The terms physical security assessment and security audit are often used interchangeably. In practice, they usually answer different questions.
A physical security assessment asks, “What could happen here, where are we vulnerable, and what should we improve?” A security audit asks, “Are our current controls operating as required by an established policy, contract, or other defined benchmark?”
The distinction matters for Manhattan property owners, managers, tenants, and construction teams. Choosing the wrong type of review can produce a report that is technically sound but does not address the decision you need to make.
Physical security assessment vs. security audit at a glance
| Area | Physical security assessment | Security audit |
|---|---|---|
| Primary purpose | Identify threats, vulnerabilities, and practical improvements | Test existing controls against defined criteria |
| Typical approach | Site observation, interviews, risk analysis, and system review | Evidence sampling, documentation review, interviews, and control testing |
| Starting point | The property’s risks, operations, and environment | A policy, procedure, contract, standard, or approved security plan |
| Typical output | Prioritized findings and risk-reduction recommendations | Findings showing conformance, partial conformance, or gaps |
| Best used when | Conditions have changed or the property needs a security strategy | Management needs assurance that required controls are being followed |
These are working distinctions rather than universal definitions. Providers may label their services differently, so decision-makers should compare the proposed scope, methodology, and deliverables—not just the name of the service.
What is a physical security assessment?
A physical security assessment is a structured review of how well a property protects people, operations, information, and physical assets. It considers both the security measures already in place and the conditions that could allow an incident to occur.
What an assessment may examine
Depending on the property and assignment, the review may cover:
- Public, tenant, employee, and vendor entrances
- Lobby operations and visitor management
- Doors, locks, gates, turnstiles, and key control
- Access control and video surveillance coverage
- Loading docks, service corridors, mailrooms, and package areas
- Stairwells, roofs, garages, mechanical spaces, and restricted floors
- Lighting, landscaping, sightlines, and perimeter conditions
- Guard post orders, staffing patterns, patrols, and incident escalation
- Deliveries, contractors, after-hours access, and special events
- Emergency communications and coordination responsibilities
The reviewer should also consider how the property actually operates. A control that appears effective on a floor plan may be impractical during the morning rush, a large delivery, tenant move-in, or overnight shift.
What the finished assessment should provide
A useful assessment does more than list deficiencies. It should explain the significance of each finding and organize recommendations by priority, feasibility, and expected risk reduction.
Recommendations might include revising lobby procedures, improving credential management, adjusting camera placement, securing a service entrance, updating post orders, or changing the deployment of security guards. The goal is not automatically to add personnel or technology; it is to develop a proportionate combination of people, procedures, and systems.
What is a security audit?
A security audit evaluates whether specified security controls exist and are functioning as expected. Unlike a broad assessment, an audit needs defined criteria.
Those criteria might come from:
- The property’s approved security plan
- Company policies and standard operating procedures
- Lease or client requirements
- Guard-service post orders
- Vendor responsibilities or service-level expectations
- Insurer recommendations
- A recognized framework selected by the organization

For example, if policy requires management to review active access credentials every quarter, an auditor may examine records to determine whether those reviews occurred. If post orders require documented patrols at specified intervals, the audit may sample activity logs and compare them with the requirement.
An audit can identify whether a process was followed, but it does not automatically prove that the process is sufficient for the building’s current risks. That broader question is usually better addressed through an assessment.
A security audit is not automatically a compliance certification
Calling a review an “audit” does not make it a government inspection, legal opinion, or formal certification. If the objective involves a law, code, insurance obligation, or contractual requirement, the scope should identify the exact criteria and the qualifications of the reviewer.
Fire and life-safety responsibilities should also be handled as a distinct workstream when appropriate. They may intersect with security operations, but they involve different plans, roles, and technical considerations. Properties needing operational personnel can separately review fire guard services and fire and life safety director coverage.
Which review does your property need?
Choose a physical security assessment when:
- You are opening, acquiring, renovating, or repositioning a property.
- Building use, occupancy, neighborhood conditions, or operating hours have changed.
- A recent incident exposed a possible vulnerability.
- Management is planning a security budget or technology upgrade.
- Tenants or employees have raised concerns that require a broader review.
- You need to compare risks across entrances, shifts, or multiple properties.
A Manhattan office property, for example, may need an assessment before redesigning its lobby. The review can examine how proposed turnstiles, visitor registration, delivery routing, and guard positions will work together. This is especially important where several tenants, public-facing businesses, and service vendors share the building. Guardian also supports properties evaluating broader commercial office security needs.
Choose a security audit when:
- Leadership wants to verify that approved procedures are being followed.
- A client, tenant, insurer, or contract calls for documented control testing.
- Management wants to check vendor performance against post orders.
- A prior assessment produced corrective actions that now need verification.
- Policies are consistent across several sites, but execution may differ.
Use both when assurance and strategy are needed
Many properties benefit from a combined approach. An assessment can determine whether the security strategy fits the current risk environment. An audit can then verify whether the approved measures are consistently implemented.
The sequence can also work in reverse. An audit may reveal repeated procedural failures, leading management to commission an assessment to determine whether staffing, technology, training, or an unrealistic policy is the underlying problem.
How to scope the engagement
Before selecting a provider, define the decision the report needs to support. A clear request should address the following points.
Property boundaries and operating periods
Specify whether the review includes tenant floors, retail areas, loading docks, garages, rooftops, construction zones, or adjacent public space. Note whether nighttime, weekend, or shift-change observations are necessary.
Threats and concerns
Identify known issues without prescribing the conclusion. These could include unauthorized access, workplace violence concerns, theft, vandalism, package handling, protests, executive visits, vacant space, or contractor control.
Evaluation criteria
For an audit, provide the policies, post orders, contracts, or other benchmarks to be tested. For an assessment, agree on a risk-rating method and the assumptions that will shape prioritization.

Evidence and access
Determine which records may be reviewed, such as incident reports, access-control data, visitor records, patrol logs, staffing schedules, and maintenance histories. Sensitive records should be handled according to the organization’s privacy and information-security practices.
Deliverables
Ask whether the final report will include:
- An executive summary for ownership or senior management
- A description of the methodology and limitations
- Site-specific observations supported by evidence
- Prioritized recommendations
- Immediate, near-term, and capital-planning options
- Responsible parties and suggested follow-up dates
- A confidential technical appendix, if needed
Common mistakes to avoid
Buying technology before defining the problem
More cameras, alarms, or access-control devices do not necessarily resolve unclear procedures or weak accountability. Start with the risk and operational objective, then select the appropriate control.
Reviewing only the daytime operation
Conditions can differ significantly after business hours. An assessment may need to observe overnight access, deliveries, cleaning crews, construction work, or the process for securing secondary entrances.
Treating every finding as equally urgent
A long checklist without priorities makes budgeting difficult. Findings should be evaluated in context, including potential consequences, likelihood, existing safeguards, and implementation constraints.
Ignoring follow-through
Assign each accepted recommendation to an owner and target date. After changes are made, a focused audit or validation visit can confirm that the new control is operating as intended.
Planning the next step for a New York City property
If the central question is whether your property’s security strategy matches its current risks, begin with a physical security assessment. If you need evidence that established controls are being followed, request a security audit with clearly defined criteria. If both questions matter, scope a phased engagement that evaluates design first and execution second.
Guardian ISI can help Manhattan property teams review site conditions, clarify operational priorities, and plan appropriate security coverage. For urgent staffing needs, see emergency security coverage.
Call or text Guardian ISI at [(212) 602-1695](tel:+12126021695), or [request coverage online](/contact).
Frequently asked questions
Is a physical security assessment the same as a risk assessment?
They often overlap. A physical security assessment typically identifies threats, vulnerabilities, potential consequences, and safeguards at a site. “Risk assessment” can be broader and may include cyber, financial, operational, or other risks, so the proposed scope should be confirmed.
Does a security audit require a formal standard?
An audit requires defined evaluation criteria, but those criteria do not have to come from a public standard. They may come from internal policies, post orders, contracts, an approved security plan, or another benchmark selected by the organization.
How often should a property conduct a security assessment?
There is no single schedule for every property. A new assessment is worth considering after a serious incident, renovation, change in occupancy or operating hours, acquisition, major technology project, or material change in local conditions.
Can the same provider perform the assessment and audit?
Yes, if the provider has the appropriate expertise and the organization is comfortable with the level of independence. When independent verification is important, management may choose a different reviewer for the follow-up audit.
Will an assessment tell us how many security guards we need?
It can help evaluate posts, schedules, duties, and coverage gaps. Staffing recommendations should be based on site risks, operating conditions, technology, procedures, and the responsibilities assigned to each post—not a generic guard-to-occupant ratio.
What should we prepare before a site review?
Helpful materials may include floor plans, incident records, access procedures, current post orders, staffing schedules, vendor lists, emergency contacts, and known concerns. The reviewer should identify which records are necessary and how sensitive information will be protected.

