What to Look for in a Biometric Testing Laboratory

Using an independent testing laboratory is a critical component of managing risk across the lifecycle of a biometric programme. This applies whether the buyer is a vendor preparing a product for certification or an end user procuring a system that will sit in front of customers, citizens, or employees. A test report is a piece of evidence that will travel with the product through procurement reviews, regulator enquiries, audit cycles, and, increasingly, public scrutiny. 

This post outlines the criteria that vendors and end users should weigh when selecting a biometric testing partner, drawing on standards under ISO/IEC, NIST, FIDO Alliance, CEN/CENELEC, and the scheme-specific frameworks that now shape the market. 

This guide is intended as a practical starting point. For organisations planning biometric evaluations, BixeLab is also preparing a more detailed guide on selecting and scoping biometric testing services. To register interest or request early access, please contact the BixeLab team at info@bixelab.com.

Throughout this guide, “vendors” refers to organisations developing biometric products that need certification or assurance for sale; “end users” refers to organisations procuring biometric systems including banks, government agencies, and large employers, that will operate those systems in front of customers, citizens, or employees. Where the advice applies to both groups, this guide uses the term “buyers”. 

Accreditation Is the Baseline, Not the Differentiator

Accreditation under ISO/IEC 17025 is the minimum credential that a biometric testing laboratory should hold. The standard governs the technical competence of testing and calibration for laboratories and is the mechanism by which national accreditation bodies- like NVLAP in the United States, NATA in Australia, UKAS in the United Kingdom, and their counterparts elsewhere- confirm that a lab’s methods, staff, equipment, and quality system meet international expectations. 

When choosing a laboratory, buyers should confirm the accreditation is current, identify the scope of accreditation (the specific standards and test methods covered), and check that the accreditation body is a signatory to the ILAC Mutual Recognition Arrangement.  

Scheme Recognition Determines Where the Report Is Useful

Scheme recognition is distinct from ISO/IEC 17025 accreditation: where accreditation confirms baseline technical competence, scheme recognition confirms that a laboratory has been formally approved by a specific certification scheme to perform testing against that scheme’s requirements. The two are usually held in addition to one another, not as alternatives. 

Beyond ISO/IEC 17025, several certification schemes maintain their own lists of recognised laboratories. A report from a non-recognised lab, however technically sound, will not be accepted into a scheme’s formal certification process. The practical consequence is that vendors must select their laboratory with the target market in mind. 

FIDO Alliance

The FIDO Alliance recognises laboratories separately for its Biometric Component Certification (BCC), Identity Verification and Binding (IDV), and Document Authenticity (DocAuth) programmes.  

MOSIP

The Modular Open Source Identity Platform (MOSIP) operates the MOSIP Accredited Compliance Provider (MACP) scheme for foundational identity ecosystems.  

European Digital Identity (EUDI) Regulation

For products targeting European Digital Identity frameworks, recognition under the emerging EUDI evaluation schemes is becoming relevant.

These schemes are expected to reference CEN/TS 18099 for injection attack detection testing alongside ISO/IEC 30107 for biometric presentation attack detection testing. End users procuring biometric solutions that must be auditable against these schemes, should ask which qualifications the lab holds and confirm those recognitions directly with the scheme owner.

Standards Fluency Signals the Ceiling of What a Lab Can Do

Accreditation confirms a lab can execute specific test methods correctly. Fluency across the wider standards landscape determines whether a lab can design a meaningful evaluation when the requirement does not map cleanly to a single standard (which in biometrics, is most of the time). 

Observable indicators of standards fluency include: active participation in the relevant standards development bodies (ISO/IEC JTC 1/SC 37, the national mirror committees such as Standards Australia IT-032, the FIDO Alliance working groups, MOSIP working groups); contributions to published standards; technical commentary or editorial roles in normative documents; and a track record of explaining, in a scoping conversation, how multiple standards interact for a specific evaluation. A lab that can only point to its accreditation scope, without speaking to the standards landscape around it, is competent but not fluent. 

For biometric performance testing, the ISO/IEC 19795 series define the necessary methodology across technology, scenario, and operational evaluations, with Part 10 covering demographic differential performance, which provides the basis for demographic differential performance evaluation. For presentation attack detection testing, the ISO/IEC 30107 series remain the primary reference, with Part 3 specifying the testing framework. For injection attack detection testing, which is still a novel and developing discipline, CEN/TS 18099 and emerging ISO/IEC work are now shaping expectations. Biometric sample quality is addressed by the ISO/IEC 29794 series. Information security management is governed by ISO/IEC 27001. For template protection, ISO/IEC 30136 and IEEE Std 2410 remain the key references. 

A capable laboratory should be able to speak to how these standards interact. For example: why ISO/IEC 30107-3 PAD testing without an accompanying ISO/IEC 19795-1 baseline accuracy evaluation leaves a meaningful gap; or how ISO/IEC 19795-10 demographic differential testing interacts with confidence interval reporting when subject pool is small. The response to “which standards apply here and why?” is a reliable indicator of depth.

Independence and Impartiality Are Non-Negotiable

ISO/IEC 17025 requires laboratories to operate impartially, and reputable schemes enforce separation between testing, consulting, and product development. Buyers should confirm that the laboratory does not also develop, resell, or hold a commercial stake in the technology under test.  

A practical conflict-of-interest check is whether the laboratory has helped build, tune, train, or supply datasets for the same product or vendor it is later being asked to test. For example, a laboratory that produces or curates training or benchmark datasets for a vendor may have a perceived or actual conflict if it subsequently evaluates that vendor’s product against related performance claims. Buyers should ask the laboratory to disclose any prior involvement with the technology, datasets, configuration, or vendor development process before relying on the report for procurement or certification evidence. 

This matters for vendors because reports provided by laboratories seen as partial are commonly challenged or rejected by regulators and downstream customers, and it matters for end users because an impartial evaluation is the only kind that delivers meaningful assurance. 

Report Quality Determines Whether Evidence Survives Scrutiny

A biometric test report should be readable by a technical reviewer up to two years after issue, without the authors present, and still answer the substantive questions a procurement reviewer, regulator, or audit cycle would put to it: methodology, sample composition, environmental conditions, statistical treatment, and confidence intervals. Buyers should request a redacted sample report before engaging a laboratory. 

Specific features to look for in a high-quality test report include:  

  • clear articulation of the test plan against the governing standard 
  • explicit reporting of the metrics appropriate for the evaluation type, with relevant confidence intervals. Typical examples include APCER, BPCER and IAPAR for PAD and IAD evaluations, and FMR, FNMR, FTA and FTE for biometric performance evaluations. 
  • traceability between raw data and reported figures (an auditable path from each headline metric back to the underlying comparison decisions that produced it) 
  • explicit reporting of edge cases, outliers, and how they were handled in the analysis.  
  • exclusions, constraints, and any protocol deviations.  
  • High-quality test reports use precise, evidence-based summary language and provide complete and balanced reporting of methods, results, limitations, and supporting data. 

Demographic Reach Matters for Fairness and Realism

A demographic differential performance evaluation under ISO/IEC 19795-10, informed by the methodology described in NIST Interagency Report 8280, depends on test crews that meaningfully represent the demographic groups relevant to the technology under test’s deployment context. A laboratory with a narrow subject pool will likely not produce credible demographic differential performance results for a product deployed across multiple regions. End users particularly should ask how a laboratory recruits and manages subjects, how it documents demographic composition, and how it handles intersectional categories. 

Data Governance Is Part of the Service, Not an Afterthought

Biometric evaluations generate sensitive data: face images, fingerprint captures, liveness video, device telemetry, and often personally identifiable information from test subjects. A laboratory’s data handling procedures should be documented under ISO/IEC 27001, or an equivalent information security management framework, and include written policies on subjects such as data retention, access control, cross-border transfer, and subject consent. For programmes operating under regulatory regimes such as the Reserve Bank of India’s digital payment security and biometric data directions, Bank Negara Malaysia’s e-KYC and Risk Management in Technology (RMiT) requirements, the State Bank of Vietnam’s Circular 50/2024, or Australia’s Digital ID Act 2024 and AGDIS framework, the lab should be able to articulate how its data handling processes align. 

For Vendors: Prioritise Pathway Clarity and Iteration Support

A vendor preparing for testing is buying two things from a laboratory: a compliant report and the shortest credible path to that report. The laboratory should be able to map the vendor’s product to the relevant scheme, identify the most efficient testing pathway, and flag likely pre-test issues before a formal evaluation begins. Pre-assessment or readiness review services can surface attack surface weaknesses, and metric shortfalls before a formal evaluation begins, when remediation is typically cheaper than after. Vendors should also ask about the laboratory’s experience with their specific modality, capture environment, and deployment context, because generic biometric competence does not always translate across modalities or form factors. 

For End Users: Prioritise Assurance and Procurement Alignment

An end user procuring a biometric system is buying assurance that the system will perform as claimed, for the population it will serve, under the conditions of operational use. The relevant question is, “has the product been tested in a way that answers my risk questions?” For example, a FIDO BCC certification confirms component-level performance and PAD resistance, but does not by itself, answer operational questions about enrolment drop-off in a branch environment or demographic performance across a specific customer base. This is why end users should consider whether a technology evaluation alone meets their assurance needs, or whether scenario and operational evaluations under ISO/IEC 19795-2 and 19795-6 are also required.

Questions Worth Asking During Due Diligence

  • A short, direct due-diligence conversation usually separates capable laboratories from those overstating their reach. Useful questions include:  
  • What is the scope of your ISO/IEC 17025 accreditation and your scheme recognitions, which bodies issued each, and which are currently active?  
  • Can you share a redacted sample report relevant to our programme?  
  • How do you handle independence and any potential conflicts of interest?  
  • What is your subject recruitment process, and how is demographic composition documented?  
  • How is evaluation data stored, retained, and disposed of?  
  • Who signs off on the test report, and what is their technical background?  

Answers to these questions, when considered as a whole, provide a reliable picture of whether the laboratory is a good fit for the programme at hand.

Closing Thought

A test report is only as useful as the laboratory that stands behind it. The criteria above – accreditation scope, scheme recognition, standards fluency, impartiality, reporting rigour, data governance, demographic reach, and practical testing experience, are the dimensions along which that usefulness is determined. Vendors and end users who apply these criteria early in the engagement cycle are far more likely to end up with evaluations that withstand procurement reviews, regulatory scrutiny, and the passage of time. 

BixeLab brings these elements together through a specialist focus on biometric and digital identity evaluation. As an NVLAP-accredited biometric testing laboratory, BixeLab operates under ISO/IEC 17025 and supports evaluations across biometric performance, presentation attack detection, document authenticity, injection attack detection, demographic differential performance, and operational assurance. Its work is grounded in relevant ISO/IEC standards, FIDO Alliance requirements, MOSIP compliance frameworks, CEN/CENELEC guidance, and practical experience testing real-world biometric systems across certification, procurement, and assurance contexts. 

Stay Connected

BixeLab is based in Canberra, Australia, and is NVLAP-accredited under Lab Code 600301-0, with recognitions across ISO/IEC 19795, ISO/IEC 30107, FIDO BCC/IDV/DocAuth, and MOSIP MACP. To discuss a programme or register interest in the upcoming whitepaper, contact the BixeLab team at info@bixelab.com or click below button.