KYC Authentication
KYC authentication is the re-confirmation of an already verified customer's identity at a later moment, such as a login, high-value transaction or account recovery, usually by matching a fresh selfie against the face enrolled during onboarding.
Why it matters
Onboarding proves who opened the account; authentication proves the same person is still acting on it. Account takeover, SIM-swap fraud and social engineering exploit the gap between the two.
How it works
- Enrol a face biometric during onboarding as part of KYC.
- Trigger authentication on defined events: new device, password reset, large transfer, beneficiary change.
- Capture a selfie with liveness detection and compare it with the enrolled face using a configurable match threshold.
- Return a pass, refer or fail result to the business's risk workflow.
Common challenges
- Presentation attacks (photos, masks, replayed video) and injection attacks against the camera feed.
- Friction if step-up is triggered too often; risk if it is triggered too rarely.
- Ensuring accuracy across diverse populations and capture conditions.
How IDWise supports this
IDWise addresses this within the Continuous Trust Platform through the following modules, configured per market, product line and risk tier.
Frequently asked questions
Is KYC authentication the same as two-factor authentication?
It is a form of strong authentication that uses a biometric factor tied to the verified identity, rather than a code sent to a device that could itself be compromised.
When should biometric step-up be used?
For events with elevated risk, such as account recovery, changes to contact details or payees, and transactions above a threshold.
Does authentication need a new document check?
No. It reuses the biometric enrolled at onboarding, which keeps the step short.
Related terms
Talk to an IDWise specialist about your markets, regulators and risk controls.