Knowella

Access Control Review

An access control review checks who holds access to which areas and whether that is still justified, run every six months by security with the area owners. Its recurring failure is not a missing review but a stale one: the count of holders is confirmed against a card system report rather than against the people who actually still need to be there, and access granted for a project that ended three years ago rolls forward untouched.

KnowSafeReviewSAF-14740 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.8.1
Workspace
KnowSafe
Form type
Review
Completed by
Security, with area owners confirming who is on the list
Raised
Every six months, and after any trigger that changes who should have access

The short version

  • The review scores 'Justified By Current Role' against 'Holders With Access' as two separate counts for a reason. A list that is complete but not reconciled against current roles looks tidy and hides exactly the access this review exists to remove.
  • A shared door code known to fifty people is not access control, and the form says so directly. Widely shared codes score zero regardless of how convenient they are, because a shared code cannot be attributed to anyone once something goes missing.
  • Access granted for a project three years ago is named in the form's own header as the most common finding. It is not a hypothetical; it is what area owners find almost every cycle once they are asked to look rather than confirm.
  • The review only closes something if area owners actually confirm the list. A central review run from the card system report without area owner sign-off produces a document, not a reconciled access position.

What this is

What is an access control review?

What is an access control review?

A periodic check, by area, of who holds physical access to a site and whether their current role still justifies it. It exists because access accumulates through onboarding, projects, contracts and role changes, and almost never sheds itself without someone deliberately removing it.

Why review by area rather than by person?

Because the question that matters is whether an area's access list is defensible, not whether a given individual's total footprint feels reasonable. A person can legitimately hold access to several areas; an area holding access it cannot justify is the finding this review is built to surface.

Who should confirm the access list?

The area owner, not central security working from the card system alone. Security holds the record of who was granted access and when; the area owner is the one who knows whether that person still works there and still needs to get in.

Scope

When is an access control review required?

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • The six-month review interval is due for the site or a specific area
  • The workspace is being set up, or the singleton register needs establishing
  • A trigger event has occurred: a wave of leavers, a completed project, a reported shared code
  • You are running the Lone Working and Security, Site Access and Facilities, or Worker Onboarding and Offboarding programme and this is one of its steps
  • A linked record needs this one to exist: Contractor access, Worker register

Do not use it for

  • Security Risk Assessment, which sets the access levels this review checks are still being honoured, rather than checking them itself.
  • Key and Access Device Register, which is the live inventory of who holds which physical key or card, not the periodic justification check.
  • Access Request Record, which grants access at the point it is needed, the decision this review later re-examines.
  • Worker Offboarding Checklist, which is where access should already have been revoked before a leaver ever shows up as a finding here.
  • Anything outside KnowSafe, which belongs in the workspace that owns that process.

Compliance mapping

Which ISO 45001 cl.8.1 requirements does this satisfy?

ISO 45001 requires operational controls to be established and applied, and access control is one of the more literal examples of a control that decays silently if nobody checks it is still doing what it was set up to do.

ClauseRequirementWhere it lands
ISO 45001 cl.8.1Operational controls established, implemented and maintained, applied here to physical access by area rather than left as a one-off grantBy area
ISO 45001 cl.5.4Consultation and participation of relevant workers, applied here as area owner confirmation rather than a central review aloneBy area
ISO 45001 cl.7.5.3Documented information controlled and kept current, applied to the key register and master key accounting as records that must stay accurate between reviewsFindings
ISO 45001 cl.6.1.2.1Hazard identification proactive and ongoing, extended here to unattributed shared codes and temporary access never revokedFindings
ISO 45001 cl.10.2Corrective action taken and tracked to a verified close where access is found to be unjustifiedOutcome
ISO 45001 cl.9.1.1Monitoring and measurement of whether a related process, here offboarding, is actually working rather than assumed to beOutcome
ISO 45001 cl.8.1Operational control extended to related processes such as contractor approval and worker records that access decisions depend onRelated records

What it does not cover

  • Security Risk Assessment, which decides what access level each area should have, a decision this review checks against but does not itself make.
  • Key and Access Device Register, which is the ongoing inventory of physical keys and cards, kept current between reviews rather than only at review time.
  • Worker Offboarding Checklist, which is where a leaver's access should be revoked at the point they leave, not left to surface as a finding here months later.
  • Contractor approval record, which governs whether a contractor should have access at all, a decision this review assumes was made correctly and checks has not expired.
  • CCTV and Monitoring Review, which reviews the monitoring system separately from who is permitted to be in the areas it watches.

Global

Access Control Review requirements by country

Access control itself is rarely named in law. What reaches it in practice is the general duty to maintain operational controls, and separately, the treatment of access logs and card data as personal information.

United States

OSH Act General Duty Clause; state data privacy statutes

No federal standard mandates periodic access review, but unresolved access failures feeding a workplace violence or security incident engage the General Duty Clause, and access logs are increasingly treated as personal data under state privacy law.

The review is voluntary good practice until an incident makes the absence of one the finding an investigation lands on.

United Kingdom

Data Protection Act 2018 / UK GDPR

Access logs, card records and CCTV tied to named individuals are personal data, and retaining access that is no longer justified sits uneasily with data minimisation as well as security.

A leaver still holding access is both a security finding and, strictly, a data protection one, since their card activity continues to be logged after they had any lawful basis to be on site.

International

ISO 45001 cl.8.1; commonly paired with ISO/IEC 27001 access control requirements

ISO 45001 requires operational controls to be maintained; organisations running an information security management system alongside typically hold physical access to the same access-review discipline as system access.

Where both certifications are held, an inconsistent standard between physical and system access control is the kind of gap an auditor working across both will notice quickly.

How to complete it

How to complete an access control review, step by step

The form prompts for a count in every area. Whether the count means anything depends on judgement calls the review cannot make by simply asking for numbers.

Reconcile the count, don't just take it

Holders With Access and Justified By Current Role are two different questions asked back to back for a reason. Recording the same number in both because nobody actually checked role against list defeats the review before it starts.

Treat a widely shared code as a finding, not a footnote

Shared Codes In Use scoring 'Widely' at zero is not about inconvenience; it is that a shared code cannot be attributed to anyone, which means an access record built on it cannot answer who was actually where. Changing it is a Findings action, not a note for next time.

Get area owner sign-off, not a central report

Area Owner Confirmed The List is the field that separates a reconciled review from a card-system printout. Central security knows who was granted access; the area owner is the one who can say whether that person still belongs there today.

Chase leavers and expired contractors as the real signal

A non-zero count of leavers still holding access or contractors past their approval is not a number to record and carry to next cycle. It is the review's own evidence that the offboarding and contractor approval processes it depends on are not closing access when they should.

What auditors find

Most common access control review findings

The review usually runs to schedule. Findings concern whether the numbers were reconciled against something real, and whether what they surfaced was acted on.

FindingClauseWhat fixes it
Holders With Access and Justified By Current Role recorded as the same number without evidence either was actually checked against role.ISO 45001 cl.8.1Require the area owner to confirm role against access individually, not approve the list as a block.
Leavers still holding access carried forward from the previous review with no action raised.ISO 45001 cl.10.2Raise Action Required against every leaver-access finding at the point it is found, with an owner and a date.
Shared codes marked widely known with no plan to change them recorded elsewhere in the record.ISO 45001 cl.6.1.2.1Route a widely-shared code straight to a corrective action; do not let it stand as a description of normal practice.
Area owner confirmation marked partly or not obtained, but the review closed as complete regardless.ISO 45001 cl.5.4Hold Status at in progress until every area in scope has an area owner confirmation, partial or better.
Master keys not fully accounted for, or the key register marked as only partly current.ISO 45001 cl.7.5.3Physically verify every master key against the register at each review; do not accept an assumed location.
Repeated finding of contractors with expired approval, indicating the contractor approval process itself is not closing access on time.ISO 45001 cl.9.1.1Escalate a repeat finding to a process review of contractor approval, rather than logging the same numeric finding each cycle.

Case in point

Case in point: the card that outlived the job

A distribution site ran its six-month access review on schedule. Security pulled the card system report, counted holders per area, and circulated the list to area owners for sign-off. The despatch area owner confirmed without reading closely; the list matched what the system showed, and the review closed with zero leavers found.

Four months later, a former agency worker's card was used to enter the yard at 2am. The card had never been deactivated when the agency contract ended eight months earlier, because deactivation depended on the agency notifying the site, which it had not. The review had asked whether holders matched current role, and the area owner had confirmed a list without checking a single name against who was still actually working there, because the list looked complete and nothing prompted a closer look.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

40fields
5 sections
Reference
SAF-147
Archetype
Review
Record ID
ACR-2026-000
Scoring
Unjustified access
Direction
Low is good
Singleton
Yes
Basis
ISO 45001 cl.8.1
Links
Links Contractor access, Worker register
Tags
Security, Access
Sections
5
Fields
40
Follow up fields
3
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Review ID*

Generated on save

Auto sequence. Format ACR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Info

Access Granted For A Project Three Years Ago

Access accumulates and never sheds. This review exists to remove what is no longer justified, which is almost always more than anybody expects.

Text

Period Covered*

Users

Reviewed By*

Numeric Answer

Access Holders In Scope*

By area

Repeats8 fields
Single Choice

Area*

The area within the site.

Cutting roomBoning hallPackingChill storeFreezerPasteurisingFillingCulture roomDespatchYardWorkshopPlant roomOffices
Location

Exact Location

Optional

Drop a pin for anything hard to find.

Single Choice

Access Level*

Scored
  • Escorted only3 pts
  • General areas2 pts
  • Restricted areas1 pt
  • Full site0 pts
Numeric Answer

Holders With Access*

Numeric Answer

Justified By Current Role*

Scored
Numeric Answer

Access Removed This Review*

Scored
Single Choice

Area Owner Confirmed The List*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Restricted Area*

YesNo

Findings

9 fields
Numeric Answer

Leavers Still Holding Access*

Scored
Numeric Answer

Contractors With Expired Approval*

Scored
Numeric Answer

Cards Issued Not Returned*

Scored
Numeric Answer

Access Not Matching Current Role*

Scored
Single Choice

Shared Codes In Use*

Scored

A shared door code known to fifty people is not access control.

  • No3 pts
  • Some1 pt
  • Widely0 pts
Single Choice

Codes Changed Since Last Review*

Scored
  • Yes3 pts
  • Not needed3 pts
  • No0 pts
Numeric Answer

Temporary Access Never Revoked*

Scored
Single Choice

Master Keys Accounted For*

Scored
  • All3 pts
  • Most1 pt
  • No0 pts
Single Choice

Key Register Current*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Security Assessment ID

OptionalLinked

The assessment that set the access levels.

Links to SAF-142 Assessment ID

Outcome

12 fields
Numeric Answer

Total Access Removed*

Scored
Single Choice

Process Improvement Needed*

Scored
  • No3 pts
  • Yes1 pt
Single Choice

Offboarding Process Working*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Review Due*

Users

Security*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-147 · record IDs look like ACR-2026-000 · Links Contractor access, Worker register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The review itself is a form with a count. What fails is the handoff either side of it: access that should have closed on offboarding, and findings here that stall before becoming a corrective action.

KnowSafe

Holds the review against the site's area register, flags overdue cycles, and tracks findings through to a verified corrective action close.

KnowOps

Links leaver findings back to the offboarding checklist that should have closed access already, so the gap is visible at its source, not just at the review.

KnowContractor

Cross-checks contractor approval expiry against site access so a lapsed approval surfaces before the six-month review finds it rather than after.

Ella
Ella

Watches leaver and contract-end events elsewhere in the record set and raises an out-of-cycle area review rather than waiting for the scheduled date.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Access Control Review definitions and key terms

Justified access
Access held by someone whose current role genuinely requires it, distinct from access that was once granted and simply never removed.
Shared code
An access code known to and used by multiple people rather than issued individually, which defeats attribution regardless of how the door itself is secured.
Area owner
The person responsible for who is permitted in a specific area, who confirms the access list against actual current need rather than against system records alone.
Master key
A key or credential that opens multiple areas rather than one, and whose loss or unaccounted status carries proportionately higher risk.
Access holder in scope
Anyone counted as holding access for the purposes of this review, whether employee, contractor or agency worker, regardless of how the access was originally granted.

FAQ

Frequently asked questions about access control review

Six months feels infrequent for something that accumulates continuously. Should it run more often?+

The interval is a backstop, not the only trigger. A wave of leavers, a completed project or a reported shared code should raise an out-of-cycle review of the affected area rather than waiting for the calendar, the same way a risk assessment gets triggered by change rather than only by date.

Why does the review ask area owners to confirm, when security already has the access data?+

Because security's data shows who was granted access and when, not who still needs it. The area owner is the only person positioned to answer the second question, and a review that skips them is checking the system against itself.

What should we do about a shared code we can't change immediately?+

Record it as a finding and raise the action regardless of the timeline to fix it. A shared code that will take a month to change is still a finding today; deferring the record until the fix is done just hides the gap for a month.

Do contractors count in the access holders total?+

Yes, and they need their own line of scrutiny, because contractor approval typically has its own expiry that runs on a different clock to employee role changes. Contractors With Expired Approval exists as a separate count for exactly this reason.

How do we handle an area with no clear single owner?+

Assign one for the purpose of this review even if operational responsibility is genuinely shared. A confirmation with no accountable name behind it tends to get treated as everybody's job and nobody's, which is how areas go multiple cycles unconfirmed.

What does a high number of leavers still holding access actually tell us?+

That the offboarding process, not this review, has a gap. This review is the check, not the fix; a repeated finding here is evidence the Worker Offboarding Checklist is not closing access reliably and needs attention in its own right.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 clauses 8.1, 5.4, 7.5.3, 9.1.1 and 10.2
  • Data Protection Act 2018 / UK GDPR, personal data in access logs and CCTV
  • ISO/IEC 27001, information security management, access control requirements
  • OSH Act Section 5(a)(1), General Duty Clause (US)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.