Complete COP 119 Guide for UK Security Firms | ESC Support
UK security labour compliance guide

COP 119 Guide for Security Labour Providers: Vetting, Payroll & Audit Readiness

COP 119 became a recognised benchmark for controlling labour supplied into the security and events sectors. The practical focus is straightforward: know who is being supplied, prove they are suitable and lawful to deploy, keep the payroll and employment chain transparent, and retain evidence that survives customer, ACS and certification scrutiny.

Last reviewed: August 2026 15 min read
Quick answer

What does COP 119 actually require a security labour business to control?

COP 119 is best understood as a labour-supply assurance framework rather than a generic guarding standard. It looks behind the rota and asks whether the organisation supplying people can demonstrate controlled recruitment, screening, right-to-work checks, licensing where required, lawful employment arrangements, transparent pay, appropriate training, clear responsibilities and reliable records.

For an SIA Approved Contractor, this matters even if the labour provider itself is not ACS approved. Current SIA guidance expects the buying contractor to carry out enough due diligence to show that ACS requirements are being met throughout the supply chain. That can include supplier audits, worker-file sampling and payroll checks.

COP 119 / NCP 119 Established sector code and certification language for responsible security and events labour provision.
BS 10119:2026 The current national British Standard, published 30 June 2026, building on earlier labour-provider assurance frameworks.
SIA ACS Does not make COP 119 certification universally mandatory, but does require effective supply-chain due diligence and compliance evidence.
BS 7858 screening Personnel-file screening evidence is a core control where BS 7858 applies.

What is COP 119 and which businesses should care about it?

COP 119 is the name widely used in the security market for the code of practice governing the provision of labour into security and events operations. NSI used the closely related NCP 119 terminology, and now confirms that NCP/COP 119 has been developed into BS 10119:2026.

The core problem it addresses is common across the industry. A guarding company, venue, event organiser or principal contractor wins work but needs extra people to meet the deployment. Instead of directly recruiting every worker, it purchases supplementary labour from another organisation.

That flexibility creates risk if nobody has clear evidence of who recruited the workers, who screened them, whether they have the right to work, whether the correct SIA licence is held, who pays them, what employment model is being used, who monitors hours and what happens when a check expires.

COP 119 is therefore most relevant to:

  • security labour providers supplying officers to another security contractor;
  • event labour providers supplying stewards, crowd-management personnel or security staff;
  • ACS-approved contractors buying in supplementary labour;
  • venues, property managers and event operators carrying out supplier due diligence;
  • businesses seeking to demonstrate a controlled, ethical and transparent labour supply chain.

If you need hands-on preparation rather than general guidance, see our COP 119 consultancy service.

A distinction that affects ACS risk

Is your supplier providing labour, or subcontracting the security service?

This distinction is not just wording. SIA guidance treats bought-in labour differently from subcontracting a customer security service.

Question Labour provision Subcontracted security service
Who holds responsibility for the customer contract? The buying security contractor remains responsible for delivering the service. The subcontractor is responsible for delivering an element of the service on behalf of the main contractor.
Who directs and supervises the operatives? The buying contractor normally directs, inducts, supervises and manages the supplied workers. The subcontractor normally manages its own personnel and service delivery.
Does the supplier need ACS approval? Not automatically if it is genuinely supplying labour only. The actual contract and operating model matter. For designated security services, ACS-approved contractors normally subcontract only to other approved contractors unless an SIA exception applies.
What due diligence remains with the buyer? High. The buyer must be able to demonstrate that supplied personnel meet applicable ACS and legal requirements. Due diligence still applies, even where the subcontractor is ACS approved.

Do not rely on the contract label alone

If an agreement says “labour supply” but the provider is actually managing the security service, setting service standards and controlling delivery, the arrangement may not operate as pure labour provision in practice. Map responsibility for induction, supervision, welfare, performance and customer delivery before deciding which controls apply.

SIA ACS supply-chain assurance

Why COP 119 matters for SIA ACS even when the labour provider is not ACS approved

The strongest reason for an ACS contractor to care about COP 119-style controls is accountability. The SIA's 2026 ACS update says organisations buying labour must carry out sufficient due diligence to demonstrate that the standard is being met throughout the supply chain. It specifically notes that requirements applying to employees also apply to people sourced from other organisations.

In practice, that means a purchase order and a supplier's insurance certificate are not enough. Your due diligence should be capable of answering questions such as:

  • Can we prove supplied workers have been appropriately screened and vetted?
  • Have SIA licences been independently checked where licensable activity is performed?
  • Can we verify right-to-work controls rather than simply accept a supplier declaration?
  • Do payroll and employment arrangements show lawful PAYE, National Insurance and worker payments?
  • Are hours, welfare and minimum-pay risks being monitored?
  • Can we trace a sample worker from recruitment through deployment and payroll?
  • Do we know whether the provider is using another labour provider further down the chain?

The SIA also says supply-chain assurance is likely to require some form of audit, including periodic sampling or testing. That is exactly where a COP 119-style supplier-control framework becomes commercially useful.

Need an independent check before an ACS or customer audit?

ESC Support can review your labour-provider due diligence, sample personnel files, test payroll evidence and identify gaps before an assessor or principal contractor finds them.

What will buyers and auditors expect to see in a controlled labour-supply system?

Exact certification criteria should always be checked against the authorised code or current British Standard and your certification body's scheme rules. At a practical level, however, a mature labour provider should be able to evidence the following control areas.

Control area What can go wrong Evidence an auditor can test
Recruitment & identity Incomplete identity checks, aliases not captured, inconsistent onboarding. Application records, verified identity documents, recruitment checklist, approval decision.
BS 7858 screening Unverified gaps, incomplete references, checks started after deployment, weak outsourced-screening oversight. Chronology, screening evidence, gap resolution, screening-provider controls and internal review.
Right to work Expired permission, incorrect share-code process, missing follow-up dates, no retained check evidence. Correct online/manual/digital check, date completed, checker identity, follow-up control where applicable.
SIA licensing Wrong licence type, expired licence, assuming the supplier checked it. SIA register check, role-to-licence assessment, expiry monitoring and escalation records.
Employment status Workers labelled self-employed when the reality looks like employment, or inappropriate intermediary models. Documented status rationale, contracts matching reality, tax advice where needed, current ACS controls.
PAYE & payroll Opaque deductions, underpayment, non-compliant umbrella/intermediary arrangements, late payment. Payslips, RTI/PAYE evidence where appropriate, payment records, deduction rules, supplier payroll due diligence.
Working time & welfare Excessive hours, inadequate breaks, fatigue and poor treatment of temporary workers. Rota/hours records, opt-out controls where used, welfare arrangements, escalation and review.
Training & competence Available staff deployed without role or site competence. Training matrix, certificates, induction records, assignment briefings and competence sign-off.
Uniform & PPE Unclear responsibility or workers arriving without suitable equipment. Issue records, PPE assessment, replacement controls and customer-specific requirements.
Customer & supplier agreements Assumptions about who checks, pays, supervises or manages workers. Written responsibilities, service/labour agreement, escalation routes and permission for further sourcing.
Records & data protection Missing evidence, uncontrolled spreadsheets, personal data retained insecurely. Document control, access rules, retention schedule, audit trail and data-protection controls.
Supplier monitoring Strong onboarding followed by no ongoing checks. Risk rating, review schedule, file sampling, supplier KPIs, corrective actions and re-approval.
Vetting and screening

What does BS 7858 vetting mean for COP 119 labour files?

BS 7858:2019 is the current British Standard for screening individuals working in a secure environment. It is central to security-sector assurance and is specifically referenced by the SIA for ACS pre-employment screening.

A common mistake is to treat BS 7858 as nothing more than “get five years of references”. That is too simplistic. Public NPSA guidance summarising BS 7858:2019 describes screening as covering identity and address, education and employment information, criminal-record checks, financial checks and confirmation of a current SIA licence where applicable. It also summarises the minimum screening period as three years, with no unverified gaps greater than 31 days, and gives completion deadlines where screening continues after employment starts.

For a labour provider, the practical audit question is whether the personnel file tells a coherent, evidenced story. A reviewer should be able to see:

  • who the person is and how identity was verified;
  • their address and relevant history;
  • employment, education or other activity across the required screening period;
  • how gaps or conflicting information were investigated;
  • the criminal-record and financial checks applicable to the screening process;
  • whether the correct SIA licence was checked where the role requires one;
  • who approved the screening outcome and when;
  • what controls applied if the person started before every check had been completed.

Outsourcing screening does not outsource accountability

The SIA says ACS-approved contractors remain responsible for ensuring outsourced pre-employment screening conforms to BS 7858. A supplier certificate or portal screenshot should not be the end of your control. Define the standard in the contract, audit the screening process and sample underlying evidence.

For exact requirements, use an authorised copy of BS 7858:2019 from BSI and current SIA guidance.

Immigration compliance

How should right-to-work checks be controlled for supplied security workers?

Right-to-work evidence is a recurring audit weakness because businesses sometimes keep a copy of a passport or a share-code email without proving that the prescribed employer check was completed correctly.

For direct employees, the Home Office requires the employer to complete a compliant check before employment begins. Depending on the individual's status, this can be a manual document check, a Home Office online check using a right-to-work share code, or an eligible digital verification route for British and Irish citizens. Time-limited permission also requires follow-up control.

For a security labour supply chain, good due diligence should answer four questions:

  1. Who is the legal employer? Identify who carries the statutory employer duty.
  2. How was the check completed? Do not accept a vague statement that “RTW was done”.
  3. What evidence is retained? The record should show the check result, date and any work restrictions or expiry.
  4. How will expiry be controlled? Build a follow-up date into the worker or supplier monitoring system.

Current Home Office guidance says employers should retain clear right-to-work check evidence for the duration of employment and for two years after it ends. For bought-in labour, your own retention basis may differ because you are not necessarily the legal employer, but your ACS, contractual and supplier-audit evidence still needs to be sufficient to demonstrate due diligence.

Official reference: Home Office right-to-work checks guidance.

Payroll transparency

What are the main COP 119 PAYE and payroll risks in 2026?

Payroll is not a back-office issue when you supply security labour. It is a supply-chain compliance control. SIA ACS guidance expects approved contractors to evidence compliance with relevant PAYE and National Insurance requirements and allows assessors to trace sampled staff through the payroll system.

For labour providers and contractors, the highest-risk areas include:

  • workers being treated as self-employed where the actual working relationship points towards employment;
  • personal service company models being used for regulated activity in an ACS supply chain;
  • opaque umbrella or intermediary arrangements where nobody has tested whether PAYE is being operated correctly;
  • deductions that are unclear, unauthorised or reduce pay below the applicable minimum wage;
  • late or inconsistent payments to workers supplied through an agency;
  • invoices that cannot be reconciled to named workers, hours and payroll evidence;
  • supplier rates that appear commercially impossible once lawful pay, holiday, employer NICs and other employment costs are considered.

2026 ACS red flag: personal service companies

The SIA's July 2026 ACS update states that approved contractors cannot use operatives working through their own intermediaries, commonly called personal service companies, to deliver regulated activity, whether directly or through labour providers or other entities. If your supply chain still contains one-person company arrangements for frontline regulated work, treat this as an immediate review point.

2026 tax change: umbrella-company PAYE liability

From 6 April 2026, new PAYE rules apply to labour supply chains involving umbrella companies. HMRC says the agency contracting with the end client, or the end client where no agency is involved, is responsible for making sure PAYE is operated correctly and HMRC can recover underpaid PAYE from them. Security businesses using umbrella-style labour models should update supplier due diligence accordingly.

What should payroll due diligence test?

  • Who employs and pays each worker?
  • Is the contractual model consistent with how work is actually controlled?
  • Can sample shifts be traced from timesheet to invoice to payslip/payment?
  • Are deductions transparent and agreed?
  • Is minimum wage compliance tested after relevant deductions?
  • Are workers paid within the agreed cycle?
  • Can the supplier provide reasonable evidence of PAYE and tax compliance?
  • Do commercial rates make sense once lawful employment costs are included?

Where tax status is uncertain, take specialist tax advice. COP 119 compliance consultancy should not be used as a substitute for HMRC guidance or professional tax advice.

Subcontracting and chain control

Why second-tier labour can become your biggest COP 119 risk

A labour provider may look compliant at onboarding but quietly source workers from another agency when demand spikes. That creates another layer of recruitment, screening, payroll and responsibility that the buying contractor may never have approved.

Typical warning signs include:

  • workers appearing on site who were not on the approved labour-provider list;
  • different company names appearing on payslips, timesheets or invoices;
  • the provider being unable to produce screening evidence directly;
  • large increases in supplied headcount with no corresponding recruitment activity;
  • staff saying they are paid by a different company;
  • workers using inconsistent uniforms, induction records or contact routes;
  • the provider refusing to disclose whether it uses other labour sources.

Your supplier agreement should therefore be explicit about whether further labour sourcing is allowed, what approval is required, which standards apply, what audit rights you retain and what evidence must be available for every worker deployed.

For ACS-approved contractors, this also supports the wider requirement to understand whether the arrangement is labour provision or true subcontracting and to control the quality of external suppliers.

COP 119 audit checklist: can you evidence these controls today?

Use this as a management-level readiness check before a customer review, ACS assessment or labour-provider certification audit. It is not a substitute for the official scheme criteria.

  • Our labour-provider model and responsibilities are documented.
  • We know the difference between labour supply and subcontracted service delivery.
  • Every worker can be traced to an approved provider and assignment.
  • Recruitment and identity evidence is complete and controlled.
  • BS 7858 screening is demonstrable where applicable.
  • Outsourced screening providers are contractually controlled and audited.
  • Right-to-work checks are valid, retained and monitored for expiry.
  • SIA licences are independently verified for licensable roles.
  • Licence expiry and suspension risks are monitored.
  • Employment status is documented and matches working reality.
  • No prohibited PSC arrangement is being used in the ACS regulated labour chain.
  • PAYE and National Insurance compliance can be evidenced.
  • Sample shifts can be traced through timesheet, invoice and payroll.
  • Minimum-pay and deduction risks are reviewed.
  • Working-time and fatigue controls are operating.
  • Training, induction and competence evidence matches the assignment.
  • Uniform, PPE and welfare responsibilities are clear.
  • Supplier agreements control further labour sourcing.
  • Supplier performance is reviewed after initial approval.
  • Corrective actions are documented and closed out.
  • Personnel and supplier records are secure, legible and retrievable.
  • Managers can explain the system without relying on one compliance person.

If several answers are “no”, “partially” or “we think so”, start with a gap analysis

A focused gap analysis is usually more useful than buying another generic policy pack. ESC Support can review the system you already have, sample real files and prioritise the weaknesses most likely to create audit findings.

COP 119 vs BS 10119:2026: what should existing labour providers do now?

BS 10119:2026 is titled Provision of labour to the security and events sectors — Code of practice. BSI describes it as certifiable best-practice guidance for managing additional licensed or unlicensed labour, and says it covers organisational responsibilities, screening, training, PPE, employment documentation and records, with controls around SIA licensing, working time, PAYE, right to work and employment status.

NSI says its NCP 119 code has now been developed into BS 10119 and that the new British Standard contains substantial similarity plus additional requirements that strengthen labour provision.

Area COP 119 / NCP 119 BS 10119:2026
Status Established sector code/certification terminology still visible in existing certificates and procurement. Current British Standard, published 30 June 2026.
Purpose Control ethical, lawful and reliable provision of security/events labour. Nationally standardised best-practice framework for bought-in labour in security and events.
Core themes Screening, right to work, licensing, pay, employment controls and supply-chain assurance. Retains those themes and formalises broader management, responsibilities, worker controls and evidence.
Certificate transition Existing certificate remains subject to the issuing body's scheme and transition arrangements. Do not assume automatic conversion. Confirm the migration route with your certification body.
Best action now Keep existing controls working and correct known weaknesses. Map existing COP 119 evidence against BS 10119 and close additional gaps before transition deadlines or customer requests.

Five sensible steps for a COP 119-certified or COP 119-ready business

  1. Do not dismantle your current system. Much of the evidence remains useful.
  2. Get the authorised BS 10119 standard. Do not build a transition plan from online summaries alone.
  3. Confirm your certification body's route. Ask what changes, deadlines and audit arrangements apply to your certificate.
  4. Run a formal gap analysis. Compare current policies, worker files, payroll controls and management evidence with BS 10119.
  5. Fix process gaps before rewriting documents. A procedure should describe a control your business can actually perform and prove.

For a full explanation of the new standard, use the BS 10119 hub and BS 10119:2026 guide. If you want a managed transition project, see BS 10119 consultancy support.

Already have COP 119 documents? You probably do not need to start again.

ESC Support can review the controls and evidence you already use, identify what remains suitable and build a targeted transition plan for BS 10119. The objective is to preserve useful work, not replace it with a second parallel compliance system.

Frequently asked questions about COP 119

Is COP 119 mandatory for UK security companies?

No. COP 119 is not legislation requiring every UK security business to hold certification. It has been used as a sector benchmark for responsible labour provision and may be required by customers, principal contractors or certification schemes. BS 10119:2026 is now the current British Standard for this area.

Is COP 119 the same as BS 10119:2026?

They cover closely connected labour-provider controls, but they are not simply interchangeable labels. BS 10119:2026 was published by BSI on 30 June 2026 and is the current British Standard. Existing COP 119 or NCP 119 certificate holders should confirm transition arrangements with their certification body.

Does COP 119 replace SIA ACS approval?

No. SIA ACS applies to eligible security contractors, while COP 119 and BS 10119 focus on the provision and control of supplementary labour. They can interact because ACS-approved contractors must carry out due diligence on labour providers and supplied workers.

Does a labour provider need SIA ACS approval?

Not necessarily. Current SIA guidance distinguishes pure labour provision from subcontracting a security service. A labour provider supplying temporary workers who are directed and supervised by the ACS contractor is not treated in the same way as a subcontractor delivering the security service. The actual contract and operating model matter.

Can an ACS contractor outsource BS 7858 screening?

Yes, but responsibility does not disappear. SIA guidance states that an approved contractor remains responsible for ensuring outsourced pre-employment screening conforms to BS 7858 and should audit the screening process.

Can ACS security operatives work through personal service companies?

The SIA's 2026 ACS update states that approved contractors cannot use operatives working through their own intermediaries, commonly called personal service companies, to deliver regulated activity, whether directly or through the wider labour supply chain.

What should a COP 119 audit file contain?

A strong audit trail normally links company-level procedures to worker-level evidence. This can include recruitment and screening records, right-to-work evidence, SIA licence checks where required, employment and payroll records, training and competence evidence, working-time controls, deployment records, supplier agreements and internal review records.

Does an existing COP 119 certificate automatically become BS 10119 certification?

No. Publication of BS 10119:2026 does not automatically convert an existing COP 119 or NCP 119 certificate. Certificate holders should follow the transition route set by their certification body.

Turn the checklist into an audit-ready compliance system

Reading the standard is one job. Proving that screening, payroll, right-to-work checks and labour-provider controls work across real worker files is another. ESC Support helps UK security and event labour businesses find the gaps, fix the evidence and prepare management for independent scrutiny.