What ISO 27566 Means for Age Assurance: Insights from Tony Allen on the Exploring Standards Podcast

Age assurance and online safety are becoming more prevalent as governments around the world strengthen online safety legislation. Organisations are under increasing pressure to ensure children cannot access age-restricted products, services and digital content online.

But how do businesses implement age assurance in a way that is accurate, secure and respectful of user privacy?

In a recent episode of Exploring Standards, Assent Risk Management’s podcast exploring the world of international standards, host Jess spoke with Tony Allen, Chief Executive of the Age Check Certification Scheme, to discuss the publication of ISO 27566 and why it could become the global benchmark for age assurance systems.

Why age assurance is suddenly in the spotlight

Age assurance has existed for centuries. Businesses have always needed to verify that customers are old enough to purchase products such as alcohol, tobacco or fireworks.

What’s changed is where those interactions now take place.

As Tony explained during the podcast, the rapid growth of online retail, social media, gaming and digital services means organisations can no longer rely on face-to-face checks. Instead, they must establish a user’s age remotely while balancing privacy, security and user experience.

At the same time, governments across the world are introducing online safety legislation that places increasing responsibility on organisations to prevent children accessing inappropriate content or services.

This combination of technological change and evolving regulation is driving unprecedented interest in age assurance.

Age assurance isn’t just age verification

One of the key themes Tony highlighted was the importance of using the correct terminology.

ISO 27566 defines age assurance as the overarching term that includes three different approaches:

Age verification

This confirms a person’s age by validating their date of birth against trusted evidence such as a passport, driving licence or other official record.

Age estimation

Rather than identifying an exact age, age estimation uses characteristics that change over time, such as facial features or voice, to estimate whether someone is above or below a particular age threshold.

Age inference

Age inference determines whether someone is likely to belong to a particular age group based on other trusted information.

For example, holding a mortgage, possessing a firearms licence or being enrolled in a particular school year may allow reasonable conclusions to be drawn about someone’s age without identifying their exact date of birth.

Together, these three methods form the broader concept of age assurance.

What is ISO 27566?

During the discussion, Tony described ISO 27566 as a framework rather than a technology standard.

Instead of prescribing one specific solution, it establishes a common international approach for designing, implementing and evaluating age assurance systems.

The standard is currently being developed in three parts:

  • Part 1 introduces the overall framework, common terminology and the core characteristics of effective age assurance systems.
  • Part 2 will provide implementation guidance for organisations introducing age assurance.
  • Part 3 will focus on comparing, evaluating and certifying age assurance systems.

Interestingly, Tony noted that Part 1 has been made freely available, something relatively unusual for an ISO standard, reflecting its growing international importance.

The five characteristics every age assurance system should demonstrate

Rather than asking whether a system simply works, ISO 27566 encourages organisations to evaluate age assurance across five key areas.

Functionality

Does the system perform the task it claims to perform?

Performance

How accurate and reliable are the age assurance results?

Privacy

How is personal information collected, protected and minimised?

Security

Can the system resist fraud, attacks and attempts to bypass age checks?

Acceptability

Is the solution transparent, inclusive and accessible for users?

As Tony explained, these principles help ensure organisations consider trust and user confidence alongside technical performance.

Why implementation is more complicated than it first appears

One of the strongest messages from the podcast was that successful age assurance starts long before selecting technology.

Every organisation has different risks, different users and different regulatory obligations.

For some businesses, verifying a customer’s age may be sufficient. Others may require estimation or inference depending on the service being provided and the privacy considerations involved.

Tony emphasised that organisations should first understand the context of use before deciding how age assurance should be implemented.

This risk-based approach sits at the heart of ISO 27566.

Why independent certification matters

The conversation also explored the role of independent certification.

Tony explained that his Age Check Certification Scheme has been developed to assess age assurance solutions against ISO 27566, providing objective evidence that systems perform as claimed.

Rather than relying on vendor declarations alone, certification gives organisations confidence that solutions have been independently evaluated for performance, privacy, security and resilience.

This can be particularly valuable for organisations selecting technology providers or demonstrating due diligence to regulators.

Could ISO 27566 become the benchmark for age assurance?

Looking ahead, Tony believes ISO 27566 will become increasingly embedded within procurement processes, regulatory expectations and supplier assurance programmes.

He compared its likely evolution to other well-established product standards that have become routine requirements across global supply chains.

While the standard is still relatively new, adoption is already growing, with certification activity increasing as organisations prepare for changing regulatory expectations.

Key takeaways from the episode

Tony’s discussion highlights several important lessons for organisations:

  • Age assurance is broader than traditional age verification.
  • Privacy and security are fundamental components of effective age assurance.
  • ISO 27566 provides a common international framework rather than prescribing a specific technology.
  • Organisations should adopt a risk-based approach based on how users interact with their services.
  • Independent certification can help demonstrate trust, transparency and compliance.

Listen to the full conversation

This article summarises just some of the insights shared by Tony Allen during his appearance on the Exploring Standards podcast.

If your organisation is preparing for online safety legislation, implementing age assurance or simply wants to understand what ISO 27566 means in practice, we recommend listening to the full episode for a deeper discussion of the challenges, opportunities and future direction of the standard.

Watch the Full Episode

Jessica Inglis
Jessica Inglis
Articles: 79