{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Safe Key Holding and Access Management Policy
1. Purpose
The purpose of this policy is to ensure the safe and responsible management of keys and access to service users’ homes and facilities within {{org_field_name}}. The secure handling, storage, and usage of keys are critical to safeguarding service users, preventing unauthorised access, and ensuring compliance with Care Quality Commission (CQC) Fundamental Standards and data protection regulations.
This policy provides a structured approach to key holding, ensuring that service users feel safe and confident in the integrity of our care workers while maintaining strict security protocols.
2. Scope
This policy applies to all employees, care workers, agency staff, management, and any third parties authorised to hold or access keys. It covers:
- Procedures for key allocation and storage.
- Security protocols for key handling and return.
- Access management and authorisation.
- Incident reporting for lost, stolen, or unauthorised key use.
- Compliance with legal and regulatory requirements.
- Staff training and responsibilities.
- Auditing and monitoring procedures.
3. Legal and Regulatory Framework
This policy must be implemented in accordance with applicable legislation and regulatory requirements in England, including:
- Health and Social Care Act 2008 – provides the statutory framework for the regulation of health and adult social care services in England and the functions of the Care Quality Commission.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, including, where relevant to key holding and access:
- Regulation 9 – Person-centred care, requiring care and treatment to reflect the service user’s needs and preferences.
- Regulation 10 – Dignity and respect, including the requirement to protect the service user’s privacy and support their autonomy and independence.
- Regulation 11 – Need for consent, requiring care and treatment to be provided only with the consent of the relevant person and requiring the Mental Capacity Act 2005 to be followed where a person aged 16 or over lacks capacity to make the relevant decision.
- Regulation 12 – Safe care and treatment, requiring risks to the health and safety of service users to be assessed and reasonably practicable measures taken to mitigate those risks.
- Regulation 13 – Safeguarding service users from abuse and improper treatment, requiring effective systems to prevent, identify and investigate abuse or improper treatment.
- Regulation 17 – Good governance, requiring effective systems for assessing, monitoring and mitigating risks and for maintaining accurate, complete and contemporaneous records.
- Regulation 20 – Duty of candour, where an incident associated with key holding or access meets the statutory criteria for a notifiable safety incident.
- Care Quality Commission (Registration) Regulations 2009, including Regulation 18 – Notification of other incidents, which requires specified incidents, including relevant allegations or evidence of abuse, to be notified to the Care Quality Commission without delay.
- Mental Capacity Act 2005 and its Code of Practice – apply where a service user may lack capacity to make a particular decision about access to their home, key holding, key-safe arrangements or associated care and support.
- UK General Data Protection Regulation and Data Protection Act 2018 – apply to the collection, use, storage, disclosure and security of personal information associated with keys, addresses, key-safe codes, alarm codes and other access arrangements.
- Health and Safety at Work etc. Act 1974 – applies to the organisation’s responsibilities for the health and safety of employees and others who may be affected by its activities.
All staff must comply with this policy together with the organisation’s safeguarding, consent and mental capacity, data protection, incident reporting, duty of candour and risk management policies.
4. Key Allocation and Access Authorisation
Keys, key-safe codes, door-entry codes or other means of accessing a service user’s home must only be accepted, held, recorded or used where there is a lawful and clearly documented reason for doing so.
The following requirements apply:
- Service User Consent: Where the service user has capacity to decide about key holding and access to their home, their informed consent must be obtained and recorded before the organisation accepts responsibility for a key, key-safe code or other access arrangement. The service user must be informed of the proposed arrangements, including who may have access and the circumstances in which access may be used.
- Continuing Consent: Consent must be treated as an ongoing process. A service user who has capacity may change or withdraw their consent to key holding or access arrangements. Any withdrawal or change must be acted upon promptly and the care plan, access instructions and relevant records must be updated.
- Mental Capacity: A service user must be presumed to have capacity unless it is established otherwise in accordance with the Mental Capacity Act 2005. Where there is reason to doubt the person’s capacity to make the specific decision about key holding or access to their home, an appropriate decision-specific capacity assessment must be completed and recorded.
- Where the Service User Lacks Capacity: Where the service user lacks capacity to make the relevant decision, staff must not obtain consent merely from a relative, next of kin or other informal representative. Any decision must be made in accordance with the Mental Capacity Act 2005, including its best-interests requirements, unless a person with lawful authority is entitled to make the particular decision on the service user’s behalf.
- Attorney or Deputy: Where a person purports to make the decision on behalf of the service user under a registered Lasting Power of Attorney or an order appointing a deputy of the Court of Protection, the organisation must establish that the person’s authority applies to the particular decision before relying on it. Evidence of the relevant authority must be recorded appropriately.
- Risk Assessment: Before key holding or other access arrangements commence, the organisation must assess relevant risks to the service user’s safety, security, privacy and welfare. The assessment must consider the person’s individual needs and preferences, the proposed method of access and any foreseeable consequences of loss, theft, disclosure or misuse.
- Care and Access Plan: The agreed access arrangements must be clearly recorded in the service user’s care plan or associated access record. This must include, as applicable:
- the authorised means of access;
- when and why staff are permitted to use it;
- any requirement to knock, call or otherwise announce arrival before entry;
- any individual safety or security instructions;
- emergency access arrangements;
- any restrictions imposed by the service user or lawful decision-maker.
- Authorisation Records: The organisation must maintain an accurate and up-to-date record of keys or other access credentials held. The record must include sufficient information to establish:
- the service user to whom the access arrangement relates;
- the authorised key holder or persons permitted to access the information;
- the reason for holding or providing access;
- the date of issue or commencement;
- where applicable, the date of return, cancellation or termination.
- Secure Identification: Physical keys must not display the service user’s name, full address or other information that would enable an unauthorised person who obtained the key to readily identify the property.
- Authorised Access Only: Keys, key-safe codes and other access information may only be provided to staff or other persons who require them for authorised purposes connected with the provision of the service.
5. Key Security, Storage and Handling
Keys and access information must be managed in a way that protects service users from foreseeable risks of unauthorised entry, theft, abuse, loss of privacy or other harm.
The following requirements apply:
- Secure Storage: Keys held at the office must be kept in a locked and access-controlled location. Access must be restricted to authorised persons.
- Minimum Access: Access to service user keys, key-safe codes and other access credentials must be limited to staff who require access for an authorised work purpose.
- Secure Coding: Keys must be identified by a secure code or reference that does not reveal the service user’s identity or home address if the key is lost or obtained by an unauthorised person.
- No Unauthorised Duplication: Staff must not copy, duplicate or arrange the duplication of a service user’s key unless this has been specifically authorised by the organisation and by the person legally entitled to authorise the duplication.
- Off-site Key Holding: A service user’s key must not routinely be stored in a staff member’s home, unattended vehicle or other personal location. Where operational circumstances require an authorised member of staff to retain a key away from the office, this must be specifically authorised by the organisation, supported by an assessment of the risks and subject to appropriate security arrangements.
- No Unattended Identifiable Keys: Keys must not be left unattended together with information that identifies the service user’s name or address.
- Check-out and Check-in Records: Where physical keys are issued to individual staff, an accurate record must identify who has taken possession of the key and, where applicable, when it was issued and returned.
- Access Codes: Key-safe codes, alarm codes, entry codes and similar security information must only be disclosed to authorised persons who require the information to perform their duties. Such information must not be written on or attached to a physical key in a manner that could enable unauthorised access.
- Change in Risk: Any change that may affect the security of a key or access arrangement must be reported promptly and the associated risk assessment and access arrangements reviewed where necessary.
6. Access Management and Entry Procedures
A key, key-safe code or other means of entry must only be used for an authorised purpose and in accordance with the service user’s agreed care and access arrangements.
Staff must:
- carry appropriate organisational identification while undertaking care visits and present it where requested or appropriate;
- attend only at agreed times, subject to legitimate variations arising from the person’s care arrangements or an emergency;
- knock, ring the bell, call out or otherwise announce their arrival in the manner agreed with the service user before using a key or access code, unless the documented care plan or emergency circumstances provide a clear reason why this would be inappropriate;
- use a key, key-safe code or other access arrangement only where access has been authorised and is required for the provision of agreed care or support;
- comply with any individual access instructions recorded in the service user’s care plan or associated access record;
- respect the service user’s privacy, dignity, autonomy, preferences and home at all times;
- enter only those parts of the property reasonably required for the authorised purpose, unless an emergency or another lawful reason requires otherwise;
- not permit an unauthorised person to enter the service user’s home using a key, code or other access arrangement held by the organisation;
- secure the property appropriately when entering and leaving, taking account of the service user’s preferences and assessed risks;
- report promptly any evidence of forced entry, unexplained damage, security concern, suspected unauthorised access or circumstances suggesting that the service user may be at risk;
- follow the organisation’s emergency procedures where the service user does not answer and there is reasonable concern for their safety, rather than entering or leaving solely on personal judgement where the care plan provides an escalation procedure; and
- ensure that keys and access credentials are returned, cancelled or otherwise dealt with securely when the organisation’s authority to hold them ends.
7. Reporting Lost, Stolen, Misused or Compromised Keys and Access Information
Any loss, suspected theft, unauthorised use, unauthorised copying or disclosure of a service user’s key, key-safe code, entry code, alarm code or other access credential must be treated as a security incident and reported immediately.
The following procedure must be followed:
- Immediate Internal Reporting: The member of staff who discovers or becomes aware of the incident must notify their line manager or the person responsible for managing incidents without delay.
- Immediate Risk Assessment: The manager must assess the immediate risks to the service user’s safety, security, privacy and welfare and take proportionate action to protect the service user.
- Service User Notification: The service user must be informed as soon as reasonably practicable where they have capacity to receive and act on the information. Where appropriate and lawful, a person authorised to act for or support the service user must also be informed.
- Immediate Security Action: Depending on the circumstances and risk, action may include:
- retrieving the key or access information;
- disabling or changing an access code;
- arranging for the key safe to be reset;
- arranging additional security;
- changing locks or arranging replacement keys;
- preventing further use of compromised access information;
- ensuring that alternative arrangements are available so essential care can continue safely.
- Incident Record: An accurate and contemporaneous incident record must be completed. It must include:
- the date and time the incident occurred or was discovered;
- what key or access information was affected;
- the circumstances;
- persons known to have had access;
- the immediate risk assessment;
- action taken;
- communication with the service user or other relevant persons;
- referrals or notifications made;
- the outcome of the incident and any further action required.
- Safeguarding: Where there is an allegation, evidence or reasonable suspicion that a key or access arrangement has been deliberately misused, including suspected unauthorised entry, theft, exploitation or other abuse, the organisation’s safeguarding procedure must be initiated immediately. Appropriate referral must be made to the relevant local authority safeguarding service and to any other appropriate body in accordance with the circumstances.
- CQC Notification: The registered person must assess whether the incident is a notifiable event under the Care Quality Commission (Registration) Regulations 2009. Where the notification criteria are met, including where there is an allegation or evidence of abuse falling within Regulation 18, the Care Quality Commission must be notified without delay in the required manner.
- Police: Where theft, burglary, fraud, deliberate misuse, unauthorised entry or another suspected criminal offence may have occurred, the police must be contacted where appropriate. Immediate danger must be reported through the emergency services.
- Data Protection: Loss or unauthorised disclosure of access information that constitutes personal data must also be managed as a potential personal data breach in accordance with Section 8 of this policy and the organisation’s data protection and personal data breach procedures.
- Duty of Candour: Where the incident meets the statutory threshold for a notifiable safety incident under Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, the registered person must comply with the statutory duty of candour.
- Investigation and Learning: The organisation must investigate the incident to the extent necessary and proportionate to the circumstances, identify any failure in systems or practice, and implement and record required corrective action.
8. Confidentiality, Data Protection and Access Information
Information concerning a service user’s home address, key-safe code, door-entry code, alarm code, location of a hidden key or other access arrangements must be treated as confidential and protected against unauthorised access, disclosure, alteration, loss or destruction.
Personal data processed in connection with key holding and access arrangements must be handled in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and the organisation’s data protection policies.
The following requirements apply:
- access information must only be collected, used and disclosed where there is an appropriate and lawful purpose connected with the provision or management of the service;
- access must be restricted to staff and other authorised persons who require the information for their duties;
- personal data and access information must be adequate, relevant and limited to what is necessary for the relevant purpose;
- records must be accurate and kept up to date where necessary;
- written and electronic records must be protected by appropriate organisational and technical security measures;
- electronic systems containing access information must be subject to appropriate access controls, including individual user access and authentication measures where applicable;
- staff must not share key-safe codes, addresses, alarm codes or other security information through unauthorised communication channels or with persons who have no authorised need to receive the information;
- access information must not be retained for longer than is necessary in accordance with the organisation’s retention arrangements;
- when the organisation no longer has authority or a legitimate need to hold an access code or similar information, the information must be securely deleted, destroyed or otherwise rendered inaccessible as appropriate;
- any actual or suspected loss, disclosure, unauthorised access or other compromise of personal data must be reported immediately through the organisation’s personal data breach procedure;
- every personal data breach must be documented in accordance with applicable data protection requirements, including the circumstances, effects and remedial action taken;
- where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the organisation must notify the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach; and
- where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, the organisation must communicate the breach to that individual without undue delay unless an applicable legal exception applies.
9. Staff Training and Responsibilities
To ensure the safe handling of keys, all staff must undergo:
- Mandatory key-holding and access training during induction.
- Regular refresher training on security and safeguarding protocols.
- Scenario-based training on handling key-related incidents (e.g., lost keys, security breaches).
- Accountability Awareness – Staff must acknowledge and sign a key-holding agreement outlining their responsibilities.
10. Monitoring, Auditing and Policy Enforcement
{{org_field_name}} must operate effective systems for monitoring compliance with this policy and for identifying, assessing and mitigating risks arising from key holding and access arrangements.
The following requirements apply:
- key-holding, key issue and return, access and incident records must be maintained accurately, completely, securely and contemporaneously;
- records relating to individual service users must be updated promptly where consent, capacity, access arrangements, risks or authorised persons change;
- audits must examine whether key and access arrangements are operating safely and in accordance with this policy, service users’ agreed arrangements and applicable regulatory requirements;
- identified risks, deficiencies, incidents, patterns or repeated failures must be assessed and proportionate corrective action taken without unnecessary delay;
- corrective actions arising from audits, incidents or reviews must be recorded, allocated to an appropriate responsible person and followed through to completion;
- where an identified concern affects an individual service user, their risk assessment, care plan or access arrangements must be reviewed and updated where necessary;
- staff compliance with key security and access arrangements must be monitored, and appropriate supervision, additional training or management action must be taken where shortcomings are identified;
- feedback and concerns from service users or their representatives concerning staff access to their homes must be considered as part of quality monitoring;
- serious or repeated failures must be escalated to the registered manager or other appropriate senior person;
- suspected misconduct, deliberate unauthorised access, theft or misuse must be managed under the appropriate safeguarding, disciplinary and incident management procedures; and
- audit and monitoring records must provide evidence of risks identified, decisions taken, actions completed and improvements made.
11. Policy Review and Updates
This policy is reviewed annually or sooner if significant regulatory changes occur. Any updates will be communicated to all staff, and additional training will be provided as necessary.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.