Skip to content
Phone Guides

Page

AI voice-call security: defend approval workflows against deepfakes

AI-generated and cloned voices make a familiar weakness more persuasive: people tend to trust a voice that sounds urgent, senior or known to them. The practical defence is not trying to judge whether a voice “sounds AI.” It is designing sensitive workflows so that a phone call alone cannot authorise the action.

Identify high-risk phone requests

Prioritise requests that move money, disclose information, change access or create an irreversible commitment.

Request Unsafe approval pattern Safer control
Payment or bank-detail change Caller sounds like an executive or supplier Confirm through a known independent contact and approved workflow
Password or MFA reset Caller supplies personal details or urgency Use authenticated self-service or a separate identity check
Customer-record change Caller ID or voice treated as identity proof Re-authenticate through established account controls
Urgent confidential disclosure Caller claims an incident and demands secrecy Apply need-to-know review and callback verification
Staff instruction Voice message overrides ordinary approval Require the normal documented authorisation path

Make the verification independent

Call the person back using a number already held in a trusted directory, not a number provided during the suspicious interaction. Use an authenticated portal or established internal messaging channel where appropriate. For high-value actions, require two people or two independent factors.

The test is whether a fraudster who controls the incoming call can also satisfy the verification. If they can, it is not independent.

Use caller ID and authentication correctly

Caller ID presentation and call-authentication frameworks can help with routing, analytics and some anti-spoofing decisions. They do not establish that a particular human is authorising a transaction. Explain this distinction in staff training; “verified call” and “verified person” are not interchangeable.

Prepare for a suspected impersonation

Give staff a simple response: pause the request, record the time and relevant contact details, preserve the approved evidence, notify the right security/finance owner and use the independent contact method. Avoid accusing a caller during the interaction; the objective is containment and verification.

Review the control after changes

Test the workflow after a change to phone routing, contact directories, supplier onboarding, identity systems or AI tools. Incident exercises should include a plausible urgent voice call, an unavailable approver and a compromised caller-ID scenario.

Further reading: the FTC advises people to verify a purported emergency using a phone number they already know is genuine rather than relying on a voice alone. FTC: Fighting back against harmful voice cloning.

This page is an operational security framework, not legal advice. Align verification, recording and incident actions with your organisation’s privacy, financial-control and regulatory obligations.