Facial recognition is moving from specialist security environments into a much broader range of workplaces, campuses, transport locations, critical infrastructure and high-security facilities.
For security teams, the attraction of facial recognition access control is clear. Instead of relying solely on something an individual carries, such as an access card, the system can verify that the person presenting themselves at an entrance matches an enrolled biometric identity.
That can potentially reduce badge sharing, improve auditability and create faster access at busy entry points.
But facial recognition introduces procurement questions that conventional card access does not. Accuracy must be assessed across the intended population and operating environment. Presentation attacks need to be considered. Biometric information requires appropriate protection. Organisations also need clear rules covering enrolment, retention, access and deletion.
The procurement decision therefore needs to balance four things:
Security → Performance → User experience → Privacy
This guide examines what security professionals should compare when procuring facial recognition access control and the questions suppliers should be expected to answer.
At a Glance: Facial Recognition Access Control
| Capability | What Security Buyers Should Compare |
|---|---|
| Accuracy | False acceptance and false rejection performance |
| Liveness detection | Resistance to photos, video, masks and presentation attacks |
| Throughput | Verification speed at real entry points |
| Environment | Performance in different lighting and weather conditions |
| Enrolment | Identity verification and template creation |
| Privacy | Lawful processing, transparency and proportionality |
| Storage | Location and protection of biometric templates |
| Retention | How long biometric information is retained |
| Integration | Compatibility with existing physical access systems |
| Resilience | Fallback procedures and offline operation |
| Governance | Permissions, auditing and accountability |
| Supplier support | Updates, maintenance and performance monitoring |
What Is Facial Recognition Access Control?
A facial recognition access control system uses biometric characteristics from a person’s face to verify their identity before allowing access to a controlled area.
Typically, an authorised user is enrolled in advance. The system creates a biometric representation or template from their facial characteristics.
When they subsequently approach an access point, a camera captures their face and compares it with the enrolled information.
If the system determines that the match meets its required threshold, it can trigger an action such as:
- Opening a door
- Releasing a turnstile
- Opening a gate
- Recording attendance
- Authorising access to a secure zone
Unlike passwords or cards, biometric matching is not based on two perfectly identical values. The NCSC explains that successive biometric captures will not be identical, meaning systems assess similarity against an enrolled biometric reference.
NCSC – Biometric Recognition and Authentication Systems – https://www.ncsc.gov.uk/collection/biometrics
That makes system accuracy and threshold configuration particularly important.
Facial Recognition Security
Facial recognition security should be evaluated as part of the overall physical access architecture rather than as an isolated device.
A deployment might integrate facial recognition with:
- Doors
- Turnstiles
- Speed gates
- Visitor management
- Contractor management
- CCTV
- Security control rooms
- Time and attendance
- Physical access control software
Different locations may also require different levels of assurance.
An office lobby and a critical infrastructure control room do not necessarily need identical controls.
The NCSC advises organisations considering biometrics to assess their particular security requirements and expected adversaries, rather than assuming that any biometric automatically provides stronger authentication.
NCSC – General Principles for Biometrics – https://www.ncsc.gov.uk/collection/biometrics/general-principles
Security Insight
Biometrics should not automatically be equated with maximum security.
The real question is whether the entire access-control system (enrolment, biometric matching, databases, devices, networks and fallback processes) provides the level of assurance required.
Face Recognition Security System Accuracy
Accuracy is one of the first areas buyers should investigate when comparing a face recognition security system.
Two important measures are:
False acceptance
The system incorrectly determines that an unauthorised person matches an enrolled user.
False rejection
The system fails to recognise someone who should legitimately be granted access.
Reducing one can affect the other.
A very strict matching threshold may reduce false acceptances but increase the number of legitimate employees being rejected.
A more permissive threshold may improve convenience while potentially changing the security risk.
Buyers should therefore avoid asking simply:
“How accurate is your system?”
Instead ask suppliers to explain the performance measures used, the matching threshold and how results were tested.
Test Performance in Your Environment
Laboratory performance does not necessarily translate perfectly to a live entrance.
Facial recognition may need to operate with:
- Bright sunlight
- Low light
- Changing weather
- Glasses
- Hats
- PPE
- Facial hair
- High-volume shift changes
- Users of different heights
- People moving rather than standing still
A system deployed at an outdoor industrial gate therefore faces different challenges from one installed in a controlled corporate reception.
Buyers should consider running a pilot at representative access points before committing to wider deployment.
Buyer Tip
Don’t demonstrate the system only in a meeting room.
Test it where it will actually operate, i.e. at the gate, turnstile, lobby or secure doorway, during the busiest part of the day.
Liveness Detection and Spoofing
Facial recognition systems can potentially be targeted using presentation attacks.
These might involve attempts to fool a sensor using:
- Photographs
- Screens
- Video
- Masks
- Other representations of an authorised user
Liveness detection, sometimes described as presentation attack detection or anti-spoofing, is therefore an important procurement consideration.
The NCSC identifies presentation attacks alongside attacks against biometric sensors, stored references and wider systems as issues organisations need to consider.
NCSC – How Biometrics Are Attacked – https://www.ncsc.gov.uk/collection/biometrics/how-biometrics-are-attacked
Buyers should ask suppliers:
- Which spoofing attacks have been tested?
- Is detection passive or does the user perform an action?
- Which independent testing has been completed?
- What happens when liveness checks fail?
- Can security teams investigate repeated failures?
This is particularly important for high-security applications.
Facial Recognition Privacy
Facial recognition privacy needs to be addressed during system design and procurement, not after deployment.
In the UK, biometric information used for the purpose of uniquely identifying an individual is subject to specific data-protection considerations.
The Information Commissioner’s Office provides dedicated guidance covering biometric recognition, including lawful processing, fairness, accuracy, transparency, individual rights and security.
ICO – Biometric Recognition Guidance – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/
Importantly, the ICO currently notes that this guidance is under review following changes introduced by the Data (Use and Access) Act. Buyers should therefore check the latest regulatory position during procurement rather than relying on historic policies or previous deployments.
Privacy questions should include:
- Why is facial recognition necessary?
- Is its use proportionate?
- What lawful basis applies?
- What information is collected?
- Where is it stored?
- Who can access it?
- How long is it retained?
- How are individuals informed?
- What happens when someone leaves?
- What alternative is available where appropriate?
Legal and data-protection specialists should be involved early in the project.
Biometric Surveillance vs Access Control
It is useful to distinguish biometric access control from broader biometric surveillance.
In a typical controlled-access scenario, an enrolled individual deliberately approaches a designated authentication point and the system verifies their identity for entry.
Broader surveillance applications may involve analysing people within public or semi-public spaces, potentially without the same type of direct interaction.
The privacy, proportionality and governance questions can therefore differ significantly.
Security teams should clearly define the intended use case and prevent the system’s purpose gradually expanding without appropriate review.
For example, technology purchased to authenticate employees entering a secure building should not automatically be repurposed for wider behavioural monitoring simply because the technical capability exists.
Governance Principle
Define the purpose before procurement, and control function creep afterwards.
Enrolment Is Part of Security
A sophisticated facial-recognition algorithm cannot compensate for a weak enrolment process.
If the wrong person is enrolled against an identity, the system may subsequently authenticate that incorrect identity perfectly.
The NCSC highlights enrolment as a fundamental consideration when building secure biometric authentication systems.
NCSC – General Principles – https://www.ncsc.gov.uk/collection/biometrics/general-principles
Buyers should therefore establish:
- How identity is confirmed during enrolment
- Who is authorised to enrol users
- Whether enrolment is supervised
- How contractors are handled
- How duplicate records are identified
- How enrolment actions are audited
- How users are removed
High-assurance locations may require stronger identity proofing than general workplace access.
Where Is Biometric Data Stored?
One of the most important architectural questions is where biometric information resides.
Depending on the system, processing or storage might take place:
- On the access device
- On an organisation-controlled server
- Within a cloud platform
- Across a hybrid architecture
Buyers should understand precisely what is stored.
A supplier may describe a system as not storing “photographs”, for example, while still storing biometric templates used for recognition.
Ask:
- What information is retained?
- Is the original image stored?
- Is a biometric template stored?
- Is information encrypted?
- Who controls encryption keys?
- Where are servers located?
- Which supplier personnel can access information?
- Can information be exported?
- How is it deleted?
The ICO specifically addresses keeping biometric information secure as part of its biometric-recognition guidance.
ICO – Keeping Biometric Data Secure – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/how-do-we-keep-biometric-data-secure/
Set a Clear Data Retention Policy
Biometric information should not simply accumulate indefinitely because nobody has established a deletion process.
Retention rules should address:
- Employees
- Contractors
- Visitors
- Temporary workers
- Former employees
- Dormant accounts
Deletion should ideally connect with existing identity lifecycle processes.
For example:
Employee leaves → HR record changes → access withdrawn → biometric record deleted according to policy
Buyers should ask whether this can be automated and whether deletion can be verified through audit logs.
Integration with Existing Access Control
Few organisations are starting with an entirely blank physical-security environment.
A facial recognition solution may need to integrate with existing:
- PACS platforms
- Door controllers
- Turnstiles
- Gates
- Visitor systems
- CCTV
- HR systems
- Identity management
- Security operations platforms
Buyers should establish whether integration is native, API-based or requires additional middleware.
Also consider what happens if connectivity is lost.
Can the terminal continue authenticating authorised users locally?
Or does every transaction require communication with a remote server?
These architectural decisions can directly affect operational resilience.
What Happens When Recognition Fails?
Every access system needs a fallback.
A legitimate employee may be rejected because of:
- Camera obstruction
- Lighting
- Appearance changes
- Equipment failure
- Network outage
- Database problems
Fallback mechanisms might include:
- Access cards
- PINs
- Security staff verification
- Mobile credentials
- Secondary biometrics
However, the fallback cannot be dramatically weaker than the primary system.
Otherwise an attacker may simply target the recovery process rather than defeat facial recognition itself.
The NCSC specifically recommends considering both secure fallback and, for higher-security applications, whether biometrics should be combined with another authentication factor.
NCSC – General Principles – https://www.ncsc.gov.uk/collection/biometrics/general-principles
User Experience and Throughput
Security is only part of the business case.
At busy sites, an access system needs to move people through efficiently.
Buyers should measure:
- Authentication time
- People per minute
- Failed attempts
- Queue formation
- User positioning requirements
- Accessibility
A system that works reliably but requires every user to stop, remove glasses and align their face precisely may be unsuitable for a high-throughput entrance.
Conversely, very fast processing should not come at the expense of the required security threshold.
The objective is appropriate security with the least unnecessary friction.
Supplier Accountability
Facial recognition is not a technology organisations should procure on vague claims.
Suppliers should be able to explain:
- How their technology is tested
- Which performance metrics they use
- How liveness detection works
- How software updates affect models
- How vulnerabilities are handled
- How biometric information is protected
- Which integrations are supported
- How systems are monitored
- What support is provided after deployment
Security teams should also establish who is responsible when components come from multiple vendors.
If the camera, recognition algorithm, access platform and installation are supplied by different organisations, accountability needs to remain clear.
What Should Buyers Compare?
Accuracy
How are false acceptances and false rejections measured?
Liveness
How does the system detect presentation attacks?
Environmental performance
Does recognition work reliably at the intended locations?
Privacy
Can the organisation demonstrate appropriate, proportionate use?
Storage
Where are biometric templates processed and retained?
Retention
Can information be removed according to organisational policy?
Integration
Will the solution work with existing physical security infrastructure?
Resilience
What happens during network, server or device failure?
Auditability
Can security teams investigate access decisions and administrative changes?
Supplier support
How are updates, vulnerabilities and performance issues managed?
Questions to Ask Facial Recognition Suppliers
- How do you measure recognition accuracy?
- What are your false-acceptance and false-rejection rates?
- Which populations and environments were used during testing?
- How does your liveness detection work?
- Which presentation attacks have been tested?
- What biometric information is stored?
- Where is that information processed?
- How is biometric information encrypted?
- Can retention and deletion policies be automated?
- How does enrolment verify someone’s identity?
- Which access-control platforms do you integrate with?
- What happens if connectivity is lost?
- Which fallback authentication options are supported?
- How are software and recognition models updated?
- Can we run a live pilot before wider deployment?
- What audit reporting is available?
- How do you support privacy and data-protection assessments?
- What happens to our biometric information if we terminate the contract?
Frequently Asked Questions
What is facial recognition access control?
It is a biometric access system that compares a captured image or facial representation with enrolled biometric information to help verify whether someone is authorised to enter a controlled location.
Is facial recognition more secure than an access card?
It can address risks such as shared or stolen credentials because it verifies characteristics of the person rather than simply possession of a card. Overall security still depends on enrolment, system design, anti-spoofing, data security and fallback processes.
What is liveness detection?
Liveness or presentation-attack detection aims to determine whether the system is seeing a genuine person rather than an attempt to fool it using something such as a photograph, screen or mask.
Is facial recognition biometric data?
Facial information processed through specific technical means for the purpose of uniquely identifying a person falls within biometric-data considerations under UK data-protection rules.
Should facial recognition be the only access factor?
That depends on the risk. The NCSC recommends considering a second factor for high-security biometric applications.
How long should facial recognition data be stored?
There is no sensible universal retention period for every deployment. Organisations need a documented policy based on their purpose, legal obligations and data-protection requirements.
Related Reading
Continue exploring facial recognition and biometric physical security with these articles from Security Briefing:
- Facial Recognition Month: Lessons from Secure Facilities, Airports and Local Authorities – https://totalsecuritysummit.co.uk/briefing/facial-recognition-month-lessons-from-secure-facilities-airports-and-local-authorities/
- Facial Recognition Month: Emerging Use Cases in Public and Corporate Security – https://totalsecuritysummit.co.uk/briefing/facial-recognition-month-emerging-use-cases-for-in-public-and-corporate-security/
- Facial Recognition Month: Seeing Is Believing When It Comes to the Latest Security Tech – https://totalsecuritysummit.co.uk/briefing/facial-recognition-month-seeing-is-believing-when-it-comes-to-the-latest-security-tech/
Product Guide
Senior security professionals attending the Total Security Summit can meet providers operating across biometric authentication, physical access control, electronic security and integrated site protection.
Featured Suppliers
IDEMIA Public Security
Biometric identity and access-control technology provider offering facial recognition, fingerprint and contactless biometric solutions for workplaces, critical infrastructure and other secure facilities. Its VisionPass facial-recognition range combines AI-based recognition with 3D, visible and infrared imaging, alongside spoofing-detection capabilities and integration with physical access-control environments.
Website: https://www.idemia.com/control-access-sites-facilities/
Lexnis Services
Security and facilities-management provider delivering electronic security systems including access control, CCTV, alarms and integrated site-security solutions. Its access-control services include card, biometric and PIN-based options alongside monitoring and integration with wider electronic security infrastructure.
Website: www.lexnisservices.co.uk
Assessing Facial Recognition Access Control
Facial recognition can make physical access more difficult to share, lose or misuse than conventional credentials, while potentially creating faster and more seamless entry.
But its value depends on much more than recognition speed.
Accuracy, liveness detection, enrolment, privacy, data security, integration, resilience and supplier accountability should all form part of the procurement decision.
The Total Security Summit connects senior security professionals with carefully selected providers of biometric, access-control and wider physical-security solutions through a programme of pre-arranged one-to-one meetings.
Assess facial recognition access control, compare specialist providers and explore how biometric authentication can be introduced without losing sight of privacy, resilience or operational performance.
Sources
- Information Commissioner’s Office – Biometric Recognition Guidance – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/
- Information Commissioner’s Office – Keeping Biometric Data Secure – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/how-do-we-keep-biometric-data-secure/
- National Cyber Security Centre – Biometric Recognition and Authentication Systems – https://www.ncsc.gov.uk/collection/biometrics
- National Cyber Security Centre – General Principles for Biometrics – https://www.ncsc.gov.uk/collection/biometrics/general-principles
- National Cyber Security Centre – How Biometrics Are Attacked – https://www.ncsc.gov.uk/collection/biometrics/how-biometrics-are-attacked
Image credit: https://unsplash.com/photos/close-up-of-a-purple-iris-with-a-black-pupil-nmz4_TsfpZM





