Knowledge base
How management system work is actually done: documentation, evidence, internal audit and the practicalities of an audit day.
- September 13, 2026Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards MappingWhat does an automotive vendor cybersecurity assessment cover?Read the article
- September 13, 2026Cybersecurity and Data Protection Requirements for Manufacturing Companies in IndiaA Simple Guide to the DPDP Act, CERT-In Directions, IT Act and Customer Cybersecurity AssessmentsRead the article
- September 12, 2026DPDP Act: Documentation and Compliance RequirementsThis guide explains, in simple language, what organisations need to document under the Digital Personal Data Protection (DPDP) Act) and what an auditor may ask to see as evidence.Read the article
- September 12, 2026GDPR Requirements — Explained in Simple LanguageThis document explains what GDPR requires you to do, clause by clause, and what an auditor or regulator may ask you to show as evidence.Read the article
- September 12, 2026HIPAA: Documentation and Compliance RequirementsThis document explains what HIPAA requires, section by section, and what an auditor may ask you to show as evidence.Read the article
- September 12, 2026ISO 13485:2016: Documentation and Compliance RequirementsA simple, clause-by-clause guide to what ISO 13485:2016 requires you to document and what an auditor may ask to see as evidence.Read the article
- September 12, 2026ISO 14001:2015: Documentation and Compliance RequirementsThis guide explains, clause by clause, what ISO 14001:2015 expects an organisation to have in place and what an auditor may ask to see as evidence.Read the article
- September 12, 2026ISO 14001:2026: Documentation and Compliance RequirementsThis guide explains, clause by clause, what ISO 14001:2026 requires and what evidence an auditor may ask to see. It covers 64 requirements across 7 key areas.Read the article
- September 12, 2026ISO 14064-1:2018 – Requirements in Simple LanguageThis guide explains what ISO 14064-1:2018 requires, clause by clause, and what an auditor may ask you to show as evidence.Read the article
- September 12, 2026ISO 21001:2025: Documentation and Compliance RequirementsThis document explains what ISO 21001:2025 requires, clause by clause, and what an auditor may ask for as evidence.Read the article
- September 12, 2026ISO 22000:2018: Documentation and Compliance RequirementsISO standards help businesses work responsibly, earn trust, and grow successfully in the long term.Read the article
- September 12, 2026ISO 22301:2019: Documentation and Compliance RequirementsISO 22301:2019 explains what an organisation needs to have in place to manage business continuity and prepare for disruptions.Read the article
- September 12, 2026ISO 26000:2010: Requirements for Documentation and ComplianceHere’s a simpler version: A clause-by-clause guide to what ISO 26000:2010 expects you to document, including the evidence an auditor may ask to review. It is written as clear requirements rather than a checklist.Read the article
- September 12, 2026ISO 37001:2025: Documentation and Compliance RequirementsThis guide explains what ISO 37001:2025 requires, clause by clause, and what evidence an auditor may ask for.Read the article
- September 12, 2026ISO 41001:2018: Documentation and Compliance RequirementsISO 41001:2018 documentation requirements, explained clause by clause, including the evidence and records an auditor may ask to review. Written as clear requirements rather than a checklist.Read the article
- September 12, 2026ISO 45001:2018: Documentation and Compliance RequirementsA clause-by-clause guide to everything ISO 45001:2018 requires you to document, including what an auditor may ask to review for each requirement. Written as clear requirements, not as a checklist.Read the article
- September 12, 2026ISO 50001:2018: documentation and compliance requirementsWhat does ISO 50001:2018 require you to document?Read the article
- September 12, 2026ISO 9001:2026: Documentation and Compliance RequirementsA simple, clause-by-clause guide to what ISO 9001:2026 expects an organisation to document and what an auditor may ask to see as evidence.Read the article
- September 12, 2026ISO/IEC 17025:2017 – Documentation and Compliance RequirementsThis guide explains, clause by clause, what a laboratory needs to document and what an auditor or assessor may ask to see as evidence.Read the article
- September 12, 2026ISO/IEC 20000-1:2018: Documentation and Compliance RequirementsThis document explains, clause by clause, what ISO/IEC 20000-1:2018 expects an organisation to have in place and what an auditor may ask to see as evidence.Read the article
- September 12, 2026ISO/IEC 27001:2022: documentation and compliance requirementsEverything ISO/IEC 27001:2022 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkliRead the article
- September 12, 2026ISO/IEC 27701:2025: documentation and compliance requirementsEverything ISO/IEC 27701:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkliRead the article
- September 12, 2026ISO/IEC 42001:2023: documentation and compliance requirementsISO/IEC 42001:2023 documentation requirements explained clause by clause, including the evidence and records an auditor may ask to review. Presented as clear requirements rather than a checklist.Read the article
- September 12, 2026SOC 2: Documentation and Compliance RequirementsThis document explains, in simple language, what SOC 2 requires an organisation to have, what should be documented, and what an auditor may ask for as evidence.Read the article
- August 30, 2026How to Take the Free Readiness Self-AssessmentA simple step-by-step guide to using the MSCi readiness checklistRead the article
- August 30, 2026How your readiness score is calculatedWhat each answer earns, why every checklist adds to exactly 100, why the marks are hidden while you answer, and how the bands decide the advice.Read the article
- August 16, 2026ISO 9001 Documentation: What you Actually NeedA short reference on what ISO 9001 requires you to document, and what it does not.Read the article
- August 16, 2026Major and Minor Nonconformities: Understanding the DifferenceA simple reference explaining how audit findings are classified, what each level means, and what action is required for each finding.Read the article
- August 16, 2026ISO 27001: Required Documented Information – Simple GuideA guide to the key documents required for ISO 27001 compliance.Read the article
- August 16, 2026ISO 27001 Risk Assessment: A Simple and Practical ApproachISO 27001 requires a risk assessment, but you can choose your own method. This is a practical approach that auditors can accept.Read the article
- August 16, 2026ISO 14001 Documentation: What You Actually NeedISO 14001 requires organisations to maintain certain documents and records as evidence that their Environmental Management System (EMS) is properly planned, implemented, and monitored.Read the article
- August 16, 2026Building an Effective Compliance Obligations RegisterThe **Compliance Obligations Register** is an important document that auditors carefully check during an **ISO 14001 audit**. However, many organisations do not prepare it correctly. Here’s a simple guide to help you create a clear, practical, and audit-ready Compliance Obligations Register.Read the article
- August 16, 2026How to Properly Investigate an Incident Under ISO 45001Here is a simple-language version: ISO 45001 requires organizations to investigate incidents to identify their root or underlying causes and check whether the same or similar incidents could happen in other areas of the organization. This approach provides a practical way to meet that requirement and helps organizations take appropriate corrective actions to prevent incidents from happening again.Read the article
- August 16, 2026How to Conduct a Meaningful Business Impact Analysis (BIA)The Business Impact Analysis (BIA) is the foundation of ISO 22301. It helps identify what is most important to the business and provides a clear, well-supported basis for the rest of the requirements.Read the article
- August 16, 2026Writing Learning Outcomes That Can Be Clearly AssessedLearning outcomes are at the heart of ISO 21001. The way a programme is designed, delivered, assessed and evaluated should all be connected to its learning outcomes.Read the article
- August 16, 2026Understanding What the Organisation Needs from Its FacilitiesDemand analysis is the starting point of an ISO 41001 system and is often overlooked. This approach helps you understand actual needs and create something practical and useful.Read the article
- August 16, 2026How to Build an Accurate Record of Processing ActivitiesA Record of Processing Activities (RoPA) is the foundation of your privacy compliance. Here’s a simple, practical way to create one that accurately reflects how your organization actually handles personal data.Read the article
- August 16, 2026How to Set an Effective Energy Baseline and Performance IndicatorsThe baseline and performance indicators help you measure and prove improvements in energy performance. If they are not set correctly, you cannot clearly demonstrate whether your energy management system is actually improving.Read the article
- August 16, 2026CE Marking Documentation – Simple GuideHere’s a simpler version: A guide to the documents required for CE marking. The exact documents may vary depending on the laws and regulations applicable to your product, but this is the general documentation required.Read the article
- August 16, 2026How to Identify the Applicable CE Legislation and Conformity Assessment ProcessTwo key decisions guide a CE marking project: which laws and regulations apply to the product, and which conformity assessment process must be followed. This approach helps you make both decisions clearly and with proper justification.Read the article
- August 16, 2026AI System Impact Assessment under ISO 42001The AI system impact assessment is what distinguishes ISO 42001 from the security and privacy standards it structurally resembles. This is a method for doing it properly.Read the article
Not sure which standard applies to you?
Send us the requirement you have been given. We will tell you which standard satisfies it, what it takes and what it costs, before you commit.
