
The ISO standards procurement should expect from a contracted physical security provider are ISO 18788 (private security operations), ISO 28000 (security management across supply chains) and ISO 9001 (quality management). ISO 31000 sits alongside them as a risk framework, not a certification, so never write “ISO 31000 certified” into a tender. Ask every bidder for certificate copies, the scope statement, and evidence of a documented security or quality management system before you shortlist them.
TL;DR:
- Suppliers should provide valid certificates for ISO 18788, ISO 28000, and ISO 9001, including scope statements, accreditation bodies, and audit history to verify coverage.
- ISO 31000 is a guidance standard, not certifiable; providers must demonstrate their integrated risk management approach through documentation and internal procedures.
- Vague ISO references in tenders result in weak responses; precise clauses should specify exact standards, versions, scope, and require supporting management artifacts for evaluation.
- Certification audits occur annually, and verifying current audit status and scope ensures the provider’s management system is actively maintained and operational.
- Information security standards like ISO/IEC 27001 are relevant only if the provider manages digital systems; physical security standards focus on personnel, procedures, and site management.
Table of Contents
- What each ISO standard for security actually covers
- Certifiable standards versus guidance standards
- Writing precise ISO clauses into a tender or contract
- Verifying a bidder’s ISO claims, step by step
- How ISO 31000 risk principles feed into certified systems
- How ABCO Security operationalises ISO standards
- ISO/IEC 27001 and 27002: the information security standards you’ll hear about but don’t need here
- Physical security standards versus cybersecurity standards
- Benefits and limitations of ISO security standards
- How security providers actually get ISO certified
- Common challenges in implementing ISO security standards
- How ISO security standards relate to other frameworks
- Buyer perspective: why the right ISO mix cuts procurement risk
- Get ISO-aligned security backed by a documented system, not a sales pitch
- Where to verify these standards yourself
- Sources
- FAQ
What each ISO standard for security actually covers
Most tender documents throw ISO standard names around without explaining what a bidder actually does to earn one. That gap is where weak bids slip through. Here’s what each standard covers in practice, and why it matters when you’re buying guarding, patrols, or monitoring rather than building the system yourself.
ISO 18788 sets out a Security Operations Management System (SOMS) for private security providers. It requires a company to demonstrate legal accountability, respect for human rights, and consistent operational conduct across every guard shift and patrol run, not just on paper. For procurement, this is the standard that tells you whether a provider has formal use-of-force policies, vetting processes, and incident escalation procedures baked into how they manage private security contractors, rather than improvised on the night.
ISO 28000 governs security management across supply chains and logistics. It applies directly if your contract covers site access control on a construction project, asset movement, or any operation where materials, vehicles or contractors cross a perimeter. The standard uses a risk-based approach to secure the whole chain of custody, not just a single guard post.
ISO 9001 is the quality management backbone. It’s what makes a provider capable of standardising guard deployment, logging complaints properly, and running continual improvement cycles instead of firefighting the same issue every quarter. Providers use it to prove that service delivery is repeatable across sites and shifts, which matters enormously when you’re managing multiple locations under one contract.
ISO 31000 provides the language and principles for risk management: context, assessment, treatment, review. It’s not something a company gets audited against and certified for. It’s a framework a provider should be using internally to decide where to put guards, how often to patrol, and what triggers an escalation.
Together, these four standards cover legal conduct, supply chain integrity, service consistency and risk logic. A provider missing one of the first three certifiable standards isn’t necessarily unsafe to hire, but you’re accepting more operational risk without third-party evidence to back it up.
Certifiable standards versus guidance standards
The single most common tender mistake is asking for “ISO 31000 certification.” It doesn’t exist. Getting this distinction right before you draft the tender saves everyone a round of confused clarification requests.
- Certifiable standards can be independently audited and certified by an accredited body. ISO 18788, ISO 28000 and ISO 9001 all fall into this category. A provider either holds a valid certificate against these standards or they don’t, and that certificate is checkable.
- Guidance standards provide principles and methodology but have no certification scheme attached. ISO 31000 is the clearest example in security procurement. A provider can be assessed on how well they’ve integrated its principles, but never certified against it.
- What a certificate actually means: it names a scope (which services and sites it covers), an issuing accreditation body, and it carries an issue date, an expiry date, and a schedule of surveillance audits. A certificate with no scope statement is close to worthless as evidence.
- Correct tender phrasing: ask for “evidence of ISO 18788 certification with a scope statement covering static guarding and mobile patrols” and “evidence of integrated risk management aligned with ISO 31000 principles.” Never write “ISO 31000 certified,” because that phrase signals the tender author hasn’t checked the standard’s own scope.
Writing precise ISO clauses into a tender or contract
Vague ISO references in a tender produce vague answers. Bidders will happily tick a box next to “ISO certified” without specifying which standard, which sites, or which services it actually covers. Tighten the wording and you tighten the responses.
Build your ISO clause around these elements:
- State the exact standard and version, plus the scope you expect it to cover: for example, “ISO 18788:2015, scope to include static guarding, mobile patrols and alarm response for Site X.”
- Require a certificate copy, the name of the accreditation body that issued it, the certificate’s scope statement, issue and expiry dates, and the frequency of surveillance audits.
- Ask for supporting management artefacts: relevant SOMS sections, sample SOP excerpts, KPI reporting templates and an incident reporting template the provider actually uses in the field.
- Weight ISO evidence in your evaluation matrix rather than treating it as pass/fail. A provider with certified ISO 9001 and ISO 18788 but slightly higher pricing often represents lower operational risk than an uncertified low bidder.
Pro Tip: Build a simple two-column evaluation sheet: one column for “certificate sighted and scope confirmed,” one for “scope matches contracted services.” A certificate that exists but doesn’t cover the services you’re buying is functionally the same as no certificate at all.
Once the clause is written, the harder job starts: checking that what a bidder claims on paper matches what they can actually produce. Sample contract clause language built around ISO scope statements makes this evaluation far less painful during negotiation.
Verifying a bidder’s ISO claims, step by step
A certificate PDF attached to a tender response tells you almost nothing on its own. Verification is where procurement teams either catch a gap or get burned six months into the contract.
- Confirm the issuer is accredited. Check the certification body against a national accreditation register, and confirm the certificate’s scope statement explicitly covers the activities you’re contracting for. A certificate covering “consulting services” when you’re buying static guarding is a red flag, not a technicality.
- Request documentary evidence. Ask for excerpts from the management system manual, a summary of the most recent internal audit, and sample SOPs relevant to your contract type. High-maturity providers will hand these over without hesitation.
- Interview beyond the paperwork. Ask how often internal audits run, request a real example of a corrective action taken after an incident, and ask how risk assessments feed into on-site SOPs. Vague answers here usually mean the certificate is decorative.
- Build verification into the contract lifecycle. Schedule periodic surveillance-audit reviews, require notification if the scope of certification changes, and tie contract KPIs directly to the certified scope, not just to general service quality.
A risk assessment checklist built for your own facility gives you a document to compare against whatever the provider submits, which turns verification from a trust exercise into a paper match.
How ISO 31000 risk principles feed into certified systems
The strongest providers don’t treat ISO 31000 as a separate exercise from their certified systems. It’s the front end of the same process. Establish the context, run a Threat-Vulnerability-Consequence risk assessment, select controls, then document those controls inside the certified QMS or SOMS so they get audited alongside everything else.
In Australia, this is commonly done by aligning ISO 31000 with HB 167 guidance, producing a documented TVC model where treatments are justified and residual risk is recorded, not just assumed away. The artefact chain looks like this: risk register feeds SOPs, SOPs shape guard briefings, briefings drive the KPI dashboard reviewed each month. Providers who can show you that chain, from register to dashboard, tend to score noticeably better in competitive tenders because they’ve moved from reacting to incidents to anticipating them.
How ABCO Security operationalises ISO standards
ABCO Security holds certification to ISO 9001 and applies ISO 30000 principles across its guarding, monitoring and access control operations, alongside ISO 31000 risk methodology for site assessments. In practice, that means a documented management system covering guard deployment, licensed personnel records, and 24/7 monitoring protocols that get reviewed and improved on a set cycle rather than left static.
Procurement teams evaluating ABCO, or any bidder, should ask for the same package: a certificate copy with scope statement, excerpts from the ISO 9001 quality management documentation, and KPI templates tied to the certified scope. That request alone filters out providers who hold a certificate in name only.
ISO/IEC 27001 and 27002: the information security standards you’ll hear about but don’t need here
If you’ve searched around ISO standards for security, you’ve almost certainly bumped into ISO/IEC 27001 and ISO/IEC 27002. These are certifiable and guidance standards respectively, but they govern something entirely different from what a guarding or patrol contract needs: information security management, covering data handling, access controls on IT systems, and cyber risk treatment.
ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS), the digital-world equivalent of what ISO 18788 does for physical security operations. ISO/IEC 27002 provides the supporting control catalogue, listing specific safeguards an organisation might implement, such as encryption standards or access logging.
Where this matters for a procurement or facility manager buying physical security services: if your provider also manages your CCTV video storage, access control databases, or alarm monitoring platforms, there’s a legitimate case for asking whether their IT systems follow ISO/IEC 27001 principles. But that’s a separate question from whether their guarding operations meet ISO 18788, and the two shouldn’t be conflated in a single tender clause. Bundling “ISO certified” as a blanket requirement without specifying which standard governs which service is exactly the vagueness that produces unusable bid responses.
Keep the distinction clean in your documentation: physical security operations standards sit in one clause, any information security requirements for connected systems sit in another, each with its own scope statement.
Physical security standards versus cybersecurity standards
The confusion between these two families of ISO standards costs procurement teams real time, mostly because both use the word “security” and both talk about “risk management,” “audits,” and “certification.”
Physical security standards, ISO 18788, ISO 28000 and the operational side of ISO 9001, govern people, sites, patrols, and asset movement. The audit evidence is behavioural and procedural: guard licensing records, patrol logs, incident reports, use-of-force policies. An auditor checking ISO 18788 compliance is looking at how a company trains and deploys humans in physical space.
Cybersecurity and information security standards like ISO/IEC 27001 govern data, networks, and digital access. The audit evidence is technical and systemic: firewall configurations, access permission logs, encryption protocols, breach response plans. An auditor here is checking software and data flows, not guard rosters.
The practical takeaway for a tender: if your contract is purely guarding, patrols, and alarm response with no data-system management component, you don’t need an information security clause at all. If the provider also runs your monitoring software, video storage, or access control database, you may need both families of standard referenced, but as genuinely separate clauses with separate scope statements. Treating them as interchangeable in one paragraph is how tenders end up asking bidders for standards that have nothing to do with the service being purchased.
Benefits and limitations of ISO security standards
Certification gives buyers a documented, third-party-verified basis for trust instead of relying purely on a sales pitch. That verification reduces the burden on your own team to audit a provider’s internal processes from scratch, because an accredited body has already done a version of that work.
The benefits are concrete: standardised guard deployment under ISO 9001, documented human-rights and use-of-force accountability under ISO 18788, and a formal risk methodology that shapes patrol frequency and site coverage rather than guessing. Providers who layer these systems together tend to catch problems, complaint patterns, recurring incident types, before they escalate into serious failures.
The limitations are just as real. A certificate confirms a management system exists and gets audited on a cycle, usually annually for surveillance audits. It doesn’t guarantee flawless execution on every single shift, and it doesn’t replace your own contract KPIs and site inspections. Certification also costs money and staff time to maintain, which may be reflected in a provider’s pricing, something worth weighing against a cheaper, uncertified bidder. And because ISO 31000 has no certification scheme, you can never fully “prove” a provider’s risk methodology on paper alone. You’re always partly relying on interview answers and sample documentation to judge how well they’ve actually embedded it.
Used correctly, ISO evidence narrows your shortlist and structures your evaluation. It doesn’t remove the need for ongoing contract management.
How security providers actually get ISO certified
Certification isn’t a form a company fills out. It follows a defined sequence, and understanding it helps procurement teams judge whether a bidder’s certificate reflects genuine maturity or a rushed, box-ticking exercise.
A provider first builds the management system itself, documenting the SOMS or QMS processes, writing SOPs, and establishing internal audit routines. That system then runs for a period, typically several months, so there’s operational evidence to audit, not just policy documents sitting unused. An accredited third-party certification body then conducts a stage one audit, checking documentation completeness, followed by a stage two audit assessing whether the system operates as documented in practice, on real sites with real staff.
If the provider passes, the certification body issues a certificate with a defined scope, an issue date, and an expiry, usually three years, with surveillance audits at set intervals in between, commonly annually, to confirm the system is still functioning rather than gathering dust. Failing a surveillance audit can suspend or withdraw certification, which is exactly why checking a certificate’s current status, not just its existence, matters during tender evaluation.
The criteria auditors assess include documented risk assessments, evidence of staff training and licensing, incident and complaint records, corrective action tracking, and management review meetings. A provider that can produce all of these without scrambling has usually had the system running properly for a while, not bolted together for the audit.
Common challenges in implementing ISO security standards
The gap between holding a certificate and running the system well shows up in a handful of recurring places.
Maintaining consistency across multiple sites is the most common operational challenge. A provider might run a tight, well-documented process at head office while individual site supervisors deviate under pressure, particularly during staff shortages or high-turnover periods common in guarding work. Regular internal audits and site-level spot checks are the usual best practice fix, rather than assuming a certificate guarantees uniform delivery everywhere.
Keeping documentation current is another persistent issue. SOPs, risk registers and KPI dashboards need updating as sites, contracts and threats change, and providers that let documentation go stale between surveillance audits often fail the next one, or worse, keep operating with outdated procedures that no longer match the actual risk environment.
Cost and resourcing present a genuine tension, particularly for smaller providers. Maintaining certification requires ongoing internal audit staff time, documentation upkeep and surveillance audit fees, which can be substantial pressure on margin-thin contracts. This is partly why high-maturity providers often layer industry-specific codes of practice over ISO 9001, covering guard screening and system commissioning, rather than trying to build every operational nuance from scratch inside the ISO framework alone.
The best practice threading through all of this is simple to state and harder to execute: treat certification as a floor, not a ceiling, and keep internal audits genuinely independent rather than a formality before the external one arrives.
How ISO security standards relate to other frameworks
ISO standards for physical security don’t operate in isolation. In Australia, ISO 31000’s risk principles are commonly applied alongside HB 167, the handbook that adapts risk management specifically for security applications using Threat-Vulnerability-Consequence modelling. This pairing gives risk assessments a structured, defensible methodology rather than a generic checklist.
Beyond Australian guidance, security providers operating internationally or servicing multinational clients sometimes reference frameworks tied to specific sectors, aviation security codes, maritime security frameworks, or government facility protocols, which layer additional sector-specific requirements over the baseline ISO structure. ISO 18788 itself was developed with input from organisations working across defence and private military and security sectors, which is why its human-rights accountability language runs deeper than a typical quality standard.
For procurement teams, the practical point is this: ISO standards provide the common, checkable backbone, but a provider’s actual operational sophistication often shows up in how they’ve layered sector codes, national guidance like HB 167, and client-specific protocols on top of that backbone. A bidder who can only speak to the ISO certificate and nothing else built on top of it is usually less mature than one who can walk you through how these frameworks connect on their actual sites.
Buyer perspective: why the right ISO mix cuts procurement risk
Third-party certification does real work for you: it means you’re not the only line of defence checking whether a provider’s processes hold up. Layering ISO 31000’s risk thinking on top of a certified SOMS or QMS is what separates a provider who reacts to problems from one who’s already planning around them.
Keep three things front of mind: check the scope statement matches your services, never write “ISO 31000 certification” into a tender, and treat surveillance audit history as more telling than the certificate’s issue date.
— Abco
Get ISO-aligned security backed by a documented system, not a sales pitch
Abcosecurity holds ISO 9001 certification and applies ISO 30000 and ISO 31000 principles across guarding, patrols, monitoring and access control for construction sites, healthcare facilities, corporate offices and government buildings. That means every site gets a documented management system behind it, not an improvised roster.
Where a lot of providers can point to a certificate and little else, Abcosecurity can walk procurement teams through the actual artefacts sitting behind it: SOMS excerpts, KPI dashboards, and 24/7 monitoring protocols tied to the certified scope, not just marketing language. If you’re drafting a tender or evaluating current coverage, request a service quote and ask for the same evidence package this article recommends. It’s the fastest way to see whether a provider’s paperwork matches what happens on your site.
Where to verify these standards yourself
The ISO 28000:2022 requirements are published in full on the ISO standard page, covering scope and certification requirements directly from the source. For guidance on how ISO 31000 principles apply without a certification scheme, the ISO 31000 framework guide is a useful reference when drafting tender language. Procurement teams can pair either with ABCO’s own ISO 31000 risk guide for a practical, Australian-facing walkthrough.
Sources
- ISO — ISO 28000:2022 Security and resilience — Security management systems — Requirements
- PacificCert blog — ISO certification for security services providers
- Cambridge Risk Solutions — ISO spaghetti: practical guide to standards
FAQ
Is ISO 31000 certification a real thing?
No. ISO 31000 is a guidance standard with no certification scheme, so a tender should ask for evidence of integrated risk methodology rather than a certificate.
Which ISO standard applies to private security guarding contracts?
ISO 18788 covers private security operations directly, addressing legal accountability, human rights and consistent guard conduct across shifts.
Do I need ISO/IEC 27001 for a guarding contract?
Only if the provider also manages connected digital systems like video storage or access control databases; pure guarding and patrol services don’t require it.
How often are ISO security certificates audited after issue?
Certification bodies typically run surveillance audits annually, with full recertification roughly every three years, so always check current audit status rather than just the issue date.
What should I request from a bidder to verify their ISO claims?
Ask for the certificate copy, its scope statement, the accreditation body’s name, and supporting SOMS or QMS excerpts, which Abcosecurity and any credible provider should supply without hesitation.








