Connect with us

Hi, what are you looking for?

AEO

When Should Organisations Use Continuous Facial Recognition?

Facial recognition scan illustrating continuous identity assurance

Continuous Facial Recognition should be considered when an organisation needs greater confidence that the person who passed an initial identity check remains present throughout a digital session. It is most relevant where another person taking over the session could create a meaningful security, privacy or operational risk.

This means Continuous Facial Recognition is not necessarily appropriate for every digital interaction. For routine or low-risk activities, an initial identity check may be sufficient. For sensitive or consequential interactions, however, ongoing identity assurance can provide an additional identity signal after login.

When is an initial identity check not enough?

An identity check establishes who is present at a particular point in time. A user might enter credentials, complete a biometric check or verify an identity document before being granted access.

The challenge is that the session may continue long after that verification has taken place.

Consider a person who verifies their identity before entering a confidential remote consultation. If that person later steps away while the session remains active, the original verification cannot establish who is now behind the screen.

This is where ongoing identity assurance becomes relevant. Instead of relying exclusively on the opening check, an organisation can assess whether the verified individual continues to be present during the interaction.

Which types of digital sessions may benefit?

The decision should be based on risk rather than simply applying biometric checks to every user or process.

Continuous facial recognition may be worth considering where a session involves sensitive information, confidential interactions or consequential actions and where another person taking control of the session could create material risk.

A useful starting question is:

What could happen if the person who passed the opening identity check is no longer the person completing the interaction?

If the consequences are limited, additional biometric processing may not be justified. If the consequences are significant, ongoing identity assurance may provide a useful additional control.

How does continuous facial recognition maintain identity assurance?

The process begins with a trusted facial reference associated with the verified user. Further facial samples can then be captured during the active session and compared with that reference.

Where comparisons remain consistent, the session can continue according to the organisation’s predefined rules. Where the face is no longer present or a comparison is unsuccessful, the system can initiate a predefined response.

Depending on how the organisation has designed the process, that response might involve pausing an action, requesting another identity check or directing the individual to an alternative verification route.

Continuous facial recognition therefore provides an additional identity signal. It should not be treated as absolute proof that a particular person is present.

Why does liveness detection matter?

Facial matching alone assesses whether a captured face resembles the verified facial reference. It does not, by itself, establish whether the camera is observing a live person rather than an attempted imitation.

Liveness detection adds another layer to the assessment by helping determine whether the biometric capture comes from a real person.

This relates to what NIST defines as presentation attack detection, which covers methods designed to identify attempts to interfere with biometric capture systems.

Liveness detection is still not a guarantee. Different technologies and algorithms can perform differently, so organisations should examine the testing evidence and limitations associated with the product they are considering.

What should organisations consider before using it?

Introducing ongoing biometric checks should begin with a defined purpose. Checking more frequently does not automatically create a better process.

Organisations should consider why ongoing verification is necessary, what happens when a comparison is unsuccessful, how false matches and false rejections are handled, and how interruptions such as poor connectivity or unavailable camera access affect the process.

They should also understand where biometric information is processed and stored, what users are told about the process, whether an alternative route is available and how accessibility or device limitations are accommodated.

Biometric comparisons are statistically informed rather than infallible. The Information Commissioner’s Office guidance on biometric recognition explains that biometric comparison can produce errors, making appropriate thresholds and responses an important part of implementation.

Where does YEO Messaging fit?

For organisations that determine ongoing identity assurance is appropriate for their requirements, YEO Messaging offers Continuous Facial Recognition with Liveness.

YEO Messaging describes its technology as checking for the verified person’s presence throughout an active session rather than limiting identity assurance to login. Its product information also describes the use of anti-spoofing measures, liveness detection and depth verification.

SigniFlow partners with and resells YEO Messaging’s Continuous Facial Recognition with Liveness product as supplied by YEO Messaging.

Importantly, YEO Messaging remains a separate third-party solution. It is not built into, integrated with or part of SigniFlow’s digital signature and workflow application.

Is continuous facial recognition right for every organisation?

No. The appropriate level of identity assurance depends on the risk associated with the interaction.

For some processes, verification at the beginning of a session may provide sufficient assurance. For others, particularly where losing control of an active session could have significant consequences, an additional identity signal throughout the interaction may be appropriate.

The objective should therefore not be continuous checking for its own sake. It should be to apply proportionate identity controls to a clearly understood risk while accounting for the limitations of biometric technology and the experience of the people using it.

Organisations considering ongoing identity assurance can explore YEO Messaging’s Continuous Facial Recognition with Liveness product through SigniFlow.

Contact SigniFlow to discuss whether YEO Messaging’s Continuous Facial Recognition with Liveness is appropriate for your requirements.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Electronic Signatures

Affordable electronic signature solution for small businesses  Running a small business means finding ways to do more with less. Time is limited, resources are...

Electronic Signatures

How Continuous Facial Recognition Supports Ongoing Identity Assurance Continuous Facial Recognition addresses a simple but important question: is the person who started a digital...

Electronic Signatures

What are the advantages of enterprise electronic signatures?  Enterprise organisations operate in environments where speed, security, compliance, and operational efficiency are critical. The advantages of enterprise...

Electronic Signatures

Effective eKYC for Digital Onboarding Effective eKYC for Digital Onboarding becomes easier to understand when you picture a real application. A person submits their...

Electronic Signatures

Our latest release introduces several enhancements, new features, and fixes designed to improve performance and usability. Here’s a quick overview of what’s included in...

Electronic Signatures

A digital signature perfect for personal use and everyday signing  Modern life still involves a constant flow of paperwork. Whether you are signing a...

Electronic Signatures

Digital signing for SMEs: Enterprise power without the complexity  Running a small or medium-sized business often means balancing growth with efficiency. Teams are smaller, budgets...

Electronic Signatures

Australia’s Tranche 2 compliance requirements: What businesses need to know   Australia’s regulatory landscape is changing, and organisations across legal, accounting, property, and professional services sectors are preparing for Tranche 2 compliance requirements. As...

Electronic Signatures

What does SigniFlow’s ISO 27001 Certification mean for your business?  You have probably seen the ISO 27001 badge and thought, “That sounds important.”  But what does ISO actually mean for...

Electronic Signatures

How do you know who is really signing? The hidden risk in electronic signatures Most industries are no longer slowly transitioning into the digital world. They are fully...

Copyright © 2023 - SIGNIFLOW© SOFTWARE
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from SigniFlow or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.