Blackmores is a pioneering consultancy firm with a distinctive approach to working with our clients to achieve and sustain high standards in Quality, Risk and Environmental Management. We'll be posting podcasts discussing ISO standards here very soon!
There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it's operational.
It's undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination.
For those wondering how to get involved, there is a dedicated group looking to share knowledge and tools to get you tender ready.
In this episode, we are joined by Lorna Leonard, Managing Director of LBS, and Kirsty Maynard, Commercial Director of THSP, who are instrumental in running BedX, a group dedicated to sharing knowledge and tools to help businesses get tender ready for Universal and beyond.
Listen to our roundtable discussion as we dive into why BedX was created, its main drivers, how it can support local businesses and how you can get involved.
You'll learn
· Who are Kirsty and Lorna?
· What is BedX?
· What were the main drivers behind the creation of BedX?
· What are the group's main aims?
· What are Kirsty and Lorna's roles within the group?
· How can businesses get involved with and benefit from BedX?
· What can businesses be doing now to get tender ready for Universal?
Resources
· Bedfordshire Chamber of Commerce - BedX
· BedX Webinars
· Tender Diagnostic
· Kirsty Maynard LinkedIn
· Lorna Leonard LinkedIn
In this episode, we talk about:
[02:25] Episode Summary – Stephanie Churchman and Carly Mowbray are joined by Lorna Leonard (LBSv) and Kirsty Maynard (THSP) to discuss the creation of BedX, and how it aims to support businesses with tender preparation ahead of the Universal and related projects currently underway in Bedfordshire.
[01:25] Who are Kirsty and Lorna?: Kirsty is the commercial director at THSP. THSP work with businesses across health and safety, HR and compliance, helping organizations make sure they've got the right systems, processes and people in place to operate safely, professionally and compliantly. THSP have been in operation since 1992 and support any type of organisation, from construction to food brands, global luxury retailers, major transport organizations, and complex international businesses operating in highly controlled environments.
Lorna is the managing director of LBS. LBS is a business solutions company supporting sophisticated start-ups and growing corporations with outsourced finance department services, direction and solutions. She set-up the business 14 years ago, and has worked with organisations of all sizes, from blue chip companies to micro businesses of only 1 or 2 people.
Regular listeners may recall Lorna from a previous episode, she also shares many insightful posts on LinkedIn and is certainly worth a follow!
[07:05] What is BedX? It's A business-led working group powered by the Bedfordshire Chamber of Commerce. It was created to help Bedfordshire businesses understand, prepare for and win work from the major investments coming into the region, in particular, the universal destinations and experiences, the Luton Airport expansion and other on-going linked projects.
BedX's role is to connect, inform and prepare, but they don't lobby, they don't represent the developers and they don't do politics. They are simply there to help local businesses get ready.
[07:45] What were the main drivers behind the creation of BedX? The Universal park is certainly the banner piece for the group. It's what all the big numbers are attached to, including 5 billion pounds worth of inward economic investment, 20,000 jobs created and the five years' worth of construction.
However, that is just one part of the upcoming development going on in Bedfordshire. The big project is seeing more funding going into the area to support transport networks and other venues as investors seek to make Bedfordshire a place worth staying for more than just the Universal Park.
Other projects include the expansion of the Wixams Train Station, construction at the Luton Hoo, the new Luton Town Football Club and a new Data Centre at Quest Pit.
BedX was created in response to all of these projects, not just Universal. It's to help local businesses navigate these opportunities, as this small county has rarely seen such a seismic shift in the amount of investment going into the area.
Even though the deadline for Universal Park is 5 years away, supply chains are looking for support now, which is why it's better to start preparing sooner rather than later.
[10:20] Making Bedfordshire a play to stay: It's also not just about the venues, to prepare for the influx of tourists there will be more investment in housing and transport and related routes such as the work currently going on at the Black Cat roundabout.
Kirsty states that the Bedford County Council have a scrutiny committee, which is currently labelled as the Universal Scrutiny Committee, and are in discussion about a viable tourist strategy for Bedfordshire. So, there is no doubt that there will be many more small projects going ahead within a very short timeframe to get the area ready.
[12:00] How LBS's expertise is instrumental within BedX: Businesses that want to get involved may not know how to get working capital or access potential available funding, which is where Lorna's and LBS's expertise comes in to support BedX's aims.
With tenders as highly valued as this, it can throw businesses through a loop if they're not prepared. Lorna shares a story where she explains that she used to work for a company that made point of purchase display equipment, this company had a US subsidiary called Anshauser-Busch, who own Budweiser.
That subsidiary put through an order directly through to their factory, requesting a huge order be manufactured and delivered within 180 days. The cost of which was upwards of $2.7 million, which was due to suppliers 150 days prior to Lorna's company at the time being paid.
It was their first time working with that subsidiary, so there was no guarantee on payment. The lessons they learned ended up shaping how the company operated going forward.
All this to say, if you're bidding for high value contracts, you need to think about the opportunity from every perspective.
[14:40] Be realistic about what you bid for: Kirsty states she is really passionate about ensuring businesses are trying to grow responsibly, so that they understand those terms in the bid and that they're realistic about the size of contract that they should be bidding for.
If you're looking for more guidance in this area, Katie from Bids and Tender Support provided a webinar on this topic for BedX. It's available to view on-demand on BedX's website.
[16:25] Lorna's role within BedX: Lorna reminds us that a lot of the Tier 1 contractors started out as 1 or 2 person businesses. She states that, honestly, 90% of the companies that BedX help will not be in direct contact with one of those Tier 1 contractors. However, supply chains are just that, a chain, there are many opportunities to get involved further down the line.
Lorna feels as if that's a large part of her role, keeping businesses focused on the opportunities they can access within that supply chain. She is also keen to help all the local businesses understand how this is going to affect them, because whether they get involved in the various projects being built or not, the whole area is going to be affected regardless.
She points out an example where they needed to source a large number of electricians, and it turns out that Bedfordshire simply doesn't have enough! So BedX is helping to make the wider community aware of training opportunities like this that can open doors for local businesses.
[18:45] Other considerations for businesses operating in Bedfordshire: Lorna points out a few other concerns that people had about the on-going development in the area, including the possibility of local contractors putting prices up due to all the other projects. Timeframes may also be affected by both on-going work and the fact that more businesses will be getting involved in the area's development.
[19:15] What are the group's main aims?: BedX's main aim is to be an opportunity exchange, they sit in the middle as a conduit between the opportunities and the Bedfordshire businesses and help to inform, educate and prepare to be a part of it.
They are there to support preparation local businesses are able to access emerging supply chains as that waterfall flows down into tier 2 and 3 and even into 4 and 5 over the course of the project.
If you're not sure which of those tiers you'd likely sit in, BedX have a helpful household checklist to find out.
[20:20] Getting ISO Ready for Universal: Kirsty mentions that she's seen a lot of recent Pre-Qualification Questionnaires (PQQ's) request that bidding companies are certified to ISO 27001 Information Security.
Many will be familiar with the requests for ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Occupational Health & Safety), but ISO 27001 seems to be a more recent pre-requisite.
This is particularly the case for any Government contracts, with them stating either Cyber Essentials or ISO 27001 must be in place for any bidding businesses.
Carly points out that ISO 27001 in many cases is just the first step, as you can strengthen this with supporting Standards such as ISO 27701 (Privacy Information Management) and ISO 27017 & ISO 27018 (Cloud Security), which can give you an advantage over your competitors.
If you've not got any Standards in place, or are just starting out on your implementation journey, you can get in contact with Blackmores as we'd be happy to guide you towards successful certification.
[25:00] Kirsty's role within BedX: Kirsty's role is focused on coordination, though all BedX organisers are volunteers, they still want to ensure that actions are followed up and completed.
Kirsty has a project planning background and brings those skills to the group. She also plays a key part in tender and procurement readiness, as she has years of experience with PQQ's from her work within the construction industry. She knows what good looks like when bidding for work, and ensures that knowledge is being passed on to those looking to bid for Universal and other Bedfordshire development projects.
A trait that many of the BedX team hold, Kirsty and Lorna especially, is the motivation to help people, and this group allows them to do so at scale.
[27:45] How can businesses get involved with BedX?: You don't need to be a member of the Bedfordshire Chamber of Commerce to get involved. Currently BedX's main focus is on knowledge sharing, so their main output in webinars.
They also have a tender diagnostic tool available, this is an online tool which takes just a few minutes to complete and will give you an idea of where you're already compliant and where there's work to be done.
They have also had 1 in-person event, that being their official launch in April of 2026, which was attended by members from the Bedfordshire business community and representatives from Universal, Sizewell C and Luton Rising. They expect to run more in-person events in future, so keep an eye on their LinkedIn for news on these! Lorna hints at an upcoming event planned for September 2026 😉
You can also sign up to the Bedfordshire Chambers Newsletter for more updates.
An 'Easy Guide To Social Reporting' is due out imminently. Those wanting to bid for Tier 1 contracts, social value is a legal responsibility, so if you're not sure on how to report on that, this is one for you to keep an eye out for.
For information you can access right now, they have:
· Contractor Tier Checklist
· Tender Diagnostic
· Working with Tier 1 contractors webinar (hosted by Henry from Kia)
· How to be tender or procurement ready webinar (Hosted by Kirsty)
· How to write a good bid webinar (Hosted by Katie Beryl from Tender and Bid Writing Services)
[31:10] What can businesses be doing now to get tender ready for Universal? One thing Lorna stresses is being visible. If you don't have a social presence or good SEO, then you may be missed as an option for those looking for specific services within these developing supply chains.
She also shares a story about the supply of the chocolate frogs that are sold at Universal Floria, which were all provided by a 2 person company. This highlights that it is possible for smaller local businesses to win big through these opportunities, but you need to be prepared. This is why Kirsty and Lorna both highly recommend making use of their Tender Diagnostic tool.
Being tender ready may seem like a daunting process, and it can quite difficult, but they are worth putting time into.
Also anything you can do to think about what you may need to change within the next few years. Think about how these developments are going to affect the traffic to the area, you might need to reconsider who your target market is depending on the whims of upcoming tourists. This can affect what services / products you offer and how you advertise going forward. The sooner you think about it, the better prepared you can be.
Lorna also recommends networking with local businesses. Bedfordshire is going to become a thriving hub, and the more connections you can make now, the better. Some of these tenders may require the collaboration of multiple businesses, which would be an all round win for everyone involved.
Networking also allows your name and brand to spread through word of mouth. If you're not in the room, it helps to have people who can vouch for you if your specific services are being sought out.
Lastly, Lorna and Kirsty just say to dream big. Just because you may be a small business does not mean you are automatically locked out of those big tenders, they are worth a try.
An important note, being local to Bedfordshire won't make up for gaps in the eyes of Universal and related projects, however, if you share equal capabilities as other companies outside of the county, then being local will tip you over.
[40:10] Evidence is key: Ultimately being tender ready is in your best interest. Contractors will be looking for evidence that you do what you say you do, so ensure you have Case Studies and the required certifications to back-up your claims.
Social Value is another big factor, which can account for up to 20% of a bid score, so this is another area where you need a clear trail of evidence.
Having a clear library of evidence to back up your claims, that align with how you operate will make you stand apart from the competition. So, start gathering this now if you haven't already.
If you'd like to get involved with BedX, check out their website.
If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help!
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped.
So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business.
In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some tips on basic Information Security checks you can do to ensure an AI application or integration is safe to use.
You'll learn
· The link between AI and increasing data breaches
· Recent incidents as a result of AI misuse or error
· Key considerations for the implementation of AI technology
· 11 Information Security checks for AI tools
Resources
· Isologyhub
· ISO 42001 Webinar
· IAF Accreditation Check
In this episode, we talk about:
[02:25] Episode Summary – Stephanie Churchman explains the need for caution when exploring the implementation of AI tools, and provides guidance on some information security checks you can perform to ensure your data stays safe.
[02:45] The link between AI and increasing data breaches: Data breaches tripled since the wide adoption of AI in early 2024 and studies are saying there is a clear link between these two events. Here in the UK alone, 32% of businesses experienced a cyber-attack or data breach in 2023, compared to 43% of businesses in 2025, with us already steadily on track to surpass that in 2026.
Does this mean people shouldn't use AI at all? No, of course not, but we do need far more caution before you simply start using a tool.
[03:35] Recent incidents as a result of AI misuse or error:
ChatGPT copycat – There was a ChatGPT clone available as a web extension that was downloaded by some 1.5 million users. It functioned just like ChatGPT, answered queries and provided links to legit sources. But, in the background, it was scrapping passwords and gathering information that was to be sold off without users knowledge.
Sage Copilot - The popular accounting software had to temporarily suspend Sage Copilot after a data-isolation flaw occurred. This incident caused an issue where users who prompted the AI to list recent invoices ended up with incorrectly surfaced financial records belonging to unrelated businesses. This was a major security issue, especially for an application thousands of businesses rely on to track their financial records.
Google Gemini – Google Gemini was found to have been abused by bad actors for data reconnaissance. One particular group were building profiles on major cybersecurity and defense companies and were looking to gather specific technical job roles and salary information. Google's threat intelligence team characterized this activity as a blurring of boundaries between professional research and malicious reconnaissance. Their soft touch approach allowed the bad actors to craft tailored phishing personas and to further identify potential soft targets to compromise.
[06:30] Key considerations for the implementation of AI technology: Any software or technology you plan on introducing into the business that will interact with your and your customers data should be subject to clear vetting procedures, with clear rules for use to follow.
Before integrating an AI tool, ask yourself, is the tool you want to use:
a) Relevant
b) Safe
c) Ethical
Ethical may sound strange, and will depend on what you're using an AI for. Take CV sorting for example, many studies have shown that AI's can have an inherited bias based on their training data. This has also now evolved into AI based recruitment tools preferring AI generated CV's over human written ones.
From a safety standpoint, think about the data you are feeding into those recruitment tools, that's personally identifiable information, full names, phone numbers, emails and possibly even addresses. A full profile for an individual. Is that system your using closed, do you know if you consented to having any input data used for further training? Don't just assume that inputted data won't be used beyond your control.
If that recruitment AI tool gets hacked, who do you think is liable for the breach? Is it the AI tool developer or the business that input the data? You think the answer would be clear, but the legality of all this is still being debated.
[09:10] 11 Information Security checks for AI tools:
#1: Have an AI Policy and AI Integration approval process in place - Many businesses will already have an AI policy in place, most are very generic, so we recommend looking at the guidance provided by ISO 42001 to see what good looks like for an AI policy.
You should also create a clear approval process that any AI tools must pass BEFORE people start using them. This should be clearly communicated to the wider team, and there should be a method to manage these checks such as a ticketing system to kick off the process.
#2: Understand where your data actually goes - Find out whether inputs are used to train the vendor's models. These inputs can include prompts, uploaded files or even customer data depending on what the tool is. You also need to find out how long that data is retained, and whether it's stored in a specific jurisdiction.
You can look for answers to these in a DPA (Data Processing Agreement), don't rely on the basic marketing blurb they state on the website. If those answers aren't provided, contact the tools support or basic enquiries to find out.
#3: Check for a SOC 2, ISO 27001, or equivalent certification – This is an easy check for vendor's security posture. Absence of certification shouldn't automatically disqualify a vendor or tool, but it should prompt more due diligence, not less.
Even with a certification in place, you also need to double check that it's valid. ISO 27001 for example will need to be certified by a UKAS accredited certification body for those in the UK. For overseas, you will have your own ISO accreditation bodies, which can be verified on the IAF website.
#4: Map out third-party and subprocessor risk - Most AI tools sit on top of other infrastructure like cloud hosting, underlying foundation models and additional analytics tools. You should ask for a subprocessor list to fully understand who else touches the data.
#5: Test for prompt injection and data leakage - If the tool interacts with external content such as emails, documents or web pages, it can potentially be manipulated by malicious instructions hidden in that content. Businesses should ask vendors how they mitigate this and ideally test it themselves.
#6: Clarify access controls and permission scoping - This is especially the case for AI agents or tools with system integrations. You need to establish if the tool operates with the same permissions as the user, or whether it has broader access.
Overprivileged AI agents may operate independently with no human oversight. 'Human in the loop' has become a common phrase within cyber security for a reason, you always need a point of human oversight to ensure the AI is doing what it's supposed be doing and is doing so safely.
#7: Ask about model update and versioning transparency - You need to ensure that the vendor won't just silently swap out the underlying model for its AI tools, as this can introduce sudden behaviour changes in the tool itself.
Transparency is a key component of emerging AI security frameworks and regulations such as ISO 42001 and the EU AI Act. If a vendor isn't willing to tell you when they're making major changes to their tools, then it's not a vendor you want to entertain.
#8: Evaluate the output reliability and hallucination risk in context - For security-adjacent or compliance-adjacent AI tools, factually wrong outputs are a risk.
AI can have a tendency to 'hallucinate' data or outcomes and then present them as fact. So, ask the vendor what guardrails exist and whether their tools' outputs are auditable / traceable.
They should know what data was used to train their models, or where their models are pulling data from. If they don't or can't control what data is being used, then it's not a tool you can 100% trust.
#9: Review incident response and breach notification commitments - If the vendor is breached, do you how quickly you would be notified, and what their recovery process looks like?
If you hold ISO 27001 and ISO 22301, or simply have a business continuity plan in place then you will already have similar procedures in place for peace of mind for your own customers, so why should you settle for any less?
And just like your clients would expect, breach notifications and expected recovery times should be contractually defined, not just assumed.
#10: Consider the supply-chain risk of the vendor itself - This tech is still relatively new, and so newer AI vendors may have smaller security teams and less mature processes than what you may be used to with more established providers.
However, startup pace doesn't mean you have to tolerate the start-up risk. Consider all of the previously mentioned steps, if they don't have a lot of that in place, then they may not be mature enough yet for you to go ahead with.
This doesn't mean you have to automatically disqualify them, if they have a clear plan of action for growth, which shows a clear focus on increased security and transparency within a reasonable timeframe, then it's still worth considering.
#11: AI tool monitoring and Kill switch – In addition to this initial vetting procedure, you should also have a process in place to continuously monitor these AI tools too.
Many AI tools aren't static, they'll update and become better or possibly introduce issues as they will inevitably face the risk of bugs and other technical problems as they roll out updates. If a tool is consistently encountering issues, continuous monitoring allows this to be flagged up as a security issue.
Which is where you'll also need a kill switch in place if an AI tool is behaving unsafely. It's important that you know how to isolate it and remove it from your systems.
AI tools are more ingrained that your typical software, often designed to work in tandem with existing apps rather than as a standalone system. This will mean that some tools will have access to possibly sensitive data, something that needs to be protected if the AI tool experiences issues that could lead to that data being compromised.
The relevant staff, likely your IT team, need to have a clear process for what to do in those scenarios.
If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help!
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide.
We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they've found their first year working with other organisations to help them achieve ISO certification.
You'll learn
· What is Emma's role at Blackmores?
· What does Emma enjoy outside of consultancy?
· What did Emma do before becoming an ISO consultant?
· How has Emma found her first year as an ISO consultant?
· What Standards has Emma worked with so far?
· Has there been any unexpected elements to her role?
· What is the biggest challenge Emma has had during a project so far and how did she overcome it?
· What is Emma's biggest achievement?
Resources
· Isologyhub
· TISAX Webinar
In this episode, we talk about:
[00:30] Episode Summary – We introduce Emma Coxhill, an Isologist® here at Blackmores, to discuss her recent entry into the world of ISO consultancy, including how she's found working on the other side to help other organisations achieve ISO certification.
[03:30] What is Emma's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards.
Emma specialises in information security management systems (ISMS), but is branching out to other Standards as she takes on more clients.
[04:30] What does Emma do in her free time? Emma is a big fan of the outdoors, enjoying long walks and exploring in general.
It makes sense then that she also enjoys gardening. While it is a lot of work, she finds the result rewarding.
Emma is also a big fan of movies, excluding horror films! She enjoys making the trip to see films on the big screen when she has the chance.
Lastly, Emma is also a qualified life coach. This involves guiding people to get where they want to be in life, with the crucial distinction that it's not about telling people what to do, but rather providing the right questions and tools to help them achieve their goals quicker.
These skills have evidently translated well into her role as an ISO consultant, as auditing is very similar in the fact that it's about giving people a different perspective.
[06:55] What was Emma's previous role? Emma previously worked in admi and retail roles, with her last job being a sales admin at a company for 13 years.
She first started at that company as a sales admin, moved onto business systems and around 2019 the request for them to earn ISO 27001 certification came in.
Back then ISO 27001 was a 'nice to have' and not a 'need to have' like it is today. Emma jumped at the chance to join the team working on the ISO 27001 Implementation, taking part in the research, training and implementation tasks.
The company managed to navigate their certification, even through the turbulence of COVID, and Emma was the one maintaining that ISMS for the following years.
During that time she also implemented TISAX, an Information Security Standard specific to the automotive industry, which you can learn more about on one of our previous webinars hosted by Emma.
Sadly, Emma was made redundant in 2025, but was fortunate to join the Blackmores team shortly after.
[10:10] How has Emma found her first year as an ISO consultant? It's been challenging for Emma to adjust to being on the other side of the fence, helping others to achieve certification rather than being the one to implement a system firsthand.
Thankfully there was plenty of opportunity to learn during her first year with Blackmores, including expanding her repertoire of Standards and being able to learn from other experienced consultants in the team.
She's really enjoying working with a variety of clients, getting to learn about different industries and how different each company is in their operations.
Emma is aware that she's just scratching the surface within her first year, and is eager to learn more.
[12:20] What Standards has Emma worked with so far? ISO 27001 is the main one as it's the one that Emma learned to implement from scratch at her pervious job.
Since joining the Blackmores Team she's also gained experience working with ISO 9001 (Quality Management), ISO 27701 (PII Management), ISO 17100 (Translation), ISO 42001 (AI Management) and TISAX.
ISO 27001 remains her favourite out of all of them, and she's keen to learn more from Blackmores own Information Security guru, Steve Mason.
[14:15] Has there been any unexpected elements to her role? One of the more unexpected aspects has been helping clients navigate various acquisitions. When she joined, Blackmores had an unusual amount of clients currently in the middle of this process.
Dealing with ISO management in these situations can get tricky as you're having to marry up different styles of management as two companies merge. Emma's role was in helping them to navigate that transition.
She was surprised as she expected to be dealing with companies that were business as usual for years, but ISO Management is at the heart of managing these types of changes. So, it was interesting to learn how involved an ISO consultant can get into the inner workings of a business to help ease the burden for all parties involved.
[17:20] What is the biggest challenge Emma has had during a project so far and how did she overcome it? Emma is still relatively fresh to implementation projects, but has found the process to be quite straight forward with the both the Blackmores 7 step methodology and support from other team members.
What has been a challenge was the promotion she was tasked with for TISAX. It was a new service offering for Blackmores due to her expertise, and she was involved in recording a podcast and hosting a webinar. Both activities she'd not had any prior experience with.
She doesn't think of herself as a big presenter, so it seemed like a dauting task. Emma did a lot of practice and went our of her comfort zone to do the webinar, which was positively received by the audience.
The experience certainly boosted her confidence in that area, and though it was a bit stressful at the time due to nerves, she felt like it was a good learning opportunity.
[19:45] What is Emma's biggest achievement? Emma has various moments throughout her life, with an early one being the fact that she passed her driving test first time at the age of 17.
Later in 2005, she went solo travelling for 5 months around Australia, New Zealand and Fiji. She did end up having to work for a bit of that trip to make up some additional funds, but that was a necessary evil. Other than that, she was amazed at all the different people she met during her travels and was so pleased that she was able to complete the trip.
Lastly, she's proud to have joined the Blackmores team in 2025. She's recently helped her first client achieve certification from scratch, which felt like a reward in of itself to know they'd passed their ISO assessment.
If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help!
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.
Health & Safety often gets mocked for overly cautious or seemingly onerous tasks to meet certain regulations and Standards today, however these are in place for a reason. They save lives, plain and simple.
In this episode, Ian Battersby makes the case for Health & Safety regulations, including why they were introduced, events that sparked the conversation for workplace safety and the impact regulations have had since their introduction.
You'll learn
· The decline in ISO 45001 adoption
· The Health and Safety at Work Act
· How much difference has this Act made since its introduction?
· How do the US and UK differ in their approach to safety regulations?
· What events led to the creation of safety regulations in the UK?
· Addressing broader health and safety risks – illness and long-term damage as a result of work
· How to make health & safety manageable
Resources
· HSE
· ISO 45001 Support
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian Battersby makes the case for modern Health & Safety regulations, sharing why they were introduced, how they've impacted workplace safety statistics and how you can make health & safety more manageable.
[03:30] The decline in ISO 45001 adoption – From our standpoint as consultants, there has been less adoption of ISO 45001 when compared to other Standard such as ISO 9001 or ISO 27001. In years previous, it was a common Standard to implement either with or straight after ISO 9001. There are a number of reasons for this, including:
· The appetite for ISO 45001 has reduced in favour of newer Standards
· Supply chains not proposing it as a requirement
· Our particular client base feel they are low risk in their respective industries
To be fair, health and safety does get a bad reputation for being overbearing. It's been subject to many attacks from various media and lobbying groups, however, it's necessary to ensure we all stay safe at work. Let's look at some history…
[05:00] The Health & Safety At Work Act: This act received Royal Assent in the UK on 31 July 1974, and came into force on 1 April 1975.
To an extent it replaced and improved upon previous laws covering separate industries and activities: Factories, Mines & Quarries, Agriculture, etc
It was enacted in response to a recognition that, although conditions for workers had improved over the century, there was still completely unnecessary harm being caused to many in the country's workforce.
This is also the point when the Health and Safety Executive was formally established to enforce the law. It also provides a wealth of guidance to businesses, so we highly recommend checking out their website.
They also have the legal duty to collect consolidated data on workplace injuries for the UK, and have provided an annual report since it's inception in 1975.
[07:45] How much difference has this Act made since its introduction? In the year to 31/03/1975 when consolidated data was first recorded there were 651 deaths at work. The equates to more than 2.5 deaths in a single year per 100,000 workers.
Comparatively, in 2024/25 124 people died in work, and while that's 124 too many, it's a big improvement. The rate per 100,000 workers is now 0.37, and you have to bear in mind that the workforce has grown, but overall that's a reduction of over 85%.
[09:10] How do the US and UK differ in their approach to safety regulations? The Occupational Safety and Health Administration (OSHA) serves similar purpose in USA as HSE, but they have important differences in approach and independence.
The HSE is independent of government to an extent and has no ministerial control, whereas OSHA sits within the Dept of Labor.
It can also be argued that the OSHA approach is prescriptive in setting rules whereas HSE follows the more outcome-based principles of HASAWA: to reduce risk "so far as is reasonably practicable", which some argue is more sophisticated and produces better results.
OSHA has also seen its powers to intervene, investigate and enforce curtailed at times due to certain political interests.
Looking at the numbers, the US Bureau of Labor Statistics published fatality rates for 2024: Census of Fatal Occupational Injuries:
There were 5,070 fatal work injuries recorded in the United States in 2024, down 4.0% from 5,283 in 2023. The fatal work injury rate was 3.3 fatalities per 100,000 full-time equivalent workers in 2024, a decrease from 3.5 in 2023.
That rate is notably higher than Great Britain's — 3.3 per 100,000 versus 0.37 — though the two figures aren't directly comparable. The BLS uses full-time equivalent workers as the denominator and covers a broader range of incident types, while the HSE's RIDDOR series uses a headcount of all workers and has specific exclusions (road traffic accidents, air and sea travel, etc.). The methodological differences mean a like-for-like comparison requires some care.
[13:35] What events led to the creation of safety regulations in the UK? In the days of Victorian Britain, it's difficult to view the common working man, woman AND child as anything other than a commodity.
Thousands died every year in industrial accidents during this era, and large-scale accidents in many industries weren't uncommon.
Mining was particularly tragic, a few events include:
· The Oaks Colliery explosion of 1866 killed around 360 men and boys.
· Hartley Colliery in 1862 trapped and killed 204 miners when the single shaft collapsed (but individual deaths from falls, gas explosions, and equipment failures happened constantly and attracted no particular attention)
· The Abercarn Colliery explosion in Monmouthshire (1878) killed 268 men.
· The Albion Colliery explosion at Cilfynydd in Wales (1894) killed 290.
These were not exceptional events, they were part of a continuous toll. In the 1860s alone, over 1,000 miners died annually in Britain.
Textile mills, ironworks, shipyards, and construction sites all had very high casualty rates. Factory machinery had no guards. Children routinely worked in spaces too small for adults, climbing inside machinery to clean it while it was still running, or crawling under looms. Mill workers lost fingers, hands, and arms with regularity.
The end of the Victorian era saw attempts at regulation, but without true enforcement. The Factories Act didn't appear until 1933 and it was bitterly opposed by many owners of mines and mills.
Modern regulations exist today to prevent the tragedies of the past from happening again, they were hard fought for by workers and lobbyists, and in some ways we're still fighting to include the broader impacts work can have on an individual.
[16:45] Addressing broader health and safety risks – This is in relation to harm accumulated over a lifetime of work with long-term and often fatal consequences. The suffering caused to workers exposed to hazardous conditions is immeasurable.
For example, let's look at asbestos. The dangers of working with asbestos were recognised remarkably early, as far back as 1890s in France, and Asbestosis was formally recognised in 1930.
This led to regulation in 1931, but only applying to the asbestos textile industry, excluding all the industries where its use was widespread such as construction, shipbuilding, anyone working in insulation etc
Worse still, it wasn't even enforced!
Then take mesothelioma, the distinctive and almost invariably fatal cancer of the lining of the lungs and abdomen. The connection between asbestos and mesothelioma was established in SA in 1960 when mining blue asbestos.
Further research in the UK firmly established the link in the 60s. From the mid-60s, headlines were being made nationally when shipyard workers from the war era stared dying in large numbers. Unions began lobbying for protections and media coverage continued for years as cases multiplied across several areas and industries.
Nevertheless, its manufacture and use continued.
The Asbestos (Licensing) Regulations 1983 introduced licensing for the most hazardous asbestos removal work. Blue asbestos (crocidolite) was banned in 1985, followed by brown asbestos (amosite) in 1986, though white asbestos (chrysotile) remained legal until 1999.
In the interim and since then thousands of people died and multiple legal cases have ensued.
2218 people died of mesothelioma alone in 2023. Altogether it's estimated that workplace-related lung disease and cancers kill as many 13000 per year in the UK. Several thousand more are known to die of non-lung-related occupational diseases each year, but these aren't recorded as workplace deaths on certificates, so these people aren't included in HSE annual reporting.
It doesn't stop at deaths either, there is an argument for the detriment that certain work can have on quality of life. Incidents and conditions such as:
· accidents causing amputation and fracture
· eye conditions from welding and other light sources
· Deafness and hearing difficulties
· HAVS, vibration white finger
· Skin conditions from exposure
· Musculoskeletal in low risk environments
None of these are terminal and so often go unreported.
[23:25] How to make Health & Safety manageable – Some consider modern health and safety regulations to be over the top, but overarching law in the UK has the principle 'As Far As Is Reasonably Practicable'.
One common area is in risk assessment, The Management of Health and Safety at Work Regulations states:
"Every employer shall make a suitable and sufficient assessment of—
(a) the risks to the health and safety
Where the employer employs five or more employees, they shall record—
(a) the significant findings of the assessment"
The keyword being 'significant' there. If you work in lower risk industries, you aren't being forced to make unnecessary risk assessments, only when significant risks are present do you need to complete a risk assessment.
For more guidance, check out the HSE guidance on office-based risk assessments.
[25:55] Ian poses a question: Can you seriously say that the drop in deaths and injuries suffered by the common worker would have dropped at the rate it has without regulatory intervention? Can all employers (or other vested interests) be trusted to do the right thing through good will and voluntary mechanisms alone?
If you'd like any assistance with your ISO 45001 Implementation or need any additional ISO Support, contact us, we'd be happy to help.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications!
There's a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement.
In this episode Ian is joined by Damian Edwards, Head of Standards at Wavenet, to dive into how they manage the mammoth task of maintaining seven ISO Standards, the challenges with managing multiple ISO certifications and what benefits they've brought to the business since implementation.
You'll learn
· Who is Damian Edwards?
· Who are Wavenet?
· How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services?
· What is Damian's role at Wavenet?
· How do Wavenet manage their ISO certifications?
· How has ISO Support helped you over the past year?
· What has Damian learned while managing ISO Standards?
· What are the benefits of ISO certification?
· Damain's top tip for anyone considering ISO Implementation
Resources
· Wavenet
· Wavenet Certifications
· Blackmores – ISO Support Service
· Isologyhub
In this episode, we talk about:
[00:30] Episode Summary – We welcome Damian Edwards back onto the podcast to discuss how he maintains Wavenet's seven ISO certifications, and the explore the benefits gained from an integrated ISO Management System.
[03:05] Who is Damian Edwards? Damian is the Head of Standards at Wavenet, and has featured on the ISO Show before!
One lesser known fact about Damian, is that he a 'Dance dad', supporting his daughter through all of her lessons and competitions. He's very proud of her latest achievement of qualifying for the World Championship for Irish dancing in her age group.
[05:05] Who are Wavenet? Wavenet is an IT provider, providing IT network communications, security and resilience services. They are UK based with 1,600 employees based in their Solihull head office.
Wavenet were formed in 2000, but have grown through acquisition, one of which was Damians previous company, Daisy Corporate Services. When Daisy was acquired, both businesses were of a similar size, so the process looked more like a merger in practice.
A large part of that was uniting the ISO Standards managed by both businesses, so Damian had his hands full with ISO integration, amending audit schedules and managing extension to scope audits.
[06:30] How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? One of the biggest challenges was the extension to scope that needed to happen due to the increase in sites.
Thankfully, as Wavenet were used to acquisitions, they had dedicated acquisition project managers that assist with managing the integration.
At the start, there are some teething problems as both businesses will still be using their respective processes for a while. However, once system that helped was a system called 'ServiceNow', which is where issue tickets could be logged, monitored and actioned in one centralised system.
[08:15] What is Damian's role at Wavenet? Damian is the Head of Standards, which includes both ISO Standards and ESG related regulatory compliance.
ISO certifications are more often than not a prerequisite or a condition of a bid over a contract, without them, Wavenet wouldn't win any business. They also create a foundation of trust for Wavenet's clients in the realms of Information Security, quality and environmental management. Wavenet are currently certified to the following Standards:
· ISO 9001 Quality Management
· ISO 20000-1 Service Management
· ISO 27001 Information Security Management
· ISO 22301 Business Continuity Management
· ISO 45001 Health & Safety Management
· ISO 14001 Environmental Management
· ISO 50001 Energy Management
In addition to maintaining all of these certifications, Damian also strives to utilise them to drive continual improvement within the business.
[10:30] How do Wavenet manage their ISO certifications? Damian is directly responsible for five of those ISO Standards, however there are some where he doesn't have the expertise to fully manage the requirements.
ISO 27001 and ISO 45001 for example require skilled people at the helm, so Wavenet have dedicated managers to handle those areas.
One of Damians key responsibilities is juggling all of the audits to make sure each element is covered, and he's put a lot of work into integrating those audits where possible to get the most out of their time and resources.
Though, it's important to note that you can't integrate everything, as each standard will have some unique requirements. Areas that you can integrate however include elements such as:
· Context
· Audit Programme
· Corrective Actions
When you do have a lot of Standards, some elements can get watered down if you try to integrate everything. Policy for example, if you have five Standards and decide to integrate all related policies into a single document, it will become long and unruly, which will lead to people unwilling to read it. So, you have to take care to ensure focus on certain elements to make those more accessible for the staff that need it.
Another aspect that needed additional consideration was Wavenet's risk profile, with their amount of sites and services, it's very varied. Too much for a single person to be aware of all the risks, which is where Damian's subject area experts can provide additional insight to fill the gaps.
Damian is also keen to combine external audits where possible to both reduce cost and possible duplication of effort, as many Standard do share common subject areas, this can be done across multiple Standards. Certification Bodies are usually quite happy to work with you on this!
Damians key take away is, that there isn't one solution that fits every business when managing this many Standards. It was a very trial and error process, especially with the ever changing landscape of a business, but Standards are also designed with flexibility in mind, so with the right people in place it's certainly manageable.
[16:05] How has Blackmores' ISO Support helped? Blackmores has assisted Wavenet with their ISO 45001, ISO 50001 and ISO 41001 (Facilities Management) implementation. ISO 41001 was later dropped as it was no longer applicable for the business.
Standards can be quite hard to apply to your own business when looking at them at face value, the requirements sound generic because they're designed to apply to every type of business. This is where Blackmores experience as a consultancy can help with interpretation and practicalities of how a Standard will apply to your way of working.
Blackmores will also assist with internal audits, which help identify non-conformities that may have been missed if it were not for a fresh pair of eyes. As Damian states: "I would rather have them identified before an external audit" as this gives you a chance to resolve issues or put an action plan in place before it gets to that stage.
Damain also reminds everyone to not be afraid of your auditor, internal or external. They are not maliciously looking for problems, they simply help to highlight issues which can be resolved sp you can improve as a business.
No Management System is perfect, the important thing is that you can recognise when something needs addressing, and how you go about doing so.
[19:30] What has Damian learned while managing ISO Standards? Damian has learned to not think of ISO as a tick box exercise, it's a tool to help businesses improve.
He has also learned that you don't need to reinvent the wheel when Implementing a Management System. You likely already have much of what's required in place, but not monitored or organised regularly.
For example, aspects such as 'Management Review' may already be happening in existing meetings with top management, you simply need to ensure these are minuted, cover what needs to be discussed in regards to the Management System, and make note of any gaps that need to be addressed.
Businesses like Wavenet that have been in operation for 26 years know what they're doing, and are likely already following best practice. You don't need to restructure your business to meet an ISO Standard, but rather integrate the Standard requirements with how you already operate. If done correctly, it should become a simple part of your day-today tasks.
Damian jokingly states: "What's my role? I sometimes say it's to do as little as possible", as the more a business is aligned with a Standard, the less you will have to do to upkeep that.
[22:55] What benefits have Wavenet experienced as a result of their ISO certifications? As mentioned earlier, a lot of won business is due to ISO certification. Certain certifications are simply a tender or client requirement.
Standards such as ISO 50001 tackle their energy consumption. It's focus on reducing that will inevitably lead to reduced business costs. Since implementing the Standard, Wavenet now have monthly meetings to monitor energy use, which gives them a good basis to make informed decisions on where energy use is concerned.
Damian has found that over time, good practice has been so embedded that people are using it in their everyday behaviors without even realising it. He's heard people in their resolutions team use terminology like 'root cause' without knowing where it came from.
He's seen team making use of skill matrix's when evaluating the competence of certain teams such as engineering for client visits. So, people within the business are using ISO terminology and techniques to ensure best practice without being explicitly asked to. It simply works as a method to drive the business effectively when implemented correctly.
[26:15] Damian's top tip for aspiring ISO implementors: Apart from approaching a consultancy like Blackmores to help if it's your first time going through the process, it's got to be leadership commitment.
Top management need to be actively promoting ISO within the business, and they should be involved with the process. You need everyone's buy-in to make a system work, and that is made much easier if it's driven from the top down.
Another tip is that a Management System should be a team effort. It shouldn't just be the responsibility of one person, you need input from everyone in the business to ensure you've covered all angles and risks that could affect your business.
Lastly, look at what you already have in place and try and integrate the Standard into that. Don't make more work for yourself if you don't have to, you likely already have the bones in place.
[28:20] Damian's book recommendation: The Thursday Murder Book Club – by Richard Osmond
[29:10] Damian's favourite quote? "Hard work beats talent when talent doesn't beat work hard."
And:
"You miss 100% of the shots you don't take"
To learn more about Wavenet, check out their website and keep up-to-date with their latest news via their LinkedIn page.
If you'd like any assistance with your ISO Implementation or need any additional ISO Support, contact us, we'd be happy to help.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the video interview here
Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme.
The drivers for this demand are varied, as is the approach many take for their path towards carbon verification. This can look very different depending on the industry you operate in and can be difficult to tackle for more service based industries, such as today's guest, Davies Group, who are a service provider for the insurance industry.
In this episode Mel is joined by Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss the findings of Mel's thesis regarding the demand and drivers of GHG verification for organisations across the globe, and how Davies Groups' carbon verification journey factors into the findings.
You'll learn
· Who is Gillie Fairbrother and who are Davies Group?
· What factor triggered the decision for independent carbon verification at Davies Group?
· At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard?
· What did Davies Group's GHG inventory and reporting look like before independent verification was introduced?
· Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally?
·
· What is the gap between organisations knowing they should verify emissions and actually doing it?
· Was competitive positioning part of the Davies Group case for carbon verification?
· What was the most significant finding from the first carbon verification engagement?
· How has verification changed the internal culture and engagement with the sustainability programme at Davies Group?
· How have Davies Group supported suppliers with calculating their carbon emissions?
· Where does Gillie see the expectations of institutional partners and large clients in insurance and professional services heading?
· What was a specific moment where Gillie can recall that this mattered more than she had expected?
Resources
· Davies Group
· Davies Group LinkedIn
· Carbonology – Carbon Verification Services
In this episode, we talk about:
[00:30] Episode Summary – We introduce Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss their participation in Mel's thesis research into the demand for GHG emissions, exploring Davies Group's own reasoning and journey.
[02:05] Who is Gillie Fairbrother and who are Davies Group? A route into sustainability as a career wasn't as readily available to Gillie when she attended university, so it has been something of a self-made path.
She has previously run a wellness business in the past and has experience working with sustainable brands and has done a lot of cultural advocacy, particularly in the LGBTQ space.
Taking the lead for ESG within the corporate space was a dream come true for Gillie, and she has done this for a number of US based tech firms to her current position for Davies Group.
Davies Group are a service provider for the insurance industry, who operate in 22 countries.
[03:40] What factor triggered the decision for independent carbon verification at Davies Group? Mel's research found that 29% of organisations cite market-driven factors as their primary reason for seeking GHG verification, compared with just 12% who cite regulatory compliance.
For Davies Group, their decision was led by market demand. They looked client requests versus client contractual obligations, and carbon verification was increasingly coming up in those contractual obligations.
Gillie herself has always been an advocate for working both sustainably and responsibly, promoting the revenue benefits that can be gained from doing so. However, as much as it is perceived to be the right thing to do, she doesn't want businesses to simply think of it as the 'nice thing to do'.
These should be central components to how your business operates. So in part, Davies Group saw this demand not only in the market, but as simply the right way to do business.
[05:30] At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard? Davies Group already operate in a highly regulated market, and so already have very strong governance practices in place.
Gillie didn't really have to worry about making too many improvements in the governance or purpose aspects of ESG compliance.
They participated in TCFD on a voluntary basis to highlight a possible risk from a climate perspective that could affect things like supply chain, physical sites, or the industry in general to leadership.
Thankfully, the leadership saw this as a risk worth looking into more, and were willing to quantify it properly and ensure that their data was as accurate as possible and in a place where it could be audited by a 3rd party.
[07:40] What did Davies Group's GHG inventory and reporting look like before independent verification was introduced? Before Gillie joined, these aspects were managed by a 3rd party due to lack of in-house expertise to manage it.
When Gillie joined, she worked closely with that 3rd party to continue the work. Davies Group is quite a complex business, it operates with 3 different divisions that have multiple service lines.
At the time, they did their best with the Excel spreadsheets that they had create to track various GHG emissions, but it was not as good as it could have been.
They've since grown their processes, included more in-house talent and are doing more to gain knowledge from their stakeholders, data owners and building relationships with various teams across the business.
While they are still working on Excel spreadsheets, they have advanced to reasonable assurance. Gillie is now looking into external tools to help improve their data management, but this would cost a fair bit of money that could be better used currently on reducing environmental impact.
[10:30] Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally? Gillie cites employees, as they're an industry where 30% of the workforce is likely going to retire in the next 10 years, so they're trying to attract a younger group of talent who want to work for a business that has a good purpose and is a good company. Acting sustainably and responsibly is a huge part of attracting that new young talent.
The second more important stakeholders are their clients. Davies Group is a private equity backed business, if they're not making money then they simply cease to exist as a business. Clients now have a keen interest in responsibly run businesses, and many now seek proof to claims.
Next in the list is investors, who have an interest in the regulatory requirements that the business is subjected to.
Lastly, Gillie cites suppliers as even if they aren't actively putting pressure on the business to report their emissions, without their support and cooperation, Davies Group can't meet their own goals.
[12:40] What was a particularly memorable conversation with a Stakeholder that helped drive further improvement? Gillie recalls one conversation with a new employee where they asked to be more involved with their sustainability group.
When she talked to them more, she discovered that one of the main reasons that employee sought them out was due to the responsible business page on their website, and that out of the 3 businesses they were applying to, Davies Group was the only one that had a page like that.
[37:00] What is the gap between organisations knowing they should verify emissions and actually doing it? Mel's research found that 86% of organisations report increased stakeholder demand for transparency in GHG reporting – yet 52% remain unverified.
Gillie states that there could be a lot of reasons for this, including budget, resourcing or something as simple as a piece of wording in a contract where a client might say we request versus we require.
This is why Gillie is always in conversation with clients, whether that be the sales team or the sustainability teams at our clients, to understand their goals and make sure they can all align in their goals.
The market is certainly the leading cause for many businesses as Government regulation tends to lag behind.
[17:20] Was competitive positioning part of the Davies Group case for carbon verification? For Davies Group, it was initially a contractual requirement to complete their carbon verification. So, in their case, it was an easy decision as otherwise they could potentially lose business.
However, Gillie also regularly meets with senior leadership and reports into their responsible business board committee every quarter. There they consider the growing appetite for sustainability driven demands, and how they want to leading the way in their industry. The key determining factor is whether it's relevant to them, whether that's for sustainability or for their community impact strategy.
Davies Group tend to focus on education and investment in our communities, as that's where their expertise sits. It's all about materiality as businesses need to focus on what's relevant to them.
[19:20] What was the most significant finding from the first carbon verification engagement? For Gillie, it was the clarity and transparency that had been game changing. Especially within their real estate portfolio.
Davies Group don't own any of their offices, they're all leased. As they calculated and verified the carbon footprint, the quality of the data got better and that enabled them to have better conversations with their real estate team to understand how a building worked, whether it be a lease, including services or whether it be separate.
As a result, they've been able to set a renewable energy target for all UK offices.
[19:20] How has verification changed the internal culture and engagement with the sustainability programme at Davies Group? Mel's research identifies a strong correlation between verification status and organisational confidence, with 85% of verified organisations expressing pride in their sustainability progress, compared with 50% of unverified ones.
Gillie's been writing the sustainability report for Davies Group for the past 6 years, and she can feel the difference after having their emissions verified as it adds an extra layer of credibility.
She's also wary of stepping into bragging territory about all their sustainability achievements, without reflecting on the reality. There can be a conflict between writing what the stakeholders want to hear versus what is accurate and true.
Having independent 3rd party verification gives you the confidence to back any claims made.
[24:10] How have Davies Group supported suppliers with calculating their carbon emissions? Gillie is particularly proud of an industry wide collaboration project that had close to 100 SMEs go through a Net Zero training programme that was provided by a third party.
Gillie joined many of the sessions and was so pleased to see sustainability champions emerge through the process where people suddenly got really invested and starting asking rather complex questions.
They're still gathering feedback from those sessions, but already 80% - 90% have calculated a starting carbon footprint and put in place an action plan to help reduce their impact.
This year, Davies Group have also kicked off a huge training and engagement plan with their service delivery teams who are making the decisions about their suppliers.
They've also engaged with over 400 employees in their UK groups for property claims on sustainable solutions, getting their ideas, understanding the challenges and coming out with some outcomes so they can measure the carbon of their claims process and look to reduce it. Gillie teases the pending results, so keep an eye on their socials to find out more!
[27:50] Key advice from Gillie: Focus your supply chain effort on your biggest emissions rather than your biggest spend, and tackle this in small groups.
[29:30] Where does Gillie see the expectations of institutional partners and large clients in insurance and professional services heading – and at what point does she think verified GHG data becomes a non-negotiable baseline in your market? Many businesses have been waiting on legislation and regulations to point the way, and in a sense, they will always be waiting as these things develop with our understanding and technology available.
However, businesses have done a good job of stepping up as those regulations lag behind.
There's a lot of mixed press regarding sustainability, with some professionals feeling as if the topic has come off the boil as article cite the loss of dedicated sustainability officers. The reality on the ground is that these roles are now much more embedded into the business, they're not being removed, simply passed onto roles such as the Chief Operating Officer to ensure sustainability targets are being met.
The bottom line is that the momentum for sustainability isn't going away, and that need to verify emissions is only going to grow. The key thing now is to move on from simple calculation into action, which is what Gillie is trying to drive right now.
[32:05] What was a specific moment where Gillie can recall that this mattered more than she had expected? Gillie is so proud of what their small and mighty team at Davies Group has done for their social impact.
When initially established, they were only in 1 country, they've now expanded to 22 countries and they've really focused their resources, time and effort on impacting community education and skills development, which she anticipates will have a full circle around to attracting talent into our industry.
To see more about the impacts that Davies Group are orchestrating, check out their LinkedIn page.
If you'd like any assistance with your carbon verification journey, contact our partner Carbonology, they'd be happy to help!
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That's not surprising as it's quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide.
We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Steve Mason, a Principle isologist® at Blackmores, to share the journey of how he went from intern, to ISO Assessor, to ISO consultant and the challenges he's faced while working with clients.
You'll learn
· What is Steve's role at Blackmores?
· What does Steve enjoy outside of consultancy?
· What path did Steve take to become an ISO Consultant?
· What is the biggest challenge he's faced when implementing ISO Standards?
· What is Steve's biggest achievement?
Resources
· Isologyhub
· ISO 14001:2026 What's Changed And How to Comply Webinar Registration
In this episode, we talk about:
[00:30] Episode Summary – We introduce Steve Mason, a Principle Isologist® here at Blackmores, to discuss his journey towards becoming an ISO consultant who specialises in ISO 27001, ISO 27701, ISO 27018, ISO 27017 and ISO 20000-1.
[02:40] What is Steve's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards.
As part of that support, he:
· Makes Standards understandable and accessible to clients
· Conduct internal audits
· Reviews and updates management system documentation
· Facilitate management reviews
· Train internal teams and prepare them for certification audits.
Steve is the Standard champion for ISO 27001, ISO 27701, ISO 27017, ISO 27018 and ISO 20000-1 at Blackmores, but he also deals with ISO 9001, ISO 41001, ISO 22301 and ISO 42001 related projects and support.
Steve's other main role at Blackmore's is as a Mental Health First Aider, which is shared with Minoo Agarwal. Together, they provide resources and offer support to the team.
[06:00] The importance of Mental Health management in the workplace: Steve had faced bullying in previous roles, so preventing others from experiencing the same had become a big motivator for him taking on the role of Mental First Aider for Blackmores.
He emphasizes it's importance, and highlights 2 key Standards that you can use to help support mental first aid within your business. This includes ISO 45003 Mental Health in the Workplace and BS 30480 Suicide and the Workplace.
[09:10] What does Steve enjoy doing outside of consultancy?: Steve has a wide variety of interests and hobbies, including:
Lay Minister: Steve is a Lay Minister in the United Reform Church and mainly based at the URC Chapel in Walkern, but can be found leading worship and preaching at Ashwell, Baldock, Stevenage and Knebworth chapels.
Poetry: Steve enjoys writing poetry about anything and everything, racking up an impressive 190 poems so far. Some of his main inspirations include Wordsworth and Keats. If you ever see a poem on the Blackmores LinkedIn page, odds are, it was written by Steve!
Classical Music: He's a fan of classical music, anything by Beethoven, Mahler or Shostakovich specifically. He likes these composers in particular due to their stretching of the rules of music for the time.
Exploring hidden London: Steve often goes on hidden London tours which explore disused underground stations which may have been shut down as long as 100 years ago!
Buses and Trains: Steve was lucky enough to drive a bus in his past, of which he has the licence plate of sitting in his office. He collects bus and train models and will go out to snap a photo or two of their real world counterparts when he comes across them.
History: Steve is a huge mystery buff, with a particular fondness for Richard III and the War of the Roses and the Anglo Saxon period of history.
Family Tree: Steve has been tracing his family tree back as far as he can on his mother's side, which extends as far back as 1547! Interestingly enough he found out that relatives from way back then got married in the church that he currently lives nearby and got qualified as a Lay Minister for the Church of England in Stevenage!
Cats: He's owned his fair share of feline friends through the years, with one particular tabby holding the name 'Spartacus'.
[22:35] What was Steve's path towards becoming an ISO Consultant?: Steve was once told in the 1980s 'There is no future in Standards; find another career, perhaps in Sales or Purchasing'. How wrong that turned out to be!
He's always worked with standards, from the first day he started work doing inspection in Goods Inwards, he was referring to them. The direction towards Management systems came in 1983 when he started implementing BS 5750. From that day onward he had been involved in Management Systems.
Steve completed a management apprenticeship at Racal-Guardall where he was able to do 3 months' work experience in all departments, which helped him appreciate how companies function and how important it is to maintain good communication channels. He was at the end of this apprenticeship that the opportunity arose in the QA department to work on BS 5750.
His career path has included other organisations such as Tektronix, BOC Ohmeda, Cirkit, Deta, TDK and BSI, all of which earned Steve a lot of experience in Manufacturing and Service and Distribution, mainly in Quality and Customer Service roles.
Steve has always felt a bit like a closet consultant, even when he worked as an assessor at BSI. He feels as if Blackmores has enabled him to fully flourish and develop his portfolio of standards – not bad for a career where there was apparently no future in standards!
[28:45] Born to be a consultant – Steve mentions that consultancy is a skill that many are born to be. You can train and learn the skills of course, but for some it comes very naturally and it can be hard to replicate that skillset in others.
[30:15] What is Steve's favourite aspect of being a Consultant? Steve loves talking with clients and working with them to explore solutions that can address the requirements of the standards. His motto is 'Mould the Standard to the organisation and not the organisation to the standard'
This means, always producing a management system that benefits the organisation first and then adjusting it to meet the requirements of the standard. Organisations that mould the business to the standard usually end up with a management system that is a 'bolt-on' and an uncomfortable, sometimes irrelevant, fit. Everyone in the organisation needs to feel that the management system is a natural fit to what they do.
He also enjoys supporting his colleagues at Blackmores. We're a business built on knowledge sharing, and there's no point gatekeeping anything we've learned as a team. So consultants often get together to discuss lessons learned and ensure best practice is a shared experience.
Ironically enough, one of Steve's least favourite aspects of being a consultant is auditing! Mostly since he's been doing it for some 40 years now, so he can be forgiven for finding the exercise a bit tedious at times. However, he never let's that affect the end result of an audit.
[37:00] What Standards does Steve specilaise in and why? Steve initially started with ISO 9001 but was steered towards ISO 27001 and ISO 20000-1 during his time as BSI. This was based upon his career path up to the point he joined BSI as they align assessors to familiar business and technical environments.
In Blackmores, he has been able to develop these areas of Quality, Service and Risk by adding standards related to Business Continuity, PII and Cloud Security, Facilities Management and AI Management.
Steve's favourite standard is ISO 20000-1 which started off as an IT Service Management System but can also be used effectively for all services. He always refers to ISO 20000-1 as 'ISO 9001 on Steroids' because it is much more specific and focuses on the subject of service management.
Sadly, ISO20000-1 is under rated, under sold and in some cases, never heard of – this is usually because contracts require IS O9001 but the people writing those contracts don't actually know or understand what they are asking for.
In simple terms it is a Service Quality Management System and Steve has come across organisations which have shoe-horned ISO 9001 into the business instead of using the natural fitting standard ISO 20000-1.
Steve would advise any company that is providing a service with helpdesk support to look at ISO 20000-1, especially if they find that ISO 9001 isn't working well for them.
[43:00] What is the biggest challenge Steve had faced during a project and how did he overcome it?: Creating a management system in 10 days for a client which was due to lose a major contract because they had let their certification to ISO 9001 lapse between the 2008 and 2015 versions. Quite the undertaking in such a short amount of time!
Steve refuses to claim full responsibility for the success however, as the client was totally invested in getting the system up and running and put in a lot of effort to work with Steve to get it done in time. If it had been any other standard, it would have been impossible, but because it was ISO 9001 and wthey were drawing on what had been in place previously it was possible.
Generally, problems arise when there is limited or no Leadership support and commitment, because without this management systems can't be set up in a way that benefits the organisation.
All management systems must align with the Business Strategy and should be used to ensure that the strategy is achieved.
If you'd like to learn more about the importance of Leadership and aligning your management system with strategic direction, check out a few of our previous episodes.
[50:10] What is Steve's proudest achievement? Steve isn't really one to collect achievements, so he cites winning 1st Prize at 6 years old in a fancy-dress competition, dressed as a Snowman was a proud achievement for 6 year old him.
He is also proud of becoming a Lay Reader initially in the Church of England at 37 and latterly in the URC.
Another highlight is appearing on The Chase back in 2017, successfully passing the auditions which saw 40,000 applicants. If you want to go see him go up against the Chasers, he was in Series 10 episode 119.
He can't point to any one ISO related project as he sees them all as an equal success. He puts all his effort into every project, and his success track shows this to be evident.
[54:35] ISO 14001 Transition Webinar: If you currently hold a 2015 certificate for ISO 14001, then the countdown has already started to transition to the latest 2026 version.
We'll be covering the changes and what you need to do to comply and complete your transition in a webinar on the 29th May. You can register your place here.
If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help!
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Most ISO Standards are designed with implementation flexibility in mind. They set the framework without specifying an exact method to meet requirements, giving businesses the freedom to implement them how they see fit.
One of the key requirements you can't escape, however, is documentation. This is more than a list of key documents you must have in place, it encompasses how you develop, control and store documented information.
In this episode, Ian Battersby dispels common myths around documentation in ISO, explains what the requirements actually mean in practice and how you address each one relevant to documented information.
You'll learn
· Common misunderstandings about documentation within ISO
· What do current ISO Standards require for Documented Information?
· How do you determine what should be documented information?
· How do modern Standards embed a flexible approach?
· What is considered 'documented information?'
· Breaking down clause 7.5 Documented information
· How to address clause 7.5.2 Creating and Updating documentation
· How to address 7.5.3 Control of documentation
· A cautionary tale for modern approaches to Documentation
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian dives into the topic of documentation within ISO, dispelling the myths and breaking down the requirements you need to meet relevant to documented information.
[02:40] Common misunderstandings about documentation within ISO: Taking ISO 9001 as the prime example, the most common misunderstanding is that you need a policy manual. This is not true.
This may have stemmed from previous versions of ISO 9001 where certain mandatory procedures were required, such as:
· Control of Documents (Clause 4.2.3)
· Control of Records (Clause 4.2.4)
· Internal Audit (Clause 8.2.2)
· Control of Nonconforming Product (Clause 8.3)
· Corrective Action (Clause 8.5.2)
· Preventive Action (Clause 8.5.3)
There were also mandatory records such as Management Review, calibration, supplier evaluation, design/development reviews etc.
With the introduction of the 2015 version of ISO 9001, the old terms 'Procedure' and 'Record' have changed into a single term now known as 'Documented Information', which breaks down those previous terms into the following:
· Documented information to be maintained — Previously what would have been a procedure (i.e., describing how something should be done)
· Documented information to be retained — Previously what would have been a record (i.e., evidence that something was done)
[05:10] What do current ISO Standards require for Documented Information? The 2015 version of ISO 9001 received the following updates:
· Removed the prescriptive language associated with the old terms
· Gave organisations the flexibility to develop, control and store documented information
· No longer dictates the form that documentation must take
In practice, many people still use the terms procedure and record informally, because they are well understood and conveniently descriptive. But beware using language that reinforces old-fashioned ideas about how we create management systems.
This newer language aligns with modern risk-based thinking, with direct references made to this being included in the Standard. But, while that sounds prescriptive, adopting risk-based thinking has allowed a less prescriptive approach to the standards. It allows you to consider what's significant to you and so you can plan your system accordingly.
[07:20] How do you determine what should be documented information? The effort you put into documenting something must be consistent with the risk
If, for example, a process is important, if its outcome could be in doubt, if it's complex to control, if it could lead to damage/harm, if there's a regulatory requirement, then you should put some effort into documenting how it's performed.
But, if you maintain that documentation in response to the risk to your organisation and not in response to a prescriptive demand in standard, and if a process attracts less risk, then you can deliver it with less formality and less documentation to be maintained.
The same goes for retaining documentation to evidence that you've done what you should. In short: more risk, more documentation retained to demonstrate that you've controlled it.
[08:30] How do modern Standards embed a flexible approach? ISO Standards are deliberately flexible. The extent of documented information required depends on the size of your organisation, the complexity of your processes, your customers' needs, your regulatory environment and the competence of your people.
An organisation of only 10 people will have very different needs compared to one of 10,000, and both can fully conform to the standard. It's about proportionality, not volume.
[09:20] What is considered 'documented information? ISO standards don't care what you call the documents you maintain in order to govern how you deliver your daily work.
Other than using the term process (and the process approach) to underpin how systems should interrelate, ISO 9001 doesn't specify anything else.
Would you like to use the term procedure? Or management procedure? Or SOP? Work instruction? Process map, guide, playbook, manual.
Or is your activity embedded in an online system? A workflow? A board?
It doesn't matter, you can call it what you want, and as long as it's controlled to the extent that it needs to be.
[11:05] Breaking down clause 7.5 Documented information: ISO 9001 states:
"7.5.1 General:
The organization's quality management system shall include:
a) documented information required by this International Standard;
b) documented information determined by the organization as being necessary for the effectiveness of the quality management system.
NOTE The extent of documented information can differ from one organization to another due to:
· the size of organization and its type of activities, processes, products and services;
· the complexity of processes and their interactions;
· the competence of persons."
This reinforces the fact that there is no 'one size fits all' approach.
[12:15] How to address clause 7.5.2 Creating and Updating documentation: The Standard states:
"When creating and updating documented information, the organization shall ensure appropriate."
Note that word, 'appropriate'. It doesn't indicate specifics, it indicates that you should choose certain things according to your own circumstances
So the appropriate things which you should ensure are:
Identification and description:(e.g. a title, date, author, or reference number) One trap many fall into, is the use of reference numbers. In most cases they are unnecessary. Only use them if they mean something or make life easier.
Having reference numbers with department numbering can reinforce the silo mentality; 'that's their procedure, not ours', so it's best to avoid creating that situation by foregoing reference numbers if possible.
What matters is that any users are able to easily verify that they have the right document, this can be done with a descriptive title, version numbers and a date for the version.
Online documents may have details embedded in metadata or an information box that can make this process easier to implement.
Format and media:
You'll need to consider language required for certain documentation, as international systems where there are multiple languages used by the workforce, may require additional versions.
You'll also need to establish which templates or layouts to use. Look and feel will likely be important in the organisation, so you'll want to keep documents on brand.
Other considerations include:
· The use of process maps, flowcharts, diagrams, tables, or written text.
· The software or application it is created in (e.g. Word, PDF, SharePoint)
· Whether the document is paper-based or electronic
Review and approval for suitability and adequacy:
Documented information requires appropriate review of content, this is to make sure it does what it should and that all of the above is covered.
You will also need sign-off by someone with the appropriate authority, and that authority is determined based on risk related to that document.
[18:00] How to address 7.5.3 Control of documentation: Let's break down each part of this clause:
"To ensure that
a) it is available and suitable for use, where and when it is needed;" - It must be circulated, hosted, displayed or whatever, so that those people who are required to see it, use it, know of its content can act on it.
"b) it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity)." - It must be protected so that only the right people see it, so that any confidential information is not inappropriately shared, and no one can use or amend it without the appropriate authority. This is to ensure it remains in the manner it was intended and that its content can't be altered, corrupted or destroyed.
"7.5.3.2 For the control of documented information, the organization shall address the following activities, as applicable:
a) distribution, access, retrieval and use;
b) storage and preservation, including preservation of legibility;
c) control of changes (e.g. version control);
d) retention and disposition."
This clause adds some meat to the ideas discussed already
"a) distribution, access, retrieval and use;" – This refers to who receives a document and by what means, whether the right people can access it and know what to do with it at the time they need it, while also considering the sensitivity.
"b) storage and preservation, including preservation of legibility;" - The physical or electronic location of storage and its usefulness over time. You'll need to ensure that physical things are safe from damage (fire, flood etc) and that electronic formats are protected from obsolescence.
"c) control of changes (e.g. version control)" - Who is allowed to edit, authorise, publish, issue and host a document. Establish a method of ensuring only relevant, current information is accessible by the right people, and record the history of changes where necessary.
"d) retention and disposition." – Ask yourself: how long should documented information be kept? What's useful? What's regulatory? What does the customer want? What do you do when you don't need it any more? What do you do to prevent access to obsolete information?
[22:30] A cautionary tale for modern approaches to Documentation: These days, we're seeing more and more systems relying solely on electronic documentation. This brings big advantages, but also risks.
While there are excellent methods for document control in all sorts of hosting, sharing, collaboration platforms, they still need to be managed.
Too often we see systems with multiple versions of similar documents, naming disasters, obsolete versions, poor formatting, lack of authority, breaches of confidentiality, and the simple inability to find what you want!
Modern systems can help with documented information, but they don't remove the need for managing documentation.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Most ISO Standards take what's known as a 'risk-based approach', which focuses on proactively identifying and mitigating potential risks while capitalising on opportunities.
The methods for managing risk can be very varied, and many make the mistake of treating it as a separate task rather than as an integrated part of your existing processes.
In this episode, Ian Battersby explains what risk management means in regard to ISO management, what this looks like in practice and breaks down different methods you can utilise for effective risk management.
You'll learn
· What is risk?
· Where is risk referenced in ISO Standards?
· How do you identify risks and opportunities?
· How can you document risks and opportunities?
· What does a Risk Register look like?
· How are risks categorised?
· How many risks should you document?
· How do you evaluate and rate risks?
· How do you address opportunities?
· How can ISO 31000 help?
· How different ISO Standards define their relevant risks
· Governance and risk management
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian dives into the topic of risk management within in ISO. Explaining what risk is, how they should be documented and evaluated and what methods you can use to do so.
[02:45] Further info on risk management: If you want more guidance there is a dedicated risk management Standard (ISO 31000).
[03:10] What is risk? Risk, as defined by ISO Standards is:
"An effect of uncertainty on objective.
An effect is a deviation from the expected. It can be positive, negative or both, and can address, create or result in opportunities and threats"
So important to note that this includes both risks and opportunities.
[03:40] Where is risk referenced in ISO Standards? The main risk related requirements can be found in Clause 6 Planning for most ISO Standards:
6.1 Actions to address risks and opportunities - There's a positive and a negative aspect mentioned right from the start.
However, these elements aren't relegated to a few clauses. ISO Standards are built on a 'risk-based approach', which is directly mentioned within the introduction:
"This International Standard employs the process approach, which incorporates the Plan-Do-Check-Act (PDCA) cycle and risk-based thinking
Risk-based thinking enables an organization to determine the factors that could cause its processes and its management system to deviate from the planned results, to put in place preventive controls to minimize negative effects and to make maximum use of opportunities as they arise."
While it is prescriptive, it does allow flexibility for businesses to determine what risks are significant to them.
Other places it's mentioned in Standards includes Leadership:
"Top management shall demonstrate leadership and commitment by: d) promoting the use of the process approach and risk-based thinking"
It's not just about adopting the risk-based approach, leaders have to promote it. The use of the word 'shall' indicates that this is not optional and cannot be delegated.
[08:10] How do you identify risks and opportunities? The Planning clause directly references clause 4, which is Context of the organisation.
Within that clause, businesses are required to think about the things which affect the way you operate, the world in which you work, the people and organizations you must consider, the obligations placed upon you.
One key activity that typically happens at that stage is a SWOT and PESTLE, that's not specified by the Standard but it's a very popular method of identifying your risks and opportunities against multiple areas.
The results of which can be fed back into Clause 6 Planning when it asks you to consider and do the following:-
· Give assurance that the system can achieve its intended result(s);
· Enhance desirable effects;
· Prevent, or reduce, undesired effects;
· Achieve improvement.
· Plan actions to address these risks and opportunities;
· Integrate and implement the actions into its system processes;
· Evaluate the effectiveness of these actions.
This is where you have the freedom to determine what significant risk means to your business. This also establishes the approach to risk management as proactive rather than reactive.
[13:15] How can you document risks and opportunities? Just because you need to determine risks, you don't necessarily need a risk management process or methodology based on the guidance in a standard like ISO 31000.
There's no requirement to even have a risk register! However, we do strongly recommend using one.
If you choose not to use one, you could document each risk individually with the plan of action to mitigate it. This is fine, but a register allows you to see what's happening across all risks.
It allows comparison of different types, different categories, across different parts of the organisation, at different levels. It can support decision making and allocation of resource where there's competition for that resource. It can prompt escalation and more significant management attention where it's needed.
It can also form a basis for reviewing the effectiveness of your processes.
So, while not a firm requirement, it can be a very useful tool.
[15:20] What does a Risk Register look like?: A typical Risk Register usually sits in a table or Excel document. You can number your SWOT and PESTLE findings and put them into this Risk Register.
One of the columns included is interested parties affected by it, e.g. the risk that your processes deliver the wrong product directly relates to your customers; the risk of enforcement may relate to your board; the risk of terrible PR may affect your investors; the risk of polluting may affect the local population, enforcement agencies etc
Certain standards also require you to determine compliance obligations associated with each interested party, so that may be useful to add as a column.
Then, you need a column for detailing what the impact of the issue is (remember, both positive and negative). Then you need to evaluate each entry, this involves measuring the significance, the size and scale.
When evaluating risks, you need to indicate which processes you have in place that control the risk. Then you need to rate the risks in their current (do-nothing) form.
This is where it helps to have a register where different types and categories can be judged alongside each other, so you'll be able to see what's really important in one place.
An organisation needs to decide what level of risk it's prepared to accept; this may be a straightforward decision where a specific value triggers escalation and action, but it may be more complex, depending on the organisation you are in and the environment in which you operate.
If the risk is acceptable, should you still commit resource to addressing it; there's a balance in reducing risk overall; is it an easy win? Is it easy to do?
If you feel you should address a risk, what method of risk treatment should you adopt?
The actions you propose to take should then be set out in proper detail: who will do what by when? What resource? Basically detailing the measures to assess effectiveness.
If a risk or a group of associated risks require an objective, state clearly and link to that objective.
[21:35] How are risks categorised? The types of risks you will be focused on will depend on the ISO Standard you're implementing.
For example, for ISO 9001 this will be the ability to consistently deliver the best we can to our customers. For ISO 45001 the ultimate aim is to protect your workforce from harm.
Regardless, you can get quite broad with the nature of your risks, including considerations such as the ability to fund right equipment and infrastructure; or any investment in a sustainable future; the competence of personnel; the safe working environment to deliver products/services; compliance with relevant legislation; forces affecting our market; stability of supply chains; reputation; social attitudes to work, technology etc
But, regardless of whether you're certified to a multitude of standards, operations are typically so interdependent that you can't separate financial risks from operational ones etc.
[23:55] How many risks should you document? It's easy to get overwhelmed by generating a huge register when you're a small organisation, but you should be realistic. Focus on what's really significant.
If you do a SWOT/PESTLE, if it generates lots of issues but not everything has to be treated as a risk and opportunity for the risk register.
First, ask yourself, what will actually have an impact on you if it materialises? What is beyond control or influence? What requires just monitoring?
A larger organisation will tend to generate a larger register, but this can be categorised in different ways:
· Split by functions
· Split by category (operational, safety, compliance, financial)
· Significance; operational vs strategic or corporate
· This can be done by the scale of the risk, any risk above a specific threshold could be escalated to the strategic level
· There could be factors in the risk evaluation which include strategic significance
· There could be specific subjects (eg, compliance) which you automatically escalate to a strategic level
[25:55] How do you evaluate and rate risks? There are lots of complex and sophisticated ways of doing this. Certain sectors, industries, processes have specific needs and ways of evaluating risk. But, if you're new to this, or there aren't such complexities to consider, a very simple methodology is best.
Keep to a simple matrix of consequences and likelihood. Consider what the impact would be if the risk materialised, and rate these from 1 to 5:
1 = the consequences are not significant, it would only be a slight impact on the organisation, minor disruption, small financial loss, little/no physical harm.
5 = the consequences are disastrous, it could materially affect the way the organisation operates, it could cause serious physical harm, it could lead to severe financial loss, it could totally prevent us delivering our products/services.
Now consider the likelihood of the event occurring, again rating these from 1 to 5
That could be qualitative evaluation:
· 1 = very rarely
· 5 = happens regularly, or it's certain to happen
OR, it could be more quantitative
· 1= once in ten/five years
· 5 = daily/weekly
Then multiply these numbers and plot them on a matrix. The matrix will then provide a visual heat map that indicates the level of risk and inform about the level of resource you should apply to addressing the risk.
[29:15] How do you address opportunities? You can also evaluate opportunities in a similar manner. Rather than assessing negative consequences, you consider the positive impacts on the organisation when an event occurs.
These are plotted in the same way on a matrix, but with appetite and tolerance rather than consequences and likelihood.
Risk appetite can be defined as 'the amount and type of risk that an organisation is willing to take in order to meet their strategic objectives'.
These appetites range from averse, cautious to an open, eager appetite.
For example, a public sector risk appetite example could a local council adopting a "cautious" approach to financial management while having an "open" appetite for innovation in digital service delivery. This balances the need for fiscal responsibility with the desire for improved efficiency, often accepting higher risks for long-term environmental or social gains.
Risk tolerance is the actual threshold that you can get away with, that your organisation can bear before action / escalation is needed; financial, operational, reputational, enforcement.
This concept may not be for you if you're at an early stage of development, but one to keep in mind.
[32:00] How can ISO 31000 help? If we feel we should address a risk, what method of risk treatment should we adopt?
ISO 31000 Risk Management Guidance suggestions include:
· Avoiding the risk by deciding not to start or continue with the activity that gives rise to the risk;
· Taking or increasing the risk in order to pursue an opportunity;
· Removing the risk source;
· Changing the likelihood;
· Changing the consequences;
· Sharing the risk (e.g. through contracts, buying insurance);
· Retaining the risk by informed decision (no influence, cost too great)
[33:40] How different ISO Standards define their relevant risks: ISO 45001 states:
"The organization shall establish, implement and maintain a process(es) to:
a) assess OH&S risks from the identified hazards, while taking into account the effectiveness of existing controls;
b) determine and assess the other risks related to the establishment, implementation, operation and maintenance of the OH&S management system"
ISO 22301 Business Continuity states:
"The organization shall implement and maintain a risk assessment process.
The organization shall:
a) identify the risks of disruption to the organization's prioritized activities and to their required resources;
b) analyse and evaluate the identified risks;
c) determine which risks require treatment."
Be careful not to confuse these types of risk with organisational, system risks.
[36:05] Governance and risk management: A Risk Register is not a static document. It need to be reported on regularly, such as during Management Review meetings.
The register itself isn't evidence of good risk management. It's how you use it to demonstrate that your actions have addressed risks and opportunities which counts.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year.
The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.
Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do these two compare, and is there merit in implementing both?
In this episode, Ian Battersby is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to discuss what ISO 27001 and ISO 42001 are, the main differences between the Standards and how they can complement each other when integrated.
You'll learn
· Who is Bas Von Hertom?
· Who are TUV Nord?
· What are ISO 27001 and ISO 42001?
· How does ISO 42001 support regulatory frameworks such as the EU AI Act?
· How do ISO 27001 and ISO 42001 differ in managing information security risks?
· Other key differences between ISO 27001 and ISO 42001
· How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place?
· Can ISO 27001 and ISO 42001 be integrated?
· What organisations should be implementing both Standards?
· How are Certification Bodies quoting for ISO 27001 and ISO 42001?
· Bas's advice to leadership teams looking to build a case for full certification
Resources
· TUV Nord
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to explore the differences between ISO 27001 and ISO 42001 and the benefits of integrating both Standards.
[02:30] Who is Bas Von Hertom? Bas is the Cyber Security Specialist at TUV Nord. He is a lead auditor for Standards including ISO 27001, ISO 42001, TISAX and standards specifically for industrial automation.
Bas had once stated around 5 years ago that he would never pursue a career in auditing, but once he came into contact with TUV Nord he decided to give it a go. Before joining TUV, he was a very hands-on systems administrator and many of those skills transferred well into auditing.
[04:45] Who are TUV Nord? TUV Nord are a UKAS accredited Certification Body. They also offer services for testing and inspection.
TUV have worked with a large range of sectors, from manufacturing and energy to IT, healthcare and even space.
[06:25] What are ISO 27001 and ISO 42001? ISO 27001 is the Standard for Information Security Management, with compliant management systems being called an ISMS. It provides structure for identifying, assessing, and managing risks related to the information security while also ensuring availability and resilience on the information security.
ISO 42001 AI Management is a much more recent Standard, being published in December of 2024. It focuses on ethical and effective AI management, with a system that applies to relevant products in addition to the wider business.
[07:30] How does ISO 42001 support regulatory frameworks such as the EU AI Act? The EU AI Act sets out legal obligations that organisations offering AI products must comply with, however it only defines the rules rather than providing any implementation guidance.
This is where ISO 42001 can fill the gaps, by providing a framework that will meet these regulatory requirements.
[08:45] How do ISO 27001 and ISO 42001 differ in managing information security risks? Both Standards take a risk-based approach to their subject matter, but the nature of the risks that each address are what differ.
ISO 27001 focuses on risks that relate to the protection of information assets based on confidentiality, integrity and availability of information. It's also ensures that business objectives are clearly defined and aligned with business strategy.
ISO 42001 on the other hand deals with a broader and more complex set of risks, because it also looks at ethical considerations. This can includes the monitoring and measurement of ethical risks such as AI bias and discrimination. It also looks at societal, legal and reputational risks as one of ISO 42001's key values is creating trust within the AI space.
[10:10] Other key differences between ISO 27001 and ISO 42001: Besides their subject matter, another key difference is the way objectives are framed and evaluated. In ISO 42001 these objectives have to be aligned with the Annexes within the Standard, which is something not commonly done when implementing ISO 27001.
ISO 42001 also requires an 'AI Impact Assessment', which again, aligns with the systems objectives as the results of the AI Impact Assessment will describe the way bias, ethical and societal considerations impact other requirements within ISO 42001.
[11:00] How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? If you already have ISO 27001 in place, you have a strong foundation for ISO 42001. ISO 27001 puts the fundamental base in place, with a governance structure, risk assessment processes, internal audits, corrective actions and methods for continual improvement.
There's a lot of overlap where the high-level requirements are concerned. However, ISO 42001 also looks at AI products and services, which differs from ISO 27001.
ISO 42001 may also require additional training for those involved with the management systems and the AI products and services.
[12:15] Can ISO 27001 and ISO 42001 be integrated? Yes, and in fact, Bas highly encourages it!
If you intend to implement both Standards, it's much more efficient to do so as an integrated management system. They both utilise the Annex SL format, a high-level structure that's shared with most ISO Standards, so they're designed to be integrated.
This also saves on duplication of effort where documentation is concerned and also potentially on cost if you require additional support with implementation.
[13:30] What organisations should be implementing both Standards? Both ISO 27001 and ISO 42001 can apply to any business.
Most businesses are now utilising AI in some form, and ISO 42001 can apply to those using it just as much as it does to those developing their own AI tools or selling related services.
However, sectors where ISO 42001 will likely become fundamental include the financial sector, where AI tools for fraud detection are becoming popular. There's also a growing need for it within the medical field as AI is increasingly used for research and development.
[14:30] How are Certification Bodies quoting for ISO 27001 and ISO 42001? There are a number of variables that Certification Bodies use to work out certification costs, these include size of the organisation and business complexity.
This can be tricky to calculate for ISO 42001 as you need to consider the amount of AI systems used before you can provide a quote. The full requirements for this are described in ISO 42006, which is a guidance Standard.
Most certification bodies will offer a discount for the combined certification to both Standards.
An integrated approach is certainly something that Bas recommends, in addition to ensuring that you keep the same auditor or audit team throughout the implementation. By having one team for both systems, you can complete combined internal audits to save on time and resources.
[16:20] Bas's advice to leadership teams looking to build a case for full certification: First of all, don't wait, just make a start.
A lot of businesses make the mistake of waiting until it's a common requirement within their market, which can leave you lagging behind the curve. Instead, strive to be one of the early adopters as that will give you a strategic advantage in the market.
This is especially the case if you already have ISO 27001 in place. You already have the foundational knowledge to implement ISO 42001, so just make a start on looking at risks relevant to ISO 42001.
Many businesses opt to implement certain Standard due to the demands of their clients, and ISO 42001 is likely to be added to that list. So it's better to get a head start!
Bas also recommends finding sources of guidance on ISO 42001 implementation. Whether that's sourcing training or an external party to advise, it's good to have other sources of knowledge of you're not familiar with the Standard or ISO implementation as a whole.
[21:30] Bas's favourite quote: We don't rise to the level of our expectation, but we fall to the level of the systems that we use.
If you'd like to find out more TUV Nord or are looking for ISO 27001 and ISO 42001 certification, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the video interview here
Europe is only partially on track to meet its 2030 environment and sustainability objectives, and while some objectives are being scaled back, we are seeing the introduction of more regional regulations that require tangible annual sustainability reporting.
Businesses that have built sustainability into their way of working from the start are leading the charge and defining what it means to operate responsibly. As with today's guest, Forest, an e-bike provider that is not only 100% powered by renewable energy but has also achieved the coveted B Corp Accreditation.
In this episode, Mel Blackmore is joined by Laura Elms, VP of Sustainability & Corporate Affairs at Forest, to discuss how they embedded sustainability from the start and explore their journey towards B Corp Accreditation.
You'll learn
· Who are Forest?
· Who is Laura?
· Why was B Corp important to Forest from the start?
· What other Standards do Forest currently hold?
· What does Forest's higher B Corp score of 99 mean in reality?
· How did Forest embed sustainability into a business from day one rather than retrofitting it later?
· How has Forest balanced growth with genuine environmental accountability?
· What does tackling Scope 3 look like in urban mobility?
· Why did they also attain Verra Validation, and why does third-party validation matter?
· How do sustainability, communications and public policy intersect in Laura's role?
· Advice for those seeking B Corp Accreditation
· B Corp Version 7
· What role do you think sustainable transport should play in helping cities to meet their net zero targets?
Resources
· Forest
· B Corp Accreditation
· Carbonology
In this episode, we talk about:
[00:30] Episode Summary – Mel is joined by Laura Elms, VP of Sustainability & Corporate Affairs at Forest, to explore how they lead the way in sustainability including insight into their journey towards B Corp Accreditation.
[01:10] Who are Forest? Forest is the only shared E-Bike operator to power its entire fleet with 100% renewable energy. It's also one of the world's first micro-mobility companies to have B Corp Accreditation and Verra Validation.
[01:40] Who is Laura and how did she get involved with sustainability? Laura admits that she had a rather non-linear approach to getting into sustainability.
She started her career shortly after graduating in financial communications and investor relations. Working in her first firm, she worked closely with a women called Caroline who went on to found Forest along with two other co-founders.
Caroline reached out to her 2 years after starting Forest and Laura felt it was a no-brainer as she had a pre-existing interest in sustainability, and had come to prefer the start-up space over a more corporate setting.
As is typical with the nature of start-ups, Laura wore many hats from the outset as it was a small team of four. Sustainability was what she was most passionate about, and has been the area she nurtured for Forest over the course of her six years working with them.
[03:40] Why was B Corp important to Forest from the start? Laura noticed that B Corp was gaining traction back when Forest started in 2020. She was curious about the intersection between B Corp and ESG, particularly from a start-up perspective.
When starting at Forest, she knew it would be a significant benefit to utilise renewable energy, but she felt like they needed to go above and beyond that. From there she researched B Corp and the costs involved, which were affordable as it's relative to your revenue, which is a great advantage to start-ups.
She was pleased to find that Forest could cover the 5 pillars of B Corp's credentials, not only providing bikes for urban settings but also providing excellent governance and additional benefits to their surrounding community, workers and environment.
In short, B Corp helped set the foundations for a good well rounded company that could grow.
[05:15] What other Standards do Forest currently hold? Forest currently hold ISO 9001 certification and are looking to implement ISO 14001 in the near future.
They currently operate within 18 boroughs in London, and are expanding from one central hub to several more warehouses, which is what will be covered under that ISO 14001 scope.
With B Corp as their guiding North Star, they're confident they have all the right foundations in place to grow as needed.
[06:10] What does Forest's higher B Corp score of 99 mean in reality? Within B Corp there are 5 pillars:
· Community
· Environment
· Governance
· Customers
· Workers
Its core focus is sustainability, but its approach is much more holistic and similar to the way ISO's implement a system that encompasses how a business works rather than just a siloed focus on one area.
B Corp looks at a multitude if areas, such as:
· Reducing Scope 1, 2 & 3 emissions
· Looking at your supply chain
· Evaluating how your activities interact with your stakeholders
To earn a B Corp score, you need to get certain marks and then you're scored across the 5 pillars.
Many businesses going for B Corp tend to do well in the sustainability area, but they struggle with other areas such as workers and customers.
The framework is designed to be more holistic than simply focusing on sustainability, so If you focus too much in that area, it may come at a detriment to the other pillars.
[08:20] How did Forest embed sustainability into a business from day one rather than retrofitting it later? Sustainability was Forest's vision and mission right from the start. Their CEO and Founder had previously worked at a ride-hailing company called Cabify, and had led the Latin American operations there.
Cabify was the first mobility company to offset all its emissions, this was prior to 2020 so it was seen as though-leader in the space.
This inspired the now CEO of Forest with the concept of 'Human Forest', which was the idea that humans on bikes in a city can save CO2 by choosing bikes over carbon emitting modes of transport.
Having it as a core part of the business from the start meant they didn't have to worry about budgeting road-blocks or additional approval. It was simply a part of the brand.
Laura can see why retrofitting the same level of sustainability commitment may be difficult for other businesses, as Forest had already baked in the price of renewable energy from the beginning and didn't have to worry about that transition.
Forest do differ in that unlike other larger companies that will be showing smoother trajectories towards net zero, they're already there. They face the unique challenge of keeping it there as they grow, as more bikes and available geographical locations means more manufacturing and bigger scope 3 emissions.
So their transition to net-zero will overall look a lot less linear.
[11:15] How has Forest balanced growth with genuine environmental accountability? Forest have managed to reduce their carbon footprint by 53% year on year, even with their continued growth.
Tackling environmental accountability can be something that gets businesses stuck in a rut, especially with any applicable regulations. As Laura quotes, often perfection is the enemy of good. Small incremental changes are better than trying to get it all right first time.
In Forest's case, to achieve that 53% reduction they looked at a more creative solution. Rather than manufacturing brand new bikes when needed, they reached out to the wider e-bike market to those that utilised their same manufacturer and asked if they had any spare bikes.
This helped to massively bring down emissions that would have otherwise been created making new bikes, by accessing a second-hand market. This can't be done indefinitely, but it's a small action that has created a large impact for that year.
Forest have also worked with manufacturers to help switch to using solar energy for the production process, which they are now monitoring to see how much this reduces emissions by.
[13:50] What does tackling Scope 3 look like in urban mobility? Scope 3 for most businesses is their biggest source of emissions, typically accounting for around 80-90% of a businesses total emissions. For Forest this is closer to 100%.
They've also noticed that compared to 3 years ago, the emissions are slightly less for things such as production and shipping of bikes. Laura admits that this may not be entirely due to the processes themselves getting more efficient, but as by-product of improving other areas such as technology or use of office spaces to help bring down the businesses overall emissions.
At this stage, it's getting the methodology right for scope 3, to ensure their data is as accurate as possible. This includes sending questionnaires to suppliers and making use of technology to improve data gathering and analysis.
[15:45] Why did they also attain Verra Validation, and why does third-party validation matter? Laura at the time was looking to ensure the highest level of credibility possible, which started with B Corp, ISO certification and then Verra Validation.
Verra was a leader in this space, and dominate the market in terms of carbon offsetting. Forest didn't want to go through the whole process to sell offsets with Verra as it didn't make sense for their business, but they did want the validation as another layer of credibility.
[17:45] How do sustainability, communications and public policy intersect in Laura's role? London, unlike most other major cities, does not have a single unified body, instead you have to negotiate borough by borough.
Each one has the option to pick different operators and set their own requirements, which adds an extra layer of difficulty on top of existing sustainability regulations.
Forest provided the perfect solution for various London boroughs who sought to reduce their overall carbon emissions.
[19:05] Laura's advice to organisations seeking B Corp Accreditation: Get in contact with B Corp itself. They done a lot to improve their platform, and there's a lot you can do via the portal without their assistance. However, B Corp and their team at B Lab can give you more insight and context for the data they're looking for.
She also recommends that you incorporate B Corp as early on as you can as it helps to set a solid business foundation.
Laura also recommends going beyond the B Corp portal after certification to reach out to the wider B Lab community, as there are a lot of fantastic brands to connect with.
B Corp will often host in-person networking meetings where certified businesses can catch-up, review progress and share new ideas.
[20:40] B Corp Version 7: B Corp have recently released (as of podcast publication) a new version of their requirements, raising standards once again.
One of the new requirements includes verification of an organisations' emissions, which includes products.
Forest only just received their B Corp re-authentication in December 2025, and their next focus is obtaining ISO 14001 for their new warehouses. However, they do intend to stay B Corp accredited, so will likely look at meeting version 7 requirements following that.
[21:45] What role do you think sustainable transport should play in helping cities to meet their net zero targets?: Transport makes up a third of UK emissions. Getting people onto more bikes and being more active will result in a significant reduction in emissions for our cities.
When Forest asked their users: what would you otherwise have done in terms of transport if you didn't get on one of our bikes, 11% said that they would have gone in a car or a taxi.
So an 11% modal shift, which is pretty significant! This doesn't account for private bike owners either.
For cities, there's a big push to get HGVs off the road and to retrofit spaces to accommodate for more cycle traffic. It's a lot to consider and will require a lot of work, but with transport making up a third of total UK emissions, it's worth the effort for the benefits it will bring.
If you'd like to find out more about Forest and follow along with their journey, check out the Linkedin page.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
For those in the automotive industry, namely suppliers working with European OEM's, you're likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from.
ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two.
For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don't intend to certify to both.
In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers.
You'll learn
· How does TISAX differ from ISO 27001?
· How does the recertification / annual surveillance for TISAX and ISO 27001 differ?
· Can a company have TISAX without ISO 27001 and vice versa?
· How can an existing ISO 27001 certification be leveraged for TISAX?
· What are the additional benefits of implementing both TISAX & ISO 27001?
· What is a reasonable timeframe for implementing TISAX?
· The key role of Internal Audits
· How can Blackmores support companies in implementing TISAX?
Resources
· Register for our TISAX webinar here
· ENX
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.
[03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association.
It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers.
[04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry.
ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations.
The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them.
[05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle.
TISAX does not require an annual Surveillance like ISO 27001, instead once you've earned a Label it remains valid for 3 years.
ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit.
If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal.
Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label.
[07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you're ready for re-certification.
You can of course carry on with annual internal audits to make sure you're on track.
This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.
[08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other.
Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised.
However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it's worth considering implementing both TISAX and ISO 27001.
[09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you're already 80% of the way there to TISAX compliance.
As TISAX is based off of ISO 27001's Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for:
· Data Protection
· Prototype protection
· Assets
· 3rd Party Suppliers
The amount of additional work will also depend on the TISAX Level you're aiming for, with Level 3 being the most demanding for these specific requirements.
[10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include:
Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations.
Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what's required to earn and keep both your ISO certificate and TISAX Label.
Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM's to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident.
Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX.
[12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc.
The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you're ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check.
If you already have ISO 27001 in place, than you're looking at between 3 – 6 months.
If you do not have ISO 27001 in place than you're looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it's all been communicated and the relevant individuals have been trained.
Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment.
Emma's top tip: Be honest in your self-assessment. It's there to be a benchmark, and you need to reflect on the reality of your position if you're to accurately assess what Level you are ready to be assessed against.
[14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001.
The Leadership ultimately drive TISAX's success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label.
For those within the Automotive Sector, TISAX is becoming an absolute requirement. It's being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label.
[16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you're on the right path.
They can help identify areas which may be non-conforming or simply highlight opportunities for improvement.
For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.
[18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step.
This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards.
Other options include:
· Assisting with your TISAX self-assessment (aka a Gap Analysis)
· Conducting a Maturity Assessment
· Conducting internal audits
· On-site support during your TISAX assessment audit
We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you.
[21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment.
Attendees will also get access to some freebies. So don't delay, register your place here today.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The modern automotive industry faces many new challenges, as vehicles evolve with more complex data requirements and supply chains become increasingly interconnected, major Original Equipment Manufacturers (OEMs) require certain Standards as a mark of trust from potential suppliers.
Currently, this trust is codified in TISAX (Trusted Information Security Assessment Exchange). For businesses that have not previously dealt with Standards, TISAX can be seen as a daunting regulatory hurdle. However, a TISAX label is more than a compliance check, it's a recognised mark that your organisation has robust information security measures in place specific to the automotive industry, including considerations for protecting key intellectual property and prototype innovations.
In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore what TISAX is, who it applies to, what it requires and how OEM's and automotive suppliers can take their first steps towards earning a TISAX label.
You'll learn
· What is TISAX?
· Who is TISAX applicable to?
· Why is TISAX important?
· What are the 3 assessment levels within TISAX?
· What are the 3 different subject areas within TISAX?
· How is TISAX implemented?
· Why does TISAX use labels instead of certificates – and how can people verify these?
· What is the ENX portal and how does this help with supplier onboarding?
· Where should companies start if they want to earn a TISAX label?
Resources
· Register for our TISAX webinar here
· ENX
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Emma Coxhill joins Ian to dive into the topic of TISAX, including who it's applicable to, why it's important and how businesses can make a start on earning a TISAX label.
[03:40] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association.
It's based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers.
[04:40] Who is TISAX applicable to? While applicable to the automotive industry, it encompasses quite a lot of businesses within this. This is because is applies to any organisation that handles sensitive data relating to vehicle development, manufacture and marketing.
So, this can include any company providing car parts, vehicle software, cloud services, testing labs, engineering etc. Basically, any service providers to OEMs (original equipment manufacturers) will be applicable.
TISAX can also be applicable for those dealing with automotive related events, marketing and photography, as new models are protected IP and will require related business to prove that they have the correct security requirements to ensure any potential prototypes are protected.
[06:50] Why is TISAX important? Mainly, it gives the automotive industry a trusted, standardised way to ensure information security across the entire supply chain.
Without it, the OEMs and suppliers can conduct their own audits, but it'll be their own interpretations or what is considered an adequate level of security. The industry saw this as an open door to chaos, so TISAX was created to protect highly confidential automotive information and support compliance with relevant data protection laws.
However, now it's not so much a 'nice to have' Standard as it is a requirement to trade, especially within Europe. It's fast becoming a tender requirement, and many OEMs won't make it past the procurement process without a valid TISAX label.
The ENX portal, where labels are registered, can also help speed up the on-boarding process. So, the whole TISAX system has been built for ease of access to help manufacturers choose suppliers that prioritise information security.
[09:00] What's the consequence of not having a TISAX label? A loss of opportunities. Those within the automotive industry that don't have a valid label will be seen as a security risk, leaving them at a competitive disadvantage.
[10:30] What are the 3 levels within TISAX? Unlike ISO 27001, TISAX has levels that depend on the level of data sensitivity that you're dealing with.
Level 1: Self-assessment – Considered as 'normal risk' with general processing of data.
Level 2: Remote Audit – Applicable to those dealing with confidential information such as design documents or internal projects. This requires both a self-assessment and an audit.
Level 3: On-site Assessment – Highly confidential information, so this applies to those dealing with sensitive research, development information or prototype data etc. This requires a physical on-site assessment, as the qualified TISAX auditor will need to ensure that you have the appropriate physical security measures in place.
Most businesses will require level 2, but if you're looking to work with high-spec OEMs, then level 3 is more desirable.
[12:00] What are the 3 subject areas within TISAX? The 3 main areas are as follows:
Information Security: This covers general information security controls such as relevant policies, access controls, risk management, incident handling and secure operations.
Prototype Protection: This focuses on safeguarding physical and digital prototypes, design data, test vehicles and confidential development information.
Data Protection: This ensures proper handling of personal data in line with legal requirements such as GDPR.
If you're just doing a self-assessment, you can pick the areas which are most relevant to you. If you've been requested to earn a TISAX label, they will usually provide you with their preference on subject areas.
Many will opt to take information security, but data protection is also quite common. The prototype section is more specialist and not applicable to all businesses.
[14:00] How is TISAX implemented? There are a few stages to gaining a TISAX label:
Awareness – Learn the requirements for TISAX and planning for the project ahead. This may include asking your clients about what they expect of your from an information security perspective and working out costs for assessments and any additional support. The ENX website has a lot of really useful info, including a handbook and a copy of the self-assessment.
Preparation – This is where you need to complete your TISAX scope and register yourself on the ENX portal. Your scope needs to specify your selected level (1,2 or 3) and the subject areas you'll be focusing on. You also need to include the locations within scope, which have to be listed one by one (not simply 'all offices in the UK' for example).
Self-Assessment – The template for this can be downloaded from the ENX website. This is essentially a Gap Analysis that grades your current level of compliance with the TISAX requirements. It includes a scoring mechanism, where you'll be aiming to get a 2.71, as that's the pass rate. This self-assessment will highlight what gaps you need to fill before going ahead with an external assessment.
Implementation – This is where you will bridge those gaps highlighted in the Self-assessment. This will involve creating the required documentation requested by TISAX and updating existing systems to align with requirements. Before going ahead with external assessments, we highly recommend you conduct some internal audits to ensure you're ready.
External Assessment – Whether this is remote or on-site, you need an official TISAX auditor to perform the assessment. A list of approved TISAX auditors is available on the ENX portal, we recommend getting a few quotes to get the best price. We also recommend requesting a kick-off meeting so you can have a chat with your auditor about the requirements and how they'd like to review the required evidence of compliance.
The Assessments are similar to that of an ISO certification, it's broken down into 2 segments. One is a document/evidence review and the other is done with both parties present to go through their findings, review further evidence and to question any gaps found.
Again, similar to ISO, you may receive either minor non-conformities, non-conformities, opportunities for improvement or observations in their final report. If you get any non-conformities, you'll need to provide an action plan within 2 weeks following from your assessment to address them. You will then be allowed a few months to implement the corrections, which will be reviewed and approved by the auditor before receiving your label. If you only received opportunities for improvement then you'll get a label straight away.
[20:40] Why does TISAX use labels instead of certificates – and how can people verify these? Taking ISO 27001 as a comparison, that certification has a blanket framework that can apply to every business. While you can exclude small bits, the vast majority applies to everyone.
TISAX is more scaled based on the level of security you're dealing with. Businesses can pick both different levels and different subject areas for their Label.
Another key difference is that Labels can only be verified through the ENX portal, this is where other TISAX clients can see who has what Label, including the details of level and selected subject areas.
Business can still chose to state TISAX compliance on their website, but the details regarding the level of compliance only need to be seen be relevant individuals.
[22:05] What is the ENX portal and how does this help with supplier onboarding? The ENX portal is accessible through the ENX website. It does require a fee to make an account, but this is where everything related to TISAX is managed.
This is where you will upload your scope and findings and it's where Labels are assigned and documented for suppliers to search for. There are options for how much information you want to disclose within those public searches, allowing you to select the need for contacting for further information.
The ENX portal can help massively in reducing the amount of supplier questionnaires you need to fill in, as those looking for automotive suppliers will simply look up your TISAX Label to verify if you have the required level of security to continue with the procurement process.
[24:50] Where should companies start if they want to earn a TISAX label? If you're just diving in, we recommend you do some research first to fully understand what you're expected to do to earn a Label and how much the process will cost.
Next you'll need to define your scope, so look at what sites need to be included and identify relevant client requirements in relation to TISAX. This is to ensure you're going for the right Level and subject areas.
Next evaluate your internal resource for the project and related budget. As mentioned, you will need to pay to register on the ENX portal and you need to consider Assessment costs and any additional support costs should you need consultancy services.
You'll also need to assign individuals to manage the project, which will include completing the self-assessment, updating your policies, procedures and documentation to align with the requirements and possibly conduct training if required.
This isn't a 2 week project, realistic timescales will vary, but generally if you're starting from scratch you're looking at 9-12 months. If you have ISO 27001 in place already this could be reduced to 6-8 months.
As with anything Standard related, leadership commitment is a big factor as you'll need their help and support to ensure the projects success. If you need additional help, reach out to consultants such as Blackmores to help guide you through the process.
[28:05] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we'll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment.
Attendees will also get access to some freebies. So don't delay, register your place here today.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the full video interview here
Annual sustainability and ESG reporting is now becoming a necessity for many businesses, whether driven by region specific regulations and legislation, industry expectations or client demand.
However, doing so is definitely easier said than done. It requires a complex network of data being gathered from multiple sources which then needs to be collated, analysed and summarised in a cohesive report for leadership and possible public publication.
Thankfully, there have been developments in new AI driven technology that can help ease this annual burden, allowing you to focus on utilising the results to make meaningful sustainability impacts.
In this episode Mel Blackmore is joined by Darayush Mistry, Head of Product at Pulsora, to discuss how AI can make a difference in ESG and sustainability reporting, including its benefits, pitfalls and the balance of utilising AI while considering its environmental impact.
You'll learn
· Who is Darayush?
· Who are Pulsora?
· When did Darayush realise how AI could be utilised for ESG and sustainability reporting?
· What are the positives of AI in this space?
· Why is AI for ESG and sustainability reporting becoming more necessary?
· What are the risks involved in using AI for ESG and sustainability reporting?
· Where is AI making a real difference in reporting?
· What parts of ESG and sustainability reporting need human judgement?
· How does AI help collate data from multiple sources?
· How might regulators react to AI being utilised in reporting?
· How can businesses utilise AI while still considering it's environmental impact?
· Darayush's advise to sustainability leaders looking to explore AI solutions
Resources
· Pulsora
· Darayush Mistry
· Carbonology
In this episode, we talk about:
[00:25] Episode Summary – Mel is joined by Darayush Mistry, Head of Product at Pulsora to discuss the use of AI tools in ESG and Sustainability reporting, how you can leverage this technology and what risks you need to be aware of before doing so.
[02:40] Who is Darayush Mistry? Darayush has been working with enterpirise software for the past 2 decades. This technology is used by companies to help operationalise their business.
He began his career at a company called Siebel Systems, which operated in the CRM space, spending 10 years there before moving onto the world of sustainability.
Darayush recalls how everyone was so used to working from a set of spreadsheets just 20 years ago, whereas now most will use a central CRM for business operations.
This is an area that sustainbilty reporting seems to have lagged behind, with many still trying to collate their data from multiple spreadsheets and other external sources rather than having a dedicated central system. This is why he was eager to work with Pulsora, to bring similar solutions to businesses as he once had with CRM's in the past.
[05:25] Who are Pulsora? Pulsora are an AI-forward SaaS (software as a service) platform.
The Pulsora platform helps businesses to operationalise their sustainability initiatives, which includes data collation, calculation and reporting features. This is set up for scope 1, 2 and 3 level reporting, with considerations for climate related goals, waste water monitoring, biodiversity and policy oriented information.
Darayush's role as Head of Product means he sits at the intersection between customers and Pulsora's engineering and design teams. His job is to ensure that whatever Pulsora created ultimately provides value to their customers in the form of successful sustainability outputs.
[07:50] When did Darayush realise how AI could be utilised for ESG and sustainability reporting? Darayush can pinpoint a time four years prior when he first stepped into a more sustainability focused role, speaking to the co-founders of Pulsora back in 2021 they were sharing experiences of using the then early versions of AI tools such as ChatGPT and Gemini.
It clicked for them then that they could do something similar for sustainability reporting, making it as easy as possible while still being accurate. It wasn't until 2 years later that they had a product to launch with Pulsora AI in late 2024.
This initial product allowed users to write long from narrative responses for carbon disclosures. Regulations like CSRD require a comprehensive disclosure, but not everyone is an expert in parsing the data to write that, so Pulsora AI helped get past that writers block, to give people the building blocks for that professional disclosure.
[11:55] What are the positives and negatives of AI in this space? The biggest benefits include:
· Giving professionals and sustainability teams more time back to achieve their desired outcomes.
· Cutting down on spending time in spreadsheets and on calculations on an annual basis.
· Reduction of repetitive tasks
· Ease of data collection from multiple sources and locations
· Ease of data calculation
· Allowing for pre-audit of data using AI tools
· Highlighting data gaps when rationalizing the data
[17:20] Why is AI for ESG and sustainability reporting becoming more necessary? People are starting to move on from the mindset of 'Let's try AI' to 'Let's use AI'.
Time is one of the most precious resources we have, and any tool that can help accelerate more mundane tasks so that people can focus on making results happen should be a priority.
Sustainability teams are under increasing pressure to produce tangible results, something that can be made easier with the help of AI tools.
[20:06] What are the risks of using AI in ESG and Sustainability reporting? Don't treat AI as this magic wand, it's a tool you can leverage. At the moment, it's good at certain tasks, but it cannot act on its own.
In order to progress, sustainability teams need to push on the initiatives to produce results. People know their business best, and though AI can infer certain information and produce a result, it may not always be the best solution for you. You still need that human input into areas such as strategy and action planning.
Darayush reminds us of Amara's Law: "We as humans severely overestimate technology outcomes in the short-term, and severely underestimate that in the long-term"
Don't fall into the trap of thinking AI can do everything.
[22:30] Where is AI making a real difference in reporting? Data collection, ad-hoc sustainability reporting and providing insights into the data provided. It can also help with providing a starting point for carbon disclosures or options for various strategies that you could explore.
Currently, the biggest one is data collection, as it can help do this efficiently and consistently, allowing for improved accuracy in your overall sustainability data.
[25:20] What parts of ESG and sustainability reporting need human judgement? Darayush states that these are complementary to each other, it should never be all of one and none of the other.
There will be elements that need more human in the loop and areas where it's required less. It's applicable in degrees.
One example of where the human input will be higher is in completing a materiality assessment and figuring out how to execute your decarbonisation strategy, which will require your knowledge and experience of how the business operates, it's core values and what your ultimate goals are.
AI can do the heavy lifting in areas such as sustainability reporting, as it can collate all the data and create initial reports very fast. But, at the end of the day, humans still need to understand these outputs and provide their own judgement.
'AI' today isn't true AI, they're LLM's with a great capacity to collect data, analyse it and provide outputs that can be starting points. It cannot replace human judgement, as we provide the nuance in context and experience needed to apply those results effectively.
AI responses operate in a perfect world where everything is an easy step by step process, which we all know does not reflect reality.
[29:40] How does AI help collate data from multiple sources? Older technologies like OCR (optical Character Recognition) was the go to years ago when scanning various different documents like spreadsheets, PDF's, receipts etc. This required specific code to be written to read these docs accurately, this would then feed into pipelines to bring this data together. This code was quite rigid, so any changes to document layouts would cause things to break.
AI in comparison is much more adaptable, it's capable of reading much more natural language and extracting what's required for its designated task. It also provides a much more friendly UI (user interface), meaning you don't need an IT specialist to utilise the technology.
[33:15] How might regulators react to AI being utilised in reporting? Based on Darayush's previous experience in the finance sector when people were using dedicated platforms for financial reporting, the regulators didn't care where the data came from or how it was collated, they just card if it was accurate.
Regulators want transparency, accuracy and a big part of this is providing an audit trail so they can see where the data came from. They simply want businesses to follow their guidelines, the how you get from A to B is of little importance so long as the result is accurate.
If anything, the existence of these tools will raise the bar of expectations from regulators, as businesses should be able to provide the required information with these tools readily available.
[36:30] How can businesses utilise AI while still considering it's environmental impact? – AI can certainly aid the sustainability industry in certain areas, such as reporting, but it's a resource intensive tool.
It consumes a lot of energy and water. Like with most emerging technology, the sustainability impact usually isn't addressed until much later. Much like with mobile phones, which create tonnes of E-waste every year, not to mention the mined material required to make them. It's factors like this which eventually get regulators involved to help reduce the overall harm caused.
AI is yet to go through this evolution, but both regulator and consumer pressure is building to reduce the impact of AI. This will inevitably lead to innovation as companies seek to find more sustainable ways to cool data centres and reduce the resource burden.
On the flip side, AI can help save energy in other ways, such as time taken to complete the tasks for a human, which will include travelling to an office and amount of time they use a device for the task. This also has its own carbon footprint, which can comparatively be reduced by using AI to complete the tasks in minutes as opposed to hours or days.
The bottom line as of the start of 2026 is, we know there is a resource issue when it comes to AI, and companies are looking at better ways to address it as the technology develops.
[42:20] Darayush's advise to sustainability leaders looking to explore AI solutions – Identify a problem space where you can apply AI in a measured way an start using it. The only way you can find out how it impacts you is to use the technology.
Currently, AI shines is areas such as collating data from multiple sources and locations, so if that's an issue you're tackling where sustainability reporting is concerned, that's a good place to start with utilising AI.
If you'd like to learn more about Pulsora, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
A Standard like ISO 14001 may seem more appropriate for large enterprises looking to address their environmental footprint, however it can apply to any business no matter the size.
All businesses produce waste, and we can all do more to save energy, resources and money in the process. For some SME's, tackling resource wastage through effective environmental management can make a huge difference. Such is the case for today's guest, Surface Print, a family owned wallpaper manufacturer managed by its 4th generation.
In this episode, Ian Battersby is joined by James Watson, Managing Director of Surface Print, to discuss why they implemented ISO 14001, the related resource challenges for SME's seeking ISO Standards and benefits gained from certification.
You'll learn
· Who is James?
· Who is Surface Print?
· Are there any other Standards Surface Print have to adhere to as a wallpaper manufacturer?
· Did those other Standards help with understanding the process for ISO implementation?
· What was the driver behind ISO 14001 implementation?
· How long did it take them to achieve ISO 14001?
· Have they considered any other ISO Standards?
· What were the challenges for an SME seeking ISO certification?
· What were the benefits of implementing ISO 14001?
· How have Surface Print leveraged ISO 14001 in marketing and communications?
· James' top tip
Resources
· Surface Print
· James Watson
· Isologyhub
· What is the Isologyhub?
In this episode, we talk about:
[02:05] Episode Summary – Managing Director of Surface Print joins Ian to discuss their journey towards ISO 14001 certification, the challenges involved with ISO implementation for SME's and the benefits felt after certification.
[03:25] Who is James Watson? James Watson is the Managing Director of Surface Print, a wallpaper factory that is a family-owned business based in Lancashire. Both he and he sister are the current directors, he 88 year old father is still involved within the business.
They are the 4th generation in their family to be involved with wallpaper, starting with their great-grandfather, Walter Watson, who started the business all the way back in the 1880s!
[04:35] Who are Surface Print? Surface Print operate in both analogue and digital printing, with 10 large analogue printing presses and 6 state-of-the-art HP digital presses.
They have two elements to the company, with Surface Print handling 3rd party printing and white labelling for interior design brands.
The second is 1838 Wall Coverings, which is the original design branch that sells their designs worldwide.
Surface Print are not a volume printer, they focused on high-quality manufacturing with a key focus on attention to detail. All the manufacturing occurs at the UK factory.
Their typical clientele include the likes of John Lewis, Harrods and other high-end interior stores.
Their 1838 Wall Coverings branch recently had a collaboration for the past 3 years with the Victoria and Abbot Museum in London, where they were allowed access to their archive for inspiration on designs.
[07:35] Are there any other Standards Surface Print have to adhere to as a wallpaper manufacturer? Mainly it's the Construction Products Regulation EN 15102, which is specifically for construction products used in buildings.
They also needed to get FSC certified as they were dealing with paper and wood pulp.
[08:20] Did those other Standards help with understanding the process for ISO implementation? James quite honestly admits that no, none of the previous mandatory regulations helped with understanding the ISO process.
As they understood that it was going to be quite the task, they outsourced help from Blackmores to assist with implementation. Alison Henshaw from our Team worked alongside Surface Print's ISO committee to break down the Standard and offer valuable consultancy on aspects such as legislation.
[09:05] What was the driver for ISO 14001 Implementation? Wallpaper manufacturing is very heavy waste. Analogue machines can have up to 10% - 20% waste per production order. With that much waste, it can quickly make the entire process very inefficient.
There was also the spend on energy and gas to consider as all of those prices are increasing year-on-year. ISO 14001 could solve both of these issues while saving them a significant amount of money.
[10:15] How long did it take Surface Print to achieve ISO 14001? In total, around 12 months. It would have been quicker, but there were some administration issues with the Certification Body that delayed the final Assessment.
[11:55] Have Surface Print considered any other ISO Standards? As they're only just into their first year of ISO 14001 certification, they've opted to stay focused on maturing that system before opting to go for any other Standards.
[08:20] What were the challenges for an SME seeking ISO certification? Surface Print initially struggled with the administration side of ISO 14001, things like keeping on top of document and process updates, updating the legal register etc. This is where Blackmores Consultant Alison came in to bridge the gap and ensure they kept all the necessary paperwork up-to-date.
They also needed more technical expertise in the area of environmental management. Their ISO committee weren't ISO experts and so there was a gap of knowledge between understanding the ISO Standard and how to apply it to the business, which is where Alison helped once again to guide them on their journey.
[13:35] What were the benefits of implementing ISO 14001? Their ISO 14001 certification affects every decision made. It's not just about environmental management, it's about managing your business as a whole.
The Standards actively require leadership commitment, so it starts from the top down. It's led to a more cohesive structure to making business decisions and thinking from a more environmental perspective.
There have also been cost savings. Manufacturing in the UK is generally very expensive, so the more environmentally focused you can be results in savings on energy and resources.
For example, Surface Print use a lot of electricity for both the machines and drying process involved in wallpaper manufacturing. They now measure their monthly energy usage against the rolls of wallpaper produced. They also installed solar panels which saved them a significant amount of electricity usage over the last year. They're also investing in newer equipment to help with efficiency, making plans on how to reduce gas usage.
It's also helped with their general business administration as documentation needs to be kept up-to-date. The whole process is now a lot more thorough, and has greatly improved their general monitoring and measurement processes.
They also have confidence in their regulatory and legal compliance, as ISO Standards have this as a basic requirement. Many opt to use a Legal Register to help keep all this information in one location.
Surface Print also found that they can answer client questions quicker due to the amount of documented information at their fingertips, this now includes more environmental based questions, which are cropping up more often.
[18:35] How have Surface Print leveraged ISO 14001 in marketing and communications? Surface Print often get asked by potential brand clients 'What's the benefit of working with you?', to which they can answer with a sustainability statement which lists all of the benefits. The first point of which is ISO 14001 certification, which is a globally recognised mark of effective environmental management.
They ensure that their environmentally conscious stance is first and foremost in marketing and external communications. This is not done out of a forced obligation, Surface Print have chosen to do the right thing, which is becoming the norm. To not think about the environment, especially in high-waste industries, is generally frowned upon.
[20:25] James' top tip for those thinking about implementing an ISO Standard – ISO implementation can cost a fair amount up-front, but the cost saving benefits within a year can supersede that investment.
You will see a lot of big improvements at the start, once your system matures you can expect to see those improvements slow in rate while still driving continual improvement at a steady pace.
With the addition of effective monitoring and measurement, those improvements are quantifiable, so you can really see the results of your investment.
[23:25] James' book recommendation – Guinness Book of World Records
[23:55] James' favourite quote – "You can take a horse to water, but you can't make it drink"
If you'd like to learn more about Surface Print, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
An ISO Management System can't survive without Leadership engagement. It was seen as such an essential aspect that 'Leadership commitment' became a key requirement of many ISO Standards back in 2015 when the Annex SL format was adopted.
It's easy to see why. An effective Management System will provide vital information for top management to make decisions on processes, policies and strategic direction.
So, how do you get leadership involved with your ISO management system?
In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss why leadership involvement is so crucial to effective ISO management, and explains how you can get their buy in whether you've got a mature system or are newly implementing ISO Standards.
You'll learn
· What is the isologyhub?
· What issue is the Leadership Powerup tackling?
· Who is the Leadership Powerup aimed at?
· What are the six steps in the Leadership Powerup Gameplan?
Resources
· Isologyhub
· What is the Isologyhub?
· The Integral Role of Leadership within ISO
· Aligning Objectives with Strategic Direction
In this episode, we talk about:
[02:05] Episode Summary – Blackmores Service Improvement Manager joins Steph on this episode to talk about the crucial role leadership plays in ISO management, and how you can get the most out of their involvement.
[00:45] What is the isologyhub? The isologyhub is our online learning platform for all things ISO. Its main feature is the ISO Roadmap, a 7-step guided approach to implementing your own bespoke ISO 14001 compliant Environmental Management System.
Since it's creation, it's grown to hold a library of over 200+ ISO related resources. The content available varies from quick accessible content such as ISO templates, ISO handbooks and short from video training we call Coffee Break Training which explain key elements of ISO Standards. This goes onto more in-depth content such as our ISO Pathways which take you through 3 levels of learning to help you progress from Learner to leader in your chosen subject area.
There's other exclusive content on there which you can dip into, including ISO templates, training videos and previous workshops covering topics such as ESG and AI management.
We also have a number of Gameplans, which are essentially guides where people can work through a particular set of information about a topic and get practical guidance that can be applied within their own organisation.
[02:05] What issue is the Leadership Powerup tackling? In the past, it was quite easy for leadership to lose interest in the Management System once it had been implemented. This was in part due to how Standards used to be written, and would result in the system being delegated to specific individuals.
In 2015 this, along with a number of other issues, were addressed and a new clause structure was introduced. This means that Leadership Commitment now isn't optional, as it's a direct requirement of all ISO Standards (Clause 5 typically).
The Leadership Powerup Gameplan aims to help leadership understand their role in making the Management System effective for the wider business. It helps to assess their current level of commitment and guides you through a path of improvement to get them to be a positive ambassador for the Management System.
Where leadership is concerned, it's important to remember that you're leading by example. If you don't care about the Management System, why should anyone else?
For those that want more of a deep dive on Leadership's role within ISO, check out a previous podcast.
[06:05] Who is the Leadership Powerup aimed at?: As a minimum it should be the individual or team that have day-to-day responsibilities relating to the management system.
Ideally you would also want a member of leadership, as you'll need their input to gauge the current level of commitment.
[06:50] What are the six steps in The Leadership Powerup?:
Step 1: Evaluate Leadership – For this step it's important that you're 100% honest in your reflection of how leadership are currently promoting and engaging with the management system. It includes a workbook to help you self-score, though we recommend getting a team involved who can help shape a full perspective their engagement in reality.
The included workbook also contains examples of key causes for a lack of leadership engagement. It walks you through the reasons for these causes, as it's only through understanding why something is happening is when you can seek to resolve the issues.
Step 2: Boosting Knowledge - This section works through what good looks like in terms of effective leadership commitment. You need to be able to understand the ideal end point before you can plan on how to get there.
Included in this section are key definitions and videos that break down what good looks like for leadership commitment.
Step 3: Planning Your Process – During this step you will plan on how to reach your end goal. By this point you will have assessed your current level of leadership commitment and you will have a good idea of what good looks like.
Included in this step is another workbook that will guide your planning process to answer the following questions:
· What do you want to achieve by the end of the Gameplan?
· What does good leadership engagement look like for us specifically in this business?
There's also a helpful section on understanding how processes interact, which is a fundamental part of ISO management. It's about how your business operates as one big system and not as siloed departments and processes. Having leadership understand that big picture so that they can communicate that impacts to certain teams does affect the whole business.
Step 4: Deliver Data – This section is all about information. Leaders love data as it helps them to make informed business decisions. This step guides you through what sort of data you should be gathering and how it can be presented to leadership.
This is crucial as it links back to one of the fundamentals of quality management, that being data-driven decision making. This could be in the form of customer feedback or employee feedback, or in other metrics such as health & safety incident etc. It's all about making the most of this data.
Step 5: Strengthening Strategy – It's very important that your ISO management system aligns with your businesses' strategic direction. This is a key way that you can get leadership involved in the management system, as the business direction will already be a key focus for them. Ensuring the management system not only aligns but helps to facilitate that will ensure that it stays at the forefront of their minds.
This step provides you with guidance on how to go about aligning leadership priorities and management system priorities.
Step 6: Consolidating Compliance – This step is about ensuring that you are doing what you say you're doing. The key part of leadership involvement includes leading by example, such as reviewing policies and updating them if they are no longer working for the business. It's about continuous review and implementation of key feedback and communication of changes happening within the management system from top management down.
This Gameplan can be useful for businesses where the Management System has been in place for a while and may not require their direct attention once certification has been achieved. In order to drive effective continual improvement, it's key that they still keep that management system at the core of their activities.
It can also be helpful when there is a change in leadership, and new individuals may not know what their level of involvement should be.
If you'd like to become a member of the isologyhub, we have an exclusive 20% discount available for listeners, simply Contact Us and quote: Isologyhub20 to claim that discount.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Internal Audits are a key part of any ISO Implementation journey, they are also a necessary vehicle to drive continual improvement.
For those with more mature ISO Management Systems, it can be easy for Internal Audits to become a bit of a rinse and repeat exercise. This can lead to stagnation of meaningful results, especially if you're asking the same people the same questions year on year.
So how can you revitalise the Audit process?
In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss the challenges associated with repeated internal audits, and how you can refresh the process to ensure you get meaningful results to drive continual improvement.
You'll learn
· What is an Isologyhub Gameplan?
· What issue is the Audit Accelerator tackling?
· Who is the Audit Accelerator aimed at?
· What are the five steps in the Audit Accelerator Gameplan?
Resources
· Isologyhub
· What is the Isologyhub?
In this episode, we talk about:
[02:05] Episode Summary – Blackmores Service Improvement Manager joins Steph on this episode to talk about the challenges many face when completing internal audits in an annual basis, and how these can be refreshed to ensure valuable output.
[00:45] What is the isologyhub? The isologyhub is our online learning platform for all things ISO. Its main feature is the ISO Roadmap, a 7-step guided apprach to implementing your own bespoke ISO 14001 compliant Environmental Management System.
Since it's creation, it's grown to hold a library of over 200+ ISO related resources. The content available varies from quick accessible content such as ISO templates, ISO handbooks and short from video training we call Coffee Break Training which explain key elements of ISO Standards. This goes onto more in-depth content such as our ISO Pathways which take you through 3 levels of learning to help you progress from Learner to leader in your chosen subject area.
There's other exclusive content on there which you can dip into, including our full workshop recordings which have covered topics such as utilising ISO Standards for ESG compliance, how to integrate ISO Standards and how to complete an AI impact Assessment.
[02:10] What is an isologyhub Gameplan? Gameplans have been designed to be actionable pieces of content within the Isologyhub.
They are guides where people can work through a particular set of information about a topic and practical guidance that can be applied within the own organisation.
Each game plan is structured around a kind of area that is quite commonly a difficult area for many organisations managing ISO Standards.
Each Gameplan also includes a number of Workbooks to help you through each step, whether as an individual or as part of a team.
[04:00] What issue is the Audit Accelerator tackling? internal audits are a fundamental part of any ISO management system, but it's also something that can get a little bit stale when you've had a management system for a while.
It can tend to feel a little bit like a rinse and repeat exercise where you're having similar conversations with the same people about the same processes, which isn't what internal audits should be.
The reason they're in the standards in the first place, is to help push continual improvement. For example, if you've got a quality management system, you'll be looking to ensure that processes are being followed, but also where there are opportunities to improve. This is where a lot of people drop the ball in mature systems.
Internal Audits can be intimidating for some, and can be rushed as just something that needs to get done. But by rushing them, by not talking the proper time to speak to different individuals, you are missing out on valuable information that can ultimately help you improve your services and way of working.
The Audit Accelerator Gameplan was designed to help you to really get the most out of those internal audits, give the process a bit of a refresh and rethink how you're approaching your audit planning. It also provides guidance on how you can get better engagement from the wider business with audits.
Refreshing the process will help you to gain new perspectives, and ensure that internal audits becomes a positive experience that everyone can engage with, no matter what level they are at within the business.
[08:15] Who is the Audit Accelerator aimed at?: The person who's responsible, or personal team who is responsible for coordinating the internal audit plans within an organisation.
It's aimed at those so that they can help the wider business to understand what audits are about, and also so that they can also look at how they're planning audits.
[09:15] What are the five steps in The Audit Accelerator?:
Step 1: Check – This step helps you to assess where you currently are with your Audit Program. It includes a workbook with a checklist that you can work through, this will give you a score to indicate how well you're doing and where you can improve. It asks questions such as:
· How effective are the audits that you're doing in your business?
· Are there areas that you could perhaps make improvements?
Step 2: Challenging Assumptions - This step provides information about what the purpose of internal audits are, why people have misconceptions about them, what some of the common fears and concerns are about audits, so that you can start addressing them within your business.
This can include simply talking to your colleagues in a more positively framed way about Internal Audits. Another suggestion is changing the name 'Internal Audit', especially if it has negative connotations within the business. The Standard doesn't say they have to be called anything, as long as you're asking people about how things are done, ensuring processes are being followed and allowing people to suggest improvements, the way you go about doing to (including the name) can be done in whatever way works best for your business.
This step also includes the main workbook that you will work through for the rest of the steps.
Step 3: Change It Up – This sections includes a few different videos about different ways of planning audits and different ways of explaining audits to your colleagues so that they feel a little bit more comfortable about them and understand the benefits and real opportunities that come from participating in audits as well.
Step 4: Collaboration – This step stresses that it's really important that Internal Audits is not something driven solely by just one person. Everyone has a positive part to play in the process. This includes Management, as they need to hear audit feedback and make changes where required. This helps to show that audits drive meaningful change, and should encourage everyone to have their say.
So, this step is really about making sure that management, audit planners and auditees understand their role in the process.
Step 5: Check Again – This involved going back to that initial assessment of where you were when you started the Gameplan, and reassessing after you've implemented some of these improvements through the improvement workbook and seeing if you have moved the goalpost from that initial assessment.
Hopefully you'll have a much higher score to show how much you've progressed after following the Gameplan steps.
If you'd like to become a member of the isologyhub, we have an exclusive 20% discount available for listeners, simply Contact Us and quote: Isologyhub20 to claim that discount.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
It's been a busy year for ISO Standards, with that set to ramp up in 2026 thanks to upcoming Standard transitions.
Before we dive into a new year, we'd like to take a step back and highlight some of the key ISO milestones from 2025.
In this episode, Steph Churchman, Communications Manager at Blackmores, looks back at the major Standard updates from 2025, including changes to existing Standards, new ISO's published and key upcoming changes you need to be aware of for 2026.
You'll learn
· What ISO Standards have been updated in 2025?
· What new ISO Standards were published in 2025?
· What Standards are due to be published in 2026?
· What ISO transitions do you need to be aware of in 2026?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Steph reviews major ISO Standard updates from 2025, including changes to existing ISO Standards, new Standards published and what you need to know going into 2026.
[02:34] What ISO Standards have been updated in 2025?:
ISO 27701:2025: This is the Standard for Privacy Information Management and it recently received an update in October 2025. Key updates to this Standard include:
· This is now a stand-alone Standard and can be implemented without an existing ISO 27001 ISMS in place.
· The addition of further guidance for data processors and controllers.
· Provides greater clarity on managing personal data within AI and digital ecosystems
· More focus on organisational leadership involvement.
· The update now aligns ISO 27701 more closely with global regulations such as GDPR, CCPA and LGPD.
ISO 37001:2025, the Standard for Anti-bribery. This one was well overdue an update, with its last version being 2016! It's update arrived on 2nd Feb 2025, and included: -
· Text harmonisation with the other ISO 37000 family of Standards, such as ISO 37301 (compliance management systems), ISO 37000 (governance of organisations) and ISO 37008 (internal investigations of organisations) to ensure consistency and easier integration.
· The latest version now formally introduces the concept of anti-bribery culture and emphasises its importance for the effectiveness of the management system.
· A greater emphasis on the role of top management and their involvement in overseeing the management system.
· A new requirement has been added for awareness and training as fundamental asset for management system results.
· It also receives the added climate change amendment, which many ISO's already embedded back in 2024 – learn more about that here.
· And lastly, there's more comprehensive definitions of conflict-of-interest as well as procedures to raise awareness on reporting potential and actual conflicts.
ISO 50002, the standard for energy audits. This isn't a certifiable standard, but rather a guidance document to support the energy management standard ISO 50001.
The recent update has now split this Standard into 3 parts:
· ISO 50002 part 1: General requirements with guidance for use.
· ISO 50002 part 2: Guidance for conducting an energy audit in buildings.
· ISO 50002 part 3: Guidance for conducting an energy audit in processes
Most of the revisions focused on strengthening and adding further clarification to energy auditing principles such as Competency, Confidentiality, Objectivity, access to equipment, resources and information, Evidence-based approach and Risk-based approach
Lastly, this update also clearly specifies the requirements for energy auditor competence.
[07:10] What new ISO Standards were published in 2025? ISO 42006 - Requirements for bodies providing audit and certification of artificial intelligence management systems. This is a guidance Standard that actually relates to certification bodies rather than businesses choosing to implement ISO 42001.
It builds on ISO 17021-1 and ensures that certification bodies operate with the competence and rigour necessary to assess organisations developing, deploying or offering AI systems.
While one that you as a business may not have to worry about, it's a positive addition to the growing ISO 42000 family of Standards, which are currently the only global frameworks for best practice for AI Management.
ISO 17298 Biodiversity - Considering biodiversity in the strategy and operations of organizations. ISO 17298 ultimately aims to help organizations of all types and sizes understand how they depend on and impact nature – and take concrete action to address it. It includes guidance to help you:
· Understand your biodiversity impacts, dependencies and risks
· Identify opportunities for green growth and nature-positive finance
· And develop and implement a credible biodiversity action plan
[09:45] What new ISO Standards are due to be published in 2026? ISO 53001 management system requirements for the United Nations Sustainable Development Goals.
Many businesses have already done the hard work behind aligning their ESG activities with the UN SDG's, and will soon be able to benefit from certification to an internationally recognised Standard to help manage and improve their performance against those SDG goals.
The Standard provides a framework for an SDG management system that will:
· Enhance the organization's SDG performance.
· Fulfil compliance obligations.
· Achieve selected SDG objectives.
· Create trust and confidence to relevant existing and future stakeholders
If you wanted to get a head-start, the guidance document ISO 53002: Guidelines for contributing to the United Nations Sustainable Development Goals is available to download for free right now.
ISO 14060: Net Zero Aligned Organisations. This Standard details requirements for how any type of organization can demonstrate that their net zero strategy is achievable, and that they are making credible and verifiable progress towards contributing to global net zero in line with the Paris Agreement.
There are a lot of country specific legislation and regulations now in effect, or soon to be in effect, but there is a lack of clarity around what it actually means to be Net Zero. This is where ISO 14060 comes in, to create a globally accepted definition of what it means for an organisation to be net zero.
In addition, this Standard will also:
· Define what constitutes a credible net zero strategy at an organisational level
· Establish how targets should be set, measured and delivered
· Require organisations to align with the goals of the Paris Agreement
· Build on existing ISO standards such as ISO 14064 for GHG verification and ISO 14068-1 for Carbon Neutrality
· Have a focus on organisational claims, not product or event-level claims
· And lastly it will be globally applicable and adaptable across sectors.
[12:50] What ISO Standard updates do you need to be aware of for 2026?: The anticipated update to the leading environmental management system Standard, ISO 14001, is expected to be published in Q1 of 2026. It doesn't appear to have many major changes, but rather just further guidance and clarification in a few areas, including:
· Modernised terminology and harmonised structure that aligns with other ISO Standards
· Stronger focus on environmental conditions
· Clearer EMS scope with life-cycle perspective
· Again, we see a greater focus on leadership accountability
· Refined risk-based planning
· Introduction of a new change-management clause
· Extended operational control to suppliers
· Restructured management review
· And an expanded Annex A for explanatory notes
ISO 9001 is also due a revision. It was expected out around a similar time as ISO 14001, but following its public comment round, it's gone back under revision to make more changes after that feedback.
As a result, this has pushed the expected publication date to either Q3 or possibly even Q4 of 2026.
Now despite it going back into revision following feedback, the changes are still expected to be minor. Some of the expected changes include:
· Impact of digital transformation – such as AI
· Improved supply chain resilience
· Proactive risk management and risk-based thinking
· Quality culture and awareness of ethical behaviors
· And increased attention to customer satisfaction
Looking even further forward, ISO 45001 will also be up for revision soon, though that isn't expected to be published until 2027. We'll give you more details as soon as a draft version has been made available.
All of these transitions will include a 3-year grace period, so there's no need to panic. Over the next year, we'll cover these changes in more detail, and will provide a variety of ISO Support options to help you manage and complete your ISO transitions.
That's it from us for 2025! We look forward to brining you more ISO knowledge in 2026 😊
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
AI has become inescapable over the past years, with the technology being integrated into tools that most people use every day. This has raised some important questions about the associated risks and benefits related to AI.
Those developing software and services that include AI are also coming under increasing scrutiny, from both consumers and legislators, regarding the transparency of their tools. This ranges from how safe they are to use to where the training data for their systems originates from.
This is especially true of already heavily regulated industries, such as the financial sector. Today's guest saw the writing on the wall while developing their unique AI software, that helps the financial sector detect fraud, and got a jump start on becoming accredited to the world's first best practice Standard for AI, ISO 42001 AI Management.
In this episode, Mel Blackmore is joined by Rachel Churchman, The Global Head of GRC at Umony, to discuss their journey towards ISO 42001 certification, including the key drivers, lessons learned, and benefits gained from implementation.
You'll learn
· Who is Rachel?
· Who are Umony?
· Why did Umony want to implement ISO 42001?
· What were the key drivers behind gaining ISO 42001 certification?
· How long did it take to implement ISO 42001?
· What was the biggest gap identified during the Gap Analysis?
· What did Umony learn from implementing ISO 42001?
· What difference did bridging this gap make?
· What are the main benefits of ISO 42001?
· The importance of accredited certification
· Rachel's top tip for ISO 42001 Implementation
Resources
· Umony
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Mel is joined by Rachel Churchman, The Global Head of GRC at Umony, to explore their journey towards ISO 42001 certification.
[02:15] Who is Rachel?: Rachel Churchman is currently The Global Head of GRC (Governance, Risk and Compliance) at Umony, however keen listeners to the show may recognise her as she was once a part of the Blackmores team. She originally created the ISO 42001 toolkit for us while starting the Umony project under Blackmores but made the switch from consultant to client during the project.
[04:15] Who are Umony? Umony operate in the financial services industry. For context, in that industry every form of communication matters, and there are regulatory requirements for firms to capture, archive and supervise all business communications.
That covers quite a lot! From phone calls, to video calls, instant messaging etc, and failures to capture that info can lead to fines.
Umony are a compliance technology company operating within the financial services space, and provide a platform that can capture all that communications data and store that securely.
[05:55] Why did Umony embark on their ISO 42001 journey? Umony have recently developed an AI platform call CODA, which uses advanced AI to review all communications to detect financial risks such as market abuse, fraud or other misconduct.
This will flag those potential high-risk communications to a human to continue the process. The benefit of this is that rather than financial institutions only being able to monitor a very small set of communications due to it being a very labour intensive task, this AI system would allow for monitoring of 100% of communications with much more ease.
Ultimately, it's taking communications capture from reactive compliance to proactive oversight.
[08:15] Led by industry professionals: Umony have quite the impressive advisory board, made up of both regulatory compliance personnel as well as AI technology experts.
This includes the likes of Dr.Thomas Wolfe, Co-Founder of Hugging Face, former Chief Compliance Officer at JP Morgan and the CEO of the FCA.
[09:00] What were the key drivers behind obtaining ISO 42001 certification? Originally, Rachel had been working for Blackmores to assist Umony with their ISO 27001:2022 transition back in early 2024. At the time, they had just started to develop their AI platform CODA.
Rachel learned about what they were developing and mentioned that a new Standard was recently published to address AI specifically. After some discussion, Umony felt that ISO 42001 would be greatly beneficial as it took a proactive approach to effective AI management.
While they were still in the early stages of creating CODA they wanted to utilise best practice Standards to ensure that the responsible and ethical development of this new AI system.
When compared to ISO 27001, ISO 42001 provided more of a secure development lifecycle and was a better fit for CODA as it explores AI risks in particular. These risks include considerations for things like transparency of data, risk of bias and other ethical risks related to AI.
At the time, no one was asking for companies to be certified to ISO 42001, so it wasn't a case of industry pressure for Umony, they simply knew that this was the right thing to do.
Rachel was keen to sink her teeth into the project because the Standard was so new that Umony would be early adopters. It was so new, that certification bodies weren't even accredited to the Standard when they were implementing the Standard.
[12:20] How long did it take to get ISO 42001 certified? Rachel started working with Anna Pitt-Stanley, COO of Umony, around April 2024. However the actual project work didn't start until October 2024, Umony already had a fantastic head start with ISO 27001 in place, and so project completion wrapped up around July of 2025.
They had their pre-assessment with BSI in July, which Rachel considered a real value add for ISO 42001 as it gave them more information from the assessors point of view for what they were looking for in the Management System.
This then led onto Stage 1 in August 2025 and Stage 2 in early September 2025. That is an unusually short period of time between a Stage 1 & 2, but they were in remarkably good shape at the end of Stage 1 and could confidently tackle Stage 2 in quick succession.
The BSI technical audit finished at the end of September, so in total from start to finish the Implementation of ISO 42001 took just under 12 months.
[15:50] What was the biggest gap identified during the Gap Analysis? A lot of the AI specific requirements were completely new to this Standard, so processes and documentation relating to things like 'AI Impact Assessment' had to be put in place.
ISO 42001 includes an Annex A which details a lot of the AI related technical controls, these are unique to this Standard, so their current ISO 27001 certification didn't cover these elements.
These weren't unexpected gaps, the biggest surprise to Rachel was the concept of an AI life cycle. This concept and its related objectives underpin the whole management system and its aims. It covers the utilisation or development of AI all the way through to the retirement of an AI system.
It's not a standalone process and differs from ISO 27001's secure development life cycle, which is a contained subset of controls. ISO 42001's AI life cycle in comparison is integrated throughout the entire process and is a main driver for the management system.
[19:30] What difference did bridging this gap make? After Umony understood the AI life cycle approach and how it applied to everything, it made implementing the Standard a lot easier. It became the golden thread that ran through the entire management system.
They were building into an existing ISMS, and as a result it created a much more holistic management system.
It also helped with the internal auditing, as you can't take a process approach to auditing in ISO 42001 because controls can't be audited in isolation.
[21:30] What did Umony learn from Implementing ISO 42001? Rachel in particular learned a lot, not just with ISO 42001 but with AI itself.
AI is new to a lot of people, herself included, and it can be difficult to distinguish what is considered a risk or opportunity regarding AI.
In reality, it's very much a mix of the two. There's a lot of risk around data transparency, bias and data poisoning as well as new risks popping up all the time due to the developing technology. There's also a creeping issue of shadow IT, which is where employees may use hardware of software that hasn't been verified or validated by the company. For example, many people have their own Chat GPT accounts, but do you have oversight of what emplyees may be putting into that AI tool to help with their own tasks?
On a more positive note, there are so many opportunities that AI can provide. Whether that's productivity, helping people focus more on the strategic elements of their role or reduction of tedious tasks.
Umony is a great example of where an AI has been developed to serve a very specific purpose, preventing or highlighting potential fraud in a highly regulated industry. They're not the only one, with many others developing equally crucial AI systems to tackle some of our most labour-intensive tasks.
In terms of experience with Implementing ISO 42001, Rachel feels it cemented her opinion that an ISO Standard provides a best practice framework that is the right way to go about managing AI in an organisation. Whether you're developing it, using it or selling it, ISO 42001 puts in place the right guardrails to make sure that AI is used responsibly, ethically, and that people understand the risks and opportunities associated with AI.
[26:30] What benefits were gained from Implementing ISO 42001? The biggest benefit is having those AI related processes in place, regardless of if you go for certification.
Umony in particular were keen to ensure that their certification was accredited, as this is a recognised certification. With Umony being part of such a regulated industry, it made sense that this was a high priority. As a result, they went with BSI as their Certification Body, who were one of the first CB's in the UK to get IAF accredited, quickly followed by UKAS accreditation.
[27:55] The Importance of accredited certification: Sadly, a new Standard creates a lot of tempting offers from cowboy certification bodies that operate without a recognised accreditation.
They will offer a very quick and cheap route to certification, usually provided through a generic management system which isn't reflective of how you work. Their certificate will also not hold up to scrutiny as it's not accredited with any recognisable body. For the UK this is UKAS, who is the only body in the UK under the IAF that is able to certify companies to be able to provide a valid accredited certificate.
There's are easily available tools to help identify if a certificate is accredited or not, so it's best to go through the proper channels in the first place!
Other warning signs of cowboy companies to look out for include:
· Off the shelf Management system provided for a fee
· Offering of both consultancy and certification services – no accredited CB can provide both to a client, as this is a conflict of interest.
· A 5 – 10 year contract
It's vital that you use an accredited Certification Body, as they will leave no stone unturned when evaluating your Management System. They are there to help you, not judge you, and will ensure that you have the upmost confidence in your management system once you've passed assessment.
Umony were pleased to have only received 1 minor non-conformity through the entire assessment process. A frankly astounding result for such a new and complex Standard!
[32:15] Rachel's top tip: Firstly, get a copy of the Standard. Unlike a lot of other Standards where you have to buy another Standard to understand the first one, ISO 42001 provides all that additional guidance in its annexes.
Annex B in particular is a gold mine for knowledge in understanding how to implement the technical controls required for ISO 42001.
It also points towards other helpful supporting Standards as well, that cover aspects like AI risks and AI life cycle in more detail.
Rachel's second tip is: You need to scope out your Management System before you start diving into the creation of the documentation. This scoping process is much more in-depth for ISO 42001 than with other ISO Standards as it gets you to understand your role from an AI perspective. It helps determine whether you're an AI user, producer or provider, it also gets you to understand what the management system is going to cover.
This creates your baseline for the AI life cycle and AI risk profile. These you need to get right from the start, as they guide the entire management system.
If you've already got an ISO Standard in place, you cannot simply re-use the existing scope, as it will be different for ISO 42001. If you're struggling, CB's like BSI can help you with this.
[35:20] Rachel's Podcast recommendation: Diary of a CEO with Stephen Bartlett.
[32:15] Rachel's favourite quote: "What's the worst that can happen?" – An extract from a Dale Carnegie course, where the full quote is: "First ask yourself what is the worst that can happen? Then, you prepare to accept it and then proceed to improve on the worst."
If you'd like to learn more about Umony and their services, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
When embarking on your ISO journey, a crucial first step is evaluating your current level of compliance and identifying what gaps need to be filled to gain certification or fully align with a Standard. This is typically done by conducting a Gap Analysis.
This exercise sets the foundations for your ISO Implementation project, from setting key actions and objectives, to resourcing and establishing a project timeline.
In this episode, Ian Battersby dives into the purpose of a Gap Analysis, who should be involved in the exercise and what inputs and outputs you should expect to have from conducting a Gap Analysis.
You'll learn
· What is a Gap Analysis?
· What is the aim of a Gap Analysis?
· What is the process of conducting a Gap Analysis?
· Who should be involved in a Gap Analysis?
· What inputs should be included in a Gap Analysis?
· What outputs can you expect from a Gap Analysis?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian Battersby dives into the first step on any ISO Implementation journey, breaking down what a Gap Analysis is, it's purpose and what you should expect to get out of conducting one.
[02:50] What is a Gap Analysis?: Simply put, it's the start of the process.
It's a key to understanding where an organisation is right now and establishing what it needs to do on its journey to ISO certification.
But it's not just for certification, as certification isn't always what people are trying to achieve. Many businesses opt to align themselves to a standard to ensure they're doing the right thing, but may not go through with full certification.
[04:05] Who is the aim of a Gap Analysis? The objective of a Gap Analysis is to carry out a review of your organisation against the requirements of the respective standard.
This will help to establish the following:
· Areas where you conform to the standard, where you may have established the required processes, procedures, roles, responsibilities, systems, methods, documents
· Areas of nonconformity, where such things will need to be developed
· You may partly conform, so it's important to understand that as well
From that understanding, you can build key actions, timescales and responsibilities for implementing an ISO Standard.
It's also very useful to leadership; to clarify what's needed, to look at priorities, to resource what's required and to establish a timeline to your end goal.
[06:25] What is the process of conducting a Gap Analysis? It's important to do this in a very structured manner. It's also important to get access to existing documentation and personnel in key roles; they'll be helpful during the gap analysis in providing understanding.
You'll need to evaluate your current level of compliance against the following clauses within your desired ISO Standard(s):
4 Context: Understanding the world in which you operate, the people and organisations which are important to you. This is where you will determine the scope of your system (what to include, what parts of the standard are relevant).
5 Leadership: Top management's commitment, how involved they are, their accountability and their commitment to resourcing, promoting, to giving people authority through clear roles and responsibilities.
6 Planning: This is about assessing risks and opportunities; understanding the uncertainty caused by your operating environment (context). It also involves setting objectives and then establishing meaningful plans to address the risks/opportunities and objectives; mitigations; establishing controls; operational processes.
7 Support: This is where you look at people, competence Infrastructure and environment (are your facilities/equipment appropriate to what you need to do). You will also need to identify what you need to monitor and measure to demonstrate the effectiveness of your ISO Management System.
Next, you need to cover awareness and communication, i.e. how do you make people aware of your system, policy, processes; what do you tell other interested parties?
Lastly, ensure you address how you control the documentation which supports your system.
8 Operation: This address the delivery of a product or service to the customer, including all the processes for doing so. For example, in ISO 9001 this clause defines what's required when designing, developing, controlling externally provided products/services and controlling anything which goes wrong.
This is typically the clause that contains the largest difference between ISO Standard, with each one focusing requirements on it's topic focus. For example, ISO 14001 includes requirements for emergency preparedness and response in the event of an environmental incident.
9 Performance evaluation: This is where you review and report on the results of the monitoring and measurement that you've put in place. For those familiar with ISO, this is where the internal audit and management review requirements sit.
10 Improvement: This clause states requirements for addressing any non-conformities that pop-up during your Internal Audits. It also encourages you to address opportunities for improvement to help drive continual improvement and innovation.
[13:50] Who should be involved in a Gap Analysis? One key myth that we'd like to clear up is that not everyone in the business needs to be involved in this process, however, we do recommend the following are included:
The person responsible for the day-to-day running of the Management System. This may not be known at this early stage, which is fine as the purpose of the Gap Analysis is to identify gaps such as this.
Leadership; someone in a senior role; responsible for resourcing the system, communicating its importance to the workforce; responsible for setting the strategic direction and objectives.
People who understand the context of the organisation; understanding interested parties (stakeholders); needs of customers and others; the regulatory environment
Those involved in risk management; operational, financial, commercial, regulatory, safety or environmental.
Someone with knowledge of the legal requirements and how they're evaluated; relative to specific standard.
Anyone setting objectives related to the specific standard.
Those with knowledge of competence arrangements; not just those responsible for co-ordinating the Management System, but across the board, for delivering operational processes.
Those responsible for facilities and equipment; maintenance, service, test, inspection, etc.
People responsible for developing and delivering operational processes.
People with knowledge of how things are monitored or measured; possibly operations people, data analysis or those who report performance to management.
Those who control nonconformity and those who run improvement processes.
It can be quite a range of people!
However, in smaller organisations there may be quite a limited number who likely wear many hats. Again, that's not a problem, as the Gap Analysis exists to discover that.
[21:55] What inputs should be included in a Gap Analysis? This can include a number of things, as not everything will necessarily be a document. Typically, we as consultants will look at:
· Management System manual or System Scope
· Organisational chart
· Mission, vision, values and culture
· SWOT/PESTLE and Interested Parties
· Policy relevant to the standard
· Job descriptions
· Risk and opportunities analysis; methodology
· Objectives
· Legislation register and methods of evaluation
· Competence arrangements, training records
· Management System awareness, training completion
· Details of version and document control in place
· Monitoring and measuring plans (KPIs, SLAs, internal performance metrics)
· Internal audit programme and audit reports
· Management review records
· Agendas for any regular management meetings
· Nonconformities, incident report and corrective action records
· Customer complaints/feedback
· Emergency Plans
· Process Documentation
· Examples of process documentation:
· Change control documentation
· Sales, tendering, order processing
· Procedures for the design and development of products and services
· Design and development records stating inputs, verification and validation activities, outputs, and approval of changes
· Procedures to approve products and services for release to customers including quality checks
· Supplier / third party evaluation and onboarding documents
· Non-conformity/complaint information
· Traceability documentation
[29:40] What is the output from a Gap Analysis? We look at all of this and compare it against the requirements of the Standard to see where you currently stand. In our case, we do this on a spreadsheet with a simple scoring system to give you an overview of what you already have in place and what needs to be addressed.
In many cases, businesses already have a lot of the required documentation, but don't have it tied together in one cohesive system. So a large part of implementation is consolidating that existing documentation, process ect. Into an accessible and easily understood system.
The key thing to remember is that this is not an audit. The evidence required does not have to be as detailed as an audit; some things can be taken on trust or face value. At this stage we aren't demonstrating anything to a certification body, and you are not being judged.
We are simply looking at what needs to be done to achieve full Implementation or certification.
If you'd like assistance with carrying out a Gap Analysis, get in contact with us, we'd be happy to help.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the video interview here
One of the common pain points when calculating your carbon emissions is simply gathering the data. When collating data from different departments and suppliers, it can be easy to get overwhelmed.
The struggle doesn't stop there, as after obtaining all that data you have to find the best way to capture and display it in a way that's useable for the necessary number crunching. Many will turn to an old favourite, spreadsheets, but these can quickly become very unwieldy and impractical if you've got a lot of data to process. Thankfully, there's a lot of new tech and tools available to help make this task both approachable and integrated within your business.
In this episode, Mel Blackmore is joined by Jessica Matthys, Lead Product Manager at Pulsora, to discuss how you can take data complexity from spreadsheets to supply chains, diving into data fragmentation, optimisation and how this can all be balanced for practicality.
You'll learn
· Who is Jessica Matthys?
· Who are Pulsora?
· What does data complexity mean in the context of carbon accounting?
· What are the requirements for CSRD in California?
· What are the biggest pain points relating to data collection?
· How can you prevent data fragmentation across your business?
· What does 'Comprehensive data' mean in the context of sustainability?
· How can Pulsora help a business take their carbon data from spreadsheets to integrated data systems?
· How can you make you carbon data more auditable and traceable?
· How can new carbon focused technology, such as AI tools, help with seeking investment?
· How can you get information from your supply chain to cover scope 3 emissions?
Resources
· Pulsora
· CSRD – California Regulations
· SB-253 & SB-261
· Carbonology
In this episode, we talk about:
[00:25] Episode Summary – Mel Blackmore is joined by Jessica Matthys, Lead Product Manager at Pulsora, to explore how you can take data complexity from spreadsheets to supply chains, diving into data fragmentation, optimisation and how this can all be balanced for practicality.
[01:40] Who is Jessica Matthys: Is the Lead Product Manager for carbon solutions at Pulsora. She's been with Pulsora for a year and a half, but has worked within the ESG / carbon / sustainability space for over 8 years in total.
Something that people might not know about Jessica is that her passion for sustainability started much earlier than her working career, starting in high school where she opted to live on a farm for one semester. That unique experience of working closely with nature and animals set her on the path that she still walks today.
[02:30] Who are Pulsora? Pulsora is an end to end sustainability management AI powered platform. They can manage anything from data collection and carbon accounting all the way towards ESG reporting and audit support.
The focus of their platform is auditability and transparency .
[04:40] What does data complexity mean in the context of carbon accounting? Jessica breaks this down into three main elements:
Disparate nature of data – When compiling data for greenhouse gas accounting, you have to take a lot into consideration including your own production and consumption in addition to all the upstream and downstream relationships across your value chain. The data for all of this will be scattered and will need to be brought together in order to get a full comprehensive view of your emissions data.
Missing primary data – Some data may be very difficult to obtain, say from a supplier in a remote region, so in those cases you may need to make estimations to fill those gaps. However, you need to establish a proven and trusted methodology that can be repeated for such instances.
Auditability and transparency – Your data needs to be robust enough to hold up to scrutiny in an audit. New and upcoming regulatory requirements will have stricter rules around how you collect and report your emissions. We can see this in regulations such as SB 253 and 261 within CSRD that will affect businesses in California. There's a new focus on mandatory reporting as opposed to voluntary, so you will need to ensure your data is in a good place to be audited when this starts to effect other organisations globally.
[07:30] What are the requirements for CSRD in California? There are two main climate bills coming into effect in California in 2026, these are SB-253 and SB-261, which are supported by CARB (California Air Resources Board).
These two regulations affect businesses who are either doing business in, have employees located in, or selling products over a certain revenue threshold in California. Affected businesses will be required to report on their scope 1, 2 and 3 emissions.
There isn't anything new in these regulations that we haven't already seen in other European focused requirements, aside from the mandatory element.
The first deadline for this reporting is expected to be due by June 2026, and this first year they will only be expecting reports for your scope 1 and 2 data.
SB-261 has a slightly different focus, with it requiring climate risk reporting. This is similar to existing frameworks like ISSB or TCFD. This report can be published publicly and you just need to submit a link to that report to the appropriate bodies in California. The deadline for this one is fast approaching, with it being set at 1st January 2026.
[11:10] What are the biggest pain points relating to data collection?: Jessica shares an example of a company that came to Pulsora with a spreadsheet that they dubbed 'the monster spreadsheet' that contained 100+ tabs with hundreds of people adding to it.
It got to the point where it was always crashing and simply became a burden to use. It's a fairly common story, though maybe not to this extreme, that companies find they quickly outgrow spreadsheets as a form of manual data collection.
There is also the question of the quality of data provided, how can they trust the insights gained from the data provided from so many different sources?
At Pulsora, they've made use of AI within their platform that can help bring all that data together and analyse it to identify any anomalies and duplicated data.
They've also focused on creating collaborative workflows, so all communications regarding collection of emissions data can be kept under one roof, meaning you have a fully traceable and auditable trail for all data collected.
[15:10] How can you prevent data fragmentation across your business? Pulsora have made use of AI to prevent data fragmentation, they have achieved this with agentic AI, which is AI that can coordinate between different paths and can make decisions without a human in the loop.
A use case for this might be where you have a company with thousands of suppliers, but would only be able to get emissions data from the handful of long-term suppliers that are happy to work with them. AI can assist with the remaining suppliers by looking for any published information those suppliers have, and take that emissions and financial data to create an intensity factor for the supplier. This can then make an informed estimate for how many emissions equate from so much spend with that supplier.
The AI will of course keep a trail for all it's sourced data so a human can review this and ensure the information is correct if needed.
[18:45] What does 'Comprehensive data' mean in the context of sustainability? When gathering emissions data, a business has to consider what part of its operations creates the most emissions.
This will differ depending on the sector and nature of your business. Whether you're a B2B business or a manufacturer, you need to confirm where your largest emissions source. It's imperative that your emissions inventory is reflective of your business and its impact.
There will also be gaps in the data you want / need to collect. You still need to ensure that data in any reporting provided is reflective of your operations, you can't just leave that data out, especially as there are now tools to help fill those gaps. AI for example can identify representative data to help bridge those gaps to provide a comprehensive inventory.
[22:35] How can Pulsora help a business take their carbon data from spreadsheets to integrated data systems?: Jessica uses a company, Franklin Templeton, to explain the process.
In this case, the company is a global asset manager and they used Workday for a lot of their HR, procurement and financial data. When it came to collating emissions data, they didn't realise that 95% of the information needed was already stored in Workday.
For other companies that are quire energy intensive, there's a high chance that you already have a comprehensive system with most of the data required.
In Franklin Templeton's case, they helped them to transfer this over into the Pulsora system with an existing out-of-the-box migration tool for Workday. For the HR data Pulsora were able to assist with ESG reporting.
The Pulsora system was able to apply emissions factors to the transferred data automatically, which helped to create a comprehensive view of their scope 1, 2 and 3 emissions.
Jessica give another example for a glass manufacturing company called Seagen who are based in Turkey. While they didn't have the monster spreadsheet situation, they had a fairly good system in place but it wasn't quite reaching the mark in terms of being able to report against multiple different carbon frameworks.
Pulsora's system help to quantify their data, quite a task in of itself due to how high their emissions were, and it also helped to apply all this gathered data to those carbon frameworks.
They also utilised Pulsora to help gather various metrics from 7 business units across 100 sites, that aided in audit preparation and insurance.
[29:00] How can you make you carbon data more auditable and traceable?: If you're just starting out on your emissions journey, we highly recommend looking to the GHG protocol for guidance on the scope 1,2 and 3 definitions and what's required of each for reporting.
The first step you should take is to determine what scopes and categories are relevant to your business according to the GHG protocol. There are a few different approaches including a percentage based approach or ones that include more detailed data analysis.
The second step is emission factors, which is essentially a process of taking your business activities and translating that into emissions. You need to establish a consistent approach to documenting these emission factors, and those emissions factors will be determined by your region.
UK for example use DEFRA factors, the US have EPA and Europe uses AIB. There are global data sets available as well, such as IEA.
The main key is establishing your methodology early on, and be consistent in your approach while documenting everything in line with that agreed methodology.
For a more structured approach to carbon emissions reporting, that includes auditability and traceability at it's core are ISO Standards such as ISO 14064 and ISO 14068.
[32:45] How can new carbon focused technology, such as AI tools, help with seeking investment? Jessica shares a sneak peak into a new feature that Pulsora have recently released to help with seeking investment, which is invoice reading.
This feature allows users to upload invoices to the Pulsora system, and it will extract the required data without the need for manual input. This aids in the auditability and traceability within the system as this data is displayed right alongside the evidence it was extracted from.
The system can also compare file content to spot and flag up any anomalies, so you can ensure your data is as accurate as possible before going through a formal audit process with a third-party such as Carbonology.
That stamp of approval from a successful third-party audit can then be used for raising capital and sharing with stakeholders.
[35:55] How can you get information from your supply chain to cover scope 3 emissions?: Jessica provides some helpful tips for scope 3 emissions, including:-
Don't worry about getting primary information from all of your suppliers. You only need enough data to identify your decarbonization plans and strategy to share with stakeholders with a high degree of confidence. You don't have to get it 100% perfect.
Prioritise your suppliers – Consider how much you spend with each supplier, how good are your relationships with them? What impact do your suppliers have on your emissions? You should target the ones that are the most impactful.
A lack of response doesn't always mean a lack of data - Some supplier just won't respond to your data requests, but there are ways you can still get some information, such as 10 based emission factors to get a baseline. With publicly available data about specific sectors and regions, you can get pretty close to the info you need.
Get creative – There are other ways to gather data, such as using similar more responsive suppliers as a baseline. You could hold an industry group meeting to talk about improving data transparency and data sharing. This process will be beneficial for all involved by driving both costs and emissions down through a collaborative effort. Create a sphere of influence, drive the change you want to see within your supply chain.
Create a Supplier Sustainability Strategy – Again, a consistent and planned approach will encourage engagement.
Lastly, don't sweat it if you can't always get the data you want. Making a start is more important than getting it perfect. A lot of frameworks are quite forgiving and allow you time to mature your systems to a level where reporting can be repeated on an annual basis.
[40:30] What book would Jessica recommend? A Costa Rica travel book. Jessica simply love the country and it's culture, it's also highly immersive in nature and mostly operates on renewable energy.
[40:30] What is Jessica's favourite quote? "If you were born with the weakness to fall, you were born with the strength to rise" Ruby Carr – extract from her poetry book 'Milk and Honey'
If you'd like to learn more about Pulsora, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
An ISO project can typically be completed within 6 – 12 months depending on an organisations size and complexity. Anyone who's been through the process of ISO Implementation knows that there is a lot of work involved in that time span, from coordinating teams, gathering and creating documentation to auditing your processes.
Now imagine doing that for 3 ISO Standards simultaneously within 3 months! Which is exactly what today's guest, PUBLIC, have achieved. While it's not a timeframe we recommend, their efforts deserve to be celebrated, and displays what good project management with dedicated individuals can accomplish.
In this episode, Ian Battersby is joined by Biba Gonzalez, Senior Associate of Business Operations at PUBLIC, to discuss their 3-month dash to implement ISO 9001, ISO 14001 and ISO 20000-1, and explore the challenges and benefits experienced during the process.
You'll learn
· Who is Biba Gonzalez?
· Who are PUBLIC?
· What was the main driver behind ISO 9001, ISO 14001 and ISO 20000-1 Implementation?
· What was the biggest gap identified during the Gap Analysis?
· What did Biba learn from the experience of implementing 3 standards at once?
· What are the main benefits of ISO 9001, ISO 14001 and ISO 20000-1?
· Biba's top tip
Resources
· PUBLIC
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian is joined by Biba Gonzalez, Senior Associate of Business Operations at PUBLIC, to learn more about their 3-month whirlwind journey towards ISO 9001, ISO 14001 & ISO 20000-1 implementation.
[02:30] Jumping in at the deep end: Biba was tasked with obtaining certification to 3 ISO Standard on returning from maternity leave in July 2025.
PUBLIC already held ISO 27001 certification, but were looking to achieve ISO 9001 & ISO 14001 before Christmas of 2025.
This was quite the task, especially since Biba had no previous experience with ISO Standards!
[04:15] Who is Biba? Biba is the Senior Associate of Business Operations at PUBLIC. She has been the driving force behind PUBLIC's ISO 9001, ISO 14001 and ISO 20000-1 implementation.
One fact that not many people might know about her is that she has had a private audience with the pope, by complete accident! Simply a case of wrong queue at the right time while on a family vacation.
[06:50] Who are PUBLIC? PUBLIC are a digital transformation partner. They work within the private sector to help improve public services, by providing procurement services, online safety programmes and other digitally enabled services.
[08:00] What were the main drivers behind achieving ISO 9001, ISO 14001 and ISO 20000-1?: PUBLIC work with a number of Government departments, and while bidding for various frameworks they noticed a trend in requests for bidding companies to have ISO 9001 and ISO 14001 certification.
While not always a strict requirement, it was certainly a desirable trait that was preferred of bidding companies.
There's also an increasing number of tenders asking for more environmental requirements, such as carbon emission reporting. What used to be a 'nice to have' is now becoming a requirement, and PUBLIC sought to have these requirements met via the relevant ISO Standards.
[09:40] A tight timescale: When Biba had arrived back from maternity leave in July, PUBLIC has already booked in assessment dates with a Certification Body. This left quite a tight timeline of just 3-months to get all 3 Standards implemented to a level that could pass a Stage 1 Assessment.
They already had an ISO 27001 system in place, but there was still a lot of work to do. A lot had been discussed about the implementation of additional standards in Biba's absence, but no practical steps had been taken aside from booking the audit dates.
She certainly had her work cut out for her as most ISO project typically last between 6 – 12 months!
Due to all her hard work, and some assistance from Blackmores, PUBLIC passed their Stage 1 assessment with flying colours and are in a good place to tackle their Stage 2 Assessment in late November 2025.
[11:40] What was the biggest gap identified during the Gap Analysis? Thankfully PUBLIC didn't have any huge gaps to fill. Due to their previous work with Government departments, they had a lot of the pieces just not together in a cohesive system.
They did identify early on that they wanted a system that worked for them in the long term and were conscious of creating something that fit their way of working. With so many ISO Standards, the upkeep alone would have been overwhelming so they aimed to combine as much as they could into one Business Management System rather than opting to silo each individual Management System.
[13:00] What were the benefits of Implementing ISO 9001, ISO 14001 & ISO 20000-1? Biba states that the implementation of these ISO Standards took their business to the next level.
Coming from a relatively small start-up, there was some of the micro business mentality that remained despite their growth in recent years. ISO Standards helped to keep everyone adhering to the same requirements.
PUBLIC have taken a more hollistic approach to ISO implementation to both make it as simple as possible for everyone to work within, while also driving continual improvement within the business.
Having established processes means that everyone is singing from the same song sheet, and provides traceable processes that can be questioned and amended if and when issues occur.
[16:15] Additional benefits felt from ISO Implementation: There is greater accountability with the Management system in place.
There is also the added benefits of being able to bid and win new business opportunities.
[17:25] Biba's top tip for ISO Implementation: Don't try and implement an ISO Standard (or multiple!) in just 3 months. While PUBLIC managed to do so, it was a lot of hard work squeezed into a very tight timeframe, and Biba wouldn't recommend anyone try to match their level of ambition in this regard.
Secondly she adds, make the Management System work for you and your business. ISO Standards by their nature read to be fairly generic, and that's by design, so that you have the freedom to implement them in a way that makes sense to you. There is no point implementing an obtuse system that no one wants to interact with, the key is to embed it into the way you already work, with a view to use it as a tool to drive continual improvement as the system matures.
[19:00] Looking to the future: Biba is optimistic about the business, as they're looking to grow by 20% next year, supported by all the work done to Implement ISO 9001, ISO 14001 and ISO 20000-1.
While they have had to change aspects of how they worked prior, due to being a small business the nature of approvals and ways of working were on a more individual basis, whereas now there is a team-based approach. It's been a learning curve, but ultimately one that will serve them well as they grow over the next few years.
[21:30] Biba's book recommendation: Invisible Women: the Sunday Times number one bestseller exposing the gender bias women face every day by Caroline Criado Perez
[24:05] Biba's favourite quote: "Not my circus, not my monkey" an idiom which Biba's sure a lot of Operations Directors can sympathise with
If you'd like to learn more about PUBLIC, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Continual Improvement is at the heart of ISO Management, a large part of which is dedicated to ensuring issues don't reoccur. This is more than just putting a plaster on it and calling it a day, it's about finding the root cause.
This not only eliminates wasted time, effort and money with firefighting repeated mistakes, but also drives meaningful improvement. Over the years, many techniques have been developed to help with finding cause.
In this episode, Ian Battersby explores the need to find the root cause of issues in ISO Management and explains some key techniques for root cause analysis that you can put into practice to help stop recurring issues.
You'll learn
· What is meant by 'finding cause'?
· Why do you need to find the cause?
· Where is finding cause specified in ISO Standards?
· Finding cause in practice
· What are the 5 Why's?
· What is the fish bone / Ishikawa?
· What is FMEA?
· What is fault tree analysis?
· How do these techniques work in practice?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian dives into finding cause within ISO Management, explaining various techniques to help you prevent recurring issues.
[03:15] What is meant by 'Finding cause'? When an output from a process is not what was expected, then it is classed as a non-conformity which will need to be addressed through corrective action.
Before you can put that action into place, you need to identify the root cause for the issue. It's about putting right what went wrong.
[04:00] Why do you need to find cause? Ian gives an example of a reactive response to resolving an issue, it didn't get to the root of why the mistake happened in the first place.
Finding cause is necessary to stop issues from repeating, rather than simply firefighting issues as they occur.
ISO terminology has updated to reflect this over the years. There used to be a term called 'Preventive action', but this has since been changed to 'Corrective action' following on from the 2015 Annex SL update to many ISO Standards. This reflects the new risk-based approach to ISO management.
The terms are largely the same in nature, but preventive action was widely misunderstood and so this was renamed and clarified following 2015.
[05:55] Where is finding cause specified in ISO Standards? As with many aspects of ISO, the need for finding cause can be found in a few places within a Standard, including: -
Clause 6.1.1 Planning: It specifies the need to determine risks and opportunities that need to be addressed. This is because they will affect the desired outcome of your Management System. It's also a good place to start thinking about how to reduce those risks.
Evaluating your strengths and weaknesses also gives you the chance to contemplate whether your existing processes are good at delivering what you want.
Clause 10 Improvement: The Standard states something to the effect of 'the organisation shall determine and select opportunities for improvement and implement any necessary actions to address those opportunities'
These opportunities will focus on improving products and services, which includes correcting, preventing or reducing undesired results.
Also included under clause 10 is a subclause that directly addresses non-conformities and corrective action. These specify not only the need to resolve issues as they arise, but to evaluate the need for action to eliminate the root cause.
Additional requirements include the need to review these actions and determine if they are actually effective. Ian goes into Clause 10 in more detail in a previous podcast specifically looking at opportunities for improvement.
[14:20] Finding cause in practice – Why a methodology is necessary: Ian provides an example where an employee may lack confidence completing a certain activity. Their lack of competence could lead to a process being delivered incorrectly.
That adverse quality outcome would then likely end up with the customer who would raise a complaint, in this instance that could be a damaged product. The damaged product is what needs correcting, from your perspective you would be looking at what caused that to prevent recurrence. Without knowing the initial cause, you would need to determine whether it's a production issue or a human error.
These types of scenarios can branch out further than the initial quality issue. For example, if that damaged product causes harm, then it turns into a health & safety risk. If products need to be scrapped, then there's an environmental factor.
Complaints related to product quality may also not be recorded in a standard non-conformity system, and could easily be missed for a full investigation to find root cause.
This is why it's important to have a consistent approach, in both logging issues and evaluating them to determine cause.
[18:10] What are the 5 Why's? This is one of the more popular methods that people use to determine cause. It's simply a case of asking why a scenario happened, usually 5 times, though you can ask more or less depending on how long it takes to reach the core issue.
It doesn't require much training and all it requires is an open and honest response to the questions. This method can get answers quickly and is often utilised as an early problem solving technique.
[19:30] What is the fish bone / Ishikawa? This is a more visual method to find cause. Depicting a fish skeleton that categorises possible causes and groups these accordingly.
These causes are then discussed for a few minutes, typically with teams of people in order to gain different perspectives to help pull apart complex problems into their contributing factors.
This method is particularly useful in cases where there isn't a single underlying cause.
[20:30] What is FMEA? FMEA or Failure Modes and Effects Analysis is a more structured technique and acts like a risk assessment in reverse.
It looks at what can go wrong, what the effect of failure is and then how critical that failure is to the outcome of what you're trying to do. It uses risk priorities to decide what's more important.
[21:15] What is Fault Tree Analysis? This method utilises a top-down logical approach. It's a diagrammatic representation of what's going wrong.
It asks, does this happen? Yes or no or both, and branches down paths that explore the issue. It allows for quantitative measures with a number output that can help determine how likely recurrence will be.
It's a method that is often used in engineering and manufacturing processes.
[22:55] Scatter Diagrams: Scatter diagrams are a good tool to find correlation. They help visualise the relationship between two variables. If you have data rich environments, these can really help you plot out those relationships and make those links that otherwise may have been missed.
[23:40] The 5 Why's in more detail: The 5 Why's is a great starting technique as it requires little training. Ian provides an example of using the 5 Why's, with the scenario of a worker who has injured themselves while cutting some wood.
Using the 5 Why's, he asks these questions:
· Why did the workers hand slip while cutting the wood? – They were holding the material in one had without the use of any clamping device to keep it steady.
· Why was the material being held by hand instead of using a clamp? Because there was no clamping device available.
· Why was there no clamping device available on the table? The design of that workstation didn't take into consideration the need for a permanent clamping fixture.
· Why wasn't that taken into consideration for the workstation? The risk assessment for that workstation was overlooked.
From this exercise, you can see how you can get to the root of an issue by simply asking 'Why' a number of times. Again, it can be more or less than 5 times, the name is simply a guideline.
[25:40] The Fishbone / Ishikawa method in more detail: Another favoured simple technique for finding cause is the fishbone method. It utilises 6 categories to get to the root of an issue, those being:-
· Machine: Addressing the equipment or technology that you use to deliver products and services.
· Method: The way in which you deliver products and services.
· Material: The raw inputs into your processes.
· Measurement: The data and metrics that you use to monitor the successful delivery of your products and services.
· Mother Nature: The environment and conditions in which you're operating.
· Man – Although this has now been updated to 'People', addresses the human element of product and service delivery.
This is a great method for instances where there may be multiple root issues, so you can categorise and analyse each of them with multiple perspectives involved as this is considered a more collaborative method for root cause.
[28:15] Record your findings: We dive more into this in a previous episode, but essentially, it's a requirement of every ISO Standard to address these non-conformities as they occur. Going through the process of root cause and rectifying the issue will need documentation to prove that you are actively addressing these issues, as well as doing as much as you can to prevent recurrence.
There is no defined way to do this in the Standard, so it can be documented via forms, intranets, other digital systems etc.
Documenting all the evidence of resolving issues may seem arduous at times, but it will ultimately lead to genuine continual improvement, and will lead to reduced overall error.
If you'd like any assistance with ISO Implementation or support, get in touch with us, we'd be happy to help.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
When thinking of sectors that need effective energy management, the ones that typically come to mind include the likes of transportation and manufacturing. However, energy management is something that any business can benefit from.
Such is the case with today's feature, Clyde & Co, a global law firm who made the decision to Implement ISO 50001 energy management to tackle the largest part of their sustainability impact.
In this episode, Ian Battersby is joined by Paul Barnacle, Head of Health, Safety, Security and Environment at Clyde & Co, to discuss their journey towards ISO 50001, including the challenges associated with implementation and benefits gained from certification.
You'll learn
· Who is Paul Barnacle?
· Who is Clyde & Co?
· What was the main driver behind obtaining ISO 50001?
· How long did it take to achieve certification?
· What was the biggest gap found during the Gap Analysis?
· What has Paul learned as a result of ISO 50001 Implementation?
· What are the benefits of gaining ISO 50001 certification?
· Paul's top tip
Resources
· Clyde & Co
· ISO 50001
· Isologyhub
In this episode, we talk about:
[00:25] Episode Summary – We invite guest Paul Barnacle, Head of Health, Safety, Security and Environment at Clyde & Co, onto the show to share his journey with implementing ISO 50001, including the associated challenges and benefits from gaining certification.
[02:50] Who is Paul Barnacle? Paul is the Head of Health, Safety, Security and Environment at Clyde & Co , and was the lead for the ISO 50001 Implementation project.
One thing that many may not know about Paul is that he's an avid angler, whether rain or shine, he's dedicated to getting the next big catch.
[04:45] Who are Clyde & Co? Clyde & Co are a global law firm that helps organisations navigate risk and maximise opportunities across sectors such as insurance, professional services, aviation, marine, construction and energy.
The firm has over 500 partners with a total headcount of 5,500 people operating across 70 offices around the world.
[05:40] Who is included within the ISO 50001 scope for Clyde & Co? For those that aren't aware, an ISO scope can be against an entire business, a single department or even against a specific product / service.
For Clyde & Co, their ISO 50001 scope extends across 9 offices in the UK and Republic or Ireland.
[06:15] What were the main drivers behind ISO 50001 Implementation? – One of the main drivers links back to Clyde & Co's Net Zero Strategy, which included the need to identify which sustainability focused ISO Standard would help them the most.
Following a lot of internal conversation with their Chief Sustainability Officer, they settled on ISO 50001 as they were seeking more visibility on their energy consumption and help with identifying opportunities for improvement. Ultimately taking the first steps to tackle their scope 1 and 2 emissions.
[07:05] Why ISO 50001 over ISO 14001? ISO 14001 Environmental Management was considered, however they don't have any industrial processes, so other environmental factors outside of energy aren't very applicable to a business like Clyde & Co.
Seeing as energy was their largest environmental expenditure, ISO 50001 naturally seemed like the best fit.
[08:10] How long did it take to achieve ISO 50001? Paul started the Implementation journey back in early August of 2024, and completed the Stage 2 Assessment by April 11th 2025, so a total of nine months.
[09:00] What was the biggest gap identified during the Gap Analysis? Paul highlights how key the Gap Analysis was to the whole process, as it gave them a clear picture of the amount of work involved with completing the implementation.
One of the biggest gaps identified was the fact that they didn't have a structured management system in place. There was a lack of knowledge when it came to ISO implementation, so some of the terminology was a bit lost on Paul to start with! They also lacked key documentation such as continual improvement log and Register of Energy Saving Opportunities.
[10:10] What were the benefits of ISO 50001 implementation? There are a number of benefits, including:-
· ISO 50001 allows a business to have a lot more visibility on their energy consumption
· ISO 50001 certification demonstrates a proactive approach for energy management to clients and prospects.
· The data provided by ISO 50001 allows for more informed decisions on energy saving and reduction opportunities, allowing you to target your biggest emission sources and spot any anomalies.
[11:45] Client influence: Clyde & Co were seeing an increase in requests from clients regarding their energy performance indicators and related KPI's. They were also being asked about what they were doing in relation to reducing their scope 1 and 2 emissions.
This exercise allowed them to address both, in addition to setting up the infrastructure to continuously monitor this year on year.
As a result of ISO 50001 implementation, Clyde & Co now plan to communicate the reduction in their energy consumption on a quarterly basis with staff across all regions.
[13:50] Additional Improvement as a result of ISO 50001: Paul enjoys the renewed communication between teams that hadn't really interacted prior to ISO 50001 implementation. Previously the energy management team were fairly siloed in the business, but now they're getting tech champions involved and asking anyone to contribute to the energy performance indicators.
It's created a connected culture that encourages new ideas from all corners of the business.
They've helped to facilitate this through the use of their intranet with dedicated mailboxes where people can submit any questions or suggestions for improvement. They've also got QR codes set-up for easy access for mailbox submissions.
[15:55] Paul's Top Tip: Get a copy of whichever Standard you intend to Implement and read it thoroughly. It's key that you understand what the Standard is asking for.
If you're struggling with the ISO terminology, the Standards will include a glossary of terms and definitions to help you. You can also do what Clyde & Co did, which is hire ISO consultants that specialise in ISO implementation. They will help you interpret the Standard and help you establish a Management system that is both compliant with the Standard and also integrates with the way you work.
For ISO 50001 specifically, Paul highlights the need for strong data. Energy monitoring will require some number crunching, so you need those figures to be as accurate as possible to get the best results.
[15:55] Paul's book recommendation: Sustainable Energy - Without The Hot Air by David MacKay
[15:55] Paul's favourite quote: "The best way to predict the future, is to create it." – Abraham Lincoln
If you'd like to learn more about Clyde & Co, check out their website.
We'd love to hear your views and comments about the ISO Show, here's how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The topic of suicide is all too often a discussion avoided due to its tragic and uncomfortable nature. However, the reality is that there are 6,000 deaths by suicide in the UK each year, with in excess of 727,000 deaths annually worldwide.
In recent years there has been more awareness about the topic, with a range of resources targeted to help with the prevention and support of those affected. For businesses seeking further guidance, a new Standard is on the horizon.
In this episode, Ian Battersby is joined by Marcus Long, Chief Executive at IIOA, who shares his inspirational story of working through an unthinkable tragedy and creating a silver lining that aims to tackle the intervention, prevention and support for people affected by suicide.
You’ll learn
· Who are IIOA?
· Who is Marcus Long?
· What was the catalyst behind BS 30480?
· Who is involved with the development of BS 30480?
· What does this Standard hope to achieve?
· How does this Standard compare to other ISO Standards?
· How will this Standard develop within the next year?
· The cost of suicide
· What are the benefits of BS 30480?
· How can you get involved?
Resources
· Register your interest in BS 30480
· Contact Marcus Long
· IIOA
In this episode, we talk about:
[00:25] Episode Summary – We invite guest Marcus Long, Chief Executive at IIOA, onto the show to talk about his involvement with the development of BS 30480, a Standard dedicated to the intervention, prevention and support for people affected by suicide.
[01:30] Who are IIOA? The IIOA are the Independent International Organisation for Assurance, which is a trade association for global assurance bodies.
Their members carry out certification to a wide range of ISO Standards, related Standard schemes, product certification and the provision of validation and verification training.
[02:30] Who is Marcus Long? Before becoming the Chief Executive at IIOA, Marcus worked for the national Standards body side of BSI. There he was involved with ISO Standard development and later moved into certification.
He’s had 20 years’ experience within the field of ISO Standards, and spent most of that time pushing the benefits and value of quality infrastructure.
One thing many may not know about Marcus is that he spent 48 hours underwater! While not in one stint, Marcus is an avid scuba diver, and has been taking trips under the waves since 1990, with his cumulative underwater adventures reaching 48 hours total to date.
[05:30] What was the catalyst behind BS 30480? Marcus experienced an unthinkable tragedy in October of 202, when his son Adam took his life at the age of 21. In the following three years, Marcus sought to find some sort of silver lining to give him some peace.
After a while, he turned to look at the industry he worked within, Standards, which is focused on solving problems and finding solutions. Ultimately, it’s aim is to make the world a better place, whether that’s through sustainability, quality or Health & Safety.
So why couldn’t that principle be applied to something as difficult and heartbreaking as suicide.
With that idea in mind, Marcus got talking to some national standards bodies in different countries around the globe, in addition to ISO, to see if the idea could spark some interest.
These discussions reached BSI, who were currently also working on creating a Standards on the topic of menstrual health and menopause in the workplace. Marcus appreciated that they were willing to touch on topics that many shied away from.
[08:50] The conception of BS 30480 – The first steps taken included hosting workshops at the Houses of Parliament in February of 2024. There Marcus brought together a wide range of people with different experiences, and asked them if they thought this Standard was a good idea and gather what how they would like to see something like this work in practice.
With that encouragement and feedback, Marcus set to work on setting a scope and deciding who should be involved in the development process.
[11:05] Who is involved with the development of BS 30480? As with many ISO’s, the development team are made up of a wide range of people, including people from academia and business owners. Marcus ensured that healthcare specialists and those who’ve assisted in suicide prevention schemes were also included.
All of these individuals had the same passion to help reduce the rate of suicide within the UK.
[13:10] What does this Standard hope to achieve? The sad reality is that in many instances, it’s a reactive response to suicide.
What Marcus hope BS 30480 can achieve is to encourage the creation of suicide prevention strategies. This turns that reactive response into a proactive one in terms of preventing the worst from happening.
As quoted from the Standard:
“ The aim is to make workplaces more suicide safe, more conducive to suicide prevention, more supportive of those who have been exposed to suicide and more knowledgeable and confident in talking about suicide and taking actions that prevent suicide.”
[15:30] How does this Standard compare to other ISO Standards? This Standard differs from ISO Standards such as ISO 9001 and ISO 45001 in the fact that it’s a guidance Standard, so not one that can be certified to.
It provides guidelines and guidance that businesses use, and select the parts that are most relevant to them.
The Standard also includes a number of Appendix’s that provide more practical guidance to help give businesses a clearer idea on how certain elements can be implemented, for example, the creation and deployment of a suicide prevention plan.
So rather than a rigid set of requirements, think of it as a collection of practical ideas and solutions that can aid in the prevention of suicide.
[18:20] How will this Standard develop within the next year? BS 30480 is expected to be published in November 2025, as they’ve just finished the consultation period in August 2025, which was met with a very positive response.
Marcus would love to see this Standard move into the international stage by becoming an ISO, but for now it’s being published as a British Standard.
There are plans to create training and host webinars to spread awareness about the Standard, so keep an eye out on BSI’s socials for more about that!
The standard is set to enter a phased communication strategy:
Phase 1: The launch of the Standard, which has already had some preparation as various other Standard bodies and those involved have been spreading awareness throughout the drafting process.
Phase 2: Public awareness – Marcus and those involved in the creation of BS 30480 will be ramping up public dialogue on what the Standard is about and what it can achieve for people.
Phase 3: Engagement – Actively getting business to engage with dialogue around suicide prevention, as this is a topic that some businesses are scared to even tough. But if we’re to tackle it, it needs to be discussed.
There is scope for this Standard to fit in with the likes of ISO 45001 (Occupational H&S) and ISO 45003 (Mental Health in the workplace).
Marcus also discusses the opportunities for this to help less traditional workplaces such as educational institutions, sports clubs, charities & youth clubs.
[23:30] The cost of suicide: As much as it seems inappropriate to put a price on suicide, there is more to it that the emotional and societal devastation. A report by The Samaritans suggested that each death by suicide resulted in a cost of £500,000. This is due to related costs for emergency healthcare systems and loss of productivity.
Marcus emphasizes that if we are to get more businesses, Government and local Governments on board, all impacts of suicide need to be discussed in addition to the benefits of suicide prevention.
While odd to approach it from a cost perspective, it’s more often than not the language that businesses speak. They need to be informed of the investment required in people, time and cost just as much as they need to be aware of the many benefits of effective and proactive suicide prevention.
[26:40] What are the benefits of BS 30480? The ultimate aim is to make workplaces a safer and better place. This Standard can also provide a means of effectively measuring social value, which is often times a rather nebulous metric to grasp.
This Standard is here to save lives, and its practical guidance can help businesses create a clear path of actions to help those who may suspect that a colleague is in need of help.
[28:25] How can you get involved? Marcus’ biggest ambition is for BS 30480 to assist with saving lives, but if it’s to achieve it’s main aim, it needs advocates.
Whether from trade associations, other Standards bodies or just from individuals, spread the word and encourage businesses to adopt the guidance provided.
You can register your interest in BS 30480 through BSI’s website, this ensures you get updates on the Standards progress and any training opportunities.
If you’d like learn more about BS 30480, feel free to contact Marcus Long via LinkedIn.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
When stating ISO Management System ‘compliance’, that in reality means the conformance to ISO Standard requirements, compliance in ISO terminology actually refers to compliance with legal and other statutory regulations.
It may sound like semantics, but the difference is distinct for a reason, as you don’t get a ‘non-compliance’ for not meeting requirements, rather you get a ‘non-conformity’. When it comes to compliance with the law as required by ISO Standards, you need more than a Legal Register to prove compliance.
In this episode, Ian Battersby dives into what is meant by compliance in ISO, how this relates to legal and statutory requirements, and how businesses can effectively evaluate compliance.
You’ll learn
· What is the difference between ‘Compliance’ and ‘Conformity’?
· What are the different types of compliance requirements?
· How do Acts and Regulations work in tandem?
· Who enforces legal compliance requirements?
· Where do these requirements sit in ISO Standards?
· How do you prove compliance within ISO management?
· How do you evaluate effective compliance?
Resources
· Isologyhub
· From Silos to Synergy: The benefits of Implementing an Integrated ISO Management System Webinar registration
In this episode, we talk about:
[00:30] Upcoming webinar: If you’d like to learn more about the benefits of integrated management systems, feel free to register for our upcoming webinar here.
[01:30] Episode Summary – Ian Battersby discusses the topic of compliance within ISO Standards, and how you can effectively evaluate it within your Management System.
[02:30] What is the difference between ‘Compliance’ and ‘Conformity’? It’s a common misconception that you ‘comply’ with an ISO Standard, when in reality, you conform to an ISO Standard, hence why you can receive a ‘non-conformity’ in audits and not ‘noncompliance’.
When we talk about compliance within ISO Management, this refers to compliance with the law, regulations and other statutory requirements, as this is a requirement within all ISO Standards.
[03:50] What are the different types of compliance requirements? There are many different types of law, Ian focuses on what is known as statute law legislation, as this is distinct from common law, case law and constitutional conventions.
Statute law legislation is clearly written and can be cited in something like a Legal Register, or Register of Compliance Obligations. There are different types of legislation that you’ll need to document, including:
Primary Legislation: These are put in place by acts of UK Parliament and may have involvement from devolved administrations as well. Statutory compliance refers to compliance with primary legislation. An example of this type of legislation includes the Health & Safety at Work Act.
Secondary or delegated legislation: Those primary Acts often require a lot more detail regarding the practicalities of applying them, which is delivered through Secondary or delegated legislation, otherwise more commonly known as regulations. These have more input from relevant public bodies to provide the requirements that can be applied.
Both regulations are issues under Statutory Instruments (SI's), which are the formal legal vehicle that gives them effect. Put simply, regulations are the rules and Statutory Instruments are the legal mechanism which brings those rules into effect.
[06:05] How Acts and Regulations work in tandem: Taking the Health & Safety at Work Act as an example, at the start this was quite a broad and generic act, it wasn’t until years later that the workplace health, safety and welfare regulations came about to support the Act.
This was further bolstered with the Management of Health & Safety at Work Regulations. Both regulations were developed through consultation between Government departments and other bodies such as the Health & Safety Executive.
These regulations gave companies much more detail on what’s actually required in order to comply with the Health & Safety at Work Act.
[06:50] Who enforces legal requirements? – It’s not just the police that enforce legal requirements, there are a number of other bodies independent of government and the judiciary that can enforce regulations and prosecute for breaches caused by organisations and individuals.
This can include bodies such as The Health & Safety Executive, The Financial Conduct Authority, The Environment Agency and the Information Commissioners Office. There are more for other areas, and these are often the bodies involved in the development of specific regulations.
[07:45] Where do these requirements sit in ISO Standards? As Is the case with ISO Standards, the requirement for compliance is sprinkled throughout the whole document.
Starting with Clause 4 Context. Here ‘Interested parties’ are a focus, of which regulatory bodies can be considered an interested party, as they control the regulations that you are required to comply with by law.
Even if you don’t think you fall under specific legislation, there are still general applicable business laws that all businesses must comply with. So this exercise is not simply a case of running a Management System, it’s also about running an effective business.
Ian highlights clause 6.1.3 in ISO 45001, which states the need to determine legal requirements applicable to your business, whereas in ISO 14001 this clause talks about compliance obligations. Despite the difference in wording, they are essentially looking for the same thing, which is detailing what legal requirements you need to comply with.
In ISO 9001 it also states that any products or services offered should meet customer and applicable statutory and regulatory requirements. This is then further strengthened in the Leadership clause as leaders are required to ensure that their commitments meet all customer requirements, but also any applicable regulatory and statutory requirements associated with the products and service. This is phrasing that is repeated throughout ISO 9001.
Going back to ISO 45001 and ISO 14001, both also require an evaluation of compliance, both the part of monitoring and measuring and the results of them to be submitted through your management review process.
The Standards are very clear in that they require you to determine the frequency and methods for evaluation of compliance.
[12:00] How do you prove compliance within ISO management? In ISO 45001 there is an appendix that give examples of what you can monitor and measure for the fulfilment and evaluation of legal requirements.
As mentioned, many organisations opt to use a Legal Register which states all applicable legislation for your business that will be evaluated in an Internal Audit, but proving genuine compliance is much more than just acknowledging the legislation itself.
For larger organisations, this can be a very burdensome task, especially if you find yourself in a position where legal requirements aren’t being met.
Ian provides an example to illustrate how to prove effective compliance:
Waste removal is something that every business has to do, whether they do so through a waste management contractor, or through a landlord, the law states that any waste you generate must be removed, transferred, processed, treated, etc. by licenced organisation in a very specifically regulated fashion.
You as an organisation or your landlord may receive an annual season ticket which includes the required demonstration of compliance, which can be in the form of West Carrier license number, the types of waste, the classification codes under the European or waste catalogue, dates and signatures.
Now if you run into an instance where something on that waste transfer note was incorrect, like a wrong address or waste type, how do you prove that you were still compliant in the actual activity of removing waste? An Audit will pick up on the note discrepancies and you may be faced with being non-compliant.
A way to ensure that you have a record of compliance is to keep electronic copies of all your waste transfer notes, and keep them in a central location, or even possibly linked within your Legal Register if possible. Despite the discrepancy, you will be able to prove that you have a prior record of compliance.
Ian gives another example, you may have air conditioning in your area of work that’s due for a service. The contractor will need to verify the engineer before you engage with them, including a check to see if they’re competent under F Gas Regulations and hold a valid REFCOM Registration Certificate.
If you wait to check / validate their certificates of competence, you may run into a situation where they may have an expired certificate at the time that they serviced your aircon, and so that may render that service as inadequate under your legal requirements.
To avoid this, you should reference that you’ve evaluated the contractor within your Legal Register, this would include a check on their registration number and dates of when their F Gas competency certificates are valid, ensuring your service falls within those dates.
In short, to demonstrate compliance, you should be keeping on-going records in relation to your legal requirements. These should also be readily available and easily accessible.
[20:35] How do you evaluate effective compliance: Legal requirements such as the Health & Safety at Work Act are much broader, and it can be difficult to know exactly what records you need to keep to prove compliance.
This is where the supporting regulations can provide the required detail and provide a much clearer picture of what evidence is required. One example is the requirement to carry out sufficient risk assessments, which requires you to identify hazards, assess risks, determine control measures you know, communicate those to people, and review of those assessments regularly.
You as the business will need to create a programme to manage the risk assessment process, and this should be documented somewhere, including a note of your review and action dates. This risk assessment list should also be linked within your Legal Register.
In short, one of the most effective ways to show and evaluate compliance is to ensure that all relevant evidence is linked or attached in some way to a Legal Register or Register of Compliance Obligations. These evidence documents should be active and hold a record of previous actions and any planned upcoming actions.
You could also schedule regular inspections of your legal compliance, to evaluate your level of compliance against different requirements on an on-going basis. The resulting reports can also be linked within the Legal Register.
Don’t just rely on Internal Audits to cover your legal compliance evaluation. Utilise dedicated legal compliance inspections, link all relevant evidence within your legal register and have on-going reviews and updates throughout the year.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That’s not surprising as it’s quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide.
We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Anju Punetha, a QHSE Consultant at Blackmores, to share the journey of how she transitioned from special education in India, to ISO consultancy for international organisations.
You’ll learn
· What is Anju’s role at Blackmores?
· What does Anju enjoy outside of consultancy?
· What path did Anju take to become an ISO Consultant?
· What is the biggest challenge she’s faced when implementing ISO Standards?
· What is Anju’s biggest achievement?
Resources
· Isologyhub
· From Silos to Synergy: The benefits of Implementing an Integrated ISO Management System Webinar registration
In this episode, we talk about:
[02:05] Episode Summary – We introduce Anju Punetha, a QHSE Consultant here at Blackmores, to discuss her journey towards becoming an ISO consultant who specialises in ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 20121 and ISO 55001.
[04:05] What is Anju’s role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards.
As part of that support, she:
· Conduct internal audits
· Reviews and updates management system documentation
· Facilitate management reviews
· Train internal teams and prepare them for certification audits.
When implementing a new ISO standard, she’ll start with a gap analysis – i.e comparing their current practices against the standard’s requirements. Then break down those requirements into simple, easy-to-understand language and create a practical plan to bridge the gaps.
Depending on the standard, she may also facilitate strategic business risk assessments, environmental aspects and impacts assessments, or information security risk assessments.
Additionally, Anju helps clients develop and implement policies and procedures, create legal and compliance registers, and verify their readiness for certification body audits.
[05:55] What does Anju enjoy doing outside of consultancy?: Anju loves spending time outdoors with long walks being her go-to, as they help her unwind both physically and mentally.
She also enjoys cooking for her family and friends. Experimenting with different cuisines and blending spices is something Anju finds incredibly relaxing.
[08:00] What was Anju’s path towards becoming an ISO Consultant?: Like many of the Blackmores team, Anju never planned to become an ISO consultant.
She began her career as a Special Educator, working with children with special needs in India.
Later, she transitioned into the development sector as a Research Assistant, working on projects funded by The World Bank and the UN World Food Programme. These projects focused on microfinance, training and development, and women & child health.
However, that role involved a lot of travel, which became challenging after the birth of her first son. So, Anju decided that would be a good time to take a career break.
When Anju was ready to return to work, she looked for an office-based role which resulted in her joining Ericsson, a Swedish Networking and Telecommunication Company as support staff, and progressed upwards to become the Learning and Development Manager at their rapidly growing Global Service Centre in India.
This involved managing training requirements of an employee base of around 4000+ employees, involvement in stakeholder management at all levels and vendor management.
As part of the Operational Excellence initiatives, she also got involved in preparing different business teams for their internal and external audits.
During that time, Anju became interested in Ericsson’s Group Management System, which all legal entities had to comply with. She then moved into the newly formed Quality Department and helped them to gain various ISO certifications.
She was the Project Leader for implementing Ericsson’s Operational Maturity Model compliant to the requirements of ISO 9001, ISO 14001, ISO 27001 and OHSAS 18001 (ISO 45001’s predecessor).
Joining Blackmores as an ISO Consultant felt like a natural next step when she relocated to UK. She’s now been a member of our team for over six years, and continues to inspire others with her level of dedication to her work and clients.
[13:35] What is Anju’s favourite aspect of being a Consultant? – The variation in daily activities is a big positive for Anju.
One day she may be conducting a gap analysis for Environmental Management System for an IT company, and the next drafting policies and procedures for managing Events Sustainably for an Event Management company or auditing a client on their Information Security Management System. No two days are the same!
She also enjoys being able to work with a wide range of clients across sectors like IT, construction, facilities, asset management, event management, and train operating companies, all ranging from small businesses to large, multi-site organisations.
She particularly enjoys working on Integrated Management Systems, as they help clients save time and money by streamlining multiple standards into one cohesive system.
It reduces duplication, improves efficiency, and encourages collaboration across teams—breaking down silos and building synergy.
[15:50] Upcoming webinar: If you’d like to learn more about the benefits of integrated management systems, feel free to register for our upcoming webinar here.
[17:30] What Standards does Anju specilaise in and why? Starting with:
· ISO 9001 Quality Management: A core foundation that many businesses start with when diving into the world of ISO Standards. This is an essential one for any ISO consultant and is often the first Implementation experience for many who go on to become ISO consultants.
· ISO 14001 Environmental Management: This Standard provides a solid base for any business looking to start taking sustainability seriously.
· ISO 45001 Health and Safety Management: Anju helped one of her previous employers implement this Standards’ predecessor, and has since implemented and supported ISO 45001 for a number of Blackmores clients.
· ISO 27001 Information Security Management: An increasingly popular Standard as we see more and more business rely on technology to keep their services running smoothly.
· ISO 55001 Asset Management: A popular Standard within the facilities and public transportation sectors. This Standard aims to create a framework to help organisations manage the life-cycle of their assets.
ISO 20121 Sustainable Event Management: ISO 20121 focuses on governing principles of sustainable development, which are:
· Stewardship
· Inclusion
· Integrity
· Transparency
ISO 20121 was revised in 2024. The revised standard explicitly requires considering climate change and its impact on the event and stakeholders. The new version also expands beyond environmental concerns to encompass human and child rights, social impact (including mental health and diversity), and digital responsibility and how organisations should start considering these areas at the early stages of planning an event through post event activities.
Recently, Anju has been busy in putting together the toolkit for transition to ISO 20121:2024 and preparing her clients with the implementation of the revised and new requirements.
[21:10] What is the biggest challenge Anju had faced during a project and how did she overcome it?: Anju offers one experience in particular:
She was working with a company that was implementing its first ISO Standard. The project not only involved creating and implementing standardised policies and procedures but also working on the overall change management within the business.
The teams were used to working in silos for many years and were not very forthcoming with the idea of establishing and implementing standardised ways of working.
This was due to various reasons, such as lack of awareness, operational activities taking precedence over risk and process-based approach. As a result, project leads struggled in getting support from the project sponsor and the extended project team in terms of time and effort.
They had to put the project on halt for few months and only proceeded with the project after getting the full commitment from the sponsor and other project team members.
During this time, ISO related roles and responsibilities were built into the job descriptions of the various stakeholders, these were agreed as part of the internal review processes and required time and effort for the different stakeholders within the business was agreed with the Management Team.
At the end, this project helped the company to embed the standardised processes within the business, rather than it being just a tick in the box exercise to achieve certification.
[25:35] What is Anju’s proudest achievement? Anju’s proudest achievement in relation to work, is when she’s able to see a marked difference in the confidence level of her clients, from the start of the ISO implementation project, which is the gap analysis stage, to confidently facing the certification audit and demonstrating to the external assessors that the implementation of the ISO project was not just a tick in the box exercise for them.
One achievement in particular stands out in recent months as she supported a client in successfully transitioning to the revised ISO 20121 standard.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
One of the biggest challenges for those looking to achieve Net Zero is tackling scope 3 emissions, which are indirect emissions that typically reside in your supply chain.
These can account for up to 70% of your total emissions and can be quite the undertaking to gather the necessary data to be able to complete your calculations needed for carbon verification.
In the final episode of the Platform to Proof mini-series, we invite Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, back onto the podcast to explain how to tackle scope 3 emissions, how it works in practice and how carbon accounting software can streamline the process.
You’ll learn
· What are scope 3 emissions?
· What are the drivers for those tackling scope 3 emissions?
· Where to start with scope 3 emissions
· How does supply chain engagement work in practice?
· What are the benefits for suppliers involved?
· How can carbon accounting software help with scope 3 emissions?
Resources
· Gravity
· Carbonology
In this episode, we talk about:
[02:05] Episode Summary – We introduce Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, who will accompany Mel on a 3-part mini-series diving into carbon accounting software and the value it can bring.
In this final part, Mel and Jay dive into scope 3 emissions, the challenges associated with gathering them and how carbon accounting software can help streamline this process.
[02:30] Catch-up on the first part – If you missed the first two parts of the series, catch-up with them here:
· Part 1: From Platform To Proof – What Is The Business Driver For Carbon Accounting And Reporting?
· Part 2: From Platform To Proof – How Carbon Accounting Software and Verification Combine for Carbon Compliance
[03:50] What are scope 3 emissions?: The term ‘scope 3’ comes from a document and initiative called the GHG Protocol, which sets out the core methodology by which companies should measure account for their greenhouse gas emissions. It details 3 different scopes, scope 1 is your direct emissions (i.e. fuel for vehicle use ect), Scope 2 is grid emissions associated with purchased electricity or other forms of energy (i.e. energy for offices).
Scope 3 is a very broad term and addresses the emissions created by your value / supply chain. This could include things like transportation of resources you require from a third-party.
These emissions can count to upwards of 70% of a companies total emissions, depending on the nature of the business that can even go as high as 90%!
[06:50] What are the drivers for those tackling scope 3 emissions? Jay summaries 3 of the main drivers:
Biggest emission source: For those looking to truly hit Net Zero, they can’t simply ignore their largest emission source. It poses the biggest risk to the company, so it’s in their best interest to reduce them where possible. Of course, this isn’t easy as it may involve swapping suppliers or working with existing ones to make their practices more sustainable. It’s not as straight forward as addressing your scope 1 and 2 emissions.
Regulation requirement: Scope 3 is increasingly being included within mandatory regulations, whereas in previous years, it may have been a voluntary part of those requirements. For example, the new regulations coming into effect for California in 2026 will see around 10,000 companies needing to report on their scope 3 emissions.
In the EU, regulations such as CSRD also require reporting on these emissions. Though these haven’t been made mandatory as of yet, we can see that changing in future.
Stakeholder requirement changes: Customers and other stakeholders are asking for more evidence of meaningful sustainability action. Supply chain initiatives now are gearing more towards sustainable procurement, which coincides with the rise of CSR related activities. This drive to evaluate your supply chain is being pushed from all directions.
[09:55] Where to start with scope 3 emissions: Likely stating the obvious, but ensure you have addressed your scope 1 and 2 emissions first.
When looking to your scope 3 emissions, you’ll first need to determine which of the 15 emission categories is going to be important for your business to get a handle on. The nature of your business will determine which of the categories are a priority, so if you’re a digital service based business, then the raw materials category likely won’t be very appliable to you so you’d only need to provide a very high-level summary of any related emissions.
For those categories that are a priority, you should identify how in-depth you would need to get with the data analytics, and create a strategy for each of those categories. If you’re struggling to start, there are some industry average statistics out there to help you with those initial calculations.
It’s key to set up a defined measurement cycle, that will need the ability to get more granular as you progress. This is so you can actively track your reduction efforts.
Of course, the level of this will be determined by the resource you and your suppliers have to help facilitate the process. It’s definitely worth investing in your supplier relationships to make this process run smoothly year on year.
Some business that have say 100+ suppliers will often send out a survey to obtain this data, but the quality of the information returned (if any) can be lacking. So, a more direct approach will likely reap the results you’re after.
Mel highlights an instance where an organisation had an engagement programme, where they selected 100 of their suppliers and provided training and guidance on understanding and reporting on their emissions. The suppliers could then see how beneficial the process was not just for that organisations, but for their own company as well. It’s more than just gathering data, it’s about effecting your sphere of influence for meaningful change.
[14:15] How does supply chain engagement work in practice? As mentioned, one of the ways many organisations have opted to gather data have been through supplier surveys, however, you need to supplement this with other supplier initiatives to get the best results.
Gravity took a more empathetic approach, by looking at this process from the suppliers perspective. They highlighted that this should just be an extractive exercise, the supplier should also be getting something out of this.
One such way to do so would be to give them training and / or tools in order to measure their emissions so they can give you the data you need, and also have that data to share with their other customers. You can work with them to identify potential emission reductions and energy saving schemes that could save them money down the line.
There are also a number of AI tools that can comb the web and look for any public carbon disclosures or ESG reports that suppliers may have already made. So this saves on the initial outreach and results in less burden for both parties.
[17:10] What are the benefits for suppliers involved? By adding further requirements to your supplier relationship, it offers the opportunity to evaluate and develop your supplier engagement strategy.
The suppliers can benefit both from your experience with carbon reporting, in addition to gaining access to the same tools you use to manage this.
By helping them get a jump start on their carbon disclosures, they can benefits from being ahead of the curve if certain regulations haven’t effected them yet. We’re seeing these sustainability regulations trickle down to new sectors and smaller companies, so them having the data ready puts them at a great advantage.
They can also potentially optimise their own processes and save money from the experience by using their data to identify where further reductions can be made. Those supplier reductions then benefit your organisation as your scope 3 emissions improve, it’s a win win situation.
[20:35] How can carbon accounting software help with scope 3 emissions? Using Gravity as an example, they’ve built a lot of tools that can take raw inventory and gather a lot of data concerning purchasing, logistics ect. This is all collated into one area where it can be analysed and used for calculations.
They also have an AI agent that can comb the web for specific information that your suppliers may have publicly disclosed. An AI agent can also reach out directly to suppliers for further information which will be collated within your centralised system, checked for accuracy and put into a format that’s ready for reporting.
This is all done with a full audit trail for transparency.
If you’d like to learn more about Gravity and how their energy and carbon accounting software can help you, check out their website. If you’d like to ask Jay any questions directly, feel free to send him an email.
If you’d like any assistance with Carbon Verification, get in touch with the Carbonology team, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
As the sustainability crisis grows more pressing each passing year, companies are increasingly being required to comply with various sustainability regulations and legislation, most of which include the need to monitor and verify your carbon emissions.
Calculating these carbon emissions can be tricky, especially if you have a lot of sites or international locations that require conversions. This is where dedicated carbon accounting software can save you a lot of headache!
In the second episode of the Platform to Proof mini-series, we invite Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, back onto the podcast to discuss how carbon accounting software can be utilised on your carbon verification journey, and explore the additional benefits provided by this technology.
You’ll learn
· What is the role of carbon accounting platforms and how does carbon accounting software help to overcome the challenges that organisations are facing today?
· How does carbon accounting software work?
· What additional benefits are there from using carbon accounting software?
· Why is carbon verification becoming increasingly important?
· How can carbon accounting software encourage a culture shift?
Resources
· Gravity
· Carbonology
In this episode, we talk about:
[02:05] Episode Summary – We introduce Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, who will accompany Mel on a 3-part mini-series diving into carbon accounting software and the value it can bring.
In this second episode Mel and Jay explore how carbon accounting software and verification work together for carbon compliance, in addition to the other benefits companies can gain from utilising carbon software.
[02:30] Catch-up on the first part – If you missed our first episode in the series, go back and listen to that before continuing. It gives a more in-depth introduction to Jay, Gravity and carbon accounting software in general.
[04:05] What is the role of carbon accounting platforms and how does carbon accounting software help to overcome the challenges that organisations are facing today?: Jay has had many conversations with those that have had challenges historically with gathering the data needed for carbon calculation and verification. As we see more regulations and legislation, this challenge is passed down to those just starting on their journey.
Carbon accounting software can help ease the burden involved with these tasks. This can come in the form of making it easy to aggregate the data and doing the necessary calculations while maintaining a trail of where all that information comes from.
There’s also an audit trail available for the calculations done, which can be monitored and dug down further into. There’s scope in many dedicated carbon accounting platforms for you to be able to dig deeper into your data if needed.
Lastly, this level of transparency in the data is often a requirement of going through full carbon verification in alignment with best practice standards (such as ISO 14064).
Ultimately, carbon accounting software can make the verification process go a lot more smoothly.
[09:05] How does carbon accounting software work? Jay breaks this down to help define the purpose of carbon accounting software, and the additional benefits it can bring, including:
A centralised place for carbon data: Often times, businesses need to pull data from a wide variety of places, and collating that data is always a challenge. Dedicated software allows for easier collection and storage of data from all of the necessary sources, such as utilities, logistics and finance.
Carbon accounting software will often allow for integrations that allow for existing systems to feed data into the software without any extra burden. With the addition of AI tools, they can even allow for automatic document processing that can interpret the meaning of utility bills, fuel invoices, waste receipts ect to save on manual data entry.
Carbon calculation: Another headache associated with carbon reporting is the calculation utilising all that data you’ve painstakingly collected. There’re often additional layers such as conversion or emission factors that need to be considered when making these calculations. Carbon Accounting Software can do all of this for you, saving you the trouble and potential of making mistakes. This in addition to the transparency offered as the software will provide an audit trail to show how it arrived at the final numbers.
Carbon Reporting: This isn’t a feature in all carbon related software, but it can be another time saver if you find one that does. The raw calculations data will only get you so far, and that alone may not be enough to meet the requirements of whichever framework you need to comply with.
Carbon software can assist with putting those calculations into a usable reporting format. This report and data can then be analysed and used for meaningful action, in addition to complying with a number of different frameworks.
Carbon reduction: Some carbon accounting software will also have the additional bonus of being able to help you source potential solutions and vendors to help reduce your carbon emissions. This more proactive stance on taking your findings and making improvements is voluntary in a lot of schemes currently, but we are seeing a rise in a mandatory requirements to show evidence of carbon reduction, so it’s better to get your head around this sooner rather than later.
[15:20] Why is carbon verification becoming increasingly important? Sustainability is no longer isolated to one person or department in an organisation, there’s an increasing overlap of sustainability with other functions such as financial reporting. It also coincides with those working towards ESG compliance, as the data collection, calculations and reporting infrastructure for sustainability information can have a very big practical effect.
The need for transparency regarding sustainability is also becoming a bigger concern for customers and stakeholders, so naturally, companies are taking it more seriously as more questions are being asked of them in that regard. Having the data and paper trails (or software trails if you prefer) to back up their claims is vital.
[19:20] How can carbon accounting software encourage a culture shift? Carbon accounting software is the glue that pulls all the elements of carbon compliance together. It’s often the case that the person responsible for the software in a company is crucial for the full verifications process as well.
Though the gathering of data is a team process, and if embedded correctly, then it can act as a catalyst for a cultural shift towards sustainability.
Not everyone has to have knowledge of all the inner workings of carbon collection, calculation and reporting, but by being involved in the process they can feel a sense of accomplishment when milestones are reached.
By spreading the burden companies can also afford to spend a lot more time working on this than they would have otherwise. Carbon accounting software can help this along by ensuring the data gets where it needs to go, and to make the process simpler for all those involved.
The use of both a team-based approach in tandem with dedicated software can also help in regard to risk mitigation by removing single points of failure. Carbon reporting and verification is an annual task, so when people come and go from the business, it’s key that you have the necessary skills, people and tools to help facilitate that process through those organisational changes.
If you’d like to learn more about Gravity and how their energy and carbon accounting software can help you, check out their website. If you’d like to ask Jay any questions directly, feel free to send him an email.
If you’d like any assistance with Carbon Verification, get in touch with the Carbonology team, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
One of the biggest hurdles for businesses when embarking on their journey to net zero is the calculation required for carbon verification. Depending on the nature and size of a business, it can be quite the undertaking!
Those looking to tackle this challenge have various options available to them, including the use of dedicated carbon accounting software, which we’ll explore in our latest mini-series: From Platform to Proof.
In the first episode of this series, we introduce Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, to explore the key drivers behind carbon accounting and reporting and how you can maximise value from going through the process.
You’ll learn
· Who is Jay Ruckelshaus?
· Who are Gravity?
· Why do businesses measure their carbon footprint?
· Why is the language of business value becoming more important for sustainability professionals?
· What are the key drivers for carbon accounting?
· How has GHG emissions reporting helped to drive business value?
· What should businesses be thinking about to maximise business value?
· How can businesses keep up with ever changing sustainability legislation?
· The importance of data quality
· How can carbon accounting software help?
Resources
· Gravity
· Carbonology
In this episode, we talk about:
[02:05] Episode Summary – We introduce Jay Ruckelshaus, Co-Founder and Head of Policy and Partnerships at Gravity, who will accompany Mel on a 3-part mini-series diving into carbon accounting software and the value it can bring.
In this first episode, they explore the key drivers behind carbon accounting and reporting, and how businesses can maximise the value from the process.
[03:10] Who is Jay Ruckelshaus? Jay’s involvement in sustainability was almost an inevitability, coming from a family of environmental lawyers.
Energy, climate and sustainability were topics that often came up at the dinner table, and so it remained a subject near and dear to his heart.
Initially, Jay thought he would remain in the academic world, studying polarisation and exploring how energy intensive industries think about sustainability. He found his enthusiasm spiked when working directly with companies and individuals on these topics.
As a result, he broke out of the academic world to join forces with a few technology leaders to develop a solution to help businesses measure and reduce their emissions.
[04:45] Who are Gravity?: Jay founded Gravity 4 years ago (2021). It provides a carbon and energy management platform, which assists businesses with compliance to the alphabet soup of sustainability legislation currently in effect, such as CSRD and TCFD.
This platform also uses the data collected to help businesses find and invest in projects to help reduce their emissions, which ultimately saves on energy, costs and utilities.
Their aim was to make it easier for businesses to report their emissions, by streamlining the collection process, and using the data to pre-qualify potential vendors that would fit the businesses needs when it comes to the reduction phase.
Jay initially started with emissions heavy industries such as construction, manufacturing logistics, utilities, metals, mining, energy ect. These are industries where data collection can be very challenging, so it provided a very solid base for their software so that it could tackle these challenges first and provide a way for them to work with various e-commerce, software companies and financial institutions, all within one system.
[09:05] Why do businesses measure their carbon footprint? Historically, back in the 70’s, 80’s and 90’s, sustainability was often wrapped up in the wider corporate social responsibility movement.
We’ve seen a lot of change in the last decade, where we used to have strictly voluntary schemes such as CSR, that are now transitioning into a requirement. Whether that be by stakeholders or legislation.
We’ve also seen a greater interest in ESG metrics, which require solid figures to back up your claims. This trend follows from the introduction of mandatory legislation from the European Union’s CSRD, which is trickling into California law as around 10,000 companies of a certain size that operate in California must now disclose their carbon emissions.
[11:40] Why is the language of business value becoming more important for sustainability professionals? It wasn’t too long ago that sustainability professionals were lumped in with groups that managed general social responsibility.
We’re seeing more dedicated and senior roles in relation to sustainability, such as ‘Chief Sustainability Officer’. These roles now integrate with most every branch of an organisation, from the financial reporting to the general strategy for the business. It becomes a central part of the business.
Its role can reap many benefits for businesses that embed it effectively, including cost cutting, energy reduction, creation or use of innovative products, opening doors to new markets and investment opportunities.
[14:15] What are the key business drivers for carbon accounting? There are many benefits for carbon accounting, such as: -
Saving energy: Energy prices are volatile, and often on the rise. Carbon accounting allows you to have a full view on what you’re consuming and where you can reduce or look to more efficient options.
Building in sustainability from the top down: With increasing scrutiny from stakeholder and consumers regarding sustainability, it’s in leaderships interest to ensure that sustainability is embedded in your business strategy. This alignment sets you up well for the future, In addition to creating an avenue to reap other benefits from meaningful sustainability action.
New opportunities: Embarking on your sustainability journey will open many new doors. Whether this be for innovative new technology, new partners and suppliers that better align with your values, or access to new investment opportunities.
[18:05] How has GHG emissions reporting helped to drive business value? Businesses that get their emissions verified against ISO 14064 can benefit from improved insurance rates and access to green finance.
It’s also a necessary step towards energy and cost savings. You can’t reduce what you can’t measure. Doing this correctly will require time and resources, thankfully we’re at a time where there are a lot of tools to help businesses with data collection for reporting purposes. The key is to understand where you currently stand, and where you can make improvements. From there you can look at vendors to assist and what financing is available to help facilitate the required changes.
Jay states an example of where Gravity managed to save a US based aluminum foundry over $400,000 in energy costs from their initial assessment. This was achieved through identifying energy hotspots and finding vendors and initiatives to help reduce the energy use and costs.
[21:15] What should businesses be thinking about to maximise business value?: The biggest challenge for carbon accounting is typically gathering the data. There are a lot of things to consider, facility energy usage, travel, home workers ect.
To make this easier, you should ideally have a centralised location to report and track your emissions data. You also need to ensure that this is as accurate as possible.
In order to make sure this doesn’t turn into an annual tick-box exercise, you need to embed proactive processes for monitoring and measuring this data. This way, when you have anomalies in energy usage, you can identify these quickly and put plans in place to address it.
[24:25] How can businesses keep up with ever changing sustainability legislation? In recent years, the goal posts for specific sustainability regulation and legislation has changed a lot.
This is in part due to convergence that is happening between the frameworks, countries and Governments adopting the best bits out of other requirements to make theirs more robust. So, while a lot of the information they’re asking for is largely the same, it can still be very confusing to navigate.
Jay advises that businesses focus on getting a core system for reporting, monitoring and measuring energy usage and carbon emissions in place. Depending on the requirements that you need to adhere to, you can slice and dice that data up however it’s needed, but setting up a unified approach that’s embedded throughout your business to get the data needed is they key.
[28:40] The Importance of data quality: Your first attempt at this process will likely be rough and ready. Gathering the basics of what’s available such as utility bills and general energy usage. Presenting this estimation can make for a great business case to put in place measures to get more granular data.
The more granular the data, the more insightful it can be, offering you more opportunities to save money and implement reduction initiatives.
This data will reveal trends, form benchmarks and present opportunities for meaningful action that benefits both the business and the environment, all while satisfying your legal and regulatory requirements.
[30:50] How can carbon accounting software help?: Data collection is hard, getting the data where you need it to be can be nightmare, especially when multiple departments are involved. Having a centralised location makes this task a lot easier.
Calculating this data into something usable is also tricky, and would likely require a skillset that you won’t have readily available. This may also involve knowledge of conversion factors if you have multiple international locations. Having a system that can manage all of this, while using methodologies that are in alignment with best practice standards is crucial.
Lastly, technology such as carbon accounting software, can really help with creating a proactive approach to the measurement and reporting process. It can reveal anomalies and trends to be acted on, as it can help source vendors and projects to help with emission reductions.
If you’d like to learn more about Gravity and how their energy and carbon accounting software can help you, check out their website.
If you’d like any assistance with Carbon Verification, get in touch with the Carbonology team, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Becoming an ISO consultant isn’t a career path many aspire to, rather it’s one often stumbled on after being tasked with either implementing or maintaining a Standard for a business.
We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Minoo Agarwal, a QHSE Consultant at Blackmores, to learn about her journey of following in her father’s footsteps towards ISO Standards Management, and what drives her to help clients on their ISO journey.
You’ll learn
· What is Minoo’s role at Blackmores?
· What does Minoo enjoy outside of consultancy?
· What path did Minoo take to become an ISO Consultant?
· What is the biggest challenge she’s faced when implementing ISO Standards?
· What is Minoo’s biggest achievement?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – We introduce Minoo Agarwal, a QHSE Consultant here at Blackmores, to discuss her journey towards becoming an ISO consultant who specialises in ISO 14001, ISO 9001, ISO 45001 and ISO 27001.
[03:50] What is Minoo’s role at Blackmores? Minno’s official job title is QHSE Consultant. She is the ISO14001:2015 standard champion and a Mental Health First Aider for Blackmores.
Ultimately, Minoo supports clients with embedding Management System into the heart of their companies. Her work with them typically consists of:
· Conducting internal audits
· Management review
· Consultancy days or document review days
Essentially doing whatever it takes to getting the management system to be at a suitable level to pass external audits.
[05:05] What does Minoo enjoy doing outside of consultancy?: Minoo’s free time is mostly taken up by her dear son, Aarav.
He’s very young at the moment; and so Minoo makes sure that any of her input into his life is to ensure that he is successful in whatever career he chooses. In addition, Aarav has a very busy social life! So, she’s makes sure her gets plenty of time to play with his friends.
Minoo is also a bit of a foodie, enjoying eating out when possible. She also enjoys reading books by authors such as Jay Shetty and the Sad Guru.
[07:10] What was Minoo’s path towards becoming an ISO Consultant?: Minoo, like many of our consultants, didn’t know that she would become a consultant.
The opportunity was presented by Mel Blackmore via LinkedIn in 2019, on April 1st of all dates!
Minoo’s passion for this field arose from her father, Mr Hardial Agarwal, who is very well known in the industry. He worked as a consultant for Crayola for many years, travelling abroad to meet with various suppliers and international branches of the company. His work always held an air of mystery to Minoo as a child, and she become more curious about his role in later years, even attending CQI meetings with her father to learn more.
She started her career in 2006 as a Quality, Environmental, Health & Safety Administrator and since then really never looked back, progressing from role to role from roles like Quality Associate, to a Business Quality Control Officer, to a QESH Auditor, to HSQE Compliance Manager and then as a Head of Quality.
Each role gave her a different experience of life. As a result, she has worked in many industries ranging from electronics to logistics to pharma and even automotive and IT.
She feels very fortunate to gain experience and knowledge from a range of industries from her previous roles, and now more so from Blackmores where this knowledge develops further.
[12:35] What is Minoo’s favourite aspect of being a Consultant? – Minoo genuinely loves her role as a consultant at Blackmores, it was hard to narrow down a specific aspect.
That being said, Minoo loves to hear when a client of hers has passed their surveillance and re-certification audits, especially if it was with no findings. It’s a return on their combined effort as a team to get recognition of that fact from a certification body.
She also enjoys the teamwork involved, often being seen as a real member of the client’s team. As a consultant, a bid part of your role is building strong working relationships, which makes the whole process run a lot more smoothly.
She also takes a bit of joy in being able to be a bit bossy, though all the guidance is with the best intentions.
[15:40] What Standards does Minoo specilaise in and why? Starting with:
· ISO 9001 Quality Management: A core foundation that many businesses start with when diving into the world of ISO Standards. This is an essential one for any ISO consultant and is often the first Implementation experience for many who go on to become ISO consultants.
· ISO 14001 Environmental Management: Minoo is our Standards champion for this Standard. This involves keeping on-top of any changes to the Standard and creating internal training material for the team.
· ISO 45001 Health and Safety Management: A few of Minoo’s previous roles involved health and safety compliance, so she learned a lot about ISO 45001 and general risk management along the way.
· ISO 27001 Information Security Management: This one was a necessity to learn when joining Blackmores. Many of our clients have integrated management systems with multiple ISO certifications, most of which include ISO 27001.
Minoo also has some experience with MHRA regulations and TS 16949.
[18:20] What is the biggest challenge Minoo had faced during a project and how did she overcome it?: Minoo stresses that it’s fundamental to fully understand the requirements of the client from the very onset of the project, if that is understood then there will be no challenges during a project.
She provides two incidents in particular that stood out:
Scope creep: There was an incident when there was a misunderstanding of the work agreed, and the client had anticipated much more than what was agreed. As a result, Minoo had to complete the work in her own time to meet their expectations.
Personal bias: There have been incidents not related to projects but external audits when external assessors start to audit the client by providing what they believe their interpretations is of the standard is the only way that it can be implemented. Forgetting the fact that Standards are built to be flexible in the way they are implemented. They can get very fussy about the exact way documentation should be laid out and worded, which is obviously not a specific stipulation within a Standard.
Minoo has overcome this by confronting the assessor at the time and asking them to explain where in the standard it say that – basically keeping them in check.
[21:30] What is Minoo’s proudest achievement? On the work side, Minoo is always proud to hear when a client has passed their Surveillance and Recertification Audits with no or few findings.
On the personal side, it’s her son who she lovingly dubs as her masterpiece. She’s already instilling the values of health and safety into him, and he’s always looking out for others. She couldn’t be prouder to watch him grow up into his own person.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The process of verifying your carbon emissions requires a lot of data gathering, number crunching and in some cases conversion if you’re international. It’s certainly no small task!
However, it’s worth the effort. With it completed you will have a much better idea of your current impact and be able to make better informed decisions on how to reduce it. When starting out on your verification journey you’ll need to start with calculating your scope 1 & 2 emissions, these are the direct and indirect greenhouse gas (GHG) emissions that your business is responsible for.
That alone can be quite a mammoth task, especially if you have a lot of locations worldwide, such is the case as today’s guest: Culligan.
In this episode, Mel is joined by Martin Murden, ESG Manager at Culligan International, to discuss why Culligan started their verification journey, the key insights uncovered, and the challenges involved with calculating emissions for a large international organisation.
You’ll learn
· Who is Martin Murden?
· Who are Culligan International?
· Why are Culligan seeking third-party verification for scope 1 & 2?
· Key insights uncovered as a result of verification
· What changes have they made to their data collection processes?
· How did internal teams find the experience?
· How have Culligan utilised verified data?
· What is the biggest misconception about the verification process?
Resources
· Culligan International
· Carbonology
· Culligan 2024 ESG Report
In this episode, we talk about:
[02:05] Episode Summary – Mel Blackmore is joined by Martin Murden, ESG Manager at Culligan, to discuss their carbon verification journey and explore the challenges associated with calculating scope 1 & 2 emissions for a large international organisation.
[03:25] Who is Martin Murden? Martin is an ESG Manager at Culligan, his role focuses more on the environmental aspect of ESG compliance.
His main role involves looking after Culligan’s carbon emissions, carbon reduction plan, evaluating use of resources and exploring initiatives to reduce their current impact.
One fun fact that not many people know about Martin, one of his ancestors was involved in the creation of Turkish delight!
[06:25] Who are Culligan International? Culligan International are a global leader in water services. Their solutions provide cleaner, safer, better tasting water.
While not a household name here in the UK, chances are if you’re refilling a bottle from a cooler, it’s likely derived from one of Culligan’s brands.
They own over 100 businesses in over 40 countries, with more than 600 sites ranging from warehouses and offices to production and water bottling plants. They also manage 7000 vehicles which help with delivering, installing and maintaining their equipment.
With over 15,000 people working at Culligan, it’s clear to say that it’s a large organisation with a lot of moving parts.
They keep sustainability at the heart of their business, working to discourage the use of single use plastic, and looking at other ways to reduce their impact via their supply chain.
[08:45] Why did Culligan seek third-party carbon verification? – There were a few reasons, including: -
Regulatory requirements: Being a global business, there are a number of mandatory reporting requirements coming down the pipeline in certain countries they operate in, such as Australia and Mexico, Canada, California.
Accuracy: Part of these requirements is assuring the transparency and accuracy of the data. Third-party assurance is essential to meet mandatory reporting requirements, in addition to being an added level of assurance for stakeholders.
From an internal point of view, it also gives the ESG team more confidence in the gathered data, allowing them to form a more robust baseline for their decarbonisation strategy.
[10:15] Culligan’s decarbonisation strategy – In 2024, Culligan published a number of commitments, one of those was to reduce its scope 1 and 2 carbon emissions by 40% by 2035.
They built a decarbonisation plan based on information that they had available internally. This consisted of looking at vehicle fleet use and facilities use, how large they are and what kind of energy sources they use.
They also spoke to individual business units to understand where it may be possible to switch to renewable energy sources, how initial energy use could be reduced and making use of lower carbon vehicles.
They were confident in their ability to reduce their impact, but they needed that third-party assurance that their initial baseline was as accurate as possible.
[11:35] Is this the first time Culligan has gone through a formal verification process? – While they have measured their carbon emissions since 2022, they have never formally gone through the full verification process before.
[11:55] How did they prepare for the formal verification process? – The first step was selecting a reputable carbon verification body to verify their calculations. They opted to go ahead with Carbonology, spending a lot of time with their assigned auditor to:
· Understand what the requirements were
· Ascertain what the priorities were
· Understand what evidence was required
They also needed to clearly communicate internally so that all their stakeholders and data owners were aware of what was required from them and when they needed to provide it by.
Martin has found that over the past 3 years of collating data required for carbon emission calculations, they have greatly improved their level of accuracy and accountability.
With the goal of carbon verification providing a much-needed focus, they’ve been able to identify potential gaps in their evidence received from local data owners.
[14:10] How did Culligan find the experience of working with Carbonology?:- They were pleasantly surprised! ISO Standard audits can be daunting at the best of times as you’re not really sure what to expect, however, Carbobology were great at guiding the process so it all ran smoothly.
This included a process of daily review meetings and establishing a daily agenda and priorities. Martin found himself looking forward to those meetings as they opened up the opportunity to discuss how to improve the accuracy of data in addition to the collection methods.
[16:05] What were the key insights Culligan found when going through the carbon verification process? – They certainly had a few surprises along the way, mostly positive, including: -
Exposing inaccuracies: There were cases of inaccuracies in their original data, where data owners accidentally added an extra 0, or accidentally selected gigawatt hours instead of kilowatt hours when uploading submissions. Going through this process allowed them to tidy up their data.
Identifying high energy usage: Using this updated accurate data, they could then identify what sites had a higher-than-average rate of energy consumption.
Holistic approach: The data provided a fuller picture of where their emissions were over or understated. They could then interrogate any irregularities and look at where improvements could be made, in addition to updating their data collection methods where necessary.
[18:35] What changes have Culligan made to their data collection and reporting process as a result of verification? – They’re now looking at other options for collecting data.
Ideally, they’d like to connect their data to a centralised sources, rather than having to approach each business individually. With over 100 businesses owned, you can appreciate that this is quite a time consuming task!
There are other opportunities such as getting API links in place directly with their back office systems and utility providers, so that manual intervention isn’t required.
Technology related to carbon data collection is advancing each year, there are a number of platforms that can make this process more efficient. For example, Culligan are looking into OCR software that can read PDF supplier invoices so that this no longer has to be a manual activity.
Looking forward, they would like to capture evidence needed for the audit process at the point of data entry, rather than having to ask data owners a second time to provide copies of invoices they’d already populated in a different database.
[20:55] Were there any unexpected challenges or collaboration as a result of the carbon verification process? – Martin was expecting some pushback, however he was pleasantly surprised with the amount of buy-in they had from local business units. It seemed they really understood the benefits to the business on their level and for Culligan as a whole.
As they’d been collating data for a few years now, a process was already in place meaning there was minimal work to do on their end.
Many of their local businesses have found it a real benefit to have this information available, as many clients and prospective clients are asking about their sustainability credentials.
Also, having credible third-party verification validating their claims gives them a step up from competitors, in addition to providing those clients assurance that Culligan followed due diligence.
[23:05] What additional value has third-party verification provided? –The main benefits were strengthening stakeholder trust and improved reporting confidence internally.
The initial reactions that Culligan had from colleagues once they’d shared the news that they’d passed the accreditation was an extremely positive one. Shortly after they were inundated with requests from their global business units for copies of the ISO certificate provided by Carbonology, so that they could share it with their clients and customers.
It's also provided some much-needed confidence to the ESG team in terms of combatting claims of greenwashing. With verification against the internally recognised standard ISO 14064, they know they won’t have anyone challenging the validity of their carbon emission figures.
[25:00] How else will the verified data be utilised across Culligan? – Sustainability is a key focus for Culligan, this information provides a starting point for meaning reduction in their impact, in addition to satisfying stakeholder requirements and requests for the data. It short, it benefits everyone.
Culligan have recently published their 3rd annual ESG report, and the verification is referred to regularly throughout that report, in addition to their external communications throughout the year.
This step has shown that they’re not simply jumping on the Net Zero bandwagon, they want to really understand their impact so that they can make meaningful change. In the short-term, they’re looking to tackle their scope 3 emissions within the next 12 months, and hopefully get third-party verification for those as well.
[27:15] What are Culligan’s medium and long terms goals for sustainability? – Scope 3 is the next thing they want to tackle, however, that will not be a small undertaking. They used predominantly purchased goods and services data to estimate their upstream emissions, so they need to hone in on those and ensure that they retain the same level of accuracy and consistency as the process used to calculate the scope 1 and 2 emissions.
The ESG journey is not linear, and will constantly adapt and flex as they move forward. Their main goal is simply to reduce emissions, through a reduction in resources used and the promotion of sustainability efforts such as reducing the use of single use plastic.
[29:05] What is the biggest misconception about the verification process? – For Martin, this is the fear of the unknown. For a large organisation like Culligan, this was daunting at first. Having to communicate to all their different stakeholders what the requirements are and what data and evidence was needed.
For the verification process, it was a worry if they were in for a long and painful process. In actuality, it was 8 days worth of preparation followed by 8 days of reviewing, which was much more painless than anticipated!
It’s all about establishing effective processes to manage this task on an annual basis. It will soon become business as usual, so the burden will reduce year on year. It can be challenging to start with, which is where third-party expertise can help fill the gaps in your knowledge.
[31:35] Martin’s book recommendations – The Coming Storm: Why water will write the 21st century by Liam Fox
[26:35] Martin’s favorite quotes – ‘We don't need 100 perfect activists, but millions of imperfect ones’ – Clover Hogan founder of Force of Nature.
‘Preserve wildlife. Pickle a squirrel.’ – Philosophy from a London bathroom stall.
If you’d like to learn more about Culligan, check out their Website and Linkedin.
If you’d like any assistance with Carbon Verification, feel free to get in touch with Carbonology, they’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Asset Management can be explained as a systematic process of planning, operating, maintaining, upgrading and replacing assets cost-effectively with minimum risk and at the expected levels of service over the assets’ life cycle.
One sector where effective asset management can make a huge difference is public transportation, with organisations having to keep track of an exhaustive list of costly vehicles and infrastructure.
Long time listeners may recall a previous episode where we interviewed the train operator, Greater Anglia, after they successfully achieved ISO 55001, the best practice standard for asset management.
Now 3 years on, they’ve been recently recertified and have learned a lot since their initial certification.
In this episode, Andrew Barnes, Head of Asset Management at Greater Anglia, joins Ian Battersby to discuss how they currently manage their ISO 55001 certification, what they’ve learned in the past 3 years since certification and the benefits of effective asset management.
You’ll learn
· Who is Andrew Barnes?
· Who are Greater Anglia?
· How do Greater Anglia manage their ISO 55001 certification?
· What lessons have been learned since their initial certification?
· What are the main benefits of ISO 55001?
· Andrew’s top tip for ISO Implementation
Resources
· Isologyhub
· Greater Anglia
· ISO Support Plan
In this episode, we talk about:
[02:05] Episode Summary – Ian Battersby is joined by Andrew Barnes, Head of Asset Management at Greater Anglia, to discuss their experience with being certified to ISO 55001 for the past 3 years, explaining the lessons learned and benefits gained.
[03:25] Who is Andrew Barnes? Andy is currently the Head of Asset Management at Greater Anglia. A fun fact that not many people know about him is that he was part of the Lord Mayor’s Show in the 80’s, though he had a bit of a wardrobe malfunction that ended with him getting a stern talking to!
Andy has been working in the railways since 1985, starting as an apprentice with British Rail.
[05:15] Who are Greater Anglia? Greater Anglia are a train operator who took over from National Express, East Anglia back in 2012.
They serve the Anglia region from Liverpool Street Station, and are unusual among railway companies in that they are under a full repairing and insuring lease. This differs from most who have station access conditions, where the responsibility for maintenance and repair is split between Network Rail and the train operator.
They currently operate 134 stations, with 2 more under construction which are Burley Park (due to open in October 2025) and Cambridge South (opening in early 2026).
In addition to the stations, they also own 7 depots for train stabling and maintenance. So in short, a lot of assets to keep track of!
[07:40] Extra asset requirements – They are also now challenged on cleanliness at train stations. This involves mystery shoppers visiting stations and marking them against certain criteria to give a score, which Greater Anglia tend to score quite highly.
They also have to inspect all of their assets on a conditioned surveying scheme, the scores of which need to be communicated to Network Rail.
[09:00] Andy’s role as Head of Asset Management – Andy is relatively new to this role, becoming the Head of Asset Management in April 2025. He has a team of asset inspectors that conduct the condition surveys internally.
He’s also responsible for the Engineer Insurance Team, part of their role is to determine the technical aspects of large schemes that require focused designs.
[10:05] How do Greater Anglia manage their ISO certifications? – In addition to ISO 55001, Greater Anglia also hold ISO 9001 and a number of standards specific to engineering.
They have benefitted from 3rd party support in the form of utilising Blackmores consultancy to help gain certification and aid with on-going support for internal audits.
Their processes and procedures are all managed by their Project Management Team, who conduct regular reviews against ISO requirements to ensure they stay relevant and in alignment with best practice.
They also have a strategic asset management plan, risk register and continuous improvement plans in place to address various elements of both asset management and general quality management.
Like with most ISO Standards, there’s a lot of crossover in the requirements, so elements of each certification can easily be integrated and used to bolster an existing management system.
[11:15] The benefit of a maturing management system – Andy is quite keen on learning from their maturing management system. Through effective implementation, you can look back and see what’s working well and where improvements can be made.
Having a certain level of management system maturity enables you to make more informed continual improvement decisions.
[13:20] A structured approach – Prior to ISO 55001 certification, they were still doing everything that was required of them to maintain assets simply because that was the right thing to do.
What they lacked was the structured processes and procedures to support that hard work. It wasn’t as planned and more of a reactionary approach to asset management.
Andy appreciates the clearly defined lines, processes and ability to learn from their mistakes as a result of ISO 55001 implementation. It simply helped provide a more consistent and collaborative base for effective asset management.
[14:25] Other benefits from ISO 55001 certification:-
Improved efficiency: New and improved processes helped to manage both their time and internal resource. They eliminated unnecessary meetings, and consolidated key discussion points for their regular meet-ups to ensure important updates were prioritised.
Risk Mitigation: They now have a structured approach to learning from past mistakes. This is managed via a Lessons Learned Database, which collates the answers to specific questions that get asked after project completion. They make sure to include contractor input so all parties involved feel the benefits. Recently, they’ve also been granted access to Network Rail’s Lesson’s Learned database, so they will benefit from an even wider knowledge base for future projects.
Consistent approach: Their current management system ensures that everyone is following the same policies, processes and procedures. People know what their responsibilities are, who to communicate what to and how they can help contribute to improvement efforts.
Continual Improvement culture shift: The management system doesn’t require everyone to know everything from the get-go. It encourages a culture of learning with the goal of continual improvement, so people aren’t afraid of suggesting actions for innovation.
[19:45] Lessons learned: Not just from mistakes – Ultimately, from an asset management point of view, Greater Anglia want to maintain or renew an asset as functional and preserve it for as long as possible. They need to intervene as quickly and as efficiently as possible to minimise the impact to people using it.
Minimising the time on site with things like modular construction and hauling large equipment are things we’ve done due to lessons learned from other projects. These were positive changes that we’ve taken on not due to mistakes but simply from trying different things.
A lesson learned doesn’t have to result from a mistake. It’s about learning from both risks and opportunities.
[21:20] Top ISO Implementation tips from Andy –
Do your homework: Have a good understanding of your Management System and take your time to weave it into your day-to-day activities.
A helping hand: Make use of an ISO champion, whether that’s someone internal with ISO knowledge or a 3rd party dedicated ISO consultancy (such as Blackmores) to help you break down an ISO Standard into something you can understand and apply to your way of working.
Recording evidence: Don’t just talk the talk, walk the walk! Once a process or procedure is documented, follow it, and record evidence of this. Same goes for any actions for improvement that are raised, don’t just let it sit there, action it.
[23:45] Andy’s take away from ISO 55001 management – Andy is surprised by how attuned their business is to the Standard. The Standard speak may seem obtuse or vague, but its adaptability is it’s greatest strength. You have the flexibility to apply it in a way that works for your business.
[25:15] Andy’s book recommendations – 1984 by George Orwell and Adolf Hitler: My part in his downfall by Spike Milligan.
[26:35] Andy’s favorite quote – ‘By Failing to prepare, you’re preparing to fail’ – Benjamin Franklin
If you’d like to learn more about Greater Anglia, check out their Website and Linkedin.
If you’d like any assistance with ISO 55001 Asset Management, feel free to get in touch with us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO certification is more than just earning a certificate, and it requires continuous maintenance to both retain certification and drive effective improvements.
Over the course of your 3-year certification cycle, you will need to ensure your Management System is regularly updated and reviewed so that it remains relevant to the way you’re currently working. That in addition to annual tasks such as internal auditing and management review, it can be a lot to keep on top of.
Which is why some turn to external ISO Support.
In this episode, Steph Churchman explains what ISO Support is, the challenges of managing ISO internally and the benefits of external support.
You’ll learn
· What is ISO Support?
· What tasks can you outsource
· Challenges of managing ISO internally
· What are the benefits of ISO Support?
Resources
· Isologyhub
· ISO Support Plan
In this episode, we talk about:
[02:05] Episode Summary – Steph explains what is meant by ISO Support, explains the challenges with managing ISO internally and the benefits of engaging in external support.
[02:20] What is ISO Support? ISO certification involves a 3-year cycle, where you will be subjected to an annual Surveillance audit by your certification body. On year 3, you will need to undertake a recertification audit, which will determine if you can keep your ISO certification.
During that cycle, you will be required to complete annual tasks such as internal auditing, documentation updates and management review to ensure that your management system is effective in driving continual improvement.
ISO Support is a service provided by an external party to help facilitate the management of these annual tasks, usually undertaken by a dedicated ISO consultancy.
[03:40] What tasks can be outsourced? To learn about what tasks can be outsourced, check out a previous episode.
[03:55] ISO Management Challenge #1: Internal auditors not being comfortable about auditing their peers - It may be the case that certain individuals do no get on, however if someone manages a key process or area of the business, they still need to be audited.
There’s also the chance for auditors to be misunderstood, or have trouble getting the answers they need from auditees. Auditing requires the ability to effectively communicate and make yourself understood. It’s quite common for auditees to ask for further clarification on questions asked, so you need to be able to work with them so that they understand what you’re really asking.
[04:45] ISO Management Challenge #2: Internal auditors not being particularly objective or impartial when auditing leadership – It can be hard to be impartial towards leadership, even if it is ultimately in their best interest! These dynamics can be habitual, but by not pointing out genuine issues or opportunities for improvement, you dimmish the purpose of the exercise.
This also involves any leadership being receptive to feedback given. If this hasn’t been taken well in the past, it’s understandable for individuals to be hesitant doing so again, even if it’s a necessary part of the process.
[05:35] ISO Management Challenge #3: Fed up with paying for training for a high turnover of internal auditors - Internal Auditing will require a qualification, which will cost money. It’s not a tremendous amount for these courses, but it would be an extra thing to budget for, and then there’s factoring the time to complete the course which takes away from that individuals other responsibilities.
It can also be frustrating when your only Internal Auditor moves on and so you have to train another. Depending on the business, this could happen quite frequently and so ends up being a repetitive expense.
You will also need to ensure any current auditors are competent to audit against any new ISO Standards that you may add along the way.
[06:35] ISO Management Challenge #4: Managers not having time to update processes - Your Management system is likely owned by either just 1 individual or by a small team within the business. Those involved will already have their plates full with day-to-day operations, and anything ISO related is just another task to add onto that pile. In the eyes of many, they may seem unimportant in comparison, and will continually get shuffled down the priority list until it’s time for a Surveillance Audit.
There will also be a certain amount of documentation to review and update on a regular basis. Even those with mature systems can experience trouble with duplicated processes, or confusion with old versions, and finding the time to sit and refresh all of that is often hard to accomplish.
[07:30] ISO Management Challenge #5: Managers not aware of their legal, regulatory or ISO Standards requirements - As ISO Standards lay out best practice, they do require businesses to be aware of and adhere to relevant legislation and regulations. Managers will likely not be an expert in ISO Standards or legislation, so it can be easy for things to get missed if they’ve not had sufficient training beforehand.
It will take time for relevant individuals within a business to be trained, or complete CPD to be fully competent to ensure full ISO and legal compliance.
[08:25] ISO Management Challenge #6: Not updating key information i.e. Risk Register, BCP’s, environmental/energy metrics - Monitoring and measuring is a big part of ISO Management. You need to document certain metrics if you want to track them effectively.
You will also need to update key documentation, as nothing stays the same forever. Major business changes may prompt updates to key policies and procedures. You may have opportunities to improve that fall out of audits that require certain documentation to be updated. Or correcting things where non-conformities have been raised.
These updates are necessary to keep the momentum of a management system going. It needs to grow with you, which it will fail to do if everything documented is only applicable to how your business operated a few years ago.
[09:15] ISO Management Challenge #7: Not reviewing key information i.e. Objectives, Environmental/H & S/Data Security trends - Objectives is another key metric that should be reviewed on a regular basis. To not only establish if you are making progress with them, but also to possibly adjust if the original plans were too lofty. They should still be a challenge to obtain, but we’re all only human and sometimes our first estimates about what’s achievable might be a tad too ambitious.
There is also a need to review audit results to see if there’s any trends in areas such as info sec, sustainability and risk. This could be opportunities for improvement or some reoccurring issues that need to be addressed.
All of this monitoring is going to require dedicated time from relevant personal, including feeding back results and following through with further actions.
[10:55] ISO Support Benefit #1: Expertise and Specialisation - Dedicated ISO consultants will keep you up-to-date with the latest standard revisions, interpretations, and best practices. This includes their experience with helping businesses to plan and conduct annual maintenance.
They are there as a guiding hand and can be a great sounding board for you if you have questions surrounding ideas or actions that you’re unsure about.
Their help ensures your system is maintained effectively and most importantly, compliantly.
[11:40] ISO Support Benefit #2: Cost Savings - While there's a fee for outsourcing, it’s often more cost-effective than maintaining an in-house team or dedicating significant internal resources.
As mentioned earlier, you would need qualified internal auditors at the very least, this will require training costs. You also need to consider the time taken out of individual’s typical working schedule to be able to conduct annual ISO maintenance, this will take away from their day-to-day tasks.
We took this into consideration when creating our ISO Support Plan option, which is a 3-year contract that allows you to stay at a fixed rate for those 3-years. It’s a set it and forget it approach to ISO Support, which is flexible on both the number of days required annually in addition to the tasks you’d like support with.
[12:35] ISO Support Benefit #3: Reduced Workload for Internal Staff - It’s often the case that Individuals, especially in SMEs, often wear many hats. Adding ISO maintenance onto that will impact on their day-to-day activities. Outsourcing frees up their time and resources, allowing them to focus on core business activities rather than the complexities of ISO maintenance.
A lot of people don’t take training into consideration for people who get handed the task of maintaining a management system.
It’s a lot of unnecessary stress when they’ve likely already got enough on their plate. Outsourcing will take a lot of that burden away, and give them a chance to lean on consultant guidance and be able to learn how to manage the tasks without fear of jeopardising the company’s certification.
[13:30] ISO Support Benefit #4: Impartiality and Objectivity - An external consultant can offer an unbiased perspective on your management system's performance, identifying areas for improvement that might be overlooked by internal staff due to familiarity, bias or ingrained practices.
A fresh pair of eyes can provide a lot of valuable insight, in addition to their lessons learned from other clients. It also helps to have another unbiased voice on your side if you have suggestions for improvement that need presenting to leadership.
It should also be noted that impartial audits are a requirement of ISO Standards, this is so you’re not marking your own homework all the time. It’s another level of assurance that you are doing what you say you’re doing.
[14:20] ISO Support Benefit #5: Continuity and Risk Mitigation - Employee turnover can disrupt internal ISO maintenance.
Outsourcing provides continuity, as any external provider will be available for the duration of an agreed contract, there’s no ambiguity on how long you have their support for. They will help you plan out what needs to be done, and facilitate this with the relevant individuals within your business.
[15:00] ISO Support Benefit #6: Improved Efficiency and Effectiveness - External specialists will have the experience to help streamline processes and tools for maintenance activities. Making the system and it’s running more efficient, leaving you with more time to implement worthwhile changes that reap tangible results.
Having their guidance from the start means you’ll be hitting the ground running. At Blackmores, we ensure that annual activities are planned out in advance so everyone can be prepared and work on a consistent schedule.
[15:40] ISO Support Benefit #7: Enhanced Compliance and Audit Readiness - Outsourced consultants are going to be more adept at ensuring the system remains fully compliant with ISO standards. As they can proactively identify and address non-conformities that could easily be missed by those with significantly less auditing experience.
There is a level of experience that is tricky to achieve if you do not regularly conduct internal audits. Consultants know what to look for, and will often have significant industry experience to know what stones to unturn to find issues and opportunities.
Afterall, that is the purpose of internal audits, to not only check that process, policies and procedures are being followed, but to seek out where you can be doing better, or fixing issues as your business changes and adapts.
[16:40] ISO Support Benefit #8: Focus on Core Business Activities - By offloading the burden of ISO maintenance, you can re-allocate your focus and resources to core business activities and strategic initiatives. ISO Consultants can take a lot of the mental burden of managing ISO systems away.
There will still be homework to do on your side, as ultimately, you know how your business works best, but a consultant will guide you through what needs to be done.
We know that many of you tasked with ISO compliance in your business have another primary role that requires a lot more of your attention. So make it easier on yourselves with the help of an expert, so you can get on and do what you need to do with minimal interruption.
[17:30] ISO Support Benefit #9: Potential for Scalability and Flexibility - Outsourced services can often be scaled up or down based on the business's needs, offering flexibility that an internal team might not be able to provide, especially during periods of growth, crisis or during large projects.
ISO Consultants can help either pick up the slack or give you more of the rope to handle annual ISO maintenance depending on what you need or want.
At Blackmores, we have an ISO Support Plan that can be tailored to your exact needs, including the options to complete tasks such as:-
· Conducting impartial internal audits
· Providing surveillance support
· Updating legal registers
· Documentation updates
· Conducting annual management reviews
With 3 levels of support available, we have no issue with you increasing or decreasing days required each year, or varying the tasks depending on where you need the most support.
If you’d like any assistance with ISO Support, feel free to get in touch with us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO Standards are often a must have due to stakeholder requirements, whether that’s from your customers, investors or regulators.
The need for multiple ISO certifications is also becoming more common, which can become a tricky task to juggle if you’re managing these as separate systems. The solution? An Integrated Management System.
In this episode, Steph Churchman explains what an integrated management system is, how the Annex SL format facilitates integration and the benefits and challenges involved with an IMS.
You’ll learn
· What is an Integrated Management System?
· Why consider an IMS?
· What is the Annex SL format?
· What are the benefits of an IMS?
· What are the challenges of implementing an IMS?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Steph explains what an Integrated Management System is, how the Annex SL format makes this possible and dives into the benefits and challenges associated with an IMS.
[02:20] What is an Integrated Management System? Often abbreviated to ‘IMS’, it simply refers to a management system based off certification to or alignment with multiple ISO Standards.
For example, a company may be certified to ISO 9001, ISO 14001 and ISO 45001 but will only have 1 Management system rather than 3 sperate systems.
[03:30] What is the Annex SL format? The Annex SL format was applied to most ISO Standards back in 2015. This format helped to create a consistent 10 clause structure which makes it simple to integrate multiple ISO Standards.
Before this was introduced, not all Standard clauses aligned, making it difficult to audit against and combine with other Standards, even if they had similar requirements.
[04:00] The Annex SL 10 Clause Structure explained:–
· The first 3 clauses are explanatory clauses. These give you more context for the purpose of the standards, as well as providing a helpful glossary of terms and definitions that you’ll come across in the Standard. These clauses aren’t audited against
· Clause 4 - Context of the Organisation: This is where you’ll be establishing your scope, your interested parties and looking at where your risks and opportunities are. It’s setting the foundation for your Management system.
· Clause 5 Leadership: This is where you’ll need commitment from top management. They will need to be involved with tasks such as establishing key policies, assigning roles & responsibilities and communicating the Management System once you’re ready to launch it.
· Clause 6 Planning: This is where you will look at the risks and opportunities raised during the context phase and plan what actions you’ll take to address them. This is in addition to setting your business objectives.
· Clause 7 Support: This is where you will establish the resources you have available to create and facilitate the running of the Management system. This clause gives you guidance for considerations such as people, infrastructure, monitoring and measurement needs, competence of staff and key communication requirements.
· Clause 8 Operation: This clause is where the main differences can be found between ISO Standards. It provides guidance on considerations for key processes and procedures relating to the Standard focus. ISO 9001 for example contains a rather chunky clause 8 as it details requirements for products and services, including the development and provision of them. While ISO 27001’s clause 8 focuses more on information security risk assessments and risk treatment plans.
· Clause 9 Performance Evaluation: This is where you establish the who, what and when involved in the monitoring, measurement and evaluation of your management system. This is also where Internal Auditing requirements are detailed.
· Clause 10 Continual Improvement: This is the driving force of all ISO Standards. In this last clause you’ll find requirements for Management review and non-conformity and corrective action. That’s simply about reviewing the effectiveness of the Management system and putting plans in place to correct any non-conformities raised, or act on any of those opportunities for improvement.
[08:00] IMS Benefit #1: Cost Saving – ISO Implementation can get costly, especially if you’re investing in a consultancy to help you in addition to the certification body costs involved in the actual assessment.
You can save money by implementing multiple standards at the same time. At Blackmores, we’re happy to help you implement multiple ISO’s at the same time. This saves on the time spent if you were to do them separately, as we typically combine elements of the selected standards in project days such as during a Gap analysis, document creation and internal audits.
On the certification body side, you can save on assessment days by assessing against an integrated management system, rather than assessing against 2 separate management systems. Many will do their best to accommodate integrated assessment and surveillance audits.
[09:05] IMS Benefit #2: Reduced Duplication and Increased Efficiency - There are elements of a Management system that you can combine to not only save money but also reduce document and process duplication, which leads to a more efficient system.
We’ve seen companies trying to manage separate systems over the years, and often times they end up just causing confusion, or only being adhered to by specific departments within a business. This results in duplicated work as shared elements of compliance are being managed in two different ways, often with slightly different styles of documents.
Save yourself the trouble and headache by integrating all relevant management system documentation into 1 system. It makes it so much easier to update and keep on top of, and to enable it to act as a real tool for continual improvement rather than being thought of as a chore to upkeep.
[10:10] IMS Benefit #3: Improved Communication and Collaboration - An integrated system encourages communication between all elements of your business.
This holistic approach is often broken down into silos for select departments to focus on select objectives, which in turn encourages invested teamwork which will contribute to the business’s success as a whole.
Internal Audits will also allow employees from every level to feedback to the system, highlighting key areas for improvement that could be rolled out. We see a lot of companies leveraging integrated management systems in various ways, often using them as a springboard to launch company wide initiatives that encourage further collaboration.
These are then tracked, monitored and reported on in a similar way to other company objectives, all guided by the processes put in place by the Management system.
[11:20] IMS Benefit #4: Enhanced Risk Management - Integrating multiple Standards will mean you have greater comprehension and risk assessment of multiple different aspects across your business, such as quality, environmental and Health & Safety.
Many start with ISO 9001, as that’s a fantastic solid foundation for a Management system, it builds in all the core policies and procedures needed to run a business smoothly, but it doesn’t touch on the specifics of environmental management or information security. For that, you’d need to integrate other standards to ensure you have robust measures to tackle those other elements.
[12:15] IMS Benefit #5: Streamlined Auditing Processes - Internal Audits act as a good measure of where things are going right and wrong, in addition to being a dummy run for your certification assessment if it’s your first time going through the process.
Internal Audits are also an element which can be combined, this allows you to save time for the auditees, which reduces the amount of disruption they may cause overall. It also reduces the overall amount of audit reports for review, saving a duplication of effort on auditing similar elements across multiple standards.
[13:00] IMS Benefit #6: Better Decision-Making - By having a more unified view of all processes and performance across different management areas, leadership can make more informed decisions.
ISO Standards require a Management Review, which is where you can review audit findings and put plans in place to resolve any non-conformities and address any opportunities for improvement. Don’t forget to highlight any achievements and lessons learned too! As these can be applied elsewhere in the business.
[14:00] IMS Benefit #7: Increased Stakeholder Confidence - ISO Standards are a mark of best practice, they are an internationally recognised seal of approval that proves your commitment to either quality, safety and sustainability.
This competitive advantage will also serve you when going for funding or to tender.
[14:40] IMS Benefit #8: Improved Organizational Performance and Culture - An integrated Management system ensures that everyone is unified in their way of working. It also fosters a culture of continual improvement, that encourages participation from all levels within the business.
Having a central integrated system makes things simple for everyone to understand. No one has to search out different processes for a separate quality and environmental management system, when they could all be combined and stored in 1 location.
An integrated management system approach also allows for you to collaborate across multiple different focus areas such as quality, safety and sustainability. Objectives for each can be siloed and focused on by select departments, but can still be contributed to from any part of the business.
Be open about the results in different areas of the business and encourage suggestions for improvement, this is how you’ll foster a culture of continuous Improvement.
[16:05] IMS Challenge #1: Initial set-up and resourcing - Implementing ISO Standards aren’t a small task. If you’re implementing multiple ISO Standards from the start, you’ll need to consider the people, time and expertise needed to complete the task.
This may include the assistance of a dedicated ISO consultancy, as they’ll have the expertise to guide you through the process smoothly. At Blackmores, we can help you implement an IMS that is bespoke to the way you work. It may be tempting to go with an out of the box solution, but these would need tailoring to be at all effective and likely won’t get you past certification with a UKAS accredited Certification Body.
Learn about the differences between a UKAS and Non-UKAS accredited Certification Body on one of our previous podcasts.
[17:30] IMS Challenge #2: Resistance to change - People will be used to working a certain way, often siloed into systems unique to their departments. Or if you’ve already held 1 ISO certification, integrating others will mean change to that existing system that others may not be open to at first. It will involve either new or updated policies and procedures that will take some time for everyone to adapt to.
The key here is communication. Not only to communicate the change, but allow people to voice any concerns they have about new ways of working. You may also need to issue additional training to help others adapt.
[18:20] IMS Challenge #3: Lack of top leadership commitment - If you want people to care about the management system, commitment to it needs to come from the top down. If the leadership doesn’t care about it, why should anyone else?
Any good leadership should want a holistic approach for monitoring various elements of the business, if only to make more informed decisions. An integrated Management system can provide the base to facilitate this, and it’s in leaderships best interest to keep ahead of any emerging challenges or opportunities that can be leveraged.
[19:10] IMS Challenge #4: Integration of IT systems and data - Integrating your management system may require the integration of IT systems and existing data. If you have separate management systems currently, they may be operating on different databases or formats that may be difficult to combine.
In some cases, an integrated management system is a good opportunity to refresh the way you work, it could be seen as a chance to look at other tech options out there that could be more cost effective or introduce new much needed functionality.
[19:50] IMS Challenge #5: Maintaining Scope and Avoiding Over-Complication - There is a risk that you may try to bite off a bit more than you can chew when integrating management systems.
We recommend starting with a smaller scope, as this acts as a good test that can be rolled out to the wider business if it’s effective. Many may start with just one site and then seek to roll out the changes to the wider business over the course of a few years.
This is definitely an approach we encourage, as each location will have its own teething problems to work through, which is much more manageable when tackled in chunks at a time rather than all at once.
If you’d like any assistance with Integrated Management System Implementation, feel free to get in touch with us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The process approach is recommended by all Management System Standards, and effective implementation is key to drive continual improvement.
Processes outline the basic steps needed to complete a task or achieve a certain outcome, and serve to keep things running smoothly and consistently. For those new to ISO Standards, it can be quite daunting to understand what this means in practice.
In this episode Ian Battersby explains what a process is in the context of Management systems, how to map processes and the different ways you can visualise a process for communications.
You’ll learn
· What is a Process?
· Why are processes needed in Management Systems?
· Why should you document your processes?
· How do you map a process?
· How can you display a process?
Resources
· Isologyhub
· ISO 9004
In this episode, we talk about:
[02:05] Episode Summary – Ian explains the importance of processes in Management systems, how you can effectively map processes and how you can visualise them for further communication.
[03:00] Why are processes so important for Management Systems? As ISO 9004 (Quality management - Quality of an organization - Guidance to achieve sustained success) states:-
“Organisations deliver value through activities connected within a network of processes. Processes often cross boundaries of functions within the organisation. Consistent and predictable results are achieved more effectively and efficiently when the network of It processes functions as a coherent system.”
It doesn’t propose a type of process. All organisations are different. But what it does say is that they should be viewed as a system rather than in isolation.
It’s a key principle of Quality Management and of business, allowing an organisation to manage and control the way it delivers its activities, with predictable results.
[05:30] What is a process? Put simply, a process is a set of activities which achieve a specific outcome. Or, to put it another way, it’s a series of detailed steps describing how to do a job.
[05:40] We should you document your processes?:
· To show how to repeat tasks consistently, getting the same result every time
· It guides people in how to do their jobs
· To allow you to measure that outcomes are as expected
· To provide for a structured approach to improvement
· To help mobilise new contracts, products services of a similar type which supports business growth.
[08:15] How to map a process – There are many different ways you could do this, but a popular method is with process map or process flow.
A process map is a series of boxes on a page or screen. Each box represents an activity. The activities are then linked in a sequential order, using arrows.
As an example, let’s say you have a process which repeats a task until you get the right outcome. The first box would be ‘Start job’, this then points to the next box called ‘Perform task’. In turn this points to a third box, which is a question, ‘Did it achieve the desired outcome?’.
This would lead to two options: yes and no. So. there are two arrows out this time. If no, we need to learn from it (another box). When we learn from it, we point back to ‘Perform task’. If yes we end the job, which would be another box.
Using a diagram such as this, it makes it a lot easier to visualise and follow a process. Many processes will likely be more complicated than this example, but the principle remains the same.
[11:40] Keep things simple – Ian’s had experiences of companies that insist on bloated process maps that contains hundreds of boxes and arrows that end up making the whole diagram very difficult to follow. This defeats the purpose of process mapping.
If you have a lot of complicated processes, it’s better to break these down into manageable chunks.
[12:30] Process overview: If you’re struggling to start, you may want to consider a process overview. This focuses on the main steps on how you run your organisation, so this could be marketing, sales, production and delivery services.
From there you can look at each area and focus on the more detailed activities which can be mapped and linked to each other.
The ones dealing with the process overview include subject matter experts, departmental heads, functional leads, Senior Management ect…
They will help shape the process mapping to ensure the overall delivery is in-line with the organisations’ direction.
[14:00] A collaborative task: Process mapping shouldn’t be done by one person. One person is hardly going to know how each and every aspect of your organisation works.
Don’t just leave it to your Quality Manager. Leaving this task to someone who’s not fully involved in the part of the organisation where the process originates will only end in disaster.
They will likely not be aware of small yet vital steps, such as key communication and authorisations.
So make sure you involve multiple parties, and key people involved in the areas you’re mapping process for.
[17:05] Process mapping across departments: Think practically about how you deliver products or services. How people actually do their jobs. This is a very important aspect of processes.
Then visualise how each process works: draw it with pencil and paper; throw some Post It notes on a flipchart; put it on a whiteboard and take a photo; even write it out in a Word document. Make it clear.
Make it documented: This is essential. This unleashes the power to measure and improve. Documenting something allows you to compare the way things are done to what you expect and to establish whether the outcome is as you expect.
[12:30] How processes link with other areas of ISO Standards: Processes are very useful in helping people do their job, but they can also assist with:-
Assigning roles and responsibilities.
Each box (activity) can be measured for success, performance indicators can be established at individual activity level, or for a process overall. You can see if the process is successful in delivering its intended outcome. The results can then form part of your monitoring and measuring regime as required by Management System standards (clause 9 is all about evaluating performance).
You can use them as a basis for audit, which is all about assessing whether you get what you expect.
They are also useful in explaining how you deliver to external parties; or demanding how others should do things.
Standards also specify that process performance be included in Management Review (9001 9.3.2 c) 3)) – so it really is an unavoidable step towards ISO certification!
Lastly, it can also help with clause 10, which is all about improvement. What-if scenarios can be performed by moving activities, lines, adding new ones deleting and predicting the outcome of the overall process.
Whichever way you wish to document your processes, by documenting them you have the power to improve them
If you’d like any assistance with ISO Implementation, feel free to get in touch with us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We’re past the point of simply saying you’re committed to sustainability, it’s time for tangible and verified action.
This is what many are calling for in response to the recent rise in Greenwashing and subsequent erosion of trust from consumers and other stakeholders regarding any green claims.
As a result, a number of voluntary disclosure schemes have been created to help benchmark and verify organisation’s claims, should they choose to participate. One example being the focus of today’s episode: EcoVadis.
In this episode Mel Blackmore continues with our voluntary disclosure’s series, discussing the ESG rating scheme EcoVadis, what is required to earn a Platinum rating and provides some tips on how to get that Platinum rating.
You’ll learn
· What is EcoVadis?
· What are the requirements to achieve a Platinum rating?
· Top tips for earning an Platinum rating for EcoVadis
· What are the advantages of earning a Platinum rating?
· What are the disadvantages of getting involved with EcoVadis?
Resources
· EcoVadis
· Carbonology
· Contribute to Mel’s carbon verification commitment research by taking her Survey
In this episode, we talk about:
[02:05] Episode Summary – Mel discusses the voluntary disclosure scheme: EcoVadis, including what’s involved with taking part, how to achieve a Platinum rating and the pros and cons of being benchmarked.
[03:00] Why is there a need for EcoVadis? An increased number of investors and financial institutions, in addition to clients are demanding more than just financial reports. They want to know what a company's environmental footprint is, and at this point, it's time to move on beyond simply making pledges.
This extends to other elements of governance as EcoVadis doubles as a crucial ESG rating scheme.
[04:30] What is EcoVadis? EcoVadis is a globally recognised provider of business sustainability ratings. They assess companies' environmental, social, and ethical performance across 21 indicators and four main themes: Environment, Labor & Human Rights, Ethics, and Sustainable Procurement.
EcoVadis aims to help organisations manage their supply chain sustainability risks and opportunities. If you're a supplier, you've likely received a request from a customer to complete an EcoVadis assessment.
The assessment process involves completing a detailed questionnaire, submitting supporting documentation, and then EcoVadis analysts review your submission and assign a scorecard. This scorecard provides a detailed breakdown of your performance across the four themes and assigns an overall score and a medal status: Bronze, Silver, Gold, or Platinum.
It’s this medal status that’s crucial, especially those coveted Gold and Platinum badges, which signal to your customers that you are a top-tier performer in sustainability.
[05:40] We want to hear from you: Mel is currently running some research around CDP and the key drivers behind carbon emission verification, and would appreciate your feedback if you have a few minutes to spare.
The results are completely anonymous, and it should only take 5 – 10 minutes. You can take the survey here.
Thank you in advance to any contributors!
[06:05] What is required to achieve an Platinum Rating? – While EcoVadis assesses across four themes, the 'Environment' theme often carries significant weight, and within that, greenhouse gas (GHG) emissions management is paramount for the higher ratings.
To earn an EcoVadis Platinum rating, you'll generally need to achieve an overall score between 78-100 out of 100. Key areas that you need to excel in include:-
1) Comprehensive Environmental Management System: This includes policies, actions, and reporting on a wide range of environmental issues. For Platinum, EcoVadis expects to see highly structured and systematic approaches to environmental management.
2) Robust GHG Emissions Management: For this you need to:
· Measure your GHG Emissions: Accurately calculate your Scope 1, Scope 2, and significant Scope 3 emissions. EcoVadis places increasing emphasis on Scope 3, as it often represents the largest portion of a company's footprint.
· Set Ambitious Targets: Have clear, quantitative targets for GHG emission reduction. Aligning these with a science-based target (SBTi) is highly advantageous and often a de facto requirement for Platinum.
· Implement Reduction Initiatives: Demonstrate concrete actions you are taking to reduce emissions, such as investing in renewable energy, improving energy efficiency, optimizing logistics, or engaging your supply chain.
3) Independent Verification of GHG Emissions Data: This is a non-negotiable for Platinum and often for Gold. EcoVadis awards significant points for having your Scope 1 and Scope 2 GHG emissions (and increasingly, relevant Scope 3 categories) independently verified by a third-party accredited body. This provides assurance that your reported data is accurate and reliable. As a CDP accredited verification body, we routinely help companies through this process, and it makes a profound difference in their EcoVadis and overall ESG scores.
4) Strong Policies and Actions Across All Themes: While we're focusing on environment, remember Platinum requires excellence across all four EcoVadis themes:
· Labor & Human Rights
· Ethics
· Sustainable Procurement
Implementing Standards such as ISO 37001 (Anti-Bribery and Corruption), ISO 27001 (Information Security), ISO 20400 (Sustainable Procurement) can help put some of these in place.
5) Effective Reporting and Transparency: You need to clearly articulate your policies, actions, and performance data within the EcoVadis questionnaire. This includes providing high-quality, relevant supporting documentation. To get the best result, don't just tick boxes; provide evidence!
6) Continuous Improvement: EcoVadis looks for evidence of ongoing improvement. It's not a one-off assessment; it's about demonstrating a commitment to continually raising your standards.
[14:20] How to get an EcoVadis Platinum Rating with verified data? – Here’s a few tips:
· Start Early and Plan Strategically: Don't wait until the last minute. The EcoVadis assessment requires significant time and effort. Plan your data collection, policy development, and verification process well in advance.
· Understand the EcoVadis Methodology: Download the EcoVadis methodology and scoring criteria. These double as guidance documents that explain what they're looking for in each section. Tailor your responses and documentation accordingly.
· Invest in carbon accounting software: Accurate and consistent data is paramount. Implement systems (whether software or well-organized spreadsheets) to track your energy consumption, waste, water use, and especially your GHG emissions.
· Prioritize GHG Emissions Verification: Engage a reputable, accredited third-party verification body (like Carbonology 😉) to audit your Scope 1 and Scope 2 GHG emissions. Ensure the verification covers the reporting period relevant to your EcoVadis assessment. This provides the external assurance EcoVadis demands.
· Address All Four Themes: While environmental performance is crucial, don't neglect Labor & Human Rights, Ethics, and Sustainable Procurement. A weak score in one area can pull down your overall rating.
· Leverage External Expertise: If you're new to EcoVadis or aiming for a significant jump in your score, consider consulting with experts. They can help you identify gaps, optimize your strategy, and ensure your documentation meets EcoVadis's requirements. Blackmores consultants are able to provide support if you’re seeking an EcoVadis rating.
· Continuous Improvement: Use the EcoVadis scorecard feedback to identify areas for improvement. Implement corrective actions and integrate them into your ongoing sustainability strategy. This commitment to continuous improvement is a strong indicator of a Platinum-level company.
[16:40] The pros and cons of EcoVadis: Many of these share similarities with the Carbon Disclosure Project, which we covered in a previous episode. To summarise:
Pros:
· Enhanced Reputation and Brand Value
· Risk Management and Resilience
· Cost Savings and Operational Efficiency
· Competitive Advantage
· Innovation and Strategic Planning
· Benchmarking and Peer Learning
Cons:
· Resource Intensive
· Potential for Negative Public Scrutiny
If you’d like any assistance with carbon verification, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In recent years there has been a growing need for transparency within sustainable action taken by businesses.
This is due to the rampant increase in greenwashing, which only serves to diminish the focus on genuine efforts, in addition to creating a culture of mistrust within stakeholders and consumers.
To combat this, certain organisations have taken on the task of encouraging and supporting the accurate public disclosure of environmental data. Such is the case with today’s focus, the Carbon Disclosure Project (CDP).
In this episode Mel Blackmore discusses what the Carbon Disclosure Project is, what is required to earn an A rating, provides some tips on how to get that A rating and explains the pros and cons with getting involved with the project.
You’ll learn
· What is the Carbon Disclosure Project?
· What are the requirements to achieve an A rating?
· Top tips for earning an A rating in the CDP
· What are the advantages of earning a CDP rating?
· What are the disadvantages of getting involved with the CDP?
Resources
· Carbon Disclosure Project
· Carbonology
· Contribute to Mel’s carbon verification commitment research by taking her Survey
In this episode, we talk about:
[02:05] Episode Summary – Mel discusses the Carbon Disclosure project, including what’s involved with taking part, how to achieve an A rating and the pros and cons of the project.
[03:00] Why is there a need for the CDP? An increased number of investors and financial institutions, in addition to clients are demanding more than just financial reports. They want to know what a company's environmental footprint is, and at this point, it's time to move on beyond simply making pledges.
Ultimately, key stakeholders are looking for a commitment to sustainability and for accessible information to help them understand how an organisation is managing its climate risks and opportunities. This is where CDP comes in.
A key component of getting the coveted A rating within CDP involves independent verification of greenhouse gas emissions.
[04:45] What is the Carbon Disclosure Project? CDP is a global non-profit that runs the world's leading environmental disclosure system. For over two decades, it has revolutionized how companies, cities, states, and regions report their environmental impacts. They ask thousands of organizations to disclose data on climate change, water security, and deforestation. This data is then used by investors, purchasers, and policymakers to make informed decisions.
The CDP questionnaire covers a wide range of topics, from governance and strategy to risk management, targets, and of course, greenhouse gas emissions. Companies receive a score from D- to A based on the completeness of their reporting, their level of awareness of environmental issues, their management of those issues, and ultimately, their leadership in addressing them.
[05:40] We want to hear from you: Mel is currently running some research around CDP and the key drivers behind carbon emission verification, and would appreciate your feedback if you have a few minutes to spare.
The results are completely anonymous, and it should only take 5 – 10 minutes. You can take the survey here.
Thank you in advance to any contributors!
[09:10] What is required to achieve an A Rating? – There are a number of key requirements, including:-
Comprehensive Disclosure and Data Quality: This is foundational. You need to provide accurate and complete data across all relevant sections of the CDP questionnaire. This includes detailed information on your Scope 1, Scope 2, and increasingly, your Scope 3 GHG emissions.
Strong Governance and Strategy: CDP looks for clear evidence that environmental issues are integrated into your company's core business strategy and that there's robust board and management oversight of climate-related matters. This means having a defined climate strategy, understanding your climate-related risks and opportunities, and demonstrating how you're incorporating these into your financial planning.
Verified Data: To truly hit that "A" list, your Scope 1 and Scope 2 GHG emissions, and a significant portion of your Scope 3, must be independently verified. This isn't just a suggestion; it's an essential criterion for the leadership level. Independent verification provides crucial assurance to stakeholders that your reported emissions data is accurate, reliable, and trustworthy. It also minimises the risk of “Greenwashing”.
Science-Based Targets and a Robust Climate Transition Plan: CDP is increasingly emphasizing the need for companies to set ambitious, science-based targets for emissions reductions, aligned with a 1.5°C global warming scenario. In addition, having a publicly available, credible climate transition plan that outlines how you will achieve these targets, including specific actions, metrics, and progress tracking mechanisms, is now a must for "A" list companies.
Value Chain Engagement: For many companies, the most significant emissions lie within their supply chain. To achieve an "A" rating, you'll need to demonstrate robust engagement with your suppliers to measure and reduce their emissions, and address environmental impacts across your entire value chain.
Continuous Improvement and Transparency: The "A" rating isn't a one-off achievement. It reflects a commitment to continuous improvement in your environmental performance and a willingness to be transparent about your journey, including challenges and successes.
[15:05] Top tips for achieving a CDP A Rating:-
Tip 1: Plan Ahead and Start Early. CDP reporting is an annual cycle, and it's complex. Don't wait until the last minute! Start gathering your data, assessing your internal processes, and identifying any gaps well in advance. This includes planning for your verification process.
Tip 2: Invest in Robust Data Management Systems. Accurate and comprehensive data collection is paramount. Consider leveraging sustainability software that can help you track, calculate, and manage your GHG emissions data efficiently. This reduces manual errors and streamlines the reporting process.
Tip 3: Understand the Verification Process. This is where an accredited verification body, like Carbonology, becomes invaluable. Verification Bodies work to an internationally recognized standard, typically ISO 14064-3, to ensure the accuracy and reliability of your GHG emissions data. The process involves:
· Defining the scope: What emissions are being verified?
· Data review: Examining your underlying data, methodologies, and calculations.
· Site visits (where applicable): Physically verifying operational data.
· Report generation: Providing an assurance statement on the accuracy of your emissions.
Tip 4: Engage with a CDP-Accredited Verification Body. CDP specifically requires third-party verification from an independent external organization that is accredited and competent. Look for bodies with proven experience and accreditation to international standards like ISO 14064. They can guide you through the process, identify areas for improvement, and ensure your data meets the stringent requirements for leadership points.
Tip 5: Conduct a Gap Analysis. Before you even begin your disclosure, perform a thorough gap assessment against the latest CDP questionnaire and essential criteria. This will highlight areas where your current disclosures fall short and allow you to address them proactively.
Tip 6: Focus on Quality over Quantity. While comprehensive disclosure is important, ensure the quality and accuracy of your data. It's better to provide high-quality, verified data for a focused set of emissions than to report broadly with unverified or unreliable numbers.
Tip 7: Train Your Team. Ensure your internal team understands the CDP requirements and best practices for sustainability reporting and data collection. Building internal capacity is essential for maintaining high-quality disclosures year after year.
[20:35] The pros of voluntary disclosures:
Enhanced Reputation and Brand Value: Disclosing and performing well on platforms like CDP showcases your commitment to environmental responsibility. This can significantly boost your reputation among customers, employees, and the wider public, attracting conscious consumers and talent.
Risk Management and Resilience: The disclosure process forces companies to identify and assess their environmental risks – from climate change impacts to resource scarcity. This proactive approach allows for better risk mitigation strategies, building greater business resilience.
Cost Savings and Operational Efficiency: The process of measuring and managing environmental impacts often reveals opportunities for greater efficiency, such as reduced energy consumption, waste reduction, and optimized resource use, leading to tangible cost savings.
Competitive Advantage: Being a leader in environmental transparency can differentiate your company in the marketplace, especially as sustainability becomes a key consideration for clients and supply chain partners.
Competitive Advantage: Being a leader in environmental transparency can differentiate your company in the marketplace, especially as sustainability becomes a key consideration for clients and supply chain partners.
Preparation for Future Regulation: Voluntary disclosure puts you ahead of the curve. As environmental regulations become increasingly stringent globally, companies with established reporting mechanisms will be better prepared to meet mandatory requirements.
Innovation and Strategic Planning: The disclosure process encourages long-term strategic planning around environmental impact, driving innovation in products, services, and processes.
Benchmarking and Peer Learning: CDP provides a framework for measuring and tracking your performance over time and allows you to benchmark yourself against industry peers, identifying areas for improvement and learning from best practices.
[14:15] The cons of voluntary disclosures?:
Resource Intensive: Comprehensive ESG reporting, especially to the level required for an "A" rating, can be costly and time-consuming, particularly for smaller companies with limited resources. It requires dedicated personnel, data collection, and often external consulting or verification services.
Risk of Greenwashing: If disclosure isn't backed by genuine action and verified data, there's a significant risk of "greenwashing" – providing a misleading impression of your sustainability efforts. This can lead to reputational damage, loss of trust, and even legal scrutiny if claims are found to be unsubstantiated. This is precisely why independent verification is so crucial.
Lack of Accountability (without verification): Without external verification or assurance, the reliability and accuracy of self-reported data can be questioned, diminishing the value and trustworthiness of the disclosure. This is a major concern for investors who demand the same robustness for non-financial data as they do for financial data.
Potential for Negative Public Scrutiny: Once you disclose, your data is public. This means your environmental performance, or lack thereof, can be scrutinized by activists, media, and the public. Companies must be prepared to address any critical feedback.
If you’d like any assistance with carbon verification, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The world of ISO is often stumbled into as a result of being tasked with either Implementing or maintaining a Standard for a business. It is rarely a desired career path, and yet there are thousands of ISO professionals from all corners of the globe.
We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Derek Hall, a Senior Isologist® and Sustainability Lead at Blackmores, to learn about his journey from spending 40 years in the printing industry to becoming an ISO Consultant, and what drives him to help clients on their ISO journey.
You’ll learn
· What is Derek’s role at Blackmores?
· What does Derek enjoy outside of consultancy?
· What path did Derek take to become an ISO Consultant?
· What is the biggest challenge he’s faced when implementing ISO Standards?
· What is Derek’s biggest achievement?
Resources
· Isologyhub
· Climate Change Amendment Workshop
In this episode, we talk about:
[02:05] Episode Summary – We introduce Derek Hall, a Senior Isologist® here at Blackmores, to discuss his journey towards becoming an ISO consultant who specialises in ISO 9001, ISO 14001 and ISO 22716.
[03:45] What is Derek’s role at Blackmores? Derek is a Senior Isologist® with Blackmores, supporting companies with maintaining systems, undertaking internal audits, and supporting with implementing new systems to gain certification utilising our Isology methodology.
His passion lies in the realm of sustainability, embedding it within the management systems of many of our clients regardless of any certification to any dedicated sustainability Standard.
Derek was worked with a number of sectors, including:-
· Media
· Printing
· Constructions
· Cosmetics
· Recycling
· Electrical
· Public Sector & NHS
Derek enjoys the learning aspect of working with new industries, and values the input from all personnel involved, from top management to those on the shop floor. He well and truly immerses himself within each company he works with to learn about their values and how ISO can best support their vision.
[08:30] What does Derek enjoy doing outside of consultancy?: Derek has a few varied hobbies, including oil painting born out of his other passion, photography. He often uses his own photos as subject matter for his paintings.
He also trains 4-5 times a week at his local karate club, which caters for all ages and skill sets. Derek has diligently worked his way up to black belt over the 17 years he’s been attending, and offers his skills to teach sessions.
He appreciates the respect that karate teaches, in addition to gaining more knowledge on other points of view. With such a varied class, there’s always something new to learn.
The Australian based club he attends is called GKR Karate.
[12:20] What was Derek’s path towards becoming an ISO Consultant?: Derek’s journey starts back in the 60’s, where he worked in commercial photography, taking pictures on the progress of various building works, and products for furniture stores.
He used to work with plate photography, which was a rather old school method even back then! This was coupled with more modern methods such as 35 millimeter film. He recalls witnessing the building of the Thames barrier, taking pictures to help monitor the amount of water coming through the barrier.
After that he moved onto work for a printing company in Barnet (Hertfordshire), which specialized in advertisements and signage for furniture stores. From the shop floor Derek worked his way up to becoming a printer operative.
This company evolved to include screen printing, which allowed for more versatile applications such as clothing or certain plastics.
After spending 3 and a half years there he moved on with a friend to start their own printing company in Watford, which continued until the 70’s.
In the 70’s Derek joined a much larger printing company based in Southgate London. Here he was involved in the printing of cinema posters for theatres, and musical groups. Derek remained there for 40 years, watching it evolve to larger scale printing for retail markets such as HMV Records and curry’s, in addition to bus advertisements.
During the 90’s, there was a larger push for quality Standards, their clients wanted more assurance that they were following established guidelines and could produce the quality they were after. So, Derek was tasked with Implementing BS 5750, ISO 9001’s precursor, and BS 7750, ISO 14001’s precursor.
The company then got involved in an eco management audit scheme called EMAS, which required the reporting of environmental impacts. It was similar to ISO 14001, but it’s regulatory reporting requirements more closely align with modern schemes such as ESOS.
They also introduced other schools of thinking such as Kaizen, for the purpose of continual improvement.
At this point, Derek became very involved with sustainability standards, and developed a concept called ‘The Tree of Sustainability’, which included 9 branches for improvement. This was introduced due to the fact that their industry by its current nature, wasn’t very sustainable. There was a lot that could be done to reduce their impact.
Through developing that project Derek got involved with the DTR project called ‘The Sigma Guidelines’, a backed scheme run by the BSI forum and The Accountability Institute. These guidelines outlined a 3-year project to identify what sustainability meant to them and how it could apply to their industry.
The result of their work on this project was then submitted to various awards, netting them a number of sustainability awards and The Accountability Institute Awards.
That company continued its operations until 2007, leading to Derek joining Blackmores first year of operation in 2008.
Derek is leading us down a similar sustainability path by encouraging us to become a signatory of the Terra Carta, an initiative including 100 different actions for nature, people and planet.
[26:40] What is Derek’s favourite aspect of being a Consultant? – Derek has a few, including:
Building relationships with clients – Many of Dereks clients have been working with him for over 10 years. He’s as much friends with them as he is a work colleague.
Flexible approach – Consultancy can be delivered in many different ways, allowing for hybrid working. This flexible approach also applies to the way we achieve internal targets, with each member of the team being given specific goals with the freedom to choose how they reach them. Everyone has their own way of working, and we encourage all members of the team to work how they like with the opportunity to learn from each other.
[28:35] What Standards does Derek specilaise in and why? Starting with:
· ISO 9001 Quality Management: A core foundation that many businesses start with when diving into the world of ISO Standards. Derek started with it’s predecessor, and has watched it develop over the years. He appreciates the value it can bring, especially to SME’s who are looking for a scalable model for success.
· ISO 14001 Environmental Management: Derek is a fan of sustainability in general, and encourages everyone to implement some of it’s requirements as part of any project.
· ISO 22716 Good Manufacturing Practices for the Cosmetics Industry: A rather niche quality standard for the cosmetic industry, this Standards works well in collaboration with ISO 9001 for a more holistic approach.
· ISO 45001 Health and Safety Management: Derek picked up this Standard as a result of his work with the construction industry. It’s importance as a tool to prevent harm to humans cannot be understated.
· ESG: Derek has been working closely with his colleague, Ali Henshaw, to develop an ISO based framework to tackle ESG requirements. This includes inputs and requirements from guidance standards such as ISO 20400 (Sustainable Procurement) and ISO 26000 (Social Responsibility)
· ISO 22301 Business Continuity: A lot of organisations are looking to implement aspects of business continuity as a result of the ever-changing resilience landscape.
[32:20] The link between business continuity and climate change: We have seen client requirements evolve to include various elements of business continuity in response to the increasing threats of cyber incidents and climate change related issues.
This is reflected in the recently introduced Climate Change Amendment to many commonly implemented ISO Standards. This requirement ensures that businesses consider their impact on climate change in addition to, how and if they would be affected in turn. If you would like to learn more about this, listen to a previous episode or watch our Workshop playback.
[34:20] What is the biggest challenge Derek had faced during a project and how did he overcome it?: Derek took on the challenge of implementing ISO 22716, when he knew very little about the Standard and the cosmetics industry as a whole. Though there were a few stumbles on his first attempt, they managed to get certified without issue.
That same company then wanted his help to implement ISO 14001, which is a tough ask for the cosmetics industry. There are a lot of factors to consider, such as:
· What is their environmental impact?
· Where are you sourcing materials?
· Are the ingredients shipped from across the globe or sourced locally?
· Is there any animal testing involved?
· How sustainable was their supply chain?
There was a lot to get through, but it was a beneficial choice to get a full picture of their environmental cost.
Later, the company opted to implement ISO 9001 in addition to their existing Iso 22716 and ISO 14001 certifications. This fit nicely as both ISO 22716 and ISO 9001 are quality based Standards, they complemented each other and created an effective and holistic management system.
[27:20] What is Derek’s proudest achievement? Derek received an MBE from the late Queen for services in the environment in 2005. This was earned through his sustainability work within the print industry.
For those not familiar, the Queens Award (now the King’s Award) is a prestigious award that requires 3 levels of review and vetting before winners can be announced. It includes checking evidence provided and the financials involved to verify if applicants have achieved what they say they have achieved.
Derek, along with his wife and daughters, were invited to the palace to meet the queen and receive his award.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO consultancy isn’t a field many aspire to enter, mostly because many don’t know it exists until you’re tasked with either managing an existing ISO Management System or implementing a brand new one.
We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Alison Henshaw, an Isologist® at Blackmores, to learn about her journey from aspiring pub-landlord to becoming an ISO Consultant, and what drives her to help clients on their ISO journey.
You’ll learn
· What is Ali’s role at Blackmores?
· What does Ali enjoy outside of consultancy?
· What path did Ali take to become an ISO Consultant?
· What is the biggest challenge she’s faced when implementing ISO Standards?
· What is Ali’s biggest achievement?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – We introduce Alison Henshaw (Ali), an Isologist® here at Blackmores, to discuss her journey towards becoming an ISO consultant who specialises in ISO 20400 and ISO 26000.
[03:45] What is Ali’s role at Blackmores? Ali is an Isologist® with Blackmores, supporting companies with maintaining systems, undertaking internal audits, and supporting with implementing new systems to gain certification utilising our Isology methodology.
[04:00] What does Ali enjoy doing outside of consultancy?: Ali has a daughter aged 5, so a lot of her social life revolves around play dates and kids parties.
As a family, they are very outdoor orientated, enjoying long walks and camping. In the past Ali enjoyed swimming, often visiting family near the coast to make use of the more bracing bodies of water.
She also likes to craft, recently taking up knitting as her mum often knits for different charitable causes. So far, she’s mastering the art of the knitted rectangle, which lends itself nicely to scarves and blankets.
Lastly, Ali is also a fan of photography due to her father sharing a similar interest. Most of her subject matter revolves around family and the outdoors.
[06:45] What was Ali’s path towards becoming an ISO Consultant?: Ali states that none of her working roles so far have been purposeful, rather more serendipitous.
She started managing pubs at the age of 18, after which she did relief management where she would cover different manager absences in pubs near her home. The owner of the pub she was working with at the time was looking to sell, and for a time, her plan had to been to buy and run it. Unfortunately, as she was only 18, she needed to have some form of business qualification to allow her to progress with that.
This led to Ali starting a part-time business management degree, At the time one of her pub regulars was recruiting for the production departments on a shift basis. So she ended up packing wallpaper on a factory floor for 3 days a week while earning her degree.
Sadly, by the time she had earned her degree, the pub she wanted to buy had been knocked down and turned into a block of flats! Though, after working in a different industry for 2 years she came to reevaluate her desire to run pubs, and came to the conclusion that she rather preferred the manufacturing industry and it’s ability to create something.
Ali also enjoyed the people within the factory she had been working at, and opted to stay there with her mentor, the Technical Manager, who offered her a place in the technical floor. So began her new role as the quality assurance technician.
This progressed as Ali worked her way up through Assistant quality tech to quality tech, to assistant quality manager to quality manager. Her mentor at the time was phasing out to retire, so Ali was essentially his legacy plan.
When he did retire Ali became the Quality Technical R&D and Health and Safety Manager. While in that role Ali implemented ISO 9001, in addition to business research and development programmes for product and process development compliance. Which amounted to sitting on trade association technical committees, monitoring upcoming legislation and also contributing to British technical committees that helped write the legislation for the wall-coverings sector. She later went onto help them implement ISO 45001.
Ali then had her daughter, Angie, during lockdown. For as much as she loves the manufacturing sectors, the worktime for those roles isn’t very flexible. She knew that when looking back, she would rather have spent more time with her daughter than working, so she wanted to find something with a bit more flexibility to allow her to spend quality time with her family. It wasn’t an easy decision by any means, but she was drawn to consultancy due to the variety of work and clients and the increased flexibility it would allow.
She Started to work with Blackmores following lockdown, appreciating the family values that our business was built on. Here she shares the sentiment:
“I'm very rarely the smartest person in the room, and we learn so much from each other.” Going on to say that the varied background of Blackmores consultants offers insight into so many other industries, and she’s drawn on their experience of how to apply ISO Standards in the real world.
[14:15] What is Ali’s favourite aspect of being a Consultant? – Ali enjoys working with SME’s due to her background of working with a 4th generation family owned business. They can often see the value in ISO Standards, and Ali works with them to ensure that do what they do best while working towards certification.
Many businesses simply gain ISO as a tick box for tenders or stakeholder requirements, which isn’t necessarily bad, it’s just how things work in the real world. But Ali figures that if they have to get it, get it right by ensuring it drives internal improvements. Often times clients are pleasantly surprised by all the benefits of effective ISO implementation.
Ali’s favourite clause in Standards is 6.2 Objectives as they drive proactive improvement in businesses. The key is to truly embed them in business processes and practices to ensure they are being achieved.
This is something that even mature management systems can get wrong. She’s seen cases where Objectives were one person’s responsibility, which can lead to them being a separate part of the management system. They need that lightbulb moment from leadership to realise the function of objectives to drive the whole business by taking a more proactive stance.
Many times, Ali’s heard of fantastic internal initiatives being run in a business without them being tied to any objective. By making them an objective, people can make a case for more time, resources and people to complete it, in addition to making the outcome a quantifiable and measurable metric for continual improvement.
[17:35] Practice what we preach – Ali has helped re-shape how we at Blackmores approach our sustainability objectives, turning them into something we can measure the impact of.
As Ali states: “The want for perfection stops progress”. It admirable to strive for perfection, but it isn’t realistic and it often hinders any meaningful progress. When it comes to things like sustainability, you should want to drive improvement now.
[18:55] What Standards does Ali specilaise in and why? Starting with:
· ISO 20400 Sustainable Procurement: This is a guidance Standard thar businesses can align with to ensure their procurement practices are sustainable. This extends to the supply chain, expanding each businesses sphere of influence.
· ISO 26000 Social Responsibility: Another guidance Standard that acts a solid foundation for businesses looking at starting their ESG journey. It tackles the human element of sustainability, in addition to consideration for fair labour practices and community support.
· ISO 9001 Quality Management: The first Standard Ali implemented, and the core foundation that many businesses start with when diving into the world of ISO Standards.
· ISO 14001 Environmental Management: Ali is a fan of sustainability in general, enjoying it’s tangible impacts and the creativity in the many ways people can incorporate it into their business.
· ISO 45001 Health and Safety Management: The second standard Ali implemented, it’s also one of the core 3 ISO’s that businesses tend to implement. It’s importance as a tool to prevent harm to humans cannot be understated.
· ISO 50001 Energy Management and ISO 20121 Sustainable Events: Ali helps to audit these standards, once again these fall into her preference of sustainability as a focus.
It’s clear to see that Ali loves Sustainability and safety based Standards, and the reason is mostly due to ensuring there is a bright future for her daughter. Ultimately, she aims to help people and wants to work with Standards that can make a real difference.
[22:05] What is the biggest challenge Ali had faced during a project and how did he overcome it?: The confidence clients have in themselves. People are very knowledgeable about what they do and the processes involved, but because they aren’t familiar with ISO speak they feel very lost when implementing a standard.
Ali’s main role is translating that ISO speak, and assuring clients that they’re already covering key points such as risks, opportunities and what they’re doing to address them. For many businesses, it’s simply a case of dotting the I’s and crossing the t’s ahead of certification.
The challenge for Ali is to build that confidence in clients ahead of their Stage 1 and 2 Assessments. This is where internal audits come in handy, they act as dummy runs of the assessment. Ali can reaffirm what is meant by each clause and what it relates to in terms of the business activities or certain documentation.
She also reminds clients that they can question the assessor if they don’t understand how they’ve worded a questions. It’s up to the assessor to make themselves understood.
Assessors also understand that your management system will be immature on it’s first certification, it’s simply a starting point on which you’ll build and continually improve.
[27:15] What is Ali’s proudest achievement?
· Changing careers: Ali saw herself retiring in her previous role and so it was a significant change to make the leap to consultancy. She still loves the manufacturing and wall-covering industry, and will always have a keen interest in it, but she can now see herself retiring in a consultancy role.
· Having Angie: Her daughter is one of her proudest achievements, but it also scared everything out of her. It put her at her physical limit, and she’s quite happy to have an only child, ensuring that she gets to spend as much time with as possible while she’s growing up.
· Doing a skydive: As part of a ‘Before your 30’ list with friends, Ali took part in a skydive. Which she admits was horrendous and not something she would do again, but she’s proud to have pushed past the fear as getting out of your comfort zone is often the key to growth.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Emergency preparedness is a term you’re likely familiar with regarding Health & Safety, but its application is also a key part of the Best Practice Environmental Management Standard, ISO 14001.
ISO 14001 aims to help organisations reduce their overall impact on the environment, and this includes mitigating and responding to any incidents that may adversely affect factors such as biodiversity and water quality in areas where your business is based.
While not applicable to every industry, there are many which need to take greater responsibility in the event of an environmental incident. ISO 14001 provides key guidance in how to create effective processes to ensure you respond swiftly, and in alignment with the law.
In this episode Ian Battersby explains what is meant by emergency preparedness and response within ISO 14001, and how that can apply to your business.
You’ll learn
· What is emergency preparedness and response in ISO 14001?
· How do you approach Clause 8.2 in ISO 14001?
· Planning for an environmental emergency
· Definitions of different types of emergency
· How can you prevent an environmental emergency?
Resources
· Isologyhub
· Learn more about ISO 14001
In this episode, we talk about:
[02:05] Episode Summary – Ian explains the purpose of clause 8.2 in ISO 14001, emergency preparedness and response.
[02:35] What is meant by ‘emergency preparedness and response’ in ISO 14001?: Many will be familiar with emergency preparedness and response in relation to Health and Safety. In Standards such as ISO 45001, it’s about ensuring there are plans in place to reasonably foresee and prevent any serious harm to a person or persons affected by our activities
The aim with Clause 8.2 in ISO 14001 is to minimise the risk an organisation poses to the environment. Though, these aren’t mutually exclusive and some environmental response plans can prevent harm to both people and the environment.
Ian seeks to clarify this clause further as many have a tendency to point towards their fire evacuation plan and fire drills as the first piece of evidence when demonstrating conformity to clause 8.2 in ISO 14001. While fire is very violent to the environment once it's occurred, the evacuation of people during such an event building offers little in the way of an environmental response.
[05:10] Breaking down Clause 8.2: Clause 8.1 states:
“The organization shall establish, implement and maintain the process(es) needed to prepare for and respond to potential emergency situations identified in 6.1.1.”
Like with many Standards, it references an early clause where you should be identifying the relevant emergency situations. Clause 6 focuses on risk and opportunities, and in the case of ISO 14001 this is where you’ll establish your environmental aspects and compliance obligations.
Specifically, Clause 6.1.2 states:
“Within the defined scope of the environmental management system, the organization shall determine the environmental aspects of its activities, products and services that it can control and those that it can influence, and their associated environmental impacts.”
This would take into consideration any abnormal conditions and reasonably foreseeable emergency situations.
So, this is where you should already have established the emergency situations for which you need to plan for. Risk management is a core of the standards and planning for emergency situations is a core of risk management. You don’t write plans in isolation; you will have already established what’s important.
[07:30] Planning for emergency: As stated in Clause 8.2:
“The organization shall plan:
a) to take actions to address its risks
b) how to:
1) integrate into environmental management system or other business processes;
2) evaluate the effectiveness of these actions.”
This is all part of the familiar PDCA cycle. From Ian’s perspective as an auditor, he won’t look at emergency plans first, instead looking at an organisations Aspects & Impacts Assessment.
The standard isn’t prescriptive on how you assess the impact of what you do or the risks. The methodology is your choice, but it is very explicit in that the content must include abnormal conditions and reasonably foreseeable emergency situations.
[09:40] What are the definitions for different types of emergency situations?
Normal situations are when everything operates as intended, Business as usual, the day-to-day activities you expect: E.G. Standard operation of machinery, a vehicle getting from A to B without issue.
Abnormal situations are when things aren’t quite right, not catastrophic, but not business as usual; you can still achieve your intended outcome, but maybe not as quickly or efficiently: E.G. machinery running inefficiently or perhaps using more fuel or lubricant than usual.
They don’t necessarily require an emergency plan, but you may want to monitor the severity of such situations and their potential for significant impact if unaddressed.
Emergency situations are serious events requiring immediate attention and which could cause significant environmental impacts. The type of emergency situation that could possibly occur will depend on the type of organisation, but common ones include fire or chemical / fuel spill.
[11:30] What is required by the Standard? – As stated:
You are required to:
A) plan to respond to prevent or mitigate adverse environmental impacts from emergencies; (not human)
B) respond to actual emergencies;
C) prevent or mitigate the consequences of emergencies;
D) periodically test the planned response;
E) review and revise the process, in particular after the occurrence of emergency or test;
F) provide relevant information and training, to relevant interested parties, including persons working under its control.
[13:00] Examples of Emergency Situations – We’ll look at a common one, fire. There are still 22,000 workplace fires in the UK each year, which is a significant environmental impact. That amounts to approximately 2,700 tonnes of carbon emissions annually. This in addition to the atmospheric toxins, ground/water contamination, resource loss, waste etc. So, in considering fire as an environmental emergency, these are the impacts.
IOSH states that the most common cause for workplace fires is faulty or misused electrical equipment, followed by flammable/combustible materials, dirt and clutter, human error, smoking and cooking.
One thing to note about those causes is that they are generally required to be controlled by specific legislation. So, you would be looking for a link between compliance obligations (or legal) register, the Aspects & Impacts Assessment and the controls in place to minimise the risks identified in both.
Faulty electrics would stand out, so you would look at what measures could be put in place to prevent such faults occurring, including:
· Preventive maintenance of equipment
· Inspection and testing of electrical fixed wiring
· Portable appliance testing
By demonstrating the processes in place to address these, you can evidence compliance obligations and the planning to reduce the possibility of an emergency situation arising. However, a fire may still occur
[15:40] Example emergency situation – Prevention: – You should look at the planning to prevent such a situation escalating into a full-blown emergency in order to prevent the environmental impact. This could include:
· The maintenance, inspection and testing of fire detection or suppression systems
· The inspection and servicing of firefighting equipment.
· Firefighting equipment training for personnel
Based on what you know about the causes of fire, you should examine smoking policies/practices, catering equipment maintenance, housekeeping, hazardous material management etc.
Proof of fire drills alone enough when it comes to emergency preparedness and response in ISO 14001. Especially from an auditor’s perspective, as how can you prove that your fire drills are useful in minimising the impact on the environment?
[17:15] Other emergency situations – Spillage: An area where you can more readily see that preparedness and response directly affects the environmental outcome is where there has been a spillage of some kind.
A spill of a lubricant on a shop floor, for instance, has the potential to cause a slip hazard, affecting the safety of people. The preventive measures, again, have similarities regardless of whether we’re talking safety or environment, but do differ in that we’re trying to prevent the lubricant then reaching the outside world and contaminating ground or water; that’s the environmental impact.
Waste disposal associated with the mopping of a spill; you may be dealing with hazardous waste, which must be disposed of in a controlled fashion under the law.
If you’d like assistance with ISO 14001, get in contact with us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
hh32NSNrT8MWkAPwsroK
Watch the Podcast Video on our YouTube Channel
There has been a global shift towards the sustainability effort in recent years, highlighted by various regulations and schemes aimed at businesses to help encourage a more sustainable way of operating.
This has led to more focus on the voluntary use of carbon markets, in which companies help to fund decarbonisation projects by buying carbon credits.
In this episode Mel is joined by Tiffany Cheung, the Corporate Engagement Lead at carbon markets data company AlliedOffsets, as they discuss the landscape of the market, including current trends, decarbonisation challenges in different sectors, and top tips for navigating the space.
You’ll learn
· What impact will corporate disclosures have on the carbon markets?
· What are the rates of decarbonisation across different sectors?
· What are the emerging buyer trends within the voluntary carbon market?
· What is an internal carbon price?
· How can companies use a carbon price to ensure that their sustainability goals are financially viable?
· How can AlliedOffsets’ data help companies when entering the carbon market?
· What are the critical steps businesses should take to mitigate price volatility and ensure that they're investing in high quality, impactful carbon offsetting projects?
Resources
· AlliedOffsets
· AlliedOffsets LinkedIn
· AlliedOffsets Corporate Emissions Data and Findings
· Carbonology
In this episode, we talk about:
[00:30] Episode Summary – Tiffany Cheung joins Mel to discuss buyer trends in the voluntary carbon market (VCM), including insights on the use of internal carbon prices and top tips for businesses looking to enter the market.
Don’t forget to catch-up on the previous episode where Tiffany explains what the voluntary carbon market is and gives an insight into the lifecycle of carbon credits.
[01:30] What impact will increased corporate disclosures have on the carbon markets? There are 2 main points:
Already on the Agenda: Increased corporate sustainability disclosure may already fit into the changes that are taking place within the thinking of a company. If a company is spending time on creating and publishing reports on their sustainability initiatives, it is likely that they will be exploring their options for how they can take action more broadly.This is likely to be associated with increased engagement with the voluntary carbon markets, both through offsetting of carbon footprints and investing in carbon credits or project developers.
Project Developer benefits: Project developers will likely benefit from increased insight to the kinds of projects that buyers are purchasing credits from. As a by-product, there may be more focused projects created based off what certain sectors are willing to offset or invest in.
[02:55] What are the rates of decarbonisation across different sectors? To give a macro view from the public data available in corporate sustainability reports over the last few years, the biggest total polluters by sector continue to be energy, maritime, transportation and materials and mining.
Looking at the positives, the energy sector, which has historically been the biggest polluter, has decreased its emissions in both scopes 1 and 2 since 2019. However, there’s still a very long way to go, and with major emitters recently rolling back their climate commitments, one shouldn’t assume that that trend will continue linearly.
Another sector facing an interesting decarbonization journey is aviation, whose emissions have been increasing in recent years, although not quite to pre-COVID pandemic levels. This sector will have to grapple with its emissions whilst contending with forecasted growth in both consumer and business travel over the next decade. Many aviation companies are both committed to Science Based Targets initiatives (SBTi) and fall under CORSIA (Carbon Offsetting and Reduction Scheme for International Aviation), applying pressure on the sector to decarbonize as a whole.
On a positive note, 18 sectors assessed by AlliedOffsets have decreased their average carbon emissions in scope 2 over the past few years, due in large part to increased renewable energy sourcing and improved energy efficiency.
[07:10] What are the emerging buyer trends within the VCM?: AlliedOffsets are in a particularly good position to provide insight to this due to their comprehensive view of both historic buyer activity and new market entrants across the world.
Chinese and German manufacturers have become a steady presence in the market, distinguished by their especially detailed credit retirement information. They’ll go as far as to specify the products and operating periods that are being offset, showing really high levels of engagement with their environmental impact and giving clear insight on their targeted offsetting approach.
Another buyer trend to highlight is occurring within the Australian market, where AlliedOffsets is seeing lots of credit retirement associated with the carbon neutrality certification scheme Climate Active. This is driving most voluntary retirements from the region, particularly from real estate and pension funds.
[09:15] What is an internal carbon price? An internal carbon price is a specific cost or budget set by a company for the carbon or other greenhouse gas emissions that are associated with their specific business activities.
This is typically based off of something like the World Bank calculations on the cost of climate change to society, or it could be based on the price of carbon set by an compliance emissions trading scheme (ETS) that is local to that business.
[10:20] How can companies use a carbon price to ensure that their sustainability goals are financially viable?: For example, EasyJet has an internal carbon price that's based off of the UK emissions trading scheme. That internal carbon price is factored into the airline’s master financial models and that drives their 5 - 10 year long financial plans. That helps to determine things like the geographical routes that EasyJet operates, which can affect profitability. An internal carbon price makes emissions tangible and material, playing a role in the wider business decisions. An airline operator is considered a big emitter and is likely to already be exposed to some kind of compliance carbon scheme which has a financial impact on the company.
Nonetheless, having an internal carbon price can be useful regardless of how big your business is, as it can be used to budget certain activities and see where emissions might be centralised in a particular department.
An example of this in practice may be that you have an internal carbon price of £50 per tonne, you can take that to an emissions calculator or advisor to work out a budget based on the carbon footprint of different activities or departments in the business. The idea being that if you can identify the cost associated with the emissions created, you know how much to spend to decarbonize. This process may also highlight where you can make further reductions, i.e. reducing air travel and supporting staff on switching to less polluting forms of transport.
[12:55] How can AlliedOffsets data help companies interested in an internal carbon price?: AlliedOffsets has data on the carbon pricing programmes used by companies to set their internal carbon price, as well as the specific price itself for hundreds of different companies.
This dataset also includes companies that haven't chosen to use a particular pricing scheme but have set an internal carbon price based just off of their unique activities.
This helps to contextualize the current range of internal carbon prices and the logic behind them.
[13:50] The need for regular review: Internal carbon pricing is something that needs to be reviewed on a regular basis as the costs associated with emitting in some business locations is not going to remain the same. This can also be affected by national legislation, which can increase the financial risk of emitting.
Tiffany recommends reviewing your internal carbon pricing at least annually. They’re seeing an emerging trend within the environmental space where sustainability related impacts within a company are being sequestered into their wider financial operations.
The impacts of climate change are going to become more material to businesses in the very near future. As a result of this, it makes sense for businesses to assess their internal carbon price as part of their annual financial reviews.
[16:30] What are the critical steps businesses should take to mitigate price volatility and ensure that they're investing in high quality, impactful projects? Tiffany recommends the following steps:
Focus on decarbonising your business operations first and engaging with your suppliers to tackle scope 3 emissions as well. It’s more beneficial to both the business and environment for you to reduce emissions as much as possible, so you have a smaller residual footprint to offset.
Decide what kind of projects / carbon credits you want to spend money on, whether it's offsetting or investing. Besides the climatic impact, there are many co-benefits of carbon projects to choose from, such as improved biodiversity, water supply, or workplace gender equality. Knowing what is valuable to you and your business will help in the selection of these projects.
Build strong relationships with developers directly where possible and buy credits directly, in advance. This also has the benefit of ensuring a supply of carbon credits into the future without the worry about how the market might change or become more volatile within the next couple of years.
If your business is operating at quite a significant scale, it would be wise to work with another company that's focused on the voluntary carbon market, like AlliedOffsets. They can provide guidance and forecasting for the specific projects or sectors you’d like to buy from, reducing uncertainty on the future of the market.
[20:00] Have faith in the impact of the voluntary carbon market – The voluntary carbon market has been through a turbulent period of time, and it’s alright to feel cautious about entering a space which has been unstable in the past.
The concerns about reputational risk associated with offsetting have greatly reduced in the last few years, and it’s set to reduce further as the voluntary and compliance markets merge and integrity improves.
However, if you decide that offsetting isn’t right for your business, there are still other tools that you can take from the voluntary carbon markets to help drive decarbonisation, such as internal carbon pricing.
If you’d like to learn more about AlliedOffsets, visit their website!
If you’d like any assistance with carbon standards, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
· Share the ISO Show on Twitter or Linkedin
· Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the Podcast Video on our YouTube Channel
No business can operate with zero emissions, there’s only so much you can reduce before you need to look at offsetting the remainder to truly achieve Net Zero.
Carbon offsetting comes in many forms, but the ones people will be most familiar with include purchasing carbon credits for nature restoration projects and tree planting efforts.
Historically, the voluntary carbon market has been troubled by project developers who haven’t operated their carbon offsetting projects to the environmental and social standards expected by buyers. With the use of offsets on the rise, it’s clear that there is a need for transparency and standardisation within these voluntary markets.
In this episode Mel is joined by Tiffany Cheung, the Corporate Engagement Lead at AlliedOffsets, to explain what the voluntary carbon market is, how carbon credits work from purchase to retirement and what quality controls are in place to ensure they are reliable.
You’ll learn
● Who are AlliedOffsets?
● What is the voluntary carbon market?
● What are carbon credits, and how do they work?
● What quality controls are in place for carbon credits?
● How will the voluntary carbon market affect future regulatory requirements?
● What does it mean to retire a carbon credit?
● What services do AlliedOffsets offer?
Resources
● AlliedOffsets website
● AlliedOffsets LinkedIn
● Carbonology
In this episode, we talk about:
[00:30] Episode Summary – Tiffany Cheung joins Mel to discuss the voluntary carbon market, explaining the carbon credit lifecycle and what quality controls are in place to ensure they are reliable.
[01:40] Who are AlliedOffsets?: AlliedOffsets aggregates data from over 30 carbon registries and compliance schemes as well as off-registry transactions to present the most comprehensive dataset on carbon offsetting activity globally.
Their data has been featured in publications such as the Financial Times, Forbes, The Guardian and many more.
[03:20] How did Tiffany get involved in carbon markets?: Tiffany has been working with AlliedOffsets for over a year, and a lot of their role as Corporate Engagement Lead includes talking to a variety of stakeholders on the buying side of the carbon market, understanding what their motivations for being in the space are, what their strategies are going into the future and their wider decarbonisation process. Tiffany also looks at their transactional activity and how that has changed over time.
Prior to their position at Allied Offsets, Tiffany worked in a major environmental advisory and brokerage firm based in London. There they gained a knowledge of both voluntary carbon markets as well as renewable energy markets in that space, this in addition to learning more about the accompanying compliance trading and risk side of things.
[06:00] What is the carbon market?: Carbon markets describe markets where carbon is translated from a greenhouse gas into an asset, or a commodity that can be traded. These tend to represent actual tonnes of atmospheric carbon dioxide that have been sequestered somewhere else in the world through various projects.
Compliance carbon markets work differently from voluntary carbon markets. Compliance carbon markets provide regulated ways of pricing carbon, both in terms of reducing emissions and generally making polluters aware of the environmental impact of their emissions in a financial way. They may be associated with the voluntary carbon market, also known as the VCM, or they may be referred to as a kind of carbon tax.
[07:05] What’s the difference between a voluntary carbon market and a non-voluntary carbon market? If you are engaging in the voluntary carbon market, there is no legislative impetus for you to be involved in it. It’s mostly driven by a business’ own desire to offset emissions.
The offsetting of residual emissions is done through the purchase of carbon credits, which are representative of 1 tonne of CO2 equivalent removed from the atmosphere.
If you offset all of your remaining emissions, then you may be able to claim carbon neutrality for the year that the credits apply to.
The benefits of carbon credit-issuing projects aren’t always related to solely greenhouse gas removal, and depending on a businesses motivations, you can help to fund a wide range of beneficial projects such as clean water provision or improved cook stoves which improve air quality in domestic settings.
[09:25] What type of organisations are leading the way with carbon credit purchasing? – AlliedOffsets has unique access to the transaction history across 30 different global registries, enabling them to provide an up to date and wide ranging view on the voluntary carbon market.
There is a very strong relationship between how polluting a sector is and how well engaged it is with the voluntary carbon markets. So major players include energy producers, aviation, maritime, ground transportation and mining and materials.
There is also an increase in financial services, technology and telecommunications services entering the carbon market. Tiffany expects this trend to continue with increased data centre usage and artificial intelligence driving up energy consumption across these sectors.
[11:10] How does the voluntary carbon market operate?: When a company first decides they want to buy carbon credits, ideally they would engage with a well-established broker or intermediary who can source a variety of carbon credits.
It’s helpful for the broker to know what sort of carbon credits or projects a company is looking to invest in. There’s a lot of different options, including:
● Forestry
● Alternative land use
● Blue Carbon
● Engineered carbon dioxide removal
The company will let the broker know how many tonnes of carbon credits they’d like to buy, attributed to a certain period of time or activity based on their quantification and existing carbon reporting.
Market prices will range quite significantly based off of what technology type or methodology you're going with, but most carbon credits are currently sub $15.
Once agreed, your intermediary will secure and retire the credits for you, from the registry and project developer.
Retiring a carbon credit means they are taken entirely off the market and they're considered to be “spent” or used. Nobody else can use those as an investment or offset at that point, and the purchasing company can consider their carbon footprint to have been neutralised for the specified period.
[12:00] What quality controls are in place for the voluntary carbon market? While there isn't a master registry, there are several registries across the world that generally dominate the market. They vary in terms of the methodologies that they may or may not specialise in, as well as with geographies. The biggest ones that you're most likely to see in the market are known as VCS, GS, ACR, and CAR. These account for about 80% of the total market volume by retirement and issuance.
The way that these registries work is that they perform a bookkeeping function within the space. Projects will register their sequestered tonnes of CO2 removed with these registries, who will then check to see if these projects have complied with their methodology, which would have been set by a Standards Body.
Once approved, those project developers can sell their credits as a commodity. When a business wants to buy credits, the type of projects they want to engage with will dictate the sort of registries they’ll be engaging with.
There are also checks in place set by the registries to ensure that project developers use third parties to further validate their project activities.
[16:45] What are the methodologies used in the voluntary carbon market? A methodology refers to the way in which a specific project should be undertaken in order to ensure that the pace of carbon sequestration and storage is consistent throughout the project's life.
Registries are ultimately responsible for issuing the appropriate methodology, and the project developers need to be able to evidence compliance to that methodology.
The process for a project to be registered is quite complicated, and it generally takes 2 – 3 years from concept to being in a position to issue credits.
There is also a requirement to have their work validated by a Verification and Validation Body (VVB). These are third party auditors who check the evidence provided by project developers to ensure they comply with the necessary methodology. This may include the VVBs undertaking a site visit.
[19:30] Will regulatory requirements be introduced within the voluntary carbon market? – Tiffany states that there is definitely a demand for regulatory requirements in the space. There a two key drivers for this:
The need for integrity among buyers – There are many sectors where engaging in a more unregulated space can be risky. Sectors such as the legal and financial sectors need a certain level of oversight to ensure they are making sound investments.
Convergence of compliance and voluntary markets – This is a change that’s been happening over the past few years. This is being driven by governments taking part in the voluntary carbon market space and realising that they can yield returns for the country. Additionally, when they’re spending public funds, there needs to be a certain level of assurance in the projects they’re engaging with.
There is also a growing appetite for businesses engaging in this market to ensure that they are doing the best thing possible ahead of the curve. There’s been a lot of negative press around greenwashing projects, leading to potentially tarnished reputations, to the need for proper checks and regulation is becoming a necessity.
[22:45] What does it mean for a carbon credit to be retired? – The point at which a carbon credit is retired is when it has been taken totally out of circulation for the market. That means that no other broker, intermediary or end buyer would be able to use that credit in any kind of capacity.
It's like having the receipt to say this person has purchased this product, it belongs to them now and nobody else can use it.
[24:30] How are stakeholders using the data provided by AlliedOffsets? – AlliedOffsets has a very wide data set, with an equally wide range of stakeholders.
Some particularly interesting use cases include:
Benchmarking against the competition – Corporate buyers use their data to compare how their activity measures up to competitors or peers within their sector due to AlliedOffsets long view of historic activity. It highlights what projects are being favoured by their competitors and what kind of price points they should be looking at as well.
Project developer research - Another common use case is that project developers will want to see who is active in the market and who they should be targeting for funding. AlliedOffsets can see specific buyer activity broken down by region as well as methodology, which means project developers have a really good chance of being able to engage with buyers who are entering the space and might not have established those direct procurement relationships.
Government consultation - Markets can be a huge source of income from the private sector into the public purse. For example, you might have a voluntary carbon market scheme that's associated with a compliance scheme, which can mean tax benefits for complying businesses alongside socio-environmental benefits for the country.
If you’d like to learn more about AlliedOffsets, visit their website or reach out to Tiffany for more about buyer activity in the VCM!
If you’d like any assistance with carbon standards, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO consultancy isn’t a field many aspire to enter, mostly because many don’t know it exists until you’re tasked with either managing an existing ISO Management System or implementing a brand new one.
We’re continuing with our latest mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Sarah Ball, a Senior Isologist® at Blackmores, to learn about her journey towards becoming an ISO Consultant and what drives her to help clients on their ISO journey.
You’ll learn
· What is Sarah’s role at Blackmores?
· What does Sarah enjoy outside of consultancy?
· What path did Sarah take to become an ISO Consultant?
· What is the biggest challenge she’s faced when implementing ISO Standards?
· What is Sarah’s biggest achievement?
Resources
· Isologyhub
· Productivity Ninja
In this episode, we talk about:
[00:30] Episode Summary – We introduce Sarah Ball, a Senior Isologist® here at Blackmores, to discuss her journey towards becoming an ISO consultant who specialises in ISO 9001, ISO 45001, ISO 14001 and ISO 27001.
[03:45] What is Sarah’s role at Blackmores? Sarah is a Senior Isologist® with Blackmores, supporting companies with maintaining systems, undertaking internal audits, and supporting with implementing new systems to gain certification utilising our Isology methodology.
Sarah also coordinates the development of content of our online learning platform, the isologyhub.
[04:50] What does Sarah enjoy doing outside of consultancy?: Sarah has a keen interest in history, having studied it at school, she like to travel to various locations of historical interest.
She also spends a lot of time researching her own family tree, learning as much as she can about the far reaching members of the past.
Sarah also likes to go jogging outside, as the gym environment didn’t inspire much enjoyment, she instead prefers to be in nature while exercising. She has also participated in long distance running for charity, completing the 10k Race for Life. She’s taking on the more daunting muddy 5K version this year, which includes a number of obstacles, so we’re wishing her luck!
One of the new hobbies she’s like to take up this year include mountain climbing, with Mount Snowdon on her to-do list.
[06:35] What was Sarah’s path towards becoming an ISO Consultant?: Sarah initially started in Customer Services, working as a customer service advisor in a company and then got promoted to manager of a team. At that point, her role became more about understanding why they were getting certain complaints and what could be done to prevent them happening rather than just resolving them.
She ended up spending more time with suppliers and other departments to help prevent some of the recurring issues, and along the line it lead onto being asked to implement an ISO 9001 Quality Management System.
Which was a tall request considering the fact that at the time, Sarah knew nothing about ISO 9001 outside of it’s designation and area of focus. As a result, she spent a lot of time researching it, and had the help of an external consultant to Implement the Management System. This was necessary, as knowing how to apply it to a business was something that she needed support with.
2 years later, the company asked Sarah to implement an ISO 45001 Health & Safety management system and an ISO 14001 environmental management system. These two she implemented herself after getting a feel for it during the initial quality management system implementation.
For the next 10 years, Sarah worked in other companies, assisting with their integrated management systems. Along the way, she also picked up on ISO 27001 Information Security, before landing in Blackmores in 2020.
[09:10] A path people fall onto – Most people don’t actively plan to get into ISO consultancy, it’s usually a result of being tasked with managing or implementing a management system while working in another role.
[10:10] What is Sarah’s favourite aspect of being a Consultant? – Sarah enjoys the variety, not just in the work and tasks but in the companies and industries that she gets to work with.
Each have their own way of working, unique approaches and knowledge nuggets in the form of ways of working that can be cherry picked and applied elsewhere.
She also likes to see how a management system develops and evolves overtime and how it can become part of a company’s success, driving continual improvement.
Sarah enjoys working with people that can see the real benefits of ISO management systems, rather than just focusing on the certificate on the wall.
[13:40] Making a Management System your own – Sarah is a big proponent of making a Management system your own, giving it an identity so that it can be fully integrated into the way a business works.
Businesses do it all the time, usually by naming large projects that everyone can reference by a common shorthand. A Management System can work in the same way, making it a part of the day-to-day running of the business.
She’s also a fan of not worrying about the terminology in Standards. Many of the terms used are meant to be general, this was due to the way international audiences referred to certain aspects of management, it wouldn’t always translate correctly. So many Standards have some admittedly awkward terminology that can be applied to any business, and you by no means have to use their wording, as long as you can explain what relates to what in an audit then you’re free to name things as appropriate to you.
[16:55] What Standards does Sarah specilaise in and why? Starting with:
· ISO 9001 Quality: This is the main standard that Sarah starting working with, and is one that touches on a lot of areas within other Standards. It’s a great base to build off of, and is the starting point for many venturing into the world of ISO.
· ISO 14001 Environmental: Sarah got experience with this Standard at her first company, it’s also commonly implemented alongside ISO 9001.
· ISO 45001 Health & Safety: Another one of the first Standards Sarah implemented, it’s also a common one to see in integrated management systems.
· ISO 27001 Information Security: Sarah got to grips with this Standard through years of working with other companies.
Sarah’s favourite Standard is ISO 9001, not only because it was her first experience with implementing ISO Standards, but because it create a blueprint for success.
ISO Standards are setting the minimum requirement, not the maximum, they are designed get you started so you can make continual improvements. It also acts as a foundation to build onto, you can pick aspects of other Standards to integrate into your existing system. You don’t necessarily have to certify to those additional Standards, but nothing is stopping you from strengthening your Management System with the best bits from other ISO’s.
[21:00] Sarah’s favourite clause in ISO 9001: Sarah personally favors Clause 10 – non-conformity and corrective action. The reason behind that choice is due to that clauses’ importance in driving continual improvement. It’s about taking something negative being turned into a positive, which is what Quality Management is at it’s core.
[22:05] What is the biggest challenge Sarah had faced during a project and how did he overcome it?: Molding the Standard to the business. As a consultant, the biggest challenge is understanding how to make the requirements of a Standard fit the business, and not the other way round.
It’s all about trying to align the ISO Standard requirements to their values and mission, and then getting people on board with understanding the true benefits of management system implementation.
At Blackmores, we ensure that each management system is unique to each business. We don’t operate with a copy paste model. This is another reason why Sarah encourages naming your management system, by branding it you encourage engagement.
Sarah highlights the fact that we run a lot of workshops in the initial part of a project, conducting a Gap Analysis, SWOT and PESTLE ect, this helps our consultants to really get a feel for how a business ticks. From that, we can help steer the delivery of the Management System to the wider business, by building it into their existing tools, such as an intranet.
[25:45] Leading by example: We revamped our own ISO 9001 Management System a few years ago, with both Rachel Churchman and Sarah Ball leading the refresh. We gave it a name, H20 (How 2 Operate) and integrated it with our Microsoft Teams channels as we’d all swapped to mostly remote work following the COVID pandemic in 2020.
As Sarah points out, there are many different ways to display and deliver your management system, including:
· Microsoft Teams
· Intranet
· Google / Google Drive
· SharePoint
· CRM’s such as Monday.com
The key is building it into the day-to-day tools everyone uses. Make the Management System part of your processes, so adhering and maintaining it becomes part of everyone’s way of working.
[28:55] What is Sarah’s proudest achievement? Obtaining her degree through the Open University while still working full time.
It took Sarah 8 years of hard work to obtain her honours degree in History, which was one not required by her work or career development. It was simply something she wanted to do to prove to herself that she could achieve it.
Many other members of Blackmores can attest to Sarah’s level of determination, and organisation, as she shares many tips and techniques learned from her years of study and work. This includes:
The Productivity Ninja – Learned from Graham Allcott’s book, which seeks to help reduce procrastination, and tackle tasks with efficiency.
The Second Brain – A tool to help keep track of ideas / tasks that aren’t an immediate priority.
These tools are now used by a number of the team, and we have no doubt Sarah will be schooling us on more techniques in future.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We share a lot of success stories here on the ISO Show, along with hints, tips and updates to Standards, including insights from our consultants who work with Standards day in and day out.
In our latest mini-series, we’re taking a step back to introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.
In this episode we introduce Darren Morrow, a Senior Consultant at Blackmores, to learn about his journey towards becoming an ISO Consultant and what drives him to help clients on their ISO journey.
You’ll learn
· What is Darren’s role at Blackmores?
· What does Darren enjoy outside of consultancy?
· What path did Darren take to become an ISO Consultant?
· What is the biggest challenge he’s faced when implementing ISO Standards?
· What is Darren’s biggest achievement?
Resources
· Isologyhub
· Engagement Amplifier Gameplan
In this episode, we talk about:
[00:30] Episode Summary – We introduce Darren Morrow, a Senior Consultant here at Blackmores, to discuss his journey towards becoming an ISO consultant who specialises in ISO 9001, ISO 45001, ISO 14001 and ISO 50001.
[03:45] What is Darren’s role at Blackmores? Darren is a Senior Consultant with Blackmores, supporting companies with maintaining systems, undertaking internal audits, and supporting with implementing new systems to gain certification.
A key part of his role is translating ISO Standards into plain English, and guides clients on how to apply them in practice.
[04:55] What does Darren enjoy doing outside of consultancy?: Darren moved to Norfolk back in 2021 ans has since found the relaxed way of life there to be a great fit.
It also offers a lot of good walking opportunities for his 2 Leonberger's (giant breed dogs), who mostly enjoy the local parks and beach walks.
Darren is also an avid reader, clocking in a whopping 343 weeks’ worth of reading on his kindle. His favourite genres include:-
· Crime, thriller, adventure types - Clive Cussler, Michael Connelly, David Baldacci, CJ Box, Dan Brown, James Carol
· Horror - James Herbert, Stephen King
· Supernatural, urban fantasy, fantasy - Ben Aaronvitch, Jim Butcher, Raymond E Feist, C S Lewis & Tolkien
· Historical - CJ Sansom, SJ Parris
· And Terry Pratchett for a weird dose of reality.
He’s also a movie buff, with a collection of over 1,000 films ranging from the 1930’s all the way to modern era. Recently he took on the challenge of watching all the Marvel films in chronological order, which took a few weeks!
[10:35] What was Darren’s path towards becoming an ISO Consultant?: Before Blackmores, Darren was the Quality Manager for a company that worked within the Highways Maintenance sector, working there for 8 years.
For the first 18 months he was primarily the Quality Manager for a specific contract on the Olympic Park, as that contract came to an end, he moved into the main company Quality Manager role supporting multiple highway term maintenance contracts along with various smaller projects that the business won.
Prior to that, he was a SHEQ Advisor within the Rail industry, working for a signaling company. Darren worked there for about 5 years, within head office support roles for quality and health and safety, moving to working on supporting the project teams and project delivery for signaling schemes.
Overall, looking back, he’s worked with standards within a quality, health & safety, environmental for around 25 years now.
[13:20] What is Darren’s favourite aspect of being a Consultant? – Darren likes the variety.
As an ISO Consultant, he gets to work with lots of different people, companies and industries, so he gets to learn a lot about how they work and how Standards apply to different industries.
He also enjoys the fact that after working with clients for a number of years, he becomes just another member of the team.
[15:15] What Standards does Darren specilaise in and why? Starting with:
· ISO 9001 Quality: This is the main standard that Darren starting working with back in 1999
· ISO 45001 Occupational Health and Safety: While working within rail, Darren was given the opportunity to do some training and proceeded to complete NEBOSH courses - general and construction, this proved invaluable in future roles.
· ISO 14001 Environmental: Darren ended up working with this Standard as part of on-going development. His role as a Quality Manager expanded, and at the time, all external audits with our certification body were coordinated through him. So, for on-going development he completed the NEBOSH environmental managed certificate.
· ISO 50001 Energy Management: This is one of Darren’s favourites. He’s taken on this standard since working with Blackmores and seemed like a natural progression with the work he was already doing. He likes how this standard helps companies think more about their impacts on the environment in terms of energy consumption.
In terms of companies climate change impacts, Darren likes how ISO 50001 can support deep dives into data that is available or not clearly available in many cases to support improvement and reduction in energy consumption.
This also can pave the way for those companies that take it more seriously, and progress to newer standards like ISO14064-1 for quantification and reporting of greenhouse gases, but also part 3 for the verification and validation of greenhouse gases.
This is where our sister company, Carbonology Ltd, really excel. Darren does his bit with ISO 50001 clients to educate and prepare them for taking more proactive steps towards meaningful energy and carbon reporting. For example, if they grow sufficiently or fall within the parameters of mandatory schemes such as ESOS or SECR reporting, or they just want to do their bit and demonstrate their commitment to minimising their impact on the environment and overall energy consumption.
[23:10] What is the biggest challenge Darren had faced during a project and how did he overcome it?: He doesn’t have a single one that stands out, but common issues are usually either down to availability or commitment of the individuals within the company he’s supporting.
For example, the company may decide that they require certification to a standard or multiple standards. There will be commitment from some within the business, and there are those that may not see the importance or feel it's not important to them and what they do.
Darren’s job is to support the company in achieving its main goal in gaining certification. His work with the company involved explaining what is to be done and why. He’s found that most of any resistance is because individuals do not know the why and how it impacts them, etc.
The other aspect is to make it clear that he is not there to tell them what to do, or that they’re doing it wrong. He works with people to either document the process (where required), help them find improvement in the process and continue to search for improvement.
[27:00] What is Darren’s proudest achievement? Darren states that there’s no one definitive achievement to highlight, rather he would say supporting clients who are new to the standards. Working with them and providing knowledge so that they know the 'why' and understand the standards and their processes, and finally seeing the end result with being recommended for certification.
The ones that he’s particularly happy with are those that go for multiple standards, that result in recommendation for certification with little or no significant findings from the certification body, it shows that the company has been fully engaged and embedded the overall process into how they work.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
A well implemented ISO Management System can improve efficiency, customer satisfaction and drive continual improvement for a business. On the flip side, a poorly implemented Management system will yield little to no results, so what makes the biggest difference between good and bad implementation?
Communication is the key. If no one knows about your Management System, then how can it benefit the business as a whole?
In this episode Ian Battersby discusses the importance of effective communication of your Management System, why it’s vital to reap the full benefits of ISO Implementation and gives some examples of how you can communicate elements of your Management system to the wider business.
You’ll learn
· Why do you need to communicate your management system?
· What do you need to communicate?
· Why is it important to communicate your Management system?
· Different ways you can communicate your management system
· How can you measure effective communication?
Resources
· Isologyhub
· How can ISO Standards Support ESG Compliance Workshop
In this episode, we talk about:
[00:30] Episode Summary – Ian talks discusses elements of communicating a management system including, why you need to communicate and what needs to be communicated, the importance of doing so and how you can go about doing it.
[02:45] Why do you need to communicate your Management System? In every ISO Standard, communication is a requirement. The levels and information specified will vary depending on the Standard, but the principles remain consistent.
Ian cites ISO 9004 as providing further guidance to improve on what’s initially required. In Clause 7.4 it states:
“The effective communication of policies, strategy, relevant objectives is essential to the sustained success of an organisation.”
Going on to state that communication should be “Meaningful, timely and continual” and that there should be some form of feedback within it to be able to address changes in the organisation’s context. So, it’s not just a one time exercise.
It also states that: “communication processes should be both vertical and horizontal and be tailored to the differing needs of its recipients, whether internal or external.” So you also need to consider the external communication needs too.
[04:35] Empowering through communication: ISO 9004 also talks about engaged, empowered and motivated people and their value as a key resource.
These types of people help organisations to create and deliver value, so you should have processes in place for engaging those people, to gather feedback and drive continual improvement.
[05:40] Where is Communication referenced in Standards?: Typically, communication is Clause 7.4 in most ISO Standards. Additionally there are elements of communication included in Clause 7.3. Awareness.
The Awareness clause focuses on employees knowledge of the Management System, and is more focused on internal communications rather than with external interested parties.
[06:25] What should be communicated internally? Under Clause 7.3 Awareness, it requires you to share:
· Policies
· Objectives
· The consequences of non-conformance
Other Standards may have additional communication requirements such as ISO 45001, which also highlights the need to share risks, hazards, incidents and the outcomes of investigations.
[07:10] Clause 7.4 Communication – This clause is more about determining internal and external communications. This includes considerations for:
· What communications are relevant?
· When should they be communicated?
· Who should they be communicated to?
· Who should be the one to communicate this information?
Some Standards may also include specifications for communicating legal requirements, such as ISO 14001 and ISO 45001.
[08:20] Nuance in effective communication: One key element of communication is ensuring that it’s understood and applied by the wider business.
This doesn’t mean that every employee should be able to parrot a specific policy within a business, but rather they should at least know where to find it and understand the implications for them.
[09:40] A link between Communication and Leadership: Leadership plays a key role in communications, and ISO Standards specify that certain elements can’t be delegated to another individual.
Clause 5 Leadership specifically states:
· They shall promote the use of the process approach and risk-based thinking, not delegating that promotion.
· They should communicate to the importance of the management system and of conforming to that management system.
· They should engage directly and support persons to contribute to the effectiveness of the system.
· They should promote continual improvement.
· They should support other relevant managers to demonstrate their leadership in their areas of responsibility.
We’ve stressed the importance of Leadership in the success of a Management System in a previous episode, and their support with communication is a big part of that.
[11:20] Communicating Objectives: Clause 6.2 Objectives states that they must be established and communicated. This doesn’t have to be to everyone, so you can be selective and communicate certain objectives relevant to select people.
[11:40] How to effectively communicate your management system – Management systems can be vast, and it can be tricky to know exactly how much to communicate and to who.
The first tip is to keep it simple. Translate the ‘Standard speak’ into something recognisable for your business, which may not always be easy if you’re familiar with the Standards terminology. However you need to relate these elements to how people in the business work. Try to keep it brief to avoid confusion.
Next, ensure you are assuaging fears. Many are firstly opposed to the introduction of things like Operational Procedures if they’ve not worked with a Management System in place previously. However, all this is in practice is a written format for how they work, it shouldn’t drastically change the way in which they work. Make sure they know this and describe what elements will change i.e. documentation updates.
Lastly, they need awareness of the consequences of non-conformance and the need to look for opportunities to improve.
[15:25] Communicating Policies – This is a part of all ISO Standards, a Policy can’t just be hidden away in a rarely visited folder. A Policy communicates the intent of top management in an organisation, and is something that should be communicated to everyone, which could include external parties.
So, you should try to keep this concise. On one page ideally. As long as you’ve encompassed the vision, values, strategy and top management commitment, and for certain standards a commitment to legal requirements, then you will meet an ISO Standards requirements.
Some businesses like to include links to all their procedures within a policy, which by all means, you can, but don’t expect people to read a 48 page policy and understand it enough to apply to their daily working lives.
[17:00] How can you communicate your Management System? – One key objective of communication is to ensure people understand and apply what’s being communicated.
To help achieve this, you may want to use multiple methods of communication, including:
· Feedback options on content i.e. a yes or no check / options to provide feedback
· Training sessions
· Intranet page – quick links to relevant content such as policies or audit findings
· Regular briefings
· Notice boards
· Electronic displays
· Company briefs
· Team meetings
[20:25] How can you measure effective communication? There’s a lot of ways you can assess this, including:
· E-mail voting – to clarify when people have read specific documents
· LMS Systems
· Through SharePoint systems
· Conduct surveys
· During Internal Audits
All of these can be used as methods of feedback where you can identify further opportunities for improvement from various levels of the business.
[21:35] When should you consider external communications? – Clause 4.2 is where you’re required to consider the needs and expectations of interested parties.
When going through an anaylsis of these interested parties, you determine what they expect out of your Management System.
Standards don’t specify the need to write a communication plan, but they do say who’s going to communicate what to whom, including how and when. In combination with that analysis of interested parties, it creates a solid basis for an effective communications plan.
Again, some discretion will be required as not every external party will need to be privy to your internal policies and procedures. Just communicate what’s relevant to them.
If you’d like any assistance with implementing ISO standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the Podcast Video on our YouTube Channel
Greenwashing is a concern for both businesses and consumers. The proliferation of it in recent years has caused genuine green claims to be treated with an air of caution rather than being rightfully celebrated.
It’s become clear that there is a need for transparent and substantiated green claims, both to help consumers and stakeholders to make informed decisions and to ensure that real steps towards sustainability are being taken.
Is the upcoming EU Green Claims Directive the answer we’ve been looking for?
In this episode Mel is joined by Charlie Martin, CEO and Founder of The Anti-Greenwash Charter, to discuss the purpose of the EU Green Claims Directive, who it applies to and what it’s requirements for substantiation and verification mean in practice.
You’ll learn
· What is the purpose of the EU Green Claims Directive?
· What are the drivers behind this objective?
· Who is required to comply with the EU Green Claims Directive?
· What do the requirements for substantiation and verification mean in practice?
· How will the directive impact the use of carbon offsetting and carbon neutrality claims within the EU?
Resources
· EU Green Claims Directive
· Anti-Greenwash Charter
· How can The Anti-Greenwash Charter can help with the EU Green Claims Directive
· Green Claims Policy Template
· Carbonology
In this episode, we talk about:
[00:30] Episode Summary – Charlie Martin joins Mel to discuss the upcoming EU Green Claims Directive, who it applies to and what it’s requirements mean in practice.
[02:30] What is the purpose of the EU Green Claims Directive?: This directive is a new law, not simply a voluntary scheme that businesses can opt into.
It’s a regulation that governs all voluntary green or environmental claims made by organisations operating within the EU, and requires data to back these claims up.
Another key fundamental of this directive is the need for independent verification of any claims before they’re made public.
[04:35] What are the main drivers for the EU Green Claims Directive?: One of the key drivers is combatting the rampant rise in greenwashing. It’s created a culture of mistrust around green claims, which makes it difficult for stakeholders and consumers to make informed decisions on who to work with or buy from.
Greenwashing also makes it harder to tackle bigger environmental concerns. With misleading data, we can’t accurately measure businesses impact on the environment, which is essential if we are to take meaningful action to reduce our impact.
Ultimately, greenwashing practices are slowing down our ability to effectively reduce our impact as a collective. We are at a point where sustainability related decisions need to be made quickly.
[08:00] Clearer Communications: This directive also has more control over what you can and can’t say in relation to green claims. By waiting until that independent verification has occurred, businesses can feel confident in the information they’re communicating.
[09:30] What is Green Masking? Coined by Carbonology, green masking is where organisations are essentially marking their own homework and hiding behind that fact. It’s where no independent verification has taken place, which can result in a lack of accuracy and transparency.
[10:25] Who needs to comply with the EU Green Claims Directive? – This is an EU based regulation, so if you’re located within the EU you will be expected to comply with this law.
If you do business within the EU, so if you’re based in the UK and sell to Europe, then you will also fall under this jurisdiction as well.
[11:25] What is required by the EU Green Claims Directive?: A full summary of the directive’s requirements can be found on the EU website. A simple break down of these requirements is also available on The Anti-Greenwash Charter website.
Charlie recommends familiarising yourself with the EU Green Claims Directive requirements initially, which are written to suit how businesses generally operate. He also advises that you seek legal assistance as well as sustainability and marketing experts or consultants to get a full picture of how you can comply with these requirements.
[13:35] There is an emphasis on substantiation and verification in the EU Green Claims Directive – what does this mean in practice? A green claim doesn’t account for much if you’re marking your own homework. For it to be truly substantiated, it needs to be verified by an independent third party.
The Directive also highlights the need for life cycle data, and its inclusion within the verification process. This will give businesses a more wholistic view of the impact of the materials they use, the products they use and services they deliver.
Charlie encourages businesses to get a head start on this now, not only due to the benefits it can bring but also to get ahead of the tightening of sustainability legislation that is coming down the road for the UK.
[16:15] How will the directive impact the use of carbon offsetting and carbon neutrality claims within the EU? Businesses are going to have to be crystal clear in their terminology in terms of their substantiated claims.
There is going to be a lot more scrutiny on the quality of evidence provided for carbon claims, so businesses may want to outsource help with analysing the relevant carbon data and communicating any claims and offsetting efforts.
[18:25] Is the Directive ambitious enough? Or could it be strengthened? – Previous attempts to enforce sustainability regulations have been rather weak, and time will tell if this EU Directive is set to change that pattern.
Charlie praises the Directives approach to best practice, though that will evolve further as time goes on. He thinks that the use of generative AI and how that impacts and influences sustainability communications needs to be considered further.
It’s all still quite new, so this may be added in down the line. The Anti-Greenwash Charter already have considerations for responsible AI use within communications and data processing within their Green Claims Policy Template.
They caution any signatories of their Charter to be very careful with the use of AI to support data collection and analysis, as it has the tendency to ‘hallucinate’, and companies will be held responsible for any mishaps related to incorrect results provided by AI.
[23:00] What are the potential consequences for businesses that fail to meet the requirements of the EU Green Claims Directive? – The penalties will be significant, including both fines and potential bans in areas such as marketing, advertising and promoting sustainability claims on the basis of malpractice.
Time will tell on how these penalties are delivered and to what extent within the EU and UK. It shares similarities with other regulations, such as ESOS, where a phased approach was implemented for organisations that met certain criteria.
[25:00] How can The Anti-Greenwash Chater help organisations comply with the EU Green Claims Directive? – Since it’s inception in 2022, they have paid close attention to the Directive’s development, utilising any improvements and iterations to bolster their own process.
As a result, a lot of the work they do with signatories directly aligns with and facilitates the delivery of the foundations of the Directive.
Examples of this include:
Independent verification – Their Green Claims Policy has to include a green claims database, so any claim that a business want to make has to have the relevant data to back it up. It also requires specification of what third party that business used to verify that evidence.
Accessibility of evidence – This is stressed within the EU Green Claims Directive, and is easily fulfilled with the creation of a green claims database as specified by The Anti-Greenwash Charters’ Green Claims Policy.
A full summary of how The Anti-Greenwash Charter can help with compliance to the EU Green Claims Directive is available on their website.
[27:55] How will the EU Green Claims Directive will impact consumer trust in environmental claims? – There’s currently an issue with the flooding of sustainability related communications. With greenwashing so rampant, making an informed decision as a consumer is really difficult.
The standardisation of sustainability credibility and substantiation is what the EU Green Claims Directive aims to do. Ultimately, it will act as a trustworthy marker for stakeholders and consumers to make an informed decision quickly.
If you’d like to learn more about The Anti-Greenwash Charter, visit their website!
If you’d like any assistance with carbon standards, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Watch the Podcast Video on our YouTube Channel
We are hitting a crunch point in regard to keeping to the 1.5°C limit as set out in the Paris Agreement. It’s going to take a collective effort to reduce the most catastrophic impacts of climate change, which is exactly why we’re seeing an increase in legislation and regulations that call for tangible evidence of sustainability efforts to combat the rise in greenwashing.
If you’re looking for guidance on sustainability transparency, today’s guest has an initiative that can help.
In this episode Mel is joined by Charlie Martin, CEO and Founder of The Anti-Greenwash Charter, to discuss how their charter promotes transparency and accountability for sustainability claims, and how it can help consumers to identify credible carbon claims.
You’ll learn
· What is The Anti-Greenwash Charter
· How can the Charter ensure credible carbon claims?
· What are the biggest challenges businesses face in measuring their carbon footprint?
· How can The Anti-Greenwash Charter help consumers to spot credible carbon claims?
· What role do governments and regulatory bodies play in combatting greenwashing?
Resources
· Anti-Greenwash Charter
· Green Claims Policy Template
· Carbonology
In this episode, we talk about:
[00:30] Episode Summary – Charlie Martin joins Mel to discuss how The Anti-Greenwash Charter can help promote accountability and transparency in sustainability claims, and how it can help consumers identify credible carbon claims.
[01:50] What inspired the creation of The Anti-Greenwash Charter?: Charlie used to run an agency called Gusta, which was a UK based business that worked on sustainability communication for organisations in the built environment.
His focused shifted when the Competitions and Markets authority in the UK published their Green Claims Code alongside research which found that 40% of sustainability-related messaging online was misleading.
At the same time, they had 2 very proactive clients (1 of which was going through B Corp certification) that highlighted that the CMA had not named the built environment as one of the affected sectors. They pointed out that the built environment accounts for 40% of all emissions, so were likely to be targeted by such regulations next. They asked to run a campaign that would Increase confidence both internally within their sectors and externally in their sustainability messaging.
It was decided that a publicly available document would be the best way forward to proactively disclose their carbon reduction related activities. Other ideas were added for an editorial process to include legal, sustainability and marketing feedback ahead of publishing.
Essentially, the origins are rooted in the notion of a green claims policy, which developed into a more robust accreditation signatory.
[06:30] How does Charlie define Greenwashing?: Charlie defines greenwashing as "overstating or misleading stakeholders regarding the environmental credentials of an organization, service, or product.
Charlie explains that there are two types of greenwashing: direct and indirect. Direct greenwashing involves making false claims about a product's environmental benefits, while indirect greenwashing involves making true claims that are irrelevant or misleading.
[08:00] What are the key principles of the charter, and how do you ensure adherence among signatories?: The 4 key principles are:
· Accountability
· Honesty
· Fairness
· Transparency
If you’d like to know more about each principle in more detail, visit The Anti-Greenwash Charter website.
Taking a look at transparency in more detail, it’s not just about sharing all the best sustainability related news for your business, it’s about being willing and upfront with areas where you’re not as strong.
One keyway they ensure signatories adhere to this principle involves publicly displacing their green claims policies. The first section of every policy is ‘where can we improve?’ – they specify this as there isn’t a company that is 100% environmentally sustainable, and businesses need to be honest about this if they want to improve.
[12:15] What are Charlie’s thoughts on the current state of Net Zero claims? There are some promising developments, such as the upcoming Green Claims Directive, which has more requirements set around how people make claims and being held accountable for those.
It’s challenging for everyone to navigate, and the big thing here to remember is that everyone is clumsy when it comes to Net Zero. Businesses are trying their best, but when getting deep into the topic of sustainability, it becomes clear how broad it truly is.
Ultimately, people have to be okay with getting things wrong. Some people see setting ambitious targets as dangerous, but if we don’t push for them, change is going to happen at a snails pace.
There is a need for credible, substantiated plans that are in-line with best practice, but we need to be careful to not go too far in that direction to ensure that it helps rather than hinders sustainability efforts. Innovation should be encouraged and not punished if mistakes are made or certain really ambitious targets aren’t met within a certain timeframe.
Mel highlights that Standards such as ISO 14064 are great frameworks to guide businesses in measuring their carbon footprint, with guidance that encourages independent third party verification for further transparency.
[15:40] The Green Claims Directive and Transparency – Charlie highlights that the Green Claims Directive identifies independent third party verification as a mandatory requirement of claims made before they’re disclosed publicly.
As this is also something that The Anti-Greenwash Charter encourages, signatories are already ahead of the curve.
[17:10] What are the biggest challenges that companies are facing in accurately measuring their carbon footprint and how does the Charter help to address these challenges? The main challenge is accurately measuring their carbon footprint, and the charter acts as a signpost with referral partners who can assist with this aspect of their sustainability journey.
Another challenge is communication. So you’ve got your substantiated claims and green credentials, but how do you go about communicating that? That’s one of the crucial elements that The Anti-Greenwash Charter can help with. As mentioned earlier, they can help verify a publicly available green claims policy, which is a huge step towards credible carbon claims.
If you’d like an example of this, you can download Anti-Greenwash Charters’ green claims policy template from their website – which provides a step-by-step guide on producing one of your own.
[20:50] What are the broader benefits for companies that adopt a transparent and credible green claim? Charlie explains that signatories have used their status as a signatory for their Charter on tender frameworks, and won due to that fact.
Another benefit is the Charters’ credibility, which gives external stakeholders confidence that a business is doing what they claim to be doing.
They also offer anti-greenwashing awareness training, which gives those within the business the tools and techniques that can be utilised in any published content to ensure they aren’t making any greenwashing claims.
[22:25] The negative effects of greenwashing on well meaning businesses: Charlie and Mel both highlight the sad reality that many businesses would prefer to simply not make any green initiatives or claims public for fear that if they are not done 100% successfully then there’s a chance for reputational damage.
The need for robust sustainability frameworks that build confidence is clear. Due diligence is important, and so is the need to allow room for mistakes to happen, so long as businesses take the necessary steps to fix them and keep continually improving.
[27:15] What role does Charlie see governments and regulatory bodies playing in combating greenwashing, and what policy changes would he like to see? – The EU Green Claims Directive is currently best in class as it requires businesses to look at the consequences of their impact on the environment, in addition to the requirement for independent verification to back up any claims made.
Other regulations here in the UK, like the Green Claims Code, is weaker in comparison. It was watered down through negotiation into a more voluntary scheme.
For us here in the UK, we really do need to align with Europe, as their regulations are a lot more robust and offer a tangible path towards a united greener future.
There are other benefits, as Mel highlights from her Masters research, there is compelling evidence that a company’s value increases by an average of 10% if their carbon claims are independently verified.
[32:35] What are Charlie’s aspirations for The Anti-Greenwash Charter? And what are his hopes for the future of credible carbon claims? – They’re really keen to become a multinational signatory, which is already showing promise as they’ve had interest from the US and Australia.
Charlie envisions a future where businesses publish a green claims policy regardless of if it’s mandated by legislation. This is so we can build confidence in green claims being made and be assured that people are doing what they say they’re doing.
To help with credibility and transparency, The Anti-Greenwash Charter has been incorporated as a not-for-profit organisation. Charlie wants to reaffirm that they started this to ultimately reduce the impact businesses make on the planet, and they are fully committed to this goal.
If you’d like to learn more about The Anti-Greenwash Charter, visit their website!
If you’d like any assistance with carbon standards, get in touch with Carbonology, they’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO Standards have been at the forefront of creating a unified approach to various aspects of sustainability, ensuring businesses have a robust framework to both manage and reduce their environmental impact.
However, there are a lot of different sustainability Standards that cover specific areas of sustainability, or only apply to certain sectors. Each come with their own pros and cons, making it tricky to pick the best fit for you.
In this episode Steph Churchman introduces four of the leading sustainability focused ISO Standards and explains the benefits and disadvantages of each to help you decide which could be the best fit for your business.
You’ll learn
· Learn about our upcoming ESG Workshop
· What is ISO 14001?
· What are the pros and cons of ISO 14001?
· What is ISO 50001?
· What are the pros and cons of ISO 50001?
· What is ISO 20400?
· What are the pros and cons of ISO 20400?
· What is ISO 14064?
· What are the pros and cons of ISO 14064?
Resources
· Isologyhub
· Register for our ESG Workshop (26th March 2025)
In this episode, we talk about:
[02:05] Episode Summary – Steph discusses the leading sustainability ISO Standards, and explains the advantages and disadvantages of each.
[02:45] ESG Workshop: On the 26th March 2025 we’ll be explaining how ISO Standards directly support ESG compliance, and we’re including the opportunity to participate in 1 of 3 interactive sessions that tackle things like completing a materiality assessment, a balance scorecard and learning more about the current mandatory ESG reporting requirements.
Register your place here.
[03:15] What is ISO 14001?: ISO 14001 is the Standard for Environmental Management. Published back in 1996, this Standard is one of the staples in the ISO world.
Its main purpose is to establish and implement an effective environmental management system (EMS), with the primary goal of helping organizations to minimize their environmental impact and achieve sustainability objectives.
It sets out general requirements for:
· Pollution control
· Reduction of your impact on the environment
· And compliance to relevant legislation
It is also due for a revision soon, with the latest version expected to include further considerations for changes to available technology, more emphasis on product life-cycle and supply chain issues and further guidance on integrating environmental issues into your strategic planning.
[04:35] What are the benefits of ISO 14001?:
Reducing environmental impact: By identifying and controlling environmental aspects, organizations can minimize pollution, reduce waste, and conserve resources.
Improved compliance: ISO 14001 helps organizations comply with environmental regulations and legal requirements, such as the environment Act 2021, reducing the risk of fines and penalties.
Improved efficiency: ISO 14001 helps to tighten production processes, leading to better efficiency and reduction in the risk of incidents. It also removes uncertainty by managing disruption and waste and helps to clarify staff responsibility.
Enhanced reputation: Demonstrating a commitment to environmental responsibility can enhance your reputation and brand image, attracting environmentally conscious customers and stakeholders.
Cost savings: Implementing an EMS can lead to cost savings through improved resource efficiency, reduced waste disposal costs, and lower energy consumption. Businesses can also benefit from reduced insurance costs by demonstrating better risk management.
Increased competitiveness: ISO 14001 certification can give organizations a competitive advantage in the marketplace, particularly in sectors where environmental performance is a key consideration.
[06:45] What are the disadvantages of ISO 14001?
Initial costs: Implementing an EMS requires an initial investment in resources, including training, documentation, potentially hiring consultants, and if you’re going for certification, that will incur its own costs from a certification body too.
Ongoing maintenance: Maintaining an EMS requires ongoing effort and resources to ensure compliance with the standard and continuous improvement.
Potential for bureaucracy: If not implemented effectively, an EMS can become cumbersome, hindering operational efficiency.
Limited scope: ISO 14001 focuses primarily on environmental aspects within an organization's direct control, and may not address broader environmental impacts or social responsibility concerns – which is where other Standards can fill the gap.
[08:05] What is ISO 50001? – ISO 50001 is an internationally recognized standard that provides a framework for organizations to establish, implement, and maintain an Energy Management System (EnMS).
The primary goal is to help organizations improve energy performance, including reducing energy consumption, increasing energy efficiency, and using energy more effectively.
[08:40] What are the benefits of ISO 50001?
Reduced energy costs: By identifying and addressing energy inefficiencies, you can significantly reduce your energy bills. We had great success with this when we worked closely with a branch of the NHS, where their initial energy spend was around £2.8 million which was reduced by £1 million as a result of implementing ISO 50001.
Improved energy performance: ISO 50001 helps organizations establish baselines, set targets, and track progress in improving energy performance. This is vital as you can’t hope to reduce what you can’t measure.
Enhanced environmental performance: Reduced energy consumption leads to lower greenhouse gas emissions and a reduced environmental impact. Often times, energy usage is the largest impact many organisations have on the environment, especially for those who may only have an office or warehouse.
Increased competitiveness: Demonstrating a commitment to energy efficiency can enhance an organization's reputation and attract environmentally conscious customers and stakeholders.
Improved operational efficiency: An energy management system can lead to improved operational efficiency through better resource management and reduced waste.
[10:55] What are the disadvantages of ISO 50001?
Initial investment: Implementing an EnMS requires an initial investment in resources, including training, data collection, and possible help from a consultancy.
Limited Guidance: Calculating your energy usage can be complicated, especially if you’re spread across multiple sites and countries. In cases where you’re renting space, you may face difficulties obtaining the information needed, then on top of that is the actual calculation which may involve conversion factors if you’ve got international sites in scope.
Resistance to change: Implementing changes to energy-using processes can sometimes meet with resistance from employees. A lot of practices will require a change in habits, such as turning off and unplugging all devices when leaving an office, or more frequent checks on equipment to ensure it’s running optimally.
Limited scope: ISO 50001 focuses primarily on energy performance within an organization's direct control and may not address broader energy-related issues or the entire supply chain – which includes its own energy consumption considerations.
[12:30] What is ISO 20400? – ISO 20400 is an internationally recognized standard that provides guidance on sustainable procurement. It helps organizations integrate sustainability considerations into their procurement processes, ensuring that environmental, social, and economic factors are taken into account when making purchasing decisions.
This Standard differs from the others as it’s not a certifiable Standard. It’s a guidance document that you can align with.
For those of you looking into ESG schemes, this Standard is often citied as a key tool to help get you in the right place for scoring.
In addition, for those of you looking into more comprehensive carbon reporting, Supply chains are often one of the biggest sources of emissions. Alignment with that Standard will allow you to take a good hard look at the suppliers you work with, and determine if they hold the same sustainability values as you.
[13:25] What are the benefits of ISO 20400? –
Reduced environmental impact: By selecting suppliers with strong environmental performance, businesses can reduce their overall environmental footprint. You also have a great chance to help influence your own supply chain, we know that if you’ve had a reliable supplier for a number of years, it’s not just a simple case of cut and move on.
Improved social responsibility: ISO 20400 encourages organizations to consider the social and ethical impacts of their procurement decisions, such as fair labor practices and human rights.
Enhanced reputation: Demonstrating a commitment to sustainable procurement can enhance your reputation and brand image. It shows that you’re thinking and acting sustainably from start to finish for either your product production or service delivery.
Cost savings: Sustainable procurement practices can lead to cost savings through reduced waste, improved resource efficiency, and lower long-term maintenance costs.
Increased innovation: Working with sustainable suppliers can expose you to new technologies, products, and services that can improve your own operations.
[15:35] What are the disadvantages of ISO 20400? –
Increased complexity: Integrating sustainability considerations into procurement processes can add complexity and require additional resources. This would include supplier checks before working with new suppliers and a review of all current suppliers to see where improvement could be made.
Finding sustainable suppliers: Identifying and qualifying sustainable suppliers can be challenging. Though more businesses are certainly making an effort to be more sustainable, ensuring they have proof of their claims is essential.
Potential for higher costs: In some cases, sustainable products and services may have a higher initial cost compared to conventional options.
Limited scope: ISO 20400 focuses primarily on procurement practices and may not address broader sustainability issues within the organization. This is where ISO 20400 can be supported by certifiable standards such as ISO 14001 and ISO 50001.
[17:00] What is ISO 14064? – ISO 14064-1 is an internationally recognized standard that provides a framework for organizations to quantify and report their greenhouse gas (GHG) emissions and removals.
It helps organizations to:
· Understand their carbon footprint
· Set reduction targets
· Engage in carbon markets
· Improve environmental performance
[17:45] What are the benefits of ISO 14064?
Improved data quality: The standard provides a robust methodology for collecting, analyzing, and reporting GHG emissions data, ensuring accuracy and consistency.
Set achievable reduction targets: By having an accurate way to measure your impact, you can look to set realistic and more importantly achievable reduction targets.
Enhanced credibility and transparency: Both consumers and stakeholders are increasingly looking at real tangible evidence of your carbon claims. Simply having a sustainability page full of promises is no longer enough, you need facts and figures to back up what you say you’re doing.
Reduced climate risk: By understanding and managing your GreenHouse Gas emissions, you can better mitigate the risks associated with climate change, such as regulatory changes and physical impacts.
Competitive advantage: In an increasingly climate-conscious world, businesses that can demonstrate their environmental performance through credible GHG reporting will gain a competitive advantage.
[19:30] What are the disadvantages of ISO 14064?
Initial investment: Much like the other Standards, if you want to do this right you will have to invest time, resources and money. That could include hiring consultants to help you with the necessary calculations, and if you wish to go for full verification, then there will be an additional cost from a verification body.
Ongoing maintenance: Maintaining an accurate and up-to-date GHG inventory requires ongoing effort and resources. Monitoring your emissions doesn’t stop once you get a verification badge, it will be on-going.
Data complexity: Collecting and analyzing GHG emissions data can be complex, especially for large and diverse organizations. So, you may need some initial help to do and understand this yourselves.
Limited scope: ISO 14064-1 focuses primarily on the quantification and reporting of GHG emissions and removals, and may not address broader sustainability issues.
If you’d like any assistance with implementing any of these Standards, get in touch with us, we’d be happy to help!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
If you’ve ever implemented an ISO Standard, then the term Management Review will be familiar to you.
It’s a mandatory part of the implementation process, and a crucial tool for monitoring continual improvement. Somewhere down the line, it’s become a bit of a myth that a Management Review needs to be an annual meeting.
That is simply not the case, while required by the Standard, it’s very flexible on how this could be achieved.
In this episode Ian discusses the purpose of Management Review, including what you should be including and getting out of the review and breaks down the fallacy of the annual event.
You’ll learn
· What is the purpose of a Management Review?
· What are the common misconceptions about Management Review?
· How Management Review supports other clause requirements
· What are the inputs for Management Review?
· What are the outputs of a Management Review?
Resources
· Isologyhub
· How to conduct a Management Review
· How to get the most out of your Management Review
In this episode, we talk about:
[02:05] Episode Summary – Ian discusses the real purpose of Management Review, and dispels the myth of the annual event.
[02:35] What is the purpose of a Management Review?: Management Review is a requirement of all ISO Standards. It’s main purpose is to check if your Management System is fit for purpose, and what needs to be updated to ensure it aligns with your businesses objectives and strategic direction.
In short, it’s there as a check to see what’s working well and what’s not working well, in addition to continual improvement considerations.
[03:30] What are some common misconceptions about Management Review?: Some common misconceptions include:-
· That it’s simply a formality – Rubber-stamping things and missing out on the opportunity to effectively monitor management system progress
· That It must be once a year
· Having to review everything in excruciating detail i.e. all audit findings
· The need to update the risk assessment and re-jigging scores
· That you must review and update your SWOT/PESTLE
· Or review and update all management system documentation
· That it’s the perfect opportunity to re-write a policy
There is a time and place for all of these, and you could tackle some of this in a Management Review if you really want to, but that is not the main purpose of a Management Review.
[04:50] How Management Review supports other clause requirements - Leadership: If we take ISO 9001 as an example, the Leadership clause states:
“Top management shall demonstrate leadership and commitment with respect to the quality management system by:
a) taking accountability for the effectiveness of the quality management system
e) ensuring that the resources needed for the quality management system are available
g) ensuring that the quality management system achieves its intended results”
These requirements at first glance may seem like they’d require a lot of effort and monitoring of many different factors, but in actuality they can all be satisfied through effective Management Review.
[05:55] What involvement is required from top management? As stated in ISO Standards:-
“Top management shall review the organization’s management system, at planned intervals, to ensure its continuing suitability, adequacy, effectiveness and alignment with the strategic direction of the organization.”
Top management also have involvement in the following elements of implementing and maintaining a management system:
· Context
· IPs
· Risks/Ops
· Objectives
· Policy
· Support
· Operation
· Performance monitoring
Management Review relates specifically to ‘performance monitoring’, but that in of itself will include elements of all the other clauses within the Standard, and many of those require top managements involvement on some level.
[07:45] The fallacy of the annual event – The Management Review clause specifically states that a Management Review should be ‘carried out at planned intervals’.
Many had interpreted that as once a year, which has been the prevailing myth for decades. Looking at the Standard, no where does it say ‘once a year’, planned intervals means it could be once a month, it could be once a week, it could be a set points during the summer.
When deciding on these planned intervals, take into consideration the nature of your business, the size of your business, the risks associated with it and the maturity of your Management System. This will determine how frequent the Management Review should be, as it will differ for every business.
[09:10] Examples of Management Review frequency – Ian has worked in an organisation where they had a rather grand Management Review process, where top management and other relevant individuals meet to review the past year and set the scene for the following year.
That same organisation also had monthly meetings with the same members of top management to keep on top of new and on-going issues.
That isn’t to say this is the only way to run Management Review. Some opt to have quarterly meetings, others once every 6 months and some even leave it to once a year.
[10:40] What is required of Management Review? Inputs – Clause 9.3 details the requirements of Management Reivew in most Standards (some swap 9.3 and 9.2 around, but the contents remains the same).
First, the inputs required for Management Review include:
The status of actions from previous management reviews - If you said you were going to do something before, how’s that going?
Changes in external and internal issues that are relevant to the quality management system - this doesn’t mean that every meeting should consider the SWOT/PESTLE/IP tables, but there must be some determination of when that’s done in detail and when a senior mgt discussion should include the key aspects of that and its impact. There is a need to review these things when required anyway, so doing it only at pre-defined times can be problematic.
Information on the performance and effectiveness of the quality management system, including tends in:-
· Customer satisfaction and feedback from relevant interested parties;
· The extent to which objectives have been met;
· Process performance and conformity of products and services;
· Nonconformities and corrective actions;
· Monitoring and measurement results;
· Audit results;
· The performance of external providers;
· The adequacy of resources;
· The effectiveness of actions taken to address risks and opportunities;
· Opportunities for improvement.
[20:45] What is required of Management Review? Outputs – You will also have a number of outputs from Management Review, including:-
Opportunities for Improvement – This could be as a result or reviewing audit findings and discussing the OFI’s found and how you can address and implement these. You could also use the Management Review to review and set new objectives for the year ahead.
Any need for changes to the management system – You may need to review policies and procedures and see if they’re still fit for purpose, if they’re not then this is a good venue to discuss and update them. Other aspects that may have changed or will have a need to change include:
· Interested parties – have their needs and expectations changed?
· People – Do you need to change the people involved with certain processes?
· Awareness – Do you need to raise more awareness around a specific topic?
Resource needs – You may need to raise the need for more resourcing in regard to the management system or related processes.
If you’d like to learn about alternative ways to host a Management Review, listen to one of our previous episodes.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The importance of setting key objectives can’t be understated. They help drive continual improvement and reflect a business’s key metrics for success in various areas.
They are also a key aspect of implementing an ISO Standard, with most specifying a dedicated Objectives clause. While most businesses will have objectives irrespective of any ISO certification, many may fall into the familiar trappings of having separate objectives for different departments, which only serves to fragment your measurement of success.
In this episode Ian discusses the importance of setting key business objectives, and why you should be aligning these with your strategic direction.
You’ll learn
· What is the Annex SL format and why was it introduced?
· What is meant by ‘Strategic Direction’?
· The importance of risks and opportunities in objective planning
· Who are setting key business objectives important?
· How can you align objectives with a businesses strategic direction?
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian discusses how to align objectives with the strategic direction of the business, and why it’s important to do so.
[02:55] What is the Annex SL format and why was it introduced?: The Annex SL format refers to the standard 10 clause structure that we now see in most ISO Standards. Introduced back in 2015, it sought to address the issues with integrating multiple Standards, in addition to making them more accessible to every sector.
Prior to 2015, many ISO standards were designed with specific sectors in mind, using terminology that would make sense to them, but perhaps not to others. The Annes SL format now uses the same language across all ISO’s, making It easy to integrate multiple ISO compliant Management Systems.
[06:10] What is meant by the term Strategic Direction? Leadership: This is a term that appears in ISO 9001 5 times.
We first see it in Clause 5 – Leadership, where it states:
“Top management shall demonstrate leadership and commitment with respect to the management system by ensuring that the policy of objectives are established for the management system and are compatible with the context and strategic direction of the organisation.”
This is where it’s made explicitly clear that leadership / management are responsible for ensuring the Management System aligns with the way their business runs, in addition to integrating it into existing processes.
[07:05] What is meant by the term Strategic Direction? Management Review: It also appear in clause 9.3 Management Review, where it states:
“Top management shall review the organisation system at planned intervals to ensure its continuing suitability adequacy, effectiveness and alignment with the strategic direction of the organisation.”
Again, this reinforces the need for top management to be involved to ensure that the Management System is in alignment with their overall goals.
[08:40] What is meant by the term Strategic Direction? Context of the Organisation: It also appears at the very start of the auditable clauses, in Clause 4 – Context of the organisation, where it states:
“The organisation shall determine the external and internal issues which are relevant to its purpose and its strategic direction.”
This involves looking at issues from a legal, technical, competitive, cultural and economic point of view, and many of these will be determined by top or broader management within the business. They ultimately have the most influence in how a Management System is built, therefore have the most influence on how the policies and objectives are created.
[10:45] The importance of risks and opportunities in Objective planning – Clause 6 (Planning) is where we address risks and opportunities raised in clause 4.
It states that ‘Objectives must be established at relevant functions, levels and processes.”
For us at Blackmores, we directly relate the findings from a risks and opportunities assessment (such as a SWOT & PESTLE), and link these to our objectives to try and minimise those risks. We also leverage the opportunities, by making them real tangible goals to work towards – seems obvious but we often see businesses missing the link between these exercises!
[12:00] How can you set Objectives in alignment with Strategic Direction?: Many businesses now build their mission, values and strategic direction around sustainability and general ESG.
When building a management system, you need to consider how it affects those sustainability / ESG goals, because that is essentially the context of your organisation.
So, you’d need to consider:
How does environmental performance, health & safety performance or legal compliance contribute to the success of the management system as a whole?
You don’t have to be going for ISO 14001 or ISO 45001 for these things to matter, even a quality management system can contribute to sustainability goals. This can be through improving economic performance by reducing waste ect.
Also, don’t be afraid to relate economic performance to your management system. If you have a turnover goal of X, mention that in your context documentation, and also consider how the management system can contribute to achieving that goal i.e. through processes, controls, monitoring and improvement activity.
Also consider your client requirements, they may require an accident rate below X which can also be included in context documentation and can then be factored into your management system measures and objectives if need be to achieve that.
[16:55] How do you establish your objectives? – First you must establish context, and that context must be relevant to the purpose and strategic direction of the business. The context setting must include those who understand that context, strategic direction and the purpose of the business, the risks and opportunities must be assessed in relation to that context, which in turn is already aligned with strategic direction. Finally the objectives must be set in relation to those risks and opportunities.
It's all about having the right people to identify the relevant issues affecting the organisation, and setting concrete objectives in order to improve that.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
AI usage has skyrocketed in the past 2 years, with many commonplace apps and software now featuring an AI integration in some form.
With the rapid development and possibilities unlocked with this powerful technology, it can be tempting to go full steam ahead with implementing AI use into your day-to-day business activities.
However, new technologies come with new risks that need to be understood and mitigated before any potential incidents.
In this episode Mark Philip, Information Security Manager at Cloud Direct, joins Ian to discuss emerging AI risks and how you can build AI resilience into your existing practices.
You’ll learn
· Who is Mark?
· Who is Cloud Direct?
· How can you assess your current level of AI resilience?
· What are some of the key threats that AI systems currently face, and how can you mitigate these?
· How can you utilise AI to enhance your security?
· What is best practice when responding to an AI related security incident?
Resources
· Cloud Direct
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – We invite Cloud Direct’s Information Security Manager, Mark Philip, onto the show to discuss AI risks and how to build in AI resilience into your existing security practices.
[03:25] Who is Mark Philip?: While his primary role is as an Information Security Manager at Cloud Direct, a little known fact about him is that he is an amateur triathlete!
At London earlier in 2024, he was lucky enough to bump into Alistair Brownlee, who is the UK’s two time gold olympic medalist in triathlon.
[05:10] Who are Cloud Direct? – Founded in 2003, Cloud Direct are a Microsoft Azure expert MSP that is the top of Microsoft accreditation that any partner can hold, putting them in the top 5% of Microsoft partners globally.
They offer consultancy and professional managed services, specialising in Microsoft Cloud, which is all underpinned with security across the whole Microsoft stack. They also assist with digital transformation and modernisation.
[06:30] Assessing the current AI risk landscape: Ian points out that a recent report from the Capgemini Research Institute found that 97% or organisations are using generative AI. With this increase in AI use, there is a correlation with an increase in security incidents related to AI.
Mark adds that this technology is so new, with a lot of larger software companies such as Microsoft pushing AI elements into their tools. So there is a learning curve involved with utilising the technology.
There is also a lack of Risk Assessment being done in relation to AI, not a lot of though is going into the use of AI on a day-to-day basis. If you’re using an AI platform, you need to ask yourself:
What is this platform actually doing with the data I’m inputting?
There is also the fact that shady individuals are already leveraging this technology with the likes of deep fakes, bad bots and more sophisticated phishing schemes – and the harsh truth is that they’re going to get better at it over time.
[08:20] What is AI resilience and why is it so important? – AI resilience is about equipping businesses with the processes that control the use and deployment of AI usage, so that they can anticipate and mitigate any AI risks effectively.
Similar to ISO Standards, this would involve a risk-based approach. However, this will look very different depending on your business and how you are using AI.
For example, the risks of someone using AI to generate a transcript of meeting notes will be much lower in comparison to a healthcare company using complex sets of data with AI to synthesize new medicines.
So, if you are using AI you need to consider what the inherent risks could be, and that would be dependent on the data you’re processing i.e. is it sensitive data? And then factor in if the software is publicly available (such as ChatGPT), or it is a closed model under your control? Asking these types of questions will give you a more realistic outlook on the risk landscape you face.
[10:35] How can a business assess their current level of AI resilience? AI is here to stay, so you won’t be able to avoid if forever. So first, you need to embrace and understand it, and that includes creating a clear picture of your use cases.
Mark states they did this exercise internally at Cloud Direct when they were starting to use Microsoft’s Co-Pilot. They asked themselves:
· What sort of data is the software interacting with?
· What data are we putting into it?
· How do Microsoft manage the program and related security?
· Are Mircrosoft storing any of that data?
It’s not just about the security either, you need to understand why your using AI and if it will actually be to your benefit. A lot of people are using it because it’s new and shiny, but if it’s not actively helping you achieve your business goals, then it’s more of a distraction than anything else.
For those looking for additional guidance on AI policies, risks and resilience, there’s a lot of guidance provided by both ISO and the NCSC. ISO 42001 in particular is useful for both people using AI and developers creating AI.
If you’re stuck on where to start, a Gap Analysis is a fantastic tool to see where you are currently and what gaps you need to bridge in your security to cover any AI usage, and to see how well you are complying with current legal requirements (the EU AI Act is now in effect!). Another tool is a Risk Assessment.
You may not process what many would consider sensitive data, such as healthcare information, but even if you store and hold customer data, then you need to ensure that any AI you use doesn’t pose a risk to it.
[14:30] How can AI improve security and resilience? – Sticking with Microsoft as an example, as they are releasing a lot of AI driven tools, they can be used to fill gaps that humans may not have the time to do.
Once example of this is monitoring and sending security alerts, previously a system may have just sent this to a human member of staff to resolve, but now AI security tools can act on those alerts on your behalf.
So, if you have limited IT resources, this could be a fantastic addition to your security set-up. It also eliminates the lag of human response, and AI can look at things in a way a human wouldn’t think to.
[17:55] How do people stay ahead of the curve in the evolving AI landscape? – You should be using the myriad of resources available to learn about AI, as there are webinars, social media feeds, blogs and videos released constantly.
Microsoft in particular are offering a comprehensive feed of information relating to AI, the risks and new technologies in development.
The key is to understand AI before integrating it into your business. Don’t just jump at the new shiny toys being advertised to you, go to reputable sources such as the ICO, NCSC, Cyber Essentials and regulatory bodies to learn about the technology, the benefits it can bring in addition to the risks you need to mitigate against.
Mark can vouch for Microsoft’s though leadership in this field, as they keep all of their customers up-to-date with all of their AI related developments. Cloud Direct themselves are also putting out some great content, so don’t forget to check out their resources.
If you are already utilising Microsoft’s tools, the Cloud Direct can help explain how their new tools can apply to your business.
If you’re looking for assistance with ISO 42001, then Blackmores can help you with implementing a robust AI Management System.
[21:40] What is best practice when responding to an AI related incident? – To be honest, there’s no reason to not treat it like any other security incident. We’ve already adapted to more sophisticated security risks as a result of the move towards home and hybrid working over the pandemic.
This simply another stage along in this ever changing security landscape. You should treat it like assessing any new step, and you likely have all the processes in place for analysing risk already in place, simply apply them to the usage of AI and put in place the necessary governance based on your findings.
Standards such as ISO 20000 IT Service Management and ISO 22301 Business Continuity are fantastic tools of you’re new to this sort of incident response planning. If you’ve already been certified to these standards, then you likely have the following in place already:
· Risk Assessments
· Business Impact Assessments
· Business Continuity Plans
· Recovery Plans
Simply add AI as an additional risk factor into your existing management system and update the necessary documentation to include actions and considerations for its use.
If you update your Business Continuity and recovery plans, then make sure to test them! Don’t just assume that they will work, put them to the test and adjust until you’re comfortable that in a real incident, everyone in the business knows how to react, what to communicate and how to get back up and running.
[24:00] What are Mark’s predictions for the field of AI resilience? – People need to look at the opportunities in utilising AI, a lot of people are using it without really understanding it so there’s a lot of learning still to do.
So, he expects to see a lot of businesses fully grasping how they can use AI to their advantage in the coming years. With that comes the challenge of ensuring it’s integrated safely, with the right governance embedded to ensure its safe and ethical usage across entire organisations.
Another big challenge is the handling data privacy within AI. Scams are only going to get more complex as AI develops, and you need to ensure your business can protect against that as much as possible.
Also businesses should carefully consider what AI platforms they choose to use. Ensure you understand what data is being input and stored, and the level of control you have over it.
All of this to say, there are a lot of massive benefits of using AI and you should shy away from it. But, you need to ensure you are using it safely and ethically.
[27:30] What is Mark’s book recommendation? – The hunt for Red October by Tom Clancy
[28:45] What is Mark’s favorite quote? – “I have a bad feeling about this…” – Star Wars
Want to learn more about Cloud Direct? Check out their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The uptick in greenwashing cases, and subsequent outing of these claims only serves to make stakeholders and consumers dubious of any businesses sustainability pledges.
One key way to combat this is to have the information to back up your claims, something that is becoming a mandatory requirement for some depending on sector, location or company size.
In this episode, Mel dives into the use of ISO 14064 and how verification to this internationally recognised Standard can help companies build trust and ensure their climate action claims are genuine and impactful.
You’ll learn
· What is Greenmasking?
· Why there is a need for transparency in green claims
· What is Greenhouse Gas Statement Verification?
· What is ISO 14064?
· How can ISO 14064 Verification combat greenmasking?
Resources
· Carbonology
· 7 Shades of Greenwashing Guide
In this episode, we talk about:
[02:05] Episode Summary – In this episode, Mel delves into the world of ISO 14064 and explores how verification under this international standard can help companies build trust and ensure their climate action claims are genuine.
Catch-up with the previous episodes in the series here:
The Rise of Greenwashing
The 7 Shades of Greenwashing
[03:05] What is greenmasking?: Greenmasking (a term coined by Carbonology®) is used to describe the practice where organisations self-certify their environmental impact without independent verification.
This means they claim their green credentials are accurate while avoiding transparency about their methodology and data. Essentially, they are "marking their own homework," which can lead to misleading claims about their sustainability efforts.
This could be compared to someone completing their own MOT and signing it off themselves, instead of taking it to a qualified mechanic. Obviously, that MOT certificate wouldn’t be valid in that case, and would have no credibility when it came to selling the car.
[04:45] The need for transparency – For carbon reporting to succeed globally, enforcement will need to be standardised across all nations.
With transparency around ESG initiatives increasingly important, you need to be able to objectively and accurately measure and report on your carbon footprint. Some to keep an eye on include the Green Claims Directive and the Anti-Greenwashing Charter.
Stakeholders are now looking for independent Verification of the accuracy of your emissions data and your calculated carbon footprint through Standards such as ISO 14064-3.
[07:05] What is Greenhouse Gas (GHG) Statement Verification? - GHG Verification is the engagement of an independent third-party by an organisation to provide Verification of their GHG statements using standards such as ISO 14064-3.
Carbon footprint Verification involves, collecting data and reporting on your emissions from your company’s activities, and then independently verifying its accuracy to provide assurance to stakeholders that your claims are transparent and true.
If you’d like to learn more about the differences between the Greenhouse Gas Protocol and ISO 14064, check out a previous episode.
[08:10] What is ISO 14064-1 and ISO 14064-3? – This is the specification for Greenhouse Gas emissions reporting and part 3 is the specification for verifying that, covering more elements than the Greenhouse Gas protocol.
The reporting requires you to collect data from various sources across your scope 1, 2 and 3 emissions, collating it into a report and then have that report independently checked against the requirements of ISO 14064.
[09:45] How can Greenhouse Gas Verification combat greenmasking? –
· Highlights integrity - Verification against ISO 14064-1 highlights the veracity of your systems and processes to prove your GHG inventory, assertions and reports conform to the ISO 14064 standard; and are free from errors, omissions or misstatements, demonstrating the highest integrity of your GHG reporting.
· Validation of Net Zero goals - Verification against ISO 14064-1, establishes the integrity of your claims towards Net Zero.
· Verify success - Verification against ISO 14064-1 provides assurance of your carbon footprint declarations which will give confidence in achieving the projected emission reductions
· Stakeholder assurance - Stakeholders are increasingly looking for independent Verification of GHG Data to prove reduction are achieved year on year
Download a copy of The 7 Shades of Greenwashing from Carbonology’s website here.
If you would like some assistance with carbon Standards and reporting, simply get in touch with the team over at Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The rampant rise of greenwashing threatens to undermine genuine sustainability efforts and mislead consumers, with over 900 businesses in Europe being accused of the practice in 2024.
Greenwashing can come in many different forms, and the tactics used aren’t always easy to spot.
In this episode, Mel dives into the 7 shades of greenwashing and explains the common greenwashing tactics you should be on the lookout for.
You’ll learn
· What is Greencrowding?
· What is Greenlighting?
· What is Greenshifting?
· What is Greenlabelling?
· What is Greenrinsing?
· What is Greenhushing?
· What is Greenmasking?
Resources
· Carbonology
· 7 Shades of Greenwashing Guide
In this episode, we talk about:
[02:05] Episode Summary – In the 2nd part of this 3-part series on greenwashing, we dive into the various methods and tactics used by businesses to avoid their sustainability obligations.
[03:05] What is greencrowding?: This tactic relies on safety in numbers and occurs when different groups (like governments, organisations and companies) join forces to create the impression of making significant environmental changes.
For example, 8 of the world’s biggest 20 plastic polluters including companies such as Royal Dutch Shell, Coca-Cola, and BP are part of the Alliance to End Plastic Waste, however the group moves at the speed of the slowest member and sets low environmental targets to stall action as it is often costly and involves a lot of the companies resources and time
[03:55] What is greenlighting? – This is when companies spotlight a particularly ‘green’ product or operation which helps to draw attention away from tis otherwise environmentally damaging activities.
Commonly seen in the car industry, recent BMW campaigning highlights the company’s electric vehicles, despite being heavily invested in combustion engine vehicles therefore not addressing their major source of emissions.
Another example is Exxonmobil, who heavily advertised its “advanced biofuels” made from algae, however didn’t mention the fact that the biofuels made up a miniscule part of production. Since coming under scrutiny Exxonmobil have rescinded this project altogether and haven’t looked to practical alternatives.
[05:15] What is greenshifting? - This is where the blame gets shifted onto consumers. BP’s “Know your carbon footprint” campaign is a key example, it invited customers to share pledges for reducing their individual emissions yet BP’s core business continue to partake and scheme hugely polluting oil and gas projects.
Another example include H&M who urged consumers to recycle their old clothes yet, the company continues to be a prime culprit in fast-fashion and have a significant part to plat in over-consumerism leading to environmental degradation.
[06:10] The growing need for comprehensive carbon reporting – This occurs when companies use words like ‘eco’, ‘sustainable’ or related wording or symbols conveying green messaging with no evidence to support it.
Kohl’s and Walmart were sued for labelling toxic rayon textiles as eco-friendly bamboo.
Another more recent example is McDonald's Paper Straws where In 2019 a paper straws to introduced to replace plastic ones, claiming it was an eco-friendly move. However, it was later revealed that these paper straws were not recyclable, leading to criticism that the company was misleading consumers about the environmental benefits.
[07:15] What is greenrinsing? - This is where companies change their sustainability commitments or targets before actually achieving them.
Repeatedly, Coca-cola has missed and moved its recycling targets. Between 2020 – 2022, the company dropped its targets for using recycled packaging from 50% by 2030 to 25% proving these targets were not sufficiently made.
BP and ExxonMobil are two more examples of being criticized for frequently updating their climate targets without substantial progress. Various ambitious goals were announced over the years, but critics argue that these targets are often revised or postponed making it hard to assess real achievements and also trust between consumers, investors and legal frameworks are lost.
So the takeaway here is, make sure you’re targets are realistic!
[08:45] What is greenhushing? – This occurs when companies deliberately underreport or hide green credentials to evade scrutiny, which is a rising practice found in larger firms who struggle to successfully hit their targets/ aims.
Commonly found with firms that make distant net zero targets but do not report on progress. It allows them to hide the fact that they are not taking meaningful steps. Companies often avoid reporting positive environmental measures they may be taking to prevent greenwashing accusations which can be argued as counter-productive in the efforts to help drive systemic and industrial change in the most polluting industries.
H&M and ExxonMobil are key examples of greenhushing and no-longer actively promote their sustainability practices as they have faced criticism over false / limited actions in the past.
This one is rather damaging, especially to those who are taking meaningful sustainable action, but may not be keeping up with their targets. This is why it’s so crucial to make those targets obtainable.
If this practice continues, then there is less pressure overall for businesses to do their part for sustainability. It’s important to celebrate the victories, no matter how small, as it all adds up to the bigger picture.
[10:55] What is greenmasking? - Greenmasking (a term coined by Carbonology®) is used to describe the practice where organisations self-certify their environmental impact without independent verification. This means they claim their green credentials are accurate while avoiding transparency about their methodology and data.
Essentially, they are "marking their own homework," which can lead to misleading claims about their sustainability efforts. Some companies offer ISO 14064 consulting and verification services that may not always adhere to the rigorous standards required for genuine verification.
This can result in poor practices and undermine the credibility of the certification. For example, some consulting firms might offer ISO 14064 verification as part of their services but fail to conduct thorough and independent audits. Instead, they may ‘verify’ the data is correct in-house. This can lead to situations where companies are able to self-label their environmental impact as compliant with ISO 14064 without truly meeting the standard's requirements.
This results in a vast amount of unreliable and untrustworthy data that is purportedly verified. Furthermore, with some consultancy companies asserting that offering both consultancy and verification within the same firm is a viable option, it paves the way for poor reporting standards to be accepted, only worsening the problem in the long run.
Greenmasking can have significant implications for stakeholders, including investors, customers, and regulators, who rely on accurate and transparent environmental reporting. To combat greenmasking, it is crucial for organisations to seek independent and accredited verification of their GHG emissions ensuring that their sustainability claims are credible and based upon the rigorous standards stated in ISO14064-3.
Download a copy of The 7 Shades of Greenwashing from Carbonology’s website here.
If you would like some assistance with carbon Standards and reporting, simply get in touch with the team over at Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In a world increasingly concerned about environmental impact, companies are under immense pressure to demonstrate their sustainability credentials. But how can businesses truly differentiate themselves from those simply paying lip service to green practices?
Greenwashing is a term that you will likely be familiar with, as it’s one that’s been on the rise as consumer preference steers towards those who are seen to be doing the right thing. Alarmingly, high-severity cases, which involve companies that took a purposeful and systematic approach to concealing ESG violations, rise by more than 32% year on year.
In our upcoming 3-part series we’ll be exploring the impact of greenwashing on business, the different types of greenwashing and the role verification can play in building genuine evidence based sustainability strategies.
In this episode, Mel dives into the first of this 3-part series to explain what greenwashing is, the common tactics used in greenwashing and how businesses can build genuine sustainability.
You’ll learn
· Who is greenwashing?
· Where did the term originate from?
· The rise of greenwashing
· What are some of the common greenwashing tactics used?
· The danger of greenwashing
· How can businesses build genuine sustainability strategies?
Resources
· Carbonology
In this episode, we talk about:
[02:05] Episode Summary – We kick off our 3-part greenwashing series with an exploration of what greenwashing really is, the common greenwashing tactics businesses employ and how you can avoid those pitfalls to build genuine sustainability within your business.
[05:25] What is greenwashing?: Greenwashing, in essence, is the deceptive use of environmental claims to mislead consumers into believing a company's products or services are more environmentally friendly than they actually are.
[05:45] Where did the term ‘greenwashing’ originate from? – The term "greenwashing" was coined in 1986 by Jay Westerveld, an American environmentalist.
Westerveld first used the term in an essay describing his experience at a hotel in Fiji. The hotel encouraged guests to reuse towels to "save the environment," but Westerveld observed that the hotel was simultaneously expanding its operations, significantly impacting the local environment. This contradiction highlighted the hotel's primary intent to cut costs rather than genuinely conserve resources.
Westerveld's observation exemplified how businesses could deceptively use environmental claims to mislead consumers into believing their products or services are more environmentally friendly than they actually are.
[06:35] The rise of greenwashing: Many businesses over a wide range of industries have made a pledge to reduce their carbon impact by 2050, driven by both an increase in regulation and consumer perception.
However, the Economist highlighted some troubling research, citing that while many businesses will puff out their claims of sustainable practices, many don’t have the evidence to back them up. Many should have the resource, say an Asset Manager, that could provide tangible reports on their carbon consumption each year, and yet they choose not to publicly disclose any such reports.
So, a lot of talking the talk, but not walking the walk!
[07:40] The growing need for comprehensive carbon reporting – There are a number of sustainability and ESG regulations now in effect, with more to come in 2025 (such as the Green Claims Directive that is due to come into affect on the 27th March 2025) that require businesses of different sizes and sectors to report on their carbon consumption and reduction. If you’d like to learn more about a few of these, check out our previous episodes on:
· SECR
· ISBB S2
· CSRD
· CSDDD
[08:15] What are the common tactics used in greenwashing? These can include:-
· Vague and Ambiguous Claims: Phrases like "eco-friendly" or "sustainable" are often used without specific, quantifiable data. However, the EU Green Claims Directive, in theory help address this, although this only applied in Europe.
· Focus on Single Issues: Highlighting one minor environmental benefit while ignoring significant negative impacts across the supply chain.
· False Labels and Certifications: Creating misleading labels or misrepresenting genuine certifications. There are numerous ‘Green certifications’ out there that charge for a badge, without providing any evidence, of for those that do provide information it could just be a document that isn’t evidence based i.e. a Policy statement or ‘pledge’ or ‘commitment’
· "Greenwashing by Association": Implying a connection to environmental causes through sponsorships or marketing campaigns.
[10:15] The danger of greenwashing – The danger with greenwashing is the negative impact it has through an Erosion of Consumer Trust. People are becoming increasingly skeptical of environmental claims, making it harder for truly sustainable companies to gain credibility.
Greenwashing can also lead to Distorted Market Signals: creating a false impression of progress, hindering genuine innovation and investment in sustainable solutions.
[11:30] How can businesses build genuine sustainability strategies?
· Transparency and Accountability:
Seek independent third-party verification of sustainability claims.
Focus on Life-Cycle Assessment:
Evaluate environmental impacts across the entire product or service lifecycle, from raw material extraction to end-of-life disposal.
Continuous Improvement:
Regularly review and refine sustainability strategies based on performance data.
Engage with Stakeholders:
If you would like some assistance with carbon Standards and reporting, simply get in touch with the team over at Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The end of another year has rolled around in the blink of an eye! We’ve managed to publish a whopping 42 episodes this year, pushing us over the 200 episode mark.
We want to thank all our listeners, both old and new, for allowing us to continue to share both ISO tips and success stories from our wonderful clients. We hope you’ll follow along as we continue our podcasting journey in 2025.
To close out the year, Ian Battersby and Steve Mason share some of their stories of misadventures during audits, from common mistakes, to broom battles and forklift mishaps, they really have seen it all! Listen, laugh and learn what not to do during an audit.
You’ll learn
· What not to do in an audit
Resources
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – Ian and Steve share some of their experiences from their time as auditors. From common mistakes to outlandish situations that you’d have to see to believe, listen and learn what shouldn’t happen during an audit.
[03:40] Lazy Copycats: Steve recounts a time where a company had copy and pasted their Management Review for years, which rightfully earned them a non-conformity.
Ian shares a similar story where a construction company submitting a tender had copy pasted the content and included the wrong company name!
The copying doesn’t stop there, as Steve remembers a company Quality Manual that managed to include multiple company names. It was found that they’d simply copy and pasted example pages they’d found online that looked good, but didn’t bother to update any of the content to be relevant to them.
[06:30] Training Troubles – Ian recounts a time where he was auditing a subcontractor for a construction company that required a record of training. The induction was very important and obviously needed to be documented.
When he checked the documents, though all the forms had different names, all the signatures suspiciously had the exact same handwriting! Turns out the Director was signing them all off, which is obviously in breach of a number of health and safety related regulations.
[08:00] IT Security slip-ups – Steve recounts a time where a Finance Director had good intentions, but poorly implemented his idea. The Finance Director didn’t trust their IT system back-up and instead backed-up all his information on a memory stick.
Steve had pointed out the flaws with this, such as losing the memory stick, data getting corrupted ect. It just simply isn’t a safe or reliable way to store such important information.
[09:05] Disconnected Leadership – Ian shares a time where an auditor caught the lack of leadership commitment to their management system. Despite it being a very nice looking management system by all accounts, the cracks showed enough for an outsider to spot the flaws.
Steve adds that sometimes, you can over engineer a management system to a point past useful. It needs to work for your business, otherwise people will work around it to get what they need done.
Steve had a rather obvious example if this when he required a chat with a member of leadership, who refused on the day initially, despite it being scheduled for 6 months. The person relented a few minutes over lunch where he posed his complete commitment to BS 5750 – A standard that existed 20 years ago and had since been replaced by ISO 9001. Very telling for his level of ‘commitment’.
As we have covered in a previous episode – Leadership commitment is imperative to a successful management system.
[11:40] Skip Diving for Secrets – Steve shares his experience of conducting a skip diving exercise, which is following a document waste trail. At a certain company, they ended up looking in an actual skip only to find what looked like a lot of confidential documents, when questioned someone had said that they looked like they belonged in the CEO’s filing cabinet.
When questioned, the CEO remarked ‘I didn’t want you to catch me with anything that I shouldn’t have, so I threw it all out last night’.
This warranted a non-conformity as anyone could have gone past and fished out that confidential information just as Steve had.
Ian also adds a time where he worked in the NHS and a local hospital had an accident where a lot of confidential medical files ended up scattered across the floor. These were documents that should have been disposed of securely.
[14:05] PPE? You’ve got to be kidding me! – Ian recounts a time working for a manufacturing company that was part of a large international firm. Their UK operation had to abide by strict PPE requirements, proper shoes, eye protection ect. It was something that everyone on the premises had to adhere to.
One day, a Director walked in with none of the PPE which was clearly labelled on many of the signs decorating the shop floor. He had incorrectly assumed that because of his position, he could walk around with no PPE whatsoever. Fortunately the shop floor supervisor set him right and sent him to get properly suited up.
[15:35] Data Centre security says no – Steve recalls a time when a member of top management went to visit one of their own data centre’s, on getting to the gate the security had told him ‘I don’t care who you are, your name isn’t on the list so you’re not getting in.’
That person hadn’t gone through the process of being approved for entry. Yet, predictably, they sent complaints everywhere, but the head of the UK branch had quite rightly praised the security personnel for simply following protocol.
[16:55] Private bank details? Don’t mind if I do! – While Steve was auditing physcial security for an office, a printer ended up printing the payroll of every employee at the business. This wasn’t in a private room, this was in the middle of the office, so anybody could walk up and see bank account details and salaries!
When questioned, it turned out their Finance Director was working from home, and hadn’t bothered to contacts anyone to retrieve the documents. So unsurprisingly, they received a non-conformity.
[19:55] Do not goad the auditor - A bit of advice from Steve “Never say ‘this is our most secure room’ to an auditor” – that is essentially a challenge, and one that you’ll likely lose if you don’t follow your own processes.
Steve put this to the test when someone had claimed only 3 people had access to a certain room. Out of curiosity, Steve used his visitor badge to gain entry, and asked if he was included in that 3. Obviously he wasn’t, and this was simply down to access control being a bit muddled at that particular company.
[21:25] Mistaken Identity: Steve recalls a time when he was given a visitors badge with a completely different person as the photograph. It had no effect on the correct access rights, but amusing all the same.
He shares another story where he shared a waiting room with another Steve. When they called only the first name, the other Steve was taken into that business and questioned on ISO, to which the poor man had to inform them that he had no idea what they were talking about! Shortly after, the correct Steve was collected. But it goes to show how important it is to ensure you’re giving access to the right people.
[24:20] Battle of the Broomsticks: Ian recalls another time when working in construction, when he had the opportunity to work at a horse racecourse. They were looking to achieve what was OHSAS 18001 at the time (now known as ISO 45001), and it was going so well until a few new hires came running across the stable yard wielding 2 brooms, battling like gladiators in view of their auditor.
Thankfully they weren’t really harming each other, but it was enough for the auditor to raise a few questions about subcontractor controls. You really couldn’t write the timing any better (or worse, I suppose!).
[26:15] Clearly a certified forklift driver: While Steve was working at a warehouse, the manager there stressed how well trained all of their forklift drivers were, how sensible they all were.
Though, Steve could see a person dancing, speeding and popping wheelies with his forklift over the managers shoulder. After he’d been alerted to the wannbe stunt driver, the manager went to have a word with them.
[27:30] Accidents don’t happen after 5pm: Ian was working at a company that highly valued the use of PPE on-site, everyone did a good job of abiding by that, until it came to the end of the day. One person leaves across the shop floor in just a normal t-shirt and jeans, waving them all off happily as he leaves for the day.
He still had to cross the shop floor, and being off the clock doesn’t make you invincible.
[29:10] Fire Door Dramas: Steve recalls a time during an ISO 9001 audit where he spotted a fire door had been blocked by pallets in a warehouse.
Another time he saw a fire door that was actually chained and padlocked!
On another occasion, a local council had put their rubbish bins outside the fire door for the building, and during a fire drill, they couldn’t get out.
Ian states how many times he’s seen signs ignored by drivers who park in front of fire exits. All this to say that a little awareness goes a long way.
[31:10] Emergency Plans for the avid reader: During an incident at an NHS hospital where they’d suffered a long term major power outage, Ian and the staff had found that the emergency plans were 144 pages long! With Senior responsibilities hidden away in an Appendix on the last few pages.
Well thought out plans are necessary, but the actual procedure needs to be something that can be followed in the event of an emergency. A little common sense should be applied when deciding what needs to be communicated.
[34:00] Risk Assessment disaster: While working with a team in a manufacturing plant, Ian helped them to streamline their risk assessment process as their previous one needed too many signatures to actually go anywhere. This bottleneck was resolved with months of hard work, or so they thought…
When it came to being audited, the auditor asked the team manager what happened to all of the risk assessments, he’d then pointed towards the Health & Safety Management and claimed they had them all, who had to admit that he didn’t.
Later that evening a director called the administration and asked to hide all of the documentation, to which she rightly refused to do. This also linked back to when the auditor had asked about how the apprentices were trained, and it happened that the apprentice supervisor was on holiday and so they were just let onto the shop floor. Suffice to say, this didn’t reflect well on the resulting audit results.
[36:30] Against the wire: Ian states that manufacturing companies are not famous for admin. He had one experience while trying to get a recertification booked in, which went up against the wire for their current certification running out.
The CB obliged and sent a very qualified Health & Safety assessor there, who took them to pieces. It didn’t take long for him to point out that they had a really nice management system with no commitment from managers to use it.
A word to the wise – don’t leave your recertification up until the last minute! If a CB tried to move your recertification past that expiry date, you can and should push back.
[39:00] Password palavers: Steve shares an experience when he interviewed a very organised PA who managed 7 Directors. At the end of the audit he pointed out a folder on her computer called ‘passwords’, to which she obliged to show him the contents. Predictably it contained all the usernames and passwords for various accounts the Directors owned.
She knew about the secure passwords policy, but no one could realistically remember that many! When Steve questioned the technical team, they states only selected people needed one, and she wasn’t one of them. Steve pointed out that she did, and had done the best she could with the tools available, and gifted them a non-conformity as a result as they hadn’t done a good job of ascertaining who should get additional security tools.
By the end of that day, the PA had their own password vault.
[41:30] A fire extinguisher as useless as a chocolate teapot: In another company Steve had noted that they still had a black fire extinguisher. When asked, the staff replied that they were all up-to-date as of 2007. On checking, it was revealed that it had last been serviced in August 1997 – so no, it was not in fact ‘up-to-date’.
It may be innocuous to some, but when it comes to safety equipment, that could be the difference between life and death in an emergency.
[42:40] Technophobes in a modern age: Ian recounts a past quality audit he did for an engineering company. They require a lot of specific ISO Standards for that industry, and so the company paid a subscription service to ensure they had digital copies of all these Standards to refer back to.
One such standard was on verification, and on asking a particular quality engineer about how he verifies a specific product, he pulls out a printed hard copy of a standard from 1993. Ian was interviewing him in 2017, there had been at least 2 updated versions of the Standard out by that point. When probed about why he wasn’t using the online standards library paid for by the company, he simply stated ‘I don’t like computers’.
[45:00] The case of the mysterious ghost file: Steve once had an audit with a relatively nervous member of staff, after explaining that all he has to do is explin how he works, the interview went rather smoothly.
At one point he photocopied a bit of paper, hole punched it and filed it away on a shelf in the corner. Steve initially thought ‘good admin, he’s clearly following a process’, so when he returned Steve asked why he filed that particular bit of information away, to which the staff member said ‘I don’t know, I’ve just been told to do it’.
Steve then questioned the Quality Manager there about that document and they replied with the same. He then questioned the warehouse personnel to get the same answer.
So, you have this document being photocopied over and over, filed away each time and no one knows why! Steve politely pointed out that it might be a good idea to rethink that pointless process.
[47:50] Useless numbering systems: Ian had a similar experience with a numbering system that nobody knew the origins of. The staff involved simply shrugged it off and stated it was simply just what they used.
Ian decided to put something to the test, by getting rid of it. He removed an entire archive system from a company’s network folder, as back then file space was a big cost and concern. He kept the files and waited to see if anyone actually needed them. After months, he only had 2 requests for documents.
It’s important to ask both what is and isn’t working well. Getting input from all levels of staff can be eye opening, and empower those employees who can help shape up company processes to work more efficiently.
[49:50] Allergic to Audits: Ian shares a secondhand story where a trainer for the HSE was conducting a site visit, where he needed to question the shop supervisor on a few things. He asked him for something he couldn’t see, and the guy agreed to go get it, and just never came back. Apparently he was so scared of the auditing process that he just went home!
[54:00] Shady police and stolen cars: One of Steve’s previous clients had an experience where what they thought was a policeman asked about a hire car the company owned, stating it had been involved in a crime. They didn’t think much of letting him take it for his ‘investigation’.
Later when the hire company asked about getting their car back, the staff let them know what happened, rightly confused this led to a lot of discussion. As you can probably tell, the man was not a policeman and had made off with a nice shiny BMW simply by asking for it.
If something like this happens to you, always ask for documentation from the police.
[55:00] The Great Computer Caper: Ian recalls a training centre incident where a lot of computer equipment is stored in one suite. One day a few guys came in and started lifting stuff out, people were holding doors open for them, not at all thinking them to be thieves. Low and behold, they were and took everything.
Steve recounts a very similar experience where the thieves posed as a computer service company, stripping the entire office on a Friday afternoon. It wasn’t until Monday when everything was still gone that people thought to question who those people really were.
Thank you all for a great 2024, we look forward to bringing you more ISO tips and success stories in 2025.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
On average, international events emit over 2,000 tonnes of greenhouse gases, which is the equivalent to what 270 UK citizens emit in a whole year.
The events industry has been under scrutiny for a number of years in regard to its sustainability, with many factors such as international and domestic travel and exhibition waste to consider, it’s quite a beast to tackle!
Back in 2012, to coincide with the London Olympics, a new Standard dedicated to Sustainable Events Management was launched. ISO 20121 provides a robust framework for those seeking to take actionable steps to tackle their sustainability, such as todays’ guest FESPA.
In this episode Ian is joined by Graeme Richardson-Locke, Head of Associations & Technical Lead at FESPA, to discuss FESPA’s journey towards achieving ISO 20121, the challenges faced along the way and benefits felt from certification.
You’ll learn
· Who is Graeme Richardson-Locke?
· Who are FESPA?
· What was the main driver behind obtaining ISO 20121?
· What was the biggest gap identified in the initial Gap Analysis?
· What did FESPA learn from the experience of implementing ISO 20121?
· What are the main benefits of ISO 20121 certification?
Resources
· FESPA
· FESPA Sustainability Spotlight
· Isologyhub
In this episode, we talk about:
[02:05] Episode Summary – We welcome today’s guest, Graeme Richardson-Locke, Head of Associations & Technical Lead at FESPA, to discuss their journey towards achieving the best practice standard for Sustainable Event Management – ISO 20121.
[02:40] Who is Graeme?: Graeme has spent 40 years in the print sector, from textiles to graphics to industrial printing. Starting from an apprenticeship in screen printing, which moved onto industrial printing and then finally into digital print.
A little known fact about Graeme, he used to live on a goat farm on the Isle of Isla in the inner Hebrides. He speaks fondly of his time in a small community of just over 3,000 people, taking long walks and admiring the rich landscape.
[06:00] Who are FESPA? – FESPA is the global Federation of National Specialty Print Trade Association.
They work to support visual communication businesses in wide format and production of wide format products, so this includes things like garment decoration, interior décor, signage and industrial products.
Their association have members across 37 countries with around 1400 businesses within their membership. They ultimately seek to reinvest their profits for the purpose of inspiring, educating and growing the industry.
Their roots can be found in creativity, with some of their founding members coming from a background of screen printing.
[09:55] What is the scope of FESPA’s ISO 20121 certification? Currently it extends to their major European based exhibition – Global Print Expo, which also includes their European Sign Expo.
They thought it best to roll out certification to the Standard against their largest event.
Outside of the certification scope (so far) they do run events in Mexico, Brazil, Africa and the Middle East. It would be much too large of an undertaking trying to certify all their events initially, so they started with the European events with a view to expand their scope of certification at a later date.
[11:05] What was the main driver for achieving ISO 20121? Their was a clear need for sustainability related materials to be made available to their members. So FESPA started to develop a guide on sustainability certification schemes, a glossary of terms and a calculating carbon guide.
As a result, they set-up a feature on their website called Sustainability Spotlight, which highlights new sustainability produced materials coming to market. So it was clearly a topic of focus for their members.
They also sought to increase the positive impact they can have within their community, reduce the negative impacts and further develop their overall value.
[13:05] The ethical way forward – As an internal advocate, Graeme wanted to put forward a proposal for something that was really meaningful and not just a greenwashing exercise. This is something that seeking certification, which includes third-party verification, can provide.
[13:35] How long did it take FESPA to achieve ISO 20121? – FESPA began looking into the Standard back in 2022, but it was mired with other turbulence that needed their focus. The pandemic, the war in Ukraine, supply disruption and inflation, there was a lot happening in a short space of time.
They made a start on their journey in the Summer of 2022, but it was slow going as they were still building back from the pandemic. The slow burn picked up speed in 2023, with their certification being secured in May 2024.
[15:45] What was the biggest Gap identified during the Gap Analysis? FESPA have a lot of talented members, with a lot of competence, but the experience of creating formalised policies, procedures and a Management System that had to meet the set requirements of the Standard was a learning curve.
FESPA didn’t have the benefit of other ISO certifications, and this was the first time they were implementing an audited Standard, so the whole process was very eye opening.
[16:40] What impact did Implementing ISO 20121 have on FESPA? It provided a new perspective on their business, and has helped to develop a greater awareness of sustainable development opportunities.
An example of this includes when they started to really dig deeper into how they build and run events, from stand materials to catering. They found that switching their stand build materials to fiber build materials reduced their carbon footprint by 90%!
By simply thinking more carefully about what they were doing, they managed to make a massive carbon reduction, with an appetite to reduce this even further.
They worked with a company called Quota to calculate their carbon emissions, as they didn’t have that particular expertise in-house.
With that massive reduction as a motivator, they are now looking at stand material lifecycle, with a view to use more recycled materials that can be reprocessed.
[19:00] An eye opening experience - Completing exercises like a SWOT and PESTLE and rolling out a risk register which is reviewed on a quarterly basis, allows them to really keep an eye on how things are changing and any available opportunities.
All of these feed into their objective setting for the next year, establishing a solid path of progression to drive the business forward.
[20:10] Keeping up with an ever changing world: FESPA have molded their Management to suit the way they work, which is not linear.
Venues change ever year, and it’s critical that their management system assist in asking the right questions for new event locations.
One of their recent events took place in The Rye in Amsterdam, and they had zero emissions relating to energy because the Rye had their own sustainability related policies and procedures in place.
[21:15] The event industry’s collective effort: Many venues and other businesses involved in the events sector are large organisations with high energy consumption.
Many will already fall under legislative requirements to address and reduce their energy consumption. So, everyone is working in step with each other for the most part.
FESPA’s own members are showing trends of steering more towards utilising more sustainable materials such as recycled fabrics, as these have less weight, less cost to ship and more opportunity for reprocessing.
It’s still very much a work in progress, but it’s being driven in the right direction.
[24:20] Graeme’s Top Tip: The power of systematic thinking, Implementing a Management System requires a new way of working.
Graeme ran into trouble when first providing auditable evidence, as it was not something FESPA had ever done before. They encountered a minor non-conformance for F gas leakage in their head office air conditioning, and while they could confirm that their provider was F gas certified but they hadn’t checked to make sure the certificate was in date.
Little examples like this proved that they need a more systematic approach in all aspects of the business to ensure they complied with all relevant regulations, while also providing a solid framework for continual improvement.
[26:15] Celebrating ISO Success: Graeme was fortunate to attend a Certificate ceremony, put on by their Certification Body, BSI. The acknowledgement of not only his effort, but others who had been through a similar experience made for a fantastic celebration of FESPA’s achievements.
[27:20] Graeme’s book recommendation: Green Swans, The Coming Boom in Regenerative Capitalism – By John Elkington
[29:15] Chris’s favourite quote: The biggest threat to this planet is the belief that someone else will save it – Robert Swan
If you would like to learn more about FESPA, and their sustainability initiatives, visit their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
AI has been integrated into almost every aspect of our lives, from everyday software we use at work, to the algorithms that determine what content is recommended to us at home.
While extraordinary in its capabilities, it isn’t infallible and will open up everyone to new and emerging risks. Legislation and regulations are finally catching up to the rapid adoption of this technology, such as the EU AI Act and new Best Practice Standards such as ISO 42001.
For those looking to integrate AI in a safe and ethical manner, ISO 42001 may be the answer.
Today Rachel Churchman, Technical Director at Blackmores, explains what ISO 42001 is, why you should conduct an ISO 42001 Gap analysis and what’s involved with taking the first step towards ISO 42001 Implementation.
You’ll learn
· What is ISO 42001?
· What are the key principles of ISO 42001?
· Why is ISO 42001 Important for companies either using or developing AI?
· Why conduct an ISO 42001 Gap Analysis?
· What should you be looking at in an ISO 42001 Gap Analysis?
Resources
· Register for our ISO 42001 Workshop
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Rachel Churchman joins Steph to discuss what ISO 42001 is, it’s key principles and the importance of implementing ISO 42001 regardless of if you’re developing AI or simply just utilising it.
Rachel will also explain the first step towards implementation – an ISO 42001 Gap Analysis.
[02:45] Upcoming ISO 42001 Workshop– We have an upcoming ISO 42001 workshop where you can learn how to complete an AI System Impact Assessment, which is a key tool to help you effectively assess the potential risks and benefits of utilising AI.
Rachel Churchman, our Technical Director, will be hosting that workshop on the 5th December at 2pm GMT, but places are limited so make sure you register your place sooner rather than later!
[03:20] The impact of AI – AI is everywhere, and has largely outpaced any sort of regulation or legislation up until very recently. These are both needed as AI is like any other technology, and will bring it’s own risks, which is why a best practice Standard for AI Management has been created.
If you’d like a more in-depth breakdown of ISO 42001, check out our previous episodes: 166 & 173
[04:30] A brief summary of ISO 42001 – ISO 42001 is an Internationally recognised Standard for developing an Artificial Intelligence Management System. It provides a comprehensive framework for organisations to establish, implement, maintain, and continually improve how they implement and develop or consume AI in their business. It aims to ensure that AI risks are understood and mitigated and that AI systems are developed or deployed in an ethical, secure, and transparent manner, taking a fully risk-based approach to responsible use of AI.
Much like other ISO Standards, it follows the High-Level Structure and therefore can be integrated with existing ISO Management systems as many of the core requirements are very similar in nature.
[05:45] Why is ISO 42001 important for companies both developing and using AI? – AI is now becoming commonplace in our world, and has been for some time. A good example is the use or Alexa or Siri - both of these are Large Language AI Models that we all use routinely in our lives. But AI is now being introduced in many technologies that we consume in our working lives - all designed to help make us more efficient and effective. Some examples being:
· Microsoft 365 Copilot
· GitHub Copilot
· Google Workspace
· Adobe Photoshop
· Search Engines i.e. Google
Organisations need to be aware of where they're consuming AI in their business as it may have crept in without them being fully aware. Awareness and governance of AI is crucial for several reasons:
For companies using AI they need to ensure they have assessed the potential risks of the AI such as unintended consequences and negative societal impacts, or potential commercial data leakage. They also need to ensure that if they are using AI to support decision making, that they have ensured that decisions made or supported by AI systems are fair and unbiased. It's not all about risk - organisations can also use AI to streamlining processes helping to become more efficient and effective, or it could support innovation in ways previously not considered.
For companies developing AI, the standard promotes the ethical development and deployment of AI systems, ensuring they are fair, transparent, and accountable. It provides a structured approach to risk assessment and governance associated with AI, such as bias, data privacy breaches, and security vulnerabilities.
And for all, using ISO 42001 as the best practice framework, organisations can ensure that their AI initiatives are aligned with ethical principles, legal requirements, and industry best practices. This will ultimately lead to more trustworthy, reliable, and beneficial AI systems for all.
[10:00] Clause 7.4 Communication – The organisation shall determine the internal and external communications relevant to the system, and that includes what should be communicated when and to who.
[09:00] What are the key principles outlined in ISO 42001? –
· Fairness and Non-Discrimination - ensuring AI systems treat all individuals and groups fairly and without bias.
· Transparency and Explainability - Making AI systems understandable and accountable by providing clear explanations of their decision-making processes.
· Privacy and Security - Protecting personal data and privacy while ensuring the security of AI systems.
· Safety and Security - Prioritising the safety and well-being of individuals and the environment by mitigating potential risks associated with AI systems.
· Environmental & Social - Considering the impact of AI on the environment and society, promoting sustainable and responsible practices.
· Accountability and Human Oversight - Maintaining human control and responsibility for AI systems, ensuring they operate within ethical and legal boundaries. You'll often hear the term 'Human in the loop'. This is vital to ensure that AI is sanity checked by a human to ensure it hasn't hallucinated or result ‘drifted’ in any way.
[11:10] Why conduct an ISO 42001 Gap Analysis? What is the main aim? – Any gap analysis is a strategic planning activity to help you understand where you are, where you want to be and how you’re going to get there. The ISO 42001 gap analysis will identify gaps and pinpoint areas where your AI practices need to meet the ISO 42001 requirements.
It aims to conduct a systematic review of how your organisation uses or develops AI to then assess your current AI management practices against the requirements of the ISO 42001 standard. This analysis will then help you to identify any "gaps" where your current practices do not fully meet the standard's requirements. It also helps organisations to understand 'what good looks like' in terms of responsible use of AI.
It will help you to prioritise improvement areas that may require immediate attention, and those that can be addressed in a phased approach.
It will help you to understand and mitigate the risks associated with AI.
It will also help you to develop a roadmap for compliance to include plans with clear actions identified that can then be project managed through to completion, and as with all ISO standards it will support and enhance AI Governance.
[13:15] Does an ISO 42001 gap analysis differ from gap analysis for other standards? – Ultimately, no. The ISO 42001 gap analysis doesn't differ massively from other ISO standard gap analysis, so anyone who already has an ISO Standard and has been through the gap analysis process will be familiar with it.
In terms of likeness, ISO 42001 is similar in nature to ISO 27001 in as much as there is a supporting 'Annex' of controls and objectives that need to be considered by the organisation. Therefore the questions being asked will extend beyond the standard High Level Structure format.
Now is probably a good time to note that the Standard itself is very informative and includes additional annex guidance information to include
· implementation guidance for the specific AI controls,
· an Annex for potential AI-related organisational objectives and risk sources,
· and an Annex that provides guidance on use of the AI management system across domains and sectors and integration with other management system standards.
[14:55] What should people be looking at in an ISO 42001 gap analysis? – The Gap Analysis will include areas such as looking at the 'Context' of your organisation to better understand what it is that you do, or the issues you are facing internally and externally in relation to AI - both now and in the reasonably foreseeable future, and also how you currently engage with AI in your business. This will help to identify your role in terms of AI.
It will also look at all the main areas typically captured within any ISO standard to include leadership and governance, policy, roles and responsibilities, AI Risks and your approach to risk assessment and treatment and AI system impact assessments. It also looks at AI objectives, the support resources you have in place to manage requirements, awareness within your business for AI best practice and use, through to KPI's, internal audit, management review and how you manage and track issues through to completion in your business.
The AI specific controls look more in-depth at Policies related to AI, your internal organisation in relation to key roles & responsibilities and reporting of concerns, The resources for AI Systems, how you assess the impacts of AI Systems, The AI system lifecycle (AI Development), Data for AI Systems, Information provided to interested parties of AI Systems, and the use of AI Systems and 3rd party and customer relationships.
[18:10] Who should be involved in an ISO 42001 Gap analysis? – An ISO 42001 gap analysis looks at AI from a number of different angles to include organisational governance that includes strategic plans, policies and risk management, through to training and awareness of AI for all staff, through to technical knowledge of how and where AI is either used or potentially developed within the organisation. This means that it is likely that there will need to be multiple roles involved over the duration of a gap Analysis.
At Blackmores we always provide a Gap Analysis 'Agenda' that clearly defines what will be covered over the duration of the gap analysis, and who typically could be involved in the different sessions. We find this is the best way to help organisations plan the support needed to answer all the questions required.
It's also important to treat the gap analysis as a 'drains up' review, to help get the most benefit out of the gap analysis. This will ensure that all gaps are identified so that a plan can then be devised to support the organisation to bridge these gaps, putting them on the path to AI best practice for their business.
If you’d find out more about ISO 42001 implementation, register for our upcoming Workshop on the 5th December 2024.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
One of the biggest contributors to a stagnating ISO Management System is a failure to communicate.
This has certainly been true in our experience with implementing ISO Standards for over 18 years, and as a result, we make sure to highlight awareness and communication as an integral step of the Implementation process.
It’s a wasted effort only to have your management system gathering dust in a rarely visited folder on your server. If you want to reap the benefits of ISO implementation, it’s in your best interest to make everyone aware of their role in relation to your management system and its continual improvement.
Today Ian Battersby explains what ISO Standards mean by awareness and communication, why they are so integral to a successful management system and how you can effectively communicate your management system.
You’ll learn
· What does awareness and communication mean in relation to ISO Standards?
· Why should you communicate your management system?
· The benefits of management system awareness
· How can you effectively communicate your ISO management system?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian Battersby will be explaining what ISO Standards mean by awareness and communication, and why they are so integral to a successful Management System.
[02:30] What is awareness and communication so important?– The success and failure of a management system depends on it’s existence being known and understood within an organisation.
Staff have a key part to play, and they need to know their part in the Management System and how it aligns with the organisations direction.
[03:20] Extra guidance available for awareness and communication – There is a Standard that accompanies ISO 9001, called ISO 9004:2018 – Quality of an Organisation: Guidance to achieve sustained success.
This is a great companion to any Standard, as it provides general guidance on how to properly embed a management system within your business.
It talks at length about people and the need to ensure that they are competent, engaged, empowered and motivated. These are crucial as:
Engagement of people enhances the organisations ability to create value for interested parties.
Empowerment motivates people to take responsibility for their work and the results of their work.
These can be achieved by providing people with necessary information with authority and the freedom to make decisions related to their own work.
People should understand the significance and importance of their role, specifically in creating that value to meet and exceed customer expectations.
[05:30] What should be communicating according to ISO Standards? – Taking ISO 9001 as the example, because it is the basis for most ISO Standards, it has a specifies the following:
5.2.2 Quality Policy - The policy should be available and maintained as documented information, so must be issued somewhere so that people can see it. But it also, quite importantly, must be communicated, understood and deployed within the organisation. It also needs to be made available to other relevant and trusted parties.
5.3 Organisational roles, responsibilities and authorities - Top management have a responsibility here. They must ensure that responsibilities and authorities for relevant rules are assigned, communicated and understood within the organisation. There’s a lot to consider here as this will also take into account for ensuring processes are delivering expected outputs, the reporting of system performance and improvement and the promotion of customer focus throughout the organisation.
6.2 Objectives - The organisation should establish objectives. These will be targeted at relevant functions, levels and processes and should be communicated to the relevant people affected by those objectives.
7.3 Awareness – Includes the specification that anyone working under the organisations control, so this could include indirect workers, must be aware of your quality policy. Also included is the awareness of objectives and staff’s contribution to the effectiveness of the management system. People aslo have to be aware of the implications of not conforming to the requirements of the management system or standard.
[09:30] The implications of not following requirements – You need to consider what happens if someone doesn’t follow a process. For Standards such as ISO 45001 Health & Safety management, following processes could be a matter of someone getting hurt or breaking the law.
[10:00] Clause 7.4 Communication – The organisation shall determine the internal and external communications relevant to the system, and that includes what should be communicated when and to who.
[10:30] When should you deliver ISO Management System awareness and communication training? – If you’re just starting out on your ISO Implementation journey, it’s crucial to communicate at the outset the importance of the process of achieving certification.
The level of awareness will vary depending on people’s roles, i.e:
Top Management: Top management must understand the role of the management system in relation to the strategic direction of the organisation as part of context, they must understand what the management system contributes to the overall business outcomes. While top management don't need to know standards inside out, they must be aware and must have understanding of the overall purpose of the standard and the benefits that standard will bring to the organisation.
To gauge the level of awareness top management need, ask yourself, would you be happy to let them be interviewed in private by a third-party assessor in regards to all of their responsibilities in relation to the management system?
[13:20] General awareness for the workforce– While leadership require a greater level of awareness, there is still a need for general staff to have a certain level of management system awareness.
For those on their first implementation journey, you should bring people in from the very beginning, this includes all staff and those working indirectly under your organisation.
You will want to make them aware of the following:
What is a quality management system? – Define what it is and what it means
What’s important about the Standard? – People don’t need to know the intricacies of standard subclauses, so just select important aspects such as the Plan Do Check Act (PDCA) cycle
If you’re integrating Standards, what are some common requirements? – If you’re integrating a new standard, what requirements specific to that new standard need to communicated?
[15:15] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[17:20] General awareness for the workforce continued – You will also need to make sure people are aware of:
What do they need to know in relation to certification? – This can include the date you’re working towards, what might be expected of them during an ISO assessment, what does the certification actually mean for the business?
Accessing the Management system – How can people find your management system? What documents does it hold? How do you use it? And how does this impact on staff’s day to day activities?
Staff’s role in relation to the Management system – How do staff contribute to the management system on a daily basis? How do they contribute to business objectives?
How does the management system benefit them? – Your management system will include tools and guidance on how to carry out certain activities. It explains how improvements can be suggested and made and how audits work. Ultimately it provides a structured approach to ensure everyone is singing from the same song sheet.
The importance of complying with policies, processes and procedures – including the consequences of not complying with them.
Raising issues relating to non-conformity, the effectiveness of the management system and any potential improvements – You can’t have eyes everywhere, and the people working in alignment with your processes can better highlight where something may not be working. This also increases engagement as people will have a real impact on how your business operates.
[20:15] Specific standard considerations for communication – The focus of elements of your communication will be tied to the specific ISO Standard you’re implementing.
I.e. A Health & Safety management system will include communication of key risks and hazards, how to report safety issues and abiding by Health & Safety law
Environmental management systems may include awareness of the need to protect the world we live in, how each person can help lessen their impact on an individual scale ect.
[21:00] Other key roles and related communication – There are other key roles within the organisation which will have specific communication requirements.
These will be people like operational functional managers with key roles in processes they may be involved in, i.e. sales, design, purchasing, calibration ect.
If they've got specific functions in the organisation with respect to the management system, they need to understand them as much as top management needs to know theirs and the general workforce need to know theirs.
[21:50] Communicating key changes to the Management system – You need to continually communicate to the workforce when changes occur to the management system. That communication doesn’t stop as soon as you’re certified!
For first time implementation, you’ll want to communicate when you’ve achieved certification.
[22:30] The importance of communication within a Management System – If people are aware of their role and importance to a management system, they will be more engaged with its operation.
This can include reporting on objectives progress during team briefs, raising potential issues and non-conformities or opportunities for improvement, highlighting customer complaints, monitoring number of incidents at work ect
All of these contribute to the success of the business and need to be reported on continually.
These can turn into lessons learned, which could lead to major system changes where documentation or processes need to be updated and communicated.
[24:30] What’s the best way to communicate your ISO management system? – Not all organisations are the same, so there is no right or wrong way to do so. A few suggestions include:
· SharePoint
· Teams Channel
· E-mail / internal newsletters
· Bulletins
· In-person training
· Videos
For any of the above you may need to consider how to record who has completed set awareness training.
[25:30] A final thought – If an auditor stops and asks a worker about your quality policy, what will that person say to that auditor?
We understand that the quality policy must be communicated, but how does each person understand it?
Your awareness raising needs to capture methods of ensuring that that happens, which is a tricky task!
They do not need to know a Standard verbatim, but they should know the importance of complying with it, what a non-conformity within that system means, and what are the consequences are if they don’t follow the rules.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
A crucial part of Implementing any ISO Standard is addressing your risks and opportunities.
This is a key part of Clause 4 Context of the organisation, which expresses and explicit need to review and assess what internal and external factors could help and hinder in achieving your business goals.
While ISO Standards don’t define a definitive method of doing so, many have adopted the practice of carrying out a SWOT and PESTLE analysis.
Today Ian Battersby explains what a SWOT and PESTLE analysis is, the key questions you should be asking and the importance of continually reviewing and updating the results as your management system matures.
You’ll learn
· What is a SWOT analysis?
· What is a PESTLE analysis?
· Examples of questions you should be asking during a SWOT and PESTLE
· How often should a SWOT and PESTLE be conducted?
· Examples of SWOT and PESTLE in practice
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian Battersby will be explaining what a SWOT and PESTLE exercise is, it’s role in fufilling key requirements in Clause 4 of any ISO Standard, and the key questions you should be asking during the exercise.
[02:30] What is a SWOT and PESTLE analysis? – This is one is the tools you can use to look at various factors that affect your organisation.
SWOT standards for:
· Strengths
· Weaknesses
· Opportunities
· Threats
PESTLE standards for:
· Political
· Economical
· Social
· Technological
· Legal
· Environmental
And in recent years, people have added ethical into PESTLE too. Whether that’s on its own or integrated within the other elements is up to the organisation and how they want to run the exercise.
Both analysis are fundamental in helping organisations understand the benefits and pitfalls of a project, management system implementation included.
[05:05] Where in the Standard is there a need for a SWOT and PESTLE? – Clause 4 in all ISO Standards is known as ‘Context of the organisation’, which you need to establish early on in order to set the foundations for building your management system.
Context is the world in which an organisation works, it is the considerations of the internal and external factors that affect what you do.
SWOT and PESTLE, while not specifically referenced in the Standard, is a highly recommended tool as it directly assesses multiple internal and external factors and can fulfil the requirements of any ISO Standard.
[06:20] Addressing Context of the Organisation – Clause 4, Context of the organisation states:
“The organisation shall determine external and internal issues that are relevant to its purpose and its strategic direction, and that affects its ability to achieve the intended results of its management system.
The organisation shall monitor and review information about these external issues.”
There are also 3 additional notes:
#1: Issues can include positive and negative factors or conditions
#2: Understanding the external context can be facilitated by considering issues arriving from legal, technological, competitive, market, cultural, ect
3#: Understanding the internal context can be facilitated by considering Issues related to values, culture, knowledge and performance of the organisation.
So, there’s a lot to consider!
[08:10] How SWOT and PESTLE address Context of the Organisation – Taking a look at SWOT, strengths and weaknesses would refer to factors internal to your organisation, while the opportunities and threats would be external.
Depending on the focus of your management system, you may also want to complete this exercise through a certain lens. That could be information security, health & safety or environmental.
The Standard requires you to align your management system with the strategic direction of the organisation, so even if you are viewing this exercise through a certain lens, don’t do so in complete isolation.
[09:55] How to conduct a SWOT and PESTLE – The people involved in completing this exercise are important, not just the questions you ask.
Senior management should be included as they will have key insight to the strategic direction of the business.
You should also include operational managers or other functional managers as they will have more context for how things actually work in practice.
The point of a SWOT and PESTLE is to ascertain where you stand in terms of your risks and opportunities, and issues relating to resources, people, information, process, technology, equipment, laws, markets, environment, finance, economy ect from both an internal and external lens.
This will give you a solid foundation to build your management system on, which will ultimately help you achieve your intended outcomes and lead to a cycle of continual improvement.
[11:55] Considerations for Strengths – Strengths is an internal factor. Questions you could ask include:
· What do we control through good processes?
· What are we known for?
· What does our marketplace and competitors say about us?
· What are we good at?
· What assets do we have?
· What resources and knowledge do we have readily available?
· What's the strength in our products and in the processes for delivering those products and the people that run those processes and deliver those products, their skills, their knowledge, their strengths, their weaknesses and their expertise?
· What areas in our organisation are already at a high standard and don't necessarily need improvement?
· Do we have objectives and targets that we measure against, i.e. KPIs, metrics, success factors and service level agreements, that demonstrate we're good?
[13:10] Considerations for Weaknesses – Weakness is another internal factor, one that you have to be brutally honest conducting. Questions you could ask include:
· What could you improve?
· Where is money being spent poorly, or being lost?
· What do your competitors do better than you?
· What resources / knowledge / people / expertise do you lack?
· What processes do you lack?
· Where can your products or services be improved?
· What are the constraints on your ability to meet changes in market need or demand?
· What does your customer feedback look like?
· Do your suppliers meet your requirements or the requirements of your clients?
[14:45] Considerations for Opportunities – Opportunities are considered an external factor. Questions you could ask include:
· What new opportunities are available in your market?
· What data do you have available on market trends, and how can you leverage that?
· How changes in compliance requirements in your specific industry or your locality might provide you with opportunity to gain an edge?
· What are past identified opportunities that we’ve not acted on?
· What is the competition not taking advantage of that you could?
· How can you increase customer satisfaction based on both positive and negative feedback received?
[16:00] Considerations for Threats – Threats are also considered an external factor, they are obstacles for you achieving your goals. Questions you could ask include:
· What new environmental effects may affect you? Note: there is a new climate change amendment added to many commonly adopted ISO Standards, so this is something you will need to address.
· What competitors are a threat to you?
· Are other competitors taking advantage of markets that you have not accessed?
· Why might competitors be getting ahead?
· Are the habits of customers changing, and if so, how?
· Are there other interested parties other than customers who present obstacles to you?
· Are there any foreseeable resource issues? i.e. loss of experienced staff, lack of relevant talent in the pool of available people ect
· Are you adapting to changes in the world?
[16:00] PESTLE: Addressing political factors – When you’re looking at political factors affecting your intended outcomes, consider the following:
· What is happening politically in your environment? - That could be international or local on scale
· What is the impact of policy or tax?
· What is the impacts of employment trends / trade restrictions / tariffs?
· What is the impact of unemployment rates on your organisation?
· What is the impact of workforce shortages that may affect you?
· Is there any form of Government intervention in your specific market?
· Would this government intervention be considered an opportunity or threat? i.e. offering grants
[19:20] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[21:25] PESTLE: Addressing economic factors – When you’re looking at economic factors affecting your intended outcomes, consider the following:
· What is the impact of interest rates / exchange rates / inflation?
· What is economic policy doing to you and your industry and your clients?
· What are the impacts on wage rates / minimum wage changes /affordable living cost of living?
[21:50] PESTLE: Addressing social factors – When you’re looking at social factors affecting your intended outcomes, consider the following:
· What's the impact of changes in the cultural landscape?
· What’s the impact of the expectation of people?
· What’s the impact on working people’s lives and what their expectations are for working life in general? i.e. working hours and career aspirations
· What is the and the emphasis on ethics, safety, Environmental Protection and data privacy for your clients / workforce / suppliers?
[22:50] PESTLE: Addressing technology factors – When you’re looking at technological factors affecting your intended outcomes, consider the following:
· What is happening technology wise which impacts on what you do?
· How does this affect the equipment you use? i.e. automation, the age of your equipment ect
· What's the impact of emerging technology?
· How you decide on the costs and benefits of investing in new technology?
· How do you use your website / blogs / social media to interact with your marketplace?
· Have you got intellectual property you need to protect? i.e copyright pins that need consideration.
[23:40] PESTLE: Addressing legal factors – When you’re looking at legal factors affecting your intended outcomes, consider the following:
· How does the law affect how you do business? i.e company law, health & safety law, HR law, trade law?
· What changes in legislation have occurred recently that you need to have considered?
· How do you horizon scan for changes in legislation that affect you in your market?
· What's the impact on employment on imports, exports, labour departments?
· Have you considered other compliance obligations, such as certification to certain standards?
[24:50] PESTLE: Addressing environmental factors – When you’re looking at environmental factors affecting your intended outcomes, consider the following:
· How do environmental aspects impact you, and how does the way you operate affect the environment? This includes consideration for air, water, land, natural resources, flora, fauna.
· How do changes in the energy and utilities markets affect you?
· How does your organisation fit in with any carbon reduction targets that your Government may have in place?
· Are you required to create a carbon reduction plan?
· Do you need to comply with certain environmental reporting requirements? i.e. here in the UK we have schemes like ESOS and SECR
[24:50] PESTLE: Addressing ethical factors – This one is optional, but many are choosing to include it as part of their PESTLE now. When you’re looking at ethical factors affecting your intended outcomes, consider the following:
· How do you stay on the right side of the law with respect to the use of money?
· Have you considered human rights / labour / children in the workforce / slavery / health & safety and well-being of local populations?
· What charitable contributions do you make as an organisation?
[27:15] Assigning significance – The next part of a SWOT and PESTLE requires you to assign significance to the various factors affecting your organisation.
So, make sure you document every factor and how those factors affect your ability to achieve what you intend. Ensure that this all remains in alignment with the strategic direction of the business, as ultimately, you want your Management System to help drive those goals forward.
[30:25] Frequency of a SWOT and PESTLE: This isn’t just a one-off exercise. You should be continually monitoring these internal and external factors, and only updating the exercise during a management review meeting will do you a disservice.
This is an ever-changing world, it’s the one in which you operate, and you need to ensure you’re keeping up with it.
You could look at various factors in monthly or even weekly meeting with the appropriate parties, and see if circumstances have changed.
[31:25] Examples of why you should continually update your SWOT and PESTLE: Ian recounts an experience he had with a client where they had failed to disclose where they had switched to a digital system for competence related documentation, but it had not met their needs and so they needed to return to manual documentation.
This switch made finding the required documentation for internal audits difficult. None of this was recorded in their SWOT and PESTLE.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Business travel remains one of our largest sources of greenhouse emissions, accounting for 26% of the UK’s total emissions.
In an ideal world, no one would have to travel to work or events, some might even point to the way everyone adapted in COVID as a prime example of this in practice. However, for many that model of work is not feasible in the long-term.
So, how can we reduce this unavoidable stream of emissions?
Businesses are starting to take the right steps, however, today’s guest is paving the way as a shining example of sustainable business travel and events management.
In this episode, Mel is joined by Christopher Truss, Global Sustainability Director at Reed & Mackay, to discuss their impressive existing ISO Standard portfolio and their journey towards ISO 14064 carbon verification.
You’ll learn
· Who is Chris Truss?
· Who are Reed & Mackay?
· What are the highlights from Reed & Mackay’s latest Sustainability and Responsible Business report?
· What Standards are Reed & Mackay certified to?
· What is the demand for sustainability within the business travel and events management sector?
· Why get ISO 14064 verified?
· What were the challenges with obtaining ISO 14064 verification?
· What are the benefits of obtaining ISO 14064 Verification?
Resources
· Reed & Mackay
· Reed & Mackay Sustainable and Responsible Business Report 2024
· Carbonology
In this episode, we talk about:
[02:05] Episode Summary – We welcome today’s guest, Chris Truss, Global Sustainability Director at Reed & Mackay, to explore their ISO Standards portfolio and journey towards ISO 14064 verification.
[02:40] Who is Chris?: Chris has had over 20 years experience in the business travel industry. He is currently responsible for driving the sustainability agenda at Reed & Mackay, which includes the development of services and solutions that their clients require to meet their own sustainability initiatives.
He also manages a wide range of third-party suppliers.
A lesser know fact about Chris is in a band, playing the folk fiddle and singing in pubs around Yorkshire. He also plays tennis in the over 45 category for Yorkshire!
[04:50] Who are Reed & Mackay? – Reed & Mackay are a global travel management and event management business. They help clients all the way from picking up the telephone and making bookings on their behalf, helping them source appropriate venues for their events and then managing the overall spend, the supply chain and ultimately reporting back to them on what they've been up to and how they can improve their processes and save money.
Reed & Mackay are highly regarded for their quality of services, especially within the professional services sector, and they proudly boast a number of large blue chip clients.
[05:50] What are some of the highlights in Reed & Mackay’s Sustainability and Responsible Business Report? When Chris came into his latest role, he looked to tackle two main points:
· How can Reed & Mackay operate sustainably?
· How can we articulate that to our clients?
As a result of the work Chris has done, Reed & Mackay have signed up to the United Nations Global Compact and have aligned themselves with the UN’s Sustainable Development Goals.
They have also become an EcoVadis rated supplier and are undertaking their first Carbon Reduction Plan disclosure.
From a corporate responsibility point of view, they have made great strides to improve their gender pay gap. They are also ensuring the integrity of their charitable partnerships.
[08:00] What are some of the sustainability initiatives that Reed & Mackay have started? Reed & Mackay support a charity called 4Ocean, who are trying to remove as much plastic from our oceans as possible.
They selected this charity in particular due to it’s global reach, embodying the nature of Reed & Mackay’s global influence in 13 countries for the past 10 years. They recognised the need to support a sustainability based charity as corporate travel is highly polluting, so this is a form of taking responsibility and looking at where they can assist to reduce environmental damage.
4Oceans also allows their employees to get involved directly, should they choose to take some time out of the office to help with ocean clean-up.
[09:55] What ISO Standards are Reed & Mackay certified to? They are currently certified to:
· ISO 27001 Information Security
· ISO 14001 Environmental Management
· ISO 22301 Business Continuity
· ISO 9001 Quality Management
All of which they have been certified to for over 10 years now! They acted as a foundation for Chris to drive his sustainability agenda.
[11:10] How are these ISO Standards managed across the business? – Reed & Mackay have a dedicated Security and Trust team that manage all ISO certifications, in addition to their other responsibilities.
All of the ISO Standards are a part of their Integrated Management System, which sits alongside their policies and procedures for the business that are managed by a central team.
This has provided them with an invaluable foundation to ensure the delivery of quality services, client satisfaction and continual improvement.
[12:45] What is the demand for sustainability within the business travel sector? They are receiving more requirements and requests from clients in regard to their own operational CO2 footprint, which is needed for clients own reporting requirements as Reed & Mackay would count towards many clients Scope 3 emissions.
There is also a need for more transparency with carbon reporting, including the use of credible calculation methodology’s.
The verification of GHG emissions also gives clients more confidence that businesses are doing what they say they’re doing.
[14:15] What was the main driver behind Reed & Mackay gaining ISO 14064 verification?: While they felt confident in their sustainability efforts up to a certain point, they wanted someone to come in and mark their homework to make sure they were doing the right thing.
With the increase in client demand for credible sustainability reporting, it was vital to pursue various CPD disclosures such as EcoVadis and prepare for upcoming legislation like CSRD.
To ensure they were in the best possible shape to give the information requested by clients and other stakeholders, they needed am accurate and reliable method of verification, which is what ISO 14064 could provide.
[15:40] What were the main challenges in obtaining ISO 14064 verification?: Just getting a hold of the raw data was the most difficult part, although they found it to be a very enlightening experience too.
Having to dig to find the right information helped Chris to understand the business better, giving him a greater visibility on where their carbon emissions are coming from and where there are opportunities to reduce those.
You have to be very tenacious to get all the necessary data. Chris highlights purchased goods and services data as particularly challenging to obtain due to its granular nature.
Now they have been through this process once, they’ve got a system in place to make data collection a lot easier in future.
[18:55] What impact has ISO 14064 verification had on Reed & Mackay?: It’s helped from an internal perspective as people now have a greater visibility and understanding of the impact that have on an individual basis. This in turn creates a strong launchpad for their Net Zero strategy.
From an external perspective, it’s given Reed & Mackay a lot more confidence in their own processes and their ability to work with their clients towards sustainability goals.
[20:00] What were the main benefits of getting ISO 14064 verified?:
Giving clients, stakeholder and employees confidence: The verification calculation is reliable, and so they can be confident in relaying the facts and figures to interested parties.
A great insight: The data has provided huge insights into how the business operates and where it’s biggest emissions sources lie. This is vital to know before you take steps to try and reduce your current impact.
Ability to create an accurate Carbon Reduction Plan: Once again, with confidence in having the correct data to hand, they are able to formulate an accurate Carbon Reduction Plan which can be realistically achieved.
Anti Green-washing: Consumers are crying out for a reliable sign of credibility. Simply having an environmental policy statement may have been enough 10 years ago, but that’s not the case now. People expect evidence of your sustainability claims.
[21:50] Chris’s top tip for anyone considering ISO 14064 verification: Just get started and don’t be scared by the process.
Though it may seem daunting to start, you will actually be in a much better position than when you started. Having verified data and awareness of where that data comes from and what it means on a larger scale will be vital to looking for opportunities for improvement.
So, if you want to improve your sustainability, you just need to get cracking!
[23:20] How are Reed & Mackay helping organisations improve the sustainability of their travel?: Reed & Mackay’s ambition is to make sure that clients understand the impact of their choices at every single step of their journey.
To help, they provide the carbon footprint of every booking they make, whether that be through their site or with a consultant.
They also have approval processes built into their systems, which can be based on carbon. For example, if a client doesn’t want to take the lowest carbon option on a particular journey, they can add required approval from an additional person within that client’s organisation. So it adds a level of accountability over the choices people make.
They also provide full reporting on business travel activity and where potential savings have been missed. This is a valuable tool if they need to provide travel data to carbon consultants for example, they’ll already have all of those granular reports prepared.
These reports will highlight where clients haven’t taken the lowest carbon option, i.e. where they could travel in a group instead of individually. Reed & Mackay’s intention is to make sure people have visibility of carbon alongside cost so clients can make a fair and balanced decision.
Additional services include:
· Able to set carbon budgets across a business
· Ability to purchase carbon credits for offsetting purposes
· Opportunities to mitigate carbon emissions through offsetting, or decarbonise through Carbon Reduction Plans over a period of time
[28:50] Chris’s book recommendation: His Dark Materials by Philip Pullman
[29:15] Chris’s favourite quote: You can't measure success if you have never failed – Steffi Graf
If you would like to learn more about Reed & Mackay, and their sustainability initiatives, visit their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Purchasing goods and services is a necessity for any business, whether that’s simply stocking up on office supplies, or looking for someone to manage your IT environment.
Procurement has a key role to play in keeping things running smoothly, along with facilitating the core values of businesses as priorities change, such as a commitment to ESG compliance.
In this episode, Ian is joined by Philip Ideson, Founder & Managing Director of Art of Procurement, to discuss procurement’s role in ESG compliance, the challenges procurement faces with ESG, and learn about their mission to 10X the impact of procurement.
You’ll learn
· Who is Philip Ideson and the Art of Procurement?
· What are the current trends in procurement?
· What is procurement’s role in relation to ESG?
· How do ESG deliverables fit in with the other results procurement is expected to deliver?
· What are the greatest challenges procurement currently faces with ESG?
· What is Art of Procurement’s mission to 10X the impact of procurement?
· What are the 6 principles of this mission?
Resources
· Art of Procurement
· Art of Procurement Podcast
· The Art of Procurement philosophy
· ESG Compliance
In this episode, we talk about:
[00:25] Episode Summary – We welcome today’s guest, Philip Ideson, Founder and Managing Director of the Art of Procurement, to discuss the role procurement has in ESG compliance. Additionally we will dive into Philip’s mission to increase the impact of procurement.
[03:00] Who is Philip?: Philip has been in the procurement space for almost 25 years now!
He started at Ford Motor company, in direct Procurement where he was purchasing parts for car manufacture. He later moved into indirect Procurement, which is essentially everything you need to operate on a day-to-day basis i.e. office supplies, childcare facilities ect.
Philip has worked in the UK, Europe, India and has been based in the US for the past 19 years.
To get a perspective on the other side, he joined a Service Provider who provided outsourced procurement, that company later got bought out by Accenture, which was when Philip decided to go out on his own and started ‘Art of Procurement.
His podcast has been running for 9 years, and has the aim to share inspiring stories of companies who think differently about procurement.
[06:05] Hard Truth: Inside the Football Industry Podcast – Philip also co-hosts another podcast in his spare time, which was awarded the EFL podcast of the year in 2023!
Hard Truth delves into the behind the scenes aspects of football, co-hosted by the owner and Chairman of Peterborough United, it also gives an owner perspective of the football season.
[07:05] What are some of the top trends and priorities in procurement currently?
Digitisation: Procurement was an area where technological change happened relatively slowly, at least up until around 5 years ago there weren’t many tech solutions built specifically for procurement. However, a lot of money has been poured into the space, so now there’s the challenge of ‘How can we digitise?’
The problem with a lot of technology solutions is that they often become obsolete quickly, and with the rise of AI it’s trickly to keep up, let alone get ahead.
[08:10] What is something about procurement that might surprise people who don’t work in the field? Procurement gets a bad rep for trying to save every last penny at the cost of bullying suppliers. However, they are a lot more passionate around the role that suppliers can play in the growth of a business.
It’s all about marrying together the capabilities of supply chains with the needs of a business, rather than trying to squeeze every last penny’s worth out of suppliers.
[09:15] Procurement put into a box: In a lot of businesses, procurement kind of professionalised the profession based on an ROI which was tied to cost savings, because procurement sold that value proposition to get the investment, it means that that's the only thing businesses think they can do.
Procurement gets put in this box within a business of when I need to save money, you know break the glass, bring out procurement and they can do that.
Where you actually get a much better result by working more collaboratively with your procurement team. There’s a lot more tied to business objectives than with procurement objectives, instead of focusing on what procurement can do to save you money, look at what other objectives they can help you achieve.
[10:35] What is procurement’s role with regard to ESG? – Philip was involved in a research study that was done by The Economist, where they surveyed approximately 2300 C-Suite executives, procurement and non-procurement individuals. It was revealed that ESG was the number 2 priority right now, specifically where sustainability was concerned.
Modern slavery is also becoming more of a concern.
[12:00] A fad or long term change? Priorities like this for any business are subject to the politics of the day. They are important now as that’s where a lot of focus in from many different sources, but they are likely temporary and will be dependent on geographical location and available investment.
However, the impact of emissions reporting as a result of ESG will have a longer term affect as scope 3 emissions include supply chains. More businesses will be expecting their supply chains to meet their emissions reporting requirements going forward.
[13:20] How long has procurement been doing ESG/CSR type work?: Back 14 years ago, when they had to report back on supplier diversity spend, they had very little data. It involved a lot of extrapolating data so that you have something to report back with.
More accurate data reporting has picked up in the last 6 years, and is more on an organisation by organisation basis.
The key driver for procurement involvement in any aspect of sustainability is due to regulatory requirements.
[15:00] Innovation for a better future: The digitisation and other technological advancements will allow for better ESG support, with more accurate data and reporting capabilities.
Back in the day, it may have been a case of sampling some 100 suppliers out of a pool of 10,000 listed on a simple spreadsheet, and then googling them to see which ones would be considered diverse suppliers. It short, it used to involve a lot of manual data gathering, which is rapidly getting replaced by new tech tools.
[26:20] What are the greatest challenges procurement currently faces with ESG? One of the challenges is internal. When ESG is brought to the table, decisions have to be made about selecting suppliers who would align with their ESG requirements, which is a decision that is ultimately made by the budget holder.
Procurement can do everything they can to mitigate any additional cost, but they do not decide who spends the money with who.
A lot of the role procurement can play in supporting ESG is dependent on the organisational focus on those initiatives and how well everything is communicated to all involved.
[17:20] Looking to the future of procurement: Procurement was once seen as a cost management function, now professionals like Philip are looking at how they can demonstrate the additional value they can bring to an organisation, including supporting ESG compliance.
Procurement has shifted more towards risk management, with a greater focus on risk factors such as cost and sustainability.
There’s still a lot of uncertainty around what the next 10 years will look like. Philip predicts that procurement will become a smaller, yet more impactful area than it is today.
The operating model will likely shift to a more service-based approach with a more nuanced approach to supporting businesses. Philip can see a world where sustainability and supply chains merge as third-party suppliers will have an increased effect on an organisations ability to meet its sustainability goals.
[20:30] What is Art of Procurements’ mission to 10X the impact of procurement?: Philip aims to change the mindset of procurement leaders, and get them to think outside of the box.
Procurement can have a significant impact on organisations, in the form of additional support like ESG, but also because they have a much wider field of view regarding potential suppliers.
It’s about going back to basics, asking:
· What is procurement?
· How should it operate?
· How can procurement best support businesses?
Their mission aims to rethink how procurement works, and refining how to best work with organisations to achieve their goals.
[22:25] What are the principles of this mission?: Philip highlights a few that he’s passionate about, including:
Focus on driving business outcomes: How can procurement build their capabilities around what the business truly needs? There can be conflict between an organisation and its procurement, whether that be with stakeholders or selecting suppliers. So, it’s about finding a balance between doing what can be done to further an organisations goals while also saving them money.
Procurement facilitating differentiated decision making: Procurement can offer some crucial insight into potential suppliers for organisations, but they can only do so if they have the correct data to help make those decisions. When it comes to measurable data, like many aspects of how sustainable a supplier may be, this is where procurement can help businesses make smarter decisions.
Overseeing not managing spend: Procurement should not necessarily have complete control over the spend of an organisations, but using technology they should be able to understand what is being spent and with who. It’s keeping an eye on potential risk factors with suppliers and helping organisations decide who to continue to work with.
[28:00] How are the Art of Procurement philosophically different? They see procurement as a journey, where many organisations are on a different part of the maturity curve and may need help bridging those gaps to keep moving forward.
Art of Procurement seek to accelerate that speed of maturity by working smarter with new technology, and in alignment with an organisations goals.
Procurement is facing a battle currently, where if they don’t adapt, they run the risk of losing out to purely AI driven tools. This is of course, not a concern unique to the world of procurement, it’s actively affecting HR, IT support and the creative industry in a huge way.
[30:40] Connect over common goals: Procurement professionals often want to be more collaborative than people may think. Don’t be afraid to reach out to your procurement team to see what common goals you can try to achieve.
They are there to work with you, not against you.
[32:45] Procurement and ISO: Philip has seen a lot of instances where an internal audit finding will lead to procurement success. In some cases, this may be from an identification of a need for investment in procurement, it’s seen as necessary tool for the organisation and so they approach it with that mindset in mind.
Internal Audits, a staple in the world of ISO, offer the opportunity to highlight where improvements can be made. They also compile credible evidence to put a case forward to relevant individuals, who may have not listened to previous grievances.
If you would like to learn more about the Art of Procurement, check out their podcast available on their website.
If you’d like to hear more from Philip, he also co-hosts the hard truth - inside the Football Industry podcast.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Sustainability is an area that affects all businesses, no matter the sector. We are all currently contributing to the climate crisis, from travel and hospitality to manufacturing to those working in an office or from home.
You may be surprised to hear that the legal sector is currently one of the leaders in championing sustainability, not just in enforcing new environmental legislation, but also leading by example in the race to net zero.
One such stand out leader is today’s guest – Clyde & Co, a global law firm that have made great strides in their sustainability journey.
In this episode, Mel is joined by Paddy Linighan, Chief Sustainability Officer at Clyde & Co, to discuss their ambitious net zero targets, sustainability initiatives and their journey towards ISO 14064 Carbon Verification.
You’ll learn
Resources
In this episode, we talk about:
[00:25] Episode Summary – We welcome today’s guest, Paddy Linighan, Chief Sustainability Officer at Clyde & Co, to dive into their responsible business report, discuss their net zero ambitions and journey towards ISO 14064 Carbon Verification.
[01:40] Introduction to Paddy: Paddy has 30 years experience in the legal sector, and was formerly the Chief Operating Officer for Clyde & Co before transitioning to the role of Chief Sustainability Officer. Paddy is also a Director at the Legal Sustainability Alliance, which is an association committed to supporting the legal sector to measure and manage their carbon emissions to achieve net zero.
One lesser-known fact is that Paddy was a Latin and ballroom dancer!
[02:30] Who are Clyde & Co? – They are a global law firm with 500 partners, 2700 lawyers and 3216 legal professionals across the world and operating out of 70 offices. They set out to help organisations successfully navigate risk and maximise the opportunity in the sectors that underpin global trade, namely insurance, aviation, marine construction, energy, trade and natural resources.
They offer a comprehensive range of contentious and non-contentious legal services and commercially minded legal advice to businesses operating across the world in seamless fashion.
Clyde & Co are committed to operating in a responsible way by progressing a diverse and inclusive workforce that reflects the communities and the clients it serves, and provides an environment in which hopefully everyone can realise their potential. They use their legal and professional skills to support communities through pro bono work, volunteering charitable partnerships, and minimisation of environmental impact through the pursuit of sustainability standards.
[04:25] What are some of the Net Zero targets highlighted in Clyde & Co’s responsible business report?
[06:25] What are some of the sustainability initiatives that Clyde & Co have started? All their initiatives can be broadly groups into 3 categories, but ultimately they seek to decarbonize their operations, address resource consumption and offset emissions where possible.
They found that 95% of their emissions reside in their scope 3, which is due to their supply chain. A few of their initiatives include rationalizing their supply chain to reduce the impact of purchasing goods and services.
They are also supporting their supply chain to measure and reduce their own emissions. Clyde & Co have also incorporated their sustainability requirements into their Procurement Process and Due Diligence Process.
One challenging area for a professional services business like Clydo & Co is sustainable business travel. They have adopted a global note on sustainable travel, which trickles down into regional travel policies. Working with travel management companies, they will implement those new policies, in addition to improving the quality of travel data collection and prioritisation of sustainability over cost.
Clyde & Co are also making the move to switch direct and in-direct consumption of fossil fuels to renewable energy in the heating and cooling of their buildings.
As of summer 2023, all UK offices were on 100% renewable energy! They aim to roll this out on a global scale, but understand that there are significant challenges with doing so.
[09:30] How did Clyde & Co celebrate Earth Day? They introduced climate change awareness training on Earth Day. It wasn’t mandatory in any way, and included the rolling out of several blogs and videos which were produced by AXA Climate School in Paris.
They ran these through Earth Day (April 22nd) to World Environment Day (5th June). Covering topics such as:
This led to a campaign called ‘Zero as One’ which helped to create of a network of sustainable champions across their organisation, who help to further raise awareness and where there may be regional issues with reducing resource consumption and energy use.
This campaign has continued and is beginning to facilitate a structured, bespoke training programme for all Clyde & Co staff which covers climate awareness to climate competency. It will encourage people to think ‘How can I, as an individual, make a difference?’
[15:30] The Clyde & Co Community Forest – A 6.2 hectare plot of land is shared with 2 other community groups, and is not only being used for reforestation but also biodiversity, focusing on red squirrels in particular.
Getting this project set up included:
They know that they’ll never be able to 100% decarbonise their operations, but they hope to get it down to 10% remaining emissions which can be offset with more projects like the community forest.
[19:35] What does Paddy think of the sustainability reporting regulatory requirements affecting the legal sector? Not only do lawyers have a key part to play in supporting and advising clients in relation to how they navigate towards a low carbon economy, but they are also a part of many businesses supply chain – meaning they would be included in scope 3 emissions for others.
Putting in the work at their end enables them to proactively help and assist clients with their emissions reduction and reporting.
The drive in this sector is mostly due to client demand.
[21:10] The increase in sustainability targets in North American companies: Paddy highlights that a recent report issued by Climate Impact Partners found that 79% of North American companies now have climate targets, which is up 6% on Asian companies and just shy of European companies.
61% of those North American companies report under ISO 14064.
[23:00] What were the drivers behind Clyde & Co getting ISO 14064 verified?:
High Transparency: They wanted to ensure that any disclosed information was reliable and that they’d had third-party verification to back that up, making them much more comfortable putting that information out into the public.
Financial Benefits: Sustainability and greenhouse gas emission reduction was a part of their main KPI’s to tackle, the main reason being to save money through not only the reduction in energy use but also reduced interest rates as a result of their sustainability efforts.
[25:20] What were the main challenges in obtaining ISO 14064 verification?: Clyde & Co are a large organisation, so gathering and quantifying the necessary emissions information was like getting blood from a stone!
Nearly 65 – 70 sites only have a small team of 5 people, and getting data from each can be time consuming.
Also, the quality of data can vary a great degree with that many sites, especially on a global scale as you need to consider the conversion factors when collating all the data into something verifiable.
[26:50] What impact has ISO 14064 verification had on Clyde & Co’s sustainability credentials?: Very simply, it validates Clyde & Co’s claims.
With the third-party assessment, it shows that they are actually doing what they say they’re doing, and not simply paying lip service.
[27:45] What were the main benefits of getting ISO 14064 verified?:
Helping to secure financial benefits: ISO 14064 verification is proof enough for banks to issue discounts on interest rates
Ease of process: The audit process introduced for ISO 14064 can be repeated as needed. As a result of getting verified, Clyde & Co found the exercise a good stress test for existing auditing procedures, and found a way to simplify them further.
Credibility: Third-party verification adds a level of credibility which is lacking from internal calculation alone.
[29:00] Paddy’s top tip for anyone considering ISO 14064 verification: Do not let perfection get in the way of progress.
They found that people can become a bit defensive in audits, trying to avoid errors being picked up, however, audits are meant to be constructive. They are opportunities to pick up on areas for improvement.
[30:40] Paddy’s book recommendation: The Ministry for the Future by Kim Stanley Robinson
[32:10] Paddy’s favourite quote: The greatest threat to our planet, is the belief that someone else will save it – Robert Swan OBE
If you would like to learn more about Clyde & Co, and their sustainability initiatives, visit their website.
To find out more about verification visit www.carbonologyhub.com
We’d love to hear your views and comments about the ISO Show, here’s how:
Don’t forget to subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Did you know that only a third of the emissions reductions required to achieve the country’s 2030 target are currently covered by credible plans?
As a result, we can expect to see more mandatory and voluntary regulations that require carbon emissions reporting to verify your ESG and net zero claims.
In this episode, Mel closes out the ESG Reporting Disclosures series by explaining what Corporate Sustainability Due Diligence Directive (CSDDD) is, it’s key emissions reporting requirements, the verification requirements and who qualifies for CSDDD.
You’ll learn
· What is CSRD?
· Key requirements of CSDDD
· Key emissions reporting requirements
· the emissions verification requirements for CSRD?
· Who qualifies for CSDDD?
· The likely impact of CSDDD
Resources
· Carbonology
· Carbonology LinkedIn
· Carbonology Instagram
· CSDDD
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:10] Episode summary: Mel closes out the series on ESG reporting requirements by diving into CSDDD.
[03:10] What is CSDDD? – The Corporate Sustainability Due Diligence Directive (CSDDD) is a new EU directive that promotes sustainable and responsible corporate behaviour in companies’ operations and across their global value chains.
Purpose: It aims to promote sustainable business practices, protect human rights, and address environmental challenges.
The CSDDD was adopted by the European Commission on the 23rd of February 2022 and approved by the Council of the European Union on the 24th of May 2024. The new rules ensure that companies in scope identify and address adverse human rights and environmental impacts of their actions inside and outside Europe. The CSDDD is expected to start affecting companies from 2027 at the earliest once the directive has been transposed into national legislation.
[05:10] What are the key requirements of CSDDD?:
· Human rights due diligence: Companies must identify, prevent, and mitigate adverse human rights impacts within their value chains.
· Environmental due diligence: They must assess and manage risks related to climate change, biodiversity loss, and pollution.
· Disclosure obligations: Companies must disclose their due diligence processes, findings, and any remedial actions taken.
[06:20] What are the Emissions Reporting Requirements? Under the CSDDDD, companies are required to report on their greenhouse gas (GHG) emissions within a climate transition plan.
This includes considerations for Scope 1, 2 and 3. These were explained in more detail in a previous episode on CSRD, so go check that out if you want to learn more about the individual scope requirements.
What if you fit the requirements of both CSRD and CSDDD, do you have to double report on emissions? In short – No!
The climate transition plan required by the CSDDD will be reported within CSRD reporting, as organisations just need to adhere to the CSDDD’s implementation requirements for the transition plan.
[10:10] What are the Emissions Verification Requirements? More definitive guidance on verification requirements is expected closer to 2027. Companies will more than likely need to verify the emissions data reported through CSDDD, as the directive mandates a climate change transition plan that aligns with the Corporate Sustainability Reporting Directive (CSRD), which does require companies to verify their emissions data.
[09:55] Who qualifies for CSDDD? The Corporate Sustainability Due Diligence Directive (CSDDD) applies to both EU and non-EU companies depending on their workforce size and revenue:
EU and non-EU companies (or the ultimate parent company of a group):
· With more than 1,000 employees and a global net turnover of at least €450 million in the last fiscal year; or
· Which have franchising or licensing agreements in the EU in return for royalties with more than €22.5 million generated by royalties in the EU and have a net worldwide turnover of over €80 million in the last financial year.
[11:10] What is the possible impact of this new directive? Similar to the other ESG disclosures I’ve covered over the past few weeks in this series on reporting disclosures, the impact of the CSDDD will result in 3 key impacts:-
· Increased transparency: This directive will provide stakeholders with a clearer picture of companies' sustainability efforts, to combat greenwashing.
· Enhanced accountability: Companies will be held accountable for their environmental and social performance.
· Stimulation of sustainable business practices: The directive will encourage companies to adopt more sustainable practices, including regular reporting.
If you would like to learn more about CSDDD or inquire about the related course, please get in touch with Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
2030 is fast approaching and we’re already falling behind on our Net Zero targets, which will take a coordinated collective effort to get back on track.
As a result, businesses are coming under increasing pressure to monitor, report and reduce their energy use and carbon emissions to meet net zero targets.
This has led to an increase in both mandatory and voluntary regulations that require carbon emissions reporting to verify your net zero claims.
In this episode, Mel continues the ESG Reporting Disclosures series by explaining what the Corporate Sustainability Reporting Directive (CSRD) is, how it affects your emissions reporting, the verification requirements and who qualifies for CSRD.
You’ll learn
· What is CSRD?
· How will the CSRD affect your Emissions Reporting?
· What are the emissions verification requirements for CSRD?
· Who qualifies for ISSB S2?
Resources
· Carbonology
· Carbonology LinkedIn
· Carbonology Instagram
· CSRD
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:10] Episode summary: Over the course of September, Mel will be exploring the latest climate change regulations that may affect your organisation. In this episode she dives into Corporate Sustainability Reporting Directive (CSRD).
[02:55] What is CSRD? – The Corporate Sustainability Reporting Directive (CSRD) is a new EU directive that modernises and strengthens the rules concerning the social and environmental information that companies have to report. It revises the 2014 Non-Financial Reporting Directive (NFRD), extends the scope of covered companies, and strengthens the reporting requirements.
The CSRD was formally adopted by the European Council on 28 November 2022.
The directive is transforming ESG reporting and will start affecting almost 50,000 companies from 2024 by expanding the scope to include all large companies, all companies listed on regulated markets, and non-EU companies with substantial activities in the EU. This includes non-EU companies with subsidiaries operating within the EU or those listed on EU regulated markets.
Many companies located both within and outside the EU will be affected during the CSRD’s phase-in period beginning in fiscal year 2024.
[05:10] How will the CSRD affect your Emissions Reporting?: Under the CSRD, companies are required to report on their greenhouse gas (GHG) emissions. This includes:
· Scope 1 Emissions: Direct emissions from owned or controlled sources. For example, emissions from combustion in owned or controlled boilers, furnaces, vehicles, etc.
· Scope 2 Emissions: Indirect emissions from the generation of purchased energy. This includes emissions from the production of electricity, steam, heating, and cooling consumed by the company.
· Significant Scope 3 Emissions: Other indirect emissions that occur in a company’s value chain. Companies are required to report on significant Scope 3 sources. This could include emissions from business travel, employee commuting, waste disposal, etc.
[07:10] What are the Emissions Verification Requirements? Under the CSRD, companies are required to have their reported GHG emissions data verified by an independent third party. The verification process ensures the accuracy and reliability of the reported information.
Verification options for CSRD include:
· Independent Verification: Companies must engage an accredited third-party verifier to audit and confirm the accuracy of their GHG emissions reports.
· Verification Standards: The verification must be conducted in accordance with recognised international standards, such as ISO 14064-3.
· Assurance Levels: The verification should provide a reasonable level of assurance that the emissions data is accurate and complete.
· Frequency of Verification: Verification is required on an annual basis to ensure ongoing accuracy and compliance with the CSRD.
[10:10] Who qualifies for CSRD? The Corporate Sustainability Reporting Directive (CSRD) applies to a broad range of companies based on the following criteria:
1) Companies listed on regulated markets in the EU (excluding listed micro-enterprises).
2) Large companies, classified as those meeting at least two of the following three conditions:
· More than 250 employees.
· A turnover of over €40 million.
· Over €20 million in total assets.
3) Listed Small and Medium-sized Enterprises (SMEs), although there will be a transitional period when SMEs can opt out until 2028.
4) Non-EU companies with a net turnover of €150 million in the EU, and with at least one subsidiary or branch in the union.
If you would like to learn more about CSRD or inquire about the related course, please get in touch with Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Businesses are coming under increasing pressure to monitor, report and reduce their energy use and carbon emissions to meet net zero targets.
As a result, we’re seeing an increase in both mandatory and voluntary regulations that require carbon emissions reporting to verify your net zero claims.
In this episode, Mel continues the ESG Reporting Disclosures series by explaining what The International Sustainability Standards Board Climate-related Disclosures (ISSB S2) are, the emissions reporting and verification requirements and who qualifies for ISSB S2.
You’ll learn
· What is ISSB S2?
· What is the scope of ISSB S2
· What are the emissions reporting requirements for ISSB S2?
· Emissions verification requirements
· Who qualifies for ISSB S2?
Resources
· Carbonology
· ISSB S2
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:10] Episode summary: Over the course of September, Mel will be exploring the latest climate change regulations that may affect your organisation. In this episode she dives into The International Sustainability Standards Board Climate-related Disclosures (ISSB S2).
[03:20] What is ISSB S2? – The International Sustainability Standards Board Climate-related Disclosures (ISSB S2) is a new global standard that mandates entities to provide comprehensive information about climate-related risks and opportunities.
The ISSB S2 was issued by the International Sustainability Standards Board on the 26th of June 2023 and is effective for annual reporting periods beginning on or after the 1st January 2024. The new standard ensures that companies disclose physical and transition risks and their potential impact on the move towards a low carbon economy.
[04:20] Further learning with Carbonology: Carbonology have created a half-day course which walks you through all of the various carbon reporting disclosures and sustainability disclosure reporting requirements.
If you would like to learn more, get in touch with Carbonology.
[07:00] What does ‘Acute and Chronic Physical risks’ mean in the context of ISSB S2? Climate related physical risks are risks resulting from climate change that could be event driven, so an example of an acute physical risk could arise from weather related events like storms, floods and heatwaves, which are increasing in frequency.
These could have a knock-on effect to businesses, taking a heat wave as the example, you will need to consider:
· Can your IT systems and datacentres cope with it?
· Have you got resilience built in to your operations to be able to deal with that sort of disruption to your organisation?
Chronic physical risks arise from longer term shifts in climatic patterns, including changes in precipitation and temperature, which could lead to sea level rises and reduced water availability and changes in soil productivity.
These risks could carry a weighty financial burden either through direct damage to assets, or indirectly through supply chain disruption.
[09:35] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[11:43] What does ‘Transition risk’ mean in the context of ISSB S2? This is looking for a climate related transition plan, which should include targets, actions and resources for the transition towards a lower carbon economy.
This would include actions such as reducing greenhouse gas emissions.
[12:30] What is the scope of ISSB S2? This Standard applies to:
· climate-related risks to which the organisation is exposed, which are:
· climate-related physical risks; and (ii) climate-related transition risks; and
· climate-related opportunities available to the entity.
Climate-related risks and opportunities that could not reasonably be expected to affect an organisation’s prospects are outside the scope of this Standard.
· The Standard covers:-
· Governance
· Strategy
· Climate related risks and opportunities
· Business Model and Value Chain
· Financial position, financial performance and cash flows
· Climate resilience
· Risk Management
[14:10] What are the emissions reporting requirements for ISSB S2? - Under ISSB S2, companies are required to measure and disclose their greenhouse gas (GHG) emissions across three scopes:
· Scope 1 Emissions: Direct emissions from owned or controlled sources. For example, emissions from combustion in owned or controlled boilers, furnaces, vehicles, etc.
· Scope 2 Emissions: Indirect emissions from the generation of purchased energy. This includes emissions from the production of electricity, steam, heating, and cooling consumed by the company.
· Scope 3 greenhouse gas emissions: Indirect greenhouse gas emissions (not included in Scope 2 greenhouse gas emissions) that occur in the value chain of an entity, including both upstream and downstream emissions. Scope 3 greenhouse gas emissions include the Scope 3 categories in the Greenhouse Gas Protocol Corporate Value Chain (Scope 3) Accounting and Reporting Standard (2011).
[16:20] Emissions verification requirements - Under ISSB S2, companies are required to have their reported greenhouse gas (GHG) emissions data verified.
Verification can provide users of financial reports confidence that the information is complete, neutral and accurate.
Disclosure of inputs to Scope 3 greenhouse gas emissions needs to disclose information about the measurement approach, inputs and assumptions it uses.
[18:30] Who qualifies for ISSB S2? - ISSB S2 applies to all entities that are required by law, regulation, or administrative provision to prepare financial statements. This includes, but is not limited to:
· Publicly listed companies
· Large private companies
· Financial institutions such as banks and insurance companies
· State-owned enterprises
Entities are encouraged to adopt the ISSB S2 voluntarily, even if they are not mandated by law or regulation. Early adoption is permitted and encouraged to enhance transparency and accountability in climate-related disclosures.
If you would like some help with your carbon emissions reporting, please get in touch with Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
As the urgency to address the climate emergency heightens, businesses are coming under increasing pressure to monitor, report and reduce their energy use and carbon emissions to meet net zero targets.
As a result, there is an increase in regulations to ensure that companies are taking the climate emergency seriously and not pay lip service to climate action.
During September, we’ll be taking a look at a few of the latest regulations that may affect your organisation, including:
· SECR – Streamlined Energy and Carbon Reporting
· ISSB S2 - International Sustainability Standards Board Climate related disclosures
· CSRD - Corporate Sustainability Reporting Directive
· CSDDD - Corporate Sustainability Due Diligence Directive
In this episode, Mel Blackmore breaks down what Streamlined Energy and Carbon Reporting (SECR) is, its reporting requirements, it’s qualifiers and how it can work in tandem with other carbon management initiatives.
You’ll learn
· How do these regulations relate to ESG reporting?
· What is Streamlined Energy and Carbon Reporting?
· What are the SECR Emissions Reporting Requirements?
· Who qualifies for SECR?
· How can SECR work with other carbon management initiatives?
Resources
· Carbonology
· SECR
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:10] Episode summary: Over the course of September, Mel will be exploring the latest climate change regulations that may affect your organisation. In this episode she dives into Streamlined Energy and Carbon Reporting (SECR).
[03:20] How do these regulations relate to ESG reporting? – ESG requirements include a commitment to sustainability, and reducing your overall impact. All of these regulations contribute towards an organisations ESG reporting requirements, as they require tangible proof to back up your ESG claims.
They will require you to provide comprehensive emissions reporting, the level of detail of which will depend on the specific applicable regulation.
[04:05] Future content to look forward to: During September Mel will look at involuntary emissions reporting schemes, but in October she will be looking into the voluntary schemes that many are already adopting as part of their Stakeholder requirements.
This will include:
· CDP (Carbon Disclosure Project)
· EcoVardis
[05:50] What are the SECR Emissions Reporting Requirements?: SECR has been around since April 2019, and was originally introduced to replace the Carbon Reduction Commitment Scheme.
This is a mandatory scheme, so it is a legal requirement for those that meet it’s criteria. For those that are familiar with ESOS (The Energy Savings Opportunity Scheme), it functions in a very similar way.
This scheme isn’t solely focused on reporting energy usage and carbon emissions, it’s also looking for organisations to report on efficiency measures that are undertaken on an annual basis. Which is reflected in the financial reporting that you will also have to submit.
It’s important to note that SECR has specific requirements for the disclosure of greenhouse gas (GHG) emissions and energy consumption. Emission reporting requirements vary slightly between quoted companies and large unquoted companies and LLPs.
For quoted Companies:
· Global Scope 1 and 2 GHG emissions must be reported. Scope 3 emissions reporting is strongly recommended but voluntary.
For large unquoted companies and LLPs:
· UK based Scope 1 and Scope 2 emissions and associated energy consumption. Scope 3 emissions from the combustion of fuel in vehicles or equipment not owned by the company.
[10:10] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[12:05] Who qualifies for SECR?: All UK Quoted Companies: Any company that has shares listed on the UK Stock Exchange is required to comply with SECR.
Large Unquoted Companies and Large LLPs: These are companies and Limited Liability Partnerships (LLPs) that are not listed on the UK Stock Exchange but meet two or more of the following criteria:
· Turnover: More than £36 million per annum.
· Balance Sheet Total: More than £18 million.
· Number of Employees: 250 or more employees.
These criteria ensure that SECR framework targets large organisations that have a significant impact on the UK’s energy consumption and carbon emissions. By complying with SECR, these organisations can contribute significantly to the UK’s sustainability goals.
[14:10] When is the SECR disclosure made? SECR reporting must occur alongside financial reporting, being included within annual reports and Directors’ Reports, which are then filed with Companies House.
[14:30] The importance of Accurate SECR Reporting and Carbon Reduction - The reporting process can unlock valuable insights and opportunities for operational improvements, leading to enhanced energy efficiency and reduced carbon emissions over time.
Demonstrating your organisation’s commitment to energy efficiency and carbon reduction can enhance brand perception and foster positive relationships with stakeholders, including investors, clients, and regulators.
[16:05] Integrating SECR Reporting with Other Carbon Management Initiatives - You are missing a trick if you’re keeping your SECR reporting separate from the rest of your business activities. It should be included as a part of your sustainability umbrella, and can be invaluable if you’re going for other reporting requirements such as EcoVardis and CSRD.
There’s no need to reinvent the wheel if you already have something like an Environmental Management System in place, simply weave the additional requirements in with your usual annual maintenance. Established systems will already be adhered to across the business, meaning any new requirements will soon become business as usual.
You could incorporate this as part of your Net Zero strategy, or Carbon Reduction Plan if PPN 06/21 is one of your reporting requirements. You could also incorporate this into your supply chain emissions reporting.
If you would like some help with SECR, please get in touch with Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
There have been a reported 9,478 publicly disclosed data incidents in 2024 alone, with that amounting to over 35 million known records breached.
It has become clear in recent years that information security isn’t just a ‘nice to have’, it’s a necessity to ensure you and your client’s data are protected. Which is especially the case for those processing personal and financial data, such as today’s guest, Mintago.
In this episode, Tom Catnach, Head of Product and Information Security Officer for Mintago, explains their journey towards ISO 27001, the challenges faced and benefits felt from certification to the leading Information Security Standard.
You’ll learn
· Who are Mintago?
· Who is Tom Catnach?
· What was the main driver behind achieving ISO 27001?
· What was the biggest ‘gap’ identified in the Gap Analysis?
· What have they learned from the experience?
· What are the benefits of certification to ISO 27001?
· What does the threat horizon for information security look like?
Resources
· Mintago
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:15] Episode summary: Today we welcome guest Tom Catnach from Mintago to discuss their journey towards ISO 27001 certification.
[02:20] Who are Mintago? – Mintago are an employee benefits company, who work with companies to help their employees be financially better off. They do this in a number of ways, including:
· Finding lost pension pots
· Help to save money through finding discounts
· Retirement planning
· Offering various salary sacrifice products
· Helping companies to be more financially efficient with pension salary sacrifice or other national insurance savings
· Helping people to be more financially literate
[05:10] Who is Tom Catnach?: Tom has a split role at Mintago, his primary role being Head of Product and secondary being Information Security Officer.
Through both roles he looks after all the products and offerings as well as the information security across the business, he was also the driving force behind achieving ISO 27001.
Outside of work, Tom likes to travel via motorbike, preferring to stay away from the screens and enjoying the sights.
[06:30] What was Mintago’s main driver to Implement ISO 27001?: Mintago, and most other businesses by their nature, are required to hold a lot of sensitive data and so have a responsibility to their clients and employees to ensure it’s security.
Mintago were looking for a robust framework to base their Information Security around, and what better option that the leading Information Security Standard, ISO 27001.
ISO 27001 also offer the assessment of general business practice, and allows for growth and scaling. As a start-up, they wanted to have a solid base for policies, training ect to roll out to new hires as they expand.
[08:30] Aligning Standards with core values: Trust is one of Mintago’s core values and want to give their clients the assurance that they can be trusted to protect their data.
ISO 27001 can be compared to the likes of Bcorp as it’s an on-going process. It doesn’t just stop at getting the certificate, you have annual surveillance to ensure you are still compliant year on year.
[10:15] What was the scope of Mintago’s certification?: For the initial implementation, Mintago opted to just scope in Product and Customer Service.
This was because all of the sensitive data is handled in those departments and they don’t allow access to any other teams, so it made sense to start there with a view to expand the scope after certification.
That being said, they still rolled out Information Security training to all staff, and everything has been set-up to allow for an easy business wide roll-out when they’re ready.
[11:50] How long was Mintago’s certification journey?: They started their journey in September 2023, in fact it was Tom’s first project with Mintago!
Mintago enlisted Blackmores help to implement ISO 27001, and after nine months they have been successfully certified.
Tom attributes their ease of implementation to the fact that they are currently a small business, citing that it’s an advantage to implement ISO Standards early while your agile so that your management system grows with you.
[14:25] What was the biggest ‘gap’ identified at the Gap Analysis? Mintago are lucky in the fact that they are a new business so are using modern tech, and don’t have the burden of rack mounted servers.
However, policy, procedure and evidence to ensure they were doing the right thing were lacking at the start of their journey. They did have a good 70% in place and that last 30% was mostly down to having the ability to evidence their compliance.
There was also some additional work to do to improve existing policies and procedures. One example of this was having a solid Business Continuity Plan in place.
[16:35] Did Mintago experience any significant barriers in addressing identified gaps? Being a smaller business, they were able to adapt a lot quicker than a larger organisation may have been able to.
One of the biggest struggles for Tom was getting the necessary technology to aid with Information Security. They needed to show that they had a competent Mobile Device Management Solution (MDM), antivirus and anti-phishing in place.
When trying to buy some software solutions, Tom encountered a lot of companies simply not replying to his requests due to Mintago’s size. Many organisation sadly prioritize bigger potential clients, and so it took a while to finally get all the required software.
[18:45] Engagement is key - Getting everyone involved with the management system is critically important. Especially with information security as the people most often targeted are frontline workers, so they need to be actively engaged in security.
Mintago also has the advantage of being a smaller business, so getting communication out isn’t a hardship and resulted in high engagement. This was benefitted from a top-down initiative via their ‘C-Suite’.
Tom also states that you can make any necessary training more lighthearted, team based or interactive, as that’s something that people would want to engage in.
It’s also important to stress that any information security training can be beneficial for personal use too to avoid being a victim of fraud or a scam. It can be something people take away to their family members to ensure they stay safe online.
[23:10] Did the adoption of ISO 27001 highlight any issues not already considered by Mintago? - The biggest thing was how their internal process could be improved. For example, looking at the scenario of ‘what if our back-ups don’t work?’, ISO 27001 drilled down to ask specifics such as:
· How do we recover from that scenario?
· Are we 100% confident in our back-ups?
· Will they work near instantaneously?
· What’s Mintago’s availability like in that scenario?
· How do we prevent disruption to our clients during that scenario?
So, while they did have back-ups they weren’t necessarily considering the whole scenario, especially if those back-ups were to fail. ISO 27001 ultimately helped to flesh out existing plans to make a much more robust system.
In regards to threat horizons, Mintago do practice OWASP and keep the team informed via e-mail, newsletters and GitHub repositories.
[25:00] Internal Auditing – A beneficial tool - Tom found the internal auditing process to be very beneficial for Mintago, currently they do a few monthly on average.
Blackmores assisted with the audits during implementation to ensure they were in the right place for assessment. Of course, the Certification Body audits were a bit more nerve wracking for Stage 1 and 2 as they would determine if they would be certified.
Mintago passed their Stage 1 (documentary review) with flying colours, their Stage 2 (evidence checking) highlighted a few non-conformities that were quickly addressed. Following the Stage 2, they were recommended for ISO 27001 certification.
[27:20] Minor Non-conformities aren’t the end of the line – There’s a common misconception that getting a certain number of minor non-conformities during a Stage 2 assessment means you can’t be certified, but that’s simply not true!
If an Assessor if comfortable that you are in a good position for certification, they will recommend you.
ISO Standards are all about continual Improvement, which is something Mintago are embracing as they continue to address issues raised at audits.
[29:00] Benefits of ISO 27001 certification – Benefits Mintago are already experiencing include:
Internal Stakeholders – The Team worked hard to achieve the Standard and have embraced it’s core qualities to the benefit of their own Information Security practices.
Positive Market Response – Much larger clients who are also ISO 27001 certified now have a mutual understanding of each other’s commitment to information security.
Gaining certification early – As a start-up, Mintago are agile and will be able to develop and mature their ISMS (Information Security Management System) as they grow.
[31:10] Any concerns on the threat horizon?: As the Information Security Officer, Tom is concerned about new emerging trend in AI led scams. They’re going to be a lot more sophisticated and harder to spot and deal with.
Thankfully, even if they are impacted, it will be rather isolated. Tom raises concerns for vital services such as Air Traffic Control which could have dire consequences if they were to be affected by a data incident.
However, with ISO 27001 Mintago are in a good place to keep on-top of their threat horizon and have the processes in place to mitigate potential incidents and continually improve their own security.
[34:30] In Summary: Mintago are a shining example of gaining certification for the right reasons. It’s not just about getting a badge, they have truly embraced a culture of continual improvement and are utilising ISO 27001 to ensure they have a robust information security management system in place.
If you would like to learn more about Mintago and their financial services, check out their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Greenhouse Gas (GHG) accounting has become increasingly important in recent years due to the demand for more environmental accountability.
Whether by choice or due to legislation or mandatory Government led schemes, organisations need to able to effectively calculate their current impact before they can the right steps to reduce and offset the remaining emissions.
There are a lot of different routes to take, and some may look so similar that you have to squint to see a difference.
In this episode, Mel Blackmore breaks down the similarities and differences between the leading GHG emission reporting frameworks, ISO 14064-1 and the GHG Protocol Corporate Standard.
You’ll learn
· What are the 2 leading GHG accounting frameworks?
· What are the similarities between the GHG Protocol and ISO 14064?
· What are the differences between the GHG Protocol and ISO 14064?
· Reporting on indirect emissions
· Choosing the right framework
· How can the GHG Protocol and ISO 14064 complement each other?
Resources
· Carbonology
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:30] Episode summary: Mel will look at the similarities and differences between the 2 leading GHG emissions reporting frameworks, the GHG Protocol and ISO 14064-1:2018.
[02:20] What are the 2 leading GHG accounting frameworks? – Greenhouse gas (GHG) accounting has become increasingly important for organisations seeking to manage their environmental impact and contribute to climate change mitigation efforts. Two prominent frameworks guide this process: ISO 14064-1:2018 and the GHG Protocol Corporate Standard.
Climate change concerns necessitate robust methodologies for quantifying and reporting organisational GHG emissions. Standardised frameworks offer a transparent and reliable approach for organisations to measure their impact and contribute to environmental sustainability goals. This article examines two leading frameworks: ISO 14064-1:2018 and the GHG Protocol Corporate Standard.
[06:10] What are the similarities between the GHG Protocol and ISO 14064? – GHG Scope Definition: Both frameworks categorise emissions into three scopes: Scope 1 (direct emissions from owned or controlled sources), Scope 2 (indirect emissions from purchased electricity, heat, or steam), and Scope 3 (other indirect emissions throughout the value chain).
In general, the GHG Emissions covered in the GHG Protocol Corporate Standard conform to ISO 14064-1 if significant Sope 3 GHG emissions and GHG removals are both considered.
Quantification Principles: Both emphasize the importance of accuracy, completeness, consistency, transparency, and relevance when quantifying emissions.
GHG Reporting Boundaries: Both require clear definition of the organisational boundaries for which emissions are quantified.
GHG Inventory: Both frameworks guide the development of a GHG inventory, a comprehensive record of all organisational emissions.
[09:15] What are the differences between the GHG Protocol and ISO 14064? – Focus: ISO 14064-1 is a more procedural framework, outlining the steps for quantifying, reporting, and verifying GHG emissions. The GHG Protocol, on the other hand, offers detailed guidance on calculating emissions for various activities and sectors but lacks formal verification requirements.
Level of Detail: The GHG Protocol provides a more comprehensive and detailed approach, including calculation methods, guidance on emission factors, and best practices. ISO 14064-1 offers a less prescriptive approach, allowing organisations to choose calculation methodologies based on their specific needs.
Avoided GHG Emissions: The concept of avoided GHG emissions is not addressed in ISO 14064-1. However, the GHG Protocol Corporate Standard addresses the quantification of avoided emissions, which are required to be reported separately.
Verification: Verification by a third-party verifier is optional under the GHG Protocol but mandatory for organisations seeking public disclosure or certification under ISO 14064-1. Verification enhances the credibility and reliability of reported emissions data, this could be to schemes like EcoVadis.
Value Chain Emissions: While both frameworks acknowledge Scope 3 emissions, the GHG Protocol offers a dedicated standard - the Corporate Value Chain (Scope 3) Standard - providing specific guidance on quantifying these emissions.
Addressing GHG Emissions and Removals: ISO 14064-1 clearly address GHG emissions and removals for each category and removals are therefore an inherent part of the GHG quantification. The guidance in the GHG protocol is not as clear but allows for the reporting of removals separately from GHG Emissions.
[13:30] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[17:05] Reporting on indirect emissions: The main challenge for organisations is the reporting of indirect emissions (Scope 3), often leading to confusion based on a lack of clarity and understanding of how granular the data needs to be, combined with challenges extracting data from third-parties.
ISO 14064-1 is very clear regarding which Scope 3 emissions are to be included, whereas the GHG Protocol standard maybe viewed as more open to interpretation.
In contrast, GHG Protocol standards require the inclusion of Scope 2 (indirect emissions from purchased energy); the inclusion of other indirect GHG Emissions under scope 3 is optional.
The GHG Protocol standard is referred to in various GHG reporting and disclosure initiatives whose requirements for the reporting of the Scope 3 emissions vary. Whereas ISO 14064-1 has been created and approved by representatives from 61 nations to determine a specification for Scope 3 emissions reporting.
[20:30] Choosing the right Framework: The choice between ISO 14064-1 and the GHG Protocol depends on an organisation's specific needs and goals. Here are some considerations:
· Is there a need for Verification? i.e. is it a mandatory requirement
· What level of detail is required? If a detailed approach with extensive calculation guidance is preferred, the GHG Protocol might be more suitable.
· Resource availability – Do you have the resource to do this yourself or will you need a helping hand?
· Disclosure reporting requirements – check what you need to comply with as this could determine which framework you use.
[23:30] How can the GHG Protocol and ISO 14064 complement each other? - This podcast may have you thinking that it has to be one or the other, but in actuality the two frameworks can be used together effectively. Organisations can utilise the GHG Protocol's detailed guidance to develop their GHG inventory and then follow ISO 14064-1's process for verification and reporting.
If you would like some help with GHG reporting or Verification, please get in touch with Carbonology.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ESG is a very broad topic to try and address for any organisation, leaving many scratching their heads on where to start with ESG reporting.
Currently, there is no official certification for ESG, however there are a number of schemes that will give you either a score or rating for your level of compliance against their requirements.
For those currently working towards one of these schemes, you may already have a solid foundation in place if you’re certified to one or many ISO Standards.
In this episode, Ian Battersby and Ali Henshaw discuss ESG compliance and how elements of an ISO Management system can help with ESG reporting.
You’ll learn
· What is ESG?
· Is ESG reporting required?
· Is ESG a nice to have or good solid business practice?
· Is ESG certifiable?
· How can ISO Standards help to address the 3 pillars of ESG?
· How ESG compliance helps to combat Greenwashing
Resources
· Isologyhub
· ESG Audit
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:00] Episode summary: Ian and Ali will be discussing how ISO Standards can help with ESG reporting.
[02:20] What is ESG? – ESG stands for Environmental, Social, and Governance. Analysis and evaluation against these three elements help organisations to consider different areas within their overall sustainability profile.
The Environmental section looks at issues surrounding climate change and actions to address an organisation’s environmental responsibility. This includes monitoring and management of your energy consumption, waste management and pollution. It also seeks to tackle how organisations can address, reduce and mitigate their overall environmental impact.
The Social aspect is based around the relationships an organisation has with its stakeholders. This is focused on employees and looks at a broad range of topics including employee wellbeing, fair and competitive pay, benefits and human resource related policies. Considerations can also include wider business relationships such as supplier relations, local community and government work.
[05:00] The pillars of ESG aren’t silos – You shouldn’t approach each pillar of ESG in isolation, as they cross over in a lot of areas.
For example, in environmental management you may manage hazardous substances, you’ll have a duty to ensure those substances don’t pollute the surrounding area or bodies of water. However, you will also need to consider the health and safety aspect of storing and working with that material. So already you have 1 issue that crosses both the Environmental and Social pillar of ESG.
[05:50] What does the Governance pillar cover? – Governance criteria focuses on creating a business environment that is fair, transparent, and accountable. Considerations in this area include board composition, fairness in pay structures and executive compensation, business ethics and risk management.
[07:05] What types of ESG reporting are required? – For small organisations, there is currently no set requirement as it stands, but you many encounter stakeholder or customer requirements that encourage ESG reporting on some level.
For larger organisations at certain sizes there are mandatory reporting frameworks that you will be required to fulfill. At the moment it’s quite sector specific but this is a trend that will only increase over time.
Like with anything new, this is likely to trickle down to smaller organisations over time, however there will likely be funding and grants available to assist when that time comes.
[08:25] Is ESG a nice to have or good solid business practice? If you want to be a sustainable business, with good legacy that has the ability to grow and develop, ESG is a fantastic tool.
Investors are now looking for sustainable businesses, it’s become a market trend for an ever increasingly environmentally conscious consumer base. You either need to move with the times of get left behind, and sustainability is one key factor that will determine which of those categories you fall into.
[09:50] Which ISO Standards can support ESG?: From a holistic point of view, the structure of ISO standards, the plan do check Act (PDCA) cycle, the need for monitoring and measurement and the need for improvement supports the principles of ESG in terms of quantifiable results.
The additional aspect of having set objectives and proof of tangible improvement actions was something that fulfilled CSR (Corporate Social Responsibility), which in turn has been superseded by ESG.
ISO Standards high-level structure and life cycle approach lend themselves to support various aspects of ESG, depending on the Standard you implement.
ISO 14001 for example, would support the environmental pillar, as it looks at your significant aspects and impacts in addition to that of your supply chain. You’ll need to factor these into your objectives and overall business strategy.
ISO 45001 would tackle elements of the social pillar as it directly addresses the well-being of your employees. It also includes a clause for the consultation and participation of workers, so work directly with employees to identify and address risks that may be missed by management.
[13:40] Is there a certifiable Standard for ESG?: Not currently, but an ISO guidance document is in the works.
Standards that address core elements of ESG include ISO 26000 (Social Accountability) and ISO 20400 (Sustainable Procurement). Again, these aren’t certifiable, but provide invaluable guidance.
Guidance documents have the advantage of being selective in what elements you decide to adopt. The ESG one in development is a good example, ESG as a topic is huge, a smaller organisation may not realistically be able to implement all of the advice.
But, it can be used as a starting point for a materiality assessment that will allow you to be selective of the core subjects you apply to your business.
The idea of guidance documents is not to be a bolt on, as those quickly get forgotten. It’s all about embedding their elements into existing processes.
[17:10] Utilising elements of ISO Implementation for ESG reporting: If you’ve already got an ISO Management System in place, i.e. ISO 14001 or ISO 45001, then you’ll already have objectives, processes and monitoring & measurement in place to address those elements.
ISO 26000 is another good example as it covers a wide range of topics, including human rights, labour practices, the environment, community involvement and development, consumer issues and fair operating practices. Some may not be applicable to you, but as mentioned, it’s a guidance document so you have the freedom to be selective about the aspects you incorporate into your management system.
You need to decide what really applies to you. It’s better to prioritise and take 10 steps on one subject vs 1 on 10 subjects.
[20:25] ESG isn’t a once a year activity: There’s no tick box exercise that you can do once a year and claim compliance, ESG is an on-going endeavor for as long as your business is running. It’s a way of operating, much like ISO Standards. It will develop and grow with your business.
[21:30] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[23:36] Will elements of ESG become certifiable down the line? We’ll never say never! It’s still very much a developing field. There is currently a framework being developed by the International Standards Organisation, it’s currently in draft form.
Ali herself is on the commenting committee for it’s development, and can confirm that the framework is looking at the links between certifiable Standards and the tangible application.
ISO Standards require third-party verification of your claims before getting certified. In that aspect, they’re the perfect tool to provide tangible proof that you are doing what you say you’re doing, but only in select aspects.
ESG is broad, almost too broad to certify. It’s not really feasible for one person to come in and assess a whole business like they would do for an ISO Assessment, there’s simply too much to cover!
[25:00] The trouble with ESG verification: Currently, a lot of voluntary schemes require you to report against and fulfill, but they are very sector specific because a general one would be too broad and likely will not cover every aspect appliable to every business.
Schemes out there are doing something to battle greenwashing, as the environmental aspects are easier to verify, however social aspects are a lot more tricky and can get even more complicated outside of the UK where there is no HSE annual reporting available.
[26:20] How can you support the Social aspect of ESG?: Measuring your social value can difficult, many think of education as the solution. Here are some ideas to consider:
· Working with local schools – Improvement projects driven by Student run business studies
· Work experience
· Charitable work – allow staff to have a charity day as part of a benefits package
[28:10] How can we prevent the greenwashing of ESG compliance?: Government Bodies are working to tackle this. It’s being built into legislation to prevent greenwashing in future where self-policing hasn’t gone far enough.
Trade Associations are also pushing their members towards more legitimate frameworks to ensure they do remain accountable and transparent about their activities in relation to ESG compliance.
[30:00] What resources do Blackmores have to help? We’ve developed an ESG Gap Analysis, based on the guidance provided in ISO 26000 Social Accountability.
This ESG Gap Analysis will highlight where you’re already compliant and where there is work to be done.
You may be surprised to see that you’re more compliant that you think! Especially if you’re certified to one or many ISO Standards.
We also have a Materiality Assessment, which will help you to determine which topics are of importance to your business and your stakeholders.
You can take the findings from both to help develop your ESG Strategy. If you’re not mandated to do any reporting, you can leave it at that. However, you may want to consider sector specific frameworks to get ahead of the curve for when elements of ESG do become mandated down the line.
[36:00] Where should you start with tackling ESG using ISO Standards? If you’re certified to one or many ISO Standards, then you will have processes in place that can support an ESG initiative program strategy, and you can make it as big or as small as you want.
Start by looking at your environmental, social and governments impacts and work to embed ESG into your existing ISO Management System before they become mandated by stakeholders and legislation – being ahead also feeds into the principles behind social responsibility.
You're embedding a culture, and it becomes a norm which can be developed further. Then, when legislation or customer requirements come in, you’re already prepared to answer.
Also, with ESG there is a focus on people and you can't have a successful business without good people. ESG isn’t only attractive to your customers, but also to potential employees who will want to work for ethical, sustainable businesses. If you aren’t keeping up and fulfilling that, you will struggle to find new talent.
It also goes without saying that being ESG compliant will attract consumers. Greenwashing, as frustrating as it is, exists for a reason - because people want businesses to be sustainable. People wouldn't lie about it if it wasn't important to someone, so stand out by beating the greenwashing allegations and take the right steps towards tacking ESG.
If you’d like to book a demo for the isologyhub, or would like help with an ESG Gap Analysis, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In July 2024, A logic error in an update for CrowdStrike’s Falcon software caused 8.5 million windows computers to crash. While a fix was pushed out shortly after, the nature of the error meant that a full recovery of all effected machines took weeks to complete.
Many businesses were caught up in the disruption, regardless of if this affected them directly or by proxy due to affected suppliers. So, what can businesses learn from this?
Today, Ian Battersby and Steve Mason discuss the aftermath of the CrowdStrike crash, the importance of good business continuity and what actions all businesses should take to ensure they are prepared in the event of an IT incident.
You’ll learn
· What happened following the CrowdStrike crash?
· How long did it take businesses to recover?
· Which ISO management system standards would this impact?
· How can you use your Management System to address the affects of an IT incident?
· How would this change your understanding of the needs and expectations of interested parties?
· How do risk assessments factor in where IT incidents are concerned?
Resources
· Isologyhub
· ISO 22301 Business Continuity
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian Battersby is joined by Steve Mason to discuss the recent CrowdStrike crash, the implications on your Management system and business continuity lessons learned that you can apply ahead of any potential future incidents.
[03:00] What happened following the CrowdStrike crash?– In short, An update to CrowdStrike’s Falcon software brought down computer systems globally.
8.5 million windows systems, which in reality is less than 1% of windows systems, were affected as a result of this error.
Even still, the damage could still be felt from key pillars of our societal infrastructure, with a lot of hospitals and transportation like trains and airlines being the worst affected.
[04:45] How long did it take CrowdStrike to issue a fix? – CrowdStrike fixed the issue in about 30 minutes, but this didn’t mean that computers affected would be automatically fixed.
In many cases applying the fix meant that engineers had to go on site to many different locations which is both time consuming and costly. In some cases Microsoft said that some computers might need as many as 15 reboots to clear the problem.
So, a fix that many were hoping would solve the issue ended up taking a few weeks to fully resolve as not everyone has IT or tech support in the field to issue a manual reboot.
A lot of businesses were caught out as they don’t factor this into their recovery time, some assuming that an issue like this is guaranteed to be fixed within 48 hours, which is not something you can promise. You need to be realistic when filling out a Business Impact Assessment (BIA).
[07:55] How do you know in advance if an outage will need physical intervention to resolve? – There is a lesson to be learnt from this most recent issue. You need to take a look at your current business continuity plans and ask yourself:
· What systems to you use?
· How reliable are the third-party applications that you use?
· If an issue like this to reoccur, how would it affect us?
· Do we have the necessary resource to fix it? i.e. staff on site if needed?
Third-parties will have a lot of clients, some may even prioritise those that pay a more premium package, so you can’t always count on them for a quick fix.
[09:10] How does this impact out businesses in terms of our management standards? – When we begin to analyse how this has impacted our management systems, we can’t afford to say ‘We don’t use CrowdStrike therefore it did not impact us’ – it may have impacted your suppliers or your customers. Even if there was zero impact, lessons can be learned from this event for all companies.
Standards that were directly affected by the outage were:
· ISO 22301 – Business Continuity: Recovery times RPO and RTO; BIA; Risk Assessments
· ISO 27001 – Information Security: Risk Assessment; Likelihood; Severity; BCP; ICT readiness
· ISO 20000-1 – IT Service Management; Risk Assessment of service delivery; Service continuity; Service Availability
Remember, our management systems should reflect reality and not aspiration
[11:30] How do we use our Management Systems to navigate a path of corrective action and continual improvement? – First and foremost an event like this must be raised as an Incident – in this case it would no doubt have been a Major Incident for some companies. This incident will typically be recorded in the company’s system for capturing non-conformities or continual improvement.
You could liken this to how ISO 45001 requires you to report accidents and incidents.
From the Incident a plan can be created which should include changes to be considered or made to the management system.
The Incident should lead us to conducting a lessons learned activity to determine where changes and improvements need to be made.
We are directed in all standards to Understanding the Organisation and its context
The key requirement here is to determine the internal and external issues that can impact your management system, and prevent it from being effective. Whatever method a company uses for this, perhaps a SWOT and PESTLE; the CrowdStrike/Microsoft Outage should be included in this analysis as a threat and/or Technical issue.
[15:15] What are the lessons learned from our supply chain? – In many ISO Standards, such as ISO 9001 and ISO 27001, there is a requirement to review your suppliers and the effectiveness of the service they’re delivering.
So you could send them an e-mail to ask how they have dealt with the issue, what actions did they take and how long did it take to fully restore services.
This is a collaborative process that you can factor into your own risk assessments, as you can make a better judgement on future risk level if you are privy to their recovery plans.
Many people still think of that requirement only in relation to goods and products. i.e. has my order been delivered ect. However, it relates to services such as IT infrastructure as well. You rely on that service, so evaluate how well it’s being delivered.
[17:35] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[19:50] Once you have established lessons learnt, what’s next? – The Standards provide a logical path to work through.
One of the first steps is to conduct a SWOT and PESTLE, and doing so after a major incident is recommended, as your threats and weaknesses may have changed as a result.
Do not simply put the sole blame on a third-party who an incident may of originated from. This is about your response and recovery, your plans coming into effect to deal with the situation, not about who is at fault.
One such finding may be your lack of business continuity plans, in which case, looking at implementing aspects of ISO 22301 may be an action to consider.
It’s also important to note down any positives from the incident too. You may have dealt with something very fast, communicated the issue effectively and worked with clients to ensure that their level of service was minimally impacted.
If a team dealt with a situation particularly well, they should be recognised for that, as it really does go a long way.
[23:55] The importance of revisiting your SWOT and PESTLE: These exercises shouldn’t just be a one time thing. You should be addressing these after incidents and any major changes within the business.
Ideally, you should be looking at these in all your meetings, as many actions may need to be escalated to a strategic level.
If you’d like to learn about how one of our clients embraced SWOT and PESTLE, and used it to their advantage, check out episode 53.
[25:20] How has our understanding of the needs and expectations of Interested Parties been changed? - How has the Outage impacted the needs and expectations of interested parties? Understanding this might lead companies to ask questions about the robustness and effectiveness of different parts of the management system:
· Risk Assessment
· BIA for BCP
· Recovery Plans
· DR plans
· Service Continuity
[27:50] What should you be considering with your risks assessments? - Risk Assessments, if they follow the traditional methodology, with have Likelihood and Impact/Severity scores an in the light of this outage, and any event, the likelihood and Impact scores should be updated.
If a company has set the likelihood as ‘once every 5 years’ it should seriously consider changing this to ‘once every 6 months’ or 'once every year’ to understand if this poses any new risks to the business. The likelihood score would of course be updated every year until it has recovered to ‘once every 5 years’.
The impact is important to look at. If a company has been impacted by this outage, what has it cost the company to recover – talk to finance and other departments to understand the cost and change the scoring accordingly.
[33:20] Why should a business carry out a risks assessment as part of lessons learnt? - Our risk assessments are not a one-off, but should be living documents that reflect the status of threats to the business. In ISO 27001 there is a statement to identify the ‘Consequences of unintended changes,’ and it could be argued that an Outage on the level of the CrowdStrike/Microsoft outage was an ‘unintended change that led to consequences in many businesses.
So, use your risk assessments as live tools to report on the reality facing the organisation.
Similarly, BIA assessments for BCP should be reviewed to determine if the assumed impact reflects the real impact; also look at the recovery plans to see if they are effective.
If a recovery plan has stated that this type of incident could be recovered in 48 hours, and in reality it has taken 2 weeks, it means that recovery times in terms of RPO and RTO should be reviewed.
Remember - your management system should reflect reality and not aspiration.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Continual Improvement is at the heart of every ISO Standard.
The cyclical nature of ISO Standards lends itself to regular review and update of your Management System, to ensure it’s working efficiently and to address any issues or opportunities that inevitably crop up.
However, Integrating these improvements can be challenging, even for mature systems.
Today Ian Battersby explains the concept of Improvement as defined in ISO Standards, how to find root cause for non-conformities and integrating improvement actions from multiple sources.
You’ll learn
· What is meant by ‘Improvement’ in ISO Standards?
· Common misconceptions about Improvement in ISO Standards
· How to address non-conformities in your Management System
· Finding the root cause of a non-conformity
· Integrating Improvement actions
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian Battersby will be explaining what Improvement means in relation to ISO Standards, how to address non-conformities and integrating the required Improvement actions.
[02:30] What is meant by ‘Improvement’ in ISO Standards? – One of the requirements of all Management System standards is to determine and select opportunities for improvement (Clause 10). This is the fundamental aim of Management Systems: to make things better
In the words of the standards, it is so that an organisation can:
“Implement any necessary actions to meet customer requirements and enhance customer satisfaction
These shall include:
a) improving products and services to meet requirements as well as to address future needs and expectations;
b) correcting, preventing or reducing undesired effects;
c) improving the performance and effectiveness of the management system.”
An organisation going through certification for the first time may never have had in place a system for planning improvements. Some organisations are dealing with improvements, but not necessarily through a single, consistent route.
While you can meet the requirements of the standards without a single route, the standard is not prescriptive in how you go about this.
[04:45] Common misconceptions about non-conformities – the standard does go on to cover nonconformity and corrective action (10.2); is it suggesting these as the main source of non-conformities (NC). It isn’t really explicit about other sources, other than specifically including customer complaints as a form of NC.
However, there’s a strong argument for consolidating data from different sources, so it’s worth considering how complaints data is handled. Other sources of non-conformities can include your Internal Audit findings, addressing where you may not be meeting client expectations, addressing failure to meet legal obligations ect.
As a reminder, ISO 9000 (Fundamentals and vocabulary) includes the definition of nonconformity: non-fulfilment of a requirement: need or expectation that is stated, generally implied or obligatory i.e. Legal / client expectation.
[10:00] Addressing non-conformities – You need to evaluate the need for action to eliminate the cause of the nonconformity, to ensure that the issues doesn’t recur, or pop-up elsewhere.
When a non-conformity does occur, you need to:
· Determine the causes
· Determining if similar nonconformities exist, or could potentially occur;
Any corrective actions should be appropriate to the effects of the nonconformities encountered.
So, you don’t need to commit a huge amount of resource to minor issues.
[11:40] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[13:40] Finding the cause of non-conformities – Without removing the cause, repetition may occur, and this is where integrating improvement data from multiple sources comes into its own.
The idea of Common cause is - a single cause may manifest itself in very different outcomes. For example, a lack of competence could lead to a process being delivered wrongly, leading to reducing level of quality in service or product, which would be picked up as an NC.
Competence is an area which can also lead to NC’s, through the result of a helath & safety incident or environmental incident if people aren’t trained to use equipment or follow set procedures.
It can also lead to a customer complaint where the failed process is apparent to a customer.
If a product NC isn’t spotted until after the product delivered/in service it could lead to a warranty claim
Or even a claim for damages should it lead to harm/loss to the customer
It could lead to regulatory breach or even enforcement or legal action
Some of these outcomes may not be apparent until they have impacted upon a customer or other interested party, so would not be recorded internally through a nonconformity system.
All this to say, finding the root cause will require looking in a lot of different places. Having a common methodology in place to address non-conformities, including considerations for different types of issues, makes life a lot easier.
[15:55] Integrating Improvements from multiple sources: There are many sources which can highlight opportunities for Improvement, including:
Internal Audit – This is a conformity assessment, so any gaps or issues identified will be NC’s that need addressing.
Surveillance Audit / Certification Audit – Your Certification Body will also be conducting a third-party conformity assessment, which may highlight something you’ve missed in your own internal audits.
Supply Chain Audit – Auditing your supply chain can also highlight NC’s that you can encourage them to address, both for your benefit and theirs.
Client Audit – You may be audited by clients, especially where there may be specific technical industry related issues.
Management Review – This is the perfect platform to identify Opportunities for Improvement. You can highlight NC trends from Internal Audits here and define if they need to be addressed separately. You will often have members of senior management present at a Management Review, so there is a greater chance for you to plan tangible actions to address issues, especially if they are business critical.
SWOT / PESTLE – This usually happens early on in the Implementation phase, but there’s no reason why you can’t repeat the exercise on an annual basis. This exercise directly identifies your risks and opportunities, both from internal and external sources. Getting input from all levels of staff as they may also shed light on potential NC’s and opportunities other departments may not even be aware of.
Accident reporting / Safety observations – Any incident should be viewed as an opportunity to improve. Some accidents are unavoidable, but many are a result of someone not following instructions, equipment being left unattended or in the wrongs location ect. Addressing these will help you to ensure a safer environment.
Site inspections – Just walking around your site can yield new insights. Ask other departments that may not visit your area to do a sweep and report any findings. Sometimes all you need is a fresh pair of eyes to highlight issues you’ve missed.
Complaint / Other customer feedback – Allow clients and stakeholders to have input.
Regulatory requirements – You may discover you are breaching a regulation, which needs to be addressed ASAP. Consider a legal register to keep track of all your legal and regulatory requirements.
Enforcement (HSE, EA, professional body) – You may have opportunities for improvement enforced by professional bodies such as the HSE or Environment Agency.
Management Action – Any management meetings should take opportunity suggestions from both management and the general workforce.
Product NC’s – If you’re in the manufacturing industry, you likely already have a system in place for monitoring any product related non-conformities. This process can be applied on a broader scale, as it embodies the same principles: Identify the problem, find the root cause, address the root cause, put preventative measures in place to stop recurrence.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In the workplace, everyone is responsible for safety.
It’s not just for managers or senior management to worry about where legislation is concerned, everyone from the top to the bottom needs to be actively ensuring the safety of others.
ISO 45001 highlights the importance of this in its most recent iteration, which includes a specific requirement for the consultation and participation of workers. But, how does this work in practice?
Today Ian Battersby explains what consultation and participation of workers in ISO 45001 is, and how you can incorporate elements of reactive and proactive hazard reporting to meet that requirement.
You’ll learn
· What is consultation and participation of workers in ISO 45001?
· What is the identification of hazards?
· What’s the difference between reactive and proactive hazard reporting?
· Common approaches to reactive and proactive hazard reporting
· Proactive hazard reporting in action
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian Battersby will be explaining reactive and proactive hazard reporting, and how this relates to the consultation and participation of workers (clause 5.4) requirement in ISO 45001.
[02:30] What is ‘Consultation and Participation of workers? – ISO 45001’s clause 5.4 states:
“The organization must have a process for consultation and participation of workers at all levels and functions, and their representatives in the development, planning, implementation, performance evaluation and actions for improvement of the OH&S management system.”
ISO 45001 expects occupational health and safety aspects to be fully embodied within the organisation structure. All workers should be aware of their responsibilities, and work together to meet the organisation’s health and safety goals.
Everyone is responsible for safety.
Consultation implies two-way communication, so workers can provide feedback to be considered by the organisation before taking a decision. This is important; the organisation has to consider workers’ feedback before making decisions
Participation implies the contribution of workers, including non-managerial workers, to decision-making related to OH&S performance and to proposed changes.
[05:50] Hazard Identification – A specific issue which must be considered is the identification of hazards:
· Identifying hazards and assessing risks and opportunities (Clauses 6.1.1 and 6.1.2);
· Determining actions to eliminate hazards and reduce OH&S risks
There are numerous sources for consideration when it comes to hazards
· How work is organised
· Routine/non-routine activities
· Past incidents
· Emergency situations
· People
· Processes
· Workplace design
· Equipment
· Change
[07:35] What’s the difference between proactive and reactive hazard reporting? – Proactive is about spotting hazards in advance and putting in place measures to minimise the chances of them materialising and causing harm (eg, through an accident)
Reactive is in response to an event which has already occurred, such as an accident; a hazard existed without being spotted already and dealt with.
[08:20] A common approach to proactive hazard reporting – Risk Assessment. Consider hazard sources (i.e. people, processes, equipment, workplace etc) and consider what may happen; what could go wrong. Then consider what controls could be put in place to try and prevent that happening.
Risk assessment can help you to demonstrate worker consultation and participation by including those affected:
· Involved in or affected by an activity
· Those delivering a process
· Using equipment
· Occupying a workplace
Those people have valuable knowledge and understanding, sometimes moreso than someone in a supervisory / managerial role.
And an absolute must: recording that all employees have read, understand and are committed to the controls included in Risk Assessments; that process may also give rise to workers’ further involvement – through querying, suggesting change etc
This also helps the culture of hazard spotting and promotes engagement among the workforce, both of which are vital in driving a proactive approach
[11:10] A common approach to reactive hazard reporting: Accident reporting systems is the obvious choice. However, there are ways you can make this more proactive.
There are various levels to accident reporting. Traditional systems wait until an accident occurs before recording and acting upon it.
Some organisations also record near misses: where an event has occurred, but no harm has been caused.
This approach in itself can be very valuable; and it provides an opportunity to act before any harm has occurred.
However, we can go a step further and allow the workforce to observe what’s happening; their surroundings and listen to what they feel may present a hazard to them and their colleagues (remember, everyone is responsible for safety).
[13:00] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[15:30] Proactive hazard reporting in action: Ian recounts his experience in a previous company where their proactive hazard reporting led to meaningful change.
This took place in a large manufacturing plant, but there was also significant office-based activity as well.
Because of the nature of the work, many people would not have access to online systems so there was both online and paper systems; this is important; if everybody is responsible, everybody needs access and engagement is vital.
In addition to the traditional accident/near miss system, there was a safety observation card (all data ended up in the same database). It was simple to fill out, would have only taken about 5 minutes at most.
In an organisation of 500ish, we received 2200 observation cards per year by the time I left.
When combined with accidents/incidents, there’s a predictable cycle: more reports, poor quality, more accidents, better quality, improved actions, fewer accidents.
[17:30] Creating an observation card: It should be easy to understand and record what’s necessary, recommended content includes:
· Date / Time
· Who was involved – employee / contractor / visitor ect
· Location of hazard / incident
· Description of hazard / incident (ideally in 10 words or less)
You could get more granular and include:
· Identification of an unsafe condition or unsafe act
· Type of hazard or incident: slip, trip or fall / exit obstructed / machinery being used unsafely / unsafe structure / not using PPE
You could also include an option for actions taken if you decide to inform a manager of the issue, if you’ve corrected someone on the use of equipment or PPE ect.
[21:15] The Importance of peer inspections: Often they would have supervisors from one area, checking a different one. This fresh pair of eyes may offer new insight into something that you usually miss!
Note that you should also encourage any site visitors to do the same. The fact that you’d ask them to report any incident also displays that you take safety seriously, and are open to feedback to improve.
[22:40] Hazard scoring: In order to judge that quality, they went a step further and graded all observations from 1-3:
Saw something but didn’t act
Saw it, acted to put it safe there and then
Saw it, acted to prevent it happening again
This allowed them to judge how effective hazard spotting is in removing cause and filters out points-scoring.
[22:45] The results speak for themselves:
Increasing number of observations
Increasing number of participants
Increasing quality of observations
Reducing number and severity of accidents.
Over five years, they increased the number of observations per employee ten-fold.
As a result, they reduced lost time accidents over 75%
This was a superb example of a personal safety campaign and a great demonstration of consultation and participation,
It’s not difficult to do, but it needs leadership commitment, constant and clear comms, user-friendly systems and effective analysis / reporting.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ESG compliance has fast become a focus for many organisations looking to address their wider sustainability profile.
However, its broad framework has left many scratching their heads on exactly where to start with evaluating and addressing various elements of Environmental, Social, and Governance compliance.
For those looking for some direction, you may already have a solid foundation in place if you’re certified to one or many ISO Standards.
Today Steph Churchman will explain what ESG is, how it can be scored and what role ISO Standards can play in ESG compliance.
You’ll learn
· What is ESG?
· What scoring systems are available for ESG?
· How can ISO Standards support ESG compliance?
· What ISO Standards can support each pillar of ESG?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Steph will be breaking down what ESG compliance means, how ISO Standards can support ESG compliance and give some examples of what ISO Standards can support each pillar of ESG.
[02:50] What is ESG? – ESG stands for Environmental, Social, and Governance. Analysis and evaluation against these three elements help organisations to consider different areas within their overall sustainability profile.
The Environmental section looks at issues surrounding climate change and actions to address an organisation’s environmental responsibility. This includes monitoring and management of your energy consumption, waste management and pollution. It also seeks to tackle how organisations can address, reduce and mitigate their overall environmental impact.
The Social aspect is based around the relationships an organisation has with its stakeholders. This is focused on employees and looks at a broad range of topics including employee wellbeing, fair and competitive pay, benefits and human resource related policies. Considerations can also include wider business relationships such as supplier relations, local community and government work.
Governance criteria focuses on creating a business environment that is fair, transparent, and accountable. Considerations in this area include board composition, fairness in pay structures and executive compensation, business ethics and risk management.
[04:15] An evolution of CSR – CSR (Corporate Social Responsibility) is very similar to ESG, but is less sustainability focused. It also lacked substance in the form of effective and accountable scoring systems that held businesses to account. This is where ESG differs, with many scoring systems, certifications and even mandatory requirements driving businesses to address their compliance.
[04:45] ESG scoring – There are many schemes, scoring systems and certifications available for ESG, some of which are specific to industry sectors and company sizes. What one you pick will be up to you (note that some many be mandatory in select countries), however, here are a few examples:
The S&P Global ESG Score – This assesses a company's performance and management of ESG risks and opportunities using a combination of company disclosures, media analysis, and industry-specific questionnaires. A score of 0-100 is given based on their findings and are relative within a company’s industry sector.
Fitch Ratings ESG Relevance Scores - Fitch Ratings assigns ESG Relevance Scores alongside their traditional credit ratings. These scores assess how ESG factors could impact a company's creditworthiness. Their scores range from 1-5, with 5 indicating the highest ESG relevance to credit risk.
MSCI – They offer ESG ratings for a broad range of companies, it’s not really limited by sector or size. They use a letter grade system, going from AAA-CCC, to assess a company's relative ESG risks and opportunities compared to its peers. The scoring for this one assigns companies as either an ESG leader, average or laggard within their industry.
[06:10] How can ISO Standards support ESG Compliance – It's important to clarify that there's no single ISO standard that guarantees ESG compliance because ESG is a broad framework. However, ISO standards provide a strong foundation for implementing many aspects of an ESG strategy.
[06:35] Supporting ESG – Structure and Framework: ISO standards offer a structured approach to managing environmental, social, and governance practices. This helps companies identify key areas for improvement and develop a systematic plan to address them.
[07:10] Supporting ESG – Improved Performance: By following ISO standards, companies can demonstrably improve their environmental performance, social responsibility, and governance structures by putting in frameworks that align with best practice standards
[07:30] Supporting ESG – Transparency and Credibility: Achieving certification to a relevant ISO standard involves a third-party audit, which verifies that a company's systems and processes meet the standard's requirements. This certification acts as a credible signal to stakeholders such as your investors, customers, regulators, that you’re committed to ESG principles.
[07:55] Supporting ESG – Risk Management: Proactive management of ESG risks is a key component of any ESG strategy. Many ISO standards focus on risk identification and mitigation. For example, ISO 37001 (Anti-Bribery Management Systems) helps identify and address bribery risks, which can have significant financial and reputational consequences. Or ISO 45001 health and safety management, which requires risk assessments to be carried out to ensure the safety and well being of your employees on site locations, which would fall under the social aspect of ESG.
[08:30] Supporting ESG – Competitive Advantage: Strong ESG performance is increasingly sought after by investors and stakeholders. Implementing ISO standards can help companies demonstrate their ESG commitment and gain a competitive advantage in the marketplace. You’ll also feel the benefit of gaining multiple badges, through ISO certification and possibly an ESG score if you choose to go through one of the official scoring schemes.
[08:55] Think of ISO standards as building blocks. They provide the foundation and structure for a strong ESG strategy. By implementing relevant standards and achieving certification, you can demonstrate a dedicated commitment to ESG principles.
[09:50] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[11:55] What ISO Standards can support the Environmental aspect of ESG Compliance?:
· ISO 14001: Environmental Management - This provides a framework for managing environmental impacts, reducing waste, and improving your resource efficiency.
· ISO 50001: Energy Management – this helps companies monitor and optimize their energy use with the aim to help reduce greenhouse gas emissions.
· ISO 20400: Sustainable Procurement – This will help you to adopt sustainable procurement principles and practices within your organisation, by looking at how you can reduce waste, choose more sustainable options for required resources, how you can extend the life of resources available through remanufacturing and recovery of waste, and encourages the use of more innovative products and services.
· ISO 20121: Sustainable Event Management – This Standard is mostly applicable to the events sector, and aims to help reduce the amount of waste produced during events, either through potential energy savings and the production and recycling of resources used during an event. It’s recently had an update, so check out our latest episode to find out what the changes are.
· ISO 14064: Greenhouse Gas Verification – This provides a framework for measuring and managing greenhouse gas emissions. This is a crucial step if you’re working towards Net Zero, as you need to know what your baseline is before you can work on reducing and offsetting remaining emissions.
· ISO 14068: A framework for helping businesses achieve Net Zero, this standard will replace PAS 2060 in November 2025, so anyone looking into PAS 2060 now may be better off going with ISO 14068 as it includes more guidance on purchasing credible carbon credits.
[14:15] What ISO Standards can support the Social aspect of ESG Compliance?:–
· ISO 26000: Social Responsibility – which offers guidance on integrating social responsibility practices throughout your organization.
· ISO 45001: Occupational Health and Safety Management - which helps companies create a safe and healthy work environment. It provides a robust set of requirements designed for improving workplace safety in organisations and supply chains, with the aim of reducing workplace injury and illness.
· ISO 45003: Psychosocial Health & Safety Management aka Mental health in the workplace. For the last 4 years or so, work related stress, depression and anxiety has been the leading cause for work related ill-health cases and lost working days. That’s according to the annual HSE reports, which clearly highlights a big issue that many more need to consider and address.
[14:15] What ISO Standards can support the Governance aspect of ESG Compliance?:–
· ISO 9001: Quality Management – this is the leading global ‘quality mark’ for businesses and designed as a vital business improvement tool. It’s quite simply A blueprint for running your business successfully.
· ISO 22301: Business Continuity Management - Which provides a basis for planning to ensure your long-term survivability following a disruptive event. This is a Standard that many align with, but don’t always certify to, and for good reason as it provides some invaluable guidance for establishing robust Business Continuity Plans.
· ISO 27001: Information Security – This is a Standard that is common place for most sectors now, given how reliant we all are on tech. ISO 27001 will help you to implement an Information Security Management System (ISMS), which is a systematic approach to managing sensitive company information, ensuring it remains secure and available. It encompasses people, processes and IT systems.
· ISO 37001: Anti-Bribery Management Systems - It’s the International Standard that allows organizations of all types to prevent, detect and address bribery by adopting an anti-bribery policy, appointing a person to oversee anti-bribery compliance, training and carry out risk assessments.
· ISO 44001: Collaborative Business Management – This was originally a British Standard that had been created to provide a framework for creating and managing collaborative business relationships between organisations. The standard promotes the best way for businesses to work together, thus effectively developing and managing their interactions with each other for maximum benefit to all.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 20121:2012, the Standard for Sustainable events management, was originally created and launched in coordination with the London 2012 olympics. 12 years on, it seems only fitting that its next revision would applied to the 2024 Paris Olympic Games.
10 Years on from it’s original release, the Standard has received a substantial update to not only bring it in-line with other ISO Standards, but to also address additional elements within event management, such as human rights and legacy.
Today Steph Churchman will explain the changes to ISO 20121:2024, what certified companies must do to transition and the consequences of not doing so before the deadline.
You’ll learn
· What is ISO 20121?
· What are the changes to ISO 20121:2024?
· What steps should certified companies take to complete their transition?
· What should you be updating?
· What are the consequences for not completing your transition ahead of the deadline?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Steph will be discussing the changes to the Sustainable Event Management Standard, ISO 20121:2024, in addition to outlining what you should be updating ahead of your transition to the latest version of the Standard.
[02:30] What is ISO 20121? – . The Standard for Sustainable events management was originally created and launched in coordination with the London 2012 olympics.
When it came to planning the 2012 Olympic Games, they took a step back and considered the impact of required development and construction would have on biodiversity, as well as how they could reduce their Greenhouse Gas emissions and general waste in the preparation and running of the event.
12 years on, it seems only fitting that it’s next revision would applied to the 2024 Paris Olympic Games.
ISO 20121 specifies the requirements for an Event Sustainability Management System to improve the sustainability of events. The standard applies to all types and sizes of organisations involved in the events industry – from caterers, lighting and sound engineers, security companies, stage builders and venues to independent event organisers and corporate and public sector event teams.
[04:45] A high-level overview of the changes to ISO 20121:2024 – One of the biggest and most welcomed changes is the fact that the Standard is now aligned with the familiar High Level Structure that many other ISO’s follow. This means it will be easier to integrate with other Standards like ISO 9001 and ISO 14001.
Next, there is a bigger focus on climate change, legacy and human rights. These elements weren’t necessarily missing from the previous version, but they weren’t a key focus either.
[05:10] Climate Change in ISO 20121:2024 – , ISO 20121:2024 now explicitly requires considering climate change and its impact on your event and stakeholders. So, this might involve carbon emission reduction strategies and adapting to potential climate-related disruptions. Biodiveristy may also fall under this, especially if your events require construction, or take place in an outside venue such as a park or field.
A quick reminder that 31 common ISO Standards also received a Climate Change Amendment, so if you haven’t addressed that yet, check out our podcast episode and workshop recording to learn about what you need to do.
What does this focus on climate change mean for certified companies?:
· It provides an opportunity for event professionals and event organisers to demonstrate leadership in taking action around climate change
· Certified organisations are required to ensure that any carbon offsetting completed via carbon credits are credible
· ISO 20121:2024 Standard facilitates the process of taking credible action and aligns ISO 20121 with big changes relating to climate change
[06:55] Human Rights in ISO 20121:2024 – The new version also expands beyond environmental concerns to encompass human and child rights, social impact (including mental health and diversity), and digital responsibility. Your management system will need to address these aspects throughout the event lifecycle.
What does the increased focus on human rights in ISO 20121 mean for certified organisations?:
· Certified organisations will need to demonstrate and adhere to UN Guiding Principles on Business and Human Rights.
· The revised standard also now references social impact in its definitions – primarily in the definition for Sustainable Development and Stewardship.
· A new Annex has been added – Annex D: Guidance on Human and Child Rights.
· Added guidance states that event organisers should consult with Human and Child Rights experts and conduct a Human Rights Assessment to identify potential risks to the people as a result of an event and its surrounding activities.
· You should publish a Human Rights Policy to ensure that Human Rights consideration is embedded in the whole lifecycle of an event.
[08:40] Legacy in ISO 20121:2024 – An added focus on Legacy provides an opportunity to event organisers to focus, not only on the few days of event delivery, but also supports in creating enduring results for the hosting community.
For example, creating an economic impact for the local population, by providing the opportunity to acquire new skills, to share best practices on how to do events in a more sustainable way or by improving a public place close to the event.
[09:20] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[11:30] A strengthening of Stakeholder Engagement – The Standard now emphasizes demonstrating sustainability throughout your supply chain. This might involve you requesting proof of sustainability practices from vendors and incorporating ethical sourcing practices.
The definition of stakeholders has also now been expanded to include partners and sponsors. So, you’ll need to consider how their sustainability practices align with your event's goals.
The policy clause now requires reporting on your sustainability achievements and lessons learned. Building a system for tracking and reporting these aspects will be crucial, and will likely involve a lot more communication between your stakeholders to gather any necessary data for reporting purposes.
[12:35] alignment and flexibility – The updated standard aligns with other management system standards thanks to the high level structure update, making integration easier for organizations with existing systems.
The revised standard also caters to events of all sizes and complexities, allowing for adaptation to your specific needs.
There’s now alignment with Global Frameworks, like the UN Sustainable Development Goals (SDG’s) and the Paris Agreement. If you’d like to learn more about the SDG’s, check out a few previous podcast episodes: 106, 107 & 108.
[13:30] Transition Deadline – What happens if you miss it? – Anyone certified to the 2012 version of the Standard will have until the 31st March 2027 to transition to the 2024 version.
If you don’t, you’ll risk losing your certification, and you’ll have to go through the whole Stage 1 and 2 Assessment again to get that certificate back, which is obviously quite costly.
[14:15] What do you need to do to transition? – Here’s a very high-level of the steps you should take:
· Review and conduct a Gap Analysis: This is to compare your existing system against the new standard's requirements to identify areas needing improvement.
· Update your Policies and Procedures: specifically your event sustainability policy to reflect the broader range of sustainability issues and incorporate reporting requirements.
· Develop a plan to engage with a wider range of stakeholders, including sponsors and partners, on sustainability initiatives.
· Review your Supply Chain Management: This will involve establishing or updating procedures for assessing and integrating sustainability practices throughout your vendor network.
· Training and Awareness: Any and all changes should be communicated. Educate your team on the new standard's requirements and integrate them into event planning and execution processes.
· Carry out Internal Audits: Once you’ve implemented the changes, audit against the new Standard and ensure you’re compliant. Then you’ll need to prepare for your Certification Body Transition visit.
[15:30] What Specific actions can you take to update your ISO 20121 Management System?
Here are some suggested actions to address Human Rights and Children’s Rights:
· Update your event sustainability policy to explicitly state your commitment to respecting human rights and children's rights throughout the event lifecycle.
· Update your Risk Assessments as you’re going to need to identify potential human rights risks associated with your event, such as discrimination in hiring or unfair labour practices within the supply chain.
· Review your Supplier Management as you’ll need to ensure your suppliers uphold human rights standards.
· Engage with relevant stakeholders like human rights organizations or local communities to understand potential human rights concerns and incorporate their feedback into your planning.
A few other actions you could do include:
· Partnering with organizations promoting fair labor practices and human rights.
· Including human rights clauses in contracts with suppliers and partners.
· Conduct training for staff on identifying and mitigating human rights risks.
· Implementing a grievance process for reporting potential human rights violations.
[17:00] What further actions can you take to address Legacy?:
· Integrate legacy planning into the early stages of event development. Consider aspects like infrastructure, also workforce development (for example training opportunities for local communities), and universal accessibility for people with disabilities.
· Develop metrics to measure the positive legacy of your event. This could involve tracking the number of jobs created, increased accessibility measures implemented, or infrastructure donated to the community.
· Consider the potential to partner with local organizations to ensure the event's legacy benefits the community in the long term. This might involve collaborating on infrastructure projects or workforce development initiatives.
· You should also Conduct a post-event impact assessment to evaluate the event's legacy.
[18:00] Reporting on the social, economic and environmental impacts – The first step should be to develop a Reporting Framework: This framework should consider relevant metrics for social (e.g., job creation, diversity), economic (e.g., local business involvement), and environmental (e.g., carbon footprint, waste generation) impacts.
Next, you need to Implement a system for collecting and analyzing data related to your event's social, economic, and environmental performance.
And lastly, choose appropriate communication channels for your sustainability report, such as your website, annual reports, or dedicated sustainability reports.
You could look at specific reporting software or get help from a third-party such as Blackmores.
We’d recommend purchasing a copy of the Standard so you can review the specific changes yourself, in addition to reviewing the updated guidance provided in the Annexes.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO Standards provide a framework to help businesses manage various aspects of their activities. Whether that’s quality, risk, environmental or Information Security management, they provide invaluable guidance to establish an effective Management System.
One element that is key, no matter the Standard or subject area, is Leadership. Without this driving force, your Management System will not get the momentum it needs to truly benefit your way of working.
Today Ian Battersby will explain the integral role of leadership within the Implementation and maintenance of an ISO Management System, and how their active participation benefits the whole business.
You’ll learn
· What is Leadership?
· Where is Leadership referenced in ISO Standards?
· How do Leadership get involved with the Implementation and Management of ISO Standards?
· How does Leadership participation benefit the business?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian will be discussing the role of Leadership within ISO Management Systems and how their active participation can benefit the business as a whole.
[02:30] What is Leadership? – Leadership is central to success in achieving any goal in business. It involves motivating a group of people toward a common pursuit, and it certainly isn’t straightforward without leadership believing in what it’s doing.
Without showing that belief, why would the workforce sit up and take note: ‘If it’s not important to you, why should it be to me?’
[03:30] Why should Leadership get involved? – The need for leadership has been recognised by Standards bodies, hence why it’s been made central to all Management System Standards.
For many years, Management Systems were separate from the day-to-day activities of running a business, often boiled down to just a person in a room with manuals, getting through certifications and earning a nice shiny badge.But this had little to no impact on the bottom line (be honest)!
But, a well-run Management System can have huge impacts and benefits on all types of organisation, and updated ISO standards aim to deliver that impact more readily, so leadership gets its own clause (Clause 5 – Leadership)
[05:25] Clause 5.1 Top management shall demonstrate leadership & commitment – This boils down to taking accountability for effectiveness of the system, but how do you do this?
Firstly, the system can only be effective if it is designed correctly, so leadership must ensure it fits with its context of the organisation, which is required in Clause 4.
There are ways of doing this, but we favour a SWOT and PESTLE. This is simply to ensure that those establishing context don’t do it in a vacuum, opening up the floor to get input from everyone effected by the Management System.
This is key because Senior Managers need active involvement to understand how the system works, its resource needs and its performance.
[07:25] Ensuring quality policy and objectives are established and compatible with context and strategic direction – The quality objectives must contribute to the business, so there's a role for senior managers to ensure that they are aligned and have a measurable contribution to the business.
What measures are included in your objectives which can demonstrably show that they affect the business in some way in a good way?
That's what senior management have to do to link quality objectives with strategic organisational business objectives.
[08:20] Ensuring integration into the organisation’s business processes – The quality objectives must contribute to the business, so there's a role for senior managers to ensure that they are aligned and have a measurable contribution to the business.
They must ensure integration into the organisations’ business processes, which in turn must be aligned with the context. They must also be relevant to the way the organisation runs and senior management needs to oversee a system which allows processes to do that.
[05:20] Promoting use of the process approach and risk-based thinking – This requires senior management to actually do some promotion – which is stipulated as ‘Shall Promote’. For those that don’t know, whenever the word ‘Shall’ is used in an ISO Standard, that essentially means you MUST do it.
In this instance, that means actually contributing the communications and raising of Management System Awareness.
Senior Management have to be involved in the process of describing to people what's important, why the standards are important and that risk and process are central to the organisations operations.
[09:35] Providing resources for the system – There’s a number of resources that Senior Management need to consider, including:
· People - Need to be enlisted to run a system and to operate the system throughout the organisation.
· Competence – You may need to invest in training if required.
· Expertise in the standard – Do you have expertise in-house on the Standard you’re certifying to? If not, you will have to invest in training or additional help from a third-party.
· Systems / Access and Documented Information – Do you have a place for hosting of documentation, workflows, forms? Further considerations are needed for required authorization and controlled access.
· Time – Implementing and maintaining a Management System is a big task, whether done by an individual or a team, they will need time to complete necessary Management System activities.
[10:30] Communicating the importance of an effective system and conforming to its requirements – Everyone looks up to Senior Management in regard to what their priorities are. It’s up to them to effectively communicate the importance of the Management System, it’s processes, their role in relation to the Management System and how to confirm with it’s requirements.
Key points to get across:
· How this system makes your workplace a better place.
· How it contributes to success of the organisation – I.e. happier customers, safer working conditions, ect
· How it can make their daily routine more fulfilling – i.e. having a complete picture of their place in the business, how they contribute to its success.
· What could nonconformity bring if people choose to step outside a management system? – I.e. With ISO 45001, nonconformance could risk someone getting injured.
[13:50] Engaging/directing/supporting persons to contribute to effectiveness of the system – Team managers should be harnessing the people at all levels to be able to fulfil the requirements of the Management System.
They should do that by providing clear expectations, which can be done via so communications and objective setting.
[14:30] Promoting improvement – Continual Improvement is absolutely key to every management system.
When something does go wrong, senior management must provide the resources for actively asking why things may have underperformed, so you can get to the cause of why it’s underperforming and put it right.
It’s also an opportunity to highlight when things have improved and celebrate those that contributed to that success.
[15:30] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[17:40] Supporting other management to demonstrate leadership in their areas – Leadership drives top to bottom. Everybody can have a role in leadership.
Roles and responsibilities are assigned by senior management, and this offers the opportunity for individuals to provide their own leadership in their specific areas.
[18:15] 5.2 Policy – The definition of Policy in ISO Standards is:
The overall intentions and direction of the organisation, expressed by senior management. A policy exists to govern the behaviour of an organisation and its employees in order to provide the best outcomes. It also provides the basis for the establishment of objectives. It does not explain how the policy is to be delivered through individual tasks. This may not be a detail for top management.
What’s the requirement?:
Top management must ensure its appropriate to the purpose and context of the organization and supports its strategic direction
It’s not simply just a piece of paper to sign once a year.
[19:25] 5.3 Organizational roles, responsibilities and authorities – What does the Standard say:
‘Top management shall ensure that responsibilities and authorities for relevant roles are assigned, communicated and understood within the organization’
What does this actually mean?:
· Ensuring the Management system conforms to your ISO Standard(s)
· Ensuring processes deliver desired results
· Performance reporting including opportunities for improvement
· Promotion of customer focus
· Ensuring integrity of the management system through change and continual improvement
[21:30] Leadership in practice – Ian recounts an experience where senior management did regular safety checks in an organisation he worked with previously.
Senior Management took an hour out each month to do a floor walk and actually talk to those on the ground floor to ask them about risk, equipment and just generally get a feel for how everything really worked.
In turn, they were challenged by their staff on safe working systems and this proper conversation led to better understanding on both parts. The staff got to see their Senior Management genuinely care about their work and well-being, and Senior Management got much needed insight into the actual day-to-day activities and see first hand where improvements could be made.
Those familiar with ISO 45001 will know that worker participation is a requirement of the Standard, but there’s no reason why you can’t apply this to other Standards.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
There is a growing pressure on businesses to address their environmental impact, both from the Government as well as a more sustainably minded consumer base.
As a result, the need to carry out Greenhouse Gas (GHG) emissions reporting is being introduced as a mandatory requirement for tenders, and Government led initiatives such as Streamlined Energy and Carbon Reporting (SECR).
Today Mel Blackmore will discuss Greenhouse Gas (GHG) emissions reporting, and how verifying GHG Statements in alignment with ISO 14064-1 can benefit your business.
You’ll learn
· Why is there a growing need to report on GHG emissions?
· What is the difference between certification and verification?
· What is ISO 14064-1?
· What are the benefits of ISO 14064-1?
Resources
· Carbonologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Mel will be discussing GHG emissions reporting, and why verifying your businesses GHG Statements in alignment with ISO 14064-1 is a smart move.
[02:30] What’s the difference between Certification and Verification? – We covered this in detail on a previous episode, go back and listen to episode 162
[02:40] Why is there a growing need to address GHG emissions? – Climate change is a top concern for many. Consumers, investors and governments across the globe are all demanding greater transparency and accountability from businesses regarding their environmental impact. In particular, the carbon footprint a business claims to have.
[03:25] What is ISO 14064-1? – ISO 14064-1 is in internationally recognised Standard for quantification of Greenhouse Gas (GHG) emissions and removals at the organisational level.
In simple terms, this is the go-to Standard for businesses looking to calculate, verify and publish its carbon emissions.
[03:40] Benefit #1: Making compliance and reporting easier – Now, it’s important to note that the first time you go through this process will be like pulling teeth. You will need to do a fair bit of work initially, but once that’s set-up, it will make the necessary annual reporting a much easier process.
ISO 14064-1 verification ensures you are complying with applicable regulations such as SECR and the Governments requirement for a PPN 06/21 (within the UK).
If you are based in the UK, there is now Public Sector tendering requirement to identify what your carbon footprint is and make recommendations for reductions in the form of a Carbon Reduction Plan (CRP).
It can also help to streamline initiatives like the CDP (Carbon Disclosure Project) or EcoVardis.
[05:40] Benefit #2: Taking a deeper look at your emissions footprint – Verification is not simply just ticking a box, it’s about providing a clear picture of your organisations’ total GHG emissions.
Not just your CO2 emissions, ISO 14064-1 ensure you account for different types of emissions sources. This granular understanding will be crucial in identifying areas for improvement and developing an effective reduction strategy.
[06:25] Benefit #3: Providing Trust and Transparency – Having your report verified by am independent third-party adds a layer of credibility to your GHG reporting.
Anyone can just say their carbon emissions are X, but it’s another to have that backed up by a third-party. They can ensure your claims are true, correct and that there is a credible methodology behind it.
Stakeholders such as investors, consumers and regulators will then have the confidence that your emissions data is accurate and transparent.
Carbonology can assist you with the training resources needed to do this – so check out their website to learn more.
[07:30] Benefit #4: Pave a way for Carbon Reduction Strategies – We mentioned earlier about the requirement for a PPN 06/21, this requires a Carbon Reduction Plan (CRP).
Whether you create one based on a mandatory requirement or not, having a CRP is a no brainer for any business.
It helps you to understand your emissions, which is the first step towards reducing them. ISO 14064-1 verification lays the ground work for developing and implementing an effective CRP.
This can translate into significant cost savings and a competitive edge in the long run.
[08:30] Benefit #5: Embrace Mitigation – The verification goes beyond just cutting emissions. It supports mitigation actions like carbon removal projects, allowing you to demonstrate a holistic approach to tackling climate change year on year.
[08:50] Benefit #6: It’s a global Standard – ISO 14064-1 was created by over 140 representatives from over 50 countries globally to define exactly what greenhouse gas emission verification should look like.
While there are lots of other ways to achieve Net Zero, it makes more sense to choose an established route that will be recognised as best practice globally.
[10:25] Benefit #7: Tracking your progress – Verifying your GHG statements allows you to track progress over time.
This data is invaluable for communicating your achievements both internally and externally to key stakeholders about your drive towards net zero goals. It also helps to showcase your commitment to sustainability.
[11:00] Benefit #8: Participation in sustainability initiatives – Verification opens doors to participating in voluntary GHG registries and sustainability reporting initiatives.
This in turn will help to broaden your visibility as an organisation, amongst the environmentally conscious stakeholders that will be looking for credible sustainable businesses to work with or buy from.
[11:45] ISO 14064 is a no-brainer – It offers a significant strategic advantage and can help to demonstrate transparency with GHG reporting – something very sought after in the midst of a lot of green washing claims.
If you’d like assistance with ISO 14064-1, visit Carbonology’s website and get in contact, they’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO Standards provide a framework to help businesses manage various aspects of their activities. Whether that’s quality, risk, environmental or Information Security management, they provide invaluable guidance to establish an effective Management System.
However, for those who are new to ISO Standards, the Standards themselves can seem rather intimidating to interpret.
Back in 2015, the Annex SL format was introduced to provide a common high-level structure for Management Systems. With 10 clauses now common in most widely adopted ISO Standards, it can still be a bit difficult to understand exactly how these all work together.
Today Ian Battersby will explain how ISO Standard clauses work in tandem to create a cohesive cycle, from context of the organisation through to Improvement.
You’ll learn
· What is the high-level structure?
· What are ISO Standards structured this way?
· How do ISO Standard clauses interconnect?
· How does this apply to Quality Management?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Ian will be discussing the interconnectedness of clauses, which basically just means explaining the key links between the clauses and how that applies to your management system.
[02:40] High level structure – 10 years ago, Annex SL was introduced to create a common framework for ISO Standards. Today, Ian will focus on ISO 9001 as that really is the grandfather of all Management System Standards. ISO 9001 includes elements which are applied to most commonly adopted ISO Standards, and sets the scene in terms of how the clauses link together.
[03:20] Why are ISO Standards structured this way? – On their surface, ISO Standards can seem very repetitive in the way that they’re written, but there is a good reason for that.
There are all based around the Plan-Do-Check-Act cycle.
[04:10] What is the Plan Do Check Act cycle? – This is a simple process that all Management System Standards adhere to.
So you start with a ‘Plan’ to establish objectives, the resources which you need to deliver results, you identify risks and opportunities. From that point you fulfil the ‘Do’ part through Implementation and using the Management System.
From there you ‘Check’ so you monitor against the policies, objectives and any other requirements. Basically monitor against what you said you'd do and then you ‘Act’ if you find anything that needs to change, you make that change and you improve as an organisation and you improve that management system.
[05:00] A logical path – Management System Standards are designed in such a way that they flow from one clause to the other. One cannot exist without the other.
[05:20] How does Clause 4 Context of the Organisation link with Clause 6 Planning? – As clause 4 Context of the Organisation states:
‘external and internal issues relevant to your purpose and strategic direction…
…and that affect your ability to achieve intended results’
The scope of your management system depends entirely on this.
The world in which you operate - what you buy, the people you employ, what you make, who you sell to, the laws you follow…
Clause 4 also requires us to identify all interested parties (which we’ll address later!).
With careful planning, you can align documentation you develop for one clause with other clauses.
Clause 4 doesn’t tell us how we should work out our context, but it provides some very good clues
· NOTE 1 Issues can include positive and negative factors
· NOTE 2 Understand the external context by considering issues arising from legal, technological, competitive, market, cultural, social and economic environments
So they’re not saying how to do it, but they’ve said what you can consider
This sounds a lot like a traditional SWOT/PESTLE analysis…
If we skip to Clause 6, Planning, the first thing we must do when we plan is to identify actions to address risks and opps
A SWOT will mean you’ve covered these elements, consider the following =
· Weakness = Risk
· Threat = Risk
· Opportunity = Opportunity
We can similarly view the PESTLE in the same light.
So you can see that with careful planning, as mentioned you can align documentation for one clause with other clauses.
[10:00] How does Clause 6 link with Clause 7 & 8? – Skipping from Clause 6.1
If you’ve identified what might go wrong (aka - risk), you need to plan to ensure it doesn’t happen again. That may involve a single improvement action, which is linked to clause 10 (funnily enough, Improvement)
It may be that you need something bigger, involving many steps, over a period of time, say an objective (clause 6.2)?
So, the planning of objectives links directly to the context of the organisation, the world in which you operate. It may be that you need an operational control to mitigate risk, a process or procedure that helps to manage the situation as a business as usual situation (clause 7 documented info and clause 8, operation)
So the planning of processes and procedures links directly to the context of the organisation, the world in which you operate. In all these circumstances, it’s the same for opportunities, except you’re putting in place measures to take advantage of the opportunities.
[13:05] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[15:10] Clause 7 Support and related links – Moving through the standard, clause 7.4 relates to Communications.
You need to determine internal and external communications relevant to the QMS (for 9001). In clause 4, you would have looked at interested parties (i.e. stakeholders). You need to determine who affects the way in which you operate and what they need/expect from you. Parties to consider include:
· Customers
· Employees
· Shareholders
· Suppliers
· Regulators
· Neighbours
· Media
So, by Clause 7 you will have already identified who’s interested and what interests them, so it’s only a small step to add to this the communications plan. ISO 9001 doesn’t ask for one specifically, but it’s a good way to fulfil the requirements of clause 7.3.
Clause 7 also mentions Monitoring and measuring resources (7.1.5). This is a very brief clause, but central to establishing the means for demonstrating performance.
We need reliable results when monitoring or measuring is used to verify the conformity of products and services to requirements, i.e. do we do what we say we do?
Clause 7.5 requires us to document how we do things. Again it’s very brief in its requirements (leaves it up to you to decide), but clause 8 is all about operation – which is the way you do things.
It’s much more specific about understanding what the customer wants, designing it correctly, controlling changes, making it, delivery and addressing issues.
This is what you measure: 7.1.5 requires you to ensure you can measure, 7.5 requires you to document how you do things, 8 requires you to do things according to the way you’ve said you will.
[20:10] Clause 9 Performance Evaluation and related links – Moving onto Clause 9, Performance Evaluation, again risk appears. We’ve already assessed risk right at the start, now we evaluate whether we’ve successfully controlled risk.
We decide what to audit based on the level of risk attached to certain controls (policies, procedures, processes…). We’ve set objectives based on risks and opportunities and now we must measure performance.
We’ve put in place operational controls to mitigate risk (clause 8) and now we measure whether those controls work.
[21:30] Clause 10 Improvement and related links – This one is fairly self-evident. If something goes wrong, find out why and put it right and make sure it doesn’t happen again. Look at your system and continually improve based on your evaluations in Clause 9.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
After 5 years of hosting the ISO Show, Mel Blackmore will be taking a step back as she focuses on her sustainability related endeavors.
She’s passing the baton onto our new host – Ian Battersby. Ian is a Senior isologist at Blackmores, and while relatively new to the team, he has a wealth of Standard and ISO related knowledge to share with you all.
Today we Introduce Ian Battersby as the new host for the ISO Show and learn about his background in Standards and ISO.
You’ll learn
· Taking a step back
· Introduction to Steph Churchman
· Introduction to Ian Battersby
· What Standards has Ian worked with?
· What Sectors has Ian worked in?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: After 5 years of the ISO Show, Mel Blackmore is handing the hosting baton over to Ian Battersby
[02:25] Interim host – Ian will be the main host going forward, but there will be additions from Blackmores’ Communication Manager – Steph Churchman.
You may recognise her from recent episode such as:
· Top 10 Reasons to use ISO 42001 AI Management
· Top ISO Standard Trends in the Data Centre Industry
Steph will be sharing findings from our own research, standards updates and conducting interviews with our isologists.
[03:35] An Introduction to Ian Battersby – Ian has been working for Blackmores since August 2023. Although he is meant to be part-time, he’s had a very busy first few months here!
Ian began working in British Aerospace, specifically manufacturing, in 1984. He later decided to return to university to study electrical and electronic engineering, which was promptly dropped.
His return to BAE lasted a few years before he moved onto the civil service for the Department of Health, working with them to conduct safety investigations and helped to create a broader risk profile.
When he moved to work with the NHS, firstly, with the litigation authority setting up governance and risk standards and then as a risk manager.
Surprisingly, after moving up a few levels, he decided to move onto run a restaurant! A Curry House to be specific, but after a year of rather stressful work that ended up costing a lot more than expected, he returned to work within the construction industry which is where he became more involved with ISO Standards.
From there he went onto work in manufacturing of high pressure pumps for a while before moving onto an organisation who rant he estate for the Department of Work and Pensions.
In the end, Ian left them due to being unable to live the life he wanted to live.
[05:15] What Standards has Ian worked with? – He started with ISO 9001, ISO 14001 and OHSAS 18001 (now ISO 45001).
[06:00] Digital Nomad – Ian currently splits his time between Leeds in the UK and Malaga in Spain.
Having a lot of experience working remotely in previous industries, this leap didn’t impede on his work in any way.
[07:15] What other Standards has Ian worked with? – He has assisted with ISO 44001 (Collaborative Business Management), but admittedly it was not his favorite ISO Standard to work with. It’s one of the rare instances in ISO where the Standard doesn’t quite align with others.
[08:00] What Sectors has Ian worked in – Ian’s extensive work history has afforded him the opportunity to work in a number of sectors, including:
· Construction and Fit out
· Manufacturing
· Estate Management
· Private enterprise
· Healthcare / NHS
· Facilities
With this list growing at a rapid pace since his introduction at Blackmores!
[09:45] What’s a big challenge that Ian’s had to overcome in the past? – In terms of ISO, it has to be Leadership. Ian’s found that to always be an issue within businesses attempting to implement ISO Standards.
A good looking Management System will only go so far without leadership commitment.
While working in facilitating Standards for an organisation, you won’t be implementing the whole system yourself. It’s more a case of delivering through others, the organisation controls and delivers their own processes and improvements, and so it’s imperative that Leadership are also embedding and encouraging these actions.
Ian will be going more in-depth on this topic in a future episode.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Can you believe we’ve been publishing the ISO Show for 5 years now! We certainly can’t!
The ISO Show began back in 2019, following a trip to Cumbria by the host Mel Backmore. She was, and still is, an avid fan of podcasts and while listening to a few of her favourites on the 4 hour trip, she got to wondering if there were any podcasts about ISO Standards.
As it happened, there wasn’t at the time, and so the idea for the ISO Show was born. Not more than a few months later the first episode went live, and the rest is history.
For the past 5 years, we’ve had the honour of sharing our team’s combined 18 years of knowledge, including amazing insights from our clients and industry experts along the way.
Today Mel Blackmore will reflect on the ISO Show so far and share it’s next evolution as we introduce a new host.
You’ll learn
· Why was the ISO Show created?
· Why is Mel taking a step back?
· What will be the focus for the future?
· An introduction to the new host(s)
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: After 5 years of the ISO Show, it’s hitting a turning point as we introduce a new host.
[02:25] An amazing journey – It’s been an amazing 5 years of digging deep into some of the most pressing issues we’ve faced, sharing tips and dispelling myths about ISO Standards.
We’ve explored a lot of topics over the years, including:
· Sharing our ISO 22301 (Business Continuity) knowledge when COVID hit, to help people with future and current response plans.
· Transitioning to new versions of Standards, such as ISO 27001:2022
· Interviewing leaders within the ISO space, such as Kit Oung, who helped to develop the UK’s current energy and climate change regulations.
[04:05] Mel’s sustainability journey – why she’s taking a step back as host – Mel’s made it no secret that her passion lies with Sustainability Standards. This podcast has helped to amplify their importance within our space, but she wants to take this a step further.
Going forward, Mel will be dedicating herself full-time to researching the crucial role of carbon standards in achieving Net Zero emissions by 2050.
[05:00] An evolution for the ISO Show – All this to say, the ISO Show isn’t going anywhere, rather we are introducing a new main host – Ian Battersby!
[05:05] Who is Ian Battersby? – Ian is a senior Isologist here at Blackmores. Ian brings a wealth of knowledge, expertise and a passion for helping businesses raise their game with ISO standards.
He’s a bit of a digital nomad, splitting his time between working from Span and England, he works part-time at Blackmores.
So he is very much involved in the day-to-day understanding of challenges of ISO Management, This includes the frustrations that businesses face and also how ISO standards support the achievement of greater productivity and profitability.
Ian will be introducing himself fully on the next episode 😊
[06:25] Thank you for making the ISO Show such a success! – We’ve now got a few thousand subscribers, with a global reach, we honestly never expected to have so many listeners when we started.
So whether you’re a regular or occasional listener, thank you for being here with us, we truly hope that our knowledge has helped you on your own journey to continual improvement within your own organisation.
[07:25] A long journey – A lot has happened over the past 5 years. In addition to being the CEO of Blackmores, Mel has also developed the isologyhub – an on-line learning platform which helps to raise awareness and understanding of ISO Standards.
She has also founded Carbonology – a sister company that specialises in carbon related Standards, which will be where focuses her main efforts over the next few years.
[07:44] Stepping back – but not gone – While you will be hearing less from Mel, she won’t be completely absent. She will be joining us at least once a month to explore how ISO Standards are shaping the landscape of Net Zero.
She will be sharing her journey to achieve net zero based on academic research, including primary and secondary research on how the various carbon related standards support the Sustainable Development goals and achieving net zero.
This will primarily be diving into Standards such as ISO 14064 (Carbon Verification) and ISO 14068 (Net Zero), in relation to how they support the Sustainable Development Goals, help to create a level playing field, providing transparency, reliability, accountability and without a doubt, credibility.
[09:20] Why the focus on sustainability? – Mel will be studying a masters by researching the role of Carbon Standards Verification in contributing to achieving Net Zero.
This focus hasn’t appeared out of the blue. Mel founded Carbonology with the goal of tacking Net Zero, one business at a time. They’ve already had great success over the past few years’ but there’s still so much more to do when it comes to understanding Greenhouse Gas emission verification, carbon removals, reductions and offsetting.
[10:10] Another big thank you – The ISO Show has been running for the past years with the assistance of Blackmores Communication Manager – Steph Churchman.
Starting from humble beginnings of recording using a mic housed in a shoebox, to being stuffed in a cupboard to combat our offices’ terrible acoustics. We’ve thankfully since upgraded our set-up to something much more comfortable.
Along the way we’ve experienced our fair share of technical issues, as you can’t really go 5 years of recording without something going wrong. However, there wasn’t much we couldn’t work around in some way or another.
As Steph has helped in researching topics we’ve discussed over the years, she will also be joining Ian on hosting the ISO Show in future episodes.
[12:45] On to the next chapter – It’s not goodbye from Mel, but rather see you later. We’ll be bringing you all along on this next chapter of the ISO Show, so make sure you subscribe to stay up-to-date with our latest episodes.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Data Centres could be considered the powerhouse of thousands of businesses globally.
Long gone are the days of small physical servers being housed on-site, instead we rely on data centres to keep all our critical data safe and secure. But how do we know they are doing just that?
Many hold certifications to security-based Standards such as SOC 2 or NIST to display their commitment to data security. However, many also hold various ISO certifications that cover other aspects of the business outside of information security.
Today Steph Churchman, Communications Manager at Blackmores, will be sharing the top ISO Standard trends within the UK Data Centre industry.
You’ll learn
· Why did we look into the Data Centre industry specifically?
· What are the top 5 ISO Standard Trends in Data Centres?
· Why are these ISO Standards essential for Data Centres?
· Other commonly adopted ISO Standards within the data centre space
Resources
· Isologyhub
· ISO 27001:2022 Transition Gameplan
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:25] Episode summary: We’ll be taking a look at the top ISO Standard Trends within the UK Data Centre Industry
[02:30] Why did we look into the Data Centre industry specifically? – In the mid 2010’s, we noticed an influx in enquiries from Data Centres in regard to Implementation of ISO Standards. That prompted a research project that led to Blackmores working with some of the top UK Data Centres.
Now in 2023 and 2024 we’re starting to see a similar push for ISO Standards within the same industry. So, we revived the project to get a grasp on the modern ISO landscape, and took a look at the top 100 Data Centres within the UK.
[03:34] #1: ISO 27001 Information Security – Out of the 100 data centres sampled 72% of them were certified to ISO 27001.
Security is of upmost importance to data centres, and the great thing about ISO 27001 is that it considers security for not only the digital environment, but also for people and physical security.
This Standard is also, in most cases, a stakeholder requirement. Certification to ISO 27001 indicates that you’re adhering to best practice in information security, and through the creation of an ISO 27001 compliant Management system, you will have documentation in place such as an information security policy and data retention policy, that often get requested by potential clients.
If you’d like to learn more about the Implementation process for ISO 27001, we’ve got a helpful 3-part podcast series that summarises the entire process from Gap Analysis to Assessment preparation.
anyone currently certified to ISO 27001:2013 that you have just over 1 more year to complete your transition to ISO 27001:2022. If you don’t do so by October 31st 2025, you’ll risk losing your ISO 27001 certification.
That’s not the only reason you should be transitioning though. The new version of the Standard includes 11 new controls, which cover some newer technologies which really weren’t around when the 2013 version was published. So regardless of the risk of losing your certification, it’s in your best interest to ensure that you’re adhering to the latest version.
If this is all news to you, then you can also go back and check out episodes 128 through to 133. This was a little mini-series we did to summarise the key changes to ISO 27001 and what actions you need to take to transition. We also have a Transition Gameplan available on the isologyhub if you’d like a more guided approach, including document templates and training videos covering those new controls.
[06:25] #2: ISO 9001 Quality Management – The Quality Management Standard is as popular as ever, even within the data centre space, with 51% of the 100 sampled data centres being certified.
ISO 9001 is considered the leading ‘Quality mark’ for businesses and is often the starting point for many diving into the world of ISO implementation. ISO 9001 creates a well-rounded base Management system to help you manage your risks and opportunities, as well as ensuring you drive a culture of continual Improvement. Its guidance can help you establish your core policies, processes and procedures to ensure everyone is singing from the same song sheet.
The fact that this one is popular among data centres isn’t too much of a surprise, it’s a universally adopted Standard that isn’t limited by industry or organisational size. Currently, there are over 1 million ISO 9001 certificates issued worldwide, and that trend shows no signs of slowing down.
[08:25] #3 ISO 14001 Environmental Management – A surprising 25% of the sampled data centres were certified to ISO 14001.
From an objective point of view, it makes sense for data centres to consider their environmental footprint. But a lot of that would fall under energy usage rather than just general environmental management, so this likely means it’s mainly driven by stakeholder requirements.
ISO 14001 is being requested more and more for the likes of large Government contracts, so If you want a chance at bidding for these, ISO 14001 is a must.
Now don’t get me wrong, I’m sure a lot of data centres have implemented this Standard in an earnest effort to monitor and measure their impact holistically. After all ISO 14001 asks businesses to consider how they can prevent environmental impacts such as pollution and degradation of nature. And the additional guidance provides some helpful starting points for those that may not be sure where to start, for example making commitments to recycling, protection of biodiversity and climate change mitigation.
For data centres specifically, this may come into effect when we think of the amount of electronic waste that they could potentially produce. Obviously, this can’t just be thrown out in a standard green lidded bin, it’ll need to be taken to a dedicated electronic waste facility for processing, disposal and recycling. Racking, shelving and cables will all also need to be replaced at some point, and it’s up to each data centre to ensure they have the appropriate processes and policies to ensure this is done correctly and more importantly legally, which again, is where ISO 14001 can help put those frameworks in place.
[10:30] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[12:45] #4: ISO 50001 Energy Management – With just 13% of the 100 sampled data centres certified! This one is a shocker because, typically, data centres highest cost is in relation to their energy usage. They require enormous amounts of energy to keep their facilities running and to cool down their equipment 24/7. Which I imagine they’d be quite keen to reduce if only to save on running costs.
This is where ISO 50001 can come in, to help create a structured approach to effectively monitor that energy usage, so you can identify key trends and opportunities to reduce overall energy consumption, which in turn will save a lot of money.
With a healthier proportion being certified to ISO 14001, it seems a shame that so many are missing out on the additional benefits that ISO 50001 can bring, especially when it can very easily be integrated with ISO 14001. In fact, if you’re already certified to ISO 14001, then you’ve already done half the work to implement ISO 50001. Both frameworks are based on that Annex SL format, and both have a lot in common in terms of what documentation is required.
It can also help with compliance with some UK and EU based energy initiatives. For example, here in the UK we have ESOS (The Energy Savings Opportunities Scheme) which applies to large organisations that fit within its criteria. They’re usually required to provide a report once every 4 years, however as of 2023, Phase 3 now requires organisations to provide an Energy Action Plan which details what actions they plan to take to reduce their energy consumption.
There are likely a few data centres that would fall into ESOS’s criteria, and if you’re sick of going through the ESOS song and dance every few years, then ISO 50001 may be the answer for you, as being certified means that you’re going above and beyond ESOS’s requirements and will be considered compliant. Meaning no more pesky reporting, or having to locate an ESOS assessor to sign off on those reports.
[15:10] #5 ISO 22301 Business Continuity Management – With 12% of the 100 sampled data centres being certified.
ISO 22301 is the Standard for Business Continuity, and provides a basis for planning to ensure your long-term survivability following a disruptive event.
That 12% may not be truly reflective of all the data centres that have business continuity plans in place however, as according to a recent Business Continuity institute survey, 56% of surveyed businesses use ISO 22301 as a framework but aren’t certified to it.
There will be a fair few data centres in our sample list that fall under that category.
Why should this Standard be a priority for Data Centres? Well, the answer should be simple, if a disaster were to knock out a data centre, that has a massive knock-on effect. Many house servers used by hundreds if not thousands of businesses and users. If they’re unable to provide services, that will in-turn cause multiple other businesses to grind to a halt.
The true cause of failures at data centres can be many things such as hardware failure, human error or a disaster such as flooding or fires. However, the advantage of utilising ISO 22301 is the ability to be able to effectively deal with these incidents and restore services, which is essential for an industry which is quite literally the powerhouse for millions of other business and people.
If you fail to plan, you plan to fail
Having a robust business continuity plan should be a top priority for any business, especially data centres, seeing as so many rely on them to keep their own services running. Even if you don’t want to go through the full certification process, it’s worth grabbing a copy of the Standard, as it provides a lot of helpful guidance.
If you’d like to learn more about ISO 22301 in general, go back and check out episode 42 where we go over the Standard in more detail and it’s many benefits.
[17:45] Runner up: ISO 20000 Service Management – Saw 11% of our sample data centres certified to this Standard.
This actually used to be known specifically as the IT Service Management Standard, so that probably clues you into why this would be adopted by many with in tech spaces. However, it truly is applicable to any business offering services.
The aim of ISO 20000 is to provide a framework for an effective end-to-end service management system which encompasses the entire lifecycle of a service from concept and design, through to service removal and end-of-life.
[18:55] Runner up: ISO 27017 information security controls for cloud services – With just 5% of our sampled Data Centres certified.
This one is fairly self explanatory in it’s relation to data centres, which operate solely on cloud based services.
This Standard was introduced after the 2013 version of ISO 27001 was published, as the main standard didn’t really address cloud security controls specifically. Mostly because cloud computing and its related security weren’t as widely adopted as they are now. So ISO 27017 was created to try and bridge those gaps.
In the latest 2022 version of ISO 27001, there’s now a new control for cloud security. So, we may see less interest in ISO 27017 certification going forward.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Working towards a sustainable future is going to require a joint effort from everyone if we’re to reach our 2030 and 2050 targets.
Several initiatives have come out in recent years to try and address one of our biggest challenges, energy consumption. Many of us in the UK will be familiar with ESOS (The Energy Savings Opportunities Scheme), which involves regular reporting from those that fit its criteria. It’s also recently updated to include a stipulation to include an ESOS Energy Plan, which requires you to detail a route to reduce your energy consumption.
However, many businesses would prefer a more consistent approach to energy management, such as today’s guest – Daisy Corporate Services.
Today Mel is joined by Damian Edwards, ISO Standards Manager at Daisy Corporate Services, to discuss why they Implemented ISO 50001, what they’ve learned from the experience and the benefits gained from implementing an Energy Management System
You’ll learn
· Who is Damian and who are Daisy Corporate Services?
· Why did they decide to Implement ISO 50001?
· What was the biggest gap identified during their Gap Analysis?
· What lessons did they learn from Implementing ISO 50001?
· What benefits did they gain from ISO 50001 certification?
Resources
· Isologyhub
· Daisy Corporate Services
· Daisy Corporate Services ESG
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:30] Episode summary: Mel is joined by guest Damian Edwards, ISO Standards Manager at Daisy Corporate Services, to discuss their journey towards ISO 50001 certification.
Daisy are not strangers to ISO Standards, already having achieved: ISO 9001, ISO 14001, ISO 27001, ISO 45001, ISO 20000 and ISO 22301!
They have also recently won the Sustainability and Tech Awards 2024 and the Green Shoots Awards too.
[04:15] Who is Damian Edwards? – Damian has worked at Daisy as their ISO Standards Manager for the past year. A little known fact about Damian: He listens to classical music as a way to focus.
[05:25] Who are Daisy Corporate Services? – The are primarily a provider of IT and Communications. They currently supply a range of services including:
· Unified Communications
· Connectivity
· Modern Workplace
· Cyber Security
· Cloud services
· Managed Services
· Operational Resilience
[06:25] What were the main drivers behind obtaining ISO 50001 Certification? – In addition to the office spaces Daisy controls, they also have a number of data centres, which use massive amounts of energy. Finding ways to monitor, measure and potentially reduce that energy use, and subsequently cost, was essential.
The second main driver is mainly for commercial reasons. Without Standards like ISO 50001, you can’t bid for larger contracts or Government frameworks.
[08:30] Daisy’s commitment to ESG – Daisy have a made a solid commitment to ESG, explained further on their website as they break it down into 10 key focus areas. Energy Management is one of the logical steps to tackle reducing carbon emissions.
Data centres can be very inefficient, so being able to consistently monitor, measure and improve their energy consumption is a key part of tackling some of their ESG related goals.
Also being certified means you have the certificate to back up your claims. It’s not you just making a statement, it has to be verified by a third-party.
[10:30] How long did it take to Implement ISO 50001? – It took between 8 – 11 months. For a Standard like ISO 50001, it’s important to do it properly. Some organisations may request it in 6 months, but for larger organisations, that would be a tough ask, and you run the risk of rushing into certification without having those processes embedded in.
[11:45] Did having existing ISO Standards make the process smoother? – Yes, as it was a case of integrating ISO 50001 with our existing systems rather than starting from scratch. Though, having so many ISO’s can water the message down a bit, to combat that we’ve got a single statement that gets across everything you need to know about Daisy.
[12:55] What was the biggest gap identified during the Gap Analysis? – Because we already have so many ISO’s, we can be a bit big headed and say there weren’t many gaps at all, however, there were still some things we could do. One of the biggest areas for improvement was Clause 7, Documentation, as all ISO Standards have their own required documentation.
Another was putting in place a plan for monitoring and measuring our energy usage. We have a Property Director who did do that, but he wasn’t really documenting it, so we’ve put in place some proper processes to help show that we’re actively monitoring it, looking at the trends and putting in actions to reduce and improve on that.
[14:55] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[17:10] Did closing those gaps make a big difference? – We did have a lot of help from Blackmores in order to address those gaps. Out consultant advised us to combine elements of out Management Review with out monthly Team Meetings, as our Director is involved with those, and we avoid another meeting for meeting’s sake.
We now also produce a pack of all the monitoring and measuring that’s done throughout the month, which makes it easy for us to analyse and identify trends in energy use. Any actions from reviewing this are then recorded and followed up on. So, in essence it’s just made everything a lot smoother.
[19:55] What did Daisy learn from Implementing ISO 50001? – It takes a team to achieve this – you can’t do it on your own. You also can’t rush it!
Another key take away is that the whole project needs to be driven by top management, without all of those elements combined, it’s probably not going to work (or be a lot slower and more painful!)
It’s also really helped with our commitment and messaging around ESG too. So within those monthly Management Review meetings we have a representative from the energy efficiency team, the ESG team and our bids team. They’re then all communicating what the customer message is, that they expect of us, in turn they’re kept in the loop about our energy usage and related actions and can communicate that outwards.
[21:15] What other benefits are there from achieving ISO 50001? – Having our management system verified by a third-party means that we can confidently say we’re adhering to best practice. It also just validates that we are doing things correctly!
It also means that we can monitor opportunities for improvement. If we identify more gaps in future, we have the processes in place to address them.
ISO 50001 has also helped to put some context behind the energy data we’re collecting. Thanks to the new processes we can accurately identify key trends and explain why energy usage may be going up and down.
[23:25] Damian’s top tip – Ensure that your project is driven by top management. They’re involvement means it’s a lot easier to communicate that message that you’re doing the right thing.
Also, ISO 50001 helps with your regulatory compliance too. If you’re a larger organisation, then you likely have to adhere to schemes like SECR or ESOS. If you’re certified to ISO 50001, then you’re already complying with both.
[24:35] Damian’s book recommendation – Beryl in search of Britain's greatest athlete.
[26:45] Damian’s favorite quotes – “Hard work beats talent when talent doesn't work hard” and “You miss 100% of the shots you don't take.”
If you’d like to learn more about Daisy Corporate Services, visit their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In February 2024, the ISO and IAF issued an unprecedented change to 31 commonly adopted ISO Standards, such as ISO 9001, ISO 14001 and ISO 27001.
This change saw the addition of a new ‘Climate Change Amendment’, which was applied in part due to the ISO’s resolution in support of the ISO London Declaration on Climate Change.
So what does this mean for ISO certified businesses?
Join Mel as she discusses what this new ISO Climate Change Amendment is, why it was introduced, what are the consequences if you don’t address it and the benefits of its introduction.
You’ll learn
· What is the ISO Climate Change Amendment?
· Why was it introduced?
· What are the consequences if you do not address the change?
· What are the benefits of the Climate Change Amendment?
Resources
· Isologyhub
· ISO Climate Change Amendment Workshop
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:30] Episode summary: We break down the new ISO Climate Change Amendment, including why it was introduced and why you should address it ahead of your next Certification Body visit.
[02:55] Join our Workshop– If you’re not sure where to start with addressing this amendment, join our interactive workshop taking place on the 20th May (14:00 – 16:00 GMT). There we will explain how you can integrate the new changes into your existing ISO Management System. Register your place here.
[04:30] What is the new ISO Climate Change Amendment? – A key clarification before we go into more detail, this is not a new version of a Standard i.e. ISO 27001:2022, where you must transition to a new version.
So, what is it? In February 2024, the International Organization for Standardization (ISO) introduced a groundbreaking amendment to integrate climate change considerations into various management system standards.
The amendment doesn't assign specific actions. Instead, it adds text to existing clauses in 31 standards (including ISO 9001, 14001, 27001) requiring organizations to consider:
· Relevance of climate change: Organizations must assess if climate change is a relevant issue for their operations and context (Clause 4.1).
· Stakeholder expectations: Note added: Relevant Interested Parties can have requirements related to climate change (Clause 4.2).
As we’ve learned from our sister company, Carbonology, it is often Stakeholders driving forward that need to verify a business’s carbon footprint and take steps towards Net Zero.
[09:30] Why was this change Introduced? – This change was in part due to ISO’s resolution in support of the ISO London Declaration on Climate Change. The aim is making climate change considerations an integral part of management systems, their guiding policies and practises – not simply as an afterthought.
As we all know, climate change will affect everyone, and should be a concern that every business fully considers to ensure they are resilient and adaptable enough to deal with climate related risks.
This amendment means businesss will need to address these risks where relevant, and integrate them into strategic objectives and look what can be done from a risk mitigation perspective.
The global business community will be one of the driving forces for paving a way to a more sustainable future – It all starts with changing the way we work, making the shift towards embedding environmental consciousness into the very heart of your business.
ISO Standards are widely adopted, and this change offers a catalyst for meaningful climate action on a global scale.
[11:00] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[13:20] What are the consequences for not addressing this change? - Certification bodies will be asking you about these amendments effective immediately. If you’ve not addressed them ahead of your next certification body visit, you could run the risk of getting a non-conformity. The amendment added to Clause 4.1 especially states ‘Must’ – so there’s no getting away with simply ignoring it.
[14:50] What are the benefits of this change? – Some of the benefits will likely already be felt by those with existing environmental standards such as ISO 14001 and ISO 50001 in place. So, let’s take a look at how you can benefit from addressing this amendment:
· Reduced Environmental Footprint: By integrating climate change considerations, businesses can identify and implement practices that lower their carbon emissions and resource consumption.
· Enhanced Sustainability: Addressing climate change demonstrates a commitment to sustainability, which is increasingly important for attracting environmentally conscious customers and investors.
· Cost Savings: Climate-conscious practices can lead to cost savings through improved resource efficiency, reduced waste, and potentially lower energy bills.
· Resilience and Risk Management: By considering climate-related risks (e.g., extreme weather events, resource scarcity), businesses can proactively develop strategies to mitigate these risks and ensure operational continuity.
· Innovation: Focusing on climate change can lead to innovation in areas like cleaner technologies or sustainable product development, giving businesses a competitive edge.
· Positive Brand Image: Demonstrating proactive action on climate change can enhance a company's brand image and reputation among environmentally conscious stakeholders. This is a particularly important issue to younger generations who are becoming the dominant buying power from a commercial perspective.
· Stronger Stakeholder Relationships: By considering stakeholder expectations around climate change, businesses can build stronger relationships with customers, investors, and regulators.
· Holistic Approach to sustainability: Integrating climate change considerations strengthens a businesses’ overall management system by fostering a more comprehensive and future-proof approach.
· Continual Improvement: The amendment emphasizes continual improvement, encouraging businesses to constantly seek ways to reduce their environmental impact, leading to long-term sustainability benefits.
If you’d like to learn about what actions you can take to integrate the ISO Climate Change Amendment into your ISO Management System, join our live event on the 20th May – register here.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 42001 was published in December of 2023, and is the first International Standard for Artificial Intelligence Management Systems.
It was introduced following growing calls for a common framework for organisations who develop or use AI, to help implement, maintain and improve AI management practices.
However, its benefits extends past simply establishing an effective AI Management System.
Join Steph Churchman, Communications Manager at Blackmores, on this episode as she discusses the top 10 reasons to adopt ISO 42001.
You’ll learn
· What is ISO 42001?
· What are the top 10 reasons to use ISO 42001?
· What risks can ISO 42001 help to mitigate?
· How can ISO 42001 benefit both users and developers of AI?
Resources
· Isologyhub
· ISO 42001 training waitlist
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:30] What is ISO 42001?: Go back and listen to episode 166, where we discuss what ISO 42001 is, why it was introduced and how it can help businesses mitigate AI risks.
[02:45] Episode summary: We take a look at the top 10 reasons why you should consider implementing ISO 42001.
[02:55] #1: ISO 42001 helps to demonstrate responsible use of AI. – , ISO 42001 helps ensure fairness, non-discrimination, and respect for human rights in AI development and use.
Remember, AI can still be bias based on the fact that AI models are typically trained on existing data, so any existing bias will carry over into those AI models – an example of this is the existing lack of representation for minority groups.
We also need to take care in the use of AI over people, as staff being replaced by AI is a very real concern and should not be treated lightly. We’ve already seen a few cases where this has happened, especially across the tech support field where some companies mistakenly think that a chatbot can replace all human staff.
We also need to consider the ethics of AI content. It’s predicted that 90% of online content will be AI generated by 2026!
A lot of this generated content includes things like images, which poses a real concern over the values we’re translating to people. The content we consume shapes the way we think and if all we have is artificial, then what message is that conveying?
An example of this is Dove’s recent advert, which showed an example of AI generating images of very unobtainable ideals of a beautiful face. Which were predictably absolutely flawless, almost inhuman and something that can only be achieved through photo editing. If the internet was flooded with this sort of imagery, then that starts to become the expectation to live up to, which can be tremendously damaging to people’s self-esteem. They then went on to show actual unedited people, in all their varied and wonderful glory and stated that they will never use AI imagery in any of their future marketing or promotional material.
Which sends a very strong message – AI definitely has its place, but we need to fully consider the implications and consequences of it’s use and possible oversaturation.
[05:20] #2: Traceability, transparency and reliability - Information sourced via AI is not always correct – It collates information published online, and as many of us are aware, not everything on the internet is correct or accurate.
Data sets carelessly scrapped from online sources may also contain sensitive or unsavoury content. We’ve had cases where people have managed to ‘break’ Chat GPT, causing it to spew out nonsense answers which also contained sensitive information such as health data and personal phone numbers. While not usually accessible when requested, it does not stop the risk of this data being dug up through exploits. AI is like any other technology, and is not infallible.
So, it’s up to developers to ensure that the data used to train models is safe and appropriate for use. It should be expected that data sets will be scrutinised from a legal standpoint – either as a result misuse of AI or a mandatory exercise as a part of future legislation.
There’s also research that suggests data sets can be potentially poisoned to produce inaccurate results – which is another consideration for developers using live data sets, who will need to stay on top of these risks to ensure the integrity of their tools.
ISO 42001 provides specific guidance that covers how developers can ensure transparency and explainability within sample training data.
[06:45] #3: It’s a framework for managing risks and opportunities – AI, like any other new technology, is going to create new risks and opportunities.
Risks include the likes of inaccurate data being used, existing bias in data training sets, plagiarism, information security risks and data poisoning.
If you’re simply using AI to gather information, it’s also a good exercise to ensure that the information is coming from a reputable source. One easy way to so this is to simply ask for the source to be cited when pluging in a prompt into tools like Chat GPT and Gemini. You can then verify how legitimate that source is.
For web developers and SEO specialists, Google has recently updated it’s algorithm to punish those with a lot of AI generated content on their websites. So those within the SEO space may see some interesting trends over the course of 2024.
Another unfortunate risk is that of more complex scams being implemented through the use of AI. An example of this involves those who may use an AI assistant in their systems, which can be affected by malicious emails that contain prompt injections which could be used to send data from a victims machine to outside sources.
This is only touching on a few risks, but as you can see, there’s a lot to consider and I’ve no doubt that more complex risks will make themselves known as the technology evolves.
However, there are a lot of opportunities to be found with AI use.
There’s a huge potential for AI to be utilised to tackle mundane and routine tasks which could be automated.
AI also has the capability to scan masses of data and provide suggestions based on it’s findings. Obviously, humans can’t possibly compete with the sheer volume of data that AI can process, and so we can utilise it to help us make better more informed decisions.
A lot of commonly used software has already integrated various AI tools which offer great quality of life updates and help make a lot of tasks quicker. Which in turn means our time is better spent elsewhere on tackling the more complex issues that require a more human touch.
ISO 42001 can help you balance out these risks and opportunities by helping you build a robust management system to manage and mitigate risks, and drive forward opportunities through continual improvement.
[10:35] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[12:50] #4: Demonstrate that introducing AI is a strategic decision with clear objectives - Businesses looking to integrate AI should not make this decision lightly.
I know it’s tempting to play with the newest toy, but we should take care to look at any possible risks, and that it aligns with both your company objectives and ethics before rushing to utilise something.
For example, allowing your staff to use ChatGPT for content creation. You need to consider a few things:
You need to make sure Staff aren’t putting in any confidential or sensitive information into publicly available AI tools.
Also, ensuring that Staff understand that content provided by the likes of ChatGPT and Gemini could be plagiarised if used as is. You need to build, adapt and change the content so it’s something unique.
It’s all well and good introducing AI technology if it truly is going to be beneficial to your employees and to the business as a whole, however if you’re just introducing it because everyone else seems to be, then you really have to question if it’s worth it. If it’s not actively making your work lives easier and helping you to achieve your objectives, then is it really worth the potential cost and effort to implement?
It may also be worth looking into how the AI tool you’re using was created. There is sadly still a lot of exploitation involved in the development of new technology, so it’s up to you to ensure that the tools you’re using were created in an ethical way.
Ultimately, ensure that you are using AI safely, ethically and that it aligns with your businesses established objectives. This will need to be communicated clearly to everyone in the business.
ISO 42001 is, at its heart, a Management system standard. Like many other ISO Standards, it includes guidance on setting objectives and communicating these to your wider business.
[15:24] #5: ISO 42001 helps to implement safeguards – Certain features of AI may require safeguards to help protect businesses against the extra risks they pose, such as the increased potential of more sophisticated cyber attacks or compromised training data.
This can be applied within a particular process or an entire system.
Examples of features that may require these safeguards include:
· Automatic decision making
· Data analysis, insight and machine learning
· Continuous learning
Something you need to consider: Cyber scams are going to become a lot more complex with the help of AI, so you need to ensure you’re staff are both aware of this and how they can avoid falling prey to them. Safeguards may simply involve more training on these new risks, or updating to a more robust security software that is able to detect possible AI cyber scams.
Developers are also going to need to keep on top of any data being fed into their tools. Public live data tools especially will be more susceptible to being poisoned and tampered with, so it’s up to them to monitor and ensure the integrity of their data.
ISO 42001 provides guidance in it’s annexes for users and developers to implement these necessary safeguards.
[16:30] #6: ISO 42001 Supports compliance with legal and regulatory Standards – More AI focused legislation is an inevitability, with the new EU AI Act being a perfect example.
It’s important to ensure that you are prepared to comply with legislation as it’s released, or you may be held liable and be subject to fines.
Currently, the UK has no plans to introduce a new regulator for AI, instead relying on existing technology based regulators like the Information Commissioners Office (ICO), Ofcom and FCA.
ISO 42001 includes specific considerations for any potential applicable legislation.
[17:06] #7: ISO 42001 Can enhance your reputation – ISO Standards are internationally recognised and ensure you are complying with best practice.
Gaining certification to ISO 42001 will show you are confident in your AI related claims, and are happy to have this verified by a third party.
[17:30] #8: ISO 42001 Encourages innovation within your business – For as much as we’ve stressed the potential risks AI could expose your business to, ultimately AI is here to help make our lives easier. We just need to ensure we’re responsible when applying it.
ISO 42001 ensures you can safety integrate AI tools and systems within your business. It’s there to help guide the adoption of this new technology, and drive continual improvement as your management system matures.
[17:55] #9: ISO 42001 Can be easily integrated with existing systems – ISO 42001, like many ISO Standards, is based on the Annex SL format and can be easily integrated with existing ISO Management Systems such as an ISO 9001 (Quality management) or ISO 27001 (Information Security management) system.
Risks addressed in ISO 42001 include security, privacy and quality among others, and can help to enhance the effectiveness of your Management system in those areas.
[18:25] #10: ISO 42001 Does not require an existing Management System to implement – While ISO 42001 would make a great addition to any ISO Management System, it’s important to note that this can be implemented independently.
It is also not intended to replace or supersede any existing quality, safety or privacy Standards / existing management systems.
We’ll be releasing a suite of ISO 42001 related training content on the isologyhub, if you’d like to get notified as soon as this becomes available, please register your interest on our waitlist.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Nearly 60% of businesses that are impacted by a cyber incident go out of business within the 6 months following.
With our heavy reliance on technology to keep both businesses and services running, it’s imperative that everyone take cyber risk seriously.
However, incidents will inevitably happen and it’s up to you to ensure that your business is prepared to ride out the wave, and hopefully make a full recovery!
We invited Jack Morris, Account Director at Epiq, back onto the show to discuss the consequences of not being prepared for a cyber incident and the key steps businesses should take in the event of an incident.
You’ll learn
· Who are Epiq?
· What does the current cyber incident landscape look like?
· What are the consequences if a business does not respond to a cyber incident effectively?
· How can a business detect if they’re being attacked?
· How should businesses respond in the event of a cyber incident?
· What role does a legal team play in incident response?
Resources
· Epiq
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Jack Morris, Account Director at Epiq, to discuss how businesses should respond to a cyber incident.
[03:00] Who are Epiq? – Epic is a global leader in technology enabled legal services. In fact, it supports 90% of the top law firms globally! With over 8000 employees spread over 19 countries, it helps to support corporations, law firms and government agencies across the globe.
[04:35] What constitutes a cyber incident and why is it so important to respond effectively? – A cyber incident refers to unathorised access or attempted access to an organisation’s IT systems. Types of incident include breaches, malicious attacks (e.g. Ransomware), and accidental events (e.g. Fire Damage). Responding effectively is crucial to minimize damage and protect sensitive data.
[05:40] What does the cyber incident landscape currently look like, and what challenges will organisations face in responding to an incident? : The cyber incident landscape is ever evolving, but here are some key trends we saw in 2023:
Attacks on the rise – the number of organisations posted on ransomware and data theft sites increased by over 70% year-on-year.
Business Email Compromise (BEC) incidents surged by 67% in 2023 – these events are where people within an organisation fall victim to phishing or similar – clicking on malicious links which ultimately compromise your mailbox.
For me, there are 3 main challenges that organisations face when responding to a cyber incident:
· Day-to-day management – balancing the technical aspects of the incident with broader business continuity, communications, financial and legal considerations. This can be hugely difficult for an organisation, during and already high stakes situation.
· Expertise and support – navigating the complex legal, technical and operational aspects of an incident
· Data-focused impact – understanding and assessing the risk to data after resolving an incident.
[10:00] What are the solutions to these challenges? – Understanding the various external expertise and support available to a business, whether that be engaging with a law firm, a cyber incident response expert and cyber insurer will give you access to support with both the day-to-day management of an incident, as well as the legal, operational and commercial impact of said incident.
[12:10] What are the consequences for an organsiation that does not respond effectively to a cyber incident? – : Failing to respond effectively to a cyber incident often leads to a variety of sever complications for a business, such as;
· Operational Issues: operational disruptions will occur due to prolonged exposure of sensitive information, and if Ransomware has infected systems, the organization will not have access to potentially crucial business information. Financial losses and higher costs to incident response can come as a result of poor planning.
· Additional Data Breaches: if an organization doesn’t respond effectively to a cyber incident, taking steps to gain control over their systems, additional data breaches can occur from threat actors gaining further access to the organisation’s systems.
· Financial losses: cyber incidents affect a business’ bottom line. Costs including incident investigations, recovery, legal fees and potential fines. Further, knock on effects such as lost business opportunities and damaged investor confidence come from poorly managed cyber incidents.
· Damage to Reputation and Trust: Public perception matters for a business. A poorly handled cyber incident damages an organization’s reputation. Customers, partners and stakeholders lost trust, affecting long-term relationships and market position.
· Legal Consequences: Regulatory fines and potential follow on litigation arise from non-compliance with data protection laws. Organisations failing to report breaches promptly face penalties. Legal battles can be costly and time consuming.
[16:25] How can organisations detect if they are being attacked? – signs will vary depending on the type of cyber incident, but organisations and end users could expect to experience; slow systems, locked accounts (no access to mailboxes etc), inability to access documents or shared drives, ransom demands and unusual emails from organisation domains are all tell-tale signs of a cyber incident. If an organisation has invested in Managed Detection and Response software for their end-points, this will proactively scan your environment and provide alerts to potential and actual cyber incidents.
[17:40] What are the key steps an organization must take in responding to a cyber incident? – It’s a great question, and these key steps will be implemented during a cyber incident response plan – an impacted organization should:
· Triage: Assess the severity and impact of an incident (organisations can instruct a first response organization to shut the doors, and assess the damage)
· Identify: Understand what is happening to a business post incident? Things like locked accounts, no access to business systems etc.
· Resolve: take technical actions to mitigate the incident – shutting off access to accounts – closing the door
· Report: Notify relevant stakeholders, including legal obligations.
· Learn: analyse the incident to then take retrospective action to prevent further incidents.
[21:23] Join the isologyhub – Don’t miss out on a suite of over 200+ ISO tools, templates and training, sign-up to become a member of the isologyhub
[23:48] How does Cyber Insurance play a pivotal role in Cyber Incident Response? – like with most walks of life, insurance plays a crucial role in supporting organisations in effectively responding to disasters.
· Response Funding: Insurers cover costs related to incident response, including professional services.
· Response Time: Insurers bring in experts promptly, improving incident resolution.
· Affordability: For small to medium businesses, insurance may be the only way to afford a response team.
[26:10] What role do vendors like Epiq do to support the incident response lifecycle? – Just like Law firms providing legal advice and support in responding to a cyber incident, cyber incident response providers support with the operational response to a cyber incident.
Initially, vendors like Epiq support with the incident identification and forensic investigations. Essentially finding the open door and closing it.
Further investigation on how the threat actor (baddie) got into the open door is conducted to prevent other doors from opening too.
Following this, the operational partner will support in understanding the extent of the incident, whether that be identifying impacted entities, notifying them of the incident and providing remediation, as well as supporting with any follow on litigation or mass claim.
[27:25] What are the legal obligations that exist after a cyber incident, especially in related to personal data breaches? – the legal obligations are clear – an organisation must report personal data breaches within 72 hours of awareness, unless the risk to individuals’ rights is unlikely. This quick turnaround is why it’s imperative that organisations have an established cyber incident response plan, and know who they should be talking to regarding the legal and operational implications.
[28:45] What support is there out there for organisations that are victim to a cyber incident? – On the previous episode, we discussed what organisations can do to be proactive in mitigating the risks associated to a cyber incident, we discussed the important of Cyber Incident Response plans, as they outline what external support an organisation should seek in the event.
Having playbooks and relationships with law firms, cyber providers like Epiq, and cyber insurance coverage are 3 key focuses for every business.
[30:35] What role does a legal team play in incident response? – Legal support and advice is critical during an incident. As mentioned, they will help support with report the incident to the regulatory bodies required.
· Breach Notification – legal support ensures compliance with data breach disclosure laws and regulatory requirements.
· Breach Counsel – law firms act as a breach counsel for organisations, enabling them to support and advise on the legal implications of a cyber incident. Most law firm cyber practice groups will have relationships with external vendors, like Epiq, to support with the operational response. They can co-ordinate with these external vendors to ensure compliance.
· Privacy Law Compliance – they guide handling of personal data and privacy implications to ensure no further issues.
[32:30] What role do vendors like Epiq do to support the incident response lifecycle? – Just like Law firms providing legal advice and support in responding to a cyber incident, cyber incident response providers support with the operational response to a cyber incident.
Initially, vendors like Epiq support with the incident identification and forensic investigations. Essentially finding the open door and closing it.
Further investigation on how the threat actor (baddie) got into the open door is conducted to prevent other doors from opening too.
Following this, the operational partner will support in understanding the extent of the incident, whether that be identifying impacted entities, notifying them of the incident and providing remediation, as well as supporting with any follow on litigation or mass claim.
[36:00] What should an organisation do in future to prevent further incidents? – Benjamin Franklin’s famous quote is so true here – ‘by failing to prepare, you are preparing to fail’.
The key point here is to learn from your mistakes. There may have been numerous reasons that the organisation wasn’t ready for a cyber incident, but they should learn from what led to the incident previously, and proactively address this to prevent further incidents. 67% of organisations that get hit by a cyber incident are subject to further attacks within 1 year. It’s important to reduce your attack surface, and ensure you have cyber security themes running throughout the business.
[37:45] What are Jack’s top 3 tips to take away from this session to help them respond effectively to an incident? –
· Establish an Incident Response Plan – we spoke through IR plans during the first episode, but creating a plan that outlines roles, responsibilities and communication channels during an incident is key. Once implemented, regularly testing the plan and simulating these incidents is key to ensuring effective response.
· Engage external experts early – during this session we identified 3 critical external support pillars to an incident – having legal advice, operational and response support and insurance is key.
· Prioritise business continuity – enabling the external experts to support you through the incident will free your bandwidth to ensure that you minimise damage and downtime to your business.
If you’d like to learn more about Epiq and how they can help you, visit their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Cyber incidents are on the rise as data shows there was a 20% increase in data breaches from 2022 to 2023.
Technology has become an integral part of most businesses, especially post pandemic where many who may have avoided this reliance on tech had no choice but to adapt to survive.
As a result, the question of businesses being affected by a cyber incident has become ‘when’ rather than ‘if’. However, there are a number of steps you can take to mitigate risks ahead of any potential incidents.
We invited Jack Morris, Account Director at Epiq, to discuss cyber incidents, the importance of being proactive in reducing cyber incident risk and the steps you can take to mitigate these risks.
You’ll learn
· Who are Epiq?
· What is a cyber incident?
· The importance of being proactive in reducing the risk of an incident
· What can organisations do to be proactive in mitigating cyber incident risk?
· What are forensic tabletop exercises, and how do they enhance preparedness?
· Why might an organisation need to get an incident response retainer?
· What role do Information Governance consultants play in reducing cyber risk?
Resources
· Epiq
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Jack Morris, Accoutn Director at Epiq, to discuss how to mitigate cyber incident risk.
[02:40] Who are Epiq? – Epic is a global leader in technology enabled legal services. In fact, it supports 90% of the top law firms globally! With over 8000 employees spread over 19 countries, it helps to support corporations, law firms and government agencies across the globe.
[04:31] Who is Jack Morris? – Jack joined the industry relatively fresh out of university, starting at an organisation called Kroll where he was focused on data management – including overcoming ransomware infected devices and essentially allowing organisations to get access to data that was previously taken away from them.
Kroll was later acquired by Duff and Phelps and went through a turbulent time of many name changes before settling on Kale Discovery. He ended up leaving a year ago and joined Epiq as an Account Director.
Jack’s role at Epiq includes being a facilitator, introducing law firms, corporations and cyber insurers to best in class people and technology.
[06:40] What is a cyber incident?: A Cyber Incident is any unauthorised or unexpected event that compromises the confidentiality, integrity or availability of an organisation’s information systems, data or network. Incidents can range from data breaches and malware infections to single mailbox compromises and insider threats.
Organisations looking to combat information security risks should consider ISO 27001, as it’s key principles include the confidentiality, integrity or availability of your businesses information.
[08:29] Why is it important for organisations to be proactive in reducing their risk of an incident, no matter the size of your business? – Let’s look at some startling statistics:
In 2022, 39% of businesses in the UK identified a cyber attack in the previous 12 months. Of this 39%, 31% of those businesses experienced attacks at least once a week.
48% of Small to Medium Businesses, globally, experienced a cyber incident in the last 12 months, with 61% of all cyber-attacks specifically targeting small business.
This is the most shocking of the statistics, and why it’s so important for us to be having these kinds of conversations around how business, no matter the size, need to be proactive in mitigating the impact of a cyber incident.
70% of small to medium businesses in the UK believe that they are unprepared to deal with a cyber attack (which excludes those who think they have proper processes in place but ultimately don’t).
Nearly 60% of businesses that are impacted by a cyber incident go out of business within 6 months following!
[12:10] Are there any particular industries that are most at risk from a cyber incident? – Cyber Incidents are not siloed to particular industries, but there are some trends that we see in the market. Looking at Q1 2024:
January saw a rise in cyber incidents predominantly affecting retail, education and local government.
In February we saw a significant number of breaches, impacting organisations across the full spectrum of markets.
All of this to say that regardless of the size of your business and the industry you operate in, the number of cyber incidents are increasing as well as the severity of said incident.
[13:35] ISO Standard trends – At Blackmores, we’ve seen an increase in demand for ISO 27001 and related data privacy standards across the board for all sectors. A stark difference to 10 years ago where it would mostly only be adopted by those in the managed services or tech based industries.
[15:30] What can organisations do to be proactive in mitigating cyber incident risk? – Things such as implementing a proactive incident response plan, engaging with law firms and consultancy organisations to become aware of the organisation’s requirements and compliance issues arising from a cyber incident.
If you were hit with an incident today, you must report any personal data breaches to the relevant regulators within 72 hours of becoming aware of an incident or there can be fines that are implicated. To deal with these types of situations, it’s imperative that your organisation has established, sound relationships with law firms and consultants.
[17:25] What is the importance of an incident response plan? – Implementing an incident response plan is crucial because it allows organisations to prepare for potential cyber incidents before they occur. By identifying risks, implementing preventive measures, and conducting exercises, organisations can significantly reduce the impact of incidents.
Organisations should be aware of both the legal and operational issues that arise from a cyber incident – from regulatory compliance and liability concerns right the way through to loss of systems/data and brand reputation are all key considerations that have an effect on the whole of a business.
[18:35] What are forensic tabletop exercises, and how do they enhance preparedness? – Forensic tabletop exercises simulate cyber incidents in a controlled environment. They involve key stakeholders discussing and practicing their roles during an incident. These exercises improve coordination, communication, and decision-making, ensuring a more effective response when a real incident occurs.
The workflow here is clearly defined; implement an incident response plan, and then test that plan for robustness – engaging with external providers, like Epiq, to further add to the existing plan and to test how the organisation will manage an active incident.
[19:35] Join the isologyhub – Don’t miss out on a suite of over 200+ ISO tools, templates and training, sign-up to become a member of the isologyhub
[21:45] Links with Business Continuity – Response readiness plans and forensic tabletop exercises both tie into aspects of ISO 22301 – business continuity.
In Blackmores’ experience, a lot of organisations don’t actually test their plans, so when going through the process of implementing ISO 22301, where testing these response plans are a requirement, it’s a bit of an eye opener when they realise they’re not as resilient as initially thought.
It’s always better to test these plans in a simulated environment vs a live one, so you can be assured that your plans are up to the task.
[23:40] Why might an organisation need to get an incident response retainer? – We're starting to see a number of industries, particularly in regulated verticals, requiring businesses in their supply chain to meet a number of different cyber security requirements. One, which keeps popping up, is to have a plan in place for responding to security incidents. Having a retainer can help meet these compliance requirements.
[26:05] What role does Managed Detection and Response (MDR) software play in proactive incident response? – MDR solutions continuously monitor networks, detect threats, and provide real-time alerts. They enhance proactive response by identifying suspicious activities early, allowing organisations to take preventive action before incidents escalate.
[27:50] What role do Information Governance consultants play in reducing cyber risk? – : Information Governance (IG) consultants specialise in helping organisation define their Information Governance Strategy encompassing data security and defining compliance policies.. They support organisations in defining:
· Data Classification: Identifying Sensitive and PII data and categorising based on their confidentiality or regulatory requirements.
· Retention Policies: Defining policies on retention period of records and method of disposition aligned with compliance requirements.
· Legal Holds: Ensuring necessary data is preserved for potential litigation, internal investigation or as part of audit process.
· Privacy Compliance: Aligning with regulations such as GDPR, DP, DPA, CCPA.
[33:30] What are Jack’s top tips that the listeners can take away from this podcast session and implement today to begin mitigating their risk? – : Unfortunately mitigating cyber risk isn’t a one-size-fits-all response, however I like seeing cyber risk as 3 buckets, that businesses should be aware of and measure their organisation against:
Technology & Infrastructure – outdated systems, unpatched software and not fit for purpose IT infrastructure pose risks.
These types of vulnerabilities are exploited by attackers, leading to data breaches, malware infections and system disruptions.
So, making sure that your technology and infrastructure is fit for purpose, and up to date is a key takeaway. We spoke about Managed Detection and Response solutions earlier in the session, which is a great, cost effective way of adding an additional layer of technology security.
Human Factor – for me, this is the number 1 frailty to a business. Business Email Compromise incidents increased by 67% in 2023, with Multi-Factor Authentication (MFA) being bypassed in 29% of these cases.
Over recent years, cybersecurity awareness has been the aim of the game. However it is crucial that, as our understanding progresses, we switch our focus to fostering a culture of cybersecurity responsibility among colleagues and employees.
Ensuring that your people are aware of cyber incident (perhaps listening to this podcast), and their role in mitigating the risks associated to a cyber incident are crucial in ensuring that your business is secure.
Preparation – in just about all walks of life, preparation is key for preventing almost anything. We have spoken today about some of the key preparation themes I’m seeing in the industry, from Response Readiness plans, to MDR, to Incident Response Retainers. Getting sufficient Cyber Insurance coverage is of paramount importance to ensure that your business can respond effectively to an incident, should one occur.
If you’d like to learn more about Epiq and how they can help you, visit their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Businesses looking to tackle their environmental impact will need to look at how they can reduce their carbon emissions and offset any remaining emissions to ensure that they reach Net Zero.
One of the most common ways businesses offset their emissions is through the purchasing of carbon credits that typically go towards planting trees or re-wilding.
However, there are a number of new emerging trends following on from the current commodification of nature, resulting in an attitude shift from businesses who are looking to get a lot more involved in the offsetting process.
We invited Luke Baldwin, Co-founder and CEO of Nature Broking, back onto the show to explain the latest trends in the carbon market.
You’ll learn
· What are the latest trends in the carbon market?
· The importance of high integrity within carbon offsetting
· Looking for impactful solutions
· Why education around carbon offsetting is key for long-term sustainability commitment
· How buying carbon credits now can lead to significant savings
Resources
· Nature Broking
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Luke Baldwin, Co-founder and CEO of Nature Broking, to discuss emerging trends in the carbon market that help businesses tackle their carbon offsetting.
[02:50] What are the key trends in the Carbon Market – As of 2024, Luke states the leading trends as:
· High Integrity
· Impactful solutions
· Education
· Purchase carbon credits now and save later
[04:10] High Integrity – There’s now a lot of carbon credits available and due to the nature of the unregulated carbon markets, it’s led to an increase in bad actors generating revenue in a bad way.
Once example of this is Kariba, a project in Zimbabwe that aimed to tackle deforestation, which was recently exposed in the Guardian and The New Yorker for having incorrect calculations. Credits purchased towards that programme were then called into questions and any associated companies were accused of greenwashing.
To avoid this, businesses are now putting a greater focus on high integrity solutions, which involves considerations such as:
· Are the credits durable? Will the carbon be stored long term?
· Are their significant CO2 benefits?
· Are the credits contributing anything besides just removing carbon? i.e. regenerative agriculture or woodland plantation
[06:20] Impactful Solutions: The carbon markets offers a lot of fantastic solutions and businesses are moving away from the quick commodification of those solutions, and are instead looking to really understand the impact of how they chose to offset their emissions.
It’s becoming more of a question of buying carbon credits that align with your values, whether this be social values or sustainability values.
They’re looking to invest in projects that will have a tangible outcome. Which is exactly what Nature Broking sets out to assist businesses with by tailoring bespoke solutions that adhere to their specific values.
[08:10] Education – The need for more education around the carbon markets is crucial.
Luke remembers the quote “you can't love what you don't know”, which applies as how can a business truly invest in something that they don’t fully understand.
Sustainability is a mindset, and a cultural shift towards more sustainable practices starts with an education.
Carbonology uses an ISO framework, but also provide an education around the carbon reduction plan provided to inspire a mindset shift change towards sustainability.
[09:05] Blackmores experience – Blackmores have been implementing environmental and energy Standards for over 18 years, but it’s only been in recent years that we’ve seen a mindset shift in leadership towards sustainability.
While people may be aware of Standards such as ISO 14001 or B Corp, but may not be aware of other governance frameworks that can help businesses to manage their carbon footprint and carbon neutrality.
[10:20] Join the isologyhub – Don’t miss out on a suite of over 200+ ISO tools, templates and training, sign-up to become a member of the isologyhub
[12:25] How can you make significant savings when purchasing carbon credits? – A lot of carbon solutions currently are very cost effective, in particualr forestry credits and carbon removal credits.
Some of the more technological ones such as direct air capture or bioenergy and carbon capture and storage can be more expensive now because the technology utilised is still so innovative and in it’s infancy. However, that will change in time.
If you're looking at building a carbon portfolio for your net zero journey, for example, say are going through a science based targets initiative and you've decided that you cannot avoid the 10% of remaining emissions your net zero journey and you need to buy carbon removals - you're much better purchasing carbon removals now than in the future.
This is because there will be a supply shortage in future, especially when we see more enforced regulations come into play between 2030 and 2035. This will mean that the price of those carbon credits will rise significantly.
What may cost £20-£30 per tonne for carbon removal now may go up to anywhere between £100 - £150 per tonne!
So it’s worth investing in your carbon portfolio now, especially in the case of tree planting as those tress are going to take a while to grow and actually start storing carbon.
If you finance projects now, you will have already made an amazing impact from the start, and will potentially save yourself a lot of trouble and money in future by planning ahead.
If You’d like to learn more about Nature Broking and their solutions, check out their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The UK is the first major economy to achieve it’s 50% reduction target for Greenhouse Gas Emissions (between 1990 and 2022). However, we’ve still got a lot of work to do to reach our 2023 target of a 68% reduction.
Many businesses are already making great strides to reduce their Impact, and while you can reduce, achieving true carbon neutrality will involve offsetting a certain amount of emissions.
One of the biggest challenges for businesses in terms of completing their offsetting is finding a credible carbon offsetting scheme.
Mel is joined by Luke Baldwin, Co-founder and CEO of Nature Broking, to discuss credible nature-based solutions for carbon offsetting.
You’ll learn
· Who are Nature Broking?
· What is Natural Capital?
· How can we restore nature at scale?
· Financing transition regenerative agriculture through the sale of natural capital
· How have Nature Broking worked with clients to complete their carbon offsetting?
· How can you demonstrate a credible carbon offsetting scheme?
· What projects are Nature Broking currently working on?
Resources
· Nature Broking
· Isologyhub
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Luke Baldwin, Co-founder and CEO of Nature Broking, to discuss credible nature based solutions for carbon offsetting and explore some of the wonderful projects Nature Broking have been involved with.
[04:10] What is natural capital? – Natural capital is the idea of creating value from nature. What natural capital does is, it encompasses all the things that we get from nature that we rely on. That could be the shelter in your house all the way through to carbon offsets.
[04:55] Who are Nature Broking? – Nature Broking’s story starts off on a somber note. Sadly, Luke lost one of his friends in a mountaineering accident, and in his memory, Luke and another friend rewilded one acre of Scottish Borders Woodlands. This is something they make a point to visit every year, to pay tribute and to keep their living, breathing monument of his friends memory alive and well.
The experience was an eye opening one. For as lovely as the process was, it was incredibly expensive, and not very easy to do. Luke then realised that philanthropy alone wasn't going to be able to cover the costs of what we required to restore nature.
Looking into the matter further he found that 50% of the world's GDP is moderately or highly dependent on nature and that the UK, whilst green and beautiful, sits in the bottom 10%.
And so, an idea was sparked. Together his friend and Co-founder Andy started down the nature restoration path and created Nature Broking.
[06:20] What is Nature Broking’s mission?: Nature Broking have 2 major missions:
#1: Help restore nature at scale
#2: Help finance a transition to regenerative agriculture
[06:34] How can we restore nature at scale? – The UK Government has set targets of halting nature decline by 2030, with a view to increase nature by 2045.
The Green Finance Institute has calculated that there is a funding gap of about 56 billion in order for us to achieve our legally binding environmental targets. That’s a hefty sum to put on public money and philanthropy, which is where private markets and business can make a big impact.
Frameworks like PAS 2060 (ISO 14068) help businesses invest in nature, and with the creation of carbon credits, carbon has been commodified to make it more accessible for businesses to contribute to carbon offsetting.
[08:20] How can we help finance transition regenerative agriculture through the sale of natural capital? – Regenerative agriculture is about restoring the soils, restoring nature back to its original level.
Modern farming techniques, while fruitful, use tools such as fertilisers and mechanised farming that have damaged the soils biome. That’s going to take time and a concerted effort to fix.
Now obviously, we can’t just stop farming, we need food, so not all land can go back to nature. Currently, 70% of the UK is farmed, so the agricultural sector will play a big part in being more regenerative.
However, the current incentives aren’t great, so there’s a lot of work that needs to be done in terms of financing the mechanisms behind it, i.e. funding and subsidies ect. One way we could do this is by ulitilising the carbon markets, as regenerative agriculture can lead to significant carbon sequestration.
[12:20] How do Nature Broking work with clients? – They make sure to work within the bounds of the business itself, as every business is different..
They don’t do off the shelf solutions, preferring to work closely with their clients and help them to really spend time in nature at the place where their carbon credits are being implemented. It’s ultimately about education on the different solutions available, including asking important questions like:
· What impact do you want to have?
· What are the challenges with each solution?
· What do you need to watch out for?
Each solution is tailored to your business. So, if you’d prefer to work in woodland restoration over regenerative agriculture, then Nature Broking would be happy to work with you to achieve that.
Carbon credits include their own set of challenges, one of the main ones being that science changes, so the solutions offered through carbon credits will also change. It may be a case of purchasing credits that tackle different solutions over a large area rather than pooling them all into planting trees for example. Nature Broking are here to help advise and facilitate this.
[15:30] Join the isologyhub – Don’t miss out on a suite of over 200+ ISO tools, templates and training, sign-up to become a member of the isologyhub
[17:45] How can Nature Broking demonstrate credible carbon offsetting? – Nature Broking are at their heart transparent with how they operate. By taking clients to see the actual physical results of their carbon credits, they can educate and help others form a genuine connection to nature. They want clients to truly understand the full impact of their efforts.
The second element is due diligence, which can be displayed by utilising one of the many carbon related frameworks now available, such as B Corp and Sylvera. Though these don’t always work within a UK setting, so Nature Broking are working towards creating frameworks that do fit within the overall market view.
Lastly, they ensure that the standard they’re using is of high integrity, using frameworks such as the Integrity Council for the voluntary market, which analyses different standards. The 2nd is understanding the quality of the project developer, so looking at their technical expertise, looking at their financial ratings, and then evaluating the individual project itself in terms of potential risks.
[21:50] What are some of the projects that Nature Broking are currently working on? – A broad view of what’s available in terms of schemes include:
· The Woodland Carbon Code
· The Peatland Carbon Code – This is run by the IUCN, which is the International Council for the Conservation of Nature.
They are both defined and funded by DEFRA. These are some of the first carbon codes to move into the UK, however there is a lack of available carbon credits, which should change in future.
Other’s include:
· Wilder Carbon – A carbon code focused on rewilding, run by The Wildlife Trust.
· Carbon Code of Conduct - A regenerative agriculture code, so it focuses on analysing the full sequestration and full emissions potential of a whole landholding.
[25:00] Carbon Credits in practice – There’s a current project called Bank Farm in Kent, which is being used as a test site for regenerative agriculture. This includes the likes of agroforestry, which is where you integrate trees into fields which provide shade for animals and store carbon. So, you’re not removing those fields from production, simply adapting them to be more sustainable.
They’re also practicing mob grazing, which is all about using herbivores to maxmise the amount of carbon stored in the soil. You can do this by moving, say cows for example, around a field to graze quickly on small areas before moving them on.
[27:05] Mel’s conclusion – There’s a huge opportunity in the management of agriculture that can be utilised within carbon credit schemes. In addition to helping our economy by creating new jobs within this new approach to tackling emissions and storing carbon. Hopefully we’ll see larger corporations investing in these sorts of schemes both here in the UK and abroad.
If You’d like to learn more about Nature Broking and their solutions, check out their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The UK recently hit a huge milestone, according to the Department for Energy Security and Net Zero (DESNZ), the UK have reduced their Greenhouse Gas Emissions by 50% between 1990 and 2022.
The UK are the first major economy to achieve this, however we’ve still got a lot of work to do to meet our 2030 target of a 68% reduction.
Over the past few years there have been a number of schemes aimed at businesses to help tackle their impact, specifically their energy consumption. Here in the UK, ESOS (The Energy Savings Opportunities Scheme) was introduced as an implementation of the EU Energy Efficiency Directive and has been a mandatory undertaking for large organisations that fit the criteria.
Recently, that scheme has been updated and a number of changes have come into effect for Phase 3.
Ian Boylan, Chief Executive Officer at ISO Baseline, joins Mel to explain the recent changes to ESOS, how they affect organisations in the UK and EU and how ISO Baseline’s software can help businesses consistently manage their energy consumption in alignment with ISO 50001 (The Energy Management Standard).
You’ll learn
· Who are ISO Baseline?
· What is the Energy Savings Opportunities Scheme (ESOS)?
· What are the changes to ESOS?
· How do the changes affect those who currently comply using ISO 50001
· What are the changes to the ESOS eligibility requirements?
· How can ISO Baseline help businesses with their ISO 50001 and ESOS compliance?
Resources
· ISO Baseline
· Isologyhub
· ISO 50001
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Ian Boylan, Chief Executive Officer at ISO Baseline, to discuss the changes to The Energy Savings Opportunities Scheme (ESOS), and how the changes will affect the European Directive on energy management and energy reporting.
[03:20] Who is Ian and ISO Baseline? – Ian has been involved with ISO Standards for a number of years, starting with the technical aspects of building Management Systems, to working with Certification Bodies as an auditor for Management Systems.
From this experience, Ian really got to understand the challenges that organisations face when implementing ISO Standards. Challenges such as maintenance to ensure they are achieving their requirements and objectives.
Which is where the concept for ISO Baseline was born. Targeted specifically towards the Energy Management Standard ISO 50001, ISO Baseline’s software allows organisations to manage their energy processes and provide evidence that you are meeting your energy objectives.
[05:30] What features are included in ISO Baseline’s software? – Features include:
Energy reporting: Information can be displayed in graph or Sankey diagrams to help visualize your energy performance.
Identification of opportunities: Any opportunities for improvement found in the provided energy report will be recorded in an ‘Opportunities Register’
Financial Assessments: Work out life-cycle costs for assets, which can be used as a guide to establish possible savings by implementing suggested improvements.
[07:25] What is ESOS?: ESOS was introduced when we were still a part of the European Union, when there was a European Directive on energy efficiency.
It placed a requirement on member states in the EU to put together schemes for ensuring that large organisations undertake energy audits on a regular 4 yearly basis. In the UK this was adopted as the ESOS regulations.
For many years, if a business’s ISO 50001 certification scope covered all of its energy usage, then your business was considered compliant with ESOS.
If you didn’t have an ISO 50001 Management System in place, you would have to undertake energy audits once every 4 years, and have that reviewed, approved and signed off by a lead ESOS assessor.
At the time, this had to cover 90% of your energy usage. One of the more updated inclusions into these regulations was the introduction of transport as a source of energy consumption.
ESOS also included the requirement to identify significant energy consumption and propose a logical way to reduce energy consumption to improve energy performance.
[11:30] Main changes to ESOS: Accounting for your energy consumption – Instead of accounting for 90% of your total final energy consumption, you're now required to account for 95% of your total final energy consumption. The de minimis component of it has been reduced by 50%
[012:30] Main changes to ESOS: Activity Metrics – All organisations will be required to develop activity metrics and as part of your audits you'll be required to submit those activity metrics.
The aim of this is to allow the UK to effectively assess organisations over established periods (i.e. from Phase 3 to phase 4) to see if and how they are actually reducing their energy consumption.
This could potentially lead to benchmarking, where organisations can be measured against each other.
[14:45] Main changes to ESOS: Submitting Actions Plans – Previously, you just had to submit your completed audits and overall savings potential, now you will be required to submit a proposed Action Plan to improve your energy performance.
You will also be required to report annually on your progress towards that Action Plan.
So no longer can companies coast on simply paying to complete an Energy Audit exercise once every 4 years, now you will have to produce publicly available information that will hold organisations to account. Essentially a name and shame for organisations that choose to do nothing.
[16:55] Making Actions Plans publicly available – Incidentally, it always has been a requirement that everything that has been reportable regarding resources should be accessible, but previously you were not required to produce Action Plans. So essentially now that will also become part of the publicly available information.
[17:30] Making ESOS fit for purpose – When ESOS was introduced, there was already so much other legislation around in the UK, so the main focus then was to align them with one another and to ensure that they were all working towards a common purpose.
In this update, it hasn't ultimately required you to determine your energy savings potential in carbon reduction, but quite obviously that would be a little bit ludicrous if an organisation went down this route and not to look at it from a carbon perspective, as It's only a tiny little additional step when you're doing it from a money perspective and an energy perspective to figure out what the carbon impact is.
[18:30] Do you need help with your Carbon Reporting? – If you need assistance with GHG emission or SECR reporting, contact our sister company Carbonology®.
[19:20] Join the isologyhub – Don’t miss out on a suite of over 200+ ISO tools, templates and training, sign-up to become a member of the isologyhub
[21:25] Main changes to ESOS: Confirming your compliance – There are different approaches that you will need to be aware of when submitting your evidence of compliance, and which one you use will depend on which route you’re taking.
For the full ISO 50001 route, you will need to complete the Annex 1 approach, which is a reduced reporting requirement where you do not need to use an ESOS lead Assessor to submit it on your behalf, the organisation can do it themselves.
If you going down either the energy audit route or do not have 100% of your energy consumption covered by ISO 50001 – you will be reporting using the Annex 2 approach. This is where you still require a lead ESOS Assessor to work with you and provide final sign-off on that reporting.
[24:15] Are there any changes in the eligibility requirements? – There aren’t any major changes in ESOS’s eligibility requirements. They have now updated the turnover amounts from Euro to Pound Sterling following our exit from the EU.
[25:35] How will these changes impact organisations? – Organisations will have to adapt to a more proactive approach towards their energy reporting and management.
No longer can you get away with doing an energy audit once every 4 years and then forgetting about it until the next Phase. You need to start looking at it from the perspective of annual reporting, as all this information is going to be publicly available every year, which is going to be scrutinized if you’re seen to not be taking any significant action.
Large organisations will be compared against each other, and if one is taking action every year to reduce its impact and another is doing nothing for 4 years, which do you think will gain a more favorable reputation?
This level of accountability is long overdue, and will be of benefit to organisations in terms of potential cost savings through reduction of energy use, and also more importantly to the environment.
[30:00] How can ISO Baseline ISO 50001 help organisations with their ESOS compliance? – ISO Baselines tools and software are going to be the most benefit to organisations that have a real objective to improve energy performance. If you’re just doing the bare minimum to meet requirements, then it’s no for you.
ISO Baseline ISO 50001 is a tool to help systemise your organisations approach to energy management. It can help to avoid a lot of the bureaucracy that can hold up progress, so you can spend your time focusing on the objectives and what the Management System is meant to lead to.
Their software will guide you through the required processes involved with ISO 50001 Energy Management, including Internal Audit planning and completion, Management review, logging and addressing non-conformities and corrective actions.
If You’d like to learn more about ISO Baseline and their software, check out their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
According to the ISO Survey, there’s been a 82.9% increase in worldwide ISO 22301 certificates issued following 2020.
Business Continuity is a must have for businesses who want to ensure long-term survivability following a disruptive event. Many turn to ISO 22301 to help put a framework in place, including today’s guest – Lifelong Learner.
However, what usually takes businesses a minimum of 6 months, Lifelong Learner managed to accomplish in just 4 months across an international organisation! That is no small part due to the tremendous effort of Lifelong Learner’s Manager of Information Security, Governance, Risk and Compliance, Lauren Taylor.
Lauren joins Mel on this weeks’ episode to share her journey and explains the challenges associated with implementing a Business Continuity Management System in just 4 months.
You’ll learn
· Who are Lifelong Learner?
· Why did they decide to Implement ISO 22301?
· What did they learn from implementing ISO 22301?
· What was the biggest challenge with Implementation?
· What are the benefits of implementing ISO 22301?
Resources
· Isologyhub
· Lifelong Learner
· PSI Testing Excellence
· Talogy
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today Mel is joined by guest Lauren Taylor who is the Manager of Information Security, Governance, Risk and Compliance at Lifelong Learner Holdings LLC.
Lifelong Learner and it’s brands represent a fusion of comprehensive workforce solutions, with a human-first focus of changing lives through assessment. This includes helping people advance in educational and career aspirations, earning or maintaining licensing or certifications, or providing the tools to develop future leaders.
Lauren has helped Lifelong Learner accomplish a massive milestone, and that’s the implementation of the Business Continuity Standard ISO 22301 across an international organisation, which she managed to do in just 4 months! She’s here to share her journey and lessons learned from implementing ISO 22301.
[03:30] Not many people know this about Lauren – She had previously trained to be a mental health counsellor.
[04:05] Who are Lifelong Learner LLC? – Lifelong Learner is the parent company of two subsidiaries:
PSI Testing Excellence: a leading provider of assessment solutions for the licensing and certification markets, to Educational Testing Services.
Talogy: A market leader in the talent management space whose core purpose is helping organizations achieve their potential. They manage the talent management side of the business. So what they'll do is they'll put together psychometric tests that help companies find the right person for the right job, and will assist with skills development.
[05:00] Adding to Lifelong Learner’s ISO Collection: Lifelong Learner already have an impressive ISO Library, being certified to:
· ISO 9001 – Quality Management
· ISO 14001 – Environmental Management
· ISO 27001 – Information Security Management
[05:20] What was the main driver behind obtaining ISO 22301? – The main driver, as with most companies, is usually a client contractor requirement, but business continuity has been something that we've wanted to look further into for a while, just because there's elements of ISO 27001 that cover the business continuity.
While we were able to get through the audits with what we had, we just felt that it just needed a little bit more building out. Business Continuity is a requirement in part of ISO 27001, but for Stakeholders that want assurance that a business has robust business continuity plans in place, ISO 22301 is the next step.
[06:10] The Implementation Timeline – In October 2023, we began with the context workshop where we could kind of get a better idea of the scope of the management system.
This was followed by a number of SWOT and PESTLE workshops to help identify what the perceived risks would be.
Next came the Business Impact Analysis (BIA) - So essentially what you're needing to find out from these workshops is, the core activities that each of the teams perform on the day-to-day basis. You also need to understand what their systems are that they use, if they have any dependencies, and essentially it all comes down to understanding that if the business cannot perform those activities, what would be the impact overtime if those activities were to stop.
Once you have all that information, the next step was to map it across into a risk assessment, which really helps you to understand the granular risks to your business when it comes to business continuity planning.
This risk assessment helped to highlight some weaknesses that we hadn’t considered before, and gave us a point in the right direction as to what we needed to work on to bridge those gaps.
Next was the creation and revamping of documentation inline with ISO 22301 requirements. Thankfully, due to the other ISO’s we hold, we already had a lot in place. Same goes for Internal Audits, so this was more a case of integrating ISO 22301 into our existing Management System.
Once we had all the documentation, we conducted a ransomware test exercise, which we also documented all the findings from. Then we were we were ready for stage 1!
[09:15] What were the biggest gaps Lifelong Leaner needed to address?: Following the BIA and Risk Assessment, we were able to see where we needed response plans because business continuity is always your Plan B. So in our minds, we had an idea of what kind of response plans we would need in terms of i.e. a malware response plan, a ransomware response plan, those sorts of things. But until we actually looked at the BIA we released we needed a few more.
[10:25] What difference did addressing those gaps make? – For us it was understanding the real risks to our business.
We already had ISO 27001 in place, and we figured if there were to be another pandemic for example, that we’d be covered. However, it wasn’t until we did those exercises did we realise that there was a lot we could improve on.
[13:25] What did Lauren learn from Implementing ISO 22301? – How much people underestimate the importance of a good business impact analysis.
After going through this in a very, very short space of time, I realised that it is actually the driving force behind a good business continuity management system.
Also, it highlighted just how many people believe business continuity is just all about IT and physical security, they completely loft out the human element.
An example of this is having a single point of failure, which is where if somebody left there would be a gap.
[14:40] What benefits have Lifelong Learner experienced since implementing ISO 22301? – Lauren has noticed that more clients are requesting to see their Business Continuity Plans.
It’s helped with the introduction of the latest ISO 27001:2022 controls – as these too also focus on elements of business continuity.
[15:50] Lauren’s top tips for implementing ISO 22301 – Definitely give yourself longer than 4 months!
Logically think about how everything links together, the clauses all have purpose and flow in a logical pattern to help create a Management System.
Your Management Review can be your best friend. It's your opportunity to really engage with senior management and help them understand what your risks are to the business, how your internal audit is coming along, how you manage your nonconformities and it can be all neatly wrapped up in that nice management review bow.
[18:00] Lauren’s book recommendation – The Matthew Perry Autobiography, Friends, Lovers and the Big Terrible Thing.
[19:30] Lauren’s favorite quote – “You catch more flies with honey than vinegar.”
If You’d like to learn more about Lifelong Learner, check out their website.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
There’s no escaping it, AI is here to stay. Over the course of 2023 we’ve seen more general and public use of popular AI tools such as ChatGPT and Gemini (previously Google Bard).
It’s now even being integrated into everyday applications such as Microsoft Word and Teams. There is no doubt that there are a lot of benefits to using AI, however, with new technology comes new risks.
So how do we address the growing concerns around AI development and use? That’s where the new Standard for AI Management Systems, ISO 42001 comes in!
Join Mel this week as she explains exactly what ISO 42001 is, who it’s applicable to, why it was created and how ISO 42001 can help businesses manage AI risks.
You’ll learn
· What ISO 42001 AI Management Systems is
· Who it’s applicable to
· Why it was created
· How ISO 42001 can help businesses manage AI risks
Resources
· Isologyhub
· ISO 42001 Webinar registration
In this episode, we talk about:
[00:30] Join the isologyhub – To get access to a suite of ISO related tools, training and templates. Simply head on over to isologyhub.com to either sign-up or book a demo.
[02:05] Episode summary: Today we’re touching on a very topical subject – AI, and more specifically the brand new AI Management System Standard – IS0 42001. We’ll also be exploring who it’s applicable to, why it was created and how it can help businesses manage AI risks.
[03:30] What is AI? – AI – otherwise known as Artificial intelligence, as it’s most simplest description is the science of making machines think like humans.
We’ve seen a lot of AI tools be released to the public over the last year or so, tools such as ChatGPT and Google Bard. It’s already being integrated with some of the most commonly used apps and programs like Microsoft word and Teams.
In short, AI integration is here to stay, so we may as well get to grips with it and make sure we’re using it responsibly.
[05:10] What is ISO 42001? – , ISO 42001 is the first International Standard for Artificial Intelligence Management Systems, designed to help organisations implement, maintain, and improve AI management practices.
It was jointly published in December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
The emphasis of ISO 42001 is on integrating an AI Management System with an organisations existing management system – i.e. ISO 9001 or ISO 27001 compliant management systems.
Interestingly, a lot of the specific mentions of Artificial Intelligence and Machine Learning are within the Annexes rather than the body of the Standard. The Standard itself is very similar to ISO 27001 in that it’s mostly about what organisations should be doing to manage computer systems regardless of any AI components.
[08:00] The 4 Annexes of ISO 42001:
Annex A: This acts as a Management guide for AI system development, with a focus on trustworthiness.
Annex B: This provides implementation guidance for AI controls, with specific measures for Artificial intelligence and Machine Learning – if you’d like to learn more about the difference between the two, go back and listen to episode 135.
Annex C: Which addresses AI-related organisational objectives and risk sources.
Annex D: This one is about the domains and sectors in which an AI system may be used. It also addresses certification, and we’re pleased to see that it actively encourages the use of third-party conformity assessment. This just ensures that your AI claims have more validity.
[09:15] Who is ISO 42001 applicable to? – Those annex descriptions may have you assuming that this Standard is only applicable to organisations developing AI technology but in actuality it’s applicable to any organisation who is involved in developing, deploying OR Using AI systems.
So if you’re a company who is only utilising AI in your day to day activities, it’s still very much applicable to you!
[10:20] Join the isologyhub and get access to limitless ISO resources – From as little as £99 a month, you can have unlimited access to hundreds of online training courses and achieve certification for completion of courses along the way, which will take you from learner to practitioner to leader in no time. Simply head on over to the isologyhub to sign-up or book a demo.
[12:25] Why was ISO 42001 created?:
· To address the unprecedented rapid growth of AI and all the risks that come with this new technology.
· To ensure that AI development and use are trustworthy and above all, ethical.
· The public are also reasonably wary of this new technology, so ISO 42001 aims to help build more public trust and confidence in the future use of AI .
· ISO 42001 acts as guidance for organisations on exactly how to integrate AI Management controls with their existing systems.
[14:05] AI risks you should be aware of – This isn’t an exhaustive list, as the technology develops, more risks will become known. However, as of the start of 2024, you should be aware of:
Inaccurate information – Many of the chat bots and public AI tools are trained on publicly available information, and as we all know, not everything on the internet is true. So the output from these chat bots will need to be checked and verified by a person before being used or published.
AI bias – Studies have proven that AI results can still be bias. As all the data fed into it is all based on existing information, it still presents the issue of a lack of information from underrepresented groups, or existing bias based on existing data.
Time sensitivity – Not all AI use live data sets. Google Bard does, however Chat GPT is only accurate up until 2021. So double check whichever tool you’re using to make sure the information it produces is up-to-date.
Plagiarism – Data gathered using AI came from somewhere! If you simply copy and paste information provided by AI platforms, there’s a chance you may be plagiarising existing content. Be sure to just use AI as a starting point!
Security risks – Use of AI can expose you to additional security risks, For example, malicious actors could send someone an email with a hidden prompt injection in it. If the receiver happened to use an AI virtual assistant, the attacker might be able to manipulate it into sending the attacker personal information from the victim’s emails.
Data Poisoning – AI uses large data sets to train its models, and we currently rely on these data sets being relatively accurate. However, researchers have found that it’s possible to poison data sets – so in future, AI may not be very reliable if preventative measures aren’t put in place by AI developers.
[17:45] How can ISO 42001 help business manage these risks? – Above all, it provides a structured approach to identify, assess, and mitigate AI risks. ISO 42001 includes the guidance needed to put this in place from the start to ensure you don’t fall prey to the risks mentioned, with a view to monitor and update to address new risks in future.
It promotes transparency and accountability throughout the AI life cycle.
It helps ensure fairness, non-discrimination, and respect for human rights in AI development and deployment.
It will help minimise potential legal and ethical liabilities associated with AI. The UK’s current GDPR and Data Protection Act can loosely cover aspects of AI, depending on how the terminology is applied, but there are already dedicated AI based regulations being developed within the EU which will likely be adopted by the UK.
It can foster innovation and accelerate adoption of responsible AI practices.
And lastly, it provides a common language and framework for collaboration on AI projects.
[21:35] Don’t miss out on our ISO 42001 webinar – We’re partnering with PJR to bring you a 2-part webinar series on ISO 42001. Catch the first part on the 5th March 2024 at 3pm GMT, register your interest here.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We have over 18 years experience of implementing various ISO’s, covering a wide range of topics such as Quality, Sustainability, Information Security and Risk.
With a 100% success rate, we’re confident in our consistent approach to implementing ISO’s, so much so that we’ve coined our own unique methodology.
Our regular listeners may be familiar with the term ‘isology’ from previous episodes referencing our online platform – the isologyhub. But what is isology exactly?
Put simply, isology is our 7-step method for implementing any ISO Standard. Join Mel this week as she breaks down each of the 7 steps, including the planning, creation and review of an ISO Management System.
You’ll learn
· Our experience implementing ISO’s
· The origin of isology
· What is isology?
· The seven steps of isology
Resources
· Isologyhub
· Isology synopsis
In this episode, we talk about:
[00:25] Episode Summary – Mel Blackmore will be explaining our world leading methodology to implement any ISO Standard, which we’ve affectionately named ‘Isology’.
[00:45] The creation of isology: We’ve been implementing ISO Standards for 18 years, starting with ISO 9001 and have since expanded our repertoire to over 20 ISO Standards covering risk, sustainability, quality and Information Security.
The creation of the isology methodology has been a team effort from all of the consultants who have worked with Blackmores over the years, and is primarily built on best practice.
[01:35] Step 1: Plan – Get a copy of the Standard, determine your scope, timescales, leadership commitment, resources and selecting a Certification Body.
Timescales: This is typically around 6 months, but could be longer or shorter depending on your specific requirements.
Resources: As an example, if you were looking to obtain ISO 14001 certification, you may need to appoint a sustainability champion. For ISO 27001 you’ll need a representative from the IT department.
Selecting a Certification Body: Ensure whichever Certification Body you choose is UKAS accredited. You can check this on the UKAS website. International listeners will need to verify on your country’s national accreditation body website.
[03:45] Step 2: Discover – Time to understand what you have in place already and what you’re missing – this is done through a Gap Analysis.
This will often involve an initial meeting with the leadership team to establish what you already have in place, i.e. relevant policies and procedures or any relevant objectives.
We break this down step-by-step and document it all in a Gap Analysis, which will deduce your current level of compliance. From this an action plan can be created to indicate what needs to be done to become fully compliant, including assigning roles to assist with the Implementation.
[05:30] Step 3: Expose - This is where we look at risks and opportunities related to your desired Standard (both internally and externally). This is typically done through a SWOT (Strengths, Weaknesses, Opportunities and Threats) and PESTLE (Policital, Economic, Social, Technological, Legal and Ethical).
In this stage you will also need to understand the key requirements of any relevant stakeholders, so this can include clients, subcontractors, regulatory bodies ect.
A Risk Register may be created to capture the findings to be addressed later. Some ISO’s require a Risk Register, others don’t, but in our experience it’s beneficial to have one regardless.
Companies are also encouraged to create a Legal Register to keep track of all their statutory, regulatory and contractual requirements.
[07:50] Step 4: Create – Time to review the requirements of the Standard in terms of documentation – and create what’s needed. This includes capturing your way of working with documented Procedures, so make sure you have the relevant staff involved in their creation.
Something to remember, you can have additional policy statements that aren’t required by the Standard. If they are important to you, add them in!
We’re in a modern age now, gone are the days of paper manuals gathering dust on an office shelf. Software and applications may be where the bulk of your Management System documentation lives. For example, at Blackmores we use a combination of Monday.com and SharePoint to manage all of our day-to-day activities, including our own ISO 9001 compliant Management System.
The key here is to make your Management System accessible for everyone.
[10:20] Step 5: Launch – Once the Management System has found its home, you need to communicate it. Consider the type of launch you want and who will be involved. Make sure you encourage engagement with the Management System.
Why should you Launch your Management System? Quite simply, there isn’t much point in having controls in your business if no one knows about them!
We have 2 key ways of supporting you with the launch of your Management system:
1) We can run an awareness session on your Management System either in person or via Teams. It can then be recorded and used as refresher / induction training.
2) Get access to the isologyhub – out online platform with a suite of over 200 ISO courses, training, tools and templates.
[12:15] Step 6: Engage - After the launch you want to ensure that employees are fully engaged and they actually not only are aware of the policies and procedures that you've got in place, but they're actively using them.
The only way to verify this is through Internal Audits – that’s not just our opinion, that’s a mandatory requirement of any ISO Standard.
We can assist with conducting these Internal Audits, which double up as a dummy run ahead of your assessment visits. These audits are essentially a show and tell exercise to gather evidence that you’re doing what you say your doing.
[13:55] Step 7: Review - Time to take a step back and look at what’s been achieved and what’s been highlighted as areas for improvement through your Internal Audits. This is done at what we call a Management Review.
These are typically conducted as meetings, but they don’t have to be a meeting specifically. We’ve done a podcast covering other ways to conduct this review.
At this Management Review you will collate data on the performance of your business in relation to the ISO Standard. The minutes must be recorded, as your Assessor will expect to see these as it’s a mandatory requirement of any ISO Standard.
If you’d like to learn more about what’s involved with a Stage 1 and 2 Assessment, go back and listen to a previous episode.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The deadline is looming over the horizon as October 2025 marks end of the validity of ISO 27001:2013 certificates.
Have you made a start on your transition journey? If not, you really should make a start in 2024 to ensure you’re all set well before that final deadline. The first step is to decide if you want to do it yourself or enlist the help of a professional consultant.
For those that want to tackle it yourselves, you’re in luck! As we have just the tool to help: The ISO 27001:2022 Transition Gameplan.
In this weeks’ episode, Steph Churchman, Communications Manager at Blackmores, explains why you need to transition to the 2022 version of the Standard and outlines the 7-step ISO 27001:2022 Transition Gameplan available on the isologyhub.
You’ll learn
· Why do you need to transition to ISO 27001:2022?
· What happens if you don’t transition?
· What is the ISO 27001:2022 Transition Gameplan?
· An overview of the 7-step Gameplan
Resources
· Isologyhub
· ISO 27001 Transition Gameplan
In this episode, we talk about:
[00:25] A different host – Steph Churchman, Communications Manager at Blackmores, steps in to cover today’s episode. She’s heavily involved with the development and updating of the isologyhub, and will be explaining one of the latest Gameplan’s: The ISO 27001:2022 Transition Gameplan
[01:15] Why do you need to transition to ISO 27001:2022? The October 2025 deadline is fast approaching, so you really should be making a start in 2024 if you’ve not already.
[01:45] Who needs to transition to ISO 27001:2022? – Basically, anyone who is currently certified under ISO 27001:2013 will have to transition to the updated Standard.
One of the main reasons why we recommend getting a head start on this is , Certification Bodies will undoubtedly have a large demand for transition audits in 2025, when everyone’s rushing to get it done last minute. This results in a shortage of resources from the CB’s, and you may end up struggling to get booked in time.
[02:35] What happens if you don’t transition in time? – The harsh truth is you will lose your ISO 27001 certification.
This then means you’ll be required to go through another Stage 1 and 2 Assessment against the latest version of ISO 27001, which can be costly.
Another key reason is the latest version of ISO 27001 also considers a lot of new technologies that weren’t around back when the last version was published. You can imagine now that there are a lot more cybersecurity risks to consider with all the latest technology that has been released in that time. Put simply, it’s for the benefit of your Information Security to ensure you are adhering to the most recent best practice Standards.
[03:40] What is the ISO 27001:2022 Transition Gameplan? This Gameplan will walk you through the stages of transition, which align to our proven isology® approach. Isology being our methodology for implementing any ISO Standard, based on our 18+ years of experience.
In this Gameplan we provide training videos on the changes to ISO 27001, along with specific training videos covering each of the new Annex A controls that you will need to be familiar with, along with templates and workbooks to take you through the process from beginning to end.
[04:20] Step 1: Plan – Before you begin on your journey, it’s advised to understand the main changes to the standard. We’ve summarised the high-level changes in a previous podcast, and included a quick summary in the first step of the Gameplan.
In this first step, you’ll also find guidance on how to prepare for your Certification Body visit. You really do need to do this early on to help establish a realistic timeline to complete your transition work.
[04:55] Step 2: Discover – At this stage, you need to get to grips with the changes to the Standard. There have been a number of controls changed, and 11 completely new ones added. We did cover a select few of these new controls in a few previous podcasts: #111, #112, #113, #114
In this Discover step we provide a number of awareness videos to explore these new controls and changes in detail, including how they may apply to your business.
We’ve also included a downloadable PDF guide to these changes, in case you’d like to share this information internally.
[05:40] Step 3: Expose - In this step we’ve included an ISO 27001:2022 transition workbook, which will act as a guide for all your transition activities. The first being the conducting of a Gap Analysis against the latest version of the Standard.
After completing this, you will have a much better idea of where your main gaps and vulnerabilities are, so you can start putting the necessary controls in place to ensure compliance with ISO 27001:2022.
We’ve also included a summary of the main Management System documentation that will need to be updated ahead of your transition visit.
[06:20] Step 4: Create - This is the step where you will be implementing those changes as a result of your Gap Analysis. This will also be guided by that workbook, and we have provided some additional templates and resources to aid you.
These include:
· A Statement of Applicability Template
· Annex A Control Mapping
· ISO 27001 Management Review Template
[07:15] Step 5: Launch – It’s not just about updating your documentation, you will obviously need to communicate these changes to the wider business.
In this step we go over a few options for your launch plan – including guidance for both a soft launch and an all-in launch.
To help you decide which one would be the best fit for you, we’ve included a full summary of each method in addition to a pro’s and con’s list for each.
[08:30] Step 6: Engage – The last stages are all about gathering evidence of compliance against new and updated clauses and controls.
In this step we provide some insight into what’s required from your Internal Audits and Management Review ahead of your transition visit.
If you wanted to get some more tips on carrying out internal Audits within your business – we also offer a full Internal Auditor course on the hub that covers the core skills needed to complete those. If you become a member of the hub, you’ll get access to our whole library of resources – which includes a wealth of ISO related tools, templates and training videos.
[09:20] Step 7: Review – This last step will help you prepare for the transition visit with your certification body.
We touch on what you should expect from your Certification Body ahead of the transition visit, and include guidance on carrying out a final Document and evidence check to make sure you’re all good to go.
If you’d like to book a demo for the isologyhub, simply contact us and we’d be happy to give you a tour.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Did you know that in the UK alone, 22 million pieces of furniture are discarded each year, the majority of which goes directly to landfill. That amounts to an estimated 670,000 tonnes of furniture wasted, where a significant portion could be recycled and reused. (Source)
It’s clear to see the need for a more sustainable approach to furniture design, manufacture and lifecycle, which is where today’s guest, Design Conformity, come in.
Design Conformity live and breathe circular design, the process for creating products sustainably from the beginning, and offer a Life Cycle Assessment Certification Process which has already led to significant carbon reductions.
Mel is joined by Adam Hamilton-Fletcher, Founder and Director at Design Conformity, to discuss the application of circular design within the furniture manufacture industry and explain how their Life Cycle Assessment certification process can help businesses reduce their carbon footprint.
You’ll learn
· Who are Design Conformity?
· What is circular design and how does it help companies reduce their carbon footprint?
· What are the benefits of Design Conformity’s certification?
· Can sustainability be of financial and environmental benefit to businesses?
· Examples of circular design in practice
Resources
· The ISO Show
· Design Conformity
· Carbon Calculator
· Circular Design Guide
In this episode, we talk about:
[00:25] Introducing today’s guest – We welcome Adam Hamilton-Fletcher, Founder and Director at Design Conformity, onto the show. Design Conformity are currently setting the standard in retail sustainability, particularly in relation to the furniture industry.
[01:30] Who are Design Conformity? Adam worked in the manufacturing industry for about 15 years, designing lighting systems for major retailers like boots, Next, Marks & Spencers and Morrisons. He worked primarily with the lighting used in displays, and had been tasked with selling lighting products. In order to do so, he needed to develop a specification to help understand customer requirements, which would then be used to develop their ideal solution.
The problem: There were little to no Standards in UK and Europe for the retail display industry.
Which directly led to the creation of Design Conformity – who started out as an electrical and lighting Standard certification company, that developed into a full carbon certification company.
They aim to become the gold Standard for sustainable furniture design.
[03:10] What is Circular Design? – Circular design is born out of this principle of a circular economy. To compare, a linear economy is when we take a raw material, use it, process it, and then it’s just disposed of, usually straight to landfill.
Whereas, circular economy is where we take that waste product and we design it so that it can be repurposed and refreshed and reused. Those materials can then eventually be recycled – so the goal is to not use any raw materials at any point.
Circular design is the intent to minimise environmental impact, to design equipment that could be reused and repurposed, and then at the end of its life be recycled.
[04:05] How do Design Conformity operate? – Design Conformity look at the way that companies design their furniture and then take them through a learning process (online course).
They help businesses to understand how to design a product in such a way where it can be repurposed or reused, where raw material usage can be reduced and where the shipping requirements can be reduced.
They provide guidance and advice on recommended materials, including the provision on an online carbon calculator.
They also provide reporting in alignment with existing carbon standards, such as ISO 14064, for product evaluation.
[06:55] How can the Carbon Calculator help? By selecting a product of a particular type, you can use the estimator by entering the details of where and what you’re manufacturing, and then it will give you a carbon footprint for that, which you can use to compare that against other industry designers.
It displays these other designers anonymously, but you can get a feel for if your product is above or below the average for carbon emissions.
[08:55] An example of the Carbon Calculator in practice – Design Conformity recently worked with Costa Coffee, who were looking to reduce the environmental impact of their of their shops and coffee lounges. The beginning of that process is to work with their manufacturers, to identify the environmental impact of the furniture that they've got.
They used the Carbon Calculator to help create an initial benchmark, which highlighted key indicators that can lead to carbon reductions.
[09:35] Design Conformity’s Certification – They’ve borrowed the concept used by existing Energy Performance Certificates, by having a carbon efficiency index, ranging from C1 – C7.
Their score is a bit more unique however as it incorporates elements of circular design. Their score is based on a products total carbon emissions, divided by it’s size and total lifespan. An Ecolabel is then awarded based on the final score.
[11:45] What are the benefits of Design Conformity’s certification?:-
· It’s a mix between carbon reporting and a carbon rating.
· It’s easier for consumers to understand the benefits in comparison to companies that advertise compliance with ISO 14064 and PAS 2060.
· Not just a green label, as reporting is a key component of gaining certification.
· It provides a cradle to cradle analysis on a products carbon footprint and translates that into something that is recognisable.
[14:15] Are businesses right to be skeptical about the value of the cost versus the value of environmental certification?– 100%! It’s not uncommon for eco labels to be more of a marketing tool rather than a tool for tangible carbon reduction. A lot of them out there are unregulated and are contributing to green washing.
That’s where Design Conformity’s differs, as they actually collate and process real data to provide tangible value and add credibility to their claims.
[16:10] Will there be a time where sustainability can be of financial and environmental benefit to businesses? – Yes, absolutely! And if there is a way to do that, it’s through Circular Design.
As an example, if you’re a manufacturing company that’s producing shelving, you need to buy in steel, which can fluctuate a lot in price at any given time. But you don’t need to buy more steel every time, where instead you could get your original product back, reprocess and redistribute.
Adam has experience of suppliers who are practicing this, they purchase their products back at 40%-50% of the price, saving a lot of money in raw material!
[19:00] Examples of companies who have embraced circular design –
Tesco: They’ve introduced a policy whereby they purchase metal shelving, use it for 5 years, then take it back out of the store to get powder coated, cleaned and reintroduced to the store. That reduces the carbon footprint by 70% in comparison to buying a new shelving set!
Boots: Their beauty halls wanted to introduce a lot of new brands, which meant a lot more displays were needed. Boots started working with Design Conformity towards earning their certification, specifically in relation to the lighting they used in stores. With Design Confomity’s help, they managed to reduce the carbon footprint at selected stores by 39%!
[21:20] Circular Design Guide – 14 people were involved in creating this guide, which is designed to give you an introduction to and overview of circular design. Access it over on their website.
If you’d like assistance with any ISO Standards, get in contact with Blackmores and we’ll be happy to help 😊
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
For those in the ISO Space, you may be very familiar with the term ‘Certification’ in relation to ISO Standards. However, for certain ISO Standards there is a different type of terminology you need to be aware of.
The demand for a more unified and structured approach to reduce carbon emissions has resulted in a few carbon related ISO Standards to be published over the last few years. Standards such as ISO 14064 (Carbon Verification) and ISO 14068 (Climate Change Management) use the term ‘Verification’ rather than ‘Certification’.
So, what’s the difference between the two?
Join Mel in this weeks’ episode as she explains the key differences between the terms ‘Certification’ and ‘Verification’ in relation to ISO Standards.
You’ll learn
· What is Certification?
· What is Verification?
· What is the difference between certification and verification?
· What’s involved with Verification?
· Is there a demand for Verification in the UK and overseas?
Resources
· The ISO Show
· Carbonology
In this episode, we talk about:
[00:25] Episode summary – Listeners familiar with the world of ISO will know of the term ‘Certification’, however the release of new Carbon related Standards such as ISO 14064 and ISO 14068 has brought in a new term: ‘Verification’
This episode, we’ll explain the difference between the two. If you’d like to learn more about ISO 14064 and ISO 14068, check out episode 72 and episode 158.
[02:00] What is Certification? – Quiet simply, Certification is for businesses who wish to certify an ISO Management system – so a company wishing to implement a Quality Management system to ISO 9001, would get the ISO System certified by an accredited Certification Body.
[02:25] What is Verification? – Verification is the confirmation of a claim, through the provision of objective evidence, that specified requirements have been fulfilled. Therefore ISO 14064 the carbon footprint verification standard is a standard that is verified not certified.
The ‘claim’ or ‘statement’ is typically the QES ‘Qualifying Explanatory Statement’. If you’d like to find out more about this, then checkout Episodes 91 to 97, where David Algar, Principal Carbonologist at Carbonology explains in more detail.
[03:35] Setting the record straight – Some organisations (and even Certification Bodies!) have been stating they have been certified to PAS 2060 or ISO 14064 – which is technically incorrect.
As a certificate is not issued and they're not certified.
[04:30] Think of Verification as an MOT: A simple analogy for Verification is a car MOT. This is an annual check to verify that a claim is correct, much like an MOT, someone must inspect evidence and check that everything is as claimed – not unlike checking under a car bonnet and checking tires to see if everything is in working order.
[05:20] What is the difference between accreditation for certification and verification bodies? – For ISO Certification, certification bodies must adhere to ISO 17021:2015. This standard basically provides a requirements for bodies providing audit and certification of management systems, and applies to CB’s like BSI or NQA.
There are many others here in the UK, simply visit the UKAS website to find a list of accredited CB’s. In other countries, simply go to your national accreditation body website to find a full list.
[06:40] Accreditation for Verification Bodies – Verification Bodies need to adhere to ISO 17029, which was a Standard first published in 2019. That standards title is: Conformity assessment, general principles and requirements for validation and verification bodies.
Both Standards provide structure and governance to basically ensure that standards are either certified or verified to a level playing field.
[07:20] Watch out for the cowboys – Unfortunately, there are some fake third party so-called certification and verification bodies that offer certification and verification.
They do not adhere to either ISO 17025 or ISO 17029, and instead play by their own rules. Which results in utterly worthless (and very expensive) ‘certificates’ that won’t hold up under scrutiny in tendering applications. So please ensure you use an Accredited Certification or Verification Body!
[07:48] What are the differences between Certification and Verification? Certification in more detail – Certification of an ISO Management System means of providing assurance that the organisation has implemented a system, so they've got the policies, procedures and controls in place against the relevant activities for their products and services to be delivered.
Certification for management system provides that independence, that impartiality that the company is actually doing what they say that they're doing, and that it's effectively implemented.
If you want to get certified, you need to undertake an Assessment. Typically this is done in two parts – A Stage 1 Assessment is a document review and Stage 2 Assessment is the evidence to prove that the companies following its policies and procedures.
[09:35] What are the differences between Certification and Verification? Verification in more detail – There are actually 2 definitions for Verification:
1: The process for evaluating a statement of historical data and information to determine the statement is materially correct and conforms to criteria in 3.6.10.
2: It's a confirmation of a claim through a provision of objective evidence that specified requirements have been fulfilled. There are a couple of notes with this one, including:
· Verification is considered to be a process for evaluating a claim based on historical data and information to determine whether the claim is materially correct and conforms with specified requirements.
· Verification is applied to claims regarding events that have already occurred are results that have already been obtained, confirmation of truthfulness.
[11:30] Avoiding Greenwashing – Now more than ever is the time to actually have systems in place to be able to verify that claims are factually correct.
A key thing to note with both Verification definitions is that they state you can only make a claim for a certain period – again, much like an MOT.
[12:55] What’s involved with Verification? – There are a few ways to gather the historical data needed for verifiers, here’s a few:
· Observation;
· Inquiry;
· Analytical testing;
· Confirmation;
· Recalculation;
· Examination;
· Retracing;
· Control testing;
· Estimate testing;
· Cross-checking;
· Reconciliation
From those terms alone, you can tell that this is a much more analytical approach than compared with Certification.
[14:30] What’s the current status of Verification in the UK and overseas (as of 2024) – In addition to being the Managing Director of Blackmores, Mel is also CEO of Carbonology – a sister company dedicated to Carbon Standards.
Across both companies, we’re seeing a lot of interest in Sustainability Standards such as ISO 14001 and ISO 50001.
At this current time, there is not so much of a demand for Verification and as such, there’s not a demand for third-party verification at this stage. There is however, a demand for an impartial second-party Verification to back up an organisations’ claims.
[16:15] Need any help with ISO 14064 or ISO 14068? – Get in contact with Carbonology and speak to our expert Carbonologists.
If you’d like assistance with other ISO Standards, get in contact with Blackmores and we’ll be happy to help 😊
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO Standards are internationally recognised as the gold standard for best practice within a variety of subjects and sectors.
But what ISO Standards are the most popular across the whole globe? And are there any trends that can be gleaned?
Thankfully, the International Standards Organization runs a yearly survey to find out!
Join Mel in this weeks’ episode as she breaks down the top 10 ISO Standards Implemented globally, where they are most popular and identifies key trends.
You’ll learn
· What are the top 10 Implemented ISO Standards?
· What Standards are gaining traction?
· Where are the top 10 Standards most popular?
· Are there any trends within the top 10 Implemented ISO Standards?
Resources
· The ISO Show
· ISO.org
In this episode, we talk about:
[00:25] Don’t forget to subscribe and leave a review – We love sharing top tips and dispelling myths about ISO Standards. Help us reach a wider audience by subscribing on your preferred media player, and leaving us a review 😊
[01:10] Episode summary – We’ll be taking a look at the top 10 most popular ISO Standards based on the ISO Survey, run annually by iso.org. The survey results break down the number of ISO Certificates issued, and highlights which countries and sectors these Standards are most popular in.
We’re basing this episode on the 2022 results, as the 2023 results won’t be out until later this year. We’ll do another episode on the 2023 results to see what’s changed – so keep an eye out for that!
[02:14] #1: ISO 9001 – No surprises here! The Quality Management Standard is still top of the pops. It’s holding strong with a 12% increase based on the previous year.
It’s most popular within the Construction, wholesale & retail, electrical, machinery & equipment sectors.
China is in the lead with number of certificates issues (by a very large margin!), followed by Italy, India, Germany and the UK.
[03:30] #2: ISO 14001 – We’re happy to see the Environmental Management Standard so popular! In fact, it’s had a 21% increase over the previous year!
It’s most popular in China, Japan, Italy, UK and Spain.
Construction is the leading sector, but we’ve also seen an increase in the number of professional services choosing to adopt this Standard.
[04:15] #3: ISO 45001: Coming in at #3 we have the Occupational Health & Safety Management Standard. This has seen an even bigger increase in demand, 29% more than the previous year.
China still leads the way with number of certificates issued, but the UK and Australia are not far behind.
Interestingly, there is little uptake within the Agriculture sector, which is concerning considering they consistently have the highest injury and death statistics year on year (in the UK according to the annual HSE reports).
[05:25] #4: ISO 27001 – The Information Security Management Standard comes in at #4, with a 21% increase in demand over the previous year.
Unsurprisingly, it’s increased primarily in the IT sector, but that’s followed by transport, storage and communications, along with financial services and real estate / renting.
[06:00] #5: ISO 22000 – The Standard for Food Safety Management makes it into the top 10, with it being more popular in Taiwan and Greece.
The sector specific information for this particular Standard is slim, but it’s applicable to any organisation involved in the making, packing and distribution of food, as well as organisations in the hospitality sector.
[06:30] #6: ISO 13485 – This is the Standard for Medical Devices. The USA are leading the way with certificates issued, followed by France, Germany and Italy.
We’re pleased to see that none of these ISO Standards are in any decline, and only seem to be increasing in popularity as the years go by.
[07:20] #7: ISO 50001 – This is the Standard for Energy Management, if you’d like to learn more about this Standard, check out a few of our previous episodes.
ISO 50001 has seen a 33% increase in demand, which is amazing to see! We hope this is a sign of more organisations taking climate change seriously, and taking the appropriate steps to start reducing their impact.
China is still in the lead where number of certificates issued is concerned, followed by Germany, Spain, Italy and France.
[08:25] #8: ISO 20000 – The Service Management Standard is still very popular within countries where we see a lot of call center activity.
This used to be known as the ‘IT Service Management Standard’, but it has since evolved and encompasses Service Management as a whole. We did a podcast episode covering this Standard in 2023, so go back and listen if you’d like to find out more.
No surprises to see China still in the lead with number of certificates issued, followed by USA, India, Italy and Spain.
[09:15] #9: ISO 37001 – This one was a surprise, ISO 37001 is the Anti-Bribery Standard.
Blackmores have implemented this Standard in the Construction and Facilities Management sectors, but it’s a shock to see it in the top 10 as it’s always been very niche here in the UK.
This particular Standard is most popular in Peru, followed by Italy, Indonesia, Korea and Brazil.
We were curious about why Peru were in the lead, and it seems that there may be a requirement for certain organisations to have this. Back in 2017, we knew there was a voluntary requirement, but perhaps this has changed in the last few years. If we have any listeners in Peru – we’d love to hear your feedback on this subject!
[10:35] #10: ISO 22301 – The Business Continuity Standard. This Standard is most popular in the UK, and based on our experience, it’s commonly adopted by those in the professional services and IT managed services sectors to help provide resilience and continuity for their Stakeholders.
Other countries where it’s popular include India, China, Greece and Korea.
[11:20] The runners up – These Standards didn’t make it to the top 10, but they were very close:
· ISO 55001 – Asset Management
· ISO 20121 – Sustainable Event Management
· ISO 44001 – Collaborative Business Management
[12:10] Conclusions – It’s clear to see that sustainability based Standards are becoming very popular. We’re particularly pleased to see the 33% increase in demand for ISO 50001!
If you’d like to request a specific topic, or be a guest on a future episode, get in contact and let us know.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Before we dive into the new year, we’d like to take a step back and reflect on 2023.
Last year was filled with a lot of topics and challenges, from tackling the transition to ISO 27001:2022, to finding credible ways to offset your carbon emissions within the UK.
With a total of 33 episodes published last year, Mel looks back on the 5 most popular episodes of 2023, including some highlights from each episode.
You’ll learn
· What were the top 5 most popular podcast episodes of 2023?
· A highlight from each of the top 5 episodes
Resources
· The ISO Show
In this episode, we talk about:
[00:45] Editor shoutout – A special shout out to the Blackmores Communication Manager, Steph Churchman, who helps organise, produce and publish the ISO Show podcast!
[01:20] Information Security was a favorite topic for 2023 – ISO 27001:2022 was definitely a hot topic in 2023, which is not a surprise seeing as anyone currently certified to ISO 27001:2013 will need to transition to the latest standard by October 2025. Many were making a start on this in 2023, or looking to plan it in for 2024.
[02:10] #1: Episode 128 What’s new with ISO 27001:2022? – Orginially published as part of a series of podcasts explaining the new Standard. This episode focuses on a high-level overview of the major changes.
Here are a few highlights from the snippet:
· Steve Gives an overview of what’s new in ISO 27001:2022 – The updated version of ISO 27001 was released on the 26th Oct 2022. The new version included 24 changes and clarifications within the main clauses.
· The controls for the new standard are now categorised into 4 groups: Organisation, People, Physical and Technology
· We covered some of the new controls in more detail in previous episodes: #109, #110, #111, #112, #113 and #114
· The 24 changes and clarifications to Clauses include older existing clauses which have been tidied up to be more transparent. We recommend reviewing to ensure that you are complying in a way that aligns with the Standard.
· There are 11 new Controls. 56 controls from the 2013 version have been reduced to 24 with 58 remaining unchanged. So, in short, Annex A has been simplified with less duplication of controls.
[09:15] #2: Episode 130 What are the 11 new controls in ISO 27001:2022? – In this episode we brought Steve Mason back to discuss the 11 new controls in ISO 27001:2022, and delve into the context of why these were added. We also highlight some of the resources we’ve made available in the isologuhub, including mention of our ISO 27001 Transition Gameplan.
Here are a few highlights from the snippet:
· These new controls are nothing to worry about – they are simply aligning the Standard with more modern security considerations. You may already be complying with them!
· Control A.5.7 Threat intelligence – ‘To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken.’ – This can come from many different sources, such as the NCSC or local police websites. There are also additional tools you can add to detect possible phishing attacks. This also includes consideration to external threats – Information Security is about much more than just protecting data! It also includes physical security.
· Control A.5.23 Information security for use of cloud services – “To specify and manage information security for the use of cloud services.” – More and more businesses reply on cloud-based computing. It’s important to verify the security of your service provider to ensure it’s adequate. You can check to see if they have any valid Information Security related credentials such as CSA Star, Cyber Essentials, SOC. You could also adopt principles of ISO 27017 (certification for cloud security), ISO 27018 (Protection of PII in the public cloud) and ISO 27701 (PII security Standard).
· Control A.5.30 ICT readiness for business continuity –‘ To ensure the availability of the organization’s information and other associated assets during disruption’ – There a few standards that could assist with this, including ISO 27031 (ICT readiness for Business Continuity). Those that have ISO 22301 may want to look at how ISO 27001 elements can be integrated and improved in any disaster recovery plans. ISO 27001 needs to be an integral part of any business continuity plans – not just a bolt on. Small business may not want to conduct a full business impact analysis, but should carry out a risk assessment around business continuity at the very least.
[21:20] #3: Episode 134 Credible Carbon offsetting with Treeconomy: We had some fantastic guests on the show last year, such as Harry Grocott – CEO of Treeconomy. We invited him on to talk about how we can demonstrate credible carbon offsetting through schemes here in the UK, and how you can avoid falling prey to greenwashing.
Here are a few highlights from the snippet:
· Can we quantify the value of nature? Short answer right now is no, but there is a lot of nuance. Nature offers ecosystem services i.e. farms offer a calorific benefit, we can put a price on the value that offers. The same principle applies to resources such as wood or oil. Now we are gaining the ability to quantify CO2 removal, which is undeniably valuable to humanity.
· Other more recent services such as biodiversity projects are a bit harder to quantify – as they vary so much depending on the country. However, we are starting to assign value to these.
· How can people be sure that they don’t fall prey to Greenwashing? There are 2 main issues to consider: 1) Are your carbon credits credible? 2) what claims are top management making?
· Tackling claims made by leadership: ISO standards are starting to solve this issue. There are clear requirements and certifications that need to be in place to back those claims.
· Tackling carbon credits: The carbon offsetting market is heavily unregulated currently. Essentially it’s a lot of people trading in invisible gas. There are a number of carbon standards (Not quite at the same level as ISO Standards), such as the Woodland Carbon Code and the Peatland Code, and Internationally there are standards such as Verra VSC – unfortunately, a lot of these standards aren’t very robust and aren’t enforced.
· Many companies will often look to buy the cheapest offsets available, which are likely to be non-credible and will provide no evidence of actual offsetting occurring. But, there are a lot of new companies emerging that provide tangible evidence of offsetting (such as Treeconomy )
[33:50] #4: Episode 136 dotdigital’s sustainable transformation with ISO 14001 – We’re always delighted to share stories about our clients’ ISO journeys. In this case we got the chance to talk to Steve Shaw, the Chief Product and Technology Officer at dotdigital, about their journey to achieve ISO 14001.
Dotdigital have a habit of going above and beyond when it comes to implementing ISO Standards, and this time is no different as Steve explains some of the fantastic sustainability initiatives introduced as a result of gaining certification.
Here are a few highlights from the snippet:
· dotdigital was the worlds first carbon neutral marketing automation platform that was ISO 14001 certified. They also aim to be net zero by 2030!
· They have a relatively small footprint as a primarily digital based company, only really having to consider the running of computers, air conditioning and standard office facilities. So it can be a challenge to reduce!
· What led to the success of dotgreen? – dotdigital launched a group called dotgreen, which has since thrived into a community of likeminded individuals all working together to improve and reduce dotdigital’s impact. They were fortunate to have an Executive group sponsor who can take ideas and suggestions to other leadership for consideration. This grassroots group encourages suggestions from everyone – no idea is a bad idea. Over time, the group evolved and helped to develop a sustainability programme for the business.
· What was one of the initiatives implemented from dotgreen? – They identified that existing data centers used by the business weren’t always utilising renewable energy. So, over the course of 2 years, they worked with Microsoft to build on their Azure platform to enable dotdigital to make the switch. Azure runs on renewable energy sources, and any remaining emissions can be offset through carbon credits.
· A green option for their customers – As a result of their cloud platform now being run through green partners, they can extend the environmental benefit to their customers.
[42:25] #5: Episode 135 Emerging SaaS Trends in Health and Safety – Health and Safety can be quite the task to keep on top of, a well known fact for anyone certified to ISO 45001. Thankfully, there are a number of Software as a Service options out there to make the lives of Health and Safety professionals much easier. New and emerging technologies are only going to develop more rapidly with the integration of AI and machine learning.
We invited James Sharp, Chief Technical Officer at Riskex, onto the show to discuss the top 10 emerging SaaS trends, including how each can help streamline processes and gather and analyse large amounts of data.
Here are a few highlights from the snippet:
· Riskex have been certified to a number of ISO Standards, including ISO 18001 (Prior Health and Safety Standard, now certifying to the latest version, ISO 45001), ISO 27001 (Information Security) and ISO 9001 (Quality Management)
· Software as a Service became very popular during Covid, as business became very fragmented and were looking for solutions that could be rolled out across multiple sites. Riskex also created their own track and trace system based on established software they were already offering – helping businesses manage Covid safely.
· Trend #1 – Artificial Intelligence – Artificial learning is all around us and with vast volumes of data being collected by safety management platforms. AI allows decision engines to predict and provide guidance based on key trends or established KPI’s. For example, if accident rates were to increase but at the same time risk levels have been reducing, it could soon highlight this trend and look at other surrounding data or previous trends to establish a pattern. This will lead to a more pro-active approach to reporting and subsequent decision-making.
· Trend #2 – API Connectivity – Providing an open API platform will allow businesses to integrate internal systems and external services to digest data. As more organisations adopt Cloud solutions, connectivity between platforms has become increasingly important. With a robust API offering, multiple business services can interact with ease and become part of the safety management space, without incurring significant cost or time.
· Trend #3 – Low-Code Optimisation – Developing generic components within software to allow for quicker builds, implementations and tailoring requests. As stand-alone and generic component development increases, solutions can offer more flexibility and self-serve options to the end user to assist them with aligning platforms with their specific processes.
· Trend #4 – Mobile Optimisation – More and more end-users are accessing health and safety software via their mobiles but for various reasons, are not always able to use native apps (installed on the device). Therefore, health and safety software platforms need to adapt use on multiple devices, without the loss of features.
We can’t wait to dive into new topics this year! If you’d like to request a specific topic, or be a guest on a future episode, get in contact and let us know.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Trying to achieve Carbon Neutrality can feel like a monumental task, especially with so many separate elements that you have to complete. From quantifying your data, reducing where possible and offsetting the remainder, it can be hard to keep track of it all with taking a structured approach.
Which is where ISO 14068 comes in. This is the new Standard for Climate Change Management, and it’s specially designed to help businesses with the transition to Net Zero.
In this weeks’ episode Mel explains 10 reasons why you should use ISO 14068 – the new Standard for Carbon Neutrality.
You’ll learn
· What is ISO 14068?
· Why should you adopt ISO 14068?
· How can Carbonology Support you with ISO 14068?
Resources
● Carbonology
● Grab a copy of our Net Zero Planner
● ISO 14068
In this episode, we talk about:
[00:25] What is ISO 14068? – This is standard for Climate Change Management. If you’d like to find out more about the Standard, it’s purpose and how it can prevent green washing, go back and watch our previous episode.
[00:55] Where to find more information – This podcast is based off BSI’s most recent Publication on ISO 14068: ‘Climate Change Management – Transition to Net Zero – Part 1: Carbon Neutrality (A BSI Executive Briefing).
You can download this from a recent blog on BSI’s website.
[01:05] Reason 1: A structured approach – Mel found out firsthand from a recent EMEX event that people are looking for a structured approach to carbon neutrality.
ISO 14068 gives organisations a structured process for developing a detailed carbon neutrality management plan with short- and long-term targets.
[02:10] Reason 2: Quality - In contrast to unsubstantiated claims of neutrality, claims under ISO 14068 have to be based on all GHGs, take a lifecycle approach and can only be made after the development of long-term planning, with real GHG reductions in place, and offsetting restricted to residual emissions using high quality carbon credits.
[03:10] Reason 3: Credibility: Use of this internationally recognised standard can offer market benefits by increasing the credibility and verifiability of a product or organisational claim of carbon neutrality.
This Standard has been developed by international technical committees and subject matter experts across the globe, which gives it a lot more credibility in the eyes of Stakeholders. They will have confidence that claims are transparent and reliable from those who adopt ISO 14068.
[04:22] Reason 4: Global Recognition – A quick reminder - Those who have been listening to the ISO Show for a while now may remember our previous podcasts on PAS 2060 – the previous Standard for Carbon Neutrality. Companies will now have 2 years to transition to ISO 14068. We’ll be doing a podcast on how to go about doing that in 2024!
Circling back to Global Recognition, ISO 14068 provides a common set of criteria for measuring and reporting carbon neutrality. This ensures consistency across different organizations and industries, underpins easer comparisons for carbon neutrality efforts between entities, allows stakeholders to assess and benchmark efforts, and supports global recognition for claims of carbon neutrality.
[05:30] Reason 5: Convenience – If you’ve already got other ISO’s in place, good news! ISO 14068 is designed to work with other quantification standards such as ISO 14064 or other equivalents.
[05:55] Reason 6: Flexibility - ISO 14068 can be used by any sized organisation, in any country or sector. It can also be applied to whole organisations or individual products.
[05:55] Reason 7: Responsibility - The standard encourages organisations to take responsibility for minimising their own carbon footprint before paying third parties to offset their emissions.
We’ve seen in the past where people think just paying for carbon credits will work in the long-term – which just isn’t sustainable. You should be looking to reduce as much as possible before moving onto the Offsetting stage.
[08:00] Reason 9: Risk Mitigation – Adopters of ISO 14068 will be in a strong position to manage current and emerging regulatory and market risks in relation to GHG emissions.
It’s a competitive market place out there, with ESG requirements appearing more on tenders year on year. Many will now require you to prove your commitment to carbon neutrality, and it’s become clear that we need Standards to be able to provide that evidence.
This is where ISO 14068 comes in, as you will have that proven methodology that you can then demonstrate to those stakeholders.
[09:30] Reason 10: Competitiveness – ISO 14068 demonstrates a commitment to climate action can also mitigate reputational risks and enhance brand value, market access and competitiveness
[10:30] Further Information – Our sister company, Carbonology, will be publishing more content around ISO 14068 in 2024. Check back on their website to find out more.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We’re inching closer to our 2030 and 2050 Net Zero targets, and if we keep going the way we are, we’re not going to hit either one.
This is unsurprising considering the lack of a unified approach to achieving Net Zero. There are a lot of options to tackle certain aspects of sustainability, but few outline an entire pathway to guide businesses towards a tangible goal.
However, that may be set to change with the release of ISO 14068-1:2023 – Climate Change Management!
In this weeks’ episode Mel explains what BS ISO 14068 is, who can use the Standard, and how this Standard can combat green washing.
You’ll learn
· What is ISO 14068?
· Who is this Standard for?
· Why was this Standard created?
· How can ISO 14068 help businesses to tackle climate change
· How can ISO 14068 help combat green washing
Resources
● Carbonology
● Grab a copy of our Net Zero Planner
● ISO 14068
In this episode, we talk about:
[00:25] Introduction and episode summary – ISO 14068 has just been published, superseding PAS 2060. In this episode, we’ll explore what this Standard is all about, how it can help you and help prevent green washing.
Keep an eye out for our follow-up episode, which will give you more insight into the 10 reasons for adopting this Standard to achieve Net Zero in 2024.
[01:40] A passion for Sustainability – If you’re new, you may not be aware that Mel is the CEO of both Blackmores and Carbonology. Carbonology was created as a sister company in 2023, and it’s sole purpose is to help businesses to be able to demonstrate with credibility and complete transparency - A legitimate route to achieving carbon neutrality.
[03:00] What is ISO 14068-1:2023? – This is standard for businesses transitioning to Net Carbon zero.
The standard for specifies the requirements for achieving and demonstrating carbon neutrality through the quantification, reduction, removal and offsetting of greenhouse gas (GHG) emissions.
[03:30] Who can use this Standard? BS ISO 14068-1:2023 can be used by any organization, in the private or public sectors, that wishes to make either the organization or a product climate neutral. Products may be consumer-facing or business to business, and include all types of goods and services, including events and financial services.
[04:05] Why has this Standard been developed now?: To avoid the worst effects and keep the rise in global temperatures to no more than 1.5°C, the Intergovernmental Panel on Climate Change (IPCC) of eminent scientists has identified that we need to cut emissions of greenhouse gases by 40% in this decade and to global net zero by 2050.
However, working towards a long-term target of net zero can be difficult without recognition of achievements along the pathway. That’s where carbon neutrality can help; organisations that have a clear plan and have started making real greenhouse gas (GHG) reductions can counterbalance their remaining carbon footprint using high quality carbon credits / offsets to achieve carbon neutrality.
ISO 14068-1 is the new International Standard that sets out requirements for organisations wishing to achieve carbon neutrality, including for products, such as goods, services or events.
ISO 14068-1 also provides a rigorous and robust framework for avoiding greenwashing, and builds on the 15 years’ experience of the previous Standard – PAS 2060.
Organizations using the standard will benefit in two main ways: internally, through having a clear guide on best practice in reaching carbon neutrality; and externally, by demonstrating compliance with a rigorous standard on carbon neutrality.
[06:40] How can the standard help businesses that are still scratching their heads about how to tackle climate change? - The standard provides clear principles that entities need to consider when seeking carbon neutrality. These include establishing a hierarchy, so that GHG emission reductions are made first – and reductions are often the most cost-effective way of reducing a carbon footprint, avoiding the need for potentially costly carbon credits.
The hierarchy is then used to determine a pathway to carbon neutrality, including short- and long-term targets for minimising the carbon footprint. The standard also explains how the pathway is used in developing a detailed carbon neutrality management plan, which provides clear guidance for those responsible for the implementation of carbon neutrality.
[08:30] How can the standard combat green washing? In recent years, there have been many claims of carbon neutrality that are unsubstantiated or supported only by purchasing a few carbon credits, with a consequent risk of greenwashing.
Following BS ISO 14068-1 means organiations will be able to demonstrate that their claim of carbon neutrality is underpinned by real action to reduce GHG emissions and includes a clear pathway to eliminate all possible GHG emissions, so it does not just fall back on purchasing carbon credits in the market. This significantly improves the credibility of a claim.
[09:45] Keep an eye out for future episodes! We’ll be talking more about ISO 14068 in future episodes, including the benefits of adopting this Standard. We’ll also dedicate an episode to explaining the difference between Certification and Verification – so stay tunned!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The use of AI within business is starting to become more common place. With major applications like Microsoft Teams and Word integrating many new features designed to make our lives easier.
However, we still need to exercise caution with this new technology and consider what we can put in place to mitigate any potential security risks while developing or utilizing it. Which is precisely what today’s guest, Monolith, has done.
Monolith provide a machine learning program that engineers can adopt to build highly accurate self-learning AI models that instantly predict the performance of systems in a wide variety of operating conditions.
In this weeks’ episode Mel is joined by Æsc George, Senior Software Engineer at Monolith, to discuss why they have adopted ISO 27001, explain their implementation journey and the benefits of having an Information Security Management System.
You’ll learn
· Who are Monolith AI?
· What was their main driver behind obtaining ISO 27001?
· What was the biggest Gap identified in the initial Gap Analysis?
· What benefits did Monolith AI gain from implementing ISO 27001?
Resources
● Monolith
● ISO 27001 Transition Gameplan
In this episode, we talk about:
[00:25] An introduction to Monolith and Æsc George – Monolith AI is all about empowering engineers to develop self-learning models from their engineering test data. With this they can develop machine learning models to really accelerate new product introductions and get these new products to market much more quickly, primarily by using these models to accelerate and streamline their testing.
They are currently recommended for ISO 27001 certification, and are eagerly awaiting the arrival of their physical certificate.
Æsc George is a Senior Software Engineer of this web browser based software. He is also the interim security officer, which is why he was tasked with obtaining ISO 27001.
Fun fact about Æsc: He was a proud owner of a colony of 8 rats! He currently takes care of 4 cats, which have access to a plethora of enrichment in his home 😊
[03:35] What was the main driver for Monolith to obtain ISO 27001? – There were a few drivers, the most obvious being that they want to display their commitment and credibility when it comes to Information Security.
Acquiring ISO 27001 makes it easier to show their clients and prospects that their engineering data is in safe hands.
Monolith also know that there's a lot of buzz about artificial intelligence and machine learning at the moment, and that buzz covers both sides of the coin. What good it can do for the world and the harms it can do, so aligning with ISO 27001 shows that they’re trying to use AI in a responsible way.
[05:10] The start-up is getting a head start! – Monolith AI is a start-up company, only a year in and already leading the way for AI development by ensuring security is a priority from the start.
[05:40] How long did it take to implement ISO 27001? Nine months from the point of contacting Blackmores to assist to being recommended for certification.
Æsc recounts his experience: “My perception is that the effort was quite front loaded, so the amount of effort involved in the process almost wound down towards the end - even with the external audit happening towards the end.
I think once the information security management had been established and we'd worked it into our day-to-day, the perceived effort was lower. So I felt pretty confident going through our audit processes because I've experienced the system working already.”
[08:15] What was the biggest gap identified at the Gap Analysis?: There wasn’t a formal approach to information security risk and risk treatment.
There were already a number of existing systems and ad-hoc arrangements to mitigate information security risks – but they had been framed in terms of risk.
They hadn’t gone through a process where risks were quantified and weighed against each other.
So following the gap analysis, one of the many actions Monolith took was to make sure they were consistently and regularly assessing information security risk in various dimensions.
They now have the right framework in place to allocate the appropriate time and resources towards information security, and to prioritise the biggest risks.
[10:10] What difference has Implementing ISO 27001 made? - It’s given Monolith more confidence in their understanding of Information Security risks, and assurance that there aren’t any massive, unidentified risks that may cause trouble later down the line.
It’s also made it easier to discuss information security risk and policy decisions. Monolith AI are a remote first company, allowing their staff the freedom to experiment with new technologies, and be in an environment where they feel comfortable. Having formal risk treatment in place means they can maintain this highly flexible, highly innovative and productive way of working – but with their eyes wide open.
[11:40] What has Æsc learned from the experience of Implementing ISO 27001? Æsc is not new to ISO Management Systems, having been involved with the maintenance and implementation of a few in the past.
However, he has gained an appreciation for the nuance in ISO 27001. For example, the knowledge that the standard uses words like ‘should’ and ‘shall’ that have particular intentions – ‘shall’ being mandatory and ‘should’ being recommended.
His previous experiences with Management systems had more available resource than at Monolith, so learning this nuance has been important in the prioritization of focus and resources in his current position.
[13:30] What have been the main benefits from Implementing ISO 27001? Having a holistic and formal approach to Information Security and risk management compared to the ad-hoc approach they had prior.
It’s brought the company together on a really important issue, and helped everyone to understand the role they play in Information Security.
Personally, Æsc has enjoyed reaching out to people he may not ordinarily get the chance to work with, as a result of this unifying issue that everyone at Monolith cares about.
[17:00] Once Monolith formally receive their ISO 27001 certificate, what benefits will that bring? – Currently Monolith AI are recommended for Certification, and are simply waiting on the delivery of their physical certificate.
Once received, they will be able to present it to prospects and clients if they are questioned on information security credentials – to show that they are serious about their commitment to security.
It will also open doors to new prospects that may bother considering them as a supplier due to the lack of ISO 27001 certification.
They are also a leading example in the relatively new industry of AI, those with ISO 27001 certification at this stage stand out from other competitors.
[19:15] What tips does Æsc have for those starting out on their ISO jorney? – Speaking from experience, Æsc recommends hiring a specialist in ISO to assist with your implementation.
In his case, Blackmores helped to organise the process, drive a lot of the early gap analysis and gave him confidence in going through internal and external audits.
Having someone with experience acting as a guiding hand makes the whole process go a lot more smoothly. This could be a consultant, or someone you train within your own business.
These projects are the sort of thing that turn passion into action. Whether that’s information security or environmental management ect, it’s better to have someone experienced or trained in the nuances of the Standard to ensure it’s implemented in a way that truly benefits your business.
[21:20] Æsc’s book recommendation - Nature's Calendar: The British Year in 72 Seasons by Kiera Chapman, Rowan Jaines, Lulah Ellender and Rebecca Warren. It’s Inspired by a traditional Japanese calendar which divides the year into segments of four to five days, this book guides you through a year of 72 seasons as they manifest in the British Isles.
As Æsc describes: “Lots of the seasons will be very familiar to people who've lived in this country their whole life, but they may not have necessarily thought about the context of it.
So I think is really grounding. Time and the way we measure it can seem so arbitrary and abstract sometimes, and measuring minutes and hours is responsible for so much stress and anxiety, so taking a breath, thinking about how nature moves at a different, slower, more deliberate pace, and finding the time to synchronise with that move with nature can be a really rewarding experience”
[24:15] One of Æsc’s favorite quotes - “I went to the woods because I wished to live deliberately, to front only the essential facts of life, and see if I could not learn what it had to teach, and not, when I came to die, discover that I had not lived” - Henry David Thoreau (from his book ‘Walden’)
[26:10] Need help with your ISO 27001 transition? – We have an ISO 27001 Transition Gameplan available on the isologyhub. This Gameplan provides a step by step guide for you to transition to the latest 2022 Standard.
If you’d like to learn more about Monolith AI, check out their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The demand for tangible sustainability action is becoming more pressing as we inch closer to our 2030 and 2050 Net Zero targets.
However, that is still quite a way off, and many businesses are dragging their feet when it comes to taking action. Sure, some may have an ESG Policy or mention it on their website, however that term is starting to become synonymous with green washing due to poor implementation in many cases.
So, what can you do to make a difference right now?
In this weeks’ episode Mel explains the principle of Parkinson’s law, how ISO Standards can help to tackle climate change and how you can achieve Net Zero in just 90 days.
You’ll learn
· What Parkinson’s Law is
· How can ISO standards help tackle climate change
· The 3 reasons why businesses are behind on achieving net zero
· How you can achieve Net Zero in just 90 days using the Net Zero Planner
Resources
● Carbonology
● Register for EMEX here
● Grab a copy of our Net Zero Planner
In this episode, we talk about:
[00:25] Come visit the Carbonology stand at EMEX! – EMEX is a free exhibition to learn about carbon management, ESG and sustainability. It takes place at ExCeL London on 22nd – 23rd November 2023 – Carbonology will be at Stand G38. Come grab a free Net Zero Planner while you’re there! Register your place here.
[02:10] Episode Summary – Today we’ll be talking about why we need to act now rather than in a decade or two, how ISO Standards can play a critical role in tackling climate change and using the Net Zero Planner to help you set achievable objectives to work towards Net Zero in just 90 days.
[02:55] We need to act now rather than later! – Our 2030 and 2050 targets are very far away, which results in businesses not doing much to address them in the meantime.
They might have an ESG policy or they might have something referencing ESG on their website, but are they actually taking action right now to make that happen? In many cases, no. Which is where Parkinson’s Law comes into play.
[03:40] What is Parkinson’s Law? Parkinson's Law is the idea that work expands to fill the time allotted for its completion. This may mean you take longer than necessary to complete a task or you procrastinate and complete the task right before the due date.
Parkinson's Law is the old adage that work expands to fill the time allotted for its completion. The term was first coined by Cyril Northcote Parkinson in a humorous essay he wrote for “The Economist” in 1955.
Lets say you are given a task to complete a report in 3 weeks, chances are if you were given the task to do in 1 week – you’d make it happen.
Parkinson's Law says that the perceived importance and difficulty of a task will grow in proportion to the amount of time given to finish it.
[05:30] Is it possible to achieve Net Zero in 2024?: Yes! Carbonology® been turning around projects to help businesses to build net carbon neutral in less than three months - so why can’t you?
[06:05] The Net Zero Planner - The Net Zero in 90 days planner gives you a pathway to follow to achieve Net Carbon Zero.
Each day focuses on a specific task, enabling you to make step by step progress to achieve your goals.
Your Net Zero Planner provides the foundations for not only achieving Net Zero but also achieving verification to Carbon standards along the way. Grab a copy here!
[08:25] What role do ISO Standards play in tackling climate change? Standards have a critical role in helping meet climate goals. Particularly when there is an influx of greenwashing across industries.
The international standards for carbon verification (ISO 14064) and carbon neutrality (PAS 2060, due to be ISO 14064 in 2024) support the Sustainable Development Goals (SDG) and create a level playing field, providing transparency, reliability, accountability and without a doubt, credibility.
[10:00] Why are businesses struggling to achieve Net Zero? there are three reasons why businesses are behind on achieving Net Zero:-
· Time and resources have not been dedicated.
· Lack of focus and structure
· Lack of knowledge on what to do
The Net Zero Planner will help to address these challenges.
[11:15] Carbonology is there to support you – Some of the tasks in the planner may be tricky – quantifying your emissions for example, this is always going to be challenging.
Carbonology is there to support you, either with consultancy or digital resources via the Carbonologyhub. If you need some extra assistance, simply contact them.
[11:55] How can the Net Zero Planner help you? – First and foremost, Net zero is not going to happen, unless you prioritise your time.
This starts with designing your ideal week. Imagine how would you structure your week if you had 100% control. What does your ideal week look like?
Remember, What gets scheduled gets done. Sticking to a plan takes discipline, but imagine if every business dedicated 2 hours a day for 3 months, we’d be achieving net zero well before 2050!
By setting aside 2 hours a day to complete a Net Zero task, you and your team will be well equipped to put your planning in place and achieve Net Zero accreditation! Of course, not every week will be aligned with your ideal week, but it’s a guide that you can refer back to.
[13:00] Making progress with the Net Zero Planner - It’s imperative you review progress on a weekly and monthly basis and at the end of the 9O days. This will help to drive momentum when you see what you’ve achieved and also provide a reality check if you need additional support or time.
The weekly, monthly and quarterly review provides an opportunity to look back at your progress and allows you time to reflect on what went well, and where you’ve been having challenges which may result in making decisions to address any shortfalls.
This could include allowing more time for a specific task the following week, delegating responsibilities internally or outsourcing activities i.e. carbon quantification or verification.
It's recommended that you schedule this review and reflection time in your calendar i.e. 1 hour on a Friday afternoon or at the end of the month. In addition to the structured planner pages, there are blank pages for expanding on your ideas and taking notes.
[15:25] Special Deal! - The Net Zero Planner is available for Amazon at a reduced price of £7.99 until the 15th December 2023. The Standard price will be £14.99. If you’re at EMEX on the 22nd or 23rd November 2023, we have 100 free copies to give away!
Lastly, if you have an questions or would like to learn more about how Carbonology can help you, feel free to book a call in via David’s Calendly.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Sustainability has become a top topic to address in the last few years, both for businesses and individuals. In fact, 90% of business leaders think sustainability is important, but only 60% actually have a sustainability Strategy.
The demand for tangible action is becoming more pressing as we inch close to the 2030 milestone of the Paris Agreement.
To encourage action from businesses, we’re seeing more public and private sector contracts include a tendering requirement to show your commitment to sustainability. One such example is the need for a PPN 06/21 Carbon Reduction Plan.
In this weeks’ episode David Algar, Principal Carbonologist® at Carbonology, joins Mel to explain how to create a Carbon Reduction Plan, shares some top tips on presentation and how Carbonology® can support you.
You’ll learn
· How to create a Carbon Reduction Plan
· How Carbonology® can help you align that plan with ISO 14064 and PAS 2060
· Addressing difficult tendering questions
· How to best present your Carbon Reduction Plan
Resources
● Carbonology
● Book a call with David Algar
● A quick Guide to creating your PPN 06/21 Carbon Reduction Plan
In this episode, we talk about:
[00:24] What are PPN 06/21 Carbon Reduction Plans? – Go back and listen to our previous episode to learn more.
[00:42] Episode Summary – Today we’ll be talking about how to create a Carbon Reduction Plan (CRP), how to deal with difficult tendering questions and the best ways in which to present your CRP.
[02:46] How do you actually calculate the emissions? We have gone into this in a lot more detail on a previous episode, but to summarise:-
Emissions are calculated by taking your activity data, such as kWh of electricity, or miles driven in a vehicle, and multiplying it by an emission conversion factor.
Specific emission conversion factors are available from DEFRA for specific activity data, they are also year-specific.
The hard part is sourcing your activity data, accounting for missing information, performing estimates, and ensuring the overall methodology is accurate.
This is all done in alignment with ISO1464-1, as well as the PPN guidelines, so one of the very first things we’ll do with you is define your organisational and reporting boundaries,
[05:27] How can a business set carbon reduction targets and forecast emissions? This is tricky as it involves trying to predict the future, not just in the short term, but potentially several decades ahead depending on your goal.
The good thing is you know the end destination of your carbon pathway: little to no emissions by 2050.
Using this and some simple maths you can at least map out where you should be each year when moving forward from the base year, the base year being the period you use to compare future results against.
Usually the base year is the first year you complete calculations, but this can change over time. We’re finding some clients are opting to change their base year to account for the disruption of COVID-19 on operations
[06:40] How do you actually set the targets?: When we look at target setting and emission forecasts we generally take 2 approaches:
Milestones:
· The first, and our most common approach, is about setting milestones based on specific carbon reduction initiatives the business can implement, at specific dates.
· For instance, all company vehicles being hybrid by 2025 and fully EV by 2035? Or what if we phased out gas by a certain date? Or cut out all single use plastics?
· Using this milestone method for the forecasting can be tricky, but you can end up with a carbon pathway that is more representative of real life.
Straight line method:
· The second is what we refer to as the ‘straight line’ method. This is a simpler approach that involves doing some simple maths to plan out your carbon targets for each year, without factoring in specific milestones or events.
· We refer to this unofficially as the ‘straight line’ method as the graph showing your carbon pathway is pretty much a straight line from your base year towards net zero, using the milestones method gives a ’bumpy’ line due to the influence of specific milestones at specific years.
[08:35] A tip for setting targets for the first time is by thinking ‘what if? This is essentially looking at the thing you’re doing now and replacing it with a more sustainable alternative. For instance, calculating what your business travel emissions would be last year if they were all completed in hybrids, or if domestic flights were replaced by train journeys.
Doing these ‘what if?’ calculations is a bit hypothetical as operations are likely to change over the years, but it still helps give you a specific target to aim for a specific GHG sources.
[10:40] How can you influence carbon reduction in areas where you have no direct control? Some areas will be out of your control, for instance if you ship goods in from around the world you can’t necessarily decide how they get to you, or if they are transported via more sustainable transport.
· One thing you can do is aim to set a good example yourself as a business
· You could also adopt the PPN framework yourself and request it from anyone that is aiming to win your business
· Another quick win is actually speaking to your suppliers. If you use a local delivery firm you could speak to them about their plans for an electric fleet, or more sustainable packaging. Or if you use a data centre, you could enquire about if is run on renewable energy sources
[13:15] But what if we are planning to grow as a business? Results are expected to fluctuate over time, so if they go up after the base year this shouldn’t impact your success or failure in your tender submission. The aim is obviously to decrease on average over time
If you know for certain that they will increase in the next few years, for instance through opening new sites, making acquisitions, or just natural growth, that’s ok.
You could pick a new base year if operations significantly change as this will give a more realistic figure to work down from. You can also use this as an opportunity to evidence efficiency improvements through intensity metrics, such as your tonnes of carbon per employee, or relative to your revenue.
[15:15] In what other ways can Carbonology help to support you? – Once everyone is happy with the CRP, you’ll then have to actually use it in tenders. The fun thing about tenders is that they can all ask different questions, despite PPN having technical requirements, so you can’t always have the information to hand before submitting one.
We can’t write your tender submissions for you, but we can provide guidance and pull out the necessary figures if requested, for instance if you need certain numbers to support with your Social Value Model reporting.
[16:20] How can this help on your journey to Carbon Neutrality? – If you’ve gone through all the hard work to create a PPN 06/21 Carbon Reduction Plan, you’ll be in the ideal position to achieve carbon neutrality of your operations via PAS 2060.
The next step would be creating a PAS 2060 Qualifying Explanatory Statement, or QES, which details how you have achieved carbon neutrality through offsetting, and your commitment to maintain this for future reporting periods.
[17:25] Where does the verification come into play? If you’ve already calculated your emissions you may be asked to have them independently verified by an independent third party.
We’ve recently developed a process so we can check over you GHG calculations, policies, procedure and overall alignment with the standard.
As part of this, Carbonology can provide a verification report with all findings and opportunities for improvement, as a well as a verification statement to show you have had emission independently verified in alignment with ISO 14064.
For further information, David has prepared a quick guide for creating your PPN 06/21 Carbon Reduction Plan. Feel free to download it here.
Lastly, if you have an questions or would like to learn more about how Carbonology can help you, feel free to book a call in via David’s Calendly.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Sustainability has become one of the main focal points for businesses to address in the last few years, and for good reason! We’re already seeing the devastating effects of simply doing nothing in the form of more extreme weather, occurring much more frequently in areas not equip to handle it.
To encourage action from businesses, we’re seeing more public and private sector contracts include a tendering requirement to show your commitment to sustainability. One such example is the need for a PPN 06/21 Carbon Reduction Plan.
In this weeks’ episode David Algar, Principal Carbonologist at Carbonology, joins Mel to explain exactly what PPN 06/21 Carbon Reduction Plans are, what the requirements mean in practice and the consequences if a business does not meet the requirements.
You’ll learn
· What are PPN 06/21 Carbon Reduction Plans?
· What the requirements mean in practice
· Benefits to a business
· What if a business does not meet the requirements?
Resources
● Carbonology
● Book a call with David Algar
● A quick Guide to creating your PPN 06/21 Carbon Reduction Plan
In this episode, we talk about:
[00:42] Episode Summary - We’re talking about PPN 06/21 Carbon Reduction Plans because there is a government requirement to submit one. This episode will cover the what and why, in part 2 we’ll go into more detail about how to create a Carbon Reduction Plan.
[02:10] What is a PPN 06/21 Carbon Reduction Plan? Procurement Policy Note 06/21 was introduced back in June 2021, hence the 06/21 part, and is a tendering requirement for companies looking to win contracts in the public sector that links to the Government’s Net Zero target.
[02:28] What is the UK government’s Net Zero target? The ‘net zero target’ refers to a government commitment to ensure the UK reduces its emissions by 100% from 1990 levels by 2050.
[02:55] Who does PPN apply to?: Public sector, so any businesses that works with education, local authorities, housing, infrastructure, defence, transit, and of course, the NHS who have set a goal of Net Zero by 2040.
Officially this is for contracts that are valued at £5M or more, but in April 2024 the NHS will be requesting a Carbon Reduction Plan for all procurement.
Unofficially, this framework could be adopted by any business, so even if you don’t deal directly with the public sector, or are a subcontractor, your supply chain may soon be requesting a Carbon Reduction Plan!
[04:05] Why do you need a Carbon Reduction Plan? Although the Government’s targets and policies around Net Zero keep changing, the overall goal of PPN 06/21 is to encourage businesses to reach Net Zero before 2050, come up with a plan to do so, and implement emission reduction initiatives in the delivery of Government contracts.
[04:35] From a businesses perspective, what are the main benefits? There are 2 main benefits:
● It’s essential for some tendering, with as much as a 10% weighting based on your carbon management and social values. Put simply, if you don’t produce one when needed, you may fail the tender requirements and probably won’t make the sale.
● The second main benefit is that this isn’t just a piece of paper with a graph on it, it’s a great opportunity to investigate your business’ GHG emissions, and put a plan in place to reduce them. This also helps you show to stakeholders that you are actually committed to environmental protection and could identify some cost savings in your business after going through all the data.
● It’s also a great addition to any existing ISO 14001 or ISO 50001 Management Systems!
[06:10] What are the key requirements of PPN 06/21? – Firstly you’ll need to make a commitment to achieving net zero by 2050 at the latest. This includes annually calculating your emissions and updating the Carbon Reduction Plan.
Next you’ll need to report on a minimum set of GHG categories: 100% of your Scope 1 emissions, so direct emission from company vehicles, gas heating (so stuff you burn) and any fugitive emissions, which are leaks from HVAC systems for most businesses. 100% of your Scope 2 emissions which is electricity most of the time but can also refer to steam you import from an external source.
You’ll also need to report on 5 Scope 3 categories, these are your indirect emissions:
● Waste generated in operations
● Business travel in vehicles you don’t own, so staff cars, flights, trains, etc
● Commuting, so staff traveling to and from work, being careful not to double count business travel not already claimed under expenses
● And arguably the most complicated, upstream and downstream transportation, i.e. goods in, and goods out – physical transport of goods
[09:50] Are there any other categories covered by scope 3 that we should consider? – Generally, when we produce a CRP for our clients, we’ll look at a few extra Scope 3 categories such as water, homeworking, or purchased goods, so carbon reduction planning can extend to other elements of the business. In all cases you’ll need to report in tonnes of carbon dioxide equivalent, or tCO2e, as this accounts for the global warming potential of multiple GHGs.
[11:30] Are there any ISO standards that you can align the Carbon Reduction Plan to? Yes! At Carbonology, we use ISO 14064-1. This sets out a series requirements and guiding principles for the quantification and reporting of emissions. We wouldn’t necessarily have to go all the way to meeting every single requirement of the standard for your CRP but we always align with the key requirement of the standard when completing a CRP.
And if you’re lucky we’ll also cover your SECR figures!
[12:05] What is SECR? - Streamlined Energy and Carbon Reporting. This is mandatory reporting for businesses that are defined as large, so 250+ staff, and 36M turnover or 18M on the balance sheet.
[18:20] Asset Management - In 8.2 there is a consideration for Asset Management on your side. You should take care of any assets relating to the customer, where it’s stored and how it’s being looked after.
Standards such as ISO 27001 (Information Security) and ISO 55001 (Asset Management) already have some considerations for this.
[13:30] You’ve calculated your GHG results, what’s next?- Once you’ve calculated emission from the required sources, you’ll then need to look at the carbon reduction side of your Carbon Reduction Plan.
To start with you’ll need to outline existing initiatives you have, for instance, a sustainable travel policy, EV charging on site or a hybrid working model. It’s really important that these are relevant to the delivery of the contract you are trying to secure.
Next, you’ll need to outline planned future initiatives, but bear in mind, these will need to be realistic and relevant, so no wild claims about buying an EV fleet or going zero waste next week!
Once you’ve done all this you can then start looking at carbon reduction forecasts and what the numbers might look like between now and 2050 (or you chosen date.
[15:10] Additional PPN 06/21 tips from David: It will need to be signed off by a director, or equivalent, at your business to demonstrate leadership commitment. If the document isn’t signed off on you may fail on the tender.
You’ll need to publish it on your website, making it easy to access. Simple solution to this is just add a link at the bottom of your landing page.
And finally, you’ll need to make sure this is kept up to date each year. Reporting for emissions occurs on a 12 monthly basis. This can either be calendar year or your financial year, but ideally, you’ll want to publish the updated version as soon as you can after the year-end, certainly no longer than 6 months after.
[16:40] What does a Carbon Reduction Plan look like? - When the government announced this requirement, they also released a template document that businesses can complete. This is to simplify the process for businesses that are reporting on emission for the first time, but more importantly it standardises reporting. However, the template is a bit basic!
You’re not marked on presentation, but you can dress it up a little as long as you don’t deviate from the template too much. So feel free to put come company branding on it, make a cover page, change the font, etc.
You could also make a ‘full’ version of your CRP that includes further details on boundaries, methodologies and results, just make sure you only submit the template version to tenders.
[19:10] What happens if you don’t meet the requirements? - If you don’t meet the requirements without a valid reason, chances are you’ll fail the selection criteria. The selection criteria is a bit like the marking scheme associated with PPN. We can’t say for a fact that this means you’ll subsequently fail the tender, but it will certainly have a negative impact.
For further information, David has prepared a quick guide for creating your PPN 06/21 Carbon Reduction Plan. Feel free to download it from the link provided in the Resources section.
Lastly, if you have an questions or would like to learn more about how Carbonology can help you, feel free to book a call in via David’s Calendly.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Last week we gave you an introduction to ISO 20000, the Service Management Standard. As a refresher, the aim of the standard is to provide a framework for an effective end-to-end service management system which encompasses the entire lifecycle of a service from concept and design, through to service removal and end-of-life.
It’s best adopted by businesses who provide a service, particularly those that operate a help / service desk system.
For some this may still seem a bit nebulous, especially for those that may not be familiar with Service Management terminology. To help demystify this Standard, we’ve brought Steve back to take a deeper dive into what makes this Standard unique.
Join Steve Mason and Mel in this weeks’ episode as they explore Clauses 7 and 8 of ISO 20000 in more detail, and how certain aspects can apply to any business.
You’ll learn
● What is ISO 20000?
● What is included in Clause 8 of ISO 20000?
● How can ISO 20000 apply to any business?
Resources
● isologyhub
● ISO 20000
In this episode, we talk about:
[00:43] What is ISO 20000? Go back and listen to our previous episode to learn what ISO 20000 is, a brief overview of the key clauses and the benefits of adopting the Service Management Standard.
[02:00] A recap of the main requirements of the Standard:
· 4.0 Context of the Organisation
· 5.0 Leadership
· 6.0 Planning
· 7.0 Support of Service Management System
· 8.0 Operation of the Service Management System
· 9.0 Performance Evaluation
· 10.0 Improvement
Clauses 7 and 8 are where the main differences lie between this Standard and others. It includes requirements for aspects such as:
· Service Portfolio
· Relationship Agreements
· Supply and Demand
· Service Design and Transition
· Resolution and Fulfilment
[03:15] Similarities with other ISO Standards – Ultimately, this standard in terms of the structure, it looks like any other ISO standard, i.e. we've got context of the organisation, leadership, Planning, performance Evaluation and improvement. These will be familiar if you’ve worked with ISO 9001, ISO 14001 or ISO 27001.
[04:05] Clause 7 – Support of Service Management System: This is where we’re really looking at the competency awareness communications and documented information required by the standard. In 7.5 there is a really useful list of all the documented information that's required in the management system – one that we wish was included in every ISO Standard!
That required documented information doesn’t have to be in writing, it could be on computer or established system.
Another key aspect of Clause 7 is Knowledge – this is about ensuring all knowledge is documented and sharable and not just stuck in people’s heads. For Service Management, this may involve the creation of a customer portfolio where you can record any incidents that occur during a service call, and how you dealt with it ect.
Competence is also another major component – Make sure people are competent to do their job, i.e. they’ve been trained to do things properly and effectively.
[06:40] Different ways of knowledge sharing – Knowledge sharing doesn’t just have to be written down – it could be done via a recorded video. We use Loom a lot at Blackmores to get things across quickly.
There are also a number of service desk tools available that can help you put together process flow diagrams to make things easier to understand.
[08:15] Clause 8 – Operation of the Service Management System: Before you do any sort of service management, you need to plan it properly – otherwise, if you fail to plan, you’ll plan to fail.
First you need to understand what resources you have, what activities there are in the service management to deliver that service to the customer and ensure that they're coordinated.
A top tip from Steve: Separate resources into five groups: people, technology, information, finance and service partners.
[09:55] Planning your Service – Now you understand what you’re trying to deliver, it’s time to plan your service.
First you want to take a look at the flow of the service through the organisation. Which departments does it go into? Is there good connection between departments? Can you ensure that a customer’s order is going to stay the same through the whole process, you wouldn’t want possibilities for miscommunication to occur.
We’d recommend drawing up a flow diagram for this process – just so you can clearly see who is doing and communicating what at any stage.
[11:20] Getting Operations in order – once you understand what the process is, you need to begin to control and involve the interested parties within the life cycle of your process.
This isn’t just the customer; this also includes confirming what services you’re actually delivering – as you’ll be looking to improve these services as time goes on.
You also need to consider the whole service life cycle. This includes things like if a customer wants to move to a different service – how would you deal with that? Have you got a process in place to handle the return of customer assets if they disengage from your services?
[12:30] Service Level Agreements: It’s a good idea to establish Service Level Agreements and Delivery Level Agreements early on. This is so you typically know what you are going to be delivering to a customer and how quickly can you deliver it and ensure the whole process is sustainable as well.
This will also clarify key accountabilities for everyone involved with delivering a specific service.
Clearly defined services – Finally, it also provides a clearly defined service for Salespeople. This avoids the situation where they simply sell what they think sounds good but isn’t backed up by any resources to actually deliver the service they sold.
You need to have a clear strategy that sales can use and go out and sell – this may be referred to as a Service Catalogue.
[15:18] A Service Catalogue in action - In Blackmores case, our Service Catalogue is online on our website. We have all the ISO Standards we can assist with listed, in addition to a description of how we can help companies implement an applicable Management System.
You don’t have to have all your prices listed out at that stage, that can come later when you have a full view of the customer requirements and agreements are made.
[18:20] Asset Management - In 8.2 there is a consideration for Asset Management on your side. You should take care of any assets relating to the customer, where it’s stored and how it’s being looked after.
Standards such as ISO 27001 (Information Security) and ISO 55001 (Asset Management) already have some considerations for this.
[19:05] Configuration Management - Configuration management is understanding how the parts of the service fit, so you don't disassociate them from each other.
The Standard asks you to identify what's known as CIS, these are configuration items, and these are all the things that you need to deliver your service. We’ll dig more into this aspect in future content – so keep an eye out!
[20:40] A final top tip from Steve: Collaboration and communication that involves leadership. If you just devolve it down to parties doing the work and just get them to work in silo, it will not work for you. It's a collaborative standard – both inside and outside of the business.
[21:20] Resources available - We’ve got a number of ISO 20000 related resources available on the islogyhub – contact us to learn more!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Often seen as the poor cousin to ISO 9001, ISO 20000 Service Management largely gets ignored in favor of the more popular Quality Management Standard.
To be fair, it’s title may have done it a disservice in the past. Being known as the IT Service Management Standard prior to 2018, it was often perceived as only applicable to IT service providers, when in actuality it could be adopted by any business!
So, what is ISO 20000 exactly? The aim of the standard is to provide a framework for an effective end-to-end service management system which encompasses the entire lifecycle of a service from concept and design, through to service removal and end-of-life.
It’s best adopted by businesses who provide a service, particularly those that operate a help / service desk system.
In this weeks’ episode, Steve Mason joins Mel to discuss what ISO 20000 is, who can use and benefit from the Standard and how it fits in with other more widely adopted ISO Standards.
You’ll learn
● What is ISO 20000?
● Who is ISO 20000 designed for?
● What are the benefits of ISO 20000?
● A brief overview of the Standard
● How ISO 20000 integrates with other ISO Standards
Resources
● isologyhub
● ISO 20000
In this episode, we talk about:
[00:50] Why are we talking about this Standard? We’ve had a lot of interest in a few of our informative videos available on YouTube over the past year, with ISO 20000 content constantly ranking in our top 5 most watched videos every month.
[01:00] ISO 20000-1 was previously known as the ‘IT Service Management Standard’, but since it’s most recent update in 2018, it’s simply known as the ‘Service Management Standard’ now.
[03:10] Why is ISO 20000 one of Steve’s favourite Standards? – It takes some of the aspects of quality a step further and actually gives you much clearer detail on how you can improve your management systems. So, if you've got a Service Management System in any way, shape or form, this is the standard to go.
It's also one of the easiest standards to audit because there's some very simple questions to ask that can highlight some very obvious weaknesses. This can lead to significant improvement when compared to the likes of ISO 9001.
[04:05] What Is ISO 20000? – ISO20000-1:2018 is a Service Management standard which has evolved from the IT industry and the ITIL Framework for Service Management; but today it can be used in all types of Service Industries particularly where there is a need for a Help Desk / Service Desk system.
Some may ask, isn’t this what ISO 9001 can do? In short, no. ISO 9001 will give you a bare framework of how to create a Quality Management System, but it won't give you the fundamental details of how to improve that Service Management System, and that's where ISO 20000 comes in.
[05:39] Who is ISO 20000 applicable to? – Any business that provides a service, but more specific examples include: IT Service provider, call centres, gas / electricity providers, retail ect.
[07:15] A high level overview of ISO 20000 – This Standard follows the Standard structure that many other ISO Standards follow. The first 3 clauses are all informative, starting from clause 4 we have:
· 4.0 Context of the Organisation
· 5.0 Leadership
· 6.0 Planning
· 7.0 Support of Service Management System
· 8.0 Operation of the Service Management System
· 9.0 Performance Evaluation
· 10.0 Improvement
Clause 8.0 is where ISO 20000 fills in the gaps for other Standards, as it covers topics such as:
· Service Portfolio
· Relationship and Agreement
· Supply and Demand
· Service Design, Build and Transition
· Resolution
· Service Assurance
[08:20] Familiar to some – Those in Service Management may recognise some of those terms, but may not use that exact wording. For example ‘relationships and agreements’ may be more commonly known as Service Level Agreements and Operating Level Agreements – which can be a business critical area for some.
[10:45] What are the benefits of ISO 20000? - Improve the planning and introduction of services: This standard would help you understand what it is you need to do to introduce that new service, go through the planning, testing through a proper change management system and launch through a release and deployment management system.
SLA’s and OLA’s - Achieve Service Level Agreements (SLAs) and Operating Level Agreements (OLAs) will be achieved consistently month on month.
Reduce Stress - It will help to reduce employee stress as service request, incident and problem queues become manageable. Knowledge articles can be created to document incidents and solutions for future reference.
Improved quality of service through continual improvement gained from Incidents and Problem fixes resulting in both time and financial savings.
[12:30] ISO 20000 to the rescue - Steve recounts an experience he had at a company that had an outstanding issue ticket queue of 800. With the introduction of elements of ISO 20000, they we able to reduce this ludicrous amount down to 30!
[14:05] A top recommendation - We’d highly recommend that you consider doing a Gap Analysis against ISO 20000. Even if you have no plans to implement it, you can still benefit from the findings.
[14:40] Further resources - You can purchase the Standard directly from the ISO website.
We also have a number of short courses covering specific clauses in ISO 20000, available in the isologyhub.
[15:55] How does ISO 20000 fit in with other ISO Standards?- ISO20000-1:2018 has now been remodelled using the High Level Standard (HLS) framework so that clauses 4 to 7 and 9 to 10 can all be interconnected with only minor differences due to the nature of each standard.
Essentially, if you already have ISO9001:2015 or ISO27001:2013 most of the framework for ISO20000-1:2018 will have already been done; all that would be required is to address the service aspects in those six clause before tackling the main work in clause 8.
[18:20] Business Continuity - ISO 20000 specifies a section on ‘service continuity management’ which can neatly slot in with ISO 22301 – the Standard for Business Continuity. While ISO 22301 focuses on the bigger picture, the ISO 20000 element focuses on how a service can continue for a customer during an incident or accident occurring.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
One of the most crucial steps to gaining your ISO certification is the completion of a Stage 1 and Stage 2 assessment, conducted by an accredited Certification Body. A quick reminder - your certification doesn’t mean much if you haven’t received certification from an accredited Certification Body – so make sure you do your research!
Businesses going through their final Assessments to gain ISO certification may see any decisions made by Certification Body Assessors as infallible, however there’s still a very human aspect which can lead to some common pitfalls.
Last week we dived into the requirements of ISO 17021 – the Conformity Assessment Standard designed for Certification Bodies, and more specifically the requirements in relation to you as a client.
In this weeks’ episode, Steve Mason joins Mel once again to share some issues raised by Blackmores’ clients against Certification Bodies, and explains the related rules in ISO 17021 which Certification Bodies should abide by.
You’ll learn
● What is ISO 17021?
● Key issues raised by Blackmores’ clients in relation to Certification Bodies
● Related ISO 17021 requirements
Resources
● isologyhub
● ISO 17021
In this episode, we talk about:
[00:24] What is ISO 17021? It’s the Conformity Assessment Standard designed for Certification Bodies. In effect, it acts as a service level agreement. These are the rules that these certification bodies need to comply with if they are accredited by an accreditation body like UKAS. Listen to the previous episode to learn more.
[01:10] What are we focusing on in this episode? There have been some issues raised by some of our clients time and time again over the last 6 – 8 months. We want to break some of these issues down, and help listeners to understand what are the actual rules around these areas in relation to ISO 17021.
[01:40] Issue #1: Cancellations – Sometimes a cancellation is unavoidable, however there are still rules that any Certification Body needs to follow – most importantly they should notify the client.
Steve shares his experience with an Assessor who was due to show up on the 5th September 2023, and never turned up! it turned out that whilst the date was in the previous report, it had been removed from his diary, but it hadn't then been put into somebody else's diary, and because it hadn't been put into somebody else's diary, there was no flag to anybody to let the client know that the visits should take place. Now that visit had to be pushed back into January next year, which is the only time we can make it.
[02:50] Balancing Expectations – There's an expectation from certification bodies that clients should not cancel a month or less than a month before they visit. Steve recommends that should apply to certification bodies cancelling for clients too.
There are many considerations to Certification Body visits, including:- cost, scheduling the right people to be present, setting time aside for the audit ect.
[04:30] One-sided penalties – Penalties seem to be very one-sided. For example: if the client cancelled two or three weeks beforehand because they had personal circumstances which meant that they couldn't attend, they would be penalised and would have to pay in full for that visit. Yet the certification body can not show up on a day, and there's no compensation whatsoever.
[05:10] This is not the norm for Certification Bodies – A reminder that the issues were raising are not the norm for Certification Bodies – however we are seeing an increase of complaints raised by our clients. This may have been exacerbated due to the recent shortage of Assessors.
[05:50] Issue #2: Planning Audits - Another issue that's been cropping up is about planning audits - not just surveillance audits, but also stage 1 and stage 2 Assessments.
In regards to ISO 17021, Certification Bodies should be providing an Stage 1 Audit plan to the client to detail what will happen during the visit.
That plan is often not happening, or there's a generic plan that gets sent out by the certification body which bears no relevance to what the assessor ends up doing. So that's as useful as a chocolate teapot.
It should be sent a month ahead of the visit, not 2 -3 days before the visit takes place. Companies need time to organise the right people and Certification Bodies need to be considerate of that fact.
[07:35] Steve’s experience with a poor Audit plan from a Certification Body – Steve had an occasion where he had to write a plan on behalf of the Certification Body Assessor for the client as they’d neglected to even send one!
Steve used to be an Assessor, so is familiar with how these plans should be structured. The designated Assessor ended up using his plan – but this should not have been the case.
[07:58] Poor planning - There have been instances where the planning has been so poor that they send the wrong Assessor to a client site. We’ve had experiences where an ISO 27001 Audit was due to take place and the Assessor turned up expecting to Audit against ISO 9001.
[08:50] What should Certification Bodies be providing following a Stage 1 Assessment visit? - After your Stage 1, you should have another plan come out of that stage, after what’s known as the Programme Management Day. The reason for that is because the assessor sometimes needs to go away, look at what they've written up, and take into account what they've heard from the client, and put a reasonable plan in place.
The assessor should then sit down with the client to discuss the plan and what sites are going to be visited during the Stage 2 Assessment.
[09:30] Using the right language - Often we see plans come out with language in the plans that is alright for certification body, but the client has no idea what the assessor is going on about. Steve always used to sit down with his clients and say right, ‘what language do you want me to use?’ And then would use their language and would also put the clause from the related standard next to that and say ‘that's the bit I'm going to audit’. You're writing the plan for the customer, not for yourself.
It also acts as assurance for a potential replacement Assessor if the first Assessor is off sick and can’t make the next visit.
[11:33] What does ISO 17021 say? - In clause 9, ISO 17021 states that: the certification should ensure that the audit plan is established prior to each audit identified in the audit programme to provide the basis for agreement regarding the conduct and scheduling of the audit activities.
If they fail to put a plan in place, they are not meeting a requirement.
ISO 17021 also says that if you've got an organisation that's got different sites, then the plan should take into account the different sites and whether the visit is going to be on site off site – as remote audits have become more common place post-pandemic.
[12:35] Steve’s experience with a flimsy plan provided by a Certification Body - ‘I came across an audit plan which was just a list of all the requirements a standard. It was across 5 days. But there was no indication as to which day those requirements were going to be assessed. There's no indication as to how long each of those requirements are going to be assessed? So what could the client do to prepare for that?’
Steve did say to client send it back and get a proper plan, but they have absolutely no joy with the certification body.
[13:50] Issue #3: Unnecessary charges - Mel recounts a recent incident where a Certification Body cancelled 2 site visits, and due to the long delay between rebooking, the client had moved office. However, they only relocated a few doors down in one instance and across the road in another. The client then received a quote for an extension to scope – amounting to 3 extra days due to the address change!
Mel checked ISO 17021 and confirmed that an extension to scope is only applicable if changing what you're doing or you're adding a new location to the scope – however if you’re using the exact same scope and are only moving your business from one location to the next – it is not an extension to scope, it’s just a change of address.
Steve recounts a similar instance where a client was charged £160 for the address to be changed on their certificate! Which is a ridiculous and unnecessary admin fee which only serves to upset the client.
[17:50] Issue #4: No disclosure of the appeals process - if client a company isn't happy with their nonconformities, there is an appeals process, which is a requirement of ISO 17021.
Steve highlights an incident where an Assessor told a client ‘don't bother with the appeals process because it'll only delay the delivery your certificate’ – Which was highly unprofessional of that particular Assessor to say.
The appeals process there is there to help clients if they disagree with their assessor, and allow them to go to a sort of third party that's within the certification body and say, look, I don't agree with this. Can you explain why it's a nonconformity?
Top tip: If you do get a non-conformity that you’re confused about – Ask the Assessor to show you where in the standard it requires you to do that. If an assessor cannot show you that, then it is not a nonconformity.
[20:30] The complaints process - The complaints process really is not about appealing against a nonconformity, but complaining against perhaps not getting your plans in your reports and all that sort of thing.
[21:20] These issues are not the norm – don’t be put off ISO certification! - While we have noticed an increase in complaints in the last year, we also want to highlight that these have mostly been for 1 or 2 select Certification Bodies.
On the whole, Certification Bodies provide a wonderful service to their clients. We just wanted to bring their code of practice to your attention, that you can check ISO 17021 to verify that the Certification Body is being fair to you and fulfilling their own requirements in relation to customer service.
[23:35] Receiving reports - Lastly a reminder that reports to clients following visits should not take months to get to them. Clients should expect reports from Assessors in 2 – 3 days – not months!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
If you are going for certification, or currently manage a certified ISO Management System, then you should also be aware of ISO 17021 ahead of any Assessments or Surveillance audits conducted by an accredited Certification Body.
ISO 17021 sets out requirements for bodies providing audit and certification of management systems. It ensures that Certification Bodies provide a reliable assessment of compliance with the applicable requirements, carried out by a competent impartial audit team, to achieve a consistent result for all clients.
So, why should you be aware of this Standard in particular? ISO 17021 also establishes what you as a client should expect from your Certification Body.
Steve Mason, Managing Consultant at Blackmores, joins Mel to discuss what ISO 17021 is, why you should be aware of it and the requirements related to expected service delivery from Certification Bodies.
You’ll learn
● What is ISO 17021
● The difference between accredited and non-accredited certification bodies
● A brief overview of the Standard and client related requirements
Resources
● isologyhub
● International Accreditation Forum
● ISO 17021
In this episode, we talk about:
[01:40] Why are we talking about ISO 17021 now? In our internal Team Meetings, Certification Bodies are an established talking point. Highlighting the good and the bad, but in recent months it’s been more on the negative side. Steve had highlighted ISO 17021 as the Standard to look at in regard to expected service delivery requirements from Certification Bodies – so here we are!
[03:00] What is ISO 17021? The reason for the standard is that it ensures that all certification bodies are delivering the same level of service to all customers. Certification Bodies don’t need to be certified to other standards such as ISO 9001, as ISO 17021 was specifically designed for the purpose of delivering certifications.
It’s also the standard where you can find out what’s expected of Certification Bodies – like a Terms and Conditions or service level agreement.
[05:00] The difference between accredited and non-accredited Certification Bodies - Go back and watch episode 19 to learn more.
[06:10] Why is it important that the Certification Body is accredited? – Accreditation proves that the Certification Body is being checked by another body. Accreditation is also recognised worldwide – it’s trusted as a gold standard of performance. There are many different accreditation bodies around the world, here in the UK it’s UKAS, but there are others such as ANAB in the US. Check out the International Accreditation Forum website to confirm the accreditation body for your country.
[08:10] Ultimately, a Certification Body can’t offer accredited certification services unless they've actually been assessed by the applicable accreditation body to ISO 17021, and they need to do that on an ongoing basis like any other certification.
They also may not be accredited to deliver every standard they offer – so make sure you verify with the certification body that they are in fact accredited to ISO 9001, ISO 27001 ect.
[09:15] A brief overview of what’s included in ISO 17021 – A lot of the clauses before this are really about the management of certification body, but when it comes to clause 9, this is where the customer becomes a lot more involved in the requirements. It covers topics such as planning audits, conducting audits, certification decision making, maintaining certification, the appeals process, the complaints process and then keeping client records.
Clause 9 in particular is where you, as a client, should focus.
[11:00] What core principles are described in ISO 17021? - Impartiality, competence, responsibility, openness, confidentiality, responsiveness to complaints, risk based approach and legal responsibilities.
[12:20] What personal behaviors should you expect from your assessor? – In Steve’s experience, he’s seen more and more assessors not living up to the requirements of ISO 17021. This could be for a number of reasons, i.e. they could have an uncooperative client, they may not have had adequate training, perhaps there’s a break down between clients and client managers. Either way, these are a few of the qualities that Assessors should embody: ethical, fair, truthful, sincere, honest, discrete and open-minded.
[14:00] A lack of open mindedness - Steve had encountered an Assessor that stated ‘This must be wrong because I've never seen it done that way’ – which is not open minded in the least. This resulted in a non-conformity which should have never been raised.
ISO 17021, clause 9.4.5 states that any non-conformity raised shall be recorded against a specific requirement in the Standard being audited. Assessors need to take heed not to assess to their preference.
[15:15] Top Tip - If you get asked a question, then give an answer and they raise that as a non-conformity that you’re unsure as to why it’s being raised - it's always worth asking the Assessor to show you where in the standard they're raising the non-conformity against.
It's a case of clarifying the question and verifying what they’re raising a non-conformity against, and if there’s a justification for it. If there is, then great, they’re doing a great job! If not, it may be the Assessor’s personal bias, and there’s a chance you can get that non-conformity down to an opportunity for improvement.
[17:05] Other expected traits for Assessors to be aware of - Collaborative: It should be a partnership between the client and Assessor – they want what’s best for you.
Tenacious: This can sometimes be taken too far. For example, if your Assessor it still assessing past 5pm, tell them to go home. If they need more time, then it's up to the certification body to work that one out.
Other basic traits include: Observational, being perceptive and versatile.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
One of the most common reasons why businesses look to achieve certification is because a client or prospective client is demanding it. Questions are often asked in tenders such as do you have an Environmental policy? A complaints procedure? Data privacy controls? And of course do you have ISO 9001 (the quality standard)? Or ISO 14001 (the Environmental Management Standard)?
These answers accrue points and when bidding for a contract, the more points you can get the better chance you have of winning that lucrative contract, which could bring your company 1 – 3 years of high value revenue and profit.
So why are ISO Standards, Policies and Procedures mentioned in tenders?
And why should you look to align your business with quality, environmental and risk standards?
Join Mel on today’s episode as she shares 10 reasons why ISO Standards can help businesses win tenders.
You’ll learn
● Why are ISO Standards mentioned in Tenders?
● The difference between accredited and non-accredited certification bodies
● 10 Reasons why ISO Standards can help to win Tenders
Resources
● isologyhub
In this episode, we talk about:
[00:55] Based on 17 years of running four businesses relating to ISO standards, Mel estimates that 8 out of 10 businesses that look to achieve certification is because they want to win or retain a client contract.
[01:35] If you've got your Policies, Procedures, Standards and systems in place, it does make the whole process of bidding for tenders a lot easier, in addition to giving you a greater chance of winning those tenders.
[02:30] Reason #1: Proof that you have achieved the highest standards - Put yourself in your clients’ shoes – would you rather work with a company that pays lip service to protecting your valuable data? Or that they have over 100 controls to manage your data in the security? (Such as in the Standard for Information Security - ISO 27001)
One of the main reasons your clients will be looking for your company to be certified to an ISO as because it demonstrates that you operate your business to the highest global standards.
[04:00] Reason #2: Demonstrates independent 3rd party certification – This means that its not just you that claims that your business has good health and safety controls in place – an ISO certified business has to prove that its compliant year after year. Being certified is proof that you practice what you preach and that there is evidence to back this up.
[04:50] Be careful – know the difference between accredited and non-accredited certification – Go back and watch episode 19 to learn more.
[05:45] Reason #3: Recognised across the globe – Passport to trade – When organisations are looking to expand internationally, ISO certification is often a requirement to deliver services or provide products overseas. This is because ISO Standards are recognised globally as they way businesses should be run.
ISO’s aren’t just passports to trade internationally – they are also passports to trade in certain sectors. For example in Construction – you aren’t going to get very far in tenders if you don’t have ISO 9001 (Quality), ISO 14001 (Environment) and ISO 45001 (Health and Safety).
[08:40] Reason #4 – USP - Many organisations adopt ISO Standards to give them a competitive edge and score more points in a tender. For example, let’s say you’re bidding for a public sector contract worth £2 million, and they are very keen on their suppliers verifying their carbon footprint and being carbon neutral. It would give you a massive competitive edge if you could prove this and demonstrate evidence, once such way would be to get certified to ISO 14064 (Carbon Verification) and PAS 2060 (Carbon Neutrality). If you’d like to learn more about those Standards, go back and listen to episodes 72 and 73.
Note: PAS 2060 is set to become an ISO in the near future! Keep an eye out for news concerning ISO 14068…
[11:55] Reason #5: Risk Management - ISO Standards help to significantly reduce risk. This is why certified business have lower insurance costs and win more business. All businesses need effective risk management – even Law Firms. Over the last few years, we’ve seen more and more law firms achieve certification to ISO 27001 (Info Sec), ISO 27701 (GDPR) and business continuity (ISO 22301).
[13:20] Reason #6: Meeting customer requirements - The one thing that a client outsourcing services expects as a minimum is that you actually meet their needs. It’s not much to ask is it? Though, you would be surprised how many businesses operate without processes!
ISO Standards help to define what your processes, and provide a blueprint for how you run your business – therefore providing clients with a standardised approach that is repeatable and guarantees high standards of quality products and services time and time again.
[14:30] Reason #7: Reduce ambiguity - ISO Standards set out very clear specification – Many of them require certain documents that non-certified businesses often don’t have.
One such example is a process for dealing with problems, otherwise known as ‘Non-conformities’ in the ISO world. Businesses shouldn’t just bury their heads in the sand, they should have a system in place to log issues / customer complaints, rectify the issue and put preventative measures in place to prevent a recurrence.
[16:05] Reason #8: Industry specific standards - Certain ISO Standards prove that you meet the highest quality best practice standards for your industry.
Not every industry has specific ISO Standards – but an example of this may be an events company that wants to stand out by being sustainable. ISO 20121 (Sustainable Event Management) would give them a huge advantage over competitors.
[17:10] Reason #9: Competent personnel with clear accountability and responsibility - ISO Standards do stipulate that you have people that actually know what they're talking about, in some cases, for businesses that don't have ISO’s, this can be a bit of a steep learning curve.
If you’re looking to gain some basic competency in ISO Standards – check out our online learning platform, the isologyhub.
[18:10] Reason #10: Gives assurance to clients for a period of 3 years – ISO Standards are continuously maintained over a 3-year cycle. It’s not a case of passing an assessment then waving goodbye to the systems you’ve got in place to run the business.
You have to prove continued compliance through annual surveillance audits, and recertify after 3 years.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Quality and environmental management are top priorities for many organisations, backed up by the increasing number of ISO 9001 and ISO 14001 certificates being issued every year.
Aside from being a popular requirement on tenders, ISO 9001 and ISO 14001 provide a robust framework for businesses to ensure they follow Best Practice, enhance their businesses performance and put measures in place to reduce their environmental impact. We often see these two Standards being implemented in tandem, as is the case with todays’ guest, Asynt.
Asynt is a global provider of world leading technologies and services for scientific research, developed by chemists for chemists, their laboratory equipment responds to the real demands of industry and academia across the globe.
Today we welcome Siobhan Ellwood, Sales Support Manager at Asynt, as she explains their journey towards ISO 9001 Implementation, and how they embedded ISO 14001 along the way using our online learning platform – the isologyhub.
You’ll learn
● Who are Asynt?
● How did Siobhan get involved with ISO Standards?
● What was Asynt’s main driver for obtaining ISO 9001 and ISO 14001?
● What did Asynt learn while implementing ISO 9001 and ISO 14001?
● Siobhan’s experience using the isologyhub to implement ISO 14001
Resources
● Asynt
● ISO 9001
● ISO 14001
● isologyhub
In this episode, we talk about:
[00:55] An Introduction to Asynt - A global provider of world leading technologies and services for scientific research. Based just outside of Ely in Cambridgeshire, they just celebrated 20 years in business!
[02:10] Siobhan’s role and how she got involved with ISO Standards: Siobhan is the Sales Support Manager for Asynt, she assist with raising quotations, managing sales orders and providing support for the warehouse.
In January 2023, 3 members of the Asynt Team were tasked with researching and obtaining ISO 9001, with a view to adopt ISO 14001 later on. Siobhan had experience working with Quality Standards thanks to her previous work in aviation and automotive companies, and had even previously implemented the Standard. Naturally, she was a perfect fit to head the ISO 9001 and ISO 14001 project at Asynt.
[05:40] What did Siobhan enjoy most about Implementing ISO Standards? Initially, realising that she had a lot more knowledge about ISO than she gave herself credit for. Also, making use of the 5 Why’s to identify where something has gone wrong, implement a solution and preventing it from recurring.
[06:40] What were the main drivers behind Implementing ISO 9001 and ISO 14001?: For ISO 9001 – Top Management saw the need to have proper procedures in place, to ensure that everything was written down and could be communicated and conducted by other staff if needed. Ultimately, they wanted a cohesive system where everything, included roles and responsibilities, were documented and managed.
For ISO 14001 – Customers often ask for ISO 9001, but ISO 14001 was also starting to pop up in conversation more. Top Management at Asynt wanted to get ahead of the curve and make the move towards becoming more environmentally friendly. It was also seen as a stepping stone towards being in a position to calculate their Carbon Footprint and make further improvements.
[09:50] The ISO 14001 Coaching Programme – Asynt were one of the first companies to go through our ISO Coaching Programme, hosted via the isologyhub. This programme combined the DIY digital platform with group coaching sessions, allowing all participants to work collaboratively towards creating their own Environmental Management System.
[10:20] Siobhan’s experience with the ISO 14001 Coaching Programme: Overall Siobhan had a very positive experience in the coaching programme, a few highlights include:
Sharing ideas: Other participants come from a wide range of industries, and each brought their own unique ideas to the table, encouraging others to look at things from many different points of view.
Support: If another participant is struggling with something, there is a group of people to support and provide possible solutions. Siobhan gave an example of where she provided an Excel guide to another member who was looking for a solution.
Resources: Siobhan had previous experience with implementing ISO Standards, so she was aware of what type of documentation was required. She found the resources on the hub useful to refer to outside of coaching sessions, to enhance Asynt’s own ISO Standard Implementation.
[12:20] What was the biggest Gap identified during Asynt’s Gap Analysis? Mostly it was the lack of documentation, which required a lot of work to get everything written down in cohesive processes and procedures.
For ISO 14001, Asynt are fortunate enough to own the buildings that they operate in. So, gathering the initial information required where potential energy and environmental improvements could be made was fairly easy.
[15:00] What differences did Asynt see after addressing the identified gaps? For ISO 14001 – Some elements were already in place (recycling waste ect), but weren’t being monitored in any meaningful way. Now Siobhan has got processes in place to ensure the recycling is being separated correctly and weighed so they can properly gauge their impact.
For ISO 9001 – It was the introduction of the 5 Why’s, which Asynt have used to great effect to identify problems and implement solutions. An example of this can be found in their warehouse, lanes and shelves weren’t labelled, causing confusion. It was a quick fix that could have been implemented years ago, but the 5 Why’s forced a much needed change.
[18:00] What did Siobhan learn from the experience of Implementing ISO 9001 and ISO 14001? Integrating a Management System can save on a lot of paperwork! Initially the plan was to have just an ISO 9001 System, with ISO 14001 implemented at a later date. Going through the process of Implementing them as the same time highlighted how much easier it would be to combine them, thanks in part to how many elements overlap between the two.
It also makes the system a lot easier to interact with, having everything in one place rather than spread between two separate systems means staff don’t have to waste time digging for policies and Procedures.
[20:00] Certification plans: Asynt are well on their way towards ISO 9001 and ISO 14001 certification with their Stage 1 in October and Stage 2 in November 2023. With just under 2 months before the Stage 1, Siobhan plans to continue working through some opportunities for Improvement, raised by Blackmores in some recent Internal Audits.
[21:41] Siobhan’s top tip: Trust in the process and make sure that you have the right person in your business to lead the ISO project.
Also being open to change, being honest with yourself about where the gaps are and trying to get those closed but also manage expectations within the business.
[23:50] Siobhan’s book recommendation: Salt path by Raynor Winn.
[26:05] Siobhan’s favorite quote: “Personal growth is not a matter of learning new information, but unlearning old limits” – Alan Cohen
If you’d like to learn more about Asynt check out their website!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The UK events industry accounts for 35% of the UK visitor economy and is estimated to be worth £42 billion, yet it is still incredibly wasteful, with 68% of waste going directly to landfill.
Haymarket Media Group is a global media data and information company, who offer a wide range of digital print, tech and live event services. Haymarket UK had been certified to ISO 14001 (Environmental Management) and ISO 50001 (Energy Management) for a few years prior to 2019, covering most aspects of their business from a sustainability point of view.
However, their live events still had many sustainability opportunities that were not being taken into consideration by their existing certifications. So, in early 2022 they embarked on their journey to gain ISO 20121 (Sustainable Event Management) certification.
Today, Gary Charlton and Natalie Harris from Haymarket join Mel to discuss exactly why they added ISO 20121 to their portfolio, the challenges faced with Implementing the Standard, and the benefits gained from certification.
You’ll learn
● Who are Haymarket?
● What is ISO 20121 Sustainable Event Management?
● Why did Haymarket choose to Implement ISO 20121?
● What challenges did they face?
● What are the benefits of ISO 20121?
Resources
● Haymarket Media
● ISO 20121
● isologyhub
In this episode, we talk about:
[00:50] An Introduction to Haymarket Media Group - A global media data and information company, with offices in the UK, US, Germany, India and Asia. They produce live events (including award ceremonies, conferences and exhibitions), digital print, education data and tech services.
[02:25] Gary Charlton is the Head of Procurement for the UK - Part of his role includes supporting the Haymarket approach towards sustainability, to ensure their products and services are as environmentally and socially sustainable as possible.
[02:45] Natalie Harris is the Procurement Executive at Haymarket – A lot of her role revolves around live events in addition to purchasing our products and services. Additionally, she advises the wider team on buying legally, sustainably and ethically. Both Natalie and Gary form a team, and were the main driving force behind the creation of their Sustainable Event Management System.
[03:40] What is ISO 20121?: ISO 20121 was launched for, and named after, the 2012 Olympics, making it the worlds first sustainable Olympics! The Standard provides a framework for managing events sustainably, that includes having the policies, procedures, registers and records to demonstrate that the events are being run in a sustainable manner. Being certified indicates that a company is not just paying lip service to sustainability, it's actually practicing what they preach. If you’d like to learn more about ISO 20121, go back and listen to episode 38.
[05:30] What was the main driver behind Haymarket achieving ISO 20121?: Haymarket first contacted Blackmores about assisting with ISO 20121 Implementation in 2019. At the time, they were already certified to ISO 14001 and ISO 50001, so they understood the benefits that came with ISO certifications - including the framework to start making better decisions and accurately measure what you're doing.
Their head of facilities had started the process of evaluating other areas they could improve with ISO Standards, particularly around sustainability. Live events are a large service offering for Haymarket, which has a significant environmental footprint, so a case was put forward for the benefits if reducing that impact with the help of ISO 20121. The team running their live events were very positive about the potential benefits presented, and the go ahead was given.
[07:20] Sustainability is central to how Haymarket wants to operate – Implementing ISO 20121 would ensure that there was more standardisation across their processes. This would introduce some uniformity that could apply to all types of events, which was very important to the Live event lead - Donna Murphy.
Natalie was in the right place at the right time, already in the position of working in collaboration with Haymarket’s Live events team on sustainable procurement, ensuring that due diligence was followed with suppliers and their accreditations. So, it was a no-brainer getting her on board with the ISO 20121 project!
[09:30] How long did it take to implement ISO 20121?: Haymarket engaged in Blackmores services in February 2022 and were accredited by July 2023. In total, it took 18 months for the planning, creation and development ahead of the assessment.
They ensured the system was refined to ensure it worked efficiently, encouraging continual improvement and a harmonious approach for the whole business.
[11:15] Above and beyond: Haymarket received a lot of praise from their Assessor – highlighting their thoroughness, including the involvement of top management and many others within the organisation in the creation of the Management System. Also for ensuring that the system would be applicable for the 4 main types of events that Haymarket runs.
[12:00] ISO 20121 requires an audit to be conducted during a live event – So Haymarket had a lot to consider when selecting the event to be audited.
[13:30] Haymarket’s key insights on Implementing ISO 20121: #1: The Gap Analysis was an integral part of the process – by highlighting the gaps you can clearly see where improvements can be made. While they may have been a bit crestfallen and daunted by the gaps presented, they came out if knowing they already had around 27% of a Sustainable Event Management system already in place – partly due to their existing certifications.
This soon bumped up to 59% at the half-way checkpoint! This assured them that ISO 20121 was within reach, and simply required at bit of time and effort to achieve.
#2 Having leadership involvement and backing – They were quick to involve their live event lead, Donna Murphy, in key decision making and with the roll-out of the Management System. She was instrumental in ensuring the Standard was in place and being followed.
[18:45] What were some of the gap identified and how did Haymarket bridge them? Required documentation – Many ISO standards have required documentation. A lot of times companies do have a lot of it place, but it’s simply just not formalised. Natalie highlights that this was the case with a Risk Register. It’s not a universal company need to have, but as part of the Procurement Team it’s simply a part of who they are and what they do.
For live events, they need to do the appropriate health and safety checks, but it wasn’t formalised in any way. Thankfully their facilities and environment specialist, who assisted with the existing ISO 14001 and ISO 50001 certifications, was on hand to help with the creation of risk procedures based on procedures from the existing Management System.
With this collaborative approach, using elements from the exiting Management System, they created 31 brand new documents consisting of Procedures, Registers, Log and Records that are continuously used, monitored and updated.
This new documentation, while a lot of work to create, ultimately helps Haymarket track, measure and set parameter’s for continuous Improvement. It ensured they have a really visual system, with a clear view of what needs to be done to run sustainable events.
[23:00] What difference has Implementing ISO 20121 made?: There was a big amount of short-time work for a long term gain. It’s not simply a stack of useless documents sitting in a corner, it’s a living, breathing system that is injected into the business.
The Management system is of benefit to everyone, including those new to Haymarket’s team as it provides a structured and standardised approach to sustainable event delivery. It’s provided knowledge and helped to develop new skills that will stick with all those that interact with the Management system, whether they stay with Haymarket or move elsewhere.
Ultimately, it’s all about ensuring they are doing the right thing for the planet. By creating more sustainable events, they are reducing their impact as a whole.
[26:00] What is the main achievement from being certified to ISO 20121?: Morale and confidence that they can say they really do practice what they preach. They could hold a mirror up and say, right, we've created this system and we're confident in it – with internal audits conducted by third-parities to confirm they’re on the right track with their intended goals.
Certification is not the end goal. You have annual Surveillance Audits to check-in, so the system must be a long-term feature in your business, and it must drive continual improvement.
[27:50] What top tip would Gary and Natalie give for ISO 20121 Implementation? Gary: Make sure you’re resolute in your reasoning for Implementing the standard and the implications of doing so. Also, enlist the help of someone with Implementation experience!
Natalie: Don’t underestimate the amount of work required. Select someone in-house to manage the project and when / if you can, use external resources such as a consultant to assist. They can also provide unbias, reflective feedback to ensure you’re on the right track.
[30:10] What’s a favorite quote? “The greatest threat to our planet is the belief that someone else will save it” – Robert Swan
If you’d like to learn more about Haymarket check out their website!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Energy Management can be a tricky topic to approach depending on your industry. There are a lot of factors that need to be considered to ensure that you are accurately monitoring and measuring your energy consumption.
Thankfully ISO 50001, the Standard for Energy Management, does provide a lot of useful guidance to help you get started. As a reminder, ISO 50001 can help your business to continually improve its energy performance, energy efficiency, energy use and energy consumption. Building an energy management system (EMS) based on the requirements of ISO 50001 will ultimately help you to understand, monitor and measure your use of energy.
However, even with the guidance, we often see a few common mistakes companies make while managing their EMS. Today Darren Morrow, Senior Isologist here at Blackmores, joins us to share his top 5 mistakes to avoid while managing an EMS.
You’ll learn
● What is ISO 50001?
● 5 mistakes to avoid while managing an Energy Management System
● How can you avoid these mistakes?
Resources
● isologyhub
● ISO 50001
In this episode, we talk about:
[00:30] What is ISO 50001? ISO 50001 is all about continually improving energy performance, energy efficiency, energy use and energy consumption. By Implementing an energy management system, you will be able to fully understand and monitor and measure your use of energy. Like most other ISO’s, continual improvement is at the heart of ISO 50001, and It’s also based on the Annex SL format. So, it shares some similarities with Standards such as ISO 9001 and ISO 14001. If you’ve got ISO 14001, you’re already half-way there!
[01:14] We have a more detailed walkthrough of ISO 50001 Implementation available in our steps to success podcast series, which are episodes: 84, 85 and 88
[02:00] Mistake 1 – Lack of commitment from top management: This can be one of the biggest issues and can cause the most damage in relation to any management system.
A lack of support from top management often leads to:-
· A loss of motivation for improvement
· A lack of financial support and resources – The EMS should be considered in budgets so you can account for any additional maintenance that needs to be done to ensure equipment is running optimally, or possibly investing in newer technology that is designed to be more efficient.
· Lack of alignment of the EMS and organisational goals and objectives – Everyone in the business should be aware of the organisation’s goals, if energy management is included as part of those goals, then they are more likely to be fulfilled.
Having a commitment from top management ensures that EMS is part of the business and not just a bolt on.
[03:25] Mistake 2 – Built by one person or department: If one person is deemed ultimately responsible, even if supported by top management, overall commitment throughout the business can be difficult, sometimes with comments such as 'that’s Bob's job'.
With one person or department, there can be the lack of authority to make decisions, and inevitably they can become siloed from the rest of the business - not hearing about improvement opportunities, not being involved in internal projects, etc.
Ensure that, even in a smaller businesses where one person may form the 'Energy Team', that everyone is able to contribute.
[04:20] Mistake 3 – Rushed Implementation of the Energy Management System: This can lead to confusion as to who is responsible and what responsibilities are shared. It can also lead to failures to record opportunities for improvement, or for monitoring and managing any deviations in energy consumption that may occur and require investigation.
There is also the risk of a lack of awareness amongst staff if you’ve not taken the time to communicate roles and responsibilities in relation to the EMS.
[05:30] Mistake 4 – Manual controls that can be overridden by staff: A lot of what you monitor and measure may be automated, but there will always be elements where there is a potential for human error. So ideally, where possible during energy reviews or audits, consider those elements that humans have direct impact for the control and influence of energy.
Typical examples include:
· Heating and cooling - Problems and excessive energy use can be caused through individuals changing temperatures resulting in equipment working harder and on many occasions working against each other.
· Lighting - Many companies now have sensor controlled lighting, this ensures lights are only switched on when required. Manual lighting controls typically have resulted in lights being switched on and left on in rooms that are not occupied, example being meeting rooms.
[06:50] Mistake 5 – Data collection and monitoring: Data collection is crucial in supporting decision making and also to be able to demonstrate improvement. Common pitfalls in this category include:
· Lack of attention to monitoring and measurement results / trends – there is a likelihood that data will not be collected properly, recorded incorrectly, resulting in data that is only used to populate a spreadsheet or software based database, and does not provide any valuable information.
Results may not be analyzed at appropriate times to identify any trends or issues / deviations that may arise, potentially leading to inefficiencies in equipment operations, and ultimately increased costs
· Poor data collection and record keeping and general housekeeping - Data if not collected periodically, covering determined periods, will result in being unable to compare consumption on a like-for-like basis. This means you will only be recording usage, with significantly reduced means to identify opportunities for improvement and / or causes for deviations.
· Relying on energy bills (estimated and not reading meters) – This should be a last resort for data collection. This will not provide accurate information to base decisions on, inevitably bills will show an estimated consumption and cost, followed by a 'reading' sometime during the year, resulting in an amendment or adjustment being made - primarily cost.
This has a significant impact the data collected, along with any possibility of accurately identifying improvements and / or deviations that could impact the business
[09:40] We’re offering a Buy 1 Get 1 Free offer on isologyhub memberships until the 31st October 2023! Contact us to book a demo.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
There are a lot of tedious tasks that we put off, or would rather just not do! Often, these types of tasks don’t take too long, but can cause delays if not completed. If you find yourself battling with this, it may be time to ask:
Where could you save 10 minutes a day?
That’s the exact question Lorna Leonard, Managing Director of Leonard Business Services, asked her team at the start of 2023. Focusing on tasks that were being put off for various reasons, Lorna found a potential time saving of 52 hours a month!
Today Lorna joins us to share her story of how saving just 10 minutes a day can potentially lead to 8 days’ worth of time saved, in addition to the pitfalls and solutions she found along the way.
You’ll learn
● Who are Leonard Business Services
● Why did the 10 minute initiative start?
● The power of saving 10 minutes a day
● What challenges did they face?
Resources
● Leonard Business Services
● Lorna Leonard’s LinkedIn
● ISO 9001
● isologyhub
In this episode, we talk about:
[01:25] An Introduction to Lorna Leonard and Leonard Business Services – a virtual finance department who are certified to ISO 9001. Lorna also joined us on a previous episode, Chaos to Calm, to talk about their experience working during the COVID pandemic.
[03:25] The challenge: Lorna started off with only 1 other member of staff, over the years they’ve grown to 7, with an increasing number of associates. With the organisation growing, Lorna was unable to be as hands on as she was before, so some things started to slip through the cracks. She wanted to ensure that was nipped in the bud early on.
The nature of her business needs very specific qualities in individuals, ones that are hard to come by. So, she was seeking to save as much wasted time with her current team as possible.
[04:50] Nothing is ever down to human error, it always comes down to a process – Some words of wisdom from Rachel Churchman, a Blackmores Managing Consultant who works with Lorna with on-going support. Processes change, they need regular review and updates to ensure they work well for you. Lorna found that a number of their processes created bubbles of inefficiency, which resulted in various 10-15 minute tasks that others found frustrating to complete.
[05:50] Saving 10 minutes a day: As a result of the process review, Lorna decided to focus on just saving 10 minutes a day – taking baby steps to tackle a bigger problem. She asked all of her staff to think of any tasks they found frustrating, and added them to a log. She kept that log going until May, to capture a snapshot of the issues before tackling them. This is just so she could measure the results more accurately later on.
[08:15] What tasks did Lorna’s staff highlight as frustrating?: A lot of problems were a result of software systems not talking to each other, meaning a lot of basic merging / collating of data had to be done manually between 2 systems.
[09:25] How they calculated the potential time-savings: Using the log, they estimated the time taken for each task, including consideration for which other members of staff may be affected by the same issues. At the end of the May, they found that there was a potential time-saving of 54 hours, which amounts to a full 8 days of work!
[11:25] Taking principles of ISO 9001 to heart: Lorna has truly embraced one of the key elements of ISO 9001 – addressing non-conformities through looking at your risks and weaknesses. By taking a step back and shining a spotlight on the negative, you can work towards making a positive change, and continually improving your way of working.
[13:30] How did Lorna’s team feel about the iniative: At the start, it was like pulling teeth. Many felt as if the wasted time was a reflection on their performance rather than a failure of processes and systems which weren’t working as efficiently as they could. Once improvements were starting to be implemented, the team could see just how valuable this exercise was. Lorna even received kudos (through an internal perk system) from the Team!
[16:45] A part of the exercise involved accepting some things that you can’t change.
[17:00] The tip of the iceberg: One issue can lead down a deeper path. For example, Lorna found that their expenses app wasn’t integrating with their accounting app – resulting in a manual exchange of data. By talking to app support, they were able to find a solution. 2 weeks later Lorna found that, that solution resulted in fixing a problem elsewhere that she wasn’t even aware of!
[18:30] For the things that can’t be changed, there is always a possibility to look at more long-term solutions that may require a roadmap to get to. The key takeaway is that you’re making worthwhile improvements, no matter how quickly or long they may take to achieve.
[19:30] Other types of solutions found: Most of the solutions came down to outsourcing. For example, Lorna is not a software expert, so resolving the software system issues would have taken a long time. Luckily, she found an associate in Michigan who specialised in API development, who could create ways to make the systems talk to each other using Zapier. It wasn’t always possible as some apps don’t allow for custom triggers, but there was a lot of issues he could help resolve. Lorna now thinks of him as an extension of the team.
[22:00] Another example of time-saving: Lorna’s team often have to fill out P11D’s and submit them to HMRC on behalf of clients. The format that is provided made it difficult for staff to fill out, meaning it caused a lot of headache and wasted a lot of time just trying to reformat them in an easily editable way. They managed to source a system that does this for them, at a small cost per year. It was definitely worth it – saving the whole team 3 days’ worth of time a year!
[26:00] Leonard Business Services is a perfect example of how taking a proactive approach can lead to great success. They have won a number of awards over the years, and will no doubt win many more in the future.
If you’d like to learn more about Leonard Business Services, check out their website! Also take a look at Lorna’s LinkedIn, where she shares a lot of insightful business tips.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We’re already seeing the devastating effects of failing to maintain global warming at the 1.5 degrees, as pledged in the 2015 Paris Climate Agreement. In order to get this back on track we all need to consider our current energy consumption.
So, what can businesses do to manage their impact?
That’s where ISO 50001, the Standard for Energy Management, comes in! ISO 50001 can help your business to continually improve its energy performance, energy efficiency, energy use and energy consumption. Building an energy management system will ultimately help you to understand, monitor and measure your use of energy.
Today Darren Morrow, Senior Isologist here at Blackmores, joins us to share his top 5 top tips for ISO 50001 Implementation.
You’ll learn
● What is ISO 50001?
● 5 top tips for Implementing and Energy Management System
Resources
● isologyhub
● ISO 50001
In this episode, we talk about:
[00:52] We have a more detailed walkthrough of ISO 50001 Implementation available in our steps to success podcast series, which are episodes: 84, 85 and 88
[01:05] What is ISO 50001? ISO 50001 is all about continually improving energy performance, energy efficiency, energy use and energy consumption. By Implementing an energy management system, you will be able to fully understand and monitor and measure your use of energy. Like most other ISO’s, continual improvement is at the heart of ISO 50001, and It’s also based on the Annex SL format. So, it shares some similarities with Standards such as ISO 9001 and ISO 14001. If you’ve got ISO 14001, you’re already half-way there!
[01:40] ISO 50001 and ESOS – ISO 50001 can also help you comply with ESOS (The Energy Savings Opportunities Scheme). If you’d like to learn more about that, listen to episode 138.
[02:50] Tip 1 – Top Management commitment and allocation of resources: This is vital, as the reason for implementation, management, requirements and aims along with expectations of everyone within the business for their support, is clearly demonstrated and communicated from the top down.
With an energy management system, part of this commitment includes making sure suitable resources are made available, this includes:
· People - For implementation, maintenance and improvement of the systems, including the means of gathering and reporting data.
· Financial support - There will be times where investment will be required. Ensuring existing equipment maintenance and servicing undertaken as required to maintain efficiency.
Allocate clear responsibilities for individuals e.g. gathering data such as meter readings, fuel usage, so that this is done consistently and the data is not only available but accurate.
[04:14] Tip 2 – Data: For data collection we need to understand certain things, an Energy review will support the identification of energy sources, identify and understand energy use and determine clear performance monitoring and indicators, leading to the determination of the data required. Some key considerations include:
· Identify sources of energy and your energy consumption from the energy review
· The quality, precision and accuracy of the data collected needs to be considered and monitored if measuring / monitoring results are to be meaningful.
· Data collection frequency should be determined and maintained to support the overall statistical analysis.
Finally, set goals and targets for improvement (EnPIs) - this can be in overall energy consumption, specific equipment improvements, other ratios measures such as consumption per person of consumption vs revenue.
[06:10] Tip 3 – Align and Integrate with other business management systems, goals and strategies: Sounds simple, but not always undertaken effectively, when implementing an energy management system consider any other management system that is already in place and look at any similarities, any elements that already exist that can be tweaked or expanded - this way, it is treated as 'business as usual'.
[07:20] Tip 4 – Communication, training and awareness: Communication plays a key role in any system, make sure you:
· Communicate requirements, goals and commitments, and objectives or targets.
· Keep staff informed of what’s going on as their involvement and direct actions support achieving goals and targets, along with identifying improvements.
· Assign responsibilities, create a team and/or assign a champion - This supports the effectiveness of data collection, and also can increase motivation and encourage identification of energy saving opportunities
Energy savings require the commitment of the whole workforce. There ideally needs to be a champion in the organization who can drive change and savings.
[08:41] Tip 5 – Record opportunities for improving energy efficiency: Any and all identified opportunities can be, and should be logged and monitored for suitability, no matter how 'far out there' these may be.
Some may not be appropriate or feasible immediately, or in the short term, possibly due to costs / investment requirements. However, once an opportunity is logged, it can be monitored, assigned financial support and be planned for Implementation.
[10:40] We’re offering a Buy 1 Get 1 Free offer on isologyhub memberships until the 31st October 2023! Contact us to book a demo
Stay tuned for next weeks’ episode as Darren joins as again to highlight 5 key mistakes to avoid while managing an Energy Management System.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We sadly often see Management Systems fade into the background following successful certification. When this happens, it can stagnate and cease to be a driving force for continual Improvement within the business.
So, what can you do to reinvigorate interest?
That’s where the Engagement Amplifier Gameplan comes in! This Gameplan was created by today’s guest, Sarah Ball, an isologist here at Blackmores and one of the main driving forces behind our online membership – the isologyhub.
Today Sarah will continue on from the last episode and explain the last few steps in the Engagement Amplifier Gameplan.
You’ll learn
● What is the isologyhub
● What are the final 4 steps in the Engagement Amplifier Gameplan?
Resources
● isologyhub
● What’s in a name
In this episode, we talk about:
[00:55] The isologyhub is our online Membership our online membership site that includes a full ISO 14001 roadmap to help you create and launch your own bespoke environmental management system. Also included are a suite of templates and training on various ISO’s to help take you from zero to hero in ISO Standards.
[01:15] Sarah Ball created the Engagement Amplifier Gameplan in addition to many other resources on the hub. She is one of the key people behind the hub’s creation and currently drives it’s development.
[01:30] This is part 2! We covered what the Engagement Amplifier is, along with the first few steps in the Gameplan in the last episode. If you missed out, I highly recommend going back and giving it a listen.
[01:45] Step 4 – Champions: A team of management system Champions, whether that be Health & Safety Champions, Quality Champions or any other discipline, can have a significant impact on engagement levels. They can advocate for the management system and, crucially, Champions lead by example when they engage with the management system themselves. In Step 4 of the Gameplan takes you through what Champions can do, what makes a good team of Champions and how to start your own team of Champions.
[03:40] Step 5 – Brand Boost: This is how you brand and sell your management system to your employees and other key stakeholders, which is crucial to how they relate to it and engage with it. It walks you through the importance of a brand identity for your management system, how to develop this and how to launch, or re-launch, the management system with a new brand within the business. This step can be useful for the implementation of your management system and for when engagement has really fallen. For further listening – go back to our ‘What’s in a Name’ episode.
[04:30] Practicing what we preach – We did a recent rebrand of our Management System at Blackmores. Even though it’s a mature system that’s years old, we felt that it wasn’t doing much for us. So we followed our own plan and created H20 (How 2 Operate), a much more accessible and collaborative Management System that is housed on our shared Teams channel and SharePoint.
[05:40] Step 6 – Communicate and Celebrate: . Ongoing communication is a key part of maintaining momentum and engagement, it provides an opportunity to keep the management system at the forefront of people’s minds and to celebrate successes. It also allows you to recognise examples of engagement with the management system. The Gameplan takes you through what you should communicate and how and is something that you can revisit at any point as your management system matures.
[06:45] Step 7 – Momentum: Once you have reinvigorated engagement, it is crucial to maintain that momentum. This step takes members through how to recognise engagement, continue to reassess engagement levels and developing a future strategy to maintain the desired level of engagement.
[07:50] We’re offering a Buy 1 Get 1 Free offer on isologyhub memberships until the 31st October 2023! Contact us to book a demo
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
When a Management System is first implemented, there is often a spotlight being cast on it’s importance to the business and everyone’s roles in relation to it.
However, we often see this buzz quickly fall off, letting the Management System fade into the background. When this happens, it can stagnate and cease to be a driving force for continual Improvement within the business.
So what can you do to reinvigorate interest?
That’s where the Engagement Amplifier Gameplan comes in! This Gameplan was created by today’s guest, Sarah Ball, an isologist here at Blackmores and also one of the main driving forces behind our online membership – the isologyhub.
Today Sarah will explain exactly what the Engagement Amplifier Gameplan is, who it’s suitable for and give an overview of the first few steps.
You’ll learn
● What is the Engagement Amplifier?
● Who is the Engagement Amplifier for?
● What are the first 3 steps in the Gameplan?
● How long does it take to action this Gameplan?
Resources
● isologyhub
In this episode, we talk about:
[00:25] The isologyhub is our online Membership our online membership site that includes a full ISO 14001 roadmap to help you create and launch your own bespoke environmental management system. Also included are a suite of templates and training on various ISO’s to help take you from zero to hero in ISO Standards.
[01:15] Sarah Ball created the Engagement Amplifier Gameplan in addition to many other resources on the hub. She is one of the key people behind the hub’s creation and currently drives it’s development.
[01:45] What is the Engagement Amplifier? The Engagement Amplifier Gameplan, like all the Gameplan in the isologyhub, is an action plan, something you can follow to transform an aspect of your management system. In this case, to increase engagement from across your business and key stakeholders with your management system.
[02:05] What does the Engagement Amplifier aim to address? It is very common after a period of time for management systems to fade into the background a little. The risk when there is a lack of engagement is that the management system begins to stagnate and no longer drives the business forward. So, reinvigorating that engagement is really crucial and the Gameplan walks you through the steps to assess what your level of engagement is now, where you want it to be and how you can get there.
[04:05] Who would this Gameplan be good for? – The Engagement Amplifier Gameplan is good for any company with a management system in place. And for any point in the maturity of your management system. Certainly, the first part of the Gameplan where you will determine what your engagement goal is, and what level of engagement you currently have.
[05:55] Step 1: Assess – This gives an overview of what good engagement looks like, why it is important to measure and, importantly, how you can measure the engagement you have.
[05:40] Step 2: Myth Busting – This is important because a common cause of a lack of engagement is a lack of understanding about what the management system is and how people should engage with it. In this step we explain what some of the myths are and what the reality is, so that members can address these myths in their own business.
[07:15] Step 3: Leadership – This is really key as the approach of the Leadership Team to the management system is one of the biggest factors in the level of engagement with the management system. Leadership set the tone of the organisation’s culture and have a significant role in embedding your management system into daily operations and aligning it to your strategy and vision. In this step there are activities for the Leadership team to complete to define how the management system can support strategic goals. As well as practical tips on how the Leadership level can show their commitment and promote engagement with the management system.
[08:40] How long would it take for someone to action this Gameplan? – That can vary a lot depending on how much time you have available to dedicate to it and how many people you want to get involved. It’s certainly not intended to be done in a day or even a week. You will need time within each step to engage with others, get feedback and analyse information. Sarah would suggest at least a month, but potentially longer depending on other priorities.
[09:50] We’re offering a Buy 1 Get 1 Free offer on isologyhub memberships until the 31st October 2023! Contact us to book a demo
Stay tuned for next week’s episode where Sarah will be joining us again to cover steps 4 – 7 of the Engagement Amplifier Gameplan!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
With a growing number of threats and risks facing businesses every day, it’s never been more crucial to have a proper system in place to mitigate and manage issues when they crop up.
A variety of ISO Standards can help businesses to do just that! And we’re seeing an ever-increasing trend of requests for Integrated Management Systems, which combine multiple ISO certifications to cover every aspect of their business. Such is the case with today’s guest, Todd Research.
Todd Research have been in the business of designing, manufacturing and supplying X-ray scanners for 70 years. They have since expanded their product range to include other solutions, all designed to detect suspect devices.
We’re joined by Caroline Banks, Support Manager at Todd Research, to learn about why they decided to implement ISO 9001 (Quality Management) and ISO 27001 (Information Security), including an insight into their experience with our ISO 14001 coaching programme, hosted on the isologyhub.
You’ll learn
● Who are Todd Research?
● Why did they choose to Implement ISO 9001 and ISO 27001?
● What challenges did they face?
● The benefits of ISO 9001 and ISO 27001
● Their experience with our ISO 14001 coaching Programme
Resources
● Todd Research
● isologyhub
● ISO 9001
● ISO 27001
In this episode, we talk about:
[00:37] An introduction to Todd Research and Caroline Banks’ role as Support Manager there.
[01:20] What is something not many people know about Caroline? She’s taken up running and started with the couch to 5K. She later completed a half-marathon in the same year, and has since gone on to finish 21 more half-marathons and 2 full ones!
[02:27] Who are Todd Research? They were founded in 1950, designing, manufacturing and supplying X-ray scanning equipment. They also provide service and maintenance for their devices worldwide.
[03:11] What Standards are they certified to? ISO 9001 (Quality Management, inherited from a previous company) and ISO 27001 (Information Security Management)
[03:48] What was the main driver for achieving ISO 9001 and ISO 27001? – For ISO 9001 – As a manufacturing company, they want to ensure that they can provide the best quality in terms of product and service. For ISO 27001 – This was more sales driven and was being requested in a lot of tenders, particularly Government tenders.
[04:35] How did Caroline manage an inherited Quality Management System? – Caroline completely revamped the inherited Management System, making it their own and adapting it to suit how they currently run their business. It involved a lot of review and removal of unnecessary documentation, with the end result of streamlining the whole system. They also appreciated a 3rd party coming into review and assist with the process. After moving to a new premises, they are still continually Improving system year on year.
[06:25] How long did it take to achieve certification to ISO 27001? – They started in April 2021 with a Gap Analysis and gained certification in September 2021 (6 months in total). As they already held ISO 9001, they made the decision early on to integrate the two Standards into a Business Management System.
[07:50] What was the biggest gap found after the initial ISO 27001 Gap Analysis? – The biggest challenge for Todd Research was carrying out the Risks Assessments. Getting Directors involved in the review of Standards and agreeing what risks applied to them took the most time in the early stages.
[09:00] Caroline’s experience with ISO 27001 – While she had experience with ISO 9001, ISO 27001 was a whole new ball game. There are a lot of risks associated with Information Security including, phishing, malware, risks to hardware ect. This was all new territory for Caroline, but she adapted and learned a lot along the way.
[09:50] What difference has the Management System made to the business? – It’s unique to them and their way of working, especially as a result of integrating the two Standards into a single Management System. The whole process gave them a chance to look at the business with a new perspective, which in turn helped them to streamline a lot of processes.
[10:20] What lessons have they learned from Implementing ISO 9001 and ISO 27001? – Caroline now has a better understanding of how the business works from all angles, from manufacturing to finance. Her experience with having Blackmore assist with Internal Audits highlighted the need and importance of impartiality.
[11:20] What are the main benefits? – For them, it’s having an Integrated Management System, as a lot of aspects of various ISO Standards share similarities, and it just makes sense to combine them to save on doubling up on documented information. Caroline also highlights the Corrective Actions Log as her key tool for managing actions following on from Internal Audits, allowing for a proactive approach for business improvement on a weekly basis.
[12:50] What is the ENE / ISO 14001 Coaching programme? – Blackmores secured some European funding to support 7 businesses in the East of England to raise awareness of environmental issues and implement some practical tools for Environmental Management. We opted for an ISO 14001 focus and utilized our online membership portal, the isologyhub, as the host with additional coaching from one of our experienced consultants.
[13:25] What was Caroline’s experience with the isologyhub and the ISO 14001 coaching programme – Todd Research made the decision early on not to go for ISO 14001 certification. The experience gave Caroline a good insight into what the requirements are for the Environmental Management Standard in preparation for potentially certifying in future.
Caroline highlights the wealth of information available in the hub, including documentation which supplemented the coaching sessions. Her 1-2-1 coaching sessions resulted in deeper analysis of what their business can act on to improve their impact, for example putting in place a scrap metal policy for X-ray scanners and equipment that needs to be disposed of. They have also streamlined their Engineer’s service visits, by making the most of them while in any given area to reduce the carbon impact of travel.
[17:00] What was the most useful resource in the isologyhub? – The training provided for carrying out Risk Assessments, with a focus on their environmental risks.
[18:05] What was the main benefit of achieving certification to ISO 9001 and ISO 27001? – Having both standards sets them aside from their competitors, as many have ISO 9001 but not many have ISO 27001. It also brings a sense of continuity to the business.
[18:55] Caroline’s top tips – Use an independent company (such as Blackmores) to assist with Implementation. Having a helping experienced hand will make the journey run a lot more smoothly and will give you piece of mind, especially as you have your own day job to worry about!
[19:30] A reminder that the ISO 27001 Transition Gameplan is available on the isologyhub – ISO 27001 recently updated, and those certified with need to update to the latest 2022 version of the Standard. Our Transition Gameplan will guide you through the changes and what needs to be done to update your Management System.
[21:17] Caroline’s book recommendation – ‘Menopausing’ by Davina McCall
[22:17] Caroline’s favorite quote – ‘It’s not so much that I began to run, it’s that I continued’
You can find out more about Todd Research via their website!
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Anyone whose been involved in the implementation or maintenance of an ISO Management System will know it’s not a small feat. There’s a lot of time and teamwork involved in getting a system in place for certification, so it’s definitely a cause for celebration when you finally do get that certificate at the end!
But what can you do with that? A lot of companies will get an ISO certification as a necessity, whether that be an industry requirement, legal requirement or client requirement. Often times, they’re quite content to just let those interested parties know about it and leave it at that. Which is a shame, as we think it’s something worth shouting about.
It’s a display of your commitment to best practice, whether that be in quality, health & safety, information security, risk management or any combination of those – and better still, it’s a globally recognised certification.
In this episode, Stephanie Churchman, Communications Manager at Blackmores, will take you through a few ways you can celebrate your ISO success.
You’ll learn
● Why promote your ISO certification?
● How can you promote your ISO success?
● How can Blackmores help you celebrate your ISO success?
Resources
· Isologyhub
In this episode, we talk about:
[00:30] Mel will be back in the next episode after taking a well deserved break 😊
[01:15] Why celebrate your success? You / your team worked hard to put that Management System in place and get it ready for certification, so it’s worth celebrating when you finally do get that certificate. It’s also a globally recognised certification that displays your commitment to Best Practice.
[02:23] #1 Certificate Award ceremony – This is something you may need to organise ahead of getting your final certificate. It’s worth asking your certification body if they do a certificate award ceremony. Some CB’s will invite clients to a location to hand out certificates in a batch – or they may be happy to come an officially award you your certificate on your own premises. Either way, it’s a great opportunity to get a photo that you can then use later on your website or in social media, in addition to making it more of an event.
[03:09] Publish a blog or news article – This is a newsworthy event! And you should take the time to write a short statement for your website – Bonus points if you can get some statements from those involved with the process. It doesn’t have to be overly long, it can just be a short paragraph.
[03:35] Social Media Post – Social media is the main place a lot of people get information nowadays. Many platforms have character limits, so you can keep it short and sweet, as this is just to inform your wider audience who may not regularly visit your website. On platforms like LinkedIn, you can even tag some key members involved so they can add their own comments and experience under the post.
This is also a great opportunity to work in collaboration with your Certification Body – as they’re also keen to show off their clients successes. It’s worth getting in touch with their marketing team and ask if they’d be happy for you to tag them in a post– so they can reciprocate with a post and tag of your company – which would in turn expand your audience for that post significantly depending on how much reach the certification body has.
[04:54] Website Promotion - You could make a more permanent addition to your website. A lot of businesses tend to have a page for awards and accreditations, which is the perfect place to display the digital badge that your certification body will provide following certification. You could also link your current certificate if so inclined. Another place we often see clients displaying those digital badges is the website footer, it’s unobtrusive but makes for something a bit more eye catching when displayed next to the typical links you see in website footers.
[05:35] Email Signatures – Are another subtle way to make sure those digital badges get some use and imprint themselves in the minds of anyone you contact. It’s a relatively easy update to make and is just another way to make sure it’s seen by both internal and external contacts on a daily basis.
[05:55] Newsletters – Many of you will have some sort of weekly, monthly or annual communications with your clients and prospects. Make sure to include a mention of your certification in the next update. If you wanted to make it something special, make it a main feature and include some story behind the why and how you went about Implementation. Let your audience know why that certificate is important and highlight any notable success as a result of that certification, i.e. with ISO 50001 (energy management), you may have already made significant changes to reduce your energy consumption. Whether that be switching all your lighting to a more eco-friendly option or sharing some actual figures on energy reduction following certification.
[06:50] Case Studies – This is just another way to get your ISO journey written down in a concise, easy to digest format that can then be shared via your website and social channels. It’s another great place to highlight the why, how, any challenges you overcame and what your next steps are.
Keep it to 1 page if possible – as people often get turned off by looking at a daunting page count. Bullet point what you can and expand where needed, as that helps to break up walls of text and just makes it a bit easier for people to read. Take a look at some examples online for layout inspiration – there’s no shortage out there. Of course, if you work with us, we’re happy to do all the design and writing for you.
[07:45] Podcast / Video - Not everyone is going to have the means to publish videos and podcasts – So this won’t be applicable to everyone, but that doesn’t necessarily mean you have to drop this idea entirely. For example, we feature a lot of clients on our podcast and we’re more than happy for them to use their episode in marketing, or on their site or wherever they want to. So, if you work with a third party that has a podcast or produces their own videos, it’s worth an ask to see if they’d be open to featuring you.
For those that do have the means to do this in-house – It’s highly recommended that you do either one or both of these, as you can then link back to them in social posts and other marketing.
[08:50] This isn’t a one time thing – you can re-use a lot of these resources elsewhere, and remind others that you hold certain certifications when appropriate.
[09:15] The main takeaway is – You worked hard to earn that certificate, so don’t let it be a quiet victory.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The Energy Savings Opportunity Scheme (ESOS) is a legal requirement for organisations of a certain size or value. The scheme is designed to make companies look at how they use energy with a view to improving performance. If your organisation qualifies for ESOS, you have until December 5th to comply or complete your phase 3 reporting.
Over the last few episodes we’ve explored two routes to compliance: Energy Audits and ISO 50001. As we explained, ISO 50001 goes above and beyond ESOS requirements and ensures you don’t have to gather an evidence pack every four years to prove compliance.
However, there are many more benefits to ISO 50001 than just it’s compliance with ESOS requirements. Join Mel this week as she dives into the other benefits ISO 50001, including real world examples from some global brand names.
You’ll learn
● Why Implement ISO 50001?
● What are the benefits of ISO 50001?
● Who has found success with ISO 50001?
Resources
· ESOS
· ISO 50001
In this episode, we talk about:
[00:35] Watch our previous episodes to learn more about Energy Audits and ISO 50001
[01:41] Benefit #1: Cost savings – By Improving your energy efficiency and reducing energy consumption, you can save a startling amount. ISO 50001 helps you to put a system in place that will allow optimisation of your energy usage.
[02:20] Benefit #2: Compliance – ISO 50001 can help you comply with the likes of ESOS and SECR. Carbon reporting and legal requirements in relation to it are global, any countries lagging behind on these requirements will soon adopt or create their own in response to the limited time we have left to reduce the effects of the climate crisis.
[02:45] Benefit #3: Reduce your environmental Impact – By reducing energy usage and switching to more energy efficient means, you will reduce your carbon emissions. ISO 50001 also acts as a complementary tool to ISO 14001 (Environmental Management) that many already have in place.
[03:10] Benefit #4: A coordinated approach – Companies, especially large ones, may have multiple systems in place to manage energy. ISO 50001 helps to create a universal framework that can be applied to a whole business.
[03:25] Benefit #5: External Incentives - There may be external benefits that can be gained by proving that you are taking steps to reduce your environmental impact. This could include tax benefits, insurance ect
[04:25] Benefit #6 Informed funding – There is a lot of funding out there to help companies with new green technology. Having ISO 50001 in place will give you a consistent overview of your energy usage, so you’ll be able to make informed funding choices based on where more savings can be made in terms of emissions and general costs.
[04:55] Benefit #7 Track Objectives – ISO 50001 can help you set Objectives and then set policies and procedures to help make those a reality. Those familiar with ISO Standards will know that it’s all about continual Improvement, so you’ll always be making progress.
[05:30] Benefit #8 Credibility – ISO 50001 is an internationally recognised Standard, and is a mark of your credibility. This can be used in marketing materials, displayed on your website, used in Case Studies ect.
[06:35] You don’t have to be a large brand or organisation to Implement ISO 50001. It can be implemented for a business of any size where energy is a significant environmental Impact.
[07:05] Hilton’s success with ISO 50001: One of the world’s largest hotel chains, Hilton was the first global hospitality company to achieve portfolio-wide certification to ISO 50001. The savings have been significant, reducing Hilton’s energy intensity by 20.6% and its carbon intensity by 30.0% from a 2008 baseline.
[07:55] Bentley’s success with ISO 50001: Reduced energy usage by two-thirds for each car produced and by 14% overall for the entire plant, delivering savings of 230 GWh of energy – enough to power 11,500 houses for a year!
[09:37] Hitachi’s success with ISO 50001: Following the Japanese earthquake disaster in 2011, Hitachi decided to introduce “the smart next-generation factory plan”. Following implementation of ISO 50001, the plant reduced 23 % of the contract electricity, 15 % of CO2 emissions and 5 million yen/month of electricity costs.
[10:12] Toyota’s success with ISO 50001: Implementation of ISO 50001 resulted in a reduction in electricity usage which has translated into cost-savings of more than R4.8 million (Over £210,000!) over a two-year period. The company also generated energy savings of GWh 8.15 across its 14 plants, and reduced its GHG emissions by 7,804 tons.
[10:50] Schneider Electric’s success with ISO 50001: The company adopted ISO 50001 certification in order to maximise energy performance. Following the certification, the business’ energy performance increased by 10.5%, with savings totaling £26,500 over 3 years.
[12:15] Want more info on ISO 50001? – Head on over to the isologyhub to get access to a wealth of ISO 50001, and energy management tools
For those interested in ISO 50001, we’re offering a free copy of the Standard to anyone who signs up for Implementation with us before the 30th June.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The Energy Savings Opportunity Scheme (ESOS) is a legal requirement for organisations of a certain size or value. The scheme is designed to make companies look at how they use energy with a view to improving performance. If your organisation qualifies for ESOS, you have until December 5th to comply or complete your phase 3 reporting.
Last week Mel explained the Energy Audits route to compliance, which is a process that must be repeated every 4 years. Companies that want to avoid the inevitable rush to get reports submitted before the deadline may want to consider a more long-term commitment to ensure continued compliance, that being the Implementation of ISO 50001.
ISO 50001 is the standard for Energy Management, and it goes above and beyond what is required of ESOS. Companies certified to this standard are already considered compliant to ESOS with out the need to complete any additional reporting outside of what is already monitored and measured by the standard.
Join Mel this week as she explains what ISO 50001 is, how it complies with ESOS requirements and the key differences between other environmental standards such as ISO 14001.
You’ll learn
● What is ISO 50001?
● How ISO 50001 complies with ESOS?
● What is the difference between ISO 50001 and ISO 14001?
Resources
· ESOS
· ISO 50001
In this episode, we talk about:
[00:50] Watch our previous episode to learn more about Energy Audits
[01:00] Reminder: Companies certified to ISO 50001 do not have to carry our Energy Audits.
[01:14] What is ISO 50001? This is the Energy Management Standard, a globally recognised best practice framework designed to help manage a companies energy performance, optimise their energy efficiency and reduce their overall impact.
[01:50] Why have a Standard for Energy Management? This standard is most appliable for businesses who are looking to put measures in place to reduce their overall environmental impact, specifically in relation to energy management. Businesses who operate data centers or large healthcare facilities will use a lot of energy, many Implement ISO 50001 to help reduce their costs for energy.
[02:48] Why Implement ISO 50001 if you already have ISO 14001? – ISO 50001 is specifically aimed at the energy aspect of environmental impact. It helps businesses to take a deeper look at their operations and how their managing energy performance. If you already have ISO 14001, you’re already half-way there, and ISO 50001 could easily be integrated as an enhancement to your Management System.
[03:25] If you want to claim ESOS compliance, it’s important to ensure that your ISO 50001 certification is valid for the compliance date.
[03:50] If you want to go down the ISO 50001 route, the time to act in now (April / May 2023) – You will need to factor in a minimum of 6 months to Implement ISO 50001. Need help with this? Contact us!
[04:40] There has been an increase in uptake of ISO 50001, which has put a lot of UK certification Bodies under pressure to get Assessments booked in before the ESOS deadline. So get in touch with a few UKAS accredited Certification Bodies ASAP to find out if they can accommodate you in an appropriate time frame. We offer a quote request service for free, simply contact us for more info.
[05:50] More about ISO 50001 – It’s based on the Plan-Do-Act-Check cycle, which is a familiar structure to a lot of ISO’s. Many aspects of ISO 50001 Implementation will be similar to the likes of ISO 9001, i.e. having policies and procedures in place and conducting Internal Audits ect.
[06:34] How does ISO 50001 differ from ISO 14001? – The main difference is the requirement for an Energy Review. This is all about understanding how you’re using energy as an organisation, then using that information to recommend controls to reduce energy use.
[07:43] You will be able to determine your Energy Performance Indicators following on from an Energy Review. These help to establish a clear roadmap and energy controls for reducing energy usage. For example, you could put controls in place for certain equipment, LED light replacements, cycle to work or car share schemes ect.
[08:45] What is the benefit of ISO 50001 over Energy Audits?: ISO 50001 puts a whole system in place to continually Improve your energy performance through controls and procedures. Energy Audits will only tell you about your current energy use and provide recommendations for Improvement with no clear roadmap or further incentive to Implement those changes.
[09:00] What else is involved with ISO 50001?: Another key aspect of ISO 50001 is the continued monitoring and measurement of energy performance. This can then be reported back to the board so they can see the progress being made.
[10:00] What are the key clauses in ISO 50001? ISO 50001 went under a revision in 2018 to align itself with Annex SL, which is common across a lot of other ISO’s. The 10 clauses are as follows:
· Clauses 1,2,3 – Explanatory clauses. You won’t Implement these, they simply provide context and help with key terms and definitions.
· Clause 4 – Context of the Organisation
· Clause 5 – Leadership
· Clause 6 – Planning
· Clause 7 – Support
· Clause 8 – Operations
· Clause 9 – Performance Evaluation
· Clause 10 – Improvement
[11:00] Want more info on ISO 50001? – Head on over to the isologyhub to get access to a wealth of ISO 50001, and energy management tools
For those interested in ISO 50001, we’re offering a free copy of the Standard to anyone who signs up for Implementation with us before the 30th June.
Tune in next week where we explore the many benefits of Implementing ISO 50001.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The Energy Savings Opportunity Scheme (ESOS) is a legal requirement for organisations of a certain size or value. The scheme is designed to make companies look at how they use energy with a view to improving performance. If your organisation qualifies for ESOS, you have until December 5th to comply or complete your phase 3 reporting.
Over the next few weeks, we will focus on how you can comply with ESOS, starting with Energy Audits. These audits are required by ESOS in order to understand where and how energy is used within the organisations premises and operations. Every audit will recommend cost-effective measures that will save the organisation energy and money, which is the ultimate intention of the legislation.
Join Mel this week as she explains what Energy Audits are, what data you need to report on and what final sign-off is required before a report is submitted.
You’ll learn
● Who needs to comply with ESOS?
● How can you comply with ESOS?
● What are Energy Audits?
● What data do you need to gather?
● Who needs to sign-off the ESOS report before submission?
Resources
In this episode, we talk about:
[00:44] The deadline for Phase 3 ESOS reporting is the 5th December. Remember that ISO 50001 is considered a route to compliance if you don’t want to go ahead with conducting Energy Audits.
[01:32] What is ESOS? ESOS stands for the Energy Savings Opportunity Scheme. It was launched by the department of energy and climate change, Deck, back in July 2013. It was established to comply with Article 8 – an EU directive that was created in 2014. Despite Brexit, any qualifying businesses must still comply. ESOS in simple terms is an energy assessment that must be carried out by its definition of large enterprises.
[02:50] Who qualifies for ESOS? Large enterprises as defined by ESOS are businesses that have more than 250 employees and / or an annual turnover exceeding 50 million euro or a balance sheet exceeding 43 million euro. This only applies to the private sector – the public sector is exempt.
[03:33] When does ESOS reporting occur? Every 4 years – The first phase staring in 2014, Phase 2 was in 2019 and Phase 3 will have it’s deadline this year.
[04:08] Why is ESOS important? – No matter where you are in the world, energy reduction is crucial. Businesses should also be well aware of their own energy use and impact, not only to reduce but hopefully offset as part of ongoing sustainability efforts.
[04:35] It’s estimated that there will be a net benefit of £1.6 billion as a result of ESOS to the UK alone.
[04:55] What do you need to do to comply with ESOS? An ESOS assessment requires you to do 3 things:
· Measure your total energy consumption
· Conduct Energy Audits – to identify cost effective energy reduction recommendations
· To report compliance back to the Environment Agency (For the UK, other European countries will have their own authority)
[05:42] How can you comply with ESOS? – There are 2 routes to compliance:
· Conduct Energy / ESOS Audits
· Implement ISO 50001 - Companies certified to this standard are already complying with ESOS, as it goes above and beyond ESOS’s requirements.
[07:20] What’s involved in an ESOS Energy Audit? – You will be required to collect 12 months of energy data, provide cost effective energy reduction recommendations for the areas audited in scope, and findings need to be reviewed by an ESOS Lead Assessor.
[08:00] What do you need to consider when collecting data and looking at where reductions can be made? – Facilities – i.e. heating, lighting, ventilation ect. There are a number of energy efficiency initiatives to help reduce costs involved with elements of facility management. It can be something simple like replacing old boilers, using energy efficient Led lighting, reducing working hours in the office, reviewing time settings for lighting, ventilation and heating ect. Many businesses leave unnecessary functions / devices on overnight, start looking at how much energy you’re using and where and you’ll be able to identify where energy use and costs can be cut.
[10:20] Other things to consider are additional warehouses or transportation within your business i.e. fuel consumption, vehicle maintenance ect.
[10:53] To truly make a difference, you need to spread awareness within your business about any changes you’re making as a result of these energy audits. Including any reminders to them i.e. turning off lights when they leave a premises.
[11:05] What do you need to do to carry out an ESOS Energy Audit?:
· You need to plan the audit – including establishing the scope
· Conduct the audit
· Collect data for analysis and identify the opportunities for improvement
· Pull together all the documentation in an ESOS evidence pack which will be reviewed and signed off by top management and an ESOS Lead Assessor
· Finally, you can submit that evidence pack to the Environment Agency
If you need help with any of this – Blackmores can help 😉
[11:45] What are the different data sources you should look at? Meter reading records, delivery notes, automatic meter readings ect. We find that the financial team and facility managers are instrumental in gathering the necessary data. Don’t forget to gather any travel information from your drivers of vehicle fleet managers!
[12:31] Establishing the scope and documentation – You will need to set the scope and boundaries of the audit, document the methodology for your data collection and recommendations for improvement, document your data sources and identify any gaps.
[13:00] Final sign-off: Once everything has been documented in an evidence pack, you need to get this signed off by a director or member of top management and by an ESOS energy assessor. Once done, you can submit this to the Environment Agency
Tune in next week where we explore the ISO 50001 route to ESOS compliance.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Sustainability should be a top priority for any business going into 2023. The last few years’ worth of extreme weather have proven that action needs to be taken now to protect our future. But where do you start?
While there are a lot of great ideas out there, it’s becoming increasingly clear that a standardised approach is needed to keep everything on track. Which is where ISO Standards come into play – having been promoted heavily at the last few COP conferences, there are a whole range of environmental Standards to help businesses manage and reduce their impact.
One of the most popular being ISO 14001 (Environmental Management), which was adopted by the subject of today’s interview – dotdigital.
dotdigital is an online marketing company who specialise in email and SMS marketing automation, tailoring customer experience and providing solid data analysis tools.
Mel is joined by Steve Shaw, Chief Product & Technology Officer at dotdigitial, to talk about the positive impacts following on from their successful ISO 14001 implementation, and to explain some of their fantastic sustainable initiatives introduced over the past few years.
You’ll learn
● Who are dotdigital?
● How do dotdigital manage their Environmental Management System?
● What are dotdigital’s sustainable initiatives?
● What have they learned through the implementation of ISO 14001?
Resources
In this episode, we talk about:
[01:07] Listen to our previous interview with dotdigital – where we discussed their ISO 27001 (Information Security) certification.
[01:32] An introduction to Steve Shaw – He is the Chief Product & Technology Officer at dotdigtal, who oversees a lot of their innovators (which comprises of software engineers and those involved with product development and support). He also manages the various acquisitions for the group.
[03:15] Who are dotdigital? Dotdigital have been around since 1999, they have evolved and adapted to join the growing SaaS market. They provide a range of automated marketing solutions in addition to a customer experience and data platform. They recently celebrated reaching 400 employees and have become AIM listed.
[03:52] What can dotdigital’s platform do? Data collection and analysis to build a profile for single or groups of users. This data can then be used in combination with AI and machine learning to create a tailored digital journey with a brand.
[05:15] How do dotdigital manage their current ISO 14001 certified system? – Their Management System is an integrated Management System, which provides the business with a central hub to work from. They have an established team who are tasked with the management of their ISO system (this is not a dedicated role for anyone in that team). Part of their role involves looking at the businesses aspects and impacts to see where the biggest consumption of energy is happening, measuring this consumption and setting objectives to help reduce this where possible.
[06:51] dotdigital was the worlds first carbon neutral marketing automation platform that was ISO 14001 certified. They also aim to be net zero by 2030!
[07:10] They have a relatively small footprint as a primarily digital based company, only really having to consider the running of computers, air conditioning and standard office facilities. So it can be a challenge to reduce!
[08:30] What led to the success of dotgreen? – dotdigital launched a group called dotgreen, which has since thrived into a community of likeminded individuals all working together to improve and reduce dotdigital’s impact. They were fortunate to have an Executive group sponsor who can take ideas and suggestions to other leadership for consideration. This grassroots group encourages suggestions from everyone – no idea is a bad idea. Over time, the group evolved and helped to develop a sustainability programme for the business.
[10:30] What was one of the initiatives implemented from dotgreen? – They identified that existing data centers used by the business weren’t always utilising renewable energy. So, over the course of 2 years, they worked with Microsoft to build on their Azure platform to enable dotdigital to make the switch. Azure runs on renewable energy sources, and any remaining emissions can be offset through carbon credits.
[12:00] A green option for their customers – As a result of their cloud platform now being run through green partners, they can extend the environmental benefit to their customers.
[14:00] A sustainable culture shift – The introduction of dotgreen, it’s initiatives and the success of certification to ISO 14001 fostered a shift in the businesses culture. It spread to all aspects of the business – even resulting in their marketing team making the decision to not send out Christmas gifts and instead used the money to buy credits for tree planting.
[15:25] What is dotvoice? – Another pillar in the internal mechanisms of dotdigital. This voluntary group look at how they can promote awareness of different issues. One such example was organising interviews to celebrate the women in tech at dotdigital for International Women’s Day.
[17:10] Adapting – Like many businesses, they had to adapt over Covid to allow for home working. Following on from feedback, they have kept up with hybrid working. This means that meeting in-person usually becomes a big event! They ensure that all employees are taken care of, even creating another pillar called dotwellbeing to offer mental health support.
[21:53] Through the use of dotgreen and dotvoice, they promote voluntary days to assist with local initiatives and charities (many of which are their clients – such as the Woodland Trust).
[23:20] What have dotdigital learned over the years of maintaining an ISO 14001 certified system?
[23:20] Steve’s top tips: Get leadership support, look for passionate individuals to get involved, let the Standard guide you and don’t be afraid to set lofty goals.
[23:20] Steve’s book recommendation: Creativity Inc – by Ed Catmull
[23:20] Steve’s favorite quote: “The only constant in life is change” / “Some people want it to happen, some wish it could happen and others make it happen”
You can find out more about dotdigital via their website.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
With the pandemic being the driving force behind more remote working than ever before, health and safety professionals are becoming increasingly tech-savvy. All evidence points to them increasing their reliance on Software as a Service (SaaS) solutions to keep on top of H&S compliance and the ever-changing risks that are presenting themselves to businesses the world over.
Companies such as Riskex offer many software solutions to make Health and Safety Professionals’ lives easier, by streamlining compliance processes, gathering better safety data and providing total visibility on the performance of risk management. As a result, they keep a keen eye on new technology being adopted by the H&S sector.
Mel is joined by James Sharp, Chief Technical Officer at Riskex, to explain the top 10 emerging Software as a Solution trends in Health and Safety.
You’ll learn
● Who are Riskex?
● Why are people leaning towards SaaS?
● What are the top 10 emerging SaaS trends in health and safety?
● What solutions do Riskex provide?
Resources
● Riskex
● AssessNet
● ISO 45001
In this episode, we talk about:
[01:40] An introduction to Riskex and James Sharp’s role as Chief Technical Officer there.
[02:51] What is AssessNet? AssessNet is an online Health and Safety / Risk Management System designed to help streamline compliance processes and make gathering data much easier.
[04:00] Riskex have been certified to a number of ISO Standards, including ISO 18001 (Prior Health and Safety Standard, now certifying to the latest version, ISO 45001), ISO 27001 (Information Security) and ISO 9001 (Quality Management)
[06:20] Software as a Service became very popular during Covid, as business became very fragmented and were looking for solutions that could be rolled out across multiple sites. Riskex also created their own track and trace system based on established software they were already offering – helping businesses manage Covid safely.
[08:40] Trend #1 – Artificial Intelligence - Artificial learning is all around us and with vast volumes of data being collected by safety management platforms. AI allows decision engines to predict and provide guidance based on key trends or established KPI’s. For example, if accident rates were to increase but at the same time risk levels have been reducing, it could soon highlight this trend and look at other surrounding data or previous trends to establish a pattern. This will lead to a more pro-active approach to reporting and subsequent decision-making.
[10:35] Trend #2 – API Connectivity - Providing an open API platform will allow businesses to integrate internal systems and external services to digest data. As more organisations adopt Cloud solutions, connectivity between platforms has become increasingly important. With a robust API offering, multiple business services can interact with ease and become part of the safety management space, without incurring significant cost or time.
[11:50] Trend #3 – Low-Code Optimisation - Developing generic components within software to allow for quicker builds, implementations and tailoring requests. As stand-alone and generic component development increases, solutions can offer more flexibility and self-serve options to the end user to assist them with aligning platforms with their specific processes.
[13:30] Trend #4 – Mobile Optimisation - More and more end-users are accessing health and safety software via their mobiles but for various reasons, are not always able to use native apps (installed on the device). Therefore, health and safety software platforms need to adapt use on multiple devices, without the loss of features.
[14:45] Trend #5 – Vertical SaaS - Configuring EHS Software to align with the specific risks, terminology and processes that are pertinent to a given sector. As systems continue to grow in terms of sophistication and the ability to customise, so does the need to ensure that they remain User-friendly. A key factor to consider is that each industry has its own set of industry codes of practice, regulations, hazards and risks – and EHS systems need to be designed with these in mind.
[15:50] Trend #6 – White Labelling - Integrating 3rd party EHS platforms into a client’s corporate brand identity. When it comes to optimising User engagement and embedding technology effectively into business operations, it is important that the look and feel of the system interface is aligned with an organisations branding, company values and mission to create a more cohesive User experience. Riskex have embraced this by offering ‘FreshNet’ to clients, which can be tailored and aligned with clients existing branding.
[17:10] Trend #7 – Centralised Analytics (BI) - Robust Health and Safety management systems rely on an abundance of performance data arising from core processes – Risk Assessments, Audits, Contractor Governance, Incident Management and so on. The sheer volume of information generated by these processes can provide a wealth of positive opportunities to improve safety outcomes, if analysed correctly – which is where BI platforms come in to help provide an overall picture of risk performance management.
[19:40] Trend #8 – Micro-SaaS - Deploying discreet elements of a SaaS platform to work as standalone entities to fit a specific customer requirement. Modular-based solutions or smaller SaaS platforms can meet the needs of those organisations that may only require a specific feature, not necessarily a holistic service.
[20:30] Trend #9 – Machine Learning – This is a subset of AI, machine learning learns as it goes, picking up trends and offering insights for consideration.
[21:27] Trend #10 – Customer Experience - Customer Experience, in terms of both useability and service will outshine complex offerings. As SaaS becoming commonplace from both consumer and commercial perspectives, User’s expectations regarding Customer Experience are growing sharply when they are looking to make technology purchase decisions. Successful EHS SaaS vendors put significant focus and investment in optimising the Customer Experience, both in terms of interface and functionality, to reduce the barriers to adoption by focusing on how Users interact with their solutions.
[28:00] Businesses usually have a very limited Health and Safety resource. SaaS solutions enables informed decisions to be made despite a lack of human resources available.
You can find out more about Riskex via their website. Don’t forget to check out their Health and Safety Management software – AssessNet
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
To keep global warming to no more than 1.5°C – as called for in the Paris Agreement – emissions need to be reduced by 45% by 2030 and reach net zero by 2050.
Many businesses are already making great strides to reduce their Impact, and while you can reduce, achieving true carbon neutrality will involve offsetting a certain amount of emissions.
Treeconomy are one of the few companies in the UK that offer credible carbon credits. Backed by principles of PAS 2060 (Carbon Neutrality), they seek to break the greenwashing cycle.
Mel is joined by Harry Grocott, CEO and Co-founder of Treeconomy, to discuss their credible carbon offsetting schemes and the innovative technology they use to help quantify the value of nature.
You’ll learn
● Who are Treeconomy?
● What is the difference between services offered for landowners and Offset buyers?
● Can you quantify the value of nature?
● How can people be sure that they don’t fall prey to Greenwashing?
● How can someone go about buying and monitoring offsetting credits?
● Are Treeconomy’s carbon offsetting schemes verified?
Resources
● Treeconomy
● Sherwood
● ISO 14064
● PAS 2060
In this episode, we talk about:
[00:30] Catch up our episodes covering the Sustainable Development Goals (Part 1 / Part 2), ISO 14064 and PAS 2060.
[01:00] Treeconomy are a company that offer credible carbon offsetting schemes – they are one of the few companies who are recognised by PAS 2060 (the Standard for Carbon Neutrality)
[02:05] Harry Grocott (CEO) introduces Treeconomy - A nature based, carbon removal and restoration company that operate in the UK and Internationally. They offer schemes that work towards afforestation, peatland restoration, rewilding ect. They are also keen to enable evidencing the impact, developing a software platform, remote sensing, and AI technology to do so.
[03:41] They are part of the Centre for climate change innovation which is an initiative of Imperial College London and the Royal Institution to catalyse innovation of all forms that address the causes and effects of climate change.
[04:22] What is the difference in services for Landowners and Offset Buyers? For landowners, Treeconomy can help you change land use from one to another. I.e changing land used for sheep grazing into something more carbon intensive. Treeconomy will ensure that any project started with them is a verified Carbon Scheme – in-line with the woodland carbon code. Once your project set up has been completed and verified, Treeconomy will assist in the sale of credible carbon credits.
[07:22] For offset buyers: Treeconomy offer a wide range of projects and varyingly priced carbon credits.
[07:45] Can we quantify the value of nature? Short answer right now is no, but there is a lot of nuance. Nature offers ecosystem services i.e. farms offer a calorific benefit, we can put a price on the value that offers. The same principle applies to resources such as wood or oil. Now we are gaining the ability to quantify CO2 removal, which is undeniably valuable to humanity.
[09:18] Other more recent services such as biodiversity projects are a bit harder to quantify – as they vary so much depending on the country. However, we are starting to assign value to these.
[12:15] How can people be sure that they don’t fall prey to Greenwashing? There are 2 main issues to consider: 1) Are your carbon credits credible? 2) what claims are top management making?
[12:44] Tackling claims made by leadership: ISO standards are starting to solve this issue. There are clear requirements and certifications that need to be in place to back those claims.
[13:00] Tackling carbon credits: The carbon offsetting market is heavily unregulated currently. Essentially it’s a lot of people trading in invisible gas. There are a number of carbon standards (Not quite at the same level as ISO Standards), such as the Woodland Carbon Code and the Peatland Code, and Internationally there are standards such as Verra VSC – unfortunately, a lot of these standards aren’t very robust and aren’t enforced.
[15:30] Many companies will often look to buy the cheapest offsets available, which are likely to be non-credible and will provide no evidence of actual offsetting occurring. But, there are a lot of new companies emerging that provide tangible evidence of offsetting (such as Treeconomy 😊)
[18:30] How can someone go about buying and monitoring offsetting credits? If you don’t want to use a company like Treeconomy, you would need to directly contact and purchase credits from a company who is developing a project.
[19:23] Treeconomy have created a platform called Sherwood – this displays all the projects they are helping to develop, which also tells you who the landowners are and the carbon inventory attached to each project. It can also help you evidence credits purchased, whether they are historic or future carbon removal.
[21:30] Not many companies offer comprehensive reporting and evidencing of carbon credits in practice. Treeconomy use a range of methods such as drones, satellites and AI programs to report back, and aim to make getting this information as easy as possible for credit purchasers.
[23:20] How did Harry get into this business? Starting off studying geography and Science – he later went onto work in finance for 3 years and qualified as a finance adviser. While working he realised that the amount of money available is rarely the issue, rather the use of it. He saw that there was a large gap in funding for climate change mitigation and adaptation – but not enough money was going towards it. He began wondering why more couldn’t be invested and so decided to study climate change management and finance (partly though Covid), where he met his co-founder. After getting some Government grant funding, investors and landowner partners, they have flourished over the last 3 years.
[27:00] Are Treeconomy’s offsetting schemes verified? Yes – they work under the UK woodland carbon code (and soon the peatland carbon code). They are also working to create a new protocol to tackle rewilding, including how the value and progress can be tracked. Internationally they will be working under Verra.
[29:05] Treeconomy can help to provide detailed evidence of carbon offsetting thanks to their reporting capabilities, this can be passed onto 3rd party auditors to verify in-line with any carbon Standard.
[30:00] You can find Treeconomy via their website, LinkedIn, Twitter and Instagram 😊
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Anyone with a current ISO 27001:2013 certificate will be required to update and add certain elements in their existing Information Security Management System to ensure compliance to ISO 27001:2022 ahead of the October 2025 deadline.
Over the past few weeks, our mini-series has covered the fundamental changes to the Standard, along with tips on how to plan and Implement the required updates.
Join Mel this week as she explains the final few stages of an ISO 27001 transition, including the Internal Auditing and final preparation ahead of a Certification Body visit.
You’ll learn
● What needs to be audited?
● What do I need to do to prepare for the Certification Body visit?
● How can you get a free copy of ISO 27001:2022?
Resources
● Isologyhub
● ISO 27001 Transition Programme
● What you need to know to transition to ISO 27001:2022
In this episode, we talk about:
[00:44] Catch up on the last two episodes before listening to this one: What you need to know to transition to ISO 27001:2022 / What changes need to be Implemented to transition to ISO 27001:2022
[01:00] The last stages are all about gathering evidence of compliance against new and updated clauses and controls
[01:28] Make sure you plan your transition visit well in advance – If you leave it too late you may incur additional fees for more days or possibly even for a full certification if you miss the deadline.
[02:15] This process for transition is fairly consistent among Certification Bodies. It typically includes a Readiness Review and a transition visit where they will review evidence of compliance against the new controls.
[02:45] You can get a free copy if you sign up to our Transition Programme by April 1st 2023)
[02:55] The last stage ahead of the transition visit is Internal Auditing. For those still planning their 2023 Internal Audits, you may wish to Implement the changes earlier in the year with a view to audit the changes in the later half of 2023. Ensure that you allow time to build evidence of compliance ahead of a transition visit.
[03:45] If you need a bit of extra help, we include Internal Auditing within our transition programme – this will typically take 1 day.
[04:30] We can also support you during your transition visit – this could be on-line or on-site, which would depend on your Certification Bodies preference.
[05:20] Currently many Certification Bodies are suggesting a half day for the Readiness Review and another day for the transition. Some may choose to include this transition as a part of their annual Surveillance visit to help save on costs. If you have a Surveillance coming up, it’s worth getting in contact with them to see what they would recommend regarding your transition.
[05:43] We advise that you also ask your Certification Body, when they will be UKAS accredited for ISO 27001:2022 – they may not be ready complete a transition visit until the later half of 2023.
[06:35] For our global listeners, your Certification Body will have an Accreditation Body that needs to verify their ability to conduct transition visits. For the UK this is UKAS, but it may differ for other countries.
[07:15] Don’t leave this until last minute! Based on previous experience with transitions, we’ve found companies that leave it until a few months before the deadline often can’t transition in time, and end up having to pay up for a full Stage 1 and 2 Assessment in order to keep their certification.
Grab a copy of our ISO 27001:2022 Guideline to the changes here
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The updated ISO 27001:2022 has had several changes, including the addition of 11 completely new controls and the merging of 56 other controls into 24 newly titled controls.
These changes mean that anyone with a current ISO 27001:2013 certificate will be required to update and add certain elements in their existing Information Security Management System to ensure compliance to ISO 27001:2022 ahead of the October 2025 deadline.
Join Mel this week as she explains the changes that need to be made, including what key documentation requires updating to align with ISO 27001:2022.
You’ll learn
● What changes need to be made to your existing Information Security Management System?
● What key documents need to be updated?
● How can you get a free copy of ISO 27001:2022?
Resources
● Isologyhub
● ISO 27001 Transition Programme
● What you need to know to transition to ISO 27001:2022
In this episode, we talk about:
[00:44] In the last episode we covered the planning stages for your transition – catch up here
[01:02] We have a free ‘Guide to the ISO 27001 Changes’ available – simply fill out the form at the end of the Show Notes to download your copy
[01:29] You should have a copy of ISO 27001:2022 ahead of Implementing the changes (you can get a free copy if you sign up to our Transition Programme by April 1st 2023)
[01:35] Before you move onto Implementation, ensure that you have: planned back from your transition date, have an understanding of the new controls and had a Discovery session / Gap Analysis to see where the gaps in your current system are
[02:11] This is also a good opportunity to revamp your Management System! We have a few older episodes to help you with this: #102, #103, #104
[02:50] What needs updating? This will include:
[03:45] At this stage you need to look at what controls you have in place – there may be some you can now merge together to reduce any paperwork involved.
[04:25] We have some tools available to tackle the new controls (i.e Threat Intelligence, data masking, physical security monitoring ect) if you need some extra help
[04:50] It’s not just about updating documentation, you will need to fully implement and communication these new controls to the wider business. You may find that you already have some controls covered, but not yet formalised.
[05:30] The main aspect of the Implementation phase is to address the gaps found during the Gap Analysis. For example, new controls such as data masking, threat intelligence and web filtering, which you may not have considered seriously before, now need to put formal documented measures in place to address it.
[06:26] Communication and evidence should be at the forefront of your mind when updating your Info Sec Management System.
[06:39] Don’t just implement controls for the sake of it – considering how they are going to reduce risk and how they’re going to make a difference to improve your Risk Register and Statement of Applicability.
[07:00] The Implementation phase of our Transition Programme is 1-3 days depending on your level of required support
[07:54] You should also consider creating a Communication Plan to share knowledge of these changes to the wider business. Make sure you also compile any evidence of training on new elements of your Management System too. We will have Coffee Break Training available on the isologyhub which could help with this.
Grab a copy of our ISO 27001:2022 Guideline to the changes here
Keep an eye out for next weeks episode where we explain how to complete your ISO 27001:2022 transition.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27001 2022 is here, which means it’s time to start thinking about starting the transition process. While the deadline is set at December 2025, we recommend making a start on planning now!
If this is all news to you, check out our previous three episodes, where we reviewed all the major changes to ISO 27001, including clause updates and the 11 completely new controls added.
Join Mel this week as she explains what you need to know before embarking on your ISO 27001 transition journey, in addition to a summary of our transition programme.
You’ll learn
● How to plan for your ISO 27001 transition
● How can Blackmores help you?
● How can you get a free copy of ISO 27001:2022?
Resources
● Isologyhub
● ISO 27001 Transition Programme
● High level overview of ISO 27001 2022 Control changes
In this episode, we talk about:
[00:44] Businesses have until December 2025 to transition to the updated version of ISO 27001:2022 – but don’t wait until the last minute! Certification Bodies get really booked up in the last year, and you could risk losing your certification and paying for another Stage 1 and 2 Assessment.
[01:30] We recommend that you start thinking about your transition in 2023 so you have everything in place to start the process in 2024.
[02:28] As a recap – the major changes to ISO 27001:2022 are: 56 controls have been merged into 24 newly titled controls, the addition of 11 completely new controls and controls are now categorised into just 4 groups instead of the 14 from the previous version.
[03:00] ISO 27001:2022 Guideline to the changes available – Simply fill out the form available at the end of the show notes to grab a copy!
[04:25] Over the next few episodes, Mel will talk through the process of planning, implementing and preparation for the Certification Body transition visit.
[05:51] All steps of the transition process are laid out in our Transition Programme, which includes: an awareness video, a transition action plan, Implementation of changes, Internal auditing of the changes and some optional support during the Certification Body visit.
[08:45] The Planning Phase: We recommend trying to combine your transition visit with your next Surveillance visit – you can have a chat with your CB to see if that’s possible. This may not be possible if your Surveillance is coming up very soon, as you need time to implement the changes needed. Those that have it in say 6 or more months’ time would be in a good position to make the request.
[09:30] Certification Bodies are recommending an extra half day for transition - some may require a desktop review ahead of the actual visit. Combining this visit with your Surveillance is a good way to reduce costs.
[10:30] When planning out your timescales for transition, don’t forget to inform Leadership and key personnel involved in the running of the Management System about the expected changes to come – and plan in time for them to help with the implementation.
[11:10] Understanding the changes: We gave a high-level overview of the 11 new controls in our last episode. We will also have 11 Coffee Break Training courses covering the controls in more detail, available from March 31st 2023 on the isologyhub.
[12:11] Offer: We’re including a free copy of ISO 27001:2022 for those that sign up to our Transition Programme before April 1st 2023.
[12:34] You may get asked for a copy of the Standard at your transition visit – as having a copy can come under ‘other’ legal requirements.
[13:10] Discovery Phase: We have a transition checklist which can help you identify where the gaps are in terms of compliance with the new controls. You may already have some of it in place!
Grab a copy of our ISO 27001:2022 Guideline to the changes here
Keep an eye out for next weeks episode where we dive into how to Implement the changes…
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27001, The Information Security Standard, was updated in October 2022. While there is a 2-year grace period for transition, we would urge everyone to make a start on implementing the changes to ensure you are compliant with latest best practice standards.
Over the last two episodes, we’ve gone over the key changes and explored the specific clause updates in more detail. As mentioned in the first episode of this mini-series, there have been 11 new controls added to ISO 27001:2022.
Mel is once again joined by Steve Mason, Managing Consultant here at Blackmores, to discuss the 11 new controls added to ISO 27001:2022 and their purpose.
You’ll learn
Resources
In this episode, we talk about:
[01:00] A quick overview of the key changes - 56 Controls combined into 24 newly titled controls, 11 new controls added and 58 existing controls remained unchanged.
[02:30] We have been over a few of the new controls in ISO 27002:2022 in more detail in a few previous episodes: #111, #112, #113, #114
[02:50] These new controls are nothing to worry about – they are simply aligning the Standard with more modern security considerations. You may already be complying with them!
[03:32] Control A.5.7 Threat intelligence – ‘To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken.’ – This can come from many different sources, such as the NCSC or local police websites. There are also additional tools you can add to detect possible phishing attacks. This also includes consideration to external threats – Information Security is about much more than just protecting data! It also includes physical security.
[05:33] Control A.5.23 Information security for use of cloud services – “To specify and manage information security for the use of cloud services.” – More and more businesses reply on cloud-based computing. It’s important to verify the security of your service provider to ensure it’s adequate. You can check to see if they have any valid Information Security related credentials such as CSA Star, Cyber Essentials, SOC. You could also adopt principles of ISO 27017 (certification for cloud security), ISO 27018 (Protection of PII in the public cloud) and ISO 27701 (PII security Standard).
[08:30] Control A.5.30 ICT readiness for business continuity –‘ To ensure the availability of the organization’s information and other associated assets during disruption’ – There a few standards that could assist with this, including ISO 27031 (ICT readiness for Business Continuity). Those that have ISO 22301 may want to look at how ISO 27001 elements can be integrated and improved in any disaster recovery plans. ISO 27001 needs to be an integral part of any business continuity plans – not just a bolt on. Small business may not want to conduct a full business impact analysis, but should carry out a risk assessment around business continuity at the very least.
[11:30] Control A.5.30 ICT readiness for business continuity – further considerations: A key focus of this part of the Standard is Recovery Time Objectives and Recovery Point Objectives. Overall, the whole business continuity aspect of the updated ISO 27001:2022 may take a bit of work to implement, but you will ultimately be much better off in the event of a disaster or security incident. For further guidance, you may want to check out an older non-certifiable standard, BS 25777 (ICT continuity).
[13:20] Control A.7.4 Physical security monitoring –‘ To detect and deter unauthorized physical access.’ - This can include things like CCTV, access control, swipe cards ect. This also includes the ability and regular practice of monitoring these access methods, for the purpose of detecting any anomalies.
[18:56] Control A.8.9 Configuration management – ‘To ensure hardware, software, services and networks function correctly with required security settings, and configuration is not altered by unauthorized or incorrect changes’ – Configuration for things like a firewall, software, any hardware devices, passwords ect should be documented, explained and monitored on a regular basis to ensure nothing has been changed without notifying the relevant people. ISO 20000 includes a helpful section around configuration if you require further guidance.
[21:41] Control A.8.10 Information deletion – ‘To prevent unnecessary exposure of sensitive information and to comply with legal, statutory, regulatory and contractual requirements for information deletion.’ – This already existed in the Standard, it has simply been clarified further. You will now need to prove that data has been deleted as required, if you use a 3rd party for this, they will need to provide the relevant certificates.
[22:05] Control A.8.11 Data Masking – ‘To limit the exposure of sensitive data including PII, and to comply with legal, statutory, regulatory and contractual requirements.’ – You have 3 options for data masking: Obfuscation, pseudonymisation and annoymisation. This also helps to comply with GDPR requirements.
[24:10] Control A.8.12 Data leakage prevention – ‘To detect and prevent the unauthorized disclosure and extraction of information by individuals or systems.’ – This control has made a return from the 2005 version of ISO 27001. Businesses should have systems in place to monitor any particularly large data downloads – or even possibly large print batches. You should also ensure that you have a secure email system in place as well as VPN’s and regular security training to sure up your security to prevent any potential leaks.
[27:00] Control A.8.16 Monitoring Activities – ‘To detect anomalous behaviour and potential information security incidents.’ – Appropriate monitoring should be in place to detect any potentially dangerous or malicious behavior.
[28:00] Control A.8.23 Web Filtering – ‘To protect systems from being compromised by malware and to prevent access to unauthorized web resources.’ – Your systems should be set up in a way to prevent people from accessing unsecure or unsavory sites. This could include Social Media sites – but be mindful that there may have to be exceptions for marketing or communications personnel for those particular sites.
[28:00] Control A.8.28 Secure Coding – ‘To ensure software is written securely thereby reducing the number of potential information security vulnerabilities in the software.’ – If you have created your own secure coding, be sure to evaluate it against industry professional standards such as OWASP and NIST.
As a reminder, we’ll be running a mini-series through January and February on the updated ISO 27001:2022 in addition to how you can transition to the new version.
Keep an eye out for next weeks episode where we dive into the clause clarifications and control changes of ISO 27001:2022…
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
As many of you are aware, an updated version of ISO 27001 was published in October 2022. While there is a 2-year grace period for transition, we would urge everyone to make a start on implementing the changes to ensure you are compliant with latest best practice standards. But where do you start?
In the last episode, Mel and Steve gave an overview of the updated ISO 27001:2022, including a high-level look at some of the key changes.
In addition to the control changes, there have been several changes made to specific clauses within the Standard.
Mel is once again joined by Steve Mason, Managing Consultant here at Blackmores, to discuss the ISO 27001:2022 clause updates and their purpose.
You’ll learn
Resources
In this episode, we talk about:
[01:06] The changes to these clauses appear to align your Management System with the business – a key focus is integration.
[01:20] First change: Clause 4.2 Understanding the needs and expectations of Interested parties – ‘c) which of these requirements will be addressed through the information security management system.’ - This seeks to align the Management System with interested parties and identify where it may or may not be able to meet their needs and expectations.
[03:30] Clause 4.4 Information Security Management System – ‘The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.’ – There will be more focus on process flows and not Policies and Procedures. This can be further used to align the Management System with your business, by clearly identifying where it fits in with your business activities.
[06:14] Clause 5.1. Leadership – ‘Reference to “business” in this document can be interpreted broadly to mean those activities that are core to the purposes of the organization’s existence.’ – This acts more as a reminder to top management to ensure they include the Management System as part of the business and not just a bolt-on. It should be a part of the strategy and part of the business (part of the ship, part of the crew)
[07:42] Clause 6.1.3 Information Security Risk Treatment –‘ Note 2 in sub-clause ‘c’ now states ‘Annex A contains a list of possible information security controls.’ (it had previously read Annex A contains a comprehensive list of control objectives and controls.) – This simply means that you can add references to other controls outside of the list provided within Annex A i.e. NIST or Cyber Essentials. Though, do be careful to avoid doing this at minutia level, as that just increases Management System maintenance.
[09:15] Clause 6.2 Information security objectives and planning to achieve them –‘ A couple of extra points have been added to this clause: d) be monitored g) be available as documented information’ - The monitoring was previously a given, but not really specified. So now, you’ll have to demonstrate how you’re monitoring objective planning and achievements.
[10:24] Clause 6.3 Planning of Changes – ‘When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.’ – This has now been aligned more with ISO 9001’s approach to changes. All changes should be planned before implementation, and this now includes information security consideration. Fun fact – they forgot to include this clause in the Standard table of contents! (as of January 2023, this will probably be added later!)
[11:55] Clause 9.3.2 Management Review Inputs –‘ c) changes in needs and expectations of interested parties that are relevant to the information security management system’ – This just ensures that the needs and expectations of your Interested Parties are reviewed and not just left stagnant.
[13:20] To help you revamp your Management Review, check out episodes #99 and #100
As a reminder, we’ll be running a mini-series through January and February on the updated ISO 27001:2022 in addition to how you can transition to the new version.
Keep an eye out for next weeks episode where we dive into the clause clarifications and control changes of ISO 27001:2022…
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The long-awaited update of ISO 27001 arrived in October 2022, having gone 9 years since its previous 2013 iteration. Needless to say, it was much overdue.
The new 2022 version of the Standard includes 11 new controls and sees around 56 other controls combined into 24 newly titled controls.
In order to cover every aspect of the new Standard, we’ll be running a mini-series through January and February on the updated ISO 27001:2022 in addition to how you can transition to the new version.
Starting off the series strong, Mel is joined once again by Steve Mason, our very own Information Security guru, to broadly discuss the changes to ISO 27001:2022.
You’ll learn
Resources
In this episode, we talk about:
[01:50] Steve Gives an overview of what’s new in ISO 27001:2022 – The updated version of ISO 27001 was released on the 26th Oct 2022. The new version included 24 changes and clarifications within the main clauses.
[02:50] The controls for the new standard are now categorised into 4 groups: Organisation, People, Physical and Technology
[05:50] We covered some of the new controls in more detail in previous episodes: #109, #110, #111, #112, #113 and #114
[06:17] The 24 changes and clarifications to Clauses include older existing clauses which have been tidied up to be more transparent. We recommend reviewing to ensure that you are complying in a way that aligns with the Standard.
[06:35] There are 11 new Controls. 56 controls from the 2013 version have been reduced to 24 with 58 remaining unchanged. So, in short, Annex A has been simplified with less duplication of controls.
[07:44] Steve highlights section A.9 for Access Control as one of the much-improved controls – due to the lack of repetition and simplified requirements for compliance.
[08:35] Steve’s favourite update to the Standard: The whole Standard now collectively encourages incorporation into your business. Your ISMS should not feel like a bolt on, it should be a part of your businesses DNA.
[10:36] Steve’s favourite update to the Standard #2: It’s not a static Standard, it encourages development and continual improvement.
[13:45] For those completely new to ISO 27001 – check out our 3-part Steps to Success series which explains the Implementation process from start to finish.
[14:38] Listen to some of our client interviews to hear the challenges others faced when Implementing ISO 27001 in addition to the benefits gained as a result of adopting the Standard:
[14:50] Why would the business continuity elements of ISO 27001:2022 pose a challenge? There used to be a clause in the 2005 version of the standard which documented the need for a business impact analysis – this was removed in the 2013 version. The new ‘ICT readiness for business continuity’ control will require at the very least, a risk assessment.
[16:48] Steve recommends checking out the Plan, Do, Act, Check diagram in ISO 27031 (Guidelines for information and communication technology readiness for business continuity). It also includes some great guidance on business impact analysis.
[18:40] The ICT readiness control is not designed to be an all encompassing business continuity strategy – it’s designed to work in tandem with as existing one (you may already be certified to ISO 22301 Business Continuity Management).
[19:50] It’s highly recommended that if you don’t have a Business Continuity Plan or strategy – at least have a framework in place. Disasters by their nature are unpredictable, as is the resulting damage to an extent. You will not know the full extent until you’ve lived it – so don’t write an exhaustive 80+ page manual that no-one will read, document the what, who and how of getting yourself back up and running again.
[21:11] There has also been an update to ISO 27005 (Risk assessment in relation to info sec). It includes a new set of threat categories: physical threats, natural threats, infrastructure failures, technical failures, human actions, compromised services or functions and organisational threats. These may help you when putting a business continuity framework in place.
[22:05] Above all else – ISO 27001:2022 has modernised and aligned itself more with the likes of cyber essentials and NIST.
Keep an eye out for next weeks episode where we dive into the clause updates…
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Happy New Year! We at Blackmores hope you all managed to have a break over the holiday season and are gearing up for many challenges and successes in 2023.
As a reminder, we signed off last year by highlighting the top 5 podcasts as dictated by you, the listeners.
Before we dive into a brand-new year full of top tips, expert advice with industry leaders and client interviews, we’d like to take a step back and let the host share her reflections on 2022.
Join Mel as she shares her personal top 5 ISO Show episodes from last year.
You’ll learn
Resources
In this episode, we talk about:
[00:30] A reminder to listen to our last podcast, covering the top 5 podcasts as dictated by the listeners.
[01:21] #1 Episode 102 – What’s in a name? This episode features our Senior Isologist, Sarah Ball, as she explains the importance of giving a meaningful name to your Management System.
[03:40] What’s in a Name snippet – Full episode available in the ISO Show Archive
[08:01] #2 Episode 94 – The 7 Steps of Carbonology_ Reduce – Part 4 of the 7 Steps of Carbonology series, featuring our Carbonologist, David Algar. This episode delves into the creation and communication of a carbon reduction plan, and the benefits of reducing your footprint rather then relying on offsetting alone.
[10:14] The 7 Steps of Carbonology - Reduce snippet – Full episode available in the ISO Show Archive
[16:48] #3: Episode 117 PMC’s journey and ongoing success with ISO 27001– This is an interview with Philip Bailey, the Managed Services Director at PMC Retail, talking about their ISO 27001 journey. Philip shares his lessons learned and gives some top tips for anyone considering implementing the Information Security Standard
[17:58] PMC’s journey and ongoing success with ISO 27001 snippet – Full episode available in the ISO Show Archive
[24:00] #4: Episode 100 How to get the most out of your Management Review – Featuring Rachel Churchman, Managing Consultant here at Blackmores, this episode explores how added value can be gained from doing a Management Review. Mel and Rachel discuss various ways you can conduct a Management Review and what should be your key inputs and outputs.
[26:14] How to get the most out of your Management Review snippet – Full episode available in the ISO Show Archive
[30:41] #5: Episode 108 How to align your Management System with the Sustainable Development Goals– Following on from the Sustainable Development Goals summary episodes, Mel shares how you can align your Management System right now without the need for any ISO certification.
[32:37] How to align your Management System with the Sustainable Development Goals snippet – Full episode available in the ISO Show Archive
We look forward to bringing you even more amazing content in 2023, so stay tuned! 😊
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
It’s been a busy year here at Blackmores! Somehow, we managed to fit in the time to publish 37 new ISO Show episodes.
It’s been a mix of knowledge sharing, top tips, advise and stories from our very own consultants and clients – and we’re looking forward to sharing even more with you next year!
We thought it’d be good to end this year on a look back at 2022 and highlight 5 of the most listened to episodes of the ISO Show across its many platforms.
Join Mel as she shares some snippets from our top 5 most popular episodes this year.
You’ll learn
Resources
In this episode, we talk about:
[00:30] The top 5 episodes of 2022 have been selected based on which episodes have been listened to the most.
[01:00] #1 98 What is a Management Review? This is an episode that appeals to a more general audience as Management Review is a requirement of many ISO’s. This was the 1st of a 3-part series and explains the basics of what a Management Review is and what it typically includes.
[02:47] What is a Management Review snippet – Full episode available in the ISO Show Archive
[05:40] #2 100 How to get the most out of your Management Review – Part of the Management Review series – this episode includes Rachel Churchman, a Managing Consultant here at Blackmores. The episode explored various ways in which you can make your Management Review both more engaging and successful in achieving tangible outcomes.
[06:55] How to get the most out of your Management Review snippet – Full episode available in the ISO Show Archive
[13:20] #3: 106 What are the Sustainable Development Goals – This is a 2-part series which explores the 17 SDG’S and how ISO Standards can meet certain goals. In both episodes, Mel gives specific examples of the many ISO’s that align with the SDG’s.
[15:08] What are the Sustainable Development Goals snippet – Full episodes available in the ISO Show Archive - Part 1 / Part 2
[22:08] #4 and #5: 109 What’s new with ISO 27002:2022? / 110 What are the 11 new controls in ISO 27002? – Both of these episodes shortly followed the release of ISO 27002 – A guidance document for ISO 27001. While not certifiable, it did give us an insight to the changes in ISO 27001 that were published later in the year. Episode 109 summarises how ISO 27002 works in relation to ISO 27001, along with a very brief summary of the changes. Episode 110 goes into more detail on each of the 11 new controls – and features our very own Managing Consultant, Steve Mason.
[24:38] What are the 11 new controls in ISO 27002 snippet – Full episode available in the ISO Show Archive
That’s it from us for 2022! We hope you all have a wonderful Christmas and New year - See you on the other side in 2023 😊
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Currently, there are around 1,077,884 valid ISO 9001 certificates globally – which beats the second runner ISO 14001 by over 600,000!
There is no doubt that the Quality Management Standard, ISO 9001, is still the most widely adopted ISO Standard – and for good reason!
ISO 9001 is basically a model for running a successful and profitable business. It provides a common framework for things that all businesses should have in place, including defining your companies unique ‘way of working’.
In addition to being a blueprint for a business’s operation, there are many other benefits to be gained from implementing ISO 9001. Today, Mel explains a few of these benefits in greater detail.
You’ll learn
Resources
In this episode, we talk about:
[00:30] Why talk about ISO 9001 benefits? Often times, Mel gets asked for benefits of ISO 9001 so a business case can be put forward.
[01:00] What is ISO 9001? For a detailed break down of the Standard, go back and watch ‘Episode 36 – What is ISO 9001?’
[01:45] For those that have Implemented ISO 9001, what are the benefits? We’d love to hear from you! If you have some stories to share – feel free to leave a comment on which ever media player you’re listening on – or email us. We’d love to share some of your experiences in a future episode.
[02:09] Benefit #1: Win new business – From a sales and marketing perspective, ISO 9001 is essentially a passport to trade. It demonstrates credibility to Stakeholders as it’s a mark of quality.
[02:55] Benefit #2: A framework that can fit any business – This can be for any industry sector and business size. It helps businesses figure out what is working well and what’s not working so well.
[03:10] Benefit #3: Identify opportunities for Improvement - It helps businesses figure out what is working well and what’s not working so well. It can help identify issues such as: Bottlenecks in processes, resourcing and external factors.
[04:05] ISO 9001 helps you to look at your business – warts and all. It does no one any good to bury their head in the sand and ignore issues, especially as Stakeholders and clients will see through this.
[04:40] Benefit #4: Put quality controls in place to mitigate risk and raise your standards – If you have complaints or need to do a product recall – you need processes in place to handle this. ISO 9001 gives you the tools to do so, creating an effective framework everyone can follow.
[05:40] Benefit #5: Improve efficiency – ISO 9001 helps you identify the best way of working and pushes you to optimise that. That could include eliminating aspects of you business that waste time, or create burdens.
[06:05] Benefit #6: Creating a unique Blueprint – ISO 9001 isn’t an out of the box solution – it can be tailored to your way of working. It helps to establish relevant Policies and Procedures that improve your business operations.
[06:24] Benefit #7: Enhancing customer satisfaction and employee retention – Good quality business practices will inevitably help you to keep ahold of good clients – and good employees too! This can be achieved by having clear roles and responsibilities in addition to vision and goals for the business.
[07:20] Benefit #8: Increase profitability – Businesses often look at the cost of poor quality – where is your business leaking money? Addressing those issues is a direct cost saving.
[08:21] Businesses who have grown through acquisition often find ISO 9001 a great tool to help standardise their way of working, so they can easily integrate other businesses and services.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Data breaches have risen by 70% globally in Q3 of 2022, reenforcing the requirement for many to seek out Information Security solutions, especially those within the tech space.
Today we speak to Triaster, who have been in operation since 1994, providing businesses with process mapping and execution software to help drive business improvement.
Triaster’s Business Operations Manager, Jane Duncan, explains why they sought to implement ISO 27001, what challenges they faced and what they learned during their certification journey.
You’ll learn
Resources
In this episode, we talk about:
[00:54] Get to know Jane Duncan – Triaster’s Business Operations Manager who has recently started fostering dogs for a local charity.
[01:41] Who are Triaster? In short, they build software solutions that drive business improvement. They are a thought leader in their field and strive to create new software to meet business needs.
[02:25] What was the main driver for achieving ISO 27001? In 2020, they had certified to the Quality Standard, ISO 9001, and saw the many benefits that come with ISO certification. They saw ISO 27001 as both an opportunity and a necessity due to their work within the IT industry. ISO 27001 is seen as a mark of trust and provides a central framework to improve data security.
[04:28] How long did It take to implement ISO 27001? They started looking at certification bodies and consultants to help with implementation in March 2021. The project overall lasted six months, with their assessments taking place in September and October of the same year. They also chose to recertify to ISO 9001 at the same time – this aligned both Standards under one Integrated Management System.
[06:35] If you are considering implementing multiple ISO’s, it’s recommended to integrate them into a single Management System. This reduces the costs of implementation and is overall easier to maintain.
[07:17] What was the biggest gap identified in Triaster’s initial Gap Analysis? They had a lack of security policies in place in addition to a lack of processes that would have mitigated potential data security risks.
[08:00] What was the biggest difference ISO 27001 made? They now do regular annual SWOT and PESTLE’s that are evaluated at Management Reviews. Risks identified during those reviews are added to a risk register and are used to develop the necessary objectives and controls needed to mitigate future risk.
[08:38] Other differences include the ability to track non-conformities, security risks and opportunities for improvement. They also have the confidence to prove their data security credentials to clients and have the required documentation to back it up. Tendering processes are also made easier by having ISO 27001 as it is often a requirement that can now be ticked off.
[09:25] Triaster use Infrastructure partner (who are also ISO 27001 certified) and can now hold them accountable for the services they provide.
[09:50] Jane states that they are now a much better business following the Implementation of both ISO 9001 and ISO 27001 – continually improving their processes and scrutinising working practices.
[10:54] All of the same security practices can be done by those who are homeworking at Triaster
[11:05] What has been the main lesson learned? The process if certification is a journey – it’s about continually improving and truly adopting the ethos of Information Security into every aspect of the business.
[11:52] What are the main benefits? They hope their clients can see their efforts and have confidence in Triaster’s ability to keep their data secure. They also now have the processes in place that drive continual Improvement.
[12:33] Jane’s top tip: Document what you do as a business and look for gaps. Also, certification is a journey, and you shouldn’t stop striving to improve once you achieve certification.
[13:00] What book would you recommend and why? Internal Auditing in plain English: A simple guide to super effective ISO Audits by Craig Cochran
[14:15] Jane’s favorite quote: “No one is you, and that is your superpower”
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
All companies have a legal obligation to comply with existing legislation – it’s the law!
Failure to comply to legal requirements can be costly in terms of fines and reputational damage if an incident occurs. So, it’s in your best interest to ensure you can identify all applicable compliance requirements.
Most ISO’s specify a requirement to identify legal compliance requirements, and in our experience, the most effective way to do so is through the creation of a Legal Register.
Mel is joined by Sarah Ball, A QHSE Consultant here at Blackmores, to discuss how you can create your own Legal Register and keep up-to-date with changes in legislation.
You’ll learn
Resources
In this episode, we talk about:
[01:06] Why do you need to comply with Legislation – quite simply, it is the law! It can be very costly for you in both a financial and reputational respect.
[01:25] There is a requirement for identifying legal compliance requirements in most ISO’s i.e. ISO 45001 (Health and Safety) and ISO 14001 (Environmental)
[02:33] A Legal Register is not a requirement of any ISO – but we find it is the most effective way of documenting and keeping track of changes in applicable legislation.
[03:05] Why is it so important to manage legal compliance? Besides the financial and reputational cost of not complying with the law – it’s a way to protect your business. The law is there for a reason and it is often times to protect individuals or communities.
[04:35] You will need to take a proactive approach to find out what legislation is applicable to you.
[05:40] How can you identify your legal obligations? Firstly, do some basic research, start by visiting reputable industry authorities as they will likely have some guidance available i.e. The HSE Website or the Legislation.gov website. There are also subscription services available that give you an overview of what may be applicable to you and notify you of any updates. Finally, you can look to a specialist consultancy to help you.
[09:05] We do have a module on Legal Compliance available in the isologyhub!
[10:05] Why is it important to have a legal register? You will have to keep track of a lot of legislation! By documenting it, you have full visibility and can identify any gaps. You can also assign accountability against each piece of legislation, so the responsibility can be shared and managed.
[11:40] Your brain is for thinking and processing, not remembering. By documenting information, you create a ‘second brain’ to free up your brain for more important tasks – We recommend checking out the ‘Productivity Ninja’ series of books for more helpful organisation and prioritisation tips!
[12:28] What does a Legal Register look like? It’s typically a table of information – we use spreadsheets but any format is fine. Key columns we use identify the name of the legislation or contractual obligation, a link to the legislation, the requirements and purpose (what does this legislation mean to you?), A link to any further guidance and description of what good looks like to you i.e an example of evidence of compliance. You could include a column for accountability.
[16:00] How do you create a Legal Register? First, set up your table, next go out and find your applicable legislation, confirm and document your requirements in regard to the legislation, then assign accountability within the organisation. You may want to consult stakeholders to complete the obligations and figure out what good looks like. It is also good practice to do a legal compliance audit to ensure you are meeting obligations and identify any gaps.
[17:50] You can document other requirements in the Legal Register – this can include Service Level Agreements or even any ISO standards you’re certified to. It is advised to add any contractual requirements with customers or possibly landlords or suppliers. If you are a trade body that has a code of conduct, we recommend you include that too.
[21:00] Sarah’s top tip: When creating new processes or updating existing ones, it’s always good to look back at the Legal Register and check that any changes you’re making aren’t going to affect anything in terms of compliance.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
We have over 17 years experience of implementing various ISO’s – and we’d like to share some insight into our proven methodology.
Our regular listeners may be familiar with the term ‘isology’ from previous episodes where we’ve highlighted our online platform – the isologyhub. But what is isology exactly?
Put simply, isology is our 7-step method for implementing any ISO Standard. Join Mel this week as she breaks down each of the 7 steps, including the planning, creation and review of an ISO Management System.
You’ll learn
Resources
In this episode, we talk about:
[00:31] An overview of isology – a methodology for implementing any ISO. Find out more over on the isologyhub
[01:08] How the isology methodology was created – 17 years in the making with the help of our consultants.
[01:33] A brief overview of the 7 Steps of isology
[03:05] 1st Step - Plan: Get a copy of the Standard, determine your scope, timescales, leadership commitment, resources and selecting a Certification Body. Some choose to implement the system but leave out the badge. There are ISO’s that aren’t certifiable but good to have i.e. ISO 20400 Sustainable Procurement.
[05:38] 2nd Step – Discover: Time to understand what you have in place already and what you’re missing – this is done through a Gap Analysis.
[06:35] 3rd Step - Expose: This is where we look at risks and opportunities related to your desired Standard (both internally and externally). This is typically done through a SWOT and PESTLE. A Risk Register may be created to capture the findings to be addressed later. Companies are also encouraged to create a Legal Register to keep track of all their statutory, regulatory and contractual requirements.
[08:41] 4th Step - Create: Time to review the requirements of the Standard in terms of documentation – and create what’s needed. This includes capturing your way of working with documented Procedures – make sure you have the relevant staff involved in their creation.
[10:05] 5th Step - Launch: Once the Management System has found it’s home (usually an intranet or SharePoint) – you need to communicate it. Consider the type of launch you want and who will be involved. Make sure you encourage engagement with the Management System.
[11:18] 6th Step - Engage: There’s little point in having a Management System if people don’t know about it or have little interest in it. You should train your staff on the Management system, so that they are aware of your policies and procedures and where to find key documents. You must verify compliance through Internal Audits – this is a requirement of any ISO Standard.
[13:09] 7th Step - Review: Time to take a step back and look at what’s been achieved and what’s been highlighted as areas for improvement through your Internal Audits. There’s a set list of criteria in each ISO Standard to help you plan an agenda for the Review.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 22716 sets out the framework for a quality management system for anyone involved in the manufacture of cosmetics and other healthcare related products. While this Standard’s focus is on the manufacture of cosmetics specifically, many of the requirements can apply to any manufacturing process, especially those that involve a risk of contamination.
This Standard sets out clear guidance to help you ensure you align with Good Manufacturing Practices (GMP), but how do you go about implementing it?
In our last episode of the ISO 22716 series, we bring back Derek Hall once again to share his experience with implementing ISO 22716 and offer some top tips to get you started.
You’ll learn
Resources
In this episode, we talk about:
[01:10] If you want a recap on the Standard – Watch our first episode in the ISO 22716 series
[01:50] Key considerations for Personnel: Establish an Organisational Chart (with clear references for the responsibility and authority of quality issues), use a Skills matrix to help determine where training gaps are, develop procedures and processes to control what people can and can’t do in certain locations.
[08:33] Key considerations for Premises: Manufacturers should consider how the building is designed and laid out, ensure that there is a good flow for materials, have effective filling and packaging areas, introduce efficient sanitation programs, what can you do to minimise mix-ups?
[10:45] Key considerations for Premises: Manufacturing areas should only be accessed by authorised personnel, you should have effective measures in place to prevent pests – this includes the exterior as well as the interior of your buildings! You might want to consider external contractors for pest control.
[13:05] Key considerations for Equipment: Ensure all equipment is fit for purpose, efficient and has the ability to be cleaned thoroughly, make sure any calibrations are assessed and documented, equipment should be laid out in a way to ensure a flow of materials, make sure there is a clear segregation of manufacturing and storage areas.
[16:45] Key considerations for Raw Materials and Packaging Materials: – Raw materials should be well stored and clearly labelled, source your materials from trusted and accredited suppliers, have a controlled and quality approved list of suppliers and vendors (Do these suppliers provide proof of quality? Set out your minimum requirements for quality and ensure suppliers fulfill these)
[19:15] Key considerations for Production: All raw materials and manufacturing batches should be identified by a unique code for control and traceability, regular quality control inspections should take place, determine what methods are used to ensure that products meet customer expectations, samples should be taken during set stages of manufacturing to check for quality.
[21:20] Key considerations for Finished Products: Finished products should not be stored on the floor (use pallets), do what you can to minimise contamination during storage, ensure all staff know how to store products correctly and what to do if there is contamination, have defined acceptance criteria for products, have clear labelling, any faulty products should be labelled as ‘quarantined’ or ‘rejected’ and moved to a designated area.
[24:48] Key considerations for Quality Control: Ensure all raw materials, components, bulk product and packed products pass established quality tests, obtain Certificates of Analysis, have acceptance criteria forms – fill these out at all relevant stages.
[26:30] Any products out of specification should be investigated by authorised personnel, only those responsible for product quality can decide to destroy or reprocess products.
[27:25] Key considerations for Wastes: Identifiy different types of waste, ensure these wastes are disposed of in a timely and sanitary manner, have processes in place for collection, transportation, storage and disposal of waste.
[28:48] Key considerations for Wastes: Where necessary, allocate a code in line with the European Waste Catalogue, ensure that correct waste carriers licenses are received and maintained.
[29:19] Key considerations for Subcontracting: You can subcontract a lot of aspects i.e. cleaning, pest control, packaging ect. Ensure that any subcontractors are reviewed and approved, have clearly defined written agreements in place that outline roles and responsibilities (this can be a contract or just strictly in writing)
[32:10] Key considerations for Deviations: Deviations can happen anywhere, have a regime in place to investigate complaints, in the case of serious deviations that could affect health and safety – ensure you have an effective recall process in place.
[33:25] Key considerations for Complaints and Recalls: All complaints should be communicated to the plant, all complaints should be investigated and followed-up, if a recall needs to happen – ensure that appropriate steps are taken to recall and then take corrective action.
[12:05] Key considerations for Change Control: Have a change management system in place to document any changes (and define if they are fixes, enhancements or major revisions), you need to establish who can: request, approve, develop, test and implement these changes.
[36:35] Key considerations for Internal Audits: Internal audits need to be carried out in regular intervals, a minimum of 1 a year (but we recommend more!), track findings and document any corrective actions taken in a Continual Improvement Log.
[38:17] Key considerations for Documentation: Documents are used through the whole process – ensure all documents used are approved, signed and dated by authorised personnel, key documents should be version controlled.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 22716 sets out the framework for a quality management system for anyone involved in the manufacture of cosmetics and other healthcare related products. While this Standard’s focus is on the manufacture of cosmetics specifically, many of the requirements can apply to any manufacturing process, especially those that involve a risk of contamination.
As discussed in last weeks’ episode, having ISO 22716 is essential if you are manufacturing or distributing within the EU. Besides being a legal requirement for certain regions, what other benefits can ISO 22716 offer?
Today, Mel is joined by Derek Hall, a Senior Consultant here at Blackmores, to explain some of the key internal and external benefits of ISO 22716 and how it can work in tandem with other ISO Standards.
You’ll learn
Resources
In this episode, we talk about:
[00:50] Adoption of standards such as 22716 are often key requirements of Stakeholders
[01:15] One general benefit of implementing ISO 22716 is the ability to win new business by virtue of displaying compliance to EU regulations.
[01:40] What are the internal benefits? Firstly, it ensures you’re legally compliant
[02:10] ISO 22716 put controls in place that can reduce risk and hazards with product manufacture, storage and distribution.
[02:35] There can be tangible cost savings – Derek highlights a few clients who have taken a step back to correct and improve their internal processes, which in turn resulted in cost savings. Compliance can also help to avoid any fines
[03:29] It can help to avoid products being wrongfully distributed – which can be a very costly mistake, both in time, money and reputation.
[04:20] ISO 22716 can integrate seamlessly with other ISO Standards such as ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Health and Safety Management). They are all based on a similar framework and are designed to work together
[06:15] ISO Standards can act as a roadmap for managing a business – especially for micro businesses
[08:05] ISO Standards are all scalable and can apply to any size of business. So, if you were to acquire more sites, you can simply roll out your management system across the expanding business
[08:43] ISO 22716 is very clearly laid out and easy to follow
[09:30] What are the external benefits? It’s an internationally recognised Standard, and can be used for various marketing and tendering opportunities
[10:47] ISO 22716 is a mark of quality and displays a brands commitment to delivering quality products
[11:10] It promotes ethical behavior through your supply chain
[11:50] It promotes regulatory credibility – Ensures your products meet regulatory requirements
[12:05] It gives assurance that your product ingredients also meet legal requirements
[12:40] Some ISO Standards can reduce insurance costs – This is something we’ll explore in future episodes!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 22716 sets out the framework for a quality management system for anyone involved in the manufacture of cosmetics and other healthcare related products. While this Standard’s focus is on the manufacture of cosmetics specifically, many of the requirements can apply to any manufacturing process, especially those that involve a risk of contamination.
On the surface, ISO 22716 may be considered a niche Standard, so why it is still so widely adopted?
Today, Mel is joined by Derek Hall, a Senior Consultant here at Blackmores, to discuss the key drivers behind ISO 22716, including legal EU requirements and other related regulations.
You’ll learn
Resources
In this episode, we talk about:
[00:42] A brief summary of ISO 22716 – watch the last episode for a full summary
[01:25] Do you still need to comply with EU directives? Short answer – Yes, especially if you sub-contract parts of your manufacturing process / packaging or export product within the EU.
[02:00] Why was the Cosmetic Regulation (EC) No 1223 created? To streamline and modernize current legislation across Europe for Cosmetics (though this can also include hygiene products i.e. soaps, toothpaste, deodorants ect)
[03:30] What is the Cosmetic Regulation (EC) No 1223? This regulation establishes rules to be complied with by any cosmetic product made available on the market – to ensure a high-level of protection of human health
[04:21] ISO 22716 is the central pillar of the Cosmetic Regulation (EC) No 1223
[05:02] A bit of background to the EU adoption of ISO 22716 – On April 21st 2011 – ISO 22716 officially became the Good Manufacturing Practices Standard for cosmetic product across Europe. This created a harmonised approach that ensured cosmetic products are safely manufactured, stored and shipped.
[05:58] The whole regulation came into effect in July 2013. The laws for each nation had to follow this regulation – which included any relevant Standards or guidance affecting the cosmetic industry. This requirement also applies to any cosmetic manufacturers outside the EU that want to import into the EU.
[07:36] Who are the regulations applicable to? Anyone involved in the cosmetic products chain (European and non-European). This includes raw materials producers, product assembly, distributors, exporters ect
[08:05] ISO 22716 provides guidance for most parts involved in cosmetic production i.e. production, control, storage and shipment. However, it does not cover: safety for personnel (this may fall more under ISO 45001), protection for the environment, is not appliable to research & development and not appliable to the distribution of finished product
[09:55] ISO 22716 is almost 20 years old – so environmental considerations weren’t as much at the forefront of product manufacturing as they are today. Any manufacturers should be doing what they can about their impact regardless of current regulations (new versions may add guidance around this, so keep up-to-date with regulatory changes)
[11:45] Other applicable standards include: The two part ISO 16128 Standard:
ISO 16128-1: Guidelines on technical definitions and criteria for natural and organic cosmetic ingredients and products
ISO 16128-2: Describes approaches to calculate natural, natural origin, organic and organic origin indexes that apply to the ingredient categories
[13:58] COSMOS (standard Cosmetics Organic and Natural Standard) was created by many different International parties including BDIH (Germany), COSMEBIO & ECOCERT (France), ICEA (Italy), AISBL (Belgium) and Soil Association (UK). Its purpose is to define common requirements and definitions for organic and / or natural cosmetics.
[15:25] Standards are created collaboratively by technical committees made up of global experts of their respective fields – they take years to develop to establish best practice
[16:09] ISO 22716 has been approved by many regulatory bodies around the world, including the ICCR (The International Cooperation on Cosmetic Regulation), FDA (Food and Drug Administration), JCIA (The Japan Chemical Industry Association) and ASEAN Consultative Committee for Standards
[17:10] Through current regulations, there is increased responsibility in regards to: Ingredients toxicity, product labelling, more comprehensive product file and compulsory notification of new products introduced to the EU
[21:00] The current regulations have specific requirements for ingredient toxicity and product labelling
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 22716 sets out the framework for a quality management system for anyone involved in the manufacture of cosmetics and other healthcare related products. This is not only limited to production but also the control, storage, and transportation of products, including the purchase of raw materials, components and packaging material.
While this Standard’s focus is on the manufacture of cosmetics, many of the requirements can apply to any manufacturing process, especially those that involve a risk of contamination.
Today, Mel is joined by Derek Hall, a Senior Consultant here at Blackmores, to talk through the main structure of the Standard and how it can be applied.
You’ll learn
Resources
In this episode, we talk about:
[00:35] A description of ISO 22716 Good Manufacturing Practices – A supporting Standard for the manufacture of cosmetics
[01:20] Why are we talking about such a niche standard? It’s one of our most popular standards via website enquiry, so we’d like to share our knowledge 😊
[02:20] There is an EU directive pushing for the adoption of this Standard where applicable
[03:00] A more in-depth summary of ISO 22716 – Why it’s so important and why it was made
[04:01] What does ISO 22716 cover? Guidelines and practical advice on the management of the human, technical and administrative factors affecting product quality.
[04:58] A summary of the 17 clauses within ISO 22716
[07:55] What are the core elements of ISO 22716? Personnel, Premises and Equipment, Operations and Material Management, Quality Control and Cosmetics Quality Management System
[08:50] Personnel – Key considerations include: Restricted areas free from food and drink, visitor supervision, personnel authorisation, personnel uniforms (removal of rings, hair restraints, safety glasses, gloves ect)
[11:25] Premises and Equipment: The layout of buildings and equipment placement need to be controlled, controls for sanitisation and cleaning, guidance for storage, proper access to materials and equipment.
[13:27] Premises: Pest control – should be very controlled to prevent contamination. This can be controlled via the building layout and cleaning controls. A pest control program should be created and followed. This extends to the exterior of your building too!
[15:45] Equipment: Automated systems should be controlled in-line with ISO 22716. Equipment should be suitable for purpose and capable of regular cleaning and maintenance to avoid contamination.
[17:02] Materials Management and Operation: How well do you control your materials? What controls do you have in place for manufacturing and packaging? How good is your storage? What is your delivery process? Do you keep documentation of all your purchasing and quality checks?
[18:15] Materials Management and Operation: Stock – Consider how you manage and store stock, include regular checks to ensure it’s all well within date. The Operations area in particular aligns with ISO 9001 – Quality Management.
[19:40] Materials Management: You need to set the criteria for quality during different stages of manufacturing i.e. specifications for raw materials, components and packaging material. This should also include release parameters.
[21:00] Materials Management criteria can be set out in a checklist. Mel mentions ‘The Checklist Manifesto’ as a recommended read
[24:15] Materials Management: Make sure you store in a way that avoids any contamination or mix-ups. Ensure all containers are stored off the floor. Use clear labelling to show if they are accepted, rejected or quarantined
[25:37] Operations: Should be carried out according to manufacturing documentation i.e. suitable equipment, product formula, details of the product process ect.
[27:15] Quality Control: Consists of sampling, specification testing, out of spec investigations and release. You may subcontract out quality control – in which case, you must ensure you get proof that they are conducting adequate tests.
[29:13] For subcontractors – Ensure you have a written contract OR agreement in place. If your subcontractor is subcontracting along the work, you need to ensure that process is controlled
[31:32] Deviations: These can happen at any point in operation and can be both internal and external in origin
[32:09] Complaints and Recall: You need to have processes in place to log and deal with complaints and recall. You should also regularly test your product recall process
[33:20] Change Control: Making sure you have effective processes and documentation to control any changes to existing operation. I.e. if you get different machinery that changes mixing times
[34:50] Internal Audits: You need to have an internal audit program in place and have competent independent personnel that can carry those audits out. This could be sub-contracted out
[36:10] Documentation: You will be documenting all throughout the manufacturing process, it’s integral. Ensure all staff know the importance of it and how to complete it correctly.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Today we’re joined by Phil Bailey, Managed Services Director at PMC Retail, to talk about PMC’s experience with ISO 27001, from implementation to on-going maintenance.
PMC is a leading retail IT services and solutions provider, who recognised the growing need for formal Information Security certification. They succeeded in achieving certification to ISO 27001 in 2021, now over a year down the line, we catch up with Phil to find out what they’ve learned, benefits of certification and some tips for those looking to implement ISO 27001.
You’ll learn
Resources
In this episode, we talk about:
[01:03] An interesting fact about Phil – He started in electronic engineering and was involved the build of a system designed to measure the mirrors used in a telescope that was carried on the Discovery shuttle!
[01:44] Who are PMC Retail? Started out consultancy to retailers, which has since branched out.
[03:49] An example of one of PMC’s projects – Pulling together legacy systems, updating them to newer technologies while maintaining the legacy data.
[04:40] Learn about Phil’s role at PMC
[05:45] PMC now certified to ISO 27001 – One of the most popular ISO’s globally in recent years. It’s becoming something of a mandatory requirement in the tech space when bidding for contracts
[06:31] How do PMC manage their ISO 27001 certification – Created a small team dedicated to the task of achieving certification – along with some help from us 😊 Following certification they onboarded a Compliance Governance Manager to keep up with Internal Audits and other ISO maintenance.
[08:25] How has the ISO Support plan helped? – Blackmores helped to implement the standard, and were very familiar with their system and way of working. Great to have a wealth of knowledge to tap into.
[09:00] PMC managed to implement the standard in just 6 months!
[10:25] What did PMC learn from their experience? It wasn’t an easy task! Getting leadership commitment from the start made a huge difference.
[11:50] The benefits PMC have experienced by implementing and maintaining ISO 27001: Being able to identify risks and put actions in place to mitigate them. Certification demonstrates a robust security infrastructure to third parties. Establishes more credibility to customers and partners. They are able to see a pathway for business growth, utilising the certification.
[14:30] ISO 27001 has helped to collate and bolster their existing Information Security structure – Having a library of resources, unified policies and procedures, company wide Objectives, and better understanding of measuring & managing risks.
[16:15] PMC ensure that staff complete annual training – as required by the Standard.
[17:10] Phil stresses that you can’t just stay still with Information Security is concerned, you need to be aware of new risks and make sure those in your business are also aware and know how to react.
[18:00] Top tips from Phil: Get Leadership commitment early on. Build yourself a Management Team. Get help from an experienced external party. It’s not a walk in the park, and needs focus to achieve in a reasonable amount of time.
[19:42] Phil’s book recommendation: The magic of thinking big by David J. Schwartz.
[21:42] Phil’s favorite quote: “You’re never too old to set a new goal, or too old dream another dream”
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The work doesn’t stop once you get ISO certified, there is a requirement to complete an annual surveillance audit to ensure your Management System continues to meet the requirements of the standard(s).
Last week Mel covered some basic preparation you can do ahead of a Surveillance Audit, but what should you expect on the actual audit day?
Today, Mel shares 10 top tips to help you prepare and ensure your next surveillance audit runs as smoothly as possible.
You’ll learn
Resources
In this episode, we talk about:
[00:36] A description of a Surveillance Audit
[02:00] A summary of the 10 top tips
[02:40] There is no right or wrong way to prepare for a Surveillance Audit – but the following tips will be applicable regardless of the standard your certified to
[03:30] Tip 1: Be Prepared – A summary of what Mel covered in the previous episode
[05:40] Tip 2 – The opening Meeting – Be sure to have all people involved in the audit present at the meeting. It’s advised to have a member of the leadership team present. Here the Auditor will explain the different types of audit findings.
[08:00] Tip 3 – Audit questions – Similar to your Stage 1 and 2 Assessment, you will be asked a lot of questions. Try to be specific with your answers, and don’t be afraid to ask for clarification. Don’t worry if you don’t know the answers to certain questions outside of your area of expertise, simply direct them to the correct individual who can answer. You are within your rights to seek clarification on findings – Do not argue with the auditor, simply ask for justification on findings if you’re confused as to why they’re being raised.
[13:05] Tip 4: Keep on track – It’s everyone’s best interest to stick to the Agenda.
[13:35] Tip 5: On-site Surveillance audits – Do a floor walk before the auditor arrives to check that you’re following your procedures. Make sure reception knows that the Auditor is arriving, and follows any of your standard visitor procedures. Try to book a room to base the audit in to avoid them overhearing any unnecessary chatter and to allow the auditor and auditees some privacy.
[16:05] Tip 6: Remote Surveillance Audits – Ensure that you follow any company remote working procedures. Ensure you have a good wi-fi connection, all attendees should be visible on camera but be muted when not speaking. Make sure everyone has access to the necessary documents while off-site.
[17:15] Tip 7: The Auditor – They are human, and they are here to support you to ensure you are doing what you say you’re doing. They are experts on their Standards and it’s advised to foster a friendly relationship with them. But please be aware that they shouldn’t be sending you reports from personal email addresses, be left unattended on-site and shouldn’t be talking any information off-site – show evidence on screen / in-person during the audit.
[20:20] Tip 8: The closing Meeting – Held at the end of the day. Listen to the feedback and findings from the auditor – they are there to help you improve. Feel free to ask for further clarification if needed. It’s advised to have everyone at the opening meeting present at the closing meeting.
[22:38] Tip 9: Evidence needed – You will typically need, audit schedule, audit reports and Management Review Minutes. You may also need various policies and procedures. Ensure that all documents are version controlled and any applicable branding is consistent.
[24:10] Tip 10: Enjoy it! – If you’re doing everything you say you’re doing, then you should enjoy showing off your Management System. The resulting report should be seen as an opportunity to continually improve – the auditor only wants the best for your business.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The work doesn’t stop once you get ISO certified, there is a requirement to complete an annual surveillance audit to ensure your Management System continues to meet the requirements of the standard(s).
Surveillance audits must be carried out by a Certification Body, during which they will typically look at your Management Review, your preventative and corrective actions process, Internal auditing process and the implementation of any recommendations that have come out of an Internal audit.
Today, Mel explains how you can prepare for a Surveillance audit and gives examples of some key considerations ahead of the Auditor arriving on site.
You’ll learn
Resources
In this episode, we talk about:
[00:59] A description of a Surveillance Audit
[01:30] The purpose of a Surveillance Audit – Ensuring your Management System meets ISO Standard requirements and as an opportunity to demonstrate continual improvement
[02:40] There is no right or wrong way to prepare for a Surveillance Audit – but the following tips will be applicable regardless of the standard your certified to
[03:30] Tip 1: Check that you have an Agenda for the visit – This should be provided at the end of your last report from the Certification Body
[04:25] A brief overview of how the certification cycle works – A 3 year plan is usually provided to you by your Certification Body
[05:50] Ensure that you go ahead with a UKAS accredited Certification Body
[06:18] Tip 2: Confirm locations – make sure you know where the auditor is being sent and to prepare staff on site about the impending visit. This can also allow you to book out time for specific people that may be required during the audit
[07:10] Tip 3: Ensure you book out time for any required key members of staff – it is also advised that you book out a meeting room for the day
[08:45] Be prepared for the Auditor to walk around your site – Especially if they’re assessing ISO 45001 (Health and Safety) and ISO 27001 (Information Security)
[09:40] Double check if the auditor visit is on-site or remote
[10:30] Tip 4 – Check that you have all the relevant Management System records in place – and that they’re up-to-date
[10:50] Examples of what documentation the Auditor will typically look at
[13:00] Tip 5 – Make sure you’ve closed out any opportunities for improvement and non-conformities from your last internal audit
[14:30] Tip 6 – Check if there have been any changes to your business that may effect the scope of certification i.e. New products or services with no controls in place yet or a new site
[16:00] Tip 6: Confirm the auditor’s visit and check if they have any accessibility or dietary needs.
[16:30] Tip 7: Warn any relevant reception / security staff about the visit so they know to expect the auditor. Ensure they go through any of your typical security procedures i.e. getting an access card, signing visitor book ect
[17:42] Tip 8: Send an email to all staff to remind them about the surveillance visit – good to do this a day or two ahead of the visit
[19:45] Tip 9: Do a floor walk – Ensure that any of the physical controls you have in place are working as intended
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
One of the new controls added under the Physical category, is something called physical security monitoring. But what does this mean exactly?
Steve Mason joins us again today to delve deeper into physical security monitoring to explain what it is and give examples of different types of security and monitoring you can put in place.
You’ll learn
Resources
In this episode, we talk about:
[00:36] A quick recap of our ISO 27002 series and it’s purpose to date – Start from Episode 109
[01:58] ISO 27002 controls reduced from 114 controls to 93 – reduction due to some of them being combined or made redundant in the latest version
[04:02] The purpose of Physical Security Monitoring
[06:22] Example of where security monitoring solved an issue at a bank
[07:29] Another example of a London business who lacked physical security monitoring
[08:45] The importance of reviewing your need for physical security monitoring – what level do you need? Will it include CCTV, Access cards ect
[10:10] An overview of the various access points to consider, including: Main building, secure offices, server rooms, visitor access rights, CCTV, security alarms and personnel
[10:53] Example of where failure to verify a visitor highlighted a companies lack of security.
[11:30] The importance of communication and inductions for key reception and security staff, to ensure they can do the proper checks on visitors / know who should and should not be allowed into certain areas of your workplace.
[13:50] Suggestion of a checklist for checks on visitors for temp reception staff
[14:32] How do you define what needs 24 hour monitoring and what can be monitored for selected hours?
[15:46] The installation of security measures should be appropriate for your needs – don’t go overboard if it’s not needed. i.e. a Data Centre would need a high level of security but a small office may only need access control
[17:48] Take note of any security requirements in customer contracts
[18:10] How do you ensure the integrity of your security measures? i.e. CCTV – guidelines are available for installation, including placement, connection to your systems, keeping the timestamps accurate, logging any camera failures.
[20:00] Example of where a German company mapped out their CCTV so they could highlight blind spots, which were then pointed out to guards who did more checks in those areas
[21:15] Make sure you maintain any security equipment
[22:10] What crossover is there with other ISO 27002 controls? i.e. data masking being used in visitor books
[24:45] How can you apply this control to home workers? This can include training on being aware of potential security risks at home and locking the computer when not nearby ect
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
One of the new controls added under the technological category, is something called web filtering. But what does this mean exactly?
Steve Mason joins us again today to delve deeper into web filtering to explain what it is, breaks down the different types and gives examples of uses that you could implement to reduce risk.
You’ll learn
Resources
In this episode, we talk about:
[01:05] How you can adopt the new controls of ISO 27002 ahead of the latest version of ISO 27001:2022 being published
[02:00] The purpose of web filtering
[02:26] An overview of what web filtering is: It’s a security technology that monitors web activity and prevents users from accessing websites with malicious content or sites that are deemed to be inappropriate for business use
[03:45] Outlook already has web filtering built in
[04:17] The Internet is still the dominant facilitator for cyber crime
[04:40] Types of web filtering, including: Browser based filters, search engine filters, client side filters and network based filters
[06:58] Examples of where web filtering comes into practice – to protect against threats from malicious sites with malware or fishing content, false anti-virus updates, sites with illegal content and sites with out of date SLL certificates.
[08:15] Are you safe relying on Microsoft Windows?
[08:50] What to look out for on websites to ensure it’s secure: A padlock in the bottom right corner, use of reputable third party payment gateways.
[09:27] Examples of what to be wary of when using the web i.e. deals that are too good to be true
[11:40] Consider setting up a small internet café that is separate from the company network – to allow employees access for personal use and to help keep your systems safe.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
One of the new controls added under the organisational category, is something called threat intelligence. But what does this mean exactly?
Steve Mason joins us again today to delve deeper into threat intelligence to explain what it is, gives examples of the different types and shares some tools and activities that will help you implement threat intelligence
You’ll learn
Resources
In this episode, we talk about:
[01:19] The definition and purpose of threat intelligence
[03:01] Threat intelligence doesn’t have to factor into your scope and context – you can integrate findings in later
[03:50] Threat intelligence is about being aware of not only internal threats, but global threats that could impact your business
[04:50] Threat intelligence is not only about IT (i.e. viruses)
[05:19] That being said – cyber threats are still a big factor. So ensure you have tools, training and measures in place to reduce cyber attacks and breaches.
[06:30] Types of Threat intelligence, including: Cyber, Strategic and Tactical
[07:58] What threat intelligence actually does – Firstly ensure that you are collecting relevant data. That data can be analysed and used to reduce risk, to help you be proactive instead of reactive to threats.
[09:51] Threat intelligence is very appliable to Business Continuity (ISO 22301)
[10:35] The different types of tools you could consider, including: Security information and event management (SIEM) and CSOC – Cyber Security Operation Centres
[12:30] Types of threat intelligence activities you can do. This includes: Establishing objectives, collection of information from selected sources, analysing information to understand how it relates and is meaningful to the business and communicating information to relevant individuals.
[15:10] Ensure your threat intelligence is dynamic – and use it to inform and update your Risk Assessments at regular intervals
[16:30] Threat intelligence works with the Plan-Do-Act-Check cycle that is commonly seen in most ISO’s
[17:10] Threat intelligence can be used by any business regardless of any ISO certification you may or may not have.
[18:05] Keep an eye out for our ISO 27001:2022 migration support offering!
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
One of the new controls added under the technological category, is something called Data Masking. But what does this mean exactly?
Steve Mason joins us again today to delve deeper into data masking to explain what it is, why it’s so important and details a few of the different types of data masking
You’ll learn
Resources
In this episode, we talk about:
[01:33] The purpose of data masking according to ISO 27002 – Now more clearly defined when compared to earlier versions
[02:55] A brief overview of PII (Personally Identifiable Information)
[03:52] A summary of the defined attributes of data masking
[05:25] What is data masking? Including definitions for obfuscation, data anonymization and pseudonymisation
[08:50] The benefits of having a more clearly defined control for protecting PII
[09:35] Other standards where data masking is applicable - ISO 27017, ISO 27018 and ISO 27701
[11:27] Why data masking is so important currently
[12:40] How data masking works in practice
[13:10] Static data masking - data is masked in an original database then duplicated into a test environment
[13:34] Dynamic data masking - The original sensitive data remains in the repository. Data is never exposed to unauthorised users, contents are shuffled in real-time on-demand to make the contents masked
[14:50] On the fly data masking - Masking data while it is transferred from production systems to test or development systems before the data is saved to disk.
[15:55] Techniques for data masking include – Substitution - Businesses substitute the original data with random data from supplied or customised lookup file.
[16:15] Shuffling - Businesses substitute original data with another authentic-looking data but they shuffle the entities in the same column randomly.
[17:09] Number and date variances - For financial and date-driven data sets, applying the same variance to create a new dataset doesn’t change the accuracy of the dataset while masking data.
[17:56] Encryption is still the number one method for data masking
[18:40] Character scrambling - This method involves randomly rearranging the order of characters. This process is irreversible so that the original data cannot be obtained from the scrambled data.
[19:50] Other forms of data to take into consideration - Protected health information, Payment card information, Intellectual property and Company specific Information
[23:02] How GDPR promotes data masking
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
As a reminder, ISO 27002 (Information security, cybersecurity and privacy protection — Information security controls) is a guidance document which provides further best practice advice to strengthen your IT Security.
Today, Steve Mason explains the changes made to the 2022 version of ISO 27002, gives a summary of the 11 new controls and gives some examples of some key considerations and actions you can take to implement them.
You’ll learn
Resources
In this episode, we talk about:
[01:28] A brief summary of the changes to ISO 27002:2022, including new controls, new structure and attribute types
[05:30] Controls in ISO 27002 now have a defined purpose to avoid misinterpretation
[06:29] A summary of the 11 new controls by name and category
[08:10] Threat intelligence – What tools do you have in place to identify threats? How do you monitor your threat intelligence effectiveness?
[11:20] Information Security use of Cloud Services – A reminder that ISO 27017 covers this in more detail! Do you have a cloud policy in place? Does it align with your clients security requirements?
[13:10] ICT readiness for Business Continuity – Focus on recovery of IT services following a disaster. Do you have Business Impact Assessments in place? If you’re certified to ISO 22301 – this area is most likely covered
[14:36] Physical Security monitoring – Are you monitoring physical security? i.e. keycard access, CCTV ect
[16:23] Configuration Management – Are you IT systems working well together? Do you have an established configuration for passwords? (i.e. how many characters, alpha numerical, symbols ect)
[18:13] Information Deletion – If data needs to be deleted, that it’s deleted in a secure manor and can’t be recovered.
[21:48] Data Masking – Make sure that any data that shouldn’t be shared is masked in some way i.e. obfuscated or anonymized.
[23:31] Data Leakage – Put measures in place to stop data being leaked through i.e. USB’s, people sending business information to personal email addresses ect
[26:55] Monitoring Activities – You could monitor network traffic, software access ect. Be selective in your monitoring, only do so if it will be of benefit to the business.
[28:04] Web Filtering – Ensure that employees can’t access any nefarious / high risk websites that could cause a security breach
[30:15] Secure Coding – Make sure that coding is done securely – making sure that any software developed is secure and free of as many vulnerabilities as possible.
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
ISO 27002 was recently updated this year – along with a reduction of overall controls, 11 completely news ones were added to keep up with new and emerging technology.
As a reminder, ISO 27002 (Information security, cybersecurity and privacy protection — Information security controls) is a guidance document which provides further best practice advice to strengthen your IT Security.
Today, Steve Mason explains the changes made to the 2022 version of ISO 27002, gives a summary of the 11 new controls and gives some examples of some key considerations and actions you can take to implement them.
You’ll learn
Resources
In this episode, we talk about:
[01:28] A brief summary of the changes to ISO 27002:2022, including new controls, new structure and attribute types
[05:30] Controls in ISO 27002 now have a defined purpose to avoid misinterpretation
[06:29] A summary of the 11 new controls by name and category
[08:10] Threat intelligence – What tools do you have in place to identify threats? How do you monitor your threat intelligence effectiveness?
[11:20] Information Security use of Cloud Services – A reminder that ISO 27017 covers this in more detail! Do you have a cloud policy in place? Does it align with your clients security requirements?
[13:10] ICT readiness for Business Continuity – Focus on recovery of IT services following a disaster. Do you have Business Impact Assessments in place? If you’re certified to ISO 22301 – this area is most likely covered
[14:36] Physical Security monitoring – Are you monitoring physical security? i.e. keycard access, CCTV ect
[16:23] Configuration Management – Are you IT systems working well together? Do you have an established configuration for passwords? (i.e. how many characters, alpha numerical, symbols ect)
[18:13] Information Deletion – If data needs to be deleted, that it’s deleted in a secure manor and can’t be recovered.
[21:48] Data Masking – Make sure that any data that shouldn’t be shared is masked in some way i.e. obfuscated or anonymized.
[23:31] Data Leakage – Put measures in place to stop data being leaked through i.e. USB’s, people sending business information to personal email addresses ect
[26:55] Monitoring Activities – You could monitor network traffic, software access ect. Be selective in your monitoring, only do so if it will be of benefit to the business.
[28:04] Web Filtering – Ensure that employees can’t access any nefarious / high risk websites that could cause a security breach
[30:15] Secure Coding – Make sure that coding is done securely – making sure that any software developed is secure and free of as many vulnerabilities as possible.
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Did you know there were 80 identified security incidents, resulting in 34,908,053 compromised records in June 2022 alone!
Standards such as ISO 27001 can help you put measures in place to reduce risk and help set up procedures for data recovery. However, not as many adopt the guidance document ISO 27002 which provides further best practice advice to strengthen your IT Security.
ISO 27002 has recently been updated with 11 new controls that tackle recent emerging technology not covered in ISO 27001:2013.
Today, Mel explains ISO 27002 (Information security, cybersecurity and privacy protection - Information security controls), why it’s been updated and gives a high-level overview of the changes.
You’ll learn
Resources
In this episode, we talk about:
[00:30] A reminder to keep an eye out for future episodes on the upcoming updated version of ISO 27001:2022
[00:52] An introduction to the guidance document ISO 27002
[02:02] Controls from the updated version of ISO 27002 can be implemented right now – not a requirement of ISO 27001 but recommended.
[02:25] Why ISO 27002 has been updated – To bring it up-to-date with the latest technologies and simplification of controls
[03:15] What this means for your Information Security Management System
[03:50] We expect to see the new controls in ISO 27002 to be reflected in the updated version of ISO 27001 coming out later this year.
[4:27] Reminder: ISO 27002 is not a certifiable standard but it is best practice.
[05:00] ISO 27002 had its last major update in 2013 – think how much technology has changed since then!
[06:00] A summary of the changes to controls in ISO 27002
[07:25] New controls added to ISO 27002 highlight that the standard is more then just IT Security – A trait shared with ISO 27001
[09:13] A summary of what categories the 11 new controls fall under
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The Sustainable Development Goals have been established by world leaders with the hope that we can work together towards a better world by 2030.
The last two episodes provide an overview of all 17 Goals and related ISO Standards that you could align with to meet these goals. But how do you put this into practice? How do you go about aligning your Management System to the SDG’s?
Today, Mel explains the role ISO Implementation plays in working towards a better future and shares 5 actions you can take to align your businesses Management System.
You’ll learn
Resources
In this episode, we talk about:
[00:46] A reminder to watch the 2 previous episodes to learn about each of the 17 SDG’s
[00:52] The importance of ISO’s and how they can help work towards a better future, including alignment with the SDG’s
[01:24] Find out what SDG’s align with certain ISO’s on the ISO.org website
[02:19] Recommended action: Look at what your currently certified to and what other ISO Standards of interest that you could adopt to enhance your Management System
[04:40] If you need assistance with aligning to the SDG’s or want to implement an ISO – Blackmores can help, and we have resources available on the isologyhub
[05:30] Action 1: Leadership Commitment – Have you made a declaration of commitment to the SDG’s? Where have you displayed this commitment?
[07:10] Action 2: Management Review – Include discussions around your SDG commitment within a Management review. Make sure any actions are noted in the meeting minutes.
[08:31] Action 3: Context of the Organization – Consider actions related to SDG’s in SWOT and PESTLE’s
[10:10] Action 4: Objectives – Set out clear key performance indicators to achieve your commitment to select SDG’s. Can be short or long term.
[11:20] Action 5: Operational Controls – Put controls in place that actively work towards achieving objectives related to the SDG’s
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
In 2015, world leaders came together to create 17 Sustainable Development Goals (SDG’s) which aim to tackle various social, economic and environmental issues, to build a better world by 2030.
What you may not be aware of is the fact that ISO Standards play a big part in the journey towards a better future. Many commonly used ISO Standards already meet certain goals, with more in development.
This is part 2 of our 2-part series on the United Nations Sustainable Development Goals and the ISO standards that support them.
Today, Mel explains the 7 remaining SDGs, the ISO standards that relate to them and how organisations can meet these goals…
You’ll learn
Resources
In this episode, we talk about:
[00:46] The Sustainable Development Goals set out by the UN.
[02:27] How ISO 9001 and 14001 relate to the SDGs.
[02:56] Goal 10 (Reduced inequalities) and how ISO 26000 (Guidance for social responsibility) relates to it.
[06:04] Goal 11 (Sustainable cities and communities) and the series of standards ISO 37101, ISO 37120, ISO 37122, ISO 37123, and ISO 22301 that can help meet this goal.
[07:50] Goal 12 (Responsible consumption and production) and the related standards ISO 14020 Series, ISO 15392, and ISO 20245.
[10:42] Goal 13 (Climate Action) and the standards that help with climate change and greenhouse gases ISO 14001, ISO 14064, ISO 14067, and PAS 2060.
[14:14] Goal 14 (Life underwater) and the 250 sustainability-related Standards dedicated to Shipping, port waste management and protection of marine life.
[15:30] Goal 15 (Life on land) and the related standards ISO 14001 and ISO 38200.
[16:27] Goal 16 (Peace, justice and strong institutions) and the standards that support this goal ISO 37001, ISO 37301, and ISO 37000.
[18:18] Goal 17 (Partnerships for the goals) and it’s relevance to ISO Standards.
[19:43] How ISO standards are developed.
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
The world is facing a crisis: poverty, hunger, inequality and climate change are just some of the issues we need to address.
In 2015, world leaders came together to create 17 Sustainable Development Goals (SDG’s) which aim to tackle these issues, to build a better world by 2030.
What you may not be aware of is the fact that ISO Standards play a big part in the journey towards a better future. Many commonly used ISO Standards already meet certain goals, with more in development.
Today, Mel explains what the SDG’s are, and how businesses can align themselves with the SDG’s with related ISO standards.
You’ll learn
Resources
In this episode, we talk about:
[01:48] What the sustainable development goals are.
[02:29] When the SDG was established and what it’s agenda is.
[03:17] An overview of the 17 SDG’s.
[04:48] Where the term ISO came from.
[09:05] How ISO 20400 and ISO 37001 relate to the goal of ‘No Poverty’.
[11:25] The ISO standards related to the goal of ‘Zero Hunger’ including ISO 22000, ISO 26000 and ISO 20400.
[13:05] How ISO 13845 can relate to the goal of ‘Good health and well-being’.
[13:53] The first-ever management standard on education ISO 21001.
[15:23] How ISO 26000 can help improve gender equality.
[17:40] The ISO standards for water management that relate to the UN’s goal of ‘Clean water and sanitation’ including ISO 24518, ISO 14001 and ISO 24521.
[19:48] The increase in development of ISO standards in the area of Affordable and clean energy’ including ISO 50001 and the ISO 52000 series of Standards.
[21:37] How international standards promote the goal of ‘Decent work and economic growth’ including ISO 45001, ISO 37001, ISO 9001 and ISO 44001.
[27:48] How international standards promote the goal of ‘Industry, Innovation and Infrastructure’ including ISO 56002 and ISO 56003
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Do you find keeping up with regular annual ISO tasks a struggle?
It’s easy to let ISO maintenance slip through the cracks, especially if it’s in addition to your primary job role.
If this sounds familiar, then you should consider outsourcing certain areas of your ISO management system to be managed by ISO experts.
Today, Mel explains the areas that should be managed in-house, the areas that can be outsourced, and explains the ISO support plan we offer to help businesses outsource aspects of their management systems.
You’ll learn
Resources
In this episode, we talk about:
[01:38] How long ISO certifications are valid and the ISO support plan we provide.
[02:38] Why businesses outsource certain aspects of their management system.
[03:34] What areas you can outsource and what you should keep in-house.
[04:48] Health and safety requirements and risk management needs.
[06:03] The most popular ISO areas that can be outsourced.
[09:27] How to optimise performance through updating management systems.
[09:57] The importance of being able to quantify the results of ISO systems.
[10:54] How to outsource the facilitation of your management review.
[12:15] Employee engagement training that can be outsourced.
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
5 Steps to revamp your Management System
Has your Management System been left to collect dust? Hidden away so that no one except a select few can access and update it ahead of Surveillance Audits.
If this sounds familiar, then it’s time to revamp your Management System to ensure it’s incorporated with your core vision and values and encourages engagement from employees on all levels.
Today, Mel takes you through 5 steps that will help to rejuvenate your Management System, including key content considerations, the design and alignment with your company culture.
You’ll learn
Resources
In this episode, we talk about:
[00:57] What is essential from an ISO perspective
[01:22] How having too much in your Management System can lead to a lack of compliance
[02:20] Remember – If an ISO Standard states ‘shall’ – you must fulfill this requirement
[02:55] How to establish what’s essential to your business – including your way of working
[03:53] Different ways you can add value to your Management System
[05:25] An example of how Blackmores have added value with our Client Success Journey
[07:15] Why collaboration is so important when revamping your Management system
[08:52] How a Quality Circle can assist with a collaborative approach
[10:15] How you can align your company culture, strategy, values and goals within the Management System
[11:32] Why it’s important to share the Management system and any related updates
[12:38] Key considerations for the look, feel and accessibility of the Management System
[14:05] Examples of different ways you can display and share your Management System
[15:36] Consider how easy your Management System is to access and navigate
[17:12] Consider different methods of communicating the Management System – i.e. Audio, video, visual, flowcharts ect
Just a reminder, we’re offering 6 months free access to the isologyhub for anyone who signs up to an ISO Support Plan!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
It’s not uncommon to see a businesses Management System left to collect dust, either because it’s not fit for purpose or simply a carbon copy of an ISO Standard.
Sound familiar? Do you think your business and your employees deserve better? Your ISO Management System should represent your businesses way of saying – “This is what we stand for, this is our vision, values and processes.”
Today, Mel explains why it’s so vital to ensure your Management System is fit for purpose, and give some examples of where you can add value and reduce risk.
You’ll learn
Resources
In this episode, we talk about:
[01:03] Examples of poor quality Management Systems Mel’s come across
[02:19] The importance of having a bespoke Management System
[03:33] How out-of-date Management Systems can be detrimental
[04:40] Latest offering: A free Management System review and consultation – Simply contact us
[05:05] Why it’s important to continually update your Management System
[06:25] How initiatives / functions can get overlooked if they’re not referenced in your Management System
[07:38] Guidance on what should be included within your Management System to add value and reduce risk
[08:01] Examples of how a Social Media Policy / Process could be included and how it adds value
[09:45] How we at Blackmores follow our Social Media Process, record results and use the captured data
[11:10] How you can add risk mitigation to your Management System
[12:35] Other reasons why your Management System may be ready for a revamp
[13:10] Guidance on how you can improve the look and feel of your Management System
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
What’s in a name?
Is your ISO Management System just called a ‘Management System’ or is it named to reflect your companies culture and brand?
Sarah Ball, QHSE Consultant shares her views and tips on the power behind a name.
A name is people’s first impression of your Brand, System etc, it sets the tone for how people interact with it. So, it’s best to give it the time and thought necessary to make sure it makes the right impact.
Today, Mel and Sarah discuss why the naming of a Management system is important and share some great examples.
You’ll learn
Resources
In this episode, we talk about:
[01:05] How a Management System without a name can be detrimental
[02:39] A reminder of the definition of a Management System
[03:03] Why naming a Management System is so important to a business
[04:41] How including ‘Management’ in the name can alienate people from engaging with the System
[06:57] Guidance on selecting a Management System name
[09:30] Some examples of unique Management System names Sarah has come across
[11:18] Examples of some names and Acronyms we use at Blackmores
[12:01] Important considerations when creating acronyms – including taking account of any existing relevant industry related ones
[13:25] Why naming the Management System should be a collaborative effort
[14:54] Why the format of a Management System is important
[16:09] How getting the Management System name and format right can help share a businesses core vision, principles and culture
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
This episode Mel is joined by the CEO and Founder of SalesEnabla, and part-time Adventurer Matt Garman to talk about creating an awesome Sales Process.
Sales are an intrinsic part of any business, and while you may be happy with your current way of working, there is a lot you can do to optimize your process to increase the quality of your leads.
Today, Mel and Matt dive into Matt’s book ‘Learning the Ropes’ to explain the four pillars of Sales and how you can use these as a basis to improve your Sales Process.
You’ll learn
Resources
In this episode, we talk about:
[03:02] Matt’s past adventures and his latest challenge ‘Ocean Dadventure’
[06:42] How Matt’s epic challenge is supporting two incredible charities -Prostate Cancer UK and WOLO (We Only Live Once) foundation
[08:45] The reason why Matt wrote ‘Learning the Ropes’
[09:07] Matt’s past in Sales and his takeaway from experience
[11:50] An explanation of the four pillars – Vision, People, Process and Management
[17:00] The purpose for creating a Sales Process or ‘Playbook’– and why it’s especially important for smaller businesses
[18:28] The importance of having an effective ‘Discovery meeting’ to ascertain the viability of opportunities
[19:27] What a good ‘Discovery meeting’ looks like
[21:15] What skillset and mindset are needed for an awesome Sales Process
[23:30] An explanation of SalesEnabla and how it can be utilised
[25:49] How to avoid a high turnover in sales representatives
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
This episode is the final part of our 3-part series on Management Review, and this time Mel is joined by Rachel Churchman to explain how to best conduct Management Reviews and what’s best to include in them. Rachel Churchman is a Managing Consultant at Blackmores where she assists clients to implement, maintain and continually improve their UKAS certified ISO Management Systems.
Mel and Rachel discuss the different ways to conduct a Management Review, how to improve the Management Review process, and who should be involved in your Management Review.
You’ll learn
Resources
In this episode, we talk about:
[07:30] The purpose of a Management Review.
[11:15] The Management Review carried out at Blackmores and the issues we came across.
[13:06] The ways Covid has shifted from being viewed as a risk to an opportunity.
[14:14] The importance of reviewing your company's subscriptions in your Management Review.
[15:30] The benefits of involving more people in your Management Review.
[17:52] Why data analysis is so essential in a Management Review.
[22:35] The importance of considering your outputs as well as your inputs in your Management Review.
[24:47] Areas you should monitor and measure in your Management Review.
[30:53] The most beneficial ways to review your objectives.
[34:43] How to deal with non-conformities and corrective opportunities at Management Review.
[37:20] Types of resources you should review in your Management Review.
[41:50] Our top tips for Management Review.
[47:24] The three different ways to conduct a Management Review and the benefits of each one.
For members of the isologyhub, we have a few Management Review templates available for download
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
This episode is part 2 of our 3-part series on Management Review, explaining how to conduct Management Reviews and what you should include in them Today, Mel looks at the three different ways you can deliver a management review, what you need to consider when planning a management review and the key aspects of what to include in your management review report.
You’ll learn
Resources
In this episode, we talk about:
[01:30] What you need to consider when planning a management review.
[03:20] The different ways to deliver a management review.
[06:10] Facilitating a management review and emphasising continual improvement.
[06:47] Different inputs you can include in the management review.
[07:45] Chairing a meeting and how to inspire confidence during management review meetings.
[08:55] Key aspects of what to include in your management review report.
[10:05] The purpose of a management review.
[10:34] The importance of transferring agreed actions into deliverable continuable improvement.
If you need assistance with implementing ISO 14001, ISO 27001, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
This episode is part 1 of our 3-part series on Management Review, explaining exactly what Management Review is and how most companies carry them out.
Today, Mel looks at what the Standards require from a Management Review, the different areas Management Review addresses, and how companies can carry out a Management Review for the first time.
You’ll learn
Resources
In this episode, we talk about:
[00:44] Which ISO standards have a requirement for Management Review.
[02:50] Why Management Review is important.
[03:53] Different areas Management Review addresses.
[04:26] The importance of being flexible with your objectives and when to look for trends.
[05:40] The main reason for carrying out a Management Review.
[06:10] What the Standard requires from a Management Review.
[06:55] What you should include in your Management Review.
[08:08] What the Standard says about inputs.
[09:42] How often you should review your objectives and trends.
[11:18] How the Standard helps you understand what the outputs of your review should look like.
For members of the isologyhub, we have a few Management Review templates available for download.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
This episode is the final part of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral. This time, our resident Carbonologist David Algar is talking through the seventh step of the Carbonology process, ‘Declare’.
David explains the purpose of a formal declaration, different ways companies can make their declaration, and the different ways you can promote your achievement of carbon neutrality.
You’ll learn
Resources
In this episode, we talk about:
[01:56] A recap of the 7 steps to carbonology.
[04:02] The purpose of having a formal declaration.
[04:57] What the formal declaration involves.
[06:55] Different ways to make a declaration and which one’s most popular.
[08:31] How long your declaration is valid for.
[09:20] The importance of having an unambiguous declaration.
[10:07] The key outcomes and deliverables of the ‘Declare’ step.
[10:43] How publicised your Qualifying Explanatory Statement should be.
[11:27] Ways to promote achieving carbon neutrality.
[13:42] What companies tend to do after achieving carbon neutrality.
[14:23] Why it’s easier making a declaration in the second year.
[15:15] How to find out more information about the 7 step methodology.
[16:02] The importance of data.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is Part 6 of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
This time, our resident Carbonologist David Algar is talking through the sixth step of the Carbonology process, ‘Offset’.
David explains what companies can do to offset emissions, how offsetting works in relation to PAS 2060, and the importance of picking the right Offset provider.
You’ll learn
Resources
In this episode, we talk about:
[01:43] The five steps before you go down the route of Offsetting.
[02:12] Why Offsetting is a controversial topic.
[03:03] How Offsetting works in PAS 2060.
[03:41] What Offsetting is and how Carbon Credits work.
[04:59] Credible Offsetting schemes in the UK.
[07:58] Key considerations you need to consider when buying a Carbon Offset.
[10:48] How PAS 2060 helps companies prove they really are carbon neutral.
[12:20] How Carbonologists help their clients know which schemes meet the requirements of PAS 2060 and which don’t.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
If you’d like to book a free consultation with our Carbonologist, David Algar, feel free to book a slot Here.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is Part 5 of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
This time, our resident Carbonologist David Algar is talking through the fifth step of the Carbonology process, ‘Re-quantify’.
David explains why it’s important to recalculate your emissions after measures have been put in place from the Reduce stage, what to do if you're not hitting your targets, and how the ‘Re-quantification’ stage can help your public image.
You’ll learn
Resources
In this episode, we talk about:
[01:05] The seven steps of carbonology.
[01:32] Why it’s so important to ‘re-quantify’.
[02:31] The real purpose of the ‘re-quantification’ stage.
[05:16] How to feel if you’re not hitting your targets.
[05:50] The importance of consistency, accuracy, and transparency in ISO 14064 and PAS 2060.
[07:20] How to follow a carbon reduction plan while in a state of growth.
[08:34] The key outcomes and deliverables in your ‘Re-quantification’ stage.
[09:30] Our free carbon neutral checklist.
Download your free Carbonology Checklist here
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is Part 4 of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
This time, our resident Carbonologist David Algar is talking through the fourth step of the Carbonology process, ‘Reduce’.
David explains how we can put our Carbon Reduction Plan into action so we can see clear tangible results in our reductions, and the benefits this brings to organisations and their employees.
You’ll learn
Resources
In this episode, we talk about:
[03:05] The ‘reduce’ phase of the Carbonology process.
[04:36] The need to make your staff aware of your carbon reduction plan.
[05:13] How to best manage communications with staff around carbon reductions.
[06:36] How a carbon reduction plan can be beneficial for an organisation and their staff.
[07:26] How to best monitor the success of your initiatives and the benefits this has.
[11:11] The benefits of reducing your carbon footprint rather than offsetting it.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is Part 3 of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
Our resident Carbonologist David Algar is back to talk through the third step of the Carbonology process, Commitment.
David explains how organisations can identify the type of targets to put in place, the importance of having a launch and communications plan, and shares some popular ways organisations can reduce their carbon emissions.
You’ll learn
Resources
In this episode, we talk about:
[02:19] How to begin the commitment stage of Carbonology.
[04:00] Why organisations need a plan to achieve PAS 2060.
[05:27] Popular ways organisations can reduce their carbon emissions.
[06:40] The approach you need to take when setting targets.
[09:30] Typical targets organisations can put in place.
[11:31] The importance of having a launch and communications plan.
[12:06] The typical outcomes and deliverables organisations will be provided.
[13:31] The expectation of businesses to have a carbon footprint management plan.
[14:19] The importance of having your staff involved with your plan.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is the second of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
We’re joined by our resident Carbonologist David Algar to talk through the second step of the Carbonology process, Quantify.
What does the Quantify Step entail?
Calculating your emissions : This will be carried out for Scope 1 2 and 3 emissions.
What information do you need to quantify your emissions?
You’ll need to collect and process data. This can be:
Why is Transparency so important?
There are 6 key principles of ISO 14064, but one David is particularly mindful of is Transparency.
So what’s the purpose of quantification?
As well as giving you a total footprint for a specific time period, calculating your carbon footprint will enable you to do a few things:
Firstly you’ll be able to see what are the most emission-intense areas of your organisation, i.e. where the emissions are coming from, whether this is a specific location, or activity or even department
Secondly, by using this information you will be able to prioritise the areas that need to have their emissions reduced. This will form the basis of your Carbon Footprint Management Plan which we will go into more detail on in the next few episodes.
What are the Outcome and Deliverables?
One outcome of this exercise is a GHG Inventory. This is a requirement of ISO 14064 and put simply, is a big list of categorised emission sources, and the specific GHGs they produce. Here you’ll also list all emission conversion factors you used to turn activity data into tonnes of specific GHGs.
Another useful outcome is that you’ll be able to instantly and credibly respond to any tenders that require you present green credentials. As we’ve mentioned in previous podcasts, in the UK it is now a requirement for most large public sector contracts for the tendering organisation to outline its emissions.
Being able to easily present your carbon footprint to a potential tender could help in winning new business, particularly if you’ve completed this in line with an international recognised standard
Join us next week as we move onto the next step, Commit.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
David Algar is also available for a free Carbonology consultation until the end of March – Book your slot Here
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode is the first of our 7-part mini-series explaining our Carbonology service, a 7 step methodology to help companies become Carbon Neutral.
We’re joined by our resident Carbonologist David Algar to talk through the first step of the Carbonology process, Define.
David explains why the define stage is so important, what it entails, and how it works.
You’ll learn
Resources
In this episode, we talk about:
[02:38] What the seven steps of Carbonology are.
[03:08] The first step to becoming carbon neutral.
[03:52] How the define stage in Carbonology works.
[04:42] What Carbonology boundaries in an organisation may look like.
[06:20] The importance of identifying the people involved with Carbonology work.
[07:00] The type of people that are normally involved with managing the Carbonology standards in a business.
[08:25] How organisations can determine the selection of the subject.
[09:49] Why it’s important to clearly define the subject and your boundaries.
[10:33] The recommended approach to define the subject and boundaries.
[12:17] The outcomes and deliverables that are provided through the define stage.
[13:35] Who the Qualifying Explanatory Statement has to be shared with.
If you need assistance with implementing ISO 14064, PAS 2060, or another standard – Contact us!
David Algar is also available for a free Carbonology consultation until the end of March – Book your slot Here
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode we’re joined by the Founder of Slip Safety Services, and host of ‘The Safety and Risk Success Podcast' Christian Harris to talk about how Chris got into the business, the seriousness of slips, trips, and falls for both employers and employees, and the four main costs of Health and Safety.
Slips and trips cost UK employers approximately £512 million per year in lost production and other costs and are the leading cause of workplace injuries.
Christian explains how the UK court system works for criminal health and safety offences, why safety is such a key foundation of an organizations success, and how creating a better safety culture can increase a company’s profitability.
LinkedIn: https://www.linkedin.com/in/christian-harris-slip-safety/
You’ll learn
Resources
In this episode, we talk about:
[02:45] How Christian went from being a management consultant to becoming a safety specialist.
[03:51] The health and safety incident that changed Christian’s life.
[06:40] The psychological effect of living through an accident and how the incident has shaped the work Christian does.
[08:30] The four financial costs involved with Slips, Trips, and Falls.
[11:26] How the UK court system works for criminal health and safety offences.
[13:20] The criminal costs of accidents and how much money is claimed each year.
[15:13] The percentage of claims that get paid out.
[16:15] The difference between manual handling and Slips, Trips, and Falls.
[17:23] The positive benefits of creating a better safety culture.
[21:28] The slip safety scorecard and how you can access it.
If you need assistance with implementing ISO 45001, ISO 45003, or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode, we’re joined by Transformational Marketing Strategist, Podcaster, and Speaker Jürgen Strauss to talk about ISO 9001, and how businesses can identify their ideal client.
All businesses need customers and they need to understand who their ideal client would be, as only then can you clearly identify what your ideal clients needs are.
Jürgen explains how to identify your ideal client, how using an empathy map can assist with this, and how this all influences your marketing strategy.
Contact Jürgen on LinkedIn: https://au.linkedin.com/in/jurgenstrauss
You’ll learn
Resources
In this episode, we talk about:
[02:37] How Jürgen Strauss was involved in ISO 9001 implementation and how it helped him improve his business efficiency.
[04:20] How Jürgen developed his podcast based on the principles of ISO 9001.
[06:15] The global audience you can reach through podcasting.
[07:27] What makes a ‘dream customer’ and how Jürgen reaches them through his podcast.
[09:00] Why it’s important to have an ideal client for your business.
[12:23] How to identify who your ideal client is and what they’re needs are.
[14:23] What an Empathy map is and how the tool can help you locate your dream client.
[18:42] How an Empathy map helps you truly understand your customers.
[22:36] How to reject a client that you don’t want to work with.
[24:13] Why it’s important to identify what the customer journey is and how it relates to marketing.
[28:35] The circular nature of the customer journey.
[30:22] The importance of creating processes and systems, and common resistance points people have with creating an ideal client profile.
If you need assistance with implementing ISO 9001 or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This episode, we’re joined by Paul Robinson our Managing Consultant at Blackmores to talk about ISO 50001 – the Energy Management Standard.
Paul gives us some guidance and advice on how to audit and implement this standard effectively and how you can make improvements in your energy management.
We also talk about some common techniques to reduce energy consumption, how to increase a buildings energy efficiency, and how to monitor if equipment is being used in line with good practice.
You’ll learn
Resources
In this episode, we talk about:
[02:25] The purpose and benefits of carrying out internal audits.
[03:31] Benefits data centres have had as a result of auditing.
[04:45] How an organization can set up a robust audit programme.
[07:23] The impact a building’s design has on its energy efficiency and how this can be improved.
[10:16] The importance of monitoring systems and the power of automation.
[11:59] How to know which maintenance companies to work with.
[13:13] How to know if equipment is being used with good practice.
[15:26] The benefits of raising opportunities of improvement to management.
[17:59] Common opportunities for businesses to improve their energy management.
[21:24] Evidence you expect to see when carrying out an ISO 50001 audit.
If you need assistance with implementing ISO 50001 or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
We’re diving further into sustainability and best practices today as Mel is joined by Kit Oung who is a leading energy consultant with a wealth of experience spanning the last 25 years.
Kit is an energy and resource efficiency practitioner, consultant, trainer, and author on the subject of energy and resource efficiency; operational excellence, and triple bottom line.
Notable engagements include: designing regulations in the UK (energy and climate change regulations); Sharjah, UAE (mandatory Health and Safety awareness), and Singapore (waste regulation); drafting guidebooks on integrated management systems (ISO), energy efficiency (UNEP), ISO 50001 (ISO/UNIDO) and promoting of good governance in energy, environment, and health safety in India, Zambia, UAE, Qatar, Saudi Arabia, Oman, and Nigeria.
Kit is the author of Energy Management in Business: The Manager’s Guide to Maximising and Sustaining Energy Reduction (Gower, 2013), and coauthor of Best Practices and Case Studies for Industrial Energy Efficiency Improvement (UNEP, 2016). He also assisted in the technical review of ISO 50001: Energy management systems – A practical guide for SMEs (ISO, 2015).
Kit serves on IChemE’s Congress, IChemE’s Energy Community of Practice, IChemE’s annual sustainability awards judging panel, UNIDO’s global energy management leadership awards judging panel, and take part in developing National, Regional and International standards. He chaired ISO 14002-2 (current), ISO 50002 (current), PAS51215, EN16247-3, and participated in the development of ISO 14001 series, ISO 50001 series, and EN16247 series of standards.
Today, we’re looking at how to make energy sustainability strategies actionable, what the drivers for energy sustainability are, and how we can gain and maintain management commitment in sustainable energy practices. We’ll also have a sneak peak into Kit’s upcoming book: People, Planet, Profit: Environmentally and Socially Sustainable Business Strategies (Which you can pre-order! Link available under Resources)
You’ll learn
Resources
In this episode, we talk about:
[02:12] Kit’s experience in working with energy management and sustainable initiatives.
[05:48] Key aspects that need to be in place for a sustainability strategy to be actionable and have real influence on a company’s products and services.
[10:40] A case study of how British Airways has integrated sustainability into their business structure.
[15:15] The main drivers of sustainability practices in the Middle East.
[17:12] What inspired Kit to write his new book - People, Planet, Profit: Environmentally and Socially Sustainable Business Strategies
[21:20] Low cost technologies businesses can use to reduce their energy consumption.
[23:48] The three elements you need in an organisation to effectively control your energy consumption.
[25:40] How to gain and maintain management commitment.
[28:30] The importance of understanding every aspect of an organisation's processes and the hidden costs around waste materials.
[32:34] The importance of measuring consumption of resources and benchmarking.
[34:16] How to break down your energy consumption and make it visible.
[38:26] How external providers can help companies with the technical aspect of the data.
[40:48] How to break down implementation barriers in companies.
[47:03] The psychological benefits of celebration.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Today we’re joined by the Director of Morgan Green Advisory, Hayden Morgan.
Hayden is an independent consultant with a mission to enable a sustainable, lower-carbon future.
He has been pioneering sustainability within the finance sector for almost 25 years, and provides award-winning insights and solutions, focusing on transitioning to beneficial outcomes.
Today we talk about sustainable finance and the work Hayden is doing with leading experts from over 25 countries to develop the new global sustainability standard for financial organisations ISO 32210...
You’ll learn
Resources
In this episode, we talk about:
[02:24] How Hayden got involved in working in global sustainability.
[04:05] The work Hayden’s been doing on the new sustainable finance standard.
[04:56] How you can get involved with the new ISO 32210 standard.
[06:48] Hayden’s involvement advising the world bank around the development of a label for sustainable infrastructure.
[10:42] The pilot projects taking part in a sustainable infrastructure label.
[11:51] What sustainable finance is.
[12:39] The principles of the ISO 32210 standard and how it complements other requirements.
[15:30] The implementation guidance for ISO 32210’s principles.
[17:09] The best practice resources that will be available to help people implement the standard.
[18:17] The benefits of implementing the ISO 32210 standard.
[22:16] The plans for the standard and the expected launch date for the ISO 32210 standard.
[23:41] The sustainable integration work and climate risk strategies Hayden works on at Morgan Green Advisory.
If you need assistance with implementing ISO 32210 or another standard – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
We’re joined again by Paul Robinson, Managing Consultant at Blackmores. Last week Paul summarised the importance of energy management and introduced us to ISO 50001. This week, he delves deeper into the individual clauses of the Standard to break down what’s required in a typical Energy Management System.
What you’ll learn:
What are the main clauses of ISO 50001?
ISO 50001 has been aligned with the Annex SL format since 2018 so that it may be more easily integrated with other ISO Standards. The clauses are as follows:
Clauses 1, 2 and 3 – These are all explanatory clauses, starting with the scope, then Normative References and lastly Terms and Definitions.
Clause 4 – Context of the Organisation: Here you would define the scope and boundaries of your energy management system and understanding the processes affected. This includes looking at your energy inputs and outputs. You’ll also address any energy issues that affect you and interested parties involved.
Clause 5 – Leadership: This refers to Top Management commitment, which is necessary if you want your energy management system to be successful. They will need to provide resources required to implement an energy policy, and to define roles and responsibilities.
Clause 6 – Planning: This is a central pillar behind every Energy Management System as it talks about strategic and tactical considerations. This includes high-level issues, the needs and expectations of interested parties and the risks and opportunities associated with them in an energy context.
This clause also includes an Energy Review, which will help you build a picture of your energy sources and current consumption. From that you can start setting your Objectives and Targets and actions going forward using energy baselines and energy performance indicators established from the Energy Review.
Clause 7 – Support: This clause talks about provision of resources, competencies, awareness, communication and documented information required for energy management.
Clause 8 – Operation: This is where operational controls are defined to help you manage your energy effectively. It also covers design and procurement, which means procuring of energy, consuming assets and having effective processes in place to ensure energy is a key consideration when making infrastructure changes.
Clause 9 – Performance Evaluation: ISO 50001 is very data driven and clause 9 states the requirements for monitoring and measurement of your energy use, which will be used to demonstrate your improvement in energy efficiency. This clause also covers Internal Audits and Management Review to ensure the Management System is performing effectively.
Clause 10 – Improvement: This clause talks about taking opportunities that drive continual improvement in the Management System, but also recognizing that sometimes things go wrong. It also addresses significant deviations and a structure to investigate and correct those deviations to keep the management system on track.
What can go wrong?:
Based on his experience, Paul highlighted some issues he’s seen in existing Management Systems:
That’s it from Paul this week! For further information on ISO 50001, visit our Standards page Here. We also have an ISO 50001 Handbook available to members of the isologyhub, sign up here to grab a copy.
If you’re just getting started with ISO, we do have a free ISO Blueprint available for download to help you to plan, create, launch and get certified to ISO Standards.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Today we’re joined by Paul Robinson, Managing Consultant at Blackmores. Paul is here to introduce the Energy Management Standard, ISO 50001, why it’s important and give you an overview of its basic structure.
What you’ll learn:
Why have an Energy Management Standard?
There’s a big focus on trying to maintain global warming to that 1.5 degrees increase. Right now, we’re failing on that. In order to get this back on track we need to consider our current energy consumption. During COP26 we heard a lot about phasing out coal power, unfortunately there are some countries who are resistant to that and as a result have had the requirements watered down. Regardless, energy use continues to rise as does the demand.
Energy Management is particularly relevant for organisations who want to measure their impact and put measures in place to reduce their environmental footprint.
Why is it so important to restrict Global Warming to 1.5 degrees?
It’s literally the difference between survival. We’re at a tipping point now, failing to stick to this 1.5 degrees will result in rising sea levels and rising temperatures. Paul shares his experience working in Cyprus where it’s not uncommon now for the temperature to reach 45 degrees. This isn’t sustainable and it will get to the point where it’s difficult for humans to survive if we keep going at this rate.
What is the main purpose of ISO 50001?
ISO 50001 includes continually improving energy performance, energy efficiency, energy use and energy consumption. Building an energy management system will help you to understand, monitor and measure your use of energy, and like most other ISO’s, continual improvement is at the heart of ISO 50001. Key factors it addresses are energy performance, energy efficiency and energy consumption.
What are the main clauses of ISO 50001?
ISO 50001 went through it’s latest revision in 2018, aligning it with the Annex SL format that many other ISO’s use. The clauses are as follows:
Clauses 1, 2 and 3 – These are all explanatory clauses, starting with the scope, then Normative References and lastly Terms and Definitions.
Clause 4 – Context of the Organisation: Here you would define the scope and boundaries of your energy management system and understanding the processes affected. This includes looking at your energy inputs and outputs. You’ll also address any energy issues that affect you and interested parties involved.
Clause 5 – Leadership: This refers to Top Management commitment, which is necessary if you want your energy management system to be successful. They will need to provide resources required to implement an energy policy, and to define roles and responsibilities.
Clause 6 – Planning: This is a central pillar behind every Energy Management System as it talks about strategic and tactical considerations. This includes high-level issues, the needs and expectations of interested parties and the risks and opportunities associated with them in an energy context.
This clause also includes an Energy Review, which will help you build a picture of your energy sources and current consumption. From that you can start setting your Objectives and Targets and actions going forward using energy baselines and energy performance indicators established from the Energy Review.
Clause 7 – Support: This clause talks about provision of resources, competencies, awareness, communication and documented information required for energy management.
Clause 8 – Operation: This is where operational controls are defined to help you manage your energy effectively. It also covers design and procurement, which means procuring of energy, consuming assets and having effective processes in place to ensure energy is a key consideration when making infrastructure changes.
Clause 9 – Performance Evaluation: ISO 50001 is very data driven and clause 9 states the requirements for monitoring and measurement of your energy use, which will be used to demonstrate your improvement in energy efficiency. This clause also covers Internal Audits and Management Review to ensure the Management System is performing effectively.
Clause 10 – Improvement: This clause talks about taking opportunities that drive continual improvement in the Management System, but also recognizing that sometimes things go wrong. It also addresses significant deviations and a structure to investigate and correct those deviations to keep the management system on track.
That’s it from Paul this week! For further information on ISO 50001, visit our Standards page Here. We also have an ISO 50001 Handbook available to members of the isologyhub, sign up here to grab a copy.
If you’re just getting started with ISO, we do have a free ISO Blueprint available for download to help you to plan, create, launch and get certified to ISO Standards.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
This week Mel and Darren delve into the different factors that can impact on workers Mental Health:
Remote and isolated work
Workload and work pace
Working hours and schedule
Job security and precarious work
Working in situations that are not properly covered or protected by labour law or social protection
Social Factors at work:
Interpersonal relationships
Leadership
Organizational/workgroup culture
Career development
Support
Supervision
Civility and respect
Work/life balance
Violence at work
Harassment
Unwanted, offensive, intimidating behaviours (sexual or non-sexual in nature) which relate to one or more specific characteristic of the targeted individual, e.g.
Bullying and victimization
Repeated (more than once) unreasonable behaviours which can present a risk to health, safety and well-being at work; behaviours can be overt or covert, e.g.
Assigning impossible deadlines
Work environment, equipment and hazardous tasks
Work environment, equipment and hazardous tasks
How can we identify psychological hazards in our workplaces?
There are several ways that the organization can identify psychosocial hazards, this can include (but not limited to):
We’d love to hear your views and comments about the ISO Show, here’s how:
The Importance of Mental Health:
Who’s most at risk?
Identification of who could be harmed or at risk of harm psychologically can be complex, with varying factors, including (but not limited to):
There is no single way to manage and reduce stress, what works for one person, may not work for another.
What are the negative outcomes for employees?
What are negative outcomes for the organisation?
If we get mental health right – what’s the upside?
What is ISO 45003?
ISO 45003 has been published to provide guidance on the management of psychosocial risks and promoting well-being at work. Intended to be used together with ISO 45001 as part of an occupational health and safety (OH&S) management system, the guidelines are suitable for all sectors and types of organisations.
Defines Psychosocial risk as ‘combination of the likelihood of occurrence of exposure to work-related hazard(s) of a psychosocial nature and the severity of injury that can be caused by these hazard(s)’.
ISO 45003 is a guidance standard only. It is intended to complement the requirements in ISO 45001 and guide organisations on how to address OH&S issues relating to psychological health within their general OH&S management system.
What are the aims?
Therefore, it is critically important for the organisation to eliminate hazards and minimise OH&S risks by taking effective preventive and protective measures, which include measures to manage psychosocial risks. Psychosocial hazards are increasingly recognized as major challenges to health, safety, and well-being at work.
What are the psychosocial hazards?
What are the signs of exposure to Psychosocial risk?
What are the considerations in risk assessments?
At work, many situations (basic through to complex) are risk assessed, however, many assessments fail in relation to causes of psychological problems.
Every employer has a legal duty to assess and protect employees from work-related stress under the Management of Health and Safety Regulations 1999.
How does ISO 45003 support ISO 45001?
It is recognised that psychological health, safety and well-being are not always fully addressed within OH&S management. The standard is designed to help organisations better understand and address these aspects of OH&S management so that their system covers all aspects of health and safety, not just those that
We’d love to hear your views and comments about the ISO Show, here’s how:
One of the first steps towards becoming more sustainable is knowing where you currently stand in terms of your emissions. Calculating this may seem like a mammoth task, especially if you have multiple sites or assets such as company vehicles to keep track of.
David Algar joins Mel today to discuss how to calculate your Green House Gas (GHG) emissions, starting from Establishing boundaries through to number crunching and quantification.
What is the first step when embarking on quantifying your GHG emissions?
So how do you define your boundaries?
How would you recommend going about collecting to data?
Selecting a base year
The Number Crunching
Estimates, Assumptions, Uncertainties and Transparency
Managing your Emissions Going Forward – Applications of Quantification
Further resources:
Free Webinar - Targeting Carbon and Supporting Net Zero – hosted by Alcumus, David Algar will feature as a guest to help you understand your Carbon Footprint and provide a roadmap towards Carbon Neutrality. Register Here.
We also have more information about our Carbonology service available Here.
We’d love to hear your views and comments about the ISO Show, here’s how:
Today we’re joined by Will Richardson, Founder and Managing Director of Green Element, to discuss how he helps other organizations become more environmentally friendly.
Will established Green Element in 2004 with a desire to help as many businesses as possible to go green.
A pioneer and early adopter of many now-mandatory environmental standards, his visionary approach, and inspiring leadership are exemplary.
Will also runs a podcast that is constantly featured in the top of the eco podcasts, and is a current board member and Chairman of the British Kitesports Association; the NGB to Kitesports; helping push kite sports within the Olympic sporting ecosystem.
In 2018, Will conceived Compare Your Footprint in response to demand from companies that want to reduce their carbon footprint but were not ready to engage with experts.
This episode, he shares how companies can most effectively tackle their energy and carbon management, and the science behind carbon reductions...
You’ll learn
Resources
In this episode, we talk about:
[01:10] How Will got involved with sustainable energy and carbon management.
[02:14] Why Will started his own business and how it’s changed over the years.
[03:58] How Green Element helps organizations become more environmental.
[05:15] The difference between the life cycle analysis for products or services.
[06:24] How long it takes to work out a product’s life cycle.
[07:30] The two different ways there are to look at carbon footprinting.
[10:51] Different types of benchmarking you can do and how to do it.
[14:26] How to successfully carry out energy data reporting and why you shouldn’t rush it.
[17:59] The problems with net carbon zero and carbon neutral targets, and the benefits of Science Based Targets.
[22:36] The complex nature of effective environmental strategies.
If you need assistance with implementing sustainable practices – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Implementing an ISO can seem like a daunting task at first – There’s a lot to consider! Most importantly, are you implementing the Standard for the whole business – just one location? For just one Service?
In today’s podcast – I’m going to share with you ‘how to establish the scope of your ISO System’ as it’s the number one consideration when you start planning your ISO Project. This will also help to determine timescales, costs and resources needed for your ISO Project.
What is the ‘Scope’?...
The scope of the EMS will clarify the organisational and physical boundaries to which your activities applies, particularly if the company is part of a larger organisation.
Your organisation has the freedom and flexibility to define these boundaries. Your company may choose to only include a specific activity, location, product, or service delivery.
How to calculate the scope…
Most organisation’s, particularly if they are an SME (Small and medium enterprises with less than 250 employees) will include all aspects of their business activities within the scope of their EMS, and also their scope of certification to ISO 14001.
Larger organisations, or SME’s across multiple locations (including international) may want to carefully consider the scope of certification as there will be additional costs and time factors to take into consideration.
Why defining the scope is so Important…
Once your scope has been defined within your EMS, that this is what is included in ‘black and white’ on your certificate. Therefore, if one of the reasons to achieve certification is to impress your stakeholders with your environmental credentials, then being fully inclusive and transparent with a wider scope covering all your company activities, services and locations will be far more credible then a restricted scope.
Consider what will have the biggest impact – where you can make the biggest difference.
Further Resources:
We have a super useful checklist on how to plan, create, launch and implement your ISO Project so that you can successfully achieve certification. Download your FREE ISO Standards blueprint here.
Pssst!... Whilst your there, you may also want to check out our membership which includes all the tutorials, check sheets, templates and training to implement ISO Standards. As a member of the isologyhub we give you all the support that you need to make your ISO Project a reality and success.
In this episode I will cover:
[01.55] – What is the Scope?
[03.45] – How to establish your scope
[05.40] – Why defining the scope is so Important
[06.20] – Expanding the scope of your certification
[07.40] – Further considerations
We’d love to hear your views and comments about the ISO Show, here’s how:
Today, we’re joined by our resident Carbonologist David Algar to discuss SECR.
What is SECR?
SECR stands for Streamlined Energy and Carbon Reporting, it stemmed from The Companies Act (2006) which was updated in 2013 to require quoted companies to report annual emissions in their directors’ report.
In 2018, the regulations were updated and an additional disclosure requirement for quoted companies was brought in. They now require energy use and associated GHG emissions to be reported by quoted companies, as well as by large, limited liability partnerships (LLPs).
Why was it introduced?
To increase awareness of a business’ energy use and emissions and to encourage the introduction of initiatives to reduce energy usage.
To provide organisations with the relevant data to make informed decisions.
To help increase visibility to key decision makers who may not have been aware of how much carbon their organisation is producing.
Provides transparency on an organisation’s emissions and energy use to external stakeholders.
Is it applicable to you?
SECR reporting is designed to apply to all quoted companies in the UK, as well as unquoted companies and LLPs defined as ‘large’ under the Companies Act 2006.
To be defined as ‘large’ under the Companies Act and therefore qualify for SECR reporting they must meet 2 or more of the following criteria:
Who does it not apply to?
Low energy users, those using less than 40MWh per year.
If disclosing energy use data could inadvertently reveal sensitive information about your business, or seriously detrimental to the interests of your business.
Not all public bodies are required to report.
If your data would not be practical to obtain.
What needs to be included?
This is where it gets slightly more complex as this is where reporting guidelines specify what you must report depending on if you are a quoted company compared to a large unquoted or LLP.
Similarities (what everyone needs to report):
Differences:
What are the benefits for your organisation?
You would have quantified a significant proportion of your emissions, which paints a good picture of where your largest emission sources are from.
You would have just taken one of the first steps towards achieving carbon neutrality.
SECR also helps provide greater transparency for investors and other stakeholders.
It also supports other reporting such as ESOS and the new requirement for businesses looking to obtain large government contracts to have a carbon reduction plan in place.
How can Blackmores help?
By quantifying your emissions for your reporting period, in the long term we can help quantify any remaining emissions that are not referred to in SECR, specifically any remaining Scope 3s
We can also help provide clarity on the definitions of each scope and the subcategories within them.
We have various templates that we have created and refined to help simplify the process.
We can produce the SECR report, meeting all the requirements of UK Environmental Reporting Guidance, and as well as the main SECR report, we can produce the summary of your Director’s Report.
We’d love to hear your views and comments about the ISO Show, here’s how:
If you’d like further information on how we can help you with Carbon verification, SECR or Carbon Neutrality, check out our Carbonology Service.
A standard that seems to be growing in demand, certainly this year, is ISO 20400 which is a guidance document on sustainable procurement.
However, because it’s a guidance document, this means it’s not a certifiable standard…
But, it is useful if you are looking at your procurement, supply chain and how sustainable it is as ISO 20400 provides you with everything that you need to know on how to manage your supply chain sustainably!
A little background on the standard…
The standard has been around for some time, but it was a British standard (BS 8903: 2010), we’ve been familiar with it for a number of years, and we’ve aligned this standard with some of our client’s environmental management systems.
Why should it be something you want to consider doing?
It could be beneficial for your organisation, not only from an operational point of view but also in terms of having a competitive advantage.
So, let’s take a look at the standard…
As we know, every single organisation on the planet has an environmental, social and economic impact regardless of the size of the organisation…
Therefore, this particular guidance document is applicable to ANY size organisation across ANY type of industry, because those impacts have an influence throughout the supply chain.
Procurement is a powerful vehicle for organisations wishing to behave in a responsible way and contribute to the sustainable development goals.
By integrating sustainability in procurement policies and practices, it helps you to be able to manage your opportunities, risks and to focus in on those sustainable, environmental, social and economic development issues.
Ultimately, sustainable procurement represents a real opportunity to improve productivity, assess value and performance throughout your supply chain, enabling communication between purchase’s, suppliers and all other key stakeholders and helps to encourage innovation.
In this episode I will cover:
[05:00] The definition of procurement and sustainable procurement within this standard.
[06:16] Drivers for sustainable procurement within your organisation.
[13:20] Clauses 1,2 and 3.
[14:05] Clause 4- Understanding the fundamentals.
[14:40] Clause 5- Integration of sustainability at a strategic level
[16:06] Clause 6- Management techniques needed to successfully implement and to continually improve sustainable procurement.
[17:00] Clause 7- Considerations for the integration into existing procurement processes.
[19:08] The key principles of sustainable procurement.
We’d love to hear your views and comments about the ISO Show, here’s how:
If you’d like to get access to further information on ISO 20400, plus many other ISO Standards, check out the isologyhub which is an online membership platform, it’s a cost efficient and time effective way to implement your ISO standards and to get access to a wealth of information and guidance. There is an eLearning course you can get access to and an ISO 20400 checklist. So, if you want to find out more head over to: www.isologyhub.com
Today, we’re joined by Morgan Sindall’s Head of Information Security and Compliance Neil Binnie, to discuss the Information Security Standard ISO 27001.
Morgan Sindall has been ahead of the curb when it comes to information security having been certified to ISO 27001 for almost 3 years, but with information breaches becoming more common it’s even more vital to get ISO 27001 certified to prove you have a robust information security framework.
Neil explains the importance of information security, the new cloud security standards that are coming out, and the benefits of using ISO 27001.
Website: https://www.morgansindall.com/
You’ll learn
Resources
In this episode, we talk about:
[02:27] Why information security is so important in the construction industry.
[03:34] The benefits of having the ISO 27001 framework in place.
[05:28] Why supply chain security is so important.
[06:20] How a construction company can help to secure their supply chain.
[08:34] Neil’s experience implementing ISO 27001 in Morgan Sindall.
[12:43] The cloud security standards that are coming out.
[14:52] The benefits of having ISO 27001 in place prior to the Covid lockdowns.
[17:21] The incorrect assumptions people have about ISO 27001.
[18:37] The importance of having a collaborative approach when implementing ISO 27001.
If you need assistance with implementing ISO 27001 – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Today we’re joined by Senior Information Security Consultant, Steve Mason to discuss how working from home has affected our online security.
Remote working has become the norm during the pandemic and it’s proven that it can be an effective way for people to have a good work-life balance.
But with working from home comes many security risks, we need secure Wi-Fi connections, virus-free laptops, and to be working in environments where we can’t be listened in to.
Steve is an information security expert and as data security risks for homeworkers have shot up, he’s here to explain what we can do to negate this risk.
We talk about the general security risks of working remotely, and the importance of businesses taking this seriously and creating effective processes to mitigate that risk across their business...
You’ll learn
Resources
In this episode, we talk about:
[02:30] The added difficulties involved with improving remote client’s security.
[04:06] The benefits of using company devices and the security risks of using your own device and working from home.
[05:47] How to know you’re using a good VPN and adequate virus protection.
[06:36] Using a working from home policy and the benefits that can have.
[09:30] How to monitor employee’s software usage if they are working remotely.
[10:50] Issues some remote workers have with backing up their documents securely.
[12:17] The ways working from home affects your home insurance.
[14:09] The importance of fixing all security weaknesses you become aware of.
[16:56] The necessity of proper security training being given to staff working from home.
[18:38] Security in virtual meeting rooms and the policy we created around that.
[21:10] The main risks involved with working in public places like a coffee shop.
If you need assistance with implementing ISO 27001 – Contact us!
Today, we’re joined by our resident Carbonologist David Algar to discuss the seven vital steps to Carbonology.
If you’re looking for a sustainability roadmap for your business and looking to address the climate emergency while also meeting your stakeholders needs you’re in the right place.
Over the last 2 episodes Carbonoloigst David Algar and Mel have been going through ISO 14064 the Carbon Verification Standard and PAS 2060 the Carbon Neutrality Standard.
Today, David and Mel will be explaining how you can meet the requirements of both standards, gain verification, and demonstrate your business as carbon neutral.
That’s all going to be based on our game-changing route to sustainability, Carbonology.
What makes Carbonolgy unique is rather than paying lip service to the climate change emergency, Carbonolgy provides a proven methodology for sustainable success, allowing businesses to become carbon neutral and to achieve ISO standards successfully.
You’ll learn
Resources
In this episode, we talk about:
[03:12] The seven steps of Carbonology to achieve carbon neutrality.
[7:54] The different options there are to verify that you are carbon neutral.
[9:07] The different areas you need to define when starting off in your Carbonology journey.
[11:45] How to quantify the emissions embedded in different products that you sell.
[14:22] What’s included in a Carbon Footprint Management Plan.
[16:50] The importance of including working from home in your scope 3 emissions.
[17:57] How long a reduction period lasts and what in involves.
[19:27] The benefits or re-quantification and how it works.
[21:14] How offsetting works as part of Carbonology.
[23:31] How making a declaration of achievement of neutrality works.
If you’d like a quote for Carbonology – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Today, we’re joined by our resident Carbonologist David Algar who shares with us everything he knows about the Carbon Neutrality Standard PAS 2060.
Customers are demanding more environmentally friendly products and services, and to remain competitive organizations need to reduce their emissions and improve their environmental records.
Having a sustainability roadmap is critical to both government and industry now and in the future.
When implementing effective climate change mitigation measures the ability to differentiate between real and false claims of carbon neutrality is absolutely critical.
If you’re looking for a credible roadmap for your sustainability journey PAS 2060 can help you cut through the cynicism and doubt and maintain trust in your ethics to manage and reduce your greenhouse gas emissions.
You’ll learn
Resources
In this episode, we talk about:
[02:13] What PAS 2060 is and how it assists companies to become carbon neutral.
[2:55] The difference between being ‘net carbon zero’ and ‘carbon neutrality’.
[3:48] The importance of quantifying and reducing your emissions.
[4:18] What carbon offsetting is and how it works.
[6:54] The main benefits for a business in adopting PAS 2060.
[7:46] What a carbon footprint management plan is and how it can help save money.
[8:50] The benefits of validating your carbon neutrality.
[10:20] How Carbonology can help businesses become carbon neutral.
If you need assistance with implementing PAS 2060 – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
If businesses aren’t talking about COVID-19, they are discussing how to become carbon neutral.
To show their commitment to protecting the environment, companies are often claiming to be carbon neutral, but the issue is…where is the actual proof? Where is the credible framework that demonstrates that carbon verification?
Today we’re excited to share how to get started with introducing ISO 14064 (the carbon footprint verification standard). So, if you're looking for a sustainability roadmap for your business and are wondering where to begin, then you’re in luck as we're going to be providing you with information on that over the next couple of podcasts! We’re delighted to be joined by David Algar, our resident Carbonologist at Blackmores, over the next few podcasts as he’s going to share with you information about the international standards that everybody's talking about when it comes to demonstrating your carbon neutrality. This includes ISO 14064 for carbon footprint verification and PAS 2060 on carbon neutrality.
So, in this episode, let's kick off with ISO 14064 and find out what's it all about!
What you’ll learn:
ISO 14064 is a specification with guidance at the organisational level for the quantification and reporting of greenhouse gas emissions and their removals. So, essentially, ISO 14064 is a standard for an organisation of any type, size, quantity, or location globally to quantify its emissions of greenhouse gases, with the end product of this being the creation of a greenhouse gas inventory.
Now, let’s find out where we would begin with ISO 14064…
In ISO 14064, the standard begins with defining the organisational boundaries and the reporting boundaries. So essentially what you're covering in your greenhouse gas inventory and what the reporting boundaries are. This will also include any exclusions you decide to make i.e. elements of your business that will not be have their associated GHGs quantified.
An organisation embarking on its sustainability roadmap could carve out part of the business. So, for example by year one the UK operations, and then have a roadmap in place so that they include other locations and services as time goes on.
David expands on the greenhouse gas inventory by highlighting that this is where you would document all your emission sources. So, they are divided up into scope one, scope two, and scope three sources. Scope one is the direct ones, so for example stationary or mobile combustion, or anything your organisation directly burns. Then it goes into scope two, which is your purchased energy (the electricity, steam, heating and cooling that you would use in the building that you own or lease). Finally going into scope three can be a bit more complicated. This would be your other indirect sources, upstream and downstream. For example, if you are a manufacturing company, the upstream emissions would be the emissions associated with activities, for example, before your products are delivered to your manufacturing or warehouse. So that would include the extraction of the raw materials, the processing, packaging, and then the transport and distribution. The upstream emissions associated with a vehicle, for example, include putting it in a cargo ship and shipping it across the world. So, once it leaves your warehouse or plant, it would then go off to the customer. This is where you are looking at the downstream emissions, including emissions associated with the product’s use
The greenhouse gas inventory does split the scopes up for you, so you don't have to worry about memorising every single little part of the scopes! It is very useful in that aspect and it lays it out in a list for you.
Let’s take a quick dive into the vertification options for ISO 14064…
If you do decide to go for a third-party vertification from a certification board, the chances are that they're going to ask you questions on why you decided to include and exclude certain things within your greenhouse gas inventories. For example, certain operations in your business or why you have made certain exclusions. Another key element of producing greenhouse gas inventories is that you must use emission factors. These are how you quantify and convert, for example kilowatts, into tonnes of Co2 equivalent. So, the certification body may ask you why you've chosen to use a certain metric. That’s why it would always be a very good idea to document these choices, as you may be asked about them. So, in essence, this provides complete transparency on your carbon emissions across the organisation because you've justified the reason for including or excluding them.
Now, moving on to some of the benefits of ISO 14064…
Because it's an ISO standard and internationally recognised, it provides a reliable and proven framework for quantifying your emissions. So as a result of this, this helps identify individual sources of emissions and enables you to identify the biggest source of emissions, energy usage, and vehicle usage. Therefore, you can use it to identify areas for improvement by setting targets. However, the result of going down this road is that once you've implemented those improvements, it can actually save you costs in many instances, for instance through lower energy usage.
Another benefit is that it helps demonstrate your public commitment to environmental protection. This is excellent for your corporate image and CSR. Combined with third-party verification, it really does help show you are committed to environmental protection, and you're not just pursuing this activity for greenwashing purposes.
It can also be a tendering requirement for a lot of new businesses as it can support a lot of governmental requirements. So, it can be a framework to help you support any mandatory reporting of emissions, such as the SECR (Streamline Energy and Carbon Reporting) and ESOS (Energy Saving Opportunities Scheme) which are requirements essentially based on quantifying emissions and energy usage. So, if you've implemented ISO 14064, you've (almost) already built that framework to help you with the data collection and data presentation that you'll need for the SECR and ESOS reporting.
One thing which makes ISO 14064 very different from any of the ISO standards that we have implemented over the last 15 years at Blackmores is the fact that you don't actually get certification to this standard. It's classed as a verification, which has options for self-verification and third-party verification.
There are three main tiers to it, let’s find out what they are.
The first tier is the self-verification method, where you essentially pour over the data yourself and decide internally within your company that you’re happy to publish this publicly. Although, this is slightly less credible because your company is essentially verifying itself. The second level to that is a second-party verification, where you get an external body (such as Blackmores) to go over the data and essentially audit you on it. But what is generally regarded as the most credible is a third-party certification, the third tier. This would be done through a UKAS accredited certification body (such as BSI, or NQA). This method demonstrates confidence to all your stakeholders that the verification has been done properly because an independent third party has approved it.
Unlike certificates to management system standards like ISO 14001 (where they're valid for three years). This is just valid for the period that you've actually defined within the scope. So, that could be a period of 12 months, then you would have to go through the re-verification process.
We do have a podcast coming up on Carbonology which focuses on the process to meet the requirements of ISO 14064 and PAS 2060 to be carbon neutral…so, let’s get a sneak peek and find out how Carbonology might help with meeting the requirements of ISO 14064.
Carbonology is based on a seven-step process to help an organisation become carbon neutral. The first step of Carbonology is the Quantify stage. This is where ISO 14064 comes in because this is where you would essentially quantify and document all your greenhouse gas emission sources for scope one, two, and three. So, essentially, ISO 14064 really does form the bedrock of the Carbonology service.
That’s it for today, watch out for our future blogs as we'll be joining David on the next podcast where we'll be talking all about the next stage in your journey to becoming carbon neutral.
A question that we get every single time somebody asks about an ISO standard is ‘how long does it take to implement an ISO’, or ‘how long does it take to get certified to an ISO’?
In this episode, you’re going to find out what you need to take into consideration when it comes to timescales for implementing and getting certified to an ISO standard. ISO 14001 (the environmental standard) will be used as an example, but don’t worry -this can be applied to most other ISO standards.
So, are you looking to help your business? Create a system for success? To be kind to the planet, and improve your company's brand reputation? Then we're going to be talking about realistic timescales for making this happen.
If you're ready to implement an Environmental Management System (EMS) to help reduce your company's damage to the climate, then you're in the right place!
First and foremost, make sure you download our FREE ISO standards blueprint here. This helps you to plan, create and launch your EMS, ready for getting certified.
Now, let's dive into finding out about timescales for your ISO project!
What you'll learn:
The short and sweet answer is that most businesses take between 6 to 12 months to get certified. But it depends on the size of your organisation and the complexity of it.
Let’s get to know the different variables involved with this project because there is actually a way that you can implement any EMS in a much quicker timescale (we have had companies that have achieved this in less than three months!). And in fact, you can achieve this also by going to www.isologyhub.com (our new online portal), where you can go at your own pace.
The main thing is to have a clear plan, which is well organised and disciplined. It's worthwhile optimising both your internal and external resources. That would include your environmental champions, or your ISO coach (if you have one) if you're looking at using the isology hub as well because that could have a detrimental impact on the timescales allowed. So, if you're wondering what you should be doing, then it's definitely worthwhile either getting help from someone that does know what they're doing or finding other people within the business who have a bit more knowledge about environmental management and ISO 14001.
Now for larger organisations, it can take longer. You may take up to 12 months or even longer than that. What you need to do is consider breaking the project down into incremental phases. So, let's say you had 10 locations across the globe. You may decide to break that down into incremental phases so that you get certain locations certified in year one, and then you can have other locations included in the scope of certification in years two and three. So, don't think that you have to implement an EMS and get certified across all locations and services. You can go at your own pace. But ultimately, the scope would be for whatever you have set in your objectives for achieving implementation. What we do find is that some businesses implement an EMS across the entire organisation, but they might just get certified for a part of that business (this covered in a previous episode, where we look at assessments and getting quotes for certification as well!).
Remember you can extend your scope of certification at any time. It can be revisited at the annual surveillance visits that you get. Ultimately you want to build your ambitions, your objectives, and your targets for environmental management and achieving certification into your sustainability roadmap.
Now, it was mentioned earlier that you could fast-track creating an EMS, but you do need to establish a time to gather evidence and make sure that the system is working and is effective. So, when you're planning your launch just make sure that you're effectively targeting all key stakeholders (all stakeholders must be aware of this). And the general rule of thumb is to allow three months past the launch to make sure that your system is fully established because when it comes to certification, your certification body will expect to see some evidence and records. So, let's say, within your EMS you say that you have provided training for employees. You need to be able to show the evidence of that on the records and that doesn't happen overnight (obviously). So, with monitoring and measuring information on your environmental footprint, you need to allow time to do that. Ultimately what you're doing is proving that you ‘walk the walk’, and you will allow plenty of time to demonstrate that you're serious about reducing your company's environmental footprint.
Finally, one of the things that a lot of businesses don't really take into consideration is the time allowed for the assessment. Make sure that you have briefed your employees ahead of the dates of an assessment. Essentially, ensure you consider the timescales for your stage one and stage two assessments.
Let’s find out what’s involved in the assessment process…
Typically stage one is completed first, and then stage two could be within a few weeks or up to a couple of months after. You need to manage timescales so you can go through stage two relatively quickly. You just need to allow a few days in case there are any findings and if you need to implement any corrective action! Once you’ve completed the assessment, you're not actually formally certified as an organisation. There’s a due diligence process that takes place behind the scenes with the certification body, and it can even take several weeks before you actually get a copy of the certificate. Try and factor that into your overall planning, if you're looking at having a communications plan for celebrating your success, that's why six months is typically a good timescale.
A final factor to bear in mind is that if you've already got a management system in place, you could potentially fast-track the integration of ISO 14001 if you're developing an integrated management system.
Now, hopefully, that’s been helpful to you for implementing an EMS and getting certified to ISO 14001.
Remember the isology hub is now live, so feel free to join as a member to get access to all the support that you need on our online membership portal. It's the one and only go-to place for all things ISO. We've got video tutorials, check sheets, quick wins, and we've even got a module on timescales as part of the Planning stage. We take you through all seven stages of isology, in the isology hub. There's everything that you need in there to create, launch, and build your ISO system for success. So head over to www.isologyhub.com!
And finally, don't forget your FREE ISO standards blueprint here, where we cover timescales and there's even a planner within it on timescales which you can use to get your ISO management system kick-started.
Today Mel Blackmore is joined by David Ball, the CEO and founder of Brandfuel, a leading event management company. David's here to tell us all about Brandfuel and its sustainability journey. It's an inspirational and interesting story to hear about this journey and their experience of implementing ISO 20121, the sustainable event management standards.
First and foremost, let’s find out more about Brandfuel!
Brandfuel is a creative events agency, and they specialise in creating experiences which can be anything from very different types of virtual events, broadcast programmes, exhibitions, conferences, demos, dinners, to award ceremonies. The key thing about Brandfuel as an organisation is that they work hard with clients over a long-term period to translate their business needs and objectives into measurable results for their business.
Brandfuel started with some incredible clients; David has been working with Google for the last 18 years before he even started the company. They have a phenomenally strong class of clients ranging from companies like Slack, Stripe, Snapchat, BlackRock, Barclays and Deloitte and of course, Google and YouTube.
Now let’s find out about David’s thoughts on sustainability in the events industry…
What you’ll learn:
Sustainability in the events industry
David believes that transport travel accounts for the majority of the carbon emissions at Brandfuel. It's almost an impossible scenario to imagine if you take the travel away in the events industry. But it has to be measured and mitigated. David is confident that there will be substantial changes following this year of very little travel. He was typically required to take an excess of 100 flights a year, and last year…he flew twice!
So, that's the big elephant in the room in Brandfuel as 75% of the job is related to travel and transport in some way.
However, there are some simple things that can be done to create a change. But you need your clients on board with you to make this change happen. David is happy to say that they're past what was an attitude within clients when they wanted to be seen as ‘doing the right thing’. But actually, if it cost more money, they wouldn't take action. And now they are in a new realm where clients not only want to be seen doing the right thing, but they also actively want to be able to demonstrate their commitment to sustainability now and in the future, and they're willing to pay for it. So, Brandfuel seems to be heading into a very exciting journey, where sustainability is on the clients requirement list of what they want from an agency to deliver for them.
So now before we dive into ISO 20121, the sustainable event management standard, let’s find out how Brandfuel adapted during the pandemic. The pandemic was a major upheaval in the events industry, yet Brandfuel managed to achieve certification to ISO 20121. So, let’s understand how Brandfuel made it happen.
How did Brandfuel adapt business during the pandemic?
David is accurate in saying it's been a quite catastrophic year! But it's also been an exciting year.
The adaptation was really quick. They decided, instantaneously that switch to working online. So, they had to learn about arranging virtual events, and to become a broadcast business they had to learn every facet of broadcast as quickly as possible. They were fortunate in being agile and they were very quick to practice.
David set up some vehicles to help Brandfuel achieve this. One of which was an internal brand called Fuel Studios, which was the overarching umbrella that allowed Brandfuel to play, train, learn and get as much experience in broadcast as possible within the bounds of the agency to then be able to use it for clients.
They did things like turn company meetings into broadcasts and events into shows, and they started segmentizing. So, for example, they would mimic in a short video someone sharing their home with them and practice the filming, the editing and other interesting things like using triggered audio and watermarking on mobile devices to add content into video via broadcasts. So, some really clever stuff!
They also arranged a ‘lockdown low-down’, which was getting everyone at home to video what they were up to during lockdown. The studio also learned to design three-dimensional virtual sets. They also learned about green screens, lighting, camera work, multi-camera work and camera tracking -they did everything! And it really proved so useful because within a few months, they were given an incredible opportunity with an existing client to organise the global planning summit with three and a half thousand attendees. It was super complicated, massive scale, and very quick, but it gave them a lot of confidence, and they never looked back.
This really is incredible, just talk about diversification and innovation!
So, moving onto 20121 then…let’s find out how Brandfuel diversified in terms of the actual events that they were running, to then switch to online events via investment.
How did Brandfuel manage the transformation of physical events to virtual events?
David reveals that this was quite tricky! First and foremost, they needed to find a suitable set of events to be mentioned. They needed a balance of some in person and the actual event deliveries. This needed permissions from clients, and it needed a lot more planning. So, the first one they were fortunate with was the annual event for VGC partners, the world's largest electronic data brokerage. It's their charity day on September 11th and it's a recognition of all the staff that they lost in the Twin Towers tragedy. It's a very emotional and important day for them and regularly they would raise between $10 to $12 million in a day.
They achieve this by having almost 100 celebrities appear on the trading floor in London, and trade with their clients over the phone. Now, to do that virtually was a challenge in itself, but David reveals that the client was willing to give it a go. Brandfuel had a big team that had to go on site and fortunately, VGC had relocated from their building. So, Brandfuel was able to use this building to social distance and managed to bring celebrities in virtually to have video conversations with BDCs clients who were also virtual. This gave them access to talent that they never got physically. They had Kelly Osborne attend virtually, along with famous cricketers and golfers. So, it was very different, and it worked really well as they raised phenomenal $10 million, with only 25 celebrities!
So, now that Brandfuel is certified to ISO 20121, let’s find out what David identifies as some of the benefits of this standard...
Benefits of ISO 20121
Well, David believes that the benefits are huge! He identifies the obvious benefit to be that they are now commercially classified as being an agency that can be trusted to work to the highest standards in sustainability This is helpful for them as David believes this is going to be one of the biggest buying signals and cues that clients will show in the future. The other key thing for Brandfuel now is management systems; their internal management systems have improved so much. That gives them an incredibly strong platform to build on and to keep building.
David believes that ISO certification comes down to focus and to allocate the right amount of resources internally. It is a time commitment and resource commitment, but when you manage this and really stand behind as a business, it runs incredibly smoothly.
Brandfuel has successfully brought ISO standards into its DNA because it's part of the fuelling station, which in effect is their ‘go-to’ place within the business; it’s their intranet. The fuelling station as their intranet has been incredibly important currently as they’re all working from home. So, they made sure that all those management systems were fully integrated into new processes, and this meant being fully integrated into their communication processes. Their fuelling station was the centre of that, so they can really use it as a resource.
Brandfuel are also currently in the process of implementing ISO 27001 Blackmores. The ISO 27001 progress is going really well, and straight after that they’re going to implement the Health & Safety, ISO 45001 standard. This will open new sectors and new opportunities for Branfuel commercially.
That’s it from David! We hope you’ve enjoyed getting to know his journey and inspirational stories.
There are many resources to consider if you are planning to implement ISO 14001 to ensure that the project is successful, including time, people, finance, infrastructure, technology, and suppliers.
The resources you’ll learn about in this episode includes:
Time
The amount of time you spend on the Environmental Management system (EMS) will pay back in dividends once you’ve achieved certification. So, if you apply minimal effort and commitment, that’s what you’ll get out at the end! You need to allow time for how much waste your business is producing and the environmental life cycle analysis of your products and services, so that you have an easy to manage EMS.
People
The most successful 14001 projects involve leadership commitment, a project leader, and environmental champions.
Let’s find out exactly what this means…
Project leads: The project lead will be responsible for planning, creating, implementing, compliance, and the overall delivery of the implementation project. The isology hub is a great place for the project leader to gain a deeper understanding of ISO 14001!
Environmental champions: It can be tremendously valuable to have a group of people who are passionate about helping to make your company more environmentally friendly. It works really well if you can get a cross-representation from across the key functions within your business.
Finance
One of the aims of the isology hub is to provide a low-cost ‘Do it yourself’ (DIY) solution to implementing an ISO 14001 EMS. Should you find that you are struggling for time, and have extra budget for support, then there is an option to upgrade your membership to the ‘ISO Coach’ level. This is a fantastic opportunity for you to have an ISO Coach for 6 months to take you through the seven isology steps, or you may simply wish to outsource to a consultancy firm such as Blackmores UK Ltd, the team behind isology.
Infrastructure
Through implementing an EMS, your aim is to reduce costs associated with your buildings, activities, equipment, and supply chain. Many opportunities for reductions are no-cost or low-cost solutions i.e., ‘Switch-off’ Campaign, switching to renewable energy, printing double-sided, or (even better) not printing at all!
Technology
Try and use the current technology you already have within your business to your advantage i.e., communications channels and apps. Some organisations choose to implement software to assist them.
And now finally…
Suppliers
Many of your suppliers will be able to provide essential support and evidence to support your environmental initiatives. These can include facilities management and waste management, for example.
If you would like any help implementing ISO 14001, then make sure to sign up to the isology hub waitlist. This is a game-changing innovation in the ISO standards field. All the resources that you need on ISO 14001 will be available on www.isologyhub.com.
And let’s not forget your FREE ISO standards blueprint to kick start your EMS! You can download this here.
The aim of this episode is to have a clear plan for your ISO System for Success – from choosing the ISO Standard, to branding and establishing a place where everyone can access the system – so that you can move onto creating your ISO System.
You’ll learn about:
Identifying your current level of compliance
Set your expectations
Clarify why you want to achieve an ISO certification
Decide whether ISO Certification is the right choice
Decide which ISO Standard(s) and scope
Research your standards options
Decide what your scope of certification will be
Get leadership buy-in
Validate your ISO initiative
Establish timescales and resources
Resourcing
Establish project sponsor
Consider getting assistance i.e., at isologyhub.com
Choosing a Certification body
Get quotes from an accredited Certification body
Check if the Certification body has experience in your sector for the standard you are interested in.
Create a Project Plan
Establish roles, responsibilities, accountabilities
Identify key dependencies
Decide on the branding of your ISO system
Decide how you want to position your system within the company
Choose your system branding
Establish a ‘home’ for your system
Where will your system live?
Determine how you would like employees to get the most from the system
Create a Communications Plan
Establish what you are going to communicate, when, how, and with whom
Start to consider the communication of your success once your company has achieved certification.
Identify your current level of compliance
Purchase a copy of the ISO Standard
Hopefully, that's helped understand what's involved at the planning stage of introducing an EMS.
If you would like any help implementing ISO 14001, then make sure to sign up to the isology hub waitlist! This is going to be a game-changer in the ISO standards field, which is why we won the support of the UK government through their sustainable innovation grant. All the resources that you need on ISO 14001 will be available on www.isologyhub.com. So, click on the link to join the waitlist to be notified of when you can get access to our online membership portal. It is the go-to place for all things ISO. We've got video tutorials, check sheets, quick wins, eLearning courses, and just about everything you need to create, launch and build your ISO system for success.
Don't forget to download your FREE ISO standards blueprint here to get your EMS kick started!
Today Mel Blackmore is joined by Richard Turner, the Head of Asset Management at Greater Anglia, a train operating company in the UK.
We're going to be talking about his journey in relation to asset management and ISO 55001. Greater Anglia have been certified to this standard for a few years now, and they're a bit of a trendsetter, as far as asset management and certification to ISO 55001 is concerned.
What you’ll learn:
First of all, let’s talk about what Greater Anglia is and does…
What does Greater Anglia do?
Greater Anglia was one of the first train operating companies to embark on a full repairing lease in 2012. That means having a full responsibility as opposed to the normal setup (with Network Rail as the landlord and the train operating company as a tenant). It was a first for a train operating company to have their own Asset Management Department and it was a really big deal for a lot of those that joined asset management. Richard came from Network Rail, doing asset management in a department where a train operating company was leading from an asset management point of view.
Let’s get to know more about Richard’s background…
Richard joined Network Rail around the year 2000. He was an asset manager at the start, and then the senior asset manager, soon after becoming a root asset manager – he went right through the asset management field! So, when the Greater Anglia job came around in 2012, Richard jumped at it because it was a massive new challenge for him, as it was a new thing for a train operating company to start off with an Asset Management Department which never existed before.
Now for those of you who aren't actually familiar with asset management, let’s take a moment to understand what it is and why it’s important to an organisation…
Asset Management
From the asset management side for Greater Anglia, they look after the stations, depots, all the assets within the station demise that sit under their responsibility, maintain, renew, enhance and they look at longevity. They see themselves literally from inception to completion…they are like a landlord effectively. From an asset management point, it’s really, really key that they are involved every step of the way from design to construction essentially. It's an interesting role that is very varied. One day you could get involved in the refurbishment of a waiting room, then the next day, you would be discussing a brand-new station that's going to be built. It's so varied and what Richard loves about his job is that every day is so different.
It’s safe to say he definitely needs to work in collaboration with lots of different stakeholders in this role!
And that's a key point, actually…Richard tells us that one thing you learn through asset management is how to meet the expectations of your stakeholders, how you have performed, and what their expectations are. So, the stakeholder internally and externally is vital for any business to succeed. Because if you haven't got the buy-in of your stakeholders, then you're going to really struggle.
Now let's dive into ISO 55001…
What made Greater Anglia consider ISO 55001?
Striving for excellence, once the franchise agreement was in place, Richard was keen to set a high standard and embed Asset Management ‘Best practice’ into the DNA of the organisation. ISO 55001 was the ideal framework for this.
So, let’s find out how Greater Anglia went about tackling the challenge of achieving certification…
Tackling the challenge
There was a massive change of direction in everything Greater Anglia did with regards to presentations, training, updating their process strategy and getting everybody's buy-in, and inductions in what they do within the company. Richard thinks they got this from the ISO standard itself -in terms of the structure of how it was set out and what they did going forward.
The improvement within the team at Greater Anglia and the structure are more defined. And even the line of sight, when it goes right up to the managing director and down to the person at the station…you can see that link. Richard sees this as the most impressive part. At one point, when going on an ISO audit with BSI (British Standards Institution), they were speaking to a member of staff at a ticket office and asked him ‘Do you know much about asset management and the asset management system here?’…And he said ‘Yes!’. This really goes to show that how far it filters down.
It definitely is very challenging to ensure everyone is on the same page. But it’s so rewarding when you see it happening. At Greater Anglia, they learned so many lessons from when they started, they were in such a different position to where they are now. Richard sees this as a massive learning curve for them!
What’s interesting is that Greater Anglia has a broad range of different suppliers. So, let’s find out how having structure, policies and systems in place helped to coordinate operations with stakeholders…
Coordinating with stakeholders
When they started the franchise in 2012, they’d inherited the existing asset management system via Network Rail. Stakeholder engagement and collaboration were key, so to encourage feedback they liaised with various parties to ask the question about the current systems, ‘what do you want it to do for you?’ this included their commercial team, project team, assets team, and so on. This resulted in constructive feedback which helped Greater Anglia to initiate various improvements. Their supply chain now is very consistent, and there's a link to their system with regards to reactive and renewals, etc.
So, let’s find out what benefits Greater Anglia have seen as a result of having that asset management system in place...
Benefits for Greater Anglia
Richard reveals that prior to setting up their new system, everything was managed so differently. Now they have one big unit that manages all assets. So, information with regards to surveys, renewals, stakeholder projects, or third party is all linked. Whereas before, it would have been harder to manage…now, it's all unified.
This clearly saves Greater Anglia a lot of time by having information at their fingertips, together with knowing how it all connects with other areas of the business
Now finally, let’s see what kind of hints and tips Richard has for individuals that are responsible for asset management within an organisation and are considering implementing ISO 55001 and some kind of framework to have that structure.
Richard sees it as absolutely crucial that you find somebody (like Blackmores!) to help you, as they will guide you through the process. You need someone to look at your setup, and how your structure and strategy are, etc so they can tell you what you need and how to improve. The daunting part is actually looking at the standard as a technical specification and wondering ‘how is this going to be interpreted for our business?’ and so that’s how Blackmores helped.
Greater Anglia is now up to its third year of recertification, which is just fantastic!
If you're wondering where to begin with strengthening your environmental credentials, a great way to do this is to implement ISO 14001. This is a world-leading standard for businesses on environmental management.
In the last episode, I shared with you what an environmental Management System (EMS) is. So, if you haven't heard that yet, I'd recommend that you have a quick listen before listening to this one because it's essential listening, it provides an overview of what an EMS is.
Now, I'm going to just provide a high-level overview of ISO 14001. But if you'd like to get all the resources on implementing ISO 14001, then the isology hub membership is the place to go. It has everything that you need, including video tutorials, downloads, workbooks, check sheets, and also a stack of training classes as well to help you to create your very own bespoke ISO 14001 compliant EMS. We're super excited to be launching this game-changer in ISO standards. So, if you don't want to miss out, go over to the membership site, which is www.isologyhub.com to join the waitlist, and don’t forget to download our free ISO Standards Blueprint here, which provides you with all the information that you need on the key steps to plan, create, launch and get certified to an ISO standard.
Let's dive into ISO 14001!
What you’ll learn:
Let's start right back at the beginning…
Key purpose of ISO 14001
This standard is a specification. It's a document that you can purchase online, which provides a framework for actually building an EMS
An EMS is to provide a framework to help support any organisation to improve its overall environmental performance and provide a sound basis for sustainable development initiatives.
It's designed to embrace continual improvement, and enhance operational performance, which is similar to any other ISO standard. So, if you've already got an ISO standard in place, the chances are that you're in a really good position to integrate the elements of ISO 14001 because there are quite a lot of similarities.
The structure of ISO 14001
So, by just running through that briefly, you'll probably be thinking, “oh yeah, well we've got that and yep we've got that too”…but it might just not cover environmental management. So, that's where you need to make those tweaks and changes.
For those of you that aren't familiar with ISO standards you might be thinking, “well that's pretty comprehensive”. And yes, it is actually! It does provide you with a holistic framework for managing environmental performance.
Key principles of ISO 14001
Now, looking at the key principles then of ISO 14001…ultimately, it's down to:
So, those are the fundamental principles of ISO 14001. If you’re focusing on achieving certification to this standard, then you really need to focus on clauses 4 to 10 of the standard. These are the elements that are implemented within your business and they are the areas that the independent third-party body will be looking at when it comes to your stage one and stage two assessment.
There’s a lot more advice and information on that over at www.isologyhub.com, which provides a full list of the key and essential documents, what is desirable and provides examples of those using templates, guidance, and training.
So, to wrap up…
What are the benefits of ISO 14001?
If you'd like all the resources needed to implement ISO 14001 yourself or if you'd like to join one of our ISO 14001 six-month coaching programmes, we've got seven places available! So, head over to www.isologyhub.com to find out more, and don’t forget to download your FREE ISO Standards Blueprint here.
I look forward to catching up with you on the next episode, where I'm going to be sharing with you how to plan your ISO 14001 implementation project!
An exciting announcement about a game-changer in the world of ISO standards was made in the last episode….which was about the isology hub!
Let’s have a little reminder…
What is the isology hub?
It's a Netflix version of unlimited ISO standards support, which includes videos, checklists, sample policies, templates, plus many other things such as eLearning courses! You’ll get access to binge-worthy content to help you raise your game and take your business to the next level.
So, what is it that makes the isology hub such a game-changer you ask?
Well, it's a game-changer because it provides a DIY (do it yourself) solution to implementing an ISO standard. Our inaugural ISO Roadmap is for an Environmental Management System (EMS). So, in effect, it’s a roadmap for you to implement an ISO 14001 EMS.
Over the next few episodes, I'm going to be sharing with you some of the topics that we cover in the isology hub in terms of ISO 14001. We have an ISO 14001 roadmap, and we kick off by explaining what an EMS is, and we feature step by step, specific actions that you can take to make your business more sustainable and take it to the next level!
But before I kick off with explaining what an EMS is in this episode, I’d just like to announce that we have an awesome ebook guide for your ISO project.
And it's free of charge!
It's called the ISO Standards Blueprint simply go to isologyhub.com to download it for free. The great thing about it is that it's a guide for any ISO standard. So that's why the ISO Standards Blueprint is a blueprint for implementing any ISO standard.
Now, let's dive into explaining what an EMS actually is…
What is an EMS?
So…what is actually inside an EMS?
Which documents must you include?
And…
Examples of Documented Information include:
In Summary…What can an EMS help with?
Hopefully, that's given you a snapshot of what an EMS is!
We go into this in a lot more detail in the isology which is where you’ll find everything you need to implement an EMS and achieve certification to ISO 14001
So, don't forget to download your FREE ISO Standards Blueprint over at isologyhub.com
Today’s podcast is unlike any other podcast we’ve recorded before. That’s because we’ve got a special announcement to make about a ground-breaking innovative gamechanger in the ISO Standards landscape – the isology hub, which is due to be launched in May 2021.
What you’ll learn:
Now, I’m recording this in April 2021, but I’d like to take you back to March 2020 to explain when and why my journey began with initiating this innovative online solution. I think it’s quite important to appreciate that this sort of innovation probably would have taken us three to four years to come up with. But COIVD-19 has encouraged many organisations to think outside of the box, to think differently, and to look at sustainability in a very different way.
So, let’s go back to March 2020 and find out how the isology concept was born!
March 2020
In March 2020, the UK like many other countries across the globe were thrown into lockdown, and life was turned upside down, as we were hit with a global pandemic. Little did we know…that life as we know it was never going to be quite the same again!
Now, at the time, we felt that we had the curve. Partly because we’d already been using Teams to have meetings online and to do internal audits, mostly with some of our international clients at Blackmores.
Many of you know me as the Managing Director of Blackmores (as well as the podcaster on the ISO Show). Blackmores is my primary business and very dear to my heart. I’ve been running that business for 15 years and immediately I was concerned about the welfare of our employees and clients, and like many other businesses thinking “Okay, so how are we going to best get through this?!”. We went into our BCP mode (Business Continuity Planning mode) and we actually shared a lot of that information on the ISO Show!
We felt that we owed it to our listeners and our clients at Blackmores to share examples of pandemic business continuity plans. And at the time, it was really well received! In fact, we didn’t realise until we did that how much of a wide global reach of listeners we had. It was amazing! We had people contacting us from Papua New Guinea, Kula Lumpur and places all across the globe saying “thank you this is great!” or “this is really helpful” because at the time, businesses were looking for reassurance as well. So, we were more than happy to provide the support.
Not long after that…
it was just before the Easter weekend, so April last year. We had a quarter of our clients cancel within the span of 10 days! Straightaway we thought ‘okay, this is going to affect us’. We quickly realised that a lot of our clients are in manufacturing or in the events industry, and they simply could not operate!
So, we had to shift gear…and adapt!
We had to change the way assessments were undertaken and the way we deliver our consultancy services to do it all remotely. That’s when I realised that actually…there is an opportunity for certification bodies to do part of their assessments remotely. Obviously, for some types of assessments this wouldn’t be applicable. But in many cases, I could see that there was a significant opportunity for us to reduce our environmental footprint and work remotely!
At that time, we were already creating eLearning courses, and there was some work taking place internally within our team on developing a learner profile. So, taking an individual from a grassroot level, with no knowledge whatsoever about an ISO standard, right through to professional status. So, work was already underway. When we looked at the possibility of offering our services online and after the research we did, we realised that actually, it would be really good if we could provide an online solution that all of our ISO show listeners could also access!
That was when the initial concept was born for creating a state-of-the-art online, learning and support membership.
This was made for organisations looking to not only achieve ISO certification, but also for those businesses that are already certified to ISO standards, but their system just isn't working for them. They might be stuck in a rut…they're stuck in the trenches there because there may be certain issues like a lack of engagement, leadership, or even compliance. So, I came up with this concept of creating an online membership platform so that it was accessible to all regardless of the industry, the location, the time zone, and to be able to provide the equivalent of a Netflix version of ISO standards support!
I had heard from a funding body, within the government in the UK, about an Innovate UK competition. This competition was all about helping businesses to be innovative and provide sustainability solutions as well and to help businesses through COVID.
It was then that the penny dropped…
I thought well, actually, why not go for it! If we win it, we win it. If we don't, then we don't! So, I put together a business plan and got a lot of advice from a European enterprise network and put together a bid for this competition.
There were actually three rounds to it! Let’s find out how they went…
Innovate UK competition
So, round one…
I hadn't done anything like this before and it had taken weeks to put together that bid. We found out about a month later...that we had failed! But only by a very slim margin, which was very frustrating. But this encouraged me, particularly as a result of the positive comments from the assessors, that assess the application, saying that there was quite a bit of mileage in this innovation.
Now onto the next round…
The deadline for the second round was only two days after we got the feedback from the first round. My advisor said “you know there isn't much point in rushing this, you want to spend time to get this absolutely perfect, so that you can absolutely smash it at round three”. This was the final bite of the cherry…it was a last chance saloon. I thought well…if we get it, we get it, and this is going to be a game-changer. If we don't, that's it.
Fortunately…we won the competition; we won the funding!
There are five different assessors from all sorts of different industries that recognise this as being a game-changer in our field. They believe it could have a significant positive impact on the environment. Because our MVP (minimum viable product) is a part of this membership platform and is all about environmental management standards. So, we've been working hard over the last few months to bring together this MVP, and we're due to launch it in May 2021. It's going to be called the isology hub and it's based on isology methodology…which is ultimately seven steps to implementing any ISO standard!
Now, I’m sure you’re wondering…who is isology for?
The isology hub
This membership platform is for anybody who needs to achieve ISO certification. This might be because you need to win a tender, or you just want to raise standards within your business, or you may have stakeholders that are demanding that you provide some type of commitment in some area, whether it be sustainability or information security. It's also for those people that have spent countless frustrating hours trying to understand how an ISO standard could actually be interpreted within their business. It's also for those people who have an ISO management system…but it's archaic. It was written in the dark ages! And it doesn't bear any resemblance to how you operate as a business right now. In effect, it's working against you. So, you need some type of solution to revamp it, give it a makeover, getting engagement and in making sure that it is a system that helps you to build success for the future of your business.
It's also for those of you that would like to integrate other standards into your existing management system. So, you might be looking at cloud security standards, or carbon neutrality standards. So, it's for those businesses that are already working hard to raise standards within their business, but they want to go the extra mile…they want to go above and beyond, and they need the systems, tools, templates, eLearning and guidance to help them to do that. It's also for those individuals that would like to achieve qualifications in ISO standards to improve their knowledge and to support career development as well.
So, what we're trying to avoid here is having any overly technical and expensive training courses. You can access it whenever you want, from wherever you want. It's a place for organisations to learn how to achieve ISO standards, and also to get gameplans for raising their game. It's packed with in depth, practical training and resources on all aspects of planning, creating and managing a successful ISO system.
Now, we have also created an ISO standards blueprint, which is a free download for you to get access to, if you come over to the isology hub website. All you need to do is Google www.isologyhub.com and you'll be able to download your free ebook on how to plan, create and manage a successful ISO system ready to get you certified
And that applies to all ISO standards!
Now, I’m sure you must be thinking…what makes isology hub so different?
Well, this is a ground-breaking approach. It's the quickest and easiest way to get ISO certification that gets results. But it's not just about the accolade of getting certification through your certification body, but having that results driven, systemised way of managing your business, to give you that freedom and time so that you can grow your business.
It also gives access to expertise. Over the last 15 years, we have implemented ISO standards for hundreds of organisations across the 19 standards and over 25 different countries. So, you're actually tapping into over 200 years of combined experience now (that's not me personally obviously) that's our team! It's our team that's helped put this together. All our intellectual property and all of the work that we've been doing over the years to support businesses in all industries is going to be put together in the isology hub. That's where you can get access to that.
And, of course, we walk the talk…
We have done this time and time again. These are the proven concepts. Isology and the seven steps have been put to the test and it's been successful…time after time!
And we are pretty straight talking!
We are very friendly, very approachable and we want that to come across with the membership platform. So, you'll be able to listen to our tutorials and join us for our monthly live Q&A sessions if you've got any questions or if you'd like to discuss anything at all to do with ISO standards.
Ultimately, we live and breathe ISO standards…you get our full commitment, and you get that team behind you through the membership portal.
But I must say…the isology hub isn't for everybody!
Who is the isology hub not for?
If you simply want to tick a few boxes and get the badge…this isn't the right solution for you. If you want to go down the non-accredited certification body route…it's not for you. And If you're looking for ISO in a box so you don't have to do any work at all…it's not for you either. It's also not for you if you're expecting guaranteed results. That's because it is down to you to put the effort in to actually make it happen. Although we've got 100% success rate in helping our clients get through certification because we've helped to do a lot of the work with them, the membership portal is there to guide and support you…so you have to put the work in yourself. The templates, tutorials, guidance, action plans are all provided for you. But you do need to spend the time to actually completing them and implementing them within your business.
B1G1
One of the things that we're passionate about at Blackmores is acting responsibly and doing the right thing. With having an online system, we are donating for every new member that joins the isology hub.
This will be done through B1G1 (buy one, give one!)
We will tackle climate change and poverty, one member at a time. The project we have selected is in Madagascar. Unfortunately, Madagascar is a country in crisis. 70% of the country lives in poverty and half of its rainforest has been eradicated due to the strain of population growth in the country. So, we’ve picked out a project whereby we can support the planting of trees and also provide sustainable agriculture training as well so that the communities are self-sufficient. This will enable them to send their children to school to be educated. We'll also have a live widget on the isology hub website. So that we can see our STG goals are updated whenever a new member joins!
Now let’s get back to isology!
There is a wealth of information in there, and it's not just about documents…we've got a unique roadmap that's been trademarked, and this is based on our seven-step isology concept! We've provided an ISO roadmap for ISO 14,001 for the launch. This will take you through everything that you need to do to get ready for an assessment for ISO 14,001. It also provides everything that you need for an environmental management system, even if you don't want to go for certification! So, how to create an environmental policy, what to look for in terms of creating your objectives, how to identify your environmental aspects and impacts, and how to launch your management systems…it takes you through the seven steps. In addition to that, we've also given you access to our eLearning courses. A lot of the learning is through videos, to action plans, guiding you step by step through your ISO roadmap. We also include checklists workbooks, cheat sheets, and templates, as well, to support you. So, some examples of those could be a launch communications planner, or even an email launch sequence and templates to go with it. Things like internal audit scheduled templates, report templates, samples of policies and procedures and so on. As I said it's not ISO in a box, these are just examples of best practice. And we guide you through creating your own documentation for your own bespoke management system. And, of course, we’ve got our live Q&A’s, feel free to join us for those live Q&A’s within the membership, or we can answer any questions that you've got.
The other thing that we're really excited about launching as well is our ISO coach programme!
ISO Coach
We're conscious of the fact that some businesses might just want to join the membership and get on and do it all themselves. Or they might need some guidance and support. There is an upgrade available, which is the ISO coach programme and that's a six-month programme, where you'll be part of a small group of up to seven other individuals. On a fortnightly basis, you will have group coaching sessions on the seven steps. Then on the alternate fortnight's, you can book one-to-one sessions with your ISO coach to go through and discuss any queries concerns or review documents that you've created, just to help you on your journey and make sure that you stay on track as well. This programme does start at specific dates! The next date that we've got starting will be the 2nd of June. So, if any of you are interested in joining the ISO coach programme, please do get in touch with us!
Because the isology hub is new, we would absolutely love to hear about any suggestions or ideas on content that you'd like to include within the isology hub. Every single month we'll be adding new content, whether it's an ISO roadmap for implementing another ISO standard. So, I'd be delighted to hear from you and also to answer any questions that you might have about the isology hub.
So regardless of whether you're just starting out on your ISO journey, or you've already got a system in place but just want to raise your game that bit further, we would love for you to join us as a member on the isology hub!
Thanks very much for listening and I look forward to catching up with you on the next ISO show!
Dinesh Sharma, Director of Information Security Governance at Epiq, joins us on the ISO Show today. He discusses ISO 27001, his in-depth experience of this standard, how it’s working for Epiq, lessons learned, and how he manages this globally for Epiq Global.
We are so excited to interview Dinesh! He has a wealth of experience in terms of implementing frameworks like ISO 27001 and PCI DSS. He’s got plenty of experience ranging from developing information security policies, procedures, managing risk assessments, to delivering security training and awareness, and overseeing internal audits. He also has expert experience in security management and governance as his last 15 years focused on information security.
You’ll learn about:
First and foremost, let’s dive into what Epiq is and does…
What does Epiq do?
Epiq, primarily based in the U.S, is a global professional services company, operating in approximately 25 countries including Germany, Belgium, India, London and so many more.
Epiq primarily provides support to the legal industry (so to law firms and the legal departments within large organisations). Their key service is around E-discovery. This is where there is potentially an investigation, or if two parties are about to enter a litigation. Some processes need to happen around data collection, data review, forensics, processing and document review. Epiq can make all of this so much more efficient and cost-effective for clients! Another core service Epiq provides is court reporting and transcription services. Other services include business transformation services, class-action and a range of other services.
Now, let’s find out more about Dinesh’s role…
Role at Epiq
Dinesh is part of the Global information security function at Epiq. They have a dedicated Global information security team to support the business.
Dinesh’s specific role is to lead the security governance side of things. This means that he manages and helps to define the information security policy set and Information Security Management System (ISMS) within Epiq. He also leads and coordinates the internal security assessments (part of which is internal ISMS audits as well as internal security audits across Epiq). He even reviews and provides input on contracts of clients and vendors around security clauses to ensure they align with the policies of Epiq. His team also delivers staff security awareness and training. Finally, his team manages security certifications including ISO 27001 (very relevant for today!).
So, let’s explore how a mature ISMS is managed…
How to go about setting up a security team and manage it in terms of global responsibilities?
At Epiq they have a dedicated team within their information security function for security operations. This team oversees the security toolset, they monitor the alerts from this toolset, such as their end-point detection and the logging and alerting around network security. This security operations team also takes the lead on defining their processes and handling any security incidents. So, they have a separate team for this specifically.
They also have a separate team for security architecture and security engineering. These teams work very closely with the business to make sure that security is considered and embedded within the projects and new offerings Epiq has as a business, as well as developing their tools. So, if Epiq is looking to implement a new security tool, this team will be very involved in looking at the different vendors that provide that offering, how that would be embedded and work within the infrastructure of Epiq, and the environments with which they serve their clients. So, Epiq has got the structure of sub-teams within the security function well defined!
Of course, sitting on top of this, Epiq is very fortunate to have some very experienced and very qualified leadership come into that team. The governance and operations side is managed by a gentleman called Jason. He has lots of experience and brings experience from other industries he’s worked with. He has a peer called Andrew, who looks after the engineering and architecture side. Epiq also has a new Chief Security Officer (CSO) who is very knowledgeable and savvy. He is doing a really good job of lifting the profile of not only security within the organisation, but also Epiq’s security functions. So, they are fortunate to have that leadership as well.
This is fantastic…when organisations are starting with implementing an ISMS, we always find that leadership commitment is so key! It’s great to hear that Epiq has got a mature management system yet are still continuing to focus on leadership commitment and bringing that in from various angles across the organisation as well.
In terms of the ISMS then…
Epiq has got many other security standards, so what we want to know is how their ISMS helps them to manage all their activities.
Well, looking at the requirements of ISO 27001 and setting up an ISMS that works, Dinesh thinks the most important thing it gives an organisation, regardless of what level of maturity it is at, is what the basic components and principles are in terms of a framework that you should be having in place or that you should consider having. This is because if you want to go for certification to ISO 27001, then you must have some of these things in place.
Dinesh very much sees this as a baseline!
Once, you establish that baseline and you’ve got the documentation, the processes which support the documents and the staff in place who can deliver on those processes. You then think…‘what can you do to increase the maturity’?
A big part of ISO 27001 is continual improvement. This is something Dinesh thinks is very important and puts a lot of focus on in his role. So, that’s all tied with the kind of internal security reviews that they do with the internal assessments that happen. But any feedback they get from the business, or any input or discussions they have with the business which can raise or flag something, e.g., as a potential block, are put onto their continual improvement register to work with the team or the business area. It might be something they have to work on themselves. The important thing is to always look out for these kinds of things. That’s why this is a key area of focus for Dinesh, in his role, as he thinks about what can improve each step of the ISMS in Epiq.
However, a lot of companies, once they’ve completed the assessment, think that’s the job done. But you can’t put your feet up just yet! This is only the beginning of the journey, which is why Dinesh identifies this as the baseline and the foundation to be used for continual improvement.
So, let’s look at what Epiq has implemented in relation to continual improvement, which has been above and beyond this baseline.
Epiq and continual improvement
Epis has implemented a Critical Asset Reviews. They identified their 15 most critical assets and instead of doing a full security review, they pick the 10 most important controls and other controls they think would deliver the highest level of security if they had it in place. So, they have done a very focused security review, based on risk and what they think their most important assets are. They dig deep into what are the risks and issues and by acting on these, it moves Epiq to another level.
Now, let’s move onto the part where we dispel myths around ISO standards!
Dispelling ISO 27001 myths
Dinesh believes that a good understanding of ISO 27001 is needed to know what the standard actually means. There is a difference between being aligned and being certified to ISO 27001. So, an independent review of your ISMS is really important as it shows you haven’t just picked and chosen which parts of the core standard you’re going to implement. It shows that you’ve had to do them all and have had that verified and tested. This would provide a level of assurance to your organisation and stakeholders. That’s why there is such a big difference between being aligned to the standard and being compliant with it.
Finally, I’m sure our audience would love to know…
What has worked well from an information security perspective in relation to ISO 27001?
Dinesh identifies the top-level management commitment within a business as the most crucial thing in any implementation of a standard. The business needs to understand the importance of information security. So, everyone needs to be aware of what the benefits are, what’s going on and what is important…having this conversation in your business really makes everything easier according to Dinesh. Epiq does this during their management reviews, where all four of their CEOs attend. They take the management review section of ISO 27001 and cover most of it in their quarterly meetings, and because this is visibly supported by their CEO, the business leaders reporting to the CEO and all their directors attend the management reviews as well. So, they all understand what’s going on, what’s important and what the key risks are from the security team’s perspective. Having this conversation just makes everything a lot easier according to Dinesh.
That’s it from Dinesh! We hope you enjoyed learning about Epiq’s journey…it’s inspirational to hear how Epiq is still developing, evolving, improving and still getting such fantastic commitment from the very top as well. It clearly demonstrates Epiq Global’s commitment to information security without a shadow of a doubt!
Contact details for Dinesh, if you have any enquires or would simply like to connect with him, you can get in contact using one of the ways below:
Email: dsharma@epiqglobal.co.uk
Website URL : Epiqglobal.com
LinkedIn handle: uk.linkedin.com/in/dineshcsharma
Seacourt is the highest scoring B Corp printing company on the planet, they believe in business as a force for good for society.
Fun facts: Seacourt is the winner of the Queens award for sustainable development. They’ve won this three times! In 2017, they were also crowned Europe’s most sustainable SME! No wonder they are recognised as one of the top three leading environmental printers in the world!
Seacourt Managing Director, Gareth Dinnage, joined us for an interview to tell us about Seacourt’s journey and its initiatives. Gareth has been part of Seacourt’s sustainability journey from the very start. He started his journey first as apprentice and then heading up to Sales and Marketing and finally owner and Managing Director.
You’ll learn about:
Let’s start right back at the beginning of Seacourt’s journey!
Where did Seacourt begin and where did its sustainability journey begin?
Seacourt started in 1946! They were set up as a commercial printing company in Oxford, working with local businesses. Not much changed for them until the mid-90s, when the owners at the time had the good fortune to attend a seminar focused on sustainability.
We know what you must be thinking, whoever put together this seminar must have had incredible foresight, to have looked into commercial impacts and sustainability!
The owners realised that the printing industry is among the fifth largest manufacturing sectors in the UK since 1996…
And that it’s also the fourth worst polluter!
That’s when they decided that they don’t want to be part of the problem, but a part of the solution. This thought marks the moment of a change of goals and priorities for Seacourt. From this point in 1996, the business changed from a linear business model, focusing on outputs, to becoming a value-based business, to considering the impacts on the environment and society, as well as profits.
This marked the magic transformation of Seacourt!
For the last 25 years, their philosophy has been “will this improve the environmental performance of our business. If the answer is “yes!”, then they do it regardless of the financial cost. So, without this fundamental change in mindset, Seacourt would not have been where it is today.
Guiding principle for Seacourt
Environmental management has been a guiding principle for Seacourt for the past 25 years. It’s fundamental and core to the company.
Currently:
So, when you wrap all of this up in its entirety, Seacourt has created a concept called Planet Positive Thinking -which means that they give back more carbon into the atmosphere than they are responsible for consuming.
Seacourt’s journey to understanding their carbon footprint
A lot of businesses are new to the concept of Net Carbon Zero. So, let’s find out how Seacourt went about understanding what their carbon footprint was.
Seacourt does this by unravelling their entire supply chain and ask challenging questions to their supply chain, such as how they power their plants, what is the carbon impact per tonne of paper they are using, how they transport their materials from the forest and much more never before asked questions! They used the amount of paper they have purchased over a 12-month period and worked with their suppliers to get an accurate carbon impact figure. They created their own methodology and matrix, using the same process to identify the carbon impact figure that they used for their paper, for other areas in their operations, for example their ink.
By this point, Seacourt knew their carbon impact holistically for a 12-month period and sought to work on a regenerative project in the Amazonian basin. In this project, Seacourt safeguards 86,000 hectares of endangered forestry and are reforesting 12,000 hectares of deforested lands. They also have a social element where they support a programme with indigenous people. So, this is how Seacourt maintains their Planet Positive Thinking element, as they give back more than they consume in everything they have an impact on.
Significance of being Net carbon zero
Of course, we are conscious of the fact that we are in a lockdown where many businesses are struggling financially. So, this is for those of you thinking “is it going to be really costly for me to be Net Carbon Zero or Carbon positive?”. Gareth emphases the need to understand the impact of sustainability, to have a strategic plan and an idea of what goal you want to reach and how you will achieve it. Otherwise, your business will get left behind! Other business will pick up this leadership agenda and show exactly what business can do. Gareth identifies these businesses as the ones to be the most successful. This is already evident among investors refusing to work with fossil fuel-based business. That’s why business need to act responsibly to stay ahead of the game!
How management systems help Seacourt run their business
Seacourt has been certified to ISO 9001 and ISO 14001 for years. These management tool helps Seacourt set the business up to the highest standards and ensure continual improvement. The quality environmental management system provides a framework for delivering sustainable best practice.
B Corp
Now let’s move on to talk about B Corp!
B Corp is the global movement that aligns businesses who share the same philosophy, which is that businesses can and should be a force for good. Certified B Corps meet the highest standards of verified social and environmental performance, transparency, and accountability. The unifying goal of B Corps is that the main driver is stakeholder value, not shareholder value.
Understanding your supply chain
For those of you who have not yet looked into their supply chain, Gareth recommends:
These steps would give you key findings and insights that you can use in your goals and strategy.
Contact details for Gareth, if you have any enquires or would simply like to connect with him, get in contact using one of the ways below:
Email: garethdinnage@seacourt.net
Website URL : www.seacourt.net
Twitter handle: @seacourtltd
LinkedIn handle: Garethdinnage
Today, we’re joined by the Director of Corporate Assurance at Totally PLC, Falu Bharmal.
Falu plays a key role in working with NHS England and has in-depth knowledge and understanding of ISO implementation, Legal Policy relating to corporate governance, health and safety, and integrated Risk Management. He has extensive experience in establishing new corporate governance structures, systems, and processes to ensure organizations are fit for purpose.
Today, Falu is here to discuss ISO 27001 (Information Security Management), and why it’s so important to have consistent practices throughout a company.
Falu explains how he’s able to implement new ISO’s so effectively and some of the biggest improvements ISO 27001 has allowed him to make.
We talk about how best you can prepare before implementing a new standard, and how ISO’s can help systemise your way of working across a company.
Website:
Mobile phone:
Email:
You’ll learn
Resources
In this episode, we talk about:
[00:29] The services Totally PLC supplies and how they support the NHS and reduce A&E waiting times.
[03:30] The different divisions that makeup Totally PLC.
[05:36] The ways Falu as Director of Corporate Assurance is involved with ISO implementations.
[06:34] How Falu implements ISO standards effectively.
[07:21] How ISO 27001 is used as a best practice mechanism for Totally PLC.
[08:20] Some of the biggest improvements Falu’s made through using ISO 27001.
[09:25] How ISO standards help to systemise ways of working across a company.
[10:14] The different roles Totally PLC has dedicated to ISO implementation.
[12:18] The best things you can do before implementing a new standard.
[13:46] The extra pressures Totally PLC has faced due to the pandemic, and the new opportunities this has brought.
If you need assistance with implementing ISO 27001 – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Steve Mason is a Senior Consultant at Blackmores (UK) Ltd, and has a 100% success rate of supporting clients in achieving their ISO 9001 & ISO 27001 certifications on their first time.
With over 38 years of experience working with standards, Steve is incredibly knowledgeable about how to ensure companies get the best benefits when implementing new standards. Steve has never stopped advancing himself and continues to broaden his knowledge of new standards as they come into existence.
Today, Steve is back to discuss the new ISO 27017 (Information Security Controls for Cloud Services Standard), and why it is needed in addition to ISO 27001.
The current publication of ISO 27001 was released back in 2013 before cloud security was as big of a concern. Due to this, it does not adequately cover cloud security and hence the new standard ISO 27017 was released.
It is wise not to assume that the cloud is secure on its own, you need a provider that can demonstrate protection from hacking and guarantee you security.
There are 7 new controls that the ISO 27017 standard brings -
In this episode, Steve talks through some of these new controls, explains why they’re so important, and describes who can benefit from implementing this new standard.
You’ll learn
Resources
In this episode, we talk about:
[01:30] Why it’s important to have a standard for cloud security when we already have ISO 27001.
[02:46] The type of new controls in ISO 27017 and how they make the standard ‘cloud effective’.
[05:37] Some examples of the new controls that ISO 27017 has.
[07:20] The prerequisites you need before implementing ISO 27017.
[08:37] The type of certificate you get with ISO 27017.
[10:22] How ISO 27017 can set companies apart from their competitors.
[11:03] What the future for ISO 27001 and ISO 27017 looks like.
[13:03] Advice for anyone thinking of implementing ISO 27017.
[14:20] The main benefits there are from implementing ISO 27017.
If you need assistance with implementing ISO 27017 – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
Steve Mason is a Senior Consultant at Blackmores (UK) Ltd, and has a 100% success rate of supporting clients in achieving their ISO9001 & ISO27001 certifications on their first time.
With over 38 years of experience working with standards, Steve is incredibly knowledgeable about how to ensure companies get the best benefits when implementing new standards. Steve has never stopped advancing himself and continues to broaden his knowledge of new standards as they come into existence.
Today, Steve is here to discuss ISO 27701 (Data Privacy), and why it’s so important to have so that you can prove you are GDPR compliant.
Since the new European Data Privacy Laws were introduced in May 2018 there have been over 150,000 personal data breaches within Europe, and the estimated total of GDPR fines total a little over 220 million euros.
Steve explains why GDPR is so important, how companies can avoid having data breaches, and what makes ISO 27701 different from previous standards.
You’ll learn
Resources
In this episode, we talk about:
[00:29] The big personal data breaches that have happened in the last 2 years, and the fines the companies received for not being compliant with the data protection laws.
[04:11] Why we have General Data Protection Regulations and what they are there to protect.
[06:36] What ISO 27701 is and how it helps companies be GDPR compliant.
[09:26] What PII (Personally Identifiable Information) is.
[11:41] An overview of ISO 27701 and what its main clauses are.
[14:04] What the two control sets of the standard are and what the difference between a data controller and a data processor is.
[17:20] How this standard helps companies know what needs to be put in place to be GDPR compliant.
[18:51] What makes ISO 27701 better than BS 10012 and why it will eventually completely replace it.
[22:14] What you already need in place to get ISO 27701 certified.
[24:10] The main benefits for companies implementing this standard has.
If you need assistance with implementing ISO 27701 – Contact us!
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
So this is for our ISO Show listeners that are already certified to ISO Standards, in some cases – not that often, some companies can get really fed up or frustrated with their certification body provider.
Now on the whole, accredited CB’s are great – however over the last 14 years we’ve come across the good, the bad and the ugly too!
So, this podcast is for those companies that maybe looking to switch, so we’ll cover…….
Why companies decide to change CB’s
Can’t get hold of anyone to help them – inform them of change in business and the CB is not adaptable.
Frustrated with lack of organisation – not keeping client informed, assessor showing up to audit the wrong standard.
Their CB is not listening to them
Not happy with the assessor – No really a hard reason – Just request a different Assessor
Lack of value – assessor shows up later and leaves at 2.00pm and you don’t get the report for another 2 -3 weeks after chasing.
Why switch?
Because you can – you have a choice
You are expanding internationally – need a CB with an international presence
How to switch
Here in the UK - If you are certified by a UKAS accredited certification body the switch is free of charge to another UKAS accredited CB.
Provide your requirements – also explain why you are looking to change CB’s as you want assurance that they will be able to provide you with the service you need.
Consider –
How we can help? – Free service to send an RFQ to CB’s so you can get comparative quotes. We don’t have an exclusive relationship with any 1 Certification Body, but we can help you gain a quote as a free service we offer. If you need help getting a quote, contact us!
Look out for our directory of recommended CB’s in 2021.
Fail to prepare, then prepare to fail. If you don’t want to fail an assessment before you’ve even begun, be prepared.
I’m just going to take you through the top 5 mistakes companies make that can lead to stress and failure – now this isn’t a definitive list – there are of course many things that could go wrong, I’m just going to share with you my 5 favourite blunders that you can very easily avoid.
Yes – pretty obvious, but you’d be surprised to hear how many times a Management systems is just kept to one person and a communications plan has not been implemented to inform all employees. The best informed employees make the best people to be assessed.
Imagine – you are an assessor and you rock up only to hear an employee when asked about their process say ‘What process? What Environmental Policy?
Communication plan – CEO, Champions, agenda of meetings, launch, newsletter updates, online comms i.e. slack
Not having access to the right people
This helps you to ensure that the right people are available at the right time.
Not having access to your management system
Sounds silly, but you’d be surprised.
Accessiblity is key – Sharepoint/intranet/wiki’s/dropboc
Not having access to your records.
And last but not least……
So to recap – the 5 mistakes to avoid in an ISO assessment are……
And don’t forget, these mistakes can easily be prevented if you prepare well before an assessment.
In the words of Benjamin Franklin, By failing to prepare, you are preparing to fail.
If you need any assistance with ISO standards, contact us!
Richard Matheron is the Quality and Continuous Improvement Manager at BP Chargemaster. He’s had a long career as a quality professional and hands-on Manager, with his background mostly being in engineering and manufacturing management.
Currently, Richard is working for BP Chargemaster helping them transform themselves from an SME to an international world-class business. BP Chargemaster is the UK's biggest name in electric vehicle charging. They design, build, sell and maintain the most popular charging units in the country, and have begun to expand their business worldwide.
Today, Richard is here to discuss his experience with implementing ISO 9001 (Quality Management) and ISO 14001 (Environmental Management). These have been a fundamental component in his management of transitioning the company from an SME to an international organisation.
Richard explains why these ISO’s are so necessary, and why it's so important that a company has someone who can focus on continuous improvement within their business. He reiterates the importance of people to not be afraid of change and discusses some of the most effective ways to carry out positive improvements within your organisation.
He explains the ways having a priority board and suggestion box can help to drive continuous improvement, and how often the best solution for an issue isn’t a complicated one but is one of the simplest...
Website: www.bpchargemaster.com
Mobile phone: 07813098736
Email: Richard.matheron@bp.com
You’ll learn
Resources
In this episode, we talk about:
[00:30] Who Richard is, what he does for a living, and what he’ll be sharing with us today.
[01:50] The types of dance that Richard teaches in his free time.
[03:44] BP Chargemasters position in the electric vehicle charging market.
[04:55] How demand for electric cars has changed over the last year.
[05:39] The tax incentives and grants that are available for businesses for using electric cars.
[07:14] What Richard does as the Quality and Continuous Improvement Manager at BP Chargemaster.
[10:05] The value of data and the importance of digital security.
[12:29] How to best manage a company that’s growing from an SME to an international enterprise.
[18:22] The way Richard drives continuous improvement at BP Chargemaster.
[20:43] What ‘8 D’ is and how it can help to identify the causes of problems and the best ways to improve on them.
[25:06] How Richard tracks the different improvements that he puts in place.
[27:27] The book Richard recommends to those working in the business world.
If you need assistance with implementing ISO 9001 or ISO 14001 – Contact us!
This episode we are joined by Mark Frudd, Managing Director and Founder of Security and Software Development at company TriplePs.
Mark’s here to tell us about the information security Standard ISO 27001. It’s brought his business countless benefits, allowed them to expand, and win government contracts. But it hasn’t been all easy sailing, the ISO has brought up some unique challenges for Mark to overcome. He explains what these are, how he tackled them, and what he wishes he knew before embarking on this journey...
Mark Frudd is the Managing Director and Founder of Security expert at software development company TriplePs. His work history revolves around the cybersecurity industry and delivering high profile public sector projects.
With a personal motto that IT and security doesn’t need to be expensive to be effective, Mark now focuses on providing affordable security, and software solutions, that meet the needs of both his clients and their end-users.
This episode, Mark is here to talk about his experience implementing and managing the information security standard ISO 27001. After putting the ISO into place his company quickly expanded in size and Mark soon realized that the standard wasn’t being effectively implemented across his business.
He explains why this was, what he did to rectify it, and how he could have avoided that happening in the first place.
In his own words ‘An ISO isn’t just for Christmas, it’s there every single day. You don’t just manage it, you adopt it.’
Mark explains how having ISO 27001 helped expand his business and why it’s so important when trying to gain government contracts.
Finally, he explains how following this standard has shaped TriplePs business strategy and the different benefits that it has brought to his business...
Website: https://www.triplepsltd.com/
Twitter: https://twitter.com/TriplePsLtd
Linkedin: https://www.linkedin.com/company/triplepsltd
You’ll learn
Resources
In this episode, we talk about:
[00:33] Who Mark Frudd is and how he ended up implementing ISO 27001.
[01:04] Who TriplePs are.
[01:51] Mark’s history working in Butlins, and what he learnt there.
[02:51] The type of security work TriplePs does.
[05:35] Why TriplePs decided to work with Blackmores when implementing the ISO 27001 procedure.
[07:22] What Mark’s role in TriplePs is and what his daily work life looks like.
[09:00] What the process for implementing ISO 27001 looked like.
[11:16] The importance of maintaining the right ISO standards when your company goes through rapid growth.
[13:18] The importance of adopting ISO’s into the heart of your businesses culture.
[15:52] How ISO 27001 has shaped TriplePs business strategy.
[18:57] The best way to implement a new ISO standard.
[20:51] The benefits involved with following the ISO 27001 standard.
[23:34] Mark’s favorite book.
[24:36] How ISO’s are a constant and not ‘Just for Christmas’.
[25:27] How to find out more about TriplePs.
If you need assistance with implementing ISO 27001 – Contact us!
Andy Pavlovic is the Compliance director at Maris. Maris is certified to four ISO standards, ISO 9001 for quality, ISO 14001 for environmental management, ISO 45001 for health and safety, and ISO 37001 for anti-bribery standards. He manages and maintains all of these ISO standards for Maris and makes sure that the company upholds these standards across the board.
This episode, Andy Pavlovic is here to share with me what he’s learnt from his years working as Maris’s compliance director and overseeing the implementation of four different ISO standards.
Andy speaks about how ISO standards enable Maris to maintain consistency across the company in the quality of their work, their health and safety procedures, and their environmental impact.
He explains how implementing standards allow organisations to be scalable and how having multiple standards doesn’t necessarily mean spending more time on them.
With ISO 37001 being a relatively new standard, he explains the value following this standard has not only for the ethos of Maris but also to the commercial side of his business.
Finally, he explains how Maris keeps their employees compliant with their standards and what the key benefits of having an integrated management system are...
Website: https://www.maris.co.uk/
Linkedin:
You’ll learn
Resources
In this episode, we talk about:
[00:32] Who Andy Pavlovic is and the different ISO standards that Maris are certified with.
[01:48] Andy’s experience working with ISO standards.
[02:18] What Maris does and the industries they work in.
[03:05] Andy’s ISO responsibilities as the Compliance Director.
[04:00] How ISO standards work across different cultures and the importance of having these in place.
[05:12] How Andy manages four different ISO standards, and how having these standards enable companies to be scalable.
[08:07] The importance of organisations accepting standards as part of their culture.
[09:52] The importance of giving new employees a proper formal induction and what this process looks like.
[11:52] The commercial advantages of having ISO standards and how this has helped Maris win new business during the COVID pandemic.
[13:34] What the benefits of having an integrated management system are.
[15:16] Advice Andy has for anybody who is looking to implement ISO standards.
[16:45] Andy’s book recommendation to anyone looking for self-growth.
[18:19] The importance of having someone with the right expertise in house when implementing ISO procedures.
[19:14] How to get in touch with Maris or Andy himself.
If you need assistance with implementing ISO 14001, ISO 9001, ISO 45001 or ISO 37001 – Contact us!
Yousif Rajah is the Head of Info Sec at DotDigital, a UK-based tech company that builds software service solutions to help customers engage with their clients. He coordinated most of the work involved with creating the ISO 27001 system, and recently has contributed to DotDigital becoming ISO 27001 certified.
« It sounds dauting and it feels daunting, but if you have a program in place already, chances are you’re quite a long way down the road already. » - Yousif Rajah
Picture this: Your digital marketing company is expanding, and you know you need to comply with data protection requirements, protect your reputation and demonstrate to customers that you have taken the steps to protect your business and their personal information. You’ve heard of the importance of becoming ISO 27001 certified but are unsure where to start. Join us today as our guest, Yousif Rajah, explains his company’s journey in becoming ISO 27001 certified, the changes he has noticed since implementing this ISO standard, and how you can get started on becoming certified today.
Website: https://dotdigital.com/contact-us/
You’ll learn
In this episode, we talk about:
[01:13] What does DotDigital do?
[02:14] Something not many people know about Yousif
[03:34] Main driver behind implementing ISO 27001
[04:57] The journey of becoming certified and going through the assessment
[05:52] What is the scope of the certification?
[7:56] What was the biggest gap in the gap analysis?
[9:16] Reaching the gaps and the difference it made within DotDigital
[11:04] The benefits of certification on a global scope
[12:35] What Yousif has learned since implementing ISO 27001
[13:28] Main benefits to DotDigital in achieving certification
[15:30] If you could give any tips to someone implementing ISO 27001, what would they be?
[16:11] If you could gift a book to somebody what would it be and why?
[16:49] Favorite quote to leave listeners with
9th September 2020
#52 Lloyd’s of London shares ISO Journey to HSE certification
Today’s Guest
Trevor Jennings is a Risk Manager with the Corporate Real Estate Department at Lloyd’s of London. He works to provide client facing advice and support on all matters of risk, excluding financial and contractual risk, and to ensure health and safety is co-ordinated across all building users within Lloyd’s UK and overseas premises.
« It’s steps at a time that will get you through to the certification aspect. »
- Trevor Jennings
Picture this: An organization has set effective environmental, health, and safety standards for their company. Worker participation is high and the leadership is flourishing. Sounds marvelous, don’t you think? Tune in to this episode to learn from a man who has made this happen for the world's specialist insurance and reinsurance market. Trevor Jennings speaks about his journey to implementing environmental standards (ISO 14001), health and safety standards OHSAS (18001), and his experience with the migration to the latest health and safety standard ISO 45001. He details the main advantages of having an ISO compliant health and safety system in place and the key factors that led to Lloyd’s success, including employee engagement groups to foster worker participation. Trevor divulges the top environmental factors that Lloyds is focusing on and how it affects their bottom line, as well as his top tip for anyone who is looking to implement ISO 14001 or ISO 45001.
Website: https://www.lloyds.com/about-lloyds
Linkedin: https://www.linkedin.com/in/trevor-jennings-msc-cmiosh-44917b37/
You’ll learn
Resources
In this episode, we talk about:
[00:51] What is Lloyd’s and what is Trevor’s role?
[03:36] Something not many people know about Trevor
[05:10] How Trevor got started at Lloyd’s
[07:34] The main advantages of having a health and safety system in place compliant to 18001
[08:44] Facing the challenge of implementing 14001
[12:12] The Health, Safety, and Environmental Coordination Group
[13:42] Energy is at the top of the list of targets to focus on
[14:54] The effect on the bottom line of operations
[16:52] The migration of OHSAS 18001 to ISO 45001
[21:24] Tips for organizations looking to implement ISO 14001 or ISO 45001
[23:48] If you could gift a book to somebody, which would you choose and why?
Today’s Guest
Ian Van Der Pool is the chairman of the European Facilities Standards committee and co-author of ISO 41001 and ISO 41014. He also has his own business, which is ISO 41001 CSI. He currently works with the Dutch Ministry of Defence and is responsible for implementing a brand new FM system fully compliant to ISO 41001.
Tune in to this episode to learn from Ian Van Der Pool, who has lots of valuable experience implementing ISO standards for facilities management. Ian speaks about how he got involved with ISO 41001, why it’s important to have an ISO standard, and how such a standard is created. He details the commercial value in ISO 41001, the benefits and main drivers of having a facilities management system in place that is aligned with the standard, and the risk of not having one implemented. The uncertainty of returning to the office amid a pandemic is discussed, along with the effects of this uncertainty. Then, Ian shares his top tips for implementing facilities management systems, noting a valuable lesson he learned in all the organizations he has interviewed.
Website: www.iso41001csi.com
Linkedin: www.linkedin.com/in/ianvanderpool
Course Date: 18th September 2020
Course cost: £500
You’ll learn
Resources
In this episode, we talk about:
[00:43] A bit about Ian Van Der Pool
[02:50] Something not many people know about Ian
[03:40] How Ian got involved with ISO 41001
[06:51] Why is it important to have an ISO standard for facilities management?
[08:32] Is ISO 41001 the only certifiable standards that organizations can be certified against?
[09:30] How does a standard get created?
[12:25] Main drivers for implementing ISO 41001 for a facilities management company or venue
[14:39] The commercial value in ISO 41001
[17:39] The risk of not having it implemented
[18:55] The effects of uncertainty regarding going back into the workplace
[20:43] The benefits of having a facilities management system in place that is aligned with the standard
[22:37] Why would you need ISO 41001 in addition to or instead of other standards?
[27:30] Tips for implementing facilities management systems + A valuable lesson learned in all the organizations Ian has interviewed
[31:02] How to learn more about and contact Ian + About his foundation training course
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
To celebrate hitting 50 episodes, I wanted to bring to bring to you something a little extra special today. and that is ‘How to implement any ISO’, but before we do, I’d just like to say a huge thank you to all our listeners. Keep sharing the ISO Love, and share this episode with anyone who is looking to take their business to the next level.
In this episode I take you through 4 simple steps to implementing any ISO Standard.
When you break it down, the same ingredients apply to how you approach to implementing and ISO Standard.
To celebrate hitting 50 episodes, I wanted to bring to bring to you something a little extra special today. and that is ‘How to implement any ISO’, but before we do, I’d just like to say …….
Thank you, thank you, thank you – for listening in, and giving your time to listen to the ISO Show, I’ve loved recording the last 50 episodes with some amazing guests, and I really hope you’ve found them beneficial and taken away some great tips and insights into how other businesses have succeeded and how they’ve transformed their businesses with ISO Standards. So I hope you’ve enjoyed listening to them too, if you did please could leave a review and hit subscribe wherever you listen to your podcasts, because that that means that we can continue to inspire and educate others, and it also means we can keep getting epic guests on the show.
I’d also like to give a quick shout out to Steph Churchman, our Communications Manager here at Blackmores, who has been my saviour in doing these recording – especially when we’ve had technical issues, and even lost guests midway through recording. She’s been absolutely fabulous in making my vision for the ISO Show become a reality! So huge thank you Steph! You are a star!
So, onto today’s episode which is ‘How to implement any ISO Standard’ – you may think, hey that’s a bit of a bold statement, there are thousands of ISO Standards! Yep! But when you are implementing an ISO Standard to improve a business, there are a few secret ingredients, and I’m going to let you in on those today. But I don’t just want to do that, I’m going to provide a free check-sheet on ‘How to implement any ISO Standard’ which will be available to download from the show notes.
I’m going to share with you our ISO Steps to Success – this is a proven methodology that, at we’ve refined over the last 14 years, and implemented for over 250 companies – 250 companies, in over 20 countries. Not only that – with a 100% success rate, yep, an awesome 100% success rate. So here’s what we do
# 1 Understanding the organisation
You need to fully understand what your businesses biggest risks are but also establish where you most impactful opportunities are.
It’s only really when you’ve fully understood your organisation that you can create a roadmap to achieve success with where you are trying to get to.
# 2 Creation
Create the Management System policies, procedures and templates – long gone are the days of Quality Manual or worse still ISO Manual – you label it to suit your company brand, culture and vision. Give it some thought, as this will be the central point that you want employees to go back to I they need any guidance and support on their way of working. For the purposes of this podcast, I’ll simply refer to the Standards terminology of ‘Management System’.
So lets get down to the creation of your management system…..
Top tip alert – where the standard says ‘shall’ it is basically saying – don’t bullshit me – you’ve got to god damn have this in your system or it will fail an assessment!
So if the standard says’ top Management SHALL establish, implement and maintain an environmental Policy – it means, DO IT!
If the standard says ‘The organisation SHALL establish environmental objectives at relevant functions and levels – DO IT!
The standard is there to HELP your business, and it is crystal clear in the ‘SHALL’s’ exactly what you need to do to achieve success.
# 3 Sharing
There is no point having an awesome ISO Management System sitting in a manual or buried in a server somewhere if no one knows about it, or they can’t find it!
You need to SHARE it with everyone, after all its been created for the organisation to succeed – to be more profitable, productive, reduce risk, be more sustainable – so everyone needs to be AWARE of the management system AND be empowered to take responsibility for it!
There is no point in having an Information Security System in place, if know one knows what a security breach is in your business is or who to report it too! What’s the point!
So you need to have….
# 4 - Engagement
Engagement is so critical to making this a success……
If you are launching a new client onboarding process to improve the customer experience – make it clear, how the process works, what results you expect to see, how you are going to monitor the results, and who is going to make it happen!
Get those responsible to own it and take pride in their achievements.
In all businesses there are usually closet ISO Champions – just waiting to be asked to contribute – so why not encourage engagement?
Why not Create a hub for Champions? – give them the tools and platform to make it happen!
This isn’t just about when you launch a new ISO System, but to demonstrate how you are continually raising standards! so let’s say you have a Health and Safety System – ISO 45001 – Your H & S Champions could be championing the COVID-19 H & S Risk Assessments, controls and awareness for your employees across all area of your businesses.
Having these champions, will make Management’s life easier to communicate key issues and solutions, to create a better working environment and happier clients.
Carrying out Internal Audits – So this another ‘Shall’. It is not optional, and this is where ISO Standards can get bad press, as a result of lazy or incompetent auditors (or worse still lazy and incompetent) just using it as a ‘tick-box’ exercise. Use this opportunity to really engage with your workforce – this is such a value tool in the tool box if done in the right way – it helps you to understand an employees:
Level of understanding
Opinions and views of the process
Opportunities for improvement
Gauge level of compliance and readiness for the assessment.
Engaging in the Leadership Team through Management Review
So that’s it in a nutshell, that’s how you implement ANY ISO Standards.
I’d love to hear what your top takeaways were on the show today, and share that with me, I absolutely love reading the reviews and suggestions.
Don’t forget to follow us on Linkedin. Also, ISO Show listeners will get a 10% discount on ISO Steps to Success, ISO Support Plans and ISO Elearning. Just quote ‘ISO Show’ in your enquiry.
………before I go I just wanted to say thank you so, so much for being here and listening to the ISO Show, and showing up today – if you know anyone, colleagues, associates, friends in your life that would really benefit from having an awesome System in place to take their business to the next level – to be more efficient, sustainable and profitable then please share this episode with them.
Thanks once again for listening, and I look forward to catching you on the next ISO Show….
Awesome resources
ISO Steps to Success – Free consultation to discuss the feasibility of ISO for your business
ISO Support Plan – Free health check on your ISO Management System
ISO Elearning – Wide range of ISO Standards courses for just £50 per course.
We’d love to hear your views and comments about the ISO Show, here’s how:
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud
EMCOR has gone from strength to strength over the years, so Alex is joining us today to discuss ISO 22301 (Business Continuity Management) and how the system is helping them to not just survive, but thrive during these difficult times.
Free Covid-19 monitoring tool for businesses - Join James Sharp, CTO, Riskex to hear how to manage your company’s duty of care through a free online tool. This weeks ISO Show explains how to make managing COVID in the workplace easier and safer
Join Mel and Rachel this week as they discuss the main changes to ISO 22301:2019 and how they will affect your Business Continuity Management System
Continuing from last week’s episode we look at how you can engage your staff while implementing and testing the Business Continuity Management System (BCMS).
Join Mel and Rachel this week as they discuss how to successfully share and communicate a Business Continuity management system compliant to ISO 22301.
Join Mel and Rachel this week as they discuss the early steps to implement ISO 22301 – the standard for Business Continuity
As part of Mental Health Awareness week, this weeks’ Podcast covers the management of psychological issues people are facing such as isolation, worry and anxiety both now and over the coming year ahead.
Join Mel this week as she discusses ISO 22301 (Business Continuity), a standard that is completely focused on resuming operations to get back to ‘business as usual’.
Join Mel and Arantza as they discuss The Brewery’s journey to ISO 20121, the benefits gained and continued drive to improve their sustainability:
This episode’s guest has experienced at first-hand what it’s like going from Chaos to Calm amidst the impact of the Coronovirus Pandemic, and how she has slipped into seamlessly delivering her work remotely, which typically would have been done face to face.
So how do you make remote working work for you? Well it partly comes down to the tech, but if you’ve got the confidence in yourself and ability to communicate, its actually really easy.
Recognising that something needed to be done about this wasteful industry a standard for sustainable events was created by the events industry for the events industry known as ISO 20121.
I’m recording this in March 2020, just over a year since we launched the ISO Show and sadly a pandemic – the coronavirus has broken out globally, with over 110,000 reported cases across 95 countries. So I thought it would be helpful to share with you some guidance to try and minimise business disruption caused by the Coronavirus through Business Continuity Planning (known as BCP).
This weeks ISO show provide an overview of ISO 9001:2015, where interpret the standard (as a technical document) and break it down into very simple terms what the requirements actually mean.
Tony Bennet, Senior Information Security Executive shares his journey on achieving certification to ISO 9001 (Quality), ISO 27001 (Information Security) and ISO 22301 (Business Continuity) in one hit!
Damian Edwards of XMA explains how assurance is built into XMA’s service delivery. Hear why XMA are certified to 5 ISO Standards and deliver ‘Best Practice’ in the IT Sector.
We often get asked which is the best ISO Standard to go for and what are the benefits. In this week’s ISO Show we highlight the top 5 from the Annual ISO survey published by the International Standards Organisation.
This week we're going right back to basics to understand what ISO really means and why it matters to businesses.
We welcome back Derek for the final part in the ISO 14001 Steps to Success series, where we discuss hints and tips for ensuring that your Environmental Management System (EMS) is compliant and ready for your Certification Body Assessment visit.
We welcome back Derek for the second part in the ISO 14001 Steps to Success Podcast, sharing key considerations for creating an Environmental Management System (EMS).
Join us on our ISO Show 3 part series on Implementing ISO 14001. The leading global environmental standard, is still as popular as ever for businesses that are serious about acting responsibility and not just paying ‘lip service’ to ‘going green’.
Join Mel and Derek Hall, this week as they discuss the awesome sustainability work that Derek did to be awarded an MBE for his contribution to sustainability management in business based on ISO 14001 and ISO 9001.
With the ESOS deadline being just a few weeks away, I’m joined on today’s podcast by Andrew Geens, Head of certification at CIBSE (Chartered Institution of Building Engineers) to discuss CIBSE and his views on the routes to compliance and the UK’s readiness for the deadline in December 2019.
The third and final episode in our ISO 45001 Steps to Success Podcast Series covers launching and demonstrating compliance in preparation for an assessment. Paul Robinson, Managing Consultant at Blackmores shares hints and tips for the final stages of implementing your Health and Safety System.
In episode two of the ISO 45001 Steps to Success Podcast series on The ISO Show, Paul Robinson provides tips on where to begin with identifying, understanding and addressing your Health and Safety obligations and how to create a H & S Manual compliant to legal requirements and ISO 45001.
Paul Robinson, Managing consultant at Blackmores, has over a decade of experience of implementing ISO Standards at Blackmores, joins us for this weeks’ ISO Show Podcast. Paul interprets the ISO ‘Speak’ and shares a ‘Masterclass’ in implementing ISO 45001.
Join Mel as she shares her story about where it all started with the launch of Blackmores in 2006.
Many organisations began with a quality manual in the 90’s or noughties and have since added complimentary standards. Typically, these standards are ‘bolted’ on as separate manuals. So what are the issues associated with having separate manuals for ISO Standards?
There are many misconceptions around the well know ‘Clear Screen Clear Desk’ Policy used in IT Security. Join Mel and Steve Mason as they discuss some top tips for promoting the policy to your staff along with some of their own stories.
Join Mel and Paul Simpson, Chair of the ISO 9001 Technical Committee in the UK (TC 176) and Director of Strategy to Action, this week as they discuss the future of ISO 9001.
Certification is the last step on your journey to gaining an ISO. Join Mel as she discusses the certification options available and what you need to consider when using a third party
If your organisation qualifies for ESOS, then there is a chance that your premises may be subject to an on-site energy audit. Join Mel and Rachel as they discuss how to conduct energy audits.
Our ISO Show this week features Lucille Ryan, Sustainability Manager from Informa who provides an insight into how Informa reduces waste and demonstrates a commitment to sustainability to buck the wasteful trend in the industry.
Bribery is one of the world’s most destructive and challenging issues. ISO 37001 aims to promote a more ethical business culture. Join Mel and John (Interchange Solutions) as they discuss how ISO 37001 can help businesses tackle this issue
In our final Podcast episode on how to implement ISO 27001, Steve Mason, Senior Consultant at Blackmores takes us through the last few months of an ISO 27001 project. This stage generally takes three months because it is a UKAS requirement that the system is ‘established’ prior to the assessment.
Last week we looked at how to begin planning you journey to ISO 27001. Join Mel and Steve Mason this week as they discuss how to implement ISO 27001.
In our first episode in the ISO 27001 Steps to success podcast series, we take you through how to implement ISO 27001 with Steve Mason, Senior Information Security Consultant with Blackmores.
Last week we covered what ESOS is, who qualifies and a brief explanation of methods of compliance. In this week’s episode we’ll go into more detail on the methods for compliance, namely ESOS Energy Audits and ISO 50001.
With the ESOS phase 2 deadline looming, do you know if you qualify? And if so, do you know what to do to comply? In this week’s podcast we will look at what ESOS is and briefly cover the various methods for compliance.
You’ve done all the hard work, the Quality Management System (QMS) has been created and implemented. Our final episode in the ISO 9001 Steps to Success Podcast series with Rachel Churchman covers the final critical stage – compliance and preparation for your certification assessment.
In our second episode in the ISO 9001 Steps to Success Podcast, Rachel Churchman explains in detail about how to create and launch your Quality Management System.
Rachel Churchman is my guest on the ISO 9001 Steps to success series. As a Managing Consultant at Blackmores, she brings a wealth of experience of implementing ISO Standards, and will guide you through the Blackmores ISO Steps to success for successful delivery of your ISO 9001 Project.
Established in over 100 years ago back in 1912, The London School of English is the longest-established Accredited English language school in the world. With premises in London and Canterbury, and now offering courses online. I was delighted to be joined by Hauke Tallon, CEO of the London School Group on this weeks’ Podcast.
I was delighted to be joined by one of our ISO Support Plan clients, Optimum on the ISO show this week. Optimum is part of Totally Group Plc and an important player in the healthcare sector in the UK.
I’m delighted Kim-Marie Freeston, Managing Director of UComply shared with me her background and journey to ISO 9001 and ISO 27001 in this weeks podcast. Kim-Marie is a thought-leader in employers’ compliance, in particular the Home Office requirements for employee ‘Right to Work’. Gain an insight into Kim-Marie’s views by subscribing to our Podcast ‘The ISO Show’.
In the ISO Show Podcast ‘How to systemise your business’, I’ll give you an example of a company that doesn’t have a process for new enquiries and one that does, and the difference this makes.
Welcome to the ISO Show, dispelling myths and sharing tips for success to improve your business with ISO Standards.
Welcome to the ISO Show, dispelling myths and sharing tips for success to improve your business with ISO Standards.
Welcome to the ISO Show, dispelling myths and sharing tips for success to improve your business with ISO Standards.