top of page
solomons-facilities-management-logo.jpg

Key Control Policy: A Practical Guide for Facilities Teams

Writer: Solomons FM
Solomons FM
4 days ago
12 min read

A contractor leaves a London office on Saturday afternoon and the duty manager discovers that a master key hasn't come back. The contractor's phone goes to voicemail, the register contains a signature but no reliable return time, and nobody can confirm which risers or tenant areas the key opened. By Monday morning, the client is asking whether to rekey the building, notify the insurer, or just hope the key turns up.


That situation exposes the weakness in most key control documents. A cabinet and a spreadsheet don't control access by themselves. A useful key control policy connects authorisation, issue, custody, return, leaver management, contractor oversight, incident response and audit evidence across the whole building.


Table of Contents



Why a Key Control Policy Matters in UK Facilities


In a 12-storey multi-tenant office in Holborn, a missing contractor master key can affect more than the facilities team. It can raise questions about tenant security, lease obligations, insurance conditions, emergency access and the building owner's confidence in the managing agent. The immediate cost may be a locksmith call or a cylinder change, but the operational problem is the absence of a defensible decision trail.


UK guidance treats keys as governed security assets, not casual pieces of hardware.


NPSA guidance recommends tight control over key distribution, accurate issue records, secure storage and a defined contingency process for lost keys, including access to spare cylinders and replacement keys where appropriate.


A working policy must prove four things:


  • Accountability: a named person authorised the issue.

  • Traceability: the record shows who held the key, where it was used and when it was due back.

  • Lifecycle control: HR, contractors, tenants and reception follow connected return and revocation processes.

  • Auditability: the facilities team can demonstrate what happened without relying on memory.


Ownership must be explicit


The facilities manager should normally act as policy custodian, with a named deputy who can authorise routine issues when the custodian is absent. The building manager should approve high-tier access, unusual overrides and rekey decisions. HR must provide leaver information promptly, while security, reception and contract managers must act on the approved access matrix.


Your policy should state who can issue each tier, who can authorise exceptions, who contacts the locksmith, who informs the building owner and who closes the incident. Solomon's key holding services guidance is relevant to this operating model because key custody and out-of-hours response need a defined responsible party, not an informal arrangement between shifts.


Core Elements Every Key Control Policy Must Contain


A policy should be short enough for a duty manager to use during a busy shift, but precise enough to govern a serious incident. Include these elements as essential controls.


  1. Scope and applicability. Name every building, department, tenant area, plant space, riser, event area and key type covered. This prevents cleaning, security and contractor keys from falling outside the process.

  2. Roles and RACI. Identify the security custodian, facilities manager, building manager, HR contact, reception team and contractor manager. A simple RACI should show who is responsible, accountable, consulted and informed for issue, return, audit, loss and rekeying.

  3. Key hierarchy. Define grand master, master, sub-master, restricted duplicate and individual user keys. Access should follow the minimum necessary principle, consistent with UK government identity and access control policy.

  4. Issue and return procedure. Set the identity check, authorisation check, register fields, return deadline, signature requirement and overdue escalation.

  5. Register and logging. Record the key ID, serial or coded reference, holder, authoriser, issue time, return time, purpose and exception notes.

  6. Storage standards. Specify the cabinet, access permissions, spare-key arrangements and dual control for high-risk rings. Collections Trust guidance on securing keys calls for secure retention, separate storage for spare and master keys, limited access and regular audits.

  7. Labelling rules. Prohibit addresses, floor descriptions, tenant names and visible key numbers on tags. Use coded identifiers that only authorised staff can interpret.

  8. Audit and review. Define routine musters, independent checks, register reconciliation and policy version control.

  9. Loss, copying and non-return. State the immediate notification route, cabinet freeze, investigation steps, rekey authority and evidence requirements.

  10. Contractor, tenant and leaver provisions. Make return obligations contractual, link leaver notifications to HR, and define what happens when an occupier refuses to return a key.


For practical storage instructions, use the guidance on locking keys as an operational reference, then adapt the wording to the site's actual locks, leases, fire arrangements and insurance requirements.


Don't copy an American template wholesale. UK buildings may have specific lease conditions, fire-service access arrangements and insurer wording. Your policy must be tested against the building's real access hierarchy and emergency procedures.


Access Levels and Who Holds Which Keys


A key hierarchy must match the building's risk, not just the labels on a cabinet. In a mixed-access building, one person may need office access but not residential, plant-room, or tenant areas.


Tier 1, grand master keys, belong only to named facilities leads and an approved deputy. In a City office, keep the approved sets in restricted storage, record every issue and require a stated business reason. They must not move informally between shifts, contractors or managers.


Tier 2, area master keys, cover a floor, wing, riser or operational zone. A residential block might assign one to the concierge and duty engineer, with controlled handover between shifts. A security supervisor may hold one during a response, but the register must record the transfer and return.


Tier 3, sub-master or suite keys, support FM technicians, cleaning supervisors and building-management subcontractors. The access matrix should grant only the areas required for the task. Contractor terms must prohibit copying, lending and unauthorised off-site retention, with return linked to contract completion and leaver notifications.


Tier 4, individual or suite keys, usually go to occupiers, residents or event clients. At an exhibition venue, reception can issue stand-build keys after identity verification and record their return at the end of the working period. Although the access scope is narrower, unreturned keys still require prompt reconciliation.


Tier

Typical Holders

Storage

Audit Frequency

Tier 1

Named facilities leads and approved deputy

Restricted cabinet with enhanced control

Monthly muster

Tier 2

Duty managers and security supervisors

Controlled key cabinet or secure handover

Monthly muster

Tier 3

FM, cleaning and subcontractor teams

Contract-controlled storage and issue log

Quarterly contractor reconciliation

Tier 4

Occupiers, residents and event clients

Reception or approved local custody

Reconcile against moves, departures and event close


Set access rights against the building's real hierarchy, including emergency overrides and shared areas. The access control systems guidance can help decide where electronic credentials should complement physical keys. Electronic access does not remove control of mechanical keys or cabinet access.


Issuing, Returning and Mustering Keys in Practice


The Monday morning issue desk should operate like a controlled transaction point. The person requesting a key explains the purpose and duration, then the issuing officer verifies identity against the approved access matrix.


Issue procedure


Record the holder's name, date, key ID, serial or coded reference, signature, return-by time and issuing officer. For a contractor or short-term set, use a distinct coded or coloured tag that identifies the custody category without revealing the building address or protected area.


Before release, check for outstanding keys. The issuing officer should confirm the request is within the person's role and that any exception has written approval from the authorised manager. The holder signs for the key and receives the return instruction.


A six-step infographic illustrating the formal procedure for requesting, issuing, returning, and mustering keys in an organization.

Return and close-out


Contractors should return keys the same day unless the contract manager has approved overnight custody. Permanent staff should return keys through the leaver checklist, not by leaving them in a desk drawer or handing them to a colleague. After-hours returns should use an approved secure key-return point; where tamper-evident bags are used, record the holder's identity, time and key reference and place the bag in a secure controlled receptacle.


The receiving officer checks the key for damage, confirms the identifier and marks the transaction returned. A damaged or incomplete set remains an open incident until the facilities manager decides whether the lock or cylinder requires inspection.


Muster standards


A clean muster means the physical count agrees with the register, each high-tier key has a named custodian, overdue items are explained, and exceptions have an incident reference. Count grand master, master, sub-master and user keys separately. Don't combine them into one total that hides a missing high-risk item.


High-volume event sites may use fobs or biometric controls for routine movement, while retaining a controlled process for mechanical overrides and plant access. The technology should support the policy's authorisation and audit trail, not replace them.


Sample Clauses You Can Adapt for Your Policy


The following wording is designed for a UK facilities template. Replace bracketed terms with site-specific details, but don't weaken the controls to make administration easier.


Purpose and scope


“This policy governs the issue, custody, use, return, storage, audit and incident management of all physical keys, restricted duplicates, key rings and associated access credentials used at [site or portfolio]. It applies to employees, contractors, tenants, residents, visitors, event clients and any person authorised to hold or use a key.”

This clause prevents a common loophole, where an event or cleaning set is treated as “temporary” and therefore escapes the register.


Definitions


“A grand master key opens multiple controlled areas across the site. A master key opens a defined floor, wing or operational zone. A sub-master key opens a limited group of suites or rooms. A user key opens an individual room, suite or approved area. A restricted duplicate is a copy produced only with written authorisation from [authorising role].”

Use the site's actual cylinder terminology. If staff use “master” to mean three different things, the policy won't control access.


Issue and signature


“Keys may be issued only by [key custodian or approved deputy] to a person listed on the current access matrix. The recipient must provide approved identification, state the purpose of access, sign the register and accept the stated return deadline. No key may be issued against verbal approval except where the emergency procedure applies and the issuing officer records the approving person and incident reference.”

The final sentence matters. Emergencies need a route, not a blank cheque.


Return and contract end


“The holder must return the key immediately on demand, at the end of the approved task, at the end of the shift, or when employment, tenancy, appointment or contract ends. A contractor must return keys through the designated control point unless written approval permits another method. Non-return must be reported as an access incident.”

Storage and labelling


“Unissued keys must be stored in the approved locked cabinet or key box. Grand master and master sets must be held under the site's enhanced control arrangement, including dual authorisation where specified by the building manager. Tags must use coded identifiers and must not display the building address, tenant name, room description or key number.”

UK physical security standards also address certified cylinder performance and controlled storage. The FIA code of practice for secure information boxes records requirements used in UK security practice, including issue recording and precautions against revealing the protected container.


Prohibited actions and breach response


“A holder must not copy, lend, transfer, photograph, relabel, remove or retain a key off site without written authorisation. Breach may result in immediate withdrawal of access, contract action, disciplinary action, investigation and rekeying where authorised by the building manager.”

Don't remove “lend” because a team wants flexibility. A colleague-to-colleague handover is exactly how the audit trail fails.


Running Key Audits That Actually Find Problems


A missing key incident exposes weak governance long before anyone checks the cabinet. An effective audit tests whether physical holdings still match the register, access matrix, contractor records, HR leaver information and current building arrangements. Treat the audit as a lifecycle check, covering employees who have left, contractors whose work has ended and occupiers sharing controlled areas.


Use different controls for each risk tier:


Key Tier

Recommended Frequency

Method

Escalation Threshold

Tier 1

Monthly

Named-holder confirmation and physical count

Any unexplained gap

Tier 2

Monthly

Cabinet count and shift-log reconciliation

Any missing area master

Tier 3

Quarterly

Contractor-list comparison and sample check

Unapproved or overdue set

Tier 4

At occupier or event close, with routine reconciliation

Return check against moves or close-out list

Any unresolved return


(NPSA) guidance recommends maintaining accurate key issue records, controlling the number of keys issued, carrying out regular key audits and musters, and having a defined contingency process when a key cannot be accounted for. It also recommends planning for replacement locks or cylinders where required.


Audit method


Start with the register and current access matrix, then test the cabinet. Select high-tier keys for a physical count and confirm each named holder, permission and work area. For contractor and short-term sets, use a random sample defined by the policy. Verify the holder, contract, issue date, return status and approved work area.


The auditor must check lifecycle exceptions, not just count hooks. Compare leaver records with active permissions, closed contracts with outstanding sets, temporary access with expiry dates, and mixed-access areas with the permissions granted. Any exception needs an owner and a recorded resolution.


An annual independent audit should be completed by someone outside the issuing team. Review exception approvals, overdue records, lost-key incidents, duplicate authorisations and recent cylinder changes. A cabinet count will not reveal that a former employee remains active in the register.


When the count fails


If records and holdings do not match, secure the affected cabinet or tier and freeze further issues until the discrepancy is explained. Record the missing identifier, last known holder, affected access areas, witness accounts, camera evidence and notifications made. Escalate according to the key's tier and exposure, rather than treating every discrepancy as a routine admin error.


For a portfolio estate, an electronic key management system can provide searchable transactions and permission controls. It still depends on accurate data, clear ownership and physical checks. A bad register in an electronic cabinet remains a bad register.


Lost, Copied and Unreturned Key Procedures


A missing key incident needs a decision tree, not a vague instruction to report the matter to security. The first person receiving the report must know what to do immediately, including outside normal office hours.


The first response


The duty facilities manager records the incident, freezes the relevant register entry and identifies the key's access scope. The team checks the issue point, vehicle, work area, contractor bag, reception desk and handover records. Security preserves relevant incident logs and camera footage. The manager obtains a written account from the holder and any witness.


Assess exposure before waiting for recovery. A lost individual room key may require a controlled replacement. A missing master key can affect several occupiers, so refer it immediately to the building manager, insurer where required and an approved locksmith.


The incident record should capture the key reference, last confirmed holder, access areas, time reported, checks completed and decisions made. That record gives the next shift clear instructions and prevents an out-of-hours report from becoming an undocumented handover.


Rekeying and copying decisions


The policy must name who can approve a cylinder change, restricted keyway swap or emergency override. Do not apply one universal threshold. Assess the key tier, protected areas, evidence of unauthorised duplication, recovery prospects and the requirements of the building owner or insurer.


If a duplicate is suspected, quarantine the relevant set and ask an approved locksmith to inspect the key profile, cut quality and authorisation history. A contractor hand-back that reveals an unrecorded copy is a control breach, even if no unauthorised entry has been proven. Record the suspected source, affected contractor or employee, and any access that must be suspended.


Where UK guidance refers to contingency planning, spare cylinders and immediate supply, the practical instruction is clear: maintain response capability before an incident occurs. The policy should name the locksmith, emergency contact, approving manager and documentation route. Store those details where duty staff can access them without relying on the missing key register entry.


Leavers and overdue returns


HR must notify FM when employment ends or access changes. The leaver checklist records the key reference, return status, badge or fob status and approving officer. Contractors return keys the same day unless an authorised exception exists. Write the permanent staff return deadline into the policy and enforce it through the exit process.


NPSA guidance recommends a formal exit process for employees and contractors, including the return of company assets such as keys and the removal of physical access rights. Facilities teams should therefore reconcile HR leaver notifications with active key holders and record any outstanding keys until they have been returned or the associated access risk has been resolved.


Close the incident only when the key is recovered, the cylinder is changed, or the building manager formally accepts the residual risk. Keep the report, register history, approvals, notifications and locksmith record together for audit defence.


Implementation Checklist and Frequently Asked Questions


Start with control, not technology. During the first week, appoint the person who owns the cabinet and the person who covers absence. Then create the access tiers, audit the current inventory, configure the register, brief reception and security, and connect the return process to HR and contractor management.


Week-one checklist


  • Assign custody: Name the key controller, deputy and high-tier approver.

  • Define access: Categorise grand master, master, sub-master and user keys.

  • Secure storage: Source a suitable secure key cabinet or approved key box.

  • Build the register: Record identifiers, holders, approvals, issue times and returns.

  • Brief the front line: Train reception, security, cleaning supervisors and duty managers.

  • Set audits: Put musters and independent checks into the site calendar.

  • Connect leavers: Make HR notification and key return part of the exit workflow.


Questions clients ask after rollout


Who signs when the key controller is absent? The named deputy signs within the authority defined in the RACI. High-tier exceptions still go to the building manager.


What if a tenant refuses to return a key? Record the refusal, notify the property manager, apply the lease or licence process, and assess whether the affected cylinder should be changed.


What evidence might an insurer ask for after a loss? Keep the register entry, access approval, incident report, witness accounts, audit history, notifications, locksmith advice and rekey decision together.


Does an electronic cabinet replace the policy? No. It records transactions and can enforce permissions, but the policy still defines roles, exceptions, contractor duties and incident response.


How often should a site audit? Match the cadence to the access risk. High-tier keys need tighter checks than routine suite keys, and multi-tenant buildings need stronger reconciliation than a small single-occupier site.


If you only do three things, appoint one accountable custodian, reconcile every high-tier key, and write the lost-key decision process before the next incident.



Solomon's Facilities Management can support London sites with key holding, controlled access, reception and concierge coverage, security personnel, incident logging and out-of-hours escalation.


Speak with Solomon's Facilities Management to review your current key control policy and turn it into a working access governance process.


Comments


290b12_d6b14ae5707b49d1b85231d152625b37~mv2.jpg

SOLOMON'S FACILITIES MANAGEMENT

Get a quote for security guards or FM services in London — free, within 24 hours

SOLOMON'S FACILITIES MANAGEMENT

Social Media Accounts

bottom of page