Sustainability & Quality

Quality Certifications

We design, implement and maintain management systems certifiable against ISO standards and sector schemes: from the gap analysis to the audit by the accredited certification body, with lean documents and processes that work.

What we do

Our areas of work

Quality: ISO 9001

We design the quality system around the process approach: context and interested parties, risks, objectives and indicators, supplier control, non-conformities and customer satisfaction. Short documents, consistent with the way the organisation actually works.

Environment and energy: ISO 14001 and 50001

We identify environmental aspects and impacts, compliance obligations and significant energy uses; we build operational control, monitoring and improvement plans that can also be reused for sustainability reporting.

Health and safety: ISO 45001

We integrate the system with the risk assessment document (DVR) and the duties under Italian Legislative Decree 81/2008, from worker consultation to the management of contractors and near misses, and set it up so that it can underpin the organisational model under Article 30 and support the annual OT23 application to INAIL.

Information security: ISO/IEC 27001

We define the scope, the risk assessment, the statement of applicability and the Annex A controls; we extend the system to 27701 for privacy, to 27017 and 27018 for the cloud and to ISO/IEC 42001 for artificial intelligence, coordinated with GDPR and NIS2.

Anti-bribery, compliance and sector schemes

We develop ISO 37001 and 37301 in support of the 231 Model, ISO 22301 for business continuity and the sector or supply chain schemes required by clients and tender documents: ISO/IEC 20000-1, ISO 13485, ISO 22000 and FSSC 22000, SA8000, UNI/PdR 125.

Integrated systems, audit and certification

Thanks to Annex SL we combine several schemes into a single system, verifiable through one integrated audit. We run the internal audit in accordance with ISO 19011, prepare the management review and support the organisation during certification and surveillance audits.

The context

Certified management systems began as a tool for internal organisation and have, over the years, become in many cases a condition of access to the market. Contracting authorities may require them in tender documents as evidence of technical capacity; the Italian Public Contracts Code (Legislative Decree 36/2023) provides, under Article 106(8), for a reduction of the guarantees required from bidders holding certain certifications (including ISO 9001, 14001, 45001, 27001 and 50001), at different percentages and with limits on cumulation; large clients include them in their supplier qualification processes; they can also carry weight in assessments by banks and insurers.

For health and safety at work, an ISO 45001 system certified under accreditation is one of the measures that allow a company to apply to INAIL (the Italian national institute for insurance against accidents at work), through an annual application (form OT23), for a reduction of the average premium rate. Article 30 of Italian Legislative Decree 81/2008 goes further: for health and safety offences (Article 25-septies of Italian Legislative Decree 231/2001) it bases the organisational model with exempting effect on a safety management system. Paragraph 5 of that article presumes compliant, for the corresponding parts, models defined in accordance with the 2001 UNI-INAIL guidelines and BS OHSAS 18001:2007, now replaced by ISO 45001. Certification on its own is not enough: powers of control, a disciplinary system and a Supervisory Body (OdV) are also required.

The range of schemes has widened well beyond quality. Alongside ISO 9001, ISO 14001 and ISO 45001 there is information security (ISO/IEC 27001, with 27701 for privacy and the 27017/27018 controls for the cloud), anti-bribery (ISO 37001) and compliance (ISO 37301), energy (ISO 50001), business continuity (ISO 22301), IT services (ISO/IEC 20000-1), artificial intelligence management (ISO/IEC 42001), road traffic safety (ISO 39001), medical devices (ISO 13485), food safety (ISO 22000 and FSSC 22000), social accountability (SA8000) and gender equality (UNI/PdR 125:2022). UNI ISO 26000 on social responsibility and ISO 30415 on diversity and inclusion are, by contrast, guidance documents: they inform choices and may be the subject of voluntary attestations, but they are not requirements standards against which a system can be certified.

One element is common to almost all of these standards: the harmonised structure of Annex SL (Harmonized Structure, previously High Level Structure), with the same clauses on context, leadership, planning, support, operation, performance evaluation and improvement. That is what makes a single integrated system possible instead of several parallel ones.

Our approach

We start from how the organisation works today. The initial gap analysis compares existing processes, documents and records with the requirements of the standard and produces a plan with priorities, roles and timescales. On that basis we design a lean documented system: the standard does not ask for voluminous manuals, it asks that rules be defined, applied and verifiable. Procedures are written with the people who will use them, building on whatever already works.

Implementation is hands-on: we do not hand over a package of documents, we work with function heads so that objectives, indicators, risk management and operational control become daily practice. We train senior management on its own role, the system contacts on day-to-day management and staff on the procedures that concern them.

Before the external audit we run the internal audit in accordance with ISO 19011 and prepare the management review, with verifiable data and traceable decisions. We support the organisation in selecting an accredited certification body (in Italy accredited by Accredia, or by another signatory of the EA and IAF agreements), in comparing quotations and during the certification audit, across stage 1 and stage 2, through to the closure of findings.

After certification the cycle continues with annual surveillance audits and three-yearly recertification. We offer maintenance arrangements covering internal audits, management of non-conformities, attendance during audits and updating to new editions of the standards, such as the transition to the 2026 editions of ISO 14001 and ISO 9001 within the deadlines set by the accreditation bodies.

What sets our service apart

  • Integration: the various ISO schemes are designed as a single system, with one set of procedures and, as a rule, a single integrated audit; we link it to the 231 Model, GDPR, NIS2 and sustainability reporting.
  • Lean documentation: only what the standard requires and what is of use to the people doing the work, in short documents that stand up to audit.
  • Presence during audits: we stand alongside management during the certification body’s audits and surveillance visits, and handle the response to findings together, through to the closure of non-conformities.
  • Internal audit and review before the external audit: we run the internal audit in accordance with ISO 19011 and prepare the management review, delivering the audit programme and report, the corrective action plan and the minutes with indicators, results and decisions.

Our method

How we work

  1. Initial gap analysis

    A visit to the company, interviews with the managers concerned and a review of existing documents; we deliver a report on the gaps against the standard and a work plan with timescales and roles.

  2. System design

    With management we define context, policy, objectives and scope; we identify the processes to be documented and the records to be kept, distinguishing what the standard requires from what is merely custom.

  3. Implementation and training

    We work alongside each function in applying the requirements, collect the necessary records and train the people involved, each on their own role within the system.

  4. Internal audit and review

    We verify the entire system through an internal audit, manage the corrective actions and run the management review ahead of the external audit.

  5. Certification and maintenance

    We support the choice of an accredited certification body, the certification audits and the closure of findings; we then support the surveillance visits, recertification and continual improvement.

Benefits

What the business gains

  • Access to public tenders and to the qualification lists of large clients that make certification a condition of participation
  • Reduced guarantees in public contracts for the certifications listed in Article 106(8) of Italian Legislative Decree 36/2023 (ISO 9001 and others)
  • A possible reduction of the INAIL premium rate (form OT23) for organisations with a certified ISO 45001 system
  • Clearer processes, defined responsibilities and indicators that help management take decisions on the basis of data
  • A single documented system for quality, environment, safety and compliance, with no duplicated procedures

Deliverables

What we deliver

  • Gap analysis report with an implementation plan, responsibilities and deadlines
  • Analysis of the context and interested parties, management system policy and objectives
  • Procedures, work instructions and essential forms, shared across several schemes
  • Assessment of risks and opportunities, with the registers required by the scheme adopted
  • Audit programme, internal audit report and corrective action plan
  • Management review minutes with indicators, results and decisions
  • Documented training for senior management, system contacts and staff
  • Comparison of quotations from accredited certification bodies and a plan for responding to certification audit findings

Frequently asked questions

Answers to the questions we hear most often

How long does it take to reach ISO 9001 certification?

It depends on size, process maturity and the availability of the people involved. For an SME whose processes are already in good order the route usually takes a few months, because before issuing the certificate the certification body requires evidence that the system is working: records, an internal audit and a management review. A plan with realistic timescales is agreed in the initial proposal.

Does Nexaura issue the certificate?

No. The certificate is issued by an independent certification body, accredited by a recognised authority (in Italy Accredia), at the end of the stage 1 and stage 2 audits. Where non-conformities emerge, the body requests a corrective action plan and, in more serious cases, a further audit before taking its decision. We design the system with the organisation and support it through this phase too, but the decision rests with the body.

Is a dedicated person needed in-house to run the system?

An internal contact is needed, though not necessarily full time: in an SME this is often a function head who devotes part of their time to the system. Their task is to keep records and indicators up to date and to act as the link with us. The more technical activities, such as the internal audit, regulatory updates and preparation for audits, can stay with us as part of our support.

Can an organisation that already holds ISO 9001 add 14001 and 45001 without starting again?

Yes. Management system standards share the Annex SL structure, with the same clauses and the same common requirements. We extend the existing system with the specific requirements (environmental aspects, safety hazards and risks) and set it up for an integrated audit, which reduces audit time and cost.

What does it cost to maintain certification over the years?

The certification cycle runs for three years, with annual surveillance audits and recertification on expiry. Costs comprise the certification body’s audit days, which depend on headcount and sites, and internal time for audits and review. We can take on maintenance under an annual arrangement proportionate to the structure of the organisation, so that recurring activities do not weigh on internal staff.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.