Internal Audit under ISO 18788
Introduction
An internal audit is not merely a compliance exercise — it is a systematic, independent, and documented process that evaluates whether the SOMS:
- Conforms to the requirements of ISO 18788 and related standards.
- Has been effectively implemented and maintained.
- Achieves the objectives set at the strategic, tactical, and operational levels.
Clause 9.2 ensures that the organization establishes and maintains an internal audit program that provides assurance to top management, clients, and regulators.
Objectives of Internal Audit
- Assurance of Compliance - Verify conformity with ISO 18788, VPSHR, local laws, and contractual requirements.
- Operational Effectiveness - Assess whether controls and SOPs are working in practice, not just on paper.
- Risk Management Integration - Confirm that risks identified in Clause 6.1 are addressed through effective controls and continual improvement.
- Continual Improvement - Identify opportunities for corrective and preventive action.
- Accountability and Transparency - Provide evidence of oversight and governance for clients, communities, and regulators.
The Internal Audit Program
An internal audit program must be planned, risk-based, and systematic.
1. Audit Planning
- Develop an annual audit plan covering all SOMS processes, functions, and sites.
- Prioritize high-risk areas (e.g., use of force, weapons management, grievance handling).
- Ensure coverage of strategic, tactical, and operational processes.
2. Audit Criteria and Scope
- Criteria: ISO 18788 clauses, internal policies, legal obligations, VPSHR, client contracts.
- Scope: Must be clearly defined (e.g., site audits, process audits, thematic audits such as Human Rights or Incident Management).
3. Independence and Objectivity
- Auditors must be independent of the activities they audit.
- Cross-functional audit teams or external consultants may be used for sensitive areas.
4. Audit Execution
- Collect evidence through interviews, observation, document review, and testing of controls.
- Use the Audit Evidence Reliability Model (AERM) to prioritize objective, verifiable evidence.
5. Reporting and Corrective Actions
- Audit findings must be documented in clear, factual reports.
- Nonconformities must be classified (major, minor, opportunities for improvement).
- Corrective actions must be tracked to closure.
Integration with Strategic, Tactical, and Operational Levels
- Strategic: Internal audits provide assurance to the Board and CEO that SOMS aligns with governance and compliance objectives.
- Tactical: Divisional managers receive insights into process gaps and resource needs.
- Operational: Supervisors and guards receive corrective actions and retraining based on audit findings.
Audits therefore connect top-down strategy with bottom-up operational realities, closing the loop between governance and field-level implementation.
Frequency of Audits
- Must be defined in the audit program (typically annual coverage of all processes).
- High-risk areas may require quarterly or semi-annual audits.
- Unplanned (ad-hoc) audits may be triggered by incidents, complaints, or grievances.
Documentation and Audit Evidence
Auditors and certification bodies will expect to see:
- Internal Audit Procedure - defining responsibilities, criteria, and reporting requirements.
- Annual Audit Plan - showing risk-based prioritization.
- Audit Checklists - aligned with ISO 18788 clauses.
- Audit Reports - with findings, nonconformities, and corrective actions.
- Corrective Action Logs - tracking resolution of audit findings.
- Management Review Records - demonstrating leadership follow-up on audits.
Most reliable evidence: Audit reports with supporting records and corrective action closures.
Moderate: Meeting notes, verbal confirmations documented by auditor.
Least reliable: Informal or undocumented observations.
Conclusion
Internal audits under Clause 9.2 of ISO 18788 are a critical assurance mechanism. They provide independent verification that the SOMS is:
- Compliant with ISO 18788 and contractual/legal obligations.
- Effectively implemented and maintained across all levels.
- Continuously improving through corrective and preventive actions.
A strong internal audit program builds trust with clients, confidence for the Board, and assurance for communities that the security provider operates with accountability, transparency, and human rights at the core of its SOMS.