Key Management
Key management describes the procedures by which physical keys, key cards and master keys are issued, tracked and recovered, as queried in property insurance proposal forms to assess the integrity of an otherwise effective mechanical security or access control system.
- Category
- Security
- Data type
- Text
- Risk drivers
- Moral hazard, Frequency
- Underwriting impact
- Condition/Warranty, Premium
Typical proposal-form questions
- How is the issuance of keys, key cards and master keys to employees and third parties recorded and by whom?
- What procedure exists for recovering or invalidating keys and access credentials when an employee leaves or a contractor's assignment ends?
- Has a key or master key ever been lost or stolen without the lock or access system being replaced or reprogrammed?
Evidence
- Key issuance register / key holder list
- Written key management procedure
- Incident record of lost or stolen keys and remedial action taken
Why it matters for underwriting
Key management is the organisational layer that determines whether otherwise strong mechanical security and access control measures continue to function as intended over time: a high-grade lock or a well-designed access zone is only as effective as the discipline with which the keys or credentials that open it are issued, tracked and recovered. Underwriters treat this attribute as a proxy for the insured’s overall security culture, because an account with an informal, undocumented approach to keys frequently proves, on closer investigation, to also be lax in other areas of loss prevention. Uncontrolled or undocumented key holding widens the pool of people who could have facilitated or committed a burglary or theft without forced entry, which complicates claims investigation and raises the moral-hazard component of the risk.
Capturing the attribute and evidence
Underwriters ask how key and access-credential issuance to employees and third parties (cleaning staff, contractors, delivery services) is recorded, and what procedure exists to recover or invalidate keys and credentials when a person leaves the organisation or a contract ends. A written key management procedure and a current key holder register are typically requested as evidence, together with a record of any past incidents involving lost or stolen keys and the remedial action taken, particularly whether locks or access credentials were changed following such an incident.
Effect on coverage, premium and conditions
A documented key management procedure with an accurate, regularly reconciled key holder register and prompt recovery on staff or contractor changes supports more favourable premium terms and is often treated as a precondition for higher theft or burglary sublimits. Undocumented or unenforced key handling, and particularly a history of lost or stolen keys without corresponding lock or credential changes, commonly leads to conditions requiring a formal procedure to be implemented, or to premium loadings reflecting the elevated moral-hazard and no-forced-entry exposure.
Mitigation measures
Where key management is weak, insurers and risk engineers typically recommend introducing a written procedure covering issuance, tracking and recovery of all keys and credentials, maintaining a current key holder register reconciled at regular intervals, and rekeying or reprogramming affected locks and access systems promptly whenever a key or credential is lost, stolen or not returned.
Standards and codes
- ISO 31000:2018 – Risk management, Guidelines