Identity-verification provider Sumsub has launched Workforce Verification, a product designed to insert document checks, biometric liveness and screening into enterprise identity and HR workflows.
The product’s most interesting feature is not recruitment screening. It is the attempt to re-establish human identity at high-risk moments after onboarding, such as password resets, suspicious logins, MFA re-enrolment and privilege escalation.
That addresses a familiar weakness in enterprise identity and access management. An IAM system can validate that the correct password, token or device credential was presented, but that does not always prove that the authorised person is the one presenting it. Deepfake-enabled social engineering, stolen credentials and compromised help-desk processes can exploit that gap.

Sumsub says its approach creates an initial identity baseline and then triggers step-up checks when another system flags risk. The company also claims the service is designed to resist deepfake attacks. Those performance assertions are vendor claims and should be evaluated independently by buyers.
The broader trend is important for financial services because identity assurance is moving from a one-time onboarding exercise toward a lifecycle problem. Banks already understand this on the customer side through KYC, transaction monitoring and step-up authentication. The same principle is increasingly relevant to employees, contractors and privileged administrators who can reach high-value systems.
Sumsub Chief Product Officer Andrew Novoselsky describes the problem as the difference between possession and identity: a valid credential shows that someone has the credential, not necessarily that the legitimate employee is still behind it.
For CISOs, the control question is how frequently to re-verify and what should trigger it. Continuous biometric checks would be intrusive and operationally heavy. Risk-triggered re-verification offers a more targeted model: ask for stronger proof only when a password reset, new device, unusual login or privilege change raises the stakes.
The product also illustrates why deepfake defence is becoming an identity architecture issue rather than a standalone detection problem. Detecting synthetic media is useful, but the enterprise outcome that matters is whether access is granted, blocked or escalated. The next generation of identity controls will increasingly be judged by how well they connect detection to that decision.
