Incident Monitoring, Reporting, and Investigations under ISO 18788
Introduction
Incident management is only effective if there is a structured approach to monitoring, reporting, and investigating incidents. Clause 8.8.2 of ISO 18788:2015 requires organizations to ensure that all incidents, from minor breaches to major disruptive events, are tracked, documented, and thoroughly reviewed. This ensures that every incident becomes part of a continuous improvement cycle, feeding intelligence back into tactical risks, strategic objectives, and overall governance.
1. Incident Monitoring
Purpose
Incident monitoring is the ongoing process of detecting and tracking security events to ensure they are addressed in real-time and analysed afterward.
Key Practices
- Detection Systems:
- Access control alarms, CCTV, intrusion detection, patrol reports, bodycams, and whistleblower channels.
- Incident Logs:
- Centralized registers documenting all incidents, regardless of severity.
- Trend Analysis:
- Monitoring recurring incidents (e.g., repeated unauthorized entry) to identify systemic weaknesses.
Outcome: Incident monitoring ensures no event is overlooked, creating a reliable data pool for risk and performance analysis.
2. Incident Reporting
Purpose
Reporting provides timely communication and accountability. Every incident must be formally recorded and escalated to the appropriate authority within the SOMS.
Key Practices
- Immediate Reporting:
- Personnel must report incidents in real time through operational communication channels (radio, mobile, incident management systems).
- Structured Incident Reports:
- Each report should include:
- Date, time, and location.
- Personnel involved.
- Nature of incident (security breach, OHS, grievance, human rights issue).
- Escalation steps taken (Use of Force Continuum, communication with authorities).
- Chain of Command:
- Reports must flow upwards from operational staff → supervisors → tactical managers → strategic oversight, as necessary.
- Transparency:
- Clients and relevant stakeholders should be informed of significant incidents as part of contractual and ethical obligations.
Outcome: Incident reporting provides a traceable record for accountability, legal compliance, and audit readiness.
3. Incident Investigations
Purpose
Investigations ensure that root causes are identified, and corrective actions applied. This transforms incidents from isolated events into learning opportunities.
Key Practices
- Immediate Containment: First secure the scene and prevent further harm.
- Collection of Evidence:
- Incident reports, CCTV footage, bodycam recordings, radio logs, witness statements.
- Evidence must follow the Audit Evidence Reliability Model (AERM) for credibility.
- Root Cause Analysis (RCA):
- Determine why the incident happened, not just what happened.
- Use tools like the ICE methodology (Internal Control Effectiveness) to measure control gaps.
- Human Rights Review:
- Ensure no abuse occurred during the incident response (aligning with VPSHR).
- Corrective and Preventive Actions:
- Adjust SOPs, retrain personnel, reinforce controls, or introduce new technologies.
- Independent Oversight:
- High-risk incidents (e.g., involving firearms or allegations of abuse) should be reviewed by an independent authority or external auditor.
Outcome: Investigations ensure accountability, corrective measures, and continual improvement.
Integration with Risk and Objectives
- Operational Level: Incidents are logged, reported, and investigated.
- Tactical Level: Trends from investigations inform departmental risk registers.
- Strategic Level: Serious or recurring incidents drive policy updates, resource allocation, and long-term objectives.
This ensures incidents are not isolated but linked into the risk-objective-policy loop.
Documentation and Audit Evidence
Auditors will expect:
- Incident Management Policy and SOPs.
- Incident Logs/Registers (centralized, complete, and traceable).
- Investigation Reports (root cause, corrective action, accountability measures).
- Corrective Action Records linked to incident findings.
- Training Records showing personnel competence in reporting and investigation procedures.
- Trend Analysis Reports used in management reviews.
Most reliable evidence (AERM): CCTV/bodycam, automated system logs, signed reports.
Moderate: Supervisor notes, investigation findings.
Least reliable: Verbal accounts without documentation.
Conclusion
Incident monitoring, reporting, and investigations form the backbone of Clause 8.8.2 in ISO 18788. They transform incidents from isolated disruptions into intelligence-driven improvements.
By embedding these processes, organizations ensure that every incident is:
- Detected and tracked through monitoring.
- Reported and documented for accountability.
- Investigated and analysed for continual improvement.
This cycle protects human rights, strengthens governance, and builds client confidence that the security provider operates at the highest level of professionalism and accountability.