
The ISO system on the shelf: why certified businesses still run on memory
Why so many certified small businesses only open the folder a fortnight before the audit.
Two weeks before the surveillance audit
The date has been in the diary for months and nobody has given it a thought since the last one. Then it gets to a fortnight out, and the manual comes down off the shelf.
Someone goes through the calibration records and finds a gauge that went out of date in March. The training matrix is updated from memory. The internal audit that should have happened in the spring happens now, over two evenings. Management review minutes get written up to resemble the meeting the standard describes.
Tidying up before a visitor arrives is all any of this is, and the visitor half expects it. But it tells you something the certificate on the wall doesn't. The business is running two systems. There is the one that gets product out of the door, and there is the one in the folder.
That can hold for years. It holds right up until something other than an audit asks to see the system.
Why it ended up on the shelf
The usual explanation is that people weren't committed. In my experience that is almost never it.
Look at how most small businesses got certified in the first place. A customer or a tender made ISO 9001 a condition. Money was tight, so they took the cheapest quote, and what arrived was a pre-written system with a bit of customisation on top. That system was built for a notional business of sixty or so people with a quality manager who has the time to run it.
At either end of that range, it doesn't fit. A firm of fifteen, where the same person handles purchasing, despatch and the internal audits, gets buried in it. A larger and more complex business finds the template can't carry what it actually does, and outgrows it quietly.
So the folder goes back on the shelf. Given what was in it, that is a reasonable decision.
The part worth knowing is that most of that paperwork was never required. ISO 9001:2015 got rid of the mandatory quality manual and the six documented procedures the old version insisted on. What it asks for is documented information 'to the extent necessary', judged against the size of your organisation and the complexity of what you do. The bulk of it came from the provider's template rather than from the standard.
Build it around how you already run the place
Every business is already being managed somewhere. There is a production meeting, or a shift start briefing, or a walk round the floor each morning, or a monthly board meeting where the decisions actually get made. Agendas exist. Minutes get taken.
Then, running alongside all of that, there is the ISO system with its own meetings, its own reviews and its own calendar, referring to none of it.
Collapse the two. The standard is on your side here, and this is the bit the template providers skip: clause 5.1.1(c) of ISO 9001 requires top management to ensure the quality management system is integrated into the organisation's own business processes. A separate ISO calendar is arguably the weaker position against that clause, not the safer one.
The mechanics are more flexible than people assume. Management review under clause 9.3 sets out what has to go into it and what has to come out of it, and says it happens 'at planned intervals'. It does not say one annual meeting with ISO in the title. If your board meeting and your monthly ops meeting between them cover the inputs the clause lists, customer feedback, process performance, nonconformities, audit results, resources and improvement among them, that is your management review. Internal audit is a programme as well, so a slice each month off the back of checks you already carry out will beat one compressed week in the spring.
One practical point, because this is where it tends to fall over. Keep a single page showing where each required input gets covered and in which set of minutes. Without it, the auditor can't see the review and you get written up for something you are already doing. With it, the answer to 'show me your management review' is a list of meetings you were holding anyway.
Say what you do, do what you say. It is an old line and it still works.
Why the audit keeps passing it
Certification runs on a three-year cycle: an initial assessment, a surveillance visit in each of the two years that follow, then recertification. Surveillance visits are short, in the region of a third of the time spent on the original audit, and they work by sampling.
The rules certification bodies work to require every surveillance visit to cover internal audits and management review, action taken on previous nonconformities, complaints, changes, use of the certification mark, and continued operational control. Nearly all of that list is documentation, and documentation can be brought into shape in a fortnight. The operational part is real, but it is a sample, taken on a day everybody knew about months ahead, with the people who look after the folder in the room.
So the system passes, and the pass gets taken as evidence that everything works. The audit was never asking that question. Three other things ask it, and none of them gives you two weeks' notice.
Calibration, and the question that comes afterwards
Calibration is the easiest thing in the world to get caught on, and the bigger the site the easier it gets. A gauge that should have been calibrated and wasn't. More often, a piece of kit in a drawer with nothing on it to say whether it is in scope, indication only, or deliberately excluded.
Some of it matters a great deal. Torque on wheel fixings, to take an obvious example. Get that wrong and you have a safety problem rather than a paperwork one.
Two fixes are worth having. Label everything, including the equipment you have deliberately left out, and keep a short list of those exclusions with the reason alongside. Then put the gauges you use twice a year onto calibrate-before-use instead of a fixed interval, which clause 7.1.5.2 permits. That takes a recurring diary entry out of the system rather than adding one.
Now the part people don't see coming. The same clause says that where equipment is found to be unfit for its purpose, you have to determine whether previous measurement results were affected. The finding is the cheap part. The real cost is the question that follows it. What have you measured with this since it last passed, and where has that product gone? On anything safety critical, that question doesn't stop at your gate.
While you are there, don't confuse calibration with statutory inspection. LOLER thorough examination and PUWER inspection are separate obligations with separate records, and they get mixed up constantly.
What actually tests the system
Tenders have got harder. Procurement teams in construction, the public sector and the larger manufacturing groups have stopped taking the certificate number and moving on. They want to see a corrective action from raising to close-out, an example of how you controlled a subcontracted process in the last twelve months, who owns document control and what happened the last time a procedure changed. A business that does all of this perfectly well in practice, and can't show it, loses to one whose system produces the evidence as a by-product of normal work.
Then there is the regulator. After an accident, an HSE inspector reconstructs what you actually did. Certification to ISO 45001 will be noted. What counts is whether the risk assessment matched the job being done that day, whether the training record matches the person who was on the machine, whether the maintenance regime on paper is the one in the workshop. A shelved system is worse than useless here, because it sets out in your own words what you knew should have been happening, alongside evidence that it wasn't. ISO 45001 puts accountability for the management system with top management, and directors who assume the certificate demonstrates due diligence are usually carrying more personal exposure than they realise.
And the quiet one. Ask how purchasing approval works and the answer is a person's name. Ask how the shift handover records quality holds and it is a different name. At fifteen people that is efficient. At forty, across two shifts, it isn't, and the day one of those people retires or goes off sick for three months you find out how much of the business was never written down.
One more reason to look at it this year
ISO 9001 is being revised. The final draft cleared its ballot in July and publication is expected in September, with a three-year transition to follow, likely running to 2029.
There is nothing to do in September and no reason to panic. But every certified business is going to have to open that folder and go through it line by line at some point in the next three years. If what's in there is a template built for somebody else, that is an expensive exercise. If it describes how you actually work, it is a short one. It is also the best excuse you will get to throw away the two thirds of the system nobody was ever going to use.
A question worth answering before somebody else asks it
When did anyone in your business last open the management system for a reason that had nothing to do with an audit?
If the answer came quickly, this doesn't apply to you. If there was a pause, the gap is already there, and the only open question is who finds it first. A tender panel, an inspector, or the resignation letter that was always going to arrive eventually.
If your system passes its audits but nobody touches it in between, send me a short note about it. I will give you an independent read on where the gap is and whether it is worth closing before the next tender or client review asks the question. I answer these myself, usually the same day. Where it needs more than a note, we can look at a proper review of the system.

