A certificate is issued once. Keeping it means checks at every facility, records that are current, trained people, contractors under control and evidence ready for an auditor who can turn up at any site. Most organisations have nobody whose whole job that is. We take it on.
ESGweise runs certified ISO management systems for multi-site organisations in the UAE and wider GCC as a managed service on a monthly retainer. We cover ISO 45001, ISO 14001, ISO 9001 and ISO 50001, singly or integrated: monthly site checks, legal and risk registers, document control, training and competence records, contractor controls, performance dashboards, impartial internal audit, and preparation and representation at certification audits.
Why systems slip between audits
A management system is not owned by one department. It runs through HR, procurement, facilities, risk and operations, at every site, on a calendar nobody is paid to keep.
Competence and training records sit with HR. Contractor and supplier controls sit with procurement. Risk registers sit with risk, site checks with facilities, and the legal register with whoever last had time. Each piece has its own cadence: monthly checks, quarterly updates, an annual review. Multiply that by every site and every standard held, and the system that was audit-ready on the day of certification drifts a little every month until the next surveillance visit finds it.
On a multi-site certificate the exposure is wider. Under IAF MD 1:2023 the certification body audits the central function every time and picks a sample of sites itself. Every site has to be ready, not just the one you would have chosen.
Every moving part, on one calendar
Site checks
Monthly inspections at every site against the controls each standard requires, from fire safety and emergency preparedness to waste, energy use and equipment. Sites submit them with photographs on a common checklist; we review and issue the actions.
People and training
Training matrix and competence records for every site, inductions for new joiners, refreshers tracked against expiry, and an annual awareness programme. For safety systems, fire wardens and first aiders appointed and kept current by floor and shift.
Contractors and procurement
Contractor prequalification, site rules and induction, and supplier evaluation against the system's requirements, so the controls reach the people doing work on your premises and not only your own staff.
Risk and legal compliance
Risk, hazard and aspect registers reviewed on a schedule and whenever something changes. A legal register for each country and, where it applies, each emirate, with an annual evaluation of compliance.
Documentation on cadence
Document control under your framework, updates when regulation or the organisation changes, and a single evidence repository organised by clause, so any audit question has an answer in minutes.
Performance and reporting
A monthly dashboard for every site: checks done, training completion, incidents and near misses, open actions and legal compliance. Monthly calls with site leads, a quarterly pack for executive management, and the inputs to the annual management review.
The audit cycle
An annual internal audit of every site by an ESGweise auditor who takes no part in running the system, which keeps it impartial. Readiness reviews before each surveillance and recertification visit, representation at the audit, and every finding closed with root cause and evidence.
Assess, fix, then keep it running
Gap check at every site
A visit to each site against your framework, the standard and the local requirements, with a gap report per site and one consolidated plan. Your framework governs: we run it, we do not replace it.
Close the gaps
Implementation on site with your facilities teams. One toolkit of checklists, registers and report formats is built once and used at every site, so all sites run the same way and report in the same format.
Monthly retainer
Starts as each site is implemented. Remote by default through the monthly evidence cycle, with visits where the work has to be done on site. One fee, one team, one calendar across every site.
The year at a glance
- Monthly: site checks, incident and action log review, site dashboard, calls with site leads, awareness topic
- Quarterly: register and contact list updates, legal register update, joint site walk, executive pack
- Twice a year: emergency drills at every site, where the system requires them
- Annually: risk assessment review, compliance evaluation, internal audit, management review, refresher training
- Each external audit: readiness review, representation, findings closure
What stays with you
Accountability for the system stays with your top management, because the standards require it and no certification body will accept anything else. Your site teams carry out the site actions using our checklists, and your certification body issues the certificate. We design, schedule, check, train, audit, report and represent. That division is what lets a small central team, or none at all, hold a certificate across many locations.
- ISO 45001 occupational health and safety
- ISO 14001 environmental management
- ISO 9001 quality management
- ISO 50001 energy management
Related: ISO implementation builds a system from scratch, certification support takes it through the first external audit, internal audit is available on its own, and HSE systems covers safety and environmental controls in operational detail.
Managed ISO Systems: questions we hear most
What is a managed ISO management system?
An outsourced arrangement in which an external team runs the day-to-day of a certified management system on the organisation's behalf: the monthly site checks, the registers, document control, training records, contractor controls, performance reporting, internal audit and preparation for the certification body. It is delivered on a monthly retainer rather than as a one-off project, because the work it covers is continuous.
Can we outsource ISO 45001 or ISO 14001 and still keep the certificate?
You can outsource the work, not the accountability. The standards require top management to take overall responsibility for the system, and that cannot be handed to a consultant. What can be handed over is the operation of the system: scheduling, checking, recording, training, auditing and reporting. Certification bodies see this arrangement often, and it is sound as long as the organisation's own management stays visibly in charge.
How do you maintain ISO certification?
By running the system as documented every month, not just before the audit. That means current risk and legal registers, controls checked at every site, training records kept up to date, incidents and nonconformities closed with evidence, an internal audit at planned intervals, and a management review. The certification body then checks at each surveillance audit that all of this is happening. Certificates are rarely lost on a single failure; they are lost when months of routine work turn out to be missing.
Does ISO certification expire?
Yes. Accredited certificates run on a three-year cycle. Under ISO/IEC 17021-1, the standard certification bodies work to, surveillance audits take place at least once every calendar year except the recertification year, and the first must fall within 12 months of the certification decision. A recertification audit before the end of the third year starts a new cycle. Miss a surveillance audit or leave major findings open, and the certificate can be suspended before it expires.
What is the difference between a surveillance audit and a recertification audit?
A surveillance audit is a partial check, held in each year between certification and recertification, that the system is still operating and improving. It samples parts of the scope. A recertification audit is a full review of the whole system against the standard in the third year, and it decides whether the certificate is renewed for another three years.
How does a multi-site certificate get audited?
Under IAF MD 1:2023, the international rules for multi-site certification, the certification body audits the central function at every audit and a sample of the sites, sized from the square root of the number of sites. The certification body chooses the sample, so any site can be the one visited, and every site has to be audit-ready all the time, not just the ones expected that year.
Does this need someone on site at every location?
Not every month. Sites carry out their own checks with a common checklist and submit the results with photographs, and we review them remotely and issue the actions. We visit where the work has to happen on site: the initial gap assessment, implementation, drills, closing findings that need physical verification, and preparing a site before a certification audit.
Which standards can be managed this way?
Any standard built on the harmonised structure, which includes ISO 9001, ISO 14001, ISO 45001 and ISO 50001. Where an organisation holds more than one, they are run as one integrated system with a single calendar, a single evidence repository and one internal audit programme.
Are you a certification body?
No. ESGweise does not issue certificates. We prepare the system and the sites, represent you during the audit and close the findings afterwards. Keeping the consultant and the certification body separate is what the accreditation rules require.
Thirty minutes. We figure out if there's a fit.
We don't pitch on the call. We listen, ask sharp questions, and tell you honestly whether managed iso systems is what you need, or what else might be.
Speak with our team