Contact us
Illustration for ISO management-system services

ISO 18788

ISO 18788 private security operations management consulting

ISO 18788 consulting helps organisations conducting or commissioning lawful private security operations define responsibilities for service contracts, authority, personnel, human rights and incidents. Vosurein starts with the scope, existing processes and evidence, then helps assign responsibilities, implement the system and review it internally.

Discuss ISO 18788 Private Security Operations Management System consulting needs

For Your Business

Who this service is for and when to start

For organisations conducting or commissioning lawful private security operations. Start by identifying gaps when responsibilities for handovers, subcontracting, incidents and complaints are inconsistent.

The Challenge

Common challenges faced by businesses

If service contracts are written vaguely, on-site personnel may be unclear about the extent of action they can take. Subcontracting and temporary shift changes can also easily result in incomplete qualifications, training, and handovers; if incident investigations are concluded only internally, complaints from affected parties may not be properly addressed.

Our Approach

Methods and applicable requirements

The applicable edition is ISO 18788:2015, the first edition, with climate action amendment Amd 1:2024.

This standard sets out requirements and guidance for the management of private security operations, linking operational risks, legal responsibilities, and human rights issues to service execution. Organizations must clearly define their responsibilities and those of subcontractors; the system itself does not confer any additional law enforcement power.

The following consulting tasks can be arranged to suit your needs.

Review current practices and scope

Confirm services, regions, locations, clients, and system gaps.

Risk and human rights management

Review operational risks, potentially affected parties, responsibilities and improvements.

Contracts and service responsibilities

Organize service scope, authority, communication, changes, and delivery responsibilities.

Personnel and competency management

Review qualification confirmation, selection processes, training, suitability, and supervision.

Subcontracting and external supply

Plan selection, contract requirements, performance review, and anomaly handling.

Operations and incident management

Organize handover, notification, incident records, responses, and post-review.

Complaints and remedies

Establish procedures for receiving complaints, protecting confidentiality, assigning investigation tasks, responding and following up improvements.

Internal review and improvement

Support system pilots, internal audits, management reviews and certification preparation.

Process

Consulting scope and process

  1. Review security services and lawful authority

    Verify each service region, contract, and on-site authority, check client requirements and subcontractor roles to avoid security tasks exceeding legal or agreed scope.

  2. Human rights risk and personnel competency planning

    Link operational and human rights risks to selection, qualifications, training, and supervision arrangements, clearly recording reporting channels for personnel encountering uncertain situations.

  3. Trial subcontractor handovers and grievance procedures

    Check subcontractor handovers and temporary shift changes. Trial complaint intake and confidentiality procedures so on-site staff and management contacts can coordinate.

  4. Incident review and internal audit

    Review whether investigation, response, and remediation were completed based on incidents and complaints, track recurring deficiencies through audits, and adjust service supervision methods.

Preparation

What documents do companies need to prepare?

  • Service Contract: Region, location, services, and legal authority.
  • Personnel Competence: Qualification verification, training, scheduling, and supervision.
  • Subcontracting Operations: Suppliers, handover, and on-site procedures.
  • Incidents and Complaints: Notification, investigation, response, and remediation summary.

For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.

Project Planning

Estimating time and cost

Costs are estimated according to service area, location, personnel, and subcontracting level. Differences in authority and contracts across regions need individual verification, which will impact interview and system documentation work.

Operational systems, training, and incident procedures can be included in guidance; legal opinions, security permits, and third-party certification are arranged separately, with on-site handling according to applicable laws and contracts.

FAQ

Frequently asked questions

Does the ISO system grant enforcement authority?

No. Security activities, permits and authority to act depend on local laws and contracts. A management system does not grant powers to search, restrain people or use force.

Can existing systems and records be reused?

You can first review existing service and contract summaries, roles, qualification verification, training, and incident procedures to confirm applicable period, scope, and evidence quality before filling gaps; rewriting all documents is not a prerequisite for implementation.

How to coordinate temporary personnel?

Confirm qualifications, training and the scope of authority, then provide site procedures and incident reporting information. Keep handover records so staff do not have to work out the limits of their authority on arrival.

How are consulting and third-party certification responsibilities divided?

Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.

Can subcontracted security be excluded from management?

It must be confirmed according to the organization’s contract and control responsibilities, incorporating selection, requirement communication, and service review into arrangements; subcontracting cannot be used as a reason to ignore related operational risks.

Which version should be confirmed before implementation?

The applicable edition is ISO 18788:2015, the first edition, with climate action amendment Amd 1:2024. Confirm the edition and transition arrangements required by customers and the assessment scheme. The publication date of a standard is separate from an organisation’s transition deadline.

Related

Related services and enquiries

Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents