Security assessor inspecting facility lobby

A physical security risk assessment checklist covers nine areas: perimeter and site boundary, vehicle and pedestrian access, CCTV and sightlines, intruder alarms, lighting, barriers, staffing and contractor controls, policies and training, and recordkeeping. Run it before authorising operations, then repeat it at least annually. The Queensland Department of Education also requires reassessment after major incidents, new CCTV or alarm installation, building expansion, or changes to IT facilities.

Your immediate next steps:

  • Confirm scope: identify the site boundary, critical assets, operating hours, and key stakeholders before you walk the site.
  • Schedule an on-site inspection with a licensed assessor and arrange access to all areas, including service yards and plant rooms.
  • Download the free Abcosecurity template or contact Abcosecurity for a professional assessment.

Table of Contents

What does a security risk assessment checklist cover?

The checklist below is grouped by physical area. Each item is a verification action. Tick it when you can confirm the control is in place and functioning; flag it when you cannot.

Perimeter and site boundary

  • Fencing is continuous, in good repair, and at a height that deters casual entry.
  • Perimeter lighting activates at dusk and covers fence lines without dark gaps.
  • Signage identifies the site as restricted and displays emergency contact numbers.
  • Vegetation is trimmed to remove concealment points within 2 metres of the fence line.

Pro Tip: On construction sites, temporary fencing is the first line of defence. Prioritise corners and service-entry points, where panels are most likely to be shifted or removed.

Vehicle access and gates

  • Vehicle entry points are limited to the minimum operationally required.
  • Gates are fitted with rated locks or electronic access control and are closed when unattended.
  • A vehicle register or boom gate log is maintained for all site entries.
  • Tyre-shredding or speed-control measures are in place at high-risk entry points.

Pedestrian access and doors

  • All external doors are fitted with rated hardware and self-closing mechanisms.
  • Visitor management is active: sign-in, ID check, and escort policy in place.
  • Tailgating controls (turnstiles, airlocks, or supervised entry) are used at high-traffic points.
  • Emergency exit hardware is tested and compliant with the applicable building code.

CCTV and sightlines

  • Cameras cover all entry and exit points, service yards, and car parks with no blind spots.
  • Footage is time- and date-stamped and retained for an appropriate period.
  • Camera housings are clean, undamaged, and positioned to avoid backlight glare.
  • Remote monitoring or 24/7 review capability is confirmed.

Intruder alarms and response

  • All alarm zones have been tested regularly.
  • Response protocols are documented and tested with the monitoring centre.
  • Alarm panel access is restricted to authorised personnel only.
  • Duress alarms are installed in reception, cash-handling, and isolated work areas.

Lighting and passive observation

  • All pathways, car parks, and loading docks are adequately illuminated.
  • Motion-activated lighting supplements fixed lighting in low-traffic areas.
  • Internal common areas allow natural surveillance from occupied spaces.

Physical barriers and vehicle mitigation

  • Bollards or rated barriers protect building entrances and glazed facades from vehicle impact.
  • Temporary water-filled barriers are used on construction sites where permanent bollards are not yet installed.
  • Protective barrier specifications match the assessed vehicle threat level.

Staffing, guards, and contractor controls

Policies, signage, and training

  • A written security policy exists, is current, and has been communicated to all staff

Recordkeeping and evidence capture

  • Each assessment is stamped with date, assessor name, and the version of the standard used.
  • Photographic evidence with timestamps and map references is filed with the assessment report.
  • A physical security risk register is maintained and reviewed at each reassessment.

Pro Tip: For events, add crowd-barrier placement, emergency egress routes, and credentialling controls as a separate checklist section before each event.

How do you conduct a physical security risk assessment?

The Queensland Department of Education’s four-step process applies directly to any site: identify, analyse, evaluate, and treat. Here is how to run it.

Step 1: Define scope and context

Map the site, list critical assets (cash, data, plant, stock, people), confirm operating hours, and identify stakeholders. AS ISO 31000:2018 requires you to set risk criteria before you begin scoring, so agree on consequence and likelihood scales with your team at this stage.

Step 2: Conduct the on-site inspection

Walk every area in the checklist above. Photograph each finding with a timestamp and a short narrative note. Interview facilities staff, security personnel, and operational managers — they will flag issues that are invisible on a walkthrough alone.

Step 3: Score each finding

Visual flowchart of security assessment steps

Use a likelihood × consequence matrix. The table below shows a sample scoring approach aligned with the Queensland Department of Education’s semi-quantitative method.

LikelihoodConsequenceRisk ratingExample finding
Almost certain (5)Major (4)ExtremeUnlit service yard, no camera coverage
Likely (4)Moderate (3)HighVisitor sign-in not enforced
Possible (3)Minor (2)MediumOne gate lock worn but functional
Unlikely (2)Insignificant (1)LowSignage faded but present

Residual risk is the rating that remains after your proposed mitigation is applied. Document both the inherent and residual ratings for each finding.

Step 4: Post-inspection tasks

  1. Compile findings into a draft report with photos and map references.
  2. Assign an owner and a target completion date to each finding.
  3. Estimate cost and implementation time for each mitigation.
  4. Add all findings to the physical security risk register.
  5. Schedule the next reassessment date.

Pro Tip: Timestamped photos paired with a short narrative note cut procurement lead times significantly. Insurers and approvers can act on clear evidence without requesting a second site visit.

How do you prioritise fixes and estimate costs?

Not every finding needs the same urgency. Use risk rating, asset criticality, and your organisation’s risk tolerance to assign one of four priority levels.

  • Immediate: Extreme-rated findings. Address within 24–72 hours. Examples: unmonitored perimeter breach, non-functional alarm.
  • High: High-rated findings. Resolve within 30 days. Examples: missing visitor management, unlit car park.
  • Medium: Resolve within 90 days. Examples: worn gate hardware, outdated training records.
  • Low: Schedule in the next annual cycle. Examples: faded signage, minor vegetation overgrowth.

Typical Australian cost bands for common mitigations (ballpark, supply and install):

  • Lighting upgrade (car park or pathway): costs vary depending on site size and requirements
  • CCTV system (multiple cameras, monitored): costs vary depending on system size and complexity
  • Access control (single door, card reader): costs vary depending on technology and installation
  • Permanent perimeter fencing: costs vary depending on materials and length
  • Temporary construction fencing (per week, hire): costs vary depending on provider and panel type
  • Licensed security guard (per shift): costs vary depending on provider and region

Batch quick wins (lighting, signage, lock replacements) into a single works order to reduce mobilisation costs. Capital items like full CCTV systems or access control upgrades typically require procurement approval and a 4–12 week lead time for supply and installation.

Which Australian standards apply to your assessment?

Three documents form the core framework for physical security risk assessments in Australia.

  • AS ISO 31000:2018 sets the overarching risk management process: context, identification, analysis, evaluation, and treatment. Use it to set your risk criteria and scoring scales.
  • SA HB 188:2021 covers base-building physical security for high-risk assets, with guidance on vulnerability analysis and threat sources including terrorism and civil commotion. For construction managers, this handbook stresses identifying vulnerabilities during the design or modification phase rather than retrofitting controls later.
  • SA HB 167:2025 reframes security as a cross-enterprise responsibility, integrating physical, cyber, and people risks. It is the reference for multi-use facilities and sites with IT assets.

For schools and educational facilities, the Queensland Department of Education’s school security procedure sets the minimum reassessment frequency and triggers. For facilities where physical access intersects with IT systems, Cyber.gov.au’s physical security guidelines cover server room zoning, device enclosures, and preventing unauthorised observation.

Compliance checklist items: record the assessment date, assessor name, version of each standard referenced, and the date of the next scheduled review.

What mitigations actually work, and when should you use them?

  1. Protective barriers (fencing, bollards): High upfront cost, low ongoing cost, and effective against vehicle threats and casual intrusion. Prefer for permanent sites. For construction, temporary water-filled barriers are faster to deploy and relocate.

  2. Electronic detection (CCTV, alarms, analytics): Moderate cost, high deterrence value, and essential for evidence capture. Requires a service contract and regular cleaning to maintain effectiveness. Camera analytics (motion zones, loitering alerts) reduce false alarms and improve response times.

  3. Access control (locks, card readers, turnstiles): Best for sites with defined user populations and regular access patterns. Credential management adds an administrative overhead that guards do not. Combine with CCTV for full audit trails.

  4. Lighting and passive surveillance: The lowest-cost mitigation per risk point reduced. Prioritise before any other capital spend. Well-lit sites deter opportunistic crime and improve camera image quality.

  5. Staffing (static guards, mobile patrols): Prefer operational controls when the threat is dynamic (events, construction handover, high-value asset movements) or when a physical control cannot be installed quickly. Mobile patrols cover multiple sites cost-effectively compared to static posts.

  6. Policies and training: Zero capital cost and often the fastest win. An enforced visitor management policy or a tailgating awareness session can close a High-rated finding within days.

Implementation timeline guide: address immediate and high-priority items first (0–30 days), then medium-priority capital works (30–90 days), then longer-term infrastructure upgrades (3–12 months), and schedule lifecycle replacements (12+ months).

Pro Tip: Facility cleanliness and maintenance directly affect passive surveillance. Clear sightlines, unobstructed lighting, and tidy common areas reduce concealment opportunities. Professional cleaning and maintenance is a low-cost complement to physical security controls.

Where can you get a ready-to-use template?

Abcosecurity’s free security risk assessment template includes the grouped checklist above, a scoring matrix, an action register, and a printable inspection form. Download it, add your site map and asset list, and adjust the scoring thresholds to match your organisation’s risk tolerance.

Quick adaptations by sector:

  • Construction: — Add temporary entry points, hoarding integrity, contractor induction records, and plant and equipment storage security.

Pro Tip: Stamp every completed assessment with the date, assessor name, and version number. Store completed assessments in a central repository — auditors and insurers will ask for the last two or three versions, and a gap in the record is harder to explain than a finding that was treated.

How should you document findings and maintain records?

Good documentation does two things: it creates a defensible audit trail, and it drives continuous improvement. Each finding in your risk register should carry the risk rating (inherent and residual), the assigned owner, the agreed treatment, the target completion date, and the actual completion date.

Review the register at every reassessment and at each governance meeting where security is on the agenda. SA HB 167:2025 is explicit that security assessments should feed into enterprise risk registers rather than sit as standalone documents. That integration is what turns a one-off checklist into a continuous improvement cycle.

Retain completed assessment reports for a minimum of seven years. Many insurance policies and government contracts require evidence of regular assessments, and a complete record demonstrates due diligence if a claim or incident is disputed.

Who should you involve in the assessment?

The assessor should not walk the site alone. Facilities managers know where the informal entry points are. Security staff know which alarm zones are routinely bypassed. Operational managers know which assets are genuinely critical versus which ones appear critical on paper.

Structure your stakeholder interviews around three questions: What are the highest-value assets or activities on this site? Where do you see the most unauthorised or unexpected activity? What controls have failed or been circumvented in the last 12 months?

SA HB 167:2025 treats stakeholder involvement as a governance requirement, not a courtesy. For large or complex sites, a pre-assessment workshop with facilities, operations, HR, and security representatives will surface risks that no walkthrough alone would find.

What physical security threats are most common in Australia?

Australian sites face a mix of threats that differ from the generic international risk profile.

Manager indicating outdoor security camera

Opportunistic theft and break-ins remain the most frequent threat across construction, retail, and corporate sites. Construction sites are particularly exposed during after-hours periods and at project handover, when plant, tools, and materials are at their highest value and access controls are often in transition.

Workplace violence and aggression is a significant risk in healthcare, retail, and government-facing facilities. The threat is often internal or from known individuals rather than external intruders, which means access control and duress alarm coverage matter as much as perimeter security.

Natural disasters create secondary security vulnerabilities. Cyclones, floods, and bushfires can disable perimeter fencing, CCTV power supplies, and alarm systems simultaneously, leaving sites exposed at exactly the moment when opportunistic theft peaks. Post-disaster reassessment is a specific trigger that many organisations overlook.

Protest and civil disruption affects infrastructure, government, and resource-sector sites. SA HB 188:2021 addresses civil commotion as a threat source and recommends vulnerability analysis for buildings in these sectors.

Regional and remote sites face longer police response times, which increases the relative value of detection and deterrence controls (CCTV, lighting, alarms) over response-dependent controls.

What are your liability and insurance obligations?

Occupiers of commercial premises in Australia owe a duty of care to employees, contractors, and visitors. A documented security risk assessment is one of the clearest ways to demonstrate that you have taken reasonable steps to identify and mitigate foreseeable risks. Without it, a workplace injury or theft claim becomes much harder to defend.

Most commercial property and public liability insurers now ask for evidence of regular security assessments as a condition of cover or as a factor in premium calculation. Some policies include a requirement to implement recommendations within a specified timeframe. Failing to act on a documented finding and then suffering a loss in that area is the scenario insurers and courts find hardest to excuse.

Workers’ compensation obligations under state and territory legislation also require employers to identify and control workplace hazards, and physical security threats qualify as hazards in high-risk environments.

This article provides general information only and is not legal or insurance advice. Confirm your specific obligations with a qualified legal professional or your insurer.

Abcosecurity: professional assessments across Australia

Abcosecurity delivers on-site physical security risk assessments backed by over 15 years of sector experience and ISO 9001 and ISO 30000 certifications. That combination means the assessment process itself meets a quality standard, and the findings carry weight with insurers, procurement teams, and regulators.

Abcosecurity

For construction managers, the construction site security technology offering covers temporary fencing, CCTV, mobile patrols, and access control from a single provider, which removes the coordination overhead of managing multiple contractors. For facility managers and corporate owners, Abcosecurity’s integrated security solutions cover the full spectrum from assessment through to system design, installation, and 24/7 monitoring.

The practical next step: schedule a site inspection or download the free template at abcosecurity.com.au/security-risk-assessment-template.

Key takeaways

A physical security risk assessment checklist is only useful when it drives documented, prioritised action — scope it correctly, score every finding, and reassess at least annually.

PointDetails
Cover all nine areasPerimeter, access, CCTV, alarms, lighting, barriers, staffing, policies, and recordkeeping must all be verified.
Score with likelihood × consequenceUse a semi-quantitative matrix to produce Extreme, High, Medium, or Low ratings and calculate residual risk after mitigation.
Reassess annually and after triggersReassess at least once per year and after incidents, new system installation, or building changes.
Document for complianceRecord date, assessor, standard version, and findings in a central risk register retained for at least seven years.
Abcosecurity for professional helpISO 9001 and ISO 30000 certified, with 15+ years of experience across construction, healthcare, events, and corporate facilities.

Why most sites get assessed too late

The conventional wisdom is that a security assessment happens after something goes wrong. A break-in triggers a review. A near-miss prompts a walkthrough. That reactive pattern is the single most expensive mistake a facility manager can make, because the cost of a documented assessment is a fraction of the cost of a single significant incident.

What most assessments miss is not the obvious gaps — the broken lock, the dark car park. It is the systemic ones: the service yard that sits outside every camera’s field of view, the contractor induction that has not been updated since the last major works, the alarm zone that staff have been bypassing for months because it false-triggers. Those gaps do not show up on a quick walkthrough. They show up in stakeholder interviews and in the records review, which is why skipping those steps produces a checklist that looks complete but leaves real exposure in place.

A well-run assessment, documented properly and fed into the enterprise risk register, also changes the conversation with insurers. It shifts the organisation from a reactive claimant to a demonstrably managed risk, and that distinction shows up in premiums and in how claims are handled.

Useful sources

Cite these sources in procurement documentation and compliance reports to demonstrate that your assessment methodology aligns with recognised Australian standards.

FAQ

How often should a physical security risk assessment be done?

At least once per year, and also after any major incident, new security system installation, building expansion, or significant change to site operations or assets.

What is the difference between a security audit and a risk assessment?

A security audit checks whether existing controls meet a defined standard; a risk assessment identifies threats, scores their likelihood and consequence, and recommends treatments for gaps. Most sites need both.

What does a risk rating of “Extreme” mean in practice?

An Extreme rating means the combination of likelihood and consequence is at the highest end of your matrix. Address it within 24–72 hours, regardless of cost, and document the interim controls you put in place while the permanent fix is procured.

Can Abcosecurity conduct the assessment for my site?

Yes. Abcosecurity provides on-site physical security risk assessments across Australia for construction, healthcare, corporate, events, and government facilities, backed by ISO 9001 and ISO 30000 certifications.

Do I need a licensed assessor to conduct a security risk assessment in Australia?

Licensing requirements vary by state and territory. For assessments that inform procurement of licensed security services or that are submitted to insurers or regulators, using a licensed security professional is strongly recommended. Confirm requirements with your state’s security industry regulator.

Leave A Comment

related posts