Nonconformity and Corrective Action under ISO 18788

Introduction

No management system operates without flaws. Nonconformities — failures to comply with ISO 18788, company policies, client contracts, or legal/human rights obligations — must be systematically addressed.

Clause 10.1 of ISO 18788 requires organizations to establish a Corrective Action Process that ensures:

  1. Nonconformities are identified and documented.
  2. Root causes are analysed to prevent recurrence.
  3. Corrective actions are implemented, verified, and closed.
  4. Lessons learned are integrated into the SOMS for continual improvement.

What is a Nonconformity?

A nonconformity is any deviation from:

  • ISO 18788 requirements.
  • Internal SOMS policies, SOPs, or procedures.
  • Legal or regulatory obligations.
  • Client or contractual requirements.
  • Human rights principles (e.g., VPSHR).

Examples:

  • Failure to investigate an incident in line with SOP.
  • Patrol logs incomplete or falsified.
  • Weapons not properly accounted for.
  • Repeated community grievances not addressed.
  • Internal audit finding of control weakness.

The Corrective Action Process

Step 1: Identification and Documentation

  • All nonconformities must be logged in a Nonconformity Register.
  • Include: reference number, date, description, source (audit, incident, grievance, review).

Step 2: Immediate Containment (if required)

  • Take action to control the impact of the nonconformity.
  • Example: If a weapon is unaccounted for, immediately secure the area and suspend usage until resolved.

Step 3: Root Cause Analysis (RCA)

  • Determine why the nonconformity occurred, not just what happened.
  • Use structured tools:
    • 5 Whys.
    • Fishbone Diagram (Ishikawa).
    • ICE methodology (Internal Control Effectiveness).

Step 4: Corrective Action Plan (CAPA)

  • Define actions to eliminate the root cause.
  • Assign responsibility, resources, and deadlines.
  • Record in a Corrective Action Register.

Step 5: Implementation and Monitoring

  • Actions must be implemented within the agreed timeframe.
  • Progress tracked by supervisors, managers, or internal auditors.

Step 6: Verification and Closure

  • Confirm corrective actions resolved the issue and are effective.
  • Close the finding only when evidence proves resolution.
  • Record closure evidence (updated procedures, training records, audit results).

Step 7: Learning and Integration

  • Update SOPs, training, risk registers, and policies where necessary.
  • Feed lessons into management reviews (Clause 9.3) and risk assessments (Clause 6.1).

Evidence Required for Nonconformity & Corrective Actions

Auditors will expect:

  • Nonconformity Register (centralized log of all NCs).
  • Corrective Action Register (CAPA log) with status and closure evidence.
  • Root Cause Analysis Reports.
  • Containment and Immediate Action Records.
  • Verification Records (audit or re-test confirming effectiveness).
  • Management Review Minutes showing oversight of recurring NCs.

Most reliable evidence: Signed CAPA records, updated SOPs, training attendance logs, audit verification reports.

Moderate: Supervisor notes, verbal confirmations documented.

Least reliable: Unrecorded actions or undocumented verbal assurances.

Integration with Governance and Risk

  • Strategic: Board and CEO receive reports on systemic nonconformities (e.g., repeated grievances, compliance failures).
  • Tactical: Divisional managers track CAPA progress in their departments.
  • Operational: Supervisors ensure frontline corrective actions are implemented.

This ensures a golden thread from incident → nonconformity → corrective action → improvement.

Conclusion

Nonconformity and corrective action under Clause 10.1 of ISO 18788 ensures that mistakes, weaknesses, and failures are not hidden but systematically corrected and prevented from recurring.

By combining structured registers, RCA methodologies, and management oversight, organizations embed a culture of transparency, accountability, and continual improvement.

A strong corrective action process not only satisfies auditors but also builds trust with clients, regulators, and communities, showing that the security provider is serious about accountability and improvement.