Visitor screening is the process of checking who a visitor is, why they're coming and whether they should get access before they enter your workplace. It can be as light as confirming a name against a host's invite or as strict as an ID check against government watchlists. Most organizations fit somewhere in between, and the right level depends on your industry, your regulations and what's inside the building.
Screening is the decision step inside visitor management. Registration collects details, and check-in records arrival. Screening decides whether the person is allowed in, and under what conditions.
A typical flow looks like this:
BLS recorded 57,610 nonfatal workplace violence cases serious enough to require days away from work across 2021 and 2022, plus 524 workplace homicides in 2022. Screening won't stop every incident, but it gives the front desk a way to act on known risks, such as a former employee barred from the site. Our guide to office security covers the wider picture.
Visitors can see screens, whiteboards, prototypes and documents. Under ITAR, showing controlled technical data to a foreign person in the US counts as an export, and 22 CFR 120.56 includes visual inspection as a release. For defense and aerospace sites, knowing who's in the building is a compliance issue.
Some regulations spell out visitor controls. The HIPAA Security Rule at 45 CFR 164.310 lists "visitor control" as an addressable safeguard for covered entities. A documented process also gives auditors a timestamped record that checks happened.
Match the checks to real risk. A few questions settle most of it:
Most corporate offices do well with pre-registration, host confirmation, ID checks for first-time visitors and an NDA where needed. Visitor management tools can run these checks at sign-in and alert the host on arrival. Many workplace teams manage visitors in the same platform they use for desk booking; our roundup of hot desk booking software and our guide to hybrid work software cover options.
No. Most offices face no general legal requirement to screen visitors. Specific rules apply in certain sectors: HIPAA for healthcare, ITAR and EAR for export-controlled sites, federal facility security standards and some payment card rules. OSHA has no specific workplace violence standard, though employers still carry a general duty to provide a safe workplace.
Yes. Visitors can pre-register from an invite link, then check in at a tablet kiosk or by scanning a QR code. The system verifies details, collects signatures, prints a badge and notifies the host. Anyone flagged by a watchlist match can be routed to security staff instead of the lobby.
Set a retention period in your policy and stick to it. Under GDPR, the ICO's storage limitation guidance says personal data shouldn't be kept longer than you need it. Regulated sites may need longer retention for audits, so check sector rules with your legal team.
Usually at a lighter level. Many offices send couriers to a mailroom or reception drop point so they never pass the lobby. If a courier needs access beyond that, the same policy applies: identity, purpose and a logged entry. Recurring contractors should be rescreened on a regular schedule.