Management Review under ISO 18788

Introduction

Management Review is the culmination of the Plan-Do-Check-Act (PDCA) cycle within ISO 18788. While monitoring, measurement, analysis, and audits provide data, it is the Management Review that transforms this information into governance decisions, resource allocation, and strategic directionIt is not simply a meeting but a structured governance process where leadership evaluates whether the Security Operations Management System (SOMS) remains:

  • Adequate.
  • Suitable.
  • Effective.
  • Continually improving.

Purpose of Management Review

  1. Strategic Oversight - Provides the Board, CEO, and Executive Team with assurance that SOMS supports corporate objectives and human rights commitments.
  2. Performance Evaluation - Ensures results from Clause 9.1 (monitoring, measurement, analysis, evaluation) and Clause 9.2 (internal audits) are acted upon.
  3. Risk Alignment - Confirms that risks and opportunities identified (Clause 6.1) are being managed effectively.
  4. Compliance Assurance - Verifies alignment with ISO 18788, VPSHR, local laws, and client contracts.
  5. Continual Improvement - Identifies where improvements, resources, or corrective actions are required.

Inputs to Management Review

Management reviews must be evidence-based, drawing from documented information. Typical inputs include:

  • Results of Monitoring and Measurement of controls and objectives (Clause 9.1).
  • Analysis and Evaluation Reports (performance vs. strategic/tactical/operational objectives).
  • Internal Audit Results (Clause 9.2).
  • Incident Management Data (Clause 8.8) - including lessons learned.
  • Stakeholder Feedback (clients, employees, communities, subcontractors).
  • Legal and Compliance Updates (changes in law, VPSHR obligations, ISO standard revisions).
  • Risk Registers and Trends (Clause 6.1).
  • Corrective and Preventive Actions Status.
  • Training, Competence, and Awareness Records (Clause 7).
  • Resource Adequacy Reviews (budget, facilities, HR, technology).
  • Opportunities for Improvement identified during audits or exercises.

Process of Management Review

1. Planning the Review

  • Define frequency (usually quarterly, semi-annual, and annual strategic reviews).
  • Ensure participation from all governance levels: Board, EXCO, tactical managers, operational supervisors.

2. Conducting the Review

  • Review past objectives and performance.
  • Compare results against strategic, tactical, and operational objectives.
  • Evaluate the effectiveness of risk treatment plans.
  • Consider resource needs and reallocation.
  • Assess compliance with human rights obligations (VPSHR).
  • Identify non-conformities, CAPAs, and systemic weaknesses.

3. Outputs of the Review

  • Decisions on Improvement Actions - updates to SOPs, policies, or controls.
  • Strategic Adjustments - revision of objectives, priorities, or risk appetite.
  • Resource Allocation - budgets for new technology, training, or staffing.
  • Policy Updates - including Security Policy, Use of Force Policy, or Whistleblower Policy.
  • Continual Improvement Records - tracking measurable outcomes over time.
  • Communication to Stakeholders - internal (employees, subcontractors) and external (clients, communities).

Integration with the Golden Thread

  • Operational Level: Data from incidents, patrol performance, grievances.
  • Tactical Level: Divisional audits, risk registers, and KPIs.
  • Strategic Level: Management Review consolidates all information to validate objectives and governance direction.

This ensures a closed-loop system:

  • Data → Analysis → Audit → Management Review → Strategic Decisions → Implementation → New Data.

Documentation and Audit Evidence

Auditors will expect:

  • Management Review Procedure - defining frequency, responsibilities, and inputs/outputs.
  • Management Review Agendas - showing structured coverage of inputs.
  • Minutes of Management Reviews - with decisions, action points, and responsible owners.
  • Action Logs - tracking improvement measures and resource allocations.
  • Follow-up Records - proof that outputs of reviews are implemented and effective.

Most reliable evidence: Signed minutes, Board decisions, updated objectives

Moderate: Meeting presentations, summaries.

Least reliable: Verbal assurance that reviews were conducted.

Conclusion

Management Review under Clause 9.3 is the strategic control point of the SOMS. It ensures that the entire ISO 18788 ecosystem—incident management, risk management, compliance, resources, training, audits, and performance data—is brought together at governance level to drive continual improvement.

By aligning top-down strategy with bottom-up performance data, management reviews ensure the SOMS remains effective, resilient, and responsive to risks, client needs, and human rights obligations.