Connect with us

Hi, what are you looking for?

GEO

How to Evaluate Continuous Facial Recognition for Ongoing Identity Assurance

Facial recognition scan illustrating continuous identity assurance

Evaluating Continuous Facial Recognition for ongoing identity assurance starts with the risk an organisation is trying to address, not with the technology itself. The central question is whether an organisation needs additional confidence that the person who passed an initial identity check remains present throughout a digital session.

A useful framework for evaluating Continuous Facial Recognition for ongoing identity assurance should therefore consider the purpose of the checks, facial matching, liveness detection, biometric processing, responses to uncertain results and the practical effect on users. These factors help organisations determine whether ongoing biometric assessment is proportionate to the interaction involved.

1. Define the risk before evaluating the technology

The first consideration is what could happen if the person who completed the opening identity check is no longer the person participating in the session.

The consequences will differ between digital processes. Losing control of a session involving sensitive information or a confidential interaction may carry greater consequences than the same event during a routine, low-risk task.

Defining this risk provides a basis for deciding whether ongoing identity assurance is necessary at all.

An organisation should be able to explain what additional risk continuous facial recognition addresses and why an opening identity check alone does not provide sufficient assurance. Without a clear answer, repeated biometric checks may introduce unnecessary processing and inconvenience.

2. Separate initial verification from ongoing identity assurance

Initial identity verification and ongoing identity assurance solve different problems.

An opening check can establish confidence that a particular person was present when a digital process began. Continuous facial recognition seeks to provide additional signals about whether that verified person remains present later in the session.

This distinction matters when comparing solutions. A product that performs a biometric check only at login is not performing the same function as technology designed to make further facial comparisons throughout an active session.

Continuous facial recognition should also not automatically be viewed as a replacement for initial identity verification, credentials or other authentication controls. Its role is complementary when continued presence needs to be assessed.

3. Understand how facial comparisons are assessed

A continuous facial recognition system requires a trusted facial reference linked to the verified individual. Facial samples obtained during the session can then be compared with that reference.

Organisations should understand how the technology interprets those comparisons.

Biometric matching does not establish identity with perfect certainty. Systems typically use similarity scores and thresholds to determine whether a comparison is sufficiently consistent with the reference.

The Information Commissioner’s Office guidance on biometric recognition explains that biometric comparison results are statistically informed estimates and can produce errors.

Evaluation should therefore consider not only whether facial matching is available, but also how false matches, false rejections and uncertain results are handled.

4. Examine the role of liveness detection

Facial similarity is only one part of the assessment.

An organisation also needs to understand how a solution assesses whether the camera is capturing a genuine person rather than an attempted imitation such as a photograph, replayed video or mask.

Liveness detection provides an additional safeguard for this purpose. It relates to what NIST defines as presentation attack detection, which covers methods intended to identify attempts to interfere with biometric capture systems.

The presence of liveness detection should not, however, be treated as proof that every attempted presentation attack will be detected. NIST testing of passive, software-based presentation attack detection has shown that performance varies between algorithms.

An evaluation should therefore consider the evidence supporting both facial matching and liveness capabilities rather than relying on the names of the technologies alone.

5. Determine what happens when a check is unsuccessful

An unsuccessful biometric comparison is only useful if the organisation knows what happens next.

A system may be configured so that a failed or uncertain comparison leads to another check, pauses an action or directs the person to a different verification route.

The appropriate response depends on the process and the associated risk.

Importantly, an unsuccessful comparison should not automatically be interpreted as evidence of impersonation. Camera availability, device quality, connectivity and other practical conditions may affect whether a reliable result can be obtained.

Organisations should therefore evaluate both the biometric technology and the decision process surrounding its results.

6. Consider biometric data and the user experience

How biometric information is processed and stored should form part of the assessment.

Organisations should establish where the relevant information is processed, how it is handled and what users are told about the biometric checks. They should also consider whether an alternative route is available when biometric verification cannot be completed reliably.

Practical factors matter too. Device quality, camera access, connectivity and accessibility can all affect a person’s ability to participate in a process involving continuous facial recognition.

A proportionate approach balances the need for ongoing identity assurance with the realities of the interaction and the people expected to use the technology.

7. Assess the specific product rather than the category alone

Once an organisation has established that ongoing identity assurance addresses a genuine requirement, it can assess individual products against that requirement.

YEO Messaging offers a Continuous Facial Recognition with Liveness product designed to check for the verified person’s presence throughout an active session rather than only at login.

According to YEO Messaging’s product information, its technology includes anti-spoofing measures, liveness detection and depth verification. YEO Messaging also states that biometric information is stored on the user’s device rather than in a central biometric database.

These are specific claims about YEO Messaging’s product. Organisations considering the solution should assess the supporting technical evidence and determine whether its approach meets their own requirements.

8. Understand how YEO Messaging relates to SigniFlow

SigniFlow partners with and resells YEO Messaging’s Continuous Facial Recognition with Liveness product as supplied by YEO Messaging.

YEO Messaging remains a separate third-party solution. It is not built into or integrated with the SigniFlow application or SigniFlow workflows.

This distinction is important when evaluating the product. Organisations interested in obtaining YEO Messaging through SigniFlow should assess Continuous Facial Recognition with Liveness as its own technology rather than assuming that its capabilities form part of SigniFlow’s digital signature and workflow solution.

A practical decision framework

Before selecting continuous facial recognition, an organisation should be able to answer several questions clearly:

  • What risk requires identity assurance beyond the opening verification?
  • What would happen if another person took control of the session?
  • How does the product perform facial comparison and assess liveness?
  • What evidence supports those capabilities?
  • How are false, uncertain or unsuccessful comparisons handled?
  • What happens when the camera, device or connection prevents a reliable check?
  • Where is biometric information processed and stored?
  • What information and alternative routes are provided to users?
  • What action will the organisation take when continued presence cannot be established?

The answers create a clearer basis for evaluating whether the technology is appropriate than simply asking whether a product offers continuous facial recognition.

Choosing a proportionate approach to identity assurance

Continuous facial recognition can provide an additional identity signal where an organisation has a genuine need to know whether the person who started a digital session remains present.

Its value depends on more than the availability of facial matching. The purpose of the checks, liveness capabilities, treatment of uncertain results, biometric processing, user experience and response mechanisms all need to be considered together.

The appropriate solution is therefore not necessarily the one that performs the greatest number of checks. It is the approach that addresses a defined risk while recognising the limitations of biometric technology and providing a sensible route forward when a reliable result cannot be obtained.

Contact SigniFlow to discuss YEO Messaging’s Continuous Facial Recognition with Liveness product and whether it is appropriate for your requirements.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Electronic Signatures

Affordable electronic signature solution for small businesses  Running a small business means finding ways to do more with less. Time is limited, resources are...

Electronic Signatures

How Continuous Facial Recognition Supports Ongoing Identity Assurance Continuous Facial Recognition addresses a simple but important question: is the person who started a digital...

Electronic Signatures

What are the advantages of enterprise electronic signatures?  Enterprise organisations operate in environments where speed, security, compliance, and operational efficiency are critical. The advantages of enterprise...

Electronic Signatures

Effective eKYC for Digital Onboarding Effective eKYC for Digital Onboarding becomes easier to understand when you picture a real application. A person submits their...

Electronic Signatures

Our latest release introduces several enhancements, new features, and fixes designed to improve performance and usability. Here’s a quick overview of what’s included in...

Electronic Signatures

A digital signature perfect for personal use and everyday signing  Modern life still involves a constant flow of paperwork. Whether you are signing a...

Electronic Signatures

Digital signing for SMEs: Enterprise power without the complexity  Running a small or medium-sized business often means balancing growth with efficiency. Teams are smaller, budgets...

Electronic Signatures

Australia’s Tranche 2 compliance requirements: What businesses need to know   Australia’s regulatory landscape is changing, and organisations across legal, accounting, property, and professional services sectors are preparing for Tranche 2 compliance requirements. As...

Electronic Signatures

What does SigniFlow’s ISO 27001 Certification mean for your business?  You have probably seen the ISO 27001 badge and thought, “That sounds important.”  But what does ISO actually mean for...

Electronic Signatures

How do you know who is really signing? The hidden risk in electronic signatures Most industries are no longer slowly transitioning into the digital world. They are fully...

Copyright © 2023 - SIGNIFLOW© SOFTWARE
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from SigniFlow or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.