The Statement of Conformance (SoC) in ISO 18788: Demonstrating Leadership, Accountability, and Commitment

Introduction

In the governance of security operations, trust, accountability, and transparency are non-negotiable. ISO 18788:2015, the international standard for Security Operations Management Systems (SOMS), recognizes this by requiring organizations to establish a Statement of Conformance (SoC) under Clause 5.1.2.

The SoC is a formal declaration by top management that the organization is committed to conducting its security operations in full alignment with ISO 18788 requirements, applicable laws, contractual obligations, and international human rights principles. This statement is not symbolic—it is a binding expression of accountability that provides confidence to clients, employees, regulators, and affected communities.

Purpose of the Statement of Conformance

The SoC provides three key assurances:

  1. Commitment from Leadership
    • Demonstrates that the Board, Executives, and Top Management accept ultimate responsibility for ethical, lawful, and professional security operations.
    • Reinforces the “Tone at the Top” and cascades accountability throughout the organization.
  2. Alignment with Standards and Laws
    • Affirms compliance with ISO 18788, relevant national legislation, and international frameworks such as the Montreux Document, the International Code of Conduct for Private Security Providers (ICoC), and the UN Guiding Principles on Business and Human Rights.
  3. Assurance to Stakeholders
    • Provides clients, regulators, auditors, and communities with confidence that the organization has formally committed to ethical and transparent practices.
    • Positions the company as a responsible security provider worthy of international certification and trust.

Key Elements of a Statement of Conformance

A robust SoC should include:

  1. Endorsement by Top Management
    • Signed by the CEO, Board Chair, or equivalent authority.
    • Clearly stating accountability for the SOMS.
  2. Commitment to ISO 18788 Implementation
    • A declaration that the organization has implemented, maintains, and will continually improve its SOMS.
    • Confirmation that policies, procedures, and controls are aligned with the standard.
  3. Commitment to Human Rights and Ethics
    • Explicit statement of respect for human rights and humanitarian law.
    • A pledge that operations will be conducted lawfully, proportionately, and transparently.
  4. Scope of Application
    • Confirmation of the operations, personnel, and services covered under the SoC.
    • Avoidance of narrow or misleading scopes that could undermine credibility.
  5. Continual Improvement
    • A pledge that the SOMS will be regularly reviewed, audited, and improved in line with changing risks, contexts, and stakeholder needs.

Why the SoC Matters

  • For Clients - It assures them that services are delivered within a governance framework that respects law, ethics, and human rights.
  • For Employees & Contractors - It sets clear expectations and empowers them to act in line with organizational values.
  • For Regulators & Auditors - It serves as documentary evidence that top management is accountable for SOMS conformance.
  • For Communities & Stakeholders - It signals transparency, respect, and commitment to responsible operations.

The SoC as a Leadership Tool

The SoC is more than a compliance requirement—it is a leadership statement. When communicated effectively, it reinforces:

  • Tone at the Top - Leadership accountability.
  • Tone in the Middle - Managerial ownership of conformance.
  • Tone at the Operational Level - Frontline confidence that operations are governed by standards, not improvisation.

By signing and publishing the SoC, leaders demonstrate that they are personally invested in ethical, lawful, and sustainable security operations.

Conclusion

The Statement of Conformance (Clause 5.1.2 of ISO 18788) is a cornerstone of accountability in security operations. It provides visible assurance that top management is committed to implementing, maintaining, and continually improving the SOMS in line with international standards and human rights principles.

For clients, auditors, regulators, and communities, the SoC is proof of intent and trustworthiness. For the organization, it is a leadership tool that cements credibility and strengthens the path toward international certification, ethical conduct, and operational excellence.

Introduction

In security operations, controls are the backbone of risk management. Clause 6 of ISO 18788:2015 requires organizations to establish and maintain controls to mitigate risks, protect human rights, and deliver professional, ethical, and lawful security services. While ISO 27002 provides structured categories of controls for information security, the same principles can be adapted to the security operations environment.

To move beyond “tick-box compliance,” security controls must be verifiable, repeatable, and validated. This is achieved by applying Internal Control Effectiveness (ICE) to measure performance and embedding controls into a Combined Assurance Model (CAM) to demonstrate reliability to boards, clients, regulators, and communities.

Security Controls in the ISO 18788 Environment

Drawing from ISO 27002 control families but tailoring them to security operations, controls in the SOMS may include:

  1. People Controls (Human Resources & Competence)
    • Vetting, background checks, training, and competence assessments.
    • Ethical awareness and human rights training.
  2. Process Controls (Policies & Procedures)
    • Security policies, SOPs, deployment procedures, and incident management protocols.
    • Use of force guidelines, grievance mechanisms, escalation processes.
  3. System Controls (Operational Management Systems)
    • Rostering, deployment, and incident reporting systems.
    • Risk registers and compliance tracking platforms.
  4. Tools & Equipment Controls
    • Radios, vehicles, personal protective equipment (PPE), firearms, and body-worn cameras.
    • Maintenance and calibration processes.
  5. Technology Controls
    • CCTV with AI analytics, access control systems, drone surveillance.
    • Automated reporting and monitoring technologies.
  6. Compliance & Governance Controls
    • Licensing, legal obligations, contractual compliance, and audits.
    • Alignment with the Montreux Document, ICoC, and human rights frameworks.

Measuring Control Effectiveness with ICE

The Internal Control Effectiveness (ICE) methodology provides structured measurement of each control's effectiveness:

  • Excellent (90%+) - Fully effective, no further treatment needed.
  • Very Good (80%) - Strong control, minor improvements possible.
  • Good (70%) - Majority of risk exposure controlled.
  • Satisfactory (60%) - Basic control in place but not fully managed.
  • Weak to Ineffective (≤ 50%) - Controls exist but major deficiencies remain.
  • No Control (0%) - No evidence of mitigating measures.

Each Management Control (MC) is linked to a Contributing Factor (CF) in the risk register and assessed with ICE. The resulting percentage gives a Level of Assurance (LoA) and helps determine the residual Level of Risk (LoR).

This ensures that security risks are not managed through assumptions or “Fear, Uncertainty, and Doubt (FUD),” but through quantifiable evidence of control performance.

Combined Assurance Mapping of Controls

A Combined Assurance Model (CAM) integrates ICE results into a holistic framework, ensuring that all levels of assurance are addressed:

  • Management (1st Line) - Responsible for implementing controls.
  • Risk & Compliance (2nd Line) - Monitors and validates control effectiveness.
  • Internal Audit (3rd Line) - Provides independent assurance.
  • External Assurance (4th Line) - Certification bodies and regulators.
  • Clients & Stakeholders (5th Line) - External verification through contracts, SLA compliance, and feedback.
  • Community & Society (6th Line) - Human rights, ethical assurance, and social license to operate.

By mapping security controls through these six lines of assurance, organizations can demonstrate transparency, accountability, and stakeholder confidence.

Benefits of Using ICE and Combined Assurance for Security Controls

  1. Objectivity - Provides measurable evidence of control effectiveness.
  2. Traceability - Links each control to specific risks, objectives, and assurance providers.
  3. Transparency - Builds trust with clients, regulators, and communities.
  4. Strategic Decision-Making - Guides leadership on where to strengthen, treat, or redesign controls.
  5. Audit Readiness - Provides structured evidence for certification under ISO 18788 and alignment with ISO 31000 and ISO 37301.

Conclusion

Security controls under ISO 18788 must go beyond being listed in policies—they must be measured and validated. By adopting structured control families (inspired by ISO 27002), applying the ICE methodology for effectiveness measurement, and embedding them into a Combined Assurance Model, organizations can create a powerful, evidence-based framework.

This approach assures clients, regulators, and communities that controls are real, effective, and aligned with international best practice. It also empowers leadership with reliable insights, ensuring that the SOMS is not only compliant but also resilient, ethical, and performance-driven.