Patient Experience Procedure: Why your 91% Score Misleads

Direct Answer. A patient experience procedure is the documented process by which a healthcare organization determines how service user experience is assessed, from whom, by what method, how the results are analyzed, and where they are reported. Under ISO 7101 Clause 8.10.2, a patient experience procedure must use a valid and reliable methodology with a representative sample in which all groups are equitably included. That single requirement is the one most experience programs cannot demonstrate, because every collection route selects — and the groups a route misses are the groups the clause exists to protect.

The annual assessment comes back at 91 percent positive on equal treatment, from 1,240 responses. It goes to the board as a strong result, and it is a strong result. The patient experience procedure behind it did nothing wrong. The methodology is sound, the instrument is validated, the sample is large, and nobody has done anything wrong.

Then someone disaggregates it. One group returns 54 percent positive on the same domain. That group is 6 percent of respondents and 19 percent of the population the organization serves, and it has been below its response floor for three consecutive periods without anyone deploying an additional route — because there was no per-group floor to fall below. The aggregate was accurate. It was also answering a question nobody had asked.

This is not a story about intentions. It is a story about sampling method and analysis, which are the two things a patient experience procedure is for. Across 200+ audits attended in 28 years, MSI consistently sees experience programs that are well run, well liked, and structurally incapable of answering the question their governing clause asks — a first-party observation from MSI's own audit-attended history rather than a published statistic, offered because the pattern is so consistent.

A note on spelling. ISO 7101 is written in British English and uses service user, people-centred care and behaviours. Where this article names a term as the standard uses it, the standard's spelling is reproduced so you can find it in your own licensed copy. Everywhere else, US spelling. The article also uses patient experience where readers search for it and service user where the standard governs, because the standard's term is broader — it includes families, caregivers and communities, not only patients.


Section 1 · The clause itself

What Clause 8.10.2 Requires of a Patient Experience Procedure

Reach. Disaggregate. Act.

The clause a patient experience procedure exists to discharge, service user experience, sits inside Clause 8.10, People-centred care, in ISO 7101:2023 . That placement is not filing convenience, and it shapes what a patient experience procedure is for. It puts experience alongside compassionate care, inclusivity and diversity, health literacy, co-production and workforce wellbeing — the clause group that defines what people-centred care actually obliges an organization to do rather than to say.

Clause 8.10.2 asks a patient experience procedure to settle four things, and the first is where nearly all the difficulty lives.

  • A valid and reliable methodology covering a representative sample of service users, with all groups equitably included. Two tests, not one: the method must be sound, and the reach must be fair.
  • The experience of families and caregivers assessed in its own right — not as a weaker proxy for the service user's account.
  • Assessment across all service areas, clinical and administrative alike.
  • Determination of whether people are treated equally regardless of characteristics such as sex, gender, age, race, ethnicity, condition and clinical diagnosis — which is a question about differences between groups, not about an overall level.

Direct Answer. ISO 7101 Clause 8.10.2 requires a patient experience procedure to assess service user experience using a valid and reliable methodology across a representative sample in which all groups are equitably included, to assess family and caregiver experience in its own right, to cover clinical and administrative service areas alike, and to determine whether people are treated equally regardless of characteristics such as sex, gender, age, race, ethnicity, condition and diagnosis. The equality determination is the requirement an aggregate score structurally cannot deliver.

Two honest framing points before going further, because anyone building a patient experience procedure deserves both.

ISO 7101 is a young standard. First edition, published October 2023, developed by ISO/TC 304 rather than by the technical committee behind ISO 9001. Certification practice around it is still settling, auditor expectations of a patient experience procedure vary considerably, and there is no accumulated body of interpretation to lean on. That is worth knowing before an organization builds a program around anyone's confident reading of it, including this one.

It carries no regulatory status in the United States. ISO 7101 has not been adopted as an American National Standard; ANSI's role with ISO/TC 304 is to hold the secretariat, which is an administrative function rather than an adoption. The standard is voluntary everywhere. Organizations build a patient experience procedure to this standard because a structured management system beats department-by-department quality, not because a regulator requires it. MSI's overview of the ISO 7101 healthcare quality standard sets out the wider structure, and its work on people-centred care and service user focus covers what top management has to be able to show.

One structural note that saves time. ISO 7101 conforms to ISO's harmonized structure — the same ten-clause architecture as ISO 9001, ISO 14001 and ISO 45001, with identical core text where the core text applies. An organization already running one of those has the scaffolding. What it does not have is Clause 8, which in ISO 7101 is larger and more prescriptive than the operational clause of any other standard in the family, and which is where the patient experience procedure lives. One further difference worth internalizing: the improvement engine is Plan-Do-Study-Act, not Plan-Do-Check-Act. Study rather than check is a deliberate choice, and it is the whole argument of this article in one word.

Section 2 · The requirement almost nobody implements

Equitable Inclusion: Why Every Collection Route Selects

Who. Was. Reached.

Experience assessment is conducted by whatever route is cheapest to operate. A tablet in the discharge lounge. An email to the address on file. A text message survey. Each is defensible, each appears in a perfectly respectable patient experience procedure, and each is a reasonable operational decision made by people trying to reach as many service users as possible on a fixed budget.

Every one of those routes selects.

  • The tablet reaches people well enough to stand at it, and unaccompanied enough to stop.
  • The email reaches people with an address on file, a device, and the literacy and confidence to use both.
  • The text survey reaches people who read the language it was written in.
  • The paper form at reception reaches people who were well enough to attend, which excludes everyone whose experience ended in a transfer.

The selection is systematic rather than random, which is the whole problem for a patient experience procedure. A random shortfall averages out at scale. A systematic one does not, no matter how many responses accumulate. And the groups these methods miss are, with unhelpful consistency, the groups the clause exists to protect — people with limited English, people with cognitive or sensory impairment, people who were sickest, people without stable digital access.

Now put that next to the equality determination the patient experience procedure has to deliver. Clause 8.10.2 requires the assessment to establish whether people are treated equally regardless of characteristics including sex, gender, age, race, ethnicity, condition and diagnosis. An assessment that never reached those populations cannot answer that question. A high aggregate score from a sample that excluded them is not evidence of equitable care. It is evidence of a convenient sampling frame.

An organization serving a population that is 22 percent non-native speakers, running an English-only digital survey, may collect 900 responses and receive 30 from that group. The sample is large. The sample is not representative. Nothing about the score reveals this — only the comparison against the served population does, and nothing in a standard survey workflow performs that comparison.

There is a second structural point for any patient experience procedure that follows immediately, and it is the reason an overall response-rate target does not rescue any of this. An aggregate is the wrong instrument for an equality question. If 90 percent of respondents say yes and the 10 percent saying no are concentrated in a single group, the aggregate reads as a strong result while the finding is precisely the opposite. Clause 8.10.2 names the characteristics for exactly this reason — so the analysis can be run along them.

Which means the response floor in a patient experience procedure has to be set per group, against that group's share of the served population. A program can hold an entirely healthy overall rate while one group responds at a fraction of its share, and an overall floor will never detect it. This is the single highest-yield line the document contains, and it is one sentence long.

The decisions, already made

Twenty-eight years of judgment calls, written down and editable

Most templates restate the clause and stop, which leaves you making every hard decision yourself — the reason you wanted a template. MSI's ISO Procedure Templates and Guides library does the opposite: the per-group response floor is set, the disaggregation categories are chosen, the secondary-route triggers are written, and every bracketed placeholder marks a value that is genuinely yours. Editable Word, worked examples, registers, and a four-level maturity ladder you can score yourself against — across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101.

Browse the ISO Procedure Templates and Guides library

Section 3 · The prerequisite

Knowing Who You Serve Before Choosing a Method

Denominator. First. Always.

Representativeness is a comparison, and a comparison needs two numbers. A patient experience procedure has to hold both. Most organizations have the first — who responded — and have never assembled the second. Without a served-population profile, “representative” is an adjective rather than a test, and a patient experience procedure cannot demonstrate the thing the clause asks it to demonstrate.

Direct Answer. A representative sample in a patient experience procedure is one whose composition matches the served population group by group, not merely one that is large. The test is a comparison: each group's share of respondents against that group's share of the people the organization serves. A sample of 900 with 30 responses from a group that is 22 percent of the population is a large sample and an unrepresentative one, and only the comparison reveals it.

Building that profile is ordinarily a data exercise rather than a research project. The information already exists in the patient administration system, and the work is selecting which dimensions matter and committing to them in writing. Reasonable dimensions include preferred language, age band, service line or care setting, admission route, and whichever of the characteristics named in Clause 8.10.2 the organization records reliably and lawfully in its jurisdiction. That last qualifier is real: what may be collected and reported differs by country and by state, and the procedure should say which dimensions the organization uses and why the others were excluded.

Then the small-numbers problem, which stops more patient experience procedure builds than any other and has a settled answer. Where a group is too small to report without risking identification, the response is to suppress the cell, state that it was suppressed and why, and aggregate over a longer period until the count supports reporting — not to drop the group from the analysis. A group quietly removed from a table because it was inconvenient to report is the group the clause was written for. Suppression is a disclosure control. Exclusion is a finding.

Section 4 · Reaching people the first route missed

Accessible Mechanisms, Tested Rather Than Assumed

Offer. Test. Prove.

Clause 7.4.2, Service user communication, requires communication with service users to be accessible — and accessibility is a property a patient experience procedure has to demonstrate rather than declare. An interpretation line that exists in policy and has never been used at 7pm on a Friday is not an accessible mechanism. It is an intention with a phone number attached.

A patient experience procedure that takes this seriously names the alternative routes in advance, states the trigger that deploys each one, and periodically tests that they work. Practical routes that reach populations digital surveys miss:

  • Assisted completion by someone independent of the care team, offered at the bedside or by telephone.
  • Interpreted completion using the organization's interpretation service, with the interpreter booked as part of the assessment rather than improvised.
  • Easy-read and large-print versions, prepared before they are needed rather than promised on request.
  • Proxy and caregiver routes for service users who cannot respond for themselves — which is not a fallback but a requirement in its own right, discussed below.
  • Structured conversation captured by a staff member who has somewhere to put it, which is the only route that reaches people who would never complete anything.

Two design notes in the patient experience procedure make these routes work rather than merely exist. The trigger has to be automatic — the per-group floor is missed, therefore the secondary route deploys for that group, without anyone needing to argue for the budget in the moment. And the person collecting has to be independent of the care team, because a service user asked about their care by the person who delivered it is answering a different question than the one printed on the form.

Family and caregiver experience is required in its own right. Clause 8.10.2 names it separately, and the distinction matters operationally: for service users who cannot speak for themselves, the family account is not a weaker substitute for the real evidence — it is the only evidence that exists. A patient experience procedure that treats caregiver responses as a lower-quality proxy discounts exactly the data that covers the least-heard population.

Section 5 · The half that gets left out

The Service Areas the Clause Names and Programs Omit

Clinical. And. Administrative.

Clause 8.10.2 requires assessment across all service areas, clinical and administrative. Administrative is stated, and administrative is the half most often missing from a patient experience procedure — not through oversight but through authorship. Experience programs are designed by clinical teams, around clinical encounters, using instruments built to evaluate care.

Registration. Appointment booking. Billing. Records access. Discharge administration. Transport booking. Interpretation booking. These generate a disproportionate share of complaints and almost none of the survey coverage — and they are the part of the pathway where service users most often report being treated as a case number rather than a person. The clinical encounter is frequently the part of the journey people rate most highly and remember least resentfully.

Fixing this rarely requires a second instrument. It requires the service-area list to be written into the patient experience procedure as an explicit inventory, with a named owner for each area and a stated coverage expectation, so that a gap is visible as a gap rather than invisible as an absence. MSI's work on procedure standardization across sites makes the same argument about definitional questions generally: what counts, and against what, are decisions made once and centrally or improvised differently everywhere.

Section 6 · No ISO 9001 equivalent

Two Obligations a 9001-Shaped System Has No Route For

Share. Inform. Report.

These deserve their own section, because an organization bringing a patient experience procedure across from a quality system shaped by ISO 9001 will have no established mechanism for either. Not a weak one — none.

Obligation Clause Why it gets missed
Share results and improvement proposals with internal and external stakeholders 9.1.4, Results ISO 9001 sends satisfaction data to management review and no further. There is no existing route for external sharing, and building one is a governance decision rather than a quality one.
Informing the service user where a nonconformity affects them — required, not discretionary 10.2.2 ISO 9001 leaves customer notification entirely to the organization. Here it is an obligation, which means the procedure needs a threshold, an owner, and a record.

The external-sharing obligation is the one most likely to be argued about when the patient experience procedure is drafted, so it is worth being precise about what it does and does not demand. It is not a requirement to publish everything, and it does not override confidentiality or disclosure law. It is a requirement that the results and the improvement proposals reach stakeholders outside the organization — which for most providers means a defined summary, at a defined interval, through a defined channel, decided in advance rather than negotiated each time under pressure.

The reporting obligation sits inside the experience clause itself. Evaluation of service user experience is to be included in the required management review — which means an organization whose experience data reaches a patient experience committee and stops there has not met the clause, however good that committee is.

Direct Answer. The results of a patient experience procedure must reach top management through management review, not only a patient experience committee, and under Clause 9.1.4 they must also be shared with stakeholders external to the organization along with the improvement proposals arising from them. A committee that reviews the data thoroughly and reports upward informally satisfies neither obligation, because neither is satisfied by good practice — both require a route that can be evidenced.

Where the result has to land

The agenda, the inputs, and minutes that record a decision rather than attendance

Service user experience is a named management review input under Clause 9.3.2, and the experience clause itself puts the reporting obligation there. A review that presents the score and adjourns has met the input half of the requirement and failed the output half. MSI's ISO Management Review Toolkits give you the agenda, the input templates, the decision worksheet, and a minutes format built to evidence decisions — for ISO 7101, ISO 9001, ISO 13485, ISO 14001 and ISO 45001.

See the ISO Management Review Toolkits

Section 7 · Worked example A

The Concern That Was Never a Complaint

Heard. Not. Filed.

A family member mentions to a healthcare assistant, while collecting belongings, that their relative had not understood the discharge instructions. They are not annoyed. They want nothing. The service user themselves says nothing at all.

The only route by which this reaches the patient experience procedure is a remark to someone who has somewhere to put it. A formal complaint would never have been made — and the reason is the point: the service user could not easily have made one. There is no survey response here either, because the service user could not have completed the survey for the same reason they could not follow the instructions.

The investigation finds discharge instructions given verbally at 7pm with no interpretation arranged — a failure no patient experience procedure built on survey returns alone would have surfaced. Separately, the equity analysis has been showing that language group responding at 11 percent of its population share for three periods. Those are the same finding, arriving by two routes, and neither route on its own would have produced it. The remark explains the number, and the number establishes that the remark is a pattern rather than an incident.

Three procedural consequences follow, and all three belong in the patient experience procedure rather than in the complaints process. Frontline staff need a route for concerns that are not complaints, which takes seconds and requires no form. That route has to feed the same analysis as the survey data, not a separate log nobody reads. And the disaggregated response rates have to be visible to whoever is investigating, because that is what turns an anecdote into evidence.

Section 8 · Worked example B

The Score That Concealed the Finding

Correct. Answer. Wrong question.

Return to the 91 percent from the opening. It is worth walking through slowly, because the instinct is to look for the mistake in the patient experience procedure and there is not one.

The instrument was validated. The sample was 1,240, which is large by any standard. The analysis was performed competently and the result reported accurately. The board received a true statement about the organization: across everyone who answered, 91 percent reported being treated equally.

Disaggregated by group, one group returns 54 percent positive on the same domain. It is 6 percent of respondents and 19 percent of the served population — under-represented by a factor of three — and it had sat below its response floor for three consecutive periods without the additional route ever deploying, because the program held a per-program floor rather than a per-group one. Every individual control in the patient experience procedure worked. The architecture did not.

There is a hard-edged implication every patient experience procedure should account for: the under-representation almost certainly understates the problem. The people from that group least able to complete the survey are, on the evidence of every other finding in this article, the people whose experience was worst. The 54 percent is a floor rather than an estimate.

Note how differently the two examples are shaped. A is a single remark that surfaced a systemic failure. B is a correct aggregate that answered the wrong question. A well-run patient experience procedure has to be capable of catching both, and the controls that catch one do not catch the other.

Score your own process first

Find out which of these eight elements your process actually holds

The Customer Satisfaction and Feedback Maturity Check scores your current patient experience procedure across eight elements on a four-level ladder — served-population profile, per-group reach, accessible routes, service-area coverage, disaggregated analysis, external sharing, review reporting and ownership. A few minutes, and it tells you where your patient experience procedure actually sits rather than where you assume it sits.

Score your experience assessment process

Section 9 · The document itself

What a Complete Patient Experience Procedure Contains

Decide. Document. Deploy.

Purpose, scope, references, definitions, responsibilities and records are boilerplate in any procedure, and a patient experience procedure is no exception. What separates a patient experience procedure that works from one that merely exists is whether the following decisions have been made in writing rather than left to whoever runs the program this year.

  • The served-population profile — which dimensions, from which source system, refreshed on what interval, and why the excluded dimensions were excluded.
  • The per-group response floor, expressed against each group's share of the served population rather than as a single overall target.
  • The named alternative routes and their automatic triggers, so a missed floor deploys a route without a fresh budget argument.
  • Independence of the collector from the care team, stated rather than assumed.
  • The family and caregiver route, defined as evidence in its own right with its own coverage expectation.
  • The service-area inventory, clinical and administrative, each with a named owner and a coverage expectation.
  • The disaggregation categories and the small-numbers rule — suppress and state, never drop.
  • The analysis obligation: every reported domain analyzed by group, with the aggregate never reported alone.
  • The management review route, naming the meeting and the standing agenda item.
  • The external sharing route — what summary, what interval, what channel, whose sign-off.
  • The service-user notification threshold under Clause 10.2.2, with an owner and a record.
  • The instrument review trigger, so the question set is examined on named events and not only on the calendar.

Direct Answer. A patient experience procedure differs from a complaints process in who initiates it. Complaints are self-selecting and individually triggered, and they describe the people motivated enough to raise something. A patient experience procedure is organization-triggered and deliberately sampled, and it exists to describe people who will never raise anything. Neither substitutes for the other, and an organization holding only complaints data holds only the loudest end of the distribution.

On the recurring question of whether a validated instrument is required or an organization may write its own: the clause asks for a valid and reliable methodology, which is a property the patient experience procedure has to be able to evidence. A published, validated instrument makes that evidence straightforward. A locally written one is permissible and often better fitted to the service, but the validity and reliability work then belongs to the organization — cognitive testing, a pilot, internal consistency, stability over repeat administration — and the procedure should say which route was taken and where that evidence lives. Most organizations building a patient experience procedure are best served by a validated core with locally added items, which keeps the evidentiary burden proportionate.

And on the boundary that trips people up: a patient experience procedure is not a complaints process. Complaints are self-selecting, individually triggered, and tell you about the people motivated enough to raise something. Experience assessment is organization-triggered, deliberately sampled, and exists to tell you about people who will never raise anything. Neither substitutes for the other, and an organization that has only complaints data has only the loudest end of the distribution. MSI's ISO procedure order guidance covers which documents to write first so the set interlocks rather than cross-references, and the ISO 7101 Overview course covers the framework for anyone new to the standard.

Section 10 · Knowing when to stop

Where Organizations Should Stop

Enough. Is. Enough.

Maturity ladders invite a particular mistake, which is treating the top rung as the target, and a patient experience procedure is a common place to make it.

Level 2 is a legitimate place to stop. A well-implemented certified process sits somewhere around Level 2 to Level 3 and satisfies the clauses completely. In that patient experience procedure the served population is profiled, the floor is per group, the analysis is disaggregated, the results reach management review and one external channel. That is a conforming, useful, defensible patient experience procedure, and an organization that stops there has not cut a corner. Treating Level 4 as the destination is how improvement programs lose credibility — effort goes into instrumentation nobody reads while the basics quietly decay.

There is one exception, and it is the equity analysis. Level 1 on the external sharing route is a gap to close in due course. Level 1 on disaggregation is a different category of problem, because it is the only control that can detect unequal treatment at all, and an organization without it is not making a slower version of the right decision — it is making decisions with the relevant evidence structurally absent, and no other part of the patient experience procedure compensates. That comes first, before anything else on the ladder.

The wider principle holds well beyond the patient experience procedure. MSI's calibration maturity model makes the same case in a very different domain: know which rung you are on, know which rung is enough, and spend the difference where it matters more.


Section 11 · Questions and answers

Patient Experience Procedure FAQ

Ask. Answer. Apply.

What is a patient experience procedure?

A patient experience procedure is the documented process defining how service user experience is assessed, from whom, by what method, how the results are analyzed, and where they are reported. Under ISO 7101 it discharges Clause 8.10.2 within the people-centred care clause group, and it carries the reporting and sharing obligations that attach to the results under Clauses 9.1.4 and 9.3.2.

What does ISO 7101 mean by equitable inclusion?

That all groups within the served population are reached by the assessment, not merely permitted to respond to it. It is a reach test rather than an access test. Since every collection route selects systematically, a patient experience procedure demonstrates equitable inclusion by comparing who responded against who was served, group by group, and deploying an additional route where a group falls short of its share.

Do we have to assess administrative services?

Yes. Clause 8.10.2 requires assessment across all service areas, clinical and administrative. Registration, booking, billing, records access, discharge administration and transport are named in almost no patient experience procedure and generate a disproportionate share of complaints, which is a reliable sign that the experience there is not what the clinical scores suggest.

Is a validated instrument required, or can we write our own?

Either is permissible for a patient experience procedure, but the evidence burden differs. The clause requires a valid and reliable methodology, and a published validated instrument supplies that evidence directly. A locally written instrument is permissible, and the validity and reliability work then belongs to you — cognitive testing, a pilot, internal consistency and stability across administrations. A validated core with locally added items is the proportionate answer for most organizations.

What do we do when a group is too small to report without identifying people?

Suppress the cell, state that it was suppressed and why, and aggregate over a longer period until the count supports reporting. Do not drop the group from the analysis. Suppression is a disclosure control applied to a result you hold; exclusion means you never produced the result. Set the threshold in the patient experience procedure in advance so it is a rule rather than a judgment made under pressure.

Does ISO 7101 require us to publish our results?

It requires results and improvement proposals to be shared with stakeholders internal and external to the organization under Clause 9.1.4. That is not the same as publishing everything, and it does not displace confidentiality or disclosure law. In practice it means a defined summary, at a defined interval, through a defined channel, decided in advance — and it is the obligation a system shaped by ISO 9001 has no existing route for.

How does this compare to the ISO 9001 requirement?

ISO 9001 Clause 9.1.2 asks for monitoring of customer perception of the degree to which needs and expectations have been fulfilled, and leaves sampling, analysis and reporting entirely to the organization. ISO 7101 specifies the sampling test, names the characteristics the analysis must run along, names the service areas, and requires external sharing. A patient experience procedure therefore carries obligations a customer satisfaction procedure does not, and ISO 7101 is the more prescriptive of the two by a considerable margin. MSI's companion pillar on the customer satisfaction procedure under ISO 9001 and ISO 13485 works through the general-product and medical device versions.

Related reading and matching templates

Talk it through

One call, and you will know which two changes are worth making first

A planning session is a working conversation about your actual program — who you reach, who you miss, how the analysis runs, and where the results land. No presentation, no pitch. MSI has attended 200+ certification and surveillance audits across 28 years, supported 80+ certifications and trained 600+ professionals, and most of what is worth changing in a patient experience procedure turns out to be two or three specific decisions.

Call 760-434-9141

Starting at board level? Watch the ISO Executive Decision Briefs — short leadership training videos on what a management system decision actually commits you to. Already certified and want the system maintained year-round? See SureResults. And if you want experienced eyes on the whole document set, MSI's ISO consulting practice does exactly that.

References and primary sources

Clause titles and numbering verified against the published ISO 7101:2023 contents on August 7, 2026. Clause references are provided so readers can locate each requirement in their own licensed copy; the standard itself is not reproduced. This article is guidance, not legal, clinical or regulatory advice.

About the author

Diana Lynn · Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com · 760-434-9141 · Veteran-owned and female-owned.

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply