ISO 9001:2026 – The new version is here, and what it means to you.

Find out what ISO 9001:2026 version means to your business. What's different, and what you need to do by when. Everything explained.

Date: 10 September 2026

ISO 9001:2026 · Guide

By Fiona Parker, ISO 9001 Certified Lead Auditor, Iseo Blue

ISO 9001:2026 was published on 16 September 2026 and replaces ISO 9001:2015 as the current edition of the standard. Certified organisations have a three-year transition period, so certificates issued against the 2015 edition remain valid until September 2029, subject to formal confirmation of the timetable by the International Accreditation Forum and your certification body. So, the good news is that as we stand, currently in 2026, there’s no need to rush to the new version, the accreditation bodies aren’t ready, and it’s likely to take them a year or so to get themselves certified as auditors before they can start auditing us (phew!).

This article is designed to explain the key differences between the old and new versions to get you ahead of the curve and understand what changes and how long you have to do it.

So, the new edition introduces a number of concepts that have prompted plenty of discussion among us quality managers, consultants and certification bodies. Before the standard is finalised it goes through several drafts, and to the credit of ISO, these are available for public review (at a price), so it’s not something that is created behind closed doors and then suddenly released on the world.

The headlines are that it aligns the framework with the other ISO standards (aligning the clauses with things like ISO 27001), introduction of quality culture, ethical behaviour, a clearer split between risks and opportunities, and greater emphasis on leadership accountability now appear in the requirements.

But for many SMEs, the immediate concern is a practical one: what records do I actually need to show to an auditor to meet the new requirements?

The simple and suprising answer is that most organisations already hold much of the evidence they need.

Auditors cannot audit culture, ethics or leadership intentions directly; they audit objective evidence. In practice, that means the decisions your organisation makes, the actions it takes and the records it retains when quality issues arise.

For most smaller businesses, meeting the new requirements will be less about creating new procedures and more about understanding how existing records support the new expectations.

Get our FREE ISO 9001 Toolkit

For our free toolkit, including all the document templates you need, visit our ISO 9001 Toolkit page.


The biggest misconception about ISO 9001:2026

Certainly, my first reaction to the revised standard was that it will require an Ethics Policy, a Quality Culture Procedure and a Leadership Programme. However, upon closer review, that’s unlikely to be where certification bodies focus their attention.

As mentioned, an auditor cannot objectively verify whether your organisation has good ethics. It’s a bit etheral. What they can verify is how customer complaints are handled, how management responds to problems, whether issues are investigated honestly, whether employees are encouraged to report concerns, and how improvement opportunities are identified and acted upon.

In other words, auditors are likely to assess behaviour through records rather than through the policies that describe it. It’s a bit like a driving test; The examiner doesn’t ask you to recite the Highway Code and then wave you through. They sit beside you and watch what you actually do at the junctions, roundabouts, hazardous situations.


What auditors are likely to look for

The Certification Bodies (CBs) are still completing their own transition training and accreditation, so expect the detail of audit practice to settle over the coming year as they trash these issues out in a darkened room somewhere.

Based on the published text, the five areas below are where the expectations have changed most.

1. Quality culture

Top management is now expected to promote a quality culture, and frankly this just aligns with the other standards like ISO 27001, so not a great suprise.

For auditors, this is likely to translate into questions about whether employees contribute to improvement, whether quality issues are discussed openly, how managers respond when problems are identified, and whether continual improvement is visible in practice. The evidence is unlikely to sit in a standalone culture document; it will be scattered throughout the management system and pieced together by the auditor like Colombo solving a crime.

2. Ethical behaviour

ISO 27001:2026 also expects organisations to promote “ethical behaviour”.

From an audit perspective, this is demonstrated when an organisation tells customers the truth when things go wrong, investigates issues honestly, addresses root causes and corrects problems rather than concealing them.

Again, the evidence is found in more in records, not slogans tucked into policies.

3. Leadership commitment

Leadership has always been a core principle of ISO 9001, but the 2026 edition places greater emphasis on accountability (and rightly so in my book – you cannot have drive and ownership without clear accountabilities, in fact this is a weakness I’ve witnessed over the years, so I’m fully behind it).

Auditors are likely to expect evidence that leadership actively reviews performance, allocates resources, addresses risks, supports opportunities and promotes improvement.

Management review records therefore become more important than ever.

Again, this aligns with existing ISO standard frameworks, so nothing massively suprising here.

4. Risks and opportunities as separate requirements

One of the more significant structural changes is that risks and opportunities are now addressed as distinct requirements rather than a single combined clause. Organisations will need evidence that opportunities are identified, evaluated, acted upon and measured, not just that risks are managed. Many organisations already generate this evidence without realising it.

5. Organisational knowledge

Expectations around knowledge management have also been expanded. The focus now is no longer simply on retaining knowledge; organisations are expected to share it, apply it and acquire new knowledge as the business changes.

Most SMEs already maintain records that support this, even if they have never labelled them as “knowledge management”.

A note on climate change. The requirement to consider whether climate change is a relevant issue for the organisation, and whether interested parties have climate-related requirements, was introduced by amendment in 2024 and is now embedded in the 2026 text.

For most SMEs a short, reasoned statement in the context review is sufficient; a lengthy analysis is not expected where the issue is not material to your QMS.


The records you probably already have

One of the easiest ways to prepare for ISO 9001:2026 is to map your existing records against the new expectations.

The table below covers the headline areas and the related requirements that auditors routinely sample alongside them.

New Focus AreaWhat Auditors Are Really Looking ForExisting Records Most SMEs Already Have
Quality CultureEmployees identifying and solving problemsCorrective actions, improvement logs, internal audit findings, lessons learned
Ethical BehaviourHonest responses to quality issuesComplaint investigations, customer communications, nonconformity reports
Leadership CommitmentManagement involvement in quality decisionsManagement review minutes, resource approvals, quality objectives
Opportunity-Based ThinkingEvidence of proactive improvementImprovement registers, project plans, strategic actions, management review actions
Customer FocusFair treatment of customersComplaints records, customer feedback, corrective actions, service recovery records
Continual ImprovementOngoing enhancement activitiesCAPA records, improvement projects, audit findings, KPI reviews
Organisational KnowledgeKnowledge retained and sharedSOPs, training records, competency matrices, meeting minutes
AwarenessEmployee understanding of quality requirementsInductions, toolbox talks, training records, internal communications
Change ManagementControlled implementation of changeChange records, project documentation, management review actions
Business ResilienceResponse to disruptionsRisk registers, contingency plans, incident records, supplier reviews

Demonstrating quality culture without creating more paperwork

Many organisations assume they need a quality culture programme. However, in reality, auditors are more likely to assess whether a quality culture exists through everyday activity.

Consider a typical chain of events in a business: an employee identifies a recurring customer issue; the issue is recorded; management reviews the problem; corrective action is implemented; customer satisfaction improves. There may be no culture record anywhere in that sequence, yet the chain of evidence demonstrates quality culture in action.

Warning signs for auditors. The opposite situation can raise concern. A system with no internal audit findings, no improvement suggestions, no corrective actions and no reported mistakes is not a perfect system; experienced auditors know that immaculate records usually indicate that problems are not being reported.

Demonstrating ethical behaviour through existing records

Ethics can look difficult to audit, but the evidence is often straightforward.

The records that demonstrate an honest, transparent response are the internal escalation, the customer notification, the updated delivery date and the corrective action taken to prevent a repeat.

The complaint log, investigation, root cause analysis, corrective action and response to the customer together show a willingness to address problems rather than hide them.


Making management reviews work harder

Management reviews are likely to become one of the most valuable sources of audit evidence under the 2026 edition.

Most SMEs already review customer complaints, objectives, risks and internal audit findings. To align with the new requirements, consider adding the following to the agenda:

Observations on quality culture, including how issues were raised and handled

Improvement opportunities identified and their status

Organisational knowledge risks, such as key-person dependency

Employee feedback

Emerging business opportunities

Lessons learned from disruptions

So, no new procedure is necessary. Just a simple update to the management review agenda, followed through in the minutes, can provide substantial evidence.


Opportunities: evidence you are already generating

Opportunities are the inverse of risks. They are the positive outcomes of having a progressive business / QMS.

Most businesses identify opportunities every week without calling them that: a new service offering, a new software platform, process automation, improved supplier arrangements, AI-assisted workflows, or an enhancement a customer has asked for.

The difference under ISO 9001:2026 is that you should retain evidence that the opportunity was identified, evaluated, acted upon and reviewed. A basic improvement log can satisfy much of this requirement.


Internal audits should evolve too

Internal audit programmes may need small updates to reflect the new themes. In addition to auditing procedures, consider asking questions such as:

✔ Leadership: how does management promote quality, and how are improvement ideas reviewed?

✔ Customer focus: how are complaints escalated, and how are customers informed when problems occur?

✔ Quality culture: are employees comfortable raising concerns, and how are lessons learned shared?

✔ Opportunity management: how are opportunities identified and tracked, and how is success measured?

These questions help surface evidence that is already present in the organisation. Our ISO 9001 audit checklist has been updated to include them.


Timing: what to do and when

The ISO 9001:2026 Transition Timeline

Publication marks the start of the transition period, not a deadline.

As I mentioned earlier, Certification Bodies need time to train their auditors and complete accreditation, so very few certificates against the 2026 edition are likely to be issued in the first few months of 2027.

That’s going to give you a natural window to review your records against the mapping table above, adjust your management review agenda and internal audit questions, and address any real gaps well before your certification body offers a transition audit.

Most organisations will naturally transition between 2027 and 2029, most likely at the point of their next major audit.

Your existing ISO 9001:2015 certificate remains valid throughout, so you don’t need to worry about that.


Final thoughts

ISO 9001:2026 is not a revolution, it’s an evolution.

For most SMEs it is an evolution of existing good practice. Quality culture, ethical behaviour and leadership will not be demonstrated through new standalone procedures; they will be evidenced through how you manage complaints, investigate problems, engage employees, review performance and drive improvement.

Before creating anything new, review the records you already hold. Customer complaints, corrective actions, internal audits, management reviews, improvement logs, training records and risk assessments will, in most cases, already provide much of the objective evidence an auditor is looking for.

NEXT post

Photo of author

Written by

Fiona Parker

Fiona Parker is a BSI-qualified ISO 9001 Lead Auditor and leads the quality management practice at Iseo Blue Limited. She spent six years running a certified integrated management system for a UK critical power systems contractor, four of them under certification, and twenty years before that in IT service management and process consultancy, including senior roles at McLaren. She carries out independent internal audits and coaches UK SMEs building lean, practical quality management systems.