buyer guide

Face Recognition Access Control: How to Choose a Terminal

A face recognition access control system matches a live face to enrolled templates. Compare liveness, outdoor ratings, wiring, capacity and GDPR storage.

Key takeaways

  • Specify liveness detection by method (binocular visible + near-infrared, or 3D depth), not by the word "anti-spoofing" alone.
  • In 1:N mode, the chance of a false match grows roughly in proportion to the number of enrolled faces at a fixed threshold; use 1:1 card + face on large or sensitive doors.
  • Outdoor doors need more than an IP code: check IK rating, operating temperature, WDR and which way the camera faces the sun.
  • Run the terminal as a reader (Wiegand or OSDP) where security matters, and keep the lock relay on the secure side of the door.
  • Face templates are biometric data under GDPR Article 9 and laws such as Illinois BIPA; decide where templates are stored before you buy.

A face recognition access control system grants entry when a camera matches a live face against templates enrolled in advance, then signals a lock, turnstile or access panel. To choose a terminal, compare five things: how it detects spoofing, whether it copes with your site’s light and weather, how it passes identities to your controller, where it stores face data, and whether its capacity fits your user count.

How face terminals work: templates and 1:N matching

Enrollment comes first. The terminal or its management software captures a face image, detects and aligns the face, and runs it through a recognition algorithm that outputs a template: a compact set of numbers describing the face, sometimes called an embedding. Many terminals also keep the enrollment photo, which matters for privacy and for any later migration.

At the door, the terminal builds a template from the live image and compares it with the enrolled ones. There are two modes:

  • 1:N identification. The live face is searched against every enrolled template (the gallery). If the best similarity score clears the configured threshold, the terminal grants access for that user. No card or PIN is needed. See 1:N face matching.
  • 1:1 verification. The user presents a card or enters a PIN first, and the terminal compares the face only with that user’s template. This adds a second factor and limits false-match exposure to a single comparison.

The threshold sets the trade-off between the false accept rate (FAR, an impostor is accepted) and the false reject rate (FRR, an enrolled user is asked to try again). Raising the threshold lowers FAR and raises FRR. Vendors usually expose it as a security level; set it per door instead of leaving the default everywhere.

Gallery size matters in 1:N mode. If one comparison has a false match rate p, the chance that a live face falsely matches at least one of N templates is 1 − (1 − p)N, roughly N × p while that product is small. A door that behaves well with 200 enrolled users can produce more false matches at 20,000 unless the threshold is raised or 1:1 verification is used.

Templates are also algorithm-specific. One vendor’s templates generally cannot be used by another vendor’s algorithm, so changing platforms usually means re-enrolling users or re-importing their enrollment photos.

Liveness detection methods

Liveness detection, also called presentation attack detection (PAD), decides whether the camera sees a real, present person rather than a printed photo, a video on a phone or tablet, or a mask. It is the biggest technical difference between entry-level and serious terminals.

Method Sensor hardware Attacks it is designed to resist Trade-offs
Passive, single visible-light camera 1 × RGB camera Printed photos, some screen replays Relies on image cues only; weakest against high-quality screens and video
Binocular visible + near-infrared (NIR) 1 × RGB + 1 × NIR camera, IR illuminator Printed photos and screen replays (a phone or tablet screen emits visible light only, so a replayed face looks wrong to the NIR camera) Higher cost; not a guarantee against realistic 3D masks
3D depth (structured light or time-of-flight) Depth sensor with IR projector Flat photos, screens and many masks Highest cost; limited working distance; strong sunlight can degrade IR-based depth outdoors
Active challenge (blink, head turn) Any camera plus software Static photos Slows every transaction; poor fit for turnstiles and busy lobbies

Two practical points. First, “anti-spoofing” on a datasheet says nothing about the method. Ask which sensors are used, and confirm liveness is switched on at commissioning.

Second, the international test method for PAD is ISO/IEC 30107-3. If a vendor claims PAD performance, ask for the test report, who ran it and which attack types were included.

Outdoor face recognition access control: IP65, WDR, sunlight and temperature

A terminal that works well in a lobby can struggle at a gate. For outdoor or semi-outdoor doors, check:

  • Ingress protection. IP65 means dust-tight and protected against water jets from any direction; IP66 adds protection against powerful jets. Indoor terminals often carry no IP rating at all. Confirm that cable entries and the back box are sealed, not only the front face.
  • Impact resistance. For unattended gates, look for an IK rating under IEC 62262: IK08 withstands 5 J impacts and IK10 withstands 20 J.
  • Wide dynamic range (WDR). A face in shade against a bright sky or glass entrance is the classic backlight problem. A WDR sensor keeps both face and background usable; ask for the WDR figure in dB and test on site at the worst time of day.
  • Sun angle. Do not point the camera toward the rising or setting sun, and avoid spots where users stand with the sun directly behind them. A canopy or hood reduces lens glare and screen washout.
  • Temperature and condensation. Indoor-class terminals are often rated for a narrow band such as 0 to +45 °C. For cold or hot climates, confirm the full-function operating range and how the display behaves near its limits.
  • Night operation. Terminals with an NIR illuminator can recognize faces in darkness. A visible white fill light helps color cameras but can dazzle users, so check both in your actual lighting.

Glasses, masks and sunglasses

Does facial recognition work with glasses? For clear prescription glasses, generally yes. Enroll users as they normally appear at the door, and if the terminal supports more than one template per user, add one without glasses for people who switch to contact lenses.

Problems come from the edge cases:

  • Reflections. The terminal’s own IR illuminator can reflect off lenses and hide the eyes. A small change in tilt or mounting height often fixes it.
  • Sunglasses. Results depend on tint and coatings. Some dark lenses pass enough near-infrared for an NIR camera to see the eyes; others do not. Many sites simply ask users to remove sunglasses at the door.
  • Face masks. Many terminals offer a mask mode that matches on the upper face. With less of the face visible there is less to match, so expect more rejections, or use card + face verification where it matters.
  • Hats and hoods. Deep brims and hoods shadow the eyes; signage at the door helps.
  • Appearance over time. Beards, weight change and aging drift away from the enrollment template. Plan a re-enrollment path; some terminals can update templates after successful matches, so confirm how that works before enabling it.
  • Identical twins. Face recognition cannot reliably separate them. Give those users a card or PIN as a second factor.

Mounting height affects matching too. Follow the vendor’s recommended height and camera angle, then check that your shortest and tallest users, and anyone using a wheelchair, fall inside the recognition field.

Integration: Wiegand, relay, TCP/IP and SDK

Face terminals fit into a system in one of three ways. Choose the architecture first, then check the ports.

1. Standalone. The terminal stores users, makes the decision and switches its own relay (NO/COM/NC dry contact) to drive the lock, with inputs for an exit button and door status sensor. It is quick to install, but if the terminal sits on the unsecured side, anyone who pulls it off the wall reaches the lock wiring. Where security matters, keep the lock-switching relay on the secure side, in a controller or separate relay module inside the protected area.

2. Reader for an existing panel. The terminal identifies the user and sends that user’s ID as a Wiegand message; the panel treats it like a card read and makes the decision. Wiegand 26 carries an 8-bit facility code (0–255) and a 16-bit number (0–65,535) plus two parity bits; Wiegand 34 carries 32 data bits plus two parity bits. Allocate user IDs to fit the chosen format and match the panel’s records, as explained in the Wiegand 26-bit format guide. Many terminals also have a Wiegand input, so an external reader, such as one of our encrypted card readers, can supply card numbers for card + face verification.

Wiegand is one-way and unencrypted. If your panel supports OSDP, which runs over RS485 and offers Secure Channel encryption, ask whether the terminal supports it; do not assume so. Our Wiegand vs OSDP guide compares the two.

3. Networked. Over TCP/IP (Ethernet, sometimes Wi-Fi), terminals sync users and templates with management software and upload event logs. For custom platforms, review the SDK or HTTP API documentation before ordering. Integrators most often need user and photo push, remote door control, real-time event callbacks and firmware updates, and coverage varies between products.

For turnstiles and speed gates, the same choices apply: relay pulses into the gate board’s direction inputs, or Wiegand into the gate’s access controller.

Power. Screens, cameras and illuminators draw far more than a card reader, and some terminals ship with a 12 V DC, 3 A adapter. Size the supply from the datasheet’s peak figure before sharing it with a lock.

Face recognition attendance

Most terminals double as time-and-attendance clocks. Each recognition is logged with user ID, time and often a snapshot, and the software or API exports punches to payroll. Check log capacity, whether attendance status keys (check-in, check-out, break) are supported, and how long snapshots are kept, because they are personal data too.

Data privacy and GDPR: where face templates are stored

In the EU and UK, biometric data processed to uniquely identify a person is special category data under GDPR Article 9. Processing needs a lawful basis under Article 6 plus an Article 9 condition, usually explicit consent for access control, and supervisory authorities generally expect a data protection impact assessment (DPIA, Article 35) before deployment. In workplaces, consent is hard to rely on because of the employer–employee imbalance, so offer a card or PIN to anyone who declines.

Outside Europe the rules differ. In the US, Illinois’ Biometric Information Privacy Act (BIPA) requires written notice, a written release and a public retention and destruction policy; Texas and Washington have their own biometric laws. In the EU, also check how the AI Act applies to your use case. This section is an overview, not legal advice.

Where templates live affects both compliance and risk:

Storage model How it works Advantages Watch-outs
On the terminal only Enrolled and matched locally No central biometric database; works offline A stolen or scrapped terminal holds data; confirm encryption at rest and secure wipe
Terminal + server sync Server holds master records and pushes templates Central enrollment for many doors Two places to secure; deletion must reach every device
Server-side matching Terminal sends images to a server Central control of algorithm and thresholds Network dependency; images in transit must be encrypted
Template on a card (1:1) Template written to the user’s smart card No template database at all Needs card + face and support on both card and terminal; confirm before specifying

Practical controls: keep templates rather than photos where the software allows, delete templates when a user leaves, set retention periods for logs and snapshots, restrict admin access, and ask for encryption details at rest and in transit.

Capacity and speed specs that matter

Datasheets list many figures. These are the ones that change how a deployment behaves:

Specification Unit Why it matters What to ask
Face capacity (1:N gallery) faces Must exceed enrolled users with margin Is recognition time quoted at full gallery?
Card and user capacity users Card + face deployments need both Are faces, cards and users counted separately?
Event log capacity records Offline buffer before logs are overwritten What happens when it is full?
Recognition time ms Throughput at busy doors and turnstiles Measured from face detected to relay output, with liveness on?
Recognition distance m Walk-up comfort and lane layout Minimum and maximum, at what light level?
Screen size in (diagonal) Enrollment, user feedback Readable in direct sunlight?
Operating temperature °C Outdoor and unheated entrances Full-function range, not storage range
Ingress and impact IP / IK code Weather and vandal exposure Rating of the complete unit, including cable entry
Power supply V DC, A PSU and cable sizing Peak current with illuminator on

Face capacity is commonly quoted in classes such as 1,000 or 10,000 faces. Leave headroom for growth, and use 1:1 verification at sensitive doors rather than simply buying the biggest number.

Face recognition terminal price: what drives cost

Configuration moves the price more than the model name does, so we quote per project. These tiers show what shapes a quote:

Tier Typical configuration Where it fits
Entry Small screen, single camera, indoor housing, 1,000-face class Internal doors, small offices, attendance
Mid 5-inch class screen, binocular RGB + NIR liveness, built-in card reader, 10,000-face class Main entrances, multi-door sites, gyms
Upper Larger screen, IP65 metal housing, extra credentials (fingerprint, QR, video intercom), SDK Outdoor gates, turnstile lanes, residential entry

Beyond the terminal, software licensing, the lock, power supply, cabling and, in Europe, the DPIA effort all belong in the comparison. Compare quotes on the complete door, not the terminal alone. You can browse the face recognition terminals we supply to see which configurations are available.

Face terminal specification checklist

  • Liveness method stated (binocular RGB + NIR or 3D depth) and enabled at commissioning
  • ISO/IEC 30107-3 PAD test evidence requested for high-risk doors
  • Face capacity covers enrolled users plus growth; 1:1 card + face available for large galleries
  • IP and IK ratings, operating temperature and WDR confirmed for outdoor doors
  • Mounting position checked for sun angle, backlight and user height range
  • Output matches the panel: Wiegand 26/34 format and ID range, or OSDP if required
  • Lock relay on the secure side; exit button and door status sensor wired
  • SDK or API documentation reviewed for the functions you need
  • Template storage location, encryption and deletion process documented
  • Legal basis, DPIA and a non-biometric alternative in place where GDPR or BIPA applies
  • Power supply sized for terminal peak current plus the lock

Next steps

Send us your door count, number of enrolled users, indoor or outdoor mounting, and the panel or software you need to integrate with. We will shortlist suitable terminals, confirm Wiegand or network compatibility and test before dispatch. Request a quote or sample and we will reply within 24 hours.

Frequently asked questions

Does facial recognition work with glasses?

Yes, clear prescription glasses rarely cause problems if users enroll wearing them. Glare from the terminal's infrared illuminator, thick frames and dark or mirrored sunglasses can increase rejections, so test with your own users and add a second template where the terminal allows it.

Can a face recognition terminal be fooled by a photo?

Terminals that rely on a single visible-light camera are more exposed to printed photos and screen replays. Binocular visible + near-infrared or 3D depth liveness raises the bar; ask whether presentation attack detection was tested to ISO/IEC 30107-3.

Can I connect a face terminal to my existing access control panel?

Usually yes. Most terminals can output the matched user's ID as Wiegand 26 or 34, which the panel treats like a card read; match the format and ID range, and confirm OSDP support explicitly if your panel requires it.

Is face recognition suitable for outdoor access control?

Only with a terminal rated for it: an IP65 or higher enclosure, an operating temperature range that covers your climate and a wide dynamic range (WDR) camera. Shade the unit from direct sun and rain, and avoid mounting positions where users are backlit.

Is face recognition access control allowed under GDPR?

It can be, but face templates used to identify people are special category data under Article 9, so you need an Article 9 condition such as explicit consent, normally a DPIA, and a non-biometric alternative for people who decline. Take legal advice for your jurisdiction.

What affects face recognition terminal price?

The main factors are liveness hardware, enclosure rating, screen size, face capacity and extra credentials such as card, fingerprint, QR or intercom. Software licensing and the lock, power supply and cabling also belong in the comparison.

Want a second opinion on your spec?

Send us your controller, credential type and environment — we'll recommend compatible hardware and quote within 24 hours.

Products mentioned

Hardware for this job

CR-180

Touch Keypad RFID Card Reader, Wiegand 26/34/66

Square 89.5 mm touch-keypad reader for card plus PIN, reading up to 9 cm, in EM, MIFARE, sector-read, FeliCa and dual-frequency versions with Wiegand output.

125 kHz, 13.56 MHz or dual (by version)Wiegand 26/34/66Up to 9 cm
Details →
CR-300

OSDP & Wiegand Metal Card Reader, 125 kHz + 13.56 MHz + BLE

Slim 86 × 86 mm metal reader with OSDP v2.2, RS485, Wiegand and Bluetooth LE 5.3. Reads 125 kHz EM plus MIFARE, DESFire EV1–EV3, ICODE and FeliCa; IP65.

125 kHz + 13.56 MHz + 2.4 GHz (BLE 5.3)OSDP v2.2, RS485, Wiegand0–3 cm
Details →
CR-190

Wiegand 26/34 RFID Card Reader, EM, MIFARE or Dual

Card-only 89.5 mm square reader with Wiegand 26/34 output (66 on upper tiers), in EM, MIFARE, sector-read, FeliCa and dual-frequency versions.

125 kHz, 13.56 MHz or dual (by version)Wiegand 26/34/6612 V DC ±5%, ≤ 200 mA
Details →
CR-130

Metal Keypad Wiegand Card Reader with Doorbell Button

Card-plus-PIN reader in a 120 × 80 mm metal housing with physical keys, a doorbell button and Wiegand 26/34/66 output to your controller.

125 kHz (-E) or 13.56 MHz (-M, -MS, -MS-FC)Wiegand 26/34; 66 on -MS tiersPhysical keys + doorbell button
Details →

Keep reading

Tell us what you are building

Send your card type, interface and quantity. You get a quote, lead time and compatibility notes within 24 hours — samples available for most items.

Email us
sales@valenid.com

Request a quote

Tell us what you need — an engineer replies within 24 hours with pricing, lead time and compatibility notes.

We reply within 24 hours on working days. Your details are used only to answer this inquiry — see our privacy policy.