5 Red Flags When Vetting a Security Provider

Written by Abbey Petkar | Aug 19, 2026, 11:13:13 AM

The UK security market contains excellent providers and very poor ones. The problem is that poor providers are rarely obvious at the proposal stage. Here are five red flags that are reliably predictive of a security provider likely to underdeliver - and what they signal about the company behind them.

Red flag 1 - No meaningful accreditation - or vague answers about their level

Every credible security provider will be able to tell you immediately: their SIA Approved Contractor Scheme tier, their NSI accreditation level and which service categories it covers and when each was last audited. They will be able to provide documentation on request.

If a provider's accreditation claims are vague - "we're fully accredited," "we hold all the necessary approvals" - without specific answers and supporting documents, that vagueness is doing a job. What a credible provider has is specific and verifiable.

Red flag 2 - Agency guards or a vague staffing answer

Ask directly: are your security guards directly employed by your company, or do you use agency or subcontracted staff? A direct answer should come back immediately. I f the response is a description of "flexible workforce management" or references to a "staffing partner" or "resourcing model" the answer is agency.

Agency staffing is a legitimate business model - but it means the security company does not directly control the training, conduct, or consistency of the people working on your site. That accountability gap matters when something goes wrong.

Red flag 3 - Insurance level not confirmed, or below benchmark

Ask for the public liability insurance level - not as a question about whether they're insured, but as a request for a specific number and written confirmation. The benchmark is £10 million. Providers that are reluctant to confirm the figure, or that carry significantly less than £10 million, are signalling a risk you may be absorbing without realising it.

Red flag 4 - No written SLA or KPI framework

Verbal commitments about response times, guard quality and account management are easy to make and impossible to enforce. A professional security provider will offer a written Service Level Agreement that specifies what they commit to, how performance is measured and what happens if it isn't met.

If a provider resists a written SLA or tells you that "the relationship is more important than the paperwork," that relationship will serve their interests when things get difficult, not yours.

Red flag 5 - Reluctance to provide references

A security company proud of its operational performance will be happy to put you in touch with clients in similar sectors or site types. References should be named contacts at real organisations - not anonymised case studies or website testimonials.

If a provider offers only general testimonials, declines to provide references, or provides references that turn out to be difficult to reach, take note. A company doing the job well has clients who will say so.

Use the Security Buyer's Checklist to run through every provider on your shortlist.

It covers accreditations, questions to ask, and red flags - one page, print-friendly, free to download