Edition analysed: ISO 9001:2015 · historical reference. Official entry for the 2015 edition: ISO 9001:2015 on iso.org ↗. Current edition: ISO 9001:2026 on iso.org ↗. The analysis below relates to the 2015 edition.
ISO 9001 organises quality as a system: processes, responsibilities, risks, measurement, customer satisfaction and improvement. A rigorous assessment starts with a simple question: what can the organisation demonstrate when it says it manages quality?
Evidence that carries weight
- Records of actual operations, not just approved procedures.
- Management review minutes with decisions, resources and follow-up.
- Indicators used to make decisions, not decorative dashboards.
- Evidence of improvement and effective closure of findings.
Where it tends to fail
- Procedures that exist but do not govern operations.
- Indicators with no owner, no target or no associated decision.
- Corrective actions that fix paperwork but not causes.
- Management review reduced to an annual formality.
- Is an ISO 9001 diagnostic assessment equivalent to certification?
- No. A diagnostic assessment identifies gaps, available evidence, risks and system architecture. Certification is issued by a certification body within its scope.
- What does an auditor look at first in ISO 9001?
- They look at whether actual processes are defined, measured, controlled and reviewed by management with traceable evidence.
↑ Back to index ISO/IEC 27001 is not a list of technical controls. It is a management system for governing information risks, defining scope, selecting controls, managing evidence in practice and reviewing whether security supports the business.
Evidence that carries weight
- Asset inventory and information classification.
- Up-to-date risk matrix and treatment decisions.
- SoA linked to actual controls, responsible parties and evidence.
- Records of incidents, tests, access reviews and internal audits.
Where it tends to fail
- Confusing a security tool with a management system.
- Generic or copied statement of applicability.
- Risks with no owner, no treatment or no evidence of monitoring.
- Controls operated by IT without top management involvement.
- Does ISO/IEC 27001 certify total cybersecurity?
- No. It certifies an information security management system within a defined scope. It does not guarantee the absence of incidents or cover anything outside the declared scope.
- What is the most common mistake before ISO 27001 certification?
- Having isolated technical controls without a risk methodology, a defensible SoA or evidence of sustained management.
↑ Back to index ISO/IEC 42001 enables artificial intelligence to be structured as a management system. The question is not whether the organisation uses AI, but whether it can demonstrate how it governs it, who is accountable, which risks it controls and when a person intervenes.
Evidence that carries weight
- Register of AI use cases and AIMS scope.
- Documented impact assessments and risk criteria.
- Evidence of effective human oversight and the ability to intervene.
- Controls over suppliers, data, performance, incidents and changes.
Where it tends to fail
- Using AI without an organisation-wide inventory or identifiable accountable individuals.
- Confusing an AI policy with an AI management system.
- Nominal human oversight with no real ability to block or correct.
- Dependence on suppliers without contractual, technical or operational evidence.
- Does ISO/IEC 42001 certify an AI model?
- Not in general terms. It enables certification of an AI management system within a defined scope. It does not, in itself, make every model responsible, safe or mature.
- Where should an ISO 42001 diagnostic assessment start?
- With an inventory of AI uses, accountable individuals, risks, suppliers, data, impact and evidence of human oversight.
↑ Back to index ISO 14001 requires the environment to be assessed through real processes: aspects, impacts, compliance obligations, operational controls, emergencies, objectives and improvement. Environmental management is not demonstrated through rhetoric: it is demonstrated through traceability.
Evidence that carries weight
- Up-to-date aspects and impacts matrix.
- Records of legal compliance, permits, monitoring and controls.
- Environmental indicators with trends and actions.
- Drills, environmental incidents and corrective actions.
Where it tends to fail
- Generic environmental aspects with no connection to actual operations.
- Outdated legal requirements matrix or one without evidence of compliance.
- Environmental objectives that are merely decorative.
- Operational controls without measurement or verification.
- Does ISO 14001 require perfect legal compliance?
- It requires identifying, evaluating and managing applicable compliance obligations, with evidence of monitoring and treatment when deviations occur.
- What distinguishes ISO 14001 from an environmental policy?
- The policy declares intent. The EMS demonstrates operational control, responsibilities, measurement, compliance and improvement.
↑ Back to index ISO 45001 structures occupational health and safety as a prevention system. The assessment must go into the field: real hazards, controls, worker participation, incidents, contractors and management decisions.
Evidence that carries weight
- Hazard identification and risk assessment matrix or an equivalent methodology, with genuine updates.
- Records of training, permits, inspections and controls.
- Incident investigations and effectiveness of actions.
- Evidence of participation, consultation and contractor control.
Where it tends to fail
- Risk matrices that do not reflect conditions in the field.
- Recorded training without verification of competence.
- Contractors outside the system.
- Incident investigations that do not reach the root cause.
- What does an ISO 45001 audit examine in the field?
- It cross-checks hazards, controls, permits, operational behaviour, incidents, contractors and documentary evidence.
- Does ISO 45001 replace legal OH&S obligations?
- No. It helps manage them within a system, but does not replace applicable legal compliance.
↑ Back to index ISO 37001 is not an ethical declaration. It is a system for identifying bribery risks, defining controls, assessing third parties, investigating alerts and demonstrating top management commitment.
Evidence that carries weight
- Documented and up-to-date risk assessments.
- Records of due diligence and third-party approval.
- Controls over payments, gifts, conflicts of interest and contracting.
- Evidence of investigations, whistleblower protection and actions taken.
Where it tends to fail
- Integrity programme without operational evidence.
- Generic due diligence on critical third parties.
- Reporting channels without documented investigations.
- Top management that approves policies but does not review risks.
- Does ISO 37001 eliminate bribery risk?
- No. It defines a reasonable system of prevention, detection, response and improvement. No serious system promises zero risk.
- What evidence matters in ISO 37001?
- Risks, third parties, controls, reports, investigations, decisions, training and management review.
↑ Back to index ISO 50001 turns energy into a management system: baseline, significant uses, indicators, objectives, measurement, procurement, design and performance improvement.
Evidence that carries weight
- Consumption data, relevant variables and baseline.
- EnPIs with a methodology and an accountable person.
- Improvement projects with before/after measurements.
- Records of energy reviews and management decisions.
Where it tends to fail
- Measuring consumption without a defensible baseline.
- Energy indicators without relevant variables.
- Savings projects without verification of results.
- Energy management isolated from operational decisions.
- Does ISO 50001 require consumption to be reduced every year?
- It requires improved energy performance within the scope, with a baseline, indicators and evidence of effective actions.
- What is reviewed first?
- Data quality, the baseline, significant energy uses and the indicators used for decision-making.
↑ Back to index ISO 22301 asks what must keep working when something fails. A rigorous assessment reviews the BIA, priorities, dependencies, strategies, plans, exercises and learning.
Evidence that carries weight
- BIA updated and approved by business owners.
- Tested plans with results and follow-up actions.
- Incident, drill and recovery records.
- Critical dependencies and agreements with third parties.
Where it tends to fail
- Plans that no one has tested.
- BIA outdated or prepared without process owners.
- Critical dependencies not inventoried.
- Continuity treated as an IT issue rather than a business issue.
- Is ISO 22301 only about disaster recovery?
- No. It includes business continuity, crises, dependencies, testing and improvement. IT is one part, not the entire system.
- Which evidence carries the most weight?
- Real tests, results, recovery times, decisions made and subsequent corrective actions.
↑ Back to index ISO 22000 integrates management, HACCP, prerequisite programmes, traceability, communication and improvement. Food safety is not sustained by a folder: it is sustained by the process.
Evidence that carries weight
- HACCP plan and control records.
- Batch-by-batch traceability and recall testing.
- PRP, cleaning, maintenance and monitoring records.
- Verifications, deviations and corrective actions.
Where it tends to fail
- HACCP copied without any connection to the actual process.
- Traceability not tested through to an effective recall.
- Prerequisite programmes without reliable records.
- Deviations treated as isolated incidents.
- Does ISO 22000 replace HACCP?
- No. It integrates it into a management system with leadership, processes, communication, verification and improvement.
- What is reviewed in a food safety diagnostic assessment?
- Hazards, controls, PRPs, traceability, recall, suppliers, records and system effectiveness.
↑ Back to index ISO 13485 requires regulated quality: design, production, sterilisation where applicable, traceability, validation, suppliers, complaints and post-market surveillance.
Evidence that carries weight
- DHF/DMR or another equivalent documentation structure according to scope.
- Validation, traceability and release records.
- Critical supplier evaluation and controls.
- Complaints, CAPA and post-market evidence.
Where it tends to fail
- Using ISO 9001 logic without regulated design and validation control.
- Critical suppliers without sufficient evaluation.
- Incomplete traceability by batch, serial number or component.
- CAPA without thorough cause investigation.
- Does ISO 13485 replace regulatory requirements for medical devices?
- No. It helps structure the quality system, but must be integrated with the regulatory requirements applicable to the product and market.
- What distinguishes ISO 13485 from ISO 9001?
- ISO 13485 focuses on safety, regulation, traceability, validation, suppliers and the medical device life cycle.
↑ Back to index ISO 22716 structures good manufacturing practices for cosmetics: personnel, premises, equipment, production, control, storage, dispatch, deviations and complaints. An auditor's perspective distinguishes production routines, evidence and traceability.
Evidence that carries weight
- Batch, cleaning, inspection, release and storage records.
- Specifications, certificates, raw material and finished product controls.
- Batch traceability and evidence of recall or blocking where appropriate.
- Management of complaints, deviations and corrective actions.
Where it tends to fail
- Incomplete traceability between formula, batch and inputs.
- Cleaning and contamination control without reliable records.
- Outsourcing without technical evaluation of the supplier.
- Complaints treated as customer service rather than system evidence.
- How does ISO 22716 differ from ISO 9001?
- ISO 9001 structures general quality management. ISO 22716 applies that approach to specific good practices for the manufacture, control, storage and dispatch of cosmetic products.
- What is examined first in cosmetics?
- Production flow, hygiene, raw materials, batches, release, traceability, complaints and change control are reviewed.
↑ Back to index ISO/IEC 20000-1 turns IT service operations into a system: catalogue, agreements, incidents, problems, changes, configuration, continuity, suppliers and improvement. The diagnostic assessment looks at whether the service is governed or merely supported.
Evidence that carries weight
- Tickets, times, priorities, root cause and effective closure.
- Change, approval, failure and rollback records.
- SLA indicators and reports to customers or management.
- Contracts, suppliers, continuity and capacity management.
Where it tends to fail
- Measuring tickets without governing the service.
- Urgent changes without traceability or approval.
- SLAs promised without the operational capacity to meet them.
- Critical suppliers outside the service architecture.
- Is ISO/IEC 20000-1 the same as ITIL?
- No. ITIL is a good practice framework; ISO/IEC 20000-1 sets requirements for a service management system.
- Which evidence carries the most weight in IT services?
- SLAs, tickets, changes, problems, suppliers, continuity, performance reports and improvement decisions.
↑ Back to index ISO/IEC 17025 requires demonstrated technical competence: methods, personnel, equipment, metrological traceability, uncertainty, assurance of validity and reporting of results. A tidy documentation system is not enough.
Evidence that carries weight
- Validated or verified methods and complete technical records.
- Calibration certificates, maintenance and metrological traceability.
- Proficiency testing, quality controls and review of results.
- Authorised competence, issued reports and handling of deviations.
Where it tends to fail
- Confusing ISO/IEC 17025 with ISO 9001 for laboratories.
- Methods used without sufficient verification for the actual scope.
- Uncertainty stated but not understood by decision-makers.
- Calibrated equipment without analysis of its impact on results.
- Does ISO/IEC 17025 assess only documents?
- No. The focus is technical competence: methods, personnel, equipment, traceability, uncertainty, validity of results and impartiality.
- How does it differ from ISO 9001?
- ISO 9001 structures general quality management. ISO/IEC 17025 requires laboratories to demonstrate that they produce technically valid results within their scope.
↑ Back to index ISO 55001 structures asset management as a system: value, risk, life cycle, data, maintenance, investments, performance and decisions. The assessment examines whether assets are administered or truly governed.
Evidence that carries weight
- Asset register with criticality, condition, owner and reliable data.
- Maintenance plans, history, failures, costs and performance.
- Risk assessments and investment or renewal decisions.
- Availability, reliability, safety and value indicators.
Where it tends to fail
- Asset inventories that are incomplete or disconnected from decisions.
- Reactive maintenance presented as asset management.
- Technical indicators without financial or risk interpretation.
- Investments prioritised without common criticality criteria.
- Is ISO 55001 only about maintenance?
- No. It includes the life cycle, value, risk, data, objectives, decisions, performance and investments associated with assets.
- What is reviewed first?
- Inventory, criticality, objectives, risks, plans, performance data and evidence of asset-related decisions.
↑ Back to index ISO 31000 provides guidance on managing risks. It does not function as a traditional ISO management system certification, but helps design criteria, a common language, risk appetite, treatment, monitoring and reporting.
Evidence that carries weight
- Risk matrix or register with defined criteria.
- Treatments, responsible individuals, dates and evidence.
- Reports to management and related decisions.
- Reviews of effectiveness and changes in context.
Where it tends to fail
- Huge risk matrices that nobody uses.
- Inconsistent impact/probability criteria.
- Treatments without follow-up.
- Risk presented as a formality rather than a decision.
- Can ISO 31000 be certified?
- ISO 31000 provides risk management guidance. On this site, it is treated as a framework for architecture and diagnostic assessment, not as a promise of certification.
- How is it useful before implementing an ISO standard?
- It helps structure risk criteria, responsibilities, treatments and reports that then support several management systems.
↑ Back to index ISO 10002 helps design a robust complaints-handling process: receipt, recording, investigation, response, follow-up, learning and improvement. The diagnostic assessment examines whether the voice of the customer informs real decisions.
Evidence that carries weight
- Complete records of complaints, timelines, responsible individuals and responses.
- Analysis of trends, causes, recurrence and actions taken.
- Measurement of satisfaction and perceptions after closure.
- Improvement decisions arising from complaints and feedback.
Where it tends to fail
- Treating complaints as customer service rather than system evidence.
- Responding quickly without investigating the cause.
- Measuring satisfaction without connecting results to improvements.
- Failing to distinguish between a claim, a complaint, an incident, a nonconformity and an opportunity.
- Does ISO 10002 replace ISO 9001?
- No. It complements quality management with specific guidance on complaints handling and customer satisfaction.
- What turns a complaint into useful evidence?
- A complete record, an analysed cause, a traceable response, effective action, follow-up and learning to prevent recurrence.
↑ Back to index FSSC 22000 adds specific requirements to the ISO 22000 foundation: sector-specific PRPs, additional requirements, food fraud, food defence and extended supply chain control.
Evidence that carries weight
- Matrix of FSSC requirements and compliance by area.
- Food fraud and food defence assessments.
- PRP, traceability, withdrawal and supplier records.
- Corrective actions and performance review.
Where it tends to fail
- Thinking of FSSC as ISO 22000 with more paperwork.
- Food fraud and food defence treated as appendices without operational implementation.
- Incomplete sector-specific PRPs.
- Evidence scattered across quality, production and purchasing.
- Is FSSC 22000 an ISO standard?
- It is a food safety certification scheme based on ISO 22000, sector-specific PRPs and additional requirements.
- When is it worth assessing FSSC 22000?
- When the organisation needs to meet global supply chain, retail, export or customer requirements that are more demanding than ISO 22000.
↑ Back to index IATF 16949 builds on ISO 9001 and adds automotive-specific requirements: defect prevention, variation, traceability, customer requirements, Core Tools and change control.
Evidence that carries weight
- FMEA and control plans kept up to date.
- PPAP, approvals and controlled changes.
- Customer indicators, complaints, scrap, rework and deliveries.
- Process and product audits with effective actions.
Where it tends to fail
- Core Tools completed as files, not used to control processes.
- Customer-specific requirements not deployed.
- Changes without risk assessment and approval.
- Internal auditing that does not examine critical processes.
- Does IATF 16949 replace ISO 9001?
- For the automotive sector, IATF 16949 incorporates the ISO 9001 foundation and adds sector-specific requirements.
- What carries the most weight in the diagnostic assessment?
- Customer requirements, Core Tools, change control, traceability, process performance and evidence of prevention.
↑ Back to index ISO 22163 extends quality management to the railway sector: projects, configuration, RAMS, supply chain, customer requirements, safety and performance.
Evidence that carries weight
- Project quality plan and configuration control.
- Change, validation and acceptance records.
- Supplier evaluation and supply chain performance.
- Risks, incidents, nonconformities and lessons learned.
Where it tends to fail
- Managing railway projects with generic ISO 9001.
- Configuration and changes without sufficient traceability.
- Critical suppliers outside the system's control.
- Contractual requirements not incorporated into processes.
- Is ISO 22163 useful outside the railway sector?
- Its focus is on railways. Some practices may inform complex projects, but an assessment is justified when the scope falls within that supply chain.
- How does it differ from ISO 9001?
- It adds sector-specific requirements for projects, configuration, safety, suppliers and railway performance.
↑ Back to index ISO/IEC 27701:2025 is a standalone privacy management standard (PIMS) that can be certified independently. The assessment reviews roles, purposes, legal bases, rights, transfers, suppliers, incidents and evidence of operational compliance.
Evidence that carries weight
- Record of processing activities.
- Policies, notices, consents, contracts and assessments.
- Management of rights, incidents and suppliers.
- Evidence of minimisation, retention and security.
Where it tends to fail
- Privacy reduced to a website policy.
- Incomplete inventory of processing activities.
- Suppliers without contractual clauses or assessments.
- Data subject rights without a measurable process.
- Does ISO/IEC 27701 replace GDPR or local laws?
- No. It helps manage privacy as a system, but must be mapped against applicable legal obligations.
- Do I need ISO/IEC 27001 for ISO 27701?
- No. The ISO/IEC 27701:2025 edition is a standalone privacy management standard that can be certified independently; it integrates well with an ISO/IEC 27001 ISMS, but no longer requires it as a foundation.
↑ Back to index ISO/IEC 27017 extends security controls for the cloud. The key consideration is shared responsibility: what the provider controls, what the customer controls and what evidence exists on both sides.
Evidence that carries weight
- Cloud responsibility matrix.
- Configurations, logs, access reviews and monitoring.
- Contracts, certifications and supplier reports.
- Backup, recovery and incident tests.
Where it tends to fail
- Assuming that the cloud provider covers all risk.
- Critical configurations without independent review.
- Insufficient logs to reconstruct incidents.
- Contracts lacking clarity on location, support and subprocessors.
- Does ISO/IEC 27017 replace ISO/IEC 27001?
- No. It complements the ISMS with controls and guidance specific to cloud services.
- What is reviewed first in the cloud?
- The shared responsibility model, critical configuration, access, logs, contracts and monitoring evidence.
↑ Back to index ISO/IEC 27018 focuses on protecting personally identifiable information in the public cloud. The assessment examines contracts, subprocessors, location, access, deletion, incidents and transparency.
Evidence that carries weight
- Map of PII in the cloud and data flows.
- Contracts, DPA, subprocessors and location evidence.
- Records of access, deletion, incidents and requests.
- Technical and organisational controls applied.
Where it tends to fail
- Not knowing where PII is or who processes it.
- Undeclared or unassessed subprocessors.
- Deletion and retention without evidence.
- Cloud privacy outside the ISMS.
- Does ISO/IEC 27018 apply only to cloud providers?
- Its focus is on protecting PII in the public cloud. It also helps customers assess providers' responsibilities and evidence.
- How does it differ from ISO/IEC 27701?
- ISO/IEC 27701 manages privacy broadly; ISO/IEC 27018 focuses on PII in the public cloud.
↑ Back to index ISO 26000 provides guidance on social responsibility. It helps examine governance, human rights, labour practices, the environment, fair practices, consumers and the community using verifiable criteria.
Evidence that carries weight
- Map of stakeholders and material topics.
- Policies, programmes, indicators and results.
- Evidence of participation, complaints, impacts and corrections.
- Reports with traceability and declared boundaries.
Where it tends to fail
- Confusing social responsibility with corporate communications.
- Reporting impact without evidence of outcomes.
- Isolated programmes without governance.
- Not declaring boundaries, assumptions or unmeasured effects.
- Is ISO 26000 certifiable?
- ISO 26000 provides guidance on social responsibility. On this website, it is used for assessment and architecture, not as a promise of certification.
- What does it contribute to an ESG strategy?
- It provides criteria for organising stakeholders, governance, labour practices, the environment, consumers, the community and evidence.
↑ Back to index