top of page
solomons-facilities-management-logo.jpg

How to Lock Keys Safely in Facilities Management

Writer: Solomons FM
Solomons FM
Sep 8
9 min read

At 9.45pm, a contractor is waiting outside a London office while the outgoing guard searches a drawer for the alarm key. The key eventually turns up beside an unlabeled bunch for the neighbouring building. Nobody can say who last took it, whether the alarm code is still valid, or whether the night team has logged the handover. The premises may be locked, but the process isn't secure.


That's the practical reality behind how to lock keys safely in facilities management. A key safe or cabinet matters, but it's only one part of the control. The stronger system numbers each key set, restricts access, records every movement, separates spares, and makes one person accountable for checking the return.


London sites face this problem across offices, residential blocks, retail units and event venues. A simple lock-up can become a chain-of-custody failure when several contractors, reception teams, mobile patrols and out-of-hours responders use the same keys. The sections below focus on the controls that hold up during a night shift, an incident review or an insurance query.


Table of Contents



Why Key Control Matters More Than the Lock Itself


A strong cabinet can't tell you who removed a key at the end of a shift. It can't explain why the set came back with a missing fob, or whether a temporary contractor still knows the code. Those answers come from the operating process around the cabinet.


The historical lesson is surprisingly clear. The formal locking of the Tower of London dates back to the mid-1300s, after Edward III ordered the castle to be locked at sunset and unlocked at sunrise following an incident in December 1340 when he entered unchallenged. In 1826, the Duke of Wellington fixed the ceremony at 10pm, so soldiers stationed at the Tower were inside before the gates were locked, as recorded by Historic Royal Palaces. The important operational shift was from a vague event, sunset, to a defined and repeatable control point.


A modern lock-up needs the same discipline. The supervisor should know which key set is being issued, who has custody, when the transfer happened and whether the receiving person accepted responsibility. If an alarm activates overnight, the responder must be able to identify the correct set without relying on memory or a drawer label written in fading marker pen.


Practical rule: A better box protects keys at rest. A documented process protects every movement before and after storage.

For facilities managers, the exposure isn't limited to theft. Unauthorised access, missed lock checks, undocumented contractor access and unclear responsibility can all complicate incident handling, insurer discussions and compliance reviews. The answer isn't always expensive technology. Often, the most useful improvement is a disciplined register, witnessed handovers and a clear rule that no key returns to storage until someone verifies it.


What Secure Key Storage Actually Requires


Secure storage starts with restricted custody, not with the cabinet specification. Keys should stay in a restricted secure facility, such as a controlled response centre or a properly managed key cabinet, with access limited to authorised personnel. A staff drawer, reception cupboard or shared office safe doesn't become controlled storage because it has a lock.


BS 7984-1:2016 provides recommendations for keyholding and response services, including the management and control of keys and associated records. NSI guidance on the standard states that where keys remain unclaimed after a contract ends, they should be securely disposed of after one month, with a record of the disposal method retained for seven years.


Build the register before choosing the box


Create a register that identifies the key set, the site or doors it operates, its storage position and its current status. Number the complete set, not just the most obvious front-door key. Include access fobs, alarm keys, plant-room keys and any device that gives practical entry to the premises.


The register should show:


  • Unique identification: Give every set and spare a number that can be read quickly during an out-of-hours call.

  • Controlled access: Maintain an authorised access list and remove leavers or temporary users promptly.

  • Recorded movement: Record sign-out and sign-in with the user, date, time and receiving or witnessing person.

  • Separate spares: Keep spare keys apart from the working set, with access limited to a very small number of senior or authorised staff. This reflects wider good-practice principles around restricted key access, including those set out in Home Office security guidance.


The register can be paper or digital. What matters is that the record is available for review and that staff use it consistently. A cabinet with no movement log gives you storage, but not accountability.


Teams managing several buildings should also link the key number to the site name and alarm instructions. That prevents a common night-shift error, where a responder takes a familiar-looking set that belongs to another property. For broader entry governance, the same control should sit alongside the site's access control systems, rather than operating as an isolated key cupboard.


How to Lock Keys and Manage Handovers Reliably


A reliable lock-up is a sequence, not a final turn of a key in a cylinder. Each stage should leave a record that the next person can understand without calling the previous shift.


Start with identification and issue


Assign every working set a unique identifier before it enters service. Mark the set in a way that remains legible but doesn't disclose the doors it opens to anyone who finds it. The register should connect the identifier to the property, the permitted purpose and the storage position.


When a guard, cleaner, engineer or mobile patrol takes custody, record the key number, the person's identity, the date and time, and the reason for issue. The person receiving the key should sign or otherwise confirm acceptance. For higher-risk handovers, have a second member of staff witness the transaction.


Don't leave an issued key on a reception counter while the paperwork catches up. The record should be created at the point of transfer, not reconstructed later from a rota or an email trail.


Return, inspection and lock verification


On return, the receiving staff member should compare the key set against the register description. Check that the expected keys, fobs and tags are present, then record the return time and the name of the person who accepted it. If a seal is used, it should be non-reusable, so a broken or replaced seal becomes visible rather than reused.


The lock-up itself needs a separate verification. A person should confirm that the key has been returned to its designated slot, the cabinet or safe is secured, and the relevant doors, shutters, gates or alarm points have been checked. A mobile patrol can complete this as part of a scheduled visit, but the report still needs to identify the location and the result.


A flowchart showing the four-step procedure for a reliable key handover process including identification, logging, storage, and verification.

Adapt the routine to the building


An office may issue keys to a late engineer who needs plant-room access, then return the set to reception before the building closes. A residential block may need a controlled set for communal doors, a concierge desk and emergency access, with the spare stored separately from the daily set. A retail site may need a closing supervisor to verify shutters, staff entrances and the alarm route before the key is secured.


The locations differ, but the controls remain consistent:


  1. Identify the user: Confirm the person is authorised for that site and task.

  2. Log the issue: Record the key number and handover details before release.

  3. Secure the return: Place the set in its designated storage position immediately after use.

  4. Verify completion: Check the key, storage point and lock-up, then close the record.


Temporary access needs extra care. After a contractor's access ends, remove their permission, recover all issued devices and change any shared code that person could use. An external box or vault shouldn't be introduced casually. Where keyholding is provided as contracted private security work, SSAIB security-services guidance notes that an SIA licence is required when keeping custody of, or controlling access to, any key or similar device used to operate a lock.


Formal key holding services can support authorised callouts, emergency access and documented lock checks where the in-house team can't provide continuous cover.


Choosing Between Physical Storage and Digital Alternatives


The right tool depends on the access pattern, not on how modern the cabinet looks. A single office with a stable facilities team may gain more from a restricted cabinet and a properly maintained register than from an electronic system nobody updates. A multi-site portfolio with frequent contractor changes may need digital issuance records, user permissions and automatic alerts.


Storage Method

Best For

Audit Strength

Key Risk to Manage

Restricted physical cabinet with controlled register

Stable teams and single-site operations

Strong when every movement is recorded and witnessed

Staff bypassing the register

Mechanical key safe

Emergency access where a small authorised group needs entry

Limited unless access and code changes are logged

Shared codes and weak external positioning

External box or vault

Sites requiring authorised out-of-hours access

Depends heavily on access records and customer controls

Exposure to tampering, insurer conditions and uncontrolled users

Electronic key cabinet

Busy sites with frequent issue and return activity

Stronger automated traceability when permissions are maintained

Power, network, override and administrator access

Digital key tracking linked to access control

Multi-site portfolios and contractor-heavy environments

High potential audit strength across users and locations

Poor configuration, stale permissions and incomplete exception handling


Physical storage remains effective when the team treats the register as part of the security equipment. A cabinet slot should have one defined key set, and staff should never substitute a loose bundle because “it's only for tonight”. The cheaper option can be the safer option when it creates less friction and supervisors enforce the routine.


Digital systems earn their place when the volume and turnover make manual records difficult to maintain. Electronic cabinets can restrict individual compartments, record user activity and flag overdue returns. They also introduce new dependencies, including administrator permissions, power, network availability and emergency override procedures. A digital audit trail isn't useful if the system allows shared credentials or if nobody reviews exception reports.


Site context matters too. Reception and visitor processes should align with key issuance, especially in multi-tenant buildings. A coordinated visitor management system can help the team confirm who is authorised to enter, but it doesn't replace the key register or the physical return check.


The strongest setup is the one night staff can follow under pressure and supervisors can audit afterwards.

Common Mistakes That Undermine Key Security and How to Avoid Them


Most failures happen after the team has already bought a secure box. The hardware is present, but staff leave the register blank, store spares beside the working set or allow a temporary contractor to keep the access code indefinitely.


Undocumented handovers create the largest blind spot. If a guard passes a key to a cleaner without a witnessed sign-out, the next shift can't establish custody. Require the transfer to be logged at the moment it happens, with a second person witnessing higher-risk issues.


Ad hoc storage causes misidentification. A key left in a drawer may be physically safe for a short time, but nobody can confirm whether it belongs to the current site or another property. Give every set one numbered position and reject “temporary” storage that has no return deadline.


Reused codes turn temporary convenience into permanent access. Change the code after temporary use, restrict distribution and record who received it. If the box can't support sensible code control, reconsider whether it belongs on the site.


Spares stored with master sets make a single loss more serious. Keep spares separately and limit access to a very small authorised group, reflecting wider security good practice, including principles set out in Home Office security guidance for businesses. The night team should use the working set, not open the spare store for routine access.


A professional hand holding keys with a Documented Handover tag over a checklist and key box.

Unsecured external boxes need a documented risk decision. Obtain customer acknowledgement, consider insurer requirements and restrict access to authorised staff. If a key is missing, don't replace it and carry on. Record the incident, review the access list and assess whether locks, codes or alarm credentials need changing.


Putting Your Key Control Plan Into Practice


Start with a short physical audit at each site. Open the cabinet, identify every set, compare the contents with the register and ask the current shift who can access each storage point. Any unidentified key, missing entry or shared code is a priority issue.


Then apply the controls in order:


  1. Number every working set and spare.

  2. Create one current register for each site or controlled portfolio.

  3. Move keys into restricted storage.

  4. Require witnessed sign-in and sign-out where the risk warrants it.

  5. Separate spares and review access after staff or contractor changes.

  6. Add lock verification to patrol or closing reports.

  7. Review records regularly and investigate exceptions rather than correcting them.


A small team can run this with a secure cabinet and disciplined paperwork. A busy London portfolio may need electronic issuance, mobile patrol support or a contracted keyholding arrangement. The test is simple: can the duty manager identify the key, the last authorised user and the verified return without relying on memory?



Solomon's Facilities Management provides key holding, lock-up support, mobile patrols and documented security reporting for commercial, residential and retail sites across London. If your current setup depends on an open drawer, shared code or informal night-shift handover, visit Solomon's Facilities Management to discuss a controlled process for your buildings.


Comments


290b12_d6b14ae5707b49d1b85231d152625b37~mv2.jpg

SOLOMON'S FACILITIES MANAGEMENT

Get a quote for security guards or FM services in London — free, within 24 hours

SOLOMON'S FACILITIES MANAGEMENT

Social Media Accounts

bottom of page