Regulatory and Compliance Arena Under Enterprise Risk Management

Redmond Worldwide, Inc provides a framework for quality management and quality assurance with it’s ISO service offering. . Even Entities that are not required to have ISO can benefit tremendously by incorporating ISO standards.

ISO, International Trans-Organization for Standardization, is a network of organizations across over 30 countries that set of standards and requirements that allow an organization to seek certification for ISO.

Section 1 Enterprise Risk Worldwide, Inc. ISO service offerings:

Redmond Worldwide, Inc ISO staff are all Certified.

Redmond Worldwide, Inc offers a wide range of services within the world of ISO

We also offer a service called the Quality Pro – for those times when a full-time hire is not the answer to a pressing problem.


ISO Pre-assessments & Training

If you think you are almost ready for the ISO registrar but would like one more last-minute check, Redmond Worldwide, Inc provides pre-assessments to help ensure that any major gaps are identified and closed. 

The overall context of the pre-assessment (audit) is to help encourage the view that audits are opportunities for learning and should be used to improve the organization.   

The audit findings are presented in a way that encourages your organization to close the gaps from a systemic-process point of view. 

The overall audit will ultimately be viewed by your organization as chance for them to make a difference in the success of their company.

Training is also available to help the employees know what to expect from the registrar and how to respond to the registrar’s questions.


ISO Implementation

Redmond Worldwide, Inc’s approach to implementing ISO is to not just put a certificate on the wall, but to create a business management system that:

- All of which contribute to your profit margin and also make your company more valuable.

Implementing an ISO system that functions as your business management system can be a challenge.  Implementation requires a different skill set than those required for auditing;  skills such as:  facilitation, project management, human relations, systems thinking – to name a few. 

Redmond Worldwide, Inc provides a full range of services.  We offer:

How to sell ISO internally

And as we always say: 

 “If at the end of the day, you tell us that you are doing something because it is what Redmond Worldwide, Inc or ISO says you are supposed to be doing – that’s the wrong answer!  You are supposed to be doing it because it adds value.  If it’s not – we need to fix it so that it is helping your organization.”

A successful implementation should always have a positive effect on your bottom line.


ISO Internal  Consultative Audits

ISO’s internal audits should be viewed as ‘windows’ into your organization.  And working in conjunction with the Corrective/Preventive Action System and the Management Review should be a major driver within your system. 

If this is not happening and you feel that your audit program needs a boost.  Redmond Worldwide, Inc can:


ISO Integrated Consultative Audits (for the real-time enterprise)

Your organization undergoes many different types of audits throughout the course of a year.  Sometimes these audits add little or no value and in a few cases seem to be more disruptive to process efficiency and effectiveness than they are worth.  As organizations become more real-time, their systems are becoming increasingly integrated.  Taking a functional approach often sub-optimizes these processes. 

Processes themselves are becoming more visible through the use of technology i.e., flowcharts, BTO applications, CRM and ERP.  It’s the management and control of these processes that will determine how well an organization will perform and conform to various requirements pressed upon it.  Most of these audits, if properly planned ahead of time and done so either as a system/process audit – could be coordinated for both the audit and audit results and actually be viewed as an asset to the organization – and not an necessary evil.

Redmond Worldwide, Inc can help you with coordinating the upfront activities of integrating some of the audits that you will have to do throughout the year.  We can also facilitate and oversee the audit process to make sure it is done in the most efficient and effective manner.  And we can work with the auditors to ensure that the reports are integrated and written in a manner that will help to drive improvement.


Quality Pro

With budgetary pressures and staffing issues, maintaining your current business/quality management system can prove to be an overwhelming challenge.  With the help of Redmond Worldwide, Inc’s Quality Pro, you can benefit from the experience of a seasoned pro but at significantly less cost than adding a full-time resource.

The Quality Pro can help to:

Section 2:  Redmond Worldwide, Inc. - ISO and Related Services

Redmond Worldwide, Inc ISO staff are all Certified.

Basic information on ISO 9000, 14000 and 17799

ISO 9000 Family of Standards:

ISO 9001:2000 – third generation, is one of the most recognized standards for a management system in the world. ISO 9000 applies to all types of organizations. It doesn't matter what size they are or what they do. It can help both product and service oriented organizations achieve standards of quality that are recognized and respected throughout the world. Developed by the International Organization for Standardization in Switzerland, more than 610,000 companies are now registered to this standard in over 160 countries around the world. ISO 9001:2000 is one of the best models available for establishing a powerful and robust business management system.

Fundamental aspects of the model:

The ISO model enables organizations to manage, control and improve their processes even with the many requirements placed upon it by customers, shareholders, regulators, and society at large.

ISO 9001:2000 provides a way to integrate the various risk related requirements that are currently ‘floating’ around i.e., IS, BCP, DRP, SAS 70s, Market & Credit Risk, and in particular is appropriate for Basel’s definition of operational risk “the risk of direct or indirect loss resulting from inadequate or failed internal processes, people and systems or from external events.” 

In essence, ISO is a methodology for transforming your organization into a huge plug-in-play system that synergistically (efficiently and effectively) weaves requirements into the existing system without continually adding overhead and creating additional and unnecessary functional silos.

ISO 14000 Family of Standards:

ISO 14001:1996 Environmental management systems – specifications with guidance for use is growing rapidly in acceptance both in the US and worldwide.  As the economy becomes increasingly global in nature, organizations are being asked to demonstrate sound management of economic, social and environmental issues.  Focusing on this “triple bottom line” can result in advantages in financing, insurance, marketing, regulatory treatment and other areas.

A structured approach to managing the environmental bottom line can be best achieved by implementing an Environmental Management System (EMS) – and ISO 14001 is the most widely recognized EMS framework in the world.  It’s particularly strong in helping organizations to better manage the impact of their activities on the environment and also in demonstrating sound environmental management. 

Some of the significant tangible benefits:

And as with ISO 9001, an EMS (14001) can be implemented in any organization regardless of industry or size.  

ISO/IEC 17799:2000:

ISO/IEC 17799:2000 Information technology – Code of practice for information security management is of growing interest to firms who are interested in protecting their information and also maximizing their return on business investments and business opportunities.   

Information exists in many forms and can be shared and stored in a growing number of mediums.  And the paradox is that as information becomes one of the more valuable assets of a firm, it is often the least protected. 

Organization’s information systems and networks are increasing under attack from a wide assortment of threats ranging from computer-assisted fraud, espionage, sabotage, vandalism, fire and floods.  Public and private networks have become more interconnected and the trend towards distributed computing has diluted the effectiveness of the traditional central control.

Information security is characterized by three components: confidentiality, integrity and availability.  Actual information security requires a suitable set of controls such as policies, practices, procedures, organizational structures and software functions.  Utilizing such controls will help to ensure that the security objectives of the organization are met. 

ISO 17799 offers one of the most comprehensive guidance documents available in today’s world of information security.