Morgan Compliance Group

ISO Management Systems

Practical ISO consultancy for businesses implementing, improving or integrating ISO 9001 quality, ISO 14001 environmental and ISO 45001 occupational health and safety management systems. We help build proportionate systems around real operations, strengthen internal controls, support continual improvement and prepare organisations for independent certification.

Book a Free Consultation

Last updated: 27 September 2026

Who this service is for

Businesses seeking first ISO certification, improving or taking control of an existing management system, responding to audit findings or combining quality, environmental and occupational health and safety requirements within an integrated management system.

Common reasons to act

  • A customer, framework or tender requires ISO certification
  • You need an ISO gap analysis before starting implementation or changing consultant
  • Informal processes no longer provide adequate control as the business grows
  • An internal, customer or certification audit has identified weaknesses
  • Existing procedures are not consistently implemented or maintained
  • Separate quality, environmental and safety systems need integrating

What you receive

  • A written gap analysis against the selected ISO standard or standards
  • A defined management-system scope and prioritised implementation plan
  • Process maps and proportionate controlled documentation agreed within the project scope
  • Support implementing responsibilities, operational controls and required records
  • Internal audit, corrective-action and management-review support
  • Certification-readiness review and preparation for Stage 1, Stage 2, surveillance or recertification audits where applicable
  • A practical maintenance plan for ongoing monitoring, review and continual improvement

Consultancy fees depend on the selected standard or standards, business size, operational complexity, number of locations, existing arrangements and required deadline. Certification-body application, audit, surveillance and certification fees are paid separately by the client.

View the Pricing Guide

Practical support

How Morgan Compliance Group can help

We begin by defining the intended scope, business objectives and current arrangements.

A gap analysis is then used to identify strengths, missing controls and priorities.

Support can include:

  • process mapping
  • documented information
  • risk and opportunity controls
  • legal and other requirements
  • objectives
  • competence
  • operational controls
  • performance monitoring
  • internal audits
  • management review
  • corrective action

The aim is to create a system that is embedded into day-to-day operations and supports the Plan-Do-Check-Act cycle and continual improvement rather than producing documents solely for certification.

Our consultancy supports, but does not replace, your legal health and safety duties. Advice is given within the agreed scope and relies on accurate information from you. Accreditation and certification decisions are made independently by the relevant bodies. See our Terms of Service for full details.

How the process works

01

Define the scope

Confirm the selected standard or standards, intended certification scope, locations, objectives and required timetable.

02

Assess the gaps

Review existing processes, documents, records and operational controls against the applicable requirements and agree a prioritised project plan.

03

Build and implement

Develop proportionate documented information, assign responsibilities and help embed the required controls into normal business activities.

04

Audit and prepare

Complete internal audit and management-review activities, address corrective actions and prepare the organisation for independent certification assessment.

Frequently asked questions

Which ISO standard is right for our business?

ISO 9001 focuses on quality management and consistent customer outcomes. ISO 14001 focuses on environmental management and environmental performance. ISO 45001 focuses on occupational health and safety risks and performance. A business may implement one standard or combine several within an integrated management system depending on its objectives, risks and customer requirements.

What does an ISO consultant actually do?

An ISO consultant can review your existing arrangements, complete a gap analysis, help define the management-system scope, develop proportionate documented information, support implementation, carry out internal audits, facilitate management review and prepare the business for independent certification. The exact scope should reflect what the organisation already has and what support it genuinely needs.

Is ISO certification compulsory?

Certification is generally voluntary, but a customer, tender, framework, contract or sector requirement may make it commercially necessary. Businesses can also implement an ISO management system without seeking certification where the objective is operational improvement rather than an external certificate.

Can ISO 9001, ISO 14001 and ISO 45001 be integrated?

Yes. The standards use a compatible management-system structure, allowing common requirements such as leadership, document control, competence, internal audit, management review and corrective action to be managed through one integrated system. Standard-specific requirements must still be properly addressed.

Can you take over or improve an existing ISO system?

Yes. We can review an existing management system, identify gaps, duplication or outdated controls and help simplify, update or integrate it. Suitable existing policies, procedures and records are retained wherever possible rather than replaced unnecessarily.

Can we use our existing policies and procedures?

Yes. We begin by reviewing what already exists and retain suitable arrangements wherever possible. Documents are only created or revised where needed to meet the agreed scope and ensure the system reflects how the organisation genuinely operates.

Do you provide ISO internal audits?

Yes. Internal audit support can be provided as part of an implementation project or as a separate service. The audit scope and programme are agreed around the applicable standard, certification scope, previous findings, business risks and the areas that need objective assurance.

How long does implementation take?

Timescales depend on the selected standard or standards, business size, number of locations, operational complexity, available resources and condition of the existing arrangements. We confirm the likely consultancy scope and timetable after the initial review.

What are internal audits and management reviews?

Internal audits test whether the management system conforms to planned arrangements and is operating effectively. Management review is a formal evaluation by senior management of performance, risks, objectives, audit results, changes and improvement needs. Both are important parts of maintaining an effective management system and preparing for certification.

Should we use a UKAS-accredited certification body?

Where customers, tenders or supply chains require recognised accredited certification, the certification body should normally hold suitable UKAS accreditation for the relevant management-system standard and technical scope. UKAS accredits certification bodies; it does not directly certify ordinary businesses. The exact requirement should be confirmed with the customer or tender authority.

Can you guarantee certification?

No. Certification decisions are made independently by the selected certification body. Morgan Compliance Group can help identify gaps, implement proportionate controls, complete internal readiness activities and support responses to audit findings, but cannot guarantee certification.

Related guidance

Not Sure Where to Start?

Book a free consultation and explain what your business is trying to achieve. Morgan Compliance Group will help identify the most practical next step.

Book a Free Consultation