NEWRecognition module — recognise hard work and the people going above and beyond
SecureOptixSecurity workforce software
Screening & Vetting11 October 2026 · 6 min read

BS 7858 screening: the gaps assessors actually find

Screening to BS 7858 is the backbone of trust in the security industry. A client putting officers into a data centre, a cash-handling operation or a school is relying on the fact that somebody verified who those people are and what they have been doing. When an assessor opens the screening files, they are testing whether that reliance was justified.

The common finding is not an unscreened officer. It is screening that was done, filed, and would not withstand a question about what it actually established.

Unexplained gaps in employment history

The screening standard requires a continuous account of the applicant's history over a defined period, with gaps above a short threshold accounted for and, where possible, corroborated. The point of the exercise is not tidiness; a period nobody can account for is precisely where a reason not to employ somebody would sit.

In practice files routinely contain a gap marked 'travelling' or 'unemployed' with no supporting evidence and no record of what was asked. An applicant's unsupported assertion is not corroboration, and a file consisting entirely of the applicant's own account has verified nothing. The fix is usually to record the enquiry rather than to obtain more documents: what was asked, what the applicant said, what corroboration was sought and whether it was obtained.

References that confirm nothing useful

Reference practice has degraded across the whole economy, and security screening has inherited the problem. Large employers increasingly provide bare confirmation of dates and job title through an HR portal, which satisfies the mechanical requirement to obtain a reference and establishes very little.

Assessors look at whether the reference actually covers the period claimed and whether it came from a verifiable source. The weak points are references from a personal email address, references from a company whose existence was never checked, and references covering a different period from the one the applicant claimed. Where a former employer will only confirm dates, the file should say so explicitly rather than leaving an apparent reference that quietly does less than it appears to.

Screening that stops on the start date

The most consequential gap is conceptual. Screening is often treated as an onboarding task: complete the file, issue the uniform, deploy. But an officer screened four years ago has four years of history nobody has looked at, and a security company's exposure is to who somebody is now.

SIA licence status is the obvious continuing check and the one most often automated, because a lapsed licence is an immediate operational problem. Rather less common is any routine re-examination of the wider position — ongoing right to work for time-limited permissions, declared changes in circumstances, or the periodic rescreening some client contracts require. A company that can evidence continuing checks is describing a screening regime; one that can only evidence onboarding is describing a file.

The subcontracted officer nobody screened

Covering a shift through another company at short notice is normal in security operations. It is also where screening assurance most often disappears, because the officer standing on a client's site was screened by somebody else, to a standard nobody has inspected, and the client's contract is with the company that sent them.

A verbal assurance that a subcontractor screens to BS 7858 is worth very little after an incident. What holds up is a record, per subcontractor, of what was checked about their screening regime and when, and a per-deployment record of which officer attended which site and under whose screening. Companies that cannot reconstruct who was on a client's site on a given night have a bigger problem than screening.

Right to work, and the timing that catches people out

Right to work checking carries its own statutory framework separate from BS 7858, with its own rules about acceptable documents, digital verification routes and timing. The recurring operational failure is not an absent check but a follow-up that never happened: a time-limited permission verified correctly at onboarding, with an expiry date that nobody diarised.

Because the rules on acceptable documents and digital checks have changed repeatedly in recent years, this is an area to verify against current Home Office guidance rather than against an internal procedure written when the last change landed. A check performed correctly under superseded rules is not necessarily a check that still establishes a statutory excuse.

Retention, and the file nobody can find

Screening files contain substantial personal data and are subject to retention limits, which pulls against the instinct to keep everything indefinitely in case an assessor asks. The resolution is a stated retention policy applied consistently, with the rationale recorded, rather than either extreme.

The practical failure assessors meet more often is retrieval rather than retention: files split between an HR system, a shared drive, a filing cabinet and the operations manager's email. A screening regime that is sound but takes two days to evidence will be recorded as a finding, because the assessor's experience is the same as a client's would be.

What good looks like when somebody asks

An officer's screening position should be answerable in one place and in a few minutes: identity verified and how, history covered for the required period with gaps explained and corroborated, references obtained with their actual scope noted, licence status current, right to work established with any follow-up date, and the date of any rescreening. Where a contract imposes additional requirements, those sit alongside rather than in a separate system.

The standard itself, its required periods and its corroboration expectations are revised periodically, and companies should work from the current version of BS 7858 and current SIA and Home Office guidance rather than from an induction pack. The failures above, though, have been consistent for years, because they are failures of process rather than of knowledge.

Identity verification and the document that was never really checked

Identity sits underneath everything else in a screening file: if the person is not who the documents say, nothing else established anything. It is also the element most often performed as a formality, with a photocopied passport on file and no record of who saw the original, when, or whether the person presenting it matched the photograph.

Where identity is verified digitally, the equivalent questions are which provider was used, what level of check was performed, and whether the result is retrievable. A screenshot of a green tick, with no reference number and no record of the service used, is not something an assessor can verify independently.

The practical strengthening is small: record the verifier, the date, the method and a reference, and note explicitly that the original was seen where it was. It costs seconds at the time and is the difference between a file that evidences identity and one that contains documents.

Screening under pressure, which is when it matters

Screening quality degrades predictably under mobilisation pressure. A contract award that requires sixty officers in three weeks produces a volume of screening that the usual process was not built for, and the shortcuts taken are the ones above: references accepted at face value, gaps noted and not pursued, identity checked quickly.

This is exactly inverted from where care is most needed, because a new contract is also where the client is paying closest attention and where an officer who should not have been deployed is most consequential. Building screening capacity into mobilisation planning — as a resourced activity with a realistic rate, rather than an assumption that existing staff absorb it — is the control that actually works.

Where the timetable genuinely cannot accommodate full screening before deployment, the honest position is a documented risk-based decision: what was completed, what was outstanding, what supervision or restriction applied in the interim, and by when it was closed. That is defensible. Deploying and hoping is not.

Key takeaways

  • An unexplained gap is the point of the exercise — record what was asked and what corroboration was sought.
  • A bare dates-and-title reference establishes little; say so in the file rather than leaving it looking like more.
  • Screening that stops at the start date leaves years nobody has examined — evidence continuing checks.
  • Record per subcontractor what you verified about their screening, and per deployment who actually attended.
  • Diarise time-limited right to work expiry; the usual failure is a missed follow-up, not a missed check.
  • If evidencing a sound regime takes two days, the assessor records that as the finding.

The SecureOptix team

Written by people who work daily with security contractors on SIA licensing, screening and the records that hold up under an inspection.