ISO 9001 – Quality management systems
ISO 9001 is the base standard for quality management and the way into almost every management system. It sets the same requirements for every sector and every size of organisation and deliberately leaves open how a company meets them.
That openness is its strength. It is also the reason why two companies holding the same certificate can run completely different systems: a lean one that helps day to day, and a cumbersome one that is only brought out for the audit.
Who it applies to
- Companies whose customers require a certificate as a supplier criterion – by far the most common trigger
- Businesses that have grown and are finding that responsibilities and processes no longer explain themselves
- Organisations that want to add further standards later: ISO 9001 is the basis on which ISO 14001, ISO 45001 and ISO 50001 build
- As the foundation for sector-specific standards such as ISO 13485 or IATF 16949
Where it usually goes wrong
Far too much gets documented
The most common mistake when a system is first built, and the most expensive one. Anyone reading the standard for the first time writes a procedure for everything, just to be safe. That passes the certification audit, but it takes its revenge for years: every process change drags document maintenance behind it, nobody reads the procedures, and at the next audit it becomes obvious that documented practice and actual practice have drifted apart.
The standard asks for considerably less than most people assume. It requires documented information where it is needed to control the work or to serve as evidence, not for every single step. A system half as thick is usually the better one.
Risks and opportunities as a box-ticking exercise
Clause 6.1 is often worked through as a table: list the risks, rate them, tick them off. What is missing is the follow-through – which action results from it, who implements it, and how anyone will later tell that it worked.
In the audit this shows up immediately, because the risk assessment has nothing to do with the actual day-to-day business. It names abstract topics such as “skills shortage”, while the problems people genuinely talk about on site do not appear at all.
The detour is not worth it: an honest list of five real risks, each with one concrete action, carries further than a complete one with thirty.
How we support you
We start by looking at what is already running. In our experience, a company that has grown over the years already meets a considerable part of the standard. It is simply not documented as evidence. That baseline assessment produces a plan that says what is genuinely missing and what you can spare yourself.
After that: build up or slim down, internal audit, preparation for the certification audit. Details under Building a management system and Internal audits & gap analyses.
Where the evidence trail breaks down across scattered spreadsheets, we build the database that takes it over – the point at which we differ from consultancies that only advise.
Who handles this at our end
Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927
Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806
Michael Bremer – subject matter expert, particularly in laboratory and medical device environments
Three people for the same standard means your support continues through holidays or illness. The team in detail
Related standards
- ISO 14001 – environmental management, very often run as an integrated system
- ISO 45001 – occupational health and safety, same high-level structure
- ISO 13485 – medical devices, builds on ISO 9001
- IATF 16949 – automotive industry, requires ISO 9001
Frequently asked questions
How long does it take to reach certification?
For a company with established but undocumented processes, expect six to twelve months until you are ready for certification. What decides the pace is less our speed than your availability. The processes have to come from the people who live them every day.
What does it cost?
Projects of this kind typically range between 10,000 and 50,000 euros. Where you land within that is set by three factors: the size of the company and the number of sites, the maturity of the existing processes, and the share you take on yourselves. The certification body charges its fees separately.
Which documents do we really need?
Fewer than you think. The mandatory items include the scope, the quality policy, the quality objectives and a number of records on competence, monitoring, internal audits and management review, among others. A quality manual has not been required since the 2015 revision, yet it is still written out of reflex.
How does the certification audit work?
In two stages: first the certification body reviews the documentation and your readiness for audit in what is known as the stage 1 audit, then a few weeks later the actual stage 2 audit takes place on site. After that come annual surveillance audits, and recertification after three years.
We already have a system, it has just become too much work. Does that help?
That is one of our most frequent assignments. Streamlining an existing system is usually faster and cheaper than building a new one, and the effect on day-to-day work is considerably greater.
Do we have to get certified at all?
Only if a customer or an invitation to tender demands it. A management system to ISO 9001 can be run without a certificate if what you care about is order in the business rather than proof to the outside world. We will tell you that honestly in the first conversation.
Let us talk about it
The first conversation is free and without obligation.