Biometrics & Liveness
Remote verification needs three answers: is the document genuine, is the face the same, and is the person live. Face matching, liveness detection and OCR capture answer them in one flow on the customer's own device.
Three checks in one capture
The customer photographs their document and takes a selfie once. Everything below runs off that.Liveness detection
Face matching
OCR capture
Why remote verification needs biometrics
A DVS check proves the document is real. It can't prove the person holding the phone owns it.Remote onboarding
Customers verify from anywhere without a branch visit, and you still know who was present.
Spoof resistance
Liveness detection catches presentation attacks: printed photos, screens held to the camera, replayed video.
Less typing
OCR removes manual entry, so checks stop failing on transposed digits and misspelt street names.
Evidence
Similarity scores and capture frames are retained to your retention setting, ready for dispute or audit.
Where the checks run
Pick by how your team works; the checks and results are the same.API endpoints
Request schemas and example calls are in the API reference. Sandbox available for integration testing.What does liveness detection detect?
add
Whether a live human being is present at the moment of capture. Not whether it is the right human; that is a separate check.
It analyses the video stream for signals that a printed photograph, a screen held up to the camera, or a replayed or synthetic video cannot reproduce. Presentation attacks of that kind are the usual way a stolen document gets past a remote check, because the attacker has the document image but not the person it belongs to.
When the signal is ambiguous the capture fails, not the person: the customer is asked to try again, instead of being recorded as a failed verification.
What is the difference between liveness and face matching?
add
They are sequential checks answering different questions, and neither substitutes for the other.
Liveness detection asks: is there a real, live person in front of this camera right now?
Face matching asks: is that person the one pictured on the document?
Run alone, each leaves an obvious hole. Face matching without liveness can be satisfied by holding up a photograph of the document holder. Liveness without face matching confirms somebody real is present, but not that they are the person being verified.
Together with a DVS document check, the three answer the full remote verification question: the document is genuine, the face matches it, and the person is live.
Does this stop deepfakes?
add
Liveness detection covers deepfake playback, meaning a synthetic video presented to the camera in place of a live face. That is the form the attack takes in a remote verification flow. The check looks for the capture-time signals that a rendered or replayed stream does not reproduce.
It is worth being precise about the claim. This is a presentation-attack defence, and it is one layer of several.
The reason it is paired with a DVS document check and per-field data verification is that an attacker who defeats one layer still has to produce a genuine document and a set of personal details that resolve to a real, living person. Defeating all three is a materially harder problem than defeating any one.
How does the similarity threshold work?
add
Face matching returns a similarity score, not a bare yes or no, and you set the score that counts as a pass.
The trade-off is direct. A higher threshold means fewer false accepts and more captures routed to manual review; a lower one clears more customers automatically and lets more marginal matches through. Because that is a risk appetite decision, it is yours to set.
Most clients start at our recommended default and adjust after a few weeks of live traffic, once they can see the actual distribution of scores across their own customer base. The score is recorded alongside the result, so any decision can be reviewed later against the threshold that applied at the time.
Which documents can a customer use in a self-service check?
add
A remote ID Pass check accepts five document types, four of which are read by OCR:
- Australian driver's licence — verified against NEVDIS
- Australian passport — verified against DFAT
- Medicare card — verified against Services Australia
- Foreign passport, for Australian visa holders — matched to the passport linked to their visa at DFAT
- Centrelink concession card — manual entry only, no OCR
You can require up to three documents, and the usual configuration is two with at least one photo ID. A document already used in a verification cannot be presented again for a later step in the same check.
This is a deliberately narrower set than the full DVS range. Where a customer holds a document outside this list (a birth or citizenship certificate, an ImmiCard), the check is run by your team through the portal or the API instead, which covers all 14 DVS document types.
How are images stored and protected?
add
Retention is configurable and defaults to zero days: captured images are deleted as soon as the verification completes.
Where you do choose to retain them, they are encrypted at rest under a key unique to that single verification, and processed in Australia under ISO 27001 controls.
Similarity scores and capture frames are retained to whatever setting you choose, and that is the material you would need for a dispute or an audit. The evidence record of the check itself (what ran, when, against what, with what result) is kept regardless of the image retention setting.
What about customers who cannot complete a selfie check?
add
They are not locked out. The flow falls back to document and data verification, which establishes the same identity without a biometric step, and staff-assisted checks are available through IDFEX ID Check where someone needs help completing it.
This matters for accessibility as much as for edge cases. A customer may have no working camera, poor connectivity, or a disability that makes the capture difficult.
Designing the fallback in from the start is what stops a technical limitation from turning into a declined application, and from becoming a discrimination question later.
Can we build the capture into our own app?
add
Yes. Four endpoint groups expose the capability at different levels:
- ID Pass — create, read and cancel a fully hosted verification flow
- Liveness Check — the hosted liveness flow on its own
- Likeness Check — a face similarity score between two images
- ID Document — OCR extraction and face image extraction from a document
Hosting the flow yourself gives you full control of the interface. Using ID Pass means capture, retries and browser compatibility are handled for you. Both run the same checks and produce the same evidence record.
Other solutions
Document Verification Service
Authenticate Australian identity documents against the DVS and confirm the details match authoritative sources.
Read morearrow_forward account_balance_walletIdentity verification
Verify identity documents against the DVS and personal details against Australian data sources.
Read morearrow_forward search_checkKYC due diligence
Verify who an individual customer is, screen them, and keep the evidence for each check.
Read morearrow_forwardRequest a demo of our solutions
Complete the form and our team will be in touch shortly to walk you through how it works.
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
