Selection, Background Screening, and Vetting of Subcontractors in Security Operations

Introduction

Subcontractors are often used in the security industry to extend coverage, provide specialized services, or reduce costs. However, subcontractors represent the same risks and liabilities as directly employed staff — sometimes even greater, since they may operate at arm's length from company oversight.

ISO 18788 requires that organizations apply equivalent standards of selection, screening, and vetting to subcontractors as they do to their own personnel, ensuring that subcontracted services align with the Security Operations Management System (SOMS), human rights obligations, and the Voluntary Principles on Security and Human Rights (VPSHR).

1. Selection of Subcontractors

Selection must be structured, transparent, and aligned with organizational objectives.

  • Qualification Criteria: Subcontractors must demonstrate compliance with ISO 18788 or equivalent governance frameworks.
  • Experience and Track Record: Verification of previous contracts, client references, and incident history.
  • Scope Alignment: Confirm the subcontractor can deliver services aligned with the organization's strategic, tactical, and operational objectives.
  • Code of Conduct Compliance: Subcontractors must agree in writing to abide by the company's policies on ethics, human rights, and use of force.

Outcome: Only subcontractors who share the organization's values and compliance obligations are engaged.

2. Background Screening of Subcontractors

Screening must extend to both the company entity and its key personnel.

  • Legal and Regulatory Compliance: Confirmation that the subcontractor holds valid licenses, permits, and certifications.
  • Ownership and Management Checks: Ensuring no affiliations with criminal organizations, human rights violators, or sanctioned individuals.
  • Criminal and Civil Litigation History: Review of past convictions, regulatory breaches, or unresolved disputes.
  • Financial Stability: Credit checks and audits to ensure subcontractor solvency and resilience.
  • Reputation Assessment: Client feedback, media monitoring, and due diligence reports.

Outcome: Screening reduces the risk of associating with disreputable or non-compliant subcontractors.

3. Vetting of Subcontractors

Vetting ensures that subcontractors are not only compliant at the point of onboarding but also aligned with the company's risk appetite and human rights commitments.

  • Operational Risk Profiling: Assess subcontractor deployment models, security risks, and alignment with the Use of Force Continuum.
  • Human Rights and VPSHR Alignment: Verify that subcontractors have policies and training on human rights, grievance handling, and community engagement.
  • Capacity Assessment: Evaluate whether subcontractors have adequate resources (trained personnel, equipment, communications) to deliver services reliably.
  • Continuous Vetting: Subcontractors must be monitored and re-evaluated during the contract lifecycle, particularly after incidents or complaints.

Outcome: Vetting ensures subcontractors are sustainable partners that enhance rather than undermine the SOMS.

Strategic, Tactical, and Operational Impact

  • Strategic Level: Contracts and procurement policies ensure subcontractors are evaluated against ISO 18788 and VPSHR criteria.
  • Tactical Level: Divisional managers oversee subcontractor performance, enforce compliance, and monitor risks.
  • Operational Level: Subcontractor personnel integrate with the company's SOPs, training, and reporting systems.

Documentation and Audit Evidence

To prove compliance, organizations must maintain:

  • Subcontractor Selection Records: Tendering processes, bid evaluations, and decision matrices.
  • Screening Reports: Background checks, financial audits, litigation reviews.
  • Vetting Records: Risk assessments, capacity analyses, human rights compliance checks.
  • Contractual Documents: Service-level agreements (SLAs), compliance clauses, and signed codes of conduct.
  • Performance and Review Logs: Evidence of ongoing audits, monitoring, and corrective actions.

Audit Reliability (AERM):

  • Most Reliable: Third-party due diligence reports, regulator certifications, audit findings.
  • Moderate: Signed self-declarations, client references.
  • Least Reliable: Verbal assurances without supporting documentation.

Conclusion

The selection, background screening, and vetting of subcontractors is a critical requirement under ISO 18788. Security companies cannot outsource accountability; they remain responsible for the actions of their subcontractors.

By applying rigorous, auditable processes to subcontractor selection and vetting, organizations ensure that all personnel operating under their banner—whether direct employees or third parties—adhere to the same standards of lawfulness, professionalism, and respect for human rights.