The Unified Biometric System (EBS) is a Russian state information system that stores citizens’ biometric samples — face and voice — and allows banks, government services, and other organizations to remotely confirm a person’s identity without requiring them to show up in person with a passport. The EBS’s current legal regime is set by Federal Law No. 572-FZ of 29 December 2022, and the system’s operator, designated under Government of the Russian Federation Resolution No. 834 of 21 June 2024, is the Center for Biometric Technologies JSC. What follows is how the EBS is structured, how to enroll biometrics in it, where it’s used in practice, and how it differs from the commercial biometric systems that businesses build for themselves.
What the Unified Biometric System Is, in Simple Terms
The EBS is a database of biometric samples that can be queried to confirm that the person standing in front of a camera or speaking into a microphone really is who they claim to be. Technically, the system supports both biometric identification (searching for which of the many registered people the data belongs to) and authentication (matching the data against one specific, named person) — both terms appear in the law’s own title.
Here’s how it works: a person enrolls their face and voice in the EBS once, and after that, a bank, a government agency, or another service sends the system a comparison request whenever it needs one — and gets back information on the degree of match, not the biometric data itself. This lets an organization confirm a customer’s identity remotely, without asking them to show a passport in person.
How the EBS Is Structured and Who Its Operator Is
The EBS’s operator is designated by the Government — the current role of the Center for Biometric Technologies JSC was established by Government of the Russian Federation Resolution No. 834 of 21 June 2024. It’s the operator that stores the biometric samples and handles matching them against organizations’ requests; the EBS itself is technically integrated with the Unified Identification and Authentication System (ESIA) — the same system that underpins the Gosuslugi (State Services) portal.
This integration with ESIA isn’t just a technical detail — it’s a mandatory condition: to register biometrics on your own through the app, you need a verified Gosuslugi account. On Gosuslugi, the “Biometrics” section lets you check the status of your data and manage your consents; the EBS and ESIA nonetheless remain separate state information systems.
What Biometric Data Is Stored in the EBS
The EBS collects two types of data: a facial image and a voice recording. Under Article 11 of 152-FZ, this data acquires the status of biometric personal data precisely because it’s used to establish identity — the same logic applies to any other biometric system: a photo or a voice recording doesn’t automatically become biometric personal data on its own; it acquires that status by virtue of the purpose it’s used for.
The data is stored encrypted, in a closed loop, on Russian territory. The EBS stores biometric personal data — the facial image and voice recording — along with the vectors generated from them. Organizations using the EBS receive information on the degree of match, and in scenarios provided for by law, vectors may be passed to accredited participants; the operator does not provide the biometric personal data itself to third parties, except in cases expressly established by law.
How to Enroll Biometrics: Three Methods
The level and method of biometric enrollment in the EBS depend on where and how it’s done; in every case, you’ll need a verified Gosuslugi account.
- Through the “Gosuslugi Biometrics” app. Self-service enrollment with no need to visit anywhere in person. The app supports simplified biometrics — a selfie — or standard biometrics with additional identity confirmation; face and voice are captured together only in the standard scenario.
- In person at a bank branch. A staff member registers confirmed biometrics — the most complete level; you’ll need your passport and SNILS (individual insurance account number).
- On-site enrollment. Arranged through a partner bank: a staff member comes to you and registers confirmed biometrics on the spot, also using your passport and SNILS.
The set of services available after enrollment depends on the level of biometrics — simplified, standard, and confirmed don’t unlock the same list of options.
Which Banks Let You Enroll Biometrics
Most large retail banks support EBS biometric enrollment — the exact list keeps changing, so there’s no point pinning it down here: it would go out of date faster than this article could be of use. The Bank of Russia publishes a current, complete list of enrollment points with addresses on an official interactive map on its website — that’s a more reliable source than roundups in articles, including this one.
The EBS covers only the layer of state biometric identification — companies separately need their own KYC processes, liveness checks, and protection against forgeries
How to Check and Delete Your Biometrics
You can check your EBS registration status through the Gosuslugi portal or the “Gosuslugi Biometrics” app — it shows whether your data is registered and when that happened.
Federal Law No. 572-FZ expressly establishes that enrolling biometrics is voluntary and that consent to processing the data can be withdrawn. Consent can be withdrawn through your personal account on Gosuslugi or by a written application directly to the operator, the Center for Biometric Technologies JSC; once withdrawn, the data must be deleted from the system. The right to withdraw isn’t just a formality on paper — it’s a direct consequence of the fact that enrolling biometrics in the EBS is not mandatory for Russian citizens. For foreign nationals and stateless persons, separate rules do require having biometrics in the EBS — for example, to register a SIM card, effective 1 January 2025 (Federal Law No. 303-FZ of 8 August 2024).
Where the EBS Is Used
Today the EBS is built into several practical scenarios:
- age verification when purchasing age-restricted goods — without showing a passport
- entry to the metro and other public transit by face, with no card or phone needed
- extra protection for a Gosuslugi account
- flight check-in and hotel check-in
- remote identification at banks — opening an account or a deposit, taking out a loan, or making a transfer without visiting a branch is possible precisely because the customer’s identity is confirmed through ESIA and the EBS (Article 7(5.8) of 115-FZ); the specific set of available operations depends on the biometric level and the individual bank’s rules
Separately, the “Migom” platform is built on EBS biometrics — a set of services where you don’t need to show a passport to get a service. Some of these scenarios are still running in pilot mode in individual regions or organizations — a limited pilot shouldn’t be mistaken for a universally available feature.
Is It Safe to Store Biometrics in the EBS
Biometric data requires a stricter protection regime than most other personal data — unlike a password, it can’t simply be replaced after a leak. That’s exactly why the operator gives organizations that query the EBS to verify a customer information on the degree of match, not the original facial image or voice recording; the biometric personal data itself is not disclosed to third parties, except in cases expressly established by law, where vectors may be passed to accredited participants. For more on how similar protection of biometric data is built into a company’s own KYC processes, see the article “How to Ensure the Protection of Personal and Biometric Data in KYC Processes”.
Liability for leaks has also become stricter: as of 30 May 2025, Article 13.11(17) of the Code of Administrative Offenses of the Russian Federation sets a fine of ₽15–20 million for companies and sole proprietors for acts or omissions that result in the unlawful disclosure of biometric personal data.
Technical protection of storage isn’t enough on its own: at the moment a person presents their face to the camera, the threat of spoofing remains — presentation attacks using a photo or a video on a screen, silicone masks, deepfakes. This is where liveness detection comes in — checking that there’s a live person in front of the camera at that moment, not a recording. For the technologies that process EBS biometric data and vectors, Ministry of Digital Development (Mintsifry) Order No. 453 sets requirements for detecting presentation attacks, including a maximum acceptable attack-acceptance error probability of 0.01 — but no verification method, including liveness, gives a 100% guarantee against every possible attack, and presenting it as absolute protection would be an overstatement. A breakdown of the methods attackers use to try to bypass liveness checks is available in the article “How Liveness Detection Is Bypassed”. How the liveness-detection technology itself works is covered on the NeuroVision Liveness Detection page.
EBS and CBS: What’s the Difference
Alongside the EBS itself, the abbreviation CBS — commercial biometric system — has come into use. Strictly speaking, 572-FZ doesn’t introduce the term “CBS” as such: in practice, that’s what people call the information systems of organizations accredited by Mintsifry that perform authentication using EBS vectors and interact with the EBS itself under the rules of Articles 16–17 of the law. An organization needs grounds for this kind of accreditation and must meet the law’s requirements — not every internal biometric system a business runs automatically becomes a CBS. The legal regime for a company’s other internal biometric solutions depends on the specific scenario and the exceptions provided for by law, and doesn’t reduce to a single universal scheme.
| EBS | CBS | |
|---|---|---|
| Type of system | State information system | Information system of an accredited organization |
| Operator | Center for Biometric Technologies JSC | An organization accredited by Mintsifry |
| Legal basis | 572-FZ | 572-FZ, Articles 16–17 |
| Data | Biometric personal data and vectors stored in the EBS | Uses EBS vectors for authentication, without substituting for the EBS itself |
| Where it’s used | Government services, banks, transit, financial services | Authenticating an accredited organization’s customers using the EBS |
| Accreditation | Not required — the system is a state one | Mandatory |
The EBS and a CBS don’t substitute for one another: they solve different tasks and are subject to different requirements under the same law. If a checkout service or a bank’s app offers payment or login by face, either the EBS itself or an accredited CBS running on EBS vectors could be behind it — these are different systems with different legal statuses. Article 15 of 572-FZ prohibits organizations from keeping their own database of customer biometrics for payment or facial login outside this framework.
What the EBS Means for Business
For banks and fintech companies, the EBS is a way to remotely confirm a customer’s identity through the state framework, without building their own database of biometric samples from scratch. The connection model and the set of requirements depend on the scenario and the organization’s legal status: for customer identification — only direct use of EBS services (Article 9 of 572-FZ); for authentication — also through an accredited organization’s information system running on EBS vectors (Article 16). Connection is described in the operator’s technical documentation.
But the EBS covers only one layer — identification against the state biometric reference. It doesn’t replace the entire KYC and AML framework: document verification, customer risk assessment, transaction monitoring, and compliance with 115-FZ and 152-FZ are still things a business has to build itself — the article “How to Build a KYC Policy” breaks down how these requirements relate to one another. CBS status — that is, authentication using EBS vectors through your own information system — is only available after accreditation by Mintsifry and within the requirements of Articles 16–17 of 572-FZ; it’s not a universal alternative for any and all internal business needs.
How the EBS, KYC, and Liveness Are Connected
The EBS and a CBS are sources of the biometric signal itself: the EBS stores the reference samples and vectors, accredited CBSs work with EBS vectors, and both answer the same question — does the presented face or voice match what’s registered. KYC is a broader customer identification process that includes document verification, screening against watchlists, and risk assessment, with biometric matching being just one element of it. For more on how face recognition fits into this process and improves verification accuracy, see the article “Biometric Face-Based KYC”.
Liveness sits at the intersection of the two — regardless of whether a company uses the EBS or works through an accredited CBS. It protects the actual point where biometrics are presented from being spoofed: without liveness, even the most reliable database of biometric samples ends up comparing the reference against whatever showed up in front of the camera, including a photo or a deepfake. Companies building their own identification loop typically need their own tools on top of integrating with state or commercial biometric systems — face recognition, liveness checks, anti-spoofing — a package like this is offered, for example, by NeuroVision KYC.
The Unified Biometric System is a state tool for remotely confirming identity by face and voice, not a universal replacement for a passport. For Russian citizens, participation is voluntary: biometrics can be enrolled at different levels and in different ways, their status can be checked on Gosuslugi, and consent to processing can be withdrawn at any time. For business, the EBS covers only one layer — state biometric identification. It doesn’t replace the entire KYC framework: document verification, customer risk assessment, and transaction monitoring are still things a company has to build itself, and commercial systems (CBS) remain a separate, accredited path rather than a free-standing alternative to the EBS. Technically, biometrics carries the same general limitations as any identification system: without liveness detection, even the most reliable database ends up comparing the reference against whatever showed up in front of the camera, and no verification method offers a complete guarantee against forgery.