Knowella

CCTV and Monitoring Review

A camera system that looks complete on the installation plan can still be useless the one time it matters, because coverage was drawn from where the cameras point, not from what the footage actually shows at 2am. The recurring failure in this review is testing the system against its own paperwork instead of pulling real footage, so a system that has quietly degraded, or never worked in the dark, keeps passing every year until an incident proves otherwise.

KnowSafeReviewSAF-14840 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.8.1
Workspace
KnowSafe
Form type
Review
Completed by
Carried out by security with the privacy owner
Reviewed
Yearly, against footage actually sampled, not camera positions on a plan

The short version

  • A pass on this review means the footage was tested, not that the cameras were counted. Coverage adequacy, night performance and export all need to be demonstrated against real footage each cycle.
  • Identification and recognition are different standards. Footage that lets you notice a shape moving is not footage that lets you identify who it was, and only the second is useful in an investigation.
  • Retention set to the cheapest storage tier rather than the realistic delay before an incident is reported is the single most common reason footage isn't there when it's needed.
  • Monitoring introduced without consulting workers first, and footage that drifts into performance management, are treated by this review as findings in their own right, separate from whether the cameras function.

What this is

What is a CCTV and monitoring review?

What is a CCTV and monitoring review?

It is an annual test of whether a camera system does what it is meant to: cover the entry points and high-value areas, produce footage good enough to identify someone rather than just notice them, retain that footage long enough to support an investigation, and restrict who can view it. It is a functional test of the system, not an inventory of the cameras installed.

Why does a privacy owner sign off alongside security?

CCTV is personal data processing, and the security case for keeping cameras running does not satisfy the privacy case for keeping them lawful. The privacy owner checks the impact assessment is current, that monitoring was consulted on rather than announced, and that footage has not drifted into uses it was never justified for.

How is this different from an access control review?

Access Control Review tests who can get through a door. This review tests whether the cameras watching that door actually work: coverage, image quality, retention and who can view the recording. A site can pass one and fail the other.

Scope

When is a cctv and monitoring review required?

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • The annual review interval for the camera system has come round, or a trigger event (a failed investigation, a new build, a coverage complaint) has brought it forward
  • The workspace is being set up and the camera system needs a first baseline record
  • You are running the Lone Working and Security programme and this is one of its steps
  • A linked record needs this one to exist: links Security Risk Assessment, Records Retention
  • A new impact assessment has been issued for the monitoring system and this review needs to confirm it is reflected

Do not use it for

  • Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering.
  • Access Control Review, which reviews who can pass through a door or gate, not what the camera watching it records.
  • Site Security Audit, which tests the wider physical security arrangements by walking them, of which cameras are only one part.
  • Anything outside KnowSafe, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 45001 cl.8.1 requirements does this satisfy?

CCTV sits across two different regulatory logics at once: ISO 45001 treats it as an operational control that has to be maintained and monitored like any other, while UK data protection law treats the same cameras as personal data processing with its own separate justification.

ClauseRequirementWhere it lands
ISO 45001 cl.8.1Operational controls, including monitoring equipment relied on for security and worker safety, established, implemented and maintainedCoverage
ISO 45001 cl.9.1Monitoring and measurement of processes relied on for safety, including whether the equipment performs as intended under real conditionsImage quality
Protection of Freedoms Act 2012 s.29-33 (Surveillance Camera Code of Practice)Surveillance used for a specified purpose, proportionate, and subject to regular review of whether it remains justifiedRetention and access
UK GDPR Art.5(1)(e)Personal data, including footage, kept for no longer than necessary for the purpose it was collected forRetention and access
UK GDPR Art.35A data protection impact assessment carried out and kept current where monitoring is likely to result in high risk to individualsRetention and access
UK GDPR Art.5(1)(b)Personal data collected for a specified purpose not further processed in a manner incompatible with that purposeRetention and access
UK GDPR Art.32Appropriate technical and organisational measures to restrict and log access to personal dataRetention and access
ISO 45001 cl.5.4Consultation and participation of workers in matters affecting their health, safety and working conditionsRetention and access

What it does not cover

  • Security Risk Assessment, which assesses the site against theft, unauthorised access, sabotage and product tampering as a whole, of which cameras are one control among several.
  • Access Control Review, which reviews physical and electronic access permissions, not what the cameras trained on those access points actually capture.
  • Data Protection Impact Assessment, which is the standing privacy risk assessment this review checks is current, rather than one it performs itself.
  • Site Security Audit, which tests the wider security arrangements, perimeter, keys, visitors, by walking them, not by reviewing camera footage.
  • Security Incident Investigation, which investigates what happened in one specific event, not whether the camera system in general still functions.

Global

CCTV and Monitoring Review requirements by country

CCTV regulation is uneven across borders in a way that matters for a multi-site operator: some jurisdictions regulate the cameras directly, and others regulate them only as a form of personal data processing.

United States

State-level consent-to-record and biometric information laws (e.g. Illinois BIPA), OSHA general duty clause

No single federal video surveillance statute exists; the relevant rules sit in a patchwork of state consent, biometric and workplace privacy laws.

The review needs to know which state's rules apply at each site, especially where analytics could add facial recognition to a system built only for coverage.

United Kingdom

Protection of Freedoms Act 2012, Surveillance Camera Code of Practice, UK GDPR

Public-facing surveillance is expected to have regard to a twelve-principle code, and every camera capturing identifiable footage is personal data processing needing a lawful basis.

Signage, retention limits and an impact assessment are not administrative extras, they are the actual legal basis for keeping the cameras switched on.

International

ISO 45001 cl.5.4 and cl.8.1, plus GDPR-modelled data protection regimes adopted across much of the rest of the world

ISO 45001 requires worker consultation before monitoring changes regardless of jurisdiction; most other data protection regimes now mirror GDPR's purpose and storage limitation principles.

A single retention and consultation standard travels well across a multi-site footprint, even where no dedicated CCTV statute exists locally.

How to complete it

How to complete a cctv and monitoring review, step by step

Most of this review is a functional test dressed up as a checklist. The judgement calls sit in how rigorously that test is actually run.

Test the footage, not the site plan

A camera can be correctly positioned on a diagram and still deliver nothing usable, because the lens has clouded, the compression setting was changed, or the field of view was never what the spec claimed. The review has to be answered from footage actually pulled and viewed, not from the layout the cameras were installed against.

Treat night performance as a pass or fail, not a footnote

Most incidents this system exists to evidence happen outside daylight hours. A marginal night performance rating should stop the review at a caution rather than being folded into an overall score that looks fine on average. Coverage that does not work in the dark is coverage on paper only.

Answer 'not used for performance monitoring' with evidence, not intent

The field asks about a standing practice, not a promise. Confirming it without pointing to an access log or a review of recent pulls answers the question with intention rather than fact, and that gap is exactly what a tribunal or regulator will test.

Separate 'access restricted' from 'access logged'

A system can restrict who has a login while keeping no record of what any of them actually viewed. Both halves need to be tested independently: who can get in, and what evidence exists of what they did once inside.

What auditors find

Most common cctv and monitoring review findings

Findings on this review cluster around two things: footage that was never actually tested, and retention or access decisions made for storage convenience rather than the review's own stated purpose.

FindingClauseWhat fixes it
Footage sampled only during daytime hours; night performance recorded as acceptable without an overnight sample.ISO 45001 cl.9.1Sample footage across a full 24-hour cycle including overnight hours at every review, not just when it is convenient to pull.
Export process marked as working, but never actually run end to end during the review.UK GDPR Art.32Perform a live export at each review and record whether it produced usable, time-stamped footage.
Retention period set by the cheapest storage tier rather than the realistic delay before an incident is reported.UK GDPR Art.5(1)(e)Set retention from the longest plausible gap between an event and it being reported, not from the storage budget.
Monitoring system in use with no current data protection impact assessment on file.UK GDPR Art.35Raise or refresh the impact assessment before the review is marked complete, and link its reference on the record.
Workers informed that monitoring was live only after cameras were installed, with no consultation beforehand.ISO 45001 cl.5.4Run consultation ahead of any new camera or coverage change, and record it as consultation, not as a notice sent afterward.
Footage pulled to check timekeeping or productivity rather than for a security purpose.UK GDPR Art.5(1)(b)Restrict access logs to the stated security purpose and require a documented reason for any pull relating to a named individual.

Case in point

Case in point: the camera that filmed nothing anyone could use

A distribution site suffered a theft from its loading dock overnight. The dock had CCTV coverage confirmed on the annual review, marked yes for external coverage and yes for identification possible from footage. When the recording was finally pulled for the investigation, the footage showed a shape moving near the trailer for four minutes, in grainy, underexposed video that no one could match to a person.

The prior year's review had answered the identification question based on a daytime test, walked through once with good light, and had never sampled footage from the hours the dock actually operated unattended. The system had not failed; the review had never tested the condition it was built for. The fix was procedural, not technical: every future review had to sample footage from the actual risk window, not the convenient one.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

40fields
4 sections
Reference
SAF-148
Archetype
Review
Record ID
CCR-2026-000
Scoring
Coverage adequate
Direction
High is good
Singleton
Yes
Basis
ISO 45001 cl.8.1
Links
Links Security assessment, Records retention
Tags
Security, Monitoring
Sections
4
Fields
40
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Review ID*

Generated on save

Auto sequence. Format CCR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Info

Coverage That Does Not Work In The Dark

Cameras are usually specified once and never checked against what they actually record. Review the footage, not the camera positions on a plan.

Text

Period Covered*

Users

Reviewed By*

Numeric Answer

Cameras In System*

Coverage

6 fields
Single Choice

All Entry Points Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

High Value Areas Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Food Defense Points Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Numeric Answer

Blind Spots Identified*

Scored
Single Choice

External Coverage Adequate*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Dock And Yard Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Image quality

6 fields
Single Choice

Footage Sampled And Viewed*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Identification Possible From Footage*

Scored

Recognising that somebody was there is not the same as identifying who. Test it.

  • Yes3 pts
  • Recognition only1 pt
  • No0 pts
Single Choice

Night Performance Acceptable*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Numeric Answer

Cameras Obstructed Or Dirty*

Scored
Numeric Answer

Cameras Faulty Or Offline*

Scored
Single Choice

Time And Date Stamps Correct*

Scored

A wrong clock makes footage useless as evidence.

  • Yes3 pts
  • Drifted1 pt
  • Wrong0 pts

Retention and access

18 fields
Single Choice

Retention Period*

1 year3 years5 years7 years10 years40 yearsPermanent
Single Choice

Retention Meets Investigation Needs*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Single Choice

Export Process Works*

Scored
  • Yes, tested3 pts
  • Untested1 pt
  • No0 pts
Single Choice

Access Restricted And Logged*

Scored
  • Yes3 pts
  • Restricted only1 pt
  • No0 pts
Single Choice

Privacy Notice Displayed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Impact Assessment Current*

Scored
  • Yes3 pts
  • Overdue1 pt
  • None0 pts
Text

Assessment ID

OptionalLinked

Links to CMP-032 Assessment ID

Single Choice

Workers Consulted On Monitoring*

Scored

Monitoring introduced without consultation damages trust more than it deters theft.

  • Yes3 pts
  • Informed only1 pt
  • No0 pts
Single Choice

Not Used For Performance Monitoring*

Scored
  • Confirmed3 pts
  • Occasionally0 pts
  • Routinely0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Review Due*

Users

Security*

Signature

Signature*

Users

Privacy Owner*

Signature

Second Signature*

SAF-148 · record IDs look like CCR-2026-000 · Links Security assessment, Records retention

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Pulling real footage instead of trusting the plan, keeping the impact assessment current, and making sure access to recordings is actually logged, is the work that slips between reviews.

KnowSafe

Holds the CCTV review against the annual cycle, blocks sign-off where night performance or export was never actually tested, and keeps the evidence trail together.

KnowComply

Tracks the data protection impact assessment as a linked, separately-dated record, so a lapsed assessment surfaces before the review is marked complete.

KnowMaintain

Logs faulty or offline cameras as maintenance items against the asset, so a coverage gap found on review becomes a tracked repair rather than a note that resurfaces next year.

Ella
Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

CCTV and Monitoring Review definitions and key terms

Identification-grade footage
Footage clear enough that a specific individual can be recognised, as distinct from footage that only shows a shape or presence was there.
Retention period
The length of time footage is kept before being overwritten or deleted, set against the realistic delay before an incident is reported, not storage cost.
Data protection impact assessment
A structured assessment of the privacy risk a monitoring system poses, required under UK GDPR where the processing is likely to be high risk.
Surveillance Camera Code of Practice
The twelve-principle code under the Protection of Freedoms Act 2012 that relevant UK authorities must have regard to when operating surveillance systems.
Purpose limitation
The principle that data collected for one stated purpose, such as security, cannot be repurposed for another, such as performance monitoring, without a fresh basis.

FAQ

Frequently asked questions about cctv and monitoring review

What is the CCTV and monitoring review template based on?+

It is built against ISO 45001 cl.8.1, which requires operational controls such as monitoring equipment to be established and maintained. Where the site is in the UK, the review also has to satisfy UK GDPR's rules on retention, purpose limitation and impact assessment, since camera footage is personal data.

What sections does the CCTV and monitoring review contain?+

There are four sections: header, coverage, image quality, retention and access. Together they hold 40 fields, 35 of which are required.

How many CCTV and monitoring review records should we have?+

This is a singleton. One record per workspace, set up once and maintained through annual reviews, rather than one per event.

Which programme does this review belong to?+

It sits in Lone Working and Security, and touches Data Protection and Information Security through its retention and impact assessment fields. It supports both a tested security position and a monitoring practice introduced with proper consultation.

Why does night performance get its own scored field?+

Because it is where systems most commonly fail without anyone noticing. A camera that performs well in daylight and marginally at night looks fine on an average score while being genuinely unfit for the hours it matters most.

Can the CCTV and monitoring review template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001 — Occupational health and safety management systems, cl.8.1, cl.9.1, cl.5.4
  • Protection of Freedoms Act 2012 — Surveillance Camera Code of Practice
  • UK GDPR — Article 5 (principles), Article 32 (security), Article 35 (impact assessment)
  • ICO — guidance on video surveillance, including CCTV, ANPR and body-worn video

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.