Interview with Puneet Gupta, Founder, MG Environmental Consulting

Connectively

Connectively connects subject-matter experts with top publishers to increase their exposure and create Q & A content.

10 min read

Interview with Puneet Gupta, Founder, MG Environmental Consulting

© Image Provided by Connectively

This interview is with Puneet Gupta, Founder, MG Environmental Consulting.

Puneet, as the Founder in environmental services who audits and consults on ISO 9001/14001/45001, R2v3, e‑Stewards, and NAID, how do you describe the focus of your work and the types of organizations you help?

I run MG Environmental Consulting out of Hayward. We get companies through certification: ISO 9001 for quality, ISO 14001 for environmental, ISO 45001 for safety, and the standards specific to electronics recycling and IT asset disposition—R2v3, e-Stewards, RIOS, and NAID AAA for data destruction.

As for what the work actually consists of, certification is the outcome clients call about. The job is rebuilding how the operation runs. It includes:

  • Document control
  • Corrective action
  • Supplier qualification
  • Training records
  • Getting a written procedure to match what people on the floor actually do at two in the afternoon

Most companies think they have a documentation problem; they have a process problem, and the documentation is just where it becomes visible.

The organizations are mostly small and mid-sized:

  • Manufacturers
  • Electronics recyclers and ITAD firms
  • Healthcare facilities

Electronics recycling is where Ive spent the most time and where the standards are hardest, because youre accountable for material after it leaves your building.

A lot of them come to me because a customer or a contract now requires the certificate, and theyve been quoted a number by a large consultancy thats roughly double what this should cost. I built the firm partly to prove that pricing isn’t necessary.

What path took you from on‑site EHS program implementation to founding your consultancy?

I came at it from the operator side, which shapes how I work now.

I spent years running environmental, health, and safety programs inside organizations rather than advising on them from outside. I managed safety programs, budgets, teams, inspections, and the reporting calendar.

At Stanford Health Care, I handled EHS in a hospital environment, which means hazardous waste streams, regulatory documentation, and the kind of compliance where the consequences of getting it wrong are immediate. I later did EHS leadership work supporting a large technology campus.

What that period taught me is what a consultant’s deliverable looks like from the receiving end. I sat with binders that somebody had been paid a lot of money to produce, and they described a facility that didn’t exist. Beautiful documents describing the wrong building. Then the auditor arrived, and it was my problem, not the consultant’s. That experience is the reason I now start every engagement by walking the floor before I write anything.

My background before EHS was in engineering and computer science, and I earned a master’s degree in engineering and industrial management at USC. That’s a systems education more than an environmental one, and it turns out management systems are systems: inputs, controls, feedback, and failure modes. I think that’s why the process side of this work interests me more than the regulatory trivia.

Founding MG in 2019 came down to two observations. Small manufacturers were being quoted certification prices that made no sense relative to the work involved, and nobody was serving the electronics recycling sector well despite R2v3 being genuinely difficult and the industry growing fast. So I started with the clients the large firms overcharged and the sector they didn’t understand.

Becoming a contract lead auditor came later, and it was the piece that completed the picture. Once you’ve audited enough companies, you stop guessing what will pass.

When a client is overwhelmed by ISO options, how do you quickly separate contractual or legal must‑haves from nice‑to‑haves so they know where to start first?

I ask one simple question: Who is asking you for this?

That answer usually ends the confusion in about ten minutes. Nine times out of ten, a specific customer has put a requirement in a contract or an RFP, and the standard they named is the only one that matters right now. Everything else can wait.

If nobody is asking, and the client is certifying because it seems like the responsible thing to do, that’s a different conversation, and often my advice is to wait until somebody does ask.

  1. The first sort is contractual. Show me the clause. I want to read the actual language, because customers are frequently imprecise about what they’re requiring. I’ve had clients convinced they needed ISO 9001 when the contract asked for a documented quality management system, which isn’t the same thing and is considerably cheaper to satisfy.

  2. The second sort is legal, and it’s narrower than people expect. ISO standards are voluntary. Almost nothing legally requires them. What does bind you is the underlying regulation, and in California that’s the reporting:

    • hazardous waste
    • universal waste
    • your HMBP and CERS filing
    • stormwater, if you’re covered
    • CalRecycle, if that applies

    Those obligations exist whether or not you ever certify anything, and a small shop will get caught out by the reporting long before certification becomes their problem. When someone comes to me overwhelmed by ISO options and I find out they haven’t filed properly, we fix that first.

  3. Then there’s market access, which is real but discretionary. ISO 13485 opens medical device work. AS9100D opens aerospace. R2v3 or e-Stewards is effectively the entry ticket for enterprise ITAD contracts. Worth pursuing if that’s the market you want, not urgent otherwise.

As someone who audits for accredited bodies, what is your five‑minute process for verifying whether a supplier’s certificate is credible and accredited?

First, I don’t care what the certificate looks like. PDFs are trivial to fake, and the most professional-looking ones are often the worst offenders. I care about three fields on it and whether they check out somewhere other than the document itself.

  1. Check the certification body’s name and its accreditation mark. A legitimate certificate names the accreditation body — in the U.S., usually ANAB; elsewhere, UKAS or another IAF signatory. Then go to that accreditation body’s own website and look up the certification body. Not the certification body’s site — the accreditor’s. If the registrar isn’t listed there, you’re done, and this happens more than people expect. There are shops selling certificates with no accreditation behind them at all, and the customers buying them frequently don’t know.

  2. Find the certificate on the registrar’s public directory. Most registrars maintain a searchable list of who they’ve certified. Search by company name and confirm the certificate number matches. If the registrar has no public directory, that itself tells you something.

  3. Read the scope statement carefully. This is where most of the real deception lives, and it isn’t usually deception so much as customers not reading. The scope names what’s actually covered, including which site, which processes, and which product lines.

    A company with five facilities can be certified at one of them and will happily let you assume it covers all five. I’ve seen a certificate covering “sales and distribution” presented as evidence of a certified manufacturing process. The certificate was completely genuine; it just didn’t say what the buyer thought it said.

  4. Check the expiry date and the surveillance cycle. Certificates typically run three years with annual surveillance audits in between, so a certificate that’s two years old should have surveillance activity behind it. Being in date isn’t the same as being in good standing. Some will refuse, which is their right. How they handle the question is informative on its own.

  5. If you’re doing this at volume, put the scope statement in your supplier file rather than relying on the certificate alone. Six months later nobody remembers what was actually covered, and that’s when the gap gets discovered by your own auditor instead of by you.

For a first ISO 14001 build, what single practice best turns the aspects register and legal obligations into daily behavior on the production floor?

Attach the obligation to the moment it is handled, and put it in the language the person actually uses.

Concretely, the aspects register and the legal register are auditor documents. Nobody on the floor is ever going to read them, and expecting otherwise is how these systems end up as binders.

So I take the significant aspects and the obligations attached to them, and translate each one into a single instruction at the point where the material or activity is handled: the label on the drum, the line on the shift checklist, the sign above the accumulation area with the start date on it.

For example: the register might say something like “generation of hazardous waste from parts cleaning, with obligations under Title 22 for labeling, accumulation time limits, and container management.”

That sentence means nothing to the person running the cleaning station. What they need is: “This drum gets a label with today’s date when you open it; it stays closed except when you’re pouring; and it leaves in ninety days.” Three things they can do — same obligation, translated.

Then the checking has to happen where the work happens. I have clients do a short walkthrough on a set cadence, usually weekly, where somebody looks at the actual containers and the actual labels rather than reviewing a document. Ten minutes.

The person doing it should be from the area, not from quality, because the point is that the area owns it. What that produces is a habit of looking, which is worth more than any procedure I could write.

This collapses the gap between the register and reality. When those two things live in separate places, the register drifts within months and the floor never knows the difference. When the obligation is embedded in the physical work, the register stays honest because any change on the floor is immediately visible against it.

Working across ISO 9001/14001/45001, what is your blueprint for an integrated management system that avoids duplicate procedures and duplicate audits?

Those three standards share most of their structure: the same clause architecture and the same requirements for document control, internal audit, management review, corrective action, and competence. What differs is the technical content underneath. Build the shared machinery once and keep the technical parts separate.

That means one document control system, one corrective action process, one internal audit programme, one management review, and one training framework — not three of each with different form numbers.

What should stay separate is risk identification: environmental aspects under 14001, hazard identification under 45001, and process risk under 9001 are different analyses. Merging them into one master register produces something useless to all three. Keep the analyses distinct, then feed their outputs into the same corrective-action and objective-setting processes.

For internal audits, audit by process, not by standard. For example, go to Receiving and look at everything at once: incoming inspection, waste generated, hazards, and the training of people there. One visit, three standards, one report with findings tagged to the applicable clauses.

Auditing by standard means visiting the same area three times a year with overlapping questions; this exhausts staff and teaches them that the whole exercise is theatrical.

Management review should be one meeting with one agenda covering all three standards, since the standards ask for largely the same inputs.

In the first 90 days after launching an EMS, what KPI or leading indicator do you insist clients track to prove real environmental performance gains?

Corrective action closure time should be measured from when the issue was found, not from when someone got around to writing it up.

In the first ninety days, you don’t have enough data for waste volumes or energy intensity to mean anything. Those numbers move with production, not with your system, and a client who ships less in that quarter will show a beautiful reduction that had nothing to do with the EMS. Reporting it as a gain is how these programmes lose credibility internally.

What you can measure in ninety days is whether the machinery works. Corrective action closure time tells you that. It requires someone to have found a problem, recorded it, assigned it, fixed it, and verified the fix.

If that cycle is running in a reasonable number of days, the system is alive. If findings sit open for two months, nothing else you measure matters, because you don’t have a system; you have documentation.

The companion indicator I ask for is how many issues get raised at all. Counterintuitively, I want that number to go up early. A facility reporting zero environmental issues in the second month isn’t compliant; it’s not looking. Rising issue identification with falling closure time is the pattern that tells me an EMS is taking hold.

The lagging environmental numbers come later, and they should be normalized against production so they mean something — waste per unit, not waste per month. But at ninety days, ask whether the organization notices problems and fixes them. Performance gains follow from that; they don’t precede it.

In R2v3 and e‑Stewards projects, how do you approve and monitor downstream vendors so a client isn’t stranded if a processor loses its permit?

Approval starts with the same verification I would apply to any certificate, and then goes further, because under R2v3 your accountability does not stop at your immediate vendor. It follows the material to final disposition.

So I map the whole chain, not just tier one. Who does your vendor send material to, and who do they send it to? Most clients can name their first downstream and go quiet after that, which is exactly the exposure.

For each one, I want the certificate verified through the accreditation body, the permits for the material streams they will actually handle, and a scope statement that covers those streams specifically. A processor certified for one commodity is not certified for your batteries. Then, where the material warrants it, someone conducts a site visit. Site visits catch things documents do not.

The monitoring is a cadence, not an event. Permits and certificates expire on known dates, so those go in a calendar with a reminder ahead of each one rather than being discovered at renewal. I also want reconciliation of weights out, matched against weights received, on a regular basis. When those stop matching, something changed upstream before you find out about it.

As for not getting stranded, approve the backup before you need it. Qualify a second outlet for every material stream where losing the primary would stop your operation, and keep that approval current even if you never ship there. It costs a little to maintain.

The alternative is holding material on site while you scramble, and accumulation time limits do not pause for your vendor’s problems. That’s how a downstream failure becomes your own violation.

Contractually, require notice of any change in permit or certification status, and require that notice to reach you rather than sit in an inbox. Also build the exit terms into the contract at signing, including who pays to move material if you have to leave quickly.

Before a certification audit, how do you stress‑test procedures against real operator behavior to catch gaps between documentation and practice?

I stop reading the procedure and go watch the work.

The method is simple. Pick a procedure, find the person who performs it, and ask them to walk me through what they actually do — not what the document says, but what they do. Then I compare. The gap is almost always there, and it is usually a workaround somebody invented because the official step was impractical.

A form that takes twenty minutes is filled in at the end of the shift from memory. A check that requires a second person is done alone when the shift is short.

The other half is tracing backwards from records. Pick a finished job and reconstruct it from the paperwork. Can I follow it from order to shipment, with the inspection results, the training records of whoever touched it, and any deviation that came up?

If the trail breaks, that is the finding an auditor will write, and it is better to find it yourself two weeks out.

I also ask operators directly, “What part of this process do you think is pointless?” The answers are reliable, and they tell me which steps are being skipped when nobody’s watching.

Then correct the procedure to match the better practice, rather than retraining people into a worse one. Half the time the workaround is smarter than the step it replaced. Where the procedure has to hold, make the compliant version the easier one, because a control that depends on discipline won’t survive a busy Tuesday.

Documentation that matches reality passes audits. Documentation describing an imaginary process fails, and an auditor spots the difference in about ten minutes.

Up Next