Instantiation questionnaire — one sheet to populate the whole system¶
Maintained page — not a controlled document; kept current alongside the template. Completed per client organisation; the filled copy belongs to the instance, never to the template. Use of the template and this sheet is subject to the Disclaimer & terms of use.
This template is deliberately full of blanks: substitution tokens (the organisation's name, its document prefix, its role titles) and decision markers (the bracketed ORG-DECISION and NEEDS INPUT notes) at every point where a generic document would otherwise pretend to know something about your organisation. This sheet gathers all of them in one pass, grouped by topic rather than by document — so the person who knows the answer sees all their questions together, once.
How this works¶
- Complete this sheet — sections name who should answer them. Expect 2–3 hours in total across the right people, most of it in sections D–F.
- Return it to your consultant. An agent working in the repository then runs the V1 population: it builds the parameterisation profile from your answers, substitutes every token, resolves every decision marker your answers cover, and drafts the longer passages (policy wording, offer definitions) from what you wrote — never from imagination.
- Review the drafts. Everything lands as Draft through the normal pull-request lifecycle. Nothing is approved by the agent, ever — approval is a named human's merge.
- Anything you marked
LATERsurvives in the documents as a visible marker: the honest tailoring worklist, not a hidden gap.
Conventions
- Write answers after each Answer: prompt, or in the Your answer column of a table.
- Where a default is shown, leaving the answer blank accepts it. The defaults are sensible for a small professional-services firm; override anything that doesn't match how you actually work.
- Write
LATERif you genuinely can't answer yet. Never guess — an honest gap is recoverable; a confident wrong answer ends up in an audited document. - Facts only. Anything legal or jurisdiction-specific you provide here is a starting point: it is verified against authoritative sources during instantiation before it enters any document.
A. Organisation identity and systems¶
Answered by: top management or whoever holds the company details. ~10 minutes.
A1 — Trading name. The name used day-to-day on reports and proposals.
Answer:
A2 — Registered legal name (if different).
Answer:
A3 — Document ID prefix. 2–4 letters; every controlled document gets an
ID like EX-001.
Answer:
A4 — Email/web domain (e.g. example.com).
Answer:
A5 — Headcount — everyone the system touches: employees and regular contractors.
Answer:
A6 — What the organisation does, in a short paragraph: services, typical clients, how work reaches you and leaves you. This steers the whole tailoring pass — write it the way you'd brief a new starter.
Answer:
A7 — Sites. Every place work happens under your control: offices (city is enough — street addresses live in the registers, not documents), client sites, field work, vehicles, home-based work.
Answer:
A8 — Operating jurisdiction(s) — where you operate, state/territory level (e.g. "Australia (QLD)"). Work-health-and-safety law attaches here.
Answer:
A9 — Private GitHub repository URL for the instance (LATER is fine —
needed before go-live, not before drafting).
Answer:
A10 — Airtable workspace (paid tier — the register automations need
it). LATER is fine.
Answer:
B. Capability switches¶
Answered by: top management. ~5 minutes. Switching an area off excludes it from scope with a written justification — never silently.
B1 — Do you design or develop services/products? Test: do you create new service methods or products to a client's requirements (not just deliver an established service)? Yes switches on the ISO 9001 8.3 design & development procedure. If yes, also say what triggers design treatment versus routine delivery of a standard offering (new service offerings? custom solutions above a certain size?).
Answer (yes/no; if yes, what you design and what triggers it):
B2 — Do measuring instruments matter to your results? (e.g. PID meters, water-quality meters, GPS, survey equipment.) If yes: list the instrument types and any handling/storage rules they need (calibration scheduling is handled by the register).
Answer:
B3 — Rendered intranet site? Default is reading the documents directly in GitHub (free, private). A styled internal website build is optional.
Answer (GitHub-native / rendered site):
C. People, roles and worker voice¶
Answered by: top management; C3 belongs to the workers. ~15 minutes.
C1 — The five accountability roles. One person may hold several roles. Hard constraint the system enforces: on any document, the owner is never the approver and the reviewer is never the approver — so at least two people must be able to act on any document. Names and emails go into the profile and the People register only, never into documents.
| Role | Your job title for it | Held by (name) | |
|---|---|---|---|
| Top management (the accountable leader) | |||
| Quality manager | |||
| OH&S coordinator | |||
| Document controller | |||
| Worker H&S representative |
C2 — Internal auditors. The audit programme runs as 12 small monthly slices, and each slice's auditor must be independent of the area audited (you can't audit your own work). List the people available to audit, and which areas each one runs (and therefore can't audit). If no one is independent for some area, say so — borrowing an external auditor for that slice is a legitimate answer.
Answer:
C3 — How the Worker H&S Representative is chosen, and for how long.
This is the workers' decision, not management's — if it hasn't been put to
them yet, write LATER and hold a short worker meeting rather than
answering on their behalf.
Answer:
C4 — What training the representative gets, and how often it refreshes (jurisdictions often prescribe an approved course — verified during instantiation).
Answer:
C5 — Contractor training recognition. May a contractor's equivalent training from their own employer count toward your requirements, and on what evidence (certificate, statement from their employer)?
Answer:
C6 — Stop-work wording. How should the rule that anyone may stop unsafe work be worded and delivered for your actual work (toolbox talk, induction line, site card)? The rule itself does not change; only how you say it and where people meet it.
Answer:
D. What you sell and who buys it¶
Answered by: top management / whoever owns client relationships. ~30 minutes — this section does the most work downstream.
D1 — Your services, in your own commercial language. The list a client would recognise from your proposals. This becomes the scope statement's covered-services list.
Answer:
D2 — Confirm the boundary. Everything from A7 that involves work under your control is inside the management system — including field work, vehicles and home-based work if they exist. List anything you believe sits outside the boundary and why.
Answer:
D3 — Your offers: each service × the market that buys it. One row per offer (e.g. "Contaminated land site investigations — property developers"). For each: what does this buyer judge success by (turnaround? plain-language reporting? defensibility to a regulator?), and how does your delivery satisfy that? Two or three honest sentences per offer beat a page of aspiration — this seeds the offer definitions document.
| Offer (service — market) | What this buyer judges success by | How you deliver against that |
|---|---|---|
D4 — Claims you can currently substantiate, per offer: turnaround times you actually hit, accreditations you actually hold, coverage you actually provide. Claims you aspire to don't go in documents.
Answer:
D5 — Outputs later checking can't verify. Do any services produce
results that can't be re-checked afterwards (one-off field observations,
destructive sampling, live interventions)? If yes, list them — they need
qualified methods and competence rules. If not, write none.
Answer:
D6 — (Only if B1 = yes) Design change authority. Who may authorise a design change at each level — e.g. design lead for minor changes, quality manager for changes affecting verified results, top management for safety-critical or contractual changes?
Answer:
E. Legal touchpoints — starting points only¶
Answered by: whoever handles compliance/insurance. ~15 minutes. Everything here is verified against authoritative sources during instantiation; the system never takes legal content on memory — yours or an AI's.
E1 — Regulators and instruments you already know. Your WHS regulator, the statutes/regulations/codes of practice you know apply, licences or accreditations you hold, client-imposed or professional commitments you've signed up to. Name what you know; instantiation completes and verifies the list from source.
Answer:
E2 — Shared workplaces. Do you work on sites controlled by others, or host others on yours (contractors, client staff)? Coordination duties with other duty-holders attach here.
Answer:
E3 — Legal-update subscriptions you already receive (regulator mailing lists, legislation alert services, professional body updates).
Answer:
E4 — Notifiable incidents. Your current understanding of what you'd have to report to the regulator and how fast (verified at instantiation — this also feeds the emergency plan's notification steps).
Answer:
E5 — Record retention obligations you know of — legal or contractual minimum retention periods for any record category (project files, safety records, financial).
Answer:
E6 — Insurance you require of contractors — types and minimum cover
(public liability, professional indemnity, workers' compensation), if you
have a standing rule. Contract- and jurisdiction-dependent; LATER is
common here.
Answer:
F. Strategy, risk appetite and context¶
Answered by: top management. ~30 minutes. The long-form answers here are the difference between a policy that reads generic and one that reads like you.
F1 — Strategic direction, three prompts (feeds the Quality & OH&S Policy so it demonstrably fits your organisation — two or three sentences total is enough):
- The markets or service lines you're growing into:
- The reputation you trade on (what clients say when they recommend you):
- The thing that would hurt the business most if quality or safety failed:
Answer:
F2 — Policy availability. Publish the Quality & OH&S Policy on your website, provide it on request to clients/regulators, or both? (Publishing changes its classification to Public.)
Answer:
F3 — Scope statement publication. Additionally published externally (useful for tenders/certification), or internal only?
Answer:
F4 — Stop-work authority. Does every worker hold explicit authority to stop their own work when they judge it unsafe? Recommended: yes. Saying yes here puts it in the scope statement's leadership commitments.
Answer:
F5 — Interested parties beyond the obvious. Clients, workers and regulators are already covered. Who else matters here — insurers, industry associations, neighbours and the public near work sites, workers' families, lenders, landlords?
Answer:
F6 — Do the standard context categories fit? The context document frames your environment as: clients & market, workforce, regulators & law, suppliers & contractors, community. Confirm, rename, or add categories so it matches how you actually think about your world.
Answer:
F7 — Your context, honestly. Four prompts for the internal/external issues register (dot points are fine):
- What's changing in your market or client base right now?
- What internal strengths does the business rely on?
- What internal fragilities worry you (key-person dependence, systems, cash-flow seasonality)?
- What external forces could change how you work (regulation, technology, climate/weather, competition)?
Answer:
F8 — Risk matrix calibration. The 5×5 matrix ships with default anchors: likelihood from "not expected within 10 years" (Rare) to "several times a year" (Almost certain); consequence from "first-aid-only / negligible rework" (Insignificant) to "fatality / business-threatening" (Severe). Do these fit your scale of operations, turnover and workforce? If not, say what a Moderate and a Major consequence look like in your terms (dollars, client impact, injury severity).
Answer (blank = defaults fit):
F9 — Risk appetite. Default: a residual Medium is acceptable with the row owner's documented sign-off; a residual High or Extreme requires top management's explicit acceptance or a treatment plan. Tighten or confirm.
Answer (blank = accept default):
F10 — High/Extreme close-out rule. Default: administrative or PPE controls alone can never close out a High or Extreme rating — a higher-order control or formal top-management acceptance is required. Confirm or tighten (this rule cannot be loosened).
Answer (blank = accept default):
G. Operating rhythm and communication¶
Answered by: top management with the OH&S coordinator. ~15 minutes.
| # | Question | Default | Your answer |
|---|---|---|---|
| G1 | Management review & audit shape: 12 short monthly slices, or quarterly sessions (very small orgs)? | Rolling monthly | |
| G2 | How often may two adjacent monthly slices be combined into one session per yearly cycle? | Twice per cycle | |
| G3 | How often does everyone hear objectives progress? | Quarterly all-hands | |
| G4 | How often does everyone hear quality performance & customer feedback themes? | Quarterly | |
| G5 | Channel for announcing approved document changes? | — (e.g. team chat, email digest) | |
| G6 | Toolbox-talk / worker consultation cadence? | — (weekly or fortnightly, match the tempo of field work) | |
| G7 | Any languages or accessible formats your workforce needs? | None | |
| G8 | Month of the annual training-curriculum review? | — (align to objectives cycle) | |
| G9 | Process indicators to watch monthly? | On-time delivery, review-stage completion, rework rate | |
| G10 | How is customer satisfaction measured, how often, and how do you sample small repeat clients? | Short structured follow-up per completed job | |
| G11 | Mechanism for requesting feedback on every completed job? | Standing post-job feedback email | |
| G12 | Any audit areas worth auditing more than once per yearly cycle? | None — the cycle covers every area once |
H. Day-to-day mechanics¶
Answered by: whoever runs delivery/operations. ~25 minutes. These make the procedures describe your actual practice instead of a textbook's.
H1 — Job files. Where does a job's record live and what's its standard structure (folder per job in a document system, record in a project-management tool)?
Answer:
H2 — Job numbering. The scheme and where identifiers are issued.
Answer:
H3 — Deliverable status marking. How does anyone tell a draft deliverable from a released one — filename convention, document control block, or a status field in the job system?
Answer:
H4 — Release authority. Who signs work out the door by default — the quality manager, or a nominated senior reviewer per service line?
Answer:
H5 — Minor in-job changes. May small scope/method changes be authorised below the default authority, and by whom?
Answer:
H6 — Error-proofing you already do beyond review (system validation rules, paired field work, checklists)?
Answer:
H7 — IT arrangement. In-house or managed provider, and the core systems delivery depends on.
Answer:
H8 — Backups. What's covered, frequency, retention, and how restoration is proven (a restore test that never runs is not a backup regime).
Answer:
H9 — Vehicles. Fleet, allowances, or private-vehicle-for-work — and who verifies servicing.
Answer:
H10 — Premises issues. Who/where do people report building and facilities problems?
Answer:
H11 — Procurement records. Where purchase and contract artifacts are stored.
Answer:
H12 — Where project knowledge lives so it's findable, not tribal (filing structure, runbooks, code repositories, client notes).
Answer:
H13 — Re-acknowledgement rule. When an acknowledgement-required policy gets a major revision: always rerun the acknowledgement campaign, or only when the approver judges the change material?
Answer (always / approver judges):
H14 — Document access for non-GitHub staff — read-only accounts provisioned at onboarding, or controlled distribution of rendered copies?
Answer:
H15 — Confidential documents. Handling rule for Confidential-classified material (restricted repository, access list)?
Answer:
H16 — Root-cause method by severity. Default: 5-why for low severity; structured causal analysis for high/notifiable.
Answer (blank = accept default):
H17 — Workplace inspections. Cadence and scope suited to your operations (offices vs field sites differ).
Answer:
H18 — Change log. Keep pre-implementation change records in one single log location, or with each job/document (the default)?
Answer:
H19 — Concession authority. Who may accept delivering a nonconforming output to a client? Default: quality manager, escalating to top management where the client relationship or safety is engaged.
Answer (blank = accept default):
H20 — Contract commitment thresholds. Routine quotes get a one-person checklist review; novel, high-value or unusual-terms work gets a deliberate review meeting. Where's the line (value, risk, non-standard terms), and who holds commitment authority at each level?
Answer:
H21 — Outsourced processes. Which processes, if any, does an external
party perform on your behalf that affect your deliverables or safety (lab
analysis, drafting, IT, specialist subcontracting)? None is a fine
answer.
Answer:
H22 — What you typically buy. The categories of goods and services you routinely purchase (subconsultants, laboratory testing, field contractors, software, plant hire). This sets the shape of the procurement procedure's scope.
Answer:
I. Emergencies¶
Answered by: OH&S coordinator with top management. ~10 minutes.
I1 — Your real field emergency types — not generic ones. (Medical emergency in a remote area? Vehicle incident on unsealed access? Severe weather on site? Lost contact with a lone worker? Client-site evacuation? Hazardous materials?)
Answer:
I2 — First aid officers — who is trained today (names go to the People register), and is coverage adequate for field teams?
Answer:
I3 — Muster/assembly point for each fixed site.
Answer:
I4 — Drills. Default: office evacuation drill annually, plus one field-scenario exercise annually rotating through the I1 emergency types.
Answer (blank = accept default):
J. Targets¶
Answered by: top management. ~10 minutes. Targets only — baselines are deliberately not asked (see L1).
| # | Company-wide objective | Suggested target | Your target |
|---|---|---|---|
| J1 | Customer satisfaction | Average rating ≥ 4.0 of 5 | |
| J2 | Right-first-time delivery | Sustained downward nonconformity trend vs baseline | |
| J3 | Corrective actions close on time and work | ≥ 90% closed by due date with effectiveness check | |
| J4 | Injury & ill-health prevention | Zero lost-time injuries | |
| J5 | Hazard reporting (leading indicator) | Set N reports/quarter, trending to routine | |
| J6 | Hazards controlled promptly | 100% of High/Extreme within an agreed timeframe — state the timeframe per rating | |
| J7 | Training currency | ≥ 95% of people fully in date | |
| J8 | Programme runs on schedule | 100% of review/audit slices in the month due, slips recovered next month |
J9 — Offer-level objectives ("sleeves"). Later, management review may pick offers for their own objective sets. What would make an offer worth one — delivery volume, strategic priority, distinct buyer needs, a usable data source?
Answer (blank = accept those four criteria):
J10 — How many sleeves at once? Default: 1.
Answer (blank = 1):
K. Tempo defaults¶
Answered by: anyone senior, in one sitting. Blank = accept the default. These are working rules, not aspirations — override any your team can't actually meet.
| # | Window | Default | Your answer |
|---|---|---|---|
| K1 | Log a new enquiry/variation within | 2 working days | |
| K2 | Complete a contract-review exception within | 5 working days | |
| K3 | Design-procedure exception validity | 90 days | |
| K4 | Service-delivery exception validity | 90 days | |
| K5 | Supplier re-evaluation cadence | Annual (High criticality); each engagement (Medium); on issue (Low) | |
| K6 | Retrospective evaluation of an emergency-engaged supplier within | 14 days | |
| K7 | Respond to external OH&S communications within (statutory timeframes always win) | 10 working days | |
| K8 | Communication-procedure exception validity | 90 days | |
| K9 | Evaluate training effectiveness after | 3 months | |
| K10 | Training-procedure exception validity | 30 days | |
| K11 | Instrument currency checks (legislation still current?) | Annual; more often for fast-moving instruments | |
| K12 | Every compliance obligation evaluated at least | Annually (one run, or sliced across the year) | |
| K13 | Triage a new hazard report within | 2 working days | |
| K14 | Compliance-procedure exception validity | 90 days | |
| K15 | Acknowledgement campaign deadline | 10 working days | |
| K16 | Document-control exception validity | 90 days | |
| K17 | Start an incident investigation within (injury / high-potential near miss) | 2 working days | |
| K18 | Retrospectively assess an emergency change within | 5 working days | |
| K19 | Corrective-action timeframes by severity | e.g. High/notifiable 7 days, Medium 30, Low 90 — set yours | |
| K20 | A Draft document is stale after | 30 days | |
| K21 | An Approved document is reviewed every | 365 days | |
| K22 | Procurement-procedure exception validity | 90 days | |
| K23 | Maximum deferral of an audit slice | One month | |
| K24 | Maximum stretch of the full audit cycle | 14 months |
L. Deliberately not asked here¶
Honesty items — this sheet doesn't ask what can't honestly be answered yet:
- L1 — Baselines. Every objective's baseline reads "first full measurement period" until it has actually been measured. A baseline invented in a questionnaire is fiction; leave them to fill themselves.
- L2 — The first sleeve. Offer-level objectives are adopted by a recorded management-review decision after go-live — pre-selecting one here would fake that record.
- L3 — Training content. Induction content, self-check questions and the authors' sandbox exercise are drafted by the agent from your A–I answers, for your review — they're outputs of this sheet, not inputs.
- Form URLs — exist only after the Airtable forms are built.
- Register seeding — people, training items and legal instruments are register work, not document text. Have ready: a staff & contractor list, your training items, and any existing legal/obligations register.
What happens when this sheet comes back¶
For the consultant/agent running the V1 population — the contract:
- Build
org-profile.ymlfrom sections A–C; run the token substitution pass; apply the B switches (an area switched off gets a written scope exclusion, drafted for approval). - Resolve every decision marker mapped in the appendix below from the
corresponding answer.
LATERanswers leave the marker in place — they are the tailoring worklist. - Draft the long-form passages (policy strategy wording from F1, offer definitions from D3–D4, context issues from F5–F7) only from the answers given. Legal content (E, I) enters documents only after verification against authoritative sources.
- Everything lands as Draft via pull request; the named approver's merge — a human's — is the only approval there is.
- The instantiation checker must end the pass with zero unresolved tokens;
surviving markers must equal exactly the set of
LATERanswers.
Appendix — coverage map¶
Machine contract for the population pass, checked in CI by
tools/check_questionnaire.py: every decision marker in the documents must
be claimed by a row here (matched on file + the marker's opening words).
Adding a marker to a document means adding a row — and usually a question —
here. Not for filling in.
| Item | Document | Marker text begins |
|---|---|---|
| A5 | ims-objectives-improvement-plan.md | headcount |
| B1 | design-development-procedure.md | the concrete triggers that put a piece |
| B2 | monitoring-measurement-calibration-procedure.md | instrument handling specifics |
| C1 | ims-scope-statement.md | the role-to-person mapping is maintained in the People |
| C2 | internal-audit-procedure.md | independent role |
| C2 | internal-audit-procedure.md | external auditor support |
| C3 | communication-consultation-participation-procedure.md | how the representative is chosen by workers |
| C4 | communication-consultation-participation-procedure.md | the representative training provided |
| C5 | competence-training-awareness-procedure.md | whether a contractor's equivalent training |
| C6 | competence-training-awareness-procedure.md | the wording and delivery of this stop-work rule |
| D1 | ims-scope-statement.md | list the product and service types |
| D2 | ims-scope-statement.md | list every location where work under |
| D3 | product-market-offer-definitions.md | replace the worked example below with |
| D4 | product-market-offer-definitions.md | list only claims |
| D5 | operational-control-service-delivery-procedure.md | whether any of the organisation's services produce such outputs |
| D6 | design-development-procedure.md | change authorisation thresholds |
| E1 | context-interested-parties-compliance-obligations.md | confirm the applicable statute and regulations |
| E1 | context-interested-parties-compliance-obligations.md | identify at instantiation |
| E1 | context-interested-parties-compliance-obligations.md | confirm at instantiation |
| E1 | context-interested-parties-compliance-obligations.md | at instantiation, identify the |
| E1 | customer-requirements-contract-review-procedure.md | the statutory and regulatory requirements applicable |
| E2 | context-interested-parties-compliance-obligations.md | confirm jurisdiction-specific coordination duties |
| E3 | compliance-obligations-procedure.md | the jurisdiction-specific subscription and alert services |
| E4 | incident-reporting-investigation-procedure.md | the jurisdiction's notifiable |
| E4 | emergency-preparedness-response-plan.md | confirm the notification obligations |
| E5 | document-record-control-procedure.md | minimum retention periods for record categories |
| E6 | procurement-contractor-management-procedure.md | required insurance types and minimum cover |
| F1 | quality-ohs-policy.md | add one or two sentences tying this policy |
| F2 | quality-ohs-policy.md | choose the availability mechanism |
| F2 | communication-consultation-participation-procedure.md | whether also published, e.g. on |
| F3 | ims-scope-statement.md | whether the scope statement is additionally published externally |
| F4 | ims-scope-statement.md | whether all workers hold explicit authority to stop |
| F5 | context-interested-parties-compliance-obligations.md | other parties relevant to this organisation |
| F6 | context-interested-parties-compliance-obligations.md | The category set below is a starting frame |
| F7 | context-interested-parties-compliance-obligations.md | populate at instantiation from the context review session |
| F8 | risk-opportunity-hazard-methodology.md | calibrate both the likelihood frequencies |
| F8 | risk-opportunity-hazard-methodology.md | calibrate to operations |
| F9 | risk-opportunity-hazard-methodology.md | default — a residual Medium is acceptable |
| F10 | risk-opportunity-hazard-methodology.md | confirm or tighten this rule at instantiation |
| G2 | management-review-procedure.md | combination limit |
| G3 | communication-consultation-participation-procedure.md | cadence, e.g. quarterly all-hands |
| G4 | communication-consultation-participation-procedure.md | cadence, e.g. quarterly |
| G5 | communication-consultation-participation-procedure.md | the announcement channel, e.g. team chat or email digest |
| G6 | communication-consultation-participation-procedure.md | cadence — e.g. weekly or fortnightly |
| G7 | communication-consultation-participation-procedure.md | the languages, accessible formats, and delivery adjustments the workforce requires |
| G8 | competence-training-awareness-procedure.md | the month of the annual curriculum review |
| G9 | monitoring-measurement-calibration-procedure.md | process indicators |
| G10 | monitoring-measurement-calibration-procedure.md | method and cadence |
| G11 | ims-objectives-improvement-plan.md | mechanism, e.g. a standing post-job feedback email |
| G12 | internal-audit-procedure.md | which slices repeat within a cycle |
| H1 | customer-requirements-contract-review-procedure.md | the organisation's job-file system and location |
| H1 | operational-control-service-delivery-procedure.md | where job files live and their standard structure |
| H2 | operational-control-service-delivery-procedure.md | the job numbering scheme and where identifiers are issued |
| H3 | operational-control-service-delivery-procedure.md | the marking mechanism: a filename convention |
| H4 | operational-control-service-delivery-procedure.md | the default release authority |
| H5 | operational-control-service-delivery-procedure.md | lower authorisation threshold for minor in-job changes |
| H6 | operational-control-service-delivery-procedure.md | any further error-proofing measures |
| H7 | operational-control-service-delivery-procedure.md | the organisation's IT arrangement |
| H8 | operational-control-service-delivery-procedure.md | the backup and recovery regime |
| H9 | operational-control-service-delivery-procedure.md | the vehicle arrangement — fleet, allowances |
| H10 | operational-control-service-delivery-procedure.md | the role or channel responsible for premises issues |
| H11 | procurement-contractor-management-procedure.md | where procurement and contract artifacts are stored |
| H12 | competence-training-awareness-procedure.md | where project/delivery knowledge is held |
| H13 | document-record-control-procedure.md | whether a major revision of an |
| H14 | document-record-control-procedure.md | the access mechanism for workers and contractors |
| H15 | document-record-control-procedure.md | handling rule for Confidential-classified documents |
| H16 | incident-reporting-investigation-procedure.md | 5-why for low |
| H17 | risk-opportunity-hazard-methodology.md | set inspection cadence and scope to suit operations |
| H18 | management-of-change-procedure.md | single change-log location |
| H19 | nonconformity-corrective-action-improvement-procedure.md | concession authority; default |
| H20 | customer-requirements-contract-review-procedure.md | the value and risk thresholds |
| H21 | procurement-contractor-management-procedure.md | which processes, if any, are currently outsourced |
| H22 | procurement-contractor-management-procedure.md | the organisation's typical purchase categories |
| I1 | emergency-preparedness-response-plan.md | the organisation's real field emergency types |
| I2 | emergency-preparedness-response-plan.md | nominated trained roles |
| I3 | emergency-preparedness-response-plan.md | location |
| I4 | emergency-preparedness-response-plan.md | the default is an office evacuation drill |
| J1 | ims-objectives-improvement-plan.md | average rating at or above |
| J2 | ims-objectives-improvement-plan.md | sustained downward trend against baseline |
| J3 | ims-objectives-improvement-plan.md | at least 90% |
| J4 | ims-objectives-improvement-plan.md | zero lost-time injuries |
| J5 | ims-objectives-improvement-plan.md | at least N reports per quarter |
| J6 | ims-objectives-improvement-plan.md | timeframe by inherent rating |
| J6 | ims-objectives-improvement-plan.md | 100% of High/Extreme within timeframe |
| J7 | ims-objectives-improvement-plan.md | at least 95% |
| J8 | ims-objectives-improvement-plan.md | 100%, with any slip recovered next month |
| J9 | ims-objectives-improvement-plan.md | delivery volume, strategic priority |
| J10 | ims-objectives-improvement-plan.md | N, default 1 |
| K1 | customer-requirements-contract-review-procedure.md | logging timeframe, e.g. 2 working days |
| K2 | customer-requirements-contract-review-procedure.md | exception completion window, e.g. 5 working days |
| K3 | design-development-procedure.md | exception validity period, e.g. 90 days |
| K4 | operational-control-service-delivery-procedure.md | exception validity period, e.g. 90 days |
| K5 | procurement-contractor-management-procedure.md | re-evaluation cadence — default annually |
| K6 | procurement-contractor-management-procedure.md | retrospective-evaluation window, e.g. 14 days |
| K7 | communication-consultation-participation-procedure.md | response timeframe, e.g. 10 working days |
| K8 | communication-consultation-participation-procedure.md | exception validity period, e.g. 90 days |
| K9 | competence-training-awareness-procedure.md | effectiveness-evaluation window, e.g. 3 months |
| K10 | competence-training-awareness-procedure.md | exception validity period, e.g. 30 days |
| K11 | compliance-obligations-procedure.md | currency-check frequency per instrument type |
| K12 | compliance-obligations-procedure.md | evaluation frequency; the default is that every obligation |
| K13 | ims-objectives-improvement-plan.md | working-day window |
| K14 | compliance-obligations-procedure.md | exception validity period, e.g. 90 days |
| K15 | document-record-control-procedure.md | campaign deadline, e.g. 10 working days |
| K16 | document-record-control-procedure.md | exception validity period, e.g. 90 days |
| K17 | incident-reporting-investigation-procedure.md | e.g. 2 working days |
| K18 | management-of-change-procedure.md | retrospective assessment window, e.g. 5 working days |
| K19 | nonconformity-corrective-action-improvement-procedure.md | default action timeframes by severity |
| K22 | procurement-contractor-management-procedure.md | exception validity period, e.g. 90 days |
| K23 | internal-audit-procedure.md | maximum deferral, e.g. one month |
| K24 | internal-audit-procedure.md | cycle tolerance, e.g. 14 months |
| L1 | ims-objectives-improvement-plan.md | first full measurement period |
| L1 | ims-objectives-improvement-plan.md | first training snapshot |
| L1 | ims-objectives-improvement-plan.md | first programme quarter |
| L2 | ims-objectives-improvement-plan.md | replace this worked example with the organisation's first real |
| L3 | ims-induction.md | client induction content |
| L3 | ims-induction.md | 3–5 self-check questions |
| L3 | document-lifecycle-for-authors.md | client content — a hands-on exercise |
| L3 | document-lifecycle-for-authors.md | self-check questions. |
| L3 | emergency-response-basics.md | client content |
| L3 | emergency-response-basics.md | self-check questions. |
| L3 | hazard-and-incident-reporting.md | client content |
| L3 | hazard-and-incident-reporting.md | self-check questions. |