Pre-ICO Audit Compliance Review – Facial Recognition Technology

A proactive, independent pre-audit to help police forces demonstrate lawful, fair and proportionate use of facial recognition technology before ICO review.

Facial Recognition Technology (FRT) Pre-Audit Service for UK Police Forces

The Information Commissioner’s Office (ICO) has confirmed it will be conducting audits of UK police forces on their use of facial recognition technology (FRT). These audits will assess whether forces are handling personal information lawfully, fairly and proportionately, with a strong focus on governance, safeguards, and public confidence.

Our FRT Pre-Audit Service is designed to prepare forces for the ICO’s scrutiny. Acting as an independent governance, risk and compliance partner, we provide a structured review of your current practices and identify gaps before the regulator does.

What We Do

Our pre-audit examines the same key areas the ICO will assess, including:

  • Governance of FRT use – oversight, accountability, and decision-making processes.
  • Data Protection Impact Assessments (DPIAs) – full review of your DPIAs to ensure completeness, effectiveness, and compliance; a robust DPIA is mandatory and essential for lawful FRT deployment.
  • Retention and use of personal data – ensuring policies meet legal requirements and proportionality tests.
  • Staff training and awareness – assessing whether teams are equipped to handle sensitive biometric information.
  • Safeguards and controls – protections in place to build and maintain public trust.
  • Necessity & Proportionality Challenge – assessing whether FRT is essential, exploring less intrusive alternatives, and documenting decisions to ICO-defensible standards.
  • Data Minimisation & Format Review –confirming irreversible biometric templates are used where possible and that the retention of any raw images adheres to strict, legally justified retention schedules.

Find Out How We Can Help

Why It Matters

Our audit provides a clear picture of your current compliance status – highlighting strengths, exposing risks, and delivering actionable recommendations. But compliance with data protection and human rights obligations is not a one-off exercise. In practice, most enforcement actions have failed on two fronts: proving necessity and proportionality, and demonstrating robust handling of biometric data formats. Our pre-audit directly addresses these high-risk areas, giving forces a defensible position if challenged by the ICO or in court.

The lawful, fair and proportionate use of FRT requires ongoing oversight, continuous improvement, and regular reviews to respond to evolving legal, ethical and public expectations.

The Benefits of a Pre-Audit

  • Regulatory readiness – anticipate issues before the ICO identifies them.
  • Public confidence – demonstrate proactive commitment to safeguards and transparency.
  • Operational assurance – give leadership confidence that FRT is being used responsibly and defensibly.
  • ICO-defensible assurance – tackle the areas most often challenged by regulators, with evidence-based documentation of necessity, proportionality, and data minimisation.

Download or View The Police FRT Pre-ICO Audit Service Leaflet

From our Blog

Secure by Design: The Future of Information Assurance for UK Policing

For decades, information assurance in UK policing has relied heavily on accreditation processes and the Risk Management and Accreditation Document Set (RMADS). While these frameworks provided a degree of structure, they often fell short in agility, technical relevance, and real-world application. In response to evolving threats and the changing landscape of digital policing, Secure by […]

SIRO Training

Training for risk owners

IAO Training

Training for your IAO

Data Protection

Compliance with UK GDPR & DPA

Consultancy

Governance, Risk & Compliance Services

Visit Your Police Homepage for All Services and Training