Clause 4.3 says the organisation shall determine the boundaries and applicability of the management system to establish its scope. Read that first word again. The organisation. Not the certification body, not the auditor, not the consultant. You decide what your management system covers, and you are entitled to draw that line deliberately. That freedom comes […]
Articles
Psychosocial Hazards at Work: What Australian Law Requires, and Where ISO 45001 Stops Short
Every Australian jurisdiction now requires you to manage psychosocial hazards as hazards, not as wellbeing. What the law asks for, where the states differ, and why a certified ISO 45001 system may not prove compliance.
Knowledge Momentum: What ISO 9001 Clause 7.1.6 Really Asks of You
Clause 7.1.6, organisational knowledge, is one of the few requirements unique to ISO 9001. An auditor on why key-person risk quietly erodes quality, and how to capture knowledge before it walks out the door.
When Your Failover Fails: Business Continuity and the Mobile-Outage Trap
Most business continuity plans nominate mobile as the failover when the primary connection drops. Today’s nationwide Telstra outage showed why that’s a hidden single point of failure, and what a real BCP does about it.
You Built Your ISO System with AI. Who Audits It?
AI has changed how ISO management systems get built. A capable person with the right prompts can now draft a quality manual, a risk assessment or a set of procedures in an afternoon. That is a real shift, and for a lot of the documentation work it is a good one. But it leaves a […]
Louder Is Not More Credible: A Code of Conduct for Consultants and Auditors
If you spend any time on professional social media, you will have noticed the drift. The feed fills up with self-promotion, recycled hot takes, AI-generated posts dressed up with the same little icons and the same confident cadence, and, every so often, someone building an audience by tearing other people down. It is easy to […]
The ACSC Just Told You Your Website Is the Attack Surface
A global campaign is deploying webshells through known CMS and plugin vulnerabilities, and the ACSC says many small and mid-sized Australian businesses are already impacted. Nearly every flaw already has a patch.
Microsoft Launches Defender Experts Suite: What It Means for Australian Businesses
Microsoft’s Defender Experts Suite is a managed detection and response (MDR) service: in plain terms, Microsoft’s own security analysts watching your environment and hunting for threats using the signals your Microsoft 365 and Defender licences already generate. For the many Australian businesses running on Microsoft but without a 24/7 security team, it’s a genuinely useful […]
The First AI-Run Cyberattack Hit Hugging Face. The Real Lesson Is Older Than AI.
Update, 22 July 2026: OpenAI has now confirmed that this incident was caused by its own models, not an outside attacker. In a joint statement with Hugging Face, OpenAI said two of its models, the publicly available GPT-5.6 Sol and a more capable unreleased model, were running an internal cyber-capability benchmark called ExploitGym with their […]
South Australia Just Dropped the Fall Threshold to 2 Metres. The Data Says That’s Where People Were Falling.
From 1 July 2026, SA reduced the high-risk construction work fall threshold from three metres to two. The reason is in the data: 68% of falls from above 2 metres happened between 2 and 3 metres, the exact gap the old rule left open.
- « Previous Page
- 1
- …
- 4
- 5
- 6
- 7
- 8
- …
- 15
- Next Page »












