CEI Bite-Sized Learning: Bite-Sized Learning Module: AI Deepfakes and Fraud: A Board-Level Risk for Clubs

Why This Matters

Cybercrime in Australia continues to grow, with reports Cybercrime lodged every seven minutes and cyber criminals increasingly using AI-generated deepfakes, cloned voices and impersonation scams. The AICD warns that Boards should stop relying on generic cyber security assurances and instead challenge management on specific controls and preparedness measures.

What Is a Deepfake?

A deepfake is AI-generated content that imitates a real person.

This could include:

  • A video appearing to show your CEO requesting an urgent payment
  • A phone call using a cloned voice that sounds exactly like the club chair
  • An email written in the style of a trusted executive
  • A fake video meeting involving realistic-looking executives or Board members.

The challenge is that these communications can appear genuine, making it increasingly difficult for employees to distinguish between legitimate requests and fraud.

Real-World Example

The Australian Cyber Security Centre has highlighted an incident where cyber criminals used AI-generated deepfakes during a video conference to impersonate senior executives. Although the employee initially suspected a scam, seeing familiar faces and hearing familiar voices convinced them the request was genuine. The employee authorised the transfer of millions of dollars to the attackers.

Key Lesson:

  • Seeing and hearing someone is no longer proof of identity
  • Verification processes must be stronger than trust alone.

Guidance for Boards

The AICD recommends that Boards take a more active role in understanding and overseeing cyber risks, including AI-enabled fraud.

  1. Strengthen Verification Processes
    Any financial approval process should require independent verification, regardless of who is making the request.
  2. Remove Executive Exceptions
    Verification controls should apply equally to everyone, including CEOs, chairs and directors.
  3. Move Beyond Compliance
    Cyber risk management should not be treated as a “tick-the-box” exercise. Boards need confidence that controls work in practice.
  4. Conduct Regular Simulations
    Organisations should test their ability to respond to cyber incidents, including deepfake and social engineering attacks.
  5. Continuously Review Emerging Threats
    AI-driven threats are evolving rapidly. Boards should regularly review their cyber resilience and challenge management about emerging risks.

Five Questions Club Boards Should Ask Their CEO Based on the AICD Guidance:

  1. How do we independently verify payment requests and financial approvals to include cyber risks?
  2. What processes are in place to verify the identity of executives, directors, suppliers and contractors?
  3. Have we tested our response to an AI-generated fraud or deepfake attack?
  4. Which areas of our club are most vulnerable to deepfake-enabled fraud?
  5. How do we know our people can recognise and respond to AI-enabled scams?

Source: Australian Institute of Company Directors (AICD), 5 Questions Directors Should Ask CEOs About AI Fraud and Deepfakes.

Key Takeaway

AI has made fraud more convincing than ever. Boards can no longer rely on seeing a face, hearing a voice or receiving an email as proof of legitimacy.

The strongest defence is a combination of robust verification processes, ongoing staff education, regular testing and active Board oversight.

CEI seminars give you more than theory. We will cover Regulator ready board minutes and resolutions and Balancing Compliance and Strategy: Strengthening Both, Not Choosing Between Them. Register now for the next CEI seminar.

Upcoming Courses:

Face-to-Face Training

For more information regarding our upcoming scheduled mandatory training and AICD course schedule for 2026-2027, please click here

ClubSafe Virtual Training

Advanced Responsible Conduct of Gambling

Mandatory training for staff to become Responsible Gambling Officers (RGOs).

View course details

Responsible Gambling Board Oversight

Builds the knowledge and skills Responsible Gambling Officers need to support player welfare and promote responsible gambling practices.

View course details

AML/CTF Compliance Officer

Essential training for AML/CTF Compliance Officers in registered clubs.

View course details

AML/CTF Board & Senior Management Oversight

Provides directors and senior leaders with AML/CTF governance oversight responsibilities under Australia’s AML/CTF framework and 2026 reforms.

View course details

Enrolling in a ClubSafe course

To register, enrol here.
If you are a ClubSafe Premium member, click here.

Need Support?

ClubAssist is available to help directors and CEOs navigate governance challenges and strengthen board effectiveness.

Call 1300 730 001 or email enquiries@clubsnsw.com.au.