Continual Improvement under ISO 18788
Introduction
ISO 18788 is designed as a risk-based, performance-driven management system. Its success depends not on one-time compliance, but on the organization's ability to continuously learn, adapt, and improve.
Clause 10.2 requires organizations to continually improve the adequacy, suitability, and effectiveness of the Security Operations Management System (SOMS). This ensures the system stays relevant, resilient, and trusted in a changing security, legal, and human rights environment.
Why Continual Improvement Matters
- Dynamic Risk Environment
- Security risks evolve (new threats, technology, political contexts).
- Improvement ensures the SOMS adapts to these changes.
- Client and Stakeholder Trust
- Demonstrates commitment to excellence, accountability, and responsiveness.
- Supports compliance with VPSHR and human rights frameworks.
- Sustained Compliance
- Prevents stagnation and maintains alignment with ISO 18788, ISO 31000, ISO 37301, and other integrated standards.
- Operational Excellence
- Turns lessons learned into better SOPs, training, and resource allocation.
Inputs Driving Continual Improvement
Continual improvement must be evidence-driven, using inputs from across the SOMS:
· Incident and Investigation Data (Clause 8.8)
o Identifies recurring failures or risks that require systemic fixes.
· Monitoring & Measurement Results (Clause 9.1.1-9.1.4)
o Reveals underperforming controls.
· Audits (Clause 9.2)
o Provide findings and opportunities for improvement.
· Management Review Outputs (Clause 9.3)
o Strategic-level decisions driving improvement.
· Corrective Action Records (Clause 10.1)
o Ensure lessons learned from NCs are institutionalized.
· Stakeholder Feedback (Clause 4.2)
o Communities, clients, and subcontractors highlight performance gaps.
· Legal/Regulatory Updates
o Improvement ensures compliance with new obligations.
The Continual Improvement Process
1. Identify
- Collect opportunities for improvement (OFIs) from audits, reviews, incidents, risk assessments.
2. Prioritize
- Rank OFIs based on risk impact, cost-benefit, and strategic alignment.
3. Implement
- Execute improvement projects — updating SOPs, retraining staff, procuring new technology, or redesigning processes.
4. Monitor and Measure
- Track performance indicators (KPIs/KRIs) to ensure improvements deliver results.
5. Review and Institutionalize
- Confirm effectiveness in management reviews.
- Update the SOMS documentation, risk registers, and training programs.
Tools for Continual Improvement
- PDCA Cycle (Plan-Do-Check-Act) - The backbone of ISO management systems.
- Kaizen Approach - Small, incremental improvements at all levels.
- Corrective and Preventive Action (CAPA) System - Systematic handling of NCs and OFIs.
- ICE Methodology - Measuring control effectiveness to drive improvement decisions.
- Combined Assurance Model - Aligning assurance providers to reduce duplication and close gaps.
Evidence of Continual Improvement
Auditors will expect:
- Improvement Register/Log with documented opportunities for improvement.
- Action Plans and Records showing implementation of improvements.
- Trend Analysis Reports demonstrating better performance over time.
- Updated Documentation (SOPs, policies, manuals) showing integration of improvements.
- Training and Awareness Records for new/improved practices.
- Management Review Minutes confirming oversight of improvement initiatives.
Most reliable evidence: Resolved NCs linked to systemic improvements, documented changes to risk registers/SOPs, training records.
Moderate: Meeting notes, informal improvement actions logged.
Least reliable: Claims of “improvement†without documented evidence.
Integration with Strategic, Tactical, and Operational Objectives
- Strategic: Improvement initiatives must align with organizational strategy (e.g., compliance with VPSHR, strengthening reputation).
- Tactical: Divisional managers drive improvements in risk registers, SOPs, and resources.
- Operational: Guards, supervisors, and frontline personnel propose and implement improvements through feedback and lessons learned.
This creates a golden thread: operational lessons → tactical fixes → strategic improvements.
Conclusion
Continual improvement under Clause 10.2 of ISO 18788 is the heartbeat of the SOMS. It ensures that security operations remain:
- Adequate (fit for purpose).
- Suitable (aligned with organizational context and risks).
- Effective (achieving objectives consistently).
By embedding continual improvement into every layer — operational, tactical, and strategic — organizations move beyond compliance to become resilient, adaptive, and trusted partners.