TacDesk
All articles

Security Site Risk Assessments: A Practical Guide for Guarding Firms

How to write a site risk assessment that holds up at audit, how it connects to your assignment instructions, and where TacDesk holds the site information behind both.

By Michael Bryce · 26 September 2026 · 5 min read

A generic risk assessment copied across every site is one of the most common things an ACS assessor or a client audit picks up on, and it's an easy gap to leave open because writing a proper one takes longer than copying the last one. Here's a practical approach, and how it should connect to the assignment instructions your guards actually read.

Start from the site, not the template

A site risk assessment identifies the hazards specific to that location, rates how likely each one is and how bad it would be if it happened, and sets out what you do about it. It is not the same document as your generic company risk policy, and it should not read like one. Walk the site. Note the actual access points, the lighting, the areas with no CCTV coverage, the parts of the site guards are expected to patrol alone at night, any history of incidents there, and anything about the client's operation, deliveries, visitors, machinery, that creates a specific risk a generic template wouldn't capture.

Rate each hazard consistently

A simple, defensible way to score a hazard is likelihood multiplied by severity, each scored on a small scale, giving you a single number you can rank hazards by and a way to justify why one gets more attention than another. A low score doesn't mean ignore it, it means monitor and revisit. A high score means it needs a control in place before the guard starts, not a note to think about it later. Whatever scale you use, use it the same way across every site so a manager can compare risk across your whole guarding book, not just within one assessment.

Common hazards on a manned guarding site

  • Lone working at night, particularly on patrol routes away from CCTV or other staff
  • Access control gaps: doors propped open, unmonitored delivery entrances, tailgating risk
  • Conflict and aggression, especially where the guard's role includes refusing entry or engaging with the public
  • Vehicle movement on site, particularly where guards direct traffic or work near loading bays
  • Environmental hazards specific to the site: uneven ground, poor lighting on a patrol route, exposed plant or machinery
  • Emergency response gaps: unclear fire evacuation role, no confirmed route to the nearest useful help at night

Who signs it off, and how often

A site risk assessment should have a named author and a named manager who reviews and approves it, not just whoever happened to be free that week. Set a fixed review interval, most firms use annually as a baseline, and treat that as a minimum rather than the trigger: a change of client operating hours, a new tenant or contractor sharing the site, an incident on site, or a guard raising a new hazard should all trigger an earlier review regardless of where you are in the cycle. Brief every guard rostered to a site on the current risk assessment before their first shift there, not just the assignment instructions; a new starter who's read the site rules but doesn't know why the loading bay is treated as a higher-risk area is missing half the picture. When a client or an assessor asks who reviewed the assessment and when, "we're not sure" is the answer that costs you the contract or the accreditation, not the hazard itself.

Connect the risk assessment to the assignment instructions

A risk assessment that sits in a folder and never reaches the guard on shift isn't doing its job. The controls you identify, don't patrol that stairwell alone after 11pm, check that gate every hour, call this number first if there's a confrontation, need to end up in the site's assignment instructions, the document the guard actually reads and is expected to follow. Assignment instructions guards actually follow covers what makes an assignment instruction genuinely usable rather than a fifteen-page document nobody reads, and the same principle applies here: a risk assessment that isn't reflected in what the guard is told to do on shift is a paperwork exercise, not a control.

Review both documents on a schedule, not just when something goes wrong. A site's risk profile changes when the client changes their opening hours, when a new tenant moves into a shared building, or after an incident, and the risk assessment and the assignment instructions both need updating when it does. Regular site inspections are a natural point to check whether the risk assessment still matches what you find on site.

Where TacDesk holds this

TacDesk's Compliance module holds site risk assessments as records tied to the client and, where relevant, to the site's assignment instruction: each assessment lists its hazards, with a likelihood and severity score calculated into a risk rating and a level from low to critical, plus a review date so a manager can see which assessments are overdue rather than finding out at audit. Assignment instructions themselves are version-controlled documents in the same module: a manager creates and approves a version, guards acknowledge that they've read the current one, and supporting site documents, floor plans, client procedures, emergency contact sheets, attach directly to the instruction rather than living as a separate file nobody can find. Both are part of the Compliance module, included on every paid plan, not TacFree.

That's a records system, not a substitute for doing the assessment properly. TacDesk doesn't write your risk assessment or decide what's a hazard on your site, and it doesn't make your assignment instructions compliant on its own; it holds the version history, the acknowledgements and the review dates so that when a client or an assessor asks to see it, you're not searching three shared drives and a plastic wallet in the gatehouse for the current copy.

If your site risk assessments and assignment instructions are still separate documents nobody's sure are up to date, book a demo to see how the Compliance module ties them together, or start free to get your basic site and licensing records running today.

MB

Michael Bryce

Founder of TacDesk. Writes about SIA compliance, operations, and running a UK security company — from someone who actually works the shifts.

Connect on LinkedIn →

See TacDesk in action

Win contracts, pass SIA audits, and run your whole operation from one place. Book a free 30-minute demo.

Book a Free Demo

Get Field Notes

The ACS traps, licensing changes and ops shortcuts we write about, one straight email every week or two, from someone still doing the shifts, not a marketing team. Unsubscribe anytime.