Private Security Operations Management System Consultants in Dubai, Abu Dhabi & Saudi Arabia
Nathan ISO Consulting implements and certifies ISO 18788:2015 Management Systems for Private Security Operations for guarding companies, close protection providers, cash-in-transit operators and critical infrastructure security firms across the UAE, Saudi Arabia and the wider GCC.
A private security company operates in a category few other businesses share: the work itself carries potential for serious harm if governance fails, and the clients hiring these firms — governments, critical infrastructure operators, major developers — increasingly know it. Where ISO 9001 assumes the worst outcome of a failed process is a dissatisfied customer, ISO 18788 is built around the reality that the worst outcome in this sector can be a person seriously hurt, and it governs accordingly.
What Is ISO 18788:2015?
ISO 18788:2015 is the international standard for Management Systems for Private Security Operations. It was developed in response to a governance gap exposed by private security and military contracting in high-risk environments over the past two decades. It shares its underlying philosophy with ANSI/ASIS PSC.1 and reflects principles set out in the Montreux Document on private military and security company obligations under international law.
The result is a standard treating human rights due diligence, use-of-force governance and accountability as core management system requirements rather than optional ethical additions. It scales across the security risk spectrum — from static guarding at a shopping mall through to close protection, cash-in-transit and critical infrastructure protection — but its governance requirements bite hardest, and add most value, at the higher-risk end.
| Requirement | What it means in practice |
|---|---|
| Use-of-force policy and escalation | A documented, trained, auditable framework for how and when force may be used, proportionate to threat, with accountability for every escalation |
| Human rights due diligence | A formal process identifying and mitigating human rights risks connected to your own security operations — not a policy statement |
| Incident reporting and accountability | Every use-of-force incident, weapons discharge or serious complaint tracked, investigated and reported through a defined chain, with no informal internal pathway avoiding scrutiny |
| Personnel vetting and competence | Background screening, licensing verification and ongoing competence assessment proportionate to role risk |
| Weapons and equipment management | Where weapons are authorised, full lifecycle control — issuance, storage, maintenance, accountability and disposal |
| Subcontractor oversight | The same governance standard extending down the supply chain, not stopping at the prime contractor |
| Emergency and crisis management | Defined response to security incidents, medical emergencies and escalating situations on client sites |
The most common reaction when we introduce this requirement is that it duplicates existing HR policy or anti-discrimination commitments. It does not. Human rights due diligence under ISO 18788 asks a narrower question: what risks does this organisation’s own security operation pose to the human rights of the people it interacts with — the public, detainees where applicable, workers on a client site, attendees at an event — and what is being done to identify and reduce those risks before an incident occurs.
Done properly this is a practical exercise: reviewing use-of-force training against international norms, checking that detention or restraint procedures where they exist are proportionate and documented, and confirming personnel understand escalation limits before being placed in roles where the limits matter. Done badly it becomes a paragraph copied from a generic corporate social responsibility statement, which auditors familiar with this standard recognise immediately.
Why ISO 18788 Certification Matters in the UAE and GCC
Dubai’s Security Industry Regulatory Agency, SIRA, licenses and regulates private security companies, guards, training institutes and security systems providers, with defined licensing categories, mandatory training standards and ongoing compliance obligations. Abu Dhabi applies its own regime through relevant policing and security authorities, and other emirates maintain comparable frameworks through their police directorates. Saudi Arabia’s sector operates under Ministry of Interior licensing. Qatar, Kuwait, Oman and Bahrain each license security activity through their interior ministries or equivalent authorities.
A licence confirms a company and its guards are legally permitted to operate. It says comparatively little about how well that operation is governed once the licence is granted, which is precisely the gap ISO 18788 fills.
Large developers, free zone authorities, airports, energy facilities and government entities carry their own exposure from the conduct of the security contractors they hire. A guard’s excessive use of force, however isolated, becomes the client’s problem the moment it happens on their property in their required uniform. Procurement teams at this level now ask a more specific question than whether you are licensed — they ask whether you can demonstrate structured governance over the risks that turn an isolated incident into a lawsuit or a headline.
Contracts protecting critical infrastructure, major real estate developments, high-profile events and government facilities increasingly specify ISO 18788 or an equivalent internationally recognised system as a qualification requirement.
Following a serious incident, the question asked by the authority, insurer and client is whether the organisation took reasonable steps to prevent it. A certified, independently audited system carries materially more weight than an internal policy no external party has reviewed.
Structured vetting, competence frameworks and supervision requirements raise operational standards in a sector where turnover is high and competence is frequently assumed rather than verified.
Nathan ISO Consulting’s ISO 18788 Services
We begin with time on the ground — reviewing actual guard deployments, existing incident records, current use-of-force training content, and how supervisors handle escalation in practice — before a single policy document is drafted.
A documented escalation framework proportionate to your actual service lines, with defined limits, decision authority, reporting obligations and training requirements that supervisors managing guards in real time can genuinely apply.
A practical assessment of risks your operations pose to the rights of those you interact with, with mitigation built into training, procedures and supervision rather than stated as a policy commitment.
Screening, licensing verification and competence assessment differentiated by role risk rather than running every guard through the same baseline course.
| Role risk grade | What increases beyond baseline licensing |
|---|---|
| Low — static, unarmed, low-footfall site | Standard licensing, use-of-force awareness, incident reporting training |
| Medium — crowd management, high-footfall, cash handling | De-escalation training, conflict management assessment, more frequent refresher cycles |
| High — armed response, close protection, critical infrastructure | Enhanced background and psychological screening, scenario-based use-of-force assessment, increased supervisory oversight ratios |
Where firearms or other weapons are authorised, full accountability from issuance through storage security, maintenance, end-of-shift checks and disposal.
A defined reporting chain with no informal pathway avoiding scrutiny, plus investigation procedures reaching genuine root cause rather than stopping at the individual guard.
Vetting, training and incident visibility extending to subcontracted guarding force operating under your contracts — because your client’s exposure does not distinguish between your staff and your subcontractor’s.
Where client sites impose their own use-of-force or access rules, we reconcile them formally with your company policy rather than leaving contradictions for a supervisor to resolve under pressure.
Guard and supervisor training delivered in the languages your workforce speaks, plus internal auditor qualification for your nominated staff.
Full PSOMS internal audit, properly minuted management review, certification body selection, Stage 1 and Stage 2 attendance including site visits, and nonconformity closure.
Our ISO 18788 Certification Process
Confidential consultation and fixed proposal. Discussion of your service lines, licensing position, client base and risk exposure, followed by a fixed written quotation.
Operational risk review. Site visits, deployment review, incident record analysis and training content assessment.
Scope definition. Which service lines, sites and jurisdictions the certificate covers.
Risk assessment across service lines. From static guarding through to any higher-risk operational work.
Use-of-force and human rights framework. Governance built to match your actual operating environment and client base.
Vetting and competence framework. Differentiated screening and assessment by role risk grade.
Documentation development. Procedures, incident reporting, weapons control, emergency response and subcontractor governance.
Training rollout. Guard and supervisor training in relevant languages, plus internal auditor qualification.
Internal audit. Full audit across sites and service lines with genuine findings and verified corrective action.
Management review. Structured review covering every required input, properly minuted.
Stage 1 and Stage 2 audits. Documentation review then implementation audit including site verification and guard interviews.
Certification and surveillance support. Nonconformity closure, certificate issue and ongoing support across the three-year cycle.
Why Choose Nathan ISO Consulting
No generic templates for this standard. We turn away more template requests here than for any other standard. Use-of-force and human rights documentation that does not reflect your operating reality can genuinely fail to prevent the harm the standard exists to prevent.
Time on the ground first. Guard deployments, incident records and actual supervisor behaviour reviewed before any policy is drafted.
Risk-graded competence design. Differentiated vetting and training rather than one baseline course for every role, which is what actually raises operational standards.
SIRA and regional licensing alignment. We align PSOMS documentation with your existing licensing records rather than duplicating them.
Operations leadership engaged directly. Use-of-force governance must be understood by supervisors managing guards in real time, not just documented at head office.
Immediate risks prioritised over timeline. Where gaps represent genuine operational risk rather than documentation gaps, we say so and fix them ahead of the certification schedule.
Multi-language training delivery. Guard-level training in the languages your workforce actually speaks.
Confidential engagement. Initial discussions treated in confidence, with a candid assessment of your position before any programme is proposed.
Fixed written pricing. Agreed upfront with audit attendance included.
Certification body selection advice. We recommend bodies genuinely equipped to assess private security operations rather than treating it as a generic management system audit.
Security Services We Support
Manned guarding and static security. Commercial, residential, retail and industrial site protection.
Close protection and executive security. Personal protection details with elevated use-of-force and incident risk.
Cash-in-transit and valuables logistics. Armed and unarmed CIT operations with weapons control and route security requirements.
Critical infrastructure protection. Energy facilities, ports, airports, utilities and telecommunications sites.
Event and crowd security. High-footfall events with crowd management and de-escalation demands.
Retail and mall security. Public interaction, loss prevention and detention procedure exposure.
Maritime and port security. Vessel, terminal and offshore facility protection.
Electronic security and monitoring. Control room operations, CCTV monitoring and alarm response coordination.
Security consultancy and risk assessment. Threat assessment and security design services.
Locations We Serve
ISO 18788 consultants across Dubai — Business Bay, Downtown, Deira, Al Quoz, Jebel Ali, Dubai Investment Park and Dubai South — plus JAFZA, DMCC, DAFZA, DIFC and Dubai Silicon Oasis, working with SIRA-licensed security companies and providers operating under Trakhees and the Dubai Development Authority.
Abu Dhabi city, Al Reem Island, Yas Island, Mussafah, ICAD, KEZAD, Khalifa Port, Ruwais, Masdar City and Al Ain — including providers serving ADNOC facilities and government and semi-government contracts.
Sharjah city and industrial areas, Hamriyah Free Zone and SAIF Zone; Ajman and Ajman Free Zone; Ras Al Khaimah, RAKEZ and RAK Maritime City; Umm Al Quwain; Fujairah, Fujairah Free Zone and Fujairah Port.
Riyadh, Jeddah, Dammam, Al Khobar, Dhahran, Jubail, Yanbu, Mecca, Medina and Tabuk — including providers serving Aramco and SABIC facilities, Royal Commission industrial cities, and NEOM, Qiddiya and Red Sea developments.
Qatar — Doha, Lusail, Ras Laffan and Mesaieed. Kuwait — Kuwait City, Shuwaikh, Ahmadi and Mina Abdullah. Oman — Muscat, Sohar, Salalah and Duqm. Bahrain — Manama, Sitra, Hidd and Bahrain International Investment Park.
What Determines the Cost of ISO 18788 Certification?
Certification body audit fees follow mandatory audit-day tables based on guard headcount, number of client sites within scope and assessed risk category. Armed service lines and higher-risk operations sit in higher bands than unarmed static guarding.
Our consultancy fee is separate and fixed in writing before engagement, driven by the range of service lines in scope, guard headcount and training languages required, whether weapons are authorised, the extent of subcontracted guarding, and the state of existing incident records. Where historic incidents have been handled informally without written investigation, rebuilding that evidence base takes time the documentation work itself does not.
Get Started with ISO 18788 Certification
For ISO 18788 certification in Dubai, Abu Dhabi, Sharjah, Saudi Arabia, Qatar, Kuwait, Oman or Bahrain, call +971 50 258 5024, email info@nathanisoconsulting.com, or visit our contact page. Conversations at this stage are treated in confidence, and we will tell you plainly during the initial review whether your current governance already covers most of what the standard requires or whether there is genuine work to do.
Frequently Asked Questions About ISO 18788 Certification
No. Licensing through SIRA in Dubai or the equivalent authority in other emirates is the legal requirement to operate. ISO 18788 is a voluntary international management system standard sitting above that licensing floor, increasingly requested by government and critical infrastructure clients as a tender qualification.
ISO 9001 addresses general quality management — consistent service delivery, customer satisfaction, process control. ISO 18788 addresses risks specific to security operations: use-of-force governance, human rights due diligence, weapons management and incident accountability. Many security companies hold both, with ISO 18788 covering what ISO 9001 was never designed to address.
Yes, scaled to relevance. An unarmed static guarding company carries a lighter weapons management burden than an armed close protection provider, but use-of-force escalation, incident reporting, vetting and human rights due diligence remain relevant wherever personnel interact with the public or protect assets.
The Montreux Document sets out states’ obligations and good practice recommendations regarding private military and security companies under international law. ISO 18788 was built with these principles in mind. A UAE or Saudi firm operating domestically is not directly bound by it, but the governance standard it represents is what the management system operationalises.
Twelve to sixteen weeks for a single-licence operator with an established, lower-risk client base. Organisations with higher-risk service lines, multiple licensing jurisdictions or extensive subcontracted guarding should plan on five to six months.
Yes, and these are among the clearest fits for the standard given elevated use-of-force and incident risk. The weapons management and escalation governance requirements map directly onto the operational realities of both service types.
Availability varies, since this is less commonly requested than ISO 9001 or ISO 45001. We confirm current accreditation scope with an appropriate body during scoping and will recommend a certification body genuinely equipped to assess private security operations rather than treating it as a generic audit.
Supply chain oversight extends to subcontracted personnel operating under your contract, not just directly employed staff. If a client engages you and you subcontract part of the guarding force, your system needs visibility into that subcontractor’s vetting, training and incident history, because the client’s exposure does not distinguish between the two.
There is a genuine overhead, concentrated in incident tracking and competence review. Most established security companies find it smaller than expected, because much of the underlying data — licensing records, shift rosters, incident reports — already exists. What changes is that it becomes structured, reviewed and connected to management decisions rather than filed and forgotten.
Certification assesses whether you have a functioning management system, not whether your history is spotless. An organisation with honest incident records, genuine investigation and evidence of corrective action is in a stronger position than one presenting an implausibly clean record. Where an incident raises legal exposure, we advise obtaining independent legal counsel — that is a legal matter, not a management system one.
No. SIRA sets mandatory licensing and training standards that continue to apply. ISO 18788 builds above that baseline with role-differentiated competence, ongoing assessment and governance structure. We align the two so one system satisfies both rather than running parallel documentation.
They need formal reconciliation with your company policy. A client site imposing rules that subtly conflict with your documented framework, with the contradiction unresolved, leaves a supervisor to make the call under pressure — which is exactly the situation the standard is designed to prevent. We formalise this as part of implementation.
It requires vetting and competence proportionate to role risk. For high-risk roles — armed response, close protection — enhanced screening including psychological assessment is generally appropriate and is what auditors expect to see for those grades. For low-risk static guarding, standard background and licensing verification is proportionate.
Yes, scope can be defined by service line, site or jurisdiction. Bear in mind that a certificate covering only your lowest-risk guarding while armed operations sit outside scope offers limited assurance to a client conducting genuine due diligence, and sophisticated procurement teams read scope statements closely.
ISO 45001 addresses occupational health and safety of your own personnel. ISO 18788 addresses the risks your security operations pose to others, alongside governance of force, weapons and accountability. They complement each other well and share the Annex SL structure, so integration is efficient — guards face genuine occupational risk as well as posing risk to others.
Full lifecycle accountability where weapons are authorised — acquisition and licensing, secure storage with access control, issuance and return logging per shift, maintenance and inspection records, ammunition accountability, incident reporting for any discharge, and controlled disposal. Incomplete end-of-shift accountability is one of the most common findings.
They can, where they form part of the security operation being certified. Control room procedures, alarm response coordination, CCTV monitoring protocols and data handling all sit within a PSOMS scope covering electronic security services, and increasingly overlap with information security requirements around footage retention and access.
Through a documented assessment of interaction risks specific to your operations, evidence that training content addresses those risks, records showing escalation limits are understood by deployed personnel, procedures for detention or restraint where applicable, and a complaints route accessible to people outside the organisation. Auditors test whether this is lived practice or a policy paragraph.
We design the competence framework and deliver awareness, supervisor and internal auditor training. Practical use-of-force and defensive tactics instruction is typically delivered by accredited specialist trainers, and we specify what that training must cover and verify that it does.
By keeping incident reporting genuinely active, running the competence re-assessment cycle, maintaining weapons and vetting records currently, re-verifying subcontractors, reviewing the human rights assessment when service lines or client sites change, and holding management review on schedule. Incident registers that go quiet are treated by auditors as a reporting culture problem rather than evidence of a safe operation.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving