Quality management gap assessment
A structured review of your current system against ISO 9001 and against how your work actually runs. A facilitated workshop and a written findings report with a prioritised action plan.
Quality, environment, health and safety, and information security. Designed around how your business actually works, and built as one system rather than four.
They are written so an auditor visiting for two days can trace a requirement to a document and tick it off. That constraint is real and has to be met. It is also the least useful thing a management system does.
A system built for the audit passes the audit, then sits in a folder people open twice a year while the work carries on being done the way it always was.
Underneath the clauses, a management system answers one question: how do we do this here, so it comes out the same whoever is doing it. That is how you stop depending on the three people who remember everything.
Most of our work starts with quality, because that is usually where the pain is and because ISO 9001 gives a well understood structure to build against.
It rarely stays there. The machinery underneath a quality system, document control, internal audit, management review, corrective action and competence records, is the same machinery an environmental, health and safety or information security system needs. Build them separately and you build that machinery four times and maintain four versions of it.
So we build one integrated system covering whichever of these you need:
Information security brings its own additions, a risk assessment against your information assets and a statement of applicability, but it stands on the same foundations as the rest. Adding a standard costs much less than the first build.
From the work, not the standard. We map how delivery actually runs, workarounds included. Each workaround marks a place where the official way was slower than the real one.
As small as it can be. Every extra document is something somebody has to keep current alongside their real job.
Where the work happens. In your existing systems, a click from where people already are.
Through first contact. The system runs on live work while we are still there, which is when the gap between design and reality shows.
Then it is yours, with a named owner on every process and your people already using it.
Built this way the system will get you through certification, and the audit inspects something real rather than a performance. If you do not need a certificate most of the value is still there: plenty of our work is with businesses that want consistency, less rework and defensible records and have no interest in one.
A structured review of your current system against ISO 9001 and against how your work actually runs. A facilitated workshop and a written findings report with a prioritised action plan.
We get you ready and support you through the audit. The certificate comes from an accredited body that must be independent of whoever built the system. That independence is what makes it worth anything.
Systems fail for a short list of repeatable reasons: written for an auditor rather than the work, built by someone who then left, kept somewhere nobody goes, or owned by nobody. We design against all four.
Four to eight months to a first certifiable system for a mid-sized business. The variable is rarely our drafting speed. It is how fast your team reviews what we produce.
Yes, aligned with ISO 31000, and connected to the management system so risk decisions are recorded where the work happens rather than in a register nobody opens. One distinction worth knowing: ISO 31000 is guidance rather than a certifiable standard, so a framework aligns with it but is not certified against it the way a quality system is against ISO 9001.
Common, and reasonable. Document Management Systems, an internal audit programme or a Technical Review Framework can each be built alone and connected later. The gap assessment tells you which is worth doing first.