Passive checks can leave more residual risk because they often rely on a single image and no deliberate user action. That makes them more convenient, but it also narrows the evidence available to the system. If the model or image quality is weak, a spoofed selfie, video, or manipulated image may be harder to distinguish from a real person.
Why Passive Liveness Checks Create Residual Risk
Passive liveness checks reduce friction, but they also reduce the amount of challenge-response evidence available to prove that a live person is present. When verification depends on a single frame or a short passive capture, the system has fewer signals to separate a genuine user from replayed media, deepfake content, screen replays, or image manipulation. That matters because remote identity verification is not just about matching a face, but about resisting presentation attacks under imperfect capture conditions.
The risk is amplified when organisations treat convenience as equivalent to assurance. A passive check may look strong in a demo yet still be brittle against camera quality issues, compression artefacts, poor lighting, or adversarial media that mimics expected appearance closely enough to satisfy the model. NHI Management Group research shows that identity failures often persist when organisations do not have full visibility into machine and credential controls, and the same blind spot appears here as a weak evidentiary model rather than a missing password.
In practice, teams often discover the weakness only after a fraudulent enrolment or account recovery event shows that the control confirmed resemblance, not presence.
How Passive Verification Works, and Where It Breaks
Passive liveness is usually embedded inside a remote onboarding or reauthentication flow. The user uploads a selfie or short video, and the system scores whether the media shows signs of a real person without asking the user to blink, turn, speak, or follow prompts. That lower-friction design can be valuable in high-drop-off journeys, but the assurance model is narrower because the evidence is largely observational rather than behavioural.
Security teams should think in terms of what the control can and cannot prove. Passive checks can help detect some spoofing patterns by looking for texture, depth, motion consistency, or camera artefacts, but they do not inherently prove intent, spontaneity, or resistance to high-quality synthetic media. If the capture source is already compromised, or if the verification pipeline accepts low-confidence matches too readily, the residual risk remains even when the interface reports success.
- A single capture gives the attacker fewer opportunities to fail under scrutiny, so replay media can be harder to distinguish from a live subject.
- Model performance depends heavily on capture quality, which means mobile devices, low bandwidth, and image compression can lower both security and usability at the same time.
- Passive checks often need compensating controls such as device binding, fraud analytics, step-up review, or document validation to close the assurance gap.
Current guidance from digital identity practice increasingly treats liveness as one signal inside a larger assurance stack, not as a standalone proof of personhood. For a broader control lens on identity assurance, the NIST Cybersecurity Framework 2.0 is useful for understanding how identity controls fit into a wider resilience model, while the eIDAS 2.0 EU Digital Identity Framework shows how assurance and trust services become part of regulated identity ecosystems. Passive liveness tends to break down when remote enrolment is high volume, attackers can iterate cheaply, and the verifier accepts low-friction paths without enough secondary evidence.
Common Variations and Edge Cases
Tighter liveness assurance often increases user friction, operational cost, and false rejections, so organisations must balance conversion against fraud resistance. That tradeoff is real, and the right answer depends on what the identity will be allowed to do after verification.
Not every use case needs the same level of resistance. A consumer account reset, a payroll change, and a regulated financial enrolment carry very different consequences, so the verification bar should rise with the impact of impersonation. Passive checks may be acceptable for low-risk interactions when paired with other signals, but they become a weaker choice when the outcome unlocks money movement, account recovery, or access to sensitive records.
Teams also need to account for edge cases that degrade passive scoring without necessarily indicating fraud. Poor lighting, accessibility needs, older devices, and network instability can all increase failure rates, which is why best practice is evolving toward risk-based orchestration rather than a single universal rule. Where there is no universal standard for this yet, the defensible approach is to reserve passive checks for lower-impact flows and add step-up controls when anomalies, high-value actions, or prior fraud indicators appear.
Practitioner takeaway: Passive liveness is best treated as a convenience layer with bounded assurance, not as a decisive proof of real presence. The more consequential the transaction, the more the verifier should demand additional evidence beyond a single passive capture.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL — Identity Assurance Level | Remote identity verification hinges on assurance strength and evidence quality. |
| Recommendation — Set the assurance level to match the consequence of impersonation. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Liveness checks are one part of identity assurance and access governance. |
| Recommendation — Combine liveness with layered identity controls and step-up verification. | ||
| CIS Controls v8 | 6 — Access Control Management | Weak verification can create unreliable access paths into sensitive systems. |
| Recommendation — Tighten access decisions when identity proof is low assurance. | ||
| MITRE ATT&CK | T1110 — Brute Force | Adversaries may iterate cheap verification attempts until one passes. |
| Recommendation — Monitor repeated verification attempts and throttle suspicious reuse. | ||
| EU AI Act | Article 9 — Risk Management System | AI-driven identity checks need documented risk controls and oversight. |
| Recommendation — Document liveness-check risks and review them as part of AI governance. | ||
Related resources from NHI Mgmt Group
- How should organisations evaluate passive liveness checks for identity verification at scale?
- How should security teams choose between passive, active, and hybrid liveness detection for remote identity verification?
- Why does mandatory video interviewing create risk for conversion in remote identity verification?
- Why do remote MCP servers create more identity governance risk than local ones?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org