Region
UK
Sector
Professional Services
Service
ISO Standards & Compliance
Clarity Outsourcing Group is a professional outsourcing business that became an independent organisation following its seperation from a parent company. As part of the transition, the business needed to establish its own operational controls, compliance processes and internationally recognised certifications under the Clarity Outsourcing Group name.
With no standalone ISO management systems in place, Clarity appointed Critical Path to deliver a complete, ground up implementation of both an ISO 9001 Quality Management System and an ISO 27001 Information Security Management System.
The project required more than the preparation of ISO documentation. Clarity Outsourcing Group needed fully functioning management systems that reflected its new organisational structure, outsourcing activities, supply chain responsibilities, information security risks and day to day business processes.
Critical Path supported the business throughout the complete ISO certification journey, taking Clarity from an initial zero state position to successful certification through PJR Certification UK, who are a UKAS accredited certification body, within six months.
Critical Path delivered a full start-to-finish ISO consultancy programme covering the design, implementation and preparation of two integrated management systems.
We began with a comprehensive business compliance review to understand Clarity Outsourcing Group’s new operating model, responsibilities, existing processes and areas of risk. This allowed our consultants to create a practical implementation plan covering both quality management and information security compliance.
Our team completed a full ground-up build of the ISO 9001 Quality Management System and ISO 27001 Information Security Management System. Policies, procedures, registers, controls and supporting documentation were developed around the organisation’s actual activities rather than relying on generic ISO templates.
Working closely with ITG, Clarity Outsourcing Group’s external IT provider, we aligned the Information Security Management System with the organisation’s technical infrastructure and cyber security arrangements. This integrated approach helped ensure that documented controls, IT processes, access arrangements, data security measures and operational responsibilities formed one rounded and consistent management framework.
Critical Path also completed supply chain Data Protection Impact Assessments, helping Clarity Outsourcing Group assess how personal data was handled across supplier and outsourced service relationships. These reviews supported stronger GDPR compliance, information security risk management and third-party due diligence.
To prepare the business for external certification, we delivered ISO training, conducted internal audits and hosted the formal management review meetings required by both standards. Findings and improvement actions were managed through to completion before Clarity Outsourcing Group progressed to its independent certification audits.
Through the full Critical Path ISO consultancy process, Clarity Outsourcing Group achieved certification to both ISO 9001 and ISO 27001 within six months.