ISO · Documents

The documents you will actually be asked for — and who keeps them current.

If anyone proposes forty documents for an SME, ask them which forty your people will genuinely keep up. This is the short list that survives contact with a real working week — and the one register nobody remembers to update, which is where most first audits find their first finding.

The short list

What a typical one-standard SME ends up with. Four things, plus the records the work already makes.

DocumentIn plain wordsWho owns itHow often it changes
PolicyOne page: what we promise about quality, safety or environmentManaging directorReviewed yearly, signed once
Scope statementOne sentence: what this certificate covers, and from whereManaging directorAlmost never — only when the business changes shape
ProceduresHow each key job is done, and who is responsible — short, not a manualProcess ownerWhen the way you work changes
RegistersThe lists: legal rules, environmental aspects, hazards, equipment, training, contractorsNamed individual per registerContinuously — this is the living part
RecordsWhat the work already produces: checklists, logs, certificates, service reportsWhoever does the workEvery day

The registers, one by one

Legal register

Which rules apply to you, and who watches each one. Out-of-date legal registers are the easiest finding for an auditor to make.

Aspects register

Everything the work uses, produces or emits — with the important ones marked and controlled.

Hazard and risk assessments

One per activity, current, with the controls that are actually in place rather than the controls you wish were in place.

Training matrix

Who has been trained for what, when, and the certificate to prove it — including new staff, who are the most common gap.

The records your work already makes

You do not create this evidence. You stop throwing it away.

Version control, one paragraph, no jargon

What we hand you vs what you keep

We write and set upYou keep current afterwards
Policy, scope statement, procedures, all registersRegisters: updating them as the business changes
The training matrix and the retention ruleRecords: keeping what the work produces
The internal audit plan and the first internal auditThe yearly internal audit and the management review
The calendar with every date in itOpening the calendar and acting a month before each date

Questions we get asked

How many documents is normal for an SME?

One policy, six to ten short procedures and the registers. If a proposal runs past twenty documents for a single-site SME, ask what each one is for and who will keep it up. Documents nobody reads are liabilities.

Do we need to buy software?

No. Spreadsheets and folders work, and most of our clients stay on them. Software helps when several sites genuinely need the same document at the same time — that is a scale decision, not a certification one.

What if a procedure is wrong?

Then change it. The system expects it. What fails an audit is a procedure that is wrong and still being followed silently.

Can we write the documents ourselves?

Yes, if someone has the time and the appetite for the standard's language. Many companies write the first draft and pay us to review it — that is a smaller, cheaper engagement and we are happy to do it.

Who owns the documents at the end?

You do, and you keep them if we part ways. We retain ownership of our own templates and methods, which is clause 12 of our terms.

Want to see what your set would look like?

Tell us your trade and roughly how many people and processes are involved. We will send a plain-English contents list before you commit to anything.