Access Control System
Access control system records the method by which entry to a location or to sensitive areas within it (server rooms, cash offices, hazardous storage) is restricted and logged, as queried in property and cyber insurance proposal forms to assess unauthorised-access exposure.
- Category
- Security
- Data type
- Enumeration
- Risk drivers
- Frequency, Accumulation, Moral hazard
- Underwriting impact
- Premium, Condition/Warranty, Exclusion
Typical proposal-form questions
- How is access to the building and to sensitive areas (server room, cash office, hazardous materials store) controlled and by whom?
- Does the system electronically log entries and exits, and for how long are access logs retained?
- How quickly are access rights revoked when an employee leaves or a contractor's assignment ends?
Evidence
- Access control system specification
- Access rights matrix / authorisation list
- Access log retention policy
Why it matters for underwriting
Access control determines who can physically reach an insured location’s most sensitive areas, and it is one of the few security attributes that is relevant to both property and cyber underwriting at once: a server room or data centre protected only by a mechanical lock shared by many key holders exposes the account to unauthorised physical access that can defeat even strong logical security controls, while a cash office or hazardous materials store without controlled, logged access raises both theft and moral-hazard exposure. Underwriters use the type and rigour of access control to assess how well an insured limits the population that can reach critical assets, and how quickly access is revoked when personnel or contractor relationships end, since stale access rights are a recurring root cause behind both physical theft and cyber incidents traced to former employees or contractors.
Capturing the attribute and evidence
Proposal forms typically distinguish between no formal access restriction, simple mechanical locks, and electronic systems using keycards, PIN codes or biometrics that log every entry and exit. Underwriters request the access control system specification, an access rights matrix showing which roles are authorised for which areas, and the organisation’s policy on revoking access when employment or contractor relationships end. For higher-value or higher-sensitivity locations, a risk engineering survey typically verifies that access zones actually match the authorisation matrix and that logs are retained long enough to support an investigation.
Effect on coverage, premium and conditions
Electronic, logged access control covering all sensitive areas, combined with a documented and promptly enforced revocation process, supports more favourable premium terms on both the property and cyber programme and can reduce the likelihood of exclusions tied to inadequate access governance. Reliance on shared mechanical keys without logging, or access rights that are not promptly revoked, commonly leads to conditions requiring remediation, sublimits on theft or data-breach cover, or exclusions for losses traceable to access-control failures.
Mitigation measures
Where access control is weak, insurers and risk engineers typically recommend migrating sensitive areas to an electronic system with individual credentials and logging, restricting authorisation to a documented list of roles, and formalising a process that revokes access immediately when an employment or contractor relationship ends.