Ga naar inhoud

ISO 27001 ·

ISO 9001:2026 when you already run an ISO 27001 ISMS

August 2026. ISO 9001:2026 is due on 16 September. Most coverage is written for quality managers who work with 9001 on its own. If you already operate an ISMS under ISO 27001, your starting point is different: three of the five major changes will look familiar, and a fourth touches your AI policy. Here is what you can reuse — and where it genuinely chafes.

Climate: you have already done this

The new requirement in clause 4.1 to assess whether climate change is relevant to your context is precisely the amendment added to ISO 27001 back in 2024. See our article on the climate amendment. Your existing context analysis and its rationale are reusable — provided they cover the organisation and not information security alone. Check that, because this is the trap.

Risks and opportunities: your process transfers, your register does not

ISO 9001:2026 separates risks from opportunities in clause 6.1. Your ISO 27001 risk process is methodologically strong enough to handle that; the problem is scope. An information security risk register deals with confidentiality, integrity and availability, not with delivery reliability or customer satisfaction. You reuse the method and the risk appetite scale, not the content.

Change management: two standards, one process

The expansion of clause 6.3 asks for controlled changes to processes, resources, technology and responsibilities. That overlaps heavily with the change management you already run under Annex A. See Annex A controls. This is where the biggest saving sits: one change process with one record, shown to both auditors.

AI and digitalisation: the ISO 42001 overlap

Where 9001:2026 asks about data integrity and the monitoring of AI tools in your processes, ISO 42001 asks about governance over those same tools. If you have already mapped AI use for your ISMS scope, the step to the quality side is small. If you have not, you can now do it once for both standards.

Culture: this is where the overlap stops

Quality culture and ethical behaviour are new and have no counterpart in your ISMS. Security awareness does not cover it: that is about behaviour around information, not about how your organisation handles mistakes, complaints and dissent. This is the part where you have genuinely new work.

One set of evidence, two audits

The practical gain lies in shared artefacts: context analysis, management review, internal audit planning, change records and the awareness programme. Set those up so both standards can be served from them and you will save a meaningful number of days across the transition to September 2029. See also audit preparation.

This article is based on the FDIS version of ISO 9001. We will update it after publication on 16 September 2026.

Deep dive in the knowledge base

Continue in ISO Ready

Manage actions, risks and evidence in one line of sight toward certification.

Visit ISO Ready

← Back to overview