BRITISH COLUMBIA · SINCE 2015CALL A LOCAL TEAM — (604) 360-7400
(604) 360-7400Book a free site walk-through

Biometrics at the door: FAR, FRR, and what an accuracy claim means

An accuracy claim on a fingerprint or face reader is a single point on a curve, and the vendor chose which point to show you. Here is what the two numbers underneath it actually trade against each other.

Guard Nation Security9 min read

The demonstration is always the same, and it always works. Someone presents a finger or stands in front of a lens, a light goes green, the door releases. Fast, modern, and nobody has to carry anything. Somewhere in the conversation a number appears — an accuracy figure with a string of nines in it — and it settles the question in the room, because who argues with a number.

That number is the part worth slowing down on. Not because it is a lie, but because it is not a specification. It is one point selected from a curve, and the vendor selected it. Everything below is about the mechanism, not about any particular product.

There are two different ways a reader can be wrong

A biometric reader is not matching a finger to a finger. It captured a sample when the person was enrolled, reduced it to a mathematical representation — the template — and threw the picture away. Every later presentation is reduced the same way and compared to the stored template. The output is not "yes" or "no". It is a similarity score, and the system compares that score against a threshold to decide whether to open the door.

It is, in other words, still the credential half of the four-part model every access control system runs on — people, credentials, doors and time. Only the credential has changed. Once you see that a threshold exists, the two error types follow immediately.

A false accept is the reader opening for the wrong person — scoring someone as a match when they are not. This is the failure everybody imagines, and the one the marketing addresses. The false accept rate, or FAR, describes how often it happens.

A false reject is the reader refusing the right person — a properly enrolled, fully authorized employee at their own door, told no. The false reject rate, or FRR, describes how often that happens.

Both are ordinary consequences of the same threshold. Nobody has to have done anything wrong for either to occur.

The trade is unavoidable, and it is the entire point

Set the threshold high — demand a very close match — and it becomes harder for the wrong person to score above the line. False accepts fall. But now every ordinary variation in a real presentation matters: a slightly different finger angle, a drier day, a different standing distance, a shadow. The right people start getting refused. False rejects rise.

Set the threshold low and the reverse happens. The right people sail through, and so does more of everything else.

You cannot improve both by turning the dial, because they are the two ends of one dial. A genuinely better sensor or algorithm moves the whole curve, so any chosen threshold does better on both counts than the old system did — but the trade never disappears, it just relocates. Every device you can buy sits somewhere on a curve of its own, and the configuration on install day picks the point.

This is why a single accuracy figure tells you close to nothing. To be a specification it would need three things it almost never states:

Which threshold. A figure quoted at a permissive setting and one quoted at a strict setting describe the same device behaving completely differently. Quoting one rate without the other, at an unstated threshold, is choosing the flattering end of the dial and printing it.

Which population. Performance is measured against a test set of people — how many, of what ages, doing what work, with what hands. A result from a controlled evaluation and a result from your loading bay in February are not the same measurement, and only one of them is on the brochure.

Which conditions. Lighting, temperature, sensor cleanliness, how much instruction the subject received, how many attempts they were allowed. A rate that assumes several attempts is not describing the experience of a person late for a shift.

None of that makes vendors dishonest. It makes the headline number a marketing sentence rather than an engineering one. The right response is not scepticism about biometrics — it is a request for the conditions. It is the same reflex worth applying to a frequency printed on a card: a specification that sounds precise is not automatically telling you what you assumed.

The cost of false rejects is operational, and it lands on you

False accepts are a security problem, and they get the attention. False rejects are the ones that actually reshape your building, because they are frequent, visible, and they happen to people who are entitled to be there.

Follow the chain. A reader set strictly refuses people occasionally. At a quiet office door that is a shrug and a second attempt. At a shift-change door with a queue behind it, it is a bottleneck — and the person refused is being publicly told they do not belong, in front of colleagues, while late. Repeat for a few weeks.

What happens next is the most predictable event in access control: somebody props the door. Not out of malice, but out of practical frustration with a system that keeps refusing legitimate people at the worst moment. A supervisor props it at shift change and closes it after. Then somebody forgets. Your carefully specified reader is now decorating a wall beside an open door.

That is the real cost of a high false reject rate. Not the seconds lost — the fact that the people you have inconvenienced will engineer a workaround, and the workaround will be worse than whatever the threshold was protecting against. A system tuned so tightly that people route around it provides less security than a looser one they comply with.

Enrolment is where most of the trouble is actually born

The comparison is only as good as what it compares against. If the stored template was built from a poor sample, that person will have a bad experience every day, indefinitely, and no threshold adjustment fixes it — the problem is not the door, it is the reference.

Enrolment usually happens on the busiest possible day: a batch of new starters, a technician on a schedule, everybody queued at a desk. Somebody presents a finger badly, the software accepts the sample, and everyone moves on. The consequence shows up weeks later as "the system doesn't like Priya", gets reported as a reader fault, and does not get solved.

The practical version: treat enrolment as a real step with somebody responsible for it. Confirm the capture quality the software reports rather than accepting the first sample. Enrol more than one finger where the technology allows it, so a bandage is not a lockout. And keep a fast, documented route to re-enrol someone — hands change, and a template captured two years ago is a record of a person as they were.

The door is a real place, and BC weather is in it

Everything above assumes an ideal presentation. Your doors are not laboratories.

Gloves. Contact readers and gloves are simply incompatible, and a great many of the people entering commercial and industrial buildings in this province are wearing them for good reason. The real choice is whether to require someone to strip a glove at every door, in the rain, carrying things.

Wet, cold and dry hands. Cold fingers, wet fingers after a walk from the parking lot, hands dried out by winter or by cleaning products — all change what the sensor sees relative to the enrolled template. That is not an exotic condition in BC. It is most of the year.

Dirt and wear. Trades, warehouse work, kitchens, groundskeeping. Hands that do physical work for a living are the hands least well served by fingerprint readers, and they belong to the people who most often arrive together at a shift boundary.

The sensor itself. A contact sensor accumulates a film of everything that has touched it, and performance degrades gradually. Nobody notices a slow drift; they notice that "it's been playing up lately". Give it a cleaning schedule.

Face and lighting. Contactless approaches dodge the glove problem and pick up a different one: a lens pointed at a glass entrance is looking into whatever the sky is doing, and low winter sun at a west-facing door is a genuinely hard condition.

Shift workers. Every one of these problems concentrates at the moment the door is busiest. Average performance is not the figure that matters; performance at the shift boundary is.

Now the part most vendors skip: it is personal information

A biometric template is information about an identifiable individual, held by your organization, and in British Columbia that puts it squarely inside the Personal Information Protection Act. Not by analogy. Directly.

We have set out what that Act asks of an access control system in your door logs are personal information, and will not repeat it here — the notification duties at sections 13, 16 and 19, the obligation to protect what you hold at s.34, and the requirement to have decided how long you keep it at s.35 apply to biometric data exactly as they apply to the movement logs. Read that one alongside this.

What is worth adding are the questions specific to biometrics, which a card never raises:

Purpose. Why this door, and why this technology rather than a credential. "It was on the quote" is not a purpose. If a strong credential would meet the same need, you are collecting something more sensitive than you need to.

Consent, and what a person can actually decline. An employee asked to enrol at their own workplace is not in a symmetrical position. You need a real answer for the person who objects, and a workable alternative beats a policy that pretends nobody will.

Where the template lives. On the reader, on a server in the building, on a card the person carries, or in a vendor's cloud in another country. These are meaningfully different exposures and the answer is often not in the proposal.

What happens when someone leaves. Deactivating a credential and deleting a template are different operations. Ask which one the offboarding process performs, and ask someone to show you.

The asymmetry that makes this different from a card

Here is the sentence to keep. A compromised card is reissued. A person cannot be reissued.

If a credential is copied, the fix is administrative and cheap: revoke the number, issue a new one, the person carries it tomorrow. The old credential is worthless the moment you say so. That property — the thing being verified is disposable — is what makes card systems recoverable from mistakes.

Biometric characteristics do not have it. They are not replaceable, and the person carries them into every other system that ever asks. That does not make biometric access control wrong for your building; it means the consequences of holding that data poorly are permanent in a way that nothing about a fob is, and the care taken with storage, retention and deletion has to be proportionate to that.

What to ask for

Ask, in writing, for the threshold your system will be commissioned at, and for both error rates at that setting rather than one number. Ask under what conditions and against what population any quoted figures were produced. Ask what the fallback is when the reader refuses an authorized person, because a system without a dignified fallback gets a propped door instead. Ask who owns enrolment quality and re-enrolment. And ask where templates are stored, who can reach them, how long they are kept, and what deletes them when someone leaves.

A vendor who answers those calmly is worth working with. A vendor whose entire case is a single accuracy figure has told you where on the curve they would like you to look.

You will have noticed that no performance figures appear anywhere above. That is deliberate. We hold no verified primary source for any specific error rate, and a security company inventing an accuracy statistic inside an article about distrusting accuracy statistics would be worth nothing to you. The relationship is the useful part, and it needs no numbers.

Written by the Guard Nation Security team — from the sites we install, monitor, guard and investigate across British Columbia, and have since 2015.
General information, not legal or code advice · bylaws and enforcement differ by municipality, and your authority having jurisdiction has the final say.
Sources & the full caution

Sources

  • Personal Information Protection Act (SBC 2003, c. 63), s.13 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Personal Information Protection Act (SBC 2003, c. 63), s.16 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Personal Information Protection Act (SBC 2003, c. 63), s.19 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Personal Information Protection Act (SBC 2003, c. 63), s.34 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • Personal Information Protection Act (SBC 2003, c. 63), s.35 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01

Building and fire codes, municipal bylaws, and how they are enforced differ from one site to the next, and the authority having jurisdiction (AHJ) for your building has the final say — confirm current requirements with your AHJ and municipality before you act on anything here, and for legal decisions, with your lawyer.

Want a second opinion on your doors?