ISO 18788 is the standard for Security Operations Management. In plain English, it's about proving your security operations are planned and controlled, legally compliant, risk-based (not reactive), properly supervised, and continuously improved.

It's especially relevant if you provide guarding, mobile patrols, key holding, event security, or any security service where clients need confidence you'll do the right thing under pressure.
What ISO 18788 Actually Covers
ISO 18788 is built around a management system approach — similar in structure to other ISO standards — but tailored to security operations. It focuses on:
- Operational planning and control
- Legal and regulatory compliance
- Risk assessment and mitigation
- Competence, supervision and accountability
- Incident management and learning
- Monitoring, audits and continual improvement
The goal isn't paperwork. The goal is consistent, controlled delivery — with evidence.
Who ISO 18788 Is For
ISO 18788 is a strong fit for:
- Private security companies
- Organisations delivering security operations in higher-risk environments
- Suppliers working with public sector, infrastructure, or larger corporates
Why Clients Ask for ISO 18788
- Buyer confidence — It shows you're not just “licensed” — you're managed, controlled and accountable
- Reduced operational risk — Better planning, clearer roles, and tighter control reduces incidents and complaints
- Stronger supervision and performance — It forces clarity on competence, monitoring, and corrective action
- Competitive advantage — In a crowded security market, ISO 18788 is a differentiator
What You Need to Pass ISO 18788
- Defined scope for security operations management
- Legal and compliance obligations identified and controlled
- Risk assessment and controls (threats, vulnerabilities, mitigation)
- Operational procedures and briefings
- Incident response process and records
- Competence and supervision controls
- Monitoring and measurement (KPIs)
- Internal audits, management review, corrective actions
What Makes ISO 18788 Audits Fail
- Procedures that don't match real operations
- Weak evidence of supervision and monitoring
- Risk assessments that are generic and not site/service specific
- Corrective actions not tracked to completion
Key Takeaway
Keep it operational, keep it evidence-led, and make sure what you say you do is what you actually do. That's what ISO 18788 demands — and what clients expect from a professional security operation.
Ready to Get ISO 18788 Done Right?
Practical, paperless, and audit-ready. We'll tell you exactly what you need (and what you don't), then get you ready fast.
Get Your Free Quote