Establishing Norms of Behaviour and Codes of Ethical Conduct

Introduction

Security companies operate in high-risk environments where staff interact daily with clients, communities, and sometimes hostile actors. These interactions carry moral, legal, and reputational risks. Clause 8.2 of ISO 18788:2015, supported by A.8.2, requires organizations to define, communicate, and enforce norms of behaviour and ethical codes of conduct.

This is not an abstract exercise. Norms and codes must become practical tools that shape daily conduct, guide decision-making under stress, and reinforce the organization's commitment to human rights, legal compliance, and professional standards.

Purpose of Norms and Codes in Security Operations

  1. Ethical Compass - Ensures security staff act with integrity, even when laws or contracts may be ambiguous.
  2. Risk Control - Prevents misconduct that could escalate into legal cases, reputational crises, or loss of client trust.
  3. Cultural Alignment - Shapes organizational culture by reinforcing shared values and expectations.
  4. Human Rights Protection - Ensures staff understand and respect the inherent dignity and rights of all people, in line with A.8.1.3 and the Voluntary Principles on Security and Human Rights (VPSHR).
  5. Audit and Certification - Provides evidence of compliance with ISO 18788, ISO 37001 (Anti-Bribery), and ISO 37301 (Compliance).

Elements of Norms of Behaviour and Ethical Codes

According to Clause 8.2 and Annex A.8.2, organizations must establish norms and codes that address:

  • Integrity and Honesty - Zero tolerance for corruption, bribery, or fraudulent conduct.
  • Respect for Human Rights - Adherence to VPSHR, UN Guiding Principles, and local laws.
  • Use of Force - Clear rules on proportionality, escalation, and lawful conduct.
  • Confidentiality and Data Protection - Respecting privacy of clients, staff, and communities.
  • Conflict of Interest - Disclosure and management of personal or organizational conflicts.
  • Professionalism - Behaviour that promotes dignity, cultural sensitivity, and respect.
  • Community Engagement - Building trust through transparency and dialogue.
  • Reporting Obligations - Duty to report misconduct, violations, or unethical behaviour.
  • Whistleblower Protections - Safe, confidential channels for raising concerns.

Strategic, Tactical, and Operational Implementation

1. Strategic Level

  • Policy Framework: Executive management adopts a Code of Ethical Conduct as a binding governance document.
  • Tone at the Top: Board and executives set examples by consistently modelling ethical behaviour.
  • Integration: Ethical standards linked to strategic objectives, contracts, and risk management.
  • Stakeholder Engagement: Policy commitments communicated to clients, regulators, and communities.

2. Tactical Level

  • Procedures and Guidance: Departmental managers translate codes into SOPs and operational rules.
  • Training: Competence programs include modules on ethics, anti-bribery, and human rights.
  • Monitoring and Enforcement: Tactical audits ensure compliance with behavioural norms.
  • Disciplinary Measures: Clear consequences for breaches, applied consistently.

3. Operational Level

  • Daily Practice: Guards, patrols, and frontline staff follow SOPs based on the Code.
  • Toolbox Talks & Awareness Campaigns: Reinforce expected behaviours through reminders.
  • Incident Reporting: Frontline personnel know how to escalate ethical breaches or misconduct.
  • Behavioural KPIs: Supervisors track conduct indicators (e.g., complaint trends, grievance resolutions, client feedback).

Documentation and Audit Evidence

To demonstrate compliance with Clause 8.2, organizations must keep:

  • Code of Conduct Document: Signed and communicated to all employees.
  • Training Records: Proof of ethical and human rights training delivered.
  • Incident Reports: Logs of ethical violations, use-of-force cases, or misconduct.
  • Disciplinary Records: Documentation of corrective or punitive actions taken.
  • Whistleblower Logs: Evidence of safe channels and protection measures.
  • Management Review Minutes: Records of ethical performance monitoring.

Evidence must comply with the Audit Evidence Reliability Model (AERM):

  • Confirmative Evidence: External audits, certifications (ISO 37001, ISO 37301).
  • Analytical Evidence: Ethics dashboards, trend analyses.
  • Physical Evidence: Signed codes, training attendance registers, incident logs.

Benefits of Ethical Norms in Security Operations

  1. Reputation & Trust: Demonstrates professionalism and credibility to clients and regulators.
  2. Risk Mitigation: Reduces exposure to lawsuits, fines, or reputational damage.
  3. Cultural Strength: Reinforces a positive work culture and employee engagement.
  4. Human Rights Protection: Prevents violations that could escalate into community conflict or international scrutiny.
  5. Audit and Certification Success: Ensures ISO 18788 certification is sustainable and defensible.

Conclusion

Clause 8.2 of ISO 18788, supported by A.8.2, requires organizations to define and enforce norms of behaviour and codes of ethical conduct that ensure professionalism, compliance, and respect for human rights.

By managing these norms strategically (policy and governance), tactically (procedures and monitoring), and operationally (daily conduct and training), security companies create a culture of integrity and accountability. This culture not only protects the organization and its clients but also strengthens community trust and supports international certification.