Connecting Apprehension and Search with the Use of Force Continuum, Human Rights, and VPSHR
Introduction
Apprehension and search are among the most sensitive activities in security operations. They involve direct physical interaction with individuals, which introduces legal, ethical, and reputational risks. If not governed properly, these activities can lead to human rights violations, client mistrust, and regulatory sanctions.
To manage these risks, ISO 18788 requires that apprehension and search processes be lawful, necessary, proportionate, and accountable. This is best achieved when they are linked to three critical frameworks:
- The Use of Force Continuum.
- Human rights obligations under international law.
- The Voluntary Principles on Security and Human Rights (VPSHR).
Apprehension and Search within the Use of Force Continuum
The Use of Force Continuum provides a structured escalation path — from presence to lethal force — ensuring that force is used only as required. Apprehension and search sit squarely within this framework:
- Officer Presence & Verbal Commands - The first stages of apprehension are rooted in professional presence and verbal direction. A subject should always be given a clear opportunity to comply voluntarily.
- Soft Control (Restraints / Guiding Holds) - If the subject resists, minimal force may be applied to effect apprehension or search. This must remain non-violent and focused on control, not punishment.
- Hard Control or Non-Lethal Tools - Only if resistance escalates or safety is threatened should harder control measures or authorized non-lethal tools (batons, shields, handcuffs) be applied.
- Lethal Force (Last Resort) - Only in situations where there is an imminent threat to life would the continuum permit escalation to lethal force during apprehension.
Key Point: Apprehension and search must always start at the lowest possible level of the continuum and escalate only as strictly necessary.
Human Rights Considerations in Apprehension and Search
Security providers are legally and ethically obligated to respect internationally recognized human rights during apprehension and search:
- Right to Dignity - Individuals must not be humiliated, degraded, or treated inhumanely during search procedures.
- Right to Privacy - Searches must be justified, proportionate, and conducted with sensitivity (gender-appropriate personnel, private settings).
- Right to Liberty and Security - Apprehension must be based on lawful grounds, and individuals must be informed of the reasons for detention.
- Right to Life - The use of lethal force during apprehension may only occur when there is an imminent threat to life.
Key Point: Every apprehension and search must balance security needs with the preservation of fundamental rights.
VPSHR and Responsible Security Practice
The Voluntary Principles on Security and Human Rights (VPSHR) provide specific guidance for companies, particularly in extractive and high-risk sectors, where security forces interact closely with local communities. VPSHR's three pillars align directly with apprehension and search:
- Risk Assessment
- Apprehension and search protocols must be based on risk assessments that consider potential human rights impacts (e.g., racial profiling, unlawful detention).
- Interactions with Public Security
- When apprehension involves handing over individuals to public police or military forces, VPSHR requires protocols that ensure these actors also respect human rights.
- Interactions with Private Security
- Private guards must be vetted, trained, and monitored to ensure apprehension and search are lawful and proportionate.
Key Point: VPSHR requires security providers to embed human rights into every stage of security interactions, including apprehension and search.
Integrating the Frameworks in Practice
To fully connect apprehension and search with the Use of Force Continuum, Human Rights, and VPSHR, organizations should:
- Develop Clear SOPs
- SOPs must define escalation pathways in line with the Use of Force Continuum.
- Searches must always be lawful, consent-based where possible, and gender-sensitive.
- Train Personnel
- Training must emphasize de-escalation first.
- Human rights and VPSHR modules must be integrated into use-of-force training.
- Monitor and Review Incidents
- Every apprehension and search incident must be documented and independently reviewed.
- Data should be used to identify trends (e.g., patterns of complaints, use of excessive force).
- Engage Stakeholders
- Communities, clients, and regulators should be engaged to ensure that apprehension and search processes respect local expectations and VPSHR obligations.
Documentation and Audit Evidence
Auditors will seek evidence of:
- Policies and SOPs - Aligned with ISO 18788, Use of Force Continuum, and VPSHR.
- Training Records - Proof of competence in human rights and lawful search procedures.
- Incident Logs - Detailed records of apprehensions, with escalation steps documented.
- Grievance Registers - Evidence that complaints regarding apprehension and search are recorded and resolved.
- Audit Trails - Armory logs, bodycam/CCTV footage, and supervisor reviews.
Audit Evidence Reliability Model (AERM):
- Most reliable: CCTV/bodycam evidence, biometric logs, signed consent/authorization forms.
- Moderately reliable: Supervisor reports, written witness statements.
- Least reliable: Verbal accounts without supporting documentation.
Conclusion
Apprehension and search are pivotal moments where security operations intersect with the Use of Force Continuum, human rights, and the Voluntary Principles on Security and Human Rights (VPSHR).
By ensuring that these activities are lawful, necessary, proportionate, and accountable, organizations demonstrate their commitment to ethical conduct, client assurance, and ISO 18788 certification.
When connected with the Use of Force Continuum, they ensure escalation is controlled. When integrated with human rights and VPSHR, they ensure dignity and trust are preserved. Together, they form the golden thread of lawful, ethical, and auditable security operations.
Introduction
Clause 6.2.2 of ISO 18788:2015 builds on the foundation of Clause 6.2 (Security Operations Objectives) and requires organizations to not only define objectives but also to establish plans for how these objectives will be achieved and treated. This clause ensures that objectives are actionable, measurable, and linked to risk treatment measures, providing assurance to clients, regulators, and communities that security operations are managed systematically and ethically.
The focus here is on bridging the gap between policy and practice—transforming strategic objectives into operational results through concrete actions, treatments, and monitoring mechanisms.
Security Operations Objectives in Context
As outlined in Clause 6.2, Security Operations Objectives must:
- Be consistent with the Security Policy (Clause 5.2).
- Align with the risk and opportunities process (Clause 6.1).
- Be measurable where practicable.
- Be communicated and understood throughout the organization.
- Be monitored, evaluated, and continually improved.
Clause 6.2.2 takes this further by requiring organizations to define how these objectives will be achieved and treated.
Planning to Achieve Security Operations Objectives
ISO 18788 requires organizations to create structured plans that detail:
- What will be done
- Define clear initiatives, projects, or controls to achieve each objective.
- Example: If the objective is “Reduce incident response time by 20%â€, the plan may include:
- Implementing new digital reporting tools.
- Training supervisors in rapid decision-making.
- Establishing a 24/7 operations control centre.
- What resources will be required
- Financial budgets, personnel, technology, and logistical support.
- Example: Allocating funds for surveillance upgrades or hiring additional compliance officers.
- Who will be responsible
- Clear ownership through assignment of accountable individuals or departments.
- Example: Operations Department accountable; IT Department providing technology support.
- When it will be completed
- Time-bound objectives and milestones with realistic deadlines.
- Example: All guard force retraining completed by Q4.
- How results will be evaluated
- Key Performance Indicators (KPIs) and measurable metrics.
- Example: Tracking average response time before and after the new processes are implemented.
Linking Objectives with Risk Treatment
Clause 6.2.2 integrates directly with Clause 6.1 (Risks and Opportunities) and requires that achieving objectives must involve risk treatment actions.
- Risk Identification - Each objective must be linked to risks identified in the Strategic, Tactical, or Operational Risk Registers.
- Risk Treatment Options (aligned with ISO 31000:2018):
- Avoid - Cease operations in high-risk areas.
- Mitigate - Apply controls to reduce likelihood or impact.
- Transfer - Outsource or insure against risk.
- Accept - Tolerate residual risks within defined risk appetite.
- Implementation of Controls - Security controls (training, procedures, technology, governance) must be mapped to objectives.
- Monitoring Residual Risk - Post-treatment monitoring ensures risks remain within tolerable levels.
Example:
- Objective: Ensure compliance with human rights obligations.
- Risk: Allegations of unlawful detention by security staff.
- Treatment:
- Mandatory human rights training for all guards.
- Clear rules of engagement.
- Independent grievance mechanisms.
- Evaluation: Tracking incidents, complaints, and disciplinary actions.
Achieving and Sustaining Security Operations Objectives
To ensure objectives are successfully achieved:
- Integration with Daily Operations - Objectives must be embedded in operational procedures, not treated as parallel activities.
- Performance Management - Use dashboards, scorecards, and KPI monitoring to track progress.
- Management Reviews - Regular reviews by top management to assess effectiveness, allocate resources, and make adjustments.
- Audit and Assurance - Internal audits and external certification audits verify that objectives and treatments are properly applied.
- Continual Improvement - Lessons learned from incidents, near misses, and audits feed back into updated objectives and treatment plans.
Example of an Objective and Treatment Flow
- Strategic Objective: Enhance client trust through international certification.
- SOMS Objective: Achieve and maintain ISO 18788 certification.
- Departmental Objective: Conduct quarterly compliance audits across all regions.
- Operational Objective: Ensure 100% incident reports are submitted within 24 hours.
- Linked Risk: Inconsistent incident reporting across provinces.
- Treatment:
- Implement standardized digital reporting tool.
- Train all supervisors in its use.
- Audit incident reports monthly.
- Evaluation: Measure compliance rate, corrective actions, and residual risk rating.
This demonstrates the golden thread of alignment, supported by treatments that are concrete, measurable, and linked to risk management.
Conclusion
Clause 6.2.2 of ISO 18788 ensures that Security Operations Objectives are not abstract intentions but concrete, measurable commitments backed by resources, responsibilities, timelines, and treatments. By linking objectives to risk treatment, organizations create a transparent and auditable process that aligns strategy with daily operations.
Ultimately, this clause ensures that security companies and departments move from policy to practice, delivering on their commitments to professionalism, human rights, compliance, and continual improvement.