CCTV System Documentation Standards and Best Practices: What Every Installation Should Include

CCTV System Documentation Standards and Best Practices: What Every Installation Should Include

Most people focus entirely on the hardware when planning a CCTV installation β€” cameras, cables, DVR. What they rarely think about is the paperwork. And yet, the documentation that surrounds a CCTV system is often what determines whether the system is useful in a crisis, legally defensible, maintainable over time, and correctly handed over when ownership or management changes. This guide covers what professional documentation looks like and why it matters.

Why Documentation Matters More Than You Think

A CCTV system without proper documentation is a bit like a building without a floor plan. Everything looks fine until something goes wrong β€” a camera fails, a technician needs to trace a cable, a police officer requests footage from a specific time, or a new property manager takes over and has no idea how the system is configured. At that point, the absence of documentation becomes a real, expensive problem.

Good documentation serves multiple functions simultaneously. It protects the installer by proving what was agreed and delivered. It protects the property owner by ensuring the system can be serviced, extended, and operated correctly by anyone with access to the records. It supports legal and compliance requirements, particularly relevant as Kenya’s Data Protection Act 2019 places obligations on organisations operating surveillance systems. And it creates a paper trail that can be the difference between usable evidence and a failed investigation.

Documentation is not glamorous work. It doesn’t show up on a quote line or make for interesting conversation. But among professional security installers, the quality of a company’s documentation is one of the most reliable indicators of how seriously they take their work overall.

The Kenya reality

The majority of CCTV installations in Kenya β€” particularly residential and small business installations β€” are handed over with no documentation at all beyond perhaps a brief verbal walkthrough. If the installing technician becomes unavailable, the owner has no record of what cameras were installed, how they are configured, where cables run, or what credentials access the system. This is a significant vulnerability that most owners don’t recognise until they need the information urgently.

1. The Site Survey Report

The site survey is the foundation of any properly planned CCTV installation. It happens before any equipment is purchased or installed, and the report that comes from it should inform every decision that follows. A verbal site visit with no written record is not a site survey β€” it is just a conversation.

What a Site Survey Report Should Contain

A thorough site survey report documents the physical environment the system will operate in. This means a description of the property β€” its layout, construction type, number of floors, access points, perimeter boundaries, and existing infrastructure. It should identify the specific areas and objectives of surveillance: which zones need coverage, what level of detail is required at each position (detection, recognition, or identification), and any environmental constraints like lighting conditions, reflective surfaces, or areas of high sun exposure.

The report should include a risk assessment β€” where are the most likely points of entry, what are the highest-value assets, what are the current security gaps? This drives camera placement decisions rationally rather than by guesswork or convenience.

Existing infrastructure should be assessed: is there existing cabling that can be reused, where is the proposed DVR/NVR location, is there a reliable power supply at that location, and what is the internet connectivity situation for remote viewing? For IP systems, the network infrastructure β€” router capability, available ethernet ports, Wi-Fi coverage β€” should be assessed and recorded.

Site Survey ElementWhat It RecordsWhy It Matters
Property overviewLayout, construction, floor count, plot sizeDetermines system scope and cabling requirements
Surveillance objectivesWhat needs to be seen, at what level of detailDrives camera type and resolution selection
Risk assessmentAccess points, blind spots, high-value areasEnsures camera placement is threat-driven, not convenient
Environmental factorsLighting, sun angles, weather exposure, vandalism riskDetermines camera specifications and housing requirements
Existing infrastructureCable runs, power points, network equipmentIdentifies what can be reused and what must be added
Proposed camera positionsSketched or photographed positions with notesForms the basis of the system design document
Client requirementsBudget constraints, special requests, future expansion plansAligns the system design with actual client needs

The site survey report should be a written document, signed by both the installer and the client, before any quotation is finalised. It forms part of the agreement between both parties and protects both sides if there are later disputes about scope or deliverables.

2. System Design Document

The system design document translates the site survey findings into a technical specification for the installation. It is the blueprint for what will be installed, where, and why β€” and it should exist before a single cable is run or a bracket is drilled into a wall.

Camera Schedule

The design document specifies every camera in the system: its position (described in text and shown on a layout diagram), its type (bullet, dome, PTZ), its resolution, its field of view angle, the lens focal length, and whether it is indoor or outdoor. For outdoor cameras, it should note the IP rating and whether a drip ledge or additional housing is required.

System Architecture

This section specifies the recording unit β€” DVR or NVR, brand and model, channel count β€” along with the hard drive specification (brand, capacity, RPM, rated for 24/7 operation), UPS specification, and any network equipment required. For IP systems, it documents the PoE switch (if separate from the NVR), router, and cabling plan including cable types and estimated run lengths.

Coverage Map

A coverage map is a floor plan or site plan with camera positions marked, field-of-view cones drawn, and any blind spots identified. This does not need to be an architect-level drawing β€” a clear sketch drawn to rough scale is sufficient. What it must show is that every critical area is covered and that there are no significant gaps in surveillance. The coverage map is also a useful record for future maintenance or expansion.

Why the coverage map matters legally

If an incident occurs in a location that your CCTV system is supposed to cover but doesn’t, having a coverage map that was approved by the client protects the installer from liability. It also helps the client demonstrate to their insurer or the police that they had a documented, deliberate surveillance plan in place.

3. As-Built Drawings

The system design document describes what was planned. The as-built drawings record what was actually installed β€” because the two are never perfectly identical. In practice, cable routes change when you discover a concrete beam in an unexpected place, camera positions shift slightly when you find the original angle is blocked by a sign, and component models sometimes change when a specified item is out of stock at the supplier.

As-built drawings are updated from the design documents during or immediately after the installation. They should show the actual camera positions and angles as installed, the exact cable routes (including which walls and ceilings the cables pass through), the location of the DVR/NVR and all junction boxes, and the location of the power distribution board.

These drawings are invaluable for future maintenance β€” a technician coming to replace a failed camera or trace a cable fault years after installation needs to know where things actually are, not where they were supposed to be. Without as-built drawings, every maintenance visit involves rediscovering the installation from scratch, which costs time and money every single time.

“As-built drawings are the difference between a 30-minute fault-finding visit and a three-hour investigation every time something goes wrong.”

4. Equipment Schedule and Component Register

The equipment schedule is a complete inventory of every component installed in the system. This sounds straightforward, but it’s remarkable how often this basic record doesn’t exist β€” leaving owners unable to identify what they have, what warranty applies, or where to source replacement parts when something fails.

ComponentDetails to Record
Cameras (each unit)Brand, model number, serial number, resolution, camera ID/label, installation position, date installed
DVR / NVRBrand, model, serial number, firmware version, channel count, MAC address, location
Hard Drive(s)Brand, model, serial number, capacity, installation date (drives have a finite life β€” knowing install date predicts when replacement is due)
Power Supply UnitBrand, model, output voltage and amperage, number of channels, location
UPSBrand, model, VA rating, battery replacement date
PoE Switch (IP systems)Brand, model, port count, total PoE wattage, firmware version
CablingCable type (RG59/Cat6), brand, total length installed, conduit type used
Warranty documentsWarranty period per component, supplier contact, claim procedure

Serial numbers are particularly important. When a camera fails and a warranty claim needs to be made, the serial number is the reference the supplier needs. Without it, warranty claims are difficult to process and owners often end up paying for replacements that should have been covered.

5. Cable Register and Labelling Standards

A cable register is a document that maps every cable in the system β€” from which camera it originates, through which route it travels, to which DVR/NVR channel it terminates at. Combined with physical cable labelling at both ends, it transforms a future fault-finding exercise from a guessing game into a straightforward lookup.

Physical Labelling

Every camera should be labelled with a unique identifier β€” typically CAM-01, CAM-02, and so on, or a descriptive label like GATE-CAM or RECEPTION-CAM. That same label should appear at the DVR/NVR end of the cable and in the on-screen camera name configured in the recording software. When all three match, there is never any ambiguity about which physical camera corresponds to which channel on the recorder or which feed on the phone app.

Cable Labelling

For larger installations with multiple cable runs, each cable should be labelled at both ends using durable cable markers or heat-shrink labels. This is particularly important in cable trays, conduit entries, and junction boxes where multiple cables run together. The cable label should reference the camera it serves and the DVR channel it connects to.

Simple labelling approach for home installations

Even for a basic 4-camera home system, taking a photograph of the DVR rear panel showing which cable connects to which channel, and another photograph showing each camera position with its label visible, gives you a reference that is faster to consult than a formal document. Save these photographs to cloud storage β€” not just to a folder on a computer that might fail.

6. System Configuration Record

This is the document that most installations in Kenya completely omit β€” and its absence causes more frustration than almost any other documentation gap. The configuration record captures every software setting in the DVR/NVR that someone would need to know if they had to access, troubleshoot, or reconfigure the system from scratch.

What the Configuration Record Should Include

Setting CategoryWhat to Record
Access credentialsDVR/NVR admin username and password (stored securely β€” not on a sticky note attached to the unit)
Network settingsDVR/NVR IP address (static or DHCP), port numbers configured for remote access, DDNS hostname if used
Remote accessApp name and version, P2P serial number or UID, cloud account email, router port forwarding rules
Recording settingsRecording mode (continuous/motion/scheduled), resolution per channel, frame rate per channel, compression format
Storage settingsHDD total capacity, overwrite settings, recording retention days at current settings
Motion detectionZones configured per camera, sensitivity settings, alert method (email/push/buzzer)
Time settingsTime zone, NTP server, daylight saving configuration
Firmware versionCurrent firmware version per device, date last updated
Password security note

Default passwords β€” “admin/admin” or “admin/12345” β€” must be changed at installation and the new password documented securely. In 2023, a well-publicised security breach involved attackers accessing live feeds from over 60 school cameras through an unchanged default DVR password. The configuration record should note the password change date, but the actual password should be stored in a secure location separate from the system β€” not taped to the DVR.

7. Commissioning and Handover Checklist

The commissioning checklist is completed at the end of the installation, before the client signs off on the work. It confirms that every aspect of the system has been tested and verified β€” not just installed. A system that looks installed but hasn’t been tested is not a delivered system.

Camera and Coverage Verification

  • Every camera is live and displaying a clear image on the monitor
  • Camera angles match the approved design and coverage map
  • No significant blind spots in critical coverage areas
  • Night vision / IR is functional on each camera (tested in low-light conditions)
  • WDR or backlight compensation is correctly configured for high-contrast positions
  • Camera labels on screen match physical camera labels and DVR channel labels

Recording System Verification

  • Hard drive is detected and operational at full rated capacity
  • Recording is active on all configured channels
  • Playback works correctly β€” footage can be retrieved and reviewed
  • Recording schedule is configured as agreed with the client
  • Overwrite is configured correctly so the system doesn’t stop recording when the HDD fills
  • Time and date are correctly set and synced

Remote Access Verification

  • Client can view live footage on their phone via the agreed app
  • Remote playback is functional
  • Motion alert notifications are working and arriving on the correct device
  • Remote access tested from outside the local network (i.e., on mobile data, not Wi-Fi)

Client Handover

  • Client has been shown how to view live footage on monitor and on phone
  • Client has been shown how to review and export recordings
  • Client has been given all login credentials in writing
  • Client has been given all documentation listed in this guide
  • Client has signed a completion certificate confirming acceptance of the system
  • Warranty terms have been explained and documented

The completion certificate is a short, signed document confirming that the installation has been delivered as specified, the client has accepted it, and both parties agree on the warranty terms and support arrangement going forward. It protects both the installer and the client by creating a clear record of what was delivered and when.

8. User Manual and Operating Procedures

A system that the owner cannot operate confidently is a system that will not be used effectively. The user manual does not need to be a thick technical document β€” a clear, site-specific guide covering the everyday tasks the owner will actually need to perform is far more useful than a manufacturer PDF written for a general audience in a foreign language.

What a Good User Manual Covers

The manual should cover, in plain language: how to log into the DVR/NVR on the local monitor, how to switch between live view and playback, how to search for footage by date and time, how to export a clip to a USB drive, and how to view cameras remotely on the phone app. It should include the specific steps for the actual model installed β€” not generic instructions β€” with screenshots where possible.

It should also cover basic troubleshooting: what to do if a camera shows a blank screen, how to check if the hard drive is recording, and who to call and what information to have ready if a fault cannot be resolved without a site visit.

Emergency procedures are worth including: what is the process if an incident occurs and footage needs to be preserved before the system overwrites it? Many owners don’t realise that a DVR set to continuous overwrite will eventually record over an incident if they don’t export the footage. The manual should specify how long footage is retained and what steps to take immediately after an incident to preserve it.

9. Maintenance Log and Service Records

Every service visit β€” whether a routine maintenance check or a fault repair β€” should be recorded in a maintenance log. This creates a history of the system’s performance over time, which is useful for identifying recurring problems, tracking component age, and demonstrating due diligence to insurers or authorities if the system’s reliability is ever questioned.

What a Service Record Should Document

FieldDetails
Date of visitWhen the service was conducted
Technician nameWho carried out the work
Work performedSpecific tasks: camera cleaning, firmware update, HDD health check, cable re-termination, etc.
Faults foundAny issues identified during the visit
Faults resolvedWhat was fixed and how
Parts replacedAny components swapped out, with new serial numbers recorded
Outstanding issuesAny problems identified but not yet resolved, and the plan for resolution
Next service dueRecommended date for the next maintenance visit
Sign-offTechnician and client signatures confirming the visit was completed

Recommended Maintenance Frequency in Kenya

Given Kenya’s climate β€” dust during dry season, humidity and insects during rains, and UV exposure year-round β€” an annual maintenance visit is the minimum for any serious installation. Commercial properties and those in particularly dusty or humid environments benefit from six-monthly checks. Routine maintenance should include cleaning camera lenses and housing, checking and re-securing any cable fixings that have worked loose, verifying HDD health using the DVR’s built-in diagnostics, checking and updating firmware, and verifying that the UPS battery is holding charge correctly.

10. Footage Request and Incident Log

Every time footage is reviewed following an incident, or when footage is requested by a third party β€” police, insurer, neighbouring property β€” that request and the response to it should be documented. This is both a good practice record and, in commercial settings, a compliance requirement under Kenya’s Data Protection Act 2019.

What the Incident Log Should Record

Each entry should note: the date and time of the incident the footage relates to, the date the request was made and by whom, whether footage was found covering the relevant time and camera, what action was taken (footage exported, reviewed internally, provided to police with reference number), and whether any footage was unavailable and why. If footage was unavailable because the recording had been overwritten, that should be documented along with the retention period in effect at the time β€” this protects the system operator from accusations of deliberate deletion.

Kenya Data Protection Act consideration

Under the Data Protection Act 2019, organisations operating CCTV systems in Kenya have obligations around how personal data β€” including video footage β€” is stored, accessed, and shared. Maintaining a footage request log is a practical step toward demonstrating compliance. If footage is shared with a third party, the legal basis for doing so should be noted β€” typically a police request, a court order, or the consent of the individuals visible in the footage.

11. Data Protection and CCTV Policy

For businesses, schools, apartment blocks, and any organisation operating CCTV in a context where employees, tenants, or members of the public are recorded, a written CCTV policy is both good practice and increasingly a legal expectation under Kenya’s Data Protection Act 2019.

What a CCTV Policy Should Cover

The policy should state the purpose of the CCTV system β€” why it exists and what it is intended to achieve. It should describe the areas under surveillance and confirm that areas where people have a reasonable expectation of privacy (bathrooms, changing rooms, private offices) are not monitored. It should specify the data retention period β€” how long footage is stored before being automatically overwritten β€” which should be no longer than necessary for the stated purpose. Thirty days is the standard commercial retention period in most applications.

The policy should identify who has access to footage β€” by job title rather than individual name, so the policy survives staff changes β€” and under what circumstances footage will be reviewed. It should set out the procedure for handling footage requests from data subjects (individuals who appear in the footage and request to see it) and from law enforcement. It should state that footage will not be shared with third parties without a lawful basis for doing so.

For organisations with employees, the CCTV policy should be communicated to all staff and acknowledged in writing. CCTV signage at all monitored entrances is a minimum legal and ethical requirement for any commercial or organisational setting.


CCTV Documentation in the Kenyan Context

The documentation standards described in this guide are based on professional best practice internationally, adapted to the realities of the Kenyan security installation market. The honest picture is that documentation standards vary enormously among installers in Kenya β€” from companies that provide a thorough handover pack to those who hand over a system with nothing in writing at all.

There are a few particular documentation gaps that come up repeatedly in the Kenyan market:

No Written Agreement Before Work Begins

A significant number of installations proceed on the basis of a verbal quote and a handshake. Without a written scope of work β€” specifying exactly what is to be installed, the brand and model of each component, the warranty terms, and the payment schedule β€” disputes about what was agreed are almost impossible to resolve fairly. Any installation costing more than KES 15,000 warrants a written agreement signed by both parties before work begins.

No Credentials Provided at Handover

It is surprisingly common for Kenyan property owners to have a CCTV system installed and not receive the DVR/NVR admin password in writing. Some installers β€” intentionally or otherwise β€” retain this information, creating a dependency relationship. Every client has a right to full administrative access to their own system. If your installer won’t provide the login credentials, that is a serious concern.

No Record of the Remote Access Configuration

Remote viewing on a phone involves configuring the DVR/NVR with a specific app, P2P UID, or DDNS hostname. This configuration is invisible to the user and cannot easily be reconstructed without the original installer’s knowledge of how it was set up. When a system is replaced, the router is changed, or a new phone needs to be configured, the absence of this record means starting from scratch β€” or calling the original installer and hoping they remember.


What to Ask Your Installer About Documentation

Before committing to any CCTV installer in Kenya, these are the documentation-related questions worth asking directly:

  • Will you provide a written site survey report before the installation begins? If the answer is no, the system design is based on impressions rather than a structured assessment.
  • Will you provide a coverage map showing where each camera is positioned and what it covers? This is the minimum visual documentation of the installation.
  • Will I receive an equipment list with make, model, and serial numbers for every component? This is essential for warranty claims and future servicing.
  • Will you provide all login credentials in writing at handover? DVR/NVR admin password, remote app credentials, and any cloud account details.
  • Will you demonstrate how to use the system and provide written operating instructions? Verbal training is forgotten. Written instructions are referred to for years.
  • Do you provide a written completion certificate at handover? This confirms the system has been tested and accepted.
  • Do you offer a maintenance contract, and does it include service records? A company that maintains records has skin in the long-term performance of the system.

A professional installer will answer yes to all of these questions without hesitation. Hesitation or vague answers on any of these points is a signal worth taking seriously before the contract is signed.


Frequently Asked Questions

Do I really need documentation for a small home CCTV system?

Yes β€” the scale of the system does not change the value of the documentation. For a 4-camera home system, the minimum useful documentation is: a written list of components with serial numbers, the DVR/NVR login credentials in writing, the remote app configuration details, and a simple diagram showing where each camera is positioned and which DVR channel it corresponds to. This takes 20 minutes to produce and can save hours of frustration later.

What should I do if my current system has no documentation?

Start building it now. Take photographs of every camera from its mounting position, noting what it covers. Open the DVR/NVR menu and photograph or write down the system information β€” model number, firmware version, HDD capacity, IP address, and recording settings. Log into the remote app and note the UID or device serial number used for connection. This retroactive documentation is not as good as starting right but is significantly better than nothing.

How long should CCTV footage be kept before overwriting?

Thirty days is the standard commercial retention period for most applications and is consistent with best practice guidelines. Residential systems often run shorter cycles β€” 7–14 days β€” because hard drive capacity and cost make longer retention expensive at higher resolutions. The key is that the retention period should be documented in your CCTV policy, and any incident footage should be exported and preserved separately as soon as an incident is identified, before the normal overwrite cycle removes it.

Is a CCTV policy legally required for businesses in Kenya?

Kenya’s Data Protection Act 2019 creates obligations for organisations processing personal data, which includes CCTV footage of identifiable individuals. While the Act does not prescribe a specific CCTV policy format, operating a surveillance system without documented policies, clear signage, and defined retention and access controls would likely be considered non-compliant. The Office of the Data Protection Commissioner has published guidance that businesses and organisations operating CCTV should follow.

What is the difference between a site survey and a site visit?

A site visit is when an installer comes to your property and looks around. A site survey is a structured assessment that produces a written report. Many installers in Kenya offer a “free site visit” which is essentially a sales call β€” the installer assesses whether the job is worth taking and gives a verbal quote. A genuine site survey produces documented findings about the property’s security needs, current gaps, environmental factors, and infrastructure, and that report forms the basis of the system specification. If no document is produced, it was a site visit, not a site survey.

Can I request documentation from my installer after the installation is complete?

Yes, and you should. Any professional installer should be able to provide an equipment list, coverage diagram, and system configuration record even if these were not originally given at handover. If an installer is unwilling to provide this information about a system they installed on your property, that is a significant concern β€” the documentation of your own security system belongs to you.

How should CCTV documentation be stored?

At minimum, keep a physical folder on site with printed copies of all key documents β€” equipment list, coverage diagram, configuration record, warranty documents, and user manual. Additionally, store digital copies in cloud storage β€” Google Drive, Dropbox, or similar β€” so they are accessible even if the physical copies are lost, damaged, or located in a property that becomes inaccessible. Do not store the DVR/NVR password document in a location accessible to unauthorised persons.


Documentation Is Part of the Installation

A professionally installed CCTV system and a well-documented CCTV system are not the same thing β€” but they should be. The hardware is what you see. The documentation is what makes it maintainable, legally defensible, and genuinely useful beyond the day it is switched on.

For property owners in Kenya, the practical takeaway is this: before accepting any CCTV installation as complete, ensure you have the equipment list, the login credentials, the coverage diagram, and the operating instructions in your hands. If your current system lacks these, it is not too late to build that documentation β€” start with what you can access now and work from there.

For anyone planning a new installation, ask about documentation standards before you sign anything. The installers who take documentation seriously tend to be the same ones who take everything else seriously too. It is one of the most reliable indicators of professional quality in a market where quality varies enormously.

Get a Fully Documented CCTV Installation from AreaSpy

Every AreaSpy installation comes with a written site survey, equipment register, coverage diagram, full login credentials, operating instructions, and a signed completion certificate. No guesswork, no missing paperwork, no locked-out owners. Fill in the form below to request a free site assessment.

CCTV QUOTE REQUEST