KITE 2025 New Product Award โ€” Local IT | SACEEC
Environment and quality

ISO 9001 coverage that makes quality auditable

Processes mapped with the risks that threaten them, nonconformities tracked to root cause, and supplier evaluation running on a cycle, all with the evidence an auditor expects.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What ISO 9001 requires

Process register with risk linkage

Processes mapped with their inputs, outputs, sequence and measures. Risks recorded directly against the processes they threaten, ready for the question an auditor will ask.

Nonconformities that trend

Nonconformities tracked with root cause analysis and corrective actions carried until evidence closes them. Patterns across processes and suppliers visible in one view.

Supplier evaluation on a cycle

Suppliers carry evaluation criteria, scores and review dates. Re-evaluation runs on schedule rather than only at onboarding.

One system across multiple certifications

Context, leadership, competence, internal audit and management review are shared with ISO 14001, 45001 and 27001. Dimeri runs one system with separate scopes.

ISO 9001 compliance, covered by default

Process risks, nonconformity tracking, supplier evaluation and the evidence that the system works, all in one platform so risk-based thinking has an answer rather than a paragraph.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Process register with risk linkage

Processes mapped with their inputs, outputs, sequence and measures. Risks recorded directly against the processes they threaten, ready for the risk question an auditor will ask.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Nonconformity and corrective action

Nonconformities tracked with root cause analysis and corrective actions carried until evidence closes them. Trends across processes and suppliers visible in one view.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Supplier evaluation on a cycle

Suppliers carry evaluation criteria, scores and review dates. Re-evaluation runs on schedule rather than only at onboarding, which is what the standard asks for.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Process performance measures

Criteria and performance thresholds per process, with customer satisfaction captured and trended alongside operational measures.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Competence and training records

Competence requirements per role, training records by individual and calibration schedules tracked. Gaps raised as actions rather than noted.

What Dimeri tracks

Dimeri holds the process map, the risks against each process, and the evidence that controls operate, in one structure.

Process approach and leadership

The processes of the system determined with their inputs, outputs, sequence and measures, and top management accountable including for customer focus.

  • Process register with owners and interactions
  • Criteria and performance measures per process
  • Quality policy with approval and review dates
  • Customer requirements captured and tracked

Risk-based thinking

Risks and opportunities that affect conformity of products and services and the ability to enhance customer satisfaction, addressed and their effectiveness evaluated.

  • Risks recorded against the processes they threaten
  • Opportunities captured alongside risks
  • Actions with owners and due dates
  • Effectiveness of the action evaluated

Resources and competence

People, infrastructure, environment and monitoring resources determined and provided, with competence established and evidenced.

  • Competence requirements per role
  • Training and qualification records by individual
  • Calibration and maintenance schedules tracked
  • Gaps raised as actions rather than noted

Externally provided processes and suppliers

Controls over externally provided processes, products and services, with criteria for evaluation, selection and re-evaluation of suppliers.

  • Supplier register with evaluation criteria and scores
  • Re-evaluation on a cycle, not only at onboarding
  • Controls held against the supply contract
  • Performance issues raised as nonconformities

Nonconforming output and corrective action

Nonconforming output identified and controlled, and nonconformities investigated with corrective action taken where the cause could recur.

  • Nonconformity register with disposition recorded
  • Root cause analysis against recurring issues
  • Corrective actions carried until evidence closes them
  • Trend view across processes and suppliers

Monitoring, audit and management review

Performance and customer satisfaction monitored, internal audit run across the system, and management review held with the expected inputs.

  • Process measures tracked with thresholds
  • Customer satisfaction captured and trended
  • Internal audit programme covering every clause
  • Management review inputs assembled through the year

Getting ISO 9001 coverage in place

4 steps from where you are today to a ISO 9001 position your auditor can rely on.

Book a demo

The standard wants the processes, their inputs and outputs, their sequence and interaction, and the criteria and measures that show they work. Everything else in the standard hangs off this map.

How Dimeri covers ISO 9001

Risk-based thinking with somewhere to live

The standard asks for risks to processes but gives no register to keep them in, so most organisations improvise a spreadsheet. Dimeri holds them in the same register as every other risk, scored the same way, which is what makes risk-based thinking auditable.

Nonconformities that trend

Individual corrective actions close. Patterns across processes and suppliers only become visible when nonconformities share a structure, which is where the improvement commitment actually earns its place.

Supplier evaluation on a cycle

The standard requires re-evaluation, not just selection. Suppliers carry review dates and performance history, and the third party risk module uses the same records.

ISO 9001 questions

What happened to preventive action in the 2015 revision?

It was removed as a separate clause and replaced by risk-based thinking throughout the standard. The reasoning is that a management system built around risks and opportunities is preventive throughout, rather than having prevention bolted on as one procedure. Practically, auditors now ask where your process risks are recorded and what you did about them.

Do we need a quality manual?

The current edition removed the explicit requirement for a quality manual and for six documented procedures, replacing them with documented information that the organisation determines is necessary. Many organisations keep a manual because customers expect it, but the standard does not require one.

Can ISO 9001 and ISO 14001 share one system?

Yes, and most organisations holding both do. The common management system structure means context, leadership, competence, documented information, internal audit and management review are shared clauses. Dimeri holds one system with separate scopes and one internal audit programme covering both.

Is certification worth it if no customer has asked?

That is a commercial judgement rather than a compliance one. The structure is useful on its own, and many organisations align without certifying. Certification matters when a tender, a customer or a supply chain requires independent assurance, which in South African public procurement is increasingly common.

Is this a substitute for the standard itself?

No. ISO 9001 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to certify against it.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.