Security patrols
Key control: who holds the keys, and how to show it
Key control is the system a building owner, employer or property manager uses to decide who is authorized to hold each key, fob and access code, to record every key issued and returned, and to check regularly that every key is where the record says it is.
No single Canadian law sets out a key control policy, but provincial health and safety law, the fire code, tenancy and condominium law and the federal government's own physical security guidance all depend on knowing who can open which door. This guide covers what a key control system includes, how to write the policy, what the key control log should record, the end-of-shift key check, and how to run a key audit.
01
What key control is, and the law behind it
In physical security, key control refers to managing the keys and other credentials that open a building, to protect the people and assets inside: deciding who may have them, issuing and recovering them, tracking the spares and master keys, and checking that the record matches what is on the key board and in people's pockets. (In auditing and compliance, a "key control" is one of the most important internal controls businesses rely on to prevent or detect errors; this guide is about the keys to a building.) The Royal Canadian Mounted Police, the federal government's lead security agency for physical security, puts the purpose plainly in its Access Management Guide (GCPSG-006, 2024): "When keyed locks are used for access control, control over who has access to the keys becomes critical. If keys can be easily copied, control of access cannot be guaranteed."
No Canadian statute requires a document called a key control policy for an ordinary building. The duties that make one necessary are mostly provincial; the examples below are Ontario's, and every province and territory has its own equivalents.
- Occupational health and safety. Ontario's Occupational Health and Safety Act requires an employer to "take every precaution reasonable in the circumstances for the protection of a worker" (clause 25 (2) (h)), and its workplace violence program must "include measures and procedures to control the risks identified in the assessment" (clause 32.0.2 (2) (a)). Who can get into the building, and into rooms where people work alone or cash is kept, is one of those measures. Federally regulated workplaces such as banks and airports fall under Part II of the Canada Labour Code, whose section 124 sets the same general duty.
- The fire code. Key control must never stand between people and an exit. The Ontario Fire Code, O. Reg. 213/07, Division B, Article 2.7.2.2 requires that, unless otherwise approved, an exit door can be "readily opened from the inside with no more than one releasing operation and without requiring keys, special devices or specialized knowledge of the door opening mechanism". Where Section 2.8 applies, Article 2.8.1.4 says keys needed to operate the fire alarm system or reach fire protection equipment "shall be readily available to on-duty supervisory staff". Other provinces adopt the National Fire Code of Canada with their own amendments.
- Rental housing. Ontario's Residential Tenancies Act, 2006 says a landlord "shall not alter the locking system" on a door into a rental unit or residential complex during the tenancy "without giving the tenant replacement keys" (section 24), and a tenant may not change a lock without the landlord's consent (subsection 35 (1)). A master key does not change the entry rules: outside emergencies and consent, a landlord enters on written notice given at least 24 hours ahead (subsection 27 (1)).
- Condominiums. Under Ontario's Condominium Act, 1998, the corporation may enter a unit "on giving reasonable notice" (section 19), and the board may make reasonable rules to "promote the safety, security or welfare of the owners and of the property" (clause 58 (1) (a)), which is where fob issue and deactivation are usually set out.
- Locksmiths. British Columbia's Security Services Act licenses locksmiths as a security business, defining one to include a person who "makes, services, repairs, codes, recodes, rekeys or repins any locking device" or provides restricted keys, which include keys made from a code registered to the keyholder using equipment unique to that type of key, and keys that are government property.
Insurers, leases and security contracts often add their own conditions, such as rekeying after a lost master.
02
What a key control system covers
A key control system is everything that keeps the keys and the record in step. In a small office it may be a locked key cabinet and a sign-out sheet; on a campus it is a centralized key office. The University of Waterloo's Plant Operations Key Control office, for example, is "responsible for the distribution and safekeeping of keys to facilities on campus" and handles "more than 50,000 key transactions per year". Whatever the scale, the same parts appear:
- The keying schedule: every lock, which key operates it, and how the keys fit under any master key system. Without it, nobody can say what a lost key opens.
- The key inventory: every key numbered, how many copies exist and where the spares are. Tracking every copy is what turns a lost key into a known risk rather than a guess.
- The issue register: who holds each key long term, who authorized it and when it is due back.
- The daily sign-out log: working keys borrowed for a shift or a job by guards, custodians, contractors and building operators.
- Secure storage: a locked key cabinet in a controlled room or at the security desk, its own key and code held by few people.
- Electronic credentials: access cards and fobs, and the user list and schedules in the access control software.
- Codes and combinations: keypad, alarm and lock codes, which are keys in all but name.
The RCMP's Operational Physical Security Guide (GCPSG-010, 2022) sets a sound baseline for any building, not only a federal one. It says a "complete keying protocol should be implemented for the facility, which includes key control and key accountability", that locks on perimeter doors "should be keyed separately from other locks, and they should not enable access with a master key", that "keys for the entire facility, spare keys and the information needed to reproduce keys should not all be stored in the same container", and that master keys "should not leave the building and not be marked to identify the building for which they provide access".
Electronic systems change the risk rather than remove it. The Access Management Guide notes that an electronic system can record "where entry was made and with which key or device", and that a lost card's privileges "can be easily changed in the database without modification to the entry point or the reader". That is an audit trail of key usage that a paper log cannot match. A lost metal key may mean a new cylinder. Most buildings run both, so the system has to cover both.
03
Writing a key control policy
A key control policy answers one question for every key and credential in the building: who may have it, and how do we know they still should. It is written by whoever manages the premises: the property manager, the condominium manager, the facility manager or the school board's facilities department, with the security provider's input. A workable policy sets out:
- Who owns the system: one named role, with a deputy. Shared responsibility usually means nobody reconciles the log.
- Who can authorize a key: a short list of named roles. Waterloo's model is common in larger organizations: "each department has one or more persons, usually administrative assistants, who are authorized to issue keys and request lock changes within the department."
- The basis for issuing: access only where the person's work needs it. The Access Management Guide says those responsible should "actively review access privileges and should revoke access when it is no longer required".
- Master keys: who may hold one, and how it is signed out. Fewer masters reduce what one lost key can open.
- Contractors and cleaners: keys and fobs issued for the length of the job, and recovered when it ends.
- Return, loss and theft: keys handed back on the last day; a loss reported at once to a named person, with the rekeying decision made by someone who can see the keying schedule.
- Copying: none except through the key control office, with a restricted keyway where the risk justifies it.
- Codes: who knows them and when they change. The Access Management Guide says "combinations must not be written down where they can be found by others" and "should be frequently changed".
Two principles keep a policy honest. The first is separation: for access cards, the Access Management Guide says a process should "ensure no single official in the process may authorize and issue an identification or access card to a person", and the same holds for keys. The second is the fire code: no key control rule may lock an exit or keep the fire alarm keys from the staff on duty.
04
The key control log and the end-of-shift key check
The key control log is the record of keys moving: out, back and lost. Whether it is a bound book at the security desk, a spreadsheet or a key management system, each entry should show:
- the key or fob number, and the doors or areas it opens;
- the name of the person taking it, and their company if they are a contractor;
- who authorized it, for anything beyond the routine working keys;
- the date and time out, and the reason or the job;
- the date and time back, and who received it;
- anything unusual: a key returned late, damaged, or by someone other than the person who signed for it.
Keep long-term issue and daily sign-out apart. A tenant's suite keys or a property manager's master are issued once and audited periodically; the mechanical room key a contractor borrows should be back on the board by the end of the day. Mixed in one book, the short-term keys that never came back are hidden.
On a guarded site the end-of-shift key check catches a missing key while it can still be found. The outgoing guard counts the keys on the board against the log, notes any key still out and who has it, and the incoming guard confirms the count. The post orders should say which keys are counted, what to do if the count is short, and who to call.
Fobs need their own routine. The access control software holds the list of active credentials, but rarely tells anyone that a contractor's fob is still live months after the job ended. Comparing that list with the people who should have access is part of the same check. Access log data shows who opened which door and when, so decide who may read it, and why, before anyone needs to.

05
The key control audit: how often, and what it should find
A key audit compares three things: the keys that exist, the keys the register says exist, and the keys people actually hold. No Canadian law sets how often it is done for an ordinary building, so the frequency follows the risk, the insurer and the contract. A common pattern is:
- Every shift or every day: the working keys on the board counted against the sign-out log.
- Monthly: the key cabinet checked against the inventory, and the access control user list against current staff and contractors.
- Annually: a full audit, in which every key holder with a long-term key or master confirms they still have it, ideally by showing it, and the register, keying schedule and inventory are reconciled.
- After any change that matters: a lost master, a break-in, a new security or cleaning contractor, or a manager or tenant leaving.
Raise the frequency when the threat rises. For a medium threat level, the Access Management Guide's examples of increased vigilance include changing access codes and combinations on locks, and to "verify locations of keys and ensure that key control has not been lost".
A useful audit ends with actions, not just a count: keys nobody can account for, written off and their locks assessed; masters held by people who no longer need them, recovered; fobs for people who have left, deactivated. Record what was found and done, so the next audit starts from a known position.
06
Where key control records fail, and where SiteClara fits
The key log at the security desk is only as good as the last person who wrote in it. Keys go out with a signature and come back with none. The end-of-shift count is ticked by someone who never opened the cabinet. The annual audit happens when somebody remembers, and a missing key is a line in a notebook nobody reads. The property manager responsible for several buildings sees none of it unless they visit.
SiteClara records the routine checks at the place they happen. A printed QR poster, with an optional NFC tag behind it, goes where the check is made: beside the key cabinet or at the security desk. At the change of shift the guard scans the code or taps the tag on their own phone, with no app to install, sees the checks due there, such as the key count, and marks each one done or explains what stopped them. The time and the named person are recorded as it happens, with a photo when the check asks for one. A key found missing is reported on the spot and goes onto the team's list of jobs until someone closes it, and the supervisor can escalate it to the building's manager to answer.
The supervisor sees what was due, done and missed, and records the reason a check was missed. Each day the supervisor reviews it, adds a note and approves the daily report, which goes to nominated management or client contacts at 8 a.m. the next morning, showing how the checks went, what was reported and what is still open.
07
Questions people ask
What is the purpose of key control?
Key control makes sure that only authorized people can open each part of a building, and that the organization can show it. The RCMP's Access Management Guide (GCPSG-006, 2024) says keyed mechanical locks may be an effective and inexpensive way to help manage access "if proper key control is maintained by a centralized system".
What is key control in security?
It is the part of access management that covers keys, fobs, cards and codes: issuing them only to people whose work needs them, recording who holds each one, recovering them and auditing the record. The Canadian Centre for Occupational Health and Safety lists "using coded cards or keys to control access to the building or certain areas within the building" among the measures in its guidance on violence and harassment in the workplace.
08
Further reading, and a list to take away
For practice, read the RCMP's Access Management Guide (GCPSG-006) and Operational Physical Security Guide (GCPSG-010), written for federal buildings but sound for any. For the law, start with the province where the building is: in Ontario, the Occupational Health and Safety Act, the Fire Code, the Residential Tenancies Act, 2006 and the Condominium Act, 1998; in British Columbia, the Security Services Act. For the guard's side, see security post orders and the building security checklist.
Before you write or review a key control policy, check that:
- one named role owns key control, with a deputy;
- a current keying schedule shows what every key opens;
- only named roles authorize keys, and nobody both authorizes and issues alone;
- perimeter doors are off the master key, and masters stay in the building;
- working keys are counted at every change of shift;
- keys and fobs are recovered, and codes changed, when someone leaves;
- the access control user list is checked against current people monthly;
- a full audit is done yearly and after any break-in or change of contractor;
- no key control rule locks an exit or keeps fire alarm keys from staff on duty.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Access Management Guide (GCPSG-006, 2024) rcmp.ca
- Occupational Health and Safety Act ontario.ca
- Canada Labour Code laws-lois.justice.gc.ca
- Ontario Fire Code, O. Reg. 213/07 ontario.ca
- Residential Tenancies Act, 2006 ontario.ca
- Condominium Act, 1998 ontario.ca
- Security Services Act bclaws.gov.bc.ca
- Plant Operations Key Control uwaterloo.ca
- Operational Physical Security Guide (GCPSG-010, 2022) rcmp.ca
- Violence and harassment in the workplace ccohs.ca



