Security patrols
Security officer report: what to write, and how to make it stand up
A security officer report is a factual, timed, written record, made by the officer on duty, of the work done on a shift or of a specific incident on site.
Most of what a security officer does is never seen by the client, and the report is how it becomes visible: what was checked, what happened, and what was done about it. This guide covers the reports officers write on a UK site, what each should contain, and what makes one credible when it is read weeks later.
01
What a security officer report is
A security officer report, often called a security guard report, is a written record made by the officer on duty of something that happened on site or of the work done during a shift. Its main purpose is to document incidents and routine work so that someone who was not there can rely on it. The client organisation reads it, the security company relies on it, and it may be handed to the police, an insurer, HR teams or a court. A security report that is vague, late or written from memory is worth little in any of those places.
Front-line security officers in the UK are licensed by the Security Industry Authority (SIA) under the Private Security Industry Act 2001. The SIA's Knowledge and Skills Specification: Common Security Industry Knowledge, which underpins the licence-linked training for security officers and door supervisors, has a session on record keeping: learners must be able to identify the types of records that may need to be completed and what information to include in them, and to complete an evidential statement, known as a Section 9 statement. A Section 9 statement takes its name from section 9 of the Criminal Justice Act 1967, under which, in England and Wales, a written statement signed by the person who made it, declaring it true to the best of their knowledge and belief, can be admitted in criminal proceedings as evidence to the same extent as oral evidence, provided the section's other conditions are met. No Act sets out a standard format for the report itself. The format comes from the security company's procedures and the site's assignment instructions, which say what must be reported, to whom and how quickly.
Providers that follow the British Standard for static guarding, BS 7499, or that hold the SIA's voluntary Approved Contractor Scheme status, are expected to keep proper site records and to have a clear reporting system between the officer, the control room and the client.
02
The reports an officer writes
Security staff write several kinds of report, and confusing them is where many records go wrong. The usual set on a guarded site is:
- The daily occurrence book or log: a running, time-ordered record of the shift – arrivals, patrols, keys issued, alarms, visitors, anything out of the ordinary.
- The patrol report: which areas were patrolled, when, and what was found, such as a door left open, a light out or a leak.
- The incident report: a formal record of one specific event, written separately and in detail – an intrusion, an altercation, a theft, a medical emergency, vandalism, a fire alarm activation.
- The daily activity report: a summary of the shift for the client or the security supervisor, often built from the log.
- The handover report: what the incoming officer needs to know – open issues, keys out, contractors still on site, systems in fault.
- The accident report: an injury or near miss, recorded in the accident book and, where it is reportable, passed on so the employer can meet its duties under RIDDOR.
The daily log records that something happened; the incident report explains it. A line in the log such as "22:40 youths on perimeter fence, police called, see incident report" is how the two connect.
03
What a security incident report should contain
Whatever the security company's report format, a good security incident report answers the same questions. Each report should carry:
- The date and time of the incident, and the time the report was written. Exact times matter more than approximate ones.
- The location, precisely: building, floor, door or gate, not just "the site".
- The incident type: unauthorised access, theft, criminal damage, disorder, medical, fire alarm, a system fault, and so on.
- A detailed description of the incident, in order, as the officer saw and heard it.
- The people involved: names and contact details of witnesses, staff and anyone injured, with descriptions where names are not known.
- The actions taken: what the officer did to manage the situation, who was called and when – the control room, the supervisor, the emergency services, the client's duty manager.
- Evidence: photographs, whether CCTV footage exists and which cameras cover the area, access logs, items retained and who holds them.
- The outcome: what is still open, such as a broken lock awaiting repair or a police reference to follow up.
- The officer's name, SIA licence number and signature.
Submit it as soon as practicable, and within whatever time the assignment instructions set. For serious incidents that is normally before the end of the shift, with the control room or supervisor told straight away by radio or phone rather than waiting for the paperwork.
04
How to write a report that stands up
A report is read by people who were not there, sometimes months later, and sometimes by someone looking for its weaknesses. Report writing is a skill, and the habits that make a written report reliable are well known:
- Write it at the time, or as close to it as you can. A contemporaneous note in a pocket notebook or on a phone is worth more than a polished account written the next day.
- Facts, not opinions or assumptions. Write "the man was shouting and swaying, and smelled of alcohol", not "he was drunk". Record what was said in the words used.
- Keep a clear structure. Tell it in the order it happened, with times against each step.
- Be specific. "Fire door F3 on level 2 found propped open with a wedge" can be acted on; "doors insecure" cannot.
- Say what you did not see. If you arrived after the event, say so, and say who told you what happened.
- Do not alter it afterwards. If something needs correcting, add a dated note. Crossed-out and rewritten entries invite questions in legal proceedings.
- Proofread it once for times, names and locations before it is submitted.
Handwritten reports are acceptable as long as they are legible, complete and kept safely. Many security companies now use a digital reporting system instead, which helps with legibility and speed, but the rules above apply either way: a well-written report on paper beats a vague one in an app.

05
What happens after a report is submitted
A report that nobody reads improves nothing. On a well-run contract the security supervisor or account manager reviews each incident report, checks it is complete, and decides what follows:
- The client is told, in the way and within the time the assignment instructions set, with serious matters passed on at once.
- Faults are raised with whoever fixes them: a broken lock, a failed light, a camera out of action. The report should say who it was reported to.
- Patterns are spotted, which is how reporting incidents helps to improve security: repeated incidents at one gate, one time of night or one kind of visitor point to a change in patrol routes, lighting or access control.
- Evidence is preserved: CCTV footage is overwritten on a cycle, so the CCTV operator or the client has to be asked to keep it quickly, particularly where criminal activity means the police or other law enforcement agencies may want it.
- Internal reviews use the report to decide whether procedures or the assignment instructions need to change.
The same reports feed the monthly review with the client, where the security provider shows what the security team dealt with and what it prevented. That conversation is much easier when every report says what was done, and when.
06
Where security reports fail, and where SiteClara fits
The incident report is usually the strongest record on a site, because something happened and someone had to write it down. The weak records are the routine ones. A patrol logged as "all areas checked, all in order" every two hours for a month tells the client nothing about which doors were tried. A fault noted in the log at 03:00 may never reach the people who fix it. A client who asks whether an officer actually went to the loading bay last night gets an assurance rather than a record.
SiteClara is a way to record the routine part. A printed QR poster, with an optional NFC tag behind it, is placed at each location that matters: a gate, a plant room door, a fire exit, a loading bay. The officer scans the code or taps the tag on their own phone, with no app to install, and marks the scheduled check done or says what stopped them. The time and the named person are recorded as it happens, with a photo where one helps. An issue found on the round – a door that will not secure, a light out, a leak – is reported there and goes onto the team's list of jobs until someone closes it.
The supervisor sees what was due, done and missed, and can record why a check was missed. At the end of the day the supervisor reviews the totals and photos, adds a note and approves the daily report, which goes to nominated management or client contacts at 8am the next morning, showing what was reported, what is still open and how scheduled checks went.
07
Further reading, and a list to take away
The Security Industry Authority publishes licensing criteria, the training requirements for security officers and door supervisors, and the Approved Contractor Scheme standard on GOV.UK, including the form for reporting security staff or companies. BSI publishes BS 7499 for static guarding and BS 7984-3 for mobile patrol services. The Health and Safety Executive explains RIDDOR reporting, and the Information Commissioner's Office publishes guidance on CCTV and personal data.
Before the next shift, check that:
- the assignment instructions say which incidents must be reported, to whom and how quickly;
- officers know the difference between a log entry and an incident report;
- every report form asks for exact times, precise locations and actions taken;
- officers write in facts, not opinions, and never rewrite an entry;
- someone reviews each incident report and tells the client;
- faults found on patrol go to someone who will fix them, and the report says who;
- reports are stored securely and kept for a set period.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Private Security Industry Act 2001 legislation.gov.uk
- Knowledge and Skills Specification: Common Security Industry Knowledge assets.publishing.service.gov.uk
- Section 9 of the Criminal Justice Act 1967 legislation.gov.uk
- BS 7499 knowledge.bsigroup.com
- RIDDOR legislation.gov.uk
- Data Protection Act 2018 legislation.gov.uk



