Security audits
A security audit is worth commissioning only if someone has already decided what they will do with a bad result. Otherwise it produces a document, a period of discomfort, and no change.
What an audit is for
An audit tests whether the arrangements the organisation believes it has actually exist and work. It is not a risk assessment, which looks outward at the environment, and it is not an inspection, which looks for individual fault. It compares practice against the organisation's own stated standard, and it reports the difference.
The distinction matters because the three are routinely confused, and an organisation that wants an audit but commissions an inspection gets a list of names.
Scoping it so that it produces decisions
- Decide the standard being audited against. The organisation's own policy, a sector standard, or a donor requirement. Without a stated standard, the auditor will use their own judgement and the findings will be arguable.
- Decide the unit. A country programme, a single site, a specific function such as journey management or communications, or the whole organisation. An audit of everything produces findings nobody can act on.
- Decide who sees the report and what happens next. Before the audit starts. An audit whose findings have no route to a decision maker with budget has failed at the commissioning stage.
- Decide how the findings will be handled at the field level. Auditors interview staff. If those staff believe that what they say will reach their manager attributed to them, the audit will collect the official version and nothing else.
- Decide whether it is announced. An announced audit tests the documented system. An unannounced one tests the real one. Both are legitimate; they answer different questions, and the choice should be deliberate.
What auditors find
The findings are consistent enough to predict. Movement procedures exist on paper and are not followed, usually because the person expected to enforce them has no authority to refuse a journey. Communications equipment is present and untested, or tested but not used on the schedule the policy states. Training records exist but the training was delivered before the context changed. Incident reports are filed and never analysed. Residential security arrangements were set at the start of the programme and not reviewed since. National staff are excluded from briefings that their exposure requires them to attend.
None of those are unusual and none require a specialist to identify. What requires a decision is what happens after they are identified.
After the audit
A findings list without owners and dates is a wish. The output that matters is a set of actions, each with a named owner, a date, and a statement of what the organisation will do if the action is not completed. Actions that require money go into the budget cycle rather than into a separate list that never gets funded. And the audit is repeated, because the value of the first one is the baseline it establishes.
Related
Practical guidance and research on the security of humanitarian staff, for the organisations that send them.