A failed biometric match should trigger a straightforward manual review of the passenger’s ID and boarding pass, not an ad hoc workaround. The fallback process needs to preserve safety, maintain throughput, and avoid delaying legitimate travellers unnecessarily. A clear human review path also reduces pressure to overtrust the biometric system as the only gatekeeper.
Manual review should be the default fallback, not an exception path
When biometric boarding fails or a traveller opts out, the right response is a controlled manual identity check against the person, the boarding document, and the operational record. That keeps the process predictable, reduces queue friction, and avoids turning biometric failure into an arbitrary dispute at the gate. The fallback should be designed as part of the boarding workflow, not improvised by staff under pressure.
The important distinction is that a biometric system can assist boarding, but it should not become the sole source of truth when it returns no match or when consent is withdrawn. The fallback needs to preserve safety, protect legitimate travellers from unnecessary delay, and keep staff from making inconsistent case-by-case decisions.
Design the fallback so it preserves throughput and trust
A good manual review path is fast, bounded, and easy to execute. Staff should know exactly which documents to inspect, what constitutes a satisfactory check, and when escalation is required. If the fallback is vague, agents will invent workarounds, apply different standards at different gates, or pressure passengers to retry the biometric step just to keep the line moving.
That is where operational quality matters: the process must handle false rejects, partial captures, accessibility issues, and deliberate opt-outs without creating a second, less reliable security decision. For passengers who decline biometric processing, the check should be no more burdensome than necessary to verify eligibility for boarding.
For organisations using biometrics as part of a broader identity control strategy, the control objective is still the same: confirm the traveller’s identity in a way that is proportionate to the risk and workable at the point of departure. General guidance on secure operations and access decisions is consistent with this approach, including NCSC UK Advice and Guidance and the security and privacy control families in NIST SP 800-53 Rev 5 Security and Privacy Controls.
Risk and Threat Considerations
Biometric boarding introduces a failure mode if staff treat the biometric result as definitive even when the system rejects a legitimate passenger or the traveller declines enrollment. The main risks are exclusion of valid travellers, inconsistent gate decisions, and pressure to bypass the intended check in order to maintain flow.
Failure mechanism: A false reject, temporary sensor issue, or opt-out can push staff toward ad hoc judgment, which weakens consistency and may create an unofficial override path that is harder to audit than the biometric check itself.
Impact: Legitimate travellers can be delayed or wrongly denied boarding, while the organisation loses confidence in the control because the fallback is not clearly defined, repeatable, or defensible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management, Authentication, and Access Control | Manual fallback after biometric rejection is an access-control decision. |
| PR.PT-3 — Least Functionality | Gate processing should use only the minimum checks needed to complete boarding safely. | |
| Recommendation — Define a manual identity verification path for biometric failures and opt-outs. Limit fallback review to the minimum information required to confirm boarding eligibility. | ||
| CIS Controls v8 | 6 — Access Control Management | The boarding fallback is a controlled access decision when automation does not resolve identity. |
| 14 — Security Awareness and Skills Training | Staff need a consistent, trained response to biometric failure and opt-out cases. | |
| Recommendation — Standardize manual review steps for rejected or declined biometric checks. Train gate staff to apply the same fallback procedure every time biometric boarding fails. | ||
| NIST SP 800-63 | 5.2 — Identity Proofing and Enrollment | Biometric boarding depends on trustworthy identity verification and recovery when the primary check fails. |
| Recommendation — Use a documented alternate verification path when biometric matching does not succeed. | ||
Practitioner Guidance
What to verify: The fallback path should be rehearsed at the gate, with staff able to show that manual review is the expected response to rejection or opt-out, not a discretionary exception. Verify that the review is limited to the minimum evidence needed to confirm the traveller’s identity and boarding eligibility.
Common mistake: Teams often optimise for biometric adoption metrics and forget that the real control is the end-to-end boarding decision. If the fallback is slow or unclear, staff will compensate informally, which is exactly where errors and inconsistent treatment begin.
Practitioner takeaway: The best fallback is one that is boring in practice, because it is predefined, quick to execute, and strong enough to handle both false rejects and opt-outs without turning the biometric system into a hard gate that can fail the journey.
Related resources from NHI Mgmt Group
- Why do aviation privacy programs face higher risk when they use biometric boarding and automated passenger profiling?
- What breaks when biometric screening cannot handle variable lighting, movement, and passenger behaviour?
- How should border and airport teams balance faster passenger flow with strong identity verification in biometric departure processing?
- How should teams roll out biometric sign-in without forcing every customer onto Face ID or Touch ID immediately?