Quality Management

A management system your team uses, not one they work around

Quality, environment, health and safety, and information security. Designed around how your business actually works, and built as one system rather than four.

Most management systems are built for the wrong reader

They are written so an auditor visiting for two days can trace a requirement to a document and tick it off. That constraint is real and has to be met. It is also the least useful thing a management system does.

A system built for the audit passes the audit, then sits in a folder people open twice a year while the work carries on being done the way it always was.

Underneath the clauses, a management system answers one question: how do we do this here, so it comes out the same whoever is doing it. That is how you stop depending on the three people who remember everything.

One system, not four

Most of our work starts with quality, because that is usually where the pain is and because ISO 9001 gives a well understood structure to build against.

It rarely stays there. The machinery underneath a quality system, document control, internal audit, management review, corrective action and competence records, is the same machinery an environmental, health and safety or information security system needs. Build them separately and you build that machinery four times and maintain four versions of it.

So we build one integrated system covering whichever of these you need:

  • ISO 9001, quality
  • ISO 14001, environment
  • ISO 45001, health and safety
  • ISO 27001, information security

Information security brings its own additions, a risk assessment against your information assets and a statement of applicability, but it stands on the same foundations as the rest. Adding a standard costs much less than the first build.

How we build one

From the work, not the standard. We map how delivery actually runs, workarounds included. Each workaround marks a place where the official way was slower than the real one.

As small as it can be. Every extra document is something somebody has to keep current alongside their real job.

Where the work happens. In your existing systems, a click from where people already are.

Through first contact. The system runs on live work while we are still there, which is when the gap between design and reality shows.

Then it is yours, with a named owner on every process and your people already using it.

Where certification fits

Built this way the system will get you through certification, and the audit inspects something real rather than a performance. If you do not need a certificate most of the value is still there: plenty of our work is with businesses that want consistency, less rework and defensible records and have no interest in one.

What you end up with

  • Work that comes out consistent regardless of who picked up the job
  • A system people use because following it is faster than working around it
  • Evidence produced as the work happens, rather than reconstructed before an audit
  • One system to maintain instead of several

Also in Quality Management

Where to start

Common questions

Can you get us certified?

We get you ready and support you through the audit. The certificate comes from an accredited body that must be independent of whoever built the system. That independence is what makes it worth anything.

We tried this before and it did not stick. Why would this be different?

Systems fail for a short list of repeatable reasons: written for an auditor rather than the work, built by someone who then left, kept somewhere nobody goes, or owned by nobody. We design against all four.

How long does it take?

Four to eight months to a first certifiable system for a mid-sized business. The variable is rarely our drafting speed. It is how fast your team reviews what we produce.

Do you build risk management frameworks?

Yes, aligned with ISO 31000, and connected to the management system so risk decisions are recorded where the work happens rather than in a register nobody opens. One distinction worth knowing: ISO 31000 is guidance rather than a certifiable standard, so a framework aligns with it but is not certified against it the way a quality system is against ISO 9001.

What if we only need part of this?

Common, and reasonable. Document Management Systems, an internal audit programme or a Technical Review Framework can each be built alone and connected later. The gap assessment tells you which is worth doing first.