Internal and External Complaint and Grievance Procedures under ISO 18788
Introduction
A robust security operation is not measured only by how it prevents and responds to incidents but also by how it listens and responds to grievances. Complaints and grievances are a feedback mechanism for clients, communities, employees, and other stakeholders.
Clause 8.8.3 of ISO 18788 requires security companies to establish clear, accessible, and transparent internal and external complaint and grievance procedures. These processes ensure accountability, protect human rights, and provide evidence of continual improvement.
Purpose of Complaint and Grievance Procedures
- Accountability and Transparency - Demonstrate that the organization takes concerns seriously.
- Human Rights Protection - Provide mechanisms for reporting abuses, discrimination, or misconduct.
- Conflict Resolution - Resolve disputes quickly before they escalate into larger risks.
- Risk Management - Identify recurring issues that signal systemic weaknesses.
- Reputation Management - Show clients and communities that the company is responsive, ethical, and trustworthy.
Internal Complaint and Grievance Procedures
Internal procedures focus on employees and subcontractors.
Key Elements
- Access and Awareness: All staff must know how to file a grievance, through HR, supervisors, or digital platforms.
- Confidentiality and Non-Retaliation: Staff must feel safe to raise issues without fear of retaliation.
- Investigation and Resolution: Complaints must be formally investigated, with findings documented and corrective actions taken.
- Escalation: If unresolved at a supervisor level, grievances must escalate through HR to senior management.
- Integration with Whistleblower Policy: Anonymous reporting channels should be available for sensitive issues.
Examples of Internal Grievances
- Allegations of excessive use of force by colleagues.
- Unsafe working conditions or OHS violations.
- Discrimination, harassment, or unethical conduct by supervisors.
- Payroll or contractual disputes.
External Complaint and Grievance Procedures
External procedures ensure clients, communities, and stakeholders can raise concerns.
Key Elements
- Accessibility: Complaints channels must be open to all affected external stakeholders (hotlines, email, community liaison offices).
- Transparency: Processes must be published and explained in contracts, community engagements, and client agreements.
- Timeliness: Complaints must be acknowledged promptly and resolved within set timelines.
- Independence: Sensitive complaints (e.g., human rights violations) may require external review or third-party mediation.
- Communication: Outcomes must be communicated clearly to the complainant, within the limits of confidentiality.
Examples of External Grievances
- Community complaints about security personnel misconduct.
- Client concerns about service delivery or compliance.
- Allegations of human rights abuses by subcontractors.
- Local business complaints about disruptive security practices.
Link to Human Rights and VPSHR
- Complaint and grievance mechanisms are essential to human rights protection.
- They operationalize the Voluntary Principles on Security and Human Rights (VPSHR), which require companies to provide accessible, effective grievance channels for communities.
- They ensure victims of misconduct have a path to remedy and that incidents are not hidden but addressed systematically.
Integration with Risk Management
- Complaints feed into risk registers, highlighting systemic or recurring issues.
- For example: multiple complaints of excessive force → tactical risk of misconduct → strategic objective to strengthen training and oversight.
- Complaints are also inputs into incident management (Clause 8.8.1) and continual improvement (Clause 10).
Documentation and Audit Evidence
Auditors will expect:
- Policies and SOPs on complaint and grievance handling.
- Registers documenting internal and external complaints.
- Investigation Reports with findings, corrective actions, and follow-ups.
- Evidence of Communication with complainants.
- Trend Analysis Reports showing how complaints inform improvements.
Audit Evidence Reliability (AERM):
- Most reliable: Signed grievance records, case management logs, audio recordings of hotline reports.
- Moderate: Supervisor notes, HR memos.
- Least reliable: Verbal statements without documentation.
Conclusion
Internal and external complaint and grievance procedures are the voice of accountability in a security organization. They provide employees, clients, and communities with safe, accessible, and reliable channels to raise concerns and ensure issues are investigated transparently.
By embedding these processes into the SOMS, aligned with ISO 18788, ISO 37301 (Compliance), and VPSHR, organizations not only comply with standards but also earn trust, reduce risks, and strengthen their license to operate.