The ISO Show

Blackmores UK

Blackmores is a pioneering consultancy firm with a distinctive approach to working with our clients to achieve and sustain high standards in Quality, Risk and Environmental Management. We'll be posting podcasts discussing ISO standards here very soon!

  1. 2 天前

    #256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

    There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it's operational. It's undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those wondering how to get involved, there is a dedicated group looking to share knowledge and tools to get you tender ready. In this episode, we are joined by Lorna Leonard, Managing Director of LBS, and Kirsty Maynard, Commercial Director of THSP, who are instrumental in running BedX, a group dedicated to sharing knowledge and tools to help businesses get tender ready for Universal and beyond. Listen to our roundtable discussion as we dive into why BedX was created, its main drivers, how it can support local businesses and how you can get involved. You'll learn ·      Who are Kirsty and Lorna? ·      What is BedX? ·      What were the main drivers behind the creation of BedX? ·      What are the group's main aims? ·      What are Kirsty and Lorna's roles within the group? ·      How can businesses get involved with and benefit from BedX? ·      What can businesses be doing now to get tender ready for Universal?     Resources ·      Bedfordshire Chamber of Commerce - BedX ·      BedX Webinars ·      Tender Diagnostic ·      Kirsty Maynard LinkedIn ·      Lorna Leonard LinkedIn   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman and Carly Mowbray are joined by Lorna Leonard (LBSv) and Kirsty Maynard (THSP) to discuss the creation of BedX, and how it aims to support businesses with tender preparation ahead of the Universal and related projects currently underway in Bedfordshire.   [01:25] Who are Kirsty and Lorna?: Kirsty is the commercial director at THSP. THSP work with businesses across health and safety, HR and compliance, helping organizations make sure they've got the right systems, processes and people in place to operate safely, professionally and compliantly. THSP have been in operation since 1992 and support any type of organisation, from construction to food brands, global luxury retailers, major transport organizations, and complex international businesses operating in highly controlled environments. Lorna is the managing director of LBS. LBS is a business solutions company supporting sophisticated start-ups and growing corporations with outsourced finance department services, direction and solutions. She set-up the business 14 years ago, and has worked with organisations of all sizes, from blue chip companies to micro businesses of only 1 or 2 people. Regular listeners may recall Lorna from a previous episode, she also shares many insightful posts on LinkedIn and is certainly worth a follow! [07:05] What is BedX? It's A business-led working group powered by the Bedfordshire Chamber of Commerce. It was created to help Bedfordshire businesses understand, prepare for and win work from the major investments coming into the region, in particular, the universal destinations and experiences, the Luton Airport expansion and other on-going linked projects. BedX's role is to connect, inform and prepare, but they don't lobby, they don't represent the developers and they don't do politics. They are simply there to help local businesses get ready. [07:45] What were the main drivers behind the creation of BedX? The Universal park is certainly the banner piece for the group. It's what all the big numbers are attached to, including 5 billion pounds worth of inward economic investment, 20,000 jobs created and the five years' worth of construction. However, that is just one part of the upcoming development going on in Bedfordshire. The big project is seeing more funding going into the area to support transport networks and other venues as investors seek to make Bedfordshire a place worth staying for more than just the Universal Park. Other projects include the expansion of the Wixams Train Station, construction at the Luton Hoo, the new Luton Town Football Club and a new Data Centre at Quest Pit. BedX was created in response to all of these projects, not just Universal. It's to help local businesses navigate these opportunities, as this small county has rarely seen such a seismic shift in the amount of investment going into the area. Even though the deadline for Universal Park is 5 years away, supply chains are looking for support now, which is why it's better to start preparing sooner rather than later. [10:20] Making Bedfordshire a play to stay: It's also not just about the venues, to prepare for the influx of tourists there will be more investment in housing and transport and related routes such as the work currently going on at the Black Cat roundabout. Kirsty states that the Bedford County Council have a scrutiny committee, which is currently labelled as the Universal Scrutiny Committee, and are in discussion about a viable tourist strategy for Bedfordshire. So, there is no doubt that there will be many more small projects going ahead within a very short timeframe to get the area ready. [12:00] How LBS's expertise is instrumental within BedX: Businesses that want to get involved may not know how to get working capital or access potential available funding, which is where Lorna's and LBS's expertise comes in to support BedX's aims. With tenders as highly valued as this, it can throw businesses through a loop if they're not prepared. Lorna shares a story where she explains that she used to work for a company that made point of purchase display equipment, this company had a US subsidiary called Anshauser-Busch, who own Budweiser. That subsidiary put through an order directly through to their factory, requesting a huge order be manufactured and delivered within 180 days. The cost of which was upwards of $2.7 million, which was due to suppliers 150 days prior to Lorna's company at the time being paid. It was their first time working with that subsidiary, so there was no guarantee on payment. The lessons they learned ended up shaping how the company operated going forward. All this to say, if you're bidding for high value contracts, you need to think about the opportunity from every perspective. [14:40] Be realistic about what you bid for: Kirsty states she is really passionate about ensuring businesses are trying to grow responsibly, so that they understand those terms in the bid and that they're realistic about the size of contract that they should be bidding for. If you're looking for more guidance in this area, Katie from Bids and Tender Support provided a webinar on this topic for BedX. It's available to view on-demand on BedX's website. [16:25] Lorna's role within BedX: Lorna reminds us that a lot of the Tier 1 contractors started out as 1 or 2 person businesses. She states that, honestly, 90% of the companies that BedX help will not be in direct contact with one of those Tier 1 contractors. However, supply chains are just that, a chain, there are many opportunities to get involved further down the line. Lorna feels as if that's a large part of her role, keeping businesses focused on the opportunities they can access within that supply chain. She is also keen to help all the local businesses understand how this is going to affect them, because whether they get involved in the various projects being built or not, the whole area is going to be affected regardless. She points out an example where they needed to source a large number of electricians, and it turns out that Bedfordshire simply doesn't have enough! So BedX is helping to make the wider community aware of training opportunities like this that can open doors for local businesses. [18:45] Other considerations for businesses operating in Bedfordshire: Lorna points out a few other concerns that people had about the on-going development in the area, including the possibility of local contractors putting prices up due to all the other projects. Timeframes may also be affected by both on-going work and the fact that more businesses will be getting involved in the area's development. [19:15] What are the group's main aims?: BedX's main aim is to be an opportunity exchange, they sit in the middle as a conduit between the opportunities and the Bedfordshire businesses and help to inform, educate and prepare to be a part of it. They are there to support preparation local businesses are able to access emerging supply chains as that waterfall flows down into tier 2 and 3 and even into 4 and 5 over the course of the project. If you're not sure which of those tiers you'd likely sit in, BedX have a helpful household checklist to find out. [20:20] Getting ISO Ready for Universal: Kirsty mentions that she's seen a lot of recent Pre-Qualification Questionnaires (PQQ's) request that bidding companies are certified to ISO 27001 Information Security. Many will be familiar with the requests for ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO 45001 (Occupational Health & Safety), but ISO 27001 seems to be a more recent pre-requisite. This is particularly the case for any Government contracts, with them stating either Cyber Essentials or ISO 27001 must be in place for any bidding businesses. Carly points out that ISO 27001 in many cases is just the first step, as you can strengthen this with supporting Standards such as ISO 27701 (Privacy Information Management) and ISO 27017 & ISO 27018 (Cloud Security), which can give you an advantage over your competitors. If y

    #256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond
  2. 7月22日

    #255 AI Due Diligence - Information Security Checks Before You Integrate AI

    AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped. So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business. In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some tips on basic Information Security checks you can do to ensure an AI application or integration is safe to use.   You'll learn ·      The link between AI and increasing data breaches ·      Recent incidents as a result of AI misuse or error ·      Key considerations for the implementation of AI technology ·      11 Information Security checks for AI tools     Resources ·      Isologyhub ·      ISO 42001 Webinar ·      IAF Accreditation Check   In this episode, we talk about: [02:25] Episode Summary – Stephanie Churchman explains the need for caution when exploring the implementation of AI tools, and provides guidance on some information security checks you can perform to ensure your data stays safe. [02:45] The link between AI and increasing data breaches: Data breaches tripled since the wide adoption of AI in early 2024 and studies are saying there is a clear link between these two events. Here in the UK alone, 32% of businesses experienced a cyber-attack or data breach in 2023, compared to 43% of businesses in 2025, with us already steadily on track to surpass that in 2026. Does this mean people shouldn't use AI at all? No, of course not, but we do need far more caution before you simply start using a tool. [03:35] Recent incidents as a result of AI misuse or error: ChatGPT copycat – There was a ChatGPT clone available as a web extension that was downloaded by some 1.5 million users. It functioned just like ChatGPT, answered queries and provided links to legit sources. But, in the background, it was scrapping passwords and gathering information that was to be sold off without users knowledge. Sage Copilot - The popular accounting software had to temporarily suspend Sage Copilot after a data-isolation flaw occurred. This incident caused an issue where users who prompted the AI to list recent invoices ended up with incorrectly surfaced financial records belonging to unrelated businesses. This was a major security issue, especially for an application thousands of businesses rely on to track their financial records. Google Gemini – Google Gemini was found to have been abused by bad actors for data reconnaissance. One particular group were building profiles on major cybersecurity and defense companies and were looking to gather specific technical job roles and salary information. Google's threat intelligence team characterized this activity as a blurring of boundaries between professional research and malicious reconnaissance. Their soft touch approach allowed the bad actors to craft tailored phishing personas and to further identify potential soft targets to compromise. [06:30] Key considerations for the implementation of AI technology: Any software or technology you plan on introducing into the business that will interact with your and your customers data should be subject to clear vetting procedures, with clear rules for use to follow. Before integrating an AI tool, ask yourself, is the tool you want to use: a)    Relevant b)    Safe c)    Ethical Ethical may sound strange, and will depend on what you're using an AI for. Take CV sorting for example, many studies have shown that AI's can have an inherited bias based on their training data. This has also now evolved into AI based recruitment tools preferring AI generated CV's over human written ones. From a safety standpoint, think about the data you are feeding into those recruitment tools, that's personally identifiable information, full names, phone numbers, emails and possibly even addresses. A full profile for an individual. Is that system your using closed, do you know if you consented to having any input data used for further training? Don't just assume that inputted data won't be used beyond your control. If that recruitment AI tool gets hacked, who do you think is liable for the breach? Is it the AI tool developer or the business that input the data? You think the answer would be clear, but the legality of all this is still being debated. [09:10] 11 Information Security checks for AI tools: #1: Have an AI Policy and AI Integration approval process in place - Many businesses will already have an AI policy in place, most are very generic, so we recommend looking at the guidance provided by ISO 42001 to see what good looks like for an AI policy. You should also create a clear approval process that any AI tools must pass BEFORE people start using them. This should be clearly communicated to the wider team, and there should be a method to manage these checks such as a ticketing system to kick off the process. #2: Understand where your data actually goes - Find out whether inputs are used to train the vendor's models. These inputs can include prompts, uploaded files or even customer data depending on what the tool is. You also need to find out how long that data is retained, and whether it's stored in a specific jurisdiction. You can look for answers to these in a DPA (Data Processing Agreement), don't rely on the basic marketing blurb they state on the website. If those answers aren't provided, contact the tools support or basic enquiries to find out. #3: Check for a SOC 2, ISO 27001, or equivalent certification – This is an easy check for vendor's security posture. Absence of certification shouldn't automatically disqualify a vendor or tool, but it should prompt more due diligence, not less. Even with a certification in place, you also need to double check that it's valid. ISO 27001 for example will need to be certified by a UKAS accredited certification body for those in the UK. For overseas, you will have your own ISO accreditation bodies, which can be verified on the IAF website. #4: Map out third-party and subprocessor risk - Most AI tools sit on top of other infrastructure like cloud hosting, underlying foundation models and additional analytics tools. You should ask for a subprocessor list to fully understand who else touches the data. #5: Test for prompt injection and data leakage - If the tool interacts with external content such as emails, documents or web pages, it can potentially be manipulated by malicious instructions hidden in that content. Businesses should ask vendors how they mitigate this and ideally test it themselves. #6: Clarify access controls and permission scoping - This is especially the case for AI agents or tools with system integrations. You need to establish if the tool operates with the same permissions as the user, or whether it has broader access. Overprivileged AI agents may operate independently with no human oversight. 'Human in the loop' has become a common phrase within cyber security for a reason, you always need a point of human oversight to ensure the AI is doing what it's supposed be doing and is doing so safely. #7: Ask about model update and versioning transparency - You need to ensure that the vendor won't just silently swap out the underlying model for its AI tools, as this can introduce sudden behaviour changes in the tool itself. Transparency is a key component of emerging AI security frameworks and regulations such as ISO 42001 and the EU AI Act. If a vendor isn't willing to tell you when they're making major changes to their tools, then it's not a vendor you want to entertain. #8: Evaluate the output reliability and hallucination risk in context - For security-adjacent or compliance-adjacent AI tools, factually wrong outputs are a risk. AI can have a tendency to 'hallucinate' data or outcomes and then present them as fact. So, ask the vendor what guardrails exist and whether their tools' outputs are auditable / traceable. They should know what data was used to train their models, or where their models are pulling data from. If they don't or can't control what data is being used, then it's not a tool you can 100% trust. #9: Review incident response and breach notification commitments - If the vendor is breached, do you how quickly you would be notified, and what their recovery process looks like? If you hold ISO 27001 and ISO 22301, or simply have a business continuity plan in place then you will already have similar procedures in place for peace of mind for your own customers, so why should you settle for any less? And just like your clients would expect, breach notifications and expected recovery times should be contractually defined, not just assumed. #10: Consider the supply-chain risk of the vendor itself - This tech is still relatively new, and so newer AI vendors may have smaller security teams and less mature processes than what you may be used to with more established providers.  However, startup pace doesn't mean you have to tolerate the start-up risk. Consider all of the previously mentioned steps, if they don't have a lot of that in place, then they may not be mature enough yet for you to go ahead with. This doesn't mean you have to automatically disqualify them, if they have a clear plan of action for growth, which shows a clear focus on increased security and transparency within a reasonable timeframe, then it's still worth considering. #11: AI tool monitoring and Kill switch – In addition to this initial vetting procedure, you should also have a process in place to continuously monitor these AI tools too. Many AI tools aren't static, th

    #255 AI Due Diligence - Information Security Checks Before You Integrate AI
  3. 7月1日

    #254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

    The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they've found their first year working with other organisations to help them achieve ISO certification. You'll learn ·      What is Emma's role at Blackmores? ·      What does Emma enjoy outside of consultancy? ·      What did Emma do before becoming an ISO consultant? ·      How has Emma found her first year as an ISO consultant? ·      What Standards has Emma worked with so far? ·      Has there been any unexpected elements to her role? ·      What is the biggest challenge Emma has had during a project so far and how did she overcome it? ·      What is Emma's biggest achievement?   Resources ·      Isologyhub ·      TISAX Webinar   In this episode, we talk about: [00:30] Episode Summary – We introduce Emma Coxhill, an Isologist® here at Blackmores, to discuss her recent entry into the world of ISO consultancy, including how she's found working on the other side to help other organisations achieve ISO certification. [03:30] What is Emma's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. Emma specialises in information security management systems (ISMS), but is branching out to other Standards as she takes on more clients. [04:30] What does Emma do in her free time? Emma is a big fan of the outdoors, enjoying long walks and exploring in general. It makes sense then that she also enjoys gardening. While it is a lot of work, she finds the result rewarding. Emma is also a big fan of movies, excluding horror films! She enjoys making the trip to see films on the big screen when she has the chance. Lastly, Emma is also a qualified life coach. This involves guiding people to get where they want to be in life, with the crucial distinction that it's not about telling people what to do, but rather providing the right questions and tools to help them achieve their goals quicker. These skills have evidently translated well into her role as an ISO consultant, as auditing is very similar in the fact that it's about giving people a different perspective. [06:55] What was Emma's previous role? Emma previously worked in admi and retail roles, with her last job being a sales admin at a company for 13 years. She first started at that company as a sales admin, moved onto business systems and around 2019 the request for them to earn ISO 27001 certification came in. Back then ISO 27001 was a 'nice to have' and not a 'need to have' like it is today. Emma jumped at the chance to join the team working on the ISO 27001 Implementation, taking part in the research, training and implementation tasks. The company managed to navigate their certification, even through the turbulence of COVID, and Emma was the one maintaining that ISMS for the following years. During that time she also implemented TISAX, an Information Security Standard specific to the automotive industry, which you can learn more about on one of our previous webinars hosted by Emma. Sadly, Emma was made redundant in 2025, but was fortunate to join the Blackmores team shortly after. [10:10] How has Emma found her first year as an ISO consultant? It's been challenging for Emma to adjust to being on the other side of the fence, helping others to achieve certification rather than being the one to implement a system firsthand. Thankfully there was plenty of opportunity to learn during her first year with Blackmores, including expanding her repertoire of Standards and being able to learn from other experienced consultants in the team. She's really enjoying working with a variety of clients, getting to learn about different industries and how different each company is in their operations. Emma is aware that she's just scratching the surface within her first year, and is eager to learn more. [12:20] What Standards has Emma worked with so far? ISO 27001 is the main one as it's the one that Emma learned to implement from scratch at her pervious job. Since joining the Blackmores Team she's also gained experience working with ISO 9001 (Quality Management), ISO 27701 (PII Management), ISO 17100 (Translation), ISO 42001 (AI Management) and TISAX. ISO 27001 remains her favourite out of all of them, and she's keen to learn more from Blackmores own Information Security guru, Steve Mason. [14:15] Has there been any unexpected elements to her role? One of the more unexpected aspects has been helping clients navigate various acquisitions. When she joined, Blackmores had an unusual amount of clients currently in the middle of this process. Dealing with ISO management in these situations can get tricky as you're having to marry up different styles of management as two companies merge. Emma's role was in helping them to navigate that transition. She was surprised as she expected to be dealing with companies that were business as usual for years, but ISO Management is at the heart of managing these types of changes. So, it was interesting to learn how involved an ISO consultant can get into the inner workings of a business to help ease the burden for all parties involved. [17:20] What is the biggest challenge Emma has had during a project so far and how did she overcome it? Emma is still relatively fresh to implementation projects, but has found the process to be quite straight forward with the both the Blackmores 7 step methodology and support from other team members. What has been a challenge was the promotion she was tasked with for TISAX. It was a new service offering for Blackmores due to her expertise, and she was involved in recording a podcast and hosting a webinar. Both activities she'd not had any prior experience with. She doesn't think of herself as a big presenter, so it seemed like a dauting task. Emma did a lot of practice and went our of her comfort zone to do the webinar, which was positively received by the audience. The experience certainly boosted her confidence in that area, and though it was a bit stressful at the time due to nerves, she felt like it was a good learning opportunity. [19:45] What is Emma's biggest achievement? Emma has various moments throughout her life, with an early one being the fact that she passed her driving test first time at the age of 17. Later in 2005, she went solo travelling for 5 months around Australia, New Zealand and Fiji. She did end up having to work for a bit of that trip to make up some additional funds, but that was a necessary evil. Other than that, she was amazed at all the different people she met during her travels and was so pleased that she was able to complete the trip. Lastly, she's proud to have joined the Blackmores team in 2025. She's recently helped her first client achieve certification from scratch, which felt like a reward in of itself to know they'd passed their ISO assessment.  If you'd like any assistance with implementing ISO standards, get in touch with us, we'd be happy to help! We'd love to hear your views and comments about the ISO Show, here's how: ●     Share the ISO Show on Twitter or Linkedin ●     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one. Subscribe to keep up-to-date with our latest episodes: Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

    #254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill
  4. 6月24日

    #253 Building The Case For Health & Safety Regulations & Standards

    Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.   Health & Safety often gets mocked for overly cautious or seemingly onerous tasks to meet certain regulations and Standards today, however these are in place for a reason. They save lives, plain and simple. In this episode, Ian Battersby makes the case for Health & Safety regulations, including why they were introduced, events that sparked the conversation for workplace safety and the impact regulations have had since their introduction. You'll learn ·      The decline in ISO 45001 adoption ·      The Health and Safety at Work Act ·      How much difference has this Act made since its introduction? ·      How do the US and UK differ in their approach to safety regulations?  ·      What events led to the creation of safety regulations in the UK? ·      Addressing broader health and safety risks – illness and long-term damage as a result of work ·      How to make health & safety manageable   Resources ·      HSE ·      ISO 45001 Support ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian Battersby makes the case for modern Health & Safety regulations, sharing why they were introduced, how they've impacted workplace safety statistics and how you can make health & safety more manageable.    [03:30] The decline in ISO 45001 adoption – From our standpoint as consultants, there has been less adoption of ISO 45001 when compared to other Standard such as ISO 9001 or ISO 27001. In years previous, it was a common Standard to implement either with or straight after ISO 9001. There are a number of reasons for this, including: ·      The appetite for ISO 45001 has reduced in favour of newer Standards ·      Supply chains not proposing it as a requirement ·      Our particular client base feel they are low risk in their respective industries To be fair, health and safety does get a bad reputation for being overbearing. It's been subject to many attacks from various media and lobbying groups, however, it's necessary to ensure we all stay safe at work. Let's look at some history… [05:00] The Health & Safety At Work Act: This act received Royal Assent in the UK on 31 July 1974, and came into force on 1 April 1975. To an extent it replaced and improved upon previous laws covering separate industries and activities: Factories, Mines & Quarries, Agriculture, etc It was enacted in response to a recognition that, although conditions for workers had improved over the century, there was still completely unnecessary harm being caused to many in the country's workforce. This is also the point when the Health and Safety Executive was formally established to enforce the law. It also provides a wealth of guidance to businesses, so we highly recommend checking out their website. They also have the legal duty to collect consolidated data on workplace injuries for the UK, and have provided an annual report since it's inception in 1975. [07:45] How much difference has this Act made since its introduction? In the year to 31/03/1975 when consolidated data was first recorded there were 651 deaths at work. The equates to more than 2.5 deaths in a single year per 100,000 workers. Comparatively, in 2024/25 124 people died in work, and while that's 124 too many, it's a big improvement. The rate per 100,000 workers is now 0.37, and you have to bear in mind that the workforce has grown, but overall that's a reduction of over 85%. [09:10] How do the US and UK differ in their approach to safety regulations? The Occupational Safety and Health Administration (OSHA) serves similar purpose in USA as HSE, but they have important differences in approach and independence. The HSE is independent of government to an extent and has no ministerial control, whereas OSHA sits within the Dept of Labor. It can also be argued that the OSHA approach is prescriptive in setting rules whereas HSE follows the more outcome-based principles of HASAWA: to reduce risk "so far as is reasonably practicable", which some argue is more sophisticated and produces better results. OSHA has also seen its powers to intervene, investigate and enforce curtailed at times due to certain political interests.   Looking at the numbers, the US Bureau of Labor Statistics published fatality rates for 2024: Census of Fatal Occupational Injuries: There were 5,070 fatal work injuries recorded in the United States in 2024, down 4.0% from 5,283 in 2023. The fatal work injury rate was 3.3 fatalities per 100,000 full-time equivalent workers in 2024, a decrease from 3.5 in 2023. That rate is notably higher than Great Britain's — 3.3 per 100,000 versus 0.37 — though the two figures aren't directly comparable. The BLS uses full-time equivalent workers as the denominator and covers a broader range of incident types, while the HSE's RIDDOR series uses a headcount of all workers and has specific exclusions (road traffic accidents, air and sea travel, etc.). The methodological differences mean a like-for-like comparison requires some care. [13:35] What events led to the creation of safety regulations in the UK? In the days of Victorian Britain, it's difficult to view the common working man, woman AND child as anything other than a commodity. Thousands died every year in industrial accidents during this era, and large-scale accidents in many industries weren't uncommon. Mining was particularly tragic, a few events include: ·      The Oaks Colliery explosion of 1866 killed around 360 men and boys. ·      Hartley Colliery in 1862 trapped and killed 204 miners when the single shaft collapsed (but individual deaths from falls, gas explosions, and equipment failures happened constantly and attracted no particular attention) ·      The Abercarn Colliery explosion in Monmouthshire (1878) killed 268 men. ·      The Albion Colliery explosion at Cilfynydd in Wales (1894) killed 290. These were not exceptional events, they were part of a continuous toll. In the 1860s alone, over 1,000 miners died annually in Britain. Textile mills, ironworks, shipyards, and construction sites all had very high casualty rates. Factory machinery had no guards. Children routinely worked in spaces too small for adults, climbing inside machinery to clean it while it was still running, or crawling under looms. Mill workers lost fingers, hands, and arms with regularity. The end of the Victorian era saw attempts at regulation, but without true enforcement. The Factories Act didn't appear until 1933 and it was bitterly opposed by many owners of mines and mills. Modern regulations exist today to prevent the tragedies of the past from happening again, they were hard fought for by workers and lobbyists, and in some ways we're still fighting to include the broader impacts work can have on an individual. [16:45] Addressing broader health and safety risks – This is in relation to harm accumulated over a lifetime of work with long-term and often fatal consequences. The suffering caused to workers exposed to hazardous conditions is immeasurable. For example, let's look at asbestos. The dangers of working with asbestos were recognised remarkably early, as far back as 1890s in France, and Asbestosis was formally recognised in 1930. This led to regulation in 1931, but only applying to the asbestos textile industry, excluding all the industries where its use was widespread such as construction, shipbuilding, anyone working in insulation etc Worse still, it wasn't even enforced! Then take mesothelioma, the distinctive and almost invariably fatal cancer of the lining of the lungs and abdomen. The connection between asbestos and mesothelioma was established in SA in 1960 when mining blue asbestos. Further research in the UK firmly established the link in the 60s. From the mid-60s, headlines were being made nationally when shipyard workers from the war era stared dying in large numbers. Unions began lobbying for protections and media coverage continued for years as cases multiplied across several areas and industries. Nevertheless, its manufacture and use continued. The Asbestos (Licensing) Regulations 1983 introduced licensing for the most hazardous asbestos removal work. Blue asbestos (crocidolite) was banned in 1985, followed by brown asbestos (amosite) in 1986, though white asbestos (chrysotile) remained legal until 1999. In the interim and since then thousands of people died and multiple legal cases have ensued. 2218 people died of mesothelioma alone in 2023. Altogether it's estimated that workplace-related lung disease and cancers kill as many 13000 per year in the UK. Several thousand more are known to die of non-lung-related occupational diseases each year, but these aren't recorded as workplace deaths on certificates, so these people aren't included in HSE annual reporting. It doesn't stop at deaths either, there is an argument for the detriment that certain work can have on quality of life. Incidents and conditions such as: ·      accidents causing amputation and fracture ·      eye conditions from welding and other light sources ·      Deafness and hearing difficulties ·      HAVS, vibration white finger ·      Skin conditions from exposure ·      Musculoskeletal in low risk environments None of these are terminal and so often go unreported.   [23:25] How to make Health & Safety manageable – Some consider modern health and safety regulations to be over the top, but overarching law in the UK has the principle 'As Far As Is Reasonably Practicable'. One common area is in risk assessment, The Management of Health and Safety at Work Regulations states: "Every

    #253 Building The Case For Health & Safety Regulations & Standards
  5. 6月17日

    #252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

    Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There's a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode Ian is joined by Damian Edwards, Head of Standards at Wavenet, to dive into how they manage the mammoth task of maintaining seven ISO Standards, the challenges with managing multiple ISO certifications and what benefits they've brought to the business since implementation.   You'll learn ·      Who is Damian Edwards? ·      Who are Wavenet? ·      How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? ·      What is Damian's role at Wavenet? ·      How do Wavenet manage their ISO certifications? ·      How has ISO Support helped you over the past year? ·      What has Damian learned while managing ISO Standards? ·      What are the benefits of ISO certification? ·      Damain's top tip for anyone considering ISO Implementation   Resources ·      Wavenet ·      Wavenet Certifications ·      Blackmores – ISO Support Service ·      Isologyhub   In this episode, we talk about: [00:30] Episode Summary – We welcome Damian Edwards back onto the podcast to discuss how he maintains Wavenet's seven ISO certifications, and the explore the benefits gained from an integrated ISO Management System.   [03:05] Who is Damian Edwards? Damian is the Head of Standards at Wavenet, and has featured on the ISO Show before! One lesser known fact about Damian, is that he a 'Dance dad', supporting his daughter through all of her lessons and competitions. He's very proud of her latest achievement of qualifying for the World Championship for Irish dancing in her age group. [05:05] Who are Wavenet? Wavenet is an IT provider, providing IT network communications, security and resilience services. They are UK based with 1,600 employees based in their Solihull head office. Wavenet were formed in 2000, but have grown through acquisition, one of which was Damians previous company, Daisy Corporate Services. When Daisy was acquired, both businesses were of a similar size, so the process looked more like a merger in practice. A large part of that was uniting the ISO Standards managed by both businesses, so Damian had his hands full with ISO integration, amending audit schedules and managing extension to scope audits. [06:30] How did Damian manage integrating management systems during Wavenet's acquisition of Daisy Corporate Services? One of the biggest challenges was the extension to scope that needed to happen due to the increase in sites. Thankfully, as Wavenet were used to acquisitions, they had dedicated acquisition project managers that assist with managing the integration. At the start, there are some teething problems as both businesses will still be using their respective processes for a while. However, once system that helped was a system called 'ServiceNow', which is where issue tickets could be logged, monitored and actioned in one centralised system. [08:15] What is Damian's role at Wavenet? Damian is the Head of Standards, which includes both ISO Standards and ESG related regulatory compliance. ISO certifications are more often than not a prerequisite or a condition of a bid over a contract, without them, Wavenet wouldn't win any business. They also create a foundation of trust for Wavenet's clients in the realms of Information Security, quality and environmental management. Wavenet are currently certified to the following Standards: ·      ISO 9001 Quality Management ·      ISO 20000-1 Service Management ·      ISO 27001 Information Security Management ·      ISO 22301 Business Continuity Management ·      ISO 45001 Health & Safety Management ·      ISO 14001 Environmental Management ·      ISO 50001 Energy Management In addition to maintaining all of these certifications, Damian also strives to utilise them to drive continual improvement within the business.   [10:30] How do Wavenet manage their ISO certifications? Damian is directly responsible for five of those ISO Standards, however there are some where he doesn't have the expertise to fully manage the requirements. ISO 27001 and ISO 45001 for example require skilled people at the helm, so Wavenet have dedicated managers to handle those areas. One of Damians key responsibilities is juggling all of the audits to make sure each element is covered, and he's put a lot of work into integrating those audits where possible to get the most out of their time and resources. Though, it's important to note that you can't integrate everything, as each standard will have some unique requirements. Areas that you can integrate however include elements such as: ·      Context ·      Audit Programme ·      Corrective Actions When you do have a lot of Standards, some elements can get watered down if you try to integrate everything. Policy for example, if you have five Standards and decide to integrate all related policies into a single document, it will become long and unruly, which will lead to people unwilling to read it. So, you have to take care to ensure focus on certain elements to make those more accessible for the staff that need it. Another aspect that needed additional consideration was Wavenet's risk profile, with their amount of sites and services, it's very varied. Too much for a single person to be aware of all the risks, which is where Damian's subject area experts can provide additional insight to fill the gaps. Damian is also keen to combine external audits where possible to both reduce cost and possible duplication of effort, as many Standard do share common subject areas, this can be done across multiple Standards. Certification Bodies are usually quite happy to work with you on this! Damians key take away is, that there isn't one solution that fits every business when managing this many Standards. It was a very trial and error process, especially with the ever changing landscape of a business, but Standards are also designed with flexibility in mind, so with the right people in place it's certainly manageable. [16:05] How has Blackmores' ISO Support helped? Blackmores has assisted Wavenet with their ISO 45001, ISO 50001 and ISO 41001 (Facilities Management) implementation. ISO 41001 was later dropped as it was no longer applicable for the business. Standards can be quite hard to apply to your own business when looking at them at face value, the requirements sound generic because they're designed to apply to every type of business. This is where Blackmores experience as a consultancy can help with interpretation and practicalities of how a Standard will apply to your way of working. Blackmores will also assist with internal audits, which help identify non-conformities that may have been missed if it were not for a fresh pair of eyes. As Damian states: "I would rather have them identified before an external audit" as this gives you a chance to resolve issues or put an action plan in place before it gets to that stage. Damain also reminds everyone to not be afraid of your auditor, internal or external. They are not maliciously looking for problems, they simply help to highlight issues which can be resolved sp you can improve as a business. No Management System is perfect, the important thing is that you can recognise when something needs addressing, and how you go about doing so. [19:30] What has Damian learned while managing ISO Standards? Damian has learned to not think of ISO as a tick box exercise, it's a tool to help businesses improve. He has also learned that you don't need to reinvent the wheel when Implementing a Management System. You likely already have much of what's required in place, but not monitored or organised regularly. For example, aspects such as 'Management Review' may already be happening in existing meetings with top management, you simply need to ensure these are minuted, cover what needs to be discussed in regards to the Management System, and make note of any gaps that need to be addressed. Businesses like Wavenet that have been in operation for 26 years know what they're doing, and are likely already following best practice. You don't need to restructure your business to meet an ISO Standard, but rather integrate the Standard requirements with how you already operate. If done correctly, it should become a simple part of your day-today tasks. Damian jokingly states: "What's my role? I sometimes say it's to do as little as possible", as the more a business is aligned with a Standard, the less you will have to do to upkeep that. [22:55] What benefits have Wavenet experienced as a result of their ISO certifications? As mentioned earlier, a lot of won business is due to ISO certification. Certain certifications are simply a tender or client requirement. Standards such as ISO 50001 tackle their energy consumption. It's focus on reducing that will inevitably lead to reduced business costs. Since implementing the Standard, Wavenet now have monthly meetings to monitor energy use, which gives them a good basis to make informed decisions on where energy use is concerned. Damian has found that over time, good practice has been so embedded that people are using it in their everyday behaviors without even realising it. He's heard people in their resolutions

    #252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards
  6. 6月10日

    #251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

    Watch the video interview here Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The drivers for this demand are varied, as is the approach many take for their path towards carbon verification. This can look very different depending on the industry you operate in and can be difficult to tackle for more service based industries, such as today's guest, Davies Group, who are a service provider for the insurance industry. In this episode Mel is joined by Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss the findings of Mel's thesis regarding the demand and drivers of GHG verification for organisations across the globe, and how Davies Groups' carbon verification journey factors into the findings. You'll learn ·      Who is Gillie Fairbrother and who are Davies Group? ·      What factor triggered the decision for independent carbon verification at Davies Group? ·      At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard? ·      What did Davies Group's GHG inventory and reporting look like before independent verification was introduced? ·      Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally? ·        ·      What is the gap between organisations knowing they should verify emissions and actually doing it? ·      Was competitive positioning part of the Davies Group case for carbon verification? ·      What was the most significant finding from the first carbon verification engagement? ·      How has verification changed the internal culture and engagement with the sustainability programme at Davies Group? ·      How have Davies Group supported suppliers with calculating their carbon emissions? ·      Where does Gillie see the expectations of institutional partners and large clients in insurance and professional services heading? ·      What was a specific moment where Gillie can recall that this mattered more than she had expected?   Resources ·      Davies Group ·      Davies Group LinkedIn ·      Carbonology – Carbon Verification Services   In this episode, we talk about: [00:30] Episode Summary – We introduce Gillie Fairbrother, Global Responsible Business Officer at Davies Group, to discuss their participation in Mel's thesis research into the demand for GHG emissions, exploring Davies Group's own reasoning and journey. [02:05] Who is Gillie Fairbrother and who are Davies Group? A route into sustainability as a career wasn't as readily available to Gillie when she attended university, so it has been something of a self-made path. She has previously run a wellness business in the past and has experience working with sustainable brands and has done a lot of cultural advocacy, particularly in the LGBTQ space. Taking the lead for ESG within the corporate space was a dream come true for Gillie, and she has done this for a number of US based tech firms to her current position for Davies Group. Davies Group are a service provider for the insurance industry, who operate in 22 countries. [03:40] What factor triggered the decision for independent carbon verification at Davies Group? Mel's research found that 29% of organisations cite market-driven factors as their primary reason for seeking GHG verification, compared with just 12% who cite regulatory compliance. For Davies Group, their decision was led by market demand. They looked client requests versus client contractual obligations, and carbon verification was increasingly coming up in those contractual obligations. Gillie herself has always been an advocate for working both sustainably and responsibly, promoting the revenue benefits that can be gained from doing so. However, as much as it is perceived to be the right thing to do, she doesn't want businesses to simply think of it as the 'nice thing to do'. These should be central components to how your business operates. So in part, Davies Group saw this demand not only in the market, but as simply the right way to do business. [05:30] At what point did the leadership team recognise that unverified carbon data represented a credibility and governance risk that was inconsistent with that professional standard? Davies Group already operate in a highly regulated market, and so already have very strong governance practices in place. Gillie didn't really have to worry about making too many improvements in the governance or purpose aspects of ESG compliance. They participated in TCFD on a voluntary basis to highlight a possible risk from a climate perspective that could affect things like supply chain, physical sites, or the industry in general to leadership. Thankfully, the leadership saw this as a risk worth looking into more, and were willing to quantify it properly and ensure that their data was as accurate as possible and in a place where it could be audited by a 3rd party. [07:40] What did Davies Group's GHG inventory and reporting look like before independent verification was introduced? Before Gillie joined, these aspects were managed by a 3rd party due to lack of in-house expertise to manage it. When Gillie joined, she worked closely with that 3rd party to continue the work. Davies Group is quite a complex business, it operates with 3 different divisions that have multiple service lines. At the time, they did their best with the Excel spreadsheets that they had create to track various GHG emissions, but it was not as good as it could have been. They've since grown their processes, included more in-house talent and are doing more to gain knowledge from their stakeholders, data owners and building relationships with various teams across the business. While they are still working on Excel spreadsheets, they have advanced to reasonable assurance. Gillie is now looking into external tools to help improve their data management, but this would cost a fair bit of money that could be better used currently on reducing environmental impact. [10:30] Which specific stakeholders were asking the hardest questions about Davies Group's sustainability data, and how did those questions land internally? Gillie cites employees, as they're an industry where 30% of the workforce is likely going to retire in the next 10 years, so they're trying to attract a younger group of talent who want to work for a business that has a good purpose and is a good company. Acting sustainably and responsibly is a huge part of attracting that new young talent. The second more important stakeholders are their clients. Davies Group is a private equity backed business, if they're not making money then they simply cease to exist as a business. Clients now have a keen interest in responsibly run businesses, and many now seek proof to claims. Next in the list is investors, who have an interest in the regulatory requirements that the business is subjected to. Lastly, Gillie cites suppliers as even if they aren't actively putting pressure on the business to report their emissions, without their support and cooperation, Davies Group can't meet their own goals. [12:40] What was a particularly memorable conversation with a Stakeholder that helped drive further improvement? Gillie recalls one conversation with a new employee where they asked to be more involved with their sustainability group. When she talked to them more, she discovered that one of the main reasons that employee sought them out was due to the responsible business page on their website, and that out of the 3 businesses they were applying to, Davies Group was the only one that had a page like that. [37:00] What is the gap between organisations knowing they should verify emissions and actually doing it? Mel's research found that 86% of organisations report increased stakeholder demand for transparency in GHG reporting – yet 52% remain unverified. Gillie states that there could be a lot of reasons for this, including budget, resourcing or something as simple as a piece of wording in a contract where a client might say we request versus we require. This is why Gillie is always in conversation with clients, whether that be the sales team or the sustainability teams at our clients, to understand their goals and make sure they can all align in their goals. The market is certainly the leading cause for many businesses as Government regulation tends to lag behind. [17:20] Was competitive positioning part of the Davies Group case for carbon verification? For Davies Group, it was initially a contractual requirement to complete their carbon verification. So, in their case, it was an easy decision as otherwise they could potentially lose business. However, Gillie also regularly meets with senior leadership and reports into their responsible business board committee every quarter. There they consider the growing appetite for sustainability driven demands, and how they want to leading the way in their industry. The key determining factor is whether it's relevant to them, whether that's for sustainability or for their community impact strategy. Davies Group tend to focus on education and investment in our communities, as that's where their expertise sits. It's all about materiality as businesses need to focus on what's relevant to them. [19:20] What was the most significant finding from the first carbon verification engagement? For Gillie, it was the clarity and transparency that had been game changing. Especially within their real estate portfolio. Davies Group don't own any of their offices, they're all leased. As they calculated and ver

    #251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification
  7. 5月15日

    #250 Driving ISO Implementation – Meet the Consultant: Steve Mason

    How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That's not surprising as it's quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide. We're continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Steve Mason, a Principle isologist® at Blackmores, to share the journey of how he went from intern, to ISO Assessor, to ISO consultant and the challenges he's faced while working with clients. You'll learn ·      What is Steve's role at Blackmores? ·      What does Steve enjoy outside of consultancy? ·      What path did Steve take to become an ISO Consultant? ·      What is the biggest challenge he's faced when implementing ISO Standards? ·      What is Steve's biggest achievement?   Resources ·      Isologyhub ·      ISO 14001:2026 What's Changed And How to Comply Webinar Registration   In this episode, we talk about: [00:30] Episode Summary – We introduce Steve Mason, a Principle Isologist® here at Blackmores, to discuss his journey towards becoming an ISO consultant who specialises in ISO 27001, ISO 27701, ISO 27018, ISO 27017 and ISO 20000-1. [02:40] What is Steve's role at Blackmores? Her role primarily involves supporting clients in two key areas: maintaining and continually improving their existing ISO management systems and helping them establish and implement new standards. As part of that support, he: ·      Makes Standards understandable and accessible to clients ·      Conduct internal audits ·      Reviews and updates management system documentation ·      Facilitate management reviews ·      Train internal teams and prepare them for certification audits. Steve is the Standard champion for ISO 27001, ISO 27701, ISO 27017, ISO 27018 and ISO 20000-1 at Blackmores, but he also deals with ISO 9001, ISO 41001, ISO 22301 and ISO 42001 related projects and support. Steve's other main role at Blackmore's is as a Mental Health First Aider, which is shared with Minoo Agarwal. Together, they provide resources and offer support to the team. [06:00] The importance of Mental Health management in the workplace: Steve had faced bullying in previous roles, so preventing others from experiencing the same had become a big motivator for him taking on the role of Mental First Aider for Blackmores. He emphasizes it's importance, and highlights 2 key Standards that you can use to help support mental first aid within your business. This includes ISO 45003 Mental Health in the Workplace and BS 30480 Suicide and the Workplace. [09:10] What does Steve enjoy doing outside of consultancy?: Steve has a wide variety of interests and hobbies, including: Lay Minister: Steve is a Lay Minister in the United Reform Church and mainly based at the URC Chapel in Walkern, but can be found leading worship and preaching at Ashwell, Baldock, Stevenage and Knebworth chapels. Poetry: Steve enjoys writing poetry about anything and everything, racking up an impressive 190 poems so far. Some of his main inspirations include Wordsworth and Keats. If you ever see a poem on the Blackmores LinkedIn page, odds are, it was written by Steve! Classical Music: He's a fan of classical music, anything by Beethoven, Mahler or Shostakovich specifically. He likes these composers in particular due to their stretching of the rules of music for the time. Exploring hidden London: Steve often goes on hidden London tours which explore disused underground stations which may have been shut down as long as 100 years ago! Buses and Trains: Steve was lucky enough to drive a bus in his past, of which he has the licence plate of sitting in his office. He collects bus and train models and will go out to snap a photo or two of their real world counterparts when he comes across them. History: Steve is a huge mystery buff, with a particular fondness for Richard III and the War of the Roses and the Anglo Saxon period of history. Family Tree: Steve has been tracing his family tree back as far as he can on his mother's side, which extends as far back as 1547! Interestingly enough he found out that relatives from way back then got married in the church that he currently lives nearby and got qualified as a Lay Minister for the Church of England in Stevenage! Cats: He's owned his fair share of feline friends through the years, with one particular tabby holding the name 'Spartacus'. [22:35] What was Steve's path towards becoming an ISO Consultant?:  Steve was once told in the 1980s 'There is no future in Standards; find another career, perhaps in Sales or Purchasing'. How wrong that turned out to be! He's always worked with standards, from the first day he started work doing inspection in Goods Inwards, he was referring to them. The direction towards Management systems came in 1983 when he started implementing BS 5750. From that day onward he had been involved in Management Systems. Steve completed a management apprenticeship at Racal-Guardall where he was able to do 3 months' work experience in all departments, which helped him appreciate how companies function and how important it is to maintain good communication channels. He was at the end of this apprenticeship that the opportunity arose in the QA department to work on BS 5750. His career path has included other organisations such as Tektronix, BOC Ohmeda, Cirkit, Deta, TDK and BSI, all of which earned Steve a lot of experience in Manufacturing and Service and Distribution, mainly in Quality and Customer Service roles. Steve has always felt a bit like a closet consultant, even when he worked as an assessor at BSI. He feels as if Blackmores has enabled him to fully flourish and develop his portfolio of standards – not bad for a career where there was apparently no future in standards! [28:45] Born to be a consultant – Steve mentions that consultancy is a skill that many are born to be. You can train and learn the skills of course, but for some it comes very naturally and it can be hard to replicate that skillset in others. [30:15] What is Steve's favourite aspect of being a Consultant? Steve loves talking with clients and working with them to explore solutions that can address the requirements of the standards. His motto is 'Mould the Standard to the organisation and not the organisation to the standard' This means, always producing a management system that benefits the organisation first and then adjusting it to meet the requirements of the standard. Organisations that mould the business to the standard usually end up with a management system that is a 'bolt-on' and an uncomfortable, sometimes irrelevant, fit. Everyone in the organisation needs to feel that the management system is a natural fit to what they do. He also enjoys supporting his colleagues at Blackmores. We're a business built on knowledge sharing, and there's no point gatekeeping anything we've learned as a team. So consultants often get together to discuss lessons learned and ensure best practice is a shared experience. Ironically enough, one of Steve's least favourite aspects of being a consultant is auditing! Mostly since he's been doing it for some 40 years now, so he can be forgiven for finding the exercise a bit tedious at times. However, he never let's that affect the end result of an audit. [37:00] What Standards does Steve specilaise in and why? Steve initially started with ISO 9001 but was steered towards ISO 27001 and ISO 20000-1 during his time as BSI. This was based upon his career path up to the point he joined BSI as they align assessors to familiar business and technical environments. In Blackmores, he has been able to develop these areas of Quality, Service and Risk by adding standards related to Business Continuity, PII and Cloud Security, Facilities Management and AI Management. Steve's favourite standard is ISO 20000-1 which started off as an IT Service Management System but can also be used effectively for all services. He always refers to ISO 20000-1 as 'ISO 9001 on Steroids' because it is much more specific and focuses on the subject of service management. Sadly, ISO20000-1 is under rated, under sold and in some cases, never heard of – this is usually because contracts require IS O9001 but the people writing those contracts don't actually know or understand what they are asking for. In simple terms it is a Service Quality Management System and Steve has come across organisations which have shoe-horned ISO 9001 into the business instead of using the natural fitting standard ISO 20000-1. Steve would advise any company that is providing a service with helpdesk support to look at ISO 20000-1, especially if they find that ISO 9001 isn't working well for them. [43:00] What is the biggest challenge Steve had faced during a project and how did he overcome it?: Creating a management system in 10 days for a client which was due to lose a major contract because they had let their certification to ISO 9001 lapse between the 2008 and 2015 versions. Quite the undertaking in such a short amount of time! Steve refuses to claim full responsibility for the success however, as the client was totally invested in getting the system up and running and put in a lot of effort to work with Steve to get it done in time. If it had been any other standard, it would have been impossible, but because it was ISO 9001 and wthey were drawing on what had been in place previously it was possible. Generally, problems arise when there is limited or no Leadership support and commitment, because without this management systems can't be set up in a way that benefits the organisation. All manag

    #250 Driving ISO Implementation – Meet the Consultant: Steve Mason
  8. 4月28日

    #249 How To Meet Documentation Requirements Within ISO

    Most ISO Standards are designed with implementation flexibility in mind. They set the framework without specifying an exact method to meet requirements, giving businesses the freedom to implement them how they see fit. One of the key requirements you can't escape, however, is documentation. This is more than a list of key documents you must have in place, it encompasses how you develop, control and store documented information. In this episode, Ian Battersby dispels common myths around documentation in ISO, explains what the requirements actually mean in practice and how you address each one relevant to documented information. You'll learn ·      Common misunderstandings about documentation within ISO ·      What do current ISO Standards require for Documented Information? ·      How do you determine what should be documented information? ·      How do modern Standards embed a flexible approach? ·      What is considered 'documented information?' ·      Breaking down clause 7.5 Documented information ·      How to address clause 7.5.2 Creating and Updating documentation ·      How to address 7.5.3 Control of documentation ·      A cautionary tale for modern approaches to Documentation   Resources ·      Isologyhub   In this episode, we talk about: [02:05] Episode Summary – Ian dives into the topic of documentation within ISO, dispelling the myths and breaking down the requirements you need to meet relevant to documented information. [02:40] Common misunderstandings about documentation within ISO: Taking ISO 9001 as the prime example, the most common misunderstanding is that you need a policy manual. This is not true. This may have stemmed from previous versions of ISO 9001 where certain mandatory procedures were required, such as: ·      Control of Documents (Clause 4.2.3) ·      Control of Records (Clause 4.2.4) ·      Internal Audit (Clause 8.2.2) ·      Control of Nonconforming Product (Clause 8.3) ·      Corrective Action (Clause 8.5.2) ·      Preventive Action (Clause 8.5.3) There were also mandatory records such as Management Review, calibration, supplier evaluation, design/development reviews etc. With the introduction of the 2015 version of ISO 9001, the old terms 'Procedure' and 'Record' have changed into a single term now known as 'Documented Information', which breaks down those previous terms into the following: ·      Documented information to be maintained — Previously what would have been a procedure (i.e., describing how something should be done) ·      Documented information to be retained — Previously what would have been a record (i.e., evidence that something was done) [05:10] What do current ISO Standards require for Documented Information? The 2015 version of ISO 9001 received the following updates: ·      Removed the prescriptive language associated with the old terms ·      Gave organisations the flexibility to develop, control and store documented information ·      No longer dictates the form that documentation must take In practice, many people still use the terms procedure and record informally, because they are well understood and conveniently descriptive. But beware using language that reinforces old-fashioned ideas about how we create management systems. This newer language aligns with modern risk-based thinking, with direct references made to this being included in the Standard. But, while that sounds prescriptive, adopting risk-based thinking has allowed a less prescriptive approach to the standards. It allows you to consider what's significant to you and so you can plan your system accordingly. [07:20] How do you determine what should be documented information? The effort you put into documenting something must be consistent with the risk If, for example, a process is important, if its outcome could be in doubt, if it's complex to control, if it could lead to damage/harm, if there's a regulatory requirement, then you should put some effort into documenting how it's performed. But, if you maintain that documentation in response to the risk to your organisation and not in response to a prescriptive demand in standard, and if a process attracts less risk, then you can deliver it with less formality and less documentation to be maintained. The same goes for retaining documentation to evidence that you've done what you should. In short: more risk, more documentation retained to demonstrate that you've controlled it. [08:30] How do modern Standards embed a flexible approach? ISO Standards are deliberately flexible. The extent of documented information required depends on the size of your organisation, the complexity of your processes, your customers' needs, your regulatory environment and the competence of your people. An organisation of only 10 people will have very different needs compared to one of 10,000, and both can fully conform to the standard. It's about proportionality, not volume. [09:20] What is considered 'documented information? ISO standards don't care what you call the documents you maintain in order to govern how you deliver your daily work. Other than using the term process (and the process approach) to underpin how systems should interrelate, ISO 9001 doesn't specify anything else. Would you like to use the term procedure?  Or management procedure? Or SOP? Work instruction? Process map, guide, playbook, manual. Or is your activity embedded in an online system? A workflow? A board? It doesn't matter, you can call it what you want, and as long as it's controlled to the extent that it needs to be. [11:05] Breaking down clause 7.5 Documented information: ISO 9001 states: "7.5.1 General: The organization's quality management system shall include: a) documented information required by this International Standard; b) documented information determined by the organization as being necessary for the effectiveness of the quality management system. NOTE The extent of documented information can differ from one organization to another due to: ·      the size of organization and its type of activities, processes, products and services; ·      the complexity of processes and their interactions; ·      the competence of persons." This reinforces the fact that there is no 'one size fits all' approach. [12:15] How to address clause 7.5.2 Creating and Updating documentation: The Standard states: "When creating and updating documented information, the organization shall ensure appropriate." Note that word, 'appropriate'.  It doesn't indicate specifics, it indicates that you should choose certain things according to your own circumstances So the appropriate things which you should ensure are: Identification and description:(e.g. a title, date, author, or reference number) One trap many fall into, is the use of reference numbers. In most cases they are unnecessary. Only use them if they mean something or make life easier. Having reference numbers with department numbering can reinforce the silo mentality; 'that's their procedure, not ours', so it's best to avoid creating that situation by foregoing reference numbers if possible. What matters is that any users are able to easily verify that they have the right document, this can be done with a descriptive title, version numbers and a date for the version. Online documents may have details embedded in metadata or an information box that can make this process easier to implement.   Format and media: You'll need to consider language required for certain documentation, as international systems where there are multiple languages used by the workforce, may require additional versions. You'll also need to establish which templates or layouts to use. Look and feel will likely be important in the organisation, so you'll want to keep documents on brand. Other considerations include: ·      The use of process maps, flowcharts, diagrams, tables, or written text. ·      The software or application it is created in (e.g. Word, PDF, SharePoint) ·      Whether the document is paper-based or electronic Review and approval for suitability and adequacy: Documented information requires appropriate review of content, this is to make sure it does what it should and that all of the above is covered. You will also need sign-off by someone with the appropriate authority, and that authority is determined based on risk related to that document. [18:00] How to address 7.5.3 Control of documentation: Let's break down each part of this clause: "To ensure that a)    it is available and suitable for use, where and when it is needed;" - It must be circulated, hosted, displayed or whatever, so that those people who are required to see it, use it, know of its content can act on it. "b) it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity)." - It must be protected so that only the right people see it, so that any confidential information is not inappropriately shared, and no one can use or amend it without the appropriate authority. This is to ensure it remains in the manner it was intended and that its content can't be altered, corrupted or destroyed. "7.5.3.2 For the control of documented information, the organization shall address the following activities, as applicable: a) distribution, access, retrieval and use; b) storage and preservation, including preservation of legibility; c) control of changes (e.g. version control); d) retention and disposition." This clause adds some meat to the ideas discussed already "a) distribution, access, retrieval and use;" – This refers to who receives a document and by what means, whether the right people can access it and know what to do

    #249 How To Meet Documentation Requirements Within ISO

簡介

Blackmores is a pioneering consultancy firm with a distinctive approach to working with our clients to achieve and sustain high standards in Quality, Risk and Environmental Management. We'll be posting podcasts discussing ISO standards here very soon!

你可能也會喜歡