Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What happens when face verification is used without…
Identity Beyond IAM

What happens when face verification is used without presentation attack detection in e-KYC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Identity Beyond IAM

Without presentation attack detection, a biometric onboarding flow can mistake a spoof for a real customer and approve identity theft. That creates downstream risk in regulated onboarding, fraud screening, and account access because the system has no reliable way to distinguish a live person from a fabricated or manipulated sample. The result is weaker trust in the entire verification process.

Why Face Verification Without Spoof Detection Fails E-KYC

face verification only answers one narrow question: does this face match the claimed identity record? In e-KYC, that is not enough on its own because the onboarding channel also has to resist presentation attack such as printed photos, replayed video, masks, deepfake-assisted capture, or other manipulated inputs. Without presentation attack detection, the control can appear accurate while still accepting synthetic or stolen biometric evidence, which weakens the trust basis for customer due diligence and fraud controls. For regulated onboarding, that gap is often the difference between identity proofing and mere image comparison. One useful reference point is the FATF Recommendations — AML and KYC Framework, because e-KYC failures are not only technical defects but also customer-due-diligence weaknesses.

In practice, many security teams discover this gap only after a fraudulent onboarding review or an account takeover pattern has already exposed that the biometric step was never testing liveness or presentation integrity.

How the Verification Flow Breaks in Practice

Face verification and presentation attack detection solve different problems. The first compares the captured face against an enrolled or asserted identity. The second evaluates whether the captured sample is being presented by a live person in a trustworthy capture session. If PAD is missing, the system assumes the input is genuine and moves straight to matching, which means the strongest signal in the workflow may still come from an untrusted image source.

That matters because e-KYC is usually an evidence-stacking process, not a single-test decision. A strong design combines document checks, biometric comparison, device and session signals, fraud screening, and step-up review when confidence is low or the context looks abnormal. If face verification is treated as a stand-alone trust decision, the workflow can approve the wrong person even when the face match appears technically successful. That creates a false sense of assurance for onboarding operations, compliance teams, and downstream access provisioning.

Common failure modes include weak capture guidance, no sensor-level challenge, no replay resistance, and overreliance on a pass result from the biometric engine. In higher-risk journeys, the lack of PAD also makes the workflow easier to automate at scale, because attackers only need a workable sample of the target or a convincing fabricated face source. For identity assurance, the relevant question is not only whether the face matches, but whether the sample is trustworthy enough to be used as evidence.

Where this guidance breaks down is in low-risk consumer journeys that intentionally use a lighter trust threshold, because the organisation may be accepting convenience trade-offs rather than claiming strong identity proofing.

When the Exception Becomes the Rule

Tighter biometric onboarding often increases friction, so organisations have to balance user experience against the assurance level the decision actually requires. That trade-off becomes material when the same process is reused for regulated KYC, account recovery, or privileged access escalation, because a control that is acceptable for low-stakes re-engagement may be inadequate for identity proofing.

One important edge case is the difference between verification and proofing. Verification can be a useful component of e-KYC, but it does not by itself establish that the presenter is genuine, that the channel is live, or that the biometric source has not been manipulated. Another edge case is fallback logic: if failed face checks are silently routed to manual review, the organisation may still be exposed if reviewers are not given enough context to recognise spoof indicators or document mismatch patterns. There is also an industry consensus gap on how much PAD is required for every use case, because some deployments rely on risk-based combinations of controls rather than a single mandatory liveness method. That said, high-assurance onboarding should not treat a match result as equivalent to verified identity.

eIDAS 2.0 — EU Digital Identity Framework is useful here because it reinforces that identity assurance is a governance problem as much as a technology one. The practical limit is simple: once the process cannot distinguish a live claimant from a manipulated sample, the biometric result stops being trustworthy evidence.

Risk and Threat Considerations

Without presentation attack detection, e-KYC becomes vulnerable to presentation spoofing, replay, and synthetic-input abuse. The risk is not limited to a failed biometric check; it extends to identity fraud, weak customer due diligence, and downstream account abuse when onboarding decisions are based on an untrusted capture channel.

Failure mechanism: The workflow trusts the captured face as authentic before it has validated liveness or presentation integrity, so an attacker can use a photo, replayed video, mask, or manipulated capture to satisfy the matcher.

Impact: A false accept can create fraudulent accounts, weaken fraud screening, and contaminate the identity record that later supports authentication, access, or regulatory evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the technical controls, while EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access Controle-KYC face verification is an identity assurance control that affects trust before access decisions.
Recommendation — Strengthen identity assurance before granting account trust or access.
NIST SP 800-63IAL — Identity Assurance LevelFace verification without PAD weakens the assurance level of the proofing step.
AAL — Authenticator Assurance LevelWeak onboarding evidence can undermine later authentication trust decisions.
Recommendation — Raise the proofing assurance level when biometric evidence is the onboarding signal. Separate onboarding proofing strength from later authentication requirements.
CIS Controls v85 — Account ManagementFraudulent onboarding creates untrusted accounts that must be governed as access risk.
Recommendation — Tie onboarding assurance to account creation and exception handling.
EU AI ActArt. 9 — Risk Management SystemBiometric identity verification used in high-stakes onboarding needs documented risk controls.
Recommendation — Assess biometric onboarding risks and keep the mitigation evidence current.

Practitioner Guidance

What to prioritise: Treat PAD as part of the assurance decision, not as a cosmetic enhancement. If the journey supports regulated onboarding, account recovery, or high-value financial actions, a match-only design should be considered insufficient unless compensating controls materially reduce the residual risk.

What to verify: Confirm that the vendor or internal pipeline can detect replay and presentation manipulation under the actual capture conditions you use, including camera type, lighting, mobile devices, and remote onboarding paths. Also verify the fallback path, because manual review without clear spoof indicators often becomes a weak point rather than a safeguard.

Practitioner takeaway: The real control objective is not facial similarity, but trustworthy identity evidence; if that evidence can be fabricated, the onboarding decision is only as strong as the easiest spoof path.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org