How to Vet Executive Protection Companies in Los Angeles
If I were a family office, chief of staff or UHNW family hiring an executive protection company in Los Angeles, I would not start with vehicles, weapons, former police titles or photographs of agents standing next to celebrities.
I would start with two questions.
Is this actually a properly licensed, insured and compliant California security company?
Then:
Who exactly is going to protect the principal after the contract is signed?
Those are separate questions.
A company can have a highly experienced founder and still staff an account poorly. A protector can have an impressive biography and still work inside a weak organization with inconsistent supervision, no trained relief team, poor information control and no meaningful process for handling an emerging threat.
A polished proposal can also hide operational problems.
The rate may look attractive while overtime, minimum hours, travel time, vehicles, advances, lodging and management fees remain undefined. The company may advertise armed executive protection while giving vague answers about the actual California authority under which its plainclothes personnel carry firearms. It may promise continuity while depending on whoever happens to be available that week.
I have spent enough time in private protection to know that executive protection is rarely won or lost in the sales presentation.
It is won or lost in the operation behind it.
That matters even more for a UHNW family because an executive protection company may receive access to information that almost nobody outside the household should have.
The principal’s residence.
Children.
Schools.
Family movements.
Aircraft schedules.
Vehicles.
Medical information.
Employees.
Travel.
Threat history.
Security systems.
And the periods when the family is away.
I would treat selection of an executive protection firm accordingly.

Key takeaways
- Verify the California PPO yourself. The California Bureau of Security and Investigative Services maintains a public license search for Private Patrol Operators, security guards, firearm permits and other regulated security credentials. Do not rely on a license number printed in a proposal. BSIS Verify a License.
- Verify the people, not just the company. California law requires a PPO to confirm that an employee performing security-guard functions holds a current and valid guard registration.
- A guard card is a regulatory baseline, not proof of executive protection competence. Current California requirements establish minimum licensing and training requirements. They do not establish whether somebody can manage a principal, conduct an advance, work around children, handle sensitive intelligence or operate inside an UHNW household.
- California changed guard training requirements in 2026. SB 652 took effect January 1, 2026 and requires the initial Power to Arrest and Appropriate Use of Force training to be instructed and certified by a single course provider and completed within six months before the guard application is submitted. BSIS SB 652 notice.
- Understand what armed actually means. A BSIS firearm permit is an exposed-firearm permit. It does not by itself authorize concealed carry. A plainclothes armed detail therefore deserves very specific licensing questions.
- Do not accept pending as current. BSIS processing data updated October 6, 2026 showed target processing times of 60 days for initial online guard registrations and 75 days for initial online firearm permits. A submitted application is not the same thing as a current credential. BSIS application processing times.
- Verify insurance beyond a generic certificate. California requires a PPO to maintain at least $1 million per occurrence in commercial general liability coverage, and BSIS states that the required coverage must be occurrence based rather than claims made.
- Understand who employs every protector. A security guard registration does not turn an individual into a security company. BSIS states that a guard registrant cannot independently contract out guard services. If personnel come from another company, identify that licensed company, its insurance and its supervision.
- Interview the proposed detail leader. For a long-term family account, that person can matter more to daily performance than the executive who gave the sales presentation.
- Demand a relief plan. Ask what happens when a core protector calls out sick, takes vacation, travels or reaches a fatigue limit.
- Evaluate training beyond state minimums. Executive protection requires capabilities that are not established by obtaining a guard registration.
- Treat medical readiness as a core capability. Ask about current CPR and AED competence, severe-bleeding response, equipment and hands-on refreshers.
- Evaluate information security. Principal schedules, residences, reports and threat information should not live indefinitely in personal text chains and uncontrolled devices.
- Normalize pricing before comparing rates. Minimum shifts, California overtime, double time, travel, vehicles, advances, holidays, lodging, mileage and cancellations can change the real cost materially.
- Use a written agreement with a clear scope. I did not find a special BSIS client-contract form specifically prescribed for executive protection. I would still require a detailed written service agreement reviewed by the family office and its counsel before deployment.
- Do not hire the proposal. Hire the operation capable of delivering the proposed standard after the sales process is over.
Why executive protection company due diligence matters in Los Angeles
Los Angeles has a particular combination of wealth, public visibility, entertainment, technology, family offices, private aviation, high-value residences and executives who move between several controlled and uncontrolled environments during one day.
That does not mean every wealthy person faces the same threat.
They do not.
But the local environment gives family offices another reason to evaluate whether a protection firm understands what is happening beyond its own marketing.
In November 2025, FBI Los Angeles said South American Theft Groups continued to affect Southern California and described actors using surveillance and technical tools while increasingly targeting the homes of celebrities and professional athletes. FBI Los Angeles.
In April 2026, the U.S. Attorney’s Office in Los Angeles announced that a Canyon Country defendant had pleaded guilty in a case involving a crime-tourism network that federal prosecutors said caused at least $23.9 million in burglary and theft losses around the country. U.S. Attorney Central District of California.
LAPD had also announced in August 2025 that a coordinated operation targeted a burglary crew the department linked to nearly 100 residential burglaries across Los Angeles.
I would not use those cases to frighten a client into buying manpower.
I would use them to test the company I am interviewing.
Can it explain the difference between residential burglary risk, targeted violence, stalking, workplace conflict, public exposure, extortion, kidnapping risk and ordinary opportunistic crime?
Does it understand how an issue at a residence affects the mobile protection detail?
Does it understand protective intelligence?
Can it change the protective posture when facts change?
Or does every risk somehow result in the same sales recommendation?
Step one: verify the California Private Patrol Operator
California regulates businesses that provide contract security through the Bureau of Security and Investigative Services.
BSIS describes a Private Patrol Operator as a business that protects persons or property or prevents theft. Its current PPO requirements include qualifying experience, an examination and criminal-history review. BSIS PPO information.
Before I spend time evaluating a company’s tactical claims, I would confirm that the company itself is legally in the business.
Use the official BSIS lookup
Ask for the PPO number.
Then search it yourself through BSIS Verify a License.
BSIS allows public searches for Private Patrol Operators, security guards, firearm permits and several other regulated credentials.
I would confirm:
- company name;
- license type;
- current status;
- expiration date;
- address where relevant;
- and any publicly displayed disciplinary information.
Do not verify from the company website
A PPO number printed on a website or proposal tells me what number the company wants me to see.
The BSIS record tells me what the regulator currently shows.
I would use the regulator.
Understand what the PPO proves and what it does not
A current PPO license matters.
It means the business cleared an important California regulatory threshold.
BSIS currently requires qualifying PPO experience that includes at least 4,000 hours of paid guard, patrol or watchman experience or qualifying equivalent experience, together with at least 2,000 hours of qualifying management or administrative experience with a licensed PPO. The qualified manager also goes through examination and criminal-history review.
That is meaningful.
But it does not establish that the company is good at executive protection.
A PPO license does not tell me whether the company can:
- manage a long-term UHNW family detail;
- conduct competent advance work;
- manage family-office communications;
- retain strong personnel;
- integrate residential and mobile protection;
- maintain medical readiness;
- handle a stalking problem;
- protect sensitive information;
- manage private aviation movements;
- or adapt calmly when the principal changes the plan.
I see licensing as the entry point.
The operational review begins after that.
Confirm the legal business entity behind the brand
A family may know a security company by a brand name while the actual PPO is held by a corporation using a DBA.
That can be completely legitimate.
I still want the structure to make sense.
Compare the names on:
- the proposal;
- service agreement;
- PPO license;
- certificate of insurance;
- invoice;
- and California business records.
The California Secretary of State makes corporation, LLC and limited-partnership records available through bizfile. Its public data can include entity name, status, registration information, addresses, agent for service of process and certain management information. California Secretary of State business records.
If the names are different, ask why.
There may be a straightforward answer.
The family office should still know which legal entity is accepting the contract and responsibility.
Ask who the qualified manager is
A California PPO operates with a qualified manager responsible for the licensed business.
That person may be the owner.
It may be someone else.
The qualified manager does not need to stand next to the principal every day.
I would still ask who that person is.
BSIS describes the qualified manager as the individual who manages the business on a day-to-day basis.
For the client, the practical question is:
Where does California regulatory accountability sit inside this company?
Verify the individual protectors
Company-level licensing is not enough.
California Business and Professions Code section 7583.8 states that a PPO may not permit an employee to perform security-guard functions without confirming that the person holds a current and valid security guard registration.
The client can check guard registrations through the same BSIS public system.
If a company proposes a four-person core team for a long-term UHNW account, I would want the names of those people before onboarding is complete.
I want to know:
- who the detail leader is;
- who the core protectors are;
- who normally works each shift;
- who the trained relief personnel are;
- and who may be inserted if the core team is unavailable.
A nationwide network is not a staffing answer
I hear versions of this frequently:
We have hundreds of agents in our network.
That may be useful for surge capacity.
It does not answer who is protecting the family tomorrow.
A family office should bring the conversation back to the actual account.
Know the 2026 California guard-training rules
California made a material training change effective January 1, 2026.
Under SB 652, the required Power to Arrest and Appropriate Use of Force training for a guard applicant must be instructed in its entirety and certified by one course provider. It must also be completed within six months before the guard application is submitted. A licensed security company can provide that training to its direct employees and applicants for employment. BSIS SB 652 notice.
Current BSIS training requirements also include three hours of Power to Arrest and five hours of Appropriate Use of Force at the initial stage. Registered guards then complete 32 hours of security-officer skills training within the first six months, with training staged during that period, and eight hours of continuing training annually. The annual requirement includes review of appropriate use-of-force topics. BSIS security guard training requirements.
Ask the company how it verifies compliance
I would ask:
- Who tracks guard training?
- Who verifies completion dates?
- Who checks annual continuing training?
- Who audits expired registrations?
- How does the company stop an expired employee from being scheduled?
- Does management receive expiration alerts?
- How quickly is the client told if an assigned protector loses required authorization?
The family office does not need to manage BSIS compliance for the vendor.
It should know the vendor has a system.
The California minimum is not executive protection training
A guard registration establishes the legal baseline for security-guard work.
It does not establish executive protection competence.
Those are different questions.
I would separately evaluate whether assigned protectors can perform the work the principal actually requires.
That can include:
- advance work;
- protective movements;
- vehicle arrivals and departures;
- executive driving where assigned;
- protective intelligence reporting;
- residential integration;
- medical response;
- de-escalation;
- professional interaction with family and staff;
- incident writing;
- shift handovers;
- travel operations;
- and calm decision-making under changing conditions.
Ask how the company trains after hiring
Useful questions include:
- How frequently does the company conduct in-person training?
- Which training is mandatory for the executive protection team?
- Who teaches it?
- Are protectors evaluated or simply marked present?
- How is poor performance corrected?
- Are scenario exercises based on the work the team actually performs?
- Are relief personnel trained to the same account standard?
- Does the detail leader participate in training?
- Does management review training records?
I am less interested in a wall of certificates than whether training changes performance.
Do not accept pending credentials as deployment authority
This is especially relevant in 2026 because BSIS continues to publish application-processing times.
As of October 6, 2026, the Bureau listed a target timeframe of 60 days for an initial online security guard application and 75 days for an initial online firearm permit. Those figures can change because BSIS updates the page weekly.
The practical client lesson is simple.
Applied is not the same as current.
If a company proposes an armed protector, verify the person’s current permissions.
If somebody is waiting for approval, schedule somebody else who already holds what the assignment requires.
Armed executive protection requires more specific vetting
The word armed is not enough.
BSIS describes its firearm permit as an exposed-firearm permit. The permit authorizes a qualified holder to carry an exposed loaded firearm of an approved caliber while performing duties associated with the qualifying license or registration.
BSIS does not issue California concealed-carry licenses.
The California Department of Justice states that carrying a concealed weapon in public generally requires a valid CCW license issued through an authorized sheriff or police department, subject to the current California statutory framework. California DOJ CCW information.
That distinction matters in plainclothes executive protection
If a company proposes an armed plainclothes protector, I would ask:
What specific California authority allows this individual to carry the firearm in the manner proposed?
I do not need a long speech.
I want a clear answer.
Guard registration.
BSIS firearm permit where required.
Applicable concealed-carry authority.
Current status.
California concealed-carry rules changed again in 2026
California DOJ issued additional firearms-law updates in 2026, including changes under AB 1078 affecting CCW eligibility and nonresident licensing, followed by additional CCW updates later in the year. That is another reason I do not want a provider relying on what somebody remembers the law to have been several years ago. California DOJ firearms information bulletins.
The company should know what authority its assigned personnel have today.
Verify current firearm qualification
Current BSIS firearm-permit renewal requirements call for four range qualifications during the two-year permit term: two during each 12-month period, with no two qualifications closer than four months apart. BSIS also requires use-of-force and de-escalation review before those qualifications and a written firearms examination during the permit term. BSIS firearm permit requirements.
That still does not establish advanced executive-protection firearms ability.
It establishes another regulatory item the family office can verify.
Do not assume off-duty law enforcement solves the licensing question
Law-enforcement experience can be valuable.
I came from law enforcement myself.
But I would never tell a client that a police title makes the California private-security rules disappear.
BSIS publishes specific exemptions for qualifying peace officers from certain fingerprint, training and range-requalification requirements. Those exemptions are limited and condition specific. The Bureau also states that firearm-permit issuance is tied to a qualifying BSIS license or registration. BSIS peace officer exemptions.
If a company builds its staffing model around off-duty officers, ask it to explain the actual licensing and employment structure.
Do not stop at:
They are cops.
Understand who employs the protectors
This is a major family-office due-diligence question.
Ask:
Are the protectors assigned to us employees of your company?
If the answer is no, keep going.
Who employs them?
Which PPO is responsible for them?
Whose insurance applies?
Who supervises them?
Who holds their training records?
Who disciplines them?
Who receives their incident reports?
Who replaces them?
A guard card is not a freelance business license
BSIS currently states in its security guard application information that a guard registrant cannot contract out their security services directly and must instead be an employee of the person or business for which security services are being provided.
That matters because the UHNW security market includes a large pool of individuals who describe themselves as independent executive protection agents.
If another licensed PPO is supplying personnel to the company you hired, that can be examined as a business relationship.
If the answer is simply that an individual has a guard card and sends an invoice, I would ask more questions.
Why I value career protectors on long-term family accounts
For a one-day event, personnel may come together temporarily.
A long-term UHNW detail is different.
Continuity creates knowledge.
A consistent protector learns:
- family members;
- household employees;
- normal vehicles;
- regular visitors;
- family preferences;
- children’s routines;
- normal vendors;
- frequent destinations;
- medical considerations;
- communication preferences;
- and the normal baseline around the principal.
That baseline matters.
If the protector changes every few days, that knowledge keeps walking out the door.
Ask for the turnover picture
I would ask a company:
- How long have the proposed protectors worked for you?
- How long has the proposed detail leader worked for you?
- How frequently do long-term accounts rotate personnel?
- What caused turnover on comparable accounts?
- How do you keep strong people?
- What happens when the client asks for a protector to be replaced?
The client is not entitled to confidential employee information.
It is reasonable to understand whether the staffing model is stable.
Ask for the relief model before you need it
One of my favorite questions is:
Your night protector calls out at 3:00 p.m. for a 6:00 p.m. shift. What happens?
I want a specific answer.
Not:
We will find somebody.
I want to know whether the company maintains relief personnel who are:
- already licensed;
- already vetted;
- already trained;
- already familiar with the account;
- already briefed on client confidentiality;
- and capable of stepping into the role without starting from zero.
Ask how many people know the account
If a schedule requires four regular protectors, I would not want exactly four people to be the entire institutional memory.
Vacations happen.
Illness happens.
Training happens.
Family emergencies happen.
Travel happens.
A mature staffing plan anticipates normal human life.
Spend serious time with the proposed detail leader
For a long-term family account, I would rather spend an hour talking with the person who will run the detail than another hour hearing corporate marketing.
The detail leader will influence:
- standards;
- discipline;
- communication;
- reporting;
- principal relationship;
- staff relationships;
- training;
- relief quality;
- and whether small problems are corrected before they become large ones.
Ask scenario questions
I would ask:
The principal changes the destination while the vehicle is moving. What do you do?
A person appears repeatedly near the residence but has not made a threat. What do you do?
A family member does not want to follow a security procedure. What do you do?
The driver is not at the airport when the aircraft lands. What do you do?
A nanny reports an unusual message involving a child. What do you do?
A protector is technically competent but rude to household staff. What do you do?
The principal wants to leave through an entrance you did not plan to use. What do you do?
The day runs four hours longer than planned. What do you do about fatigue?
I am looking for judgment.
Not theater.
Ask who manages the detail leader
A long-term account should not become an island.
Company leadership needs continuing visibility.
Ask:
- Who supervises the detail leader?
- How often does management review the account?
- Who reviews client feedback?
- Who reviews incident patterns?
- Who audits training status?
- Who resolves conflict between the client and the detail leader?
- Who checks whether the proposal is still being delivered six months later?
If the founder disappears after signature and the client never hears from company management again, that tells me something.
Medical readiness deserves separate vetting
I would not stop at:
Are your agents CPR certified?
That question is too broad.
I would ask:
- Which certification is required?
- Is it current?
- When did the protector last perform hands-on CPR practice?
- Do protectors train on one-rescuer CPR?
- Two-rescuer CPR?
- AED use?
- Severe bleeding?
- Choking?
- What medical equipment is carried?
- Who checks expiration dates?
- Who checks the AED?
- What equipment travels with the principal?
- What happens when the principal travels internationally?
A serious medical event is a very realistic protection problem.
I want the company’s training priorities to reflect that.
Ask about driving as its own skill
A person can be a capable protector and an average driver.
Do not assume one proves the other.
If protectors will drive the principal, ask:
- Who is expected to drive?
- What driving training have they received?
- How recent is that training?
- Does the company review driving records?
- Does the protector routinely drive large SUVs?
- Who maintains company vehicles?
- What commercial auto coverage applies?
- What happens if the primary vehicle is unavailable?
- How does the company manage fatigue before long drives?
A family office should also decide whether it wants a dedicated professional driver, a protector-driver or a mixed model based on the assignment.
Ask how advance work actually happens
Good executive protection often looks easy because work was done before the principal arrived.
When vetting the firm, ask:
- Who conducts advances?
- What triggers an advance?
- How are venues contacted?
- How are arrival and departure points confirmed?
- How are medical and emergency considerations addressed?
- How are transportation changes communicated?
- How does the working protector receive the information?
- How are updates recorded?
- Who owns the advance when outside personnel are used?
The company should be able to explain the process without disclosing another client’s confidential information.
Ask how protective intelligence reaches the working detail
Protective intelligence does not require a giant command center.
It does require an intake process.
If the family receives:
- persistent unwanted messages;
- threatening communications;
- repeated unwanted approaches;
- possible surveillance;
- a suspicious gate visit;
- contact involving children or staff;
- or escalating fixation behavior;
where does that information go?
Ask who owns the case
Detail leader?
Company security director?
Protective-intelligence staff?
Family office?
Another provider?
I do not care which organizational chart the answer uses.
I care that there is an answer.
Ask whether historical information survives staff changes
A person of concern can disappear for months and return.
If the previous reports existed in the phone of an agent who left the company, the new contact can look like the first incident.
That weakens the protective picture.
Threat history should belong to the protection program, subject to the client’s data policies, rather than to one individual’s memory.
Information security should be part of the company interview
Every executive protection company says it is discreet.
I would ask what that means operationally.
Where is the principal’s schedule stored?
Where are residential addresses stored?
Where are incident reports stored?
Who can access them?
Can temporary personnel see months of family information?
Can departing employees still access the platform?
Are personal email accounts used?
Are sensitive updates sent through ordinary group texts?
Are photographs stored automatically in personal cloud photo libraries?
Does the company have an access-removal process when somebody leaves?
An NDA is not the entire security system
An NDA can be useful.
It does not stop:
- weak account permissions;
- shared passwords;
- uncontrolled forwarding;
- personal-device storage;
- screenshots;
- or former personnel retaining access.
I would ask about the process behind the confidentiality agreement.
Ask about social media
Can agents photograph the client?
Can they follow the principal publicly?
Can they post from the residence?
Can they identify the client on LinkedIn?
Can they post the private aircraft?
Can they announce that they are protecting a billionaire in Malibu?
The answer should be very clear.
Incident reporting should be part of due diligence
Ask for a blank or fully sanitized example of the company’s standard incident-report structure.
You are not asking for another client’s confidential report.
You are asking whether the company knows how to document an event.
I want to know:
- what gets reported;
- who receives it;
- how quickly it is distributed;
- how photographs or video are handled;
- who assigns follow-up;
- and whether management can identify recurring patterns.
Some incidents also trigger BSIS reporting
BSIS currently states that Private Patrol Operators and security guards must submit an incident report to the Bureau within seven business days for qualifying incidents involving a physical altercation, firearm discharge or use, or use of a deadly weapon while on duty. BSIS incident reporting.
I would ask the provider:
Who inside your company determines whether an incident triggers a BSIS filing, and who confirms it was completed?
That tells me something about its compliance infrastructure.
BSIS enforcement makes license verification more than paperwork
California has continued active enforcement against unlicensed and noncompliant private-security activity.
In an August 2025 BSIS enforcement update, the Bureau reported that unlicensed activity represented more than one-quarter of open investigations and 45 percent of citations issued during the referenced fiscal-year period. BSIS also described joint compliance sweeps with local law enforcement.
The Department of Consumer Affairs later reported BSIS participation in joint enforcement operations and continued focus on unlicensed activity in the private-security sector.
My takeaway for a family office is straightforward.
Do the verification.
Verify general liability insurance properly
California requires licensed PPOs to maintain commercial general liability insurance with at least $1 million per occurrence for bodily injury, death or property damage. BSIS PPO insurance requirements.
BSIS also requires the certificate to align with the licensed PPO entity and include the policy number, policy period and PPO information. The Bureau specifically states that the required coverage must be occurrence based; claims-made coverage does not satisfy the PPO licensing requirement.
Request a current certificate of insurance
I would verify:
- insured legal entity;
- carrier;
- policy number;
- effective dates;
- general liability limits;
- and whether the entity matches the PPO and contract.
I would also have the family office’s insurance adviser or counsel review the insurance requirements for the actual engagement.
The California minimum may not match the risk the client faces
$1 million per occurrence is the regulatory floor for PPO general liability.
That does not mean a family office has to accept that amount as the complete insurance program for a substantial UHNW engagement.
Depending on the scope, the client’s advisers may want to examine:
- higher general liability limits;
- umbrella or excess liability;
- commercial automobile liability;
- workers compensation;
- employment-related coverage;
- cyber coverage where sensitive data is maintained;
- and contract-specific insurance requirements.
I would let the client’s legal and insurance professionals determine the appropriate limits and endorsements.
The executive protection company should be able to provide documentation.
Verify workers compensation
California employers with one or more employees generally must provide workers compensation coverage. The California Department of Industrial Relations states that even an employer with one employee must satisfy the requirement. California Division of Workers Compensation.
This is another reason I care about the staffing model.
If the provider says its entire protection force consists of independent operators, I would want the family office to understand exactly who employs and insures the people being assigned.
Verify commercial auto coverage when the company drives
If the executive protection firm provides vehicles or drivers, I would ask:
- Who owns the vehicle?
- Who leases it?
- Who maintains it?
- Whose insurance covers it?
- What commercial auto limits apply?
- Who is approved to drive it?
- What happens with rentals?
- What happens when a client-owned vehicle is used?
General liability and automobile liability are different issues.
I would not assume one solves the other.
Use a written executive protection agreement
I reviewed the current BSIS consumer and licensing pages for this article and did not find a special statewide BSIS contract template specifically prescribed for executive protection clients.
I am not going to invent one.
I would still never put a significant family-office protection program in place on the strength of texts, emails and a verbal hourly rate.
A detailed written agreement protects both sides by defining what the company is actually being hired to provide.
Have counsel review the agreement
This article is about operational procurement, not legal drafting.
For a substantial UHNW or corporate engagement, the client should have qualified counsel review the contract.
The scope should be specific
The agreement or associated scope of work should answer basic questions.
- How many protectors?
- What coverage hours?
- Armed or unarmed?
- Plainclothes or uniformed?
- Dedicated detail leader?
- Protective driver?
- Vehicle provided?
- Advance work included?
- Residential support included?
- Travel included?
- Protective-intelligence support included?
- Incident reporting included?
- Management oversight included?
- What happens outside the defined scope?
Ambiguity becomes expensive later.
Define personnel substitution
I would want the contract to address whether the provider can replace assigned personnel without notice.
For a long-term UHNW account, I prefer a defined process.
If somebody needs emergency relief, the company should be able to act.
The family office should also know who has been inserted into the protective environment.
Define confidentiality and data ownership
Who owns:
- shift reports;
- incident reports;
- threat files;
- advance information;
- photographs;
- principal preference information;
- and account records?
What happens to that information after termination?
How much can the provider retain?
Who can access it?
Those questions should not be left until the relationship ends badly.
Define termination and transition
Protection contracts end.
When they do, continuity matters.
The agreement should address:
- notice requirements;
- return of client property;
- return or revocation of credentials;
- transfer of relevant client-owned information;
- removal of system access;
- final invoicing;
- and transition assistance where appropriate.
A family should not lose its own threat history because it changed security companies.
Compare total operating cost, not the advertised hourly rate
This is one of the easiest procurement mistakes to make.
Company A quotes a lower hourly number than Company B.
That tells me very little until I know the billing model.
I would normalize:
- minimum billable hours;
- overtime;
- double time;
- holiday rates;
- travel time;
- advance time;
- vehicle charges;
- mileage;
- fuel;
- parking;
- airfare;
- lodging;
- per diem;
- management charges;
- equipment;
- cancellations;
- schedule extensions;
- and standby time.
California overtime can materially change a protection invoice
California’s general overtime rules require time-and-a-half for nonexempt employees after eight hours in a workday up to 12 hours, as well as after 40 hours in a workweek, with double time generally applying after 12 hours in a workday and in specified seventh-day situations. Exceptions can apply depending on lawful schedules and classifications. California DIR overtime information.
Executive protection regularly involves 10-, 12-, 14- or 16-hour operational days.
A family office should understand how the vendor’s billing reflects that reality.
Ask for a sample invoice scenario
I would give each finalist the same hypothetical week.
For example:
- five local 12-hour days;
- one 16-hour evening event;
- one early-morning airport movement;
- one same-day trip to San Francisco;
- one vehicle;
- and one advance.
Ask each company to show what the invoice would look like.
Now the family office can compare economics rather than marketing rates.
Ask what happens when the principal runs late
An executive dinner scheduled to end at 8:00 p.m. ends after midnight.
What happens?
The protector should not abandon a required assignment because the calendar changed.
But there are still questions:
- How is the extension billed?
- At what point does fatigue become an operational concern?
- Can relief be brought in?
- Does the same agent return at 6:00 a.m.?
- Who makes that decision?
Fatigue management is a client issue
A company can make a proposal look less expensive by assuming the same person will work extremely long days repeatedly.
I do not automatically view that as a benefit.
Ask the firm how it handles:
- long event days;
- overnight travel;
- early airport movements;
- international arrivals;
- late schedule extensions;
- and short turnarounds between shifts.
A person can still be physically present while no longer operating at the standard the assignment requires.
Do not let manpower become the measure of sophistication
A firm recommending six agents is not automatically more capable than a firm recommending two.
I want to know why each position exists.
Ask:
What risk does this position address?
What function does this person perform?
What changes if the person is removed?
Can the requirement be addressed another way?
Manpower should follow the problem.
The company should be asking the family serious questions
A provider cannot design a thoughtful long-term executive protection program without understanding the client.
Before prescribing a large team, I would expect questions about:
- the principal;
- spouse or partner;
- children;
- residences;
- family office;
- corporate environment;
- public profile;
- known threats;
- previous incidents;
- litigation;
- activism or controversy;
- travel;
- aircraft;
- vehicles;
- medical considerations;
- events;
- current security;
- household staffing;
- and lifestyle.
If the company barely knows the family and already knows exactly how many agents it wants to sell, I would ask how it reached that conclusion.
How a family office should run the selection process
I would make the process structured enough that every company is answering the same core questions.
Phase one: regulatory desk check
- Verify PPO.
- Verify legal entity.
- Review publicly available license status and discipline.
- Request current insurance.
- Identify the proposed detail leader.
- Identify employment model.
Phase two: written capability response
Ask each company to explain:
- staffing model;
- relief coverage;
- training;
- medical readiness;
- armed licensing where applicable;
- protective-intelligence process;
- advance capability;
- information security;
- reporting;
- travel support;
- management oversight;
- and pricing assumptions.
Phase three: operational interview
Interview:
- company leadership;
- account manager;
- proposed detail leader;
- and, for a major long-term account, representative core-team members.
Phase four: scenario testing
Give each company the same realistic scenarios.
Do not reward dramatic answers.
Evaluate judgment.
Phase five: document verification
Before final award, collect the records necessary to substantiate material claims.
Phase six: contract normalization
Compare the same scope, schedule and assumptions.
Phase seven: 30-day operational review
Do not assume contract signature ends the selection process.
The first month should confirm that the company can actually perform.
Documents I would request from a finalist
- California PPO license information;
- legal contracting entity information;
- current certificate of general liability insurance;
- workers compensation certificate where applicable;
- commercial auto evidence if vehicles or driving are included;
- umbrella or excess liability evidence if contractually required;
- names of proposed core protectors;
- current guard registration information for assigned personnel;
- current firearm permit information where applicable;
- confirmation of concealed-carry authority where the proposed assignment requires it;
- training matrix for the proposed team;
- current CPR or medical qualification information relevant to the assignment;
- description of relief staffing;
- redacted or blank incident-report format;
- description of information-security controls;
- social-media and client-photography policy;
- sample invoice based on the client’s operating scenario;
- proposed service agreement;
- and authorized references where available.
I would not ask a company to disclose another client’s protected information to prove competence.
Comparable references should respect confidentiality
Executive protection is confidential work.
I become cautious when a company proves its discretion by casually telling me private information about other families.
A provider may still be able to offer:
- authorized family-office references;
- authorized corporate references;
- estate-manager references;
- or anonymized descriptions of comparable operational experience.
Ask about the work without demanding somebody else’s secrets.
Questions for references
I would ask:
- Did the company deliver the personnel it proposed?
- How stable was the team?
- Did management stay involved?
- How were callouts handled?
- Were reports useful?
- Did billing match expectations?
- How did the company respond to criticism?
- How did it handle a protector who was not a fit?
- Did confidentiality remain strong?
- Would you hire the company again?
Red flags I would take seriously
The California PPO is unclear
The company cannot clearly identify the licensed entity providing the service.
The company resists independent verification
A legitimate provider should expect sophisticated clients to verify credentials.
The actual team is never identified
The biographies are impressive, but nobody can tell you who will work the account.
The sales team is the company
Senior personnel are everywhere during procurement and vanish immediately after award.
There is no relief model
The answer to every staffing emergency is that someone will make calls.
The company relies heavily on individual freelancers without explaining the licensed structure
The buyer should know who employs, licenses, insures and supervises each person.
Armed plainclothes personnel come with vague legal answers
Ask for the actual current authority.
The conversation centers on weapons
Firearms can be appropriate.
If the company has far more to say about guns than it does about medical readiness, planning, intelligence, staffing, communication and judgment, I would notice that.
No current insurance documentation
That is basic procurement.
The insurance entity does not match the contracting structure
Resolve it before deployment.
No explanation of workers compensation
Especially concerning when the firm claims to employ a significant staff.
No information-security system
The complete answer is that everyone signs an NDA.
No reporting process
The company cannot show how information moves from agent to detail leader to management to client.
No training records
The company says its personnel train constantly but cannot explain how training is documented or evaluated.
No account-management process
The plan is to send agents and figure things out later.
The proposal is cheap because it assumes excessive hours from the same people
That can create a fatigue problem disguised as savings.
The rate is clear but expenses are not
Travel, vehicles, lodging, overtime and minimums can completely change the real cost.
Famous clients are used casually as proof
That can raise its own confidentiality question.
The company promises an outcome nobody can promise
Protection reduces risk and improves options.
No company controls every action another person may take.
Ask what happens when the threat level rises
A low-profile family may hire a discreet two-person operation.
Six months later something changes.
A public lawsuit.
A business dispute.
A hostile former employee.
A stalking concern.
Doxxing.
An online fixation.
A concerning approach at the residence.
A high-profile transaction.
Media attention.
The company should be able to explain how it reassesses and scales.
Ask:
- Who conducts the reassessment?
- Who receives threat information?
- How quickly can additional vetted personnel be added?
- How is residential security brought into the picture?
- Can travel procedures change?
- Who handles law-enforcement liaison?
- How does the family office stay informed?
Ask the reverse question too
If the risk decreases, can the protective footprint come down?
I do not believe in maintaining unnecessary manpower indefinitely because an account began during a crisis.
Protection should follow the current risk picture.
Ask how the company operates outside Los Angeles
A Los Angeles executive protection firm may perform very well locally.
A UHNW family often travels.
Ask what happens in:
New York.
Miami.
London.
Paris.
Tokyo.
Dubai.
Or another city where the company does not maintain its normal core personnel.
Questions include:
- Does the core protector travel?
- Who sources local support?
- Who vets local personnel?
- Who verifies licensing?
- Who controls client information?
- Who briefs the local team?
- Who remains in charge?
- How are vehicles sourced?
- How are local advances reviewed?
A network is useful when the network is managed.
Ask what the first 30 days will look like
This question exposes whether the provider has actually thought through onboarding.
If we sign today, walk me through the first 30 days.
I would expect a thoughtful long-term program to address areas such as:
- kickoff with family-office leadership;
- principal preferences;
- family requirements;
- emergency contacts;
- medical considerations;
- core-team selection;
- relief-team preparation;
- residential familiarization where relevant;
- vehicle and route familiarization;
- staff introductions;
- communication channels;
- reporting;
- protective-intelligence intake;
- credentialing;
- information access;
- and a formal early review.
The first month should build baseline knowledge
The team needs to understand normal.
Normal family.
Normal staff.
Normal vehicles.
Normal visitors.
Normal vendors.
Normal movement.
Normal schedules.
Normal behavior around the residence.
Once the team understands that baseline, deviations become easier to recognize.
The family office should evaluate the provider during onboarding
Ask:
- Are personnel arriving on time?
- Are they discreet?
- Do they fit the household?
- Are they professional with staff?
- Are reports useful?
- Does the detail leader communicate appropriately?
- Does management respond?
- Are staffing changes handled cleanly?
- Are confidential details being controlled?
- Is the company delivering what the proposal promised?
Correct problems early.
Build a few measurable expectations into a long-term program
I would not bury a family detail under dozens of corporate KPIs.
A few measurable items can create accountability.
- scheduled shift coverage;
- late arrivals;
- license and permit compliance;
- training currency;
- incident-report timeliness;
- relief staffing;
- management reviews;
- open corrective actions;
- and client feedback.
The purpose is not bureaucracy.
It is knowing whether the promised protection program is actually operating.
A practical family-office scorecard
I would make regulatory items pass or fail.
A provider does not earn extra points for holding the license required to perform the work.
After that, compare companies across consistent operational categories.
Regulatory status
- Current California PPO.
- Clear qualified manager.
- Clear legal entity.
- Current assigned personnel credentials.
- Current armed credentials where applicable.
Insurance
- General liability.
- Workers compensation.
- Commercial automobile where applicable.
- Additional client-required coverage.
Personnel
- Proposed detail leader.
- Core team.
- Experience relevant to the principal.
- Family compatibility.
- Staffing continuity.
Relief capability
- Number of relief personnel.
- Account familiarity.
- Callout process.
- Replacement approval.
Training
- Frequency.
- In-person component.
- Evaluation.
- Medical.
- Driving where relevant.
- Executive-protection skills.
Operations
- Advances.
- Transportation.
- Shift handovers.
- Travel.
- Emergency procedures.
Protective intelligence
- Information intake.
- Case ownership.
- Historical retention.
- Escalation.
- Law-enforcement liaison.
Information security
- Schedule control.
- Address control.
- System access.
- Personal-device policy.
- Offboarding.
Management
- Account supervision.
- Leadership availability.
- Performance correction.
- Client review process.
Economics
- Base rate.
- Minimums.
- Overtime.
- Vehicles.
- Travel.
- Expenses.
- Cancellation.
- Total modeled cost.
Questions I would ask every executive protection company in Los Angeles
- What is the California PPO license number of the company that will contract with us?
- Who is the qualified manager?
- What legal entity will appear on the contract and invoice?
- Who is our proposed detail leader?
- Will that person actually work and manage the account?
- Who supervises the detail leader?
- Who are the proposed core protectors?
- Can we independently verify their guard registrations?
- Are the protectors your employees?
- If not, which licensed company employs them?
- Who insures outside personnel?
- How many relief protectors will be familiar with the account?
- What happens when someone calls out hours before a shift?
- How are replacement personnel approved?
- What training is required beyond California minimums?
- How frequently does in-person training occur?
- How is performance evaluated?
- What medical training is required?
- What medical equipment is carried?
- If personnel are armed, what current authority applies to the actual manner of carry?
- How do you track guard and firearm permit expirations?
- Can we receive a current certificate of insurance?
- What general liability coverage applies?
- What workers compensation coverage applies?
- What auto coverage applies when your personnel drive?
- What excess or umbrella coverage exists?
- Who performs advance work?
- How does advance information reach the assigned protector?
- How do you document concerning behavior?
- Who owns a developing threat case?
- When does the company contact law enforcement?
- How are principal schedules protected?
- Where are residential addresses stored?
- How are incident reports stored?
- What access does a temporary relief protector receive?
- What happens to system access when somebody leaves?
- What is the policy on client photography and social media?
- How does one shift hand information to another?
- How do you manage fatigue?
- How does the rate change during long days?
- What is the daily minimum?
- How are travel days billed?
- How are vehicles billed?
- How are lodging and airfare billed?
- What is the cancellation policy?
- Which additional charges can appear outside the base rate?
- How quickly can the detail scale if the threat changes?
- How does the detail contract again if the threat decreases?
- How do you support the principal outside California?
- Can you provide an authorized comparable reference?
- What happens during the first 30 days after contract award?
What I would not use as the primary selection criteria
Height
Physical capability can matter.
It is not a substitute for judgment.
A police title by itself
Law-enforcement experience can provide valuable skills.
The family still needs to evaluate private-protection experience, compliance, discretion and client fit.
A military unit by itself
Military experience can be highly relevant to certain skills.
Protecting an UHNW household is a different operating environment.
A huge network
Scale can be useful.
I still need to know who is working the account.
Weapons
Equipment does not prove judgment.
Luxury SUVs
Transportation matters.
The vehicle does not replace planning.
Celebrity name dropping
I consider uncontrolled disclosure of other clients a negative indicator.
The lowest hourly number
Price should be evaluated in context of staffing stability, leadership, training, insurance, total billing and execution.
Frequently asked questions
How do I verify an executive protection company in California?
Start with the official BSIS public license search. Verify the business under Private Patrol Operator and then separately verify the assigned guards and firearm permits where applicable. BSIS Verify a License.
What is a California PPO?
A Private Patrol Operator is the regulated California business category for companies providing contract security services to protect persons or property or prevent theft. BSIS requires qualifying experience, an examination and criminal-history review.
Does a PPO license prove executive protection competence?
No. It proves an important licensing threshold. The family still needs to evaluate personnel, management, training, medical readiness, advance capability, intelligence, travel, driving, information security and staffing continuity.
Should I verify each assigned protector?
Yes. California law requires a PPO to confirm that employees performing security-guard functions hold a current and valid guard registration. BSIS provides a public lookup.
What changed in California guard training in 2026?
SB 652 took effect January 1, 2026. The required Power to Arrest and Appropriate Use of Force instruction must be completed through a single course provider and within six months before the guard application is submitted.
How much initial security guard training is required?
Current BSIS requirements include Power to Arrest and Appropriate Use of Force training before registration, followed by 32 hours of security-officer skills training during the first six months. BSIS also requires eight hours of continuing training annually.
Does a guard card make someone an executive protection professional?
No. The guard registration is a California regulatory requirement. Executive protection competence must be evaluated separately.
Can a guard work while the registration application is pending?
A family office should verify the current legal status before deployment rather than assuming an application is enough. BSIS publishes current registration information and processing times. As of October 6, 2026, the Bureau showed substantial target processing periods for initial guard and firearm applications.
What insurance must a California PPO maintain?
BSIS requires at least $1 million per occurrence in commercial general liability coverage as a condition of PPO licensure. The required policy must provide occurrence coverage rather than claims-made coverage.
Is the California $1 million minimum enough for a UHNW family?
That is the regulatory minimum. The family office should have its insurance adviser and counsel decide whether the engagement calls for higher liability limits or additional coverage.
Should I ask for workers compensation coverage?
Yes. California generally requires employers with one or more employees to provide workers compensation.
Should I ask for commercial auto insurance?
Yes when the protection provider supplies vehicles or drivers. The client should understand who owns the vehicle, who is insured to drive it and which policy responds.
What is a BSIS firearm permit?
BSIS issues an exposed-firearm permit to qualified private-security licensees and registrants who satisfy current eligibility, screening, training and qualification requirements.
Does a BSIS firearm permit allow concealed carry?
No. BSIS describes the permit as an exposed-firearm permit. California concealed carry is governed separately.
Why does that matter for executive protection?
Executive protection is frequently conducted in plain clothes. If armed personnel are proposed, the family office should ask the company to identify the current legal authority supporting the actual manner of carry.
How often does a BSIS firearm permit holder qualify?
For renewal, BSIS currently requires four range qualifications during the two-year permit term, with two during each 12-month period and spacing requirements between qualifications.
Can an off-duty police officer automatically work private executive protection?
Do not assume that police employment removes private-security requirements. BSIS publishes specific peace-officer exemptions, but they are limited. The provider should be able to explain the licensing structure for the actual assignment.
Can an individual guard card holder freelance directly to a UHNW family?
BSIS states that a security guard registrant cannot contract out guard services directly and must be employed by the person or business for which the security services are being performed. When a family hires a security company, it should understand which licensed entity employs and supervises the assigned personnel.
Should I prefer employee protectors?
For long-term family protection, I place substantial value on a stable core team because continuity builds knowledge of the principal, household and normal environment. Other staffing structures can be appropriate for short assignments or travel, but the client should understand how outside personnel are licensed, vetted, trained, insured and supervised.
What should I ask about subcontracted personnel?
Ask which licensed company employs them, whose insurance applies, who verifies credentials, who trains them, who supervises them, who receives reports and whether the client is notified before they are assigned.
Who should I interview besides company leadership?
For a long-term account, interview the proposed detail leader. I would also want meaningful information about the proposed core team.
Why is the detail leader important?
The detail leader shapes daily standards, personnel performance, reporting, client communication, shift handovers and the relationship between security and the family office.
What is relief coverage?
It is the company’s prepared method for maintaining the required protection when a core protector is sick, traveling, training, on vacation or otherwise unavailable.
What should I ask about medical readiness?
Ask about current CPR and AED competence, severe-bleeding response, hands-on refreshers, carried equipment, equipment inspections and how medical capability follows the principal during travel.
What should I ask about executive driving?
Ask who drives, what recent driving training that person has, whether driving records are reviewed, what vehicles are used, how vehicles are maintained, what insurance applies and how fatigue is managed.
What should I ask about protective intelligence?
Ask where concerning information goes, who assesses it, how history is retained, how information reaches the working detail and what triggers law-enforcement involvement.
What should I ask about information security?
Ask where schedules, residential addresses, travel information and incident reports are stored; who can access them; what temporary personnel can see; and how access is removed when someone leaves.
Is an NDA enough for UHNW executive protection?
No. An NDA is useful, but practical confidentiality also depends on access controls, secure systems, disciplined personnel and offboarding.
What should I ask about incident reporting?
Ask how incidents are documented, who receives reports, how quickly reports are completed, how supporting evidence is handled and who owns follow-up actions.
Does BSIS require reporting of serious guard incidents?
Yes. BSIS states that PPOs and guards must report qualifying physical altercations, firearm incidents and use of deadly weapons within seven business days.
How should I compare executive protection prices?
Compare the complete operating model. Include minimum hours, overtime, double time, holidays, advances, travel time, vehicles, mileage, lodging, airfare, per diem, cancellation and other charges.
Why does California overtime matter?
Executive protection frequently involves long days. California generally requires daily overtime after eight hours for nonexempt employees and double time after 12 hours, subject to applicable exceptions. Those labor costs can influence a provider’s billing model.
Should a family office ask for a written contract?
Yes. I would use a detailed written service agreement defining scope, personnel model, pricing, confidentiality, substitution, travel, termination, information ownership and other terms relevant to the engagement, with qualified counsel reviewing significant contracts.
Does BSIS have a special executive protection contract form?
I did not find a special statewide BSIS executive protection client-contract form in the current licensing and consumer information I reviewed in October 2026. I would therefore not claim that one exists.
What should a long-term executive protection contract say about personnel?
It should make the staffing assumptions clear and address how substitutions, relief personnel and material team changes are handled.
What should I ask about confidentiality in the contract?
Address sensitive client information, reports, photographs, system access, social media, information ownership, retention and what happens when the relationship ends.
What are important red flags when hiring an executive protection company?
Unclear licensing, vague staffing, weak relief coverage, no current insurance documentation, ambiguous armed authority, unstable personnel, no medical program, undefined information security, hidden billing assumptions and inability to explain the first month of operations would all concern me.
Should the cheapest executive protection company win the contract?
No. Price should be compared alongside staffing quality, continuity, compliance, leadership, training, insurance, systems and total cost.
Should a company provide references?
Authorized references can be useful. A company should also protect existing client confidentiality, so I would not penalize a provider for refusing to disclose private client names without permission.
What should happen during the first 30 days?
The company should establish the core team, relief structure, client preferences, family-office contacts, communication channels, medical information, reporting, protective-intelligence intake, relevant residence and route familiarization, emergency contacts and management review.
How should a family office compare several companies fairly?
Give each company the same scope assumptions, due-diligence questions and operating scenarios. Treat regulatory compliance as pass or fail, then compare the operational system, personnel, leadership, information security and total economics.
Does the company founder need to personally protect the principal?
No. A security company should be judged on whether the organization it built can deliver the contracted standard through its assigned personnel and management structure.
Closing thought
When I evaluate an executive protection company, I keep coming back to the same principle.
Do not hire the proposal.
Hire the operation behind it.
Licensing tells you whether the company cleared an important California threshold.
Insurance tells you something about its risk structure.
A résumé tells you something about one person’s background.
A firearm permit tells you something about regulatory authorization.
None of those, standing alone, tells you what the protection detail will look like at 2:00 a.m. six months into the contract.
That is where the deeper due diligence begins.
Who is actually protecting the principal?
Who employs that person?
Is the company licensed?
Are the individual credentials current?
Who trained the team?
Who supervises them?
Who replaces them?
What happens when someone makes a mistake?
What happens when the principal changes the plan?
What happens when the threat picture changes?
Who sees a concerning message?
Who preserves the history?
Who checks the medical equipment?
How does night shift know what day shift saw?
Where is the family’s information stored?
What happens when an employee leaves?
What will the invoice actually look like?
And does company leadership remain engaged after the sales process is finished?
Those are the questions I would ask before putting an executive, spouse, children or UHNW family into an executive protection company’s hands.
The company I would choose is the one that can show, in licensing, staffing, judgment, leadership, training, medical readiness, insurance, information control, reporting and daily execution, that the operation behind the proposal is real.
Sources
- BSIS Verify a License
- BSIS SB 652 notice
- BSIS application processing times
- FBI Los Angeles
- U.S. Attorney Central District of California
- BSIS PPO information
- California Secretary of State business records
- BSIS security guard training requirements
- California DOJ CCW information
- California DOJ firearms information bulletins
- BSIS firearm permit requirements
- BSIS peace officer exemptions
- BSIS incident reporting
- BSIS PPO insurance requirements
- California Division of Workers Compensation
- California DIR overtime information
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.