Management Systems & ISO Certification
Implementation, integration, certification and maintenance of management systems for high-complexity organizations.
We turn regulatory, operational, environmental, social and governance requirements into management systems that are auditable, integrated and ready for certification.
Certifiable
- ISO 9001
- ISO 14001
- ISO 45001
- ISO 37001
- ISO 37301
Guidance
- ISO 26000
- ISO 30415
Context
Certification is the outcome. The work is the system.
Contracts, lenders, regulators and boards now ask for more than good practice: they ask for evidence. Legal requirements, permit conditions, contractual obligations and internal policies have to be tied to processes, owners, indicators and records that hold up under audit.
A system built only to obtain the certificate becomes a parallel file, detached from operations, and its weaknesses show at the next audit. Built from the way the organization actually works, it organizes routines, reduces rework between departments and sustains certification throughout the cycle.
For leadership
Risks, obligations and performance visible in one place.
For operations
Clear processes, with no document that nobody uses.
For the audit
Traceable evidence, from requirement to record.
What we do
From gap analysis to keeping the certificate.
Our ISO advisory covers the full life cycle of a management system: from complete implementation to specific stages, such as internal audits or preparation for the external audit.
Assess and plan
Maturity assessment and gap analysis
A review of what already exists against the requirements of the standard: gaps, risks and the real effort of implementation.
Implementation planning
Scope, schedule, owners and milestones through to the certification audit.
Structure and implement
Management system design
Context, interested parties, policy, objectives, risks and opportunities, roles and responsibilities.
Process mapping and standardization
Processes described the way the organization actually runs, with defined interfaces and controls.
Documentation drafting and review
Lean documented information: what is needed to operate, to provide evidence and to audit.
Indicators, controls and monitoring
Metrics, operational controls and follow-up routines tied to the objectives of the system.
Training and awareness
Training for leaders, teams and internal auditors, in the language of each department.
Integrate
Integrating multiple standards into an IMS
One integrated management system for quality, environment, health and safety, anti-bribery and compliance, with no duplicated structures.
Governance, integrity and compliance
Governance structure, integrity risk management, controls, reporting channels and monitoring of the compliance program.
Social responsibility and diversity guidance
ISO 26000 and ISO 30415 as references for policies, practices and indicators. They are guidance standards: they inform the system and do not lead to a certificate.
Audit, certify and maintain
Internal audit
Planning and conducting internal audits, with an objective report and an action plan.
Preparation for the external audit
Readiness review, mock audit and support throughout the certification stages.
Nonconformity management
Root cause analysis, corrective action and effectiveness review, with traceable records.
Certification cycle maintenance
The annual routine of audits, management review and preparation for surveillance and recertification.
Standards we cover
Five certifiable standards, two guidance standards.
We work on the implementation, certification and maintenance of ISO 9001, 14001, 45001, 37001 and 37301, incorporating the ISO 26000 and ISO 30415 guidance standards.
Requirements standards · certifiable
ISO 9001
Quality management
Standardized processes, customer focus, risks and opportunities and continual improvement. Usually the base on which the other systems are integrated.
2026 edition published in September 2026. Certificates to the 2015 edition must transition by September 30, 2029.
ISO 14001
Environmental management
Aspects and impacts, legal requirements, permits and permit conditions, operational controls and environmental performance.
2026 edition published in April 2026. The transition of certificates to the 2015 edition takes about three years, following the certification body's schedule.
ISO 45001
Occupational health and safety
Hazards and risks, worker participation, operational controls, contractors and emergency preparedness.
2018 edition in force.
ISO 37001
Anti-bribery management
Bribery risk assessment, third-party due diligence, financial and non-financial controls, reporting channel and investigation.
2025 edition in force. Certificates to the 2016 edition must transition by February 28, 2027.
ISO 37301
Compliance management
Compliance obligations, risk assessment, controls, culture and monitoring, in a certifiable requirements standard.
2021 edition in force, confirmed by ISO in 2026.
Guidance standards · not certifiable
ISO 26000 and ISO 30415 guide policies and practices but contain no certifiable requirements. They are therefore incorporated into the management system, not certified.
ISO 26000
Social responsibility
Guidance on organizational governance, human rights, labor practices, the environment, fair operating practices, consumer issues and community involvement.
ISO 30415
Diversity and inclusion
Guidance on diversity and inclusion in human resource management: responsibilities, recommended actions and suggested measures.
Status of the standards checked in October 2026. Transition deadlines follow international accreditation rules; always confirm with your certification body.
Standards in transition
Three standards with a transition under way.
The main management system standards have been revised. Organizations already certified have a transition period to move to the new edition; those certifying now start with it.
Assess the transition of my systemFebruary 28, 2027
ISO 37001
End of the transition to the 2025 edition. Since August 31, 2026, initial certifications and recertifications are carried out only to the new edition.
September 30, 2029
ISO 9001
End of the transition to the 2026 edition, published in September 2026.
About three years
ISO 14001
2026 edition published in April 2026. Moving certificates from the 2015 edition follows the schedule agreed with the certification body.
How we work
A system built from the way the organization operates.
Five stages, with clear deliverables in each and the same lead from start to finish.
01
Assessment
Maturity, gaps against the standard and the context of the organization. The output is a plan with realistic scope, timeline and effort.
02
Design
Policy, objectives, risks, processes, controls and documented information, designed from the way work is actually done.
03
Implementation
The system enters the routine: training, indicators, records and adjustments with each department.
04
Verification
Internal audit, nonconformity management and management review ahead of the external audit.
05
Certification and maintenance
Support during the certification body's audit and throughout the cycle: annual surveillance audits, recertification and continual improvement.
When to engage
When it makes sense to call H·MARIZ.
A contract, tender or lender now requires certification.
An implementation plan with scope, timeline and milestones.
The organization is pursuing its first certification.
A maturity assessment and a realistic path to the audit.
The system exists, but it does not reflect how the organization works.
A review of processes, documents and controls.
Each standard has its own system, with duplicated routines.
Integration into a single integrated management system.
The standard has been revised and the certificate must move to the new edition.
A gap analysis and a transition plan.
The audit is approaching and nonconformities remain open.
Corrective action, effectiveness review and preparation.
Integrity and compliance need auditable requirements.
A structure based on ISO 37001 and ISO 37301.
Permits, permit conditions and ESG commitments have become hard to control.
Legal requirements and commitments managed inside the system.
What sets us apart
What changes when the system is built by someone who has worked inside one.
Executive experience, from inside the system
Working on the structuring, certification and maintenance of an integrated system, in an executive role, teaches what holds up in daily routine and what only exists on paper.
Integration that is real
Quality, environment, health and safety, anti-bribery and compliance in one system, with shared policy, risk management, audits and management review.
Legal requirements inside the system
Permits, permit conditions, contractual obligations and ESG commitments handled as controlled requirements. This is where environmental and regulatory management meets the management system.
A proportionate system
Lean documentation and controls proportionate to risk. The system exists for the operation, not for the archive.
Senior-led work
The professional who runs the assessment is the one who designs the system, trains the teams and supports the audit.
Independence preserved
H·MARIZ prepares the organization. The decision to certify belongs to an independent, accredited certification body.

Experience
Experience applied in complex environments.
Direct executive involvement in structuring, certifying and maintaining an integrated management system on a high-complexity infrastructure project, covering quality, environment, health and safety, integrity and compliance.
Executive experience of Henrique Mariz, who leads this practice at H·MARIZ.
What that experience involves
- Integration across departments
- Legal and corporate requirements
- Internal and external audits
- Indicators and controls
- Governance and continual improvement
- Maintaining the system through the annual cycle
Applications by sector
Where the management system weighs on the decision.
Infrastructure and concessions
Concession contracts, lenders and granting authorities often require certified systems and ongoing evidence of quality, environmental and safety performance.
Mining
Operations under constant scrutiny, with extensive legal requirements, permit conditions, contractors and communities within the scope of the system.
Construction and real estate development
Construction quality, occupational safety and environmental management of sites, with requirements from lenders and institutional clients.
Industry
Facilities with permits, emissions, waste and requirements from customers and supply chains.
Energy
Distributed assets and contractors, with regulatory, environmental and social obligations from construction through operation.
Investment projects
Governance, integrity and compliance as a condition for access to capital and for bringing in partners.
Related practice areas
The management system connects with our other practice areas.
- Land Use & PermittingPermits and permit conditions are legal requirements of the environmental management system.
- ESG & Environmental and Social ManagementCommitments, programs and indicators gain a process, an owner and evidence.
- Intelligence & TechnologyData and automation to track requirements, deadlines and records with traceability.
- LeadershipWho leads the practice, and with what experience.
Frequently asked questions
What clients usually ask before starting.
- What is an integrated management system (IMS)?
- It is a single management system that meets the requirements of more than one standard at the same time: for example, quality (ISO 9001), environment (ISO 14001) and health and safety (ISO 45001). Instead of parallel structures, the organization shares policy, processes, risk management, internal audits and management review. ISO management system standards follow the same structure of requirements, which makes this integration natural.
- Which ISO standards does H·MARIZ cover?
- We work on the implementation, certification and maintenance of ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety), ISO 37001 (anti-bribery) and ISO 37301 (compliance), incorporating the ISO 26000 (social responsibility) and ISO 30415 (diversity and inclusion) guidance standards.
- Does H·MARIZ work only on certification?
- No. Certification is one stage. We work from the maturity assessment through to maintaining the system: design, processes, documentation, indicators, training, internal audit, preparation for the external audit, nonconformity management and support for surveillance and recertification audits. We also support organizations that want a sound management system without seeking the certificate right away.
- What is the difference between ISO 26000 / ISO 30415 and the certifiable standards?
- ISO 9001, 14001, 45001, 37001 and 37301 contain requirements and can be audited by a certification body. ISO 26000 and ISO 30415 are guidance standards: they guide policies and practices on social responsibility and on diversity and inclusion, but contain no certifiable requirements. That is why we speak of incorporating this guidance into the system, never of certifying it.
- Does the advisory include internal audits?
- Yes. We plan and conduct internal audits, preserving the impartiality the standard requires in relation to the activities audited, train the organization's own internal auditors where it makes sense and support nonconformity management through to the effectiveness review.
- Can mining, infrastructure and real estate development companies benefit?
- Yes. These are sectors with many legal requirements, permits, permit conditions, contractors and interested parties. A management system organizes those requirements into processes, owners and evidence, and responds to what contracts, lenders and investors demand.
- Can quality, environment, OH&S, integrity and compliance be integrated into a single system?
- Yes. The standards share the same structure of requirements, which allows one integrated policy, common risk management, a single internal audit program and one management review. The controls specific to each topic remain; what is eliminated is the duplication.
- How does preparation for the external audit work?
- It starts with a readiness review: a complete internal audit, nonconformities addressed and management review carried out. We then prepare leaders and teams for interviews, organize the evidence and support the organization during the certification audit, which takes place in two stages, and in the surveillance audits of the following years.
- Does H·MARIZ issue the certificate?
- No. The certificate is issued by an independent certification body. In Brazil, those bodies are accredited by Cgcre, the accreditation arm of Inmetro. Advisory and certification are kept separate by impartiality rules: our role is to prepare the organization and the system; the decision to certify belongs to the certification body.
- My standard has been revised. What needs to be done?
- When a standard is revised, certified organizations have a transition period to bring the system in line with the new edition. Three standards are currently in transition: ISO 37001 (until February 28, 2027), ISO 9001 (until September 30, 2029) and ISO 14001, where the move takes about three years, following the certification body's schedule. We carry out the analysis of changes, the transition plan and the preparation for the audit to the new edition.
- How long does an implementation take?
- It depends on size, complexity, the number of standards and the starting level of maturity. That is why we begin with the assessment: it defines scope, effort and a realistic schedule before any commitment to an audit date.
Contact
Does your organization need to certify, integrate or sustain a management system?
Start with the assessment: scope, gaps and a realistic path to the audit.
Henrique Marizhenrique@hmariz.comWhatsApp (31) 99791-8003Belo Horizonte, Minas Gerais