A security failure is rarely caused by one dramatic mistake. More often, it starts with a vague instruction, an unclear escalation route, or a report that never reaches the person who needs to act on it.
In plain English, a security services SLA is a security service level agreement. It sets out what the provider will do, how performance is evidenced, and what happens when standards slip.
The starting point is not a template. It is the actual site, its risks, its people and its operating hours.
A contract, service specification and SLA do different jobs
These documents are often bundled together, then treated as though they say the same thing. They do not.
The contract sets the legal and commercial framework
Private security companies often divide contractual and operational responsibilities across these documents. The contract sets out the commercial arrangement within relevant legal frameworks. It identifies the parties, charges, insurance, liability limits, payment terms, confidentiality requirements, dispute resolution, termination rights and the length of the arrangement.
It also records responsibilities which cannot be left to a verbal understanding. For example, who provides radios, access cards, body-worn cameras, welfare facilities, parking, induction training and control-room access.
A contract can be perfectly valid whilst still saying very little about daily security operations. That is where the service specification and SLA matter.
The scope of services describes the work, the SLA measures it
The service specification, or scope of services, states what the officers, mobile patrol team or control room are contracted to do. It should name the premises, posts, shift patterns, patrol areas, access points, visitor procedures and exclusions.
The service level agreement then states the agreed standard. It might require a logged welfare check at set intervals, a monthly management report, or an incident report submitted within an agreed period.
“Provide a professional service” is not a service level. It is a marketing phrase with no practical test.
For procurement teams, the useful question is simple: could an independent person review the records and tell whether the service was delivered?
Build the agreement around the site risk assessment
The agreement must be built around site-specific risk, not a generic schedule. A warehouse at night, a managed residential block, a construction site and a busy public venue need different controls. One schedule cannot properly cover all four.
Start with the operational reality
The risk assessment should identify what is being protected, who uses the site, when risk increases and what a security officer can reasonably control. Theft, unauthorised access, lone working, violence, fire safety, anti-social behaviour and terrorism-related risks may all be relevant.
For airports, shopping centres and other high-footfall environments, the agreement should account for crowd movement, lost children procedures, abandoned items, public reassurance and rapid liaison with police or emergency services. A fixed response target copied from another site is not enough.

Record what changes the level of service
The SLA should state how service levels change during deliveries, events, refurbishment works, seasonal trading, tenant moves or reduced opening hours.
It should also say who can request additional cover, what notice is required, and how emergency cover is authorised. Otherwise, an urgent request can become an argument about cost and authority whilst the site remains exposed.
A good review cycle is also part of the agreement. Risk assessments should not sit untouched for three years because the original contract has not expired.
Set clear scope, staffing and competence requirements
Security guard services are made up of ordinary details. That is exactly why they need to be written down.
Define the scope and its limits
List each duty in practical terms: reception screening, patrols, keyholding, alarm response, CCTV observation, access control checks, vehicle checks, contractor sign-in, opening and locking, or event stewarding.
Then state what the provider is not responsible for. A guard may report a faulty fire door, for example, but is not responsible for repairing it. A concierge may monitor visitors, but may not have authority to use force or physically remove a person.
This avoids the familiar problem where the client assumes a task is covered because it sounds like security, whilst the provider regards it as an extra service.
Check licences, training and supervision
Where a role involves licensable activity under a contract for services, private security companies must supply appropriately licensed staff. Clients can use the official register to check security staff have a licence.
The SLA should require the provider to notify the client if a licence, right-to-work check, qualification or vetting status affects an assigned officer. It should also cover site induction, first aid, conflict management, fire procedures and any role-specific training.
SIA licence-linked training requirements include Emergency First Aid at Work competence for Security Guarding and Door Supervision applicants. The current SIA training guidance is a sensible reference point, but site training still needs to be agreed separately.
What a security services SLA should measure
The strongest performance metrics describe an outcome, a source of evidence and a review period. Together, they form practical key performance indicators for contract reviews. They don’t reward paperwork for its own sake.
Use targets that fit the service type
For static guarding, useful measures may include filled shifts, punctual handovers, completed patrols, welfare checks and post instructions followed. For keyholding or mobile response, expectations must reflect distance, traffic, access arrangements and the priority of the callout. Alarm response times should be realistic for the site and the agreed service level.
For CCTV or remote monitoring, metrics may cover alarm handling, outage reporting, system uptime and the escalation of confirmed incidents. Don’t borrow a promise from a sales proposal unless the provider can explain how it will be delivered at your site.
Measure what happens after an incident
Incident reporting isn’t complete when an officer submits a form. The SLA should track whether the report was timely, factual, correctly categorised and followed by the right action.

A guard tour system, digital occurrence book or control-room log can provide useful evidence. However, the agreement should state who owns the data, who can access it, how long it’s retained and what happens when the system fails.
| Area | A workable SLA measure | Evidence |
|---|---|---|
| Staffing | Agreed shifts filled by approved officers | Rota, attendance and handover records |
| Patrols | Required patrols completed within agreed windows | Guard tour records and exception logs |
| Incidents | Priority reports sent within agreed timescales | Incident record and escalation log |
| Quality | Corrective actions closed by the agreed date | Monthly review minutes |
The point is accountability. A long report that doesn’t show missed patrols, recurring faults or overdue actions is decorative.
Put incident response and reporting routes in writing
When an incident happens, staff shouldn’t need to interpret a contract before making a decision. The incident response plan needs to be direct and support emergency management during fire, medical, violence and major system incidents.
Agree the escalation pathway
Set out the communication protocols and escalation procedures, including what the officer does first and who is contacted next. State when emergency services take priority. The pathway should cover fire alarms, medical emergencies, violence, suspected criminal activity, suspicious items, unauthorised entry, safeguarding concerns and major system failures.
Name the client contacts and provide an out-of-hours route. Include a process for failed contact attempts, so officers know when they can proceed to the next escalation level.
The provider’s control room may coordinate the response, but the SLA should state whether it has authority to call contractors, arrange relief staff or instruct a keyholder. It should also define which decisions remain with the client.
Make reporting useful to management
Set clear reporting requirements for immediate visibility and longer-term management review. Daily occurrence reports are useful for immediate visibility. Weekly or monthly reports should reveal patterns such as repeat trespass, access-control faults, missed deliveries, damaged fencing, aggressive behaviour or recurring patrol findings.
Reports should distinguish fact from opinion. For security incidents, they should include times, locations, actions taken, witnesses where appropriate, reference numbers and supporting images or footage where lawfully held.
A monthly review should also record corrective actions, responsible owners and dates. If the same failure appears for three months, the meeting has become a ritual rather than a control.
Handle compliance, data and service failure properly
An SLA supports compliance requirements, but it doesn’t transfer every legal duty from client to provider. Each party remains responsible for its own obligations.
Cover UK GDPR, health and safety and future duties
CCTV footage, visitor records, access logs, body-worn video and incident reports may contain personal data. The agreement should identify whether each party is a controller or processor, set access restrictions, define retention periods and require prompt reporting of suspected data breaches. The ICO’s data protection guidance is clear that safeguards must be appropriate to the risk.
Health and safety responsibilities need the same clarity. Officers need safe access, suitable welfare facilities, reliable communications and a method for reporting hazards. The security provider and client must not treat outsourced staff as invisible simply because another company employs them.
Martyn’s Law, formally the Terrorism (Protection of Premises) Act 2025, received Royal Assent on 3 April 2025. Its core duties are not yet in force and implementation is expected in spring 2027. The Home Office factsheet on Martyn’s Law is useful background for affected venues and events.
Use service level credits with care
Service level credits can apply to measurable, repeated failures, such as an unfilled shift or missed mandatory report. They’re not a substitute for fixing an unsafe service.
The clause should define the trigger, evidence, measurement period, exclusions, credit calculation, monthly cap and whether credits are the client’s sole financial remedy. Serious or repeated breaches may require a recovery plan or personnel replacement. The agreement may also include a termination clause, subject to its agreed terms. Any disagreement should follow the contract’s existing dispute resolution mechanism.
Industry standards can also inform supplier selection. BS 10800 security services certification is relevant to the provision of security services, but it is not a shortcut around a proper site specification.
Key takeaways for procurement teams
Before signing or renewing a security services SLA:
- Match every service level to a real site risk, shift pattern and operational requirement.
- Ask how each metric will be evidenced, reviewed and corrected when it is missed.
- Separate the commercial contract, service specification and performance schedule.
- Record data handling, incident escalation, health and safety arrangements and authority limits.
- Treat service credits as one remedy, not a complete answer to persistent poor performance.
Frequently asked questions
What should a security services SLA include?
It should include the service scope, premises and hours, staffing requirements, licences and training, performance metrics, incident response plan, reporting requirements, data handling, governance meetings, remedies and exit arrangements.
Exact clauses depend on the service type and risk assessment. A keyholding SLA will not read like an agreement for a 24-hour corporate reception.
Are response times always included?
They should be included where response is part of the service, but there is no universal number that suits every location. Agree the priority categories, start point for timing, access arrangements, exclusions and evidence source before setting a target.
Can an SLA make a provider responsible for GDPR compliance?
It can allocate duties and set required controls, but it cannot remove either party’s legal responsibilities. Controller and processor roles should be assessed for each activity, particularly where CCTV and digital incident systems are involved.
A practical agreement is the real standard
A security contract SLA is the practical tool for effective security contract management. It should make ordinary operations visible, including who attends, what they do, how issues are reported and when the client can expect action.
That level of detail is not bureaucracy. It is the difference between a service that sounds dependable and one that can prove it is.

0 Comments