Security patrols
Security report writing: what to record, with examples that stand up
Good security guard report writing records what happened, where, at what time, who was involved and what was done, in plain and objective language – for example, "01:52, electric fence alarm on zone 3, east boundary; control room told at 01:53; tree branch found across the top two strands at 01:58, no damage".
A security report is a factual, timed, written account by the officer on duty of an incident on site or of the work done on a shift, written so that someone who was not there can rely on it. In South Africa no Act prescribes its format, but the Private Security Industry Regulations, 2002 require a security business to keep the records of the service it renders for at least four years, available to PSIRA inspectors, and the Code of Conduct for Security Service Providers, 2003 expects the service to be rendered and supervised with skill, diligence and care. This guide covers the reports a security officer writes, what each should contain, worked examples of good and weak reports, and what happens to a report once it is handed in.
01
What a security report is, and what the rules say about it
A security report, often called a security guard report or an incident report, is a written record made by the officer on duty of something that happened on site, or of the routine work done during a shift. The client reads it, the security company relies on it, and it may be handed to the South African Police Service (SAPS), an insurer, a disciplinary hearing or a court.
Security officers and the businesses that employ them are regulated by the Private Security Industry Regulatory Authority (PSIRA) under the Private Security Industry Regulation Act 56 of 2001. No provision in the Act prescribes a report form. The duty to keep reports comes from regulation 10(1) of the Private Security Industry Regulations, 2002, which says every security business must "keep all the records and documents concerning the management, administration and other matters relating to the rendering of security service by it". Regulation 10(2) requires the originals to be kept "in a secure and orderly manner", available for inspection by PSIRA, for at least four years from the date they came into existence. An incident report written on a client's site is hard to treat as anything other than such a record.
The Code of Conduct for Security Service Providers, 2003 explains why reports matter. Regulation 9(5)(b) requires the contracted service to be rendered "with such a degree of skill, diligence and care as may be expected of a reasonable, competent and qualified security service provider in the circumstances". Regulation 13(2) requires a security business to implement systems of management, control and supervision that ensure "effective control over the rendering of security services". Reports are how both are shown.
Reports are also read by people outside the business. Section 34 of the Act lets a PSIRA inspector enter premises where a security service is rendered, without prior notice, and require "all or any records or documentation relating to the activities of the security service provider". Regulation 7(3) of the Code requires a provider to furnish, without undue delay, all the information and documentation that a member or employee of a Security Service (which includes SAPS) or an organ of state may lawfully require. Anyone unhappy with a security service can complain to PSIRA: section 4(r) of the Act requires the Authority to establish a complaints office "to receive, process, refer or deal with complaints regarding the quality of service rendered by security service providers", and section 26 lets it suspend a provider's registration, pending an investigation or enquiry, where there is a prima facie case of improper conduct. The format comes from the company's procedures and the site instructions.
02
The reports a security officer writes
Confusing one kind of report with another is where many records go wrong. On a guarded site in South Africa the usual set is:
- The occurrence book (OB): the running, time-ordered record of the shift – takeover, patrols, keys, visitors, alarms, load shedding and anything out of the ordinary, a few lines each.
- The incident report: a separate, detailed account of one event – a break-in or attempted break-in, theft, damage, a trespasser, an assault, an electric fence or intruder alarm, a fire alarm activation, a medical emergency.
- The patrol report: which points or areas were patrolled, when, and what was found, such as an open window, a light out, a cut in the fence or a leak.
- The shift or daily activity report: a summary for the supervisor or the client, often built from the OB.
- The handover report: what the incoming officer needs to know – open incidents, keys out, contractors still on site, systems in fault, instructions from the client.
- The injury or hazard report: a person hurt on site, or a hazard found, passed to the employer responsible so it can deal with it under the Occupational Health and Safety Act.
The OB records that something happened; the incident report explains it. An OB line such as "23:10 Suspect seen at north perimeter fence, armed response called, see incident report 14/09" is how the two connect.
03
What a security incident report should contain
Whatever the company's form looks like, a good incident report answers the same questions: what happened, where, when, who was involved, what was done and what is still open. Each report should carry:
- The date and time of the incident in the 24-hour clock, and the time the report was written.
- The exact location: building, floor, gate, door or fence section, not just "the site".
- The type of incident: unauthorised access, theft, damage, a suspicious person or vehicle, an alarm, a medical emergency, a fire, a system fault.
- What happened, in order, as the officer saw and heard it, with a time against each step.
- The people involved: names and contact details of witnesses, staff and anyone injured, with descriptions and vehicle registrations where names are not known.
- The actions taken: who was called and when – the control room, the supervisor, armed response, the fire brigade, SAPS, an ambulance, the client's contact – and when each arrived.
- Evidence: photographs, which CCTV cameras cover the area, access control records, items found and who now holds them.
- References: the OB entry, the SAPS case (CAS) number where one was given, and the name of the police official who attended.
- The outcome: what is still open, such as a gate motor awaiting repair or a fence section to be fixed.
- The officer's full name, PSIRA registration number and signature.
Submit it within the time the site instructions set. For anything serious, tell the control room or supervisor at once by radio or phone, and finish the report before the end of the shift.
04
Security report writing examples
The examples below are fictional, but they show the difference between a report that can be acted on and one that cannot.
Each better version gives exact times and places, names who was told and says what is still open. None guesses at a motive or blames anyone.

05
How to write a report that can be relied upon
A report is read by people who were not there, sometimes months later. The habits that make it accurate and reliable are simple:
- Write it at the time, or as close to it as possible. Notes made in a pocket book at the scene are more reliable than an account written from memory the next day.
- Be objective: facts, not opinions. Record your own observations. Write "the man was swaying, slurring his words and smelled of alcohol", not "he was drunk". Record what was said in the words used.
- Tell it in order, with the time against each step.
- Be specific. "Fire escape door on level 2 found wedged open" can be acted on; "doors not secure" cannot.
- Use plain language. Avoid slang, abbreviations only your site knows and guesses about why suspects did what they did.
- Say what you did not see. If you arrived afterwards, say so, and name who told you what happened.
- Never change it afterwards. Add a dated note to correct a mistake. A rewritten report invites questions at a hearing or in court.
Regulation 10(4) of the 2002 Regulations allows records to be kept "in an electronic format through the use of an appropriate computer program", provided a correctly dated back-up is made separately each day the records change. Section 15 of the Electronic Communications and Transactions Act 25 of 2002 says a data message must not be refused as evidence merely because it is electronic, and that its weight depends on how reliably it was generated, stored and kept intact and how its originator was identified. A digital report does the job if it is timed, tied to a named officer and cannot be edited without trace.
06
What happens after a report is handed in
A report nobody reads changes nothing. On a well-run contract the security supervisor or area manager reads every incident report, checks it is complete and decides what follows:
- The client is told, in the way and within the time the site instructions set.
- Faults go to whoever fixes them: a gate motor, a broken lock, a fence section, a camera or light out of action. The report says who it was reported to.
- Evidence is kept: CCTV footage is overwritten on a cycle, so the client or control room must be asked to save it quickly when SAPS may want it.
- Patterns are spotted: repeated alarms on one zone or incidents at one gate point to a change in patrols, lighting or access control.
The same reports feed the monthly meeting with the client, which is far easier when every report says what was done, by whom and when.
07
Where security reports fail, and where SiteClara fits
The incident report is usually the strongest record on a site, because something happened and someone had to write it down. The weak records are the routine ones. A patrol written up as "all correct" every two hours for a month tells the client nothing about which gates were checked. A fault noted at 03:00 may never reach the managing agent.
SiteClara is a way to record the routine part of the shift where it happens. A printed QR poster, with an optional NFC tag behind it, is placed at each checkpoint: a gate, a plant room, a fire escape, a basement parking level, a corner of the perimeter. The officer scans the code or taps the tag on their own phone, with no app to install, and marks the scheduled check done or says what stopped them. The time and the named officer are recorded as it happens, with a photo when one is asked for. A fault found on the round is reported there and goes onto the team's list of jobs until someone closes it.
The supervisor sees what was due, done and missed, and can record why a check was missed. At the end of the day the supervisor reviews the totals and photos, adds a note and approves the daily report, which goes by email to nominated management or client contacts at 08:00 the next morning, showing what was reported, what is still open and how the scheduled checks went.
08
Further reading, and a list to take away
PSIRA publishes the Private Security Industry Regulation Act, the Private Security Industry Regulations, 2002 and the Code of Conduct for Security Service Providers, 2003 together on psira.co.za. The Department of Employment and Labour publishes the OHS Act and the General Administrative Regulations, including the Annexure 1 form.
Before the next shift, check that:
- the site instructions say which incidents must be reported, to whom and how quickly;
- officers know the difference between an OB entry and an incident report;
- every report form asks for exact times, precise locations, actions taken and who was told;
- a supervisor reads every incident report and the client is told;
- injuries are passed to the employer who keeps the Annexure 1 record;
- reports are stored securely and kept for at least four years.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Private Security Industry Regulation Act 56 of 2001 gov.za
- Private Security Industry Regulations, 2002 psira.co.za
- Code of Conduct for Security Service Providers, 2003 psira.co.za
- Occupational Health and Safety Act 85 of 1993 gov.za
- General Administrative Regulations, 2003 gov.za
- Electronic Communications and Transactions Act 25 of 2002 gov.za
- Protection of Personal Information Act 4 of 2013 gov.za



