Systemic Integrated Risk Intelligence Solution

ISO 9001:2026: 5 questions your quality manager will soon need to ask themselves

«Are we going to have to start all over again?» This is probably one of the first questions quality managers ask themselves as ISO 9001:2026 approaches. Processes, procedures, risk analyses, indicators, documentation, audits…

«Are we going to have to start all over again?»

This is probably one of the first questions that quality managers ask themselves when preparing for ISO 9001:2026.

Processes, procedures, risk assessments, indicators, documentation, audits… when a quality system has been in place for several years, the announcement of a new version can quickly conjure up the image of a major undertaking.

The good news is: you don’t have to start from scratch.

The forthcoming edition retains the tried-and-tested framework of ISO 9001 whilst introducing targeted changes: these include clarified requirements, a stronger emphasis on leadership and quality culture, and a clearer distinction between risks and opportunities, amongst other things.

For an organisation that is already certified, the real challenge will therefore be, above all, to determine what is changing, how this affects her, and what actually needs to be adapted.

And that’s where the good questions begin.

The 5 questions you should ask yourself

What will actually change for our organisation?

Reading the list of changes in ISO 9001:2026 is one thing.

To know what they are going to change within your own quality management system is another one.

Because a change to the standard does not necessarily mean you need to review all your processes and documentation. The first step is to compare the new requirements with what already exists: what is already covered? Where are there any gaps? And do these gaps really require any changes?

In other words: Before making any changes, you need to know where to look.

And that is often where the real work begins.

A requirement may have implications for several processes, involve different managers and necessitate a review of existing documents, controls or practices. If these links are not clearly established, every new development may trigger a fresh investigation : Where have we dealt with this point? Who is affected? What do we need to check?

When requirements are directly linked to the organisation’s processes, the reasoning changes: We no longer search everywhere for areas that the standard might affect. We start with the requirement to identify the areas where the analysis needs to be carried out

Comment piloter les exigences et leur impact avec SIRIS+

Here, for example, a data protection requirement is directly linked to the relevant processes. If this requirement changes, the data controller already has a starting point for determining which activities need to be reviewed.

That does not mean that the tool decides for them what needs to change. It helps him know where to focus his attention.

And in a normative transition, this distinction can save a great deal of unnecessary research.

Which processes and components of our system will be affected?

A new requirement never stands alone.

It may have an impact on a process, a procedure, a control, a risk, a responsibility or an indicator.

Let’s take an example.

Whilst expectations regarding quality culture and leadership are changing, it will not necessarily be enough simply to amend a document entitled «Quality Policy».

We may need to look at how these principles are actually put into practice in:

  • responsibilities; ;
  • raising staff awareness; ;
  • management practices; ;
  • the objectives; ;
  • inspections; ;
  • management reviews; ;
  • improvement measures.

This is often where the transition becomes time-consuming: not understanding a new requirement, but identifying all the places where it has an impact.

A connected management system is precisely what helps to avoid this silo-based approach. The requirement can be linked to the relevant processes and then to the elements needed to manage it.

The question is therefore no longer:

«When did we talk about that?»

but:

«Who is affected and who needs to take action?»

Are we really managing the risks… and the opportunities?

The word «risk» has taken on a significant role in management systems since ISO 9001:2015.

But his neighbour has sometimes received less attention: the right time.

The forthcoming edition does indeed provide greater clarity on the distinction between risks and opportunities and reinforces the idea of taking a proactive approach to the latter.

An opportunity isn’t necessarily spectacular.

It can be very practical: to reduce the time spent preparing for audits, to streamline a process, eliminate duplicate data entry, improve the flow of information or automate a repetitive monitoring task.

But that’s not all to identify these opportunities, assess them and decide which ones are worth pursuing.

As with risks, a matrix allows them to be categorised according to their probability and impact.

Here, for example, «Prepare for audits on an ongoing basis» is identified as a high-probability, high-impact opportunity, directly linked to the «Audit Management» process.

So the question is no longer simply:

«What could possibly go wrong?»

But also:

«What should we be doing better?»

Risk management safeguards performance. Opportunity management can also help to drive it.

Does our quality system exist outside the quality department?

This is probably one of the most important issues in this review.

ISO 9001:2026 places greater emphasis on leadership, a culture of quality, accountability and ethical behaviour.

In other words, quality cannot be confined solely to the procedures followed by the quality manager.

It must be reflected in decisions, behaviour and day-to-day practices.

And that is where organisational realities can get in the way of good intentions.

If the quality manager is the person who:

  • updates the information; ;
  • relaunches the initiatives; ;
  • monitors deadlines; ;
  • prepares the audits; ;
  • collects evidence; ;
  • and reminds everyone what they need to do…

Is the system actually shared?

Or does it mainly work because one person makes up for it?

A digital management system does not, of course, create a culture of quality on its own.

But it can help to provide a framework: clear responsibilities, assigned tasks, accessible information, monitored deadlines and a shared understanding of progress.

The tool is no substitute for people’s commitment.

It ensures that this commitment does not rely solely on memory and reminders from the quality manager.

Will we be able to demonstrate in simple terms what we have adapted?

A few months after the transition, a question is likely to come up eventually:

«How have you taken the new requirements of ISO 9001:2026 into account?»

And that’s when the difference between to have done and to be able to demonstrate what has been done becomes important.

❌ Which requirements were analysed?

❌ Which processes were affected?

❌ What discrepancies have been identified?

❌ What measures have been decided upon?

❌ Who was responsible?

❌ What checks were carried out?

❌ Where is the evidence?

When this information is scattered across emails, Excel files, documents and several shared folders, Simply finding out where the transition actually stands can be a task in itself.

Conversely, centralising monitoring provides an immediate overview of the situation: compliance levels, risks, actions to be taken, requirements to be addressed and recently amended documents.

Risques, niveau de conformité, actions, exigences : l'essentiel en un coup d'oeil

Risks, compliance levels, actions, requirements: a centralised overview makes it possible to monitor changes to the system as they occur, rather than having to reconstruct its history at the time of the audit.

The aim is not to reconstruct the history of the transition at the time of the audit, but to be able to monitor it as it unfolds.

ISO 9001:2026: preparing for the transition WITHOUT rebuilding your system

The forthcoming edition of ISO 9001 does not require certified organisations to scrap ten years’ worth of quality management systems and start afresh.

ISO states that a transition period will be provided to allow certified organisations to adapt.

So, above all, it’s an opportunity to look at one’s system in a different light.

Not only that:

«Which documents do we need to amend?»

But:

«Are we able to quickly understand what is changing, where it affects us, who needs to take action, and how we are going to demonstrate this?»

A quality system in which requirements, processes, risks, opportunities, controls, actions and indicators are linked enables us to tackle this development with greater clarity.

And perhaps this is, after all, one of the most interesting lessons to be learnt from’ISO 9001:2026 :

A mature quality system is not one that has the most documentation.

It is what enables the organisation to understand, make decisions, take action and adapt.