Liveness Detection for KYC | Anti-Spoofing Biometric Onboarding | WebFootprint
Compliance Integrations Liveness Detection · Anti-Spoofing

Liveness Detection for KYC: Prevent Identity Fraud During Digital Onboarding

A printed photo or a R250 deepfake kit can beat a static selfie. If your biometric onboarding cannot prove a live person is present, presentation attacks will keep opening accounts in someone else's name.

We layer ISO-aligned liveness detection into the KYC journey you already run.

A CRM panel connected by a mint light ribbon of selfie and video challenge frames to a glossy Liveness badge, illustrating biometric anti-spoofing in onboarding
2,137%
rise in deepfake-based fraud since 2022; now 6.5% of all fraud attacks globally
300%+
surge in synthetic identity document fraud (Q1 2024 to Q1 2025)
~R250
cost of a complete AI-generated synthetic identity kit on dark-web markets
63% → 99%
completion lift when replacing active challenges with passive liveness
The Problem

Sound Familiar?

These are the exact issues fraud and compliance leads bring us before we add presentation attack detection:

  • Applicants pass KYC with a printed photo or phone screen replay of someone else's face
  • Static selfie checks have no defence against deepfake video or injection attacks
  • Fraud teams discover spoofed accounts weeks later, after credit or payouts have gone out
  • Active challenge flows (blink, turn head) frustrate genuine clients and drive abandonment
  • Compliance cannot show ISO/IEC 30107 PAD evidence when examiners ask how you stop presentation attacks

Deepfake injection attacks surged 783% from 2023 to 2024, and a successful fraudulent account opening can return R33,000 to R830,000+ against a kit that costs a few hundred rand. Static selfie KYC is no longer a control; it is an invitation.

How It Works

What Liveness Detection Actually Does in Onboarding

Applicant starts KYC → PAD challenge runs → spoof fails or live person passes → CRM gets the evidence.

1

Document + Selfie Captured

Applicant uploads ID and a selfie inside your existing onboarding funnel

2

Liveness / PAD Check

Passive analysis or active video challenge confirms a real person is present

3

Risk Escalation

High-risk signals trigger stronger challenges or human review before approval

4

Evidence Written Back

Pass/fail, attempt logs, and provider artefacts land in CRM for FICA packs

What We Build

Everything You Need for Identity Fraud Prevention at Onboarding

Passive Liveness Layer

Analyse a single selfie or short video in the background. No blink-or-turn prompts for low-risk applicants, so completion stays high.

Active Motion Challenges

Escalate high-risk sessions to randomised head turns, blinks, or video challenges that defeat replay and printed-photo spoofs.

ISO 30107 PAD Alignment

Select providers and configurations tested to ISO/IEC 30107-3 Levels 1–3, with APCER and BPCER thresholds your risk committee can defend.

Deepfake & Injection Defence

Layer camera integrity, virtual-camera detection, and PAD so synthetic faces and stream-injection attacks fail before the account opens.

CRM & Core Write-Back

Liveness pass/fail, attempt count, and provider evidence sync into your CRM or core banking system with an audit trail for FICA packs.

Provider-Agnostic Wiring

We integrate Onfido, Sumsub, Didit, FaceTec, and similar PAD-capable stacks into your existing onboarding, not a rip-and-replace.

PAD Providers We've Wired into Onboarding

OnfidoSumsubDiditFaceTecID R&DInnovatricsCustom PAD SDKs
Client Story

From Photo Spoofs to PAD-Grade Onboarding

How a digital lender stopped presentation attacks without crushing genuine applicant completion.

Before

Static Selfie KYC

  • Selfie-to-ID match only; no dedicated liveness or anti-spoofing step
  • Fraud ops found printed-photo and screen-replay accounts after first drawdowns
  • Active blink-and-turn pilot abandoned ~37% of genuine applicants
  • No ISO/IEC 30107 PAD evidence for examiners or the board risk committee
  • Each synthetic account risked R33,000+ in first-cycle credit loss
~1% of prior onboardings later flagged as presentation attacks
After

Passive-First Liveness Layer

  • Passive PAD on every selfie; active video challenge only on high-risk signals
  • Print, replay, and basic deepfake spoofs fail before the account is opened
  • Genuine completion back above 99% with sub-second passive checks
  • Provider APCER/BPCER reports filed into the FICA evidence pack
  • CRM stores pass/fail, attempt count, and session artefacts for audit
99%+ liveness step completion for bona fide applicants
63% → 99% liveness completion rate
13s → 1s average check time
~1% historic spoofs surfaced and closed
<8 weeks to full ROI on blocked fraud
The Difference

Before vs After Liveness Detection

Before
After
Spoof resistance
Photo / screen replay passes
ISO 30107 PAD blocks them
Deepfake defence
None at capture time
PAD + injection checks
Genuine completion
~60–63% with active-only
95–99%+ with passive-first
Check duration
~13 seconds active
~1 second passive
Examiner evidence
Selfie file only
PAD metrics in FICA pack
Fraud discovery
Weeks after payout
Blocked at onboarding
Getting Started

How It Works

From threat review to live anti-spoofing in 3–6 weeks.

01

Map Your Threat Model

Current selfie KYC gaps, presentation-attack history, and which ISO 30107 PAD level your risk appetite requires.

02

Provider & Flow Design

Choose passive-first vs hybrid challenges, risk triggers for escalation, and how results write back to CRM or core.

03

Build & Parallel Test

Wire the SDK or API into your journey, run spoof and bona fide test packs, and tune abandonment vs security.

04

Go Live & Monitor

Ship with APCER/BPCER dashboards, fraud-ops alerts on fail clusters, and examiner-ready evidence packs.

Questions

Frequently Asked Questions

What is liveness detection and how is it different from facial recognition?

Facial recognition asks "does this face match the ID?". Liveness detection (presentation attack detection) asks "is a real, live person in front of the camera right now?". You need both for biometric onboarding: match the face to the document, then prove the submission is not a photo, replay, mask, or deepfake.

Should we use passive or active liveness?

Most regulated onboarding flows do best with passive liveness as the default and active motion challenges only when risk scores rise. Innovatrics field data showed active checks completing for about 63% of users in 13 seconds, versus 99.9% completion in about one second with passive. ID R&D reported completion rising from roughly 60% to over 95% after a similar switch, without degrading spoof detection.

What is ISO/IEC 30107 and why does PAD Level matter?

ISO/IEC 30107-3 is the standard for testing presentation attack detection. Level 1 covers print and screen replay attacks. Level 2 adds medium-complexity 3D masks (typical target APCER ≤1%). Level 3 covers advanced, high-fidelity instruments. We help you pick a provider and operating threshold that matches your fraud loss appetite and examiner expectations.

Can you add liveness to our existing KYC stack?

Yes. This is a capability layer, not a vendor replacement. We integrate PAD from providers such as Onfido, Sumsub, Didit, FaceTec, and others into the onboarding journey you already run, including document capture and selfie-to-ID match steps.

Will liveness detection hurt conversion?

Poorly designed active-only flows can. A tuned passive-first design usually improves conversion because genuine applicants finish faster and fraudsters fail earlier. We measure abandonment and spoof rates in parallel testing before you switch off the old path.

How much does a liveness integration cost?

Provider SDK wiring into an existing journey typically starts from around R25,000. Full hybrid PAD with risk-based escalation, CRM write-back, and examiner evidence packs usually sits between R40,000 and R90,000. Against even a handful of blocked synthetic accounts (each potentially worth R33,000 to R830,000+ in fraud loss), payback is measured in weeks, not years.

Ready to stop spoofs?

Stop Relying on Static Selfie KYC

If a printed photo or a cheap deepfake can open an account on your platform, your biometric onboarding is incomplete. Liveness detection closes that gap without forcing every genuine client through a friction gauntlet.

Tell us which KYC stack you run today, where spoofs are getting through, and what PAD level your risk committee expects. We will show you how to layer Onfido, Sumsub, Didit, or another provider into the journey you already have.

Chat with us