Below you can find some of the most frequently asked questions about Critical Path and our services.
Critical Path provides tailored consultancy across ISO standards and compliance, environmental and ESG, health and safety, HR advisory, and project management and controls. We also support the implementation of integrated management systems covering ISO 9001, ISO 14001 and ISO 45001.
Our ISO consultancy services include gap analysis, bespoke documentation, management-system implementation, internal auditing, mock audits, training, corrective-action support and ongoing compliance advice.
Every engagement is tailored around the client’s organisation, operations and objectives. We do not simply issue a generic document pack and leave the client to implement it.
Our consultants take the time to understand how your business works before developing practical policies, procedures and management systems. You can choose remote or onsite delivery, pay-as-you-go consultancy, a defined implementation package or ongoing support.
Remote consultancy can normally begin soon after your requirements and scope have been agreed. Where an onsite visit is required, we aim to arrange it within 30 days of receiving a signed agreement, subject to consultant availability and location.
If you have an urgent tender, certification deadline or compliance concern, let us know during your initial consultation and we will explain what can realistically be achieved.
Yes. You can book a free 30-minute consultation with one of our friendly consultants. It is an informal, no-obligation conversation where we learn about your organisation, answer your initial questions and help you understand the most suitable next step.
There is nothing formal to prepare, although it can be helpful to know which standard or compliance area you are considering and whether you already have any systems or documentation in place.
Yes. Critical Path provides both remote and onsite consultancy. Some activities, including document reviews, online training and ongoing advisory support, can be delivered efficiently remotely. Site audits, operational reviews and certain risk assessments may benefit from an onsite visit.
We can also provide a blended approach, combining remote consultancy with targeted onsite support.
ISO 9001 is the internationally recognised standard for Quality Management Systems. It provides a structured framework for managing processes, meeting customer requirements, controlling risks and continually improving organisational performance.
The standard can help an organisation make its operations more consistent, improve accountability and demonstrate a commitment to quality.
A Quality Management System, commonly called a QMS, is the collection of processes, responsibilities, policies and records an organisation uses to manage quality.
A well designed QMS should reflect how the business actually operates. It should help employees understand responsibilities, maintain consistency, resolve problems and identify opportunities for improvement.
Yes. Within our Resource Hub, you can download free individual templates or purchase complete ISO 9001 document packs. Some resources are generic, editable documents that you can tailor to suit your organisation, while others provide a useful starting point for developing your Quality Management System.
If you need additional help, you can schedule time with one of our consultants. We can help you adapt the templates, develop bespoke ISO 9001 documents and ensure your management system reflects how your organisation operates in practice.
We begin by understanding your organisation and reviewing the quality processes and documents already in place. We then identify any gaps and agree a practical ISO 9001 implementation plan.
Support can include gap analysis, bespoke QMS documentation, process mapping, procedures, staff training, internal auditing, management reviews, mock audits and preparation for independent certification. Consultancy is available remotely, onsite or through flexible pay-as-you-go support.
ISO 14001 is the internationally recognised standard for Environmental Management Systems. It helps organisations identify environmental impacts, understand compliance obligations, control environmental risks and continually improve environmental performance.
Implementing ISO 14001 can support waste reduction, resource efficiency, legal compliance, carbon management and more sustainable business practices. It can also strengthen tender applications and demonstrate environmental responsibility to clients, suppliers and stakeholders.
An environmental aspect is an activity, product or service that can interact with the environment. The environmental impact is the resulting change to the environment.
Examples include:
- Fuel use and greenhouse-gas emissions
- Material consumption and resource depletion
- Waste generation and disposal
- Water consumption
- Noise, dust or air pollution
- Use of chemicals
- Supplier and transport impacts
An ISO 14001 aspects and impacts register helps an organisation evaluate these issues, identify significant impacts and establish suitable operational controls.
Yes. Our Resource Hub provides free environmental templates and paid ISO 14001 document packs. These editable resources can be used as a starting point when developing an Environmental Management System.
Documents must be adapted to reflect your organisation’s environmental aspects, compliance obligations, activities and operational controls. If you need help, a Critical Path ISO 14001 consultant can tailor the templates and develop bespoke EMS documents around your organisation.
Critical Path provides flexible ISO 14001 consultancy for organisations starting from scratch or improving an existing Environmental Management System.
Support can include an ISO 14001 gap analysis, aspects and impacts assessment, compliance evaluation, environmental objectives, bespoke documentation, employee training, internal auditing, management-review support and a mock audit. The final certification audit is completed independently by your chosen certification body.
ISO 22301 is the international standard for Business Continuity Management Systems. It helps organisations prepare for disruptive incidents, protect critical operations and recover services within planned timescales.
ISO 22301 certification can demonstrate that an organisation has established structured business continuity arrangements and regularly reviews, tests and improves its ability to respond to disruption.
A business impact analysis identifies an organisation’s critical activities and assesses what would happen if they were disrupted. It considers operational, financial, contractual, regulatory and reputational consequences.
The analysis helps establish:
- Critical products and services
- Dependencies and essential resources
- Maximum tolerable periods of disruption
- Recovery time objectives
- Recovery priorities
- Minimum operating requirements
A robust business impact analysis provides the foundation for an effective ISO 22301 Business Continuity Management System.
A business continuity plan should address disruptions relevant to the organisation rather than relying on a generic list of emergencies.
Potential scenarios can include cyberattacks, IT outages, utility failures, supply-chain disruption, severe weather, fire, flooding, loss of premises, equipment failure, staff shortages and telecommunications problems. Plans should clearly identify responsibilities, escalation routes, communications and recovery actions.
Critical Path begins by reviewing your operations, existing plans, critical activities and continuity risks. We then help you build a Business Continuity Management System tailored to your organisation.
ISO 22301 consultancy can include gap analysis, business impact analysis, continuity risk assessment, recovery strategies, incident-response procedures, business continuity plans, testing exercises, internal audits, management reviews and certification preparation.
ISO/IEC 27001 is the international standard for Information Security Management Systems. It provides a structured framework for protecting the confidentiality, integrity and availability of information.
ISO 27001 can benefit any organisation handling sensitive or business-critical information, including technology companies, professional services, healthcare providers, recruitment businesses, financial organisations and outsourced service providers. Certification is also increasingly requested in tenders and supplier-assurance processes.
Cybersecurity usually focuses on protecting systems, devices and networks from digital threats. ISO 27001 takes a broader risk-based approach covering people, processes, physical security, suppliers, information, systems and technology.
An Information Security Management System may address areas such as access control, remote working, employee responsibilities, incident response, asset management, supplier security, backups and business continuity. ISO 27001 helps bring these controls together within one continually improving management framework.
The Statement of Applicability is a key ISO 27001 document that records which information-security controls are applicable to the organisation.
It should explain:
- Which controls have been selected
- Why each control is applicable
- Whether the control has been implemented
- Why any controls have been excluded
The Statement of Applicability must reflect the organisation’s information security risk assessment and risk-treatment decisions rather than being copied from a generic template.
Yes. Critical Path can support the complete development and implementation of an ISO 27001 Information Security Management System.
Our consultancy can include an ISO 27001 gap analysis, information-security risk assessment, ISMS scope, bespoke policies and procedures, Statement of Applicability, risk-treatment plan, training, internal auditing, management reviews, corrective actions and preparation for an independent certification audit.
ISO 45001 is the international standard for Occupational Health and Safety Management Systems. It helps organisations identify hazards, assess workplace risks, meet applicable obligations and prevent work-related injury and ill health.
The standard places strong emphasis on leadership, worker consultation, operational control and continual improvement. ISO 45001 can support safer working practices, clearer responsibilities and more consistent health and safety management.
ISO 45001 provides a structured framework for identifying and managing applicable health and safety obligations. It can help an organisation improve legal registers, responsibilities, risk assessments, operational controls, performance monitoring and compliance evaluations.
However, ISO 45001 certification does not automatically guarantee legal compliance. The organisation must still identify and meet the specific health and safety legislation applicable to its activities, workforce and locations.
Yes. Our Resource Hub includes free health and safety templates and paid Occupational Health and Safety document packs. These editable documents can be used as a starting point for developing an ISO 45001 management system.
Generic templates must be reviewed and adapted to reflect your organisation’s actual hazards, activities, employees, contractors and legal responsibilities. Our consultants can help tailor the documents and complete business-specific risk assessments where required.
Critical Path provides tailored ISO 45001 consultancy remotely and onsite. Support can include gap analysis, health and safety compliance reviews, hazard identification, risk assessments, bespoke OH&S documentation, worker-consultation processes, training, internal audits, management reviews and mock audits.
We help prepare your organisation for certification, while the final ISO 45001 certification audit is completed independently by your chosen certification body.
ISO 50001 is the international standard for Energy Management Systems. It provides a structured framework for measuring energy use, identifying improvement opportunities and continually improving energy performance.
An ISO 50001 Energy Management System can help organisations reduce unnecessary energy consumption, control operating costs, improve efficiency and support carbon-reduction objectives.
An energy review examines how energy is purchased, consumed and managed across the organisation. It uses available data to identify energy sources, consumption patterns, significant energy uses and opportunities to improve performance.
The findings are used to develop energy baselines, energy performance indicators, objectives and action plans. The review should be updated as facilities, equipment, processes and energy use change.
An energy baseline provides a reference point against which future energy performance can be compared. Energy performance indicators, often called EnPIs, are measures used to monitor energy efficiency, consumption or use.
Suitable indicators depend on the organisation. They may include energy consumed per product manufactured, per square metre, per operating hour or per service delivered. Meaningful indicators help distinguish genuine improvement from changes caused by production levels, weather or other variables.
A Critical Path ISO 50001 consultant can review your existing energy arrangements, identify gaps and help develop a practical Energy Management System.
Support can include energy reviews, significant energy-use assessments, baselines, EnPIs, energy objectives, bespoke documentation, operational controls, monitoring arrangements, internal auditing, management reviews, mock audits and preparation for independent ISO 50001 certification.
Critical Path provides practical health and safety consultancy for SMEs and larger organisations. Our support is tailored to the workplace, activities, workforce and level of risk.
Services can include health and safety compliance reviews, workplace inspections, onsite risk assessments, policies and procedures, accident and incident processes, ongoing advisory support and managed health and safety systems. Remote and onsite options are available.
Employers must assess risks to employees and other people who may be affected by their work. Risk assessments should be suitable and sufficient, reflect actual workplace activities and identify appropriate control measures.
They should also be reviewed when:
- Work activities or equipment change
- New hazards are introduced
- An accident or near miss occurs
- Relevant legislation changes
- There is reason to believe the assessment is no longer valid
Where an employer has five or more employees, significant findings must be recorded.
Yes. We can review your current health and safety documentation to identify missing, outdated or generic content.
Depending on your requirements, we can develop tailored policies, procedures, responsibilities, risk assessments and supporting records. Our aim is to create clear health and safety documents that employees can understand and apply in practice—not paperwork that simply sits unused.
Yes. Critical Path offers flexible ongoing health and safety support for organisations that do not require a full-time internal advisor.
Support can include telephone and email guidance, document updates, annual reviews, onsite audits, risk assessments and help responding to workplace concerns. Businesses can choose pay-as-you-go consultancy or a structured support package.
Scope 1 emissions are direct greenhouse-gas emissions from sources owned or controlled by the organisation, such as company vehicles, boilers or industrial processes.
Scope 2 covers indirect emissions associated with purchased electricity, heating, cooling or steam. Scope 3 covers other indirect value-chain emissions, including purchased goods, business travel, employee commuting, transport, waste and use of sold products where relevant.
Measuring Scope 1, 2 and material Scope 3 emissions helps create a more complete organisational carbon footprint.
A credible carbon reduction plan should begin with a reliable emissions baseline and clearly defined reporting boundary. It should identify significant emissions sources, establish measurable targets and set out practical actions, responsibilities and timescales.
Actions may include improving energy efficiency, changing transport arrangements, purchasing renewable energy, reducing waste, engaging suppliers and selecting lower-impact materials. Progress should be measured and reported consistently.
Sustainable procurement introduces environmental, social and governance considerations into purchasing and supplier-management decisions.
It can help organisations:
- Understand supplier environmental performance
- Improve Scope 3 emissions data
- Select lower-impact products and materials
- Reduce waste and unnecessary consumption
- Include sustainability requirements in contracts
- Engage suppliers in carbon reduction
- Strengthen environmental supply-chain resilience
The approach should be proportionate to the organisation’s purchasing influence and most significant impacts.
Critical Path’s environmental and ESG consultancy follows five connected stages: Measure, Analyse, Reduce, Validate and Report.
Our support can include organisational carbon footprints, Scope 1, 2 and 3 emissions, lifecycle assessments, Environmental Product Declarations, sustainable procurement, strategy and governance, carbon reduction planning, carbon neutrality and environmental reporting. Each service is tailored to the organisation’s objectives, data, stakeholders and reporting requirements.