Overview
ISO/IEC 19795-5:2011 - Information technology - Biometric performance testing and reporting - Part 5: Access control scenario and grading scheme - defines a standardized framework for biometric performance testing and a conservative grading scheme specifically for access control applications. The standard describes test environments, metrics, test conduct and reporting so vendors, test labs and procurers can quantify the technical performance of biometric verification subsystems used in doors, turnstiles and other access control installations. It focuses on technical performance (error rates and transaction time) and explicitly excludes unusual/extreme scenarios and non-technical testing (e.g., security vulnerability, human factors, environmental or reliability testing).
Key topics and technical requirements
- Testing framework and scenario: Defines a common access-control scenario and controlled indoor environment for repeatable evaluations.
- Performance metrics: Specifies measurement of False Accept Rate (FAR), False Reject Rate (FRR), Failure to Enrol (FTE), Failure to Acquire (FTA) and transaction time. Minimum FAR tested is 0.1%.
- Grading scheme: Assigns grades to measured performance using statistical analysis and confidence intervals so claims are conservative-performance is at least as good as the grade indicates (90% confidence level).
- Testing methodology: Covers enrolment and verification transactions, impostor tests, temporal separation of enrolment and verification, and incremental evaluations.
- Test crew management: Defines requirements for crew demographics, selection, size, training and habituation to ensure representative and reproducible results.
- Documentation and reporting: Specifies report structure, test control, data collection, problem tracking and how graded results should be presented.
- Statistical annex: Normative annex includes methods (correlated binary, beta-distribution, z-statistic) for estimating confidence bounds of graded metrics.
Applications and who uses it
- Vendors and manufacturers use ISO/IEC 19795-5 to validate biometric components and produce comparable performance claims.
- Independent test laboratories adopt the framework to run repeatable, auditable access control evaluations.
- System integrators and procurement teams specify grading requirements in tenders to ensure minimum biometric performance.
- Security architects and facility managers use graded reports to assess suitability of biometric systems for standard access-control deployments.
Related standards
- ISO/IEC 19795 family: Part 1 (Principles and framework), Part 2 (Testing methodologies), Part 3 (Modality-specific guidance), Part 4 (Interoperability), Part 6 (Operational evaluation), Part 7 (On-card comparison). These provide complementary guidance for broader biometric testing and operational use.
Keywords: ISO/IEC 19795-5:2011, biometric performance testing, access control, grading scheme, FAR, FTE, FTA, statistical confidence, enrolment, verification.