top of page

azakaw named an IDC Innovator in Middle East Regulatory Technology Providers 2026 Report

azakaw colored logo.png
Arrow 6.png

What is a deepfake? How it works and how to prevent it

  • Writer: azakaw
    azakaw
  • 6 days ago
  • 12 min read

Updated: 14 hours ago

Deepfakes are no longer merely a social media issue. They have become a documented financial crime tool, and the numbers make that hard to ignore.


According to some online reports, deepfake fraud increased globally by four times between 2023 and 2024, making up 7% of all fraud attempts on verification platforms. 


For compliance officers, KYC analysts, and fraud teams in the UAE, Saudi Arabia, South Africa, etc deepfakes pose a direct threat to digital onboarding, video KYC, and customer due diligence controls.


This guide outlines how the threat works, what it means for your compliance programme, and what detection controls are available.


Deepfakes - Key Takeaways

  • Deepfakes have evolved from manipulated media into a financial crime tool.

  • Deepfake fraud can combine face swaps, voice cloning, synthetic identities, and AI-generated documents to impersonate legitimate customers or executives.

  • Digital onboarding is exposed because institutions must establish identity remotely through documents, biometrics, video, device data, and automated checks that attackers can attempt to manipulate.

  • A successful deepfake can compromise the entire compliance lifecycle.

  • Liveness detection remains important, but it is not sufficient on its own.

  • Stronger protection combines liveness detection, AI-based deepfake analysis, behavioural signals, document authentication, secondary data verification, and human review for suspicious or higher-risk cases.

  • Compliance teams should explicitly incorporate deepfake risk into KYC and EDD procedures, staff training, escalation protocols, and due diligence of identity verification vendors.

  • For regulated businesses in markets such as the UAE, Saudi Arabia, and South Africa, deepfake resilience is increasingly part of maintaining effective remote identity verification and CDD controls.


What are deepfakes?

Deepfakes are synthetic audio, video, or image files created using artificial intelligence (AI) to make a real person appear to say or do things they never actually did


For compliance reasons, the key point is this: deepfakes will make a fraudster appear and sound just like someone else during a real-time verification session.


Nowadays, deepfakes are a common business fraud.


How does deepfake work?

Most deepfakes use a type of AI known as a generative adversarial network (GAN). A GAN works by pitting two AI models against each other:

  • One model develops a fake image or video.

  • The other model tries to establish if it's authentic.


After countless iterations over thousands of cycles, the generator improves until its output is nearly impossible to differentiate from actual footage.


Face-swap deepfakes superimpose one person's facial features onto another person's live video feed in real time. Voice cloning creates a synthetic voice that copies a particular individual using just a few seconds of audio.


All these methods are now accessible via commercial tools, dark web services and even open-source software.

The evolution from social media threat to financial crime tool

Deepfakes initially came to public attention through manipulated celebrity videos and political disinformation. Compliance teams mostly stood on the sidelines watching from afar. That distance is closing fast.


In February 2024, a multinational company's finance employee based in Hong Kong was tricked into moving $25 million after a video call in which all participants, except the person pretending to be the company's chief financial officer, were deepfakes. (Hong Kong Police Force press conference, February 2024)


Although that case didn't involve digital KYC onboarding, it showed that even highly skilled professionals could be deceived by a live video call which had been fabricated to such a high standard.


The same technology now aims at video KYC sessions held at regulated financial institutions.


Reduce Deepfake Fraud Risk

Automate and accelerate the onboarding process, minimising manual intervention and reducing errors by leveraging an AI-powered solution built by AML compliance experts.


How deepfakes are used to commit financial fraud

The various uses of deepfakes in financial crime go far beyond what most compliance teams have planned so far. Knowing each type of attack helps to construct controls that address the full extent of the threat.


Defeating video KYC and remote identity verification

Video KYC, where a client verifies their identity through a live video session with an agent or an automated system, has been introduced in part to add a human element that photos alone cannot provide. 


Deepfakes attack this directly. A fraudster will use a face-swap tool to put a stolen identity's photo over their own live video feed. To a basic automated system checking if there is a face and whether it matches an ID photo, the deepfake will pass.


Sumsub's data show deepfake attacks increased by 533% in fintech between 2023 and 2024.


The UAE, where digital onboarding has accelerated quickly under CBUAE frameworks, and South Africa, where FSCA-regulated fintechs have adopted eKYC at scale, are both in markets where this type of attack is becoming increasingly common.


Read more about UAE AML compliance.


Synthetic identity fraud and account takeover

A synthetic identity combines actual data points, for example, an existing national ID number, with completely made-up personal details, often backed up by an AI-generated face and a deepfake video to get past biometric verification.


The final identity doesn't actually belong to a real person, so no actual victim will file a fraud complaint. McKinsey estimates synthetic identity fraud costs US banks around $6 billion every year.


Deepfakes do strengthen synthetic identity attacks. Rather than sending a still photograph that biometric systems can look at closely, fraudsters send live video that passes liveness checks.


The process is to make sure a real, present person is doing the verification because the deepfake video seems to move and react naturally.



CEO and executive impersonation in payment fraud

Beyond initial customer onboarding, deepfakes are being used to impersonate senior executives in payment authorisation fraud.


A deepfake audio call or video message from someone appearing to be the CFO or CEO tells a finance employee to authorise an urgent wire transfer.


Regula's 2024 survey found that financial services companies that experienced deepfake fraud reported an average loss of $603,000 per affected company (Regula Deepfake Fraud survey, August 2024).


AI-generated identity documents and forged evidence

Generative AI tools today create convincingly fake identity documents (passports, driving licenses, national ID cards) that will pass basic visual checks and some OCR checks. 


Sumsub's 2025-2026 fraud report noted that AI-assisted document forgery rose from 0% to 2% of all fraud types between 2024 and 2025, driven by tools including large public language models.


These AI-generated documents, when combined with a deepfake video of a person 'holding' them, form a compound attack that beats non-integrated verification systems.

The AML and compliance risk landscape

Deepfakes aren't just threatening fraud controls. They do threaten the whole customer due diligence process that AML programs rely on.


When a false identity does get past onboarding, every subsequent control is working off a seriously compromised base.


Why digital onboarding creates vulnerability

Traditional branch onboarding lets staff actually hold documents, see the customer and make a judgement that no automated system could fully replicate.


Digital onboarding removes much of that physical verification layer. Instead, institutions have to establish identity remotely through uploaded documents, facial biometrics, video, device data and automated identity checks.

This creates a fundamentally different risk.


Images and videos can be manipulated, biometric checks can be targeted with presentation or injection attacks, and fraudsters can attempt onboarding remotely and at scale.


Deepfake technology makes this particularly dangerous because it can create increasingly convincing synthetic faces, videos and identities designed specifically to pass automated verification.


The UAE's swift adoption of digital financial services within CBUAE frameworks and Saudi Arabia's Vision 2030-driven fintech expansion have all greatly increased the digital onboarding surface area.


South Africa's FSCA-regulated sector has also seen eKYC adoption accelerate.


Every expansion presents an even greater attack opportunity if deepfake detection doesn't keep pace with the rate of digital onboarding adoption.


Accelerate Global User Onboarding

Transform end-to-end onboarding with customised flows tailored to your business needs using the most advanced and secure solution available in the market.



Deepfakes and the breakdown of CDD controls

Customer Due Diligence is the process of verifying who a customer is and evaluating the risk they represent, relies heavily on identity verification at onboarding.


If a deepfake gets past that verification, the CDD record will be based on a completely false identity.


Transaction monitoring, risk scoring and SAR filing all originate from that compromised baseline.


Our experience shows that fraud isn't limited to onboarding; it spreads throughout the whole compliance lifecycle.

Regulatory exposure: what regulators in UAE, KSA and South Africa expect

Regulators in all three markets demand that regulated entities use robust identity verification methods proportionate to the level of risk involved.


  • CBUAE's digital onboarding guidelines actually mandate liveness detection and biometric verification as part of eKYC. 

  • SAMA's AML framework demands controls that tackle emerging financial crime risks.

  • The FSCA in South Africa will require FICA-compliant CDD, with digital verification methods expected to offer the same degree of assurance as in-person checks.


If a deepfake outwits your verification controls, it's not merely a fraud loss. It's a complete CDD failure that regulators could regard as a control weakness in your AML program.

How to detect deepfakes

There isn't a single detection method that catches every deepfake. Effective detection stacks several signals on top of each other. Here's what we've got and the limitations of each method.


Liveness detection: active vs passive checks

Liveness detection makes sure that a real, live human being is right there during video verification, rather than just a photo or recording or even a deepfake.


Active liveness actually prompts the user to do particular things: blink, smile, turn their head and checks whether the result matches up with what you'd expect from a genuine person.


Passive liveness looks at the video without needing any action from the user, taking into account skin texture, tiny movements and depth clues.


Some advanced deepfakes can now outsmart both approaches. Tools designed to detect active liveness using older attack methods won't necessarily spot the latest face-swap tools that can adapt to prompts dynamically.


Meanwhile, passive methods struggle against high-quality GAN output. This doesn't mean liveness detection is completely useless. It remains essential, but it can't be your sole deepfake control.


AI-based deepfake detection tools

Specialist deepfake detection systems will look at videos for those little inconsistencies, such as:

  • unusual blinking patterns

  • slight warping at the edges of the face

  • inconsistent lighting on skin compared to hair

  • pixel-level anomalies around the jawline or ears.


These tools work well against less sophisticated deepfakes and form a useful extra layer against the more advanced ones.


AI-Based Deepfake Detection tool

Identify and verify natural persons while managing all customer data through a single, centralised platform. Simplify compliance and meet regulatory requirements with azakaw's KYC software solutions.



Human review and behavioural signals

Fraud analysts, who have received specialised training, will remain among the most dependable resources for detecting deepfakes because human judgment picks up on contextual signals that no automated system can fully reproduce


Analysts will look for:

  • slight delays in facial responses

  • audio-visual synchronisation problems

  • unnatural eye movements

  • sessions that appear overly scripted instead of natural


Behavioural indicators, such as a session that is abnormally short, a device that doesn't align with the client's stated location or a verification attempt made at an unusual hour, increase the level of context.


Limitations of current detection technology

The main problem is essentially an "arms race". As deepfakes become more realistic, detection methods have to be updated.


Models developed using 2023 deepfake datasets might not perform so well when confronted with attack methods used in 2025. This implies that when evaluating vendors who provide identity verification services, ask them specific questions about how often their detection models are retrained and against which types of attacks they are trained.


Building a deepfake-resilient compliance programme

Detection technology is necessary but far from enough. Building genuine resilience against deepfake fraud demands updating processes, training personnel and critically examining the tools that we actually rely upon.


Updating your KYC and EDD procedures

  • Make explicit reference to the deepfake risk within your KYC and Enhanced Due Diligence (EDD) procedures for those clients identified as being at high risk.

  • Demand multi-factor verification during the onboarding procedure: document authenticity check, biometric liveness and then a secondary data cross-check like a credit report or a government database check

  • Implement even tighter controls for clients who are onboarded entirely remotely from locations that are considered high-risk or highly adopted jurisdictions.

  • Flag and send to a senior person any video-based KYC session where there's an issue with audio-visual synchronisation, facial movement or session activity that lies outside the usual parameters



Staff training and escalation protocols

Frontline KYC analysts and fraud examiners need specific training in deepfake warning signs. Standard fraud awareness training doesn't cover this.


The training should contain:

  • footage of deepfake attacks

  • clear guidelines on what to do if you suspect a deepfake session

  • a documented review procedure

  • etc


Vendor due diligence for identity verification providers

  • Ask your vendors how well their liveness detection performs against current real-time face-swapping tools rather than replay attacks

  • Get hold of some data showing how often their deepfake detection model is updated and also details of the different types of attacks used during the retraining process

  • Find out whether their platform combines AI-powered detection that's specific to deepfakes right next to the standard liveness checks

  • Check whether they're part of an industry information-sharing group such as the Global Anti-Scam Alliance or indeed relevant FinTech bodies, since sharing threat intelligence is absolutely vital here


Accuracy & Safety Over Speed

Drive business growth and operational efficiency with azakaw, an AI-powered fully customisable solution that improves onboarding times and reduces compliance costs.



The regulatory response to deepfake fraud

Regulators are starting to take official action. The response is still relatively new in most markets, but the direction of travel is crystal-clear.


FATF guidance on digital identity and verification

The FATF's guidance on digital identity clearly states that digital onboarding is perfectly acceptable, provided that the verification method offers a level of assurance equivalent to face-to-face verification.


This new benchmark effectively forces an acknowledgement of deepfake risks since a digital verification procedure that could be easily tricked by a widely available AI tool doesn't give you that degree of assurance.


FATF's guidelines specifically say that companies have to consider the likelihood of identity document forgery and presentation attacks when creating their eKYC controls.


Emerging regulation in MENA and Africa

In November 2024, the US Financial Crimes Enforcement Network (FinCEN) released formal Alert FIN-2024-Alert004 that explicitly mentioned the use of deepfakes and generative AI to evade KYC and bypass identity verification controls. This is the first formal regulatory alert from a major worldwide regulator specifically focusing on deepfake fraud in financial services.


The UAE's CBUAE has issued digital onboarding guidelines requiring liveness detection and biometric verification as explicit components of eKYC. Although CBUAE guidelines do not yet refer to deepfakes by name, its requirement for controls equivalent to in-person verification creates a clear obligation to address this threat.


SAMA's AML framework in Saudi Arabia and the FSCA's FICA requirements in South Africa function on the same principle.

Frequently asked questions


What is a deepfake and why does it matter for financial compliance?

A deepfake is AI-generated video or audio that realistically replicates a real person's appearance or voice. To compliance teams, deepfakes matter since they will defeat video KYC, bypass liveness detection, and allow scammers to start accounts under completely false identities; thus breaking down the base of Customer Due Diligence.


Can deepfakes bypass video KYC verification?

Yes, advanced face-swap deepfakes can bypass video KYC sessions, including some actual liveness checks.


How can banks detect deepfakes during customer onboarding?

Banks use a combination of active and passive liveness detection. These AI models identify GAN artefacts and facial inconsistencies, behavioural analysis of the verification session, and trained human review for escalated cases.



What is synthetic identity fraud and how does it relate to deepfakes?

Synthetic identity fraud combines a genuine piece of data with completely fabricated personal information to create a completely fictional client. Deepfakes can strengthen synthetic identity attacks by providing a convincing live video and biometric match that can pass liveness detection, allowing a completely fabricated identity to get past the verification phase entirely.


Are there regulations specifically addressing deepfake fraud?

FinCEN issued formal Alert FIN-2024-Alert004 back in November 2024 specifically mentioning deepfakes and generative AI being used to evade KYC controls.


CBUAE's digital onboarding guidelines require liveness and biometric verification, which implicitly address deepfake risk.


Virtually all regulators are still developing their own specific deepfake guidelines. Still, the current CDD standards already need controls quite robust enough to detect AI-assisted scams.


What is liveness detection and does it stop deepfakes?

Liveness detection verifies whether there is a real, live person involved in the video verification rather than a photo, recording or a deepfake.


How should compliance teams respond to suspected deepfake identity fraud?

Immediately end the verification session. Don't approve the account yet. Escalate to your fraud team based on your documented deepfake escalation protocol. Hold onto the session recording and metadata.


Think about filing a Suspicious Activity Report if the attempt indicates a coordinated fraud effort. Log those red flags you found and check if your detection controls actually caught the session correctly.


Is deepfake fraud increasing in the GCC and Middle East?

Yes. The Regula 2024 survey, which had UAE participants, found 49% of businesses were hit by video deepfake fraud in 2024, up from 29% in 2022.


Rapid digital onboarding adoption in the UAE and Saudi Arabia makes both markets prime targets. FinCEN's November 2024 alert highlighted deepfake attacks as a rapidly spreading global threat affecting international financial services worldwide.


Conclusion

Global deepfake fraud grew fourfold in 2024. In fintech, cases jumped by 533%. Entrust saw a deepfake identity attack happening every five minutes. Firms in the financial services sector hit by deepfake fraud averaged $603,000 in losses each time it happened.


The Hong Kong $25 million deepfake video call fraud showed that live video can be fabricated to a level that even trained professionals would be tricked by it.


The same tech targets video KYC and biometric onboarding sessions at highly-regulated institutions in the UAE, Saudi Arabia and South Africa markets, which have taken to digital onboarding fast and on a massive scale.


No single detection method will be enough. Layered controls (liveness detection, AI-based deepfake analysis, behavioural signals, human review and vendors' models constantly updated) are precisely what the risk needs. And procedures, training and escalation protocols all have to show that deepfake fraud is now a real, not just theoretical threat.


The End-to-End Compliance Tool

Streamline compliance from identity and business verification to corporate compliance and AML transaction monitoring, reducing costs and complexity so you can scale with confidence.



Deepfakes Video Summary



Related articles


 
 
bottom of page