From the Auditor's Desk

The PICMS Blog

ISO compliance guides, comparisons and practical insights for UK businesses — written by an IRCA® Registered Principal Auditor, not a marketing department.

Latest · Milestone

We used our own platform to get Cyber Essentials certified

PICMS Ltd is now Cyber Essentials certified (IASME) and registered with the ICO. The part we're proudest of: we prepared and evidenced the whole thing inside PICMS, using the same Cyber & Privacy pack our customers use. It's not just a badge, it's proof the platform works on the toughest customer we've got: us. What that means for you, and why ISO 27001 is next.

Jason Misters · 19 August 2026 Read article
ISO 14001

ISO 14001:2026 is published: what actually changed, and the deadline before the deadline

Climate change, biodiversity and resource availability are now named in the context clause, planning of changes has a clause of its own, and life-cycle thinking reaches into externally provided services. The four changes that matter, why this is not the 2024 climate amendment again, and why your real transition date is October 2027 rather than 2029.

Jason Misters · 12 September 2026 Read article
ISO 9001

ISO 9001:2026 publishes 16 September: what happens to your 2015 certificate

Nothing, on the day — but the transition window opens, and the deadline that applies to you is set by your own audit cycle, not by 2029. How to work out your date from your certificate expiry, why waiting for the 2029 recertification is a trap, and the evidence your certification body will expect.

Jason Misters · 29 August 2026 Read article
Integrations

SharePoint isn't a compliance system: turning your document library into audit-ready ISO evidence

Your policies, procedures and certificates live in SharePoint — and at the audit, almost none of it counts as evidence, because a folder isn't ISO 9001 document control. What "audit-ready" actually requires (version control, approval, traceability), why "just use SharePoint" quietly fails, and how PICMS's new Microsoft 365 integration turns your existing documents into clause-mapped evidence — no migration required.

Jason Misters · 5 August 2026 Read article
RAMS & Site Safety

When the scope changes at 6am: building a RAMS process that survives it

The RAMS is dated correctly, signed correctly, filed correctly, and describes a job that isn't the one being done today. Why last-minute scope changes break most SME RAMS processes, what ISO 45001 and CDM 2015 actually require (and don't), and the three things the contractors who never get flagged have in common.

Jason Misters · 15 August 2026 Read article
Document Control

Read-and-sign vs email acknowledgement: which one holds up?

Emailing the policy round and asking people to reply is how most UK SMEs distribute controlled documents — and it satisfies who and when while almost always failing on which version. Why an email trail stops being evidence the moment a document is revised, the four fields a defensible acknowledgement record needs, and three ways to close the gap.

Jason Misters · 12 August 2026 Read article
People · Product

Right to work, DBS & the £60,000 mistake: the employee checks UK employers keep getting wrong

One illegal worker can now cost £45,000–£60,000, and starting care staff before their DBS clears is a safeguarding breach. What care, construction and security employers must check — right to work, the right DBS level, the ~6-month retention rule — the 2024–2026 employment-law changes raising the stakes, and the personnel-data trap behind it all. Introducing PICMS People Vault.

Jason Misters · 24 July 2026 Read article
Product · Audit Readiness

Introducing the Audit-Readiness Copilot: 20 AI agents built for UK ISO compliance

Why we built PICMS as an Audit-Readiness Copilot instead of another "AI compliance assistant." Twenty specialist agents under one Master Agent, autonomy on a Trust Ladder dial, full ISO 42001 audit trail on every AI action. Plus the vertical moats — diving + social housing — nobody else touches.

Jason Misters · 7 July 2026 Read article
AI Governance

ISO 42001 for UK businesses: comply before the EU AI Act's August 2026 deadline

The EU AI Act is extraterritorial — if your AI's output is used in the EU, it reaches you, and the high-risk obligations apply from 1 August 2026. What those duties require, an indicative clause-by-clause mapping from ISO 42001, and an honest account of where the standard stops (CE marking, declaration of conformity, EU database registration).

Jason Misters · 17 July 2026 Read article
Cyber Essentials

Cyber Essentials 2026 "Danzell": the auto-fails catching out construction & healthcare

Two answers now fail an assessment outright: MFA missing on any cloud service, and high or critical patches later than 14 days. Cloud services are explicitly in scope — which is why most failures start with an incomplete SaaS inventory. The pre-assessment checklist, plus the ISO 27001 control mapping.

Jason Misters · 17 July 2026 Read article
Data Protection

DUAA 2025: how to build a compliant data-complaints process

The UK's new data-protection complaints duty is now in force — a clear complaints route, a 30-day acknowledgement clock, and a process to investigate and respond, for organisations of any size. A step-by-step procedure mapped to ISO 27001 controls, plus the legal-register entry.

Jason Misters · 29 June 2026 Read article
ISO 9001

ISO 9001:2026 transition guide: what's changing and how to prepare

The first major ISO 9001 revision since 2015 is coming — FDIS out, publication expected September 2026, three-year transition. The likely changes (quality culture, ethics, leadership, explicit climate & digital context), the timeline, and a practical gap-planning checklist to get ahead before the rush.

Jason Misters · 29 June 2026 Read article
ISO 9001

ISO 9001 internal audit checklist (UK, 2026)

The clause most organisations treat as a box-tick is the one a certification auditor leans on hardest. A practical, clause-by-clause internal audit checklist (context 4 through improvement 10) with example questions, the objective evidence to look for, and how to record nonconformities and corrective action under Clause 10.2.

Jason Misters · 22 June 2026 Read article
Construction

CHAS vs ISO 45001: do UK contractors need both?

One is a UK pre-qualification accreditation that gets you onto construction tender lists; the other is a certifiable international H&S management system. The real differences in scope, recognition and audit depth — and the honest answer to whether you need both.

Jason Misters · 22 June 2026 Read article
ISO Standards

ISO 9001 vs ISO 45001: what's the difference?

One manages quality, the other manages health and safety — but they share an identical Annex SL backbone (clauses 4 to 10). Where they genuinely differ, and how UK SMEs holding both run them as one integrated management system.

Jason Misters · 22 June 2026 Read article
Commercial Diving

ACoP L104 vs L103: what UK diving contractors need to know

Two HSE Approved Codes of Practice sit under the Diving at Work Regulations 1997 — and they're constantly confused. L103 is offshore, L104 is inland/inshore. The precise difference, the duty-holder roles, and the audit pitfalls that catch contractors out.

Jason Misters · 22 June 2026 Read article
Insight

Compliance on autopilot: running ISO 9001, 14001 & 45001 from one system

"Autopilot" sells software — but the businesses that breeze through surveillance audits automated the right things and kept a human at the controls. Where that line falls, from the auditor's side of the table.

Jason Misters · 11 June 2026 Read article
Guide

How PICMS helps businesses prepare for — and maintain — ISO compliance

ISO compliance has two halves: getting certified and staying certified. Most software only helps with the first. How PICMS — built by an IRCA Registered Principal Auditor with years of hands-on implementation experience — carries businesses through both.

Jason Misters · 10 June 2026 Read article
Buyer's Guide

How to choose ISO compliance software

The UK buyer's guide to choosing ISO compliance software — the evaluation criteria that actually matter, fair pricing, build-vs-buy, and the red flags to walk away from.

Jason Misters Read guide
Comparison

Best ISO compliance software UK 2026

PICMS, Mango QHSE, Citation, Cority and Vanta compared head-to-head for UK ISO buyers — standards coverage, pricing, sector focus and UK presence.

Jason Misters Read comparison
Head-to-Head

PICMS vs Vanta® — UK ISO buyer's comparison

Vanta covers SOC 2 + ISO 27001 for the US startup market; PICMS covers the full ISO ladder (9001 / 14001 / 45001 / 27001 / 42001) plus UK sector packs. Which fits your business?

Jason Misters Read comparison

Written by Jason Misters — IRCA® Registered Principal Auditor

Lead auditor and ISO consultant. Founder of Training Assurance Consultancy and PICMS. Every article on this blog is written from years of hands-on experience implementing ISO standards into UK businesses — verifiable on the CQI-IRCA register.

Ready to put the reading into practice?

14 days free, full feature access. Run a gap analysis on day one and find out exactly where you stand — before an auditor does.

Start Free Trial Book a Demo