Audited,
not asserted.
Quality management is the service we sell, so the systems we run it under are certified and independently audited rather than described.

Our certification register.
Three international standards govern how we deliver quality, protect information and handle personal data.
-

ISO 9001
Quality management systems. Requires documented, consistently applied processes, customer focus, risk-based thinking and continual improvement across the services we deliver.
Request certificate → -

ISO/IEC 27001
Information security management systems. Sets requirements for assessing information security risks and applying controls that protect the confidentiality, integrity and availability of client and company information.
Request certificate → -

ISO/IEC 27701
Privacy information management. Extends ISO/IEC 27001 with controls for handling personally identifiable information, supporting obligations under privacy laws such as the Australian Privacy Act and GDPR.
Request certificate →
How quality is governed at PinnacleQM.

Standards-aligned
methodology
Our Enterprise Test Strategy Framework combines a quality assurance policy, an enterprise test strategy and a defect management plan, aligned with ISO/IEC/IEEE 29119, ISO/IEC 25010 and ISTQB principles.
Controlled
delivery and review
Thirteen core process areas, from planning and estimation to traceability, environments, data and reporting, use controlled templates, review checkpoints, version management and approval authorities, aligned with ISO 9001 and ITIL practices.
Outcome-based
measures
We report critical-risk coverage, defect detection effectiveness, severity 1 and 2 leakage, reopen rates, forecast accuracy and automation reliability, so decisions rest on outcomes rather than activity counts.
What each standard actually covers.

Client data handling
How production-derived test data is masked, held, and destroyed at engagement close.
Access and credentials
How access to client systems is granted, reviewed and revoked, and by whom.
Delivery records
What evidence is retained per engagement, for how long, and who can retrieve it.
Corrective action
How a non-conformance is raised, owned, closed and verified as closed.
Supplier and partner control
How the specialist partner network is assessed and held to the same terms.
Continuity
What happens to an engagement, and its evidence, if a site or system becomes unavailable.
Need evidence for a tender or review?
Our team can provide certificates, policies and capability statements for procurement panels, supplier onboarding and security assessments. Tell us what your evaluation requires and your deadline.
List the documents you need and your submission deadline.