Voluntary Principles on Security and Human Rights (VPs)
The Voluntary Principles on Security and Human Rights (VPs), established in 2000, guide extractive sector companies in maintaining the safety and security of their operations within a framework that respects human rights. The VPs are a multi-stakeholder initiative involving governments (13), companies (39), and NGOs (13). Three pillars: risk assessment, interactions with public security, and interactions with private security. Companies report annually on VP implementation. The VP Initiative is administered from The Hague. Particularly relevant for operations in conflict-affected and high-risk areas.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Assurance
| Code | Title |
|---|---|
| VP-MON-01 | Internal Audit and Assurance |
Governance
| Code | Title |
|---|---|
| VP-GOV-01 | Public Commitment to the Voluntary Principles |
| VP-GOV-02 | Governance Structure and Accountability |
Grievance
| Code | Title |
|---|---|
| VP-INC-02 | Whistleblower and Community Grievance Mechanism |
Implementation and Governance
| Code | Title |
|---|---|
| BIK-G1 | Alignment with Digital Services Act |
| BIK-G2 | Safer Internet Centres network |
| BIK-G3 | Cross-sectoral cooperation |
| BIK-G4 | Monitoring and reporting |
| IG-1 | Annual Reporting |
| IG-2 | Multi-Stakeholder Engagement |
| IG-3 | Continuous Improvement |
| IG-4 | Incident Response |
Improvement
| Code | Title |
|---|---|
| VP-MON-02 | Continuous Improvement and Lessons Learned |
Incident Management
| Code | Title |
|---|---|
| VP-INC-01 | Incident Reporting and Investigation |
| VP-INC-03 | Cooperation with Investigations and Remediation |
Interactions with Private Security
| Code | Title |
|---|---|
| PrS-1 | Selection and Vetting |
| PrS-2 | Contractual Requirements |
| PrS-3 | Use of Force Policies |
| PrS-4 | Training Requirements |
| PrS-5 | Grievance Mechanisms |
Interactions with Public Security
| Code | Title |
|---|---|
| PS-1 | Policy and Procedures |
| PS-2 | Position Risk Designation |
| PS-3 | Personnel Screening |
| PS-4 | Personnel Termination |
| PS-5 | Personnel Transfer |
Private Security
| Code | Title |
|---|---|
| VP-PRI-01 | Selection and Vetting of Private Security |
| VP-PRI-02 | Contract Clauses for Private Security |
| VP-PRI-03 | Use of Force and Firearms Policy |
| VP-PRI-04 | Training of Private Security Personnel |
Public Security
| Code | Title |
|---|---|
| VP-PUB-01 | Engagement with Public Security |
| VP-PUB-02 | Training and Capacity Building for Public Security |
| VP-PUB-03 | Monitoring Public Security Conduct |
Reporting
| Code | Title |
|---|---|
| VP-REP-01 | Annual Reporting to the Initiative |
| VP-REP-02 | Public Disclosure and Transparency |
Risk Assessment
| Code | Title |
|---|---|
| COSO-IC-ERM-ST | Strategy and objective-setting — aligning risk appetite with strategy and formulating business objectives (ERM Framework integration) |
| COSO-IC-RA-06 | The organization specifies objectives with sufficient clarity for risk identification and assessment |
| COSO-IC-RA-07 | The organization identifies risks to objectives across the entity and analyzes them for management |
| COSO-IC-RA-08 | The organization considers the potential for fraud in assessing risks |
| COSO-IC-RA-09 | The organization identifies and assesses changes that could significantly impact internal control |
| DMF-4.1 | Impact Assessment |
| DMF-4.2 | Risk Categorization |
| DMF-4.3 | Regulatory Risk Assessment |
| RA-1 | Policy and Procedures |
| RA-2 | Security Categorization |
| RA-3 | Risk Assessment |
| RA-4 | Rule of Law Assessment |
| RA-5 | Vulnerability Monitoring and Scanning |
| VP-RA-01 | Country and Asset Level Risk Assessment |
| VP-RA-02 | Identification of Conflict and Human Rights Indicators |
| VP-RA-03 | Equipment Transfers and Use of Force Assessment |
Risk Assessment
A dynamic and iterative process for identifying and assessing risks to the achievement of objectives, forming the basis for determining how risks should be managed.
| Code | Title |
|---|---|
| COSO-IC-ERM-ST | Strategy and objective-setting — aligning risk appetite with strategy and formulating business objectives (ERM Framework integration) |
| COSO-IC-RA-06 | The organization specifies objectives with sufficient clarity for risk identification and assessment |
| COSO-IC-RA-07 | The organization identifies risks to objectives across the entity and analyzes them for management |
| COSO-IC-RA-08 | The organization considers the potential for fraud in assessing risks |
| COSO-IC-RA-09 | The organization identifies and assesses changes that could significantly impact internal control |
| DMF-4.1 | Impact Assessment |
| DMF-4.2 | Risk Categorization |
| DMF-4.3 | Regulatory Risk Assessment |
| RA-1 | Policy and Procedures |
| RA-2 | Security Categorization |
| RA-3 | Risk Assessment |
| RA-4 | Rule of Law Assessment |
| RA-5 | Vulnerability Monitoring and Scanning |
| VP-RA-01 | Country and Asset Level Risk Assessment |
| VP-RA-02 | Identification of Conflict and Human Rights Indicators |
| VP-RA-03 | Equipment Transfers and Use of Force Assessment |
Stakeholder Engagement
| Code | Title |
|---|---|
| VP-STK-01 | Community Consultation and Engagement |
| VP-STK-02 | Civil Society and Multi Stakeholder Engagement |
Your Compliance Coverage
If you comply with Voluntary Principles on Security and Human Rights (VPs), you already cover:
German Supply Chain Due Diligence Act (LkSG)
15%
8 controls mapped
Compare →ASEAN Data Management Framework
13%
7 controls mapped
Compare →Modern Slavery Act 2018 (Australia)
13%
7 controls mapped
Compare →+ 594 more: AML/CTF Act 2006 (Australia) (13%), Singapore Government Instruction Manual on ICT&SS Management (IM8) (13%)
See all 597 mapped frameworks ↓Maps to 597 other frameworks
Frequently Asked Questions
What is Voluntary Principles on Security and Human Rights (VPs)?
Voluntary Principles on Security and Human Rights (VPs) is a compliance framework from International (VP Initiative) with 14 domains and 52 controls. The Voluntary Principles on Security and Human Rights (VPs), established in 2000, guide extractive sector companies in maintaining the safety and security of their operations within a framework that respects human rights. The VPs are a multi-stakeholder initiative involving governments (13), companies (39), and NGOs (13). Three pillars: risk assessment, interactions with public security, and interactions with private security. Companies report annually on VP implementation. The VP Initiative is administered from The Hague. Particularly relevant for operations in conflict-affected and high-risk areas. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Voluntary Principles on Security and Human Rights (VPs) have?
Voluntary Principles on Security and Human Rights (VPs) has 52 controls organised across 14 domains. The largest domains are Risk Assessment (13 controls), Implementation and Governance (8 controls), Interactions with Private Security (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Voluntary Principles on Security and Human Rights (VPs) map to?
Voluntary Principles on Security and Human Rights (VPs) maps to 597 other compliance frameworks. The top mapping partners are German Supply Chain Due Diligence Act (LkSG) (15% coverage), ASEAN Data Management Framework (13% coverage), Modern Slavery Act 2018 (Australia) (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Voluntary Principles on Security and Human Rights (VPs) compliance?
Start your Voluntary Principles on Security and Human Rights (VPs) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Voluntary Principles on Security and Human Rights (VPs) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required