What is ABIS?

What Is ABIS? Automated Biometric Identification Systems Explained

ABIS stands for Automated Biometric Identification System. In biometrics it means one specific thing: a system that enrols biometric records, stores them, and searches a submitted biometric against the whole database to find out who someone is.

The acronym is used for other things in other industries, including retail point of sale software and a book classification scheme. This page is about the biometric system, which is the meaning used by NIST and by government identity programmes worldwide.

Inside an abis six components

The definition that matters

NIST uses the term in its own glossary to describe IDENT, the Department of Homeland Security system that holds biometric records for immigration, border and law enforcement purposes. That gives you the working definition: a large scale repository plus a matching engine, built to answer identification questions rather than authentication questions.

An ABIS differs from an AFIS in scope. An AFIS handles fingerprints. An ABIS handles several biometric characteristics, typically face and fingerprint and often iris, and can combine them in a single decision.

Detect Deepfakes before they become a Threat

Deepfakes are becoming more sophisticated, increasing the risk of fraud and identity manipulation in digital environments. Download our 10-step guide to learn how to detect threats early and protect your organization with proven best practices.

What is inside an ABIS

Enrolment processing. The system accepts biometric samples, checks their quality, extracts features and creates templates in standardised formats. ISO/IEC 19794 and the newer ISO/IEC 39794 series define how those templates are structured so that different systems can exchange them.

Encrypted template storage. Templates are stored, not raw images, and in a well designed system they are encrypted at rest and in transit. A template is a mathematical representation of biometric features. ISO/IEC 2382-37 is explicit that a stored image is not a template.

Embedding-based search. A brute force comparison against millions of records would once have been too slow for operational use. Modern systems avoid that trade-off altogether: each template is encoded as an embedding, and similarity search against the entire gallery runs fast enough that no indexing or filtering shortcuts are needed to reach every candidate.

Matching engine. This is the core. It performs both 1:1 comparisons, where a submitted biometric is compared to one specific record, and 1:N searches, where it is compared against the entire gallery.

Deduplication engine. At enrolment, the system checks whether the subject already exists under another identity, using configurable matching thresholds.

Operational services. Dashboards, transaction logs, performance monitoring and audit trails. In regulated deployments this layer carries as much weight as the matcher, because it is what makes a decision defensible afterwards.

 

1:1 vs 1:N Not interchangeable

1:1 and 1:N are both inside an ABIS, and they are not interchangeable

A 1:1 comparison answers “is this the person this record belongs to”. A 1:N search answers “who is this, if anyone”.

The second is a much harder problem, and it gets harder as the database grows. Each comparison in the gallery carries a small chance of a false match, so the more records you search against, the more opportunities there are for a wrong candidate to surface. This is why 1:N systems are evaluated separately from 1:1 systems. NIST runs FRTE 1:N for face and FRIF TE E1N for fingerprint identification and NIST IREX for Iris identification, both distinct from the one-to-one tracks such as FRTE 1:1 or NIST MINEX III.

Any vendor accuracy figure that does not state which operation was measured, at what gallery size, is not usable for comparison.

Deployment models

Centralised. All matching happens in one place. This is the classic model and it suits national registries and watchlists.

On-premise or hybrid. The matching engine runs inside the customer’s own infrastructure or a mix of private and cloud. Common in government and regulated finance where data residency is a requirement.

Edge capture with central matching. Capture and validation happen on the device, and only what is needed travels to the central matcher. This reduces latency, lowers bandwidth dependence and keeps enrolment working in low connectivity conditions.

Identy.io is built around the third model. Biometric capture is processed on the device itself, and the ABIS handles centralised 1:N identification and deduplication across the enrolled population. The system is designed for horizontal scaling and supports on-premise and hybrid deployment.

Standards and independent evaluation

Three families of reference points are worth knowing when assessing any ABIS.

Interchange formats. ISO/IEC 19794 and ISO/IEC 39794 for template formats, and ANSI/NIST-ITL for biometric data exchange between agencies. These determine whether you can migrate or interoperate later.

Presentation attack detection. ISO/IEC 30107-3 defines how PAD is tested and reported, including the metrics used. Identy.io’s facial biometric technology holds iBeta certification for ISO/IEC 30107-3 Level 1 and Level 2 with a 0 percent Imposter Attack Presentation Match Rate under the conditions of that test.

Algorithm performance. NIST runs continuous, public, free-to-enter evaluations. MINEX III for interoperable fingerprint templates, PFT III for proprietary 1:1 fingerprint matching, FRTE for face, FRIFTE E1N for fingerprint identification. Results are published per participant and per submission.

Ask for the participant identifier and the submission date, not a screenshot. Evaluations are ongoing and a result from three years ago describes a different algorithm.

Where ABIS systems are used

National ID issuance and civil registries, where deduplication protects the integrity of the population register. Border control and traveller processing. Law enforcement, including civil and criminal applications with full lifecycle management. Financial onboarding and KYC in markets where regulation requires identification rather than simple verification. Voter registration. Telecom SIM registration.

Identy.io’s ABIS has completed MOSIP’s partner compliance process and is listed on the MOSIP Marketplace, which governments deploying foundational digital identity on that platform can evaluate directly.

What to look for when choosing one

Accuracy claims tied to a named evaluation, a participant identifier and a gallery size. Interchange format support, so you are not locked in. A described deduplication workflow including backfill on historical records. Capture layer defences, not just matcher accuracy. Deployment flexibility that matches your data residency requirements. An operational and audit layer you could defend to a regulator.

Continue reading: the practical comparison in AFIS vs ABIS, the operational distinction in 1:1 verification vs 1:N identification, or our buyer’s guide to ABIS software.

Frequently asked questions

What does ABIS stand for?

ABIS stands for Automated Biometric Identification System. It is a large scale system that enrols biometric records, stores them as encrypted templates, and searches a submitted biometric against the full database to establish identity. NIST uses the term to describe the Department of Homeland Security IDENT system.

What are the main components of an ABIS?

An ABIS typically includes enrolment processing with quality checks and template extraction, encrypted template storage, searchable index generation, a matching engine that performs both 1:1 comparison and 1:N search, a deduplication engine with configurable matching thresholds, and operational services covering dashboards, transaction logs and audit trails.

What is the difference between ABIS and AFIS?

An AFIS handles fingerprints only. An ABIS handles multiple biometric modalities, typically face and fingerprint and often iris, and can fuse evidence across them in a single decision. An ABIS also deduplicates across the whole population rather than a single modality.

How is ABIS accuracy measured?

Through independent evaluation programmes rather than vendor testing. NIST runs continuous public evaluations including MINEX III for interoperable fingerprint templates, PFT III for proprietary one-to-one fingerprint matching, FRTE for face recognition and FRIFTE E1N for fingerprint identification. Any accuracy figure should state which evaluation, which participant submission and what gallery size it refers to.

Can an ABIS run on-premise?

Yes. Deployment models include fully centralised, on-premise or hybrid, and edge capture with central matching. On-premise and hybrid are common in government and regulated finance where data residency requirements apply. Identy.io supports on-premise and hybrid deployment with horizontal scaling, and processes biometric capture on the device.

 References

  • NIST. Glossary: Automated Biometric Identification System (IDENT). https://www.nist.gov/glossary-term/18926
  • Department of Homeland Security. DHS/OBIM/PIA-001 Automated Biometric Identification System. https://www.dhs.gov/publication/dhsnppdpia-002-automated-biometric-identification-system
  • NIST. Face Recognition Technology Evaluation (FRTE) 1:N Identification. https://pages.nist.gov/frvt/html/frvt1N.html
  • NIST. FRIFTE E1N — Fingerprint 1:N Identification Results. https://fingerprint.nist.gov/frifte/e1n/results/
  • NIST. Proprietary Fingerprint Template (PFT) III. https://www.nist.gov/itl/iad/image-group/proprietary-fingerprint-template-pft-iii
  • NIST. Minutiae Interoperability Exchange (MINEX) Overview. https://www.nist.gov/programs-projects/minutiae-interoperability-exchange-minex-overview
  • ISO/IEC 2382-37:2022. Information technology — Vocabulary — Part 37: Biometrics. https://www.iso.org/standard/73514.html
  • ISO/IEC 30107-3:2023. Biometric presentation attack detection — Part 3: Testing and reporting. https://www.iso.org/standard/79520.html
  • ISO/IEC 39794 series. Extensible biometric data interchange formats.
  • MOSIP Marketplace. Identy.io ABIS product listing. https://marketplace.mosip.io/products/305
Matus Kapusta
Product Director for the ABIS portfolio at Identy.io and a specialist in large-scale biometric identification systems. He spent more than 16 years at Innovatrics. There he grew a six-person team into a full portfolio covering ABIS, criminal case management, document issuance and enrollment stations. At Identy.io he combines mobile-first biometric capture with enterprise ABIS matching, so governments and banks in Africa, Latin America and Asia can build identity registries without proprietary hardware. He also led the MOSIP partner certification of Identy's ABIS. His focus is practical: population-scale deduplication, Frankenstein identities, operator fraud and identity inclusion in emerging markets.

Related Posts

COPYRIGHT © 2026 IDENTY.IO

Download our guide: Detect deepfakes before they become a threat
Descargue nuestra guía: Detecte deepfakes antes de que se conviertan en una amenaza
Baixe nosso guia: detecte deepfakes antes que se tornem uma ameaça