{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Building Security and Access Control Policy

1. Purpose

The purpose of this policy is to establish clear arrangements for maintaining the security of {{org_field_name}} while ensuring that security measures respect the rights, privacy, dignity, autonomy and freedom of movement of individuals receiving care and support.

This policy supports compliance with:

{{org_field_name}} will maintain premises that are secure from unauthorised access while ensuring that security arrangements are proportionate to identified risks and do not unnecessarily restrict an individual’s freedom of movement, privacy, dignity, independence or ability to receive visitors.

Any restriction placed on an individual’s movement or access to and from the premises must be based on an individual assessment, be necessary and proportionate to the identified risk, be documented within the individual’s personal plan where appropriate, and have lawful authority where the restriction amounts to a deprivation of liberty.

This policy describes how {{org_field_name}} manages access to the premises, security measures, visitor arrangements, staff responsibilities, surveillance systems where used, and responses to security incidents or unauthorised access.

2. Scope

This policy applies to all residents, staff, agency workers, contractors, visitors, and emergency personnel entering or exiting {{org_field_name}}. It covers:

3. Principles of Building Security

{{org_field_name}} is committed to ensuring a safe, secure, and welcoming environment by following these key principles:

4. Security Measures and Access Control

4.1 Secure Entry and Exit Points

{{org_field_name}} will maintain appropriate arrangements to protect the premises from unauthorised access while ensuring that individuals receiving care and support are not unnecessarily restricted from entering or leaving the premises.

Security arrangements will be proportionate to the nature of the service, the risks associated with the premises and the assessed needs of individuals living at the service.

Measures include:

Security arrangements will be reviewed whenever an individual’s needs, capacity, risks or legal authority change.

4.2 Visitor Management and Sign-In Procedures

{{org_field_name}} will operate proportionate visitor arrangements which protect individuals and the security of the premises while respecting individuals’ rights to maintain relationships, receive visitors and meet visitors in private.

The following arrangements apply:

Visiting arrangements will not be applied in a way that unnecessarily interferes with an individual’s privacy, dignity, family relationships or personal autonomy.

4.3 Staff Responsibilities and Access Control

Staff members are responsible for maintaining security by:

4.4 Individual Security, Freedom of Movement and Restrictions

{{org_field_name}} recognises that individuals living at the service retain their rights to autonomy, independence and freedom of movement. Living in a care home does not, in itself, remove an individual’s right to enter or leave the premises.

Security arrangements must therefore balance the requirement to protect individuals from avoidable harm with their legal rights, wishes, independence and personal outcomes.

The following requirements apply:

The Registered Manager must ensure that restrictive arrangements are kept under review and that restrictions are reduced or removed where they are no longer necessary or lawful.

4.5 CCTV, Monitoring and Surveillance

Where {{org_field_name}} uses CCTV or other surveillance technology, its use must be lawful, necessary, proportionate and consistent with individuals’ rights to privacy, dignity and confidentiality.

{{org_field_name}} will maintain a written CCTV and Surveillance Policy covering surveillance used by the service and the arrangements applicable where individuals, representatives, families, visitors or staff request or use surveillance equipment.

CCTV or surveillance will only be used for specified and legitimate purposes, such as protecting individuals, staff and visitors, preventing or investigating crime, protecting property or maintaining the security of the premises.

Where CCTV is used:

Where surveillance is proposed for the purpose of monitoring a particular individual, the service must consider the individual’s wishes and capacity to consent, the necessity and proportionality of the measure, less restrictive alternatives and whether any additional lawful authority is required.

Covert surveillance must not be routinely undertaken by {{org_field_name}}.

Intruder alarms, door alarms and other security-monitoring systems may be used where supported by the service’s security risk assessment. Where such equipment restricts or monitors an individual’s movement, the requirements of Section 4.4 must also be followed.

4.6 Managing Security Breaches and Unauthorised Access

Any actual or suspected unauthorised access, security breach, loss of security equipment, failure of an access-control system or other security incident must be responded to promptly and proportionately.

Staff must take the following actions:

  1. Protect individuals from immediate harm

Staff must assess the immediate risk and take reasonable action to protect individuals, staff and visitors without placing themselves or others at unnecessary risk.

  1. Obtain emergency assistance where required

The police or other emergency services must be contacted without delay where there is an immediate threat to life or safety, suspected criminal activity, violence, serious unauthorised entry or another emergency requiring their assistance.

  1. Inform management

The Registered Manager or senior person on duty must be informed promptly. Serious incidents must be escalated in accordance with the service’s management and on-call arrangements.

  1. Safeguarding

Where the incident raises a concern that an individual has experienced or is at risk of abuse, neglect or improper treatment, immediate safeguarding action must be taken in accordance with the Safeguarding Adults from Abuse and Improper Treatment Policy and the Wales Safeguarding Procedures.

  1. Preserve evidence

Staff must take reasonable steps to preserve relevant evidence, including CCTV recordings, access-control records, visitor records and other documentation, where required for a safeguarding enquiry, police investigation, regulatory investigation or internal investigation.

  1. Record the incident

A contemporaneous incident record must be completed containing sufficient detail to establish:

  1. the date, time and location of the incident;
  2. persons involved;
  3. what occurred;
  4. immediate risks identified;
  5. action taken to protect individuals;
  6. persons or agencies contacted;
  7. whether the police were contacted;
  8. whether safeguarding procedures were initiated;
  9. whether CIW notification was required and made; and
  10. any actions identified to prevent recurrence.
  11. Notify CIW and other authorities where required

The Registered Manager and service provider must ensure that statutory notifications are made in accordance with Regulation 60 and Schedule 3 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.

This includes notifying CIW, without delay and in the required form, where the incident:

  1. has been reported to the police;
  2. involves abuse or an allegation of abuse requiring notification under Schedule 3;
  3. results in a serious accident or injury meeting the notification requirements;
  4. prevents, or could prevent, the provider from continuing to provide the service safely; or
  5. otherwise falls within an event specified in Schedule 3.

Other notifications, referrals or reports must be made to the local authority safeguarding team, police, placing authority or other body where required by legislation or safeguarding procedures.

  1. Review and learning

Following a security incident, the Registered Manager must review the circumstances, identify contributory factors and determine whether changes are required to risk assessments, access-control arrangements, staffing, equipment, training, personal plans or policies and procedures.

Actions identified following the review must be recorded and monitored to completion.

4.7 Key Management and Security Codes

To prevent unauthorised access to restricted areas:

4.8 Contractor and External Service Provider Access

All contractors and service providers must adhere to strict security procedures, including:

4.9 Staff Training and Competence

Staff whose duties include building security, access control, visitor management or the operation of security systems must receive information, instruction and training appropriate to their role.

Training and competency arrangements must include, where relevant:

Staff competence and understanding must be monitored through supervision, observation, incident review and other appropriate governance arrangements.

Additional or refresher training must be provided when legislation, statutory guidance, equipment, security arrangements or identified risks change.

5. Safeguarding and Access Control

Maintaining strict access control is crucial in safeguarding vulnerable residents. Staff must be vigilant and report any concerns related to:

All concerns must be reported to the Safeguarding Lead, {{org_field_safeguarding_lead_name}}, and handled according to the Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13).

6. Related Policies

This policy must be read in conjunction with the following policies and procedures, where applicable:

7. Policy Review

This policy will be reviewed annually or sooner if legislative changes, security incidents, or operational needs require updates. Staff will receive regular updates and training to ensure continued compliance.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *