Skip to content
Safety Tech Review
Menu

Cameras and infrastructure

Existing CCTV Readiness Checklist: Can Your Cameras Run Safety Analytics?

A practical checklist to test whether existing CCTV can support AI safety analytics: streams, ONVIF, placement, image quality, network, cybersecurity and privacy.

By · Updated · 10 min read · 14 sources

Most sites can run a first AI safety analytics pilot on cameras they already own, provided those cameras are IP cameras that expose a standard video stream, are fixed in position, and actually point at the hazards the site wants to monitor. The usual blockers are camera placement, image quality at distance, lighting, network capacity and governance, more often than camera brand. This checklist walks through each test an EHS manager, IT lead and security team should run before a vendor survey, so the pilot starts with a realistic view of what the cameras can and cannot show.

Can existing CCTV run safety analytics?

In most modern facilities, the answer for at least some cameras is yes. Vendors in this category design for reuse. Protex AI says it connects to existing fixed-position CCTV cameras over RTSP and processes the feed on an on-site edge device [1]. Visionify says its system works with existing IP camera systems, including video management system (VMS) and network video recorder (NVR) setups, and that the customer needs to provide RTSP streams [2]. Spot AI describes itself as camera-agnostic [3], and Samsara said when it launched Site Visibility in 2021 that customers did not need to replace existing cameras [4].

Compatibility in these statements means the software can read the stream. It does not mean every camera is useful for every use case. A camera that clearly shows a dock door for security purposes may show a forklift driver's blind spot poorly or not at all. The checklist below separates the two questions: can the system get the video, and can the video show the hazard?

The checklist at a glance

# Check Pass looks like Red flag
1 Camera type IP cameras, or a recorder that outputs IP streams Old analog cameras with low image quality
2 Stream access RTSP URL available, ONVIF conformance, credentials documented Proprietary streams only, unknown passwords
3 Coverage of hazards Aisles, crossings, docks and machine zones in view Cameras aimed at doors, fences and tills
4 Detail at distance A reviewer can judge PPE and spacing at the far end of the view Workers are a few pixels tall where it matters
5 Frame rate and compression Smooth motion, little blur or blocking on moving vehicles Very low frame rate or heavy compression artifacts
6 Lighting and environment Usable image on every shift Glare at dock doors, dark night shifts, dust or steam
7 Fixed and stable mounting Camera does not move; view is the same week to week PTZ cameras, loose brackets, vibration
8 Network and compute Bandwidth and edge capacity confirmed by IT Saturated switches or recorder already at its limit
9 Cybersecurity and supply chain Current firmware, unique passwords, approved hardware Default credentials, unsupported or restricted models
10 Ownership and contracts Site controls cameras and VMS licenses Cameras owned by a landlord or security contractor
11 Privacy and purpose DPIA planned, notices to be updated, worker consultation Security footage repurposed without review

1. What type of cameras do you have?

IP cameras send compressed digital video over a network and are the default for safety analytics. Older analog cameras send a signal over coaxial cable to a digital video recorder. Some recorders can provide a network stream of analog channels, and hardware encoders can convert analog signals into IP streams, but the image quality of the original camera does not improve in the process. If the footage is soft or noisy, analytics will inherit that.

Make an inventory: camera make and model, resolution setting, mounting location, what it is aimed at, and which recorder it feeds. Most security integrators can export this from the VMS.

2. Can the analytics system get the stream?

The Real Time Streaming Protocol (RTSP) is the most common way analytics software requests a live feed. RTSP 2.0 was published by the IETF in December 2016 as RFC 7826 and replaced the original RTSP 1.0 specification [5]. In practice, many cameras still use RTSP 1.0, and vendors test against specific camera models.

ONVIF conformance is a good sign. ONVIF publishes profiles that define what conformant devices support. Profile T covers H.264 and H.265 video compression, imaging settings, motion and tampering events, metadata streaming and HTTPS streaming [7]. Profile M covers metadata and analytics configuration, including generic object classification [8]. Profile G covers devices with local storage, and the profiles page notes that Profile Q was deprecated in April 2022 [6]. A camera listed as conformant to Profile S or T should be able to hand a stream to third-party software.

Practical checks for this step:

  • Find out whether the vendor will pull streams from each camera directly or from the recorder. Pulling from the recorder means fewer connections to the cameras but more load on the recorder.
  • Confirm the camera passwords are known, unique and stored in a password manager, and decide whether the vendor will get a dedicated read-only account.
  • Identify which stream profile the vendor wants. Many cameras offer a high-resolution main stream and a lower-resolution substream; analytics on a substream may miss small objects.

3. Do the cameras show the hazards you care about?

This is where most readiness surveys find the biggest gaps. Security cameras are usually aimed at entrances, fences, cash points and high-value stock. Safety use cases need views of forklift aisles, pedestrian crossings, loading docks, racking ends, crane areas and machine guarding zones.

Start from your risk assessment, not your camera list. Take the five or six hazards most likely to cause serious injury, mark where they occur on a site plan, then mark camera fields of view on the same plan. The overlap is your realistic pilot scope. Areas with no overlap need a new or repositioned camera, or a different control altogether.

4. Is there enough detail where it matters?

No single resolution figure guarantees good results, and vendors rarely publish one. Visionify's description of its setup, for example, specifies edge server hardware but no camera resolution or frame rate [2]. What matters is how many pixels fall on the object at the distance where the event happens. A 4K camera looking down a 60 meter aisle may give less useful detail at the far end than a 1080p camera covering a 15 meter crossing.

A simple test helps. Export still frames from each candidate camera at a busy time and on a night shift. Ask a safety professional to look at the part of the frame where the hazard occurs and answer the questions the system will be asked: Is that person wearing a hard hat and high-visibility vest? Is that forklift moving? How far is the pedestrian from it? If a trained person cannot answer confidently from the frame, a model will not do better.

5. Are frame rate and compression adequate?

Moving vehicles blur at low frame rates and under heavy compression. Recorders are often configured to save storage, with low bitrates or reduced frame rates that are fine for after-the-fact security review but poor for detecting fast interactions. Research on image classifiers by Dodge and Karam found that deep neural networks are susceptible to quality distortions, particularly blur and noise, with compression also tested [9]. Ask the vendor for the minimum frame rate and bitrate it needs per use case, then check each camera's settings against that. Changing camera settings can affect security recording retention, so involve whoever owns the VMS.

6. Do lighting and environment hold up on every shift?

Cameras that look fine on a day-shift walkthrough can fail at 3 a.m. Check for:

  • Night operation. Many cameras switch to infrared in low light and produce grayscale images, which removes the color cues used for high-visibility clothing.
  • Glare and backlight at dock doors and skylights, especially at low sun angles.
  • Dust, steam, rain, condensation and dirty lenses, which build up gradually.
  • Flickering older lighting, which can create banding.

Pull footage from each shift and from different weather conditions before agreeing on the pilot scope.

7. Are the cameras fixed and stable?

Zones, walkways and distance calibration are drawn on a fixed camera view. If the camera moves, the rules stop matching the scene. Protex AI specifies fixed-position cameras [1]. Pan-tilt-zoom (PTZ) cameras are usually a poor fit for this reason, although ONVIF Profile T does include PTZ configuration [7], so a PTZ unit locked to a preset may work. Check brackets for vibration near heavy plant and racking, and agree a process for re-checking the view after any maintenance work near a camera.

8. Can the network and edge compute carry the load?

Most systems analyze video on an on-site edge device and send short clips and metadata to the cloud. Visionify's example edge server has an Intel Core i7 class processor, an NVIDIA RTX A4000 class GPU, 32 GB of memory and a 1 TB SSD, and handles up to 10 cameras [2]. Other vendors use different hardware, but the planning questions are the same:

  • How many cameras per edge device, at what resolution and frame rate?
  • What bandwidth does each stream use between camera and edge device, and can the switches carry it alongside existing traffic?
  • Does the edge device need inbound connections, or only outbound connections to the vendor's cloud?
  • Where will the device sit, with what power, cooling and physical security?
  • Who replaces it if it fails at a weekend?

Intenseye, for example, says it applies privacy protections before data leaves the device and stores thumbnails and short clips for positive alerts [10]. Ask every vendor for the same detail in writing.

9. Are the cameras secure and permitted?

Connecting a new system to camera networks raises the security bar. Check firmware versions against the manufacturer's current releases, remove default passwords, and confirm the camera network is segmented from business systems.

Also check supply chain rules that apply to your organization. In the United States, an FCC rule effective February 6, 2023 prohibits new equipment authorizations for equipment on the FCC's Covered List, which has named equipment from Hikvision and Dahua among others since March 2021; the 2023 rule did not revoke existing authorizations [11]. The FCC adopted further rules in November 2025 that address limits on previously granted authorizations [12]. Federal contractors, critical infrastructure operators and companies with their own security policies may face tighter restrictions. Ask your security and legal teams whether any installed models are affected before extending their use.

10. Who owns the cameras and the software?

On leased sites, shared logistics parks and ports, cameras may belong to a landlord, a security contractor or a terminal operator. VMS licenses may limit third-party streaming or charge per connection. Confirm in writing who owns each camera, who may grant access to its stream, who maintains it, and who pays if analytics needs a camera to be moved or upgraded.

11. Is the new purpose covered by your privacy process?

Footage collected for security is being reused for a different purpose. Under UK data protection law, the ICO says organizations using surveillance systems must carry out a data protection impact assessment (DPIA) for processing likely to result in high risk, and can use personal data for a new purpose only if it is compatible with the original purpose, based on consent, or required by law [13]. The ICO also asks organizations to consider whether they are using a new technology or processing data in a way people would not reasonably expect [13]. In the EU, the European Data Protection Board's Guidelines 3/2019 on video devices set out how the GDPR applies to video surveillance [14].

In practice, plan a DPIA, update signage and privacy notices, consult worker representatives where required, and decide which analytics features (such as face blurring or no identification) are part of the design.

How to run a camera readiness survey

A focused survey takes about a week of elapsed time for a single site.

  1. Pull the camera inventory and site plan from the VMS and the security integrator.
  2. Map the top hazards from the risk assessment onto the plan and mark camera coverage.
  3. Export still frames and short clips from candidate cameras on each shift.
  4. Run the still-frame test with a safety professional and mark each camera pass, marginal or fail per use case.
  5. Have IT confirm stream access, credentials, bandwidth and edge device location.
  6. Have security and legal confirm firmware, segmentation, restricted models and ownership.
  7. Start the DPIA and worker consultation.
  8. Share the results with shortlisted vendors and ask each one to confirm, camera by camera, which use cases it expects to support.

The output is a short table of cameras, use cases and gaps that turns vendor promises of "works with your cameras" into a scope everyone can check.

When new cameras are the better answer

Adding cameras is often cheaper than forcing a poor view to work. New or repositioned cameras make sense when a high-severity hazard has no coverage, when the only view is from too far away or at a steep angle, when lighting cannot be fixed, or when existing cameras are analog, unsupported or restricted. A small number of well-placed cameras at the riskiest crossings usually produces more useful events than dozens of security cameras that only partly show the work.

Summary

Existing CCTV can usually support a first safety analytics pilot, but only for the cameras that are IP-based, fixed, adequately lit and aimed at real hazards. Check stream access and ONVIF conformance, then test placement and detail with real frames from every shift. Confirm frame rate, compression, network capacity and edge hardware with IT, and confirm firmware, ownership and any supply chain restrictions with security and legal. Treat the reuse of security footage as a new purpose that needs a DPIA and updated notices. The result is a camera-by-camera map of what the system can see, which is the right starting point for any vendor conversation.

Frequently asked questions

+Do I need new cameras for AI safety analytics?

Often not for a first pilot. Vendors such as Protex AI, Visionify, Spot AI and Samsara say their products work with existing IP cameras. Most sites still find a few hazards that no current camera covers well, so budget for some additional or repositioned cameras.

+Can analog CCTV cameras be used?

Sometimes, through the recorder or an encoder that converts the signal into an IP stream. Image quality from older analog cameras is often too low for small details such as PPE, so test the actual footage before committing. Analog systems near the end of their life are usually a better candidate for replacement than for retrofitting.

+Will analytics slow down our security recording system?

It can if streams are pulled carelessly. Each analytics stream adds load on the cameras, the recorder and the network. Ask the vendor whether it pulls streams directly from cameras or from the recorder, which stream profile it uses, and the bandwidth per camera, then have IT confirm the switches and recorder can carry it.

+Do pan-tilt-zoom cameras work for safety analytics?

Poorly, in most cases. Zones and distance calibration are drawn on a fixed view, so when a PTZ camera moves, the rules no longer line up with the scene. If a PTZ camera must be used, lock it to a preset position for analytics or choose a fixed camera for that area.

Sources

  1. [1]Privacy at Protex AI
  2. [2]How It Works (Visionify)
  3. [3]Spot AI FAQ
  4. [4]Streamlining Operations: Announcing Site Visibility (Samsara, 2021)
  5. [5]RFC 7826: Real-Time Streaming Protocol Version 2.0 (IETF, 2016)
  6. [6]ONVIF Profiles
  7. [7]ONVIF Profile T
  8. [8]ONVIF Profile M
  9. [9]Dodge and Karam, Understanding How Image Quality Affects Deep Neural Networks (arXiv, 2016)
  10. [10]Privacy (Intenseye)
  11. [11]Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program (FCC rule, Federal Register, February 2023)
  12. [12]Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program (FCC rule, Federal Register, November 2025)
  13. [13]How can we comply with the data protection principles when using surveillance systems? (ICO)
  14. [14]Guidelines 3/2019 on processing of personal data through video devices (EDPB, 2020)

New chapters and updates, once a month

One email when we publish or update guidance. No vendor promotions. Unsubscribe any time.