Key Control: What It Is, the Policy and the Custody Log That Proves It

Key control custody log: issue, return and lost-key fine trail in AVES

Key control is the practice of tracking every physical key on a site – who holds it, when it was issued and when it came back – so that at any moment you can say exactly where each key is and prove the custody trail. It turns a drawer of unlabelled keys into an accountable, auditable system.

A single lost master key can force a site to rekey an entire building and the bill runs into the thousands. Yet on many guarded sites, key control still means a hook board, a dog-eared register and a lot of trust. This guide covers what key control is, what belongs in a key control policy, the custody log that makes it defensible and where the paper process quietly fails.

Why key control matters

Keys are access. A key that leaves the site in the wrong pocket is an unlocked door, a compromised store room or a master that opens far more than anyone intended. Unlike a swipe card you can deactivate in seconds, a physical key cannot be revoked remotely – the only control you have is knowing who took it and getting it back.

That is the whole job of key control: at any moment, for any key, you can answer three questions. Who has it? When did they take it? When is it due back? If a site cannot answer those, it does not have key control – it has a key drawer and good intentions.

What is key control?

Key control is a formal process for issuing, tracking and returning physical keys, backed by a record that stands up to audit. A proper system ties four things together:

  1. A key register – every key and its type accounted for, not a mystery hook board.
  2. An issue and return process – a key is requested, issued to a named person and signed back in.
  3. A custody trail – a timestamped record of who held each key and for how long.
  4. An exception process – what happens when a key is not returned, is lost or is damaged.

Drop any one of those and the system develops the gap through which the expensive key eventually walks out.

What a key control policy covers

A workable key control policy does not need to be long, but it must be specific. At minimum it defines:

  • Key classification – which keys are master, sub-master or single-door and who is allowed to hold each.
  • Authorisation – who can approve a key being issued and to whom.
  • Issue and return rules – how a key is requested, the maximum time it can be held and how it is signed back in.
  • The custody record – what gets logged on every issue and return: key, holder, date, time and who accepted it.
  • Lost and damaged keys – the process when a key does not come back, including any fine or replacement charge and who authorises it.
  • Audit cadence – how often the full key register is reconciled against what is physically on the board.

The policy is the rulebook. The log is the proof it was followed.

The key control log: your custody trail

A key control log is the running record of custody. For every movement it should capture the key itself, its type, the person it was issued to, who authorised or accepted the handover, the date and time out and the date and time returned. Done properly, the log lets you produce, months later, a complete history for any key: every hand it passed through and every gap between issue and return.

This is the part that paper does worst. A register signed in ballpoint tells you a key went out on Tuesday; it rarely tells you reliably when it came back and it never alerts anyone that a key is overdue.

Where key control breaks down on paper

The hook board and the register are simple, which is exactly why they fail under real conditions:

  • No overdue visibility. A paper log is passive. Nothing flags that a key issued this morning never came back tonight – you find out when someone needs it.
  • Illegible or missing sign-backs. The issue line is filled in; the return line is blank or unreadable. The custody trail has a hole in it.
  • No accountability for loss. When a key goes missing, there is no clean record of who last held it, so the cost quietly becomes everyone’s problem and therefore no one’s.
  • Stale key register. The board has keys nobody can identify and gaps nobody can explain, because the register was never reconciled.
  • No audit-ready history. Asked to prove custody of a specific key over the last quarter, the site produces a shoebox of registers, not an answer.

A lost key with no record of who held it is not just a rekeying cost – it is a loss you cannot pin down and therefore cannot prevent from happening again.

Managing key control digitally

This is where a structured workflow closes the gaps a register leaves open. In AVES, a Key Checklist runs key custody as a tracked record rather than a signature on a page:

  • Each key is logged with its key type and availability, so the register reflects what is actually on the board.
  • A key is requested to a named approver and issued, with accepted by, date and time captured on the handover – a real custody entry, not an illegible line.
  • The return is recorded against the same entry, closing the custody trail for that key.
  • When a key is lost, the lost date, a fine amount, who issued the fine and the receipt number are captured, so a loss has an owner and a paper trail instead of a shrug.
  • Each entry carries a status, so an overdue or outstanding key is visible rather than buried in a register.

The point is not software for its own sake. It is that the accountability key control exists to provide – who holds this key, when it is due, who last had the one that went missing – becomes a record you can produce on demand, rather than a story reconstructed from a register.

Common mistakes to avoid

  1. Treating the register as the system. A signature captures issue, not return. Without a closed custody trail, the log proves half of what matters.
  2. No overdue trigger. If nothing flags a key that has not come back, you will always find out too late.
  3. No consequence for loss. When losing a key costs nothing and names no one, keys keep going missing.
  4. Never reconciling the board. A key register that is not periodically checked against the physical keys drifts out of truth within weeks.
  5. One policy for every key. A single-door key and a building master do not deserve the same controls. Classify keys and match the controls to the risk.

Frequently asked questions

What is key control?
Key control is the practice of tracking every physical key on a site – who holds it, when it was issued and when it was returned – with a record strong enough to audit, so you can always say where each key is and prove its custody trail.

What should a key control policy include?
At minimum: key classification, who can authorise an issue, the issue and return rules, what gets logged on every movement, the process for lost or damaged keys and how often the key register is reconciled.

What is a key control log?
A running record of key custody. For each movement it captures the key, its holder, who authorised or accepted the handover and the times out and back, so you can reconstruct the full history of any key.

Who should have master keys?
Only named, authorised holders defined in the key control policy. Master and sub-master keys open far more than a single-door key, so they warrant tighter authorisation, shorter hold times and closer audit.

Do I need software for key control?
No – the requirement is the policy and the discipline behind it, which can be run on paper. A digital record mainly helps with the parts paper does worst: flagging overdue keys, keeping a legible custody trail and producing an audit-ready history for any key on demand.

Related reading

See key custody tracked end to end

Running sites where a single lost master key means rekeying a building and your only record is a paper register? See how AVES turns key custody into a tracked, auditable trail – issue, return, overdue status and a lost-key fine record with who held it last. Book a 30-minute demo and we’ll walk you through the actual Key Checklist screen – or start a free trial.

Follow AVES on Instagram for more security operations tips.