Quality, ISO & Health and Safety answers

Clear answers to the questions businesses ask about QMS, ISO 9001, 14001 and 45001.

Plain-English guidance on audits, document control, COSHH, risk assessments, competency, meetings, incidents and the records businesses need to keep.

Practical guidance, not management-system jargon.

These answers are written for managers, site teams and business owners who need to understand what good control looks like and how to produce reliable evidence. They explain the principles clearly, but they are not a replacement for legal advice, certification-body guidance or the wording of the standards themselves.

Standards and legislation change. Always confirm current requirements with the relevant standard, regulator, certification body or competent adviser. ISO readiness in bert. does not guarantee certification.
ISO 9001 and quality

Quality management questions

How businesses organise processes, responsibilities, records and improvement.

What is ISO 9001?

ISO 9001 is the international standard for quality management systems.

It provides a framework for delivering consistent products and services, meeting customer and applicable regulatory expectations and continually improving how the organisation operates. It can be used by organisations of any size and in any sector.

What is a quality management system?

A QMS is the connected set of processes, responsibilities, controls and records used to manage quality.

It should make clear what must happen, who is responsible, how performance is checked and what happens when requirements are not met. A QMS is more than a folder of procedures: it is the way the organisation controls and improves its work.

What documents are required for ISO 9001?

ISO 9001 does not prescribe one fixed list of documents for every organisation.

Businesses need enough documented information to operate their processes effectively and show that requirements are being met. This commonly includes policies, objectives, process controls, competence records, audit results, management-review records, non-conformances and corrective actions.

What is an internal audit?

An internal audit is a planned, objective check of whether processes are being followed and controls are effective.

It should compare actual practice with agreed requirements, record clear evidence and identify both conformity and areas needing improvement. Auditors should be sufficiently independent of the work being reviewed.

What is a non-conformance?

A non-conformance is a failure to meet a requirement.

The requirement may come from an ISO standard, legislation, a customer specification, a company procedure or an agreed working method. A good record states what happened, the requirement that was not met, the immediate correction and what will stop recurrence.

What is corrective action?

Corrective action removes the cause of a problem so it is less likely to happen again.

A correction fixes the immediate issue. Corrective action goes further by investigating why it happened, deciding what needs to change, assigning responsibility and checking that the change was effective.

ISO 14001 and environment

Environmental management questions

How businesses control environmental aspects, legal duties and improvement.

What is ISO 14001?

ISO 14001 is the international standard for environmental management systems.

It provides a framework for identifying environmental aspects and impacts, meeting compliance obligations and continually improving environmental performance.

Does ISO 14001 replace environmental law?

No. Certification is generally voluntary, but applicable environmental law still applies.

The standard helps organisations organise controls and evidence. It does not replace permits, duty-of-care rules or regulator requirements.

ISO 45001 and Health & Safety

Safety-management questions

Managing hazards, incidents, worker involvement and improvement.

What is ISO 45001?

ISO 45001 is the international standard for occupational health and safety management systems.

It provides a framework for managing health and safety risks, preventing work-related injury and ill health, involving workers and continually improving safety performance.

Is ISO 45001 a legal requirement?

Certification to ISO 45001 is generally voluntary, but compliance with applicable Health & Safety law is not.

Many organisations adopt ISO 45001 to organise their controls, demonstrate commitment and improve assurance. Certification does not replace the need to identify and meet legal duties.

What is the difference between an incident and a near miss?

A near miss caused no harm, but had the potential to do so.

Incidents and near misses should be recorded, reviewed and used to identify weaknesses before a more serious event occurs. Certain workplace events must also be formally reported under RIDDOR; businesses should check the current HSE rules.

How should workplace incidents be reported?

Record the facts promptly, make the area safe and preserve useful evidence.

A good incident record includes when and where it happened, people involved, injuries or potential consequences, immediate controls, photographs, witness information, investigation findings and resulting actions. It should also record whether external reporting is required.

What is a toolbox talk?

A toolbox talk is a short, focused briefing on a specific workplace topic.

It should be relevant to the work, easy to understand and encourage questions. Records should show the subject, date, presenter, recipients and acknowledgement or attendance.

How often should risk assessments be reviewed?

Review them when there is reason to believe they may no longer be valid or when significant change occurs.

Triggers can include incidents, new equipment, new substances, process changes, legal changes, worker feedback or evidence that controls are not working. Many organisations also set a planned review interval.

How bert. supports this

Documents, people, meetings and incidents

The extra functions that keep the management system usable day to day.

What is simple document control?

Keep the current approved version, name an owner and set the next scheduled review date.

People should be able to find the live document, see who is responsible for it and know when it is due for review. Obsolete copies should be withdrawn so the wrong version is not used on site.

What should be stored for COSHH, work instructions and risk assessments?

The current assessment or instruction, linked to the work it controls, and available when the job is done.

Relevant COSHH assessments, work instructions and risk assessments should sit with the activity, not in an unrelated folder. Review dates, ownership and the live version need to be obvious.

Does ISO readiness guarantee certification?

No. Readiness helps you get there. It does not guarantee ISO certification.

bert. can show which controls and evidence are in place for ISO 9001, 14001 and 45001. Certification decisions are made independently by a certification body after assessing the complete system in practice.

What belongs in an induction package and job role?

The documents, forms, PPE, training and controls that role actually requires.

Define the job role once, then issue the matching induction pack. New starters should receive what the role needs, and the organisation should be able to show what was issued and acknowledged.

What is the difference between training and job competency?

Training is what was delivered. Competency is whether the person can do the work.

Internal training records show attendance or completion. Job competency needs a separate assessment, supervision or demonstration. Assignment of a document or course is not evidence of competence.

How should meetings keep minutes and actions?

Schedule the meeting, record the decisions and turn agreed points into owned actions.

Minutes without follow-up are only a record of discussion. Each action needs an owner, a deadline and a way to check it was done.

What does incident reporting, investigation and analysis include?

Report the event, investigate why it happened, raise corrective action and look for patterns.

A complete trail covers the first report, evidence, investigation findings, resulting actions and a review of similar events. Analysis is how the organisation learns, not a legal determination by software.

How do you prove employees have read a document?

Keep a dated acknowledgement linked to the person and the exact document version.

For higher-risk changes, acknowledgement alone may not be enough. The organisation may also need a briefing, competence check, supervision or other evidence that the information was understood and applied.

bert. connects the check, action and proof trail.

Schedule audits, control documents, keep COSHH and risk assessments available, run inductions, record competency, hold meetings with minutes and actions, and investigate incidents — then build reports from live records.

See extra functions