Two systems, one assumption

When someone leaves, HR triggers the identity provider and their accounts close within minutes. The physical access control system (PACS) is usually a separate database. Unless it is integrated, someone has to deactivate the badge by hand, from a ticket, on the right day. Everyone assumes it happened.

Where the join breaks

  • Manual tickets that sit in a facilities queue over a weekend or a holiday.
  • Contractors, agency staff and vendors who were never in the HR system, so no leaver event ever fires.
  • Several sites, several PACS databases, and only one of them in the offboarding checklist.
  • Temporary and spare badges issued "for a week" with no end date.
  • Offline and wireless locks that only receive changes when they next sync.
  • The badge itself never collected, so a deactivation mistake becomes a working credential in someone’s drawer.

A test you can run this week

This needs no specialist tools, only two exports and a spreadsheet.

  1. Ask HR for everyone who left in the last 90 days, with their leave date.
  2. Export the active cardholder list from the access control system, with the last-used date for each card if it is available.
  3. Match the two. Any leaver with a card still active is a finding.
  4. Then look at the access events. Any badge used after its holder’s leave date is a serious finding, because it means someone walked in.
  5. Repeat for contractors against whatever list your procurement or facilities team holds.

Fixing it for good

ControlWhat it involvesPrice range
Default end dates for contractor and temporary badgesA setting in most access control systemsNo cost
A weekly reconciliation of leavers against active cardsAn export, a match and a named ownerNo cost
Quarterly access reviews signed by area ownersRequired for SOC 2 and ISO 27001 anywayStaff time
Integrate the PACS with HR or the identity providerA connector or middleware so a leaver event disables the badgeBudget item, get quotes

If you are working towards SOC 2, this is the evidence your auditor will ask for under CC6.4. See SOC 2 CC6.4: physical access controls.

How we assess it

Deprovisioning is one of the six areas of our credential and access control assessment. We follow a sample of leavers from HR through the identity provider to the access control system and, where authorized in writing, to the reader itself.

Last reviewed September 23, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.