Liveness Detection for KYC: Prevent Identity Fraud During Digital Onboarding
A printed photo or a R250 deepfake kit can beat a static selfie. If your biometric onboarding cannot prove a live person is present, presentation attacks will keep opening accounts in someone else's name.
We layer ISO-aligned liveness detection into the KYC journey you already run.

Sound Familiar?
These are the exact issues fraud and compliance leads bring us before we add presentation attack detection:
- Applicants pass KYC with a printed photo or phone screen replay of someone else's face
- Static selfie checks have no defence against deepfake video or injection attacks
- Fraud teams discover spoofed accounts weeks later, after credit or payouts have gone out
- Active challenge flows (blink, turn head) frustrate genuine clients and drive abandonment
- Compliance cannot show ISO/IEC 30107 PAD evidence when examiners ask how you stop presentation attacks
Deepfake injection attacks surged 783% from 2023 to 2024, and a successful fraudulent account opening can return R33,000 to R830,000+ against a kit that costs a few hundred rand. Static selfie KYC is no longer a control; it is an invitation.
What Liveness Detection Actually Does in Onboarding
Applicant starts KYC → PAD challenge runs → spoof fails or live person passes → CRM gets the evidence.
Document + Selfie Captured
Applicant uploads ID and a selfie inside your existing onboarding funnel
Liveness / PAD Check
Passive analysis or active video challenge confirms a real person is present
Risk Escalation
High-risk signals trigger stronger challenges or human review before approval
Evidence Written Back
Pass/fail, attempt logs, and provider artefacts land in CRM for FICA packs
Everything You Need for Identity Fraud Prevention at Onboarding
Passive Liveness Layer
Analyse a single selfie or short video in the background. No blink-or-turn prompts for low-risk applicants, so completion stays high.
Active Motion Challenges
Escalate high-risk sessions to randomised head turns, blinks, or video challenges that defeat replay and printed-photo spoofs.
ISO 30107 PAD Alignment
Select providers and configurations tested to ISO/IEC 30107-3 Levels 1–3, with APCER and BPCER thresholds your risk committee can defend.
Deepfake & Injection Defence
Layer camera integrity, virtual-camera detection, and PAD so synthetic faces and stream-injection attacks fail before the account opens.
CRM & Core Write-Back
Liveness pass/fail, attempt count, and provider evidence sync into your CRM or core banking system with an audit trail for FICA packs.
Provider-Agnostic Wiring
We integrate Onfido, Sumsub, Didit, FaceTec, and similar PAD-capable stacks into your existing onboarding, not a rip-and-replace.
PAD Providers We've Wired into Onboarding
From Photo Spoofs to PAD-Grade Onboarding
How a digital lender stopped presentation attacks without crushing genuine applicant completion.
Static Selfie KYC
- Selfie-to-ID match only; no dedicated liveness or anti-spoofing step
- Fraud ops found printed-photo and screen-replay accounts after first drawdowns
- Active blink-and-turn pilot abandoned ~37% of genuine applicants
- No ISO/IEC 30107 PAD evidence for examiners or the board risk committee
- Each synthetic account risked R33,000+ in first-cycle credit loss
Passive-First Liveness Layer
- Passive PAD on every selfie; active video challenge only on high-risk signals
- Print, replay, and basic deepfake spoofs fail before the account is opened
- Genuine completion back above 99% with sub-second passive checks
- Provider APCER/BPCER reports filed into the FICA evidence pack
- CRM stores pass/fail, attempt count, and session artefacts for audit
Before vs After Liveness Detection
How It Works
From threat review to live anti-spoofing in 3–6 weeks.
Map Your Threat Model
Current selfie KYC gaps, presentation-attack history, and which ISO 30107 PAD level your risk appetite requires.
Provider & Flow Design
Choose passive-first vs hybrid challenges, risk triggers for escalation, and how results write back to CRM or core.
Build & Parallel Test
Wire the SDK or API into your journey, run spoof and bona fide test packs, and tune abandonment vs security.
Go Live & Monitor
Ship with APCER/BPCER dashboards, fraud-ops alerts on fail clusters, and examiner-ready evidence packs.
Frequently Asked Questions
What is liveness detection and how is it different from facial recognition?
Facial recognition asks "does this face match the ID?". Liveness detection (presentation attack detection) asks "is a real, live person in front of the camera right now?". You need both for biometric onboarding: match the face to the document, then prove the submission is not a photo, replay, mask, or deepfake.
Should we use passive or active liveness?
Most regulated onboarding flows do best with passive liveness as the default and active motion challenges only when risk scores rise. Innovatrics field data showed active checks completing for about 63% of users in 13 seconds, versus 99.9% completion in about one second with passive. ID R&D reported completion rising from roughly 60% to over 95% after a similar switch, without degrading spoof detection.
What is ISO/IEC 30107 and why does PAD Level matter?
ISO/IEC 30107-3 is the standard for testing presentation attack detection. Level 1 covers print and screen replay attacks. Level 2 adds medium-complexity 3D masks (typical target APCER ≤1%). Level 3 covers advanced, high-fidelity instruments. We help you pick a provider and operating threshold that matches your fraud loss appetite and examiner expectations.
Can you add liveness to our existing KYC stack?
Yes. This is a capability layer, not a vendor replacement. We integrate PAD from providers such as Onfido, Sumsub, Didit, FaceTec, and others into the onboarding journey you already run, including document capture and selfie-to-ID match steps.
Will liveness detection hurt conversion?
Poorly designed active-only flows can. A tuned passive-first design usually improves conversion because genuine applicants finish faster and fraudsters fail earlier. We measure abandonment and spoof rates in parallel testing before you switch off the old path.
How much does a liveness integration cost?
Provider SDK wiring into an existing journey typically starts from around R25,000. Full hybrid PAD with risk-based escalation, CRM write-back, and examiner evidence packs usually sits between R40,000 and R90,000. Against even a handful of blocked synthetic accounts (each potentially worth R33,000 to R830,000+ in fraud loss), payback is measured in weeks, not years.
Stop Relying on Static Selfie KYC
If a printed photo or a cheap deepfake can open an account on your platform, your biometric onboarding is incomplete. Liveness detection closes that gap without forcing every genuine client through a friction gauntlet.
Tell us which KYC stack you run today, where spoofs are getting through, and what PAD level your risk committee expects. We will show you how to layer Onfido, Sumsub, Didit, or another provider into the journey you already have.