
Data-Driven Border Management
As air passenger numbers continue to rise, traveller expectations are increasing, and risks are evolving faster. How are border agencies expected to deliver better outcomes with fewer resources? Across the world, the answer is increasingly framed around technology and data, but translating that expectation into practical, operational change is considerably more complex than might be appreciated.
For many years, governments have made great strides in strengthening their border security by improving processes, deploying new technologies, and adopting an intelligence-led approach to border management.
Passenger numbers continue to grow rapidly, and an increasingly volatile geopolitical environment is putting more demands on countries’ borders.
Significant pressure is evident in passport control queues at airports in many countries. Improved efficiency in airport terminal operations and, in some cases, larger aircraft carrying more passengers mean that an increasing number of travellers must be processed within a finite space. I have recently disembarked a few flights with a spring in my step, only for my progress towards baggage reclaim to come to a shuddering halt as I join the back of a line a considerable distance from the ever-friendly face of a border guard.
While many relatively new, excellent airport terminals have been designed for this growth, a significant number of facilities are older and, to put it bluntly, past their prime. They were designed in a bygone era, when risks and attitudes to border security were different, and traveller numbers were a fraction of today’s. There’s often no budget or room for more eGates or border guard posts, and no space to accommodate more travellers in immigration halls. In any case, accepting that longer queues will result from increased traveller numbers will certainly be met with dismay by both travellers and airlines. As ever in government operations, we must work with the tools we have. Building new terminals is not always practical and can be eye-wateringly expensive, often taking several years to move from concept to the ribbon-cutting ceremony.
This physical manifestation of the paradox of achieving more with less, or at the very best, achieving more with the same, highlights the need to adopt a data-driven mindset, maximising efficiency with the information and tools available. I’ve been joined over the years by many colleagues in discussing the merits of using data such as Advance Passenger Information (API) and Passenger Name Record (PNR) as supplementary tools for those involved in protecting borders worldwide. We need to ensure we’re extracting the most value from this data, turning it into actionable intelligence, and that we’re using it in the most suitable and efficient way while respecting privacy and human rights.
We cannot rely on this data alone; we need to be aware of its advantages and limitations, all while maintaining, or ideally improving, border security. This compromise, as always, must be struck while maintaining the ever-present need to balance security and facilitation, a principle that has been at the heart of effective border security since time immemorial.
Security and facilitation are often presented as opposites. One tightens the screw while the other oils the wheels. The safest border is a completely closed border; the one that allows the most travellers to pass is completely open. Get the balance wrong, and the consequences are immediately obvious.
The ideal solution is not to choose between security and facilitation, but to design working practices that support each other by making the best use of the right data.
Focusing attention on what matters most allows low-risk travellers and goods to move quickly, while border officials spend their time where it genuinely adds value. Done well, facilitation becomes a security multiplier, not a concession. Every minute saved on routine processing is a minute that can be redirected towards higher-risk cases.
Of course, data and the smart use of technology alone are not enough. Processes and inter-agency cooperation matter just as much.
How government agencies are structured, and whether they are actually set up to share data with one another are key factors in improving border security. There are, sadly, many examples, hopefully now rectified, about the consequences of agencies not sharing information. Several prominent terrorist attacks may well have been prevented if agencies were organised differently or if they’d been able to share data prior to these events taking place. The most notable example of this was the reorganisation of structures and working practices in the aftermath of the terrorist attacks in the United States in September 2001.
In some countries, border control, immigration, customs, law enforcement and security agencies sit in separate organisational silos, each with its own mandate, systems and legal frameworks. In the past, this division made sense: organisations were created organically when their services were deemed necessary, based on the risks and threats present at the time. However, as time progressed and the risk and threat environment changed, valuable information often stopped at departmental boundaries. Data was collected, analysed and acted upon in isolation, rather than combined to form a coherent risk picture.
If government agencies continue to follow these outdated working practices, there is a risk of duplication of effort at best and blind spots at worst. One agency may hold intelligence that would materially change another’s operational decision, but without timely access, this vital information arrives too late or not at all. Decisions may be made based on partial information, while travellers are subjected to repeated checks that add friction without adding security.
Organisational barriers also slow down responses to emerging threats. When data sharing relies on manual processes, formal requests or personal relationships, agility disappears. Threats and risks are rarely constrained by organisational charts and can quickly exploit gaps that governments may not be aware of.
The solution lies in releasing this trapped information. examining and changing organisational structures to encourage collaboration rather than protecting an agency’s domain.
As mentioned earlier, many governments have been using API and PNR for several years in a valiant effort to make the best use of the data available to them to make proactive decisions about travellers arriving at their borders.
The clearest benefit for travellers is fewer delays and a smoother journey, as only basic checks should be required to pass the border. For authorities, it means better visibility into who is arriving, departing, and transiting, often well before an aircraft arrives. This proactivity can drive efficiency, allowing agencies to focus on identified risks and threats.
API provides a reliable snapshot of who is on board a flight, captured directly from travel documents at check-in. It supports basic identity checks, document validation and watchlist matching, identifying travellers who may be wanted by the authorities. This helps border agencies identify known risks early and with a high degree of accuracy.
PNR offers richer contextual information: how a journey was booked, payment methods, travel companions and routing patterns. PNR is often used to spot patterns in arriving passengers’ journeys that match those exhibited by travellers who have committed offences and been apprehended at the border. Someone arriving on a ticket bought just before departure, paid in cash, a return journey booked very shortly after arrival, with several heavy bags, for example, may well be worthy of a little extra attention on arrival, as a traveller with similar details in their PNR was caught smuggling drugs. It is not an indication that the arriving traveller is definitely a smuggler, but their journey profile matches that of someone who was. Such analysis, known as risk profiling, helps agencies identify travellers whose PNR journey data indicates they may pose a risk.
When used correctly, watchlist matching and risk profiling improve both security and facilitation, reducing unnecessary checks and making better use of limited operational resources.
Obtaining reliable API and PNR data from airlines is not without challenges, but most airlines’ systems and business operations deliver high-quality data, on time and in the correct format, enabling governments to make effective use of it. General aviation, that is, business jets and private aircraft, presents a different challenge.
Unlike airlines, general aviation operators lack dedicated IT systems or check-in procedures. Passenger and crew details may be gathered just before the flight, amended frequently, or recorded in formats that are not easily compatible with government systems. For border authorities, this makes API collection difficult. PNR is not provided by general aviation. PNR is created when travellers make a reservation and is stored in airlines’ reservation systems. As no reservation is made and no reservation system exists for general aviation operations, there is no PNR.
Business jets and private aircraft operate in a far more fragmented and flexible environment than commercial airlines. Standardised processes are uncommon in general aviation. Business jets often operate at short notice, with the passengers sometimes not confirmed until the aircraft door closes. Private aircraft operated by leisure pilots fly where and when the owner’s mood takes them; a friend of mine based in the UK often tells me, “I just popped to France for lunch today.”
There is a question of awareness and compliance. Many pilots and operators are small businesses or individuals with limited knowledge of regulatory requirements, especially when crossing international borders, even though they are legally responsible for providing the required information in advance of their arrival. Requirements can vary significantly from one country to another, increasing the risk of confusion, incomplete data or unintentional non-compliance.
From an operational perspective, enforcing API requirements in general aviation is challenging. With a high number of flights, how can we ensure every passenger is as declared? At some locations, it would be possible for a flight to carry more passengers than the API indicates, and for a person with malicious intent to abscond immediately after arrival.
One government I worked with had a high number of business jets that arrived in their country solely to refuel en route to their destination. A real concern was the possibility that these flights could be used for smuggling money, weapons, drugs, or other contraband into their country. It’s easy to imagine an aircraft touching down and a bag being passed to a member of their criminal enterprise working at the refuelling facility.
This topic arose at a seminar I attended last week, and an interesting discussion followed on how we might use the API submitted by these general aviation operators to identify potentially risky arrivals. One of the main challenges of API in general aviation is that data is self-submitted; that is, the aircraft operator submits the data themselves. We should be aware that some data may be inaccurate due to genuine mistakes, but there is a darker possibility: individuals on board who wish to avoid detection may not have submitted their information. If many aircraft stop for less than half an hour to refuel, with passengers who do not cross the border, how feasible is it for every flight to be checked by the authorities?
We also discussed that the potentially unreliable API does not provide sufficient information to assess the arriving passengers, and with no PNR available, risk profiling is not possible. How can we use data to drive decisions made in this case?
The conclusion was that we need to use the data available to us and think more creatively about these situations. In these circumstances, the aircraft itself may provide more information about the risk posed. The tail number, that is, the aircraft’s registration number, will be provided in both the flight plan and the API submitted in advance of its arrival. A little more research will be required, but it is certainly quicker and more efficient than meeting and inspecting every aircraft that arrives for refuelling.
If the data about the aircraft is analysed, it will be possible to see if it has arrived in the country before, which routes it usually flies, who the owner is, whether it has been parked out of storage for a while, if it has been involved in criminal activity before, and if the aircraft type, age, and other characteristics are in line with what is expected for the journey being undertaken. An aircraft older than might be expected, recently reactivated after storage, and capable of making the journey without refuelling, for example, might raise suspicion. Do these characteristics mean the aircraft is certainly involved in illicit activity? Not at all, but limited resources would be better used checking out this aircraft on arrival rather than one that does not stand out in this way.
The example above also highlights an important point that is often overlooked. We should not rely on data alone. A degree of unpredictability at the border further enhances security. An aircraft that raises no suspicion should also be subject to random inspections, just as a traveller arriving in front of a border guard at an airport should sometimes be asked more questions than usual about the purpose of their journey, or have their baggage inspected. This unpredictability increases the likelihood of detecting illegal activities at the border, helps identify emerging threat patterns, and keeps those involved in these activities on the back foot.
Ultimately, although data-driven border management has the potential to significantly increase efficiency and security at the border, it is only one tool in governments’ toolkits. Border security must be viewed holistically, encompassing organisational structure, operational efficiency, and inter-agency cooperation. Without aligning data, people and processes around a shared purpose, even the most advanced systems will fall short of delivering secure, efficient and resilient borders.
By Andrew Priestley, Border Management, Business Consultant and Experienced Trainer.
Andrew is a respected and trusted consultant and senior manager, widely experienced in border management, operations, business development, and sales and account management.
