AML & Financial Crime

AI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification

Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.

By Jonas Adam Mohamed Osman AbdelghafourPublished 27 August 2026Last reviewed 27 August 2026

A foundational assumption is weakening

Remote onboarding depends on the proposition that identity documents, biometric checks and human interaction can provide reliable evidence of identity. AI-generated documents, synthetic faces and voice cloning weaken that assumption.

The synthetic identity problem

Synthetic identity is especially challenging because it may combine genuine and fabricated information. The result can survive basic validation while still representing a fictitious or manipulated person. Customer verification therefore needs multiple independent sources rather than reliance on one apparently strong signal.

Layered verification

Controls can combine document authentication, liveness detection, device intelligence, behavioural information, database checks, source-of-funds plausibility and post-onboarding transaction behaviour. No individual control should be treated as infallible.

Model risk

Fraud detection and biometric systems themselves require governance. False positives can exclude legitimate customers; false negatives can admit sophisticated synthetic identities. Firms should monitor performance by segment and investigate material drift.

Escalation

Where evidence conflicts, the process should allow investigators to pause onboarding and seek additional information. Operational pressure to maximise conversion should not override unresolved identity concerns.

Conclusion

AI does not make digital onboarding impossible. It makes evidence triangulation more important. The future of KYC is likely to depend less on a single document or biometric check and more on the consistency of multiple independent indicators.

Related reading

See AML & Financial Crime, Model Risk and Regulatory Compliance.

About the author

Jonas Adam Mohamed Osman Abdelghafour is a risk and compliance expert advising banks, insurers, payment institutions and asset managers on governance, financial crime, AI oversight and enterprise risk across UK and EU regimes. See qualifications and services, or get in touch to discuss an engagement.

*This article discusses regulatory frameworks in general terms and is not legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.*

Sources

The International Compliance Association is cited here as an editorial source for current compliance issues. No affiliation with, or endorsement by, the ICA is claimed or implied.

Frequently asked questions

What should risk leaders know about a foundational assumption is weakening?

Remote onboarding depends on the proposition that identity documents, biometric checks and human interaction can provide reliable evidence of identity. AI-generated documents, synthetic faces and voice cloning weaken that assumption.

What should risk leaders know about the synthetic identity problem?

Synthetic identity is especially challenging because it may combine genuine and fabricated information. The result can survive basic validation while still representing a fictitious or manipulated person. Customer verification therefore needs multiple independent sources rather than reliance on one apparently strong signal.

What should risk leaders know about layered verification?

Controls can combine document authentication, liveness detection, device intelligence, behavioural information, database checks, source-of-funds plausibility and post-onboarding transaction behaviour. No individual control should be treated as infallible.

What should risk leaders know about model risk?

Fraud detection and biometric systems themselves require governance. False positives can exclude legitimate customers; false negatives can admit sophisticated synthetic identities. Firms should monitor performance by segment and investigate material drift.

What should risk leaders know about escalation?

Where evidence conflicts, the process should allow investigators to pause onboarding and seek additional information. Operational pressure to maximise conversion should not override unresolved identity concerns.