Skip to content

Risk & Fraud

Deepfake & Synthetic Identity Fraud in KYC: A BFSI Guide to Detection and Defense

Deepfakes are testing Video KYC. See what RBI's KYC norms require and how BFSI teams are strengthening liveness detection and face matching.

Pranshi Mittal

· 8 min read

Deepfake and synthetic identity fraud in KYC: a BFSI guide to detection and defense. A face held inside a verification frame under a scan line, with an alert marker beside it.

Executive Summary

Deepfake and synthetic identity fraud in KYC means using AI-generated faces, voices, or fabricated identity data to impersonate or invent a customer during onboarding. Most of these attacks are built specifically to target Video KYC (V-CIP), the live video call that Indian banks and NBFCs use to confirm that an applicant is a real, present, and consenting person. As V-CIP becomes the default onboarding path across BFSI, the same call designed to stop impersonation has become the point attackers are trying hardest to beat.

Deepfake and synthetic identity fraud: detecting what isn't real before onboarding completes. A face rendered half photographic and half wireframe, with flagged face and voice inputs on one side and signal mismatch and liveness checks on the other.

This piece looks at how deepfake and synthetic identity fraud actually attack the KYC process, what RBI's KYC norms already require of Video KYC systems, and where liveness detection and face matching fit into a compliant, fraud-resilient onboarding flow.

Deepfake Fraud and Synthetic Identity Fraud Are Not the Same Problem

The two terms get used interchangeably, but they describe different attack patterns, and BFSI risk teams end up building different defenses for each.

Deepfake fraud uses AI-generated video, audio, or images to impersonate a real, specific identity, usually someone else's, during a liveness check or a live V-CIP call. The face on screen is designed to pass as a real person who is not actually present.

Synthetic identity fraud combines real and fabricated data points, for example a genuine mobile number or partial document data stitched to an invented name or date of birth, to construct an identity that does not correspond to any single real person. It is less about impersonating someone specific and more about manufacturing a plausible someone.

The two increasingly overlap: a synthetic identity built from fabricated data is easier to push through onboarding if it is also fronted by a deepfaked face during the video call. This piece focuses specifically on the video KYC and liveness layer, where deepfakes do most of their work.

Where Deepfakes Actually Attack the KYC Process

Deepfake attacks target four distinct points in a typical digital onboarding flow, and each one needs a different defense.

KYC stepHow a deepfake attacks itWhat should catch it
Live V-CIP video callReal-time face-swap or AI avatar overlaid on the applicant's video feed during the interviewPassive liveness detection plus randomized, varied questioning during the call
Liveness or spoof checkA pre-recorded or fully AI-generated video submitted in place of a live camera feedLiveness detection built to catch injection attacks, not only printed-photo or screen-replay attacks
Face matchingAn AI-generated face constructed to statistically resemble the photo on the submitted ID documentFace matching that returns a confidence score against a threshold the institution sets, not a simple pass or fail
Document submissionAI-manipulated or fabricated ID document images submitted alongside the video callDocument checks used together with face matching, never as a standalone signal

This is also why liveness detection and face matching are usually discussed as a pair rather than as substitutes for each other. Liveness detection confirms a real human is present in front of the camera right now. Face matching confirms that human is the same person shown on the submitted ID. A system can pass one check and still fail the other.

Two checks, different jobs. Liveness detection confirms a real human is physically present on camera right now. Face matching confirms that human is the same person shown on the submitted ID.

What RBI's KYC Norms Already Require of Video KYC

BFSI compliance teams do not need to guess at what "good enough" liveness and face-match defenses look like. RBI's Master Direction on Know Your Customer (KYC) Direction, 2016 (updated August 14, 2025), sets specific requirements for V-CIP:

"The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy... Appropriate artificial intelligence (AI) technology can be used to ensure that the V-CIP is robust."

"Based on experience of detected / attempted / 'near-miss' cases of forged identity, the technology infrastructure including application software as well as work flows shall be regularly upgraded."

"The sequence and/or type of questions, including those indicating the liveness of the interaction, during video interactions shall be varied."

"Any prompting observed at [the] end of [the] customer shall lead to rejection of the account opening process."

Read together, these clauses describe a system that does not treat liveness and face matching as a one-time gate. It expects randomized questioning within the call itself, ongoing upgrades based on near-miss fraud attempts, and automatic rejection when a customer appears to be reading from a script or being coached off-camera. For a BFSI compliance or risk head, this is the baseline a deepfake-resilient V-CIP workflow has to clear, not an aspirational target.

Fraud Attempts Are Getting More Layered, Not Simpler

Attackers are increasingly combining techniques rather than relying on a single method. Sumsub's September 2026 fraud report found that attacks combining multiple fraud techniques within a single verification attempt rose 180% year-over-year, even as the overall global identity fraud rate fell from 2.6% to 2.2%. In practice, that means fewer isolated forged documents or one-off face-swap attempts, and more attempts that stack a fabricated document, a synthetic identity, and a manipulated face or video together in the same onboarding session.

That trend is a big part of why a deepfake detection API for KYC cannot sit in isolation. Liveness detection, face matching, and document verification need to work off the same session so a pass on one check does not quietly offset a failure on another.

How FinHub Supports Deepfake-Resilient Onboarding and Video KYC

FinHub's Face Verification suite is built as API-level infrastructure that BFSI teams plug into their own onboarding and V-CIP workflow, rather than a packaged product that sits outside it:

  • Face Liveliness checks whether the face presented during onboarding belongs to a live human physically in front of the camera, rather than a photo, screen replay, or AI-generated feed.
  • Face Matching compares the live capture against the photo on the submitted ID document to confirm they belong to the same person, as a real-time face match KYC solution rather than a batch process run after the fact.
  • Age Verification confirms the applicant meets age-based eligibility rules as part of the same face-verification step.
  • Image Background Removal standardizes captured images for downstream verification and record-keeping.
  • Intelli VKYC supports the video-based customer identification call itself, the same V-CIP workflow RBI's KYC norms govern.

Together, these sit inside FinHub's broader KYC and verification API suite, so liveness, face matching, and video KYC are not bolted onto a separate VKYC platform, they run against the same applicant record as the rest of onboarding.

A Practical Checklist for Evaluating Deepfake Defenses

Before committing to a vendor or a build for this layer, BFSI risk and compliance teams typically work through a short list of questions:

Before you sign: five questions on deepfake defenses. Passive or active liveness, a confidence score rather than a pass or fail, randomized questioning during V-CIP calls, whether near-misses are logged, and whether a rejected session's evidence is retained.
  • Is the liveness check passive, requiring no gestures from the applicant, or active, requiring a blink or head turn, and does it hold up against injection attacks and not just presentation attacks like a printed photo?
  • Does face matching return a confidence score and a threshold your institution controls, or only a pass and fail result with no visibility into how close a match was?
  • Is question sequencing during the V-CIP call randomized per session, in line with RBI's requirement that question type and sequence be varied?
  • Does the platform log and flag near-miss and prompting incidents in a form your audit and compliance team can actually review?
  • What happens to a rejected or flagged session afterward, and is that decision and its evidence retained in the audit trail?

See How FinHub Strengthens Your KYC Fraud Defenses

Deepfake and synthetic identity fraud do not wait for the next policy review cycle. If your Video KYC or onboarding flow needs stronger liveness detection, real-time face matching, or a broader identity verification layer built for BFSI compliance, FinHub's team can walk you through the relevant APIs for your existing stack.

Book a demo with FinHub

FAQ

Deepfake & synthetic identity fraud in KYC: Common Questions

Deepfake fraud in KYC is the use of AI-generated video, audio, or images to impersonate a real identity during identity verification, most often during a live Video KYC (V-CIP) call or a liveness check, so that an unauthorized or fabricated applicant appears to be a genuine, present customer.

Talk to Our Product Experts

See how these ideas apply to your institution's specific workflows.