Pranshi Mittal
· 8 min read

Executive Summary
Deepfake and synthetic identity fraud in KYC means using AI-generated faces, voices, or fabricated identity data to impersonate or invent a customer during onboarding. Most of these attacks are built specifically to target Video KYC (V-CIP), the live video call that Indian banks and NBFCs use to confirm that an applicant is a real, present, and consenting person. As V-CIP becomes the default onboarding path across BFSI, the same call designed to stop impersonation has become the point attackers are trying hardest to beat.

This piece looks at how deepfake and synthetic identity fraud actually attack the KYC process, what RBI's KYC norms already require of Video KYC systems, and where liveness detection and face matching fit into a compliant, fraud-resilient onboarding flow.
Deepfake Fraud and Synthetic Identity Fraud Are Not the Same Problem
The two terms get used interchangeably, but they describe different attack patterns, and BFSI risk teams end up building different defenses for each.
Deepfake fraud uses AI-generated video, audio, or images to impersonate a real, specific identity, usually someone else's, during a liveness check or a live V-CIP call. The face on screen is designed to pass as a real person who is not actually present.
Synthetic identity fraud combines real and fabricated data points, for example a genuine mobile number or partial document data stitched to an invented name or date of birth, to construct an identity that does not correspond to any single real person. It is less about impersonating someone specific and more about manufacturing a plausible someone.
The two increasingly overlap: a synthetic identity built from fabricated data is easier to push through onboarding if it is also fronted by a deepfaked face during the video call. This piece focuses specifically on the video KYC and liveness layer, where deepfakes do most of their work.
Where Deepfakes Actually Attack the KYC Process
Deepfake attacks target four distinct points in a typical digital onboarding flow, and each one needs a different defense.
| KYC step | How a deepfake attacks it | What should catch it |
|---|---|---|
| Live V-CIP video call | Real-time face-swap or AI avatar overlaid on the applicant's video feed during the interview | Passive liveness detection plus randomized, varied questioning during the call |
| Liveness or spoof check | A pre-recorded or fully AI-generated video submitted in place of a live camera feed | Liveness detection built to catch injection attacks, not only printed-photo or screen-replay attacks |
| Face matching | An AI-generated face constructed to statistically resemble the photo on the submitted ID document | Face matching that returns a confidence score against a threshold the institution sets, not a simple pass or fail |
| Document submission | AI-manipulated or fabricated ID document images submitted alongside the video call | Document checks used together with face matching, never as a standalone signal |
This is also why liveness detection and face matching are usually discussed as a pair rather than as substitutes for each other. Liveness detection confirms a real human is present in front of the camera right now. Face matching confirms that human is the same person shown on the submitted ID. A system can pass one check and still fail the other.

What RBI's KYC Norms Already Require of Video KYC
BFSI compliance teams do not need to guess at what "good enough" liveness and face-match defenses look like. RBI's Master Direction on Know Your Customer (KYC) Direction, 2016 (updated August 14, 2025), sets specific requirements for V-CIP:
"The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy... Appropriate artificial intelligence (AI) technology can be used to ensure that the V-CIP is robust."
"Based on experience of detected / attempted / 'near-miss' cases of forged identity, the technology infrastructure including application software as well as work flows shall be regularly upgraded."
"The sequence and/or type of questions, including those indicating the liveness of the interaction, during video interactions shall be varied."
"Any prompting observed at [the] end of [the] customer shall lead to rejection of the account opening process."
Read together, these clauses describe a system that does not treat liveness and face matching as a one-time gate. It expects randomized questioning within the call itself, ongoing upgrades based on near-miss fraud attempts, and automatic rejection when a customer appears to be reading from a script or being coached off-camera. For a BFSI compliance or risk head, this is the baseline a deepfake-resilient V-CIP workflow has to clear, not an aspirational target.
Fraud Attempts Are Getting More Layered, Not Simpler
Attackers are increasingly combining techniques rather than relying on a single method. Sumsub's September 2026 fraud report found that attacks combining multiple fraud techniques within a single verification attempt rose 180% year-over-year, even as the overall global identity fraud rate fell from 2.6% to 2.2%. In practice, that means fewer isolated forged documents or one-off face-swap attempts, and more attempts that stack a fabricated document, a synthetic identity, and a manipulated face or video together in the same onboarding session.
That trend is a big part of why a deepfake detection API for KYC cannot sit in isolation. Liveness detection, face matching, and document verification need to work off the same session so a pass on one check does not quietly offset a failure on another.
How FinHub Supports Deepfake-Resilient Onboarding and Video KYC
FinHub's Face Verification suite is built as API-level infrastructure that BFSI teams plug into their own onboarding and V-CIP workflow, rather than a packaged product that sits outside it:
- Face Liveliness checks whether the face presented during onboarding belongs to a live human physically in front of the camera, rather than a photo, screen replay, or AI-generated feed.
- Face Matching compares the live capture against the photo on the submitted ID document to confirm they belong to the same person, as a real-time face match KYC solution rather than a batch process run after the fact.
- Age Verification confirms the applicant meets age-based eligibility rules as part of the same face-verification step.
- Image Background Removal standardizes captured images for downstream verification and record-keeping.
- Intelli VKYC supports the video-based customer identification call itself, the same V-CIP workflow RBI's KYC norms govern.
Together, these sit inside FinHub's broader KYC and verification API suite, so liveness, face matching, and video KYC are not bolted onto a separate VKYC platform, they run against the same applicant record as the rest of onboarding.
A Practical Checklist for Evaluating Deepfake Defenses
Before committing to a vendor or a build for this layer, BFSI risk and compliance teams typically work through a short list of questions:

- Is the liveness check passive, requiring no gestures from the applicant, or active, requiring a blink or head turn, and does it hold up against injection attacks and not just presentation attacks like a printed photo?
- Does face matching return a confidence score and a threshold your institution controls, or only a pass and fail result with no visibility into how close a match was?
- Is question sequencing during the V-CIP call randomized per session, in line with RBI's requirement that question type and sequence be varied?
- Does the platform log and flag near-miss and prompting incidents in a form your audit and compliance team can actually review?
- What happens to a rejected or flagged session afterward, and is that decision and its evidence retained in the audit trail?
See How FinHub Strengthens Your KYC Fraud Defenses
Deepfake and synthetic identity fraud do not wait for the next policy review cycle. If your Video KYC or onboarding flow needs stronger liveness detection, real-time face matching, or a broader identity verification layer built for BFSI compliance, FinHub's team can walk you through the relevant APIs for your existing stack.