a
.

    News and Commentary on ISO Management System Standards

    Dr John FitzGerald

    Director & Founder of deGRANDSON Global. Spent 15 years in the manufacturing industry and 25 years training, consulting & auditing management systems
    Find me on:

    Recent Posts

    05 May 2026

    Why ISO 21001 and not ISO 17024 or EXEMPLAR or IRCA Accreditation?

    Other Topics

    deGRANDSON Global holds ISO 21001 Certification, a university-grade accreditation, because it's the only one that matters. Without independent auditing to confirm compliance, it's only a badge! We started by asking what would be the best choice of Learning Provider qualification for ISO Lead Auditors, ISO Consultants, and others wishing to audit, implement, or maintain ISO Management Systems to a ...
    Read More
    30 Apr 2026

    FDA QMSR and ISO 14971: What to do about Risk Management

    ISO 13485, ISO 14971

    Don't believe everything you read about ISO 14971! The FDA's 'Medical Devices; Quality System Regulation Amendments' website explicitly states: All sections of ISO 13485 apply to device manufacturers. While there is much mention of 'incorporating by reference' and many misguided interpretations of that phrase, don't let anyone mislead you. To reiterate, the FDA's website explicitly states that ...
    Read More
    28 Apr 2026

    Correction, Corrective Action and Preventive Action explained

    ISO Standard Implementation

    Badly written Corrective Action Clauses in ISO Management System Standards add to the confusion. Correction, Corrective Action, and Preventive Action (CCAPA) are essential management systems components that help organizations identify, address, and prevent issues to ensure ongoing compliance and improvement. And all three expressions are defined and explained in this Post.
    Read More
    23 Apr 2026

    QHSE, HSEQ, SHEQ, IMS explained

    ISO 9001, ISO 45001, ISO 27001, ISO 14001

    These are commonly used terms, but they have no official standing So, where are they used, and what is their significance when you wish to be an Auditor certified to more than one ISO Management System Standard?
    Read More
    21 Apr 2026

    ISO 27001, ISO 27701 and GDPR: a natural combination

    ISO 27001, Data Protection

    In 2018, many organizations, not only those based in the EU, spent much time and money on compliance with the General Data Protection Regulation (GDPR). But what actions should we take now to ensure ongoing compliance? It's not enough to have policies and procedures to demonstrate compliance with the requirements. If there is a data breach or similar event, regulators will challenge you to ...
    Read More
    16 Apr 2026

    ISO 45001 Risk Assessment & Risk Treatment Tools

    ISO 45001

    You'll need OH&S Risk Management Methods & Tools Unlike ISO 9001, the Occupational Health and Safety Management System (OHSMS) Standard requires the application of OH&S Risk Management Methods in Clause 6.1. So, risk-based thinking alone does not meet requirements. Formal and documented Risk Assessment followed by Risk Treatment is required for compliance.
    Read More
    15 Apr 2026

    ISO Auditor Competence: who decides?

    ISO Auditing

    Your ISO Auditor Certificate doesn't make you competent Being on a professional ISO auditor register isn't enough either Competence is defined as the ‘ability to apply knowledge and skills to achieve intended results.’ And so it is with ISO Auditor Competence. Your Lead Auditor Certificate alone does not ensure competence. Nor, when competent, do you suddenly become incompetent three years after ...
    Read More
    07 Apr 2026

    Medical Devices: Residual Risk and Risk Tolerance

    ISO 13485

    QMSR & ISO 13485: On 02-Feb-26, the FDA Final Rule comes into force. The amendments incorporate by reference (and so align more closely with) the international standard ISO 13485:2016, Medical Devices - Quality Management Systems - Requirements for regulatory purposes. Managing residual risk and understanding risk tolerance are crucial aspects of ISO 13485 compliance. ISO 13485:2016 is an ...
    Read More
    25 Mar 2026

    Why ISO 14001 Matters to SMEs

    ISO 14001

    Even the smallest organization has a lot to gain from a certified Environmental Management System (EMS) New businesses often ponder the benefits of ISO 14001 Certification and, being busy with start-up priorities, postpone certification until it is asked for in a tender document or by a prospective customer. At that point, it is, of course, too late. Optimistically, getting certified takes at ...
    Read More
    10 Mar 2026

    ISO 27001 in Manufacturing & Service Industries - the FAQs

    ISO 27001

    Have you considered this possibility? If you wait until this message greets you at work, a Notebook PC is stolen from a company vehicle, or staff members are working on their own PCs from home, it will be too late. It's not a question of whether your business will be targeted. You're already a target but have been lucky to date.
    Read More

    Last Modified: March 11, 2026

    Subscribers get a 10% Discount

    MONTHLY OFFER
    Get 25% off on all ISO 9001 Training and Certification Courses in May