Skip to main content

ISO 9001:2026: How to Implement the Changes, Not Just Read Them

· 12 min read
Israel Munguia
Consultant and Instructor

ISO 9001:2026 is not a revolution, and that is exactly what makes it risky. The changes look small, and if you implement them poorly they will be written up in your transition audit.

Almost everything published about this update walks you through the list of changes, clause by clause. You end up knowing what changed and with no idea how to land it. This article does the opposite: the changes that genuinely cost work, and for the two hardest ones, the methodology I use to implement them.

Not all changes are equal

When I went through the published version I sorted the changes into three groups, and that sorting is what saves you time:

  1. General changes. Wording adjustments that make the standard easier to read. They do not touch your quality management system and they are not worth your time.
  2. Small changes. Low impact, but worth knowing about. I left them for the end of this article.
  3. Big changes. Here you will implement something new, or change your approach to something you already have.

There are three big ones, and in my experience they rank like this in difficulty: the quality culture requirement in 5.1.1, risks and opportunities in 6.1, and the new interested parties filter in 4.2.


1. Interested parties: clause 4.2 c)

The note about climate change is not the interesting part of this clause: that had already been a requirement since the 2024 amendment. The interesting part is item c).

The standard now asks you to determine, out of every requirement from your interested parties, which ones you will address through the quality management system. That is a requirement, not a recommendation.

Watch out for what this is not, because this is where most people get confused: the standard does not ask you for a new procedure or a new form. It asks you for a criterion, and the criterion is yours to set. A couple of extra columns in the table where you already manage interested parties will cover the record; what is missing is the logic behind the decision.

I use a five-node decision tree. You walk it once per requirement, and the moment a node takes you out of the path you already know what to record and why.

Five-node decision tree for determining which interested party requirements are addressed through the quality management system under clause 4.2 c) of ISO 9001:2026

Three things worth pointing out about the path:

  • Node 1 drops the most rows. A requirement existing does not mean you are the one who has to meet it. If the discharge permit is in the name of the industrial park, the park is the obligated party. If neighbors expect the access road to be paved, that falls to the local authority. Outsourcing, on the other hand, does not transfer responsibility: if a food safety regulation requires pest control and you contract it out, the requirement is still yours under clause 8.4.
  • Node 2 is decisive. If the requirement is mandatory, whether by law, by contract, or because the product does not conform without it, you skip straight to node 5. There is nothing to decide.
  • Node 4 is the one almost nobody records. An expectation becomes a requirement the moment your top management adopts it, not before. If your retail customer wants recyclable packaging and it is not in the contract, it is an expectation. Once management decides to adopt it because that is your main account, it is your requirement, and from that date on.

If you want the background on why this clause exists, I wrote about it a while ago in interested parties in ISO 9001.


2. Quality culture: clause 5.1.1 i)

To me this is the change with the largest impact in the whole update, and it is a single item: top management must now promote a quality culture and ethical behavior.

Let me put my opinion up front, because it is opinion and not requirement. I have always believed culture was one of the great gaps in the ISO standards, and I have been saying so since 2019. As a consultant I walk into companies that only ever wanted the certificate and that are chaos on the inside. A system can be perfectly documented, certified, and still be a facade. This requirement goes straight at that, and at the consultants who sell a folder of procedures with the logo swapped out and call it a management system.

Now the requirement itself. Four things worth getting straight before you implement anything:

  • Ethical behavior is part of the quality culture, not a separate program. The standard is not asking you for two things. It is asking for one.
  • The note refers to shared values, attitudes, practices and actions. With those last two words in there, declaring values is not enough: you have to evaluate that they are applied.
  • Shared means shared. It is not enough for top management to have a quality culture, and the scope reaches employees, suppliers, customers and any other interested party.
  • It does not require documents, but it does require evidence. A code of ethics, a whistleblowing line, a culture survey, an ISO 37001 implementation: none of these are mandatory. They help, but a small company can comply without any of them by demonstrating real actions.

And the working definition I use so I do not lose the thread: quality culture is how your people behave when complying costs time, costs money or costs a telling-off, and nobody is watching.

Since this does not get solved with a policy and a couple of forms, I designed a six-phase method. Each phase produces a deliverable, and those deliverables together are the only evidence you can use to hold the requirement up.

Six-phase cycle for implementing the quality culture and ethical behavior requirement of clause 5.1.1 i) of ISO 9001:2026, where every phase contributes its deliverable to the same outcome: evidence that people actually live the quality culture

Three notes on the method:

  • Start with phase 1, and run it with your top management in the room. A critical behavior point is a real situation where doing the right thing hurts: the out-of-spec lot when the truck leaves in an hour, the mistake nobody else saw, the measuring equipment that fails mid-shift. For each one you declare the expected behavior. That is customized by definition, and it is why nobody can sell you the finished procedure.
  • Phase 3 is the most uncomfortable and the one that changes the most. This is where you check whether your own system pushes people against what management declares. A bonus based on output that ignores rejects, or a zero-complaints target that rewards not logging them, contradicts this requirement even if nobody planned it that way.
  • The full cycle is plan, do, check, act. It is not a layer on top of the system. It is the system.

And a warning that will save you the project: reported nonconformities will go up at first. That is normal, and it is the signal that it is working, because people stopped hiding them. If top management reacts by punishing, you destroy in one meeting what you built across six phases.

If you want the short version of why culture decides whether your processes are followed, I covered it here.

The two methodologies in this article, the decision tree and the six phases, are my own work and I am giving them away. Use them as they are if they fit, or adapt them to your organization, which is what they are for. The diagrams reproduce the logic exactly as I use it.


3. Risks and opportunities: clause 6.1

The simple way to explain this change is that the standard finally gave opportunities a place of their own. Up to the 2015 version it mentioned them as the positive effect of a risk. Now it separates them.

And it is not asking you to separate the concept. It is asking you to separate the methodology, because a risk and an opportunity are neither evaluated nor treated the same way:

RisksOpportunities
How you evaluate itLikelihood or frequency, against impact or severityFeasibility, against benefit
Action strategiesTerminate, treat, transfer, tolerateExploit, enhance, share, observe
Which way you pushDown: less likelihood, less impactUp: more likelihood, more benefit

If your matrix uses the same likelihood-and-impact scale for both, there is your first job. Open it and split the rows: negative effects on one side, positive ones on the other. In most of the matrices I get to review one of two things happens: either no opportunity survives, or the ones that do are the same risks written backwards.

And a clarification I end up making often on the plant floor, because the confusion is real:

When it happensWhat you do
RiskIn the future, it might happenYou prevent it
ProblemIn the present, it is happeningYou solve it
NonconformityIn the past, it already happenedYou correct it and learn from it

Corrective action has not disappeared, it is still in clause 10. What it no longer is, is the primary improvement mechanism, and the reason is simple: by the time you apply it, the cost, the complaint or the lost customer already happened.


The small changes, one by one

None of these force you to redesign anything, but it is worth knowing they are there:

ClauseWhat changedWhat you have to do
6.3 Planning of changesThe full plan-do-check-act cycle is made explicit, and the criterion is now that the change achieves its intended objectivesPlanning the change used to be enough. Now the criterion is the result
7.1.3 InfrastructureA note adds on-site, remote or combined workIf you have remote or hybrid staff, provide their infrastructure too
7.1.4 EnvironmentRecognizes that some factors depend on the quality culture and ethical behaviorNothing extra. It follows from 5.1.1 and is resolved there
7.1.6 Organizational knowledgeA note clarifies where knowledge lives: people, methods, processes, products and documented informationNothing extra, but the clarification is useful
7.3 AwarenessBrings in the quality culture and ethical behaviorPhase 5 of the method above covers it
8.2.1 e) Customer communicationNew item: provide information on contingency actions, including disruptions to supplyThe focus moved from the document to the actual communication. Review your contingency plans and include supply interruptions, not only fires and equipment failures
8.4.3 d) External providersProvider interactions with your customers and interested partiesIf your provider deals directly with your customer, set the rules in writing
9.1.3 and 9.3.2 Analysis and management reviewRisks and opportunities appear separately, and changes in interested party expectations come in as an inputNew inputs for your management review. No rethinking needed
10.1 and 10.2 ImprovementContinual improvement becomes 10.1 and corrective action moves to the end. A note clarifies that improvement can be incremental or disruptive, through innovation or reorganizationA change of form, with a clear message: corrective action is the last resort in improvement, not the first

How long do you have to transition?

The short answer is three years. That is what has historically been granted to move from one version to the next, it is what happened in the transition from the 2008 version to 2015, and it would give you until September 2029 to complete it.

One thing to be clear about: your certification body is the one that confirms the official deadline, so keep an eye on the announcements they will issue. And do not worry, because throughout that whole period your ISO 9001:2015 certificate remains completely valid. In fact, if you are only now pursuing certification, you will be certified to the 2015 version, because certification bodies also need time to prepare for the new one.

Once the transition period ends, the 2026 version will be the only one you can certify to.


Do not leave it until the end

Three years sounds like plenty of time, and that is the trap.

The quality culture requirement in 5.1.1 is not something you implement in a month, because it does not depend on writing a document: it depends on real things happening in your company and being recorded. If you start generating that evidence in the year of your transition audit, you will show up with a freshly signed policy and not one logbook proving anyone lives by it. That is exactly the paper system this requirement came to expose.

The other two big changes cost less, but they share the same underlying problem. The 4.2 c) filter and the separation of risks and opportunities move documents that later feed your management review. The later you touch them, the more you will have to redo.

Start this year, even if it is with a single clause. Pick the one that hurts most in your operation, and work it through end to end.

tip

With AdminISO you keep your Quality Management System aligned with the ISO 9001 changes, with risks and opportunities already separated into two distinct methodologies. See how AdminISO helps you.