Integrate liveness detection with ISO 30107-3 PAD compliance into an identity proofing flow

domain: ibeta.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Select a liveness vendor that has obtained iBeta ISO 30107-3 PAD Level 1 or Level 2 certification; verify the certification letter is current (iBeta issues time-limited reports) before procurement.
  2. Determine whether passive liveness (no user action, analyzes depth/texture/motion cues) or active liveness (user prompted to blink or turn head) fits your UX requirements; passive is preferred for low-friction flows.
  3. Integrate the vendor's SDK or API into the selfie capture step of your identity proofing flow; pass the liveness check result alongside the biometric comparison result in your compliance audit log.
  4. Record the vendor name, PAD level achieved, test date, and result in the identity proofing transaction record to support audit and NIST 800-63A-4 evidence documentation.
  5. Establish a fallback path for liveness failures: allow a limited number of retries before routing to supervised (in-person or video) proofing rather than infinitely looping.
  6. Review the vendor's spoofing attack taxonomy (print, replay, 3D mask) against your threat model to confirm PAD level covers the attack vectors relevant to your risk profile.

Known gotchas

Related routes

Implement passive liveness detection compliant with ISO 30107-3 PAD Level 1 using a single-frame selfie capture
iso.org · 5 steps · unrated
Configure active liveness detection with a challenge-response (head turn or number reading) to satisfy ISO 30107-3 PAD Level 2
iso.org · 5 steps · unrated
Use iBeta's published ISO/IEC 30107-3 PAD confirmation letters to evaluate and select a liveness detection vendor by certification level rather than marketing claims
ibeta.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans