The Deepfake KYC Era: Why Verification Must Move From Checkbox Compliance to Predictive Defence

I have spent over two decades in banking and financial services, and in that time, I have watched identity fraud change its nature entirely. For most of those years, fraud was a forgery problem. Someone presented a document that was not theirs, and the job of verification was to spot the mismatch. That era has quietly ended. The person attempting to open an account in your bank today does not need to steal a document. A photograph and a few seconds of audio will do.

The numbers describe a system under a different kind of pressure. The Reserve Bank’s latest annual report shows the number of reported bank fraud cases falling sharply to a little over 10,000, even as the value involved rose to around Rs 48,021 crore. Fewer incidents, considerably larger losses. That is not the profile of a safer system. It is the profile of one where attacks have become better researched, better targeted and far more valuable per attempt. Separately, close to 28 lakh cyber fraud cases involving roughly Rs 22,931 crore were reported through the National Cyber Crime Reporting Portal during 2025.

The regulator has read the signal correctly. In its April discussion paper on digital payment safeguards, the Reserve Bank named deepfake impersonation in the same breath as bogus call centres and mule account networks, and proposed structural measures including a lagged credit window for large person to person transfers. Draft directions on customer liability in electronic banking fraud have followed. The direction of travel is unmistakable. Supervision is shifting from asking institutions whether they verified a customer to asking whether they could reasonably have seen the fraud coming.

That is a far harder question to answer, and it exposes the weakness in how most verification is still built. A large part of India’s onboarding infrastructure was designed for a world where the threat was a person holding a printed photograph in front of a camera. It asks a single question at a single moment. Is the document valid, is the face live, does the name match. Once the customer clears that gate, the file is closed and the compliance record is complete. Synthetic identities are constructed precisely for that gate. A genuine Aadhaar number paired with a fabricated name and address will pass validation, because the number itself is real. An injected video stream will pass a first generation liveness check, because the check was never designed to ask where the video came from.

Predictive defence begins with three shifts in thinking. The first is treating verification as a continuing state rather than a single event. A customer verified at onboarding is not verified forever. Risk changes when the device changes, when behaviour changes, when money begins moving in patterns that do not fit the profile.

The second is correlating signals instead of scoring them in isolation. A deepfake rarely fails on the face alone. It fails on the mismatch between the location of the device handling the OTP and the device carrying the video, on metadata inconsistencies, on an application completed at a speed no human hand achieves. Individually these read as noise. Read together, they read as an attempt.

The third, and the most uncomfortable for our industry, is accepting that no single institution sees enough to defend itself well. Mule networks operate across banks by design, which is exactly why the Reserve Bank Innovation Hub’s work on machine learning models for near real time mule account identification matters. It is a recognition that fraud intelligence performs best as shared infrastructure rather than as a private asset.

None of this makes compliance less important. It makes compliance more useful. The institutions that come through this period intact will be the ones that stop treating verification as a file to be completed and start treating it as a risk position to be monitored. The audit trail should be the by product of a good defence, not the purpose of it.

Working with enterprises in this space on verification and risk infrastructure, the pattern I encounter most often is that technology is rarely the constraint. The constraint is the assumption that a customer, once cleared, stays cleared. In the deepfake era, that assumption is itself the vulnerability.

Authored by

S. Anand

 

S. Anand

Founder and CEO

PaySprint, India’s B2B Banking Fintech and Regtech Infrastructure Company

Popular from web