Security contractor due diligence
Ask how workforce readiness is evidenced, not simply stated.
Before appointing a security provider, a client should understand the proposed roles, how relevant licensing is checked, what training and site-briefing evidence exists, and how readiness will be documented before the service begins. An internal record is useful—but it is not the same thing as an official licence check.
A measured approach
Start with the role, then ask for relevant evidence.
Private-security licensing depends on the activity and the circumstances. A buyer should not assume that every title implies the same licence requirement, nor that a provider’s internal record replaces the official routes used to verify licence status.
Due diligence is more useful when it is connected to the proposed service. Ask which roles are required, what site-specific readiness is needed, how training and instructions are managed, and how the provider handles licence-status visibility. SSS can discuss its Application, which supports compliance documentation, training records and daily SIA licence-status visibility in the agreed operational workflow.
The due-diligence framework
Four areas to test before the service starts.
The evidence needed depends on the service and role. These headings give a procurement team a practical way to ask precise questions without turning the conversation into a generic credential checklist.
Scope and activities
Ask which roles are proposed, what each person is expected to do and which activities are relevant to any licensing requirement.
Official licence checks
Ask how relevant licence status is checked and how the provider distinguishes official verification from its own internal records.
Training and site instruction
Ask how required training, induction, site instructions and the agreed brief are communicated and recorded.
Current service evidence
Ask how the provider will show that the agreed team, records and client-facing operating information are ready for the start date.
Questions for a provider
Make the answer specific to the proposed service.
A useful answer should explain the process and scope without exposing unnecessary individual data or claiming that a provider can determine legal status by itself.
| Due-diligence question | Why it matters | A useful answer may explain |
|---|---|---|
| Which roles are proposed? | Licensing and training questions depend on the activities the role will perform. | Role purpose, relevant responsibilities and the agreed site brief. |
| How is licence status checked? | A buyer should distinguish official checking from a provider’s internal visibility or alerting process. | The source/process used, relevant timing and how exceptions are handled. |
| How are training and site instructions managed? | A valid licence does not replace the need for site-specific understanding. | Induction, instructions, training records and how updates are communicated. |
| What can the client see? | Clients need clarity on the agreed evidence route without assuming access to personal data. | The agreed client visibility, reporting route and privacy boundaries. |
| What happens before mobilisation? | The buyer needs confidence that the contractual scope can begin with clear ownership. | The information, records, contacts and site steps required before commencement. |
A clear route from selection to operational readiness.
Use these steps to connect procurement checks to the actual service—not merely to a list of general credentials.
Define the roles
Confirm what the service requires before asking what evidence is relevant.
Check the process
Ask how licensing, training, instructions and readiness are managed for the agreed roles.
Agree visibility
Document what evidence the client needs to see and the appropriate privacy boundaries.
Confirm mobilisation
Use the start process to make sure site details, contacts and operating instructions are current.
The SSS Application
Compliance information should support operational readiness.
The SSS Application supports daily SIA licence-status visibility, compliance documentation, training records, operational records and agreed client reporting. SSS can explain the applicable workflow within a specific proposal.
Questions answered
Useful answers before you make contact.
These answers are general operational guidance. The final scope should be agreed through a site, event or client-specific discussion.
Does an internal provider record replace an official SIA licence check?
No. A provider’s internal record can support operational visibility, but it is not the same as the official routes used to verify licence status. The role and activity must also be considered.
Should a client ask for individual licence numbers on a public form?
No. Workforce checks should be handled through an appropriate confidential due-diligence process that respects data-protection and operational-security boundaries.
Is a licence the only evidence a client should consider?
No. The client should also understand the proposed role, relevant training, site instruction, mobilisation process, client visibility and agreed operational responsibilities.
Guide notes
Clear guidance. Sound boundaries.
Reviewed 23 September 2026. Current GOV.UK guidance should be checked for the relevant activity and role. This guide provides procurement context only and does not give legal advice or disclose individual workforce information.
GOV.UK — Find out if you need an SIA licence GOV.UK — Check a private security licence SSS Application
Start with a practical conversation
Ask the right workforce questions before appointment.
Discuss the workforce, evidence and mobilisation information that is relevant to your corporate, venue or property-security requirement.
Important: This page provides general operational and procurement information. It is not legal, safety, licensing, employment, tax or data-protection advice, and it does not confirm a site, event, person or service as compliant. Agree the final scope through an appropriate client-specific assessment and written service proposal.