A physical security assessment template gives organisations a starting framework for evaluating their security arrangements. Done well, it ensures the assessment covers the right ground — threats, controls, vulnerabilities, and priorities — in a structured, repeatable way.
Done poorly, it produces a checklist that looks thorough but misses the site-specific analysis that makes an assessment genuinely useful.
This guide explains what a physical security assessment template should include, what distinguishes a well-structured assessment report from a generic checklist, and why the methodology behind the template matters as much as the template itself.
Why Template-Based Assessments Have Limitations
Before covering what a good template should include, it’s worth being direct about what a template cannot do.
A physical security assessment template provides structure — a consistent set of questions and categories to work through. What it can’t provide is the judgement required to apply those questions meaningfully to a specific site, threat environment, and organisational context.
Two sites can complete the same template and produce very different risk pictures — because the threat environment is different, because the existing controls perform differently in practice than they do on paper, and because the physical environment of each site creates different vulnerabilities. A template can prompt the right questions. It can’t answer them.
This is why independent security risk assessments consistently produce better outcomes than self-assessments using a template — not because the template is wrong, but because the expertise and objectivity of an independent assessor is what turns a structured framework into accurate, site-specific findings.
With that context, here’s what a quality physical security assessment template should include.
What a Physical Security Assessment Template Should Include
Site context and scope
Every assessment should start with a clear statement of what’s being assessed and why. Site context includes the type of facility, its hours of operation, the population of users and visitors, the surrounding environment, and the purpose of the assessment — whether it’s a governance requirement, a capital works decision, a DA condition, or a response to an incident.
Scope defines what the assessment covers — which buildings, which areas, which systems, and which time periods. A scope that’s too narrow misses significant risks. A scope that’s undefined produces findings that can’t be acted on efficiently.
Threat identification
A structured threat identification section documents the realistic threats relevant to the specific site — not a generic list of everything that could theoretically go wrong. For most WA organisations, this includes unauthorised access, theft, vandalism and antisocial behaviour, aggression toward staff, and after-hours intrusion. For higher-profile or critical infrastructure sites, the threat picture may extend to vehicle-borne threats and the broader threat environment relevant to the sector.
The threat identification section should be site-specific, not copied from a previous assessment. Different sites in different locations with different uses carry different threat profiles — and a template that doesn’t account for this produces the same findings regardless of the actual risk.
Current controls inventory
This section documents what’s currently in place — CCTV coverage and configuration, access control arrangements, lighting, perimeter treatments, alarm systems, patrol arrangements, and security procedures. The purpose isn’t just to list what exists — it’s to establish a baseline against which each control can be evaluated against the identified threats.
A common mistake is treating the existence of a control as evidence that the risk is managed. A CCTV camera that’s pointed at the wrong area, configured to produce footage at the wrong resolution, or not recording properly is not a functioning control — it’s security theatre. The template should prompt evaluation of whether each control is actually working, not just whether it exists.
For each identified threat, the template should prompt an evaluation of whether existing controls adequately address it — and where they don’t. This is the analytical core of the assessment and the element most often missing from self-completed templates.
Vulnerabilities might include access control credentials that haven’t been updated since staff turnover, CCTV coverage gaps in high-risk areas, lighting that meets standards during the day but fails after hours, patrol routes that haven’t been reviewed against current incident data, or procedures that exist on paper but aren’t understood by the staff who need to follow them.
Risk rating
A risk rating section applies a likelihood-consequence matrix to each identified threat — rating how likely the threat is to materialise and how serious the consequence would be if it did. This produces a risk register that prioritises findings rather than treating all issues as equally urgent.
The risk rating methodology should be aligned with ISO 31000:2018 — Risk Management: Guidelines. This is the recognised Australian and international standard for risk management, and alignment with it makes the assessment findings defensible when presented to boards, audit committees, insurers, and regulators.
A risk register without a structured methodology is an opinion list. A risk register aligned with ISO 31000:2018 is a governance document.
Findings and evidence
The findings section documents what the assessment identified, supported by photographic evidence of key issues. Good findings are specific — not “CCTV coverage is inadequate” but “Camera 3 at the southern carpark entry is positioned to cover the exit lane rather than the entry point, creating a blind spot at the highest-risk access point. Image resolution at this camera is insufficient for identification-quality footage under current lighting conditions.”
Specific, evidenced findings give decision-makers something to act on directly. Generic findings require another round of investigation before any action can be taken.
Prioritised recommendations
Based on the risk ratings and findings, the template should include a recommendations section that distinguishes between immediate actions, medium-term improvements, and longer-term strategic investments. Organisations working within constrained budgets need to know what to fix first — a list of recommendations without priority order is difficult to translate into an action plan.
Recommendations should be vendor-neutral — specifying performance outcomes rather than particular products or brands. “Install additional lighting in the southern carpark to achieve a minimum of 20 lux at ground level consistent with AS/NZS 1158” is a vendor-neutral recommendation that any qualified electrician or lighting designer can act on. “Install Brand X LED floodlights” is a specification that reflects a product preference, not a performance requirement.
Implementation and review
A complete assessment template includes guidance on how findings will be implemented — who is responsible, what the timeline is, and what resources are required — and how the assessment will be reviewed and updated over time. Security risk is not static, and an assessment that doesn’t include a review cycle becomes outdated as the threat environment, the site, and the organisation’s controls all change.
For most organisations, a full assessment every two to three years with an annual desktop review of the risk register is a reasonable baseline. For organisations with compliance obligations — critical infrastructure operators under the SOCI Act, healthcare facilities under AS 4485:2021, councils with ongoing governance requirements — the review cycle may be more frequent.
When a Template Is Enough — and When It Isn’t
A physical security assessment template is a useful tool for organisations conducting an initial self-assessment — to understand the scope of the task, identify obvious gaps, and prepare for an independent assessment.
It’s generally not sufficient when:
The assessment findings will be presented to a board, council committee, auditor, or regulator — where the methodology behind the findings needs to be independently credentialled and defensible.
A significant investment decision — capital works, a new guarding contract, a technology upgrade — is being made on the basis of the assessment.
The organisation has a compliance obligation that requires a formally documented, ISO 31000:2018-aligned assessment from a licensed independent consultant.
The site is complex — a multi-building campus, a regional or remote facility, a public-facing environment with a diverse user population — and the assessment requires site-specific expertise to produce accurate findings.
In each of these cases, an independent physical security assessment from a credentialled consultant produces findings that are more accurate, more specific, and more defensible than a self-completed template.
Engaging Smartsec for an Independent Physical Security Assessment in WA
Smartsec Security Solutions delivers independent physical security assessments for organisations across Perth and regional WA. Our assessments go well beyond what a template can produce — site-specific threat identification, ISO 31000:2018-aligned risk rating, photographic evidence, and prioritised, vendor-neutral recommendations structured for governance and compliance purposes.
We are a licensed WA Security Risk Consultant and Security Agent, holding the Security Risk Management Certified Professional (SRMCP) credential. We are a WALGA Preferred Supplier (PSP001-002 and PSP001-026) — WA councils can engage us directly without a separate procurement process.
Contact Smartsec Security Solutions to arrange a confidential scoping conversation.


