{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Building Security and Access Control Policy
1. Purpose
The purpose of this policy is to establish clear arrangements for maintaining the security of {{org_field_name}} while ensuring that security measures respect the rights, privacy, dignity, autonomy and freedom of movement of individuals receiving care and support.
This policy supports compliance with:
- the Regulation and Inspection of Social Care (Wales) Act 2016;
- the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended;
- the Social Services and Well-being (Wales) Act 2014;
- the Mental Capacity Act 2005 and the Deprivation of Liberty Safeguards, where applicable;
- applicable data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018; and
- relevant statutory guidance and requirements issued by the Welsh Government and Care Inspectorate Wales (CIW).
{{org_field_name}} will maintain premises that are secure from unauthorised access while ensuring that security arrangements are proportionate to identified risks and do not unnecessarily restrict an individual’s freedom of movement, privacy, dignity, independence or ability to receive visitors.
Any restriction placed on an individual’s movement or access to and from the premises must be based on an individual assessment, be necessary and proportionate to the identified risk, be documented within the individual’s personal plan where appropriate, and have lawful authority where the restriction amounts to a deprivation of liberty.
This policy describes how {{org_field_name}} manages access to the premises, security measures, visitor arrangements, staff responsibilities, surveillance systems where used, and responses to security incidents or unauthorised access.
2. Scope
This policy applies to all residents, staff, agency workers, contractors, visitors, and emergency personnel entering or exiting {{org_field_name}}. It covers:
- Physical security measures to safeguard the premises.
- Controlled access for staff, residents, visitors, and contractors.
- Staff responsibilities in maintaining security.
- Procedures for managing security breaches and unauthorised access.
3. Principles of Building Security
{{org_field_name}} is committed to ensuring a safe, secure, and welcoming environment by following these key principles:
- Safety First: Residents’ security and well-being are the top priority.
- Controlled Access: Access is strictly monitored and regulated for all individuals entering the premises.
- Compliance with CIW Standards: Security measures meet or exceed regulatory requirements.
- Respect and Dignity: Security procedures balance safety with residents’ right to independence and personal choice.
- Continuous Monitoring: Security risks are regularly assessed, and improvements are made as necessary.
4. Security Measures and Access Control
4.1 Secure Entry and Exit Points
{{org_field_name}} will maintain appropriate arrangements to protect the premises from unauthorised access while ensuring that individuals receiving care and support are not unnecessarily restricted from entering or leaving the premises.
Security arrangements will be proportionate to the nature of the service, the risks associated with the premises and the assessed needs of individuals living at the service.
Measures include:
- Main entrance security: External entrance doors may be secured to prevent unauthorised access. Entry systems such as intercoms, electronic access controls or staff-controlled entry may be used where appropriate. These arrangements must not unlawfully prevent an individual living at the service from leaving the premises.
- Staff access: Keys, access cards, electronic fobs or security codes will only be provided to authorised staff where required for their role. Access credentials must not be shared with unauthorised persons.
- Emergency exits: Emergency escape routes and exits must be maintained in accordance with the service’s fire risk assessment and applicable fire safety arrangements. Security measures must not prevent safe evacuation in an emergency. Any alarm or monitoring arrangement associated with an emergency exit must be appropriate to the assessed risk and must not create an unlawful restriction on an individual’s freedom of movement.
- Individual security arrangements: Where an individual may be at risk if leaving the premises without support, an individual risk assessment must be completed and the least restrictive measures capable of managing the identified risk must be used. Relevant measures must be reflected in the individual’s personal plan.
- Restrictions on leaving the premises: A locked door, electronic access system, staff intervention, monitoring system or other security measure must not be used to prevent an individual from leaving unless the restriction is lawful, necessary and proportionate. Where the individual lacks capacity to consent to arrangements that restrict their liberty, the Mental Capacity Act 2005 and applicable deprivation of liberty requirements must be followed and lawful authority obtained where required.
Security arrangements will be reviewed whenever an individual’s needs, capacity, risks or legal authority change.
4.2 Visitor Management and Sign-In Procedures
{{org_field_name}} will operate proportionate visitor arrangements which protect individuals and the security of the premises while respecting individuals’ rights to maintain relationships, receive visitors and meet visitors in private.
The following arrangements apply:
- Signing in: Visitors will normally be required to follow the service’s sign-in and sign-out arrangements so that the service can maintain appropriate oversight of persons present on the premises.
- Identity and purpose: Staff may ask a visitor to confirm their identity and reason for attending where this is reasonably necessary to protect individuals or maintain the security of the service.
- Professional and contractor access: The identity and authority of professionals, contractors and other persons attending in an official capacity will be verified where appropriate before access to restricted areas is provided.
- Private visits: Individuals will be supported to receive family members, friends, representatives, advocates and other persons of their choosing and, where they wish, to meet them in private. Suitable arrangements will be made for private visits in accordance with the individual’s wishes and assessed needs.
- Supervision of visitors: Visitors will not routinely be required to remain under staff supervision. Supervision or restrictions will only be imposed where there is an identified and documented safeguarding, safety, security or legal reason for doing so, and any restriction must be necessary and proportionate to the identified risk.
- Restricted access: Visitors must not enter staff-only, medication, confidential records, plant, storage or other restricted areas unless appropriately authorised.
- Restrictions relating to a particular visitor: Where there are safeguarding concerns, court orders, an individual’s expressed wishes or another lawful reason for restricting a particular person’s access, the service will follow the relevant safeguarding, legal and risk-management procedures. Any restriction affecting the individual must be documented appropriately.
- Emergency services: Access by the emergency services must not be unnecessarily delayed by normal visitor identification or sign-in arrangements.
Visiting arrangements will not be applied in a way that unnecessarily interferes with an individual’s privacy, dignity, family relationships or personal autonomy.
4.3 Staff Responsibilities and Access Control
Staff members are responsible for maintaining security by:
- Ensuring all doors and security systems are properly secured after use.
- Challenging and reporting any suspicious or unauthorised individuals.
- Wearing ID badges at all times while on duty.
- Not sharing access codes, key cards, or security information with unauthorised individuals.
4.4 Individual Security, Freedom of Movement and Restrictions
{{org_field_name}} recognises that individuals living at the service retain their rights to autonomy, independence and freedom of movement. Living in a care home does not, in itself, remove an individual’s right to enter or leave the premises.
Security arrangements must therefore balance the requirement to protect individuals from avoidable harm with their legal rights, wishes, independence and personal outcomes.
The following requirements apply:
- Individuals who have capacity to make a decision about leaving the premises will be supported to exercise that choice. Staff may discuss identified risks and offer appropriate support, but an individual must not be prevented from leaving solely because staff consider their decision unwise.
- Relevant risks associated with an individual leaving the premises independently must be assessed and managed through person-centred risk assessment and care planning.
- Risk assessments must consider the individual’s wishes, capacity, communication needs, personal outcomes, previous history and the nature and likelihood of identified risks.
- Positive risk-taking and independence must be supported where appropriate and the least restrictive approach must always be considered.
- Where an individual wishes or requires staff support when leaving the premises, this must be recorded within the individual’s personal plan and appropriate staffing arrangements must be made.
- An individual must not be prevented from leaving the premises through locked doors, electronic access controls, physical intervention, continuous supervision or another restrictive measure unless the restriction is necessary, proportionate and lawful.
- Where there is reason to doubt an individual’s capacity to consent to arrangements restricting their movement, capacity must be considered in accordance with the Mental Capacity Act 2005. Capacity must be assessed in relation to the specific decision at the relevant time and must not be assumed solely because of a diagnosis, disability, age or behaviour.
- Where an individual lacks capacity to consent to arrangements necessary for their care and support, decisions must be made in accordance with the Mental Capacity Act 2005, including its best-interests and least-restrictive principles.
- Where the arrangements amount to a deprivation of liberty, lawful authority must be obtained through the applicable legal process. The service must comply with current deprivation of liberty legislation, statutory guidance and CIW requirements.
- Any authorised restrictions must be clearly recorded within the individual’s records and personal plan, communicated to relevant staff, implemented only to the extent authorised and reviewed whenever circumstances change.
- Requests and authorisations relating to Deprivation of Liberty Safeguards must be notified to CIW where required under Regulation 60 and Schedule 3 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.
The Registered Manager must ensure that restrictive arrangements are kept under review and that restrictions are reduced or removed where they are no longer necessary or lawful.
4.5 CCTV, Monitoring and Surveillance
Where {{org_field_name}} uses CCTV or other surveillance technology, its use must be lawful, necessary, proportionate and consistent with individuals’ rights to privacy, dignity and confidentiality.
{{org_field_name}} will maintain a written CCTV and Surveillance Policy covering surveillance used by the service and the arrangements applicable where individuals, representatives, families, visitors or staff request or use surveillance equipment.
CCTV or surveillance will only be used for specified and legitimate purposes, such as protecting individuals, staff and visitors, preventing or investigating crime, protecting property or maintaining the security of the premises.
Where CCTV is used:
- the purpose and necessity of surveillance must be established and kept under review;
- cameras must only cover areas necessary for the identified purpose;
- surveillance must not be used in areas where individuals would reasonably expect a particularly high level of privacy unless there is an exceptional, lawful and individually assessed justification;
- appropriate signage and privacy information must be provided;
- recordings must be processed in accordance with applicable data protection legislation;
- access to recordings must be restricted to authorised persons;
- recordings must be retained only for as long as necessary for the identified purpose or where preservation is required for an investigation or legal process;
- requests for disclosure or access to recordings must be handled in accordance with data protection legislation;
- recordings must be protected against unauthorised access, alteration, disclosure, loss or destruction; and
- surveillance arrangements must be reviewed where an individual’s privacy, dignity, capacity, safeguarding needs or personal plan may be affected.
Where surveillance is proposed for the purpose of monitoring a particular individual, the service must consider the individual’s wishes and capacity to consent, the necessity and proportionality of the measure, less restrictive alternatives and whether any additional lawful authority is required.
Covert surveillance must not be routinely undertaken by {{org_field_name}}.
Intruder alarms, door alarms and other security-monitoring systems may be used where supported by the service’s security risk assessment. Where such equipment restricts or monitors an individual’s movement, the requirements of Section 4.4 must also be followed.
4.6 Managing Security Breaches and Unauthorised Access
Any actual or suspected unauthorised access, security breach, loss of security equipment, failure of an access-control system or other security incident must be responded to promptly and proportionately.
Staff must take the following actions:
- Protect individuals from immediate harm
Staff must assess the immediate risk and take reasonable action to protect individuals, staff and visitors without placing themselves or others at unnecessary risk.
- Obtain emergency assistance where required
The police or other emergency services must be contacted without delay where there is an immediate threat to life or safety, suspected criminal activity, violence, serious unauthorised entry or another emergency requiring their assistance.
- Inform management
The Registered Manager or senior person on duty must be informed promptly. Serious incidents must be escalated in accordance with the service’s management and on-call arrangements.
- Safeguarding
Where the incident raises a concern that an individual has experienced or is at risk of abuse, neglect or improper treatment, immediate safeguarding action must be taken in accordance with the Safeguarding Adults from Abuse and Improper Treatment Policy and the Wales Safeguarding Procedures.
- Preserve evidence
Staff must take reasonable steps to preserve relevant evidence, including CCTV recordings, access-control records, visitor records and other documentation, where required for a safeguarding enquiry, police investigation, regulatory investigation or internal investigation.
- Record the incident
A contemporaneous incident record must be completed containing sufficient detail to establish:
- the date, time and location of the incident;
- persons involved;
- what occurred;
- immediate risks identified;
- action taken to protect individuals;
- persons or agencies contacted;
- whether the police were contacted;
- whether safeguarding procedures were initiated;
- whether CIW notification was required and made; and
- any actions identified to prevent recurrence.
- Notify CIW and other authorities where required
The Registered Manager and service provider must ensure that statutory notifications are made in accordance with Regulation 60 and Schedule 3 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.
This includes notifying CIW, without delay and in the required form, where the incident:
- has been reported to the police;
- involves abuse or an allegation of abuse requiring notification under Schedule 3;
- results in a serious accident or injury meeting the notification requirements;
- prevents, or could prevent, the provider from continuing to provide the service safely; or
- otherwise falls within an event specified in Schedule 3.
Other notifications, referrals or reports must be made to the local authority safeguarding team, police, placing authority or other body where required by legislation or safeguarding procedures.
- Review and learning
Following a security incident, the Registered Manager must review the circumstances, identify contributory factors and determine whether changes are required to risk assessments, access-control arrangements, staffing, equipment, training, personal plans or policies and procedures.
Actions identified following the review must be recorded and monitored to completion.
4.7 Key Management and Security Codes
To prevent unauthorised access to restricted areas:
- Keys and access cards are only issued to authorised personnel and must be returned when no longer required.
- Lost or stolen keys/cards must be reported immediately, and access codes must be changed if compromised.
- High-risk areas such as medication storage, financial offices, and confidential records rooms have restricted access.
4.8 Contractor and External Service Provider Access
All contractors and service providers must adhere to strict security procedures, including:
- Pre-arranged appointments for non-emergency work.
- Signing in upon arrival and being issued a temporary access pass.
- Being supervised by a designated staff member while on-site.
- Complying with the Health and Safety at Work Policy (CHW16) and security protocols.
4.9 Staff Training and Competence
Staff whose duties include building security, access control, visitor management or the operation of security systems must receive information, instruction and training appropriate to their role.
Training and competency arrangements must include, where relevant:
- procedures for controlling unauthorised access;
- visitor management and verification procedures;
- use of keys, access cards, keypads and electronic access systems;
- actions to take following a security breach or unauthorised access;
- safeguarding responsibilities and the action required where a security incident raises safeguarding concerns;
- emergency procedures and arrangements for contacting the emergency services;
- incident recording and escalation;
- statutory notification requirements relevant to security incidents;
- confidentiality and data protection requirements relating to visitor information, access-control data and CCTV recordings;
- the Mental Capacity Act 2005;
- lawful deprivation of liberty arrangements;
- the requirement to use the least restrictive approach;
- recognition that an individual must not be prevented from leaving solely because staff disagree with the individual’s decision; and
- the requirement to follow an individual’s personal plan and any lawful restrictions applicable to that individual.
Staff competence and understanding must be monitored through supervision, observation, incident review and other appropriate governance arrangements.
Additional or refresher training must be provided when legislation, statutory guidance, equipment, security arrangements or identified risks change.
5. Safeguarding and Access Control
Maintaining strict access control is crucial in safeguarding vulnerable residents. Staff must be vigilant and report any concerns related to:
- Unknown or unauthorised individuals attempting to gain entry.
- Residents being coerced or persuaded to leave with unauthorised individuals.
- Suspicious behaviour by visitors, contractors, or other personnel.
All concerns must be reported to the Safeguarding Lead, {{org_field_safeguarding_lead_name}}, and handled according to the Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13).
6. Related Policies
This policy must be read in conjunction with the following policies and procedures, where applicable:
- Safeguarding Adults from Abuse and Improper Treatment Policy (CHW13) – for preventing, identifying, reporting and responding to safeguarding concerns arising from security incidents, visitors or unauthorised persons.
- Health and Safety at Work Policy (CHW16) – for general health and safety arrangements, risk assessment and staff responsibilities.
- Risk Management and Assessment Policy (CHW18) – for assessing and managing environmental, individual and operational security risks.
- Emergency and Business Continuity Plan (CHW19) – for major security incidents, loss of access-control systems, damage to premises and other events affecting the safe operation of the service.
- Confidentiality and Data Protection Policy (CHW34) – for the lawful processing, storage, access, retention and disclosure of personal information, visitor records, access-control records and surveillance information.
- Use of CCTV and Surveillance Policy – for the lawful use of CCTV or other surveillance by the service and arrangements concerning surveillance used or requested by individuals, representatives, families, visitors or staff.
- Control, Restraint and Restrictive Practice Policy – for any practice or intervention that controls or restricts an individual’s movement, including restrictions associated with doors, exits or access-control arrangements.
- Mental Capacity and Deprivation of Liberty Safeguards Policy – for assessment of capacity, best-interests decision-making, lawful restrictions and obtaining and monitoring appropriate legal authority where care arrangements amount to a deprivation of liberty.
- Fire Safety Policy and Procedures – for the management of emergency exits, fire doors, evacuation arrangements and the interaction between fire safety and building-security systems.
7. Policy Review
This policy will be reviewed annually or sooner if legislative changes, security incidents, or operational needs require updates. Staff will receive regular updates and training to ensure continued compliance.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.