Respect for Human Rights in Security Operations

Introduction

Respect for human rights is a cornerstone of ISO 18788:2015. Annex A.8.1.3 emphasizes that security-related functions must always be carried out in ways that protect the dignity, rights, and freedoms of individuals. This requirement goes beyond compliance with local law; it aligns with international frameworks such as the Universal Declaration of Human Rights, the UN Guiding Principles on Business and Human Rights, and the Voluntary Principles on Security and Human Rights (VPSHR).

Security companies are often deployed in high-risk environments where the potential for abuse is significant. ISO 18788 requires a structured, auditable system that ensures human rights are respected strategically, tactically, and operationally.

The Voluntary Principles on Security and Human Rights (VPSHR)

What They Are

The VPSHR is a global multi-stakeholder initiative launched in 2000 by governments, extractive companies, and NGOs. It provides guidelines for companies to maintain the safety and security of their operations while respecting human rights.

Core Components of VPSHR

  1. Risk Assessment - Identifying risks to human rights from security operations.
  2. Interactions with Public Security - Ensuring state security forces respect human rights when protecting company operations.
  3. Interactions with Private Security - Setting standards for private security providers, including vetting, training, and accountability.
  4. Implementation Guidance - Practical steps for companies to integrate human rights into their security frameworks.

Global Application

The VPSHR is widely implemented in sectors such as oil, gas, mining, and large-scale infrastructure, particularly in fragile states and conflict-affected regions. Many multinational clients require security contractors to comply with VPSHR as a contractual condition.

Strategic Implementation (Board and Executive Level)

At the strategic level, leadership must embed human rights into the company's vision, policy, and governance structures:

  • Policy Commitment - A public Statement of Conformance (SOC) to ISO 18788 and VPSHR.
  • Risk Management Framework - Strategic risk registers include human rights risks (excessive use of force, community grievances, freedom of movement restrictions).
  • Stakeholder Engagement - Regular engagement with governments, communities, and NGOs to align expectations.
  • Governance & Oversight - Board-level committees responsible for human rights performance.
  • Resource Allocation - Budget and training dedicated to VPSHR implementation.

Tactical Implementation (Divisional and Managerial Level)

At the tactical level, management must translate strategy into processes, procedures, and controls:

  • Vetting and Recruitment - Screening of guards and supervisors for history of human rights violations.
  • Training Programs - Regular training in human rights, rules of engagement, de-escalation, and use of force.
  • Stakeholder Mapping - Identification of community leaders, grievance stakeholders, and local NGOs.
  • Partnerships with Public Security - MOUs with state forces to align conduct with VPSHR.
  • Complaint and Grievance Mechanisms - Accessible systems for employees, clients, and communities to report violations.
  • Audits and Monitoring - Tactical reviews of deployments, SOPs, and compliance with VPSHR requirements.

Operational Implementation (Frontline and Day-to-Day Level)

At the operational level, frontline staff and supervisors must apply VPSHR principles in real time:

  • Rules of Engagement - Guards follow clear SOPs that prioritize de-escalation and minimum necessary force.
  • Incident Reporting - Any human rights-related incident (use of force, community confrontation) is documented, reported, and investigated.
  • Community Engagement - Security staff trained in cultural awareness and respectful interaction.
  • Awareness and Behaviour Change - Regular toolbox talks and awareness campaigns reinforce human rights as a daily responsibility.
  • Corrective Actions - Disciplinary processes and remedial training for violations.

Linking ISO 18788 and VPSHR Across the Security Ecosystem

  1. Risk Assessment Integration
    • ISO 18788 requires risk assessments (Clause 6.1). VPSHR aligns by requiring risk assessments that specifically address human rights impacts.
  2. Documentation and Evidence
    • Clause 7.5 requires documented information; VPSHR compliance is demonstrated through policies, training records, incident reports, and grievance registers.
  3. Communication and Grievance Procedures
    • Clause 7.4 requires communication systems; VPSHR reinforces this with grievance mechanisms for communities and staff.
  4. Monitoring and Continuous Improvement
    • Clause 10 of ISO 18788 emphasizes continual improvement; VPSHR similarly requires companies to monitor and improve how security interacts with stakeholders.

Audit and Assurance of Human Rights Respect

To demonstrate compliance, organizations must provide:

  • Policies and Procedures - Human rights policies, VPSHR-aligned SOPs.
  • Training Records - Evidence of human rights training for all security staff.
  • Incident Logs - Documentation of any use-of-force or rights-related incidents.
  • Grievance Registers - Community and employee complaints, with resolutions.
  • Independent Audits - External verification of VPSHR and ISO 18788 compliance.

Using the Audit Evidence Reliability Model (AERM), the most reliable evidence comes from:

  • Automated/Physical Evidence - Incident logs, CCTV recordings.
  • Confirmative Evidence - Third-party audit reports.
  • Analytical Evidence - Human rights performance dashboards.

Conclusion

Respect for human rights under A.8.1.3 of ISO 18788 is more than compliance—it is the foundation of ethical and sustainable security operations. The Voluntary Principles on Security and Human Rights (VPSHR) provide the practical framework to embed these principles across the organization.

By managing VPSHR strategically (policies, governance, stakeholder engagement), tactically (procedures, training, grievance mechanisms), and operationally (frontline conduct, incident reporting, community interaction), security companies ensure that their operations are credible, lawful, and trusted.

Human rights respect is not an abstract ideal—it is an operational necessity, a client expectation, and an audit requirement for ISO 18788 certification.