ISO readiness

We implement your management system under the international ISO standards: ISO/IEC 27001 (information security), ISO/IEC 42001 (AI) or ISO 22301 (business continuity). From zero to prepared for certification with an accredited body, with monthly maintenance once the system is in place.

A buyer asks for an ISO certificate before they sign

Your enterprise customers want to know how you protect their information, how you govern the AI in your product and whether your service withstands a disruption. An ISO certificate shows that a certification body audited your management system and found that it conforms to the standard.

The three standards share the same structure (clauses 4 to 10): each one asks you to define the scope of the management system, set a policy, assign roles, address risks, run internal audits and review the system at top-management level.

Each one adds its own. ISO/IEC 27001 and ISO/IEC 42001 ask for a statement of applicability with the controls the company needs. ISO 22301 asks for a business impact analysis (BIA): how the interruption of an activity affects your company over time.

Certification is granted by an accredited certification body after it audits your system. Our job is to get you ready for that audit.

If you need more than one standard, they are implemented as one integrated project: several standards on a single system, with an integrated policy, one risk method, a combined internal audit and one team.

What you receive

  • System scopeWhich processes, teams and locations the management system covers.
  • Policy and rolesThe policy of the system, set by top management, and who has which responsibility and authority to run it.
  • Risk assessment and treatmentThe risks the system must address and what is done about each one. In ISO/IEC 42001 it includes the AI system impact assessment; in ISO 22301, the business impact analysis.
  • Statement of applicabilityIn ISO/IEC 27001 and ISO/IEC 42001: which controls your company needs, why they are included and why it excludes those it does not apply.
  • Procedures and recordsThe procedures and documented information the system needs to operate and to show that it works.
  • Internal audit programWhat gets audited, how often and how, with the first internal audit already carried out, so your company can keep auditing the system at planned intervals (clause 9.2).
  • Management reviewThe information package for top management to review the system (clause 9.3): its performance, the audit results and the opportunities for improvement. The first review takes place before certification.
  • Monthly maintenance (optional)Once the system is in place, we keep it up to date with your team: risks, documents, indicators and audit preparation.

How it works

  1. We agree with you on which standards to implement and the scope of the system.

  2. We review what your company already has and compare it with the requirements of each standard.

  3. We build the system with your team: policy and roles, risk assessment, procedures and, where the standard asks for it, the statement of applicability, the AI system impact assessment or the business impact analysis.

  4. We run the first internal audit and the first management review with your team: the certification body checks that both have been done before it certifies. The audit is done by your team or by Gradiente auditors who did not take part in the implementation.

  5. Your system is ready for certification with an accredited body and, if you decide, we continue with monthly maintenance.

What defines the scope

  • How many standards are implemented and whether they go in one integrated project.
  • The size of the organization and how many processes, teams and locations are in scope.
  • What your company already has documented and working.
  • Whether monthly maintenance is added.

How to engage

The implementation is contracted as a fixed-fee project, and the maintenance of the implemented system as a monthly fee.

Let's talk about the management system your company needs.

In 30 minutes we review where you stand and suggest where to start.

Book 30 minutes contacto@gradiente.cl Write to us and we will set up a 30-minute conversation