APS Advanced Project Services

APS Advanced Project Services

Share

We drive process excellence and compliance in mobility engineering. And we are hiring!

We assist you in achieving the full potential of your projects through our bespoke consultancy and training services. Our specialisation is in the management of technology-driven projects using sustainable strategies. With our support at every stage, we ensure a smooth journey that achieves your desired outcomes and long-term success.

23/08/2026

๐Ÿ“ข The European standard EN 18286:2026 supporting implementation of the EU AI Act is now available.

EN 18286:2026 has now been published, marking an important milestone in the development of the European standards framework supporting implementation of the EU AI Act.

Announced by CEN-CENELEC as the first European standard supporting the AI Act, EN 18286 focuses on quality management for organisations providing AI systems, with particular relevance to providers of high-risk AI systems under Article 17.

It complements other management and governance frameworks rather than replacing them. While ISO/IEC 42001 provides an organisation-wide Artificial Intelligence Management System (AIMS) for governing AI, EN 18286 focuses specifically on the quality management requirements associated with AI Act implementation.

A practical advantage is that EN 18286 includes informative annexes mapping its requirements to ISO 9001:2015 and ISO/IEC 42001:2023, helping organisations integrate AI Act-related quality management requirements with existing management systems.

An important distinction remains: implementing a standard, achieving certification, and complying with the EU AI Act are three separate concepts. The legal obligations come from the Regulation itself, while standards provide structured frameworks that can help organisations address those obligations.

For organisations preparing for the AI Act, EN 18286 represents another important building block in the European AI governance ecosystem, translating regulatory expectations into a structured quality management approach.

19/08/2026

๐Ÿ“– Lesson #3: Why Good Reporting Isn't All

Good reporting creates transparency.

But transparency alone does not change a project.

Deviations can be identified early, root causes analysed thoroughly and forecasts updated accurately. Yet there is still one important step: deciding what to do with that information.

The decision may be to adjust the plan, investigate further or deliberately stay the course. What matters is that the findings of the reporting process lead to a conscious management decision rather than simply another reporting cycle.

The full article explores why strong project control depends not only on understanding where a project is heading, but on deciding whether anything should change as a result.

๐Ÿ”— Read more at the link below. ๐Ÿ‘‡

15/08/2026

๐Ÿค” What changes as you scale a tech company?

Growth often brings a new ambition: winning larger and more demanding customers.

That's the point where the conversation begins to change.

Trust becomes part of the buying decision.

Customers start evaluating the company behind the product, rather than just the product itself.

Questions about information security, governance and risk management become part of every serious commercial conversation. ISO 27001, TISAX and security questionnaires are simply different ways of asking the same question:

"Can we trust this company?"

The value of an Information Security Management System goes beyond certification.

It's the ability to demonstrate that information security is managed systematically as part of day-to-day operations.

An ISMS is essential when trust becomes part of what you're selling. ๐ŸŽฏ

10/08/2026

๐Ÿš— Do you need to understand automotive cybersecurity to do your job?

APS is organising the Automotive Cybersecurity Engineering training to provide a practical introduction to UNECE R155, ISO/SAE 21434 and the cybersecurity engineering practices required throughout the vehicle lifecycle.

๐Ÿ’ป Online Training
๐Ÿ“… 11 September 2026
๐Ÿ“Œ Limited places available

Participants will discover:

โœ“ The fundamentals of automotive cybersecurity and the regulatory framework.
โœ“ The key principles and requirements of UNECE Regulation R155 and ISO/SAE 21434.
โœ“ How cybersecurity is integrated throughout the vehicle lifecycle, from concept and development to production and post-production.
โœ“ Organisational and project-level cybersecurity management within the UNECE R155 framework.
โœ“ Practical approaches to Threat Analysis and Risk Assessment (TARA), cybersecurity validation and verification, and cybersecurity activities across the product lifecycle.

Who should attend?

Engineers, systems engineers, project managers, quality professionals, cybersecurity specialists and project professionals involved in automotive development and cybersecurity.

Whether you are building new expertise or your role now requires a solid understanding of automotive cybersecurity, this course provides practical knowledge of UNECE R155, ISO/SAE 21434 and TARA that you can apply directly in automotive engineering projects.

๐Ÿ”— More information and registration: www.aps-srl.ro/training

05/08/2026

๐Ÿ” The TISAXยฎ process begins long before the assessment.

Many organisations first hear about TISAXยฎ when a customer requests it.

The next question is usually: "How can we prepare for TISAXยฎ if we don't even have an Information Security Management System?"

For many SMEs, the honest answer is not immediately.

The TISAXยฎ process evaluates the maturity of your Information Security Management System. Building that management system is the organisation's responsibility before the formal assessment.

To help organisations bridge this gap, APS offers dedicated support for:

โœ… Information Security Management System (ISMS) implementation aligned with ISO 27001;
โœ… TISAXยฎ implementation and assessment preparation;
โœ… Independent internal audits and gap assessments;
โœ… Practical support to establish governance, processes and documentation before the formal assessment.

๐Ÿ’ก Our approach is rooted in practical implementation rather than unnecessary bureaucracy. We work with organisations in Germany and Romania that need pragmatic solutions rather than generic templates.

Whether your goal is a first TISAXยฎ assessment, strengthening an existing ISMS or preparing for future customer requirements, we help you build management systems that are practical to operate and designed for continuous improvement.

๐Ÿ“ˆ Passing an assessment is important. Building an organisation that can maintain information security afterwards is even more valuable.

03/08/2026

๐Ÿ“– Lesson #2: The Risk Register Trap

A comprehensive risk register can create confidence.

But identifying risks is not the same as managing them.

A well-maintained risk register is essential. It creates visibility, accountability and organisational memory. But a documented risk does not automatically mean the project is prepared to deal with it.

The real challenge is turning identified risks into decisions, actions and effective responses. If a team can explain what might happen but not what they are doing about it, the register may be recording uncertainty rather than managing it.

The full article explores why effective risk management depends not only on identifying risks, but on challenging assumptions, recognising weak signals and taking deliberate action before options become limited.

๐Ÿ”— Read more on our website: https://aps-srl.ro/lessons/risk-identified-not-risk-managed.

27/07/2026

๐ŸšจThe recent cyber attack that affected Romania's land registry was more than just a cybersecurity incident. It disrupted operations, and its effects extending far beyond the systems themselves.

It revealed how dependent our economy has become on digital systems that often go unnoticed until they stop working.

๐Ÿ  Property transactions are delayed.
๐Ÿฆ Banks wait.
๐Ÿ“‘ Notaries wait.
๐Ÿ‘ฅ So do citizens.

Cyber attacks do not create dependencies. They simply expose the interdependencies that already exist.

It's often only when an incident occurs that organisations fully appreciate this distinction.

The first question is usually:

"How did they get in?"

It's the right question, but not the only one.

"How quickly can we continue operating when something goes wrong?" is just as important.

๐Ÿ›ก๏ธ European regulations, including NIS2, the Cyber Resilience Act (CRA) and, where AI is involved, the EU AI Act, reflect exactly this shift in thinking.

Too often, organisations view these regulations merely as compliance obligations.

We believe their real value lies in helping organisations strengthen their governance and resilience before an incident puts those capabilities to the test.

Compliance alone will never prevent every attack.

Understanding what your organisation cannot afford to lose and preparing for when things go wrong can dramatically improve your ability to respond, recover and continue serving your customers.

Cybersecurity is not just an IT responsibility. It never was.

It is a business continuity issue. A governance issue. Ultimately, a trust issue.

๐Ÿ’กThe real test of resilience is not whether an attack happens.

It's whether people can continue to rely on your organisation when it does.

26/07/2026

๐Ÿ’ก What turns a successful pilot into an organisational improvement?

Recently, we worked with an organisation that chose to pilot an improvement initiative before rolling it out more widely.

It was a pragmatic approach: start with one project, validate it in a real environment, learn from the experience, and then decide how to proceed.

That experience reminded us of Ray Levitt's concept of "death by a thousand pilots". He uses the phrase to describe organisations that struggle to move beyond successful pilots.

It wasn't the risk itself that resonated with us. It was the question it raised:

What is a pilot really supposed to achieve?

Although Levitt discusses this in the context of innovation and digital transformation, we believe the same principle applies to process improvement and organisational change.

Organisations pilot new tools.

They pilot new processes.

They pilot new ways of working.

In our experience, the value of a pilot isn't simply the evidence it produces. It's the decisions it enables.

A pilot isn't valuable simply because it validates one project.

It's valuable because it gives an organisation the confidence to apply the same approach elsewhere.

That means a successful pilot should do more than answer the question:

Can this work?

More importantly, it should help answer questions such as:

โœ… What is preventing wider adoption?
โœ… What needs to change before scaling?
โœ… Is the approach repeatable across different projects and teams?
โœ… What evidence would give the organisation the confidence to move forward?

Our experience suggests these questions should shape the pilot from the outset, not emerge as an afterthought once it has finished.

The objective isn't a successful pilot. It's a repeatable way of working.

Ultimately, a successful pilot only becomes an organisational improvement when the organisation is willing to act on what it has learnt.

24/07/2026

When is the best time to bring in an external project manager? ๐Ÿค”

All too often, the answer is when the project starts to show signs of trouble.

We believe that's too late.

By that point, real problems have often been building for months: unquestioned assumptions, postponed decisions, competing priorities, and issues that everyone sees but no one takes ownership of.

The value of an external project manager isn't just additional capacity.

It's perspective and objectivity.

Someone who wasn't involved in yesterday's decisions can ask today's uncomfortable questions:

โ€ข What assumptions are no longer true?
โ€ข Who's accountable for the decision that's blocking progress?
โ€ข What has changed since we agreed on this plan?

The best external project managers don't take control of your project.
They help your organisation maintain control of it. ๐ŸŽฏ

22/07/2026

๐Ÿ“– LESSON #1: The Detailed Plan Illusion

Having more information doesn't always lead to better understanding.
A project can have thousands of perfectly planned activities.....and still fail to make the next priority obvious.
๐Ÿ’ก That's the illusion.
Read the full story on our website:
๐Ÿ”— https://aps-srl.ro/lessons/the-detailed-plan-illusion

Want your business to be the top-listed Engineering Company in Bucharest?
Click here to claim your Sponsored Listing.

Telephone

Address


Aleea Dorohoi 8
Bucharest
041686

Opening Hours

Monday 08:00 - 18:00
Tuesday 08:00 - 18:00
Wednesday 08:00 - 18:00
Thursday 08:00 - 18:00
Friday 08:00 - 18:00