24–72 hour key return checklist for facility managers, NIST compliant

When an employee leaves, you have three jobs to do fast: collect every physical key, badge, and token they were issued, disable their electronic access before they walk out the door, and decide whether the situation calls for rekeying, a full lock change, or reprogramming your access system. Get those three right and everything else in this guide is just detail.
TL;DR:
Employees leaving should have all physical keys, badges, and tokens collected and logged immediately to prevent unauthorized access.
Disabling electronic access and conducting an access audit should be completed within 24 to 72 hours after departure to close security gaps.
Rekeying should be performed if a non-master key is lost, while hardware replacement is necessary for damaged or outdated locks, and system reprogramming applies to electronic credentials.
Maintaining detailed records of issued, returned, and actioned keys, including master keys, reduces risk and aids future security audits.
Locksmith services should be hired for rekeying, lock replacement, or electronic system updates, with preparation including access info and scope to ensure quick, effective work.
Table of Contents
First 24 to 72 hours: prioritized, time-bound actions
The window right after an employee leaves is when most security gaps open up. Move through these steps in order, and write down what happens at each one.
Collect every physical key, fob, and badge the employee was issued, and log what comes back versus what does not.
Disable badge access, PIN codes, and any software or building system accounts tied to that person immediately.
Run a quick access audit: list every door, gate, cabinet, and room the employee could have entered.
Escalate to a rekey or lock change if the person held master-level access or if any key or credential is unaccounted for.
This sequence matches how GSA physical-protection guidance frames facility security: access lists get updated and reviewed, and credentials tied to someone no longer authorized get removed without delay. NIST SP 800-171 backs this up on the electronic side, calling for disabling system access and revoking authenticators the moment employment ends, not at the next convenient IT ticket cycle.
Pro Tip: Keep a simple sign-off sheet for every departure: name, date, items returned, items missing, and who disabled which system. It turns a stressful afternoon into a five-minute record you can produce if anyone ever asks.
Rekey, replace, or reprogram: decision rules and cost or time tradeoffs
Not every departure needs the same response, and treating them all the same wastes money or leaves you exposed. Match the action to the risk.
Rekey when a single non-master key is lost or unreturned and the lock itself is in good condition.
Replace the hardware when locks are damaged, outdated, or you suspect a key was duplicated without authorization.
Reprogram or revoke credentials when the employee used a fob, PIN, or card system instead of a physical key.
Treat any lost master key as an automatic trigger for rekeying every cylinder it opened, not just the front door.
NIST-aligned guidance on personnel termination calls for changing keys or combinations whenever someone with access is terminated, which is the baseline most facility managers should treat as non-negotiable rather than optional. Electronic access has one clear advantage here: a manager can revoke a credential from a laptop in seconds, which cuts down on how often physical rekeying is needed at all.
Rekeying commercial locks tends to run on the lower end of the cost scale compared to full hardware replacement, though your actual price depends on cylinder count, whether you run a master-key system, and whether you use restricted keyways. Restricted keyways cost more upfront because duplicate blanks are controlled, but they make unauthorized copies far harder to produce later, which matters most for server rooms, cash offices, and other high-security areas.
Employee key return policy: template and operational checklist
A written policy is what turns “we should probably do something” into a repeatable process every manager on your team can follow the same way, every time.
Start with issuance rules: track who gets which key or credential, on what date, and under whose authorization. Assign one role (often a facilities or office manager) as the single point of accountability for issuing and logging keys, so responsibility never gets split across departments.
Your exit checklist should mirror the immediate-action steps above but formalized in writing:
Retrieve all keys, fobs, and access cards during the exit interview or on the last working day.
Disable electronic access accounts the same day, not the same week.
Document every action taken, including what was returned and what was not.
Apply the rekey, replace, or reprogram decision rules before closing the file.
Master-key control deserves its own line item. Keep a written record of who is authorized to hold a master key, require sign-off for issuance, and use restricted keyways so blanks cannot be duplicated at a hardware store counter. CISA’s ChemLock guidance makes the same point for secured facilities: keys go only to authorized people, they get collected on departure, and locks get rekeyed or replaced the moment compromise is suspected.
Your recordkeeping should track:
Field | Why it matters |
Employee name and role | Ties access history to a specific person |
Key or credential ID/serial | Confirms exactly what was issued |
Date issued and date returned | Creates an auditable timeline |
Areas accessible | Defines the scope of exposure if lost |
Locksmith or vendor action taken | Documents rekey, replace, or reprogram decisions |
A master key system guide can help you map out cylinder relationships before you ever need to make an emergency decision, which is far easier than reconstructing that map after someone has already left.
When to hire a locksmith and what to expect on the job
Some of this you can handle in-house. The moment master keys, damaged hardware, or electronic reprogramming are involved, it is worth bringing in a professional.
Call a locksmith for commercial rekeying when a key holder leaves and any lock in the system needs new pins.
Call for full lock replacement when hardware is damaged, outdated, or a duplication risk has been identified.
Call for electronic access or key-fob programming when you are adding, removing, or reissuing digital credentials.
Call for master-key cleanup when your physical hardware and your key records have drifted out of sync.
Before the technician arrives, have your lock model, cylinder count, and any master-key documentation ready, along with a clear sense of urgency: an emergency same-day rekey moves faster than a scheduled multi-door commercial job, and pricing reflects that difference. A small office rekey with a handful of cylinders is a different job than a commercial property with a master-key system spanning multiple buildings, and both time and cost scale with that complexity.
Pro Tip: Ask for a service ticket that lists cylinder serials and the specific work performed, plus an invoice. That paperwork becomes part of your audit trail the next time someone leaves.
A locksmith workshop equipped for both mechanical rekeying and key-fob programming can usually handle both sides of a departure in a single visit.
Author perspective and how Progressive Locksmith Cerrajero approaches these jobs
Julio Borroto has spent years working directly with property managers and business owners across Miami-Dade County on exactly this problem: what happens to the locks after an employee walks out for good. Progressive Locksmith Cerrajero handles emergency and scheduled rekey, lock change, and key programming work, and can be reached through Locksmithfromiami.
The most common mistake is treating a key return as an administrative afterthought instead of a security event with a clock running on it.
— Julio Borroto
Editorial take on compliance-driven key control
Most advice on this topic focuses on the paperwork: forms, sign-off sheets, termination checklists. That is necessary, but it is not where the actual risk sits. The risk sits in the gap between when someone loses access to your trust and when they lose access to your building, and that gap is often measured in days, not minutes.
Federal-style guidance from GSA and NIST is written for large institutions with dedicated security staff, but the underlying logic scales down fine to a five-door office or a small retail property. The part that gets skipped is the master-key audit. Businesses will diligently collect a departing employee’s individual key and call it done, without checking whether that key also opened a master cylinder covering six other doors. That is the actual exposure, and it is the one a rekey decision should be built around, not the visible key that got returned.

Quick contact and next steps with Progressive Locksmith Cerrajero
Once you have made the call on rekey, replace, or reprogram, the next step is booking the work before the gap sits open any longer than it has to. For urgent situations, such as a departure involving a master key or a suspected duplication, use the emergency lockout and rapid-response page. For scheduled commercial rekeying, lock changes, or access control upgrades, the primary services page covers the full range of work, including key programming and reprogramming for electronic systems.

Before the visit, pull together your building access list, note which doors or areas are affected, and decide whether you are leaning toward a rekey or a full replacement so the technician can quote accurately on arrival. A locksmith service provider serves Miami-Dade County properties with licensed, insured technicians and Spanish and English bilingual service. Request a visit through the services page to get a scheduled appointment or emergency response started.
Sources
This guide draws on GSA physical-protection standards, CISA’s ChemLock recommendations, and NIST SP 800-171 termination procedures, alongside practical access control guidance from Tawy Systems for organizations weighing electronic alternatives to physical keys.
FAQ
How fast should we rekey after an employee leaves?
Act within the first 24 to 72 hours, especially if the departing employee held a master key or any credential is unreturned. GSA guidance treats termination as a trigger for immediate key or combination changes, not a task to schedule later.
What is the difference between rekeying and replacing a lock?
Rekeying changes the internal pins so old keys no longer work, while the existing hardware stays in place. Replacement swaps the entire lock, which makes sense when hardware is damaged, outdated, or a key may have been duplicated without authorization.
Do we need a locksmith for electronic access changes too?
Yes, when fob or card-based systems are involved, a locksmith with programming experience can add, remove, or reissue credentials and clean up any mismatched records. This is often faster than a full physical rekey and gives you remote revocation capability going forward.
What should our key return policy document?
At minimum, track who was issued each key or credential, the date issued and returned, which areas it accessed, and what action a locksmith took afterward. NIST SP 800-171 recommends documenting termination actions like disabling access and retrieving security property as standard practice.
What happens if a key is never returned?
Treat any unreturned key as a rekey trigger for every lock it opened, particularly if it was a master key. CISA’s ChemLock guidance calls for rekeying or replacing locks whenever compromise is suspected, and an unreturned key qualifies.
Recommended


Comments