In early 2024, an employee at global engineering firm Arup joined what appeared to be an ordinary video conference with the company’s Chief Financial Officer and several colleagues. During the meeting, the CFO instructed the employee to authorize a series of confidential wire transfers.
The employee complied.
Only later did they discover that every participant on the call, including the CFO, had been generated using artificial intelligence. According to the Financial Times, 15 transfers totaling approximately $25 million had been sent to fraudsters. Arup later confirmed that none of its internal systems had been compromised. The employee trusted what they saw and heard on the call, and that trust is what the fraudsters exploited.
Stories like this are becoming much more common as generative AI becomes more sophisticated. Deepfakes (AI-generated synthetic audio, video, and images) are becoming a new tool for corporate fraud. PwC research found that deepfake operations have increased by 1,100% in the last two years. While much of the conversation has focused on the technology itself, ethics and compliance leaders face a more important question: What happens when your compliance program can no longer assume that seeing is believing?
Deepfakes challenge the assumptions that modern compliance programs, fraud controls, internal investigations, and third-party due diligence processes were built on.
What Is a Deepfake and Why Does It Matter?
A deepfake is AI-generated content that convincingly imitates a person’s appearance, voice, or mannerisms. While deepfake AI has attracted attention for political misinformation and celebrity impersonations, its implications for organizations are becoming far more practical and costly.
According to Deloitte, generative AI is expected to increase financial fraud, with projected fraud losses in the United States growing from $12.3 billion in 2023 to $40 billion by 2027 as AI lowers the cost and complexity of sophisticated scams.
For compliance leaders, the concern extends beyond fraud losses. Deepfakes change how organizations establish identity, authorization, and evidence.
Three Assumptions Deepfakes Break
Seeing or hearing someone is proof of identity. Many organizational controls still rely on an informal but powerful assumption: if the request comes from your CEO’s voice, your CFO’s face, or a familiar colleague during a video meeting, it is authentic. The Arup incident demonstrated that this assumption no longer holds. Organizations should keep using video meetings and phone calls. They just can’t treat them as sufficient proof of identity anymore. High-risk approvals (particularly those involving payments, sensitive information, or policy exceptions) should require independent verification through established channels rather than relying solely on the communication that initiated the request.
Documentation can no longer be assumed authentic. Ethics and compliance departments know that third-party due diligence has traditionally focused on collecting documentation (e.g., corporate registrations, identity documents, ownership records, financial statements, supporting certifications). Historically, the question has often been, “Did we receive the required documentation?” Deepfake AI and generative AI require organizations to ask a different question: “How do we know these documents or even the individuals providing them are authentic?”
Recent guidance from PwC highlights that generative AI can now produce highly convincing identity documents, invoices, financial records, and supporting materials that appear internally consistent. Rather than forging a single document, bad actors can fabricate an entire due diligence package that looks legitimate on its face. Due diligence teams should keep collecting documentation, but weigh it as one input rather than the final word, and lean more heavily on independently verified information.
Internal investigations can no longer treat audio and video as definitive evidence. Deepfakes may have their biggest long-term impact on internal investigations. For decades, investigators have reviewed audio recordings, video footage, and photographs as strong forms of corroborating evidence. That assumption no longer holds.
Investigators must now ask: “Where did this recording originate? Who controlled it before we received it? What independent evidence supports its authenticity?”
This is a subtle but significant shift in investigative methodology. Rather than treating digital media as definitive evidence, investigators should increasingly evaluate: the provenance of digital files, chain of custody, metadata, corroborating communications, access logs, payment approvals, witness interviews, and other independent records. Video and audio become supporting evidence, weighed alongside everything else investigators gather.
Deepfakes create a second investigative challenge as well. Once employees know convincing AI-generated media exists, individuals accused of misconduct may attempt to dismiss authentic recordings as fabricated. Researchers often refer to this phenomenon as the “liar’s dividend,” coined by Robert Chesney as the ability to undermine genuine evidence simply by claiming it is AI-generated. Both risks point to the same conclusion: investigation procedures should evolve before these cases become even more frequent.
Technology Alone Is Not the Answer
The natural response to deepfakes is to look for a technological solution. Detection tools will likely become an important component of many organizations’ control environments, but they should not become the new single point of trust.
As generative AI continues to improve, deepfake detection becomes increasingly difficult. Organizations cannot rely solely on software to determine whether audio, video, or documentation is authentic. Instead, compliance leaders should view deepfakes as a governance challenge rather than simply a cybersecurity problem. The goal is to design compliance processes that remain effective even when synthetic media is convincing, not to catch every fake image or voice recording.
A Compliance Program Review Checklist
Deepfakes call for a fresh look at the assumptions behind your existing controls, not an entirely new compliance program. Consider reviewing your program against the following questions:
- Identify where voice, video, or images function as controls. Map the business processes that rely on recognizing someone’s voice, face, or communication style to verify identity or authorize action. This may include payment approvals, executive communications, employee onboarding, vendor verification, access recovery, or hotline interviews.
- Require independent verification for high-risk requests. Review whether material requests such as wire transfers, changes to banking information, or policy exceptions require confirmation through an independent, trusted channel rather than relying solely on the communication that initiated the request.
- Reevaluate urgency and exception procedures. Many deepfake-enabled fraud schemes rely on authority, secrecy, and urgency. Examine whether existing controls can be bypassed simply because a request appears to come from a senior leader or is labeled confidential or time-sensitive.
- Update internal investigation procedures. Consider whether your investigation methodology adequately addresses synthetic media. Audio, video, photographs, and screenshots should be evaluated alongside provenance, chain of custody, metadata, system logs, and other corroborating evidence, not treated as definitive proof on their own.
- Strengthen third-party verification. Assess whether due diligence relies primarily on documents supplied by the third party or whether key information such as ownership, registration, banking details, and principal identities are independently verified through trusted external sources.
- Train employees on verification, not detection. Employees should not be expected to determine whether a video or voice recording is AI-generated. Focus employee training on when to seek additional verification, how to confirm unusual requests through established processes, and why following those procedures protects both the employee and the organization.
- Test your controls. Finally, incorporate deepfake scenarios into tabletop exercises and fraud response testing. Simulate executive impersonation, synthetic vendor communications, or fraudulent payment requests to determine whether employees follow verification procedures under realistic conditions.
A Final Thought
Deepfakes may change the way people commit fraud, but they don’t have to change the effectiveness of your compliance program. Organizations that review and strengthen their controls now, before their own Arup moment, will be in a stronger position later. Make sure your compliance program aligns with a world where we can no longer accept digital content at face value.