ISO 9001:2026 · Guide
By Fiona Parker, ISO 9001 Certified Lead Auditor, Iseo Blue
ISO 9001:2026 was published on 16 September 2026 and replaces ISO 9001:2015 as the current edition of the standard. Certified organisations have a three-year transition period, so certificates issued against the 2015 edition remain valid until September 2029, subject to formal confirmation of the timetable by the International Accreditation Forum and your certification body. So, the good news is that as we stand, currently in 2026, there’s no need to rush to the new version, the accreditation bodies aren’t ready, and it’s likely to take them a year or so to get themselves certified as auditors before they can start auditing us (phew!).
This article is designed to explain the key differences between the old and new versions to get you ahead of the curve and understand what changes and how long you have to do it.
So, the new edition introduces a number of concepts that have prompted plenty of discussion among us quality managers, consultants and certification bodies. Before the standard is finalised it goes through several drafts, and to the credit of ISO, these are available for public review (at a price), so it’s not something that is created behind closed doors and then suddenly released on the world.
The headlines are that it aligns the framework with the other ISO standards (aligning the clauses with things like ISO 27001), introduction of quality culture, ethical behaviour, a clearer split between risks and opportunities, and greater emphasis on leadership accountability now appear in the requirements.
But for many SMEs, the immediate concern is a practical one: what records do I actually need to show to an auditor to meet the new requirements?
The simple and suprising answer is that most organisations already hold much of the evidence they need.
Auditors cannot audit culture, ethics or leadership intentions directly; they audit objective evidence. In practice, that means the decisions your organisation makes, the actions it takes and the records it retains when quality issues arise.
For most smaller businesses, meeting the new requirements will be less about creating new procedures and more about understanding how existing records support the new expectations.
Get our FREE ISO 9001 Toolkit
For our free toolkit, including all the document templates you need, visit our ISO 9001 Toolkit page.
The biggest misconception about ISO 9001:2026
Certainly, my first reaction to the revised standard was that it will require an Ethics Policy, a Quality Culture Procedure and a Leadership Programme. However, upon closer review, that’s unlikely to be where certification bodies focus their attention.
As mentioned, an auditor cannot objectively verify whether your organisation has good ethics. It’s a bit etheral. What they can verify is how customer complaints are handled, how management responds to problems, whether issues are investigated honestly, whether employees are encouraged to report concerns, and how improvement opportunities are identified and acted upon.
In other words, auditors are likely to assess behaviour through records rather than through the policies that describe it. It’s a bit like a driving test; The examiner doesn’t ask you to recite the Highway Code and then wave you through. They sit beside you and watch what you actually do at the junctions, roundabouts, hazardous situations.
What auditors are likely to look for
The Certification Bodies (CBs) are still completing their own transition training and accreditation, so expect the detail of audit practice to settle over the coming year as they trash these issues out in a darkened room somewhere.
Based on the published text, the five areas below are where the expectations have changed most.
1. Quality culture
Top management is now expected to promote a quality culture, and frankly this just aligns with the other standards like ISO 27001, so not a great suprise.
For auditors, this is likely to translate into questions about whether employees contribute to improvement, whether quality issues are discussed openly, how managers respond when problems are identified, and whether continual improvement is visible in practice. The evidence is unlikely to sit in a standalone culture document; it will be scattered throughout the management system and pieced together by the auditor like Colombo solving a crime.
2. Ethical behaviour
ISO 27001:2026 also expects organisations to promote “ethical behaviour”.
From an audit perspective, this is demonstrated when an organisation tells customers the truth when things go wrong, investigates issues honestly, addresses root causes and corrects problems rather than concealing them.
Again, the evidence is found in more in records, not slogans tucked into policies.
3. Leadership commitment
Leadership has always been a core principle of ISO 9001, but the 2026 edition places greater emphasis on accountability (and rightly so in my book – you cannot have drive and ownership without clear accountabilities, in fact this is a weakness I’ve witnessed over the years, so I’m fully behind it).
Auditors are likely to expect evidence that leadership actively reviews performance, allocates resources, addresses risks, supports opportunities and promotes improvement.
Management review records therefore become more important than ever.
Again, this aligns with existing ISO standard frameworks, so nothing massively suprising here.
4. Risks and opportunities as separate requirements
One of the more significant structural changes is that risks and opportunities are now addressed as distinct requirements rather than a single combined clause. Organisations will need evidence that opportunities are identified, evaluated, acted upon and measured, not just that risks are managed. Many organisations already generate this evidence without realising it.
5. Organisational knowledge
Expectations around knowledge management have also been expanded. The focus now is no longer simply on retaining knowledge; organisations are expected to share it, apply it and acquire new knowledge as the business changes.
Most SMEs already maintain records that support this, even if they have never labelled them as “knowledge management”.
A note on climate change. The requirement to consider whether climate change is a relevant issue for the organisation, and whether interested parties have climate-related requirements, was introduced by amendment in 2024 and is now embedded in the 2026 text.
For most SMEs a short, reasoned statement in the context review is sufficient; a lengthy analysis is not expected where the issue is not material to your QMS.
The records you probably already have
One of the easiest ways to prepare for ISO 9001:2026 is to map your existing records against the new expectations.
The table below covers the headline areas and the related requirements that auditors routinely sample alongside them.
| New Focus Area | What Auditors Are Really Looking For | Existing Records Most SMEs Already Have |
|---|---|---|
| Quality Culture | Employees identifying and solving problems | Corrective actions, improvement logs, internal audit findings, lessons learned |
| Ethical Behaviour | Honest responses to quality issues | Complaint investigations, customer communications, nonconformity reports |
| Leadership Commitment | Management involvement in quality decisions | Management review minutes, resource approvals, quality objectives |
| Opportunity-Based Thinking | Evidence of proactive improvement | Improvement registers, project plans, strategic actions, management review actions |
| Customer Focus | Fair treatment of customers | Complaints records, customer feedback, corrective actions, service recovery records |
| Continual Improvement | Ongoing enhancement activities | CAPA records, improvement projects, audit findings, KPI reviews |
| Organisational Knowledge | Knowledge retained and shared | SOPs, training records, competency matrices, meeting minutes |
| Awareness | Employee understanding of quality requirements | Inductions, toolbox talks, training records, internal communications |
| Change Management | Controlled implementation of change | Change records, project documentation, management review actions |
| Business Resilience | Response to disruptions | Risk registers, contingency plans, incident records, supplier reviews |
Demonstrating quality culture without creating more paperwork
Many organisations assume they need a quality culture programme. However, in reality, auditors are more likely to assess whether a quality culture exists through everyday activity.
Consider a typical chain of events in a business: an employee identifies a recurring customer issue; the issue is recorded; management reviews the problem; corrective action is implemented; customer satisfaction improves. There may be no culture record anywhere in that sequence, yet the chain of evidence demonstrates quality culture in action.
Warning signs for auditors. The opposite situation can raise concern. A system with no internal audit findings, no improvement suggestions, no corrective actions and no reported mistakes is not a perfect system; experienced auditors know that immaculate records usually indicate that problems are not being reported.
Demonstrating ethical behaviour through existing records
Ethics can look difficult to audit, but the evidence is often straightforward.
Example 1 · A delivery is delayed
The records that demonstrate an honest, transparent response are the internal escalation, the customer notification, the updated delivery date and the corrective action taken to prevent a repeat.
Example 2 · A compliant is received
The complaint log, investigation, root cause analysis, corrective action and response to the customer together show a willingness to address problems rather than hide them.
Making management reviews work harder
Management reviews are likely to become one of the most valuable sources of audit evidence under the 2026 edition.
Most SMEs already review customer complaints, objectives, risks and internal audit findings. To align with the new requirements, consider adding the following to the agenda:
✔ Observations on quality culture, including how issues were raised and handled
✔ Improvement opportunities identified and their status
✔ Organisational knowledge risks, such as key-person dependency
✔ Employee feedback
✔ Emerging business opportunities
✔ Lessons learned from disruptions
So, no new procedure is necessary. Just a simple update to the management review agenda, followed through in the minutes, can provide substantial evidence.
Opportunities: evidence you are already generating
Opportunities are the inverse of risks. They are the positive outcomes of having a progressive business / QMS.
Most businesses identify opportunities every week without calling them that: a new service offering, a new software platform, process automation, improved supplier arrangements, AI-assisted workflows, or an enhancement a customer has asked for.
The difference under ISO 9001:2026 is that you should retain evidence that the opportunity was identified, evaluated, acted upon and reviewed. A basic improvement log can satisfy much of this requirement.
Internal audits should evolve too
Internal audit programmes may need small updates to reflect the new themes. In addition to auditing procedures, consider asking questions such as:
✔ Leadership: how does management promote quality, and how are improvement ideas reviewed?
✔ Customer focus: how are complaints escalated, and how are customers informed when problems occur?
✔ Quality culture: are employees comfortable raising concerns, and how are lessons learned shared?
✔ Opportunity management: how are opportunities identified and tracked, and how is success measured?
These questions help surface evidence that is already present in the organisation. Our ISO 9001 audit checklist has been updated to include them.
Timing: what to do and when

Publication marks the start of the transition period, not a deadline.
As I mentioned earlier, Certification Bodies need time to train their auditors and complete accreditation, so very few certificates against the 2026 edition are likely to be issued in the first few months of 2027.
That’s going to give you a natural window to review your records against the mapping table above, adjust your management review agenda and internal audit questions, and address any real gaps well before your certification body offers a transition audit.
Most organisations will naturally transition between 2027 and 2029, most likely at the point of their next major audit.
Your existing ISO 9001:2015 certificate remains valid throughout, so you don’t need to worry about that.
Final thoughts
ISO 9001:2026 is not a revolution, it’s an evolution.
For most SMEs it is an evolution of existing good practice. Quality culture, ethical behaviour and leadership will not be demonstrated through new standalone procedures; they will be evidenced through how you manage complaints, investigate problems, engage employees, review performance and drive improvement.
Before creating anything new, review the records you already hold. Customer complaints, corrective actions, internal audits, management reviews, improvement logs, training records and risk assessments will, in most cases, already provide much of the objective evidence an auditor is looking for.
How Iseo Blue can help
Our ISO 9001:2026 gap assessment identifies where your existing records already meet the new expectations and where practical improvements are needed, so you can transition without adding bureaucracy. If you prefer to do it yourself, the Iseo Blue ISO 9001 Toolkit has been fully updated to the 2026 edition and is available now. You can also read our guide to what ISO 9001 certification costs.
Not sure where you stand? Get in touch to discuss a practical, evidence-based transition.