Skip to navigation

      Deepfake videos, synthetic identities and generative AI are making it increasingly difficult to determine whether the person on the other side of a screen is real or not. Organizations using biometric verification need to be sure that their systems can detect and resist increasingly sophisticated fraud attempts.

      At KPMG's accredited biometric testing lab in Zurich, we recreate real-world attacks under controlled conditions. We test biometric systems against presentation attacks, deepfake attacks, virtual cameras and manipulated data streams. This shows how well they detect and respond to different forms of biometric manipulation.

      The result is independent evidence of how your biometric solution performs under attack conditions. Our evaluations help identify where the solution is vulnerable and how well its security controls detect and prevent manipulation.

      Reto P. Grubenmann

      Director, Head of Certification & Attestation

      KPMG Switzerland

      Matthias Bossardt

      Partner, Head of Cyber & Digital Risk Consulting

      KPMG Switzerland


      biometric attack mark
      swiss accreditation sts 0789
      ilac mra mark

      Get your AI governance certified with KPMG

      In addition to testing your biometric solutions, we also provide ISO/IEC 42001 certification for AI solutions.

      sresi

      Why independent biometric testing matters

      Biometric systems are widely used for digital onboarding, remote identity verification and trust services. As adoption increases, so does the need to test their security and reliability.

      Organizations use independent testing to:

      • Test security and resilience objectively
      • Identify vulnerabilities before deployment or certification
      • Support certification and conformity assessment
      • Provide independent evidence to customers, auditors and regulators
      • Strengthen procurement and due diligence


      An accredited biometric testing laboratory can help technology providers demonstrate that their security controls perform as intended. 

      It can also provide additional assurance during customer evaluations.


      Is biometric testing relevant for your organization?

      Biometric testing may be relevant if you develop, provide or use biometric technologies for identity verification, authentication or other critical processes.

      This includes:

      • Biometric technology and identity verification providers assessing solutions used to verify biometric identities, identity documents or other supporting evidence in digital services
      • Financial institutions and other organizations using biometrics for digital onboarding processes, authentication or electronic transactions
      • Qualified Trust Service Providers (QTSPs) supporting digital trust and assurance services
      • Government entities and EUDI Wallet ecosystem participants preparing for digital identity and compliance requirements
      Factsheet: Protecting biometric systems

      Factsheet: Protecting biometric systems

      Protect your biometric systems against fraud and deepfakes

      Why KPMG's software testing laboratory?

      • More than 20 years of digital identity and trust expertise

        For more than two decades, KPMG has evaluated and certified digital identity systems, trust services and security-critical technologies.

        Our experts combine accredited testing with experience in digital trust and regulation assessment.

      • From product validation to certification readiness

        Your testing needs depend on your product, market and objectives.

        KPMG helps choose the right testing approach for your goals – from market launch and customer requirements to certification and conformity assessment.

      • Internationally accredited biometric testing

        KPMG tests biometric solutions against recognized international standards.

        These assessments help organizations test their security, resilience and performance under defined conditions.


      What we test

      • Resistance to spoofing attacks

        Can your biometric system detect and reject attempts to spoof the sensor?

      • Resistance to deepfakes and injection attacks

        Can your system detect manipulated biometric data before it reaches the authentication process?

      • Biometric accuracy and reliability

        How accurately does your system recognize legitimate users under real-world conditions?

      What is a presentation attack?

      A presentation attack targets the biometric sensor.

      Instead of a genuine user being physically present, an attacker presents a fraudulent biometric sample to a camera, a fingerprint reader or another sensor.

      Common examples include:

      • A printed photo presented to a camera
      • Video replays displayed on another device
      • Silicone and 3D-printed masks designed to resemble a legitimate user
      • Artificial fingerprints and other physical spoofing artifacts

      Presentation Attack Detection (PAD), also called biometric spoofing detection, checks whether the system can detect and reject these attacks. At the same time, legitimate users should still be able to authenticate successfully.

      For facial recognition systems, advanced liveness detection helps determine whether a live person is in front of the camera rather than a photograph, replayed video or other fraudulent presentation. Depending on the use case and technology, liveness detection may be active or passive.

      Presentation attack detection (PAD) testing: and, where applicable, a face liveness detection test, assess how effectively these controls detect and reject presentation attacks.

      What is an injection attack, and why do deepfakes matter?

      Unlike a presentation attack, an injection attack bypasses the physical sensor. The attacker inserts or manipulates biometric data within the software, hardware or communication flow used for enrollment or verification.

      Common examples include:

      • Deepfake-generated biometric samples, including face swaps that alter or replace facial features
      • Virtual camera attacks
      • Manipulated video streams
      • Mobile device application hooking
      • Synthetic biometric data introduced during enrollment or verification

      A deepfake injection attack can introduce manipulated biometric data directly into the authentication process. The physical sensor is bypassed, so controls designed to detect presentation attacks may not identify this type of manipulation.

      Injection Attack Detection (IAD) addresses this risk by assessing whether manipulated biometric data can be detected as such within the processing flow. Injection attack detection testing, including deepfake detection testing, evaluates how effectively these controls identify and reject such attacks.

      How we evaluate your biometric system: 4 steps

      • Understand your technology and goals

        We first discuss your biometric solution, use case and evaluation goals. We then define the relevant attack scenarios, standards and level of assurance.

      • Define the testing approach

        We create a test plan based on the agreed scope. It covers a wide range of attack vectors, test methods and technical requirements.

      • Simulate real-world attacks

        We perform the agreed tests using recognized procedures. We then evaluate how the system responds to presentation attacks, injection attacks and other relevant threats.

      • Review the results

        You receive a detailed evaluation report that documents the test scope, methods, results and findings. Where applicable, we also issue a Statement of Conformity.


      What you receive

      At the end of the evaluation, you receive documented results showing how your solution performed against the agreed test scenarios.

      Depending on the scope of the evaluation, this may include:

      • An accredited evaluation report documenting the test scope, methods and results
      • Detailed findings on vulnerabilities and areas for improvement
      • Test results against defined criteria for the relevant attack scenarios
      • Supporting documentation for certification or conformity assessment, where applicable
      • A Statement of Conformity (SoC), where applicable

      Standards we test against

      Our evaluations follow recognized international standards for biometric security, attack detection and biometric recognition performance testing.

      Relevant standards include:

      • ISO/IEC 30107-3:2023

        PAD testing and reporting

      • ISO/IEC 19989-3:2020

        Presentation Attack Detection (PAD) evaluation

      • CEN/TS 18099:2025

        Biometric Injection Attack Detection (IAD), Injection Attack Method (IAM) and Injection Attack Instrument (IAI) 

      • ISO/IEC 19795-1:2021

        Biometric performance testing and reporting (PERF)


      Frequently asked questions

      The right level depends on your biometric system, use case, risk exposure and certification goals. During the scoping phase, KPMG helps determine which level best fits your requirements.

      Accredited evaluation reports can provide independent evidence for broader conformity assessment and certification.

      This may include initiatives involving ETSI TS 119 461 and eIDAS 2.0 remote identity verification, depending on the applicable scheme.

      The timeline and cost depend on your biometric solution, evaluation scope, applicable standards, attack scenarios and desired level of assurance.

      Once the scope is clear, KPMG provides a detailed proposal and quotation.

      What we need depends on your biometric solution and testing goals. This may include software components, technical documentation, test environments and other information needed for the assessment.

      The results show where your system may need improvement. You can use these findings to address vulnerabilities before a subsequent assessment.

      We test your solution in a secure environment under strict confidentiality requirements. Only personnel involved in the evaluation can access your systems, software, documentation and test data.


      Ready to assess your biometric system?

      Not sure which tests or standards apply to your biometric solution?

      Speak with our experts about your system, relevant attack scenarios and the right testing approach.

      Meet our experts

      Reto P. Grubenmann

      Director, Head of Certification & Attestation

      KPMG Switzerland

      Matthias Bossardt

      Partner, Head of Cyber & Digital Risk Consulting

      KPMG Switzerland

      Related articles and more information

      Implement ISO/IEC 42001 for responsible AI governance. Swiss firms can build trust, mitigate risks, and ensure ethical AI with KPMG's expert guidance.