ISO/IEC 27566-3
ISO/IEC 27566-3 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 3: Approaches to analysis or comparison
[DRAFT]
Abstract
ISO/IEC 27566 part 3 "establishes considerations for analysing, comparing or differentiating the characteristics of age assurance systems or components. The document includes metrics, elements and indicators of effectiveness for age assurance systems or components."
[Source: Committee Draft]
Introduction
Part 3 concerns gaining assurance regarding the accuracy of age verification approaches through techniques to measure, analyse and compare approaches - for example when adult website or application designers are considering various ways to distinguish children from adult users.
Scope
Measuring relevant characteristics and analysing them in order to assess the suitability of various age assurance approaches.
The standard does not define age thresholds or criteria to determine whether the age detection system is or is not appropriate for a given use case, but rather describes how to go about examining and analysing the system for its suitability.
Structure
Main clauses (so far - in the 2nd Committee Draft):
5: Approaches to analysis or comparison
6: Indicators of effectiveness
7: Analysis considerations
8: Characteristics and measurements for age assurance components
9: Reporting of analysis results
Annex A: Document authenticity
Annex B: Illustrative age assurance deployment models
Annex C: Measurement of the classification accuracy for classification models using facial analysis
Annex D: Sample breakdowns, liveness detecton and biometric presentation attack detection for facial age estimation methods
Annex E: Example analysis report
Status
The standard development project launched in 2023.
Part 3 is at Draft International Standard stage. It may be published towards the end of 2026 but more likely in 2027.
Commentary
See also ISO/IEC 27566-1 and ISO/IEC 27566-2.
