Compliance gap analysis template (multi-standard)
A multi-standard compliance gap-analysis template — one rubric for ISO 9001, 13485, 27001, 14001, 45001, EU AI Act, GDPR. Severity, evidence, action plan.
- ISO 9001
- ISO 27001
- ISO 13485
- GDPR
Methodology
Articles applying Plan-Do-Check-Act to QMS.
A multi-standard compliance gap-analysis template — one rubric for ISO 9001, 13485, 27001, 14001, 45001, EU AI Act, GDPR. Severity, evidence, action plan.
A practical accessibility gap-analysis template for EN 301 549 and WCAG 2.1 AA — section coverage, evidence, severity ranking, remediation plan.
What to do in the 12, 4, and 1 weeks before a certification or surveillance audit. Cross-industry, vendor-neutral, applies to ISO 9001 and adjacent standards.
A post-market monitoring plan template for high-risk AI systems under EU AI Act Article 72 — what to monitor, how often, what to do with the data.
A documented information control procedure for ISO 9001:2015 clause 7.5: naming, versioning, review, retention, disposition. Vendor-neutral starting template.
How to bridge ICT accessibility (EN 301 549) into a quality management system — process map, ownership, evidence, and the EAA 2025 deadline.
A quality management system template for high-risk AI systems under EU AI Act Article 17 — 13 mandatory elements, mapping to ISO 9001, lawful-basis notes.
A practical, vendor-neutral walkthrough of implementing ISO 9001:2015 — clauses 4 to 10 — with the process approach, risk-based thinking, and common industry pitfalls.
A clause-by-clause internal audit checklist for ISO 9001:2015 — sampling guidance, nonconformity grading, and a downloadable Excel workbook.
A management review minutes template aligned with ISO 9001:2015 clause 9.3. Required inputs, decision register, action log, and a downloadable DOCX.
A practical quality manual outline for ISO 9001:2015 — section by section, with what to include, what to omit, and where to point to other documents.
What ISO/IEC 90003 adds for software organisations on top of ISO 9001 — interpretive guidance, not a separate certification. Mapping to agile and DevOps.
How statistical process control (SPC) sits inside ISO 9001 clauses 9.1.1 and 8.5.1 — control charts, capability indices, and the manufacturing-shop pitfalls.
What ISO 13485:2016 adds on top of ISO 9001 for medical-device organisations — design controls, risk management, post-market surveillance, regulatory hooks.