Gambling in your blood

Selfie KYC fails triple when liveness checks run after 10pm

· 5 min read
Selfie KYC fails triple when liveness checks run after 10pm

Selfie-based identity checks fail roughly three times as often when they run between 22:00 and 02:00 than during the working day, according to verification data operators have been quietly circulating since late 2024. The pattern holds across document types and providers: a pass rate that sits near 91% at 14:00 can drop to around 68% after 22:00, with the worst window between 23:30 and 00:45. It is not a fraud spike. It is a lighting, fatigue and device-handling problem, and it lands hardest on the customers UK operators are least able to lose.

Why the after-10pm window breaks liveness detection

Liveness checks are not one technology. Most UK-facing vendors stack three tests: a passive texture and depth analysis of the face, an active challenge (turn your head, blink, read a phrase), and a comparison against the document photo. Each fails differently after dark.

Passive analysis

Passive models are trained on faces lit from the front, usually by a screen or a ceiling light. At 23:00 the dominant light source is often the phone itself — a 6.1-inch OLED panel held 30cm from the face at a slight angle. That produces a hard falloff across the cheekbones, a blown-out forehead and deep shadow under the brow. Depth estimation degrades because the shadow map no longer matches the geometry the model expects. Vendors report false "presentation attack" flags — the system deciding it is looking at a photo or a mask — rising from around 1.2% in daylight to 4-6% late at night.

Active challenges

Challenge-response tests assume the user can follow an instruction within a two-to-four second window. At 23:40, after a shift or a few drinks, reaction times lengthen and head turns overshoot. A test that requires the face to stay inside a 320-pixel oval for 1.5 seconds fails when the user is lying in bed with the phone above them and their arm drifting. This is the single largest contributor to the triple failure rate, and it is almost entirely a usability problem rather than a security one.

Document comparison

The selfie is matched against the photo page, usually captured seconds earlier. At night that page is often shot under the same poor light, with glare from a passport laminate or a driving licence hologram. A 2023 study of 40,000 remote onboarding attempts found document-capture rejection running at 2.9x the daytime rate after 22:00, and selfie-to-document mismatch at 2.4x. The two compound: a marginal selfie plus a marginal document capture produces a rejection neither would have caused alone.

The commercial case for fixing it, not just measuring it

A failed check is not a neutral event. In the UK, a customer who cannot pass verification at 23:00 does not simply retry at 09:00. UK Gambling Commission licence conditions require age and identity verification before gambling, and most operators block the account until it clears. The practical result is an abandoned deposit, a support ticket, and — for a meaningful share — a customer who signs up somewhere else the next evening.

The numbers are not trivial. If an operator onboards 4,000 new customers a month and 22% of attempts fall in the 22:00-02:00 window, that is 880 checks. Moving the failure rate from 32% to 12% in that window recovers around 176 verified customers a month. At a conservative first-deposit value of £45 and a 12-month retention curve, that is not a rounding error.

There is a compliance angle too. Section 3.4.1 of the Commission's remote gambling and software technical standards requires identity verification to be reliable and proportionate. A process that rejects a disproportionate share of legitimate customers on a time-of-day basis is neither. It is also, under the Equality Act 2010, a potential indirect discrimination issue: older customers, those with darker skin tones, and users on older handsets all show higher failure rates, and the night-time effect amplifies each of them.

Who gets hit hardest

Vendor data consistently shows the night-time penalty is not evenly distributed:

  • Users on handsets more than four years old: failure rate roughly 1.6x the average after 22:00, because low-light camera performance and slower processors affect both capture and on-device pre-processing.
  • Users with darker skin tones: passive liveness models have historically performed worse here, and low light narrows the margin further. One vendor's 2024 audit showed a 9-percentage-point gap in daylight widening to 19 points at night.
  • Users aged 55 and over: slower challenge completion and more frequent glasses glare.
  • Users in shared or public spaces: unwilling to perform a head-turn challenge, so they abandon rather than fail.

What actually reduces night-time failures

The fixes that move the number are mostly unglamorous and sit on the operator's side of the integration, not the vendor's model.

Loosen the challenge, not the threshold

The instinct is to lower the match threshold after hours. That is the wrong lever — it trades fraud resistance for pass rates. The better move is to drop the active challenge entirely when a passive score is already high, and reserve the head-turn for borderline cases. Vendors that have shipped this report night-time pass rates recovering to within 4-6 points of daytime without a measurable rise in fraudulent passes.

Give the user light

A one-line instruction — "move somewhere brighter" — before capture, with a live exposure meter, is worth more than most model upgrades. Operators that added a brightness gate (refuse to capture below a set lux threshold, prompt instead) saw selfie rejections in the night window fall by roughly a third. The cost is a small increase in abandonment at the point of prompt; the net is strongly positive.

Offer a route that is not a selfie

Bank-based verification, open banking checks, and for existing customers a re-verification via a known device and behavioural signals all bypass the problem. For a customer at 23:00 who has already deposited before, a step-up check is slower and more annoying than a selfie that works. For a new customer in bed, it is the difference between an account and a bounce.

Staff the night shift on the manual queue

Automated rejection should not mean instant dead end. Routing night-window failures to a manual review queue with a 15-minute target resolution, rather than a "try again tomorrow" message, converts a meaningful share. The economics only work if the queue is actually staffed — a review that lands at 09:00 has already lost the customer.

The question operators have not answered

The data says the problem is real, measurable, and fixable. What is less clear is whether the industry wants to fix it. Night-time verification failures are, in accounting terms, invisible: they do not appear as fraud losses or chargebacks, they appear as marketing spend that did not convert. That makes them easy to ignore and hard to justify a budget line for.

The harder question is what the regulator does with this. If a verification process systematically fails a protected group at a higher rate after 22:00, and the operator knows the number, at what point does "we use an industry-standard vendor" stop being a defence? The Commission has not published guidance on time-of-day verification performance. It may not need to. The first operator to publish its own night-window pass rates — and the gap between its daytime and night-time numbers — will force everyone else to measure theirs.