As voice cloning and deepfake video make impersonation cheap and convincing, verified trust — proving a human is who they claim to be — becomes a designed layer of the customer experience, not a background security control.
Verified trust is the deliberate design of identity checks — voice, video, biometric, or behavioural — into moments where fraud risk is highest: large payments, account changes, executive approvals, call-centre escalations. Unlike legacy security theatre (endless password resets, static security questions), it uses layered, low-friction signals that confirm identity without interrogating the customer.
The trigger is stark. In early 2024, a finance employee at engineering firm Arup, working in its Hong Kong office, was tricked into transferring HK$200 million (roughly US$25 million) after joining a video call with what appeared to be the company's CFO and colleagues — all deepfake reconstructions. That case moved deepfake fraud from theoretical to boardroom-urgent almost overnight.
The design challenge is behavioural as much as technical: verification steps that feel accusatory erode the very trust they're meant to protect.
Why we think it'll come up
The Arup precedent went public in early 2024
Arup's disclosure that a single video call — entirely fabricated using deepfake technology — cost its Hong Kong office HK$200 million (~US$25 million) turned an abstract cybersecurity warning into a concrete case study that finance, legal, and CX leaders now cite directly.
Voice cloning tools became consumer-accessible
Commercial voice-cloning software can now replicate a person's speech patterns from seconds of sample audio, lowering the barrier for impersonation scams targeting call centres, family members, and executive assistants.
Regulators started drafting deepfake-specific rules
Financial regulators and standards bodies in multiple markets began 2024–2025 consultations on synthetic-media fraud, signalling that verification obligations will soon be formalised rather than left to individual firms.
What it changes for customer experience
For customers
Extra verification steps at high-risk moments, ideally invisible during routine ones — the trade-off between protection and friction becomes tangible and personal.
For business
A single successful deepfake fraud can cost tens of millions and permanently damage partner and client trust in financial and operational processes.
For CX & operations
Verification design becomes a core experience discipline — fraud teams, CX teams, and technology teams must co-design checks that protect without alienating.
Industries on the front line
The Call That Wasn't Real
In early 2024, a finance employee at the engineering firm Arup joined what looked like an entirely ordinary video call. The CFO was there. Colleagues were there. Instructions were given, and the employee acted on them, transferring HK$200 million — roughly US$25 million — out of the company's Hong Kong office. None of the people on that call were real. Every face and voice had been synthetically reconstructed. The money was gone before anyone realised the meeting itself was the fraud.
That single incident did more to concentrate executive attention than years of abstract cybersecurity briefings. It demonstrated that deepfake fraud no longer requires a gullible target or a crude script. It requires only a convincing video call and a plausible instruction. For finance, legal, and CX leaders, Arup became shorthand: the case that proved impersonation had moved from novelty to operational threat.
Why Verification Is Now a Design Problem
Identity verification used to be background infrastructure — passwords, security questions, the occasional callback. It sat behind the experience, invisible unless something went wrong. Deepfake fraud breaks that model because the thing being faked is no longer a credential. It is a person. A voice. A face on a screen saying things that person would plausibly say.
That shifts verification from a technical control into a designed layer of the customer and employee experience. The challenge is not simply detecting fraud — it is deciding when and how to ask someone to prove they are who they claim to be, without making them feel accused. Verification steps that feel like interrogation erode the trust they exist to protect. A CFO who must repeatedly prove they are the CFO, even to their own staff, experiences the check as friction and suspicion rather than protection.
The problem deepfakes create is not that people are fooled. It is that everyone, including the genuine article, now has to prove they aren't fake.
The Tools Are Already in Consumers' Hands
Part of what makes the Arup case a signal rather than an outlier is accessibility. Commercial voice-cloning software can now replicate a person's speech patterns from a short sample of audio — seconds, not hours. That lowers the barrier for impersonation scams aimed at call centres, family members, and executive assistants alike. A scam that once required skill and planning now requires only a recording and off-the-shelf software.
This accessibility matters for CX design because it means the threat is not confined to boardroom-level fraud. The same techniques that fabricated a CFO on a video call can fabricate a customer's voice on a support line, or a family member's voice in a distress call. Any channel that relies on recognising a voice or a face as proof of identity is now exposed.
Regulation Is Catching Up, Slowly
Financial regulators and standards bodies in multiple markets began consultations in 2024 and 2025 on synthetic-media fraud. That signals a direction of travel: verification obligations that are currently left to individual firms' discretion will likely become formalised requirements. Organisations that treat layered verification as a voluntary enhancement today are likely to find it mandated tomorrow, on someone else's timetable rather than their own.
For businesses, the calculus is already stark without waiting for regulation. A single successful deepfake fraud can cost tens of millions and cause lasting damage to how partners and clients trust operational and financial processes. The Arup loss was not just a line-item cost — it was a demonstration, to everyone watching, that the company's verification processes had a gap large enough to drive a fabricated CFO through.
Designing Protection Without Friction
The practical answer is layered, low-friction verification concentrated at genuinely high-risk moments: large payments, account changes, executive approvals, escalations at the call centre. Behavioural biometrics, callback protocols through independently verified channels, and multi-channel confirmation can each add a layer of assurance without turning every interaction into a checkpoint.
The organisations most likely to get this right will not deploy verification everywhere at once. They will pilot layered checks at the touchpoints where fraud is most consequential, learn how customers and employees experience those checks, and expand only once the friction has been designed out rather than bolted on. Verification, done well, should feel like a company that takes your protection seriously — not one that doubts you by default.
Watch closely and pilot layered verification (behavioural biometrics, callback protocols, multi-channel confirmation) at high-value, high-risk touchpoints before mandating it everywhere.
Trends Radar
Other trends
Build for what's next
Turn this trend into a measurable experience advantage.
