Biometric Governance
Review status: This foundation page requires specialist review before public approval. Its claims must remain within the scope stated here.
Biometric evidence can strengthen remote identity proofing or authentication, but it also creates elevated privacy, security, accessibility, and fairness obligations. UbID treats biometrics as a governed evidence source, not as an unrestricted universal identifier.
This page describes the public governance model. It does not disclose vendor configuration, matching thresholds, liveness rules, fraud heuristics, or bypass procedures.
Start with necessity
Before enabling biometric processing, the accountable institution should document:
- the specific purpose;
- why non-biometric evidence is insufficient for the required assurance;
- whether biometrics are optional, mandatory by law, or justified under another valid condition;
- which people or transactions are in scope;
- available non-biometric and accessibility alternatives;
- consequences of refusal, failure, or an indeterminate result;
- human-review and appeal procedures;
- retention and deletion design;
- vendor and international-processing roles.
“More secure” is not by itself a complete necessity analysis.
Separate biometric functions
Different functions require different governance:
| Function | Purpose | Governance focus |
|---|---|---|
| Identity proofing | Compare a person with authoritative identity evidence | Source quality, presentation attack detection, review, and issuance consequence |
| Authentication | Confirm continuity with an enrolled user | Device binding, template protection, fallback, retry limits, and account recovery |
| Deduplication | Detect possible duplicate enrollment | Necessity, population scope, false-match impact, and human investigation |
| Fraud investigation | Support a defined investigation | Legal authority, access restriction, evidence preservation, and proportionality |
| Document portrait comparison | Compare a live capture with a document image | Document provenance, image quality, confidence limits, and review |
A result produced for one purpose should not be silently reused for another.
Data separation
Biometric governance should distinguish:
- temporary capture images;
- derived templates or embeddings;
- liveness or presentation-attack evidence;
- match scores and confidence categories;
- document portraits;
- manual-review artifacts;
- final decision and reason category;
- operational logs and vendor telemetry.
These data sets have different sensitivity, access, retention, and deletion requirements. The minimum evidence required to explain a decision does not necessarily include the raw image or reusable template.
Processing lifecycle
A controlled lifecycle is:
- present a clear purpose and notice;
- confirm the applicable legal condition and any required consent;
- offer an appropriate alternative where required;
- capture only the data needed for the approved function;
- protect transport, temporary processing, and data in use;
- evaluate quality, liveness, match, and policy;
- route low-confidence or exceptional outcomes to authorized review;
- retain only the evidence required for the approved period;
- delete temporary or reusable biometric material according to policy;
- record the decision, policy version, and deletion outcome.
Human review and fairness
Biometric output is evidence, not an unquestionable fact. Governance should provide:
- confidence categories rather than unsupported certainty;
- trained review for consequential or indeterminate results;
- a method to challenge identity mismatch or inaccessible capture;
- testing across relevant demographic, device, lighting, and document conditions;
- monitoring for differential failure rates;
- accessibility and disability accommodations;
- protection against reviewers seeing unrelated personal information;
- documented authority for overrides and exceptions.
A human review process must itself be controlled, auditable, and limited to authorized purposes.
Security and vendor governance
Controls should include:
- encryption and restricted access;
- separation from general profile and analytics data;
- no use for model training or unrelated product improvement without explicit authority;
- processor and subprocessor disclosure;
- location and international-transfer assessment;
- secure deletion and termination assistance;
- breach and incident notification duties;
- independent testing appropriate to the use case;
- prohibition on exporting reusable templates to unauthorized parties;
- evidence that production policy matches the approved profile.
Retention
Retention should be defined separately for:
- unsuccessful temporary captures;
- successful proofing evidence;
- reusable authentication templates;
- fraud or security evidence;
- manual-review records;
- legal holds and disputes;
- vendor diagnostic data.
Keeping all biometric artifacts for one generic period is not a privacy-by-design approach.
Decision boundaries
A biometric match does not by itself prove:
- that the source document is genuine;
- that the person lawfully owns the claimed identity;
- that the credential should be issued;
- that the current transaction is authorized;
- that a relying party must accept the person;
- that reuse for another purpose is permitted.
The issuer or relying party must combine the result with provenance, document, credential, device, policy, and contextual evidence.
Evidence without overcollection
A reviewable record may contain:
- transaction and participant reference;
- approved purpose and policy version;
- capture and result timestamps;
- vendor or component version reference;
- result category and review outcome;
- authorization or notice reference;
- retention class and deletion due date.
Public or general operational logs should not contain raw biometric images, reusable templates, detailed anti-fraud signals, or complete identity documents.
See Identity Proofing and Biometrics and Data Lifecycle and Individual Rights.