One Constellation
Identity Verification

Biometric Authentication Methods: Types, Accuracy and Risks

Biometrics have moved from border control to every phone and banking app. This guide compares the main biometric authentication methods, explains how matching and accuracy actually work, covers the spoofing and deepfake attacks they have to withstand, and sets out the rules that govern their use.

Published: October 2026 Category: Identity Verification Read time: ~11 minutes
Quick Answer
Biometric authentication confirms a person's identity using a physical or behavioural characteristic instead of — or as well as — a password. The main methods are facial recognition, fingerprint, iris, voice, palm or vein recognition and behavioural biometrics such as typing and swipe patterns. Each works the same way: a sample is captured, converted into a template, and compared with a stored template to produce a match score. Accuracy is measured by the false match rate (impostors accepted) and the false non-match rate (genuine users rejected) — NIST's 2025 digital identity guidelines require a false match rate of 1 in 10,000 or better. The biggest risks are spoofing with photos, masks or deepfakes, which liveness detection is designed to stop, and privacy: biometric data is specially protected under laws such as the GDPR.

Biometrics are now part of everyday finance: unlocking a banking app with a face, approving a payment with a fingerprint, or taking a selfie to open an account. The same technology serves very different jobs, and the risks differ with the job — which is why it helps to separate the methods, the use cases and the safeguards.

For how biometrics fit into customer onboarding specifically, see our guide to eKYC, liveness detection and biometric verification.

Authentication, Verification and Identification

The three terms are often used interchangeably, but they describe different comparisons:

ComparisonTypical use
Biometric authenticationOne-to-one: a returning user against their own enrolled templateLogging in, approving a payment, unlocking a device
Biometric verificationOne-to-one: a person against the photo on their identity documentRemote onboarding — the selfie-to-ID match in KYC
Biometric identificationOne-to-many: an unknown person searched against a databaseBorder control, law enforcement, duplicate-account detection

The distinction has legal weight. The EU AI Act treats remote biometric identification as high-risk, but excludes biometric verification whose sole purpose is to confirm that a person is who they claim to be.

The Main Biometric Authentication Methods

MethodHow it worksStrengthsWeaknesses
Facial recognitionMaps facial geometry from a camera image or 3D sensorWorks on any smartphone; contactless; suits remote onboardingLighting, angle and ageing affect results; target of photo, mask and deepfake attacks
FingerprintCompares ridge patterns and minutiae points from a sensorMature, fast and familiar; small sensorsWorn or damaged prints; needs a sensor; can be spoofed with moulds
IrisAnalyses the texture of the iris using near-infrared imagingHighly distinctive and stable over timeNeeds specialised cameras; less practical for remote use
VoiceCompares vocal characteristics from speechWorks over the phone; no extra hardwareBackground noise and illness; vulnerable to voice cloning
Palm and veinReads palm print or the vein pattern beneath the skinVein patterns are internal and hard to copyNeeds dedicated readers; less widely deployed
Behavioural biometricsProfiles how a person types, swipes, holds a device or moves a mousePassive and continuous; no extra step for the userProbabilistic — best as a risk signal, not a sole factor

There is no single best method. Iris and vein recognition are highly distinctive but need special hardware; facial recognition is the most practical for remote use but needs strong liveness protection; behavioural signals add security without friction but are rarely decisive on their own. Most strong implementations combine a biometric with a second factor.

How Biometric Authentication Works

1

Enrolment

The user's characteristic is captured — a face scan, fingerprint or voice sample — and converted into a mathematical template. The raw image does not need to be kept, and generally should not be.

2

Storage

The template is stored either on the device, in a secure hardware area such as a phone's secure enclave, or on a server. On-device storage keeps the biometric out of central databases; server-side storage enables cross-device and onboarding use but must be protected as sensitive data.

3

Capture and comparison

At each authentication, a fresh sample is captured, checked for liveness, converted into a template and compared with the stored one, producing a similarity score.

4

Decision

If the score passes a configured threshold, the user is accepted. Setting the threshold is a trade-off: stricter thresholds let fewer impostors in but reject more genuine users.

Measuring Accuracy: FMR, FNMR and Liveness

Two error rates describe how well a biometric system performs:

  • False match rate (FMR) — how often an impostor is wrongly accepted. This is the security measure.
  • False non-match rate (FNMR) — how often a genuine user is wrongly rejected. This is the usability measure.

Lowering one raises the other, so the operating threshold is a deliberate choice. NIST's Digital Identity Guidelines (SP 800-63B-4) set concrete benchmarks for biometric authentication:

  • a false match rate of one in 10,000 or better, achieved for all demographic groups;
  • a false non-match rate of less than 5% (recommended);
  • presentation attack detection — required for facial recognition and recommended for fingerprint and iris; and
  • biometrics used only as part of multi-factor authentication with a physical authenticator, not as a stand-alone factor.

The demographic requirement matters: a system that performs well on average but poorly for particular groups creates both fairness and operational problems, and should be tested for it.

Spoofing, Deepfakes and Injection Attacks

A biometric is only as strong as the system's ability to tell a live person from a fake. The attacks fall into two families:

  • Presentation attacks — showing the sensor something that is not a live person: a printed photo, a video replayed on a screen, a 3D mask, or a silicone fingerprint.
  • Injection attacks — bypassing the camera altogether by feeding synthetic or manipulated video, such as a deepfake, into the capture pipeline through a virtual camera or a compromised device.

Defences work in layers: liveness detection — passive, from a single capture, or active, asking the user to move — to catch presentation attacks; independent testing of presentation attack detection against the ISO/IEC 30107-3 methodology; and device and stream integrity checks to detect injected video. See our liveness detection glossary entry for the basics.

Biometrics in KYC and Customer Onboarding

In financial services, biometrics do two jobs:

  • At onboarding, a live selfie is matched to the photo on the customer's identity document. This binds the verified identity to the person actually applying, closing the gap that document or database checks leave open.
  • After onboarding, biometrics re-authenticate the customer for logins, high-value payments, changes to account details and account recovery — the moments where account takeover happens.

Combined with document checks and screening, this is the core of modern eKYC. See how biometric verification fits into the One Constellation platform, or our guide to KYC verification for the wider process.

Privacy and Regulation

  • EU — GDPR: biometric data used to uniquely identify a person is a special category of personal data under Article 9, which may be processed only under specific conditions such as explicit consent or where required by law.
  • EU — AI Act: remote biometric identification is high-risk, and real-time remote biometric identification in public spaces for law enforcement is prohibited outside narrow exceptions; one-to-one verification for identity confirmation is excluded from the high-risk category.
  • EU — payments: under PSD2 strong customer authentication, a biometric counts as an "inherence" factor, used together with a possession or knowledge factor.
  • United States: there is no single federal biometric privacy law, but state laws apply — notably Illinois's Biometric Information Privacy Act (BIPA), which requires informed written consent and a published retention policy and gives individuals a private right of action.
  • Singapore: biometric data is personal data under the Personal Data Protection Act, so consent, purpose limitation and protection obligations apply.

Across regimes the practical principles are the same: collect biometrics for a clear purpose, store templates rather than raw images where possible, protect them as highly sensitive data, keep them no longer than needed, and offer a fallback for people who cannot use them.

Benefits and Risks

BenefitsRisks
Hard to share, guess or phish, unlike passwordsA compromised biometric cannot be changed like a password
Fast, low-friction authentication on everyday devicesSpoofing and deepfake attacks without strong liveness detection
Binds a verified identity to the real person at onboardingUneven accuracy across demographic groups if not tested
Reduces account takeover and synthetic-identity fraudPrivacy and legal exposure if collected or stored carelessly

The risks are manageable with the controls above — template protection, on-device matching where possible, tested liveness detection, demographic testing and a non-biometric fallback. The mistake is treating a biometric match on its own as proof of identity.

Frequently Asked Questions

What are the main types of biometric authentication?

Facial recognition, fingerprint, iris, voice, palm or vein recognition, and behavioural biometrics such as typing rhythm, swipe patterns and how a device is held.

What is the most secure biometric authentication method?

No single method is most secure in every setting. Iris and vein recognition are highly distinctive but need special hardware; facial recognition with strong liveness detection is the most practical for remote use. Security comes mainly from liveness protection and combining the biometric with a second factor.

What does "biometrically authenticated" mean?

It means a person's identity was confirmed by matching a live biometric sample — such as their face or fingerprint — against a previously enrolled template, rather than only by a password or code.

What is the difference between biometric authentication and biometric verification?

Authentication usually means confirming a returning user against their own enrolled template, for example at login. Verification, in KYC, usually means matching a person to the photo on their identity document during onboarding. Both are one-to-one comparisons.

Is biometric authentication safe?

It is safe when implemented with liveness detection, protected templates and a second factor. On its own, without liveness checks, a biometric can be spoofed with photos, masks or deepfakes.

Sources

This article is general information, not legal advice. Requirements change — check the current text with the regulator before relying on it.

Biometric Verification With Liveness Built In

One Constellation matches each customer to their identity document with biometric face matching and liveness detection — on the same platform as KYC, screening and monitoring.

← eKYC, Liveness & Biometrics What Is KYC? → All Articles
Scroll to Top