top of page
solomons-facilities-management-logo.jpg

Corporate Security Services in London: A Practical Guide

  • Writer: Solomons FM
    Solomons FM
  • Aug 27
  • 10 min read

You arrive at a Canary Wharf tower on Monday morning and the security picture is already incomplete. Three overnight incident reports are missing, the patrol log doesn't reconcile with access-control timestamps, and the control-room phone has gone unanswered twice. The supplier's account manager is asking for more time to investigate, while your landlord, tenants and senior leadership want a clear answer now.


That situation exposes the core purpose of corporate security services. You aren't buying bodies in uniform or the lowest hourly rate. You're buying a controlled operating system for people, premises, information and incidents, with one party accountable when the system fails. The contract should show who owns the outcome, how performance is measured, how licences are verified, and how physical evidence moves securely through your organisation.


For London facilities teams, the practical decision covers five areas: the service you need, the supplier structure that closes accountability gaps, measurable KPIs, SIA compliance, and the connection between physical security and digital evidence.


Table of Contents



The Real Question Behind Hiring Corporate Security Services


The usual procurement question is, “How many officers do we need?” It sounds practical, but it often produces the wrong contract. Headcount doesn't tell you whether an overnight patrol happened, whether the officer could reach the right loading bay, whether a CCTV alert was escalated, or whether the incident record is complete by the time management arrives.


The better question is, who owns the security outcome when something goes wrong? It makes you examine control-room cover, handover quality, patrol verification, escalation routes, access-control data and the relationship between reception, engineering, cleaning and security.


A guard can follow the post orders correctly and still be undermined by a failed camera. A reception team can challenge an unauthorised visitor and still lack the authority to hold them while the security supervisor responds. A patrol provider can report a locked door while the access system shows it was opened moments later.


Treat security as an operating process


A sound corporate security services brief should define the risks first, then specify the controls.


For a London office estate, that might include unauthorised entry, tailgating, theft from loading areas, out-of-hours access, tenant incidents, protest activity, fire-door breaches and incomplete evidence after an event.


The supplier should then explain how officers, reception staff, CCTV operators, access systems and the facilities team work together.


Require a named escalation chain, shared reporting standards and a clear handover process between shifts.


Make the contract answerable


The Security Industry Authority reported 507,300 active licences in its 2024-25 annual report, with 7,343 licences revoked and 1,528 suspended during the year. It also recorded 723 businesses approved or reapproved under the Approved Contractor Scheme, as shown in the SIA annual report and accounts for 2024 to 2025. The figures underline the scale of a regulated workforce, but your contract still has to turn regulation into daily evidence.


Ask for reports that reconcile with building systems. Ask who checks the checks, who receives an exception, and what happens when an officer is absent, a camera fails or an incident crosses from security into engineering or IT.


Core Service Categories and When Each One Earns Its Cost


Corporate security services work when each element has a defined job. Buying every available service creates activity, not necessarily protection. Start with the operational trigger that justifies the spend.


Static guarding


Static officers earn their cost where front-of-house control and security are inseparable. A multi-tenant office with frequent visitors, contractors, deliveries and executive meetings needs more than a receptionist with a visitor tablet. The officer may need to challenge access, manage incidents, protect sensitive areas and coordinate emergency response without turning the entrance into a hostile checkpoint.


Specify the post's purpose, not merely its hours. Include visitor screening, contractor sign-in, badge control, delivery procedures, incident logging and relief arrangements. For a deeper operational view, see static security guards for corporate premises.


Mobile patrols


Mobile patrols suit multi-site portfolios, perimeter checks and out-of-hours risk. They earn their cost when a fixed officer can't cover several entrances, roof areas, car parks, plant rooms or satellite buildings. Scheduled and randomised visits are more useful than predictable rounds that create a timetable for anyone watching the site.


Patrol instructions should identify risk points, required checks, evidence of arrival and the escalation threshold. The SIA publishes current data on approved security contractors, including breakdowns by licensing sector and UK region, which can help buyers assess the regulated supplier market. The SIA's 2026–29 strategic plan reports that 719 businesses are approved contractors, with 670 supplying security guarding services, and notes that most are based in London and the South East.



CCTV monitoring


A wall of screens isn't monitoring if no one reviews the alert, records the decision or escalates it to the right person. Require documented procedures for alarm verification, camera failure, evidence preservation and communication with on-site officers or emergency services.


Event security


Event work is a separate discipline. Crowd movement, search procedures, queuing, restricted areas and emergency routes need a plan that matches the venue and audience. Don't fold event cover into a general guarding schedule without checking competence, licensing and supervisor arrangements.


Access control and reception


Integrated access control turns security into part of the visitor experience. Reception staff issue badges, verify appointments and handle enquiries, while security controls exceptions and responds when someone refuses the process. This works best when both teams use one procedure and one incident record.


Single-Supplier FM Versus Multiple Security Vendors


A single integrated facilities management supplier can deliver security alongside reception, cleaning and mechanical and electrical services. A multi-vendor model gives each discipline its own specialist contract.


With multiple vendors, a missed patrol may sit with the security company, a faulty camera with the technology contractor and an open door with reception or engineering. Each supplier can produce a defensible explanation while the client still owns the operational failure. The facilities manager becomes the integration layer, often without the authority or information needed to control it.


A single supplier doesn't remove every risk. It does give you one contract owner, one account director and one escalation route. KPIs can cascade across security, reception, cleaning and engineering rather than stopping at departmental boundaries. The model is especially useful where an access incident involves a guard, a receptionist, a door controller and a tenant representative.


Dimension

Single-Supplier FM

Multiple Security Vendors

Accountability

One contract owner for connected failures

Responsibility can sit across separate contracts

Reporting

A consolidated operational picture

Separate reports requiring manual reconciliation

Escalation

One account director and defined chain

Several account teams and competing priorities

Specialist depth

May depend on the supplier's subcontracting and management model

Stronger discipline-specific focus can be available

Mobilisation

One coordinated transition

Multiple mobilisations, interfaces and handovers

Commercial control

Fewer invoices and variation routes

Greater choice, but more contract administration

Client resource

Lower integration burden if governance is strong

Higher in-house coordination requirement


The trade-off is real. A specialist CCTV operator, guarding company or event-security provider may outperform a general FM supplier in its individual discipline. If your estate has unusual technical systems, high-risk operations or complex event requirements, specialist capability may justify separate procurement.


Before choosing consolidation, assess building complexity, compliance exposure and your own contract-management capacity. The integrated facilities management model makes most sense when the client wants one party to manage the interfaces, not just one invoice.


The supplier must state who responds to a failed access reader, who checks a propped fire door, who retrieves footage and who informs the client when an incident affects several systems.


KPIs, SLAs and the Reporting a London Contract Should Demand


A London corporate security contract should define the event, the clock, the evidence, the reporting owner and the consequence of failure.


Set targets that reflect the building's risk and geography. For an alarm call in a City building, you might require an on-scene guard within a clearly defined site-specific response time, provided the supplier validates that target through a site survey and response plan. Define minimum patrol frequency per shift, lone-worker check-in cadence and the time allowed for incident reports.

KPI / SLA

Example contractual target

Reporting cadence

Alarm response

Guard on scene within the agreed site-specific response time.

Per incident and monthly trend

Patrol completion

All contracted visits completed, with time, location and exception evidence

Daily exception report and monthly KPI pack

Incident reporting

Initial notification within the agreed period, followed by a complete report

Per incident

Lone-worker welfare

Check-ins at the agreed cadence, with missed-check escalation

Shift record and weekly exception summary

Licence compliance

Every deployed officer holds the required in-date SIA licence

Pre-deployment and monthly audit

Reporting delivery

Daily logs, weekly exceptions and monthly KPI pack delivered on time

Daily, weekly and monthly


Demand usable evidence


Require daily occurrence logs in a shared format, weekly exception summaries and monthly KPI packs with trend lines. The monthly pack should show planned versus completed patrols, response performance, incidents by category, open actions, staffing changes, training status and recurring exceptions.


Separate hard SLAs from soft KPIs. A hard SLA can trigger financial abatement or a service credit. A soft KPI can require an improvement plan, additional supervision or a management review.


Remove vague tender language


The SIA's 2026–27 business plan places renewed emphasis on strengthening individual licensing and improving security business standards. That makes licence tracking and supplier verification an ongoing contract control, rather than an administrative check carried out only at mobilisation.


SIA Licensing and Approved Contractor Scheme Evidence


Treat SIA checks as an operational control you repeat. The provider must prove that each person deployed is authorised for the role they perform and that the company evidence remains current.


Run the individual check


Start with the operative's licence number and verify it on the public SIA register. Check that the licence type matches the duty, whether that is Security Guarding, Door Supervision or Public Space Surveillance (CCTV). Then verify the expiry date before deployment and again through the contract's review cycle.


A person suitable for reception security may not hold the authorisation required for door supervision or public-space surveillance.


The SIA is also developing a new Business Approval Scheme (BAS) to replace the existing ACS, with pilot activity planned for spring 2027.


Check the company evidence


If the supplier claims Approved Contractor Scheme status, check the SIA register to confirm which licensable activities its approval covers and when the approval expires.

An ACS status indicates that the business has undergone an audited assessment of its systems, but it doesn't remove your responsibility to test whether those systems operate at your site.


Don't confuse an ACS certificate with proof that every individual is correctly licensed. One concerns the organisation's approved processes, while the other concerns the operative's legal authorisation for a particular role.


Request a complete evidence pack


Before award, request:


  • Licence register: Names, licence numbers, role types and expiry dates for proposed officers.

  • Verification method: The process and owner for checking status before each deployment.

  • ACS evidence: Current approval, scope and assessment documentation where applicable.

  • Vetting records: Confirmation that required checks and role-specific screening are complete.

  • Training matrix: Site induction, conflict management, emergency procedures and system training.

  • Insurance documents: Current certificates and policy scope relevant to the services.

  • Change-control process: The method used after sickness cover, staff replacement or TUPE transfer.



Where Physical Security Meets Digital Evidence and Compliance


The modern security operative doesn't just patrol a building. They may create body-worn video, access logs, incident photographs, vehicle records and footage requests. Those records enter the same information environment as employee data, visitor details, HR records and building-management systems.


The UK's cyber security sector generated £14.7 billion in revenue in 2026, up 11% on the previous year's study, with 2,603 firms and 69,600 full-time equivalent employees, according to the UK government's 2026 cyber security sectoral analysis. For facilities teams, the implication is direct: physical security suppliers must now answer credible questions about data handling.


Put integration questions in the tender


Ask bidders to explain:


  • Identity management: Can the VMS and access-control platform support single sign-on and role-based permissions?

  • Evidence export: Can the incident system export footage, photographs and access records through a controlled process?

  • Audit trails: Who can view, download or amend evidence, and where is that activity recorded?

  • Retention: How are retention periods set for CCTV, body-worn video, photographs and access logs?

  • Subject access: How will the supplier support a data subject access request without exposing unrelated people?

  • Lawful monitoring: What is the documented basis for monitoring staff areas and recording visitors?

  • Cyber controls: How does the supplier align its systems and subcontractors with the client's cyber security requirements?


GDPR decisions must cover footage retention, access requests and monitoring in staff areas. Set the purpose, access authority, review process and deletion rule in the information-governance schedule.


CCTV monitoring only works as part of that chain when operators can detect, document and escalate an event without compromising the evidence. The CCTV monitoring services overview is relevant to buyers comparing remote monitoring with on-site response.


The following video can help frame the evidence-management discussion:




Choosing a London Security Provider and Putting It on Contract


Use the following weighting as a practical starting point:


Criterion

Weight (%)

Evidence to Request

Benchmark to Expect

SIA ACS status

20

Current certificate, scope and assessment evidence

Approval relevant to the contracted services, with transparent limitations

London incident response record

15

References, anonymised incident records and response reports

Comparable estates, clear escalation and evidence of review

Single-supplier FM integration

15

Operating model, interface matrix and account structure

One accountable lead with defined cross-service responsibilities

KPI transparency and reporting

15

Sample daily logs, exception summaries and monthly packs

Time-stamped data, trend analysis and action ownership

Officer welfare and training

10

Training matrix, supervision plan and welfare process

Role-specific competence, relief cover and visible supervision

Cyber-physical evidence handling

10

Data flows, retention schedule and access audit process

Controlled storage, permission management and export procedure

Contract flexibility

15

Mobilisation plan, variation terms and exit provisions

Milestones, continuity controls and a workable handover


Test the bidder in the building


Shortlist three to five bidders and make the site visit decisive. Ask each one to inspect a comparable London estate, not just present slides at its head office. Watch whether the proposed account director notices loading-bay access, reception queues, blind spots, lift dependencies, delivery peaks and the quality of the existing handover.


Protect the exit as carefully as mobilisation


Write a clear exit clause tied to repeated SLA failure, serious compliance breaches and failure to maintain agreed cover. Require an orderly handover of reports, keys, access permissions, footage procedures and site instructions. A provider earns trust by making continuity measurable, not by promising that problems won't occur.


A London-based option such as Solomon's Facilities Management combines security, reception, CCTV monitoring, cleaning and concierge under a single contract, with SIA-licensed personnel and digital patrol and incident reporting.



Looking for corporate security services in London? Contact Solomon's Facilities Management to discuss your security, reception, CCTV monitoring and wider facilities-management requirements.

Comments


290b12_d6b14ae5707b49d1b85231d152625b37~mv2.jpg

SOLOMON'S FACILITIES MANAGEMENT

Get a quote for security guards or FM services in London — free, within 24 hours

SOLOMON'S FACILITIES MANAGEMENT

Social Media Accounts

bottom of page