AVEN

Make standards operational

We translate requirements into management questions and evidence needs without reproducing copyrighted standard text.

Updated October 2026

From requirements to working evidence

AVEN helps teams identify applicable requirements, build a workable system, operate it and demonstrate real evidence. One management foundation can serve several standards when shared and specialist controls are clear. This is our interpretation, not a substitute for licensed standards.

01

Which standard should I start with?

Start with the business question, then confirm the applicable scope.

NeedStarting point
Customers require consistent qualityISO 9001
Data, IT or partners ask about securityISO/IEC 27001
Food safety across the supply chainISO 22000 / HACCP
Food partners require the FSSC schemeFSSC 22000
Environment, exports or ESG requestsISO 14001
Occupational health and safetyISO 45001
Develop or use automated decision systemsISO/IEC 42001
Energy performanceISO 50001 · contact us

02

Work to do and evidence to retain

Open a card to connect requirements to work and records.

ISO 9001Customers require consistent quality

ISO 9001:2026; transition 2015 certificates by 30 Sep 2029.

For: Organizations controlling customer commitments, processes and outputs.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Separate risks from opportunities by process; consider climate context when relevant.
  4. Build role competence and control usable information.
  5. Agree acceptance criteria, handoffs and handling of nonconforming outputs.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: Scope, process map, customer requirements, inspection results, feedback and corrective actions.

Common mistake: Polished procedures without samples from actual work.

Edition / change: The 2026 edition emphasizes quality culture and ethical conduct; revisit risk and opportunity management and the 2024 climate amendment.

ISO/IEC 27001Data, IT or partners ask about security

ISO/IEC 27001:2022 + Amd 1:2024.

For: Teams handling important information or customer data.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Map assets, threats, risks and risk owners.
  4. Build role competence and control usable information.
  5. Select risk-based controls, maintain a Statement of Applicability and test control operation.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: ISMS scope, risk assessment, Statement of Applicability, access logs, incidents and recovery tests.

Common mistake: Copying a control list without showing the organization’s own risks.

Edition / change: Use the 2022 edition with the 2024 climate amendment; check implications for context and interested parties.

ISO 22000Food safety across the supply chain

ISO 22000:2018 is under review.

For: Organizations at any point in the food chain.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Identify hazards, inputs, handoffs and responsibilities across the food chain.
  4. Build role competence and control usable information.
  5. Design PRPs and hazard-control/HACCP plans; obtain food-safety specialist validation.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: Hazard analysis, PRP records, control monitoring, traceability and recall drills.

Common mistake: Using a generic HACCP plan without checking product, process and applicable law.

Edition / change: The 2018 edition is under review; draft changes are not published requirements.

FSSC 22000Food partners require the FSSC scheme

Version 7 applies from 1 May 2027.

For: Food businesses whose market or customers request FSSC.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Identify scheme scope, product categories and supply-chain demands.
  4. Build role competence and control usable information.
  5. Combine ISO 22000, sector PRPs and additional FSSC requirements; obtain specialist validation.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: PRP records, hazard analysis, traceability, supplier approval and internal audits.

Common mistake: Assuming ISO 22000 alone covers the FSSC scheme.

Edition / change: Plan the move to v7 against the FSSC scheme documents and the applicable scope.

ISO 14001Environment, exports or ESG requests

ISO 14001:2026; transition by 30 Apr 2029.

For: Organizations managing environmental impacts by activity and site.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Identify environmental aspects, compliance obligations and emergencies; obtain specialist validation.
  4. Build role competence and control usable information.
  5. Control significant-impact activities and relevant contractors.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: Aspect and obligation registers, relevant monitoring, response drills and corrective actions.

Common mistake: Keeping a policy but no evidence of control at the worksite.

Edition / change: The 2026 edition is published; map changes from the 2015 system, including climate context.

ISO 45001Occupational health and safety

Current ISO 45001; the revision remains a draft.

For: Workplaces with operational, contractor or working-condition risks.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Identify hazards, duties and worker participation; obtain safety specialist validation.
  4. Build role competence and control usable information.
  5. Prioritize hazard elimination, work controls and emergency preparedness.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: Hazard assessments, worker consultation, training, inspections and incident investigations.

Common mistake: Counting accidents while missing risks that have not caused incidents.

Edition / change: Track the draft revision without treating unpublished text as an obligation.

ISO/IEC 42001Develop or use automated decision systems

ISO/IEC 42001:2023.

For: Organizations governing automated systems, impacts and accountability.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Inventory automated systems, intended uses and lifecycle risks.
  4. Build role competence and control usable information.
  5. Control data, human approval, output monitoring and incident handling.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: System inventory, impact assessments, approvals, tests, monitoring and incidents.

Common mistake: Publishing a policy without knowing deployments and decision owners.

Edition / change: Use the 2023 edition and assess 2024 climate context where relevant.

ISO 50001Energy performance

Contact us to confirm the applicable edition and scope.

For: Organizations seeking measured control of energy use.

Seven core tasks

  1. Confirm scope, context and interested parties.
  2. Leadership assigns ownership and resources.
  3. Identify significant energy uses, influencing variables and owners.
  4. Build role competence and control usable information.
  5. Set baselines, performance indicators and improvements that can be remeasured.
  6. Measure outcomes, conduct independent internal audits and management review.
  7. Address causes of deviations and verify improvement effectiveness.

Evidence: Consumption data, baseline, indicators, action plans and verification results.

Common mistake: Claiming savings without a baseline and comparable measurements.

Edition / change: Confirm the edition and energy specialist needs during discovery.

03

A seven-step roadmap

Time ranges are illustrative for a small-to-medium, single-site scope. Multiple sites, shifts or missing records require a separate schedule. They are not certification deadlines.

  1. Discovery & GAP

    1–3 weeks · illustrative

    AVEN: Platform organizes scope and evidence samples; specialist reviews the gaps.

    Your team: Confirm scope, provide records and appoint process owners.

  2. System design

    2–6 weeks · illustrative

    AVEN: Map processes, controls, owners and approved templates.

    Your team: Approve decisions and specialist controls.

  3. Operation & records

    4–12 weeks · illustrative

    AVEN: Guide work and flag missing evidence without inventing records.

    Your team: Perform real work and keep dated records.

  4. Internal audit

    1–3 weeks · illustrative

    AVEN: Prepare an independent sampling plan and track findings.

    Your team: Provide auditors and address actual findings.

  5. Management review

    1–2 weeks · illustrative

    AVEN: Assemble inputs and decisions with clear sources.

    Your team: Leadership holds and records the review.

  6. Certification readiness

    1–3 weeks · illustrative

    AVEN: Check unresolved gaps and help coordinate with the chosen body.

    Your team: Choose an independent certification body and own the audit.

  7. Annual maintenance

    Ongoing · illustrative

    AVEN: Track actions, versions and review cycles.

    Your team: Operate controls, refresh evidence and follow up.

05

One system, several requirements

Use fewer systems to demonstrate more requirements. One internal-audit calendar and document-control process can serve 9001, 14001, 45001 and 27001; sampling still covers each standard’s specific risks.

Document control

One place for versions, access and approvals; classify records by applicable requirement.

Competence

One role matrix, with specialist evidence for safety, environment and security.

Audit & improvement

One audit and action cycle; findings still identify standard, process and source.

05

Traceable edition transitions

ISO 9001:2026

Published 16 Sep 2026. From 31 Mar 2028, new certificates use the 2026 edition; 2015 certificates cease to be valid after 30 Sep 2029.

Map old to new clauses, check quality culture, ethics, risks/opportunities and operating records; produce a transition GAP report.

Transition source

ISO 14001:2026

Published Apr 2026. Transition 2015 certificates by 30 Apr 2029; from 31 Oct 2027 new certificates use the 2026 edition.

Map clauses, review environmental aspects, obligations and measurements; qualified specialists validate technical content.

Transition source

The 2024 climate amendment is assessed against context and interested parties; it does not automatically create the same new obligation for every organization. ISO/IAF

FAQ

Frequently asked questions

How long does implementation take?

It depends on scope, existing controls, people and the amount of real operating evidence. Discovery produces a schedule; reference ranges on this page are not a promise.

How many people do we need?

Name an internal coordinator and real process owners. The number depends on sites, shifts and scope; one person cannot replace operational ownership.

Does the platform issue ISO certificates?

No. Independent certification bodies conduct certification audits and make certification decisions.

Must a consultant stay for the whole project?

No. Your team owns decisions and work. Platform guidance and specialist reviews can be used where they add value.

Where is our information kept?

Project records belong in the authorized workspace with role-based access. Confirm hosting, retention and export terms before uploading sensitive material.

We have ISO 9001. How do we add ISO/IEC 27001?

Reuse document control, competence, audit and review processes. Add an ISMS scope, information-risk method, Statement of Applicability and security evidence.

Can one system cover several standards?

Yes, shared controls can serve multiple requirements; each standard still needs its own specialist controls and evidence.

07

Start with your scope

Choose a useful next step; confirm plan and resources after discovery.

We provide consulting and training; certification decisions are made independently by certification bodies.