The order
- Context and interested parties — what we operate in, who has an interest.
- Scope — draw the boundary, write it down.
- Leadership and roles — who is responsible for what, with what authority.
- Risk assessment and legal obligations — this is the system's real input.
- Policy — top management's commitment.
- Objectives and plans — derived from risks and obligations.
- Processes and controls — operational planning, emergency preparedness.
- Competence, awareness, communication, documented information.
- Monitoring and measurement.
- Internal audit.
- Management review.
- Nonconformity and corrective action — and round again.
Why this order
Each step consumes the previous one's output. A system with an unclear scope produces an incomplete risk assessment; an organisation that does not know its risks sets arbitrary objectives; monitoring without objectives does not know what it is watching.
The two most common mistakes
First, starting by writing documents. Template procedures describe the template, not the organisation, and get rewritten once context is clear. Second, setting objectives before the risk assessment; the objective then follows what is easiest to measure rather than what carries the most risk.
How long it takes
Giving one figure would be misleading; it depends on size, number of sites and the state of existing records. What can be measured is this: an organisation that moves on before finishing a step ends up back at the beginning.
Can a system be bought ready-made?
A document set can be bought; a system cannot. What makes a system is not the records but the habits that produce them.