Add them when the business issue is proving that the user has a real document in hand, not just a readable image. That matters most in regulated onboarding, higher-risk account opening, and recovery flows where a false identity would create downstream trust and compliance problems.
When liveness checks solve the right onboarding problem
Liveness-style checks are useful when the onboarding decision depends on whether a person is physically present and actively presenting a genuine document or credential, rather than submitting a replayed image, screen capture, or deepfake-assisted sample. That is a narrower problem than general identity verification, and teams often overuse it when a simpler document or database check would be enough. In regulated onboarding, fraud-sensitive account opening, and recovery workflows, the control can reduce false acceptance, but it also raises friction and can create failure modes for legitimate users with poor cameras, accessibility constraints, or unstable capture conditions. FATF Recommendations — AML and KYC Framework sets the broader compliance context for high-risk onboarding where stronger identity assurance may be justified. In practice, many teams discover they needed stronger proof-of-presence only after synthetic or replay-based enrolment has already reached an account-opening decision.
How teams should think about adding liveness or hologram-style checks
The right trigger is not “we want more security” in the abstract. The trigger is that the onboarding step is making a trust decision that would be costly to reverse if the applicant were fake, impersonated, or using a tampered credential. Hologram checks, motion prompts, and similar challenge-response steps are best understood as anti-spoofing measures: they aim to detect whether the source is a live capture of a real person and document, not a copied artefact. They do not prove legal identity on their own, and they do not replace policy-based identity proofing, sanctions screening, or manual review where those are required.
In practice, teams usually get the most value when they apply these checks selectively. Common examples include higher-risk new account opening, step-up re-verification after suspicious activity, and recovery journeys where an attacker might otherwise use stolen biographical data plus a synthetic image to take over the process. The added step can materially improve assurance, but only if the downstream workflow uses the signal correctly. If a liveness failure merely creates another retry loop with no escalation path, the control becomes noisy rather than protective.
- Use the check when the main risk is spoofing a face-to-camera or document-presentment step.
- Do not use it as a substitute for verifying identity evidence quality, document authenticity, or policy eligibility.
- Treat repeated capture failures as a decision point, not just a UX problem, because they can reflect attack attempts or genuine accessibility issues.
- Make sure the organisation knows who can override the result and under what evidence threshold.
Where this guidance breaks down is in low-risk onboarding flows, offline enrolment, or cases where the trust decision depends more on authoritative records than on presentation challenge.
Where liveness checks add assurance, and where they add friction
Tighter capture controls often increase abandonment and support burden, so organisations have to balance fraud resistance against user completion rates and accessibility. That tradeoff becomes most visible when the population includes older devices, low bandwidth, assistive technology users, or applicants who cannot easily complete repeated facial or document prompts. The same is true for hologram checks: they are only useful when the document type actually contains a reliable feature to inspect and the capture process can expose it consistently.
There is also a genuine operational variation problem. Some teams use “liveness” to mean active facial challenge response, while others mean document anti-spoofing, and some combine both in one vendor journey. Those are not interchangeable. A facial liveness step may help against presentation attacks, but it does little if the core concern is forged identity documentation. Conversely, a hologram or security-feature check can strengthen document review, but it does not solve impersonation if the wrong person is presenting a genuine document.
Guidance vs consensus: there is broad agreement that stronger checks belong in higher-risk onboarding, but there is not universal consensus on the best technical mix, the right threshold for step-up, or how much friction is acceptable. The decision should follow the business consequence of false acceptance, not vendor default settings.
Risk and Threat Considerations
The material risk is false acceptance during identity proofing, especially where an attacker can combine stolen personal data with synthetic images, replayed captures, or a manipulated document presentation. The control matters because onboarding is often the point where an organisation grants a new trust relationship, and a mistake there can persist into account takeover, fraud loss, or compliance exposure.
Failure mechanism: Attackers exploit weak capture assurance by feeding the process a static image, screen replay, injected media, or another form of presentation attack that looks legitimate to a basic photo or document check. If the workflow does not distinguish live presentation from copied content, the control boundary is bypassed at the point where confidence should be highest.
Impact: A false identity can be issued an account, accepted into a regulated service, or used to initiate recovery, which creates downstream trust contamination, fraud cost, and remediation overhead. In some workflows, the damage is not immediate compromise but the creation of an identity record that is hard to unwind later.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, CIS Controls v8, MITRE-ATTACK and NIST IR 8596 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL-2 | Liveness checks support higher-assurance identity proofing during onboarding. |
| Recommendation: Stronger evidence and verification are appropriate when onboarding risk justifies higher identity assurance. | ||
| NIST CSF 2.0 | ID.RA-1 | The question concerns onboarding exposure to spoofing and false acceptance risk. |
| Recommendation: Identity proofing controls should reflect the fraud and trust risk of the onboarding flow. | ||
| CIS Controls v8 | 5.1 | Onboarding controls affect whether new accounts are legitimately created and tracked. |
| Recommendation: Account creation should be governed so fraudulent enrolments do not enter the environment unchecked. | ||
| MITRE-ATTACK | T1589 | The scenario involves adversaries using identity data to bypass onboarding checks. |
| Recommendation: Attackers may combine stolen identity data with replay or spoofing to pass enrolment. | ||
| NIST IR 8596 | IDENTITY-RELATED FRAUD | False onboarding identities create incident and remediation obligations when fraud is suspected. |
| Recommendation: Strong enrolment evidence helps contain identity fraud and simplifies later investigation and recovery. | ||
Practitioner Guidance
What to prioritise: decide whether the onboarding step is a proof-of-presence problem or a proof-of-identity problem. If the main concern is spoofing a live interaction, liveness-style controls are relevant; if the real issue is document validity or policy eligibility, other checks need to carry more weight.
What to verify: verify what the control actually detects, because many failures come from assuming all anti-spoofing checks cover the same threat. Teams should be able to show which onboarding path uses which signal, what happens on failure, and when a human review is triggered.
Decision rule: add stronger capture checks when false acceptance would create lasting trust, fraud, or compliance consequences. Keep them light or optional when the cost of friction exceeds the harm of a low-value onboarding failure.
Practitioner takeaway: the right threshold is not technical sophistication, but whether the onboarding decision would be expensive or dangerous to reverse if the applicant were fake.
Related resources from NHI Mgmt Group
- How should security teams use liveness checks in high-risk identity journeys?
- How do liveness checks affect identity proofing under NIST-style assurance models?
- What do security teams get wrong about liveness detection in onboarding?
- How can identity teams tell whether liveness checks are actually working?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org