Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What happens when identity verification is attempted without…
Identity Beyond IAM

What happens when identity verification is attempted without liveness checks and capture integrity controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Without those controls, a fraudster can present a printed deepfake, replay a synthetic image on another device, or inject previously generated media through a virtual camera. If the system only checks that an image was provided, rather than whether it came from a live capture, the attacker may pass as a legitimate user and bypass onboarding or account recovery controls.

Why the control gap matters

When capture integrity is missing, the verification step is no longer testing whether the person is physically present, only whether some image-like content can satisfy the checker. That weakens onboarding and recovery flows because attackers can reuse pre-made media, synthetic faces, or replayed captures to impersonate a real applicant without needing the live subject in front of the camera.

The practical failure is not just “bad photo accepted”, it is that the system confuses presentation of evidence with evidence of presence. A robust verifier has to distinguish live capture from stored, replayed, or injected media, otherwise fraud can be scaled with automation and reused artefacts.

How attacks typically succeed

Attackers usually exploit the gap by choosing the lowest-friction path that still satisfies the checks the platform actually performs. That may include showing a printed image to the camera, replaying a deepfake or synthetic face on a second device, or routing pre-recorded media through a virtual camera so the application sees a valid stream.

Once the workflow accepts “an image was provided” as sufficient proof, the attacker can often move past identity proofing, account recovery, or first-time enrolment. The control failure is especially dangerous when downstream decisions trust the result as if it came from a live, human-present session.

For teams designing fraud-resistant verification, the relevant comparison is not image quality alone but capture authenticity. The challenge is to ensure the session includes signals that are hard to fake at scale, then treat any missing or suspicious signal as a reason to step up verification rather than silently continue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlIdentity verification gates access decisions and recovery flows.
Recommendation — Enforce stronger access gates when capture integrity is weak.
NIST SP 800-63IAL — Identity Assurance LevelThe question concerns assurance in identity proofing and verification.
Recommendation — Use higher assurance steps when live presence cannot be established.
CIS Controls v86 — Access Control ManagementVerification failures can bypass account recovery and enrolment access decisions.
Recommendation — Require stronger control checks before granting recovery or onboarding access.

Practitioner Guidance

What to verify: Confirm the verifier is checking for live capture signals, replay resistance, and injection resistance, not just face similarity or document readability. If the workflow cannot distinguish a camera feed from a virtual camera, assume it is vulnerable to media replay.

Decision rule: If the control only proves that an image or video frame was supplied, do not use it as a standalone gate for onboarding or account recovery. Route the case to a higher-assurance step when the session is high value, the user is high risk, or the captured signal looks artificially generated.

Common mistake: Teams often tune for lower false rejects and then remove the very checks that stop replay and injection abuse. That improves convenience for legitimate users, but it also makes the workflow easier to automate for fraudsters.

Practitioner takeaway: Treat live-capture assurance as a security control, not a cosmetic UX feature, because once that distinction is lost the verification flow becomes easy to spoof at scale.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org