contractscomplianceoperations

Subcontracting Security Work: Risks and Controls

CGuardPro

Every contract security company eventually faces the same call. A client wants coverage in a city where you have no officers, or wants a specialized service you do not provide, or needs a hundred hours next weekend for an event and you cannot staff it. Subcontracting security work is the obvious answer, and it is frequently the right one. It is also the fastest way to inherit somebody else’s licensing problem, somebody else’s insurance gap and somebody else’s uniform standards while your name stays on the invoice.

This is general orientation, not legal or insurance advice. Whether and how a licensed security company may subcontract, what registrations the subcontractor and its officers must hold, how liability is allocated, and what your own client contract permits are all governed by state law, by the terms of your agreements, and by your insurance policies — all of which vary and change. In Texas, the Texas Department of Licensing and Regulation (TDLR) is the regulator to verify licensing questions with. Confirm everything specific with your regulator, your broker and counsel.

The client bought you, not them

Start with the commercial reality, because it explains every control that follows. Your client signed a contract with your company. They evaluated your references, your insurance, your training program and your management. When a subcontractor’s officer sleeps at the post, the client does not experience that as a subcontractor problem. They experience it as your company failing, and they are contractually correct to do so.

That means the standard you have to hold a subcontractor to is not “adequate.” It is “indistinguishable from us.” Anything less and you are selling a product you cannot control while carrying the full reputational and contractual downside.

The first control, then, is upstream and costs nothing: read your own client contract before you agree to anything. Most well-drafted contract security agreements say something about subcontracting, and what they say is usually one of three things. Some prohibit it outright. Some permit it with prior written consent. Some are silent, which is not the same as permission and should be treated as a question rather than an opening. There may also be a flow-down clause requiring that any subcontractor be bound to the same terms you are — insurance limits, background screening standards, confidentiality, indemnity, audit rights.

If consent is required, get it in writing, in advance. A client who discovers a subcontractor on their site by reading a uniform patch is a client who now believes you hid something.

Licensing exposure travels in both directions

The licensing question in subcontracting is not one question but three, and operators routinely answer only the first.

Is the subcontractor licensed to provide contract security in the jurisdiction where the work is performed? Verify this directly with the regulator, not by accepting a photocopy. License numbers can be looked up. A certificate emailed to you proves only that someone owns a scanner.

Are the individual officers properly registered? Depending on the state, individual officers may need their own registration, and armed work may require a separate endorsement. Your subcontractor’s assurance that “all our people are licensed” is not evidence. Ask for the officer-level detail for the specific officers assigned to your account, and re-ask it when they rotate people in.

Does your own license permit the arrangement, and does it extend to work performed in another jurisdiction? Some states regulate the act of providing security services within their borders regardless of where the provider is based. If you contract to deliver coverage in a state where you are not licensed and satisfy it entirely through a licensed local firm, whether that is permissible is a real question, not a formality. Ask before you sign, because the answer varies and getting it wrong can be a licensing matter for you rather than for them.

The record you want to be able to produce, on demand, for any subcontracted post: which company, which license, which officers, which credentials, which dates. If assembling that takes more than a few minutes, you do not actually have the control you think you have.

Operations dashboard showing live coverage across client sites and the current status of every post

Insurance is the control most often faked

A certificate of insurance is a summary of coverage that existed on the day it was issued. It is not the policy, it is not a guarantee, and it does not obligate anyone to tell you when the coverage lapses. Treat it accordingly.

Work through this with your broker rather than from a template, but the shape of the diligence is consistent: confirm the coverage types you require are actually in place; confirm that the limits and terms meet what your client contract obligates you to maintain, because flow-down means your subcontractor’s shortfall becomes your breach; confirm additional insured status where your agreement calls for it and understand what that status does and does not do; understand whether the policy responds on a claims-made or occurrence basis and what that implies after the engagement ends; and confirm whether your subcontractor’s coverage is primary and non-contributory relative to yours, because otherwise your policy may end up doing work you did not expect.

Then set a diary date. Certificates expire. The most dangerous certificate in your file is the one issued eighteen months ago for a subcontractor still working your account today.

Two additional pieces belong in this conversation. Workers’ compensation for the subcontractor’s officers, because an injured officer with no coverage behind them will look for a deeper pocket. And indemnity — who defends whom, for what, and whether the obligation survives termination. Have counsel draft it. Indemnity language borrowed from an unrelated industry is a common and expensive mistake.

Service standards have to be specified, not assumed

Licensing and insurance protect you from catastrophe. Service standards are what keep the client. Write them down and make them contractual, because “professional appearance” means nothing when the officer shows up in a polo shirt.

The specifics worth naming: uniform standard and whose uniform is worn; grooming and appearance; equipment carried and what is prohibited; training required before an officer works the post, including your client’s site-specific orientation; post orders — yours, not a generic set; reporting format and cadence; supervision, meaning who does the field checks and how often; escalation and after-hours contact; background screening standards matching your own; and confidentiality covering client information the officers will inevitably see.

Add the one clause operators forget: no further subcontracting without your written consent. A chain of subcontractors is a chain of unverified licenses.

Visibility is the control that actually works

Contractual language is retrospective. It tells you who pays after something goes wrong. What you actually want is to know, tonight, that the post is covered and the officer is doing the work — the same thing you want from your own officers, and harder to get from a company that does not report to you.

The practical answer is to insist that subcontracted posts run inside your operational visibility rather than beside it. If the subcontractor’s officers use your guard tour system, scanning the same checkpoints on the same route, you know the property was covered without taking anyone’s word for it. If they file daily activity reports in your format, the client receives one consistent record regardless of who employed the officer that night. If their check-in and check-out is captured the same way yours is, billing reconciles against something real.

Guard mobile app home screen showing the officer's current shift and available actions on post

There is a negotiation here — some subcontractors will resist running on your tooling. That resistance is information. A firm confident in its service delivery rarely objects to the client seeing what it does. A firm that objects strenuously is telling you something about what the coverage will look like at 3 a.m.

Where the arrangement is long-term and the client is sophisticated, giving them one client portal that shows all their coverage regardless of which company staffed it is usually better than pretending the subcontractor does not exist. Sophisticated clients find out anyway. Being the one who told them is a much stronger position.

When not to subcontract

Sometimes the honest answer is no. If the account is your flagship reference, if the site carries genuine risk, if the client’s tolerance for variation is low, or if you cannot verify the subcontractor’s licensing and insurance to your own satisfaction, subcontracting converts a good relationship into an uncontrolled one. Declining a piece of scope and keeping the core account is a legitimate business decision, and clients respect it more often than owners expect.

If you want to see how tours, reports and coverage visibility can be run consistently across every post you are responsible for, explore CGuardPro or get in touch.

Run the whole operation in one place

Shifts, attendance, patrols, incident logs and clients on one platform — with the guard app on site and the client portal on the other side.

  • Attendance with selfie and GPS
  • QR patrols and a digital logbook
  • Client portal included

Keep reading