19th & 20th October 2026
Radisson Hotel & Conference Centre London Heathrow
11th March 2027
Hilton London Canary Wharf
Audax

Facial Recognition Access Control: Procurement, privacy and performance

Facial recognition is moving from specialist security environments into a much broader range of workplaces, campuses, transport locations, critical infrastructure and high-security facilities.

For security teams, the attraction of facial recognition access control is clear. Instead of relying solely on something an individual carries, such as an access card, the system can verify that the person presenting themselves at an entrance matches an enrolled biometric identity.

That can potentially reduce badge sharing, improve auditability and create faster access at busy entry points.

But facial recognition introduces procurement questions that conventional card access does not. Accuracy must be assessed across the intended population and operating environment. Presentation attacks need to be considered. Biometric information requires appropriate protection. Organisations also need clear rules covering enrolment, retention, access and deletion.

The procurement decision therefore needs to balance four things:

Security → Performance → User experience → Privacy

This guide examines what security professionals should compare when procuring facial recognition access control and the questions suppliers should be expected to answer.

At a Glance: Facial Recognition Access Control

CapabilityWhat Security Buyers Should Compare
AccuracyFalse acceptance and false rejection performance
Liveness detectionResistance to photos, video, masks and presentation attacks
ThroughputVerification speed at real entry points
EnvironmentPerformance in different lighting and weather conditions
EnrolmentIdentity verification and template creation
PrivacyLawful processing, transparency and proportionality
StorageLocation and protection of biometric templates
RetentionHow long biometric information is retained
IntegrationCompatibility with existing physical access systems
ResilienceFallback procedures and offline operation
GovernancePermissions, auditing and accountability
Supplier supportUpdates, maintenance and performance monitoring

What Is Facial Recognition Access Control?

A facial recognition access control system uses biometric characteristics from a person’s face to verify their identity before allowing access to a controlled area.

Typically, an authorised user is enrolled in advance. The system creates a biometric representation or template from their facial characteristics.

When they subsequently approach an access point, a camera captures their face and compares it with the enrolled information.

If the system determines that the match meets its required threshold, it can trigger an action such as:

  • Opening a door
  • Releasing a turnstile
  • Opening a gate
  • Recording attendance
  • Authorising access to a secure zone

Unlike passwords or cards, biometric matching is not based on two perfectly identical values. The NCSC explains that successive biometric captures will not be identical, meaning systems assess similarity against an enrolled biometric reference.

NCSC – Biometric Recognition and Authentication Systems – https://www.ncsc.gov.uk/collection/biometrics

That makes system accuracy and threshold configuration particularly important.

Facial Recognition Security

Facial recognition security should be evaluated as part of the overall physical access architecture rather than as an isolated device.

A deployment might integrate facial recognition with:

  • Doors
  • Turnstiles
  • Speed gates
  • Visitor management
  • Contractor management
  • CCTV
  • Security control rooms
  • Time and attendance
  • Physical access control software

Different locations may also require different levels of assurance.

An office lobby and a critical infrastructure control room do not necessarily need identical controls.

The NCSC advises organisations considering biometrics to assess their particular security requirements and expected adversaries, rather than assuming that any biometric automatically provides stronger authentication.

NCSC – General Principles for Biometrics – https://www.ncsc.gov.uk/collection/biometrics/general-principles

Security Insight

Biometrics should not automatically be equated with maximum security.

The real question is whether the entire access-control system (enrolment, biometric matching, databases, devices, networks and fallback processes) provides the level of assurance required.

Face Recognition Security System Accuracy

Accuracy is one of the first areas buyers should investigate when comparing a face recognition security system.

Two important measures are:

False acceptance

The system incorrectly determines that an unauthorised person matches an enrolled user.

False rejection

The system fails to recognise someone who should legitimately be granted access.

Reducing one can affect the other.

A very strict matching threshold may reduce false acceptances but increase the number of legitimate employees being rejected.

A more permissive threshold may improve convenience while potentially changing the security risk.

Buyers should therefore avoid asking simply:

“How accurate is your system?”

Instead ask suppliers to explain the performance measures used, the matching threshold and how results were tested.

Test Performance in Your Environment

Laboratory performance does not necessarily translate perfectly to a live entrance.

Facial recognition may need to operate with:

  • Bright sunlight
  • Low light
  • Changing weather
  • Glasses
  • Hats
  • PPE
  • Facial hair
  • High-volume shift changes
  • Users of different heights
  • People moving rather than standing still

A system deployed at an outdoor industrial gate therefore faces different challenges from one installed in a controlled corporate reception.

Buyers should consider running a pilot at representative access points before committing to wider deployment.

Buyer Tip

Don’t demonstrate the system only in a meeting room.

Test it where it will actually operate, i.e. at the gate, turnstile, lobby or secure doorway, during the busiest part of the day.

Liveness Detection and Spoofing

Facial recognition systems can potentially be targeted using presentation attacks.

These might involve attempts to fool a sensor using:

  • Photographs
  • Screens
  • Video
  • Masks
  • Other representations of an authorised user

Liveness detection, sometimes described as presentation attack detection or anti-spoofing, is therefore an important procurement consideration.

The NCSC identifies presentation attacks alongside attacks against biometric sensors, stored references and wider systems as issues organisations need to consider.

NCSC – How Biometrics Are Attacked – https://www.ncsc.gov.uk/collection/biometrics/how-biometrics-are-attacked

Buyers should ask suppliers:

  • Which spoofing attacks have been tested?
  • Is detection passive or does the user perform an action?
  • Which independent testing has been completed?
  • What happens when liveness checks fail?
  • Can security teams investigate repeated failures?

This is particularly important for high-security applications.

Facial Recognition Privacy

Facial recognition privacy needs to be addressed during system design and procurement, not after deployment.

In the UK, biometric information used for the purpose of uniquely identifying an individual is subject to specific data-protection considerations.

The Information Commissioner’s Office provides dedicated guidance covering biometric recognition, including lawful processing, fairness, accuracy, transparency, individual rights and security.

ICO – Biometric Recognition Guidance – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/

Importantly, the ICO currently notes that this guidance is under review following changes introduced by the Data (Use and Access) Act. Buyers should therefore check the latest regulatory position during procurement rather than relying on historic policies or previous deployments.

Privacy questions should include:

  • Why is facial recognition necessary?
  • Is its use proportionate?
  • What lawful basis applies?
  • What information is collected?
  • Where is it stored?
  • Who can access it?
  • How long is it retained?
  • How are individuals informed?
  • What happens when someone leaves?
  • What alternative is available where appropriate?

Legal and data-protection specialists should be involved early in the project.

Biometric Surveillance vs Access Control

It is useful to distinguish biometric access control from broader biometric surveillance.

In a typical controlled-access scenario, an enrolled individual deliberately approaches a designated authentication point and the system verifies their identity for entry.

Broader surveillance applications may involve analysing people within public or semi-public spaces, potentially without the same type of direct interaction.

The privacy, proportionality and governance questions can therefore differ significantly.

Security teams should clearly define the intended use case and prevent the system’s purpose gradually expanding without appropriate review.

For example, technology purchased to authenticate employees entering a secure building should not automatically be repurposed for wider behavioural monitoring simply because the technical capability exists.

Governance Principle

Define the purpose before procurement, and control function creep afterwards.

Enrolment Is Part of Security

A sophisticated facial-recognition algorithm cannot compensate for a weak enrolment process.

If the wrong person is enrolled against an identity, the system may subsequently authenticate that incorrect identity perfectly.

The NCSC highlights enrolment as a fundamental consideration when building secure biometric authentication systems.

NCSC – General Principles – https://www.ncsc.gov.uk/collection/biometrics/general-principles

Buyers should therefore establish:

  • How identity is confirmed during enrolment
  • Who is authorised to enrol users
  • Whether enrolment is supervised
  • How contractors are handled
  • How duplicate records are identified
  • How enrolment actions are audited
  • How users are removed

High-assurance locations may require stronger identity proofing than general workplace access.

Where Is Biometric Data Stored?

One of the most important architectural questions is where biometric information resides.

Depending on the system, processing or storage might take place:

  • On the access device
  • On an organisation-controlled server
  • Within a cloud platform
  • Across a hybrid architecture

Buyers should understand precisely what is stored.

A supplier may describe a system as not storing “photographs”, for example, while still storing biometric templates used for recognition.

Ask:

  • What information is retained?
  • Is the original image stored?
  • Is a biometric template stored?
  • Is information encrypted?
  • Who controls encryption keys?
  • Where are servers located?
  • Which supplier personnel can access information?
  • Can information be exported?
  • How is it deleted?

The ICO specifically addresses keeping biometric information secure as part of its biometric-recognition guidance.

ICO – Keeping Biometric Data Secure – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/how-do-we-keep-biometric-data-secure/

Set a Clear Data Retention Policy

Biometric information should not simply accumulate indefinitely because nobody has established a deletion process.

Retention rules should address:

  • Employees
  • Contractors
  • Visitors
  • Temporary workers
  • Former employees
  • Dormant accounts

Deletion should ideally connect with existing identity lifecycle processes.

For example:

Employee leaves → HR record changes → access withdrawn → biometric record deleted according to policy

Buyers should ask whether this can be automated and whether deletion can be verified through audit logs.

Integration with Existing Access Control

Few organisations are starting with an entirely blank physical-security environment.

A facial recognition solution may need to integrate with existing:

  • PACS platforms
  • Door controllers
  • Turnstiles
  • Gates
  • Visitor systems
  • CCTV
  • HR systems
  • Identity management
  • Security operations platforms

Buyers should establish whether integration is native, API-based or requires additional middleware.

Also consider what happens if connectivity is lost.

Can the terminal continue authenticating authorised users locally?

Or does every transaction require communication with a remote server?

These architectural decisions can directly affect operational resilience.

What Happens When Recognition Fails?

Every access system needs a fallback.

A legitimate employee may be rejected because of:

  • Camera obstruction
  • Lighting
  • Appearance changes
  • Equipment failure
  • Network outage
  • Database problems

Fallback mechanisms might include:

  • Access cards
  • PINs
  • Security staff verification
  • Mobile credentials
  • Secondary biometrics

However, the fallback cannot be dramatically weaker than the primary system.

Otherwise an attacker may simply target the recovery process rather than defeat facial recognition itself.

The NCSC specifically recommends considering both secure fallback and, for higher-security applications, whether biometrics should be combined with another authentication factor.

NCSC – General Principles – https://www.ncsc.gov.uk/collection/biometrics/general-principles

User Experience and Throughput

Security is only part of the business case.

At busy sites, an access system needs to move people through efficiently.

Buyers should measure:

  • Authentication time
  • People per minute
  • Failed attempts
  • Queue formation
  • User positioning requirements
  • Accessibility

A system that works reliably but requires every user to stop, remove glasses and align their face precisely may be unsuitable for a high-throughput entrance.

Conversely, very fast processing should not come at the expense of the required security threshold.

The objective is appropriate security with the least unnecessary friction.

Supplier Accountability

Facial recognition is not a technology organisations should procure on vague claims.

Suppliers should be able to explain:

  • How their technology is tested
  • Which performance metrics they use
  • How liveness detection works
  • How software updates affect models
  • How vulnerabilities are handled
  • How biometric information is protected
  • Which integrations are supported
  • How systems are monitored
  • What support is provided after deployment

Security teams should also establish who is responsible when components come from multiple vendors.

If the camera, recognition algorithm, access platform and installation are supplied by different organisations, accountability needs to remain clear.

What Should Buyers Compare?

Accuracy

How are false acceptances and false rejections measured?

Liveness

How does the system detect presentation attacks?

Environmental performance

Does recognition work reliably at the intended locations?

Privacy

Can the organisation demonstrate appropriate, proportionate use?

Storage

Where are biometric templates processed and retained?

Retention

Can information be removed according to organisational policy?

Integration

Will the solution work with existing physical security infrastructure?

Resilience

What happens during network, server or device failure?

Auditability

Can security teams investigate access decisions and administrative changes?

Supplier support

How are updates, vulnerabilities and performance issues managed?

Questions to Ask Facial Recognition Suppliers

  1. How do you measure recognition accuracy?
  2. What are your false-acceptance and false-rejection rates?
  3. Which populations and environments were used during testing?
  4. How does your liveness detection work?
  5. Which presentation attacks have been tested?
  6. What biometric information is stored?
  7. Where is that information processed?
  8. How is biometric information encrypted?
  9. Can retention and deletion policies be automated?
  10. How does enrolment verify someone’s identity?
  11. Which access-control platforms do you integrate with?
  12. What happens if connectivity is lost?
  13. Which fallback authentication options are supported?
  14. How are software and recognition models updated?
  15. Can we run a live pilot before wider deployment?
  16. What audit reporting is available?
  17. How do you support privacy and data-protection assessments?
  18. What happens to our biometric information if we terminate the contract?

Frequently Asked Questions

What is facial recognition access control?

It is a biometric access system that compares a captured image or facial representation with enrolled biometric information to help verify whether someone is authorised to enter a controlled location.

Is facial recognition more secure than an access card?

It can address risks such as shared or stolen credentials because it verifies characteristics of the person rather than simply possession of a card. Overall security still depends on enrolment, system design, anti-spoofing, data security and fallback processes.

What is liveness detection?

Liveness or presentation-attack detection aims to determine whether the system is seeing a genuine person rather than an attempt to fool it using something such as a photograph, screen or mask.

Is facial recognition biometric data?

Facial information processed through specific technical means for the purpose of uniquely identifying a person falls within biometric-data considerations under UK data-protection rules.

Should facial recognition be the only access factor?

That depends on the risk. The NCSC recommends considering a second factor for high-security biometric applications.

How long should facial recognition data be stored?

There is no sensible universal retention period for every deployment. Organisations need a documented policy based on their purpose, legal obligations and data-protection requirements.

Related Reading

Continue exploring facial recognition and biometric physical security with these articles from Security Briefing:

Product Guide

Senior security professionals attending the Total Security Summit can meet providers operating across biometric authentication, physical access control, electronic security and integrated site protection.

Featured Suppliers

IDEMIA Public Security
Biometric identity and access-control technology provider offering facial recognition, fingerprint and contactless biometric solutions for workplaces, critical infrastructure and other secure facilities. Its VisionPass facial-recognition range combines AI-based recognition with 3D, visible and infrared imaging, alongside spoofing-detection capabilities and integration with physical access-control environments.
Website: https://www.idemia.com/control-access-sites-facilities/

Lexnis Services
Security and facilities-management provider delivering electronic security systems including access control, CCTV, alarms and integrated site-security solutions. Its access-control services include card, biometric and PIN-based options alongside monitoring and integration with wider electronic security infrastructure.
Website: www.lexnisservices.co.uk

Assessing Facial Recognition Access Control

Facial recognition can make physical access more difficult to share, lose or misuse than conventional credentials, while potentially creating faster and more seamless entry.

But its value depends on much more than recognition speed.

Accuracy, liveness detection, enrolment, privacy, data security, integration, resilience and supplier accountability should all form part of the procurement decision.

The Total Security Summit connects senior security professionals with carefully selected providers of biometric, access-control and wider physical-security solutions through a programme of pre-arranged one-to-one meetings.

Assess facial recognition access control, compare specialist providers and explore how biometric authentication can be introduced without losing sight of privacy, resilience or operational performance.

Sources

Image credit: https://unsplash.com/photos/close-up-of-a-purple-iris-with-a-black-pupil-nmz4_TsfpZM

YOU MIGHT ALSO LIKE

Leave a Reply

Your email address will not be published. Required fields are marked *