Security risk management for humanitarian organisations
Practical guidance, research and incident learning for agencies that send staff into high-risk environments, and for the people who carry that risk.
The European Interagency Security Forum is a network of humanitarian organisations that work together on the security of their staff and operations. This site is its public information resource. It collects guidance on how risk is assessed and managed, research on the conditions that create risk, and the lessons that agencies have drawn from incidents.
Nothing here is written for a specialist audience alone. A country director, a security focal point, a human resources officer and a programme manager all make decisions that determine how much risk a colleague carries, and each of them needs the same material in a usable form.
Where to start
-
Introduction
What is humanitarian security risk management?
The definition, the scope, and the vocabulary that the rest of the site uses.
-
Library
Guidance and research
The full collection: duty of care, risk assessment, training, incident management, insurance and access.
-
Theme
Managing sexual violence against aid workers
Prevention, response and reporting, brought together in one place.
-
Research
Diverse profiles
How gender, nationality, ethnicity, faith, age, disability and sexual orientation change the risk a colleague carries.
What security risk management covers
Security risk management is the process by which an organisation decides how much risk it is prepared to accept in order to deliver its work, and then acts on that decision. It has four moving parts, and they are only useful together.
- Context analysis. What is happening in the environment where the organisation works: who holds power, who is armed, who is negotiating, and how the answers to those questions are changing.
- Risk assessment. What could happen to staff, assets, programmes and reputation, how likely it is, and how severe the consequence would be.
- Risk treatment. What the organisation will do about each risk: avoid it, reduce it, transfer it, or accept it and say so.
- Monitoring and review. How the organisation finds out whether the treatment is working, and who is responsible for changing course when it is not.
The output of the process is not a document. It is a set of decisions that are written down, resourced, and revisited. An organisation that produces a security plan nobody reads has not managed anything.
Duty of care
Alongside the operational question sits a legal and ethical one. An employer that sends a member of staff into a high-risk environment owes that person a duty of care, and the duty does not end at the point of deployment. It covers preparation and training, medical and psychological support, insurance, communication with families, and what happens after a serious incident. Several items in the library deal with the practical shape of that obligation, including one that reviews an employment tribunal judgment holding an agency to it.
How this site is organised
The library holds the guidance and research collection, each item on its own page with a summary and a link to the document. News carries shorter pieces: commentary, summaries of new research, and notes on developments that affect how agencies work. Themes groups material that cuts across both, where a single subject generates enough guidance and commentary to justify collecting it. The resources library lists every document published on the site in one index.
Older material is still reachable. Records that were filed under an earlier version of this site remain available at their original addresses and are linked from the pages that replaced them.
Practical guidance and research on the security of humanitarian staff, for the organisations that send them.