Blog cover

Perry Johnson Registrars

Blog

IATF 16949 Revision 2: The Five Priority Topics and What They Mean for Your Organization

10/8/2026
A mechanic leaning over an engine of a car with an electronic image of a car with numbered steps

IATF 16949 Revision 2: The Five Priority Topics and What They Mean for Your Organization If your organization is certified to IATF 16949, or is working toward it, you have probably heard that a new edition is on the way.…

Read more

IATF 16949 Revision 2: The Five Priority Topics and What They Mean for Your Organization

If your organization is certified to IATF 16949, or is working toward it, you have probably heard that a new edition is on the way. In its July 2026 stakeholder communiqué, the International Automotive Task Force (IATF) shared the first official look at what is driving the revision.

A quick note on roles: the IATF owns and maintains IATF 16949. Perry Johnson Registrars (PJR) is a certification body that audits and certifies organizations to the standard. We follow every update closely so the organizations we work with are never caught off guard, and this post is written from that perspective.

What the IATF Has Actually Announced

Revision 2 is being driven by feedback from stakeholders across the automotive industry. Based on that input, the IATF has identified five priority topics. These are not new clauses, and they are not final requirements. They signal where the industry believes the current system can work better.

The Five Priority Topics

  1. Simplification, Clarity and Efficiency
    The goal is a standard that is easier to understand, implement and audit without losing effectiveness. That means reducing unnecessary complexity, narrowing the room for inconsistent interpretation, and avoiding duplication with ISO 9001.

    Ask yourself: Where does our quality management system create complexity without adding real control?

  2. Software Quality Assurance
    Software is playing a bigger role in both automotive products and the processes that build them. Revision 2 is expected to apply existing quality principles more consistently across the software lifecycle, with a focus on embedded software, and without adding unnecessary complexity.

    Ask yourself: Does software receive the same quality discipline as our products and processes?

  3. Tier N Supply Chain Management
    Automotive quality depends on the whole supply chain, not just direct suppliers. The revision aims to promote a more consistent risk-based approach to lower-tier suppliers, better deployment of customer requirements, and clearer communication, while keeping requirements practical and auditable.

    Ask yourself: Do we understand the risks that sit beyond our direct suppliers?

  4. Launch Management
    Product and process launches are among the highest-risk phases of the automotive lifecycle. Revision 2 is expected to put more emphasis on a structured approach to new products, change management and industrialization, with the aim of improving launch readiness and reducing quality risk during implementation.

    Ask yourself: Can we demonstrate launch readiness before start of production?

  5. Customer-Specific Requirements (CSR)
    Customer-Specific Requirements are one of the most discussed topics in the IATF 16949 scheme, and stakeholders consistently describe them as a challenge. The IATF aims to improve how applicable CSR are identified and managed, and to look at whether common CSR could be incorporated into the standard itself where possible.

    Ask yourself: Are all applicable CSR identified, current, deployed and effective?

Five Priorities, Five Familiar Problems

None of these priorities will come as a surprise to anyone who has lived inside an automotive quality system. Each one points to a challenge many organizations already recognize:

  • A quality management system with complexity that does not always add control
  • Software treated separately from established quality disciplines
  • Limited visibility beyond direct suppliers
  • Launches that still create quality and delivery disruption
  • Customer-specific requirements that are hard to identify, update and deploy consistently

That is useful news. It means the work of getting ready is largely the work of improving what you already do.

What We Know About the Timeline

The IATF has shared a high-level plan and is clear that the dates are indicative and may be adjusted as work progresses. Working draft development and external feedback are planned for 2026. Final validation, translation and supporting documents follow in 2027, with publication planned for mid-2027. The IATF has also stated that the end of the transition period will be aligned with the end of the ISO 9001 transition.

Specific transition rules for certified organizations have not been announced. As details are released, we will share what they mean for audits and certificates.

How to Prepare Without Getting Ahead of the Standard

The standard has not been published, so there is no reason to build new procedures around assumptions about what it will say. Rewriting your system now risks solving problems that the final text does not contain.

What you can do today is use the five priorities as a self-check. Walk through the questions above with your quality, supply chain, engineering and program management teams. Gaps you find are worth closing under the current standard, and they will put you in a stronger position whatever the final text looks like. It is also a good moment to review how your team tracks CSR and how clearly your launch readiness evidence is documented.

Frequently Asked Questions

Has IATF 16949 Revision 2 been published?

A: No. The IATF currently plans to publish the 2nd edition in mid-2027, and it has noted that dates may change. Until then, IATF 16949:2016 remains the standard organizations are certified to.

Do I need to change my quality management system now?

A: You do not need to create new procedures based on a standard that has not been released. You can, however, review your current system against the five priority areas and strengthen any weak spots.

Are the five priority topics new requirements?

A: No. They are the areas the IATF has identified for improvement. How they are reflected in the final standard will not be known until the revision is published.

Will customer-specific requirements go away?

A: The IATF has not said that. Its stated aim is to improve how applicable CSR are identified and managed, and to explore incorporating common CSR into the standard where possible.

Who sets the rules for IATF 16949, and where does PJR fit in?

A: The IATF develops and maintains IATF 16949 and the rules of the certification scheme. PJR is a certification body that audits organizations against the standard and issues certification based on the outcome.

Talk to PJR About IATF 16949 Certification

Whether you are already IATF 16949 certified or exploring certification for the first time, our team can help you understand where things stand and what to expect. Call Perry Johnson Registrars at (248) 422-3013, email pjr@pjr.com, or Request A FREE Quote.

Know Thyself: How ISO 42001 Clause 4 Lays the Groundwork for Self-Policing AI

10/5/2026
A person holding a brain in their hand, meant to symbolize artificial intelligence.

Know Thyself: How ISO 42001 Clause 4 Lays the Groundwork for Self-Policing AI As AI tools move from pilot projects into everyday operations, more organizations are asking the same question: how do we keep our own AI in check before…

Read more

Know Thyself: How ISO 42001 Clause 4 Lays the Groundwork for Self-Policing AI

As AI tools move from pilot projects into everyday operations, more organizations are asking the same question: how do we keep our own AI in check before a regulator, customer, or headline does it for us? ISO/IEC 42001, the international standard for Artificial Intelligence Management Systems (AIMS), offers a structured answer. And that answer starts not with algorithms or audits, but with self-awareness.

Clause 4, Context of the Organization, is the foundation the rest of the standard is built on. It asks an organization to look honestly at its environment, its stakeholders, and its own role in the AI ecosystem, and then to draw clear boundaries around what its management system will cover. Get this step right, and self-policing becomes a disciplined, repeatable practice. Skip it, and every control that follows is built on guesswork.

Why Self-Policing Starts with Context

Self-policing means an organization sets its own rules for responsible AI, watches for its own failures, and corrects them without waiting for outside pressure. That only works if the organization knows what “responsible” means in its specific situation. A hospital using AI to triage patients faces very different risks than a retailer using AI to recommend products. A company that builds AI models carries different obligations than one that simply buys them.

Clause 4 forces those distinctions into the open. It turns vague good intentions into a documented picture of the organization’s circumstances, and that picture becomes the yardstick against which every later decision, from risk assessment to internal audit, is measured.

4.1 Understanding the Organization and Its Context

The first requirement is to identify the external and internal issues that are relevant to the organization’s purpose and that affect its ability to achieve the intended results of its AIMS. For AI, that list tends to be broad.

External issues: applicable laws and regulations (such as the EU AI Act), industry expectations, competitive pressure, public attitudes toward AI, and the maturity of available technology.

Internal issues: governance structure, organizational culture, internal policies, contractual obligations, available skills, and the organization’s appetite for risk.

Clause 4.1 also asks the organization to determine its role with respect to AI systems. Is it an AI producer, provider or user, or some combination? Each role carries different responsibilities, and many organizations play more than one. It must also consider the intended purpose of the AI systems it develops, provides, or uses.

For self-policing, this is where the organization defines its own jurisdiction. You cannot police what you have not identified, and you cannot hold yourself accountable for obligations you have not acknowledged.

4.2 Understanding the Needs and Expectations of Interested Parties

Next, the organization must identify the interested parties relevant to its AIMS, determine their relevant requirements, and decide which of those requirements it will address through the management system. In AI, interested parties reach well beyond customers and shareholders. They can include employees whose work is changed by automation, end users who interact with AI outputs, people who are the subject of AI decisions without ever touching the system, regulators, data suppliers, and the broader community.

This requirement is the conscience of a self-policing program. By asking “who could be affected, and what do they reasonably expect of us?”, the organization builds an outside perspective into its internal rules. Expectations around fairness, transparency, privacy, and human oversight often surface here first, long before they appear as formal complaints.

4.3 Determining the Scope of the AIMS

With context and stakeholders understood, the organization defines the boundaries and applicability of its AIMS. The scope must take into account the issues from 4.1 and the requirements from 4.2, and it must be available as documented information.

A well-defined scope answers practical questions: Which AI systems are covered? Which business units, locations, and processes? Which lifecycle stages, from design and data acquisition through deployment and retirement? A scope that is too narrow leaves high-risk systems ungoverned. One that is too broad spreads resources thin and weakens accountability. The goal is a scope that is honest about where AI risk actually lives.

4.4 The AI Management System

Finally, Clause 4.4 requires the organization to establish, implement, maintain, and continually improve an AIMS, including the processes needed and how they interact. This is the commitment that turns analysis into action. Context is not a one-time exercise; it feeds directly into leadership (Clause 5), risk planning and impact assessment (Clause 6), and the monitoring and improvement cycle of Clauses 9 and 10.

Putting Clause 4 to Work: Practical Steps

Build an AI inventory. List every AI system the organization develops, provides, or uses, including tools embedded in purchased software. Shadow AI is one of the most common blind spots.

Define your role for each system. Record whether you are the producer, provider and user and note where responsibilities are shared with vendors.

Run a structured context review. Use a PESTLE, SWOT, or similar analysis to capture external and internal issues, and revisit it when laws, technology, or business strategy change.

Map interested parties. Identify who is affected by each system, what they expect, and which of those expectations you will commit to meeting.

Write a scope statement you can defend. Document what is in, what is out, and why. Exclusions should be justified, not convenient.

Connect context to risk. Carry the issues and stakeholder requirements forward into your AI risk assessments and AI system impact assessments so nothing identified in Clause 4 is lost.

Common Pitfalls to Avoid

Treating context as paperwork. A context document written once and filed away quickly goes stale in a field that changes as fast as AI.

Overlooking indirect stakeholders. People affected by AI decisions are often not the people using the system.

Scoping out the hard parts. Excluding high-risk or high-visibility systems to simplify certification undermines the credibility of the entire program.

Ignoring third-party AI. Buying an AI capability does not transfer accountability for how it is used.

The Bottom Line

Self-policing an AI system is ultimately an exercise in self-knowledge. Clause 4 of ISO/IEC 42001 gives organizations a disciplined way to understand their environment, their stakeholders, their role, and the limits of their responsibility. That understanding is what makes every later control meaningful. Organizations that invest in getting their context right are better positioned to catch problems early, earn stakeholder trust, and demonstrate, to themselves and to others, that their AI is governed with intent. For further information email us at pjr@pjr.com or request a quote for ISO 42001 certification.

How ISO 14001 Certification Turns Data Centers Into Better Neighbors

10/1/2026
Files with

How ISO 14001 Certification Turns Data Centers Into Better Neighbors The Data Center Boom Has a Neighbor Problem The rise of cloud computing and AI has pushed data center construction into areas that were never built around industrial-scale infrastructure: suburban…

Read more

How ISO 14001 Certification Turns Data Centers Into Better Neighbors

The Data Center Boom Has a Neighbor Problem

The rise of cloud computing and AI has pushed data center construction into areas that were never built around industrial-scale infrastructure: suburban business parks, rural crossroads, and sites just down the road from residential neighborhoods. For the people living closest to these facilities, the concerns are significant. Cooling systems and backup generators run around the clock, producing a low mechanical hum that does not let up at night. Evaporative cooling towers draw heavily on local water supplies, sometimes in regions already under drought restrictions. Diesel generators tested regularly for backup readiness, add emissions and noise of their own. None of this shows up in a data center’s marketing material, but it is a reality for nearby neighborhoods.

What ISO 14001 Actually Requires: It Starts With Naming the Impact

ISO 14001 does not let an organization decide for itself which environmental concerns to include or exclude. Clause 6.1.2, Environmental Aspects, requires the organization to formally determine all of the environmental aspects, and their associated potential impacts, given the organization’s specific management system and operational scope – in other words, “its activities, products, and services that it can control and those it can influence”. This process must be documented with evidence and must employ a life cycle perspective. For a data center, that means impacts such as noise generation, water consumption and discharge, and emissions from backup power systems all must be identified and documented. A data center cannot simply ignore these issues if seeking certification to the standard.

The Standard Puts Neighbors on the Record

Clause 4.2, Understanding the Needs and Expectations of Interested Parties, requires the organization to identify the interested parties relevant to its environmental management system and determine which of their needs and expectations become compliance obligations. Local communities and neighbors are explicitly recognized as an interested party category under this clause, alongside regulators, customers, and employees. That means a certified data center has to ascertain what the surrounding neighborhood, as a relevant interested party, expects related to environmental conditions, such as noise pollution and water usage or discharge, not only what a permit requires. Clause 6.1.4, Risks and Opportunities, then carries those expectations forward by requiring the organization consider such external issues, and their associated environmental risks, compliance obligations, etc., to be formally addressed by the management system.

From Paperwork to Practice: Operational Controls

Identifying an impact only matters if it changes how the facility operates. Clause 8.1, Operational Planning and Control, requires the organization to establish operating criteria and implement controls for its significant environmental aspects, using a hierarchy of controls that vary from elimination and substitution to engineering and administrative measures. For noise concerns, acoustic enclosures, sound barriers, and equipment placement decisions can be built into standard procedure instead of being left to individual judgment. For water, cooling system design and discharge controls become documented operating criteria rather than informal practice.

Proof, Not Promises: Monitoring and Measurement

Clause 9.1, Monitoring, Measurement, Analysis and Evaluation, requires the organization to monitor and measure its environmental performance using defined methods and calibrated equipment (where applicable), and to evaluate the results against established criteria. In practice, that could look like ambient noise readings and water usage or discharge data, in the form of recurring, documented measurements instead of one-time assurances made to a zoning board. This is the clause that turns a general claim of managing environmental impact into a body of evidence a certification auditor, and by extension the surrounding community, can refer to for assurance.

Accountability Built Into the System

ISO 14001 also requires the organization to hold itself accountable. Clauses 9.2, Internal Audit, and 9.3, Management Review, require regular internal evaluation of whether the environmental management system is actually working; for example, meeting its objectives and requirements, and avoiding negative environmental impacts. Any gaps identified require resolution, and the standard holds leadership responsible for ensuring this is the case. Clause 10, Improvement, requires nonconformities to be fed through an established resolution process for corrective action and continual improvement. A noise complaint or a water usage overage is not simply resolved once; it becomes an input that tightens the operational controls described above to address the core issue(s). This is the mechanism that makes certification more than a one-time inspection: it is a standing obligation to keep finding and fixing gaps.

A Note on the People Inside the Fence

ISO 14001 is an environmental standard, so it addresses a data center’s impact on its surroundings: noise, water, emissions, waste. Occupational health and safety, protecting the people who work inside the facility, is addressed by a separate standard, ISO 45001. Some data center operators pursue both certifications together, since the two standards share a similar structure and can be integrated into a single management system. A dual-certified facility is addressing the full picture: the neighborhood outside the fence and the workforce inside it.

Bottom line: ISO 14001 does not just document a data center’s environmental impact. It requires the organization to identify it, control it, measure it, and prove improvement over time, with the surrounding community’s expectations built into the process from the start.

FAQs

Q: Does ISO 14001 cover the noise a data center produces?

A: Yes. Noise pollution is a potential environmental issue, and a certified organization must consider it, and potentially both control it through documented operating procedures and monitor it against defined criteria.

Q: Does ISO 14001 address the water a data center uses for cooling?

A: Yes. Water consumption and discharge fall under the same context, risk, and aspects and impacts requirements, and any related permits or local water restrictions become tracked compliance obligations under Clause 6.1.3.

Q: Is ISO 14001 the same standard that covers employee health and safety?

A: No. ISO 14001 is an environmental management standard. Occupational health and safety for workers is covered by ISO 45001, which data center operators may pursue alongside ISO 14001.

Q: How would a community know whether a data center is actually meeting its ISO 14001 commitments?

A: Certification requires ongoing internal audits, management review, and monitoring records under Clauses 9.1 through 9.3, plus annual third-party audits by an objective and competent Certification Body auditor. Certification status is generally verifiable through the Certification Body.

Data centers are not going away, and neither are the communities surrounding them. ISO 14001 certification gives operators a documented, auditable way to show they take that relationship, and their ability to impact their neighbors and nearby environment, seriously. Contact PJR to discuss ISO 14001 certification or ask about pairing it with ISO 45001 for a complete environmental and workforce safety program.

Preparing for the Change – Transition to ISO 9001:2026

9/23/2026
A sticky note with FAQ on it stuck on a paper with charts and question marks

Preparing for the Change – Transition to ISO 9001:2026 As everyone in the quality game is aware, the world now has a new version of ISO 9001. ISO standards touch almost everything we do, and they help to make the…

Read more

Preparing for the Change – Transition to ISO 9001:2026

As everyone in the quality game is aware, the world now has a new version of ISO 9001. ISO standards touch almost everything we do, and they help to make the world a safer and more efficient place. This drives the need to evaluate the effectiveness of the standard and make changes to drive continual improvement within our own organizations and industrywide.

The task of understanding the revised standard’s effect on your organization can be overwhelming. We at PJR want to ease our clients and potential clients into this new standard and have composed this simplified FAQ to address some of the most pressing questions and address what steps can be taken now to prepare for the coming change. In addition to this FAQ, PJR also offers an overview of changes via our ISO 9001:2026 webinar, with easy registration available at https://www.pjr.com/upcoming-webinars.

ISO 9001:2026 FAQs

Why is the ISO 9001 standard changing again?

The primary reason for the revision to ISO 9001 on this occasion is the update that took place earlier to the High-Level Outline (Annex SL) by the ISO. The most important change that took place at that level was the introduction of the concept of “culture.” In ISO 9001 this concept manifests as “Quality Culture.” This requirement has been sprinkled throughout ISO 9001 (appearing 13 times overall including 4 references in the auditable portion.) The basic concept can be boiled down to the idea that an ISO 9001 certified company should seek to make their quality management activities a “culture” or an embedded part of company life. The other significant update on this revision is the introduction of climate change language in the high-level outline. We’ve provided a separate Q&A below for this item.

What is the expected timeline?

The new standard was published on September 16, 2026. The GAC (this is the organization that manages ISO 9001 certifications from a high-level perspective) has indicated that they will allow a three-year transition period and will use the “end of the month” markers for the important deadlines. This means that the ISO 9001:2015 standard will become obsolete on September 30, 2029. As a result, all ISO 9001:2015 certifications issued in late 2026 and beyond will have to bear an expiry date of September 30, 2029.

Companies will be permitted to gain a new certification (either through a Stage 2 or Recertification audit) to ISO 9001:2015 through March 30, 2028 (this represents the halfway point of the transition timeline.) Companies will technically be permitted to perform surveillance audits to ISO 9001:2015 through September 30, 2029 – but PJR will cease offering audits of any kind to ISO 9001:2015 on June 30, 2029.

My audits are normally due in late July, and the transition period ends in September. Why can’t my company have its transition audit in late July 2029?

While it is true that the transition period does not end until September 30, 2029, it is not just required that your audit is conducted by this date. If any nonconformities are discovered during the audit, they must be addressed with corrective action, and PJR’s Executive Committee (decision-making body) must review and approve the audit package by the transition deadline. A late July 2029 audit likely does not provide enough time for this to happen. Thus, your organization could transition in July 2027, July 2028 or choose to have an earlier audit in 2029, perhaps May or June, to allow adequate time for completion of the post-audit process.

All transition audits must be completed within 90 days of the transition end date of September 30, 2029. Thus, all transition audits must be completed by June 30, 2029.

My organization is not yet certified. We have been working at implementing ISO 9001:2015 for a while. Can we still seek certification to the 2015 version of the standard and then transition later?

PJR appreciates that a lot of work may have gone into preparing for certification to ISO 9001:2015. Per the GAC requirements we will allow initial audits to the 2015 version of the standard until eighteen months into the transition period, or March 30, 2028.

Keep in mind that ISO 9001:2015 will be obsolete on September 30, 2029. Therefore, the expiration date on any 2015 certificate issued after the publication of ISO 9001:2015 will be September 30, 2029. Thus, it may appear that your organization is not being granted a full, three-year certificate. However, after successful transition to ISO 9001:2026, the expiry date of your certificate will be amended to reflect a full three-year certification.

What if we have a Recertification audit in early 2027, should we just plan on performing that audit to ISO 9001:2026?

This will be a strategic decision that each company makes on its own, but there are a few key points to bear in mind.

  • If you have had a chance to examine your quality system against the revised requirements and feel that you are ready, you can certainly request that your upcoming recertification audit be performed to ISO 9001:2026.
  • Timing the transition to your regular recertification audit is ideal, but not in any way mandatory.
  • You could certainly perform your 2027 Recertification Audit to ISO 9001:2015 and then complete a transition audit to ISO 9001:2026 in 2028 or 2029.

Is it better to transition earlier?

As described in the question above, it is important to avoid waiting until the last minute. However, there is no difference if you transition in April 2027, April 2028 or April 2029, for example. An ISO 9001:2015 certificate is still valid until the end of the transition period. In no way should an ISO 9001:2026 certificate be perceived as better than an ISO 9001:2015 certificate until the obsolescence date of that standard.

What happens if my organization doesn’t transition on time?

If your organization does not have a transition audit prior to the end of the transition period/obsolescence date of ISO 9001:2015, then you will no longer be certified as of the end of the transition period. To become certified to ISO 9001:2026, you will need to start over with an initial audit (Stage 1 and Stage 2).

If your organization does have its transition audit but the audit package is not closed prior to the end of the transition period/obsolescence date of ISO 9001:2015, then an ISO 9001:2026 certificate will be issued as soon as the package can be closed. This means that there will be a lapse in your certification status. Our Scheduling Department will work with you to ensure the timely scheduling of any transition audits that occur later in the transition period to avoid this unfortunate situation.

What are the critical changes?

PJR has prepared a separate presentation showing an overview of the changes to the standard. The summation of that report can be stated as follows: “nothing of significance.” The Quality Culture and Climate Change updates are frankly the only updates of any minor impact. There are other more nuanced changes, but none of these should have any significant impact for a company already certified to ISO 9001:2015.

What is Annex SL, and what does it have to do with ISO 9001?

Annex SL is a portion of the “ISO/IEC Directives Part 1 – Procedures for the technical work – Consolidated ISO Supplement – Procedures specific to ISO” document. This standard regulates and controls the process of developing, updating, and issuing ISO published standards.

The full text of Directives Part 1, including the Annex SL portion can be found here: https://www.iso.org/sites/directives/current/consolidated/index.html

Annex SL can be thought of as a ten-section blueprint to be used for all ISO standards. It promotes (among other things) common terms and core definitions for many of the terms used in the ISO family of standards. It is through the mandatory structure of Annex SL that organizations will be better enabled to achieve multiple certifications such as ISO 9001, ISO 14001, and ISO 45001, because each of these standards will have the same 10 sections and the same core terms and definitions.

We’ve already been certified for a long time, and our procedures are well implemented, do we have to change them?

PJR’s analysis has concluded that for the average ISO 9001:2015 certified company, the impact of the revised standard will be minimal and quite manageable. It is important to bear in mind that the ISO is seeking greater inclusion for the ISO 9001 standard. They want to see it continue to grow into new sectors and be even more user friendly than it is now. Requiring a company to aggressively overhaul their current ISO 9001:2015 system is not consistent with this objective.

Tell me more about the new “Climate Change” requirement

This requirement actually isn’t new. It was originally published as an officially binding addendum to ISO 9001:2015 in 2024. Despite what some sources are claiming, the “climate change” requirements are very minimal in ISO 9001:2026. They can be summarized thusly:
All ISO 9001 certified companies must consider Climate Change as a potentially relevant issue to their quality management system and act accordingly.

Note that it is absolutely possible for an organization to conclude that climate change has no bearing on them or their interested parties – PJR just needs to be able to see evidence of how that decision was reached.

Will our staff have to complete transition training?

It will depend on the extent of revisions that you make to your quality management system, but generally yes, you will be expected to provide some form of transition training to your staff.

At a minimum, PJR would expect that awareness training of the new standard would be provided, as well as an assessment of the new standard’s impact on the various processes and personnel. However, it is entirely conceivable that the majority of your staff will feel no effect from your company’s transition to ISO 9001:2026.

What about our internal auditors, will they have to complete transitional training?

Internal auditing is viewed in the same light as any other required competency within a quality management system. Namely, the organization is responsible for determining what competencies are required for its internal auditors, as well as the methods to be used to achieve those competencies.

To put it more plainly, each organization will have to decide on its own the extent to which transition training will be needed. It is conceivable that a seasoned team of internal auditors could complete a period of self-study and successfully transition to auditing ISO 9001:2026. As has always been the case, the competency of your internal auditors will be judged by the overall effectiveness of your internal audit process.

Will the other standards (AS9100, IATF 16949, etc.) be updated also?

All of the major sector specific standards, including IATF 16949, AS9100, and TL9000 have indicated their intentions to transition and continue their alignment with ISO 9001. The timelines for these other standard updates are not fully known at this time, but a 2026 or 2027 publication date seems likely for all three. At present the only major standard that is not planning to update is ISO 13485:2016.

What steps can we take right now?

PJR recommends the following steps be taken in a transition to ISO 9001:2026:

  1. A full review of the ISO 9001:2026 standard should be performed by Top Management to identify the gaps that need to be addressed.
  2. A plan of implementation should be developed with assigned responsibilities.
  3. All quality management system documents (including the quality and procedures manual, if applicable) should be updated to reflect any new or revised processes.
  4. All necessary awareness and transition training should be completed.
  5. A full system internal audit followed by a Management Review should be complete.
  6. Corrective Actions for all internal audit findings should be in process or complete.
  7. Coordinate with PJR for planning of transition arrangements.

Will extra audit time be needed for my transition audit?

Potentially and only if you plan on transitioning on a surveillance audit. This is based on guidance provided by the GAC which states the following: “In determining if additional audit time is needed, the certification body shall consider, at a minimum, the degree of change to the client’s management system.”

If you plan to transition as part of a surveillance audit you can expect to receive a short pre-audit questionnaire from PJR that will enable us to ascertain how much of an impact ISO 9001:2026 has had on your quality management system. Because surveillance audits are typically shorter in duration than recertification audits, and based on what we learn from the questionnaire, we may conclude that a small measure of added time is needed.

If you plan to transition as part of a recertification audit PJR has concluded that no additional time will be needed.

Our organization is considering transferring our accredited ISO 9001:2015 certification to PJR. How does the transition timeline impact our plans to transfer?

The requirements will be the same whether you are a currently certified PJR client or a transfer candidate. PJR will transfer an ISO 9001:2015 certificate until March 30, 2028. Subsequent to this date, we cannot guarantee that all transition activities will be completed prior to the transition deadline.

These helpful ISO 9001 transition FAQ’s are also be available via download.

Should you have further questions or require assistance please contact PJR for a Project Manager.
Website: www.pjr.com • Phone: (248) 358-3388 • Email: pjr@pjr.com

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

8/3/2026
Group of businesspeople holding jigsaw puzzles, team solving and planning together

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot) A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc. If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about…

Read more

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc.

If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about the upcoming 2026 revision. Perry Johnson Registrars, Inc. (PJR) recently hosted a webinar breaking down what’s on the horizon. The short version: change is coming, but it’s evolutionary, not revolutionary.

A Quick Refresher: Where ISO 9001 Comes From

ISO standards are developed by dedicated Technical Committees. For ISO 9001, that’s Technical Committee 176 (TC 176), which draws members from major industrialized nations, including the American National Standards Institute (ANSI).

A significant portion of the standard’s content is mandatory boilerplate defined by Annex SL, the shared structure that allows ISO 9001 to align with other management system standards.

Where Things Stand: Timeline Update

ISO/FDIS 9001 (Final Draft International Standard) was issued for review and approval voting in May 2026, the last formal step before publication. Earlier milestones:

  • Committee Draft released in April 2024
  • Draft International Standard (DIS) released in June 2025

Publication is expected in September or October 2026. Once published, existing ISO 9001:2015 certifications remain valid for three years.

What’s Staying the Same

The most reassuring takeaway from PJR’s analysis is how much is not changing. Specifically, ISO 9001:2026:

  • Maintains the familiar 10-section auditable structure and section titles used in ISO 9001:2015.
  • Keeps the same minimal documentation requirements; no procedures are mandated.
  • Preserves the process approach that has anchored ISO 9001 since the 2000 revision.
  • Retains the Plan-Do-Check-Act (PDCA) methodology.
  • Introduces no new substantive terminology or definitions beyond what already exists in the 2015 version.
  • Keeps every concept introduced in 2015 fully intact: Risk, Interested Parties, Internal/External Issues, Organizational Knowledge, and Manageent Accountability all remain.

What’s Actually Changing

PJR’s review of the FDIS found few substantive changes, but they’re worth understanding.

Climate Change Language

This isn’t new. A February 2024 amendment added climate change considerations to sections 4.1 and 4.2, and that language carries forward unchanged. Organizations must consider whether climate change is a relevant issue to their quality management system and be able to show the reasoning, even if the answer is “it isn’t relevant to us.”

The Rise of “Quality Culture”

The phrase “Quality Culture” now appears throughout the standard. The idea is straightforward: quality shouldn’t be a checklist exercise; it should be woven into how a company operates day to day. It surfaces in several auditable clauses:

  • Clause 4.1 ties “culture” to the existing concept of organizational “context.”
  • Clause 5.1.1 assigns Top Management responsibility for promoting and empowering a quality culture.
  • Clause 7.1.4 links quality culture to an organization’s environmental factors (social, physical, etc.).
  • Clause 7.3 requires organizations to ensure employees are aware of the quality culture.

“Quality Culture” appears in nine additional places within the FDIS, and final wording may shift before publication.

A Possible Tweak to Your Quality Policy

Clause 5.2.1(e) now requires that an organization’s quality policy “take into account the context of the organization and support its strategic direction.” Most companies already meet this, but it’s a good opportunity to revisit your policy and confirm it still fits.

Risk Triggers Get a Clearer Definition

Clause 6.1.2 now states that organizations must determine, analyze, and evaluate risks affecting their ability to consistently deliver conforming products and services. This clarifies original intent rather than introducing something new.

“Opportunities” Gets Its Own Clause

Previously bundled with Risk, “Opportunities” now has its own clause 6.1.3. The wording mirrors 6.1.2, but the message is clear: risks and opportunities are distinct, and organizations should be ready to explain how each is addressed.

Documented Information Language Shifts Again

ISO 9001:2015 replaced the plain terms “document” and “record” with “documented information,” distinguished only by the verbs “maintain” and “retain.” The 2026 revision doesn’t simplify this; it introduces new phrasing instead:

  • “…shall be available as documented information” implies a document requirement.
  • “Appropriate documented information shall be available as evidence of…” implies a record requirement.

The key word to watch for going forward is “evidence,” which is now the separator between the two.

Customer Communication Adds Contingency Planning

Clause 8.2.1 now requires organizations to communicate with customers about agreed-upon responsibilities for contingency actions, where relevant. Specific guidance is expected after publication.

Social Media as a Customer Satisfaction Input

A new note to clause 9.1.2 recognizes social media as a legitimate source for gauging customer perception. How organizations monitor and act on this will vary by industry and company size.

Other Notable Smaller Changes

  • Clause 5.3: Top Management must now assign responsibility for reporting on opportunities for improvement.
  • Clause 6.3 adds non-binding guidance on planning and executing changes effectively.
  • Clause 8.4.3 adds an “as appropriate” qualifier to purchase order information requirements.
  • Clause 10.2.1 clarifies (via a note) that customer complaints remain a potential, not mandatory, input to Corrective Action.

Annex A Guidance Expands Significantly

Annex A, the non-enforceable guidance portion of the standard, grows from roughly two pages to eleven and has been renumbered to align with the main clause numbers. Nothing in Annex A is auditable, but it now offers expanded guidance on structure and terminology, leadership and commitment, risks and opportunities, and management review intervals.

The Bottom Line: Minimal Disruption Expected

PJR’s conclusion is simple: the substantive changes are minimal, and organizations certified to ISO 9001:2015 should find the shift manageable. PJR does not anticipate changes to its audit process, including the Leadership Interview. A handful of new prompts may be added to audit documentation, but core auditing practices will remain consistent.

How Will the Transition Work?

A three-year transition period will begin once ISO 9001:2026 is formally published. In practical terms:

  • Any organization certified to ISO 9001:2015 after the 2026 standard publishes will receive a certificate valid for less than three years. If the standard publishes October 2, 2026, a company certified December 2, 2026 would receive a certificate expiring October 1, 2029.
  • PJR intends to offer ISO 9001:2026 audits within weeks of publication, prioritizing organizations whose certificates expire between October 2026 and January 2027.
  • Organizations with certificates expiring in 2027 will need to decide how to proceed; recertifying to ISO 9001:2015 first means the transition occurs during a surveillance audit.

PJR has not set a date for when it will stop offering ISO 9001:2015 certifications; that decision likely won’t be finalized until mid-2027.

Will Staff and Internal Auditors Need Training?

In most cases, yes, though the scope depends on how much your quality management system actually changes. At a minimum, PJR recommends awareness training plus an assessment of the standard’s impact on your processes and personnel. Many employees will notice little change day to day.

For internal auditors, the expectation is the same as with any required competency: your organization determines what’s needed. A seasoned team may be able to transition through self-study alone.

Looking Ahead

ISO 9001:2026 continues a standard with nearly 40 years of history. The publication date is still a few months away, but the direction is clear: organizations already doing quality management well won’t need to reinvent their systems. A thoughtful review of your quality policy, risk and opportunity processes, and documentation language will go a long way toward a smooth transition.

PJR will continue to share updates, articles, and webinars as ISO 9001:2026 moves toward publication, and we’re committed to making the transition as smooth as possible.

Contact Perry Johnson Registrars, Inc.
Website: www.pjr.com • Phone: (248) 358-3388 • Email: pjr@pjr.com