Business guide

Deepfake detection in KYC: where image forensics actually fits

A non-hype mapping of face-image manipulation and synthetic-media detection to NIST, FATF and FinCEN language — including everything TrueFace explicitly does not do.

1. What KYC actually is

KYC (Know Your Customer) is not "send me your passport". The FATF Customer Due Diligence framework describes a set of activities: identify the customer; verify their identity using reliable, independent source documents, data or information; identify and reasonably verify beneficial owners where applicable; understand the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny. Identification is what the customer tells you. Verification is independent evidence supporting it.

Around those activities sit related but distinct processes: document verification, face matching, liveness / presentation-attack detection, PEP screening, sanctions screening, source of funds versus source of wealth, enhanced due diligence and ongoing monitoring. Image forensics is none of these.

2. Where image forensics sits in the pipeline

A simplified remote onboarding flow runs: identity information collected → identity evidence submitted → document authenticity → face-image integrity → face-to-document comparison → liveness / PAD → identity verification → beneficial ownership → PEP and sanctions screening → risk assessment → decision.

Face-image integrity and synthetic-media detection is the single box TrueFace occupies. It is not a replacement for the boxes around it.

3. This step is standards-backed

NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment (July 2025), states that organisations conducting remote identity proofing SHALL analyze all digital media submitted during identity proofing for artifacts and indicators of potential modification, manipulation, tampering, or forgery, and that they SHOULD analyse digital media for signatures of generative-AI algorithms and deepfake tools known to create forged media. NIST also expects automated image-analysis algorithms to be tested against manipulated and genuine media, with false-positive and false-negative rates established and documented, and automated analysis augmented by manual review.

FATF's digital-identity guidance is technology-neutral and permits digital identity evidence where the information used is reliable and independent, discussing assurance levels rather than endorsing any product category. FinCEN guidance recognises documentary and non-documentary verification methods, provided the institution can form a reasonable belief that it knows the customer's true identity. Neither body says a manipulation detector satisfies CDD.

4. What TrueFace does — and does not — do

TrueFace analyses a submitted face image and scores how likely it was digitally altered, filtered or synthetically generated, per face, returning the underlying forensic signals. When a face shows signs of alteration, it may attempt a reconstruction and shows an approximation of the likely true appearance only when reconstruction confidence is adequate; otherwise it returns the detection report alone.

TrueFace does not:

  • confirm who a person is, or perform identity verification or identity proofing;
  • match a face against a document, database or reference image;
  • read, parse or authenticate identity documents;
  • perform liveness or presentation-attack detection (NIST/ISO/IEC 30107-3:2023 PAD requires control of the biometric capture session, which TrueFace does not have);
  • screen against sanctions, PEP or adverse-media sources;
  • establish beneficial ownership, source of funds or source of wealth;
  • constitute a KYC, AML or CDD programme, or a compliance decision of any kind.

A "no manipulation detected" result does not establish that a document is genuine, that it belongs to the applicant, that the photo was not stolen, that the person is physically present, or that an attack outside TrueFace's detection scope was not used.

5. Interpreting results inside a KYC engine

TrueFace resultAppropriate interpretation
No manipulation detectedNo detected image-integrity anomaly (not proof of authenticity)
Manipulation detectedPotentially unreliable identity photograph
AI-generated likelihood highPotential synthetic identity / synthetic person indicator
UncertainInsufficient evidence → route to additional verification
Detection unavailableDo not infer authenticity; escalate to manual review

The defensible workflow is: manipulation or synthetic likelihood high → do not auto-reject → request an original or live capture, run document verification and biometric comparison, or route to manual review / enhanced due diligence. The institution's KYC engine makes the decision; TrueFace contributes one signal to it.

6. Vendor due-diligence checklist

If you are evaluating any media-integrity detector, ask for evidence rather than an accuracy headline: dataset composition (genuine, retouched, face-swapped, morphed, fully generated); generator coverage; performance against generators unseen in training; false-positive and false-negative rates at documented thresholds; demographic breakdown; degradation behaviour after JPEG compression, resizing, screenshotting and social-media processing; adversarial testing; and how performance is re-established as new generative models appear. This mirrors what NIST SP 800-63A-4 expects to be documented and disclosed to relying parties.

7. Related attack surface: face morphing

NIST published NISTIR 8584, Considerations for Implementing Morph Detection, covering images blended from two identities to defeat document issuance and face comparison. NIST's media-forensics work also treats deepfake detection and image manipulation detection as distinct forensic tasks. Any claim about morph detection should be backed by evaluation against morph datasets specifically.

Sources

  • NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment (2025)
  • NIST SP 800-63B / ISO/IEC 30107-3:2023 — presentation attack detection
  • NISTIR 8584 — Considerations for Implementing Morph Detection
  • FATF Recommendations and Guidance on Digital Identity — Customer Due Diligence
  • FinCEN Customer Identification Program guidance and CDD requirements
  • UK FCA Handbook / FCG — customer due diligence and enhanced due diligence

This guide summarises published standards and regulatory guidance for orientation only. It is not legal or compliance advice, and TrueFace makes no certification or compliance claim.