Key Updates to ISO Standards: Latest ISO Standards Updates for Your Business

The ISO standards that underpin quality, environmental, health and safety, and information security management are not static. The International Organisation for Standardisation publishes revisions and amendments on a rolling basis, and organisations holding certification need to be aware of what is changing and when.

This article summarises the key updates across the main management system standards relevant to UK businesses, as of early 2026.

ISO 9001: Quality Management Systems

ISO 9001:2015 introduced risk-based thinking, leadership engagement, and a shift from prescriptive procedures to outcomes-based requirements. The standard is currently under revision, with a new edition expected. The revision is expected to reinforce the standard’s alignment with climate change considerations and strengthen requirements around organisational knowledge.

For businesses holding ISO 9001:2015 certification, no immediate action is required while the revision is in development. However, organisations should monitor announcements from their certification body about transition timelines once the new edition is published.

Key areas being discussed in the revision include:

  • More explicit integration of climate-related risks and opportunities into the management review and planning processes
  • Strengthened requirements around documented information, particularly for distributed and remote working arrangements
  • Alignment with the updated High Level Structure (HLS) used across all ISO management system standards

ISO 14001: Environmental Management Systems

ISO 14001 is undergoing revision for 2026. The current edition, ISO 14001:2015, has been a cornerstone of environmental management for over a decade, but the revision is expected to significantly strengthen climate change requirements.

The 2026 revision is anticipated to:

  • Require organisations to explicitly consider climate change as an external issue when determining the context of the organisation
  • Strengthen requirements for lifecycle thinking across products and services
  • Better align with global frameworks such as the Science Based Targets initiative (SBTi) and GHG Protocol

Organisations currently certified to ISO 14001:2015 should begin preparing for the transition period. Certification bodies typically allow a transition period of three years from the publication of a new edition.

For practical steps on preparing for the ISO 14001 revision, see our dedicated article: Understanding the 2026 Revision of ISO 14001.

ISO 45001: Occupational Health and Safety Management Systems

ISO 45001:2018 is also under revision, with the updated standard expected around 2027. The revision is anticipated to strengthen worker participation, mental health and wellbeing, and contractor management requirements.

Key themes being developed include:

  • Greater emphasis on psychological health and wellbeing, not just physical safety
  • More explicit requirements for managing occupational health risks (not just safety)
  • Strengthened requirements for worker consultation and participation, particularly for contractors and temporary workers
  • Better integration with organisational risk management frameworks

Our detailed article on the ISO 45001 revision covers what to expect: Understanding ISO 45001:2027 and Its Implications for Your Business.

ISO 27001: Information Security Management Systems

ISO 27001:2022 was published in October 2022, updating the previous 2013 edition. The transition deadline for existing certified organisations was 31 October 2025. Any organisation that had not transitioned by that date will need to treat their certification as lapsed and begin a fresh certification process.

The 2022 edition introduced:

  • A restructured Annex A with 93 controls (down from 114), reorganised into four themes: Organisational, People, Physical, and Technological
  • 11 new controls, including threat intelligence, ICT readiness for business continuity, physical security monitoring, data masking, and secure coding
  • Attributes for each control to support different filtering approaches (for example, by cybersecurity concept or operational capability)

For organisations that have already transitioned to ISO 27001:2022, the focus should now be on embedding the new controls and ensuring Annex A is properly reflected in the Statement of Applicability.

What this means for your organisation

The collective direction of travel across all major ISO management system standards is clear: greater emphasis on climate and environmental risk, psychological health and wellbeing, worker participation, and information security resilience.

Organisations that treat these standards as living systems: updating their management review inputs, monitoring their performance against objectives, and engaging with revision processes: will find transitions easier and their systems more genuinely useful.

If you hold certification to any of these standards, or are considering certification, contact Elmar Risk Management to discuss how we can help you stay ahead of these changes.

ISO 9001ISO 14001ISO 45001ISO 27001standards update

Share:

LinkedIn

Book a Free Call

Need compliance support for your organisation?

Every business is different. Book a free introductory call with Peter Berry to discuss what your organisation needs and how Elmar can help.

Book a Free Introductory Call