Knowella

Key and Access Device Register

The recurring failure isn't a lost key, it's a register that never existed to notice it was lost. A leaver hands back a badge but keeps the spare fob from three roles ago, a master key gets cut without anyone updating who holds one, and the annual access review becomes a guess dressed up as an audit because nothing on paper says what any given device actually opens.

KnowOpsRegisterOPS-02635 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27001 cl.7.2
Workspace
KnowOps
Form type
Register
Raised
Once at set-up, then maintained continuously as devices are added, reassigned or retired
Completed by
Security, with sign-off from the site manager

The short version

  • A key and access device register exists because you cannot review physical access without a list of who holds what — an access review run against memory rather than a register is a guess, not an audit.
  • It's a singleton register with a repeating Devices section: one row per key, fob, card, PIN or biometric enrolment, each carrying its own holder, status and review confirmation.
  • The template runs 35 fields across four sections — Header, Devices, Related records, Register health — and scores on devices accounted for, where high is good.
  • It links forward into Access Review and Offboarding, so a leaver's devices and a scheduled review both have a single register to check against, rather than each rebuilding the picture from scratch.

What this is

What is a key and access device register?

What is a key and access device register?

It's the KnowOps register that holds every key, fob, access card, PIN code and biometric enrolment in use across a site, who currently holds each one, and what it opens. It's built against ISO 27001 cl.7.2 and sits inside the Asset and Equipment Control programme, with links out to access review and worker offboarding.

When is the register updated?

Once at set-up to capture what already exists, then continuously afterwards as devices are issued, reassigned or retired. It isn't a periodic count — it's the standing record that a periodic access review is checked against.

What counts as an access device on this register?

Anything that grants physical or system entry on its own: a physical key, a fob, an access card, a PIN code or a biometric enrolment. Device Type covers all five, and each row records what it Opens Or Grants specifically, rather than a generic 'building access' description.

Scope

When is a key and access device register required?

This register holds the current state of every physical and system access device on a site. It isn't the place to log a one-off equipment loan, a stores tool issue, or an asset changing hands between areas.

Use this template when

  • A physical key, fob, access card, PIN code or biometric enrolment is being issued, reassigned or retired and the register needs an entry to reflect it
  • An access review is due and needs a current list of who holds what, rather than being reconstructed from memory or a spreadsheet nobody maintains
  • A worker is leaving and their devices need identifying so they can be recovered as part of offboarding
  • A master or grand-master key's whereabouts need confirming as part of a periodic security check
  • A linked record needs this one to exist: Access Review or Worker Offboarding checking device holders against it

Do not use it for

  • Asset Movement and Transfer, which records an asset moving between areas, sites or owners, with condition at both ends — a physical asset changing custody, not an access device changing hands.
  • Tool Crib Issue and Return, which issues a tool or instrument to a person for a shift or task, not a standing device that grants ongoing access.
  • Equipment Loan Record, which lends equipment to or borrows it from another site, a contractor or a supplier, with terms and condition — a temporary equipment loan, not an access grant.
  • Access Request Record, which raises and approves the request for access in the first place; this register is where the device that request produced gets tracked afterwards.
  • Anything outside KnowOps, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27001 cl.7.2 requirements does this satisfy?

ISO 27001 cl.7.2 sits in Annex A's physical controls, covering physical entry to secure areas. Applied to a key and access device register, that means every device capable of granting entry has to be identified, owned and periodically justified, not just issued once and left.

ClauseRequirementWhere it lands
ISO 27001 Annex A 7.2Physical entry to secure areas is restricted to authorised individuals, and this register is the record of who currently holds that authorisation.Header
ISO 27001 Annex A 5.9An inventory of assets extends to physical and system access devices; each key, fob, card, PIN or biometric enrolment must be identified individually, not held as an aggregate count.Devices
ISO 27001 Annex A 5.18Access rights must be provisioned, reviewed at defined intervals and revoked when no longer justified — the review each device row is put through.Devices
ISO 27001 Annex A 7.9Security of assets off-premises applies to devices carried by workers between sites, home or a vehicle, not only to devices that stay on one site.Devices
ISO 27001 Annex A 5.11Return of assets on a change of employment or contract requires access devices to be physically recovered, not just deactivated on paper while the leaver still holds the item.Register health
ISO 27001 cl.10.2A device unaccounted for, or a lock change required after a suspected loss, is a nonconformity requiring a corrective action reference, not a note for the next review.Register health
ISO 27001 Annex A 5.9Master and grand-master keys represent concentrated access across multiple areas and warrant the same, if not tighter, inventory discipline as any single-area device.Devices

What it does not cover

  • Lock Change Required, which sits at No while a master key from a suspected loss is still unaccounted for.
  • Devices Unaccounted For, which shows a number above zero with Action Required left at No.
  • Held By Leavers, which is non-zero months after the leaver's last working day.
  • Justified By Current Role, which is marked Yes for a holder whose role changed since the last review.
  • Confirmed This Review, which is ticked Yes across every row with no evidence anyone actually checked the drawer.

Global

Key and Access Device Register requirements by country

ISO 27001 is jurisdiction-neutral, but physical access to the areas a key or card opens is exactly what several data protection and security regimes come looking for, and they read this register differently depending on what sits behind the door.

European Union

GDPR Article 32 — security of processing

Requires technical and organisational measures appropriate to risk, explicitly including physical access control

Where a key or card controls entry to an area holding personal data — an HR office, a server room — this register becomes part of the evidence that access to that data was actually restricted, not just policy that said it should be.

United States

HIPAA Security Rule, 45 CFR §164.310 — physical safeguards

Federal requirement for facility access controls where electronic protected health information is held

A covered entity or business associate has to show facility access is limited to authorised individuals, and a register that can't say who currently holds a key to a server room is exactly the gap a HIPAA audit is designed to find.

International

ISO/IEC 27001 Annex A 7.2 — physical entry

Certification-scheme control assessed wherever an organisation holds ISO 27001 certification

An auditor assessing physical entry controls will ask to see the current register, not the policy describing one, which is what makes this record the actual evidence rather than a supporting document.

How to complete it

How to complete a key and access device register, step by step

Most rows are simple Yes/No, but four judgement calls decide whether this register functions as live evidence or a snapshot that's already out of date.

Is 'Opens Or Grants' specific enough to mean anything?

A device row can record Opens Or Grants as vaguely as 'main building' or as specifically as 'server room, rack 4'. Whether the description is precise enough to support an actual access decision, or just precise enough to fill the field, is a judgement the reviewer has to make row by row.

Is 'Justified By Current Role' re-asked, or carried forward unchanged?

Nothing stops Justified By Current Role being copied forward from the last review with a fresh date and no fresh thought. Whether the reviewer is actually re-checking each holder's current role against what the device grants, or simply confirming what was already there, decides whether the review is real.

Does a non-zero Devices Unaccounted For actually block anything?

Devices Unaccounted For is a number, not a gate — the register can show Complete or Closed status with that number sitting above zero. Whether an unaccounted-for device stops the register closing, or is noted and carried into next cycle, is a control decision this template records but doesn't enforce on its own.

Does 'Lock Change Required' lead to an actual re-key?

Marking Lock Change Required as Yes records the decision, but nothing on the register confirms the physical work happened. Whether that Yes is chased through to a completed lock change, or left open across several review cycles, is the difference between a security control and a flagged risk nobody closed.

What auditors find

Most common key and access device register findings

The recurring gaps sit less in what the register asks and more in what happens between one review and the next.

FindingClauseWhat fixes it
Devices Unaccounted For is populated but Action Required stays at No.ISO 27001 cl.10.2Force Action Required to Yes whenever Devices Unaccounted For is above zero, and require a CAPA ID before the register can show Complete.
Held By Leavers never reaches zero because offboarding doesn't feed this register directly.ISO 27001 Annex A 5.11Link the worker offboarding process so a leaver's device rows are flagged automatically the day access is revoked, rather than waiting for the next manual review to notice.
Master Or Grand Master rows are reviewed on the same cycle as an ordinary fob.ISO 27001 Annex A 5.9Set a shorter, mandatory review interval specifically for any row where Master Or Grand Master is Yes.
Restricted Area Access rows carry no additional sign-off beyond the standard Confirmed This Review tick.ISO 27001 Annex A 7.2Require a named second approver — Security or Site Manager — specifically for rows where Restricted Area Access is Yes.
Access Request ID is left blank on newly issued devices with no request to check against.ISO 27001 Annex A 5.18Make Access Request ID required for any device issued after the request process went live, reserving a blank field for legacy devices that predate it.
Lock Change Required sits at Yes across consecutive review cycles with nothing forcing it closed.ISO 27001 cl.10.2Surface any open Lock Change Required row on a standing report until it flips to No or the register shows Complete against a CAPA reference.

Case in point

Case in point: the master key that outlived three role changes

A facilities lead was issued a grand-master key when the site opened, before this register existed in its current form. Over the following three years she moved into a different role, then a different department, and the master key moved with her each time — nobody's job was to ask whether she still needed it, because nobody's job was the register.

It surfaced when a security review finally walked the building looking for every master key in circulation, at which point Justified By Current Role should have caught the gap two role changes earlier. Under this template, that field exists precisely to force the question at every review rather than only when someone happens to go looking — the failure wasn't the key sitting with the wrong person, it was three review cycles that ticked Confirmed This Review without actually asking.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

35fields
4 sections
Reference
OPS-026
Archetype
Register
Record ID
KEY-2026-000
Scoring
Devices accounted for
Direction
High is good
Singleton
Yes
Basis
ISO 27001 cl.7.2
Links
Links Access Review and Offboarding
Tags
Asset, Access, Registry
Sections
4
Fields
35
Follow up fields
3
Repeating sections
1
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

8 fields
Text

Register ID*

Generated on save

Auto sequence. Format KEY-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Last Reviewed*

Users

Maintained By*

Date & Time

Next Review Due*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Info

What Makes An Access Review Possible

You cannot review physical access without a list of who holds what. Most sites have a drawer of unlabelled keys and a memory of who took the last one.

Devices

Repeats12 fields
Text

Device Identifier*

Single Choice

Device Type*

Physical keyFobAccess cardPIN codeBiometric enrolment
Text

Opens Or Grants*

Users

Issued To

Optional
Date & Time

Issued Date

Optional
Single Choice

Status*

Scored
  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Single Choice

Restricted Area Access*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Master Or Grand Master*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Date & Time

Return Due

Optional
Single Choice

Justified By Current Role*

Scored
  • Yes3 pts
  • No longer0 pts
  • Under review1 pt
Single Choice

Confirmed This Review*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Text

Access Request ID

OptionalLinked

Links to OPS-028 Request ID

Related records

1 field
Text

Access Request ID

OptionalLinked

The request that granted this device.

Links to OPS-028 Request ID

Register health

14 fields
Numeric Answer

Devices On Register*

Numeric Answer

Devices Unaccounted For*

Scored
Numeric Answer

Held By Leavers*

Scored
Single Choice

Master Keys Accounted For*

Scored
  • All3 pts
  • Most1 pt
  • No0 pts
Single Choice

Lock Change Required*

Scored
  • Yes0 pts
  • No2 pts
  • N/Aexcluded from denominator
Text

Access Review ID

OptionalLinked

Links to SAF-147 Review ID

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Security*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

OPS-026 · record IDs look like KEY-2026-000 · Links Access Review and Offboarding

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The register is easy to keep accurate at the moment a device is issued; the discipline that actually matters is whether it's still accurate months later, when a role has changed or someone has left.

KnowOps

Holds the device register against the Asset Register, tracks review dates across every device, and keeps master keys and unaccounted-for items visible until they're closed out.

KnowComply

Treats the register as certification evidence for physical entry controls, surfacing gaps — an unreviewed master key, an unaccounted-for device — before an ISO 27001 audit finds them first.

KnowContractor

Flags devices issued to contractor personnel against their engagement end date, so a contractor's access doesn't quietly outlast the contract.

Ella
Ella

Coordinates offboarding and access reviews against the same register, rolls overdue confirmations into one view, and holds every write for your approval before it touches a record.

This template lives in KnowOps — frontline execution. Shift handover, production control, daily management, worker lifecycle and improvement.

Meet KnowOps→

Glossary

Key and Access Device Register definitions and key terms

Physical entry control
A security control — a lock, card reader or biometric reader — that restricts entry to a defined area to individuals authorised to be there.
Master key / grand-master key
A key or credential that opens multiple locks across an area or site, representing concentrated access that a single lost or miscopied item can compromise broadly.
Access review
A periodic check confirming that everyone holding access still needs it for their current role, run against a register rather than reconstructed from memory.
CAPA
Corrective and Preventive Action — the reference raised against a nonconformity, such as an unaccounted-for device, to track it through to close-out.
Offboarding
The process of removing a leaver's access and recovering their equipment, which depends on the register to identify what devices they actually hold.

FAQ

Frequently asked questions about key and access device register

What is the Key and Access Device Register template based on?+

It's built against ISO 27001 cl.7.2, physical entry, an Annex A control requiring entry to secure areas to be restricted to authorised individuals. ISO 27001 is the international standard for information security management systems, and physical access control is treated as part of protecting information, not a separate concern.

What sections does the template contain?+

Four sections: Header, Devices, Related records and Register health. Devices repeats for every key, fob, card, PIN or biometric enrolment in circulation, all rolled up into the health metrics and sign-off in Register health.

Who completes the register?+

Security maintains it continuously, with sign-off from the site manager. Individual device rows may be updated by whoever issues or recovers a device, but Security owns the register as a whole.

How does this connect to worker offboarding?+

Held By Leavers and the Access Request ID link give the register a direct line into who's left and what request originally granted a device, so offboarding can check recovery against an actual list rather than asking around.

How is the register scored?+

Scoring is devices accounted for, where high is good. The scored fields cluster around whether each device's access is still justified, whether the review actually happened, and whether master keys and unaccounted-for devices are closed out.

Can the template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the links to Access Review and Offboarding carry over. Most teams install it as it is, run it for a cycle, then tighten the review interval for higher-risk devices.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27001:2022 Annex A 7.2 — Physical entry
  • ISO/IEC 27001:2022 Annex A 5.11 — Return of assets
  • ISO/IEC 27001:2022 cl.10.2 — Nonconformity and corrective action
  • GDPR Article 32 — Security of processing
  • HIPAA Security Rule, 45 CFR §164.310 — Physical safeguards

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.