
SQC ADVISORY | Week September 13

Regulatory & Standards Intelligence --- Weekly Briefing
Week of September 7 -- 13, 2026
Prepared for Mitchell Sevcik
This week's briefing covers active developments across the four ISO management system standards SQC Advisory tracks for clients --- ISO 9001 (Quality), ISO 14001 (Environmental), ISO 45001 (Occupational Health & Safety), and ISO 42001 (AI Management Systems) --- along with U.S. state-level regulatory activity that intersects with each. The headline this week is the imminent publication of the revised ISO 9001, alongside continued fallout from the already-published ISO 14001:2026 and a fast-moving state AI compliance landscape. A practical steps section follows the standard-by-standard summaries.
ISO 9001 --- Quality Management Systems
The sixth edition of ISO 9001 cleared its final procedural hurdle this month. ISO/TC 176/SC 2 confirmed on August 7, 2026 that the Final Draft International Standard (FDIS) passed with overwhelming international support, and ISO 9001:2026 is now scheduled for formal publication on September 16, 2026 --- just days from this briefing. The revision is described across certification bodies as a moderate, clarifying update rather than a structural overhaul.
The most consequential change for management review and internal audit programs is the explicit introduction of quality culture and ethical behavior into Clause 5.1 (Leadership and Commitment), with expanded guidance in Annex A on how organizations are expected to demonstrate both. Clause 6.1 on risk and opportunity has been split into distinct subclauses (6.1.1--6.1.3), separating risk treatment from opportunity management rather than treating them as a single activity. The 2024 climate change amendments to Clauses 4.1 and 4.2 --- requiring organizations to determine whether climate change is a relevant issue in their organizational context and among interested-party requirements --- have now been folded permanently into the base standard. Terminology in Clause 3 has also been aligned with the harmonized structure shared across ISO 14001 and ISO 45001, which should ease integrated management system audits going forward.
Action items: Do not claim conformity to ISO 9001:2026 before the September 16 publication date. Brief leadership on the confirmed milestone now and begin a gap analysis against the FDIS text --- particularly Clause 5.1 quality-culture/ethics evidence and the restructured Clause 6.1 --- so a formal transition plan is ready once the International Accreditation Forum publishes transition rules (historically a three-year window, though a shorter period is plausible given the moderate scope of this revision).
Sources: ANSI Blog (ISO/FDIS 9001:2026), CBQA Global, Smithers, DNV, SGS.
ISO 14001 --- Environmental Management Systems
Unlike ISO 9001, ISO 14001:2026 has already cleared publication and is now the live edition, replacing the 2015 version. Certification bodies confirm a three-year transition window: certificates issued against ISO 14001:2015 must migrate to the 2026 edition before April 30, 2029, to remain valid.
The revision broadens the environmental context analysis in Clause 4 well beyond climate change alone, now explicitly naming pollution levels, biodiversity, and the availability of natural resources as issues organizations must consider. Lifecycle thinking has been strengthened, requiring environmental impacts to be assessed across the full value chain rather than direct operations only, and operational controls have been extended to cover externally provided processes, products, and services --- a meaningful change for organizations relying on outsourced manufacturing or logistics. Change management planning is now a distinct, structured requirement, and internal audit expectations have been clarified with defined objectives and audit-program structure.
Action items: Although the 2029 deadline feels distant, the expanded supply-chain and lifecycle scope typically requires new data collection from suppliers --- start that outreach in 2026 rather than waiting. Update environmental aspect/impact registers to explicitly address biodiversity and resource availability, not climate alone, and fold the new change-management planning requirement into existing management-of-change procedures.
Sources: DNV, LRQA, SGS, Amtivo, Nemko.
ISO 45001 --- Occupational Health & Safety Management Systems
No new edition of ISO 45001 published this week or this month --- the current 2018 edition remains in force. The revision process, however, is active: it formally began in May 2024, the international drafting committee met again in May 2025, and publication of the revised standard is now anticipated in 2027, with a standard three-year transition period expected to follow. Two themes are driving the revision: alignment with the harmonized structure's climate-change context requirement (mirroring the change already made to ISO 9001 and ISO 14001), and a more explicit recognition of psychological health and safety --- covering stress, burnout, and mental fatigue --- as a core component of occupational risk rather than an optional add-on.
Separately, ISO 45003:2021 (psychological health and safety guidance, not a certifiable requirements standard) continues to see growing practical adoption. Recent implementation literature emphasizes combining a dedicated implementation team with a facilitated planning process, rather than treating psychosocial risk as a bolt-on to the existing physical hazard register.
Action items: Clients should not wait for the 2027 revision to act on psychosocial risk --- auditors are already probing this area under the existing 2018 clauses on worker consultation and hazard identification. Stand up a psychosocial hazard register now (see Practical Steps below) so the organization has a defensible audit trail ahead of the eventual revision.
Sources: Smithers, MSI International, ScienceDirect, ISO.org.
U.S. State Regulatory Activity Affecting These Standards
AI Governance (ISO 42001)
Four state AI laws took effect January 1, 2026. Texas's TRAIGA (HB 149) prohibits developing or deploying AI with intent to manipulate, unlawfully discriminate, or infringe rights, and --- notably for ISO 42001 clients --- grants safe-harbor protection to organizations that achieve substantial compliance with the NIST AI Risk Management Framework. California's SB 53 imposes frontier-model obligations on large AI developers, including published risk frameworks, safety-incident reporting, and whistleblower protections, while California's AB 2013 requires any generative-AI system offered in the state to publish training-data summaries --- a requirement that reaches ordinary B2B software with embedded generative features, not just AI-first vendors. Illinois's HB 3773 prohibits AI-driven employment discrimination and requires notice when AI influences a hiring decision. Looking ahead, New York's RAISE Act --- finalized this year --- takes effect January 1, 2027, for frontier AI model safety and incident reporting, and Colorado's SB 26-189 replaces the state's original 2024 AI Act with a consumer-protection framework (pre-use notice, adverse-outcome explanations, human review rights) effective in 2027.
Environmental (ISO 14001)
PFAS ('forever chemicals') restrictions expanded across a large block of states effective January 1, 2026, including Colorado, Connecticut, Illinois, Maine, Minnesota, New Jersey, Oregon, Vermont, and Washington, with several (Minnesota's PRISM reporting system, Washington's manufacturer reporting) imposing new disclosure obligations rather than outright bans. Organizations with PFAS anywhere in their product formulations or supply chain should treat this as a direct input to the ISO 14001:2026 lifecycle and externally-provided-services assessment discussed above. Separately, California's SB 253 climate disclosure law remains on track, with initial Scope 1 and 2 emissions reports due November 10, 2026 for entities with revenue exceeding $1 billion doing business in the state; companion law SB 261 (climate-related financial risk disclosure, $500 million revenue threshold) is currently paused under a Ninth Circuit preliminary injunction pending appeal.
Occupational Health & Safety (ISO 45001)
With the federal OSHA heat-illness rulemaking still stalled, state-level heat standards continue to be the operative requirement in six states: California (separate outdoor and indoor standards), Oregon, Washington, Nevada, Maryland, and --- newly effective January 1, 2026 --- Colorado's agricultural-sector heat standard. All six exceed the stalled federal proposal on at least one dimension (rest-break frequency, indoor coverage, or acclimatization monitoring), meaning organizations operating in these states should audit their hazard registers against the specific state rule rather than a generic heat-illness policy.
Practical Steps to Meet the New Requirements
The subsections below translate this week's developments into concrete; auditable actions clients can implement ahead of the next surveillance or certification audit.
Quality Culture (ISO 9001 Clause 5.1.1 / 7.3)
Document leadership engagement with quality objectives through dated, signed management walk-around logs rather than relying on meeting minutes alone. Run an annual quality-culture pulse survey with year-over-year trend tracking as an objective input to management review, and tie at least one individual performance-review criterion per department to a quality metric so culture has a paper trail independent of the audit cycle. Where quality objectives cascade from corporate to team level, keep the cascade documented in a single traceable register auditors can follow from Clause 6.2 objectives down to individual accountability.
Ethics (ISO 9001 Leadership and Awareness Clauses)
Maintain signed acknowledgment records of a code of conduct for all employees and key suppliers, refreshed annually, and log completion rates as a management-review metric. Keep a redacted ethics/whistleblower hotline log showing case counts, categories, and resolution timelines --- auditors increasingly ask to see that a reporting channel is actually used, not merely available. For higher-risk decisions (supplier selection, product claims, AI-influenced outputs), keep dated minutes from an ethical-review checkpoint showing the decision was actually considered against the code of conduct rather than assumed compliant.
Climate Change (ISO 9001 Clause 4.1 / ISO 14001)
Add a standing climate-risk line item to the Clause 4.1 context-analysis review, documented at least annually, even for organizations concluding climate change is not currently material --- the requirement is to demonstrably consider the question, not necessarily to act on it. Where the organization is in scope for SB 253 or similar disclosure regimes, cross-reference the emissions inventory directly into the EMS objectives register so the same data supports both the regulatory filing and the ISO 14001 performance evaluation, avoiding duplicate data-collection efforts. Keep scenario-planning notes (even brief ones) on file as evidence that climate risk was evaluated against the organization's specific operations, not copied from generic guidance.
Psychosocial Risk (ISO 45001 Revision / ISO 45003 Guidance)
Stand up a psychosocial hazard register that sits alongside, not folded into, the physical hazard register, covering workload, bullying/harassment, role clarity, and job security as named hazard categories. Run an anonymous psychosocial-risk pulse survey at least annually and retain the aggregate results as objective evidence for management review. Require documented manager training on recognizing psychosocial risk indicators, and update incident-investigation procedures so psychosocial contributing factors (not just physical root causes) are a mandatory field in every investigation report.
AI Governance Alignment (ISO 42001 and State Safe-Harbor Provisions)
Given how many state AI laws now reference the NIST AI Risk Management Framework directly, maintain a single documented crosswalk mapping ISO 42001 Annex A controls to the NIST RMF's Govern, Map, Measure, and Manage functions, and keep it current as new state laws are enacted. Maintain an AI system inventory with a documented risk tier for each system and require a pre-deployment impact assessment for any system that influences employment, credit, housing, or other consequential decisions --- this directly supports Illinois HB 3773 and similar disclosure duties. Log training-data summaries for any generative AI feature offered to California users to satisfy AB 2013 and retain incident and adverse-outcome logs in a format that could support the 72-hour reporting timelines emerging in frontier-model legislation such as New York's RAISE Act.
SQC Advisory --- This briefing summarizes publicly available standards and regulatory developments as of the date above and does not constitute legal advice. Clients should confirm applicability to their specific certification scope and jurisdiction before acting.