Why we built one workspace for QMS + ISMS
Quality and security are run by different people in different tools — yet they share most of the same evidence. Here is why we put them on one process map.
The Obligara team ·
Most mid-market service organisations end up running their quality management system and their information security management system as two separate worlds. Quality lives in one place — often Word, Excel and a SharePoint folder. Security lives in another — a GRC tool, or another set of spreadsheets. The two teams rarely touch the same system, and the software actively keeps them apart.
That's strange, because the two frameworks overlap far more than the org chart suggests.
The same evidence, filed twice
A supplier you assess for ISO 9001 purchasing controls is the same supplier you assess for ISO 27001 A.5.19 supplier security. The corrective action you raise after a quality non-conformance has the same shape as the one you raise after a security incident. The management review the quality lead runs and the one the ISMS owner runs pull from overlapping sources. The document control, approval and distribution machinery is identical.
When these live in separate tools, every shared thing gets maintained twice — and the two copies drift. The risk register the security team keeps doesn't know about the process the quality team just changed. Nobody is wrong; the tooling just never let them share a source of truth.
The process map as the spine
We made a different bet: that the process is the natural spine of a compliance programme, and that quality, security and trust are different lenses on the same set of processes.
So in Obligara, every record — a risk, a document, a CAPA, an audit finding, a quality objective, a control — links back to a process. Click a process and you see everything connected to it, across frameworks. The order-fulfilment process carries its quality objectives and its security risks and the controls that protect the data flowing through it.
Why this matters for an audit
When an auditor asks "show me how this process is controlled," you don't assemble an answer from three systems. The process already holds its risks, documents, CAPAs and findings — across QMS and ISMS — in one view.
The journey, not the silo
There's a path most of our customers walk:
- ISO 9001 first. They have a mature quality system and a customer base that expects it.
- ISO 27001 next. A bigger customer, or a tender, asks for information-security assurance.
- SOC 2 after that. A US enterprise deal needs the report Americans recognise.
If each step means adopting a new tool and rebuilding the foundations, the journey is painful and the evidence never compounds. If each step is a module on the same workspace — the same process map, the same audit log, the same permissions — then ISO 27001 reuses what ISO 9001 established, and SOC 2 reuses what ISO 27001 established. The work compounds instead of resetting.
One audit trail, one permission model
There's a quieter benefit to one workspace: one audit log and one access model. Every change — across every framework — writes to the same in-transaction audit log. Access is governed by the same role, per-module and capability model whether you're touching a quality objective or a security control. You don't reconcile three audit trails at review time, and you don't manage three sets of permissions.
What we deliberately didn't do
We didn't build three products and glue them together with a shared login. That's the trap — it looks like one workspace until you try to link a quality CAPA to a security incident and discover they live in different databases. The frameworks in Obligara sit on the same tables, the same audit log and the same permissions, so cross-framework links are real, not cosmetic.
Quality, security and trust were always describing the same organisation. The software should too.
See how the ISO 9001 and ISO 27001 modules share a spine, or book a demo to see it on your processes.