Access control answers three questions: who may enter, where, and when. The credential is how the system recognises a person, and each type makes a different trade between convenience, cost and certainty.
RFID cards and fobs
Still the workhorse of commercial access control. Cheap per user, quick to issue and revoke, and familiar to everyone.
The important caveat is technology generation. Legacy 125 kHz proximity cards can be cloned with inexpensive equipment and should not be relied on for anything sensitive. Modern 13.56 MHz smart cards with encrypted, mutually authenticated communication (MIFARE DESFire EV2/EV3 and similar) are a different proposition. If you are specifying a new system, specify the encrypted generation — the cost difference is small and the security difference is not.
The residual weakness is that a card proves possession, not identity. Cards get lent and lost.
PIN codes
No credential to issue or lose, and near-zero marginal cost. But codes get shared, observed and written down, and they are rarely changed. A PIN alone suits low-risk internal doors; it is not appropriate on its own for a controlled area.
PINs are far more useful as a second factor — card plus PIN — where you want to raise assurance on a specific door without deploying biometrics everywhere.
Biometrics
Biometrics bind access to the person rather than to a token.
- Fingerprint — mature and cost-effective. Reliability drops with wet, dusty, worn or gloved hands, which matters on industrial and construction sites.
- Face recognition — contactless and fast, and now the common choice for main entrances and time-and-attendance. Performance depends heavily on lighting and camera placement; specify units with proper anti-spoofing (liveness detection).
- Iris and palm vein — very high accuracy for a small number of critical doors, at a higher price point.
Two practical cautions. First, biometric templates are personal data: confirm they are stored as irreversible templates rather than raw images, kept encrypted, and covered by a retention policy — a lost card can be reissued, a compromised biometric cannot. Second, always design a fallback for enrolment failures and for people who cannot use the reader.
Mobile and QR access
Credentials on a phone over Bluetooth or NFC remove card stock entirely and make issuing and revoking instant — useful across multiple sites. QR codes suit time-limited visitor access. The dependency is the phone: battery, OS updates and lost devices become access issues, so keep a physical fallback.
Choosing per door, not per building
The usual mistake is picking one credential for the whole site. Risk is not uniform, so the design should not be either. A pattern that works well:
- Main entrance / turnstiles — card or face, optimised for throughput at shift change.
- General office areas — encrypted card.
- Server room, cash office, pharmacy, evidence store — two factors, typically card plus biometric or PIN.
- Perimeter gates and vehicles — long-range readers or ANPR.
What actually determines success
Beyond credentials, these decide whether the system works in practice:
- Fire integration. Doors on escape routes must release on fire alarm. This is a life-safety requirement and is coordinated with the fire system, not bolted on afterwards.
- Fail-safe or fail-secure. Decide deliberately, per door, what happens on power loss.
- Anti-passback and interlocks where you must prevent tailgating or control airlocks.
- Audit trail and reporting — including a roll-call report, which is what makes the system valuable during an evacuation.
- Leaver process. Most real-world failures are administrative: credentials that were never revoked.
TSB Smart Tech designs and installs access control across Iraq and the Kurdistan Region, integrated with CCTV, intrusion and fire systems. Contact us for a door-by-door assessment.

