Biometric technology is increasingly embedded in the way organisations identify customers, authenticate employees, prevent fraud and control access to sensitive systems. Facial images, fingerprints, voice patterns, iris scans and behavioural signals can reduce dependence on passwords and make some forms of impersonation more difficult.
The same technology creates a concentrated data risk. A compromised password can be reset; a person cannot readily replace their face, voice or fingerprints. Although well-designed templates may be renewable, poor collection, excessive retention or uncontrolled reuse can create consequences beyond one account or service.
For financial crime teams, the issue is not whether biometrics are inherently safe or unsafe. It is whether the organisation can prove that collection is necessary, the system performs reliably, the data is protected throughout its lifecycle and biometric decisions are connected to wider identity and transaction intelligence.
Listen the podcast
Watch the video
Why corporate biometric practices matter now
Biometrics have moved from specialist security environments into everyday commercial activity. Financial institutions use selfies and facial comparison during remote onboarding. Employers may use fingerprints or facial recognition for attendance and access control. Contact centres analyse voice characteristics, while digital platforms use behavioural signals such as typing rhythm and device handling to distinguish legitimate users from bots or account takeovers.
This expansion is driven by a legitimate control need. Passwords can be phished, documents forged, and remote onboarding exploited through synthetic identities, deepfakes and injection attacks. A biometric check can add evidence of physical presence and identity consistency.
However, a useful security purpose does not automatically justify every collection practice. The UK Information Commissioner’s Office treats biometric data used for unique identification as particularly sensitive and expects organisations to establish a lawful basis, a separate condition for processing and a proportionate purpose. Its enforcement against facial recognition and fingerprint scanning for employee attendance showed that convenience may not justify intrusive processing where less invasive alternatives exist.
US enforcement has raised similar concerns. The Federal Trade Commission has warned that biometric technologies can create privacy, security, bias and discrimination risks. Its action involving a major pharmacy chain showed how weak testing, poor oversight and inadequate responses to false matches can turn a crime-prevention system into a source of consumer harm.
Corporate responsibility begins before deployment. An organisation must understand what it collects, why it is needed, who controls it and what happens when the technology is wrong.
What companies actually collect
A facial-recognition journey may begin with a photograph or video. Software extracts measurable features and converts them into a mathematical representation known as a template. The system compares that template with another image or stored reference and produces a similarity score.
A template is not a harmless string of numbers. It remains personal information where it relates to an identifiable individual and may preserve enough structure to create security and privacy risk.
Systems may also retain timestamps, devices, IP addresses, geolocation, confidence scores, failed attempts, document images and liveness results, creating a detailed access history.
Behavioural biometrics are less visible. A customer may be assessed through keystroke cadence, mouse movement, navigation patterns, gait, touchscreen pressure or the way a device is held. These signals can identify bots, remote-access manipulation or account takeover. They also create transparency challenges because users may not realise that ordinary interaction is being converted into an identity or risk profile.
The governance question is broader than whether a company stores a fingerprint or selfie. It includes the complete data package, the decisions derived from it and the secondary purposes for which it may later be used.
Function creep and meaningful consent
Biometric data is frequently collected for a narrow purpose and later becomes attractive for another. A facial image gathered for account verification may be proposed for model training or watchlist screening. Employee access data may become a productivity-monitoring tool. Voice recordings collected for service quality may be converted into voiceprints.
This function creep changes the relationship with the individual. A customer who verified an account may not expect indefinite retention, group-wide sharing or additional inference.
Consent is especially difficult where there is an imbalance of power. An employee required to provide a fingerprint may have little practical freedom to refuse. A customer who cannot access an essential service without facial verification may not have a meaningful choice, even where a consent box appears on screen.
A defensible programme therefore requires purpose limitation and a genuine alternative where consent is relied upon. New uses should trigger a fresh assessment.
Why biometric compromise is different
Biometric data creates a distinctive security problem because the identifier is persistent. A person can change a password or payment card number after compromise. They cannot replace their face or fingerprints in the same way.
This does not mean that every leaked template can be replayed against every service. Systems use different sensors, formats and matching methods. Protected templates can also be designed so that a compromised representation is revoked and replaced.
The risk remains serious because the same characteristic may be reused across contexts. Facial images can support deepfakes, document manipulation or weaker verification attacks; voice recordings can enable impersonation.
Stolen biometric material may therefore be used against a recognition system or to strengthen the wider criminal identity package surrounding account takeover, authorised push payment fraud or business email compromise.
How criminals attack biometric systems
The most visible threat is a presentation attack: presenting a photograph, replayed video, mask, synthetic voice or artificial fingerprint to a sensor. Liveness and presentation-attack detection attempt to distinguish a live person from a reproduction, but performance varies by technology and attack method.
Remote onboarding creates additional exposure because the institution does not control the customer’s device or camera. Criminals can use emulators, virtual cameras, screen injection, modified applications and deepfake tools to bypass the physical capture process. The system may receive a clean video stream that never came from a genuine live customer.
Face morphing creates another risk. Images of two people can be blended so that one identity document may match more than one individual under certain conditions. NIST’s evaluation work on morph detection reflects the operational relevance of this problem.
Criminals also attack the recovery path. If biometric authentication fails, the service may fall back to passwords, one-time codes, call-centre questions or document uploads. A strong biometric front door provides limited protection where the fallback route is easier to manipulate.
The most resilient institutions assess the complete identity journey. Biometrics should contribute evidence, not create a false assumption that the person has been conclusively identified.
Accuracy, bias and customer harm
Biometric recognition is probabilistic. A false match occurs when different people are treated as the same person; a false non-match occurs when the genuine person is rejected.
A false match can grant access to an impostor or lead an organisation to accuse an innocent customer of suspicious activity. A false non-match can exclude a legitimate customer, delay a payment or force someone into an onerous manual process.
NIST testing shows that performance can vary materially across algorithms, image quality and demographic groups. Lighting, camera angle, ageing and under-representation in training data can influence results. This does not mean every system is uniformly biased or inaccurate. It means firms must test the specific product under conditions resembling their population and operating environment.
A vendor’s headline accuracy rate is not enough. Institutions need to understand the threshold used, expected error rates, performance across relevant groups and how adverse outcomes are reviewed. High-impact decisions should not rely solely on an automated biometric output.
For FinCrime operations, poor accuracy creates a double risk. Weak thresholds may allow impersonators through, while overly strict thresholds may block legitimate customers and generate unnecessary fraud referrals.
Third-party and supply-chain risk
Many organisations purchase cloud matching services, liveness tools and identity-verification platforms from specialist vendors. Data may pass through several processors before the decision returns to the institution.
The firm needs to know where samples and templates are stored, whether data is used to train vendor models, who can access it, how long it is retained and whether it crosses jurisdictions. Contracts should define deletion requirements, breach notification, model changes, subcontracting and access to testing evidence.
The institution should understand the effect of vendor acquisition, insolvency or changed data terms. Outsourcing technology does not outsource accountability.
What a resilient control stack looks like
The first layer is necessity and purpose. The organisation should document the specific risk the biometric system addresses and why a less intrusive method is insufficient.
The second layer is data minimisation. Where possible, verification should occur on-device, with the organisation receiving a trusted result rather than the biometric.
The third layer is template protection. Biometric references should be encrypted, segregated and designed for revocability where technically possible. Access should be restricted, logged and monitored.
The fourth layer is independent testing. Recognition and presentation-attack detection should be evaluated across relevant demographics, devices, lighting conditions and attack types. Material model changes should trigger revalidation.
The fifth layer is layered identity assurance. Biometrics should be combined with device intelligence, document validation, cryptographic authentication, behavioural signals and transaction context. No single modality should become an unquestioned source of truth.
The sixth layer is human review and accessible fallback. Customers need a workable route to challenge a failed match or automated decision. Reviewers must be able to correct the outcome rather than repeat the same check.
Finally, retention and deletion must be operational controls. Samples, videos and templates should be removed when the purpose expires, including in vendor environments.
What an effective incident response looks like
A biometric incident requires more than resetting credentials. The organisation should establish exactly what was exposed: original images, voice recordings, templates, liveness data, decision scores or linked identity records.
Affected templates may need to be revoked and customers re-enrolled. Fraud teams should monitor for impersonation, account recovery attempts, beneficiary changes and unusual access linked to the affected population.
The institution should also assess secondary misuse. Compromised facial or voice data may appear in deepfake-enabled social engineering even where it cannot be replayed directly against the original system.
Customers need specific guidance on the exposed data, affected services and additional monitoring.

What this means for financial crime leaders
Biometrics can strengthen remote onboarding, authentication and account-takeover prevention. They can also create durable identity risk when deployed without clear purpose, reliable testing or lifecycle governance.
Leaders should ask whether every use is necessary, whether customers have meaningful alternatives, whether performance has been independently tested and whether a compromise can be contained without permanently disadvantaging the individual.
The strongest programmes will avoid treating biometric technology as either infallible security or unacceptable surveillance. They will use it as one governed component of layered identity assurance, connect biometric events with fraud and transaction intelligence, and preserve human accountability for high-impact decisions.
Biometric data can make identity harder to steal. Poor biometric governance can make the consequences of theft harder to escape.




Biometric technology can strengthen identity verification, reduce impersonation and improve protection against account takeover. However, its effectiveness depends on far more than the sophistication of the recognition model. The real control challenge lies in how biometric data is collected, tested, stored, shared, retained and used within wider corporate decision-making.
Unlike passwords or payment cards, biometric characteristics cannot be easily replaced after compromise. Poor governance can therefore create persistent identity, privacy and conduct risks. Excessive retention, weak vendor oversight, inaccurate matching, hidden secondary uses and insecure fallback processes can undermine the very protections that biometric systems are intended to provide.
A resilient approach requires clear purpose limitation, data minimisation, independent performance testing, robust template protection and meaningful human review. Biometrics should operate as one component of layered identity assurance, supported by device intelligence, behavioural analysis, cryptographic authentication and transaction monitoring.
Financial crime leaders should also ensure that biometric failures and breaches are treated as potential fraud events rather than solely as privacy or technology incidents. Compromised facial, voice or behavioural data may be used to support impersonation, account recovery abuse, deepfake-enabled scams and wider identity theft.
Ultimately, biometric security is not defined by whether an organisation can recognise a face, voice or fingerprint. It is defined by whether the organisation can use that capability proportionately, explain its decisions, protect the underlying data and contain the consequences when the technology fails.