Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Biometric Governance

Biometric AI Use Governance

What this control does

Apply enhanced approval and safeguards to biometric identification, categorisation and emotion-recognition use cases.

How to implement

Classify the actual biometric use before approving it: identification, verification, categorization or emotion recognition can have different requirements. Document the purpose, location, affected people and legal route. Check applicable prohibitions before considering controls for permitted use. For qualifying high-risk biometric identification, record the required logging and human-verification arrangements. Route law-enforcement authorization and reporting through the Biometric Law-Enforcement Authorisation and Reporting control. Do not assume that an ordinary access-control use or a human review makes every biometric use lawful.

Suggested timing and triggers

Before acquisition or deployment; after changes in purpose, setting or functionality; periodic review of permitted use.

Evidence examples

Biometric use-case and legal assessment Approval, restrictions and any required authorization Logging specification and human-verification procedure Configuration checks and records of use Review and escalation history

How to check this control

Trace one deployed biometric use back to its assessment. Verify the configured purpose and restrictions, and test the applicable logging or verification step. Escalate differences between the approved design and actual use.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Biometric AI Use Governance | EU AI Act Suggested Control | Tracker Networks