Skip to content

Evidence request lists

Voluntary Principles on Security and Human Rights (VPs)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Governance and Public Commitment

VP-GOV-01
Public Commitment to the Voluntary Principles

Make a public, board level commitment to implementing the Voluntary Principles on Security and Human Rights in extractive sector operations and embed the commitment in corporate policy.

Artefacts an auditor will ask for
  • Board approved human rights policy referencing the VPs
  • Public statement on the corporate website
  • Annual sustainability report disclosure
Where this commonly fails
  • Commitment buried in sub policies and not publicly visible
  • No board level approval evidence
  • Policy not refreshed after restructuring or new asset acquisitions
VP-GOV-02
Governance Structure and Accountability

Define accountable owners at corporate and asset level for implementation of the Voluntary Principles, including roles for security, human rights, community relations, and legal functions.

Artefacts an auditor will ask for
  • RACI for VP implementation
  • Steering committee charter
  • Asset level VP champions list
Where this commonly fails
  • Sole reliance on the security function
  • No community relations seat at the table
  • No escalation route to executive leadership

Implementation

VPSHR-3
Implementation Guidance and Reporting

Per VP: Annual Reporting + Multi-Stakeholder Engagement + Continuous Improvement + Incident Response.

Artefacts an auditor will ask for
  • VP evidence for VPSHR-3
Where this commonly fails
  • risk + training partial

Incidents, Grievance and Remediation

VP-INC-01
Incident Reporting and Investigation

Maintain a system to report, record, and investigate all incidents involving use of force, alleged abuses, or harm to workers, community members, or security personnel.

Artefacts an auditor will ask for
  • Incident management procedure
  • Investigation reports for material incidents
  • Root cause analysis
  • Corrective action register
Where this commonly fails
  • Incidents recorded as security events with no human rights lens
  • Investigation completed by the line of business involved
  • No timeline for closure
VP-INC-02
Whistleblower and Community Grievance Mechanism

Provide accessible mechanisms for workers, contractors, and community members to raise concerns about security related human rights impacts without retaliation.

Artefacts an auditor will ask for
  • Grievance procedure including anonymous channels
  • Statistics on grievances received and resolved
  • Anti retaliation policy
Where this commonly fails
  • No community accessible channel beyond a corporate hotline
  • Channels not communicated in local languages
  • No evidence of effectiveness review
VP-INC-03
Cooperation with Investigations and Remediation

Cooperate with lawful investigations into incidents involving security forces and provide remediation where the company has caused or contributed to harm.

Artefacts an auditor will ask for
  • Documented cooperation with authorities
  • Remediation plans for harmed individuals or communities
  • Closure letters
Where this commonly fails
  • Cooperation limited by legal posture without considering human rights obligations
  • Remediation defined only as monetary compensation
  • No follow up to confirm remediation was effective

Interactions

VPSHR-2
Interactions, Training, Capacity Building

Per VP: interactions including training + capacity + arms management + use of force consistent with human rights + complaints.

Artefacts an auditor will ask for
  • VP evidence for VPSHR-2
Where this commonly fails
  • risk + training partial

Interactions with Private Security

VP-PRI-01
Selection and Vetting of Private Security

Use private security companies that have policies and practices consistent with the Voluntary Principles, including human rights screening, background checks, and avoidance of personnel implicated in past abuses.

Artefacts an auditor will ask for
  • Pre qualification questionnaire
  • Background check procedure for private security personnel
  • Excluded individuals list
Where this commonly fails
  • No vetting beyond local licensing
  • No mechanism to flag personnel with abuse history
  • Vetting outsourced fully to the contractor with no oversight
VP-PRI-02
Contract Clauses for Private Security

Include in private security contracts explicit obligations to comply with the Voluntary Principles, the International Code of Conduct for Private Security Service Providers where applicable, proportional use of force, and cooperation with investigations.

Artefacts an auditor will ask for
  • Model contract clauses
  • Executed contracts with private security firms
  • Compliance certification from contractors
Where this commonly fails
  • Generic compliance language with no VP specific obligations
  • No reference to the International Code of Conduct
  • No right to terminate for human rights non compliance
VP-PRI-03
Use of Force and Firearms Policy

Require private security providers to limit the use of force to that which is strictly necessary and proportional, in line with the United Nations Basic Principles on the Use of Force and Firearms by Law Enforcement Officials.

Artefacts an auditor will ask for
  • Use of force policy issued to security personnel
  • Acknowledgement records
  • Firearms register where applicable
Where this commonly fails
  • Policy not translated into local language
  • No periodic refresher training
  • Firearms inventory not reconciled
VP-PRI-04
Training of Private Security Personnel

Ensure that private security personnel receive training on human rights, the Voluntary Principles, use of force, first aid, and respectful interaction with communities and workers.

Artefacts an auditor will ask for
  • Training curriculum
  • Training attendance records
  • Refresher schedule
  • Competency assessment results
Where this commonly fails
  • Training only on weapons handling with no human rights content
  • No records kept for guards rotated frequently
  • No verification of trainer credentials

Interactions with Public Security

VP-PUB-01
Engagement with Public Security

Engage with host government and public security providers to express the company's expectations regarding human rights, proportional use of force, and respect for international standards.

Artefacts an auditor will ask for
  • Memoranda of understanding with public security
  • Meeting minutes with police or military authorities
  • Briefing materials shared
Where this commonly fails
  • No written MoU
  • Engagement limited to operational logistics with no human rights content
  • No documentation of dialogue
VP-PUB-02
Training and Capacity Building for Public Security

Support, where appropriate, training of public security forces deployed to protect company operations on human rights, use of force, and the United Nations Code of Conduct for Law Enforcement Officials.

Artefacts an auditor will ask for
  • Training curriculum
  • Attendance records of public security personnel
  • Train the trainer plan
Where this commonly fails
  • Training delivered once at deployment and never refreshed
  • No coverage of women, children, and vulnerable groups
  • No method to verify trained individuals are actually on site
VP-PUB-03
Monitoring Public Security Conduct

Monitor the conduct of public security forces protecting company facilities and record incidents involving use of force, detention, or alleged abuse.

Artefacts an auditor will ask for
  • Incident log
  • Daily occurrence reports
  • Investigation files for serious incidents
Where this commonly fails
  • Incidents documented internally but never escalated to corporate
  • No definition of what constitutes a reportable incident
  • Records destroyed prematurely

Monitoring and Assurance

VP-MON-01
Internal Audit and Assurance

Subject VPs implementation to periodic internal audit and, where appropriate, external assurance against recognized criteria.

Artefacts an auditor will ask for
  • Internal audit plan including VPs
  • Audit reports with findings and management responses
  • External assurance statement where applicable
Where this commonly fails
  • VPs out of scope of corporate internal audit
  • Findings closed without verification
  • No second line review of self assessments
VP-MON-02
Continuous Improvement and Lessons Learned

Capture lessons learned from incidents, audits, and stakeholder engagement and feed them into improvements in policy, training, contracts, and operational practice.

Artefacts an auditor will ask for
  • Lessons learned register
  • Updates to policy and contracts traceable to lessons
  • Annual program improvement plan
Where this commonly fails
  • Lessons captured at site level but not shared across the portfolio
  • No metrics for improvement
  • Improvement actions without owners or due dates

Policy and Risk

VPSHR-1
Policy, Risk Assessment, Engagement with State and Private Security

Per Voluntary Principles on Security and Human Rights: Risk Assessment + Engagement with public and private security + commitment to international human rights + UN Code of Conduct.

Artefacts an auditor will ask for
  • VP evidence for VPSHR-1
Where this commonly fails
  • risk + training partial

Reporting and Transparency

VP-REP-01
Annual Reporting to the Initiative

Submit annual implementation reports to the Voluntary Principles Initiative covering policy commitments, risk assessment, public and private security engagement, training, incidents, and remediation.

Artefacts an auditor will ask for
  • Annual VPs implementation report
  • Internal data collection workflow
  • Sign off by accountable executive
Where this commonly fails
  • Reports late or skipped
  • Aggregated reporting hiding asset level issues
  • No internal audit of report content
VP-REP-02
Public Disclosure and Transparency

Disclose publicly the company's approach to implementing the Voluntary Principles, including material incidents and remediation, in sustainability or human rights reporting.

Artefacts an auditor will ask for
  • Sustainability report referencing VPs
  • Human rights report
  • Material incident disclosures
Where this commonly fails
  • Boilerplate reference to the VPs with no substance
  • No disclosure of incidents or lessons learned
  • No alignment with GRI or UNGPs reporting standards

Risk Assessment

VP-RA-01
Country and Asset Level Risk Assessment

Conduct a documented risk assessment for each operating context that identifies risks to human rights arising from interactions with public security, private security, and other security providers.

Artefacts an auditor will ask for
  • Country risk profile
  • Asset level risk register
  • Stakeholder mapping
  • Conflict sensitivity analysis
Where this commonly fails
  • Risk assessment limited to security threats against the company
  • No analysis of risks to communities and workers
  • Assessment not refreshed when operating context changes
VP-RA-02
Identification of Conflict and Human Rights Indicators

Identify indicators of conflict, repression, and human rights abuses in the operating environment, including historical patterns of violence and the rule of law.

Artefacts an auditor will ask for
  • Indicator framework
  • Open source and academic sources reviewed
  • Periodic indicator refresh log
Where this commonly fails
  • Indicators tracked but not used in decisions
  • No threshold for escalation
  • Reliance on government sources only
VP-RA-03
Equipment Transfers and Use of Force Assessment

Assess the risks associated with transferring equipment such as vehicles, communications gear, or non lethal materials to public or private security and the potential for misuse against civilians.

Artefacts an auditor will ask for
  • Equipment transfer register
  • Pre transfer human rights assessment
  • Post transfer monitoring records
Where this commonly fails
  • No record of equipment transfers
  • Transfers handled informally by site managers
  • No monitoring of how equipment is used

Stakeholder Engagement

VP-STK-01
Community Consultation and Engagement

Engage proactively with affected communities, including indigenous peoples where applicable, to understand security related concerns and to communicate the company's expectations of security providers.

Artefacts an auditor will ask for
  • Community engagement plan
  • Meeting minutes with community representatives
  • FPIC documentation where applicable
Where this commonly fails
  • Engagement only at project inception
  • No women, youth, or vulnerable group representation
  • FPIC treated as a one off consultation
VP-STK-02
Civil Society and Multi Stakeholder Engagement

Engage with civil society organizations and participate in the Voluntary Principles Initiative multi stakeholder dialogue at national and global levels.

Artefacts an auditor will ask for
  • VPI membership documentation
  • Plenary attendance
  • In country working group participation
Where this commonly fails
  • Membership without active participation
  • No engagement with critical civil society voices
  • Reporting limited to internal channels
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Voluntary Principles on Security and Human Rights (VPs) framework page.