Page
AI voice-call security: defend approval workflows against deepfakes
AI-generated and cloned voices make a familiar weakness more persuasive: people tend to trust a voice that sounds urgent, senior or known to them. The practical defence is not trying to judge whether a voice “sounds AI.†It is designing sensitive workflows so that a phone call alone cannot authorise the action.
Identify high-risk phone requests
Prioritise requests that move money, disclose information, change access or create an irreversible commitment.
| Request | Unsafe approval pattern | Safer control |
|---|---|---|
| Payment or bank-detail change | Caller sounds like an executive or supplier | Confirm through a known independent contact and approved workflow |
| Password or MFA reset | Caller supplies personal details or urgency | Use authenticated self-service or a separate identity check |
| Customer-record change | Caller ID or voice treated as identity proof | Re-authenticate through established account controls |
| Urgent confidential disclosure | Caller claims an incident and demands secrecy | Apply need-to-know review and callback verification |
| Staff instruction | Voice message overrides ordinary approval | Require the normal documented authorisation path |
Make the verification independent
Call the person back using a number already held in a trusted directory, not a number provided during the suspicious interaction. Use an authenticated portal or established internal messaging channel where appropriate. For high-value actions, require two people or two independent factors.
The test is whether a fraudster who controls the incoming call can also satisfy the verification. If they can, it is not independent.
Use caller ID and authentication correctly
Caller ID presentation and call-authentication frameworks can help with routing, analytics and some anti-spoofing decisions. They do not establish that a particular human is authorising a transaction. Explain this distinction in staff training; “verified call†and “verified person†are not interchangeable.
Prepare for a suspected impersonation
Give staff a simple response: pause the request, record the time and relevant contact details, preserve the approved evidence, notify the right security/finance owner and use the independent contact method. Avoid accusing a caller during the interaction; the objective is containment and verification.
Review the control after changes
Test the workflow after a change to phone routing, contact directories, supplier onboarding, identity systems or AI tools. Incident exercises should include a plausible urgent voice call, an unavailable approver and a compromised caller-ID scenario.
VoIP security baseline
€” establish practical access, endpoint and monitoring controls.
VoIP incident response
€” preserve evidence and contain an active incident.
Phone service support model
€” define escalation ownership.
Business phone number management
€” maintain trusted contact and routing records.
VoIP fraud prevention
€” reduce account-abuse and toll-fraud exposure.
Further reading: the FTC advises people to verify a purported emergency using a phone number they already know is genuine rather than relying on a voice alone. FTC: Fighting back against harmful voice cloning.
This page is an operational security framework, not legal advice. Align verification, recording and incident actions with your organisation’s privacy, financial-control and regulatory obligations.