Skip to content

Visitor Security Policy Recommendations

  • Knowledge Level: All Levels
  • Protection Stage: All Stages
  • Time to read:

This document was created in collaboration with the UK’s university sector through a combination of existing university visitor policies, alongside NPSA guidance to allow universities to safely encourage individuals to visit and contribute to research while still following good research security practice

Last Updated: 23 June 2026
Share this article:

This guidance is also available as a PDF: Visitor Security Policy Recommendations

Origin and Scope

Through NPSA and NCSC’s Trusted Research Universities Forum, a small working group with representatives from five universities was put together to discuss and create a short policy guide for universities and research institutions (hereafter “universities”) to use when hosting visitors to ensure good research security practices are applied.

This Visitor Security Policy Recommendations document was created in collaboration with the UK’s university sector through a combination of existing university visitor policies, alongside NPSA guidance to allow universities to safely encourage individuals to visit and contribute to research while still following good research security practice.

NPSA encourages universities to read and apply these recommendations alongside their existing visitor policy/policies. While it is likely that some of the measures recommended in this guidance are already in place, application of all measures in this guidance will help to ensure the visitor lifecycle is as secure as possible.

It is also important to note that all aspects of this guidance should be applied alongside other relevant legislation, such as data protection laws and employment laws.

Summary

  • All visitors should be logged appropriately, with information retained for an appropriate period of time in line with your own institutional data storage and processing policies.
  • Visitors should be appropriately identifiable to all members of staff, and only permitted access to IT and physical locations necessary for the purpose of their visit.
  • Visitors should all have a corresponding host from within the university, who is responsible for ensuring they follow all appropriate policies.
  • Once a visit has ended, a visitor must be fully offboarded with all relevant accesses revoked and policies followed.

Visitor Categorisation

In this document, the term ‘visitor’ will be used to refer to anyone who is not a permanent member of staff, who has access to physical university sites and/or IT systems; this would include access to IT systems when working remotely. It will largely focus on longer-term visitors, but will also address some particular considerations for short-term visitors.

The list below denotes some of the categories you may wish to group visitors into, considering particular security practices to reflect the level of access they may need to the university – whether that is for an individual meeting or for longer term access.

As a university, you will likely wish to create further categories within some of these, but the visitor security process should remain similar across all groups.

It is also important to consider whether each category of visitor will be supervised or unsupervised during their time at the university, and as such what security measures should be put in place for each visit. For some supervised visits, visitors may need to be escorted at all times, while others may be able to have periods without supervision.

Visitor Categories

  • Visiting academics from other universities (both domestic and international).
  • Visiting staff from other sites and departments, such as overseas campuses or joint educational institutes.
  • Managed service providers, such as catering, cleaning or maintenance.
  • Contracted staff not aligned to research or core business.
  • Potential investors.

Identification Of Visitors

All visitors should be logged and recorded, and this information should be stored securely for a period of time in line with your own institutional data storage and processing policies.

It is recommended that all visitors are signed in and out of university buildings, preferably through a manned reception. As such, the following information should be collected for all visitors and then checked against a valid form of identification on their arrival (or through the due diligence process):

  • Full Name
  • Date of Birth
  • Job Title/Role (if there is relevant ID associated with this)

The NPSA guidance for Document Verification explains how to ensure presented identification is genuine, which will be relevant both for reception security as well as those conducting due diligence before inviting a visitor.

Short-term visitors should be identifiable to other members of staff.

It is recommended that all short-term visitors are issued with a visitor pass or some other identifying object (such as a different coloured or patterned lanyard to staff) for the duration of their visit (and must be returned upon departure), to denote which locations they are allowed to access. This will allow other members of staff in the university to identify visitors and ensure they are only accessing relevant locations and can only see relevant information.

Staff should be aware of what the visitor lanyards look like, and therefore what accesses that visitor has. NPSA also encourages universities to encourage staff to politely challenge if visitors are identified in areas where they are not meant to be. 

For short term visits (e.g an individual visit taking place on one day), it is recommended that visitors should only have necessary items with them. At times it may be necessary to use highly knowledgeable individuals to carry out an escorting role due to the sensitivity of an area in which a visitor or contractor is working. When identifying these areas, it is also recommended to restrict the possession of digital devices for visitors to prevent loss of sensitive information.

Identification Of Long-Term Visitors:

For longer term visitors such as visiting academics or professors, it is important that their identity is fully confirmed before offering them a more permanent form of access to the university, such as their own access pass. Long-term visitors should comply with university policy on displaying passes.

The following information is a suggestion of what can be collected for verification (this will usually be completed by relevant HR or Security functions, as opposed to the host, but the host may be responsible for facilitating the exchange of information).

  • Visitor’s CV
  • Visitor’s Passport / National ID scanned copy
  • Signed Visitor Agreement
  • Initial letter of invitation (if applicable)
  • Visa (in circumstances where the visitor already has an appropriate visa in place) - this may include an ATAS Certificate
  • Tier 5 documentation (if applicable)

All visitors should have an associated ‘end date’ to their visiting period.

Once a visitor is confirmed, a record should be kept ensuring that access passes and IT access can be monitored and then removed once the visiting period has ended.

Host Requirements

Every visitor should have a corresponding ‘host’, who is responsible for managing the visitor throughout their visit.

It is recommended that each visitor has an assigned ‘host’. This is likely to be the individual who initiated the request for a visitor, and they should be responsible for ensuring that the correct processes are followed throughout the period for the visit.

The host should be responsible for the following:

  • Creating the initial justification for the invitation of the visitor.
  • Ensuring all relevant documentation and approval is received before initiating the visit.
  • Ensuring the visitor is aware of all relevant university and HR policies and codes of conduct.
  • Ensuring the visitor only has accesses to relevant IT and physical locations, without providing access to unrelated data. This makes it less likely for potential breaches across projects, with visitors only able to use relevant university provisions.
  • Ensuring that once the visit is complete, that the visitor is fully “offboarded” (see below) and has no further accesses (such as returning passes or removing their university IT accounts and handing back any devices or equipment).

Depending on each university, these responsibilities may be shared between an individual host as described above, as well as separate HR or IT functions. It is important to clarify within a university’s own policies who is responsible for each of these areas, and where each role begins and ends ownership of the responsibility.

Offboarding Process

All visitors should be fully offboarded once their end date has been reached. This includes revoking accesses to IT and physical locations.

A clear and structured offboarding process is essential for strong research security. When a visit is first approved, it is important to have a date assigned where the visitor is expected to leave, and on this date they will lose the relevant accesses and be required to return any passes or other institutional property. It is recommended that the host is responsible for facilitating the return of these items, and each item should be accounted for in the initial visitor onboarding process.

Extensions should be managed in a controlled manner, with regular reviews and updates to security checks being conducted throughout a visit.

In the case of an extension being required, this should be requested and approved (at the same level of seniority as the original request) in advance of the initial end date, so that the appropriate record can be updated. Again, the host should be responsible for ensuring this new date is adhered to, and it is recommended that checks should be re-completed if the length of the visit is drastically increased. This will prevent visitors from being automatically approved for extended periods that are unnecessary and may lead to disproportionate access being granted.

Rejection of Visitors

Where appropriate, reasons for rejecting visitors should be transparent to avoid poor security practices being adopted.

It is important that during the approval process, any reason for rejection of the visitor is recorded appropriately and (if necessary) given to the host, subject to advice from university legal departments.

This reduces the likelihood of visitors being repeatedly requested until a workaround is found, while also improving the chances of being able to host them securely. For example, if a visitor is rejected from physically visiting the university but could be securely granted remote access to necessary areas, they may still be able to contribute to research.

Did you find this page useful?
helpfulness rating