Facial recognition has been largely misunderstood in retail due to missteps in other sectors. There’s a clear separation between facial recognition technology (FRT) that creates risk and facial recognition technology that reduces it almost entirely, with the safeguards, workflows, and governance built around it from the start.
Used responsibly with purpose limits, controlled use of data, and human oversight at every key decision point, facial recognition gives frontline retail teams something traditional security cannot: the ability to detect a known high-risk persons of interest before an incident unfolds, not after.
This article covers:
- What facial recognition actually does
- How facial recognition tech is commonly used for retail crime prevention
- How AI powers the matching process and where human verification can help with misidentification risk
- How facial recognition fits into a retail loss prevention context alongside methods like license plate recognition
- What retail legal and privacy team will typically want to see before any deployment moves forward
What facial recognition actually does (and doesn't do)
Facial recognition is a biometric technology that analyzes unique facial features to determine whether a detected face matches a known offender on a watchlist. Much like a fingerprint, a face can be analyzed as a unique identifier based on facial geometry. A camera detects a face, and the system converts it into a numerical dataset, formally called a biometric template, which is then compared against the biometric templates of the individuals on a watchlist.
Facial recognition technology is commonly used to unlock personal devices, check passports, and prevent crime. When used for crime prevention, the system matches known high-risk persons of interest against a defined watchlist of individuals with a verified history of serious offending or violence. Cameras capture faces as people enter a store, convert them to a biometric template, and compare in real time against the watchlist, triggering an alert to the retail team if there's a match.
In a responsible retail deployment of a facial recognition solution like Auror Subject Recognition, a trained authorized person reviews the suggested match alongside relevant context, confirms or rejects it, and every action is logged. If there is no match, the temporary biometric data is discarded immediately and never written to disk or stored.

That distinction matters, because it’s where responsible deployments differ sharply from the scenarios that have generated legitimate privacy concern. In contrast to the facial recognition tech raising concerns for retailers, Auror Subject Recognition is responsible by design: purpose-limited to retail crime prevention, with data minimization and human verification built into every step, not added as an afterthought. Responsible recognition does not retain biometric data long-term of every human face that walks through the door. It is built only for safety purposes and and first checks whether a detected face matches a known person of interest, discards the data if it does not, and requires a human to verify it if it does.
“You’ve got all of those great efficiencies, but you’ve also got the added safeguarding and reassurance.” - Hannah Cleary, Senior Manager Crime & Security
What responsible retail facial recognition is not:
- Mass surveillance of shoppers
- Behavioral profiling or marketing
- Emotion detection or demographic bias analysis
- Automated decisioning without human oversight
The concern about facial recognition is centered on misuse of data and absence of governance, not the underlying technology when it’s deployed with the right controls.
How facial recognition is used today, and why retail is different
Facial recognition is already part of daily life for most people, even if they do not think of it that way. Unlocking a smartphone with Face ID, going through airport security, verifying identity for a bank account, or accessing office buildings with a face scan are all facial recognition applications. These use cases are accepted because the check is deliberate, the purpose is clear, and the data handling is understood.
Retail is a different context, and the design has to reflect that. In the above scenarios, the system is verifying one known person against one stored face vector (biometric template), so it’s a one-to-one confirmation. In retail, the challenge is detecting whether a known person of interest has entered a busy, unpredictable environment, often before any incident has occurred, in time for store teams to respond safely.
That is a one-to-many identification problem, and it requires stricter governance precisely because it operates passively, without the individual initiating the check. Responsible retail applications of facial recognition address this through:
1. Purpose limitation: only matching against known high-risk persons of interest
2. Data minimization: discarding all non-match data immediately
3. Human verification: a person confirms every alert before any action is taken
How AI powers modern facial recognition systems, and where humans come in
Artificial intelligence helps make modern facial recognition accurate enough to be useful in the real world. Earlier face recognition systems relied on manually defined rules for comparing facial features. Modern systems use deep learning algorithms trained on large datasets to extract a mathematical representation of a user's face and compare it against reference images with far greater precision.

When a face is detected, a deep learning model analyzes it to generate what’s called a face vector, a unique numerical representation of facial geometry that serves as a biometric template. The algorithm used to produce this vector is specific to each vendor, which is one reason performance varies significantly between providers.
That template is compared against reference images, and the system generates a confidence score reflecting how closely the two match. Lighting, camera angle, partial occlusion from hats or masks, and camera quality all affect accuracy. Modern models are trained on these variables specifically because retail environments are not controlled environments.
Once the match meets the required confidence score, that’s where the human steps in. In a responsible retail deployment, a trained team member reviews the suggested match alongside prior incident history, known behaviors, and risk indicators. If the match is rejected, the outcome is logged and the biometric data is discarded. If it is confirmed, then the team follows what’s laid out in the store’s playbook.
How is facial recognition used in retail stores?
In a well-designed retail deployment, facial recognition works on one thing: it detects known high-risk persons of interest earlier, before an incident has the opportunity to escalate.
Most retail loss prevention teams are already familiar with the logic from License Plate Recognition (LPR). When a vehicle linked to a prior incident enters a store car park, the team receives an alert with information related to prior incidents, associated individuals, and risk indicators. That early awareness lets store teams follow their standard operation procedures such as adjust coverage, contact security, or involve law enforcement agencies where appropriate.
Facial recognition provides a second layer of defense that can be used in tandem with LPR or on its own. A known high-risk person of interest who would not have triggered a vehicle alert can now be detected on entry, with a human-verified workflow.
In practice, a facial recognition alert delivers more than a face match. In a platform-integrated deployment, it surfaces the full intelligence picture, which makes a coordinated, proportionate response possible. A face match connected to a history of threatening behavior across six stores is intelligence.
Preventing repeat theft and organized retail crime
A small cohort of repeat offenders, and the organized retail crime (ORC) groups behind them, drives a disproportionate share of loss across stores, regions, and jurisdictions. One challenge is that these offenders move freely between locations. They hit one store, then another, then another, and without a connected intelligence picture, each incident looks isolated.
Facial recognition changes the math on repeat offending. When a known person of interest (POI) walks into a store, the alert gives a store team context. In Auror Subject Recognition, POI enrollment is limited to high-risk repeat offenders that meet the prescribed thresholds, which means the system is focused exclusively on the cohort driving the most harm in stores.
Previously, they had no way of knowing which POIs had been apprehended three times across two other retailers or had a known history of violence, but now they have the information before anything happens.

For organized retail crime specifically, that early awareness matters. ORC offenders often rely on the assumption that retailers cannot see them coming. When the team has connected intelligence and an agreed standard operating procedure for how to respond, the store team can observe, request support, or contact police departments as appropriate, without confrontation and without waiting for a loss to appear on CCTV after the fact.
Protecting store teams from threatening behavior
Frontline retail teams face threatening behavior, including aggressive incidents, weapons, physical abuse, and the stress of not knowing what’s to come. Repeat retail offenders are up to 5X more likely to be physically abusive and 6X more likely to involve weapons. For store teams, earlier awareness can help them feel safe at work. For instance, 9 out of 10 security colleagues at Morrisons reported feeling safer as a result of Auror Retail Crime Intelligence.
When a person with a documented history of threatening behavior enters a store, a context-rich alert gives managers time to respond and properly follow protocols the store has in place before any interaction occurs. That might mean adjusting floor coverage, discreetly alerting security, briefing specific team members, or preparing to de-escalate if approached. Because every retailer's operating model is different, the value goes beyond a single prescribed response, providing priceless additional time and context to act on the protocol that's right for that store.
In a six-month pilot for a multi-brand homeware and apparel retailer, Subject Recognition supported a 25% reduction in threatening behavior over six months, alongside a 42% average loss reduction — 2X greater than stores without Subject Recognition. When prolific, known high-risk persons of interest are detected earlier and responded to appropriately, fewer incidents escalate to the point where someone gets hurt.

Store team members who feel safer also show up differently. Turnover drops, reporting rates improve, and the intelligence that feeds the network becomes more valuable.
How facial recognition and license plate recognition work together
License plate recognition and facial recognition solve overlapping problems and cover the gaps the other can’t fill. For instance, a vehicle of interest detected in a parking lot triggers an early alert. If the same person then enters the store and triggers a Subject Recognition alert, the team now has two data points confirming the same risk, more certainty, and more time to act before an incident unfolds.
Hannah Cleary, Senior Manager of Crime and Security at Morrisons, put it plainly:
"I'd say about 30% of our investigations are initiated or dramatically expanded by virtue of an ANPR [Automatic Number Plate Recognition] alert."
Running Vehicle Recognition and Subject Recognition in one platform means the watchlists stay connected. A person of interest profile in Auror already has associated vehicles, and a vehicle of interest profile already has associated persons. When a detection occurs, the alert surfaces both, giving teams the full picture.
What responsible recognition looks like in practice
Auror Subject Recognition is Auror's facial recognition capability built for retail. It’s integrated directly into the Auror platform rather than added as a separate system. It detects known high-risk persons of interest earlier, before an incident escalates, using workflows designed to keep store teams safer without compromising privacy or reputation.
Here’s why retail teams rely on Subject Recognition:
Built for retail. Subject Recognition alerts help LP teams see the full Auror intelligence picture. Store teams and guards receive the information they need, such as prior incidents, known behaviors, associated persons, violence indicators, and target patterns, to make an informed decision.
Responsible by design. Subject Recognition is purpose-limited to detect known high-risk persons of interest for crime prevention. No biometric data is retained for regular shoppers, and non-match biometric templates are discarded immediately and never stored. Enrollment is based on high-risk criteria set by the retailer and requires human approval. Every alert prompts human verification before any action is considered, and every decision is logged in a full audit trail that legal and privacy teams can inspect.
One platform, less complexity. Because Subject Recognition is embedded within the Auror platform, persons-of-interest candidates are surfaced automatically from the intelligence retailers are already capturing. There is no separate facial recognition system to manage, no duplicate watchlist to maintain, and no manual bridging between tools.
If you’re evaluating deployment for retail, consider these five facial recognition realities:
- The capability you choose determines the level of reputational risk
- Not all facial recognition is built for retail
- The external risk is not a false positive, but misidentification
- How biometric data is handled depends on the vendor’s privacy policies
- Managing risk and public perception depends on the program design

Get those five things right, and facial recognition becomes a layer in a coordinated approach to keeping stores safer and protecting the people in them.
Learn how Auror Subject Recognition works for retailers worldwide.










