Deepfake Fraud: What Internal Auditors Should Test

A finance professional joins a video meeting. Several colleagues appear on screen, the voices sound right, and an urgent transfer is requested. The cues that normally make a business interaction feel authentic are all present. The problem is that the people on screen are not who they appear to be.
Hong Kong Police has documented major fraud cases involving deepfake technology and prerecorded video conferences. In official information covering 2024, the force reported two such cases with losses of approximately HK$240 million and HK$4 million. The lesson is larger than the technology itself: when an organization treats a familiar face, voice, or video presence as sufficient evidence of identity, synthetic media can turn an ordinary control weakness into an extraordinary loss.
Internal Audit does not need to begin by learning forensic deepfake detection. It should begin by asking whether critical processes remain secure when a convincing voice, face, or message can no longer be trusted as proof of identity.
Deepfakes change impersonation, not the control objective
Deepfakes are synthetic media that can fabricate or imitate video, images, and audio. In corporate fraud they can strengthen tactics that already exist: social engineering, business email compromise, fraudulent bank-account changes, urgent payment requests, and impersonation of executives or suppliers.
FinCEN warned in 2024 that financial institutions were reporting increased suspicious activity involving deepfake media and generative AI. The FBI has likewise described criminals using AI-generated audio to impersonate trusted people and synthetic video to appear as company executives or other authority figures in real-time communications.
The control implication is straightforward: a communication channel should not be treated as an authentication mechanism. A video call proves that an audiovisual signal exists. It does not, by itself, prove who controls that signal.
That changes the audit question. Instead of asking only, “Did the employee recognize the executive?”, auditors should ask, “What independent evidence had to exist before the requested action could be authorized?”
Four areas Internal Audit should test
The risk becomes much easier to audit once it is translated into verifiable controls. For a generalist internal auditor, four areas capture much of the practical exposure.
| Area | Control objective | What Internal Audit should test |
|---|---|---|
| Identity | Confirm that the person requesting a sensitive action is actually who they claim to be. | Whether high-risk requests require verification outside the originating channel using trusted contact information or corporate authentication mechanisms. |
| Payment and beneficiary | Prevent a compromised identity from redirecting funds on its own. | Segregation of duties, dual approval, limits, validation of bank-account changes, and controls over beneficiary creation or modification. |
| Exceptions and escalation | Prevent urgency, secrecy, or hierarchy from disabling the normal process. | What happens when someone asks staff to bypass controls, change the normal channel, accelerate a transfer, or keep an instruction outside the standard workflow. |
| Readiness and response | Ensure employees recognize the scenario and know how to act. | Training, simulations, reporting channels, containment procedures, incident records, and lessons learned. |
These layers matter together. An independent callback is weak if the phone number came from the same fraudulent message. Dual approval is weak if both approvers are being manipulated in the same synthetic meeting. Annual awareness training is weak if the culture penalizes an employee for questioning an urgent instruction from a senior executive.
The strongest control does not try to decide whether a face or voice is “real.” It prevents that judgment from being enough to move money, change master data, or release sensitive information.
Test identity where seeing is no longer verifying
The most important procedure is to determine whether sensitive actions require out-of-band verification. FBI guidance recommends independently verifying the identity behind suspicious communications rather than relying on the communication itself. In a corporate setting, that may mean calling a number already stored in a trusted directory, obtaining approval inside an enterprise system, confirming in person, or using strong authentication.
Internal Audit can sample high-value payments, bank-account changes, vendor onboarding, and exceptional requests. For each item, reconstruct the approval path and ask:
- Was the requester’s identity confirmed through a channel independent from the original request?
- Did the contact information come from trusted master data rather than the incoming email, message, or call?
- Did beneficiary changes trigger additional verification before the first payment?
- Was approval captured in a system with adequate traceability?
- Could the requester’s seniority reduce or remove any of these steps?
That fifth question often reveals the real weakness. Many frauds do not defeat a technical control. They exploit a cultural exception: “It is the CFO,” “this is confidential,” or “we need it immediately.”
Payment testing should focus on where a convincing story can change the process
Deepfakes make the story more persuasive, but money still moves through familiar systems and workflows. An audit should therefore trace the transaction from request to execution and identify where urgency or apparent authority can override a rule.
A practical work program can test:
- recent changes to supplier or employee bank accounts;
- high-value payments shortly after a beneficiary change;
- transactions approved outside the normal system;
- limit overrides or manual bypasses;
- urgent or confidential payments requested by senior executives;
- concentration of beneficiary creation, modification, and approval;
- evidence of callbacks and who initiated the verification;
- alerts, exceptions, and transactions stopped or reversed after fraud concerns.
The objective is not to design a standalone “deepfake control.” It is to determine whether the financial process can withstand a highly convincing false identity.
This logic is consistent with the COSO/ACFE Fraud Risk Management Guide: Second Edition, which frames fraud risk management as an ongoing program of governance, fraud risk assessment, preventive and detective controls, investigation, and monitoring. Deepfakes should update fraud scenarios and control responses rather than create a separate discipline disconnected from the internal control system.
Escalation and culture are controls, not soft topics
An employee may sense that something is wrong and still execute the request if the organization rewards compliance with authority more than constructive challenge. Internal Audit should therefore test not only whether an escalation procedure exists, but whether people can use it under pressure.
A simple procedure is to review recent incidents and simulations. What did employees do when they received an unusual request? Did they know whom to call? Could a payment be paused? Did Finance receive support when it challenged a senior requester? Were exceptions documented?
Simulations can include voice calls, video meetings, urgent messages, and supplier changes. They do not require sophisticated synthetic media. The control logic can be tested by reproducing the attack pattern: apparent authority, urgency, secrecy, deviation from normal process, and pressure to act.
Organizations should also learn from failed attempts. Fraud logs, bank alerts, attempted master-data changes, and employee reports can expose patterns before they result in a material loss.
Internal Audit assesses the fraud risk; it does not authenticate every video
The Global Internal Audit Standards make fraud a clear part of engagement work. Standard 13.2 requires internal auditors, when assessing engagement risks, to consider risks specifically related to fraud. Standard 4.2 also connects due professional care with considering the probability of fraud and other significant risks.
That does not turn Internal Audit into a synthetic-media forensics laboratory. The function can already assess the design and operating effectiveness of identity verification, payment controls, master data, segregation of duties, exceptions, escalation, awareness, and incident response. When a conclusion depends on technically determining whether media was manipulated, analyzing metadata, attributing an attack, or validating biometric technology, digital-forensics, cybersecurity, or identity specialists may be needed.
The professional boundary matters. An auditor does not need to prove how a deepfake was created to conclude that a material payment process allows an unverified identity to authorize a transfer.
Deepfake capability will continue to improve. Sustainable defense will not come from expecting employees to identify every synthetic artifact. It will come from designing processes in which even a highly convincing fake cannot replace independent controls. For Internal Audit, that turns an intimidating technology risk into familiar assurance questions about authority, evidence, segregation, exceptions, and behavior.
Sources
- The Institute of Internal Auditors, Global Internal Audit Standards
- Hong Kong Police Force, official information on deepfake fraud cases
- FinCEN, Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions
- FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud
- COSO, Fraud Risk Management Guide: Second Edition