Physical security audit checklist for any facility
A physical security audit checklist covering perimeter, access control, cameras, alarms, interior and life safety, plus how to write findings that get funded.

A physical security audit is a walk with a clipboard and a grudge. You are looking for the gap the client has stopped seeing: the gate that stopped latching in spring, the camera aimed at a wall, the badge that still opens the server room.
Walk the perimeter, the access points, the cameras, the alarms, the interior, life safety and the procedures, in that order, using the same list every time. Test rather than observe: pull the door, ask for playback, check the extinguisher tag. Then write each finding as location, condition, consequence and fix, graded by risk.
An audit of a workplace is partly a life safety audit. Several items below are federal OSHA requirements, not best practice, and they go in the report even if the client only asked about theft.
How do you run the audit so the findings mean something?
- Walk it twice. Daylight shows fence condition and sightlines. Darkness shows which lights are out and which cameras relied on ambient light nobody costed.
- Test, do not observe. Pull the door instead of looking at the lock. Ask the client to play back yesterday afternoon instead of watching the live wall.
- Photograph as you go, and grade every finding. A photo ends the argument about whether the gap is a gap; an ungraded list of forty items gets none fixed.
For a new-contract proposal the emphasis shifts toward scope and staffing; the site security assessment checklist covers that. CISA also fields Protective Security Advisors who help critical infrastructure owners with vulnerability assessments at no cost.
What do you check on the perimeter?
The property line is the first thing an intruder deals with and the last thing anyone maintains. Walk the whole boundary, back corners included; what looks intact from the main entrance often is not.
Fencing and barriers
A distribution yard and a residential community need different answers here.
Perimeter lighting
Lighting degrades silently. Nobody reports a burned-out pole light, and a year later half the lot is dark. Assess this section after sunset only.
Landscaping
The landscaper and the security consultant have opposite goals. Mature planting is where concealment comes from.
How do you evaluate access control?
Audit the decisions about who goes where and the machinery that enforces them. A perfect reader on a door with a soft frame is a decorative reader.
Entry points
Electronic access control
The system is usually fine. The administration is not. Ask for the credential list and compare it against the current employee roster before you look at any hardware.
That last item is where security and life safety collide, so resolve it with the fire marshal rather than in the report. More in access control beyond badge readers.
Key control
Mechanical keys outlive the electronic systems installed to replace them, and a loose master key defeats everything above it.
With no written policy behind that list, attach the key control policy template to the finding.
Does the camera system actually do anything?
Cameras get installed once and audited never. Three failures recur: coverage that no longer matches the layout, silent recording failure, and footage nobody can retrieve.
Coverage
Functionality
Do this with the client next to you. Pick a random hour from two days ago and ask them to pull it up.
Retention length is a business decision: however long it takes the client to discover the loss they actually suffer, plus a margin. Video analytics for security covers the rest.
Is the alarm system real?
An alarm that false-activates gets ignored; an alarm nobody tests fails silently. Both end in the same place.
Detection coverage
System integrity
What needs protecting inside?
Layer interior protection by what a space contains: what a person could take, damage or reach from it.
Visitor handling fails most often, because it depends on a person at a desk making a judgment. A visitor management SOP is the usual remediation.
What does life safety add to a security audit?
The federal floor, which is not optional and not the client's opinion. Three OSHA standards drive most of what a walk turns up.
Under 29 CFR 1910.37, exit routes must be unobstructed, with nothing stored in them even temporarily, and sprinklers, alarms, fire doors and exit lighting must be in working order. Each exit needs an illuminated sign, and any doorway that could be mistaken for one has to be marked as not an exit.
Under 29 CFR 1910.157, portable extinguishers must be mounted, identified and accessible, kept charged and in their designated places, inspected visually every month, and given a dated annual maintenance check.
Under 29 CFR 1910.38, a required emergency action plan must be written, kept in the workplace, and cover reporting an emergency, evacuation and exit route assignments, who shuts down critical operations, how people are accounted for, what rescue and medical personnel do, and who to ask about the plan.
The client-facing version belongs on a wall, not in a binder: see the emergency response quick reference.
Which operational gaps do audits miss?
The ones that are nobody's equipment. Hardware gets replaced because someone can point at it; procedure rots quietly.
Test procedure by watching it under load. Standing in the lobby at shift change beats reading the policy, which is the logic behind a security post inspection.
How do you write findings that actually get funded?
"Improve perimeter security" buys nothing. A finding is four things, and it needs all four.
- Location, specific enough that a facilities tech can walk to it: "northeast fence line, 40 feet east of the maintenance gate."
- Condition, what you observed, with the photo attached.
- Consequence, what it lets somebody do. This is the sentence that gets the fix funded, and the one most reports leave out.
- Remediation, a specific fix with a rough cost if you can give one.
Then grade it, so the client knows what to do first.
| Priority | Target | Meaning |
|---|---|---|
| Critical | Immediate | Actively exploitable now, or a life safety violation |
| High | 30 days | Serious weakness that needs a funded plan |
| Medium | 90 days | Real gap, or a meaningful improvement |
| Low | When convenient | Minor issue or good practice |
Then book the re-walk. Findings never re-checked teach the client that audits are a document, not a process.
Key Takeaways
- Walk the site twice, once after dark. The two visits find different problems.
- Test rather than observe. Pull the door, request playback, check the extinguisher tag.
- Compare the access credential list against the current roster before you look at a reader.
- Blocked exits, inaccessible extinguishers and a missing action plan are OSHA violations, not preferences.
- Write findings as location, condition, consequence and fix, graded by risk. Consequence gets it funded.
Continue Reading

Site security assessment checklist: 101 points
A 101-point site security assessment checklist covering perimeter, access control, cameras, fire safety and operations, plus how to rank what you find.

Retail loss prevention strategies that work
What the NRF shrink numbers actually say, and the floor layout, exception reporting, officer training and outside partnerships that answer retail theft.

Security escalation matrix template: who to call
A security escalation matrix template with four severity levels, notification times, named backups and call sequences for medical, fire and active threat.