SQC Advisory | Week of August 17

SQC Advisory | Week of August 17

SQC Advisory | Week of August 17

Weekly Regulatory & Standards Newsletter

ISO 9001 | ISO 14001 | ISO 45001 | ISO 42001 | US State Regulatory Watch

Week of August 11–17, 2026

Prepared for Mitchell Sevcik

This Week in Brief

This is a consequential stretch of the standards calendar. ISO 9001:2026 is now only weeks from publication, with the Final Draft International Standard circulated and a target release date of September 16, 2026, which puts the new quality culture and ethical behavior requirements into play for every certified organization. ISO 14001:2026 has been published since April and is now in the early phase of its 36-month transition, and the revised ISO 45001 sits at Draft International Standard stage with psychosocial risk and mental health as its defining additions. On the AI side, ISO/IEC 42001 continues to move from novelty to procurement expectation, while the accreditation infrastructure underneath it firms up under ISO/IEC 42006.

The US state regulatory picture was comparatively quiet this week, largely because most legislatures remain in summer recess. California is the exception: its legislature is running suspense-file votes on roughly thirty AI bills, and the California Air Resources Board has just closed comment on modifications to the SB 253 and SB 261 climate disclosure rules. Both threads matter directly to how organizations scope ISO 42001 and ISO 14001 systems.

ISO 9001 — Quality Management

What changed. The Final Draft International Standard for ISO 9001 has been issued and the standard is on track for publication on September 16, 2026. Nothing new was published this week, but the FDIS content is now stable enough that transition planning should be treated as a live project rather than a watching brief. The revision is evolutionary rather than structural: the Harmonized Structure and the ten-clause architecture remain, and the core requirements are intact.

The substantive additions cluster around organizational behavior. Clause 5.1.1 now explicitly requires top management to promote and demonstrate a quality culture and ethical behavior, moving both concepts from implied good practice into auditable requirement. Clause 7.3 on awareness has been expanded correspondingly, so that persons working under the organization's control must be aware of the organizational quality culture and ethical behavior expectations. An accompanying note clarifies that culture and ethics may be evidenced through shared values, beliefs, history, attitudes, and observed behaviors. Elsewhere the revision sharpens risk-based thinking, brings climate change into the context-of-the-organization analysis, and adds emphasis on digital transformation, organizational resilience, and sustainability-driven stakeholder expectations.

Why it matters. Culture and ethics requirements are unusual in that they cannot be satisfied by writing a procedure. Auditors will look for behavioral evidence, and organizations that respond by drafting a one-page values statement will find themselves with a nonconformity or, at minimum, an uncomfortable opening meeting. The three-year transition period, expected to run to roughly September 2029 subject to formal IAF confirmation, sounds generous but the culture-related evidence takes the longest to accumulate because it depends on records generated over time.

Action items. Confirm that the International Accreditation Forum transition resolution is reviewed as soon as it publishes alongside the standard in September, since that document, not the standard itself, sets the binding certificate deadlines. Begin a gap assessment now against the FDIS text, focused specifically on Clauses 4.1, 5.1.1, and 7.3. Be aware that once the 2026 edition is live, certification bodies will apply shortened validity periods to any new certificates still issued against ISO 9001:2015.

Sources: ISO 9001 standard page (ISO.org); SGS — ISO 9001:2026 Key Updates and Transition Guidance; BSI — ISO 9001:2026 Key Changes and Guidance; ANSI Blog — ISO 9001:2026 QMS Revision Updates.

ISO 14001 — Environmental Management

What changed. No new development surfaced this week. The governing event remains the publication of ISO 14001:2026 on April 15, 2026, which replaced the 2015 edition including the 2024 climate change amendment. The International Accreditation Forum has set a 36-month transition, so existing certificates must migrate by April 2029. The intermediate milestone is the one organizations tend to miss: approximately eighteen months after publication, around October 2027, certification bodies can no longer issue new certificates against the 2015 edition at all.

The technical center of gravity is Clause 4.1. The revision names specific environmental conditions that must be considered when determining organizational context, including climate change, availability of natural resources, pollution levels, biodiversity, and ecosystem health. Climate change must be actively considered rather than assumed away. A substantially expanded Annex A.4.1 introduces natural capital thinking and ecosystem interconnection. Beyond context, the revision strengthens life cycle thinking, adds structured change management, sharpens supply chain and value chain expectations, and pushes harder on demonstrable, measurable environmental performance rather than procedural compliance. The text is fully aligned to the current Harmonized Structure, which makes integration with ISO 9001 and ISO 45001 materially easier.

Why it matters. The overall change set is moderate by design, and lighter than the 2015 transition. But the shift from documented process to demonstrated performance is a real one, and organizations whose EMS has historically been strong on paperwork and thin on outcome metrics will feel it. The climate and biodiversity context requirements also create a natural bridge to state and federal disclosure regimes, which is where the ISO 14001 and California climate reporting workstreams begin to converge.

Action items. Work backward from the October 2027 date rather than the April 2029 deadline if there is any prospect of a new site, new scope, or new certificate in the interim. Revisit the Clause 4.1 context analysis and make sure each named environmental condition is addressed explicitly and in writing, including a documented rationale where a condition is judged not relevant.

Sources: ISO — ISO 14001:2026 published; ISO 14001:2026 standard page; DNV — ISO 14001:2026 Published: What's Changed; NQA — ISO 14001:2026 Climate Change Requirements.

ISO 45001 — Occupational Health & Safety

What changed. No new milestone this week. The current position is that the Draft International Standard was released in mid-April 2026, with publication of the revised standard anticipated in 2027. The DIS retains the Harmonized Structure and develops existing requirements rather than rebuilding them, with the stated intent of more integration, less bureaucracy, and a stronger focus on effective prevention and a practiced safety culture.

The defining change is the elevation of psychosocial risk. Mental health, burnout, harassment, and work-related stress move from the periphery into the hazard identification and risk assessment machinery of the standard. Alongside that, the draft addresses hybrid and remote work patterns, climate-related risks to workers, organizational resilience, supply chain responsibility, and worker participation. ISO 45003:2021 remains the operative guidance document and is the practical starting point for anyone wanting to get ahead of the revision.

Why it matters. Psychosocial hazards are the hardest category of risk for a traditional safety program to absorb, because the existing toolkit of guarding, PPE, and lockout has no analogue. The organizations that struggle will be those that treat psychosocial risk as an HR wellness initiative rather than as a hazard subject to the same identification, assessment, control hierarchy, and effectiveness review as any physical hazard. Regulators are moving in the same direction: OSHA increasingly characterizes psychological safety as an integral component of workplace risk management and has recognized psychosocial stressors as compounding factors in heat-related illness.

Action items. Use the eighteen-month runway to build a psychosocial risk register under ISO 45003 now, so that when the revision publishes the organization is transitioning a working system rather than starting one. Confirm that remote and hybrid workers are inside the scope of the OH&S management system, since the boundary definitions written in 2018 frequently do not cover them.

Sources: ISO 45003:2021 — Psychological health and safety at work; DQS — Revision of ISO 45001 at a glance; Smithers — Preparing for the Possible 2027 Standard Revision.

ISO 42001 — Artificial Intelligence Management Systems

What changed. This is the most active of the four standards. Certification announcements continue at a steady pace, with NeenOpal announcing ISO/IEC 42001:2023 certification of its AI management system on August 11, 2026, certified by InterCert. The more consequential development is structural: the accreditation layer under ISO/IEC 42006:2025 is maturing. UKAS granted BSI the first accreditation for ISO/IEC 42001 certification under ISO/IEC 42006 in January 2026, ANAB operates a US accreditation program for AIMS certification bodies, and the roster of accredited bodies now includes Schellman, BSI, DNV, A-LIGN, SGS, and Palindrome Technologies. EN ISO/IEC 42001:2026 has been adopted as a European standard by CEN-CENELEC/JTC 21.

Market pressure is the other story. By mid-2026 the question of whether a vendor is certified or implementing ISO 42001 appears in roughly forty percent of enterprise AI vendor RFPs in the EU and around a quarter in North America. Certification typically takes six to twelve months, and Stage 2 audit scheduling backlogs at some bodies have run to six months or more.

Why it matters. Two cautions are worth repeating to clients. First, ISO 42001 is not a harmonized standard under the EU AI Act, so certification does not confer a presumption of conformity, even though the Act's high-risk system obligations took effect on August 2, 2026. Second, and for the same reason, certification of the management system does not make any particular AI system compliant with any particular law. ISO 42001 evidences governance discipline; it does not substitute for a legal conformity assessment. Given the audit backlog, organizations facing RFP pressure should start the process well before the commercial deadline that motivates it.

Action items. Verify that any certification body under consideration holds accreditation under ISO/IEC 42006 from a recognized accreditation body, because the unaccredited certificate market is growing and buyers are beginning to distinguish. Build the AI system inventory first; it is the single artifact that serves the ISO 42001 audit, the EU AI Act analysis, and the emerging state law obligations simultaneously.

Sources: ISO — ISO 42001 explained; ISO/IEC 42006:2025 standard page; ANAB — ISO/IEC 42001 AIMS certification bodies; NeenOpal ISO 42001 certification announcement (Aug 11, 2026).

US State Regulatory Watch

Artificial intelligence — bearing on ISO 42001

The week of August 10 was legislatively quiet nationally, with most state legislatures in summer recess. California is the exception and is worth watching closely. On August 13 both chambers held suspense-file votes on the roughly thirty AI bills still active; five of the twenty-nine remaining bills were held in committee and the rest advanced toward floor votes. Two narrow bills went to the Governor: AB 1651, on AI use in the state bar exam, and SB 928, requiring California State University instructors to be human rather than AI.

The wider in-force landscape is what drives compliance work. Texas HB 149, the Responsible Artificial Intelligence Governance Act, has been effective since January 1, 2026 and is the broadest comprehensive state model currently in force. California AB 2013 on generative AI training-data documentation and SB 53 on frontier model safety and transparency also took effect January 1, 2026, and SB 942, requiring large generative AI platforms to provide free AI-content detection tools and embed provenance watermarks, became operative for covered providers on August 2, 2026. Colorado repealed and replaced its original AI act with SB 26-189, a narrower automated decision-making statute effective January 1, 2027; notably, the risk management program and impact assessment duties are gone, replaced by pre-use consumer notices, thirty-day adverse-outcome explanations, meaningful human review rights, and developer documentation duties. Illinois SB 315, a frontier model safety law modeled on California and New York approaches, was signed July 6, 2026. Roughly eighty-five new AI-related laws have passed across twenty-seven states so far in 2026.

For ISO 42001 purposes, the practical implication is that the standard's Annex A controls on AI system impact assessment, data governance, transparency to users, and human oversight are now doing double duty as the evidentiary backbone for multi-state compliance. Colorado's pivot away from mandated risk management programs is instructive: the compliance burden did not disappear, it shifted toward disclosure and explainability, both of which are harder to produce retroactively without a governed inventory.

Environmental and climate — bearing on ISO 14001

California's climate disclosure regime moved this week. CARB released proposed modifications to the SB 253 and SB 261 implementing regulations for a fifteen-day public comment period that closed August 11, 2026. The modifications add time and flexibility in the first program year, permit parent companies to file consolidated reports, and clarify the covered-entity assessment. Separately, on June 24, 2026 CARB deferred the Scope 1 and Scope 2 greenhouse gas reporting deadline from August 10 to November 10, 2026. SB 253 covers US-based entities with at least one billion dollars in global annual revenue doing business in California, requiring Scope 1 and 2 disclosure beginning in 2026 and Scope 3 beginning in 2027. SB 261 remains stayed pending appeal of a court injunction, so covered entities should confirm status with counsel before acting.

Occupational safety — bearing on ISO 45001

Federal OSHA's heat illness rulemaking remains stalled following the January 2025 regulatory freeze, though the agency continues to cite heat hazards under the General Duty Clause. State activity is filling the gap. Six states have enforceable heat illness prevention standards in 2026: California, Oregon, Washington, Nevada, Colorado for agricultural operations, and Maryland. Virginia enacted legislation in April 2026 directing its Safety and Health Codes Board to develop heat illness regulations, and New Mexico has opened formal rulemaking toward a mandatory standard. Multi-state employers running a single ISO 45001 system should assume the applicable heat requirement is the strictest state standard in their footprint rather than the federal baseline.

Sources: Transparency Coalition — AI Legislative Update, August 14, 2026; Cooley — State AI Laws: Where Are They Now?; Sidley — SB 253/SB 261: What CARB's 15-Day Modifications Mean; Davis Polk — SB 253/261 update: CARB workshop on August 2026 reporting; Certainty — State Heat Illness Standards in 2026.

Practical Steps to Meet the New Requirements

The recurring difficulty with the requirements now entering these four standards is that they are behavioral, contextual, or psychological rather than procedural, and auditors will nonetheless expect objective evidence. What follows is a set of concrete, auditable practices for each theme.

Quality Culture (ISO 9001 Clauses 5.1.1 and 7.3)

Define what quality culture means for your organization in specific behavioral terms rather than aspirational ones. A statement that employees are empowered to stop work when quality is at risk is auditable; a statement that the organization values excellence is not. Write three to five such behavioral commitments and put them in the quality policy or a controlled companion document.

Then generate evidence that those behaviors occur. Records of stop-work or hold events initiated by front-line staff, with documented management response and no adverse consequence to the person who raised the issue, are among the strongest evidence available. Management review minutes that show culture as a standing agenda item with discussion of specific incidents, not a checkbox. Employee perception survey results with quality culture questions, trended over at least two cycles, with documented actions arising from the results. Leadership gemba walk or floor engagement logs that record what was discussed and what changed. New-hire and refresher training records that include culture expectations as a distinct module with a competence check, which is also what closes the Clause 7.3 awareness requirement. Finally, run a small number of awareness interviews internally before the certification body does, asking staff at random what the organization's quality culture expectations are; if they cannot answer, the training was not effective and you have time to fix it.

Ethics (ISO 9001 leadership and awareness clauses)

Adopt or refresh a code of ethical conduct that addresses the specific ethical failure modes of your business, such as falsification of inspection or test records, unauthorized concessions, misrepresentation of certification scope, or supplier conflicts of interest. Generic anti-bribery language will not survive an auditor asking how it applies to a quality decision.

Build the evidence chain around it. Maintain signed acknowledgment records with a defined renewal cycle. Operate a confidential reporting channel with a documented case log showing receipt, investigation, disposition, and timeliness, and preserve the anonymized log as evidence that the channel functions. Add ethics and data integrity to the internal audit program as a defined audit criterion, including verification that records are attributable, legible, contemporaneous, original, and accurate. Document a non-retaliation commitment and be able to show it was honored in at least one real case. Where leadership faces a genuine tension between schedule, cost, and quality, record the decision and its rationale; a documented instance of leadership choosing quality against commercial pressure is the single most persuasive artifact you can present.

Climate Change (ISO 9001 Clause 4.1 and ISO 14001:2026)

Treat climate as a mandatory determination, not an optional consideration. Amend the context of the organization register so that climate change appears as an explicit row with a documented conclusion of relevant or not relevant and the reasoning behind it. Auditors will accept not relevant if it is reasoned; they will not accept silence.

Where relevant, work both directions. Assess physical risk to operations, including heat, flood, storm, wildfire, and water availability, at each site and link the findings to business continuity plans and to the OH&S hazard register where worker exposure is implicated. Assess transition risk from regulation, carbon pricing, customer requirements, and supply chain shifts. Under ISO 14001:2026 also address the other named environmental conditions explicitly: natural resource availability, pollution levels, biodiversity, and ecosystem health. Set at least one measurable climate-linked environmental objective with a baseline, target, owner, and review cadence, since the revision's emphasis on demonstrated performance means an objective without a trend line is thin evidence. If the organization is a covered entity under California SB 253, align the greenhouse gas inventory boundary and methodology with the ISO 14001 objective set so the same data serves both, and confirm the current status of the November 10, 2026 reporting deadline with counsel.

Psychosocial Risk (ISO 45001 revision and ISO 45003 guidance)

Bring psychosocial hazards into the existing hazard identification and risk assessment process rather than running them as a parallel wellness program. Use the ISO 45003 hazard categories as the checklist: workload and work pace, work schedule including shift and on-call patterns, job control and autonomy, role clarity and role conflict, organizational change management, interpersonal relationships including bullying and harassment, remote and isolated work, and job security.

Assess with data you can defend. Validated survey instruments administered at a group level rather than individually, supplemented by leading and lagging indicators already in the business: absenteeism and turnover by department, overtime hours, unused leave balances, grievance and harassment complaint volumes, employee assistance program utilization rates in aggregate, and exit interview themes. Apply the hierarchy of controls in the same way you would for a physical hazard, which means eliminating or redesigning the source before offering resilience training. Redesigning a rotation that produces chronic fatigue is a control; a mindfulness webinar is not, and auditors are increasingly making that distinction. Train supervisors to recognize and respond to psychosocial risk, and record the training. Confirm that remote and hybrid workers are within the defined scope of the management system. Finally, ensure worker participation is documented, since psychosocial risk assessment conducted without worker involvement will not satisfy the participation and consultation requirements of Clause 5.4.

AI Governance (ISO 42001 and state AI law)

Newly emphasized this period given the August 2 effective date of the EU AI Act high-risk obligations and the volume of state activity. Start with a complete AI system inventory covering purpose, owner, data sources, model provenance, deployment context, and whether the system influences a consequential decision about a person. This one artifact underpins the ISO 42001 audit, the EU analysis, and Colorado's SB 26-189 duties. Conduct and retain AI impact assessments for each system that touches consequential decisions. Document the human oversight mechanism for each such system in operational terms, naming who reviews what, on what trigger, with what authority to override, because Colorado's meaningful human review right and the thirty-day adverse-outcome explanation duty both depend on it. Maintain training data documentation sufficient to answer California AB 2013 questions. Where the organization is a large generative platform, verify provenance watermarking and detection tooling against SB 942, operative since August 2, 2026. And state plainly in customer-facing materials that ISO 42001 certification evidences a governed management system rather than legal conformity of any individual AI system, since misstating this is itself a compliance exposure.

Demonstrated Performance and Change Management (ISO 14001:2026)

The revision's shift from procedural conformity to measurable outcome deserves its own attention. Ensure each significant environmental aspect has an associated performance indicator with a baseline and a trend, and that management review addresses whether performance improved rather than whether procedures were followed. Separately, establish a documented change management process covering planned changes to processes, products, facilities, and suppliers, with environmental impact evaluated before the change is implemented and the evaluation retained. Life cycle thinking should be visible in design, procurement, and supplier evaluation records, not confined to a paragraph in the manual.


Next issue: week of August 24, 2026. Items to watch include the ISO 9001:2026 publication on September 16 and the accompanying IAF transition resolution, California floor votes on the surviving AI bills, and the CARB response to the fifteen-day comment period on SB 253 and SB 261.

Prepared by SQC Advisory from publicly available sources as of August 17, 2026. This newsletter is informational and is not legal advice. Regulatory status, particularly for litigated state rules such as California SB 261, changes rapidly; confirm current status with qualified counsel before acting.

Speak With An ISO Expert

Share your ISO, risk, or compliance needs, and we will respond promptly with clear next steps, suitable engagement options, and confidential guidance aligned with your current audit timeline.

Contact Us

Social Media