Biometric eKYC in Kenya: ID, Face Match and Liveness
A practical evidence chain for remote onboarding in Kenya: document checks, source validation, face match, liveness and exception decisions.
A selfie can match the portrait on an uploaded ID and still leave two questions open. Was the document validly issued? Did the image come from a person present in this session? If you approve the customer on the similarity score alone, you have merged three separate claims into one result.
For a Kenyan reporting institution, remote biometric eKYC works as an evidence chain. Document inspection examines the object presented. An independent source, where one is available and authorised, helps validate identity attributes. 1:1 face comparison links the presenter to the portrait, and liveness or presentation attack detection (PAD) checks whether the capture looks like a genuine live presentation. The customer due diligence (CDD) decision stays with the institution. Kenya's 2023 POCAMLA Regulations and the Central Bank of Kenya's CDD guidance set the risk and identity-verification context. Neither one obliges every institution to buy a particular biometric tool.
One session, five distinct conclusions

Signal | What it can support | What it cannot establish alone | If unresolved |
|---|---|---|---|
Document capture and inspection | Fields, format, expiry and signs of tampering in the presented image | That the issuing record is current or that the presenter owns the document | Recapture, inspect manually or seek an appropriate source check |
Independent attribute or issuer check | Consistency of identity details with an authorised reliable source | That the applicant holding the camera is the record subject | Keep the case pending; do not convert an unavailable source into a fraud finding |
Face Match, 1:1 | Similarity between a session face and the portrait on the chosen evidence | The document's validity, liveness or entitlement to the service | Review image quality, threshold and mismatch; route to an accessible alternative |
Liveness/PAD | Evidence against particular photo, screen, mask or replay presentations | The person's legal identity or every form of injected media | Retry under a controlled policy or escalate |
Session and decision controls | Whether the signals belong to one protected attempt and meet the institution's policy | A legal conclusion from any single vendor score | Pause, investigate or decline under the institution's documented rule |
The split follows NIST's identity-proofing model, where evidence validation and attribute validation come before the question of whether the applicant rightfully owns the evidence. We use NIST as a technical reference; it is not Kenyan law. Its guidance also warns that PAD and live capture do not stop every digital injection or forged-media attack.
Document authenticity is not source verification
Optical checks can flag an altered portrait area, inconsistent fields or an unreadable document. What they assess is the presented image. A clean scan says nothing about whether the number belongs to an active record at the issuer, so the onboarding design should keep “document image passed inspection” apart from “attributes checked against a reliable independent source”. The second needs a lawful, technically available route. This article does not assume that Biometric.Vision, or any private organisation, can query a Kenyan government register.
The POCAMLA Regulations frame CDD for reporting institutions, and CBK guidance treats a digital channel without strong verification as a potential risk factor for institutions in its scope. Your technical checks should carry out the institution's risk policy, including what to do when a source is unavailable or attributes contradict each other. The wider legal and customer-risk steps are in our Kenya KYC evidence guide.
Face Match binds a presenter to evidence, within a threshold
A 1:1 face comparison asks one narrow question: does the face captured in this session resemble the portrait on this document? Searching one face across a customer gallery is a different task. A score near the configured threshold feeds the decision; it does not show the applicant is an impostor. Capture quality, ageing, the quality of the document portrait and presentation conditions all move the result. Your exception path should say when to retry, when to ask for different evidence and when to send the case to trained review.
Run the face check against the validated evidence chosen for the case. Compare a selfie with a tampered document portrait and you can get a strong similarity score for a weak identity claim. That is why NIST SP 800-63A-4 treats validation and verification as separate tasks.
Liveness addresses a different attack surface
People often say liveness when they mean PAD, a test for signs that the capture is a photo, replay, mask or similar presentation instead of a live person. Run it in the same controlled session as the face comparison. Passing liveness does not validate the ID. It also does not prove the live person holds that ID, and it cannot rule out manipulation elsewhere in the capture path.
NIST's digital injection discussion distinguishes an object held in front of the camera from media inserted between the sensor and the comparison system. A remote flow needs device and channel signals, replay resistance and protected transport as well as PAD. Test these controls against your own attack and accessibility cases; a product label alone proves little.
Resolve failures without inventing certainty
Three routine states need different routes:
Poor capture: glare, blur or a covered face leaves too little evidence. Offer a clear retry, and track how often legitimate applicants fail capture.
Source unavailable: a timeout is an availability event. Hold the source-dependent conclusion or use an approved alternative; do not label the applicant fraudulent.
Biometric mismatch or PAD alert: keep the signal, quality information and session context for review. A score by itself does not prove deception. Apply the institution's documented threshold, retry limit and escalation route.
The fourth case carries more risk. Every component returns “pass”, yet the document attributes conflict with a trusted source or with what the customer declared. The case stays open, because a successful face comparison only links the presenter to the selected portrait, and a biometric result cannot fix contradictory identity evidence.
For each attempt, record the evidence type and provenance, the checks you actually ran, source availability, model or rule version, result, exception, reviewer, decision and retention category. Keep raw biometric captures only where the organisation's documented data policy justifies it. Kenya's Data Protection Act treats biometric data as sensitive personal data; our Kenya biometric-data guide covers the separate questions of legal basis, impact and retention.
Where Biometric.Vision fits
Biometric.Vision describes document verification, 1:1 Face Match and liveness detection as modules that can make up a remote verification flow and feed technical signals into the matrix above. The product pages do not claim access to a Kenyan issuer database, Kenyan legal approval, or the right to make the final CDD decision for the institution. Before deployment, check the supported Kenyan document variants, integration permissions, performance and data handling in your own test environment.
Start by drawing a decision boundary around each signal. Which evidence does it test, what does “pass” mean, and who resolves a missing or conflicting result? Then test the liveness module as one part of that controlled flow.
Sources
Kenya, Proceeds of Crime and Anti-Money Laundering Regulations, 2023, Kenya Law; official search excerpts inspected 2026-09-23; full current text recheck pending; reporting-institution CDD and third-party responsibility.
Central Bank of Kenya, Guidance on Customer Due Diligence, August 2025; official search excerpts inspected 2026-09-23; full PDF recheck pending; financial-institution risk context for delivery channels.
Kenya, Data Protection Act, Kenya Law; official search excerpts inspected 2026-09-23; full current text recheck pending; biometric-data classification.
NIST SP 800-63A-4, Identity Proofing and Enrollment, July 2025; checked 2026-09-23; technical distinctions and attack boundaries. US guidance, not Kenyan law.
Biometric.Vision Document Verification, Face Match and Liveness product pages; checked 2026-09-23; module descriptions only.
Ready to strengthen your customer checks?
500 checks free every month · no card · no contract · no sales call.


