What this is
What is a key and access device register?
What is a key and access device register?
It's the KnowOps register that holds every key, fob, access card, PIN code and biometric enrolment in use across a site, who currently holds each one, and what it opens. It's built against ISO 27001 cl.7.2 and sits inside the Asset and Equipment Control programme, with links out to access review and worker offboarding.
When is the register updated?
Once at set-up to capture what already exists, then continuously afterwards as devices are issued, reassigned or retired. It isn't a periodic count — it's the standing record that a periodic access review is checked against.
What counts as an access device on this register?
Anything that grants physical or system entry on its own: a physical key, a fob, an access card, a PIN code or a biometric enrolment. Device Type covers all five, and each row records what it Opens Or Grants specifically, rather than a generic 'building access' description.
Scope
When is a key and access device register required?
This register holds the current state of every physical and system access device on a site. It isn't the place to log a one-off equipment loan, a stores tool issue, or an asset changing hands between areas.
Use this template when
- A physical key, fob, access card, PIN code or biometric enrolment is being issued, reassigned or retired and the register needs an entry to reflect it
- An access review is due and needs a current list of who holds what, rather than being reconstructed from memory or a spreadsheet nobody maintains
- A worker is leaving and their devices need identifying so they can be recovered as part of offboarding
- A master or grand-master key's whereabouts need confirming as part of a periodic security check
- A linked record needs this one to exist: Access Review or Worker Offboarding checking device holders against it
Do not use it for
- Asset Movement and Transfer, which records an asset moving between areas, sites or owners, with condition at both ends — a physical asset changing custody, not an access device changing hands.
- Tool Crib Issue and Return, which issues a tool or instrument to a person for a shift or task, not a standing device that grants ongoing access.
- Equipment Loan Record, which lends equipment to or borrows it from another site, a contractor or a supplier, with terms and condition — a temporary equipment loan, not an access grant.
- Access Request Record, which raises and approves the request for access in the first place; this register is where the device that request produced gets tracked afterwards.
- Anything outside KnowOps, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27001 cl.7.2 requirements does this satisfy?
ISO 27001 cl.7.2 sits in Annex A's physical controls, covering physical entry to secure areas. Applied to a key and access device register, that means every device capable of granting entry has to be identified, owned and periodically justified, not just issued once and left.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27001 Annex A 7.2 | Physical entry to secure areas is restricted to authorised individuals, and this register is the record of who currently holds that authorisation. | Header |
| ISO 27001 Annex A 5.9 | An inventory of assets extends to physical and system access devices; each key, fob, card, PIN or biometric enrolment must be identified individually, not held as an aggregate count. | Devices |
| ISO 27001 Annex A 5.18 | Access rights must be provisioned, reviewed at defined intervals and revoked when no longer justified — the review each device row is put through. | Devices |
| ISO 27001 Annex A 7.9 | Security of assets off-premises applies to devices carried by workers between sites, home or a vehicle, not only to devices that stay on one site. | Devices |
| ISO 27001 Annex A 5.11 | Return of assets on a change of employment or contract requires access devices to be physically recovered, not just deactivated on paper while the leaver still holds the item. | Register health |
| ISO 27001 cl.10.2 | A device unaccounted for, or a lock change required after a suspected loss, is a nonconformity requiring a corrective action reference, not a note for the next review. | Register health |
| ISO 27001 Annex A 5.9 | Master and grand-master keys represent concentrated access across multiple areas and warrant the same, if not tighter, inventory discipline as any single-area device. | Devices |
What it does not cover
- Lock Change Required, which sits at No while a master key from a suspected loss is still unaccounted for.
- Devices Unaccounted For, which shows a number above zero with Action Required left at No.
- Held By Leavers, which is non-zero months after the leaver's last working day.
- Justified By Current Role, which is marked Yes for a holder whose role changed since the last review.
- Confirmed This Review, which is ticked Yes across every row with no evidence anyone actually checked the drawer.
Global
Key and Access Device Register requirements by country
ISO 27001 is jurisdiction-neutral, but physical access to the areas a key or card opens is exactly what several data protection and security regimes come looking for, and they read this register differently depending on what sits behind the door.
GDPR Article 32 — security of processing
Requires technical and organisational measures appropriate to risk, explicitly including physical access control
Where a key or card controls entry to an area holding personal data — an HR office, a server room — this register becomes part of the evidence that access to that data was actually restricted, not just policy that said it should be.
HIPAA Security Rule, 45 CFR §164.310 — physical safeguards
Federal requirement for facility access controls where electronic protected health information is held
A covered entity or business associate has to show facility access is limited to authorised individuals, and a register that can't say who currently holds a key to a server room is exactly the gap a HIPAA audit is designed to find.
ISO/IEC 27001 Annex A 7.2 — physical entry
Certification-scheme control assessed wherever an organisation holds ISO 27001 certification
An auditor assessing physical entry controls will ask to see the current register, not the policy describing one, which is what makes this record the actual evidence rather than a supporting document.
How to complete it
How to complete a key and access device register, step by step
Most rows are simple Yes/No, but four judgement calls decide whether this register functions as live evidence or a snapshot that's already out of date.
A device row can record Opens Or Grants as vaguely as 'main building' or as specifically as 'server room, rack 4'. Whether the description is precise enough to support an actual access decision, or just precise enough to fill the field, is a judgement the reviewer has to make row by row.
Nothing stops Justified By Current Role being copied forward from the last review with a fresh date and no fresh thought. Whether the reviewer is actually re-checking each holder's current role against what the device grants, or simply confirming what was already there, decides whether the review is real.
Devices Unaccounted For is a number, not a gate — the register can show Complete or Closed status with that number sitting above zero. Whether an unaccounted-for device stops the register closing, or is noted and carried into next cycle, is a control decision this template records but doesn't enforce on its own.
Marking Lock Change Required as Yes records the decision, but nothing on the register confirms the physical work happened. Whether that Yes is chased through to a completed lock change, or left open across several review cycles, is the difference between a security control and a flagged risk nobody closed.
What auditors find
Most common key and access device register findings
The recurring gaps sit less in what the register asks and more in what happens between one review and the next.
| Finding | Clause | What fixes it |
|---|---|---|
| Devices Unaccounted For is populated but Action Required stays at No. | ISO 27001 cl.10.2 | Force Action Required to Yes whenever Devices Unaccounted For is above zero, and require a CAPA ID before the register can show Complete. |
| Held By Leavers never reaches zero because offboarding doesn't feed this register directly. | ISO 27001 Annex A 5.11 | Link the worker offboarding process so a leaver's device rows are flagged automatically the day access is revoked, rather than waiting for the next manual review to notice. |
| Master Or Grand Master rows are reviewed on the same cycle as an ordinary fob. | ISO 27001 Annex A 5.9 | Set a shorter, mandatory review interval specifically for any row where Master Or Grand Master is Yes. |
| Restricted Area Access rows carry no additional sign-off beyond the standard Confirmed This Review tick. | ISO 27001 Annex A 7.2 | Require a named second approver — Security or Site Manager — specifically for rows where Restricted Area Access is Yes. |
| Access Request ID is left blank on newly issued devices with no request to check against. | ISO 27001 Annex A 5.18 | Make Access Request ID required for any device issued after the request process went live, reserving a blank field for legacy devices that predate it. |
| Lock Change Required sits at Yes across consecutive review cycles with nothing forcing it closed. | ISO 27001 cl.10.2 | Surface any open Lock Change Required row on a standing report until it flips to No or the register shows Complete against a CAPA reference. |
Case in point
Case in point: the master key that outlived three role changes
A facilities lead was issued a grand-master key when the site opened, before this register existed in its current form. Over the following three years she moved into a different role, then a different department, and the master key moved with her each time — nobody's job was to ask whether she still needed it, because nobody's job was the register.
It surfaced when a security review finally walked the building looking for every master key in circulation, at which point Justified By Current Role should have caught the gap two role changes earlier. Under this template, that field exists precisely to force the question at every review rather than only when someone happens to go looking — the failure wasn't the key sitting with the wrong person, it was three review cycles that ticked Confirmed This Review without actually asking.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- OPS-026
- Archetype
- Register
- Record ID
- KEY-2026-000
- Scoring
- Devices accounted for
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 27001 cl.7.2
- Links
- Links Access Review and Offboarding
- Tags
- Asset, Access, Registry
- Sections
- 4
- Fields
- 35
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 4
Header
8 fieldsRegister ID*
Auto sequence. Format KEY-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Last Reviewed*
Maintained By*
Next Review Due*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
What Makes An Access Review Possible
You cannot review physical access without a list of who holds what. Most sites have a drawer of unlabelled keys and a memory of who took the last one.
Devices
Repeats12 fieldsDevice Identifier*
Device Type*
Opens Or Grants*
Issued To
Issued Date
Status*
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Restricted Area Access*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Master Or Grand Master*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Return Due
Justified By Current Role*
- Yes3 pts
- No longer0 pts
- Under review1 pt
Confirmed This Review*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Access Request ID
Links to OPS-028 Request ID
Related records
1 fieldAccess Request ID
The request that granted this device.
Links to OPS-028 Request ID
Register health
14 fieldsDevices On Register*
Devices Unaccounted For*
Held By Leavers*
Master Keys Accounted For*
- All3 pts
- Most1 pt
- No0 pts
Lock Change Required*
- Yes0 pts
- No2 pts
- N/Aexcluded from denominator
Access Review ID
Links to SAF-147 Review ID
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Security*
Signature*
Site Manager*
Second Signature*
OPS-026 · record IDs look like KEY-2026-000 · Links Access Review and Offboarding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The register is easy to keep accurate at the moment a device is issued; the discipline that actually matters is whether it's still accurate months later, when a role has changed or someone has left.
Holds the device register against the Asset Register, tracks review dates across every device, and keeps master keys and unaccounted-for items visible until they're closed out.
Treats the register as certification evidence for physical entry controls, surfacing gaps — an unreviewed master key, an unaccounted-for device — before an ISO 27001 audit finds them first.
Flags devices issued to contractor personnel against their engagement end date, so a contractor's access doesn't quietly outlast the contract.

Coordinates offboarding and access reviews against the same register, rolls overdue confirmations into one view, and holds every write for your approval before it touches a record.
This template lives in KnowOps — frontline execution. Shift handover, production control, daily management, worker lifecycle and improvement.
Meet KnowOps→Glossary
Key and Access Device Register definitions and key terms
- Physical entry control
- A security control — a lock, card reader or biometric reader — that restricts entry to a defined area to individuals authorised to be there.
- Master key / grand-master key
- A key or credential that opens multiple locks across an area or site, representing concentrated access that a single lost or miscopied item can compromise broadly.
- Access review
- A periodic check confirming that everyone holding access still needs it for their current role, run against a register rather than reconstructed from memory.
- CAPA
- Corrective and Preventive Action — the reference raised against a nonconformity, such as an unaccounted-for device, to track it through to close-out.
- Offboarding
- The process of removing a leaver's access and recovering their equipment, which depends on the register to identify what devices they actually hold.
FAQ
Frequently asked questions about key and access device register
What is the Key and Access Device Register template based on?+
It's built against ISO 27001 cl.7.2, physical entry, an Annex A control requiring entry to secure areas to be restricted to authorised individuals. ISO 27001 is the international standard for information security management systems, and physical access control is treated as part of protecting information, not a separate concern.
What sections does the template contain?+
Four sections: Header, Devices, Related records and Register health. Devices repeats for every key, fob, card, PIN or biometric enrolment in circulation, all rolled up into the health metrics and sign-off in Register health.
Who completes the register?+
Security maintains it continuously, with sign-off from the site manager. Individual device rows may be updated by whoever issues or recovers a device, but Security owns the register as a whole.
How does this connect to worker offboarding?+
Held By Leavers and the Access Request ID link give the register a direct line into who's left and what request originally granted a device, so offboarding can check recovery against an actual list rather than asking around.
How is the register scored?+
Scoring is devices accounted for, where high is good. The scored fields cluster around whether each device's access is still justified, whether the review actually happened, and whether master keys and unaccounted-for devices are closed out.
Can the template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to Access Review and Offboarding carry over. Most teams install it as it is, run it for a cycle, then tighten the review interval for higher-risk devices.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Asset and Equipment Control
Assets that keep their maintenance and inspection history when they move.
Site Access and Facilities
Access that expires on its own, and a visitor log the warden can carry.
Worker Onboarding and Offboarding
Nobody starting unprepared, and nobody leaving with access they still hold.
Used together in Asset and Equipment Control
Asset Register
Holds every piece of equipment, machine, vehicle and tool you track
Tool and Equipment Register
Holds portable tools, gauges, lifting accessories and small equipment that sit below asset level but still need control
Asset Movement and Transfer
Records an asset moving between areas, sites or owners, with condition at both ends
Tool Crib Issue and Return
Issues a tool or instrument to a person and records its return and condition
Equipment Loan Record
Lends equipment to or borrows it from another site, a contractor or a supplier, with terms and condition
Temporary Equipment Approval
Approves equipment brought onto site temporarily, covering inspection, electrical safety, suitability and how long it may stay
More in Equipment Movement
Asset Movement and Transfer
Records an asset moving between areas, sites or owners, with condition at both ends
Tool Crib Issue and Return
Issues a tool or instrument to a person and records its return and condition
Equipment Loan Record
Lends equipment to or borrows it from another site, a contractor or a supplier, with terms and condition
Temporary Equipment Approval
Approves equipment brought onto site temporarily, covering inspection, electrical safety, suitability and how long it may stay

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27001:2022 Annex A 7.2 — Physical entry
- ISO/IEC 27001:2022 Annex A 5.11 — Return of assets
- ISO/IEC 27001:2022 cl.10.2 — Nonconformity and corrective action
- GDPR Article 32 — Security of processing
- HIPAA Security Rule, 45 CFR §164.310 — Physical safeguards
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.