Humanitarian access in a changing world: why security risk management matters
Access negotiations and security risk management are usually run by different people, reported to different managers and recorded in different documents. They are the same conversation.
Access is the ability to reach people who need assistance. It is granted or withheld by whoever controls the ground: a state, an armed group, a local authority, a community, or a combination that changes from one district to the next. Security risk management is the process by which an organisation decides what risk it will accept in order to work somewhere.
The two are treated separately because they sit in different departments. Access negotiations belong to programmes, humanitarian affairs or a dedicated access function. Security belongs to a security manager or an operations director. The separation produces three predictable failures.
An agreement that cannot be delivered. Access is negotiated on the basis that a team will travel a route and deliver a programme. The security assessment that determines whether the route is usable is produced afterwards, by someone who was not in the negotiation. When the assessment says the route is not manageable, the organisation has made a commitment it cannot keep, and its standing with the party it negotiated with has just fallen.
A risk assessment that ignores the deal. The reverse failure is equally common. A security assessment treats an area as inaccessible when the organisation has, in fact, reached an understanding with the group that controls it. The assessment is written from open sources and national reporting, and it does not know what the access team knows.
No record of who promised what. Access agreements are frequently verbal and are held in the memory of the person who made them. When that person rotates out, the agreement is not in any system the organisation maintains, and the next team discovers the arrangement only when it stops working.
The correction is procedural rather than structural. The access negotiation and the security assessment are produced together, by people who have spoken to each other, and both record the same facts: which area, which route, which party, which named interlocutor, what was agreed, on what date, and what the organisation will do if the agreement does not hold. Access records are held with the security file, so that rotation does not lose them. And any change to an access agreement goes through the same assessment that produced the original plan.
The organisations that manage this well are not the ones with the largest access teams. They are the ones where the person negotiating access and the person signing the risk assessment know each other's constraints, and where both of them have written down what the other one needs.