Evidential Documentation of all Training
Introduction
ISO 18788:2015 requires organizations to maintain evidential documentation that demonstrates competence, training, and compliance with strategic, tactical, and operational objectives. Clause 7.2.4 highlights the importance of keeping auditable records, not only to prove that processes are in place but also to provide reliable evidence of their effectiveness.
The quality of evidence matters as much as its availability. The Audit Evidence Reliability Model (AERM) ranks different types of evidence by reliability. Combined with legal frameworks such as the Archiving Act (and country-specific records management laws), organizations must ensure evidence is collected, classified, stored, and retrievable in a secure and systematic manner.
Types of Evidential Documentation (Based on AERM)
1. Verbal Evidence / Inquiry (Least Reliable)
- Definition: Oral statements during interviews with employees, managers, or contractors.
- Examples: Interview notes with security officers about their training or SOP adherence.
- Documentation: Record interview summaries, sign-off by the interviewer and interviewee.
- Archiving: Keep securely with metadata (date, person, purpose); not sufficient alone as proof.
2. Observation (Very Low Reliability)
- Definition: Auditor's direct observation without measurement or written record.
- Examples: Witnessing a guard conduct an access control check.
- Documentation: Visual inspection notes or photographs with timestamp.
- Archiving: Record in audit reports; attach as supporting evidence.
3. Documentary Evidence (Low Reliability)
- Definition: Internal records reflecting procedures, policies, logs, or approvals.
- Examples: Training registers, SOPs, incident reports, attendance sheets, version-controlled manuals.
- Documentation: Version-controlled, signed/approved by authorized personnel.
- Archiving: File under the company's document retention schedule in compliance with the Archiving Act.
4. Technical Evidence (Moderate Reliability)
- Definition: Auditor's notes based on review of methods, processes, or calibration.
- Examples: Tool calibration checks, vehicle inspection records, guard equipment verification.
- Documentation: Signed-off inspection reports, photographs with references, calibration certificates.
- Archiving: Keep with technical logs; ensure traceability to original equipment.
5. Analytical Evidence (Reliable)
- Definition: Data interpretation by the auditor or organization.
- Examples: Incident trend graphs, guard deployment KPIs, training pass/fail statistics.
- Documentation: Charts, reports, data extracts with methodology explained.
- Archiving: Store in both raw data (source logs) and final reports for audit trail.
6. Confirmative Evidence (Highly Reliable)
- Definition: Independent confirmation by external bodies.
- Examples: Third-party accreditation reports, external audit certificates, supplier verification.
- Documentation: Certificates, signed reports, external inspection findings.
- Archiving: Preserve in secure, tamper-proof storage with expiry/revalidation dates.
7. Physical / Mathematical Evidence & Automated Testing (Most Reliable)
- Definition: Direct, objective, measurable evidence or automated logs.
- Examples: Biometric access logs, time-stamped patrol verification scans, CCTV footage with metadata, AI-driven log analysis.
- Documentation: Original logs, validated reports, digital records.
- Archiving: Store securely (per Archiving Act), ensure encryption, retention, and retrieval protocols.
Evidential Documentation in the Archiving Context
According to the Archiving Act and best practice:
- Retention: Records must be kept for the legally defined minimum period (often 5-7 years, longer for HR, compliance, or legal matters).
- Classification: Each document type must be classified (policy, procedure, training record, log, report, certificate).
- Version Control: Maintain change history with authorized sign-offs.
- Access Control: Limit access to authorized personnel to ensure confidentiality and integrity.
- Retrievability: Documents must be easily retrievable for audits, certifications, and investigations.
- Disposal: At the end of the retention period, secure and documented destruction must occur, unless required for litigation or historical record.
Integration with Competence & Training Records
For Clause 7.2.4 specifically (Competence):
- Keep: Job descriptions, skills assessments, training records, certificates, evaluation reports, refresher schedules.
- Link to PMS: Evidence of quarterly competence reviews, performance appraisals, corrective actions.
- Audit Trail: Ensure every competence gap and training response is backed by evidential documentation.
Conclusion
Clause 7.2.4 of ISO 18788 requires organizations to maintain a structured evidential documentation system that aligns with the AERM reliability scale and complies with archiving requirements. Verbal statements and observations may supplement, but only documentary, confirmative, and physical/mathematical evidence carry the weight needed for high assurance.
By combining ISO 18788, the AERM model, and the Archiving Act, security organizations ensure their SOMS is audit-ready, transparent, and credible—able to demonstrate competence, compliance, and continual improvement with verifiable proof.