Skip to main content
Home / Blog / Security Operations
Security Operations

Where Security Contract Billing Leaks Revenue

Security contract billing leaks revenue in four specific places: overtime and premium hours that were worked but never reached an invoice, variation orders agreed verbally and never priced, retainer contracts where the delivered headcount quietly exceeded the contracted one, and invoices raised late enough that the working capital cost exceeds the margin on the work. All four share a cause. Each occurs at a handover between operations and finance, where information has to move from one system or one person to another, and where anything that fails to move is invisible rather than wrong.

Leakage of this kind does not show up as a loss. It shows up as a contract that is slightly less profitable than the model said, consistently, for its whole term, and it is nearly impossible to diagnose from financial reports alone because the missing revenue never entered the accounts to be missed.

Four contract shapes, often on one client

Security agencies bill in several structurally different ways, and many run all of them simultaneously.

Retainer bills a fixed monthly amount for defined coverage. Simple to invoice and the easiest to under-recover, because the invoice does not change when the delivered service does.

Man-month bills a rate against contracted headcount. Recovery depends on the headcount figure being current, which means it depends on somebody updating it when posts are added.

Man-hour bills from timesheets. Most accurate, most sensitive to attendance data quality, and the only model where verified hours flow directly into revenue.

Event-based bills ad hoc against a quoted scope. Highest margin variance because scope changes during delivery and rarely gets repriced.

The complexity is that a single client relationship may combine a retainer for the main site, man-hour billing for relief coverage, and event work for their annual functions. Any system that assumes one billing model per client will be worked around within a month.

The rate card is where the detail lives

A rate card that is a single hourly figure per client is not a rate card. What is actually needed varies along several axes at once: officer grade, shift type (day, night, public holiday), location where travel or difficulty justifies a differential, overtime multipliers, and client-specific surcharges for uniforms, administration or equipment. GST treatment sits alongside it.

The reason this needs to be structured data rather than a document is that every one of those dimensions is a place a billing error can hide. A night differential defined in the contract but not encoded in the rate card will be applied when someone remembers and omitted when they do not, and the omissions are silent.

The test for whether a rate card is properly encoded is whether the system can price a shift without human interpretation. Given an officer grade, a shift date and time, a site and a contract, it should produce a billable amount with no judgement required. If a person has to decide anything, that decision will eventually go the cheap way.

Variation orders, which is where the money actually goes

The largest single source of leakage in most agencies is scope that expanded without the contract following it.

The pattern is consistent and entirely mundane. A client asks for an extra officer during a fit-out, or extended hours over a holiday period, or coverage of an additional entrance while construction is underway. Operations delivers it, because refusing would damage the relationship over something small. Nobody prices it, because it was meant to be temporary. It continues for months. When someone eventually notices, the agency faces a choice between raising a backdated invoice the client will contest and absorbing the cost, and they usually absorb it.

The systemic fix is making variation capture cheap enough that it happens at the point of agreement. A variation record with scope, effective date, pricing derived from the existing rate card, and a client approval step, raiseable by the operations person who received the request rather than routed through a commercial team, is the mechanism. It succeeds or fails on friction: if raising a variation takes twenty minutes, it will not happen for a request that seems minor.

The second half is that approved variations must flow automatically into both the revised budget and the billing schedule. A variation that is approved but requires someone to remember to add it to next month’s invoice has moved the failure point rather than removed it.

From verified hours to invoice line

The mechanical core of billing hygiene is that approved timesheets, retainer schedules and approved variations generate invoices without a retyping step.

Every manual transcription between operations data and billing data is an opportunity for hours to be lost, and losses are asymmetric: an under-billing is never queried by the client, so it persists indefinitely, while an over-billing is queried immediately and corrected. A process with a manual step therefore drifts steadily downward in recovery over time, which is why agencies that reconcile properly for the first time usually find money rather than errors.

Timesheet approval is the gate. Only verified attendance should generate timesheet lines, only approved timesheets should generate invoice lines, and adjustments at either stage should require reason codes so patterns are visible. Once approved, records lock; reopening requires an explicit, logged unlock.

Client-specific invoice requirements are worth building for rather than working around. Purchase order number capture, cost centre breakdowns, and supporting attendance or incident summaries attached to the invoice are common requirements in facilities and government contracts, and an invoice that arrives without them is an invoice that will be returned, which is another form of late payment.

Pricing a tender that stays profitable

Costing sits upstream of all of this and determines whether the contract was ever going to work.

A manpower costing calculation starts from the applicable wage floor for the required officer grade, applies the shift pattern to determine how many officers a post actually requires including rest-day relief, adds leave provision, employer contributions and overheads, and then projects that forward across the contract term against the published wage schedule. The last step is the one most often skipped, and it is the one that determines whether year three of a three-year contract is profitable.

Historical cost data makes this progressively better. An agency that knows its actual delivered cost per guard-hour by site type, rather than its modelled cost, prices from evidence. That feedback loop between delivery and tendering is the same mechanism that works in project-based contracting generally, and it is worth reading alongside how the same problem appears in project cost overruns for Singapore contractors, where the leakage points differ but the structure is identical.

How Moxogo implements it

Moxogo Security supports retainer, man-month, man-hour, event and hybrid contract types with rate cards structured by officer grade, shift type, public holiday and overtime multiplier, plus client-specific surcharges and GST treatment, so a shift prices without human interpretation. Variation orders are tracked with scope, effective dates and approval, flowing into both the revised contract value and the billing schedule automatically.

Invoices generate from approved timesheets, retainer schedules and approved variations, with client-specific templates, purchase order capture and cost centre breakdowns, and supporting attendance summaries attachable. Timesheets generate only from verified attendance, adjustments require reason codes, and approved records lock against silent editing. The manpower costing calculator estimates monthly cost from wage floors, shift patterns, leave provision and overheads for tender pricing.

Commercially this runs on the same Invoicing Management and Accounting and Finance modules used across the Moxogo platform, which is what allows verified operational hours to reach an accounting entry without an export and reimport.

A practical test

Take one contract and one closed month. Reconcile three numbers: hours verified as worked, hours billed, and hours paid. In a clean operation the first two match within a rounding tolerance and the third differs only by the wage-versus-charge margin. Where the first exceeds the second, that difference is leakage, and it is almost certainly recurring at roughly the same rate every month.

Frequently Asked Questions

Where does security contract billing most commonly leak? Four places: overtime and premium hours worked but never invoiced, variation orders agreed verbally and never priced, retainers where delivered headcount exceeded the contracted figure, and invoices raised late enough that working capital cost eats the margin. All four occur at handovers between operations and finance.

Why is under-billing more persistent than over-billing? Because clients query over-billing immediately and never query under-billing. Any process with a manual transcription step therefore drifts downward in recovery over time, which is why first-time reconciliations typically find money rather than errors.

What makes variation orders so costly? Scope expands informally, operations delivers to protect the relationship, nobody prices it, and it continues for months. By the time it is noticed the choice is between a contested backdated invoice and absorbing the cost. Making variation capture low-friction at the point of agreement is the only reliable fix.

What does a properly structured rate card need? Rates varying by officer grade, shift type including night and public holiday, location differentials where applicable, overtime multipliers, client surcharges and GST treatment, all as structured data. The test is whether the system can price a shift with no human judgement required.

Why does tender costing need to model wage step-ups? Because the Progressive Wage Model floor rises on a published schedule, so a multi-year contract priced at today’s cost loses margin predictably each year. Costing has to project across the full contract term rather than the current position.

Related in this series