A facilities manager asks for another restricted key. Their name is not on the authority record. Stop there. A locksmith key control register shows who approved the key, who holds it and what still needs fixing before you cut or release anything.
Duplication authority varies by restricted-key system and customer agreement. Check the rules for that key system before cutting, then follow the authority method recorded for that customer and site.
Run the locksmith key control register as a history of every handover. A current-holder box is not a custody trail. Keep the key, customer authority, handovers and open problems as separate linked records.
Decide what the locksmith key control register must prove
Start with the questions your office must answer while the customer is waiting:
- Which commercial site does the key belong to?
- Which key system and opening or access group apply?
- Which physical key or controlled set is involved?
- Who may request, approve, receive or return it?
- Who has recorded custody now?
- Which job sheet supports the issue or transfer?
- Is the key overdue, missing, damaged or retired?
- Is any mismatch still open?
Choose the sites and customer actions the register will cover. Include commercial keys that your business cuts, supplies, holds, delivers, recovers or retires. Include temporary keys when your team records their issue or return.
Do not quietly add unrelated assets. Access cards, fobs and mechanical keys can follow similar controls, but each needs a clear asset type and identifier. A vague row marked “front access” is not enough.
Use one controlled register. Do not let each tradesperson keep a private list while the office keeps another. Two live records create two answers when a key goes missing.
Keep authority, custody and condition separate
Authority answers who may approve an action. Custody answers who received the physical key. Condition answers whether that key is serviceable, damaged, missing or retired.
One person can appear in more than one role, but the roles are not interchangeable. A facilities employee may hold a key without permission to order another. A managing agent may approve a key without taking possession of it.
Write those answers in separate fields. Then an office worker can check authority without mistaking the current holder for an approver.
Set the site and identifier rules before entering keys
Create the site record first. Use the full property address and postcode, plus a stable internal site ID. Keep separate site records where one customer controls several properties.
The site ID should remain unchanged when the tenant, facilities contact or managing agent changes. People move. The property record stays.
Do not carry approval from one site across a customer’s portfolio unless the authority record expressly covers the other site and key system. Familiar names are not enough.
Give each part of the record its own ID
Use controlled identifiers for:
- Customer account
- Commercial site
- Key system or series
- Opening or access-group ID
- Individual key or controlled set
- Authority record
- Custody event
- Problem record
- Job record
Do not reuse an old key ID after retirement. Retired keys can return in a drawer, cabinet or former contractor’s van. Reusing the ID makes the old key look like the new one.
Write down the naming rule for your team. Keep it short enough to use at the bench. The identifier stamped on the key, written on the job sheet and stored in the commercial key register must match.
Keep useful opening details off the visible tag
An opening or access-group ID is a code that points to the door or group in the customer’s private key schedule. A tag should help authorised staff find that controlled record without advertising the property or door it opens.
Use the key ID on the visible tag. Keep the address, tenant name, room description and opening details inside the controlled record.
Track each key separately when individual custody matters. You can track a sealed emergency set as one asset only when the customer stores, issues and checks it as one sealed unit. If the keys can leave separately, give each one its own key ID.
If you are still designing the system and door schedule, settle that scope before creating the asset records. Use the master key suite quoting guide to connect the approved openings, key quantities and commercial quote.
Build the locksmith key control register from linked records
Do not build one long row and keep overwriting the holder. Build four linked record groups. This preserves the history without making the live position hard to find.
Key asset record
The asset record distinguishes one physical key or controlled set from every other copy. Keep missing, damaged and retired keys in the record so an old key cannot be mistaken for a current one.
Customer authority record
The authority record says who may take a defined action. It must also show who checked that authority, when they checked it and where the supporting evidence is held.
Permitted actions might include request, approve, receive or return. Do not write “full access” when you mean permission to approve another key. State the action.
Restricted key authority should also state its scope. Tie it to the named site, key system and opening or access-group ID. If the customer allows one person to approve standard replacements but not a wider access group, record that boundary.
Close an old authority period when a contact leaves. Add a new record for the replacement. Do not overwrite the earlier name because you may need to establish who approved an earlier handover.
Custody event
Create a new custody event for every issue, transfer and return. Never edit an earlier event to show a later holder.
The latest valid custody event identifies the current recorded holder. The earlier events remain untouched.
A holder can be a named person or a named controlled location. If the key enters a security desk, key cabinet or site safe, record that location and the person or team responsible for it. Never leave the holder blank.
Problem record
Open a problem record when the physical key and paperwork do not agree. Name the person responsible for follow-up and keep the record open until a return, correction, retirement instruction or other recorded customer decision settles it.
Set restricted key authority across a UK property chain
Commercial properties often involve a freeholder, managing agent, occupier, facilities team and temporary contractors. Do not assume one party can approve for another.
Record the customer account and site authority separately. The account tells you who buys the work. The authority record tells you which named person may approve a specific key action for that property.
For each party, record the sites and key systems they cover, the actions they may take, the agreed confirmation method and the dates their authority runs.
Support the confirmation method with a current authority record, an agreed customer contact route or the authority method required by the restricted-key system. Record which one applies before the request reaches the bench. Name the person who checked it, record the date and link the evidence reference to the job.
A known email address, purchase order or job title is not authority by itself. A purchase order supports the commercial instruction, but the sender and requested action must still match the current authority record and system rules.
The same distinction applies to access. Permission to enter a property is not automatically permission to order a restricted key. Use the locksmith proof-of-address and right-to-enter guide when the job also involves opening or entering premises, but keep that check separate from key-order approval.
When a managing agent changes, close the old authority period and add the new agent and named contacts. Then inspect every open custody event and problem at the site. A contractor’s temporary key does not disappear from the record because the account contact changed.
Do not treat an account-name change as proof that custody transferred. Add a custody event only when the physical key moves under an approved handover.
Check the request before cutting another key
Put the request beside the current authority record. Match:
- Site ID and address
- Key system
- Opening or access-group ID
- Key quantity
- Requested action
- Requester
- Approver
- Intended recipient
- Customer instruction or purchase order
- Job reference
Stop if any part falls outside the recorded authority or restricted-key system rules. Contact the customer through the agreed route and record the answer. Do not cut the key and try to repair the paperwork afterwards.
An approver may cover one building but not another. A familiar email address or senior job title does not fill that gap.
If the request changes after approval, check it again. A different quantity, site, key system or access group is a different instruction. Record the customer’s approval before adding the change to the job.
Create the key asset before release
Once cutting is approved, create a unique asset record for every new key before it leaves the bench. Link that asset to the approved cutting instruction, authority evidence and job reference.
Stamp or tag the new key with its controlled ID. Do not release a duplicate that exists only as a quantity on the job sheet.
Run a bench check before releasing the key
Put the physical key, job sheet and register together. Read the stamp or tag. Match it to the key ID, system reference and opening or access-group ID.
If the stamp on the key does not match the job sheet, stop the handover. Open a problem record. Find whether the mistake is on the physical key, the job sheet or the register.
Do not solve a mismatch by editing whichever field is easiest. Check the approved instruction and trace the key back through the job. Record the correction and who approved it.
Close the problem only when the three records agree or the customer gives a recorded instruction about the discrepancy. The person at the counter should not have to guess.
Complete the key issue record during handover
Record the issue while the key and recipient are in front of you. Memory is not a handover system.
Confirm the recipient using the method agreed with the customer. Then record the recipient, approver, locksmith, date and time, job reference and acknowledgement method. For a temporary key, record either an expected return date or the customer’s decision that no return date applies.
The key issue record should point back to the authority record used for approval. That link lets the office answer both questions later: who authorised the issue, and who took custody?
If the recipient changes at collection, stop and check whether the replacement person may receive the key. Do not hand it over because they work for the same organisation.
Record transfers and returns without rewriting history
For a transfer, add a new custody event. Name the previous holder, new holder, approver and person completing the handover. Link it to the preceding event.
Do not edit the original issue to show the new holder. That removes the first part of the chain and makes it impossible to see when custody changed.
For a return, inspect the physical key before recording the event. Match its identifier and note its condition. Record who surrendered it, who accepted it and where it will be stored next.
If the wrong key comes back, leave the expected key issued. Open a problem record for the mismatch. Receiving a similar key does not prove that the recorded one has returned.
Act on overdue, missing and damaged keys
An expected return date passing does not mean the physical key came back. Change its status to overdue, keep the named holder and open a problem record.
Assign the problem to a named person. Record the next contact, customer response and decision. Do not use a shared note such as “office to chase”. Nobody owns that action.
When a key is reported missing, preserve the last valid custody event. Record when the report arrived, who made it and what the customer instructed next. Do not mark the key returned or delete it.
For a damaged key, note whether the physical key was surrendered and where it went. If the customer retires the key, mark it retired and link that decision to the job or written instruction. Keep the earlier issue history.
Copy-ready register template
Keep these as four linked records. Use the site ID, key ID and job reference to join them.
#### Key asset
| Field | Entry |
|---|---|
| Customer account | [Customer name] |
| Site ID | [Controlled site ID] |
| Site address and postcode | [Full address] |
| Key ID or set ID | [Physical identifier] |
| Key system | [Controlled system reference] |
| Opening or access-group ID | [Code from the private key schedule] |
| Key type | [Standard, controlled or restricted] |
| Key location or status | [In stock, issued to named holder, stored at named controlled location, overdue or unresolved] |
| Key use | [Active or retired] |
| Physical condition | [Serviceable, damaged, missing or unknown] |
| Approved cutting instruction | [Instruction reference] |
| Job reference | [Job number] |
| Retirement reference | [Job or customer decision] |
#### Authority
| Field | Entry |
|---|---|
| Authority record ID | [Identifier] |
| Customer account | [Customer name] |
| Site ID | [Controlled site ID] |
| Authorised person | [Name, organisation and role] |
| Permitted action | [Request, approve, receive or return] |
| Key system and access scope | [Controlled IDs] |
| Confirmation method | [Current authority record, agreed customer contact route or system-required method] |
| Verified by | [Name of person who checked the authority] |
| Verification date | [Date checked] |
| Evidence reference | [Document, file or controlled storage reference] |
| Effective from | [Date] |
| Effective to | [Date or current] |
| Customer reference | [Instruction or document] |
#### Custody event
| Field | Entry |
|---|---|
| Custody event ID | [Identifier] |
| Key ID or set ID | [Identifier] |
| Event | [Issue, transfer or return] |
| Previous event | [Event ID or first issue] |
| Previous holder | [Person or named controlled location] |
| New holder | [Person or named controlled location] |
| Approved by | [Authorised person] |
| Handled by | [Locksmith or office worker] |
| Date and time | [Date and time] |
| Expected return date | [Date or recorded decision that no date applies] |
| Acknowledgement | [Method and reference] |
| Job reference | [Job number] |
#### Problem
| Field | Entry |
|---|---|
| Problem ID | [Identifier] |
| Site ID | [Controlled site ID] |
| Key ID or set ID | [Identifier] |
| Type | [Overdue, missing, damaged, duplicate or mismatch] |
| Last known holder | [Person or named controlled location] |
| Opened | [Date and time] |
| Follow-up owner | [Named person] |
| Next action | [Action and review date] |
| Customer decision | [Recorded instruction] |
| Closure reference | [Event, job or decision] |
| Closed | [Date or open] |
Protect the personal data in the register
The register holds names, roles, contact details, timestamps and custody history. Collect only what you need to identify authority, record the handover and follow up a problem.
Limit access to the office staff and locksmiths who need the record for the job. Do not leave exports, printed sheets or customer contact lists in an open van, shared inbox or unlocked cabinet.
Write down why each record is kept and the lawful reason for retaining it. Use the GOV.UK data protection guidance (opens in a new tab) to set and document the retention period, then securely dispose of paper and digital copies when that need ends.
Correct inaccurate personal details without erasing the custody history. Record what changed, when it changed and who made the correction.
During the next account review, check who can open the locksmith key control register, which fields they can change and whether old exports still exist.
Remove stale access, secure the remaining copies and write the retention rule beside the register.