Knowella

Access Revocation Record

An access revocation record exists because access removal is the control everyone assumes happened and nobody checks. Its recurring failure is timing: the record gets completed days or weeks after the engagement actually ended, by which point a card that should have stopped working on day one has already been used, or simply sits live in a system nobody is monitoring.

KnowContractorRecordCON-03141 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27001 A.9
Workspace
KnowContractor
Form type
Record
Window
Same day the engagement ends, not reconstructed later
Owner
Managed by security or IT

The short version

  • Same day, not next month. A card that stays live after a contractor leaves is a live security exposure for every day it remains active, not a paperwork gap.
  • A returned card and a revoked card are two different facts. Card Returned records the physical object; System Access Revoked records whether it still opens anything, and a returned card that was never deactivated is still a working key in a drawer.
  • Shared codes need changing, not just individual cards deactivating. A departing contractor who knew an out-of-hours code takes that knowledge with them regardless of what happens to their own card.
  • Reconciliation closes the loop that individual revocation does not. Cards Issued against Cards Returned catches the card nobody remembered to ask for back, which a per-person checklist will not surface on its own.

What this is

What is an access revocation record?

What is an access revocation record?

An access revocation record is the record that a departing contractor's physical and system access, cards, keys, system accounts and site network access, has actually been withdrawn. It is completed once, at or immediately after the point the engagement ends, and reconciled against what was originally issued.

Who completes it?

Security or IT, not the contract owner, because they are the parties who control the systems being revoked and can confirm the action rather than report an intention. The contract owner countersigns to confirm the trigger and the timing, not the technical steps.

What triggers it?

Work complete, contract ended, an individual removed from the contract, suspension, or an expired induction. The trigger matters because it sets urgency: a suspension or a removed individual needs same-day action in a way a planned contract end does not.

Scope

When is an access revocation record required?

This record exists at the end of an engagement, or the moment it is cut short. It does not cover the physical and administrative wind-down of the contract itself.

Use this template when

  • The engagement has ended, whether on schedule, early, or through suspension
  • An individual named on the worker register is being removed while the contract continues with others
  • A trigger event has occurred: work complete, contract ended, individual removed, suspension, or induction expired
  • A linked record needs this one to exist: links vendor, worker
  • Security or IT needs a reconciled record of cards, keys and accounts before closing the contractor's file

Do not use it for

  • Contractor Demobilization Record, which covers the physical wind-down, equipment removal, waste clearance and area restoration, not access.
  • Contractor Final Evaluation, which assesses the contractor's overall performance across the engagement.
  • Contractor Worker Register, which this record updates through Removed From Worker Register, but which is the master list, not the revocation evidence.
  • Site Access Authorization, which grants access at the start of an engagement and is the record this one is reversing.
  • Anything outside KnowContractor, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27001 A.9 requirements does this satisfy?

ISO 27001 Annex A treats termination of access as a control in its own right, distinct from the access-granting control it mirrors, precisely because the two fail differently.

ClauseRequirementWhere it lands
ISO 27001 Annex A.9.2.6Access rights of all employees and external party users to information and information processing facilities shall be removed upon termination, or adjusted upon changeIndividuals
ISO 27001 Annex A.9.2.1A formal user registration and de-registration process shall enable assignment and revocation of access rightsIndividuals
ISO 27001 Annex A.11.1.2Physical entry controls shall ensure only authorised personnel are allowed access, which extends to withdrawing access once authorisation endsHeader
ISO 27001 Annex A.11.2.6Security of equipment and assets off-premises, including control of removable credentials such as vehicle passes, shall be addressed on terminationWider access
ISO 27001 Annex A.8.1.4All employees and external party users shall return organisational assets in their possession upon terminationIndividuals
ISO 27001 Annex A.9.2.5Access rights shall be reviewed at regular intervals, which a reconciliation of issued against returned credentials supportsReconciliation
ISO 27001 Annex A.7.3.1Termination responsibilities, including which functions perform revocation and by when, shall be defined and communicatedHeader

What it does not cover

  • Contractor Demobilization Record, which covers physical departure from site, equipment and waste, separately from access and accounts.
  • Contractor Final Evaluation, which records performance judgement, not security control.
  • Site Access Authorization, which is the originating grant this record reverses, and is not amended by completing this one.
  • Contractor Worker Register, which this record feeds a status change into, but does not itself maintain.
  • The password or credential reset itself, which is an IT operational task evidenced here, not performed here.

Global

Access Revocation Record requirements by country

Access revocation sits inside information security and physical security obligations that are widely required in substance even where no regulator inspects the specific form.

United Kingdom

UK GDPR Article 32 and ISO 27001 Annex A.9

Appropriate technical and organisational measures include controlling who can access personal data, and a live account for a departed contractor is a control failure under that duty.

A data breach traced to an unrevoked contractor account is assessed against whether revocation was timely, not whether a record exists at all.

United States

State data breach notification laws and sector rules such as the HIPAA Security Rule

Several regimes name termination access controls explicitly; the HIPAA Security Rule requires documented procedures for terminating access when a workforce or business relationship ends.

In regulated sectors, the gap between an engagement ending and revocation being actioned is the fact investigators ask for first.

International

ISO 27001 Annex A.9.2.6 and A.8.1.4

Certification audits examine termination and change of employment as a control, checking evidence of timely revocation and asset return.

An auditor sampling recent leavers will ask for the gap between last day and revocation date, not just whether revocation eventually happened.

How to complete it

How to complete an access revocation record, step by step

The fields record whether access was removed. Whether the removal was fast enough, and complete enough, is a judgement the record has to support rather than make automatically.

Treat Effective Date as a deadline, not a label

Effective Date should be the day access stops, and Time Revoked against each individual should be measured against it. A revocation actioned three days after a suspension's effective date has left three days of live access on a trigger that meant access should not have continued at all.

Card Returned and System Access Revoked are not proxies for each other

A physical card can be handed back while the underlying system account stays active, and a card that opens doors mechanically can remain live while a system account is disabled. Score both, and do not infer one from the other.

Weight the trigger, not just the outcome

A revocation for Work complete and one for Suspension can look identical in the fields, both fully closed, but the suspension trigger should have compressed the timeline to hours, not the standard window. The record should show that urgency, not just a same-day date.

Reconcile the register, not just the individuals

Cards Outstanding against Cards Issued catches what the Individuals section cannot: a card issued to someone who left the crew, was never logged on this record, and was never asked for back. Reconciliation checks that the register itself is complete.

What auditors find

Most common access revocation record findings

These are the findings that recur when revocation is treated as an administrative step rather than a security control.

FindingClauseWhat fixes it
Revocation record completed days or weeks after the engagement actually ended.ISO 27001 Annex A.9.2.6Trigger the record from the same event that ends the engagement, work order closure or contract termination, not from a periodic review.
Card recorded as returned with no corresponding check that system access was also revoked.ISO 27001 Annex A.9.2.1Score card return and system access revocation as separate, both-required fields, not one inferred from the other.
Shared out-of-hours codes left unchanged after a departure.ISO 27001 Annex A.11.1.2Change shared codes on any departure with knowledge of them, regardless of whether that individual's own card was returned.
Cards issued and cards returned are not reconciled; outstanding cards are not deactivated centrally.ISO 27001 Annex A.9.2.5Reconcile Cards Issued against Cards Returned at the register level, and deactivate any outstanding card even if the individual cannot be reached.
Security or reception not notified of the departure, relying on the card system alone to prevent re-entry.ISO 27001 Annex A.7.3.1Notify security and reception as a required step, since a deactivated card does not prevent someone being waved through on recognition.
IT or system accounts left active because the trigger was treated as a site event and never flagged to IT.ISO 27001 Annex A.9.2.6Route every revocation trigger to IT as well as to security, regardless of whether the departure looks like a physical-access-only case.

Case in point

Case in point: the card that outlived the contract

A refrigeration contractor's engagement ended when the work order closed. The engineer's site access card was collected at the gate on his last visit, Card Returned was marked Yes, and the access revocation record was signed off the same week. System Access Revoked, however, was left as Pending, because the card system and the building management system credential were administered by different teams, and the record's author only had visibility of the card system.

Four months later, the same credential, unassigned to any active card but still enabled in the building management system, was used to remotely adjust a chiller setpoint during an unrelated fault investigation, and it took a full day to establish the access had never actually been closed out. The corrective action was to make System Access Revoked a required field with its own owner, IT, distinct from Card Returned, rather than letting one confirmed step stand in for both.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

41fields
4 sections
Reference
CON-031
Archetype
Record
Record ID
AREV-2026-000
Scoring
Complete or not
Direction
High is good
Singleton
No
Basis
ISO 27001 A.9
Links
Links Vendor, Worker
Tags
Contractor, Security
Sections
4
Fields
41
Follow up fields
3
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

12 fields
Text

Record ID*

Generated on save

Auto sequence. Format ARR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Pick List

Contractor*

From FDN-005 Vendor NameFilter: Status is Approved
Text

Vendor ID*

Linked

Format VEN-0000.

Links to FDN-005 Vendor ID

Info

Same Day, Not Next Month

Cards that stay live after a contractor leaves are a security exposure and break your emergency headcount. Revoke on the day, and reconcile what came back.

Single Choice

Revocation Trigger*

Work complete, contract ended, individual removed, suspension, or induction expired.

Work completeContract endedIndividual removedSuspensionInduction expired
Date & Time

Effective Date*

Users

Actioned By*

Individuals

Repeats9 fields
Text

Name*

Text

Card Number

Optional
Single Choice

Card Returned*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

System Access Revoked*

Scored
  • Yes3 pts
  • Pending1 pt
  • No0 pts
Date & Time

Time Revoked

Optional
Single Choice

Removed From Worker Register*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Keys Or Equipment Returned

OptionalScored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

Locker Or Storage Cleared

Optional
YesNot applicableNo
Text

Reason If Card Not Returned

Optional

Wider access

6 fields
Single Choice

Vehicle Access Removed

OptionalScored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

IT Or System Accounts Disabled

OptionalScored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

Site Wifi Or Network Access Removed

OptionalScored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

Out Of Hours Codes Changed

OptionalScored

Shared door codes known to departing contractors need changing, not just deactivating a card.

  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

Security Notified*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Reception Notified*

Scored
  • Yes3 pts
  • No0 pts

Reconciliation

14 fields
Numeric Answer

Cards Issued*

Numeric Answer

Cards Returned*

Scored
Numeric Answer

Cards Outstanding*

Scored
Single Choice

Outstanding Cards Deactivated*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Recharge Applied

Optional
YesWaivedNo
Single Choice

Register Reconciled*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Security*

Signature

Signature*

Users

Contract Owner*

Signature

Second Signature*

CON-031 · record IDs look like AREV-2026-000 · Links Vendor, Worker

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The record is a confirmation. What actually fails is the handoff between the event that ends an engagement and the teams who have to act on it.

KnowContractor

Triggers the access revocation record automatically from a contract end, suspension or worker removal, and keeps the reconciliation against cards issued in one place.

KnowComply

Checks the revocation record against ISO 27001 Annex A.9 evidence requirements ahead of a certification audit, and flags gaps before the auditor samples them.

KnowSafe

Cross-checks Removed From Worker Register against the site's current headcount, so an unrevoked worker cannot be miscounted as present during an emergency evacuation.

Ella
Ella

Watches for the gap between an engagement ending and this record being completed, and escalates same-day rather than at the next periodic review.

This template lives in KnowContractor — contractor management. Prequalification, approval, induction, permits and performance.

Meet KnowContractor→

Glossary

Access Revocation Record definitions and key terms

Revocation trigger
The event that starts the requirement to remove access: work complete, contract ended, an individual removed, suspension, or an expired induction, each carrying a different expected urgency.
Reconciliation
Checking the total cards or credentials issued against what has been returned or deactivated, which surfaces gaps that per-person checklists miss.
Out-of-hours code
A shared access code, distinct from an individually issued card, that must be changed rather than individually revoked when someone who knew it leaves.
System access
Login credentials to IT, network or building management systems, which can remain active independently of whether a physical card has been returned.
Recharge
A cost applied to the contractor for a card or item not returned, used as a practical incentive for return alongside the security requirement to deactivate it regardless.

FAQ

Frequently asked questions about access revocation record

How quickly should access be revoked?+

The same day the engagement ends, and immediately for a suspension or a removed individual. A window measured in days rather than hours treats a security control as an administrative task, and every day of delay is a day the exposure is live rather than theoretical.

Does returning the card mean access is revoked?+

No. A returned card confirms the physical object is back; it says nothing about whether the underlying system account or building management credential was disabled. Both need their own confirmation.

What if a card is not returned?+

Deactivate it centrally regardless, record the reason, and apply a recharge if that is your policy. An outstanding card that has been deactivated is a minor administrative loss; an outstanding card left active is a live security exposure.

Do shared codes need to change every time?+

Yes, whenever someone who knew the code leaves under a trigger that removes trust, contract ended, suspension, individual removed. A code known to a departed contractor is compromised for as long as it stays the same, regardless of what happens to their card.

Who should be notified beyond IT and security?+

Reception, or whoever staffs a manned entry point, since recognition-based entry can bypass a deactivated card entirely. The record treats Security Notified and Reception Notified as separate required fields for that reason.

What does Register Reconciled actually confirm?+

That the count of cards issued against this engagement matches what was returned or accounted for as outstanding and deactivated, closing the record at the register level rather than only at the level of the individuals actually processed.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 27001:2013 Annex A.9.2.1 and A.9.2.6, user registration and removal of access rights
  • ISO 27001:2013 Annex A.8.1.4, A.7.3.1 and A.11.1.2, return of assets, termination responsibilities and physical entry
  • HIPAA Security Rule, termination procedures, 45 CFR 164.308(a)(3)(ii)(C)
  • UK GDPR Article 32, security of processing

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.