Home > Cybersecurity > Expert Contributor

The Face as a Key: The Strategic Decision Behind Bank Biometrics

By Aarón Porraz Capetillo - IQSEC
CEO

STORY INLINE POST

DIA assistant
Aarón Porraz Capetillo By Aarón Porraz Capetillo | CEO - Wed, 08/05/2026 - 05:30

share it

The amendment to the Circular Única de Bancos — the regulatory framework that consolidates the rules applicable to credit institutions in Mexico, issued by the National Banking and Securities Commission (CNBV) — was published on July 1 and, outside the financial sector, likely went almost unnoticed. It shouldn't have. By incorporating facial recognition as a valid identification mechanism, alongside the fingerprint scanning already required for in-person openings of certain higher-risk accounts, Mexico's regulator has just handed banks a decision that goes far beyond compliance: what kind of trust do they want to build for the next decade?

It's worth framing it this way because Mexico isn't moving in this direction alone. The European Union is advancing its electronic identification regulation, eIDAS, toward a digital identity wallet for all its citizens. India, for its part, built the world's largest biometric identity system in Aadhaar, with more than a billion people enrolled. And across much of Asia and Latin America, banks already condition sensitive transactions on biometric verification. Wherever you look, verifiable identity is becoming the foundational layer of the digital economy.

What sets the Mexican case apart is a national biometric database: that of the National Electoral Institute (INE), the authority that manages the voter ID card, against which banks can now cross-check their customers' identities. It's worth clarifying a point that often gets muddled in public conversation: biometric validation in Mexican banking is not new. Banks have already been verifying fingerprints against that electoral database, precisely to mitigate the risks of identity theft, money laundering, and terrorist financing. What's changing now is the expansion to a second biometric factor and, with it, the maturing of the technical scaffolding around it.

The rule, moreover, doesn't stop at generalities: it points to concrete international standards, citing the U.S. National Institute of Standards and Technology (NIST) for biometric matching engines and ISO 30107, from the International Organization for Standardization, for presentation attack detection — that is, attempts to fool the system with photographs, masks, or videos. So this isn't the beginning of something; it's the consolidation of it. And consolidations, in financial regulation, tend to be the moment that separates organizations that execute with vision from those that merely execute.

Two Paths, Two Risk Profiles

The regulation presents institutions with a choice that's far from trivial. Banks can validate customer identity by querying the electoral institute's database with every transaction, or they can build their own biometric repositories for subsequent authentication.

The first path requires less investment and less custodial responsibility. The second offers operational autonomy, but it turns the bank into the custodian of one of the most sensitive assets that exists: biometric data that, unlike a password, cannot be reset. That's why the regulation requires institutions that opt for their own databases to implement robust encryption, network segmentation, access controls that log every employee who interacts with the data, and explicit mechanisms to prevent copying of the repositories.

And here it's worth sharing something we've seen up close while working with financial-sector organizations: the costliest mistake is almost never the technology chosen, but underestimating the governance that technology demands. That means privacy notices aligned with the actual purpose of data processing, limited-use policies, and a zero-trust architecture — the security principle that assumes no user or device is trustworthy by default — that acknowledges the traditional perimeter no longer exists.

The Threat That Won't Wait

There's also a risk that requires looking beyond the regulatory calendar. The most sophisticated attackers already practice a tactic known as "harvest now, decrypt later": they steal encrypted data today that they can't yet read, betting that quantum computing will let them decrypt it within a few years. Biometric data is the perfect target for this strategy, because its value never expires. The person who opens an account today will still have the same face and the same fingerprints when today's encryption algorithms become vulnerable.

The international response is already underway. NIST published its first post-quantum cryptography standards in 2024, designed to withstand future quantum computers. The practical takeaway for Mexico is clear: institutions designing biometric databases today should already be verifying that the encryption protecting their infrastructure can evolve toward algorithms built to withstand those technological advances.

The compliance deadline will arrive soon, and every bank will meet it one way or another. But the question boards of directors should be asking — in Mexico and in any market moving toward digital identity — is a different one: when customer identity becomes the gateway to every service you offer, will your organization have simply checked a box, or built a competitive advantage? That difference is being decided right now.

  
About IQSEC
  
IQSEC is a 100% Mexican company with nearly two decades of specialized experience in cybersecurity, cryptography, digital identity, and artificial intelligence. We have dedicated research and development as well as cyberlegal departments, enabling us to anticipate market trends through continuous monitoring and the creation of proprietary technological solutions, including advanced digital identity and cybersecurity products. Our portfolio includes unique national success stories and cutting-edge architectures such as cybersecurity mesh. IQSEC adopts a consultative approach focused on generating value with a technology-agnostic vision and proven integration capabilities across both public and private sectors. Our Cyber Risk Operation Center (CROC) enhances organizational risk management, while our talent development programs reaffirm our commitment to social responsibility. Backed by our own infrastructure, solid financial footing, and thought leadership, IQSEC has established itself as a strategic partner for organizations seeking resilience and comprehensive protection against evolving cyber threats.
 

You May Like

Most popular

Newsletter