No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

by Matt Flegg
May 1, 2026
in Risk
magritte son of man deepfake

Deepfake fraud has already cost individual companies tens of millions — but K2 Integrity’s Matt Flegg argues the more significant development is regulatory. The UK’s Economic Crime and Corporate Transparency Act exposes large firms to unlimited fines for failure to prevent deepfake-enabled fraud, while the updated corporate governance code requires board-level declarations of control effectiveness covering cyber and fraud channels. 

Deepfakes are crossing new risk thresholds: from online curiosities to enterprise-scale fraud, market-moving disinformation and executive impersonation on live video calls. In recent public cases, attackers cloned the faces and voices of senior leaders to induce fund transfers, resulting in massive losses.

Other potential vectors include altering vendor details or seeding reputational crises. The tools are cheap, the attacks fast and the impact material. However, regulators are stepping in. The UK’s Economic Crime and Corporate Transparency Act (ECCTA) and updates to the corporate governance code (Provision 29) are driving fresh expectations around controls, disclosure and accountability. 

The evolution of deepfakes

While image manipulation dates back centuries, the digital deepfake story really took off in 2014, with academic breakthroughs in generative adversarial networks (GANs). Since then, catalyzed by social media and election manipulation, open-source tools and “deepfake-as-a-service” platforms have democratized access, enabling increasingly realistic face and voice synthesis. 

Attackers now deploy these tools live on video calls or call-forwarding apps, turning technology into a real-time weapon.

Over just the past few years, this risk has proliferated:

  • In 2024, a Hong Kong finance employee participated in a realistic video meeting featuring a deep-faked CFO and colleagues, ultimately paying around $25 million before the fraud was detected. The scale of the loss and the use of a multi-person video conference demonstrate the sophistication of the fraud. 
  • In 2025, a finance director of a Singaporean corporation was duped by an AI-generated CFO impersonation, executed primarily via WhatsApp and a Zoom call. Authorities recovered most of the $499,000 wired in the incident.

These illustrate how deepfakes are increasingly effective. They often amplify trust exploitation, using reconnaissance, phishing, urgency and pushing for rapid payments.

deepfake concept pixelated faces
Cybersecurity

Can You Spot a Deepfake? Are You Sure?

by Perry Carpenter
March 10, 2025

With synthetic media losses projected to triple by 2027, detection techniques must evolve beyond visual verification alone

Read moreDetails

Rising regulatory pressure: ECCTA & Provision 29

In the UK, the regulatory and governance landscape has been evolving to counter a range of corporate threats, including the rise of deepfakes. Two of the most relevant developments are the Economic Crime and Corporate Transparency Act (ECCTA) and the corporate governance code’s Provision 29.

Economic Crime and Corporate Transparency Act

From September 2025, this landmark UK legislation introduces a raft of provisions that could mean inadequate deepfake risk management could have significant impacts on a business. The provisions include: 

  • “Failure to prevent fraud” offense for large firms, requiring preventive procedures, including for fraud via deepfakes. Large companies could face unlimited fines if they cannot prove taking “reasonable steps” to prevent fraud.
  • Wider corporate liability extended to senior manager behavior during frauds. This demonstrates an underlining of top-down oversight.
  • Enhanced powers for Companies House verification, making identity integrity a compliance requirement. 

Corporate governance code: Provision 29

From January 2026, board-level reporting and disclosures must cover social-engineering, business email compromise and deepfake schemes; in addition, they must:

  • Include a formal declaration on the effectiveness of material internal controls covering cyber and fraud channels.
  • Disclose any control failures and remediation actions.
  • Show continuous monitoring of risk frameworks and internal controls.

Mitigation tactics for compliance and resilience

No single control will defeat a threat evolving as rapidly as deepfake technology. What is required is a layered architecture of governance, detection and culture.

  • Strengthening governance: Policies should reflect that seeing or hearing is no longer sufficient for verification, embedding callback procedures and multi-person approval requirements for financial transactions or vendor changes. Risk mapping should be aligned to Provision 29, with board oversight extending explicitly to fraud, deepfake, cyber and third-party risk frameworks.
  • Controls and detection: Tiered verification thresholds should be established so that material transactions, news releases or identity changes require robust sign-off and documentation checks. Tools should be deployed across security operations centers and conferencing gateways, supported by clear escalation protocols.
  • Processes and culture: Scenario-based training should be introduced for finance and HR teams, incorporating voice and video deepfake drills alongside tabletop exercises for boards. Organization-wide adoption of the “VOICE” checklist — verify callbacks, observe anomalies, involve peers, confirm details, escalate — provides a practical framework for day-to-day vigilance.
  • Crisis readiness: Boards should approve playbooks aligned to Provision 29 covering both operational and reputational response, with detection and takedown workflows ensuring content can be traced, attributed and responded to swiftly. Organizations should also confirm that cyber insurance coverage is appropriate and that external advisors have sufficient experience to support effectively in the event of an attack.
  • Third-party governance: Supplier contracts should stipulate clear verification protocols and notification obligations in the event of deepfake fraud attempts, ensuring third-party exposure is governed with the same rigor applied internally.

Why engagement matters

Regulators increasingly expect deepfake risk management to be embedded in corporate governance. The ECCTA demands procedures to prevent fraud, while Provision 29 requires board-level declarations of control effectiveness and transparency regarding failures.

Failure to prepare is now not just poor risk management; it can trigger regulatory sanctions, reputational damage and even criminal liability.

Deepfakes have converted perception into a proven attack vector, a challenge that must be governed as fraud, cyber and operational risk. Regulators in the UK are setting the bar high: ECCTA and Provision 29 are carving paths toward corporate liability based on controls and disclosure, not just failure. A layered approach — comprising governance, detection, training, controls, cross-functional crisis playbooks and investigative readiness — is a legal and strategic imperative. Companies that move first will treat deepfakes not as a future threat but as a pillar of contemporary governance.

Tags: Artificial Intelligence (AI)Board of DirectorsCyber Risk
Previous Post

LogicGate Names New CEO, Co-Founder Transitions to Chairmanship

Next Post

Brave Leaders Aren’t Loud

Matt Flegg

Matt Flegg

Matt Flegg is an associate managing director in investigations and disputes in K2 Integrity’s London office. Before joining K2 Integrity, he held senior roles at a global investigations and risk advisory firm, where he designed and implemented sophisticated investigative strategies and led initiatives that integrated advanced technology and innovative techniques with traditional investigative methods.

Related Posts

robot fallen over

‘Blame the Bot’ Won’t Cut It in Front of Regulators

by Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh
May 11, 2026

Responsible automation requires human judgment, independence and evidence

robot and human hand touching

Your Next AI Risk Is Inside the Systems You Trust the Most

by Bill Lewis
May 11, 2026

If an organization is not inventorying and analyzing its AI agents, it isn’t managing risk

Ethixbase360 Third Party Cyber Risk

A Practical Guide to Third-Party Cyber Risk Management

by Corporate Compliance Insights
May 8, 2026

A practical, business-focused look at third-party cyber risk as the natural next step in TPRM eBook A Practical Guide to...

brain obscured behind glass

Why Experience Still Matters in an Automated Finance World

by Ryan Padget
May 8, 2026

AI is reshaping workflows in finance, but the judgment that protects organizations remains deeply human

Next Post
don yelling at peggy

Brave Leaders Aren’t Loud

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2026 Corporate Compliance Insights