Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Age assurance and digital ID choice: what should IAM teams watch?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Its MyFace passive liveness model achieved 0% APCER and 0% BPCER at both ISO 30107-3 Level 1 and Level 2 in iBeta testing, according to Yoti, while its facial age estimation received a smaller German buffer and showed 0.6% false positives for 13 to 17 year olds. The governance question is no longer whether these controls work in isolation, but how identity programmes balance assurance, user friction and policy choice across verification routes.

NHIMG editorial — based on content published by Yoti: a blog on MyFace liveness, age assurance and digital ID choice

By the numbers:

  • Yoti says 60% of 18 year olds and 80% of 19 year olds pass an over-17.5 check, showing how threshold design changes user flow.

Questions worth separating out

Q: How should organisations balance age assurance accuracy with user friction?

A: Use a risk-based threshold model.

Q: Why do biometric verification systems need policy buffers?

A: Because model outputs are probabilistic, not absolute.

Q: How do security teams evaluate whether liveness detection is strong enough?

A: Look for measurable resistance to presentation attacks, defined false accept and false reject rates, and testing that reflects the real environment where the control will run.

Practitioner guidance

  • Define assurance thresholds by use case Set separate thresholds for age-restricted content, right-to-work checks and account recovery so that the same biometric or document control is not forced into one policy model.
  • Map approved proofing routes to policy outcomes List the identity proofing routes your organisation accepts, then tie each route to a specific outcome such as over-18 access, employment eligibility or account verification.
  • Test liveness and age controls against real user populations Validate model performance using the ages and scenarios you actually serve, not only lab benchmarks.

What's in the full article

Yoti's full blog post covers the operational detail this post intentionally leaves for the source:

  • iBeta testing results for MyFace passive liveness at Level 1 and Level 2, including APCER and BPCER performance
  • Detailed discussion of the German buffer change and the regulatory context behind the 3 year threshold
  • Expanded explanation of Australia’s age assurance discussions and the practical consequences for social media checks
  • The policy comparison between government digital ID, private-sector digital ID and physical documents in right-to-work flows

👉 Read Yoti’s analysis of liveness testing, age assurance and digital ID choice →

Age assurance and digital ID choice: what should IAM teams watch?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Age assurance is becoming a policy engine, not just a model test. The article shows that the real decision is how much confidence is required to gate access, not whether a biometric model can produce a score. That shifts age verification into the same governance territory as authentication assurance, where threshold selection, exception handling and evidence quality matter as much as model performance. Practitioners should treat age estimation as an identity control with explicit policy boundaries.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which helps explain why identity proofing and verification governance so often outruns operational visibility.

A question worth separating out:

Q: Who should be accountable when multiple digital ID routes are accepted?

A: The organisation that sets the acceptance policy remains accountable for how those routes are validated and documented. If government ID, private-sector ID and physical documents are all acceptable, teams must define equivalence, audit trails and escalation rules so the decision can be defended later.

👉 Read our full editorial: Digital identity verification now hinges on liveness, age checks and choice



   
ReplyQuote
Share: