Questions to ask before commissioning a security audit
Ask the right questions before hiring a security auditor. Learn what good answers sound like and which responses signal genuine expertise versus a generic checklist.
A security audit looks straightforward from the outside: you hire someone, they inspect your property, they hand you a report. But the auditor you choose and the questions you ask during the vetting process will shape whether you get genuine insight or an expensive tick-box exercise. The real skill is knowing what to listen for—and what to watch out for—when you're interviewing potential auditors.
What experience do you have with properties like mine?
This is your opening question, and it matters because security challenges differ sharply by context. A retail business in a shopping centre faces different risks than a warehouse, a home office, or a medical practice. A good auditor will name specific types of properties they've worked on, describe the kinds of vulnerabilities they typically find in that setting, and ask you clarifying questions about your layout, hours of operation, and who has access. They might say, "We've audited twelve small retail spaces in the past two years, and in nine of them we found the back-door locks weren't adequate for the inventory value. Can you walk me through your back-of-house?"
An evasive answer sounds like, "We audit everything," or "Security is security"—which usually means they'll apply a generic checklist rather than think about what actually threatens you.
Will you give me a breakdown of what you'll assess?
A credible auditor will walk you through their methodology before you commit. They might cover physical access points, lighting, alarm system functionality, staff protocols, inventory controls, or CCTV placement—depending on your property and risk profile. They should explain why each area matters to you specifically, not rattle off a one-size-fits-all list. Ask them to tell you what they *won't* assess, too. Some auditors exclude IT security or access-control systems; others won't touch compliance audits. Knowing the boundaries stops you paying for a report that misses critical gaps.
If an auditor is vague or says "I'll see what's needed when I arrive," that's a red flag. You deserve to know the scope upfront.
How do you stay independent?
This question cuts to the heart of whether you'll get honest advice. An auditor who sells security products or works for a security company may unconsciously favour solutions from their own catalogue. Ask directly: Do you recommend specific brands or products? Who funds your business—is it audit fees, or do you earn commission on recommendations? Will your report suggest solutions from multiple suppliers, or only ones you provide? A truly independent auditor will disclose their financial model and explain how they avoid bias. They might say, "We recommend three different CCTV options and name the retailers who stock them; you choose who to buy from."
Evasion here—"We always recommend what's best for the client" without explaining how they stay impartial—suggests you should ask harder questions or seek a second opinion.
What happens after the report?
Your audit is useful only if you understand and act on it. Ask: Will you explain the findings in a follow-up meeting or call? Will you prioritise the recommendations—which are urgent, which are nice-to-have? Will you help me understand why each recommendation matters? Some auditors deliver a dense document and disappear; others spend time walking you through it and even help you find vendors for remedial work. Neither approach is wrong, but knowing what you'll receive helps you budget your own time and decide if you need post-audit support.
- Does the auditor offer follow-up calls to explain the report?
- Will they prioritise recommendations by risk and cost?
- Do they help with vendor recommendations or implementation advice?
What qualifications and references do you have?
Ask the auditor about their professional background, relevant certifications, and insurance. Request contact details for three recent clients in your sector and actually call them. Ask those references: Did the auditor deliver on time? Was the report useful? Did they explain things clearly? Were there any surprises in the findings, or did everything make sense? This step takes effort, but it's the closest thing to a guarantee that you're hiring someone competent.
A security audit is an investment in seeing your vulnerabilities clearly. The auditors you interview now will shape how well you understand the risks you actually face. When you're ready to commission, platforms like Strove let you find verified local auditors, read their reviews, and compare their approaches before you make the call.
Common questions
- How do I know if an auditor is truly independent?
- Ask directly whether they sell security products or work for a security company, and whether they earn commission on recommendations. An independent auditor will disclose their funding model and explain how they avoid bias—for example, by suggesting solutions from multiple suppliers rather than only their own. Get specific details about who pays them and how they structure their work before you commit.
- What should I do if the auditor's report is hard to understand?
- A good auditor will offer a follow-up meeting or call to walk you through the findings. If yours doesn't, ask for one anyway. You're paying for insight, not jargon. A competent auditor should be able to explain why each recommendation matters to your specific situation and help you prioritise what to tackle first.
- Is it worth checking references from previous clients?
- Yes. Contact three recent clients in your sector and ask whether the auditor delivered on time, explained findings clearly, and gave useful recommendations. This step takes effort but reveals more about an auditor's real-world performance than any credential on a website.
- What if an auditor says they'll assess everything from IT to physical security?
- Be cautious. Most auditors specialise in one or two areas. Ask exactly what they will and won't cover, and why. If your audit needs to include IT security as well as physical access, you may need two different specialists rather than one generalist offering a watered-down review of both.
Find a verified provider on Strove
Compare vetted security audits providers, check their credentials, and book or request a quote — all in one place.
Find a Business