When does a product need real-name verification or facial identity checks?
Where law, sector rules, or the target platform explicitly requires identity verification, implement the specified identity factors at the required step. Otherwise, do not default to facial checks simply because a transaction feels risky. First test account evidence, SMS, bank or document verification, MFA, and manual review. Use facial data only when alternatives cannot meet the same purpose, necessity is demonstrated, an impact assessment passes, and a practical non-facial route remains available.
Real name, real person, and face are different. Phone verification proves control of a number; name and document matching checks identity attributes; liveness reduces photo or video impersonation; one-to-one comparison matches a captured face to a claimed person; one-to-many identification searches a population and is more intrusive. Define the threat before selecting the least invasive control.
When translating compliance duties into evidence and controls, also compare What compliance support can a software development provider deliver?; the linked guidance adds context that should be considered in the same decision.
| Purpose | Lower-impact starting point | Possible escalation | Invalid shortcut |
|---|---|---|---|
| Ordinary registration | Email or phone, device and abuse controls | Explicit real-name duty or proven abuse | Many users means face is mandatory |
| Account recovery | Known device, recovery code, MFA, manual evidence | Existing evidence fails and loss is severe | One failed check means forced face |
| Contract signing | Identity, authority chain, reliable signature evidence | Specific law or transaction risk requires presence proof | Every electronic contract needs face |
| Payment or high-value transaction | Licensed-provider KYC and transaction controls | Applicable regulation and risk model | High value automatically justifies biometrics |
| Access or attendance | Card, QR, or staffed document check | Alternatives cannot meet a necessary purpose | Administrative convenience permits face-only access |
China's Facial Recognition Technology Application Security Measures, effective 1 June 2025, require a specific purpose, sufficient necessity, and the least harmful method. Where another method achieves the same purpose, facial recognition cannot be the sole route; a reasonable convenient alternative must be offered. Consent-based processing also requires prominent notice, separate consent, and convenient withdrawal where applicable.
Document the actual threat—multi-account abuse, identity-document theft, account takeover, or remote onboarding—and compare alternatives for security, false rejection, operational cost, and privacy. Hardware keys or MFA often address privileged-account takeover more directly than a face. Device, account, and payment signals may control promotional abuse without collecting biometrics.
If face remains necessary, complete a personal-information impact assessment covering purpose, method, rights impact, leakage risk, and safeguards. Give clear notice of handler, purpose, method, retention, and rights. The Measures restrict internet transmission and storage in specified circumstances and require the shortest necessary retention; certain storage volumes may trigger filing. China's Personal Information Protection Law also treats biometrics as sensitive personal information.
Prefer a provider design that returns a necessary decision and transaction ID instead of every image, video, and template. Verify provider role, location, retention, subprocessors, deletion, incidents, and training use. Keep raw faces and full documents out of logs. Test false acceptance and rejection, liveness attacks, time, and human handoff across target users, devices, light, and networks. Important rights should not be denied by one model score; provide appeal and recovery.
Wavesteam first produces an identity-risk and alternative-control assessment, then integrates a qualified provider only after the requirement is confirmed. We deliver the flow, minimized interface, permissions, logs, and tests; we are not the authoritative identity source and do not sell facial recognition as a universal security feature. The AI security solution shows the relevant vision capability, not its suitability for every identity use.