Physical access control manages the doors, readers, and badge actions that enforce entry. Physical identity governance manages the lifecycle, policy, and review logic that determine who should have those entitlements in the first place. Organisations need both, but governance is what keeps the control aligned with identity changes and business need.
How physical access control works at the point of entry
Physical access control is the enforcement layer. It uses locks, badge readers, turnstiles, mantraps, PIN pads, biometrics, alarms, and visitor checks to decide whether a person or device gets through a boundary at a given moment. The control is operational: if the credential or factor is accepted, the door opens; if not, entry is denied or logged.
That makes physical access control immediate and observable, but also narrow. It answers a simple question at the edge: should this badge, token, or person be admitted now? It does not, by itself, decide whether the entitlement should exist, who approved it, or whether the access still matches current job need.
What physical identity governance decides before the door ever opens
Physical identity governance sits upstream of the reader and the lock. It defines who should receive building, floor, room, or cabinet access, how those entitlements are approved, who owns them, when they expire, and how they are reviewed or removed after a role change, move, or departure. In practice, it is the policy and lifecycle layer for physical access rights.
The difference matters because governance is about entitlement correctness, not just enforcement. A well-run governance process prevents stale badges, excessive access, shared credentials, and forgotten exceptions from becoming permanent. In other words, it keeps the access control system aligned with actual organisational need rather than inherited history.
Why organisations need both, not one in place of the other
Physical access control and physical identity governance solve different problems. Control without governance can faithfully enforce the wrong permissions for months or years. Governance without control can produce clean approvals on paper while the building still relies on weak badge issuance, inconsistent revocation, or manual workarounds.
That separation is especially important when people change teams, contractors rotate, or access is inherited through project-based exceptions. The control layer answers whether entry is technically permitted; the governance layer answers whether it should still be permitted. Strong programmes connect the two so that policy decisions actually change who can enter.
IAM and IGA Basics is a useful reference point because the same distinction between enforcement and lifecycle governance applies cleanly to physical access entitlements. The broader governance pattern also aligns with Access Reviews and Certification Guide, where the key question is not only who has access, but whether that access is still justified.
Risk and Threat Considerations
When these two layers are confused, the main exposure is access drift: people keep badges after role changes, temporary access becomes standing access, and exceptions outlive the business need that created them. That creates both operational risk and security risk because the physical control may be working exactly as designed while the identity decision behind it is outdated.
Failure mechanism: Weak governance allows over-entitled, orphaned, or unreviewed physical access to persist, and the control layer then enforces those stale entitlements without questioning their validity.
Impact: Organisations can end up with unauthorised entry paths, poor accountability, failed audits, and a larger insider or tailgating exposure surface than they realise.
For practitioners, the most common failure is assuming badge technology is the whole solution. In reality, the highest-risk gap is often between HR or role change events and the actual revocation of physical access. The strongest control environment is the one that treats access approval, review, and removal as part of the same governed lifecycle, not separate administrative chores.
Joiner-Mover-Leaver (JML) Guide illustrates the lifecycle side well, while Segregation of Duties (SoD) Guide is relevant where physical access combinations create conflict, such as facilities, cash handling, labs, or sensitive storage areas.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Physical access rights need assignment, review, and removal controls. |
| Recommendation — Review and revoke stale access rights on a defined schedule. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Physical access entitlements require lifecycle control, approval, and revocation. |
| IA-2 — Identification and Authentication (Organizational Users) | Entry control depends on proving the identity behind the badge or credential. | |
| Recommendation — Implement lifecycle controls for issuing, reviewing, and removing access rights. Require strong identity proofing and authentication before granting access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The topic distinguishes enforcement of access from governing who should have it. |
| A.5.18 — Access rights | Physical identity governance is about granting, reviewing, and removing entitlements. | |
| Recommendation — Define access rules and ensure they are consistently enforced. Review and remove access rights when business need changes. | ||
Practitioner Guidance
What to verify: Confirm that every physical entitlement has an owner, an approval basis, and a review cadence. If you cannot trace a badge or door permission back to a current business justification, treat it as a governance defect rather than an access-control defect.
Decision rule: If a person changes role, location, supplier status, or employment status, process the access change through governance first and then validate that physical control systems have actually enforced the update. Do not wait for the next periodic review to correct known drift.
What good looks like: The access system grants entry only to current, approved identities, and governance evidence shows timely provisioning, recertification, and revocation with no unexplained standing exceptions.
Role Mining and Role Design Guide is useful where physical access is assigned by department or job function, because poor role design quickly turns into access sprawl. Identity Security Programme Guide helps when you need a single operating model that ties approvals, reviews, and offboarding together across physical and logical access.
Practitioner takeaway: Physical access control stops unauthorised entry at the door, but physical identity governance is what prevents unauthorised access from being approved, forgotten, and normalised over time.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between identity governance and ITSM for access control?
- What is the difference between revoke-only access control and modify-based remediation in identity governance?
- What is the difference between ABAC and role-based access control in enterprise identity governance?