GST & Indirect Tax

Deepfake Payment Fraud: The Internal-Control Test for Finance Teams

Cyber Fraud in Finance: Why Deepfakes Are the New Internal Control Test
CA Nikhil Gupta·May 2026·2 min readGST, MSME & Business Compliance Explainers
CERT-In clockSpecified incidents within six hoursFrom noticing or being informed
Control principleOut-of-band verificationVoice or video alone is not authority
Payment designMaker–checker plus transaction limitsNo single-channel override

Current position

CERT-In directions require specified cyber incidents to be reported within six hours of noticing them or being brought to notice. Financial entities may also have RBI, SEBI, insurance or sector-specific incident and fraud reporting duties. The exact event, clock, regulator and reporting format must be assessed immediately; internal investigation should not delay urgent containment.

How it works

Deepfake fraud usually combines impersonation with urgency, secrecy and a payment exception. The technology is new, but the control failures are familiar: weak callbacks, shared credentials, overridden approval limits and unverified bank changes.

Vendor master changes should be verified using independently held contact details, not the number in the change request. High-risk payments should have cooling periods or secondary confirmation.

Preserve email headers, call logs, device details, payment trails and CCTV or access records. Evidence can disappear when accounts or devices are wiped.

IssueCurrent positionWhy it matters
CERT-In clockSpecified incidents within six hoursFrom noticing or being informed
Control principleOut-of-band verificationVoice or video alone is not authority
Payment designMaker–checker plus transaction limitsNo single-channel override

Practical example

A finance manager receives a video call that appears to show the CEO ordering a confidential ₹75 lakh acquisition payment. The request uses a new beneficiary and bypasses procurement. The correct response is to pause, call the CEO through an independently stored number, verify the board or deal record and require the normal second approver. Urgency is a risk signal, not an approval.

Action checklist

Evidence and document checklist

Common mistakes

Red flags

Escalation and complaint route

Contact the bank immediately to freeze or recall funds, report cyber financial fraud through 1930 and the official cybercrime portal, and assess CERT-In and sector-regulator reporting. Preserve evidence and involve legal, IT, finance and law enforcement together.

Frequently Asked Questions

Can a video call be treated as approval? â–¼
No. Use the organisation’s documented authority and an independent verification channel.
How quickly must CERT-In be informed? â–¼
Specified incidents are subject to a six-hour reporting direction; assess applicability immediately.
What should happen first after payment fraud? â–¼
Contact the bank and cybercrime authorities at once while preserving evidence and containing access.
Is deepfake detection software enough? â–¼
No. Detection helps, but robust payment design should remain safe even when a fake looks convincing.

Source and review trail

Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.

Primary category
GST & Indirect Tax
Official starting point
www.gst.gov.in
Editorial review date
2026-07-19
Content status
Finin2min explanation; official source controls where facts, law, rates, forms or procedures can change.

Page source links

The prior page did not embed a page-specific external source. The category authority above is the minimum verification starting point; a specific instrument should be added during the next substantive editorial review.

Home / Insights / Markets & Economy Insights
More on Markets & Economy Insights
Browse all Markets & Economy Insights articles →
Related Articles
AI in Finance: A Control Framework for CFOs, Accountants and Auditors AI Data Centres: The Power, Water and Capex Economics Behind the Boom Carbon Credits in India: Climate Finance or Greenwashing Risk? Green Bonds: When Climate Ambition Meets Credit and Covenant Risk PLI Schemes: Can Incentives Build Durable Manufacturing Moats?