Information security management system

Information security management system

Informasjonssikkerhet

Certain QMS is a fully-featured quality management system with functionality for management processes, documentation, risk assessment, audit and more. The system also meets the requirements for an organisation-wide information security management system (ISMS).

This means that organisations can use Certain QMS to establish, follow up and document information security in a structured and transparent manner, without additional software or separate ISMS tools.

This article explains how you can use Certain QMS to establish and manage a complete ISMS. We walk through the relevant features of the system and describe what is included in terms of ready-made templates, supporting documentation and tools in our ISMS package.

Certain QMS: a comprehensive ISMS tool

Certain QMS supports the entire lifecycle of information security work, from establishment through to continual improvement, and is suited both to organisations seeking ISO 27001 certification and to those wanting a structured ISMS without formal certification.

The system gives you the tools you need to:

  • Establish an ISMS: Access ready-made procedures, policies and process models that can be adapted to your organisation.
  • Plan and follow up: Use the annual planner functionality to plan activities and tasks, assign responsibilities and ensure that tasks are completed and documented.
  • Assess risk: The risk module provides an overview and control, making it straightforward to follow up on actions.
  • Manage data protection: The DPIA process supports the assessment of high-risk processing activities, and is linked to risk assessment and actions.
  • Ensure compliance: The compliance module helps you document that requirements from legislation, standards and customers are being met.
  • Document processing activities: The records of processing activities provide an overview of the organisation’s personal data processing, functioning as an integrated part of the ISMS.

What is an ISMS?

An information security management system (ISMS) is a framework that helps organisations protect information systematically. It provides structure for how risks are identified, controls are put in place, security measures are documented and follow-up is carried out over time.

The main objectives of an ISMS:

  • Information should always be confidential, accurate and available to those who need it
  • Compliance with legal requirements, standards and internal guidelines

In the same way as a quality management system (QMS), an ISMS combines processes, routines, policies and documentation to give the organisation a clear framework.

An ISMS makes it possible to:

  • Assess and manage risks relating to information
  • Ensure that actions are followed up and documented
  • Clarify roles and responsibilities for security
  • Document compliance with standards and legal requirements
  • Continually improve information security

By using Certain QMS as an ISMS, the organisation has all the necessary tools in one place — from document control and risk assessment to checklists, processes and audit — making implementation and follow-up clear and cohesive.

Why is an ISMS important for the organisation?

An ISMS gives management a systematic framework for documenting and following up that the organisation complies with legislation, regulations and both internal and external requirements relating to information security and data protection.

The main reasons for having an ISMS:

  • Legislation and regulation: An ISMS makes it possible to document that the organisation complies with applicable laws and regulations, such as the Personal Data Act / GDPR and the NIS2 Directive for critical infrastructure, or sector-specific requirements.
  • Standards and certifications: ISO 27001 and other international standards set requirements for the management of information security, and an ISMS provides a documented basis for compliance and any certifications.
  • Customer expectations: More customers require their suppliers to manage information security systematically, and an ISMS provides documentation of this.
  • Risk and vulnerability management: The system makes it possible to identify and manage risks relating to information, whilst follow-up and control are documented.
  • Continual improvement: By establishing a systematic framework, the organisation can follow up on actions, document results and continuously improve its security level.

With an ISMS, organisations can demonstrate to both regulators and customers that they take information security seriously.

A process-oriented approach to ISMS

Certain QMS supports a process-oriented approach to management, meaning that information security work is organised around processes rather than functions or departments.

Information security work is established as a dedicated process area in which both main processes and sub-processes are modelled. This makes it easier to see the full picture of the work and where responsibility lies.

Documentation linked to processes

All documentation (procedures, guides, instructions, templates and more) is linked to the relevant activities in the process, and is also logically organised within a dedicated folder area for information security. Users can navigate via the processes or the folder structure.

All documents have full version control, and both documents and processes can be managed with role-based access, so that only authorised users see relevant content.

Annual planner for information security work

Certain QMS supports a process-oriented approach to management, meaning that information security work is organised around processes rather than functions or departments.

Information security work is established as a dedicated process area in which both main processes and sub-processes are modelled. This makes it easier to see the full picture of the work and where responsibility lies.

Annual planner for ISMS establishment

The annual planner for ISMS establishment helps you carry out the initial setup work in a structured manner, ensuring that the ISMS is established correctly from the outset.

Contents:

  • 12-month structured plan
  • Activities with clear guidance text and tasks
  • Green status shown when tasks are completed

Examples of activities throughout the year:

  • January: Map existing security work
  • May: Carry out risk assessment
  • July: Establish controls and security routines
  • December: Complete and publish the ISMS
Årshjul etablering av ISMS Certain QMS

Annual planner for ISMS establishment.

Annual planner for continual improvement

Once the ISMS has been established, the system must be kept active. This annual planner provides a template for annual maintenance, follow-up and improvement.

Activities include:

  • Revision of previous risk assessments
  • Internal audit and management review
  • Training and awareness-raising
  • Review of the records of processing activities and DPIA requirements

Ready-made document templates for ISMS

Certain QMS can be delivered with a complete template set for ISMS, giving the organisation a solid starting point for documenting and following up on information security.

The templates are designed to be adapted to the individual organisation, whilst ensuring that all necessary elements are in place.

The template set covers:

  • ISMS policy
  • All necessary procedures, including incident management, access control and operations
  • DPIA procedure and templates
  • Audit plan and audit report
  • Management review

The document templates include:

  • Field lists with guidance text to assist the user
  • Established content templates that can be inserted into documents where relevant

DPIA support in Certain QMS

A DPIA (Data Protection Impact Assessment) is an assessment of how a personal data processing activity may affect individuals’ rights and freedoms. Carrying out a DPIA is required when processing is likely to result in a high risk to data subjects.

Certain QMS supports the entire DPIA process by combining checklists, document templates and risk assessment.

How the system supports DPIA work:

  • Checklist for assessing the need for a DPIA
  • Guidance for assessment in line with the Norwegian Data Protection Authority
  • Risk analysis template for carrying out a DPIA
  • Request function for risk analysis
  • Incident register for data protection risk
  • Dedicated impact areas for data protection rights, confidentiality, availability, integrity, reputation, legal requirements and regulations

Risk analysis request

In Certain QMS, users can submit a request for a risk analysis directly within the system. This enables the data protection officer, information security officer or other relevant roles to receive notification that an analysis of a system or process needs to be carried out.

The feature ensures clear accountability and efficient follow-up, without requiring everyone involved in DPIA or process work to carry out the analysis themselves.

DPIA document template

Once a DPIA has been completed, the results can be documented using a dedicated DPIA template in Certain QMS. The template helps you systematically summarise the purpose, processing activity, assessed risk, actions and conclusion. Built-in guidance text and a clear structure ensure that all relevant elements are covered, even for users without specialist data protection expertise.

The document can be linked directly to the records of processing activities, and serves as the organisation’s documented evidence that the assessment has been carried out in accordance with GDPR Article 35. The DPIA documentation can be used in management reviews, internal controls or external audits, and ensures both traceability and compliance.

Dokumentmal oppsummering gjennomført DPIA Certain QMS

Document template for summarising a completed DPIA.

Systematic risk work for information security

Certain QMS offers a tool that covers the entire risk management process, from planning through to follow-up:

  • Planning
  • Risk analysis
  • Risk evaluation
  • Risk management

Within the solution, information security is configured as a dedicated risk area. The analysis is delivered with a pre-configured template that includes relevant impact areas, acceptance levels and predefined events to be assessed. The predefined event register streamlines the work for the analysis team, enabling them to focus on assessing and prioritising risks rather than starting from a blank page when identifying potential threats.

All steps and fields in the analysis include extensive guidance text to guide the user through the process. The guidance text can also be adapted to the organisation, and consequence levels are described with explanatory text to support assessments.

The risk analysis template supports:

  • Predefined events, causes and actions
  • Multiple impact areas, including CIA + data protection rights
Analysemal for DPIA Certain QMS

Analysis template for DPIA.

Visual and dynamic overview of the risk landscape

Certain QMS provides a visual representation of the risk landscape through both risk matrices and table views. This makes it straightforward to understand and communicate which threats have been assessed as most critical, and which actions have been put in place.

The solution also offers a dynamic risk report where you can filter by risk area, responsible party, department and other parameters. This gives the organisation a real-time reflection of the actual risk landscape, based on which analyses have been carried out and assessed.

 

The report makes it possible to:

  • View aggregated risk within areas such as information security, data protection or ICT operations
  • Identify risks that lack actions or have a high residual uncertainty
  • Give management an up-to-date and documented overview of the organisation’s risk profile

This supports systematic follow-up, simplifies audits and ensures that risk work is embedded and visible across the organisation.

Risk management with actions and action plan

Once the risk analysis has been completed, an action plan is drawn up to reduce the risks associated with information security. The action plan forms the basis for risk management, with the risk owner taking responsibility for follow-up.

In Certain QMS, all of this can be handled directly within the solution, and tasks to be carried out can be assigned from the tool.

In the management phase, the risk owner can:

  • Prioritise actions for implementation
  • Accept residual risk
  • Delegate responsibility for implementing actions
  • Set deadlines for actions and follow-up
  • Record costs associated with implementation
  • Monitor the status and progress of each action

Risk management is concluded when the risk owner has assessed the effect of the actions implemented, signed off on the residual risk and formulated a final conclusion for the work.

Compliance register

A compliance register is an overview of requirements from legislation, standards and internal guidelines, linked to relevant documentation in the management system. In Certain QMS, the compliance register is one of many available features that helps the organisation maintain an overview and ensure compliance.

For ISO 27001 Annex A, all 93 controls are pre-registered in the system. Each control includes an explanation of what it entails and status fields indicating whether the requirement has been met. This makes it straightforward to use the register in audits, gap analyses and improvement work.

A ready-made template set for a GDPR article register can also be produced as part of the delivery.

Samsvarsregistermannex A ISO 27001

Compliance register for Annex A ISO 27001.

Records of processing activities and GDPR

Certain QMS offers a table-based document template for records of processing activities that follows the requirements of GDPR Article 30 and the Norwegian Personal Data Act. The template includes fields for the legal basis for processing, types of personal data, storage, security measures and other relevant information.

The documentation can also be linked to associated DPIAs and compliance assessments, giving the organisation a clear overview of all connections between processing activities, risk and legal requirements.

Follow-up and version control

As part of the work with records of processing activities, Certain QMS also supports control of the records through the annual planner for continual improvement. Version management and availability of the records of processing activities are handled directly in the document module, so that all changes and updates can be easily followed up.

Making documentation available and sharing it

Certain QMS supports the publishing of selected documents on internal or open portals. This enables employees, customers and partners to access relevant information without having to navigate the entire system.

This supports compliance by ensuring that all relevant parties always have access to correct and up-to-date documentation. In this way, requirements for compliance, training and internal control are met, whilst important processes and routines become transparent to all who need them.

Leder som følger opp informasjonssikkerhet ISMS

ISMS package for Certain QMS

Ready to install and use from day one

Our ISMS package is delivered pre-configured and installed on the customer’s own Certain QMS installation. Each package gives the organisation everything needed to establish, document and follow up an information security management system in line with ISO 27001 and GDPR:

  • ISMS documentation: procedures, policies and process models
  • Annual planner for establishment
  • Annual planner for continual improvement
  • Risk analysis templates for information security
  • DPIA support with checklists, guidance and risk templates
  • Compliance register for ISO 27001 and the option of a GDPR article register
  • Document template for records of processing activities
  • Full version control and role-based access for all documentation

The packages are ready to use from day one, but can be adapted to the organisation’s needs and existing processes.

Contact us for a demonstration and pricing.

SharePoint as a work surface for a quality management system

SharePoint as a work surface for a quality management system

Certain QMS SharePoint

A prerequisite for succeeding with quality management and improvement is that all employees have quick and easy access to internal documentation and internal reporting systems.

That is why we have chosen to make the functions that all employees need to use available in SharePoint.

SharePoint is familiar and user-friendly

Adopting “yet another IT system” can be demanding for employees who do not have direct responsibility for developing the organisation’s QHSE processes. At the same time, the entire organisation should benefit from the QHSE work carried out within the quality management system.

With SharePoint as the work surface, employees can search for internal procedures and processes, and report non-conformances without leaving the intranet. Notifications in SharePoint and shortcuts to reading lists ensure that information reaches all employees.

Quick and easy access to up-to-date and relevant information is the key to improvement – and that is what we can offer with SharePoint as the work surface.

What can you do in SharePoint?

In SharePoint we have gathered the most important functions for the organisation’s employees, along with useful notifications for tasks that require handling directly in Certain QMS.

Non-conformances

All types of non-conformances, suggestions for improvement or reports of serious concerns can be registered by employees directly in SharePoint.

Case handlers for non-conformances and other types of cases receive notifications in SharePoint showing the status of the following:

  • Number of new cases awaiting assignment to a case handler
  • Number of own cases currently being processed
  • Number of tasks and measures not yet closed
  • Number of cases that have exceeded the internal deadline

Processes

  • Search for processes
  • Navigate the process landscape
  • Read and click on activities within processes

Employees who produce or are responsible for the organisation’s processes receive dedicated notifications showing how many processes have not been approved or have passed their revision deadline.

Documents

  • Search for documents
  • Read documents
  • Confirm reading

Employees who produce or are responsible for the organisation’s documentation receive dedicated notifications showing how many documents are awaiting approval or consultation, or have passed their revision deadline.

Reading lists

  • Display of a personalised reading list applicable to the employee’s role or position
  • Notification showing the number of unread documents in the reading list

Risk

Employees who carry out risk assessments in Certain QMS receive notifications showing the number of their own risk analyses currently in progress, and the number of risk-reducing measures that have not yet been closed.

Useful for multiple types of users

Certain QMS is a digital solution designed to be used in different ways and for different tasks, depending on the role a person holds within the organisation. For everyone with management or QHSE responsibilities, Certain QMS will be an important professional and governance system.

For employees who work directly within the system – for example, producing documentation, carrying out risk analyses or handling non-conformances – SharePoint will also be useful for notifications and status updates.

The personalised section of SharePoint displays new cases, unread documents or deadlines for revision and case handling. This gives those responsible a quick overview of tasks awaiting attention and a practical shortcut directly to the work surface in Certain QMS.

The user account in SharePoint is linked to the user account in Certain QMS, so information and access permissions will always be tailored to each individual employee and their role.

Marte Sunde

Marte Sunde

Business Consultant

Marte Sunde is a Business Consultant for Certain QMS, specialising in quality management and HSE systems. She works at the intersection of operational practice and digital solutions, helping organisations implement and improve management systems that ensure compliance, structure, and continuous improvement.

eHandbook for document control in the healthcare sector

eHandbook for document control in the healthcare sector

eHandbook document control in the healthcare sector

The document module in Certain QMS is the core of the quality management system, bringing together the organisation’s internal procedures, guidelines, routines and other governing documentation in one place.

For many years, the solution has been used by large organisations in the healthcare sector, where it is referred to as the eHandbook — a term with a long history in the sector. The eHandbook in Certain QMS serves as the organisation’s digital reference for both practical working routines and other governing documentation that forms the basis for operations, internal control and systematic quality work.

Key features of the eHandbook

To support the requirements for document control, internal control and quality in the healthcare sector, the eHandbook in Certain QMS covers the entire lifecycle of governing documents — from drafting, internal consultation and approval through to publishing, use and revision. The solution offers, amongst other things:

  • Flexible and customised document templates for different types of procedures, guidelines and instructions, making documentation more consistent and easier to maintain.
  • Approval workflows and clearly defined roles for who can edit, quality-assure, approve and publish documents.
  • Advanced role and access management, which can be integrated with the organisation’s AD/Entra ID, so that employees are automatically granted access to the right content based on their role and department.
  • Restriction of sensitive information, ensuring that certain content is only accessible to defined roles or user groups.
  • HTML-based and searchable documents, combined with the ability to upload various file formats and link to external resources.
  • Change summaries, giving users a quick overview of what is new or changed in a document.
  • Reading lists with acknowledgement, where managers can require employees to read selected documents and have confirmation of completion recorded.
  • Review deadlines and automatic notifications, ensuring that documents do not remain outdated without responsible parties being followed up.
  • Public document portal for external publishing of selected documents, so that procedures, guidelines and other information can be shared online — without requiring a login.

Scope and use of the eHandbook in the healthcare sector

Figures from the large healthcare organisations using the eHandbook in Certain QMS show that the solution is not a passive document archive, but a reference tool that is actively used by employees on a daily basis.

Usage data shows high levels of activity, with thousands of document views each day and a large number of unique users over time. This confirms the eHandbook’s role as a central working environment for governing documentation — for clinical staff, managers and support functions alike.

Examples of document scope and publishing:

Organisation Internal documents Public documents
Oslo University Hospital HF approx. 33,000 approx. 8,000
Vestre Viken HF approx. 18,000 approx. 8,000
Helse Fonna HF 8,000+ approx. 500
Lovisenberg Diaconal Hospital approx. 3,500 0*

 

eHandbook healthcare sector

Public document portal – controlled sharing of governing documentation

Many organisations need to make parts of their documentation available to external users, whilst retaining full control over content, versions and publishing. With the public document portal, selected documents from the eHandbook can be published in a dedicated, open eHandbook portal that is accessible via a browser, with no login required. The documents continue to be maintained, approved and revised within the same solution before being published to the public portal.

In the healthcare sector, this is used, amongst other things, to share patient-facing procedures, information about services, collaboration routines with GPs and other stakeholders, and guidelines that are required to be publicly available. When documents are updated in the eHandbook, they are also updated automatically in the public portal, reducing the risk of outdated information being accessible externally.

The public document portal in Certain QMS thus enables secure public access to and sharing of documents, with full traceability and revision control maintained within Certain QMS.

Experiences from Oslo University Hospital

Oslo University Hospital (OUS) was established in 2009 through the merger of Rikshospitalet, Ullevål University Hospital and Aker University Hospital. The hospital is the largest in Europe, with 24,000 employees.

The eHandbook in a large and complex organisation

OUS has used Certain QMS for effective document control since 2010, and demonstrates a mature and considered approach to the use of the eHandbook. With a document base running to tens of thousands of internal documents and daily use by many thousands of employees, the solution functions as a central knowledge platform across disciplines, roles and locations.

Usage is high throughout the year, with continuous lookups of documents that are directly integrated into both clinical and administrative day-to-day work.

Training and role understanding as the key to effective system use

At OUS, considerable emphasis has been placed on training in the use of the eHandbook, and a dedicated internal support function has been established to build user competence over time. Experience shows that the way in which support and guidance are provided has a significant bearing on whether employees become confident and independent in their use of the system.

Rather than completing tasks on behalf of users, the focus has largely been on explaining how different roles should work within the solution and how tasks are carried out correctly. This has contributed to a strong understanding of roles, higher quality in system use and a clear reduction in the number of support requests over time.

Active use and high engagement with content

Usage statistics show that the eHandbook is used by many thousands of employees, with daily views of thousands of documents. Data from OUS also shows that the solution is not merely visited, but actively used throughout the year.

The figures indicate a high degree of engagement with the content, with employees navigating between pages, opening documents, using search and following the structure of the handbook — rather than retrieving individual documents in isolation.

When training supports quality compliance in practice

Training is not, however, solely about learning to use the system itself — it is about ensuring that quality work is genuinely put into practice across the entire organisation. At OUS, the eHandbook is closely linked to e-learning courses and competence plans associated with different roles, so that employees receive training in both their responsibilities and work processes — not just in the features of the solution.

To maintain quality in document work, employees who are to be granted write access must complete mandatory training before access is granted. In addition, checklists within documents are used to support the correct completion of key tasks in day-to-day work, and a refresher shortly after training is recommended to ensure that knowledge is translated into practice.

OUS's public document portal: a national reference for procedures and professional practice

The public document portal at OUS is not only used internally, but is also actively used by other actors in the healthcare sector. Healthcare professionals across the country can look up how OUS approaches various procedures, treatments and interventions, and use this as guidance in their own work. In this way, OUS effectively serves as a national reference for the design of procedures, the content of routines and professional practice across a wide range of areas.

This is closely connected to the role Oslo University Hospital plays in medical research and the training of healthcare professionals in Norway. As a university hospital, OUS contributes significantly to the development of professional standards, and through publicly available documentation this knowledge can be shared broadly across the sector — in a structured, quality-assured and up-to-date manner.

View OUS’s public eHandbook here: ehandboken.ous-hf.no

Taken together, the experiences from OUS demonstrate how the eHandbook can be used as an active tool for building competence, ensuring quality and enabling efficient operations — not merely as a place where documents are stored.

From documentation to quality in practice

In complex organisations, effective document control is a prerequisite for good and efficient management.

Experience from the healthcare sector shows that the true value of the eHandbook is realised when it becomes a natural part of day-to-day work — where employees can easily find current routines and training is closely linked to the governing documentation.

Over time, this contributes to shared practice, fewer errors and a stronger basis for improvement — and experience from Oslo University Hospital and others demonstrates that the right structure, clearly defined roles and active use deliver lasting benefits for the organisation as a whole.

Marte Sunde

Marte Sunde

Business Consultant

Marte Sunde is a Business Consultant for Certain QMS, specialising in quality management and HSE systems. She works at the intersection of operational practice and digital solutions, helping organisations implement and improve management systems that ensure compliance, structure, and continuous improvement.

Quality management with a central framework and local adaptations

Quality management with a central framework and local adaptations

Quality management central frameworks in QMS

When multiple organisations need to collaborate on quality management, a shared challenge frequently arises: how to share structure, requirements and best practice whilst allowing each organisation to adapt the system to its own operations. Whether it involves a group with established HSEQ functions or collaboration between independent organisations, the goal is to strike the right balance between standardisation and local control.

Certain QMS has been developed precisely for this purpose, with a solution that makes it possible to build on a shared quality framework whilst each organisation retains ownership of its own quality management system.

When multiple organisations need to benefit from the same quality framework

In groups and larger organisations with dedicated HSEQ resources, established structures and extensive documentation in the management system typically already exist. The challenge is often to ensure that this content is accessible and straightforward to adopt across all parts of the organisation — across departments and business units.

In alliances and industry collaborations, the starting point is often different. Here, the collaboration typically consists of organisations with limited capacity to develop and maintain a fully functioning quality management system on their own. The need is therefore access to ready-made structures, templates and recommended working methods that can serve as a starting point within their own organisation.

Both situations require a solution that enables quality content to be shared in a structured way, whilst allowing each organisation to adapt the system to its own circumstances and responsibilities.

Support for a shared quality framework with local adaptations

Certain QMS has been developed to support both of these scenarios. The solution can be used both in organisations where shared quality frameworks are defined centrally, and in collaborations where independent organisations have agreed to develop and use shared structures, templates and working methods for quality management.

One master solution – separate quality management systems

A central “master solution” is established, functioning as a shared quality framework with structure, templates and a recommended configuration for the quality management system. The content of the master solution is developed and maintained by a central HSEQ function or a working group with representatives from the various organisations.

Each company receives its own installation of Certain QMS, based on and integrated with the master solution. This provides a shared structure and content, whilst each company has its own users, its own data and full ownership of its own quality work.

In this way, multiple organisations can work within the same quality framework, whilst the system can be adapted to local operations.

How it works

The master solution in Certain QMS can be configured and adapted at several levels, functioning both as a template for system configuration and as a shared starting point for governing documents. These two elements are handled somewhat differently.

Master solution as a template for system structure and modules

Certain QMS consists of several modules for quality management. The master solution can contain ready-made configurations, structures and templates, for example for:

  • Document structure and folder structure
  • Processes and workflows
  • Non-conformity handling and categorisation
  • Risk analyses and risk templates
  • Checklists
  • Annual planners and scheduled activities

When a local installation is created, this configuration is copied from the master solution and used as the starting point for the organisation’s own quality management system.

Once the local installation has been established, the organisation is free to:

  • Modify structures
  • Adjust processes
  • Add or remove content
  • Adapt the system to its own operations

If improvements or changes are subsequently made to the master configuration, these can be transferred to local installations as required — but this is carried out as a managed update, initiated by the system administrator.

This gives the organisation full control over its own quality management system, whilst retaining the option to adopt improvements developed centrally.

Governing documents: continuous synchronisation and local extension

For governing documents, the solution is more dynamic — precisely because this is content that often needs to be kept up to date across organisations.

Documents managed in the master solution are shared with local installations through continuous synchronisation. The system checks at regular intervals whether there are new or revised documents to be made available locally.

 

Examples of governing documents often managed centrally:

  • Top-level policies for quality, HSE and internal control
  • Shared procedures for non-conformity handling and improvement work
  • Guidelines for risk assessment and use of risk matrices
  • Requirements for documentation, traceability and archiving
  • Emergency procedures and notification routines
  • Routines for training and competence assurance
  • Audit programmes and methodology for internal audits
  • Guidelines for supplier follow-up and procurement
  • Templates for work instructions and checklists

 

When documentation is updated centrally:

  • Local users are notified by email
  • They are informed which documents are new or changed
  • It can be assessed whether local adaptations need to be updated

At the same time, each organisation is free to add its own local documents that are not linked to the master solution.

How local extensions work in governing documents

For documents originating from the master, a simple and clear model is used for local adaptation:

The main body of the document is locked for editing, but a dedicated field is available for local clarifications and additions. When this is used, the document is referred to as an extended document.

In this way, the following are preserved:

  • Shared wording and requirements in the main document
  • Whilst local practice can be clearly and correctly documented
Certain QMS eksempel styrende dokument med lokal tilpasning

Example of a governing document where the main content is managed centrally, whilst local clarifications are added in a dedicated field as part of an extended document.

Two purposes – one solution

The master solution in Certain QMS thus supports two distinct needs:

  • as a template for system configuration and quality structure, where local installations are built on a shared foundation
  • and as a shared source for governing documents, with ongoing updates and clear handling of local adaptations

This provides both flexibility in system use and confidence that shared requirements and procedures can genuinely be kept up to date across organisations.

Mirjam Meling

Mirjam Meling

Marketing & Communications Manager

Produces content for Certain QMS on management systems, quality management, information security, and AI governance. She collaborates with subject matter experts to communicate complex topics in a clear and practical way.

Quality management in the power and energy sector

Quality management in the power and energy sector

Certain quality management system kvalitetsarbeid kraft og energibransjen

The power and energy sector is characterised by a level of responsibility that extends far beyond the individual organisation. Grid companies and energy companies manage critical infrastructure, national security and emergency preparedness, often with small organisations and limited resources.

At the same time, strict requirements apply to documentation, traceability, risk management and compliance with laws and regulations. This includes requirements related to emergency preparedness, the handling of grid-sensitive information and compliance with regulations, where availability, confidentiality and information governance are central elements.

Quality management in the sector is not generic

When the quality management system becomes a side project

In this context, quality management is not an administrative support function but a prerequisite for safe operations. Nevertheless, many organisations find that in practice the quality management system becomes something that “sits alongside” the actual day-to-day work. Procedures are documented but rarely used. Checklists exist but lead a life of their own. Risk analyses and emergency plans are seldom updated – not because they are unimportant, but because many quality management systems are not adapted to the need for continuous use in an operational environment. This is a particular challenge in a sector where emergency plans, exercises and measures under the Power Emergency Preparedness Regulation require that documentation is actually up to date, accessible and known throughout the organisation.

A tailored system – not a lack of ambition

Experience from the power and energy sector shows that this challenge is rarely about a lack of will or ambition. It is about whether the quality management system is actually designed for the sector’s structure, responsibilities and ways of working. For power and energy companies, this means choosing a quality management system that not only documents requirements but actually makes them easier to fulfil – in operations, in the field and in emergency situations.

Certain quality management system quality management power and energy sector

Small organisations and major requirements

Many power and energy companies are small and medium-sized enterprises.

They often have few administrative resources, yet are still responsible for:

  • Internal control and document management
  • HSE, emergency preparedness and risk management
  • Compliance with regulations
  • Follow-up of fieldwork, vehicles, equipment and technical installations

In addition, knowledge must be shared, employees kept up to date, and management must maintain oversight, often across roles, disciplines and locations.

Fragmented tools and increasing complexity

The challenge is not a lack of will or competence. The challenge is that many solutions have been developed without sufficient regard for how power and energy companies actually work. The result is often fragmented tools, overlapping documentation and a working environment in which employees must navigate multiple systems to find what they need.

Quality must be a shared working tool

For small organisations, this becomes particularly demanding. When the quality management system is perceived as something separate from the daily work surface, the risk increases that it will only be used by a few – typically quality managers – rather than serving as a shared working tool for the entire organisation.

When the quality management system exists but creates no value

In the power and energy sector, there is rarely a shortage of documentation. Procedures, checklists and routines are often well described and technically sound. Nevertheless, many organisations find that their quality management work does not deliver the desired effect in practice.

The challenge rarely lies in what is documented, but in how it is structured, made accessible and used in everyday work. When the quality management system is perceived as something that exists alongside actual operations, it becomes difficult to ensure that procedures are actually followed, that checklists are used correctly, and that risk and emergency preparedness work is kept alive over time.

Typical signs of this include:

  • Documents that are technically correct but rarely used
  • Checklists completed without a clear link to follow-up and accountability
  • Risk analyses not connected to actual work processes
  • Emergency preparedness documentation that is difficult to locate when needed

When emergency preparedness documentation and information about critical installations is difficult to access in normal circumstances, the risk of mishandling also increases when incidents actually occur – particularly where grid-sensitive information must be shared quickly but in a controlled manner.

Risk to governance, safety and trust

For power and energy companies, where both safety and availability are critical, this is more than a question of efficiency. It is a matter of governance, compliance and trust – both internally and externally. Experience from the sector shows that quality management only creates real value when structure and use are adapted to the organisation’s actual responsibilities, ways of working and risk exposure.

This is precisely where the difference between a quality management system that merely exists and one that genuinely supports operations and emergency preparedness becomes clear. In the next section, we take a closer look at what characterises value-creating quality management in the power and energy sector.

Certain quality management system quality management power and energy sector

Value-creating quality management starts with structure – not volume of documents

In the power and energy sector, it is easy to end up with quality management systems that grow in scope but not in value. New requirements lead to new documents, new routines and new checklists – often without making the overall picture clearer or more usable.

Value-creating quality management takes the opposite approach: structure first, then content. It requires a system built to reflect the organisation’s actual structure, responsibilities and risk profile – not a generic folder or document structure. This is precisely the gap that Certain QMS is built to address: one coherent structure that makes quality management achievable in everyday work – not just correct on paper.

Certain QMS: One integrated system for operations and follow-up

Certain QMS has been developed with this as a central professional starting point. The system is built to connect documents, processes, risk, non-conformances, checklists and annual planning cycles in one coherent structure. This makes it possible to view quality management as a whole, where requirements, measures and follow-up are linked together, and where these connections are visible to both management and employees.

The combination of module interplay and the ability for controlled sharing and local adaptation is one of the main reasons why many power and energy companies choose Certain QMS.

The master solution in practice – shared governance and local adaptation

In the power and energy sector, there is often a strong need for shared practice and clear governance, while at the same time the operational reality varies significantly between companies. Many are organised within corporate groups, partnerships or alliances where responsibilities, regulations and emergency preparedness must be understood in the same way, while actual implementation takes place locally. To achieve this in practice, a model is needed that both provides a shared professional foundation and allows room for local adaptations. This is what we refer to as a master solution – an overarching solution that manages shared content and structure, and which can be distributed in a controlled manner to subsidiary companies.

One solution per company – one shared master

In Certain QMS, this is addressed by giving each company its own solution, tailored to its own organisation, operations and responsibilities. At the same time, a separate master solution can be established that functions as an overarching professional level. This master is used to manage shared structures, procedures, checklists and documentation that are intended to set norms across companies, whether within a corporate group or a sector partnership.

Shared ownership of requirements and regulations

The master solution is typically owned by the corporate group or a central professional team, and represents a shared interpretation of requirements, regulations, roles and responsibilities. This is where overarching documents are maintained and developed. Subsidiary companies can import this content into their own solutions, ensuring they always start from the same professional foundation. In practice, this enables faster onboarding of new companies or units, more consistent compliance and less local maintenance work, while each company retains control over its own operations.

Controlled sharing and version management

An important point is that this does not involve uncontrolled copying of documents. The transfer from the master takes place in a controlled manner, with clear ownership and version management. When master content is updated, companies are notified and can decide how the change should be implemented locally. In this way, shared governance is combined with local decision-making authority.

Local specifications without breaking the structure

At the same time, the solution is built to allow each company to extend and supplement shared content with local specifications. Documents sourced from the master can be expanded with local clarifications, additions and descriptions relating to the company’s own installation types, geographical conditions or ways of working. These local adaptations are added without breaking the connection to the shared content and without losing overall visibility.

Example: Shared emergency preparedness and local reality

A grid company can, for example, take a shared emergency preparedness procedure as its starting point, and supplement it with local descriptions relating to its own transformer substations, grid network or emergency response organisation. What is shared remains recognisable, while local responsibilities are clearly documented in the company’s own solution.

Structured flexibility over time

When the master solution is used in this way, it delivers quality management that is both structured and flexible. Corporate groups or partnerships gain visibility, consistency and the opportunity to learn across the organisation, while each individual company retains ownership of its own operations. For the power and energy sector, where requirements are numerous and the consequences of errors can be significant, this provides quality management that is robust, practical and capable of being used correctly – over time.

Certain QMS system quality management power and energy sector

From shared structure to practical application

When quality management is anchored in a clear master structure, the conditions for how the system is actually used within the organisation change. Structure and content are linked in a way that differs from traditional solutions, and quality management becomes more closely tied to real work tasks and responsibilities.

An integrated part of operations and management

For power and energy companies, this means that requirements for internal control, HSE, emergency preparedness and documentation no longer appear as separate activities, but as an integrated part of operations. When shared procedures, checklists and risk descriptions are established at an overarching level, it becomes easier to put them into practice locally – in planning, execution and follow-up.

Clear frameworks in small organisations

This is particularly significant in small and medium-sized organisations, where the same person often has responsibility for several disciplines. When the quality management system is structured in line with the organisation’s actual structure and ownership, the need to “translate” requirements into practice is reduced. It becomes clear what applies, who is responsible and how work should be documented.

When quality management delivers real value

Over time, this means that quality management feels less like an add-on and more like a support in everyday work. Documents are used more frequently, checklists are followed up more systematically, and the connection between risk, measures and operations becomes clearer. This is where many organisations find that quality management begins to deliver real value.

Quality management that supports safe operations and emergency preparedness

In the power and energy sector, quality, safety and emergency preparedness are closely intertwined. Requirements for availability and security of supply mean that errors, deficiencies or unclear responsibilities can have serious consequences. It is therefore essential that quality management not only documents how things should be done, but actually supports the organisation when it matters most.

Emergency preparedness that is accessible when it matters

When the quality management system is built around a shared structure and clear frameworks, it becomes easier to keep emergency preparedness-related documentation up to date and accessible. Risk analyses, emergency plans and operational procedures can be linked directly to the processes and installations they relate to, making them easier to find and use – even under time pressure.

Systematic improvement based on experience

At the same time, this approach provides better conditions for working systematically on improvement. Experiences from incidents, non-conformances or exercises can be followed up in a way that both addresses local circumstances and contributes to cross-organisational learning. Changes made centrally can be communicated in a controlled manner, while local adjustments are documented where they belong.

Supporting the organisation's public service mission

The result is quality management that more effectively supports the organisation’s public service mission. It gives management better oversight, employees clearer frameworks, and the organisation as a whole greater confidence that requirements for safety, emergency preparedness and compliance are actually met in practice – not just in the documentation.

Certain quality management system kvalitetsarbeid kraft og energibransjen

Secure information flow, sensitivity and access in practice

The power and energy sector handles information that in many cases is security-critical. Documentation relating to installations, emergency preparedness, risk assessments and operational procedures must be accessible to those who need it, while at the same time being protected from unauthorised access. This places high demands on how information is structured, shared and managed over time.

Visibility and labelling of sensitive information

For many power and energy companies, there is also a need to make visible what type of information is actually being handled. In practice, this means being able to label documents and risk analyses with varying degrees of sensitivity – for example, grid-sensitive information. In Certain QMS the organisation can itself establish and manage its own register for sensitivity labelling, adapted to internal needs, regulations and risk assessments.

This labelling follows the document and analysis during viewing and sharing, so that users can clearly see what type of information they are handling and take appropriate care in use, sharing and follow-up. This improves compliance in practice – without compromising accessibility for those who actually need the information. This is particularly relevant in work relating to emergency preparedness, incident management and compliance with requirements for the handling of grid-sensitive information.

Roles rather than individuals

When quality management is built on a clear shared structure, it becomes possible to work more systematically with sensitivity and access. Documents and processes can be linked to roles and responsibilities rather than to individuals, and information can be made available where it is actually needed, without losing control. This is particularly important in organisations where employees move between the office, control room and field.

The right information at the right time

In practice, this means that quality management is not only about content, but also about information flow. When documentation is structured correctly from the outset, it becomes easier to ensure that the right information reaches the right person at the right time. At the same time, the risk of sensitive information being shared inadvertently or remaining inaccessible when most needed is reduced.

For management, this provides better governance and oversight. For employees, it provides confidence in their day-to-day work. And for the organisation as a whole, it contributes to strengthening safety, compliance and trust – both internally and externally.

Seamless integration that lowers the threshold for quality management

One of the biggest challenges in quality management is not a lack of good procedures, but that systems feel distant from the everyday work environment. In small and medium-sized power and energy companies, where time and capacity are limited, this is particularly noticeable. The more tools employees have to deal with, the greater the risk that the quality management system will be deprioritised.

Quality in the existing work surface

With an integration to Microsoft SharePoint, quality management becomes accessible within the same work surface that employees already use. Documents, checklists, non-conformances and tasks become a natural part of the working day, rather than something that requires a conscious decision and extra effort. This is especially important for field personnel, who often need quick access to up-to-date information without having to navigate multiple systems.

Better involvement across the whole organisation

For small organisations, this delivers a significant benefit. Seamless access makes it easier to involve the entire organisation in quality management, not just those with specific professional responsibilities. Over time, this contributes to better compliance, more consistent use of procedures and a stronger quality culture.

When accessibility creates value

When the quality management system is actually used, it also becomes a better basis for improvement. Experiences are captured, non-conformances are followed up, and the organisation gains a more realistic picture of its own practice. For many power and energy companies, this is closely connected to the quality management system being accessible where employees already work – for example through SharePoint as an intranet and work surface. When employees can find procedures, complete tasks and report non-conformances without “switching systems” mentally and practically, the threshold for use is lowered. This is where the connection between structure, accessibility and value becomes clear.

When the quality management system sits within the SharePoint work surface, it effectively becomes part of the intranet and everyday work – not a separate specialist system that only a few people visit.

Certain QMS integration

Cross-organisational learning and continuous improvement in the sector

The power and energy sector is characterised by a high degree of collaboration, whether through corporate structures, alliances or industry partnerships. This creates significant potential for cross-organisational learning, but also a risk that experiences remain local if good mechanisms for sharing are not in place.

Shared structure enables shared learning

When quality management is built on a shared structure and shared frameworks, it becomes possible to extract value from this collaboration. Experiences from incidents, non-conformances, audits and improvement work can be used as a basis for developing shared practice further, without overlooking local circumstances. Over time, this helps to raise the standard across the whole organisation, or across multiple companies.

User forums and professional meeting places

User forums and professional meeting places play an important role here. They provide space for dialogue, experience sharing and the prioritisation of improvements that genuinely make a difference in everyday work. When this is combined with a technical and structural solution that supports sharing, continuous improvement becomes more than an ideal – it becomes a practical way of working.

For power and energy companies, this means increased maturity over time, better handling of regulatory changes and greater confidence in the face of new requirements and expectations.

What this means for power and energy companies going forward

Quality management in the power and energy sector cannot be reduced to documentation alone. It is about structure, ownership and use – and about building solutions that genuinely work in a busy and demanding environment. Experience from the sector shows that when these conditions are in place, quality management changes in character from being an obligation to becoming a tool for governance, safe operations and continuous improvement.

For many companies, this starts with asking some fundamental questions:

  • How is quality management structured today?
  • Is it adapted to the organisation’s responsibilities and risk profile?
  • And do the systems provide support in practice – or only on paper?

In a sector where requirements are high and the consequences of errors can be significant, this is not just a question of efficiency. It is a question of robustness, trust and social responsibility. It is also about compliance with emergency preparedness requirements, trust in critical infrastructure and the organisation’s ability to handle both incidents and inspections in a controlled manner.

For organisations that want a quality management system that is actually used, and that can withstand both audits, operations and emergency situations, it is precisely this holistic approach that Certain QMS is built to support.

Since 2021, Netpower has delivered its quality management system to over 20 grid companies through Nettalliansen’s industry solution – a partnership that has given the sector a shared, standardised quality management platform.

Marte Sunde

Marte Sunde

Business Consultant

Marte Sunde is a Business Consultant for Certain QMS, specialising in quality management and HSE systems. She works at the intersection of operational practice and digital solutions, helping organisations implement and improve management systems that ensure compliance, structure, and continuous improvement.