In security tenders, you’re not only being judged on price. You’re being judged on risk.

Buyers want to know:
– Can you supply competent, vetted people?
– Will you manage incidents properly?
– Can you prove control with evidence (not promises)?

That’s why the security companies that win consistently usually have the same “compliance stack” in place.

Here’s what it looks like in plain English.

What buyers are really buying: reduced risk
A buyer doesn’t want a supplier who “says they’re compliant”. They want a supplier who can prove:
– staff are suitable and competent
– processes are controlled
– incidents are managed
– records exist and can be produced quickly

The Security Compliance Stack (the practical checklist)
1) Screening and vetting (non-negotiable)
This is where bids often fall down.

Have ready:
– your screening process (step-by-step)
– evidence of checks completed (per employee)
– re-screening / periodic review approach
– right to work checks

Tip: If you’re working to BS7858, make sure you can evidence it cleanly (dates, outcomes, who checked, what was verified).

2) Training and competence (with proof)
Buyers don’t want “we train our staff”. They want evidence.

Have ready:
– training matrix by role
– induction records
– site/assignment briefings
– refresher schedule
– supervision/spot-check records

3) Assignment instructions and control
In security, “the plan” matters.

Have ready:
– assignment instructions template
– escalation route and contact list
– incident reporting process
– handover process

4) Incident management (show you’re in control)
Buyers want confidence that when something happens, you respond properly.

Have ready:
– incident report template
– investigation approach
– corrective actions process (CAPA)
– trend review (what you do with repeat issues)

5) Accreditations and client-required schemes
Only include what you actually hold and can evidence.

Common requests (varies by client):
– CHAS / SafeContractor (if operating on construction sites)
– Constructionline (where relevant)
– sector-specific approvals

6) ISO standards (the trust layer)
ISO isn’t magic — but it’s a recognised way to prove control.

Common:
– ISO 9001 (quality)
– ISO 14001 (environment)
– ISO 45001 (health & safety)
– ISO 27001 (information security) for higher-risk contracts

The key is not the certificate — it’s the evidence behind it:
– internal audits
– management reviews
– corrective actions
– controlled documents and records

7) Supplier/subcontractor control
If you use subcontractors, buyers will ask how you control them.

Have ready:
– approved supplier list
– onboarding checks
– monitoring and performance review

8) The “Tender Evidence Folder” (wins time and wins bids)
The fastest way to look professional is to make evidence easy to navigate.

Create one folder with subfolders:
– Insurance
– Policies
– Training
– Screening
– RAMS (if relevant)
– Accreditations
– Records (audits, incidents, corrective actions)

Rule: If a buyer asks for evidence, you should be able to find it in 60 seconds.

Common reasons security bids lose (even when the service is good)
– screening process unclear or inconsistent
– training claimed but not evidenced
– incident process exists but no records
– documents out of date / wrong versions
– evidence is scattered across emails and desktops

How CAW helps
We help security companies build an audit-ready, tender-ready compliance stack — fast, practical, and jargon-free.

CTA
If you want our security tender evidence checklist and folder structure, message us and we’ll send it over.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect