# Face recognition governance checklist

Twelve controls a defensible deployment carries. Each is stated as something
you can check rather than something you can claim — a control that cannot be
demonstrated is a description.

This is not legal advice. Biometric regulation differs by country, by state or
province, and by sector, and it changes. You must assess the laws and
requirements applicable in your own jurisdiction with your own advisers. What
this offers is the engineering shape of the controls such an assessment will
ask about.

Full guidance: https://facerec.ayonix.com/technology/privacy-and-governance

## Before deployment

- [ ] Write the purpose in one testable sentence: the population, the location, the trigger and the action. If you cannot say what the system must refuse to do, the purpose is not yet narrow enough.
- [ ] Record the lawful basis for this purpose specifically, and name its owner.
- [ ] Decide retention per data category — captured images, templates, event records, audit entries — and enforce each in software with deletion logged.
- [ ] Design the fallback path and cost its staffing. Quick, visible and unremarkable to use.

## Access and review

- [ ] Define who may enrol, search, export and change a threshold as four separate permissions, not one administrator role.
- [ ] Specify what the operator sees at the moment of decision: both images, the similarity score and the threshold in force. Not a name and a percentage.
- [ ] Log operator decisions separately from system output, and plan to compare them. If operators essentially never disagree, review has become a signature rather than a control.
- [ ] Require human review before any consequential action. Bookmarking video, notifying an operator and logging an event may be automatic; refusing entry, intercepting someone or recording a person as identified may not.

## Measurement and evidence

- [ ] Measure both error types broken down by demographic group, on the population that will actually use the system, with a stated plan for what you will do if a difference is found.
- [ ] Establish the audit record by exercising it: reconstruct one transaction from the log during commissioning.
- [ ] Write the incident response before you need it, including how the audit log establishes what was accessed. Templates cannot be reissued like passwords, so the harm assessment differs.
- [ ] Build verifiable deletion for data-subject requests — locate, export and delete one person’s data, and show it happened. Much harder to add later than to design in.

## Watchlists specifically

- [ ] Every entry carries a named authoriser, a recorded basis and an enforced expiry. A list that only grows becomes both operationally useless and legally indefensible.
- [ ] Lists are segmented by purpose and by camera. A list appropriate at a stadium turnstile is not appropriate at a staff entrance.
- [ ] Thresholds are set per camera against what each error costs at that location, with the value and reasoning recorded.
- [ ] Alert volume is configured to what the control room can actually review. A room receiving more alerts than it can review will review none of them.
- [ ] Dismissed alerts are reviewed for pattern. A camera generating dismissals is telling you something about its placement, its lighting or its threshold.

## Review

- [ ] Set a review date for the whole assessment. Deployments drift and regulations change; an assessment with no review date will be out of date without anyone noticing.
- [ ] Re-measure after any change to camera placement, lighting or the enrolment process.

---

Published by Ayonix, facerec.ayonix.com. Ayonix sells face recognition and
therefore has an interest in how these checklists are used — they are written
so they can be applied to Ayonix as readily as to any other supplier, and if
following one leads you to a different supplier or a different category of
system, that is a legitimate outcome.

No accuracy percentage appears in any Ayonix material, for Ayonix or any other
vendor, because a figure without its threshold, dataset, gallery size and
demographic breakdown cannot be reproduced.

Corrections: infojp@ayonix.com. Last reviewed 11 September 2026.
