Back to blog
Digital Onboarding2026-09-03

Detection at a Glance: SmartID Passive Liveness Analysis

Passive LivenessActive LivenessDigital Identity VerificationAnti-SpoofingPresentation AttackSmartID SDKAndroidiOSRemote Customer Onboarding
Detection at a Glance: SmartID Passive Liveness Analysis

Improving security in digital identity verification does not have to make the user experience more difficult. Passive liveness technology can assess in the background whether the person in front of the camera is real and present at that moment, without asking the user to smile, close their eyes, or turn their head in specific directions.

As remote customer onboarding, account opening, and digital contracting become more widespread, biometric verification is no longer limited to measuring facial similarity. The system must also determine whether the face shown to the camera belongs to a real person rather than a photograph, screen recording, video replay, or similar attack.

With active and passive liveness capabilities on Android and iOS, SmartID SDK helps organizations strike a flexible balance between security and user experience.

Why Has Liveness Detection Become More Critical?

As facial verification systems become more common, the methods used to attack them are also evolving. Printed photographs, videos displayed on another device, prerecorded footage, and AI-generated or manipulated images create new risks for digital identity verification processes.

A modern facial verification process must therefore answer two separate questions:

  • Is the person in front of the camera the same person shown on the identity document?
  • Does the camera feed come from a real, live person who is present at that moment?

The second question is answered through liveness detection and Presentation Attack Detection (PAD) technologies.

NIST's digital identity guidelines call for controls against presentation attacks, image injection, and artificially generated or manipulated media in remotely captured biometric samples. ISO/IEC 30107-3 provides an international framework for testing and reporting biometric presentation attack detection systems.

What Is the Difference Between Active and Passive Liveness?

Active liveness verification asks the user to perform specific movements. In active liveness flows supported by SmartID, users may be asked to:

  • Smile
  • Close their eyes
  • Turn their head to the right or left
  • Raise their head

These movements can be presented in a random order, making it more difficult to deceive the system with prerecorded photographs or videos.

With passive liveness, the user is not asked to perform any movement. While the user looks naturally at the camera, the system analyzes the image stream and different facial characteristics in the background.

In most cases, looking at the camera briefly is sufficient for passive liveness detection. The complexity of the technology is not exposed to the user.

SmartID active-passive

Less Friction, a Smoother User Experience

Although active liveness provides a strong security layer, users are expected to follow a sequence of instructions correctly. Low light, an incorrectly positioned device, accessibility needs, or misunderstood instructions can make the process take longer.

Passive liveness can significantly reduce this interaction burden:

  • Users do not need to perform the requested movements.
  • The process can be completed in fewer steps.
  • The need to retry because of an incorrect movement or timeout is reduced.
  • It provides a clearer experience for people using digital services for the first time.
  • More inclusive flows can be designed from an accessibility perspective.
  • It creates a more natural customer onboarding experience.

In high-volume banking, finance, insurance, telecommunications, and digital marketplace applications in particular, every additional verification step can increase the risk of customer abandonment. Passive liveness helps reduce this friction by allowing security checks to operate in the background.

Passive Liveness Is More Than a Single Image

SmartID SDK uses a layered approach that evaluates multiple images together with indicators observed over time during passive liveness detection.

On Android and iOS, signals such as image clarity, facial position and pose, natural variation, the relationship between the camera and the face, and whether the image originates from a physical person are examined together.

This layered assessment approach prevents the decision from depending on a single photographic frame or rule.

SmartID active-passive

Can Passive Liveness Replace Active Liveness?

The most appropriate approach should be determined by the risk level of the transaction and the regulations that apply to it.

Passive liveness can be used in the following models.

Passive-Liveness-First Flow

The user is assessed without performing any movement. If the confidence level is sufficient, the process continues immediately. This model is suitable for transactions where user experience is a priority and regulations permit it.

Active Liveness When Risk Is Detected

The process begins with passive liveness. If image quality or the risk assessment is insufficient, the user is asked to perform randomized active liveness movements. Most users complete a shorter flow, while suspicious transactions receive an additional control.

Combining Active and Passive Liveness

For high-risk transactions, passive analysis can operate as an additional security layer behind active movements. While the user's movements are verified, the system also assesses whether the image shows signs of a presentation attack.

Supporting Video Calls

During video calls with an agent, passive controls can provide additional indicators that support the agent's decision. However, where regulations explicitly require a video call or randomized movement instructions, passive liveness should not be treated as an automatic replacement for those requirements.

Remote identity verification regulations in Türkiye include specific requirements such as moving images, real-time communication, and unpredictable instructions. The implementation model should therefore be determined according to the applicable regulations, sector, and transaction type.

Risk-Based, Layered Approaches Are Gaining Ground Worldwide

Ease of use is not the only reason passive liveness is becoming more widespread. International standards and regulators are moving toward stronger presentation-attack and manipulation controls in remote identity verification.

The EBA guidelines on remote customer onboarding state that active or passive liveness controls can increase the reliability of remote verification. ETSI TS 119 461 treats presentation attacks, injection attacks, and deepfake content as threats that remote identity proofing must address.

The independent evaluation of passive, software-based liveness solutions by the NIST Face Analysis Technology Evaluation — PAD program also shows that this technology has become a distinct security discipline worldwide.

No liveness method eliminates every attack on its own. A strong verification process should combine document verification, face matching, passive and—when needed—active liveness, device security, image-source controls, and risk analysis.

A Consistent Security Approach on Android and iOS with SmartID

SmartID SDK enables organizations to apply similar security policies across their Android and iOS applications. According to their transaction and risk profiles, organizations can configure:

  • Passive liveness only
  • Passive and active liveness
  • On-device and server-side anti-spoofing
  • A transition to active controls when risk is detected
  • Different confidence thresholds for different transactions

These configurations can be defined according to each organization's transaction and risk profile.

SmartID's face recognition capability, grounded in NIST evaluation discipline, supports reliable comparison of a face that has passed liveness checks with the photograph on the identity document. Face matching and liveness detection are complementary security layers with different purposes.

Instead of imposing one rigid process, this approach provides an identity verification infrastructure that can be adapted to regulatory and business requirements.

SmartID hero visual

Conclusion: Security Does Not Have to Burden the User

Passive liveness is changing the traditional balance between security and ease of use in digital identity verification. Background analysis performed without requiring additional movements from users creates a faster, more natural experience while providing an important layer of protection against presentation attacks.

Where active liveness is mandatory or greater assurance is required, passive liveness does not have to be an alternative. The two technologies can be combined to create a stronger, risk-based verification process.

SmartID SDK's on-device architecture for Android and iOS, optional server-side controls, active and passive liveness options, and face recognition capabilities enable organizations to create secure, fast, and user-friendly digital onboarding processes.

Contact Us

Contact us to plan how SmartID Passive Liveness can be integrated into your organization's digital identity verification processes and configured alongside active liveness flows.