Compliance
Oct 8, 2026

Face Verification and Liveness Detection: How Selfie Checks Work

How face verification and liveness detection work: selfie checks, active vs passive liveness, ISO 30107-3 and iBeta testing, deepfakes and your biometric data.

Face Verification and Liveness Detection: How Selfie Checks Work

Face verification is the check that compares a live selfie with the photo on your ID document to confirm you are the person the document belongs to. Liveness detection is the step that makes this meaningful: it checks that the selfie comes from a real, present human in front of the camera, not a printed photo, a screen replay, a mask or a deepfake. Together they are what most people mean by "selfie verification" or "biometric verification" when opening an account at a crypto exchange, bank or fintech app.

This guide explains how the checks work, the difference between active and passive liveness, how vendors are tested against ISO/IEC 30107-3, why deepfakes and injection attacks are the current battleground, what privacy law says about your face data, and what to do if you keep failing the check.

What face verification is, and what it is not

Face verification is a one-to-one comparison: is this face the same person as that ID photo? It is different from face identification, which is a one-to-many search of a face against a database to find out who someone is. The distinction matters legally as well as technically. The EU AI Act lists remote biometric identification systems as high-risk in Annex III, but excludes biometric verification whose sole purpose is to confirm that a specific person is who they claim to be.

The terms overlap in everyday use:

  • Biometric verification is the umbrella term for confirming identity with a physical or behavioural trait. In online onboarding that is almost always the face.
  • Selfie verification describes the user experience: you take a selfie or a short video in the app.
  • Face matching is the comparison algorithm that produces a similarity score between the selfie and the document photo.
  • Liveness detection, known in the standards as presentation attack detection (PAD), checks that the face in front of the camera is real and present.

How a selfie verification check works

The exact flow depends on the vendor, but a typical online check runs in this order:

  1. Document capture. You photograph your passport, ID card or driving licence. The software reads the data, checks security features and extracts the portrait.
  2. Selfie or video capture. The app opens your front camera and guides you to frame your face, sometimes with prompts.
  3. Liveness detection. The software analyses the capture for signs of a spoof, such as paper texture, screen glare, mask edges or synthetic artefacts.
  4. Face match. If the capture is judged live, the face is compared with the document portrait and a similarity score is produced.
  5. Decision. Clear passes are approved automatically. Borderline results go to a human reviewer, and clear failures are rejected or sent back for another attempt.

Face verification is one layer of KYC, not the whole of it. The same onboarding usually includes document checks, sanctions and PEP screening, and sometimes proof of address. Our explainer on what KYC means in crypto covers the full process.

Active vs passive liveness detection

Liveness checks come in two broad styles, and many products combine them.

Active liveness asks you to do something: blink, smile, turn your head, follow a dot or read numbers aloud. The prompts are often randomised so a pre-recorded video cannot anticipate them. They add friction, and can be harder for some users with disabilities or old phones.

Passive liveness works in the background from a single image or short video, with no special action from you. It analyses cues such as texture, depth, lighting and reflections. It is faster, but relies entirely on the quality of the model.

In practice, vendors layer the two and add deepfake detection on top. iDenfy's biometric verification service, for example, describes active prompts, passive 3D depth and texture analysis, and a separate deepfake detection module running in the same flow. If you are choosing a provider, our comparison of crypto KYC software providers covers the wider market.

How liveness is tested: ISO/IEC 30107-3, iBeta and NIST

Because every vendor claims high accuracy, buyers look for independent testing. Three references come up repeatedly.

ISO/IEC 30107-3. The international standard for testing presentation attack detection is ISO/IEC 30107-3:2023, "Biometric presentation attack detection, Part 3: Testing and reporting". The current second edition was published in January 2023 and replaced the 2017 version. It sets principles and methods for assessing PAD, how to report results and a classification of known attack types. Its scope is important: it covers attacks at the capture device during presentation, meaning something held up to the camera. Other attacks are outside its scope.

iBeta PAD testing. iBeta is an independent test laboratory with NIST NVLAP accreditation that includes ISO 30107-3 in its scope. Its published test levels differ in how much time, expertise and money an attacker is assumed to have. Level 1 uses common materials costing up to $30 per artefact, and Level 2 uses more advanced artefacts such as masks, costing up to $300. iBeta states that its confirmation letters show conformance with the ISO 30107-3 test methodology for a specific product configuration; they are not a product certification. When a vendor says "iBeta Level 2", ask for the letter and check which product version and device it covers.

NIST FATE PAD. The US National Institute of Standards and Technology evaluated passive, software-based face PAD algorithms in NIST IR 8491, published in September 2023. It tested 82 algorithms from 45 developers and found that accuracy varied widely by algorithm and attack type. Photo print and replay attacks and some mask types were well detected by several developers, while other attack types produced high error rates for every implementation tested. Many algorithms did better on video than on a single still image.

Deepfakes and injection attacks

The scope notes above point to the biggest current gap. A presentation attack happens in front of the camera. An injection attack bypasses the camera altogether: the attacker feeds a pre-recorded or AI-generated video straight into the app's video stream, for example through a virtual camera, an emulator or a modified app. ISO/IEC 30107-3 treats attacks outside the capture-device presentation as out of scope, and the NIST report says it is silent on injection attacks. Passing a PAD test does not, on its own, show that a product resists injected deepfakes.

Regulators have noticed. In alert FIN-2024-Alert004 of 13 November 2024, the US Financial Crimes Enforcement Network said it had seen an increase since 2023 in suspicious activity reports describing deepfake media used in fraud, often to get past identity verification. Its red flags include:

  • a customer's photo that is internally inconsistent or does not fit their other details, such as their date of birth;
  • the use of a third-party webcam plugin during a live verification check;
  • repeated "technical glitches" or requests to switch communication method during a live check;
  • a photo or video flagged by deepfake detection software, or matching an online gallery of AI-generated faces;
  • geographic or device data that does not match the identity documents.

Defending against this takes more than a better face model: device and camera integrity checks, detection of virtual cameras and emulators, and comparison with other signals such as document data and device history. Deepfakes are also one of the tools behind synthetic identity fraud.

Privacy: what happens to your face data

In the EU, face data used for verification is among the most protected kinds of personal data. The GDPR defines biometric data in Article 4(14) as personal data from specific technical processing of a person's physical, physiological or behavioural characteristics that allows or confirms their unique identification, and gives facial images as an example. Article 9 prohibits processing biometric data to uniquely identify someone unless an exception applies, such as explicit consent or a substantial public interest grounded in law.

A platform should tell you who processes your selfie (often a verification vendor acting for the exchange), on what legal basis and for how long. AML law separately requires the exchange to keep due diligence records for years after the relationship ends, which may include images. Ask the platform, and read our guide to what happens to your KYC data for the retention rules.

Why crypto exchanges use face verification

Crypto exchanges onboard customers remotely, often across many countries, and AML rules require them to identify and verify those customers. A selfie with liveness detection is the most common way to tie a remote applicant to their ID document. It also deters account takeovers, money mules who sell their verified accounts, and fraudsters opening accounts with stolen or synthetic identities.

Non-custodial DeFi is different. JewelSwap's apps on MultiversX, Sui and Radix are non-custodial and do not run identity checks themselves; see KYC in DeFi explained.

Tips if you keep failing a selfie check

  • Light your face from the front. Avoid a window or lamp behind you, and avoid harsh shadows.
  • Remove hats, glasses and masks unless they appear in your ID photo, and keep hair off your face.
  • Use the device camera directly. Close virtual camera, filter or screen-sharing apps; they can trigger injection-attack detection.
  • Use a stable connection. Heavy video compression can look like a spoof to passive models.
  • Check the document photo. If your appearance has changed a lot, or the document is damaged or near expiry, ask support about manual review or using a different document.

Never use someone else's face or document, or tools to get around the check, even to "help": that is fraud. More practical advice is in our ID verification tips for crypto exchanges.

Frequently asked questions

What is the difference between face verification and face recognition?

Face verification is a one-to-one check that confirms a live face matches a specific ID photo. Face recognition or identification searches one face against many stored faces to find out who someone is. KYC onboarding uses verification.

What is liveness detection?

Liveness detection, or presentation attack detection, checks that a selfie comes from a real person present in front of the camera rather than a photo, screen replay, mask or deepfake. It runs before or alongside the face match.

What is the difference between active and passive liveness?

Active liveness asks you to perform actions such as blinking or turning your head. Passive liveness analyses a single image or short video in the background without any special action. Many products combine both and add deepfake detection.

What does ISO 30107-3 or iBeta Level 2 mean?

ISO/IEC 30107-3 is the international standard for testing presentation attack detection. iBeta is an accredited lab that tests products against it; Level 2 assumes a more skilled attacker with more expensive artefacts than Level 1. A letter shows conformance for a specific product configuration, not a general certification, and the standard itself does not cover injection attacks.

Why does my selfie verification keep failing?

Common causes are poor or back lighting, glasses or hats not in the ID photo, a shaky camera, a weak connection, virtual camera or filter apps, and a damaged or outdated document photo. If it still fails, ask support for a manual review.

Is my face data stored after verification?

Often, for a period. In the EU, biometric data is special-category data under the GDPR, and AML law requires platforms to keep due diligence records for years after the relationship ends. The platform's privacy notice should say who stores it, for how long and for what purpose.

Keep reading

This article is educational and is not legal or financial advice. Standards, test-lab and regulatory references were checked on 8 October 2026 against ISO, iBeta, NIST IR 8491, FinCEN alert FIN-2024-Alert004, the GDPR and the EU AI Act, linked inline. Vendors are mentioned for illustration, not as recommendations.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.