SIA Compliance for Buyers: What You Must Check Before a Guard Steps On Site
A plain-English guide to Security Industry Authority obligations — and how UK security operations are replacing spreadsheet chaos with software that never misses an expiry date.
See How GuardFlowApp Handles This
What does SIA compliance mean for a buyer of security services?
UK buyers of security services must verify that all operatives hold a valid, in-date SIA licence for the specific role they carry out. Checking licence status, licence category and expiry date before an operative starts work — and retaining a record of each check — is the minimum a compliant buyer must do. The Security Industry Authority (SIA) is the non-departmental public body that regulates the private security industry across England, Wales, Scotland and Northern Ireland, and its licensing regime is a legal requirement, not a voluntary standard. Deploying or knowingly using an unlicensed operative exposes both the security provider and the procuring organisation to significant legal and reputational liability.
The six compliance checks every buyer should make before and during a security contract
SIA compliance is not a single check at contract start — it is a continuing obligation throughout the life of the engagement. A buyer who takes compliance seriously should confirm all six of the following before any operative works on their premises, and repeat the process whenever the workforce changes.
- Verify each operative holds a current, in-date SIA licence using the SIA's free public licence checker at sia.homeoffice.gov.uk — a licence number or full name is enough to confirm status
- Confirm the licence category matches the role: a Security Guard licence does not authorise door supervisor duties, a CCTV (Public Space Surveillance) licence does not cover close protection, and substituting categories is a compliance breach even when the individual is otherwise licensed
- Check that your security contractor holds SIA Approved Contractor Scheme (ACS) status — the independently assessed quality standard for security providers covering management, training, business integrity and operational practices
- Track licence expiry dates throughout the contract: SIA licences run for three years and must be renewed before they lapse — an operative whose licence expires mid-contract is unlicensed from that date
- Retain a written record of every licence check you carry out, with the date, the licence number confirmed and who conducted the check, so you can demonstrate due diligence in the event of an audit or incident
- Repeat a full check for any new operative added to your contract — a change in staffing is a fresh compliance trigger, not a continuation of an existing check
How it works
In practice, most compliance failures happen not because buyers or security firms don't know the rules, but because tracking dozens of licences across a rotating, multi-site workforce falls apart when the process lives in spreadsheets and shared inboxes. A security operation managing fifty operatives across ten sites needs to know, at any moment, whose SIA licence expires in the next thirty days, which site is approaching a gap and which operatives are deployed where. That visibility is impossible to sustain manually without someone missing something. GuardFlowApp — built and operated by the NovaStacks team — was designed for exactly this operational reality. Licence expiry tracking, automated alerts, shift scheduling, site assignments and auditable compliance records sit in one platform, not across five tools and a spreadsheet. For buyers who want to hold their security contractor to account, the right question to ask your provider is simple: can you show me a live compliance dashboard? A provider who can't answer that question is a provider running on manual checks.
Why NovaStacks — proof from the security industry
NovaStacks doesn't advise on security software from the outside. GuardFlowApp is a live, operational security workforce management platform built and run by the NovaStacks engineering team — every compliance tracking pattern in the platform was stress-tested in a real security operation before it was offered to a single client. That distinction matters: off-the-shelf workforce tools are built for generic use cases and retrofitted to security. GuardFlowApp was built for security from day one, which is why it handles the specifics that generic platforms miss — licence category matching, site-level compliance status, expiry windows and audit trails that hold up under scrutiny. For security firms whose compliance requirements go beyond the GuardFlowApp standard platform — bespoke integrations with existing payroll or HR systems, white-labelled compliance portals for their own clients, or custom reporting for large multi-site contracts — NovaStacks builds to the same production standard it holds its own live products to. The team has built and continues to run software across security, care, fleet and cleaning, and every new build starts with the same question: what does non-compliance cost you today, and what does the process actually look like?
Frequently asked questions
Is it the security company's responsibility to hold SIA licences, or does the buyer also carry obligations?
Both parties carry legal and operational responsibility. The individual operative must hold a valid SIA licence to work legally — working without one is a criminal offence. The security contractor has a duty to deploy only licensed staff. The organisation buying the service has a duty not to knowingly use unlicensed personnel and should take reasonable steps to verify compliance independently. Retaining evidence of the licence checks you ran is the practical way to demonstrate you discharged that duty if an incident or audit ever puts the question to you.
How do I check whether an operative's SIA licence is valid right now?
The SIA provides a free public licence checker at sia.homeoffice.gov.uk. Enter the operative's licence number or full name to confirm whether the licence is current, which category it covers and when it expires. Buyers should run this check before an operative starts work on their premises and repeat it periodically for the duration of long-running contracts — the database reflects current status in real time, so a check from six months ago tells you nothing about today.
Is ACS accreditation legally required, or just best practice?
ACS status is voluntary — there is no legal rule that forces a buyer to use only ACS-accredited contractors. However, procuring from an ACS-accredited firm is the clearest available signal that your provider has been independently assessed against defined standards covering training, management and operational integrity. Many public sector contracts and large corporate procurement frameworks now require ACS as a minimum, and from a due diligence standpoint, choosing a non-ACS provider creates a gap in your compliance narrative that is harder to defend if something goes wrong.
Stop tracking SIA licences manually — see the platform built for it
SIA licence compliance fails when it depends on human memory and files that someone forgets to update. Whether you run a security operation and need a platform that surfaces expiry alerts automatically across your whole workforce, or you buy security services and want contractual proof that your provider is managing compliance properly, GuardFlowApp gives you the operational backbone to stay compliant without the manual overhead. If your compliance needs go further than a standard platform covers, the NovaStacks team builds bespoke security software to the same standard it runs in its own live products. Tell us what your current process looks like and we will show you what it looks like when it runs on software built for security.
See How GuardFlowApp Handles This
See How GuardFlowApp Handles This
Thanks — we've got your details and we'll be in touch shortly.