GDPR compliance: the parts a small company actually has to do
Most GDPR programmes drown in policy templates. The obligations that regulators check are a much shorter list, and each one produces a record.
Most of ISO 9001 describes how a well-run company already works. The gap is usually in evidence, ownership and the parts that repeat on a schedule.
ISO 9001 is the international standard for quality management systems. It does not say how to make your product; it says that you should understand what your customers require, plan how to deliver it, control the processes that do, measure whether they worked, and improve where they did not — and that you should be able to show all of this.
For a company that already works competently, the standard rarely demands new activity. It demands that existing activity be assigned, recorded and repeated on a schedule. That is why the gap between "we do this" and "we can show we do this" is where certification projects actually spend their time.
Internal audit and management review are the two that get scheduled and then quietly skipped, and they are also the two an auditor checks first — because both leave an unmistakable record when they happen and an equally unmistakable gap when they do not.
The 2015 revision removed the requirement for a quality manual and for six mandatory procedures. What remains is the requirement to keep the documented information necessary for the effectiveness of the system, plus the specific records the standard names. Companies that build a large document set are usually re-creating an older version of the standard, or copying a template from a much larger organisation.
A procedure nobody follows is worse than none. If the written process and the real process differ, an auditor has evidence that the system is not being operated — and the honest fix is usually to rewrite the document to match what the competent version of the work actually looks like.
Because the standard is largely about documented information being current, approved and findable, the document layer is where most of the practical work lives. Ettex Docs keeps procedures with their approvals, revision history and review dates, so an auditor’s question about which version was in force in April is a property of the document. Everything the documents describe — the processes, the audits, the corrective action — still has to be done by the organisation, and no tool substitutes for that.
The honest answer depends on why you are doing it. If customers or tenders require the certificate, the decision is made. If the motivation is internal improvement, the standard is a reasonable checklist but an expensive one, and much of the benefit is available by adopting the parts that matter — process ownership, internal audit, management review — without the certificate.
No. The 2015 revision removed that requirement, along with the six mandatory documented procedures. Many organisations keep a short manual anyway because it is a convenient index.
Typically three to nine months for a small organisation, driven mostly by the need to complete a cycle of internal audits and at least one management review before the stage 2 audit.
ISO 9000 sets out the vocabulary and principles; ISO 9001 contains the requirements you can be certified against. ISO 9004 gives guidance on going further than the requirements.
Yes. The standard is deliberately sector-neutral; the requirements apply to the processes that deliver whatever you provide, product or service.
Most GDPR programmes drown in policy templates. The obligations that regulators check are a much shorter list, and each one produces a record.
Certification is not a document review. Stage 1 checks whether the system exists, stage 2 whether it operates — and the second one samples your evidence.
Incoterms allocate cost, risk and customs duties between buyer and seller. Choosing one by habit is how companies end up insuring cargo they do not own.