On 1 May 2026, a Statutory Instrument was quietly laid before Parliament that will, over time, change the culture of the UK private security industry. It gave the Security Industry Authority (SIA) "prescribed person" status under the Public Interest Disclosure Act 1998 (PIDA) — meaning that from now on, workers in the private security industry who raise concerns about wrongdoing directly with the SIA are protected in law from unfair treatment or dismissal if they do so.
It's a small legislative change with a large practical implication. For years, front-line officers, supervisors, back-office staff and industry professionals who noticed something wrong — unlicensed staff on a site, misrepresented vetting, contract fraud, avoidable safety risks — had no protected route to raise it directly with the regulator. That route now exists. Speaking up to the SIA is a protected disclosure. This is our take on what changed, what it means for the industry, and what it means for the clients who hire security firms across Sussex, Northamptonshire and the wider UK.
The Regulator Just Became
A Safe Place To Speak Up.
The SIA now holds prescribed person status under PIDA — giving UK private security workers direct, legally-protected whistleblowing rights when they raise concerns with the regulator.
Original news reporting by Mark Rowe at Professional Security Magazine. Official SIA guidance for workers is available on gov.uk/SIA. This article is general commentary, not legal advice.
What Actually Changed On 1 May 2026
PIDA is the piece of UK law that protects workers who "blow the whistle" on wrongdoing at work. It has been the backbone of UK whistleblower protection since 1998. To trigger the protection, though, the disclosure has to be made either to the worker's employer, or to a "prescribed person" — a defined regulator, professional body or government official who is legally recognised as the right person to receive that kind of concern.
Until May 2026, the SIA was not on that list for the private security industry. A frontline officer who saw something they believed to be wrong could raise it internally, could raise it with the police, or could take their concerns to a media outlet — but disclosing directly to the industry's own regulator did not, in itself, attract PIDA protection.
That gap has now closed. The Statutory Instrument laid on 1 May 2026 formally added the SIA to the list of prescribed persons. Disclosures made to the SIA about the private security industry are now protected in law, provided the worker reasonably believes the information tends to show one of the categories of wrongdoing PIDA recognises.
The SIA developed the change in consultation with, and with the support of, Protect, the long-established UK whistleblowing charity. It has also published its own whistleblowing guidance for workers explaining what prescribed person status means for them, and how to make a disclosure — anonymously or confidentially.
"The SIA cannot regulate an industry it can't see clearly. Prescribed person status is how the regulator finally gets the intelligence its rules were always supposed to be built on."
What Can Now Be Reported Under Protection
The categories of disclosure PIDA already recognises — criminal offences, breach of legal obligation, miscarriage of justice, danger to health and safety, damage to the environment, and deliberate concealment of any of the above — all now apply where the disclosure is made to the SIA about the private security industry. In the SIA's own framing, that includes:
Unlicensed security work
Anyone working in an SIA-licensable role in the UK without a valid licence is committing a criminal offence. The unlicensed door supervisor, the "helper" on a construction site working as a security officer, the informal after-hours cover on a commercial premises — all of these now sit inside the disclosure framework.
Suspected fraudulent activity
Vetting fraud, invoice fraud, contract fraud, misrepresentation of officer training or licences, or fraudulent use of accredited-contractor marks — categories that have long sat inside the informal underbelly of the industry, and are now formally reportable to the regulator with protection attached.
Other criminal offences
Any suspected criminality inside a security firm — theft, coercion, assault, drug offences, modern-slavery indicators in the workforce — can now be raised with the SIA directly under protection.
Non-compliance and public safety risks
Systemic non-compliance with SIA licensing conditions, deliberate breaches of BS 7499 or BS 7984 standards, safety issues on sites where security is deployed, and any other pattern of behaviour that puts the public at foreseeable risk.
The Anatomy Of A Protected Disclosure To The SIA
Understanding the sequence matters — for workers thinking about raising a concern, and for firms trying to run a business that never has one raised about it.
Observe
A worker sees or reasonably believes something wrong is happening — unlicensed staff, fraudulent vetting, licensing non-compliance, safety risk.
Disclose
The worker discloses directly to the SIA — using its published whistleblowing guidance and route, anonymously or confidentially if they choose.
Protect
Provided the reasonable-belief and public-interest tests are met, PIDA protections attach — the worker is legally protected from unfair treatment or dismissal.
Investigate
The SIA investigates the concern using its regulatory powers — audits, compliance reviews, licence checks and, where warranted, enforcement action.
Act
Regulatory action follows if warranted — licence revocations, criminal referrals, ACS status impacts, and public accountability for the firms involved.
Martyn's Law Will Follow
The SIA has confirmed that its prescribed person status will be extended to cover Martyn's Law — the Terrorism (Protection of Premises) Act 2025 — once that framework comes into force. Enforcement is expected any time after April 2027. Venues that fall inside the Standard or Enhanced tier of Martyn's Law can expect the same protected-disclosure route to open up alongside enforcement. It's a further reason for venues to get their public protection procedures documented, trained and tested well before the deadline bites.
Martyn's Law
Enforcement Date
What This Means For The Private Security Industry
For the professionally-run end of the UK private security industry — the SIA Approved Contractors, the BS 7858-vetted firms, the ACS Pacesetters — this change is welcome, overdue, and largely operationally invisible. Firms that already run a culture where staff can raise concerns internally, that already vet properly, that already comply with BS 7499 and BS 7984, that already publish their standards, don't have anything new to worry about. Nothing has changed for them except that the regulator now has a cleaner line of sight into the rest of the industry.
For the rest of it — the unlicensed cash-in-hand corners, the firms with more badges than officers, the sites where the "security" is a mate of the site manager and the paperwork isn't there to check — this is a meaningful change. Every worker in the private security industry now has a direct, legally-protected route to raise concerns with the regulator, without needing to go public and without needing to fear the door.
Over time — not overnight, but over time — that lifts the floor. It reduces the space in which the shadier end of the market operates. It gives clients confidence that the industry has a working accountability mechanism behind the licence they see on the front of the badge.
What This Means For Clients Hiring Security
If you're a construction site manager in Wellingborough, a school business manager in Chichester, a country-house owner in Petworth, a caravan park operator on the Sussex coast, a distribution centre director on the A14 corridor, a family office representative in London or a managing agent with a hundred blocks under management — this change should quietly reassure you. The industry you're buying from is now easier to regulate. The firms who don't run their businesses properly are now easier to expose. The compliance you already ask for on paper is now backed by a live, protected reporting line inside the industry itself.
It also raises the bar of what "due diligence" looks like when you hire security. A SIA licence has always been the floor, not the ceiling. In a post-May-2026 world, the meaningful questions to ask any security provider are more or less the same as before — but they now sit inside a stronger regulatory frame:
Are your officers SIA-licensed and BS 7858-vetted?
Are you an SIA Approved Contractor?
Do your staff have a documented, protected route to raise concerns internally?
Are you comfortable with your business being visible to the regulator?
Any provider that hesitates on the last one is telling you something.
Six Things A Well-Run Security Firm Already Does
The SIA's expanded whistleblowing status is a check on the industry, not a burden on it. Any firm running its business properly is already doing the following as a matter of course — and would welcome any of its staff raising concerns with the regulator if there were ever anything worth raising.
Open Internal Reporting
A documented, named route for any staff member to raise concerns internally — with the confidence they will be heard, taken seriously and never penalised.
SIA-Licensed & Vetted Officers
Every officer SIA-licensed and vetted to BS 7858 before they set foot on a site. No exceptions, no informal cover.
BS 7499 & BS 7984 Aligned
Static guarding, mobile patrolling, key holding and alarm response all aligned to the UK British Standards — with the audit trail to evidence it.
Director-Level Accountability
Every contract has a named director-level point of contact. If something is going wrong on a site, it lands at a level with the authority to fix it.
Transparent Client Relationships
Written contracts, defined SLAs, incident reporting the client actually sees, and no hidden line items. Discretion where clients need it — never opacity.
Regulator-Ready By Default
Nothing about the business that we wouldn't be comfortable explaining to the SIA on a Monday morning — because that's the standard we run against, not around.
Our Position On This Change
We welcome the SIA's new prescribed person status. It's a step the industry has needed for years, it draws a cleaner line between firms who run their businesses properly and firms who don't, and it strengthens the professional identity of the front-line officers who make up the actual workforce.
Any member of our team — officer, supervisor, dog handler, controller, back-office staff — has every right and every route to raise a concern about our business with the regulator, and would have our support in doing so. It is genuinely difficult to imagine the situation in which that would be necessary, because we've built the business the other way round: on the assumption that everything we do would be defensible to anyone who ever asked. But that door being open, from May 2026, is a good thing for the industry as a whole — and a good thing for every client who ever hires a UK security firm.
If you're commissioning security cover across Sussex or Northamptonshire — manned guarding, mobile patrols, key holding, event or construction cover — the industry's regulatory backbone just got a little stronger. That should quietly change how confident you feel about the professionally-run firms you deal with. It should very publicly change how the rest of the industry has to operate.
Hiring Security You Can Rely On, Openly.
If you'd like to talk about security cover across Sussex, Northamptonshire or the wider UK — with an SIA-licensed, ACS-vetted, BS 7499 / BS 7984-aligned provider — we'd welcome the conversation. Every contract sits on the same standard: nothing we do that we wouldn't be comfortable explaining to the regulator on a Monday morning.
Arrange A Conversation →