Commercial Security Service Agreement Checklist
Evaluate a commercial security service agreement by testing scope, exclusions, response clocks, restoration duties, costs, evidence and exit terms.
A security service agreement proves its value when a camera is offline before an incident, a controlled door will not secure, an alarm path fails or a critical licence expires. The customer needs to know who acts, how quickly the risk is contained, what restoration means, what it will cost and what evidence closes the ticket.
Use one rule for every important promise: define the event, clock start, target, owner, evidence and remedy. Apply it to preventive maintenance, remote support, on-site response, parts, software, monitoring coordination and emergency work. This turns broad assurances such as “priority service” into operating commitments that facilities, security, IT, procurement and the provider can follow under pressure.
This checklist supports commercial contract review and operational planning. It is not legal advice. Ask qualified legal counsel to review liability, indemnity, insurance, privacy, termination and other legal terms for your organization.
Start with the customer outcome and the consequence of delay
The agreement should protect defined business operations. Begin with failure scenarios and required outcomes, then map services to them.
For each site, ask:
- Which camera views, controlled openings, intrusion zones, intercoms, recorders, servers, networks, cloud services and monitoring paths are covered?
- What operational consequence follows if each service is unavailable?
- How long can that condition continue before a temporary control or restoration is required?
- Who can approve downtime, dispatch, after-hours work and additional cost?
- Which records must exist after response and repair?
A distribution facility may need a failed shipping-gate reader contained before the next shift. A property manager may need a recorder fault diagnosed before the required video window is lost. A retailer may need a failed alarm communication path escalated immediately after closing. These are service outcomes. The device list supports them.
Attach a dated asset and service inventory to the agreement. Include quantities, locations, model families, software versions, licences, warranty status, customer-supplied infrastructure and known deficiencies. A price based on an undefined installed base invites disputes when an older device, lift requirement or third-party dependency appears during a call.
Make included work, assumptions and exclusions explicit
Customers often discover the practical boundary of a service plan only after opening a ticket. Convert that boundary into a schedule that can be read before signature.
| Service element | Define in the agreement | Evidence to request |
|---|---|---|
| Support intake | Phone, portal and email channels; service hours; authorized callers; after-hours path | Test ticket with time-stamped acknowledgement |
| Remote diagnosis | Covered platforms, secure-access method, customer approval, time limit and handoff | Session record and diagnostic summary |
| On-site labour | Included hours, technician qualifications, travel zone, minimum charge and overtime rule | Work order with arrival, departure and labour category |
| Preventive maintenance | Exact devices, tasks, frequency, sampling rule and deficiency process | Asset-level checklist, readings, images where useful and failed items |
| Parts and consumables | Included parts, allowance, markup, batteries, drives, loaners and substitutions | Parts record, authorization and warranty disposition |
| Access equipment | Lifts, traffic control, escorts, roof access, permits and site induction | Priced responsibility and scheduling lead time |
| Software and licences | Renewals, updates, compatibility testing, backups, rollback and vendor support | Version report, licence record and post-change test |
| Monitoring coordination | Test periods, signal handling, call-list updates and return-to-service confirmation | Monitoring activity record and closure confirmation |
List exclusions beside the related service. A general exclusions paragraph can hide the operational effect. State whether damage, vandalism, water, power quality, network changes, construction, third-party products, obsolete equipment, cybersecurity incidents, failed customer infrastructure and out-of-area travel are excluded or separately priced.
Also state the assumptions that make the price valid: safe access, accurate drawings, available spares, supported software, customer escorts and remote connectivity. Assign an owner and a correction process when an assumption proves false.
Define response, containment and restoration as separate commitments
“Four-hour response” is incomplete until the agreement defines what happened at hour four. It could mean an email acknowledgement, remote diagnosis, technician dispatch or arrival on site.
Build service levels around observable events:
| Stage | Contract question | Example evidence |
|---|---|---|
| Detection | Who notices the fault, and does the plan include system-health monitoring? | Health alert or customer ticket |
| Acknowledgement | When does an accountable person accept the case? | Ticket status and named owner |
| Triage | When is severity confirmed, and who can change it? | Diagnostic note and priority record |
| Containment | What temporary measure reduces exposure while repair is pending? | Documented workaround and customer approval |
| Attendance | When is on-site arrival required, if remote work cannot restore service? | Technician check-in or site record |
| Restoration | Which complete security function must pass? | Functional test and customer-visible result |
| Closure | Who approves the result, and what remains open? | Signed service report and deficiency list |
Define priority using business consequence. A recorder serving a high-consequence area, an uncontrolled perimeter door and a single failed low-priority camera should not automatically share one target.
For every clock, specify coverage hours, time zone, start event, stop event, measurement formula and permitted pauses. Identify dependencies such as customer access, manufacturer authorization, replacement parts and third-party network repair. Require the provider to record the pause reason and notify the customer instead of silently stopping the clock.
The Treasury Board of Canada Secretariat’s service-agreement guideline separates scope, governance, operations, finances, performance and implementation. It also describes service targets using a definition, timeframe, assumptions, responsibilities, service level and measurement formula. The guideline was written for federal service relationships, so commercial organizations should use its structure as a drafting aid and obtain legal review for their own contract.
Assign responsibilities across facilities, IT, security and the provider
Physical security systems cross several operational boundaries. Cameras and controllers depend on power and networks. Monitoring depends on current contacts and instructions. Remote support depends on approved access. Repairs may depend on escorts, lifts or a landlord.
Use a responsibility matrix for recurring work and incidents. Name the role that performs each task and the role accountable for the result. Cover at least:
- system-health review and ticket creation;
- user, credential and administrator management;
- network, server, storage, power and time-source support;
- manufacturer advisory and lifecycle review;
- update approval, backup, testing and rollback;
- monitoring contacts, test periods and dispatch instructions;
- site access, keys, escorts and safety requirements;
- privacy requests, authorized video export and disclosure records;
- spare ownership, replenishment and secure storage;
- incident escalation, temporary controls and business communication; and
- invoice approval, service-level review and dispute escalation.
Public Services and Procurement Canada’s 2026 service-contract administration guidance recommends agreeing on responsibility division before finalizing a contract and monitoring time, resources, cost and quality against an agreed work plan. Its rules apply to federal procurement, while the control is broadly useful: appoint one customer contract owner and one technical authority, then make handoffs visible.
Price the full service path and protect future choice
The recurring fee is only one part of the customer’s exposure. Create a rate schedule covering regular hours, after-hours labour, travel, minimum calls, remote support, lifts, consumables, parts markup, shipping, loaners, software, licences, cloud storage, cellular service, monitoring, inspections and project work.
For each price, record:
- what quantity or event triggers the charge;
- what is included in the base fee;
- the authorization threshold for extra work;
- annual adjustment or index rule;
- taxes and currency assumptions;
- rate validity and renewal date; and
- the evidence required with the invoice.
Keep warranty and service coverage separate. A manufacturer may repair or replace eligible hardware while labour, removal, shipping, access equipment, reinstallation and retesting remain outside that remedy. Axis currently describes a five-year limited hardware warranty for most eligible hardware, paid RMA support in some uncovered cases, and distinct hardware, device-software and application-software support periods in its support policy after discontinuation. Those are one manufacturer’s current terms. The agreement needs product-specific terms for the installed estate.
Define exit before renewal. Require a current asset list, configuration backups, drawings, licence records, warranty records, administrator transfer, credential and data export, open-ticket history, service records, return or destruction of customer data, revocation of remote access and reasonable transition assistance. State formats, deadlines, charges and the functions that continue after cancellation.
Where a provider handles video or access records containing personal information, address authorized use, safeguards, staff access, subcontractors, incident notice, retention, return and deletion. The Office of the Privacy Commissioner of Canada’s outsourcing guidance explains that an organization subject to PIPEDA remains responsible for protecting personal information handled by a third-party processor. Applicable law and organizational circumstances require case-specific privacy advice.
Connect standards, certification and manufacturer lifecycle to the exact service
A reference to “industry standards” does not identify the service being purchased. Name the standard, edition, system, certificate requirement, provider listing category, test obligation and required record.
UL Solutions Canada’s fire and security alarm certificate program identifies CAN/ULC-S301:2018 for signal receiving centres and CAN/ULC-S302-14 for intrusion alarm installation, inspection and testing. It states that applicable program service contracts and auditable service records must be maintained. It also distinguishes Full Service from Shared Service and explains that a listed company does not make every installation a certificated system. Ask whether the specific site requires an active certificate, who issues and maintains it, and which party performs service and monitoring.
Lifecycle duties need the same precision. The current Genetec Security Center lifecycle policy separates general availability, general support, limited support and end of life, with different maintenance and support at each stage. Other manufacturers use different terms and dates. Require the provider to maintain a model-and-version register, notify the customer of lifecycle changes, recommend action with lead time, identify upgrade dependencies and obtain approval before changing production systems.
Make performance visible through evidence and review
An agreement becomes manageable when the customer can verify its operation. Specify a monthly or quarterly service report that includes:
- tickets opened, severity, source and covered system;
- acknowledgement, triage, attendance, containment, restoration and closure times;
- clock pauses and reasons;
- service-level results using the agreed formula;
- repeat faults and root-cause actions;
- preventive work completed, missed and rescheduled;
- open deficiencies, temporary controls, owners and due dates;
- parts usage, spares below threshold and obsolete items;
- lifecycle, licence, certificate and warranty changes; and
- charges outside the base fee with approval evidence.
Review the report with facilities, security, IT and procurement. Focus on repeated failure, missed outcomes and unresolved risk. Service credits can provide a commercial remedy, but they do not restore a camera view or secure a door. Require a corrective-action plan when the same service-level failure recurs.
Run an acceptance drill before relying on the agreement
Test the support model during onboarding and after material changes. Use controlled, fictional scenarios and coordinate monitoring tests to avoid unintended dispatch.
- Open a routine ticket through the approved channel and verify acknowledgement, ownership and status visibility.
- Simulate a critical camera or recording fault and confirm priority, remote diagnosis, containment and escalation.
- Test one controlled-door failure from customer report through safe temporary control and passing functional retest.
- Place an intrusion point on test, exercise the agreed workflow and verify return-to-service evidence.
- Request a configuration backup, current asset list and administrator-access record.
- Compare the service report with tickets, test evidence and the rate schedule.
Record every gap as a contract clarification, onboarding deficiency or operating procedure. Assign an owner and due date before declaring the service ready.
This agreement checklist has a narrower job than a purchasing scorecard or cost model. It converts the selected service into measurable operating commitments. Use it within a broader commercial security system program, then transfer lifecycle dates, spare requirements, renewal triggers and unresolved risks into the facility’s security-system lifecycle plan.
If your organization needs a service scope tied to actual sites, systems and failure consequences, Securitron Canada can help document the installed baseline, response workflow, evidence and acceptance tests before renewal or procurement.
Frequently Asked Questions
Define each covered system and site, service hours, preventive work, incident priorities, response and restoration targets, parts and labour, customer duties, exclusions, evidence, escalation, pricing, renewal, data handling and exit assistance. Attach the asset and service inventory used to price the agreement.
No. Response may mean acknowledging a ticket, starting remote diagnosis or arriving on site. Restoration means returning the agreed security function to service. Define both clocks, their start and stop events, coverage hours, pauses, dependencies and required evidence.
The agreement should state exactly which labour, travel, lifts, consumables, replacement parts, shipping, software support and after-hours premiums are included. Warranty coverage should also identify who pays for diagnosis, removal, shipping, reinstallation and retesting.
Run a controlled service drill, review monthly ticket and response data, sample preventive-maintenance evidence, verify open deficiencies, and test restoration of representative camera, access-control and alarm functions. Reconcile results with invoices and service-level calculations.


