TacDesk
All articles

UK Security Company Compliance: The Complete Checklist

SIA licensing, ACS, BS 7858 vetting, right to work, working time, Martyn's Law and GDPR: the checklist every UK security company needs to keep on top of, with the current rules and where to go for the detail.

By Michael Bryce · 26 September 2026 · 5 min read

Security compliance in the UK is not one rulebook, it is eight or nine separate obligations that all land on the same ops manager. Some are legal duties with a criminal penalty attached. Some are voluntary standards that clients now treat as a minimum. This is the checklist: what each one actually requires, and where to go for the full detail.

SIA Licensing

Every guard, door supervisor, CCTV operator or close protection operative carrying out a licensable activity must hold a valid SIA licence, and it is the security company's duty to check this before deployment, not just the individual's. Deploying an unlicensed operative is an offence under the Private Security Industry Act 2001, and it can also put a company's ACS status at risk if the assessor finds it. Licences last three years, and the public register shows the holder's name, licence category and current status (active, expired, suspended or revoked) for free.

That register is a snapshot at the moment you look, so a licence checked in January and never looked at again tells you nothing about March. The obligation to deploy licensed staff does not end at hiring; it runs for as long as that person is on the rota.

Full guide: How to verify a security guard's SIA licence using the public register. Official source: gov.uk, apply for an SIA licence.

TacDesk re-checks your guards' licences against the SIA public register automatically, working through the list every day, and sends managers and guards expiry reminders from 90 days out. See SIA licence tracking.

ACS: The Approved Contractor Scheme

The Approved Contractor Scheme is voluntary, run by the SIA, and assesses a company (not an individual) against criteria covering vetting, training, financial management and service delivery. It is not a legal requirement, but a large share of public sector and enterprise contracts specify ACS as a condition of tendering, so in practice it is a market entry requirement for anyone chasing that work.

Losing ACS status mid-contract is worse than never having it: it can trigger a clause allowing the client to terminate. That is why the evidence behind an ACS score, vetting records, training completion, policy documents, needs to be kept current between assessments, not assembled the fortnight before one.

Full guide: What is the SIA Approved Contractor Scheme?

BS 7858 Vetting

BS 7858 is the BSI standard for the vetting of individuals working in a secure environment: identity verification, right to work, employment history checks, and references, going back further the more sensitive the role. It is not a legal requirement in itself, but it is the vetting standard ACS assessors and most large clients expect to see followed and evidenced.

Full guide: BS 7858 vetting explained. The current edition sits with BSI: BS 7858:2019.

TacDesk's paid Compliance module tracks each BS 7858 step per operative, identity through to references, so a gap is visible before an assessor finds it. See the Compliance module.

BS 7499

BS 7499 is the BSI code of practice for static site guarding services, covering how a guarding operation should be managed, staffed and supervised. The current 2020 edition covers static guarding only; mobile patrol services now sit under a separate standard, BS 7984-3. Like BS 7858, it is voluntary but widely referenced in tenders and ACS assessments.

Source: BSI, BS 7499:2020.

Right to Work

Every employer, including security companies, must check that a worker has the right to work in the UK before employment starts, and keep evidence of the check on file. Employing someone without the right to work can carry a civil penalty of up to £60,000 per illegal worker, and for security companies specifically it can also put ACS status at risk. Since the end of free movement, checks increasingly run through the Home Office's online service rather than a physical document alone, and the evidence from that check needs to be retained for as long as the worker is employed and for a set period afterwards.

Full guide: Right to work checks for security guards. Official source: gov.uk, right to work checks.

Working Time

The Working Time Regulations 1998 apply in full to security guards, including agency and casual staff: a maximum average 48-hour week (unless the worker has opted out), 11 hours' rest between shifts, and statutory holiday entitlement that accrues even for irregular hours. Night work and lone working sites add their own record-keeping obligations, and a rota that quietly breaches the 48-hour average across a reference period is a liability the company carries, not just the guard who worked the extra hours.

Full guide: Working time regulations and security guards. Source: legislation.gov.uk, Working Time Regulations 1998.

Martyn's Law

The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, received Royal Assent on 3 April 2025. It places a tiered duty on certain premises and events, not on security contractors directly, to prepare for a terrorist attack: a standard tier for premises where 200 or more people may be present, focused on simple, low-cost procedures, and an enhanced tier for premises and events of 800 or more, which goes further into reducing the risk and harm of an attack. As of April 2026 the government has published statutory guidance under section 27 of the Act, but the substantive duties are not yet in force; a commencement date is still to be confirmed, consistent with the at-least-24-month lead-in promised at Royal Assent. The SIA is expected to take on the regulatory role for the new duty once it commences.

Full guide: Martyn's Law: what UK security companies need to know. Source: gov.uk, Terrorism (Protection of Premises) Act 2025 guidance.

GDPR and CCTV

Security operations handle personal data constantly: guard records, GPS location data, incident reports naming members of the public, and CCTV footage. UK GDPR requires a lawful basis for each of these, a retention policy rather than indefinite storage, and signage wherever CCTV is in operation. The ICO expects a data protection impact assessment for any monitoring that is systematic or covers a wide area, which in practice covers most CCTV and GPS-tracking deployments a security company runs. The ICO's CCTV guidance is the reference point clients and assessors expect you to follow.

Full guide: GDPR compliance for security companies. Source: ICO, guidance on video surveillance.

Keeping the Record Straight

None of this software makes a company compliant; compliance is the assessor's call and the employer's responsibility. What a system like TacDesk gives you is the record: licences checked, vetting steps logged, evidence filed against the right criterion, so the answer is already there when a client or an ACS assessor asks for it.

Start free on TacFree, or book a demo to see the compliance record running against your own guard list.

MB

Michael Bryce

Founder of TacDesk. Writes about SIA compliance, operations, and running a UK security company — from someone who actually works the shifts.

Connect on LinkedIn →

See TacDesk in action

Win contracts, pass SIA audits, and run your whole operation from one place. Book a free 30-minute demo.

Book a Free Demo

Get Field Notes

The ACS traps, licensing changes and ops shortcuts we write about, one straight email every week or two, from someone still doing the shifts, not a marketing team. Unsubscribe anytime.