Deepfake Risk Calculator
Score synthetic media and voice-clone fraud risk from public exposure, verification workflow, channel and transaction value.
Inputs
Deepfake Fraud Risk
Medium
Risk Score
3.88/ 10
Probability One Attempt Succeeds
38.8%
Expected Annual Loss
$1,164,375
Voice or Face Clone Feasibility
7.50/ 10
Highest-Value Control
Require callback to a pre-agreed number plus a code word for any instruction to move money or change details
Step by step
Values used
Public audio and video of key people = Regular media and earnings calls — 8; Channel used for approvals = Video call — 7; Out-of-band verification for instructions = Reply on the same channel — 8; Value of a single approvable transaction = 500,000 currency; Dual authorisation on payments and changes = Yes; Staff trained on synthetic-media fraud = 40 %; Synthetic-media detection tooling = Manual review of suspicious media — 7; Impersonation attempts expected per year = 6 attempts/year
Deepfake Risk
risk = cloneFeasibility × controlStrength ÷ 10, where cloneFeasibility = mean(public media footprint, channel weakness) and controlStrength is the residual weakness after verification, dual control and training.
Deepfake Fraud Risk
= Medium
Risk Score
= 3.88 / 10
Probability One Attempt Succeeds
= 38.8
Expected Annual Loss
= 1,164,375
Voice or Face Clone Feasibility
= 7.50 / 10
Highest-Value Control
= Require callback to a pre-agreed number plus a code word for any instruction to move money or change details
How it works
Cloning quality is no longer the constraint — a few minutes of public audio is enough — so the risk is almost entirely a process question: can a convincing voice or face alone authorise something consequential. Out-of-band verification to a pre-agreed number with a shared code word is the control that works, because it does not depend on anyone detecting the fake. Dual control and training reduce the residual, and detection tooling is a supplement rather than a defence. The control that stops synthetic-media fraud is the same one that stopped its telephone predecessor: never act on an instruction verified only through the channel it arrived on.
Formula
Deepfake Risk
risk = cloneFeasibility × controlStrength ÷ 10, where cloneFeasibility = mean(public media footprint, channel weakness) and controlStrength is the residual weakness after verification, dual control and training.
- cloneFeasibility
- How easily a convincing clone can be produced and delivered
- controlStrength
- Residual weakness of the approval process
- expectedLoss
- attempts × success probability × transaction value
Frequently Asked Questions
How is Deepfake Risk calculated?
risk = cloneFeasibility × controlStrength ÷ 10, where cloneFeasibility = mean(public media footprint, channel weakness) and controlStrength is the residual weakness after verification, dual control and training. Cloning quality is no longer the constraint — a few minutes of public audio is enough — so the risk is almost entirely a process question: can a convincing voice or face alone authorise something consequential. Out-of-band verification to a pre-agreed number with a shared code word is the control that works, because it does not depend on anyone detecting the fake. Dual control and training reduce the residual, and detection tooling is a supplement rather than a defence.
Why does Deepfake Risk matter?
The control that stops synthetic-media fraud is the same one that stopped its telephone predecessor: never act on an instruction verified only through the channel it arrived on.
What values do I need to enter?
This calculator takes 8 inputs: Public audio and video of key people, Channel used for approvals, Out-of-band verification for instructions, Value of a single approvable transaction, Dual authorisation on payments and changes, Staff trained on synthetic-media fraud, Synthetic-media detection tooling, Impersonation attempts expected per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Can detection tools reliably identify deepfakes?
Not dependably in a live call, and generation improves faster than detection. Treat detection as a useful signal for retrospective investigation, and put the reliance on process controls that do not require judging authenticity.
Why does public exposure matter if anyone's voice can be cloned?
Because quality scales with available material. A few seconds produces something passable on a bad phone line; hours of earnings-call audio produces a clone that survives a video conference with a suspicious CFO.
You might also need
- Synthetic Identity Risk CalculatorCommonly used together
- Email Security Score CalculatorCommonly used together
- Phishing Risk CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats