What this is
What is an access revocation record?
What is an access revocation record?
An access revocation record is the record that a departing contractor's physical and system access, cards, keys, system accounts and site network access, has actually been withdrawn. It is completed once, at or immediately after the point the engagement ends, and reconciled against what was originally issued.
Who completes it?
Security or IT, not the contract owner, because they are the parties who control the systems being revoked and can confirm the action rather than report an intention. The contract owner countersigns to confirm the trigger and the timing, not the technical steps.
What triggers it?
Work complete, contract ended, an individual removed from the contract, suspension, or an expired induction. The trigger matters because it sets urgency: a suspension or a removed individual needs same-day action in a way a planned contract end does not.
Scope
When is an access revocation record required?
This record exists at the end of an engagement, or the moment it is cut short. It does not cover the physical and administrative wind-down of the contract itself.
Use this template when
- The engagement has ended, whether on schedule, early, or through suspension
- An individual named on the worker register is being removed while the contract continues with others
- A trigger event has occurred: work complete, contract ended, individual removed, suspension, or induction expired
- A linked record needs this one to exist: links vendor, worker
- Security or IT needs a reconciled record of cards, keys and accounts before closing the contractor's file
Do not use it for
- Contractor Demobilization Record, which covers the physical wind-down, equipment removal, waste clearance and area restoration, not access.
- Contractor Final Evaluation, which assesses the contractor's overall performance across the engagement.
- Contractor Worker Register, which this record updates through Removed From Worker Register, but which is the master list, not the revocation evidence.
- Site Access Authorization, which grants access at the start of an engagement and is the record this one is reversing.
- Anything outside KnowContractor, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27001 A.9 requirements does this satisfy?
ISO 27001 Annex A treats termination of access as a control in its own right, distinct from the access-granting control it mirrors, precisely because the two fail differently.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27001 Annex A.9.2.6 | Access rights of all employees and external party users to information and information processing facilities shall be removed upon termination, or adjusted upon change | Individuals |
| ISO 27001 Annex A.9.2.1 | A formal user registration and de-registration process shall enable assignment and revocation of access rights | Individuals |
| ISO 27001 Annex A.11.1.2 | Physical entry controls shall ensure only authorised personnel are allowed access, which extends to withdrawing access once authorisation ends | Header |
| ISO 27001 Annex A.11.2.6 | Security of equipment and assets off-premises, including control of removable credentials such as vehicle passes, shall be addressed on termination | Wider access |
| ISO 27001 Annex A.8.1.4 | All employees and external party users shall return organisational assets in their possession upon termination | Individuals |
| ISO 27001 Annex A.9.2.5 | Access rights shall be reviewed at regular intervals, which a reconciliation of issued against returned credentials supports | Reconciliation |
| ISO 27001 Annex A.7.3.1 | Termination responsibilities, including which functions perform revocation and by when, shall be defined and communicated | Header |
What it does not cover
- Contractor Demobilization Record, which covers physical departure from site, equipment and waste, separately from access and accounts.
- Contractor Final Evaluation, which records performance judgement, not security control.
- Site Access Authorization, which is the originating grant this record reverses, and is not amended by completing this one.
- Contractor Worker Register, which this record feeds a status change into, but does not itself maintain.
- The password or credential reset itself, which is an IT operational task evidenced here, not performed here.
Global
Access Revocation Record requirements by country
Access revocation sits inside information security and physical security obligations that are widely required in substance even where no regulator inspects the specific form.
UK GDPR Article 32 and ISO 27001 Annex A.9
Appropriate technical and organisational measures include controlling who can access personal data, and a live account for a departed contractor is a control failure under that duty.
A data breach traced to an unrevoked contractor account is assessed against whether revocation was timely, not whether a record exists at all.
State data breach notification laws and sector rules such as the HIPAA Security Rule
Several regimes name termination access controls explicitly; the HIPAA Security Rule requires documented procedures for terminating access when a workforce or business relationship ends.
In regulated sectors, the gap between an engagement ending and revocation being actioned is the fact investigators ask for first.
ISO 27001 Annex A.9.2.6 and A.8.1.4
Certification audits examine termination and change of employment as a control, checking evidence of timely revocation and asset return.
An auditor sampling recent leavers will ask for the gap between last day and revocation date, not just whether revocation eventually happened.
How to complete it
How to complete an access revocation record, step by step
The fields record whether access was removed. Whether the removal was fast enough, and complete enough, is a judgement the record has to support rather than make automatically.
Effective Date should be the day access stops, and Time Revoked against each individual should be measured against it. A revocation actioned three days after a suspension's effective date has left three days of live access on a trigger that meant access should not have continued at all.
A physical card can be handed back while the underlying system account stays active, and a card that opens doors mechanically can remain live while a system account is disabled. Score both, and do not infer one from the other.
A revocation for Work complete and one for Suspension can look identical in the fields, both fully closed, but the suspension trigger should have compressed the timeline to hours, not the standard window. The record should show that urgency, not just a same-day date.
Cards Outstanding against Cards Issued catches what the Individuals section cannot: a card issued to someone who left the crew, was never logged on this record, and was never asked for back. Reconciliation checks that the register itself is complete.
What auditors find
Most common access revocation record findings
These are the findings that recur when revocation is treated as an administrative step rather than a security control.
| Finding | Clause | What fixes it |
|---|---|---|
| Revocation record completed days or weeks after the engagement actually ended. | ISO 27001 Annex A.9.2.6 | Trigger the record from the same event that ends the engagement, work order closure or contract termination, not from a periodic review. |
| Card recorded as returned with no corresponding check that system access was also revoked. | ISO 27001 Annex A.9.2.1 | Score card return and system access revocation as separate, both-required fields, not one inferred from the other. |
| Shared out-of-hours codes left unchanged after a departure. | ISO 27001 Annex A.11.1.2 | Change shared codes on any departure with knowledge of them, regardless of whether that individual's own card was returned. |
| Cards issued and cards returned are not reconciled; outstanding cards are not deactivated centrally. | ISO 27001 Annex A.9.2.5 | Reconcile Cards Issued against Cards Returned at the register level, and deactivate any outstanding card even if the individual cannot be reached. |
| Security or reception not notified of the departure, relying on the card system alone to prevent re-entry. | ISO 27001 Annex A.7.3.1 | Notify security and reception as a required step, since a deactivated card does not prevent someone being waved through on recognition. |
| IT or system accounts left active because the trigger was treated as a site event and never flagged to IT. | ISO 27001 Annex A.9.2.6 | Route every revocation trigger to IT as well as to security, regardless of whether the departure looks like a physical-access-only case. |
Case in point
Case in point: the card that outlived the contract
A refrigeration contractor's engagement ended when the work order closed. The engineer's site access card was collected at the gate on his last visit, Card Returned was marked Yes, and the access revocation record was signed off the same week. System Access Revoked, however, was left as Pending, because the card system and the building management system credential were administered by different teams, and the record's author only had visibility of the card system.
Four months later, the same credential, unassigned to any active card but still enabled in the building management system, was used to remotely adjust a chiller setpoint during an unrelated fault investigation, and it took a full day to establish the access had never actually been closed out. The corrective action was to make System Access Revoked a required field with its own owner, IT, distinct from Card Returned, rather than letting one confirmed step stand in for both.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- CON-031
- Archetype
- Record
- Record ID
- AREV-2026-000
- Scoring
- Complete or not
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 27001 A.9
- Links
- Links Vendor, Worker
- Tags
- Contractor, Security
- Sections
- 4
- Fields
- 41
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
12 fieldsRecord ID*
Auto sequence. Format ARR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Contractor*
Vendor ID*
Format VEN-0000.
Links to FDN-005 Vendor ID
Same Day, Not Next Month
Cards that stay live after a contractor leaves are a security exposure and break your emergency headcount. Revoke on the day, and reconcile what came back.
Revocation Trigger*
Work complete, contract ended, individual removed, suspension, or induction expired.
Effective Date*
Actioned By*
Individuals
Repeats9 fieldsName*
Card Number
Card Returned*
- Yes3 pts
- No0 pts
System Access Revoked*
- Yes3 pts
- Pending1 pt
- No0 pts
Time Revoked
Removed From Worker Register*
- Yes3 pts
- No0 pts
Keys Or Equipment Returned
- Yes3 pts
- Not applicable3 pts
- No0 pts
Locker Or Storage Cleared
Reason If Card Not Returned
Wider access
6 fieldsVehicle Access Removed
- Yes3 pts
- Not applicable3 pts
- No0 pts
IT Or System Accounts Disabled
- Yes3 pts
- Not applicable3 pts
- No0 pts
Site Wifi Or Network Access Removed
- Yes3 pts
- Not applicable3 pts
- No0 pts
Out Of Hours Codes Changed
Shared door codes known to departing contractors need changing, not just deactivating a card.
- Yes3 pts
- Not applicable3 pts
- No0 pts
Security Notified*
- Yes3 pts
- No0 pts
Reception Notified*
- Yes3 pts
- No0 pts
Reconciliation
14 fieldsCards Issued*
Cards Returned*
Cards Outstanding*
Outstanding Cards Deactivated*
- Yes3 pts
- No0 pts
Recharge Applied
Register Reconciled*
- Yes3 pts
- No0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Security*
Signature*
Contract Owner*
Second Signature*
CON-031 · record IDs look like AREV-2026-000 · Links Vendor, Worker
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The record is a confirmation. What actually fails is the handoff between the event that ends an engagement and the teams who have to act on it.
Triggers the access revocation record automatically from a contract end, suspension or worker removal, and keeps the reconciliation against cards issued in one place.
Checks the revocation record against ISO 27001 Annex A.9 evidence requirements ahead of a certification audit, and flags gaps before the auditor samples them.
Cross-checks Removed From Worker Register against the site's current headcount, so an unrevoked worker cannot be miscounted as present during an emergency evacuation.

Watches for the gap between an engagement ending and this record being completed, and escalates same-day rather than at the next periodic review.
This template lives in KnowContractor — contractor management. Prequalification, approval, induction, permits and performance.
Meet KnowContractor→Glossary
Access Revocation Record definitions and key terms
- Revocation trigger
- The event that starts the requirement to remove access: work complete, contract ended, an individual removed, suspension, or an expired induction, each carrying a different expected urgency.
- Reconciliation
- Checking the total cards or credentials issued against what has been returned or deactivated, which surfaces gaps that per-person checklists miss.
- Out-of-hours code
- A shared access code, distinct from an individually issued card, that must be changed rather than individually revoked when someone who knew it leaves.
- System access
- Login credentials to IT, network or building management systems, which can remain active independently of whether a physical card has been returned.
- Recharge
- A cost applied to the contractor for a card or item not returned, used as a practical incentive for return alongside the security requirement to deactivate it regardless.
FAQ
Frequently asked questions about access revocation record
How quickly should access be revoked?+
The same day the engagement ends, and immediately for a suspension or a removed individual. A window measured in days rather than hours treats a security control as an administrative task, and every day of delay is a day the exposure is live rather than theoretical.
Does returning the card mean access is revoked?+
No. A returned card confirms the physical object is back; it says nothing about whether the underlying system account or building management credential was disabled. Both need their own confirmation.
What if a card is not returned?+
Deactivate it centrally regardless, record the reason, and apply a recharge if that is your policy. An outstanding card that has been deactivated is a minor administrative loss; an outstanding card left active is a live security exposure.
Do shared codes need to change every time?+
Yes, whenever someone who knew the code leaves under a trigger that removes trust, contract ended, suspension, individual removed. A code known to a departed contractor is compromised for as long as it stays the same, regardless of what happens to their card.
Who should be notified beyond IT and security?+
Reception, or whoever staffs a manned entry point, since recognition-based entry can bypass a deactivated card entirely. The record treats Security Notified and Reception Notified as separate required fields for that reason.
What does Register Reconciled actually confirm?+
That the count of cards issued against this engagement matches what was returned or accounted for as outstanding and deactivated, closing the record at the register level rather than only at the level of the individuals actually processed.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Contractor Onboarding and Management
Contractor Prequalification Questionnaire
Collects a contractor's safety, insurance, training and performance information before they are approved
Contractor Safety Statistics Review
Reviews a contractor's injury rates, citations and experience modifier over recent years
Contractor Risk Classification
Classifies a contractor by the risk of the work they do, from low risk services to high risk construction
Contractor Approval Record
Records the decision to approve a contractor to work on site
Contractor Safety Program Review
Reviews the contractor's own written safety programme against your requirements
Subcontractor Declaration
Records any subcontractors a contractor intends to use

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 27001:2013 Annex A.9.2.1 and A.9.2.6, user registration and removal of access rights
- ISO 27001:2013 Annex A.8.1.4, A.7.3.1 and A.11.1.2, return of assets, termination responsibilities and physical entry
- HIPAA Security Rule, termination procedures, 45 CFR 164.308(a)(3)(ii)(C)
- UK GDPR Article 32, security of processing
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.