What the ISM Code Can Teach Us About Risk: Part Two

Editor’s note: This is the second of a two-part article examining the risk-based thinking lessons to be learned from maritime safety and security protocols. You can read part one here.

The International Safety Management (ISM) Code brings a framework for safety through systematic management. It was introduced by the International Maritime Organization after several major maritime accidents revealed a common problem: The causes were rarely technical alone; instead, they were failures of management systems. The ISM Code, therefore, established a simple but powerful requirement, wherein shipping organizations must implement a documented safety management system (SMS) to ensure the safe operation of ships and the protection of the environment.

The principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

Connecting the ISM code and ISO 9001

The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing leadership responsibility, risk assessment, operational control, training and competence, incident reporting, corrective action, and continual improvement. These requirements may sound familiar to anyone working with ISO management system standards such as ISO 9001 and others following the harmonized structure. In essence, the ISM Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

Establishing an SMS based on the ISM code and principles of ISO 9001 means planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, person in water, and/or security threats or piracy. (Note that maritime security is covered by the International Ship and Port Facility Security Code and ISO 28001 covering security management systems for the supply chain). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised.

Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of considering what could go wrong and if people know their roles if (when) it does. It also means interrogating the system to determine how the organization will handle the ramifications of the adverse event.

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. Sections 5.1 and 5.2 require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The master has overriding authority. At the same time, as per section 4, the ISM Code requires those off the ship to support the master through a defined role known as the Designated Person Ashore (DPA). This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles: Authority must match responsibility and top management must remain connected to operational realities.

ISO 9001 expresses the same idea in a different context. As seen in clause 5.1 (“Leadership and commitment”) and clause 5.3 (“Organizational roles, responsibilities, and authorities”) leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

In the case of mariners, competence and training are systematized. The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important: continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon-ship drills, and damage-control exercises are conducted not because emergencies are frequent; instead, it is because although they are rare, they are also highly consequential. This principle translates directly into quality management. Competence is not merely about qualifications; it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from incidents, as seen in ISO 9001’s clause 7.1.6 (“Organizational knowledge”) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of nonconformities, accidents, and hazardous occurrences. The purpose is not to blame, but to learn. Each incident becomes an opportunity to ask, “What failed in the system?” “What corrective action is needed?” and/or “How do we prevent recurrence?” Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about all key decisions, including how and when to transit dangerous areas. These decisions are rarely simple. They require balancing safety risks, commercial pressures, and regulatory requirements, including ever-changing statutory requirements of various contracting governments. This must be seen within the contexts of operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk; they provide a framework for making better decisions about risk.

The ISM Code as a case study for risk-based thinking

Mariners have much to teach quality professionals on the use of the system approach for considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons:

  • Systems matter more than individuals; therefore, while competent people are essential, reliable operations depend on structured systems.
  • Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away.
  • Leaders must prepare for rare but high-impact events, because risk management is not only about what happens frequently.
  • Practice builds readiness.
  • Training and drills ensure procedures work under real conditions.

The takeaway is that there is a need to learn relentlessly from failure and use nonconformities as opportunities to strengthen the system.

The need to navigate uncertainty strengthens the importance of the ISM Code and/or ISO 9001 to inform leaders about risk and process management. For ship owners and masters, decision-making requires a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Yet despite these uncertainties, global shipping remains remarkably reliable. More than 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

The ISM Code, as well as ISO 9001, recognize that outcomes, whether safety or quality, depend on well-defined processes and leadership oversight. To mariners and quality professionals alike, I would advise another close look at your management system. Strengthen it. Maritime leaders ashore, like executives in the boardroom, must stay involved in assessing and mitigating risks to provide the best chance for safety, security, and success.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Home » Audits

Integrated Management System: Combining ISO 9001 and ISO 14001 Without Doubling the Work

An integrated management system (IMS) combining ISO 9001 (quality) and ISO 14001 (environment) is not double the work – it’s half the effort. Built on the shared Annex SL High Level Structure, an IMS eliminates siloed audits, redundant documentation, and conflicting objectives, replacing them with a single, unified framework for operational excellence.

The harmonized standards were not available till about 2012. Yet at QMII, we talked about an integrated approach to management and worked with organizations on the advantages of the integrated management system (IMS) or combined management systems. Why this discussion? It is a classic efficiency and silos battle. Many organizations treat ISO 9001 (quality management system, QMS) and ISO 14001 (environmental management system, EMS) as two separate burdens, often managed by two different departments that barely speak. With the emphasis on ISO 45001 (occupational health and safety, OHS) in recent times, we can see that an environmental impact could cause health consequences. Yet I see large organizations with siloed departments. In this short article I want to challenge and leave this for discussion that this double the work myth is incorrect and how the Annex SL harmonized structure makes various standards natural partners.

This myth of the parallel path must be demystified at the highest level. In many boardrooms, ISO is a word associated with binders, audits, and administrative fatigue. When a company decides to pursue both quality (ISO 9001) and environmental (ISO 14001) and other standards, the gut reaction is often to build two or as many separate systems as for each applicable standard. My first question is why manage your business as if your quality goals, OHS goals, asset management goals, crypto security goals, business continuity goals and your environmental impact etc. happen in different buildings? An integrated management system (IMS) isn’t just possible, it is the only way to achieve true operational harmony and genuine continual improvement.

The foundation of the integrated management system: Annex SL (High Level Structure). The secret weapon for harmonization is Annex SL. Most of the harmonized standards share identical core structures, meaning the skeleton of the management system is already the same. They share terms, definitions, and most importantly, their core clauses.

If I put this in phases, then the phase 1 would be to look at harmonizing the context and leadership. Let us simplify this discussion take just two standards, ISO 9001 and ISO 14001. At the start of both standards, the requirements are nearly indistinguishable in intent:

  • Clause 4: context of the organization would then not require doing two SWOT analyses, just do one. Identify your internal and external issues once. Under clause 4.2, the organization can identify the interested parties. A customer (quality) and a local regulatory body (environment) are both stakeholders. Managing them in one register ensures that environmental compliance doesn’t accidentally bottleneck quality delivery.
  • Clause 5: leadership and commitment where most un-integrated systems fail. Management shouldn’t have to attend two different management review meetings. Integration forces leadership to view quality and sustainability as two sides of the same strategic coin. One policy, one set of roles, and one unified vision based on risks across the organization.

The phase 2: then I would say would be the integrated planning and risk. This is where the heavy lifting of harmonization happens.

  • Clause 6.1: Actions to address risks and opportunities — a cornerstone of risk-based thinking in both standards. In ISO 9001, the organization looks at risks to product quality. In ISO 14001, you look at environmental aspects and impacts. By combining these in a single integrated management system, you see the full picture. For example, a chemical change in manufacturing might improve product durability (9001) but increase hazardous waste (14001). If these systems aren’t harmonized, you solve one problem only to create another.
  • Clause 6.2: objectives and planning harmonization enables the organization to set smart objectives that satisfy both standards simultaneously, such as reducing material waste which then lowers costs (quality) and reduces environmental footprint (environment).

Phase 3: could be unified support and operation and would meet the requirements of clauses 7 & 8 of both standards:

  • Clause 7: support would not need two sets of document control procedures or two different training programs. Clause 7.2 (competence) and clause 7.3 (awareness) can be handled through a single employee onboarding process.
  • Clause 8: operation while ISO 9001 focuses on operational control of the product and ISO 14001 focuses on life-cycle perspective and emergency response, they both live on the shop floor. Integrating these means the organization’s standard operating procedures (SOPs) include environmental safeguards alongside quality checks.

Phase 4: would then be a great advantage to the organization as it would provide the single pane of glass evaluation with the greatest efficiency gain in an IMS coming during the evaluation phase.

  • Clause 9.2: internal audit would be simpler and give more productivity. After all, why pay for or conduct two separate audits? A harmonized internal audit looks at a process from start to finish, checking for quality defects and environmental non-conformance in one walk-through.
  • Clause 9.3: management review would bring quality data and environmental performance to the same table and would allow executives to make resource allocation decisions based on the whole business, not just a siloed report.
  • Clause 10: Improvement. Corrective actions (clause 10.2) should follow the same root-cause analysis (RCA) path within the PDCA (Plan-Do-Check-Act) cycle. Whether a part failed a stress test or a spill occurred, the process for fixing the system and preventing recurrence is identical. The risks are common.

The concluding phase would bring the organization to move from fragmentation in the approach to bringing harmony by combining ISO 9001 and ISO 14001. It isn’t just about saving paper or reducing audit days. It’s about organizational maturity. When organizations harmonize these systems, they stop treating quality and environment as extra tasks and start treating them as the standard way of doing business. For those who still don’t appreciate the value they need to look at the bottom line. Less redundancy, clearer communication, and a unified strategy are the hallmarks of a company that isn’t just compliant, but competitive.

The primary standard ISO 9001 is being updated, and the new version will be available in September 2026. ISO 14001 is already available in the updated version. The update of other standards including the aerospace and other industry standards will follow.  The change to clauses in the updates of the standards is minimal. It means the structure will be same; the emphasis is in the implementation. As organizations move toward ESG (Environmental, Social, and Governance) reporting, having a harmonized ISO 9001/14001 integrated management system (IMS) provides the verified QMS and EMS data needed to back up those high-level sustainability claims.

Then there is the cost saving angle too. Human ROI of systems engineering must be considered. In the world of ISO, we often talk about process efficiency, but we forget that stressed employees are the primary drivers of hidden costs. When a system is fragmented, people are forced to become the glue manually reconciling data, filling out redundant forms, and bracing for audits. That glue is expensive, and eventually, it cracks. There is a need to bridge that connection. Stress drains the bottom line, often termed the friction tax. In a siloed organization, employees pay this friction tax daily perhaps as a decision fatigue when quality and environmental objectives conflict, managers hesitate. Hesitation delays production. Then another one of the common costs is the audit anxiety. If an internal audit feels like a blame game session because the paperwork is a mess, morale drops. Low morale leads to higher turnover and the cost of replacing skilled employees are often twice their annual salary. The need to make double entries wherein technicians must log a chemical spill in the quality log and also in the environmental log. It is not just annoying but a sheer waste of billable hours.

The logic of the harmonized integrated management system therefore provides a clear ROI. Organizations can visualize the connection for example in reduced waste (clause 8.1) where an integrated process ensures that doing it right the first time (quality) also means using only what is necessary (environmental). Less scrap material means lower disposal costs and lower procurement costs.

Leaderships understand the importance of a proactive system. Being predictive is better than a system which is reactive. If the organization is all the time firefighting the stress will be more. A harmonized system uses clause 6.1 (risk management) to prevent fires before they start. It is significantly cheaper to maintain a machine (preventing both a quality defect and an oil leak) than it is to clean up a disaster. Streamlined training is another plus of the harmonized system. By integrating requirements, you reduce the time employees spend in training rooms and increase the time they spend on the value-add line.

The ultimate goal of any management system isn’t to pass an audit. It is to provide a stable platform for the business to grow. When we treat ISO 9001 and ISO 14001 (as also other relevant standards) as separate entities, we inadvertently bake friction into our corporate DNA. We create a system where the left hand ignores the right, and the employees the organization’s most valuable assets, pay the price in stress and burnout. By harmonizing these systems into a true integrated management system (IMS), organizations eliminate the friction tax. Administrative noise is replaced with operational clarity. When a system is integrated, clause 10 (Improvement) ceases to be a chore and becomes a natural byproduct of a focused workforce. In summing up I would say less complexity leads to less stress. Less stress leads to fewer errors. Fewer errors lead to less waste and higher ROI. For those who still view integration as a nice-to-have, remember in an increasingly volatile market, the most successful companies aren’t the ones with the most binders on the shelf they are the ones with the most streamlined, intuitive, and stress-free processes. Integrating ISO 9001 and 14001 isn’t just a technical exercise, it is a commitment to organizational health. When your management systems work in harmony, your people can finally stop managing the system and start managing the business.

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

The Hidden Signals of Process Breakdown

When implementing management system, the organizations are really not trying to reinvent the wheel.  The availability of ISO standards gives us a well tried, over the years updated approach in terms of the available clauses. The PDCA (plan, do, check and act) cycle approach in the harmonized standards enables designing an effective management system, monitoring it and updating it to not just produce confirming products and services but also to use inputs at the check stage to continually improve it. Yet the systems fail. Non-conforming products are released. Is there then an anatomy of a quiet failure? Indicators that will enable discovering these signals proactively. If that can be analyzed organizations would appreciate these hidden signals of the system breakdown and take proactive measures. Risks and trends are data driven. Can we expect our auditors to proactively recognize these.

There is the lagging indicator trap between being reactive and proactive. Up to the 2015 version of ISO 9001 (and equivalent industry specific standards in the harmonized structure) preventive action was taken based on data, invariably at the act stage of the PDCA cycle. From the 2015 version onward clause 6.1 introduced the risk appreciation requirement at the plan stage itself and then throughout the work cycle. Separating knowledge (clause 7.1.6 of ISO 9001) from competence (clause 7.2 of ISO 9001), has introduced us to corporate knowledge in terms of lessons learnt. Leadership in analyzing changing context and risk thereof should be on the lookout for indicators.  Therefore, the PA (preventive action) concept needed a change to risk. The idea was not to throw the baby with the bathwater. NC (non-conformity) did drive correction and CA (corrective action), however, as the organization collected data it became proactive wherein data drives risk and trends. Waiting for a nonconformity (NC) is a reactive strategy. Therefore, organizations should not be we waiting for NCs. By the time an NC appears, the financial or quality damage is already done. Being proactive therefore, is the need of a functioning system.

With the ISO 9001 revised 2026 version expected in September 2026 there is, quite correctly the need to strengthen the check stage. The organizations will expect better auditing instead of just a check list being completed. The auditor’s sixth sense to ask better questions and to establish how the system is working will be important. Just having a frame and expecting it to do magic and pinpoint failures of the system is not sufficient, but the need is for a high-level pattern recognition. The skilled auditors look for the erosion of intent, where the way work is done drifts away from how it was designed. They need is to provide these inputs during audits to the leadership.

For the organizations and the auditors there are many signals of this hidden failure. There is the tribal knowledge drift as recognizing the symptoms, where the question is: “how do you do XXX?” and the employee reaches for a handwritten sticky note or a personal notebook instead of the official SOP (standard operating procedure). The hidden meaning here is that the official process is likely too rigid, outdated, or inaccessible. This is indicative of a workaround culture in its infancy. Then there is the risk scalability. The process lives in heads, not in the systems. This is indicated by when those people leave, the process collapses. Technically it was not a system. The system instead of being a working process was dependent on individual competence.

Good auditors are conscious of another signal indicated by the language used and the linguistic friction. The Symptom here is in phrases like “we usually just…”, or “on a good day, we…”, or “that’s just how we have to do it.” In these and similar cases the hidden meaning is indicating to the organization and to the auditors that the standard process is no longer the path of least resistance. For a good auditor the clue is the hesitation or glance-exchanges between team members when answering simple procedural questions. Looking ahead at expectations of the ISO 9001, 2026 version of the standard the auditors need to be conscious of how the system is actually working, working or not working.

The next signal to watch out for could be the ghost workload (shadow processes) indicated by the excessive use of excel trackers to manage data that should be in the ERP/QMS, or the need for frequent offline meetings to fix recurring errors or the use of tiger teams to cover the back log. The hidden meaning of this should be clear. The formal system is failing to provide the necessary utility. Also, that the risk is not being proactively data driven. Data integrity and lack of visibility by the management leads to the leadership  seeing a green dashboard, when the reality is red and it is showing a mirage of being held together by manual labor.

Related to this is the physical and digital clutter. The clear symptom of this e.g.  in a physical plant, it’s unlabeled bins or “red tag” areas that haven’t moved in months. In a digital space, it’s numerous versions of the same document with names like final_vrn2_use_this.pdf. etc. The implication of this is the loss of 5S discipline (sort, set in order, shine, standardize, sustain). Clutter is a visual representation of a mind and of a process that has lost its focus.

Good auditors must also consider the human element and its connected emotional cues like the defensiveness vs. transparency conflict. If a process owner is overly protective of their territory, they are often hiding a breakdown they don’t know how to fix. It can also be a conflict between fatigue and apathy leading to when and why? This is answered with rationalization, because that’s the rule, the connection between the task and the value (quality) has been severed.

My concluding thought is to prepare for implementation of ISO 9001:2026 (expected in September 2026). In preparing understand that the auditors should be becoming proactive auditors. They need to shift the goal and change their attitude. The goal isn’t to catch people; it’s to catch the process before it fails them and therefore the organization. The value add is that a skilled auditor saves the company money by identifying these frictions before they turn into a notice of inspection by a statutory body, a client, a recall, or a lost certification. Organizations should expect their auditors to catch these hidden signals of process breakdown timely and report them. A good audit report should include these and this should be the expectation.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Auditing Risk Management: How Experienced Auditors Identify Risks That Aren’t Listed in the Risk Register.

Organizations today rely heavily on risk registers to track and manage potential threats. Risk registers are useful tools, and they document known risks, assess their likelihood and impact, and assign ownership for mitigation actions. They help leadership visualize risk exposure and provide a structured way to prioritize responses.

However, risk registers have their limits. Experienced auditors know something critical, that the most damaging risks are often the ones that never appear in the register. A risk register represents what the organization already knows or believes it knows. The context of the organization changes. A risk register reflects the thinking of the team that created it. But risks evolve, environments change, and assumptions become outdated. As a result, relying solely on the documented register can create a false sense of security. Seasoned auditors understand that their responsibility goes beyond verifying that risks are listed and mitigations are documented. Their deeper role is to identify blind spots and record risks that exist outside the documented system. This is where experience, professional skepticism, and systems thinking become essential. Skilled auditors recognize patterns, inconsistencies, and subtle signals that indicate hidden risks. QMII specializes in risk and with our forty plus years in the system field, in this article, we explore how experienced auditors uncover risks that never make it into the risk register and why this capability is essential for effective risk management.

The questions therefore are, why risk registers miss critical risks. I think, before examining how auditors uncover hidden risks, it is important to understand why risk registers are incomplete.

Risk registers reflect perception and often not the reality. Risk registers are typically compiled during structured workshops or periodic reviews. Participants identify risks based on their knowledge and experience. But human perception is limited. People tend to list:

  • Risks they have seen before.
  • Risks that are already familiar.
  • Risks that are easy to articulate.

But unfamiliar or emerging threats often remain invisible. For example, a manufacturing team might focus heavily on supply chain delays while overlooking risks related to cybersecurity vulnerabilities within their operational technology systems. Experienced auditors recognize this limitation and therefore treat the risk register as a starting point, not the final word.

Then there is the organizational bias which influences risk Identification. Risk registers can be influenced by internal politics or cultural pressures. Some risks may be downplayed because:

  • They reflect poorly on leadership decisions.
  • They expose systemic weaknesses.
  • They challenge existing strategies.

In such cases, risks may be intentionally or unintentionally omitted. Auditors who understand organizational dynamics pay attention not only to what is documented, but also what is missing.

Please also consider that risks often evolve faster than documentation. The modern risk landscape changes rapidly due to:

  • Technological advancements.
  • Regulatory changes.
  • Market disruptions.
  • Geopolitical instability.

Risk registers are often updated annually or quarterly. But emerging risks can develop far faster than review cycles. Experienced auditors therefore examine current conditions, not just documented assessments. The experienced auditors detect unlisted risks. The difference between routine auditing and expert auditing lies in how auditors think. Experienced auditors do not simply verify compliance. They analyze systems, behaviors, and signals that reveal underlying vulnerabilities. The ISO 9001 version expected in September 2026 expects organizations to go beyond check lists and see how their system works to produce confirming products and services.  The auditors of the future must work to providing these inputs. Several approaches distinguish their work.

The primary is developing the attitude and aptitude where the auditors look for process weaknesses, not just risk entries. Experienced auditors start by examining processes rather than documentation. Instead of asking: “Is this risk listed in the register?” They ask: “Where could this process fail?” Every process contains inherent vulnerabilities. Skilled auditors identify points where failure could occur, including:

  • unclear responsibilities.
  • lack of monitoring.
  • excessive reliance on manual steps.
  • insufficient controls.

For example, if a company relies heavily on one individual to approve high-value financial transactions, an auditor immediately recognizes concentration of authority risk, even if the risk register never mentions it. In other words, auditors uncover risks by studying how work actually happens.

Observing operational reality is another positive trait in an auditor. Documentation often describes how processes are supposed to work. But experienced auditors know that actual practice frequently differs from documented procedures. They therefore observe operations directly by speaking with frontline staff, watching processes in action and asking open-ended questions. These conversations often reveal informal workarounds, shortcuts, or unofficial practices that introduce risk. For instance, employees might bypass a cumbersome control procedure to meet production deadlines. While the process appears compliant on paper, operational reality tells a different story. This gap between documented procedure and actual practice often exposes hidden risks.

Auditors can add value by providing inputs in audit reports which connect risks across functions. Risk registers are frequently organized by departments. Each function identifies its own risks independently. But real risks often emerge between functions, where responsibilities intersect. Experienced auditors look for these interdependencies. Examples include IT changes affecting operational reliability, procurement decisions impacting regulatory compliance or sales commitments creating financial exposure and so on. When risks are examined in isolation, these connections may never be recognized. Auditors with systems thinking identify risks that arise from interactions between processes.

Another useful tip I could share with auditors would be to learn the art of questioning assumptions. A hallmark of experienced auditors is professional skepticism. They challenge assumptions that others take for granted. Common assumptions include:

  • “This control has always worked.”
  • “That vendor is reliable.”
  • “This system cannot fail.”

History repeatedly shows that risks often emerge when organizations become overly confident in their controls. Complacency is in itself a risk. Auditors therefore test assumptions by asking questions as, what happens if this control fails? Or what alternative scenarios could occur? Or perhaps, what early warning signs might exist? This mindset helps auditors uncover risks that have never been formally considered.

Identifying early warning signals should be the organizations’ role. However, it is often missed as the organization gets acclimatized to it. Hidden risks rarely appear suddenly. They often produce early signals which even if missed by the organization can be observed by the experienced auditor. These signals may include:

  • recurring minor incidents.
  • increasing process delays.
  • rising customer complaints.
  • frequent control overrides.

Individually, such signals may appear insignificant. But collectively, they may indicate deeper systemic risks. Experienced auditors are trained to recognize these patterns. They understand that small anomalies often precede major failures.

Therefore, the role of auditor experience is vital. Technical knowledge alone does not enable auditors to detect hidden risks. Experience plays a critical role. Experienced auditors develop several capabilities over time for example their ability to see a pattern recognition. Years of exposure to different organizations allow auditors to recognize patterns that others miss. They may recall similar conditions that led to failures in other organizations and apply those lessons proactively.

Systems thinking is another quality experienced auditors possess. They may be auditing a few selected processes in a particular audit; however, the system perspective must be kept in mind. Experienced auditors understand organizations as interconnected systems. They see how decisions in one area influence outcomes in another. This perspective helps them identify risks that arise from system complexity rather than isolated failures.

Experienced auditors have judgment and intuition. They know that while auditing they must remain evidence based.  Seasoned auditors also develop professional intuition. We are not recommending experience as the basis for audit decisions. Requirements should remain the primary basis. Yet this intuition arises from accumulated experience and allows auditors to recognize subtle indicators that something may be wrong, even when documentation appears complete. They therefore ask questions to unearth hidden risks.

Strengthening risk management through auditing is a desirable trait. When auditors identify risks outside the risk register, they provide tremendous value to leadership. Their insights help organizations:

  • identify emerging threats earlier.
  • improve risk identification processes.
  • strengthen internal controls.
  • enhance organizational resilience.

Most importantly, they shift risk management from a static checklist to a dynamic learning process. Organizations that encourage auditors to explore beyond the register benefit from more realistic and proactive risk oversight. Auditors must start moving beyond the checklist mindset. In some organizations, audits become overly focused on verification. Inexperienced auditors tend to look at questions in terms of, is the risk listed or is the mitigation documented or is the review completed? While these checks are necessary, they represent only the baseline of effective auditing. Experienced auditors move beyond checklist thinking by asking deeper questions:

  • What risks might exist that we have not yet identified?
  • Where could the system fail under stress?
  • What assumptions might be wrong?

This shift transforms auditing from a compliance exercise into a strategic capability.

In conclusion I would opine an experienced auditor is like a risk detective. Risk registers remain valuable tools. They provide structure, accountability, and visibility into known risks. But they cannot capture every emerging or hidden threat. That is why experienced auditors play such a crucial role in risk management. By observing operations, questioning assumptions, connecting systems, and recognizing subtle warning signs, skilled auditors identify risks that others overlook. In many cases, their ability to detect these hidden risks prevents costly failures long before they occur.

Ultimately, the most effective auditors behave not just as compliance reviewers, but as risk detectives who are constantly searching for what the organization has not yet seen.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Audit Focus Areas Under ISO 28000 for 2026 (and Beyond)

-by Dr. IJ Arora

In this article on ISO 28000:2022, “Security and resilience—Security management systems—Requirements,” I want to emphasize the audit focus areas for the standard, based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. This focus will allow organizations registered to the standard to go from mere compliance to resilience, leading to more secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this past year exposed an uncomfortable truth: Many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Organizations should not wait for audits to ensure continual improvement, act on risks, and explore opportunities for improvement. However, the fact of the matter is that nonconformities drive corrective actions. As such, audits play a minor part in providing inputs at the check stage of the plan-do-check-act (PDCA) cycle. The question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

Lessons learned

Audits in 2025 outlined the audit focus areas that will define credible, value-adding ISO 28000 audits going forward. Following are four key audit lessons learned.

Lesson 1: Risk assessments were static in a dynamic threat environment

Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. Although these assessments were often well-structured and aligned with ISO 28000’s clause 4, “Security risk assessment and planning,” they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

Lesson 2: Limited visibility beyond tier 1 suppliers

A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in tier 2 or tier 3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

Lesson 3: Cyber risks were poorly integrated into supply chain security

Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. The use of the harmonized structure presumed that an integrated management system approach could answer this, but organizations did not generally integrate ISO 27001 and ISO 28001 with ISO/IEC 27001:2022, “Information security, cybersecurity and privacy protection—Information security management systems—Requirements.”

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

Lesson 4: Business continuity planning lacked supply chain realism

Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301:2019, “Security and resilience—Business continuity management systems—Requirements.” However, audits in 2025 showed that supply chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Actions to consider

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider the following five actions.

Action 1: Going from risk identification to risk intelligence

From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. Clause 4 of ISO 28000, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:

  • The use of internal and external intelligence sources
  • Defined triggers for risk reassessment
  • Evidence that changes in risk lead to timely management action

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

Action 2: Supplier security assurance, not just evaluation

ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:

  • Supplier segmentation and prioritization
  • Proportionate security controls
  • Evidence of supplier audits, self-assessments, or performance reviews
  • Corrective action and escalation when requirements are not met

Supplier security must be demonstrable and sustained, not assumed.

Action 3: Integration of cyber and physical security controls

Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:

  • Identification of cyber-enabled supply chain risks
  • Coordination between security and IT incident response
  • Protection of logistics data, tracking systems, and access controls

Although ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

Action 4: Testing, exercises, and demonstrated preparedness

In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:

  • Scenario-based exercises relevant to the organization’s supply chain
  • Participation by relevant internal and external stakeholders
  • Lessons learned and system improvements following exercises

Preparedness is best demonstrated through practice, not paperwork.

Action 5: Governance and leadership accountability

A notable trend emerging from late 2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:

  • Management review outputs related to supply chain security
  • Resource allocation decisions
  • Evidence of board or senior leadership awareness of key risks

Implications and conclusions

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are twofold.

First, for auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.

Second, for organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion, I would say 2025 taught us that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity—they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

Above article was recently featured in an Exemplar Global publication – ‘The Auditor’.

Audit Focus Areas Under ISO 28000 for 2026 and beyond

In this article on ISO 28000 I want to emphasize the audit focus areas based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. The emphasis is from mere compliance to resilience leading to secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this period exposed an uncomfortable truth, many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Agreed organizations must not wait for audits to ensure continual improvement, act on risks and to use the opportunities for improvement (OFI). However, this too is true that NCs (nonconformities) drive correction and CA (corrective action). As such audits play a minor part in providing inputs at the check stage of the PDCA (plan-do-check-act) cycle. Therefore, the question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

This article reflects on what audits in 2025 revealed and outlines the audit focus areas that will define credible, value-adding ISO 28000 audits from 2026 onwards. Let us first dwell on what 2025 taught the industry and look at the key audit lessons:

  1. Risk assessments were static in a dynamic threat environment. Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. While these assessments were often well-structured and aligned with ISO 28000 Clause 4 (Security risk assessment and planning), they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

  1. Limited visibility beyond tier-1 suppliers. A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in Tier-2 or Tier-3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

  1. Cyber risks were poorly integrated into the supply chain Security. Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. With harmonized structure (HS) it was presumed that an integrated management system approach could answer this but organizations did not integrate ISO 27001 and ISO 28001 by and large.

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

  1. Business continuity planning lacked supply chain realism. Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301 (Business Continuity). However, audits in 2025 showed that supply-chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider:

  1. Going from risk identification to risk intelligence. From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. ISO 28000 Clause 4, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:
  • The use of internal and external intelligence sources.
  • Defined triggers for risk reassessment.
  • Evidence that changes in risk lead to timely management action.

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

  1. Supplier security assurance, not just evaluation. ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:
  • Supplier segmentation and prioritization.
  • Proportionate security controls.
  • Evidence of supplier audits, self-assessments, or performance reviews.
  • Corrective action and escalation when requirements are not met.

Supplier security must be demonstrable and sustained, not assumed.

  1. Integration of cyber and physical security controls. Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:
  • Identification of cyber-enabled supply chain risks.
  • Coordination between security and IT incident response.
  • Protection of logistics data, tracking systems, and access controls.

While ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

  1. Testing, exercises, and demonstrated preparedness. In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:
  • Scenario-based exercises relevant to the organization’s supply chain.
  • Participation by relevant internal and external stakeholders.
  • Lessons learned and system improvements following exercises.

Preparedness is best demonstrated through practice, not paperwork.

  1. Governance and leadership accountability. A notable trend emerging from late-2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:
  • Management review outputs related to supply chain security.
  • Resource allocation decisions.
  • Evidence of board or senior leadership awareness of key risks.

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are:

  1. For auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.
  2. For organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion I would say, based on QMII experience that what 2025 has taught us is that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity, they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

AS9100 for Tier-2/3 Suppliers: Minimum-Viable Risk & Special Process Control Without Gridlock

AS 9100 is applicable to any organization as a choice but is often a business demand. Aerospace is a vast field and has major and minor players. Does it therefore imply that tier 2 and tier 3 suppliers should go through the same documentation burden as a primary aerospace organization? This is a dilemma faced by tier 2/3 suppliers. I have often thought about this. This short article based on QMII experience is specifically written for AS9100 Tier-2/3 Suppliers and how they can maintain the balance between control and still maintain agility and meet the requirements of the standard.

Tier-2 and Tier-3 aerospace suppliers face a unique dilemma, the need to meet AS9100’s rigorous expectations while working with limited resources and tight delivery schedules. Customer flow-downs, documentation demands, and special-process scrutiny can quickly overwhelm small teams. The key challenge is achieving effective control without unnecessary bureaucracy, preserving the agility that keeps smaller suppliers competitive. This special article is aimed at this need of the tier 2/3 suppliers.

The supplier’s challenge in aerospace quality comes from the aerospace customers bringing layers of requirement complexity, unique quality clauses, FAIR specifics (First Article Inspection Report, and the broader process called First Article Inspection (FAI), special-process certifications, customer portals, and documentation formats. These customer-specific expectations often exceed the base AS9100 standard and force Tier-2/3 suppliers to interpret, prioritize, and integrate a landscape of varied demands. Without a structured approach, they risk creating bloated systems that satisfy auditors on paper but hinder production flow.

Understanding AS9100 Clause 8 – operational controls is therefore essential. Clause 8 is the operational heart of AS9100, setting expectations for planning, process control, risk mitigation, and configuration management. It emphasizes that conformity comes from effective planning and controlled execution, not from sheer volume of documents. Suppliers must ensure that personnel have the right information at the right time, that processes are validated where outcomes cannot be fully verified after the fact, and that changes are managed with discipline. For small suppliers, the goal is implementing these controls proportionally to risk, not copying OEM (original equipment manufacturers)-level tier 1 systems.

Minimum-Viable Risk (MVR) must be considered as a pragmatic interpretation of AS9100. AS9100 demands risk-based thinking, but many small suppliers interpret this as “more forms” instead of “better decisions.” MVR provides a method to match controls to actual consequences. It prevents systems from becoming document-heavy while maintaining the safeguards needed for aerospace.

Basic MVR principles include:

  1. Identifying what can truly go wrong (escape, defect, missed requirement).
  2. Assessing the severity of consequence.
  3. Matching control strength to risk severity—not habit or tradition.
  4. Eliminating duplicate or ritualistic checks.
  5. Documenting the rationale for proportional controls.

MVR (monitoring, verification, and reporting) is simplicity with discipline and is the heart of AS9100 done well. It includes applying MVR to special processes without gridlock. Special processes, like welding, heat treat, coatings, NDT (nondestructive testing), bonding pose inherently higher risks because results cannot be fully verified after production. However, small suppliers can maintain strong control without drowning in paperwork. They should control inputs, not layers of signatures. Validate equipment capability, freeze key parameters, ensure personnel competency, and maintain controlled settings. Excess signatures do not improve quality, controlled inputs do.

The tier 2 and 3 suppliers should build process ownership. Escapes in special processes usually stem from incorrect settings, outdated drawings, or tribal knowledge. An escape is a defect that leaves your organization and reaches the customer. A single-point accountability model, owned by the welding lead, NDT supervisor, or coating tech reduces error pathways better than multiple inspectors. Also, use of one-page critical parameter sheets condenses travelers into one-page sheets listing key variables, limits, and required verifications. This approach focuses on what actually matters to conformity.

Another important organizational priority of tier 2/3 suppliers (AS 9100 clause 4.4.1) is to right size the QMS to their risk level. AS9100 allows flexibility, and small suppliers should embrace it. Not every process requires the same level of documentation, inspection, or validation.

  • Low-risk machining or simple assembly can rely on straightforward checks.
  • High-risk special processes need tighter controls, but not excessive forms.
  • Different supplier tiers have different expectations; Tier-3 machining houses need far less documentation than Tier-1 system integrators. 
  • A right-sized QMS is efficient, compliant, and scalable.

Then there is the use of practical supplier evaluation methods. Supplier oversight does not have to involve 12-page questionnaires or annual onsite audits. AS9100 encourages objective, data-driven oversight:

  • On-Time Delivery (OTD).
  • NCR (non-conformity report) and escape trends.
  • Responsiveness to containment.
  • Corrective action effectiveness.

This approach is more reliable than generic forms and lets purchasing focus on high-risk, high-impact suppliers.

 

Then there are the common audit weaknesses in tier suppliers. QMII’s audit experience reveals recurring issues across Tier-2/3 organizations:

  • Manuals copied from templates that do not match actual practice.
  • Weak configuration control, especially in revision management.
  • Inconsistent traceability in special processes and outsourced steps.
  • Internal audits that check boxes instead of evaluating system effectiveness.
  • Training records that prove attendance but not competency.
  • Excessive documentation without actual operational control.

These weaknesses stem not from lack of effort, but from systems that were built to “pass audits” rather than ensure reliability.

Using MVR to reduce escapes and customer returns. Most escapes involve incorrect flow-downs, poor configuration management, or over-reliance on manual documentation. MVR shifts focus from detection to prevention, reducing escapes by simplifying controls and strengthening process discipline. Early requirement clarification, targeted training, and controlled process inputs all contribute to fewer customer complaints and more predictable performance.

As an example, perhaps a recommendatory timeline from QMII for consideration could be for a Tier-2/3 implementation blueprint (90 Days) would be three phased. Phase 1 – Diagnose (Weeks 1–3).  Map critical processes, identify friction points, and assess risk using MVR. In Phase 2 simplify (Weeks 4–8), streamline travelers, create one-page control sheets, and combine competency and training logs. Finally in Phase 3 – reinforce (Weeks 9–12), clarify process ownership, audit for effectiveness, and pilot new controls. This, I think, builds a lean, compliant AS9100 system with predictable output.

In conclusion and as a call to action I would say a streamlined, risk-aligned AS9100 system allows Tier-2/3 suppliers to maintain compliance without sacrificing agility or productivity. By matching control depth to risk, strengthening special-process discipline, and using data-driven supplier monitoring, organizations can reduce escapes, satisfy customers, and maintain competitive flow.

For suppliers looking to strengthen their capability, QMII offers AS9100 auditor training that emphasizes process-based auditing, practical system improvement, and real-world risk management—equipping teams to build QMSs that are both compliant and efficient.

Procedure, Work Instruction, or Flowchart?

-by Dr. IJ Arora

The choice between writing a procedure or a work instruction is an essential decision when designing a management system. Clause 4.4.1 of ISO 9001:2015 (as well as all the ISO management system standards using the harmonized structure) requires the establishment and implementation of a management system. This management system will have procedures and work instructions and further down the hierarchy, checklists and forms.

Processes can be actualized in many forms. Today, mapped processes make it easy to visualize the functioning of the process. This is an important distinction in quality management systems based on ISO 9001—or for that matter any sector-specific standard like those dedicated to management within maritime, aerospace, etc. Many organizations struggle with when to write a procedure, when to write a work instruction, and how and when a flowchart should be used.

I think the core difference between a procedure and a work instruction is that a procedure answers the question, “What happens and who does it?” A procedure defines the process, its purpose, its sequence (clause 4.4.1b), and who is responsible for the work, perhaps as process owners (clause 4.4.1e). It answers what is to be done, when it must be done, who is responsible, and why it matters. The flowchart then helps visualize the inputs and outputs that flow between the steps.

What is a procedure and how it is used?

A procedure does not tell someone how to do a task; it simply describes the steps or stages necessary to accomplish it. I think of the procedure as the blueprint of the workflow. Therefore, I would recommend using the procedure when multiple people or departments are involved, when there is decision-making or sequencing, when the process crosses functional boundaries, and when documenting the process supports consistency, audits, or training. The procedure is also best when regulatory bodies expect clearly defined processes.

What is a work instruction and how is it used?

On the other hand, a work instruction shows stakeholders how exactly a task is to be accomplished. A work instruction “goes into the weeds” to the extent required by the workforce (depending on their confidence, competence, knowledge, and so on). It describes specific methods, often at a deep level of detail. It answers questions such as:

  • “How do I perform this task?”
  • “What tools, equipment, settings, forms, and/or software steps are required?”
  • “What are the acceptance criteria?”
  • “What do I check and how do I measure performance?”

Remember, work instructions are intended to be simple, direct documents for use by the workforce. Use them when:

  • A task requires technical, step-by-step details
  • Training new personnel
  • Incorrect execution can create quality or safety risks
  • Standardization is essential
  • Variation in execution must be eliminated

What is a flowchart and how is it used?

Flowcharts can technically be used to support both procedures and work instructions, but I generally recommend their use in conjunction with procedures. This helps make the procedure visual by mapping the 50,000-foot view of a process. A flowchart is ideal when the process has multiple decision points, parallel paths, several departments interacting, and inputs/outputs that must be made clear. The flowchart helps avoid the confusion that can come when procedures are described in long paragraphs. Flowcharts make complex processes easy to understand immediately. I therefore believe in flowcharting a procedure when the process needs high-level clarity, the sequence matters, when an organization wants to show interactions between departments, when it supports risk-based thinking, and when you want to simplify training for new personnel.

Flowcharts work best for document control, non-conformances, and corrective action processes, purchasing and supplier management, production scheduling, quality inspection, and testing flows and change management processes (as seen in clauses 5.3e, 6.3., 8.2.4, 8.3.6, and 8.5.6). Flowcharts do not replace work instructions; they complement them.

Final thoughts

To sum up how these tools work together, the practical document hierarchy an organization could consider starting with policy (and why that policy exists), move into documenting the procedure (preferably supported by a flowchart) to convey what happens and in what order, and then crafting work instructions to clarify how to carry out specific tasks. Finally, document everything through records and forms to provide evidence that the work was performed.

All this should connect as a system where a flowchart procedure should describe the process, a work instruction explains each critical task, and the documented information provides traceability. Performance monitoring (clause 9) can be documented via procedures, work instructions, and flowcharts.

 

Note – The above article was recently featured in an Exemplar Global publication ‘The Auditor’. 

Hope Is Never A Plan

Wishful thinking is fine, but it rarely achieves positive results in professional settings. The best path to reach a desired outcome is to implement a structured, process-based management system. It is not a guarantee of success, but if implemented by competent and motivated teams, such a system allows the organization to produce conforming products and services and embrace continual improvements.

I often hear from leadership about their faith in the power of hope, but my experience tells me that hope is never a plan. For those who believe in hope, my advice is to base it on a well-designed management system. There is no need to re-invent the wheel. ISO standards exist for management teams to use.

In organizations of every size, across industries and borders, there is often an invisible reliance on hope. Leaders hope customer complaints will decline. Managers hope processes will perform as intended. Teams hope risks won’t materialize.

Hope can inspire, but it cannot control outcomes. It is not a strategy, and it is certainly not a plan. In contrast, a good management system transforms that hope into structured action, measurable results, and continual improvement.

A Better Way

At my organization, we have long stressed (and said) “Hope is never a plan.” The plan—the real plan—is embedded in the process-based management approach that underlies ISO 9001 and other international standards. This approach replaces uncertainty with understanding and reactivity with resilience.

The problem with hope as a strategy is there is no plan. In times of uncertainty—economic shifts, market volatility, supply chain disruptions—many organizations fall back on hope as a substitute for planning.

However, in my experience, success is built upon the foundation of a process-based management system. Remember the wise words of Deming: “A bad system will beat a good person every time.” The process approach, central to ISO 9001 and mirrored in ISO 14001, ISO 45001, and numerous other ISO standards, recognizes that results come from well-managed processes.

The journey from wishful thinking to structured management is embodied in the process approach, which was first formalized in ISO 9001:2000 and reinforced in ISO 9001:2015. The standard recognizes that consistent, predictable results arise from well-defined and managed processes, not from chance. In particular, sub-clause 4.4 of ISO 9001:2015 requires organizations to establish, implement, maintain, and continually improve a management system, including the processes needed and their interactions.

Where hope says, “Let’s see how it goes,” a process-based system asks:

  • What inputs are required, and what outputs are expected?
  • Who is responsible for the process?
  • What resources and controls are necessary?
  • How will we measure performance?

This thinking moves an organization from reacting to problems to controlling the variables that create success. Rather than managing departments or reacting to problems, organizations use the process approach to:

  • Define interrelated processes that deliver outputs valuable to customers and stakeholders (sub-clause 4.4.1).
  • Identify inputs, activities, and controls within each process (sub-clause 4.4.1).
  • Establish measurable objectives and performance indicators (sub-clauses 6.2 and 9.1.3)
  • Use data and analysis to drive decisions.

This approach replaces hope with evidence, accountability, and continual improvement.

Plan, Do, Check, Act (PDCA) and the Importance of Leadership

The PDCA cycle implies planning as the basis for turning vision into reality. Clause 6 emphasizes “Planning,” i.e., the transformation of organizational context (subclauses 4.1 and 4.2) and risks (sub-clause 6.1) into actionable objectives and opportunities for improvement:

  • Risks and opportunities (not just reacting to issues)
  • Resources and competence needed to achieve results
  • Process interactions that maintain flow and consistency
  • Measurable outcomes that guide continual improvement

In this framework, hope is replaced by proactive thinking, i.e., identifying what could go wrong and preparing responses before it happens. This is far superior to a reactive approach. Of course, in the initial functioning of the management system, any non-conformances (NCs) found will drive corrective action. However, once data accumulates (based on closed NCs and other monitoring and analysis) then those data will drive risks and trends and enable proactive system.

Leadership plays a very important part in the success of an organization. From slogans to systems, true leadership is not about motivational statements but about embedding systems that work even when leaders aren’t watching.

Leaders demonstrate commitment by:

  • Integrating the management system into business strategy (sub-clause 5.1.1c)
  • Promoting process ownership and accountability
  • Ensuring alignment of policies (sub-clause 5.2), objectives (sub-clause 6.2), and actions

A strong system outlives individual personalities—it ensures the organization runs effectively on principles, not just people. What employees learn during their work life at the organization is captured as lessons learned and forms the organization’s corporate knowledge (sub-clause 7.1.6).

Continual improvement (sub-clause 10.3) is the antidote to complacency. Even good systems fail if they stop evolving. ISO’s process-based model ensures continual improvement through:

  • Audits and reviews that identify gaps and inefficiencies
  • Corrective actions that prevent recurrence
  • Performance metrics that inform decision making

Hope says, “Things will get better.” A good management system says, “Here’s how we’ll make them better—and how we’ll know it worked.”

Conclusion

My advice to leaders is to replace hope with a system. Every organization faces uncertainty, but those that succeed do not count on hope—they rely on structured management, clear processes, and evidence-based decisions. Leadership is responsible for maintaining customer focus (sub-clause 5.1.2), understanding customer requirements and associated risks, having thorough knowledge of their products, and carefully selecting vendors.

Uncertainty and hazards must not be passed to employees, users, or other stakeholders. Instead, they should be converted into manageable and low-impact risks. Those risks can then be addressed and/or converted into opportunities for improvement.

In an uncertain world, replacing hope with a system is a must. Hope may be emotionally comforting, but it is operationally dangerous. A good management system, based on ISO 9001’s process approach, gives structure to intention and reliability to performance. It enables organizations to anticipate risks, seize opportunities, and deliver consistent value. It creates confidence among customers, regulators, and employees that the organization is not merely hoping for success—it is planning, executing, and improving toward it.

The above article was recently featured in ‘The Auditor’, an Exemplar Global publication

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Cost-Benefit Analysis: ROI of ISO 9001 Registration for U.S. Manufacturers

For some U.S. manufacturers, registration to ISO 9001 raises one question: “Is it worth the investment?” In other words, how can an organization maximize the benefits of ISO 9001 registration and convert them to a solid return on investment (ROI)?

Analyzing ROI

A consideration of costs and benefits must be included in an ROI analysis to allow manufacturers to make good decisions about ISO 9001 registration. Calculating the value of an effective quality management system (QMS) must include integrating quality and the overall management of the organization (as seen in clause 5.1.1 of ISO 9001). This would include the costs and payoffs that create the real ROI of ISO 9001 registration.

Mere compliance to the language of the standard is not enough; what is required is that ISO 9001 registration leads to competitive advantage. The intent for any manufacturer is to boost efficiency and revenue. In this new environment, where a considerable amount of manufacturing is being re-shored to the United States, ISO 9001 registration matters more than ever. Registration to ISO 9001 is worth it if it brings a clear ROI, such as cash in the bank in the form of cost savings or revenue increases. The answer lies in understanding the ROI that comes from building a strong QMS based on ISO 9001 or other relevant industry-specific standards such as AS9100, etc.

There is no free lunch. In other words, there are costs associated with ISO 9001 registration. Therefore, manufacturers should budget for:

  • Consulting and training. Staff must be prepared to align processes with the requirements of ISO 9001.
  • System development. This may include documenting procedures, implementing software, and updating workflows.
  • Certification audits. Certification bodies (CBs) require fees for initial certification and surveillance audits.
  • Time and resources. These may include employee hours spent on training, process improvements, and audits.

Costs vary depending on company size and can run from tens of thousands of dollars for small factories to much more for large, multi-site operations. The good news is that the benefits of working systematically using a process-based management system (as per clause 4.4.1 or ISO 9001) drive the ROI as the system implementation reduces waste and other production inefficiencies.

Although there can be significant upfront costs, the benefits of ISO 9001 registration often compound over time. These can include operational efficiency with streamlined processes which reduce waste, downtime, and rework, leading directly to lower production costs. Customer confidence and market access improve as the manufacturer consistently produces confirming products and services. Many U.S. manufacturers find ISO 9001 and/or relevant industry-specific standards to be a “ticket to entry” for bidding on contracts, especially in sectors such as automotive, aerospace, and military/defense.

Reducing Risk

Documented processes and corrective action systems reduce the likelihood of costly failures or recalls. Employee engagement improves, resulting in highly motivated teams working within clearly defined roles. Appropriate training oriented toward competency (as seen in clause 7.2 of ISO 9001) reduces errors and boosts productivity. Continual improvement is an added benefit of ISO 9001 as the implementation of the standard promotes a culture of ongoing improvement, helping companies stay competitive in fast-changing markets.

Calculating the ROI of ISO 9001 registration can be assessed by comparing costs against measurable gains such as:

  • Reduced scrap/rework = cost savings
  • Improved on-time delivery = fewer penalties and more repeat orders
  • Access to new markets/contracts = increased revenue
  • Enhanced reputation = long-term customer retention

Example: If a manufacturer spends $50,000 on registration but reduces rework costs by $80,000 and gains $200,000 in new contracts, the ROI is clear and compelling.

Then there is the real-world impact. Studies consistently show manufacturers that achieve ISO 9001 registration experience:

  • 5–15% cost savings from efficiency gains
  • Revenue growth due to market access
  • Improved customer satisfaction scores, leading to stronger long-term partnerships
Final Thoughts

Initially, ISO 9001 registration may seem like a simple expense. But when viewed as an investment, the ROI to be found in ISO 9001 registration becomes clear. It brings definite improved efficiency, stronger customer trust, and measurable financial gains. For U.S. manufacturers competing in global markets, the payoff often far outweighs the cost.

The above article was recently published in an Exemplar Global publication ‘The Auditor’.

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.