
SQC Advisory | Week of August 10, 2026

Weekly Regulatory Newsletter | ISO Management System Standards
Week of August 10, 2026
Prepared for Mitchell Sevcik
This week's issue lands at an unusually consequential moment for anyone maintaining more than one management system. ISO 9001 cleared its final ballot in mid-July and is now weeks away from publication, ISO 14001 is already published and burning through its transition clock, ISO 45001's revision is taking shape around psychosocial risk, and the AI management system market is being reshaped by an accreditation infrastructure that only became fully operational this year. Layered on top is a US state regulatory picture that is moving faster than any of the standards — and in the case of AI, moving in two directions at once as federal preemption pressure collides with state enactments. What follows is a read on what changed, why it matters, and what to do about it.
ISO 9001 — Quality Management
What changed. The Final Draft International Standard for ISO 9001 received final approval from ISO on 15 July 2026, and publication is now firmly scheduled for 16 September 2026. That date has been confirmed by multiple certification bodies and is no longer treated as provisional. ISO/TC 176/SC 2 has closed out the comment disposition process, meaning the technical content is locked — what appears in September will be substantively what is in the FDIS today. A three-year transition period is anticipated, putting the expected sunset of ISO 9001:2015 certificates somewhere around September 2029, though the precise deadline will not be official until the accreditation community issues its formal transition communique after publication.
The FDIS confirms roughly seven headline shifts. Climate change is now explicitly folded into the determination of organizational context under Clause 4.1 — an organization must determine whether climate change is a relevant issue for its quality management system, rather than treating it as an environmental-only concern. Clause 5.1.1 adds an obligation on top management to promote quality culture and ethical behavior, with accompanying guidance on how that promotion can be demonstrated. Beyond those two, the revision strengthens risk and opportunity management, sharpens change management, elevates workforce awareness and engagement, pushes for tighter strategic alignment between the QMS and business objectives, and cleans up terminology throughout.
Why it matters. The extent of change is moderate — meaningfully less disruptive than the 2008-to-2015 jump — but the character of the change is what should get attention. Quality culture and ethical behavior are the first requirements in ISO 9001's history that ask an auditor to evaluate something intangible. Organizations that have historically satisfied leadership clauses with a signed quality policy and a management review agenda will find that insufficient. The practical difficulty is not understanding the requirement; it is producing evidence for it.
Action items. Do not wait for September. The technical content is settled, so gap analysis against the FDIS can begin now. Note also the accreditation lag: certification bodies must be trained and then accredited to the new edition by their national accreditation bodies, a process that typically runs nine to twelve months, which means the first ISO 9001:2026 certificates are not realistically expected until roughly August 2027. Organizations planning a recertification cycle in late 2026 or early 2027 should have an explicit conversation with their registrar now about whether that audit will be conducted against the 2015 or 2026 edition.
Sources: LRQA; ANSI Blog; DQS; SGS; DNV; TÜV Rheinland; Quality Magazine; ISO.org (ISO 9001 standard page).
ISO 14001 — Environmental Management
What changed. Nothing new was published this week, but the item worth restating is that ISO 14001:2026 has been in force since 15 April 2026 with a 36-month transition, making April 2029 the outside date for moving certificates off the 2015 edition. Roughly four months of that window are already gone. The revision folds in the 2024 climate change amendment permanently, broadens the scope to reflect climate resilience, biodiversity and sustainable resource use, and aligns the standard to the Harmonized Structure so it integrates cleanly with ISO 9001 and ISO 45001.
The stated design objective of the revision was to clarify existing requirements while keeping new requirements to a minimum, and most commentary from the certification community agrees the changes are moderate. The more interesting framing — and the one that will show up in audits — is the repositioning of environmental management from a compliance-focused system toward a strategic, risk-informed business tool. Biodiversity in particular is new territory for most certified organizations, which have no established method for evaluating it as an environmental aspect.
Why it matters. The transition clock is the practical issue. Organizations with multiple certified systems face an awkward sequencing problem: ISO 14001 transitions must be complete by April 2029 and ISO 9001 transitions by roughly September 2029, with ISO 45001 arriving behind both. Treating these as three separate projects will cost significantly more than treating them as one integrated program, particularly given that all three now share climate change language in their context clauses.
Action items. If a transition plan is not yet approved and resourced, that is the near-term gap. Where an integrated management system exists, build a single climate context assessment that serves ISO 9001 Clause 4.1 and ISO 14001 simultaneously rather than producing two documents that say the same thing differently. ANAB has published transition guidance worth reviewing before scheduling the first transition audit.
Sources: ISO.org (ISO 14001:2026 publication announcement); DNV; DEKRA; DQS; SGS; TÜV SÜD; ANAB Blog; Trihydro.
ISO 45001 — Occupational Health & Safety
What changed. No formal milestone landed this week. The revision remains in drafting, with a Draft International Standard anticipated during 2026 and publication expected in 2027, followed by the customary three-year transition. That timeline has held steady across recent commentary and should be treated as the planning assumption rather than a commitment.
The substantive direction is clearer than the schedule. The revision is expected to expand occupational health and safety well past physical hazards: psychosocial risk and mental health, worker participation, workplace culture, hybrid and remote work arrangements, digital work environments, contractor control, supply chain risk, leadership accountability, and the differing needs of diverse worker populations. Climate-related worker risks — heat stress and extreme weather among them — are expected to appear alongside adaptation and prevention measures. Burnout and harassment are named repeatedly in the commentary as hazards the revised standard will expect organizations to manage rather than merely acknowledge.
Why it matters. Psychosocial risk is the change that will separate mature safety programs from paper ones. ISO 45003:2021 already provides the guidance framework for identifying, assessing and managing psychosocial hazards, and it has been available for five years — but adoption has been thin because it carries no certification requirement. When the ISO 45001 revision pulls those concepts into a certifiable standard, organizations that have never run a psychosocial risk assessment will be starting from zero under audit pressure. The organizations that use the 2026 drafting window to build the capability voluntarily will be in a materially better position.
Action items. Treat ISO 45003 as a preview of the requirement and pilot a psychosocial hazard assessment this year while there is no auditor in the room. Separately, review whether the existing hazard identification process is capable of capturing heat, extreme weather and remote-work exposures — for many organizations it is scoped to physical plant only.
Sources: IHMM; National Association of Safety Professionals; MSI International; Core Business Solutions; ICExperts Academy; ISO.org (ISO 45003:2021).
ISO 42001 — AI Management Systems
What changed. The most consequential development for ISO 42001 is dated 2 August 2026 — one week ago — when the EU AI Act's high-risk system obligations took effect. The critical point for anyone advising on this standard is that ISO/IEC 42001 is not currently a harmonized standard under the EU AI Act, which means certification does not confer a presumption of conformity. It is strong evidence of governance maturity; it is not a legal shield. That distinction is being blurred in a great deal of vendor marketing right now and is worth correcting explicitly with clients.
On the certification infrastructure side, the picture has firmed up considerably. ISO/IEC 42006:2025 now sets the requirements for bodies that audit and certify AI management systems, covering auditor competence, impartiality and audit time calculation — which is what makes accredited certification meaningful rather than self-declared. UKAS granted accreditation in January 2026, ANAB operates an ISO/IEC 42001 accreditation program, and CEN has adopted the standard as EN ISO/IEC 42001:2026. Certification is now held by AWS, Anthropic, Microsoft and a growing list of software vendors, with early certifications issued through BSI, A-LIGN, Schellman and KPMG establishing the benchmark audit patterns.
Why it matters. The commercial driver has arrived ahead of the regulatory one. By mid-2026, the question of whether a vendor is certified to or implementing ISO 42001 is appearing in roughly 40 percent of enterprise AI vendor RFPs in the EU and around 25 percent in North America. That is procurement pressure, not compliance pressure, and it moves faster. Typical certification runs six to twelve months and costs somewhere between five and thirty thousand dollars for the initial audit, plus annual surveillance — which makes the timing decision a straightforward commercial calculation for organizations selling AI-enabled products into enterprise accounts.
Action items. Verify that any certification a client holds or is pursuing is accredited under ISO/IEC 42006 rather than issued by an unaccredited body; the market has attracted both. For clients selling into the EU, map ISO 42001 controls against EU AI Act obligations explicitly and identify the gaps, rather than assuming coverage.
Sources: ISO.org (ISO/IEC 42001 and ISO/IEC 42006 standard pages); ANAB; Openlayer; Modulos; A-LIGN; NQA; iTeh Standards (EN ISO/IEC 42001:2026).
US State Regulatory Activity
State-level activity is where the most movement occurred, and it bears directly on all four standards.
Artificial Intelligence — Colorado, Texas, California, and Federal Preemption
Colorado remains the most significant state AI regime for management system purposes, and it has slipped. Governor Polis signed SB 189 on 14 May 2026, revising the Colorado AI Act and pushing its effective date from 30 June 2026 to 1 January 2027 while scaling back the original requirements substantially. The underlying framework — risk-based governance of AI used in consequential decisions affecting employment, housing, health care and education — is the state law that maps most closely onto an ISO 42001 impact assessment. The delay buys time; it does not remove the obligation.
Texas TRAIGA took effect 1 January 2026 but is a narrower instrument than Colorado's: a short list of banned uses plus rules governing state-government AI, rather than a general high-risk regime. California's SB 53 and AB 2013 also took effect 1 January 2026, and the California AI Transparency Act — amended by AB 853 — reached its delayed implementation date of 2 August 2026, the same day as the EU's high-risk obligations.
Overhanging all of it is the December 2025 executive order establishing a national AI policy framework, which created a DOJ AI Litigation Task Force empowered from 10 January 2026 to challenge state AI laws in federal court, directed Commerce to publish a review of burdensome state laws by 11 March 2026, and sought to condition roughly $42 billion in broadband funding on repeal of certain state AI rules. Legal commentary is broadly skeptical that an executive order can independently displace state law, since preemption normally flows from congressional enactment — but the pressure has visibly shaped what states chose to pass in 2026, pushing legislative energy toward child safety, data centers and consumer protection. Notably, state laws in those areas plus government procurement are understood to be outside the preemption challenge.
Bearing on ISO 42001: the regulatory target is moving, which argues for building the AI management system around durable governance capability — inventory, impact assessment, human oversight, incident response — rather than around the specific text of any one state statute.
Workplace Heat — Six States Ahead of Federal OSHA
The federal heat rule remains stalled. OSHA published its proposed rule in August 2024 with triggers at 80°F and 90°F, but the January 2025 regulatory freeze halted the rulemaking and no target finalization date appears on the unified agenda. In April 2026, OSHA renewed its heat National Emphasis Program through April 2031 — enforcement activity continues, but under General Duty Clause authority rather than a specific standard.
States have not waited. As of mid-2026, six state OSHA programs maintain specific, citable heat rules, and every one of them exceeds the proposed federal rule on at least one dimension. California added an indoor heat standard triggering at 82°F in July 2024 alongside outdoor rules at 80°F with enhanced measures at 95°F. Washington's revised outdoor rule applies year-round at an 80°F trigger with mandatory paid breaks at higher temperatures, acclimatization and buddy-system requirements. Oregon covers both indoor and outdoor workplaces from a heat index of 80°F with enhanced protections above 90°F.
Bearing on ISO 45001: multi-state employers cannot manage heat to a single national threshold. The hazard identification and legal-requirements processes need to be state-aware, and the coming ISO 45001 revision's climate-related worker risk provisions will make this an audit finding rather than a legal one.
Workplace Violence and Psychosocial Exposure
California remains the only state with an active general-industry workplace violence mandate. SB 553 has required most employers to maintain a written Workplace Violence Prevention Plan since 1 July 2024, and the state's Occupational Safety and Health Standards Board must adopt the formal standard no later than 31 December 2026 — meaning further draft revisions are likely before year end. New York extended requirements to retail employers in 2025 and, through A203 signed in December 2025, to hospitals and nursing homes effective September 2026.
Bearing on ISO 45001 and ISO 45003: workplace violence programs already require post-incident response including access to employee assistance and trauma-informed support. That infrastructure is the natural starting point for a broader psychosocial risk program.
Climate Disclosure — California SB 253 and SB 261
CARB announced on 24 June 2026 that the SB 253 Scope 1 and 2 reporting deadline has been postponed to 10 November 2026, moving off an initial compliance date that had been set for today, 10 August 2026. SB 253 applies to companies with more than $1 billion in total annual revenue doing business in California and ultimately requires Scope 1, 2 and 3 disclosure with independent third-party assurance. CARB is exercising enforcement discretion for the first compliance year.
SB 261, which requires climate-related financial risk disclosure aligned to TCFD or an equivalent framework, is in a more uncertain position. CARB has stated it will not enforce the 1 January 2026 deadline because of a Ninth Circuit injunction, and will set an alternate reporting date once the appeal resolves.
Bearing on ISO 14001 and ISO 9001 Clause 4.1: the emissions inventory and climate risk analysis built for California reporting is the same evidence base that supports the climate context determination in both standards. Organizations doing this work for CARB should be routing it into their management system documentation rather than maintaining a parallel exercise.
Sources: Hunton; King & Spalding; Cooley; White & Case; Paul Hastings; TechPolicy.Press; Ogletree; Beveridge & Diamond; OSHA.gov; Cal/OSHA (DIR); Littler; BDO; Greenberg Traurig; Nixon Peabody.
Practical Steps to Meet the New Requirements
The recurring difficulty with the newer requirements across all four standards is that they ask for evidence of things organizations have historically treated as culture rather than process. The following are concrete, auditable approaches.
Quality Culture (ISO 9001 Clause 5.1.1 / 7.3)
Quality culture is auditable when it is instrumented. Establish a baseline through a short annual quality culture survey — six to ten questions covering psychological safety in reporting problems, whether people believe quality is prioritized over schedule, and whether they know how their role affects the customer — and trend the results in management review with documented actions against declines. That trend line is the single most useful artifact to hand an auditor.
Beyond survey data, the demonstrable evidence includes: minuted management review discussion of culture indicators rather than only conformity metrics; a documented near-miss or quality-concern reporting channel with visible response times and a stated non-retaliation position; leadership behaviours written into performance objectives for managers, with completed appraisals as evidence; onboarding and refresher awareness training under Clause 7.3 that connects individual roles to customer outcomes and to the consequences of nonconformity, with attendance and comprehension records; and recognition programs that reward problem identification rather than problem absence. Where a decision was made to prioritize quality over cost or delivery, record it — a documented example of the trade-off going the right way is worth more than a policy statement.
Ethics (ISO 9001 Leadership and Awareness Clauses)
Ethical behaviour under the revised leadership clause needs the same treatment: a written code of conduct is table stakes, and what matters is what surrounds it. Maintain an ethics policy that is specifically connected to quality decisions — data integrity, accurate test and inspection records, honest reporting of nonconformity, truthful customer communication — rather than a generic corporate ethics statement that never mentions the QMS.
Auditable supporting evidence includes annual acknowledgement records covering employees and, where relevant, suppliers and contractors; a confidential reporting or whistleblower channel with a documented investigation and closure process and retained case records with outcomes; ethics and integrity criteria built into supplier evaluation and re-approval; data integrity controls over quality records, including audit trails in electronic systems and defined rules for correcting records; and a periodic review of quality-related ethical risk — pressure to release nonconforming product, incentive structures that reward throughput over conformity, sole-source supplier dependencies. Recording that review and its mitigations produces exactly the evidence the clause anticipates.
Climate Change (ISO 9001 Clause 4.1 / ISO 14001)
The Clause 4.1 requirement is narrower than it first appears: determine whether climate change is a relevant issue for the management system, and document the determination either way. A defensible negative conclusion is acceptable — an undocumented one is not.
Build one climate context assessment that serves both standards. Assess physical risk to operations and supply chain — extreme weather affecting facilities, transport routes, single-source suppliers, and utility availability — alongside transition risk from regulation, customer requirements and market shifts. Record the conclusion in the context analysis with the reasoning behind it, and where climate is determined to be relevant, carry it into the risk and opportunity register with assigned owners and defined actions rather than leaving it in the context document. Reference existing continuity plans where they already address weather disruption; auditors accept cross-references to real plans and reject standalone climate paragraphs that connect to nothing. Where the organization reports under CARB's SB 253 requirements or a customer's supply-chain disclosure program, cite that inventory as the data source. Re-run the determination annually as part of management review, since the whole point of the clause is that context changes.
Psychosocial Risk (ISO 45001 Revision / ISO 45003 Guidance)
Start by extending the existing hazard identification process rather than building a parallel system. ISO 45003 provides the hazard categories — workload and work pace, job control and autonomy, role clarity, interpersonal relationships including bullying and harassment, organizational change and job insecurity, remote and isolated work, and emotionally demanding work. Add those categories to the existing risk assessment methodology and score them with the same likelihood-and-consequence approach used for physical hazards, so the outputs land in one register.
Gather data from sources that already exist before commissioning new ones: absence and turnover patterns by department, employee assistance program utilization rates in aggregate, exit interview themes, grievance and harassment complaint volumes, and overtime distribution. Supplement with an anonymous psychosocial risk survey where headcount makes anonymity credible. Controls should be organizational rather than individual — workload redistribution, clarified role definitions, manager training in recognizing distress, consultation requirements before organizational change — because resilience training offered in place of workload management is the finding auditors are most likely to write. Document worker consultation on psychosocial hazards specifically, since the revision is expected to strengthen participation requirements. Finally, verify that incident reporting procedures accept psychosocial incidents such as harassment, threats and acute stress events, and that investigation and post-incident support processes cover them.
Climate-Related Worker Risk and Heat Exposure (ISO 45001)
Given the six-state patchwork and the expected climate provisions in the ISO 45001 revision, build a heat exposure assessment covering both indoor and outdoor work at the lowest applicable state trigger rather than the federal proposal. Auditable elements are a written heat illness prevention plan with defined temperature triggers, acclimatization procedures for new and returning workers, documented access to water, shade and rest at the trigger thresholds, training records covering symptom recognition, an emergency response procedure, and monitoring records showing measured temperature or heat index at the work location. Where operations cross state lines, maintain a legal requirements register that identifies the governing threshold per site.
AI Governance Evidence (ISO 42001)
For organizations pursuing or maintaining ISO 42001 while state and federal AI law remains unsettled, the durable investments are an AI system inventory that captures purpose, data sources, model provenance and deployment status; documented impact assessments for any system used in consequential decisions, which is the artifact both Colorado's framework and the EU AI Act converge on; defined and evidenced human oversight for those systems; an AI incident and complaint process distinct from general IT incident management; and supplier due diligence over third-party models and AI-enabled tools. These carry across regimes regardless of how preemption litigation resolves.
Looking Ahead
Three dates warrant calendar entries. ISO 9001:2026 publishes on 16 September 2026, after which the accreditation community's transition communique will set the actual certificate deadline. CARB's revised SB 253 Scope 1 and 2 reporting deadline falls on 10 November 2026. And California's Occupational Safety and Health Standards Board must adopt its general-industry workplace violence standard by 31 December 2026, with draft revisions likely before then. The ISO 45001 Draft International Standard is expected sometime during the remainder of 2026 without a fixed date; it is the item most worth watching for a formal announcement.
Prepared by SQC Advisory. This newsletter summarizes publicly reported regulatory and standards developments and is provided for informational purposes. It is not legal advice; confirm effective dates and applicability against primary sources and counsel before acting.