, and which carry detection? What are the measured detection rates, by attack class, on your traffic rather than a vendor benchmark? Who tested the injection defense, and when, name the lab or the internal red-team cadence? What happens on detection: the escalation path, the customer-facing handling, the reporting trail? And the closer: show the file for this flagged session.
Banks that can answer from system output are done in an afternoon. Banks that answer from policy documents are beginning a finding.
Bank Deepfake Detection FAQ
- Are banks required to use deepfake detection?
- In Hong Kong, yes: the HKMA requires AI-based deepfake detection across remote banking video KYC. Elsewhere, supervisory expectations are converging the same way through examination practice, and manual review of synthetic video is increasingly treated as an inadequate control rather than a defensible one.
- How do deepfakes attack bank onboarding?
- Three main routes: real-time face puppeting on live video KYC calls, pre-rendered synthetic responses to challenge prompts, and injection of fully synthetic sessions through virtual cameras that bypass the physical camera entirely. Defense requires structural liveness plus capture-path verification, not visual review.
- What is the best deepfake detection approach for video KYC?
- Layered: structural liveness that verifies physical presence through the whole call, injection defense on the capture path, media and voice forensics on content, and continuous red-team validation. Single-layer detectors decay against each new generator release; the layered stack holds because presence and capture physics do not.
- How do banks stop deepfake wire fraud?
- By re-verifying the human at the point of instruction: payment releases above threshold require a liveness-confirmed authentication of the instructing party, independent of the video call or email chain that carried the request. The $25 million video-call losses all share one property: the face was never verified, only watched.
- What deepfake evidence do bank examiners expect?
- Measured detection rates by attack class on the bank's own traffic, third-party or red-team test results for injection defense, documented escalation and reporting paths, and reconstructable per-session evidence files. Vendor brochures and policy statements no longer close the question.
Relevant Articles
How to Detect a Deepfake
The signals underneath the bank stack.
Sep 11, 2026
Injection Attack Detection: Closing the Virtual Camera Gap
The channel layer of the engine.
Sep 14, 2026
KPMG Buys Into Deepfake Detection
The market maturation moment.
Sep 14, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More