Not a slide deck. These are working screens from the live system, rendered from a real example management system, and they are the same ones your auditor will be shown.
Working screens from the live system. The same ones your auditor will be shown.
Seventeen live tiles in three groups: what needs attention, system health, and what's coming up. Every one is computed from your real registers the moment the page opens, and every one clicks straight through to the record behind it.
It's the screen a Managing Director opens on a Monday morning, and the one we open together on quarterly reviews: no report-writing, no chasing three departments for a figure nobody wants to own. The numbers are simply what the registers say.
Each month has a short, sensible task list. Tick it and the portal stamps who did it and when. Every task links straight to the register it belongs to, the current month is highlighted, and a missed month flags itself in red until it's cleared.
You set the start of your compliance year to match your certification cycle, and the tasks in each month are yours to edit. The rhythm does the remembering, so nobody carries the system in their head.
A five-by-five heat map plots every risk by likelihood and severity, switchable between inherent and residual scoring, so you can show an auditor in seconds that your controls actually move the numbers.
Underneath it sits the full register: threats and opportunities, owners, controls, review dates and cross-references to the changes, communications and nonconformities each risk connects to.
Every obligation you carry, whether environmental, health & safety, information security or employment, with how it applies to you, who owns it, and a direct link to the official text on legislation.gov.uk. No second-hand summaries. The actual current law, one click away.
Compliance evaluations reference the same register, so every "compliant" is backed by an evaluation record with evidence. Anything not yet evaluated says so, plainly, until it is.
A person-by-course matrix shows the whole workforce's training position at a glance: current, expiring, expired or not required. Certificates upload onto the exact cell they evidence.
Behind the matrix, each person carries a competence record: qualifications, experience and the documents that prove them. It is the file an auditor asks for by name, usually about ten minutes after taking his coat off.
The annual internal audit programme carries the clause 9.2.2 justification auditors look for: why each audit is planned when it is, based on importance, changes and previous results. Overdue detection runs by month as the year goes on.
When top management approves the programme, it locks with their signature. Every completed audit links through to its findings, and findings feed corrective action.
Every nonconformity runs the full corrective-action lifecycle, from containment through root cause and action to verification, and stays linked to whatever raised it: a complaint, an audit finding, a supplier issue.
Recurrence is visible by design. When the same failure comes back, the record says so, and the root-cause conversation starts from evidence rather than memory.
Approved suppliers sit in three tiers: preferred, alternative and last resort. They are judged against acceptance criteria you control under clause 8.4.1, published right beside the register so the rules and the list can't drift apart.
Re-evaluations, certificates and risk status live on each supplier's card; moving a supplier between tiers is one edit, and an overdue re-evaluation flags itself before your auditor finds it.
A structured template walks your review through every required input and output of clause 9.3. That means audit results, performance, resources, risks, improvement opportunities, and worker consultation where 45001 applies. Nothing forgotten, nothing padded.
The finished review becomes a clean, printable report your certification body can follow line by line, chaired signature included, and it downloads as a standalone document for the board pack.
Calibration certificates on the instrument. Drill reports on the drill. Signed policies on the policy. Concession records on the nonconforming output. Every register takes uploads with labels that match what the document actually is, and everything opens in the portal or downloads on demand.
That's the difference on audit day: the question "can you show me?" has a one-click answer, every time.
Every page below is live in the portal today. Registers specific to a standard appear only when that standard is in your scope.
Documents, objectives, context, complaints, certificates, KPIs. All of them the same live, evidence-carrying registers. The ten tabs above barely scratch it.
Either the records are current when the auditor arrives, or the fortnight before is spent making them current. That is the whole decision, and it comes round again every year until something is done about it. ISO 9001:2026 just put a date on it.
Five fields and no card. Either way you'll be speaking with a Consultant right from the start… not a sales team.