Two systems, one assumption
When someone leaves, HR triggers the identity provider and their accounts close within minutes. The physical access control system (PACS) is usually a separate database. Unless it is integrated, someone has to deactivate the badge by hand, from a ticket, on the right day. Everyone assumes it happened.
Where the join breaks
- Manual tickets that sit in a facilities queue over a weekend or a holiday.
- Contractors, agency staff and vendors who were never in the HR system, so no leaver event ever fires.
- Several sites, several PACS databases, and only one of them in the offboarding checklist.
- Temporary and spare badges issued "for a week" with no end date.
- Offline and wireless locks that only receive changes when they next sync.
- The badge itself never collected, so a deactivation mistake becomes a working credential in someone’s drawer.
A test you can run this week
This needs no specialist tools, only two exports and a spreadsheet.
- Ask HR for everyone who left in the last 90 days, with their leave date.
- Export the active cardholder list from the access control system, with the last-used date for each card if it is available.
- Match the two. Any leaver with a card still active is a finding.
- Then look at the access events. Any badge used after its holder’s leave date is a serious finding, because it means someone walked in.
- Repeat for contractors against whatever list your procurement or facilities team holds.
Fixing it for good
| Control | What it involves | Price range |
|---|---|---|
| Default end dates for contractor and temporary badges | A setting in most access control systems | No cost |
| A weekly reconciliation of leavers against active cards | An export, a match and a named owner | No cost |
| Quarterly access reviews signed by area owners | Required for SOC 2 and ISO 27001 anyway | Staff time |
| Integrate the PACS with HR or the identity provider | A connector or middleware so a leaver event disables the badge | Budget item, get quotes |
If you are working towards SOC 2, this is the evidence your auditor will ask for under CC6.4. See SOC 2 CC6.4: physical access controls.
How we assess it
Deprovisioning is one of the six areas of our credential and access control assessment. We follow a sample of leavers from HR through the identity provider to the access control system and, where authorized in writing, to the reader itself.
Last reviewed September 23, 2026.