Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Liveness checks and digital identity verification: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Liveness detection is presented as a way to prove a real person is present during selfie-based identity and age verification, blocking presentation and injection attacks while reducing fraud, account takeover, and false rejections, according to Yoti. The core issue is that digital identity flows now depend on proving human presence at runtime, not just matching a face to a record.

NHIMG editorial — based on content published by Yoti: liveness checks and why they matter for digital identity

By the numbers:

Questions worth separating out

Q: How should security teams use liveness checks in high-risk identity journeys?

A: Security teams should reserve stronger liveness checks for account opening, recovery, and high-value transactions where impersonation would create material loss.

Q: Why do liveness checks matter more as identity moves online?

A: They matter because digital journeys remove face-to-face confirmation, which used to provide a basic reality check.

Q: What do organisations get wrong about inclusive biometrics?

A: They often assume that a vendor’s accuracy claim is enough.

Practitioner guidance

  • Test for both spoof classes Validate controls against presentation attacks and injection attacks separately, because each bypass path behaves differently in production journeys.
  • Define assurance thresholds before rollout Set acceptable false accept and false reject rates for onboarding, age verification, and recovery flows before exposing the process to customers.
  • Place liveness at the right trust boundary Use liveness where the workflow needs proof of real-time presence, especially in account opening, step-up verification, and age-gated access.

What's in the full article

Yoti's full article covers the operational detail this post intentionally leaves for the source:

  • The article walks through how passive liveness detection differs from active challenge-response in everyday verification journeys.
  • It explains the difference between presentation attacks and injection attacks in plain language.
  • It describes why benchmarked liveness performance matters for lower friction onboarding and age assurance.
  • It outlines the privacy-preserving model that confirms presence without retaining biometric data indefinitely.

👉 Read Yoti's article on how liveness checks work and why they matter →

Liveness checks and digital identity verification: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Liveness checks are a human identity assurance control, not a cosmetic anti-fraud feature. Their role is to prove presence at the point of verification, which means they sit inside the identity trust boundary rather than beside it. That matters because a face match without presence verification is only partial assurance. For practitioners, the control belongs in the same governance conversation as onboarding risk, recovery risk, and age assurance.

A few things that frame the scale:

  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how often identity control breaks down before teams can even detect misuse.

A question worth separating out:

Q: How can teams balance security and user experience in age verification?

A: Use the least intrusive liveness method that still meets the risk level of the journey. Passive methods reduce friction for most users, while stronger challenge-based methods may be justified for higher-risk flows. The key is to align assurance level, accessibility, and privacy expectations.

👉 Read our full editorial: Liveness checks are becoming the trust gate for digital identity



   
ReplyQuote
Share: