top of page

ISO/IEC 27566-3

ISO/IEC 27566-3 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 3: Approaches to analysis or comparison

[DRAFT]

Abstract

ISO/IEC 27566 part 3 "establishes considerations for analysing, comparing or differentiating the characteristics of age assurance systems or components. The document includes metrics, elements and indicators of effectiveness for age assurance systems or components."


[Source: project team]

Introduction

Part 3 concerns assurance regarding the accuracy of age verification approaches such as facial imagery, offering techniques to measure, analyse and compare approaches - for example when adult website or application designers are considering various ways to distinguish children from adults. 

Scope

Measuring relevant characteristics and analysing them in order to assess the suitability of various age assurance approaches.

Structure

Main sections (in Committee Draft):

  • 5: Approaches to analysis or comparison

  • 6: Indicators of effectiveness

  • 7: Analysis considerations

  • 8: Characteristics and measurements for age assurance components

  • 9: General reporting principles

  • Annex A: Effectiveness analysis

  • Annex B: Example analysis report

  • Annex C: Document authenticity

  • Annex D: Use case examples

  • Annex E: Indicative effectiveness banding

  • Annex F: Measurement of the classification accuracy for classification models using facial analysis

  • Annex G: Sample breakdowns, liveness detection and biometric presentation attach detection for facial age estimation methods

  • Annex H: Image quality impact for age estimation methods using facial analysis

Status

The standard development project set off in 2023.


This was originally destined to become part 2, then shifted to part 3.


Part 3 is at Working Draft stage.

Commentary

Fade to black

This page last updated:

2 November 2025

© 2025 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page