An access control audit checklist should review more than whether a card reader unlocks a door. For a commercial property, a useful first-pass audit connects each protected door with its credentials, permissions, schedules, hardware, records, connected cameras, and responsible administrator.
This article focuses on physical access control for offices, clinics, retail sites, warehouses, and other commercial properties. It is different from a software user-access or identity and access management review, which examines accounts and permissions inside digital systems. For a refresher on access control basics, separate authentication, which verifies identity, from authorization, which determines what that identity may access.
Quick summary

- Inventory every protected door and confirm its intended security purpose.
- Match every credential to a current, identifiable person or approved purpose.
- Review permissions, schedules, former-user removal, and restricted areas.
- Sample audit records, test hardware behaviour, and verify integrations.
- Record evidence and escalate unclear door, network, safety, or multi-site issues.
How to use this access control audit checklist
Assign an authorised reviewer, define the sites and review period, and avoid making changes while collecting evidence. Mark each item as pass, gap, or unable to verify. For every gap, record the affected door or user, evidence collected, risk, responsible owner, and follow-up date.
| Audit check | Evidence to collect | Action if it fails |
|---|---|---|
| System scope | Door inventory, plans, device list | Document unprotected or unknown doors |
| Credentials | User list, card or fob register, PIN records | Investigate unknown or shared credentials |
| Permissions | Role matrix, schedules, approvals | Remove unnecessary access |
| Former users | Offboarding records and disabled credentials | Revoke access and review related shared access |
| Audit trail | Sample events, exports, denied attempts | Confirm system limits and preserve useful evidence |
| Hardware | Door, reader, lock, power, and override observations | Escalate unsafe or uncertain behaviour |
| Integrations | Camera links, alarms, network and privacy procedures | Assign owners and document remediation |
1. Confirm the system scope and every protected door

Start with a complete inventory of entrances, staff-only areas, storage rooms, server or records rooms, loading areas, tenant spaces, and other restricted locations. Include doors controlled by a reader, smart lock, intercom, PIN, key switch, or another electronic method.
For each door, document its purpose, reader or credential method, locking hardware, controller, camera coverage, emergency release arrangement, and administrator. Compare the intended protection with what is actually installed. Look for undocumented doors, unused devices, routinely propped-open doors, mechanical bypasses, and areas where requirements have changed.
For a multi-site business, create a separate inventory for every property before comparing equipment or procedures. Similar buildings may have different layouts, operating hours, network paths, risks, and local responsibilities.
2. Verify credentials and the people who own them
Review the credential register and match each keycard, fob, PIN, mobile credential, temporary pass, and administrator account with an identifiable person or documented business purpose. Investigate credentials with no owner, duplicate assignments, shared permanent PINs, unexplained administrator privileges, and cards that remain active but cannot be located.
Compare the credential method with the door and its users. Keycards, fobs, PINs, and mobile credentials create different administration and recovery considerations. This overview of access control credential types can help frame that comparison, but the right choice depends on the property, users, door hardware, and management process.
Ask whether visitors, contractors, cleaners, tenants, and delivery personnel receive temporary access, and whether that access expires. Confirm how lost credentials are reported, disabled, replaced, and recorded.
3. Review permissions, restricted areas, and schedules
Compare each person’s role with the doors, times, and actions they actually need. A receptionist may need an entrance during business hours but not a records room. A contractor may need one area for a defined period, while a site manager may need broader access.
Use least-privilege thinking: provide the minimum access required for assigned work, then document who approved it. Government access-control guidance also supports withdrawing or revising access when responsibilities change and limiting privileges to what a person needs.
Check scheduled access, holiday rules, restricted areas, temporary permissions, shared access, and administrator rights. An active credential is not proof that its permissions remain appropriate.
4. Test former-user removal and access changes
Review a sample of employees, tenants, contractors, vendors, and people who changed roles. Compare the departure or role-change record with the date their credential was disabled, their card or device was returned, and their permissions were updated.
Do not limit this check to named users. Ask whether former users could still enter through a shared PIN, borrowed fob, mobile account, visitor code, or another person’s credential. Check who approves changes and whether those approvals are recorded.
A safe test can use a controlled test credential, a scheduled maintenance window, and an authorised observer. Avoid disabling a live user or testing an emergency function during occupied operations without an appropriate plan.
5. Verify audit trails and the evidence they contain
Sample recent entry and exit events for different doors and credential types. Check whether records identify the person or credential, door, date, time, event type, denied attempt, and override where supported. Confirm who can view, export, alter, or delete records.
Do not assume every system creates a complete or tamper-proof audit trail. Confirm what the controller and software record, how long records remain available, whether clocks are accurate, and whether an export can be understood without specialist software.
Canadian privacy guidance recommends protecting personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification. Treat access records as sensitive operational information: limit administrator access, avoid collecting more than necessary, and document who reviews or exports them.
6. Inspect door hardware, overrides, and failure behaviour
A software review cannot reveal whether a door closes properly, whether a reader is damaged, or whether a lock releases when the building needs it to. Inspect the reader, lock alignment, hinges, frame, door closer, request-to-exit device, local controls, visible cabling, and signs of physical damage.
Document permitted tests involving power loss, network loss, rejected credentials, valid credentials outside their schedules, and approved local overrides. Fail-safe and fail-secure behaviour depends on the door’s purpose, life-safety requirements, building conditions, and system design. There is no universal setting for every door.
Do not experiment with emergency releases, powered locks, or occupied exit routes if you are unsure of the arrangement. Record the uncertainty and request qualified assessment.
7. Review integrations, privacy safeguards, and follow-up actions
List every connected system, including CCTV, alarms, intercoms, network cabling, remote management, and monitoring services. For each integration, identify the expected event, responsible system, administrator, and fallback if the connection is unavailable.
Where supported, test whether an access event can be associated with relevant camera footage. Check that the door, time, and camera view align rather than assuming a linked system automatically provides useful identification. Results depend on the installed equipment, configuration, clock settings, and coverage.
Assign each gap an owner and priority. Review administrator access, record-handling procedures, retention decisions, incident escalation, and the process for adding or removing users. Privacy safeguards should reflect the sensitivity and use of the information.
Commercial and multi-site considerations
Businesses with several properties should decide whether administration is centralised, site-level, or a combination. Centralised management may support consistent roles and cross-site review, but it can increase dependence on shared connections and central components. Site-level management may provide local independence, but it requires consistent procedures and more local administration.
Document who can view live events, review recordings, export evidence, change settings, add users, and approve access at each location. Keep organisation-wide standards separate from site-specific requirements. Also state what happens when a site loses connectivity, a local administrator is unavailable, or a user transfers between locations.
For a deeper comparison of centralised and site-level management, focus on connectivity, recording, permissions, maintenance, documentation, and failure reporting.
When to handle gaps yourself and when to request professional help
An authorised administrator can often complete a first-pass inventory, reconcile credentials, compare permissions with current roles, review approvals, and document evidence. These tasks remain valuable when a specialist will complete the next stage.
Request professional assistance when door hardware or emergency behaviour is unclear, access events do not match camera footage, network cabling or controllers are undocumented, unexplained credentials remain active, or several sites depend on inconsistent administration. Professional help is also appropriate when testing could affect safety or building operations.
Frequently asked questions
How often should a commercial access-control system be reviewed?
Review it after major staffing, tenant, door, software, or site changes, and establish a recurring schedule appropriate to the property’s risks. Review former-user removal and administrator access whenever responsibilities change.
What evidence should be collected?
Collect the door inventory, credential and user register, permissions and schedules, approval records, offboarding records, event exports, hardware observations, system diagrams, integration tests, and unresolved limitations.
What is the difference between an access-control audit and a user-access review?
A physical audit reviews doors, locks, readers, credentials, schedules, entry records, and connected security systems. A user-access review usually focuses on software accounts and permissions. They can overlap, but they are not the same review.
Can access-control events be linked to security-camera footage?
Some configured systems can associate an access event with footage, but the result depends on compatible equipment, accurate time settings, camera coverage, recording availability, and permissions. Test the actual door and camera combination.
Should a multi-site business centralise administration?
Not automatically. Centralisation can help with consistent roles and cross-site oversight, while site-level control can preserve local independence. Compare connectivity, responsibilities, failure planning, and cross-site visibility first.
Turn the checklist into a documented security decision
A useful access control audit starts with the doors and ends with accountable follow-up. Inventory the system, reconcile people and credentials, review permissions and former-user removal, verify the evidence trail, inspect hardware behaviour, and test integrations and privacy safeguards. Mark unknowns clearly instead of treating them as passes.
Routine administrative gaps may be corrected internally, while uncertain hardware, safety functions, network dependencies, incomplete documentation, and multi-site issues deserve qualified review. True Vision Surveillance canada inc offers access-control solutions for single doors through multi-site commercial environments.
