Biometric Authentication: How Face Login Stops Fraud
Biometric authentication confirms that the person logging in or approving a payment is the account owner, using a body trait such as the face or a fingerprint. For banks and e-wallets, face authentication beats OTP and passwords against SIM swaps and phishing. But it only works when liveness detection proves the face is live and real.
What Biometric Authentication Is: Verification vs Authentication

Simply put, biometric authentication uses a physical or behavioural trait to confirm a returning user’s identity. It answers one question: is this the same person who set up the account? Because the trait is part of the person, there is also nothing to remember, and nothing to type into a phishing page.
However, people often confuse the term with biometric verification. The two use the same technology at different moments, so it helps to keep them apart.
| Biometric verification | Biometric authentication | |
|---|---|---|
| When it happens | Once, at onboarding | Every login, payment or account change |
| Question it answers | Is this person who their ID says they are? | Is this the same person who opened the account? |
| Reference it checks against | An ID photo or a government record | The face template captured at onboarding |
| Typical check | Selfie matched to ID portrait, plus liveness | New capture matched to the enrolled template, plus liveness |
In practice, authentication is only as strong as the verification behind it. If a fraudster passed onboarding with a stolen ID, every later face login simply confirms the fraudster. That is why both steps should share the same liveness and face verification standards.
Types of Biometric Authentication: Physical, Behavioural and Multimodal
In general, biometric methods fall into two families. First, physical biometrics measure what you are, such as your face or fingerprint. Second, behavioural biometrics measure how you act, such as your typing rhythm or the way you hold a phone. Multimodal systems combine two or more methods.
| Method | Works on a standard phone? | Main strength | Main weakness |
|---|---|---|---|
| Face | Yes, with the front camera | Matches against an ID photo or a government record | Needs liveness and deepfake checks to resist spoofs |
| Fingerprint | Only with a sensor | Fast and familiar, while the data stays on the device | Has no ID document to match against, so it proves only device enrolment |
| Voice | Yes, with the microphone | Useful for call centres, especially for repeat callers | AI voice clones are now cheap and convincing |
| Iris | Rarely | Very distinctive pattern, even between twins | Needs infrared hardware most phones lack |
| Behavioural | Yes, passively | Runs in the background, so users make no extra effort | Gives a risk score, not a hard identity match |
For banks and e-wallets, the face therefore has one big advantage. It is the only common biometric that a bank can compare both to a government ID and to a fresh capture on any phone. For a closer look at the trade-off, see our comparison of fingerprint vs facial recognition.
How Face Authentication Works at Login and at Transaction
In practice, face authentication follows the same five steps whether it guards a login or a large transfer. What changes, though, is how strict the threshold is.
- Enrolment. At onboarding, the system captures a selfie, checks it against the ID, and stores a face template.
- Capture. At login or payment, the app captures a new face image or short video.
- Liveness and deepfake checks. Next, the system confirms that a live person is present and that no generator produced the face.
- Matching. Then it compares the new capture with the enrolled template and produces a similarity score.
- Decision. Finally, the system compares the score with the threshold for that action, and the user passes, fails or gets a fallback.
Device-Native Biometrics vs Server-Side Face Checks
This distinction, however, matters more than most product teams expect. Device-native biometrics, such as the phone’s own face unlock or fingerprint, prove that someone enrolled on that phone is holding it. Yet anyone the owner has added to the phone, or anyone who enrolled their own face after taking it over, passes too.
By contrast, server-side face checks work differently. The bank captures the face in its own app and matches it against the template from onboarding. So the check proves the account holder is present, not just a phone user. Many banks use device biometrics for low-risk logins and server-side face checks for high-risk actions, which is the model most regulators in the region now expect.
Use Cases for Biometric Authentication in Banking and E-Wallets

Face authentication earns its place on the actions where fraud concentrates. Most banks start with a short list and expand it once pass rates look healthy.
| Journey | Why a face check helps | Typical setting |
|---|---|---|
| Login on a new device | Stops account takeover, for example after a SIM swap or credential theft | Always on |
| Large transfer or new payee | Confirms the owner approves the payment, because only they can pass | Above a value threshold |
| Limit increase | Blocks fraudsters who raise limits before they cash out | Always on |
| Change of phone number or email | Protects recovery channels, since attackers target them first | Always on |
| Account recovery | Replaces weak security questions with a check against the onboarding face | Always on |
| Routine balance check | Low risk, so device unlock is usually enough | Off, or device biometrics only |
This step-up pattern keeps friction low for everyday use. At the same time, it puts the strongest check exactly where attackers try to move money or seize control.
Where Face Authentication Beats OTP and Passwords, and Where It Does Not
OTP and passwords prove possession of a phone number or knowledge of a secret. So fraudsters can steal both without the victim being anywhere near the fraud. Face authentication changes that, although it does not solve every attack.
| Threat | Password | SMS OTP | Face authentication with liveness |
|---|---|---|---|
| Phishing page captures credentials | Fails | Fails if the OTP is relayed in real time | Holds, because nobody can type a face into a page |
| SIM swap | Not relevant | Fails, because the fraudster receives the code | Holds |
| Malware reading SMS | Partly | Fails | Holds when the app checks device integrity |
| Stolen or borrowed phone | Fails if saved | Fails | Holds with server-side matching |
| Victim coached by a scammer | Fails | Fails | Fails, because the real owner shows their face |
| Deepfake or replayed video | Not relevant | Not relevant | Holds only with liveness and deepfake detection |
The coached-victim row is the honest limit. If a scammer talks the real customer into approving a transfer, a face check confirms the right person and the money still leaves. So face authentication needs to sit alongside device and behaviour signals that spot a scam in progress, such as an active call during a transfer.
Why Liveness Decides Whether You Can Trust a Face Match
On its own, a face match only says that two images look like the same person. It cannot tell a live customer from a printed photo, a replayed video or a deepfake. Without that second check, face authentication is easier to beat than a good password, because faces are public.
Liveness detection therefore closes most of that gap. It confirms that a real person is in front of the camera at that moment. Deepfake detection then checks whether that face is genuine or generated, which matters more each year as face swap tools spread.
For high-risk actions, both checks should run on the same capture, and the server should verify the result rather than trusting the app. Otherwise, a fraudster with a hooked app can simply return “passed”.
Measuring Face Authentication Performance: FAR, FRR and Pass Rates
Every face authentication system makes two kinds of mistakes. The false accept rate (FAR) measures how often it lets the wrong person through. The false reject rate (FRR) measures how often it turns away the right person. Moving the threshold trades one for the other, so you cannot minimise both at once.
Meanwhile, independent benchmarks help you compare matchers on equal terms. For example, NIST’s Face Recognition Technology Evaluation (FRTE) tests one-to-one verification and one-to-many search on large, controlled datasets. Still, a benchmark result is not your production result. Lighting, camera quality and your customers’ devices all shift real-world numbers.
So measure on your own traffic. Track the first-attempt pass rate, the share of users who need a fallback, and the fraud rate on journeys protected by face checks. Then review those numbers by device model and region every month, since a dip usually signals a camera or lighting issue, not fraud.
Biometric Authentication Rules in Southeast Asia
Meanwhile, regulators across the region have started to require biometrics for high-risk banking actions, mostly in response to scams that defeated SMS OTP. Three examples show the direction of travel, and all three target high-value actions.
- Vietnam. According to Decision 2345, Vietnamese banks must run biometric checks on transfers above VND 10 million, on daily totals above VND 20 million, and on the first transaction from a new device.
- Thailand. In 2023, the Bank of Thailand required facial biometric checks for mobile transfers above 50,000 baht per transaction or 200,000 baht per day, according to its published measures.
- Malaysia. In September 2022, Bank Negara Malaysia told banks to migrate away from SMS OTP towards more secure authentication. It also asked them to bind authentication to one device and add a cooling-off period for new enrolments.
The common thread, then, is clear. Regulators want strong authentication on the actions that move money or change account control, not on every login. As a rule, that gives banks room to keep low-risk journeys light while applying face checks where fraud concentrates.
Implementation Checklist for Banks and E-Wallets
Use this list, then, when planning or reviewing face authentication in a mobile banking or e-wallet app:
- Map actions to risk. Decide which actions need a face check, for example large transfers, new payees, device changes and limit increases.
- Match to the onboarding template. Use server-side matching for high-risk actions, not just the phone’s own biometrics.
- Run liveness and deepfake detection. Apply both on every face check that can move money.
- Check device integrity. Look for emulator use, root access, hooking frameworks and fake camera drivers before you trust a capture.
- Set thresholds per action. A balance check and a large transfer rarely need the same strictness.
- Design fallbacks. Offer an assisted route for users who cannot complete a face check, without making it the easy path for fraud.
- Protect templates. Encrypt stored templates, limit access, and document retention for your privacy notice.
- Monitor outcomes. Track pass rates by device model and fraud rates by journey, then tune.
For broader context on biometrics across the customer lifecycle, see how biometric verification in banking supports onboarding.
Privacy and Security Risks of Biometric Authentication
Of course, biometrics bring their own risks, and a good programme plans for them from the start. First, nobody can reset a face like a password. So if templates leak, the damage lasts. Second, privacy laws in most markets treat biometric data as sensitive, which means stricter consent, purpose and retention rules.
Accuracy and fairness also need attention, for example across age groups and skin tones. A system tuned on one population can reject genuine users from another more often, so test on your real customer base. Finally, offer another route for people who cannot use the camera, such as users with certain disabilities, and log every fallback for review.
How Verihubs Supports Face Authentication
Verihubs face recognition handles the matching step for both onboarding and repeat authentication. The product page lists NIST FRTE 1:1 and 1:N evaluations, which cover one-to-one verification and one-to-many search. For high-risk actions, it also pairs with liveness detection and deepfake checks, so the system trusts a match only when the face is live and real.
Frequently Asked Questions About Biometric Authentication
What is biometric authentication?
Biometric authentication confirms a returning user’s identity with a physical or behavioural trait, such as the face, a fingerprint or typing rhythm. It replaces or supports passwords and one-time codes at login and payment.
What is the difference between biometric verification and authentication?
Biometric verification checks a person against an ID document at onboarding. Biometric authentication checks a returning user against the template stored at onboarding, every time they log in or approve a payment.
Is face authentication more secure than OTP?
Against SIM swaps, phishing and SMS-reading malware, yes, provided liveness detection is in place. However, neither method stops a victim whom a scammer coaches into approving a payment, so banks also need scam signals.
Can hackers beat biometric authentication?
Attackers try photos, masks, replayed video, deepfakes and tampered apps. Those attacks fail when liveness, deepfake and device checks run together.
What are the types of biometric authentication?
The main types are face, fingerprint, voice, iris and behavioural biometrics. Many systems also combine two or more, an approach known as multimodal biometric authentication.
Do regulators require biometric authentication for banking?
Several do for high-risk actions. Vietnam requires biometrics above set transfer thresholds, Thailand requires facial scans for large mobile transfers, and Malaysia has told banks to move away from SMS OTP.
Biometric Authentication Works When It Proves Presence, Not Just Likeness
At first glance, the appeal of biometric authentication is obvious: no codes to steal, nothing to type, faster checkout. But the real value comes from one property only. It ties an action to the physical presence of the account holder. A face match without liveness loses that property, and a phone unlock that anyone enrolled can pass never had it.
So treat face authentication as a risk control, not a convenience feature. Put it on the actions that move money, match against the onboarding template, prove the face is live and real, and keep scam signals running in parallel. Banks that do this get stronger security and faster journeys at the same time.
Planning face authentication for transfers or device changes? Talk to Verihubs about matching, liveness and deepfake checks in one flow.