Business
Business FAQ: TrueFace in KYC, AML and trust workflows
Scope, limits, interpretation and validation evidence — phrased in the language of NIST, FATF, FinCEN and FCA guidance, without compliance claims.
What is TrueFace's role in a KYC process?
TrueFace is a supporting control, not a KYC solution. It analyses a submitted face image and scores how likely it was digitally altered, filtered or synthetically generated. That output informs the reliability of submitted identity evidence inside a broader Customer Due Diligence process owned by the institution.
Does TrueFace verify or confirm identity?
No. TrueFace does not confirm who someone is. It does not match a face to a document or database, does not authenticate identity documents, and does not screen sanctions, PEP or adverse-media sources. Identity proofing under NIST SP 800-63A and CDD under FATF remain broader processes.
Which standard makes image-manipulation analysis relevant to onboarding?
NIST SP 800-63A-4 (2025) states that organisations conducting remote identity proofing SHALL analyse all digital media submitted during identity proofing for artifacts and indicators of potential modification, manipulation, tampering or forgery, and SHOULD analyse it for signatures of generative-AI algorithms and deepfake tools. TrueFace addresses that specific analysis step.
Is TrueFace liveness detection or presentation-attack detection?
No. Presentation-attack detection determines whether a biometric sample is an attack rather than a genuine live presentation, with performance conformant to ISO/IEC 30107-3:2023, and requires control of the capture session. TrueFace analyses an existing image and therefore is not liveness or PAD.
What does the forensic reconstruction actually show?
When a face shows signs of alteration, TrueFace may attempt a reconstruction and shows an approximation of the likely true appearance only when reconstruction confidence is adequate. Otherwise it returns the detection report alone. The reconstruction is an approximation, never a claim about a specific person's real appearance.
How should our decision engine consume the score?
As a risk signal that routes work, not as a verdict. No manipulation detected means no detected anomaly, not proof of authenticity. Manipulation detected or high AI-generated likelihood should trigger an original or live capture request, document verification, biometric comparison, or manual review and enhanced due diligence.
Can TrueFace produce false positives and false negatives?
Yes. Heavy recompression, screenshots, resizing and social-media processing erase forensic artifacts, and new generative models leave fewer traces. NIST expects automated media-analysis algorithms to have their false-positive and false-negative rates established, documented and made available to relying parties on request.
What validation evidence should we request in procurement?
Dataset composition (genuine, retouched, face-swapped, morphed, fully generated), generator coverage, performance on generators unseen during training, threshold analysis, demographic breakdown, degradation behaviour under compression and screenshotting, adversarial testing, and how performance is re-established as new generative models appear.
Does TrueFace detect face morphs?
Morph detection is a distinct forensic task, covered by NISTIR 8584, and must be validated against morph datasets specifically. Treat any morph-related capability as unproven for your workflow until it has been evaluated on your own data.
Does using TrueFace make our onboarding compliant?
No. TrueFace makes no compliance or certification claim, and no single tool creates compliance. Regulatory obligations under FATF-aligned regimes, FinCEN rules or FCA requirements remain with your institution.