General

ISO standards update for 2026 and beyond

Published: March 09, 2026
General

ISO’s management system standards continue to advance through formal review and approval stages. Since our January 2025 article, several revisions have progressed from early drafts toward finalisation, giving organisations clearer milestones to plan against.

Expectations are evolving. Governance oversight is becoming more explicit. Sustainability and climate considerations are being embedded more firmly. Risk management is increasingly positioned as a strategic discipline rather than a supporting activity.

This update summarises confirmed progress, expected timing, and the practical implications for organisations preparing ahead.


What’s changed since our 2025 article

Several developments have progressed materially:

  • ISO/DIS 9001:2026 was published in August 2025, moving the revision into the formal comment phase.
  • ISO/FDIS 14001:2026 has been issued, with publication expected in April 2026.
  • ISO 45001 revision work has advanced through committee draft stages, progressing toward anticipated publication in 2027.
  • ISO 19011 (Guidelines for auditing management systems) has moved to the Final Draft International Standard stage, signalling that a revised edition is approaching publication in May 2026.
  • ISO 31000 (Risk management) has progressed to the Committee Draft stage, confirming that the revision process is actively underway, though with no date yet announced for its publication.

Organisations can now review consolidated draft content rather than relying on early projections and begin aligning terminology and integration approaches across their management systems.


ISO 9001 – Quality Management Systems

ISO 9001 has reached the Draft International Standard stage. The DIS, published in August 2025, provides the first consolidated view of the revised requirements ahead of final approval.

Publication of ISO 9001:2026 is expected in September 2026.

Based on the DIS and committee commentary, anticipated refinements include:

  • Broader emphasis on risk, resilience and sustainability
  • Clearer integration of climate change considerations
  • Strengthened expectations around leadership and the promotion of quality culture and ethical behaviour
  • Updated guidance on risk and opportunity processes

The structure remains familiar, but the language reinforces accountability and governance oversight more clearly than before.

Following publication, a transition period of three years is expected.


ISO 14001 – Environmental Management Systems

ISO 14001 has progressed to the Final Draft International Standard stage. ISO 14001:2026 is expected to be published in April 2026, replacing ISO 14001:2015.

The revision consolidates the 2024 climate change amendment and aligns fully with the ISO Harmonised Structure. Key developments include:

  • Expanded consideration of environmental context and conditions, including biodiversity and natural resources
  • Inclusion of a planning of changes clause
  • Clarified risk and opportunity requirements
  • Stronger emphasis on life-cycle perspective when evaluating environmental aspects
  • Improved implementation guidance

The update does not introduce significant additional complexity, but it strengthens how environmental governance is evidenced and integrated.

Organisations certified to ISO 14001:2015 can expect a transition window of three years once the revised standard is published.


ISO 45001 – Occupational Health and Safety Management Systems

The revision of ISO 45001 is underway and remains in earlier drafting stages. A Committee Draft was published in 2025, with further drafts expected to progress through review.

Publication of ISO 45001 is anticipated in 2027, although precise publication timing has not been confirmed.

Draft developments suggest:

  • Broader treatment of worker wellbeing and psychosocial risk
  • Consideration of modern working arrangements
  • Increased emphasis on diversity, inclusion, and resilience
  • Continued structural alignment with other management system standards, and the inclusion of a “planning of changes” clause

Organisations should monitor developments and begin internal awareness discussions as the revision progresses.


ISO 19011 – Guidelines for Auditing Management Systems

ISO 19011 has progressed to the Final Draft International Standard stage, indicating that a revised edition is approaching publication.

ISO 19011 provides guidance on auditing management systems, including internal, supplier and certification audit principles. The forthcoming edition is expected to reflect developments across revised management system standards and evolving audit practices.

Areas likely to receive attention include:

  • Risk-based auditing approaches
  • Enhanced remote auditing considerations
  • Integration of audits across multiple management systems
  • Auditor competence and evaluation
  • Alignment with updated terminology and structural expectations

Organisations delivering internal audits should monitor publication timing and plan to update auditor training once the revised edition is released.


ISO/IEC 27001 – Information Security Management Systems

ISO/IEC 27001:2022 remains the current edition, and there is no formal revision underway for the core standard.

However, the wider 27000 series continues to evolve. In particular:

  • ISO/IEC 27005 (Information security risk management) continues to align with the 2022 framework, shaping how risk assessments and treatment plans are structured and evidenced.
  • ISO/IEC 27701 (Information security, cybersecurity and privacy protection), now issued as a standalone privacy management system standard, remains closely aligned with ISO/IEC 27001 and affects how privacy controls are integrated within an ISMS.

While the core clauses of ISO/IEC 27001 are stable, expectations around risk management, supplier security, cloud governance, and performance measurement continue to mature through these supporting standards.

Organisations certified to ISO/IEC 27001:2022 remain aligned with the current authoritative text but should ensure their implementation reflects developments across the wider 27000 series.


ISO 22301 – Business Continuity

ISO 22301:2019 remains unchanged, with no confirmed revision timetable.

Organisations with integrated continuity or resilience programs should consider aligning internal terminology with the updated vocabulary and continue monitoring related committee activity, particularly where alignment with ISO 31000 and sector-specific standards may influence future developments.


ISO 31000 – Risk Management

ISO 31000:2018 remains the current edition. However, revision work is underway, and the project has progressed to the Committee Draft stage, confirming that the next edition of the standard is actively being developed.

At this stage, there is no confirmed publication date. As a principles-based framework rather than a certifiable management system standard, ISO 31000 tends to evolve carefully to maintain its broad applicability across sectors and management systems.

Early draft discussions suggest the revision may place greater emphasis on:

  • Stronger integration between risk management and organisational governance
  • Clearer alignment of risk management with strategic decision-making
  • Greater emphasis on defined risk ownership and accountability
  • Reinforcement of risk management as a driver of organisational resilience and long-term value

ISO 31000 continues to underpin risk thinking across multiple management system standards, including ISO 9001, ISO 14001 and ISO 45001. Organisations using integrated management systems should therefore monitor developments as the revision progresses.

While the revised standard is still in development, organisations should continue applying ISO 31000:2018 and ensure risk management remains embedded within leadership processes, strategic planning and performance management.


What these updates mean in practice

Across these standards, a clear pattern is emerging:

  • Leadership accountability and governance oversight are more explicit
  • Climate and sustainability considerations are embedded across multiple standards
  • Structural and terminology alignment is improving integration
  • Risk and resilience are increasingly positioned at a strategic level

These are evolutionary changes rather than disruptive rewrites, but they will influence audit focus and system design.


Practical priorities

  • Monitor formal draft publications rather than relying on early projections
  • Conduct structured gap assessments once draft texts are available
  • Engage leadership on governance implications
  • Plan training and capability development ahead of transition windows

A coordinated approach across quality, environmental, OH&S, continuity and information security frameworks reduces duplication and strengthens overall system maturity.

When the revised editions are officially released, our courses will be delivered to the updated requirements. If your organisation is planning its transition strategy, now is the time to map out when your team will need training against the new standards.

Back to Insights

What our students say about our courses

“The virtual classroom coupled with an enthusiastic trainer made the course easy to run through and as good as any face-to-face courses I have ever attended.”

“Honestly thought it was gonna be boring. I was very wrong! Very engaging and informative. Loved all 5 days and will be back for more courses!”

“Let’s be honest – ISO standards aren’t exactly edge-of-your-seat material. But this course proved that with the right coach, even clauses and compliance can be compelling! Packed with real-world examples, well-paced sessions, and just the right amount of workshops, it was surprisingly enjoyable. Highly recommended!”

“It was clearly evident that the lead auditor trainer had significant industry-related experience in auditing. He was able to keep the class fully engaged with personal interaction and reinforce learnings. Getting full copies of the standards was amazing, the catering and the training location in Brisbane was perfect.”

“The trainer’s experience and real-life examples gave great context to the course material. The 5 days allowed the material to be digested in a way that was not overwhelming. I’d definitely recommend the course to others.”

Need help finding a course?

Speak directly with a member of the RTP team to decide which course is right for you.

×