Policy Pros
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Policies for Security Companies

Policy Pros writes bespoke policies and procedures for security guarding, door supervision, CCTV monitoring and keyholding companies across the UK. Whether you are preparing for Approved Contractor Scheme assessment, responding to a tender or putting proper documentation behind a growing guarding operation, we write the documents your assessors and clients expect to see.

Bespoke, audit-ready policies from £65 + VAT per document. Get a quote or call 020 3951 2875 for a free scoping conversation.

Policies Security Companies Need

Legally Required

  • Health and Safety Policy - a written policy is required at five or more employees under the Health and Safety at Work etc. Act 1974.
  • Risk Assessments - required by the Management of Health and Safety at Work Regulations 1999, recorded in writing at five or more employees, covering lone working, conflict and night work.
  • Data Protection Policy - security companies process vetting files, incident reports and CCTV footage, all personal data under UK GDPR and the Data Protection Act 2018.
  • CCTV Privacy Documentation - UK GDPR requires a lawful basis, signage, retention rules and a data protection impact assessment before large-scale monitoring of public areas.
  • Employment Contracts with Disciplinary and Grievance Procedures - a written statement covering both is required from day one under the Employment Rights Act 1996.
  • SIA Licence Verification Procedure - supplying unlicensed operatives for licensable work is an offence under the Private Security Industry Act 2001.

Expected by Regulators and Clients

  • BS 7858 Screening and Vetting Policy - the British Standard vetting benchmark that ACS assessment and most client contracts demand.
  • Assignment Instructions and Operating Procedures - site-specific instructions expected under the ACS self-assessment workbook and BS 7499.
  • Lone Working Policy - expected by the HSE wherever officers patrol, monitor or respond alone.
  • Use of Force and Physical Intervention Policy - expected for door supervision teams and demanded by venue clients and insurers.
  • Training and Competence Policy - a documented training matrix is a core people indicator in the ACS workbook.
  • Complaints Handling Procedure - an ACS workbook requirement and a standard clause in guarding contracts.
  • Business Continuity Plan - assessed under ACS and increasingly requested in tenders for contracted guarding.

SIA Licensing and the Approved Contractor Scheme

Under the Private Security Industry Act 2001, individuals carrying out contracted security guarding, door supervision, public space surveillance using CCTV, keyholding, close protection or cash and valuables in transit must hold the correct SIA licence. Directors, managers and supervisors of licensed operatives need non-front line licences even if they never work a site themselves.

The Approved Contractor Scheme is voluntary, but it is treated as a baseline in security tenders and on regulated sites. Assessment runs on a self-assessment workbook verified against your written policies, vetting records and procedures, and our SIA ACS documentation guide sets out exactly which documents the workbook draws on.

Vetting and Staff Safety

Screening to BS 7858 is the vetting standard the industry runs on. It expects identity, right to work and financial probity checks plus a five year employment history, with any gap of 31 days or more investigated and documented, so you need a written vetting policy and records that show the process is followed.

Security work also carries distinct safety risks, including lone patrols, conflict with the public and night working. HSE inspectors and ACS assessors expect health and safety policies and risk assessments that reflect those realities rather than generic office hazards, alongside the HR policies that govern recruitment, screening and discipline.

CCTV Operators and UK GDPR

If you monitor CCTV, run a control room or deploy body-worn video, you are processing personal data and the ICO's video surveillance guidance applies. That means a documented lawful basis, visible signage, retention limits, a process for subject access requests and a data protection impact assessment before high risk monitoring begins.

Where you monitor a client's system you may act as a processor, which needs contract clauses and procedures of its own. Our data protection policy service covers both positions.

Martyn's Law and Venue Clients

The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, is expected to come into force in 2027 and will be regulated by the SIA. Venues where 200 or more people may be present will need documented protective procedures, and many will turn to their security contractor to help deliver them.

Guarding and door supervision firms that can evidence their own counter-terrorism procedures will be better placed to win that work. Our Martyn's Law compliance guide explains the tiers and timescales, and our Martyn's Law documentation service covers the documents in-scope venues will need.

What Policy Pros Delivers

  • Bespoke policies written around your actual operation, licence categories and client base, never adapted templates.
  • A fixed-price quote before any work starts.
  • Review rounds included, so the final documents say exactly what you need them to.
  • Documents delivered on professionally branded templates, ready for assessors and client audits.

Extremely professional and thorough. The policies were tailored perfectly to our sector and delivered ahead of schedule.

You can read reviews of Policy Pros on Trustpilot.

How to Get Started

Tell us what you do, how many staff you deploy and what your clients or assessors are asking for. We will scope the documents you actually need and send a fixed-price quote with no obligation. Get a quote or call 020 3951 2875.

Frequently Asked Questions

What policies does a security company legally need?

Every security company with five or more employees needs a written health and safety policy and recorded risk assessments, and every employer must give staff a written statement covering disciplinary and grievance procedures from day one. Because vetting files and CCTV footage are personal data, a data protection policy under UK GDPR is effectively unavoidable.

The Private Security Industry Act 2001 also makes it an offence to supply unlicensed operatives for licensable work, so a documented SIA licence checking procedure protects the business itself.

What documents do we need for SIA ACS approval?

ACS assessment verifies your self-assessment workbook scores against written evidence. Assessors expect BS 7858 vetting records, SIA licence checking procedures, assignment instructions, training records, health and safety documents, a complaints procedure and a business continuity plan.

The documents need to show evidence of review and use, not simply that they exist. A pack assembled the week before the visit rarely survives scrutiny.

Does BS 7858 apply if we are not going for ACS approval?

BS 7858 is not law, but most guarding, monitoring and keyholding contracts require staff to be screened to it, and it underpins ACS assessment. If you supply officers to client sites, expect to evidence BS 7858 vetting whether or not you seek approval.

Do CCTV monitoring companies need their own data protection policy?

Yes. A company monitoring CCTV is processing personal data, whether as controller of its own system or as processor of a client's, and the ICO expects a documented lawful basis, retention rules and procedures for subject access requests.

A data protection impact assessment is also required before large-scale monitoring of publicly accessible areas begins.

Trustpilot Reviews - 5 Stars