What this is
What is a CCTV and monitoring review?
What is a CCTV and monitoring review?
It is an annual test of whether a camera system does what it is meant to: cover the entry points and high-value areas, produce footage good enough to identify someone rather than just notice them, retain that footage long enough to support an investigation, and restrict who can view it. It is a functional test of the system, not an inventory of the cameras installed.
Why does a privacy owner sign off alongside security?
CCTV is personal data processing, and the security case for keeping cameras running does not satisfy the privacy case for keeping them lawful. The privacy owner checks the impact assessment is current, that monitoring was consulted on rather than announced, and that footage has not drifted into uses it was never justified for.
How is this different from an access control review?
Access Control Review tests who can get through a door. This review tests whether the cameras watching that door actually work: coverage, image quality, retention and who can view the recording. A site can pass one and fail the other.
Scope
When is a cctv and monitoring review required?
This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- The annual review interval for the camera system has come round, or a trigger event (a failed investigation, a new build, a coverage complaint) has brought it forward
- The workspace is being set up and the camera system needs a first baseline record
- You are running the Lone Working and Security programme and this is one of its steps
- A linked record needs this one to exist: links Security Risk Assessment, Records Retention
- A new impact assessment has been issued for the monitoring system and this review needs to confirm it is reflected
Do not use it for
- Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering.
- Access Control Review, which reviews who can pass through a door or gate, not what the camera watching it records.
- Site Security Audit, which tests the wider physical security arrangements by walking them, of which cameras are only one part.
- Anything outside KnowSafe, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 45001 cl.8.1 requirements does this satisfy?
CCTV sits across two different regulatory logics at once: ISO 45001 treats it as an operational control that has to be maintained and monitored like any other, while UK data protection law treats the same cameras as personal data processing with its own separate justification.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.8.1 | Operational controls, including monitoring equipment relied on for security and worker safety, established, implemented and maintained | Coverage |
| ISO 45001 cl.9.1 | Monitoring and measurement of processes relied on for safety, including whether the equipment performs as intended under real conditions | Image quality |
| Protection of Freedoms Act 2012 s.29-33 (Surveillance Camera Code of Practice) | Surveillance used for a specified purpose, proportionate, and subject to regular review of whether it remains justified | Retention and access |
| UK GDPR Art.5(1)(e) | Personal data, including footage, kept for no longer than necessary for the purpose it was collected for | Retention and access |
| UK GDPR Art.35 | A data protection impact assessment carried out and kept current where monitoring is likely to result in high risk to individuals | Retention and access |
| UK GDPR Art.5(1)(b) | Personal data collected for a specified purpose not further processed in a manner incompatible with that purpose | Retention and access |
| UK GDPR Art.32 | Appropriate technical and organisational measures to restrict and log access to personal data | Retention and access |
| ISO 45001 cl.5.4 | Consultation and participation of workers in matters affecting their health, safety and working conditions | Retention and access |
What it does not cover
- Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering as a whole, of which cameras are one control among several.
- Access Control Review, which reviews physical and electronic access permissions, not what the cameras trained on those access points actually capture.
- Data Protection Impact Assessment, which is the standing privacy risk assessment this review checks is current, rather than one it performs itself.
- Site Security Audit, which tests the wider security arrangements, perimeter, keys, visitors, by walking them, not by reviewing camera footage.
- Security Incident Investigation, which investigates what happened in one specific event, not whether the camera system in general still functions.
Global
CCTV and Monitoring Review requirements by country
CCTV regulation is uneven across borders in a way that matters for a multi-site operator: some jurisdictions regulate the cameras directly, and others regulate them only as a form of personal data processing.
State-level consent-to-record and biometric information laws (e.g. Illinois BIPA), OSHA general duty clause
No single federal video surveillance statute exists; the relevant rules sit in a patchwork of state consent, biometric and workplace privacy laws.
The review needs to know which state's rules apply at each site, especially where analytics could add facial recognition to a system built only for coverage.
Protection of Freedoms Act 2012, Surveillance Camera Code of Practice, UK GDPR
Public-facing surveillance is expected to have regard to a twelve-principle code, and every camera capturing identifiable footage is personal data processing needing a lawful basis.
Signage, retention limits and an impact assessment are not administrative extras, they are the actual legal basis for keeping the cameras switched on.
ISO 45001 cl.5.4 and cl.8.1, plus GDPR-modelled data protection regimes adopted across much of the rest of the world
ISO 45001 requires worker consultation before monitoring changes regardless of jurisdiction; most other data protection regimes now mirror GDPR's purpose and storage limitation principles.
A single retention and consultation standard travels well across a multi-site footprint, even where no dedicated CCTV statute exists locally.
How to complete it
How to complete a cctv and monitoring review, step by step
Most of this review is a functional test dressed up as a checklist. The judgement calls sit in how rigorously that test is actually run.
A camera can be correctly positioned on a diagram and still deliver nothing usable, because the lens has clouded, the compression setting was changed, or the field of view was never what the spec claimed. The review has to be answered from footage actually pulled and viewed, not from the layout the cameras were installed against.
Most incidents this system exists to evidence happen outside daylight hours. A marginal night performance rating should stop the review at a caution rather than being folded into an overall score that looks fine on average. Coverage that does not work in the dark is coverage on paper only.
The field asks about a standing practice, not a promise. Confirming it without pointing to an access log or a review of recent pulls answers the question with intention rather than fact, and that gap is exactly what a tribunal or regulator will test.
A system can restrict who has a login while keeping no record of what any of them actually viewed. Both halves need to be tested independently: who can get in, and what evidence exists of what they did once inside.
What auditors find
Most common cctv and monitoring review findings
Findings on this review cluster around two things: footage that was never actually tested, and retention or access decisions made for storage convenience rather than the review's own stated purpose.
| Finding | Clause | What fixes it |
|---|---|---|
| Footage sampled only during daytime hours; night performance recorded as acceptable without an overnight sample. | ISO 45001 cl.9.1 | Sample footage across a full 24-hour cycle including overnight hours at every review, not just when it is convenient to pull. |
| Export process marked as working, but never actually run end to end during the review. | UK GDPR Art.32 | Perform a live export at each review and record whether it produced usable, time-stamped footage. |
| Retention period set by the cheapest storage tier rather than the realistic delay before an incident is reported. | UK GDPR Art.5(1)(e) | Set retention from the longest plausible gap between an event and it being reported, not from the storage budget. |
| Monitoring system in use with no current data protection impact assessment on file. | UK GDPR Art.35 | Raise or refresh the impact assessment before the review is marked complete, and link its reference on the record. |
| Workers informed that monitoring was live only after cameras were installed, with no consultation beforehand. | ISO 45001 cl.5.4 | Run consultation ahead of any new camera or coverage change, and record it as consultation, not as a notice sent afterward. |
| Footage pulled to check timekeeping or productivity rather than for a security purpose. | UK GDPR Art.5(1)(b) | Restrict access logs to the stated security purpose and require a documented reason for any pull relating to a named individual. |
Case in point
Case in point: the camera that filmed nothing anyone could use
A distribution site suffered a theft from its loading dock overnight. The dock had CCTV coverage confirmed on the annual review, marked yes for external coverage and yes for identification possible from footage. When the recording was finally pulled for the investigation, the footage showed a shape moving near the trailer for four minutes, in grainy, underexposed video that no one could match to a person.
The prior year's review had answered the identification question based on a daytime test, walked through once with good light, and had never sampled footage from the hours the dock actually operated unattended. The system had not failed; the review had never tested the condition it was built for. The fix was procedural, not technical: every future review had to sample footage from the actual risk window, not the convenient one.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- SAF-148
- Archetype
- Review
- Record ID
- CCR-2026-000
- Scoring
- Coverage adequate
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 45001 cl.8.1
- Links
- Links Security assessment, Records retention
- Tags
- Security, Monitoring
- Sections
- 4
- Fields
- 40
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
10 fieldsReview ID*
Auto sequence. Format CCR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Coverage That Does Not Work In The Dark
Cameras are usually specified once and never checked against what they actually record. Review the footage, not the camera positions on a plan.
Period Covered*
Reviewed By*
Cameras In System*
Coverage
6 fieldsAll Entry Points Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
High Value Areas Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
Food Defense Points Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
Blind Spots Identified*
External Coverage Adequate*
- Yes3 pts
- Partly1 pt
- No0 pts
Dock And Yard Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
Image quality
6 fieldsFootage Sampled And Viewed*
- Yes3 pts
- No0 pts
Identification Possible From Footage*
Recognising that somebody was there is not the same as identifying who. Test it.
- Yes3 pts
- Recognition only1 pt
- No0 pts
Night Performance Acceptable*
- Yes3 pts
- Marginal1 pt
- No0 pts
Cameras Obstructed Or Dirty*
Cameras Faulty Or Offline*
Time And Date Stamps Correct*
A wrong clock makes footage useless as evidence.
- Yes3 pts
- Drifted1 pt
- Wrong0 pts
Retention and access
18 fieldsRetention Period*
Retention Meets Investigation Needs*
- Yes3 pts
- Marginal1 pt
- No0 pts
Export Process Works*
- Yes, tested3 pts
- Untested1 pt
- No0 pts
Access Restricted And Logged*
- Yes3 pts
- Restricted only1 pt
- No0 pts
Privacy Notice Displayed*
- Yes3 pts
- Partly1 pt
- No0 pts
Impact Assessment Current*
- Yes3 pts
- Overdue1 pt
- None0 pts
Assessment ID
Links to CMP-032 Assessment ID
Workers Consulted On Monitoring*
Monitoring introduced without consultation damages trust more than it deters theft.
- Yes3 pts
- Informed only1 pt
- No0 pts
Not Used For Performance Monitoring*
- Confirmed3 pts
- Occasionally0 pts
- Routinely0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Review Due*
Security*
Signature*
Privacy Owner*
Second Signature*
SAF-148 · record IDs look like CCR-2026-000 · Links Security assessment, Records retention
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Pulling real footage instead of trusting the plan, keeping the impact assessment current, and making sure access to recordings is actually logged, is the work that slips between reviews.
Holds the CCTV review against the annual cycle, blocks sign-off where night performance or export was never actually tested, and keeps the evidence trail together.
Tracks the data protection impact assessment as a linked, separately-dated record, so a lapsed assessment surfaces before the review is marked complete.
Logs faulty or offline cameras as maintenance items against the asset, so a coverage gap found on review becomes a tracked repair rather than a note that resurfaces next year.

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
CCTV and Monitoring Review definitions and key terms
- Identification-grade footage
- Footage clear enough that a specific individual can be recognised, as distinct from footage that only shows a shape or presence was there.
- Retention period
- The length of time footage is kept before being overwritten or deleted, set against the realistic delay before an incident is reported, not storage cost.
- Data protection impact assessment
- A structured assessment of the privacy risk a monitoring system poses, required under UK GDPR where the processing is likely to be high risk.
- Surveillance Camera Code of Practice
- The twelve-principle code under the Protection of Freedoms Act 2012 that relevant UK authorities must have regard to when operating surveillance systems.
- Purpose limitation
- The principle that data collected for one stated purpose, such as security, cannot be repurposed for another, such as performance monitoring, without a fresh basis.
FAQ
Frequently asked questions about cctv and monitoring review
What is the CCTV and monitoring review template based on?+
It is built against ISO 45001 cl.8.1, which requires operational controls such as monitoring equipment to be established and maintained. Where the site is in the UK, the review also has to satisfy UK GDPR's rules on retention, purpose limitation and impact assessment, since camera footage is personal data.
What sections does the CCTV and monitoring review contain?+
There are four sections: header, coverage, image quality, retention and access. Together they hold 40 fields, 35 of which are required.
How many CCTV and monitoring review records should we have?+
This is a singleton. One record per workspace, set up once and maintained through annual reviews, rather than one per event.
Which programme does this review belong to?+
It sits in Lone Working and Security, and touches Data Protection and Information Security through its retention and impact assessment fields. It supports both a tested security position and a monitoring practice introduced with proper consultation.
Why does night performance get its own scored field?+
Because it is where systems most commonly fail without anyone noticing. A camera that performs well in daylight and marginally at night looks fine on an average score while being genuinely unfit for the hours it matters most.
Can the CCTV and monitoring review template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Lone Working and Security
Food Defense Plan
Assesses where product could be deliberately contaminated and sets out how that is prevented
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Security Incident Investigation
Records theft, break in, unauthorised access, tampering or threat
More in Security and Lone Working
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Security Incident Investigation
Records theft, break in, unauthorised access, tampering or threat
Access Control Review
Reviews who holds access to which areas and whether that is still justified

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001 — Occupational health and safety management systems, cl.8.1, cl.9.1, cl.5.4
- Protection of Freedoms Act 2012 — Surveillance Camera Code of Practice
- UK GDPR — Article 5 (principles), Article 32 (security), Article 35 (impact assessment)
- ICO — guidance on video surveillance, including CCTV, ANPR and body-worn video
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.