Access Control and Door Entry Installer Insurance
Access control has two opposite failure modes, and the second one is far more serious than the first.
Keeping People Out, And Letting Them Out
The obvious failure is a system that let the wrong person in: a credential that should have been revoked, a door that did not lock, a reader that could be bypassed, and a theft or an assault follows. The failure nobody plans for is a system that would not let people out. Electronic locking on an escape route has to release on a fire alarm, on a power failure and on a green break glass, and if it does not, a locked door stands between people and the way out.
On top of that, an access control system is a database of who went where and when, which makes a small installer the custodian of personal data about a building's occupants.
What Access Control Installer Insurance Covers
Public liability
Injury and damage to third parties, including building occupiers. £5 million is usual and £10 million on managed residential and commercial contracts.
Fail safe and escape route failures
The severe exposure. Electronic locking that did not release on alarm, power failure or break glass, where the consequence is injury rather than loss.
Professional indemnity
System design, interface with the fire alarm, and the specification of what releases when are judgements a building relies on. Mechanics on our professional indemnity page.
Efficacy and failure to secure
A system that did not keep somebody out is a failure of function rather than damage, which some wordings treat separately or exclude.
Cyber and data
Access logs, credentials, photographs and the personal data of everybody who uses the building, frequently held on a system you administer.
Employers' liability
Compulsory at a £5 million statutory minimum. Electrical work, door and gate mechanisms, and work at height on gates and barriers.
Damage during installation
Cable routes through finished walls and fire compartments, and doors, frames and glazing modified for locking hardware.
Where The Cover Stops
Wordings differ between insurers, so treat these as the usual position rather than as universal fact. Where one of them matters to you, it is worth checking on your own schedule before you need to.
Fire alarm interface
The single most important function, and the one most likely to be tested at the worst moment. Who configured and tested it decides a claim.
Inherited systems on maintenance
A service contract makes somebody else's configuration your responsibility, including the release arrangements you never designed.
Failure to secure as a loss
A theft after a credential was not revoked is a loss of property, and whether that is your liability depends on what you were contracted to manage.
Fire compartment penetrations
Cable through a compartment wall without reinstated fire stopping is your hole, and the consequence is smoke spread.
Data in the system
Access logs show individuals' movements. A breach is a personal data incident rather than a technical fault.
Gates and barriers
Powered gates and barriers are machinery with force and crushing hazards, and they carry their own safety requirements.
The Door Has To Open
Everything about access control liability starts with the fact that a locked escape route is a life safety failure, not a security feature.
Electronic locking on a final exit or an escape route must release in the circumstances that matter: on a fire alarm signal, on loss of power, and on operation of a green emergency release adjacent to the door. Getting that right is partly product selection, because a fail secure lock and a fail safe lock behave in opposite ways when power is removed, and partly configuration, because the interface to the fire alarm has to be wired and tested rather than assumed. The realistic failures are a lock specified fail secure on an escape door, a fire alarm relay never connected, a break glass that was fitted but not wired through, and a configuration change during later maintenance that quietly removed the release.
So the commissioning record is the defence, and it needs to be specific. Which doors are on escape routes, what lock type was fitted and why, that the fire alarm interface was tested by activating the alarm rather than by shorting a terminal, that each emergency release was operated and the door opened, and the date and who witnessed it. Repeat it on every maintenance visit, because a system that released correctly at handover and does not now is still a system somebody relies on.
Taking On Somebody Else's Configuration
Maintenance contracts in this trade carry a particular risk, because what you inherit is not just hardware but a set of decisions.
A system installed years ago by somebody else has lock types you did not choose, a fire alarm interface you did not wire, release arrangements you have never tested, credentials issued to people who left, and sometimes doors that were added later by a handyman. From the day you hold the contract, a failure is examined against what a competent maintainer should have found, and the fact that you did not create the problem is not much of an answer.
Which makes the takeover inspection worth more than the first year's contract fee. Walk every door, record the lock type and release arrangement, test the fire alarm interface and every emergency release, list what is wrong, and give the client a written report with recommendations and a priority. Where remedial work is declined, keep that refusal and restate it at every subsequent visit rather than carrying it silently. Also review the credential database, because a system full of active cards belonging to former staff is a security failure sitting in your contract.
You Are Holding Data About People
An access control system is a record of individuals' movements, and installers frequently end up administering it without thinking of themselves as data handlers.
The system knows who entered which door at what time, often with a photograph, and sometimes with biometric data. Where you host the software, hold remote access, or administer users on the client's behalf, you are handling personal data about every occupant of the building, which includes employees, residents, visitors and contractors. A compromise of your remote access is both a security failure for the building and a personal data incident for everybody in it.
So treat the access side of your business with the controls that implies. Multi factor authentication on any remote access platform, unique credentials per engineer rather than a shared password, default passwords on controllers and intercom panels changed as part of commissioning rather than left, a record of which clients you hold remote access to, and clarity in the contract about whether you administer users or the client does. Then check the cyber wording, because a policy written around your own office data may not contemplate a breach of a system you administer for somebody else.
Gates And Barriers Are Machinery
Where the access point is a vehicle gate or a barrier rather than a door, the exposure changes from electronics to machinery.
A powered sliding or swing gate moves with enough force to injure, and the hazards are recognised: crushing between a leaf and a post, trapping in a drive mechanism, shearing at a hinge, and a gate that fails and falls. The people affected are frequently residents and children at a block of flats rather than trained users, and they have no idea they are near a machine. Force limitation, safety edges, photocells, and a force test with measured results are the controls, and the commissioning record with those measurements is the document that matters.
The same applies to taking on maintenance of existing gates, which is where most of the serious incidents arise: gates installed years ago without safety devices, with devices that have failed, or with force settings that were never measured. If you are asked to maintain one, assess it and report in writing rather than servicing it as found, because a gate that injures somebody after your visit is examined against what you should have identified. Where domestic driveway gates are the work, our fencing page covers that end.
How To Choose A Broker For Access Control
The escape route question is the one that matters most. We are an FCA regulated broker and will not tell you we are the best choice. These are the questions that decide it.
Is a failure to release on escape routes covered?
Electronic locking that did not release on alarm or power failure is an injury exposure rather than a loss.
Is system design covered as advice?
Lock selection, the fire alarm interface and what releases when are judgements the building relies on.
Is failure to secure within the wording?
A theft after a credential was not revoked is a performance failure, which some wordings treat separately or exclude.
Does cyber cover extend to systems you administer?
A policy written around your own office data may not contemplate a breach of a client's system through your remote access.
Are powered gates and barriers included?
They are machinery with crushing and shearing hazards, used by residents and children rather than trained operators.
How are inherited systems on maintenance treated?
A contract makes somebody else's lock types and release arrangements your responsibility from the first visit.
Factually, here is what we do against those questions. We put the escape route exposure first because a locked escape door is an injury claim rather than a property one, we arrange professional indemnity where you design systems and configure fire alarm interfaces, we check cyber cover extends to client systems you administer remotely, and we ask whether powered gates and barriers are inside the wording. We are a broker, so it goes to several insurers rather than one.
We also insure security systems installers, fire alarm installers and automatic door installers, so escape routes, interfaces and powered machinery in doorways are familiar ground here.
What Moves The Price
Every policy is priced on the business behind it. These are the things that move the premium:
- Whether escape route release failures are covered
- Whether you design systems or install to a specification
- Whether powered gates and barriers are installed
- Whether you administer client systems or hold remote access
- The number of systems under maintenance contract
- Building types served, including residential blocks
- The limit of indemnity your contracts require
- Claims history, including security and release failures
We are a broker, so we take it to several insurers rather than quoting one. Call 02382 000820 for a quote.
What We Need To Quote
- The systems you install, access, door entry and gates
- Whether you design systems and configure fire alarm interfaces
- Whether powered gates or barriers are part of the work
- Whether you host software or hold remote access to client systems
- Approximate number of systems under maintenance
- Your commissioning and release testing procedure
- The limit of indemnity required, and who requires it
- Any claims in five years, including failures to secure
Cover that often goes with this
The gaps we most often find sitting next to this policy.
- Security systems installersIntruder alarms, CCTV and monitored response.
- Fire alarm installersThe system your locking has to listen to.
- Automatic door installersPowered doors in public entrances.
- Fencing contractorsDomestic powered driveway gates.
- Cyber insuranceAccess logs, credentials and remote access you hold.
- Talk to a brokerAsk how escape route release failures are treated.
Common questions
What insurance do access control installers need?+
Public liability at £5 million, or £10 million on managed residential and commercial contracts, written so a failure of electronic locking to release on an escape route is covered, because that is an injury exposure rather than a loss. Then professional indemnity for system design and the fire alarm interface, cover reaching failure to secure since that is a performance failure, cyber and data cover extending to systems you administer for clients, employers' liability at a £5 million statutory minimum, and cover for damage during installation including fire compartment penetrations.
What happens if a locked door does not release in a fire?+
It is the most serious exposure in the trade, because a locked escape route is a life safety failure rather than a security feature. Electronic locking on a final exit must release on a fire alarm signal, on loss of power and on a green emergency release beside the door. The realistic failures are a fail secure lock specified on an escape door, a fire alarm relay never connected, a break glass fitted but not wired through, and a configuration change during later maintenance that quietly removed the release. The commissioning record is the defence.
What should a commissioning record actually say?+
Enough to show the release was tested rather than assumed. Which doors are on escape routes, what lock type was fitted and why, that the fire alarm interface was tested by activating the alarm rather than shorting a terminal, that each emergency release was operated and the door physically opened, and the date with who witnessed it. Then repeat it at every maintenance visit, because a system that released correctly at handover and does not now is still a system people rely on, and the service record shows who was there last.
Am I responsible for a system I did not install?+
Once you hold the maintenance contract, in practice yes. What you inherit is not just hardware but decisions: lock types you did not choose, a fire alarm interface you did not wire, release arrangements never tested, credentials issued to people who left, and doors added later by somebody else. A failure is examined against what a competent maintainer should have found. So walk every door at takeover, record lock types and release arrangements, test every interface and emergency release, and give the client a written report with priorities, keeping any refusal in writing.
Does an access control installer hold personal data?+
Usually yes, and installers often do not think of themselves that way. The system records who entered which door and when, frequently with photographs and sometimes biometrics, so where you host the software, hold remote access or administer users on a client's behalf you are handling personal data about every occupant. A compromise of your remote access is both a building security failure and a data incident for everybody in it. Use multi factor authentication, unique engineer credentials, changed default passwords, and check your cyber wording covers client systems you administer.
Who insures access control and door entry installers in the UK?+
It is written as an electrical and security installation trade, sometimes within a general electrical policy that does not contemplate the life safety side. It is placed mostly through brokers. What separates placements is whether a failure to release on an escape route is covered, whether system design and the fire alarm interface are covered as advice, whether cyber cover extends to client systems you administer, and whether powered gates and barriers are within the wording.
More food, drink and leisure we cover
What our customers say on Google
5.0average from 169 Google reviews
