Step-by-step implementation guides for ISO certification, GxP compliance, cyber security, AI governance, business continuity and more. Written by practitioners with 20+ years of sector experience. Free, instant access.
Showing 17 guides
Guide
ISO 22301 Business Continuity Certification: A Practical Guide
Step-by-step guide to ISO 22301 certification — BIA, risk assessment, plan development, audit preparation and what auditors actually assess.
GCC Cyber Compliance: Qatar, Saudi, UAE, Bahrain, Oman and Kuwait
Practical guide to navigating GCC cyber security regulatory frameworks across all six GCC member states for technology organisations and critical infrastructure operators.
Outsourced Quality Management: When to Use It and How to Structure It
When outsourced quality management delivers value, when it does not, and how to structure an effective engagement with specific scope and authority boundaries.
ISO 42001 vs EU AI Act: Understanding the Difference
Practical guide to building an integrated ISO 42001 and EU AI Act compliance programme — what each requires, where they overlap, and the six-step integration approach.
Counterfeit Part Prevention in the Aerospace Supply Chain
AS5553 and AS6081 implementation guide — approved supplier list development, incoming inspection, suspect part reporting and what prime contractors require.
Carrier Qualification and Third-Party Logistics Compliance
Risk tiering of carrier relationships, qualification criteria, performance monitoring, GDP requirements and ISO 9001 Clause 8.4 compliance for logistics organisations.
Transport & LogisticsISO 9001Carrier Qualification
Integrating ISO 9001, ISO 14001 and ISO 45001 into a single management system — benefits, implementation approach and how IMS certification differs from individual audits.
IMS implementation for manufacturers — integrating ISO 9001, ISO 14001 and ISO 45001, managing sector-specific extensions (IATF 16949, ISO 13485), and audit programme design.
Operational Resilience for Financial Services: What Regulators Expect
FCA and PRA operational resilience policy — important business service mapping, impact tolerances, scenario testing and annual self-assessment requirements.
Understanding OEM Customer-Specific Requirements in IATF 16949
What CSRs are, which OEMs have them, how to identify your obligations, and how to integrate them into your quality management system before the certification audit.
EU AI Act: What Technology Companies Must Do Before August 2026
Risk classification, high-risk AI obligations, GPAI model requirements, conformity assessment, CE marking, EU database registration and the August 2026 deadline.
Multi-Cloud Security Governance: A Practical Framework
Shared responsibility models, IAM across providers, Cloud Security Posture Management, data governance and ISO 27001 alignment for AWS, Azure and GCP environments.