From Passport to Digital Identity: What Know Your Passenger Means for the Future of Travel
AO commentary on Facephi analysis of the Know Your Passenger model
Facephi has published an analysis of the emerging Know Your Passenger model. AO looks at what happens when identity becomes part of the travel architecture rather than a checkpoint inside it, and what airlines, airports and travel platforms have to integrate to get there.
Based on an original publication by Facephi

Facephi has published an analysis of the emerging Know Your Passenger model, in which a traveller verifies their identity once and then reuses that verification across the journey. We would add a different lens to it. For the airlines, airports, loyalty programmes and travel platforms AO builds for, this is less a biometrics story than an architecture story about where identity lives.
Why travel identity is changing
Today a passenger proves who they are repeatedly, to parties that mostly cannot see each other's checks. Documents come out at check-in, at bag drop, at security, at the gate, sometimes at boarding, and again on arrival.
Each check is a queue. Each check is a manual comparison performed under time pressure. Each check is an opportunity for a document to be misread or a fraudulent one to be accepted. And because none of the checks share evidence, the tenth verification is no better informed than the first.
What is Know Your Passenger?
KYP describes moving the expensive part of verification to the beginning. Identity is established once, to a standard high enough to be relied upon: reading the passport chip, capturing a live image, and confirming that the person presenting the document is the person it describes.
That result then travels with the passenger as a credential. Later touchpoints authenticate against it rather than repeating the original verification. Facephi covers the mechanics and the industry context in the source article.
What are verifiable credentials?
The simplest way to describe a verifiable credential is a digitally signed statement you hold yourself.
An issuer confirms something, for example that this passport was verified and matches this person. That statement is signed, stored in the traveller's wallet, and can later be checked for authenticity by anyone who trusts the issuer, without a call back to the issuer for every check and without handing over the underlying documents again. Standards in this area are still maturing, and different schemes make different choices about what is shared and with whom.
Why biometrics matter, and what they actually do
Biometrics do two distinct jobs, and confusing them leads to weak systems.
The first is matching: linking a live person to a verified document at the moment of enrolment. The second is authentication: confirming later that the person at the gate is the same person who enrolled. Authentication is only ever as good as the enrolment behind it. A frictionless gate on top of a weak enrolment simply makes a weak identity travel faster.
Privacy and security are central
We would not describe any system as completely secure, and we would treat that phrasing with suspicion wherever it appears. The honest framing is that these architectures are designed to strengthen security and reduce identity friction, and that they carry real obligations.
Biometric data is uniquely sensitive because it cannot be reissued. Reasonable practice includes collecting the minimum needed, being explicit about purpose, keeping retention short and defined, keeping the credential under the traveller's control where the scheme allows, sharing only the attribute a party needs, and holding the whole estate to a security standard proportionate to the data.
From identity to travel experience
The reason this matters commercially is that identity is the join between systems that currently do not know they are describing the same person.
- Book
- Verify identity
- Travel credential
- Airport
- Security
- Boarding
- Destination & loyalty
Once a verified identity flows through that chain, several things become possible that are difficult today: recognising a passenger at a service desk without another document check, connecting loyalty to the actual journey rather than to a booking reference, presenting payment and ancillary offers that fit the traveller, and resolving disruption without re-identifying everyone in the queue.
Where AO fits
AO has delivered and supported a global travel API ecosystem connecting travel content, booking and loyalty services at scale, so our interest here is practical rather than theoretical.
We do not operate airport or border-control identity systems. What we do is the integration around them: connecting identity providers to airline, agency and platform systems, building and operating the API layer between booking, loyalty, payments and operations, designing the customer-facing applications where a credential is presented, and handling the data, AI and enterprise platform work behind it.
- Identity providers
- APIs & integration
- Travel platforms
- Customer applications
- Loyalty & payments
If you are working through what a credential-based passenger journey means for your estate, explore Mobility & Transport, our Identity and eKYC capability or enterprise integration.
Frequently asked questions
- What is Know Your Passenger?
- Know Your Passenger, or KYP, is an emerging model in which a traveller's identity is verified once to a high standard, typically by reading a passport chip and matching it to a live biometric capture, and is then reused across the journey as a digital credential rather than being re-established manually at each touchpoint. Facephi describes the model and its supporting technology in the original article.
- How does biometric passenger verification work?
- At a conceptual level there are two stages. Enrolment establishes the link between a verified travel document and the person present, usually through chip verification plus a liveness-checked facial capture. Authentication later compares a new capture against that established reference at a touchpoint such as bag drop, security or boarding. The second stage is only as trustworthy as the first.
- What are verifiable credentials?
- A verifiable credential is a digitally signed statement issued by one party, held by the person it describes, and checkable by a third party without contacting the issuer for every verification. In travel this allows a passenger to present proof that their identity was verified, rather than handing over the underlying documents again. Standards and industry schemes in this area are still evolving.
- Can digital identity reduce airport friction?
- It can reduce repeated manual document checks and the queueing they create, and it can allow staff to focus on exceptions. How much friction disappears depends on how many touchpoints accept the credential, how well systems are integrated and what regulators in each jurisdiction require. It is best described as designed to strengthen security and reduce identity friction, not as a guarantee of a document-free journey.
- What privacy considerations apply to biometric travel?
- Biometric data is sensitive and generally cannot be reissued if compromised. Reasonable design practice includes explicit and informed consent, collecting the minimum data needed for the stated purpose, clear retention and deletion rules, keeping the credential under the traveller's control where possible, sharing only the attribute a party needs rather than the full record, and strong security and access control across the estate. Specific obligations vary by jurisdiction.
Source & attribution
This article contains AO commentary based on an original publication by Facephi. The underlying announcement and statements regarding Facephi, its technology and partnerships originate from Facephi.
The source article, including its description of industry trials and the wider IATA ecosystem, originates from Facephi. AO does not operate border-control or airport identity systems; our role is integration and delivery.
- Original source:
- Facephi
- Original publication:
- Know Your Passenger (KYP): redefining identity on travels
- Original author:
- Facephi Observatory
Sources and references
- Know Your Passenger (KYP): redefining identity on travels — Facephi. Original publication by the Facephi Observatory. AO commentary is independent and does not reproduce the original text.
Planning something like this?
Book a Discovery Call with the AO team and we will work through it with you.
Related from AO

Synthetic Identities and Mule Accounts: Why KYC Alone Is No Longer Enough
Facephi has published research on detecting mule accounts opened with synthetic identities. AO looks at what that means architecturally: identity verification and transaction monitoring can no longer be run as two unrelated controls.

Digital Identity and the Next Phase of Financial Inclusion in South Africa
Facephi has published an analysis of collaborative fintech and financial inclusion in South Africa. AO looks at inclusion as an architecture problem: identity, payments, data, risk, channels and regulation have to connect before access becomes useful.

ThitsaWorks and Tazama Partner to Advance Real-Time Fraud Protection
The ThitsaWorks and Tazama partnership highlights an important challenge for digital finance: expanding access and accelerating payments while strengthening the technology used to identify and respond to financial crime.
