Most organisations rarely stop to consider why their control environment works. The answer is deceptively simple: decisions are built on evidence that is assumed to be authentic.
An invoice supports a payment. An identity document confirms who someone is. An email authorises a transaction. A recorded conversation provides evidence of an instruction. Screenshots, reports and approval records help auditors conclude that controls operated as intended.
Fraud has always challenged those assumptions. Forged signatures, altered invoices and impersonation are hardly new. What is changing is the ease with which convincing evidence can now be created.
Generative AI is reducing the time, cost and expertise required to produce realistic documents, voices, images and identities. In doing so, it is changing one of the assumptions on which many organisations have built their control environments: that authentic-looking evidence is more likely to be genuine than fabricated.
This is more than an emerging fraud risk. It is a governance challenge. If the evidence used to approve transactions, onboard suppliers or provide assurance can itself be manufactured, organisations need to reconsider how confidence is established in the decisions they make.
AI is changing the economics of deception
Generative AI is not creating an entirely new category of fraud. Rather, it is making familiar techniques faster, cheaper and significantly more convincing.
Business email compromise, fake invoices, supplier impersonation and identity fraud have existed for years. What has changed is that criminals no longer require specialist design skills, language expertise or significant resources to produce highly credible content. AI can generate professional correspondence, clone voices, create synthetic identities and produce supporting documentation that appears entirely consistent.
This is not simply a theoretical concern. Europol’s Internet Organised Crime Threat Assessment (IOCTA) 2026 identifies generative AI as an accelerator of online fraud, enabling criminals to automate and personalise social engineering, produce more convincing impersonation attempts and increase the scale of fraudulent activity. Rather than replacing established fraud techniques, the report concludes that AI is making them faster, more scalable and harder to detect.
The result is that many controls remain designed for an earlier version of the threat. Risks may already appear on organisational risk registers, yet the controls intended to manage them were developed when creating convincing evidence required considerably more effort.
That distinction matters because organisations often rely on the practical difficulty of forgery as an implicit control. As AI lowers that barrier, trust can no longer depend on the assumption that convincing evidence is difficult to fabricate.
When evidence becomes part of the fraud
Many organisations still rely heavily on documents, images, recordings and communications to establish identity, authority and legitimacy.
A supplier provides incorporation documents and banking details. A customer submits identification and a selfie. An employee claims expenses with supporting receipts. A senior executive authorises an urgent payment by email or telephone.
Each item may appear credible when viewed in isolation.
The challenge is that visual or verbal credibility no longer guarantees authenticity.
This is particularly significant because fabricated evidence rarely affects just one process. A synthetic identity accepted during onboarding may later appear in procurement records, payment systems, compliance files and audit evidence. Information that is trusted once often becomes trusted everywhere.
A weakness introduced at the start of a process can therefore travel across multiple business functions, influencing decisions long after the original verification took place.
That is why AI-enabled fraud should not be viewed solely as a technology or cybersecurity issue. It raises broader questions about how organisations establish trust across connected governance processes.
Verification controls need to evolve
Many organisations have strengthened verification procedures in response to payment fraud and impersonation. Independent approvals, call-back procedures and segregation of duties remain valuable controls.
However, these controls should now be examined through a different lens.
If multiple pieces of supporting evidence can be generated from the same false information, adding another document or requesting a second confirmation may provide less assurance than organisations assume.
The focus therefore shifts from asking whether evidence looks convincing to establishing whether it can be independently corroborated.
The challenge is that organisational preparedness has not kept pace with the threat. The 2026 Anti-Fraud Technology Benchmarking Report, published by the Association of Certified Fraud Examiners (ACFE) and SAS, found that only 7% of respondents believed their organisation was more than moderately prepared to detect or prevent AI-powered fraud. Respondents also expected deepfake social engineering and AI-generated document fraud to become significantly more common over the coming years.
This may involve verifying requests using previously trusted contact information rather than details supplied in the request itself, separating identity verification from transaction approval, retrieving information directly from authoritative systems and understanding the provenance of digital content rather than relying solely on its appearance.
The underlying principle is straightforward: important decisions should not depend entirely on evidence received through the same channel as the request being authorised.
Assurance needs to ask a different question
The implications extend beyond operational controls.
Internal audit, compliance and assurance teams routinely examine documents, reports, screenshots and approval records to determine whether controls have operated effectively. Traditionally, the existence of that evidence has provided confidence.
Increasingly, assurance may need to begin one step earlier.
Rather than asking whether evidence demonstrates that a control was performed, organisations should also ask why that evidence should be trusted in the first place.
Professional scepticism is no longer confined to evaluating the content of evidence. It increasingly requires an understanding of its origin, integrity and traceability.
This may place greater emphasis on direct access to authoritative systems, transaction logs, metadata and independently sourced information rather than evidence assembled specifically for review.
Confidence is created not simply because documentation exists, but because its authenticity can be established.
A governance issue, not just a fraud issue
There is a temptation to view deepfakes and AI-generated content primarily as cybersecurity concerns.
Technology teams undoubtedly have an important role in assessing detection tools, authentication technologies and platform vulnerabilities. Yet many of the decisions most vulnerable to manipulated evidence sit elsewhere in the organisation.
Finance approves payments. Procurement manages suppliers. HR verifies employees. Compliance conducts due diligence. Operational teams authorise exceptions. Internal audit provides independent assurance.
No single function owns the integrity of organisational evidence.
An effective response therefore depends on connected governance rather than isolated initiatives. Organisations need to understand where synthetic evidence could enter critical processes, how it might influence downstream decisions and whether accountability remains clear if authenticity is questioned.
Test the assumptions behind your controls
Policies can remind employees to remain alert to fraud, but they do not demonstrate that controls will perform under pressure.
Scenario testing is becoming increasingly important.
How would the organisation respond if an apparently urgent request arrived from a recognised executive, supported by a convincing voice, familiar language and realistic documentation? Would employees feel empowered to pause the transaction? Could the approval be independently verified? Would the incident be recognised quickly enough to prevent wider consequences?
These exercises often reveal that the greatest weakness is not technological. It is organisational confidence in challenging requests that appear legitimate.
They also expose whether verification processes genuinely operate independently or simply validate the same fabricated evidence through different steps.
Three questions boards and GRAC leaders should be asking
Rather than attempting to anticipate every new AI-enabled fraud scenario, organisations may benefit from testing three more fundamental assumptions.
- Which high-impact decisions still rely primarily on documents, emails, images or voice recordings that could now be convincingly fabricated?
- Where does trusted information pass between functions without being independently revalidated, allowing one false artefact to influence multiple decisions across the organisation?
- If a regulator, customer or court challenged a critical decision tomorrow, could the organisation demonstrate not only that evidence existed, but that its authenticity had been independently verified?
These are not simply fraud prevention questions. They go to the heart of governance because they determine whether confidence in important decisions is genuinely supported by the control environment.
Rebuilding confidence in evidence
Generative AI is unlikely to make documents, recordings or digital content any less important. They will remain central to governance, operational decision-making and assurance.
What is changing is the confidence organisations can reasonably place in those artefacts without independent verification.
The organisations best prepared for AI-enabled fraud will not necessarily be those that detect every manipulated document or deepfake. They will be those that design control environments where confidence is built through corroboration, trusted sources and connected governance rather than assumptions about what appears genuine.
Ultimately, this is not simply about fraud prevention. It is about ensuring that boards, executives and assurance functions can continue to rely on the information that underpins their most important decisions. As evidence becomes easier to manufacture, the resilience of the control environment will increasingly depend on an organisation’s ability to establish not only that evidence exists, but why it should be trusted.
Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>





