Integrated Management System: Combining ISO 9001 and ISO 14001 Without Doubling the Work

An integrated management system (IMS) combining ISO 9001 (quality) and ISO 14001 (environment) is not double the work – it’s half the effort. Built on the shared Annex SL High Level Structure, an IMS eliminates siloed audits, redundant documentation, and conflicting objectives, replacing them with a single, unified framework for operational excellence.

The harmonized standards were not available till about 2012. Yet at QMII, we talked about an integrated approach to management and worked with organizations on the advantages of the integrated management system (IMS) or combined management systems. Why this discussion? It is a classic efficiency and silos battle. Many organizations treat ISO 9001 (quality management system, QMS) and ISO 14001 (environmental management system, EMS) as two separate burdens, often managed by two different departments that barely speak. With the emphasis on ISO 45001 (occupational health and safety, OHS) in recent times, we can see that an environmental impact could cause health consequences. Yet I see large organizations with siloed departments. In this short article I want to challenge and leave this for discussion that this double the work myth is incorrect and how the Annex SL harmonized structure makes various standards natural partners.

This myth of the parallel path must be demystified at the highest level. In many boardrooms, ISO is a word associated with binders, audits, and administrative fatigue. When a company decides to pursue both quality (ISO 9001) and environmental (ISO 14001) and other standards, the gut reaction is often to build two or as many separate systems as for each applicable standard. My first question is why manage your business as if your quality goals, OHS goals, asset management goals, crypto security goals, business continuity goals and your environmental impact etc. happen in different buildings? An integrated management system (IMS) isn’t just possible, it is the only way to achieve true operational harmony and genuine continual improvement.

The foundation of the integrated management system: Annex SL (High Level Structure). The secret weapon for harmonization is Annex SL. Most of the harmonized standards share identical core structures, meaning the skeleton of the management system is already the same. They share terms, definitions, and most importantly, their core clauses.

If I put this in phases, then the phase 1 would be to look at harmonizing the context and leadership. Let us simplify this discussion take just two standards, ISO 9001 and ISO 14001. At the start of both standards, the requirements are nearly indistinguishable in intent:

  • Clause 4: context of the organization would then not require doing two SWOT analyses, just do one. Identify your internal and external issues once. Under clause 4.2, the organization can identify the interested parties. A customer (quality) and a local regulatory body (environment) are both stakeholders. Managing them in one register ensures that environmental compliance doesn’t accidentally bottleneck quality delivery.
  • Clause 5: leadership and commitment where most un-integrated systems fail. Management shouldn’t have to attend two different management review meetings. Integration forces leadership to view quality and sustainability as two sides of the same strategic coin. One policy, one set of roles, and one unified vision based on risks across the organization.

The phase 2: then I would say would be the integrated planning and risk. This is where the heavy lifting of harmonization happens.

  • Clause 6.1: Actions to address risks and opportunities — a cornerstone of risk-based thinking in both standards. In ISO 9001, the organization looks at risks to product quality. In ISO 14001, you look at environmental aspects and impacts. By combining these in a single integrated management system, you see the full picture. For example, a chemical change in manufacturing might improve product durability (9001) but increase hazardous waste (14001). If these systems aren’t harmonized, you solve one problem only to create another.
  • Clause 6.2: objectives and planning harmonization enables the organization to set smart objectives that satisfy both standards simultaneously, such as reducing material waste which then lowers costs (quality) and reduces environmental footprint (environment).

Phase 3: could be unified support and operation and would meet the requirements of clauses 7 & 8 of both standards:

  • Clause 7: support would not need two sets of document control procedures or two different training programs. Clause 7.2 (competence) and clause 7.3 (awareness) can be handled through a single employee onboarding process.
  • Clause 8: operation while ISO 9001 focuses on operational control of the product and ISO 14001 focuses on life-cycle perspective and emergency response, they both live on the shop floor. Integrating these means the organization’s standard operating procedures (SOPs) include environmental safeguards alongside quality checks.

Phase 4: would then be a great advantage to the organization as it would provide the single pane of glass evaluation with the greatest efficiency gain in an IMS coming during the evaluation phase.

  • Clause 9.2: internal audit would be simpler and give more productivity. After all, why pay for or conduct two separate audits? A harmonized internal audit looks at a process from start to finish, checking for quality defects and environmental non-conformance in one walk-through.
  • Clause 9.3: management review would bring quality data and environmental performance to the same table and would allow executives to make resource allocation decisions based on the whole business, not just a siloed report.
  • Clause 10: Improvement. Corrective actions (clause 10.2) should follow the same root-cause analysis (RCA) path within the PDCA (Plan-Do-Check-Act) cycle. Whether a part failed a stress test or a spill occurred, the process for fixing the system and preventing recurrence is identical. The risks are common.

The concluding phase would bring the organization to move from fragmentation in the approach to bringing harmony by combining ISO 9001 and ISO 14001. It isn’t just about saving paper or reducing audit days. It’s about organizational maturity. When organizations harmonize these systems, they stop treating quality and environment as extra tasks and start treating them as the standard way of doing business. For those who still don’t appreciate the value they need to look at the bottom line. Less redundancy, clearer communication, and a unified strategy are the hallmarks of a company that isn’t just compliant, but competitive.

The primary standard ISO 9001 is being updated, and the new version will be available in September 2026. ISO 14001 is already available in the updated version. The update of other standards including the aerospace and other industry standards will follow.  The change to clauses in the updates of the standards is minimal. It means the structure will be same; the emphasis is in the implementation. As organizations move toward ESG (Environmental, Social, and Governance) reporting, having a harmonized ISO 9001/14001 integrated management system (IMS) provides the verified QMS and EMS data needed to back up those high-level sustainability claims.

Then there is the cost saving angle too. Human ROI of systems engineering must be considered. In the world of ISO, we often talk about process efficiency, but we forget that stressed employees are the primary drivers of hidden costs. When a system is fragmented, people are forced to become the glue manually reconciling data, filling out redundant forms, and bracing for audits. That glue is expensive, and eventually, it cracks. There is a need to bridge that connection. Stress drains the bottom line, often termed the friction tax. In a siloed organization, employees pay this friction tax daily perhaps as a decision fatigue when quality and environmental objectives conflict, managers hesitate. Hesitation delays production. Then another one of the common costs is the audit anxiety. If an internal audit feels like a blame game session because the paperwork is a mess, morale drops. Low morale leads to higher turnover and the cost of replacing skilled employees are often twice their annual salary. The need to make double entries wherein technicians must log a chemical spill in the quality log and also in the environmental log. It is not just annoying but a sheer waste of billable hours.

The logic of the harmonized integrated management system therefore provides a clear ROI. Organizations can visualize the connection for example in reduced waste (clause 8.1) where an integrated process ensures that doing it right the first time (quality) also means using only what is necessary (environmental). Less scrap material means lower disposal costs and lower procurement costs.

Leaderships understand the importance of a proactive system. Being predictive is better than a system which is reactive. If the organization is all the time firefighting the stress will be more. A harmonized system uses clause 6.1 (risk management) to prevent fires before they start. It is significantly cheaper to maintain a machine (preventing both a quality defect and an oil leak) than it is to clean up a disaster. Streamlined training is another plus of the harmonized system. By integrating requirements, you reduce the time employees spend in training rooms and increase the time they spend on the value-add line.

The ultimate goal of any management system isn’t to pass an audit. It is to provide a stable platform for the business to grow. When we treat ISO 9001 and ISO 14001 (as also other relevant standards) as separate entities, we inadvertently bake friction into our corporate DNA. We create a system where the left hand ignores the right, and the employees the organization’s most valuable assets, pay the price in stress and burnout. By harmonizing these systems into a true integrated management system (IMS), organizations eliminate the friction tax. Administrative noise is replaced with operational clarity. When a system is integrated, clause 10 (Improvement) ceases to be a chore and becomes a natural byproduct of a focused workforce. In summing up I would say less complexity leads to less stress. Less stress leads to fewer errors. Fewer errors lead to less waste and higher ROI. For those who still view integration as a nice-to-have, remember in an increasingly volatile market, the most successful companies aren’t the ones with the most binders on the shelf they are the ones with the most streamlined, intuitive, and stress-free processes. Integrating ISO 9001 and 14001 isn’t just a technical exercise, it is a commitment to organizational health. When your management systems work in harmony, your people can finally stop managing the system and start managing the business.

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

The Hidden Signals of Process Breakdown

When implementing management system, the organizations are really not trying to reinvent the wheel.  The availability of ISO standards gives us a well tried, over the years updated approach in terms of the available clauses. The PDCA (plan, do, check and act) cycle approach in the harmonized standards enables designing an effective management system, monitoring it and updating it to not just produce confirming products and services but also to use inputs at the check stage to continually improve it. Yet the systems fail. Non-conforming products are released. Is there then an anatomy of a quiet failure? Indicators that will enable discovering these signals proactively. If that can be analyzed organizations would appreciate these hidden signals of the system breakdown and take proactive measures. Risks and trends are data driven. Can we expect our auditors to proactively recognize these.

There is the lagging indicator trap between being reactive and proactive. Up to the 2015 version of ISO 9001 (and equivalent industry specific standards in the harmonized structure) preventive action was taken based on data, invariably at the act stage of the PDCA cycle. From the 2015 version onward clause 6.1 introduced the risk appreciation requirement at the plan stage itself and then throughout the work cycle. Separating knowledge (clause 7.1.6 of ISO 9001) from competence (clause 7.2 of ISO 9001), has introduced us to corporate knowledge in terms of lessons learnt. Leadership in analyzing changing context and risk thereof should be on the lookout for indicators.  Therefore, the PA (preventive action) concept needed a change to risk. The idea was not to throw the baby with the bathwater. NC (non-conformity) did drive correction and CA (corrective action), however, as the organization collected data it became proactive wherein data drives risk and trends. Waiting for a nonconformity (NC) is a reactive strategy. Therefore, organizations should not be we waiting for NCs. By the time an NC appears, the financial or quality damage is already done. Being proactive therefore, is the need of a functioning system.

With the ISO 9001 revised 2026 version expected in September 2026 there is, quite correctly the need to strengthen the check stage. The organizations will expect better auditing instead of just a check list being completed. The auditor’s sixth sense to ask better questions and to establish how the system is working will be important. Just having a frame and expecting it to do magic and pinpoint failures of the system is not sufficient, but the need is for a high-level pattern recognition. The skilled auditors look for the erosion of intent, where the way work is done drifts away from how it was designed. They need is to provide these inputs during audits to the leadership.

For the organizations and the auditors there are many signals of this hidden failure. There is the tribal knowledge drift as recognizing the symptoms, where the question is: “how do you do XXX?” and the employee reaches for a handwritten sticky note or a personal notebook instead of the official SOP (standard operating procedure). The hidden meaning here is that the official process is likely too rigid, outdated, or inaccessible. This is indicative of a workaround culture in its infancy. Then there is the risk scalability. The process lives in heads, not in the systems. This is indicated by when those people leave, the process collapses. Technically it was not a system. The system instead of being a working process was dependent on individual competence.

Good auditors are conscious of another signal indicated by the language used and the linguistic friction. The Symptom here is in phrases like “we usually just…”, or “on a good day, we…”, or “that’s just how we have to do it.” In these and similar cases the hidden meaning is indicating to the organization and to the auditors that the standard process is no longer the path of least resistance. For a good auditor the clue is the hesitation or glance-exchanges between team members when answering simple procedural questions. Looking ahead at expectations of the ISO 9001, 2026 version of the standard the auditors need to be conscious of how the system is actually working, working or not working.

The next signal to watch out for could be the ghost workload (shadow processes) indicated by the excessive use of excel trackers to manage data that should be in the ERP/QMS, or the need for frequent offline meetings to fix recurring errors or the use of tiger teams to cover the back log. The hidden meaning of this should be clear. The formal system is failing to provide the necessary utility. Also, that the risk is not being proactively data driven. Data integrity and lack of visibility by the management leads to the leadership  seeing a green dashboard, when the reality is red and it is showing a mirage of being held together by manual labor.

Related to this is the physical and digital clutter. The clear symptom of this e.g.  in a physical plant, it’s unlabeled bins or “red tag” areas that haven’t moved in months. In a digital space, it’s numerous versions of the same document with names like final_vrn2_use_this.pdf. etc. The implication of this is the loss of 5S discipline (sort, set in order, shine, standardize, sustain). Clutter is a visual representation of a mind and of a process that has lost its focus.

Good auditors must also consider the human element and its connected emotional cues like the defensiveness vs. transparency conflict. If a process owner is overly protective of their territory, they are often hiding a breakdown they don’t know how to fix. It can also be a conflict between fatigue and apathy leading to when and why? This is answered with rationalization, because that’s the rule, the connection between the task and the value (quality) has been severed.

My concluding thought is to prepare for implementation of ISO 9001:2026 (expected in September 2026). In preparing understand that the auditors should be becoming proactive auditors. They need to shift the goal and change their attitude. The goal isn’t to catch people; it’s to catch the process before it fails them and therefore the organization. The value add is that a skilled auditor saves the company money by identifying these frictions before they turn into a notice of inspection by a statutory body, a client, a recall, or a lost certification. Organizations should expect their auditors to catch these hidden signals of process breakdown timely and report them. A good audit report should include these and this should be the expectation.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Auditing Risk Management: How Experienced Auditors Identify Risks That Aren’t Listed in the Risk Register.

Organizations today rely heavily on risk registers to track and manage potential threats. Risk registers are useful tools, and they document known risks, assess their likelihood and impact, and assign ownership for mitigation actions. They help leadership visualize risk exposure and provide a structured way to prioritize responses.

However, risk registers have their limits. Experienced auditors know something critical, that the most damaging risks are often the ones that never appear in the register. A risk register represents what the organization already knows or believes it knows. The context of the organization changes. A risk register reflects the thinking of the team that created it. But risks evolve, environments change, and assumptions become outdated. As a result, relying solely on the documented register can create a false sense of security. Seasoned auditors understand that their responsibility goes beyond verifying that risks are listed and mitigations are documented. Their deeper role is to identify blind spots and record risks that exist outside the documented system. This is where experience, professional skepticism, and systems thinking become essential. Skilled auditors recognize patterns, inconsistencies, and subtle signals that indicate hidden risks. QMII specializes in risk and with our forty plus years in the system field, in this article, we explore how experienced auditors uncover risks that never make it into the risk register and why this capability is essential for effective risk management.

The questions therefore are, why risk registers miss critical risks. I think, before examining how auditors uncover hidden risks, it is important to understand why risk registers are incomplete.

Risk registers reflect perception and often not the reality. Risk registers are typically compiled during structured workshops or periodic reviews. Participants identify risks based on their knowledge and experience. But human perception is limited. People tend to list:

  • Risks they have seen before.
  • Risks that are already familiar.
  • Risks that are easy to articulate.

But unfamiliar or emerging threats often remain invisible. For example, a manufacturing team might focus heavily on supply chain delays while overlooking risks related to cybersecurity vulnerabilities within their operational technology systems. Experienced auditors recognize this limitation and therefore treat the risk register as a starting point, not the final word.

Then there is the organizational bias which influences risk Identification. Risk registers can be influenced by internal politics or cultural pressures. Some risks may be downplayed because:

  • They reflect poorly on leadership decisions.
  • They expose systemic weaknesses.
  • They challenge existing strategies.

In such cases, risks may be intentionally or unintentionally omitted. Auditors who understand organizational dynamics pay attention not only to what is documented, but also what is missing.

Please also consider that risks often evolve faster than documentation. The modern risk landscape changes rapidly due to:

  • Technological advancements.
  • Regulatory changes.
  • Market disruptions.
  • Geopolitical instability.

Risk registers are often updated annually or quarterly. But emerging risks can develop far faster than review cycles. Experienced auditors therefore examine current conditions, not just documented assessments. The experienced auditors detect unlisted risks. The difference between routine auditing and expert auditing lies in how auditors think. Experienced auditors do not simply verify compliance. They analyze systems, behaviors, and signals that reveal underlying vulnerabilities. The ISO 9001 version expected in September 2026 expects organizations to go beyond check lists and see how their system works to produce confirming products and services.  The auditors of the future must work to providing these inputs. Several approaches distinguish their work.

The primary is developing the attitude and aptitude where the auditors look for process weaknesses, not just risk entries. Experienced auditors start by examining processes rather than documentation. Instead of asking: “Is this risk listed in the register?” They ask: “Where could this process fail?” Every process contains inherent vulnerabilities. Skilled auditors identify points where failure could occur, including:

  • unclear responsibilities.
  • lack of monitoring.
  • excessive reliance on manual steps.
  • insufficient controls.

For example, if a company relies heavily on one individual to approve high-value financial transactions, an auditor immediately recognizes concentration of authority risk, even if the risk register never mentions it. In other words, auditors uncover risks by studying how work actually happens.

Observing operational reality is another positive trait in an auditor. Documentation often describes how processes are supposed to work. But experienced auditors know that actual practice frequently differs from documented procedures. They therefore observe operations directly by speaking with frontline staff, watching processes in action and asking open-ended questions. These conversations often reveal informal workarounds, shortcuts, or unofficial practices that introduce risk. For instance, employees might bypass a cumbersome control procedure to meet production deadlines. While the process appears compliant on paper, operational reality tells a different story. This gap between documented procedure and actual practice often exposes hidden risks.

Auditors can add value by providing inputs in audit reports which connect risks across functions. Risk registers are frequently organized by departments. Each function identifies its own risks independently. But real risks often emerge between functions, where responsibilities intersect. Experienced auditors look for these interdependencies. Examples include IT changes affecting operational reliability, procurement decisions impacting regulatory compliance or sales commitments creating financial exposure and so on. When risks are examined in isolation, these connections may never be recognized. Auditors with systems thinking identify risks that arise from interactions between processes.

Another useful tip I could share with auditors would be to learn the art of questioning assumptions. A hallmark of experienced auditors is professional skepticism. They challenge assumptions that others take for granted. Common assumptions include:

  • “This control has always worked.”
  • “That vendor is reliable.”
  • “This system cannot fail.”

History repeatedly shows that risks often emerge when organizations become overly confident in their controls. Complacency is in itself a risk. Auditors therefore test assumptions by asking questions as, what happens if this control fails? Or what alternative scenarios could occur? Or perhaps, what early warning signs might exist? This mindset helps auditors uncover risks that have never been formally considered.

Identifying early warning signals should be the organizations’ role. However, it is often missed as the organization gets acclimatized to it. Hidden risks rarely appear suddenly. They often produce early signals which even if missed by the organization can be observed by the experienced auditor. These signals may include:

  • recurring minor incidents.
  • increasing process delays.
  • rising customer complaints.
  • frequent control overrides.

Individually, such signals may appear insignificant. But collectively, they may indicate deeper systemic risks. Experienced auditors are trained to recognize these patterns. They understand that small anomalies often precede major failures.

Therefore, the role of auditor experience is vital. Technical knowledge alone does not enable auditors to detect hidden risks. Experience plays a critical role. Experienced auditors develop several capabilities over time for example their ability to see a pattern recognition. Years of exposure to different organizations allow auditors to recognize patterns that others miss. They may recall similar conditions that led to failures in other organizations and apply those lessons proactively.

Systems thinking is another quality experienced auditors possess. They may be auditing a few selected processes in a particular audit; however, the system perspective must be kept in mind. Experienced auditors understand organizations as interconnected systems. They see how decisions in one area influence outcomes in another. This perspective helps them identify risks that arise from system complexity rather than isolated failures.

Experienced auditors have judgment and intuition. They know that while auditing they must remain evidence based.  Seasoned auditors also develop professional intuition. We are not recommending experience as the basis for audit decisions. Requirements should remain the primary basis. Yet this intuition arises from accumulated experience and allows auditors to recognize subtle indicators that something may be wrong, even when documentation appears complete. They therefore ask questions to unearth hidden risks.

Strengthening risk management through auditing is a desirable trait. When auditors identify risks outside the risk register, they provide tremendous value to leadership. Their insights help organizations:

  • identify emerging threats earlier.
  • improve risk identification processes.
  • strengthen internal controls.
  • enhance organizational resilience.

Most importantly, they shift risk management from a static checklist to a dynamic learning process. Organizations that encourage auditors to explore beyond the register benefit from more realistic and proactive risk oversight. Auditors must start moving beyond the checklist mindset. In some organizations, audits become overly focused on verification. Inexperienced auditors tend to look at questions in terms of, is the risk listed or is the mitigation documented or is the review completed? While these checks are necessary, they represent only the baseline of effective auditing. Experienced auditors move beyond checklist thinking by asking deeper questions:

  • What risks might exist that we have not yet identified?
  • Where could the system fail under stress?
  • What assumptions might be wrong?

This shift transforms auditing from a compliance exercise into a strategic capability.

In conclusion I would opine an experienced auditor is like a risk detective. Risk registers remain valuable tools. They provide structure, accountability, and visibility into known risks. But they cannot capture every emerging or hidden threat. That is why experienced auditors play such a crucial role in risk management. By observing operations, questioning assumptions, connecting systems, and recognizing subtle warning signs, skilled auditors identify risks that others overlook. In many cases, their ability to detect these hidden risks prevents costly failures long before they occur.

Ultimately, the most effective auditors behave not just as compliance reviewers, but as risk detectives who are constantly searching for what the organization has not yet seen.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Audit Focus Areas Under ISO 28000 for 2026 (and Beyond)

-by Dr. IJ Arora

In this article on ISO 28000:2022, “Security and resilience—Security management systems—Requirements,” I want to emphasize the audit focus areas for the standard, based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. This focus will allow organizations registered to the standard to go from mere compliance to resilience, leading to more secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this past year exposed an uncomfortable truth: Many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Organizations should not wait for audits to ensure continual improvement, act on risks, and explore opportunities for improvement. However, the fact of the matter is that nonconformities drive corrective actions. As such, audits play a minor part in providing inputs at the check stage of the plan-do-check-act (PDCA) cycle. The question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

Lessons learned

Audits in 2025 outlined the audit focus areas that will define credible, value-adding ISO 28000 audits going forward. Following are four key audit lessons learned.

Lesson 1: Risk assessments were static in a dynamic threat environment

Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. Although these assessments were often well-structured and aligned with ISO 28000’s clause 4, “Security risk assessment and planning,” they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

Lesson 2: Limited visibility beyond tier 1 suppliers

A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in tier 2 or tier 3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

Lesson 3: Cyber risks were poorly integrated into supply chain security

Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. The use of the harmonized structure presumed that an integrated management system approach could answer this, but organizations did not generally integrate ISO 27001 and ISO 28001 with ISO/IEC 27001:2022, “Information security, cybersecurity and privacy protection—Information security management systems—Requirements.”

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

Lesson 4: Business continuity planning lacked supply chain realism

Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301:2019, “Security and resilience—Business continuity management systems—Requirements.” However, audits in 2025 showed that supply chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Actions to consider

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider the following five actions.

Action 1: Going from risk identification to risk intelligence

From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. Clause 4 of ISO 28000, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:

  • The use of internal and external intelligence sources
  • Defined triggers for risk reassessment
  • Evidence that changes in risk lead to timely management action

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

Action 2: Supplier security assurance, not just evaluation

ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:

  • Supplier segmentation and prioritization
  • Proportionate security controls
  • Evidence of supplier audits, self-assessments, or performance reviews
  • Corrective action and escalation when requirements are not met

Supplier security must be demonstrable and sustained, not assumed.

Action 3: Integration of cyber and physical security controls

Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:

  • Identification of cyber-enabled supply chain risks
  • Coordination between security and IT incident response
  • Protection of logistics data, tracking systems, and access controls

Although ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

Action 4: Testing, exercises, and demonstrated preparedness

In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:

  • Scenario-based exercises relevant to the organization’s supply chain
  • Participation by relevant internal and external stakeholders
  • Lessons learned and system improvements following exercises

Preparedness is best demonstrated through practice, not paperwork.

Action 5: Governance and leadership accountability

A notable trend emerging from late 2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:

  • Management review outputs related to supply chain security
  • Resource allocation decisions
  • Evidence of board or senior leadership awareness of key risks

Implications and conclusions

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are twofold.

First, for auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.

Second, for organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion, I would say 2025 taught us that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity—they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

Above article was recently featured in an Exemplar Global publication – ‘The Auditor’.

Procedure, Work Instruction, or Flowchart?

-by Dr. IJ Arora

The choice between writing a procedure or a work instruction is an essential decision when designing a management system. Clause 4.4.1 of ISO 9001:2015 (as well as all the ISO management system standards using the harmonized structure) requires the establishment and implementation of a management system. This management system will have procedures and work instructions and further down the hierarchy, checklists and forms.

Processes can be actualized in many forms. Today, mapped processes make it easy to visualize the functioning of the process. This is an important distinction in quality management systems based on ISO 9001—or for that matter any sector-specific standard like those dedicated to management within maritime, aerospace, etc. Many organizations struggle with when to write a procedure, when to write a work instruction, and how and when a flowchart should be used.

I think the core difference between a procedure and a work instruction is that a procedure answers the question, “What happens and who does it?” A procedure defines the process, its purpose, its sequence (clause 4.4.1b), and who is responsible for the work, perhaps as process owners (clause 4.4.1e). It answers what is to be done, when it must be done, who is responsible, and why it matters. The flowchart then helps visualize the inputs and outputs that flow between the steps.

What is a procedure and how it is used?

A procedure does not tell someone how to do a task; it simply describes the steps or stages necessary to accomplish it. I think of the procedure as the blueprint of the workflow. Therefore, I would recommend using the procedure when multiple people or departments are involved, when there is decision-making or sequencing, when the process crosses functional boundaries, and when documenting the process supports consistency, audits, or training. The procedure is also best when regulatory bodies expect clearly defined processes.

What is a work instruction and how is it used?

On the other hand, a work instruction shows stakeholders how exactly a task is to be accomplished. A work instruction “goes into the weeds” to the extent required by the workforce (depending on their confidence, competence, knowledge, and so on). It describes specific methods, often at a deep level of detail. It answers questions such as:

  • “How do I perform this task?”
  • “What tools, equipment, settings, forms, and/or software steps are required?”
  • “What are the acceptance criteria?”
  • “What do I check and how do I measure performance?”

Remember, work instructions are intended to be simple, direct documents for use by the workforce. Use them when:

  • A task requires technical, step-by-step details
  • Training new personnel
  • Incorrect execution can create quality or safety risks
  • Standardization is essential
  • Variation in execution must be eliminated

What is a flowchart and how is it used?

Flowcharts can technically be used to support both procedures and work instructions, but I generally recommend their use in conjunction with procedures. This helps make the procedure visual by mapping the 50,000-foot view of a process. A flowchart is ideal when the process has multiple decision points, parallel paths, several departments interacting, and inputs/outputs that must be made clear. The flowchart helps avoid the confusion that can come when procedures are described in long paragraphs. Flowcharts make complex processes easy to understand immediately. I therefore believe in flowcharting a procedure when the process needs high-level clarity, the sequence matters, when an organization wants to show interactions between departments, when it supports risk-based thinking, and when you want to simplify training for new personnel.

Flowcharts work best for document control, non-conformances, and corrective action processes, purchasing and supplier management, production scheduling, quality inspection, and testing flows and change management processes (as seen in clauses 5.3e, 6.3., 8.2.4, 8.3.6, and 8.5.6). Flowcharts do not replace work instructions; they complement them.

Final thoughts

To sum up how these tools work together, the practical document hierarchy an organization could consider starting with policy (and why that policy exists), move into documenting the procedure (preferably supported by a flowchart) to convey what happens and in what order, and then crafting work instructions to clarify how to carry out specific tasks. Finally, document everything through records and forms to provide evidence that the work was performed.

All this should connect as a system where a flowchart procedure should describe the process, a work instruction explains each critical task, and the documented information provides traceability. Performance monitoring (clause 9) can be documented via procedures, work instructions, and flowcharts.

 

Note – The above article was recently featured in an Exemplar Global publication ‘The Auditor’. 

Hope Is Never A Plan

Wishful thinking is fine, but it rarely achieves positive results in professional settings. The best path to reach a desired outcome is to implement a structured, process-based management system. It is not a guarantee of success, but if implemented by competent and motivated teams, such a system allows the organization to produce conforming products and services and embrace continual improvements.

I often hear from leadership about their faith in the power of hope, but my experience tells me that hope is never a plan. For those who believe in hope, my advice is to base it on a well-designed management system. There is no need to re-invent the wheel. ISO standards exist for management teams to use.

In organizations of every size, across industries and borders, there is often an invisible reliance on hope. Leaders hope customer complaints will decline. Managers hope processes will perform as intended. Teams hope risks won’t materialize.

Hope can inspire, but it cannot control outcomes. It is not a strategy, and it is certainly not a plan. In contrast, a good management system transforms that hope into structured action, measurable results, and continual improvement.

A Better Way

At my organization, we have long stressed (and said) “Hope is never a plan.” The plan—the real plan—is embedded in the process-based management approach that underlies ISO 9001 and other international standards. This approach replaces uncertainty with understanding and reactivity with resilience.

The problem with hope as a strategy is there is no plan. In times of uncertainty—economic shifts, market volatility, supply chain disruptions—many organizations fall back on hope as a substitute for planning.

However, in my experience, success is built upon the foundation of a process-based management system. Remember the wise words of Deming: “A bad system will beat a good person every time.” The process approach, central to ISO 9001 and mirrored in ISO 14001, ISO 45001, and numerous other ISO standards, recognizes that results come from well-managed processes.

The journey from wishful thinking to structured management is embodied in the process approach, which was first formalized in ISO 9001:2000 and reinforced in ISO 9001:2015. The standard recognizes that consistent, predictable results arise from well-defined and managed processes, not from chance. In particular, sub-clause 4.4 of ISO 9001:2015 requires organizations to establish, implement, maintain, and continually improve a management system, including the processes needed and their interactions.

Where hope says, “Let’s see how it goes,” a process-based system asks:

  • What inputs are required, and what outputs are expected?
  • Who is responsible for the process?
  • What resources and controls are necessary?
  • How will we measure performance?

This thinking moves an organization from reacting to problems to controlling the variables that create success. Rather than managing departments or reacting to problems, organizations use the process approach to:

  • Define interrelated processes that deliver outputs valuable to customers and stakeholders (sub-clause 4.4.1).
  • Identify inputs, activities, and controls within each process (sub-clause 4.4.1).
  • Establish measurable objectives and performance indicators (sub-clauses 6.2 and 9.1.3)
  • Use data and analysis to drive decisions.

This approach replaces hope with evidence, accountability, and continual improvement.

Plan, Do, Check, Act (PDCA) and the Importance of Leadership

The PDCA cycle implies planning as the basis for turning vision into reality. Clause 6 emphasizes “Planning,” i.e., the transformation of organizational context (subclauses 4.1 and 4.2) and risks (sub-clause 6.1) into actionable objectives and opportunities for improvement:

  • Risks and opportunities (not just reacting to issues)
  • Resources and competence needed to achieve results
  • Process interactions that maintain flow and consistency
  • Measurable outcomes that guide continual improvement

In this framework, hope is replaced by proactive thinking, i.e., identifying what could go wrong and preparing responses before it happens. This is far superior to a reactive approach. Of course, in the initial functioning of the management system, any non-conformances (NCs) found will drive corrective action. However, once data accumulates (based on closed NCs and other monitoring and analysis) then those data will drive risks and trends and enable proactive system.

Leadership plays a very important part in the success of an organization. From slogans to systems, true leadership is not about motivational statements but about embedding systems that work even when leaders aren’t watching.

Leaders demonstrate commitment by:

  • Integrating the management system into business strategy (sub-clause 5.1.1c)
  • Promoting process ownership and accountability
  • Ensuring alignment of policies (sub-clause 5.2), objectives (sub-clause 6.2), and actions

A strong system outlives individual personalities—it ensures the organization runs effectively on principles, not just people. What employees learn during their work life at the organization is captured as lessons learned and forms the organization’s corporate knowledge (sub-clause 7.1.6).

Continual improvement (sub-clause 10.3) is the antidote to complacency. Even good systems fail if they stop evolving. ISO’s process-based model ensures continual improvement through:

  • Audits and reviews that identify gaps and inefficiencies
  • Corrective actions that prevent recurrence
  • Performance metrics that inform decision making

Hope says, “Things will get better.” A good management system says, “Here’s how we’ll make them better—and how we’ll know it worked.”

Conclusion

My advice to leaders is to replace hope with a system. Every organization faces uncertainty, but those that succeed do not count on hope—they rely on structured management, clear processes, and evidence-based decisions. Leadership is responsible for maintaining customer focus (sub-clause 5.1.2), understanding customer requirements and associated risks, having thorough knowledge of their products, and carefully selecting vendors.

Uncertainty and hazards must not be passed to employees, users, or other stakeholders. Instead, they should be converted into manageable and low-impact risks. Those risks can then be addressed and/or converted into opportunities for improvement.

In an uncertain world, replacing hope with a system is a must. Hope may be emotionally comforting, but it is operationally dangerous. A good management system, based on ISO 9001’s process approach, gives structure to intention and reliability to performance. It enables organizations to anticipate risks, seize opportunities, and deliver consistent value. It creates confidence among customers, regulators, and employees that the organization is not merely hoping for success—it is planning, executing, and improving toward it.

The above article was recently featured in ‘The Auditor’, an Exemplar Global publication

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Cost-Benefit Analysis: ROI of ISO 9001 Registration for U.S. Manufacturers

For some U.S. manufacturers, registration to ISO 9001 raises one question: “Is it worth the investment?” In other words, how can an organization maximize the benefits of ISO 9001 registration and convert them to a solid return on investment (ROI)?

Analyzing ROI

A consideration of costs and benefits must be included in an ROI analysis to allow manufacturers to make good decisions about ISO 9001 registration. Calculating the value of an effective quality management system (QMS) must include integrating quality and the overall management of the organization (as seen in clause 5.1.1 of ISO 9001). This would include the costs and payoffs that create the real ROI of ISO 9001 registration.

Mere compliance to the language of the standard is not enough; what is required is that ISO 9001 registration leads to competitive advantage. The intent for any manufacturer is to boost efficiency and revenue. In this new environment, where a considerable amount of manufacturing is being re-shored to the United States, ISO 9001 registration matters more than ever. Registration to ISO 9001 is worth it if it brings a clear ROI, such as cash in the bank in the form of cost savings or revenue increases. The answer lies in understanding the ROI that comes from building a strong QMS based on ISO 9001 or other relevant industry-specific standards such as AS9100, etc.

There is no free lunch. In other words, there are costs associated with ISO 9001 registration. Therefore, manufacturers should budget for:

  • Consulting and training. Staff must be prepared to align processes with the requirements of ISO 9001.
  • System development. This may include documenting procedures, implementing software, and updating workflows.
  • Certification audits. Certification bodies (CBs) require fees for initial certification and surveillance audits.
  • Time and resources. These may include employee hours spent on training, process improvements, and audits.

Costs vary depending on company size and can run from tens of thousands of dollars for small factories to much more for large, multi-site operations. The good news is that the benefits of working systematically using a process-based management system (as per clause 4.4.1 or ISO 9001) drive the ROI as the system implementation reduces waste and other production inefficiencies.

Although there can be significant upfront costs, the benefits of ISO 9001 registration often compound over time. These can include operational efficiency with streamlined processes which reduce waste, downtime, and rework, leading directly to lower production costs. Customer confidence and market access improve as the manufacturer consistently produces confirming products and services. Many U.S. manufacturers find ISO 9001 and/or relevant industry-specific standards to be a “ticket to entry” for bidding on contracts, especially in sectors such as automotive, aerospace, and military/defense.

Reducing Risk

Documented processes and corrective action systems reduce the likelihood of costly failures or recalls. Employee engagement improves, resulting in highly motivated teams working within clearly defined roles. Appropriate training oriented toward competency (as seen in clause 7.2 of ISO 9001) reduces errors and boosts productivity. Continual improvement is an added benefit of ISO 9001 as the implementation of the standard promotes a culture of ongoing improvement, helping companies stay competitive in fast-changing markets.

Calculating the ROI of ISO 9001 registration can be assessed by comparing costs against measurable gains such as:

  • Reduced scrap/rework = cost savings
  • Improved on-time delivery = fewer penalties and more repeat orders
  • Access to new markets/contracts = increased revenue
  • Enhanced reputation = long-term customer retention

Example: If a manufacturer spends $50,000 on registration but reduces rework costs by $80,000 and gains $200,000 in new contracts, the ROI is clear and compelling.

Then there is the real-world impact. Studies consistently show manufacturers that achieve ISO 9001 registration experience:

  • 5–15% cost savings from efficiency gains
  • Revenue growth due to market access
  • Improved customer satisfaction scores, leading to stronger long-term partnerships
Final Thoughts

Initially, ISO 9001 registration may seem like a simple expense. But when viewed as an investment, the ROI to be found in ISO 9001 registration becomes clear. It brings definite improved efficiency, stronger customer trust, and measurable financial gains. For U.S. manufacturers competing in global markets, the payoff often far outweighs the cost.

The above article was recently published in an Exemplar Global publication ‘The Auditor’.

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Building a Quality Culture: The Role of Leadership

When the leadership at a U.S. industrial plant makes the strategic decision to roll out certification to ISO 9001, their first instinct is often to focus on documentation, audits, and procedures. They start by looking for a consultant who often (for quick money) provides a template. That is the start of misery for an organization.

A Better Way To Begin

The “As-Is” of the management system should be the start of this process. What has been developed over the years should not be forgotten or lost! The truth is that no checklist or manual can build a true quality culture. The secret ingredient in implementing ISO 9001 is the involvement of leadership in developing the system. As per sub-clause 5.1 (“Leadership and commitment”), their total involvement and commitment is required, in addition to others who assist them in this role, as per sub-clause 5.3 (“Organizational roles, responsibilities and authorities”).

Why leaders can make or break ISO 9001 effectiveness is an important question, and taking positive action to do so is therefore a vital decision. Employees don’t take their cues from policies—they take them from people. If leaders treat ISO 9001 as “just another certification,” that’s exactly how the workforce will see it. On the other hand, when leadership is visible, engaged, and committed, quality stops being a buzzword and becomes a way of working. A system that has the support of leadership has the best chance to produce conforming products and services and also ensure continual improvement.

ISO 9001 makes this clear. Clause 5 (“Leadership”) puts accountability squarely onto the leadership. It’s not just the quality manager’s responsibility anymore—it’s a business-wide effort, and leaders must own it. It is leadership that matters in ISO 9001 and is an important aspect of the process.

Clause 5 emphasizes that leaders must:

  • Demonstrate commitment to the quality management system (QMS)
  • Align quality objectives with organizational strategy
  • Promote a culture of continual improvement

The View From The Shop Floor

In U.S. industrial plants, where efficiency and production targets often dominate discussions, leadership involvement ensures quality doesn’t get sidelined. Leaders act as role models, showing that meeting quality objectives is as important as meeting delivery deadlines.

When auditors look at the implementation of a management system standard like ISO 9001, they need to be able to clearly evidence what leadership involvement looks like in practice. There are numerous indicators, most of them based on ISO 9001 subclauses 5.1, 5.1.2 (“Customer focus”), 5.2 (“Policy”), 6.1 (“Actions to address risks and opportunities”), 6.2 (“Quality objectives and planning to achieve them”), and 10.3 (“Continual improvement”). To generalize these into simple language I would say these would include the following:

  • Setting the tone. A plant manager who opens every team meeting with a quality update shows that it matters as much as production numbers.
  • Walking the floor. Leaders who regularly join quality reviews or stop by the line to ask about issues send a strong signal of support.
  • Connecting quality to strategy. Instead of treating ISO 9001 as paperwork, leaders can frame it as a competitive edge, leading to fewer defects, happier customers, and stronger market position.
  • Celebrating wins. Recognizing teams for continuous improvement projects—no matter how small—builds momentum and pride.

Culture is caught, not taught. We can train employees on ISO 9001 requirements, but culture is shaped by what leaders actually do. Creating an environment of quality is a leadership accountability issue. When executives understand the value of nonconformities as the drivers of corrective action and improvement, follow procedures, welcome audits, and act on feedback, employees naturally mirror those behaviors. Over time, this creates a culture where quality isn’t “extra work”—it’s simply the way we work. It is then that the organization can go from a reactive to a proactive manufacturing entity.

The return on investment in ISO 9001 can be traced to sub-clause 6.2 and the achievement of specific quality improvement objectives. Industrial plants that embrace ISO 9001 leadership involvement don’t just pass audits. They see less rework, stronger customer trust, and a workforce that takes pride in doing things right the first time. In today’s competitive manufacturing landscape, that’s not just compliance—it’s survival.

Bringing It Forward

Five practical steps leaders can take to lead the industry may include the following:

  1. Communicating the vision. It is important to clearly articulate why ISO 9001 matters—not only for certification, but for customer trust, employee pride, and long-term competitiveness.
  2. Allocating resources. Quality initiatives fail when they’re underfunded. Leaders must ensure sufficient training, technology, and staffing to support ISO 9001 compliance. Where they cannot provide resources, they must assume the risk and adjust objectives.
  3. Engaging with the employees. This includes walking the floor, participating in quality meetings, and recognizing contributions. All of these actions reinforce that quality is everyone’s responsibility.
  4. Integrating quality into the organization’s strategy. Quality goals should not be separate from business goals. For example, reducing defects can be tied directly to cost savings and improved customer satisfaction.
  5. Leading by example. Leaders who adhere to procedures, value data-driven decisions, and embrace audits demonstrate that ISO 9001 is part of the plant’s DNA.

ISO 9001 isn’t a binder sitting on a shelf. It’s a leadership-driven culture shift, and when leaders lead the way, the entire plant follows. Just keeping the binder on the shelf is no good. It may get the organization a certificate but will not result in a positive return on investment.

Without leadership involvement, ISO 9001 may become the missing link in the success of U.S. industrial plants. Your involvement as leaders at every step of your organization matters more than checklists. You must drive the culture of change.

In concluding, I would opine that rolling out ISO 9001 in U.S. industrial plants requires more than technical checklists; it requires leadership. By committing to involvement in the implementation of ISO 9001, plant managers and executives can transform their organizations into a quality-driven powerhouses that thrive in today’s competitive market.

The above article was recently published in “The Auditor” (an Exemplar Global publication).

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Integrating Standards for Safe Nuclear Expansion

-by Dr. IJ Arora

As nuclear energy regains attention as a low-carbon solution, organizations developing these energy sources need to consider a systems approach to the safe launch and growth of facilities. Once considered a great alternative to gasoline and coal, the nuclear energy industry’s growth was negatively affected by incidents like those at Chernobyl and Three Mile Island.

In this short article, I will attempt to convey that customer focus (clause 5.1.2 of ISO 9001:2015) is best ensured by proactive, not reactive, measures. This can be achieved through appreciating hazards, converting them to risks, prioritizing them, and planning the management system to achieve desired objectives.

Having served on a nuclear submarine and been on board when a nuclear accident took place, I know the pros and cons of this energy source. However, the world has changed since these tragic incidents and now there are advancements in not only nuclear technology but also in the management of nuclear facilities. ISO 19443:2018 a quality management system (QMS) standard built on the foundation of ISO 9001, but which is specific to the management of nuclear facilities. For those in the United States, ASME offers the NQA-1:2024 standard which is similarly dedicated to the nuclear industry.

Nuclear energy is perhaps an answer to the world’s power requirements. The demand for electricity is growing by the day with the extensive use of artificial intelligence and large data centers. A systems approach to management of this industry gives the world the best chance to appreciate risks systematically and plan for consequences proactively.

Grave negative effects to safety, security, health, and the environment are all likely consequences if a nuclear mishap takes place once again. Although the primary objective of a QMS is to get the desired output, it should not be at the cost of these potential harms.

The Three Mile Island facility is in the news once again for re-opening ahead of schedule. For those who do not remember, on March 28, 1979, a partial meltdown occurred at the Unit 2 reactor outside of Harrisburg, Pennsylvania. Environmental impacts included the release of radioactive gases into the atmosphere (albeit in limited amounts), long-term challenges in radioactive waste storage, and site contamination. Additionally, there were psychological and social effects that caused a loss of public trust in the nuclear energy industry.

As discussions emerge about reopening the Three Mile Island facility (now scheduled by 2027), evaluating its environmental effects through the lens of the ISO 14001:2015 environmental management system (EMS) is both prudent and proactive. Therefore, in the following section, I will outline the relevant applicable clauses from ISO 14001:2015.

Applicability of ISO 14001:2015 to a nuclear facility

Clauses 4.1 and 4.2, “Context of the Organization” and “Needs and Expectations of Interested Parties”

Nuclear facilities would benefit from considering:

  • Historical context (e.g., past accidents and public concern)
  • Stakeholders such as regulatory bodies, local communities, and environmental NGOs
  • Emerging media reports and public opposition or support as environmental risk indicators

Clause 6.1, “Actions to Address Risks and Opportunities related to Significant Environmental Aspects”

Considering a lifecycle approach, a reopened nuclear plant must assess:

  • Emissions of ionizing radiation
  • Spent fuel storage and long-term waste management
  • Thermal pollution from coolant discharge
  • Accident and emergency scenarios
  • And other significant environmental aspects requiring control measures and documentation

Clause 6.1.3, “Compliance Obligations”

This subclause involves alignment with:

  • Nuclear Regulatory Commission (NRC) rules
  • EPA guidelines on radiological impacts
  • International agreements on nuclear safety and waste

Clause 6.1.4, “Planning Action”

The plant must establish plans to:

  • Prevent recurrence of accidents like those of March 28, 1979
  • Contain and manage radioactive leaks
  • Mitigate environmental risks in both normal and abnormal operating conditions

Clause 8.2, “Emergency Preparedness and Response”

This subclause includes details critical for a nuclear facility and requires:

  • Detailed emergency response procedures for nuclear accidents
  • Training for first responders and public communication plans
  • Coordination with local and federal emergency management agencies

Clause 9.1.1, “Monitoring, Measurement, Analysis, and Evaluation”

To meet the requirements of this subclause, facilities must continuously monitor:

  • Radiation levels in air, water, and soil
  • Effectiveness of containment systems
  • Compliance with regulatory thresholds

Clause 10.1, “Nonconformity and Corrective Action”

This subclause would require that:

  • Any incident or near-miss must trigger a formal investigation
  • Includes lessons learned from:
    • The March 28, 1979 event itself
    • Any deviations during recommissioning or startup

A system approach to nuclear facility management

The opening (or, in this case, reopening) of a nuclear facility offers an opportunity to integrate modern management system practices with lessons learned from the past. ISO 19443:2018 and ISO 14001:2015 provide a structured framework to manage the needs of nuclear operations as well as public environmental concerns.

During my time consulting for numerous industries, I have found a strengths, weaknesses, opportunities, and threats (SWOT) analysis to be a very useful tool— especially the weaknesses and threats that help identify risks. A detailed SWOT analysis for the Three Mile Island facility might provide the following inputs as an example:

Technical and operational risks: aging infrastructure

  • Although it was not the site of the 1979 meltdown, Unit 1 is more than 50 years old.
  • Restarting involves complex retrofits, control system upgrades, and re-licensing—all of which require time and precision.
  • Rushing these checks might lead to overlooked fatigue, corrosion, or component failures.

Human factors

  • Post-incident, nuclear workforce training and institutional memory may be weak.
  • Skilled nuclear operators must be retrained or recruited, and hasty onboarding increases the chance of human error—a factor in many historical nuclear mishaps.

Environmental risks: radioactive emissions and waste

  • Restarting means handling spent fuel, coolant systems, and storage pools.
  • Hurrying these operations risks could lead to:
    • Leaks during fuel handling or containment failures
    • Inadequate radioactive waste protocols

Ecosystem disruption

  • Cooling systems may discharge thermal pollution into nearby rivers.
  • Emergency preparedness might not be fully revalidated for post-reopening conditions.

Better alternatives to a rushed restart

Although early reopening offers incentives like energy security, carbon reduction, and economic revival, these gains are precariously balanced against high-impact risks that could derail long-term viability. The strengths and opportunities may only be fully realized with a controlled, phased, and transparent approach, not through acceleration that bypasses environmental, technical, and social due diligence.

As such, organizations pursuing the development of nuclear energy plants must consider:

  • Phased reopening with public oversight
  • Third-party safety audits after at least two cycles of internal audits post implementation of the management system
  • Full-scale emergency drills and community outreach prior to operation
  • Independent environmental impact assessments (EIA)

Conclusion

The benefits of a fast reopening exist, however, the risks far outweigh short-term gains unless stringent safety, regulatory, and public engagement protocols are followed. Strategic value lies in measured and transparent activation/reactivation, not haste. ISO 14001:2015, ISO 19443:2018, and ASME NQA-1:2024 provide the framework for an integrated management system.

In conclusion, I would say a good strategy to implement and to safely accelerate nuclear energy deployment must include the adoption of a management system. ISO 14001:2015 ensures environmental responsibility and community accountability; ISO 19443:2018 drives quality, culture, and nuclear-supplier discipline; and ASME NQA-1:2024 enforces technical rigor and traceable QA processes. Together, these standards offer a comprehensive, risk-based, and stakeholder-aligned approach.

Rushing implementation without such integration would leave critical blind spots. An integrated implementation roadmap including these standards could guide the strategic and operational implementation in support of safe, controlled nuclear energy expansion.

The article was recently published in “The Auditor” An Exemplar Global Publication.

Types of Challenging Auditees – and How to Engage Them Effectively

– by Julius DeSilva

In every audit, auditors will encounter a diverse range of personalities—some cooperative, others a bit more complex. Understanding and managing these interactions is a core skill, particularly when auditees inadvertently—or intentionally—create barriers to transparency. Here are the most common types of challenging auditees, and expanded strategies on how to engage them effectively.

1. The One Word Wonder

Characteristics:

  • Offers short, clipped answers.
  • Rarely expands on details unless specifically asked.
  • May be uncomfortable, anxious, or disengaged.

Enhanced Strategies:

  • Build rapport early: Start with informal, low-stakes conversation before diving into audit questions. A simple “How long have you been with the company?” can ease tension.
  • Use layered questioning: Follow up “Yes/No” questions with: “Can you walk me through how that works?” or “What happens next?”
  • Prompt with context: “When I reviewed the procedure, it mentioned X—how is that handled in your area?”
  • Be patient and unhurried: Silence is a tool. After a question, wait calmly. Many reserved auditees will fill the silence with additional information if not interrupted.

2. The Egoist

Characteristics:

  • Seeks to dominate the conversation.
  • May condescend or subtly undermine the auditor’s authority.
  • Talks more about theory than actual practice.

Enhanced Strategies:

  • Acknowledge their expertise: Use phrases like “You clearly have deep experience in this process” to soften defensiveness.
  • Redirect focus to conformity: “That’s a great point. Let’s tie it back to what the standard requires and how your team demonstrates that.”
  • Anchor with facts: Use documentation and objective evidence as neutral ground—“Let’s take a look at the latest calibration log to verify that.”
  • Avoid debates: Don’t match ego with ego. Instead, maintain a calm, confident presence grounded in your role and purpose.

3. The Perfectionist

Characteristics:

  • Presents carefully curated documents.
  • May try to steer you away from real-time observations.
  • Views any finding as a personal failure.

Enhanced Strategies:

  • Normalize findings: “It’s common for systems to evolve, and audits are a way to support that continuous improvement.”
  • Use the PDCA approach: Frame observations as part of the cycle—”This finding shows an opportunity to adjust and refine the process.”
  • Request real-time demonstrations: Ask to observe actual practices in the workplace—not just documentation—to validate implementation.
  • Showcase positive practices: Where applicable, cite strengths during the audit to balance critique and support their desire for excellence.

4. The Over-Talker

Characteristics:

  • Provides excessive detail, often going off-topic.
  • Turns simple answers into storytelling sessions.
  • May genuinely enjoy the audit—or be trying to obscure weak spots.

Enhanced Strategies:

  • Set time expectations upfront: “We’ve got 30 minutes scheduled to cover this section, so let’s focus on the core areas first.”
  • Use summary statements: “So, to confirm, your process begins with A, goes through B, and ends at C—is that correct?”
  • Politely interrupt: “Sorry to cut in—I just want to make sure we stay on track. Can you show me the documentation for that step?”
  • Assign structure: Give the auditee a format to follow. “Can you explain this in three steps—input, action, output?”

5. The Ghost

Characteristics:

  • Avoids being present.
  • Pushes responsibility to others.
  • Responds only under pressure.

Enhanced Strategies:

  • Secure buy-in from leadership: During opening meetings, confirm auditee availability and responsibilities with senior management.
  • Use formal scheduling tools: Calendar invites, email confirmations, and audit plans in writing create accountability.
  • Document delays diplomatically: If access is denied or delayed, note this in the audit record professionally.
  • Adapt and improvise: Shift to records review or interview other personnel if the primary auditee is unavailable. Highlight systemic access issues in findings if applicable.

6. The Nervous Novice

Characteristics:

  • Easily flustered.
  • May fear saying the “wrong thing.”
  • Often new to audits or in a junior role.

Enhanced Strategies:

  • Create a low-pressure environment: Explain that the audit is not a test of their personal performance.
  • Break questions down: Instead of asking “How does your process ensure compliance with Clause 8.5.1?”, ask “What’s the first step you take when starting this task?”
  • Avoid audit jargon: Use plain language, e.g., “How do you make sure things are done the right way every time?”
  • Reassure through transparency: Let them know what you’ll be asking and why. “Next, I’d like to look at how you manage incoming materials—is that okay?”

Final Thoughts: Mastering the Human Element of Auditing

At its core, auditing is not just about finding nonconformities—it’s about understanding how people interact with systems. Every auditee, no matter how challenging, offers insight into how the organization truly functions. As auditors, our role is not to judge personalities but to uncover evidence that reflects the effectiveness of processes. This requires patience, emotional intelligence, and a steady commitment to impartiality.

By adapting our approach to the individual while remaining anchored in the audit objectives, we build credibility and foster cooperation—even in the most resistant environments. Ultimately, the success of an audit is measured not only in findings, but in the quality of the dialogue, the clarity of the evidence, and the positive influence it has on continual improvement. A skilled auditor doesn’t just complete a checklist—they leave behind a stronger, more self-aware organization.

The article was recently published in “The Auditor” An Exemplar Global publication.