Score synthetic media and voice-clone fraud risk from public exposure, verification workflow, channel and transaction value.
Cloning quality is no longer the constraint — a few minutes of public audio is enough — so the risk is almost entirely a process question: can a convincing voice or face alone authorise something consequential. Out-of-band verification to a pre-agreed number with a shared code word is the control that works, because it does not depend on anyone detecting the fake. Dual control and training reduce the residual, and detection tooling is a supplement rather than a defence. The control that stops synthetic-media fraud is the same one that stopped its telephone predecessor: never act on an instruction verified only through the channel it arrived on.
Deepfake Risk
risk = cloneFeasibility × controlStrength ÷ 10, where cloneFeasibility = mean(public media footprint, channel weakness) and controlStrength is the residual weakness after verification, dual control and training.
risk = cloneFeasibility × controlStrength ÷ 10, where cloneFeasibility = mean(public media footprint, channel weakness) and controlStrength is the residual weakness after verification, dual control and training. Cloning quality is no longer the constraint — a few minutes of public audio is enough — so the risk is almost entirely a process question: can a convincing voice or face alone authorise something consequential. Out-of-band verification to a pre-agreed number with a shared code word is the control that works, because it does not depend on anyone detecting the fake. Dual control and training reduce the residual, and detection tooling is a supplement rather than a defence.
The control that stops synthetic-media fraud is the same one that stopped its telephone predecessor: never act on an instruction verified only through the channel it arrived on.
This calculator takes 8 inputs: Public audio and video of key people, Channel used for approvals, Out-of-band verification for instructions, Value of a single approvable transaction, Dual authorisation on payments and changes, Staff trained on synthetic-media fraud, Synthetic-media detection tooling, Impersonation attempts expected per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Not dependably in a live call, and generation improves faster than detection. Treat detection as a useful signal for retrospective investigation, and put the reliance on process controls that do not require judging authenticity.
Because quality scales with available material. A few seconds produces something passable on a bad phone line; hours of earnings-call audio produces a clone that survives a video conference with a suspicious CFO.