Security Company Compliance Checklist
← Back to Insights

Security Company Compliance Checklist UK: A Complete Guide

2 October 2026
Security Company Compliance Checklist UK: A Complete Guide

Running a security company in the UK comes with many rules. Some are legal duties, while others are standards that buyers expect. Therefore, a clear security company compliance checklist in the UK helps owners track all of them. However, many owners miss one or two steps. As a result, they lose contracts or struggle at audits. In fact, others waste weeks searching for records when a client asks. This guide offers a simple checklist. First, it explains what compliance means. Then, it covers the legal basics, key standards, and records. Finally, it shows common mistakes and how to prepare for an audit. Overall, whether a company is new or growing, this checklist keeps the business organised and audit-ready.

What Is Security Company Compliance in the UK?

Security company compliance means following the laws, rules and standards that apply to your business. For example, it covers how you set up the company, hire staff, train them, protect data and keep records. In short, it covers every security company requirement in the UK.

Three groups of rules apply:

  • Legal duties: company law, employment law, health and safety law and data protection law
  • Industry rules: SIA licensing for individual officers
  • Voluntary standards: SIA ACS, BS 7858, BS 7499, BS 10800 and ISO standards

The law sets the minimum, but standards go further. Moreover, buyers often ask for both. Therefore, a good checklist covers all three groups.

Why Compliance Matters for Security Companies

Overall, Security Company Compliance protects your business in four ways.

  • More contract wins. Because buyers check records in tenders and PQQs, strong records set you apart.
  • Lower risk. For example, missing licences or poor records can lead to lost work and costly problems.
  • Safer people. Officers who pass screening and training also keep the public and your clients safe.
  • Stronger trust. Besides, clients prefer a company that proves what it does.

Buyer needs also change over time. So, review your checklist often. In addition, our PQQ guide for UK security and construction businesses shows what buyers ask for.

Security Company Compliance Checklist UK

Use this security company compliance checklist UK as a working list. First, tick each item. Then, keep proof for every tick. After all, auditors and buyers trust records, not promises.

Legal and Company Setup

main Security Company Compliance likho

Legal and Company Setup

Start with the basics of security company compliance. A clear legal setup shows buyers that your business is real and stable. It also helps you open doors with banks and insurers.

  • Choose your structure: limited company, partnership or sole trader
  • Register with Companies House if you form a limited company
  • Sign up with HMRC for tax, PAYE and VAT when needed
  • Open a separate business bank account
  • File accounts and confirmation statements on time
  • Keep director and address details up to date

Also, store a copy of every certificate in one folder. As a result, you find proof fast and keep your security company compliance records in order.

SIA Licensing

The law requires SIA licences for individuals who do licensable work. These roles include security guarding, door supervision, CCTV, key holding, close protection, cash and valuables in transit, and vehicle immobilisation. Therefore, the SIA licence is the first thing a security company needs to check.

Before you deploy anyone, check every officer. Then follow these steps:

  • Confirm that the licence type matches the job
  • Review the expiry date
  • Verify the licence on the SIA’s online register
  • Keep a copy of the licence and a record of the check

Licence rules can change over time. For this reason, always read the SIA’s latest guidance before you deploy staff.

Insurance Cover

Insurance protects your staff, clients and company. Besides that, it shows buyers that you can handle problems if they happen.

  • Employers’ liability insurance: the law requires it once you employ staff, with some exceptions
  • Public liability insurance: buyers expect it on almost every contract
  • Professional indemnity and other cover: check each contract for extra needs

Keep certificates current. Also, set a reminder before every renewal date. Finally, check that your cover limits match what each contract asks. Otherwise, a gap in cover can lose you the contract.

Staff Screening and Right to Work

Screen every person before they start. In fact, poor screening is one of the fastest ways to fail an audit.

  • Right to work checks, with copies, before day one
  • Identity confirmation
  • Employment and education history, with any gaps explained
  • References from past employers
  • Any background checks that the role needs

BS 7858 sets the standard way to screen security staff. Moreover, many contracts ask for it. Therefore, build it into your hiring process from the start.

Training and Competence

SIA licences require approved training. However, training does not stop there, because each site and role adds new needs.

  • Induction for every new starter
  • Site-specific training and assignment instructions
  • First aid and conflict management
  • Fire safety and emergency procedures
  • Regular refreshers

Keep a training matrix that shows who has done what, and when each course expires. Also, keep every certificate. As a result, audits become much easier.

Employment Law and Pay

Pay and contracts need care. In fact, mistakes here can lead to claims and unhappy staff.

  • A written statement of terms for every employee
  • Minimum wage rates that match each age group
  • Correct holiday pay
  • Working time rules, including rest breaks
  • Workplace pension enrolment for eligible staff
  • Payslips on time

Night shifts and long hours are common in security. So, check rotas carefully. Also, keep payroll and time records for every officer.

Health and Safety

Security officers often work alone, at night, and in conflict. For this reason, health and safety needs real attention. Above all, treat it as part of daily operations, not paperwork.

  • A written health and safety policy
  • Risk assessments for the company and each site
  • A lone working procedure
  • Logs for incidents and accidents
  • RIDDOR reports for serious incidents
  • First aid and PPE where needed

For a wider view, also read our guide on SHEQ meaning in safety.

Data Protection and GDPR

Security firms handle personal data every day. For example, this includes staff files, screening results, CCTV footage and incident reports. As a result, data protection matters in every part of the business.

  • Compliance with UK GDPR and the Data Protection Act 2018
  • A clear privacy notice for staff
  • Safe storage for screening files, with limited access
  • Retention periods and a plan to delete old data
  • A plan for handling a data breach
  • Rules for CCTV and body-worn cameras

Policies and Documentation

Policies show how your company works. Therefore, write them in plain English. Then, make sure staff can find and follow them. Core policies include:

  • Health and safety
  • Equal opportunities
  • Complaints
  • Disciplinary and grievance
  • Incident reporting
  • Data protection
  • Lone working

Add assignment instructions for each site. Also, add version numbers and review dates. Finally, review every policy at least once a year.

Records and Internal Audits

Records prove compliance. Without them, even good work looks weak. For this reason, keep these:

  • Staff files and licence checks
  • Screening and training records
  • Incident and complaint logs
  • Patrol and occurrence logs
  • Audit reports and action plans

Run internal audits on a regular schedule. As a result, you find gaps before a client or auditor does. In addition, our internal audit service and QMS software can help you stay organised.

UK Security Standards Explained

Standards show buyers that your systems meet a recognised level. Although most are voluntary, many tenders still ask for them. Here are the main ones.

SIA ACS

The Approved Contractor Scheme is the SIA’s voluntary quality scheme. In addition, approved companies appear on the SIA register, and buyers trust the badge. Because rules change, check the SIA’s website for the latest steps. Learn more about SIA ACS consultancy.

BS 7858 Screening

BS 7858 sets the standard for screening and vetting security staff. In particular, it covers identity, history, references, and checks. Because auditors look at every file, records matter most.

BS 7499 and BS 10800

BS 7499 covers static guarding and mobile patrol services. Meanwhile, BS 10800 gives a framework for providing security services. Together, they show that your operations follow a clear structure.

BS 10119 and COP 119

These two cover labour provision and supply chain integrity. For this reason, they matter if you supply or subcontract security staff. Also, check which one your buyers ask for.

NASDU for Dog Services

If your company provides security dogs, NASDU applies. In particular, it sets compliance expectations for dog operations. For example, handlers, dogs, and records all need checks.

ISO and Cyber Standards for Security Firms

Beyond security standards, many buyers also ask for ISO and cyber certificates. In short, these show that your business runs strong management systems.

ISO 9001, ISO 14001 and ISO 45001

These three standards cover quality, environment, and health and safety. Together, they build a strong management system. As a result, many security tenders score them highly. In addition, read why accreditation matters in our guide on ISO accredited vs non-accredited certification.

Cyber Essentials

Cyber Essentials is a UK government scheme that sets basic cyber protection standards. Furthermore, many public and large private contracts ask for it. Because security firms hold client and staff data, it adds real value.

Compliance Checklist for New vs Existing Companies

New and existing companies need different priorities. For this reason, this table shows the difference. In addition, it works as a quick security company audit checklist.

Area New company Existing company
Legal setup Register, set up tax and bank Keep filings and details up to date
SIA licences Check every officer before day one Track expiry dates monthly
Insurance Arrange cover before the first contract Review limits at every renewal
Screening Build BS 7858 into hiring Audit staff files regularly
Policies Write the core policies Review each policy yearly
Standards Plan ACS and ISO early Close gaps and renew on time

Starting a company? First, begin with legal setup, insurance, and screening. Then, add standards step by step. Many new owners search for how to start a security company in the UK, so this order gives them a safe path.

Common Compliance Mistakes to Avoid

Many security firms repeat the same errors:

  • Letting SIA licences expire without noticing
  • Missing screening records or gaps in history
  • Using old policies with no review dates
  • Skipping site risk assessments
  • Keeping no training records
  • Never running an internal audit
  • Storing personal data without proper security
  • Forgetting insurance renewal dates

Most of these mistakes come from poor tracking. So, use a simple tracker or software. Also, give one person ownership of compliance. As a result, nothing slips through.

How to Prepare for a Compliance Audit

Audits feel stressful. However, a clear plan makes them simple. Therefore, follow these steps:

  1. Choose the standard. First, read the requirements.
  2. Run a gap check. Then, use this checklist to find what is missing.
  3. Fix the gaps. Next, start with the biggest risks.
  4. Organise your records. Make each file easy to find.
  5. Brief your staff. In addition, they should know the policies and be able to answer questions.
  6. Run a mock audit. Also, test your systems before the real one.
  7. Act on findings. Finally, close every action and note the date.

How BizGrow Holdings Can Help

BizGrow Holdings is a UK compliance and accreditation consultancy. In short, we help security companies build strong systems and pass audits.

Our services include:

  • SIA ACS consultancy
  • BS 7858, BS 7499, BS 10800 and BS 10119 support
  • NASDU and COP 119 compliance
  • ISO 9001, ISO 14001 and ISO 45001 support
  • Cyber Essentials
  • Internal audits and QMS software

First, we check your gaps. Next, we prepare your documents. Then, we guide you through the audit. Because the cost depends on your company size and the standards you need, contact us for a clear quote. Browse our services or contact our team today.

FAQs

How often should a security company review its policies?

Review every policy at least once a year. Also, review them after any change in law, contracts, or processes. Then, record the date and version each time.

How long does it take to become audit-ready?

It depends on your company size and how complete your records are. However, a gap check shows what is missing. So, start with that check to get a clear timeline.

Who checks if a security company is compliant?

Buyers, auditors, certification bodies, and the SIA can all check. For example, clients review records during tenders and site visits. Therefore, keep your records ready at all times.

How long should a security company keep staff records?

No single rule fits every record. Instead, keep each record as long as your contracts, standards and the law require. Then, delete it, because UK GDPR says not to keep data longer than needed.

Can a small security company meet the same standards as a large one?

Yes, because standards test your systems and evidence, not your size. In fact, a small firm with clear policies and tidy records can pass the same audits. So, start with the basics and build up.