Liveness detection has become an important security layer for organizations using facial biometrics for remote identity verification, authentication, digital onboarding, financial services, and fraud prevention.
For compliance teams, however, knowing that a vendor offers “liveness detection” is not enough.
A proper review needs to establish what the technology is designed to protect against, how it is tested, which standards apply, what the reported metrics mean, and whether the evidence reflects the organization’s real production environment.
This is where liveness detection standards become important.
The ISO/IEC 30107 family provides a widely used framework for understanding and evaluating presentation attack detection, commonly referred to as PAD. Other industry programs and biometric evaluation frameworks can complement ISO testing depending on the application.
Understanding these standards gives compliance, security, procurement, and technical teams a common language for evaluating biometric security without relying entirely on vendor marketing claims.
What Is Liveness Detection?
Liveness detection is designed to help determine whether a biometric sample comes from a real person who is physically present rather than from an attempted presentation attack.
In a facial verification process, the system may receive a selfie, image sequence, or video through a camera. Without an additional protection layer, an attacker may attempt to present a photograph, replayed video, image displayed on another screen, mask, or digitally manipulated facial representation.
Liveness verification addresses this part of the security problem by examining the biometric presentation and determining whether it appears to come from a genuine live subject.
The terms liveness detection and presentation attack detection are often used interchangeably in commercial discussions, but compliance teams should understand the distinction.
Liveness is commonly used to describe a capability that evaluates whether a person appears to be physically present. PAD is the standardized terminology used within the ISO/IEC 30107 framework for detecting presentation attacks against biometric capture systems.
Recognito’s article on presentation attack detection and biometric security provides additional context on how PAD fits into a broader biometric security architecture.
The important compliance question is therefore not what a vendor calls its technology. It is what attacks the technology addresses and what evidence supports those claims.
Why Compliance Teams Need to Understand PAD Standards
Compliance teams do not need to become biometric algorithm specialists, but they do need enough technical understanding to evaluate whether a vendor’s security evidence is meaningful.
A statement such as “our AI-powered liveness prevents spoofing” does not explain:
- Which attack types were tested
- What test methodology was used
- Whether testing was independent
- Which technology version was evaluated
- Which metrics were measured
- What threshold or operating point was used
- Whether the test environment resembles production
Standards create a common framework for asking those questions.
ISO/IEC 30107-1:2023 establishes terminology and a framework for specifying, characterizing, and evaluating presentation attack detection methods. It does not prescribe a particular anti-spoofing algorithm or constitute a complete system-level security assessment.
That distinction is critical.
A biometric component can be evaluated against a PAD standard without that result meaning the entire identity verification platform is protected against every possible form of fraud.

Understanding the ISO/IEC 30107 Family
When organizations refer to ISO 30107, they are generally discussing a family of standards addressing biometric presentation attack detection.
Each part has a different role.
ISO/IEC 30107-1: The PAD Framework
ISO/IEC 30107-1 establishes terminology, concepts, and the general framework used when discussing presentation attacks and PAD mechanisms.
For compliance teams, this part is useful because it creates a common vocabulary for discussions involving:
- Presentation attacks
- Attack presentation instruments
- PAD mechanisms
- Biometric capture
- Evaluation concepts
- Testing terminology
A compliance review should therefore identify the exact ISO 30107 part and edition referenced by a vendor rather than accepting a generic claim of “ISO compliant.”
ISO/IEC 30107-2: Data Formats
The second part addresses data formats associated with presentation attack detection.
This area is more technical and is particularly relevant to testing laboratories, biometric technology providers, system architects, and organizations working with standardized biometric evaluation information.
The key point for compliance teams is that ISO 30107 is not one single “liveness certification.” It is a standard family addressing different parts of PAD.
ISO/IEC 30107-3: Testing and Reporting
Part 3 is especially important during vendor evaluation.
ISO/IEC 30107-3 establishes principles and methods for assessing PAD performance, reporting evaluation results, and classifying known presentation attack types.
The ISO/IEC 30107-3:2023 standard is therefore highly relevant when a vendor provides testing evidence for its liveness or PAD capability.
This is where compliance teams should distinguish between:
“The product supports liveness detection.”
and:
“The product has undergone defined presentation attack testing with documented results.”
Those statements have very different evidentiary value.

What ISO 30107 Does Not Mean
One of the most important points for compliance teams is understanding what the standard does not guarantee.
ISO 30107 should not be treated as a blanket statement that an entire biometric system is secure.
PAD testing addresses a specific part of the security problem: presentation attacks at the biometric capture stage.
It does not automatically establish that:
- The entire application is secure
- Backend systems cannot be compromised
- Device malware is prevented
- Account takeover is impossible
- Social engineering is eliminated
- Identity documents are genuine
- The complete authentication process is fraud-proof
In other words, PAD is one layer in a larger security architecture.
That is actually useful from a compliance perspective because it allows organizations to evaluate one important security component using a defined framework while separately assessing the remaining parts of the system.
Understanding Presentation Attack Detection
A presentation attack occurs when an attacker presents an artifact or manipulated representation to the biometric capture system in an attempt to interfere with the recognition process.
For facial biometrics, examples may include printed photographs, digital images displayed on screens, replayed video, or physical masks.
The capture-stage focus is important. PAD does not attempt to solve every possible form of cybercrime or identity fraud.
That creates a useful principle for compliance reviews:
A liveness system should be evaluated for the threats it is actually designed to address.
Organizations deploying facial biometrics should therefore consider PAD alongside other controls such as identity verification, document checks, authentication, fraud monitoring, and risk analysis.
Which Metrics Should Compliance Teams Understand?
Compliance teams do not need to calculate biometric metrics themselves, but they should understand what appears in a vendor’s test report.
One important concept in PAD evaluation is the rate at which attack presentations are incorrectly accepted by the system. This may be expressed through metrics such as the Impostor Attack Presentation Accept Rate (IAPAR), depending on the evaluation methodology.
The number itself should never be viewed in isolation.
A vendor report should explain:
- The metric being reported
- The test methodology
- The attack categories evaluated
- The presentation instruments used
- The operating point or threshold
- The sample size
- Whether testing was independent
- The evaluator or laboratory
- The technology version tested
A low attack acceptance rate can provide valuable evidence, but only when the compliance team understands exactly what was tested.

Mobile Liveness Testing
Mobile identity verification creates additional considerations because smartphones combine variable cameras, operating systems, hardware, software, and capture environments.
This is particularly relevant for remote onboarding applications where customers use their own devices.
Compliance teams should therefore ask whether the testing environment reflects the intended production environment.
For example, evidence from a controlled laboratory setup may not fully represent performance across different mobile devices, lighting conditions, camera quality, or operating-system versions.
The edition and scope of the applicable standard should also be documented as part of the vendor review.
FIDO Biometric Certification
ISO standards are not the only source of useful biometric assurance evidence.
The FIDO Alliance operates a Biometric Component Certification program that evaluates biometric components against defined requirements for biometric performance and presentation attack detection.
The FIDO Biometric Certification program can therefore provide another useful source of evidence during procurement and compliance reviews.
FIDO certification should not be interpreted as a generic guarantee that an entire identity platform is secure. Rather, it can provide additional independent evidence about defined biometric capabilities and testing requirements.
For compliance teams, this is an important distinction.
Different evaluation programs answer different questions, and the strongest vendor assessment uses the evidence together rather than treating one certificate as a substitute for complete due diligence.
How NIST Fits Into Biometric Evaluation
NIST provides another important source of independent biometric evaluation, although its role should be distinguished from ISO PAD standards.
The NIST Face Technology Evaluations are useful for understanding facial recognition performance under defined evaluation conditions.
This can complement PAD testing.
A compliance or procurement team evaluating a complete facial biometric solution may therefore ask three separate questions:
Recognition performance: How effectively does the system match or identify faces?
Presentation attack protection: How effectively does it resist defined attacks presented to the biometric capture system?
Production performance: How does it behave with the organization’s actual users, devices, workflows, and operating conditions?
These are related questions, but they are not the same question.
The NIST FRVT 1:1 evaluation is especially relevant when assessing face verification performance separately from PAD.
What Compliance Teams Should Request From Vendors
A screenshot saying “ISO 30107 compliant” should not be considered sufficient evidence.
Instead, compliance teams should request enough documentation to understand exactly what was tested.
The evidence package should ideally identify:
- Applicable standard and edition
- Technology or SDK version tested
- Testing methodology
- Attack categories
- Reported metrics
- Test environment
- Test population or sample information
- Independent laboratory or evaluator
- Date of testing
- Limitations and exclusions
- Relationship between the tested component and production implementation
The technology version is particularly important.
If a vendor’s algorithm or SDK has changed since the test was performed, the older evaluation should not automatically be treated as evidence of identical current performance.
How to Evaluate a Liveness Detection Vendor
A strong evaluation combines documentation with practical validation.
1. Confirm the Standard
Identify the exact standard and edition being referenced.
Avoid accepting a generic statement such as “ISO certified” without asking which part, which version, and what component was evaluated.
2. Establish the Scope
Determine whether the testing covered the biometric component, capture environment, complete workflow, or another defined scenario.
3. Review the Evidence
Examine attack categories, methodology, metrics, test conditions, technology version, and independent testing credentials.
4. Compare It With Your Deployment
Ask whether the testing resembles the actual environment.
A mobile onboarding application may have very different requirements from a controlled physical-access deployment.
5. Assess the Full Security Architecture
Determine how liveness works alongside facial matching, document verification, authentication, fraud monitoring, and other security controls.
This prevents compliance from becoming a simple checkbox exercise.

Liveness Standards vs Marketing Claims
The difference between standards-based evidence and marketing language is important.
Terms such as “AI-powered,” “advanced liveness,” “deep learning anti-spoofing,” and “real-time fraud prevention” can describe useful technology, but they do not independently establish performance.
Compliance teams should translate these claims into measurable questions.
Instead of asking:
“Does your solution have advanced liveness?”
Ask:
“Which presentation attacks were independently tested, under what methodology, against which technology version, and what were the reported results?”
That question produces evidence that can actually support a procurement or compliance decision.
Liveness Detection as Part of a Layered Security Model
No liveness standard should be treated as a standalone security guarantee.
A remote identity workflow may involve several stages:
- Document capture and verification
- Identity information validation
- Facial recognition or matching
- Liveness verification
- Fraud and risk analysis
- Account creation or authentication
- Ongoing monitoring
Each layer addresses different risks.
Document verification can help determine whether an identity document appears legitimate. Facial matching can assess whether a presented face corresponds to an established identity. Liveness verification addresses whether the biometric presentation itself appears genuine.
That layered architecture becomes increasingly important as fraud techniques become more sophisticated.
Recognito’s active versus passive liveness detection article provides additional context on the trade-offs between active and passive approaches, including user friction, verification speed, and protection against different spoofing scenarios.
How Liveness Fits Into an Enterprise Biometric Stack
Liveness is rarely the only biometric capability an enterprise needs.
For example, a remote customer onboarding workflow may combine facial matching with document analysis and document liveness before an identity is approved.
Recognito’s ID document recognition technology is relevant where organizations need to analyze and verify identity documents as part of this broader workflow.
Document presentation attacks also represent a distinct security problem. The ID document liveness detection SDK addresses whether a submitted document image appears to be a genuine live capture rather than a manipulated or reproduced document.
Keeping these capabilities logically connected helps compliance teams understand the difference between individual controls and the overall identity architecture.
Evaluating the Liveness Technology Itself
For teams assessing the practical implementation, the face liveness detection SDK provides a useful example of the capabilities that can sit behind a production liveness workflow.
Its published capabilities include passive liveness detection, presentation attack detection, deepfake detection, face liveness scoring, and mobile and server-side SDK options.
From a compliance perspective, these product capabilities should still be evaluated against the actual evidence and deployment requirements rather than accepted solely because they appear on a product page.
Technical teams can also review the Recognito GitHub repository as part of their broader technology and developer assessment.
This gives developers another source for understanding the surrounding technical ecosystem while the compliance team focuses on testing, documentation, controls, and assurance evidence.
Building a Compliance Review for Liveness Detection
A useful compliance review should document the technology, evidence, assumptions, and limitations rather than simply recording whether a vendor claims compliance.
The review should establish:
- Which liveness technology is being used
- Which ISO standards apply
- Which editions were used
- Whether testing was independent
- Which attack categories were evaluated
- Which metrics were reported
- Which technology version was tested
- Whether the production environment matches the test environment
- What additional security controls surround the biometric component
This creates an auditable record that can be revisited when the SDK, application architecture, or regulatory requirements change.
Conclusion
Liveness detection standards give compliance teams a structured way to evaluate an important component of biometric security.
ISO/IEC 30107 provides the terminology, framework, and testing principles needed to discuss presentation attack detection consistently. Other programs such as FIDO biometric certification and independent NIST evaluations can provide complementary evidence depending on the organization’s use case.
The most important lesson is that ISO 30107 is not a blanket guarantee that an entire biometric or identity verification platform is secure.
Compliance teams should therefore look beyond labels and request actual testing evidence, understand its scope, confirm the technology version, and determine whether the evaluation reflects the organization’s production environment.
Liveness verification becomes more valuable when it is combined with strong facial matching, document verification, risk controls, appropriate privacy measures, and ongoing monitoring.
Organizations evaluating these capabilities can explore Recognito as part of a broader biometric security and identity verification assessment.
Frequently Asked Questions
What is ISO 30107?
ISO/IEC 30107 is a family of standards focused on biometric presentation attack detection. It provides terminology, frameworks, and principles for testing and reporting PAD performance.
Is ISO 30107 certification enough to prove a biometric system is secure?
No. ISO/IEC 30107 addresses presentation attacks at the biometric capture stage. A complete security assessment must also consider the wider identity, application, device, backend, and fraud-control architecture.
What should compliance teams request from a liveness detection vendor?
They should request the applicable standard and edition, testing methodology, attack categories, reported metrics, technology version, test environment, independent laboratory information, testing date, and documented limitations.
Does liveness detection replace other identity security controls?
No. Liveness is one security layer. A strong identity workflow may also require document verification, facial matching, authentication controls, fraud detection, risk analysis, data protection, and ongoing monitoring.
Why should compliance teams distinguish standards from marketing claims?
Because terms such as “AI-powered liveness” or “advanced anti-spoofing” do not independently establish performance. Standards-based testing provides a more structured basis for evaluating what was tested, how it was tested, and what the results actually demonstrate.
