ISO 18788 is the standard for Security Operations Management.
In plain English, it’s about proving your security operations are:
– planned and controlled
– legally compliant
– risk-based (not reactive)
– properly supervised
– continuously improved
It’s especially relevant if you provide guarding, mobile patrols, key holding, event security, or any security service where clients need confidence you’ll do the right thing under pressure.
What ISO 18788 actually covers
ISO 18788 is built around a management system approach — similar in structure to other ISO standards — but tailored to security operations.
It focuses on:
– operational planning and control
– legal and regulatory compliance
– risk assessment and mitigation
– competence, supervision and accountability
– incident management and learning
– monitoring, audits and continual improvement
The goal isn’t paperwork. The goal is consistent, controlled delivery — with evidence.
Who ISO 18788 is for
ISO 18788 is a strong fit for:
– private security companies
– organisations delivering security operations in higher-risk environments
– suppliers working with public sector, infrastructure, or larger corporates
If your tenders ask about governance, risk, incident response, supervision, or operational control — ISO 18788 gives you a clean, auditable answer.
Why clients ask for ISO 18788
1) Buyer confidence
It shows you’re not just “licensed” — you’re managed, controlled and accountable.
2) Reduced operational risk
Better planning, clearer roles, and tighter control reduces incidents and complaints.
3) Stronger supervision and performance
It forces clarity on competence, monitoring, and corrective action.
4) Competitive advantage
In a crowded security market, ISO 18788 is a differentiator.
What you need to pass ISO 18788
You don’t need a mountain of documents — you need a working system and proof.
Typically you’ll need:
– defined scope for security operations management
– legal and compliance obligations identified and controlled
– risk assessment and controls (threats, vulnerabilities, mitigation)
– operational procedures and briefings
– incident response process and records
– competence and supervision controls (who can do what, and how it’s checked)
– monitoring and measurement (KPIs)
– internal audits, management review, corrective actions
What makes ISO 18788 audits fail
Common issues we see:
– procedures that don’t match real operations
– weak evidence of supervision and monitoring
– risk assessments that are generic and not site/service specific
– corrective actions not tracked to completion
The fix is simple: keep it operational, keep it evidence-led, and make sure what you say you do is what you actually do.
How long does ISO 18788 take?
At CAW:
– systems can be built within 48 hours
– typically delivered in 72 hours
Audit scheduling depends on the certification body, but the system build and prep doesn’t need to drag on.
Why CAW
– 100% pass rate across all standards and certification bodies (including UKAS)
– fastest turnaround in the country
– at least 50% cheaper than other UK consultancies
– ISO consultancy package price: £999
CTA
If you want ISO 18788 done properly — practical, paperless, and audit-ready — message us. We’ll tell you exactly what you need (and what you don’t), then get you ready fast.

Leave a comment