The ISO Show

The ISO Show

Blackmores UK
Krajina Spojené kráľovstvo
Jazyk EN
Epizódy 200
Najnovšia 16.09.2026

Blackmores, a UK-based consultancy firm, presents a podcast focused on achieving and sustaining high standards in quality, risk, and environmental management. The show is dedicated to discussing ISO standards, offering insights into compliance and best practices. Listeners can expect episodes that explore how organizations can implement these standards effectively.

Epizódy

  • #258 What is BS 99001? Quality Management For The Built Environment 16.09.2026 44min
    Many of you will be familiar with ISO 9001, the leading Quality Management Standard, which provides a solid foundation for managing any business. However, for certain industries, ISO 9001 alone is not enough. The built environment is one such sector, as it requires more rigorous controls to keep projects on track, ensuring safety of all involved and processes that enable documented accountability for each and every step until project delivery. BS 99001 was introduced in 2022, not to replace ISO 9001 but rather to add to existing quality management systems for those in the built environment sector. In this episode, Ian Battersby is joined by Darren Morrow, Senior Consultant at Blackmores, to explain what BS 99001 is, how it addresses challenges unique to the built environment sector and explore the clauses and how they differ from ISO 9001. You'll learn ·      What is the built environment sector? ·      Why was BS 99001 created? ·      What is BS 99001's relationship with ISO 9001? ·      How does BS 99001 differ from ISO 9001? ·      Exploring the clauses of BS 99001 ·      Where is BS 99001 going in the industry?     Resources ·      Isologyhub ·      BS 99001   In this episode, we talk about: [02:35] Episode Summary – Ian Battersby is joined by Darren Morrow to explore BS 99001, Quality Management for the Built Environment. Join them as they discuss the reason for the Standards creation, it's relation to ISO 9001 and an overview of it's main clauses. [03:30] What do we mean by the Built Environment Sector? The sector covers the whole human-made environment: ·      buildings (homes, workplaces, hospitals, schools, entertainment), ·      infrastructure (roads, rail, bridges, utilities), ·      public space (parks, squares, streets etc) On top of that, you could also add the urban environment on a large scale, the way cities and towns are planned, developed over time, connected Any profession involved could apply this standard: ·      Design and planning (town planners, architects, interior designers, landscape architects) ·      Engineering (civils, structural, M&E, transport, environmental (planning our waste, water etc) ·      Construction (delivery, PMs, QSs, SMs, trades, contractors) ·      Management (of estates/facilities, property developers, agents, surveyors, valuers) ·      Policy, regulation, compliance (local authorities, planning officials, building control, regulatory authorities, enforcement agencies) [05:00] Why was BS 99001 created?: Despite the widespread adoption of 9001 across the industry (and it being a prerequisite in many circumstances), there has continued to be a series of significant incidents, numerous reports and national enquiries. These all point to an issue with quality that a generic standard appears to have failed to address.  When this is the case, it's a sign that something more sector specific is necessary to avoid repeating the same mistakes. The UK Building Safety Act is now being enforced, which has added more implications and requirements on contractors. BS 99001 can help to support compliance with this due to its focus on responsibilities, competency and accountabilities. [09:45] What is BS 99001's relationship with ISO 9001?: BS 99001 doesn't modify or replace ISO 9001, it builds on it for the built environment sector. ISO 9001 creates a solid foundation for any business, but because of this it is deliberately vague in it's requirements. BS 99001 in comparison is very prescriptive with what it what's businesses to do, record and evidence. [10:30] How does BS 99001 differ from ISO 9001? BS 99001 is very much aware of the project based nature of its targeted sector, so the requirements are written with this in mind. Its requirements are written to ensure all parties involved in construction projects are included, accountability is its foundation, and it looks to help facilitate a lessons learned environment for compliant businesses. [11:30] BS 99001 Clauses: 4 Context - We're all used to this clause, but there's a note to consider the nature of the interested parties, as it's a lot more prescriptive and includes: ·      Members of the public are suggested first (users of stations, tenants in social housing) ·      Owners and operators of assets (ie, the built end product) ·      Project funders/investors ·      Project owners/sponsors ·      Project teams It also requires context documents specifically taking into account commitments to social, economic and environmental sustainability. So ESG is being embedded from the start. These interested parties encourage open forums between not only all those involved in the actual construction, but those that will be affected by the project and end product. This commitment to social, economic and environmental sustainability is a theme that continues throughout the whole Standard. Some businesses that already hold certification to Standards such as ISO 14001 and ISO 45001 think they may already have all of this covered, and in many ways they would be correct, however those typically apply to the business as a whole whereas BS 99001 incorporates everything in and around the project rather than treating projects as a separate entity – which is how other ISO Standards act in this sector. [15:40] BS 99001 Clauses: 5 Leadership – The specific requirement states: 'Top management shall ensure that a competent person is appointed as the management representative with oversight of quality for projects the organization is involved in or plans to be involved in' This may seem like an old-fashioned approach, however the need for competency in this sector is paramount. Organisational roles, responsibilities and authorities for Quality Management roles with clear competence and impartiality / independence criteria are explicitly stated. What was once a role that may have not held the power to stop a project like Health & Safety roles, now has that ability. If something is raised as a quality concern, then there is a strong argument for that becoming a safety risk down the line. It's better to fix something early on than to have it become a bigger problem, therefore, significance to the roles that point out these issues have been given the power they deserve in the project management process. [20:00] BS 99001 Clauses: 6 Planning – Risk management is an essential part of BS 99001, Clause 6 is where the requirements for risks and opportunities is explicitly stated, however, these are references multiple times throughout the Standard. There are specific Risk requirements to take account of are: ·      Projects it is involved in or plans to be involved in; ·      The process of construction and the subsequent use of the asset; ·      The organization as a whole; and ·      Society the economy and the environment. Many construction companies will be tendering for multiple jobs, so it's a good opportunity to build a robust risk register that gets added to with each project. Learning from one project should be used to help you to bid for the next one. Keeping track of these should also be done so you can inform your interested parties of the risks involved, and any subsequent lessons learnt should also be of value to your supply chain. One key group that often gets overlooked is the Funders, they'll have a particular interest in the risks and to have all the knowledge available about what they're funding. Having records to answer their questions will keep them happy or at least informed. Objective requirements include: ·      Quality objectives for each project, to reflect contractual and other requirements ·      Evidence of the following considerations in objectives: ·      Defined scope, time, cost and project lifecycle ·      Social, economic and environmental commitments ·      Collaboration with interested parties In ISO 9001, the objectives are set from the business level, but in BS 99001 these are aimed at the project level. [24:10] BS 99001 Clauses: 7 Support – As mentioned, people and competence is a big focus for BS 99001. Evidence for competence arrangements include: ·      Project / contract specific roles and responsibilities - formally assigned ·      Formal process(es) for determining competence ·      Competence arrangements relating to all people working on the organisation's behalf There are also verification processes for all external providers, including the need for: ·      Authorities for approval of operations, processes, design, production, inspection and tests ·      Competence arrangements for management representative(s) specifically regarding quality ·      Evidence that competence arrangements take into account requirements of interested parties It's up to the business to make sure they can prove people are competent for the roles they are assigned, which is why there is a lot of detail in this area. Documented information is also key, as this provides a traceable and auditable path of accountability. Again, BS 99001 is a lot more prescriptive on this clause when compared to ISO 9001. BS 99001 requires documentation of: ·      Process(es) to ensure awareness of statutory / regulatory requirements specifically relating to documented information (eg, building information, product safety, structure, maintenance, retention timeframes) ·      Approval methods and authorities for the different types of documented information ·      Communication / availability / control of changes to documented information to interested parties Now this doesn't mean you have to drown yourself in paperwork! These can all be stored as electronic records. This clause also sees a lot of repetition with areas such as risk, however this is simply the nature of Standards. They operate on the Plan Do Check Act cycle, you plan to do something, you do it, you check, you've done it, and you act on it. This repetition is there for a reason, documenting information especially as you need to prove that your final deliverable is safe, that it's operational and that it can be maintained. While documentation may seem like a painful process in the early phases of a construction job, it will serve you well once the project is completed as when you get to the point of handover, everything is already done and all required information is readily available for those interested parties. [31:55] BS 99001 Clauses: 9 Monitoring, measurement, analysis and evaluation – In ISO 9001, it's largely up to the organisation to determine what they monitor and measure, however in BS 99001 there are specific which must be measured, including: [28:30] BS 99001 Clauses: 8 Operation – This, like in most other Standards, is where the bulk of additional requirements sits. 8.3 Design includes: ·      Re-iterates the need to appropriate design processes at organisation and project level ·      Clear definitions of roles and responsibilities ·      Review, verification, validation, approvals and associated competences ·      Inclusion of interested partes ·      Compatibility between parties and their designs ·      Design maturity/novelty ·      Documentation needs ·      Life-cycle ·      Addressing of regulatory requirements, product safety 8.4 Control of externally provided products and services - Again, 9001 allows an organisation to determine its own controls over the supply chain (according to risk). But here, the standard specifically acknowledges the issues with supply chain which partly gave rise to it. It starts with defining the authority to approve suppliers The rest of clause 8 (Control of production and service provision) continues in similar detailed fashion, matching similar themes When we get to 8.7 (Control of nonconforming process outputs, products and services), we see the need to define specific roles, responsibilities and processes It also includes specific requirements for: ·      Evidence of reports to design team regarding design root causes ·      Close out of corrections ·      Agreements of interested parties to corrective action ·      Concession/design change notifications to design authority [35:45] BS 99001 Clauses: 9 Internal Audit – BS 99001's internal audits must be risk-based and include projects. You also need to evidence audit results being reported to interested parties. It also goes without saying that you need evidence of auditor competence. Where Management review is concerned, you must include specific information on the performance of projects, and also evidence management review outputs being reported to interested parties. [37:45] Where is BS 99001 going in the industry? – Currently, this is a Standard that applies more to bigger multi-million pound projects. However, Darren is seeing more of the requirements being pushed down the supply chain. We do see that happen with the likes of ISO 9001, ISO 14001 and ISO 45001 certified organisations doing much the same with their supply chains. But BS 99001 differs as it explicitly promotes pushing its requirements down the supply chain, it's not just a passive affect, it's something to be actioned through leadership by promoting quality management. [39:55] Top Tip – If this Standard is applicable you, we highly recommend you complete a Gap Analysis, even if you're already certified to ISO 9001. This Standard differs quite a bit and ISO 9001 misses the requirements that cover the project life-cycle, sustainability and social aspects that BS 99001 focuses on. At a basic level, ensure that your skilled people have their competences ready and available for if a client requires that information. [41:30] The advantage of BS 99001 – BS 99001 ensure that your business can plan well and protect itself with the required record keeping. If things go wrong, you have the documentation to protect yourself, and with the additional planning requirements, you can minimise the risk involved in projects before things have a chance to go wrong. If you are in the Construction Industry, this Standard is worth looking into. If you'd like any assistance with implementing or supporting BS 99001, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #257 How to meet legislative and ISO requirements in leasehold properties 19.08.2026 33min
    Many businesses do not own the property they operate in, this can lead to complex questions over who has ownership over certain property and facility related legal obligations. Managing areas such as waste transfer, electrical, gas and aircon servicing etc could feasibly be managed by both landlords and those leasing the property, and it's important to establish who manages what to ensure all legal requirements are met. In this episode, Ian Battersby discusses the complexities of leasehold compliance, including how to establish key responsibilities, examples of what legal and ISO related requirements need to be met and what evidence you need to be keeping a record of.   You'll learn ·      What is leasehold compliance? ·      What areas do you need to consider within leasehold compliance? ·      Establishing responsibility ·      What subject areas relate to ISO compliance? ·      How to plan for leasehold compliance and gathering evidence     Resources ·      Isologyhub ·      PAS 79 ·      BS 5839   In this episode, we talk about: [02:35] Episode Summary – Ian Battersby discusses leasehold compliance, including establishing responsibilities and gathering evidence to ensure your legal and related ISO requirements are being met.    [02:45] What is leasehold compliance? Many organisations don't actually own the property where they operate, it's very common for businesses to lease property. A landlord will lease the property to a client and often appoint a building manager, managing agent to run it on their behalf and act as the interface with all the leaseholders. Sometimes, the building manager will be part of a large organisation which also provide facilities management services. Often they'll only offer the most basic of services and will contract another party to provide further facilities management. Whichever party provides general facility management services will almost certainly need to contract another layer of providers responsible for specialist services such as waste transfer, electrical / gas / aircon servicing. Sometimes, the leaseholder will directly contract a third party for a service (air con, electrical, PAT, cleaning).So all in all, it can be quite a complex picture of responsibility! [05:10] The complexities of leasehold compliance: It can be tricky navigating through this and demonstrating that you've fulfilled all your own legal obligations as well as gaining assurance that other parties have done what they need to do to protect you and your employees. Often, those charged with liaising with the building manager are not experts in Health & Safety, Environment, Facilities Management and compliance. It might be the office manager who picks up this role. In some cases, you have an absolute duty, even where the landlord has complete control over the service which is provided to you (e.g. waste management). [06:45] Establishing Responsibility: Establish who owns what, who is responsible for things such as building fabric, installed services, the contracting of support services. But, regardless of actual ownership and the direct responsibility for a particular aspect of a building, there is always an interrelationship, a dependence between building, infrastructure elements. For instance, you may use a whole floor which has been fitted out for your own purposes, you own the electrical installation from the walls inwards, but that links into the electrics beyond your own shell. You may have certain responsibilities in your own area for firefighting equipment, fire doors etc, but fire safety also depends on things like: ·      The escape routes ·      The building's fire alarm ·      Emergency lighting ·      Protection of the common areas such as the lobby If the building isn't safe beyond your own demise, your own demise isn't safe. While you may not have direct control over these aspects and your legal responsibilities, leases may leave the burden on you to seek evidence. Although there should be demonstration of various compliance obligations throughout the pre-let enquiries process. You may even be lucky enough to have a lease clause which requires landlord to complete or contribute towards compliance reporting.  [08:30] What subject areas relate to ISO compliance?: Standards where leasehold compliance is particularly relevant include ISO 14001 environmental management and ISO 45001 Health & Safety management. For both of these, there may be a need for you to provide your own evidence or seek assurance from a third party. The examples we're providing here apply to office locations and for more complex, more industrial, more heavily commercial premises. Considerations / requirements for either one of both of these Standards include: Energy performance certificates: Legally required documentation. They rate the energy efficiency of a property from A to G, and they have to be provided prior to leasing and on leasing. These can apply to a whole building or just a wing or floor of a building. These can be verified online via a .gov portal. As of the 1st of April 2023, any commercial property in England or Wales must have a minimum energy performance certificate rating of E. However, this is set to change after consultation, so from April 2031 you won't be able to let property unless it's in the A or B band. Recommendations Report: This supplements the previously discussed energy rating. This report, as the name suggests, provides recommendations for improving efficiency. If you're already rated an A or A+, then there may not be too many recommendations. But C and below will have some that will improve your building over time. It's important to note that there is no mandatory obligation to action these recommendations, and some provided can be quite generic and not at all applicable. However, you should seek through the landlord and ask if they're following through on any of the recommendations to improve energy performance, particularly if you will be looking to renew leases around the time that the law changes. Air Conditioning: If your building is relatively new, less than five years, you will really need to see the installation and commissioning information associated with air conditioning. There should be records of building control, electrical installation, commissioning certificates, and also a test which is called a TN 44. This test is legally required once on installation and then again after every 5 years. It needs to be carried out by an accredited energy assessor, who can be verified via the same Government portal as the Energy performance certificates. This applies to any system with an effective rated output of more than 12 kilowatts, which quite simply, is nearly all commercial offices. The TN 44 test will also provide a report which includes recommendations on how to use the equipment, the management regime for its setting points for temperatures and other such advice to keep it working as efficiently as possible. The person responsible for air conditioning is responsible for this certificate. If you own the aircon in your demise, it's yours, if the landlord owns the aircon, it's theirs. F Gases: Any system which contains fluorinated greenhouse gases, so what we call F gases, needs to be inspected regularly to ensure that none of the gas leaks and to ensure that they're operating at optimum efficiency. This can includes things such as air conditioning, heat pumps, Fire Protection (aerosols and foams) and is often used in various parts of Industrial Manufacturing. If there are any leaks, they need to be logged, replacements need to be made, recharge needs to be done, and all this needs recording in a logbook. When it comes to servicing of anything that uses F Gases, you need to check the competence of those individuals. Refcom has a register of accredited / approved companies that provide these services. Fire Risk Assessments: Fire Risk Assessments are legally required documentation which needs to be carried out by a competent person. There isn't a prescribed frequency on fire risk assessments, but you should really be reviewing them at least annually and doing a full reassessment on a three-year period – or when there has been a significant change to the layout / occupation of the building. There is a mandatory way of completing a fire risk assessment, PAS 79, which is a publicly available specification. So you need to check that yours are being done in alignment with this Standard as this provides proper risk evaluation and an action plan which is prioritized according to the level of risk. It may also be worth checking with your insurance organization or any local authorities whether they have a prescribed frequency for your fire risk assessments. Fire Alarms: You will no doubt have a fire alarm within your building, this may be the landlords own fire alarm system or it may be one you as the leasehold business own. As a starting point, you need to understand who has ownership of this. On installation and commissioning, you must comply with certain standards. For the UK this is BS 5839, which requires building control, a commissioning certificate, handover certification, the correct drawings, a manual, a logbook, specific training to the owners and users of the system. Every six months you should have a competent person complete maintenance, servicing and inspection to ensure that the way the fire alarm was installed is the way it remains in compliance with BS 5839. As well as a six-monthly inspection, there is also a competent person test and inspection over elements over and above that, which requires certificate issuing annually. There's also a full test and inspection of the wiring underpinning the fire alarm system. This isn't prescribed, but it's commonly conducted at 10-year intervals. Fire Extinguishers: You may own the fire extinguishers in your own demise or they may be owned by the landlord. What you need to do is, if you own fire extinguishers within the organization, take responsibility for regular walk arounds to check that they're all in the right locations, the right numbers are present, that they are accessible, secure, fully charged in the green zone, undamaged, the seal is untampered, and the service date is correct. Every year, you need a competent person to come in and check the fire extinguishers fully, record this in the fire logbook and provide a certificate of service for each of the extinguishers in use. Depending on the type of extinguishers you've got, you may need a five yearly or possibly longer frequency extended service. Other Fire Suppression Systems: You might have a fire sprinkler system which will require installation and commissioning certificates. Regular inspection maintenance service will then depend on the type of system, this could be anywhere between a quarterly, annually, five yearly, 10 yearly inspection regime. There should be evidence that there is some form of local regular inspection to check that there is no visible damage to a fire suppression system. We would advise you to discuss with your landlord about what process exist for those inspections. There are also fire doors that need both competent person checks on a six month to annual basis to check for the physical robustness for the opening and closing mechanisms for external escapes to open correctly. But there should also be regular checks by local representatives within your organization of any fire doors within your own demise and from your own demise to check that they are physically sound and operate correctly. The escape routes from those should also be checked by the landlord for any obstructions beyond your demise to see that there's an adequate, safe path from the building in the event of a fire. Emergency Lighting: There is again a regular monthly checking to see that emergency lighting comes on should the power go down. Sometimes that's by flick testing, nowadays, some buildings have automated testing of their emergency lighting. This requires an annual inspection be a competent person, which will result in a test certificate as proof of inspection. Gas servicing and electrical wiring inspection: Gas servicing is required once a year by a gas safe, registered, competent person, and the resulting certificate will indicate whether there are any recommended actions. With electrical installation and condition reports (EICRs), Electrical and fixed wiring is checked every five years and on installation and commissioning as well. These have different levels of findings, including: ·      C1, danger is present ·      C2, potentially dangerous ·      C3, improvements recommended ·      And FI, further investigation Anything which is a C1 and C2 needs to be addressed, anything which is an FI requires seriously looking into to see what the implications are. If you have your own EICR for your own demise, you should be checking the content of that to see what the recommendations say, not just accepting the certificate as if it is the gospel says your equipment is safe. If the landlord is responsible for an EICR in other parts of the building, you should liaise with the landlord to see what implications there are for you. [29:15] How to plan for leasehold compliance and gathering evidence: What's your strategy for making sure you are safe and you know you're safe and you can provide assurance of that safety? If you've got direct control of the contracting of any services, then it can be quite straightforward because you control the contractor: ·      You should be verifying the contractor's competence. ·      You should be verifying that they're providing the right service, maintenance, inspection, test documentation. ·      You should have within that documentation recommendations, risks, actions that you can then take forward. But if you rely on the landlord's agent, for instance: ·      You have to rely on cooperation with them. ·      You also have to rely on their own understanding of their obligations and their record keeping. You'll need to approach them with a structured list to request all the things you need to meet your legal requirements. Work out a way to retrieve what you need, as they need it as well, so it should be straightforward once they've sourced it to provide you with it. If you have any regular tenant, landlord, managing agent meetings, use those to review compliance and any progress on recommendations. If those meetings don't exist, perhaps you could set up some form of regular meeting where you can assess your level of compliance and monitor any movement in that. Where you've received any record from a service, a maintenance, a test, a certification or an assessment, study that carefully. See where the risks are and follow through on relevant recommendations. If you'd like any assistance with navigating leasehold compliance or implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond 05.08.2026 45min
    There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it's operational. It's undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those wondering how to get involved, there is a dedicated group looking to share knowledge and tools to get you tender ready. In this episode, we are joined by Lorna Leonard, Managing Director of LBS, and Kirsty Maynard, Commercial Director of THSP, who are instrumental in running BedX, a group dedicated to sharing knowledge and tools to help businesses get tender ready for Universal and beyond. Listen to our roundtable discussion as we dive into why BedX was created, its main drivers, how it can support local businesses and how you can get involved. You'll learn ·      Who are Kirsty and Lorna? ·      What is BedX? ·      What were the main drivers behind the creation of BedX? ·      What are the group's main aims? ·      What are Kirsty and Lorna's roles within the group? ·      How can businesses get involved with and benefit from BedX? ·      What can businesses be doing now to get tender ready for Universal?     Resources ·      Bedfordshire Chamber of Commerce - BedX ·      BedX Webinars ·      Tender Diagnostic ·      Kirsty Maynard LinkedIn ·      Lorna Leonard LinkedIn   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman and Carly Mowbray are joined by Lorna Leonard (LBSv) and Kirsty Maynard (THSP) to discuss the creation of BedX, and how it aims to support businesses with tender preparation ahead of the Universal and related projects currently underway in Bedfordshire.   [01:25] Who are Kirsty and Lorna?: Kirsty is the commercial director at THSP. THSP work with businesses across health and safety, HR and compliance, helping organizations make sure they've got the right systems, processes and people in place to operate safely, professionally and compliantly. THSP have been in operation since 1992 and support any type of organisation, from construction to food brands, global luxury retailers, major transport organizations, and complex international businesses operating in highly controlled environments. Lorna is the managing director of LBS. LBS is a business solutions company supporting sophisticated start-ups and growing corporations with outsourced finance department services, direction and solutions. She set-up the business 14 years ago, and has worked with organisations of all sizes, from blue chip companies to micro businesses of only 1 or 2 people. Regular listeners may recall Lorna from a previous episode, she also shares many insightful posts on LinkedIn and is certainly worth a follow! [07:05] What is BedX? It's A business-led working group powered by the Bedfordshire Chamber of Commerce. It was created to help Bedfordshire businesses understand, prepare for and win work from the major investments coming into the region, in particular, the universal destinations and experiences, the Luton Airport expansion and other on-going linked projects. BedX's role is to connect, inform and prepare, but they don't lobby, they don't represent the developers and they don't do politics. They are simply there to help local businesses get ready. [07:45] What were the main drivers behind the creation of BedX? The Universal park is certainly the banner piece for the group. It's what all the big numbers are attached to, including 5 billion pounds worth of inward economic investment, 20,000 jobs created and the five years' worth of construction. However, that is just one part of the upcoming development going on in Bedfordshire. The big project is seeing more funding going into the area to support transport networks and other venues as investors seek to make Bedfordshire a place worth staying for more than just the Universal Park. Other projects include the expansion of the Wixams Train Station, construction at the Luton Hoo, the new Luton Town Football Club and a new Data Centre at Quest Pit. BedX was created in response to all of these projects, not just Universal. It's to help local businesses navigate these opportunities, as this small county has rarely seen such a seismic shift in the amount of investment going into the area. Even though the deadline for Universal Park is 5 years away, supply chains are looking for support now, which is why it's better to start preparing sooner rather than later. [10:20] Making Bedfordshire a play to stay: It's also not just about the venues, to prepare for the influx of tourists there will be more investment in housing and transport and related routes such as the work currently going on at the Black Cat roundabout. Kirsty states that the Bedford County Council have a scrutiny committee, which is currently labelled as the Universal Scrutiny Committee, and are in discussion about a viable tourist strategy for Bedfordshire. So, there is no doubt that there will be many more small projects going ahead within a very short timeframe to get the area ready. [12:00] How LBS's expertise is instrumental within BedX: Businesses that want to get involved may not know how to get working capital or access potential available funding, which is where Lorna's and LBS's expertise comes in to support BedX's aims. With tenders as highly valued as this, it can throw businesses through a loop if they're not prepared. Lorna shares a story where she explains that she used to work for a company that made point of purchase display equipment, this company had a US subsidiary called Anshauser-Busch, who own Budweiser. That subsidiary put through an order directly through to their factory, requesting a huge order be manufactured and delivered within 180 days. The cost of which was upwards of $2.7 million, which was due to suppliers 150 days prior to Lorna's company at the time being paid. It was their first time working with that subsidiary, so there was no guarantee on payment. The lessons they learned ended up shaping how the company operated going forward. All this to say, if you're bidding for high value contracts, you need to think about the opportunity from every perspective. [14:40] Be realistic about what you bid for: Kirsty states she is really passionate about ensuring businesses are trying to grow responsibly, so that they understand those terms in the bid and that they're realistic about the size of contract that they should be bidding for. If you're looking for more guidance in this area, Katie from Bids and Tender Support provided a webinar on this topic for BedX. It's available to view on-demand on BedX's website. [16:25] Lorna's role within BedX: Lorna reminds us that a lot of the Tier 1 contractors started out as 1 or 2 person businesses. She states that, honestly, 90% of the companies that BedX help will not be in direct contact with one of those Tier 1 contractors. However, supply chains are just that, a chain, there are many opportunities to get involved further down the line. Lorna feels as if that's a large part of her role, keeping businesses focused on the opportunities they can access within that supply chain. She is also keen to help all the local businesses understand how this is going to affect them, because whether they get involved in the various projects being built or not, the whole area is going to be affected regardless. She points out an example where they needed to source a large number of electricians, and it turns out that Bedfordshire simply doesn't have enough! So BedX is helping to make the wider community aware of training opportunities like this that can open doors for local businesses. [18:45] Other considerations for businesses operating in Bedfordshire: Lorna points out a few other concerns that people had about the on-going development in the area, including the possibility of local contractors putting prices up due to all the other projects. Timeframes may also be affected by both on-going work and the fact that more businesses will be getting involved in the area's development. [19:15] What are the group's main aims?: BedX's main aim is to be an opportunity exchange, they sit in the middle as a conduit between the opportunities and the Bedfordshire businesses and help to inform, educate and prepare to be a part of it. They are there to support preparation local businesses are able to access emerging supply chains as that waterfall flows down into tier 2 and 3 and even into 4 and 5 over the course of the project. If you're not sure which of those tiers you'd likely sit in, BedX have a helpful household checklist to find out. [20:20] Getting ISO Ready for Universal: Kirsty mentions that she's seen a lot of recent Pre-Qualification Questionnaires (PQQ's) request that bidding companies are certified to ISO 27001 Information Security. Many will be familiar with the requests for ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Occupational Health & Safety), but ISO 27001 seems to be a more recent pre-requisite. This is particularly the case for any Government contracts, with them stating either Cyber Essentials or ISO 27001 must be in place for any bidding businesses. Carly points out that ISO 27001 in many cases is just the first step, as you can strengthen this with supporting Standards such as ISO 27701 (Privacy Information Management) and ISO 27017 & ISO 27018 (Cloud Security), which can give you an advantage over your competitors. If you've not got any Standards in place, or are just starting out on your implementation journey, you can get in contact with Blackmores as we'd be happy to guide you towards successful certification. [25:00] Kirsty's role within BedX: Kirsty's role is focused on coordination, though all BedX organisers are volunteers, they still want to ensure that actions are followed up and completed. Kirsty has a project planning background and brings those skills to the group. She also plays a key part in tender and procurement readiness, as she has years of experience with PQQ's from her work within the construction industry. She knows what good looks like when bidding for work, and ensures that knowledge is being passed on to those looking to bid for Universal and other Bedfordshire development projects. A trait that many of the BedX team hold, Kirsty and Lorna especially, is the motivation to help people, and this group allows them to do so at scale. [27:45] How can businesses get involved with BedX?: You don't need to be a member of the Bedfordshire Chamber of Commerce to get involved. Currently BedX's main focus is on knowledge sharing, so their main output in webinars. They also have a tender diagnostic tool available, this is an online tool which takes just a few minutes to complete and will give you an idea of where you're already compliant and where there's work to be done. They have also had 1 in-person event, that being their official launch in April of 2026, which was attended by members from the Bedfordshire business community and representatives from Universal, Sizewell C and Luton Rising. They expect to run more in-person events in future, so keep an eye on their LinkedIn for news on these! Lorna hints at an upcoming event planned for September 2026 😉 You can also sign up to the Bedfordshire Chambers Newsletter for more updates. An 'Easy Guide To Social Reporting' is due out imminently. Those wanting to bid for Tier 1 contracts, social value is a legal responsibility, so if you're not sure on how to report on that, this is one for you to keep an eye out for. For information you can access right now, they have: ·      Contractor Tier Checklist ·      Tender Diagnostic ·      Working with Tier 1 contractors webinar (hosted by Henry from Kia) ·      How to be tender or procurement ready webinar (Hosted by Kirsty) ·      How to write a good bid webinar (Hosted by Katie Beryl from Tender and Bid Writing Services)   [31:10] What can businesses be doing now to get tender ready for Universal? One thing Lorna stresses is being visible. If you don't have a social presence or good SEO, then you may be missed as an option for those looking for specific services within these developing supply chains. She also shares a story about the supply of the chocolate frogs that are sold at Universal Floria, which were all provided by a 2 person company. This highlights that it is possible for smaller local businesses to win big through these opportunities, but you need to be prepared. This is why Kirsty and Lorna both highly recommend making use of their Tender Diagnostic tool. Being tender ready may seem like a daunting process, and it can quite difficult, but they are worth putting time into. Also anything you can do to think about what you may need to change within the next few years. Think about how these developments are going to affect the traffic to the area, you might need to reconsider who your target market is depending on the whims of upcoming tourists. This can affect what services / products you offer and how you advertise going forward. The sooner you think about it, the better prepared you can be. Lorna also recommends networking with local businesses. Bedfordshire is going to become a thriving hub, and the more connections you can make now, the better. Some of these tenders may require the collaboration of multiple businesses, which would be an all round win for everyone involved. Networking also allows your name and brand to spread through word of mouth. If you're not in the room, it helps to have people who can vouch for you if your specific services are being sought out. Lastly, Lorna and Kirsty just say to dream big. Just because you may be a small business does not mean you are automatically locked out of those big tenders, they are worth a try. An important note, being local to Bedfordshire won't make up for gaps in the eyes of Universal and related projects, however, if you share equal capabilities as other companies outside of the county, then being local will tip you over. [40:10] Evidence is key: Ultimately being tender ready is in your best interest. Contractors will be looking for evidence that you do what you say you do, so ensure you have Case Studies and the required certifications to back-up your claims. Social Value is another big factor, which can account for up to 20% of a bid score, so this is another area where you need a clear trail of evidence.   Having a clear library of evidence to back up your claims, that align with how you operate will make you stand apart from the competition. So, start gathering this now if you haven't already. If you'd like to get involved with BedX, check out their website. If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #255 AI Due Diligence - Information Security Checks Before You Integrate AI 22.07.2026 19min
    AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped. So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business. In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some tips on basic Information Security checks you can do to ensure an AI application or integration is safe to use.   You'll learn ·      The link between AI and increasing data breaches ·      Recent incidents as a result of AI misuse or error ·      Key considerations for the implementation of AI technology ·      11 Information Security checks for AI tools     Resources ·      Isologyhub ·      ISO 42001 Webinar ·      IAF Accreditation Check   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman explains the need for caution when exploring the implementation of AI tools, and provides guidance on some information security checks you can perform to ensure your data stays safe. [02:45] The link between AI and increasing data breaches: Data breaches tripled since the wide adoption of AI in early 2024 and studies are saying there is a clear link between these two events. Here in the UK alone, 32% of businesses experienced a cyber-attack or data breach in 2023, compared to 43% of businesses in 2025, with us already steadily on track to surpass that in 2026. Does this mean people shouldn't use AI at all? No, of course not, but we do need far more caution before you simply start using a tool. [03:35] Recent incidents as a result of AI misuse or error: ChatGPT copycat – There was a ChatGPT clone available as a web extension that was downloaded by some 1.5 million users. It functioned just like ChatGPT, answered queries and provided links to legit sources. But, in the background, it was scrapping passwords and gathering information that was to be sold off without users knowledge. Sage Copilot - The popular accounting software had to temporarily suspend Sage Copilot after a data-isolation flaw occurred. This incident caused an issue where users who prompted the AI to list recent invoices ended up with incorrectly surfaced financial records belonging to unrelated businesses. This was a major security issue, especially for an application thousands of businesses rely on to track their financial records. Google Gemini – Google Gemini was found to have been abused by bad actors for data reconnaissance. One particular group were building profiles on major cybersecurity and defense companies and were looking to gather specific technical job roles and salary information. Google's threat intelligence team characterized this activity as a blurring of boundaries between professional research and malicious reconnaissance. Their soft touch approach allowed the bad actors to craft tailored phishing personas and to further identify potential soft targets to compromise. [06:30] Key considerations for the implementation of AI technology: Any software or technology you plan on introducing into the business that will interact with your and your customers data should be subject to clear vetting procedures, with clear rules for use to follow. Before integrating an AI tool, ask yourself, is the tool you want to use: a)    Relevant b)    Safe c)    Ethical Ethical may sound strange, and will depend on what you're using an AI for. Take CV sorting for example, many studies have shown that AI's can have an inherited bias based on their training data. This has also now evolved into AI based recruitment tools preferring AI generated CV's over human written ones. From a safety standpoint, think about the data you are feeding into those recruitment tools, that's personally identifiable information, full names, phone numbers, emails and possibly even addresses. A full profile for an individual. Is that system your using closed, do you know if you consented to having any input data used for further training? Don't just assume that inputted data won't be used beyond your control. If that recruitment AI tool gets hacked, who do you think is liable for the breach? Is it the AI tool developer or the business that input the data? You think the answer would be clear, but the legality of all this is still being debated. [09:10] 11 Information Security checks for AI tools: #1: Have an AI Policy and AI Integration approval process in place - Many businesses will already have an AI policy in place, most are very generic, so we recommend looking at the guidance provided by ISO 42001 to see what good looks like for an AI policy. You should also create a clear approval process that any AI tools must pass BEFORE people start using them. This should be clearly communicated to the wider team, and there should be a method to manage these checks such as a ticketing system to kick off the process. #2: Understand where your data actually goes - Find out whether inputs are used to train the vendor's models. These inputs can include prompts, uploaded files or even customer data depending on what the tool is. You also need to find out how long that data is retained, and whether it's stored in a specific jurisdiction. You can look for answers to these in a DPA (Data Processing Agreement), don't rely on the basic marketing blurb they state on the website. If those answers aren't provided, contact the tools support or basic enquiries to find out. #3: Check for a SOC 2, ISO 27001, or equivalent certification – This is an easy check for vendor's security posture. Absence of certification shouldn't automatically disqualify a vendor or tool, but it should prompt more due diligence, not less. Even with a certification in place, you also need to double check that it's valid. ISO 27001 for example will need to be certified by a UKAS accredited certification body for those in the UK. For overseas, you will have your own ISO accreditation bodies, which can be verified on the IAF website. #4: Map out third-party and subprocessor risk - Most AI tools sit on top of other infrastructure like cloud hosting, underlying foundation models and additional analytics tools. You should ask for a subprocessor list to fully understand who else touches the data. #5: Test for prompt injection and data leakage - If the tool interacts with external content such as emails, documents or web pages, it can potentially be manipulated by malicious instructions hidden in that content. Businesses should ask vendors how they mitigate this and ideally test it themselves. #6: Clarify access controls and permission scoping - This is especially the case for AI agents or tools with system integrations. You need to establish if the tool operates with the same permissions as the user, or whether it has broader access. Overprivileged AI agents may operate independently with no human oversight. 'Human in the loop' has become a common phrase within cyber security for a reason, you always need a point of human oversight to ensure the AI is doing what it's supposed be doing and is doing so safely. #7: Ask about model update and versioning transparency - You need to ensure that the vendor won't just silently swap out the underlying model for its AI tools, as this can introduce sudden behaviour changes in the tool itself. Transparency is a key component of emerging AI security frameworks and regulations such as ISO 42001 and the EU AI Act. If a vendor isn't willing to tell you when they're making major changes to their tools, then it's not a vendor you want to entertain. #8: Evaluate the output reliability and hallucination risk in context - For security-adjacent or compliance-adjacent AI tools, factually wrong outputs are a risk. AI can have a tendency to 'hallucinate' data or outcomes and then present them as fact. So, ask the vendor what guardrails exist and whether their tools' outputs are auditable / traceable. They should know what data was used to train their models, or where their models are pulling data from. If they don't or can't control what data is being used, then it's not a tool you can 100% trust. #9: Review incident response and breach notification commitments - If the vendor is breached, do you how quickly you would be notified, and what their recovery process looks like? If you hold ISO 27001 and ISO 22301, or simply have a business continuity plan in place then you will already have similar procedures in place for peace of mind for your own customers, so why should you settle for any less? And just like your clients would expect, breach notifications and expected recovery times should be contractually defined, not just assumed. #10: Consider the supply-chain risk of the vendor itself - This tech is still relatively new, and so newer AI vendors may have smaller security teams and less mature processes than what you may be used to with more established providers.  However, startup pace doesn't mean you have to tolerate the start-up risk. Consider all of the previously mentioned steps, if they don't have a lot of that in place, then they may not be mature enough yet for you to go ahead with. This doesn't mean you have to automatically disqualify them, if they have a clear plan of action for growth, which shows a clear focus on increased security and transparency within a reasonable timeframe, then it's still worth considering. #11: AI tool monitoring and Kill switch – In addition to this initial vetting procedure, you should also have a process in place to continuously monitor these AI tools too. Many AI tools aren't static, they'll update and become better or possibly introduce issues as they will inevitably face the risk of bugs and other technical problems as they roll out updates. If a tool is consistently encountering issues, continuous monitoring allows this to be flagged up as a security issue. Which is where you'll also need a kill switch in place if an AI tool is behaving unsafely. It's important that you know how to isolate it and remove it from your systems. AI tools are more ingrained that your typical software, often designed to work in tandem with existing apps rather than as a standalone system. This will mean that some tools will have access to possibly sensitive data, something that needs to be protected if the AI tool experiences issues that could lead to that data being compromised. The relevant staff, likely your IT team, need to have a clear process for what to do in those scenarios. If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill 01.07.2026 25min
    The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they've found their first year working with other organisations to help them achieve ISO certification. You'll learn ·      What is Emma's role at Blackmores? ·      What does Emma enjoy outside of consultancy? ·      What did Emma do before becoming an ISO consultant? ·      How has Emma found her first year as an ISO consultant? ·      What Standards has Emma worked with so far? ·      Has there been any unexpected elements to her role? ·      What is the biggest challenge Emma has had during a project so far and how did she overcome it? ·      What is Emma's biggest achievement?   Resources ·      Isologyhub ·      TISAX Webinar   In this episode, we talk about: [00:30] Episode Summary – We introduce Emma Coxhill, an Isologist® here at Blackmores, to discuss her recent entry into the world of ISO consultancy, including how she's found working on the other side to help other organisations achieve ISO certification. [03:30] What is Emma's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. Emma specialises in information security management systems (ISMS), but is branching out to other Standards as she takes on more clients. [04:30] What does Emma do in her free time? Emma is a big fan of the outdoors, enjoying long walks and exploring in general. It makes sense then that she also enjoys gardening. While it is a lot of work, she finds the result rewarding. Emma is also a big fan of movies, excluding horror films! She enjoys making the trip to see films on the big screen when she has the chance. Lastly, Emma is also a qualified life coach. This involves guiding people to get where they want to be in life, with the crucial distinction that it's not about telling people what to do, but rather providing the right questions and tools to help them achieve their goals quicker. These skills have evidently translated well into her role as an ISO consultant, as auditing is very similar in the fact that it's about giving people a different perspective. [06:55] What was Emma's previous role? Emma previously worked in admi and retail roles, with her last job being a sales admin at a company for 13 years. She first started at that company as a sales admin, moved onto business systems and around 2019 the request for them to earn ISO 27001 certification came in. Back then ISO 27001 was a 'nice to have' and not a 'need to have' like it is today. Emma jumped at the chance to join the team working on the ISO 27001 Implementation, taking part in the research, training and implementation tasks. The company managed to navigate their certification, even through the turbulence of COVID, and Emma was the one maintaining that ISMS for the following years. During that time she also implemented TISAX, an Information Security Standard specific to the automotive industry, which you can learn more about on one of our previous webinars hosted by Emma. Sadly, Emma was made redundant in 2025, but was fortunate to join the Blackmores team shortly after. [10:10] How has Emma found her first year as an ISO consultant? It's been challenging for Emma to adjust to being on the other side of the fence, helping others to achieve certification rather than being the one to implement a system firsthand. Thankfully there was plenty of opportunity to learn during her first year with Blackmores, including expanding her repertoire of Standards and being able to learn from other experienced consultants in the team. She's really enjoying working with a variety of clients, getting to learn about different industries and how different each company is in their operations. Emma is aware that she's just scratching the surface within her first year, and is eager to learn more. [12:20] What Standards has Emma worked with so far? ISO 27001 is the main one as it's the one that Emma learned to implement from scratch at her pervious job. Since joining the Blackmores Team she's also gained experience working with ISO 9001 (Quality Management), ISO 27701 (PII Management), ISO 17100 (Translation), ISO 42001 (AI Management) and TISAX. ISO 27001 remains her favourite out of all of them, and she's keen to learn more from Blackmores own Information Security guru, Steve Mason. [14:15] Has there been any unexpected elements to her role? One of the more unexpected aspects has been helping clients navigate various acquisitions. When she joined, Blackmores had an unusual amount of clients currently in the middle of this process. Dealing with ISO management in these situations can get tricky as you're having to marry up different styles of management as two companies merge. Emma's role was in helping them to navigate that transition. She was surprised as she expected to be dealing with companies that were business as usual for years, but ISO Management is at the heart of managing these types of changes. So, it was interesting to learn how involved an ISO consultant can get into the inner workings of a business to help ease the burden for all parties involved. [17:20] What is the biggest challenge Emma has had during a project so far and how did she overcome it? Emma is still relatively fresh to implementation projects, but has found the process to be quite straight forward with the both the Blackmores 7 step methodology and support from other team members. What has been a challenge was the promotion she was tasked with for TISAX. It was a new service offering for Blackmores due to her expertise, and she was involved in recording a podcast and hosting a webinar. Both activities she'd not had any prior experience with. She doesn't think of herself as a big presenter, so it seemed like a dauting task. Emma did a lot of practice and went our of her comfort zone to do the webinar, which was positively received by the audience. The experience certainly boosted her confidence in that area, and though it was a bit stressful at the time due to nerves, she felt like it was a good learning opportunity. [19:45] What is Emma's biggest achievement? Emma has various moments throughout her life, with an early one being the fact that she passed her driving test first time at the age of 17. Later in 2005, she went solo travelling for 5 months around Australia, New Zealand and Fiji. She did end up having to work for a bit of that trip to make up some additional funds, but that was a necessary evil. Other than that, she was amazed at all the different people she met during her travels and was so pleased that she was able to complete the trip. Lastly, she's proud to have joined the Blackmores team in 2025. She's recently helped her first client achieve certification from scratch, which felt like a reward in of itself to know they'd passed their ISO assessment.  If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #253 Building The Case For Health & Safety Regulations & Standards 24.06.2026 27min
    Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.   Health & Safety often gets mocked for overly cautious or seemingly onerous tasks to meet certain regulations and Standards today, however these are in place for a reason. They save lives, plain and simple. In this episode, Ian Battersby makes the case for Health & Safety regulations, including why they were introduced, events that sparked the conversation for workplace safety and the impact regulations have had since their introduction. You'll learn ·      The decline in ISO 45001 adoption ·      The Health and Safety at Work Act ·      How much difference has this Act made since its introduction? ·      How do the US and UK differ in their approach to safety regulations?  ·      What events led to the creation of safety regulations in the UK? ·      Addressing broader health and safety risks – illness and long-term damage as a result of work ·      How to make health & safety manageable   Resources ·      HSE ·      ISO 45001 Support ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian Battersby makes the case for modern Health & Safety regulations, sharing why they were introduced, how they've impacted workplace safety statistics and how you can make health & safety more manageable.    [03:30] The decline in ISO 45001 adoption – From our standpoint as consultants, there has been less adoption of ISO 45001 when compared to other Standard such as ISO 9001 or ISO 27001. In years previous, it was a common Standard to implement either with or straight after ISO 9001. There are a number of reasons for this, including: ·      The appetite for ISO 45001 has reduced in favour of newer Standards ·      Supply chains not proposing it as a requirement ·      Our particular client base feel they are low risk in their respective industries To be fair, health and safety does get a bad reputation for being overbearing. It's been subject to many attacks from various media and lobbying groups, however, it's necessary to ensure we all stay safe at work. Let's look at some history… [05:00] The Health & Safety At Work Act: This act received Royal Assent in the UK on 31 July 1974, and came into force on 1 April 1975. To an extent it replaced and improved upon previous laws covering separate industries and activities: Factories, Mines & Quarries, Agriculture, etc It was enacted in response to a recognition that, although conditions for workers had improved over the century, there was still completely unnecessary harm being caused to many in the country's workforce. This is also the point when the Health and Safety Executive was formally established to enforce the law. It also provides a wealth of guidance to businesses, so we highly recommend checking out their website. They also have the legal duty to collect consolidated data on workplace injuries for the UK, and have provided an annual report since it's inception in 1975. [07:45] How much difference has this Act made since its introduction? In the year to 31/03/1975 when consolidated data was first recorded there were 651 deaths at work. The equates to more than 2.5 deaths in a single year per 100,000 workers. Comparatively, in 2024/25 124 people died in work, and while that's 124 too many, it's a big improvement. The rate per 100,000 workers is now 0.37, and you have to bear in mind that the workforce has grown, but overall that's a reduction of over 85%. [09:10] How do the US and UK differ in their approach to safety regulations? The Occupational Safety and Health Administration (OSHA) serves similar purpose in USA as HSE, but they have important differences in approach and independence. The HSE is independent of government to an extent and has no ministerial control, whereas OSHA sits within the Dept of Labor. It can also be argued that the OSHA approach is prescriptive in setting rules whereas HSE follows the more outcome-based principles of HASAWA: to reduce risk "so far as is reasonably practicable", which some argue is more sophisticated and produces better results. OSHA has also seen its powers to intervene, investigate and enforce curtailed at times due to certain political interests.   Looking at the numbers, the US Bureau of Labor Statistics published fatality rates for 2024: Census of Fatal Occupational Injuries: There were 5,070 fatal work injuries recorded in the United States in 2024, down 4.0% from 5,283 in 2023. The fatal work injury rate was 3.3 fatalities per 100,000 full-time equivalent workers in 2024, a decrease from 3.5 in 2023. That rate is notably higher than Great Britain's — 3.3 per 100,000 versus 0.37 — though the two figures aren't directly comparable. The BLS uses full-time equivalent workers as the denominator and covers a broader range of incident types, while the HSE's RIDDOR series uses a headcount of all workers and has specific exclusions (road traffic accidents, air and sea travel, etc.). The methodological differences mean a like-for-like comparison requires some care. [13:35] What events led to the creation of safety regulations in the UK? In the days of Victorian Britain, it's difficult to view the common working man, woman AND child as anything other than a commodity. Thousands died every year in industrial accidents during this era, and large-scale accidents in many industries weren't uncommon. Mining was particularly tragic, a few events include: ·      The Oaks Colliery explosion of 1866 killed around 360 men and boys. ·      Hartley Colliery in 1862 trapped and killed 204 miners when the single shaft collapsed (but individual deaths from falls, gas explosions, and equipment failures happened constantly and attracted no particular attention) ·      The Abercarn Colliery explosion in Monmouthshire (1878) killed 268 men. ·      The Albion Colliery explosion at Cilfynydd in Wales (1894) killed 290. These were not exceptional events, they were part of a continuous toll. In the 1860s alone, over 1,000 miners died annually in Britain. Textile mills, ironworks, shipyards, and construction sites all had very high casualty rates. Factory machinery had no guards. Children routinely worked in spaces too small for adults, climbing inside machinery to clean it while it was still running, or crawling under looms. Mill workers lost fingers, hands, and arms with regularity. The end of the Victorian era saw attempts at regulation, but without true enforcement. The Factories Act didn't appear until 1933 and it was bitterly opposed by many owners of mines and mills. Modern regulations exist today to prevent the tragedies of the past from happening again, they were hard fought for by workers and lobbyists, and in some ways we're still fighting to include the broader impacts work can have on an individual. [16:45] Addressing broader health and safety risks – This is in relation to harm accumulated over a lifetime of work with long-term and often fatal consequences. The suffering caused to workers exposed to hazardous conditions is immeasurable. For example, let's look at asbestos. The dangers of working with asbestos were recognised remarkably early, as far back as 1890s in France, and Asbestosis was formally recognised in 1930. This led to regulation in 1931, but only applying to the asbestos textile industry, excluding all the industries where its use was widespread such as construction, shipbuilding, anyone working in insulation etc Worse still, it wasn't even enforced! Then take mesothelioma, the distinctive and almost invariably fatal cancer of the lining of the lungs and abdomen. The connection between asbestos and mesothelioma was established in SA in 1960 when mining blue asbestos. Further research in the UK firmly established the link in the 60s. From the mid-60s, headlines were being made nationally when shipyard workers from the war era stared dying in large numbers. Unions began lobbying for protections and media coverage continued for years as cases multiplied across several areas and industries. Nevertheless, its manufacture and use continued. The Asbestos (Licensing) Regulations 1983 introduced licensing for the most hazardous asbestos removal work. Blue asbestos (crocidolite) was banned in 1985, followed by brown asbestos (amosite) in 1986, though white asbestos (chrysotile) remained legal until 1999. In the interim and since then thousands of people died and multiple legal cases have ensued. 2218 people died of mesothelioma alone in 2023. Altogether it's estimated that workplace-related lung disease and cancers kill as many 13000 per year in the UK. Several thousand more are known to die of non-lung-related occupational diseases each year, but these aren't recorded as workplace deaths on certificates, so these people aren't included in HSE annual reporting. It doesn't stop at deaths either, there is an argument for the detriment that certain work can have on quality of life. Incidents and conditions such as: ·      accidents causing amputation and fracture ·      eye conditions from welding and other light sources ·      Deafness and hearing difficulties ·      HAVS, vibration white finger ·      Skin conditions from exposure ·      Musculoskeletal in low risk environments None of these are terminal and so often go unreported.   [23:25] How to make Health & Safety manageable – Some consider modern health and safety regulations to be over the top, but overarching law in the UK has the principle 'As Far As Is Reasonably Practicable'. One common area is in risk assessment, The Management of Health and Safety at Work Regulations states: "Every employer shall make a suitable and sufficient assessment of— (a)      the risks to the health and safety Where the employer employs five or more employees, they shall record— (a)          the significant findings of the assessment" The keyword being 'significant' there. If you work in lower risk industries, you aren't being forced to make unnecessary risk assessments, only when significant risks are present do you need to complete a risk assessment. For more guidance, check out the HSE guidance on office-based risk assessments. [25:55] Ian poses a question: Can you seriously say that the drop in deaths and injuries suffered by the common worker would have dropped at the rate it has without regulatory intervention?  Can all employers (or other vested interests) be trusted to do the right thing through good will and voluntary mechanisms alone? If you'd like any assistance with your ISO 45001 Implementation or need any additional ISO Support, contact us, we'd be happy to help. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards 17.06.2026 33min
    Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There's a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode Ian is joined by Damian Edwards, Head of Standards at Wavenet, to dive into how they manage the mammoth task of maintaining seven ISO Standards, the challenges with managing multiple ISO certifications and what benefits they've brought to the business since implementation.   You'll learn ·      Who is Damian Edwards? ·      Who are Wavenet? ·      How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? ·      What is Damian's role at Wavenet? ·      How do Wavenet manage their ISO certifications? ·      How has ISO Support helped you over the past year? ·      What has Damian learned while managing ISO Standards? ·      What are the benefits of ISO certification? ·      Damain's top tip for anyone considering ISO Implementation   Resources ·      Wavenet ·      Wavenet Certifications ·      Blackmores – ISO Support Service ·      Isologyhub   In this episode, we talk about: [00:30] Episode Summary – We welcome Damian Edwards back onto the podcast to discuss how he maintains Wavenet's seven ISO certifications, and the explore the benefits gained from an integrated ISO Management System.   [03:05] Who is Damian Edwards? Damian is the Head of Standards at Wavenet, and has featured on the ISO Show before! One lesser known fact about Damian, is that he a 'Dance dad', supporting his daughter through all of her lessons and competitions. He's very proud of her latest achievement of qualifying for the World Championship for Irish dancing in her age group. [05:05] Who are Wavenet? Wavenet is an IT provider, providing IT network communications, security and resilience services. They are UK based with 1,600 employees based in their Solihull head office. Wavenet were formed in 2000, but have grown through acquisition, one of which was Damians previous company, Daisy Corporate Services. When Daisy was acquired, both businesses were of a similar size, so the process looked more like a merger in practice. A large part of that was uniting the ISO Standards managed by both businesses, so Damian had his hands full with ISO integration, amending audit schedules and managing extension to scope audits. [06:30] How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? One of the biggest challenges was the extension to scope that needed to happen due to the increase in sites. Thankfully, as Wavenet were used to acquisitions, they had dedicated acquisition project managers that assist with managing the integration. At the start, there are some teething problems as both businesses will still be using their respective processes for a while. However, once system that helped was a system called 'ServiceNow', which is where issue tickets could be logged, monitored and actioned in one centralised system. [08:15] What is Damian's role at Wavenet? Damian is the Head of Standards, which includes both ISO Standards and ESG related regulatory compliance. ISO certifications are more often than not a prerequisite or a condition of a bid over a contract, without them, Wavenet wouldn't win any business. They also create a foundation of trust for Wavenet's clients in the realms of Information Security, quality and environmental management. Wavenet are currently certified to the following Standards: ·      ISO 9001 Quality Management ·      ISO 20000-1 Service Management ·      ISO 27001 Information Security Management ·      ISO 22301 Business Continuity Management ·      ISO 45001 Health & Safety Management ·      ISO 14001 Environmental Management ·      ISO 50001 Energy Management In addition to maintaining all of these certifications, Damian also strives to utilise them to drive continual improvement within the business.   [10:30] How do Wavenet manage their ISO certifications? Damian is directly responsible for five of those ISO Standards, however there are some where he doesn't have the expertise to fully manage the requirements. ISO 27001 and ISO 45001 for example require skilled people at the helm, so Wavenet have dedicated managers to handle those areas. One of Damians key responsibilities is juggling all of the audits to make sure each element is covered, and he's put a lot of work into integrating those audits where possible to get the most out of their time and resources. Though, it's important to note that you can't integrate everything, as each standard will have some unique requirements. Areas that you can integrate however include elements such as: ·      Context ·      Audit Programme ·      Corrective Actions When you do have a lot of Standards, some elements can get watered down if you try to integrate everything. Policy for example, if you have five Standards and decide to integrate all related policies into a single document, it will become long and unruly, which will lead to people unwilling to read it. So, you have to take care to ensure focus on certain elements to make those more accessible for the staff that need it. Another aspect that needed additional consideration was Wavenet's risk profile, with their amount of sites and services, it's very varied. Too much for a single person to be aware of all the risks, which is where Damian's subject area experts can provide additional insight to fill the gaps. Damian is also keen to combine external audits where possible to both reduce cost and possible duplication of effort, as many Standard do share common subject areas, this can be done across multiple Standards. Certification Bodies are usually quite happy to work with you on this! Damians key take away is, that there isn't one solution that fits every business when managing this many Standards. It was a very trial and error process, especially with the ever changing landscape of a business, but Standards are also designed with flexibility in mind, so with the right people in place it's certainly manageable. [16:05] How has Blackmores' ISO Support helped? Blackmores has assisted Wavenet with their ISO 45001, ISO 50001 and ISO 41001 (Facilities Management) implementation. ISO 41001 was later dropped as it was no longer applicable for the business. Standards can be quite hard to apply to your own business when looking at them at face value, the requirements sound generic because they're designed to apply to every type of business. This is where Blackmores experience as a consultancy can help with interpretation and practicalities of how a Standard will apply to your way of working. Blackmores will also assist with internal audits, which help identify non-conformities that may have been missed if it were not for a fresh pair of eyes. As Damian states: "I would rather have them identified before an external audit" as this gives you a chance to resolve issues or put an action plan in place before it gets to that stage. Damain also reminds everyone to not be afraid of your auditor, internal or external. They are not maliciously looking for problems, they simply help to highlight issues which can be resolved sp you can improve as a business. No Management System is perfect, the important thing is that you can recognise when something needs addressing, and how you go about doing so. [19:30] What has Damian learned while managing ISO Standards? Damian has learned to not think of ISO as a tick box exercise, it's a tool to help businesses improve. He has also learned that you don't need to reinvent the wheel when Implementing a Management System. You likely already have much of what's required in place, but not monitored or organised regularly. For example, aspects such as 'Management Review' may already be happening in existing meetings with top management, you simply need to ensure these are minuted, cover what needs to be discussed in regards to the Management System, and make note of any gaps that need to be addressed. Businesses like Wavenet that have been in operation for 26 years know what they're doing, and are likely already following best practice. You don't need to restructure your business to meet an ISO Standard, but rather integrate the Standard requirements with how you already operate. If done correctly, it should become a simple part of your day-today tasks. Damian jokingly states: "What's my role? I sometimes say it's to do as little as possible", as the more a business is aligned with a Standard, the less you will have to do to upkeep that. [22:55] What benefits have Wavenet experienced as a result of their ISO certifications? As mentioned earlier, a lot of won business is due to ISO certification. Certain certifications are simply a tender or client requirement. Standards such as ISO 50001 tackle their energy consumption. It's focus on reducing that will inevitably lead to reduced business costs. Since implementing the Standard, Wavenet now have monthly meetings to monitor energy use, which gives them a good basis to make informed decisions on where energy use is concerned. Damian has found that over time, good practice has been so embedded that people are using it in their everyday behaviors without even realising it. He's heard people in their resolutions team use terminology like 'root cause' without knowing where it came from. He's seen team making use of skill matrix's when evaluating the competence of certain teams such as engineering for client visits. So, people within the business are using ISO terminology and techniques to ensure best practice without being explicitly asked to. It simply works as a method to drive the business effectively when implemented correctly. [26:15] Damian's top tip for aspiring ISO implementors: Apart from approaching a consultancy like Blackmores to help if it's your first time going through the process, it's got to be leadership commitment. Top management need to be actively promoting ISO within the business, and they should be involved with the process. You need everyone's buy-in to make a system work, and that is made much easier if it's driven from the top down. Another tip is that a Management System should be a team effort. It shouldn't just be the responsibility of one person, you need input from everyone in the business to ensure you've covered all angles and risks that could affect your business. Lastly, look at what you already have in place and try and integrate the Standard into that. Don't make more work for yourself if you don't have to, you likely already have the bones in place. [28:20] Damian's book recommendation: The Thursday Murder Book Club – by Richard Osmond [29:10] Damian's favourite quote? "Hard work beats talent when talent doesn't beat work hard." And: "You miss 100% of the shots you don't take" To learn more about Wavenet, check out their website and keep up-to-date with their latest news via their LinkedIn page. If you'd like any assistance with your ISO Implementation or need any additional ISO Support, contact us, we'd be happy to help. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification 10.06.2026 34min
    Watch the video interview here Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The drivers for this demand are varied, as is the approach many take for their path towards carbon verification. This can look very different depending on the industry you operate in and can be difficult to tackle for more service based industries, such as today's guest, Davies Group, who are a service provider for the insurance industry. In this episode Mel is joined by Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss the findings of Mel's thesis regarding the demand and drivers of GHG verification for organisations across the globe, and how Davies Groups' carbon verification journey factors into the findings. You'll learn ·      Who is Gillie Fairbrother and who are Davies Group? ·      What factor triggered the decision for independent carbon verification at Davies Group? ·      At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard? ·      What did Davies Group's GHG inventory and reporting look like before independent verification was introduced? ·      Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally? ·        ·      What is the gap between organisations knowing they should verify emissions and actually doing it? ·      Was competitive positioning part of the Davies Group case for carbon verification? ·      What was the most significant finding from the first carbon verification engagement? ·      How has verification changed the internal culture and engagement with the sustainability programme at Davies Group? ·      How have Davies Group supported suppliers with calculating their carbon emissions? ·      Where does Gillie see the expectations of institutional partners and large clients in insurance and professional services heading? ·      What was a specific moment where Gillie can recall that this mattered more than she had expected?   Resources ·      Davies Group ·      Davies Group LinkedIn ·      Carbonology – Carbon Verification Services   In this episode, we talk about: [00:30] Episode Summary – We introduce Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss their participation in Mel's thesis research into the demand for GHG emissions, exploring Davies Group's own reasoning and journey. [02:05] Who is Gillie Fairbrother and who are Davies Group? A route into sustainability as a career wasn't as readily available to Gillie when she attended university, so it has been something of a self-made path. She has previously run a wellness business in the past and has experience working with sustainable brands and has done a lot of cultural advocacy, particularly in the LGBTQ space. Taking the lead for ESG within the corporate space was a dream come true for Gillie, and she has done this for a number of US based tech firms to her current position for Davies Group. Davies Group are a service provider for the insurance industry, who operate in 22 countries. [03:40] What factor triggered the decision for independent carbon verification at Davies Group? Mel's research found that 29% of organisations cite market-driven factors as their primary reason for seeking GHG verification, compared with just 12% who cite regulatory compliance. For Davies Group, their decision was led by market demand. They looked client requests versus client contractual obligations, and carbon verification was increasingly coming up in those contractual obligations. Gillie herself has always been an advocate for working both sustainably and responsibly, promoting the revenue benefits that can be gained from doing so. However, as much as it is perceived to be the right thing to do, she doesn't want businesses to simply think of it as the 'nice thing to do'. These should be central components to how your business operates. So in part, Davies Group saw this demand not only in the market, but as simply the right way to do business. [05:30] At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard? Davies Group already operate in a highly regulated market, and so already have very strong governance practices in place. Gillie didn't really have to worry about making too many improvements in the governance or purpose aspects of ESG compliance. They participated in TCFD on a voluntary basis to highlight a possible risk from a climate perspective that could affect things like supply chain, physical sites, or the industry in general to leadership. Thankfully, the leadership saw this as a risk worth looking into more, and were willing to quantify it properly and ensure that their data was as accurate as possible and in a place where it could be audited by a 3rd party. [07:40] What did Davies Group's GHG inventory and reporting look like before independent verification was introduced? Before Gillie joined, these aspects were managed by a 3rd party due to lack of in-house expertise to manage it. When Gillie joined, she worked closely with that 3rd party to continue the work. Davies Group is quite a complex business, it operates with 3 different divisions that have multiple service lines. At the time, they did their best with the Excel spreadsheets that they had create to track various GHG emissions, but it was not as good as it could have been. They've since grown their processes, included more in-house talent and are doing more to gain knowledge from their stakeholders, data owners and building relationships with various teams across the business. While they are still working on Excel spreadsheets, they have advanced to reasonable assurance. Gillie is now looking into external tools to help improve their data management, but this would cost a fair bit of money that could be better used currently on reducing environmental impact. [10:30] Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally? Gillie cites employees, as they're an industry where 30% of the workforce is likely going to retire in the next 10 years, so they're trying to attract a younger group of talent who want to work for a business that has a good purpose and is a good company. Acting sustainably and responsibly is a huge part of attracting that new young talent. The second more important stakeholders are their clients. Davies Group is a private equity backed business, if they're not making money then they simply cease to exist as a business. Clients now have a keen interest in responsibly run businesses, and many now seek proof to claims. Next in the list is investors, who have an interest in the regulatory requirements that the business is subjected to. Lastly, Gillie cites suppliers as even if they aren't actively putting pressure on the business to report their emissions, without their support and cooperation, Davies Group can't meet their own goals. [12:40] What was a particularly memorable conversation with a Stakeholder that helped drive further improvement? Gillie recalls one conversation with a new employee where they asked to be more involved with their sustainability group. When she talked to them more, she discovered that one of the main reasons that employee sought them out was due to the responsible business page on their website, and that out of the 3 businesses they were applying to, Davies Group was the only one that had a page like that. [37:00] What is the gap between organisations knowing they should verify emissions and actually doing it? Mel's research found that 86% of organisations report increased stakeholder demand for transparency in GHG reporting – yet 52% remain unverified. Gillie states that there could be a lot of reasons for this, including budget, resourcing or something as simple as a piece of wording in a contract where a client might say we request versus we require. This is why Gillie is always in conversation with clients, whether that be the sales team or the sustainability teams at our clients, to understand their goals and make sure they can all align in their goals. The market is certainly the leading cause for many businesses as Government regulation tends to lag behind. [17:20] Was competitive positioning part of the Davies Group case for carbon verification? For Davies Group, it was initially a contractual requirement to complete their carbon verification. So, in their case, it was an easy decision as otherwise they could potentially lose business. However, Gillie also regularly meets with senior leadership and reports into their responsible business board committee every quarter. There they consider the growing appetite for sustainability driven demands, and how they want to leading the way in their industry. The key determining factor is whether it's relevant to them, whether that's for sustainability or for their community impact strategy. Davies Group tend to focus on education and investment in our communities, as that's where their expertise sits. It's all about materiality as businesses need to focus on what's relevant to them. [19:20] What was the most significant finding from the first carbon verification engagement? For Gillie, it was the clarity and transparency that had been game changing. Especially within their real estate portfolio. Davies Group don't own any of their offices, they're all leased. As they calculated and verified the carbon footprint, the quality of the data got better and that enabled them to have better conversations with their real estate team to understand how a building worked, whether it be a lease, including services or whether it be separate. As a result, they've been able to set a renewable energy target for all UK offices. [19:20] How has verification changed the internal culture and engagement with the sustainability programme at Davies Group? Mel's research identifies a strong correlation between verification status and organisational confidence, with 85% of verified organisations expressing pride in their sustainability progress, compared with 50% of unverified ones. Gillie's been writing the sustainability report for Davies Group for the past 6 years, and she can feel the difference after having their emissions verified as it adds an extra layer of credibility. She's also wary of stepping into bragging territory about all their sustainability achievements, without reflecting on the reality. There can be a conflict between writing what the stakeholders want to hear versus what is accurate and true. Having independent 3rd party verification gives you the confidence to back any claims made. [24:10] How have Davies Group supported suppliers with calculating their carbon emissions? Gillie is particularly proud of an industry wide collaboration project that had close to 100 SMEs go through a Net Zero training programme that was provided by a third party. Gillie joined many of the sessions and was so pleased to see sustainability champions emerge through the process where people suddenly got really invested and starting asking rather complex questions. They're still gathering feedback from those sessions, but already 80% - 90% have calculated a starting carbon footprint and put in place an action plan to help reduce their impact. This year, Davies Group have also kicked off a huge training and engagement plan with their service delivery teams who are making the decisions about their suppliers. They've also engaged with over 400 employees in their UK groups for property claims on sustainable solutions, getting their ideas, understanding the challenges and coming out with some outcomes so they can measure the carbon of their claims process and look to reduce it. Gillie teases the pending results, so keep an eye on their socials to find out more! [27:50] Key advice from Gillie: Focus your supply chain effort on your biggest emissions rather than your biggest spend, and tackle this in small groups. [29:30] Where does Gillie see the expectations of institutional partners and large clients in insurance and professional services heading – and at what point does she think verified GHG data becomes a non-negotiable baseline in your market? Many businesses have been waiting on legislation and regulations to point the way, and in a sense, they will always be waiting as these things develop with our understanding and technology available. However, businesses have done a good job of stepping up as those regulations lag behind. There's a lot of mixed press regarding sustainability, with some professionals feeling as if the topic has come off the boil as article cite the loss of dedicated sustainability officers. The reality on the ground is that these roles are now much more embedded into the business, they're not being removed, simply passed onto roles such as the Chief Operating Officer to ensure sustainability targets are being met. The bottom line is that the momentum for sustainability isn't going away, and that need to verify emissions is only going to grow. The key thing now is to move on from simple calculation into action, which is what Gillie is trying to drive right now.   [32:05] What was a specific moment where Gillie can recall that this mattered more than she had expected? Gillie is so proud of what their small and mighty team at Davies Group has done for their social impact. When initially established, they were only in 1 country, they've now expanded to 22 countries and they've really focused their resources, time and effort on impacting community education and skills development, which she anticipates will have a full circle around to attracting talent into our industry. To see more about the impacts that Davies Group are orchestrating, check out their LinkedIn page. If you'd like any assistance with your carbon verification journey, contact our partner Carbonology, they'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #250 Driving ISO Implementation – Meet the Consultant: Steve Mason 15.05.2026 56min
    How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That's not surprising as it's quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Steve Mason, a Principle isologist® at Blackmores, to share the journey of how he went from intern, to ISO Assessor, to ISO consultant and the challenges he's faced while working with clients. You'll learn ·      What is Steve's role at Blackmores? ·      What does Steve enjoy outside of consultancy? ·      What path did Steve take to become an ISO Consultant? ·      What is the biggest challenge he's faced when implementing ISO Standards? ·      What is Steve's biggest achievement?   Resources ·      Isologyhub ·      ISO 14001:2026 What's Changed And How to Comply Webinar Registration   In this episode, we talk about: [00:30] Episode Summary – We introduce Steve Mason, a Principle Isologist® here at Blackmores, to discuss his journey towards becoming an ISO consultant who specialises in ISO 27001, ISO 27701, ISO 27018, ISO 27017 and ISO 20000-1. [02:40] What is Steve's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. As part of that support, he: ·      Makes Standards understandable and accessible to clients ·      Conduct internal audits ·      Reviews and updates management system documentation ·      Facilitate management reviews ·      Train internal teams and prepare them for certification audits. Steve is the Standard champion for ISO 27001, ISO 27701, ISO 27017, ISO 27018 and ISO 20000-1 at Blackmores, but he also deals with ISO 9001, ISO 41001, ISO 22301 and ISO 42001 related projects and support. Steve's other main role at Blackmore's is as a Mental Health First Aider, which is shared with Minoo Agarwal. Together, they provide resources and offer support to the team. [06:00] The importance of Mental Health management in the workplace: Steve had faced bullying in previous roles, so preventing others from experiencing the same had become a big motivator for him taking on the role of Mental First Aider for Blackmores. He emphasizes it's importance, and highlights 2 key Standards that you can use to help support mental first aid within your business. This includes ISO 45003 Mental Health in the Workplace and BS 30480 Suicide and the Workplace. [09:10] What does Steve enjoy doing outside of consultancy?: Steve has a wide variety of interests and hobbies, including: Lay Minister: Steve is a Lay Minister in the United Reform Church and mainly based at the URC Chapel in Walkern, but can be found leading worship and preaching at Ashwell, Baldock, Stevenage and Knebworth chapels. Poetry: Steve enjoys writing poetry about anything and everything, racking up an impressive 190 poems so far. Some of his main inspirations include Wordsworth and Keats. If you ever see a poem on the Blackmores LinkedIn page, odds are, it was written by Steve! Classical Music: He's a fan of classical music, anything by Beethoven, Mahler or Shostakovich specifically. He likes these composers in particular due to their stretching of the rules of music for the time. Exploring hidden London: Steve often goes on hidden London tours which explore disused underground stations which may have been shut down as long as 100 years ago! Buses and Trains: Steve was lucky enough to drive a bus in his past, of which he has the licence plate of sitting in his office. He collects bus and train models and will go out to snap a photo or two of their real world counterparts when he comes across them. History: Steve is a huge mystery buff, with a particular fondness for Richard III and the War of the Roses and the Anglo Saxon period of history. Family Tree: Steve has been tracing his family tree back as far as he can on his mother's side, which extends as far back as 1547! Interestingly enough he found out that relatives from way back then got married in the church that he currently lives nearby and got qualified as a Lay Minister for the Church of England in Stevenage! Cats: He's owned his fair share of feline friends through the years, with one particular tabby holding the name 'Spartacus'. [22:35] What was Steve's path towards becoming an ISO Consultant?:  Steve was once told in the 1980s 'There is no future in Standards; find another career, perhaps in Sales or Purchasing'. How wrong that turned out to be! He's always worked with standards, from the first day he started work doing inspection in Goods Inwards, he was referring to them. The direction towards Management systems came in 1983 when he started implementing BS 5750. From that day onward he had been involved in Management Systems. Steve completed a management apprenticeship at Racal-Guardall where he was able to do 3 months' work experience in all departments, which helped him appreciate how companies function and how important it is to maintain good communication channels. He was at the end of this apprenticeship that the opportunity arose in the QA department to work on BS 5750. His career path has included other organisations such as Tektronix, BOC Ohmeda, Cirkit, Deta, TDK and BSI, all of which earned Steve a lot of experience in Manufacturing and Service and Distribution, mainly in Quality and Customer Service roles. Steve has always felt a bit like a closet consultant, even when he worked as an assessor at BSI. He feels as if Blackmores has enabled him to fully flourish and develop his portfolio of standards – not bad for a career where there was apparently no future in standards! [28:45] Born to be a consultant – Steve mentions that consultancy is a skill that many are born to be. You can train and learn the skills of course, but for some it comes very naturally and it can be hard to replicate that skillset in others. [30:15] What is Steve's favourite aspect of being a Consultant? Steve loves talking with clients and working with them to explore solutions that can address the requirements of the standards. His motto is 'Mould the Standard to the organisation and not the organisation to the standard' This means, always producing a management system that benefits the organisation first and then adjusting it to meet the requirements of the standard. Organisations that mould the business to the standard usually end up with a management system that is a 'bolt-on' and an uncomfortable, sometimes irrelevant, fit. Everyone in the organisation needs to feel that the management system is a natural fit to what they do. He also enjoys supporting his colleagues at Blackmores. We're a business built on knowledge sharing, and there's no point gatekeeping anything we've learned as a team. So consultants often get together to discuss lessons learned and ensure best practice is a shared experience. Ironically enough, one of Steve's least favourite aspects of being a consultant is auditing! Mostly since he's been doing it for some 40 years now, so he can be forgiven for finding the exercise a bit tedious at times. However, he never let's that affect the end result of an audit. [37:00] What Standards does Steve specilaise in and why? Steve initially started with ISO 9001 but was steered towards ISO 27001 and ISO 20000-1 during his time as BSI. This was based upon his career path up to the point he joined BSI as they align assessors to familiar business and technical environments. In Blackmores, he has been able to develop these areas of Quality, Service and Risk by adding standards related to Business Continuity, PII and Cloud Security, Facilities Management and AI Management. Steve's favourite standard is ISO 20000-1 which started off as an IT Service Management System but can also be used effectively for all services. He always refers to ISO 20000-1 as 'ISO 9001 on Steroids' because it is much more specific and focuses on the subject of service management. Sadly, ISO20000-1 is under rated, under sold and in some cases, never heard of – this is usually because contracts require IS O9001 but the people writing those contracts don't actually know or understand what they are asking for. In simple terms it is a Service Quality Management System and Steve has come across organisations which have shoe-horned ISO 9001 into the business instead of using the natural fitting standard ISO 20000-1. Steve would advise any company that is providing a service with helpdesk support to look at ISO 20000-1, especially if they find that ISO 9001 isn't working well for them. [43:00] What is the biggest challenge Steve had faced during a project and how did he overcome it?: Creating a management system in 10 days for a client which was due to lose a major contract because they had let their certification to ISO 9001 lapse between the 2008 and 2015 versions. Quite the undertaking in such a short amount of time! Steve refuses to claim full responsibility for the success however, as the client was totally invested in getting the system up and running and put in a lot of effort to work with Steve to get it done in time. If it had been any other standard, it would have been impossible, but because it was ISO 9001 and wthey were drawing on what had been in place previously it was possible. Generally, problems arise when there is limited or no Leadership support and commitment, because without this management systems can't be set up in a way that benefits the organisation. All management systems must align with the Business Strategy and should be used to ensure that the strategy is achieved. If you'd like to learn more about the importance of Leadership and aligning your management system with strategic direction, check out a few of our previous episodes. [50:10] What is Steve's proudest achievement?  Steve isn't really one to collect achievements, so he cites winning 1st Prize at 6 years old in a fancy-dress competition, dressed as a Snowman was a proud achievement for 6 year old him. He is also proud of becoming a Lay Reader initially in the Church of England at 37 and latterly in the URC. Another highlight is appearing on The Chase back in 2017, successfully passing the auditions which saw 40,000 applicants. If you want to go see him go up against the Chasers, he was in Series 10 episode 119. He can't point to any one ISO related project as he sees them all as an equal success. He puts all his effort into every project, and his success track shows this to be evident. [54:35] ISO 14001 Transition Webinar:  If you currently hold a 2015 certificate for ISO 14001, then the countdown has already started to transition to the latest 2026 version. We'll be covering the changes and what you need to do to comply and complete your transition in a webinar on the 29th May. You can register your place here.   If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #249 How To Meet Documentation Requirements Within ISO 28.04.2026 25min
    Most ISO Standards are designed with implementation flexibility in mind. They set the framework without specifying an exact method to meet requirements, giving businesses the freedom to implement them how they see fit. One of the key requirements you can't escape, however, is documentation. This is more than a list of key documents you must have in place, it encompasses how you develop, control and store documented information. In this episode, Ian Battersby dispels common myths around documentation in ISO, explains what the requirements actually mean in practice and how you address each one relevant to documented information. You'll learn ·      Common misunderstandings about documentation within ISO ·      What do current ISO Standards require for Documented Information? ·      How do you determine what should be documented information? ·      How do modern Standards embed a flexible approach? ·      What is considered 'documented information?' ·      Breaking down clause 7.5 Documented information ·      How to address clause 7.5.2 Creating and Updating documentation ·      How to address 7.5.3 Control of documentation ·      A cautionary tale for modern approaches to Documentation   Resources ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian dives into the topic of documentation within ISO, dispelling the myths and breaking down the requirements you need to meet relevant to documented information. [02:40] Common misunderstandings about documentation within ISO: Taking ISO 9001 as the prime example, the most common misunderstanding is that you need a policy manual. This is not true. This may have stemmed from previous versions of ISO 9001 where certain mandatory procedures were required, such as: ·      Control of Documents (Clause 4.2.3) ·      Control of Records (Clause 4.2.4) ·      Internal Audit (Clause 8.2.2) ·      Control of Nonconforming Product (Clause 8.3) ·      Corrective Action (Clause 8.5.2) ·      Preventive Action (Clause 8.5.3) There were also mandatory records such as Management Review, calibration, supplier evaluation, design/development reviews etc. With the introduction of the 2015 version of ISO 9001, the old terms 'Procedure' and 'Record' have changed into a single term now known as 'Documented Information', which breaks down those previous terms into the following: ·      Documented information to be maintained — Previously what would have been a procedure (i.e., describing how something should be done) ·      Documented information to be retained — Previously what would have been a record (i.e., evidence that something was done) [05:10] What do current ISO Standards require for Documented Information? The 2015 version of ISO 9001 received the following updates: ·      Removed the prescriptive language associated with the old terms ·      Gave organisations the flexibility to develop, control and store documented information ·      No longer dictates the form that documentation must take In practice, many people still use the terms procedure and record informally, because they are well understood and conveniently descriptive. But beware using language that reinforces old-fashioned ideas about how we create management systems. This newer language aligns with modern risk-based thinking, with direct references made to this being included in the Standard. But, while that sounds prescriptive, adopting risk-based thinking has allowed a less prescriptive approach to the standards. It allows you to consider what's significant to you and so you can plan your system accordingly. [07:20] How do you determine what should be documented information? The effort you put into documenting something must be consistent with the risk If, for example, a process is important, if its outcome could be in doubt, if it's complex to control, if it could lead to damage/harm, if there's a regulatory requirement, then you should put some effort into documenting how it's performed. But, if you maintain that documentation in response to the risk to your organisation and not in response to a prescriptive demand in standard, and if a process attracts less risk, then you can deliver it with less formality and less documentation to be maintained. The same goes for retaining documentation to evidence that you've done what you should. In short: more risk, more documentation retained to demonstrate that you've controlled it. [08:30] How do modern Standards embed a flexible approach? ISO Standards are deliberately flexible. The extent of documented information required depends on the size of your organisation, the complexity of your processes, your customers' needs, your regulatory environment and the competence of your people. An organisation of only 10 people will have very different needs compared to one of 10,000, and both can fully conform to the standard. It's about proportionality, not volume. [09:20] What is considered 'documented information? ISO standards don't care what you call the documents you maintain in order to govern how you deliver your daily work. Other than using the term process (and the process approach) to underpin how systems should interrelate, ISO 9001 doesn't specify anything else. Would you like to use the term procedure?  Or management procedure? Or SOP? Work instruction? Process map, guide, playbook, manual. Or is your activity embedded in an online system? A workflow? A board? It doesn't matter, you can call it what you want, and as long as it's controlled to the extent that it needs to be. [11:05] Breaking down clause 7.5 Documented information: ISO 9001 states: "7.5.1 General: The organization's quality management system shall include: a) documented information required by this International Standard; b) documented information determined by the organization as being necessary for the effectiveness of the quality management system. NOTE The extent of documented information can differ from one organization to another due to: ·      the size of organization and its type of activities, processes, products and services; ·      the complexity of processes and their interactions; ·      the competence of persons." This reinforces the fact that there is no 'one size fits all' approach. [12:15] How to address clause 7.5.2 Creating and Updating documentation: The Standard states: "When creating and updating documented information, the organization shall ensure appropriate." Note that word, 'appropriate'.  It doesn't indicate specifics, it indicates that you should choose certain things according to your own circumstances So the appropriate things which you should ensure are: Identification and description:(e.g. a title, date, author, or reference number) One trap many fall into, is the use of reference numbers. In most cases they are unnecessary. Only use them if they mean something or make life easier. Having reference numbers with department numbering can reinforce the silo mentality; 'that's their procedure, not ours', so it's best to avoid creating that situation by foregoing reference numbers if possible. What matters is that any users are able to easily verify that they have the right document, this can be done with a descriptive title, version numbers and a date for the version. Online documents may have details embedded in metadata or an information box that can make this process easier to implement.   Format and media: You'll need to consider language required for certain documentation, as international systems where there are multiple languages used by the workforce, may require additional versions. You'll also need to establish which templates or layouts to use. Look and feel will likely be important in the organisation, so you'll want to keep documents on brand. Other considerations include: ·      The use of process maps, flowcharts, diagrams, tables, or written text. ·      The software or application it is created in (e.g. Word, PDF, SharePoint) ·      Whether the document is paper-based or electronic Review and approval for suitability and adequacy: Documented information requires appropriate review of content, this is to make sure it does what it should and that all of the above is covered. You will also need sign-off by someone with the appropriate authority, and that authority is determined based on risk related to that document. [18:00] How to address 7.5.3 Control of documentation: Let's break down each part of this clause: "To ensure that a)    it is available and suitable for use, where and when it is needed;" - It must be circulated, hosted, displayed or whatever, so that those people who are required to see it, use it, know of its content can act on it. "b) it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity)." - It must be protected so that only the right people see it, so that any confidential information is not inappropriately shared, and no one can use or amend it without the appropriate authority. This is to ensure it remains in the manner it was intended and that its content can't be altered, corrupted or destroyed. "7.5.3.2 For the control of documented information, the organization shall address the following activities, as applicable: a) distribution, access, retrieval and use; b) storage and preservation, including preservation of legibility; c) control of changes (e.g. version control); d) retention and disposition." This clause adds some meat to the ideas discussed already "a) distribution, access, retrieval and use;" – This refers to who receives a document and by what means, whether the right people can access it and know what to do with it at the time they need it, while also considering the sensitivity. "b) storage and preservation, including preservation of legibility;" - The physical or electronic location of storage and its usefulness over time. You'll need to ensure that physical things are safe from damage (fire, flood etc) and that electronic formats are protected from obsolescence. "c) control of changes (e.g. version control)" - Who is allowed to edit, authorise, publish, issue and host a document. Establish a method of ensuring only relevant, current information is accessible by the right people, and record the history of changes where necessary. "d) retention and disposition." – Ask yourself: how long should documented information be kept? What's useful? What's regulatory? What does the customer want? What do you do when you don't need it any more? What do you do to prevent access to obsolete information? [22:30] A cautionary tale for modern approaches to Documentation: These days, we're seeing more and more systems relying solely on electronic documentation.  This brings big advantages, but also risks. While there are excellent methods for document control in all sorts of hosting, sharing, collaboration platforms, they still need to be managed. Too often we see systems with multiple versions of similar documents, naming disasters, obsolete versions, poor formatting, lack of authority, breaches of confidentiality, and the simple inability to find what you want! Modern systems can help with documented information, but they don't remove the need for managing documentation. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #248 How To Address Risk Management Within ISO 15.04.2026 38min
    Most ISO Standards take what's known as a 'risk-based approach', which focuses on proactively identifying and mitigating potential risks while capitalising on opportunities. The methods for managing risk can be very varied, and many make the mistake of treating it as a separate task rather than as an integrated part of your existing processes. In this episode, Ian Battersby explains what risk management means in regard to ISO management, what this looks like in practice and breaks down different methods you can utilise for effective risk management. You'll learn ·      What is risk? ·      Where is risk referenced in ISO Standards? ·      How do you identify risks and opportunities? ·      How can you document risks and opportunities? ·      What does a Risk Register look like? ·      How are risks categorised? ·      How many risks should you document? ·      How do you evaluate and rate risks? ·      How do you address opportunities? ·      How can ISO 31000 help? ·      How different ISO Standards define their relevant risks ·      Governance and risk management   Resources ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian dives into the topic of risk management within in ISO. Explaining what risk is, how they should be documented and evaluated and what methods you can use to do so.    [02:45] Further info on risk management: If you want more guidance there is a dedicated risk management Standard (ISO 31000). [03:10] What is risk? Risk, as defined by ISO Standards is: "An effect of uncertainty on objective. An effect is a deviation from the expected. It can be positive, negative or both, and can address, create or result in opportunities and threats" So important to note that this includes both risks and opportunities. [03:40] Where is risk referenced in ISO Standards? The main risk related requirements can be found in Clause 6 Planning for most ISO Standards: 6.1 Actions to address risks and opportunities - There's a positive and a negative aspect mentioned right from the start. However, these elements aren't relegated to a few clauses. ISO Standards are built on a 'risk-based approach', which is directly mentioned within the introduction: "This International Standard employs the process approach, which incorporates the Plan-Do-Check-Act (PDCA) cycle and risk-based thinking Risk-based thinking enables an organization to determine the factors that could cause its processes and its management system to deviate from the planned results, to put in place preventive controls to minimize negative effects and to make maximum use of opportunities as they arise." While it is prescriptive, it does allow flexibility for businesses to determine what risks are significant to them. Other places it's mentioned in Standards includes Leadership: "Top management shall demonstrate leadership and commitment by: d) promoting the use of the process approach and risk-based thinking" It's not just about adopting the risk-based approach, leaders have to promote it. The use of the word 'shall' indicates that this is not optional and cannot be delegated. [08:10] How do you identify risks and opportunities? The Planning clause directly references clause 4, which is Context of the organisation. Within that clause, businesses are required to think about the things which affect the way you operate, the world in which you work, the people and organizations you must consider, the obligations placed upon you. One key activity that typically happens at that stage is a SWOT and PESTLE, that's not specified by the Standard but it's a very popular method of identifying your risks and opportunities against multiple areas. The results of which can be fed back into Clause 6 Planning when it asks you to consider and do the following:- ·      Give assurance that the system can achieve its intended result(s); ·      Enhance desirable effects; ·      Prevent, or reduce, undesired effects; ·      Achieve improvement. ·      Plan actions to address these risks and opportunities; ·      Integrate and implement the actions into its system processes; ·      Evaluate the effectiveness of these actions. This is where you have the freedom to determine what significant risk means to your business. This also establishes the approach to risk management as proactive rather than reactive. [13:15] How can you document risks and opportunities? Just because you need to determine risks, you don't necessarily need a risk management process or methodology based on the guidance in a standard like ISO 31000. There's no requirement to even have a risk register! However, we do strongly recommend using one. If you choose not to use one, you could document each risk individually with the plan of action to mitigate it. This is fine, but a register allows you to see what's happening across all risks. It allows comparison of different types, different categories, across different parts of the organisation, at different levels. It can support decision making and allocation of resource where there's competition for that resource. It can prompt escalation and more significant management attention where it's needed. It can also form a basis for reviewing the effectiveness of your processes. So, while not a firm requirement, it can be a very useful tool. [15:20] What does a Risk Register look like?: A typical Risk Register usually sits in a table or Excel document. You can number your SWOT and PESTLE findings and put them into this Risk Register. One of the columns included is interested parties affected by it, e.g. the risk that your processes deliver the wrong product directly relates to your customers; the risk of enforcement may relate to your board; the risk of terrible PR may affect your investors; the risk of polluting may affect the local population, enforcement agencies etc Certain standards also require you to determine compliance obligations associated with each interested party, so that may be useful to add as a column. Then, you need a column for detailing what the impact of the issue is (remember, both positive and negative). Then you need to evaluate each entry, this involves measuring the significance, the size and scale. When evaluating risks, you need to indicate which processes you have in place that control the risk.  Then you need to rate the risks in their current (do-nothing) form. This is where it helps to have a register where different types and categories can be judged alongside each other, so you'll be able to see what's really important in one place. An organisation needs to decide what level of risk it's prepared to accept; this may be a straightforward decision where a specific value triggers escalation and action, but it may be more complex, depending on the organisation you are in and the environment in which you operate. If the risk is acceptable, should you still commit resource to addressing it; there's a balance in reducing risk overall; is it an easy win?  Is it easy to do? If you feel you should address a risk, what method of risk treatment should you adopt? The actions you propose to take should then be set out in proper detail: who will do what by when?  What resource?  Basically detailing the measures to assess effectiveness.  If a risk or a group of associated risks require an objective, state clearly and link to that objective. [21:35] How are risks categorised? The types of risks you will be focused on will depend on the ISO Standard you're implementing. For example, for ISO 9001 this will be the ability to consistently deliver the best we can to our customers. For ISO 45001 the ultimate aim is to protect your workforce from harm. Regardless, you can get quite broad with the nature of your risks, including considerations such as the ability to fund right equipment and infrastructure; or any investment in a sustainable future; the competence of personnel; the safe working environment to deliver products/services; compliance with relevant legislation; forces affecting our market; stability of supply chains; reputation; social attitudes to work, technology etc But, regardless of whether you're certified to a multitude of standards, operations are typically so interdependent that you can't separate financial risks from operational ones etc. [23:55] How many risks should you document? It's easy to get overwhelmed by generating a huge register when you're a small organisation, but you should be realistic. Focus on what's really significant. If you do a SWOT/PESTLE, if it generates lots of issues but not everything has to be treated as a risk and opportunity for the risk register.   First, ask yourself, what will actually have an impact on you if it materialises?  What is beyond control or influence?  What requires just monitoring? A larger organisation will tend to generate a larger register, but this can be categorised in different ways: ·      Split by functions ·      Split by category (operational, safety, compliance, financial) ·      Significance; operational vs strategic or corporate ·      This can be done by the scale of the risk, any risk above a specific threshold could be escalated to the strategic level ·      There could be factors in the risk evaluation which include strategic significance ·      There could be specific subjects (eg, compliance) which you automatically escalate to a strategic level [25:55] How do you evaluate and rate risks? There are lots of complex and sophisticated ways of doing this. Certain sectors, industries, processes have specific needs and ways of evaluating risk. But, if you're new to this, or there aren't such complexities to consider, a very simple methodology is best. Keep to a simple matrix of consequences and likelihood. Consider what the impact would be if the risk materialised, and rate these from 1 to 5: 1 = the consequences are not significant, it would only be a slight impact on the organisation, minor disruption, small financial loss, little/no physical harm. 5 = the consequences are disastrous, it could materially affect the way the organisation operates, it could cause serious physical harm, it could lead to severe financial loss, it could totally prevent us delivering our products/services. Now consider the likelihood of the event occurring, again rating these from 1 to 5 That could be qualitative evaluation: ·      1 = very rarely ·      5 = happens regularly, or it's certain to happen OR, it could be more quantitative ·      1= once in ten/five years ·      5 = daily/weekly Then multiply these numbers and plot them on a matrix. The matrix will then provide a visual heat map that indicates the level of risk and inform about the level of resource you should apply to addressing the risk. [29:15] How do you address opportunities? You can also evaluate opportunities in a similar manner. Rather than assessing negative consequences, you consider the positive impacts on the organisation when an event occurs. These are plotted in the same way on a matrix, but with appetite and tolerance rather than consequences and likelihood. Risk appetite can be defined as 'the amount and type of risk that an organisation is willing to take in order to meet their strategic objectives'. These appetites range from averse, cautious to an open, eager appetite. For example, a public sector risk appetite example could a local council adopting a "cautious" approach to financial management while having an "open" appetite for innovation in digital service delivery. This balances the need for fiscal responsibility with the desire for improved efficiency, often accepting higher risks for long-term environmental or social gains. Risk tolerance is the actual threshold that you can get away with, that your organisation can bear before action / escalation is needed; financial, operational, reputational, enforcement. This concept may not be for you if you're at an early stage of development, but one to keep in mind. [32:00] How can ISO 31000 help?  If we feel we should address a risk, what method of risk treatment should we adopt? ISO 31000 Risk Management Guidance suggestions include: ·      Avoiding the risk by deciding not to start or continue with the activity that gives rise to the risk; ·      Taking or increasing the risk in order to pursue an opportunity; ·      Removing the risk source; ·      Changing the likelihood; ·      Changing the consequences; ·      Sharing the risk (e.g. through contracts, buying insurance); ·      Retaining the risk by informed decision (no influence, cost too great) [33:40] How different ISO Standards define their relevant risks: ISO 45001 states: "The organization shall establish, implement and maintain a process(es) to: a) assess OH&S risks from the identified hazards, while taking into account the effectiveness of existing controls; b) determine and assess the other risks related to the establishment, implementation, operation and maintenance of the OH&S management system" ISO 22301 Business Continuity states: "The organization shall implement and maintain a risk assessment process. The organization shall: a) identify the risks of disruption to the organization's prioritized activities and to their required resources; b) analyse and evaluate the identified risks; c) determine which risks require treatment." Be careful not to confuse these types of risk with organisational, system risks. [36:05] Governance and risk management: A Risk Register is not a static document. It need to be reported on regularly, such as during Management Review meetings. The register itself isn't evidence of good risk management.  It's how you use it to demonstrate that your actions have addressed risks and opportunities which counts. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #247 How do ISO 27001 Information Security and ISO 42001 AI Management compare? 01.04.2026 23min
    Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year. The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.   Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do these two compare, and is there merit in implementing both? In this episode, Ian Battersby is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to discuss what ISO 27001 and ISO 42001 are, the main differences between the Standards and how they can complement each other when integrated.   You'll learn ·      Who is Bas Von Hertom? ·      Who are TUV Nord? ·      What are ISO 27001 and ISO 42001? ·      How does ISO 42001 support regulatory frameworks such as the EU AI Act? ·      How do ISO 27001 and ISO 42001 differ in managing information security risks? ·      Other key differences between ISO 27001 and ISO 42001 ·      How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? ·      Can ISO 27001 and ISO 42001 be integrated? ·      What organisations should be implementing both Standards? ·      How are Certification Bodies quoting for ISO 27001 and ISO 42001? ·      Bas's advice to leadership teams looking to build a case for full certification   Resources ·      TUV Nord ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to explore the differences between ISO 27001 and ISO 42001 and the benefits of integrating both Standards. [02:30] Who is Bas Von Hertom? Bas is the Cyber Security Specialist at TUV Nord. He is a lead auditor for Standards including ISO 27001, ISO 42001, TISAX and standards specifically for industrial automation. Bas had once stated around 5 years ago that he would never pursue a career in auditing, but once he came into contact with TUV Nord he decided to give it a go. Before joining TUV, he was a very hands-on systems administrator and many of those skills transferred well into auditing. [04:45] Who are TUV Nord? TUV Nord are a UKAS accredited Certification Body. They also offer services for testing and inspection. TUV have worked with a large range of sectors, from manufacturing and energy to IT, healthcare and even space. [06:25] What are ISO 27001 and ISO 42001? ISO 27001 is the Standard for Information Security Management, with compliant management systems being called an ISMS. It provides structure for identifying, assessing, and managing risks related to the information security while also ensuring availability and resilience on the information security. ISO 42001 AI Management is a much more recent Standard, being published in December of 2024. It focuses on ethical and effective AI management, with a system that applies to relevant products in addition to the wider business. [07:30] How does ISO 42001 support regulatory frameworks such as the EU AI Act? The EU AI Act sets out legal obligations that organisations offering AI products must comply with, however it only defines the rules rather than providing any implementation guidance. This is where ISO 42001 can fill the gaps, by providing a framework that will meet these regulatory requirements. [08:45] How do ISO 27001 and ISO 42001 differ in managing information security risks? Both Standards take a risk-based approach to their subject matter, but the nature of the risks that each address are what differ. ISO 27001 focuses on risks that relate to the protection of information assets based on confidentiality, integrity and availability of information. It's also ensures that business objectives are clearly defined and aligned with business strategy. ISO 42001 on the other hand deals with a broader and more complex set of risks, because it also looks at ethical considerations. This can includes the monitoring and measurement of ethical risks such as AI bias and discrimination. It also looks at societal, legal and reputational risks as one of ISO 42001's key values is creating trust within the AI space. [10:10] Other key differences between ISO 27001 and ISO 42001: Besides their subject matter, another key difference is the way objectives are framed and evaluated. In ISO 42001 these objectives have to be aligned with the Annexes within the Standard, which is something not commonly done when implementing ISO 27001. ISO 42001 also requires an 'AI Impact Assessment', which again, aligns with the systems objectives as the results of the AI Impact Assessment will describe the way bias, ethical and societal considerations impact other requirements within ISO 42001. [11:00] How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? If you already have ISO 27001 in place, you have a strong foundation for ISO 42001. ISO 27001 puts the fundamental base in place, with a governance structure, risk assessment processes, internal audits, corrective actions and methods for continual improvement. There's a lot of overlap where the high-level requirements are concerned. However, ISO 42001 also looks at AI products and services, which differs from ISO 27001.   ISO 42001 may also require additional training for those involved with the management systems and the AI products and services. [12:15] Can ISO 27001 and ISO 42001 be integrated? Yes, and in fact, Bas highly encourages it! If you intend to implement both Standards, it's much more efficient to do so as an integrated management system. They both utilise the Annex SL format, a high-level structure that's shared with most ISO Standards, so they're designed to be integrated. This also saves on duplication of effort where documentation is concerned and also potentially on cost if you require additional support with implementation. [13:30] What organisations should be implementing both Standards? Both ISO 27001 and ISO 42001 can apply to any business. Most businesses are now utilising AI in some form, and ISO 42001 can apply to those using it just as much as it does to those developing their own AI tools or selling related services. However, sectors where ISO 42001 will likely become fundamental include the financial sector, where AI tools for fraud detection are becoming popular. There's also a growing need for it within the medical field as AI is increasingly used for research and development. [14:30] How are Certification Bodies quoting for ISO 27001 and ISO 42001? There are a number of variables that Certification Bodies use to work out certification costs, these include size of the organisation and business complexity. This can be tricky to calculate for ISO 42001 as you need to consider the amount of AI systems used before you can provide a quote. The full requirements for this are described in ISO 42006, which is a guidance Standard. Most certification bodies will offer a discount for the combined certification to both Standards. An integrated approach is certainly something that Bas recommends, in addition to ensuring that you keep the same auditor or audit team throughout the implementation. By having one team for both systems, you can complete combined internal audits to save on time and resources.   [16:20] Bas's advice to leadership teams looking to build a case for full certification: First of all, don't wait, just make a start. A lot of businesses make the mistake of waiting until it's a common requirement within their market, which can leave you lagging behind the curve. Instead, strive to be one of the early adopters as that will give you a strategic advantage in the market. This is especially the case if you already have ISO 27001 in place. You already have the foundational knowledge to implement ISO 42001, so just make a start on looking at risks relevant to ISO 42001. Many businesses opt to implement certain Standard due to the demands of their clients, and ISO 42001 is likely to be added to that list. So it's better to get a head start! Bas also recommends finding sources of guidance on ISO 42001 implementation. Whether that's sourcing training or an external party to advise, it's good to have other sources of knowledge of you're not familiar with the Standard or ISO implementation as a whole. [21:30] Bas's favourite quote: We don't rise to the level of our expectation, but we fall to the level of the systems that we use. If you'd like to find out more TUV Nord or are looking for ISO 27001 and ISO 42001 certification, check out their website. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #246 Pedalling Towards Purpose – Forests Journey To B Corp Accreditation 19.03.2026 24min
    Watch the video interview here Europe is only partially on track to meet its 2030 environment and sustainability objectives, and while some objectives are being scaled back, we are seeing the introduction of more regional regulations that require tangible annual sustainability reporting.  Businesses that have built sustainability into their way of working from the start are leading the charge and defining what it means to operate responsibly. As with today's guest, Forest, an e-bike provider that is not only 100% powered by renewable energy but has also achieved the coveted B Corp Accreditation. In this episode, Mel Blackmore is joined by Laura Elms, VP of Sustainability & Corporate Affairs at Forest, to discuss how they embedded sustainability from the start and explore their journey towards B Corp Accreditation. You'll learn ·      Who are Forest? ·      Who is Laura? ·      Why was B Corp important to Forest from the start? ·      What other Standards do Forest currently hold? ·      What does Forest's higher B Corp score of 99 mean in reality? ·      How did Forest embed sustainability into a business from day one rather than retrofitting it later? ·      How has Forest balanced growth with genuine environmental accountability? ·      What does tackling Scope 3 look like in urban mobility? ·      Why did they also attain Verra Validation, and why does third-party validation matter? ·      How do sustainability, communications and public policy intersect in Laura's role? ·      Advice for those seeking B Corp Accreditation ·      B Corp Version 7 ·      What role do you think sustainable transport should play in helping cities to meet their net zero targets?   Resources ·      Forest ·      B Corp Accreditation ·      Carbonology   In this episode, we talk about: [00:30] Episode Summary – Mel is joined by Laura Elms, VP of Sustainability & Corporate Affairs at Forest, to explore how they lead the way in sustainability including insight into their journey towards B Corp Accreditation. [01:10] Who are Forest? Forest is the only shared E-Bike operator to power its entire fleet with 100% renewable energy. It's also one of the world's first micro-mobility companies to have B Corp Accreditation and Verra Validation. [01:40] Who is Laura and how did she get involved with sustainability? Laura admits that she had a rather non-linear approach to getting into sustainability. She started her career shortly after graduating in financial communications and investor relations. Working in her first firm, she worked closely with a women called Caroline who went on to found Forest along with two other co-founders. Caroline reached out to her 2 years after starting Forest and Laura felt it was a no-brainer as she had a pre-existing interest in sustainability, and had come to prefer the start-up space over a more corporate setting. As is typical with the nature of start-ups, Laura wore many hats from the outset as it was a small team of four. Sustainability was what she was most passionate about, and has been the area she nurtured for Forest over the course of her six years working with them. [03:40] Why was B Corp important to Forest from the start? Laura noticed that B Corp was gaining traction back when Forest started in 2020. She was curious about the intersection between B Corp and ESG, particularly from a start-up perspective. When starting at Forest, she knew it would be a significant benefit to utilise renewable energy, but she felt like they needed to go above and beyond that. From there she researched B Corp and the costs involved, which were affordable as it's relative to your revenue, which is a great advantage to start-ups. She was pleased to find that Forest could cover the 5 pillars of B Corp's credentials, not only providing bikes for urban settings but also providing excellent governance and additional benefits to their surrounding community, workers and environment. In short, B Corp helped set the foundations for a good well rounded company that could grow. [05:15] What other Standards do Forest currently hold? Forest currently hold ISO 9001 certification and are looking to implement ISO 14001 in the near future. They currently operate within 18 boroughs in London, and are expanding from one central hub to several more warehouses, which is what will be covered under that ISO 14001 scope. With B Corp as their guiding North Star, they're confident they have all the right foundations in place to grow as needed. [06:10] What does Forest's higher B Corp score of 99 mean in reality? Within B Corp there are 5 pillars: ·      Community ·      Environment ·      Governance ·      Customers ·      Workers Its core focus is sustainability, but its approach is much more holistic and similar to the way ISO's implement a system that encompasses how a business works rather than just a siloed focus on one area. B Corp looks at a multitude if areas, such as: ·      Reducing Scope 1, 2 & 3 emissions ·      Looking at your supply chain ·      Evaluating how your activities interact with your stakeholders To earn a B Corp score, you need to get certain marks and then you're scored across the 5 pillars. Many businesses going for B Corp tend to do well in the sustainability area, but they struggle with other areas such as workers and customers. The framework is designed to be more holistic than simply focusing on sustainability, so If you focus too much in that area, it may come at a detriment to the other pillars. [08:20] How did Forest embed sustainability into a business from day one rather than retrofitting it later? Sustainability was Forest's vision and mission right from the start. Their CEO and Founder had previously worked at a ride-hailing company called Cabify, and had led the Latin American operations there. Cabify was the first mobility company to offset all its emissions, this was prior to 2020 so it was seen as though-leader in the space. This inspired the now CEO of Forest with the concept of 'Human Forest', which was the idea that humans on bikes in a city can save CO2 by choosing bikes over carbon emitting modes of transport. Having it as a core part of the business from the start meant they didn't have to worry about budgeting road-blocks or additional approval. It was simply a part of the brand. Laura can see why retrofitting the same level of sustainability commitment may be difficult for other businesses, as Forest had already baked in the price of renewable energy from the beginning and didn't have to worry about that transition. Forest do differ in that unlike other larger companies that will be showing smoother trajectories towards net zero, they're already there. They face the unique challenge of keeping it there as they grow, as more bikes and available geographical locations means more manufacturing and bigger scope 3 emissions. So their transition to net-zero will overall look a lot less linear. [11:15] How has Forest balanced growth with genuine environmental accountability? Forest have managed to reduce their carbon footprint by 53% year on year, even with their continued growth. Tackling environmental accountability can be something that gets businesses stuck in a rut, especially with any applicable regulations. As Laura quotes, often perfection is the enemy of good. Small incremental changes are better than trying to get it all right first time. In Forest's case, to achieve that 53% reduction they looked at a more creative solution. Rather than manufacturing brand new bikes when needed, they reached out to the wider e-bike market to those that utilised their same manufacturer and asked if they had any spare bikes. This helped to massively bring down emissions that would have otherwise been created making new bikes, by accessing a second-hand market. This can't be done indefinitely, but it's a small action that has created a large impact for that year. Forest have also worked with manufacturers to help switch to using solar energy for the production process, which they are now monitoring to see how much this reduces emissions by.   [13:50] What does tackling Scope 3 look like in urban mobility? Scope 3 for most businesses is their biggest source of emissions, typically accounting for around 80-90% of a businesses total emissions. For Forest this is closer to 100%. They've also noticed that compared to 3 years ago, the emissions are slightly less for things such as production and shipping of bikes. Laura admits that this may not be entirely due to the processes themselves getting more efficient, but as by-product of improving other areas such as technology or use of office spaces to help bring down the businesses overall emissions. At this stage, it's getting the methodology right for scope 3, to ensure their data is as accurate as possible. This includes sending questionnaires to suppliers and making use of technology to improve data gathering and analysis. [15:45] Why did they also attain Verra Validation, and why does third-party validation matter? Laura at the time was looking to ensure the highest level of credibility possible, which started with B Corp, ISO certification and then Verra Validation. Verra was a leader in this space, and dominate the market in terms of carbon offsetting. Forest didn't want to go through the whole process to sell offsets with Verra as it didn't make sense for their business, but they did want the validation as another layer of credibility. [17:45] How do sustainability, communications and public policy intersect in Laura's role?  London, unlike most other major cities, does not have a single unified body, instead you have to negotiate borough by borough. Each one has the option to pick different operators and set their own requirements, which adds an extra layer of difficulty on top of existing sustainability regulations. Forest provided the perfect solution for various London boroughs who sought to reduce their overall carbon emissions. [19:05] Laura's advice to organisations seeking B Corp Accreditation: Get in contact with B Corp itself. They done a lot to improve their platform, and there's a lot you can do via the portal without their assistance. However, B Corp and their team at B Lab can give you more insight and context for the data they're looking for. She also recommends that you incorporate B Corp as early on as you can as it helps to set a solid business foundation. Laura also recommends going beyond the B Corp portal after certification to reach out to the wider B Lab community, as there are a lot of fantastic brands to connect with. B Corp will often host in-person networking meetings where certified businesses can catch-up, review progress and share new ideas. [20:40] B Corp Version 7: B Corp have recently released (as of podcast publication) a new version of their requirements, raising standards once again. One of the new requirements includes verification of an organisations' emissions, which includes products. Forest only just received their B Corp re-authentication in December 2025, and their next focus is obtaining ISO 14001 for their new warehouses. However, they do intend to stay B Corp accredited, so will likely look at meeting version 7 requirements following that. [21:45] What role do you think sustainable transport should play in helping cities to meet their net zero targets?: Transport makes up a third of UK emissions. Getting people onto more bikes and being more active will result in a significant reduction in emissions for our cities. When Forest asked their users: what would you otherwise have done in terms of transport if you didn't get on one of our bikes, 11% said that they would have gone in a car or a taxi. So an 11% modal shift, which is pretty significant! This doesn't account for private bike owners either. For cities, there's a big push to get HGVs off the road and to retrofit spaces to accommodate for more cycle traffic. It's a lot to consider and will require a lot of work, but with transport making up a third of total UK emissions, it's worth the effort for the benefits it will bring. If you'd like to find out more about Forest and follow along with their journey, check out the Linkedin page.   We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #245 What's The Difference Between TISAX and ISO 27001? 04.03.2026 23min
    For those in the automotive industry, namely suppliers working with European OEM's, you're likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from. ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two. For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don't intend to certify to both. In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers. You'll learn ·      How does TISAX differ from ISO 27001? ·      How does the recertification / annual surveillance for TISAX and ISO 27001 differ? ·      Can a company have TISAX without ISO 27001 and vice versa? ·      How can an existing ISO 27001 certification be leveraged for TISAX? ·      What are the additional benefits of implementing both TISAX & ISO 27001? ·      What is a reasonable timeframe for implementing TISAX? ·      The key role of Internal Audits ·      How can Blackmores support companies in implementing TISAX? Resources ·      Register for our TISAX webinar here ·      ENX ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.   [03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association. It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers. [04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry. ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations. The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them. [05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle. TISAX does not require an annual Surveillance like ISO 27001, instead once you've earned a Label it remains valid for 3 years. ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit. If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal. Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label. [07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you're ready for re-certification. You can of course carry on with annual internal audits to make sure you're on track. This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.   [08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other. Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised. However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it's worth considering implementing both TISAX and ISO 27001. [09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you're already 80% of the way there to TISAX compliance. As TISAX is based off of ISO 27001's Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for: ·      Data Protection ·      Prototype protection ·      Assets ·      3rd Party Suppliers The amount of additional work will also depend on the TISAX Level you're aiming for, with Level 3 being the most demanding for these specific requirements. [10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include: Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations. Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what's required to earn and keep both your ISO certificate and TISAX Label. Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM's to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident. Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX. [12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc. The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you're ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check. If you already have ISO 27001 in place, than you're looking at between 3 – 6 months. If you do not have ISO 27001 in place than you're looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it's all been communicated and the relevant individuals have been trained. Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment. Emma's top tip: Be honest in your self-assessment. It's there to be a benchmark, and you need to reflect on the reality of your position if you're to accurately assess what Level you are ready to be assessed against. [14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001. The Leadership ultimately drive TISAX's success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label. For those within the Automotive Sector, TISAX is becoming an absolute requirement. It's being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label. [16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you're on the right path. They can help identify areas which may be non-conforming or simply highlight opportunities for improvement. For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.   [18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step. This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards. Other options include: ·      Assisting with your TISAX self-assessment (aka a Gap Analysis) ·      Conducting a Maturity Assessment ·      Conducting internal audits ·      On-site support during your TISAX assessment audit We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you. [21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment. Attendees will also get access to some freebies. So don't delay, register your place here today. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #244 What is TISAX? 25.02.2026 30min
    The modern automotive industry faces many new challenges, as vehicles evolve with more complex data requirements and supply chains become increasingly interconnected, major Original Equipment Manufacturers (OEMs) require certain Standards as a mark of trust from potential suppliers. Currently, this trust is codified in TISAX (Trusted Information Security Assessment Exchange). For businesses that have not previously dealt with Standards, TISAX can be seen as a daunting regulatory hurdle. However, a TISAX label is more than a compliance check, it's a recognised mark that your organisation has robust information security measures in place specific to the automotive industry, including considerations for protecting key intellectual property and prototype innovations. In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore what TISAX is, who it applies to, what it requires and how OEM's and automotive suppliers can take their first steps towards earning a TISAX label.   You'll learn ·      What is TISAX? ·      Who is TISAX applicable to? ·      Why is TISAX important? ·      What are the 3 assessment levels within TISAX? ·      What are the 3 different subject areas within TISAX? ·      How is TISAX implemented? ·      Why does TISAX use labels instead of certificates – and how can people verify these? ·      What is the ENX portal and how does this help with supplier onboarding? ·      Where should companies start if they want to earn a TISAX label?   Resources ·      Register for our TISAX webinar here ·      ENX ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Emma Coxhill joins Ian to dive into the topic of TISAX, including who it's applicable to, why it's important and how businesses can make a start on earning a TISAX label. [03:40] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association. It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers. [04:40] Who is TISAX applicable to? While applicable to the automotive industry, it encompasses quite a lot of businesses within this. This is because is applies to any organisation that handles sensitive data relating to vehicle development, manufacture and marketing. So, this can include any company providing car parts, vehicle software, cloud services, testing labs, engineering etc. Basically, any service providers to OEMs (original equipment manufacturers) will be applicable. TISAX can also be applicable for those dealing with automotive related events, marketing and photography, as new models are protected IP and will require related business to prove that they have the correct security requirements to ensure any potential prototypes are protected. [06:50] Why is TISAX important? Mainly, it gives the automotive industry a trusted, standardised way to ensure information security across the entire supply chain. Without it, the OEMs and suppliers can conduct their own audits, but it'll be their own interpretations or what is considered an adequate level of security. The industry saw this as an open door to chaos, so TISAX was created to protect highly confidential automotive information and support compliance with relevant data protection laws. However, now it's not so much a 'nice to have' Standard as it is a requirement to trade, especially within Europe. It's fast becoming a tender requirement, and many OEMs won't make it past the procurement process without a valid TISAX label. The ENX portal, where labels are registered, can also help speed up the on-boarding process. So, the whole TISAX system has been built for ease of access to help manufacturers choose suppliers that prioritise information security. [09:00] What's the consequence of not having a TISAX label? A loss of opportunities. Those within the automotive industry that don't have a valid label will be seen as a security risk, leaving them at a competitive disadvantage. [10:30] What are the 3 levels within TISAX? Unlike ISO 27001, TISAX has levels that depend on the level of data sensitivity that you're dealing with. Level 1: Self-assessment – Considered as 'normal risk' with general processing of data. Level 2: Remote Audit – Applicable to those dealing with confidential information such as design documents or internal projects. This requires both a self-assessment and an audit. Level 3: On-site Assessment – Highly confidential information, so this applies to those dealing with sensitive research, development information or prototype data etc. This requires a physical on-site assessment, as the qualified TISAX auditor will need to ensure that you have the appropriate physical security measures in place. Most businesses will require level 2, but if you're looking to work with high-spec OEMs, then level 3 is more desirable. [12:00] What are the 3 subject areas within TISAX? The 3 main areas are as follows: Information Security: This covers general information security controls such as relevant policies, access controls, risk management, incident handling and secure operations. Prototype Protection: This focuses on safeguarding physical and digital prototypes, design data, test vehicles and confidential development information. Data Protection: This ensures proper handling of personal data in line with legal requirements such as GDPR. If you're just doing a self-assessment, you can pick the areas which are most relevant to you. If you've been requested to earn a TISAX label, they will usually provide you with their preference on subject areas. Many will opt to take information security, but data protection is also quite common. The prototype section is more specialist and not applicable to all businesses. [14:00] How is TISAX implemented? There are a few stages to gaining a TISAX label: Awareness – Learn the requirements for TISAX and planning for the project ahead. This may include asking your clients about what they expect of your from an information security perspective and working out costs for assessments and any additional support. The ENX website has a lot of really useful info, including a handbook and a copy of the self-assessment. Preparation – This is where you need to complete your TISAX scope and register yourself on the ENX portal. Your scope needs to specify your selected level (1,2 or 3) and the subject areas you'll be focusing on. You also need to include the locations within scope, which have to be listed one by one (not simply 'all offices in the UK' for example). Self-Assessment – The template for this can be downloaded from the ENX website. This is essentially a Gap Analysis that grades your current level of compliance with the TISAX requirements. It includes a scoring mechanism, where you'll be aiming to get a 2.71, as that's the pass rate. This self-assessment will highlight what gaps you need to fill before going ahead with an external assessment. Implementation – This is where you will bridge those gaps highlighted in the Self-assessment. This will involve creating the required documentation requested by TISAX and updating existing systems to align with requirements. Before going ahead with external assessments, we highly recommend you conduct some internal audits to ensure you're ready. External Assessment – Whether this is remote or on-site, you need an official TISAX auditor to perform the assessment. A list of approved TISAX auditors is available on the ENX portal, we recommend getting a few quotes to get the best price. We also recommend requesting a kick-off meeting so you can have a chat with your auditor about the requirements and how they'd like to review the required evidence of compliance. The Assessments are similar to that of an ISO certification, it's broken down into 2 segments. One is a document/evidence review and the other is done with both parties present to go through their findings, review further evidence and to question any gaps found. Again, similar to ISO, you may receive either minor non-conformities, non-conformities, opportunities for improvement or observations in their final report. If you get any non-conformities, you'll need to provide an action plan within 2 weeks following from your assessment to address them. You will then be allowed a few months to implement the corrections, which will be reviewed and approved by the auditor before receiving your label. If you only received opportunities for improvement then you'll get a label straight away. [20:40] Why does TISAX use labels instead of certificates – and how can people verify these? Taking ISO 27001 as a comparison, that certification has a blanket framework that can apply to every business. While you can exclude small bits, the vast majority applies to everyone. TISAX is more scaled based on the level of security you're dealing with. Businesses can pick both different levels and different subject areas for their Label. Another key difference is that Labels can only be verified through the ENX portal, this is where other TISAX clients can see who has what Label, including the details of level and selected subject areas. Business can still chose to state TISAX compliance on their website, but the details regarding the level of compliance only need to be seen be relevant individuals. [22:05] What is the ENX portal and how does this help with supplier onboarding? The ENX portal is accessible through the ENX website. It does require a fee to make an account, but this is where everything related to TISAX is managed. This is where you will upload your scope and findings and it's where Labels are assigned and documented for suppliers to search for. There are options for how much information you want to disclose within those public searches, allowing you to select the need for contacting for further information. The ENX portal can help massively in reducing the amount of supplier questionnaires you need to fill in, as those looking for automotive suppliers will simply look up your TISAX Label to verify if you have the required level of security to continue with the procurement process. [24:50] Where should companies start if they want to earn a TISAX label? If you're just diving in, we recommend you do some research first to fully understand what you're expected to do to earn a Label and how much the process will cost. Next you'll need to define your scope, so look at what sites need to be included and identify relevant client requirements in relation to TISAX. This is to ensure you're going for the right Level and subject areas. Next evaluate your internal resource for the project and related budget. As mentioned, you will need to pay to register on the ENX portal and you need to consider Assessment costs and any additional support costs should you need consultancy services. You'll also need to assign individuals to manage the project, which will include completing the self-assessment, updating your policies, procedures and documentation to align with the requirements and possibly conduct training if required. This isn't a 2 week project, realistic timescales will vary, but generally if you're starting from scratch you're looking at 9-12 months. If you have ISO 27001 in place already this could be reduced to 6-8 months. As with anything Standard related, leadership commitment is a big factor as you'll need their help and support to ensure the projects success. If you need additional help, reach out to consultants such as Blackmores to help guide you through the process.   [28:05] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment. Attendees will also get access to some freebies. So don't delay, register your place here today. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #243 How Can You Leverage AI for ESG and Sustainability Reporting 18.02.2026 47min
    Watch the full video interview here Annual sustainability and ESG reporting is now becoming a necessity for many businesses, whether driven by region specific regulations and legislation, industry expectations or client demand.  However, doing so is definitely easier said than done. It requires a complex network of data being gathered from multiple sources which then needs to be collated, analysed and summarised in a cohesive report for leadership and possible public publication. Thankfully, there have been developments in new AI driven technology that can help ease this annual burden, allowing you to focus on utilising the results to make meaningful sustainability impacts. In this episode Mel Blackmore is joined by Darayush Mistry, Head of Product at Pulsora, to discuss how AI can make a difference in ESG and sustainability reporting, including its benefits, pitfalls and the balance of utilising AI while considering its environmental impact. You'll learn ·      Who is Darayush? ·      Who are Pulsora? ·      When did Darayush realise how AI could be utilised for ESG and sustainability reporting? ·      What are the positives of AI in this space? ·      Why is AI for ESG and sustainability reporting becoming more necessary? ·      What are the risks involved in using AI for ESG and sustainability reporting? ·      Where is AI making a real difference in reporting? ·      What parts of ESG and sustainability reporting need human judgement? ·      How does AI help collate data from multiple sources? ·      How might regulators react to AI being utilised in reporting? ·      How can businesses utilise AI while still considering it's environmental impact? ·      Darayush's advise to sustainability leaders looking to explore AI solutions   Resources ·      Pulsora ·      Darayush Mistry ·      Carbonology   In this episode, we talk about: [00:25] Episode Summary – Mel is joined by Darayush Mistry, Head of Product at Pulsora to discuss the use of AI tools in ESG and Sustainability reporting, how you can leverage this technology and what risks you need to be aware of before doing so. [02:40] Who is Darayush Mistry? Darayush has been working with enterpirise software for the past 2 decades. This technology is used by companies to help operationalise their business. He began his career at a company called Siebel Systems, which operated in the CRM space, spending 10 years there before moving onto the world of sustainability. Darayush recalls how everyone was so used to working from a set of spreadsheets just 20 years ago, whereas now most will use a central CRM for business operations. This is an area that sustainbilty reporting seems to have lagged behind, with many still trying to collate their data from multiple spreadsheets and other external sources rather than having a dedicated central system. This is why he was eager to work with Pulsora, to bring similar solutions to businesses as he once had with CRM's in the past. [05:25] Who are Pulsora? Pulsora are an AI-forward SaaS (software as a service) platform. The Pulsora platform helps businesses to operationalise their sustainability initiatives, which includes data collation, calculation and reporting features. This is set up for scope 1, 2 and 3 level reporting, with considerations for climate related goals, waste water monitoring, biodiversity and policy oriented information. Darayush's role as Head of Product means he sits at the intersection between customers and Pulsora's engineering and design teams. His job is to ensure that whatever Pulsora created ultimately provides value to their customers in the form of successful sustainability outputs. [07:50] When did Darayush realise how AI could be utilised for ESG and sustainability reporting? Darayush can pinpoint a time four years prior when he first stepped into a more sustainability focused role, speaking to the co-founders of Pulsora back in 2021 they were sharing experiences of using the then early versions of AI tools such as ChatGPT and Gemini. It clicked for them then that they could do something similar for sustainability reporting, making it as easy as possible while still being accurate. It wasn't until 2 years later that they had a product to launch with Pulsora AI in late 2024. This initial product allowed users to write long from narrative responses for carbon disclosures. Regulations like CSRD require a comprehensive disclosure, but not everyone is an expert in parsing the data to write that, so Pulsora AI helped get past that writers block, to give people the building blocks for that professional disclosure. [11:55] What are the positives and negatives of AI in this space? The biggest benefits include: ·      Giving professionals and sustainability teams more time back to achieve their desired outcomes. ·      Cutting down on spending time in spreadsheets and on calculations on an annual basis. ·      Reduction of repetitive tasks ·      Ease of data collection from multiple sources and locations ·      Ease of data calculation ·      Allowing for pre-audit of data using AI tools ·      Highlighting data gaps when rationalizing the data [17:20] Why is AI for ESG and sustainability reporting becoming more necessary? People are starting to move on from the mindset of 'Let's try AI' to 'Let's use AI'. Time is one of the most precious resources we have, and any tool that can help accelerate more mundane tasks so that people can focus on making results happen should be a priority. Sustainability teams are under increasing pressure to produce tangible results, something that can be made easier with the help of AI tools. [20:06] What are the risks of using AI in ESG and Sustainability reporting? Don't treat AI as this magic wand, it's a tool you can leverage. At the moment, it's good at certain tasks, but it cannot act on its own.    In order to progress, sustainability teams need to push on the initiatives to produce results. People know their business best, and though AI can infer certain information and produce a result, it may not always be the best solution for you. You still need that human input into areas such as strategy and action planning. Darayush reminds us of Amara's Law: "We as humans severely overestimate technology outcomes in the short-term, and severely underestimate that in the long-term" Don't fall into the trap of thinking AI can do everything. [22:30] Where is AI making a real difference in reporting? Data collection, ad-hoc sustainability reporting and providing insights into the data provided. It can also help with providing a starting point for carbon disclosures or options for various strategies that you could explore. Currently, the biggest one is data collection, as it can help do this efficiently and consistently, allowing for improved accuracy in your overall sustainability data. [25:20] What parts of ESG and sustainability reporting need human judgement? Darayush states that these are complementary to each other, it should never be all of one and none of the other. There will be elements that need more human in the loop and areas where it's required less. It's applicable in degrees. One example of where the human input will be higher is in completing a materiality assessment and figuring out how to execute your decarbonisation strategy, which will require your knowledge and experience of how the business operates, it's core values and what your ultimate goals are. AI can do the heavy lifting in areas such as sustainability reporting, as it can collate all the data and create initial reports very fast. But, at the end of the day, humans still need to understand these outputs and provide their own judgement. 'AI' today isn't true AI, they're LLM's with a great capacity to collect data, analyse it and provide outputs that can be starting points. It cannot replace human judgement, as we provide the nuance in context and experience needed to apply those results effectively. AI responses operate in a perfect world where everything is an easy step by step process, which we all know does not reflect reality. [29:40] How does AI help collate data from multiple sources? Older technologies like OCR (optical Character Recognition) was the go to years ago when scanning various different documents like spreadsheets, PDF's, receipts etc. This required specific code to be written to read these docs accurately, this would then feed into pipelines to bring this data together. This code was quite rigid, so any changes to document layouts would cause things to break. AI in comparison is much more adaptable, it's capable of reading much more natural language and extracting what's required for its designated task. It also provides a much more friendly UI (user interface), meaning you don't need an IT specialist to utilise the technology. [33:15] How might regulators react to AI being utilised in reporting? Based on Darayush's previous experience in the finance sector when people were using dedicated platforms for financial reporting, the regulators didn't care where the data came from or how it was collated, they just card if it was accurate.  Regulators want transparency, accuracy and a big part of this is providing an audit trail so they can see where the data came from. They simply want businesses to follow their guidelines, the how you get from A to B is of little importance so long as the result is accurate. If anything, the existence of these tools will raise the bar of expectations from regulators, as businesses should be able to provide the required information with these tools readily available. [36:30] How can businesses utilise AI while still considering it's environmental impact? – AI can certainly aid the sustainability industry in certain areas, such as reporting, but it's a resource intensive tool. It consumes a lot of energy and water. Like with most emerging technology, the sustainability impact usually isn't addressed until much later. Much like with mobile phones, which create tonnes of E-waste every year, not to mention the mined material required to make them. It's factors like this which eventually get regulators involved to help reduce the overall harm caused. AI is yet to go through this evolution, but both regulator and consumer pressure is building to reduce the impact of AI. This will inevitably lead to innovation as companies seek to find more sustainable ways to cool data centres and reduce the resource burden. On the flip side, AI can help save energy in other ways, such as time taken to complete the tasks for a human, which will include travelling to an office and amount of time they use a device for the task. This also has its own carbon footprint, which can comparatively be reduced by using AI to complete the tasks in minutes as opposed to hours or days. The bottom line as of the start of 2026 is, we know there is a resource issue when it comes to AI, and companies are looking at better ways to address it as the technology develops. [42:20] Darayush's advise to sustainability leaders looking to explore AI solutions – Identify a problem space where you can apply AI in a measured way an start using it. The only way you can find out how it impacts you is to use the technology.   Currently, AI shines is areas such as collating data from multiple sources and locations, so if that's an issue you're tackling where sustainability reporting is concerned, that's a good place to start with utilising AI.   If you'd like to learn more about Pulsora, check out their website.   We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #242 Surface Print – The Commercial Advantage of ISO 14001 for SME's 11.02.2026 25min
    A Standard like ISO 14001 may seem more appropriate for large enterprises looking to address their environmental footprint, however it can apply to any business no matter the size. All businesses produce waste, and we can all do more to save energy, resources and money in the process. For some SME's, tackling resource wastage through effective environmental management can make a huge difference. Such is the case for today's guest, Surface Print, a family owned wallpaper manufacturer managed by its 4th generation. In this episode, Ian Battersby is joined by James Watson, Managing Director of Surface Print, to discuss why they implemented ISO 14001, the related resource challenges for SME's seeking ISO Standards and benefits gained from certification. You'll learn ·      Who is James? ·      Who is Surface Print? ·      Are there any other Standards Surface Print have to adhere to as a wallpaper manufacturer? ·      Did those other Standards help with understanding the process for ISO implementation? ·      What was the driver behind ISO 14001 implementation? ·      How long did it take them to achieve ISO 14001? ·      Have they considered any other ISO Standards? ·      What were the challenges for an SME seeking ISO certification? ·      What were the benefits of implementing ISO 14001? ·      How have Surface Print leveraged ISO 14001 in marketing and communications? ·      James' top tip   Resources ·      Surface Print ·      James Watson   ·      Isologyhub ·      What is the Isologyhub?   In this episode, we talk about: [02:05] Episode Summary – Managing Director of Surface Print joins Ian to discuss their journey towards ISO 14001 certification, the challenges involved with ISO implementation for SME's and the benefits felt after certification. [03:25] Who is James Watson? James Watson is the Managing Director of Surface Print, a wallpaper factory that is a family-owned business based in Lancashire. Both he and he sister are the current directors, he 88 year old father is still involved within the business. They are the 4th generation in their family to be involved with wallpaper, starting with their great-grandfather, Walter Watson, who started the business all the way back in the 1880s! [04:35] Who are Surface Print? Surface Print operate in both analogue and digital printing, with 10 large analogue printing presses and 6 state-of-the-art HP digital presses. They have two elements to the company, with Surface Print handling 3rd party printing and white labelling for interior design brands. The second is 1838 Wall Coverings, which is the original design branch that sells their designs worldwide. Surface Print are not a volume printer, they focused on high-quality manufacturing with a key focus on attention to detail. All the manufacturing occurs at the UK factory. Their typical clientele include the likes of John Lewis, Harrods and other high-end interior stores. Their 1838 Wall Coverings branch recently had a collaboration for the past 3 years with the Victoria and Abbot Museum in London, where they were allowed access to their archive for inspiration on designs. [07:35] Are there any other Standards Surface Print have to adhere to as a wallpaper manufacturer? Mainly it's the Construction Products Regulation EN 15102, which is specifically for construction products used in buildings. They also needed to get FSC certified as they were dealing with paper and wood pulp. [08:20] Did those other Standards help with understanding the process for ISO implementation? James quite honestly admits that no, none of the previous mandatory regulations helped with understanding the ISO process. As they understood that it was going to be quite the task, they outsourced help from Blackmores to assist with implementation. Alison Henshaw from our Team worked alongside Surface Print's ISO committee to break down the Standard and offer valuable consultancy on aspects such as legislation.   [09:05] What was the driver for ISO 14001 Implementation? Wallpaper manufacturing is very heavy waste. Analogue machines can have up to 10% - 20% waste per production order. With that much waste, it can quickly make the entire process very inefficient. There was also the spend on energy and gas to consider as all of those prices are increasing year-on-year. ISO 14001 could solve both of these issues while saving them a significant amount of money. [10:15] How long did it take Surface Print to achieve ISO 14001? In total, around 12 months. It would have been quicker, but there were some administration issues with the Certification Body that delayed the final Assessment.   [11:55] Have Surface Print considered any other ISO Standards? As they're only just into their first year of ISO 14001 certification, they've opted to stay focused on maturing that system before opting to go for any other Standards. [08:20] What were the challenges for an SME seeking ISO certification? Surface Print initially struggled with the administration side of ISO 14001, things like keeping on top of document and process updates, updating the legal register etc. This is where Blackmores Consultant Alison came in to bridge the gap and ensure they kept all the necessary paperwork up-to-date. They also needed more technical expertise in the area of environmental management. Their ISO committee weren't ISO experts and so there was a gap of knowledge between understanding the ISO Standard and how to apply it to the business, which is where Alison helped once again to guide them on their journey. [13:35] What were the benefits of implementing ISO 14001? Their ISO 14001 certification affects every decision made. It's not just about environmental management, it's about managing your business as a whole. The Standards actively require leadership commitment, so it starts from the top down. It's led to a more cohesive structure to making business decisions and thinking from a more environmental perspective. There have also been cost savings. Manufacturing in the UK is generally very expensive, so the more environmentally focused you can be results in savings on energy and resources. For example, Surface Print use a lot of electricity for both the machines and drying process involved in wallpaper manufacturing. They now measure their monthly energy usage against the rolls of wallpaper produced. They also installed solar panels which saved them a significant amount of electricity usage over the last year. They're also investing in newer equipment to help with efficiency, making plans on how to reduce gas usage. It's also helped with their general business administration as documentation needs to be kept up-to-date. The whole process is now a lot more thorough, and has greatly improved their general monitoring and measurement processes. They also have confidence in their regulatory and legal compliance, as ISO Standards have this as a basic requirement. Many opt to use a Legal Register to help keep all this information in one location. Surface Print also found that they can answer client questions quicker due to the amount of documented information at their fingertips, this now includes more environmental based questions, which are cropping up more often.   [18:35] How have Surface Print leveraged ISO 14001 in marketing and communications? Surface Print often get asked by potential brand clients 'What's the benefit of working with you?', to which they can answer with a sustainability statement which lists all of the benefits. The first point of which is ISO 14001 certification, which is a globally recognised mark of effective environmental management. They ensure that their environmentally conscious stance is first and foremost in marketing and external communications. This is not done out of a forced obligation, Surface Print have chosen to do the right thing, which is becoming the norm. To not think about the environment, especially in high-waste industries, is generally frowned upon. [20:25] James' top tip for those thinking about implementing an ISO Standard – ISO implementation can cost a fair amount up-front, but the cost saving benefits within a year can supersede that investment. You will see a lot of big improvements at the start, once your system matures you can expect to see those improvements slow in rate while still driving continual improvement at a steady pace. With the addition of effective monitoring and measurement, those improvements are quantifiable, so you can really see the results of your investment. [23:25] James' book recommendation – Guinness Book of World Records [23:55] James' favourite quote – "You can take a horse to water, but you can't make it drink" If you'd like to learn more about Surface Print, check out their website. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #241 Raise your Game With The Leadership Powerup Gameplan 28.01.2026 16min
    An ISO Management System can't survive without Leadership engagement. It was seen as such an essential aspect that 'Leadership commitment' became a key requirement of many ISO Standards back in 2015 when the Annex SL format was adopted. It's easy to see why. An effective Management System will provide vital information for top management to make decisions on processes, policies and strategic direction. So, how do you get leadership involved with your ISO management system? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss why leadership involvement is so crucial to effective ISO management, and explains how you can get their buy in whether you've got a mature system or are newly implementing ISO Standards. You'll learn ·      What is the isologyhub? ·      What issue is the Leadership Powerup tackling? ·      Who is the Leadership Powerup aimed at? ·      What are the six steps in the Leadership Powerup Gameplan?   Resources ·      Isologyhub ·      What is the Isologyhub? ·      The Integral Role of Leadership within ISO ·      Aligning Objectives with Strategic Direction   In this episode, we talk about: [02:05] Episode Summary – Blackmores Service Improvement Manager joins Steph on this episode to talk about the crucial role leadership plays in ISO management, and how you can get the most out of their involvement. [00:45] What is the isologyhub? The isologyhub is our online learning platform for all things ISO. Its main feature is the ISO Roadmap, a 7-step guided approach to implementing your own bespoke ISO 14001 compliant Environmental Management System. Since it's creation, it's grown to hold a library of over 200+ ISO related resources. The content available varies from quick accessible content such as ISO templates, ISO handbooks and short from video training we call Coffee Break Training which explain key elements of ISO Standards. This goes onto more in-depth content such as our ISO Pathways which take you through 3 levels of learning to help you progress from Learner to leader in your chosen subject area. There's other exclusive content on there which you can dip into, including ISO templates, training videos and previous workshops covering topics such as ESG and AI management. We also have a number of Gameplans, which are essentially guides where people can work through a particular set of information about a topic and get practical guidance that can be applied within their own organisation.   [02:05] What issue is the Leadership Powerup tackling? In the past, it was quite easy for leadership to lose interest in the Management System once it had been implemented. This was in part due to how Standards used to be written, and would result in the system being delegated to specific individuals. In 2015 this, along with a number of other issues, were addressed and a new clause structure was introduced. This means that Leadership Commitment now isn't optional, as it's a direct requirement of all ISO Standards (Clause 5 typically).   The Leadership Powerup Gameplan aims to help leadership understand their role in making the Management System effective for the wider business. It helps to assess their current level of commitment and guides you through a path of improvement to get them to be a positive ambassador for the Management System. Where leadership is concerned, it's important to remember that you're leading by example. If you don't care about the Management System, why should anyone else? For those that want more of a deep dive on Leadership's role within ISO, check out a previous podcast. [06:05] Who is the Leadership Powerup aimed at?: As a minimum it should be the individual or team that have day-to-day responsibilities relating to the management system. Ideally you would also want a member of leadership, as you'll need their input to gauge the current level of commitment. [06:50] What are the six steps in The Leadership Powerup?: Step 1: Evaluate Leadership – For this step it's important that you're 100% honest in your reflection of how leadership are currently promoting and engaging with the management system. It includes a workbook to help you self-score, though we recommend getting a team involved who can help shape a full perspective their engagement in reality.  The included workbook also contains examples of key causes for a lack of leadership engagement. It walks you through the reasons for these causes, as it's only through understanding why something is happening is when you can seek to resolve the issues. Step 2: Boosting Knowledge - This section works through what good looks like in terms of effective leadership commitment. You need to be able to understand the ideal end point before you can plan on how to get there. Included in this section are key definitions and videos that break down what good looks like for leadership commitment. Step 3: Planning Your Process – During this step you will plan on how to reach your end goal. By this point you will have assessed your current level of leadership commitment and you will have a good idea of what good looks like. Included in this step is another workbook that will guide your planning process to answer the following questions: ·      What do you want to achieve by the end of the Gameplan? ·      What does good leadership engagement look like for us specifically in this business? There's also a helpful section on understanding how processes interact, which is a fundamental part of ISO management. It's about how your business operates as one big system and not as siloed departments and processes. Having leadership understand that big picture so that they can communicate that impacts to certain teams does affect the whole business. Step 4: Deliver Data – This section is all about information. Leaders love data as it helps them to make informed business decisions. This step guides you through what sort of data you should be gathering and how it can be presented to leadership. This is crucial as it links back to one of the fundamentals of quality management, that being data-driven decision making. This could be in the form of customer feedback or employee feedback, or in other metrics such as health & safety incident etc. It's all about making the most of this data. Step 5: Strengthening Strategy – It's very important that your ISO management system aligns with your businesses' strategic direction. This is a key way that you can get leadership involved in the management system, as the business direction will already be a key focus for them. Ensuring the management system not only aligns but helps to facilitate that will ensure that it stays at the forefront of their minds. This step provides you with guidance on how to go about aligning leadership priorities and management system priorities. Step 6: Consolidating Compliance – This step is about ensuring that you are doing what you say you're doing. The key part of leadership involvement includes leading by example, such as reviewing policies and updating them if they are no longer working for the business. It's about continuous review and implementation of key feedback and communication of changes happening within the management system from top management down. This Gameplan can be useful for businesses where the Management System has been in place for a while and may not require their direct attention once certification has been achieved. In order to drive effective continual improvement, it's key that they still keep that management system at the core of their activities. It can also be helpful when there is a change in leadership, and new individuals may not know what their level of involvement should be.  If you'd like to become a member of the isologyhub, we have an exclusive 20% discount available for listeners, simply Contact Us and quote: Isologyhub20 to claim that discount. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #240 Revitalise your Audits with the Audit Accelerator Gameplan 21.01.2026 16min
    Internal Audits are a key part of any ISO Implementation journey, they are also a necessary vehicle to drive continual improvement. For those with more mature ISO Management Systems, it can be easy for Internal Audits to become a bit of a rinse and repeat exercise. This can lead to stagnation of meaningful results, especially if you're asking the same people the same questions year on year. So how can you revitalise the Audit process? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss the challenges associated with repeated internal audits, and how you can refresh the process to ensure you get meaningful results to drive continual improvement. You'll learn ·      What is an Isologyhub Gameplan? ·      What issue is the Audit Accelerator tackling? ·      Who is the Audit Accelerator aimed at? ·      What are the five steps in the Audit Accelerator Gameplan?   Resources ·      Isologyhub ·      What is the Isologyhub?   In this episode, we talk about: [02:05] Episode Summary – Blackmores Service Improvement Manager joins Steph on this episode to talk about the challenges many face when completing internal audits in an annual basis, and how these can be refreshed to ensure valuable output.    [00:45] What is the isologyhub? The isologyhub is our online learning platform for all things ISO. Its main feature is the ISO Roadmap, a 7-step guided apprach to implementing your own bespoke ISO 14001 compliant Environmental Management System. Since it's creation, it's grown to hold a library of over 200+ ISO related resources. The content available varies from quick accessible content such as ISO templates, ISO handbooks and short from video training we call Coffee Break Training which explain key elements of ISO Standards. This goes onto more in-depth content such as our ISO Pathways which take you through 3 levels of learning to help you progress from Learner to leader in your chosen subject area. There's other exclusive content on there which you can dip into, including our full workshop recordings which have covered topics such as utilising ISO Standards for ESG compliance, how to integrate ISO Standards and how to complete an AI impact Assessment. [02:10] What is an isologyhub Gameplan? Gameplans have been designed to be actionable pieces of content within the Isologyhub. They are guides where people can work through a particular set of information about a topic and practical guidance that can be applied within the own organisation. Each game plan is structured around a kind of area that is quite commonly a difficult area for many organisations managing ISO Standards. Each Gameplan also includes a number of Workbooks to help you through each step, whether as an individual or as part of a team. [04:00] What issue is the Audit Accelerator tackling? internal audits are a fundamental part of any ISO management system, but it's also something that can get a little bit stale when you've had a management system for a while. It can tend to feel a little bit like a rinse and repeat exercise where you're having similar conversations with the same people about the same processes, which isn't what internal audits should be. The reason they're in the standards in the first place, is to help push continual improvement. For example, if you've got a quality management system, you'll be looking to ensure that processes are being followed, but also where there are opportunities to improve. This is where a lot of people drop the ball in mature systems. Internal Audits can be intimidating for some, and can be rushed as just something that needs to get done. But by rushing them, by not talking the proper time to speak to different individuals, you are missing out on valuable information that can ultimately help you improve your services and way of working. The Audit Accelerator Gameplan was designed to help you to really get the most out of those internal audits, give the process a bit of a refresh and rethink how you're approaching your audit planning. It also provides guidance on how you can get better engagement from the wider business with audits. Refreshing the process will help you to gain new perspectives, and ensure that internal audits becomes a positive experience that everyone can engage with, no matter what level they are at within the business.   [08:15] Who is the Audit Accelerator aimed at?: The person who's responsible, or personal team who is responsible for coordinating the internal audit plans within an organisation. It's aimed at those so that they can help the wider business to understand what audits are about, and also so that they can also look at how they're planning audits. [09:15] What are the five steps in The Audit Accelerator?: Step 1: Check – This step helps you to assess where you currently are with your Audit Program. It includes a workbook with a checklist that you can work through, this will give you a score to indicate how well you're doing and where you can improve. It asks questions such as: ·      How effective are the audits that you're doing in your business? ·      Are there areas that you could perhaps make improvements? Step 2: Challenging Assumptions - This step provides information about what the purpose of internal audits are, why people have misconceptions about them, what some of the common fears and concerns are about audits, so that you can start addressing them within your business. This can include simply talking to your colleagues in a more positively framed way about Internal Audits. Another suggestion is changing the name 'Internal Audit', especially if it has negative connotations within the business. The Standard doesn't say they have to be called anything, as long as you're asking people about how things are done, ensuring processes are being followed and allowing people to suggest improvements, the way you go about doing to (including the name) can be done in whatever way works best for your business. This step also includes the main workbook that you will work through for the rest of the steps. Step 3: Change It Up – This sections includes a few different videos about different ways of planning audits and different ways of explaining audits to your colleagues so that they feel a little bit more comfortable about them and understand the benefits and real opportunities that come from participating in audits as well. Step 4: Collaboration – This step stresses that it's really important that Internal Audits is not something driven solely by just one person. Everyone has a positive part to play in the process. This includes Management, as they need to hear audit feedback and make changes where required. This helps to show that audits drive meaningful change, and should encourage everyone to have their say. So, this step is really about making sure that management, audit planners and auditees understand their role in the process. Step 5: Check Again – This involved going back to that initial assessment of where you were when you started the Gameplan, and reassessing after you've implemented some of these improvements through the improvement workbook and seeing if you have moved the goalpost from that initial assessment. Hopefully you'll have a much higher score to show how much you've progressed after following the Gameplan steps.  If you'd like to become a member of the isologyhub, we have an exclusive 20% discount available for listeners, simply Contact Us and quote: Isologyhub20 to claim that discount. We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
  • #239 2025 ISO Standard Wrap Up and Looking Ahead 17.12.2025 16min
    It's been a busy year for ISO Standards, with that set to ramp up in 2026 thanks to upcoming Standard transitions. Before we dive into a new year, we'd like to take a step back and highlight some of the key ISO milestones from 2025.  In this episode, Steph Churchman, Communications Manager at Blackmores, looks back at the major Standard updates from 2025, including changes to existing Standards, new ISO's published and key upcoming changes you need to be aware of for 2026.   You'll learn ·      What ISO Standards have been updated in 2025? ·      What new ISO Standards were published in 2025? ·      What Standards are due to be published in 2026? ·      What ISO transitions do you need to be aware of in 2026? Resources ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Steph reviews major ISO Standard updates from 2025, including changes to existing ISO Standards, new Standards published and what you need to know going into 2026.   [02:34] What ISO Standards have been updated in 2025?: ISO 27701:2025: This is the Standard for Privacy Information Management and it recently received an update in October 2025. Key updates to this Standard include: ·      This is now a stand-alone Standard and can be implemented without an existing ISO 27001 ISMS in place. ·      The addition of further guidance for data processors and controllers. ·      Provides greater clarity on managing personal data within AI and digital ecosystems ·      More focus on organisational leadership involvement. ·      The update now aligns ISO 27701 more closely with global regulations such as GDPR, CCPA and LGPD. ISO 37001:2025, the Standard for Anti-bribery. This one was well overdue an update, with its last version being 2016! It's update arrived on 2nd Feb 2025, and included: - ·      Text harmonisation with the other ISO 37000 family of Standards, such as ISO 37301 (compliance management systems), ISO 37000 (governance of organisations) and ISO 37008 (internal investigations of organisations) to ensure consistency and easier integration. ·      The latest version now formally introduces the concept of anti-bribery culture and emphasises its importance for the effectiveness of the management system. ·      A greater emphasis on the role of top management and their involvement in overseeing the management system. ·      A new requirement has been added for awareness and training as fundamental asset for management system results. ·      It also receives the added climate change amendment, which many ISO's already embedded back in 2024 – learn more about that here. ·      And lastly, there's more comprehensive definitions of conflict-of-interest as well as procedures to raise awareness on reporting potential and actual conflicts. ISO 50002, the standard for energy audits. This isn't a certifiable standard, but rather a guidance document to support the energy management standard ISO 50001. The recent update has now split this Standard into 3 parts: ·      ISO 50002 part 1: General requirements with guidance for use. ·      ISO 50002 part 2: Guidance for conducting an energy audit in buildings. ·      ISO 50002 part 3: Guidance for conducting an energy audit in processes Most of the revisions focused on strengthening and adding further clarification to energy auditing principles such as Competency, Confidentiality, Objectivity, access to equipment, resources and information, Evidence-based approach and Risk-based approach Lastly, this update also clearly specifies the requirements for energy auditor competence. [07:10] What new ISO Standards were published in 2025? ISO 42006 - Requirements for bodies providing audit and certification of artificial intelligence management systems. This is a guidance Standard that actually relates to certification bodies rather than businesses choosing to implement ISO 42001. It builds on ISO 17021-1 and ensures that certification bodies operate with the competence and rigour necessary to assess organisations developing, deploying or offering AI systems. While one that you as a business may not have to worry about, it's a positive addition to the growing ISO 42000 family of Standards, which are currently the only global frameworks for best practice for AI Management. ISO 17298 Biodiversity - Considering biodiversity in the strategy and operations of organizations. ISO 17298 ultimately aims to help organizations of all types and sizes understand how they depend on and impact nature – and take concrete action to address it. It includes guidance to help you: ·      Understand your biodiversity impacts, dependencies and risks ·      Identify opportunities for green growth and nature-positive finance ·      And develop and implement a credible biodiversity action plan   [09:45] What new ISO Standards are due to be published in 2026? ISO 53001 management system requirements for the United Nations Sustainable Development Goals. Many businesses have already done the hard work behind aligning their ESG activities with the UN SDG's, and will soon be able to benefit from certification to an internationally recognised Standard to help manage and improve their performance against those SDG goals. The Standard provides a framework for an SDG management system that will: ·      Enhance the organization's SDG performance. ·      Fulfil compliance obligations. ·      Achieve selected SDG objectives. ·      Create trust and confidence to relevant existing and future stakeholders If you wanted to get a head-start, the guidance document ISO 53002: Guidelines for contributing to the United Nations Sustainable Development Goals is available to download for free right now. ISO 14060: Net Zero Aligned Organisations. This Standard details requirements for how any type of organization can demonstrate that their net zero strategy is achievable, and that they are making credible and verifiable progress towards contributing to global net zero in line with the Paris Agreement. There are a lot of country specific legislation and regulations now in effect, or soon to be in effect, but there is a lack of clarity around what it actually means to be Net Zero. This is where ISO 14060 comes in, to create a globally accepted definition of what it means for an organisation to be net zero. In addition, this Standard will also: ·      Define what constitutes a credible net zero strategy at an organisational level ·      Establish how targets should be set, measured and delivered ·      Require organisations to align with the goals of the Paris Agreement ·      Build on existing ISO standards such as ISO 14064 for GHG verification and ISO 14068-1 for Carbon Neutrality ·      Have a focus on organisational claims, not product or event-level claims ·      And lastly it will be globally applicable and adaptable across sectors. [12:50] What ISO Standard updates do you need to be aware of for 2026?: The anticipated update to the leading environmental management system Standard, ISO 14001, is expected to be published in Q1 of 2026. It doesn't appear to have many major changes, but rather just further guidance and clarification in a few areas, including: ·      Modernised terminology and harmonised structure that aligns with other ISO Standards ·      Stronger focus on environmental conditions ·      Clearer EMS scope with life-cycle perspective ·      Again, we see a greater focus on leadership accountability ·      Refined risk-based planning ·      Introduction of a new change-management clause ·      Extended operational control to suppliers ·      Restructured management review ·      And an expanded Annex A for explanatory notes ISO 9001 is also due a revision. It was expected out around a similar time as ISO 14001, but following its public comment round, it's gone back under revision to make more changes after that feedback. As a result, this has pushed the expected publication date to either Q3 or possibly even Q4 of 2026. Now despite it going back into revision following feedback, the changes are still expected to be minor. Some of the expected changes include: ·      Impact of digital transformation – such as AI ·      Improved supply chain resilience ·      Proactive risk management and risk-based thinking ·      Quality culture and awareness of ethical behaviors ·      And increased attention to customer satisfaction Looking even further forward, ISO 45001 will also be up for revision soon, though that isn't expected to be published until 2027. We'll give you more details as soon as a draft version has been made available. All of these transitions will include a 3-year grace period, so there's no need to panic. Over the next year, we'll cover these changes in more detail, and will provide a variety of ISO Support options to help you manage and complete your ISO transitions. That's it from us for 2025! We look forward to brining you more ISO knowledge in 2026 😊 We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Obľúbený v

Tento podcast sa objavuje aj v rebríčkoch podcastov týchto krajín.