
Property crime remains a persistent and expensive problem for UK and international businesses alike, with theft, vandalism and unauthorised entry costing organisations dearly every year. Access control equipment has become one of the most effective tools for tackling this risk, giving businesses precise control over who can enter a building, when, and under what conditions. Rather than relying on physical keys that can be lost, copied or passed on without oversight, modern systems use credentials such as cards, biometrics, PIN codes and mobile devices to authenticate authorised users at every entry point. This article examines the core equipment behind commercial access control, the different technologies available, how these systems integrate with wider security infrastructure, the compliance obligations businesses need to understand, and the trends shaping where the technology is heading next.
Understanding access control systems for commercial premises
A commercial access control system is a security solution built to restrict and monitor entry to buildings, rooms or specific zones. Instead of a traditional lock and key, these systems authenticate users through credentials such as keycards, PIN codes or biometric data, and they log every access attempt to create an audit trail. This record is useful for identifying suspicious activity, since each unlock attempt is timestamped and stored, and it can also be cross-referenced with video footage if the system is integrated with CCTV.
The right configuration depends heavily on the number of users, the number of entry points, and the levels of access required across an organisation. Some businesses need only a simple model where all users share the same rights; others require role-based permissions that vary by department, seniority or job function. Getting this balance right from the outset avoids costly reconfiguration later, particularly as a business grows and its security requirements become more complex.
Key components: readers, controllers, and credentials
Every commercial access control system, regardless of complexity, is built from the same basic building blocks:
- Readers: devices installed at doors, gates or other entry points that capture credential data, whether from a card, fob, PIN or biometric scan.
- Controllers: the hardware that receives data from the reader, checks it against permissions stored in the system, and instructs the locking mechanism to grant or deny access.
- Credentials: the means of identification presented by the user, such as an RFID card, key fob, mobile credential or biometric marker.
- Locking mechanisms: electric strikes, magnetic locks or motorised bolts that physically secure the door until a valid credential is presented.
These components work together so that only authorised personnel can pass through a controlled point, while the system simultaneously builds a record of activity that can be reviewed later.
Standalone versus networked access control architecture
Traditional commercial access systems are built around a central control panel connected by hardwired cables to door readers and locking mechanisms. This approach is often considered highly secure, but it has a practical limitation: a single control panel can only support a fixed number of access points. A building with many entrances that exceed this capacity would need multiple panels, or would have to limit the number of controlled doors.
IP-based, networked systems connect components over Ethernet or Wi-Fi instead. This makes them far more versatile, since expansion doesn’t require installing additional control panels, and multiple sites can be managed from a single dashboard. The trade-off is that because components typically connect to the internet, networked systems carry a greater exposure to hacking and cyber attack, making strong cybersecurity practices essential wherever this architecture is chosen.
Wiegand protocol versus OSDP communication standards
The way a reader communicates with its controller matters for both security and future flexibility. Wiegand has long been the standard protocol for connecting card readers to controllers, but it transmits data one-way and in an unencrypted format, which makes it vulnerable to interception. The Open Supervised Device Protocol (OSDP) was developed as a more secure alternative, supporting encrypted, two-way communication between reader and controller. This allows the controller to supervise the reader’s status continuously and detect tampering or line faults, something Wiegand cannot do. Businesses upgrading or specifying new equipment should weigh up whether their chosen readers and controllers support OSDP, particularly where higher security assurance is required.
Types of access control equipment for business environments
Companies can choose from a wide variety of access control equipment, and most commercial deployments combine several credential types to suit different areas or user groups within the same site.
Proximity card and RFID-Based entry systems
Card and key fob systems remain among the most common access control credentials. These typically use RFID technology, allowing the card or fob to communicate wirelessly with a door reader to unlock it. They offer convenience and are straightforward to issue and revoke, but they carry the risk of being lost, stolen or copied without oversight. Regularly managing and updating the system is essential to ensure that only currently authorised individuals retain valid access.
Biometric access control: fingerprint, facial recognition, and iris scanning
Biometric access control uses unique physical characteristics, such as fingerprints or facial features, to authenticate a user’s identity. Because this removes the need for a physical credential altogether, it provides a level of security that is very difficult to replicate or bypass, eliminating risks associated with lost or shared cards and fobs. Biometric systems are particularly well suited to high-security areas or organisations protecting sensitive intellectual property, though the storage and handling of biometric data brings additional data protection obligations, covered later in this article.
Keypad and PIN-Based access terminals
Keypads allow users to gain entry by inputting a PIN code rather than presenting a physical credential. They are often used in place of, or alongside, a card swipe. Their main weakness is that a forgotten or shared code can undermine security just as easily as a lost card, and unlike a card reader, there is no physical item to confiscate if someone leaves the organisation. For this reason, keypads are usually best combined with another credential type, such as a card, and supported by CCTV monitoring to capture any unauthorised use of a shared code.
Mobile credentials and bluetooth low energy (BLE) access
Mobile credentials allow users to unlock doors using their smartphone, typically via Bluetooth Low Energy or similar wireless technology. These can be distributed electronically to staff and visitors, removing the need for anyone to visit a site in person to collect a physical card. This touchless approach reduces physical touchpoints, which supports hygiene as well as convenience. Mobile credentials also carry a practical security advantage: smartphones are usually locked by the user themselves, whereas a lost physical card has no such built-in protection.
Turnstiles, speed gates, and mantrap configurations
For higher-traffic or higher-security sites, access control extends beyond doors to physical barriers such as turnstiles and speed gates, which only permit entry once a valid credential has been presented. Mantrap configurations use a small enclosed space with two interlocking doors, ensuring that only one person can pass through at a time and preventing « tailgating, » where an unauthorised person follows closely behind someone with valid access. These solutions are commonly deployed in lobbies, data centres and other areas where controlling the flow of people is as important as verifying their identity.
Integrating access control with broader security infrastructure
Access control rarely operates in isolation. Its value increases substantially when connected to other security and building systems, allowing data sharing, process automation and more efficient management across hardware, software and devices from a single platform.
Access control and CCTV surveillance synchronisation
Connecting access control to video security cameras allows the system to automatically associate timestamped video with every unlock attempt at a door. This gives a business a visual record of access activity on the premises, which is invaluable for investigating incidents such as an attempted break-in, an altercation, or a dispute over who entered a particular area and when. Displaying access and video events together in a single dashboard also makes day-to-day monitoring considerably easier for security teams.
Fire alarm interlock and emergency lockdown protocols
Any electronically locked door must be designed to fail safely in the event of a fire alarm, releasing automatically so it does not trap occupants during an evacuation. This is a fundamental requirement rather than an optional feature, and it must be verified through regular testing. At the other end of the spectrum, access control systems can also support lockdown protocols during a critical incident, restricting movement throughout a building when a full or partial lockdown is required. Balancing these two functions, safe egress during a fire and restricted movement during a security incident, requires careful design and clear documentation to demonstrate ongoing compliance.
Building management system (BMS) integration
In larger commercial buildings, access control increasingly connects with wider building management functions, from elevator control to visitor management software and tenant experience platforms. This kind of integration allows a single system to manage not just who can enter the building, but also which floors they can reach, how visitors are logged and issued credentials such as QR codes, and how the space is used over time. Physical security systems of this kind can also generate valuable analytics on building utilisation, helping landlords and facilities managers plan staffing, cleaning and space allocation more effectively.
Reducing unauthorised entry through layered security zones
Rather than treating a building as a single secured perimeter, effective access control divides a site into layered zones with progressively stricter requirements. A main entrance might remain open to the public during business hours, while storerooms, back offices, server rooms and other sensitive areas require additional authentication. This zoning approach means that even if someone gains entry to a public area, they still face further barriers before reaching higher-value assets or confidential information.
Layering can combine multiple credential types for extra assurance in the most sensitive areas, such as requiring both a card and a PIN, or a card and a biometric scan, for two-factor authentication. It also allows businesses to tailor access by role: a member of staff might have access to their department’s offices but not to a server room or an executive suite, while contractors or visitors are restricted to specific, time-limited zones. This structure significantly reduces the risk of unauthorised movement throughout a facility, even where a breach occurs at a lower-security entry point.
Compliance and regulatory considerations for UK commercial sites
Access control equipment doesn’t operate in a regulatory vacuum. UK commercial buildings must satisfy requirements spanning data protection, fire safety and recognised technical standards, and these obligations should shape equipment selection from the outset rather than being treated as an afterthought.
GDPR implications for biometric data storage
Where an access control system stores or processes personal data, such as fingerprint templates, facial recognition data or access logs tied to named individuals, building owners must comply with UK GDPR and the Data Protection Act 2018. This includes secure storage of that data, controlled access to the records themselves, and clear communication to staff and visitors about how their information is collected and used. Biometric data is particularly sensitive, so businesses deploying fingerprint or facial recognition readers need robust policies covering retention periods, who can access stored templates, and how that data is protected against breach.
BS EN 60839 standards for alarm and access systems
Several British and European standards govern the design, installation and performance of access control equipment. BS EN 60839-11-1 defines system design, installation and maintenance requirements for electronic access control specifically. Alongside this, BS EN 50133-1 specifies functional and grading requirements so that a system’s resilience matches the risk profile of the building it protects. Other relevant standards include BS EN 179 and BS EN 1125, which govern emergency exit devices to ensure panic and emergency hardware can override electronic locks, and BS EN 1155, which covers electrically powered hold-open devices for fire doors. PAS 24 sets enhanced security performance requirements for door sets and hardware, while BS 7858 relates to the vetting and screening of personnel who install and maintain security systems. Compliance with these standards gives building owners assurance that equipment will perform as expected under both normal and emergency conditions.
Fire safety order 2005 and egress requirements
The Regulatory Reform (Fire Safety) Order 2005 places a clear responsibility on the « responsible person » for a building to maintain safe evacuation routes at all times. Any electronically locked door must therefore be designed to fail safely and release automatically when a fire alarm is triggered, so that the access control system never prevents occupants from evacuating. Building Regulations 2010, specifically Approved Document B on fire safety and Approved Document M on access to and use of buildings, set further standards to ensure both fire integrity and accessibility, including safe egress for users with disabilities. Reviewing access control integration with fire systems should form part of routine fire risk assessments, with regular testing and thorough documentation to demonstrate ongoing compliance.
Selecting the right access control solution for Site-Specific risks
Choosing appropriate access control equipment starts with an honest assessment of a site’s specific risks rather than defaulting to the most feature-rich system available. A business developing new products with valuable intellectual property may need stringent measures such as two-factor authentication and multiple authorisation levels across different areas. A retail store or landscaping business, by contrast, may need a much simpler system that keeps a main entrance open to the public during trading hours while restricting stockrooms and back offices to employees only.
The number of entry points is another key factor. A single small office with one or two doors requires a far simpler system than a multi-tenant commercial building with numerous access points, parking facilities, turnstiles and elevators, all of which ideally sit within a single management platform. Businesses with multiple locations should also consider a networked system, since this allows every site to be monitored and controlled from one dashboard rather than managing separate systems in isolation.
The number of users matters just as much. An organisation with hundreds of employees, plus a steady flow of visitors and contractors, needs a system that can handle multiple user profiles with different access privileges, and that makes adding or removing users straightforward. Beyond user volume, businesses should weigh:
- Compatibility with existing security components, so that access control, CCTV and alarm systems can share data and automate processes together.
- Scalability, ensuring the system can accommodate more access points, users and custom functions as the business grows, avoiding a costly full replacement later.
- Reliability, since a door that fails to lock properly, or connectivity that drops during a power or internet outage, can create serious security gaps or unintended lockouts.
- Ease of use, so that configuring the system, managing user profiles and setting access privileges doesn’t require extensive training or risk user error.
- Provider expertise, working with an experienced installer who understands the relevant industry, technology and compliance requirements, and who offers strong ongoing technical support.
Cost is also a legitimate consideration, but it should be weighed against the value of the assets, data and people the system is protecting, along with the ongoing costs of maintenance and support rather than the upfront price alone.
Future trends in commercial access control technology
Access control technology continues to evolve as businesses look for more efficient, secure and cost-effective ways to manage entry across their sites.
Cloud-based access management platforms
Cloud-based access control systems are hosted on remote servers and connect via the internet, rather than requiring an on-site server and local network. This model can be more cost-effective than an on-premise system, since it eliminates the need to invest in and maintain expensive server hardware, replacing that cost with a subscription to a third-party hosting provider. Cloud-native systems are also easier to scale and can be managed remotely from any location, which is particularly valuable for businesses operating across multiple sites. The trade-off is that cloud-based systems can be vulnerable to hacking or misuse if strong cybersecurity policies are not in place, so this remains an essential consideration alongside the operational benefits.
Ai-driven anomaly detection in entry patterns
As access control systems generate increasing volumes of entry and exit data, there is growing scope to use that data not just for historic audit trails but for identifying unusual patterns as they happen. Real-time visibility into access activity helps businesses spot suspicious behaviour, such as repeated failed attempts at a particular door or access occurring at unexpected times, and respond more quickly than manual review would allow. This kind of pattern analysis also feeds into wider building analytics, helping owners understand occupancy and utilisation trends across a site and plan resourcing accordingly.