BS 7858 Security Screening: A UK Employer Guide


0
Screening desk with a personnel file, checklist, ID document, and magnifying glass.
Visual guide to UK employer compliance checks

A security breach often starts with an ordinary weakness, an unexplained gap, a reference never chased, or a document accepted without proper scrutiny. BS 7858 security screening gives UK employers a structured way to test those weak points before someone enters a security-sensitive role.

It is not a box-ticking exercise, and it is not legislation. It is a British Standard that asks employers to build a clear, evidenced screening record that can stand up to client scrutiny, an audit, or an uncomfortable incident review.

The practical question is simple: can you show why this person was suitable to trust with the role you gave them?

Key takeaways

  • BS 7858:2019 is a code of practice for screening people who work in secure environments. It isn’t automatically a statutory requirement, but may be required by a contract, client policy, or an SIA-related scheme.
  • A proper screening file joins up identity, right to work, employment history, references, gaps, and role-appropriate checks.
  • Five years is the normal minimum screening period. Some roles and contracts require ten years.
  • SIA licence verification can provide relevant evidence, but it doesn’t automatically replace the employer’s own screening responsibilities.
  • Keep a defensible record of decisions, discrepancies, evidence received, and any risk controls applied.
  • Check the current edition of BS 7858, your contract terms, and applicable official guidance before setting policy.

BS 7858 security screening for UK employers

BS 7858:2019 is published by the British Standards Institution. It sets out a code of practice for structured security screening of individuals working in a secure environment, including employees, temporary workers, directors, sole traders and contractors. The BSI description of BS 7858:2019 is clear about the central concern: an insider could steal, damage, disclose, or threaten something of value.

It is a standard, not an Act of Parliament

BS 7858 is not a law in itself. There is no general legal duty requiring every UK employer to use it for every vacancy.

The position changes when a client contract, insurance condition, industry scheme, tender requirement, or security policy names the standard. Document the applicable vetting requirements for the role. At that point, “we carried out some background checks” is not enough. You need evidence that your process matched the requirement.

A right to work check is different. Employers have a legal duty to prevent illegal working, and must follow the current GOV.UK employer guidance on right-to-work checks before employment begins.

Decide whether the role is genuinely security-sensitive

Assess the wider security environment. A secure environment is wider than a guarding post. It may include a data centre, pharmaceutical store, airport operation, control room, cash-handling site, restricted warehouse, or a role with privileged access to systems and keys.

Start with the actual exposure. Consider access to people, premises, data, stock, vehicles, alarm systems, financial information, or client sites. Then set checks that are proportionate to that exposure and stated clearly in the recruitment process.

A compliance manager reviews personnel documents beside a secure folder in a dark office.

Build a screening file that tells a complete story

The strongest security screening files do not merely contain documents. They explain the candidate’s history without unexplained periods, untested claims, or loose ends hidden in an inbox.

Confirm identity, right to work and contact history

Begin with identity evidence and the candidate’s current address details. Record what you saw, when it was checked, and who completed the check. If documents do not reconcile, pause and resolve the difference rather than filing an assumption.

Right to work must follow the Home Office process, not an informal view that a passport “looks fine”. Keep the required record of the check separately and complete any follow-up check due for time-limited permission.

Ask candidates to provide a full address and activity history for the screening period. A move abroad, a short-term flat share, or a university address is not a problem by itself. An account that cannot be evidenced is.

Verify employment and explain every gap

BS 7858 screening normally looks back at least five years. A ten-year period may apply where the client, role, or contract calls for it. Check the current edition before fixing either period in policy.

An employment history check should come from an independent source where possible, such as an employer’s HR team, payroll contact, company email domain, or reputable reference platform. Confirm dates, job title and, where appropriate, the reason for leaving.

Treat gaps as facts to investigate, not a reason to reject someone. The issue is whether the period can be explained and supported.

A reference that arrives quickly is not necessarily a reliable reference. Confirm who gave it, how they know the candidate, and whether their contact details are independent.

Resolve difficult gaps without lowering the standard

A candidate may have been caring for a parent, travelling, recovering from illness, studying informally, unemployed, or living abroad. Ordinary life is often untidy. Your process must be careful without becoming unreasonable.

Use evidence that fits the real situation

Ask for a short written chronology first, using it as the starting point for employment gap analysis. It gives you dates, locations, activities and the documents that may exist, so request evidence proportionate to the explanation.

For informal caring, this could include correspondence connected to the cared-for person’s support arrangements, where the candidate can share it lawfully, plus character references from people who understand the arrangement. For travel, use dated travel records, accommodation bookings, bank statements, visas, or references from people who knew the candidate overseas.

Do not demand a single document that the candidate could never realistically hold. Two or three credible pieces of evidence, checked against their explanation, are usually more useful than one decorative letter.

Record the decision, not only the documents

A screening file should say what was missing, what alternative evidence was obtained, who reviewed it, and why the outcome was accepted, deferred, or rejected. Keep the language factual.

For example: “Candidate reported unpaid caring between May and October. Dates supported by bank records and two independent references. No access to client master keys until full screening sign-off.” That is a decision trail. “Gap explained” is not.

Where a concern remains, decide whether a different assignment, additional supervision, delayed start, or withdrawal is appropriate. The response should match the risk.

Criminal, financial and role-specific checks

Not every role needs the same checks, and not every check is suitable for every candidate. This is where copied-and-pasted screening policies tend to fail.

Match the check to the access

A criminal record check must use the right level and lawful route for the role. A DBS check is not a universal requirement under BS 7858, and eligibility and level depend on the role and lawful route. Don’t order a criminal record check merely because it would be convenient.

Financial probity checks may be relevant where an employee handles cash, sensitive commercial information, or high-value assets. They should be proportionate, role-led checks, not a vague search for a reason to exclude people. Define the risk, use a lawful process, and give the candidate a fair opportunity to clarify adverse information.

Background screening may also combine sanctions, directorship, overseas, licence and professional-register checks where required by a client or sector. Write down which checks apply to each role category and why.

Treat SIA licences as one part of the file

For regulated private-security activity involving the Security Industry Authority, confirm the licence is valid, belongs to the applicant, and covers the work being offered. SIA licence verification should record the verification date and include follow-up checks where needed.

A valid licence is relevant, but it does not automatically replace employment-history verification, identity checks, contractual checks, or your own assessment of access risk. It is only one part of wider security vetting. A licence answers a particular regulatory question. It does not answer every question about a candidate’s history.

SIA contractors and outsourced screening

Outsourcing can reduce the administration. It doesn’t transfer your accountability for appointing suitable people, protecting candidate data, or retaining evidence.

Know the SIA-linked requirement

For businesses in the Security Industry Authority’s Approved Contractor Scheme, BS 7858 is the applicable standard for outsourced pre-employment screening. GOV.UK sets out the position in its guidance on SIA approved contractors and outsourced screening.

That matters when a labour supplier sends staff to a client site. BS 7858 applies to work in a secure environment, so assess the client’s security environment and access risks. Establish who completes each check, who holds the evidence, who chases gaps, and who decides whether the person may start work. If nobody owns a step, it will be missed.

Test providers before you appoint them

Ask a screening provider to show a sample workflow, not a glossy promise. It should explain how references are verified, discrepancies escalated, data stored, and a complete audit trail supplied.

Before appointment, ask the screening provider how it handles difficult gaps and evidence requests. NSI Gold certification or another accreditation may support confidence in its systems. It doesn’t prove that the service meets every role, client, or contractual requirement.

Limited Screening needs written controls

Some contracts and screening frameworks permit a form of Limited Screening, allowing work to begin while outstanding checks are completed. The permitted period for Limited Screening and its conditions can differ. Don’t assume a 12-week figure quoted online applies to your role or the current standard.

Before allowing a conditional start under Limited Screening, check the current licensed standard, contract requirements and scheme rules. Put the decision in writing.

The arrangement should state what has been completed, what remains outstanding, the review date, and the work the individual may not undertake. Each Limited Screening decision must identify the outstanding evidence and its expiry or review date. Restrictions may include unsupervised access, keyholding, lone working, control-room duties, client data access, or entry to restricted areas.

Limited Screening is not a shortcut. It is a temporary risk mitigation measure with defined restrictions and an expiry point.

Retention, UK GDPR and audit-ready records

A file can be complete on day one and still become a compliance problem if it is stored carelessly, kept indefinitely, or cannot be retrieved.

Set a documented record retention schedule

Some interpretations of BS 7858, or client contracts, may call for screening records to be kept during employment and for seven years afterwards. That is not a universal statutory requirement. Sources also differ on unsuccessful applicants.

Check the current licensed standard, the client contract, your legal obligations and the type of information involved. Your record retention policy should state the justified period, access controls and disposal trigger. Apply it consistently.

The ICO’s storage-limitation guidance makes the wider point: UK GDPR does not set one universal retention period. You must be able to justify how long personal data is needed. Specialist data-protection or legal advice may be appropriate for criminal-record and financial information.

Keep access narrow and disposal provable

Screening files can contain identity documents, criminal-record information, financial information and sensitive personal explanations. Access should be limited to staff who need it for recruitment, compliance or management decisions.

Use a secure system with access controls, document any disclosure to a client, and have a deletion process that leaves a record of what was destroyed and when. A locked cabinet is useful. So is knowing who has the key.

Folders, an archive cabinet, clock, and locked storage box in a dark records room.

A practical employer checklist

Before approving a candidate for a security-sensitive post, confirm that your file can answer the following points:

  • The role risk assessment explains why BS 7858 vetting applies and what wider security vetting is required.
  • Identity and right to work checks were completed using the current legal process.
  • The required screening period is covered by verified activity, with gaps explained and evidenced.
  • References came from identifiable, independent sources and were checked for inconsistencies.
  • A criminal record check, financial probity checks, sanctions and overseas checks were used lawfully and proportionately for the role or contract.
  • Licence checks, including SIA licence verification, and other compliance checks required by the role, contract or client were completed. SIA verification doesn’t replace the employer’s wider screening.
  • Any outstanding item has a named owner, review date, and written access restriction.
  • The final decision, reviewer and decision date are recorded.
  • The file is stored securely, with a record retention period and disposal date set.

This checklist does not replace the standard or specialist advice. It gives your HR and compliance team a practical final check before a person is trusted with a sensitive assignment.

Frequently asked questions

Is BS 7858 mandatory for every UK employer?

No. BS 7858 is a British Standard, not legislation. It becomes an operational requirement where a client contract, security scheme, tender, insurer, or employer policy requires it.

Does an SIA licence remove the need for BS 7858 vetting?

No. Licence verification can form part of a screening file for relevant security roles. It does not automatically cover every check needed by your employer, client, contract, or risk assessment.

What counts as an employment gap?

The important question is whether the candidate’s activity history is continuous, credible and supported. Check the current standard for its detailed requirements, then investigate periods that cannot be independently accounted for.

Can screening be outsourced?

Yes, but the employer or contractor must still control the process. Agree responsibilities in writing, audit the provider’s work, protect candidate data, and retain the evidence needed to demonstrate compliance.

A defensible process beats a decorative policy

Good BS 7858 security screening is calm, thorough and properly recorded. It does not punish candidates for having a complicated history. It asks sensible questions, checks the answers, and applies restrictions where the evidence is still incomplete.

The strongest employer files are not the thickest ones. They are the ones that make each decision clear, proportionate and capable of being defended.


Like it? Share with your friends!

0

What's Your Reaction?

hate hate
0
hate
confused confused
0
confused
fail fail
0
fail
fun fun
0
fun
geeky geeky
0
geeky
love love
0
love
lol lol
0
lol
omg omg
0
omg
win win
0
win

0 Comments

Your email address will not be published. Required fields are marked *

Cookie Consent with Real Cookie Banner