The standard contains the requirements for quality management systems. It specifies what rules to develop for our business so that we make sure that we always provide services and products of equally highly predictable quality and that we constantly improve them. Of course, in the standard, we will not find ready solutions. Still, it allows us to consider all areas of management of a business without missing anything – from the regular provision of resources through the production and provision of services to monitoring the customer’s opinion of us.
ISO 14001:2015
The standard contains the requirements for environmental management systems. We will find requirements that aim to ensure that the organisation that implements them carefully assesses how its activities affect the environment and what measures to take to reduce harmful effects and increase usefulness. The implementation of the standard helps to monitor and control compliance with environmental legislation and meet stakeholders’ expectations.
ISO 45001:2018
The standard replaced the popular OHSAS 18001 standard, contains the occupational health and safety management systems requirements. This area of governance of an organisation is highly regulated. Through OHSMS, organizations can more efficiently manage the assessment of risks to OHS and compliance with regulatory requirements. Furthermore, in an environment of increasingly fierce competition for quality workers, the certification to ISO 45001 is a sign of a responsible attitude towards labour safety and care for workers.
ISO/IEC 27001:2022
The revised standard for information security management systems was published in October 2022 by the international standards organisation. There are no major changes to the main text of the standard, but the significant change is to Annex A of the standard, which has been reorganised. The previous 114 controls which used to be grouped into 14 clauses have been reduced to 93 controls grouped into 4 topics. Eleven entirely new controls have been introduced, 24 controls have been derived from the merging of controls existing in the previous version, and 58 controls have been updated. The presentation of the control mechanisms has also been changed by dropping the description of ‘objective’.
Read our policy on certification to the new version of the standard here.
ISO/IEC 27701:2019
ISO/IEC 27701:2019 is an international standard that extends the scope of ISO/IEC 27001 and ISO/IEC 27002 by providing guidance on the management of personal data in the context of information security management systems (ISMS). This standard establishes the requirements and provides guidance for the establishment, implementation, maintenance and continuous improvement of a personal data management system in the context of an ISMS.
ISO/IEC 27701:2019 is aimed at organisations that collect, process and store personal data, as well as organisations that provide personal data processing services to other organisations. It provides guidance on risk management, protection of data subjects’ rights and evidence of compliance with data protection legislation.
ISO/IEC 27001:2013 – withdrawn
The standard was withdrawn by ISO. Certificates of compliance with this version are not valid after 31 October 2025.
The standard contains the requirements for information security management systems. The standard requires an assessment of the security risks for “information assets” and specific measures to ensure those assets’ availability, integrity, and confidentiality. “Information assets” means all information that an organisation holds – information about customers, contracts, suppliers, financial information, etc., whether on paper or electronic form. The standard directs us to implement such a system of measures to ensure that our information remains intact (i.e. no parts of it are missing because of theft, fire or deletion), that it is available when we need it and that it remains confidential (not available to competitors, personal data of customers and users does not leak).
ISO 39001:2012
Contains requirements for road safety management systems. It is applicable to all organisations that wish to contribute to improving road safety through specific measures and actions that are within the scope of their capabilities – by committing to promoting the safe behaviour of their employees at work and leisure, by implementing road behaviour control measures, by investing in road safety technologies or projects, cooperation with other organisations and with local communities.
ISO 22000:2018
Contains requirements for food safety management systems. A standard established over the years to assess compliance with both food safety regulations and best practices to ensure the production, storage, transport and marketing of food safe for human health.
ISO 18788:2015
The standard contains the requirements for management systems for private security activities. ISO 18788 provides a business and risk management framework for organisations performing or procuring security operations and related activities and functions, while demonstrating:
(a) conducting professional security operations to meet the requirements of customers and other stakeholders;
(b) accountability to the law and respect for human rights;
(c) compliance with the voluntary commitments it makes.
ISO 18788 is applicable to any organisation that needs to demonstrate its ability to consistently provide services that meet client needs and comply with applicable laws and human rights requirements.
ISO 37001:2015
ISO 37001:2016 contains requirements for anti-bribery management systems. The standard proposes the implementation of various measures not only to address bribery risks (e.g. to our employees, contractors, partners) but also to prevent, detect and respond to bribery incidents. These measures include, however are not limited to, adopting an anti-bribery policy, designating an officer to monitor compliance with anti-bribery rules, training, risk assessments, due diligence on projects and partners, implementing financial and operational controls, and establishing reporting and investigation procedures. Last but not least, the standard requires leadership and active support and commitment from the organisation’s senior management and governing bodies.
ISO 22716:2007
Contains guidelines on Good Manufacturing Practices (GMP) for the manufacture, control, storage and dispatch of cosmetic products. The guidelines offer organisational and practical advice on managing the human, technical and administrative factors that affect product quality.

