one biometric check isn't enough anymore: banks move to continuous verification

One in five biometric fraud attempts now involves a deepfake, according to Entrust's 2026 Identity Fraud Report — and more than half of financial institutions admit they cannot fully confirm that a biometric scan was captured live rather than injected. For years, banks treated identity verification as a single gate: prove who you are once at onboarding or login, then trust the session that follows. That model is now the weakest link in the fraud chain, and 2026 is the year banks stopped pretending otherwise.
The one-time check was never built for this threat
Traditional know-your-customer (KYC) and liveness checks were designed to catch a person holding up someone else's ID or a printed photo — a single moment of friction at account opening. But injection attacks bypass that entirely: instead of presenting fake media to a camera, fraudsters feed manipulated video or audio directly into the verification pipeline. Entrust's report found injection attacks surged 40% year-over-year, and one institution alone logged 8,065 deepfake attempts in eight months, tied to $347 million in verified losses, according to Biometric Update. A check performed once, at the front door, has nothing to say about who is actually present ten minutes — or ten transactions — later.
Why point-in-time verification fails against deepfakes
Voice and face cloning have both crossed a threshold that undermines any strategy built around a single checkpoint:
- Injection attacks skip the camera entirely — manipulated video or audio is fed straight into the capture pipeline, so there's no physical presentation attack to catch.
- Voice cloning needs as little as 3 seconds of audio and has crossed what researchers call the "indistinguishable threshold" for human listeners.
- Deepfake selfies rose 58% in 2025, and national ID document forgeries now make up a growing share of onboarding fraud.
- A single "verified" moment tells you nothing about later risk — large transfers, new payees, and password resets all happen well after the original check expires in relevance.
The shift to continuous biometric verification
Banks are responding by moving verification from a one-time gate to an ongoing, risk-adjusted process. Continuous trust and layered assurance are becoming the new baseline: identity signals are checked repeatedly across a session rather than once at the start. Examples are already live — YEO Messaging and ReconIQ have brought continuous, on-device biometric checks to U.S. banks, Czechia's Air Bank added Innovatrics face verification to secure mobile-app pairing, and Mastercard, Identomat, and TrueDoc are pitching layered identity verification specifically to catch synthetic identities that pass a single check but unravel under repeated scrutiny.
What continuous verification looks like in practice
- Re-checking voice or face biometrics at moments of elevated risk — large transfers, new payee additions, password or device resets.
- Layering behavioral and device signals on top of biometric checks, rather than relying on any single factor.
- Matching a caller's voice to a face on file in real time, without needing a centralized database that itself becomes a target.
What banks and fraud teams should do now
Moving to continuous verification doesn't require ripping out existing KYC infrastructure. It requires layering ongoing checks on top of it:
- Map where verification happens only once — onboarding, call start, app login — and flag the highest-risk moments downstream that deserve re-verification.
- Deploy real-time deepfake and injection-attack detection across voice and video channels, not just at enrollment.
- Layer biometric signals with behavioral and device intelligence instead of trusting any single check in isolation.
- Treat liveness detection as a capability to continuously test and update, not a feature purchased once and left alone.
Corsound AI's Voice-to-Face AI and Deepfake Detect give banks a way to verify identity continuously — matching a caller's voice to a face without needing a pre-existing database, and flagging synthetic audio or video in real time, across the entire customer session rather than just at the door. See how continuous verification fits into your fraud stack at corsound.ai/banking-and-finance.
Photo: I'm Zion / Pexels
See Corsound AI Voice Intelligence In Action

