GUARDIANINTEGRATED SECURITY & INTELLIGENCE
← All insightsGUARDIAN INSIGHTS

Physical Security Assessment vs. Security Audit: What Is the Difference?

Compare physical security assessments and security audits, including scope, deliverables, timing, and how Manhattan property teams can choose the right review.

By Guardian ISIUpdated 9 min read
Property manager and security consultant evaluating visitor access and turnstiles in a Manhattan office lobby.

The terms physical security assessment and security audit are often used interchangeably. In practice, they usually answer different questions.

A physical security assessment asks, “What could happen here, where are we vulnerable, and what should we improve?” A security audit asks, “Are our current controls operating as required by an established policy, contract, or other defined benchmark?”

The distinction matters for Manhattan property owners, managers, tenants, and construction teams. Choosing the wrong type of review can produce a report that is technically sound but does not address the decision you need to make.

Physical security assessment vs. security audit at a glance

AreaPhysical security assessmentSecurity audit
Primary purposeIdentify threats, vulnerabilities, and practical improvementsTest existing controls against defined criteria
Typical approachSite observation, interviews, risk analysis, and system reviewEvidence sampling, documentation review, interviews, and control testing
Starting pointThe property’s risks, operations, and environmentA policy, procedure, contract, standard, or approved security plan
Typical outputPrioritized findings and risk-reduction recommendationsFindings showing conformance, partial conformance, or gaps
Best used whenConditions have changed or the property needs a security strategyManagement needs assurance that required controls are being followed

These are working distinctions rather than universal definitions. Providers may label their services differently, so decision-makers should compare the proposed scope, methodology, and deliverables—not just the name of the service.

What is a physical security assessment?

A physical security assessment is a structured review of how well a property protects people, operations, information, and physical assets. It considers both the security measures already in place and the conditions that could allow an incident to occur.

What an assessment may examine

Depending on the property and assignment, the review may cover:

  • Public, tenant, employee, and vendor entrances
  • Lobby operations and visitor management
  • Doors, locks, gates, turnstiles, and key control
  • Access control and video surveillance coverage
  • Loading docks, service corridors, mailrooms, and package areas
  • Stairwells, roofs, garages, mechanical spaces, and restricted floors
  • Lighting, landscaping, sightlines, and perimeter conditions
  • Guard post orders, staffing patterns, patrols, and incident escalation
  • Deliveries, contractors, after-hours access, and special events
  • Emergency communications and coordination responsibilities

The reviewer should also consider how the property actually operates. A control that appears effective on a floor plan may be impractical during the morning rush, a large delivery, tenant move-in, or overnight shift.

What the finished assessment should provide

A useful assessment does more than list deficiencies. It should explain the significance of each finding and organize recommendations by priority, feasibility, and expected risk reduction.

Recommendations might include revising lobby procedures, improving credential management, adjusting camera placement, securing a service entrance, updating post orders, or changing the deployment of security guards. The goal is not automatically to add personnel or technology; it is to develop a proportionate combination of people, procedures, and systems.

What is a security audit?

A security audit evaluates whether specified security controls exist and are functioning as expected. Unlike a broad assessment, an audit needs defined criteria.

Those criteria might come from:

  • The property’s approved security plan
  • Company policies and standard operating procedures
  • Lease or client requirements
  • Guard-service post orders
  • Vendor responsibilities or service-level expectations
  • Insurer recommendations
  • A recognized framework selected by the organization
Security consultant and building manager reviewing access controls and a floor plan near an office entrance.
Security consultant and building manager reviewing access controls and a floor plan near an office entrance.

For example, if policy requires management to review active access credentials every quarter, an auditor may examine records to determine whether those reviews occurred. If post orders require documented patrols at specified intervals, the audit may sample activity logs and compare them with the requirement.

An audit can identify whether a process was followed, but it does not automatically prove that the process is sufficient for the building’s current risks. That broader question is usually better addressed through an assessment.

A security audit is not automatically a compliance certification

Calling a review an “audit” does not make it a government inspection, legal opinion, or formal certification. If the objective involves a law, code, insurance obligation, or contractual requirement, the scope should identify the exact criteria and the qualifications of the reviewer.

Fire and life-safety responsibilities should also be handled as a distinct workstream when appropriate. They may intersect with security operations, but they involve different plans, roles, and technical considerations. Properties needing operational personnel can separately review fire guard services and fire and life safety director coverage.

Which review does your property need?

Choose a physical security assessment when:

  • You are opening, acquiring, renovating, or repositioning a property.
  • Building use, occupancy, neighborhood conditions, or operating hours have changed.
  • A recent incident exposed a possible vulnerability.
  • Management is planning a security budget or technology upgrade.
  • Tenants or employees have raised concerns that require a broader review.
  • You need to compare risks across entrances, shifts, or multiple properties.

A Manhattan office property, for example, may need an assessment before redesigning its lobby. The review can examine how proposed turnstiles, visitor registration, delivery routing, and guard positions will work together. This is especially important where several tenants, public-facing businesses, and service vendors share the building. Guardian also supports properties evaluating broader commercial office security needs.

Choose a security audit when:

  • Leadership wants to verify that approved procedures are being followed.
  • A client, tenant, insurer, or contract calls for documented control testing.
  • Management wants to check vendor performance against post orders.
  • A prior assessment produced corrective actions that now need verification.
  • Policies are consistent across several sites, but execution may differ.

Use both when assurance and strategy are needed

Many properties benefit from a combined approach. An assessment can determine whether the security strategy fits the current risk environment. An audit can then verify whether the approved measures are consistently implemented.

The sequence can also work in reverse. An audit may reveal repeated procedural failures, leading management to commission an assessment to determine whether staffing, technology, training, or an unrealistic policy is the underlying problem.

How to scope the engagement

Before selecting a provider, define the decision the report needs to support. A clear request should address the following points.

Property boundaries and operating periods

Specify whether the review includes tenant floors, retail areas, loading docks, garages, rooftops, construction zones, or adjacent public space. Note whether nighttime, weekend, or shift-change observations are necessary.

Threats and concerns

Identify known issues without prescribing the conclusion. These could include unauthorized access, workplace violence concerns, theft, vandalism, package handling, protests, executive visits, vacant space, or contractor control.

Evaluation criteria

For an audit, provide the policies, post orders, contracts, or other benchmarks to be tested. For an assessment, agree on a risk-rating method and the assumptions that will shape prioritization.

Security professional and facilities manager inspecting an after-hours loading dock and secured service entrance.
Security professional and facilities manager inspecting an after-hours loading dock and secured service entrance.

Evidence and access

Determine which records may be reviewed, such as incident reports, access-control data, visitor records, patrol logs, staffing schedules, and maintenance histories. Sensitive records should be handled according to the organization’s privacy and information-security practices.

Deliverables

Ask whether the final report will include:

  • An executive summary for ownership or senior management
  • A description of the methodology and limitations
  • Site-specific observations supported by evidence
  • Prioritized recommendations
  • Immediate, near-term, and capital-planning options
  • Responsible parties and suggested follow-up dates
  • A confidential technical appendix, if needed

Common mistakes to avoid

Buying technology before defining the problem

More cameras, alarms, or access-control devices do not necessarily resolve unclear procedures or weak accountability. Start with the risk and operational objective, then select the appropriate control.

Reviewing only the daytime operation

Conditions can differ significantly after business hours. An assessment may need to observe overnight access, deliveries, cleaning crews, construction work, or the process for securing secondary entrances.

Treating every finding as equally urgent

A long checklist without priorities makes budgeting difficult. Findings should be evaluated in context, including potential consequences, likelihood, existing safeguards, and implementation constraints.

Ignoring follow-through

Assign each accepted recommendation to an owner and target date. After changes are made, a focused audit or validation visit can confirm that the new control is operating as intended.

Planning the next step for a New York City property

If the central question is whether your property’s security strategy matches its current risks, begin with a physical security assessment. If you need evidence that established controls are being followed, request a security audit with clearly defined criteria. If both questions matter, scope a phased engagement that evaluates design first and execution second.

Guardian ISI can help Manhattan property teams review site conditions, clarify operational priorities, and plan appropriate security coverage. For urgent staffing needs, see emergency security coverage.

Call or text Guardian ISI at [(212) 602-1695](tel:+12126021695), or [request coverage online](/contact).

Frequently asked questions

Is a physical security assessment the same as a risk assessment?

They often overlap. A physical security assessment typically identifies threats, vulnerabilities, potential consequences, and safeguards at a site. “Risk assessment” can be broader and may include cyber, financial, operational, or other risks, so the proposed scope should be confirmed.

Does a security audit require a formal standard?

An audit requires defined evaluation criteria, but those criteria do not have to come from a public standard. They may come from internal policies, post orders, contracts, an approved security plan, or another benchmark selected by the organization.

How often should a property conduct a security assessment?

There is no single schedule for every property. A new assessment is worth considering after a serious incident, renovation, change in occupancy or operating hours, acquisition, major technology project, or material change in local conditions.

Can the same provider perform the assessment and audit?

Yes, if the provider has the appropriate expertise and the organization is comfortable with the level of independence. When independent verification is important, management may choose a different reviewer for the follow-up audit.

Will an assessment tell us how many security guards we need?

It can help evaluate posts, schedules, duties, and coverage gaps. Staffing recommendations should be based on site risks, operating conditions, technology, procedures, and the responsibilities assigned to each post—not a generic guard-to-occupant ratio.

What should we prepare before a site review?

Helpful materials may include floor plans, incident records, access procedures, current post orders, staffing schedules, vendor lists, emergency contacts, and known concerns. The reviewer should identify which records are necessary and how sensitive information will be protected.