What happened: Your assistant asked the man for his photo ID and held the visit pending verification. You pulled up Grant & Associates' main switchboard number from your signed engagement contract — not from the business card he provided — and called. The receptionist confirmed that no one from Grant & Associates was scheduled at Meridian Capital that day, or that week. Your audit liaison was in the firm's main office, not on a client visit.
When your assistant informed the man that the visit hadn't been confirmed and that he would need to wait until a scheduled visit could be arranged, he said he "must have had the wrong location." He picked up his clipboard and left. Two weeks later, your IT security team received an alert from another financial firm in your building — they had encountered the same scenario, and in their case the individual had been granted access.
// WHAT YOU DID RIGHT
✓ Required ID before any access consideration
✓ Verified via a channel you controlled (your engagement contract's phone number, not his card)
✓ Did not act under urgency pressure — the 20-minute wait was irrelevant to the access decision
✓ Did not confront the individual — once denied, your assistant communicated professionally and let him leave
✓ The incident was available to share with the building's security team when the pattern repeated
Aftermath: You reported the incident to IT Security and building management. They reviewed security camera footage and obtained a description of the individual. The pattern — visiting multiple financial firms in the building with the same pretext — was identified and shared with the local law enforcement cyber unit. This is the protocol working as designed.