
SQC ADVISORY | Week of August 23

Weekly Regulatory Newsletter | ISO Management System Standards
Week of 17–23 August 2026 · Issue dated 23 August 2026
Prepared for Mitchell Sevcik
This week the center of gravity in the ISO management system world sits squarely on quality. ISO/FDIS 9001 cleared its final ballot on 7 August with overwhelming international support, and the sixth edition of the world’s most widely held certification is now firmly scheduled for publication on 16 September 2026 — roughly three weeks out. That fixes the transition clock for the majority of certified organizations and, taken alongside the already-published ISO 14001:2026 and an ISO 45001 revision now working through its Draft International Standard ballot, means most integrated management systems will be transitioning all three core standards inside the same window. On the regulatory side, Cal/OSHA released a redrafted heat illness rule on 14 August with a 21 September comment deadline, California’s AI Transparency Act took effect on 2 August, and CARB’s deferred SB 253 emissions reporting deadline now lands in November. The practical steps section at the end translates the recurring themes — quality culture, ethics, climate change, and psychosocial risk — into auditable actions.
ISO 9001 — Quality Management
What changed. ISO/FDIS 9001 was approved on 7 August 2026 with overwhelming support from national member bodies, clearing the last technical hurdle before publication. ISO/TC 176/SC 2 and the major certification bodies now point to 16 September 2026 as the publication date for the sixth edition, which replaces ISO 9001:2015. The FDIS text retains the Annex SL harmonized structure, so clause numbering and the overall architecture of an existing QMS remain intact. The substance of the revision lies in emphasis rather than restructuring: a strengthened treatment of quality culture, explicit expectations around ethical behavior and leadership’s role in driving continual improvement, clearer language on risks and opportunities, and formal integration of the climate change amendment into Clause 4.1 rather than the bolted-on 2024 amendment text.
Why it matters. A September publication date starts a three-year transition ending in September 2029, and the International Accreditation Forum’s transition rules mean certification bodies will begin offering transition audits within months rather than years. Organizations running integrated systems should recognize that the ISO 14001 transition deadline (April 2029) and the ISO 9001 deadline (September 2029) will overlap almost entirely, and that an ISO 45001 revision published in 2027 would extend the same window to roughly 2030. The pragmatic move is a single combined gap analysis rather than three sequential projects. The culture and ethics content is the part most likely to surprise certified organizations, because it is the first time ISO 9001 asks auditors to look at something that has historically lived outside the documented system.
Action items. Obtain the FDIS or wait three weeks for the published text and schedule a clause-by-clause gap analysis before year end. Confirm with your certification body when transition audits open and whether they intend to run combined 9001/14001 transitions. Begin collecting evidence now for the quality culture and ethics expectations — these take longer to build than documentation changes and cannot be retrofitted the week before an audit.
ISO 14001 — Environmental Management
What changed. No new developments surfaced this week specific to the standard itself; the significant item remains the publication of ISO 14001:2026 on 15 April 2026, which continues to drive certification body and accreditation activity. The revised standard folds the 2024 climate change amendment permanently into Clauses 4.1 and 4.2, sharpens requirements around life cycle thinking, change management, and demonstrable environmental performance, and adds explicit consideration of biodiversity and natural resource use in the organizational context. The revision was deliberately scoped to clarify rather than expand, so organizations already conforming to the 2015 edition should find the delta moderate.
Why it matters. The IAF transition period runs three years from publication, putting the deadline for all ISO 14001:2015 certificates at roughly April 2029. Certification bodies are still working through auditor competence requirements for the new clauses, which in practice means transition audit availability may be tighter in 2028 than organizations expect. The performance-orientation of the revision deserves attention: where the 2015 edition could be satisfied with a well-run system, the 2026 edition invites auditors to ask what the system actually achieved. Organizations whose environmental objectives have been largely procedural should expect harder questions.
Action items. If a gap analysis against the 2026 text has not been completed, schedule it this quarter. Review environmental objectives for measurable outcome indicators rather than activity counts, and confirm that the context analysis explicitly addresses climate change, biodiversity, and resource use rather than referencing them generically.
ISO 45001 — Occupational Health & Safety
What changed. The ISO 45001 revision reached Draft International Standard stage in mid-April 2026 and the DIS ballot has been running through the summer; published sources differ on the exact closing date, citing both 9 August and 8 September 2026, so treat the comment window as effectively closing this month. ISO/TC 283 continues to target publication in 2027. The draft’s direction is consistent across every summary available: substantially more explicit treatment of mental health and psychosocial risk, express coverage of remote and hybrid work arrangements, integration of climate-related risk and emergency preparedness for severe weather and disaster scenarios, organizational resilience, and supply chain responsibility. The high-level structure is retained and the drafting philosophy favors targeted development of existing requirements over new bureaucracy.
Why it matters. Psychosocial risk is moving from voluntary guidance under ISO 45003 to an explicit expectation inside the certifiable standard. Organizations that treated ISO 45003 as optional have roughly four years before an auditor asks for evidence of psychosocial hazard identification and control on the same footing as machine guarding. The climate integration matters for a different reason: heat, wildfire smoke, and severe weather are simultaneously becoming enforceable regulatory obligations at state level, so the standard and the regulator are converging on the same evidence.
Action items. Treat the 2027 publication date as real and begin ISO 45003-aligned psychosocial risk assessment now rather than after publication. Extend the hazard identification process to remote and hybrid workers, and confirm that emergency preparedness plans address heat, smoke, and severe weather explicitly.
ISO/IEC 42001 — AI Management Systems
What changed. No revision activity on the standard itself — ISO/IEC 42001:2023 remains current — but certification momentum continued through the week. Mokkup.ai announced ISO/IEC 42001 certification on 19 August covering platform governance and AI lifecycle management, and CSM Technologies announced certification in August across software development, machine learning and generative AI, digital transformation, and data governance services. The more structurally important development remains ISO/IEC 42006:2025, the scheme standard governing how certification bodies audit AI management systems, which sets auditor competence, audit duration, and impartiality requirements. ANAB now lists ISO/IEC 42006:2025 as required criteria for accreditation, and the accredited body pool has broadened through 2026 to include BSI (the first with ANAB, UKAS, and RvA accreditation, secured in March), Schellman, DNV, A-LIGN, LRQA, Bureau Veritas, SGS, and TÜV SÜD.
Why it matters. Certification scopes in the recent announcements are broad, covering entire service portfolios rather than single models, which sets the emerging market expectation for what a credible ISO 42001 scope statement looks like. With ISO/IEC 42006 now the governing scheme document, certificates issued by bodies not accredited against it carry materially less weight — a real risk for buyers, since the AI assurance market has attracted unaccredited providers. Typical certification runs six to twelve months and $5,000 to $30,000 or more for the initial audit, plus annual surveillance.
Action items. Verify that any prospective certification body is accredited against ISO/IEC 42006:2025 and confirm the accreditation on the ANAB or equivalent accreditation body directory rather than the certifier’s own website. If you are scoping an AIMS, benchmark against the broad service-portfolio scopes now being announced, since a narrow scope will invite questions from customers.
US State Regulatory Activity
AI regulation and ISO 42001
The state AI landscape is unsettled in a way that directly affects how organizations should design an AI management system. Colorado’s SB 26-189, signed in May 2026, repealed the original Colorado AI Act before it ever took effect and replaced it with an automated decision-making technology law now scheduled to apply from 1 January 2027; separately, a federal magistrate judge in the District of Colorado stayed enforcement of the original law, and that stay is understood to extend to the successor legislation pending resolution of the injunction question and completion of rulemaking. California’s SB 942, the AI Transparency Act, took effect on 2 August 2026 after a delay from January, requiring large AI platforms to provide free AI-content detection tools and to embed both manifest and latent watermarks in generated content; AB 2013 training-data disclosure has applied since 1 January 2026.
Overlaying all of this, the December 2025 executive order established a Department of Justice AI Litigation Task Force, operating since 10 January 2026, to challenge state AI laws in federal court on dormant commerce clause and preemption grounds, and directs Commerce to condition BEAD broadband funding on repeal of state AI rules deemed onerous. States have nonetheless kept legislating — 109 AI laws and 28 data center laws enacted as of 1 July — with activity concentrating on child safety, data centers, and consumer protection, categories the executive order does not target for preemption.
For ISO 42001 purposes the practical conclusion is that a compliance-driven AIMS built around any single state statute is fragile. Build the system around the standard’s risk and impact assessment machinery and treat individual state obligations as controls mapped into it, so a delayed effective date or a successful preemption challenge changes a control mapping rather than the architecture.
Workplace safety and ISO 45001
Cal/OSHA released an updated draft of its heat illness regulations on 14 August 2026, aligning the indoor and outdoor rules in language and terminology. Two changes stand out: the draft outdoor rule removes the exemption that had limited high-heat procedures to agriculture, construction, landscaping, oil and gas extraction, and certain transportation employers, and it adds rhabdomyolysis to the list of conditions defined as heat illness. Comments are due 21 September 2026. Cal/OSHA also issued repeated high-heat advisories through early August. Federally, the OSHA heat injury and illness rulemaking remains pending without a target finalization date and significant revision from the proposal is widely expected.
On the psychosocial side, Maine’s restrictions on invasive employee surveillance without prior notice took effect in July 2026, one of the clearer examples of a state translating psychological safety into an enforceable employment obligation. Commentary on the federal heat rulemaking also notes OSHA increasingly treating work intensity, staffing levels, and psychosocial stressors as compounding factors in heat illness rather than viewing heat as an isolated hazard — the same integration the ISO 45001 revision is pursuing. California’s workplace violence prevention requirements under SB 553 remain in force for general industry, with a revised draft of the formal Cal/OSHA workplace violence rule circulating in August.
Environmental and ISO 14001
CARB deferred the SB 253 deadline for Scope 1 and Scope 2 greenhouse gas reporting from 10 August 2026 to 10 November 2026, following withdrawal of its May regulatory package in June and release of proposed modifications on 27 July. Scope 3 reporting and assurance are anticipated to begin in 2027. Companies above $1 billion in revenue doing business in California should treat the November date as firm and use the additional time for verification rather than deferral. Separately, state PFAS restrictions continued to expand — Maine’s Board of Environmental Protection rules prohibiting PFAS in plant-fiber food packaging took effect 25 May 2026, and Vermont and Maine restrictions across cosmetics, cookware, cleaning products, and juvenile products are now in force — while packaging EPR obligations under California SB 54 and labeling requirements under SB 343 move toward key enforcement dates. Organizations with international packaging exposure should also note the EU Packaging and Packaging Waste Regulation taking effect 12 August 2026.
These obligations map cleanly onto the strengthened life cycle and context requirements in ISO 14001:2026. An EMS whose life cycle perspective stops at the factory gate will not surface PFAS-in-packaging or EPR exposure, and the 2026 edition gives auditors clearer grounds to say so.
Practical Steps to Meet the New Requirements
The four themes below recur across every standard covered in this issue. Each subsection describes evidence an auditor can actually examine — the common failure mode is a policy statement with nothing behind it.
Quality Culture (ISO 9001:2026, Clauses 5.1.1 and 7.3)
Culture becomes auditable when it produces records. Establish a defined quality culture measurement — a short annual or semi-annual survey covering whether employees feel able to stop work over a quality concern, whether reporting a defect is met with support or blame, and whether leadership decisions visibly favor quality when it costs schedule — and retain the results, the trend, and the management response as management review inputs. Add a standing quality culture agenda item to management review with documented actions rather than a status statement.
Demonstrate leadership engagement with dated evidence: executives participating in Gemba walks or layered process audits with their own signed observation records, quality performance appearing in senior leadership objectives, and at least one documented instance where leadership accepted schedule or cost impact to protect quality. For awareness under Clause 7.3, move beyond attendance sheets to competence verification — ask employees during internal audits how their work affects quality objectives and record their answers as audit evidence. Track and trend the volume of employee-raised quality concerns, and treat a declining rate as a warning signal rather than an improvement.
Ethics (ISO 9001:2026 leadership and awareness clauses)
Issue a code of conduct that is specifically connected to the quality management system rather than a generic corporate ethics policy, addressing data integrity, accurate test and inspection records, honest reporting of nonconformity, supplier dealings, and the prohibition on falsifying certificates or records. Require documented annual acknowledgement from everyone with authority over quality records, inspection results, or product release.
Provide a confidential reporting channel that accepts quality and integrity concerns, publish how it is accessed, and maintain a case log recording receipt date, investigation, outcome, and closure — with an explicit non-retaliation commitment and evidence it has been honored. Include data integrity checks in the internal audit program: sample inspection and test records against raw instrument output, verify that electronic records carry audit trails, and confirm that no one can alter a result without a traceable record. Extend ethics expectations to suppliers through purchasing terms and include an ethics element in supplier audits.
Climate Change (ISO 9001:2026 Clause 4.1 and ISO 14001:2026)
Update the documented context analysis to state explicitly whether climate change is a relevant issue for the management system and to record the reasoning either way — a blank or a generic paragraph is the most commonly cited nonconformity against the 2024 amendment. Where it is relevant, carry the determination into the risk register with named risks: supply chain disruption from extreme weather, water availability, energy cost and availability, regulatory exposure under climate disclosure regimes, and customer or investor requirements.
Document the climate-related expectations of interested parties under Clause 4.2, including customer questionnaires, tender requirements, and disclosure obligations such as California SB 253 and SB 261. Assess climate scenarios against business continuity and emergency preparedness plans and record the results. Under ISO 14001:2026, extend this to biodiversity and natural resource use in the context analysis and ensure the life cycle perspective reaches upstream packaging and downstream end-of-life, where PFAS and EPR obligations sit. Set at least one measurable objective tied to a climate-related risk and track it through management review with outcome data rather than activity counts.
Psychosocial Risk (ISO 45001 revision and ISO 45003 guidance)
Add psychosocial hazards to the hazard identification process as a named category, using the ISO 45003 groupings: how work is organized (workload, work pace, hours, shift patterns, job control, role clarity), social factors at work (supervisory support, bullying and harassment, isolation, remote and hybrid arrangements), and the work environment and equipment. Assess them with the same risk methodology applied to physical hazards so the outputs land in the same register with the same ranking and ownership.
Build the assessment on evidence rather than assumption: a validated psychosocial survey, plus objective indicators already in hand such as absence and turnover data, overtime hours, incident reports, grievance and harassment complaints, and employee assistance program utilization at aggregate level. Apply the hierarchy of controls honestly — redesigning workload, staffing levels, or shift patterns is elimination or substitution, while resilience training is at best administrative control and should never be the primary response to a workload hazard. Consult workers through the participation mechanism required by Clause 5.4 and record it. Train supervisors to recognize and respond to psychosocial risk indicators, verify the training took hold, and confirm that reporting a psychosocial concern is possible without career consequence. Include psychosocial risk performance in management review, and where remote or hybrid work is in use, document how hazards were assessed for people not on site.
Newly emphasized this cycle: AI governance scope and accreditation verification
Two items surfaced this week that warrant the same treatment. First, verify the accreditation status of any ISO/IEC 42001 certification body against ISO/IEC 42006:2025 through the accreditation body’s own directory, and retain the verification record — unaccredited certificates are appearing in the market and will not withstand customer scrutiny. Second, when scoping an AI management system, define the scope at the level of services and lifecycle governance rather than individual models, and document the rationale, because the announced certifications now setting market expectations use broad portfolio scopes and a narrow scope invites the question of what was left out.
Sources
ISO/TC 176/SC 2 — ISO 9001 revision update: committee.iso.org/sites/tc176sc2
ISO — ISO 14001:2026 published, raising the bar for environmental performance (April 2026): iso.org/news/2026/04/iso-14001-2026-published
ISO/TC 283 — ISO 45001 revision reaches Draft International Standard ballot stage: committee.iso.org/sites/tc283
ANSI Blog / ANAB — ISO 9001:2026 QMS revision updates and ISO 14001:2026 transition guidance: blog.ansi.org
ANAB — ISO/IEC 42001 AI management systems accreditation criteria (ISO/IEC 42006:2025): anab.ansi.org
BSI — ISO 9001:2026 key changes and guidance; ANAB accreditation for ISO/IEC 42001 (March 2026): bsigroup.com
DNV — ISO 9001:2026 revision and transition; ISO 14001:2026 final version: dnv.us
SGS, DQS, TÜV SÜD, LRQA, Smithers — revision status summaries for ISO 9001, 14001, and 45001
GlobeNewswire — Mokkup.ai achieves ISO 42001 certification (19 August 2026)
Cal/OSHA — heat illness prevention guidance and August 2026 high-heat advisories: dir.ca.gov/dosh
Ogletree Deakins — Cal/OSHA updates draft heat illness regulations to align indoor and outdoor rules (August 2026)
EHSLeaders — California revises draft of proposed workplace violence rule (August 2026)
OSHA — Heat Injury and Illness Prevention in Outdoor and Indoor Work Settings rulemaking: osha.gov/heat-exposure/rulemaking
Norton Rose Fulbright; Alston & Bird; Hunton — Colorado SB 26-189 and delayed effective date
Seyfarth Shaw; Cooley; King & Spalding — state AI law status and California SB 942 / AB 2013
Paul Hastings; Latham & Watkins; Lawfare — executive order on state AI laws and DOJ AI Litigation Task Force
Tech Policy Press — where state AI legislation stands halfway into 2026
Sidley EHS Brief; Davis Polk — CARB SB 253 deadline deferral to 10 November 2026
Manufacturing Dive; MultiState; O’Melveny — state PFAS laws and packaging EPR developments in 2026
This newsletter is prepared by SQC Advisory for informational purposes and summarizes publicly reported regulatory and standards developments. It is not legal advice. Effective dates and draft standard content are subject to change; verify against the official published text and the relevant regulator before acting.