ISO compliance guides, comparisons and practical insights for UK businesses — written by an IRCA® Registered Principal Auditor, not a marketing department.
PICMS Ltd is now Cyber Essentials certified (IASME) and registered with the ICO. The part we're proudest of: we prepared and evidenced the whole thing inside PICMS, using the same Cyber & Privacy pack our customers use. It's not just a badge, it's proof the platform works on the toughest customer we've got: us. What that means for you, and why ISO 27001 is next.
ISO 14001Climate change, biodiversity and resource availability are now named in the context clause, planning of changes has a clause of its own, and life-cycle thinking reaches into externally provided services. The four changes that matter, why this is not the 2024 climate amendment again, and why your real transition date is October 2027 rather than 2029.
ISO 9001Nothing, on the day — but the transition window opens, and the deadline that applies to you is set by your own audit cycle, not by 2029. How to work out your date from your certificate expiry, why waiting for the 2029 recertification is a trap, and the evidence your certification body will expect.
IntegrationsYour policies, procedures and certificates live in SharePoint — and at the audit, almost none of it counts as evidence, because a folder isn't ISO 9001 document control. What "audit-ready" actually requires (version control, approval, traceability), why "just use SharePoint" quietly fails, and how PICMS's new Microsoft 365 integration turns your existing documents into clause-mapped evidence — no migration required.
RAMS & Site SafetyThe RAMS is dated correctly, signed correctly, filed correctly, and describes a job that isn't the one being done today. Why last-minute scope changes break most SME RAMS processes, what ISO 45001 and CDM 2015 actually require (and don't), and the three things the contractors who never get flagged have in common.
Document ControlEmailing the policy round and asking people to reply is how most UK SMEs distribute controlled documents — and it satisfies who and when while almost always failing on which version. Why an email trail stops being evidence the moment a document is revised, the four fields a defensible acknowledgement record needs, and three ways to close the gap.
People · ProductOne illegal worker can now cost £45,000–£60,000, and starting care staff before their DBS clears is a safeguarding breach. What care, construction and security employers must check — right to work, the right DBS level, the ~6-month retention rule — the 2024–2026 employment-law changes raising the stakes, and the personnel-data trap behind it all. Introducing PICMS People Vault.
Product · Audit ReadinessWhy we built PICMS as an Audit-Readiness Copilot instead of another "AI compliance assistant." Twenty specialist agents under one Master Agent, autonomy on a Trust Ladder dial, full ISO 42001 audit trail on every AI action. Plus the vertical moats — diving + social housing — nobody else touches.
AI GovernanceThe EU AI Act is extraterritorial — if your AI's output is used in the EU, it reaches you, and the high-risk obligations apply from 1 August 2026. What those duties require, an indicative clause-by-clause mapping from ISO 42001, and an honest account of where the standard stops (CE marking, declaration of conformity, EU database registration).
Cyber EssentialsTwo answers now fail an assessment outright: MFA missing on any cloud service, and high or critical patches later than 14 days. Cloud services are explicitly in scope — which is why most failures start with an incomplete SaaS inventory. The pre-assessment checklist, plus the ISO 27001 control mapping.
Data ProtectionThe UK's new data-protection complaints duty is now in force — a clear complaints route, a 30-day acknowledgement clock, and a process to investigate and respond, for organisations of any size. A step-by-step procedure mapped to ISO 27001 controls, plus the legal-register entry.
ISO 9001The first major ISO 9001 revision since 2015 is coming — FDIS out, publication expected September 2026, three-year transition. The likely changes (quality culture, ethics, leadership, explicit climate & digital context), the timeline, and a practical gap-planning checklist to get ahead before the rush.
ISO 9001The clause most organisations treat as a box-tick is the one a certification auditor leans on hardest. A practical, clause-by-clause internal audit checklist (context 4 through improvement 10) with example questions, the objective evidence to look for, and how to record nonconformities and corrective action under Clause 10.2.
ConstructionOne is a UK pre-qualification accreditation that gets you onto construction tender lists; the other is a certifiable international H&S management system. The real differences in scope, recognition and audit depth — and the honest answer to whether you need both.
ISO StandardsOne manages quality, the other manages health and safety — but they share an identical Annex SL backbone (clauses 4 to 10). Where they genuinely differ, and how UK SMEs holding both run them as one integrated management system.
Commercial DivingTwo HSE Approved Codes of Practice sit under the Diving at Work Regulations 1997 — and they're constantly confused. L103 is offshore, L104 is inland/inshore. The precise difference, the duty-holder roles, and the audit pitfalls that catch contractors out.
Insight"Autopilot" sells software — but the businesses that breeze through surveillance audits automated the right things and kept a human at the controls. Where that line falls, from the auditor's side of the table.
GuideISO compliance has two halves: getting certified and staying certified. Most software only helps with the first. How PICMS — built by an IRCA Registered Principal Auditor with years of hands-on implementation experience — carries businesses through both.
Buyer's GuideThe UK buyer's guide to choosing ISO compliance software — the evaluation criteria that actually matter, fair pricing, build-vs-buy, and the red flags to walk away from.
ComparisonPICMS, Mango QHSE, Citation, Cority and Vanta compared head-to-head for UK ISO buyers — standards coverage, pricing, sector focus and UK presence.
Head-to-HeadVanta covers SOC 2 + ISO 27001 for the US startup market; PICMS covers the full ISO ladder (9001 / 14001 / 45001 / 27001 / 42001) plus UK sector packs. Which fits your business?
14 days free, full feature access. Run a gap analysis on day one and find out exactly where you stand — before an auditor does.