Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»Enterprise risk management»Canadian business leaders believe that AI deepfakes are increasing fraud risks (Page 4)
Enterprise risk management

Canadian business leaders believe that AI deepfakes are increasing fraud risks

March 15, 20244 Mins Read
fraud risk concept

In a KPMG in Canada research survey of 300 Canadian organizations that had been previously victimized by fraud, 95% of leaders said that they are very concerned that the threat of deepfakes has increased the risk of fraud at their companies. 91% are worried that generative AI will give criminals more opportunities to launch corporate misinformation and disinformation campaigns using deepfakes.

“Because fraud is rarely reported to the police, we wanted to speak to business owners and C-suite leaders across Canada to get a deeper understanding of how the evolving fraud landscape of new technology, a shifting economy, geopolitical tensions and remote work was giving perpetrators the opportunity, motivation and rationalization to commit fraud,” said Enzo Carlucci, National Forensic Leader at KPMG in Canada.

“Respondents overwhelmingly told us the fraud landscape is becoming more complex, with 95% saying generative AI and social engineering scams make it easier for fraudsters to deceive, manipulate, misrepresent and conceal their crime. As fraudsters are becoming increasingly sophisticated in their attack methods, it’s more and more challenging to deter criminals,” Mr. Carlucci continued. “Organizations need to find new ways to strengthen their anti-fraud programs and stay one step ahead of scammers, or else they could be facing increased financial, legal, regulatory and reputational risks.”

Other key points from the survey:

  • 84% worry that current economic conditions could potentially drive their employees or their customers to commit fraud out of desperation.
  • 87% say the shift to remote work increased the risk of fraud occurring within their company, due to a reduced ability to monitor and control for fraudulent behaviour.
  • 89% admit they had to ‘scramble or react quickly’ to implement a robust fraud detection and prevention program due to a fraud incident.
  • 43% victimized by fraud disclosed that they are currently experiencing a form of internal fraud, such as embezzlement, data or personally identifiable information (PII) theft, environmental, social and governance (ESG) fraud, or procurement fraud.
  • 33% victimized by fraud say they are currently dealing with an external fraud, such as payment fraud, synthetic identity (ID) fraud, a cyber attack, or social engineering campaigns (from intentional online deception to manipulating visual media and fabricating content or deepfakes)
  • 53% say that their company lost between 1-to-5% of their profits to fraud in the past 12 months, 35% lost up to 1%, and 7% suffered losses over 5%. Only 4% that were impacted by fraud didn’t suffer any loss.

The top causes of business fraud impacts

The most common types of external fraud schemes involve the use of manufactured or falsified information, often created or aided using technology. The top three scams reported by respondents include:

  • Payment fraud, where criminals use false or stolen payment information to make a purchase.
  • Misinformation or disinformation campaigns, such as malvertising or malicious advertising and deceptive editing (deepfakes) or missing content.
  • Account takeover or synthetic identity (ID) fraud, where fraudsters use fake personas to gain access to accounts.

The most common types of internal fraud that respondents reported were:

  • Embezzlement.
  • Exaggerating, distorting, or embellishing environmental, social and governance (ESG) data.
  • Theft of personally identifiable information (PII) or using PII to commit fraud.

The respondents said their company learned of the fraud primarily through internal audits, management reviews, whistleblowers and proactive monitoring.

The research finds that 77% of companies have a fraud detection program. However, only 39% call it ‘extremely effective’. When it comes to prevention, just over half (54%) say they have a fraud prevention program in place. Yet only 37% describe their anti-fraud policies and 38% describe their financial controls as ‘extremely effective’. Further, only 42% call their fraud risk assessment programs ‘extremely effective’.

Almost half (47%) say that they are actively using emerging technologies, such as AI, advanced data analytics, generative AI, automation and biometric verification to mitigate the risk of fraud.

“It’s encouraging to see organizations starting to use technology to deter fraud, but not enough of them are,” says Marilyn Abate, a partner in KPMG’s Forensic and Financial Crimes practice. “Companies need to use AI to fight AI. These tools are fast-becoming essentials in the fraud toolkit to prevent fraudsters from gaining the upper hand. But if you don’t perform regular fraud risk assessments to identify external and internal risks and vulnerabilities, you will always be at a disadvantage.”

More details
North America
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleAudit committees prioritize cyber security and enterprise risk management
Next Article Generative AI is reshaping the cyber threat landscape: Lloyd’s report

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A woman with blonde hair and a ponytail looking at colourful sticky notes on a wall.

The stories behind the organization: how cultural narratives shape resilience

August 7, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?