An employee warning notice is a formal written record that tells a member of staff which rule or standard they fell short of, when it happened and what must change. It sits between a verbal conversation and a termination decision, and its value depends entirely on whether the facts, the date and the person who issued it were recorded at the time.
Most security teams only discover the weakness in their employee warning notice process at the worst possible moment: a dismissal is challenged, a client asks why a guard was removed from site, or a tribunal asks for the paper trail. The notice exists, somewhere. Nobody can find it, the copy on file has no date, and the supervisor who issued it left the company in March.

The notice itself is not the hard part. Writing “you were late three times” takes a minute. The hard part is that an employee warning notice has to survive being read months later by somebody who was not there, and that only happens when the right fields were captured at the moment it was issued.
This guide sets out the nine fields a defensible employee warning notice must carry, why each one matters and the mistakes that quietly make a notice worthless.
Why a vague employee warning notice protects nobody
A warning serves two people. It tells the employee exactly what to stop doing, and it tells your future self why the decision that followed was fair.
A vague notice fails both. “Attitude problem, spoken to” gives the guard nothing to correct, so the behaviour repeats. Then, when the behaviour repeats and you act on it, there is no record showing the employee was warned, told what to change, given a chance to respond and issued the notice by a named manager on a specific date.
Three failures show up again and again:
- The notice is verbal only. A conversation happened. There is no document, so as far as any later review is concerned, no warning was ever given.
- The notice has no date or no author. A signed page in a drawer proves somebody wrote something. It does not prove when, or by whom, or that the employee ever saw it.
- The notice is never linked to what happened next. The warning sits in one file, the incident in another, the eventual dismissal letter in a third. Nobody can reconstruct the sequence.
Each of these is a recording failure, not a judgement failure. The manager usually made the right call. The employee warning notice simply did not capture enough to show it.
The 9 fields every employee warning notice must include
These are the fields to capture at the moment the notice is issued. Skip one and you create a gap somebody else will have to explain later.
- Staff name. Full legal name as it appears on the employment record, not a nickname or a radio callsign. If two guards share a surname on the same site, a first initial is not enough.
- Staff ID number. The name identifies a person to you. The ID number identifies them to the system, to payroll and to whoever reads the file in two years. It is what lets you pull every notice attached to one individual instead of searching by a name that may be spelled three ways.
- Department. A warning for a control-room operator and a warning for a mobile patrol officer sit in different operational contexts. Recording the department also lets you see whether an issue is one person or one team.
- Designation. The role held at the time of the warning, which is not always the role held today. Somebody promoted from guard to supervisor six months later must have their notice read against the standard that applied when it was issued.
- Date. The calendar date the notice was issued. This is the single most commonly missing field and the one that does the most damage, because without it no sequence can be established. A first warning that cannot be dated cannot be shown to precede a second.
- Time. More precision than most templates bother with, and worth it. When a warning and an incident happen on the same day, the time is what shows which came first. It also tells you whether the notice was issued while the facts were fresh or three weeks later.
- The show-cause statement. The substance: what the employee did or failed to do, which standard or instruction it breached, and what is required now. Write it as facts rather than characterisation. “Left post at gate 2 from 02:10 to 02:45 without informing the supervisor, contrary to the post orders issued on 3 June” is a statement somebody can respond to. “Unreliable” is not.
- Notice photo. An image of the physical notice, or of the document as it was presented and acknowledged. Where a paper notice is still used on site, this is what stops the only copy living in a folder in a guard hut.
- Issued by, with date and time. The named manager who raised the notice, stamped automatically. Accountability runs both ways here: it protects the employee from an anonymous warning appearing in their file, and it protects the manager by showing the notice was raised through a proper channel rather than invented after the fact.
A tenth item is not a field but a flag: a record that the employee was notified. Knowing a notice was issued is not the same as knowing it reached the person it concerns.
How AVES records an employee warning notice
AVES handles this through the Staff Show Cause module, which is the formal disciplinary notice inside the platform rather than a free-text note.
The form captures staff name, staff ID number, department and designation, the date and time, and the show-cause text itself. A photo of the notice can be attached. A notified flag records that the staff member was informed. Every notice carries an issued-by value together with the date and time it was raised, so the author and the moment are part of the record rather than something reconstructed later.
It is worth being precise about one thing, because plenty of software in this space is not. AVES has no signature-image field anywhere in the product. Acknowledgement is handled as an audit trail of accept, decline and submitted states with the associated user, date and time, not as a captured handwritten signature. If a scanned signature is a hard requirement for your legal team, attach the signed page as the notice photo and treat the system record as the index to it.
The practical gain is retrieval. Because every employee warning notice is stored against a staff ID rather than in a folder, the full disciplinary history for one person is one lookup, with dates intact and authors named. That is the thing paper cannot do, and it is the thing you need on the day somebody asks.
For the wider picture of how notices, actions and outcomes connect, see our guide to disciplinary action tracking. Where the issue is capability rather than conduct, a performance development plan is usually the more appropriate route, and a signed policy acknowledgement form is what establishes the rule existed before the breach.
Common mistakes when issuing an employee warning notice
- Writing character judgements instead of conduct. “Lazy”, “difficult”, “bad attitude”. None of these can be evidenced or corrected. Describe the behaviour, the date and the standard it breached.
- Backdating the notice. Recording a warning as issued on the day of the incident when it was actually written a fortnight later is the fastest way to lose credibility with everyone. Record the real issue date. A gap is explainable. A falsified date is not.
- Issuing a first warning that is actually a final one. If an employee warning notice says nothing about what happens if the behaviour continues, escalation later looks arbitrary. State the next step.
- Leaving no evidence the employee saw it. An employee warning notice nobody received is not a warning. Use the notified flag, and where a paper copy is handed over, capture it as the notice photo.
- Keeping the notice separate from the incident it concerns. A warning about a missed patrol and the patrol record that shows it were both created in your systems. If they cannot be read together, half the value is lost.
- Letting each supervisor use their own template. Five formats across five sites means five sets of missing fields. One structured employee warning notice form is what makes the records comparable.
Employee warning notice FAQ
What should an employee warning notice include?
Staff name, staff ID number, department, designation, the date and time of issue, a factual show-cause statement describing the conduct and the standard breached, a photo of the notice where one exists, confirmation the employee was notified, and the name of the manager who issued it with the date and time.
Does a warning notice have to be in writing?
A verbal warning may be a legitimate first step, but only a written employee warning notice creates a record you can rely on later. If it matters enough to escalate, it matters enough to write down.
How long should a warning notice stay on file?
That depends on your jurisdiction and your own policy, and it is a question for your HR or legal adviser rather than a software vendor. What software should do is make sure the notice can still be found, with its original date and author intact, for as long as your policy requires.
Can an employee respond to an employee warning notice?
They should be able to. A show-cause notice is by definition an invitation to explain. Record the response alongside the notice so the file shows both sides.
What is the difference between a warning notice and a performance development plan?
A warning addresses conduct that breached a standard. A development plan addresses capability that needs to improve. Using one where the other belongs is a common and expensive mistake.
Get the record right the first time
Every employee warning notice you issue is a bet that you will still be able to explain the decision months from now. Structured fields, a real timestamp and a named author are what let you win that bet.
Book a 30-minute demo and we will show you the actual Staff Show Cause screen, the fields it captures and how a full disciplinary history pulls up against a single staff ID.
Prefer to look around first? Start a free AVES account and set up your own notice workflow.
Follow AVES on Instagram for more security operations guidance.
