They often signal that the capture path, the biometric threshold, or the attack mix is wrong for the journey. A weak PAD result points to spoof or replay exposure, while weak face matching can mean poor image quality, threshold drift, or an identity mismatch that needs review.
What poor PAD results are telling you
Poor presentation attack detection, or PAD, usually means the onboarding journey is exposing the wrong kind of signal to the verifier. The failure may be in the capture path, the spoof or replay mix, or the decision threshold, so the result should be read as a control-quality problem first, not just a user-quality problem.
A weak face-match result is similar, but the signal points more toward image quality, camera angle, lighting, or threshold drift. It can also indicate that the enrolled identity and the live capture are not close enough to trust without review, which is why weak biometric outcomes should be treated as evidence for investigation, not as a simple pass or fail.
Why these failures matter in onboarding
Onboarding is where the system learns whether the presented person is the right person, so weak PAD or face match performance directly affects trust in the enrollment outcome. If the capture flow is too noisy, too permissive, or too sensitive, the process can either admit spoofed activity or reject legitimate users who should have passed.
The practical issue is that these two checks protect different parts of the flow. PAD is about whether the presented sample is live and attack-resistant, while face match is about whether the sample plausibly belongs to the claimed person. When both degrade, the journey may be failing at the camera, the device, the model, or the policy settings that decide what counts as acceptable evidence.
For practitioners, that means the result should be interpreted against the exact onboarding step that failed. A poor PAD outcome can reflect a spoof attempt, but it can also reflect a capture configuration that cannot reliably distinguish a real face from a replayed image or virtual camera feed. A poor face-match outcome can reflect a true mismatch, but it can also come from low resolution, poor framing, or a threshold that no longer matches the population being onboarded.
What usually sits behind the bad result
The most common root causes are operational rather than mysterious. Image quality issues, unstable device conditions, and inconsistent capture paths are frequent causes of weak face-match performance, while replay, injection, or presentation attacks are the main reasons PAD results become unreliable. In some journeys, both problems appear together because the same capture pipeline is being asked to prove liveness and identity at the same time.
Threshold drift is another common pattern. If the match threshold is tuned too tightly, legitimate users will fail more often than expected. If it is too loose, the system may accept weak evidence that should have been reviewed. Good onboarding programs treat these thresholds as policy choices that need validation against the actual user population and device mix.
Risk and Threat Considerations
Poor PAD or face-match results are a warning that the onboarding control may no longer be aligned with the attack surface or the real-world capture conditions. That creates two risks: spoof or replay exposure if PAD is too weak, and false acceptance or unnecessary manual review if the face-match threshold or image quality is mis-set.
Failure mechanism: An attacker can exploit weak liveness detection, injected video, or poor capture controls to present a non-live or manipulated sample, while benign users can still fail because the model or threshold is not calibrated to the actual capture environment.
Impact: The organization may onboard the wrong person, create avoidable review workload, or develop blind spots about whether the biometric control is actually working in production.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST SP 800-63 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API8 — Security Misconfiguration | Bad PAD or face-match outcomes often reflect capture/configuration issues. |
| Recommendation — Harden capture and verification settings to reduce false accepts and false rejects. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Onboarding biometrics are part of user authentication assurance. |
| IA-5 — Authenticator Management | Biometric onboarding depends on correct credential and authenticator handling. | |
| Recommendation — Validate identity assurance before granting onboarding access. Manage authenticators and related enrollment inputs with strict lifecycle controls. | ||
| NIST SP 800-63 | Digital Identity Guidelines | The question concerns biometric identity proofing, liveness, and matching assurance. |
| Recommendation — Use assurance guidance to tune biometric proofing and verification decisions. | ||
| OWASP ASVS | V6 — Authentication | Biometric onboarding is an authentication-verification control, not just UX. |
| Recommendation — Verify authentication strength and failure handling for biometric journeys. | ||
Practitioner Guidance
What to verify: Check whether the failure is concentrated at one device type, one channel, or one capture step before assuming the biometric itself is broken. If PAD failures spike on a specific journey, inspect the capture path and attack mix first; if face-match failures are broad, review image quality, enrollment quality, and threshold settings.
Decision rule: Treat repeated PAD failures as a control-design issue and repeated face-match failures as a calibration or data-quality issue. If both are failing together, prioritize the capture pipeline and policy thresholds before escalating every case as an identity exception.
Practitioner takeaway: Poor biometric results are most useful when they point to the exact layer that failed, because the right fix is different for spoof resistance, capture quality, and matching policy.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org