ISO Management Systems

Working management systems for ISO 9001, 14001, 45001 and 55001 — implemented, integrated, and audit-ready. Full reference documentation below.

The standards we implement

Quality, environmental, occupational health & safety, and asset management — the four ISO standards most likely to land on a procurement RFP or insurance renewal in our sectors.

ISO 9001:2015

Quality Management System

The international standard for quality management systems. ISO 9001 is the most recognised certification globally and is the baseline customer audits and procurement processes ask for. It is structured around process control, customer focus, risk-based thinking and continual improvement.

Key Components:

  • Context of the Organization
  • Leadership and Commitment
  • Planning and Risk Management
  • Support and Resources
  • Operational Planning and Control
  • Performance Evaluation
  • Continuous Improvement

Benefits

Enhanced Customer Satisfaction

Consistently meet customer requirements and expectations

Process Optimization

Streamlined operations and reduced waste

Risk Management

Proactive identification and mitigation of risks

Access ISO 9001 Documentation

ISO 55001:2014

Asset Management System

The framework for managing physical assets across their lifecycle — acquisition, operation, maintenance, renewal, disposal — against the organisation's strategic objectives. Particularly relevant for capital-intensive operations where unplanned downtime, deferred maintenance backlogs, and asset replacement timing carry real money.

Key Components:

  • Organizational Context for Assets
  • Asset Management Leadership
  • Strategic Asset Planning
  • Asset Support Systems
  • Asset Operations Management
  • Performance Evaluation
  • Asset System Improvement

Benefits

Improved Asset Performance

Maximize value from physical assets

Cost Optimization

Balance costs, risks, and performance effectively

Strategic Decision Making

Data-driven asset investment decisions

Access ISO 55001 Documentation

ISO 14001:2015

Environmental Management System

The framework for managing the environmental footprint of an operation — emissions, effluent, waste, energy, water, land use — against legal obligations and organisational targets. Particularly relevant where regulators, lenders or customers expect documented environmental performance, or where an incident would carry meaningful licence-to-operate risk.

Key Components:

  • Environmental Context & Aspects
  • Environmental Leadership
  • Environmental Planning & Objectives
  • Support & Competence
  • Operational Controls
  • Performance Monitoring
  • Continual Improvement

Benefits

Environmental Protection

Reduce environmental impact and carbon footprint

Regulatory Compliance

Meet legal and regulatory requirements

Cost Savings

Reduce waste and improve resource efficiency

Access ISO 14001 Documentation

ISO 45001:2018

Occupational Health & Safety System

The framework for occupational health and safety: hazard identification, risk control, worker participation, incident response and continual improvement. Built around the realities of shift-based, regulated, capital-intensive operations — mining, manufacturing, construction, processing — where a section 54 stoppage or a fatality has both human and commercial consequences.

Key Components:

  • OH&S Context & Hazards
  • Worker Participation & Leadership
  • Risk Assessment & Planning
  • Competence & Training
  • Operational Safety Controls
  • Incident Investigation
  • Safety Performance Monitoring

Benefits

Improved Safety Culture

Reduce workplace incidents and injuries

Legal Compliance

Meet OH&S legal obligations

Employee Morale

Enhanced worker engagement and productivity

Access ISO 45001 Documentation

Essential Tools for Integrated ISO Management

Core tools required to effectively manage an integrated management system

An effective integrated management system (IMS) requires more than just documentation — it demands a suite of interconnected tools that drive compliance, performance, and continual improvement across ISO 9001, ISO 14001, ISO 45001, and ISO 55001. Each tool below is presented with its inputs, processes, and outputs.

1

Risk Management

Aligned with ISO 31000 + ISO 55001 clause 6 + ISO 9001/14001/45001 risk requirements

Systematically identify, analyse, evaluate, and treat risks across quality, environmental, safety, and asset management domains. Risk management underpins all ISO management system standards, ensuring that threats and opportunities are addressed proactively through structured assessment and integrated into strategic and operational decision-making.

Inputs
  • Context & interested parties (4.1 + 4.2)
  • Organizational objectives & SAMP/AMP
  • Asset register & criticality ranking
  • Historical failure / incident data
  • Legal & regulatory obligations register
  • Stakeholder requirements & expectations
  • Asset performance & condition data
  • Previous risk assessments & treatment plans
Processes
  • Risk identification (brainstorming, checklists, HAZOP, bow-tie, what-if)
  • Risk analysis (likelihood × consequence)
  • Risk evaluation (against criteria / appetite)
  • Risk treatment planning (avoid, mitigate, transfer, accept)
  • Integration into decision-making (planning, budgeting, maintenance strategy)
  • Monitoring & review of risks and controls
  • Management of change risk assessment
Outputs
  • Risk register / risk profile
  • Risk treatment plans / action registers
  • Updated asset management plans (AMP) & SAMP
  • Risk-based decision records (e.g., capex justification, maintenance prioritization)
  • Residual risk statements
  • Risk performance indicators & trends
  • Management review inputs (risk overview)
2

Document Management

Aligned with ISO 9001/14001/45001/55001 clause 7.5 – Control of documented information

Control the creation, review, approval, distribution, and retention of all documented information required by the integrated management system. Effective document management ensures that the right version of the right document is available to the right people at the right time, providing a reliable audit trail and supporting consistent, compliant operations.

Inputs
  • New or revised documents (procedures, work instructions, SAMP, AMP, registers)
  • Standards & legal requirements
  • Process changes & improvement proposals
  • Audit / nonconformity findings
  • Management review decisions
  • Templates & forms
  • External documents (supplier specs, regulations, contracts)
Processes
  • Document creation / drafting
  • Review & approval workflow (authority levels)
  • Version control & revision history
  • Classification (controlled / uncontrolled, confidential)
  • Distribution & access control (read/write permissions)
  • Periodic review & obsolescence
  • Legibility, identification, retrievability
  • Control of records (retention, disposal, protection)
Outputs
  • Approved, current version of documents
  • Master document list / register
  • Obsolete document archive (with reason & date)
  • Document change history / audit trail
  • Training acknowledgment records (for new/revised docs)
  • Evidence of control during audits (distribution lists, access logs)
3

RCM / FMEA

Reliability Centred Maintenance + Failure Modes & Effects Analysis – strategy development, ISO 55001 alignment

Determine the most technically appropriate and cost-effective maintenance strategy for each physical asset by analysing functions, failure modes, effects, and consequences. RCM and FMEA provide the analytical framework to move from reactive, time-based maintenance to optimised, risk-informed strategies that maximise asset reliability while controlling lifecycle costs.

Inputs
  • Asset hierarchy & register
  • Functional requirements & performance standards
  • Operating context & duty cycle
  • Failure history & maintenance records
  • Failure consequences (safety, environmental, production, cost)
  • Cost data (maintenance, downtime, replacement)
  • Condition monitoring data & trends
  • Criticality ranking / risk profile
Processes
  • Define functions & functional failures
  • Identify failure modes & mechanisms
  • Determine failure effects & consequences
  • Classify consequences (hidden, safety, environmental, operational, economic)
  • Select task types (time-based, condition-based, failure-finding, redesign, run-to-failure)
  • Evaluate task effectiveness & cost
  • Determine task frequency & packaging
  • Document justification & decision rationale
Outputs
  • RCM / FMEA analysis report per asset / system
  • Preventive & predictive maintenance tasks & frequencies
  • One-time change recommendations (redesign, procedure change)
  • Run-to-failure justification (where acceptable)
  • Updated maintenance strategies / task lists in CMMS/EAM
  • Task comparison matrix (before vs after RCM)
  • Cost-benefit justification for strategy changes
4

Root Cause Analysis / CAPA

RCA + Corrective & Preventive Action – ISO 9001/14001/45001/55001 clause 10.2 + continual improvement

Investigate nonconformities, incidents, and failures to identify their true underlying causes, then implement corrective actions to eliminate recurrence and preventive actions to address systemic weaknesses. RCA/CAPA is the engine of continual improvement across the integrated management system, transforming problems into lasting organisational learning.

Inputs
  • Nonconformities (product, process, audit)
  • Incidents, accidents, near-misses
  • Customer / stakeholder complaints
  • Asset failures / breakdowns
  • Condition monitoring alerts / anomalies
  • Audit findings & management review outputs
  • Trend analysis (KPI deterioration)
Processes
  • Immediate containment / correction
  • Problem definition & data collection
  • Root cause analysis (5-Why, Ishikawa, fault tree, Pareto)
  • Cause validation (evidence-based)
  • Corrective action identification & selection
  • Preventive action development (systemic fixes)
  • Action plan with responsibility, timeline, resources
  • Effectiveness review & closure
Outputs
  • RCA report (problem statement, causes, evidence)
  • CAPA register / action plan
  • Implemented corrective & preventive actions
  • Updated procedures, training, designs, risk registers
  • Effectiveness verification records & evidence
  • Lessons learned / knowledge base entries
  • Reduced recurrence rate (KPI trend)
5

Change Management

Aligned with ISO 55001 clause 8.2 + ISO 9001/14001/45001 change control requirements

Ensure that all planned and unplanned changes to assets, processes, organisational structures, or the management system itself are assessed for risk, approved by competent authority, implemented in a controlled manner, and verified for effectiveness. Change management prevents unintended consequences and maintains system integrity during periods of transition.

Inputs
  • Proposed change request (asset, process, organization, supplier, software, etc.)
  • Reason for change (improvement, obsolescence, regulation, incident)
  • Description of intended change
  • Affected assets / processes / documents / people
  • Risk profile of current situation
Processes
  • Change request submission & logging
  • Impact & risk assessment (technical, safety, environmental, financial, compliance)
  • Review by competent persons / change committee
  • Approval / rejection decision (authority levels)
  • Planning of implementation (actions, resources, timeline, communication)
  • Execution & verification
  • Post-change review & effectiveness check
  • Update of related documents, risk register, maintenance plans
Outputs
  • Approved change request record
  • Change impact & risk assessment report
  • Implementation plan & completion evidence
  • Updated asset register, maintenance strategy, documents
  • Communication records (to affected parties)
  • Post-implementation review / lessons learned
  • Evidence for audit trail (who approved, when, why)
6

Training Management / Competence & Awareness

Aligned with ISO 9001/14001/45001/55001 clause 7.2 & 7.3 – Competence and Awareness

Ensure that all persons performing work that affects quality, environmental, safety, and asset management outcomes are competent on the basis of appropriate education, training, skills, and experience. This tool also drives awareness of the management system policies, objectives, and the significance of individual contributions — building a workforce capable of sustaining and improving the integrated management system.

Inputs
  • Organizational roles, responsibilities and authorities (RACI / job descriptions)
  • Competence requirements per role / task / asset / process
  • Legal / regulatory training obligations (e.g. safety inductions, high-risk work licenses, environmental awareness)
  • Risk assessment outputs (tasks requiring specific competencies)
  • New / changed processes, equipment, substances, procedures
  • Incident / near-miss / audit findings indicating competence gaps
  • Performance reviews, skill matrix assessments
  • Employee onboarding / role changes
  • Supplier / contractor competence requirements
Processes
  • Define competence criteria (knowledge, skills, experience, qualifications, behaviours)
  • Assess current competence (gap analysis, skill matrix, certifications check)
  • Identify training / awareness needs
  • Develop / select training methods (classroom, e-learning, on-the-job, mentoring, simulation)
  • Deliver training & awareness programs
  • Evaluate training effectiveness (tests, observations, performance monitoring, feedback)
  • Maintain training records & certification expiry tracking
  • Re-assess competence after training, incidents, or significant time away
  • Manage contractor / third-party competence verification
  • Communicate awareness topics (policies, risks, objectives, incident lessons)
Outputs
  • Competence / training matrix or register (per role / person / asset type)
  • Training needs analysis / annual training plan
  • Training attendance / completion records
  • Training evaluation records (pre/post tests, practical assessments, feedback forms)
  • Certificates, licenses, qualifications records (with expiry dates)
  • Evidence of effectiveness review (e.g. reduced incidents, improved KPIs post-training)
  • Awareness communication records (toolbox talks, inductions, posters, emails)
  • Gap closure actions and follow-up records
  • Contractor / visitor competence verification records

Why teams certify

Procurement & insurance prerequisite

Tier-1 customer audits, B-BBEE supplier-development frameworks and insurance underwriting increasingly list ISO certification as a hard requirement.

A working management cadence

Management review, internal audit, corrective action and continual improvement — cycles that, once embedded, drive performance independently of the certification.

Documented risk posture

Risk-based thinking is built into the standard. The output is a defensible record — useful with regulators, with insurers, and after an incident.

Less rework, fewer surprises

Standardised processes reduce the rework, escapes and operator-by-operator variation that drive scrap, complaints and unplanned shutdowns.

Planning a certification, recertification or integration?

Tell us where you are — first-time certification, integrating two standards, recovering from a non-conformance, or moving from compliance to genuine operational value — and we'll talk through the path.

Request an ISO Gap Analysis