They should predefine who can approve the fallback, what evidence is retained, and how the exception is reconciled against the traveller record. Without that structure, manual fallback becomes an inconsistent control path rather than a governed part of the identity process.
How should fallback approval work when matching cannot be automated?
manual review should be treated as a controlled exception path, not an informal override. The key question is who is allowed to decide, what they are allowed to see, and what proof is required before the traveller record is reconciled. If those rules are missing, the fallback weakens identity assurance instead of preserving it.
That means the approval flow needs explicit authority boundaries, a defined evidence pack, and a clear record of how the manual outcome maps back to the original biometric event. For teams building that control path, the same discipline used for fallback governance in other identity workflows should be applied consistently.
When the exception is part of a broader access or assurance process, NIST Cybersecurity Framework 2.0 is useful for structuring govern, identify, protect, detect, respond, and recover responsibilities around the fallback path.
What evidence and reconciliation should the manual path require?
The manual reviewer should not be judging the biometric result in isolation. They should be confirming the identity assertion using the strongest available supporting evidence, then recording why the system could not complete matching automatically. The operational goal is to preserve traceability, not to recreate a second ad hoc identity process.
Good reconciliation usually includes a unique case identifier, the original match failure reason, reviewer identity, timestamp, retained artifacts, and the final disposition against the traveller record. Where biometrics are involved, teams should also be careful about how the evidence is retained and protected, since biometric data is sensitive personal data and the fallback may become the place where governance gaps show up most clearly.
For data-protection and lawful-processing obligations around biometric information, the General Data Protection Regulation is a relevant reference point for retention discipline, security of processing, and documentation of exceptional processing paths.
When evidence retention and review records are part of the control, NIST SP 800-53 Rev 5 Security and Privacy Controls provides useful control language for audit logging, identification and authentication, and recordkeeping expectations.
Where do teams usually get the fallback control wrong?
The common failure is treating manual review as a human convenience layer rather than a governed security decision. That creates inconsistent approvals, weak evidence standards, and record mismatches that are hard to audit later. It also invites local workarounds, where different sites or shifts apply different thresholds for the same exception.
A second failure is allowing the reviewer to approve without enough separation between the person making the decision and the systems benefiting from it. If the fallback can be used to “make the trip happen” without clear accountability, it becomes easier for mistakes, coercion, or abuse to bypass the intended biometric control.
For teams that need a threat-oriented control map around identity decisions and abuse paths, the MITRE ATT&CK Enterprise Matrix is useful for thinking about how access abuse, credentialed misuse, and downstream lateral movement emerge once a weak exception path is exploited.
Risk and Threat Considerations
Manual fallback creates risk when it is not bounded by preapproved authority, evidence retention, and reconciliation rules. The exposure is not just an audit problem, because an inconsistent exception path can become a bypass route for identity assurance and a source of privacy and compliance issues.
Failure mechanism: reviewers approve exceptions without consistent criteria, the retained evidence is incomplete or untrustworthy, and the resulting traveller record no longer reflects a defensible identity decision.
Impact: false acceptance, false rejection, audit failure, or privacy non-compliance can follow, and repeated exceptions can erode confidence in the biometric control itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Oversight of cybersecurity risk management | Manual fallback needs governed approval authority and accountability. |
| Recommendation — Define oversight for biometric fallback approvals and require accountable decision ownership. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Fallback decisions must be logged to preserve traceability and auditability. |
| IA-2 — Identification and Authentication (Organizational Users) | Manual approval depends on knowing and authenticating the reviewer authority. | |
| AU-11 — Audit Record Retention | The exception record and supporting evidence must be retained for later reconciliation. | |
| Recommendation — Log each biometric fallback decision, reviewer, and outcome. Require strong authentication for reviewers who can approve fallback decisions. Retain fallback evidence and approval records for the required audit period. | ||
| GDPR | Art.5 — Principles relating to processing of personal data | Biometric fallback handling must remain lawful, minimised, and accountable. |
| Art.32 — Security of processing | Manual review paths need protected evidence and controlled access to biometric data. | |
| Recommendation — Limit retained fallback data to what is necessary and document the processing purpose. Protect fallback records and biometric evidence with appropriate access and security controls. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Exception paths can be abused if reviewers or operators misuse legitimate access. |
| T1098 — Account Manipulation | Poorly governed exception handling can enable unauthorized identity record changes. | |
| Recommendation — Monitor reviewer and operator access for misuse of legitimate accounts. Detect and alert on unauthorized changes to identity or traveller records. | ||
Practitioner Guidance
What to prioritise: define the fallback as a controlled exception workflow with named approvers, required evidence, and a mandatory reconciliation step before the record is closed. If a team cannot explain who may approve, what must be retained, and how the decision is checked later, the control is not ready for production use.
What to verify: confirm that every manual fallback leaves an audit trail that links the original biometric failure, the reviewer decision, and the final traveller outcome. The strongest sign of control health is not low fallback volume, it is consistent disposition quality and complete traceability when fallback does occur.
Practitioner takeaway: manual review is acceptable only when it is narrower, more observable, and more defensible than the automated path it replaces.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org