How to Pass Your CHAS Assessment First Time
CHAS rejections are rarely about businesses being genuinely unsafe — they're almost always about documentation that doesn't clearly demonstrate safety practices the business is actually following. Here's where most first-time applications go wrong, and how to fix it before you submit.
Generic Risk Assessments
A risk assessment copied from a template and never adapted to your actual sites and activities is one of the most common rejection triggers. Assessors can tell the difference between a document that reflects real operational thinking and one that's been downloaded and lightly edited. Specificity matters more than length.
Missing or Outdated Training Records
It's not enough to say your staff are trained — CHAS wants to see who, when, and in what. Gaps in training records, or records that haven't been updated as staff join or move roles, are an easy and entirely avoidable reason to get sent back for resubmission.
Policies That Don't Match Practice
If your written policy describes a process your team doesn't actually follow day to day, that mismatch tends to surface during assessment — and it undermines confidence in everything else you've submitted. Policies should describe what genuinely happens, not an aspirational version of it.
Incomplete Accident and Incident Records
Some businesses worry that disclosing incidents will count against them. In practice, assessors are usually more concerned by the absence of any incident history at all (which often reads as under-reporting) than by a small number of properly investigated and closed-out incidents.
The pattern across nearly every CHAS rejection is the same: documentation that doesn't accurately or specifically reflect what the business actually does. Fix that gap before submission, and first-time passes become the norm rather than the exception.
Need Help With This?
Our compliance team can walk you through exactly what your business needs.
Book Free ConsultationKeep Reading
More Articles
5 Signs Your Security Company Needs SIA ACS Accreditation
If you're noticing any of these patterns in your tender results, ACS accreditation might be the missing piece.
ISO 9001 vs ISO 45001: What's the Difference and Do You Need Both?
Two of the most commonly confused ISO standards, explained in plain English for security businesses.
Why Cyber Essentials Matters for Security Companies in 2026
Security companies handle more sensitive data than most realise — here's why that makes cyber certification essential.