A working guide to the compliance side of security servicing in Australia: the AS/NZS 2201 framework and its system classes, what routine maintenance actually involves across alarms, CCTV and access control, what insurers and monitoring contracts expect, the licensing layer, and the records that turn service work into evidence.
Security systems are unusual among building services: no state mandates an annual “security statement” the way fire and essential safety measures are policed. The compliance pressure comes instead from three converging directions — the standards the system was specified against (AS/NZS 2201 for intruder alarms), the insurer whose policy assumed a working, monitored system of a stated grade, and the monitoring contract whose response chain only works if the field equipment does. When a burglary claim meets a dead backup battery and a service history that stops three years ago, the compliance question arrives retroactively — with money attached.
For contractors, the same logic that industrialised fire maintenance applies: specified standards plus insurer expectations plus equipment that degrades quietly equals recurring, evidence-producing service contracts.
AS/NZS 2201.1 (intruder alarm systems — client’s premises) is the backbone standard: it covers design, installation, commissioning and maintenance of intrusion systems, and grades them into five classes of ascending security — from basic residential configurations up to the high-security classes specified for banks, armouries and government facilities. The class determines detection coverage, tamper protection, signalling integrity and maintenance expectations; specifying (and maintaining) to the class the risk demands is the core professional discipline.
Around it sit the companions: AS 2201.2 for monitoring centres (the grading framework behind “Grade A1” monitoring — see the monitoring guide), signalling and equipment provisions within the series, and the adjacent standards for CCTV (AS 4806 series) and access control deployments. European-graded product (EN 50131, common on imported wireless systems) must be mapped against the Australian framework per project rather than assumed equivalent.
| System | Routine items | Typical rhythm |
|---|---|---|
| Intruder alarm | Walk test every detector; siren/strobe test; panel + comms test to monitoring; backup battery test/replace (batteries are the #1 failure); tamper checks; user list review | Annual (higher classes and monitored commercial: six-monthly) |
| CCTV | Camera image checks (focus, alignment, IR, obstruction); lens/housing cleaning; recorder health, storage days and clock sync; firmware currency; export test | Six-monthly to annual |
| Access control | Door hardware operation (locks, closers, REX, break-glass); reader function; controller battery; fail-safe/fail-secure verification; credential/user audit; firmware currency | Annual (high-traffic doors more often) |
| Monitoring path | Signal test to the centre across all paths (IP + 4G); polling confirmation; event log review | With every service, plus contract-specified tests |
The universal failure mode across all four: backup batteries. Panel, siren, controller and UPS batteries age invisibly and fail exactly when the mains does — a disciplined battery-age register across the fleet prevents most “system was dead when it mattered” conversations.
Commercial insurance policies routinely specify security requirements: an alarm to a stated class, graded monitoring, sometimes CCTV coverage or specific locking hardware. Two contractor-relevant consequences follow. First, specification: the system you install and maintain should demonstrably meet what the client’s policy assumes — worth asking for at quote time, because under-specifying against the policy sets the client up for a declined claim. Second, evidence: after an event, the insurer’s questions are about maintenance and operability — when was it last serviced, was it monitored, was it set. The service history answers for the client; its absence answers against them.
Security is a licensed industry in most Australian jurisdictions: installing, servicing and monitoring security equipment generally requires an individual security licence in the relevant class, and businesses need their own licence/registration — with ACMA cabling registration on top for fixed cabling work. The detail varies enough by state that it has its own guide in this knowledge base; the compliance takeaway here is operational: every technician’s licence class and expiry belongs in your records, because unlicensed work is unlawful, uninsurable and — on government and commercial sites — increasingly audited at induction.
This is the record set that satisfies an insurer’s post-event questions, a commercial client’s audit, and a monitoring centre’s compliance requirements — and it is the renewal argument for the maintenance contract itself.
traqR runs security maintenance the way the evidence demands: QR-coded asset registers across panels, detectors, cameras and doors; contract schedules generating the six-monthly/annual visits; per-device test results, photos and defects captured in the field; battery age tracked fleet-wide; technician security-licence and cabling-registration tracking with expiry alerts; and exportable per-site service histories that answer the insurer, the auditor and the renewal conversation in one report.
Unlike fire systems, no state mandates a universal security-servicing statement. The obligations arrive through the system’s specified AS/NZS 2201 class, insurer policy conditions (which routinely assume a working, monitored, maintained system), monitoring contract requirements, and — for government/commercial clients — contractual maintenance clauses. Practically, annual servicing is the professional baseline.
The Australian/New Zealand intruder alarm standard series: 2201.1 covers systems at client premises (design, installation, maintenance, and the five ascending security classes); 2201.2 covers monitoring centres and their grading. Systems should be specified, installed and maintained to the class the risk and the client’s insurer require.
Backup batteries — in panels, sirens, controllers and communicators. They age silently and reveal themselves during the mains failure they existed for. Fleet-wide battery age tracking with proactive replacement is the single highest-value maintenance discipline.
It depends what “compliance” means for that site: some insurers and classes require graded monitoring, others accept local alarms. Verify the client’s policy conditions and the specified system class — and document the client’s informed choice when they decline monitoring.
traqR does quoting, scheduling, invoicing, timesheets and compliance — built for Australian trades. Try it free for 14 days, no credit card required.