identity.org.au

Definitions · Verification and proofing

What is biometric identity verification?

Biometric identity verification uses a physical trait — face, fingerprint or iris — to confirm a live person matches an identity. What it checks, on-device versus cloud, and its honest limits.

Identity.org.au editorial · Last updated 25 September 2026

Biometric identity verification uses measurements of a physical body — a face, a fingerprint, an iris, sometimes a voice — to check a claim about a person. The phrase biometric digital ID describes the same practice from the identity angle: proving who you are using your body rather than a document alone.

A biometric check actually answers two separate questions, and the difference is easy to miss. Liveness: is there a real, present person responding right now? Match: does this person correspond to the reference they were enrolled against — the document portrait, the enrolment template? Both must pass; either alone can be fooled.

What biometrics can and cannot prove

Biometrics are strong because they are bound to a body rather than to something that can be handed over. Nobody can lend you their fingerprint the way they can lend a card. Two honest limits follow. First, biometrics cannot be changed: a password caught in a breach is rotated, your face is yours for life, so any system accumulating biometric material accumulates unrevocable risk. Second, a match does not prove intent — a coerced person is still a live, matching person, which is why consent records matter alongside the check.

The processing location decides most of the risk. When capture, template creation and matching happen inside the phone's secure hardware, applications and servers receive only a verdict; when images are uploaded for cloud matching, the biometric travels through networks, logs and backups on the way to a central store. The trade-off, argued in full, is biometrics: on-device versus in the cloud.

The one question that separates biometric products: if your servers were fully breached tomorrow, what biometric material would an attacker hold? The only comfortable answer is none — or ciphertext without keys.

Liveness is part of verification, not a bonus

A face match against a stored photo proves nothing an attacker cannot reproduce with a printed picture or a screen. That is why serious flows issue active liveness challenges — turn your head, blink, smile — chosen unpredictably so the response must be produced live. Head rotation is particularly hostile to synthesis, because a real head turn exposes changing three-dimensional structure, lighting and occlusion that flat reenactment struggles to hold consistent.

At the wallet's Trusted level, biometric capture goes further and happens inside the phone's secure hardware, with the device attesting its own integrity. Rendering a convincing face does not help an attacker who must also defeat a physical sensor. The attack classes these layers answer are walked through in deepfakes and identity verification.

How this service treats biometrics

The commitments are published rather than implied: biometric templates are encrypted on your device before they move, never shared with services, never written to the chain unencrypted, never sold or traded regardless of consent, and always optional. The operational detail — retention, deletion, breach commitments — is in how your biometrics are protected.

Optionality deserves emphasis. A person should be able to reach a verification level appropriate to their risk without biometrics being forced into every interaction, and refusing a biometric check should cost only what genuinely requires one.

Quick answers

Is a biometric digital ID the same as a digital identity wallet?

No. A biometric check is one method of verifying that a live person matches an identity; a wallet is where verified credentials and keys live afterwards. Biometrics are how you may be verified at setup — the wallet is what you use afterwards, so you are not re-proving yourself everywhere.

Can a biometric be changed if it is stolen?

No — which is exactly why architecture matters more than promises. You cannot rotate your face or fingerprints. Systems designed around this keep templates encrypted on your device, never share raw biometrics with services, and prefer matching inside secure hardware so there is nothing central to steal.

Is biometric verification compulsory?

It should not be, and it is not in this system. Biometric checks are optional, used to raise your verification level when something genuinely requires it. Verification levels are separate from authentication: your wallet is secured with passkeys, and biometrics enter only during checks you choose to run.