What the ISM Code Can Teach Us About Risk: Part Two

Editor’s note: This is the second of a two-part article examining the risk-based thinking lessons to be learned from maritime safety and security protocols. You can read part one here.

The International Safety Management (ISM) Code brings a framework for safety through systematic management. It was introduced by the International Maritime Organization after several major maritime accidents revealed a common problem: The causes were rarely technical alone; instead, they were failures of management systems. The ISM Code, therefore, established a simple but powerful requirement, wherein shipping organizations must implement a documented safety management system (SMS) to ensure the safe operation of ships and the protection of the environment.

The principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

Connecting the ISM code and ISO 9001

The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing leadership responsibility, risk assessment, operational control, training and competence, incident reporting, corrective action, and continual improvement. These requirements may sound familiar to anyone working with ISO management system standards such as ISO 9001 and others following the harmonized structure. In essence, the ISM Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

Establishing an SMS based on the ISM code and principles of ISO 9001 means planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, person in water, and/or security threats or piracy. (Note that maritime security is covered by the International Ship and Port Facility Security Code and ISO 28001 covering security management systems for the supply chain). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised.

Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of considering what could go wrong and if people know their roles if (when) it does. It also means interrogating the system to determine how the organization will handle the ramifications of the adverse event.

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. Sections 5.1 and 5.2 require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The master has overriding authority. At the same time, as per section 4, the ISM Code requires those off the ship to support the master through a defined role known as the Designated Person Ashore (DPA). This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles: Authority must match responsibility and top management must remain connected to operational realities.

ISO 9001 expresses the same idea in a different context. As seen in clause 5.1 (“Leadership and commitment”) and clause 5.3 (“Organizational roles, responsibilities, and authorities”) leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

In the case of mariners, competence and training are systematized. The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important: continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon-ship drills, and damage-control exercises are conducted not because emergencies are frequent; instead, it is because although they are rare, they are also highly consequential. This principle translates directly into quality management. Competence is not merely about qualifications; it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from incidents, as seen in ISO 9001’s clause 7.1.6 (“Organizational knowledge”) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of nonconformities, accidents, and hazardous occurrences. The purpose is not to blame, but to learn. Each incident becomes an opportunity to ask, “What failed in the system?” “What corrective action is needed?” and/or “How do we prevent recurrence?” Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about all key decisions, including how and when to transit dangerous areas. These decisions are rarely simple. They require balancing safety risks, commercial pressures, and regulatory requirements, including ever-changing statutory requirements of various contracting governments. This must be seen within the contexts of operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk; they provide a framework for making better decisions about risk.

The ISM Code as a case study for risk-based thinking

Mariners have much to teach quality professionals on the use of the system approach for considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons:

  • Systems matter more than individuals; therefore, while competent people are essential, reliable operations depend on structured systems.
  • Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away.
  • Leaders must prepare for rare but high-impact events, because risk management is not only about what happens frequently.
  • Practice builds readiness.
  • Training and drills ensure procedures work under real conditions.

The takeaway is that there is a need to learn relentlessly from failure and use nonconformities as opportunities to strengthen the system.

The need to navigate uncertainty strengthens the importance of the ISM Code and/or ISO 9001 to inform leaders about risk and process management. For ship owners and masters, decision-making requires a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Yet despite these uncertainties, global shipping remains remarkably reliable. More than 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

The ISM Code, as well as ISO 9001, recognize that outcomes, whether safety or quality, depend on well-defined processes and leadership oversight. To mariners and quality professionals alike, I would advise another close look at your management system. Strengthen it. Maritime leaders ashore, like executives in the boardroom, must stay involved in assessing and mitigating risks to provide the best chance for safety, security, and success.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Home » Management System

What the ISM Code Can Teach Us About Risk: Part One

For centuries, individuals have sailed the sea, perhaps for their livelihood, perhaps for adventure, or perhaps for reasons of their own. Christopher Columbus, Ferdinand Magellan, James Cook, and countless others changed the world.

Today, sailing through international waters to meet the basic needs of the world brings challenges. Without merchant ships, tankers, bulk carriers, and container vessels, the global supply chain stops. Doesn’t the world owe these mariners all due safety and security?

I am a former seafarer who commanded submarines in the Indian Navy and then continued my career as a master in the merchant marine. Today, I am a subject matter expert in issues related to maritime safety and security. Given this background, I feel compelled to analyze what I hear and read about current events and provide a structure whereby the merchant marine industry might better prepare for any and all eventualities. The International Safety Management (ISM) Code, the International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW), and ISO 9001 all provide process-based approaches that can be used by those in this industry for planning and risk mitigation.

Most of us do not have to deal with high-risk challenges at sea. For those who do, however, there are guidelines they can use. As one example, the ISM Code provides some lessons into anticipating the unexpected and planning for these risks in a systematic manner.

In this article I will touch on how portions of the ISM Code connects to elements of ISO 9001 and provide input that might be useful to maritime leadership in ensuring quality assurance and conformity assessment based on risk and considering the context in which these organizations operate. This is guidance that applies to any of us, on the water or in a facility or factory.

Similarities between the ISM Code and ISO 9001

For professional mariners, a simple rule applies: Conditions that appear routine can change without warning. The ISM Code emphasizes preparedness for emergencies and abnormal situations. Section 8.1 requires the organization to establish procedures to identify, describe, and respond to potential emergency situations aboard the ship. In other words, the ISM Code requires organizations to plan not only for technical failures or weather hazards, but also for security risks and unexpected external threats. Navies may refer to this as an operational assessment, but (in Shakespearean language) a risk by any other name would still be a risk.

ISO 9001 expresses a comparable idea through the requirement for risk-based thinking. As emphasized in clause 6.1.1, the organization shall determine the risks and opportunities that need to be addressed to give assurance that the quality management system can achieve its intended results.

From a management systems perspective, the broader lesson is clear: Organizations must plan for situations that may appear unlikely until they occur. For a ship’s captain or master, that planning may involve security drills, contingency routing, and coordination with naval authorities. For a quality manager or organizational leader, it may involve supply chain disruption, cybersecurity incidents, or geopolitical shocks. Ultimately, the decision on whether to sail should be based on a proper risk assessment. Events at sea sometimes remind us, in stark terms, why disciplined safety and command systems matter. What makes an incident significant in the context of this discussion is the reminder of just how quickly circumstances can change at sea.

Within ISO 9001, the context of the organization (clauses 4.1 and 4.2) leads to risk appreciation (clause 6.1). All of this must be integral parts of the maritime management system, at sea or ashore.

This is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations as per section 8.1. Good organizations connect real maritime events with risk-based thinking. They understand that commercial interests must mesh with the emergency planning sections in the ISM Code. This understanding is also found in ISO 9001, specifically in clause 6 (“Planning”) and clause 8 (“Operation”).

Expecting the unexpected

My own appreciation for disciplined systems thinking was shaped long before the ISM Code was widely implemented in commercial shipping. During my years in the Indian Navy, I had the privilege of commanding vessels, first on F-class boats and later through service on a Charlie II-class submarine. Submarines operate in an environment where uncertainty is not theoretical and the margin for error is extremely small. Any failure in equipment, communication, or procedure can quickly become critical. What keeps submarines safe is not individual brilliance on the part of a captain or crew. That is part of it, of course, but even more important is the relentless adherence to procedures and constant preparation for contingencies. Before every patrol, the crew repeatedly rehearses emergency actions such as flooding drills, fire drills, loss of propulsion, and loss of power. Each crew member knows precisely where to go, what valve to operate, and what sequence of actions to follow. These procedures are not simply found in written manuals. They are practiced until they become instinctive.

At that time, we did not describe this discipline in terms of “process-based management systems,” but that is exactly what it was. The system existed to ensure that when the unexpected occurred, as it inevitably does at sea, the crew would not rely on improvisation alone. The response would already be embedded in the system and in themselves. Years later, when I sailed as a master in the merchant marine and then began to work with ISO management systems, I recognized the same principles expressed in a different language. ISO 9001 requires organizations to establish, implement, and maintain the processes needed for the quality management system and their interactions, as per clause 4.4 (“Quality Management System and its Processes”). Section 1.2 of the ISM Code similarly requires organizations to ensure safe practices in ship operation and a safe working environment. Different industries, different terminology, but the underlying idea is identical: Safety, quality, and reliability are the result of preparation and training, not simply reacting well to emergencies.

I can confirm through my experience that this reflection is not merely theoretical. It comes from first-hand experience wherein I led teams and where preparation truly mattered. This background gives me a clear perspective on risk, command responsibility, and disciplined procedures under uncertainty. This perspective can make a very compelling bridge between maritime safety management (ISM/STCW) and organizational quality systems (ISO 9001).

As we consider dangerous situations on or in the water, we can see what the ISM Code and ISO 9001 (in addition to other maritime protocols and ISO standards) can teach us about risk in uncertain times. In today’s volatile world, commercial shipping once again finds itself navigating geopolitical tension. News headlines remind us that vessels may need to transit waters where the risks are not merely commercial, but also matters of safety and survival. For those who have spent a career at sea, such circumstances are not entirely unfamiliar. The maritime profession has long recognized that uncertainty is inherent to operations. Ships sail through storms, equipment failures, and occasionally conflict zones. Yet despite these uncertainties, shipping remains one of the safest and most reliable global industries. This is not an accident. Much of that safety culture comes from the ISM Code, supported by training standards such as STCW. These frameworks provide reliable, structured guidance on how organizations anticipate risk, prepare crews, and maintain operational control.

In the next part of this two-part article, we will further discuss the framework of maritime systems and how they relate to risk and ISO 9001.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Auditing Risk Management: How Experienced Auditors Identify Risks That Aren’t Listed in the Risk Register.

Organizations today rely heavily on risk registers to track and manage potential threats. Risk registers are useful tools, and they document known risks, assess their likelihood and impact, and assign ownership for mitigation actions. They help leadership visualize risk exposure and provide a structured way to prioritize responses.

However, risk registers have their limits. Experienced auditors know something critical, that the most damaging risks are often the ones that never appear in the register. A risk register represents what the organization already knows or believes it knows. The context of the organization changes. A risk register reflects the thinking of the team that created it. But risks evolve, environments change, and assumptions become outdated. As a result, relying solely on the documented register can create a false sense of security. Seasoned auditors understand that their responsibility goes beyond verifying that risks are listed and mitigations are documented. Their deeper role is to identify blind spots and record risks that exist outside the documented system. This is where experience, professional skepticism, and systems thinking become essential. Skilled auditors recognize patterns, inconsistencies, and subtle signals that indicate hidden risks. QMII specializes in risk and with our forty plus years in the system field, in this article, we explore how experienced auditors uncover risks that never make it into the risk register and why this capability is essential for effective risk management.

The questions therefore are, why risk registers miss critical risks. I think, before examining how auditors uncover hidden risks, it is important to understand why risk registers are incomplete.

Risk registers reflect perception and often not the reality. Risk registers are typically compiled during structured workshops or periodic reviews. Participants identify risks based on their knowledge and experience. But human perception is limited. People tend to list:

  • Risks they have seen before.
  • Risks that are already familiar.
  • Risks that are easy to articulate.

But unfamiliar or emerging threats often remain invisible. For example, a manufacturing team might focus heavily on supply chain delays while overlooking risks related to cybersecurity vulnerabilities within their operational technology systems. Experienced auditors recognize this limitation and therefore treat the risk register as a starting point, not the final word.

Then there is the organizational bias which influences risk Identification. Risk registers can be influenced by internal politics or cultural pressures. Some risks may be downplayed because:

  • They reflect poorly on leadership decisions.
  • They expose systemic weaknesses.
  • They challenge existing strategies.

In such cases, risks may be intentionally or unintentionally omitted. Auditors who understand organizational dynamics pay attention not only to what is documented, but also what is missing.

Please also consider that risks often evolve faster than documentation. The modern risk landscape changes rapidly due to:

  • Technological advancements.
  • Regulatory changes.
  • Market disruptions.
  • Geopolitical instability.

Risk registers are often updated annually or quarterly. But emerging risks can develop far faster than review cycles. Experienced auditors therefore examine current conditions, not just documented assessments. The experienced auditors detect unlisted risks. The difference between routine auditing and expert auditing lies in how auditors think. Experienced auditors do not simply verify compliance. They analyze systems, behaviors, and signals that reveal underlying vulnerabilities. The ISO 9001 version expected in September 2026 expects organizations to go beyond check lists and see how their system works to produce confirming products and services.  The auditors of the future must work to providing these inputs. Several approaches distinguish their work.

The primary is developing the attitude and aptitude where the auditors look for process weaknesses, not just risk entries. Experienced auditors start by examining processes rather than documentation. Instead of asking: “Is this risk listed in the register?” They ask: “Where could this process fail?” Every process contains inherent vulnerabilities. Skilled auditors identify points where failure could occur, including:

  • unclear responsibilities.
  • lack of monitoring.
  • excessive reliance on manual steps.
  • insufficient controls.

For example, if a company relies heavily on one individual to approve high-value financial transactions, an auditor immediately recognizes concentration of authority risk, even if the risk register never mentions it. In other words, auditors uncover risks by studying how work actually happens.

Observing operational reality is another positive trait in an auditor. Documentation often describes how processes are supposed to work. But experienced auditors know that actual practice frequently differs from documented procedures. They therefore observe operations directly by speaking with frontline staff, watching processes in action and asking open-ended questions. These conversations often reveal informal workarounds, shortcuts, or unofficial practices that introduce risk. For instance, employees might bypass a cumbersome control procedure to meet production deadlines. While the process appears compliant on paper, operational reality tells a different story. This gap between documented procedure and actual practice often exposes hidden risks.

Auditors can add value by providing inputs in audit reports which connect risks across functions. Risk registers are frequently organized by departments. Each function identifies its own risks independently. But real risks often emerge between functions, where responsibilities intersect. Experienced auditors look for these interdependencies. Examples include IT changes affecting operational reliability, procurement decisions impacting regulatory compliance or sales commitments creating financial exposure and so on. When risks are examined in isolation, these connections may never be recognized. Auditors with systems thinking identify risks that arise from interactions between processes.

Another useful tip I could share with auditors would be to learn the art of questioning assumptions. A hallmark of experienced auditors is professional skepticism. They challenge assumptions that others take for granted. Common assumptions include:

  • “This control has always worked.”
  • “That vendor is reliable.”
  • “This system cannot fail.”

History repeatedly shows that risks often emerge when organizations become overly confident in their controls. Complacency is in itself a risk. Auditors therefore test assumptions by asking questions as, what happens if this control fails? Or what alternative scenarios could occur? Or perhaps, what early warning signs might exist? This mindset helps auditors uncover risks that have never been formally considered.

Identifying early warning signals should be the organizations’ role. However, it is often missed as the organization gets acclimatized to it. Hidden risks rarely appear suddenly. They often produce early signals which even if missed by the organization can be observed by the experienced auditor. These signals may include:

  • recurring minor incidents.
  • increasing process delays.
  • rising customer complaints.
  • frequent control overrides.

Individually, such signals may appear insignificant. But collectively, they may indicate deeper systemic risks. Experienced auditors are trained to recognize these patterns. They understand that small anomalies often precede major failures.

Therefore, the role of auditor experience is vital. Technical knowledge alone does not enable auditors to detect hidden risks. Experience plays a critical role. Experienced auditors develop several capabilities over time for example their ability to see a pattern recognition. Years of exposure to different organizations allow auditors to recognize patterns that others miss. They may recall similar conditions that led to failures in other organizations and apply those lessons proactively.

Systems thinking is another quality experienced auditors possess. They may be auditing a few selected processes in a particular audit; however, the system perspective must be kept in mind. Experienced auditors understand organizations as interconnected systems. They see how decisions in one area influence outcomes in another. This perspective helps them identify risks that arise from system complexity rather than isolated failures.

Experienced auditors have judgment and intuition. They know that while auditing they must remain evidence based.  Seasoned auditors also develop professional intuition. We are not recommending experience as the basis for audit decisions. Requirements should remain the primary basis. Yet this intuition arises from accumulated experience and allows auditors to recognize subtle indicators that something may be wrong, even when documentation appears complete. They therefore ask questions to unearth hidden risks.

Strengthening risk management through auditing is a desirable trait. When auditors identify risks outside the risk register, they provide tremendous value to leadership. Their insights help organizations:

  • identify emerging threats earlier.
  • improve risk identification processes.
  • strengthen internal controls.
  • enhance organizational resilience.

Most importantly, they shift risk management from a static checklist to a dynamic learning process. Organizations that encourage auditors to explore beyond the register benefit from more realistic and proactive risk oversight. Auditors must start moving beyond the checklist mindset. In some organizations, audits become overly focused on verification. Inexperienced auditors tend to look at questions in terms of, is the risk listed or is the mitigation documented or is the review completed? While these checks are necessary, they represent only the baseline of effective auditing. Experienced auditors move beyond checklist thinking by asking deeper questions:

  • What risks might exist that we have not yet identified?
  • Where could the system fail under stress?
  • What assumptions might be wrong?

This shift transforms auditing from a compliance exercise into a strategic capability.

In conclusion I would opine an experienced auditor is like a risk detective. Risk registers remain valuable tools. They provide structure, accountability, and visibility into known risks. But they cannot capture every emerging or hidden threat. That is why experienced auditors play such a crucial role in risk management. By observing operations, questioning assumptions, connecting systems, and recognizing subtle warning signs, skilled auditors identify risks that others overlook. In many cases, their ability to detect these hidden risks prevents costly failures long before they occur.

Ultimately, the most effective auditors behave not just as compliance reviewers, but as risk detectives who are constantly searching for what the organization has not yet seen.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Why Most ISO Audits Miss System Failure Signals – And How Experienced Auditors Detect Them

I have always valued the process-based management system (PBMS) approach based on the ISO standards as the best start to designing and implementing a management system that produces confirming products and services. Over time with continual improvement the system should give the ROI (return on investment). The management system is not a magic trick, agreed, it all depends on the implementation. The system starts in a responsive manner where NCs (non-conformities) drive correction and CA (corrective action). The system then matures and becomes proactive when data drives risk and trends. The internal audits should give the leadership the inputs to better resource and continually improve the system.  Yet I see organizations end up with a “checklist-style” audit where these frustrating audits do not provide the inputs to improve the system. It is often because audits treat a living system like a static inventory. Most audits miss signals because they focus on conformity (did you do what you said?) rather than capability (does the process achieve the intended result?). The intend should be to bridge the gap between “compliance” and “performance.”

The illusion of compliance pays the price. Most ISO audits fail to detect systemic rot because they are designed to find missing records, not broken logic. That is because auditors fall into the checklist trap. Standard auditors often follow a linear path. If the “management review” happened and the minutes exist, they check the box. Then there is the “paper thin” system where organizations have become experts at “audit-ready” documentation that masks operational chaos. Finally, the auditors focus on output and not on outcome during the audits, they often verify that a process ran but fail to ask if the process is healthy.

The question then is why the “signals” are missed? System failures rarely happen overnight; they emit “smoke” long before the fire. Standard audits miss these because:

  • Siloed Auditing: Auditors look at Department A and Department B separately, missing the friction and “white space” between them where most failures occur.
  • Sampling Bias: Auditors often let the guide choose the records. Experienced auditors know that the most telling data is usually in the “messy” folders the guide is trying to steer them away from.
  • Metric Manipulation: If a KPI is 99% green but the customer is complaining, the system is failing. A standard audit sees the 99% and moves on.

Therefore, the need is to see how experienced auditors “hear” the system. Veteran auditors move beyond the “what” and the “where” to the “how” and the “why.” They use a PBMS lens to detect:

  • The “work-around” signal, when employees have a “shadow” spreadsheet or a personal notebook to get the job done, the formal system has already failed.
  • The “quality debt” signal where recurring “minor” non-conformities are often symptoms of a single “major” systemic bypass.
  • Language patterns when experienced auditors listen for phrases like “we usually do it this way, but for the audit…” or “that person is the only one who knows how that works.”

The need is for auditors to transition from “auditing for points” to “auditing for risk”. To truly add value, the audit must evolve into a diagnostic tool.

  • Vertical vs. horizontal auditing where instead of checking a department, follow a single order from “quote to cash” to see where the process bleeds.
  • The “stress test” approach where auditors ask, “what happens if this person is out?” or “what happens if this supplier fails?” to test system resilience.

The key takeaways so far could be summarized as:

  • The process is the patient. Treat the audit like a medical check-up. Don’t just check the pulse; look at the lifestyle and the underlying vitals.
  • Stop re-inventing, start refining.  Since you believe in standards, emphasize as an auditor, that the ISO standards already require a process approach. Most people just ignore it in favor of the easier “clause-by-clause” approach.

As an example, we can consider a perfect paper audit that is followed by a major product recall, as indicative of illustrating the compliance-performance gap. The occurrence of a mishap, or a rejected product soon after a perfect audit should make an organization investigate its auditing effectiveness. It is necessary to take the great deep-dive and shift the focus from “did they follow the process?” to “is the process actually functioning?” is what separates a tick-box auditor from a system specialist.

In a standard audit, if the records are signed and the dates match, the process is marked “effective.” But experienced auditors know that a perfectly documented process can still be a failing one. To detect the signals most miss, you must look at the friction points the places where the “official” system meets human reality. Avoid the Illusion of compliance. In the world of ISO standards, there is a dangerous comfort in a “clean” audit report. As a specialist in process-based management systems (PBMS), I have always believed in the power of standards. Why re-invent the wheel when a global framework for excellence already exists? Yet we see it constantly: organizations pass their surveillance audits with flying colors, only to suffer a catastrophic service failure, a massive product recall, or a sudden dip in profitability weeks later.

In conclusion I would caution organizations, audit clients and auditors to stop auditing the paper, and to start auditing the pulse. If we continue to treat ISO audits as a “pass/fail” hurdle for a certificate, we do a disservice to the discipline of management. A standard is not a ceiling; it is a floor. It is the “wheel” that shouldn’t be re-invented, but it must be maintained, balanced, and aligned.

Any organization’s call to action may be called the “value-add” challenge where the organization changes the lens for the next audit cycle to:

  • Ditch the clause-by-clause audit to follow a single order from “quote to cash” rather than checking department folders.
  • Search for the “shadows” and look for the post it notes and cheat sheets. They show you where the formal system is failing to support the staff.
  • Ask “why” Five times to root cause the system. Refuse to accept “human error” as a root cause. Dig until you find the process flaw. Blaming is easy but not the answer.

The goal of a Process-Based Management System is to create a resilient, predictable, and scalable organization. Let’s stop auditing for compliance and start auditing for capability. At QMII we train our auditors for this.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Audit Focus Areas Under ISO 28000 for 2026 (and Beyond)

-by Dr. IJ Arora

In this article on ISO 28000:2022, “Security and resilience—Security management systems—Requirements,” I want to emphasize the audit focus areas for the standard, based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. This focus will allow organizations registered to the standard to go from mere compliance to resilience, leading to more secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this past year exposed an uncomfortable truth: Many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Organizations should not wait for audits to ensure continual improvement, act on risks, and explore opportunities for improvement. However, the fact of the matter is that nonconformities drive corrective actions. As such, audits play a minor part in providing inputs at the check stage of the plan-do-check-act (PDCA) cycle. The question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

Lessons learned

Audits in 2025 outlined the audit focus areas that will define credible, value-adding ISO 28000 audits going forward. Following are four key audit lessons learned.

Lesson 1: Risk assessments were static in a dynamic threat environment

Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. Although these assessments were often well-structured and aligned with ISO 28000’s clause 4, “Security risk assessment and planning,” they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

Lesson 2: Limited visibility beyond tier 1 suppliers

A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in tier 2 or tier 3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

Lesson 3: Cyber risks were poorly integrated into supply chain security

Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. The use of the harmonized structure presumed that an integrated management system approach could answer this, but organizations did not generally integrate ISO 27001 and ISO 28001 with ISO/IEC 27001:2022, “Information security, cybersecurity and privacy protection—Information security management systems—Requirements.”

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

Lesson 4: Business continuity planning lacked supply chain realism

Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301:2019, “Security and resilience—Business continuity management systems—Requirements.” However, audits in 2025 showed that supply chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Actions to consider

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider the following five actions.

Action 1: Going from risk identification to risk intelligence

From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. Clause 4 of ISO 28000, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:

  • The use of internal and external intelligence sources
  • Defined triggers for risk reassessment
  • Evidence that changes in risk lead to timely management action

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

Action 2: Supplier security assurance, not just evaluation

ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:

  • Supplier segmentation and prioritization
  • Proportionate security controls
  • Evidence of supplier audits, self-assessments, or performance reviews
  • Corrective action and escalation when requirements are not met

Supplier security must be demonstrable and sustained, not assumed.

Action 3: Integration of cyber and physical security controls

Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:

  • Identification of cyber-enabled supply chain risks
  • Coordination between security and IT incident response
  • Protection of logistics data, tracking systems, and access controls

Although ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

Action 4: Testing, exercises, and demonstrated preparedness

In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:

  • Scenario-based exercises relevant to the organization’s supply chain
  • Participation by relevant internal and external stakeholders
  • Lessons learned and system improvements following exercises

Preparedness is best demonstrated through practice, not paperwork.

Action 5: Governance and leadership accountability

A notable trend emerging from late 2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:

  • Management review outputs related to supply chain security
  • Resource allocation decisions
  • Evidence of board or senior leadership awareness of key risks

Implications and conclusions

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are twofold.

First, for auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.

Second, for organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion, I would say 2025 taught us that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity—they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

Above article was recently featured in an Exemplar Global publication – ‘The Auditor’.

Procedure, Work Instruction, or Flowchart?

-by Dr. IJ Arora

The choice between writing a procedure or a work instruction is an essential decision when designing a management system. Clause 4.4.1 of ISO 9001:2015 (as well as all the ISO management system standards using the harmonized structure) requires the establishment and implementation of a management system. This management system will have procedures and work instructions and further down the hierarchy, checklists and forms.

Processes can be actualized in many forms. Today, mapped processes make it easy to visualize the functioning of the process. This is an important distinction in quality management systems based on ISO 9001—or for that matter any sector-specific standard like those dedicated to management within maritime, aerospace, etc. Many organizations struggle with when to write a procedure, when to write a work instruction, and how and when a flowchart should be used.

I think the core difference between a procedure and a work instruction is that a procedure answers the question, “What happens and who does it?” A procedure defines the process, its purpose, its sequence (clause 4.4.1b), and who is responsible for the work, perhaps as process owners (clause 4.4.1e). It answers what is to be done, when it must be done, who is responsible, and why it matters. The flowchart then helps visualize the inputs and outputs that flow between the steps.

What is a procedure and how it is used?

A procedure does not tell someone how to do a task; it simply describes the steps or stages necessary to accomplish it. I think of the procedure as the blueprint of the workflow. Therefore, I would recommend using the procedure when multiple people or departments are involved, when there is decision-making or sequencing, when the process crosses functional boundaries, and when documenting the process supports consistency, audits, or training. The procedure is also best when regulatory bodies expect clearly defined processes.

What is a work instruction and how is it used?

On the other hand, a work instruction shows stakeholders how exactly a task is to be accomplished. A work instruction “goes into the weeds” to the extent required by the workforce (depending on their confidence, competence, knowledge, and so on). It describes specific methods, often at a deep level of detail. It answers questions such as:

  • “How do I perform this task?”
  • “What tools, equipment, settings, forms, and/or software steps are required?”
  • “What are the acceptance criteria?”
  • “What do I check and how do I measure performance?”

Remember, work instructions are intended to be simple, direct documents for use by the workforce. Use them when:

  • A task requires technical, step-by-step details
  • Training new personnel
  • Incorrect execution can create quality or safety risks
  • Standardization is essential
  • Variation in execution must be eliminated

What is a flowchart and how is it used?

Flowcharts can technically be used to support both procedures and work instructions, but I generally recommend their use in conjunction with procedures. This helps make the procedure visual by mapping the 50,000-foot view of a process. A flowchart is ideal when the process has multiple decision points, parallel paths, several departments interacting, and inputs/outputs that must be made clear. The flowchart helps avoid the confusion that can come when procedures are described in long paragraphs. Flowcharts make complex processes easy to understand immediately. I therefore believe in flowcharting a procedure when the process needs high-level clarity, the sequence matters, when an organization wants to show interactions between departments, when it supports risk-based thinking, and when you want to simplify training for new personnel.

Flowcharts work best for document control, non-conformances, and corrective action processes, purchasing and supplier management, production scheduling, quality inspection, and testing flows and change management processes (as seen in clauses 5.3e, 6.3., 8.2.4, 8.3.6, and 8.5.6). Flowcharts do not replace work instructions; they complement them.

Final thoughts

To sum up how these tools work together, the practical document hierarchy an organization could consider starting with policy (and why that policy exists), move into documenting the procedure (preferably supported by a flowchart) to convey what happens and in what order, and then crafting work instructions to clarify how to carry out specific tasks. Finally, document everything through records and forms to provide evidence that the work was performed.

All this should connect as a system where a flowchart procedure should describe the process, a work instruction explains each critical task, and the documented information provides traceability. Performance monitoring (clause 9) can be documented via procedures, work instructions, and flowcharts.

 

Note – The above article was recently featured in an Exemplar Global publication ‘The Auditor’. 

Hope Is Never A Plan

Wishful thinking is fine, but it rarely achieves positive results in professional settings. The best path to reach a desired outcome is to implement a structured, process-based management system. It is not a guarantee of success, but if implemented by competent and motivated teams, such a system allows the organization to produce conforming products and services and embrace continual improvements.

I often hear from leadership about their faith in the power of hope, but my experience tells me that hope is never a plan. For those who believe in hope, my advice is to base it on a well-designed management system. There is no need to re-invent the wheel. ISO standards exist for management teams to use.

In organizations of every size, across industries and borders, there is often an invisible reliance on hope. Leaders hope customer complaints will decline. Managers hope processes will perform as intended. Teams hope risks won’t materialize.

Hope can inspire, but it cannot control outcomes. It is not a strategy, and it is certainly not a plan. In contrast, a good management system transforms that hope into structured action, measurable results, and continual improvement.

A Better Way

At my organization, we have long stressed (and said) “Hope is never a plan.” The plan—the real plan—is embedded in the process-based management approach that underlies ISO 9001 and other international standards. This approach replaces uncertainty with understanding and reactivity with resilience.

The problem with hope as a strategy is there is no plan. In times of uncertainty—economic shifts, market volatility, supply chain disruptions—many organizations fall back on hope as a substitute for planning.

However, in my experience, success is built upon the foundation of a process-based management system. Remember the wise words of Deming: “A bad system will beat a good person every time.” The process approach, central to ISO 9001 and mirrored in ISO 14001, ISO 45001, and numerous other ISO standards, recognizes that results come from well-managed processes.

The journey from wishful thinking to structured management is embodied in the process approach, which was first formalized in ISO 9001:2000 and reinforced in ISO 9001:2015. The standard recognizes that consistent, predictable results arise from well-defined and managed processes, not from chance. In particular, sub-clause 4.4 of ISO 9001:2015 requires organizations to establish, implement, maintain, and continually improve a management system, including the processes needed and their interactions.

Where hope says, “Let’s see how it goes,” a process-based system asks:

  • What inputs are required, and what outputs are expected?
  • Who is responsible for the process?
  • What resources and controls are necessary?
  • How will we measure performance?

This thinking moves an organization from reacting to problems to controlling the variables that create success. Rather than managing departments or reacting to problems, organizations use the process approach to:

  • Define interrelated processes that deliver outputs valuable to customers and stakeholders (sub-clause 4.4.1).
  • Identify inputs, activities, and controls within each process (sub-clause 4.4.1).
  • Establish measurable objectives and performance indicators (sub-clauses 6.2 and 9.1.3)
  • Use data and analysis to drive decisions.

This approach replaces hope with evidence, accountability, and continual improvement.

Plan, Do, Check, Act (PDCA) and the Importance of Leadership

The PDCA cycle implies planning as the basis for turning vision into reality. Clause 6 emphasizes “Planning,” i.e., the transformation of organizational context (subclauses 4.1 and 4.2) and risks (sub-clause 6.1) into actionable objectives and opportunities for improvement:

  • Risks and opportunities (not just reacting to issues)
  • Resources and competence needed to achieve results
  • Process interactions that maintain flow and consistency
  • Measurable outcomes that guide continual improvement

In this framework, hope is replaced by proactive thinking, i.e., identifying what could go wrong and preparing responses before it happens. This is far superior to a reactive approach. Of course, in the initial functioning of the management system, any non-conformances (NCs) found will drive corrective action. However, once data accumulates (based on closed NCs and other monitoring and analysis) then those data will drive risks and trends and enable proactive system.

Leadership plays a very important part in the success of an organization. From slogans to systems, true leadership is not about motivational statements but about embedding systems that work even when leaders aren’t watching.

Leaders demonstrate commitment by:

  • Integrating the management system into business strategy (sub-clause 5.1.1c)
  • Promoting process ownership and accountability
  • Ensuring alignment of policies (sub-clause 5.2), objectives (sub-clause 6.2), and actions

A strong system outlives individual personalities—it ensures the organization runs effectively on principles, not just people. What employees learn during their work life at the organization is captured as lessons learned and forms the organization’s corporate knowledge (sub-clause 7.1.6).

Continual improvement (sub-clause 10.3) is the antidote to complacency. Even good systems fail if they stop evolving. ISO’s process-based model ensures continual improvement through:

  • Audits and reviews that identify gaps and inefficiencies
  • Corrective actions that prevent recurrence
  • Performance metrics that inform decision making

Hope says, “Things will get better.” A good management system says, “Here’s how we’ll make them better—and how we’ll know it worked.”

Conclusion

My advice to leaders is to replace hope with a system. Every organization faces uncertainty, but those that succeed do not count on hope—they rely on structured management, clear processes, and evidence-based decisions. Leadership is responsible for maintaining customer focus (sub-clause 5.1.2), understanding customer requirements and associated risks, having thorough knowledge of their products, and carefully selecting vendors.

Uncertainty and hazards must not be passed to employees, users, or other stakeholders. Instead, they should be converted into manageable and low-impact risks. Those risks can then be addressed and/or converted into opportunities for improvement.

In an uncertain world, replacing hope with a system is a must. Hope may be emotionally comforting, but it is operationally dangerous. A good management system, based on ISO 9001’s process approach, gives structure to intention and reliability to performance. It enables organizations to anticipate risks, seize opportunities, and deliver consistent value. It creates confidence among customers, regulators, and employees that the organization is not merely hoping for success—it is planning, executing, and improving toward it.

The above article was recently featured in ‘The Auditor’, an Exemplar Global publication

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Cost-Benefit Analysis: ROI of ISO 9001 Registration for U.S. Manufacturers

For some U.S. manufacturers, registration to ISO 9001 raises one question: “Is it worth the investment?” In other words, how can an organization maximize the benefits of ISO 9001 registration and convert them to a solid return on investment (ROI)?

Analyzing ROI

A consideration of costs and benefits must be included in an ROI analysis to allow manufacturers to make good decisions about ISO 9001 registration. Calculating the value of an effective quality management system (QMS) must include integrating quality and the overall management of the organization (as seen in clause 5.1.1 of ISO 9001). This would include the costs and payoffs that create the real ROI of ISO 9001 registration.

Mere compliance to the language of the standard is not enough; what is required is that ISO 9001 registration leads to competitive advantage. The intent for any manufacturer is to boost efficiency and revenue. In this new environment, where a considerable amount of manufacturing is being re-shored to the United States, ISO 9001 registration matters more than ever. Registration to ISO 9001 is worth it if it brings a clear ROI, such as cash in the bank in the form of cost savings or revenue increases. The answer lies in understanding the ROI that comes from building a strong QMS based on ISO 9001 or other relevant industry-specific standards such as AS9100, etc.

There is no free lunch. In other words, there are costs associated with ISO 9001 registration. Therefore, manufacturers should budget for:

  • Consulting and training. Staff must be prepared to align processes with the requirements of ISO 9001.
  • System development. This may include documenting procedures, implementing software, and updating workflows.
  • Certification audits. Certification bodies (CBs) require fees for initial certification and surveillance audits.
  • Time and resources. These may include employee hours spent on training, process improvements, and audits.

Costs vary depending on company size and can run from tens of thousands of dollars for small factories to much more for large, multi-site operations. The good news is that the benefits of working systematically using a process-based management system (as per clause 4.4.1 or ISO 9001) drive the ROI as the system implementation reduces waste and other production inefficiencies.

Although there can be significant upfront costs, the benefits of ISO 9001 registration often compound over time. These can include operational efficiency with streamlined processes which reduce waste, downtime, and rework, leading directly to lower production costs. Customer confidence and market access improve as the manufacturer consistently produces confirming products and services. Many U.S. manufacturers find ISO 9001 and/or relevant industry-specific standards to be a “ticket to entry” for bidding on contracts, especially in sectors such as automotive, aerospace, and military/defense.

Reducing Risk

Documented processes and corrective action systems reduce the likelihood of costly failures or recalls. Employee engagement improves, resulting in highly motivated teams working within clearly defined roles. Appropriate training oriented toward competency (as seen in clause 7.2 of ISO 9001) reduces errors and boosts productivity. Continual improvement is an added benefit of ISO 9001 as the implementation of the standard promotes a culture of ongoing improvement, helping companies stay competitive in fast-changing markets.

Calculating the ROI of ISO 9001 registration can be assessed by comparing costs against measurable gains such as:

  • Reduced scrap/rework = cost savings
  • Improved on-time delivery = fewer penalties and more repeat orders
  • Access to new markets/contracts = increased revenue
  • Enhanced reputation = long-term customer retention

Example: If a manufacturer spends $50,000 on registration but reduces rework costs by $80,000 and gains $200,000 in new contracts, the ROI is clear and compelling.

Then there is the real-world impact. Studies consistently show manufacturers that achieve ISO 9001 registration experience:

  • 5–15% cost savings from efficiency gains
  • Revenue growth due to market access
  • Improved customer satisfaction scores, leading to stronger long-term partnerships
Final Thoughts

Initially, ISO 9001 registration may seem like a simple expense. But when viewed as an investment, the ROI to be found in ISO 9001 registration becomes clear. It brings definite improved efficiency, stronger customer trust, and measurable financial gains. For U.S. manufacturers competing in global markets, the payoff often far outweighs the cost.

The above article was recently published in an Exemplar Global publication ‘The Auditor’.

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Building a Quality Culture: The Role of Leadership

When the leadership at a U.S. industrial plant makes the strategic decision to roll out certification to ISO 9001, their first instinct is often to focus on documentation, audits, and procedures. They start by looking for a consultant who often (for quick money) provides a template. That is the start of misery for an organization.

A Better Way To Begin

The “As-Is” of the management system should be the start of this process. What has been developed over the years should not be forgotten or lost! The truth is that no checklist or manual can build a true quality culture. The secret ingredient in implementing ISO 9001 is the involvement of leadership in developing the system. As per sub-clause 5.1 (“Leadership and commitment”), their total involvement and commitment is required, in addition to others who assist them in this role, as per sub-clause 5.3 (“Organizational roles, responsibilities and authorities”).

Why leaders can make or break ISO 9001 effectiveness is an important question, and taking positive action to do so is therefore a vital decision. Employees don’t take their cues from policies—they take them from people. If leaders treat ISO 9001 as “just another certification,” that’s exactly how the workforce will see it. On the other hand, when leadership is visible, engaged, and committed, quality stops being a buzzword and becomes a way of working. A system that has the support of leadership has the best chance to produce conforming products and services and also ensure continual improvement.

ISO 9001 makes this clear. Clause 5 (“Leadership”) puts accountability squarely onto the leadership. It’s not just the quality manager’s responsibility anymore—it’s a business-wide effort, and leaders must own it. It is leadership that matters in ISO 9001 and is an important aspect of the process.

Clause 5 emphasizes that leaders must:

  • Demonstrate commitment to the quality management system (QMS)
  • Align quality objectives with organizational strategy
  • Promote a culture of continual improvement

The View From The Shop Floor

In U.S. industrial plants, where efficiency and production targets often dominate discussions, leadership involvement ensures quality doesn’t get sidelined. Leaders act as role models, showing that meeting quality objectives is as important as meeting delivery deadlines.

When auditors look at the implementation of a management system standard like ISO 9001, they need to be able to clearly evidence what leadership involvement looks like in practice. There are numerous indicators, most of them based on ISO 9001 subclauses 5.1, 5.1.2 (“Customer focus”), 5.2 (“Policy”), 6.1 (“Actions to address risks and opportunities”), 6.2 (“Quality objectives and planning to achieve them”), and 10.3 (“Continual improvement”). To generalize these into simple language I would say these would include the following:

  • Setting the tone. A plant manager who opens every team meeting with a quality update shows that it matters as much as production numbers.
  • Walking the floor. Leaders who regularly join quality reviews or stop by the line to ask about issues send a strong signal of support.
  • Connecting quality to strategy. Instead of treating ISO 9001 as paperwork, leaders can frame it as a competitive edge, leading to fewer defects, happier customers, and stronger market position.
  • Celebrating wins. Recognizing teams for continuous improvement projects—no matter how small—builds momentum and pride.

Culture is caught, not taught. We can train employees on ISO 9001 requirements, but culture is shaped by what leaders actually do. Creating an environment of quality is a leadership accountability issue. When executives understand the value of nonconformities as the drivers of corrective action and improvement, follow procedures, welcome audits, and act on feedback, employees naturally mirror those behaviors. Over time, this creates a culture where quality isn’t “extra work”—it’s simply the way we work. It is then that the organization can go from a reactive to a proactive manufacturing entity.

The return on investment in ISO 9001 can be traced to sub-clause 6.2 and the achievement of specific quality improvement objectives. Industrial plants that embrace ISO 9001 leadership involvement don’t just pass audits. They see less rework, stronger customer trust, and a workforce that takes pride in doing things right the first time. In today’s competitive manufacturing landscape, that’s not just compliance—it’s survival.

Bringing It Forward

Five practical steps leaders can take to lead the industry may include the following:

  1. Communicating the vision. It is important to clearly articulate why ISO 9001 matters—not only for certification, but for customer trust, employee pride, and long-term competitiveness.
  2. Allocating resources. Quality initiatives fail when they’re underfunded. Leaders must ensure sufficient training, technology, and staffing to support ISO 9001 compliance. Where they cannot provide resources, they must assume the risk and adjust objectives.
  3. Engaging with the employees. This includes walking the floor, participating in quality meetings, and recognizing contributions. All of these actions reinforce that quality is everyone’s responsibility.
  4. Integrating quality into the organization’s strategy. Quality goals should not be separate from business goals. For example, reducing defects can be tied directly to cost savings and improved customer satisfaction.
  5. Leading by example. Leaders who adhere to procedures, value data-driven decisions, and embrace audits demonstrate that ISO 9001 is part of the plant’s DNA.

ISO 9001 isn’t a binder sitting on a shelf. It’s a leadership-driven culture shift, and when leaders lead the way, the entire plant follows. Just keeping the binder on the shelf is no good. It may get the organization a certificate but will not result in a positive return on investment.

Without leadership involvement, ISO 9001 may become the missing link in the success of U.S. industrial plants. Your involvement as leaders at every step of your organization matters more than checklists. You must drive the culture of change.

In concluding, I would opine that rolling out ISO 9001 in U.S. industrial plants requires more than technical checklists; it requires leadership. By committing to involvement in the implementation of ISO 9001, plant managers and executives can transform their organizations into a quality-driven powerhouses that thrive in today’s competitive market.

The above article was recently published in “The Auditor” (an Exemplar Global publication).

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.

Keeping Your Management System ‘Ordinary’ in the Age of AI

We’re living in an era where every week seems to bring a new AI tool or software promising to “transform” your business. Predictive analytics, digital twins, algorithm-driven risk models; the buzzwords are endless. And while some of these advances do have their place, I argue that companies must not forget their basics. In a previous career as a mariner, as technology evolved and found their way on ships there was still some value to a simple visual bearing and the information it could give you.

Call me old-school, but I still believe in systems that are owned by people, not platforms. In fact, I’d argue that now more than ever, we need to protect the ordinariness of our management systems, because that’s where the real strength lies.

Don’t Mistake “Ordinary” for “Outdated”

I’ve worked on ships and in boardrooms, with multinationals and mom-and-pop shops. Across the board, the systems that work best are not the flashiest, they’re the ones that are understood, used, and respected. I’ve used fancy preventive/planned maintenance systems and then a simple excel spreadsheet with macros built in. Perhaps surprisingly, the company using the ordinary excel spreadsheet had better maintained equipment.

An “ordinary” system means:

  • Everyone knows their roles and responsibilities.
  • Processes are documented clearly, not buried in folders.
  • Documentation is clear and concise.
  • Records are maintained and can be trusted.

You don’t need artificial intelligence to tell you your maintenance wasn’t done. You need a culture where someone owns the task, completes it, and checks the box honestly.

When the Tool Becomes the Boss

I’ve seen organizations spend small fortunes on digital platforms that promise complete “management system automation.” These platforms often come with dashboards no one reads, workflows no one updates (because they don’t know how to), and training modules people click through just to make them go away. (Let’s be honest, you know how effective your CBT program are!)

Compare that to a simple 8D form built in Excel, yes, plain old Excel. When it’s used properly by a team that understands the process, it becomes a great tool for problem-solving. No licenses, no AI, no data scientists required.

If you’re curious, QMII’s Root Cause Analysis workshop teaches this practical approach. And it works because it’s rooted in thinking, not tech.

PDCA: Still the Smartest Loop in the Room

You don’t need AI to plan, do, check, and act. You need discipline. In a world full of reactive fixes and AI-generated insights, PDCA still calls on people to pause, observe, think, and improve. And frankly, we could all use more of that.

A well-run PDCA cycle doesn’t care whether your data comes from a sensor or a clipboard. What matters is how your team reflects, learns, and adjusts. If you want to sharpen that loop, QMII’s ISO 9001 Lead Auditor Training doesn’t just teach clauses. It teaches systems thinking, real auditing skills, and how to see the story behind the numbers.

Use AI? Sure. But Stay in the Driver’s Seat

I’m not against AI. Let me be clear on that. It’s a tool that, when used wisely, can absolutely support your management system. It can help you analyze patterns in data and generate reports that are helpful. But that’s exactly the point. AI is a tool, not the system itself, and certainly not the leader of it.

I’ve seen organizations fall into the trap of trusting algorithms more than their own people. They install AI to identify when personnel are not using PPE, to generate solutions based on data analysis and when errors occur. But no one stops to ask the most important questions: Does this make sense? Is this what’s really happening? Who validated this? Why did the person not use PPE?

The danger is that we start to mistake output for understanding. AI doesn’t know your organizational culture. It doesn’t know that one department always closes their nonconformities just to get them off the list. Only your team, using their judgment and grounded in your process reality, can make those distinctions.

If you’re going to use AI, integrate it into the PDCA cycle. Feed its outputs into your management review. Use it to inform, but not to dictate. And perhaps most importantly, teach your team to question it. Train them to ask, Where did this data come from? What assumptions are built into this model? What’s missing from the picture?

Own Your System. Keep It Ordinary.

There’s something refreshing about an audit checklist that an auditor actually helped write. Not an AI generate one. That’s real ownership. That’s engagement.

Management systems aren’t meant to be high-tech puzzles. They’re meant to be frameworks that help people do their jobs better. They are not a compliance burden, they’re a strategic asset, but only when they belong to the people who use them.

So here’s my message in conclusion: Keep your system ordinary. And make it extraordinary in how well it’s embraced and used.


About the Author
This article was written by Dr. Julius, Senior Consultant at QMII. With over 25 years of experience in ISO and aerospace quality systems, Dr. Julius has trained and advised hundreds of U.S. defense contractors in aligning with AS9100 and DoD requirements. He specializes in turning certification into a competitive advantage for suppliers.