Why Most ISO Audits Miss System Failure Signals – And How Experienced Auditors Detect Them

I have always valued the process-based management system (PBMS) approach based on the ISO standards as the best start to designing and implementing a management system that produces confirming products and services. Over time with continual improvement the system should give the ROI (return on investment). The management system is not a magic trick, agreed, it all depends on the implementation. The system starts in a responsive manner where NCs (non-conformities) drive correction and CA (corrective action). The system then matures and becomes proactive when data drives risk and trends. The internal audits should give the leadership the inputs to better resource and continually improve the system.  Yet I see organizations end up with a “checklist-style” audit where these frustrating audits do not provide the inputs to improve the system. It is often because audits treat a living system like a static inventory. Most audits miss signals because they focus on conformity (did you do what you said?) rather than capability (does the process achieve the intended result?). The intend should be to bridge the gap between “compliance” and “performance.”

The illusion of compliance pays the price. Most ISO audits fail to detect systemic rot because they are designed to find missing records, not broken logic. That is because auditors fall into the checklist trap. Standard auditors often follow a linear path. If the “management review” happened and the minutes exist, they check the box. Then there is the “paper thin” system where organizations have become experts at “audit-ready” documentation that masks operational chaos. Finally, the auditors focus on output and not on outcome during the audits, they often verify that a process ran but fail to ask if the process is healthy.

The question then is why the “signals” are missed? System failures rarely happen overnight; they emit “smoke” long before the fire. Standard audits miss these because:

  • Siloed Auditing: Auditors look at Department A and Department B separately, missing the friction and “white space” between them where most failures occur.
  • Sampling Bias: Auditors often let the guide choose the records. Experienced auditors know that the most telling data is usually in the “messy” folders the guide is trying to steer them away from.
  • Metric Manipulation: If a KPI is 99% green but the customer is complaining, the system is failing. A standard audit sees the 99% and moves on.

Therefore, the need is to see how experienced auditors “hear” the system. Veteran auditors move beyond the “what” and the “where” to the “how” and the “why.” They use a PBMS lens to detect:

  • The “work-around” signal, when employees have a “shadow” spreadsheet or a personal notebook to get the job done, the formal system has already failed.
  • The “quality debt” signal where recurring “minor” non-conformities are often symptoms of a single “major” systemic bypass.
  • Language patterns when experienced auditors listen for phrases like “we usually do it this way, but for the audit…” or “that person is the only one who knows how that works.”

The need is for auditors to transition from “auditing for points” to “auditing for risk”. To truly add value, the audit must evolve into a diagnostic tool.

  • Vertical vs. horizontal auditing where instead of checking a department, follow a single order from “quote to cash” to see where the process bleeds.
  • The “stress test” approach where auditors ask, “what happens if this person is out?” or “what happens if this supplier fails?” to test system resilience.

The key takeaways so far could be summarized as:

  • The process is the patient. Treat the audit like a medical check-up. Don’t just check the pulse; look at the lifestyle and the underlying vitals.
  • Stop re-inventing, start refining.  Since you believe in standards, emphasize as an auditor, that the ISO standards already require a process approach. Most people just ignore it in favor of the easier “clause-by-clause” approach.

As an example, we can consider a perfect paper audit that is followed by a major product recall, as indicative of illustrating the compliance-performance gap. The occurrence of a mishap, or a rejected product soon after a perfect audit should make an organization investigate its auditing effectiveness. It is necessary to take the great deep-dive and shift the focus from “did they follow the process?” to “is the process actually functioning?” is what separates a tick-box auditor from a system specialist.

In a standard audit, if the records are signed and the dates match, the process is marked “effective.” But experienced auditors know that a perfectly documented process can still be a failing one. To detect the signals most miss, you must look at the friction points the places where the “official” system meets human reality. Avoid the Illusion of compliance. In the world of ISO standards, there is a dangerous comfort in a “clean” audit report. As a specialist in process-based management systems (PBMS), I have always believed in the power of standards. Why re-invent the wheel when a global framework for excellence already exists? Yet we see it constantly: organizations pass their surveillance audits with flying colors, only to suffer a catastrophic service failure, a massive product recall, or a sudden dip in profitability weeks later.

In conclusion I would caution organizations, audit clients and auditors to stop auditing the paper, and to start auditing the pulse. If we continue to treat ISO audits as a “pass/fail” hurdle for a certificate, we do a disservice to the discipline of management. A standard is not a ceiling; it is a floor. It is the “wheel” that shouldn’t be re-invented, but it must be maintained, balanced, and aligned.

Any organization’s call to action may be called the “value-add” challenge where the organization changes the lens for the next audit cycle to:

  • Ditch the clause-by-clause audit to follow a single order from “quote to cash” rather than checking department folders.
  • Search for the “shadows” and look for the post it notes and cheat sheets. They show you where the formal system is failing to support the staff.
  • Ask “why” Five times to root cause the system. Refuse to accept “human error” as a root cause. Dig until you find the process flaw. Blaming is easy but not the answer.

The goal of a Process-Based Management System is to create a resilient, predictable, and scalable organization. Let’s stop auditing for compliance and start auditing for capability. At QMII we train our auditors for this.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Audit Focus Areas Under ISO 28000 for 2026 (and Beyond)

-by Dr. IJ Arora

In this article on ISO 28000:2022, “Security and resilience—Security management systems—Requirements,” I want to emphasize the audit focus areas for the standard, based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. This focus will allow organizations registered to the standard to go from mere compliance to resilience, leading to more secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this past year exposed an uncomfortable truth: Many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Organizations should not wait for audits to ensure continual improvement, act on risks, and explore opportunities for improvement. However, the fact of the matter is that nonconformities drive corrective actions. As such, audits play a minor part in providing inputs at the check stage of the plan-do-check-act (PDCA) cycle. The question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

Lessons learned

Audits in 2025 outlined the audit focus areas that will define credible, value-adding ISO 28000 audits going forward. Following are four key audit lessons learned.

Lesson 1: Risk assessments were static in a dynamic threat environment

Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. Although these assessments were often well-structured and aligned with ISO 28000’s clause 4, “Security risk assessment and planning,” they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

Lesson 2: Limited visibility beyond tier 1 suppliers

A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in tier 2 or tier 3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

Lesson 3: Cyber risks were poorly integrated into supply chain security

Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. The use of the harmonized structure presumed that an integrated management system approach could answer this, but organizations did not generally integrate ISO 27001 and ISO 28001 with ISO/IEC 27001:2022, “Information security, cybersecurity and privacy protection—Information security management systems—Requirements.”

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

Lesson 4: Business continuity planning lacked supply chain realism

Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301:2019, “Security and resilience—Business continuity management systems—Requirements.” However, audits in 2025 showed that supply chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Actions to consider

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider the following five actions.

Action 1: Going from risk identification to risk intelligence

From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. Clause 4 of ISO 28000, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:

  • The use of internal and external intelligence sources
  • Defined triggers for risk reassessment
  • Evidence that changes in risk lead to timely management action

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

Action 2: Supplier security assurance, not just evaluation

ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:

  • Supplier segmentation and prioritization
  • Proportionate security controls
  • Evidence of supplier audits, self-assessments, or performance reviews
  • Corrective action and escalation when requirements are not met

Supplier security must be demonstrable and sustained, not assumed.

Action 3: Integration of cyber and physical security controls

Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:

  • Identification of cyber-enabled supply chain risks
  • Coordination between security and IT incident response
  • Protection of logistics data, tracking systems, and access controls

Although ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

Action 4: Testing, exercises, and demonstrated preparedness

In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:

  • Scenario-based exercises relevant to the organization’s supply chain
  • Participation by relevant internal and external stakeholders
  • Lessons learned and system improvements following exercises

Preparedness is best demonstrated through practice, not paperwork.

Action 5: Governance and leadership accountability

A notable trend emerging from late 2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:

  • Management review outputs related to supply chain security
  • Resource allocation decisions
  • Evidence of board or senior leadership awareness of key risks

Implications and conclusions

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are twofold.

First, for auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.

Second, for organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion, I would say 2025 taught us that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity—they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

Above article was recently featured in an Exemplar Global publication – ‘The Auditor’.

Audit Focus Areas Under ISO 28000 for 2026 and beyond

In this article on ISO 28000 I want to emphasize the audit focus areas based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. The emphasis is from mere compliance to resilience leading to secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this period exposed an uncomfortable truth, many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Agreed organizations must not wait for audits to ensure continual improvement, act on risks and to use the opportunities for improvement (OFI). However, this too is true that NCs (nonconformities) drive correction and CA (corrective action). As such audits play a minor part in providing inputs at the check stage of the PDCA (plan-do-check-act) cycle. Therefore, the question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

This article reflects on what audits in 2025 revealed and outlines the audit focus areas that will define credible, value-adding ISO 28000 audits from 2026 onwards. Let us first dwell on what 2025 taught the industry and look at the key audit lessons:

  1. Risk assessments were static in a dynamic threat environment. Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. While these assessments were often well-structured and aligned with ISO 28000 Clause 4 (Security risk assessment and planning), they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

  1. Limited visibility beyond tier-1 suppliers. A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in Tier-2 or Tier-3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

  1. Cyber risks were poorly integrated into the supply chain Security. Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. With harmonized structure (HS) it was presumed that an integrated management system approach could answer this but organizations did not integrate ISO 27001 and ISO 28001 by and large.

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

  1. Business continuity planning lacked supply chain realism. Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301 (Business Continuity). However, audits in 2025 showed that supply-chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider:

  1. Going from risk identification to risk intelligence. From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. ISO 28000 Clause 4, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:
  • The use of internal and external intelligence sources.
  • Defined triggers for risk reassessment.
  • Evidence that changes in risk lead to timely management action.

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

  1. Supplier security assurance, not just evaluation. ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:
  • Supplier segmentation and prioritization.
  • Proportionate security controls.
  • Evidence of supplier audits, self-assessments, or performance reviews.
  • Corrective action and escalation when requirements are not met.

Supplier security must be demonstrable and sustained, not assumed.

  1. Integration of cyber and physical security controls. Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:
  • Identification of cyber-enabled supply chain risks.
  • Coordination between security and IT incident response.
  • Protection of logistics data, tracking systems, and access controls.

While ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

  1. Testing, exercises, and demonstrated preparedness. In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:
  • Scenario-based exercises relevant to the organization’s supply chain.
  • Participation by relevant internal and external stakeholders.
  • Lessons learned and system improvements following exercises.

Preparedness is best demonstrated through practice, not paperwork.

  1. Governance and leadership accountability. A notable trend emerging from late-2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:
  • Management review outputs related to supply chain security.
  • Resource allocation decisions.
  • Evidence of board or senior leadership awareness of key risks.

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are:

  1. For auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.
  2. For organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion I would say, based on QMII experience that what 2025 has taught us is that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity, they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

AS9100 for Tier-2/3 Suppliers: Minimum-Viable Risk & Special Process Control Without Gridlock

AS 9100 is applicable to any organization as a choice but is often a business demand. Aerospace is a vast field and has major and minor players. Does it therefore imply that tier 2 and tier 3 suppliers should go through the same documentation burden as a primary aerospace organization? This is a dilemma faced by tier 2/3 suppliers. I have often thought about this. This short article based on QMII experience is specifically written for AS9100 Tier-2/3 Suppliers and how they can maintain the balance between control and still maintain agility and meet the requirements of the standard.

Tier-2 and Tier-3 aerospace suppliers face a unique dilemma, the need to meet AS9100’s rigorous expectations while working with limited resources and tight delivery schedules. Customer flow-downs, documentation demands, and special-process scrutiny can quickly overwhelm small teams. The key challenge is achieving effective control without unnecessary bureaucracy, preserving the agility that keeps smaller suppliers competitive. This special article is aimed at this need of the tier 2/3 suppliers.

The supplier’s challenge in aerospace quality comes from the aerospace customers bringing layers of requirement complexity, unique quality clauses, FAIR specifics (First Article Inspection Report, and the broader process called First Article Inspection (FAI), special-process certifications, customer portals, and documentation formats. These customer-specific expectations often exceed the base AS9100 standard and force Tier-2/3 suppliers to interpret, prioritize, and integrate a landscape of varied demands. Without a structured approach, they risk creating bloated systems that satisfy auditors on paper but hinder production flow.

Understanding AS9100 Clause 8 – operational controls is therefore essential. Clause 8 is the operational heart of AS9100, setting expectations for planning, process control, risk mitigation, and configuration management. It emphasizes that conformity comes from effective planning and controlled execution, not from sheer volume of documents. Suppliers must ensure that personnel have the right information at the right time, that processes are validated where outcomes cannot be fully verified after the fact, and that changes are managed with discipline. For small suppliers, the goal is implementing these controls proportionally to risk, not copying OEM (original equipment manufacturers)-level tier 1 systems.

Minimum-Viable Risk (MVR) must be considered as a pragmatic interpretation of AS9100. AS9100 demands risk-based thinking, but many small suppliers interpret this as “more forms” instead of “better decisions.” MVR provides a method to match controls to actual consequences. It prevents systems from becoming document-heavy while maintaining the safeguards needed for aerospace.

Basic MVR principles include:

  1. Identifying what can truly go wrong (escape, defect, missed requirement).
  2. Assessing the severity of consequence.
  3. Matching control strength to risk severity—not habit or tradition.
  4. Eliminating duplicate or ritualistic checks.
  5. Documenting the rationale for proportional controls.

MVR (monitoring, verification, and reporting) is simplicity with discipline and is the heart of AS9100 done well. It includes applying MVR to special processes without gridlock. Special processes, like welding, heat treat, coatings, NDT (nondestructive testing), bonding pose inherently higher risks because results cannot be fully verified after production. However, small suppliers can maintain strong control without drowning in paperwork. They should control inputs, not layers of signatures. Validate equipment capability, freeze key parameters, ensure personnel competency, and maintain controlled settings. Excess signatures do not improve quality, controlled inputs do.

The tier 2 and 3 suppliers should build process ownership. Escapes in special processes usually stem from incorrect settings, outdated drawings, or tribal knowledge. An escape is a defect that leaves your organization and reaches the customer. A single-point accountability model, owned by the welding lead, NDT supervisor, or coating tech reduces error pathways better than multiple inspectors. Also, use of one-page critical parameter sheets condenses travelers into one-page sheets listing key variables, limits, and required verifications. This approach focuses on what actually matters to conformity.

Another important organizational priority of tier 2/3 suppliers (AS 9100 clause 4.4.1) is to right size the QMS to their risk level. AS9100 allows flexibility, and small suppliers should embrace it. Not every process requires the same level of documentation, inspection, or validation.

  • Low-risk machining or simple assembly can rely on straightforward checks.
  • High-risk special processes need tighter controls, but not excessive forms.
  • Different supplier tiers have different expectations; Tier-3 machining houses need far less documentation than Tier-1 system integrators. 
  • A right-sized QMS is efficient, compliant, and scalable.

Then there is the use of practical supplier evaluation methods. Supplier oversight does not have to involve 12-page questionnaires or annual onsite audits. AS9100 encourages objective, data-driven oversight:

  • On-Time Delivery (OTD).
  • NCR (non-conformity report) and escape trends.
  • Responsiveness to containment.
  • Corrective action effectiveness.

This approach is more reliable than generic forms and lets purchasing focus on high-risk, high-impact suppliers.

 

Then there are the common audit weaknesses in tier suppliers. QMII’s audit experience reveals recurring issues across Tier-2/3 organizations:

  • Manuals copied from templates that do not match actual practice.
  • Weak configuration control, especially in revision management.
  • Inconsistent traceability in special processes and outsourced steps.
  • Internal audits that check boxes instead of evaluating system effectiveness.
  • Training records that prove attendance but not competency.
  • Excessive documentation without actual operational control.

These weaknesses stem not from lack of effort, but from systems that were built to “pass audits” rather than ensure reliability.

Using MVR to reduce escapes and customer returns. Most escapes involve incorrect flow-downs, poor configuration management, or over-reliance on manual documentation. MVR shifts focus from detection to prevention, reducing escapes by simplifying controls and strengthening process discipline. Early requirement clarification, targeted training, and controlled process inputs all contribute to fewer customer complaints and more predictable performance.

As an example, perhaps a recommendatory timeline from QMII for consideration could be for a Tier-2/3 implementation blueprint (90 Days) would be three phased. Phase 1 – Diagnose (Weeks 1–3).  Map critical processes, identify friction points, and assess risk using MVR. In Phase 2 simplify (Weeks 4–8), streamline travelers, create one-page control sheets, and combine competency and training logs. Finally in Phase 3 – reinforce (Weeks 9–12), clarify process ownership, audit for effectiveness, and pilot new controls. This, I think, builds a lean, compliant AS9100 system with predictable output.

In conclusion and as a call to action I would say a streamlined, risk-aligned AS9100 system allows Tier-2/3 suppliers to maintain compliance without sacrificing agility or productivity. By matching control depth to risk, strengthening special-process discipline, and using data-driven supplier monitoring, organizations can reduce escapes, satisfy customers, and maintain competitive flow.

For suppliers looking to strengthen their capability, QMII offers AS9100 auditor training that emphasizes process-based auditing, practical system improvement, and real-world risk management—equipping teams to build QMSs that are both compliant and efficient.

Procedure, Work Instruction, or Flowchart?

-by Dr. IJ Arora

The choice between writing a procedure or a work instruction is an essential decision when designing a management system. Clause 4.4.1 of ISO 9001:2015 (as well as all the ISO management system standards using the harmonized structure) requires the establishment and implementation of a management system. This management system will have procedures and work instructions and further down the hierarchy, checklists and forms.

Processes can be actualized in many forms. Today, mapped processes make it easy to visualize the functioning of the process. This is an important distinction in quality management systems based on ISO 9001—or for that matter any sector-specific standard like those dedicated to management within maritime, aerospace, etc. Many organizations struggle with when to write a procedure, when to write a work instruction, and how and when a flowchart should be used.

I think the core difference between a procedure and a work instruction is that a procedure answers the question, “What happens and who does it?” A procedure defines the process, its purpose, its sequence (clause 4.4.1b), and who is responsible for the work, perhaps as process owners (clause 4.4.1e). It answers what is to be done, when it must be done, who is responsible, and why it matters. The flowchart then helps visualize the inputs and outputs that flow between the steps.

What is a procedure and how it is used?

A procedure does not tell someone how to do a task; it simply describes the steps or stages necessary to accomplish it. I think of the procedure as the blueprint of the workflow. Therefore, I would recommend using the procedure when multiple people or departments are involved, when there is decision-making or sequencing, when the process crosses functional boundaries, and when documenting the process supports consistency, audits, or training. The procedure is also best when regulatory bodies expect clearly defined processes.

What is a work instruction and how is it used?

On the other hand, a work instruction shows stakeholders how exactly a task is to be accomplished. A work instruction “goes into the weeds” to the extent required by the workforce (depending on their confidence, competence, knowledge, and so on). It describes specific methods, often at a deep level of detail. It answers questions such as:

  • “How do I perform this task?”
  • “What tools, equipment, settings, forms, and/or software steps are required?”
  • “What are the acceptance criteria?”
  • “What do I check and how do I measure performance?”

Remember, work instructions are intended to be simple, direct documents for use by the workforce. Use them when:

  • A task requires technical, step-by-step details
  • Training new personnel
  • Incorrect execution can create quality or safety risks
  • Standardization is essential
  • Variation in execution must be eliminated

What is a flowchart and how is it used?

Flowcharts can technically be used to support both procedures and work instructions, but I generally recommend their use in conjunction with procedures. This helps make the procedure visual by mapping the 50,000-foot view of a process. A flowchart is ideal when the process has multiple decision points, parallel paths, several departments interacting, and inputs/outputs that must be made clear. The flowchart helps avoid the confusion that can come when procedures are described in long paragraphs. Flowcharts make complex processes easy to understand immediately. I therefore believe in flowcharting a procedure when the process needs high-level clarity, the sequence matters, when an organization wants to show interactions between departments, when it supports risk-based thinking, and when you want to simplify training for new personnel.

Flowcharts work best for document control, non-conformances, and corrective action processes, purchasing and supplier management, production scheduling, quality inspection, and testing flows and change management processes (as seen in clauses 5.3e, 6.3., 8.2.4, 8.3.6, and 8.5.6). Flowcharts do not replace work instructions; they complement them.

Final thoughts

To sum up how these tools work together, the practical document hierarchy an organization could consider starting with policy (and why that policy exists), move into documenting the procedure (preferably supported by a flowchart) to convey what happens and in what order, and then crafting work instructions to clarify how to carry out specific tasks. Finally, document everything through records and forms to provide evidence that the work was performed.

All this should connect as a system where a flowchart procedure should describe the process, a work instruction explains each critical task, and the documented information provides traceability. Performance monitoring (clause 9) can be documented via procedures, work instructions, and flowcharts.

 

Note – The above article was recently featured in an Exemplar Global publication ‘The Auditor’. 

ISM Code to Bridge the Shore – Ship Gap: Making SMS a Living System

I take pride on my experience as I work with our maritime clients emphasizing the personal perspective from both below and above the surface of this ocean. My view of the ISM Code is shaped by a life at sea. I spent good 22 years of the early part of my career in the Indian Navy, eventually commanding two F-class submarines and later serving on India’s first nuclear submarine a Charlie II. After leaving the Navy, I served for a decade as Master in the mercantile marine. Then as a VP in the second largest ship registry, the Liberian Flag for 3 years and now as the leader of the QMII team. I have seen safety management from the control room of a submarine and from the bridge of a merchant ship, in fair weather and in crisis. These experiences have convinced me that a Safety Management System only works when it is lived by the people who must make decisions in real time, far from shore support.

I still remember standing on the bridge of a merchant vessel, facing commercial pressure to sail on schedule while weather and equipment concerns suggested otherwise. The manuals and procedures were on board, but what mattered in that moment was whether the company truly backed me and my Master’s judgment. That is where the real test of any SMS lies, not in what is written, but in the support given when difficult decisions must be made.

Having sailed for many years, I know how isolating a tough decision at sea can feel. A good DPA is not just a name in the manual but a trusted voice on the other end of the line, someone the Master can call at 0200 hours and speak openly with. When that relationship exists, the SMS becomes real; when it doesn’t, the paperwork quickly loses relevance on board.

After a lifetime at sea and many years working ashore with companies to implement the ISM Code, and finally leading QMII for over two decades in training, auditing and consulting in management systems, I remain convinced of one thing that the Code itself is not the problem. The real issue is whether we choose to make the SMS a living system that respects the realities of those at sea. When shore and ship learn to listen to each other through the SMS, we honor not just compliance requirements, but the professionalism and lives of the people who sail our ships.

More than 25 years after the ISM Code became mandatory, the International Safety Management (ISM) Code is still too often treated as a paper exercise. Shore offices produce manuals, checklists and forms; ships receive them, file them, and do their best to keep up. The result is a familiar complaint from both sides, “The system is for auditors, not for us.”

Yet the ISM Code was never intended to create a paperwork gap between shore and ship. It was meant to bridge that gap by providing a common safety language and a shared framework for decision-making. When understood and implemented as a living system, the Safety Management System (SMS) becomes exactly that bridge. I always recollect the curt observation by Justice Sheen post the sinking of the Herald of Free Enterprise: “…. I see a disease of sloppiness at every level of the hierarchy….”. His direct pointer at having a management system brought us the ISM Code connecting to the SOLAS.

The ISM Code’s original Intent was to have a system that connects people. The ISM Code’s purpose is clear: to provide an international standard for the safe management and operation of ships and for pollution prevention. The Code defines the Safety Management System as a structured and documented system enabling company personnel to implement the company’s safety and environmental protection policy effectively.  From the beginning, the Code placed both shore and ship within the same system. Company objectives in section 1.2 of the ISM Code include:

  • providing safe practices in ship operation and a safe working environment,
  • assessing risks to ships, personnel and the environment and establishing safeguards, and
  • continuously improving safety management skills of personnel ashore and aboard ships.

These are not separate objectives for two separate worlds. They are shared obligations, achievable only when the SMS genuinely links the office and the vessel.

So where then does the gap come from? Despite this intent, many organizations experience a shore–ship divide in their SMS.

  • On shore, staff may focus on satisfying external auditors, producing beautifully formatted procedures that look good in a DOC audit but are hard to use in real operations.
  • On board, crews often experience the SMS as extra work: duplicative checklists, complex forms, and procedures that do not reflect the realities of weather, port pressure and human limitations.

When this happens, several symptoms appear:

  • “Cut-and-paste” risk assessments that no one believes in.
  • Non-conformities written in audit language instead of operational language.
  • Masters and Designated Persons Ashore (DPAs) communicating mainly for certification, not for learning.

The result is an SMS that is formally compliant but functionally weak—it exists on paper but not in daily decision-making. The SMS must be a living system. To bridge the gap, we must return to a simple idea, the SMS is not a manual. It is the way the organization manages risk and work, documented so it can be repeated, audited and improved. A living system has several characteristics:

  • Owned by users, not by paperwork Procedures and checklists are written in the language of the people who use them. Crew and shore staff participate in their development and revision. Guidance documents are concise, operational and easy to find.
  • Fed by real feedback The Code requires procedures for reporting accidents and non-conformities, and for internal audits and management reviews as functional elements of the SMS. In a living system, these are not compliance rituals but mechanisms for learning. Near misses, hazardous observations and improvement suggestions from crew are actively encouraged, analyzed and acted upon.
  • Adaptable, not frozen, clause 12 of the Code calls for review and evaluation of the SMS.
    A living SMS changes in response to new risks, technology, trade patterns and lessons learned. Revision is continuous, not something done hurriedly before an audit.
  • Transparent roles and communication The Code requires defined levels of authority and lines of communication between shore and shipboard personnel. In a living system, these lines are not just organograms—they are trusted relationships. Masters feel supported, not second-guessed. The DPA is accessible, respected and known by name, not just as a title in the manual.

 The DPA then should be the human bridge. Perhaps the most powerful bridging mechanism in the ISM Code is the requirement that every company designate a person or persons ashore with direct access to the highest level of management (ISM Code clause 4).

In many organizations, the Designated Person Ashore (DPA) becomes either:

  • a paper coordinator, chasing signatures and tracking audits, or
  • a firefighter, reacting to incidents and port state control findings.

To make the SMS a living system, the DPA must instead function as a system integrator:

  • Listening systematically to ship feedback and ensuring it reaches senior management.
  • Challenging shore practices that create unrealistic demands on ships.
  • Ensuring that risk assessments and procedures reflect actual operations, not office assumptions.
  • Facilitating honest discussions after incidents—not searching for blame but for system weaknesses.

In short, the DPA should be the voice of the ship in the boardroom and the voice of the system on the ship.

The companies should plan practical steps to bridge the shore–ship gap. Companies that wish to transform a static SMS into a living one can take several practical steps as to co-create procedures with ship staff by involving the masters, officers and ratings when developing or revising procedures. I call it capturing the “as-is” of the system in preference to throwing the ‘baby with the bath water” by simply adopting a template. Pilot new checklists on board before formal approval. Ask: “does this help you do the job safely under time pressure?” If not, redesign. Management systems are not etched in stone. They should be open, flexible and adoptable to change.

Train to be competent and for understanding, not just for compliance. Move beyond “read and sign” familiarization. Use case studies, incident reviews and simulations that connect ISM clauses with real operational dilemmas. Emphasize why a procedure exists, not just how to follow it.

Most importantly, simplify and prioritize. The ISM Code specifies functional requirements, not thickness of manuals. Focus on critical operations and major risks; remove redundant or overlapping forms. A smaller, well-used SMS is better than a massive, ignored one. While doing this, also strengthen feedback loops. Make incident and near-miss reporting simple and non-punitive. Provide feedback to the crew on what was learned and what changed as a result. When people see that speaking up leads to improvement, not punishment, the system comes alive.

Remember data drives risk and trends and makes an organization proactive. Use data—and stories. Combine quantitative indicators (deficiencies, delays, injuries) with qualitative insights (crew narratives, master’s reviews). This blended view gives a more complete picture of safety performance and culture.

A change from compliance culture to learning culture must be brought in to create an environment for quality, safety, security and continual improvement. Port State Control statistics show that ISM-related deficiencies remain among the most frequently reported issues worldwide. This suggests that many SMSs still operate at a minimum compliance level. Bridging the shore–ship gap means moving toward a learning culture, where:

  • Deviations are signals to improve the system, not just to correct the individual.
  • Masters are empowered to exercise their overriding authority and supported by the shore organization with resources on as needed basis.
  • Top management sees the SMS not as a cost, but as an asset that protects people, ships, reputation and the marine environment.

In conclusion I would repeat that making the Code work as intended is the need. Not just talk but walk the talk. The ISM Code gave the maritime industry a powerful framework. It defined objectives, clarified responsibilities, and required a documented Safety Management System (SMS) that connects shore and ship. The challenge now is not to “comply” with the Code, but to realize its intent.

When the SMS is treated as a living system—owned by its users, nourished by feedback, continually adapted and genuinely connecting shore and ship—it becomes what the Code envisioned:

  • a bridge between management and operations,
  • a driver of safety and environmental protection, and
  • a practical expression of the company’s values at sea and ashore.

The choice is ours: an SMS that exists for certificates, or an SMS that saves lives, protects the environment, and unites shore and ship in a common purpose.  

 

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Hope Is Never A Plan

Wishful thinking is fine, but it rarely achieves positive results in professional settings. The best path to reach a desired outcome is to implement a structured, process-based management system. It is not a guarantee of success, but if implemented by competent and motivated teams, such a system allows the organization to produce conforming products and services and embrace continual improvements.

I often hear from leadership about their faith in the power of hope, but my experience tells me that hope is never a plan. For those who believe in hope, my advice is to base it on a well-designed management system. There is no need to re-invent the wheel. ISO standards exist for management teams to use.

In organizations of every size, across industries and borders, there is often an invisible reliance on hope. Leaders hope customer complaints will decline. Managers hope processes will perform as intended. Teams hope risks won’t materialize.

Hope can inspire, but it cannot control outcomes. It is not a strategy, and it is certainly not a plan. In contrast, a good management system transforms that hope into structured action, measurable results, and continual improvement.

A Better Way

At my organization, we have long stressed (and said) “Hope is never a plan.” The plan—the real plan—is embedded in the process-based management approach that underlies ISO 9001 and other international standards. This approach replaces uncertainty with understanding and reactivity with resilience.

The problem with hope as a strategy is there is no plan. In times of uncertainty—economic shifts, market volatility, supply chain disruptions—many organizations fall back on hope as a substitute for planning.

However, in my experience, success is built upon the foundation of a process-based management system. Remember the wise words of Deming: “A bad system will beat a good person every time.” The process approach, central to ISO 9001 and mirrored in ISO 14001, ISO 45001, and numerous other ISO standards, recognizes that results come from well-managed processes.

The journey from wishful thinking to structured management is embodied in the process approach, which was first formalized in ISO 9001:2000 and reinforced in ISO 9001:2015. The standard recognizes that consistent, predictable results arise from well-defined and managed processes, not from chance. In particular, sub-clause 4.4 of ISO 9001:2015 requires organizations to establish, implement, maintain, and continually improve a management system, including the processes needed and their interactions.

Where hope says, “Let’s see how it goes,” a process-based system asks:

  • What inputs are required, and what outputs are expected?
  • Who is responsible for the process?
  • What resources and controls are necessary?
  • How will we measure performance?

This thinking moves an organization from reacting to problems to controlling the variables that create success. Rather than managing departments or reacting to problems, organizations use the process approach to:

  • Define interrelated processes that deliver outputs valuable to customers and stakeholders (sub-clause 4.4.1).
  • Identify inputs, activities, and controls within each process (sub-clause 4.4.1).
  • Establish measurable objectives and performance indicators (sub-clauses 6.2 and 9.1.3)
  • Use data and analysis to drive decisions.

This approach replaces hope with evidence, accountability, and continual improvement.

Plan, Do, Check, Act (PDCA) and the Importance of Leadership

The PDCA cycle implies planning as the basis for turning vision into reality. Clause 6 emphasizes “Planning,” i.e., the transformation of organizational context (subclauses 4.1 and 4.2) and risks (sub-clause 6.1) into actionable objectives and opportunities for improvement:

  • Risks and opportunities (not just reacting to issues)
  • Resources and competence needed to achieve results
  • Process interactions that maintain flow and consistency
  • Measurable outcomes that guide continual improvement

In this framework, hope is replaced by proactive thinking, i.e., identifying what could go wrong and preparing responses before it happens. This is far superior to a reactive approach. Of course, in the initial functioning of the management system, any non-conformances (NCs) found will drive corrective action. However, once data accumulates (based on closed NCs and other monitoring and analysis) then those data will drive risks and trends and enable proactive system.

Leadership plays a very important part in the success of an organization. From slogans to systems, true leadership is not about motivational statements but about embedding systems that work even when leaders aren’t watching.

Leaders demonstrate commitment by:

  • Integrating the management system into business strategy (sub-clause 5.1.1c)
  • Promoting process ownership and accountability
  • Ensuring alignment of policies (sub-clause 5.2), objectives (sub-clause 6.2), and actions

A strong system outlives individual personalities—it ensures the organization runs effectively on principles, not just people. What employees learn during their work life at the organization is captured as lessons learned and forms the organization’s corporate knowledge (sub-clause 7.1.6).

Continual improvement (sub-clause 10.3) is the antidote to complacency. Even good systems fail if they stop evolving. ISO’s process-based model ensures continual improvement through:

  • Audits and reviews that identify gaps and inefficiencies
  • Corrective actions that prevent recurrence
  • Performance metrics that inform decision making

Hope says, “Things will get better.” A good management system says, “Here’s how we’ll make them better—and how we’ll know it worked.”

Conclusion

My advice to leaders is to replace hope with a system. Every organization faces uncertainty, but those that succeed do not count on hope—they rely on structured management, clear processes, and evidence-based decisions. Leadership is responsible for maintaining customer focus (sub-clause 5.1.2), understanding customer requirements and associated risks, having thorough knowledge of their products, and carefully selecting vendors.

Uncertainty and hazards must not be passed to employees, users, or other stakeholders. Instead, they should be converted into manageable and low-impact risks. Those risks can then be addressed and/or converted into opportunities for improvement.

In an uncertain world, replacing hope with a system is a must. Hope may be emotionally comforting, but it is operationally dangerous. A good management system, based on ISO 9001’s process approach, gives structure to intention and reliability to performance. It enables organizations to anticipate risks, seize opportunities, and deliver consistent value. It creates confidence among customers, regulators, and employees that the organization is not merely hoping for success—it is planning, executing, and improving toward it.

The above article was recently featured in ‘The Auditor’, an Exemplar Global publication

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Cost-Benefit Analysis: ROI of ISO 9001 Registration for U.S. Manufacturers

For some U.S. manufacturers, registration to ISO 9001 raises one question: “Is it worth the investment?” In other words, how can an organization maximize the benefits of ISO 9001 registration and convert them to a solid return on investment (ROI)?

Analyzing ROI

A consideration of costs and benefits must be included in an ROI analysis to allow manufacturers to make good decisions about ISO 9001 registration. Calculating the value of an effective quality management system (QMS) must include integrating quality and the overall management of the organization (as seen in clause 5.1.1 of ISO 9001). This would include the costs and payoffs that create the real ROI of ISO 9001 registration.

Mere compliance to the language of the standard is not enough; what is required is that ISO 9001 registration leads to competitive advantage. The intent for any manufacturer is to boost efficiency and revenue. In this new environment, where a considerable amount of manufacturing is being re-shored to the United States, ISO 9001 registration matters more than ever. Registration to ISO 9001 is worth it if it brings a clear ROI, such as cash in the bank in the form of cost savings or revenue increases. The answer lies in understanding the ROI that comes from building a strong QMS based on ISO 9001 or other relevant industry-specific standards such as AS9100, etc.

There is no free lunch. In other words, there are costs associated with ISO 9001 registration. Therefore, manufacturers should budget for:

  • Consulting and training. Staff must be prepared to align processes with the requirements of ISO 9001.
  • System development. This may include documenting procedures, implementing software, and updating workflows.
  • Certification audits. Certification bodies (CBs) require fees for initial certification and surveillance audits.
  • Time and resources. These may include employee hours spent on training, process improvements, and audits.

Costs vary depending on company size and can run from tens of thousands of dollars for small factories to much more for large, multi-site operations. The good news is that the benefits of working systematically using a process-based management system (as per clause 4.4.1 or ISO 9001) drive the ROI as the system implementation reduces waste and other production inefficiencies.

Although there can be significant upfront costs, the benefits of ISO 9001 registration often compound over time. These can include operational efficiency with streamlined processes which reduce waste, downtime, and rework, leading directly to lower production costs. Customer confidence and market access improve as the manufacturer consistently produces confirming products and services. Many U.S. manufacturers find ISO 9001 and/or relevant industry-specific standards to be a “ticket to entry” for bidding on contracts, especially in sectors such as automotive, aerospace, and military/defense.

Reducing Risk

Documented processes and corrective action systems reduce the likelihood of costly failures or recalls. Employee engagement improves, resulting in highly motivated teams working within clearly defined roles. Appropriate training oriented toward competency (as seen in clause 7.2 of ISO 9001) reduces errors and boosts productivity. Continual improvement is an added benefit of ISO 9001 as the implementation of the standard promotes a culture of ongoing improvement, helping companies stay competitive in fast-changing markets.

Calculating the ROI of ISO 9001 registration can be assessed by comparing costs against measurable gains such as:

  • Reduced scrap/rework = cost savings
  • Improved on-time delivery = fewer penalties and more repeat orders
  • Access to new markets/contracts = increased revenue
  • Enhanced reputation = long-term customer retention

Example: If a manufacturer spends $50,000 on registration but reduces rework costs by $80,000 and gains $200,000 in new contracts, the ROI is clear and compelling.

Then there is the real-world impact. Studies consistently show manufacturers that achieve ISO 9001 registration experience:

  • 5–15% cost savings from efficiency gains
  • Revenue growth due to market access
  • Improved customer satisfaction scores, leading to stronger long-term partnerships
Final Thoughts

Initially, ISO 9001 registration may seem like a simple expense. But when viewed as an investment, the ROI to be found in ISO 9001 registration becomes clear. It brings definite improved efficiency, stronger customer trust, and measurable financial gains. For U.S. manufacturers competing in global markets, the payoff often far outweighs the cost.

The above article was recently published in an Exemplar Global publication ‘The Auditor’.

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Building a Quality Culture: The Role of Leadership

When the leadership at a U.S. industrial plant makes the strategic decision to roll out certification to ISO 9001, their first instinct is often to focus on documentation, audits, and procedures. They start by looking for a consultant who often (for quick money) provides a template. That is the start of misery for an organization.

A Better Way To Begin

The “As-Is” of the management system should be the start of this process. What has been developed over the years should not be forgotten or lost! The truth is that no checklist or manual can build a true quality culture. The secret ingredient in implementing ISO 9001 is the involvement of leadership in developing the system. As per sub-clause 5.1 (“Leadership and commitment”), their total involvement and commitment is required, in addition to others who assist them in this role, as per sub-clause 5.3 (“Organizational roles, responsibilities and authorities”).

Why leaders can make or break ISO 9001 effectiveness is an important question, and taking positive action to do so is therefore a vital decision. Employees don’t take their cues from policies—they take them from people. If leaders treat ISO 9001 as “just another certification,” that’s exactly how the workforce will see it. On the other hand, when leadership is visible, engaged, and committed, quality stops being a buzzword and becomes a way of working. A system that has the support of leadership has the best chance to produce conforming products and services and also ensure continual improvement.

ISO 9001 makes this clear. Clause 5 (“Leadership”) puts accountability squarely onto the leadership. It’s not just the quality manager’s responsibility anymore—it’s a business-wide effort, and leaders must own it. It is leadership that matters in ISO 9001 and is an important aspect of the process.

Clause 5 emphasizes that leaders must:

  • Demonstrate commitment to the quality management system (QMS)
  • Align quality objectives with organizational strategy
  • Promote a culture of continual improvement

The View From The Shop Floor

In U.S. industrial plants, where efficiency and production targets often dominate discussions, leadership involvement ensures quality doesn’t get sidelined. Leaders act as role models, showing that meeting quality objectives is as important as meeting delivery deadlines.

When auditors look at the implementation of a management system standard like ISO 9001, they need to be able to clearly evidence what leadership involvement looks like in practice. There are numerous indicators, most of them based on ISO 9001 subclauses 5.1, 5.1.2 (“Customer focus”), 5.2 (“Policy”), 6.1 (“Actions to address risks and opportunities”), 6.2 (“Quality objectives and planning to achieve them”), and 10.3 (“Continual improvement”). To generalize these into simple language I would say these would include the following:

  • Setting the tone. A plant manager who opens every team meeting with a quality update shows that it matters as much as production numbers.
  • Walking the floor. Leaders who regularly join quality reviews or stop by the line to ask about issues send a strong signal of support.
  • Connecting quality to strategy. Instead of treating ISO 9001 as paperwork, leaders can frame it as a competitive edge, leading to fewer defects, happier customers, and stronger market position.
  • Celebrating wins. Recognizing teams for continuous improvement projects—no matter how small—builds momentum and pride.

Culture is caught, not taught. We can train employees on ISO 9001 requirements, but culture is shaped by what leaders actually do. Creating an environment of quality is a leadership accountability issue. When executives understand the value of nonconformities as the drivers of corrective action and improvement, follow procedures, welcome audits, and act on feedback, employees naturally mirror those behaviors. Over time, this creates a culture where quality isn’t “extra work”—it’s simply the way we work. It is then that the organization can go from a reactive to a proactive manufacturing entity.

The return on investment in ISO 9001 can be traced to sub-clause 6.2 and the achievement of specific quality improvement objectives. Industrial plants that embrace ISO 9001 leadership involvement don’t just pass audits. They see less rework, stronger customer trust, and a workforce that takes pride in doing things right the first time. In today’s competitive manufacturing landscape, that’s not just compliance—it’s survival.

Bringing It Forward

Five practical steps leaders can take to lead the industry may include the following:

  1. Communicating the vision. It is important to clearly articulate why ISO 9001 matters—not only for certification, but for customer trust, employee pride, and long-term competitiveness.
  2. Allocating resources. Quality initiatives fail when they’re underfunded. Leaders must ensure sufficient training, technology, and staffing to support ISO 9001 compliance. Where they cannot provide resources, they must assume the risk and adjust objectives.
  3. Engaging with the employees. This includes walking the floor, participating in quality meetings, and recognizing contributions. All of these actions reinforce that quality is everyone’s responsibility.
  4. Integrating quality into the organization’s strategy. Quality goals should not be separate from business goals. For example, reducing defects can be tied directly to cost savings and improved customer satisfaction.
  5. Leading by example. Leaders who adhere to procedures, value data-driven decisions, and embrace audits demonstrate that ISO 9001 is part of the plant’s DNA.

ISO 9001 isn’t a binder sitting on a shelf. It’s a leadership-driven culture shift, and when leaders lead the way, the entire plant follows. Just keeping the binder on the shelf is no good. It may get the organization a certificate but will not result in a positive return on investment.

Without leadership involvement, ISO 9001 may become the missing link in the success of U.S. industrial plants. Your involvement as leaders at every step of your organization matters more than checklists. You must drive the culture of change.

In concluding, I would opine that rolling out ISO 9001 in U.S. industrial plants requires more than technical checklists; it requires leadership. By committing to involvement in the implementation of ISO 9001, plant managers and executives can transform their organizations into a quality-driven powerhouses that thrive in today’s competitive market.

The above article was recently published in “The Auditor” (an Exemplar Global publication).

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Integrating Standards for Safe Nuclear Expansion

-by Dr. IJ Arora

As nuclear energy regains attention as a low-carbon solution, organizations developing these energy sources need to consider a systems approach to the safe launch and growth of facilities. Once considered a great alternative to gasoline and coal, the nuclear energy industry’s growth was negatively affected by incidents like those at Chernobyl and Three Mile Island.

In this short article, I will attempt to convey that customer focus (clause 5.1.2 of ISO 9001:2015) is best ensured by proactive, not reactive, measures. This can be achieved through appreciating hazards, converting them to risks, prioritizing them, and planning the management system to achieve desired objectives.

Having served on a nuclear submarine and been on board when a nuclear accident took place, I know the pros and cons of this energy source. However, the world has changed since these tragic incidents and now there are advancements in not only nuclear technology but also in the management of nuclear facilities. ISO 19443:2018 a quality management system (QMS) standard built on the foundation of ISO 9001, but which is specific to the management of nuclear facilities. For those in the United States, ASME offers the NQA-1:2024 standard which is similarly dedicated to the nuclear industry.

Nuclear energy is perhaps an answer to the world’s power requirements. The demand for electricity is growing by the day with the extensive use of artificial intelligence and large data centers. A systems approach to management of this industry gives the world the best chance to appreciate risks systematically and plan for consequences proactively.

Grave negative effects to safety, security, health, and the environment are all likely consequences if a nuclear mishap takes place once again. Although the primary objective of a QMS is to get the desired output, it should not be at the cost of these potential harms.

The Three Mile Island facility is in the news once again for re-opening ahead of schedule. For those who do not remember, on March 28, 1979, a partial meltdown occurred at the Unit 2 reactor outside of Harrisburg, Pennsylvania. Environmental impacts included the release of radioactive gases into the atmosphere (albeit in limited amounts), long-term challenges in radioactive waste storage, and site contamination. Additionally, there were psychological and social effects that caused a loss of public trust in the nuclear energy industry.

As discussions emerge about reopening the Three Mile Island facility (now scheduled by 2027), evaluating its environmental effects through the lens of the ISO 14001:2015 environmental management system (EMS) is both prudent and proactive. Therefore, in the following section, I will outline the relevant applicable clauses from ISO 14001:2015.

Applicability of ISO 14001:2015 to a nuclear facility

Clauses 4.1 and 4.2, “Context of the Organization” and “Needs and Expectations of Interested Parties”

Nuclear facilities would benefit from considering:

  • Historical context (e.g., past accidents and public concern)
  • Stakeholders such as regulatory bodies, local communities, and environmental NGOs
  • Emerging media reports and public opposition or support as environmental risk indicators

Clause 6.1, “Actions to Address Risks and Opportunities related to Significant Environmental Aspects”

Considering a lifecycle approach, a reopened nuclear plant must assess:

  • Emissions of ionizing radiation
  • Spent fuel storage and long-term waste management
  • Thermal pollution from coolant discharge
  • Accident and emergency scenarios
  • And other significant environmental aspects requiring control measures and documentation

Clause 6.1.3, “Compliance Obligations”

This subclause involves alignment with:

  • Nuclear Regulatory Commission (NRC) rules
  • EPA guidelines on radiological impacts
  • International agreements on nuclear safety and waste

Clause 6.1.4, “Planning Action”

The plant must establish plans to:

  • Prevent recurrence of accidents like those of March 28, 1979
  • Contain and manage radioactive leaks
  • Mitigate environmental risks in both normal and abnormal operating conditions

Clause 8.2, “Emergency Preparedness and Response”

This subclause includes details critical for a nuclear facility and requires:

  • Detailed emergency response procedures for nuclear accidents
  • Training for first responders and public communication plans
  • Coordination with local and federal emergency management agencies

Clause 9.1.1, “Monitoring, Measurement, Analysis, and Evaluation”

To meet the requirements of this subclause, facilities must continuously monitor:

  • Radiation levels in air, water, and soil
  • Effectiveness of containment systems
  • Compliance with regulatory thresholds

Clause 10.1, “Nonconformity and Corrective Action”

This subclause would require that:

  • Any incident or near-miss must trigger a formal investigation
  • Includes lessons learned from:
    • The March 28, 1979 event itself
    • Any deviations during recommissioning or startup

A system approach to nuclear facility management

The opening (or, in this case, reopening) of a nuclear facility offers an opportunity to integrate modern management system practices with lessons learned from the past. ISO 19443:2018 and ISO 14001:2015 provide a structured framework to manage the needs of nuclear operations as well as public environmental concerns.

During my time consulting for numerous industries, I have found a strengths, weaknesses, opportunities, and threats (SWOT) analysis to be a very useful tool— especially the weaknesses and threats that help identify risks. A detailed SWOT analysis for the Three Mile Island facility might provide the following inputs as an example:

Technical and operational risks: aging infrastructure

  • Although it was not the site of the 1979 meltdown, Unit 1 is more than 50 years old.
  • Restarting involves complex retrofits, control system upgrades, and re-licensing—all of which require time and precision.
  • Rushing these checks might lead to overlooked fatigue, corrosion, or component failures.

Human factors

  • Post-incident, nuclear workforce training and institutional memory may be weak.
  • Skilled nuclear operators must be retrained or recruited, and hasty onboarding increases the chance of human error—a factor in many historical nuclear mishaps.

Environmental risks: radioactive emissions and waste

  • Restarting means handling spent fuel, coolant systems, and storage pools.
  • Hurrying these operations risks could lead to:
    • Leaks during fuel handling or containment failures
    • Inadequate radioactive waste protocols

Ecosystem disruption

  • Cooling systems may discharge thermal pollution into nearby rivers.
  • Emergency preparedness might not be fully revalidated for post-reopening conditions.

Better alternatives to a rushed restart

Although early reopening offers incentives like energy security, carbon reduction, and economic revival, these gains are precariously balanced against high-impact risks that could derail long-term viability. The strengths and opportunities may only be fully realized with a controlled, phased, and transparent approach, not through acceleration that bypasses environmental, technical, and social due diligence.

As such, organizations pursuing the development of nuclear energy plants must consider:

  • Phased reopening with public oversight
  • Third-party safety audits after at least two cycles of internal audits post implementation of the management system
  • Full-scale emergency drills and community outreach prior to operation
  • Independent environmental impact assessments (EIA)

Conclusion

The benefits of a fast reopening exist, however, the risks far outweigh short-term gains unless stringent safety, regulatory, and public engagement protocols are followed. Strategic value lies in measured and transparent activation/reactivation, not haste. ISO 14001:2015, ISO 19443:2018, and ASME NQA-1:2024 provide the framework for an integrated management system.

In conclusion, I would say a good strategy to implement and to safely accelerate nuclear energy deployment must include the adoption of a management system. ISO 14001:2015 ensures environmental responsibility and community accountability; ISO 19443:2018 drives quality, culture, and nuclear-supplier discipline; and ASME NQA-1:2024 enforces technical rigor and traceable QA processes. Together, these standards offer a comprehensive, risk-based, and stakeholder-aligned approach.

Rushing implementation without such integration would leave critical blind spots. An integrated implementation roadmap including these standards could guide the strategic and operational implementation in support of safe, controlled nuclear energy expansion.

The article was recently published in “The Auditor” An Exemplar Global Publication.