Key control policy template for security teams
A key control policy template covering master key hierarchy, issuance records, card and code rules, lost-key response, key recovery and audit frequency.

A camera films the entry and an alarm announces it, but neither stops someone walking in with a key that left on a departing supervisor's ring years ago. This key control policy template covers issuing, tracking and recovering every key you own.
Key control is four things: a numbered hierarchy so you know what each key opens, a signed issuance record so you know who holds it, a scheduled audit so you find out before an incident does, and a written trigger for rekeying after a loss or a departure. Copy the tables below into your own policy and change the role names to yours.
Rekeying costs real money and gets deferred for that reason. Decide the trigger in advance, in writing, while nobody is under pressure. A rule written after the key goes missing is a negotiation, not a policy.
Which keys does this cover?
All of them. The gap in most policies is that it covers door keys and quietly ignores the padlock on the gate and the spare van key in the desk drawer.
- All mechanical keys (master, sub-master, individual)
- Electronic access cards and fobs
- Keypad codes and combinations
- Vehicle keys
- Equipment keys (cabinets, safes, machinery)
How should the key hierarchy be structured?
Four levels is enough for almost any site. The rule underneath the table is simple: the higher the key sits, the fewer hands it belongs in, and the shorter the list of people who can approve another copy.
Master Key Hierarchy
| Key Level | Access | Authorized Holders |
|---|---|---|
| Grand Master (GMK) | All locks in system | Security Director, Facility Manager only |
| Master (MK) | All locks in a building/zone | Building managers, security supervisors |
| Sub-Master (SMK) | All locks in a department/floor | Department heads, maintenance leads |
| Change Key (CK) | Individual lock only | Assigned employees, tenants |
High-Security Keys
A restricted or patented keyway means the blank is not on the rack at the hardware store and a duplicate cannot be cut without your authorization. Use them where a copy would be worth making:
- Server rooms and data centers
- Pharmaceutical storage
- Financial and cash handling areas
- Executive offices
- Security office and armory
Some of this is not your choice. For controlled substances, 21 CFR 1301.72 requires that storage areas be accessible to "an absolute minimum number of specifically authorized employees", that key locks carry "key control which limits access to a limited number of employees", and that a combination be limited to a minimum number of employees and be changeable on termination.
If you guard a pharmacy, a hospital dispensary or a cannabis dispensary, write to that standard rather than to this template.
Who is allowed to authorize a key?
Approval authority is the whole control. A key log is a record of decisions someone was entitled to make, and if anyone can make them, the log is just a list.
Authorization Requirements
| Key Type | Authorization Required |
|---|---|
| Grand Master | Executive approval + Security Director |
| Master Key | Security Director or Facility Manager |
| Sub-Master | Department Head + Security approval |
| Individual/Change Key | Supervisor + HR verification |
| Temporary Keys | Security Supervisor (24-hr max without extension) |
Issuance Procedure
- Receive authorized request form
- Verify employee identity and employment status
- Assign specific key by number from inventory
- Record in key log:
- Key number and type
- Employee name and ID
- Date issued
- Areas accessed
- Authorization reference
- Employee signs key receipt acknowledgment
- Provide key care instructions
Key Receipt Acknowledgment
Key Issuance Agreement
I acknowledge receipt of the following key(s):
Key Number(s): _______________
Key Type: _______________
Areas Accessed: _______________
I agree to:
- Keep this key secure and on my person or locked storage at all times
- Never duplicate, loan, or transfer this key to any other person
- Report loss or theft immediately to Security
- Return this key upon termination or when no longer required
- Surrender this key upon request by authorized personnel
I understand that violation of this policy may result in disciplinary action.
Employee Signature: _______________ Date: _______________
Employee Name (Print): _______________ ID #: _______________
Issued By: _______________ Date: _______________
What has to be in the key log?
Eight fields. Any fewer and the audit cannot be completed; any more and nobody fills it in.
Information to Track
| Field | Required |
|---|---|
| Key number (unique identifier) | Yes |
| Key type/level | Yes |
| Lock(s) operated | Yes |
| Assigned to (name, ID, department) | Yes |
| Issue date | Yes |
| Authorized by | Yes |
| Return date | When applicable |
| Status (active, returned, lost, destroyed) | Yes |
Daily Key Control
For keys signed out every shift, patrol keys and gate keys most of all:
- Sign-out log with time and signature
- Sign-in log with time and signature
- Eyes on the ring at handover, counted, not assumed
- A discrepancy report filed the same night if anything is missing
This is the step that quietly stops happening around month four. It shows up as a line item on the post inspection, and the count belongs in the daily activity report so a supervisor sees the night it fails rather than at the annual audit. TeamMap has no key module, but a recurring task can prompt the count and a report with a photo of the ring gives it a timestamp nobody can backdate.
How do cards and codes change the rules?
Electronic credentials are easier to revoke and easier to forget about. A card left active for a departed contractor is invisible in a way a physical key on a hook is not. More on the trade-offs in access control beyond badge readers.
Card/Fob Management
- Each credential has unique identifier in system
- Access levels assigned based on job requirements
- Credentials expire automatically for contractors/temporary employees
- Lost credentials deactivated immediately upon report
- Replacement credentials issued with new number (not reactivated)
Access Code Management
- Shared codes changed quarterly at minimum
- Codes changed the day an employee with access leaves, not at the next scheduled rotation
- No guessable codes: 1234, 0000, the year, the building number
- Codes never written on anything within sight of the keypad
What happens when a key goes missing?
The delay is the damage. Somebody who loses a master at 6pm and reports it at 9am the next morning has handed over an unmonitored night, and the policy has to make reporting cheaper than hiding it. Say plainly that a prompt report is not a disciplinary matter and a concealed one is.
Immediate Actions
- Report to Security immediately (do not wait)
- Complete lost key report with circumstances
- Security assesses risk level
- Notify supervisor and Security Director
Risk Assessment
| Risk Level | Criteria | Action |
|---|---|---|
| High | Master key, known theft, high-security area access | Immediate rekey of affected locks |
| Medium | Sub-master, circumstances unclear | Rekey within 48 hours, increase monitoring |
| Low | Individual key, likely lost (not stolen) | Document, rekey at discretion, monitor |
Lost Key Report
Date/Time Discovered Missing: _______________
Key Number: _______________
Key Type: _______________
Last Known Location: _______________
Circumstances: _______________
Search Conducted: ☐ Yes ☐ No
Reported By: _______________
Action Taken: _______________
Regulated storage has its own clock. A registrant who loses controlled substances must notify the DEA field division in writing within one business day of discovery under 21 CFR 1301.76, with DEA Form 106 to follow. If a lost key is what caused the loss, your internal report is not the only one due.
How do you get the keys back?
Before the last day, not on it. The exit interview is too late to discover that a sub-master went home three weeks ago.
Upon Termination
- HR notifies security of the departure, ideally a day ahead
- Security pulls the person's key list before the exit meeting
- Keys collected and verified one by one against the log
- Employee signs the return acknowledgment
- Log updated with the return date and new status
- Anything not returned goes straight to the rekey assessment above
Do not write "keys returned before final paycheck" into your policy without checking your state first. Federal law does not require the final check immediately, but the Department of Labor points final-pay timing questions to state labor departments, and several states restrict what an employer may hold back or deduct. Ask your state agency, then write the line.
Role Change
- Old role's keys come back before the new role's keys go out
- Access levels rewritten to match the new job, not added to the old set
- Log updated the same day
Access that only ever accumulates is how a maintenance lead ends up opening the cash room. The same drift shows up in badge systems, and it is worth catching on the physical security audit.
How often do you audit?
Frequency follows consequence. A grand master unaccounted for is a building-wide problem, so it gets counted monthly. An individual office key is a lock, so it gets counted once a year.
Audit Schedule
| Key Type | Audit Frequency |
|---|---|
| Grand Master / Master | Monthly |
| Sub-Master | Quarterly |
| Individual keys | Annually |
| Daily-issue keys | Daily (at shift end) |
Audit Process
- Compare the key log to the physical inventory
- Lay eyes on each assigned key, in the hand of the person it is assigned to
- Check cuts against the register for duplicates nobody authorized
- Write down every discrepancy, including the ones with an innocent explanation
- Update the records the same day
- Report the results, discrepancies included, to the security director
Step two is the one people skip. A key ticked off because the holder said they have it is not an audit, and the difference only matters once. If you are building a wider assessment around this, the site security assessment checklist and the visitor management SOP cover the two neighboring controls.
Key Takeaways
- Every key gets a number, a log entry and a named holder. No exceptions for the spare.
- Approval authority is the control. Write down who can say yes to each level.
- Make reporting a lost key cheaper than hiding one, and set the rekey trigger early.
- Collect keys before the exit meeting, and check your state's rules before tying return to pay.
- An audit means seeing the key. Anything else is a phone survey.
Continue Reading

Parking enforcement procedures for security officers
Parking enforcement procedures for security officers: where your authority ends, warnings and citations that survive appeal, tow rules and accessible spaces.

Visitor management SOP template for security teams
A visitor management SOP template covering pre-registration, ID verification, badge rules, escorts and the departure step where most visitor logs fail.

Daily activity report template for security guards
A daily activity report template for security guards: header, patrol log, incident log, maintenance notes, and a full sample DAR you can copy.