Back to Frameworks

Voluntary Principles on Security and Human Rights (VPs)

International (VP Initiative)
v2000 (regularly updated)
11 domains
24 controls

The Voluntary Principles on Security and Human Rights (VPs), established in 2000, guide extractive sector companies in maintaining the safety and security of their operations within a framework that respects human rights. The VPs are a multi-stakeholder initiative involving governments (13), companies (39), and NGOs (13). Three pillars: risk assessment, interactions with public security, and interactions with private security. Companies report annually on VP implementation. The VP Initiative is administered from The Hague. Particularly relevant for operations in conflict-affected and high-risk areas.

Verified

Voluntary Principles on Security and Human Rights (VPs) is a compliance framework from International (VP Initiative) with 11 domains and 24 controls that map to 112 other frameworks. The largest domains are Interactions with Private Security (4 controls), Incidents, Grievance and Remediation (3 controls), Interactions with Public Security (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Governance and Public Commitment

2 controls
Controls in the Governance and Public Commitment domain of Voluntary Principles on Security and Human Rights (VPs)2 controls
CodeTitle
VP-GOV-01Public Commitment to the Voluntary Principles
VP-GOV-02Governance Structure and Accountability

Implementation

1 controls
Controls in the Implementation domain of Voluntary Principles on Security and Human Rights (VPs)1 controls
CodeTitle
VPSHR-3Implementation Guidance and Reporting

Incidents, Grievance and Remediation

3 controls
Controls in the Incidents, Grievance and Remediation domain of Voluntary Principles on Security and Human Rights (VPs)3 controls
CodeTitle
VP-INC-01Incident Reporting and Investigation
VP-INC-02Whistleblower and Community Grievance Mechanism
VP-INC-03Cooperation with Investigations and Remediation

Interactions

1 controls
Controls in the Interactions domain of Voluntary Principles on Security and Human Rights (VPs)1 controls
CodeTitle
VPSHR-2Interactions, Training, Capacity Building

Interactions with Private Security

4 controls
Controls in the Interactions with Private Security domain of Voluntary Principles on Security and Human Rights (VPs)4 controls
CodeTitle
VP-PRI-01Selection and Vetting of Private Security
VP-PRI-02Contract Clauses for Private Security
VP-PRI-03Use of Force and Firearms Policy
VP-PRI-04Training of Private Security Personnel

Interactions with Public Security

3 controls
Controls in the Interactions with Public Security domain of Voluntary Principles on Security and Human Rights (VPs)3 controls
CodeTitle
VP-PUB-01Engagement with Public Security
VP-PUB-02Training and Capacity Building for Public Security
VP-PUB-03Monitoring Public Security Conduct

Monitoring and Assurance

2 controls
Controls in the Monitoring and Assurance domain of Voluntary Principles on Security and Human Rights (VPs)2 controls
CodeTitle
VP-MON-01Internal Audit and Assurance
VP-MON-02Continuous Improvement and Lessons Learned

Policy and Risk

1 controls
Controls in the Policy and Risk domain of Voluntary Principles on Security and Human Rights (VPs)1 controls
CodeTitle
VPSHR-1Policy, Risk Assessment, Engagement with State and Private Security

Reporting and Transparency

2 controls
Controls in the Reporting and Transparency domain of Voluntary Principles on Security and Human Rights (VPs)2 controls
CodeTitle
VP-REP-01Annual Reporting to the Initiative
VP-REP-02Public Disclosure and Transparency

Risk Assessment

3 controls
Controls in the Risk Assessment domain of Voluntary Principles on Security and Human Rights (VPs)3 controls
CodeTitle
VP-RA-01Country and Asset Level Risk Assessment
VP-RA-02Identification of Conflict and Human Rights Indicators
VP-RA-03Equipment Transfers and Use of Force Assessment

Stakeholder Engagement

2 controls
Controls in the Stakeholder Engagement domain of Voluntary Principles on Security and Human Rights (VPs)2 controls
CodeTitle
VP-STK-01Community Consultation and Engagement
VP-STK-02Civil Society and Multi Stakeholder Engagement

Your Compliance Coverage

If you comply with Voluntary Principles on Security and Human Rights (VPs), you already cover:

Maps to 112 other frameworks

24 total controls
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
4%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
4%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
4%
IEC 62443
1 source controls mapped|4 target controls covered
4%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
4%
Kids Online Safety Act (KOSA)
1 source controls mapped|1 target controls covered
4%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
4%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
4%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
4%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27014:2020
1 source controls mapped|1 target controls covered
4%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
4%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|2 target controls covered
4%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|2 target controls covered
4%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|3 target controls covered
4%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|2 target controls covered
4%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|4 target controls covered
4%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
4%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|1 target controls covered
4%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
4%
NIST SP 800-30
1 source controls mapped|1 target controls covered
4%
NIST SP 800-37
1 source controls mapped|1 target controls covered
4%
NIST SP 800-39
1 source controls mapped|1 target controls covered
4%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
4%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
4%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
4%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
4%
BSI IT-Grundschutz
1 source controls mapped|3 target controls covered
4%
API 1164
1 source controls mapped|3 target controls covered
4%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
4%
APPI
1 source controls mapped|2 target controls covered
4%
Bahrain PDPL
1 source controls mapped|2 target controls covered
4%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|3 target controls covered
4%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
4%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
4%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
4%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
4%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
4%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|2 target controls covered
4%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
4%
APRA CPS 234
1 source controls mapped|2 target controls covered
4%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
4%
NIST SP 800-171
1 source controls mapped|1 target controls covered
4%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
4%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
4%
4%
Indiana Consumer Data Protection Act
1 source controls mapped|1 target controls covered
4%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
4%
Jamaica Data Protection Act 2020
1 source controls mapped|2 target controls covered
4%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
4%
Kentucky Consumer Data Protection Act
1 source controls mapped|2 target controls covered
4%
South Korea PIPA
1 source controls mapped|2 target controls covered
4%
Laos Law on Prevention and Combating Cybercrime (2015)
1 source controls mapped|1 target controls covered
4%
LGPD
1 source controls mapped|1 target controls covered
4%
Liechtenstein DPA
1 source controls mapped|1 target controls covered
4%
Malaysia PDPA 2010
1 source controls mapped|2 target controls covered
4%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|2 target controls covered
4%
Mauritius DPA
1 source controls mapped|1 target controls covered
4%
Mexico LFPDPPP
1 source controls mapped|1 target controls covered
4%
Minnesota Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
4%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
4%
Montana Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
4%
MTCS (Singapore)
1 source controls mapped|2 target controls covered
4%
Nebraska Data Privacy Act
1 source controls mapped|4 target controls covered
4%
NERC CIP
1 source controls mapped|1 target controls covered
4%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
4%
New Hampshire Data Privacy Act
1 source controls mapped|1 target controls covered
4%
New Jersey Data Privacy Act
1 source controls mapped|2 target controls covered
4%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|4 target controls covered
4%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
4%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
4%
NIS2 Directive Implementing Acts
1 source controls mapped|1 target controls covered
4%
NIST SP 800-122
1 source controls mapped|1 target controls covered
4%
NIST SP 800-144
1 source controls mapped|1 target controls covered
4%
NIST SP 800-145
1 source controls mapped|1 target controls covered
4%
NIST SP 800-146
1 source controls mapped|1 target controls covered
4%
4%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
4%
OECD AI Principles
1 source controls mapped|1 target controls covered
4%
OECD Recommendation on Artificial Intelligence (2024 Update)
1 source controls mapped|2 target controls covered
4%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
4%
Open Banking Security
1 source controls mapped|2 target controls covered
4%
Oregon Consumer Privacy Act
1 source controls mapped|1 target controls covered
4%
OSFI B-13
1 source controls mapped|3 target controls covered
4%
Virginia CDPA
1 source controls mapped|1 target controls covered
4%
Vietnam PDPD
1 source controls mapped|1 target controls covered
4%
Uruguay DPL
1 source controls mapped|1 target controls covered
4%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
4%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
4%
Turkey KVKK
1 source controls mapped|1 target controls covered
4%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|1 target controls covered
4%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
4%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
4%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|1 target controls covered
4%
Taiwan PDPA
1 source controls mapped|1 target controls covered
4%
PSD2 SCA
1 source controls mapped|2 target controls covered
4%
Qatar DPL
1 source controls mapped|2 target controls covered
4%
Privacy Act 2020
1 source controls mapped|1 target controls covered
4%
POPIA
1 source controls mapped|1 target controls covered
4%
Peru DPL
1 source controls mapped|2 target controls covered
4%
Personal Data Act (personopplysningsloven)
1 source controls mapped|1 target controls covered
4%
PDPA Thailand
1 source controls mapped|1 target controls covered
4%
PDPA Singapore
1 source controls mapped|1 target controls covered
4%

What is Voluntary Principles on Security and Human Rights (VPs) and who does it apply to?

Voluntary Principles on Security and Human Rights (VPs) is a compliance framework from International (VP Initiative) with 11 domains and 24 controls. The Voluntary Principles on Security and Human Rights (VPs), established in 2000, guide extractive sector companies in maintaining the safety and security of their operations within a framework that respects human rights. The VPs are a multi-stakeholder initiative involving governments (13), companies (39), and NGOs (13). Three pillars: risk assessment, interactions with public security, and interactions with private security. Companies report annually on VP implementation. The VP Initiative is administered from The Hague. Particularly relevant for operations in conflict-affected and high-risk areas. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Voluntary Principles on Security and Human Rights (VPs) actually require?

Voluntary Principles on Security and Human Rights (VPs) has 24 controls organised across 11 domains. The largest domains are Interactions with Private Security (4 controls), Incidents, Grievance and Remediation (3 controls), Interactions with Public Security (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Voluntary Principles on Security and Human Rights (VPs) do I already cover?

Voluntary Principles on Security and Human Rights (VPs) maps to 112 other compliance frameworks. The top mapping partners are Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) (4% coverage), ISO 31000:2018 (4% coverage), ISO/IEC 23894:2023 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Voluntary Principles on Security and Human Rights (VPs)?

Start your Voluntary Principles on Security and Human Rights (VPs) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Voluntary Principles on Security and Human Rights (VPs) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required