CONNECTED ISO MANAGEMENT SYSTEM SUPPORT

ISO Standards Support Modules

Operate Several Frameworks Through One Assurance Platform

Zebsoft ISO standards software uses shared platform capabilities and configured support modules to help organisations operate quality, environmental, health and safety, information-security, continuity, AI, medical-device and asset-management systems.

The aim is not to build another isolated application for every standard. It is to connect requirements, risks, controls, responsibilities, workflows, evidence and human assurance while retaining the scope and judgement required for each framework.

ISO standards support modules within the Zebsoft Assurance Platform

WHAT SUPPORT MEANS

Software Supports the Management System—it Does Not Confer Certification

An ISO management-system standard establishes requirements or guidance. The organisation decides how those requirements apply, operates the resulting system and remains responsible for conformity. Where certification is sought, an independent certification body conducts the certification process.

Zebsoft provides the governed information, workflow, evidence and oversight needed to help people operate and demonstrate the system. It does not certify the organisation, replace competent interpretation or guarantee a successful external audit.

The platform can help you

  • Register applicable requirements and their operational context
  • Connect risks, opportunities, controls and responsible owners
  • Control documents, communication, competence and change
  • Operate audits, evaluations, incidents and improvement actions
  • Retain evidence of work, review, decision and exception
  • Prepare traceable information for internal and external assurance

SHARED CAPABILITY—SEPARATE ASSURANCE

One Control Can Support Several Standards Without Blurring Their Requirements

Management-system standards share structural themes, but they are not interchangeable. Zebsoft can reuse approved information and operating evidence while preserving the distinct scope, criteria, specialist judgement, testing and assurance output required for each standard.

Shared ownership

A process owner, site manager or document owner may carry responsibilities relevant to several standards without maintaining duplicate identity and authority records.

Shared control

A controlled supplier review, training workflow or change process may address several requirements while retaining the reasons and mappings relevant to each framework.

Shared evidence

One approved record can support more than one assurance question where it is relevant, reliable and authorised for that use. Reuse does not remove the need for evaluation.

Separate judgement

Quality, safety, environment, security and other specialists remain responsible for determining whether the evidence meets their applicable criteria.

DEFINE—COMMUNICATE—OPERATE—ASSURE

Turn Requirements Into Governed Operation

The standards describe expected management-system outcomes. Zebsoft structures how approved requirements move into accountable work and how evidence returns for human assurance.

Define

Establish applicable requirements, context, risks, controls, objectives, responsibilities, workflow, evidence and decision authority.

Communicate

Make approved information, changes, responsibilities and required actions visible to the relevant employees, suppliers or other parties.

Operate

Complete scheduled, triggered and responsive work through controlled tasks, checks, submissions, reviews, approvals and records.

Assure

Interrogate current information, verify evidence, evaluate performance and retain the accepted outcome, exception or required improvement.

CURRENT POSITION—28 AUGUST 2026

Standards Status Changes—Your Operating System Must Remain Adaptable

A support-module page should not freeze a management system around an obsolete edition. The snapshot below records the present position for the principal standards covered here. Organisations should also confirm transition arrangements with their certification body and relevant sector authorities.

ISO 9001

ISO 9001:2015 with Amendment 1:2024 remains the current requirements edition. ISO/FDIS 9001 is the final draft of the next edition, expected to replace it in September 2026.

ISO 14001

ISO 14001:2026 is the current environmental-management requirements edition. The 2015 edition and its 2024 climate-action amendment have been withdrawn.

ISO 45001

ISO 45001:2018 with Amendment 1:2024 remains current. A revised edition is under development at Draft International Standard stage and is not yet the published replacement.

ISO/IEC 27001

ISO/IEC 27001:2022 with Amendment 1:2024 remains the information-security management-system requirements position covered by the platform.

QUALITY MANAGEMENT SYSTEMS

Quality and Medical-Device Support Modules

Quality requirements extend beyond controlled documents. They depend on processes, responsibility, evidence, nonconformity, change, supplier control, competence and verified improvement.

ISO 9001 quality management

Connect organisational context, processes, risks and opportunities, objectives, documented information, competence, operational control, customer feedback, audit, management review and improvement. The main standards page owns the permanent ISO 9001 intent; the preparation page separately covers transition to the next edition.

ISO 13485 medical-device quality

Apply controlled quality-system capability to the more specific medical-device context, including regulatory requirements, risk-related processes, supplier controls, traceability, validation, complaint handling and retained quality records. ISO 13485:2016 remains the current edition.

ENVIRONMENT AND WORKER SAFETY

Environmental and OH&S Support Modules

Environmental and health-and-safety systems share management-system structure, but their specialist risks, obligations, operational controls, consultation and performance evidence require distinct competent oversight.

ISO 14001 environmental management

Connect environmental aspects and impacts, obligations, objectives, lifecycle considerations, operational controls, emergency response, monitoring, evaluation and improvement through the current ISO 14001:2026 context.

ISO 45001 health and safety

Connect hazards, OH&S risks and opportunities, worker consultation and participation, operational controls, competence, incidents, emergency preparedness, evaluation and improvement. Safety decisions remain with competent and authorised people.

INFORMATION AND AI GOVERNANCE

Information-Security and AI Management Modules

Both standards require governed management systems. Neither permits software or AI output to replace organisational accountability, risk judgement, legal interpretation or competent assurance.

ISO/IEC 27001 information security

Operate the ISMS through information-security risk, control selection, Statement of Applicability decisions, objectives, roles, competence, incidents, audits, review and improvement. Certification and control-effectiveness conclusions remain separate human assurance decisions.

ISO/IEC 42001 AI management

Operate an Artificial Intelligence Management System through AI-system context, policy, roles, risk, impact, lifecycle controls, supplier considerations, monitoring, incidents and improvement. ISO/IEC 42001:2023 is the management-system requirements standard; it is not a substitute for applicable AI law.

RESILIENCE AND ASSET VALUE

Continuity and Asset-Management Support Modules

Resilience and asset management both depend on reliable context, ownership, decisions, operational controls, testing and evidence across extended lifecycles.

ISO 22301 business continuity

Connect business-impact analysis, critical activities, dependencies, continuity strategies, plans, exercises, incidents, lessons and improvement through ISO 22301:2019 and its 2024 climate-action amendment.

ISO 55001 asset management

Connect asset-management objectives, lifecycle risk, decision criteria, asset information, operational control, change, performance and assurance. ISO 55001:2024 supports the strategic asset-management context rather than merely creating a maintenance register.

THE REUSABLE SUPPORT LAYER

Capabilities Used Across the Standards

The configuration changes with the subject, but the underlying governance functions can remain consistent. This is how Zebsoft reduces duplicated administration without pretending that all standards require the same evidence or decisions.

Risk and opportunity

Register context, assessment, ownership, controls, treatment, review and assurance using criteria suitable for the relevant standard and domain.

Documented information

Control authoring, review, approval, access, communication, revision, retention and withdrawal for information that directs or proves work.

Competence and awareness

Define role requirements, communicate responsibilities, request learning or evidence and retain authorised competence decisions and expiry visibility.

Audit and evaluation

Plan, perform and follow through on internal audits, compliance evaluations, inspections and other assurance activity with retained evidence.

Incident and improvement

Connect events, nonconformities, investigation, cause, correction, corrective action, change and effectiveness without losing their source context.

Management oversight

Present objectives, performance, exceptions, overdue decisions and assurance evidence for management review and continuing governance.

THIS IS HOW MULTI-STANDARD CONTROL WORKS

Map Once, Operate Once, Evaluate for Each Applicable Framework

Avoiding duplication does not mean collapsing every requirement into one generic compliance statement. The controlled route preserves the mapping and the separate assurance decisions.

01

Identify

Record the applicable standard requirements, obligations, customer conditions and internal commitments within their approved scope.

02

Map

Relate each requirement to the processes, risks, controls, roles, information, workflows and evidence that address it.

03

Operate

Complete the controlled activity once through accountable workflow rather than maintaining duplicate tasks and records for each standard.

04

Evaluate

Allow each competent function to judge the shared evidence against its own criteria and retain the resulting assurance, gap or exception.

RELATED FRAMEWORK ROUTES

Not Every Governance Requirement Is an ISO Standard

Zebsoft also supports legal, regulatory, contractual and integrated-management contexts. These should be identified accurately rather than presented as ISO certification modules.

UK GDPR and data protection

UK GDPR and the Data Protection Act 2018 are legal requirements, not ISO standards. Zebsoft can support records, DPIAs, rights workflows, supplier oversight, incidents and retained governance evidence.

Integrated management systems

Coordinate shared processes, controls and evidence across several standards while retaining their specific scope, objectives, audit criteria and specialist ownership.

Governance, risk and compliance

Connect obligations, policies, risks, controls, workflows, evidence, exceptions and oversight across ISO and non-ISO responsibilities within the wider assurance system.

PRACTICAL QUESTIONS

ISO Standards Software FAQs

Standards, certification schemes, legislation and transition arrangements change. Confirm the applicable edition, scope and external requirements with competent advisers and your certification body.

What is an ISO support module?

An ISO support module is a configured use of platform capability for a standard-specific management-system context. It can connect requirements to risks, controls, roles, workflows and evidence without becoming a separate isolated application.

Does Zebsoft include copies of ISO standards?

No. ISO standards are copyrighted publications obtained through ISO or authorised national standards bodies. Zebsoft can register and map the requirements your organisation is authorised to use but does not redistribute the standards.

Can one control support several standards?

Yes, where the control genuinely addresses several mapped requirements. The activity and evidence may be shared, but competent people must still evaluate relevance and adequacy for each applicable standard.

Can Zebsoft guarantee ISO certification?

No. Zebsoft supports management-system operation and evidence. The organisation is responsible for conformity, and an independent certification body makes certification decisions where certification is sought.

Can we operate several ISO standards together?

Yes. Shared governance functions can reduce duplication across an integrated management system while standards retain their scope, objectives, risks, controls, audit criteria and specialist assurance.

How are standard revisions handled?

Requirements, mappings, controls, documents, workflows and evidence expectations can be reviewed and changed through controlled configuration. The organisation decides the transition plan and should confirm deadlines with its certification body.

Is GDPR an ISO standard?

No. UK GDPR is legislation supported by the Data Protection Act 2018. It may interact with ISO standards and management systems, but it must not be described as an ISO certification standard.

Does AI decide whether we conform?

No. AI may assist authorised users in interrogating approved information and identifying patterns. It must not invent evidence or make conformity, legal, risk, certification or assurance decisions.

START WITH YOUR ACTUAL FRAMEWORKS

Build the Shared System Without Losing Specialist Control

Bring the standards, certification scopes, sites and existing control structure you need to operate. Zebsoft can demonstrate how shared capability reduces duplication while preserving framework-specific responsibility and evidence.

Explore the standards architecture

A useful demonstration begins with one shared control—such as document change, competence, supplier approval or internal audit—and follows its relevance across the standards in scope.