What we do
Quality, risk, governance and compliance — joined up.
Four connected areas of work, each scoped around a business problem and judged on what changes in the organisation.
What we actually do
We make management systems work for the business — not just for the audit.
Four connected areas of work. Each is scoped around a business problem, and each is judged on what changes in the organisation.
Quality
ISO 9001 · IATF 16949 · QMS improvement · internal audits · process effectiveness
Identify weaknesses before customers, regulators or certification bodies do — and turn findings into measurable improvement.
Risk
Enterprise and operational risk · risk-based thinking · controls · assurance
See where the operation is genuinely exposed, and put proportionate controls where they change the odds.
Governance
Management review · accountability · performance oversight · evidence · decision-making
Give leadership a clear line of sight from process performance to the decisions that need making.
Compliance
Gap assessments · audit readiness · regulatory and customer requirements · corrective action
Enter every audit knowing the position, with evidence organised and corrective actions that hold.
Results
What changes after we work with you.
We do not publish guaranteed percentages or financial returns. These are the changes our engagements are designed to produce, and the ones clients tell us matter most.
Where measured client results become available and permission is granted, they are published as full case studies with situation, intervention, result and evidence.
- Greater confidence before external audits
- Clearer ownership and accountability
- Stronger evidence of control
- Better visibility of operational risk
- Fewer recurring problems
- More effective corrective action
- Management systems aligned with actual business processes
- Less time spent firefighting documentation issues
Why leaders trust the approach
Four principles that govern how we work.
You are not buying documentation. You are buying a clearer view of where the system is vulnerable, and practical work to close it.

Evidence over assumptions
Recommendations are based on evidence, process understanding and objective assessment — traceable to records, data and clause requirements.
Practical over paperwork
The objective is not to create documentation for its own sake. If a control does not change behaviour or reduce risk, it does not earn its place.
Business-first thinking
Management systems should support operational performance and decision-making, and be readable by the people who run the business.
Sustainable improvement
The goal is to strengthen the underlying system rather than repeatedly fix the same symptoms, and to leave the capability inside your team.
How we work
A short path from uncertainty to a clear, costed plan.
Four steps, no drawn-out discovery phase. Most clients move from first call to agreed scope within two weeks.
- 01
Strategy session
Twenty minutes on your audit timeline, open findings, and where the system feels thin. No preparation needed.
- 02
Focused assessment
We review the relevant processes and records, then give you a prioritised picture of risk and effort.
- 03
Defined engagement
Scope, deliverables, and price agreed in writing before any work starts. No open-ended retainers.
- 04
Work the plan together
Coaching, closure support, or monthly advisory — delivered with your team in the lead so knowledge stays in-house.
Standards we support
One advisory partner across the standards your customers ask about.
We advise on preparation, interpretation, and maintenance. Certification itself is always issued by an accredited certification body — never by us.
ISO 9001
Quality management systems
IATF 16949
Automotive quality management
ISO 13485
Medical device quality systems
AS9100
Aerospace quality management
ISO 14001
Environmental management
ISO 45001
Occupational health & safety
ISO 27001
Information security management
ISO 22000 / FSSC
Food safety management
Standard names and marks belong to their respective owners. Talk & Trace is an independent advisory practice and is not a certification body, registrar, or accreditation organisation.
Next step
Find out where your management system is actually vulnerable.
A confidential 20-minute conversation with a senior practitioner. You will leave knowing what needs attention first, what it realistically takes to fix, and whether you need outside help at all.
