Defining the Scope of the Security Operations Management System (SOMS) in ISO 18788

Introduction

The scope of the management system is one of the most critical elements of ISO 18788:2015. Clause 4.3 requires organizations to clearly define which parts of their security operations are included—or excluded—from their Security Operations Management System (SOMS). This scope becomes the foundation of the certification process and ultimately determines the credibility and acceptability of the organization's certification by clients, regulators, and stakeholders.

A narrowly defined scope may undermine the very purpose of ISO certification, particularly in the security industry where trust, accountability, and uniform service delivery across all operations are non-negotiable.

Why Scope Definition Matters

Transparency for Clients

Clients need confidence that the certification reflects the reality of operations. Certifying only a head office while excluding regional or provincial branches gives a misleading picture of compliance.

Operational Integrity

Security companies often have distributed personnel across multiple regions, including thousands of guards, supervisors, and support staff. Unless these are included in the scope, the SOMS cannot accurately demonstrate accountability and conformance across the entire organization.

Credibility of Certification

International certification bodies, such as MSECB, will assess whether the scope truly represents the organization's operational footprint. A limited scope that excludes most of the workforce diminishes the certification's credibility.

Consistency in Human Rights and Legal Compliance

ISO 18788 integrates human rights commitments, legal obligations, and risk management principles. These must apply across all operations—not just head office functions—otherwise the company risks inconsistent implementation.

Risk Management

Defining the full scope ensures that risks are assessed and managed across the entire operation, including subcontractors and provincial support staff, as required under Clauses 4.1 and 4.2 of the standard.

Example: A Nationwide Security Company

Consider a security company with 60,000 guards deployed across all 11 provinces of South Africa, supported by provincial administrative teams, and a head office with 200 personnel:

  • If the organization only certifies its head office, the scope excludes the vast majority of its workforce (over 99% of operations).
  • Such a certification would not be acceptable to discerning clients, who require assurance that the guards and regional structures delivering services on the ground operate under the same international standard.
  • The correct approach would be to include all provincial operations, deployed guards, and support personnel within the SOMS scope, ensuring full compliance across the entire enterprise.

This example highlights the principle of “no selective certification”—the scope must represent the organization's full operational reality.

Best Practices in Defining the Scope

  • Comprehensive Coverage: Include all regions, divisions, and personnel relevant to security operations.
  • Explicit Boundaries: Clearly state what is included (e.g., deployed guards, provincial offices, subcontractors) and justify any exclusions.
  • Alignment with Risk Criteria: Ensure the scope covers areas where human rights, legal compliance, and operational risks are highest.
  • Transparency in Certification: Make the Statement of Scope publicly available to clients and stakeholders.
  • Integration with Other Standards: Align scope decisions with ISO 31000 (risk), ISO 27001 (information security), and ISO 22301 (business continuity) to ensure a unified management system.

Conclusion

Clause 4.3 of ISO 18788 is not just an administrative requirement—it is the cornerstone of certification integrity. Defining the scope ensures that clients, regulators, and communities can trust that certification reflects the organization's actual operational footprint. For a security company with nationwide deployment, certifying only a small head office is inadequate and misleading. A properly defined scope must include the full structure—guards, regional offices, and support functions—to provide assurance that the organization consistently applies the principles of professionalism, legal compliance, and respect for human rights across all operations.

By doing so, companies demonstrate that their certification is authentic, credible, and internationally acceptable—a true reflection of their commitment to excellence in security operations.