Join our Newsletter — 33% off our NHI Course

How should security teams reduce identity fraud when document checks are not enough to prove a real person is present?

Security teams should add face matching and liveness detection to the KYC flow so the person can be verified against the identity document in real time. That closes a common gap in document-centric onboarding, where a valid ID and clean database record do not prove the applicant is the legitimate holder. The control works best when it is paired with clear consent, retention, and review processes.

How to Reduce Identity Fraud When Documents Alone Are Not Enough

When document checks can be forged or replayed, the practical question is no longer whether the ID looks valid, but whether the applicant is the same person who owns it. That is why real-time biometric comparison and liveness checks matter: they add a present-tense signal that a static document image cannot provide, especially in remote onboarding and high-risk account opening.

The control is strongest when it is built as part of an identity-proofing flow, not as a standalone biometric feature. A good implementation ties the face comparison to the document capture, the session, and the decision record so reviewers can tell whether the check was completed, rejected, overridden, or failed because of poor image quality, suspicious behavior, or a failed presentation test.

Security teams should also treat this as a fraud control with privacy obligations, not just a technical verification step. Consent capture, retention limits, escalation paths, and manual review criteria need to be defined before rollout so the process stays defensible when the biometric result is ambiguous or the applicant cannot complete the challenge on the first attempt.

Where Document Checks Break Down

Document-centric onboarding is vulnerable because an authentic-looking document does not prove the person behind the camera is genuine. A clean database record, a high-resolution scan, or an intact barcode can still coexist with impersonation, synthetic identity abuse, replayed media, or deepfake-assisted enrollment. The gap is not document validity, it is person presence.

That gap becomes more material when onboarding is fully remote, when the account can move quickly into payment, credit, or privileged access, or when downstream recovery processes are weak. At that point, the fraud event is often not the first login, but the later exploitation of a successfully opened account, which makes the original proofing decision even more important.

Teams should therefore separate three decisions: the document is real, the document belongs to the applicant, and the applicant is physically present for the check. If those three are collapsed into one pass/fail outcome, attackers only need to satisfy the easiest part of the flow.

Designing a Stronger Proofing Flow

A stronger flow combines document authentication, face match, and liveness detection with risk-based fallback. The goal is not to force biometric use everywhere, but to use it where the fraud impact justifies the added friction and where the identity evidence needs a live-present signal.

That flow should include clear failure handling. Poor lighting, camera limitations, accessibility needs, and false rejects are operational realities, so teams need a documented path for retry, step-up verification, or manual adjudication. For higher-risk cases, the review path should require more than a second look at the image, it should verify the consistency of the session, device, and enrollment evidence.

For broader guidance on proofing controls and onboarding fraud patterns, see Identity Proofing and KYC Guide and Identity Fraud Prevention Guide. NIST’s Digital Identity Guidelines are also useful for understanding how assurance, proofing, and authenticator strength fit together in a controlled enrollment process.

Risk and Threat Considerations

When document checks are used alone, the main exposure is impersonation at the point of onboarding. Attackers can combine stolen or synthetic documents with replayed images, injected video, or deepfake content to satisfy a weak verification step and gain access to accounts, financial services, or recovery channels.

Failure mechanism: The workflow proves document authenticity but not live presence, so a counterfeit or stolen identity can pass if the control does not test the person behind the document in real time.

Impact: False acceptance can create fraudulent accounts, downstream account takeover, and costly remediation, especially where onboarding decisions are trusted by later automated processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Identity proofing, face match, and liveness are core to assurance in onboarding.
Recommendation — Apply NIST identity assurance guidance to separate document validation from live identity proofing.
OWASP Non-Human Identity Top 10 NHI-04 — Insecure Authentication Fraudulent onboarding exploits weak proofing and authentication controls.
NHI-02 — Secret Leakage Identity fraud often follows exposure or misuse of identity materials and enrollment data.
Recommendation — Use stronger authentication and proofing controls to stop forged or replayed enrollment sessions. Protect enrollment data and identity evidence from leakage that can support impersonation.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Customer onboarding is an external-user identity proofing and authentication problem.
IA-5 — Authenticator Management Enrollment flows rely on handling and lifecycle controls for authenticators and proofing evidence.
Recommendation — Require stronger identity proofing and authentication for non-organizational users during onboarding. Manage authenticator lifecycle and enrollment evidence so fraud cannot reuse weak proofing artifacts.
ISO/IEC 27001:2022 A.5.15 — Access control Identity proofing protects access decisions at account opening and recovery.
Recommendation — Tie onboarding decisions to documented access-control requirements and review exceptions.
OWASP ASVS V6 — Authentication Face match and liveness strengthen the authentication step in remote onboarding flows.
Recommendation — Require strong authentication evidence before trusting an enrolled account.

Practitioner Guidance

What to prioritise: Put the highest assurance checks on the highest-risk onboarding journeys, especially where the account can move quickly into funds movement, recovery, or privileged actions. If the business impact is low, a lighter proofing path may be acceptable, but do not assume document quality alone is sufficient.

What to verify: Make sure the biometric result is bound to the same session as the document capture and that reviewers can see the evidence trail for retries, overrides, and exceptions. If you cannot reconstruct how the decision was made, you do not have an auditable control.

Common mistake: Teams often add face matching but leave liveness as an optional or weakly tuned add-on. That gives a false sense of control because the system still may not distinguish a real applicant from replayed media, injection attacks, or presentation attacks.

Practitioner takeaway: The control objective is not to “collect more identity data”, it is to raise assurance that the applicant is physically present and legitimately tied to the document before the account becomes trusted.