The Use of Force in Security Operations
Introduction
The use of force is one of the most sensitive and high-risk aspects of security operations. Mismanagement can result in human rights violations, legal sanctions, reputational damage, and loss of client trust. Clause 8.3 of ISO 18788 requires organizations to establish strict governance, operational controls, and accountability mechanisms for when and how force may be applied.
This clause aligns with international frameworks such as the UN Basic Principles on the Use of Force and Firearms, the Voluntary Principles on Security and Human Rights (VPSHR), and national legislation governing armed and unarmed security.
8.3.1 General Requirements
Clause 8.3.1 requires that organizations:
- Define and Document Use of Force Policy
- Policy must align with:
- International human rights standards.
- Local laws and regulations.
- Client requirements and contractual obligations.
- Clearly articulate the principle that force is always a last resort.
- Proportionality and Necessity
- Force must be reasonable, necessary, and proportionate to the threat faced.
- Non-violent means must be exhausted first (verbal warnings, de-escalation).
- Clarity and Communication
- Staff must be aware of rules of engagement (RoE) and trained to apply them.
- Codes of conduct and SOPs must explicitly cover force escalation levels.
- Integration with Risk and Human Rights
- Use of force must be linked to risk assessments (Clause 6.1) and human rights obligations (A.8.1.3).
8.3.2 Management of the Use of Force
Clause 8.3.2 addresses how organizations must control and monitor the application of force:
1. Procedures and SOPs
- Develop step-by-step escalation protocols:
- Presence → Verbal Warning → Physical Restraint → Use of Equipment/Non-lethal tools → Lethal force (only when unavoidable and lawful).
- SOPs must be documented, version-controlled, and accessible to staff.
2. Training and Competence
- Personnel must be trained in:
- De-escalation and conflict resolution.
- Rules of engagement and proportionality.
- Correct handling of firearms, batons, restraints, and other tools.
- Human rights and VPSHR standards.
- Competence evaluations (Clause 7.2) must include scenario-based training.
3. Authorization and Control
- Use of force must only be carried out by authorized, trained, and certified personnel.
- All equipment (firearms, non-lethal weapons) must be controlled, logged, and maintained.
- Regular audits of armories, issuance records, and authorization lists must be kept.
4. Incident Reporting and Investigation
- Every use-of-force incident must be:
- Immediately reported through operational communication systems.
- Documented in detail (time, location, personnel, escalation path, outcome).
- Investigated by an independent authority within the organization.
- Evidence must comply with the Audit Evidence Reliability Model (AERM).
5. Corrective Action and Accountability
- Violations must trigger disciplinary measures, retraining, or termination.
- Corrective actions documented and tracked through management review.
- Feedback integrated into risk registers and competence training plans.
Integration with Strategic, Tactical, and Operational Levels
- Strategic Level
- The Board and Executive leadership endorse and enforce a zero-tolerance policy for abuse of force.
- Policy aligned with international standards (VPSHR, UN Principles).
- Transparent communication with clients and stakeholders.
- Tactical Level
- Managers ensure SOPs, rules of engagement, and training plans are implemented.
- Periodic audits of armories, access logs, and authorization lists.
- Incident trend analysis and corrective action reviews.
- Operational Level
- Frontline staff apply de-escalation first and follow SOP escalation steps.
- Immediate reporting of any force incident through communication channels.
- Supervisors verify adherence and provide real-time oversight.
Documentation and Audit Evidence
Auditors will expect to see:
- Use of Force Policy - Signed by top management, aligned to law and human rights.
- Rules of Engagement (RoE) - Clear, operationally relevant, regularly communicated.
- Training Records - Evidence of staff competence in de-escalation, RoE, lawful weapon handling.
- Incident Logs - Documented records of all use-of-force cases, including outcomes.
- Investigations - Reports of internal or external inquiries into incidents.
- Corrective Actions - Evidence of disciplinary measures or systemic improvements.
Conclusion
The use of force is a necessary but high-risk aspect of security operations. Under Clause 8.3 of ISO 18788:
- 8.3.1 requires a clear, documented policy on lawful, proportionate, and necessary use of force.
- 8.3.2 requires a management system to ensure force is controlled, authorized, reported, and audited.
When linked to risk assessments, human rights obligations, training, and operational controls, organizations can ensure that the use of force is always applied responsibly, transparently, and auditable.
This strengthens compliance with ISO 18788, enhances client trust, and protects both personnel and communities.