GCash facial verification is now being used for some GLoan applications, adding another identity check even for customers who are already logged into fully verified GCash accounts.
Fuse Financing, Inc., the lending arm of GCash, announced on August 27 that GLoan can now trigger a biometric Selfie Scan during loan applications considered to involve elevated risk.
Unlike a blanket requirement applied to every borrower, GCash describes the system as an adaptive security measure that allows lower-risk loan transactions to proceed with less friction, according to the company’s August 27 announcement.

The change raises a broader cybersecurity question for digital banking users: If GCash already knows who you are and you have successfully logged into your account, why would it need to verify your identity again?
The answer lies in the difference between gaining access to a financial account and proving that the person performing a particularly sensitive transaction is still its legitimate owner.
Being logged in does not always mean the account is safe
A successful login establishes that someone has passed the authentication requirements needed to enter an account. It does not guarantee that every action performed afterward is being initiated by the legitimate account holder.
Credentials can be stolen through phishing, social engineering or other forms of account compromise. An attacker could also obtain access to a device or an already authenticated session.
This matters more when the next action can create a new financial obligation.
Checking an account balance or browsing GCash services presents a different level of risk from taking out a loan that could immediately place borrowed funds into the wallet while leaving the legitimate owner responsible for repayment.
GCash said its new facial verification is intended to reduce the risk of unauthorized loan applications and disbursements even when a user’s login credentials have already been compromised. The Selfie Scan checks whether the person proceeding with the GLoan application matches the legitimate account holder.
This is called adaptive or risk-based authentication
Rather than asking every user to complete the strongest possible security check every time they use an app, financial platforms can apply additional authentication when a transaction appears more sensitive or risky.
This approach is commonly known as adaptive or risk-based authentication.
Cybersecurity guidance from the Open Worldwide Application Security Project, or OWASP, describes adaptive authentication as changing authentication requirements according to factors such as the sensitivity of an action, device information, location, IP address and other contextual signals.
A system could therefore allow an ordinary interaction to proceed normally but require another verification step when the risk level rises. OWASP also recommends reauthentication for sensitive transactions and after suspicious or high-risk activity, according to its Authentication Cheat Sheet.
GCash has not publicly detailed which specific signals cause its GLoan Selfie Scan to appear. What the company has disclosed is that the additional check is intended for elevated-risk moments rather than every GLoan availment.
For borrowers, that means two people applying for a loan may not necessarily encounter exactly the same authentication flow.
Why loans need stronger transaction-level protection
The distinction is particularly important in digital lending because a successful fraudulent transaction does not simply move money already belonging to the victim.
It can also create debt in their name.
Someone who gains access to a wallet account could potentially attempt to borrow money, move the proceeds and leave the legitimate account holder dealing with an unauthorized loan.

IMAGE CREDIT: GCash
That is why another identity check immediately before a sensitive financial action can serve as a second line of defense.
The principle extends beyond GLoan. Banks and fintech platforms can require additional authentication for actions such as changing important account information, enrolling a new device or completing unusually sensitive transactions even after the customer has already logged in.
In other words, authentication is increasingly becoming less about asking, “Did this person successfully log in?” and more about asking, “Are we sufficiently confident this is still the legitimate customer performing this particular action?”
What happens if the GLoan face scan fails?
GCash’s Help Center states that a face scan may be required before a user can continue with a GLoan application.
If facial verification fails five times, the borrower must wait 24 hours before trying again. GCash recommends using good lighting, keeping the face clearly visible, removing glasses or face masks and following the movements requested by the app during the Selfie Scan, according to its GLoan application guide.
The additional check does not replace GLoan’s existing eligibility requirements. GLoan remains available only to pre-qualified users, and factors such as the customer’s overall GCash profile, account activity, and payment history can still affect eligibility.
GCash is also adding loan scam insurance
Alongside facial verification, Fuse said it has expanded GLoan protection with Loan Scam Insurance of up to ₱10,000 for select users.
According to GCash, the insurance is intended to cover financial losses involving loans triggered through unauthorized account use, phishing and similar incidents.

IMAGE CREDIT: GCash
This adds a second layer to the security model. Facial verification is designed to prevent an unauthorized loan from being completed in the first place, while insurance can provide financial protection for eligible users when certain fraudulent incidents still succeed.
GCash also continues to provide eligible GLoan borrowers with free GLoan Protect health insurance through GInsure and Oona Insurance. Its GLoan Protect guide says eligible loans start at ₱500 and that the insurance is automatically added at no extra cost.
The August 27 announcement, however, does not provide the complete policy terms, exclusions or claims requirements specifically covering the newly announced Loan Scam Insurance. Borrowers should therefore check the insurance policy shown inside GInsure before assuming that every type of scam or unauthorized borrowing incident is covered.
More security does not have to mean more friction
Adding another verification screen may appear to make digital borrowing less convenient, particularly when a user has already gone through GCash’s identity verification process.
But adaptive authentication is designed around a compromise: applying stronger security where the potential consequences are greater without forcing every customer through the same additional steps for every transaction.
For GLoan, that means a selfie can become another checkpoint between gaining access to an account and taking on debt through it.
As financial apps increasingly combine payments, savings, investments, insurance and credit under one login, that distinction is becoming more important. Securing the entrance to an account is only one part of protecting a customer. High-risk actions inside that account may need their own proof that the person tapping “continue” is still the person who owns it.
