Library

Security risk management: a basic guide for smaller NGOs

Risk management

Written for organisations with no security function, no dedicated budget and no intention of acquiring either. The guide assumes that one person will do this alongside another job.

Download the guide (PDF, English)

The starting position

A small organisation faces a specific problem. It cannot match the security apparatus of a large agency, and it should not pretend to. What it can do is make sure that the decisions it takes about risk are deliberate, recorded and reviewed, and that staff know what is expected of them. That is most of security risk management, and it costs almost nothing.

The guide is honest that size is not a defence. A tribunal or a court will not apply a lower standard because an organisation is small. It will apply what was reasonable in the circumstances, and what is reasonable for a small organisation is a smaller set of measures than for a large one, not the absence of any.

The minimum an organisation needs

  1. Someone named. One person with responsibility for security, a stated amount of their time allocated to it, and a deputy. Not a committee.
  2. A written risk assessment per location. Two or three pages. What could happen, how likely, how bad, what is being done about it, who decided.
  3. A written security plan per location. The practical arrangements that follow from the assessment: movement, communications, accommodation, medical, and what to do first in an incident.
  4. A communications tree that has been tested. Who calls whom, in what order, and what happens if the first person does not answer. Tested means an actual test, not a document.
  5. Insurance that has been read. Including medical evacuation, and including national staff on terms that are not obviously worse than those for international staff.
  6. A briefing before every deployment and a debrief after. Short, specific, and recorded.
  7. A review date. The assessment is reviewed on a schedule and after any incident. The date is written on the document.

Where small organisations get it wrong

The same three failures recur. The risk assessment is written once, for a donor, and never revised. The security plan is copied from another organisation working in a different context. And the whole thing is held by one person who is also the country director, so there is no check on whether the plan is being followed and nobody to challenge a decision to proceed.

The guide's answer to the third is a peer arrangement: two or three organisations of similar size in the same location agreeing to review each other's assessments. It costs nothing, it produces an outside view, and it is the single measure most likely to catch a plan that has quietly stopped matching the context.

What to do first

If nothing else is in place, the guide recommends starting with the communications tree and the medical arrangements. They are the two things that matter in the first hour of an incident, they are cheap, and getting them right makes everything else easier to argue for.

Related

Practical guidance and research on the security of humanitarian staff, for the organisations that send them.