Security contractor due diligence

Ask how workforce readiness is evidenced, not simply stated.

Before appointing a security provider, a client should understand the proposed roles, how relevant licensing is checked, what training and site-briefing evidence exists, and how readiness will be documented before the service begins. An internal record is useful—but it is not the same thing as an official licence check.

Best forProcurement, HR, facilities & venue teams
FocusRoles, evidence, training & mobilisation
Key boundaryOfficial checks and provider records differ

A measured approach

Start with the role, then ask for relevant evidence.

Private-security licensing depends on the activity and the circumstances. A buyer should not assume that every title implies the same licence requirement, nor that a provider’s internal record replaces the official routes used to verify licence status.

Due diligence is more useful when it is connected to the proposed service. Ask which roles are required, what site-specific readiness is needed, how training and instructions are managed, and how the provider handles licence-status visibility. SSS can discuss its Application, which supports compliance documentation, training records and daily SIA licence-status visibility in the agreed operational workflow.

The due-diligence framework

Four areas to test before the service starts.

The evidence needed depends on the service and role. These headings give a procurement team a practical way to ask precise questions without turning the conversation into a generic credential checklist.

01 / Role

Scope and activities

Ask which roles are proposed, what each person is expected to do and which activities are relevant to any licensing requirement.

02 / Verification

Official licence checks

Ask how relevant licence status is checked and how the provider distinguishes official verification from its own internal records.

03 / Readiness

Training and site instruction

Ask how required training, induction, site instructions and the agreed brief are communicated and recorded.

04 / Mobilisation

Current service evidence

Ask how the provider will show that the agreed team, records and client-facing operating information are ready for the start date.

Questions for a provider

Make the answer specific to the proposed service.

A useful answer should explain the process and scope without exposing unnecessary individual data or claiming that a provider can determine legal status by itself.

Due-diligence question Why it matters A useful answer may explain
Which roles are proposed? Licensing and training questions depend on the activities the role will perform. Role purpose, relevant responsibilities and the agreed site brief.
How is licence status checked? A buyer should distinguish official checking from a provider’s internal visibility or alerting process. The source/process used, relevant timing and how exceptions are handled.
How are training and site instructions managed? A valid licence does not replace the need for site-specific understanding. Induction, instructions, training records and how updates are communicated.
What can the client see? Clients need clarity on the agreed evidence route without assuming access to personal data. The agreed client visibility, reporting route and privacy boundaries.
What happens before mobilisation? The buyer needs confidence that the contractual scope can begin with clear ownership. The information, records, contacts and site steps required before commencement.

A clear route from selection to operational readiness.

Use these steps to connect procurement checks to the actual service—not merely to a list of general credentials.

01

Define the roles

Confirm what the service requires before asking what evidence is relevant.

02

Check the process

Ask how licensing, training, instructions and readiness are managed for the agreed roles.

03

Agree visibility

Document what evidence the client needs to see and the appropriate privacy boundaries.

04

Confirm mobilisation

Use the start process to make sure site details, contacts and operating instructions are current.

The SSS Application

Compliance information should support operational readiness.

The SSS Application supports daily SIA licence-status visibility, compliance documentation, training records, operational records and agreed client reporting. SSS can explain the applicable workflow within a specific proposal.

Explore the SSS Application

Questions answered

Useful answers before you make contact.

These answers are general operational guidance. The final scope should be agreed through a site, event or client-specific discussion.

Does an internal provider record replace an official SIA licence check?

No. A provider’s internal record can support operational visibility, but it is not the same as the official routes used to verify licence status. The role and activity must also be considered.

Should a client ask for individual licence numbers on a public form?

No. Workforce checks should be handled through an appropriate confidential due-diligence process that respects data-protection and operational-security boundaries.

Is a licence the only evidence a client should consider?

No. The client should also understand the proposed role, relevant training, site instruction, mobilisation process, client visibility and agreed operational responsibilities.

Guide notes

Clear guidance. Sound boundaries.

Reviewed 23 September 2026. Current GOV.UK guidance should be checked for the relevant activity and role. This guide provides procurement context only and does not give legal advice or disclose individual workforce information.

Start with a practical conversation

Ask the right workforce questions before appointment.

Discuss the workforce, evidence and mobilisation information that is relevant to your corporate, venue or property-security requirement.

Important: This page provides general operational and procurement information. It is not legal, safety, licensing, employment, tax or data-protection advice, and it does not confirm a site, event, person or service as compliant. Agree the final scope through an appropriate client-specific assessment and written service proposal.


Scroll to Top