No items found.

Identity checks in hiring: fake candidates and deepfakes

By Jürgen Ulbrich

Identity checks in hiring should establish reasonable confidence that the person in a remote process is connected to the experience they present. They should not turn every applicant into a fraud suspect or require government ID at the application stage. The proportionate approach is layered: confirm a professional profile, compare relevant facts across channels, ask specific questions about real work, and use formal proof only when the role or access risk calls for it.

A fake candidate is not simply an applicant with an unusual CV, a new profile, an accent, or an imperfect video connection. In this context, a fake candidate is someone using a borrowed, fabricated, shared, or substituted identity to obtain a role or access. A deepfake is manipulated audio or video that can make a remote interaction appear to involve someone other than the person actually participating. Those definitions matter because they focus the process on evidence and risk rather than on appearance.

Why identity and capability need separate checks

Remote hiring can make it easier to separate a profile from the person who ultimately performs the work. A candidate may present another person’s professional history, use a shared profile, have a proxy take an early interview, or manipulate a video interaction. None of these scenarios is a reason to treat a normal candidate journey as a security investigation. They are a reason to avoid relying on any single document, video impression, or automated score.

Capability is also different from identity. A person may genuinely own a profile yet be unable to explain the work described there; conversely, a capable applicant may have a sparse public footprint. The right question is not whether the team can achieve certainty early. It is whether the checks at each stage are sufficient for the decision being made at that stage.

That distinction is especially useful when handling a high volume of applications. The guidance on application volume and CV screening explains why a CV should be treated as one source of context, not as a complete picture of either a person or their capability.

A risk ladder for identity checks in hiring

A defensible identity-check policy increases scrutiny only as both commitment and potential harm increase. It gives every candidate in the same role class the same published path, while allowing an additional check before access to sensitive systems. This is more respectful than asking for invasive proof from everyone and more reliable than making ad-hoc exceptions after an interviewer has a vague feeling.

  • Application: assess role fit and basic internal consistency. Do not make a passport, selfie, or biometric check the default entry ticket.
  • Shortlisting: invite the candidate to share and confirm a professional profile, then compare only role-relevant facts such as employer, job title, and broad dates.
  • Initial interview: use structured, open questions about a project, decision, trade-off, or result the applicant claims as their own.
  • Final selection: resolve material inconsistencies and conduct any role-appropriate reference, right-to-work, or identity step according to a documented policy.
  • Onboarding and privileged access: apply the strongest verification only where a person will receive sensitive data, financial authority, production access, or other high-impact permissions.

This ladder is the practical decision rule: use the least intrusive check that can answer the question at hand, then escalate only when the next decision carries more risk. It also prevents a common mistake in remote hiring: treating a lightweight interview signal as though it were proof of identity fraud.

What to check before asking for formal documents

Confirm professional context

A confirmed professional profile gives an applicant a chance to connect their application to a second, self-controlled source of career information. It can make an interview more specific: instead of asking for generic proof, the recruiter can ask about a particular role, team, or outcome. It should be optional unless the role has a genuinely documented need for it.

The useful test is consistency, not perfection. A title may differ between a CV and a profile because organisations use different naming conventions. Employment dates may be rounded. Invite an explanation when a difference is material to the role, and record the resolution rather than a vague suspicion. A workflow for context-led CV screening can standardise that review without claiming that a CV verifies identity.

Ask questions that are difficult to outsource but easy to answer honestly

Specific follow-up questions are often more proportionate than surveillance. Ask the candidate to describe the starting point of a project, the decision they owned, a constraint they had to work around, or what they would change in hindsight. Follow up on their own answer. This creates a useful consistency check while respecting the fact that people communicate, think, and present differently.

For remote conversations, use the same core question set for comparable candidates and allow reasonable accommodations. A candidate should not be penalised for a disability, an unreliable connection, a camera limitation, or a different communication style. The aim is to assess work-relevant context, not eye contact, background, facial movement, or a supposedly typical manner of speaking.

Structured AI interview and voice recruiting workflows can help teams ask comparable questions and retain an accurate record. They should not convert an unusual answer, a delayed response, or a technical anomaly into an automatic accusation. Human review remains essential, particularly when a system flags a potential mismatch.

Where does LinkedIn profile confirmation fit?

LinkedIn profile confirmation is a supporting signal, not proof of personhood. In a candidate portal that keeps the candidate in control of their profile, an applicant can share a LinkedIn profile and confirm that it belongs to them. This provides another professional reference point that the applicant has chosen to provide and can be used to guide a more informed conversation.

It does not prove that the person in a video call owns the profile, that every statement on the profile is correct, or that the applicant will personally perform the work after hiring. It also cannot be required as a universal condition of consideration: many excellent candidates do not use LinkedIn, keep it private, or have profiles that lag behind their current circumstances. Missing LinkedIn data should never be a sole rejection reason or a trigger for harsher treatment.

The most useful implementation is narrow. Confirm the link, compare relevant employment context, and ask about any material difference. Do not build a screening model around profile photographs, network size, posting activity, inferred demographic data, or other weak proxies for identity and ability.

Privacy, dignity, and discrimination risk

For EU hiring, the GDPR’s principles in Article 5 provide a practical design test: collect data for a defined purpose, keep it relevant and limited, protect it, and do not retain it longer than necessary. If facial or other biometric data are processed to uniquely identify a person, the additional restrictions in Article 9 may be relevant. The legal basis and safeguards should be assessed for the specific workflow before it goes live.

In the United States and elsewhere, employment, privacy, accessibility, and biometric rules vary by jurisdiction. The operational lesson still travels well: explain the purpose before collecting sensitive data, give candidates a contact point and an accessible alternative, restrict access, and document why a check is appropriate for the role. Legal and privacy teams should validate the local design rather than treating a global template as automatically sufficient.

ID mandates carry a fairness risk when they are applied inconsistently or become a proxy for nationality, race, disability, age, language, or other protected characteristics. A role-based rule is safer than interviewer discretion: define the risk category, the check, the timing, the retention period, and the alternative path in advance. The process should test claims that matter to the job, not create new barriers for people who are already less able to navigate document-heavy systems.

What technology can and cannot do

Technology can organise the journey, collect a confirmation, structure questions, and route an applicant to the next appropriate step. Atlas Apply combines candidate portal steps, forms, document upload, chat or voice interviews, and LinkedIn profile confirmation so teams can collect context progressively. It is not a promise that a profile confirmation or an interview technology can conclusively detect every deepfake, proxy, or false identity.

That limit should be part of the policy, not hidden in the fine print. Deepfake detection can be wrong; an interview may have innocent technical irregularities; a document check can validate a document without proving who is operating behind a screen. No single signal should decide an adverse hiring outcome. A separate review, a chance to clarify, and a human decision are safeguards for both candidates and employers.

When selecting systems, focus on the workflow rather than a marketing claim of certainty. The overview of AI CV-screening tools can help frame which stage a tool supports. The governance question remains yours: what decision may this signal influence, what evidence must corroborate it, and who is accountable for the final call?

A concise operating policy for hiring teams

Publish a short, role-based policy before a problem occurs. State that the team may ask candidates to confirm professional context, explain that formal identity verification is reserved for defined later stages, and identify the teams that own security, privacy, and accessibility decisions. Train interviewers to record observable inconsistencies, not labels such as suspicious or inauthentic.

Then make escalation predictable. A mismatch across relevant sources leads to a clarifying question. An unresolved, material mismatch for a sensitive role leads to the defined later-stage check. A flag from a tool leads to human review, never an automatic rejection. This is a small process change, but it makes identity checking more consistent, auditable, and humane.

FAQ: identity checks and fake candidates

Should every remote applicant provide a government ID?

No. Requiring ID at application stage is often disproportionate to the decision being made and can create unnecessary privacy and accessibility barriers. Reserve formal documentation for a clear, later-stage need that is defined by the role and applicable law.

Can a LinkedIn profile prove a candidate is genuine?

No. It can link the application to an additional professional context and support a useful consistency conversation. It cannot prove the identity of the person in an interview or independently verify every career claim.

What should an interviewer do when a deepfake or proxy is suspected?

Do not accuse the candidate on the basis of a single signal. Note the concrete inconsistency, use a comparable follow-up conversation with role-relevant questions, and follow the documented escalation path for sensitive roles.

Can an AI flag automatically disqualify a candidate?

It should not be the final decision. Automated signals can be inaccurate, incomplete, or biased by context. Use them to prompt a fair human review and give the candidate a meaningful chance to clarify material issues.

How do we protect the process without discouraging genuine applicants?

Be transparent about what is checked, why it is checked, and when it occurs. Keep early checks lightweight, offer accessible alternatives, and collect sensitive evidence only when it is necessary. Trust increases when security controls are both understandable and proportionate.

Jürgen Ulbrich

CEO & Co-Founder of Sprad

Jürgen Ulbrich has more than a decade of experience in developing and leading high-performing teams and companies. As an expert in employee referral programs as well as feedback and performance processes, Jürgen has helped over 100 organizations optimize their talent acquisition and development strategies.

Free Templates &Downloads

Become part of the community in just 26 seconds and get free access to over 100 resources, templates, and guides.

No items found.

The People Powered HR Community is for HR professionals who put people at the center of their HR and recruiting work. Together, let’s turn our shared conviction into a movement that transforms the world of HR.

Similar Posts