ISO Compliance

ISO readiness, gap assessment and certification support in one platform.

XGRC® supports readiness and gap assessment across the ISO standards that matter most for quality, safety, environmental, information security and risk management. The same platform carries you from the first gap assessment to certification, and keeps the system working through every surveillance audit after it.

ISO Readiness

ISO 27001 Readiness

XGRC® MSXCyber® gives organisations a structured way to assess ISO 27001 readiness, close control gaps, and manage the information security management system on an ongoing basis — not just in the weeks before an audit.

View readiness guide →
ISO Readiness

ISO 9001 Readiness

XGRC® MSX® gives organisations a structured way to assess ISO 9001 readiness, close quality management gaps, and run the QMS as a living system — not a folder of documents produced for the auditor.

View readiness guide →
ISO Readiness

ISO 14001 Readiness

ENVIRX® by XGRC® gives organisations a structured way to assess ISO 14001 readiness, close environmental management gaps, and monitor compliance obligations continuously — not reconstruct evidence for the auditor.

View readiness guide →
ISO Readiness

ISO 45001 Readiness

SHEQX® by XGRC® gives organisations a structured way to assess ISO 45001 readiness, close OH&S management gaps, and run hazard identification, incident management and contractor safety as one connected system.

View readiness guide →
ISO Readiness

ISO 22000 Readiness

XGRC® MSX® gives food businesses a structured way to assess ISO 22000 readiness, close food safety management gaps, and keep prerequisite programmes, HACCP plans and traceability audit-ready every day.

View readiness guide →
ISO Readiness

ISO 31000 Risk Management

ISO 31000 is a guideline for managing risk, not a certifiable management system — there is no audit to pass. XGRC® helps organisations adopt and embed the ISO 31000 risk management process, from establishing context through risk assessment, treatment, and ongoing monitoring and review.

View readiness guide →
ISO Readiness

PAS 99 / Integrated Management System

PAS 99 is BSI's specification for integrating two or more management system standards — ISO 9001, ISO 14001, ISO 45001, ISO 22000 — into one common framework instead of running each in its own silo. This checklist covers what PAS 99 integration actually requires, and XGRC® MSX® is the platform that runs the integrated system day to day.

View readiness guide →
How readiness works

From gap assessment to a certificate you keep.

Most certification projects stall for the same reason: the evidence lives in shared drives, inboxes and spreadsheets, and nobody can see which clauses are actually covered. Readiness is quicker when every clause, gap, action and record sits in one place.

  1. Set the scope and context

    Define which sites, activities and products the management system covers, who the interested parties are, and which legal and other requirements apply. Clause 4 of every ISO management system standard starts here.

  2. Run the gap assessment

    Test each clause, and for ISO/IEC 27001 each Annex A control, against what you do today. Record a status, the evidence that supports it and an owner for every gap.

  3. Close the gaps with evidence

    Turn gaps into actions with due dates. Link documents, records, risk assessments and training to the clause they satisfy, so the evidence is ready before the auditor asks.

  4. Audit and review internally

    Complete at least one internal audit cycle and a management review. Certification bodies expect to see both, with findings closed out.

  5. Certify, then keep it

    An accredited certification body runs a Stage 1 document review and a Stage 2 audit. Certificates run on a three-year cycle with surveillance audits in between, so the system has to keep working after the certificate arrives.

South African context

Each standard, and the law it sits beside.

An ISO certificate shows that a management system works. In South Africa it sits beside legislation that auditors, inspectors and customers also test, so readiness should cover both.

StandardWhat it coversSouth African linkSupported by
ISO 9001 Quality management Customer, contract and product requirements; SABS publishes it locally as a SANS standard. MSX®
ISO 14001 Environmental management Compliance obligations under NEMA (Act 107 of 1998), the National Water Act (Act 36 of 1998) and NEM:AQA (Act 39 of 2004). ENVIRX®
ISO 45001 Occupational health and safety Supports, but does not replace, the OHS Act (Act 85 of 1993) and, on mines, the MHSA (Act 29 of 1996). SHEQX®
ISO/IEC 27001 Information security Evidence for the security safeguards POPIA section 19 requires for personal information. MSXCyber®
ISO 22000 Food safety Sits alongside the R638 hygiene regulations under the Foodstuffs, Cosmetics and Disinfectants Act (Act 54 of 1972). MSX®
ISO 31000 Risk management guidelines Not certifiable. It gives King IV and King V risk governance a recognised method. Enterprise Risk Management

Running more than one standard? The PAS 99 integrated management system guide shows how to run them as one system. For data protection, PAIA and King V obligations, see regulatory compliance.

Frequently asked

Common questions.

Who can certify us to an ISO standard in South Africa?

A certification body accredited by SANAS (the South African National Accreditation System) or by another accreditation body that is a member of the IAF. Check that the body is accredited for the specific standard and scope you need, because a certificate from an unaccredited body carries little weight with customers or regulators.

Can we manage several ISO standards in one system?

Yes. ISO management system standards share the same Harmonized Structure (clauses 4 to 10), so one set of processes for context, leadership, planning, support, operation, evaluation and improvement can serve ISO 9001, 14001, 45001 and 27001 at once. PAS 99 describes how to integrate them. See the PAS 99 integrated management system guide.

Does ISO certification prove we comply with the law?

No. ISO 14001 and ISO 45001 require you to identify your compliance obligations and evaluate whether you meet them, but the certificate is not a legal ruling. Legal compliance with Acts such as NEMA or the OHS Act is still tested against the Act itself, which is why the obligations register matters as much as the clause checklist.

Is ISO 31000 a certifiable standard?

No. ISO 31000 provides principles and guidelines for risk management, so organisations align to it rather than certify against it. It is widely used to structure enterprise risk management and to show boards that risk is managed with a recognised method.

Which XGRC® solution supports which standard?

MSX® supports ISO 9001, ISO 22000 and integrated management systems, ENVIRX® supports ISO 14001, SHEQX® supports ISO 45001, MSXCyber® supports ISO/IEC 27001 and Enterprise Risk Management supports ISO 31000. They all run on the same XGRC® platform, so evidence, actions and audits are shared across standards.

See your ISO readiness in one view.

We will walk you through a gap assessment for the standard you are working towards, using your own scope.

Book a demo