Back to Blog

ISO 9001:2026: quality isn't changing the other standards, it's catching up with them

·7 min read
Illustration: three management systems aligning onto a shared structure

On 16 September 2026 UNI adds the new edition of UNI EN ISO 9001 to its catalogue, in Italian and English, together with the redline versions that highlight what has changed since the previous edition. It is a good moment for a reading that has been largely absent from the coverage of the past few weeks, because it turns the usual way of framing a revision on its head.

The usual framing goes like this: ISO 9001 is the mother standard of management systems, so when its architecture changes the change propagates downstream, towards information security and towards artificial intelligence. Anyone running integrated audits, the story goes, should brace for a domino effect.

That is not what is happening, and the direction matters more than it might seem. The common structure of management systems does not belong to ISO 9001: it is a document in its own right, living in the ISO/IEC Directives, and it was updated in 2021, when the High Level Structure was replaced by the Harmonized Structure. ISO/IEC 27001 adopted that updated structure in 2022. ISO/IEC 42001 was born on top of it in 2023. ISO 9001, still at its 2015 edition, was the only one of the three still speaking the previous version of that language.

What happens in September is not propagation. It is alignment: the most widely adopted standard in the world arrives where the other two had already arrived.

Over a million certified organisations. And for anyone maintaining several management systems at once this is, without any spin, good operational news.

The gap that is about to close

Anyone who has been through an integrated audit covering quality and information security knows the friction. It is not a friction of substance: it is one of vocabulary and of formalisation.

The clearest case is clause 6.1, the one on actions to address risks and opportunities. All three standards break it into sub-clauses, but they do not use them to say the same thing — and that is where the friction comes from.

ISO 9001:2015
Two sub-clauses

6.1.1 determine risks and opportunities from the context; 6.1.2 plan actions, integrate them into processes, evaluate their effectiveness. No formalised process required.

ISO/IEC 27001:2022
Three sub-clauses

6.1.1 general; 6.1.2 risk assessment, with criteria and repeatable results; 6.1.3 risk treatment. Documented information mandatory.

ISO/IEC 42001:2023
Four sub-clauses

Same pattern as 27001, plus 6.1.4: assessing the impact of AI systems on individuals, groups and society. No equivalent in 27001.

In ISO 9001:2015 the choice not to make risk-based thinking rigid is deliberate: the standard prescribes no methodology, imposes no matrix, and requires neither a formalised assessment process nor documented information about the process as such. How much to document is left to the organisation.

In ISO/IEC 27001:2022 the difference is not in the number of sub-clauses, it is in the requirements. Clause 6.1.2 requires establishing and maintaining risk criteria — including risk acceptance criteria — and ensuring that repeated assessments produce “consistent, valid and comparable results”; and it closes by requiring documented information about the assessment process to be retained.

In short: where ISO 9001:2015 asks you to think about risk, the other two ask you to demonstrate how you assess it.

The practical outcome today is that an organisation holding both ISO 9001 and ISO/IEC 27001 maintains two different ways of talking about risk: one structured and documented for the ISMS, one discursive for the QMS. Two registers, two reviews, two accounts for the auditor. Not because it serves any purpose, but because the two standards, written seven years apart, treat the same subject with different degrees of formalisation.

Previews circulated by certification bodies indicate that the 2026 edition will reorganise clause 6.1 into three sub-clauses, separating the treatment of risks more clearly from that of opportunities. The text is not yet available for purchase: until 16 September this remains a preview to be verified against the document, not a fact. But the direction is consistent with the adoption of the harmonized structure, and the direction is what matters for planning.

What UNI says, and what it does not say yet

The two are worth separating, because they are being blended together with some carelessness at the moment.

What is stated. UNI gives the availability date — 16 September 2026 — simultaneous publication in Italian and English, the existence of the redline versions, and three areas the updates focus on: the management of risks and opportunities, the role of leadership, and the spread of a quality culture.

What is not confirmed yet. The transition period. A three-year assumption is circulating persistently, with a deadline around September 2029, and it is a reasonable assumption because it follows historical precedent. But the length of the transition is decided neither by ISO nor by UNI: it is set by the International Accreditation Forum in a dedicated resolution, and that resolution is the document to wait for. Anyone presenting it today as settled is extrapolating, not citing.

In the meantime, nothing changes in compliance terms for an organisation certified to ISO 9001:2015. The certificate remains valid, surveillance audits continue against the edition in force, and no nonconformity can be raised on the basis of a standard that is not yet applicable.

The upside, for anyone running more than one system

This is where the alignment pays off. Shared clauses 4 to 10 are not an editorial detail: they are the infrastructure that makes it possible to collapse three management systems into a single organisational machine.

With all three standards on the same structure, it becomes realistic to unify the analysis of context and interested parties, the internal audit programme, the management review, the handling of nonconformities and corrective actions, and the documented information system. What necessarily stays separate are the specific controls — Annex A of 27001, that of 42001 — and auditor competence: an auditor qualified in quality is not thereby qualified in information security, and vice versa.

The difference is measured in audit days and in hours of internal preparation. One management review prepared once instead of three, one annual programme to run, one documentation system to maintain. For an SME holding two or three certifications this is the cost line where integration bites hardest, and until now ISO 9001 was the link forcing apart what could have stood together.

What makes sense to do now

Wait for 16 September and buy the redline version, not just the text: what you need is the delta, not the standard to read from scratch. Then compare that delta with what is already in place for the ISMS or the AIMS, because part of the work — risk criteria, assessment methodology, evidence retention — already exists and should be reused rather than rebuilt. Finally, wait for the IAF resolution before putting any deadline in the calendar, and check your certification body's transition rules, which may require auditing against the new edition earlier than the final cut-off.

What does not make sense is starting a gap analysis before having the text, or rewriting procedures on the basis of previews. The revision is substantive on clauses 5 and 6, but it is not a refoundation: anyone with a working management system will be dealing with a delta, not a project from scratch.

Sources

Details on the specific content of the 2026 edition come from certification body previews and remain to be verified against the text upon publication.

One system, three certifications

Tomato Blue helps SMEs integrate quality, information security and AI governance into a single documentation system and a single audit programme: one management review instead of three, without duplicating the work.

Talk to us →