Use of Force Procedures in Security Operations
Introduction
A Use of Force Policy sets out the organization's principles and commitments, but without clear, documented procedures, those principles cannot be effectively applied on the ground. Use of Force Procedures transform policy into practical, step-by-step guidance for security personnel, ensuring consistent, lawful, and auditable application of force.
In ISO 18788:2015 (Clause 8.3), procedures are mandatory to ensure that the use of force is:
- Controlled (only by authorized personnel).
- Lawful (aligned with legal and contractual requirements).
- Proportionate and Necessary (applied as a last resort).
- Accountable (documented, reported, and auditable).
Objectives of Use of Force Procedures
- Operational Clarity - Provide frontline staff with clear instructions on how to act in situations requiring force.
- Consistency - Ensure uniform application of force across all sites and situations.
- Risk Control - Prevent abuse, escalation, and unlawful use of force.
- Audit Evidence - Provide reliable, documented records for internal and external audits.
- Integration - Link with risk management (Clause 6.1), human rights (A.8.1.3), training (Clause 7.2), and grievance mechanisms (Clause 7.4).
Key Components of Use of Force Procedures
1. Escalation of Force Framework
Security personnel must follow a graduated response model, often referred to as the continuum of force:
- Presence - Visible deterrence through professional conduct, uniforms, equipment.
- Verbal Commands - Clear, calm instructions or warnings.
- Physical Control (Hands-On) - Minimal force to control non-compliant individuals.
- Non-Lethal Tools - Use of batons, handcuffs, shields, or pepper spray (if legally permitted).
- Lethal Force - Only as a last resort, when there is an imminent threat to life.
2. Authorization and Control
- Only authorized personnel may carry and use weapons or equipment.
- Procedures must include:
- Issuance logs for firearms and non-lethal equipment.
- Daily inspections and secure storage of weapons.
- Clear rules for when equipment can be used.
3. Training and Competence
- All personnel must be trained in:
- De-escalation and conflict management.
- Rules of engagement (RoE).
- Human rights and proportionality.
- Correct handling of firearms and non-lethal tools.
- Refresher training and scenario-based drills must be conducted regularly, with attendance documented.
4. Incident Reporting and Documentation
- Any use of force must be:
- Immediately reported to supervisors.
- Documented in detail: time, location, personnel, actions, escalation path, outcome.
- Supported with evidence (CCTV footage, body camera, witness statements).
- Reports must be logged into the SOMS documentation system (Clause 7.5.3).
5. Investigation and Review
- All use-of-force incidents must undergo a formal investigation.
- Investigations must determine:
- Was force necessary?
- Was force proportional to the threat?
- Were RoE and SOPs followed?
- Findings must be documented, with corrective or disciplinary action applied if necessary.
6. Corrective Action and Continual Improvement
- Lessons learned from incidents feed back into:
- Training plans.
- SOP revisions.
- Risk registers (Clause 6.1).
- Awareness campaigns (Clause 7.4).
Strategic, Tactical, and Operational Linkages
- Strategic Level - The Board approves the Use of Force Policy and ensures the procedures align with international law, VPSHR, and ISO 18788.
- Tactical Level - Managers enforce the procedures, maintain equipment registers, and oversee training programs.
- Operational Level - Guards and supervisors apply procedures daily, follow escalation steps, and report incidents.
Documentation and Audit Evidence
Auditors will require:
- Documented Procedures - Clear SOPs for use of force, escalation, and reporting.
- Training Records - Evidence of staff competence in applying procedures.
- Incident Logs - Records of all use-of-force events, supported by evidence.
- Investigation Reports - Documentation of inquiries and corrective actions.
- Management Reviews - Evidence of continual improvement in procedures.
Evidence should be graded using the Audit Evidence Reliability Model (AERM):
- Most Reliable: Automated logs, CCTV/bodycam recordings, signed incident reports.
- Moderate: Supervisor notes, investigation reports.
- Least Reliable: Verbal accounts without supporting documentation.
Conclusion
Use of Force Procedures are the operational backbone of a security company's Use of Force Policy. They ensure that force is applied only when lawful, necessary, and proportionate, while maintaining full accountability through documentation, reporting, and audits.
By establishing clear escalation steps, authorization controls, training requirements, and reporting mechanisms, organizations strengthen compliance with ISO 18788, protect human rights, and build trust with clients, regulators, and communities.
Introduction
A Use of Force Policy is one of the most critical governance documents in a Security Operations Management System (SOMS). It establishes clear rules and expectations for when, how, and under what circumstances force may be applied by security personnel.
In line with ISO 18788:2015 (Clause 8.3), international human rights frameworks, and national laws, the policy must ensure that the use of force is lawful, necessary, proportionate, and accountable. It protects not only the organization and its personnel but also clients, communities, and the public.
Purpose of the Policy
- Define Boundaries - Provide security staff with clear instructions on acceptable conduct.
- Prevent Abuse - Safeguard against excessive or unlawful use of force.
- Ensure Compliance - Align operations with legal, contractual, and ISO 18788 requirements.
- Protect Human Rights - Uphold dignity, life, and the principles of the Voluntary Principles on Security and Human Rights (VPSHR).
- Support Accountability - Create an auditable trail of use-of-force incidents for review and continual improvement.
Core Principles of a Use of Force Policy
- Legality
- All use of force must comply with national laws, licensing conditions, and international standards (e.g., UN Basic Principles on the Use of Force and Firearms).
- Necessity
- Force may only be used as a last resort, when non-violent means have been attempted or would clearly be ineffective.
- Proportionality
- The level of force used must be proportionate to the threat faced, never excessive or punitive.
- Accountability
- Every use of force must be reported, investigated, and documented. Personnel must know that they are accountable for their actions.
- Respect for Human Rights
- The right to life, liberty, and dignity must be respected at all times. Force must never be used to intimidate, punish, or suppress lawful activities.
Policy Requirements
A Use of Force Policy under ISO 18788 should:
- Be Documented and Approved by executive leadership.
- Define Rules of Engagement (RoE): Escalation of force steps (presence → verbal warning → physical control → use of equipment → lethal force as last resort).
- Specify Authorized Equipment: Firearms, batons, restraints, or other tools, with clear guidance on lawful use.
- Mandate Training and Competence: Personnel must receive regular training on de-escalation, human rights, and proper weapon handling.
- Establish Reporting Mechanisms: All use-of-force incidents must be immediately reported and logged.
- Require Investigations: Independent inquiry into each incident, with corrective or disciplinary action where required.
- Link to Risk and Human Rights Policies: Ensuring consistency across the SOMS.
- Provide Whistleblower Protections: Personnel must feel safe to report misuse or unlawful orders.
Implementation Across the Organization
- Strategic Level - The Board endorses the policy, ensuring alignment with client commitments and human rights obligations.
- Tactical Level - Managers implement SOPs, monitor compliance, and audit incidents.
- Operational Level - Guards and supervisors apply the policy daily, guided by RoE and reinforced through training and awareness campaigns.
Documentation and Audit Evidence
To demonstrate compliance, organizations must provide auditors with:
- The approved Use of Force Policy.
- Training records proving staff awareness and competence.
- Incident logs and reports for each case of force applied.
- Investigation files documenting reviews and corrective actions.
- Management reviews showing continual improvement of the policy.
Conclusion
A Use of Force Policy is not just a compliance requirement under ISO 18788—it is the ethical backbone of a security organization. By codifying principles of legality, necessity, proportionality, accountability, and respect for human rights, the policy provides clarity to personnel, assurance to clients, and protection for communities.
When properly implemented, documented, and audited, it ensures that force is applied only when absolutely necessary, in the right way, and with full transparency.
Introduction
The use of force, firearms, and other weapons in security operations is one of the most sensitive and risk-laden aspects of a Security Operations Management System (SOMS). Mismanagement can result in loss of life, human rights violations, legal sanctions, and reputational damage.
ISO 18788 requires that security companies establish strict policies, procedures, and controls governing the authorization, handling, and accountability of firearms and other weapons. These measures must be rooted in the principles of legality, necessity, proportionality, and accountability.
Core Principles
1. Legality
- Firearms and weapons must only be used where permitted by law and under strict regulatory compliance.
- Licensing, registration, and control of firearms must follow national legislation and, where applicable, international conventions.
- Organizations must maintain a register of all weapons and ammunition, updated daily.
2. Necessity and Last Resort
- Weapons may only be used when absolutely necessary to protect life or prevent serious harm.
- Non-violent and non-lethal measures must always be attempted first (presence, verbal commands, de-escalation).
- The use of lethal force must be exceptional, justified, and subject to strict oversight.
3. Proportionality
- The level of force applied must be proportionate to the threat faced.
- Excessive or punitive use of weapons is strictly prohibited.
- Escalation models (presence → verbal → physical restraint → non-lethal tools → firearms as last resort) must guide decision-making.
4. Accountability and Oversight
- Every use of force involving weapons must be:
- Reported immediately.
- Investigated independently.
- Documented and archived in compliance with Clause 7.5.3 and the Archiving Act.
- Organizations must maintain audit trails of issuance, use, and return of firearms and ammunition.
Operational Considerations
1. Authorization and Issuance
- Only authorized, licensed, and trained personnel may be issued firearms or weapons.
- Issuance logs must record:
- Weapon serial number.
- Ammunition issued and returned.
- Person responsible and authorization authority.
- Secure armories must be maintained, with restricted access and daily reconciliations.
2. Training and Competence
- Personnel must undergo:
- Initial training on handling, safety, and lawful use.
- Regular refresher training, including scenario-based exercises.
- Human rights and rules of engagement training, aligned with VPSHR.
- Competence must be verified and documented in personnel files.
3. Use of Non-Lethal Weapons
- Organizations should prioritize non-lethal alternatives (batons, shields, tasers, pepper spray) where legally allowed.
- Non-lethal tools must also be regulated, with SOPs for use and reporting requirements.
4. Incident Reporting and Investigation
- Any incident involving firearms or weapons must be:
- Logged with precise details (who, what, when, where, how).
- Supported by evidence (bodycam, CCTV, witness statements).
- Reviewed at tactical and strategic levels for lessons learned.
5. Health and Safety
- Use of weapons must comply with occupational health and safety requirements.
- Medical support must be available when force is applied.
Strategic, Tactical, and Operational Integration
- Strategic Level - Board approves the Use of Force and Firearms Policy, aligning it with ISO 18788, VPSHR, and national law. Regular reporting to executives ensures transparency.
- Tactical Level - Divisional managers enforce compliance through audits, SOPs, training schedules, and risk assessments.
- Operational Level - Supervisors and frontline staff apply the escalation model, ensure reporting, and follow SOPs for safe handling of weapons.
Documentation and Audit Evidence
Auditors will seek proof of:
- Firearms and Weapons Policy - Documented, approved, and communicated.
- Training Records - Competence and refresher training certificates.
- Issuance and Return Logs - Daily reconciliations of weapons and ammunition.
- Incident Reports - Detailed documentation of weapon-related events.
- Investigations and Corrective Actions - Evidence of accountability and lessons learned.
- Armory Audits - Inventory checks, access logs, and audit reports.
Using the Audit Evidence Reliability Model (AERM), the strongest evidence will be:
- Physical/Automated: Issuance logs, surveillance footage, biometric access to armories.
- Confirmative: Independent audits, regulator inspections.
- Analytical: Trend reports on use-of-force incidents.
Conclusion
The general considerations for the use of force, firearms, and other weapons under ISO 18788 ensure that organizations uphold the highest standards of lawfulness, accountability, and human rights protection.
By embedding principles of legality, necessity, proportionality, and accountability into policies, procedures, and daily operations, security providers reduce risks, protect personnel and communities, and strengthen client trust.
In practice, this means strict authorization, rigorous training, controlled issuance, transparent reporting, and independent oversight—ensuring weapons are always used responsibly, rarely, and only as a last resort.