Passive liveness detection explained
Passive liveness detection confirms a real, live person is in front of the camera from a single selfie, without asking them to blink or turn their head. It is the low-friction baseline control that lets genuine customers through in seconds while keeping printed photos, screen replays, masks, and injected video out.
Passive liveness detection is the control that confirms a live human is present at onboarding without asking the user to do anything. It is one layer of a broader defence covered in our deepfake detection in KYC guide, and it is the one most directly responsible for keeping onboarding fast. This explainer defines it, contrasts it with active liveness, sets out what it defends against, and explains how it is measured.
BriteBase's platform covers sanctions, PEP and adverse-media screening, not liveness detection as a standalone product. This guide is educational reference material on the category generally.
What is passive liveness detection?
Liveness detection answers a single question: is the face in front of the camera a real, live person, or a representation of one? Passive liveness answers it from a captured frame alone. The user takes a selfie, and the system analyses that image for the artefacts that distinguish a genuine live capture from a spoof, with no prompts, gestures, or challenges. From the customer's point of view there is no liveness step at all, which is exactly the point.
How does passive liveness differ from active liveness?
Active liveness asks the user to perform an action and infers liveness from the response. Common prompts include blinking, smiling, turning the head, or following a moving target. The action provides a signal, but it also adds friction, can confuse or exclude some users, and gives a determined attacker a known script to prepare against.
Passive liveness removes the prompt. Because there is nothing for the user to do, completion rates stay high, and because there is no scripted challenge, the attacker has less to rehearse. The trade-off is that passive detection has to do more analytical work on less explicit signal, which is why quality varies between vendors. In practice, strong stacks default to passive for the genuine-customer path and reserve active or step-up checks for sessions that already look risky, applying friction only where it is earned.
What does passive liveness defend against?
The primary target is the presentation attack: a fake shown to the camera. That includes a printed photograph, a photo or video replayed on a screen, a physical or digital mask, and a looped or pre-recorded video held up to the lens. In all of these the camera captures a real scene, but the contents of that scene are a representation rather than a live person, and passive liveness is the control trained to tell the difference.
There is a second, distinct threat that liveness alone does not fully address: the injection attack, where a synthetic feed is fed directly into the capture pipeline, bypassing the physical camera. Defending against injection requires checking the integrity of the capture itself, which is why a complete stack pairs passive liveness with dedicated injection-attack detection rather than relying on liveness in isolation. The distinction between presentation and injection is the single most important idea in this space, and we cover it in full in the deepfake detection guide.
How is liveness detection measured?
Buyers should not take liveness quality on faith. Two public references matter. The ISO/IEC 30107 standard defines how presentation-attack detection is tested and reported, and is the common language for evaluating a liveness system. The NIST face recognition evaluation program benchmarks face-matching performance, which is the adjacent capability that confirms the live face matches the identity document.
A word of caution applies here. These frameworks provide a way to assess a vendor, but a vendor mentioning a standard is not the same as a vendor having been independently tested against it. Ask exactly what testing has been performed, by whom, and with what result, and treat alignment with a benchmark as a claim to verify rather than a certification to assume. The honest framing from any vendor is alignment with a benchmark, not a certificate the firm does not hold.
Where does passive liveness fit in the onboarding flow?
Passive liveness sits at the very front of identity verification, at the moment of capture. The flow is straightforward: the customer takes a selfie, passive liveness confirms a live person, deepfake and injection detection screen out synthetic and injected media, document verification reads and cross-checks the identity document against the selfie, and screening clears the verified identity. Liveness is the first gate, and because it is passive, the genuine customer never feels it. The full picture of how these layers combine into a verification stack is on the identity verification software page.
FAQ
What is passive liveness detection?
Passive liveness detection confirms that a live person is in front of the camera by analysing a single captured frame for the artefacts that distinguish a genuine live capture from a spoof, without asking the user to perform any action. The user simply takes a selfie, and the system decides whether it is a real, present human or a representation of one, with no prompts, gestures, or challenges. From the customer's point of view there is no liveness step at all, which is exactly the point. Because it adds no steps for the genuine customer, passive liveness keeps onboarding fast and protects conversion while still defending the front door against spoofing. It is one layer of a broader defence, covered in our deepfake detection in KYC guide, and it is the one most directly responsible for keeping onboarding low friction rather than a sequence of hurdles.
What is the difference between active and passive liveness?
Active liveness asks the user to do something, such as blink, smile, or turn their head, and infers that a live person is present from the response. Passive liveness analyses a single captured frame for the signs of a spoof without any user action at all. The action in an active check provides an explicit signal, but it also adds friction, can confuse or exclude some users, and gives a determined attacker a known script to prepare against. Passive liveness removes the prompt, so completion rates stay high and the attacker has less to rehearse, at the cost of doing more analytical work on a less explicit signal, which is why quality varies between vendors. In practice, strong stacks default to passive for the genuine-customer path and reserve active or step-up checks for sessions that already look risky, applying friction only where it is earned rather than to everyone.
What attacks does passive liveness stop?
Passive liveness targets the presentation attack: a fake shown to the camera. That includes a printed photograph, a photo or video replayed on a screen, a physical or digital mask, and a looped or pre-recorded video held up to the lens. In all of these the camera captures a real scene, but the contents of that scene are a representation rather than a live person, and passive liveness is the control trained to tell the difference. There is a second, distinct threat that liveness alone does not fully address: the injection attack, where a synthetic feed is fed directly into the capture pipeline, bypassing the physical camera. That is why a complete stack pairs passive liveness with dedicated injection-attack detection rather than relying on liveness in isolation. Passive liveness is the baseline control that confirms a real human is present before the identity behind that face is trusted at all.
How is liveness detection measured?
Liveness and presentation-attack detection are evaluated against public frameworks, most notably the ISO/IEC 30107 standard, which defines how presentation-attack detection is tested and reported and is the common language for evaluating a liveness system. Face-matching performance, the adjacent capability that confirms the live face matches the identity document, is benchmarked separately through the NIST face recognition evaluation program. A word of caution applies here. These frameworks provide a way to assess a vendor, but a vendor mentioning a standard is not the same as a vendor having been independently tested against it. Ask exactly what testing has been performed, by whom, and with what result, and treat alignment with a benchmark as a claim to verify rather than a certification to assume. The honest framing from any vendor is alignment with a benchmark, not a certificate the firm does not actually hold or cannot evidence.
Does passive liveness hurt onboarding conversion?
No, and that is its main advantage. Because the genuine customer only takes a selfie and is never asked to blink, turn, or perform any action, passive liveness keeps onboarding fast and reduces drop-off compared with active checks that add steps some users abandon. The friction that hurts conversion comes from asking people to do things, and passive liveness removes that ask entirely for the legitimate path. Risk-based step-up can then be reserved for the sessions that show warning signs, so the added scrutiny lands only where it is warranted rather than on every applicant. This is why strong stacks make passive liveness the default: it strengthens the front door without taxing the honest majority to catch the dishonest few. The same fast, low-friction pass also produces a logged decision for each customer, so protecting conversion and building the compliance record are not competing goals but the same one.
Is liveness detection required for FINTRAC compliance?
FINTRAC does not mandate liveness detection by name, but Bill C-12 requires every compliance program to be reasonably designed, risk-based, and effective, and that standard is where the expectation lands. For a firm that verifies identity remotely, liveness is a core part of showing that onboarding genuinely confirms a real, present person rather than a photo, a replay, or an injected feed. An examiner can reasonably ask how a remote-onboarding control performs against today's spoofing, and a program with no meaningful liveness defence is hard to describe as effective. So while liveness is not a named requirement, it directly supports the case that the program meets the effectiveness standard. Passive liveness is particularly well suited to this because it produces a recorded decision for each customer while keeping onboarding fast, so the same control that defends the door also contributes the examiner-ready evidence a Canadian reporting entity has to be able to show.
Sources
After liveness, the verified identity still needs screening.
Book a platform demo and see real-time sanctions, PEP, and adverse-media screening with audit-ready case history.
Book a platform demo
