Compliance guide
Visitor log requirements: what US regulations actually say.
There is no single federal law that says "keep a visitor log." Instead there is a patchwork of sector rules, general duties, and insurer expectations that together make an accurate visitor record a practical requirement for most industrial and regulated facilities. Here is the map.
OSHA
The general duty, not a log mandate
OSHA does not have a standard that explicitly requires a visitor log. What it has is the General Duty Clause (Section 5(a)(1) of the OSH Act): employers must furnish a workplace free from recognized hazards. In practice that pulls visitor records in three ways. First, site-specific hazard training: if visitors or contractors enter operational areas, you need evidence they were inducted on the hazards, and evidence means a record tied to a named person on a dated visit. Second, incident investigation: after an injury involving a non-employee, OSHA and your own investigation need to establish who was on site, where, and with what authorization. Third, emergency action plans under 29 CFR 1910.38: a plan must account for everyone on site during an evacuation, which is impossible without knowing who is on site.
CFATS and chemical facilities
Access control as a security measure
Chemical facilities that were regulated under CFATS, and those following its successor guidance and state equivalents, treat visitor identification and escort as core security measures: verifying identity before entry, recording who entered which restricted areas, and screening against ban lists. Facilities with chemicals of interest typically maintain visitor records with identity verification as part of their site security plan, whatever the current federal enforcement posture.
FSMA and food facilities
Food defense means knowing who was inside
The FDA Food Safety Modernization Act Intentional Adulteration rule requires covered food facilities to run a food defense plan mitigating insider and visitor risk at actionable process steps. Auditors under SQF, BRCGS, and FSSC 22000 read that as: signed-in visitors, escorted access to production areas, and records that show who was inside on any given date. A paper book with illegible scrawls fails that audit conversation quickly.
C-TPAT and supply chain security
Visitor controls as a certification criterion
Importers and logistics operators certified under C-TPAT commit to minimum security criteria that include visitor controls: photo identification checks, visitor logs or electronic records, escorts in cargo areas, and challenge procedures for unidentified persons. The visitor record is audited at validation and revalidation visits.
Insurers and litigation
The expectations beyond regulation
Two non-regulatory forces push harder than most regulations. Property and liability insurers increasingly ask, at renewal, how site access is controlled and whether an accurate on-site list exists for emergencies; weak answers move premiums. And in litigation after an incident, the visitor record is discoverable evidence: an accurate, timestamped electronic record protects the facility, while a gap or a back-filled paper book becomes the plaintiff's exhibit.
What a defensible record looks like
Six properties
- Identity captured, not just a name. Name plus company plus host plus photo where policy allows.
- Timestamped in and out. Arrival and departure, machine-recorded, not hand-written.
- Screened at entry. Sanctions, watchlist, and internal ban list checked before the badge prints.
- Inductions and documents attached. Site rules signed, hazard induction completed, contractor insurance verified, all on the visit record.
- Retained on a schedule. Kept long enough for incident and audit windows, purged on schedule for privacy compliance.
- Retrievable in seconds. "Who was on site on March 12" answered with a filter, not an afternoon in a filing cabinet.
Replace the paper book before the next audit.
BeckonDesk produces the defensible record automatically: screened entries, timestamps, inductions, and instant retrieval.