
ISO 18788
ISO 18788 private security operations management consulting
ISO 18788 consulting helps organisations conducting or commissioning lawful private security operations define responsibilities for service contracts, authority, personnel, human rights and incidents. Vosurein starts with the scope, existing processes and evidence, then helps assign responsibilities, implement the system and review it internally.
Discuss ISO 18788 Private Security Operations Management System consulting needs
For Your Business
Who this service is for and when to start
For organisations conducting or commissioning lawful private security operations. Start by identifying gaps when responsibilities for handovers, subcontracting, incidents and complaints are inconsistent.
The Challenge
Common challenges faced by businesses
If service contracts are written vaguely, on-site personnel may be unclear about the extent of action they can take. Subcontracting and temporary shift changes can also easily result in incomplete qualifications, training, and handovers; if incident investigations are concluded only internally, complaints from affected parties may not be properly addressed.
Our Approach
Methods and applicable requirements
The applicable edition is ISO 18788:2015, the first edition, with climate action amendment Amd 1:2024.
This standard sets out requirements and guidance for the management of private security operations, linking operational risks, legal responsibilities, and human rights issues to service execution. Organizations must clearly define their responsibilities and those of subcontractors; the system itself does not confer any additional law enforcement power.
The following consulting tasks can be arranged to suit your needs.
Review current practices and scope
Confirm services, regions, locations, clients, and system gaps.
Risk and human rights management
Review operational risks, potentially affected parties, responsibilities and improvements.
Contracts and service responsibilities
Organize service scope, authority, communication, changes, and delivery responsibilities.
Personnel and competency management
Review qualification confirmation, selection processes, training, suitability, and supervision.
Subcontracting and external supply
Plan selection, contract requirements, performance review, and anomaly handling.
Operations and incident management
Organize handover, notification, incident records, responses, and post-review.
Complaints and remedies
Establish procedures for receiving complaints, protecting confidentiality, assigning investigation tasks, responding and following up improvements.
Internal review and improvement
Support system pilots, internal audits, management reviews and certification preparation.
Process
Consulting scope and process
Review security services and lawful authority
Verify each service region, contract, and on-site authority, check client requirements and subcontractor roles to avoid security tasks exceeding legal or agreed scope.
Human rights risk and personnel competency planning
Link operational and human rights risks to selection, qualifications, training, and supervision arrangements, clearly recording reporting channels for personnel encountering uncertain situations.
Trial subcontractor handovers and grievance procedures
Check subcontractor handovers and temporary shift changes. Trial complaint intake and confidentiality procedures so on-site staff and management contacts can coordinate.
Incident review and internal audit
Review whether investigation, response, and remediation were completed based on incidents and complaints, track recurring deficiencies through audits, and adjust service supervision methods.
Preparation
What documents do companies need to prepare?
- Service Contract: Region, location, services, and legal authority.
- Personnel Competence: Qualification verification, training, scheduling, and supervision.
- Subcontracting Operations: Suppliers, handover, and on-site procedures.
- Incidents and Complaints: Notification, investigation, response, and remediation summary.
For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.
Project Planning
Estimating time and cost
Costs are estimated according to service area, location, personnel, and subcontracting level. Differences in authority and contracts across regions need individual verification, which will impact interview and system documentation work.
Operational systems, training, and incident procedures can be included in guidance; legal opinions, security permits, and third-party certification are arranged separately, with on-site handling according to applicable laws and contracts.
FAQ
Frequently asked questions
Does the ISO system grant enforcement authority?
No. Security activities, permits and authority to act depend on local laws and contracts. A management system does not grant powers to search, restrain people or use force.
Can existing systems and records be reused?
You can first review existing service and contract summaries, roles, qualification verification, training, and incident procedures to confirm applicable period, scope, and evidence quality before filling gaps; rewriting all documents is not a prerequisite for implementation.
How to coordinate temporary personnel?
Confirm qualifications, training and the scope of authority, then provide site procedures and incident reporting information. Keep handover records so staff do not have to work out the limits of their authority on arrival.
How are consulting and third-party certification responsibilities divided?
Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.
Can subcontracted security be excluded from management?
It must be confirmed according to the organization’s contract and control responsibilities, incorporating selection, requirement communication, and service review into arrangements; subcontracting cannot be used as a reason to ignore related operational risks.
Which version should be confirmed before implementation?
The applicable edition is ISO 18788:2015, the first edition, with climate action amendment Amd 1:2024. Confirm the edition and transition arrangements required by customers and the assessment scheme. The publication date of a standard is separate from an organisation’s transition deadline.
Related
Related services and enquiries
Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

