Overview
ISO/IEC 9868:2025 provides international recommendations and requirements for the design, development, use and maintenance of biometric identification systems involving passive capture subjects. The standard focuses primarily on surveillance-style deployments (e.g., face recognition in public spaces) but is applicable to any biometric identification system that passively captures subjects, regardless of biometric characteristic or sensing technology. It covers pre‑ and post‑deployment evaluation, risk assessment, operational monitoring and continual improvement. Note: it does not apply to biometric verification systems or systems where capture subjects deliberately participate, nor does it prescribe specific services, platforms or tools.
Key topics and technical requirements
ISO/IEC 9868:2025 addresses technical, operational and governance aspects of passive-capture biometric systems. Major areas include:
- System design and development: requirements for biometric algorithms, training/testing practices, and the effect of capture devices on performance.
- Performance evaluation: pre‑ and post‑deployment testing, biometric recognition metrics, and third‑party ex‑ante evaluations.
- Demographic differential performance: requirements for assessing and reporting performance variation across demographic groups.
- Quality and anomaly detection: detection of poor-quality captures and anomalous inputs.
- Security and presentation attack detection (PAD): guidance on evaluating spoofing risks and system integrity.
- Biometric data management: storage, protection and lifecycle considerations for biometric information.
- Human oversight and manual review: support for operator intervention, documented processes, and competence requirements.
- Operational practice and governance: organizational control, competence of operators, monitoring, privacy measures and continual improvement (including retraining and continuous learning for ML-based systems).
- Risk and privacy: risk assessment for harms arising from passive capture, aligned with privacy frameworks (e.g., ISO/IEC 29100), and biometric information protection.
Practical applications
ISO/IEC 9868:2025 is intended for use in contexts where individuals can be identified without deliberate enrollment actions, such as:
- Public-space surveillance and crowd monitoring
- Transport hubs and security screening
- Event security and perimeter surveillance
- Any passive-capture identification deployment where privacy, bias, performance and security are critical concerns
The standard helps organizations reduce identification errors, manage bias, strengthen security and meet regulatory expectations for AI and biometric systems.
Who should use this standard
- System designers and biometric algorithm developers
- System integrators and vendors deploying passive-capture solutions
- Security architects, privacy officers and data protection authorities
- Independent evaluators, auditors and certifiers conducting performance and security assessments
- Policymakers and procurement teams specifying safe, privacy-aware biometric solutions
Related standards
Normative references include ISO/IEC 19795 (biometric performance), ISO/IEC 30107‑3 (presentation attack detection), ISO/IEC 29794‑1 (sample quality), ISO/IEC 29100 (privacy framework), ISO/IEC 24745 (biometric information protection), ISO/IEC 22989 (AI terminology) and ISO/IEC 27001/27002/27005 (information security). These provide complementary technical and governance guidance for implementing ISO/IEC 9868:2025.