us

216.73.217.78

Back
Blogs

What is biometric verification, and what does the check actually prove

What is biometric verification, and what does the check actually prove
Madiha Khatoon JULY 9, 2026 9 minutes read

Biometric verification confirms that a live person matches a stored biometric record. Here is how it works, the main types, how it differs from authentication, and what stops deepfakes.

In January 2026, the United States Department of Homeland Security’s Science and Technology Directorate published results from its Remote Identity Validation Rally, an evaluation of sixteen commercial systems that match a selfie to an identity document. Under worst-case conditions, the rate at which those systems wrongly rejected genuine people ranged from zero to almost one hundred per cent. 

All sixteen of those software systems performed biometric verification. Those results show why just having a feature alone is not much use to anyone who’s choosing a control. In this guide we’ll explain what biometric verification is, what it checks, and how you can distinguish between the one that looks good on paper and the one that actually works well in real checks.

What is biometric verification?

Biometric verification is the process of confirming that a person is who they claim to be by comparing a live biometric sample against a biometric record captured earlier and held on file.

Biometric verification meaning, in plain terms

The check answers one narrow question, which is ‘Is the person in front of the camera or sensor the same person who enrolled?’ A biometric sample is any measurable physical or behavioural trait, such as a face, a fingerprint, an iris pattern, or a voice. 

It’s often described as a one-to-one comparison because the comparison runs against one named record instead of a whole database

What a biometric template is, and why it is not a stored photo

A biometric template is the mathematical representation a system creates from a biometric document, and it stands in for the original image at comparison time. The system measures features, converts them into numbers, and stores those numbers, and does not keep the selfie or the fingerprint scan itself.

The distinction between storing the features and storing the actual selfie or fingerprint is important because the UK Information Commissioner’s Office sets out the properties a template should have under ISO/IEC 24745, the standard on biometric information protection. 

Templates should be irreversible, meaning they are difficult to turn back into a picture of someone. They should be unlinkable, meaning one organisation’s template cannot be used to find the same person in another organisation’s database. They should be revocable, meaning a compromised template can be cancelled and replaced without asking the person for a new sample.

How does a biometric verification system work?

A biometric verification system runs three steps, and the whole sequence usually completes in a few seconds.

Step one: enrolment

The person supplies a biometric sample for the first time, and the system stores it as the reference record for every later comparison. In regulated onboarding, enrolment normally happens alongside a document check, so the face is tied to a government-issued identity.

Step two: capture and liveness detection

The system takes a fresh sample and confirms it came from a real person present at that moment. Liveness detection is the feature that does this, and it looks for signals that a genuine human produces and a photograph does not, such as skin texture, depth, and the way light reflects from a real face. 

Step three: comparison and decision

The system converts the new sample into a template, compares it with the stored reference, and produces a similarity score. That score is then measured against a threshold that is set by an operator. The outcome is a match, a non-match, or an inconclusive result that goes to a human reviewer.

Five-step biometric verification process

What are the types of biometric verification?

There are five types of biometric verification that are in commercial use, and they differ mainly in what hardware they need and how easily they can be faked.

Type What it measures Where it is used Main limitation
Facial verification Geometry and texture of the face Remote onboarding, account recovery Depends entirely on liveness detection, because a camera accepts any image placed in front of it
Fingerprint Ridge patterns on the fingertip Device unlock, in-person enrolment Needs a sensor, so it suits device-based checks rather than browser flows
Iris and retina Patterns inside the eye Border control, secure facilities Needs dedicated hardware, so it rarely appears in consumer onboarding
Voice Pitch, rhythm and vocal tract characteristics Call centres, phone banking Synthetic speech is cheap to produce, so voice works best as a supporting signal
Behavioural Typing rhythm, device handling, signature dynamics Risk scoring during a session Does not confirm an identity on its own

What is the difference between biometric verification, authentication and identification?

Buyers usually frame this as biometric verification vs authentication, but there are three terms in play, not two. The table below explains this:

Check Question it answers Comparison Typical moment
Biometric verification Is this the person the record describes? One to one Onboarding, KYC, account recovery
Biometric authentication Is this the person who set up this access? One to one, repeated Login, payment approval, step-up checks
Biometric identification Who is this person? One to many Duplicate detection, watchlist search

 

The difference decides what your check proves

Biometric verification and biometric authentication run the same underlying comparison, so the thing that separates them is what the stored record was checked against when it was created.

A face enrolled against a government-issued document at onboarding is tied to a verified identity, so a later match tells you which real person is present. On the other hand, a face enrolled directly on a device is tied only to that device, so a later match tells you the same face has returned, and nothing more about that person’s identity. 

Both are accurate, but only one of them can be used to establish an identity. Teams that buy authentication and record it internally as identity verification end up with an audit trail that cannot answer questions during a regulatory audit.

Is biometric verification safe?

Biometric verification is safe when the template is protected properly, and the accuracy claims are read in context.

What protects the template

Template protection is the first control you should be evaluating the vendor for. The template should be irreversible and unlinkable under ISO/IEC 24745, a breach of a well-built system exposes numbers rather than faces. If you are tasked with evaluating a vendor, ask them where templates are stored, how long they are kept, and whether they can be revoked, because a template that cannot be cancelled is a permanent liability in a way a password never is.

Why published accuracy figures need context

Accuracy figures are close to meaningless if the test conditions are not attached. The DHS Remote Identity Validation Rally results are reported as worst-case performance, meaning the worst combination of smartphone and document type each system faced. 

Read that way, false non-match rates across the sixteen selfie-to-document systems ran from zero to under 99.66 per cent. That means if a business had deployed one of the weaker systems, it would have turned away most of its genuine applicants on some device and document combinations, but would have been able to describe its onboarding as biometrically verified.

What bias testing should cover

Bias testing measures whether error rates change across groups of people and across capture conditions. A complete test reports false match rate and false non-match rate separately for each group, breaks results out by skin tone, age, and sex, includes failure to acquire rates, records device model and lighting, and states the sample size behind every group figure.

Can biometric verification be fooled by deepfakes?

Yes, and the DHS results show how wide the gap between systems is. In the presentation attack detection track, worst-case attack acceptance across the twelve passive subsystems tested ran from under 1.7 per cent to 100 per cent. One subsystem accepted every attack presented to it under its worst conditions. Biometric verification therefore stops deepfakes only if the specific system deployed is good at it.

How presentation attacks and injection attacks differ

A presentation attack puts something false in front of a real camera, such as a printed photograph, a screen replay or a moulded mask. An injection attack skips the camera altogether and feeds a synthetic video stream directly into the application, usually through a virtual camera or an emulator. The two need different defences, because a check that inspects the image will not notice that the image never came from the expected lens.

What liveness detection adds

Liveness detection is what separates a face match from a fraud control. Passive liveness analyses the captured image in the background with no instructions to the user. Active liveness asks the person to perform an action, such as turning their head. Neither is automatically better, and the DHS figures show poor and strong performers in both categories, so the question to ask a vendor is what their system scored, not which mode it uses.

“A surprisingly effective technique is to hold up a phone with an image and pull it back until it registers. A lot of tools look at the face, do an age estimate, and process it, but they are not spotting that it is a fake. Estimating the age is not the challenge here. Spotting that this is a fake is.”

Tom Gadsden, VP of Product, Shufti, speaking on Shufti’s Open Demo Day on age verification

Where Shufti fits in biometric verification

Most teams discover the gap between a face match and a fraud control after a loss, when the review shows the selfie was a screen replay or an injected stream and the match score was perfectly healthy.

Shufti face verification software runs liveness as part of the match, not as an optional extra. Passive liveness analyses skin texture, reflections, and depth cues with no instructions to the user; active liveness detection is available where a challenge is required, and both run through models Shufti builds and maintains in-house instead of licensing them from another provider. Deepfakes, replays, and injected streams are assessed in the same pass. Shufti holds iBeta Presentation Attack Detection Level 3 conformance for passive liveness on Android and iOS, and met one hundred per cent of the biometric accuracy goals in the DHS Remote Identity Validation Rally 2025.

Test your own onboarding traffic against a live biometric check, then book a demo to see the results on real sessions.

Frequently Asked Questions

Q: What is biometric verification?

Biometric verification confirms a person is who they claim to be by comparing a live biometric sample, such as a selfie or fingerprint, against a record captured earlier. The comparison runs against one specific record rather than a whole database.

Q: What is the difference between biometric verification and biometric authentication?

Both run a one-to-one comparison, so the difference lies in what the stored record was tied to at enrolment. Verification compares a person against an identity confirmed at enrolment, usually with a document. Authentication compares a person against an access setup, so it proves the same user returned without proving who they are.

Q: Can biometric verification be fooled by deepfakes?

Weak systems can be fooled, and results vary widely between them. In DHS testing of twelve passive liveness subsystems, worst-case attack acceptance ranged from under 1.7 per cent to 100 per cent. Layered liveness detection and injection attack detection are what close the gap.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.