Contact Us
Certifications

Audited,
not asserted.

Quality management is the service we sell, so the systems we run it under are certified and independently audited rather than described.

The register

Our certification register.

Three international standards govern how we deliver quality, protect information and handle personal data.

  • ISO 9001 quality management certification

    ISO 9001

    Quality management systems. Requires documented, consistently applied processes, customer focus, risk-based thinking and continual improvement across the services we deliver.

    Request certificate →
  • ISO 27001 information security certification

    ISO/IEC 27001

    Information security management systems. Sets requirements for assessing information security risks and applying controls that protect the confidentiality, integrity and availability of client and company information.

    Request certificate →
  • ISO 27701 privacy information certification

    ISO/IEC 27701

    Privacy information management. Extends ISO/IEC 27001 with controls for handling personally identifiable information, supporting obligations under privacy laws such as the Australian Privacy Act and GDPR.

    Request certificate →
Beyond the certificate

How quality is governed at PinnacleQM.

Auditor ticking a checklist against printed evidence
  • Standards-aligned

    methodology

    Our Enterprise Test Strategy Framework combines a quality assurance policy, an enterprise test strategy and a defect management plan, aligned with ISO/IEC/IEEE 29119, ISO/IEC 25010 and ISTQB principles.

  • Controlled

    delivery and review

    Thirteen core process areas, from planning and estimation to traceability, environments, data and reporting, use controlled templates, review checkpoints, version management and approval authorities, aligned with ISO 9001 and ITIL practices.

  • Outcome-based

    measures

    We report critical-risk coverage, defect detection effectiveness, severity 1 and 2 leakage, reopen rates, forecast accuracy and automation reliability, so decisions rest on outcomes rather than activity counts.

Scope

What each standard actually covers.

Locked server cabinet with keycard access in a secure room
Client data handling

How production-derived test data is masked, held, and destroyed at engagement close.

Access and credentials

How access to client systems is granted, reviewed and revoked, and by whom.

Delivery records

What evidence is retained per engagement, for how long, and who can retrieve it.

Corrective action

How a non-conformance is raised, owned, closed and verified as closed.

Supplier and partner control

How the specialist partner network is assessed and held to the same terms.

Continuity

What happens to an engagement, and its evidence, if a site or system becomes unavailable.

Procurement and assurance

Need evidence for a tender or review?

Our team can provide certificates, policies and capability statements for procurement panels, supplier onboarding and security assessments. Tell us what your evaluation requires and your deadline.

List the documents you need and your submission deadline.