Back

Why biometrics is the new face of trust

Biometric payments can make checkout faster and easier, but the biometric itself only authenticates the customer. For PSPs and ISOs, the bigger challenge is making sure that authentication works reliably in real-world environments, handles fraud risk properly and has a clear fallback when it fails. Biometrics are most useful when they sit alongside existing payment options rather than becoming a dependency.

Key Insights

  • Biometrics authenticate the customer rather than move the money, with the payment still coming from the card, wallet or bank account linked underneath.

  • The right biometric depends heavily on the checkout environment, because lighting, noise, hardware and how customers interact with the system can all affect performance.

  • A quick biometric payment depends on what happens before checkout, particularly how easily customers can enroll and how securely their biometric template is stored.

  • Stronger fraud checks can introduce more friction, so providers need to balance liveness detection and step-up authentication against the speed biometrics are meant to provide.

  • Failure handling matters as much as successful authentication, with false rejects, false accepts and unclear liability all creating operational and commercial risks.

  • Biometrics work best as one option within a wider payment setup, with alternative ways to authenticate and pay available when the biometric does not work.

Don't have time to read more now? Sign up to our newsletter to get the latest insights directly in your inbox. 

What’s happening when you pay with a biometric?

A bouncer at the door checks your face against a list and nods you through. He’s confirmed who you are, and whatever you spend once you’re inside is between you and the bar. 

That’s closer to what’s happening every time someone pays with a scan of their face, palm or fingerprint than most people realize. It looks like the biometric is doing the paying (no card, no PIN), but the actual payment still comes from your card, wallet or bank account.

We’ve already explored how consumers feel about biometric payments and found that the technology is becoming more familiar… but familiarity only gets you so far. For biometric payments to become something businesses can rely on, the technology behind that simple scan has to work too. 

So what happens behind that biometric check? And what needs to work across the payment stack for PSPs, ISOs and merchants to rely on it? Let’s start by stripping the payment back to what’s actually happening.

What is a biometric payment?

A biometric payment uses a physical or behavioral characteristic - your face, fingerprint, palm, iris or voice - to confirm you’re the person authorized to make the transaction. Our biometric explainer goes deeper into how the technology works, where it’s already being used and some of the questions around security and trust.

Biometric authentication can already sit inside mobile wallets and banking apps, on biometric payment cards or directly at a physical checkout.

  • At the checkout, it can feel as though your biometric is the payment method itself. But in truth the biometric only authenticates you; it doesn’t move any money - that comes from the card, wallet or bank account sitting underneath the transaction.

    Biometric payment methods vary, but the basic principle is the same: a physical trait is captured and compared against a stored reference, and the payment can proceed if there’s a match.

    The appeal is obvious: there’s no PIN to remember or password to type, and a biometric can add another way of proving the person paying is who they claim to be. But whether that actually improves the payment depends on where and how it’s being used.

  • Woman being scanned for biometric payment

Not every biometric makes sense at every checkout

A biometric that works brilliantly on your phone can struggle at a busy checkout, and that’s down to the environment, not the technology.

  • Face scans tend to translate well to in-person payments: they’re contactless and relatively quick, and people are increasingly familiar with them from everyday smartphone use. The trade-off is that lighting, camera position and the way someone presents to the camera can all affect the capture.
  • Palm scans offer a similarly contactless experience and can be quick to use, but the customer still needs to position their hand correctly.
  • Fingerprint is the biometric most people already trust, but a dirty register, a plaster, or difficulty placing a finger correctly can get in the way.
  • Voice recognition sounds sensible until you remember most checkouts are noisy, making reliable voice capture more difficult.
  • Iris recognition can offer a high level of accuracy, but the hardware and capture process make it less practical for everyday retail.

There’s another factor worth considering too: how much independent testing sits behind each method. Face recognition has been tested extensively by the US government's National Institute of Standards and Technology, across different situations and with large numbers of people, while other biometric payment methods just haven’t been put to that same scrutiny yet. 

Independent testing can help expose bias, including whether a biometric is more likely to misidentify some groups of people than others, as well as how well it performs outside controlled conditions.

The takeaway for PSPs and ISOs building out biometric payment solutions? Don’t choose a biometric because it sounds advanced - choose it because it suits where and how your merchants’ customers are actually paying.

The tricky bit happens before you pay

Before anyone scans their face at a checkout, the system needs to know what that face looks like and which payment method it’s linked to. That’s called enrollment - and where it happens can make a big difference to the experience.

Enrolling calmly on your phone at home, before you ever reach a store, is a very different experience from being asked to register your face at a checkout while a queue builds behind you. 

Then there’s the question of where the biometric data lives once it’s been captured.

Some systems keep the check on your own device, with your phone confirming it’s you and simply telling the payment system you’ve been authenticated. Others involve a provider storing and comparing a biometric template through their own infrastructure, which means more parties potentially handling that information.

Either way, the system converts your identifying facial features into a mathematical template, which is what gets stored. While that offers some protection, it still leaves questions around who created that template, where it’s stored and who’s responsible for it if something goes wrong. 

That also brings regulation into the picture, because biometric data is treated more sensitively than ordinary personal data and can come with stricter requirements around how it’s collected and used.

For PSPs signing up biometric partners on a merchant’s behalf, all of that needs to be clear before the contract is signed, not after.

More security can mean more friction

The more convincing a fake becomes, the harder a payment system has to work to prove it’s dealing with a real person.

Spoofing isn’t new. People have been trying to fool biometric systems for years, whether that’s with a photo, a video or even a fake fingerprint. The difference now is how sophisticated those attempts have become, with deepfakes and injection attacks making it harder for payment systems to tell what’s real.

That’s where liveness detection comes in - essentially, the system asking: "Is this a real person who is actually here?" Passive liveness carries out the check in the background without asking you to do anything, while active liveness asks you to do something, like turning your head to prove you’re present. 

The problem is that every extra check to catch a fake adds friction to a payment that’s meant to be quick. Some systems handle this with step-up authentication instead: a normal transaction sails through on the standard checks, while anything that looks unusual triggers an extra step. That means keeping the normal payment experience simple, while having extra checks ready when something needs a closer look.

Biometric payments are easy until they don’t work

A biometric payment can feel incredibly simple when everything works: a scan, a quick confirmation and the customer is on their way. The real test comes when the system gets it wrong. 

There are two ways a biometric check can get it wrong:

  • Icon restrict access

    False reject

    A false reject is exactly what it sounds like: a genuine customer presents their own face or palm, and the system says no.

    What happens next? They try again, or they give up and reach for their card instead.

    For a merchant, those moments can mean longer queues, abandoned purchases and more pressure on staff.

  • Icon personal improvement

    False accept

    A false accept is the opposite: the system lets the wrong person through. Someone who shouldn’t match the stored biometric is accepted as the right person, and the payment can continue as though authentication succeeded.

    That creates a much trickier question than a retry: if that leads to a fraudulent payment, who carries the loss - the merchant, the PSP or the biometric provider? 

Unfortunately, there isn’t one single answer that applies to every biometric setup. It depends on the specific way the biometric is built into the payment stack and how responsibility has been agreed between the parties.

For PSPs and ISOs, that’s something worth pinning down before integrating a partner, not after the first dispute appears.

Biometrics should be another option, not another dependency

Biometric payments will get better. The technology will become more familiar, the checks will get harder to fool and more merchants will find places where a face, palm or fingerprint genuinely improves the payment experience.

But none of that means a payment setup should depend on biometrics working perfectly every time.

For PSPs and ISOs, the priority is making sure biometrics can sit alongside the rest of the payment experience, with other ways to authenticate and pay when they’re needed. It should be possible to add new partners and capabilities without rebuilding the whole setup around one biometric solution.

That’s where payment orchestration comes in. Aevi’s platform gives payment providers more flexibility over how different payment capabilities fit together, so biometrics can be added alongside existing options without becoming a dependency.

Talk to Aevi about building a payment setup that leaves room for whatever comes next.

Get our Aevi newsletter straight to your inbox!

Stay tuned for market insights, announcements and much more.

By completing this form, I accept Aevi's privacy policy.