All Practice Exams

100+ Free PECB ISO 18788 Lead Implementer Practice Questions

Prepare for the PECB Certified ISO 18788 Lead Implementer exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: PECB ISO 18788 Lead Implementer Exam

12 Questions

Official Exam Format (75 points)

PECB Candidate Handbook ISO 18788 Lead Implementer (2026)

3 Hours

Exam Time Limit

PECB Training Catalog (Lead exams: 3 hours)

70%

Passing Score

PECB Candidate Handbook ISO 18788 Lead Implementer (2026)

Open Book

Exam Delivery Mode (standard + course materials + notes)

PECB Candidate Handbook ISO 18788 Lead Implementer (2026)

33.35%

Exam Points on Implementing a SOMS (Domain 4)

PECB Candidate Handbook ISO 18788 Lead Implementer (2026)

300 Hours

Project Experience for Lead Implementer Credential

PECB ISO 18788 Credential Requirements

7 Domains

Official Competency Domains

PECB Candidate Handbook ISO 18788 Lead Implementer (2026)

3 Years

Certification Validity (CPD + AMF maintenance)

PECB Certification Maintenance Policy

PECB ISO 18788 Lead Implementer certifies the competence to establish and operate a Security Operations Management System based on ISO 18788:2015. The official exam is a 12-question, open-book, 3-hour assessment with a 70% passing score across seven domains, weighted toward implementing (33.35%) and evaluating (26.68%) the SOMS. This free bank uses four-option English MCQs as an independent study adaptation of the implementation knowledge, not a simulation of the official exam format.

Sample PECB ISO 18788 Lead Implementer Practice Questions

Try these sample questions to test your PECB ISO 18788 Lead Implementer exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1A consulting team is engaged to establish an SOMS for a private security company. What is the fundamental purpose the SOMS must serve under ISO 18788?
A.To manage security operations in a manner that enhances human safety and security and protects tangible and intangible assets, consistent with respect for international, national and local laws and human rights
B.To provide a certifiable service-quality framework for guarding contracts in stable jurisdictions, standardizing service levels and customer satisfaction measurement
C.To establish rules of engagement for military forces operating alongside private contractors in armed conflict, in line with international humanitarian law
D.To transfer the client's own duty of care for security outcomes to the contracted provider through a documented allocation of responsibilities
Explanation: Annex B.1 states the goal of an SOMS: managing security operations to enhance human safety and security and protect assets, consistent with respect for laws and human rights — particularly where governance may be weak or the rule of law undermined.
2An implementer must explain to top management which external commitments the SOMS must embed. Which set does ISO 18788 name as the instruments it draws on?
A.The Montreux Document (2008), the International Code of Conduct for Private Security Service Providers (2010), the UN Guiding Principles on Business and Human Rights (2011), and commitments such as the Voluntary Principles on Security and Human Rights (2000)
B.The Geneva Conventions and the Hague Conventions, which the standard cites as its normative references for international humanitarian law obligations
C.ISO 9001, ISO 14001 and ISO 45001, whose management system requirements ISO 18788 incorporates by normative reference
D.The UN Global Compact Ten Principles and the ILO Declaration on Fundamental Principles and Rights at Work, adopted as the standard's human rights baseline
Explanation: The Introduction and Clause 2 ground ISO 18788 in the Montreux Document, the ICoC and the UN Guiding Principles, with the Voluntary Principles cited among voluntary commitments. Clause 4.4 requires the SOMS to implement ICoC principles and Clause 5.1.2 requires a Statement of Conformance to these instruments.
3Why is the PDCA cycle relevant to structuring an SOMS implementation project?
A.ISO 18788 adopts Plan-Do-Check-Act to structure security operations processes: Plan establishes policy, objectives and procedures; Do implements and operates them; Check monitors and measures against policy and objectives; Act takes corrective action for continual improvement
B.Annex D offers PDCA only as an optional alternative to the risk-based approach of Clause 6, so an implementer may structure the project on either model
C.PDCA describes the certification audit sequence rather than the management system, mapping to Stage 1, Stage 2, surveillance and recertification audits
D.PDCA structures only the operational requirements of Clause 8, while Clauses 4 to 7 follow the ISO high-level structure instead
Explanation: Annex D describes PDCA as the structure of the SOMS: Plan establishes the system, Do implements and operates it, Check monitors and reviews performance, and Act maintains and improves it through corrective and preventive action based on internal audit and management review.
4An implementer scoping a project notes the client already runs an ISO 9001 quality management system. How does ISO 18788 treat this?
A.The standard is designed to integrate with other management systems, and an organization that has adopted a management systems approach may use its existing system as a foundation for the SOMS
B.The existing quality system must be formally decommissioned before SOMS work begins, so that quality objectives do not contaminate the SOMS scope
C.The SOMS must be run as a wholly separate system with its own policy, audit programme and management review, because ISO 18788 does not permit combined audits
D.ISO 9001 conformity already satisfies Clauses 4 to 7 of ISO 18788, so the implementation project need only address Clauses 8 to 10
Explanation: Annex D states the standard is designed for integration with quality, safety, environmental, information security and other management systems, and that organizations with an existing management system may use it as a foundation for the SOMS — one suitably designed system can satisfy multiple standards.
5Which definition should an implementer apply when drafting the organization's risk documentation?
A.Risk is the effect of uncertainty on objectives, and risk assessment is the overall process of risk identification, risk analysis and risk evaluation
B.Risk is the probability that an identified threat will exploit a vulnerability, and risk assessment is the calculation of that probability against asset value
C.Risk is the exposure remaining after controls have been applied, and risk assessment is the periodic re-costing of that exposure for insurance purposes
D.Risk is the effect of uncertainty on objectives, and risk assessment comprises risk identification, risk analysis and risk treatment
Explanation: ISO 18788 adopts the ISO Guide 73 vocabulary: risk is the effect of uncertainty on objectives, and Annex E confirms that, consistent with ISO 31000, risk assessment is the overall process of risk identification, analysis and evaluation — the structure Clause 6.1.1 requires.
6An implementer is asked whether certification is mandatory for using ISO 18788. What does Annex E say?
A.Verification of the SOMS may be by an acceptable first-, second- or third-party mechanism; verification does not require third-party certification, and adopting the standard alone does not guarantee optimal outcomes
B.Third-party certification by a body accredited to ISO/IEC 17021-1 is required before an organization may claim conformity with the standard
C.Verification is limited to second-party client audits, because the informative annexes cannot be objectively audited by a certification body
D.Adoption of the standard guarantees optimal security operations outcomes provided the organization implements every clause of Annex A
Explanation: Annex E states external or internal auditing may verify SOMS compliance, verification may be first-, second- or third-party, third-party certification is not required, and adoption of the standard does not by itself guarantee optimal security operations outcomes.
7An implementer drafting training content needs the standard's definition of competence. ISO 18788 defines competence as:
A.The ability to apply knowledge and skills to achieve intended results
B.Documented evidence that a person has attended the training the organization has specified for their role
C.The extent to which planned activities are realized and planned results achieved
D.A person's demonstrated physical and psychological fitness for the duties assigned, established during background screening
Explanation: Clause 3.5 defines competence as the ability to apply knowledge and skills to achieve intended results. Clause 7.2 builds on this: competence is demonstrated through education, training or experience and evaluated through competence-based metrics.
8An implementer must ensure the SOMS design satisfies Clause 4.4. What does the clause require the SOMS itself to implement?
A.The principles and commitments of the ICoC, with control of subcontracted or outsourced in-scope processes identified and managed within the SOMS
B.The requirements of ISO/IEC 17021-1, so that the SOMS mirrors the certification body's audit methodology from the outset
C.The Montreux Document obligations that apply to States, adopted by the organization in place of its own operational controls
D.The client's security procedures, with subcontracted processes excluded from the SOMS because the subcontractor holds its own certification
Explanation: Clause 4.4 requires the organization to establish, implement, maintain and continually improve the SOMS, states that the SOMS shall implement the principles and commitments of the ICoC, and requires control of subcontracted or outsourced in-scope processes to be identified and managed within the SOMS.
9Which documents must an implementer ensure exist as part of the SOMS documented information under Clause 7.5.1?
A.The security operations policy, Statement of Conformance, objectives and targets, the scope description, the Statement of Applicability, and a description of the main SOMS elements and their interaction
B.The policy, objectives and targets, the scope description and the internal audit programme, but not the Statement of Conformance, which Clause 5.1.2 keeps outside documented information
C.Only the documents the certification body requests at the Stage 1 documentation review, since Clause 7.5.1 defers the documented information set to the auditor
D.A quality manual, a documented procedure for each clause and a records matrix, following the six mandatory procedures required by ISO 18788
Explanation: Clause 7.5.1 lists required SOMS documented information: records required by the standard, the policy, Statement of Conformance, objectives and targets, the scope description, the Statement of Applicability, a description of the main elements and their interaction, and information needed for effective implementation and operation.
10An implementer is building the legal register required by Clause 6.1.2. Which jurisdictions must be considered when identifying applicable national laws?
A.The country of the organization, the countries of its personnel, the country of operations and the country of the client
B.The country of operations and the country of the client, but not the countries of personnel, whose home law is displaced by the employment contract
C.The country of the organization and the country of operations only, since personnel and client jurisdictions fall under contractual rather than legal requirements
D.Whichever single jurisdiction the client nominates in the contract as the governing law of the engagement
Explanation: The note to Clause 6.1.2 states national laws can include those of the country of the organization, the countries of its personnel, the country of operations and the country of the client. The legal register must also capture regulatory, contractual, licensing and voluntary commitments, and be kept up to date.

About the PECB ISO 18788 Lead Implementer Exam

Lead-level certification validating the expertise to support an organization in establishing, implementing, managing and maintaining a Security Operations Management System based on ISO 18788:2015 — from gap analysis, scope and risk criteria through operational controls for use of force, vetting, weapons and incident management, to performance evaluation, continual improvement and certification audit preparation — ensuring protection of lives and property while respecting human rights and national and international laws.

Assessment

Seven competency domains with official handbook weights (% of exam points): Domain 1 SOMS fundamental principles 6.67%; Domain 2 SOMS and ISO 18788 requirements 6.67%; Domain 3 planning the SOMS implementation 13.34%; Domain 4 implementing a SOMS 33.35%; Domain 5 monitoring, measurement, analysis and evaluation of a SOMS 26.68%; Domain 6 continual improvement of a SOMS 6.67%; Domain 7 preparing for a SOMS certification audit 6.67%.

Time Limit

180 minutes

Passing Score

70%

Exam Fee

Included with PECB training course (first attempt, one free retake, certification application fee and first-year AMF included in course price). Standalone: US$1,000 Lead exam plus US$500 certification application fee (PECB)

PECB ISO 18788 Lead Implementer Exam Content Outline

6.67% of exam points

Domain 1: Fundamental principles and concepts of a SOMS

SOMS purpose, PDCA and integration, Montreux Document, ICoC, UN Guiding Principles, key definitions and Annex E qualifiers

6.67% of exam points

Domain 2: SOMS and ISO 18788 requirements

ISO 18788:2015 Clauses 4-10 as implementation obligations, from context and risk criteria through use of force, vetting, incidents and improvement

13.34% of exam points

Domain 3: Planning the SOMS implementation

Annex C gap analysis, scope and Statement of Applicability, stakeholder and supply chain analysis, risk criteria, policy, objectives cascade, roles and resources

33.35% of exam points

Domain 4: Implementing a SOMS

Standing up SOMS processes: ethics rollout, competence and training, communications, documented information, use of force, vetting, weapons, OH&S, incidents, grievances and subcontractor controls

26.68% of exam points

Domain 5: Monitoring, measurement, analysis and evaluation of a SOMS

Monitoring determinations, KPIs, compliance evaluation, exercise programmes, internal audit programme and management review design

6.67% of exam points

Domain 6: Continual improvement of a SOMS

Nonconformity and corrective action, change management programme, and exploiting improvement opportunities

6.67% of exam points

Domain 7: Preparing for a SOMS certification audit

Certification readiness, stage 1/stage 2 expectations, nonconformity response, PECB credential tiers, and surveillance and recertification

How to Pass the PECB ISO 18788 Lead Implementer Exam

What You Need to Know

  • Passing score: 70%
  • Assessment: Seven competency domains with official handbook weights (% of exam points): Domain 1 SOMS fundamental principles 6.67%; Domain 2 SOMS and ISO 18788 requirements 6.67%; Domain 3 planning the SOMS implementation 13.34%; Domain 4 implementing a SOMS 33.35%; Domain 5 monitoring, measurement, analysis and evaluation of a SOMS 26.68%; Domain 6 continual improvement of a SOMS 6.67%; Domain 7 preparing for a SOMS certification audit 6.67%.
  • Time limit: 180 minutes
  • Exam fee: Included with PECB training course (first attempt, one free retake, certification application fee and first-year AMF included in course price). Standalone: US$1,000 Lead exam plus US$500 certification application fee

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

PECB ISO 18788 Lead Implementer Study Tips from Top Performers

1Learn the official domain weights and invest accordingly: implementing a SOMS (Domain 4) is 33.35% of points and monitoring/evaluation (Domain 5) another 26.68%
2Master the Annex C gap analysis five key areas — risk identification, human rights risk analysis, legal requirements, existing risk management practices including subcontracting, and previous emergencies and response measures
3Know the distinctive SOMS artifacts and how to build them: Statement of Conformance (public, top-management endorsed), Statement of Applicability (risk-assessment driven), security operations policy, and the objectives-targets-KPI cascade
4Be able to design the operational controls from the clauses: RUF-based use of force procedures, weapon-specific written authorizations, vetting with the eighteen-year armed minimum, weapons accountability, grievance and whistle-blower mechanisms with anti-retaliation protection
5Drill the evaluation machinery: what/when/how to monitor, periodic compliance evaluation records, annual exercises with formal reports, internal audit programme design, and management review inputs and outputs
6Distinguish correction, corrective action and preventive action precisely, and know the change management programme requirement of Clause 10.2.2

Frequently Asked Questions

What is the PECB ISO 18788 Lead Implementer exam format?

The official exam is a 12-question, 75-point open-book exam completed in 3 hours with a 70% passing score, delivered online via PECB Exams or paper-based through partners. Permitted references include the ISO 18788 standard, training materials, personal notes and a hard-copy dictionary. The PECB candidate handbook (Version 3.2) states this exam comprises essay-type questions and notes that PECB will progressively transition its exams to open-book, scenario-based multiple choice; its published sample questions remain constructed-response tasks such as drafting clause action plans.

How is the exam weighted across domains?

Per the official candidate handbook: Domain 4, implementing a SOMS, carries 33.35% of points; Domain 5, monitoring, measurement, analysis and evaluation, carries 26.68%; Domain 3, planning the implementation, carries 13.34%; and Domains 1, 2, 6 and 7 each carry 6.67%. The exam splits between comprehension/application/analysis questions (4 of 12) and evaluation-level questions (8 of 12).

What credential tiers exist for PECB ISO 18788 implementers?

Four tiers, all requiring the Lead Implementer exam (or accepted equivalent) and signing the PECB Code of Ethics: Provisional Implementer (no experience), Implementer (2 years professional experience including 1 year in security operations management and 200 project hours), Lead Implementer (5 years including 2 in the field and 300 project hours), and Senior Lead Implementer (10 years including 7 in the field and 1,000 project hours).

What makes ISO 18788 implementation different from a generic management system rollout?

Beyond the standard PDCA machinery, an SOMS embeds the Montreux Document and ICoC principles into operations: a public Statement of Conformance, a risk-driven Statement of Applicability, a human rights risk analysis, use of force procedures governed by competent-authority rules, weapon-specific written authorizations, vetting including human rights screening, grievance and whistle-blower mechanisms with anti-retaliation protection, and incident investigation with redress — all for environments where governance may be weak.

How much does the PECB ISO 18788 Lead Implementer exam cost?

With a PECB partner training course, the fee bundles the first exam attempt, one free retake, the certification application fee and the first-year Annual Maintenance Fee, completed within 12 months. Standalone, PECB publishes a US$1,000 Lead exam fee plus a US$500 certification application fee.

Is this practice test the official PECB exam?

No. OpenExamPrep provides free English multiple-choice practice questions as an independent study aid. It is not affiliated with PECB and does not replace official training or the live exam. The official assessment is a 12-question open-book exam; this bank uses 100 four-option questions with no time limit to build the underlying knowledge and judgment, not to simulate the official format.