GAISSF / D7 / D7-CTL-H03

Out-Of-Band Authentication

Objective

Prevent wire fraud via voice deepfake.

Control / requirement

Independent channel verification + policy enforcement.

Business impact

Voice deepfake attacks have successfully authorized wire transfers of $25M+ (2024 multinational deepfake fraud case). Single-channel authentication is no longer sufficient.

Validation approach

Test ID: D7-CTL-H03-VTS-001 Test Type: Manual Test Design: Financial requests >$10,000, credential resets, vendor payment changes require independent channel verification Execution Steps: 1. Initiate test financial request >$10k 2. Attempt single-channel approval 3. Verify OOB requirement enforced 4. Check policy compliance Pass Criteria: single_channel_approval_blocked = True; independent_verification_required = True; policy_compliance_audited = True Independent Verification: Auditor tests OOB enforcement.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.