A security risk assessment gives commercial property owners and managers a structured way to identify vulnerabilities before they contribute to theft, unauthorized access, workplace incidents or operational disruption. In New York City, the review must account for dense pedestrian traffic, shared building systems, frequent deliveries, contractor access and changing tenant schedules.
The goal is not to eliminate every possible risk. It is to identify credible scenarios, evaluate existing safeguards and prioritize improvements according to their likely impact and feasibility. Use this checklist as a starting point, then adapt it to the property's occupancy, location and operating profile.
Important: This checklist is a security-planning resource, not a legal or code-compliance determination. Building, fire and staffing requirements vary by property. Consult the appropriate qualified professionals about obligations that apply to your site.
1. Define the Assessment Scope
Before walking the property, document what the review will cover. A narrow lobby inspection may miss risks involving loading areas, vacant floors, mechanical spaces or overnight operations.
- List every building entrance, exit and connecting passage.
- Include lobbies, tenant floors, roofs, setbacks, garages, loading docks and service corridors.
- Identify critical rooms, including electrical, telecom, security and building-management spaces.
- Record normal, after-hours, weekend and holiday operating conditions.
- Note tenant types, public-facing operations and regularly scheduled events.
- Include adjacent conditions that affect the property, such as transit entrances, scaffolding, construction or shared plazas.
- Assign an assessment lead and representatives from property management, engineering and security.
Assessors should review the property during more than one operating period when possible. A lobby that is orderly at 10 a.m. may function very differently during the morning rush, evening departures or overnight deliveries.
2. Review Incident and Operating Data
A risk assessment should be informed by actual experience rather than assumptions alone. Collect enough information to identify recurring locations, times and contributing conditions.
Records to examine
- Security incident and daily activity reports
- Lost access-card and credential records
- Visitor-management exceptions
- Alarm activations and response records
- Package theft, property damage and trespassing reports
- Relevant tenant complaints
- Maintenance records for doors, locks, cameras and intercoms
- Emergency drill observations and after-action notes
- Contractor, vendor and delivery schedules
Look for patterns. Several low-level incidents involving the same service entrance may indicate a process weakness even if no single event caused a major loss.
3. Assess the Building Perimeter
In Manhattan, the effective perimeter often begins at the property line or sidewalk rather than the lobby desk. Street activity, temporary construction and neighboring uses can change visibility and access conditions.
- Confirm that exterior doors close and latch reliably.
- Check doors and frames for damage, misalignment or signs of tampering.
- Evaluate lighting at entrances, setbacks, alleys and loading areas.
- Identify landscaping, structures or stored materials that block sightlines.
- Confirm that emergency exits are monitored without obstructing required egress.
- Inspect roof, terrace and adjoining-building access points.
- Review scaffolding and temporary work areas for new access opportunities.
- Determine whether exterior cameras capture usable views under daytime and nighttime conditions.
- Note locations where crowds or queues could obstruct entrances.
Document temporary conditions separately. A renovation, sidewalk shed or vacant retail space can materially change the property's exposure even when the permanent security design remains unchanged.
4. Evaluate Lobby and Access-Control Procedures
Technology is only one part of access control. The assessment should test how credentials, visitor approvals and exceptions are handled during real operating conditions.
Employees and tenants
- Determine whether credentials are issued to named individuals.
- Review procedures for lost, stolen and unreturned cards.
- Confirm that terminated or expired credentials are deactivated promptly under building policy.
- Observe whether tailgating occurs during busy periods.
- Check how guards respond when a credential fails.
- Review access permissions for restricted floors and areas.

Visitors, contractors and deliveries
- Confirm how tenant authorization is obtained and documented.
- Review identification and check-in procedures.
- Determine whether temporary credentials expire automatically or are collected.
- Separate routine visitors from contractors and service personnel where practical.
- Establish procedures for unexpected, denied or confrontational visitors.
- Confirm that delivery personnel use designated routes and destinations.
- Review food-delivery and courier procedures during peak periods.
The lobby team should have clear escalation options. Guards should not have to improvise when a tenant is unreachable, a visitor refuses to cooperate or an access-control system is unavailable. Properties that need dedicated personnel can review Guardian's commercial office security services and security guard coverage.
5. Inspect Interior and Restricted Areas
Once someone enters the property, interior controls should limit unauthorized movement and protect higher-consequence locations.
- Test access restrictions for tenant floors and vacant spaces.
- Inspect stairwell re-entry and floor-access conditions.
- Review elevator and destination-control permissions.
- Secure mailrooms, package rooms and storage areas.
- Limit access to mechanical, electrical, telecom and security rooms.
- Check parking and bicycle-storage areas.
- Review access between retail, office, residential or hotel components in mixed-use buildings.
- Identify doors that are routinely propped open.
- Verify that master keys and electronic override credentials are controlled and inventoried.
Avoid assessing a safeguard in isolation. For example, a locked mechanical room offers limited protection if keys are broadly distributed or the door is frequently left open for vendors.
6. Review Cameras, Alarms and Communications
A camera's presence does not mean it provides useful coverage. Evaluate whether systems support real-time response and post-incident review.
- Confirm that camera views match current risks and physical layouts.
- Check image quality under expected lighting conditions.
- Identify blind spots at entrances, elevator banks and loading areas.
- Confirm that camera clocks and recorded timestamps are accurate.
- Review who may view, export and retain footage under property policy.
- Test duress, intrusion and door-held-open alarms where applicable.
- Confirm who receives each alarm and what response is expected.
- Test radios, desk phones, intercoms and emergency contact methods.
- Provide a backup communication method for outages.
- Protect security equipment and network components from unauthorized access.
Privacy, labor and record-retention considerations can affect the use of surveillance systems. Property management should obtain appropriate advice when establishing monitoring and retention policies.
7. Examine Loading Dock and Vendor Controls
Loading areas combine vehicle access, valuable goods, temporary workers and interior service routes. They are often among a commercial building's most complex security zones.
- Maintain an expected-delivery or vendor schedule.
- Define procedures for unscheduled arrivals.
- Verify contractor identity and work authorization.
- Control access to freight elevators and service corridors.
- Determine whether vendors require escorts in restricted areas.
- Prevent unattended vehicles or packages from blocking operations.
- Record keys or credentials issued to contractors.
- Confirm their return or deactivation when work ends.
- Coordinate major deliveries with building operations and tenants.
- Keep dock and service-door procedures consistent across shifts.
Construction and renovation create additional access points, changing hazards and frequent subcontractor turnover. For occupied properties undergoing work, consider a separate construction security plan.
8. Coordinate Security With Fire-Life-Safety Planning
Security measures should support—not conflict with—emergency procedures and required egress. Locked doors, screening stations and lobby furniture should be reviewed with both everyday security and emergency movement in mind.
- Identify the building's current emergency plans and responsible personnel.
- Confirm that guards understand their assigned emergency duties.
- Maintain current emergency contacts and escalation paths.
- Review procedures for fire, medical emergencies, utility failures and severe weather.
- Plan for shelter-in-place, partial relocation or evacuation scenarios as appropriate.
- Ensure security controls do not obstruct required exits or emergency responders.
- Establish procedures for elevator, access-control or communications outages.
- Coordinate drills and document improvement items.
- Define how tenants and visitors will receive instructions.
Security guards and fire-life-safety personnel may have different qualifications and responsibilities. Do not treat the roles as interchangeable. Guardian can help properties evaluate staffing needs for fire-life-safety directors and other site-specific coverage, while property teams should confirm applicable requirements with qualified code and compliance professionals.

9. Evaluate Security Staffing
Staffing should reflect actual posts, operating hours and expected tasks—not simply a fixed headcount.
Questions for each post
- What risks is this post intended to control?
- What specific duties must be performed?
- When is the post most important?
- Can one person perform all assigned tasks during peak demand?
- Who covers breaks, callouts and emergencies?
- Does the officer have clear written post orders?
- What training, licenses or certifications are appropriate for the assignment?
- How are performance and incident documentation reviewed?
- Can the officer request supervisory or emergency assistance quickly?
Review whether reception, screening, patrol, loading-dock and control-room responsibilities compete with one another. A guard who must remain at the lobby desk cannot simultaneously investigate an alarm several floors away without leaving the entrance uncovered.
10. Rank Findings by Risk
Not every deficiency deserves the same urgency. Use a consistent method to prioritize corrective action.
| Factor | Question |
|---|---|
| Likelihood | How plausible is the scenario under current conditions? |
| Consequence | Could it affect people, operations, assets or reputation? |
| Exposure | How often are people or assets exposed to the condition? |
| Existing controls | Do current safeguards prevent, detect or delay the event? |
| Response capability | Could staff recognize and manage the incident promptly? |
A simple high, medium or low rating may be sufficient if the criteria are defined. Avoid false precision: the purpose of scoring is to support decisions, not to predict exactly when an incident will occur.
For each finding, assign:
- A responsible owner
- A target completion date
- An interim measure, if needed
- A verification step
- A status for management review
Quick operational corrections—such as updating a contact list or closing an obsolete credential—should not be delayed while larger capital projects are considered.
11. Test the Plan and Reassess Changes
An assessment is useful only if recommendations are implemented and tested. Conduct tabletop discussions, supervised system tests or drills appropriate to the property and scenario.
Revisit the assessment after meaningful changes, including:
- A serious incident or recurring pattern
- Major tenant turnover
- Lobby, façade or access-control renovations
- New public-facing amenities
- Changes to building hours or occupancy
- Construction or scaffolding
- Changes in guard posts or vendor operations
- A drill that exposes procedural gaps
Management should also set a routine review schedule based on the property's risk profile. The frequency should reflect actual operating conditions rather than an arbitrary calendar date.
Build a Practical Security Plan for Your NYC Property
Guardian ISI can help Manhattan owners and property managers evaluate guard posts, access procedures, coverage gaps and emergency staffing needs. We can also provide emergency security coverage when an urgent absence or changing property condition requires prompt support.
Call or text [(212) 602-1695](tel:2126021695) to discuss your building, or request coverage online. Be prepared to share the property address, requested hours, post duties, anticipated start date and any immediate concerns.
Frequently asked questions
How often should an NYC commercial building conduct a security risk assessment?
Use a schedule appropriate to the property's risk profile and reassess after significant incidents, renovations, tenant changes, construction, operating-hour changes or new access systems. Routine reviews should be supplemented by event-driven assessments.
Who should participate in the assessment?
Include property management, security leadership, engineering or facilities personnel and representatives familiar with tenant and loading operations. Specialized legal, code, fire-life-safety, technology or insurance advice may also be appropriate.
What is the difference between a security survey and a risk assessment?
A survey generally documents physical conditions and existing safeguards. A risk assessment goes further by considering credible scenarios, likelihood, consequences, control effectiveness and priorities for corrective action.
Should the assessment cover fire-life-safety procedures?
Yes, security and fire-life-safety planning should be coordinated so access controls, staffing and emergency procedures do not conflict. Applicable code and staffing determinations should be made with appropriately qualified professionals.
What information should a building provide to a security company?
Share the site's operating hours, entrances, post duties, incident concerns, tenant profile, delivery patterns, emergency procedures and required start date. Avoid sending sensitive access details through unsecured channels.

