ISO readiness, gap assessment and certification support in one platform.
XGRC® supports readiness and gap assessment across the ISO standards that matter most for quality, safety, environmental, information security and risk management. The same platform carries you from the first gap assessment to certification, and keeps the system working through every surveillance audit after it.
ISO 27001 Readiness
XGRC® MSXCyber® gives organisations a structured way to assess ISO 27001 readiness, close control gaps, and manage the information security management system on an ongoing basis — not just in the weeks before an audit.
View readiness guide → ISO ReadinessISO 9001 Readiness
XGRC® MSX® gives organisations a structured way to assess ISO 9001 readiness, close quality management gaps, and run the QMS as a living system — not a folder of documents produced for the auditor.
View readiness guide → ISO ReadinessISO 14001 Readiness
ENVIRX® by XGRC® gives organisations a structured way to assess ISO 14001 readiness, close environmental management gaps, and monitor compliance obligations continuously — not reconstruct evidence for the auditor.
View readiness guide → ISO ReadinessISO 45001 Readiness
SHEQX® by XGRC® gives organisations a structured way to assess ISO 45001 readiness, close OH&S management gaps, and run hazard identification, incident management and contractor safety as one connected system.
View readiness guide → ISO ReadinessISO 22000 Readiness
XGRC® MSX® gives food businesses a structured way to assess ISO 22000 readiness, close food safety management gaps, and keep prerequisite programmes, HACCP plans and traceability audit-ready every day.
View readiness guide → ISO ReadinessISO 31000 Risk Management
ISO 31000 is a guideline for managing risk, not a certifiable management system — there is no audit to pass. XGRC® helps organisations adopt and embed the ISO 31000 risk management process, from establishing context through risk assessment, treatment, and ongoing monitoring and review.
View readiness guide → ISO ReadinessPAS 99 / Integrated Management System
PAS 99 is BSI's specification for integrating two or more management system standards — ISO 9001, ISO 14001, ISO 45001, ISO 22000 — into one common framework instead of running each in its own silo. This checklist covers what PAS 99 integration actually requires, and XGRC® MSX® is the platform that runs the integrated system day to day.
View readiness guide →From gap assessment to a certificate you keep.
Most certification projects stall for the same reason: the evidence lives in shared drives, inboxes and spreadsheets, and nobody can see which clauses are actually covered. Readiness is quicker when every clause, gap, action and record sits in one place.
Set the scope and context
Define which sites, activities and products the management system covers, who the interested parties are, and which legal and other requirements apply. Clause 4 of every ISO management system standard starts here.
Run the gap assessment
Test each clause, and for ISO/IEC 27001 each Annex A control, against what you do today. Record a status, the evidence that supports it and an owner for every gap.
Close the gaps with evidence
Turn gaps into actions with due dates. Link documents, records, risk assessments and training to the clause they satisfy, so the evidence is ready before the auditor asks.
Audit and review internally
Complete at least one internal audit cycle and a management review. Certification bodies expect to see both, with findings closed out.
Certify, then keep it
An accredited certification body runs a Stage 1 document review and a Stage 2 audit. Certificates run on a three-year cycle with surveillance audits in between, so the system has to keep working after the certificate arrives.
Each standard, and the law it sits beside.
An ISO certificate shows that a management system works. In South Africa it sits beside legislation that auditors, inspectors and customers also test, so readiness should cover both.
Running more than one standard? The PAS 99 integrated management system guide shows how to run them as one system. For data protection, PAIA and King V obligations, see regulatory compliance.
Common questions.
Who can certify us to an ISO standard in South Africa?
A certification body accredited by SANAS (the South African National Accreditation System) or by another accreditation body that is a member of the IAF. Check that the body is accredited for the specific standard and scope you need, because a certificate from an unaccredited body carries little weight with customers or regulators.
Can we manage several ISO standards in one system?
Yes. ISO management system standards share the same Harmonized Structure (clauses 4 to 10), so one set of processes for context, leadership, planning, support, operation, evaluation and improvement can serve ISO 9001, 14001, 45001 and 27001 at once. PAS 99 describes how to integrate them. See the PAS 99 integrated management system guide.
Does ISO certification prove we comply with the law?
No. ISO 14001 and ISO 45001 require you to identify your compliance obligations and evaluate whether you meet them, but the certificate is not a legal ruling. Legal compliance with Acts such as NEMA or the OHS Act is still tested against the Act itself, which is why the obligations register matters as much as the clause checklist.
Is ISO 31000 a certifiable standard?
No. ISO 31000 provides principles and guidelines for risk management, so organisations align to it rather than certify against it. It is widely used to structure enterprise risk management and to show boards that risk is managed with a recognised method.
Which XGRC® solution supports which standard?
MSX® supports ISO 9001, ISO 22000 and integrated management systems, ENVIRX® supports ISO 14001, SHEQX® supports ISO 45001, MSXCyber® supports ISO/IEC 27001 and Enterprise Risk Management supports ISO 31000. They all run on the same XGRC® platform, so evidence, actions and audits are shared across standards.
See your ISO readiness in one view.
We will walk you through a gap assessment for the standard you are working towards, using your own scope.
Book a demo