
Access Control Testing Checklist for India (2026): Every Door Opens and Locks as Designed
A ready-to-adapt per-door and system checklist to verify an access-control installation at commissioning and as a periodic check, with the egress and fire-to-release life-safety tests that must always pass before sign-off.
The controllers are wired, the readers beep, the doors clunk shut, and the installer is ready to invoice. This is exactly the moment an access-control system gets signed off on a walk-past instead of a test. Someone taps one card at the main door, sees it open, and calls it done. Meanwhile nobody has confirmed that a fire signal releases the escape doors, that a request-to-exit button actually frees the lock, or that the store-room stays secure when the power drops. An access control testing checklist turns that hopeful glance into evidence: a row-by-row record that every door behaves the way the design says it should, and that people can always get out.
This page is the testing deliverable in Studio Matrx's professional security resources toolkit. It sits at commissioning, and it comes back as a periodic check. It is the natural partner of the access control door schedule: the schedule states, per opening, what each door is meant to do; this checklist proves each one actually does it. Use it alongside the broader security commissioning checklist and the device-level sensor testing guide.
Scope & how to read this. This is a ready-to-adapt professional template, not authoritative, legal or contractual wording, and it does not set any life-safety standard. The required behaviour of fire doors and escape routes is fixed by the building's fire strategy, the National Building Code and the authority having jurisdiction (AHJ) or fire officer, and by the manufacturer of the locks and controllers. Verify pass criteria with them. Access logs and credential data identify people, so handle them under the Digital Personal Data Protection (DPDP) Act, 2023. For any contract deliverable, get professional review.
What this checklist is and when you use it
An access-control testing checklist is a structured list of checks, run at a door and across the system, each recorded as Pass or Fail with a note. You use it in two situations.
At commissioning. Before handover, you test every door against the door schedule and the fire strategy. Nothing is assumed from the fact that the reader lights up. Every function is exercised, and the egress and fire-release behaviour is proven, not promised. Fails go to the snag list, get fixed, and are retested until they pass.
As a periodic check. Access hardware drifts. Batteries age, door closers sag, a REX sensor gets knocked, a fire interface relay is left disconnected after unrelated works. A lightweight version of the same checklist, run on a sensible cycle and after any change to the door hardware or the fire system, catches these before they matter. The frequency itself is a matter for your maintenance regime, the manufacturer and the fire strategy; this template records the result, it does not set the interval.
The checks, grouped
Run the door checks at every controlled opening; run the system checks once per controller or per head-end. Group them so nothing is skipped.
Per door
- Reader and credential. A valid credential is accepted and the correct person or group is granted; an invalid, expired or unenrolled credential is refused. Test both outcomes, not just the happy path.
- Lock operation. On a valid grant the lock releases, the door can open, and it re-locks correctly once closed. Confirm the lock type installed matches the schedule (for example maglock, electric strike or motorised lock).
- Fail-safe versus fail-secure. Confirm the door does what its schedule row says on loss of power: a fail-safe lock releases and frees the door, a fail-secure lock stays locked. This must match the design intent for that specific opening, never the installer's default. See below for why this is a life-safety line.
- Request-to-exit (REX). The exit button, sensor or handle releases the lock from the secure side and lets a person out, and it does so without raising a forced-door alarm.
- Door contact and monitoring. The position sensor correctly reports open and closed, and the state shows at the head-end.
- Forced-door and held-open alarms. Opening the door without a grant raises a forced alarm; propping it beyond the allowed time raises a held-open alarm. Confirm both report where they are meant to.
- Emergency release and fire interface. The break-glass or emergency release frees the door immediately, and a fire-alarm signal releases every door designated as an escape door. This is the life-safety test; it must pass.
System
- Controllers online. Every controller or door module is communicating with the head-end, with no offline or fault flags.
- Access groups and schedules. A sample of users can enter only the doors and only at the times their access group allows; someone outside the group is refused.
- Logging. Grants, denials, REX events and alarms are being written to the log with correct date and time. Confirm the system clock is right, since a wrong timestamp weakens the log as evidence.
- Anti-passback (if used). Where anti-passback is configured, a second entry without a matching exit is handled as designed. Only test this if the design actually uses it.
- Integration. If the system is tied to CCTV or the alarm, confirm an access event calls up the right camera or triggers the linked action.
Power and backup
- Battery or UPS backup. On mains loss the system stays up for its designed hold-up, and controllers report the power change.
- Door behaviour on power loss. With power removed, each door behaves per its fail-safe or fail-secure row: escape doors free, secured non-egress doors stay locked. Test this deliberately; it is routinely skipped.
Documentation
- The tested door schedule, the completed checklist, the snag list and its close-out, and any updated as-built information are handed over as the test record.
Life-safety: egress and the fire-to-release test must pass. People must always be able to leave. Every escape door must open from the inside without a credential, the emergency release must free the door at once, and a fire-alarm signal must release every designated escape door so occupants can get out. A fail-secure lock on an escape route, or a fire interface that does not actually release, is a life-safety defect, not a snag to defer. Never leave an escape door that fails locked. Which doors are escape doors and how they must behave is set by the fire strategy and the National Building Code, so verify the required behaviour with the fire officer or AHJ and prove it under test before sign-off.
Worked example: a filled testing checklist
Example only, adapt to your project. Values are generic and illustrative. Door references, groups and pass criteria come from your own door schedule, fire strategy and manufacturer data, not from this table.
| Door ref | Check | Result (Pass/Fail) | Notes |
|---|---|---|---|
| D-01 Main entrance | Valid card granted, invalid card refused | Pass | Both outcomes confirmed |
| D-01 Main entrance | REX button releases, no false forced alarm | Pass | Exit clean |
| D-05 Fire escape (stair) | Fail-safe on power loss: lock drops, door frees | Pass | Schedule says fail-safe |
| D-05 Fire escape (stair) | Fire-alarm signal releases door | Fail | Interface relay not connected, see snag S-03 |
| D-05 Fire escape (stair) | Break-glass emergency release frees door | Pass | Immediate release |
| D-09 Server room | Fail-secure on power loss: stays locked | Pass | Not an escape door, per schedule |
| D-09 Server room | Held-open alarm after allowed time | Pass | Reports at head-end |
| D-12 Store | Forced-door alarm on opening without grant | Fail | No alarm, contact wiring, snag S-07 |
| System | Controllers online, no fault flags | Pass | All modules communicating |
| System | Log records grants, denials, alarms with correct time | Pass | Clock verified against reference |
| System | Access group: after-hours user refused at D-01 | Pass | Schedule enforced |
Note the two Fails. D-05's fire-release Fail is a life-safety hard stop: sign-off is held until it is fixed and retested, not carried as an open item. D-12's forced-door Fail is a security snag to close out. Nothing here is signed off until every row, and especially every life-safety row, reads Pass.
Blank template to copy
Copy this into your sheet, add one row per check per door, and keep the life-safety rows explicit for every door on an escape route.
| Door ref | Check | Result (Pass/Fail) | Notes |
|---|---|---|---|
| ... | Reader: valid credential granted | ... | ... |
| ... | Reader: invalid credential refused | ... | ... |
| ... | Lock releases on grant, re-locks on close | ... | ... |
| ... | Fail-safe or fail-secure per schedule | ... | ... |
| ... | REX releases lock, no false alarm | ... | ... |
| ... | Door contact reports open / closed | ... | ... |
| ... | Forced-door alarm | ... | ... |
| ... | Held-open alarm | ... | ... |
| ... | Emergency release / break-glass frees door | ... | ... |
| ... | Fire-alarm signal releases escape door | ... | ... |
| ... | Power loss: door behaves per schedule | ... | ... |
| System | Controllers online, no faults | ... | ... |
| System | Access groups and schedules correct | ... | ... |
| System | Logging on, clock correct | ... | ... |
| System | Anti-passback (if used) | ... | ... |
| System | CCTV / alarm integration | ... | ... |
Field guide: what each column means
- Door ref. The identifier from your door schedule, so a result maps to a known opening. Never test by memory; test against the schedule.
- Check. The single behaviour under test, written so a fresh reader knows exactly what to do. One behaviour per row makes a Fail unambiguous.
- Result. A plain Pass or Fail. Avoid "mostly", "later" or a blank; an untested row is a Fail until proven otherwise, especially for life-safety.
- Notes. Evidence and the snag reference. For a Fail, record what happened and where it went on the snag list.
Common mistakes to avoid
- Never testing power-loss egress. Everyone taps a card; almost no one cuts the power and confirms the escape doors free. Do it deliberately, for every escape door.
- Leaving the fire interface untested. A fire-alarm relay that is specified but never wired, or wired but never triggered under test, is a silent trap. Prove the fire signal actually releases egress.
- Fail-secure on an escape door. A lock that holds on power loss is correct for a store or riser and lethal on an escape route. Confirm every door's behaviour against the schedule and the fire strategy.
- Testing only valid credentials. A reader that grants everyone, including refused cards, passes a happy-path test and fails in reality. Always test the refusal too.
- No record. A test with no signed, dated checklist is not evidence. Keep the completed sheet as the handover record.
How it links to the rest of the project
This checklist does not stand alone. It reads from the access control door schedule, which defines each door's intended behaviour, credential type and fail mode. It feeds the security commissioning checklist and the wider snag list, where every Fail is tracked to close-out. For credential-level detail on readers and enrolment, see the biometric access control guide. Return to the full toolkit at the security resources hub.
Key takeaways
- Test against the schedule, door by door. Every controlled opening gets its reader, lock, fail mode, REX, contact and alarms proven, and the result recorded as Pass or Fail with a note.
- Egress and the fire-to-release test are non-negotiable. Escape doors must open from the inside, the emergency release must free the door, and a fire signal must release every escape door. These must pass before sign-off. Never leave an escape door that fails locked.
- Cut the power on purpose. Confirm each door behaves per its fail-safe or fail-secure row on power loss, and that fail-secure is used only where no one is trapped.
- A Fail is a snag, not a shrug. Track every Fail to close-out and retest; life-safety Fails are a hard stop on handover.
- Handle the logs as personal data. Access and credential records identify people, so keep them under the DPDP Act, 2023, and hand over the completed checklist as the test record.
References
- National Building Code of India (SP 7) and your building's fire strategy, via the fire officer or AHJ, are the authority on which doors are escape doors and how they must behave on fire and power loss. Verify the current edition and the specifics for your building; this template does not set the standard.
- Manufacturer documentation for your locks, controllers and readers, the authoritative source for fail-safe and fail-secure wiring, REX behaviour, fire-interface relays and test procedures. Follow it over any generic instruction.
- Digital Personal Data Protection Act, 2023, access logs and credential data identify people and are personal data; keep access controlled, purpose legitimate and retention limited.
- Bureau of Indian Standards catalogue for any life-safety, electrical or hardware standard referenced in your specification; verify the current edition at https://www.services.bis.gov.in/
This is an educational template to adapt, not legal advice or a life-safety certification. Fire-door and escape-route requirements come from the fire strategy, the National Building Code and the AHJ; electrical connections are qualified professional tasks. Engage licensed installers and the fire officer, and get professional review for contract deliverables.
Export this guide
Related Guides — Deep-dive reading
Access Control Door Schedule for India (2026): Every Door, Every Rule
A ready-to-adapt access control door schedule with one row per door — reader side, credential, lock type, fail-safe versus fail-secure, request-to-exit, monitoring and emergency override — so every opening is secured, released and, crucially, safe in a fire.
SecurityAccess Control Maintenance in India (2026): Readers, Locks and Fail-Safe Egress
How to keep a card, keypad, fingerprint or face access-control system reading reliably and locking securely — and, above everything, how to test that its doors still release on a fire alarm and on power loss, so an access-controlled door never becomes a life-safety trap.
SecurityFail-Safe vs Fail-Secure Locks: The Guide (India 2026)
Why fail-safe vs fail-secure is the single most important access-control decision, and how to get it right for every door.
Home Doors & EntrancesRelated Tools — Try Free
Access-Control Battery-Backup Calculator
Size the standby battery so an access system keeps running through a power cut, with an egress life-safety note.
Battery BackupAccess-Control Schedule Generator
Build the time schedules that decide when each access group can enter — an editable list for your integrator.
Time SchedulesCCTV Commissioning & Handover Checklist
An interactive go/no-go checklist to run at handover — cameras day and night, recording, alerts, passwords and documents — before you clear the final bill.
Handover Checklist