ISO 9001:2026 contains four changes that will alter what your auditor asks to see. This article explains each one and what stays as it is.

ISO 9001:2026 was published on 16 September 2026 [CONFIRM: publication date]. Some of the commentary since then suggests that every management system needs rebuilding, which is not the case. Four changes will alter what you do and what your auditor asks to see, and the rest of the revision is tidying.
I have left clause numbers out of this article. Check each point against your own copy of the published standard, which you buy from ISO.
Top management now has to promote a culture of quality and ethical behaviour, and people across the organisation have to be aware of it. This sits in the body of the standard as a requirement, so it will be audited like any other requirement.
I expect this change to cause more argument than the other three put together. I can already predict the response in a lot of organisations: somebody writes a quality culture policy, it goes into the management review pack, a slide is added to induction training, and the requirement is marked as covered.
That approach will not survive contact with a decent auditor, because culture is the one thing in the standard you cannot demonstrate with a document. An auditor will test it by talking to your people. In a manufacturing business, the question will be some version of this: what happens here when you stop the line because something does not look right? If the supervisor thanks the operator and the problem is looked at, the policy on the wall is true. If the answer is a pause, a glance at the supervisor or "it depends who is on shift", the policy is a piece of paper and your auditor now knows it.
Risks and opportunities used to sit in one clause and were treated as one job. The new edition separates them, with requirements for each.
Since 2015 I have audited hundreds of organisations against the old clause. Almost every one of them showed me a risk register, and almost none of them showed me an opportunity. I think the separation is the most honest change in the revision, because it admits how the previous version was being used.
In audit terms, an opportunity is a change you identified and evaluated, and then either took or consciously chose not to take, with a reason. Typical examples include a process you could simplify, a customer requirement you could meet before the deadline, a supplier you could bring closer, or an inspection step you could remove because the data shows the process is stable. That last example is worth real money, and I have rarely seen the people who did it write it down as an opportunity.
Open your risk register this week and look for the column that records what you improved on purpose. If there is no such column, you have found your gap.
You now have to determine whether climate change is a relevant issue for your management system, and act on it where it is. I have already heard the reaction from manufacturers who say it has nothing to do with making components.
That reaction misreads the requirement. It asks you to consider relevance and act where relevant, and it sets no requirement to reduce your emissions. Deciding that climate change is not relevant is a legitimate answer, provided you can show that you asked the question.
Before you reach that decision, look at what your customers are already sending you. If you supply automotive, aerospace or a major retailer, you are probably completing a carbon questionnaire for somebody right now. That is an interested party requirement, which places the subject inside your quality management system whether it interests you or not.
The practical step takes ten minutes. Add one line to the agenda of your next management review, asking whether climate change is a relevant issue for the organisation, then record the discussion and the answer. That record gives you a considered position to show an auditor, where its absence would leave you open to a finding.
The structure of ISO 9001 has been aligned with the other ISO management system standards. If you run ISO 9001 and ISO 14001 together, this change saves you work. The guidance annex has also been rewritten, so if your team used the old annex to interpret the requirements, read the new one before relying on it again.
The shape of the standard has not changed. Your process map, your quality objectives, your internal audit programme and your corrective action process all still stand. ISO 9001:2026 is a revision of a standard you already run. If somebody tries to sell you a full system rewrite on the back of it, ask them which clause requires it.
Organisations certified to ISO 9001:2015 have a three-year transition period, ending in September 2029 [CONFIRM: Paul's wording for the three-year transition period set by an IAF resolution]. Your certificate stays valid through that period, and you will move across at a normal surveillance or recertification audit inside it.
There is no emergency, but the transition period has started. I have watched three of these transitions now [CONFIRM: the "three transitions" line]. In my experience, the organisations that struggled left the work until the last audit of the last year and then tried to do it alongside everything else.
My advice is to read the changes this month, decide which of them apply to you, and put them into next year's internal audit programme rather than the year after.
Which of these four changes would your organisation struggle to evidence tomorrow? I take you through each of them, and what they mean for the system you already run, in the ISO 9001:2015 to ISO 9001:2026 Key Changes course.
A concise, expert-led introduction to the revision from ISO 9001:2015 to ISO 9001:2026. Understand the key changes, what remains unchanged, and the practical steps your organisation can take to prepare for the transition.