ISO management systems

Built to keep working after I have gone.

A management system that has been designed properly and brought into use should pass its first audit. The harder question is whether anybody is still running it when the auditor comes back. I build systems your own people will choose to engage with, and I will tell you plainly when a standard is the wrong answer to the problem you actually have.

01 / What I see

Where implementations go wrong.

Four patterns I have watched play out while building and auditing management systems. My own view, not research, and frequent enough that I design against them from the first conversation.

01

The system belongs to the consultant

A suite of documents arrives, gets signed off, and goes into a folder. Ask anyone inside the organisation why a given control is there and you will get a shrug. An auditor establishes that within the first ten minutes of a conversation.

02

The scope was drawn to make the audit easy

A narrow scope passes cleanly. Then a client, a tender or an insurer asks a question the certificate does not cover, and the certificate stops being worth what it cost.

03

Internal audit becomes a filing exercise

Audits get run to fill a schedule. The findings are cosmetic because a real finding would create work. The system stops telling anybody anything they did not already know.

04

Actions get logged and then roll on

Items from audits, reviews and incidents go on a register with an owner and a date, and stay there. At the surveillance visit the same items show up again with a later date against them.

02 / The work

Four stages, starting in the same place every time.

The gap analysis comes first whatever your position. An organisation starting from nothing and an organisation whose system has drifted both need the same first answer, which is what the standard asks of them and how far off they are. What changes after that is how much of the work below is left to do.

01

Scope and gap analysis

What the standard asks of an organisation like yours, what you already do, and the distance between the two. Scored by clause, so the gap comes out as a list of jobs with my reasoning against each one. Everything that follows is built on this, and the rest of the work cannot be quoted honestly until it is done.

A scope drawn around what your clients and regulators will ask about
Your context, interested parties, and the obligations that apply
A score by clause and by section, with the work that closes each gap
An honest view on whether certification is worth it for you at all
02

Building the system

Built around how the business runs, in your own terms, with named owners. Where something you already do satisfies the standard, it stays and we write down why.

Policy, objectives, and the risks and opportunities behind them
Document and record control that people will actually follow
Supplier and purchasing controls proportionate to what you buy
The operational controls the standard requires, written as procedures your people recognise
03

Putting it into use

A certification body wants evidence that the system has been running, and that it found something. This is the stage organisations underestimate, and the one that decides how the audit goes.

An internal audit programme that produces real findings
Management review your directors can run without me in the room
Gaps closed out, evidenced, and signed off
Your people walked through what they will be asked and why
04

Certification

Certification is awarded by a certification body, and I am not one. My job is getting you ready for them, being there on the day, and handling what comes out of it.

Choosing a certification body and understanding what they will quote you
Stage 1, where they read the system and tell you what is missing
Stage 2, where they audit what you actually do
Findings answered, and the surveillance cycle set up so year two is quiet
03 / Ways to work with me

How the work is bought.

Certification is a project with an end date. Keeping the system alive afterwards runs for as long as you hold the certificate, which is why the two are priced and structured differently.

Implementation

Through to certification

The gap analysis is quoted and done first. Once we both know the size of the job, the rest is scoped and quoted as a package against an agreed certification date, with no day rates running in the background.

Gap analysis, build, internal audit and management review
Alongside you at Stage 1 and Stage 2
Handover, so your people own it afterwards
Assessment

Gap analysis or internal audit

Booked on its own. Useful before you commit to certification, and useful afterwards when the internal audit programme needs an auditor independent of the people who built the system.

A score by clause, with the work that closes each gap
Internal audits run to your programme, with findings that mean something
A written report you can take to your board or your certification body
Ongoing

Fractional director support

A certificate lasts three years and asks for a surveillance visit each year. For a few organisations I run that cycle myself, a couple of days a month, alongside their wider risk, quality and compliance picture.

The competence of a director, at a fraction of the cost
Audit programme, management review and surveillance all run to time
A limited number of these at any time, by design
04 / The standards

Four standards, built the same way.

All four are built on the same structure, so an organisation holding one is a long way towards the next. Where you hold or want more than one, they are built as a single system with one set of policies, one audit programme and one management review. Separate suites end up contradicting each other.

ISO 9001
Quality management. The one I am asked about most often, and the one that does most to tidy up how work actually moves through an organisation.
ISO 27001
Information security. The heaviest of the four, and the one where a narrow scope causes the most trouble later. Includes the statement of applicability and the control set behind it.
ISO 45001
Occupational health and safety. Sits directly on top of what UK law already asks of you, so much of the work is proving and organising what a competent organisation does anyway.
ISO 22301
Business continuity. Asked for by clients, insurers and funders who want to know what happens when you are disrupted. It sits closest to the work on the business continuity page, which sets out the analysis, the plan and the exercising behind it.
05 / Our own tooling

You can see how ready you are.

Engagements are supported by our own gap-analysis and readiness tooling, so you can see maturity by clause, by section and over time, and know exactly what is left before an audit.

It also means a board paper takes minutes, and that the answer to "are we ready" is a number with working behind it.

06 / Who it suits
Organisations losing work, or expecting to, because they hold no certificate
Organisations certified some years ago, where the system has quietly stopped being used
Organisations holding one standard and being asked for a second
Organisations with a surveillance visit coming and findings still open from the last one
Organisations that have been quoted for a template suite and want to know what the difference is

Tell me where you are starting from.

All conversations are treated as strictly confidential. If a standard is the wrong answer for you, I would rather say that in the first conversation than after you have paid for it.

Call 0333 335 6730 Email Ross
© 2026 Ross Macdonald Consultancy Ltd · Company No. SC848204
Home Strategic planning Business continuity Safety and security Privacy notice