What Does False Rejection Rate FRR Mean And Its Importance?

failing to verify ID
Last updated

Have you ever been locked out of your phone because it didn’t recognize your face? That’s the false rejection rate (FRR) at work—a metric you can’t afford to ignore, especially in decision-making and accuracy assessment. 

FRR, a commonly used metric in biometrics, is a key factor in validating identities as a whole, especially identity documents. It measures the rate at which valid identities are falsely rejected by the system. In other words, it indicates the likelihood of the system rejecting a genuine identity. 

This metric is especially important when it comes to validating identity documents, such as passports or driver’s licenses, as it ensures only individuals with valid identification are granted access to certain services or areas.

In this article, we’ll dive into what FRR means, how it differs from false acceptance rate (FAR), and why getting a grip on these metrics matters for you and your business. Let’s get started.

What is false rejection rate?

False rejection rate (FRR) measures how often a system incorrectly rejects a legitimate or authorized user. In biometric systems, false rejection may also be described as a false non-match, with the metric referred to as the False Non-Match Rate (FNMR).

In statistical classification terminology, a false rejection can also be considered a Type II error, or false negative, because the system fails to recognize a legitimate match. By comparison, a false acceptance is generally analogous to a false positive, or Type I error, because an unauthorized user is incorrectly accepted.

How is false rejection rate calculated?

False rejection rate is calculated by dividing the number of legitimate attempts that were incorrectly rejected by the total number of legitimate attempts, then multiplying by 100:

FRR = (False Rejections ÷ Total Legitimate Attempts) × 100

For example, suppose 1,000 legitimate users attempt to complete an identity verification and 30 are incorrectly rejected. The false rejection rate would be:

FRR = (30 ÷ 1,000) × 100 = 3%

Interested in Learning More?
Get in touch today to talk to a Microblink fraud & identity expert

That means the system incorrectly rejected 3% of legitimate verification attempts.

A lower FRR generally means fewer legitimate users encounter unnecessary friction. However, FRR shouldn’t be evaluated in isolation. Adjusting a verification system to accept more users can potentially increase its false acceptance rate (FAR), which measures how frequently invalid or unauthorized attempts are incorrectly accepted. The appropriate balance depends on the organization’s use case, risk tolerance, and desired customer experience.

What is the difference between the false reject rate (FRR) and false accept rate (FAR)?

FRR and FAR are critical metrics in systems designed to validate an identity, but they serve different purposes. FRR measures how often the system incorrectly rejects legitimate users. A high FRR can be a headache because it means the system is a bit too skeptical, even turning away people who should have access.

On the flip side, FAR gauges how often the system incorrectly accepts unauthorized users. A high FAR is a security red flag. It indicates that your system is a little too trusting, letting in people who shouldn’t be there.

However, FRR and FAR are not the only metrics used in evaluating identity and security systems. True acceptance rate (TAR) and true rejection rate (TRR) are also important metrics. TAR measures the rate at which valid users are correctly accepted by a system, while TRR measures the rate at which imposters are correctly rejected. These metrics provide a more complete picture of the accuracy of a system. 

But when it comes to identity verification, FAR is often one of the most important metrics to consider. 

How do the FAR and FRR impact each other?

The interplay between FAR and FRR is crucial. These rates are influenced by the threshold value set in the system. 

Imagine the threshold value as a guard at the door. Set it too low, and you’ll reduce FRR but may end up with a high FAR, letting in unauthorized individuals. Set it too high, and the opposite happens: you’ll ramp up FRR by turning away legitimate users.

In terms of where these lines intersect, that point is often referred to as the equal error rate (EER), where FRR and FAR are equal. It’s a handy metric for finding a balanced threshold value that doesn’t compromise too much on security or user experience.

What causes a high false rejection rate?

False rejections aren’t always caused by a single issue. The accuracy of an identity or biometric verification system can be affected by the quality of the information it receives, characteristics of the user, environmental conditions, and the sophistication of the technology evaluating the attempt.

Environmental and capture-quality factors

Poor input quality can make it more difficult for a verification system to accurately evaluate a legitimate user. In facial recognition and identity verification, factors such as poor lighting, glare, blur, camera quality, improper positioning, or partially obscured information can reduce the quality of the data available to the system.

Document capture presents similar challenges. A legitimate identity document photographed in poor lighting or at an extreme angle, for example, may be more difficult to analyze accurately. Improving capture quality before verification can therefore play an important role in reducing avoidable false rejections.

User-related factors

Biometric characteristics aren’t necessarily static. Aging, facial hair, makeup, injuries, changes in appearance, eyewear, and other physical differences can affect how closely a new biometric sample resembles previously captured information.

User behavior can matter as well. Positioning a face incorrectly, moving during capture, presenting a document improperly, or misunderstanding instructions can produce lower-quality inputs. Clear guidance and real-time feedback can help users provide the system with the information it needs to make an accurate decision.

Algorithm sophistication

The underlying algorithms used to extract, analyze, and compare identity information also have a significant impact on FRR. More sophisticated systems can be better equipped to distinguish between natural variations in legitimate inputs and signals that indicate fraud.

This becomes particularly important as identity verification systems evaluate multiple signals. Document authenticity, extracted data, facial biometrics, liveness, image quality, and fraud indicators can each contribute information about an identity interaction. How effectively a system analyzes those signals and determines their significance can affect both fraud detection and the likelihood that legitimate users are incorrectly rejected.

Algorithm performance should therefore be evaluated not simply by how much fraud a system catches, but by how effectively it separates fraudulent activity from legitimate variation. A system that stops more suspicious attempts but also rejects significantly more genuine users may introduce unnecessary friction and hurt conversion.

Consequences of high FRR

False rejections aren’t just a momentary annoyance. They disrupt user workflows. 

Every time a legitimate user is denied access, there’s an interruption. These interruptions—especially if frequent, can accumulate into significant downtime. 

For businesses, this means tasks get delayed, meetings get postponed, and the overall pace of work slows down. Over time, this can translate into tangible financial losses, especially in sectors where real-time access is critical.

Beyond the tangible, there’s a psychological cost to FRR. Continual denials can erode user confidence and trust in the system. Feeling locked out of one’s account or denied access to crucial data, especially when the user is legitimate, can be frustrating enough to make a user leave entirely.

How do FAR and FRR affect security levels?

Both of these metrics can significantly affect the security level of identity security systems. That’s why the Equal Error Rate is often a key reference point for optimizing a system’s overall security level. In real-world scenarios, failing to find this balance can be disastrous. 

A recent study proved that over 6 million records were exposed in data breaches worldwide during the first quarter of 2023 alone. Imagine a data center suffering a security breach because its false acceptance rate was too high, allowing bad actors to access critical systems and sensitive information. A single point of failure like that can have cascading consequences.

Let’s also think about healthcare. Medical records accessed through biometric systems can present a security risk in a hospital setting. 

An FRR that’s too low might seem like a good idea to ensure doctors get immediate access to life-saving information. But if this pushes up the FAR, there’s a risk of exposing confidential patient data, breaking privacy laws, and jeopardizing patient trust.

False rejection rate in Action

In a notable incident that challenges the infallibility of biometric security systems, HSBC’s voice recognition system faced a surprising loophole. Launched with the assertion that voice prints were as unique as fingerprints, the system was proven fallible when BBC Click reporter Dan Simmons discovered his non-identical twin, Joe, could mimic his voice well enough to bypass security. 

While Joe couldn’t initiate money withdrawals, he was granted access to account balances, transaction histories, and the ability to transfer money between accounts. Alarmingly, the system permitted Joe seven attempts to replicate his twin’s voice before granting access on the eighth. 

This event was a wake-up call, highlighting the potential pitfalls of relying solely on voice recognition, especially when the stakes involve sensitive financial data. HSBC defended the system’s overall security, stating its superior safety over traditional passwords. Still, the incident serves as a cautionary tale about the nuanced challenges of biometric security and the constant need for refinement and oversight.

Ensuring Accurate Identification 

FRR isn’t a buzzword. It is a critical metric that informs the reliability and security of your systems. Balancing FRR with FAR is essential for maintaining a secure and efficient environment. 

So, don’t let it be an afterthought. As technologies advance and security becomes more complex, keeping a vigilant eye on FRR-related developments and applications will serve you well.

If you want an efficient and accurate solution for validating identity documents, look no further than BlinkID.

With its advanced machine learning algorithms and state-of-the-art technology, it offers a smooth and secure identity verification experience with a low FRR. Get started with a free trial today.

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.