NEWRecognition module — recognise hard work and the people going above and beyond
SecureOptixSecurity workforce software
SIA Licensing1 October 2026 · 6 min read

Licence expiry is an operational problem, not an admin one

An SIA licence that expired at midnight is not an administrative problem that can be sorted out on Monday. It is an officer who cannot legally work a licensable role, a post that now has to be filled from somewhere, a client who may have contractual grounds to complain, and — if the officer works the shift anyway — a potential criminal offence for the individual and exposure for the company that deployed them.

Despite that, licence expiry is handled in a great many security firms as a back-office task: a spreadsheet, a monthly review, and a reliance on officers to manage their own renewals. That arrangement works until the month it does not, and the month it does not is usually the month the person who maintains the spreadsheet is on leave.

Renewal is not instant, and the gap is the whole problem

The practical difficulty is that a renewal is not a same-day transaction. An application has to be submitted, it takes time to process, and processing times vary. There are provisions that can allow an officer to continue working in defined circumstances while a renewal is being processed, but they are conditional, they depend on the application having been made in good time, and they are not something to discover the existence of on the day a licence lapses. The SIA's own current guidance is the authority on what applies and when, and it is worth your scheduling team actually reading rather than half-remembering.

What follows operationally is simple: the date that matters to your rota is not the expiry date. It is the date by which a renewal must be under way for continuity to be assured, which sits some weeks earlier. A tracker that flags at expiry is flagging too late to be useful.

The failure modes are predictable

  • The officer who assumed the company was renewing it, in a company that assumed the officer was.
  • The part-time or relief officer who works infrequently, is not in anyone's daily eyeline, and whose licence expires between shifts.
  • The officer who renews but whose licence is issued in a different category from the one the post requires.
  • The subcontracted officer whose licence your company has never actually seen, only been told about.
  • The officer who transferred in under TUPE with a licence date nobody re-verified.
  • The licence that is suspended or revoked mid-term, which no expiry-date tracker will ever catch.

That last one is worth dwelling on, because it is the case where expiry-date tracking gives a false sense of security. A licence can cease to be valid before its printed expiry date. A system that only watches the date will show green on an officer who is no longer licensed, and the first anyone knows is when a client or an assessor checks.

Put the check where the deployment decision is made

The structural fix is to stop treating licence status as a record to be reviewed and start treating it as a condition of assignment. The question is not "is our licence spreadsheet up to date" but "can this specific person be rostered onto this specific post on this specific date", and that question has to be answered at the point the rota is built — including when cover is arranged at short notice.

That reframing matters because short-notice cover is where exposure concentrates. A planned rota built on Wednesday for the following month will generally be checked. A cover call made at nine on a Saturday night, to the first officer who answers, frequently is not. If your controls live in a monthly review rather than in the act of assignment, the unchecked deployments are precisely the ones made under pressure.

A practical consequence: licence status needs to be visible to whoever makes cover decisions out of hours, not just to the compliance function during office hours.

Category matters as much as currency

A valid licence is not automatically the right licence. Front line licences are issued in sectors, and an officer licensed for one activity is not thereby licensed for another. Mixed contracts are where this goes wrong — a site that is mostly guarding but includes a door supervision element, or a role that evolves over the life of a contract without anyone revisiting what licence the post requires.

This is one of the reasons assignment instructions are worth more than their reputation. If the instructions define what the officer is actually required to do, the licence category required for the post follows from them rather than from habit. What good assignment instructions contain is the broader subject; the licensing point is that a post should carry a documented licence requirement, and rostering should check against that rather than against a general assumption that any licensed officer will do.

Mobilisation and TUPE are when the data is worst

Two moments reliably produce poor licence data. The first is mobilising a new contract, when officers are being onboarded quickly, often in volume, often alongside everything else involved in standing up a site. Mobilising a security contract covers the wider sequence, and licence verification deserves to sit in the critical path rather than the follow-up list, because an unlicensed officer on day one of a new contract is the single worst time for it to happen.

The second is a contract changing hands. Officers transferring under TUPE arrive with employment records of variable quality, and licence details that were accurate at some point under the previous provider. Inheriting a licence expiry date without verifying it independently means inheriting the outgoing provider's data quality, which you have no way of assessing. What happens to officers when a security contract changes hands covers the transfer itself; the licensing discipline is to re-verify everyone rather than to accept a transferred list.

Accreditation puts this under external scrutiny

For firms holding or seeking Approved Contractor Scheme status, licence management is not an internal matter. It is part of what gets assessed, and the assessment looks at whether you have a working system rather than whether today's position happens to be clean.

That distinction is worth internalising. An assessor is not especially impressed by a spreadsheet showing all licences currently valid. They are interested in how you would know if one were not, how quickly, and what happens next — which is a question about process, escalation and evidence. What ACS accreditation involves sets out the wider picture, and the SIA's current ACS requirements are the authority on what is assessed.

What a working system looks like

  • Expiry tracked against a renewal-trigger date weeks ahead of expiry, not against the expiry date itself.
  • Licence status checked at the point of assignment, including out-of-hours cover, not at a monthly review.
  • Each post carrying a documented licence category requirement, derived from its assignment instructions.
  • Periodic re-verification against the SIA register rather than against your own record, so suspensions and revocations surface.
  • Subcontracted and agency officers verified by you, not asserted by their employer.
  • Everyone re-verified at mobilisation and after a TUPE transfer, regardless of what the inherited data says.
  • A documented escalation for what happens when an officer cannot be deployed, so the cover decision is not improvised at the gate.

None of this is complicated. It is mostly a matter of moving a check that currently sits in an administrative routine into the operational decision it actually governs — which is also the difference between a system that holds up under scrutiny and one that happens to be fine today.

Key takeaways

  • The date that matters is the renewal trigger, not the expiry date. A tracker flagging at expiry flags too late.
  • Check licence status at the point of assignment, including Saturday-night cover calls — that is where exposure concentrates.
  • A valid licence is not the right licence. Derive the required category from the post's assignment instructions.
  • Expiry tracking will never catch a suspension or revocation. Re-verify against the register periodically.
  • Re-verify everyone at mobilisation and after TUPE. Inheriting a date means inheriting someone else's data quality.

The SecureOptix team

Written by people who work daily with security contractors on SIA licensing, screening and the records that hold up under an inspection.