What this is
What is an access control review?
What is an access control review?
A periodic check, by area, of who holds physical access to a site and whether their current role still justifies it. It exists because access accumulates through onboarding, projects, contracts and role changes, and almost never sheds itself without someone deliberately removing it.
Why review by area rather than by person?
Because the question that matters is whether an area's access list is defensible, not whether a given individual's total footprint feels reasonable. A person can legitimately hold access to several areas; an area holding access it cannot justify is the finding this review is built to surface.
Who should confirm the access list?
The area owner, not central security working from the card system alone. Security holds the record of who was granted access and when; the area owner is the one who knows whether that person still works there and still needs to get in.
Scope
When is an access control review required?
This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- The six-month review interval is due for the site or a specific area
- The workspace is being set up, or the singleton register needs establishing
- A trigger event has occurred: a wave of leavers, a completed project, a reported shared code
- You are running the Lone Working and Security, Site Access and Facilities, or Worker Onboarding and Offboarding programme and this is one of its steps
- A linked record needs this one to exist: Contractor access, Worker register
Do not use it for
- Security Risk Assessment, which sets the access levels this review checks are still being honoured, rather than checking them itself.
- Key and Access Device Register, which is the live inventory of who holds which physical key or card, not the periodic justification check.
- Access Request Record, which grants access at the point it is needed, the decision this review later re-examines.
- Worker Offboarding Checklist, which is where access should already have been revoked before a leaver ever shows up as a finding here.
- Anything outside KnowSafe, which belongs in the workspace that owns that process.
Compliance mapping
Which ISO 45001 cl.8.1 requirements does this satisfy?
ISO 45001 requires operational controls to be established and applied, and access control is one of the more literal examples of a control that decays silently if nobody checks it is still doing what it was set up to do.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.8.1 | Operational controls established, implemented and maintained, applied here to physical access by area rather than left as a one-off grant | By area |
| ISO 45001 cl.5.4 | Consultation and participation of relevant workers, applied here as area owner confirmation rather than a central review alone | By area |
| ISO 45001 cl.7.5.3 | Documented information controlled and kept current, applied to the key register and master key accounting as records that must stay accurate between reviews | Findings |
| ISO 45001 cl.6.1.2.1 | Hazard identification proactive and ongoing, extended here to unattributed shared codes and temporary access never revoked | Findings |
| ISO 45001 cl.10.2 | Corrective action taken and tracked to a verified close where access is found to be unjustified | Outcome |
| ISO 45001 cl.9.1.1 | Monitoring and measurement of whether a related process, here offboarding, is actually working rather than assumed to be | Outcome |
| ISO 45001 cl.8.1 | Operational control extended to related processes such as contractor approval and worker records that access decisions depend on | Related records |
What it does not cover
- Security Risk Assessment, which decides what access level each area should have, a decision this review checks against but does not itself make.
- Key and Access Device Register, which is the ongoing inventory of physical keys and cards, kept current between reviews rather than only at review time.
- Worker Offboarding Checklist, which is where a leaver's access should be revoked at the point they leave, not left to surface as a finding here months later.
- Contractor approval record, which governs whether a contractor should have access at all, a decision this review assumes was made correctly and checks has not expired.
- CCTV and Monitoring Review, which reviews the monitoring system separately from who is permitted to be in the areas it watches.
Global
Access Control Review requirements by country
Access control itself is rarely named in law. What reaches it in practice is the general duty to maintain operational controls, and separately, the treatment of access logs and card data as personal information.
OSH Act General Duty Clause; state data privacy statutes
No federal standard mandates periodic access review, but unresolved access failures feeding a workplace violence or security incident engage the General Duty Clause, and access logs are increasingly treated as personal data under state privacy law.
The review is voluntary good practice until an incident makes the absence of one the finding an investigation lands on.
Data Protection Act 2018 / UK GDPR
Access logs, card records and CCTV tied to named individuals are personal data, and retaining access that is no longer justified sits uneasily with data minimisation as well as security.
A leaver still holding access is both a security finding and, strictly, a data protection one, since their card activity continues to be logged after they had any lawful basis to be on site.
ISO 45001 cl.8.1; commonly paired with ISO/IEC 27001 access control requirements
ISO 45001 requires operational controls to be maintained; organisations running an information security management system alongside typically hold physical access to the same access-review discipline as system access.
Where both certifications are held, an inconsistent standard between physical and system access control is the kind of gap an auditor working across both will notice quickly.
How to complete it
How to complete an access control review, step by step
The form prompts for a count in every area. Whether the count means anything depends on judgement calls the review cannot make by simply asking for numbers.
Holders With Access and Justified By Current Role are two different questions asked back to back for a reason. Recording the same number in both because nobody actually checked role against list defeats the review before it starts.
Shared Codes In Use scoring 'Widely' at zero is not about inconvenience; it is that a shared code cannot be attributed to anyone, which means an access record built on it cannot answer who was actually where. Changing it is a Findings action, not a note for next time.
Area Owner Confirmed The List is the field that separates a reconciled review from a card-system printout. Central security knows who was granted access; the area owner is the one who can say whether that person still belongs there today.
A non-zero count of leavers still holding access or contractors past their approval is not a number to record and carry to next cycle. It is the review's own evidence that the offboarding and contractor approval processes it depends on are not closing access when they should.
What auditors find
Most common access control review findings
The review usually runs to schedule. Findings concern whether the numbers were reconciled against something real, and whether what they surfaced was acted on.
| Finding | Clause | What fixes it |
|---|---|---|
| Holders With Access and Justified By Current Role recorded as the same number without evidence either was actually checked against role. | ISO 45001 cl.8.1 | Require the area owner to confirm role against access individually, not approve the list as a block. |
| Leavers still holding access carried forward from the previous review with no action raised. | ISO 45001 cl.10.2 | Raise Action Required against every leaver-access finding at the point it is found, with an owner and a date. |
| Shared codes marked widely known with no plan to change them recorded elsewhere in the record. | ISO 45001 cl.6.1.2.1 | Route a widely-shared code straight to a corrective action; do not let it stand as a description of normal practice. |
| Area owner confirmation marked partly or not obtained, but the review closed as complete regardless. | ISO 45001 cl.5.4 | Hold Status at in progress until every area in scope has an area owner confirmation, partial or better. |
| Master keys not fully accounted for, or the key register marked as only partly current. | ISO 45001 cl.7.5.3 | Physically verify every master key against the register at each review; do not accept an assumed location. |
| Repeated finding of contractors with expired approval, indicating the contractor approval process itself is not closing access on time. | ISO 45001 cl.9.1.1 | Escalate a repeat finding to a process review of contractor approval, rather than logging the same numeric finding each cycle. |
Case in point
Case in point: the card that outlived the job
A distribution site ran its six-month access review on schedule. Security pulled the card system report, counted holders per area, and circulated the list to area owners for sign-off. The despatch area owner confirmed without reading closely; the list matched what the system showed, and the review closed with zero leavers found.
Four months later, a former agency worker's card was used to enter the yard at 2am. The card had never been deactivated when the agency contract ended eight months earlier, because deactivation depended on the agency notifying the site, which it had not. The review had asked whether holders matched current role, and the area owner had confirmed a list without checking a single name against who was still actually working there, because the list looked complete and nothing prompted a closer look.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- SAF-147
- Archetype
- Review
- Record ID
- ACR-2026-000
- Scoring
- Unjustified access
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 45001 cl.8.1
- Links
- Links Contractor access, Worker register
- Tags
- Security, Access
- Sections
- 5
- Fields
- 40
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
10 fieldsReview ID*
Auto sequence. Format ACR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Access Granted For A Project Three Years Ago
Access accumulates and never sheds. This review exists to remove what is no longer justified, which is almost always more than anybody expects.
Period Covered*
Reviewed By*
Access Holders In Scope*
By area
Repeats8 fieldsArea*
The area within the site.
Exact Location
Drop a pin for anything hard to find.
Access Level*
- Escorted only3 pts
- General areas2 pts
- Restricted areas1 pt
- Full site0 pts
Holders With Access*
Justified By Current Role*
Access Removed This Review*
Area Owner Confirmed The List*
- Yes3 pts
- Partly1 pt
- No0 pts
Restricted Area*
Findings
9 fieldsLeavers Still Holding Access*
Contractors With Expired Approval*
Cards Issued Not Returned*
Access Not Matching Current Role*
Shared Codes In Use*
A shared door code known to fifty people is not access control.
- No3 pts
- Some1 pt
- Widely0 pts
Codes Changed Since Last Review*
- Yes3 pts
- Not needed3 pts
- No0 pts
Temporary Access Never Revoked*
Master Keys Accounted For*
- All3 pts
- Most1 pt
- No0 pts
Key Register Current*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldSecurity Assessment ID
The assessment that set the access levels.
Links to SAF-142 Assessment ID
Outcome
12 fieldsTotal Access Removed*
Process Improvement Needed*
- No3 pts
- Yes1 pt
Offboarding Process Working*
- Yes3 pts
- Partly1 pt
- No0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Review Due*
Security*
Signature*
Site Manager*
Second Signature*
SAF-147 · record IDs look like ACR-2026-000 · Links Contractor access, Worker register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The review itself is a form with a count. What fails is the handoff either side of it: access that should have closed on offboarding, and findings here that stall before becoming a corrective action.
Holds the review against the site's area register, flags overdue cycles, and tracks findings through to a verified corrective action close.
Links leaver findings back to the offboarding checklist that should have closed access already, so the gap is visible at its source, not just at the review.
Cross-checks contractor approval expiry against site access so a lapsed approval surfaces before the six-month review finds it rather than after.

Watches leaver and contract-end events elsewhere in the record set and raises an out-of-cycle area review rather than waiting for the scheduled date.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Access Control Review definitions and key terms
- Justified access
- Access held by someone whose current role genuinely requires it, distinct from access that was once granted and simply never removed.
- Shared code
- An access code known to and used by multiple people rather than issued individually, which defeats attribution regardless of how the door itself is secured.
- Area owner
- The person responsible for who is permitted in a specific area, who confirms the access list against actual current need rather than against system records alone.
- Master key
- A key or credential that opens multiple areas rather than one, and whose loss or unaccounted status carries proportionately higher risk.
- Access holder in scope
- Anyone counted as holding access for the purposes of this review, whether employee, contractor or agency worker, regardless of how the access was originally granted.
FAQ
Frequently asked questions about access control review
Six months feels infrequent for something that accumulates continuously. Should it run more often?+
The interval is a backstop, not the only trigger. A wave of leavers, a completed project or a reported shared code should raise an out-of-cycle review of the affected area rather than waiting for the calendar, the same way a risk assessment gets triggered by change rather than only by date.
Why does the review ask area owners to confirm, when security already has the access data?+
Because security's data shows who was granted access and when, not who still needs it. The area owner is the only person positioned to answer the second question, and a review that skips them is checking the system against itself.
What should we do about a shared code we can't change immediately?+
Record it as a finding and raise the action regardless of the timeline to fix it. A shared code that will take a month to change is still a finding today; deferring the record until the fix is done just hides the gap for a month.
Do contractors count in the access holders total?+
Yes, and they need their own line of scrutiny, because contractor approval typically has its own expiry that runs on a different clock to employee role changes. Contractors With Expired Approval exists as a separate count for exactly this reason.
How do we handle an area with no clear single owner?+
Assign one for the purpose of this review even if operational responsibility is genuinely shared. A confirmation with no accountable name behind it tends to get treated as everybody's job and nobody's, which is how areas go multiple cycles unconfirmed.
What does a high number of leavers still holding access actually tell us?+
That the offboarding process, not this review, has a gap. This review is the check, not the fix; a repeated finding here is evidence the Worker Offboarding Checklist is not closing access reliably and needs attention in its own right.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Lone Working and Security
Tested lone working arrangements and a security position covering theft, access and food defense.
Site Access and Facilities
Access that expires on its own, and a visitor log the warden can carry.
Worker Onboarding and Offboarding
Nobody starting unprepared, and nobody leaving with access they still hold.
Used together in Lone Working and Security
Food Defense Plan
Assesses where product could be deliberately contaminated and sets out how that is prevented
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Security Incident Investigation
Records theft, break in, unauthorised access, tampering or threat
More in Security and Lone Working
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Security Incident Investigation
Records theft, break in, unauthorised access, tampering or threat
CCTV and Monitoring Review
Reviews camera coverage, recording retention, image quality and who can view footage

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 clauses 8.1, 5.4, 7.5.3, 9.1.1 and 10.2
- Data Protection Act 2018 / UK GDPR, personal data in access logs and CCTV
- ISO/IEC 27001, information security management, access control requirements
- OSH Act Section 5(a)(1), General Duty Clause (US)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.