Audit and assurance

SOC 2 and ISO 27001: what auditors test about visitor access

Teams preparing for SOC 2 or ISO 27001 often ask which visitor fields the standard requires. Neither says. What both examine is whether the control you described was actually running, every day, for the whole period, which is a harder test than any field list.

This distinction changes what you should spend effort on. A rich visitor record that is only filled in when reception is quiet will fail. A simple one that is filled in every time will pass.

SOC 2: the Type II difference

The physical access criterion, CC6.4, concerns restricting physical access to facilities and protected information assets to authorised personnel. It does not enumerate a log format.

A Type I report says a control was designed appropriately on a given date. A Type II report says it operated effectively across a period, typically six or twelve months. That is where visitor management usually causes trouble: the design is fine and the operation is patchy. An auditor sampling three days in March and finding an empty log has an exception, regardless of how good the policy reads.

ISO 27001: Annex A 7.2 and 7.4

Annex A 7.2 covers physical entry controls, requiring secure areas to be protected by appropriate entry controls so only authorised personnel gain access. A 7.4 covers physical security monitoring. Under an ISMS, the expectation is not only that records exist but that they are reviewed, and that the review is itself evidenced.

The word doing the work in both is appropriate. You decide what is appropriate for your risk, document that decision, and are then held to it. Setting a standard you cannot sustain is worse than setting a modest one you meet.

What evidence actually looks like

  • Continuity. A record covering every day the site was open. Gaps are the single most common finding.
  • Traceability to a person. Each visit tied to an employee who authorised it, so the control has an accountable owner rather than a process.
  • Closure. Check-outs recorded, not just check-ins. An access record with no exit is an incomplete story.
  • Exceptions handled visibly. Auditors are not surprised that something went wrong; they look for whether it was noticed and addressed.
  • Retention matching policy. If your policy says ninety days, records from two years ago are a finding in the other direction.

The practical argument for automating it

Consistency is exactly what manual processes fail at, and exactly what these audits test. A paper book depends on a busy person doing the same thing correctly every time for a year. A kiosk that will not complete sign-in without the required fields produces uniform records by construction.

Where BeckonDesk fits

Sign-in produces a consistent record per visit: visitor, company, host, timestamps in and out, badge number, and any questions or documents your visitor type requires. Retention is configurable per tenant so the period matches your stated policy rather than drifting from it, and each tenant's data is isolated at the database level.

Related reading

See it on your own site.

A 30-minute walkthrough of sign-in, screening, and the record an auditor asks for. 30-day free trial, no credit card.

Get started Book a demo