Certification
What makes a fire or security certificate compliant?
The things auditors, insurers and fire officers actually look for on a fire alarm, emergency lighting, extinguisher or security certificate — and the gaps that get certificates challenged.
A certificate is evidence, not a receipt
A servicing certificate exists so that someone who wasn't there — an insurer, an auditor, a fire officer after an incident, the next contractor — can establish what was tested, what was found, and whether the system was fit for purpose on that date. Judged against that purpose, a lot of certificates in circulation are weak: a tick in a "satisfactory" box, a signature, and very little in between.
The sections below are the things that repeatedly get certificates challenged, in roughly the order they come up.
1. It identifies the system precisely
Site name and address, the specific system (a site can have several), the panel or control equipment, and — for fire alarm — the category the system was designed to. A certificate for "the fire alarm at Unit 4" that doesn't say which panel, how many zones, or what category, can't be checked against anything.
2. It says what was actually tested
"A sample of detectors was tested" is not a record. Which zones? Which devices? What were the results? The standards require every device to be tested within a defined period, and the only way to demonstrate that is a register that shows, visit by visit, which ones were covered. The same applies to luminaires, extinguishers, doors and cameras.
3. Readings come with their conclusion
Battery voltages, currents and capacities; sound pressure levels; duration test times. Recording the numbers is half the job — the certificate also has to say what they mean. A standby battery reading of 26.4 V is meaningless without the capacity calculation that says whether the system will last its required standby period.
This is where automatic verdicts earn their keep: if the pass/fail is derived from the readings by a fixed method, it's consistent between engineers and defensible later. If it's a judgement call, it's only as good as the person making it on the day.
4. Defects are specific, graded and actionable
A compliant certificate doesn't hide problems. Each defect should say what was found, where, how serious it is (non-compliant, minor, or an observation), and what should be done about it. A photo helps. A certificate that shows a system as "satisfactory" while the notes box mentions three faults is the kind of document that gets pulled apart in a dispute.
5. It's signed, dated and attributable
Who did the work, for which organisation, on what date — and ideally the client's acknowledgement that they've received it and understood any defects. A certificate that can't be attributed to a competent person is not much use as evidence of competent-person inspection.
6. It can be shown not to have changed
The quiet problem with PDFs and paper: nothing stops a certificate being edited after the fact, and nothing shows that it hasn't been. Digital fingerprinting at sign-off — a hash of the certificate's contents that anyone can verify — is the difference between "here's the certificate" and "here's the certificate, and here's proof it's the one that was signed."
Kerova fingerprints every signed certificate, records any reopen, and publishes a verification page reachable by QR code so a third party can confirm the document is genuine without an account.
Quick checklist
- Site, system, panel and design category identified
- A device-level register of what was tested, with results
- Readings recorded and assessed against the requirement
- Defects listed individually with severity and recommended action
- An overall verdict consistent with the defects
- Competent person named, dated, signed; client acknowledgement
- Next due date stated
- Tamper-evident, verifiable copy
This guide is general information for UK fire & security companies, not legal or engineering advice. Always work to the current edition of the relevant standard and your own competent-person judgement.
See this on a real certificateKerova builds the register, readings and verdict into the certificate itself.
Book a Demo