What the ISM Code Can Teach Us About Risk: Part Two

Editor’s note: This is the second of a two-part article examining the risk-based thinking lessons to be learned from maritime safety and security protocols. You can read part one here.

The International Safety Management (ISM) Code brings a framework for safety through systematic management. It was introduced by the International Maritime Organization after several major maritime accidents revealed a common problem: The causes were rarely technical alone; instead, they were failures of management systems. The ISM Code, therefore, established a simple but powerful requirement, wherein shipping organizations must implement a documented safety management system (SMS) to ensure the safe operation of ships and the protection of the environment.

The principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

Connecting the ISM code and ISO 9001

The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing leadership responsibility, risk assessment, operational control, training and competence, incident reporting, corrective action, and continual improvement. These requirements may sound familiar to anyone working with ISO management system standards such as ISO 9001 and others following the harmonized structure. In essence, the ISM Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

Establishing an SMS based on the ISM code and principles of ISO 9001 means planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, person in water, and/or security threats or piracy. (Note that maritime security is covered by the International Ship and Port Facility Security Code and ISO 28001 covering security management systems for the supply chain). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised.

Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of considering what could go wrong and if people know their roles if (when) it does. It also means interrogating the system to determine how the organization will handle the ramifications of the adverse event.

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. Sections 5.1 and 5.2 require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The master has overriding authority. At the same time, as per section 4, the ISM Code requires those off the ship to support the master through a defined role known as the Designated Person Ashore (DPA). This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles: Authority must match responsibility and top management must remain connected to operational realities.

ISO 9001 expresses the same idea in a different context. As seen in clause 5.1 (“Leadership and commitment”) and clause 5.3 (“Organizational roles, responsibilities, and authorities”) leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

In the case of mariners, competence and training are systematized. The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important: continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon-ship drills, and damage-control exercises are conducted not because emergencies are frequent; instead, it is because although they are rare, they are also highly consequential. This principle translates directly into quality management. Competence is not merely about qualifications; it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from incidents, as seen in ISO 9001’s clause 7.1.6 (“Organizational knowledge”) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of nonconformities, accidents, and hazardous occurrences. The purpose is not to blame, but to learn. Each incident becomes an opportunity to ask, “What failed in the system?” “What corrective action is needed?” and/or “How do we prevent recurrence?” Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about all key decisions, including how and when to transit dangerous areas. These decisions are rarely simple. They require balancing safety risks, commercial pressures, and regulatory requirements, including ever-changing statutory requirements of various contracting governments. This must be seen within the contexts of operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk; they provide a framework for making better decisions about risk.

The ISM Code as a case study for risk-based thinking

Mariners have much to teach quality professionals on the use of the system approach for considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons:

  • Systems matter more than individuals; therefore, while competent people are essential, reliable operations depend on structured systems.
  • Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away.
  • Leaders must prepare for rare but high-impact events, because risk management is not only about what happens frequently.
  • Practice builds readiness.
  • Training and drills ensure procedures work under real conditions.

The takeaway is that there is a need to learn relentlessly from failure and use nonconformities as opportunities to strengthen the system.

The need to navigate uncertainty strengthens the importance of the ISM Code and/or ISO 9001 to inform leaders about risk and process management. For ship owners and masters, decision-making requires a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Yet despite these uncertainties, global shipping remains remarkably reliable. More than 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

The ISM Code, as well as ISO 9001, recognize that outcomes, whether safety or quality, depend on well-defined processes and leadership oversight. To mariners and quality professionals alike, I would advise another close look at your management system. Strengthen it. Maritime leaders ashore, like executives in the boardroom, must stay involved in assessing and mitigating risks to provide the best chance for safety, security, and success.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Home » Archives for Inderjit Arora

What the ISM Code Can Teach Us About Risk: Part One

For centuries, individuals have sailed the sea, perhaps for their livelihood, perhaps for adventure, or perhaps for reasons of their own. Christopher Columbus, Ferdinand Magellan, James Cook, and countless others changed the world.

Today, sailing through international waters to meet the basic needs of the world brings challenges. Without merchant ships, tankers, bulk carriers, and container vessels, the global supply chain stops. Doesn’t the world owe these mariners all due safety and security?

I am a former seafarer who commanded submarines in the Indian Navy and then continued my career as a master in the merchant marine. Today, I am a subject matter expert in issues related to maritime safety and security. Given this background, I feel compelled to analyze what I hear and read about current events and provide a structure whereby the merchant marine industry might better prepare for any and all eventualities. The International Safety Management (ISM) Code, the International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW), and ISO 9001 all provide process-based approaches that can be used by those in this industry for planning and risk mitigation.

Most of us do not have to deal with high-risk challenges at sea. For those who do, however, there are guidelines they can use. As one example, the ISM Code provides some lessons into anticipating the unexpected and planning for these risks in a systematic manner.

In this article I will touch on how portions of the ISM Code connects to elements of ISO 9001 and provide input that might be useful to maritime leadership in ensuring quality assurance and conformity assessment based on risk and considering the context in which these organizations operate. This is guidance that applies to any of us, on the water or in a facility or factory.

Similarities between the ISM Code and ISO 9001

For professional mariners, a simple rule applies: Conditions that appear routine can change without warning. The ISM Code emphasizes preparedness for emergencies and abnormal situations. Section 8.1 requires the organization to establish procedures to identify, describe, and respond to potential emergency situations aboard the ship. In other words, the ISM Code requires organizations to plan not only for technical failures or weather hazards, but also for security risks and unexpected external threats. Navies may refer to this as an operational assessment, but (in Shakespearean language) a risk by any other name would still be a risk.

ISO 9001 expresses a comparable idea through the requirement for risk-based thinking. As emphasized in clause 6.1.1, the organization shall determine the risks and opportunities that need to be addressed to give assurance that the quality management system can achieve its intended results.

From a management systems perspective, the broader lesson is clear: Organizations must plan for situations that may appear unlikely until they occur. For a ship’s captain or master, that planning may involve security drills, contingency routing, and coordination with naval authorities. For a quality manager or organizational leader, it may involve supply chain disruption, cybersecurity incidents, or geopolitical shocks. Ultimately, the decision on whether to sail should be based on a proper risk assessment. Events at sea sometimes remind us, in stark terms, why disciplined safety and command systems matter. What makes an incident significant in the context of this discussion is the reminder of just how quickly circumstances can change at sea.

Within ISO 9001, the context of the organization (clauses 4.1 and 4.2) leads to risk appreciation (clause 6.1). All of this must be integral parts of the maritime management system, at sea or ashore.

This is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations as per section 8.1. Good organizations connect real maritime events with risk-based thinking. They understand that commercial interests must mesh with the emergency planning sections in the ISM Code. This understanding is also found in ISO 9001, specifically in clause 6 (“Planning”) and clause 8 (“Operation”).

Expecting the unexpected

My own appreciation for disciplined systems thinking was shaped long before the ISM Code was widely implemented in commercial shipping. During my years in the Indian Navy, I had the privilege of commanding vessels, first on F-class boats and later through service on a Charlie II-class submarine. Submarines operate in an environment where uncertainty is not theoretical and the margin for error is extremely small. Any failure in equipment, communication, or procedure can quickly become critical. What keeps submarines safe is not individual brilliance on the part of a captain or crew. That is part of it, of course, but even more important is the relentless adherence to procedures and constant preparation for contingencies. Before every patrol, the crew repeatedly rehearses emergency actions such as flooding drills, fire drills, loss of propulsion, and loss of power. Each crew member knows precisely where to go, what valve to operate, and what sequence of actions to follow. These procedures are not simply found in written manuals. They are practiced until they become instinctive.

At that time, we did not describe this discipline in terms of “process-based management systems,” but that is exactly what it was. The system existed to ensure that when the unexpected occurred, as it inevitably does at sea, the crew would not rely on improvisation alone. The response would already be embedded in the system and in themselves. Years later, when I sailed as a master in the merchant marine and then began to work with ISO management systems, I recognized the same principles expressed in a different language. ISO 9001 requires organizations to establish, implement, and maintain the processes needed for the quality management system and their interactions, as per clause 4.4 (“Quality Management System and its Processes”). Section 1.2 of the ISM Code similarly requires organizations to ensure safe practices in ship operation and a safe working environment. Different industries, different terminology, but the underlying idea is identical: Safety, quality, and reliability are the result of preparation and training, not simply reacting well to emergencies.

I can confirm through my experience that this reflection is not merely theoretical. It comes from first-hand experience wherein I led teams and where preparation truly mattered. This background gives me a clear perspective on risk, command responsibility, and disciplined procedures under uncertainty. This perspective can make a very compelling bridge between maritime safety management (ISM/STCW) and organizational quality systems (ISO 9001).

As we consider dangerous situations on or in the water, we can see what the ISM Code and ISO 9001 (in addition to other maritime protocols and ISO standards) can teach us about risk in uncertain times. In today’s volatile world, commercial shipping once again finds itself navigating geopolitical tension. News headlines remind us that vessels may need to transit waters where the risks are not merely commercial, but also matters of safety and survival. For those who have spent a career at sea, such circumstances are not entirely unfamiliar. The maritime profession has long recognized that uncertainty is inherent to operations. Ships sail through storms, equipment failures, and occasionally conflict zones. Yet despite these uncertainties, shipping remains one of the safest and most reliable global industries. This is not an accident. Much of that safety culture comes from the ISM Code, supported by training standards such as STCW. These frameworks provide reliable, structured guidance on how organizations anticipate risk, prepare crews, and maintain operational control.

In the next part of this two-part article, we will further discuss the framework of maritime systems and how they relate to risk and ISO 9001.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Root Cause Analysis for ISO 9001: Why “Human Error” is Never the Real Answer

We’ve all seen it on a corrective action report. A major nonconformity occurs, a customer shipment is delayed, or a critical process control is bypassed. The quality team scrambles, an investigation is launched, and under the “Root Cause” section of the form, someone writes the fatal phrase, “Human error. Employee was retrained.” Case closed. The form is filed, the auditor is supposedly satisfied, and everyone goes back to business as usual. But then, three months later, the exact same failure happens again. Different employee, same result. Blaming employees without looking at the processes can never be the answer. True in exceptional cases for example in the aviation industry pinpointing human failure can be the correction and even there not the corrective action.

If your organization is ISO 9001 certified and you find that “human error” is a recurring theme in your internal audits and corrective actions, your management system isn’t learning. In fact, relying on human error as a root cause is a red flag that your QMS is operating on compliance theater rather than true process effectiveness. As a management system framework, ISO 9001:2015 is fundamentally designed to prevent this exact trap. Here is why human error is never the real answer and how the standard gives you the architecture to dig deeper.

The myth of the careless worker starts When we blame human error, we are inadvertently stating that our processes are perfect, but our people are flawed. In the vast majority of manufacturing and service environments, this simply isn’t true. People rarely show up to work intending to make a mistake. When a mistake happens, it is almost always the predictable result of a flawed system, ambiguous instructions, or a lack of appropriate operational safeguards. ISO 9001 doesn’t view “human error” as a dead end; it views human action as an input to a process that must be managed.

Under Clause 4.4 (quality management system and its processes), the organization is required to determine the inputs required and the outputs expected from its processes, as well as the criteria and methods needed to ensure their effective operation and control. If a single human slip can crash a process, the control method is what failed, not the human.

Retraining is usually a cop-out. If the root cause is “human error,” the universal knee-jerk solution is “retraining.” But let’s be honest: if an employee already knew how to do the task and made a mistake due to fatigue, distraction, or a confusing interface, retraining them on the exact same flawed method accomplishes nothing. It is a cosmetic fix designed to show an auditor that “action was taken.” The standard addresses this distinction sharply between ISO 9001 Clause 7.2 (Competence) and Clause 7.3 (Awareness). Competence is about ensuring people have the necessary education, training, or experience to perform work affecting quality performance. Awareness, however, requires that persons doing work under the organization’s control are aware of the quality policy, relevant quality objectives, and crucially the implications of not conforming with the QMS requirements.

If an operator bypasses a step, the real question isn’t “Did we train them?” The real questions are: did they understand the risk of bypassing it? Did the system make it easy to bypass? Was production pressure actively incentivizing them to cut corners?

These structural anchors require digging behind the mistakes. To move past the surface-level excuse of human error, an effective root cause analysis (RCA) must use the framework embedded in ISO 9001 to look at the environment surrounding the worker. When a mistake occurs, use these three clause categories to guide your investigation. First the operational planning and control (ISO 9001 clause 8.1). The standard expects organizations to plan, implement, and control the processes needed to meet requirements. If a human error occurs, the organization should investigate if the process was designed to minimize the likelihood of error? Did we implement “mistake-proofing” (Poka-Yoke) or clear visual cues. If a step is critical, did we rely solely on memory, or did the system enforce a verification checkpoint?

The second important aspect is documented information (ISO 9001 clause 7.5.3). Often, “human error” is just a symptom of a terrible procedure. If an instruction is a 40-page wall of dense text sitting in a binder, or if it’s poorly formatted and confusing, a human will eventually misread it. ISO 9001 clause 7.5.3 requires documented information to be available and suitable for use, where and when it is needed. If your documentation isn’t user-friendly, the system is designed to generate errors.

Then there are the infrastructure and environment for the operation of processes (clauses 7.1.3 & 7.1.4). As humans we are heavily influenced by our physical and psychological surroundings. For example, is the lighting poor, or is the software interface counter-intuitive? Is the workplace excessively noisy or disorganized, leading to cognitive fatigue? Clause 7.1.4 explicitly requires organizations to determine, provide, and maintain a suitable environment, including social, psychological, and physical factors. If you push people past the brink of exhaustion or manage through fear, “human error” is a system-generated metric. This is further amplified as requirements in ISO 45001 and ISO 45003 and in the maritime world in the MLC (maritime labor convention).

There is then the need to drive the culture change via corrective action. To stop the cycle of lazy problem-solving, top management and quality leaders must change how they handle ISO 9001 clause 10.2 (nonconformity and corrective action). The standard outlines a strict, logical flow for failure management in terms of reacting to the nonconformity (contain the immediate issue). The need to evaluate the need for action to eliminate the causes of the nonconformity, so that it does not recur or occur elsewhere, by, reviewing and analyzing the nonconformity, determining the causes of the nonconformity and determining if similar nonconformities exist, or could potentially occur. Notice the plural language, causes. If your RCA stops at the individual who made the mistake, you have only found the mechanism of the failure, not the cause. A true root cause answer sounds like this: “The sorting process allowed a nonconforming part to pass because the visual inspection standard was ambiguous, the lighting at Station 3 was below the required lumens, and there was no secondary physical gate to catch human oversight.” Fixing that combination of system gaps actually prevents recurrence. Retraining the inspector does not.

The next time you review a corrective action report with “human error” listed as the root cause, reject it. Send it back with a simple instruction: Find out why the system made that error inevitable. If you are looking at system resilience use ISO 9001 clause 4.4 and ask if the process have adequate criteria and controls to handle human variability? When auditing competence verses awareness under ISO 9001 clauses 7.2 and 7.3 check if they lack the skill (competence), or did they lack an understanding of the impact of the mistake (awareness)? Now if you are looking at workplace factors under ISO 9001 clause 7.1.4 check if fatigue, poor layout, or excessive stress contribute to the slip? When auditing process safeguards, under ISO 9001 clause 8.1 check if the process built on robust operational planning, or is it relying purely on human heroics? Looking for evidence of true RCA execution under ISO 9001 clause 10.2 ask if they stop at who did it, or did we fix the systemic gaps to ensure it cannot happen elsewhere?

In concluding I would opine that the ultimate test of a living QMS is the sophistication of an organization’s management system and how it is mirrored directly in its corrective action register. An immature system looks for someone to blame, checks a box, and schedules a training session. A mature, high-performing QMS looks at a human mistake as a symptom, treats it as a valuable data point, and asks: “How did our system fail to protect our person from making this error?” As leadership and quality professionals, our goal shouldn’t be to build an audit-proof wall of paperwork that blames the workforce. Our goal is to engineer resilient processes.

__

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

ISO certified but nothing has changed? Here’s why your system isn’t delivering

Many organizations celebrate ISO 9001 certification, as also any other certification, as a major achievement. The certificate is framed, the scope is published, customers are informed, and the external audit is finally behind them. Yet a few months later, the uncomfortable question that arises before the leadership and the team asking, if we are ISO certified, why has nothing really changed?

The same problems keep recurring. Customer complaints are still handled reactively. Internal audits are still treated as a paperwork exercise. Corrective actions still close late. Processes still depend on individual heroics rather than robust systems. Management review still feels like an annual ritual rather than a business performance discussion. Employees still see ISO as “the quality department’s job.” This is, I think, not a failure of the standard but more often, it is a failure of implementation.

ISO 9001 was never intended to be a certificate on the wall. It is a management system standard designed to help an organization consistently meet customer, statutory, and regulatory requirements, while improving the effectiveness of its processes. If certification has not changed performance, behavior, decision-making, or customer outcomes, then the organization may have achieved conformity without achieving effectiveness. That distinction matters. A system can be documented, audited, and certified and yet still fail to deliver meaningful business value. The real question is not “are we certified?” The better question is, is our quality management system influencing how the organization is run?

QMII has been working on management systems and meeting client objectives since 1986. One thing is certain when a system is built for the auditors and not the business, it is almost worthless. One of the most common reasons ISO 9001 fails to deliver is that the system was designed around passing an audit rather than improving the organization.

This usually shows up in excessive procedures, generic policies, copied templates, and records created mainly to satisfy perceived audit expectations. The language of the system does not match the language of the business. Employees do not use the procedures because the procedures were not based on the “as-is” of the system. The system was template driven and its one and only aim was to get certified.

ISO 9001 does not require a parallel universe of paperwork. It expects the organization to determine the processes needed for the quality management system (clause 4.4.1 of ISO 9001), understand their sequence and interaction, define criteria and methods for effective operation and control, assign responsibilities, address risks and opportunities, and evaluate performance.

If your QMS is a collection of documents rather than a description of how the business creates and protects value, it will not deliver. A useful system should answer practical questions on effectiveness of the system and lead to continual improvement.

ISO 9001 Clause 5.1 requires accountability from the leadership. If the leadership is running the system using only clause 5.3 of ISO 9001 by delegation instead of owning it is doomed to failure. ISO 9001:2015 deliberately strengthened the role of top management. The standard moved away from the idea that quality can be delegated to a “management representative” and placed clear expectations on leadership. Top management must take accountability for the effectiveness of the QMS, ensure that the quality policy and objectives are compatible with the organization’s context and strategic direction, integrate QMS requirements into business processes, promote the process approach and risk-based thinking, provide resources, and support continual improvement. In practical terms, leadership must do more than attend the opening and closing

Employees are told quality matters, but production pressure overrides process controls. Corrective actions are assigned but not resourced. Customer complaints are discussed only after escalation. Internal audit findings are treated as irritations rather than opportunities to improve the system. A QMS delivers only when leadership uses it to make decisions. Certification may be achieved through documentation. Performance improvement requires leadership behavior.

The next thought that comes to mind is about the organization’s misunderstood “context”. A strong QMS begins with a clear understanding of the organization and its environment. Clause 4.1 understanding the organization and its context requires the organization to determine external and internal issues relevant to its purpose, strategic direction, and ability to achieve the intended results of the QMS. Clause 4.2. Interested parties requires the organization to understand relevant interested parties and their relevant requirements. In weak systems, this exercise often becomes a static SWOT analysis prepared once and filed away. It may list obvious items such as “competition,” “regulations,” “customers,” and “employees,” but it does not influence risk assessment, objectives, process controls, supplier management, resource planning, or improvement priorities. It must be remembered context is not a poster. It is the operating reality in which the QMS must function. For example, if the organization faces high staff turnover, then competence, training, knowledge retention, and process standardization become critical. If customer requirements are becoming more complex, then contract review, design control, change management, and communication need strengthening. If supply chain reliability is a recurring issue, then supplier evaluation, contingency planning, and incoming verification become important. If climate-related factors can affect operations, supply, infrastructure, or customer expectations. The update to standard expected in September reinforces that these issues should be considered where relevant. A QMS that ignores context becomes generic. A generic system may pass an audit, but it rarely improves performance.

Quality objectives (clause 6.2) are an important aspect of the QMS and yet are often not connected to process performance. Many certified organizations have quality objectives, but the objectives are often too broad, too safe, or too disconnected from process performance. Examples include “improve customer satisfaction,” “reduce complaints,” or “deliver quality products.” These are good intentions, but they are not always effective objectives. Clause 6.2  m expects objectives to be measurable, monitored, communicated, updated as appropriate, and consistent with the quality policy. The organization must also plan what will be done, what resources are required, who is responsible, when it will be completed, and how results will be evaluated. If objectives do not drive action, they are not management tools. They are slogans. Effective objectives should connect to the organization’s key processes and risks. A certified organization with weak objectives will often remain exactly where it was before certification. The certificate confirms that a system exists. Objectives determine whether the system is moving.

Connected closely to context is the risk-based thinking, which is often treated as a form, not a way of managing. Risk-based thinking is one of the central concepts in ISO 9001:2015. It is embedded throughout the standard, especially in Clause 6.1. Actions to address risks and opportunities. The organization must determine risks and opportunities that need to be addressed to give assurance the QMS can achieve intended results, enhance desirable effects, prevent or reduce undesired effects, and achieve improvement. In many organizations, risk-based thinking becomes a spreadsheet exercise. Risks are listed, scored, color-coded, and reviewed occasionally. But the risk register does not meaningfully affect process controls, training, supplier selection, inspection levels, maintenance, contingency planning, or management review. It is therefore not surprising that nothing changes. Risk-based thinking should influence how work is designed and controlled. If a process has high risk, it may need clearer criteria, competent personnel, verification steps, mistake-proofing, supplier controls, documented information, monitoring, or escalation triggers. If an opportunity exists, the organization should consider how to capture it, whether through technology, training, simplification, standardization, or improved customer communication.

When process owners do not really own their processes, it is an issue. ISO 9001 depends on the process approach. Processes must be defined, controlled, monitored, measured, and improved. Yet in many organizations, process ownership is unclear. A procedure may name an owner, but that person may not monitor process performance, review nonconformities, evaluate risks, train personnel, approve changes, or drive improvements. The quality department ends up chasing everyone for records, actions, and audit responses. This creates the impression that ISO belongs to quality rather than to the business. Clause 4.4 requires the organization to determine responsibilities and authorities for processes. Clause 5.3 requires organizational roles, responsibilities and authorities requires top management to ensure relevant roles are assigned, communicated, and understood. Process ownership must be real. A process owner should know, what the process is intended to achieve. What inputs and outputs matter. What risks can prevent success. What controls are required. What indicators show whether the process is effective. What nonconformities have occurred. What improvements are underway. What resources or competence are needed.  If process owners cannot answer these questions, the system is unlikely to deliver. The QMS may exist on paper, but operational accountability is missing.

Effective auditing is an essential part of decision making by leadership. If Internal audits check conformity but not effectiveness, then the system weakens. Internal audits are one of the most underused tools in ISO 9001. In weak systems, internal audits simply confirm that procedures exist and records are available. Auditors ask, “Do you have a procedure?” and “Can you show me the record?” This may establish conformity, but it does not necessarily test whether the process is effective. Clause 9.2 on internal audit requires the organization to conduct audits at planned intervals to provide information on whether the QMS conforms to the organization’s own requirements and ISO 9001, and whether it is effectively implemented and maintained. The word “effectively” is essential. A good internal audit should test whether the process achieves intended results. For example, an audit of purchasing should not only verify approved supplier lists and purchase orders. It should examine whether supplier controls are reducing risk, whether supplier performance is monitored, whether poor-performing suppliers are addressed, and whether purchased products and services consistently meet requirements.

An audit of corrective action should not only confirm that forms are completed. It should test whether root causes are credible, actions are appropriate, recurrence has been prevented, and lessons have been shared. If internal audits do not challenge process effectiveness, the certification audit may become the first serious test of the system. By then, opportunities for improvement have already been missed.

Corrective action must not stop at containment. Many organizations respond quickly to problems but fail to learn from them. They replace the defective item, reissue the document, retrain the employee, apologize to the customer, and close the action. The same issue then returns under a slightly different name. This is a classic sign that corrective action is not effective.

Clause 10.2 on nonconformity and corrective action requires the organization to react to nonconformities, deal with consequences, evaluate the need for action to eliminate causes, implement action, review effectiveness, update risks and opportunities where necessary, and make changes to the QMS if needed. The purpose is not to complete a form. The purpose is to prevent recurrence. Weak corrective action systems focus on symptoms. Strong systems investigate causes. They ask why the process allowed the issue to occur, why it was not detected earlier, whether the issue could exist elsewhere, whether controls are adequate, and whether the solution worked. A certified system that does not learn from failure will not improve. It will simply document recurrence.

Management review is often treated as a ceremonial meeting to satisfy ISO requirements. Slides are prepared, data is presented, minutes are recorded, and actions are listed. But the discussion may not influence strategy, resources, priorities, or change. Clause 9.3 on management review requires top management to review the QMS at planned intervals to ensure its continuing suitability, adequacy, effectiveness, and alignment with the strategic direction of the organization. Inputs include changes in context, customer satisfaction, process performance, nonconformities, audit results, supplier performance, adequacy of resources, effectiveness of actions taken to address risks and opportunities, and opportunities for improvement. If management review does not result in decisions and actions related to improvement, resources, process changes, risks, opportunities, and customer satisfaction, it is not fulfilling its purpose. A management review that does not change anything is a warning sign that the QMS is not connected to leadership control.

Continual improvement is expected by leadership, but the team dos does not engineer its success. Organizations often say they are committed to continual improvement, but they do not create the conditions for improvement to happen. Improvement depends on data, leadership, competence, time, ownership, and follow-through. Clause 10.3, continual improvement requires the organization to continually improve the suitability, adequacy, and effectiveness of the QMS. This connects directly to Clause 9.1 monitoring, measurement, analysis and evaluation, which requires the organization to determine what needs to be monitored and measured, the methods needed, when monitoring and measurement will be performed, and when results will be analyzed and evaluated. In simple terms: you cannot improve what you do not understand. If performance data is weak, late, inaccurate, or ignored, improvement becomes guesswork. If trends are not analyzed, the organization remains reactive. If customer feedback is collected but not acted upon, dissatisfaction continues. If process indicators are selected because they are easy to measure rather than because they reveal effectiveness, management will have poor visibility.

Continual improvement must be built into the management rhythm. It should be visible in objectives, audits, corrective actions, management review, process reviews, customer feedback, risk reviews, and operational meetings. Improvement is not an annual ISO activity. It is the habit of managing better.

So why has nothing changed? If ISO certification has not changed your organization, the likely reason is that the QMS has not been integrated into how the organization is led, planned, operated, evaluated, and improved.

The certificate may confirm that requirements were met at a point in time. But the value of ISO 9001 comes from daily use: leaders using the system to make decisions, process owners managing performance, employees following practical controls, risks being addressed before they become failures, audits testing effectiveness, corrective actions eliminating causes, and management reviews driving improvement.

ISO 9001 is not meant to sit beside the business. It is meant to help run the business. The remedy is not necessarily more documentation. In many cases, it is better integration, better ownership, better questions, and better use of existing information. Start by asking each process owner one question: How does your process prove that it is effective? Then ask top management, what decisions have we made because of the QMS? If those questions are difficult to answer, the organization may be certified but the system is not yet delivering.

The good news is that ISO 9001 already contains the architecture for improvement. Clauses 4 through 10 are not separate audit compartments; they are connected parts of a management system. Context informs risks and opportunities. Risks influence planning and controls. Controls shape operations. Operations generate performance data. Data feeds internal audit and management review. Nonconformities drive corrective action. Corrective action and analysis drive improvement.

When that cycle works, ISO certification becomes more than a market access tool. It becomes a disciplined way to manage performance, satisfy customers, reduce waste, strengthen accountability, and improve resilience. The certificate is only the beginning. The real test is whether the system changes decisions, behavior, and results.

__

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

How Should an Organization Prepare for a Surveillance Audit?

A surveillance audit is an essential component of maintaining certification to management system standards such as ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301 and many more. Unlike an initial certification audit, which evaluates the entire management system for compliance with a standard, a surveillance audit is conducted periodically, typically once or twice a year, to verify that the organization is continuing to comply with the requirements of the standard and that the management system remains effective and continually improves over time.

Preparing for a surveillance audit requires a structured and proactive approach. Organizations that maintain their management systems throughout the year generally find surveillance audits less stressful and more productive. Effective preparation not only helps ensure successful audit outcomes but also strengthens organizational performance, enhances customer confidence, and promotes a culture of continual improvement.

Purpose and Scope of the Audit

The first step in preparing for a surveillance audit is understanding its purpose and scope. Surveillance audits are designed to confirm that the certified management system is still functioning effectively and that the organization continues to meet the requirements of the applicable standard. The certification body usually provides an audit plan in advance, outlining the processes, departments, and clauses that will be reviewed and participation of the process owner.

Organizations should carefully examine the audit agenda and identify the areas that will receive special attention. Auditors often focus on changes made since the previous audit, corrective actions taken in response to past findings, internal audit results, management reviews, and key performance indicators. Understanding the audit scope allows management to allocate resources effectively and ensure that relevant personnel and records are available during the audit.

Review of Previous Findings

One of the most important preparation activities is reviewing the findings from previous audits, be it certification, surveillance, or internal or even the non-conformities raised internally without the audits. Auditors will often revisit past nonconformities and observations to verify whether corrective actions have been implemented and if the corrective action are effective or not. If there are any trends in the occurrence or recurrence of these non-conformities.

Organizations should gather evidence demonstrating that all corrective actions have been completed and that the root causes of identified issues have been addressed. This may include updated procedures, training records, monitoring reports, or revised controls. Any unresolved findings should be prioritized before the surveillance audit to avoid recurring nonconformities, which may indicate weaknesses in the management system.

Conduct Internal Audits

Internal audits are a valuable tool for assessing readiness before a surveillance audit. They provide an opportunity to identify gaps, weaknesses, and nonconformities before the external audit. Organizations should ensure that internal audits are conducted according to the planned audit schedule and cover all critical processes.

A well-executed internal audit should evaluate:

  • Compliance with management system requirements.
  • Adherence to organizational procedures.
  • Effectiveness of process controls.
  • Achievement of objectives and targets.
  • Availability and accuracy of records.

Any findings from internal audits should be documented, and addressed through corrective action processes. Evidence of these activities demonstrates the organization’s commitment to continual improvement and effective system management.

Ensure Documentation Is Current and Up-to-Date

Documentation forms the backbone of any management system. During a surveillance audit, auditors review documented information to verify compliance and consistency. Therefore, organizations should perform a thorough review of all relevant documents and records before the audit.

Key documents that should be examined include:

  • Policies and objectives.
  • Process maps and procedures.
  • Work instructions.
  • Risk assessments.
  • Training and competency records.
  • Equipment maintenance records.
  • Calibration certificates.
  • Customer complaints and feedback records.
  • Corrective action reports.
  • Internal audit reports.
  • Management review records.

Organizations should also verify that document control procedures are functioning effectively. Obsolete documents should be removed from circulation, and only approved versions should be available to employees.

Verify Employee Awareness and Competence

Employees play a critical role during surveillance audits because auditors frequently interview personnel to assess their understanding of processes and responsibilities. Staff members should be familiar with relevant policies, procedures, objectives, and their role within the management system.

Organizations can prepare employees through awareness sessions, refresher training, and communication meetings. Employees should understand:

  • Their job responsibilities.
  • Relevant procedures and work instructions.
  • Organizational objectives.
  • Quality, environmental, safety, or security policies.
  • How they contribute to management system performance.

Rather than memorizing answers, employees should be encouraged to explain their actual work practices honestly and confidently. Authentic responses provide auditors with evidence that the management system is genuinely implemented rather than existing only on paper.

Review Organizational Performance

Surveillance audits often focus on performance measurement and continual improvement. Organizations should review their key performance indicators (KPIs), objectives, and targets to ensure that performance is being monitored and evaluated effectively.

Examples of performance measures may include:

  • Customer satisfaction levels.
  • Product or service quality indicators.
  • Environmental performance metrics.
  • Occupational health and safety statistics.
  • Information security incident rates.
  • Process efficiency measurements.

Management should be prepared to demonstrate how data is collected, analyzed, and used for decision-making. Auditors may ask for evidence showing that performance trends are reviewed regularly and that actions are taken when targets are not achieved.

Conduct a Comprehensive Management Review

Management review is a fundamental requirement of most ISO standards. Before the surveillance audit, organizations should ensure that management reviews have been conducted according to schedule and that all required topics have been addressed.

A management review should evaluate:

  • Internal and external audit results.
  • Customer feedback and complaints.
  • Process performance and effectiveness.
  • Status of corrective actions.
  • Resource adequacy.
  • Risks and opportunities.
  • Achievement of objectives.
  • Opportunities for improvement.

The outputs of the management review should include decisions and actions aimed at enhancing system effectiveness. Auditors will often examine management review records to determine the level of leadership involvement and commitment.

Assess Risks and Opportunities

Modern management system standards emphasize risk-based thinking. Organizations should review their risk assessments and ensure that identified risks and opportunities remain current and relevant.

Preparation activities should include:

  • Reviewing risk registers.
  • Evaluating mitigation measures.
  • Assessing emerging risks.
  • Monitoring control effectiveness.
  • Updating risk assessments where necessary.

Auditors may seek evidence that risk considerations are integrated into planning, operations, and decision-making processes. Demonstrating proactive risk management strengthens confidence in the management system.

Evaluate Corrective Action Processes

Corrective action management is a key area of interest during surveillance audits. Auditors want to see that problems are systematically identified, investigated, and resolved.

Organizations should review all corrective actions initiated since the last audit and verify that:

  • Root causes were identified.
  • Appropriate actions were implemented.
  • Effectiveness was verified.
  • Results were documented.

A robust corrective action process demonstrates a commitment to continual improvement and helps prevent recurring issues.

Prepare Audit Logistics and Resources

Effective logistical preparation contributes significantly to a smooth audit experience. Organizations should designate an audit coordinator responsible for facilitating communication between auditors and internal personnel.

Preparations may include:

  • Confirming the audit schedule.
  • Arranging meeting rooms.
  • Ensuring access to records and documents.
  • Identifying process owners and key contacts.
  • Providing necessary equipment and internet access.
  • Organizing facility tours if required.

Well-organized logistics help create a professional impression and allow auditors to focus on evaluating the management system rather than dealing with administrative delays.

Perform a Final Readiness Check

Before the surveillance audit begins, organizations should conduct a final readiness assessment or a mock audit. This exercise helps identify any remaining weaknesses and allows employees to practice responding to auditor questions.

The readiness review should verify:

  • Availability of required records.
  • Completion of corrective actions.
  • Employee awareness.
  • Compliance with procedures.
  • Effectiveness of management system processes.

Addressing issues discovered during this final review can significantly improve audit outcomes.

Conclusion

Preparing for a surveillance audit requires commitment rather than last-minute efforts. Organizations that regularly monitor performance, conduct internal audits, maintain accurate documentation, manage risks, and implement corrective actions are generally well positioned for successful surveillance audits. By understanding the audit scope, engaging employees, reviewing management system effectiveness, and ensuring that evidence of compliance is readily available, organizations can demonstrate ongoing conformity to standards and their dedication to continual improvement. Ultimately, effective preparation transforms the surveillance audit from a compliance exercise into a valuable opportunity to strengthen organizational performance and sustain long-term certification success.

__

About the Author:

Anjalika Singh is the President of QMII (Quality Management International, Inc.), a global management systems consulting firm headquartered in Ashburn, Virginia. Over the course of her career, she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organizations adopt ISO and industry-specific management systems in a way that delivers real business value. Anjalika also serves as President and CEO of iCertifications, LLC, where she leads efforts to make accredited ISO certification services accessible to small and medium-sized businesses.

Integrated Management System: Combining ISO 9001 and ISO 14001 Without Doubling the Work

An integrated management system (IMS) combining ISO 9001 (quality) and ISO 14001 (environment) is not double the work – it’s half the effort. Built on the shared Annex SL High Level Structure, an IMS eliminates siloed audits, redundant documentation, and conflicting objectives, replacing them with a single, unified framework for operational excellence.

The harmonized standards were not available till about 2012. Yet at QMII, we talked about an integrated approach to management and worked with organizations on the advantages of the integrated management system (IMS) or combined management systems. Why this discussion? It is a classic efficiency and silos battle. Many organizations treat ISO 9001 (quality management system, QMS) and ISO 14001 (environmental management system, EMS) as two separate burdens, often managed by two different departments that barely speak. With the emphasis on ISO 45001 (occupational health and safety, OHS) in recent times, we can see that an environmental impact could cause health consequences. Yet I see large organizations with siloed departments. In this short article I want to challenge and leave this for discussion that this double the work myth is incorrect and how the Annex SL harmonized structure makes various standards natural partners.

This myth of the parallel path must be demystified at the highest level. In many boardrooms, ISO is a word associated with binders, audits, and administrative fatigue. When a company decides to pursue both quality (ISO 9001) and environmental (ISO 14001) and other standards, the gut reaction is often to build two or as many separate systems as for each applicable standard. My first question is why manage your business as if your quality goals, OHS goals, asset management goals, crypto security goals, business continuity goals and your environmental impact etc. happen in different buildings? An integrated management system (IMS) isn’t just possible, it is the only way to achieve true operational harmony and genuine continual improvement.

The foundation of the integrated management system: Annex SL (High Level Structure). The secret weapon for harmonization is Annex SL. Most of the harmonized standards share identical core structures, meaning the skeleton of the management system is already the same. They share terms, definitions, and most importantly, their core clauses.

If I put this in phases, then the phase 1 would be to look at harmonizing the context and leadership. Let us simplify this discussion take just two standards, ISO 9001 and ISO 14001. At the start of both standards, the requirements are nearly indistinguishable in intent:

  • Clause 4: context of the organization would then not require doing two SWOT analyses, just do one. Identify your internal and external issues once. Under clause 4.2, the organization can identify the interested parties. A customer (quality) and a local regulatory body (environment) are both stakeholders. Managing them in one register ensures that environmental compliance doesn’t accidentally bottleneck quality delivery.
  • Clause 5: leadership and commitment where most un-integrated systems fail. Management shouldn’t have to attend two different management review meetings. Integration forces leadership to view quality and sustainability as two sides of the same strategic coin. One policy, one set of roles, and one unified vision based on risks across the organization.

The phase 2: then I would say would be the integrated planning and risk. This is where the heavy lifting of harmonization happens.

  • Clause 6.1: Actions to address risks and opportunities — a cornerstone of risk-based thinking in both standards. In ISO 9001, the organization looks at risks to product quality. In ISO 14001, you look at environmental aspects and impacts. By combining these in a single integrated management system, you see the full picture. For example, a chemical change in manufacturing might improve product durability (9001) but increase hazardous waste (14001). If these systems aren’t harmonized, you solve one problem only to create another.
  • Clause 6.2: objectives and planning harmonization enables the organization to set smart objectives that satisfy both standards simultaneously, such as reducing material waste which then lowers costs (quality) and reduces environmental footprint (environment).

Phase 3: could be unified support and operation and would meet the requirements of clauses 7 & 8 of both standards:

  • Clause 7: support would not need two sets of document control procedures or two different training programs. Clause 7.2 (competence) and clause 7.3 (awareness) can be handled through a single employee onboarding process.
  • Clause 8: operation while ISO 9001 focuses on operational control of the product and ISO 14001 focuses on life-cycle perspective and emergency response, they both live on the shop floor. Integrating these means the organization’s standard operating procedures (SOPs) include environmental safeguards alongside quality checks.

Phase 4: would then be a great advantage to the organization as it would provide the single pane of glass evaluation with the greatest efficiency gain in an IMS coming during the evaluation phase.

  • Clause 9.2: internal audit would be simpler and give more productivity. After all, why pay for or conduct two separate audits? A harmonized internal audit looks at a process from start to finish, checking for quality defects and environmental non-conformance in one walk-through.
  • Clause 9.3: management review would bring quality data and environmental performance to the same table and would allow executives to make resource allocation decisions based on the whole business, not just a siloed report.
  • Clause 10: Improvement. Corrective actions (clause 10.2) should follow the same root-cause analysis (RCA) path within the PDCA (Plan-Do-Check-Act) cycle. Whether a part failed a stress test or a spill occurred, the process for fixing the system and preventing recurrence is identical. The risks are common.

The concluding phase would bring the organization to move from fragmentation in the approach to bringing harmony by combining ISO 9001 and ISO 14001. It isn’t just about saving paper or reducing audit days. It’s about organizational maturity. When organizations harmonize these systems, they stop treating quality and environment as extra tasks and start treating them as the standard way of doing business. For those who still don’t appreciate the value they need to look at the bottom line. Less redundancy, clearer communication, and a unified strategy are the hallmarks of a company that isn’t just compliant, but competitive.

The primary standard ISO 9001 is being updated, and the new version will be available in September 2026. ISO 14001 is already available in the updated version. The update of other standards including the aerospace and other industry standards will follow.  The change to clauses in the updates of the standards is minimal. It means the structure will be same; the emphasis is in the implementation. As organizations move toward ESG (Environmental, Social, and Governance) reporting, having a harmonized ISO 9001/14001 integrated management system (IMS) provides the verified QMS and EMS data needed to back up those high-level sustainability claims.

Then there is the cost saving angle too. Human ROI of systems engineering must be considered. In the world of ISO, we often talk about process efficiency, but we forget that stressed employees are the primary drivers of hidden costs. When a system is fragmented, people are forced to become the glue manually reconciling data, filling out redundant forms, and bracing for audits. That glue is expensive, and eventually, it cracks. There is a need to bridge that connection. Stress drains the bottom line, often termed the friction tax. In a siloed organization, employees pay this friction tax daily perhaps as a decision fatigue when quality and environmental objectives conflict, managers hesitate. Hesitation delays production. Then another one of the common costs is the audit anxiety. If an internal audit feels like a blame game session because the paperwork is a mess, morale drops. Low morale leads to higher turnover and the cost of replacing skilled employees are often twice their annual salary. The need to make double entries wherein technicians must log a chemical spill in the quality log and also in the environmental log. It is not just annoying but a sheer waste of billable hours.

The logic of the harmonized integrated management system therefore provides a clear ROI. Organizations can visualize the connection for example in reduced waste (clause 8.1) where an integrated process ensures that doing it right the first time (quality) also means using only what is necessary (environmental). Less scrap material means lower disposal costs and lower procurement costs.

Leaderships understand the importance of a proactive system. Being predictive is better than a system which is reactive. If the organization is all the time firefighting the stress will be more. A harmonized system uses clause 6.1 (risk management) to prevent fires before they start. It is significantly cheaper to maintain a machine (preventing both a quality defect and an oil leak) than it is to clean up a disaster. Streamlined training is another plus of the harmonized system. By integrating requirements, you reduce the time employees spend in training rooms and increase the time they spend on the value-add line.

The ultimate goal of any management system isn’t to pass an audit. It is to provide a stable platform for the business to grow. When we treat ISO 9001 and ISO 14001 (as also other relevant standards) as separate entities, we inadvertently bake friction into our corporate DNA. We create a system where the left hand ignores the right, and the employees the organization’s most valuable assets, pay the price in stress and burnout. By harmonizing these systems into a true integrated management system (IMS), organizations eliminate the friction tax. Administrative noise is replaced with operational clarity. When a system is integrated, clause 10 (Improvement) ceases to be a chore and becomes a natural byproduct of a focused workforce. In summing up I would say less complexity leads to less stress. Less stress leads to fewer errors. Fewer errors lead to less waste and higher ROI. For those who still view integration as a nice-to-have, remember in an increasingly volatile market, the most successful companies aren’t the ones with the most binders on the shelf they are the ones with the most streamlined, intuitive, and stress-free processes. Integrating ISO 9001 and 14001 isn’t just a technical exercise, it is a commitment to organizational health. When your management systems work in harmony, your people can finally stop managing the system and start managing the business.

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Why your ISO documentation is too complicated and how to fix it?

Documentation is one of the biggest headaches in the compliance world. Many organizations fall into the trap of “writing for the auditor” rather than writing for their own organization, resulting in a mountain of paperwork that nobody actually reads. Paperwork which is not useful or helpful to the organization in achieving the set objectives. Instead of the documentation being an asset for processes it is focused on what will satisfy an auditor. The consultants’ organizations use is often not those who will work from the base line of the organization’s “as-is”. They are in a hurry to collect their fee and fit you into some standard template they have. With forty plus years of experience we at QMII have developed a methodology for the process-based management system approach that starts with capturing the “as-is” of the organization. That way the documentation created remains relevant rather than a template pulled out of the air!

The other issue is wherein companies approach ISO certification with a “more is better” mindset. They believe that if a process isn’t documented in a lengthy clause by clause documentation, the auditor won’t believe it exists. This is most likely reason for a document bloat, a system so heavy it hinders the quality it’s supposed to manage. I have a quote I use nothing kills love, like an overdose of it and nothing kills a management system like overdocumentation. Don’t start with the premise that what your organization has developed over the years needs to be trashed to align your system to ISO 9001 or any of the standards. You want to build on your tried “as-is” system by continual improvement.

The Symptoms of an over-complicated over documentation should be noted. For example, the existence of a parallel shadow system where employees have their own cheat sheets because the official procedures are too hard to follow is an immediate indication of over documentation or useless paperwork. Any SME (subject matter expert) can see another sign where the same information is repeated across several forms. Duplication is an immediate symptom of over documentation. Look for the existence of passive Language. The use of shall and herein and similar legal language makes simple tasks feel like a threat to employees. The other common sign is documentation created for meeting auditor expectations in fear of getting a NC (non-conformity). Fear based writing does not better the management system it just covers all bases. Assists auditors to audit easy. However, the system is not designed for auditors. The management system should be designed for the employees.

The question then is why did it come to this, what is the root cause of complicated often unusable documentation? I think the main reason is the misinterpretation of ISO standards. Neither ISO 9001 nor any of the harmonized standards prescribe or suggest over documentation. The standard actually requires less documented information than previous versions. They focus on effectiveness, not page count. Then there is this tendency in some organizations to keep obsolete procedures as a just in case required syndrome instead of pruning them during updates. At QMII we recommend mapping the processes thus providing a visual representation. However, many organizations have lack of visual representations. These organizations prefer a thousand words long document to describe a process that a simple flowchart could explain in seconds.

Analyzing and knowing these root causes organizations can fix these by adopting a lean documentation strategy. The first step to this end would be to audit the organization’s documents. Before writing anything new, the organization should look at their current list and ask If this document disappeared tomorrow, would the process fail? If the answer is no or even probably not, it’s time to archive it.

Another good solution is to use the Parato 80/20 rule as applicable to documentation. Write for the 80% of daily tasks, not the 20% of rare exceptions. Use clear, active voice. Instead of it is required that the operator shall ensure the calibration is checked replace it with check calibration before starting the shift. Such simple clear active documentation is crisp and short and removes uncertainty from the system. Over documentation often ends in passing risk down the line.

Going visual is another solution. A picture is worth a thousand compliance hours. Replace dense paragraphs with flowcharts for decision-making paths. Design checklists for repetitive tasks where memory might fail. Simple clear photographs are an asset. For example, to show what a good one looks like put a photograph with what a bad one looks like. It will make things clear without overdocumentation.

Most consultant templates are aligned to clauses and often are numbered to the clauses. Sure, it makes it easy for the auditor, but for the user who works using processes, work instructions and check list a clause structured management system is not user friendly. Therefore, map to the user preferences and not to the clause. Don’t organize your folders by ISO clause numbers (e.g., clause 7.5, clause 8.1, clause 8.6 and so on). Employees don’t think in clauses. Organize your documentation by department or workstream so people can find what they need in three clicks or less. Please remember documentation should be a bridge to better performance, not a barrier to getting work done.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Can the PBMS Approach Prepare the Mercantile Marine for Conflict Zones?

This conflict in the middle east and economic and human loss in the Straits of Hormuz has brought the merchant mariner in focus. The mercantile marine since times gone has played such an important role. These are sailors sailing the oceans, perhaps for their livelihood, perhaps for adventure and many such reasons, however this is certain the Columbuses, and the likes of Captain Cook changed the world. Affected the economies. In dangerous times like sailing through a war zone to meet the basic needs of the world, brings challenges. We realize this with the Iran war as we see merchant ships, tankers, bulk carriers, container vessels and the rest in the war zone. Without them the global supply chain stops. Yet how safe are they. Does the world owe them safety, security. Can they themselves as mariner, Masters and ship owners exercise some due diligence?

 For me personally as an ex sea farer who commanded submarines in the  Indian navy and then sailed as a merchant mariner in the mercantile marine as Master and now as a SME (subject matter expert) in maritime safety, security and related issues I felt compelled this morning to see if I could analyze what I hear, read and provide a  mantra whereby maritime industry could better prepare themselves. Does the ISM Code and STCW convention and ISO 9001 with the process-based management system approach as primary standards be used to plan better.

Most of us do not have to deal with such life-and-death decisions as whether to risk transiting the Strait of Hormuz. However, for those who must traverse these waters, are there guidelines they can use.  The ISM Code can provide some lessons into anticipating the unexpected and planning for these risks in a systematic manner. In this article I touch how portions of the Code might connect to elements of ISO 9001 and provide inputs that might be useful to maritime leadership in ensuring quality assurance and conformity assessment based on risk and in the context of the organization.

Let me start with the sinking of the IRIS Dena. I start with this recent incident to convey that warships or mercantile marine, the maritime environment can be best prepared for fast developing circumstances by keeping the process-based management system (PBMS) approach as the basis for all planning. On 4 March 2026, the Iranian Navy frigate IRIS Dena was torpedoed and sunk by a U.S. Navy submarine in the Indian Ocean near the southern coast of Sri Lanka. The vessel sank within minutes after being struck, leaving at least 87 sailors dead and dozens missing, while 32 survivors were rescued by the Sri Lankan Navy. The attack was particularly notable for naval historians. It was reportedly the first time since the second world war that a U.S. submarine had sunk an enemy surface warship with a torpedo[1].

What makes the incident significant for our discussion is not the geopolitics, but the reminder of how quickly circumstances can change at sea. The Dena had recently taken part in multinational naval exercises hosted by India and was sailing in international waters near Sri Lanka when the strike occurred. For professional mariners, the lesson is familiar, conditions that appear routine can change without warning. The ISM Code is not applicable to navy, but is there a harm in understanding the principles? After all this is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations.

Clause 8.1 of the ISM Code requires that the company should establish procedures to identify, describe and respond to potential emergency shipboard situations. The Navies have their own doctrine. Yes, one wonders if risks are systematically appreciated can better decisions be made. In other words, the Code requires organizations to plan not only for technical failures or weather hazards, but also for security risks and unexpected external threats. Sure, a navy may call it an operational assessment, or by any name. Yet (in Shakespearean language) a risk would remain a risk if called by another name. ISO 9001 expresses a comparable idea through the requirement for risk-based thinking. The organization shall determine the risks and opportunities that need to be addressed to give assurance that the quality management system can achieve its intended results as emphasized in ISO 9001:2015, Clause 6.1.1.

From a management systems perspective, the broader lesson is clear. Organizations must plan for situations that may appear unlikely until they occur. For a ship’s captain, that planning may involve security drills, contingency routing, and coordination with naval authorities. For a quality manager or organizational leader, it may involve supply chain disruption, cybersecurity incidents, or geopolitical shocks. Finally, the decision on sailing should be based on the risk assessment. Events at sea sometimes remind us, in stark terms, why disciplined safety and command systems matter. What makes the incident significant for our discussion is not the geopolitics, but the reminder of how quickly circumstances can change at sea as they did for Dena.  

For professional mariners, the lesson is similar and familiar. Conditions that appear routine can change without warning. The context of the organization (ISO 9001 clause 4.1 & 4.2) leading to risk appreciation clause 6.1, must be an integral part of the maritime management system, at sea or ashore. This is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations. The company should establish procedures to identify, describe and respond to potential emergency shipboard situations per ISM Code, Section 8.1. From a management systems perspective, the broader lesson is clear. Organizations must plan for situations that may appear unlikely until they occur. Good organizations connect real maritime events with risk-based thinking, understand that commercial interests apart they must see why emergency planning clauses in ISM are not theoretical and are reinforced by ISO 9001 Clause 6 (Planning) and clause 8 (Operational control).

 My own appreciation for disciplined systems thinking was shaped long before the ISM Code was widely implemented in commercial shipping. During my years in the Indian Navy, I had the privilege of commanding submarines, first F-class boats and later service on a Charlie II submarine. Submarines operate in an environment where uncertainty is not theoretical. The margin for error is extremely small. A failure in equipment, communication, or procedure can quickly become critical. What keeps submarines safe is not individual brilliance on the part of a captain or crew. That too, but most importantly the relentless adherence to procedures and constant preparation for contingencies. Before every patrol, the crew rehearses emergency actions repeatedly as flooding drills, fire drills, loss of propulsion, loss of power. Each crew member knows precisely where to go, what valve to operate, and what sequence of actions must follow. These procedures are not simply written manuals. They are practiced until they become instinctive.

At the time, we did not describe this discipline in terms of “process-based management systems,” but that is exactly what it was. The system existed to ensure that when the unexpected occurred, as it inevitably does at sea. The crew would not rely on improvisation alone. The response would already be embedded in the system. Years later, when I sailed as Master in the merchant marine and later worked with ISO management systems, I recognized the same principle expressed in a different language. ISO 9001 requires organizations to establish, implement and maintain the processes needed for the quality management system and their interactions. Refer ISO 9001 clause 4.4. The ISM Code similarly requires companies to ensure safe practices in ship operation and a safe working environment (ISM Code, clause 1.2). Different industries. Different terminology. But the underlying idea is identical. Safety, quality, and reliability are not the result of reacting well to emergencies.

These thoughts are the result of preparing for them long before they occur. I can confirm with my experience that this reflection is not merely theoretical. It comes from my first-hand experience wherein I  led teams where preparation truly mattered. My background, commanding submarines and later sailing as Master in the merchant marine gives me a clear perspective on risk, command responsibility, and disciplined procedures under uncertainty. This perspective can make a very compelling bridge between maritime safety management (ISM/STCW) and organizational quality systems (ISO 9001).

The connection as we look at the dangerous situations at sea particularly in the Hormuz Staits is to see what the ISM Code and ISO 9001 (as also other maritime and ISO standards) can teach maritime leaders about risk in uncertain times. In today’s volatile world, commercial shipping once again finds itself navigating geopolitical tension. News headlines remind us that vessels may need to transit waters such as the Red Sea or the Strait of Hormuz where the risks are not merely commercial, but they can become matters of safety and survival. For those who have spent a career at sea, such circumstances are not entirely unfamiliar. The maritime profession has long recognized that uncertainty is inherent to operations. Ships sail through storms, equipment failures, and occasionally conflict zones. Yet despite these uncertainties, shipping remains one of the safest and most reliable global industries. This is not an accident. Much of that safety culture comes from the International Safety Management (ISM) Code, supported by training standards such as the STCW Convention. These frameworks provide structured guidance on how organizations anticipate risk, prepare crews, and maintain operational control.

Most professionals in quality assurance or conformity assessment will never face the life-and-death decisions that a ship’s master may face when deciding whether to transit a dangerous waterway. However, the principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

The ISM Code brings a framework for safety through systematic management. The ISM Code was introduced by the International Maritime Organization (IMO) after several major maritime accidents revealed a common problem: the failures were rarely technical alone. They were failures of management systems. The Code therefore established a simple but powerful requirement, wherein shipping companies must implement a documented Safety Management System (SMS) to ensure safe operation of ships and protection of the environment. This requirement may sound familiar to anyone working with ISO management systems. Like ISO 9001 and other standards in the harmonized structure (HS). The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing, leadership responsibility, risk assessment, operational control, training and competence, incident reporting and corrective action and Continual improvement. In essence, the Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

The use of the SMS based on the ISM code and principles of ISO 9001 ensures planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, man overboard and or security threats or piracy (maritime security is covered by the ISPS Code and ISO 28001). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised. In essence, the Code recognizes a fundamental truth that the safe operations are the result of disciplined management systems, not individual heroics.

Planning for the unexpected is one of the most relevant principles in the ISM Code. There is the requirement to identify potential emergency situations and establish procedures to respond to them. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised. Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate the unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of asking what could go wrong, how prepared are we, do people know their roles if it does?

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. ISM Code clause 5.1 and 5.2 seen with ISO 9001 Clause 5.1 and 5.3, require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The Master has the overriding authority. At the same time, the Code requires the company ashore to support the Master through a defined role known as the Designated Person Ashore (DPA) clause 4 of the ISM code. This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles, authority must match responsibility and top management must remain connected to operational realities. ISO 9001 expresses the same idea in a different context. Leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

Competence and training in case of the mariners are systematized. The STCW Convention (Standards of Training, Certification and Watchkeeping) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon ship drills, and damage control exercises are conducted not because emergencies are frequent, but precisely because they are rare and high consequence. This principle translates directly into quality management, competence is not merely about qualifications, it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from Incidents (ISO 9001 clause 7.1.6) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of non-conformities, accidents, and hazardous occurrences. The purpose is not blame, but learning. Each incident becomes an opportunity to ask, what failed in the system, what corrective action is needed, how do we prevent recurrence? Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about the decision a shipping company might face today whether to transit a high-risk region such as the Strait of Hormuz. The decision is rarely simple. It requires balancing safety risks, commercial pressures, regulatory requirements including daily changing statutory requirements of various contracting governments specially those controlling the war zone. This must be seen with the operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk. They provide a framework for making better decisions about risk.

A war zone has much to be learnt from. Nevertheless, quality professionals can use their learning based on their use of the system approach by considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons. Systems matter more than individuals and therefore, competent people are essential, but reliable operations depend on structured systems. Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away from top management. The leaders must prepare for rare but high-impact events risk management is not only about what happens frequently.  Practice builds readiness. Training and drills ensure procedures work under real conditions. Therefore, the need to learn relentlessly from failure, use nonconformities as opportunities to strengthen the system. Management systems do not eliminate risk. They provide a framework for making better decisions about risk.

Navigating uncertainty strengthens the need to see what the ISM Code can teach leaders about risk and process management. These geopolitical tensions bring to maritime organizations the need to reassess risks faced by commercial shipping. Headlines remind us that vessels may transit waters such as the Red Sea or the Strait of Hormuz under heightened threat conditions. For ship owners and masters, such decisions require a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Occasionally they must also consider security threats or conflict zones. Yet despite these uncertainties, global shipping remains remarkably reliable. Over 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

These small but essential thoughts from the ISM Code are the philosophy to success in challenging times, “Every company should develop, implement and maintain a Safety Management System (SMS).”  Refer ISM Code, clause 1.4 and the definition of the SMS as a, structured and documented system enabling company personnel to effectively implement the company safety and environmental protection policy, as per ISM Code, clause 1.4. Both standards recognize that outcomes, whether safety or quality depend on well-defined processes and leadership oversight.

To the mariners in the straits or those intending to cross the war zone, relook at your management system. Strengthen it. Maritime leadership ashore should stay involved in assessing risks to give the best shot at safety.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

 

The Hidden Signals of Process Breakdown

When implementing management system, the organizations are really not trying to reinvent the wheel.  The availability of ISO standards gives us a well tried, over the years updated approach in terms of the available clauses. The PDCA (plan, do, check and act) cycle approach in the harmonized standards enables designing an effective management system, monitoring it and updating it to not just produce confirming products and services but also to use inputs at the check stage to continually improve it. Yet the systems fail. Non-conforming products are released. Is there then an anatomy of a quiet failure? Indicators that will enable discovering these signals proactively. If that can be analyzed organizations would appreciate these hidden signals of the system breakdown and take proactive measures. Risks and trends are data driven. Can we expect our auditors to proactively recognize these.

There is the lagging indicator trap between being reactive and proactive. Up to the 2015 version of ISO 9001 (and equivalent industry specific standards in the harmonized structure) preventive action was taken based on data, invariably at the act stage of the PDCA cycle. From the 2015 version onward clause 6.1 introduced the risk appreciation requirement at the plan stage itself and then throughout the work cycle. Separating knowledge (clause 7.1.6 of ISO 9001) from competence (clause 7.2 of ISO 9001), has introduced us to corporate knowledge in terms of lessons learnt. Leadership in analyzing changing context and risk thereof should be on the lookout for indicators.  Therefore, the PA (preventive action) concept needed a change to risk. The idea was not to throw the baby with the bathwater. NC (non-conformity) did drive correction and CA (corrective action), however, as the organization collected data it became proactive wherein data drives risk and trends. Waiting for a nonconformity (NC) is a reactive strategy. Therefore, organizations should not be we waiting for NCs. By the time an NC appears, the financial or quality damage is already done. Being proactive therefore, is the need of a functioning system.

With the ISO 9001 revised 2026 version expected in September 2026 there is, quite correctly the need to strengthen the check stage. The organizations will expect better auditing instead of just a check list being completed. The auditor’s sixth sense to ask better questions and to establish how the system is working will be important. Just having a frame and expecting it to do magic and pinpoint failures of the system is not sufficient, but the need is for a high-level pattern recognition. The skilled auditors look for the erosion of intent, where the way work is done drifts away from how it was designed. They need is to provide these inputs during audits to the leadership.

For the organizations and the auditors there are many signals of this hidden failure. There is the tribal knowledge drift as recognizing the symptoms, where the question is: “how do you do XXX?” and the employee reaches for a handwritten sticky note or a personal notebook instead of the official SOP (standard operating procedure). The hidden meaning here is that the official process is likely too rigid, outdated, or inaccessible. This is indicative of a workaround culture in its infancy. Then there is the risk scalability. The process lives in heads, not in the systems. This is indicated by when those people leave, the process collapses. Technically it was not a system. The system instead of being a working process was dependent on individual competence.

Good auditors are conscious of another signal indicated by the language used and the linguistic friction. The Symptom here is in phrases like “we usually just…”, or “on a good day, we…”, or “that’s just how we have to do it.” In these and similar cases the hidden meaning is indicating to the organization and to the auditors that the standard process is no longer the path of least resistance. For a good auditor the clue is the hesitation or glance-exchanges between team members when answering simple procedural questions. Looking ahead at expectations of the ISO 9001, 2026 version of the standard the auditors need to be conscious of how the system is actually working, working or not working.

The next signal to watch out for could be the ghost workload (shadow processes) indicated by the excessive use of excel trackers to manage data that should be in the ERP/QMS, or the need for frequent offline meetings to fix recurring errors or the use of tiger teams to cover the back log. The hidden meaning of this should be clear. The formal system is failing to provide the necessary utility. Also, that the risk is not being proactively data driven. Data integrity and lack of visibility by the management leads to the leadership  seeing a green dashboard, when the reality is red and it is showing a mirage of being held together by manual labor.

Related to this is the physical and digital clutter. The clear symptom of this e.g.  in a physical plant, it’s unlabeled bins or “red tag” areas that haven’t moved in months. In a digital space, it’s numerous versions of the same document with names like final_vrn2_use_this.pdf. etc. The implication of this is the loss of 5S discipline (sort, set in order, shine, standardize, sustain). Clutter is a visual representation of a mind and of a process that has lost its focus.

Good auditors must also consider the human element and its connected emotional cues like the defensiveness vs. transparency conflict. If a process owner is overly protective of their territory, they are often hiding a breakdown they don’t know how to fix. It can also be a conflict between fatigue and apathy leading to when and why? This is answered with rationalization, because that’s the rule, the connection between the task and the value (quality) has been severed.

My concluding thought is to prepare for implementation of ISO 9001:2026 (expected in September 2026). In preparing understand that the auditors should be becoming proactive auditors. They need to shift the goal and change their attitude. The goal isn’t to catch people; it’s to catch the process before it fails them and therefore the organization. The value add is that a skilled auditor saves the company money by identifying these frictions before they turn into a notice of inspection by a statutory body, a client, a recall, or a lost certification. Organizations should expect their auditors to catch these hidden signals of process breakdown timely and report them. A good audit report should include these and this should be the expectation.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Auditing Risk Management: How Experienced Auditors Identify Risks That Aren’t Listed in the Risk Register.

Organizations today rely heavily on risk registers to track and manage potential threats. Risk registers are useful tools, and they document known risks, assess their likelihood and impact, and assign ownership for mitigation actions. They help leadership visualize risk exposure and provide a structured way to prioritize responses.

However, risk registers have their limits. Experienced auditors know something critical, that the most damaging risks are often the ones that never appear in the register. A risk register represents what the organization already knows or believes it knows. The context of the organization changes. A risk register reflects the thinking of the team that created it. But risks evolve, environments change, and assumptions become outdated. As a result, relying solely on the documented register can create a false sense of security. Seasoned auditors understand that their responsibility goes beyond verifying that risks are listed and mitigations are documented. Their deeper role is to identify blind spots and record risks that exist outside the documented system. This is where experience, professional skepticism, and systems thinking become essential. Skilled auditors recognize patterns, inconsistencies, and subtle signals that indicate hidden risks. QMII specializes in risk and with our forty plus years in the system field, in this article, we explore how experienced auditors uncover risks that never make it into the risk register and why this capability is essential for effective risk management.

The questions therefore are, why risk registers miss critical risks. I think, before examining how auditors uncover hidden risks, it is important to understand why risk registers are incomplete.

Risk registers reflect perception and often not the reality. Risk registers are typically compiled during structured workshops or periodic reviews. Participants identify risks based on their knowledge and experience. But human perception is limited. People tend to list:

  • Risks they have seen before.
  • Risks that are already familiar.
  • Risks that are easy to articulate.

But unfamiliar or emerging threats often remain invisible. For example, a manufacturing team might focus heavily on supply chain delays while overlooking risks related to cybersecurity vulnerabilities within their operational technology systems. Experienced auditors recognize this limitation and therefore treat the risk register as a starting point, not the final word.

Then there is the organizational bias which influences risk Identification. Risk registers can be influenced by internal politics or cultural pressures. Some risks may be downplayed because:

  • They reflect poorly on leadership decisions.
  • They expose systemic weaknesses.
  • They challenge existing strategies.

In such cases, risks may be intentionally or unintentionally omitted. Auditors who understand organizational dynamics pay attention not only to what is documented, but also what is missing.

Please also consider that risks often evolve faster than documentation. The modern risk landscape changes rapidly due to:

  • Technological advancements.
  • Regulatory changes.
  • Market disruptions.
  • Geopolitical instability.

Risk registers are often updated annually or quarterly. But emerging risks can develop far faster than review cycles. Experienced auditors therefore examine current conditions, not just documented assessments. The experienced auditors detect unlisted risks. The difference between routine auditing and expert auditing lies in how auditors think. Experienced auditors do not simply verify compliance. They analyze systems, behaviors, and signals that reveal underlying vulnerabilities. The ISO 9001 version expected in September 2026 expects organizations to go beyond check lists and see how their system works to produce confirming products and services.  The auditors of the future must work to providing these inputs. Several approaches distinguish their work.

The primary is developing the attitude and aptitude where the auditors look for process weaknesses, not just risk entries. Experienced auditors start by examining processes rather than documentation. Instead of asking: “Is this risk listed in the register?” They ask: “Where could this process fail?” Every process contains inherent vulnerabilities. Skilled auditors identify points where failure could occur, including:

  • unclear responsibilities.
  • lack of monitoring.
  • excessive reliance on manual steps.
  • insufficient controls.

For example, if a company relies heavily on one individual to approve high-value financial transactions, an auditor immediately recognizes concentration of authority risk, even if the risk register never mentions it. In other words, auditors uncover risks by studying how work actually happens.

Observing operational reality is another positive trait in an auditor. Documentation often describes how processes are supposed to work. But experienced auditors know that actual practice frequently differs from documented procedures. They therefore observe operations directly by speaking with frontline staff, watching processes in action and asking open-ended questions. These conversations often reveal informal workarounds, shortcuts, or unofficial practices that introduce risk. For instance, employees might bypass a cumbersome control procedure to meet production deadlines. While the process appears compliant on paper, operational reality tells a different story. This gap between documented procedure and actual practice often exposes hidden risks.

Auditors can add value by providing inputs in audit reports which connect risks across functions. Risk registers are frequently organized by departments. Each function identifies its own risks independently. But real risks often emerge between functions, where responsibilities intersect. Experienced auditors look for these interdependencies. Examples include IT changes affecting operational reliability, procurement decisions impacting regulatory compliance or sales commitments creating financial exposure and so on. When risks are examined in isolation, these connections may never be recognized. Auditors with systems thinking identify risks that arise from interactions between processes.

Another useful tip I could share with auditors would be to learn the art of questioning assumptions. A hallmark of experienced auditors is professional skepticism. They challenge assumptions that others take for granted. Common assumptions include:

  • “This control has always worked.”
  • “That vendor is reliable.”
  • “This system cannot fail.”

History repeatedly shows that risks often emerge when organizations become overly confident in their controls. Complacency is in itself a risk. Auditors therefore test assumptions by asking questions as, what happens if this control fails? Or what alternative scenarios could occur? Or perhaps, what early warning signs might exist? This mindset helps auditors uncover risks that have never been formally considered.

Identifying early warning signals should be the organizations’ role. However, it is often missed as the organization gets acclimatized to it. Hidden risks rarely appear suddenly. They often produce early signals which even if missed by the organization can be observed by the experienced auditor. These signals may include:

  • recurring minor incidents.
  • increasing process delays.
  • rising customer complaints.
  • frequent control overrides.

Individually, such signals may appear insignificant. But collectively, they may indicate deeper systemic risks. Experienced auditors are trained to recognize these patterns. They understand that small anomalies often precede major failures.

Therefore, the role of auditor experience is vital. Technical knowledge alone does not enable auditors to detect hidden risks. Experience plays a critical role. Experienced auditors develop several capabilities over time for example their ability to see a pattern recognition. Years of exposure to different organizations allow auditors to recognize patterns that others miss. They may recall similar conditions that led to failures in other organizations and apply those lessons proactively.

Systems thinking is another quality experienced auditors possess. They may be auditing a few selected processes in a particular audit; however, the system perspective must be kept in mind. Experienced auditors understand organizations as interconnected systems. They see how decisions in one area influence outcomes in another. This perspective helps them identify risks that arise from system complexity rather than isolated failures.

Experienced auditors have judgment and intuition. They know that while auditing they must remain evidence based.  Seasoned auditors also develop professional intuition. We are not recommending experience as the basis for audit decisions. Requirements should remain the primary basis. Yet this intuition arises from accumulated experience and allows auditors to recognize subtle indicators that something may be wrong, even when documentation appears complete. They therefore ask questions to unearth hidden risks.

Strengthening risk management through auditing is a desirable trait. When auditors identify risks outside the risk register, they provide tremendous value to leadership. Their insights help organizations:

  • identify emerging threats earlier.
  • improve risk identification processes.
  • strengthen internal controls.
  • enhance organizational resilience.

Most importantly, they shift risk management from a static checklist to a dynamic learning process. Organizations that encourage auditors to explore beyond the register benefit from more realistic and proactive risk oversight. Auditors must start moving beyond the checklist mindset. In some organizations, audits become overly focused on verification. Inexperienced auditors tend to look at questions in terms of, is the risk listed or is the mitigation documented or is the review completed? While these checks are necessary, they represent only the baseline of effective auditing. Experienced auditors move beyond checklist thinking by asking deeper questions:

  • What risks might exist that we have not yet identified?
  • Where could the system fail under stress?
  • What assumptions might be wrong?

This shift transforms auditing from a compliance exercise into a strategic capability.

In conclusion I would opine an experienced auditor is like a risk detective. Risk registers remain valuable tools. They provide structure, accountability, and visibility into known risks. But they cannot capture every emerging or hidden threat. That is why experienced auditors play such a crucial role in risk management. By observing operations, questioning assumptions, connecting systems, and recognizing subtle warning signs, skilled auditors identify risks that others overlook. In many cases, their ability to detect these hidden risks prevents costly failures long before they occur.

Ultimately, the most effective auditors behave not just as compliance reviewers, but as risk detectives who are constantly searching for what the organization has not yet seen.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.