Key Control Policy – What It Is and How to Write One (Checklist)
July 17, 2026 · 5 min read
A key control policy is a short written document that defines who may hold which keys, how keys are issued and returned, what happens when one is lost, and how often you audit. It turns key management from tribal knowledge into rules that survive staff turnover — and it's the document insurers, landlords, and auditors ask for by name.
Most key control policies fail the same way: they're ten pages long, written once for a compliance review, and never followed. This guide gives you the opposite — the minimum set of rules that actually get enforced, with a checklist at the end you can adapt in an hour.
Why you need one written down
Unwritten key rules work until exactly one of these happens:
- The person who "just knows" how keys work leaves the company
- A contractor loses a master key and you discover nobody agreed whose problem that is
- Your insurer asks for your key control procedures after a break-in, and you have nothing to show
- Two managers hand out the same restricted key under two different sets of assumptions
A written policy costs an afternoon. Each of the above costs far more. And the policy only needs to answer five questions.
The five sections of a key control policy
1. Key classification and register
Define your key classes — a simple three-tier scheme covers almost everyone:
- Restricted (masters, server rooms, safes): named individuals only, manager sign-off per checkout, always rekeyed if lost
- Standard (offices, storerooms): any authorized employee, logged checkout
- Low-risk (cabinets, lockers, shared-space keys): logged checkout, relaxed chasing
State that a register of all keys exists and who maintains it. If you don't have a register yet, build it first — our guide to keeping track of company keys covers this step by step.
2. Authorization: who may hold what
One table: key class down the side, holder type across the top (employee, manager, contractor, temp), and yes/no/with-approval in the cells. This is the section that prevents the "someone gave the cleaner a master key" conversation, because the answer is written down before anyone is embarrassed by it.
Contractors get their own line item: every external checkout is issued to a named individual (never "the electricians"), tied to their company, with a defined return date. External holders are statistically your highest-risk category and your policy should treat them that way.
3. Issue and return procedure
Keep it to a paragraph: every key transfer goes through the checkout point and is logged — key, named holder, date out, due date, date returned. No person-to-person handoffs; keys return to the checkout point between holders. No due date, no checkout.
Whether the log is a sign-out sheet or key management software doesn't change the policy — it changes how much of the policy enforces itself. Software makes the log unskippable, flags overdue keys automatically, and keeps the permanent per-key history section 5 depends on.
4. Overdue and lost key procedure
Define the escalation ladder now, calmly, rather than during an incident:
- Overdue: reminder to the holder within one working day of the due date
- Persistently overdue (e.g. 5 working days): escalation to the holder's manager or the vendor contact
- Declared lost (e.g. 10 working days or holder confirms): trigger the lost-key assessment
The lost-key assessment answers two questions: what does this key open, and who has held it (this is where per-key history earns its keep). Then apply the rule you pre-agreed: restricted keys → rekey affected locks, always, no debate; standard keys → risk decision by the responsible manager, documented; low-risk → replace and note.
Pre-agreeing "restricted = automatic rekey" is the single most valuable sentence in the policy. It removes the temptation to gamble on a master key "probably turning up."
5. Audits
Twice yearly (quarterly for restricted keys): physically reconcile keys against the register, confirm every outstanding key with its named holder, resolve every discrepancy through the lost-key procedure. Name the role responsible for running audits — unowned audits don't happen.
Key control policy checklist
Copy this list; when every box is ticked, you have a working policy:
- Key register exists and has an owner
- Keys classified (restricted / standard / low-risk)
- Authorization table: who may hold which class
- Contractor rule: named individuals, company recorded, due date mandatory
- Single checkout point; all transfers logged with due dates
- No person-to-person handoffs
- Overdue ladder defined (reminder → escalate → declared lost) with day counts
- Lost-key rule per class; restricted = automatic rekey
- Audit schedule with a named responsible role
- Policy stored where holders can read it; new holders acknowledge it once
Enforcing it without becoming the key police
A policy on paper plus a log that depends on goodwill still leaks. The practical fix is making compliance the path of least resistance: checkout takes seconds, due dates are required fields rather than habits, overdue keys flag themselves, and reminders go out with one click instead of a hallway confrontation. That's the gap key tracking software closes — the policy stays yours; the nagging gets automated.
Frequently asked questions
What is a key control policy?
A short written document defining key classes, who may hold each class, how checkouts and returns are logged, the procedure for overdue and lost keys, and the audit schedule. It's the standard evidence of "auditable key control" that insurers and landlords request.
Who should own key control?
One named role — typically facilities, office management, or security — owns the register, the checkout point, and the audits. Ownership by "everyone" is how keys get lost.
What should happen when a key is lost?
Identify what the key opens and review its custody history, then apply your pre-agreed rule: restricted keys mean rekeying affected locks automatically; standard keys get a documented risk decision. The decision rule belongs in the policy, agreed before any key is actually lost.
How often should keys be audited?
Twice a year as a baseline: physically count keys, confirm outstanding keys with their holders, reconcile against the register. Move to quarterly if you hold restricted keys or have high contractor turnover.
Policy written? Give it a system that enforces itself. Try guardable free — every checkout logged with a due date, overdue keys flagged automatically, permanent history per key. 50 items, 100 orders, no credit card.