What the first ninety days of a management system actually look like
Most implementation plans describe an ideal. This one describes what happens, including the month everyone finds difficult.
Ninety days is the standard promise in this category and it is usually made about the wrong thing. A workspace can be stood up in an afternoon. What takes ninety days is arriving at a system that reflects how your organisation actually works, tested by an audit that was allowed to find things.
Here is the shape of it, month by month, with the parts people find hard left in.
Month one: loading what is already true
The first month is about the organisation, not the standard. Departments, sites, processes, who owns what, and the documents that already exist wherever they currently live. Most organisations underestimate how much they have and overestimate how current it is.
The work that matters here is scoping. Every requirement gets marked applicable, excluded with a justification, or deferred with a date. This is the step most implementations skip, and skipping it is why so many management systems feel like a costume. A requirement about outsourced processes means nothing if you outsource nothing, and saying so in writing is what makes the rest of the system honest.
Month two: the first internal audit
The second month runs an internal audit against the scope agreed in the first. Not a readiness check, not a gap analysis with a traffic light chart. An audit, with a plan, an auditor, findings raised properly and nothing softened.
Organisations are often surprised by how many findings come out and read it as a bad sign. It is the opposite. A first internal audit that finds four things has not looked hard enough. What matters is that each finding has an owner, a due date, a recorded root cause and verification by somebody other than the owner.
This month is also when you learn whether the scoping in month one was honest. Requirements marked applicable that nobody can evidence were marked optimistically. Requirements marked not applicable that the auditor disagrees with were marked conveniently. Both get corrected here, cheaply, long before a certification body raises them.
Month three: closing and assembling
The third month closes what can be closed, verifies it, and assembles the readiness pack. The word assembles is doing less work than it looks like, because if months one and two went properly the pack mostly already exists. Evidence was filed against the control it proves as the work happened.
What you have at the end of ninety days is not a certificate. It is a current picture of where you stand, with nothing hidden and nothing flattering, and a system that produces the next picture without a project attached.
What predicts whether this works
- One named person with the authority to agree scope, available for an hour a month. Engagements without this stall in week three.
- Access to what exists today, including the documents nobody is proud of. Working from the tidy subset produces a tidy fiction.
- Leadership willing to see a first audit that finds things. If the first audit has to look good, it will, and it will teach you nothing.
- A decision about the certification body early. The visit date sets everything else, and it is usually booked later than it should be.
What happens after
Months four to twelve are quieter and this is the point. Reviews arrive on schedule, evidence lands where it belongs, findings follow a path that already exists. Year two is quieter again, because the templates, the control set and the evidence cadence already match your organisation.
The measure of a management system is not how it looks at the end of an implementation. It is whether it is still current eighteen months later, when the person who set it up has moved on and nobody has thought about it for a quarter.
