Skip to the disclosure focus

Disclosure LibraryPractitioner guidance for every reporting disclosure

GRI 410: Security Practices·Disclosure GRI 410-1

Security personnel trained in human rights policies or procedures

Practical guidance for preparing this disclosure. Use this card to identify the information to prepare, verify claims and organise supporting evidence. For exact requirements, always refer to the official Global Reporting Initiative source.

Legal status

GRI 410: Security Practices 2016 remains the applicable published GRI Topic Standard and is effective for reports or other materials published on or after 1 July 2018.

Published passport

Last reviewed 2026-08-03
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by Global Reporting Initiative

Standard

GRI 410: Security Practices

Disclosure GRI 410-1 · 2016

Effective

2018-07-01

Official source: Open ↗

Last reviewed

2026-08-03

LRA educational guidance · Not issued or endorsed by Global Reporting Initiative

Disclosure focus

This disclosure requires the organization to report the percentage of security personnel who have received formal training in the organization’s human rights policies or specific procedures and their application to security.

Security personnel can include employees of the organization and employees of third-party organizations providing security services. GRI recommends using the total number of both groups to calculate the percentage and stating whether third-party personnel are included in the calculation.

The organization must also state whether its training requirements apply to third-party organizations providing security personnel.

Generic human rights, compliance, cybersecurity, health and safety or workplace-conduct training does not automatically qualify. The training must address the organization’s human rights policy or relevant procedures and their application to security.

The disclosure does not require separate percentages by site, country or security provider. Such breakdowns can be presented where useful.

This LRA educational guidance supports disclosure preparation. For the exact requirements, always refer to the official Global Reporting Initiative source.

Before you start

Before you start

A quick mental checklist before you prepare this disclosure — tick each as you settle it.

Preparation

Key information to prepare

Preparation field What to capture Evidence hint Owner
Security-personnel population All individuals meeting the GRI definition, separated into organizational employees and third-party personnel. Security rosters, service-provider rosters, role descriptions and contracts. Security / Procurement
Qualifying training definition The policy or procedure covered and how the training applies it to security work. Course materials, agenda, module description and version history. Human Rights / Security / Learning
Trained personnel Number of individuals who received qualifying formal training. LMS records, attendance registers, provider records and completion evidence. Learning / Security
Total personnel Total security personnel used as the denominator. Reconciled internal and third-party personnel rosters. Security / Procurement
Percentage trained Trained personnel divided by the total calculation population. Calculation workbook and review evidence. Sustainability Reporting
Third-party training requirement Whether training requirements apply to third-party security providers. Contracts, procurement requirements, policies and provider instructions. Procurement / Security / Legal
Third-party inclusion in calculation Whether third-party employees are included in the percentage. Calculation methodology and reconciliation. Sustainability Reporting
Methodology and exceptions Reporting basis, starters, leavers, missing records and reasons for omission. Methodology note and exception log. Sustainability Reporting
+ Show GRI 410-1 sub-elements (LRA working checklist)

How to prepare it

Map internal roles to the GRI definition of security personnel.
Compile rosters for internal and third-party security personnel.
Define the reporting-period or reporting-date basis.
Identify the qualifying human rights policy or specific security procedure.
Verify that the training covers its application to security.
Obtain individual-level training evidence.
Remove duplicate personnel and repeated course attendances.
Calculate the trained numerator.
Calculate the total security-personnel denominator.
Prepare the percentage.
State whether training requirements apply to third-party security providers.
State whether third-party personnel are included in the calculation.
Reconcile the final figure to source records.
Apply a reason for omission where required information cannot be reported.
Verify the disclosure against GRI 410-1(a)–(b) and Recommendations 2.1.1–2.1.2.

Request the data

Request the disclosure evidence

Translate the disclosure into an internal business question — then adapt it to your organisation's own language.

Please provide the GRI 410-1 data for [reporting period]. Include: each security role included and its relationship to the GRI definition; the number of security personnel employed by the organization; the number supplied by third-party organizations; the total security-personnel population; the number who received qualifying formal training; the resulting percentage; the human rights policy or specific procedure covered; evidence that the training addressed its application to security; whether training requirements apply to third-party security providers; whether third-party personnel are included in the percentage; and any missing records or exclusions.

Use the organisation's own role and document names, but preserve the defined GRI terms and the scope described above.

Better request

Please provide the GRI 410-1 data for [reporting period]. Include: each security role included and its relationship to the GRI definition; the number of security personnel employed by the organization; the number supplied by third-party organizations; the total security-personnel population; the number who received qualifying formal training; the resulting percentage; the human rights policy or specific procedure covered; evidence that the training addressed its application to security; whether training requirements apply to third-party security providers; whether third-party personnel are included in the percentage; and any missing records or exclusions.

Draft your disclosure

Notes that turn data into a disclosure

LRA training templates — adapt them to your organisation, and check the official source before sign-off.

Method note

Security personnel include individuals performing guarding, crowd-control, loss-prevention or escort duties. The percentage is calculated as the number who received qualifying formal training divided by the total security-personnel population. [Third-party personnel are / are not] included in the calculation.

Context note

Keep mandatory GRI Requirements, GRI recommendations and additional LRA preparation controls clearly distinguished. Apply a GRI 1 reason for omission where required information cannot be reported.

Download Centre

Preparation tools & forms

Professional preparation tools for GRI 410-1 — free with an LRA Community membership. Register once (it's free) and every download unlocks, together with the Disclosure Library, templates and the LRA AI Assistant.

Free · Community members

Assurance readiness

For each claim, check the evidence

Claim Risk Evidence to check
We identified security personnel using the GRI definition.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Cybersecurity and general information-security employees were not included solely because their titles contain the word “security”.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The personnel population includes organizational employees and identified third-party security personnel.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We documented whether third-party personnel are included in the percentage calculation.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The denominator consists of individual security personnel rather than providers, contracts or training events.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The numerator includes only individuals who received qualifying formal training.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Repeat training attendances were not double counted.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The training covered the organization’s human rights policy or specific procedures.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The training addressed their application to security.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Generic EHS, cybersecurity, POSH or Code of Conduct training was not counted without confirming that it met the GRI content test.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Online and classroom training were treated consistently where both met the content and evidence criteria.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The numerator and denominator use the same reporting basis.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Starters, leavers and transfers were treated consistently.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We stated whether training requirements apply to third-party organizations providing security personnel.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
We did not confuse applicability of training requirements with actual completion by all third-party personnel.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
The published percentage can be recalculated from the source records.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Underlying counts are retained even where they are not published.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.
Missing information is addressed transparently and through an applicable reason for omission where necessary.The published response does not support this human-reviewed assurance check.Trace the statement to current approved records and the official IFRS source.

Evidence pack to prepare

Common reporting gaps

The percentage is missing.
Only the number trained is reported.
The denominator is unclear.
The percentage covers only direct employees without explaining third-party treatment.
The report states that contractors are trained but does not answer whether training requirements apply to their organizations.
The report answers the third-party yes/no requirement but does not provide the percentage.
Third-party organizations are counted instead of individual personnel.
Cybersecurity staff are included as security personnel.
Reception or front-of-house personnel are included without meeting the security-personnel definition.
Loss-prevention or escort personnel are omitted despite meeting the definition.
Generic human rights training is counted without application to security.
EHS, POSH, cybersecurity or Code of Conduct training is treated automatically as qualifying training.
The report states that training was offered but not how many personnel received it.
Personnel scheduled for future training are counted as trained.
Training events or hours are counted instead of individuals.
Repeat course attendances cause double counting.
The numerator and denominator use different dates or populations.
Separate internal and contractor percentages are presented without a clear overall calculation basis.
A provider’s general certification is used without personnel-level evidence.
The disclosure states that training requirements apply to contractors but provides no contractual or policy evidence.
The published percentage cannot be reproduced from the underlying records.

Examples

Illustrative examples

Synthetic, written by LRA — not from a company report, not text from any standard.

Illustrative example 1

Illustrative synthetic example — Utilities
The Group employed 200 security personnel directly and used 24 personnel supplied by three third-party security providers.
Of the total 224 security personnel, 208 received formal training in the Group’s Human Rights Policy and its application to access control, searches, use of force and incident response.
The percentage trained was therefore 92.9%.
The training requirements also applied to all three third-party security providers, and their personnel were included in the calculation.
Food manufacturing

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Illustrative example 2

Illustrative synthetic example — Food manufacturing
The organization had 60 directly employed security personnel and 20 contracted security personnel.
Fifty-seven direct employees and 18 contracted personnel received qualifying training, resulting in 75 trained personnel out of a total population of 80.
The percentage trained was 93.8%.
Training requirements applied to the contracted security provider, and its personnel were included in the percentage.

Synthetic LRA illustration. Replace every figure and fact with the reporting organisation's evidence.

Company reports

How companies report GRI 410-1 in practice

Examples of full and partial reporting practice. These are evidence-led reviews, not exact disclosure templates to copy.

Real published reports
Companhia Paranaense de Energia - COPEL
Electric Utilities / IPP / Energy Traders · Brazil · 2024
Open report →

Firstsource Solutions Limited provides substantive information relevant to GRI 410-1 in its ESG Report FY 2024–25.

The report states that:

all security personnel are employed through third-party vendors;

89.27% of its security workforce received training; and

the training covered environmental health and safety, prevention of sexual harassment and the Code of Conduct.

This means the current card is incorrect in describing the reported percentage as a generic security topic value and then discussing cybersecurity training and cybersecurity effectiveness.

The revised assessment should:

use the human-rights and security-personnel disclosure on page 132 as the substantive evidence;

recognise the reported 89.27% value;

recognise that the security population consists of third-party personnel;

remove references to cybersecurity threats, privacy training and cybersecurity performance;

assess whether the reported course content sufficiently demonstrates training in the organization’s human rights policies or procedures and their application to security; and

assess whether the denominator represents the complete third-party security-personnel population.

Classify the report as substantial but potentially partial practice if application of the training content to security is not made sufficiently explicit.

The official Firstsource ESG page links the FY 2024–25 report, and the report states that 89.27% of its security workforce received training.

Firstsource Solutions Limited
Professional Services · India · 2025
Open report →

Sumitomo Forestry’s current card incorrectly claims that page 536 contains a specific percentage of security personnel trained in human rights policies or procedures.

Page 536 belongs to the report’s GRI Content Index. The GRI 410-1 row provides broad ISO 26000 references but does not provide a substantive percentage or a clear answer on third-party security training requirements.

The card should:

remove the claim that a specific percentage is disclosed;

remove fire-prevention management procedures because they do not evidence GRI 410-1;

remove personal-information-management discussion because it is unrelated;

distinguish content-index mapping from substantive disclosure;

identify whether any separate substantive section provides the required percentage; and

identify whether training requirements apply to third-party security providers.

Unless additional substantive evidence is found, classify the report as not substantively reported or index reference without the required datapoints.

Sumitomo Forestry’s public GRI index maps GRI 410-1 to broad human-rights sections, while the PDF page cited by the current card is itself part of the content index rather than a percentage disclosure.

Sumitomo Forestry Co., Ltd.
Home Building · Japan · 2025
Open report →

COPEL’s current card does not provide sufficient evidence that GRI 410-1(a) is reported.

The reference to 434 whistleblowing reports on page 97 is unrelated to the percentage of security personnel trained in human rights policies or procedures.

The reported statement concerning communication to contracted companies may be relevant to whether requirements or information are extended to contractors, but it does not establish:

the percentage of security personnel trained;

the numerator and denominator;

whether the training addressed application to security; or

whether third-party personnel were included in the calculation.

The card should:

remove the whistleblowing information;

identify the substantive training disclosure rather than relying on an index reference;

assess GRI 410-1(a) and 410-1(b) separately; and

classify the report as partial or requiring substantive reassessment unless a qualifying percentage is located.

The current card relies partly on whistleblowing information and acknowledges that no clear percentage is presented.

Compare side by side →

✓ LRA AI Assistant · Human-in-the-loop
Dr Ross Kurinko

Ask the Study Studio AI Assistant about this disclosure

Get practical answers for your reporting context. Your first two answers are free — join LRA Community for free to continue without a limit.

Try How do I prepare GRI 410-1? What data do I need to collect? Where can I see a real-report example? What mistakes should I avoid?
2 free answers

Framework references

Relevant GRI requirements and related disclosures

Available framework references and nearby disclosures relevant to preparing this requirement.

GRI

GRI 410-1

within GRI 410: Security Practices

Open official source →

Related & explore

More in GRI 410 → Browse full catalogue → Disclosure Library home → Search all disclosures →

Go deeper · GRI 410-1

Learn to prepare this disclosure end-to-end

This guide covers the trained-security-personnel percentage, the application of training requirements to third-party security providers and the recommended clarification on whether third-party personnel are included in the calculation.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

Explore GRI training (ESRS bundle) →
How this library is built 312 published reports indexed 63,171 pages with page-level citations 272 practitioner-built Disclosure Cards
/en/knowledge-hub/disclosure-cards/gri-410-1/