Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Biometric Governance

Biometric Law-Enforcement Authorisation and Reporting

What this control does

Control authorised law-enforcement biometric use through approvals, scope limitations, documentation and reporting.

How to implement

Use a specialist legal and operational approval process for law-enforcement remote biometric identification. Keep real-time use under Article 5 separate from post-remote identification under Article 26(10); their authorization routes, conditions and deadlines differ. Document the permitted purpose, necessity, scope and required human decision safeguards. Track each use, any required impact assessment, registration and notification, and the applicable stop/deletion response to refusal. Prepare annual reports where Article 26(10) requires them, while protecting sensitive operational data. Do not treat one authorization as permission for unrestricted future use.

Suggested timing and triggers

Before and during each use; within the applicable authorization and notification deadlines; annually where the relevant reporting duty requires.

Evidence examples

Case-specific legal and necessity assessment Required authorization, impact assessment and registration Use logs and human-decision records Notifications, refusal responses and deletion evidence Applicable annual reports excluding protected operational data

How to check this control

Select a completed use and verify its legal route, scope and authorization timing. Trace any refusal or restriction into system use and data handling. Reconcile the relevant reporting records to the cases covered.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Biometric Law-Enforcement Authorisation and Reporting | EU AI Act Suggested Control | Tracker Networks