Biometric Identity Verification Systems: How They Work and What to Require
By [Byline TBD] · Last reviewed [date at publish]
A biometric identity verification system proves a person is who they claim to be. This is done by matching a live fingerprint, face or iris to trusted identity evidence, and recording proof that the check happened.
Agencies use these systems to issue PIV and PIV-I credentials. Enterprises use them to onboard employees and contractors and to re-check identity before high-risk account changes. The match itself is mature technology. The hard part is everything around it: who controls the capture device, who watches the session, and whether an assessor will accept the evidence provided.
NextgenID sees this first hand. Customers have come to NextgenID many times after a remote or selfie flow failed them. The usual reasons: fraudulent or injected documents; impostors, including AI-generated faces, voices, videos and ID documents used to fool remote verification; deepfake selfies and face swaps used to beat liveness checks; fake video fed into the app through a virtual camera instead of a real one; and synthetic IDs that mix real and invented data. In a smaller number of cases, the person was flagged in another system, or simply did not want to go through a phone liveness process. A supervised session is built to stop these attacks, and the operator helps the applicant through it.
This guide covers how these systems work, the system components that should be required, where each approach fails, what NIST and FIPS 201 actually say, which certifications prove what, and how to choose a solution that you can defend in an assessment.
Verification, identification and authentication are three different jobs
Vendors blur these terms. Your requirements document should not. Biometric identification and facial recognition against a whole database solve a different problem from verifying one person against their own evidence.
| Term | Question it answers | Match type | Typical example |
|---|---|---|---|
| Verification (identity proofing) | Is this person who they claim to be, against their evidence? | 1:1 | Enrolling a new hire before issuing a PIV credential |
| Identification | Who is this person, out of everyone on file? | 1:N | Law enforcement and border control searches, or checking fingerprints for duplicate enrollments |
| Authentication | Is this the same person we already proofed? | Proof of a bound authenticator | Signing in with a PIV card or passkey, often protected by a PIN or biometric |
Verification happens at enrollment, or again at a high-risk moment. Authentication happens every day after that. NIST splits the two across separate volumes: SP 800-63A covers identity proofing and SP 800-63B covers authentication.
The practical point: a strong authenticator bound to a weakly proofed identity is still a weak identity. If the wrong person was enrolled, every later login is a clean login for the wrong person. (See: Biometric verification vs biometric authentication.)
How biometric identity verification works, step by step
A supervised, high-assurance session usually runs in this order.
- 1
Claim.
The applicant asserts an identity, often from an invitation tied to an HR or sponsor record.
- 2
Evidence capture.
The system images a passport, driver’s license, mobile driver’s license (mDL) or CAC/PIV card, reads its chip or barcode where present, and checks security features.
- 3
Evidence validation.
The document data is checked for authenticity and, where the program allows, against the issuing or an authoritative source.
- 4
Live biometric capture.
Sensors built for each modality capture face, fingerprints, iris, or a combination.
- 5
Liveness detection and presentation attack detection.
The system tests whether the sample came from a live person at the sensor, not a photo, mask, replay or synthetic finger. Active liveness asks the person to do something; passive liveness analyzes the capture without prompting.
- 6
Comparison.
The system turns each sample into biometric templates, mathematical representations of physical characteristics, and compares the live face to the document portrait one to one. Fingerprints or iris images may also be searched against existing enrollments to catch duplicates.
- 7
Supervision and adjudication.
A trained operator, on site or connected remotely to a controlled station, watches the session and resolves anything the system cannot decide.
- 8
Record and bind.
The result, evidence and biometric records are stored with an audit trail, then bound to the credential or account being issued.
Most consumer tools stop at step six. Steps seven and eight decide whether you pass an assessment.
Components to require
Ask for each of these by name in your RFP. If a vendor cannot describe one in writing, treat it as missing.
| Component | What to ask for |
|---|---|
| Capture hardware | Named face, fingerprint and iris sensors, with their certifications |
| Document reader | Chip reading for passports and PIV cards, not only a photo of the page |
| Presentation attack detection | A test report against ISO/IEC 30107-3 from an accredited lab, per modality |
| Injection attack defense | How the system proves the video stream came from a genuine sensor |
| Matching algorithm | Results from NIST’s public face (FRTE) or iris (IREX) evaluations |
| Operator workflow | Who supervises, how they are trained, and what they can override |
| Audit trail | A tamper-evident session record that an assessor can review |
| Access control integration | How the verified identity reaches your physical and logical access control systems |
| Data handling | Retention period, encryption, deletion, and where data physically lives |
Selfie apps vs supervised stations: who controls the camera?
This is the question that decides your threat model.
A selfie app runs on the applicant’s own phone or laptop. You do not control the operating system, the camera driver or the network path. A presentation attack puts something fake in front of a real camera. An injection attack skips the camera and feeds a synthetic or replayed stream straight into the app, using virtual camera software, an emulator or a rooted device. Liveness detection inspects the image, and a well-made injected image can look perfectly live.
Remote vendors know this. Injection attack detection is now its own discipline, CEN published a technical specification for testing it in 2024 (CEN/TS 18099), and NIST SP 800-63A-4 requires identity providers to “implement technical controls to increase confidence that digital media is being produced by a genuine sensor” (Section 3.14). Detection is an arms race, though. A controlled station takes a different approach: it removes most of the attack surface instead of trying to spot every attack.
| Attack | Selfie app on the applicant’s device | Supervised station on a controlled device |
|---|---|---|
| Printed photo or screen replay | Caught by good presentation attack detection | Caught by detection, and seen by the operator |
| 3D mask | Depends on the tested detection level | Detection plus a person watching the session |
| Virtual camera or emulator injection | The main weakness; needs dedicated injection detection | Largely closed off: the sensor, operating system and cable path belong to the issuer |
| Deepfake face swap in a live stream | The main weakness; depends on injection and forgery detection | The controlled sensor path and the operator both stand in the way |
| A different real person standing in | Only as strong as the face match | The operator compares person, document and biometrics live |
A controlled station does not make fraud impossible. It moves the attack into a physical session that someone is watching. If your program needs IAL2 and serves low-risk users at scale, a well-tested app with injection detection may be the right choice. For credential issuance, privileged access and high-risk account changes, ask whether “the app approved it” is an answer you could give after an incident. (See: Liveness detection isn’t enough.)
Fingerprint, face or iris
Each modality has a different strength. Many programs capture more than one.
| Factor | Fingerprint | Face | Iris |
|---|---|---|---|
| Also called | Fingerprint recognition | Facial recognition, facial biometrics | Iris scans, iris recognition |
| Best use | Background checks, FBI submissions, PIV credentials | Matching a person to a document portrait | High-accuracy duplicate checks across large populations |
| Sensor | A certified fingerprint scanner | A standard camera; controlled lighting helps | A near-infrared camera |
| Matches ID documents | No; most IDs carry no fingerprints | Yes; passports and most IDs carry a portrait | No |
| Common failure | Worn or damaged ridges, dry skin | Pose, lighting and aging; demographic differences in weaker algorithms | Some eyewear and eye conditions |
| Public evaluation | FBI Certified Products List for scanners | NIST FRTE | NIST IREX |
On demographics, be specific when you ask. NIST found demographic differences in false positive rates in the majority of face algorithms it tested, and much smaller differences in the most accurate ones (Source: NIST IR 8280, December 2019). Ask each vendor for its own algorithm’s NIST results, not the industry’s.
Capturing several traits helps only if the policy uses them well. Requiring every captured trait to match makes spoofing harder, because an attacker has to fake them all. Accepting any one trait as a fallback makes the weakest trait your real defense, so fallback cases need their own review. Voice recognition and behavioral biometrics, such as typing rhythm, suit continuous authentication after login rather than identity proofing. (See: Fingerprint, face or iris.)
What NIST SP 800-63 and FIPS 201 say
NIST Special Publication 800-63 is the federal guideline for digital identity, and volume 800-63A covers identity proofing. NIST finalized revision 4 in 2025. Many certifications in force today, including NextgenID’s, were assessed against revision 3, and agencies are moving to revision 4 on their own timelines.
| Level | What revision 4 says | Biometric role |
|---|---|---|
| IAL1 | Proofing “supports the real-world existence of the claimed identity and provides some assurance that the applicant is associated with that identity” | Not required |
| IAL2 | Adds “additional evidence and more rigorous processes for validating evidence and verifying identities” | Commonly a face comparison |
| IAL3 | Adds “a trained CSP representative (i.e., proofing agent) to interact directly with the applicant as part of an on-site attended identity proofing session and the collection of at least one biometric characteristic” | At least one biometric collected |
Two details matter for anyone buying stations. First, revision 4 defines on-site attended proofing as a session where “the proofing agent or trusted referee can be co-located with the user or interact with the user via a kiosk or device.” A station with a remote proofing agent fits that definition. Second, for remote collection, revision 4 requires presentation attack detection tested to ISO/IEC 30107-3:2023, with an impostor attack presentation accept rate below 0.07 (Section 3.11).
For PIV, FIPS 201-3, published in 2022 before revision 4, is direct: PIV identity proofing and registration “meet Identity Assurance Level (IAL) 3” (Section 2.7). Agencies “MAY use a supervised remote identity proofing process,” which “involves the use of an issuer-controlled station at a remote location that is connected to a trained operator at a central location” (Section 2.7.1). The same section requires a live operator for the entire session and at least one continuous, high-resolution video transmission of the applicant. Agencies meet these requirements through their own issuer processes; FIPS 201 does not name vendors or require any particular certification.
Certifications to ask for, and what each one does not prove
Certifications answer narrow questions. The mistake is reading one as proof of something it never tested.
| Certification or list | What it proves | What it does not prove |
|---|---|---|
| Kantara Trust Status List | The service was assessed against criteria mapped to NIST SP 800-63, at a stated level and revision | Anything outside the listed scope; read whether all criteria or only some were in scope |
| FBI Certified Products List (Appendix F) | The fingerprint device captures images that meet the FBI’s image quality specification | Liveness, face or iris performance, or the proofing process around the scanner |
| GSA FIPS 201 Approved Products List | The product passed GSA’s FIPS 201 evaluation for its category | That the whole identity proofing process meets an assurance level |
| HSPD-12, FIPS 201, PIV and PIV-I | That a product or service fits the federal personal identity verification framework | A vendor-wide HSPD-12 certificate; none exists, so ask what was actually tested |
| ISO/IEC 30107-3 | How presentation attack detection was tested, with attack and error rates | Resistance to injection attacks, which it does not test |
| ISO/IEC 19795 | That match accuracy was measured with a sound method | That the numbers came from people like your applicants |
| FIDO Alliance | Authenticators and, through separate programs, face verification | Identity proofing at a NIST assurance level |
NextgenID is the only Kantara-certified IAL3 identity proofing provider in the United States (scope: Partial Service, not all applicable criteria in scope), certified against NIST SP 800-63-3.
NextgenID Identity Station kiosk, mobile and desktop models are certified on the FBI’s Certified Products List for fingerprint image quality (Appendix F). NextgenID supports HSPD-12 / PIV / PIV-I programs.
Three questions cut through most datasheets. What was assessed? By whom? Can you check the listing yourself?
Kiosk, desktop or mobile
Form factor should follow where your applicants are.
| Form factor | Best for | Trade-off |
|---|---|---|
| Kiosk | Badge offices, lobbies and credentialing centers with steady volume | Fixed location; applicants travel to it |
| Desktop | Staffed service desks, HR and security offices, lower-volume sites | Needs a desk and an operator nearby |
| Mobile | Field enrollment, remote sites, surge events | Must travel and stay under the same device controls |
The question across all three is whether the device stays under your control. A mobile station you issue and lock down is a different security object from an app on the applicant’s phone.
NextgenID Identity Stations come in all three forms, each capturing fingerprint, face and iris and checking documents on a controlled device. (See: Kiosk, desktop or mobile and Identity Stations.)
Challenges and limitations
Biometrics are strong evidence, not perfect evidence. Plan for these before launch.
- False matches and false rejects. Every matcher trades one against the other. Where the threshold sits is a policy decision, and you should know who made it.
- Accessibility and user experience. Some people cannot give usable fingerprints or iris images, and some cannot complete a selfie flow at all. You need an alternate path that keeps the same assurance level, such as a second modality or an operator-led exception. Supervised sessions help here: a trained person can adapt the session instead of rejecting it.
- Throughput. Supervised sessions take operator time. Model peak demand, such as a hiring surge or a credential renewal cycle, before you size the volume requirements. On NextgenID kiosk workstations, a typical enrollment takes 7 to 8 minutes. It can take 10 minutes or more for DHS, HHS and Well Hive, because their enrollment package is more complete, including full fingerprint capture and iris. The average is 8 minutes.
- Evidence quality. A perfect biometric match to a fraudulent document is still fraud. The document checks matter as much as the sensor.
- What assessors ask for. Buyers are often surprised by the evidence an assessor or agency auditor requests: recorded sessions, the date and time of each session, proof of the entire process, enrollee names against completion status (matched to the agency’s own lists), accuracy thresholds for biometric capture, whether the 2D barcodes or chips on documents were read, and how the credential and information package are bound to the enrollee.
- Standards drift. Revision 4 of SP 800-63 changes definitions and requirements. Ask vendors when they will be assessed against it.
Is biometric verification safe?
It can be, if you treat biometric data as the permanent, high-value record it is. A password exposed in a data breach can be reset. A fingerprint cannot, so stolen biometric data is a long-lived identity theft risk.
Ask every vendor four things:
- What is stored: templates or images? And for how long? PIV programs keep fingerprint and facial images by design, which makes protection more important, not less.
- Is data encrypted at rest and in transit, and who holds the keys?
- Can a person’s data be deleted on request, and can deletion be proven?
- Where does the data physically reside, and is any of it used to train models?
For federal programs, the Privacy Act of 1974 governs records about individuals, and the E-Government Act of 2002 requires a privacy impact assessment for new systems that collect personal information. Private employers also face state law: Illinois’s Biometric Information Privacy Act requires notice, a written release and a published retention schedule, and Texas and Washington have biometric privacy laws of their own. Programs outside the United States add laws such as the EU’s GDPR. Regulatory compliance differs by sector and by state. This is not legal advice; review each program with counsel.
Where biometric identity verification is used
| Sector | Typical trigger | Why biometrics |
|---|---|---|
| Federal civilian agencies | PIV issuance, privileged system access | FIPS 201 builds fingerprints and facial images into the credential process |
| Defense and defense contractors | Access to controlled programs, facilities and systems | Stand-in and insider risk on sensitive work |
| Healthcare | Clinician credentials, workforce onboarding | Identity proofing before credentials that reach sensitive systems |
| Financial services | High-value account opening, account recovery, privileged staff | Account takeover and synthetic identity fraud |
| Enterprise workforce | Contractor onboarding, privileged access, help desk resets | Social engineering at account recovery |
| Border and travel | Entry, exit and airport screening | Within the Department of Homeland Security, CBP collects biometrics at entry and exit and TSA uses facial comparison at checkpoints |
Identity proofing is not only for first enrollment. One NextgenID use is identity re-proofing at a PresenceID Identity Station before authorizing a high-risk account change, such as a password reset. That closes a common gap: an account proofed at a high assurance level and then recovered over a help desk phone call.
How to choose a biometric identity verification system
Fraud that gets past enrollment is the hardest fraud to find later, because every login after it looks legitimate. Work through this in order; each step narrows the field before demos.
- Set your target assurance level from your risk assessment and the programs you serve, not from a vendor.
- Decide who controls the capture device. If injection attacks are in your threat model, a controlled station narrows the attack surface in a way an app cannot.
- Pick modalities based on what you feed downstream: fingerprints for FBI checks and PIV, face for document matching, iris for large-scale duplicate checks.
- Demand public, checkable certifications. Look every vendor up on the Kantara Trust Status List and the FBI Certified Products List yourself and read the scope line.
- Test attack claims. Ask for lab reports on presentation attack detection and a written description of injection defenses, not summaries.
- Map form factors to locations. Count sites, applicants per site and peak volume.
- Run a pilot with real applicants, including the people most likely to fail capture.
- Review data handling with counsel before the contract, not after.
For the questions to put in an RFP, see Biometric Identity Verification RFP Checklist: Requirements, Scoring and Red Flags.
Go deeper
Frequently asked questions
What is a biometric identity verification system?
A system that proves a person is who they claim to be by matching a live fingerprint, face or iris to trusted evidence, such as a passport or PIV card, and recording proof of the check. It is used for credential issuance, onboarding and high-risk account changes.
How does biometric identity verification work?
The system captures an identity document and a live biometric, checks the document is genuine, confirms the sample came from a live person at the sensor, compares the two one to one, and records the result. At high assurance, a trained operator supervises the session before the identity is bound to a credential.
Can a selfie app meet NIST IAL3?
Not under revision 4 of NIST SP 800-63A, which describes IAL3 as an on-site attended session with a trained proofing agent and at least one biometric collected. The agent can be co-located with the applicant or interact through a kiosk or device. An app on the applicant’s own phone is a remote session.
What is an injection attack?
An attack that bypasses the camera and feeds a fake or replayed video stream directly into the verification software, often with virtual camera tools or emulators. Presentation attack detection alone may not catch it, which is why NIST SP 800-63A-4 (Section 3.14) requires identity providers to use controls that confirm media came from a genuine sensor.
Is biometric verification safe?
It can be. Ask what is stored and for how long, how it is encrypted, who holds the keys, whether deletion can be proven and where the data lives. Because a biometric cannot be reset after a breach, protecting the record matters as much as capturing it well.
What does the FBI Certified Products List cover?
Fingerprint capture devices that meet FBI image quality specifications. It does not assess liveness, face or iris performance, or a vendor’s overall identity proofing process.
What does “Partial Service” mean on the Kantara Trust Status List?
It means the assessment covered some, not all, of the applicable criteria. Read the scope line on the listing for any vendor you consider.
Which industries use biometric identity verification most?
Federal agencies and defense contractors issuing PIV and PIV-I credentials, regulated enterprises controlling workforce and privileged access, healthcare organizations protecting clinical systems, and financial services firms opening accounts and approving high-value changes.
The bottom line
If a credential protects something that matters, the question is not whether your system uses biometrics. It is whether you could prove, after the fact, who was actually there.
NextgenID serves federal agencies including DHS, HHS and NASA.
Before your next demo, look up every vendor on your shortlist on the Kantara Trust Status List and the FBI Certified Products List. Then see how NextgenID Identity Stations capture fingerprint, face and iris on a controlled device, or book a demo.
Index
Terms used in this guide, with the chapters where they appear.
Book a demo
"*" indicates required fields