VerifyNow guide
Reviewed by VerifyNow Compliance Team, Compliance & Regulatory Experts on 28 July 2026
How to Use Facial Recognition Verification for South African Compliance
Facial recognition verification is a powerful tool for businesses in South Africa to accurately identify individuals, combat fraud, and meet strict regulat...

Facial verification can strengthen remote onboarding when it is used for the right job. A Face Match compares a submitted selfie with a reference face image and returns a similarity result. It does not, by itself, prove that the selfie is a live capture, validate an identity document or make a customer compliant with FICA.
VerifyNow keeps those signals separate:
- Face Match compares the selfie and reference photo.
- Passive Liveness assesses one face photo for signs associated with a live presentation.
- Identity and document checks validate the evidence required by the business's onboarding policy.
That separation helps fraud and compliance teams understand exactly what passed, what failed and what still needs review.
What Is Facial Recognition Verification?
The phrase “facial recognition” is often used for two different technologies:
- One-to-one facial verification asks whether two images are likely to show the same person.
- One-to-many facial identification searches for a face among many identities.
VerifyNow's Face Match is a one-to-one comparison. It accepts a user image and a reference image, then returns a match status, score and warnings. It does not search a public population database.
The quality and provenance of the reference image matter. Depending on your workflow, the reference may come from a separately verified record or a lawfully collected identity document. Face Match does not make a low-quality or unverified source authoritative.
Face Match and Liveness Are Different Checks
A face comparison can score two images as similar even if the submitted selfie is a photograph of a screen. Liveness addresses that separate presentation risk.
VerifyNow offers passive liveness as an API service. It uses one still face photo and does not prompt the person to blink, speak or turn their head. VerifyNow does not currently offer an active challenge or video-based liveness service.
The standalone Face Match result contains the face-comparison outcome only. It does not return a liveness decision. If the workflow needs both signals, run Passive Liveness separately and keep each result under its own label.
There is one important efficiency exception: VerifyNow's Age Estimation API returns an estimated age and a passive-liveness method and score from the same selfie. A workflow using that response does not need a second standalone liveness call for the same capture.
How to Use Facial Verification in a South African Workflow
Step 1: Define the Decision
Start with the business question. For example:
- Is the selfie sufficiently similar to the verified reference photo?
- Does the submitted capture appear to be a live presentation?
- Has the person's identity information been verified against the evidence required by policy?
- Does the case need manual review?
Do not answer all four questions with a single “biometrics passed” field. Define the required checks and decision rules before collecting any images.
Step 2: Establish the Reference Image
Use a reference image obtained through a lawful, documented process. Record where it came from and why it is appropriate for the decision. If the source is an identity document, document verification remains a separate step.
The Face Match score reflects similarity between the two supplied images. It does not certify the document, the capture source or the claimed identity number.
Step 3: Capture a Current Selfie
Give the user short, practical instructions:
- face the camera directly;
- use even lighting;
- keep the full face visible;
- remove sunglasses or other obstructions;
- avoid filters; and
- make sure only one face is in the frame.
Poor capture quality can lower a genuine match score or produce warnings. Build a recapture step before sending the case to manual review.
Step 4: Run the Required Checks
For a higher-assurance remote onboarding journey, the order may be:
- validate the identity information or document;
- run Passive Liveness on the current selfie;
- compare the selfie with the approved reference image using Face Match;
- perform sanctions, PEP or other screening required by the risk assessment; and
- apply the institution's final onboarding rules.
Some workflows will need fewer checks and others will need enhanced due diligence. The right combination depends on the customer, product, delivery channel and risk.
Step 5: Review the Actual Outputs
For Face Match, use the returned status, score and warnings. For Passive Liveness, use its separate status, score and warnings. Preserve the request identifiers so a reviewer can trace the evidence.
Do not:
- turn an uncertain result into an approval;
- describe a Face Match score as a liveness score;
- tell the customer they committed fraud because an automated check declined;
- invent missing result fields after an error; or
- deduct a final decision from one biometric signal alone.
Instead, provide a clear recapture, manual-review or escalation path.
How VerifyNow's API Fits Together
The public API separates capabilities so a team can build a workflow without hiding important distinctions.
Face Match
Use Face Match when you have two lawfully obtained images and need a one-to-one similarity assessment. The response reports the face-comparison result only.
Passive Liveness
Use Passive Liveness when you need a low-friction presentation-attack signal from one still face photo. It does not ask the person to complete an active challenge.
Age Estimation
Use Age Estimation when you need an approximate age assessment. Its response includes the passive-liveness method and score from the same selfie. Neither output proves identity, so regulated age gates may need ID-backed evidence.
Identity and Document Verification
Use the identity or document service required by your policy to validate identity evidence. Document verification returns document and extraction results; it should not be described as facial liveness.
Explore identity verification services
Developers can review the request and response contracts in the VerifyNow API documentation.
FICA: Facial Verification Is Not a Mandated Technology
FICA requires accountable institutions to identify and verify clients and conduct customer due diligence. It does not prescribe Face Match, passive liveness or active liveness as a compulsory technology.
The FIC's Revised Guidance Note 7A describes a risk-based approach. An accountable institution should decide which controls are proportionate to the money-laundering and terrorist-financing risks in its customers, products and delivery channels, then document those controls in its Risk Management and Compliance Programme.
Face Match and Passive Liveness can support a remote-onboarding control where impersonation is a relevant risk. They do not replace:
- the required client identity particulars and verification evidence;
- beneficial-ownership checks for legal persons;
- sanctions, PEP or other screening where applicable;
- enhanced due diligence for higher-risk cases;
- ongoing due diligence and transaction monitoring; or
- the institution's records and final risk decision.
Avoid saying that facial verification “ensures FICA compliance”. The defensible claim is that it can support a documented control in a broader risk-based programme.
POPIA: Facial Data Needs Deliberate Governance
POPIA treats biometric information used to uniquely identify a person as special personal information. Processing it requires more than adding a generic consent checkbox.
Before collecting face images, document:
- the specific purpose of the comparison or liveness check;
- the applicable processing condition and authorisation;
- what information is collected and what is returned;
- who can access the image and result;
- how long each is retained;
- how deletion or de-identification is handled;
- the security measures protecting the data;
- the role and obligations of any operator; and
- whether cross-border transfer requirements apply.
Give users a clear notice in plain language. Collect only what the defined workflow needs, restrict internal access and keep an audit trail of the automated and human decisions.
The Protection of Personal Information Act and the Information Regulator's guidance on processing special personal information provide the legal starting point. Obtain advice for your specific sector, purpose and processing model.
Practical Decision Rules
A simple policy might route results as follows:
| Identity evidence | Passive liveness | Face Match | Action |
|---|---|---|---|
| Verified | Approved | Match | Continue if other risk checks pass |
| Verified | In Review | Match | Request a fresh selfie or review |
| Verified | Approved | No match | Review the reference and selfie |
| Not verified | Approved | Match | Stop; a live matching face does not validate the identity evidence |
| Any technical error | Unknown | Unknown | Retry safely; do not create a partial approval |
The table is an example, not a universal compliance rule. Calibrate thresholds and escalation paths against your own risk assessment, false-match tolerance and customer-support process.
Common Questions
Does Face Match include liveness?
No. VerifyNow's standalone Face Match result is a face-comparison result. Passive Liveness is a separate API service.
Does VerifyNow offer active liveness?
No. VerifyNow currently offers passive liveness from one still face photo.
Does age estimation include liveness?
Yes. The Age Estimation API returns a passive-liveness method and score from the same selfie. The age and liveness outputs remain separate signals.
Can facial verification prove a South African ID is valid?
No. It compares face images. Use the relevant identity or document check to validate the underlying identity evidence.
Is facial recognition required by FICA?
No specific biometric technology is prescribed. Institutions must select proportionate, risk-based controls and document them.
Is biometric consent always enough under POPIA?
Not necessarily. The responsible party must identify the applicable processing condition and special-information authorisation, and comply with the rest of POPIA. Legal advice may be required for the intended use.
Build a Clearer Biometric Verification Flow
Start with the evidence your policy requires, then add the specific biometric signals that address the identified risk. Keep Face Match, Passive Liveness, Age Estimation and document results separate from the final customer decision.
Create a VerifyNow account, review the API documentation, or explore Biometric Verification.
Related Articles
- Dnb Compliant South African Id Verification For Businesses Abroad
- Property Management Company Verification In South Africa Fica Kyc
- Simplify South African Id Verification For Us Businesses
- Kenya Data Protection Act And Kyc Storage A Sa Compliance Guide
- Verify Trade Qualifications Safeguard Your Business In South Africa
- Reference Check Services A Key To Compliance In South Africa
- Is Verifynow Cipc Company Verification Accurate A Practical Guide
- Is Verifynow Driver License Verification Instant In South Africa
- Public Sector Compliance Requirements In South Africa What You Need To Know
- Kyc Technology Solutions For Financial Services Firms