Pakistan’s proposed NADRA facial verification system for SIM issuance has entered a new phase after the National Database and Registration Authority clarified that it has not abandoned facial recognition technology. Instead, NADRA says the disagreement with the Pakistan Telecommunication Authority (PTA) is mainly about who should operate the verification equipment, where biometric data should be captured and which institution should remain responsible for the process.
NADRA Clarifies Its Position
The issue came to light through a written response submitted by PTA to the Senate Standing Committee on Cabinet Division. PTA said NADRA had previously been involved in discussions about facial-recognition-based SIM verification and that cellular mobile operators had completed a proof of concept.
NADRA, however, disputed the impression that it had withdrawn its support for the technology. The authority explained that it had proposed the PakID application as one possible way for citizens to obtain a facial-verification result through its Multi-Biometric Verification System.
According to NADRA, PakID was never intended to become the complete platform through which telecom companies would issue SIMs or onboard customers.
The distinction is important because NADRA facial verification can operate as a backend identity service without requiring every customer to complete the process through the PakID application.
Who Should Control the Verification Process?
At the heart of the disagreement is institutional responsibility.
NADRA says PTA should determine the verification requirements for SIM issuance, while NADRA should provide identity-verification services and establish the necessary technical and security standards.
Telecom operators, meanwhile, control their franchises, customer service centers, employees and SIM-selling processes. NADRA argues that operators should therefore also be responsible for the equipment used to capture customers’ biometric information.
Under the proposed model, a customer’s facial biometric would be captured using equipment controlled by the telecom operator. The information would then be securely transmitted to the operator’s data center and forwarded to NADRA for verification.
The operators would not be permitted to retain biometric information or establish their own biometric databases.
Facial Recognition Remains an Approved Method
NADRA has emphasized that facial recognition remains an approved biometric verification method, particularly in situations where fingerprint verification cannot be successfully completed.
The authority also stressed that the use of operator-owned equipment would not give telecom companies permission to store biometric information. Devices would be required to follow security rules preventing the storage of biometric data or facial templates.
This approach could allow NADRA facial verification to become integrated into telecom operators’ existing systems rather than requiring every SIM transaction to depend on a single government application.
Security Remains a Major Concern
Facial recognition can improve convenience, but it also creates important security challenges. NADRA says any nationwide system must include safeguards against deepfakes, biometric substitution, facial morphing and other techniques that could be used to bypass identity checks.
These protections are particularly important for SIM registration because mobile numbers can be connected to banking services, digital accounts, messaging platforms and other sensitive systems.
A secure system therefore needs more than simply matching a person’s face with an identity record. The process must ensure that the person is physically present and that the biometric information has not been manipulated.
The proposed NADRA facial verification architecture is intended to address these concerns through controlled data capture, secure transmission and backend verification.
Could Telecom Companies Speed Up the Rollout?
NADRA believes involving telecom operators directly could actually make nationwide implementation easier.
Instead of requiring every customer to use PakID, operators could potentially integrate facial verification into their own franchises, service centers and mobile applications.
This could provide customers with more options while allowing companies to use infrastructure they already control.
NADRA has said it is prepared to provide the backend verification system, secure application programming interfaces and technical standards. PTA would determine the requirements applicable to the telecom industry, while cellular operators would be responsible for implementing the necessary infrastructure.
The regulations allow NADRA, in consultation with the relevant regulator, to establish a compliance period of up to six months following notification.
PTA Continues Its Technical Review
PTA has said it is reviewing the technical and regulatory implications of NADRA’s proposal in consultation with the telecom industry.
The review is being conducted under regulations concerning access to NADRA’s National Data Warehouse, which were notified on July 28, 2026.
PTA also indicated that nationwide facial verification could be pursued through alternative approaches. At least one telecom operator is reportedly examining the possibility of introducing facial verification through its own mobile application, with technical feasibility being assessed before a potential proof of concept.
This suggests that the technology itself is not necessarily the main obstacle. Instead, the key question is how responsibilities should be divided between NADRA, PTA and telecom companies.
The debate surrounding NADRA facial verification shows the importance of clearly defining institutional responsibilities before a nationwide system is introduced.
NADRA appears ready to provide the identity-verification infrastructure and technical standards, while PTA has responsibility for regulating SIM verification requirements. Telecom operators would handle customer-facing infrastructure and biometric capture.
A clear framework could make the system more scalable while protecting citizens’ biometric information. However, the authorities will need to resolve their differences over implementation, accountability and technical standards before the system can move forward smoothly.
Facial verification could make SIM registration more convenient and provide an alternative when fingerprint verification fails. But its success will depend on strong cybersecurity, clear regulation and strict limits on how biometric information is captured, transmitted and handled.



