ISO 18788 is the standard for Security Operations Management.
In plain English, it’s about proving your security operations are:
- Planned and controlled
- Legally compliant
- Risk-based (not reactive)
- Properly supervised
- Continuously improved
It’s especially relevant if you provide guarding, mobile patrols, key holding, event security, or any security service where clients need confidence you’ll do the right thing under pressure.
What ISO 18788 actually covers
ISO 18788 is built around a management system approach — similar in structure to other ISO standards — but tailored to security operations. It focuses on:
- Operational planning and control
- Legal and regulatory compliance
- Risk assessment and mitigation
- Competence, supervision and accountability
- Incident management and learning
- Monitoring, audits and continual improvement
The goal isn’t paperwork. The goal is consistent, controlled delivery — with evidence.
Who ISO 18788 is for
ISO 18788 is a strong fit for:
- Private security companies
- Organisations delivering security operations in higher-risk environments
- Suppliers to major clients (construction, retail, facilities management, events)
- Businesses that need to prove control and compliance in tenders
Why security companies implement ISO 18788
1) Winning tenders and contracts — Buyers increasingly ask for ISO 18788 as proof of control.
2) Reducing incidents and liability — Proper planning and supervision reduce risk.
3) Proving competence and control — You can evidence training, supervision, and decision-making.
4) Managing subcontractors — Clear processes for onboarding, monitoring, and performance.
5) Building client confidence — Clients know you’re operating to a recognised standard.
What you need to pass ISO 18788
A practical ISO 18788 system typically includes:
- Security operations policy and objectives
- Risk assessment (operational, legal, reputational)
- Legal compliance register
- Operational procedures (planning, briefing, supervision, incident response)
- Competence and training requirements
- Subcontractor and supplier management
- Incident and complaint procedures
- Performance monitoring and KPIs
- Internal audits and management review
- Corrective actions and continual improvement
What makes ISO 18788 audits fail
Common issues include:
- Risk assessments that don’t reflect real operations
- Procedures written but not followed
- Supervision and competence not evidenced
- Incidents recorded but not investigated properly
- Corrective actions not tracked to completion
- Subcontractor controls weak or missing
The fix: keep it practical, make evidence easy to capture, and make sure auditors can see the system actually working.
How long does ISO 18788 take?
At CAW:
- systems can be built within 48 hours
- typically delivered in 72 hours
Certification timing depends on the certification body’s audit schedule, but the system build and prep doesn’t need to drag on.
Why CAW
- 100% pass rate across all standards and certification bodies (including UKAS)
- fastest turnaround in the country
- at least 50% cheaper than other UK consultancies
- ISO consultancy package price: £999
Ready to get ISO 18788 done right?
If you want a security operations system that’s practical, auditable, and actually works on the ground, message us at craig@cawconsultancy.co.uk.
We’ll tell you exactly what you need (and what you don’t), then get you audit-ready fast.

Leave a comment