Watching someone key in a PIN and recording it, then swiping the phone is easier than building a 3D printed color model of someone's face. Not to mention that having the biometric unlock sitting on top of a PIN means that there are many fewer chances for the PIN to be observed.
Whether biometric access is a password or username is trying to force the wrong paradigm. Going back to first concepts, we had keys and we tried to make them hard to copy but not too inconvenient. The face is the key. No, there's no practical way to re-key this lock, but it's still a lock and key. But the door also has a deadbolt (PIN code) which has to be disengaged for the "face key" to function.
The username concept applies when you have multiple people using the same resource (and don't want to know or reveal whether any 2 people use the same password) -- which again doesn't apply to a single-user device.
Finally, all this combined with the quick "hard lock" of the device (5 taps of power button) gives me the impression of a very thorough approach to security.