Every church that puts together a security or safety team — armed or unarmed, paid or volunteer — needs a written church active shooter policy. That is true regardless of any recent change in California law, because it comes from ordinary premises liability principles: a church that organizes a team and never writes down what that team is supposed to do — including a clear use-of-force standard — is worse off in a courtroom than one that never had a team at all.
California law has also changed in a way that makes this document more urgent. Churches and other nonprofits used to be broadly exempt from the licensing rules that apply to private security companies and their guards, regardless of what their volunteer or staff teams actually did. A 2024 law, Senate Bill 1454, removed that blanket exemption, effective January 1, 2025. Depending on how your church staffs its team, some or all of your security function may now need to register with the state agency that licenses security personnel, the Bureau of Security and Investigative Services (“BSIS”). The registration mechanics — who has to register, with which agency, and under what threshold — are covered in SB 1454 Church Security Requirements.
This article covers what registration status alone does not: what your team is actually supposed to do the moment something goes wrong, and why that written policy carries legal weight of its own, whether or not your team ends up needing to register at all.
Why a Church Active Shooter Policy Carries Legal Weight
California courts do not evaluate a church’s security obligations in the abstract — they look at what a reasonable operator would have done given what it knew, what it represented to the people on its property, and what it actually built. Under Ann M. v. Pacific Plaza Shopping Center (1993) 6 Cal.4th 666, a property owner’s duty to provide heightened security measures generally turns on whether prior similar incidents made third-party criminal conduct reasonably foreseeable.
But Delgado v. Trax Bar & Grill (2005) 36 Cal.4th 224 narrowed that shield: once a specific, imminent threat is apparent — someone escalating in the parking lot, a credible threat reported, an incident already underway — a duty to take at least minimal, reasonable preventive measures can arise even without any documented history of prior violence.
A church that has organized, trained, and badged a security team has already told a jury what it believed was necessary. If that team has no written scope of authority, no documented training, and no response protocol, the absence of a policy becomes evidence in a negligence claim, not a neutral fact.
A current, board-adopted policy the team was actually trained on is one of the strongest pieces of evidence a church can offer that it acted reasonably — and it is what a plaintiff’s attorney asks for first, and what your general liability and D&O carriers ask for before a claim is even filed.
The Regulatory Lanes for a Church Security Team
Before SB 1454 (Stats. 2024, ch. 484), churches and other nonprofits were categorically exempt from private security licensing as a “charitable philanthropic society or association” under Business and Professions Code § 7582.2. Effective January 1, 2025, SB 1454 deleted that exemption, and which licensing scheme now applies depends on how your church staffs the function.
- In-House Teams (Proprietary Security Services Act) — a church staffing its own team falls under Business and Professions Code §§ 7574.01 et seq. Personnel become “Proprietary Private Security Officers” only if they wear a distinctive security uniform and interact with the public in that role — and by statute, a Proprietary Officer is unarmed.
- Contracted Teams (Private Patrol Operators) — a church that hires an outside security company operates instead under Business and Professions Code Chapter 11.5 (§§ 7582.1 et seq.); the contractor, not the church, generally carries the licensing burden.
- Staying Outside Registration Entirely — a team with no distinctive security uniform or signage — greeters, ushers, first aid and CPR responders, people who simply notice and report — stays outside registration under either scheme.
- Armed Teams Need a Different Path — arming a team is not a simple extension of Proprietary registration, since a Proprietary Officer is unarmed by definition. It requires a licensed Private Patrol Operator structure or another properly licensed pathway, with its own firearms-permit requirements — scope this with counsel before a single volunteer is armed.
Operating a Proprietary team without registering as required under § 7574.10 is an infraction under § 7574.32, punishable on a first offense by a fine of $250 to $1,000, with escalated treatment available for repeat violations.
If your church instead contracts a Private Patrol Operator, that operator’s own licensing failures can draw civil penalties of up to $5,000 per violation under § 7587.15 — a separate statute from the one governing in-house teams. Neither provision addresses what your team should actually do in an emergency; that is a separate document, and the one most churches skip.
What a Registered Team’s Policy Must Document
For a registered Proprietary team, § 7574.18 requires each officer to complete training in security officer skills — including instruction in the power to arrest and the appropriate use of force — within six months of the registration date, followed by an annual dedicated review or practice of those skills at a minimum number of hours set by regulation.
Your church must keep verification records of that training for at least two years. A policy that asserts “our team is trained” is not enough — it should identify who tracks completion dates, where records are kept, and who is responsible for pulling a registrant from active duty if training lapses.
Because Proprietary registration does not extend to an armed function, any church that arms part of its team — through a licensed Private Patrol Operator arrangement or otherwise — needs a use-of-force standard on top of whatever BSIS-mandated training applies: when force is authorized, the de-escalation steps that must be attempted first, who is authorized to use lethal force and under what circumstances, and how every use-of-force incident is documented and reviewed afterward.
This is the section your insurance carrier will want to see before binding or renewing coverage for an armed program, and the section most likely to be scrutinized if force is ever actually used.
What Every Church Security Team Needs, Registered or Not
Some elements belong in every church active shooter policy, because they address the active shooter scenario itself rather than the licensing question.
- Chain of Command and Communication — who calls 911, who initiates lockdown, and who has authority to make real-time decisions during an incident — and how that authority is communicated to ushers, greeters, and staff who are not part of the security team itself.
- Lockdown and Evacuation Procedures — room-by-room, service-by-service procedures specific to your campus, including separate protocols for children’s ministry and nursery areas.
- A Relationship With Local Law Enforcement — not just a phone number, but a walkthrough of your building that patrol officers have actually done, so responding officers are not seeing your floor plan for the first time during an incident.
- Incident Reporting and Documentation — a procedure for what gets written down after any incident, near-miss, or use-of-force event, and who reviews it.
- A Documented Drill Schedule — documented, not aspirational — a policy that has never been rehearsed is difficult to defend as the church’s actual practice.
- Medical Response Stays Outside BSIS’s Reach — first aid, CPR, AED use, and emergency medical response remain outside BSIS’s regulatory reach and are encouraged regardless of which lane your security function occupies.
Adopting the Policy as a Governance Document
A church active shooter policy should be adopted the same way any other governance document is adopted — by formal board resolution, with the adoption date and any subsequent revisions recorded in your minutes. As discussed in Church Officer and Director Liability, directors who fail to exercise reasonable oversight over a foreseeable risk area can face their own exposure; a documented, board-level decision to adopt and periodically review the policy is part of demonstrating that oversight.
As discussed in General Liability Insurance, carriers increasingly ask specific underwriting questions about security programs, and a church that can produce an adopted policy, a training log, and a drill record is in a materially different position at renewal — and at claim time — than one that cannot.
A practical review cadence for your church active shooter policy is annual, timed to coincide with your general liability and D&O renewal, with an off-cycle review any time your team’s activities change — adding firearms, adding paid positions, or changing what your team’s apparel or signage says — any of which can shift which regulatory lane you are operating in.
Where to Start
Two separate questions face every church security team: whether it needs to register with BSIS, and what its church active shooter policy is supposed to say when something goes wrong. The registration question is worth resolving first, since the answer determines which version of the policy — unarmed hospitality team, registered Proprietary program, or contracted Private Patrol Operator — your board is adopting (see SB 1454 Church Security Requirements for that determination). But the policy itself is the step most churches still have not taken, regardless of where they land on registration.
Related Articles
SB 1454 Church Security Requirements
Church Security
Church Officer and Director Liability
General Liability Insurance
Disclaimer: Every situation is different and particular facts may vary thereby changing or altering a possible course of action or conclusion. The information contained herein is intended to be general in nature as laws vary between federal, state, counties, and municipalities and therefore may not apply to any given matter. This information is not intended to be legal advice or relied upon as a legal opinion, course of action, accounting, tax or other professional service. You should consult the proper legal or professional advisor knowledgeable in the area that pertains to your particular situation.