ISO Management Systems
Working management systems for ISO 9001, 14001, 45001 and 55001 — implemented, integrated, and audit-ready. Full reference documentation below.
The standards we implement
Quality, environmental, occupational health & safety, and asset management — the four ISO standards most likely to land on a procurement RFP or insurance renewal in our sectors.
ISO 9001:2015
Quality Management System
The international standard for quality management systems. ISO 9001 is the most recognised certification globally and is the baseline customer audits and procurement processes ask for. It is structured around process control, customer focus, risk-based thinking and continual improvement.
Key Components:
- Context of the Organization
- Leadership and Commitment
- Planning and Risk Management
- Support and Resources
- Operational Planning and Control
- Performance Evaluation
- Continuous Improvement
Benefits
Consistently meet customer requirements and expectations
Streamlined operations and reduced waste
Proactive identification and mitigation of risks
ISO 55001:2014
Asset Management System
The framework for managing physical assets across their lifecycle — acquisition, operation, maintenance, renewal, disposal — against the organisation's strategic objectives. Particularly relevant for capital-intensive operations where unplanned downtime, deferred maintenance backlogs, and asset replacement timing carry real money.
Key Components:
- Organizational Context for Assets
- Asset Management Leadership
- Strategic Asset Planning
- Asset Support Systems
- Asset Operations Management
- Performance Evaluation
- Asset System Improvement
Benefits
Maximize value from physical assets
Balance costs, risks, and performance effectively
Data-driven asset investment decisions
ISO 14001:2015
Environmental Management System
The framework for managing the environmental footprint of an operation — emissions, effluent, waste, energy, water, land use — against legal obligations and organisational targets. Particularly relevant where regulators, lenders or customers expect documented environmental performance, or where an incident would carry meaningful licence-to-operate risk.
Key Components:
- Environmental Context & Aspects
- Environmental Leadership
- Environmental Planning & Objectives
- Support & Competence
- Operational Controls
- Performance Monitoring
- Continual Improvement
Benefits
Reduce environmental impact and carbon footprint
Meet legal and regulatory requirements
Reduce waste and improve resource efficiency
ISO 45001:2018
Occupational Health & Safety System
The framework for occupational health and safety: hazard identification, risk control, worker participation, incident response and continual improvement. Built around the realities of shift-based, regulated, capital-intensive operations — mining, manufacturing, construction, processing — where a section 54 stoppage or a fatality has both human and commercial consequences.
Key Components:
- OH&S Context & Hazards
- Worker Participation & Leadership
- Risk Assessment & Planning
- Competence & Training
- Operational Safety Controls
- Incident Investigation
- Safety Performance Monitoring
Benefits
Reduce workplace incidents and injuries
Meet OH&S legal obligations
Enhanced worker engagement and productivity
Essential Tools for Integrated ISO Management
Core tools required to effectively manage an integrated management system
An effective integrated management system (IMS) requires more than just documentation — it demands a suite of interconnected tools that drive compliance, performance, and continual improvement across ISO 9001, ISO 14001, ISO 45001, and ISO 55001. Each tool below is presented with its inputs, processes, and outputs.
Risk Management
Aligned with ISO 31000 + ISO 55001 clause 6 + ISO 9001/14001/45001 risk requirements
Systematically identify, analyse, evaluate, and treat risks across quality, environmental, safety, and asset management domains. Risk management underpins all ISO management system standards, ensuring that threats and opportunities are addressed proactively through structured assessment and integrated into strategic and operational decision-making.
Inputs
- Context & interested parties (4.1 + 4.2)
- Organizational objectives & SAMP/AMP
- Asset register & criticality ranking
- Historical failure / incident data
- Legal & regulatory obligations register
- Stakeholder requirements & expectations
- Asset performance & condition data
- Previous risk assessments & treatment plans
Processes
- Risk identification (brainstorming, checklists, HAZOP, bow-tie, what-if)
- Risk analysis (likelihood × consequence)
- Risk evaluation (against criteria / appetite)
- Risk treatment planning (avoid, mitigate, transfer, accept)
- Integration into decision-making (planning, budgeting, maintenance strategy)
- Monitoring & review of risks and controls
- Management of change risk assessment
Outputs
- Risk register / risk profile
- Risk treatment plans / action registers
- Updated asset management plans (AMP) & SAMP
- Risk-based decision records (e.g., capex justification, maintenance prioritization)
- Residual risk statements
- Risk performance indicators & trends
- Management review inputs (risk overview)
Document Management
Aligned with ISO 9001/14001/45001/55001 clause 7.5 – Control of documented information
Control the creation, review, approval, distribution, and retention of all documented information required by the integrated management system. Effective document management ensures that the right version of the right document is available to the right people at the right time, providing a reliable audit trail and supporting consistent, compliant operations.
Inputs
- New or revised documents (procedures, work instructions, SAMP, AMP, registers)
- Standards & legal requirements
- Process changes & improvement proposals
- Audit / nonconformity findings
- Management review decisions
- Templates & forms
- External documents (supplier specs, regulations, contracts)
Processes
- Document creation / drafting
- Review & approval workflow (authority levels)
- Version control & revision history
- Classification (controlled / uncontrolled, confidential)
- Distribution & access control (read/write permissions)
- Periodic review & obsolescence
- Legibility, identification, retrievability
- Control of records (retention, disposal, protection)
Outputs
- Approved, current version of documents
- Master document list / register
- Obsolete document archive (with reason & date)
- Document change history / audit trail
- Training acknowledgment records (for new/revised docs)
- Evidence of control during audits (distribution lists, access logs)
RCM / FMEA
Reliability Centred Maintenance + Failure Modes & Effects Analysis – strategy development, ISO 55001 alignment
Determine the most technically appropriate and cost-effective maintenance strategy for each physical asset by analysing functions, failure modes, effects, and consequences. RCM and FMEA provide the analytical framework to move from reactive, time-based maintenance to optimised, risk-informed strategies that maximise asset reliability while controlling lifecycle costs.
Inputs
- Asset hierarchy & register
- Functional requirements & performance standards
- Operating context & duty cycle
- Failure history & maintenance records
- Failure consequences (safety, environmental, production, cost)
- Cost data (maintenance, downtime, replacement)
- Condition monitoring data & trends
- Criticality ranking / risk profile
Processes
- Define functions & functional failures
- Identify failure modes & mechanisms
- Determine failure effects & consequences
- Classify consequences (hidden, safety, environmental, operational, economic)
- Select task types (time-based, condition-based, failure-finding, redesign, run-to-failure)
- Evaluate task effectiveness & cost
- Determine task frequency & packaging
- Document justification & decision rationale
Outputs
- RCM / FMEA analysis report per asset / system
- Preventive & predictive maintenance tasks & frequencies
- One-time change recommendations (redesign, procedure change)
- Run-to-failure justification (where acceptable)
- Updated maintenance strategies / task lists in CMMS/EAM
- Task comparison matrix (before vs after RCM)
- Cost-benefit justification for strategy changes
Root Cause Analysis / CAPA
RCA + Corrective & Preventive Action – ISO 9001/14001/45001/55001 clause 10.2 + continual improvement
Investigate nonconformities, incidents, and failures to identify their true underlying causes, then implement corrective actions to eliminate recurrence and preventive actions to address systemic weaknesses. RCA/CAPA is the engine of continual improvement across the integrated management system, transforming problems into lasting organisational learning.
Inputs
- Nonconformities (product, process, audit)
- Incidents, accidents, near-misses
- Customer / stakeholder complaints
- Asset failures / breakdowns
- Condition monitoring alerts / anomalies
- Audit findings & management review outputs
- Trend analysis (KPI deterioration)
Processes
- Immediate containment / correction
- Problem definition & data collection
- Root cause analysis (5-Why, Ishikawa, fault tree, Pareto)
- Cause validation (evidence-based)
- Corrective action identification & selection
- Preventive action development (systemic fixes)
- Action plan with responsibility, timeline, resources
- Effectiveness review & closure
Outputs
- RCA report (problem statement, causes, evidence)
- CAPA register / action plan
- Implemented corrective & preventive actions
- Updated procedures, training, designs, risk registers
- Effectiveness verification records & evidence
- Lessons learned / knowledge base entries
- Reduced recurrence rate (KPI trend)
Change Management
Aligned with ISO 55001 clause 8.2 + ISO 9001/14001/45001 change control requirements
Ensure that all planned and unplanned changes to assets, processes, organisational structures, or the management system itself are assessed for risk, approved by competent authority, implemented in a controlled manner, and verified for effectiveness. Change management prevents unintended consequences and maintains system integrity during periods of transition.
Inputs
- Proposed change request (asset, process, organization, supplier, software, etc.)
- Reason for change (improvement, obsolescence, regulation, incident)
- Description of intended change
- Affected assets / processes / documents / people
- Risk profile of current situation
Processes
- Change request submission & logging
- Impact & risk assessment (technical, safety, environmental, financial, compliance)
- Review by competent persons / change committee
- Approval / rejection decision (authority levels)
- Planning of implementation (actions, resources, timeline, communication)
- Execution & verification
- Post-change review & effectiveness check
- Update of related documents, risk register, maintenance plans
Outputs
- Approved change request record
- Change impact & risk assessment report
- Implementation plan & completion evidence
- Updated asset register, maintenance strategy, documents
- Communication records (to affected parties)
- Post-implementation review / lessons learned
- Evidence for audit trail (who approved, when, why)
Training Management / Competence & Awareness
Aligned with ISO 9001/14001/45001/55001 clause 7.2 & 7.3 – Competence and Awareness
Ensure that all persons performing work that affects quality, environmental, safety, and asset management outcomes are competent on the basis of appropriate education, training, skills, and experience. This tool also drives awareness of the management system policies, objectives, and the significance of individual contributions — building a workforce capable of sustaining and improving the integrated management system.
Inputs
- Organizational roles, responsibilities and authorities (RACI / job descriptions)
- Competence requirements per role / task / asset / process
- Legal / regulatory training obligations (e.g. safety inductions, high-risk work licenses, environmental awareness)
- Risk assessment outputs (tasks requiring specific competencies)
- New / changed processes, equipment, substances, procedures
- Incident / near-miss / audit findings indicating competence gaps
- Performance reviews, skill matrix assessments
- Employee onboarding / role changes
- Supplier / contractor competence requirements
Processes
- Define competence criteria (knowledge, skills, experience, qualifications, behaviours)
- Assess current competence (gap analysis, skill matrix, certifications check)
- Identify training / awareness needs
- Develop / select training methods (classroom, e-learning, on-the-job, mentoring, simulation)
- Deliver training & awareness programs
- Evaluate training effectiveness (tests, observations, performance monitoring, feedback)
- Maintain training records & certification expiry tracking
- Re-assess competence after training, incidents, or significant time away
- Manage contractor / third-party competence verification
- Communicate awareness topics (policies, risks, objectives, incident lessons)
Outputs
- Competence / training matrix or register (per role / person / asset type)
- Training needs analysis / annual training plan
- Training attendance / completion records
- Training evaluation records (pre/post tests, practical assessments, feedback forms)
- Certificates, licenses, qualifications records (with expiry dates)
- Evidence of effectiveness review (e.g. reduced incidents, improved KPIs post-training)
- Awareness communication records (toolbox talks, inductions, posters, emails)
- Gap closure actions and follow-up records
- Contractor / visitor competence verification records
Why teams certify
Procurement & insurance prerequisite
Tier-1 customer audits, B-BBEE supplier-development frameworks and insurance underwriting increasingly list ISO certification as a hard requirement.
A working management cadence
Management review, internal audit, corrective action and continual improvement — cycles that, once embedded, drive performance independently of the certification.
Documented risk posture
Risk-based thinking is built into the standard. The output is a defensible record — useful with regulators, with insurers, and after an incident.
Less rework, fewer surprises
Standardised processes reduce the rework, escapes and operator-by-operator variation that drive scrap, complaints and unplanned shutdowns.