Commercial Security System Inspection Checklist

Use daily, monthly and annual security system inspections to find camera, alarm, access, power, network and process faults before an incident.

Illustrative facilities manager and security technician inspecting integrated commercial security systems

A green status icon can coexist with unusable footage, a door that does not latch, an expired battery or an alarm path that nobody receives. Facilities and property managers need an inspection program that proves complete outcomes, assigns defects and confirms repair.

Use daily operational checks, monthly functional inspections and a comprehensive annual inspection as a starting cadence. Adjust it for the facility’s risk, equipment, environment, monitoring agreement, insurer requirements, manufacturer instructions and applicable standards. Add event-driven inspections after renovations, outages, incidents, repeated alarms, network changes and configuration work.

This checklist covers video surveillance, access control, intrusion alarms and their supporting power, network and operating procedures. Fire alarms and other life-safety systems have separate code, standard and qualified-person requirements. Keep them under their required inspection programs.

1. Build the inspection register before choosing frequencies

An inspection program needs an accurate asset and service register. A checklist organized only by product type can miss dependencies such as a recorder licence, a monitoring path or the network switch powering an entire camera group.

For every security service, record:

  • business purpose and criticality;
  • site, zone and accountable owner;
  • device, panel, server, application and cloud-service dependencies;
  • power source, battery or uninterruptible power supply;
  • network path and time source;
  • monitoring destination and escalation contacts;
  • manufacturer, model, serial number, firmware and support status;
  • configuration-backup location and last verified restore;
  • required inspection source, such as a contract, standard, insurer condition or manufacturer document; and
  • last result, open defects and next due date.

The Canadian Centre for Cyber Security’s 2023 IT asset management guidance describes inventory records that include location, ownership, condition, lifecycle status, warranties, licences, support agreements and maintenance costs. Its scope is IT asset management, so facilities teams should adapt it to physical security devices and their operational purpose.

Create one test statement for each critical service. Examples include:

  • an authorized credential unlocks the correct door and creates the expected event;
  • a forced-door condition reaches the assigned operator within the approved workflow;
  • a selected camera records usable video, with the correct time, throughout the required period;
  • an intrusion input produces the correct local, monitoring and notification result; and
  • a power or network fault generates an actionable alert to an owned queue.

These statements define what the inspection must prove. Device status alone cannot prove the complete service.

2. Assign daily, monthly and annual responsibilities

Each task needs one person responsible for performing it and one person accountable for unresolved risk. Avoid shared ownership labels such as “facilities and IT” without naming the handoff.

FrequencyPrimary ownerPurposeRequired evidence
Daily or each operating shiftSecurity desk, facilities operator or site leadFind current faults and missed responsesDated check, exceptions and ticket numbers
MonthlyFacilities or security coordinator with system administratorsExercise selected functions and review driftTest sample, results, exports or screenshots where appropriate, and defect log
AnnualQualified service provider plus internal ownersInspect the full system, dependencies and operating workflowSigned report, asset-level results, deficiencies, risk acceptance and closure evidence
After change or incidentChange owner or incident ownerConfirm that the system still meets the approved purposeFocused retest linked to the change or incident record

Set a substitute for absences and a deadline for review. A completed checklist with unassigned failures leaves the risk open.

UL Solutions Canada’s current fire and security alarm certificate program overview identifies CAN/ULC-S301:2018 for signal receiving centres, CAN/ULC-S302-14 for installation, inspection and testing of intrusion alarm systems, and CAN/ULC-S304:2016 for control units and related equipment. It also states that service records are maintained within its certificate programs. The program overview does not publish every test method or interval. Confirm the current standard edition, certificate, monitoring agreement and service contract that apply to the specific installation.

3. Daily security system inspection checklist

Daily work should be short, consistent and focused on conditions that need immediate action. Automate health alerts where supported, then require a person to review the exception queue.

Video surveillance

  • Confirm that recorders, management servers and critical cameras report online.
  • Review new storage, database, licence, clock, certificate and camera-tamper warnings.
  • Play back a recent recorded segment from at least one rotating critical camera. Confirm image, time and continuity.
  • Check a rotating live view for obstruction, severe blur, glare, darkness, condensation or changed aim.
  • Confirm that privacy masks required by policy remain present in the reviewed view.

Access control

  • Review offline controllers, reader faults, communication loss and abnormal door-held or forced-door events.
  • Confirm that high-consequence doors appear closed and secure in the system and during a safe physical walk-through.
  • Review failed or repeated access events according to the approved operating procedure.
  • Confirm that urgent credential removals and temporary access expiry requests were completed.

Intrusion alarm and monitoring

  • Review panel trouble, low-battery, communication and supervision events.
  • Confirm that overnight alarm events have an operator disposition and required follow-up.
  • Check that the monitoring and emergency contact list has no known staffing gaps.
  • Escalate repeated activity from the same zone instead of repeatedly resetting it.

Shared infrastructure and response

  • Review security network, PoE switch, UPS, recorder and integration health alerts.
  • Confirm that faults entered the correct ticket queue with owner, severity and due time.
  • Check for facility conditions that can affect performance, including construction dust, moved shelving, water, impact damage or blocked doors.
  • Verify that operators can reach the current service and escalation contacts.

A rotating sample keeps the daily check manageable. Define the rotation so all critical views and doors receive attention within the monthly cycle.

4. Monthly functional inspection checklist

The monthly inspection exercises system functions and catches gradual drift. Coordinate alarm tests with the monitoring station, affected tenants and operations. Use an approved test window and prevent unintended dispatch.

Prove recording and image usefulness

  • Play back selected cameras from several past dates and times, including one low-light period where relevant.
  • Confirm expected retention without extending storage beyond the approved privacy purpose.
  • Compare critical fields of view with commissioning images or signed view schedules.
  • Check focus, aim, privacy masks, time accuracy, frame continuity and export capability.
  • Inspect accessible housings, domes, mounts and visible cable entries for dirt, damage, looseness or moisture.

Axis Communications’ 2021 PTZ preventive-maintenance instructions and checklist includes playback of a stored recording, storage status, firmware compatibility, dome condition, fasteners, brackets and Ethernet cabling. It is manufacturer guidance for Axis PTZ cameras. Apply the manual for each installed model and avoid treating one manufacturer’s document as a universal procedure.

Exercise doors and alarm inputs

  • Test a representative group of credentials, readers, request-to-exit devices and door contacts.
  • Observe that each tested door unlocks, closes and positively latches without binding.
  • Verify forced-door, held-door and invalid-credential events through the complete notification path.
  • Test selected intrusion inputs, tamper conditions, arm and disarm functions, and approved notification workflows.
  • Rotate the sample and track coverage so every device receives its required full test.

Never defeat egress, accessibility or life-safety functions for a security test. Coordinate powered-lock and emergency-release testing with qualified parties under the applicable requirements.

Review access, privacy and administration

  • Remove inactive users and expired vendor access.
  • Review administrator, remote-support and export privileges.
  • Confirm holiday schedules, time zones and automatic expiry rules.
  • Review footage exports, unusual administrator actions and configuration changes.
  • Confirm that retention, preservation and secure deletion operate as approved.

The Office of the Privacy Commissioner of Canada’s overt private-sector video guidance recommends secure storage, limited access, justified and documented disclosures, purpose-based retention and periodic evaluation. The guidance excludes employee surveillance and does not resolve every organization’s legal duties. Use the relevant law and sector guidance for the site.

5. Annual comprehensive inspection checklist

The annual inspection should cover every in-scope asset and the full path from detection to response. Qualified technicians should perform tasks that require opening enclosures, working at height, measuring power, changing firmware or affecting monitored service.

Physical and electrical condition

  • Reconcile the installed system with the asset register and as-built drawings.
  • Inspect devices, fasteners, housings, weather seals, cable paths, labels and protected enclosures.
  • Measure power and battery condition using manufacturer-approved procedures.
  • Test UPS runtime, orderly shutdown and recovery against the documented requirement.
  • Inspect racks for temperature, dust, water exposure, unsupported cables and available power or PoE capacity.

Full functional and failure testing

  • Test every required camera view under representative day and night conditions.
  • Prove recording, search, playback, export, retention and controlled deletion.
  • Exercise each required access point, credential rule, schedule, alarm input and notification.
  • Test primary and approved backup communication paths.
  • Simulate selected device, network and power failures and confirm owned alerts.
  • Run a tabletop response using a fictional incident from detection through evidence preservation and closure.

Cybersecurity and lifecycle

  • Reconcile firmware, operating systems, applications, licences and support dates.
  • Review vendor advisories and prioritize exposed or high-consequence vulnerabilities.
  • Back up current approved configurations and test a representative restoration method.
  • Review named accounts, administrative privilege, MFA, certificates, keys and vendor remote access.
  • Confirm that logs are retained, protected and reviewed according to policy.
  • Identify unsupported assets and approve a replacement or compensating-control plan.

The Cyber Centre’s 2025 cybersecurity hygiene guidance recommends maintaining asset inventories and secure baselines, patching after risk and compatibility assessment, regularly reviewing privileges, testing backups and managing device lifecycles. Security systems can have operational dependencies, so use a staged change plan with rollback and post-change functional testing.

Documentation and readiness

  • Update drawings, zone lists, camera schedules, data flows and response procedures.
  • Reconcile keys, credentials, licences, spare parts, warranties and service contacts.
  • Verify operator and administrator training through a practical task.
  • Review false alarms, recurring faults, downtime, response delays and overdue defects.
  • Reassess system purpose after layout, tenancy, staffing or operational changes.
  • Approve the next inspection schedule, budget and replacement priorities.

6. Grade defects and prove closure

Use severity definitions that facilities, IT, security and the service provider understand.

SeverityExampleRequired treatment
CriticalNo recording for a critical area, uncontrolled high-risk door, unavailable alarm path or unsafe conditionImmediate escalation, compensating measures, executive owner and continuous tracking to restoration
MajorDegraded coverage, failed backup path, recurring controller fault or overdue security update with material exposureTime-bound repair, documented risk owner and verified retest
MinorDirty housing, incomplete label or non-critical documentation gapPlanned correction and closure evidence
ObservationCapacity trend, nearing support date or improvement opportunityRecord for lifecycle and budget review

Every defect record should contain the asset, time found, observed result, expected result, evidence, operational impact, severity, temporary measure, owner, due date and repair action. Closure requires a retest by an appropriate person. A work order marked complete without the expected result leaves uncertainty.

Track a small set of useful measures:

  • percentage of scheduled inspections completed on time;
  • critical and major defects open beyond target;
  • repeat defects by asset or cause;
  • mean time from detection to compensating control and restoration;
  • percentage of critical cameras with successful sampled playback;
  • percentage of access and alarm tests that completed the full response path; and
  • unsupported assets without an approved treatment plan.

Trends should drive action. Repeated faults can indicate a design, environmental, power, network, training or service-process issue.

7. Acceptance tests and vendor questions

Before approving an inspection program or maintenance contract, ask:

  1. Which standards, contracts, insurer conditions and manufacturer procedures set the required scope and frequency?
  2. Which checks are automated, who reviews alerts and how is alert delivery itself tested?
  3. Does the annual inspection test every required device and complete workflow, or only a sample?
  4. How are monitoring tests placed on test and returned to service without unintended dispatch?
  5. What evidence accompanies each result, and who verifies defect closure?
  6. How are firmware compatibility, backups, rollback and post-update testing handled?
  7. Which batteries, drives, licences, certificates and supported-life dates are tracked?
  8. What response times and temporary controls apply to critical defects?
  9. How are tenant, privacy, egress, accessibility and operational constraints handled?
  10. Who owns the records and receives them when the service agreement ends?

Run a pilot inspection before accepting the process. Select one camera, one controlled door, one intrusion point and one shared infrastructure failure. Verify that the team can detect the condition, create a useful record, notify the correct owner, apply a safe temporary measure, repair it and produce a passing retest.

Use this framework to define the maintenance and operating section of a broader commercial security system program. A site-specific inspection plan should connect assets, required outcomes, people and evidence. If your facility needs a documented baseline and test scope, request a commercial security review that accounts for the installed equipment, operating environment and applicable obligations.

Frequently Asked Questions

Use daily operational checks, a documented monthly functional inspection and a comprehensive annual inspection as a starting cadence. Increase frequency for critical assets, harsh environments, repeated faults, insurer or contract requirements, and applicable standards. Add checks after construction, configuration changes, incidents and outages.

Name an accountable facilities or security owner, a daily operator, qualified technical support and an approving manager. Every checklist item needs one role, an escalation path and a deadline for closing defects.

No. A live image does not prove that the correct stream was recorded, retained, time-stamped and retrievable. Inspectors should play back selected footage from a defined past time and document the result.

Review firmware and security advisories on a defined schedule. Test compatibility, back up the configuration, approve the change, deploy to a limited device first and verify operation before wider rollout. Follow manufacturer and system-integrator requirements.