A security audit examines how people and vehicles enter a site, how checks work and where losses or unauthorised access could occur. The findings guide changes to guard duties, operating rules and security systems.
The Czech Ministry of the Interior's soft-target protection guidance provides a useful framework for assessing risk, but it does not prescribe a universal audit outcome. The scope, responsibilities and recommendations must be tailored to the specific site, operation and brief.
What is a physical security audit
A physical security audit examines site protection, people’s movement and working procedures. It assesses both equipment and how it is used.
- How physically secured are the entrances to the building.
- What is the condition of the fencing, lighting and perimeter.
- How the entry control of persons and vehicles takes place.
- How employees, visitors and suppliers move.
- Whether the staff actually follows established procedures.
- How technical security is set up (EZS, CCTV, access control) and whether it works.
The report ranks identified risks by severity and recommends corrective action. Each finding should show what needs attention now and what can wait.
How an audit typically takes place
Phase 1: briefing and preparation
Before visiting, we agree the audit scope with management. It may cover the whole site, recurring material losses or a suspected weakness at an entrance. The brief determines what we examine.
Phase 2: physical inspection of the facility
During the walkthrough, we inspect the agreed areas, entrances, fencing and indoor spaces. We record the condition of security measures and how staff follow procedures, then assess the findings.
Phase 3: process evaluation
We also review visitor reception, access approval for restricted areas, forgotten access cards and shift handovers. Unclear procedures can undermine otherwise functioning security equipment.
Phase 4: risk analysis and report
For each finding, we assess the likelihood of exploitation and potential loss. The report describes the problem and recommends action that can be scheduled.
How an audit creates a proposal for security arrangements
The findings inform staff positions, patrol routes and frequency, and use of security systems. The proposal also defines incident reporting and service checks.
1. Operations and risk window map
First, the rhythm of the site must be understood. When supplies arrive, when the last employees leave, when maintenance moves, when the site is at its weakest. Without time logic of operation, the security mode is poorly designed.
2. Division into critical points
The critical point may be the main entrance, a rear gate, a server room, a high-value storage area or reception. The audit identifies where a permanent presence is needed, where periodic checks are sufficient and where technology can provide monitoring.
3. Choice of service model
- Fixed security post: when continuous control of entry, visitors or vehicles is needed.
- Patrol-based service: when movement around the area and control of multiple points in time is critical.
- Reception or concierge service: when security fulfills an operational and communication role at the same time.
- Technological supervision: when it makes sense to support the service with CCTV, EPS, an intrusion alarm or an access-control system.
4. Reporting and escalation
Define what security staff record, who receives the reports and who handles incidents outside working hours. This gives the client an overview of the service and any events recorded.
Physical penetration test as part of an audit
At the customer's request, we can extend the audit with a physical penetration test. Our worker will try, with the knowledge of the management but without the knowledge of the staff, to pass into the forbidden zone by common methods: social engineering at the reception desk, following another employee through the door, exploiting inattention at the entrance.
The test shows whether staff follow the agreed procedures in the situations examined.
For whom the audit is most valuable
- Companies with valuable stock or technology: warehouses, production, logistics centers.
- Companies after a security incident: audit will help to understand how it happened and what to change systemically.
- Businesses before investing in security: before buying cameras, fencing or a new service, it's good to know what actually solves the problem.
What the final report contains
- Description of identified weaknesses without unnecessary technical jargon.
- Risk assessment of each finding.
- Specific recommendations for correction, both organizational and technical.
- Approximate cost of remediation if it can be estimated.
- Photo documentation of key findings.
Conclusion
An audit can help before changing security services, investing in equipment or after an incident. Match its scope to the site size and the problem you need to resolve.
When requesting a new guarding service, use the report to compare quotes. Providers can then base their proposals on the same findings.


