Identity Verification Australia: Why Verification Services Now Need Proof
Australia's national digital ID system, myID, can already match your face. That's no longer the impressive part. What the Australian Taxation Office just signaled, through a quiet but consequential Request for Information, is that matching faces was always the easy half of the problem. The harder half? Proving there's actually a living human being on the other end of the camera.
Australia's planned liveness detection refresh for myID, requiring ISO/IEC 30107-3:2023 compliance and third-party attestation at 10,000 verifications per hour, sets a new baseline that any system making high-stakes identity decisions will need to match or explain why it doesn't.
The RFI doesn't make front-page news. It's a government procurement document, and those rarely do. But read between the lines and you're looking at something that will reshape expectations across financial services, law enforcement, and identity verification at scale. When a government that onboards millions of citizens into a digital ID platform decides its current liveness detection is no longer good enough, that's worth paying attention to.
Australia's Liveness Detection Mandate
The ATO's RFI for myID, covered in detail by Biometric Updateisn't a minor tweak. The procurement calls for a SaaS-delivered liveness detection capability that can handle 10,000 verifications per hour at sub-second response times. That's the kind of throughput that reflects a system expecting serious usage pressure, not a pilot program.
Starts at 01:18 — this story3:50
Watch this story, in under a minute
A new briefing every weekday — three stories, three minutes.
Subscribe on YouTubeWhat "Identity Verification" Actually Means in This Context
Identity verification Australia-wide is not one single check, it's a chain of separate steps that each have to hold up. First a system confirms a document is genuine, then it confirms the person presenting that document is the same person pictured on it, and finally it confirms that person is physically present, live, in front of the camera right now. Document verification alone can be defeated by a well-made forgery; identity verification that skips the liveness step can be defeated by a photo, a video, or a mask. That's why the ATO's RFI treats identity verification and liveness detection as two halves of the same requirement rather than as separate line items.
More significant than the speed requirement is the compliance mandate. The system must meet Evaluation Assurance Level 2 under ISO/IEC 30107-3:2023the international standard for biometric presentation attack detection, and that compliance must be attested by qualified third parties. Not self-certified. Not vendor-claimed. Actually verified by someone with no commercial stake in the outcome. This article is part of a series, start with Ai Fraud Identity Verification Spending Deepfake Detection W.
According to ID Tech Wire, the current liveness capability dates to 2021. That's not ancient history in most industries, but in adversarial biometrics, where attackers are actively probing every system, iterating constantly, and now armed with generative AI, four years is a long time to stand still.
Document Verification Versus Identity Verification
It helps to separate document verification from full identity verification, because the two terms get used loosely and that looseness costs businesses money when they buy the wrong tool. Document verification checks whether a passport, licence, or other identity document is authentic and unaltered, the security features, the fonts, the microprint. Identity verification goes a step further and confirms the actual person in front of the system is the rightful holder of that document, usually through a live selfie compared against the document photo plus a liveness check. A business that only does document verification can still be fooled by a genuine, stolen document held by the wrong person.
When Face Detection Became Insufficient
Here's what makes this refresh genuinely interesting rather than just a routine procurement cycle. The attacks that liveness detection needs to catch in 2026 are categorically different from those it was designed to catch in 2021.
Replay attacks using a photo held up to a camera? Old news. OLOID's breakdown of biometric spoofing vectors outlines the current threat picture: 3D-printed masks, injected video streams that bypass the camera entirely, and deepfake overlays generated in near-real-time. The injection attacks are particularly nasty, instead of spoofing the camera, the attacker spoofs the data stream after it. A liveness system that checks for micro-movements and blink patterns can't catch an attack that never goes near the camera hardware in the first place.
"Deepfakes represent a potential staple tool for organised crime groups in the future, which could be used to create false evidence, manipulate public opinion, produce non-consensual pornography, or commit identity fraud." Europol, as cited in biometric security research
That framing, deepfakes as organised crime infrastructure, is important context for why governments aren't treating this as a software update. They're treating it as a trust architecture problem. And trust architecture problems require standards bodies, third-party auditors, and formal compliance frameworks. Not just a better algorithm pushed in a patch.
The sophistication gap between what systems were built to handle and what attackers are now deploying is precisely why ISO/IEC 30107-3:2023 matters here. Regula Forensics explains the active/passive detection distinction clearly: active liveness asks users to perform challenges (blink, turn your head), while passive liveness analyzes the biometric input itself for artifacts and anomalies without user interaction. Each approach has attack surfaces. The standard exists because no single technique covers every vector, and because ad hoc vendor testing doesn't produce defensible results when someone's identity, or their access to government services, is on the line. Previously in this series: Why Your Eyes Cant Spot A Deepfake And What Actually Can.
KYC, Digital ID, and Where Verify Fits
KYC, know your customer, is the broader business obligation that identity verification and document verification both serve. A bank or exchange doesn't verify identity for its own sake; it does so to satisfy KYC rules that require it to know who its customer actually is before opening an account or processing a transaction. Digital id systems like myID are one way to verify a customer quickly without manually checking a physical document each time, provided the underlying liveness detection is solid enough to trust.
Liveness Is Necessary. It's Not Sufficient.
There's a harder truth buried in Australia's decision to refresh. Even a liveness-certified system can be defeated if everything else around it is weak. Keyless makes the case that liveness detection alone doesn't clear the bar for high-assurance identity, systems that layer liveness with device verification and behavioral signals are materially more resistant than those treating liveness as the final checkpoint.
Think about what that means for identity systems beyond the government context. A bank onboarding a new customer remotely. An insurance company verifying a claimant. An investigator comparing images across open-source archives and agency databases. Every one of these scenarios involves a facial comparison that could have legal or financial consequences, and every one of them carries the same spoofing exposure that pushed Australia to refresh its standards. (The question of whether private-sector operators will move at the same pace as a government under procurement pressure is, let's say, a reasonable one to ask.)
Individual Verification for Business, Not Just Government
Individual verification at business scale carries the same stakes as government identity verification, just with a different regulator watching. A licence check at account opening, a person verification step before releasing funds, and a customer identity check before onboarding all exist because the business, not just the government, is exposed if the wrong person gets through. Businesses that treat identity security as a compliance checkbox rather than an actual control tend to discover the gap only after a fraud loss forces a review.
Why This Refresh Matters Beyond Australia
- ⚡ The compliance floor just movedWhen a major government mandates ISO/IEC 30107-3:2023 with third-party attestation, courts and regulators in other jurisdictions take note. That standard becomes the implicit benchmark for "reasonable" identity assurance.
- 📊 Vendor consolidation is comingThird-party attestation at EAL 2 isn't cheap or fast. Smaller vendors without the resources to certify will be squeezed out of high-stakes identity contracts, concentrating the market around certified players.
- 🔮 The attack surface is still growingFour years separated 2021's "good enough" from 2025's "needs refreshing." The next inflection point won't take four years. Generative AI capabilities are advancing faster than procurement cycles.
- 🏛️ Legal credibility now has a technical specAny facial comparison used to support an arrest, a fraud determination, or a legal identity claim will increasingly be evaluated against liveness compliance. Systems that can't demonstrate certified anti-spoofing are going to have a very uncomfortable time in discovery.
The Two-Class System That's Forming
What Australia's refresh is quietly creating, and this is the part that should keep compliance teams up at night, is a two-tier biometric world. On one side: systems that can demonstrate certified liveness detection, documented against international standards, verified by qualified third parties. On the other side: systems that match faces well and have always matched faces well, but whose anti-spoofing capability lives inside a vendor's white paper rather than an auditor's report.
For everyday consumer applications, that gap may not matter much for a while. For any application where the output of an identity check influences something consequential, access to services, financial transactions, legal proceedings, investigative leads, the gap is going to matter very soon. Courts don't need to formally adopt ISO/IEC 30107-3:2023 as a legal standard for it to start appearing in expert witness testimony. Once it appears in testimony a few times as the benchmark against which a system's adequacy is measured, the precedent sets itself.
This is how technical standards become legal norms without anyone passing a law. A government procures to a standard. A vendor achieves certification. A court case references the standard as the basis for evaluating whether an identity system was fit for purpose. The next system that appears in court without certification has a harder time. The pattern repeats. Platforms like CaraComp that already align their anti-spoofing architecture to internationally recognized standards aren't over-engineering, they're positioning for exactly this dynamic. Up next: Why 340m In Fraud Fighting Revenue Should Terrify Every Inve.
Verify Identity Once, Reuse With Care
A practical question businesses ask once they verify identity for a customer the first time: do they need to verify identity again for every subsequent transaction? Usually not for routine activity, but a fresh identity verification step is standard practice when the stakes rise, a large withdrawal, a change of registered device, or a change of address. Privacy law in Australia also shapes how long a business can retain the identity documents and biometric verification data collected during that first check, so reuse has to be balanced against data-minimisation obligations rather than treated as a free pass to skip verification later.
The Question That Needs an Answer
Australia's decision covers a system serving roughly 14 million usersa scale where getting liveness wrong isn't an edge case, it's a class-action. But the logic holds at any scale where identity verification carries weight. The attack techniques that prompted this refresh aren't targeting the Australian government specifically. They're deployed opportunistically, wherever the payoff justifies the effort, which now includes bank onboarding flows, insurance verification, and any remote identity check where a camera and an algorithm stand between an attacker and something valuable.
The honest engagement question here isn't whether liveness should be a baseline. It almost certainly should be, for any check that carries financial, legal, or access consequences. The real question is whether the industry will get there voluntarily before a high-profile failure forces the issue, and which systems will be left standing when the first major spoofing incident in a national ID context runs its way through a courtroom.
So: if a digital ID system can match a face but can't reliably prove live presence, would you trust it for a high-stakes identity check? Or has Australia just drawn the line that everyone else now has to step over?
Put plainly, identity verification in Australia is moving from "does the face match" to "can you prove, to a certified standard, that the face is real and present." That shift affects id verification vendors, the businesses that buy their tools, and the customers whose identity documents and biometric data flow through them. Any business relying on a third-party identity verification tool should be asking that vendor, in plain terms, whether it can produce third-party attestation of its liveness detection against ISO/IEC 30107-3:2023, not just a marketing claim.
Verifying a Driver Licence Alongside a Face Check
A driver licence is still the most common document Australians present when a business needs to confirm who they are, and it plays a specific role inside identity verification services once liveness checking is layered on top. The service reads the driver licence, checks it against issuing-authority data where that lookup is available, and then compares the licence photo to a live face capture rather than a static photo upload. A verify personal information step often follows, matching the name, address, and birth date on the licence against other records the business already holds. None of this replaces face verification, it works alongside it, because a valid driver licence in the wrong hands is still a fraud risk if nothing confirms a live person is holding it.
Some services extend the same pattern to a birth certificate when a customer has no driver licence to present, since a birth certificate carries a birth date and issuing details that can be checked but carries no photo at all. That gap is exactly why a birth certificate on its own is weaker evidence of identity than a document with a face on it, and why identity verification services built for Australia identity checks usually ask for a birth certificate only in combination with another form of proof. Verification services that accept a birth certificate as a sole document tend to be the ones most exposed to synthetic identity fraud, where a real birth date and a fabricated adult identity are stitched together around it.
Digital identity products are meant to reduce reliance on physical documents like a driver licence or birth certificate altogether, letting a person verify their identity once and reuse a verified digital identity credential across multiple services. That only works if the underlying verification behind the digital identity was done properly the first time, with real liveness checking rather than a face match against a photo that could itself be manipulated. A digital identity built on a shaky initial verification just moves the fraud risk downstream, from the document counter to whichever business trusts the digital identity credential without asking how it was issued.
Issued documents carry their own verification challenges regardless of format. A document issued decades ago under different security standards is harder to verify than one issued last year, and identity verification services need to account for that gap rather than treating every issued document as equally reliable. This is part of why a layered approach, document check, identity check, and liveness check together, holds up better than trusting any single issued credential on its own.
Frequently asked questions
What is identity verification Australia moving toward with myID?
Identity verification Australia is shifting toward mandatory liveness detection rather than just face matching. The ATO's Request for Information for myID calls for a SaaS-delivered liveness detection capability handling 10,000 verifications per hour at sub-second response times, showing that proving a real human is present has become the harder, more urgent problem than simply matching a face.
Why is face matching no longer enough for identity verification Australia systems?
Face matching alone no longer satisfies identity verification Australia standards because myID can already match faces reliably, but the ATO's RFI signals that liveness detection is now the priority. The real challenge is confirming there is an actual living person on camera, not just recognizing a face, which is why the ATO is refreshing its liveness detection requirements.
What standard is Australia's myID liveness detection expected to meet?
Australia's planned liveness detection refresh for myID requires ISO/IEC 30107-3:2023 compliance along with third-party attestation, plus the ability to process 10,000 verifications per hour. This sets a new baseline that other systems making high-stakes identity decisions will need to match or explain why they fall short.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Age verification software: court orders birth proof checks
A court in India just told marriage registrars they can't rubber-stamp underage marriages anymore. Here's why that one paperwork rule matters way more than it sounds.
biometricsUK age verification: pub face scans miss 1 in 6
UK pubs and bars just got the green light to check your age with a face scan instead of your ID. Here's what that actually means for your privacy on a Friday night out.
digital-forensicsDeepfake scams: Singapore acts as fraud attempts jump 1,300%
Singapore is rethinking how banks verify identity because deepfake scams have made "I heard my son's voice" useless as proof. The fix starts with a number: zero.
