FinBox Research

Why verification can’t be a one-time check

When open-source AI makes flawless deepfakes free, treating identity verification as a one-time check can become a massive risk.

Why verification can’t be a one-time check

What happens when your systems work as designed, but you still lose ₹20 crore? 

A recent loan fraud at an NBFC wasn’t perpetuated by a sophisticated cyberattack or a leaked password. The borrower’s bank statements checked out and the person on the video KYC call matched the ID on file.  

Except none of it was real. 

Fraudsters had generated the bank statements specifically to pass the checks a lender would run against them, and the face on the call was a deepfake, polished enough to clear liveness detection and fool the person watching it live. The file met every criterion it was supposed to meet and got approved. And by the time anyone caught on, the NBFC was out ₹20 crore.  

The system did exactly what it was designed to do 

When talking about AI in lending, we usually ask: what happens if the underwriting model makes a bad call? This incident flips that question. The AI model didn't make a mistake; it made a defensible decision based on the information it received. The data itself was fabricated to be indistinguishable from the real thing. 

And pulling this off doesn’t require a hacking ring or a massive budget anymore. Fraudsters are generating these flawless fakes using free, open-source AI models. 

In some ways, this is harder to contain than a targeted cyberattack. When "good enough to fool a bank" becomes free, easy to use, and available to anyone, the problem scales in a way traditional fraud never could.  

 

Human review alone doesn't close this gap 

Many lenders assume that a live video KYC call is inherently safer than an automated check because a human is watching. While human judgment makes a huge difference, it isn't entirely foolproof. 

In a controlled study of 2,000 consumers who were specifically told to look for fakes, only 0.1% could reliably tell real content from AI-generated content. Other research on video backs this up too: good quality deepfakes fool viewers easily, with only 24.5% correctly identified as fake. 

That implies that today's deepfakes are advanced enough to bypass even a trained reviewer who is actively looking for signs of fraud.  

The regulatory and financial risks are rising 

RBI data shows a 46.4% jump in banking fraud cases between FY25 and FY26, with fraudulent transactions crossing ₹48,000 crore. Because the RBI treats video KYC as legally equivalent to in-person verification, it has become the default way to onboard customers, and perhaps, a massive target. 

On top of that, the fraud doesn't stop when a synthetic identity gets rejected at one lender. Because banks don't share this data in real time, the fraudster just moves to the next institution. These fake borrowers are designed specifically to look like statistically normal, low-risk customers, allowing them to breeze right past standard anomaly-detection systems.  

One-time verification was never going to be enough 

For years, lending infrastructure has treated identity verification as a gate: check the borrower once at onboarding, and if they pass, trust them for the rest of the journey. That made sense when forging a document took real effort. It doesn't work today. 

Lenders are already spending more on fraud prevention, but a KPMG-FICCI report argues that fraud has stopped being a series of isolated incidents and now runs as a technology-driven, always-on ecosystem, powered by stolen identities, AI, and real-time payment rails.  

Pouring more money into an outdated model doesn't fix its structural blind spots. Most digital sessions go completely unmonitored after the initial login. Modern fraud builds gradually, and this kind of slow, calculated behaviour rarely trips a one-time trigger.  

The conclusion is clear: organisations need to move from investigating fraud after it happens to building continuous forensic readiness into how they operate day to day.  

Verification can no longer be a one-time checkpoint and start treating it as something that runs throughout the journey. 

ING Bank built something similar to prove its KYC process could hold up. Rather than checking customers in isolation, the bank tracked behaviour as a network of relationships over time, using graph analytics paired with machine learning, so a change that looked unremarkable on its own would still stand out against the customer's own history and the people connected to them.  

PwC's Financial Crime Report found that firms moving to this kind of continuous, event-triggered monitoring can cut compliance maintenance costs by as much as 40%, while also improving risk detection. 

India's own credit stack already has a working example of this same logic. Instead of accepting an uploaded bank statement PDF that can be edited or fabricated, Account Aggregator integration lets a lender pull that data straight from the source bank through a licensed, verified pipe, so the number on the statement and the number at the source can never drift apart.  

That's continuous, source-anchored verification in action. The opportunity for lenders now is building that logic into everything downstream of onboarding: the document checked against the bank statement, the bank statement checked against the income claim, behaviour checked against what a borrower's prior sessions looked like, and any discrepancy between those signals flagged. 

This is also where AI agents actually prove their worth. Using AI to check a borrower's file at the start is just doing the old process faster. Instead, agentic AI models built for continuous verification do a completely different job: they continuously pull in fresh data, like bank updates, device activity, and repayment patterns, and cross-check them for as long as the loan exists.   

The NBFC that lost ₹20 crore had the standard setup most of the industry relies on, which makes everyone else just as vulnerable. Every lender running video KYC is one convincing fake away from the same outcome, and the only real defense is a system built to keep verifying long after the initial approval. 

Share
Still exploring this topic?
Get instant, cited answers from the FinBox lending knowledge base

Stay current

Get research like this in your inbox.

Join 5,000+ lending professionals who read FinBox's research on credit infrastructure, underwriting, and embedded finance.

Subscribe free
Srijan Nagar
Srijan Nagar

Co-founder