Last updated: 10 September 2026
ACS audit checklist: what UK security firms need to pass their SIA assessment
An ACS audit checklist covers the seven criteria and 78 indicators the Security Industry Authority uses to score a firm under the Approved Contractor Scheme — covering strategy, service delivery, financial management, resource management, people, leadership and commercial relationship management. Assessors score each indicator on a defined achievement scale, and approval renews every three years with annual surveillance in between.
Key Takeaways
- The SIA's ACS self-assessment workbook scores a security business against 78 individual indicators, organised into seven criteria and 33 sub-criteria, per Pulse Operations's guide, The ACS self-assessment: how to evidence it.
- ACS approval renews every three years, with annual surveillance assessments in between (Coredinate, 2026).
- Approved Contractor status means a company has been independently audited across more than 75 different criteria (ProFM Group, 2026).
- The ACS scheme has been operating since 2006, according to the SIA's Strategic Plan for 2026–2029 (SIA Strategic Plan via All Time Security, 2026).
- There were 838 approved contractors under the ACS scheme as of 8 March 2022, with 196 companies new to the scheme since 2019 (GOV.UK FOI response, 2022).
What is an ACS audit checklist?
An ACS audit checklist is a preparation document that maps the Security Industry Authority's Approved Contractor Scheme (ACS) — the SIA's UK-wide accreditation for private security businesses — to the evidence an assessor will actually ask to see. The SIA is the statutory regulator created under the Private Security Industry Act 2001, and it licenses individual operatives while the ACS accredits the companies that employ them.
The checklist isn't the workbook itself. It's the operational proof — rosters, training records, incident logs, contracts — that a firm gathers before an assessor from a UKAS-accredited certification body, such as the SSAIB or NSI, arrives to test whether the paperwork matches reality.
Per Pulse Operations's guide, The ACS self-assessment: how to evidence it, the standard is organised as seven criteria, broken down into 33 sub-criteria and 78 individual indicators. Each indicator carries a required baseline achievement level scored as zero, with extra points available for evidenced good practice and continuous improvement above that baseline.
What are the seven ACS criteria assessors score?
The seven ACS criteria are Strategy, Service delivery, Commercial relationship management, Financial management, Resource management, People, and Leadership — the fixed categories the SIA's self-assessment workbook uses to structure all 78 indicators. Every approved contractor, regardless of sector, is scored against the same seven headings.
Understanding which criterion each piece of evidence belongs to is the single most useful thing a firm can do before an assessment. Assessors don't score in isolation — they trace a thread from a policy statement (Strategy) through to a duty rota (Resource management) and a licence check (People), looking for consistency.
Strategy and leadership
Strategy covers business planning, risk management and how a firm sets direction. Leadership examines how that direction is actually driven through the organisation — management structure, decision-making, and accountability. Assessors typically want to see a documented business plan, a risk register, and evidence that leadership reviews performance against it, not just that one exists in a drawer.
Service delivery and commercial relationship management
Service delivery is about whether contracted work is actually delivered to specification — patrol schedules met, incidents logged, sites covered. Commercial relationship management looks at how a contractor manages client relationships, contract variations and complaints. This is where site documentation, occurrence books and client sign-off records carry the most weight.
Financial management and resource management
Financial management checks solvency, insurance and financial controls — the kind of evidence that reassures a client the firm will still exist next year. Resource management covers how staff, vehicles, uniforms and equipment are planned and deployed against contracted hours. Duty rotas, time and attendance records, and equipment registers all sit here.
People
The People criterion checks how well contractors apply BS 7858 — the British Standard for security screening and vetting of personnel — and verify licences against the SIA's public register, per Pulse Operations's guide. This includes right-to-work checks, DBS (Disclosure and Barring Service) certificates where relevant, and training records for every operative on the payroll.
What happens during an SIA ACS audit?
An SIA ACS audit is an on-site and desk-based assessment carried out by an accredited certification body, in which an assessor reviews documents, visits operational sites and interviews staff and customers to verify that a contractor's self-assessment scores reflect real practice. The process typically spans several days depending on company size.
Assessors don't take the workbook's declared scores at face value. Per Pulse Operations's guide, they review staff files and payroll records, contracts and duty rotas, policies and procedures, and site documentation. They interview staff and customers directly, and they visit operational sites to see whether what's written down is what's actually happening.
One reported case involved a 6-day audit against a 78-assessment criteria list for a security company seeking SIA ACS approval, per Herongrange (2021). The length and depth of an audit generally scales with headcount, number of licensable sectors covered, and how many sites the assessor selects to visit.
The self-assessment workbook (SAW)
Before the audit itself, contractors complete the SIA's Self-Assessment Workbook (SAW) — an interactive scoring document where the firm rates itself against every indicator. The assessor then tests those scores rather than accepting them, which is why gaps between declared and demonstrable performance are the most common source of a failed or delayed assessment.
How do I prepare for an ACS audit?
Preparing for an ACS audit means gathering evidence against all 78 indicators well before the assessor's visit, not building a file in the weeks beforehand. The strongest preparation treats ACS evidence as a by-product of day-to-day operations — rosters, patrol records and training logs that already exist because the business runs on them.
"SIA Approved Contractor status isn't won by writing good policies, it's won by proving your paperwork matches what actually happens on site. Assessors want to see rosters, training records and incident reports that line up with reality, not a folder built the week before the audit. Get your everyday systems right first — the accreditation just confirms what's already true." — Mo Hassan, Founder, Pulse
This is precisely where firms with evidence scattered across spreadsheets, filing cabinets and individual inboxes lose weeks every year rebuilding a paper trail. Pulse Operations's compliance runway keeps SIA licence expiries, BS 7858 screening, DBS status, right-to-work checks and training records on one dashboard, so the evidence an ACS assessor asks for already exists in one place rather than being reconstructed from memory.
In practice: at Priority First — the founding team's own London security and FM operation that Pulse was built inside before being offered to other operators — checkpoint history, site notes and induction records for new sites are live in the platform from the day a contract mobilises. When three buildings were added in a single July fortnight, officers started their first shift with full site history already visible rather than relying on whatever the outgoing contractor could hand over verbally. That's the same principle an ACS assessor is testing for: does the record exist independently of who's in the building that day?
Documents to have ready
- SIA licence numbers for every operative, cross-checked against the SIA's public register
- BS 7858 screening files and DBS certificates where the role requires them
- Signed employment contracts and current duty rotas
- Time and attendance records reconciled against contracted hours
- Training records covering induction, refresher and role-specific training
- Incident reports and a daily occurrence book with a verifiable audit trail
- Client contracts, SLAs and any recorded complaints or variations
- Insurance certificates and evidence of financial solvency
- Risk assessments, including Martyn's Law readiness where premises qualify
- Health and safety policy documents aligned to the Health and Safety at Work etc. Act 1974
How does ACS scoring and banding work?
ACS scoring produces a banding that determines how a contractor is publicly listed — the higher the score, the stronger the market signal to clients and tender panels. Scores are calculated from the 78 indicators, with additional points available above the baseline zero for demonstrated good practice.
The top band is known as "Pacesetter" status. The ACS Pacesetter banding represents the top 15% of all companies under the SIA's ACS scheme, equating to approximately 700 companies as of July 2026, per ProFM Group (2026). ACS scoring for standard route approved contractors covers 780 companies, since NSI "passport scheme" approved contractors use a different scoring mechanism entirely, per the GOV.UK FOI response (2022).
The scheme offers real commercial reach. The SIA's Approved Contractor Scheme provides an opportunity for an estimated 4,000 UK security organisations to demonstrate their credibility, per Security Approval (2021) — meaning fewer than a quarter of eligible firms currently hold approval.
| Route | Who it covers | Scoring mechanism | Approx. company count |
|---|---|---|---|
| ACS Standard Route | Firms assessed directly against the 78 indicators | Points-based scoring across 7 criteria | 780 companies (2022 data) |
| NSI Passport Scheme | Firms already certified to NSI's own standards | Different, NSI-specific mechanism | Included within total 838 approved (2022 data) |
| Pacesetter banding | Top-scoring firms under either route | Top 15% by score | ~700 companies (July 2026) |
ACS Standard Route vs the NSI Passport Scheme
Firms choosing a certification body face a genuine either/or. The ACS Standard Route means direct assessment by a body such as SSAIB against all 78 indicators from scratch. The NSI Passport Scheme lets firms already holding NSI's own quality certifications carry some of that assurance across, using a different scoring mechanism, per the GOV.UK FOI response (2022). Firms already NSI-certified for other reasons — fire and security systems, for instance — often find the Passport Scheme faster; firms starting from zero typically go Standard Route.
Is the SIA replacing ACS with a new scheme?
The SIA has signalled a move towards a new Business Assurance Scheme (BAS) as part of a wider overhaul of security company standards, though the existing ACS framework remains the live accreditation route at the time of writing. The existing ACS scheme has been operating since 2006, according to the SIA's Strategic Plan for 2026–2029 (2026), and any transition is expected to be phased rather than immediate.
For firms currently preparing for or holding ACS approval, the practical implication is continuity: existing evidence-gathering discipline — licence checks, screening records, rota reconciliation — will very likely carry across to whatever replaces ACS, because the underlying operational questions (are your people licensed, vetted and where they're supposed to be) don't change with the scheme's name. Building that evidence trail into day-to-day systems now, rather than treating it as a once-every-three-years scramble, is the safer bet regardless of how BAS eventually lands.
Comparison: preparing for ACS in-house vs using an operations platform
Firms face a real choice in how they build their ACS evidence base. Some build it manually — spreadsheets, shared drives, a compliance officer chasing paper. Others run it through a platform that generates the evidence as a side effect of daily operations.
| Approach | Strengths | Weaknesses |
|---|---|---|
| Manual / spreadsheet-based | No new software cost; familiar to smaller teams | Evidence scattered across inboxes and drives; annual scramble; hard to prove patrol/rota consistency retrospectively |
| Compliance-only software | Tracks expiries and certificates centrally | Often disconnected from live rostering, patrols and incidents — still two systems to reconcile |
| Full operations platform (e.g. Pulse Operations) | Licences, screening, rotas, patrols and incidents live in one system; evidence exists because the business ran on it | Requires initial setup and migration, though Pulse's guided switch typically takes a fortnight |
Pulse Operations's compliance runway sits alongside rostering and workforce management, photo-verified patrols and a tamper-evident daily occurrence book covering 18 incident types, so the People, Service delivery and Resource management criteria are all drawing on the same live data rather than three separate systems an assessor has to be walked through.
Your ACS audit checklist
- Cross-check every operative's SIA licence number against the SIA's public register before the assessor arrives
- Confirm BS 7858 screening files and DBS certificates are complete and in date for every relevant role
- Reconcile duty rotas against time and attendance records for the last full assessment period
- Pull together signed client contracts, SLAs and any documented complaints or variations
- Compile training records covering induction, refresher and sector-specific training for all staff
- Verify the daily occurrence book and incident logs form a continuous, tamper-evident audit trail
- Review insurance certificates and financial solvency evidence ahead of the Financial management assessment
- Complete the SIA's Self-Assessment Workbook honestly, then test each declared score against real documentation
- Check Martyn's Law readiness for any qualifying premises, using Pulse Operations's Martyn's Law guide as a reference
FAQ
What is an ACS audit checklist?
An ACS audit checklist is a preparation list mapping the SIA's 78 assessment indicators, across seven criteria, to the actual evidence — licences, rotas, screening files, incident logs — a firm needs ready before a certification body's assessor visits. It exists to stop firms discovering gaps during the assessment itself.
What happens during an SIA ACS audit?
During an SIA ACS audit, an assessor from a UKAS-accredited body reviews staff files, payroll, contracts and site documentation, interviews staff and customers, and visits operational sites to verify self-assessment scores. One reported audit ran across 6 days against a 78-assessment criteria list (Herongrange, 2021).
How do I prepare for an ACS audit?
Prepare for an ACS audit by treating evidence-gathering as continuous rather than annual — keep SIA licences, BS 7858 screening, rotas and training records current in one system so nothing needs reconstructing before the assessor's visit. Complete the SIA's Self-Assessment Workbook honestly and test each score against documented proof before submission.
What documents are needed for an SIA ACS assessment?
An SIA ACS assessment requires SIA licence records, BS 7858 vetting files, DBS certificates, signed contracts, duty rotas, time and attendance data, training logs, incident reports, client SLAs, insurance certificates and risk assessments. Assessors cross-reference these against the seven scored criteria rather than accepting a self-declared score alone.
How long does an ACS audit take?
An ACS audit's length varies with company size and sector complexity, but reported assessments have run around 6 days against a 78-point criteria list, per Herongrange (2021). Larger, multi-sector contractors with more sites to visit will typically take longer than a single-site regional firm.
How often is an ACS audit carried out?
ACS approval renews every three years, with annual surveillance assessments in between, per Coredinate (2026). Where an assessor identifies improvement needs at an annual surveillance visit, they must be addressed within the timeframe the assessor sets, per Pulse Operations's ACS guide.
What is the difference between ACS Standard Route and the Passport Scheme?
The ACS Standard Route assesses a firm directly against all 78 indicators from scratch, covering 780 companies under standard scoring, per the GOV.UK FOI response (2022). The NSI Passport Scheme lets firms already NSI-certified use a different scoring mechanism, typically faster for firms with existing NSI accreditation.
What score do you need to pass an ACS audit?
Each of the 78 indicators has a required baseline achievement level scored as zero, with extra points available for evidenced good practice above that baseline, per Pulse Operations's ACS guide. Reaching the top-scoring "Pacesetter" band places a firm among roughly the top 15% of all approved contractors — around 700 companies as of July 2026, per ProFM Group (2026).
Is the SIA replacing the Approved Contractor Scheme with the Business Assurance Scheme (BAS)?
The SIA has signalled plans for a Business Assurance Scheme as part of a broader overhaul, though ACS — running since 2006 per the SIA's Strategic Plan 2026–2029 — remains the current live accreditation. Firms should keep building strong evidence trails now, since the underlying operational proof is likely to transfer to whatever scheme follows.
Preparing for your ACS audit with Pulse Operations
Every ACS criterion above — People, Service delivery, Resource management, Leadership — ultimately comes down to whether a firm's paperwork matches what actually happened on site, and that's the exact gap Pulse Operations was built to close. Licence expiries, BS 7858 screening, DBS status, right-to-work checks and training records sit on one compliance runway, while photo-verified patrols and a hash-chained, tamper-evident daily occurrence book generate the Service delivery and People evidence assessors ask for as a by-product of normal operations, not a pre-audit scramble.
Pulse Operations's own operational data shows 96.2% of checkpoints across live operations carry a watermarked, GPS-tagged photo (trailing 90 days, as of July 2026 — see the benchmark) — exactly the kind of consistent, verifiable record an ACS assessor is trained to look for rather than take on trust.
If your firm is heading towards an ACS assessment, or an annual surveillance visit is on the horizon, get in touch with Pulse Operations for a demo of the compliance runway and photo-verified patrol system — pricing is published openly at pulse-operations.co.uk/pricing, and most firms complete a guided switch within a fortnight.
Related Reading
- Security Site Induction Checklist UK: Full 2026 Guide
- Body Worn Camera Rules for UK Security Firms 2026
- Guardhouse Alternative 2026: Best UK Options Compared
