Security Compliance Checklist: What South African Businesses Should Verify

A South African business should verify more than a security company’s registration certificate. Good due diligence covers the provider, the people deployed to the site, employment and injury-cover evidence, firearms where applicable, health and safety, information protection, insurance, operating procedures, subcontractors and recurring performance records.

This checklist helps procurement, facilities and compliance teams organise that evidence. It is general information, not legal advice. Your exact obligations may also depend on your industry, bargaining arrangements, insurer, landlord, tender, municipality and contract. Ask a qualified legal or compliance professional to review high-risk or uncertain requirements.

How to use this security compliance checklist

For every item, record four things: the document or test used as evidence, the person who verified it, the verification date and the next review date. “Received” is not the same as “verified.” Check the issuing source, name, registration number, expiry date and whether the document applies to the entity actually delivering the service.

Classify each item as:

  • Required by law: a legal obligation applicable to the service or organisation;
  • Required by contract: an insurer, client, tender, landlord or site-specific requirement;
  • Recommended control: good practice used to reduce an identified risk.

This distinction prevents a useful practice from being presented inaccurately as a universal legal rule.

1. Verify the security business with PSIRA

The Private Security Industry Regulation Act requires persons rendering security services for remuneration to be registered, subject to applicable exemptions. Its definition of security services includes guarding, response, security advice, investigations, security-equipment installation or servicing and monitoring signals from electronic security equipment.

  • Obtain the provider’s full registered name and PSIRA number.
  • Verify current status through PSIRA’s official verification channels.
  • Confirm that the entity on the quotation, contract and invoice is the verified entity.
  • Check directors and managers where relevant to the statutory requirements.
  • Repeat verification periodically and before renewal, not only during the first tender.

Do not accept an expired certificate, a certificate belonging to a related company or a trading name that cannot be connected to the contracting entity.

2. Verify deployed officers, supervisors and specialists

Request a controlled deployment list before mobilisation and whenever staff change. For each assigned person, verify identity, PSIRA status and the grade or competence relevant to the work. Confirm that supervisors, control-room operators, armed personnel, investigators and technical staff meet the applicable requirements for their duties.

Maintain appropriate privacy and access controls around personnel records. Your evidence pack can record that verification was completed without circulating unnecessary copies of identity documents.

3. Check employment, wage and workforce controls

A price that depends on underpaying or overworking officers creates legal, ethical and operational risk. Ask the provider to demonstrate compliance with applicable employment law, sector arrangements and statutory deductions without requesting more personal information than you need.

  • Written employment arrangements and lawful payroll practices;
  • Applicable wage, overtime, leave and working-time compliance;
  • UIF and other required registrations or contributions;
  • Shift rosters that support the promised post coverage;
  • A relief plan for leave, absence and training;
  • Processes for grievances, discipline and fatigue concerns.

Define a proportionate audit right in the contract. Sensitive payroll data should be handled securely and only by authorised reviewers.

4. Confirm COIDA registration and good standing where applicable

Ask for current Compensation Fund evidence where it applies to the provider and contract. The Department of Employment and Labour states that Compensation Fund-registered employers whose returns and payments are up to date can generate a Letter of Good Standing, and that the certificate number can be validated.

Record the validity period and schedule a new check before it expires. If a subcontractor supplies personnel, verify the appropriate evidence for that entity too.

5. Verify firearm authority for armed services

Where the service includes armed officers or armed response, request evidence that the business, firearms and assigned personnel comply with the Firearms Control Act and applicable regulations. Confirm that authorisations match the firearms and duties involved.

  • Business-purpose licences and supporting records;
  • Relevant individual competency and training;
  • Issue, return, inspection and ammunition controls;
  • Safe custody and loss-reporting procedures;
  • Site rules for carrying and using firearms;
  • Incident escalation and evidence preservation.

Do not rely on the statement “our officers are licensed.” Have a competent reviewer verify the actual documents and processes. The SAPS Central Firearms Register is the authoritative route for firearm licensing information.

6. Review health and safety responsibilities

The Occupational Health and Safety Act addresses the health and safety of people at work and others affected by workplace activities. Security officers can face vehicle movements, lone work, confrontation, weather, working at height, dogs, firearms, electrical equipment and emergency conditions.

Before mobilisation, agree how the client and provider will coordinate:

  • Site induction and hazard communication;
  • Required personal protective equipment;
  • Emergency and evacuation procedures;
  • First-aid access and incident reporting;
  • Safe patrol routes and restricted areas;
  • Vehicle, radio, battery and equipment inspections;
  • Fatigue, heat, cold and lone-worker controls.

Record responsibility instead of assuming that the other party owns it.

7. Check insurance against the proposed service

Ask for current certificates and policy details relevant to the scope. Depending on the work, this may include public liability, employer-related cover, professional indemnity, fidelity or crime cover, motor cover and insurance for equipment in the provider’s custody.

Check the insured entity, limits, exclusions, excesses, geographic scope and renewal date. A certificate confirms that a policy exists; it does not prove that every event is covered. Ask your broker or legal adviser to assess material exposures.

8. Apply POPIA to CCTV, access and incident data

CCTV footage, access logs, visitor records, vehicle details, biometrics and incident reports can contain personal information. POPIA requires appropriate, reasonable technical and organisational safeguards, regular verification of those safeguards and updates in response to new risks or deficiencies.

If the security provider processes personal information on your behalf, POPIA provides for security measures to be addressed through a written contract with the operator. The contract should cover:

  • Purpose and permitted use of the information;
  • Authorised users and role-based access;
  • Confidentiality and personnel obligations;
  • Storage location, retention and secure deletion;
  • Remote access, passwords, updates and access logs;
  • Disclosure to law enforcement, insurers or other parties;
  • Immediate escalation of suspected unauthorised access;
  • Return or deletion of information at contract end.

Use clear notices and internal privacy documentation where appropriate to the processing. Have the organisation’s Information Officer review the arrangement. For system-specific controls, see how to design a complete business CCTV system.

9. Verify the operating procedures, not only the certificates

Compliance documents do not prove that the service works. Before go-live, approve site-specific instructions covering access, keys, visitors, contractors, deliveries, patrols, alarms, emergencies, prohibited conduct, incident scenes and escalation.

Check that officers can explain the procedures in practical terms. Run supervised scenarios and record corrective actions. Repeat tests after major staff, process or site changes.

10. Control subcontractors and third parties

Ask the lead provider to disclose any subcontracted guarding, response, monitoring, installation, maintenance, data hosting or specialist work. State whether client approval is required and make relevant compliance obligations flow down to each subcontractor.

The lead provider should remain accountable for the contracted outcome. Keep an up-to-date supplier map so an incident is never the first time you discover who actually monitors the alarm or stores the footage.

11. Check procurement and transformation evidence

Verify CIPC details, tax-related evidence required by your procurement process, banking details through an independent control and any declarations required for conflicts, anti-bribery or sanctions. If B-BBEE status is part of the tender or supplier policy, verify the appropriate certificate or affidavit.

B-BBEE status is an important procurement consideration for many organisations, but it is not a substitute for PSIRA registration, operational competence or site-specific compliance.

12. Maintain a live contract compliance file

The evidence pack should remain current after appointment. A useful monthly or quarterly file includes:

  • Current provider and deployed-personnel verification;
  • Approved roster, post schedule and relief changes;
  • Training, induction and competency records;
  • Equipment inspection, maintenance and fault reports;
  • Patrol and access-control exceptions;
  • Incident logs, response timestamps and investigations;
  • Open corrective actions with owners and deadlines;
  • Current insurance, COIDA and other time-limited documents;
  • Subcontractor changes and approvals;
  • Minutes and performance scorecards.

Copy-ready verification register

CheckEvidenceOwnerStatusNext review
PSIRA business statusOfficial verification resultProcurementOpenBefore award / periodic
Deployed personnelVerified deployment registerSecurity managerOpenOn every change
COIDA good standingValidated current letterComplianceOpenBefore expiry
Firearm controls, if applicableLicensing and competency reviewCompetent reviewerOpenBefore deployment / periodic
OHS coordinationRisk, induction and emergency recordsHSEOpenOn change / annual
InsurancePolicy schedule and broker reviewRisk / financeOpenBefore expiry
POPIA and data handlingOperator terms, access and retention controlsInformation OfficerOpenOn change / annual
Site proceduresApproved SOPs and test resultsOperationsOpenAfter incident / change
SubcontractorsApproved supplier and compliance listContract managerOpenOn every change

Common compliance failures to catch early

  • The registered entity is not the entity named in the contract;
  • Officer records were valid at tender stage but not checked after replacements;
  • An armed service is included without complete site-specific verification;
  • CCTV access is shared through generic accounts;
  • A subcontractor stores footage but is absent from the data agreement;
  • Insurance or good-standing evidence expires unnoticed;
  • Procedures exist on paper but officers have not been assessed on them;
  • Corrective actions are logged repeatedly without an accountable deadline.

Frequently asked questions

Is PSIRA registration enough to appoint a security provider?

No. It is a fundamental eligibility check, but the business should also verify people, capability, employment controls, insurance, site procedures, data protection and performance against the proposed service.

How often should security compliance documents be checked?

Check before appointment, before each time-limited document expires and whenever the provider, deployed personnel, subcontractors, scope, technology or risk changes. Use a monthly or quarterly dashboard for ongoing controls.

Does POPIA apply to CCTV?

It can apply where footage relates to identifiable people or entities. The responsible party should document purpose, access, safeguards, retention and disclosure, and should obtain advice for its specific use case.

Is B-BBEE proof a legal security requirement?

It can be required by a tender, procurement policy or client, but it does not replace security-industry registration or operational due diligence.

Who should own the compliance file?

Appoint one contract owner, with defined inputs from procurement, operations, HSE, the Information Officer, finance and legal or risk. Shared ownership without a named coordinator often leads to expired evidence.

Turn compliance into an operating control

A compliance checklist is valuable only when the evidence is verified, assigned and reviewed. Build it into supplier onboarding, monthly performance meetings and annual risk reviews.

Need help reviewing your current arrangement? Contact Azomakhanye Security Services for a compliance-led security consultation.

Authoritative references

Leave a Reply

Your email address will not be published. Required fields are marked *

Protect What Matters Most

Partner with Azomakhanye Security Intelligence and gain a security solution that is proactive, intelligent, and built around your needs.