ISO 9001:2026: what changed, what didn't, and what an auditor will actually ask for
Jonathan Phillips, Lead Auditor. Published 21 September 2026.
ISO 9001:2026 was published on 16 September 2026. It replaces ISO 9001:2015 and the 2024 climate change amendment. This page sets out what changed, based on the published text, not the drafts.
If you are certified to the 2015 edition, the short version is this. The changes are real but small. None of them requires a new document. Most of the work is in showing evidence for things you probably already do.
What did not change
The clause structure. Clauses 4 to 10 are the same, with one renumbering in clause 10.
The list of documented information the standard requires. Nothing was added to it.
The scope, the process approach, and the way exclusions work.
Your certificate. It stays valid through the transition period.
What changed
Six changes carry weight in an audit.
Quality culture and ethical behaviour (5.1.1 and 7.3). Top management must promote both. Everyone working under your control must be aware of both. The standard does not say how. A note says culture and ethics show in shared values, attitudes, practices and actions. That is a description of behaviour, not of a document.
Risks and opportunities are separated (6.1.2 and 6.1.3). Under 2015 they were handled together, and most organisations kept one register where every opportunity was the reverse of a risk. Now each has its own clause. For each you determine, analyse and evaluate, plan actions, build them into your processes, and check whether they worked. Annex A adds that risk-based thinking does not imply a formal risk management approach or a documented risk process.
Planning of changes (6.3). Four considerations become seven. The new ones are how the change is communicated, how its effectiveness is monitored and evaluated, and how the results are reviewed. Your transition to 2026 is itself a change to the QMS. Plan it this way and you have your first piece of evidence.
Interested parties (4.2). A new item: you decide which of their requirements will be addressed through the QMS. This one has had almost no coverage. It is a decision, and you should be able to say who made it and why.
Internal audit (9.2.2). Each audit must have defined objectives, as well as criteria and scope. A line on your audit plan covers it.
Analysis and management review (9.1.3 and 9.3.2). The effectiveness of actions on risks and on opportunities are now listed separately, as inputs to both.
Smaller changes:
The climate change amendment from 2024 is now built into 4.1 and 4.2.
Organisational knowledge (7.1.6) is now tied to the intended results of the QMS, and must be retained, applied and shared.
Customer communication (8.2.1) now includes information about disruptions to supply.
Clause 3 now defines 20 core terms itself. ISO 9000 is still the reference.
The old 10.1 and 10.3 are merged into a new 10.1. There is no 10.3.
Annex A is rewritten as clause-by-clause clarification. Annex B is removed.
Documents versus evidence
This is where most of the online advice goes wrong. Several sites say you now need an ethics policy, a separate opportunity register and a change management procedure. The standard says none of that.
What an auditor needs is evidence. Evidence is anything that shows the requirement is met. A conversation with your managing director is evidence. A management review minute is evidence. So is an email to customers about a late delivery.
A register or a policy is one way to hold evidence. It is often the easiest way, and I am not against it. But it is a choice, not a requirement, and a document nobody uses is worse than no document at all. An auditor will see through it in five minutes.
So the question for each change is not "which template do I need?" It is "what would I show someone who asked?"
What an auditor will ask
For culture and ethics, the questions go to top management first. How do you promote a quality culture here? Give me an example where quality or doing the right thing won over cost or deadline. Then the same ground is covered with staff. What would you do if you were asked to pass something you thought was wrong? Who would you tell? The auditor is checking whether the two answers match.
For risks and opportunities: pick one. What did you do about it? How do you know it worked? Show me an opportunity that is not simply the flip side of a risk.
For planning of changes: take me through your last change to the QMS. Who was told? How did you check it worked?
None of these can be answered with a template.
Transition
A three-year transition period is expected, which would run to September 2029. The formal rules come from the IAF and the accreditation bodies, and at the time of writing they have not been published. Certification bodies also have to be accredited for the new edition before they can audit to it. Ask yours when that will be and how it plans to handle your transition.
Until your certificate is reissued, you are certified to ISO 9001:2015. Do not change your website, tender documents or email footers before then.
What to do now
Get a licensed copy of ISO 9001:2026. You cannot assess against a standard you do not hold.
Run a gap check against the changes above. It takes an afternoon.
Plan the transition as a change under 6.3.
Brief top management. The culture and ethics questions will go to them, not to the quality manager.
Update your internal audit criteria and audit the changed clauses at least once before your transition audit.
Hold a management review with the new inputs.
A free clause cross-map
I have put together a one-page map of every clause and list item that moved between 2015 and 2026, including the clause 10 renumbering. It is free. [Link to follow.]
Jonathan Phillips is Managing Director of BS Partnership Ltd, Cardiff, and has audited against ISO 9001 for 28 years. This page describes the standard in his own words and does not reproduce its text. You need your own copy of ISO 9001:2026 to apply it.