SQC ADVISORY | Week September 6

SQC ADVISORY | Week September 6

SQC ADVISORY | Week September 6

Weekly Regulatory & Standards Newsletter

ISO 9001 | ISO 14001 | ISO 45001 | ISO 42001

Week ending Sunday, September 6, 2026

Prepared for Mitchell Sevcik

This Week at a Glance

This is a consequential week for anyone maintaining an integrated management system. ISO 9001 is ten days from publication of its sixth edition, and the final draft confirms that quality culture, ethical behavior, and climate change move from commentary into the requirements text. ISO 14001:2026 has already been in force since April and organizations are now roughly five months into a three-year transition clock, with the first transition-inclusive recertification audits arriving in October 2027. ISO 45001 remains in revision with a psychosocial-risk emphasis expected to carry through to publication in 2027, which makes ISO 45003 the practical bridge in the meantime. ISO 42001 continues to be driven less by standards activity and more by market and legal pressure, as state AI statutes take effect and procurement teams begin asking for certification by name.

On the state side, the story this week is California. The Legislature adjourned its 2026 session on August 31 with roughly thirty AI-related bills on the Governor's desk and a September 30 action deadline, so the regulatory picture for AI governance programs will look materially different by the end of this month. Separately, CARB's climate disclosure guidance and fee milestones land in early September, with the SB 253 Scope 1 and 2 reporting deadline now sitting at November 10.

ISO 9001 — Quality Management

The headline item is a firm publication date. ISO has scheduled the sixth edition of ISO 9001 for release on 16 September 2026, following FDIS approval with overwhelming international support. The path here has been steady rather than dramatic: the DIS was released on 27 August 2025 and approved by member bodies in December 2025 with a 97 percent approval rate, and the ISO/TC 176/SC 2 working group reached full technical consensus on clauses 1 through 10 after its February 2026 meeting in Mexico City. Organizations will have a three-year transition window running to September 2029.

The substance of the revision is evolutionary. The Annex SL high-level structure is preserved, and the core requirements remain recognizable, so this is not a 2008-to-2015 style rebuild. What has changed is emphasis, and three shifts matter most for audit readiness. First, Clause 5.1.1 now explicitly requires top management to promote and demonstrate a quality culture and ethical behavior, with an accompanying note clarifying that culture and ethics may be demonstrated through shared values, beliefs, history, attitudes, and observed behaviors. That note is important, because it tells auditors what kind of evidence is admissible and tells organizations that a policy statement alone will not carry the requirement. Second, climate change and sustainability are now explicitly part of determining organizational context under Clauses 4.1 and 4.2, moving beyond the 2024 amendment's minimal language into a fuller expectation. Third, risk-based thinking has been sharpened with clearer language, and the standard as a whole leans further toward treating quality management as a strategic business function rather than a compliance exercise.

Why it matters: Certification bodies will begin building transition audit capacity almost immediately after publication, and the three-year window is generous only if organizations start early. The culture and ethics clause in particular is the kind of requirement that is easy to defer and hard to evidence retroactively, because the evidence auditors will look for is behavioral and longitudinal.

Action items: Obtain the published standard once it is available on 16 September, run a clause-level gap analysis against the current QMS with particular attention to 4.1, 4.2, 5.1.1, and 7.3, and open a conversation with your registrar about transition audit scheduling before the queue forms. Begin collecting quality culture and ethics evidence now so that by the time of the transition audit there is a record with some depth to it. Practical approaches are set out in the final section of this newsletter.

Sources

ISO 14001 – Environmental Management

ISO 14001:2026 was published on 15 April 2026, so this week's relevance is less about news and more about where organizations should be on the transition curve. The transition period closes on 30 April 2029, and from 1 October 2027 recertification audits will incorporate transition requirements. That intermediate date is the one worth marking, because any organization whose recertification cycle falls after October 2027 is effectively working to a 2027 deadline rather than a 2029 one.

The changes are moderate in scope, considerably less disruptive than the 2015 transition. Climate is now fully integrated rather than bolted on, and climate aspects must be addressed systematically within the environmental management system rather than considered only as external context. The treatment of environmental aspects has expanded to give greater weight to biodiversity, resource availability, and pollution levels, which broadens the aspects and impacts register for most organizations beyond the familiar emissions, waste, and discharge categories. A new Clause 6.3 requires a structured approach to managing changes to the EMS, aligning ISO 14001 with the change management thinking that has been migrating across the Annex SL family. The standard has also been updated to reflect current environmental terminology and the latest harmonized structure.

Why it matters: The expansion into biodiversity and resource availability is the change most likely to surface gaps in an existing register, because those categories were rarely evaluated under the 2015 edition outside of resource-extractive or land-intensive sectors. The new Clause 6.3 is straightforward to satisfy but easy to overlook, since many organizations manage EMS changes informally.

Action items: Re-run the aspects and impacts evaluation with biodiversity, resource availability, and pollution level criteria explicitly added, and document the reasoning even where the conclusion is that an aspect is not significant. Establish or formalize an EMS change management procedure to satisfy Clause 6.3. Confirm your recertification date against the 1 October 2027 threshold.

Sources

ISO 45001 – Occupational Health & Safety

No new balloting milestone surfaced this week. The revision remains in progress, with a Draft International Standard expected during 2026 and publication anticipated in 2027; both dates depend on ISO committee scheduling and have moved before, so they should be treated as planning assumptions rather than commitments.

The direction of the revision is well established even without a published draft. The revised standard is expected to broaden occupational health and safety beyond physical hazards to reflect how and where people actually work, treating stress, excessive workload, burnout, bullying and harassment, job insecurity, and isolation in remote and hybrid roles as genuine occupational hazards to be identified, assessed, and controlled inside the OH&S management system rather than handled separately by human resources. ISO 45003:2021 remains the companion guidance document and is the practical instrument available today. Organizations that begin folding psychosocial factors into hazard identification and risk assessment now, using ISO 45003 as the framework, will be ahead of the requirement rather than reacting to it.

Why it matters: Psychosocial risk is the single change most likely to require genuinely new competence and new process, rather than re-documenting something already being done. Building the capability takes longer than a transition window typically allows, and there is a converging pressure from state-level workplace regulation in the United States, discussed below.

Action items: Obtain ISO 45003:2021 if you do not already hold it and pilot a psychosocial hazard identification exercise on one function or site to establish method and baseline. Confirm that any resulting findings route into the existing risk register rather than a parallel HR process, since the revision will expect them inside the management system.

Sources

ISO 42001 – AI Management Systems

Activity around ISO/IEC 42001 continues to come from adoption and regional alignment rather than from revision of the standard itself. On the European side, EN ISO/IEC 42001:2026 was approved by CEN on 13 March 2026, with national standards bodies required to give it national-standard status by September 2026. That adoption does not, however, make ISO 42001 a harmonized standard under the EU AI Act, so certification alone does not confer a presumption of conformity. The dedicated European AI management system deliverable, prEN 18286, is still under development at CEN-CENELEC, and organizations should not assume ISO 42001 certification will substitute for it.

Commercial adoption is the more visible trend. Certifications continue to be announced across the software sector, including CMiC's certification of the AI management system covering its NEXUS platform analytics chatbot, announced on 1 September 2026 and issued by Schellman. More telling than any individual certificate is the procurement signal: by mid-2026, a question about ISO 42001 certification or implementation status appears in roughly forty percent of enterprise AI vendor RFPs in the EU and roughly twenty-five percent in North America. For vendors, the standard is becoming a commercial prerequisite well ahead of any regulatory mandate.

Why it matters: The business case for ISO 42001 is currently strongest as a sales enabler and as scaffolding for state-law compliance, not as a regulatory safe harbor. Being precise about that distinction with clients and internal stakeholders avoids overselling what a certificate delivers.

Action items: For organizations selling AI-enabled products, treat ISO 42001 readiness as a revenue-protection project and check whether RFP responses currently have a defensible answer. Map your AIMS controls against the state statutes summarized below, since the overlap in impact assessment, disclosure, and documentation obligations is substantial and the work can be done once.

Sources

US State Regulatory Activity

AI Governance — Bearing on ISO 42001

State AI regulation continued to accelerate through 2026, with roughly eighty-five AI-related laws enacted across twenty-seven states so far this year. The most immediate development is procedural: the California Legislature adjourned its 2026 session near midnight on 31 August with approximately thirty AI-related bills sent to Governor Newsom, who has until 30 September to sign or veto. Several concern AI use with minors, education technology, and platform liability. Anyone advising California-exposed clients should plan on a substantive update in early October once the signing decisions are known.

The already-effective landscape is more settled. California's GAI Training Data Transparency Act (AB 2013), AI Transparency Act (SB 942), and SB 53 all took effect on 1 January 2026. Texas's Responsible Artificial Intelligence Governance Act (HB 149) also took effect 1 January 2026, carrying broad disclosure requirements, discrimination prohibitions, and tiered civil penalties — and, notably for management system practitioners, a safe harbor for organizations using the NIST AI Risk Management Framework or a comparable recognized framework. Colorado took a different path: SB 24-205 was delayed from February to June 2026 and never took effect, and in May 2026 the state repealed and replaced it with SB 26-189, a narrower statute addressing automated decision-making technology that materially influences consequential decisions, effective 1 January 2027. Six states — Michigan, Pennsylvania, Massachusetts, Ohio, New Jersey, and North Carolina — continue to consider AI bills. A December 2025 federal executive order raises questions about the reach of several state AI laws that courts have not yet resolved, so some legal uncertainty should be assumed in any compliance plan.

Practical read: The Texas safe harbor is the most actionable item here. An organization that has implemented ISO 42001, and can map its AIMS to NIST AI RMF functions, is well positioned to argue it falls within that safe harbor. That mapping is worth documenting explicitly rather than leaving as an inference.

Environmental & Climate Disclosure — Bearing on ISO 14001 and ISO 9001 Clause 4.1

California's climate disclosure regime continues to move. CARB was scheduled to issue additional guidance materials supporting 2026 reporting by 1 September 2026, with a first-year fee determination proposed for 10 September 2026. The SB 253 Scope 1 and Scope 2 reporting deadline was pushed on 24 June 2026 from the previously proposed 10 August to 10 November 2026. Enforcement of SB 261 has been temporarily halted following an injunction pending appeal in the Ninth Circuit, though in-scope entities remain obligated to submit initial SB 253 reports by CARB's deadline. Looking ahead, CARB staff have proposed requiring five Scope 3 categories beginning in 2027, limited assurance over Scope 1 and Scope 2 emissions, more detailed methodology disclosures, and an annual 10 November reporting deadline.

Practical read: The proposed limited assurance requirement is the item that most directly touches management system work, because it converts internal emissions accounting into an auditable process with evidence expectations similar to those an EMS already carries. Organizations with mature ISO 14001 data governance are in a considerably better position than those treating emissions reporting as a spreadsheet exercise. The convergence with ISO 9001:2026 Clause 4.1 and ISO 14001:2026 climate requirements means one climate-context analysis can serve all three purposes if it is scoped that way from the start.

Workplace Safety — Bearing on ISO 45001

Federal heat rulemaking remains stalled following the January 2025 regulatory freeze, which leaves state programs as the operative requirement. California's indoor heat illness prevention standard, effective since July 2024, remains in force and generally applies where indoor temperature reaches 82°F, requiring water, cool-down areas, training, emergency response procedures, and acclimatization, with additional monitoring and control measures triggered at 87°F or at 82°F where employees wear heat-retaining clothing or work in high radiant heat. The outdoor standard applies to all outdoor workplaces, with high-heat procedures at 95°F in construction, agriculture, landscaping, oil and gas extraction, and certain transportation and delivery operations. Cal/OSHA issued a reminder to employers about heat illness protection during high temperatures earlier in 2026.

On workplace violence, California employers were expected to have reviewed their prevention plans and completed annual training as of 6 May 2026. Cal/OSHA's workplace violence regulation currently applies only to the health care industry, but the agency has signaled its intent to extend it more broadly. That intended expansion is worth tracking alongside the ISO 45001 revision, because workplace violence and harassment sit at the boundary between physical and psychosocial hazard and will likely need to be addressed once for both purposes.

Practical read: Multi-state employers should verify heat program coverage against each state's own threshold rather than relying on a federal baseline that does not currently exist. Several states now exceed federal expectations, and a single corporate heat program built to the strictest applicable state standard is generally simpler to maintain than a patchwork.

Sources

Practical Steps to Meet the New Requirements

The requirements discussed above share a common difficulty: they ask for evidence of things that are cultural, forward-looking, or historically outside the management system's boundary. The guidance below is aimed at producing evidence an auditor can actually sample, rather than at restating the clause language.

Quality Culture — ISO 9001 Clauses 5.1.1 and 7.3

Start by defining what quality culture means in your organization in concrete, observable terms, because the FDIS note points explicitly to shared values, beliefs, attitudes, and observed behaviors as the demonstration route. Write a short statement of quality behaviors — how issues are raised, how errors are treated, how competing pressures between schedule and quality are resolved — and locate it where people encounter it rather than in a manual. Then build measurement around it. A short annual quality culture survey with retained results across cycles gives an auditor a trend line, which is far stronger evidence than a single snapshot. Speak-up and near-miss reporting volume, tracked over time with evidence of what happened to each report, demonstrates that raising concerns is safe and consequential.

Push the evidence into records that already exist. Management review minutes should show quality culture as a standing agenda item with discussion, not a checkbox. Performance objectives for managers should include quality behaviors, and completed appraisals become sampleable evidence. Leadership walkthroughs or Gemba visits with recorded observations tie top management personally to the requirement, which is what Clause 5.1.1 is reaching for. On the awareness side of Clause 7.3, ensure induction and refresher training covers not just the quality policy but the individual's contribution to it and the implications of nonconformity, and retain training records that show the content, not just attendance.

Ethics — ISO 9001 Leadership and Awareness Clauses

The ethics requirement is best satisfied by connecting an existing code of conduct to the quality management system rather than creating a parallel structure. Where a code of conduct exists, add explicit reference to quality-relevant ethical conduct: accurate recording of inspection and test results, honest reporting of nonconformities, integrity in supplier and customer communications, and no falsification of records. Where no code exists, a one-page quality ethics statement signed by top management is sufficient to begin.

For evidence, document a confidential reporting route and, critically, retain records of how reports were handled and closed — an unused channel proves nothing, whereas a used channel with documented outcomes proves the system works. Include ethical conduct in supplier requirements and in supplier evaluation criteria so the requirement extends across the boundary of the organization. Run periodic ethics scenario discussions with teams, using realistic quality dilemmas, and keep the attendance and discussion records. Finally, ensure disciplinary and corrective action records show consistent treatment of integrity failures, since inconsistency is the most common way this requirement fails on audit.

Climate Change — ISO 9001 Clause 4.1 and ISO 14001:2026

Treat climate as a context input with two directions, and document both. Physical risk covers how climate conditions affect your ability to deliver conforming product or service — extreme heat affecting process stability or workforce availability, water availability in water-dependent processes, flooding or wildfire risk at key sites, and supply chain interruption at upstream suppliers in exposed geographies. Transition risk covers how the response to climate change affects the organization — customer sustainability requirements flowing down through contracts, disclosure obligations such as the California regime described above, energy cost and availability, and material substitution driven by regulation.

The auditable output is a documented climate context assessment recorded in the same register as other Clause 4.1 issues, with a recorded determination of relevance for each item, including items concluded to be not relevant. Where a climate issue is material, it should flow into the risks and opportunities under Clause 6.1 with an assigned action and appear in management review. For ISO 14001:2026, go further: climate aspects must be systematically addressed within the EMS, so integrate them into the aspects and impacts register alongside the newly emphasized biodiversity, resource availability, and pollution level criteria. Ensure the emissions data underlying any external disclosure is subject to the same data integrity controls as other EMS monitoring data, since limited assurance is on the horizon and retrofitting data governance is expensive.

Psychosocial Risk — ISO 45001 Revision and ISO 45003 Guidance

Use the ISO 45003 hazard categories as the starting taxonomy rather than inventing one: how work is organized, including workload, work pace, hours, and job control; social factors at work, including relationships, supervision, harassment, bullying, and isolation; and the work environment, equipment, and hazardous tasks. Add these categories explicitly to the existing hazard identification procedure so that psychosocial hazards are assessed within the same process and the same register as physical hazards, not in a parallel HR track. This single structural decision is what the ISO 45001 revision is most likely to test.

For assessment, combine an anonymous validated survey instrument with consultation — team discussions, worker representative input — and triangulate against existing indicators the organization already holds: absence data, turnover, grievance volume, employee assistance program utilization, and overtime patterns. Set controls at the organizational level first, in line with the hierarchy of controls, because workload redesign, clarified role boundaries, manager capability, and rota design are prevention, whereas counselling and resilience training are mitigation and should not be presented as the primary control. Ensure worker consultation and participation under Clause 5.4 explicitly covers psychosocial matters and record it. Train managers to recognize and respond to psychosocial risk and retain those records. Then close the loop by reviewing effectiveness with the same rigor applied to physical controls, showing that assessments led to actions and actions changed the indicators.

Change Management — ISO 14001:2026 Clause 6.3

The new clause is satisfied by a modest but genuine process. Define what constitutes a change to the EMS — new or modified processes, new sites or equipment, changes in legal requirements, organizational restructuring, new products or services — and require that proposed changes be evaluated for environmental consequence before implementation, including unintended consequences. Record the evaluation, the decision, the resources allocated, and any reassignment of responsibility. A single change evaluation form referenced from the EMS manual, with completed examples on file, is usually sufficient evidence, and building it as a shared procedure that also serves quality and safety change management avoids running three near-identical processes.

Framework Mapping for AI Governance — ISO 42001 and State Statutes

Given the Texas safe harbor for organizations using the NIST AI Risk Management Framework or a comparable recognized framework, produce and maintain an explicit written mapping between your ISO 42001 AIMS controls and the NIST AI RMF Govern, Map, Measure, and Manage functions. Treat that mapping as a controlled document reviewed at management review. Maintain an AI system inventory with an owner, purpose, and risk classification for each system, since nearly every state statute and the AIMS itself depend on knowing what is in scope. Complete AI impact assessments for systems influencing consequential decisions, using the ISO 42001 impact assessment requirement as the vehicle so that one assessment serves both the certification and the emerging state obligations, including Colorado's SB 26-189 regime effective 1 January 2027. Finally, verify that disclosure and transparency practices meet the California and Texas requirements now in effect, and retain the evidence of those disclosures.

Looking Ahead

Two dates dominate the next month. ISO 9001:2026 publishes on 16 September, and Governor Newsom's action deadline on the California AI bill package falls on 30 September. Both will be covered in the next edition. Beyond that, watch for the ISO 45001 Draft International Standard, CARB's further guidance on Scope 3 and assurance requirements ahead of the 10 November SB 253 deadline, and any judicial clarification of the December 2025 executive order's effect on state AI statutes.

Speak With An ISO Expert

Share your ISO, risk, or compliance needs, and we will respond promptly with clear next steps, suitable engagement options, and confidential guidance aligned with your current audit timeline.

Contact Us

Social Media