
Published 17 September 2026
Last Updated 15 September 2026

There are now more than 1,300 multi-academy trusts operating in England, running close to 11,000 academies between them. The largest single trust, United Learning, oversees 92 schools across the country. Every one of those trusts asks the same operational question as they grow: when schools join at different times, with different suppliers, different badge designs and different sign-in processes, how do you turn it into one safeguarding-grade identity system?
Since the 1st of September 2026, Keeping Children Safe in Education (KCSIE) 2026 has tightened expectations around visitor identification, supervision and record-keeping, and explicitly links physical site security to a school's wider safeguarding duty. At the same time, DfE data shows cyber and data incidents are now a governance-level risk for trusts, not just an IT problem, which puts who can access your buildings, and how that access is recorded, firmly on the board's agenda.
We've worked with schools, colleges and MATs on ID and access control since 1998, so this is a question we get asked a lot as trusts grow. Here's why standardisation matters, what "good" actually looks like, and a practical roadmap for rolling it out across a growing trust.
Why ID standardisation has become a trust-level priority
Safeguarding compliance now extends to every visitor
KCSIE 2026 is one of the most substantial rewrites of statutory safeguarding guidance in years, and it places new emphasis on how schools identify, supervise and record anyone entering the site. A handwritten name in a paper visitor book isn't considered sufficient evidence of who's been in a building, when, and under what level of supervision. Every visitor needs to be identifiable, their DBS status understood, and their presence properly logged.
For a single school, that's a manageable process change. For a MAT with a dozen or more sites, each historically running its own sign-in sheet, badge stock and lanyard colour, it's a compliance exposure. If something goes wrong, the trust, not the individual school, is the accountable body. Inconsistent site-by-site processes make it much harder to demonstrate that safeguarding duties were met the same way everywhere.
Physical and digital security are now treated as one safeguarding ecosystem
The 2025/26 Cyber Security Breaches Survey found that 60% of UK secondary schools and 44% of primary schools reported a cyber security incident in the past year, and the sector has been a top ten target for cyber-attacks every year since 2020. Several of the highest-profile 2026 incidents, including ransomware attacks confirmed at schools in Surrey, began with attackers gaining a foothold that gave them visibility into access-control systems as well as pupil data.
That's why KCSIE 2026 explicitly connects cyber security and visitor management as part of one safeguarding chain, rather than two separate jobs for two separate teams. An ID and access system that's inconsistent across a trust, with different databases, different printers and different levels of card encryption from school to school, creates more entry points for something to go wrong. It also makes it much harder for a trust's central IT and safeguarding leads to audit what "good" looks like across every site.
Standardisation is where MATs are already finding savings
Independent sector research, including BESA's 2025 MAT Report, found that centralised procurement of core services (HR, finance systems, IT, utilities, and by extension physical security and ID systems) is now the norm for growing trusts, and that trust leaders consistently report it saves both money and admin time. Academy trusts are also contracting authorities under the Procurement Act 2023, so reducing procurement risk by centralising a category like ID cards, lanyards and access control onto a single framework or supplier isn't just efficient. It supports the trust's obligation to demonstrate value for money in its governance statement.
Put simply, a trust buying badges, cards, printers and lanyards separately at 15 different schools is paying 15 different admin overheads, 15 different design processes and 15 different supplier relationships for something that could be one negotiated contract.
What "standardised ID" actually means for a MAT
Standardising ID across a trust isn't just putting the same logo on every card. A properly standardised system typically covers:
- A single design template and brand standard, with consistent layout, colour-coding by role (staff, student, visitor, contractor, governor), and trust branding alongside individual school identity where it's needed
- One data and printing process, so a shared, GDPR-compliant record system means a pupil or staff member transferring between schools in the trust doesn't need a new record built from scratch
- Consistent visitor management, with the same check-in, photo-capture, DBS-status display and badge-printing process at every site, meeting KCSIE 2026's expectation of accountable, recorded visitor supervision
- Shared card technology, using a common smart-card standard (such as MIFARE) so cards can, where appropriate, be used for access control, cashless catering and library systems across sites, not just as a printed badge
- One point of procurement, with a central contract for cards, printers, ribbons, lanyards and card holders, rather than each school ordering independently
- A common data retention and security policy, giving one clear standard for how long photos and personal data are stored, who can access the system, and how it's secured, applied identically at every school
A practical roadmap for standardising ID across your trust
Step 1: Audit what every school currently has
Before you specify anything new, map what's actually in use across the trust: supplier, card stock, printer make and model, lanyard colours, data storage method, and how visitor sign-in currently works at each site. Trusts that skip this step often find they're supporting five or six incompatible printer models and several unconnected pupil databases, which limits what can realistically be standardised in year one.
Step 2: Agree the standard centrally, with input from schools
A trust-wide policy works best when central teams (safeguarding lead, DPO, IT, procurement) define the non-negotiables, such as data security, visitor badge information, DBS-status visibility and retention periods, while individual schools keep some flexibility on secondary branding elements.
Step 3: Consolidate procurement onto one supplier relationship
Move card printing, blank card stock, lanyards, card holders and printer servicing onto a single trust-wide contract, in line with your obligations under the Procurement Act 2023 and the Academy Trust Handbook's value-for-money requirements. This is usually where the clearest, fastest savings appear: bulk pricing, one set of terms, one point of contact for reordering across every site, and one relationship to manage instead of many.
Step 4: Standardise the visitor management process first
Because it's the area under the most direct regulatory pressure from KCSIE 2026, get visitor sign-in and badge printing consistent across every school before you tackle staff and student cards. Every site should be capturing a photo, checking identification, printing a badge that shows DBS or supervision status where relevant, and logging the visit in a way the trust's safeguarding lead can audit centrally.
Step 5: Roll out staff and student cards on a phased basis
Rather than reprinting every card in the trust at once, most MATs standardise as cards naturally expire, as new starters join, or school by school as each site's current stock runs out. This spreads the cost, avoids disrupting term-time operations, and still gets you to full consistency within a year or two.
Step 6: Review and audit annually
Because KCSIE is updated on a near-annual cycle and cyber security expectations keep tightening, build an annual review into the trust calendar. Check every site is still following the agreed standard, data retention rules are being met, and the supplier contract still represents value for money as the trust grows.
Common issues when standardising ID across multiple schools
- Treating it as a one-off print run, not an ongoing system. Standardisation only holds if new joiners, leavers and school transfers are processed the same way at every site, indefinitely, not just at the point of a single rebrand.
- Letting individual schools keep separate supplier relationships "just for now." These almost always persist for years and quietly undermine both the cost savings and the safeguarding consistency you're trying to achieve.
- Underestimating card technology needs. A basic printed badge is fine for visitors, but staff and student cards used for access control, catering or library systems need the right smart-card technology built in from the start. Retrofitting is far more expensive than specifying it from the get-go.
- No named owner. Trusts that get this right usually have one person, often in central operations or IT, accountable for the ID standard trust-wide, rather than leaving it to each school's office manager to interpret independently.
Does KCSIE 2026 require photo ID for all visitors?
KCSIE 2026 requires every visitor to be identifiable, with their DBS status understood and their supervision arrangements recorded. Most trusts meet this through photo capture and a printed, dated badge at sign-in, since a name in a paper log isn't considered sufficient evidence now.
Is it cheaper to centralise ID card procurement across a MAT?
Sector research consistently shows centralised procurement of core services, including ID, access control and related hardware, reduces both direct costs (bulk pricing, single contract terms) and admin overhead compared with each school ordering independently.
Do all schools in a trust need the same card technology?
Not necessarily for design, but it's strongly recommended for the underlying smart-card chip standard if cards are used for access control, cashless catering or library systems, so pupils and staff moving between trust schools don't need new cards issued.
Standardising ID doesn't have to mean a chaotic overhaul
Most trusts don't standardise everything in one go. They set the trust-wide standard, consolidate procurement onto a single supplier, fix visitor management first because it's under the most immediate regulatory pressure, and let staff and student cards catch up as they naturally renew. Done this way, standardisation tends to pay for itself in procurement savings within the first year or two, while giving your safeguarding lead and trustees a single, auditable answer to "how do we know who's on site, at every school, at any given moment."
We've been supplying identity and access control solutions to UK schools and multi-academy trusts since 1998, and we're always happy to talk through what a single trust-wide ID standard could look like across every site your MAT operates. Get in touch and we'll help you find the right fit.
About the Author
Ben O'Brien
Managing Director
Ben O’Brien is the Managing Director of ID Card Centre and a recognised authority in complex access control applications and eco-friendly identification solutions. Since entering the ID card printing industry in 1998, Ben has led countless projects across sectors, combining deep technical knowledge with a commitment to sustainability and innovation. Under his leadership, ID Card Centre continues to set standards for secure, efficient, and environmentally conscious ID systems.


















