Educational guidance on registers and logs — what each records, who maintains it, what it typically contains and how long it is generally kept. Informational only — template examples, not official documents or legal advice; a register documents activity, it does not by itself prove compliance, and employers remain responsible.
What an access control register is
An access control register is the master list of who is allowed where: the access cards, fobs or permissions held, the areas or systems they open, and the dates rights were granted, changed or withdrawn. It underpins both physical and, in some workplaces, system access.
This page is an educational overview with a simplified example. It is not an official template, not jurisdiction-specific and not legal advice — the employer decides who needs access to what and how rights are controlled.
Purpose
- Hold a single record of who has access to which areas or systems.
- Track when rights are granted, changed and removed.
- Make sure access is withdrawn promptly when someone leaves.
- Support security reviews and access audits.
Who maintains it
- A security, facilities or IT lead keeps the register current.
- Managers request access changes for their people.
- Access to the register itself is tightly controlled.
- The employer decides access policy and who owns the register.
When it is used
- When access is granted to a new worker or contractor.
- When someone changes role and needs different access.
- When someone leaves and access must be removed.
- During access audits and after a security concern.
Typical fields
- Person, card or pass identifier and the areas or systems covered.
- Date access granted and by whose authority.
- Any changes to access rights and the reason.
- Date access removed and confirmation it was done.
- Review date and audit notes.
- Example columns only — adapt to your access policy and the applicable law.
Common mistakes
- Leaving access live after someone has left.
- Granting more access than the role needs.
- No record of who authorised an access change.
- Never reviewing who has access to sensitive areas.
Document workflow
An access control register ties the people process to security: it links to the key register for physical keys, the induction and onboarding records when access is first granted, and the leaver process when it is removed. A security concern may trigger a review recorded as a corrective action.
See the related documents below for what is commonly required before and used with an access control entry.
Retention (high level)
Access records hold personal data and are generally kept for as long as access is current and for a period afterwards, in line with the employer’s security and data-protection obligations. This page does not state a required period — confirm with the applicable law and the official authority.
Completing and sharing as a PDF
An access control register is often held in a system and exported to PDF for audits. Exporting to PDF supports the record; it does not make access secure or prove compliance.
Employer checklist
- Grant access on a need-to-have basis and record the authority.
- Remove access promptly when people leave or change role.
- Review access to sensitive areas regularly.
- Protect the personal data the register holds.
Worker notes
- Use only the access you are granted and do not share passes.
- Return passes and report a lost card promptly.
- Tell a manager if you have access you no longer need.
Country considerations
Access-security and data-protection expectations vary by sector and country, with a different official authority in each. This page is general and high-level — not a statement of any country’s law and not legal advice.
Confirm current requirements with the official authority for your country and a qualified professional.
Who is responsible
The employer is responsible for controlling access to its premises and systems, protecting personal data and for compliance. This page is an educational overview with a template example; it does not make access secure or compliant and does not transfer responsibility.
Export, edit and share documents
The documents, policies and templates this involves can be exported, edited, signed, stored and shared as PDFs with the HELPERG PDF Editor.
Free, printable HR & employment resources
Practical, ungated resources to put this into action — no signup.