Evaluation Criteria — Mandatory / Desirable / Optional
Pulled verbatim from sources/src-02-part2-statement-of-requirements.md and sources/src-04-part3a-response-technical.md. Priority codes: M mandatory (failure = unviable), D desirable (materially improves viability), O optional.
Biometric Capture & Liveness Detection (LV)
| ID | Priority | Requirement |
|---|---|---|
| LV-1 | M | Capture biometric images of sufficient quality for biometric comparison, complying with ISO/IEC 29794-5 when generating the image quality profile of the acquired image. |
| LV-2 | M | Implement automated image-quality controls within its biometric capability and provide clear UI guidance to direct a user to capture an image that meets the required image quality profile. |
| LV-3 | M | Employ Presentation Attack Detection (PAD) to determine whether the acquired image originates from a living human subject present at the point of capture. |
| LV-4 | M | Complete image capture and PAD as part of a single continuous process before the image is submitted to the ATO system for online biometric verification, to prevent exploitation via separation of acquisition and PAD. |
| LV-5 | M | PAD technology meets at least Evaluation Assurance Level 2 (Level B) as defined by ISO/IEC 30107-3:2023 and the Digital ID (Accreditation) Data Standards. |
| LV-6 | M | Tested or validated by a qualified third-party biometric testing entity experienced in ISO/IEC 30107 to evidence the PAD meets EAL-2 (Level B). |
Technical Verification & Biometric Binding (TV)
| ID | Priority | Requirement |
|---|---|---|
| TV-1 | M | For foreign ePassport technical verification: (a) comply with relevant sections of ICAO Doc 9303 for remote PKI verification; and (b) check published CRLs or equivalents for ePassport cancellation status. |
| TV-2 | M | Online biometric binding MUST: complete binding within a single continuous workflow; include liveness detection as part of PAD; execute PAD at the point of capture; complete capture and PAD prior to submission for binding; use PAD technology incorporating data from both the capture subsystem and system-level monitoring consistent with ISO/IEC 30107-1. |
| TV-3 | M | Biometric matching algorithm achieves FMR ≤ 0.01 % and FNMR ≤ 3 % at a 90 % confidence interval, per ISO/IEC TS 19795-9:2019. |
Scalability (S), Performance (P), Availability (A)
| ID | Priority | Requirement |
|---|---|---|
| S-1 | M | Scalable to meet performance requirements under variable and increasing usage. |
| S-2 | M | Support SaaS solution. |
| P-1 | M | Support peak loads of 10 000 verifications/hour with 95th-percentile response time ≤ 1000 ms. |
| P-2 | M | Provide: (i) Licensed Software performance metrics and test regimes used; (ii) infrastructure design specifications; (iii) a Software Capacity Plan and supplier strategies for scaling. |
| A-1 | M | Achieve or exceed 99.95 % availability. |
Hosting (H), Integration (IN)
| ID | Priority | Requirement |
|---|---|---|
| H-1 | M | Cloud-hosted SaaS offering, delivered via a secure, scalable, vendor-managed environment. |
| H-2 | M | If cloud-based, describe connectivity with current AWS technologies and services, connectivity methods (e.g. AWS PrivateLink), and resources required from ATO to support connectivity. |
| IN-1 | M | Support the Microsoft MAUI development environment and provide bindings for client API access. |
| IN-2 | M | Support operation through standard web browsers (Chrome, Safari, Edge, Firefox) in addition to mobile platforms. |
| IN-3 | M | Where not hosted within an ATO Software Service, MUST not require server affinity. |
| IN-4 | M | Support silent automated deployments including IaaS, where ATO is responsible for deployment. |
| IN-5 | D | Provide two short case studies demonstrating delivery of similar services in high-volume, large-scale deployments, including references. |
Security & Confidentiality (SC)
| ID | Priority | Requirement |
|---|---|---|
| SC-1 | M | Evidence of ability to comply with PSPF, ISM, Essential 8 and other security requirements as defined in the Digital ID Act 2024. |
| SC-2 | M | Demonstrate compliance with the Australian Privacy Principles. |
| SC-3 | D | Secure all collected/held/used data (PI, ATO Data, ATO Material, inter-agency information) in use and at rest using ASD-approved cryptographic algorithms consistent with the Australian Government ISM or NIST. |
| SC-4 | D | Controls to ensure integrity of data generated within the client software or provided to the Facial Verification Service. |
| SC-5 | M | MUST NOT transfer Personal Information outside Australia. |
| SC-6 | M | Capable of meeting relevant ISM controls to allow the ATO’s Information Security Advisor to issue certification at the PROTECTED level. |
| SC-7 | M | All Personal and ATO data hosted and stored in Australia, complying with Australian data sovereignty laws and the Data Hosting Certification Framework. |
| SC-8 | D | List all products used in delivery of Licensed Software, their function, whether third-party, and any access those products have to user data. |
Operations (OP), Vendor Implementation Support & Maintenance (VISM), Maintainability (M)
| ID | Priority | Requirement |
|---|---|---|
| OP-1 | M | Secure, isolated non-production environments coupled with 24×7 monitoring. |
| OP-2 | D | Dynamic, automated test environments with integration testing. |
| OP-3 | M | Maintain data sovereignty and provide internal real-time service status visibility. |
| OP-4 | M | Continuously monitor access and privileged activities. |
| OP-5 | M | Assurance that system access is limited to approved IP ranges that are regionally localised. |
| OP-6 | D | Mechanisms to detect early indicators of stress or coercion among personnel interacting with sensitive systems. |
| OP-7 | M | Real-time alerts for high-risk or policy-violating behaviours, including biometric failures. |
| OP-8 | D | Tiered alerting based on risk severity; detect abnormal access or potential data loss incidents. |
| OP-9 | M | Australian-based NV1-cleared support, ISM-compliant timelines, governance reporting, secure incident management via an iRAP-certified portal. |
| OP-10 | M | Dedicated helpdesk, roadmap for fraud prevention, knowledge transfer; demonstrate experience with government identity systems and security certifications, plus SLA management and governance. |
| VISM-1 | M | Solution-specific support and troubleshooting via a formal helpdesk function. |
| VISM-2 | M | Documented processes, manuals and operational instructions. |
| VISM-3 | M | Ongoing support to keep software up-to-date with regular patching and updates. |
| VISM-4 | M | Ongoing platform maintenance services. |
| VISM-5 | D | Roadmaps and planned updates in fraud prevention and identity technology. |
| VISM-6 | D | Demonstrate proven experience in successful implementation of similar systems in other government agencies. |
| VISM-7 | D | Describe emerging technologies and recommendations based on vendor research. |
| M-1 | M | Keep Licensed Software up-to-date through maintenance and patches (including security patches) for the Licensed Software and any third-party components. |
Reporting & Monitoring (RM), User Experience & Accessibility (UX)
| ID | Priority | Requirement |
|---|---|---|
| RM-1 | M | Centrally log system activity (security settings, verification activities) and support shipping logs to ATO’s logging system. |
| RM-2 | M | Configurable metrics, dashboards and drill-down visualisations (e.g. capture-time statistics, failure-to-enrol/acquire rates). |
| RM-3 | M | Provide ATO with appropriate access to view logs (requests, response payloads, processing status) for troubleshooting. |
| RM-4 | M | Describe monitoring capability or integration options. |
| UX-1 | M | Support Mobile First and Responsive Web Design methodologies. |
| UX-2 | M | Provide UI standards, UI screen designs, and UX documentation including user-flow mappings. |
| UX-3 | M | Conform to WCAG 2.1 Level AA for mobile and web browser experiences. |
| UX-4 | M | Ability for the ATO to customise user experience elements. |
Cross-cutting headline business requirements (from §6 Overview)
- Secure — detect/prevent spoofing, deepfakes, identity threats; biometric match rates (FAR/FRR) per Digital ID Act 2024
- User-friendly — quick, simple, accessible for all users including those with accessibility needs
- Device compatibility — wide range of mobile devices, platforms, browsers, OSes
- Accessible — meets minimum WCAG requirements as defined in Digital ID Act 2024
- Scalable — high volumes, consistent performance, reliability, uptime
- Cost-effective — sustainable pricing aligned with Commonwealth procurement frameworks
- Compliant — Digital ID Act 2024 liveness/biometric verification standards and disclosure requirements
- Integratable & maintainable — seamless integration with existing ATO infrastructure and future architectures
- Value for money
Linked notes
- sable-fit — per-requirement SABLE answer (compliance position + commentary)
- gaps-and-risks — items we cannot claim compliance on today
- ato-myid-context — myID architecture context that frames the M/D/O priorities