A client can see a smart uniform and polished proposal from a provider of private security services. They cannot always see the licences, ownership records, incident reporting, and supervision that matter in the private security industry. That’s where an ACS application asks harder questions.
The Approved Contractor Scheme (ACS) is voluntary, but it isn’t decorative accreditation. It requires a security company to show that its people, systems, governance, and working practices are properly controlled.
If your business is considering ACS approval, start with the evidence you can produce today, not the policies you intend to write later.
SIA approved contractor scheme: what it is
The Security Industry Authority (SIA), the regulatory body for the private security industry, runs the approved contractor scheme (ACS). The scheme provides quality assurance for businesses, approves companies rather than individual operatives, and doesn’t award gold, silver, or bronze status.
The scheme is relevant where a business supplies regulated private security services under contract in the UK. The SIA’s Approved Contractor Scheme guidance sets out the activities within its scope, including security guarding, door supervision, close protection, public space surveillance, cash and valuables in transit, key holding, and vehicle immobilisation.
ACS approval is not an individual SIA licence
ACS approval doesn’t permit an unlicensed person to provide licensable services. Individual licensing remains a separate legal requirement.
A worker in a licensable role needs the appropriate SIA licence. ACS approval shows that the company has met the scheme standard. It doesn’t replace anyone’s licence, role-specific requirements, identity checks, or right to work.
That distinction matters in tender responses and client discussions. A company can be ACS approved and still have a serious compliance failure if it deploys an unlicensed person in a licensable role.
What ACS approval does and does not cover
Approval applies only to the activities your company has been assessed against. It isn’t a blanket endorsement of every service on your website.
Alarm installation, security consultancy, and training provision are outside the ACS scope. A business offering guarding and consultancy should describe its status honestly: ACS approved for its approved security activity, not “SIA approved” across every part of the business.
Start with the company’s actual operating position
A sound application begins with an honest account of how the business operates. The SIA needs to understand who supplies licensable services, who controls the company, and how security operatives are deployed.
That can become awkward where a company has grown quickly, uses several trading names, or sits within a wider group. It’s still better to make the structure clear at the outset than leave an assessor to find gaps later.
Clarify the business entity and service contracts
Match the legal entity named on your application to the entity that signs contracts, employs or engages staff, invoices clients, and holds insurance. If those responsibilities sit across different group companies, document the relationship.
A parent company, subsidiary, franchise operation, or shared control room isn’t a problem by itself. Vague responsibility is the problem. Show which organisation manages operatives, controls quality, and carries contractual responsibility when something goes wrong. If the business provides key holding or public space surveillance, confirm those activities are reflected in the relevant scope and records.
Keep licences and deployment records aligned
Your scheduling system, personnel records, licence register, and payroll or engagement records should tell the same story about licensable staff. A licence check recorded in one spreadsheet but absent from the workforce file isn’t a robust control.
Review every licensable role you supply. Check that the right licence category is held, expiry dates are monitored, and each assignment stays within the person’s licence scope. Where directors or senior managers carry out licensable activity, assess their licensing position properly rather than assuming their job title settles the point.
Fit and proper checks look beyond the company name
The SIA’s fit and proper assessment considers the people who own, control, and direct a business. This isn’t limited to the managing director listed on Companies House.
The review can include identity, criminality, financial probity, integrity, and compliance with the Private Security Industry Act 2001. The SIA may also consider convictions, charges, prosecutions, and enforcement activity from the previous 12 months. This isn’t an exhaustive list of every factor that may be relevant.

Identify the business’s controlling minds
The phrase “controlling minds” is practical rather than theatrical. It means the people with real authority over the business, its money, its contracts, and its decisions.
Prepare a clear ownership chart, shareholding information, director details, and records for people with significant control. Include corporate shareholders and explain the chain of ownership where it leads beyond the operating company. If a family member, investor, consultant, or group director has meaningful influence, don’t leave them out because their title sounds informal.
Deal with difficult history directly
A past issue doesn’t automatically decide an application. Trying to conceal it, minimise it, or provide a partial answer can create a greater integrity concern.
Prepare an accurate chronology where there has been a conviction, insolvency matter, regulatory action, contractual dispute, or previous security industry concern. State what happened, what the business did, and what controls now prevent a repeat. Keep supporting documents ready.
The review isn’t a request for a perfect corporate history. It’s a test of whether the people in control can be identified, checked, and trusted with their responsibilities.
Choose the right route to ACS approval
The approved contractor scheme has two main routes: the standard route and the passport route. Both involve approval by the Security Industry Authority (SIA), but use different assessment frameworks.
The right route depends on the certification you already hold, not on which option appears shorter on paper.
The standard route uses the ACS workbook
Under the standard route, the company completes the ACS self-assessment workbook. It’s a working document, not a sales brochure. Each indicator should be supported by evidence showing that the stated process is in use.
The company submits its application and pays the application fee. The SIA checks whether it meets the relevant eligibility criteria. The company then arranges a verification visit with one of the authorised assessing bodies, where the assessor tests the evidence.
The assessor must change every four years. That requirement prevents a long-standing assessment relationship from becoming too comfortable.
The passport route relies on qualifying certification
The passport route is for businesses holding certification from one of the accredited passport schemes currently recognised by the SIA. An appropriate UKAS-accredited certification body must assess the company against standards that include the ACS requirements.
The self-assessment workbook is optional on this route, though it remains useful. It helps the compliance team map policies, records, and responsibilities before the assessment starts. That external certification assessment is separate from the SIA’s process and isn’t automatically followed by another SIA verification visit.
Do not assume that a certificate qualifies because it has a familiar name. NSI Guarding Gold may be relevant to your route, but verify the current passport-scheme position directly with the SIA before planning around it. The SIA’s ACS application instructions set out the submission process and evidence required.
Select an authorised assessing body
For the approved contractor scheme, the Security Industry Authority is the regulatory body, while assessing bodies independently test your application. Their role is to verify that your evidence and day-to-day practice meet the applicable ACS standard.
Current SIA guidance identifies British Assessment Bureau, NSI, and SSAIB as assessing bodies. Compare their scope, availability, and commercial arrangements, then check the live SIA list before committing to dates or fees.
Assessment is not simply a review of policies. Your chosen assessing bodies may use the verification visit to ask about staff vetting, licence checks, training, supervision, complaints, control-room arrangements, incident records, client communication, and non-conformance. Expect the verification visit to test how these controls work in practice.
A well-written procedure that nobody follows will not carry much weight. Effective quality management connects policies, completed records, corrective actions, and management review. An ordinary record, completed properly and consistently, often tells a more convincing story.
Understand the ACS fees before you apply
Budget these costs separately, because the SIA application fee is based on the number of licensable staff deployed. For 2026 applications, check the registration fee against the current SIA schedule and assessment rates against official provider sources.
The annual registration charge is based on the number of licensable individuals deployed. Check the count carefully, particularly if your licensable staff numbers change as relief cover is added.
| Cost area | What it covers | What to check |
|---|---|---|
| SIA application charge | Processing the ACS application | The correct staff-number band |
| Registration fee | Continued ACS registration | Deployed individual numbers |
| Assessing-body fee | Verification and assessment work | Day rate, travel, remote options, and follow-up work |
Assessment fees are paid directly to assessing bodies, rather than included in the SIA charge. SSAIB’s ACS scheme information makes that separation clear.
Assessment-body rates vary, so request a written quotation for your activity, locations, staff numbers, and assessment scope. Confirm its coverage of the verification visit, travel, remote work, and follow-up charges. Check the final registration fee against deployed numbers.
Build evidence before opening the workbook
The self-assessment workbook can look like an administrative task. In practice, it tests whether the approved contractor scheme controls work in routine operations.
Don’t write a policy first and hunt for proof later. Before completing the self-assessment workbook, start with actual records and identify the process they show.

Turn each indicator into an evidence trail
For every workbook indicator, ask four direct questions:
- Who owns this requirement and who checks it?
- What record proves the process happened?
- How often is the record reviewed?
- What happens when the process fails?
For example, a licence-check procedure should lead to a current licence register, recorded checks, expiry alerts, and evidence that someone acted on an expired or incorrect licence. A lone-worker policy should connect to welfare arrangements, escalation records, check calls, and incident follow-up.
Test weak points before the assessor finds them
Sample recent jobs across different clients and shifts. Check whether assignment instructions were issued, supervisors completed visits, uniform requirements were met, incidents were recorded, and client concerns were closed properly.
Pay attention to sites that sit outside the main office routine. Remote locations, overnight shifts, relief cover, subcontracted work, and last-minute mobilisation often produce the missing records. These are not unusual edge cases. They are where a security company proves whether its systems work under pressure. Keep recent, traceable samples ready for external review by assessing bodies, as they may be tested during a verification visit.
Keep the application practical with a short checklist
Before you submit, bring the operational, commercial, and governance records together. A concise internal checklist keeps the work grounded:
- Confirm the legal entity, approved activities, ownership structure, and senior decision-makers.
- Check licences, licensable staff, personnel records, deployment arrangements, and evidence of right-to-work and vetting processes.
- Complete the workbook or confirm that your certification supports the passport route.
- Confirm the scope and quotation with the authorised assessing bodies, then prepare for the verification visit.
- Check the budget, including the registration fee, which is separate from application and assessing-body charges.
- Review client files, assignment instructions, incident records, complaints, supervision, and corrective actions.
- Resolve contradictions before submitting the application, especially between payroll, rotas, contracts, and licence records.
Give one person responsibility for coordinating the application, but don’t let the process become their private project. Operations, HR, finance, directors, and contract managers all hold part of the evidence.
Approval brings ongoing responsibilities
ACS approval is not a one-off inspection followed by a framed certificate on the reception wall. Within the approved contractor scheme, contractors are assessed each year to retain approval.
The practical standard is continual control: records stay current, people know their responsibilities, concerns are investigated, and corrective actions are closed rather than filed away.

Treat annual assessment as ordinary business
Keep a monthly compliance rhythm. Review licence expiries, staff files, complaints, incidents, training, client feedback, site visits and overdue actions through quality management. Directors should review the results and budget for the annual registration fee, particularly where trends show missed supervision or recurring client concerns.
This approach is less glamorous than a last-minute document chase, but it is more reliable. It also supports continual improvement by turning recurring complaints, missed supervision or incidents into measurable changes. A verification visit should confirm a working system, not uncover a year of neglected housekeeping.
Use Licence Dispensation Notices with care
Approved contractors may use Licence Dispensation Notices (LDNs) in limited circumstances. An LDN does not remove the need for licensing. It provides a tightly controlled temporary route only where the current SIA rules allow it.
Check those rules directly before relying on an LDN, including any permission, scope, duration and record-keeping conditions. Monitor deployment changes and licensing progress for licensable staff. Don’t treat an LDN as a staffing shortcut or build recruitment planning around it. Keep clear records of every notice, its basis, duration and licence application progress.
Key takeaways for security company owners
- ACS approval is company approval, while SIA licences apply to individuals carrying out licensable work.
- Your legal structure, ownership records, senior management and operational evidence all need to withstand scrutiny.
- The standard route uses the ACS workbook and a verification visit. The passport route depends on current qualifying certification.
- Application, registration and assessment costs are separate. Confirm current published figures before budgeting.
- Approval remains credible only when daily licence, workforce, site and incident controls stay up to date.
Frequently asked questions
Can we deploy unlicensed staff while our ACS application is being processed?
A pending approved contractor scheme application does not allow an unlicensed person to carry out licensable activity. Don’t treat it as a temporary licence, or assume it changes the legal position for licensable services such as security guarding, door supervision, or close protection.
If a staffing situation is unclear, check the live SIA guidance before deployment. Approved contractors may have access to LDN arrangements in limited circumstances, but that is separate from having an application in progress.
Does ACS approval guarantee access to tenders?
No. Some buyers require ACS status as a condition of tendering. Others treat it as one part of their supplier assessment alongside price, experience, insurance, references, mobilisation plans, and social value commitments.
It may provide a competitive advantage by strengthening supplier assurance, but it doesn’t guarantee a contract award. A tender response still needs to explain how your company will manage the particular site, risk profile, and client requirements.
Which route is best for a small security company?
The standard route is often the direct option where the business does not already hold qualifying passport certification. It requires more workbook preparation, but gives the company a clear view of its evidence and gaps.
The passport route may suit a business with recognised certification already in place. Confirm that the certification meets the current eligibility criteria and SIA requirements before choosing it. The live requirements matter more than a certificate’s reputation.
A proper ACS application starts with ordinary controls
A strong ACS application is not built on impressive wording. It rests on matching records, checked licences, and accountable directors. Staff must also know what good practice looks like on difficult shifts while delivering private security services.
Keep the evidence current, resolve awkward gaps early, and make continual improvement part of your routine. Verify live SIA requirements before you submit. Reliable compliance is routine work, done properly.

0 Comments