Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do first before upgrading access…
Governance, Ownership & Risk

What should organisations do first before upgrading access control for a safer return to work?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

The first step is to perform or update a physical security risk assessment. That assessment should map the entry process end to end, compare mitigation options, and test cost and risk trade offs before changes are made. It should also look for unintended consequences, because a control that reduces surface contact can still increase authentication weakness, unauthorized entry, or crowding.

Why the first step should be a physical security risk assessment

Before changing access control for a return-to-work plan, organisations need a current physical security risk assessment. That assessment should model the actual entry journey, compare mitigation choices against one another, and test where the proposed control improves safety without creating a new weakness in authentication, throughput, or occupancy management.

A good assessment is not just a facilities review. It should connect the entry point, reception workflow, badge or credential checks, visitor handling, queueing, and any downstream escalation path so that the organisation understands how one control change affects the whole entry environment.

What a return-to-work access review has to cover

The first question is whether the proposed access change matches the real exposure. If the goal is to reduce close contact, teams need to compare options such as touchless entry, staggered arrival windows, controlled occupancy, and revised screening steps, then judge each option against cost, usability, and operational disruption.

That comparison matters because access control is rarely isolated. A stricter check can reduce casual entry but also create bottlenecks, encourage people to tailgate, or shift effort into unmanaged side doors. A softer control can improve flow but may weaken assurance that the right person is entering the right area at the right time.

Organisations should also look for unintended consequences in the surrounding workflow. For example, a control that reduces surface contact can still increase authentication weakness, unauthorized entry, or crowding if staff bypass it under pressure or if the entry process becomes hard to use at peak times.

  • Map the entry process from arrival to final clearance.
  • Identify where identity, authorization, and occupancy decisions are actually made.
  • Compare candidate controls on safety, throughput, exception handling, and operational resilience.
  • Check whether the change introduces new bypasses, shared workarounds, or unmanaged secondary entry paths.

Why the control decision must be tested before rollout

Access control changes can fail when they are designed as isolated security upgrades instead of operational changes. If the new process is not validated end to end, an apparently safer design can simply move the risk elsewhere, for example from open contact surfaces to congestion, queue pressure, or weak manual exceptions.

That is why the assessment should include cost and risk trade-offs before implementation. The point is not to choose the most restrictive control, but to choose the one that reduces the relevant physical exposure while still being realistic for the population, the building, and the business rhythm.

Where the organisation serves a mixed population, such as employees, contractors, and visitors, the assessment should also test whether one access model works for all groups or whether different entry paths are needed. A single rule that is easy to explain is not necessarily the safest rule if it encourages exceptions that are poorly supervised.

Risk and Threat Considerations

Return-to-work access changes can create new exposure when they are rushed or designed around a single objective. The main failure modes are weak authentication at the door, tailgating, unmanaged crowding, and exception paths that are easier to exploit than the intended control.

Failure mechanism: The organisation changes entry control without fully modelling how people will queue, verify identity, or bypass the process under time pressure, so the new design shifts risk from contact exposure to access weakness or congestion.

Impact: The result can be unauthorized entry, reduced confidence in physical security, slower incident response at the entry point, and a control that looks stronger on paper but performs worse in practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementReturn-to-work access changes need controlled entry and exception handling.
Recommendation — Review and tighten access paths that control who can enter facilities.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe question is about choosing controls after comparing risk and trade-offs.
Recommendation — Use a risk strategy to compare access-control options before changing entry procedures.
ISO/IEC 27001:2022A.7.4 — Physical security monitoringPhysical entry changes should be assessed against site security monitoring and control.
Recommendation — Assess physical access changes against monitoring and guard controls.

Practitioner Guidance

What to prioritise: Treat the assessment as a decision tool, not a compliance exercise. The most important output is a side-by-side view of which control reduces exposure, which one creates operational friction, and where staff are most likely to work around it.

What to verify: Confirm that the proposed control still works at peak arrival times, for visitors and contractors, and at any secondary entrances that people may use when the main path slows down. If the workflow depends on human exception handling, that exception process needs explicit ownership and monitoring.

Practitioner takeaway: The safest access control change is usually the one that has been stress-tested against real entry behaviour, not the one that sounds most restrictive in principle.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org