Join our Newsletter — 33% off our NHI Course
Authentication, Authorisation & Trust

Equal Error Rate

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: Authentication, Authorisation & Trust

Equal Error Rate is the point where a biometric system’s false rejection rate and false acceptance rate are equal. It is used as a useful benchmark for comparing biometric methods and tuning thresholds. A lower EER generally indicates a more accurate system, though the best operating point still depends on the use case.

What EER Measures in Biometric Performance

Equal error rate, or EER, is a threshold-based comparison point for biometric systems. It marks the operating point where false rejection and false acceptance are numerically equal, giving practitioners a compact way to compare methods on the same scale.

Because EER is a benchmark, it does not by itself tell you whether a biometric system is suitable for a specific deployment. Two systems can have similar EER values but behave differently at the threshold a business actually needs, especially when one use case tolerates more inconvenience and another demands tighter security.

Why EER Is Useful, and What It Does Not Show

EER is helpful because it reduces a complex tradeoff into a single reference point. That makes it easier to compare biometric algorithms, evaluate sensor quality, and track whether a tuning change improves or degrades overall discrimination between genuine and impostor attempts.

At the same time, EER hides the operational context that matters in production. A system with a low EER may still be a poor fit if the real deployment needs a far lower false acceptance rate, since small changes in threshold can have a large effect on user friction and access risk.

EER is also more informative when read alongside other metrics such as false acceptance rate, false rejection rate, ROC or DET curves, and the expected user population. That broader view helps explain whether the apparent performance balance is actually acceptable for the intended assurance level.

How to Interpret EER in Real Deployments

The best way to interpret EER is as a comparative indicator, not a universal pass or fail test. A lower EER usually signals stronger biometric separation, but the acceptable threshold still depends on the cost of letting the wrong person in versus turning the right person away.

In high-assurance environments, a low EER may still need to be paired with stricter operating thresholds, liveness checks, or additional factors because the equal-error point may sit well above the organization’s acceptable security posture. In lower-friction consumer experiences, the same EER may be acceptable if usability is the priority and the consequence of occasional error is modest.

If the biometric is used as one signal among several, EER becomes only one part of the design conversation. In that case, the more important question is whether the chosen threshold delivers the required balance of access confidence, false alarm tolerance, and user experience.

Common Sources of Confusion Around EER

EER is often mistaken for a complete measure of biometric quality, but it is only one summary point from a larger error curve. It does not show whether the system behaves asymmetrically, whether one error type is more dangerous than the other, or how performance shifts across different subpopulations and environmental conditions.

It is also easy to overread small differences in EER. In practice, the measurement method, dataset quality, sensor conditions, and population makeup can all affect the result, so the number should be treated as a decision aid rather than a standalone claim of security or fairness.

When comparing vendors or biometric modalities, EER is most useful when the test conditions are comparable and the same evaluation protocol is used across candidates. Without that consistency, the number can look precise while still being misleading.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Biometric EER helps assess authentication accuracy for organizational access decisions.
IA-8 — Identification and Authentication (Non-Organizational Users)EER informs biometric assurance where external users are authenticated.
IA-12 — Identity ProofingBiometric error rates affect confidence in proofing and enrollment outcomes.
Recommendation — Set biometric acceptance thresholds to balance false rejects and false accepts for user authentication. Tune biometric thresholds for external-user authentication to match the required assurance level. Use biometric performance evidence to support proofing decisions and enrollment quality checks.
NIST SP 800-63Biometric performance and verifier confidenceDigital identity guidance uses biometric error rates to frame authentication assurance decisions.
Recommendation — Compare biometric performance against the assurance target before selecting the authenticator.
ISO/IEC 27001:2022A.8.5 — Secure authenticationBiometric threshold choice is part of secure authentication design and operation.
Recommendation — Document and review biometric authentication settings as part of secure authentication controls.
NIST CSF 2.0PR.AA-05 — Authenticator ManagementEER supports decisions about authenticator strength and operating thresholds.
Recommendation — Adjust authenticator settings so biometric checks meet the intended access risk tolerance.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org