CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting

ISO 18788 - Management Systems

​for Private Security Operations 

Picture
In plain English, it’s about proving your security operations are:
- planned and controlled
- legally compliant
- risk-based (not reactive)
- properly supervised
- continuously improved

It’s especially relevant if you provide guarding, mobile patrols, key holding, event security, or any security service where clients need confidence you’ll do the right thing under pressure.

What ISO 18788 actually covers
ISO 18788 is built around a management system approach — similar in structure to other ISO standards — but tailored to security operations.

It focuses on:
- operational planning and control
- legal and regulatory compliance
- risk assessment and mitigation
- competence, supervision and accountability
- incident management and learning
- monitoring, audits and continual improvement

The goal isn’t paperwork - The goal is consistent, controlled delivery — with evidence.

Who ISO 18788 is for
ISO 18788 is a strong fit for:
- private security companies
- organisations delivering security operations in higher-risk environments
- suppliers working with public sector, infrastructure, or larger corporates

If your tenders ask about governance, risk, incident response, supervision, or operational control — ISO 18788 gives you a clean, auditable answer.

Why clients ask for ISO 18788
1) Buyer confidence
It shows you’re not just “licensed” — you’re managed, controlled and accountable.

2) Reduced operational risk
Better planning, clearer roles, and tighter control reduces incidents
and complaints.

3) Stronger supervision and performance
It forces clarity on competence, monitoring, and corrective action.

4) Competitive advantage
In a crowded security market, ISO 18788 is a differentiator.

What you need to pass ISO 18788
You don’t need a mountain of documents — you need a working system and proof.

Typically you’ll need:
- defined scope for security operations management
- legal and compliance obligations identified and controlled
- risk assessment and controls (threats, vulnerabilities, mitigation)
- operational procedures and briefings
- incident response process and records
- competence and supervision controls (who can do what, and how it’s checked)
- monitoring and measurement (KPIs)
- internal audits, management review, corrective actions

What makes ISO 18788 audits fail
Common issues we see:
- procedures that don’t match real operations
- weak evidence of supervision and monitoring
- risk assessments that are generic and not site/service specific
- corrective actions not tracked to completion

The fix is simple: keep it operational, keep it evidence-led, and make
sure what you say you do is what you actually do.

How long does ISO 18788 take?
At CAW:
- systems can be built within 48 hours
- typically delivered in 72 hours

Audit scheduling depends on the certification body, but the system
build and prep doesn’t need to drag on.

Why CAW
- 100% pass rate across all standards and certification bodies (including UKAS)
- fastest turnaround in the country
- at least 50% cheaper than other UK consultancies
- ISO consultancy package price: £999

If you want ISO 18788 done properly — practical, paperless, and
audit-ready — message us.
We’ll tell you exactly what you need (and what you don’t), then get
you ready fast.



Picture

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting