Appendix A: Sample RFP Questions for Liveness Vendor Selection
Security & Certification
- Do you hold iBeta Level 1 and/or Level 2 certification? Provide certificate and report.
- What is your APCER per PAI species (print, screen photo, screen video, mask)?
- What is your BPCER at the operating threshold recommended for banking?
- Do you have deepfake detection capability? Against which deepfake types?
- How do you detect virtual camera injection attacks?
- What device integrity checks do you perform (root, jailbreak, emulator)?
- Have you submitted to NIST FRVT PAD? Provide results.
- How do you handle adversarial machine learning attacks?
Technical
- What is your SDK size (Android AAR, iOS framework)?
- What is your end-to-end latency (P50, P95, P99)?
- Do you support passive liveness, active liveness, or both?
- What is your minimum device/camera requirement?
- Do you support web browser-based liveness?
- What is your on-device vs server-side processing split?
- How do you handle poor lighting, blur, and partial occlusion?
Privacy & Compliance
- Where is biometric data processed and stored?
- Do you support data residency in India / EU / specific regions?
- Are you GDPR Article 9 and DPDPA compliant for biometric data?
- What is your data retention policy for biometric samples?
- Provide your Data Processing Agreement (DPA) template.
- What is your uptime SLA?
- What is your maximum concurrent verification capacity?
- How do you handle failover and disaster recovery?
- What is your average drop-off rate for genuine users?
Business
- What is your pricing model (per-transaction, tiered, flat)?
- What support tiers do you offer?
- What is your model update frequency?
- What are your SLA penalty terms?
- Provide 3 banking client references.
- What is your contract termination and data portability process?