What This Template Is For
You're considering using facial recognition or other biometric systems at branch locations to identify known fraud actors before they reach a teller window. This template provides a policy framework that addresses operational controls, privacy boundaries, and escalation protocols.
Financial institutions can deny services based on risk management. The law doesn't require you to serve everyone without exception. However, deploying biometric identification systems requires clear governance: who gets added to your watchlist, how staff respond to alerts, and what documentation you maintain.
This template focuses on access control decisions, not identity verification for account opening. It's designed for physical security teams working with compliance to manage known-risk individuals entering branches.
Prerequisites
Before customizing this template, ensure you have:
Legal review of biometric data laws in your operating jurisdictions. Illinois's Biometric Information Privacy Act (BIPA), Texas's Capture or Use of Biometric Identifier Act, and similar state laws impose consent, retention, and deletion requirements. Your policy must comply with the strictest standard in any state where you operate.
A defined risk classification system. You need criteria for who appears in your biometric watchlist. Categories might include individuals subject to active Suspicious Activity Reports (SARs), persons named in law enforcement alerts, customers terminated for fraud or AML violations, or non-customers involved in documented fraud attempts.
Integration between your security platform and case management system. Alerts must route to staff who can act on them. A facial recognition hit means nothing if the teller has no context or escalation path.
Staff training on response protocols. Your team needs to know what "alert" means, what actions they can and cannot take, and how to document the interaction.
The Template
BIOMETRIC ACCESS CONTROL POLICY
Effective Date: [DATE]
Policy Owner: [TITLE]
Review Frequency: Annual
1. PURPOSE AND SCOPE
This policy governs the use of biometric identification systems (facial recognition, fingerprint scanning) to identify high-risk individuals entering [INSTITUTION NAME] branch locations. The system supports fraud prevention, AML/CFT risk management, and physical security objectives.
This policy applies to all branch locations using biometric access control systems and all staff who receive or respond to system-generated alerts.
2. WATCHLIST CRITERIA
The biometric watchlist includes individuals who meet one or more of the following criteria:
a) Subject of a filed Suspicious Activity Report within the past [X] months
b) Customer whose account was closed due to fraud, money laundering, or sanctions violations
c) Non-customer involved in a documented fraud attempt or identity theft incident
d) Individual named in a law enforcement alert or information request
e) Person subject to a trespass notice or branch ban for threatening behavior
Inclusion requires approval by [ROLE: e.g., Security Director and MLRO].
3. DATA COLLECTION AND RETENTION
Biometric identifiers (facial geometry, fingerprints) are collected from:
- Security camera footage during documented incidents
- Government-issued identification presented during prior transactions
- Law enforcement bulletins or alerts
Biometric data is stored in [SYSTEM NAME] with access limited to [ROLES]. Retention period: [X] years from last alert or until removal criteria are met, whichever is earlier.
4. ALERT RESPONSE PROTOCOL
When the system generates an alert:
STEP 1: Staff receives a discrete notification identifying the individual's risk category (fraud risk, SAR subject, law enforcement interest, trespass notice).
STEP 2: Staff does NOT deny service solely based on the alert. Staff observes the transaction and applies standard due diligence procedures.
STEP 3: For fraud risk or SAR subject alerts: Staff escalates unusual transaction requests to [ROLE] before processing. Staff documents the interaction in [SYSTEM].
STEP 4: For trespass notice alerts: Staff contacts security immediately. The individual is asked to leave the premises.
STEP 5: For law enforcement interest alerts: Staff processes the transaction normally and notifies [ROLE] after the individual leaves. Do not detain or question the individual.
5. PROHIBITED ACTIONS
Staff must NOT:
- Disclose the existence of the biometric system to customers or visitors
- Refuse service based solely on an alert without supervisory review
- Share alert details with unauthorized personnel
- Use the system to monitor employees or conduct non-security surveillance
6. REMOVAL FROM WATCHLIST
Individuals are removed when:
- The retention period expires
- Law enforcement confirms the alert is no longer active
- Legal counsel directs removal following a dispute or legal challenge
- The MLRO determines the risk no longer warrants monitoring
Removal requires approval by [ROLE].
7. PRIVACY AND LEGAL COMPLIANCE
This policy complies with [LIST APPLICABLE LAWS: e.g., Illinois BIPA, Texas CUBI Act, GDPR if applicable].
For jurisdictions requiring consent: [DESCRIBE CONSENT MECHANISM, e.g., posted signage, opt-out procedures for customers].
Biometric data is not sold, shared with third parties (except law enforcement pursuant to legal process), or used for marketing purposes.
8. AUDIT AND OVERSIGHT
[ROLE] conducts quarterly reviews of:
- Watchlist additions and removals
- Alert response times and outcomes
- Staff compliance with response protocols
- System accuracy and false positive rates
Annual audit includes legal compliance review and assessment of privacy impact.
9. INCIDENT REPORTING
Staff must report:
- System malfunctions or false positives
- Inappropriate access to biometric data
- Customer complaints or privacy concerns
- Any use of biometric data outside this policy's scope
Report to [ROLE] within [TIMEFRAME].
How to Customize It
Retention periods: State laws vary. Illinois BIPA requires a publicly available retention schedule. Set your retention period based on the longest applicable state requirement, typically three to five years for fraud-related records.
Risk categories: Tailor your watchlist criteria to your institution's risk profile. A bank with high elder fraud exposure might include individuals linked to romance scams. A fintech with significant cryptocurrency activity might focus on individuals associated with mixer services or sanctions evasion.
Alert routing: Map alerts to roles with authority to act. Fraud risk alerts go to branch managers or fraud analysts. SAR subject alerts route to the MLRO or BSA officer. Trespass notices go to security. Don't send alerts to frontline staff who lack decision-making authority.
Consent mechanisms: If you operate in a consent-required jurisdiction, add signage at branch entrances: "This facility uses biometric identification systems for security purposes. By entering, you consent to biometric data collection as described in our privacy notice." Provide a link or QR code to your full privacy policy.
Removal triggers: Define clear exit criteria. A SAR subject should remain on the watchlist for at least the SAR lookback period (typically five years under BSA recordkeeping rules). A fraud attempt victim should be removed once the case closes and any litigation risk expires.
Validation Steps
Legal sign-off. Your general counsel or outside privacy counsel must review the policy before deployment, especially the data retention, consent, and removal sections.
Test alert routing. Run simulated alerts through your system. Confirm that notifications reach the correct roles, include sufficient context, and don't expose sensitive details to unauthorized staff.
Staff comprehension check. Quiz frontline staff on response protocols. They should know what each alert category means and what actions they can take without supervisor approval.
False positive rate assessment. After 30 days of operation, measure how often alerts identify the wrong person. Facial recognition accuracy varies by lighting, camera angle, and demographic factors. If your false positive rate exceeds [THRESHOLD: e.g., 5%], recalibrate your system thresholds or add a secondary verification step.
Privacy impact assessment. Document what data you collect, where it's stored, who accesses it, and how long you keep it. Many jurisdictions require this assessment before deploying biometric systems. Update it annually or whenever you change watchlist criteria.
Incident response drill. Simulate a scenario where a watchlisted individual enters a branch and attempts a high-risk transaction. Evaluate whether staff follow the protocol, escalate appropriately, and document the interaction correctly.
This isn't a customer identification program. It's a risk management tool that helps you apply enhanced scrutiny to individuals with documented fraud or AML red flags. Your policy should make that distinction clear and ensure staff understand the difference between flagging risk and denying service arbitrarily.



