The context
Certified management systems began as a tool for internal organisation and have, over the years, become in many cases a condition of access to the market. Contracting authorities may require them in tender documents as evidence of technical capacity; the Italian Public Contracts Code (Legislative Decree 36/2023) provides, under Article 106(8), for a reduction of the guarantees required from bidders holding certain certifications (including ISO 9001, 14001, 45001, 27001 and 50001), at different percentages and with limits on cumulation; large clients include them in their supplier qualification processes; they can also carry weight in assessments by banks and insurers.
For health and safety at work, an ISO 45001 system certified under accreditation is one of the measures that allow a company to apply to INAIL (the Italian national institute for insurance against accidents at work), through an annual application (form OT23), for a reduction of the average premium rate. Article 30 of Italian Legislative Decree 81/2008 goes further: for health and safety offences (Article 25-septies of Italian Legislative Decree 231/2001) it bases the organisational model with exempting effect on a safety management system. Paragraph 5 of that article presumes compliant, for the corresponding parts, models defined in accordance with the 2001 UNI-INAIL guidelines and BS OHSAS 18001:2007, now replaced by ISO 45001. Certification on its own is not enough: powers of control, a disciplinary system and a Supervisory Body (OdV) are also required.
The range of schemes has widened well beyond quality. Alongside ISO 9001, ISO 14001 and ISO 45001 there is information security (ISO/IEC 27001, with 27701 for privacy and the 27017/27018 controls for the cloud), anti-bribery (ISO 37001) and compliance (ISO 37301), energy (ISO 50001), business continuity (ISO 22301), IT services (ISO/IEC 20000-1), artificial intelligence management (ISO/IEC 42001), road traffic safety (ISO 39001), medical devices (ISO 13485), food safety (ISO 22000 and FSSC 22000), social accountability (SA8000) and gender equality (UNI/PdR 125:2022). UNI ISO 26000 on social responsibility and ISO 30415 on diversity and inclusion are, by contrast, guidance documents: they inform choices and may be the subject of voluntary attestations, but they are not requirements standards against which a system can be certified.
One element is common to almost all of these standards: the harmonised structure of Annex SL (Harmonized Structure, previously High Level Structure), with the same clauses on context, leadership, planning, support, operation, performance evaluation and improvement. That is what makes a single integrated system possible instead of several parallel ones.
Our approach
We start from how the organisation works today. The initial gap analysis compares existing processes, documents and records with the requirements of the standard and produces a plan with priorities, roles and timescales. On that basis we design a lean documented system: the standard does not ask for voluminous manuals, it asks that rules be defined, applied and verifiable. Procedures are written with the people who will use them, building on whatever already works.
Implementation is hands-on: we do not hand over a package of documents, we work with function heads so that objectives, indicators, risk management and operational control become daily practice. We train senior management on its own role, the system contacts on day-to-day management and staff on the procedures that concern them.
Before the external audit we run the internal audit in accordance with ISO 19011 and prepare the management review, with verifiable data and traceable decisions. We support the organisation in selecting an accredited certification body (in Italy accredited by Accredia, or by another signatory of the EA and IAF agreements), in comparing quotations and during the certification audit, across stage 1 and stage 2, through to the closure of findings.
After certification the cycle continues with annual surveillance audits and three-yearly recertification. We offer maintenance arrangements covering internal audits, management of non-conformities, attendance during audits and updating to new editions of the standards, such as the transition to the 2026 editions of ISO 14001 and ISO 9001 within the deadlines set by the accreditation bodies.
What sets our service apart
- Integration: the various ISO schemes are designed as a single system, with one set of procedures and, as a rule, a single integrated audit; we link it to the 231 Model, GDPR, NIS2 and sustainability reporting.
- Lean documentation: only what the standard requires and what is of use to the people doing the work, in short documents that stand up to audit.
- Presence during audits: we stand alongside management during the certification body’s audits and surveillance visits, and handle the response to findings together, through to the closure of non-conformities.
- Internal audit and review before the external audit: we run the internal audit in accordance with ISO 19011 and prepare the management review, delivering the audit programme and report, the corrective action plan and the minutes with indicators, results and decisions.