This Week in Brief

This Week in Brief

This Week in Brief

Week ending Monday, August 3, 2026

Prepared for Mitchell Sevcik

The management system landscape is in the middle of its heaviest revision cycle in a decade, and this week's developments reflect that. ISO 9001 has cleared its final draft ballot and is now on a firm path to publication next month, ISO 14001:2026 is roughly three months into its transition window with accreditation infrastructure still catching up, and ISO 45001 sits in the middle of a Draft International Standard ballot that closes in early September. ISO/IEC 42001 continues to move faster than any of them in practice, with a steady stream of certifications and a widening pool of accredited certification bodies. On the domestic regulatory side, the story of the past several weeks has been state legislatures filling the vacuum left by stalled federal rulemaking, most visibly in Illinois, alongside continued turbulence around California's climate disclosure regime.

What follows is a section on each standard covering what changed, why it matters, and what to do about it, a section on US state regulatory activity that intersects with these standards, and a closing set of practical, auditable steps for the requirements that are drawing the most attention from clients right now.

ISO 9001 — Quality Management

The Final Draft International Standard for ISO 9001 received ISO approval on 15 July 2026, following a ballot that opened in May and closed on 9 July. Approval was reported as decisive, and publication remains on track for approximately September 2026. That means the standard is now technically frozen: the text organizations will be audited against is, for practical purposes, the text that exists today. There is no further opportunity for substantive comment, and the window between now and publication is a preparation window rather than a wait-and-see window.

The revision is evolutionary rather than structural. The clause architecture and the core requirements of ISO 9001:2015 survive intact, and the 2024 climate change amendment is absorbed into the new edition. The substantive additions cluster in four areas. Clause 4.1 now requires an organization to determine whether climate change is a relevant issue in its context, and to record that determination even where the conclusion is that it is not relevant — a documented negative is still a documented conclusion, and auditors will look for it. Clause 5.1 adds promotion of quality culture and ethical behavior as an explicit leadership commitment, with accompanying guidance on how that promotion can be demonstrated rather than merely asserted. Clause 7.3 extends the awareness requirement so that personnel must understand the organization's quality culture expectations and its ethical behavior framework. Clause 6 separates risk from opportunity and introduces a more deliberate treatment of opportunity-based thinking, which had previously been folded somewhat loosely into risk-based thinking.

The practical significance is that three of these four additions are cultural and behavioral rather than procedural. An organization cannot close a quality culture gap by writing a procedure the week before the audit. Objective evidence of culture and ethics takes time to accumulate, which argues for beginning the transition work now rather than after September. A three-year transition period is expected, running to roughly September 2029, with the customary intermediate milestone at which certification bodies stop issuing new certificates against the 2015 edition.

Recommended action this quarter: run a gap assessment against the FDIS text, add a climate relevance determination to the next context review and minute the reasoning either way, and begin building the evidence trail for quality culture and ethics described in the practical steps section below.

ISO 14001 — Environmental Management

ISO 14001:2026 was published on 15 April 2026 and is now approximately fifteen weeks into a three-year transition. Certificates issued against ISO 14001:2015 remain valid during the transition but must be converted before the transition closes in 2029, and it is expected that new certificates against the 2015 edition will cease to be issuable roughly eighteen months after publication — that is, around late October 2027.

The most consequential change is that climate risk assessment moves from an amendment bolted onto the 2015 text to a central element of the environmental management system. The revision also broadens the range of environmental conditions an organization must consider when analyzing its context, naming pollution levels, biodiversity and natural resource availability alongside climate. The life cycle perspective, which many organizations treated lightly under the 2015 edition, receives strengthened emphasis in the environmental aspect determination process. New requirements address the planning and management of change. Finally, the text is aligned with the current Harmonized Structure, which improves integration with ISO 9001 and ISO 45001 for organizations running combined systems.

A practical wrinkle worth flagging: the accreditation infrastructure is still settling. The final mandatory transition document from the international accreditation community remains pending confirmation, and certification bodies are generally expected to complete their own accreditation to audit the new edition across 2027 and into 2028. First certificates against the 2026 edition are anticipated in that window. This creates a scheduling consideration rather than a compliance problem — organizations should confirm with their certification body when it expects to be accredited for the new edition, because that date, not the ISO transition deadline, is what determines when a transition audit can actually be booked.

Recommended action this quarter: ask your certification body for its accreditation timeline and transition audit availability, expand the context analysis beyond climate to cover biodiversity, pollution and resource availability, and revisit the aspects and impacts register with a genuine life cycle lens rather than a boundary-limited one.

ISO 45001 — Occupational Health & Safety

The ISO 45001 revision entered its Draft International Standard ballot on 16 June 2026 under ISO/TC 283. The ballot closes on 8 September 2026, which makes this the last realistic period in which national member bodies can shape the text through comment. Publication is currently anticipated around the middle of 2027, with a three-year transition consistent with the approach taken for ISO 9001 and ISO 14001, putting conformity deadlines somewhere near 2030.

The direction of travel is clear even though the text is not final. Psychosocial risk and mental health move from the periphery to the core of the standard, with explicit treatment of stress, burnout and workplace behavior as hazards to be identified and controlled through the same machinery as physical hazards. Climate-related occupational health and safety risks — heat exposure being the obvious example, though not the only one — receive increased consideration. The revision strengthens requirements around contractors and outsourced activities, addresses risks arising from remote and hybrid working patterns, and raises expectations for leadership accountability and worker participation.

Because ISO 45003:2021 already provides detailed guidance on psychological health and safety at work, organizations have an unusual advantage here: the implementation roadmap for the most demanding part of the coming revision already exists in published form. Organizations that begin aligning with ISO 45003 now will find the 2027 transition substantially easier, and the work is defensible on its own merits regardless of what the final ISO 45001 text says.

Recommended action this quarter: if you participate in a national mirror committee, review the DIS and submit comments before the 8 September close. Independently, begin a psychosocial hazard identification exercise using ISO 45003 as the framework, and review how contractor and remote-worker risks are currently handled in your OH&S system.

ISO/IEC 42001 — AI Management Systems

ISO/IEC 42001 saw no change to the standard text this period, but the certification ecosystem around it continued to develop rapidly. July brought a cluster of certification announcements across sectors — Presidio on 15 July, MetaPhase on 13 July certified by Bureau Veritas, and TechnipFMC also in July — which is notable less for any individual company than for the breadth of industries now treating an AI management system certification as a market expectation rather than a differentiator. On 30 July, Aprio announced it had received ANAB accreditation to conduct accredited ISO/IEC 42001 certification audits, adding to an accredited body pool that already includes BSI, Schellman, DNV, A-LIGN, LRQA, Bureau Veritas, SGS, TÜV SÜD and, since January 2026, NQA under UKAS.

The supporting standard ISO/IEC 42006:2025, which sets requirements for bodies auditing and certifying AI management systems, continues to bring consistency to a market that was previously uneven. Roughly one hundred organizations were certified as of January 2026, and the trajectory since suggests that figure has grown considerably. For advisory purposes the practical implication is about certification body selection: with accreditation still being granted on a rolling basis, verifying that a prospective certification body holds accreditation under the relevant scheme — and not merely a self-declared capability — is a meaningful piece of due diligence.

The stronger driver for ISO 42001 adoption in the United States remains regulatory rather than commercial, and that is covered in the next section. Recommended action this quarter: for organizations deploying AI in consequential decision contexts, map existing AI governance activity against the ISO 42001 Annex A controls to establish a baseline, and confirm the accreditation status and scheme of any certification body under consideration.

US State Regulatory Activity

Artificial Intelligence

The most significant state action this period was Illinois. On 6 July 2026, Governor Pritzker signed the Artificial Intelligence Safety Measures Act, which imposes governance, transparency, audit and incident-reporting obligations on developers of advanced AI models. The Act takes effect 1 January 2027, with the heavier substantive obligations phasing in during 2028. Its scope is narrow by design: it reaches "large frontier developers," defined by a combination of annual gross revenues above $500 million and training compute above a specified threshold, which limits direct application to a small number of very large firms. What makes it relevant well beyond those firms is its architecture. Covered developers must publish a frontier AI framework and transparency reporting, retain an independent third party for annual compliance audits beginning 1 January 2028, report critical safety incidents within 72 hours and imminent-harm incidents within 24 hours, and maintain confidential whistleblower channels. That combination — documented framework, independent audit, incident reporting, protected internal reporting — is recognizably a management system, and it maps closely onto what ISO/IEC 42001 already requires. Organizations that build a conforming AIMS are building most of the substrate that this class of legislation demands.

The wider state picture continues to fragment. Texas's Responsible AI Governance Act took effect 1 January 2026 and offers a safe harbor for organizations substantially complying with the NIST AI Risk Management Framework, which is an unusually explicit statutory endorsement of a voluntary framework and a useful precedent for the argument that structured governance buys regulatory protection. Colorado repealed and replaced its original AI Act with SB 26-189, a narrower automated-decision statute addressing employer obligations for AI used in consequential employment decisions, now taking effect in 2027. Connecticut enacted mandates governing workplace AI and disclosure obligations for reductions in force involving AI-assisted decisions. Illinois separately amended its human rights act to make clear that discrimination arising from an employer's use of AI in hiring, firing, discipline, tenure and training is actionable under the statute.

The compliance implication is that a US organization operating in multiple states now faces a patchwork with materially different triggers — intent-based in Texas, impact-based in Colorado, developer-scale-based in Illinois. An ISO 42001 management system does not by itself satisfy any of them, but it provides the inventory, risk assessment, impact assessment, control and monitoring machinery that each of them presupposes, which is why we increasingly recommend it as the organizing structure rather than building state-by-state compliance programs in parallel.

Environmental

California's climate disclosure regime remained unsettled through July. CARB withdrew its regulatory package in June with stated intent to modify the effective date and make clarifying amendments, then released proposed modifications to the initial regulation on 27 July 2026. SB 253, requiring scope 1, 2 and 3 greenhouse gas reporting in conformance with the GHG Protocol, has been associated with an August 2026 reporting deadline, though the ongoing regulatory revision leaves the operative timing in flux. SB 261, covering climate-related financial risk disclosure aligned to TCFD or an equivalent framework, is subject to a Ninth Circuit injunction; CARB has stated it will not enforce the 1 January 2026 deadline while the appeal proceeds and will set an alternate reporting date once resolved. Organizations in scope should be tracking the CARB rulemaking docket directly rather than relying on secondary summaries, given how much has moved in eight weeks.

At the federal level with direct state consequence, EPA proposed on 7 July 2026 to revise public participation requirements for minor New Source Review permitting, which would let state and local air agencies determine whether, when and to what extent the public is notified about minor source permits and minor modifications. A virtual public hearing was held on 22 July. The proposal has drawn attention particularly in Texas in connection with data centre backup and primary power generation. For ISO 14001 purposes this is a compliance obligations question rather than a permitting-burden question: if state-level public participation practice diverges, the organization's process for identifying and evaluating compliance obligations under the new edition needs to be sensitive to state variation rather than assuming a uniform federal floor.

Occupational Health & Safety

Federal heat rulemaking remains stalled — the January 2025 regulatory freeze halted progress, post-hearing comments closed in October 2025, and no target finalization date appears in the unified regulatory agenda. In its absence, six state OSHA programs now maintain enforceable heat illness prevention standards, California, Oregon and Washington among them. Oregon's S.B. 537 imposes workplace violence prevention and response requirements on certain health care employers including hospitals and home health providers, requiring a written prevention plan with incident reporting, internal investigation, post-incident response and worker support including first aid, medical care and trauma counselling; provisions tied to the Oregon Safe Employment Act carry a 1 July 2026 implementation date. The broader pattern across state plans is that complex risks — heat, ergonomics, workplace violence — are being converted into formal, program-based requirements. That is structurally identical to what ISO 45001 asks for, and organizations with a mature OH&S management system are generally well positioned to absorb these rules with documentation changes rather than program redesign.

Practical Steps to Meet the New Requirements

The subsections below give concrete, auditable ways to satisfy the requirements drawing the most attention across the four standards. Each is written so that the output is something an auditor can sample.

Quality Culture — ISO 9001 Clause 5.1.1 and 7.3

Quality culture is the hardest of the new requirements to evidence because it is a state of affairs rather than an activity. The workable approach is to generate artefacts that could only exist if the culture were being promoted. Start by writing a short quality culture statement — a page, not a manual — that defines what the organization expects of people in terms of speaking up about defects, stopping work when something is wrong, and reporting nonconformity without fear of consequence. Have it signed by top management and dated. Then build the evidence chain around it: include a standing quality culture item in management review with recorded discussion and decisions, not just a heading; capture leadership communications on quality in a retrievable form such as an intranet archive or a communications log; and record leadership participation in quality activity like Gemba walks, defect reviews or customer complaint discussions with names and dates attached.

For the Clause 7.3 awareness requirement, add quality culture and ethical behavior content to induction and to annual refresher training, and — critically — measure whether it landed. A short competency check or a targeted question set in an employee survey, repeated annually with results trended, converts an assertion into a measurement. Where survey results show weakness, raise an improvement action; an auditor finding an unfavorable survey result with a corrective action attached will read that far more favorably than uniformly positive results with no action trail. Finally, make sure a documented mechanism exists for employees to raise quality concerns, and that records show concerns were actually raised and closed out. An empty channel is evidence of a channel, not of a culture.

Ethics — ISO 9001 Leadership and Awareness Clauses

Ethical behavior is now explicitly a leadership commitment and an awareness topic, and the evidence expectations are similar in shape to quality culture but with a clearer compliance analogue. Establish or refresh a code of conduct that speaks specifically to quality-relevant ethics: accuracy of records and test data, honesty in reporting nonconformity, integrity in supplier and customer dealings, and the boundary between commercial pressure and product conformity. Require annual acknowledgement and retain the acknowledgement records — this is straightforward, auditable evidence.

Provide a confidential reporting route for ethical concerns, whether an internal ombudsperson or an external hotline, and maintain a log of reports and their disposition with appropriate confidentiality controls. Address ethics in the supply chain by adding conduct expectations to supplier terms and including an ethics dimension in supplier evaluation criteria. Document how the organization handles the specific situation auditors will probe: what happens when schedule or cost pressure conflicts with quality requirements. A documented escalation path with at least one worked example from the past year is the strongest available evidence that the commitment is real. Include ethics performance in management review inputs alongside the quality culture item.

Climate Change — ISO 9001 Clause 4.1 and ISO 14001:2026

Under ISO 9001 the requirement is narrow and easy to satisfy provided it is not overlooked: determine whether climate change is a relevant issue for the organization's context, and record the determination. The record should show the reasoning, not just the conclusion. A short section in the context analysis that considers physical risk to sites and operations, transition risk from regulation and market shift, supply chain exposure, and customer and stakeholder expectations, ending in a stated conclusion with a date and an owner, is sufficient. If the conclusion is that climate change is not relevant, say so explicitly and say why. Review it on the same cycle as the rest of the context analysis.

Under ISO 14001:2026 the bar is materially higher because climate risk assessment is a central element of the system. Conduct a documented climate risk assessment covering both physical and transition risk, and connect its outputs to the environmental aspects register and to objectives so that the assessment demonstrably drives action rather than sitting alongside it. Extend the context analysis beyond climate to the newly named conditions — pollution levels, biodiversity, natural resource availability — and record the evaluation of each. Rework the aspects determination with a genuine life cycle perspective covering upstream inputs, use phase and end of life, and document the boundary decisions and their rationale, since the boundary is where most life cycle findings originate. Implement a defined process for planning and managing change that includes environmental impact evaluation before the change is made, with records of change proposals and their evaluation. Where the organization is subject to California SB 253 or SB 261, align the greenhouse gas inventory and the climate-related financial risk work with the EMS climate risk assessment so that one dataset serves both purposes.

Psychosocial Risk — ISO 45001 Revision and ISO 45003 Guidance

The ISO 45001 revision is not final, but ISO 45003:2021 provides a stable framework, and work done against it will transfer. Begin with a psychosocial hazard identification exercise that uses the ISO 45003 hazard categories — work organization and job demands, social factors at work including leadership behavior and interpersonal relationships, and the work environment including equipment and hazardous tasks. Run it the same way physical hazard identification is run, with worker participation, and document participation explicitly, because worker involvement is itself a requirement and an auditor will look for it.

Assess and record psychosocial risks in the same risk register as physical risks rather than in a separate wellbeing document; integration is what demonstrates that psychosocial risk is treated as an OH&S matter. Apply the hierarchy of controls honestly: eliminating unreasonable deadlines, redesigning workload distribution and clarifying role boundaries are elimination and substitution controls, whereas resilience training and employee assistance programs are administrative controls near the bottom of the hierarchy. A control set consisting entirely of training and counselling will read as bottom-of-hierarchy and invites a finding. Establish leading and lagging indicators — absence and turnover data, workload metrics, survey indices — and trend them. Extend the incident reporting process to cover psychosocial incidents such as bullying, harassment and acute work-related stress, with a defined response procedure and confidentiality protections. Address remote and hybrid working specifically, covering isolation, boundary erosion and home workstation conditions, and address contractor and outsourced worker exposure, since both areas are expected to be strengthened in the revision. Bring psychosocial risk performance into management review as a standing input.

Risk and Opportunity Separation — ISO 9001 Clause 6

The revision's separation of risk from opportunity is a smaller change but a genuinely new documentation expectation. Many organizations maintain a single combined register in which opportunities are, in practice, absent or reduced to inverted risks. Split the register so that opportunities are identified through their own process — customer feedback, market analysis, technology assessment, improvement suggestions — rather than derived from the risk list. Record for each opportunity the decision taken, including decisions not to pursue, and link pursued opportunities to objectives and to resource allocation so the trail from identification to action is visible. Review both registers at management review and show that the opportunity register changed over the period.

Change Management — ISO 14001:2026

New requirements for planning and managing change need a defined process, and the simplest defensible version is a change request record that captures the proposed change, its environmental impact evaluation, any new or altered compliance obligations arising from it, the controls required, approval, and post-implementation verification. Apply it to process changes, new equipment, new materials, site changes and significant organizational changes. Organizations already operating a management of change process for safety purposes should extend that process rather than building a parallel one, and should make the environmental evaluation an explicit and separately recorded step so it cannot be absorbed into a general safety sign-off.

Prepared by SQC Advisory. This newsletter summarizes publicly reported developments and is provided for general information; it is not legal advice. Where regulatory deadlines are cited, confirm current status directly with the issuing agency, as several matters covered here — notably the California climate disclosure rules and the ISO 14001 accreditation timeline — remain subject to change.

Sources

— ISO — ISO 14001:2026 published, raising the bar for environmental performance (iso.org)

— ISO/TC 283 — ISO/DIS 45001 ballot, opened 16 June 2026, closes 8 September 2026 (committee.iso.org)

— ISO — ISO 9001 Quality management systems, Requirements, standard 88464 (iso.org)

— ANSI Blog — ISO 9001:2026 QMS revision updates; ISO 14001:2026 key changes and how to prepare (blog.ansi.org)

— ANAB — ISO/IEC 42001 Artificial Intelligence Management Systems certification bodies (anab.ansi.org)

— DNV — ISO 14001:2026 published, what's changed; ISO 9001 revision (dnv.com, dnv.us)

— BSI, SGS, DQS, TÜV SÜD, LRQA, Intertek, NQA — ISO 9001:2026, ISO 14001:2026 and ISO 45001:2027 transition guidance

— Norton Rose Fulbright, Greenberg Traurig, Crowell & Moring, Thompson Coburn — Illinois Artificial Intelligence Safety Measures Act (SB 315) analyses

— Latham & Watkins, WilmerHale — Texas Responsible AI Governance Act (TRAIGA)

— Epstein Becker Green, National Law Review — 2026 State AI Laws legislative wrap-up

— PwC, Nixon Peabody, Baker Tilly, Proskauer — California SB 253 / SB 261 status updates and CARB 27 July 2026 proposed modifications

— US EPA — Minor New Source Review public participation proposal, 7 July 2026; SBA Office of Advocacy summary

— OSHA — Heat Injury and Illness Prevention rulemaking status; OSHA Defense Report — State Plan Signals 2025-2026

— Oregon S.B. 537 workplace violence prevention requirements, 1 July 2026 implementation

— GlobeNewswire, Yahoo Finance, TechnipFMC, Inside Public Accounting — July 2026 ISO/IEC 42001 certification and accreditation announcements

Speak With An ISO Expert

Share your ISO, risk, or compliance needs, and we will respond promptly with clear next steps, suitable engagement options, and confidential guidance aligned with your current audit timeline.

Contact Us

Social Media