Defining Roles and Responsibilities in the Security Operations Management System (SOMS)

Introduction

A Security Operations Management System (SOMS) cannot succeed without clarity of roles and responsibilities. Clause 5.3 of ISO 18788:2015 requires organizations to assign, communicate, and document responsibilities across all levels. This ensures that security operations are managed consistently, transparently, and in alignment with the standard's principles of governance, accountability, and respect for human rights.

Defining roles is not merely administrative—it ensures accountability, prevents duplication of effort, and creates a culture of ownership from the Board to frontline personnel.

Why Roles and Responsibilities Matter

  1. Accountability - Ensures that each role has clearly defined duties, reducing gaps in security oversight.
  2. Consistency - Provides uniform application of policies and procedures across all regions and operations.
  3. Compliance - Demonstrates conformance with ISO 18788 requirements and contractual/legal obligations.
  4. Efficiency - Streamlines decision-making and escalations through defined reporting structures.
  5. Assurance - Provides auditors, clients, and regulators with confidence that responsibilities are clearly established and monitored.

Roles and Responsibilities Across the Organization

1. Board of Directors and Executive Committee (Top Management)

  • Approve and oversee the SOMS.
  • Establish the Security Policy and human rights commitments.
  • Allocate sufficient resources (financial, technological, and human).
  • Integrate SOMS into strategic planning.
  • Set the tone at the top by modelling ethical leadership.
  • Review SOMS performance through management reviews.

2. Divisional and Regional Managers (Middle Management)

  • Translate strategy into operational processes.
  • Ensure policies and procedures are implemented in their divisions/regions.
  • Monitor risk assessments and ensure mitigation measures are in place.
  • Provide upward reporting to executives and downward guidance to supervisors.
  • Act as risk and compliance champions in their business units.

3. Sectional Managers and Supervisors (Operational Leadership)

  • Enforce daily operational compliance with SOMS procedures.
  • Manage incidents, reporting, and escalation processes.
  • Ensure frontline staff understand rules of engagement, use of force policies, and human rights requirements.
  • Conduct daily oversight of guard deployments, shifts, and incident logs.
  • Build the tone at the operational level, embedding a culture of professionalism.

4. SOMS Manager / Compliance Manager

  • Act as the custodian of the SOMS.
  • Ensure that SOMS processes are implemented, monitored, and improved.
  • Lead SOMS Champions in each department.
  • Report regularly to top management on SOMS performance.
  • Coordinate audits, risk assessments, and continual improvement actions.

5. SOMS Champions (Departmental Representatives)

  • Represent their departments in SOMS implementation.
  • Drive awareness and compliance in their functional areas.
  • Report risks, incidents, and compliance challenges to the SOMS Manager.
  • Conduct periodic self-assessments.
  • Promote employee participation and feedback in improving security operations.

6. Internal Audit and Compliance Officers

  • Plan and conduct internal audits of the SOMS.
  • Monitor implementation of corrective actions.
  • Ensure compliance obligations are regularly reviewed.
  • Provide objective assurance to top management.

7. Human Resources

  • Integrate SOMS requirements into recruitment, vetting, training, and disciplinary processes.
  • Conduct background checks and ensure employee competence.
  • Provide SOMS-related training and awareness programs.
  • Support alignment with labour law and human rights obligations.

8. All Employees and Frontline Security Personnel

  • Comply with SOMS policies, procedures, and operational guidelines.
  • Report incidents, risks, or non-compliance promptly.
  • Respect human rights and act lawfully in all operations.
  • Participate in awareness and training initiatives.

RACI Matrix as a Best Practice Tool

Organizations often complement roles and responsibilities with a RACI (Responsible, Accountable, Consulted, Informed) Matrix, ensuring clarity in:

  • Responsibility - Who executes the task.
  • Accountability - Who is ultimately answerable.
  • Consulted - Who provides input or advice.
  • Informed - Who must be updated on progress or decisions.

This approach ensures no duplication, no gaps, and full traceability in the SOMS.

Conclusion

Clause 5.3 of ISO 18788 is about ensuring clarity, accountability, and ownership across all levels of the organization. From the tone at the top established by the Board, through the tone in the middle maintained by managers, to the tone at the operational level enforced by supervisors and guards, every role must be clearly defined, communicated, and monitored.

By documenting roles and responsibilities in the SOMS Manual—and reinforcing them with tools such as RACI matrices—organizations demonstrate to clients, auditors, and communities that their security operations are structured, professional, and aligned with international best practice.