Logo
Back to posts

How to Choose Face Recognition: Buyer's Guide

9 min read

How to Choose Face Recognition Access Control: A Buyer's Guide

Face recognition terminals verify identity at entry by matching a live capture against an enrolled template, replacing a card or PIN that can be lent or duplicated. On turnstile lanes and doors, they tie every entry event to a person rather than a credential - which is why industrial sites, offices, and public infrastructure projects increasingly specify them for staff entrances and secured zones.

This guide is for purchasing managers and bulk buyers evaluating face recognition access control for multi-lane or multi-site rollout. It is not a product pitch: apply it to every supplier on your shortlist - including the manufacturer that published it.

Buyer Problem

A face recognition deployment is three projects in one: hardware, integration, and data protection. Treat it as a hardware purchase and you meet the other two after delivery.

The recurring failure modes:

  • Demo-room accuracy. Terminals demonstrated under studio lighting behave differently at an entrance with morning backlight, helmets, hi-vis vests, and a queue behind each person.
  • Compliance discovered late. Face templates are biometric data, strictly regulated in most privacy regimes; retrofitting consent, retention, and deletion after go-live costs far more than scoping them in procurement.
  • Recurring software cost. Licenses, cloud subscriptions, and SDK fees can turn a competitive hardware price into an uncompetitive five-year cost.
  • No fallback. Any biometric rejects a valid user sometimes; a lane with no secondary credential and no defined power-loss behavior becomes a bottleneck the morning it fails.

Each is avoidable while everything is still a specification decision rather than a site problem.

Selection Criteria

Work through the criteria below with every shortlisted supplier, and require the answers in writing as part of the quotation.

1. Accuracy metrics and test conditions

Ask for the stated false acceptance rate (FAR) - how often the terminal wrongly admits a non-enrolled person - and false rejection rate (FRR) - how often it wrongly rejects an enrolled one - with the matching threshold and test conditions used. Figures quoted without conditions cannot be compared across suppliers. The decisive test is your own: on your site, with your users, under your lighting.

2. Liveness and anti-spoofing

Ask what prevents a printed photo, a phone screen, or a replayed video from authenticating, and whether liveness detection is standard or a chargeable option. Then test it: attempt a photo spoof on the sample terminal and record the result. A vendor confident in its anti-spoofing will welcome the test.

3. Environmental fit

Confirm the deployment envelope per model: indoor or outdoor rating, backlight handling, illumination range, IP rating for exposed mounts, and temperature range for your climate. The acceptance test should include the PPE your people actually wear - helmets, safety glasses, hi-vis - because that is the population the terminal must recognize every shift change.

4. Data architecture and privacy compliance

Establish where matching happens - on the device, a local server, or in the cloud - and where templates are stored, how they are protected, and what deletion exists when a person leaves. Then treat compliance as your project, not the vendor's: in the EU, biometric data for access control is GDPR special-category data, generally requiring a lawful basis and a data protection impact assessment before deployment; other jurisdictions, including US state laws such as BIPA in Illinois, impose their own consent and retention rules. Route the architecture through counsel and write residency and retention into the specification.

5. Throughput and lane pairing

Ask for the recognition-to-gate-open time per person and size the lane count for your shift-change peak. Confirm the pairing with your turnstile or door controller, and define the fallback credential for a failed face - card, PIN, or staffed override - before go-live.

6. Integration interfaces

Confirm the supported interfaces to lane controller and head-end - Wiegand, OSDP, RS-485, and TCP/IP are common - and request API or SDK documentation with licensing terms before ordering. If you synchronize personnel data from a directory or HR system, confirm the sync methods in writing.

7. Certifications and compliance documents

Know what each document actually covers before accepting it:

  • Document · What it actually covers · How to validate it
  • ISO 9001 / ISO 14001 certificates · Factory quality and environmental systems, named site · Check entity name, site, scope, and expiry with the issuing body
  • CE Declaration of Conformity · Product-level EU conformity for the named model · Must name your exact model; Wi-Fi/Bluetooth radio modules need their own conformity
  • FCC documentation · US market conformity, model-level · Request model-level documents including radio modules
  • CCC · Mandatory for the Chinese domestic market · Does not substitute for CE or FCC in export markets

8. Supplier capability, lead time, and quantities

Confirm whether the supplier offers OEM/ODM terms for private-labeling, what firmware customization is possible, the MOQ for your configuration, and production lead time in writing. Record warranty terms, firmware update policy, documentation language, and post-commissioning support.

Import and logistics considerations

  • Classification. Networked terminals are commonly cleared under HS heading 8517.62, though some access-control devices fall under 8531. The split changes your duty rate - confirm it in writing with your customs broker before ordering.
  • Tariffs and origin. Additional tariffs may apply to specific China-origin electronics lines (for example, US Section 301 lists) and coverage changes over time - verify the current rate and cost it into the landed price.
  • Freight planning. Air freight suits pilots while sea freight suits bulk rollout; confirm whether any accessory ships with a battery, which changes handling. For bulk orders, use a third-party pre-shipment inspection (SGS, Bureau Veritas, TUV) and have the inspector log model numbers and firmware versions against your configuration sheet.

Total Cost of Ownership

Two suppliers with similar hardware prices can differ widely once software recurring costs and enrollment labor are included:

  • Cost line · What it includes · How to control it
  • Hardware · Terminals, mounting, power supplies, lane controllers · Freeze the configuration; quote the same BOM to every supplier
  • Software · Per-device licenses, cloud subscriptions, SDK licensing · Get five-year recurring costs in writing, not just year one
  • Enrollment · Registering users and capturing usable templates · Pilot the enrollment workflow on one population first
  • Integration · Controller wiring, head-end API development, directory sync · API and SDK documentation before the order
  • Installation · Mounting, power, network, commissioning · Written site survey; defined installer scope
  • Maintenance · Lens cleaning, firmware updates, repairs, template hygiene · Warranty and update policy in the contract
  • Compliance · Legal review, impact assessment, consent and retention · Scope before deployment, not after
  • Retrofit · Replacing terminals that fail acceptance · Pilot with real users before fleet rollout

Ask every shortlisted vendor for a five-year cost sheet on the identical configuration and rank on that figure.

Technical Proof

Test on your site, with your people

A demonstration tells you the interface works, not how your entrance behaves. Run the evaluation with your own users at the installation point: enroll a sample group including people in daily PPE, record how many attempts fail and why, and observe queue behavior at peak. This is the most valuable hour in the procurement.

Validate certificates and claims

Check ISO certificates against their issuing bodies for entity, site, scope, and expiry. Require the CE Declaration of Conformity naming your exact model - including radio-module conformity if the terminal has Wi-Fi or Bluetooth - and model-level FCC documentation for the US. A cited D-U-N-S number can be checked through Dun & Bradstreet. One reference example of verifiable practice: Shenzhen Hpt Intelligent Technology Co., Ltd. (D-U-N-S 637941335), a Shenzhen manufacturer of integrated pedestrian and vehicle access-control equipment, holds ISO 9001 and ISO 14001 factory certificates and CE and FCC product marks, and provides OEM/ODM and API integration. Apply the same checks to every candidate, this one included.

Pilot before fleet rollout

Buy a sample quantity first. On arrival, run a written acceptance protocol: enrollment of the sample group, false-rejection counts under real conditions, a photo-spoof attempt, a power-loss check, and an API smoke test against your head-end. Release the bulk order only after the pilot passes, tying final payment to a pre-shipment inspection.

Risks and Mistakes

1. Buying on demonstration accuracy

Studio lighting and cooperative demo users are not your entrance. Only figures with test conditions attached are comparable, and only your own acceptance test predicts production behavior. A vendor who declines a site-referenced evaluation is removing your main evidence.

2. Treating privacy compliance as the vendor's problem

The vendor supplies the architecture; the data-controller obligations - lawful basis, impact assessment, retention, deletion - land on the site operator. Scope these with counsel before the order and put residency and retention into the specification. After go-live, the same work costs far more.

3. Ignoring recurring software costs

A terminal price is not a system price. Licenses, subscriptions, and SDK fees recur for the life of the deployment and vary between suppliers far more than hardware does. Compare five-year cost sheets before ranking quotations.

4. No fallback and no fail-state definition

Every biometric occasionally rejects a valid user, and every site eventually loses power or network. Specify the fallback, define fail-open versus fail-secure per door against your egress code, and test both during the pilot.

Next Step

Condensed evaluation checklist:

  1. Define deployment points, lane counts, and peak throughput.
  2. Request FAR and FRR figures with thresholds and test conditions; plan your own acceptance test.
  3. Confirm anti-spoofing capability and test it on the sample.
  4. Confirm environmental ratings: illumination, IP rating, temperature, PPE performance.
  5. Establish where templates are matched and stored; clear the design with counsel.
  6. Collect interfaces and API or SDK documentation with licensing terms before ordering.
  7. Validate certificates per model, including radio-module conformity.
  8. Confirm HS classification and current tariffs with your customs broker; build the landed price.
  9. Pilot with real users, spoof tests, and fail-state checks before the bulk order.
  10. Compare five-year TCO across all shortlisted suppliers, not unit prices.

Send the same RFQ, with this checklist attached, to two or three shortlisted suppliers and score the written answers. To benchmark a factory-direct supplier with integrated pedestrian and vehicle access-control capability and API integration, request an inquiry through the contact page (/contact), where a condensed, RFQ-ready version of this checklist is also available on request.

Related Posts