This audit season is different. ISO 14001 was revised in April 2026 and ISO 9001 in September, so two transition clocks are already running, and ISO 45001 follows in 2027. Meanwhile the thing auditors test has not changed at all: not whether you have procedures, but whether you can produce evidence that they were followed.
In this article
What changed with ISO 9001:2026
The sixth edition of ISO 9001 was published in September 2026, replacing the 2015 version. Certified organisations have a 36-month transition, which runs to September 2029. Your 2015 certificate stays valid in the meantime, so there is no emergency, but there is a deadline that will arrive during a year when you are also busy with something else.
It is a revision, not a redesign. Process approach, PDCA and risk-based thinking are all still the backbone. The changes published by certification bodies summarising the new edition cluster around five themes:
- The Harmonised Structure, updated. ISO 9001 aligns to the current version of the common framework shared across management system standards, including the harmonised terms and definitions in clause 3. The 2015 edition already shared that structure, so this is not new ground. What it adds is tighter alignment with the editions of ISO 14001 and ISO 45001 you will be audited against next.
- Climate change. Organisations are expected to consider whether climate change is relevant to their context, in line with the amendment already applied across ISO management system standards.
- Quality culture and ethical behaviour. Leadership is expected to promote both, and awareness requirements extend to them. Commentators point to clauses 5.1.1 and 7.3 as the places this lands.
- Risks and opportunities, separated. The 2015 text treated them together and opportunities were routinely under-addressed as a result. The new edition splits them, around clauses 6.1.2 and 6.1.3.
- Annexes. Annex A has been reworked and expanded with fuller explanations, and Annex B disappears as a standalone annex, its relevant references folded into Annex A.
One thing the revision does not do, despite a lot of speculation: it does not introduce artificial intelligence requirements. If a consultant tells you ISO 9001:2026 obliges you to govern your AI, ask them to point at the clause. The governance obligations that do exist for AI at work come from the AI Act, which we cover separately in AI in QHSE.
Culture, ethics and opportunities are the three themes an auditor cannot test from a procedure manual. They are tested through records: awareness sessions that happened, opportunities that were identified and acted on, decisions traceable to the stated policy. Which is to say the revision raises the value of your evidence trail rather than your documentation.
Where ISO 14001 and ISO 45001 stand
If you run an integrated system, the thing to understand is that you are not waiting for one deadline. You are already inside two.
ISO 14001 was published as its fourth edition in April 2026, five months ahead of ISO 9001, and ISO 14001:2015 is now withdrawn. Its own three-year transition has been running since then. If you hold both certificates, you are managing two overlapping clocks rather than one, and they are set per certificate and per audit cycle, so confirm both end dates with your certification body rather than assuming they align.
ISO 45001 is the one still in progress. The Draft International Standard was registered in April 2026 and its ballot closed in September, with publication expected in 2027 and a transition period still to be confirmed by the accreditation bodies. The themes in the draft are a good signal of where occupational health and safety auditing is heading: psychosocial risk and mental health, worker wellbeing, remote and hybrid working arrangements, climate-related safety risks, responsibility along the supply chain, and a shift towards demonstrating that safety culture is effective rather than documented.
The useful conclusion is that all three revisions push in the same direction: less weight on the existence of documents, more weight on being able to show that something actually happened, to whom, when, and with what result. Work done on that now counts whichever edition you are audited against.
The six things an auditor asks to see
Strip away the preparation anxiety and an internal audit, like the certification audit it rehearses, tests six objects. If you can produce all six quickly, the rest is conversation.
| Object | What is actually tested | Where it usually lives |
|---|---|---|
| The audit programme | That it is risk-based and covers the whole system over its cycle, not just the easy processes. Clause 9.2. | A planning document, too often a spreadsheet rebuilt each year |
| Criteria and scope per audit | That each audit stated what it was testing against, and that the auditor was independent of the area audited. | Audit plans and assignment records |
| Findings with objective evidence | Not an opinion but a traceable fact: a document, a record, a photograph, an observation with date and place. | Audit reports and their attachments |
| Corrective actions with cause analysis | That you looked for the cause rather than the symptom, and that effectiveness was verified afterwards. Clause 10.2. | The action plan, and the proof that each action closed |
| Management review inputs and outputs | That the required inputs were presented and that decisions came out with owners and deadlines. Clause 9.3. | Minutes, and the KPI pack behind them |
| Control of documented information | Version, approval, availability, protection from unintended change, retention. Clause 7.5. | Your document base, or a shared drive hoping nobody looks |
Where the evidence usually falls apart
The action that closed without proof. The status says closed. The date is there. What is missing is the evidence of effectiveness: the follow-up check, the re-audit, the measurement that shows the problem did not return. A closure without verification is among the findings auditors raise most often, and it is almost always a system design problem rather than negligence. If the tool never asked for proof, nobody produced proof.
The version you cannot pin down. An inspection was carried out in March using a checklist that has since been edited twice. Which version was used? If the answer involves opening a file's properties and guessing, you have a documented information problem that the 7.5 requirements are written precisely to prevent.
The record written after the fact. Everyone recognises the week before an audit when records get tidied. The risk is not the tidying, it is that an auditor can often tell: three months of inspections all created on the same afternoon, timestamps clustered, signatures identical. Capturing at the moment of the observation, from the field, removes the temptation and the suspicion at once.
A six-week preparation sequence
This is written for an internal audit, but it is the same sequence that makes a certification audit uneventful.
Week one: close the gap list from last time
Pull every action left open from the previous audit. Anything that cannot be closed with evidence in six weeks gets a revised deadline and a named owner today, not an optimistic status.
Week two: test six actions at random
Pick six closed corrective actions from the last twelve months and try to reconstruct each one end to end. The ones that take longest tell you exactly where the audit will hurt.
Week three: pin your document versions
Checklists, procedures, forms. One current version each, approved, dated, and identifiable from any record that used it.
Week four: rebuild the KPI pack from source
Recalculate your indicators from the underlying records rather than from last quarter's slides. Where the two disagree, you have found something more useful than a clean number.
Week five: run the management review properly
All required inputs, decisions written as actions with owners and dates. A review that produces no actions reads as a review that was not taken seriously.
Week six: do a dry run on one process
Have someone independent audit a single process as if they were the certification body. One real rehearsal is worth more than four weeks of document polishing.
What the revision means for your audit programme
Three concrete adjustments to make during the transition, none of which need to wait for 2029.
First, add transition status to your audit programme as a line item. Each cycle should ask what has been mapped to the new edition and what has not, so the gap is visible monthly rather than discovered in year three.
Second, start generating evidence on the themes that are new. Culture, ethics and opportunities cannot be evidenced retroactively. An awareness session held in 2027 produces a record in 2027. If you begin at the end of the transition you will have procedures describing a culture and nothing showing it.
Third, if you are integrated, do the mapping once. The Harmonised Structure is what makes a single audit programme covering quality, safety and environment realistic instead of theoretical. With ISO 14001 and ISO 9001 both revised and their transitions running in parallel, mapping your evidence to the common clauses now means the ISO 45001 edition expected in 2027 becomes an update rather than a third project.
And if the honest answer to “where is the evidence” is a shared drive and four spreadsheets, that is the thing to fix before the next audit, not after it. We covered why in running QHSE on spreadsheets.
Make your evidence trail the easy part
Audit programme, findings, corrective actions and controlled documents in one base, with traceability on every change. Describe your process and we build a proof of concept on your data in a few days.
Explore TimeTonic QHSEFrequently asked questions
The transition period is 36 months from publication in September 2026, so the deadline is September 2029. Existing 2015 certificates remain valid until then. If you also hold ISO 14001, note that its own transition started earlier, in April 2026. In practice your certification body will want the transition handled during a scheduled surveillance or recertification audit, so the date that matters to you is your own audit calendar rather than the 2029 limit. Confirm it with them early.
No. The revision addresses leadership, quality culture and ethics, climate change, and the separation of risks and opportunities. It does not introduce AI-specific requirements. Obligations around AI used at work come from the EU AI Act instead, where systems used to monitor or evaluate workers are treated as high risk, with those obligations now applying from December 2027.
Anything verifiable and traceable to a moment: a record, a document version, a measurement, a dated photograph, an observation with place and time. The test is whether a second auditor could reach the same conclusion from the same material. A statement that a process is generally followed is not evidence, and neither is a procedure that says what should happen.
No, and waiting is not really an option anyway: ISO 14001 and ISO 9001 were both revised in 2026, so two transitions are already running. All three revisions move in the same direction, towards demonstrated effectiveness rather than documentation, and all sit on the Harmonised Structure. Work done now on traceability, action closure and evidence applies to whichever edition you are audited against.
Sources and further reading
- ISO 9001:2026, Quality management systems, requirements, sixth edition, published September 2026.
- ISO 14001:2026, Environmental management systems, fourth edition, published April 2026, superseding ISO 14001:2015.
- Certification body transition guidance from DNV and TUV SUD on the 36-month transition period.
- ISO 45001 revision, Draft International Standard registered April 2026 by ISO/TC 283, ballot closed September 2026, publication expected 2027.
- ISO 19011:2018, Guidelines for auditing management systems.




