ISO 30107-3 PAD Explained: Demystifying iBeta Level 1 vs Level 2 for Fintech Compliance

Written by ARSA Writer Team



Blogs

ISO 30107-3 PAD Explained: Demystifying iBeta Level 1 vs Level 2 for Fintech Compliance

In the rapidly evolving landscape of digital identity, ensuring the authenticity of users is paramount, especially for compliance engineers in fintech. A critical component of this assurance is Presentation Attack Detection (PAD), and understanding ISO 30107-3 PAD explained and iBeta Level 1 vs Level 2 difference is fundamental for building robust and compliant systems. This guide will demystify these crucial standards, offering clarity on how they contribute to secure digital onboarding and transaction verification.

Presentation Attack Detection (PAD) refers to a biometric system’s ability to discern whether a biometric sample is from a live, authentic person or a fabricated artifact, commonly known as a “spoof.” As digital identity solutions become more sophisticated, so do the methods employed by fraudsters. Therefore, robust liveness detection is no longer a luxury but a necessity to meet stringent regulatory obligations such as PSD2, eIDAS, FinCEN, and RBI V-CIP.

The Foundation: ISO/IEC 30107-3 Presentation Attack Detection

The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) developed the ISO/IEC 30107 series to provide a comprehensive framework for biometric presentation attack detection. Specifically, ISO/IEC 30107-3 outlines the test methodology and reporting for PAD. This standard is crucial for evaluating the resilience of biometric systems against various spoofing attempts.

At its core, ISO 30107-3 defines Presentation Attack Instruments (PAIs) – the fake biometrics used in attacks – and establishes a structured approach for testing how well a system can detect them. These tests can evaluate a PAD subsystem, a data capture system (coupled with quality checks), or a full biometric system (including comparison capabilities). For PAD subsystem evaluations, the key performance metrics are Attack Presentation Classification Error Rate (APCER) and Bona Fide Presentation Classification Error Rate (BPCER).

Decoding iBeta Level 1 vs Level 2 PAD Certification Meaning

While ISO/IEC 30107-3 provides the standard, independent laboratories like iBeta conduct the actual testing. It’s important to understand that iBeta issues “conformance letters” indicating a product has been tested against the standard, rather than a blanket “certification” of the product itself. This distinction is vital for compliance engineers.

iBeta categorizes its PAD testing into different levels, with Level 1 and Level 2 being the most commonly referenced for face liveness. The distinction between these levels is critical for selecting the appropriate security posture for your digital identity application:

  • iBeta Level 1 PAD: This level focuses on detecting basic presentation attacks. These typically involve readily available equipment and low-cost artifacts, such as printed 2D photos, screen replays of videos, or simple paper masks. The testing is designed to simulate consumer-grade threats. For a system to achieve conformance at Level 1, it must demonstrate a 0% penetration or match rate against these types of attacks under controlled laboratory conditions. The materials used for these attack artifacts are generally limited to a cost of around $30.
  • iBeta Level 2 PAD: This level addresses more sophisticated and realistic spoofing attempts. Attack instruments at this level require moderate expertise to create and involve more expensive equipment, such as 3D printers, resin masks, or high-quality latex masks. The goal is to test against more advanced lab-crafted attacks. Systems aiming for Level 2 conformance are allowed a 1% penetration or match rate, reflecting the increased complexity of the attacks. The cost limit for Level 2 attack artifacts is typically around $300.

In 2025, iBeta also introduced Level 3 testing, which targets advanced adversary scenarios involving custom molds, hyper-realistic masks, and lab-grade fabrication, representing attackers with significant resources. It’s crucial to note that passing Level 1 does not automatically imply resistance to Level 2 or Level 3 attacks; each level requires distinct testing and builds on the rigor of the previous one. Vendors must typically clear Level 1 before attempting Level 2.

APCER BPCER Liveness Metrics Explained

When evaluating PAD solutions, understanding the metrics is as important as understanding the testing levels. The primary metrics for liveness detection are:

  • APCER (Attack Presentation Classification Error Rate): This metric quantifies the rate at which a presentation attack (spoof) is incorrectly classified as a bona fide (genuine) presentation. A lower APCER indicates higher security, as the system is better at rejecting fakes.
  • BPCER (Bona Fide Presentation Classification Error Rate): This metric measures the rate at which a bona fide presentation (a real user) is incorrectly classified as a presentation attack. A lower BPCER indicates better usability and a smoother user experience, as legitimate users are less likely to be falsely rejected.

These two metrics often present a trade-off: increasing security (lowering APCER) can sometimes lead to a higher rate of false rejections for legitimate users (higher BPCER), and vice-versa. Compliance engineers need to analyze the system’s Receiver Operating Characteristic (ROC) or Detection Error Trade-off (DET) curves to understand this balance and set appropriate thresholds based on their organization’s risk tolerance and user experience goals. For a “PASS” rating in iBeta testing, the BPCER and FNMR (False Non-Match Rate) are typically limited to 15% for Level 1 and Level 2, and 10% for Level 3, to ensure a reasonable level of usability.

Liveness Standards for KYC Compliance in Fintech

For fintech companies, adhering to robust liveness standards is not merely a best practice; it’s a regulatory imperative. Regulations like PSD2, eIDAS, FinCEN, and RBI V-CIP for video KYC mandate strong identity verification processes to combat fraud and money laundering. A solution that supports ISO/IEC 30107-3 PAD testing at appropriate iBeta levels helps organizations meet these stringent KYC and AML (Anti-Money Laundering) obligations.

It is critical to distinguish between presentation-attack detection (PAD), which is covered by ISO/IEC 30107-3 and iBeta Level 1/Level 2 testing, and injection attacks or deepfakes. Injection attacks bypass the camera entirely, feeding synthetic or manipulated data directly into the system, while deepfakes create highly realistic but entirely fabricated video or audio. While liveness detection is a necessary layer of defense, it is no longer sufficient on its own in 2026 to counter these advanced threats. A comprehensive security strategy must also consider measures against injection attacks and the detection of synthetic identities.

ARSA Technology understands these complex requirements. Our ARSA Face Recognition & Liveness API is designed to provide enterprise-grade biometric identity verification, offering both passive and active liveness detection capabilities to help prevent presentation attacks. With features like 1:N face recognition against a secure database, 1:1 face verification, and face detection with bounding boxes, it forms a critical layer in your digital identity strategy.

Building a Secure Digital Identity Framework with ARSA

Implementing a robust liveness detection solution doesn’t have to be a complex undertaking. The ARSA Face Recognition & Liveness API is a cloud SaaS solution engineered for rapid deployment, allowing you to launch face login or KYC processes in days, not months. Our API offers a ~5-minute first call setup, making integration seamless for developers.

Key functions include:

  • Face Database Management: Enroll and manage face collections within isolated per-account databases, ensuring data privacy and tenant separation.
  • Active and Passive Liveness Detection: Protect against spoofing with both passive liveness and active liveness, which includes challenge-response based head movement instructions.
  • Demographic Analysis: Gain insights with age estimation, gender classification, and expression detection (neutral, happy, sad, surprise, anger).

ARSA Technology is an NVIDIA Inception and Intel partner with over 7 years of experience, serving government, defense, and industrial clients across Asia Pacific. Our commitment to operational reliability and data control is reflected in our flexible deployment models, including on-premise and edge solutions for sensitive environments. For more insights into the business value of robust identity solutions, read about the ROI of ARSA Face Recognition & Liveness API.

Our API is accessible through a simple x-key-secret API key authentication, and all features are included across every pricing plan. You can start with a free 30-day trial offering 100 calls/month and 100 face IDs, with no credit card required. Paid plans like Pro ($29/mo), Ultra ($149/mo), and Mega ($1,290/mo) scale with your needs, ensuring you pay only for what you use without managing infrastructure. For detailed information, refer to our Face API pricing plans and Face Recognition API documentation.

Frequently Asked Questions

Q1. What is ISO IEC 30107-3 presentation attack detection?

ISO/IEC 30107-3 is an international standard that specifies the test methodology and reporting for Presentation Attack Detection (PAD) in biometric systems. It helps evaluate how effectively a system can distinguish between a live, genuine biometric presentation and a fake or spoof attempt, using defined Presentation Attack Instruments (PAIs).

Q2. What is the key difference between iBeta Level 1 and iBeta Level 2 PAD testing?

The primary difference lies in the sophistication and cost of the attack instruments used. iBeta Level 1 tests against basic, low-cost spoofs like printed photos, while iBeta Level 2 tests against more complex and expensive artifacts such as high-quality 3D masks, requiring moderate expertise to create. Level 1 allows 0% penetration, while Level 2 allows 1%.

Q3. How do APCER and BPCER relate to liveness standards for KYC compliance?

APCER (Attack Presentation Classification Error Rate) measures how often a spoof is accepted, indicating security. BPCER (Bona Fide Presentation Classification Error Rate) measures how often a real user is rejected, indicating usability. For KYC compliance, a balanced trade-off between low APCER (high security) and acceptable BPCER (good user experience) is crucial to prevent fraud while maintaining legitimate access.

Q4. Does ARSA Face Recognition & Liveness API help prevent deepfake attacks?

ARSA Face Recognition & Liveness API provides robust active and passive liveness detection to prevent presentation attacks (spoofing attempts using photos, videos, or masks presented to the camera). However, deepfake and injection attacks, which bypass the camera entirely, require additional layers of security beyond traditional liveness detection. ARSA’s solutions are designed to be part of a multi-layered security strategy.

Conclusion

Navigating the complexities of ISO 30107-3 PAD explained and iBeta Level 1 vs Level 2 difference is essential for compliance engineers in the fintech sector. By understanding these standards and the metrics like APCER and BPCER, organizations can make informed decisions about their biometric security infrastructure. Solutions like the ARSA Face Recognition & Liveness API offer a powerful, scalable, and compliant way to integrate advanced liveness detection, helping to prevent presentation attacks and meet critical regulatory requirements for digital identity verification. To explore how ARSA Technology can enhance your digital identity strategy, contact ARSA solutions team today.

Stop Guessing, Start Optimizing.

Discover how ARSA Technology drives profit through intelligent systems.

ARSA Technology White Logo

Legal Name:
PT Trisaka Arsa Caraka
NIB – 9120113130218

Head Office – Surabaya
Tenggilis Mejoyo, Surabaya
Jawa Timur, Indonesia
60299

R&D Facility – Yogyakarta
Jl. Palagan Tentara Pelajar KM. 13, Ngaglik, Kab. Sleman, DI Yogyakarta, Indonesia 55581

EN
ENEnglishIDBahasa Indonesia