---
title: "Deepfake and Voice-Clone Verification Protocol for Finance Teams (Free Template)"
description: "Free deepfake and voice-clone verification protocol for finance: safe words vs callbacks vs verifying the person, triggers, steps, escalation and an evidence log. Download as Markdown or text."
url: https://realpayee.com/templates/deepfake-verification-protocol
canonical: https://realpayee.com/templates/deepfake-verification-protocol
date_published: 2026-10-06
date_modified: 2026-10-06
updated: 2026-10-06
author: "RealPayee"
site: RealPayee
---

# Deepfake and voice-clone verification protocol for finance teams (template)

> A deepfake verification protocol stops finance from paying because a voice or face seemed familiar. The rule: **no voice-only or video-only authorization.** Pause, optionally ask a pre-agreed challenge question, **hang up and call back on a known channel**, have the requester state the details, get **identity-bound approval** above a threshold and a **second approver**, and log the evidence. Safe words help; they never replace the callback.

_Updated 2026-10-06 · 8 min read_

## Key takeaways

- Treat any money or bank-detail request by phone, video, voice note or chat as a **trigger**, whoever it appears to come from.
- **Safe words** prove a shared secret; **callbacks** prove a known number answered; **identity-bound approval** proves the enrolled person approved this exact request. Layer them.
- A video call is not proof: in the Arup case, colleagues on the call were deepfake re-creations.
- Free and ungated: copy it or **download it as .md or .txt**.

## Safe words vs callbacks vs verifying the person

A cloned voice or a deepfake video defeats any control that relies on recognizing someone. Each method below proves something different, so the protocol layers them rather than picking one.

| Method | What it proves | Where it fails | Use it for |
| --- | --- | --- | --- |
| **Safe word or challenge question** | The caller knows a secret agreed in advance, or a fact a clone would not know | Secrets leak if stored in email or chat; people forget them under pressure; a real executive may not remember either | A fast check during a live call before anything else happens |
| **Callback to a known number** | Someone answers the number you already had for that person | The number on file was changed, the call is forwarded, or an inbound call is treated as a callback | Every payment or bank-detail request that arrives by phone, video, voicemail or message |
| **Video call** | Very little on its own: the Arup case involved a video call where colleagues were deepfake re-creations | Synthetic video and voices in real time | Never as authorization |
| **Verifying the person (identity-bound approval)** | The enrolled person approved this exact request on a bound device or with ID plus liveness | A genuinely authorized insider; device theft without a second factor | Payments and changes above your threshold, recorded as evidence |

## How to use this protocol

1. Copy the protocol below, or download it as Markdown or text.
2. Replace everything in [square brackets]: names, thresholds, channels, systems.
3. Agree the safe words and challenge questions **in person** and store them offline (section 5).
4. Brief every executive and everyone in finance who can move money or change payment details, and run a drill each quarter.
5. Keep a completed evidence log (section 8) for every triggered request.

> [!NOTE]
> This template reflects common practice for finance teams. It is not legal, audit or insurance advice. Adapt it to your systems, your bank's services and any verification conditions in your insurance policy.

## Deepfake and voice-clone verification protocol for finance

**[Company Name]** · Owner: [Controller] · Approved by: [CFO] · Effective: [date] · Version: [1.0]

### 1. Purpose

Criminals can clone a voice from a short public clip and fake a face on a video call. This protocol makes sure no payment, bank-detail change or sensitive disclosure happens because a voice or face seemed familiar. We verify the person, not the channel.

### 2. Triggers: when this protocol applies

- Any request to send money, add a payee or change bank details that arrives by phone, voicemail, video call, voice note or messaging app.
- Any such request by email that refers to a call or meeting ("as discussed on the call").
- Any request presented as urgent, confidential, or as an exception to normal approvals, whoever it appears to come from.
- Any request to change an executive's or vendor's phone number, email or messaging account used for verification.
- Any payment above $[threshold] requested outside the normal workflow.

### 3. Ground rules

1. **No voice-only or video-only authorization.** A call, voicemail or video meeting is never approval, even if the person looks and sounds right.
2. **We start the contact.** Inbound calls are never verification. Hang up and call back on details we already hold.
3. **Secrecy is a red flag, not an instruction.** No executive will ask finance to skip this protocol or hide a payment from the controller.
4. **Pausing is always safe.** Nobody is criticized for delaying a payment to verify it.

### 4. Steps

1. **Pause.** Do not act during the call. Say: "Our protocol requires me to verify this. I will call you back."
2. **Challenge (optional, during the call).** Ask the pre-agreed challenge question or for the safe word (section 5). A wrong or evasive answer ends the call and goes to escalation. A right answer does not replace the next steps.
3. **Call back on a known channel.** Use the directory number, internal chat account or contact from [HR system / vendor master] that existed before the request. Never use a number, link or meeting invite from the request.
4. **Have the requester state the details.** The requester states the amount, beneficiary, bank and reason. Do not read them out for a yes.
5. **Get identity-bound approval above $[threshold].** The requester approves the exact request on [their enrolled device / ID plus liveness check / in person].
6. **Second approver.** A second person who did not take the call reviews the evidence and approves in [ERP / bank portal].
7. **Log it.** Complete the evidence log (section 8) before releasing the payment.

### 5. Safe words and challenge questions

- Agree them in person between each executive and [named finance staff]. Never send them by email, chat or text.
- Prefer challenge questions about shared, non-public context ("What did we discuss at [event]?") over facts findable online.
- Store them offline [sealed envelope / password manager vault with restricted access].
- Rotate them every [quarter] and immediately after any suspected exposure or staff change.
- A correct answer is one signal, never the only one. Callback and second approval still apply.

### 6. Escalation

- If verification fails or the requester pushes back on the protocol, stop. Notify [controller] and [IT/security] within [1 hour].
- Do not reply on the original channel. Warn the real executive or vendor through the known channel that someone is impersonating them.
- If money has already moved, call [bank fraud line] immediately, request a recall, and report to the FBI at ic3.gov.
- Preserve evidence: call logs, recordings if lawfully available, messages, meeting invites and email headers.

### 7. Exceptions

There are no verbal exceptions. A genuine emergency payment still needs the callback and second approval; only [CFO and controller together] may approve a documented exception, in writing, with reasons, reported at the next monthly review.

### 8. Evidence log

| Field | What to record |
| --- | --- |
| Request | Date, time, channel (phone, video, voice note, chat), claimed identity, amount and beneficiary |
| Challenge | Asked (yes/no) and result; never record the secret itself |
| Callback | Number or account used and where it came from; who answered; date and time |
| Details stated | Whether the requester stated details that match the request |
| Identity-bound approval | Method and result (device approval, ID plus liveness, in person) |
| Second approver | Name and date; must differ from the person who took the call |
| Outcome | Released, rejected or escalated; incident reference if escalated |

### 9. Training and drills

- Brief new executives and finance staff on this protocol within [30] days of joining.
- Run a simulated urgent executive request each [quarter] and review how it was handled.
- Review this protocol annually and after any incident or near miss.

## Frequently asked questions

### Do safe words stop deepfake scams?

They help. The FBI's IC3 suggests a secret word or phrase to verify identity (its advice is aimed at families, and the idea carries over to companies), and a Ferrari executive reportedly exposed a voice clone by asking a question only the CEO could answer. But secrets leak and people forget them, so the protocol still requires a callback on a known channel and a second approver.

### Is calling back enough?

Calling back on a number you already had beats trusting an inbound call, but it fails if that number was changed or forwarded. That is why the protocol adds identity-bound approval above a threshold and a second approver. See [is a callback enough?](https://realpayee.com/answers/is-a-callback-enough-to-stop-vendor-fraud)

### Should we use deepfake detection software?

Detection tools can flag synthetic voices or video on live calls, but they do not stop a payment by themselves. Use them, if at all, alongside a protocol that never authorizes payments on voice or video alone.

### What counts as identity-bound approval?

Approval tied to the enrolled person rather than a channel: for example approving the exact request on a device bound to them, or a government ID plus live selfie check, or in person.

### Can I use this template for free?

Yes. Copy it, download it, adapt it and use it internally. No email is required.

## Sources

- [FBI IC3 PSA: Criminals use generative artificial intelligence to facilitate financial fraud (Dec 3, 2024)](https://www.ic3.gov/PSA/2024/PSA241203)
- [Fortune: Ferrari exec foils deepfake attempt by asking the scammer a question only CEO Benedetto Vigna could answer (Jul 2024)](https://fortune.com/europe/2024/07/27/ferrari-deepfake-attempt-scammer-security-question-ceo-benedetto-vigna-cybersecurity-ai/)
- [CNN: Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee (May 2024)](https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk)
- [J.P. Morgan: When callbacks go wrong (Feb 27, 2026)](https://www.jpmorgan.com/insights/cybersecurity/business-email-compromise/when-callbacks-go-wrong)

## Related

- [CEO fraud and deepfake executive calls: how finance teams stop them](https://realpayee.com/ceo-fraud) - How CEO fraud works - from spoofed emails to deepfake video calls - and the verification steps that stop fake payment requests. (markdown: https://realpayee.com/ceo-fraud.md)
- [Deepfake scams: how AI voice and video fraud targets finance](https://realpayee.com/blog/deepfake-scams) - How deepfake scams and AI voice cloning target finance teams, what the Arup and Ferrari cases teach, and a verification protocol your team can run today. (markdown: https://realpayee.com/blog/deepfake-scams.md)
- [Executive Wire Verification Policy Template (Free SOP)](https://realpayee.com/templates/executive-wire-verification-policy) - Free executive wire verification policy template: thresholds, urgent and confidential requests, independent verification, dual approval, cooling-off period, no voice-only authorization, evidence log and exceptions. (markdown: https://realpayee.com/templates/executive-wire-verification-policy.md)
- [/answers/how-do-deepfake-cfo-scams-work](https://realpayee.com/answers/how-do-deepfake-cfo-scams-work) (markdown: https://realpayee.com/answers/how-do-deepfake-cfo-scams-work.md)
- [Book a RealPayee demo](https://realpayee.com/demo) - Book a demo of RealPayee: see vendor bank-change and high-value wire verification on your NetSuite, QuickBooks or Xero payment flow. (markdown: https://realpayee.com/demo.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/templates/deepfake-verification-protocol · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
