Phone us
Deepfake fraud is becoming a practical risk for financial organisations, payment teams and SWIFT users. This article looks at how deepfake awareness training can help staff recognise AI-enabled impersonation, verify unusual requests and respond appropriately.

AI-generated voices, images and video are becoming increasingly convincing, accessible and easy to deploy. For organisations, this creates a serious fraud and cyber security risk. An employee may receive a call, video meeting request or message that appears to come from a trusted executive, colleague, client or service provider, when the person they can see or hear is not real.

Deepfakes are now referenced within SWIFT’s Customer Security Controls Framework v2026 under control 7.2, Security Training and Awareness, as an example of an AI-based threat. This makes deepfake awareness increasingly relevant for organisations using SWIFT and for the training programmes they provide to staff.

AJC has developed dedicated deepfake awareness training for SWIFT clients in response to this change. The training is designed for banks, building societies and investment firms using SWIFT, as well as organisations seeking to strengthen their wider fraud and security awareness programmes.

Why Do Organisations Need Deepfake Awareness Training?

Deepfake fraud combines new technology with familiar social engineering techniques. Attackers gather information about an organisation and its employees, collect publicly available voice or video samples, and use AI to impersonate a trusted person. They then create urgency, invoke authority or demand secrecy to pressure the recipient into acting before the request can be independently verified.

The technology may be sophisticated, but the attack often succeeds because an employee is persuaded to bypass a normal control. A convincing imitation of a chief financial officer could be used to authorise a payment. A cloned voice might request sensitive information over the telephone. A fake IT or service desk contact could direct a user to a malicious link or ask for login credentials.

This is no longer a theoretical risk. In one widely reported incident, an employee at a multinational organisation in Hong Kong was deceived during a video conference in which fraudsters recreated the appearance and voices of the company’s chief financial officer and other colleagues. The employee subsequently transferred HK$200 million to accounts controlled by the attackers. The incident demonstrates why seeing and hearing a familiar person can no longer be treated as sufficient proof of identity.

What Does SWIFT Require in Relation to Deepfakes?

SWIFT’s Customer Security Controls Framework v2026 updated control 7.2, Security Training and Awareness, to reference deepfakes as an example of an AI-based threat. This reflects the increasing relevance of AI-enabled impersonation to payment security and the need for awareness programmes to keep pace with changing attack methods.

Our training helps organisations address this evolving threat within their SWIFT security awareness activity. It explains the risks in a practical financial services context and reinforces the behaviours that protect payment processes, including independent verification, dual approval, segregation of duties, escalation and the refusal to bypass policy under pressure.

The training can support an organisation’s wider compliance and assurance programme, although it should form part of a broader set of proportionate people, processes and technical controls.

What Does the Deepfake Training Cover?

The course begins by explaining what deepfakes are and how AI can be used to manipulate or generate voices, images and video. It follows the typical lifecycle of an attack, from reconnaissance and the harvesting of publicly available media, through to AI modelling, real-time impersonation and the use of urgency or authority to manipulate the victim.

Staff are introduced to real incidents and realistic financial-sector scenarios. These include an attacker impersonating a treasurer to contact a SWIFT operator, a deepfake video used to authorise an urgent MT103 payment, a fraudulent compliance override, a fake SWIFT service desk contact, and personalised internal phishing designed to compromise credentials.

The training also teaches participants to identify vocal, visual and behavioural warning signs. These may include unusual tone or pacing, irregular background sound, minor lip-sync problems, distortion around the face, unnatural blinking, unexpected lag, demands for secrecy and attempts to bypass established approval processes.

Because high-quality deepfakes may not display an obvious technical flaw, the course does not rely on visual detection alone. It places particular emphasis on verification through a separate, trusted channel.

Practical defensive measures are covered at the human, technical and governance levels. Staff learn why sensitive requests should be confirmed using known contact details, why pressure must never justify bypassing policy, and how prompt escalation can prevent a costly mistake. The training also explains the supporting role of multi-factor authentication, payment approval workflows, anomaly detection, email authentication and layered security controls.

Finally, participants learn what to do if a suspected deepfake incident occurs. This includes stopping an active transaction where possible, containing compromised accounts or systems, preserving evidence, escalating through the organisation’s incident response structure, and notifying relevant financial partners, authorities or regulators where required.

Tailored Training for Banks, Building Societies and Investment Firms

Generic awareness content can struggle to feel relevant. Our course is available in three sector-specific versions so that participants see how deepfake fraud could affect their own organisation and working practices.

The banking version focuses on high-value and time-sensitive payments, direct access to SWIFT and settlement systems, high transaction volumes, hierarchical approval structures, and the amount of public information often available about senior executives.

The building society version considers the exploitation of trusted, community-focused brands, real-time payments, savings and mortgage-related funds, legacy technology, customer demographics, and the risk of attackers posing as fraud prevention or SWIFT-related support personnel.

The investment firm version addresses high-value transactions, relationship-led decision making, confidential deals, frequent telephone and video communication, and the direct involvement of senior personnel in approvals. These characteristics can allow a convincing impersonation to exploit trust and familiarity.

For organisations outside these sectors, or those that do not use SWIFT, the underlying lessons remain highly relevant. Deepfake attacks can target any business in which employees act on telephone calls, video meetings, emails or messages involving payments, credentials, confidential information, or changes to normal processes. The material can therefore be provided as part of a broader cyber security, fraud prevention or security awareness programme.

Optional Deepfake Awareness Quiz

The training can be supplied with a set of assessment questions for organisations that want to test understanding after the course. The quiz can cover the nature of deepfakes, common attack methods, warning signs, verification procedures, SWIFT-related scenarios and the correct response to a suspected incident.

Including an assessment can help an organisation confirm participation and demonstrate whether the key learning points have been understood. It can also highlight areas where further communication, training or scenario testing may be needed.

Building Resilience Against AI-Enabled Fraud

Technology alone cannot remove the risk of deepfake fraud. Organisations need employees who understand that a familiar face or voice is not proof of identity and who feel authorised to pause, verify and escalate, even when a request appears to come from a senior person.

Effective awareness training turns that principle into practical behaviour. By combining clear explanations, real cases, sector-specific scenarios and actionable controls, our deepfake training helps organisations prepare their people for a form of fraud that is likely to become more convincing as AI continues to develop.

To discuss deepfake awareness training for your organisation, contact AJC. The course can be provided with sector-specific content and an optional knowledge check quiz to support your organisation’s training objectives.

Frequently Asked Questions

What is deepfake awareness training?

Deepfake awareness training teaches employees how AI-generated or manipulated audio, video and images can be used in fraud and social engineering. It explains how attacks work, the warning signs to look for, how to verify unusual requests, and what to do when an incident is suspected.

Is deepfake training only relevant to SWIFT users?

No. The course supports awareness of risks that are particularly important to SWIFT users, but deepfake impersonation can affect any organisation. It is relevant wherever staff handle payments, sensitive information, account access or important instructions through telephone calls, video meetings, email or messaging platforms.

Who should complete deepfake awareness training?

Training is particularly valuable for payment and finance teams, SWIFT users, executives, executive assistants, IT and service desk personnel, fraud teams, compliance staff, and any employees who handle sensitive or high-value requests. Organisations may also choose to include it in company-wide security awareness training.

Can the training be tailored to our organisation?

Yes. Dedicated versions are available for banks, building societies and investment firms. The training can also be provided to other organisations, including those that do not use SWIFT, as part of their wider cyber and fraud awareness activity.

Does the training include a quiz?

An optional set of questions can be supplied for organisations that want to assess participants after the training. This can help demonstrate understanding and identify areas that may require reinforcement.

What format is the training and how long does it take?

The training is provided in an MP4 video file, which is around 30 minutes long.

How AJC Can Help

AJC has developed dedicated deepfake awareness training for SWIFT clients, following the inclusion of deepfakes within SWIFT’s Customer Security Controls Framework v2026 under control 7.2, Security Training and Awareness.

The training helps organisations address this requirement by giving staff a practical understanding of how deepfake fraud works, how AI-enabled impersonation can be used to target payment processes, and why independent verification remains essential.

Designed for banks, building societies, investment firms and other organisations using SWIFT, the course uses financial-sector scenarios to reinforce key behaviours, including pausing under pressure, refusing to bypass policy, escalating suspicious requests and verifying instructions through a separate, trusted channel.

AJC can provide the training with sector-specific content and an optional knowledge check quiz to support your organisation’s SWIFT security awareness, compliance and assurance objectives.

Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Image accreditation: Getty Images on Unsplash.com+. Last accessed on 23 July 2026. Available at: https://unsplash.com/photos/portrait-of-a-layered-3d-human-head-tqX2k9BPF5I

In case you missed it...

Can AI Chatbots Be Trusted to Get the News Right?
Can AI Chatbots Be Trusted to...

Artificial intelligence chatbots are becoming a popular way to access and summarise information, but they are not always reliable. This...

Read More
What Fraud Scenarios Should Every Business Test?
What Fraud Scenarios Should Every Business...

Fraud controls should not only exist on paper. They need to be tested against realistic scenarios that reflect how criminals...

Read More
Compliance Cyber Attack
Why Compliance Alone Won’t Stop a...

Compliance with recognised cyber security standards is an important part of managing risk, but it should not be mistaken for...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.