An access control system can produce a perfect event log and still fail to control access.

A door may open for the wrong person, a former contractor may retain a valid credential, or a member of staff may make a well meant exception without understanding the consequence.

That is why a guide to access control assurance must begin with operational reality, not the access control panel.

Assurance is the disciplined process of establishing whether access controls work as intended, in the conditions in which people actually work. It is not a one-off inspection of readers, locks and cards. It tests whether technology, procedures, ownership and human behaviour combine to protect people, assets and operations.

For organisations preparing for higher protective security expectations, including those considering Martyn’s Law duties, this distinction matters. A policy can say access is restricted.

Assurance establishes whether it is restricted when the building is busy, a delivery is late, a manager is unavailable and staff are under pressure.

What access control assurance should prove

The purpose is not to prove that a system has been installed.

It is to answer a harder question: can the organisation reliably decide who should enter, where, when and under what authority?

That requires evidence across three connected areas. The first is the physical and technical control itself. Are entrances, barriers, credentials, alarms and supporting systems operating as designed? The second is process. Is access approved, changed and withdrawn through a controlled route, with clear responsibility? The third is behaviour.

Do staff, contractors and managers understand the rules, recognise exceptions and act appropriately when something does not look right?

Most weaknesses sit between these areas. A system may be technically sound, but access rights may not be removed promptly when roles change. A visitor procedure may be clear, but a receptionist may feel unable to challenge a senior person’s instruction.

A perimeter may be controlled during standard hours, while a change in cleaning, maintenance or delivery arrangements creates unmanaged access outside them.

The uncomfortable point is that access control is often treated as an equipment issue because equipment is visible and easy to procure.

The real control is the quality of the decisions around it.

Start with consequences, not equipment

Before reviewing devices or records, establish what unauthorised access would mean in each part of the operation. A public reception, a staff welfare area, a server room, a plant area and a control room do not carry the same consequence. Nor do they require identical controls.

This is where proportionality matters. Excessive controls can slow operations, create workarounds and encourage staff to bypass the very measures designed to protect them. Weak controls can expose people, information, critical services or high value assets.

Good assurance finds the point where a control is justified by the risk and can be consistently operated.

Define the access decisions that matter. Who can authorise access? What checks are required before access is granted? What should happen when a person changes role, leaves, loses a credential or needs temporary access? Who owns the decision if an exception is requested?

If these answers are vague, the issue is not a lack of technology.

It is a lack of governance. Security teams are then left trying to compensate for unclear management decisions at the gate or on the screen.

A practical guide to access control assurance

A useful assurance programme works from the expected control outcome back to the evidence needed to support it. It should be planned, proportionate and repeated often enough to identify drift before it becomes normal practice.

Establish clear control objectives

Avoid broad statements such as ‘only authorised persons may enter’. They are true but not testable. A better objective describes the required outcome in operational terms. For example, access permissions should match a current business need, be approved by an accountable person and be removed when that need ends.

Clear objectives let the organisation test what matters without turning assurance into a lengthy technical audit. They also expose conflicting priorities early.

If operations require frequent short-notice contractor access, the process must support that need safely rather than relying on informal favours.

Trace access through its full lifecycle

Select a sample of employees, contractors, visitors and temporary workers. Follow their access from request to approval, issue, use, review and removal. Compare records with the reality of their role and location.

The value comes from tracing the complete journey. A review that only checks whether cards are active may miss whether the right person approved them, whether the access level was appropriate, or whether a change in work pattern was reflected promptly. Equally, an immaculate approval record means little if the physical control does not perform reliably at the point of entry.

Sampling should be risk led rather than random for its own sake.

Prioritise areas with significant consequences, high staff turnover, complex contractor activity, frequent access changes or known operational pressure.

Observe how people work

Documents describe the intended process. Observation shows the real one.

Spend time at relevant points of entry during normal operating periods. Speak with the people responsible for managing visitors, deliveries, access queries and exceptions. Ask what makes the process difficult, where delays occur and which situations force judgement calls.

This is not about catching people out.

Staff often develop informal workarounds because the formal process is slow, unclear or detached from the pace of the operation. Treating every workaround as misconduct misses the learning.

The better question is why a capable person believed the workaround was necessary, and whether the control design has made the safe choice impractical.

Test management of exceptions and change

Access control tends to weaken during change. A new tenant moves in. A project team needs temporary space. A contractor’s work extends beyond the expected date.

A manager leaves and approval authority is unclear. None of these events are unusual, yet they are where access rights accumulate and ownership becomes blurred.

Assurance should examine whether the organisation can identify exceptions, approve them properly, set an end point and review them. It should also consider whether changes to the building, operating hours or occupancy have altered the original security assumptions.

This does not require disruptive testing or an attempt to defeat controls.

It requires sensible validation of the arrangements that staff are expected to use, supported by record checks, discussion and observation.

Common failures that paperwork does not reveal

The most common failure is permission creep. People retain access because it was easier to add it than remove it, or because no one owns the review. This is particularly common where departments, sites or systems manage access separately.

Another is weak contractor control. Contractors can be essential to business continuity, but their access arrangements are often designed around convenience rather than a clear operational need. The issue is not simply whether they have a pass.

It is whether their access, supervision and end date match the work they are actually doing.

Emergency arrangements can create a third blind spot. Staff need to know how to act safely and decisively in an emergency, but emergency procedures must not become a standing reason to ignore normal access discipline.

Assurance should check that people understand the boundary and that the organisation can account for decisions made under pressure.

Finally, many organisations collect data without using it. Event logs, alarm reports and access requests can show recurring faults, repeated exceptions or poor response times.

If nobody reviews the pattern, the data becomes administrative clutter rather than security intelligence.

Measure capability, not activity

A monthly report showing the number of cards issued tells you very little. Better measures show whether access decisions are timely, accurate and sustainable. This may include the time taken to remove access following a role change, the proportion of sampled permissions that match current need, the closure of identified exceptions and the quality of staff decisions in realistic scenarios.

Numbers need interpretation.

A low number of reported issues may indicate strong control, but it may also show that staff do not know what to report or do not believe concerns will be acted on.

Pair management information with direct engagement and periodic assurance activity.

The aim is to create a feedback loop.

Findings should lead to specific changes in process, technology, training or ownership. Those changes should then be checked. Repeating the same audit findings each year is not assurance.

It is evidence that the organisation has accepted a known weakness.

Give assurance an operational owner

Access control crosses security, facilities, HR, IT, operations and line management.

That makes shared responsibility inevitable, but shared responsibility can easily become no responsibility. A named owner should coordinate assurance, bring the right functions together and ensure actions are closed.

That owner does not need to operate every system or approve every request.

They do need sufficient authority to challenge poor practice, escalate unresolved risks and make sure security requirements remain workable for the operation.

The strongest access control arrangements are not those with the most equipment.

They are those in which people understand the purpose of the control, managers own their decisions and weaknesses are found before someone else finds them for you.

.

Useful Links:

.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center