Security patrols

Key control: how to know who holds every key, and prove it

Key control, in building security, is the set of rules and records that decides who may hold each key, card or fob to a building, which doors it opens, how often the keys are counted, and what is rekeyed when one goes missing.

By SiteClaraPublished 12 minute read

A security officer counting keys on numbered hooks in an open key cabinet behind an office lobby desk.

Many buildings have a lock shop's keying schedule, a cabinet by the security desk and a binder nobody has reconciled in a year. This guide covers what a key control program contains, where US rules touch it, how to issue, audit and rekey, and how to tell whether the counts are real.

01

What key control is, and where the rules touch it

A key control program is a written policy and a set of records covering every mechanical key, access card and fob that opens part of a building. It answers four questions at any moment: which keys exist, who holds each one, what each one opens, and what was done when one was lost or not returned. The program usually belongs to the facility manager or property manager, with the security contractor running the day-to-day issue and counts at the security desk.

No single federal rule requires an ordinary commercial building to run a key control program. Several rules touch it, and a good policy is written with them in view:

  • Exits come first. Under the OSHA exit route standard, 29 CFR 1910.36, "Employees must be able to open an exit route door from the inside at all times without keys, tools, or special knowledge." The only exception is for mental, penal or correctional facilities with supervisory personnel continuously on duty and an emergency evacuation plan. Key control decides who can get in; it must never decide who can get out. Where a state runs its own OSHA-approved State Plan, check the state's equivalent rule.
  • Healthcare records the locks. The HIPAA Security Rule's physical safeguards, 45 CFR 164.310, require covered entities and business associates to "limit physical access to its electronic information systems and the facility or facilities in which they are housed." Among the addressable specifications is maintenance records: to "document repairs and modifications to the physical components of a facility which are related to security (for example, hardware, walls, doors, and locks)." A rekey of a records room is exactly that kind of modification.
  • Rental housing in some states sets a rekey clock. In Texas, Texas Property Code section 92.156 says a security device operated by a key, card or combination "shall be rekeyed by the landlord at the landlord's expense not later than the seventh day after each tenant turnover date," and that the landlord pays for rekeying connected with the use or change of its master key. The rule applies to residential tenancies and does not cover closet or other interior doors. Other states have their own rules; check the state's property code.
  • Schools plan for responders. The CISA K-12 School Security Guide, 3rd edition (2022) advises that if a school installs automatic locks on classroom doors, it should give emergency responders a means of reaching every locked-down area, for example by keeping master keys or key fobs "in a safe but easily accessible location" or giving local authorities a copy when new locks go in.

Keep key control separate from lockout/tagout. The OSHA standard on hazardous energy, 29 CFR 1910.147, requires lockout devices to be singularly identified, used only for controlling energy and "not used for other purposes," and removed by the employee who applied them. A lockout padlock that also opens the mechanical room, or that the building's master key opens, defeats the point of both systems.

02

What a key control program covers

A program that works on a real property covers more than the brass keys on the hooks. It usually includes:

  • The keying schedule: the lock shop's or locksmith's plan of the master key system, showing the grand master, the masters, and the change keys for each door, with the keyway. It is the most sensitive document in the program and belongs in a locked file, not on a shared drive.
  • The key register: every key by its stamped number, what it opens, how many copies exist, and who holds each one, with the date issued and the signature of the person who took it.
  • The key cabinet: a locked cabinet at the security desk or engineering office, with a numbered hook for each key and a sign-out log for keys lent for a shift or a job.
  • Restricted keys: patented or restricted keyways that a hardware store cannot copy, stamped "do not duplicate" and numbered, with duplicates ordered only by named people.
  • Access cards and fobs: the electronic side, with the same rules for issue, return and cancellation, and the access control system's reports as part of the audit.
  • Contractor and vendor keys: the janitorial crew's keys, the elevator mechanic's, the HVAC contractor's, and any lockbox codes, issued to the company and a named person, not to "the cleaners".
  • Emergency responder keys: the keys the fire department or police hold or can reach, including any rapid-entry key box the local fire department has asked for, recorded like any other copy.
  • The rules for loss and rekeying: who is told, how fast, and which cylinders are rekeyed for which key.

Write the policy down and have it approved by whoever owns the building's risk: the owner, the property manager or the facility manager. Put the security desk's part of it into the post orders, so an officer on a relief shift knows what to count, what to lend, and what to do when a key is not back.

03

Issuing and returning keys

Most key problems start at issue. A key handed over at the desk because the person asking looked like they worked there, with no signature and no return date, is the key that is missing in March. A sound issue process looks like this:

  1. Authorize in writing. A named manager approves each permanent key, for a stated reason, at the lowest level that does the job: a change key for one office before a floor master, a floor master before a building master.
  2. Identify the person. Check the ID of anyone who is not known to the desk, and match a contractor to the company's work order.
  3. Record the key number, not a description. "Key 14-B, suite 1400 master" can be audited; "the 14th floor key" cannot.
  4. Get a signature that acknowledges the key is not to be copied, lent or left in a desk drawer, and must be reported at once if lost.
  5. Set a return: end of shift for a lent key, end of the job for a contractor, end of employment or tenancy for a permanent holder.
  6. Close the loop. A returned key is checked against the register and put back on its numbered hook; a card is cancelled in the system the same day.

Janitorial and security contracts deserve their own rules. A night janitorial crew may need keys to every suite for four hours; lend them as a numbered ring signed out to the lead, counted back at the end of the shift, rather than issuing permanent keys to people who change every few months. A security contractor that changes companies at the end of its contract hands back every key and card on the last day, counted against the register with the client present.

Terminations are a common point of failure. Tie key and card return to the HR or tenant move-out checklist, so the person who processes a departure also collects the keys, and so a key that does not come back triggers the loss rules below rather than a note to follow up.

04

Counts, audits and inventories

No federal rule sets a frequency for key audits in an ordinary building, so the policy has to. A common pattern is three levels:

  • Every shift change: the incoming officer counts the key cabinet against its hooks and the sign-out log, and the outgoing officer accounts for anything lent and not back. The result goes in the pass-down log, with a named key and a name next to anything missing.
  • Monthly or quarterly: the supervisor or facility manager spot-checks a sample of permanent holders, asking to see the key rather than taking their word for it, and reviews the access control system for cards belonging to people who have left.
  • Once a year: a full reconciliation of the register against every holder, every copy and the keying schedule, with the results and any rekeying signed off by the manager who owns the program.

A useful audit record shows the date and time of the count, who did it, what was expected and what was found, and what happened to each discrepancy. "All keys present" with a signature is not an audit result; "42 hooks, 40 keys, 14-B and 22-C signed out to the day porter, returned 7:10 p.m." is.

Healthcare facilities should keep the audit alongside the HIPAA facility access policies and the maintenance record of lock changes, and apartment properties in states with rekey rules should be able to show the rekey date against each turnover.

A locksmith working on the lock of a classroom door while a custodian holds a parts tray in a school hallway.

05

Lost keys, rekeying and changing cores

Write the loss rules before a key is lost. For each level of key, the policy should say who is told, how quickly, and what gets rekeyed:

  • A change key for one door: rekey that cylinder, or swap its core if the building uses interchangeable cores.
  • A floor or department master: decide, with the facility manager, whether to rekey every cylinder under it, and record the decision and the reason if the answer is no.
  • A grand master or a building entrance key: treat it as a security incident, write a security incident report, and plan the rekey with the locksmith at once, with extra patrols of the affected doors until it is done.

Rekeying is also due when it is not a loss: a tenant or unit turnover where a state rule requires it, a departing contractor that held masters, or a keying schedule so old nobody trusts it. Interchangeable cores let a locksmith change a cylinder in minutes, which makes rekeying after a loss far more likely to happen.

Record every rekey and core change: the date, the cylinders changed, who did the work, the new key numbers and who received them. In healthcare, that record is the HIPAA maintenance record for security-related hardware; in a Texas apartment, it is how the landlord shows the seventh-day rule was met. Update the register the same day, and destroy or return the old keys under the locksmith's control.

Whenever locks change, tell the people who rely on them: the fire department for any key box or responder key, the alarm monitoring company, the janitorial and security contractors, and anyone whose post orders name a door.

06

Where the key record fails, and where SiteClara fits

The policy says the key cabinet is counted at every shift change. The binder beside it has a column of ticks and initials, some written ahead to the end of the week. Nobody can tell from it when a count was actually done, who did it, or what the cabinet looked like, and a missing key is often noticed only when someone needs it.

SiteClara records the checks at the place they happen. A printed QR poster, with an optional NFC tag behind it, goes beside the key cabinet, the security desk or any lockbox on the rounds. The officer scans the code or taps the tag on their own phone, with no app to install, sees the checks due there, such as "key cabinet counted against the hooks", and marks them done or says what stopped them. The time and the named person are recorded as it happens, with a photo of the open cabinet when one is asked for. A key found missing is reported there and goes onto the team's list of jobs until someone closes it.

The security supervisor sees what was due, done and missed, with the reason where one was given, and a job that needs the building manager can be escalated to them to answer. Each day the supervisor reviews the totals and photos, adds a note and approves a report that goes to nominated management or client contacts at 8 a.m. the next morning, showing how the scheduled checks went, for example 3 of 3 cabinet counts completed, and what is still open.

07

Questions people ask

What is key control in security?

It is the part of physical security that keeps track of the keys and other devices that open doors. The federal catalog of security controls, NIST's Security and Privacy Controls for Information Systems and Organizations (SP 800-53, Revision 5), sets it out in control PE-3, Physical Access Control: an organization should "Secure keys, combinations, and other physical access devices," inventory them at a frequency it defines, and "Change combinations and keys" at a set frequency "and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated." NIST writes the catalog for information systems, but the same three duties make a sound key control policy for any building.

What are the different types of key control systems?

The same control, PE-3 in NIST's SP 800-53, Revision 5, names the devices it means: "Physical access devices include keys, locks, combinations, biometric readers, and card readers." Many buildings run a mix: a mechanical master key system with a key register and a locked key cabinet, restricted keyways for the masters, interchangeable cores for quick rekeying, and an electronic access control system for cards and fobs. NIST leaves the form of the physical access log open, too: "Audit logs can be procedural, automated, or some combination thereof."

08

Further reading, and a list to take away

OSHA publishes the exit route standard, 29 CFR 1910.36, and the lockout/tagout standard, 29 CFR 1910.147. Healthcare organizations should read the HIPAA physical safeguards in 45 CFR 164.310. Schools can use CISA's K-12 School Security Guide for the wider physical security plan. Landlords should check their own state's property code; Texas's rekeying rule is in Texas Property Code section 92.156.

Before you rely on a building's key control, check that:

  • there is a written key control policy, approved and dated;
  • the keying schedule is current and locked away;
  • every key has a stamped number and appears in the register with its holder;
  • keys are issued at the lowest level that does the job, with a signature and a return date;
  • restricted keyways are used for masters, and duplicates are ordered only by named people;
  • the cabinet is counted at every shift change, with missing keys named in the pass-down log;
  • contractor keys are issued to a named person and counted back at the end of the job or shift;
  • key and card return is on every departure and move-out checklist;
  • the loss rules say what is rekeyed for each level of key, and every rekey is recorded;
  • responders have the keys they need, and no key control measure locks an exit route.

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. 29 CFR 1910.36 osha.gov
  2. 45 CFR 164.310 ecfr.gov
  3. Texas Property Code section 92.156 statutes.capitol.texas.gov
  4. K-12 School Security Guide, 3rd edition (2022) cisa.gov
  5. 29 CFR 1910.147 osha.gov
  6. Security and Privacy Controls for Information Systems and Organizations (SP 800-53, Revision 5) nvlpubs.nist.gov