Introduction
Digital onboarding is becoming a difficult balancing act for financial institutions and other businesses that need to verify customers remotely. Consumers increasingly expect account opening and identity checks to take minutes, while fraud controls are becoming more sophisticated as criminals adopt artificial intelligence to create synthetic identities and manipulate verification processes.
Research cited by identity-verification provider Shufti found that 47% of users abandon digital onboarding when verification becomes too lengthy or cumbersome. Shahid Hanif, Shufti’s chief executive and co-founder, describes the problem as a “friction paradox”: companies must strengthen identity controls without creating enough obstacles to drive legitimate customers elsewhere.
The challenge is becoming more complex because modern identity fraud is moving beyond forged documents. AI-generated identities, deepfake documents, synthetic video and digital stream injection are testing verification systems that were originally designed around static documents and optical character recognition.
Why Digital Onboarding Creates Friction
Digital onboarding typically requires customers to provide information and evidence that allows a business to establish who they are.
Traditional systems may require users to photograph identity documents, submit supporting records and complete a facial or liveness check. While these measures can strengthen controls, poorly designed processes can create significant abandonment.
Hanif says some legitimate customers are still required to locate physical documents such as utility bills, while rigid verification systems can reject applications because of minor differences or typographical errors.
That creates a commercial problem alongside a compliance problem. Customers who cannot complete verification quickly may abandon an application rather than continue through additional checks.
The Cost of Excessive Verification
For financial institutions, payment companies and other digital businesses, onboarding is often the first major interaction with a prospective customer.
A lengthy process can therefore affect both conversion and fraud prevention. Removing controls entirely, however, creates a different risk: criminals may find it easier to establish accounts using fraudulent or synthetic identities.
The challenge is consequently not simply to make verification faster. It is to determine which checks provide meaningful assurance and how those checks can be completed with minimal unnecessary effort.
How AI Is Changing Identity Fraud
According to projections from Shufti cited in the source material, AI-powered identity fraud is expected to increase by 495% by the end of 2026, while document deepfakes are projected to rise by 3,900%.
These figures are company projections rather than independently established measurements, but they illustrate the scale of the threat Shufti says it is observing.
Hanif argues that fraud is becoming industrialised, with criminals using increasingly sophisticated methods to construct identities and manipulate verification evidence.
Beyond Traditional Document Forgery
Conventional document verification was largely designed to determine whether information on an identity document was readable and whether the document appeared authentic.
AI-assisted fraud can attack several parts of that process.
Techniques cited by Hanif include:
- Document deepfakes
- Synthetic identities
- Field manipulation
- Copy-move image edits
- Simulated security features such as holograms
- Adversarially generated identities
- Digital stream injection
- Screen-sharing and liveness bypass techniques
The underlying problem is that a document can contain apparently consistent information while the person presenting it, or the digital evidence surrounding it, is fraudulent.
Why Deepfakes Challenge Document-First Verification
A document-first verification model places considerable emphasis on the physical or digital representation of an identity document.
That approach can become less effective when attackers can manipulate the image while preserving the characteristics that automated systems are trained to recognise.
Hanif argues that AI-generated identities are exposing a structural weakness in older verification models: a system may confirm that text is readable and that a document’s layout appears correct without establishing that the identity behind the application is genuine.
This distinction is particularly important for financial institutions. A fraudulent identity that passes onboarding can remain inside a customer database long after the original verification event.
The Problem of “Sleeper Fraud”
Hanif refers to this phenomenon as sleeper fraud.
Under this model, a synthetic identity can pass a weak or point-in-time verification process and remain dormant before later being used for fraudulent activity.
That creates a delayed risk for organisations because the original onboarding decision may appear legitimate when reviewed in isolation.
The implication is that identity verification cannot necessarily be treated as a one-time event. Organisations increasingly need controls capable of detecting suspicious activity after an account has been established.
Digital Stream Injection and Liveness Detection
Another emerging concern is the manipulation of video-based verification.
According to Hanif, digital stream injection and screen-sharing techniques can allow criminals to bypass a physical camera by inserting pre-recorded or synthetic video into the verification process.
This changes the security question.
Instead of simply asking whether a face appears on screen, verification systems need to establish whether a genuine person is physically present and whether the captured biometric evidence has been manipulated.
Moving Toward Forensic Presence
Shufti says it is addressing this problem through techniques designed to identify signals that are difficult for synthetic imagery to reproduce.
Hanif points to approaches including 3D mesh reconstruction and skin-texture analysis as methods for distinguishing genuine human presence from AI-generated imagery.
He describes this broader approach as “forensic presence,” with passive liveness detection and 3D biometric analysis forming part of the verification process.
Shufti also points to a claimed zero-failure result in the U.S. Department of Homeland Security’s RIVR 2025 benchmark. That is a company-reported performance claim and should be assessed against the benchmark’s methodology, testing conditions and scope before being treated as evidence of universal performance.
The European Shift Toward Digital Identity
Europe’s developing digital identity infrastructure could change how identity verification is performed.
The eIDAS 2.0 framework and planned European Digital Identity Wallet (EUDI Wallet) are part of a broader move toward digital credentials and verifiable attributes rather than repeated submission of physical identity documents.
The model could allow verified information such as a person’s legal name, age or address to be provided through trusted digital identity infrastructure.
Examples cited by Hanif include systems such as BankID, MitID and DIIA.
From Document Images to Verified Credentials
The fundamental difference is between proving identity through an image and proving specific attributes through a trusted digital credential.
A document-based process may require a customer to photograph an identity document and have a system determine whether the document appears authentic.
A credential-based system can instead rely on cryptographic mechanisms and trusted issuers to establish that particular attributes have been verified.
Hanif says this approach could reduce user abandonment by up to 30%, according to Shufti’s estimate.
The potential benefit is therefore twofold: less manual effort for legitimate users and stronger assurance than can be achieved by simply inspecting document images.
What Financial Institutions Need to Reconsider
The rise of AI-generated fraud changes the economics and design of identity verification.
Organisations that focus exclusively on onboarding conversion may leave gaps that criminals can exploit. Organisations that respond by adding more manual checks to every application may create unnecessary friction for legitimate customers.
A more targeted approach is to examine where existing systems are most vulnerable.
Audit Existing Customer Portfolios
Hanif recommends reviewing existing customer portfolios for synthetic identities that may have passed through legacy OCR-based systems between 2020 and 2023.
The rationale is that an organisation’s fraud exposure may extend beyond new applications. Previously approved accounts can also contain identities that were not adequately validated under today’s threat environment.
Portfolio reviews can therefore form part of a broader identity-risk assessment rather than focusing exclusively on new customers.
Strengthen Liveness and Biometric Controls
Another priority is moving beyond static image analysis.
Passive liveness detection and biometric technologies can provide additional evidence that a real person is participating in the verification process.
These technologies do not eliminate fraud risk, but they can address attack methods that target document-only verification.
Reduce Friction for Legitimate Customers
Security improvements do not necessarily require more manual work from every customer.
Government-backed digital identity wallets and rapid biometric re-authentication could allow organisations to rely more heavily on previously verified credentials and attributes.
This could reduce repeated document submissions while maintaining a higher level of identity assurance.
Costs and Business Implications
The consequences of onboarding friction extend beyond the identity-verification department.
When customers abandon applications, companies can lose potential revenue. When verification is too weak, the resulting fraud can create financial losses, regulatory exposure, operational costs and reputational damage.
The challenge is therefore an optimisation problem between several competing objectives:
| Objective | Potential problem if overemphasised |
|---|---|
| Faster onboarding | Greater exposure to fraudulent identities |
| Stronger verification | Higher customer abandonment |
| Manual review | Higher operating costs and slower processing |
| Automated verification | Greater dependence on technology quality |
| Document checks | Vulnerability to sophisticated manipulation |
| Biometric verification | New technical, privacy and implementation considerations |
The most effective model will depend on the organisation’s risk profile, customer base, regulatory obligations and available identity infrastructure.
Risks and Limitations of AI-Based Verification
AI can improve identity verification, but it also introduces new technical and governance challenges.
Fraudsters and verification providers are engaged in an ongoing technological race. As detection systems become more sophisticated, attackers can develop new techniques designed to bypass them.
Biometric systems can also raise questions around privacy, data governance, false rejection and false acceptance. The effectiveness of any particular system depends on how it is designed, tested and deployed.
Digital identity infrastructure introduces another dependency: organisations must be able to trust the issuer, credential and underlying verification framework.
For these reasons, no single technology should be treated as a universal solution to identity fraud.
The Future of Digital Onboarding
The direction of travel is increasingly toward risk-based, multi-layered identity verification rather than reliance on a single document check.
Static identity documents are likely to remain part of many onboarding systems, particularly where digital credentials are unavailable. But they are increasingly being supplemented by biometric signals, liveness detection, behavioural indicators, device intelligence and trusted digital credentials.
The expansion of digital identity wallets could accelerate this transition by allowing users to present verified attributes without repeatedly submitting physical documents.
For businesses, the strategic question will be how to combine these technologies without creating unnecessary complexity for legitimate customers.
Conclusion
AI-driven fraud is changing the assumptions behind digital identity verification. The challenge is no longer simply determining whether an identity document looks genuine. Organisations increasingly need to establish whether the identity itself is genuine, whether a real person is present and whether the information can be trusted beyond the initial onboarding event.
The 47% digital onboarding abandonment rate cited by Shufti highlights the cost of excessive friction, while the company’s projections for AI-powered identity fraud and document deepfakes illustrate why businesses cannot simply remove verification controls to improve conversion.
The emerging model is likely to combine stronger biometric and liveness controls with trusted digital credentials and government-backed identity infrastructure. The objective is not to choose between security and convenience, but to design verification systems capable of delivering both without assuming that any single technology can eliminate fraud.

