- Active liveness testing requires a user action; passive liveness validates presence without visible interaction.
- Passive liveness testing typically has lower friction and better conversion in mass onboarding.
- Active liveness testing can add control in high-risk flows or contexts where additional evidence is needed.
- The correct decision combines risk, regulation, channel, user base, and anti-fraud capabilities.
Liveness testing has evolved from being just another link in the authentication chain to becoming the most effective defense against biometric fraud. Verifying a face against a document is no longer enough. Masks, deepfakes —that is, videos or images of a face generated or altered with artificial intelligence to simulate a real person—, screen reproductions, and image injections have turned presentation into the weak point that attackers exploit the most today. To be clear, the question is no longer "who are you?", but "are you alive, here and now?".
To answer it, biometrics offers two approaches: active liveness testing requires a user action (wink, turn head, smile); passive liveness testing analyzes micro-expressions, texture, and depth without interruption. Each one strikes a different balance between security and user experience, but neither is universally superior.
When considering a system to strengthen security, we must always keep business scalability in mind. That is, the right choice is not aesthetic or merely technical but strategic. Because, for example, a bank that opens digital accounts prioritizes its robustness against sophisticated attacks; while an e-commerce app needs the validation process to be fast so as not to lose sales.
Therefore, performance, accessibility, and regulatory compliance depend on finding that balance: look at your use case, quantify the actual fraud you could receive, and choose the liveness testing strategy that protects without excluding your legitimate user.
Liveness testing validates presence, not just facial matching
What is the difference between facial biometrics and liveness testing? Facial biometrics compares features between two or more different faces. Liveness testing, on the other hand, confirms that those data belong to a real, present, and active person, and that authentication occurs at that very moment. That distinction is not minor: it separates effective authentication from fraud. A printed photo, a video played on a screen, a 3D mask, or a manipulated camera feed can fool a first barrier, but not the second if it is well implemented.
That is why liveness testing has become a mandatory filter before any onboarding, authentication, or sensitive operation. Because it is not an additional step, but rather the barrier that detects forgery at the critical moment. However, while it is true that liveness testing is a more effective system than simple facial biometrics, it is worth analyzing where you would want to apply it first. It is worth looking at your own risk: what level of security does your company need and which liveness testing strategy best aligns with your use case. In biometric verification, liveness testing is mainly applied in three moments:
- Digital onboarding — validates that the person opening an account, registering a wallet, or creating a regulated profile is a present individual.
- Recurrent authentication — confirms identity in subsequent accesses without requiring the full documentary process again.
- High-risk operations — adds control before transfers, password changes, cashouts, device additions, or account recovery.
It is important not to lose focus on this: liveness testing does not replace other controls. It is combined with document validation, device analysis, transactional signals, watchlists, risk rules, and anti-fraud monitoring.
Active liveness testing introduces explicit interaction
The steps for authentication via active liveness testing are clear. First, the system asks the user to perform an action in front of the camera: turn their head, blink, smile, follow an on-screen instruction, or read a sequence. Then, it evaluates whether the response matches the requested challenge and whether the capture shows signals compatible with a real person. The goal is to reduce the likelihood of an attacker using a static photo or prerecorded video to fool the system.
This approach has a clear advantage: it generates an observable interaction. In certain contexts, that interaction can reinforce evidence or raise the level of control. But it also has costs. Each additional instruction adds friction to the authentication flow: a user may not understand the challenge, have poor lighting, use an old device, have a motor disability, or simply abandon the process out of frustration. In digital onboarding, those seconds matter and directly affect the conversion rate.
Therefore, to avoid unnecessary friction, you need to think about when active liveness testing works best. And it has been proven to be optimal when the risk justifies the friction. To start thinking about when to use it, it is worth observing if your business needs any of these actions:
- Onboarding for regulated financial products — when the process requires strong evidence of presence and consent.
- Account recovery — when the attacker may already have personal data or partial access to the device.
- Critical credential changes — when an operation alters control of the account.
- High-value transactions — when the cost of a false positive exceeds the cost of an additional interaction.
- Subsequent manual investigation — when the fraud team needs to review visual evidence of the challenge.
Active liveness testing should not be used out of habit. If applied to all flows, it can lower conversion without proportionally improving security.
Passive liveness testing reduces friction in mass flows
Passive liveness testing analyzes presence signals without asking the user to perform a specific action. For the person, the flow feels like a common facial capture. The system evaluates elements of the image, movement, capture environment, and biometric consistency to detect artifacts or manipulations. The validation occurs in the background, without interrupting the user experience —security without friction, in the most literal sense.
Its greatest value lies in improving user experience and accessibility. Fewer steps mean less abandonment, especially in mobile onboarding, digital wallets, gaming, retail, and high-volume financial services. Moreover, not all users can fulfill active challenges with the same ease: fewer visible instructions mean fewer errors, less bias, and a more inclusive authentication flow for everyone.
The limit of passive liveness testing lies in the risk model. In flows where the attacker has more time, more information, or greater economic incentive, it must be combined with additional signals: device analysis, injection detection, transactional behavior, and anti-fraud rules. Therefore, it is worth looking at the business risk profile before deciding whether passive liveness testing is sufficient or needs reinforcement.
| Criterion | Active liveness test | Passive liveness test |
|---|---|---|
| User interaction | High | Low |
| Friction in the flow | Medium to high | Low |
| Expected conversion | May decrease if the challenge is complex | Usually improves in mass onboarding |
| Visible evidence | Greater, due to explicit challenge | Lower for the user, evaluated by the system |
| Accessibility | Depends on the instruction | Better for broad populations |
| Recommended use | High risk, account recovery, sensitive operations | Mass onboarding, recurrent authentication, mobile flows |
| Combination with anti-fraud | Necessary | Necessary |
Passivity does not mean lower security but rather less visible interaction. The quality depends on the model, evaluation against real attacks, and the ability to combine signals.
The choice depends on risk and the moment in the journey
The fact that we speak of "liveness testing" in the singular does not mean there is only one correct way to do it. There is a decision matrix that combines risk, conversion, channel, and user profile: a good choice is a matter of context. It is worth thinking in terms of four dimensions, each associated with a different moment in the authentication process, to see where to invest more effort and technology.
The first dimension is the risk of the operation. Opening a bank account, withdrawing funds, changing an associated phone, or recovering account access have very different risk profiles. Liveness testing should scale according to the impact of error: a high-value operation requires more controls; a low-risk one, fewer.
The second dimension is conversion sensitivity. In an acquisition funnel, any step the user perceives as extra can cause abandonment. In a high-value operation, however, the user tolerates more friction because they understand what is at stake.
The third dimension is the channel. On mobile, the camera, lighting, and device stability condition the experience. On the web, there is more hardware variability and a higher risk of camera feed manipulation.
The fourth dimension is the user age range. Older adults, people with disabilities, users with low-end devices, or unstable connections may experience more friction with active challenges. A well-designed liveness test not only protects against fraud but also ensures that no one is excluded from the authentication flow.
If we were to build a practical matrix, it would look like this:
| Use case | Risk | Recommended model |
|---|---|---|
| Digital bank account opening | High | Passive with active escalation based on risk |
| Recurrent wallet login | Medium | Passive combined with Authenticate |
| Account recovery | High | Active plus device signals |
| Gaming cashout | High | Passive or active depending on amount and transactional pattern |
| Retail enrollment for benefits | Low to medium | Passive to reduce abandonment |
| Healthcare portal access | High | Passive with reinforced authentication |
| Digital citizen procedure | High | Model defined by regulation and accessibility |
The best design is usually adaptive. Not all users should go through the same level of control. A low-risk user can complete a passive test; a case with anomalous signals can escalate to an active test or additional review.
Security that does not distinguish risk ends up penalizing legitimate users.
The technical standard defines the baseline for evaluation
Liveness testing must be evaluated against real attacks. It is not enough to claim that a system detects photos or videos. Technical validation requires methodology, levels, artifacts, and auditable results. The ISO/IEC 30107 standard, for which at VU we obtained Level 2, establishes a framework for the detection of biometric presentation attacks. In practical terms, it defines how to evaluate whether a system can detect attempts at deception using physical or digital artifacts.
iBeta, a laboratory accredited by NVLAP (National Voluntary Laboratory Accreditation Program), performs conformity tests for biometric presentation attack detection. Their evaluations are a frequent reference for security, fraud, and compliance teams that need external evidence.
However, certification does not eliminate risk, although it does provide a verifiable signal. It also forces a look at validity: a test conducted years ago may not reflect the current state of attacks, especially with the evolution of deepfakes and synthetic generation tools. Teams evaluating liveness testing should ask for concrete evidence:
- Evaluation level — which ISO/IEC 30107-3 level was tested and under what scope.
- Type of attacks — which artifacts were used: photos, screens, masks, videos, injections, or others.
- Test date — when the evaluation was conducted and whether it corresponds to the SDK in production.
- Attack acceptance rate — how many attacks were accepted during the test.
- Usage conditions — which channel, device, or capture modality the report covers.
The standard is the baseline. Daily operation demands monitoring, recalibration, and response to new fraud patterns.
VU integrates liveness testing within an identity strategy
Liveness testing works best when it is not isolated. At VU, biometric verification is part of a digital identity architecture that combines verification, authentication, and fraud protection. The VU ONE platform consolidates these capabilities into a single SDK so that teams do not have to operate identity, authentication, and anti-fraud as separate silos.
This approach matters because fraud does not respect internal product boundaries. An attack can start as fake onboarding, continue as account takeover, and end as a fraudulent transaction. If each layer looks at different data, the system is too slow.
The benefit extends to each sector with its own needs. For financial services, unifying risk from account opening to transactional authentication. For gaming, adjusting controls in cashout and abuse prevention. For retail, reducing friction for legitimate users without losing control over anomalous patterns. For government and healthcare, adding traceability and compliance. The goal is not to choose between active or passive as fixed categories, but to apply the correct level of presence at the right moment.
Identity is not a photo. It is a risk decision. And that decision is better made with a unified view of the user and fraud: look at where visibility is lost between your identity, authentication, and fraud layers, and build an architecture that anticipates the attack rather than chasing it.
Request a demo
