The important shift is not that deepfakes exist - it is that recognising a colleague's voice or face is no longer evidence of anything. Any control that depends on a human identifying another human through a screen or a phone line has quietly stopped working.
How it is actually used
- Voice cloning for payment fraud - a short call from a senior executive authorising an urgent transfer, using a voice cloned from publicly available audio.
- Video calls with synthetic participants, sometimes multiple, to lend credibility to an instruction.
- Voice-based helpdesk fraud - impersonating an employee to obtain a password or MFA reset, which is the fastest route to account takeover.
- Recruitment fraud - synthetic candidates in remote interviews, used to place an insider or obtain equipment and access.
Note what is common to all four: the attack targets a process that treats recognition as authentication. Nothing technical is exploited.
Detection is not the answer
Detection tools exist and their accuracy varies considerably, degrades on compressed calls, and will always trail generation quality. Building a control on the assumption that a person or a tool will spot a fake is building on a moving foundation.
Design instead for the case where the impersonation is perfect - which is a far more stable assumption and, conveniently, produces controls that also defeat conventional social engineering.
Controls that hold
- Out-of-band verification for anything financial. Call back on the number already held in your records - never one supplied in the request. This single control defeats most payment fraud regardless of how convincing the approach was.
- Dual authorisation for payments and bank detail changes above a threshold, with the second approver contacting the requester independently.
- Helpdesk verification that does not rely on voice - a challenge through an enrolled device, a manager confirmation, or an in-person check for high-privilege resets.
- A stated policy that urgency is not a valid override. Every one of these attacks depends on pressure; saying explicitly that no legitimate request requires bypassing verification removes the lever.
- Pre-agreed verification for executives, so an unusual instruction has a defined confirmation path rather than deference.
Govern AI risk alongside your other controls
GRC Copilot assesses AI systems and related risks against ISO 42001 and your existing frameworks, with controls and evidence in one place.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Reduce the raw material
Voice cloning needs samples, and executives with conference recordings, podcasts and earnings calls online provide plenty. You cannot realistically remove that, but you can stop treating public presence as harmless: assume any public-facing individual can be convincingly cloned, and make sure the processes around them do not depend on voice recognition.
Train for the right thing
Awareness training that teaches people to spot visual artefacts ages badly and creates false confidence. Train the process instead: what a payment change request must go through, that verification is expected and never rude, and that the person who follows the process during a convincing call is doing exactly the right thing even if it is uncomfortable.
Frequently asked questions
Can we detect deepfakes reliably?
Not dependably enough to build a control on. Accuracy varies and degrades on real-world call quality.
What single control matters most?
Call-back verification on a number already held in your records for any payment or bank detail change.
Should we test this with simulations?
Testing whether the verification process is followed is valuable. Impersonating real named executives raises ethical and legal issues - use a generic pretext.
Is this covered by existing fraud controls?
Often the controls exist but are waived under pressure. The gap is usually enforcement and culture rather than design.
Key takeaways
- Recognition is no longer authentication - design as if impersonation is perfect.
- Call-back on a known number defeats most of this.
- Urgency is the shared lever; state explicitly that it overrides nothing.
- Train the process, not artefact-spotting.