Overview
ISO 18788:2015 - Management system for private security operations - Requirements with guidance for use - defines a framework for a Security Operations Management System (SOMS). The standard helps organizations establish, implement, operate, monitor, review, maintain and improve the management of private security operations. ISO 18788:2015 emphasizes professional conduct, legal accountability, respect for human rights and consistent risk-based management of security services.
Key topics and technical requirements
ISO 18788:2015 structures requirements around a management-system approach and covers:
- Context of the organization: internal/external context, stakeholder needs, scope and supply-chain/subcontractor mapping.
- Leadership and policy: senior management commitment, security policy and Statement of Conformance.
- Planning: risk identification, legal and human-rights requirements, objectives and risk treatment.
- Support: allocation of resources, structural requirements, competence, training, documented information and communication (including whistle-blower and grievance procedures).
- Operation: operational planning and control, norms of behaviour, ethical codes, use of force (continuum, weapons authorization, less‑lethal and lethal force), apprehension/search, law-enforcement support, detention operations, procurement and management of weapons/hazardous materials, uniforms and markings.
- Incident management: incident monitoring, reporting, investigation, complaints and corrective actions.
- Performance evaluation: monitoring, measurement, compliance evaluation, exercises/testing, internal audit and management review.
- Improvement: nonconformity, corrective action, continual improvement and change management.
The standard also includes informative annexes with guidance, principles, gap analysis and qualifiers to application.
Practical applications
ISO 18788:2015 is designed for organizations that conduct or contract private security operations and need to demonstrate consistent, legally compliant and rights-respecting services. Typical uses include:
- Designing or improving a company-wide SOMS for static guarding, mobile patrols, close protection, site security or integrated security services.
- Contract compliance and client assurance for security service providers bidding on public- or private-sector contracts.
- Integrating human-rights safeguards and use-of-force policies into operational procedures and training programs.
- Managing security-related risks across supply chains and subcontracted services.
- Establishing incident reporting, whistle-blower protections and corrective-action workflows.
Who should use this standard
- Private security companies and contractors
- Corporate security departments and risk managers
- NGOs and international organizations procuring private security
- Compliance officers, auditors and consultants working on security management and human-rights risk mitigation
Related standards and frameworks
ISO 18788:2015 is frequently implemented alongside broader management and risk standards such as ISO 9001 (quality), ISO 31000 (risk management) and occupational/health-safety standards, and with international human-rights and law-enforcement guidance to ensure comprehensive, accountable security operations.