Insurance and access control: how coverage rules are changing
Why renewal questionnaires now ask about door security, what an audit trail does for a theft claim, and the questions worth bringing to your broker.
One disclaimer before anything else. We are installers, not insurance professionals. We have been putting security systems into Orange County commercial buildings since 1984, so we see what happens on the building side of these conversations, but your broker or agent is the only person who can tell you how your specific policy is rated and what your carrier requires. Treat everything below as field notes to bring to that conversation, not as coverage advice.
With that said, the pattern is real. Ten years ago the security section of a commercial application was often one line about locks and an alarm. Now we get calls from property managers in Irvine and practice managers in Mission Viejo who have a renewal questionnaire in front of them and a set of questions their old key-and-deadbolt setup cannot answer well. This article is about why that is happening and what to do about it.
Why underwriters started caring about your doors
A few pressures are stacking up on the carrier side, and none of them are secrets. Commercial theft and burglary losses have been a sore spot for insurers, especially in retail, construction, and warehousing. Buildings sit empty more than they used to, between hybrid schedules and after-hours vacancy, and an empty building is where losses happen. And key systems turn out to be easy to defeat socially. Nobody has to pick a lock when a former employee still has a copy, or when a "locksmith" talks their way into cutting one.
So the underwriting question has shifted. It used to be "do you have locks and an alarm." Increasingly it is "who has access to this building, how do you take access away, and can you prove any of it." That is a different question, and a bowl of brass keys does not have a good answer to it. A managed access platform does, almost as a side effect of existing.
We want to be careful not to overstate this. Not every carrier asks these questions, and plenty of small policies still renew on a short application. But the direction of travel is consistent across what our customers show us, and brokers we talk to say the same thing: the security questions are getting longer and more specific, particularly for larger schedules and tougher classes of business.
The renewal questionnaire, and how you answer it
Here are the kinds of questions we see showing up on commercial renewals and new-business applications. Your exact form will differ, but the themes repeat.
- Is the premises protected by a burglar alarm, and is it centrally monitored? Local-only sirens increasingly get treated as a weaker answer than central-station monitoring.
- Are building entries controlled? By what means? Some forms now distinguish between keyed locks, keypad codes, and credentialed electronic access.
- How is key or credential issuance managed? Who has access, how is it granted, and what happens when an employee leaves.
- Is there video surveillance, and how long is footage retained? Retention windows matter because claims get reported late.
- When were the systems last inspected or serviced? A system nobody maintains is a system the carrier discounts.
Notice what happens to those questions depending on what is in the building. For a key-based building, most of them are essay questions. You are writing paragraphs about a spreadsheet you keep sometimes, and about a rekeying you did after the manager left in 2023, probably. For a building with cloud access control, they collapse into checkbox answers. Entries controlled, yes, electronic. Credentials revoked same day via the management portal. Event history retained per the subscription, exportable on request.
Underwriters read a lot of applications. Crisp, verifiable answers read differently than hopeful ones, and while we cannot tell you what that is worth in premium on any given policy, we can tell you it changes the tone of the renewal conversation. Your broker can tell you whether it changes the number.
| Insurance question | Key-based building | Cloud access building |
|---|---|---|
| Who has access to the building? | Whoever has a key, plus every copy ever made | The current credential list in the portal, exact to the person |
| What happens when an employee leaves? | Ask for the key back, rekey if you are diligent | Credential revoked the same day, with a record of when |
| Can you show who entered before the loss? | No | Time-stamped entry events per door, alongside camera footage |
| Is after-hours access restricted? | Only by trust | By schedule, enforced automatically per credential |
| Is the system maintained? | Hard to evidence | Service records plus platform health monitoring |
Claims: what an audit trail actually does
This is where we have watched access control earn its cost, and it has nothing to do with premium. Picture a theft from a storage room, discovered Monday morning, no forced entry. In a key-based building the file starts with "someone must have had a key," which is where it usually stalls too. Was it burglary? Employee theft? A vendor? The adjuster has to sort that out from almost nothing, and that sorting takes time and produces questions.
The same loss in a building with access control starts with a list: every credential that opened that door over the weekend, with timestamps, next to camera footage from the same clock. The question of who was inside is answered on day one instead of being litigated by memo. Whether it was covered still depends on the policy, but the factual part of the file is done.
This matters even more on employee-dishonesty and fidelity claims, where the whole dispute is about proving that a specific person did a specific thing. Being able to show that one credential entered the records room at 11 p.m. on a night that person was not scheduled is exactly the kind of evidence those claims live or die on.
The honest hedge: documentation does not guarantee payment. Adjusters deny well-documented claims and pay thin ones, based on policy language, exclusions, and facts we never see. What we can say from experience is that adjusters ask for this material, and the building that has it is in a much better position than the building explaining why it does not.
Protective safeguards: the fine print that bites
Some commercial policies condition part of the coverage on a security system existing and working. These provisions go by a few names, protective safeguards endorsements being the common one. The idea is simple. The carrier priced the policy assuming the alarm you told them about is armed and functional, so if a loss happens while that system was disabled, unmonitored, or bypassed, the claim can be jeopardized.
We have seen how that failure happens in the real world, and it is rarely dramatic. The last person out forgets to arm the panel. A door that never quite latches gets propped open through the summer. The monitoring contract lapses because the invoice went to someone who quit. None of that feels like a coverage decision at the time, but under one of these endorsements it can become one.
Access control helps here in a mechanical way. Doors lock on a schedule instead of relying on the last person out. Door-held-open and door-forced alerts surface the propped door the day it starts instead of months later. And when the access platform is integrated with the alarm, arming can happen automatically after the last credentialed exit, which removes the "forgot to arm it" failure mode almost entirely. If your policy carries a safeguards endorsement, that automation is not a convenience feature. It is protecting the coverage itself. Ask your broker whether your policy has one, because plenty of owners find out at claim time.
The liability side: negligent security
Property coverage is only half the picture. The other half is premises liability, and the claim type to think about is negligent security: someone is harmed on your property and alleges you failed to take reasonable steps to control who could get in. These cases turn on what was reasonable and what you can show, and "the door was controlled, entries were logged, and visitors went through a sign-in process" is a materially better position than "the back door was usually locked."
For landlords of multi-tenant buildings this is the exposure that matters most, because the common areas, lobbies, and parking structures are yours even when the suites are not. Controlled entries, a visitor process, and per-tenant credentialing are the backbone of a defensible answer, and they are the same features that make a multi-tenant building easier to run day to day. We wrote up how that works in practice in our guide to multi-tenant office access control.
What to actually ask your broker
Bring these to your next renewal conversation. They are short questions with useful answers, and a good broker will not mind any of them.
- Does my policy have a protective safeguards endorsement or any condition requiring a security or alarm system to be operational?
- Would electronic access control, central-station monitoring, or camera coverage change my rating or eligibility with my current carrier?
- Are there security questions on my renewal application that my current setup answers poorly?
- If I upgrade the building's security mid-term, should we notify the carrier now or note it at renewal?
- For a theft or employee-dishonesty claim, what documentation would the adjuster expect from us?
- Does my premises liability coverage assume any particular level of entry control or visitor management?
The paperwork to keep on your side
Whatever your broker comes back with, the building side of the job is documentation. Keep a folder, physical or shared drive, we do not care which, with four things in it.
On cost, none of this requires an enterprise system. The cloud platforms we install for Orange County businesses land in the range we lay out in our commercial access control cost guide, and the insurance-relevant features, credential management, event history, schedules, and alarm integration, come standard rather than as add-ons.
Our suggestion is simple. Before your next renewal, read the security section of your application next to your actual building, and see which questions you would rather not answer under your current setup. Then have two conversations, one with your broker about what your carrier cares about, and one with an installer about what it costs to fix. We are happy to be the second call.
Insurance and access control: quick answers
Tighten up before renewal.
Tell us about your building and we will walk it, flag what a renewal questionnaire will ask about, and price only what actually moves the needle.