loader from loading.io

#237 Gap Analysis – The First Step In ISO Implementation

The ISO Show

Release Date: 11/26/2025

#246 Pedalling Towards Purpose – Forests Journey To B Corp Accreditation show art #246 Pedalling Towards Purpose – Forests Journey To B Corp Accreditation

The ISO Show

Europe is only partially on track to meet its 2030 environment and sustainability objectives, and while some objectives are being scaled back, we are seeing the introduction of more regional regulations that require tangible annual sustainability reporting.  Businesses that have built sustainability into their way of working from the start are leading the charge and defining what it means to operate responsibly. As with today’s guest, Forest, an e-bike provider that is not only 100% powered by renewable energy but has also achieved the coveted B Corp Accreditation. In this episode,...

info_outline
#245 What’s The Difference Between TISAX and ISO 27001? show art #245 What’s The Difference Between TISAX and ISO 27001?

The ISO Show

For those in the automotive industry, namely suppliers working with European OEM’s, you’re likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from. ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two. For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don’t intend to certify to both. In this episode, Ian Battersby is joined...

info_outline
#244 What is TISAX? show art #244 What is TISAX?

The ISO Show

The modern automotive industry faces many new challenges, as vehicles evolve with more complex data requirements and supply chains become increasingly interconnected, major Original Equipment Manufacturers (OEMs) require certain Standards as a mark of trust from potential suppliers. Currently, this trust is codified in TISAX (Trusted Information Security Assessment Exchange). For businesses that have not previously dealt with Standards, TISAX can be seen as a daunting regulatory hurdle. However, a TISAX label is more than a compliance check, it’s a recognised mark that your organisation...

info_outline
#243 How Can You Leverage AI for ESG and Sustainability Reporting show art #243 How Can You Leverage AI for ESG and Sustainability Reporting

The ISO Show

Annual sustainability and ESG reporting is now becoming a necessity for many businesses, whether driven by region specific regulations and legislation, industry expectations or client demand.  However, doing so is definitely easier said than done. It requires a complex network of data being gathered from multiple sources which then needs to be collated, analysed and summarised in a cohesive report for leadership and possible public publication. Thankfully, there have been developments in new AI driven technology that can help ease this annual burden, allowing you to focus on...

info_outline
#242 Surface Print – The Commercial Advantage of ISO 14001 for SME’s show art #242 Surface Print – The Commercial Advantage of ISO 14001 for SME’s

The ISO Show

A Standard like ISO 14001 may seem more appropriate for large enterprises looking to address their environmental footprint, however it can apply to any business no matter the size. All businesses produce waste, and we can all do more to save energy, resources and money in the process. For some SME’s, tackling resource wastage through effective environmental management can make a huge difference. Such is the case for today’s guest, Surface Print, a family owned wallpaper manufacturer managed by its 4th generation. In this episode, Ian Battersby is joined by James Watson, Managing...

info_outline
#241 Raise your Game With The Leadership Powerup Gameplan show art #241 Raise your Game With The Leadership Powerup Gameplan

The ISO Show

An ISO Management System can’t survive without Leadership engagement. It was seen as such an essential aspect that ‘Leadership commitment’ became a key requirement of many ISO Standards back in 2015 when the Annex SL format was adopted. It’s easy to see why. An effective Management System will provide vital information for top management to make decisions on processes, policies and strategic direction. So, how do you get leadership involved with your ISO management system? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to...

info_outline
#240 Revitalise your Audits with the Audit Accelerator Gameplan show art #240 Revitalise your Audits with the Audit Accelerator Gameplan

The ISO Show

Internal Audits are a key part of any ISO Implementation journey, they are also a necessary vehicle to drive continual improvement. For those with more mature ISO Management Systems, it can be easy for Internal Audits to become a bit of a rinse and repeat exercise. This can lead to stagnation of meaningful results, especially if you’re asking the same people the same questions year on year. So how can you revitalise the Audit process? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss the challenges associated with repeated...

info_outline
#239 2025 ISO Standard Wrap Up and Looking Ahead show art #239 2025 ISO Standard Wrap Up and Looking Ahead

The ISO Show

It’s been a busy year for ISO Standards, with that set to ramp up in 2026 thanks to upcoming Standard transitions. Before we dive into a new year, we’d like to take a step back and highlight some of the key ISO milestones from 2025.  In this episode, Steph Churchman, Communications Manager at Blackmores, looks back at the major Standard updates from 2025, including changes to existing Standards, new ISO’s published and key upcoming changes you need to be aware of for 2026.   You’ll learn ·      What ISO Standards have been updated in 2025? ...

info_outline
#238 Umony's ISO 42001 Journey - Setting the Standard for effective AI Management show art #238 Umony's ISO 42001 Journey - Setting the Standard for effective AI Management

The ISO Show

AI has become inescapable over the past years, with the technology being integrated into tools that most people use every day. This has raised some important questions about the associated risks and benefits related to AI. Those developing software and services that include AI are also coming under increasing scrutiny, from both consumers and legislators, regarding the transparency of their tools. This ranges from how safe they are to use to where the training data for their systems originates from. This is especially true of already heavily regulated industries, such as the financial...

info_outline
#237 Gap Analysis – The First Step In ISO Implementation show art #237 Gap Analysis – The First Step In ISO Implementation

The ISO Show

When embarking on your ISO journey, a crucial first step is evaluating your current level of compliance and identifying what gaps need to be filled to gain certification or fully align with a Standard. This is typically done by conducting a Gap Analysis. This exercise sets the foundations for your ISO Implementation project, from setting key actions and objectives, to resourcing and establishing a project timeline.   In this episode, Ian Battersby dives into the purpose of a Gap Analysis, who should be involved in the exercise and what inputs and outputs you should expect to have from...

info_outline
 
More Episodes

When embarking on your ISO journey, a crucial first step is evaluating your current level of compliance and identifying what gaps need to be filled to gain certification or fully align with a Standard. This is typically done by conducting a Gap Analysis.

This exercise sets the foundations for your ISO Implementation project, from setting key actions and objectives, to resourcing and establishing a project timeline.  

In this episode, Ian Battersby dives into the purpose of a Gap Analysis, who should be involved in the exercise and what inputs and outputs you should expect to have from conducting a Gap Analysis.  

You’ll learn

·      What is a Gap Analysis?  

·      What is the aim of a Gap Analysis?

·      What is the process of conducting a Gap Analysis?

·      Who should be involved in a Gap Analysis?

·      What inputs should be included in a Gap Analysis?

·      What outputs can you expect from a Gap Analysis?

Resources

·      Isologyhub

 

In this episode, we talk about:

[02:05] Episode Summary – Ian Battersby dives into the first step on any ISO Implementation journey, breaking down what a Gap Analysis is, it’s purpose and what you should expect to get out of conducting one.

[02:50] What is a Gap Analysis?: Simply put, it’s the start of the process.

It’s a key to understanding where an organisation is right now and establishing what it needs to do on its journey to ISO certification.

But it’s not just for certification, as certification isn’t always what people are trying to achieve. Many businesses opt to align themselves to a standard to ensure they’re doing the right thing, but may not go through with full certification.

[04:05] Who is the aim of a Gap Analysis? The objective of a Gap Analysis is to carry out a review of your organisation against the requirements of the respective standard.

This will help to establish the following:

·      Areas where you conform to the standard, where you may have established the required processes, procedures, roles, responsibilities, systems, methods, documents

·      Areas of nonconformity, where such things will need to be developed

·      You may partly conform, so it’s important to understand that as well

From that understanding, you can build key actions, timescales and responsibilities for implementing an ISO Standard.

It’s also very useful to leadership; to clarify what’s needed, to look at priorities, to resource what’s required and to establish a timeline to your end goal.

[06:25] What is the process of conducting a Gap Analysis? It’s important to do this in a very structured manner. It’s also important to get access to existing documentation and personnel in key roles; they’ll be helpful during the gap analysis in providing understanding.

You’ll need to evaluate your current level of compliance against the following clauses within your desired ISO Standard(s):

4 Context: Understanding the world in which you operate, the people and organisations which are important to you. This is where you will determine the scope of your system (what to include, what parts of the standard are relevant).

5 Leadership: Top management’s commitment, how involved they are, their accountability and their commitment to resourcing, promoting, to giving people authority through clear roles and responsibilities.

6 Planning: This is about assessing risks and opportunities; understanding the uncertainty caused by your operating environment (context). It also involves setting objectives and then establishing meaningful plans to address the risks/opportunities and objectives; mitigations; establishing controls; operational processes.

7 Support: This is where you look at people, competence Infrastructure and environment (are your facilities/equipment appropriate to what you need to do). You will also need to identify what you need to monitor and measure to demonstrate the effectiveness of your ISO Management System.

Next, you need to cover awareness and communication, i.e. how do you make people aware of your system, policy, processes; what do you tell other interested parties?

Lastly, ensure you address how you control the documentation which supports your system.

8 Operation: This address the delivery of a product or service to the customer, including all the processes for doing so. For example, in ISO 9001 this clause defines what’s required when designing, developing, controlling externally provided products/services and controlling anything which goes wrong.

This is typically the clause that contains the largest difference between ISO Standard, with each one focusing requirements on it’s topic focus. For example, ISO 14001 includes requirements for emergency preparedness and response in the event of an environmental incident.

9 Performance evaluation: This is where you review and report on the results of the monitoring and measurement that you’ve put in place. For those familiar with ISO, this is where the internal audit and management review requirements sit.

10 Improvement: This clause states requirements for addressing any non-conformities that pop-up during your Internal Audits. It also encourages you to address opportunities for improvement to help drive continual improvement and innovation.

[13:50] Who should be involved in a Gap Analysis? One key myth that we’d like to clear up is that not everyone in the business needs to be involved in this process, however, we do recommend the following are included:

The person responsible for the day-to-day running of the Management System. This may not be known at this early stage, which is fine as the purpose of the Gap Analysis is to identify gaps such as this.

Leadership; someone in a senior role; responsible for resourcing the system, communicating its importance to the workforce; responsible for setting the strategic direction and objectives.

People who understand the context of the organisation; understanding interested parties (stakeholders); needs of customers and others; the regulatory environment

Those involved in risk management; operational, financial, commercial, regulatory, safety or environmental.

Someone with knowledge of the legal requirements and how they’re evaluated; relative to specific standard.

Anyone setting objectives related to the specific standard.

Those with knowledge of competence arrangements; not just those responsible for co-ordinating the Management System, but across the board, for delivering operational processes.

Those responsible for facilities and equipment; maintenance, service, test, inspection, etc.

People responsible for developing and delivering operational processes.

People with knowledge of how things are monitored or measured; possibly operations people, data analysis or those who report performance to management.

Those who control nonconformity and those who run improvement processes.

It can be quite a range of people!

However, in smaller organisations there may be quite a limited number who likely wear many hats. Again, that’s not a problem, as the Gap Analysis exists to discover that.

[21:55] What inputs should be included in a Gap Analysis? This can include a number of things, as not everything will necessarily be a document. Typically, we as consultants will look at:

·      Management System manual or System Scope

·      Organisational chart

·      Mission, vision, values and culture

·      SWOT/PESTLE and Interested Parties

·      Policy relevant to the standard

·      Job descriptions

·      Risk and opportunities analysis; methodology

·      Objectives

·      Legislation register and methods of evaluation

·      Competence arrangements, training records

·      Management System awareness, training completion

·      Details of version and document control in place

·      Monitoring and measuring plans (KPIs, SLAs, internal performance metrics)

·      Internal audit programme and audit reports

·      Management review records

·      Agendas for any regular management meetings

·      Nonconformities, incident report and corrective action records

·      Customer complaints/feedback

·      Emergency Plans

·      Process Documentation

·      Examples of process documentation:

·      Change control documentation

·      Sales, tendering, order processing

·      Procedures for the design and development of products and services

·      Design and development records stating inputs, verification and validation activities, outputs, and approval of changes

·      Procedures to approve products and services for release to customers including quality checks

·      Supplier / third party evaluation and onboarding documents

·      Non-conformity/complaint information

·      Traceability documentation

[29:40] What is the output from a Gap Analysis? We look at all of this and compare it against the requirements of the Standard to see where you currently stand. In our case, we do this on a spreadsheet with a simple scoring system to give you an overview of what you already have in place and what needs to be addressed.

In many cases, businesses already have a lot of the required documentation, but don’t have it tied together in one cohesive system. So a large part of implementation is consolidating that existing documentation, process ect. Into an accessible and easily understood system.

The key thing to remember is that this is not an audit. The evidence required does not have to be as detailed as an audit; some things can be taken on trust or face value. At this stage we aren’t demonstrating anything to a certification body, and you are not being judged.

We are simply looking at what needs to be done to achieve full Implementation or certification.

If you’d like assistance with carrying out a Gap Analysis, get in contact with us, we’d be happy to help.

We’d love to hear your views and comments about the ISO Show, here’s how:

     Share the ISO Show on Twitter or Linkedin

     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List