How to audit a Toronto security vendor before you deploy them: a 6-question technical checklist
Three vendors quoted the same Toronto deployment. Three completely different numbers. The lowest bid had a single-page website and a phone number. When asked to produce documentation before any pricing conversation, one
Three vendors quoted the same Toronto deployment. Three completely different numbers. The lowest bid had a single-page website and a phone number. When asked to produce documentation before any pricing conversation, one of the three asked why she needed it "right away." That question — that hesitation — is the entire vendor audit compressed into a single observable signal.
If you're running or building security operations in Toronto, you already know that price is a lagging indicator. The actual signal is how fast a vendor can produce verifiable documentation: a license number you can look up yourself, an insurance certificate that names the right entity, individual officer credentials for the specific roster assigned to your deployment. Compliance documents either exist or they don't — a provider who needs 48 hours to produce them doesn't have them. This checklist is how you surface that gap before it becomes your incident report.
Why Toronto's market has a specific compliance floor
Ontario's Private Security and Investigative Services Act (PSISA) sets a hard, enforceable licensing requirement at two levels: the operator entity and each individually deployed officer. That two-level structure is where most of Toronto's non-compliant vendors fall short — they hold a valid operator license but let individual officer licenses lapse or deploy unlicensed substitutes when the roster is thin.
Toronto's risk profile sharpens the stakes. Downtown and Yorkville carry concentrated event crowd-safety exposure (Scotiabank Arena, Rogers Centre, convention venues). Distillery District runs higher on high-end retail incident patterns. A vendor who can't distinguish those two risk postures by precinct — operationally, in officer briefing terms, not marketing terms — hasn't actually worked Toronto. They've worked somewhere else and rebranded the proposal.
The 6-question audit (run it before discussing price)
1. PSISA operator license number — can I verify it independently?
A compliant vendor gives you the number in the same call and doesn't object to you cross-checking it on the Ministry of the Attorney General's licensing portal. Hesitation here closes the audit. There's no reason a legitimate operator doesn't have this memorized.
2. Are individual officers licensed separately under PSISA?
This is the most common gap in the Toronto market. Operator license ≠ licensed roster. Ask for the specific PSISA license numbers of the officers assigned to your deployment, not a generic company-wide assurance. A substitution policy that doesn't include license re-verification before the substitute arrives is a policy that hides unlicensed officers.
3. Certificate of insurance — limits, named entity, and date.
Request the certificate before any further conversation. It should name your property or event as additional insured, at minimum $1M per occurrence, and the expiry date should cover your full engagement period — not just the contract start date. A common Toronto pattern: certificates that technically exist but were issued for a different address or lapsed 30 days ago. Read the document; don't accept "we're covered."
4. Documented precinct-specific deployment history.
Downtown and Yorkville event crowd safety looks different from Distillery District retail incident patterns. Ask the vendor to describe how their officer briefing differs between those two contexts. If they can't — if they give you a generic security philosophy instead of a specific operational answer — they're quoting from a template, not from deployment logs.
5. Background check specifics and recency for assigned officers.
"We background check everyone" is not an answer. Get the specific scope: criminal history, employment verification, current PSISA license standing. Get the date it was run for the specific officers assigned to your account, not a cohort-wide assurance from onboarding two years ago.
6. Substitution and no-show protocol.
Ask exactly how a substitution is handled at your deployment and whether the substitute's PSISA license is verified before they arrive on-site. Vendors who verify after — or who don't have a documented answer to this question — are managing a licensing gap on their active roster.
Pro tip: Run all 6 questions in the same phone call, before any pricing discussion. A vendor who is fully compliant answers within minutes — the documentation exists because maintaining it is a normal operational requirement, not a special request. A vendor who needs to "check with the office" on their own license number is telling you the documents don't exist yet.
Red flags specific to Toronto's vendor market
Vague precinct history. A vendor claiming broad Toronto experience who can't describe the crowd-management dynamic at a Scotiabank Arena event specifically hasn't worked that deployment. Ask for it unprompted.
Roster not confirmed until 24 hours before deployment. This is a roster licensing gap being managed in real time. A vendor who won't name assigned officers until the day before is filling shifts with whoever clears the schedule, not whoever clears PSISA.
Pricing meaningfully below market with no explanation. Licensed, individually verified, insured officers in Toronto cost what they cost. A quote well below that range usually means one of the 6 questions above has an answer the vendor would rather not give before the contract is signed.
Insurance certificates naming the wrong entity or showing an expired date. Read the certificate. Don't outsource that step.
What goes in the contract after vetting passes
Passing the 6 questions is the qualification stage. The contract is where you lock in what you verified:
- Named officers with PSISA license numbers as an appendix, updated on every substitution.
- Insurance coverage confirmed for the full contract term, with renewal as the vendor's documented responsibility.
- Incident documentation scope and turnaround time, specified in writing — not left as an informal understanding about "how we handle things."
- Compliance-triggered termination clause: if the vendor's PSISA operator license lapses, or any assigned officer's individual license is not current at deployment, the contract allows immediate termination without penalty. Compliance failure is a categorically different problem than a missed shift.
A vendor who answered the 6 questions cleanly will not object to any of these terms. Resistance at the contract stage, after a clean vetting conversation, is new information worth acting on.
One-time event vs. ongoing contract — where the emphasis shifts
The 6 questions apply either way. The weight shifts:
One-time event (Scotiabank Arena, Rogers Centre, convention venue): prioritize named officer confirmation and crowd-management certification for that specific date. A vendor who is vague about who exactly will be on-site for a single event deployment has no ongoing relationship to fall back on if something is wrong that night.
Ongoing contract (Distillery District residential, standing commercial account): prioritize the substitution protocol and the insurance renewal process. Month-one performance tells you little about month twelve. The contract terms above are what protect the deployment across the full term — not the vetting conversation you had in week one.
PSISA licensing requirements don't change with contract length. A one-night Downtown event requires the same individually licensed officers as a year-long Distillery District residential contract.
How XGuard fits into this workflow
If you're building or running security operations and need to compress this audit cycle, XGuard functions as a real-time marketplace and dispatch system where officer identity and PSISA license status are verified before a worker appears in the platform — not after you've already quoted the client. For operators managing multiple Toronto deployments across Downtown, Yorkville, and Distillery District, that pre-verification layer reduces the vetting burden to fit-for-deployment confirmation rather than starting the license and insurance check from zero with every cold-called vendor.
If you're on the operator side and want to be the one found by Toronto clients running this checklist, XGuard is where you make your verified credentials visible to that pipeline. Check out XGuard to see how the dispatch and marketplace layer works for operators building in this space.
Originally published at xguard.app. This version was adapted for this platform's audience; the canonical original lives at the link above.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.