Home › Identity verification (IDV) › Biometric Identity Verification: Liveness & Deepfakes

Biometric Identity Verification: Liveness & Deepfakes

IE By iGaming Expert Hub Editorial· Updated 2026-10-02·12 min read

Key takeaways

Biometric identity verification matches a live selfie or short video to the photo on a verified ID document, with liveness detection to prove a real person is in front of the camera. Liveness, tested under ISO/IEC 30107-3, catches photos, masks and screen replays; injection attacks skip the camera entirely and need separate injection attack detection, specified in CEN/TS 18099.

For casino and sportsbook operators, that distinction is a procurement issue. A deepfake injected straight into the data stream never meets the camera, so a vendor's presentation attack certificate says nothing about it. Below we map the attack types, the two standards and what the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), the Alcohol and Gaming Commission of Ontario and the UK Gambling Commission say about remote identity checks, then turn it into RFP questions.

What biometric identity verification is (and where it sits in iGaming KYC)

Biometrics is the measurement of physical or behavioural characteristics to recognise a person. In remote onboarding the usual modality is the face, but fingerprint and voice are also used in other settings. Biometric identity verification is the narrow use case where the system answers one question: is the person presenting this ID document the person pictured on it, and are they physically present right now?

In a typical online flow the player photographs a government-issued photo ID, the system checks its security features and extracts the data, then the player takes a selfie or short video. A facial recognition system compares the live face with the document portrait, and a liveness check judges whether a real, present human made the capture. The output is a match score, a liveness result and a decision that feeds your Know your customer (KYC) record.

1:1 face match vs identification

Verification is a 1:1 comparison: one live face against one claimed identity. Identification is 1:N: one face searched against a gallery of many people to find out who it is. The difference matters for privacy law, for error rates and, as covered below, for how the EU's Artificial Intelligence Act classifies the system. Onboarding a player is a verification problem. Searching a face against a database of known fraudsters or excluded players is an identification problem and should be scoped separately.

Onboarding, first withdrawal and step-up triggers

Operators rarely need a selfie at every login. The common placements are at registration (when the market requires identity to be validated before an account exists), at the first withdrawal, and as a step-up when risk changes, such as a new device, a large deposit or a screening hit. Because FINTRAC's casino guidance requires identity to be verified before any funds are disbursed, the first withdrawal is a natural hard stop if earlier checks were incomplete.

Biometric checks usually come bundled with document verification, so the vendor choice is part of your wider IDV stack. To shortlist, start with our guide to identity verification providers, which sets out vendor categories, pass-rate benchmarks and a pilot design. Our KYC providers guide puts document-plus-biometric checks at roughly $0.50 to $2.00 or more per check as of 2026, so where you place the selfie step affects cost as well as conversion.

Liveness detection: passive vs active in one minute

A liveness test is the control that separates a real person from a spoofing attack at the camera. Passive liveness analyses the captured image or video without asking the user to do anything, and may use natural signals such as blinking. Active liveness adds a challenge, such as turning the head or changing expression. Passive checks are lighter on the player; active checks give the system more signal but add friction. Both are aimed at the same threat: something fake held up to a real camera. The document side of the flow is covered in our guide to KYC ID verification documents.

Presentation attacks vs injection attacks

Every remote biometric flow has two places an attacker can interfere: in front of the camera, or between the camera and your server. Vendor content often blurs the two, which is how "certified liveness" ends up sold as deepfake protection.

Presentation attacks: photos, masks, screen replays

A presentation attack, a form of spoofing attack, puts an artefact in front of a genuine camera: a printed photo, a mask, or a phone or monitor replaying a video. A deepfake can be used this way too, played on a screen and filmed by the device. Liveness detection is designed for this class of attack, and it is the scope of presentation attack detection (PAD) testing.

Injection attacks: virtual cameras, emulators, replayed or generated video

An injection attack bypasses the physical camera. The attacker feeds pre-recorded or synthetic video into the capture pipeline using a virtual camera driver, an emulator, a hooked app or a manipulated web session. Nothing is presented to a lens, so camera-side liveness can pass a face that never existed. The Financial Crimes Enforcement Network described this pattern in its November 2024 deepfake alert, noting that some identity verification solutions may flag third-party webcam plugins used to display previously generated video instead of live video.

Attack typeEntry pointExamplesStandardControlAsk the vendor
Presentation attackIn front of a genuine cameraPrinted photo, mask, screen replay, deepfake played on a second deviceISO/IEC 30107-3 (PAD testing and reporting)Passive or active liveness detectionWhich lab tested PAD, against which attack types, on which product version?
Injection attackBetween camera and serverVirtual camera, emulator, hooked app, replayed or generated video streamCEN/TS 18099 (injection attack detection); ISO/IEC 25456 in developmentDevice and stream integrity checks, virtual-camera and emulator detection, server-side decisioningHas your injection attack detection been tested against CEN/TS 18099, and how do you detect virtual cameras on web and mobile?
Document attackThe ID itselfAltered or fabricated ID imageNot covered by either standard aboveDocument security-feature checks; NFC chip reading where availableDo you read and verify the chip server-side on supported documents?

Why a passing liveness score is not proof

A liveness score answers "does this look like a live face?" It does not answer "did these pixels come from this device's camera, just now?" An injected deepfake can pass the first and fail the second. A resilient flow therefore combines liveness with capture-path signals and makes the decision on the server, not the client.

The standards: ISO/IEC 30107-3 and CEN/TS 18099

Two documents frame vendor claims today; know what each covers before reading a certificate.

StandardScopeStatus/dateWhat it provesWhat it doesn't
ISO/IEC 30107-3Biometric presentation attack detection, Part 3: testing and reportingSecond edition 2023 (first edition 2017)That PAD was tested against attacks presented to the capture device, under a defined methodAnything about injection attacks, which fall outside its scope
CEN/TS 18099Biometric data injection attack detection: attack instruments, detection systems, test methodologyApproved by the European Committee for Standardization in October 2024That injection attack detection was evaluated against a defined methodologyPresentation attack performance or document authenticity
ISO/IEC 25456Matching ISO project on injection attack detectionIn development (check current status)Not yet applicable as a published standardCannot be cited as a completed certification

What a PAD certificate does and does not prove

A PAD conformance letter is not a regulator approval, and it does not cover injected media. Third-party lab programmes define their own levels and attack sets, so ask practical questions: which lab, which attack types, which product version and which platforms were tested, and when. A certificate for an older SDK version, or for mobile only when many of your players register on desktop web, is weaker evidence than it looks.

Injection attack detection and ISO/IEC 25456

CEN/TS 18099 is the first specification dedicated to injection attacks. It gives operators a common reference when asking whether a vendor detects virtual cameras, emulators and manipulated streams. ISO/IEC 25456 is the corresponding ISO project and is still in development, so treat any claim of "ISO/IEC 25456 certification" as a question to raise, not a fact to rely on.

What regulators expect from remote biometric checks

None of the regulators below mandates a particular biometric technology. They set the outcome and the timing, which decides where a selfie check sits in your flow. Timing detail is in our sibling guides; here we keep to the biometric implication. Treat it as orientation and check current rules with counsel.

RegulatorRule/guidanceRequirementImpact on biometric flow
FINTRAC (Canada)Government-issued photo ID method, non-face-to-faceAuthenticate the document with technology, then confirm the name and photo match the person, e.g. by live video chat comparison or a selfie compared to the ID photo using facial recognition technology. Only viewing a person and their ID over video conference is not enough.A document check plus selfie and face match fits the method; a manual video call alone does not.
FINTRAC (casinos)Casino client identificationVerify identity for every person for whom an account is opened before any funds are disbursed; verify for disbursements of $10,000 or more and receipt of $10,000 or more in cash or virtual currency.Biometric verification must be complete before the first payout; large transactions are a natural step-up trigger.
AGCO (Ontario)Registrar's Standards for Internet Gaming 3.01 and 3.04Under-19s are not eligible (except 18+ buying lottery tickets only). Player information, including name, date of birth, address and PCMLTFA information, must be complete, accurate and validated before a player account is created.Any selfie step used for validation runs at registration, not after first deposit.
UK Gambling CommissionSR code 3.2.11 and licence condition 17 (from 7 May 2019)Verify age before the customer can deposit, access free-to-play versions of gambling games, or gamble; verify name, address and date of birth before the customer is allowed to gamble.Biometric checks used for age or identity must finish before deposit or play.
FinCEN (US)Alert FIN-2024-Alert004, 13 November 2024Alert to financial institutions on deepfake fraud; SAR key term FIN-2024-DEEPFAKEFRAUD; red flags and suggested practices.Not a casino rule, but a useful list of injection and behaviour red flags for your fraud team.

Canada: FINTRAC and AGCO

FINTRAC's guidance on methods to verify the identity of persons and entities names a selfie compared to the ID photo using facial recognition technology as one way to match the person to an authenticated document. It also says that simply looking at someone and their ID over a video call is not enough, which rules out a manual video call as the only check for players in Canada, including the iGaming Ontario market.

UK Gambling Commission

Because age must be verified before deposit and identity before play, a "play now, selfie later" design does not work in the UK.

US: FinCEN's deepfake alert

FinCEN's alert FIN-2024-Alert004 is addressed to financial institutions, not casinos, and it does not set gambling rules. It is still worth reading for a biometric fraud team. Among account-level red flags it mentions payments to higher-risk payees such as gambling websites, which is a payment-pattern signal for banks rather than a requirement for operators. Its suggested practices include multi-factor authentication and live verification checks.

EU AI Act: verification vs identification

Some vendor content suggests that any biometric identity check is "high-risk AI" under the EU Artificial Intelligence Act. Annex III, point 1 lists remote biometric identification systems as high-risk, but excludes AI systems intended for biometric verification whose sole purpose is to confirm that a specific natural person is who they claim to be. A 1:1 onboarding selfie match generally sits on the verification side; a 1:N search against a watchlist of faces does not. Data protection law still applies, so confirm the classification of your use with counsel.

Building a resilient flow: fallbacks, NFC and manual review

No biometric check passes every genuine player first time, and no single control stops every attack. Aim for layered evidence: controlled capture in your own SDK, capture-path integrity checks, server-side decisions, and a staffed manual review queue for players who fail automation for innocent reasons.

Where a player holds an ID with an embedded chip, such as a biometric passport, reading the chip over NFC and verifying its data server-side gives a stronger defence against altered or fabricated documents than an image alone. Not every player has a compatible document or phone, so treat NFC as an upgrade path, not a requirement. For players who cannot complete a selfie, or for checks that are about age rather than identity, our guide to age verification methods covers alternatives such as facial age estimation.

Our KYC providers guide uses these healthy ranges: a first-attempt document pass rate of 80 to 92%, an automated decision rate of 85 to 95%, a median automated verification time under 60 seconds and manual review completed in under 4 hours. Treat them as pilot targets, not promises.

TriggerBiometric controlFallback
Registration in a market that requires validation before account creationDocument check plus selfie match and livenessSecond capture attempt with guidance, then manual review before the account is activated
First withdrawalSelfie re-match against the verified document portraitHold payout and route to manual review; request a fresh document if the original has expired
New device or changed communication method mid-checkFresh liveness capture with injection checksStep up to live review or an NFC chip read where supported
Casino disbursement or cash or virtual currency receipt of $10,000 or more (FINTRAC)Identity verification for the transaction (FINTRAC)Enhanced due diligence by the compliance team
Sanctions or PEP screening hitBiometric confirmation that the applicant is the document holderManual adjudication of the screening match

Questions to ask a biometric identity verification vendor

Use these in an RFP or a pilot scorecard. Ask for evidence, not adjectives.

Score the answers alongside price and pass rates from your pilot. To compare vendors that bundle document and biometric checks, use the RFP checklist and pilot design in our KYC providers guide.

Responsible gambling: Online gambling is for adults only: 19+ in Ontario and 18+ in most other regulated markets. Identity and age checks exist to keep minors and self-excluded players out, so design fallbacks that never let an unverified player gamble. If gambling stops being fun, use the deposit limits and self-exclusion tools offered by your operator or regulator.

Frequently asked questions

What is biometric identity verification in online gambling?

It is a remote check that matches a player's live selfie or video to the photo on a verified ID document, with liveness detection to confirm a real person is present. Operators use it at registration, at first withdrawal or as a step-up when risk changes, within each regulator's timing rules.

Can deepfakes bypass liveness detection?

They can when they are injected into the data stream rather than shown to the camera. Liveness detection is built for presentation attacks such as photos, masks and screen replays. Injection attacks through virtual cameras or emulators need separate injection attack detection, so a liveness result alone is not proof that a deepfake was stopped.

What is the difference between ISO/IEC 30107-3 and CEN/TS 18099?

ISO/IEC 30107-3 covers testing and reporting of presentation attack detection at the capture device; injection attacks are outside its scope. CEN/TS 18099, approved by the European Committee for Standardization in October 2024, covers biometric data injection attack detection. ISO/IEC 25456 is the matching ISO project, still in development.

Does FINTRAC accept selfie verification?

FINTRAC's government-issued photo ID method for non-face-to-face clients lets you authenticate the document with technology and then confirm the person matches the photo, for example with a selfie compared to the ID photo using facial recognition technology. Only viewing a person and their ID over video conference is not enough.

Is biometric verification high-risk under the EU AI Act?

Annex III lists remote biometric identification as high-risk but excludes systems whose sole purpose is to confirm a specific person is who they claim to be. A 1:1 onboarding selfie match generally falls under that verification exclusion. Confirm your specific configuration with counsel.

Authoritative referenceBeGambleAware — responsible gambling ↗

Compare independently vetted sites.

See reviews

18+ only. Gambling can be addictive — please play responsibly and only bet what you can afford to lose. If gambling is affecting you or someone you know, contact a local support service. This content is informational and never a guarantee of winnings.

Written and reviewed by the iGaming Expert Hub editorial team. Facts checked against primary sources; see the reference above.

← All articles