SIA-compliant scheduling means placing only licence-holding, SIA-approved officers on every shift, with an auditable trail that survives an ACS contractor audit. For UK guarding agencies, contractor approval under the Security Industry Act 2022 depends on this. If your rota puts an unlicensed operative on a contracted site, you risk both the site breach and your ACS score. The scheduling software you use must reflect who is cleared to work, not just who is available.
This guide covers what the SIA ACS actually requires of your scheduling process, the five operational checkpoints that keep your rota compliant, and how ShiftTracker's scheduling module automates the licence verification checks that most agencies currently run manually on a shared spreadsheet. Every section is written for ops managers and agency MDs who need to pass their next ACS review without surprises.
What the SIA ACS Requires of Your Scheduling Process
The Approved Contractor Scheme requires agencies to demonstrate they place only suitably licensed individuals on client sites. The relevant standard is the Security Industry Act 2022 and the accompanying ACS qualifying criteria, which inspectors assess against your documented processes. An ACS audit checks two things relevant to scheduling: first, that you hold current SIA licences for every operative before they work; second, that your scheduling process cross-references those licences against the shifts you are awarding.
The ACS does not require a specific software platform. It requires evidence. That evidence must show that your scheduling process includes a licence verification step before any operative is confirmed on a rota. The SIA's own guidance confirms that a verbal or informal check is insufficient — the verification must be documented and retained.
For most agencies, the practical compliance gap is this: licence details are held in HR records or a filing cabinet, and the weekly rota is built by an operations manager who knows the team well enough to avoid obvious problems. This is not an auditable process. An ACS inspector reviewing your scheduling records will ask to see your licence verification workflow — not just your team's recollection of it.
The other compliance risk is expiry tracking. SIA licences run for three years. An operative whose licence expires in month six of a twelve-month contract represents a latent compliance failure. Your scheduling process must catch these expiries before they become audit findings.
Five Scheduling Checkpoints That Keep Your Rota ACS-Ready
A SIA-compliant scheduling workflow builds five verification steps into every rota build. These are not optional extras — they are the structural requirements that ACS inspectors look for when they review your scheduling documentation.
Checkpoint 1: Pre-rota licence verification. Before any operative is added to a draft rota, their current SIA licence must be confirmed against the SIA public register. This check must be documented with the date, the operative's name, the licence number, and the result. ShiftTracker's scheduling module stores this verification against each operative profile, so it runs automatically when you add them to a shift.
Checkpoint 2: Right-to-work confirmation. Separate from the SIA licence, you must confirm the operative's right to work in the UK under the Immigration Act 2016. This is a legal obligation that applies to all UK employers, not a SIA-specific requirement, but ACS inspectors will note gaps here. Schedule this check at the same time as the SIA licence verification.
Checkpoint 3: Contract scope matching. Some client contracts specify the licence type required for the site — door supervisor, CCTV operator, or close protection. Before placing an operative on a specific site, confirm their licence category matches the contract requirement. This sounds obvious but is frequently missed when agencies move operatives between sites at short notice.
Checkpoint 4: Expiry alert threshold. Set a minimum threshold — typically 90 days — before an operative's SIA licence expires. Any operative approaching that threshold should trigger an alert in your scheduling system before they are confirmed on future shifts. ShiftTracker's scheduling module supports automated expiry alerts that flag at-risk operatives when you build the rota.
Checkpoint 5: Audit trail generation. Every scheduling decision — who was confirmed, when, against which licence — must be exportable in a format an ACS inspector can review. ShiftTracker generates a scheduling audit log per operative per month, showing every shift confirmed, every licence check run, and every expiry alert actioned or overridden. This is the document your ACS assessor will ask to see.
How Guarding Agencies Currently Handle SIA Scheduling Compliance
The most common approach in mid-size UK guarding agencies is a hybrid of spreadsheets and verbal checks. An operations manager maintains a shared rota in Excel or Google Sheets, with licence expiry dates tracked in a separate tab. When building the weekly rota, they mentally cross-reference who is cleared for which site. This works until an operative's licence expires quietly, or until a last-minute site change places a door-supervisor-licensed operative on a CCTV-only contract.
The problem with this approach is not operational failure — it is evidential failure. An ACS inspector reviewing your compliance cannot audit a mental process. They need documented evidence of every verification step. A spreadsheet with names and dates is better than nothing, but it does not show the decision logic: that you checked the SIA register, confirmed the licence was current, and matched the licence type to the site requirement before confirming the shift.
Larger agencies with enterprise scheduling platforms have automated some of these checks, but the automation often stops at the licence category level and does not capture the ACS-specific audit trail requirements. The result is that agencies investing in scheduling software still find gaps when their ACS assessor reviews the output.
Building a Rota That Passes an ACS Audit: A Worked Example
Consider a 40-operative guarding agency contracted across three sites: a retail mall requiring door supervisor licensed officers, a logistics warehouse requiring CCTV operator licensed officers, and a corporate office requiring a general security presence. The agency runs a weekly rota and uses a shared scheduling spreadsheet.
In week one, the operations manager builds the rota by matching available operatives to site requirements. She has worked with the team long enough to know who holds which licence. The rota goes out on Friday for the following week. This is the process currently in place.
In week 24, one operative's SIA licence expires on the last day of the month. The operations manager does not catch it. The operative works three shifts in week 25 on the retail mall contract. During a routine ACS spot check, the assessor pulls the rota and the operative's licence record. The expiry is on file. The ACS assessor notes a non-conformance: an operative worked under an expired licence.
The compliance consequence depends on whether this was an isolated oversight or part of a pattern. If it was the first occurrence and the agency can demonstrate a newly implemented structured verification process, the assessor may issue a minor non-conformance. If the pattern is repeated, the ACS score is affected, and contractor approval is at risk.
With ShiftTracker's scheduling module, this scenario does not occur because the expiry alert fires at the 90-day threshold. The operations manager receives the alert when building the rota for week 22, giving eight weeks to either renew the licence or adjust the rota. The action is documented in the scheduling audit log.
SIA Licence Categories and What Each Authorises
Understanding which SIA licence category authorises which activity is a basic compliance requirement that frequently causes confusion in mixed-contract agencies. The three most common licence types relevant to guarding agencies are:
Door Supervisor licence (DS) — authorises the holder to work at licensed premises, static guarding, and mobile patrols. Most retail and event security contracts require DS-licensed officers. The DS licence is the most commonly held in the UK guarding sector.
CCTV Operator licence (CPOCUS) — authorises the holder to operate CCTV systems in public or private spaces. This is a separate licence from DS and is required specifically for monitoring centres and static CCTV posts.
Close Protection licence (CP) — authorises the holder to work in close protection roles, typically for high-risk client assignments. CP licences are less common in standard guarding contracts but required for certain corporate and high-net-worth client engagements.
When building your rota, match the contract's licence requirement to the operative's held licence. An operative with a DS licence cannot legally fill a CCTV-only post without the CPOCUS licence, even if they are otherwise experienced and trustworthy. The licence is the legal authorisation — client preference or operational convenience does not override it.
Automating SIA Compliance Checks in Your Scheduling Workflow
Automation does not replace your compliance responsibility. It reduces the operational friction of meeting it. ShiftTracker's scheduling module integrates SIA licence verification into the rota-building workflow so that the compliance check happens at the point of placement, not retrospectively.
When you add an operative to a draft shift, the system checks their SIA licence status against the SIA public register. If the licence is current, the operative is flagged as cleared for that licence category. If the licence is expired or approaching the expiry threshold, the system flags an alert and prevents the operative from being confirmed on the rota until the alert is resolved or overridden with a documented reason.
The scheduling audit log captures every check automatically. When the operations manager builds the weekly rota, each operative's verification is time-stamped and associated with the specific shift. The log is exportable as a PDF or CSV file for your ACS submission. This is the documented evidence that the ACS requires — not a manager's recollection of the process.


