// identity · fintech · peru
KYC and liveness: digital onboarding and the SBS
Opening an account, applying for a loan, or signing up in seconds — without setting foot in a branch — is the promise of digital onboarding. But that same speed opened a door to fraud: today deepfakes already defeat selfie checks and weak liveness controls. In Peru, if your company is supervised by the SBS, verifying identity remotely is not optional — and doing it badly is a fraud risk and a regulatory-sanction risk at once. This guide explains the two layers of digital KYC, what the SBS requires, the standard against deepfakes, and how it all integrates — drawing on the experience of putting RENIEC identity validation into production.
SBS 2660-2015
the regulation that mandates identity verification
ISO 30107-3
the liveness (prueba de vida) standard (PAD)
Level 2
the market minimum for banking KYC
Sensitive data
biometrics under Law No. 29733
KYC isn't one thing: it's two distinct questions
Digital KYC has two layers that are often confused: (1) is the ID real and do the details match? — RENIEC answers that; and (2) is there a living person, and are they the one on the ID? — facial biometrics with liveness (prueba de vida) answers that. You need both: one alone is not enough.
Conflating these two questions is the root of most weak controls. The first is about identity: verifying against the official registry that the DNI exists and that its details match the holder — exactly what RENIEC validation resolves. The second is about presence: confirming that whoever is in front of the camera is a real, living person — not a photo, a video, or a deepfake — and that their face matches the one on the document. A system that validates the DNI but not the person lets anyone through with a stolen photo; one that validates the face but not the DNI has no idea who it is comparing against.
What liveness (prueba de vida) is — and why a selfie is no longer enough
Liveness (prueba de vida) confirms that a real, present person is in front of the camera — not a photo, a video, or a mask. It can be active (asking for gestures: turn, blink) or passive (asking for nothing). Without it, a stolen selfie or a deepfake clears the check with no trouble.
For years, “upload a selfie” felt like enough. It no longer is. Real-time deepfake tools exist that are built specifically to beat identity verification and liveness controls in banking onboarding. The defense isn't “having biometrics” — it's having liveness capable of telling a real person apart from an imitation — and that is measured against a standard.
The standard against deepfakes: ISO/IEC 30107-3
The international standard for measuring liveness (prueba de vida) is ISO/IEC 30107-3 (PAD, presentation attack detection). It classifies attacks into three levels, and level 2 — which withstands videos, masks, and basic deepfakes — is the market minimum for banking KYC.
| PAD level | Withstands | Typical use |
|---|---|---|
| Level 1 | Printed photos, static screens | Minimal protection |
| Level 2 | Replayed videos, masks, and basic deepfakes | Market minimum for banking KYC |
| Level 3 | Real-time deepfakes, high-end 3D masks | High risk / sophisticated fraud |
Requiring ISO 30107-3 level 2 as a minimum (often certified by labs such as iBeta) is today the de facto standard for banking and fintech. Robust defense combines active and passive liveness, facial comparison against the document, and end-to-end encryption. Without a certification behind it, “we have liveness” is a claim with nothing to back it.
What the SBS requires (and what it does NOT)
The SBS does not impose a single technology. It takes a principles-based approach: integrity of the capture, binding the customer to their document, traceability of the verification, and proportionality of the control to the risk. In other words: you choose the how, but you have to prove the what.
SBS Resolution No. 2660-2015 (the AML/CFT Risk Management Regulation) requires due diligence to identify and verify the customer, and it grades that diligence — simplified, standard, or enhanced— by the risk profile. What's telling is that the SBS doesn't dictate “use this software”: it sets principles and lets you choose the solution, as long as you can prove integrity and traceability. That freedom is precisely why regulated onboarding is built to the measure of each operation, rather than bought identical for everyone.
Biometrics are sensitive data: Law 29733
Under Law No. 29733 and its new regulation, biometric data is sensitive data, with strict obligations: consent, a declared purpose, security, and retention limits. Storing faces or fingerprints “just in case” isn't only bad practice — it's a legal risk.
Your customer's face is not just any piece of data: it's sensitive data, and mishandling it exposes the company. Onboarding has to capture consent, use the biometrics only for the declared purpose, protect them, and keep them no longer than necessary. It's a design clause, not a legal detail to bolt on at the end.
How the onboarding is assembled, layer by layer
A compliant onboarding chains several pieces together: document capture, validation against RENIEC, biometric capture with liveness (prueba de vida), facial comparison, screening against AML/CFT lists, and traceability of the whole process. Each layer answers part of what the SBS requires you to prove.
- 01Document (DNI) capture and data extraction via OCR.
- 02Validation against RENIEC: that the DNI exists and the details match the holder.
- 03Biometric face capture with liveness (prueba de vida / PAD level 2).
- 04Facial comparison: the live face against the document holder's.
- 05Screening against AML/CFT lists according to the applicable due diligence.
- 06Traceability: log every step, with what result and when — the SBS requires it.
Buy or build: what's a commodity and what's yours
The biometrics and liveness (prueba de vida) engine is a commodity: certified providers exist — don't reinvent it. What gets built to measure is the integration: how those pieces (RENIEC, liveness, lists) are orchestrated within your onboarding flow, with your risk rules and your traceability.
Building your own liveness engine is an expensive mistake: it requires certification, constant research against new attacks, and a scale that makes no sense to reinvent — it's a commodity worth buying. What no provider hands you ready-made is your onboarding: which layers you apply by risk, how they connect to your core, what you do when a validation fails, and how you leave the audit trail the SBS will ask you for. That is custom integration, and it's where the real work is.
How we do it
We integrate identity validation into production systems — RENIEC in real time in the cashier of a national university. For regulated onboarding, we orchestrate RENIEC, certified biometrics, and traceability inside your flow, meeting the SBS principles and the sensitive-data treatment of Law 29733.
We don't sell a biometrics engine: we integrate whichever certified one suits you — together with RENIEC validation and your business rules, in an onboarding that meets the SBS principles and protects the sensitive data. We choose the pieces with you, solve the technical part, and connect it to your operation, with the traceability the regulation demands.
In short
Digital KYC is two questions — real DNI? living person? — and you need to answer both: RENIEC for identity, certified liveness (prueba de vida) (ISO 30107-3 level 2) for presence. The SBS lets you choose the technology but requires you to prove integrity and traceability; Law 29733 obliges you to treat biometrics as the sensitive data they are. Buy the engine, which is a commodity; build the integration, which is yours. Done right, your onboarding is fast for the legitimate customer and a wall against fraud.
Sources
- SBS — Resolution No. 2660-2015, AML/CFT Risk Management Regulation
- Altimea — Facial biometrics in Peruvian fintech: the SBS and digital onboarding
- Didit — ISO 30107-3 vs. iBeta PAD Level 2: liveness detection standards
- Altimea — Deepfakes and identity fraud in Peruvian banking (2026)
- Law No. 29733 — Personal Data Protection Law (Government of Peru)
Can your onboarding survive a deepfake?
We integrate identity, liveness (prueba de vida), and traceability into an onboarding that meets the SBS principles — talking to an engineer, not a salesperson.
